top of page

Subscribe to Our Blog

Join our community for monthly updates, expert insights, and practical tips delivered straight to your inbox.

The PCI Compliance Grace Period Is Over. Here's What Changed.

  • Jul 16
  • 2 min read

Why PCI DSS 4.0.1 means online merchants can't treat compliance as an annual checkbox anymore



If your PCI compliance still feels like something you check off once a year and forget about, that grace period has ended. As of 2026, PCI DSS 4.0.1 is the operating standard, and every requirement that was once "future-dated" is now fully enforceable. Here's what actually changed, and why it matters more for online merchants specifically.


The Grace Period Ended March 2025

Every future-dated requirement introduced in PCI DSS 4.0 became mandatory as of March 31, 2025. Merchants completing their first full assessment cycle under the new standard no longer have transition allowances to lean on. What used to be "best practice, coming eventually" is now a hard pass-or-fail line item in an assessment.


Your Checkout Page Is Now Explicitly In Scope

One of the most significant shifts is around payment page security. New requirements call for inventorying every script running on your checkout page and monitoring for unauthorized changes. This matters because even merchants using the simplest self-assessment questionnaire (SAQ A) aren't automatically exempt anymore, eligibility now depends on how the payment page is actually built and what scripts run on it.


MFA Isn't Just For Admins Anymore

Multi-factor authentication is now required for anyone accessing the cardholder data environment, not just remote access or system administrators. That includes internal staff and third-party vendors who touch cardholder data in any capacity.

 

Compliance Is No Longer An Annual Snapshot

Perhaps the biggest philosophical shift in the new standard is the move away from a once-a-year audit mentality. Merchants are now expected to document and confirm their compliance scope at least every 12 months, and maintain ongoing security practices throughout the year rather than treating PCI compliance as a single point-in-time event.

 

What This Means For You

If you haven't reviewed your PCI compliance status against the full 4.0.1 standard, now is the time. Confirm which SAQ type actually applies to your business given how your payment page is built, inventory the scripts running on your checkout flow, and make sure MFA is enforced for everyone with access to cardholder data, not just your administrators.



Comments


Navigate the complexity of payments with confidence

Get started today.

bottom of page