Skip to content
Infilux AppSec Logo
PCI DSS 4.0 · Worldwide

PCI DSS 4.0 Compliance for Fintech & Payments

Infilux AppSec runs PCI DSS 4.0 compliance for fintechs, payment processors, and merchants — scoping the cardholder data environment, preparing the appropriate SAQ (A, A-EP, B, C, D), coordinating Approved Scanning Vendor (ASV) external scans, and supporting full Report on Compliance (RoC) engagements for Level 1 merchants and service providers.

United States United Kingdom European Union India Singapore Australia

PCI DSS 4.0 fully replaced 3.2.1 on 31 March 2024, with future-dated requirements becoming enforcement-mandatory through 31 March 2025. The new standard is significantly more prescriptive on multi-factor authentication, anti-malware, scripts on payment pages, and continuous monitoring than its predecessor. Most existing PCI programmes need real work, not just a quick refresh.

Our PCI engagement starts with scoping — what's actually in your cardholder data environment, what's connected to it, and what can be segmented out. A correctly scoped CDE shrinks the audit perimeter dramatically; we've taken Level 1 fintechs from 200+ servers in scope down to 20 through proper network segmentation.

For service providers and Level 1 merchants we engage with your QSA throughout the RoC fieldwork — control walk-throughs, sampling, evidence packages, the management response. For Level 2-4 merchants we prepare the appropriate Self-Assessment Questionnaire and complete the quarterly ASV external scan via partners.

Key controls we implement

Scope determination

What's in the CDE, what's connected, what can be segmented out. The single highest-leverage activity in any PCI engagement.

Requirement 8 — strong authentication

PCI 4.0 mandated MFA on all non-console admin access AND on all access to the CDE. Requires phishing-resistant MFA for sensitive accounts after 31 March 2025.

Requirement 11 — security testing

Quarterly ASV external scans, internal vulnerability scans, annual segmentation testing, annual external + internal penetration testing.

Requirement 6.4.3 — payment page scripts

New in 4.0 — inventory and authorise every script on payment pages, alert on changes. Mitigates Magecart / web-skimming.

Requirement 12.10 — incident response

Documented IR plan, tested annually, with PCI-specific notification timing to acquirers and card brands.

Continuous monitoring

PCI 4.0 emphasises a defined frequency for each control activity, derived from a documented risk analysis.

Network segmentation

Proper segmentation can reduce CDE scope 5-10× and dramatically lower audit + compliance cost.

Frequently asked

What's the difference between PCI DSS Level 1, 2, 3, 4?+
Merchant levels depend on annual card-transaction volume: Level 1 is 6M+ transactions/year (or any merchant that has suffered a breach), Level 2 is 1-6M, Level 3 is 20K-1M e-commerce, Level 4 is <20K. Level 1 requires an annual on-site QSA assessment + RoC. Lower levels typically use Self-Assessment Questionnaires.
What changed in PCI DSS 4.0 vs 3.2.1?+
Bigger changes: continuous monitoring expectations, MFA on all access to the CDE (not just remote), script inventory on payment pages (Requirement 6.4.3), customised approach option for risk-based control implementation, longer audit periods for sampling.
We use Stripe / a hosted payment page. Are we PCI-compliant by default?+
You're scoped to SAQ A (e-commerce with full payment redirection or iframe) — the simplest SAQ — but you still must complete it, address the requirements that apply (TLS configuration, vulnerability management, IR plan), and submit it to your acquirer. 'We use Stripe' doesn't waive PCI.
How much does a PCI DSS engagement cost?+
Level 1 RoC programmes typically run USD $80K-$300K combined (our readiness + QSA audit + ASV scans). Levels 2-4 SAQ-based programmes typically USD $15K-$50K all-in. Scope-reduction work in year one often pays for itself in year-two audit fee savings.
Do you partner with a specific QSA firm?+
We're QSA-firm-agnostic and have working relationships with multiple PCI-Council-approved QSAs across the US, UK, EU, and India. We'll introduce you if you don't already have a QSA relationship; if you do, we work with yours.

Related Infilux services

Other compliance frameworks