MAR 2025
51 requirements went live
The future-dated v4.x controls — MFA on all CDE access, targeted risk analysis, payment-page script monitoring — became mandatory with no transition period after them.
PCI DSS v4.x is fully in effect — the 51 future-dated requirements went live March 31, 2025, with no grace period. If you take card payments, you're now either compliant or you're not, and your cardholder data environment scope decides how hard that is. We scope it tight and prove it.
Book a PCI DSS Strategy Call →// WHY PCI DSS, WHY NOW
MAR 2025
The future-dated v4.x controls — MFA on all CDE access, targeted risk analysis, payment-page script monitoring — became mandatory with no transition period after them.
LEVEL 1
Any merchant that suffers a cardholder-data breach is bumped to Level 1 regardless of volume — a permanent step up to QSA-led validation. The cost of a gap isn't just a fine.
SCOPE
Your cardholder data environment sets which SAQ applies, how many requirements are in play, and total cost. The most expensive PCI mistakes are scoping mistakes.
// A PROCESSOR ISN'T A PASS
Outsourcing payments shrinks your burden; it doesn't erase it. If you accept cards, you still validate — typically a Self-Assessment Questionnaire scoped to how you accept them — and you're responsible for the service providers in your flow. For e-commerce, the v4.x payment-page requirements apply to the page that hands the customer to payment even when the form is hosted elsewhere. "We use a processor" is a reason to scope carefully, not a reason to assume PCI doesn't apply.
// THE MERCHANT LEVEL PYRAMID
Your transaction volume sets your level, and your level sets how you validate. Level 1 is the top tier — QSA-led, the most demanding — and a single breach lands any merchant there regardless of volume.
The most demanding tier: an annual QSA-led Report on Compliance plus quarterly ASV scans. The part most merchants miss — a single cardholder-data breach promotes you to Level 1 regardless of volume, a permanent step up in validation burden. The three levels below validate more lightly, by volume.
// LEVEL 2
1–6M txns
SAQ or RoC at acquirer discretion, plus quarterly ASV scans.
// LEVEL 3
20k–1M e-comm
Mid-market online band — where the SAQ A vs A-EP choice matters most.
// LEVEL 4
<20k e-comm
Largest level by count — self-assess via SAQ plus quarterly ASV scans.
Volume sets your level — but scope sets your effort.
// THE PATH
PCI DSS is an annual cycle that starts with scope, not controls. The amber stages are where outside parties enter — the quarterly ASV scans and the formal validation (SAQ or QSA-led RoC).
Scope
CDE & Level
WK 1–3
Gap
Gap Assessment
WK 3–7
Remediate
Control Buildout
MO 2–5
ASV Scans
Quarterly Scans
QUARTERLY
Validate
SAQ / RoC
ANNUAL
Maintain
Annual Cycle
CONTINUOUS
Amber stages are where outside parties enter — the Approved Scanning Vendor's quarterly scans and your annual validation (SAQ or a QSA-led Report on Compliance). PCI is a yearly cycle, not a one-time pass.
// IS THIS YOU?
// 01 // STALE SAQ
If your SAQ or RoC was completed before the March 2025 changes took effect, it doesn't reflect the controls now required — MFA on all CDE access, script monitoring, and the rest.
// 02 // SPRAWLING SCOPE
If cardholder data touches general-purpose systems instead of a tightly segmented environment, your scope — and your cost and risk — is far bigger than it needs to be.
// 03 // E-COMMERCE
The v4.x payment-page rules hit e-commerce hardest. If you haven't addressed script monitoring and change detection on your checkout flow, that's an open gap today.
// WHAT WE DO
// Phase 01 · Scope
We draw the cardholder data environment boundary and confirm your level and SAQ eligibility — the decision that drives effort and cost more than any control.
// Phase 02 · Remediate
We close the gaps against v4.x — including the requirements that tripped up most merchants in 2025 — with evidence an assessor will accept.
// Phase 03 · Validate
We carry you through SAQ submission or QSA-led RoC and keep the program live, so each year's attestation is maintenance — not a fresh scramble.
// A BREACH BUMPS YOU TO LEVEL 1
// FREQUENTLY ASKED
The active standard is v4.x — versions 4.0 and 4.0.1. v3.2.1 retired March 31, 2024, and v4.0.1 (June 2024) was a clarifying revision with no new requirements. The deadline that matters has passed: of the 64 new requirements in v4.0, 51 became mandatory on March 31, 2025, with no transition period after.
So in 2026 the framing isn't "we still have time to prepare" — it's "are we actually compliant, and can we prove it?" If your controls or last validation predate the March 2025 changes (MFA on all CDE access, targeted risk analysis, payment-page script monitoring), you're likely carrying gaps right now.
Your level is set by annual transaction volume and decides how you validate. Level 1 is over 6 million transactions — and any merchant that suffers a cardholder-data breach is assigned Level 1 regardless of volume. It requires an annual QSA-led Report on Compliance plus quarterly ASV scans. Level 2 is ~1–6M; Level 3 ~20k–1M e-commerce; Level 4 under 20k e-commerce.
Levels 2 through 4 generally self-assess via the appropriate SAQ plus quarterly ASV scans, though an acquirer can require more at its discretion. The part most miss: a single breach promotes you to the most demanding tier permanently — so getting scoping and controls wrong costs more than a fine.
Scope is the single biggest lever, because PCI DSS applies to your Cardholder Data Environment (CDE) — systems that store, process, or transmit card data, plus anything connected to them. That environment's size decides which SAQ you're eligible for, how many requirements apply, and the total cost.
A tightly scoped merchant that fully outsources payment handling can qualify for the shortest SAQ; one where card data flows through general-purpose systems drags the whole network into scope. The most expensive PCI mistakes are scoping mistakes — under-scope and your validation is invalid; over-scope and you're securing systems that never needed to touch card data. Getting the CDE boundary right is where a good engagement earns its keep.
Almost always yes — though outsourcing can dramatically reduce your burden. If you accept cards, you have PCI obligations even when a third party handles the data: you still validate (typically a SAQ scoped to how you accept payments) and you manage the service providers in your flow.
For e-commerce specifically, the v4.x payment-page requirements (script monitoring, change detection) apply to the page that hands the customer to payment even when the form is hosted by a processor — which surprised many merchants. Outsourcing well, with validated providers and redirect/iframe approaches, is one of the best ways to shrink scope — but "we use a processor" is a reason to scope carefully, not to assume PCI doesn't apply.
// THE NEXT MOVE
Book a 30-minute PCI DSS strategy call with a WatchUr6 advisor. Bring how you accept payments, your rough transaction volume, your processor or gateway, and your last SAQ or RoC if you have one. You'll walk away with a clear read on your level, a tighter scope, and an honest list of the gaps the 2025 changes opened — whether you hire us or not.
Book a PCI DSS Strategy Call →SDVOSB · DVBE · SBE · CMAS #3-25-06-1018 · CAGE 9CQZ9 · VETERAN-LED