Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

What PCI DSS 4.0.1 Compliance Means for Businesses: A Practical Q&A

PCI DSS compliance depends on your payment flows, systems, providers, and the validation method accepted by your acquirer or payment brand—not simply your size or use of a processor.
From TheFinanceBase Team6 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

PCI DSS compliance means applying the payment-data security controls that fit your business and providing the evidence required by the organization that manages your compliance program. Your obligations depend on how payments flow, which systems can access or affect account data, what a provider does for you, and whether your acquirer or payment brand requires a Self-Assessment Questionnaire (SAQ), Report on Compliance (ROC), or another validation method.

What does PCI compliance mean for my business?

The Payment Card Industry Data Security Standard (PCI DSS) is a baseline of technical and operational requirements for organizations that store, process, or transmit payment account data, and for organizations that could affect the security of the cardholder data environment. Its intended audience includes merchants, payment processors, acquirers, issuers, and service providers.

In practical terms, compliance requires you to:

  • identify payment flows, systems, people, and providers in scope;
  • apply the controls relevant to that environment; and
  • demonstrate compliance through the validation route accepted for your business.

The standard’s six control goals cover secure networks and systems, protection of account data, vulnerability management, access control, monitoring and testing, and supporting security policies and programs. PCI DSS v4.0.1 organizes these goals into 12 requirements.

PCI DSS is a continuing security program, not a one-time form. A completed questionnaire does not guarantee that a business cannot be breached or eliminate its ongoing duties.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does PCI DSS apply to small businesses?

Yes. PCI DSS applies regardless of a merchant’s size or transaction volume. A small or straightforward environment may involve fewer systems and controls, but being small does not itself create an exemption.

Payment brands and the acquirer or other organization managing your compliance program decide whether you must validate compliance and which reporting rules apply. Ask that organization what it requires for your merchant account; do not choose a form solely because your transaction volume is low.

If I use a payment processor, do I still need to be PCI compliant?

Yes. Outsourcing payment processing can reduce the controls that apply directly to your environment, but it does not transfer all responsibility. PCI SSC states: “However, this does not remove the merchant’s responsibility to ensure account data is properly protected by the third party.”

A merchant using a processor should:

  • confirm that the provider is compliant for the services it supplies;
  • keep a written agreement that acknowledges each party’s responsibilities;
  • understand which controls the provider performs and which remain yours;
  • monitor the provider’s compliance status at least annually; and
  • validate your own compliance as required by the compliance-accepting entity.

Do not assume that outsourcing automatically makes you eligible for SAQ A. Eligibility depends on the exact payment flow and all questionnaire criteria.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How do payment flows change PCI DSS scope?

Your assessment starts with how customers’ payment data moves through your business. Common arrangements have different responsibility splits:

Payment arrangement What to examine Why the route matters
In-house payment handling Your applications, networks, terminals, databases, staff access, and security controls More of the cardholder-data environment may be under your direct control.
Embedded processor page or form Your website’s integration, scripts, hosting, change processes, and the processor’s responsibilities SAQ eligibility is conditional, including a script-attack criterion for eligible embedded-page/form merchants.
Redirect to a processor website The redirect implementation, links between your site and the provider, and provider assurance The embedded-form script clarification does not apply in the same way to a redirect.
Fully outsourced payment Your agreements, redirects or integrations, provider status, and responsibilities that remain with you Outsourcing can narrow scope but does not remove merchant accountability.

This comparison does not determine your assessment. The responsible acquirer, payment brand, or other compliance-accepting entity must confirm the applicable validation method.

Do I need an SAQ or a Report on Compliance?

There is no universal answer. Payment brands, acquirers, and other compliance-accepting entities determine which validation and reporting method they accept. Depending on the program and your environment, that may be an eligible SAQ, a ROC completed with an assessor, or another specified process.

Self-Assessment Questionnaire (SAQ)

An SAQ is available only for eligible scenarios and comes with eligibility criteria. Select the questionnaire only after mapping your payment flow and confirming acceptance with the organization receiving your validation. SAQ eligibility criteria should not be used as a substitute for an ROC assessment unless that organization has reviewed and agreed to the approach.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Report on Compliance (ROC)

A ROC is a formal assessment report generally prepared with a qualified assessor when the compliance program requires it. A Qualified Security Assessor (QSA) can help define scope, test controls, and document whether applicable requirements are accurately addressed.

How to confirm the correct route

  1. Document how payment data enters, moves through, and leaves your business.
  2. List systems, personnel, vendors, and connections that store, process, transmit, or could affect payment-data security.
  3. Obtain your processor’s current compliance evidence and responsibility information.
  4. Ask your acquirer, payment brand, or compliance-accepting entity which validation method and reporting date apply.
  5. Use a QSA or other qualified adviser when scope or shared responsibilities are unclear.

What changed with PCI DSS 4.0.1?

PCI SSC published PCI DSS v4.0.1 on 11 June 2024 as a limited revision following stakeholder feedback. It corrected formatting and typographical errors and clarified the focus and intent of some requirements and guidance. PCI SSC said it added no requirements and deleted none.

PCI DSS v4.0 was retired on 31 December 2024. As of that date, v4.0.1 was the only active PCI SSC-supported version. The revision did not change the 31 March 2025 effective date for future-dated requirements. PCI SSC’s release announcement answered the timing question directly: “No. This limited revision does not impact the effective date of these new requirements.”

How should businesses report the post-2025 requirements?

Because 31 March 2025 has passed, reports use the successor requirements. PCI SSC says the superseded requirements should be reported as Not Applicable in an ROC or SAQ:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Superseded requirement Successor requirement Reporting treatment after 31 March 2025
6.4.1 6.4.2 Report 6.4.1 as Not Applicable; assess 6.4.2.
8.3.10 8.3.10.1 Report 8.3.10 as Not Applicable; assess 8.3.10.1.
10.7.1 10.7.2 Report 10.7.1 as Not Applicable; assess 10.7.2.

This is a reporting treatment for superseded identifiers, not a removal of the underlying security topics.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is the SAQ A e-commerce clarification?

For eligible e-commerce merchants using a processor’s embedded payment page or form, revised SAQ A eligibility requires confirmation that the merchant site is not susceptible to script attacks that could affect its e-commerce systems.

The clarification is specific to the embedded-page/form scenario. It does not apply in the same way to merchants that redirect customers to a processor website or fully outsource payment by sending customers to the processor’s site. All other SAQ A eligibility criteria still apply, and the recipient of your validation must confirm that SAQ A is appropriate.

PCI SSC’s January 2025 announcement removed requirements 6.4.3 and 11.6.1 from SAQ A and added the script-attack eligibility criterion. That reporting change did not remove or diminish those underlying PCI DSS requirements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who determines and supports compliance?

PCI Security Standards Council

PCI SSC publishes PCI DSS, supporting guidance, and questionnaires. It does not decide the reporting route for every merchant.

Acquirer, payment brand, or compliance-accepting entity

This organization sets the validation method, reporting format, and timing it will accept for your business or service.

Qualified Security Assessor

A QSA is an independent organization trained to perform PCI DSS assessments. An assessor can help establish scope and verify that applicable requirements are accurately defined and documented. A QSA is not automatically mandatory for every merchant.

Merchant and service provider

Both parties must document shared responsibilities, maintain their assigned controls, and keep evidence that supports the required validation.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Frequently Asked Questions

Does using a hosted payment page make a business exempt from PCI DSS?

No. Hosting or outsourcing may reduce the systems in your direct scope, but the merchant still has responsibilities for provider oversight, agreements, shared controls, and any validation required by its compliance program.

Can I choose an SAQ based only on my transaction volume?

No. Transaction volume may affect a payment brand’s validation rules, but SAQ eligibility depends on the complete payment arrangement and questionnaire criteria. Confirm the form with your acquirer, payment brand, or other compliance-accepting entity.

Is PCI DSS v4.0 still current?

No. PCI DSS v4.0 was retired on 31 December 2024. PCI DSS v4.0.1 is the active PCI SSC-supported version described here.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.