pqcstatus
Regulation & guidance

PCI DSS v4.0.1: cryptography requirements and deadlines

Industry standard

Requirement 12.3.3 makes a yearly-reviewed inventory of cipher suites and protocols mandatory since 31 March 2025.

At a glance

TypeIndustry standard
Jurisdictioninternational
Who it applies toAny organization that stores, processes or transmits payment card data (merchants, PSPs, SaaS in the payment flow).

Cryptography requirements

ReferenceRequirementWhat a scan and inventory can evidence
12.3.3Cryptographic cipher suites and protocols in use are documented and reviewed at least every 12 months: up-to-date inventory (purpose, where used), monitoring of their continued viability, and a documented strategy to respond to anticipated changes in cryptographic vulnerabilities.
  • Cryptographic inventory
  • TLS configuration
  • PQC migration plan

Key dates

  1. Requirement 12.3.3 becomes mandatory (was a best practice before).

Sources

  1. PCI DSS v4.0.1 · PCI Security Standards Council

Catalog version 2026-09-28. Every position links to its primary source; draft documents are labelled as such.

Frequently Asked Questions

Who must comply with PCI DSS v4.0.1?

Any organization that stores, processes or transmits payment card data (merchants, PSPs, SaaS in the payment flow).

What does PCI DSS v4.0.1 require for cryptography?

12.3.3: Cryptographic cipher suites and protocols in use are documented and reviewed at least every 12 months: up-to-date inventory (purpose, where used), monitoring of their continued viability, and a documented strategy to respond to anticipated changes in cryptographic vulnerabilities.

What are the key dates of PCI DSS v4.0.1?

March 31, 2025: Requirement 12.3.3 becomes mandatory (was a best practice before).