Skip to contentSkip to content
Knowledge Hub

All 12 PCI DSS v4.0.1 Requirements Explained

The definitive reference for every PCI requirement — control intent, merchant responsibilities, and audit evidence.

12 Requirements|6 Domains|PCI DSS v4.0.1 Accurate

Frequently Asked Questions

How many requirements are in PCI DSS v4.0.1?
PCI DSS v4.0.1 has 12 principal requirements organised across 6 goals: Build and Maintain a Secure Network, Protect Account Data, Maintain a Vulnerability Management Program, Implement Strong Access Control, Regularly Monitor and Test Networks, and Maintain an Information Security Policy.
What is the difference between PCI DSS 3.2.1 and 4.0.1?
PCI DSS 4.0.1 introduces 64 new requirements, the customised approach methodology, targeted risk analysis, and enhanced authentication requirements including MFA for all CDE access. Many changes became mandatory on March 31, 2025.
Which PCI requirements apply to my business?
The applicable requirements depend on your SAQ type. SAQ A merchants need only a subset of requirements, while SAQ D merchants and service providers must comply with all 12 requirements. Use our SAQ Decision Engine to determine your type.
What are the 6 goals of PCI DSS?
The 6 goals are: (1) Build and Maintain a Secure Network and Systems, (2) Protect Account Data, (3) Maintain a Vulnerability Management Program, (4) Implement Strong Access Control Measures, (5) Regularly Monitor and Test Networks, (6) Maintain an Information Security Policy.