The Payment Card Industry Security Standards Council (PCI SSC) recently announced an updated release schedule for version 4.0 for the PCI Data Security Standard (PCI DSS):
History suggests that, after the public release of PCI DSS v.4.0, there will be a transition period of approximately 18 months. During this period, organizations will have the option of being assessed against either PCI DSS v.3.2.1 or v.4.0. This would make PCI DSS v4.0 required for all relevant organizations at some point early in the third quarter of 2023.
In addition to the transition period, it seems likely that new requirements will have deferred implementation dates, as such an approach has been common across all major updates to the PCI DSS over the years. If this turns out to be the case, organizations can likely expect that any future-dated requirements will not need to be fully implemented until sometime between September 2024 and March 2025. Until then, those requirements will be considered best practices. Of course, these estimates are only based on past experiences and may change as more information is released by the PCI SSC.
One last timing note is that QSAs and Internal Security Assessors (ISAs) will be required to take additional training before being able to assess organizations against PCI DSS v.4.0. The first planned training is set for June 2022.
As we continue to learn more about the next release of the PCI DSS, we will do our best to share what we are able to, so check back often. If you have any questions about the PCI DSS transition process, please reach out to our team.
This publication contains general information only and Sikich is not, by means of this publication, rendering accounting, business, financial, investment, legal, tax, or any other professional advice or services. This publication is not a substitute for such professional advice or services, nor should you use it as a basis for any decision, action or omission that may affect you or your business. Before making any decision, taking any action or omitting an action that may affect you or your business, you should consult a qualified professional advisor. In addition, this publication may contain certain content generated by an artificial intelligence (AI) language model. You acknowledge that Sikich shall not be responsible for any loss sustained by you or any person who relies on this publication.
About the Author
Kyle Hinterberg
Kyle is a Consultant at Sikich. Having previously spent time as a Payment Card Industry subject matter expert for a Fortune 400 organization, he has experience beyond consulting that includes vulnerability management, systems administration, networking, programming, end-user support, policy creation, and data governance. Thanks to his hands-on work in IT, Kyle is familiar with a wide range of operating systems, hardware, software and programming languages, which allows him to offer valuable insight to any client, especially those looking to implement scope reduction or data devaluation. Kyle has a Bachelor of Science degree in Information and Communication Technologies and is a Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Payment Card Industry Qualified Security Assessor (QSA) and Payment Card Industry Professional (PCIP).
Sign up for Insights
Join 14,000+ Business executives and decision makers.
Latest Insights
Microsoft Fabric
Microsoft Fabric for Dynamics 365: What you need to know
December 4, 2025
Dynamics 365>Dynamics 365 Finance and Supply Chain Management
Driving efficiency: How Microsoft Dynamics 365 F&SCM out...
December 3, 2025
Security
Why Windows Hello Is More Secure Than You Think: A Defense a...
December 2, 2025
QMS
Accelerating QMS Implementations with CSA, Automation, and A...
December 1, 2025
Information Technology
Phishing Simulations: Why Regular Testing Improves Cyber Res...
November 25, 2025
Information Technology
How Law Firms Can Protect Client Confidentiality in a Digita...
November 24, 2025
Information Technology
The Critical Role of Automation Tools in Endpoint Management...
November 21, 2025
Managed Services
Give Your Identity Strategy the Gift of a Year-End Review
November 20, 2025
QMS
Navigating Generative AI in Life Sciences QMS: Opportunities...
November 19, 2025