PCI DSS compliance & audit readiness — secure cardholder data and maintain card acceptance.
PCI DSS v4.0.1 mandates security requirements for any organisation that stores, processes, or transmits cardholder data. Non-compliance can result in fines of $5,000–$100,000 per month, forced card scheme withdrawal, and breach liability. SIRI Law LLP's PCI DSS practice combines certified security engineers with legal advisory for complete compliance management.
Getting the version and deadline right
"PCI DSS v4.0" alone is the superseded label. The deadline that mattered — 31 March 2025 — has already passed.
Some PCI DSS compliance content still refers generically to "v4.0" without acknowledging two facts that materially change what compliance actually requires today. First, the current standard is v4.0.1, published 11 June 2024 as a limited clarifying revision. It didn't add new technical requirements, but every assessment conducted in 2026 must use v4.0.1's updated SAQs and Report on Compliance template — an organisation still submitting a v4.0-labelled SAQ this year is, in the words of one industry compliance guide, using "the wrong document."
Second, and more consequential: of the 64 new or updated requirements v4.0 introduced, 51 were future-dated — treated as best practice only, not formally assessed — with a hard transition deadline of 31 March 2025. That deadline has now passed. All 51 requirements are fully mandatory and in scope for every PCI DSS assessment conducted since. This includes some of the requirements most e-commerce merchants and payment platforms found hardest to implement: Requirement 6.4.3, requiring controls over payment page scripts to prevent e-skimming attacks, and Requirement 11.6.1, requiring a change- and tamper-detection mechanism for payment pages. An organisation that validated compliance under v4.0 in 2024 and treated these as optional will fail its next assessment unless the controls have since been built.
Looking ahead, PCI SSC opened a formal request-for-comments period running 3 June to 20 July 2026 on the current v4.0.1 standard, explicitly inviting feedback on AI use in payment environments alongside cloud architecture and emerging e-commerce risk — an early signal of where the next substantive revision is likely headed, though no new version had been published as of the comment period's opening.
Where PCI DSS compliance actually breaks down
Scope, segmentation, and the March 2025 transition are where most gaps hide
Recurring patterns behind the PCI DSS gaps we find most often.
Incorrect CDE scoping inflates the compliance burden
The Cardholder Data Environment and all systems connected to or that can affect its security are in scope. Organisations that scope too broadly pay for controls they don't need; those that scope too narrowly miss requirements they do.
Segmentation is assumed, rarely validated
Network segmentation intended to reduce scope is frequently untested. PCI DSS Requirement 11.4 requires penetration testing to validate that out-of-scope systems genuinely cannot reach the CDE — an assumption, not a test, is not compliance.
Pre-2025 assessments no longer reflect current obligations
Organisations whose last SAQ or ROC predates 31 March 2025 may believe their compliance posture is current when 51 formerly future-dated requirements have since become mandatory and untested.
Payment page script controls are widely underimplemented
Requirement 6.4.3's controls over payment page scripts, aimed at preventing e-skimming (Magecart-style) attacks, are among the most operationally demanding of the newly mandatory requirements, and among the most commonly missed.
Scope of services
What our engagement covers
- PCI DSS v4.0.1 gap assessment — all 12 requirements, including all 51 formerly future-dated items
- Cardholder Data Environment (CDE) scoping workshop
- Data flow mapping — cardholder data identification
- Network segmentation design and validation
- Penetration testing — PCI DSS Requirement 11.4 (annual + segmentation)
- Vulnerability scanning programme — ASV-aligned quarterly external scans
- Internal vulnerability scanning programme design
- Payment page script controls — Req. 6.4.3 and 11.6.1 implementation
- Access control and authentication hardening (Req. 7, 8)
- Logging and monitoring programme — Req. 10
- Incident response plan — PCI DSS breach notification requirements
- SAQ selection and completion advisory (current v4.0.1 versions: A, A-EP, B, C, D, P2PE)
- QSA liaison and ROC (Report on Compliance) preparation
- Tokenisation and encryption advisory — reduce scope
- Third-party/vendor PCI DSS compliance programme
- RBI payment security regulation integration
Evidence, not guesswork
v4.0 vs. v4.0.1 vs. what's actually mandatory today
Three things people conflate. Here's how they're actually different.
| Version / milestone | Date | What it means for compliance |
|---|---|---|
| v4.0 published | March 2022 | 64 new/updated requirements introduced; 51 marked future-dated (best practice only) |
| v3.2.1 retired | 31 Mar 2024 | v4.0 becomes the sole active standard for assessments |
| v4.0.1 published | 11 Jun 2024 | Clarifying revision — no new technical requirements, but updated SAQs/ROC template now required |
| Future-dated requirements mandatory | 31 Mar 2025 | All 51 requirements fully assessed — no longer optional best practice |
| Current state | 2026 | v4.0.1 with all 64 requirements mandatory is the standard in force for every assessment |
Source: PCI Security Standards Council publications and Summary of Changes documentation. Confirm current SAQ and ROC template versions directly with your QSA or acquiring bank before submission.
What the numbers actually mean
Four figures that frame PCI DSS compliance today
Formerly future-dated, mandatory since 31 March 2025 — the single biggest gap in pre-2025 compliance postures.
Range passed through by acquiring banks — escalates with duration and severity of non-compliance.
The only SAQ/ROC template version accepted for 2026 assessments — a v4.0 document is the wrong one.
Network security, data protection, vulnerability management, access control, monitoring, policy.
Our engagement process
How we work, step by step
Initial Scoping & Assessment
Gap assessment against the applicable framework — including all 51 now-mandatory requirements — engagement scope definition, and a prioritised remediation roadmap.
Programme Design
Control framework, documentation structure, evidence requirements, and governance processes tailored to your organisation.
Implementation Advisory
Advising on implementation of each required control, working alongside your technical and operational teams to build controls that are practical and auditable.
Internal Audit & Validation
Internal audit or readiness assessment identifying any remaining gaps before the formal certification or attestation process begins.
Certification / Attestation Support
Managing auditor queries, providing evidence, and resolving findings during the formal audit or assessment.
Post-Certification Advisory
Ongoing support — surveillance audit preparation, change management, and regulatory update advisory as PCI SSC guidance evolves.
Typical engagement timeline varies by organisation size and existing control maturity.
Benefits & deliverables
What you get from this engagement
Scoping Workshop
Define your CDE accurately, including all systems that store, process, or transmit cardholder data and all connected systems. Correct scoping is the most impactful compliance cost reduction available.
Gap Assessment
Comprehensive gap assessment against all 12 PCI DSS v4.0.1 requirements, with a prioritised remediation plan and compliance timeline.
Segmentation Validation
Network segmentation penetration testing, validating that your scope-reduction segmentation actually works and out-of-scope systems cannot reach the CDE.
Penetration Testing
Annual PCI DSS-compliant penetration testing of the CDE, both external and internal, with a report format that satisfies QSA requirements.
SAQ/ROC Preparation
For merchants: current v4.0.1 SAQ selection and completion advisory. For service providers requiring ROC: complete evidence preparation and QSA liaison.
Ongoing Compliance
Quarterly scanning, annual testing, and ongoing advisory, keeping your compliance current throughout the year, not just at audit time.
Integration advantage
Compliance engagements backed by qualified legal counsel
Our compliance engagements ensure your programme satisfies both technical certification requirements and legal obligations under DPDPA, IT Act, and sector-specific regulation.
We know which version and which deadline
We work from v4.0.1's current SAQ and ROC templates and treat all 51 formerly future-dated requirements as fully mandatory, not a client-side assumption to be discovered at audit time.
PCI DSS alongside RBI payment rules
Our legal team integrates PCI DSS compliance with RBI's Master Direction on Digital Payment Security Controls and PA-PG guidelines, avoiding duplicate work for payment aggregators and gateways.
Segmentation testing that's actually validated
Our security team performs the Requirement 11.4 penetration testing and segmentation validation directly, rather than outsourcing to a disconnected vendor whose report doesn't satisfy your QSA.
Certified engineers
Our team holds CCSP, CISM, CIPP/E, CEH, OSCP, CISSP, CPENT, and ISO 27001 Lead Auditor credentials, the mix QSAs and acquiring banks expect from a serious compliance programme.
Frequently asked
PCI DSS, answered directly
Is it PCI DSS v4.0 or v4.0.1, and does the difference matter for compliance?
PCI DSS v4.0.1 is the current standard, published 11 June 2024 as a limited clarifying revision to v4.0. It did not add new technical requirements, but every 2026 assessment must use v4.0.1's updated SAQs and ROC template, not the original v4.0 versions. More importantly, the 51 requirements that v4.0 introduced as future-dated best practices became fully mandatory on 31 March 2025. If your last assessment predates that date and treated those 51 requirements as optional, your next assessment will fail unless they have since been implemented.
We accept card payments through a third-party payment gateway. Are we still in scope for PCI DSS?
Yes — if your checkout page redirects to a third-party payment page and you never see cardholder data, you may qualify for SAQ A, the simplest compliance pathway. However, if your website is compromised and the redirect is modified to capture card data before it reaches the payment page, you bear responsibility. PCI DSS v4.0.1 Requirement 6.4.3 now explicitly requires controls over payment page scripts for e-commerce merchants, and this is one of the future-dated requirements that became mandatory in March 2025. We advise on your specific compliance pathway.
What is the difference between a QSA assessment and an SAQ?
A QSA (Qualified Security Assessor) assessment is conducted by an independent PCI SSC-approved firm and produces a Report on Compliance (ROC), required for Level 1 merchants and most service providers. An SAQ (Self-Assessment Questionnaire) is a self-certification completed by the merchant or service provider, available for lower-risk compliance scenarios. The appropriate validation method depends on your merchant/service provider level and card scheme requirements. We advise on the correct path for your situation.
How does PCI DSS interact with RBI's payment security regulations?
RBI regulations and card scheme PCI DSS requirements overlap significantly but are not identical. RBI's Master Direction on Digital Payment Security Controls and PA-PG guidelines impose requirements on payment aggregators and gateways. We integrate PCI DSS compliance with RBI regulatory obligations, avoiding duplicate work while ensuring full compliance with both frameworks.
Can tokenisation or point-to-point encryption (P2PE) reduce our PCI DSS scope?
Yes — tokenisation and certified P2PE solutions can significantly reduce your CDE scope by ensuring your systems never handle actual PANs (Primary Account Numbers). We advise on the scope reduction available from these technologies and the PCI DSS requirements applicable to the reduced scope. This is one of the most cost-effective ways to simplify ongoing PCI DSS compliance.
What happens if our last PCI assessment was completed before March 2025?
It should not be treated as current. A pre-March 2025 SAQ or ROC likely assessed the 51 future-dated requirements as optional best practice rather than mandatory controls. We recommend a focused gap assessment against the currently mandatory requirements, particularly Req. 6.4.3 (payment page scripts) and 11.6.1 (change-detection mechanisms), before your next scheduled assessment.
Ready to start your PCI journey?
All engagements begin with a complimentary scoping call.
Let us understand your environment and confirm whether your compliance posture reflects the requirements mandatory since March 2025.
Related services
Other ways SIRI Law LLP supports your compliance posture
Visit or contact us
SIRI Law LLP — Hyderabad, India
| Registered office | HITEC City, Madhapur, Hyderabad, Telangana 500081, India |
| Telephone | +91 79819 12046 |
| info@sirilawllp.com | |
| Other offices | New Delhi, India · Austin, Texas, USA · Online worldwide |
| Hours | Mon–Sat, 9:30 AM – 7:00 PM IST · Emergency line 24/7 |

