What changed in v4.0.1
The PCI Council retired v3.2.1 in March 2024 and made every "future-dated" v4.0 requirement mandatory on 31 March 2025. Acquirers across the GCC now expect evidence of the new controls — including targeted risk analyses, customised approach worksheets, and phishing-resistant MFA on cardholder-data environments.
The toolkit covers
- Scoping worksheet for SAQ A, SAQ A-EP and SAQ D
- Targeted Risk Analysis (TRA) template for Req 12.3.1
- Customised Approach Objective (CAO) worksheet for any tailored control
- Network-segmentation evidence pack
- Page-integrity monitoring runbook for e-commerce (Req 6.4.3 / 11.6.1)
Section 1 — Confirm your SAQ
| If you... | Use |
|---|---|
| Fully outsource e-commerce to a PCI-validated provider | SAQ A |
| Host the payment page but redirect to a provider | SAQ A-EP |
| Store, process or transmit cardholder data | SAQ D |
Section 2 — The 13 v4.0.1 requirements most teams miss
- 6.4.3 — Inventory of payment-page scripts with authorisation evidence
- 8.3.6 — Password length minimum increased to 12 characters
- 8.4.2 — MFA on all access into the CDE, including admins
- 8.5.1 — Phishing-resistant MFA for service providers
- 10.4.1.1 — Automated log review using a SIEM, not weekly spot-checks
- 11.3.1.1 — Authenticated internal vulnerability scans
- 11.4.7 — Multi-tenant penetration test segmentation
- 11.5.1.1 — Intrusion-detection on internal segments
- 11.6.1 — Tamper-detection on payment pages
- 12.3.1 — Targeted risk analysis for every flexible control
- 12.3.3 — Cryptographic cipher inventory reviewed annually
- 12.5.2.1 — Scope confirmation every six months for service providers
- 12.10.7 — Incident response when stored PAN is found outside the CDE
Section 3 — Evidence pack
For every requirement, capture: control owner, policy reference, technical artefact, last test date, residual risk.
Next step
MAST QSAs run a one-day v4.0.1 gap clinic across the UAE and India. Book a clinic and we will bring this toolkit pre-populated for your environment.