The Payment Card Industry Security Standards Council (PCI SSC) has made public version 4.0 of the PCI Data Security Standard(PCI DSS). As part of the release of this new version, we wanted to provide you with a few data points to help you manage its implementation. Based on dates provided by the PCI SSC, the current release schedule for v4.0 is:
Sikich plans to hold several training sessions to discuss the deltas between versions 3.2.1 and 4.0. Where necessary, we will also hold sessions with your team to discuss the impact that these changes may have on your environment and compliance programs.
As part of the migration to version 4.0, your organization will be provided transition periods in which to implement new requirements and, in some cases, additional time is provided for net new controls.
In the coming weeks, we will take an opportunity to discuss changes to the PCI DSS with you to help you understand how it will impact your organization. To aid in the transition from PCI DSS v3.2.1. to v4.0, Sikich plans to propose the following audit schedule for all of its clients:
To support you in this transition, Sikich plans to:
We will continue to work with the PCI SSC to understand any impacting changes and communicate this information as soon as we become aware of it. Should you or your team have any immediate questions, please do not hesitate to reach out to your Qualified Security Assessor (QSA) or myself.
This publication contains general information only and Sikich is not, by means of this publication, rendering accounting, business, financial, investment, legal, tax, or any other professional advice or services. This publication is not a substitute for such professional advice or services, nor should you use it as a basis for any decision, action or omission that may affect you or your business. Before making any decision, taking any action or omitting an action that may affect you or your business, you should consult a qualified professional advisor. In addition, this publication may contain certain content generated by an artificial intelligence (AI) language model. You acknowledge that Sikich shall not be responsible for any loss sustained by you or any person who relies on this publication.