📞 Call Now 💬 WhatsApp 📋 Report
⚖️
SIRI Law LLP
● Typically replies within 30 min
👋 Hi! How can SIRI Law LLP help you today?

We offer expert legal and cybersecurity advisory. Tap below for a confidential chat.
SIRI Law · Now
💬  Start Chat on WhatsApp
PCI DSS v4.0.1 Compliance & Audit Readiness in India | SIRI Law LLP
PCI DSS v4.0.1 · Payment Card Security · Hyderabad, India

PCI DSS compliance & audit readiness — secure cardholder data and maintain card acceptance.

PCI DSS v4.0.1 mandates security requirements for any organisation that stores, processes, or transmits cardholder data. Non-compliance can result in fines of $5,000–$100,000 per month, forced card scheme withdrawal, and breach liability. SIRI Law LLP's PCI DSS practice combines certified security engineers with legal advisory for complete compliance management.

v4.0.1Current standard, published 11 June 2024 — the version every 2026 assessment must use
51 of 64Future-dated requirements now mandatory since 31 March 2025 — no longer optional best practice
$5K–$100KMonthly fine range for non-compliance, passed through by acquiring banks
12Requirements across six control goals — network, data, vulnerability, access, monitoring, policy
The PCI DSS transition clock
Live tracking · scroll to see every relevant date
Published
MAR 2022
PCI DSS v4.0 published — the first major standard update in over a decade, introducing 64 new or updated requirements.
Retired
31 MAR 2024
PCI DSS v3.2.1 officially retired — v4.0 becomes the sole active standard, with 51 of the 64 new requirements still future-dated as best practice only.
Clarified
11 JUN 2024
PCI DSS v4.0.1 published as a limited revision — clarifying ambiguous wording, no new technical requirements added.
Mandatory
31 MAR 2025
All 51 future-dated requirements become fully mandatory and assessed — including Req. 6.4.3 (payment page scripts) and 11.6.1 (change-detection mechanisms).
Live now
2026
Every assessment conducted in 2026 uses v4.0.1's SAQs and ROC template — a v4.0 SAQ submitted this year is the wrong document.
Open comment
3 JUN–20 JUL 2026
PCI SSC opens request-for-comments on v4.0.1, seeking input on AI in payment environments, cloud architectures, and emerging e-commerce risk — signalling scope of the next revision.

Getting the version and deadline right

"PCI DSS v4.0" alone is the superseded label. The deadline that mattered — 31 March 2025 — has already passed.

Some PCI DSS compliance content still refers generically to "v4.0" without acknowledging two facts that materially change what compliance actually requires today. First, the current standard is v4.0.1, published 11 June 2024 as a limited clarifying revision. It didn't add new technical requirements, but every assessment conducted in 2026 must use v4.0.1's updated SAQs and Report on Compliance template — an organisation still submitting a v4.0-labelled SAQ this year is, in the words of one industry compliance guide, using "the wrong document."

Second, and more consequential: of the 64 new or updated requirements v4.0 introduced, 51 were future-dated — treated as best practice only, not formally assessed — with a hard transition deadline of 31 March 2025. That deadline has now passed. All 51 requirements are fully mandatory and in scope for every PCI DSS assessment conducted since. This includes some of the requirements most e-commerce merchants and payment platforms found hardest to implement: Requirement 6.4.3, requiring controls over payment page scripts to prevent e-skimming attacks, and Requirement 11.6.1, requiring a change- and tamper-detection mechanism for payment pages. An organisation that validated compliance under v4.0 in 2024 and treated these as optional will fail its next assessment unless the controls have since been built.

If your last SAQ predates March 2025, don't assume it still reflects your obligations
The practical risk here isn't abstract. Organisations whose last completed SAQ or ROC dates from before the 31 March 2025 transition may be operating under the mistaken impression that their prior assessment still describes their full compliance obligation. It doesn't. A gap assessment against the currently mandatory 12 requirements, including all 51 formerly future-dated items, is the only way to know whether controls that were optional in 2024 have actually been implemented since.

Looking ahead, PCI SSC opened a formal request-for-comments period running 3 June to 20 July 2026 on the current v4.0.1 standard, explicitly inviting feedback on AI use in payment environments alongside cloud architecture and emerging e-commerce risk — an early signal of where the next substantive revision is likely headed, though no new version had been published as of the comment period's opening.

Where PCI DSS compliance actually breaks down

Scope, segmentation, and the March 2025 transition are where most gaps hide

Recurring patterns behind the PCI DSS gaps we find most often.

01 — SCOPE

Incorrect CDE scoping inflates the compliance burden

The Cardholder Data Environment and all systems connected to or that can affect its security are in scope. Organisations that scope too broadly pay for controls they don't need; those that scope too narrowly miss requirements they do.

02 — SEGMENTATION

Segmentation is assumed, rarely validated

Network segmentation intended to reduce scope is frequently untested. PCI DSS Requirement 11.4 requires penetration testing to validate that out-of-scope systems genuinely cannot reach the CDE — an assumption, not a test, is not compliance.

03 — STALE ASSESSMENT

Pre-2025 assessments no longer reflect current obligations

Organisations whose last SAQ or ROC predates 31 March 2025 may believe their compliance posture is current when 51 formerly future-dated requirements have since become mandatory and untested.

04 — E-COMMERCE

Payment page script controls are widely underimplemented

Requirement 6.4.3's controls over payment page scripts, aimed at preventing e-skimming (Magecart-style) attacks, are among the most operationally demanding of the newly mandatory requirements, and among the most commonly missed.

Scope of services

What our engagement covers

  • PCI DSS v4.0.1 gap assessment — all 12 requirements, including all 51 formerly future-dated items
  • Cardholder Data Environment (CDE) scoping workshop
  • Data flow mapping — cardholder data identification
  • Network segmentation design and validation
  • Penetration testing — PCI DSS Requirement 11.4 (annual + segmentation)
  • Vulnerability scanning programme — ASV-aligned quarterly external scans
  • Internal vulnerability scanning programme design
  • Payment page script controls — Req. 6.4.3 and 11.6.1 implementation
  • Access control and authentication hardening (Req. 7, 8)
  • Logging and monitoring programme — Req. 10
  • Incident response plan — PCI DSS breach notification requirements
  • SAQ selection and completion advisory (current v4.0.1 versions: A, A-EP, B, C, D, P2PE)
  • QSA liaison and ROC (Report on Compliance) preparation
  • Tokenisation and encryption advisory — reduce scope
  • Third-party/vendor PCI DSS compliance programme
  • RBI payment security regulation integration

Evidence, not guesswork

v4.0 vs. v4.0.1 vs. what's actually mandatory today

Three things people conflate. Here's how they're actually different.

Version / milestone Date What it means for compliance
v4.0 published March 2022 64 new/updated requirements introduced; 51 marked future-dated (best practice only)
v3.2.1 retired 31 Mar 2024 v4.0 becomes the sole active standard for assessments
v4.0.1 published 11 Jun 2024 Clarifying revision — no new technical requirements, but updated SAQs/ROC template now required
Future-dated requirements mandatory 31 Mar 2025 All 51 requirements fully assessed — no longer optional best practice
Current state 2026 v4.0.1 with all 64 requirements mandatory is the standard in force for every assessment

Source: PCI Security Standards Council publications and Summary of Changes documentation. Confirm current SAQ and ROC template versions directly with your QSA or acquiring bank before submission.

What the numbers actually mean

Four figures that frame PCI DSS compliance today

51
Now-mandatory requirements

Formerly future-dated, mandatory since 31 March 2025 — the single biggest gap in pre-2025 compliance postures.

$5K–100K
Monthly non-compliance fine

Range passed through by acquiring banks — escalates with duration and severity of non-compliance.

v4.0.1
Current standard version

The only SAQ/ROC template version accepted for 2026 assessments — a v4.0 document is the wrong one.

12
Requirements, six goals

Network security, data protection, vulnerability management, access control, monitoring, policy.

Our engagement process

How we work, step by step

01

Initial Scoping & Assessment

Gap assessment against the applicable framework — including all 51 now-mandatory requirements — engagement scope definition, and a prioritised remediation roadmap.

02

Programme Design

Control framework, documentation structure, evidence requirements, and governance processes tailored to your organisation.

03

Implementation Advisory

Advising on implementation of each required control, working alongside your technical and operational teams to build controls that are practical and auditable.

04

Internal Audit & Validation

Internal audit or readiness assessment identifying any remaining gaps before the formal certification or attestation process begins.

05

Certification / Attestation Support

Managing auditor queries, providing evidence, and resolving findings during the formal audit or assessment.

06

Post-Certification Advisory

Ongoing support — surveillance audit preparation, change management, and regulatory update advisory as PCI SSC guidance evolves.

Typical engagement timeline varies by organisation size and existing control maturity.

Benefits & deliverables

What you get from this engagement

Scoping Workshop

Define your CDE accurately, including all systems that store, process, or transmit cardholder data and all connected systems. Correct scoping is the most impactful compliance cost reduction available.

Gap Assessment

Comprehensive gap assessment against all 12 PCI DSS v4.0.1 requirements, with a prioritised remediation plan and compliance timeline.

Segmentation Validation

Network segmentation penetration testing, validating that your scope-reduction segmentation actually works and out-of-scope systems cannot reach the CDE.

Penetration Testing

Annual PCI DSS-compliant penetration testing of the CDE, both external and internal, with a report format that satisfies QSA requirements.

SAQ/ROC Preparation

For merchants: current v4.0.1 SAQ selection and completion advisory. For service providers requiring ROC: complete evidence preparation and QSA liaison.

Ongoing Compliance

Quarterly scanning, annual testing, and ongoing advisory, keeping your compliance current throughout the year, not just at audit time.

Integration advantage

Compliance engagements backed by qualified legal counsel

Our compliance engagements ensure your programme satisfies both technical certification requirements and legal obligations under DPDPA, IT Act, and sector-specific regulation.

01 — Precision

We know which version and which deadline

We work from v4.0.1's current SAQ and ROC templates and treat all 51 formerly future-dated requirements as fully mandatory, not a client-side assumption to be discovered at audit time.

02 — RBI integration

PCI DSS alongside RBI payment rules

Our legal team integrates PCI DSS compliance with RBI's Master Direction on Digital Payment Security Controls and PA-PG guidelines, avoiding duplicate work for payment aggregators and gateways.

03 — Technical depth

Segmentation testing that's actually validated

Our security team performs the Requirement 11.4 penetration testing and segmentation validation directly, rather than outsourcing to a disconnected vendor whose report doesn't satisfy your QSA.

04 — Credentials

Certified engineers

Our team holds CCSP, CISM, CIPP/E, CEH, OSCP, CISSP, CPENT, and ISO 27001 Lead Auditor credentials, the mix QSAs and acquiring banks expect from a serious compliance programme.

Frequently asked

PCI DSS, answered directly

Is it PCI DSS v4.0 or v4.0.1, and does the difference matter for compliance?

PCI DSS v4.0.1 is the current standard, published 11 June 2024 as a limited clarifying revision to v4.0. It did not add new technical requirements, but every 2026 assessment must use v4.0.1's updated SAQs and ROC template, not the original v4.0 versions. More importantly, the 51 requirements that v4.0 introduced as future-dated best practices became fully mandatory on 31 March 2025. If your last assessment predates that date and treated those 51 requirements as optional, your next assessment will fail unless they have since been implemented.

We accept card payments through a third-party payment gateway. Are we still in scope for PCI DSS?

Yes — if your checkout page redirects to a third-party payment page and you never see cardholder data, you may qualify for SAQ A, the simplest compliance pathway. However, if your website is compromised and the redirect is modified to capture card data before it reaches the payment page, you bear responsibility. PCI DSS v4.0.1 Requirement 6.4.3 now explicitly requires controls over payment page scripts for e-commerce merchants, and this is one of the future-dated requirements that became mandatory in March 2025. We advise on your specific compliance pathway.

What is the difference between a QSA assessment and an SAQ?

A QSA (Qualified Security Assessor) assessment is conducted by an independent PCI SSC-approved firm and produces a Report on Compliance (ROC), required for Level 1 merchants and most service providers. An SAQ (Self-Assessment Questionnaire) is a self-certification completed by the merchant or service provider, available for lower-risk compliance scenarios. The appropriate validation method depends on your merchant/service provider level and card scheme requirements. We advise on the correct path for your situation.

How does PCI DSS interact with RBI's payment security regulations?

RBI regulations and card scheme PCI DSS requirements overlap significantly but are not identical. RBI's Master Direction on Digital Payment Security Controls and PA-PG guidelines impose requirements on payment aggregators and gateways. We integrate PCI DSS compliance with RBI regulatory obligations, avoiding duplicate work while ensuring full compliance with both frameworks.

Can tokenisation or point-to-point encryption (P2PE) reduce our PCI DSS scope?

Yes — tokenisation and certified P2PE solutions can significantly reduce your CDE scope by ensuring your systems never handle actual PANs (Primary Account Numbers). We advise on the scope reduction available from these technologies and the PCI DSS requirements applicable to the reduced scope. This is one of the most cost-effective ways to simplify ongoing PCI DSS compliance.

What happens if our last PCI assessment was completed before March 2025?

It should not be treated as current. A pre-March 2025 SAQ or ROC likely assessed the 51 future-dated requirements as optional best practice rather than mandatory controls. We recommend a focused gap assessment against the currently mandatory requirements, particularly Req. 6.4.3 (payment page scripts) and 11.6.1 (change-detection mechanisms), before your next scheduled assessment.

Ready to start your PCI journey?

All engagements begin with a complimentary scoping call.

Let us understand your environment and confirm whether your compliance posture reflects the requirements mandatory since March 2025.

or call +91 79819 12046 — Mon–Sat, 9 AM – 7 PM IST

Visit or contact us

SIRI Law LLP — Hyderabad, India

Registered officeHITEC City, Madhapur, Hyderabad, Telangana 500081, India
Telephone+91 79819 12046
Emailinfo@sirilawllp.com
Other officesNew Delhi, India · Austin, Texas, USA · Online worldwide
HoursMon–Sat, 9:30 AM – 7:00 PM IST · Emergency line 24/7
© SIRI Law LLP · Hyderabad, Telangana

This page is provided for general informational purposes only. Compliance requirements vary by organisation, sector, and jurisdiction. References to PCI DSS v4.0.1, the 31 March 2025 transition, and specific requirement numbers reflect publicly available PCI Security Standards Council guidance as of publication and remain subject to further PCI SSC updates; confirm current requirement text and applicable SAQ/ROC templates with your QSA or acquiring bank before submission. Engagement with SIRI Law LLP requires a formal retainer. This page does not constitute legal advice. SIRI Law LLP is a registered law firm under the Limited Liability Partnership Act 2008, practising under the Advocates Act 1961; complaints regarding professional conduct may be directed to the Bar Council of Telangana.

Scroll to Top