ciso.diy

PCI DSS v4.0.1 — no grace argument left

All 51 future-dated v4.0.1 requirements became mandatory on 31 March 2025, so 2026 is the first assessment year with nothing to defer. The January 2025 SAQ A revision is the trap: requirements 6.4.3 and 11.6.1 were removed and replaced with an eligibility criterion, and a site that embeds a gateway’s JavaScript on its payment page is SAQ A-EP whatever the vendor said.

Key dates

2 dated obligations. Rows marked verify are not final in their source. See the whole calendar.

In force SAQ A revised — 6.4.3 and 11.6.1 removed and replaced with an eligibility criterion
In force All 51 future-dated v4.0.1 requirements become mandatory — no grace argument remains

What practitioners need to know

Lifted verbatim from the kits below, each attributed to the product that says it.

  • One control — “access to production requires MFA and is reviewed quarterly” — satisfies a SOC 2 criterion, an ISO 27001 Annex A control, a HIPAA safeguard and a PCI requirement simultaneously.

    — Pillar 01 — The Compliance Operating System
  • A readiness dashboard can read 98% while the auditor’s fieldwork disagrees, because completion percentage is not evidence quality.

    — Pillar 01 — The Compliance Operating System
  • Covers SOC 2 Type I and II, ISO 27001, HIPAA, PCI DSS v4.0.1, CMMC 2.0, DORA and NIS2, plus the 2026 AI-governance layer.

    — Pillar 01 — The Compliance Operating System
  • 2026 is the first assessment year with no grace argument — PCI DSS v4.0.1 is the only active version and all 51 future-dated requirements have been mandatory since 31 March 2025.

    — PCI DSS for Healthcare Kit
  • A patient portal that embeds the gateway’s JavaScript is SAQ A-EP, whatever the vendor deck said. 6.4.3 and 11.6.1 were pulled from SAQ A in January 2025 and replaced with an eligibility criterion.

    — PCI DSS for Healthcare Kit
  • Roughly 70% of PCI’s controls are already the HIPAA Security Rule’s — and the HIPAA proposed rule moves toward PCI, not away.

    — PCI DSS for Healthcare Kit
  • Your billing company is both a service provider and a business associate. So is the gateway, the EHR payment module and the IVR vendor — collect the AOC, the BAA and the annual verification together.

    — PCI DSS for Healthcare Kit
  • When an incident touches PHI and cardholder data at once, the HIPAA and PCI clocks run in parallel with different triggers and different audiences — computed here from a single discovery time.

    — PCI DSS for Healthcare Kit
  • All PCI DSS v4.0 requirements became fully mandatory on 31 March 2025.

    — PCI DSS v4.0.1 Readiness Accelerator
  • A focused view of the 51 future-dated requirements that became mandatory in March 2025, each with a plain-English “what it requires” and an effort estimate.

    — PCI DSS v4.0.1 Readiness Accelerator

Kits that cover it

3 products, cheapest first.

Bundles

4 bundles cover this alongside adjacent work — always below the sum of the parts.

Other regimes: EU AI Act · HIPAA · DORA & NIS2 · Third-party risk · Critical infrastructure · Post-quantum

Working to a date? The compliance calendar. Not legal advice.