PCI DSS v4.0.1 — no grace argument left
All 51 future-dated v4.0.1 requirements became mandatory on 31 March 2025, so 2026 is the first assessment year with nothing to defer. The January 2025 SAQ A revision is the trap: requirements 6.4.3 and 11.6.1 were removed and replaced with an eligibility criterion, and a site that embeds a gateway’s JavaScript on its payment page is SAQ A-EP whatever the vendor said.
Key dates
2 dated obligations. Rows marked verify are not final in their source. See the whole calendar.
What practitioners need to know
Lifted verbatim from the kits below, each attributed to the product that says it.
-
One control — “access to production requires MFA and is reviewed quarterly” — satisfies a SOC 2 criterion, an ISO 27001 Annex A control, a HIPAA safeguard and a PCI requirement simultaneously.
— Pillar 01 — The Compliance Operating System -
A readiness dashboard can read 98% while the auditor’s fieldwork disagrees, because completion percentage is not evidence quality.
— Pillar 01 — The Compliance Operating System -
Covers SOC 2 Type I and II, ISO 27001, HIPAA, PCI DSS v4.0.1, CMMC 2.0, DORA and NIS2, plus the 2026 AI-governance layer.
— Pillar 01 — The Compliance Operating System -
2026 is the first assessment year with no grace argument — PCI DSS v4.0.1 is the only active version and all 51 future-dated requirements have been mandatory since 31 March 2025.
— PCI DSS for Healthcare Kit -
A patient portal that embeds the gateway’s JavaScript is SAQ A-EP, whatever the vendor deck said. 6.4.3 and 11.6.1 were pulled from SAQ A in January 2025 and replaced with an eligibility criterion.
— PCI DSS for Healthcare Kit -
Roughly 70% of PCI’s controls are already the HIPAA Security Rule’s — and the HIPAA proposed rule moves toward PCI, not away.
— PCI DSS for Healthcare Kit -
Your billing company is both a service provider and a business associate. So is the gateway, the EHR payment module and the IVR vendor — collect the AOC, the BAA and the annual verification together.
— PCI DSS for Healthcare Kit -
When an incident touches PHI and cardholder data at once, the HIPAA and PCI clocks run in parallel with different triggers and different audiences — computed here from a single discovery time.
— PCI DSS for Healthcare Kit -
All PCI DSS v4.0 requirements became fully mandatory on 31 March 2025.
— PCI DSS v4.0.1 Readiness Accelerator -
A focused view of the 51 future-dated requirements that became mandatory in March 2025, each with a plain-English “what it requires” and an effort estimate.
— PCI DSS v4.0.1 Readiness Accelerator
Kits that cover it
3 products, cheapest first.
Pillar 01 — The Compliance Operating System
Map controls once, satisfy every framework. A continuous, registry-driven compliance program across SOC 2, ISO 27001, HIPAA, PCI, CMMC, DORA and NIS2 — plus the ISO 42001 and EU AI Act layer most guides still omit.
PCI DSS for Healthcare Kit
Healthcare takes card payments too — and PCI is assessed separately from HIPAA by people who do not care that you have a Security Rule programme. One control set for both, the SAQ decision that vendors keep getting wrong, and the dual clock when an incident touches PHI and cardholder data at once.
PCI DSS v4.0.1 Readiness Accelerator
12-tab PCI DSS v4.0.1 workbook — all 12 requirement domains, SAQ type selector, 51 future-dated requirements tracker, e-commerce script security controls, and QSA-ready evidence register. Built for the March 2025 mandatory transition.
Bundles
4 bundles cover this alongside adjacent work — always below the sum of the parts.
Healthcare Provider Risk
The billing company holds your cardholder data and your PHI, and the MSP holds the admin rights over both. Assess the payment side and the provider that runs it. 15% off buying separately.
Healthcare Now & Next
The whole HIPAA programme, the Security Rule change coming in 2027, and the payment side neither covers. Three products across the compliance a healthcare organisation is actually assessed on. 19% off buying separately.
Federal Contractor Pack
CMMC 2.0 + NIST CSF 2.0 + PCI DSS for defense and federal contractors — built for DoD, GSA, and agency RFP responses. 19% off list.
Compliance Big 5 Bundle
SOC 2 + HIPAA + ISO 27001 + PCI DSS + CMMC 2.0 — every major compliance framework an auditor or regulator will ask about. 25% off list.
Other regimes: EU AI Act · HIPAA · DORA & NIS2 · Third-party risk · Critical infrastructure · Post-quantum
Working to a date? The compliance calendar. Not legal advice.