PCI DSS v.4.0 is here. Are you ready?
The newest evolution of the PCI Data Security Standards (PCI DSS) is almost upon us.
After PCI DSS v4.0 was announced in Q1 2022, companies had two more years left to use the old standard of PCI DSS v.3.2.1. Once it is officially retired on March 31, organizations have just one year to be compliant with PCI DSS v4.0.
If you consider that a typical PCI Assessment can take 3-5 months, that isn’t a lot of time.
What changes with PCI DSS 4.0 for payment security?
Background
PCI-DSS 4.0 was shaped by insights from over 200 organizations and 6,000 suggestions and tailored to meet the changing digital threats of modern payment ecosystems. Many changes are due to the payments industry’s increased focus on cloud migration, insider threats, and the surge in online commerce exacerbated by the pandemic.
Additionally, PCI-DSS 4.0 is unique in offering the opportunity to achieve compliance via tailored customization to address and accommodate dynamic technologies and diverse implementations. While PCI-DSS continues to be mandated for an organization to perform the expected due diligence, the new 4.0 standard intends to allow companies to consider the “intent” of a PCI DSS objective and account for their unique infrastructure and risk level exposure.
This creates unchartered territories with new questions and more limited precedents. PCI Compliance Assessments are always time-consuming and resource-intensive; these new requirements add an element of uncertainty to successful completion.
Who does it apply to?
Any organization that deals with Credit or Debit cardholder data.
If your organization:
Sensitive Card Data, you are subject to PCI DSS 4.0 requirements.
In other words, your cardholder data environment (CDE) is in “in-scope,” and you are subject to its guidelines.
There are 4 Levels of PCI Compliance. What are my requirements?
The PCI-DSS payment security standards apply to anyone who works with and is exposed to payment data, cardholder information, and financial accounts. There are separate requirements for merchants and service providers. Service providers are defined as business entities that are not a payment brand but are directly related to the processing, storing, or transmitting of cardholder data on behalf of another organization
For Merchants:
APPLICABLE IF YOU
- Process >6M Visa or Mastercard, or >2.5M American Express transactions each year
- Have experienced a data breach
- Are identified as “Level 1” by a card network (such as Visa or Mastercard)
REQUIREMENTS TO COMPLY
- Onsite assessment as an Annual Report on Compliance (ROC) by a Qualified Security Assessor (QSA), or internal auditor if signed by an officer of the company
- Quarterly network scan by Approved Scan Vendor (ASV)
- Attestation of Compliance (AOC) for Onsite Assessments
APPLICABLE IF YOU
- Process 1-6M transactions each year
REQUIREMENTS TO COMPLY
- Annual PCI DSS Self-Assessment Questionnaire (SAQ). Click here for a full list of merchant resources.
- Quarterly network scan by Approved Scan Vendor (ASV)
- Attestation of Compliance (AOC) —to match the SAQ type
APPLICABLE IF YOU
- Process 20K – 1M online transactions each year
- Process <1M total transactions each year
REQUIREMENTS TO COMPLY
- Annual PCI DSS Self-Assessment Questionnaire (SAQ). Click here for a full list of merchant resources.
- Quarterly network scan by Approved Scan Vendor (ASV)
- Attestation of Compliance (AOC) —to match the SAQ type
APPLICABLE IF YOU
- Process <20K online transactions each year
- Process <=1M total transactions each year
REQUIREMENTS TO COMPLY
- Annual PCI DSS Self-Assessment Questionnaire (SAQ). Click here for a full list of merchant resources.
- Quarterly network scan by Approved Scan Vendor (ASV)
- Attestation of Compliance (AOC) —to match the SAQ type
Service providers include companies that provide services that affect or may affect cardholder data security. Such services include managed service providers with managed firewalls, IDS / IPS, other services, and hosting service providers.
For Service Providers
Service providers include companies that provide services that affect or may affect cardholder data security. Such services include managed service providers with managed firewalls, IDS / IPS, other services, and hosting service providers.
APPLICABLE IF YOU
- Service Providers that store, process, or transmit >300K transactions per year (>2.5M for American Express.)
Also applicable to
- All Third Party Processors (TPPs)
- All Staged Digital Wallet Operators (SDWOs)
- All Digital Activity Service Providers (DASPs)
- All Token Service Providers (TSPs)
- All 3-D Secure Service Providers (3-DSSPs)
- All AML/Sanctions Service Providers
- All Installment Service Providers (ISPs)
- All Merchant Payment Gateways (MPGs)
- All Data Storage Entities (DSEs) and Payment Facilitators (PFs) with more than 300K total annual transactions
REQUIREMENTS TO COMPLY
- Annual PCI assessment resulting in the completion of a Report on Compliance (ROC) completed by a QSA (Qualified Security Auditor)
- Quarterly Network Scans performed by the Approved Scanning Provider (ASV)
- Annual Penetration Test
- Quarterly Local Network Vulnerability Scans
- Declaration of Conformity with an Attestation of Compliance (AOC)
APPLICABLE IF YOU
- Service Providers with <300K transactions per year (<2.5M for American Express.)
- All DSEs2 and PFs with 300,000 or less total combined Mastercard and Maestro transactions annually
Also applicable to:
- All Terminal Servicers (TSs)
REQUIREMENTS TO COMPLY
- Annual Self-Assessment Questionnaire (PCI SAQ) D
- Quarterly Network Scans performed by the Approved Scanning Provider (ASV)
- Annual Penetration Test
- Quarterly Local network Vulnerability Scans
- Declaration of Conformity with an Attestation of Compliance (AOC)
How can FLAGSHIP help me meet my PCI DSS Compliance needs?
A typical PCI Assessment covers a spectrum of needs across 12 requirements. We have simplified these, and have solutions to match the needs across all the requirements.
TYPICAL PCI DSS V4.0 SCOPE
FLAGSHIP SOLUTION
While people who participate in storing, processing, or transmitting cardholder data are part of the CDE, when implementing segmentation for PCI DSS scoping, these people do not have to be segmented or isolated from people who are outside of the CDE.
This is because the processes and technologies put in place to implement and maintain the segmentation also ensure that people in the CDE are the only ones with the requisite access.
What are my next steps?
- Understand your organization’s scope and team priorities to see if you have the time and resources needed to do this in-house by your annual assessment deadline.
- Plan out the most efficient way to meet the PCI DSS 4.0 requirements now and every quarter forward
- Contact us to see how we can help with your PCI compliance needs and prepare you for v.4.0.
PCI DSS 4.0 can feel daunting, but it doesn’t have to be. The FLAGSHIP solutions securely stores payment data, enabling organizations to descope their environments and fortify their security posture. We ensure that customers are confidently and constantly on top of changing PCI-DSS requirements, including for 4.0. Plus, we can recommend QSAs or work with your existing QSA to ensure a successful PCI audit that protects your data according to the latest regulations.