Regulation

PCI DSS v4.0.1

PCI DSS v4.0.1

12 requirements · 10 connected unified controls

Open PCI DSS v4.0.1 in the map
Version
v4.0.1
Published
2024-06-11
Effective
2025-03-31 (future-dated requirements)
Amendments
v4.0 retired 2024-12-31

Requirements and control mappings

“Full” and “Partial” describe the catalog mapping to a unified control. A partial mapping includes the remaining requirement. These mappings do not establish an organization’s implementation or certification.

PCI DSS v4.0.1

RequirementUnified control and mapping
PCI-Req1Install and maintain network security controls
UC-CONFIG-01 — Harden systems to approved secure configuration baselinesPartial

Remaining requirement: also mandates dedicated network security controls and periodic ruleset reviews

PCI-Req2Apply secure configurations to all system components
PCI-Req3Protect stored account data
UC-CRYPTO-01 — Encrypt data at rest and in transitPartial

Remaining requirement: key-management requirements (3.6-3.7) satisfied by the key lifecycle control; SAD-not-stored-after-authorization (3.3) and PAN display masking (3.4) also fall outside this control's scope

PCI-Req4Protect cardholder data with strong cryptography during transmission over open, public networks
PCI-Req5Protect all systems and networks from malicious software
PCI-Req6Develop and maintain secure systems and software
UC-CONFIG-04 — Build security and privacy into software design and upkeepPartial

Remaining requirement: also requires protections for public-facing web applications

PCI-Req7Restrict access to system components and cardholder data by business need to know
UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of dutiesPartial

Remaining requirement: semiannual review of all user accounts and privileges (7.2.4) not covered

PCI-Req8Identify users and authenticate access to system components
UC-ACCESS-09 — Authenticate all users with multi-factor authenticationPartial

Remaining requirement: account lockout and idle timeout satisfied by session/logon controls; credential lifecycle parameters (8.3.5-8.3.9), MFA implementation integrity (8.5), and shared/system/application account controls (8.2.2, 8.6) satisfied by companion credential- and account-management controls

PCI-Req9Restrict physical access to cardholder data
UC-ASSET-04 — Control storage media through use, storage, and destructionPartial

Remaining requirement: media lifecycle (9.4) is covered; facility entry controls and personnel/visitor access management (9.2-9.3) satisfied by physical-access companion controls; POI terminal anti-tampering and periodic inspection (9.5) not covered by this control

PCI-Req10Log and monitor all access to system components and cardholder data
UC-LOG-01 — Log security-relevant events across all systemsPartial

Remaining requirement: also requires daily review, 12-month retention, time synchronization, log protection

PCI-Req11Test security of systems and networks regularly
UC-VULN-02 — Test security through independent penetration exercisesPartial

Remaining requirement: also requires quarterly vulnerability scans, intrusion detection, and change-detection mechanisms

PCI-Req12Support information security with organizational policies and programs
UC-GOV-14 — Establish and maintain approved security policies and proceduresPartial

Remaining requirement: also requires awareness, screening, third-party management, and incident response program elements