---
title: The PCI DSS 4.0 Deadline Has Passed, But There’s Still Time to Play Catchup
description: Stay compliant with PCI DSS 4.0. Learn key steps for protecting cardholder data and streamlining compliance processes. Discover more in our latest webinar and free 30-day trial.
image: https://insights.comforte.com/hubfs/comforte%20AG_The%20PCI%20DSS%204.0%20Deadline%20Has%20Passed_%20But%20There%E2%80%99s%20Still%20Time%20to%20Play%20Catchup.png
---

[![Hubspot_blog_logo](https://insights.comforte.com/hs-fs/hubfs/Hubspot_blog_logo.png?width=295&name=Hubspot_blog_logo.png)](http://www.comforte.com)

[![Subscribe](https://no-cache.hubspot.com/cta/default/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0)

[![comforte AG - The PCI DSS 4.0 Deadline Has Passed, But There’s Still Time to Play Catchup](https://insights.comforte.com/hubfs/comforte%20AG_The%20PCI%20DSS%204.0%20Deadline%20Has%20Passed_%20But%20There%E2%80%99s%20Still%20Time%20to%20Play%20Catchup.png)](https://insights.comforte.com/the-pci-dss-4.0-deadline-has-passed-but-theres-still-time-to-play-catchup)

[Mirza Salihagic](https://insights.comforte.com/author/mirza-salihagic) l Apr 17, 2025 l [PCI DSS](https://insights.comforte.com/tag/pci-dss), [Compliance](https://insights.comforte.com/tag/compliance)

# The PCI DSS 4.0 Deadline Has Passed, But There’s Still Time to Play Catchup

The deadline for PCI DSS 4.0 has been and gone. But it’s never too late to advance compliance plans. It’s not just about avoiding potentially large fines and other penalties. Following the standard to the letter helps ensure organizations are adhering to industry best practices, devised by some of the smartest minds in data protection. That in itself will reduce the chances of compliant enterprises falling victim to a serious data breach.

With 51 new requirements in this latest iteration of the cardholder data security standard, there’s plenty for merchant, banks and other businesses to consider. To help make sense of it all, check out the [latest comforte webinar](https://www.youtube.com/watch?v=yKKUtjhtrQA), featuring insight from former PCI Security Standards Council (SSC) VP, Jeremy King, and Forrester Principal Analyst, Heidi Shey.

## Challenges and requirements

Among the most important Control Objectives in PCI DSS 4.0 are protecting account data and implementing strong access control measures. With threat actors continuing to target misconfigured wireless networks, and even vulnerabilities in legacy encryption/authentication protocols, it’s essential that primary account numbers (PANs) are protected at rest and in transit. The standard notes that enterprises can either encrypt prior to transmission, encrypt the entire session, or both. There are also requirements around handling of key certificates.

For Forrester’s Shey, PCI DSS 4.0 could be a useful springboard to the kind of crypto agility that will be needed in the post-quantum era. Requirement 12 demands organizations monitor industry trends and emerging cryptographic vulnerabilities, inventory their algorithms and document their use.

However, part of the challenge associated with achieving these goals is not only the speed with which the technology and threat landscapes are evolving, but the resources available to compliance teams, and the complexity of their cardholder data environments (CDEs). The sheer number of on-premises and cloud servers, web applications, virtualized components, e-commerce solutions and storage systems from potentially different providers makes the discovery and mapping piece more difficult, but also more important than ever.

## Where to start

According to PCI SSC’s King, recent innovation in payments is creating an extended supply chain of providers who may need to comply with PCI DSS 4.0. Any organization that stores, processes, or transmits cardholder data and/or sensitive authentication data will need to build a compliance program.

Among the tips shared by King and Shey are:

- Begin with data discovery and classification; understanding what information you have and where it flows
- Follow data minimization principles; delete any data that has served its purpose and is no longer required. It will only increase risk and cost if retained
- Apply controls to cardholder data to ensure it is protected in line with PCI DSS 4.0 requirements, wherever it resides and wherever it flows to
- Consider tokenization as a control, as it will allow the organization to continue using data for analytics and business enablement
- Perform data discovery, classification and control stages in parallel as the CDE is too dynamic and data volumes too great to do it in stages
- Follow good “crypto housekeeping” rules when it comes to data protection
- Enforce multi-factor authentication (MFA) and least privilege for access to CDEs, and perform annual privilege checks to ensure policy remains up to date
- Consider the PCI DSS [Customized Approach](https://insights.comforte.com/compensating-controls-customized-approach-and-tokenization-in-pci-dss-4.0?hsLang=en), which offers flexibility to meet the standard’s requirements in different ways if your tech environment and circumstances demand it

For those looking for extra guidance, the PCI SSC has published a [Prioritized Approach](https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Supporting%20Document/Prioritized-Approach-For-PCI-DSS-v4_0_1.pdf) document to help organizations gain some quick wins. But be aware that compliance is no simple check-box process. It requires significant time and effort. Take a look at comforte’s new [webinar to find out more.](https://www.youtube.com/watch?v=yKKUtjhtrQA)

comforte is offering your business a 30-day free trial of comforte Data Discovery and Classification, which features a new SaaS console manager. During the period, you’ll get a close-up look at how the product works *in situ*, and obtain a detailed understanding of where security and compliance risk exists across the organization. Most importantly, you’ll be able to see how the product could help to streamline your PCI DSS 4.0 compliance processes.

*[Get in touch](https://offer.comforte.com/free-30-day-health-check-for-sensitive-payment-data?hsLang=en) today to start your free trial. We’re here to take the pain away from PCI DSS compliance.*

---

| Share this:  | [![LinkedIn](https://insights.comforte.com/hubfs/Social%20Icons/linkedin%20icon.png)](https://www.linkedin.com/shareArticle?mini=true&url=https://insights.comforte.com/the-pci-dss-4.0-deadline-has-passed-but-theres-still-time-to-play-catchup&utm_medium=social&utm_source=linkedin) | [![Bluesky](https://insights.comforte.com/hubfs/Social%20Icons/bluesky_logo.png)](https://bsky.app/intent/compose?url=https://insights.comforte.com/the-pci-dss-4.0-deadline-has-passed-but-theres-still-time-to-play-catchup&utm_medium=social&utm_source=Bluesky) | ![Twitter](https://insights.comforte.com/hubfs/Social%20Icons/twitter_x_logo-1.png) | [![XING](https://insights.comforte.com/hubfs/Social%20Icons/xing-color2.png)](https://www.xing.com/spi/shares/new?url=https://insights.comforte.com/the-pci-dss-4.0-deadline-has-passed-but-theres-still-time-to-play-catchup&utm_medium=social&utm_source=xing) | [![Email](https://insights.comforte.com/hubfs/Social%20Icons/email%20icon.png)](mailto:?subject=Check%20out%20https://insights.comforte.com/the-pci-dss-4.0-deadline-has-passed-but-theres-still-time-to-play-catchup&utm_medium=social&utm_source=email%20&body=Check%20out%20https://insights.comforte.com/the-pci-dss-4.0-deadline-has-passed-but-theres-still-time-to-play-catchup&utm_medium=social&utm_source=email) |
| --- | --- | --- | --- | --- | --- |

## Free 30-Day Health Check for Sensitive Payment Data 

Accelerate PCI Compliance with Automatic Discovery and Classification of PANs and Cardholder Data

[![Start Your Free Trial Today](https://no-cache.hubspot.com/cta/default/4026697/b524802b-4c2a-4a07-8630-c282723556aa.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/b524802b-4c2a-4a07-8630-c282723556aa)

### Related posts

![How Vaultless Tokenization Works in Practice, to Transform Your Business](https://insights.comforte.com/hubfs/comforte%20AG_How%20Vaultless%20Tokenization%20Works%20in%20Practice%20to%20Transform%20Your%20Business_24.07.2025.png)

 Jul 24, 2025 l [PCI DSS](https://insights.comforte.com/tag/pci-dss) , [Compliance](https://insights.comforte.com/tag/compliance)

### [How Vaultless Tokenization Works in Practice, to Transform Your Business](https://insights.comforte.com/how-vaultless-tokenization-works-in-practice-to-transform-your-business?hsLang=en)

In last month’s [blog post](https://insights.comforte.com/is-pci-dss-4.0-slowing-you-down-heres-how-comforte-can-accelerate-your-pci-compliance-journey?hsLang=en) we explained how vaultless tokenization can transform PCI DSS 4.0 compliance from a regulatory burden into a business enabler. Not only does vaultless tokenization reduce the scope and cost of compliance, but it also...

[Read more](https://insights.comforte.com/how-vaultless-tokenization-works-in-practice-to-transform-your-business?hsLang=en)

![Is PCI DSS 4.0 Slowing You Down? Here’s How comforte Can Accelerate Your PCI Compliance Journey](https://insights.comforte.com/hubfs/comforte%20AG_Is%20PCI%20DSS%204.0%20Slowing%20You%20Down_%20Heres%20How%20comforte%20Can%20Accelerate%20Your%20PCI%20Compliance%20Journey%20.png)

 Jun 26, 2025 l [PCI DSS](https://insights.comforte.com/tag/pci-dss) , [Compliance](https://insights.comforte.com/tag/compliance)

### [Is PCI DSS 4.0 Slowing You Down? Here’s How comforte Can Accelerate Your PCI Compliance Journey](https://insights.comforte.com/is-pci-dss-4.0-slowing-you-down-heres-how-comforte-can-accelerate-your-pci-compliance-journey?hsLang=en)

With the latest version of PCI DSS, the Payment Card Industry Security Standards Council (PCI SSC) aims to elevate the standards for cardholder data (CHD) security with themes like stronger cryptography, multi-factor authentication, and continuous...

[Read more](https://insights.comforte.com/is-pci-dss-4.0-slowing-you-down-heres-how-comforte-can-accelerate-your-pci-compliance-journey?hsLang=en)

### Service

- [Contact](https://www.comforte.com/contact/)
- [About us](https://www.comforte.com/company/)
- [Blog](https://insights.comforte.com/)
- [Press Releases](https://www.comforte.com/company/press-releases/)
- [Career](https://www.comforte.com/company/career/)
- [Resources](https://www.comforte.com/resources/)

### Germany

comforte AG  
Abraham-Lincoln-Str. 22   
65189 Wiesbaden  
Germany

Phone: + 49 611 93199 00  
Fax: + 49 611 93199 05

### Australia

comforte PTY  
Suite 20, 1 Rivett Road  
North Ryde  
NSW 2113  
Australia

Postal Address:   
PO Box 1710  
Lane Cove  
NSW 1595  
Australia

Phone: +61 2 8197 0272

### USA

comforte Inc.  
30 Wall Street, 8th Floor  
New York, NY 10005-2205  
USA

Phone: +1-646-438-5716

### Singapore

comforte Asia Pte. Ltd.   
1 Raffles Place, #19-61 Tower 2   
Singapore 048616

Phone: +65 6808 5507

- [Sitemap](https://www.comforte.com/sitemap/)
- [Legal Notice](https://www.comforte.com/legal-notice/)
- [Privacy Policy](https://www.comforte.com/privacy-policy/)

© comforte AG 2026

<https://x.com/comforteag> <https://www.youtube.com/c/comforte-ag> <https://www.linkedin.com/company/comforte-ag/>