---
title: Streamlining PCI DSS 4.0 Compliance for IBM Z Series Customers
description: IBM Z Series customers face unique challenges in complying with PCI DSS 4.0 due to their complex IT environments. comforte's data-centric security solutions, including SecureDPS, offer a streamlined approach to data discovery, classification, and protection.
image: https://insights.comforte.com/hubfs/comforte%20AG_Streamlining%20PCI%20DSS%204.0%20Compliance%20for%20IBM%20Z%20Series%20Customers.png
---

[![Hubspot_blog_logo](https://insights.comforte.com/hs-fs/hubfs/Hubspot_blog_logo.png?width=295&name=Hubspot_blog_logo.png)](http://www.comforte.com)

[![Subscribe](https://no-cache.hubspot.com/cta/default/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0)

[![comforte AG - Streamlining PCI DSS 4.0 Compliance for IBM Z Series Customers](https://insights.comforte.com/hubfs/comforte%20AG_Streamlining%20PCI%20DSS%204.0%20Compliance%20for%20IBM%20Z%20Series%20Customers.png)](https://insights.comforte.com/streamlining-pci-dss-4.0-compliance-for-ibm-z-series-customers)

[Thomas Stoesser](https://insights.comforte.com/author/thomas-stoesser) l May 15, 2025 l [Data Protection](https://insights.comforte.com/tag/data-protection), [Compliance](https://insights.comforte.com/tag/compliance)

# Streamlining PCI DSS 4.0 Compliance for IBM Z Series Customers

IBM Z Series customers traditionally include some of the world’s biggest financial services and retail companies. This puts them firmly in the crosshairs of the Payment Card Industry Data Security Standard (PCI DSS). Yet while compliance can be onerous for smaller businesses, the challenges are often multiplied for those storing, processing and/or transmitting huge volumes of cardholder data (CHD).

Fortunately, comforte has the technology and know-how to reduce the scope and cost of PCI DSS compliance, and help IBM customers to adapt to the new regulatory regime.

## What’s new in PCI DSS 4.0?

PCI DSS was originally a card industry response to the growing threat to CHD posed by cyber-thieves, and the knock-on impact of rising card fraud levels. Those threats have continued to evolve and grow over the years since the standard was first launched back in 2004. Fed by an [infostealer epidemic,](https://insights.comforte.com/how-infostealers-are-creating-a-data-breach-epidemic?hsLang=en) the cybercrime underground is awash with personal data, including logins that adversaries can use to access sensitive corporate systems *en route* to data stores. And card fraud losses [were predicted](https://www.emarketer.com/content/spotlight-us-card-payment-fraud-losses-forecast-2022) to hit $13.8bn by the end of 2024.

PCI DSS 4.0 is the card industry’s response. It’s designed to offer more flexibility on the one hand, while also mandating retailers, financial institutions and others to tighten up security in other areas. The new version introduces dozens of new requirements, summarized [neatly here](https://listings.pcisecuritystandards.org/documents/PCI-DSS-v3-2-1-to-v4-0-Summary-of-Changes-r1.pdf). But some of the main areas of change include:

**A new “customized approach”** option which allows organizations to implement security controls in a way that best suits their technology set up and risk profile.

**Tighter rules on vulnerability remediation** so that firms manage all “applicable vulnerabilities” that they find via scans (not just those ranked as high-risk or critical).

**Stronger authentication** including multi-factor authentication (MFA) for access to cardholder data environments (CDEs).

**Stronger encryption** of CHD, even on trusted networks.

**Improved security awareness training** for all staff.

**Targeted risk assessments** to identify and remediate vulnerabilities. 

**More rigorous testing** of security controls.

## Mainframe challenges

IBM Z Series customers may have chosen the mainframe brand in part because of its superior built-in security capabilities. But there are still going to be some potential bumps in the road when complying with PCI DSS 4.0. Mainframe technology requires a specific set of skills which many organizations may find are increasingly in short supply. Aside from this they may have to manage:

- Sprawling, heterogeneous environments featuring legacy applications, in which it may be challenging to deploy modern security controls
- Specialized security configurations that must be updated in line with PCI DSS 4.0
- Diverse, interconnected systems spread across the mainframe and cloud, making it more challenging to track down and protect all CHD, and even to define the CDE

## Leading the way with comforte

Fortunately, comforte has plenty of experience with PCI DSS compliance, and is a long-time partner of IBM. Our [data-centric security approach](https://insights.comforte.com/safeguarding-data-security-and-privacy-on-ibm-mainframe-a-comprehensive-approach?hsLang=en) aligns closely with the standard, while our SecureDPS solution empowers z-Series customers to continually discover and classify data and apply strong data protection (eg format-preserving tokenization).

In summary, comforte offers IBM Z Series:

- Seamlessly integrated data protection capabilities built for demanding IT environments
- A potential way to reduce the cost and scope of PCI DSS compliance (by tokenizing data)
- Utility of data (eg for use in analytics) without compromising on security or compliance

One of the key motivations behind PCI DSS 4.0 was to encourage complying organizations to think of security as a continuous process—a journey characterized by best practice, rather than a destination reached by ticking boxes and buying point solutions. With our continuous approach to data discovery, classification and protection, that is 100% the comforte way.

---

| Share this:  | [![LinkedIn](https://insights.comforte.com/hubfs/Social%20Icons/linkedin%20icon.png)](https://www.linkedin.com/shareArticle?mini=true&url=https://insights.comforte.com/streamlining-pci-dss-4.0-compliance-for-ibm-z-series-customers&utm_medium=social&utm_source=linkedin) | [![Bluesky](https://insights.comforte.com/hubfs/Social%20Icons/bluesky_logo.png)](https://bsky.app/intent/compose?url=https://insights.comforte.com/streamlining-pci-dss-4.0-compliance-for-ibm-z-series-customers&utm_medium=social&utm_source=Bluesky) | ![Twitter](https://insights.comforte.com/hubfs/Social%20Icons/twitter_x_logo-1.png) | [![XING](https://insights.comforte.com/hubfs/Social%20Icons/xing-color2.png)](https://www.xing.com/spi/shares/new?url=https://insights.comforte.com/streamlining-pci-dss-4.0-compliance-for-ibm-z-series-customers&utm_medium=social&utm_source=xing) | [![Email](https://insights.comforte.com/hubfs/Social%20Icons/email%20icon.png)](mailto:?subject=Check%20out%20https://insights.comforte.com/streamlining-pci-dss-4.0-compliance-for-ibm-z-series-customers&utm_medium=social&utm_source=email%20&body=Check%20out%20https://insights.comforte.com/streamlining-pci-dss-4.0-compliance-for-ibm-z-series-customers&utm_medium=social&utm_source=email) |
| --- | --- | --- | --- | --- | --- |

## Free 30-Day Health Check for Sensitive Payment Data 

Accelerate PCI Compliance with Automatic Discovery and Classification of PANs and Cardholder Data

[![Start Your Free Trial Today](https://no-cache.hubspot.com/cta/default/4026697/b524802b-4c2a-4a07-8630-c282723556aa.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/b524802b-4c2a-4a07-8630-c282723556aa)

### Related posts

![Reuse, Reward: How Banks Can Safely Unlock the Value of Their Data](https://insights.comforte.com/hubfs/comforte%20AG_%20Reuse%20Reward_%20How%20Banks%20Can%20Safely%20Unlock%20the%20Value%20of%20Their%20Data_03.2025.png)

 Mar 12, 2026 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Payments Transformation](https://insights.comforte.com/tag/payments-transformation) , [Business Value](https://insights.comforte.com/tag/business-value)

### [Reuse, Reward: How Banks Can Safely Unlock the Value of Their Data](https://insights.comforte.com/reuse-reward-how-banks-can-safely-unlock-the-value-of-their-data?hsLang=en)

The financial world is awash with data. But too few organizations are able to use it effectively. In [Bank Director’s *2025 Technology Survey*](https://www.bankdirector.com/wp-content/uploads/2025/09/2025TechReport-OpenVersion.pdf), one-third of US banking leaders cite an inability to harness data as a top technology challenge facing their...

[Read more](https://insights.comforte.com/reuse-reward-how-banks-can-safely-unlock-the-value-of-their-data?hsLang=en)

![Delivering a Secure, Trusted Foundation for Cloud Growth at LGT](https://insights.comforte.com/hubfs/comforte%20AG_Delivering%20a%20Secure%2c%20Trusted%20Foundation%20for%20Cloud%20Growth%20at%20LGT_01.2026.png)

 Jan 15, 2026 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Business Value](https://insights.comforte.com/tag/business-value)

### [Delivering a Secure, Trusted Foundation for Cloud Growth at LGT](https://insights.comforte.com/delivering-a-secure-trusted-foundation-for-cloud-growth-at-lgt?hsLang=en)

There’s a world of difference between retail and private banking. While the former is transactional and focused on the mass market, the latter is built on trust and personal relationships. That trust can be hard won, but is easily lost, especially...

[Read more](https://insights.comforte.com/delivering-a-secure-trusted-foundation-for-cloud-growth-at-lgt?hsLang=en)

![Top Indicators You Have a Cybersecurity Problem—and What to Do About It](https://insights.comforte.com/hubfs/comforte%20AG_Top%20Indicators%20You%20Have%20a%20Cybersecurity%20Problem_and%20What%20to%20Do%20About%20It.png)

 May 22, 2025 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Digital Enablement](https://insights.comforte.com/tag/digital-enablement)

### [Top Indicators You Have a Cybersecurity Problem—and What to Do About It](https://insights.comforte.com/top-indicators-you-have-a-cybersecurity-problem-and-what-to-do-about-it?hsLang=en)

Data is both blessing and curse to the modern enterprise. Yes, when analyzed effectively it can surface intelligence to improve decision making, customer engagement, process efficiency and, ultimately, drive revenue. But it also represents a major...

[Read more](https://insights.comforte.com/top-indicators-you-have-a-cybersecurity-problem-and-what-to-do-about-it?hsLang=en)

### Service

- [Contact](https://www.comforte.com/contact/)
- [About us](https://www.comforte.com/company/)
- [Blog](https://insights.comforte.com/)
- [Press Releases](https://www.comforte.com/company/press-releases/)
- [Career](https://www.comforte.com/company/career/)
- [Resources](https://www.comforte.com/resources/)

### Germany

comforte AG  
Abraham-Lincoln-Str. 22   
65189 Wiesbaden  
Germany

Phone: + 49 611 93199 00  
Fax: + 49 611 93199 05

### Australia

comforte PTY  
Suite 20, 1 Rivett Road  
North Ryde  
NSW 2113  
Australia

Postal Address:   
PO Box 1710  
Lane Cove  
NSW 1595  
Australia

Phone: +61 2 8197 0272

### USA

comforte Inc.  
30 Wall Street, 8th Floor  
New York, NY 10005-2205  
USA

Phone: +1-646-438-5716

### Singapore

comforte Asia Pte. Ltd.   
1 Raffles Place, #19-61 Tower 2   
Singapore 048616

Phone: +65 6808 5507

- [Sitemap](https://www.comforte.com/sitemap/)
- [Legal Notice](https://www.comforte.com/legal-notice/)
- [Privacy Policy](https://www.comforte.com/privacy-policy/)

© comforte AG 2026

<https://x.com/comforteag> <https://www.youtube.com/c/comforte-ag> <https://www.linkedin.com/company/comforte-ag/>