---
title: "Preparing for PCI DSS 4.0: Five Steps to Get Financial Institutions Ready"
description: Discover essential steps to ensure compliance with PCI DSS 4.0 for financial institutions. Get ready efficiently with expert guidance
image: https://insights.comforte.com/hubfs/comforte%20AG_Preparing%20for%20PCI%20DSS%204.0_Five%20Steps_15.02.png
---

[![Hubspot_blog_logo](https://insights.comforte.com/hs-fs/hubfs/Hubspot_blog_logo.png?width=295&name=Hubspot_blog_logo.png)](http://www.comforte.com)

[![Subscribe](https://no-cache.hubspot.com/cta/default/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0)

[![comforte AG - Preparing for PCI DSS 4.0: Five Steps to Get Financial Institutions Ready](https://insights.comforte.com/hubfs/comforte%20AG_Preparing%20for%20PCI%20DSS%204.0_Five%20Steps_15.02.png)](https://insights.comforte.com/preparing-for-pci-dss-4.0-five-steps-to-get-financial-institutions-ready)

[Erfan Shadabi](https://insights.comforte.com/author/erfan-shadabi) l Feb 15, 2024 l [Data Protection](https://insights.comforte.com/tag/data-protection), [Compliance](https://insights.comforte.com/tag/compliance), [Financial Services](https://insights.comforte.com/tag/financial-services)

# Preparing for PCI DSS 4.0: Five Steps to Get Financial Institutions Ready

For two decades, payments security industry body the [PCI Security Standards Council](https://www.pcisecuritystandards.org/) (PCI SSC) has demanded compliance with an ever-growing set of rigorous technical and operational requirements in order to protect cardholder data. [PCI DSS 4.0](https://www.pcisecuritystandards.org/about_us/press_releases/pr_03312022) is the biggest update to its payment card industry data security standard since its inception in 2004. It applies to any organization that accepts, processes, stores or transmits card data—which means most financial institutions.

But with so much on their to-do list, what should financial services firms prioritize to accelerate compliance before the 1 April 2025 deadline?

## What’s new in PCI DSS 4.0?                                                  

PCI DSS 4.0 was designed to move with the times—not an easy feat in a world where threat actor innovation is moving as fast as enterprise digital transformation. That’s why it introduces a series of new requirements designed to ensure complying banks are as secure as they can be. In fact, the banking industry is a prime target for data breaches, given the huge quantity of card details and personally identifiable information (PII) it stores. According [to one recent study](https://www.kroll.com/en/insights/publications/cyber/data-breach-outlook-2024), the sector was the most breached in 2023, overtaking healthcare with over a quarter (27%) of recorded incidents.

In this context, some of the [key changes](https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v3-2-1-to-v4-0-Summary-of-Changes-r2.pdf?agreement=true&time=1648825820031) from the previous PCI DSS iteration are:

1. A larger range of acceptable network security controls that can be used instead of firewalls
2. A new requirement to deploy multi-factor authentication (MFA) for access into the cardholder data environment (CDE)
3. Greater flexibility in demonstrating compliance with security objectives
4. New targeted risk analyses, designed to give complying organizations more flexibility in how frequently they perform certain activities

With a mission to keep pace with the ever-changing card industry, technology and threat landscape, PCI DSS 4.0 was designed to:

1. Provide greater flexibility in the technologies organizations can use to achieve compliance
2. Promote continuous security, rather than treating compliance/security as a tick-box endeavor
3. Enhance validation methods and procedures

## Five steps to get started

There are over 50 new requirements in PCI DSS 4.0. Some will be easier to meet than others. To get started, consider the following:

1. **Perform a readiness assessment**  
   Get an in-house or third-party expert to assess the scope of the organization’s PCI DSS compliance program, and check if it’s correct. Anything done at this stage to reduce the scope (like removing unnecessary hardware/software components) will also help to reduce cost and minimize attack surface. This initial process should identify any gaps and deliver a roadmap for compliance.
2. **Update training and awareness programs**  
   Many organizations forget that a critical component of PCI DSS success is its people. Staff need to be regularly updated on the latest security threats and how to identify and handle them. That’s because each passing month, threat actors devise new ways to compromise CDEs. Training lessons should include real-world attack simulations and be fairly short (10-15 minutes), but frequent.
3. **Develop the right policies and procedures**  
   This is perhaps the most important step, as policy is the bedrock of any compliance strategy. It will require documenting a set of written procedures that explain how the organization manages its CDE. Include information security, incident response and user awareness and training as a starting point.
4. **Get granular with technical controls**  
   PCI DSS 4.0 is highly granular in its required technical controls. There will also be some updates in there from previous versions, like MFA, anti-phishing procedures, authenticating internal vulnerability scanning, and anti-e-skimming measures. Remember: the devil’s in the detail.
5. **Perform continuous monitoring**  
   PCI DSS 4.0 is all about security as a continuous process rather than a point-in-time compliance play. One of the best ways to achieve this is through continuous monitoring of security controls and of the CDE. The former will assess and flag any non-performant controls for remediation, while the latter will ensure any new data appearing in the CDE is automatically protected.

Consider comforte’s [Data Security Platform](https://www.comforte.com/data-security) here. It uses AI technology to automatically discover, classify and protect (in line with policy) any sensitive data, wherever it is being stored across the organization—including in cloud environments. This is essential given the increasingly distributed nature of banking IT infrastructure today, and the rigorous requirements of PCI DSS 4.0.

## In it for the long term

As always, the effort needed to attain PCI DSS compliance will be significant. But so will the rewards. This is not just about mitigating the risk of major compliance fines. It is about building a more secure enterprise data environment. That will stand the organization in good stead not just with the PCI SSC, but other regulations—from GDPR to CCPA and beyond.

---

| Share this:  | [![LinkedIn](https://insights.comforte.com/hubfs/Social%20Icons/linkedin%20icon.png)](https://www.linkedin.com/shareArticle?mini=true&url=https://insights.comforte.com/preparing-for-pci-dss-4.0-five-steps-to-get-financial-institutions-ready&utm_medium=social&utm_source=linkedin) | [![Bluesky](https://insights.comforte.com/hubfs/Social%20Icons/bluesky_logo.png)](https://bsky.app/intent/compose?url=https://insights.comforte.com/preparing-for-pci-dss-4.0-five-steps-to-get-financial-institutions-ready&utm_medium=social&utm_source=Bluesky) | ![Twitter](https://insights.comforte.com/hubfs/Social%20Icons/twitter_x_logo-1.png) | [![XING](https://insights.comforte.com/hubfs/Social%20Icons/xing-color2.png)](https://www.xing.com/spi/shares/new?url=https://insights.comforte.com/preparing-for-pci-dss-4.0-five-steps-to-get-financial-institutions-ready&utm_medium=social&utm_source=xing) | [![Email](https://insights.comforte.com/hubfs/Social%20Icons/email%20icon.png)](mailto:?subject=Check%20out%20https://insights.comforte.com/preparing-for-pci-dss-4.0-five-steps-to-get-financial-institutions-ready&utm_medium=social&utm_source=email%20&body=Check%20out%20https://insights.comforte.com/preparing-for-pci-dss-4.0-five-steps-to-get-financial-institutions-ready&utm_medium=social&utm_source=email) |
| --- | --- | --- | --- | --- | --- |

## Case Study: City Fresko achieves PCI-DSS compliance with tokenization

Click the button below to download the case study:

[![Download Case Study](https://no-cache.hubspot.com/cta/default/4026697/674e5f21-2dd7-4c72-87f7-7c0511122eb9.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/674e5f21-2dd7-4c72-87f7-7c0511122eb9)

### Related posts

![Reuse, Reward: How Banks Can Safely Unlock the Value of Their Data](https://insights.comforte.com/hubfs/comforte%20AG_%20Reuse%20Reward_%20How%20Banks%20Can%20Safely%20Unlock%20the%20Value%20of%20Their%20Data_03.2025.png)

 Mar 12, 2026 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Payments Transformation](https://insights.comforte.com/tag/payments-transformation) , [Business Value](https://insights.comforte.com/tag/business-value)

### [Reuse, Reward: How Banks Can Safely Unlock the Value of Their Data](https://insights.comforte.com/reuse-reward-how-banks-can-safely-unlock-the-value-of-their-data?hsLang=en)

The financial world is awash with data. But too few organizations are able to use it effectively. In [Bank Director’s *2025 Technology Survey*](https://www.bankdirector.com/wp-content/uploads/2025/09/2025TechReport-OpenVersion.pdf), one-third of US banking leaders cite an inability to harness data as a top technology challenge facing their...

[Read more](https://insights.comforte.com/reuse-reward-how-banks-can-safely-unlock-the-value-of-their-data?hsLang=en)

![Delivering a Secure, Trusted Foundation for Cloud Growth at LGT](https://insights.comforte.com/hubfs/comforte%20AG_Delivering%20a%20Secure%2c%20Trusted%20Foundation%20for%20Cloud%20Growth%20at%20LGT_01.2026.png)

 Jan 15, 2026 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Business Value](https://insights.comforte.com/tag/business-value)

### [Delivering a Secure, Trusted Foundation for Cloud Growth at LGT](https://insights.comforte.com/delivering-a-secure-trusted-foundation-for-cloud-growth-at-lgt?hsLang=en)

There’s a world of difference between retail and private banking. While the former is transactional and focused on the mass market, the latter is built on trust and personal relationships. That trust can be hard won, but is easily lost, especially...

[Read more](https://insights.comforte.com/delivering-a-secure-trusted-foundation-for-cloud-growth-at-lgt?hsLang=en)

![Top Indicators You Have a Cybersecurity Problem—and What to Do About It](https://insights.comforte.com/hubfs/comforte%20AG_Top%20Indicators%20You%20Have%20a%20Cybersecurity%20Problem_and%20What%20to%20Do%20About%20It.png)

 May 22, 2025 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Digital Enablement](https://insights.comforte.com/tag/digital-enablement)

### [Top Indicators You Have a Cybersecurity Problem—and What to Do About It](https://insights.comforte.com/top-indicators-you-have-a-cybersecurity-problem-and-what-to-do-about-it?hsLang=en)

Data is both blessing and curse to the modern enterprise. Yes, when analyzed effectively it can surface intelligence to improve decision making, customer engagement, process efficiency and, ultimately, drive revenue. But it also represents a major...

[Read more](https://insights.comforte.com/top-indicators-you-have-a-cybersecurity-problem-and-what-to-do-about-it?hsLang=en)

### Service

- [Contact](https://www.comforte.com/contact/)
- [About us](https://www.comforte.com/company/)
- [Blog](https://insights.comforte.com/)
- [Press Releases](https://www.comforte.com/company/press-releases/)
- [Career](https://www.comforte.com/company/career/)
- [Resources](https://www.comforte.com/resources/)

### Germany

comforte AG  
Abraham-Lincoln-Str. 22   
65189 Wiesbaden  
Germany

Phone: + 49 611 93199 00  
Fax: + 49 611 93199 05

### Australia

comforte PTY  
Suite 20, 1 Rivett Road  
North Ryde  
NSW 2113  
Australia

Postal Address:   
PO Box 1710  
Lane Cove  
NSW 1595  
Australia

Phone: +61 2 8197 0272

### USA

comforte Inc.  
30 Wall Street, 8th Floor  
New York, NY 10005-2205  
USA

Phone: +1-646-438-5716

### Singapore

comforte Asia Pte. Ltd.   
1 Raffles Place, #19-61 Tower 2   
Singapore 048616

Phone: +65 6808 5507

- [Sitemap](https://www.comforte.com/sitemap/)
- [Legal Notice](https://www.comforte.com/legal-notice/)
- [Privacy Policy](https://www.comforte.com/privacy-policy/)

© comforte AG 2026

<https://x.com/comforteag> <https://www.youtube.com/c/comforte-ag> <https://www.linkedin.com/company/comforte-ag/>