PCI DSS: PCI Council Releases SAQs for Version 4.0.1

18. October 2024

This week, the PCI Security Standards Council (PCI SSC) announced that it published the Self-Assessment Questionnaires (SAQs) for PCI DSS v4.0.1. [See the PCI SSC Bulletin]

With the help of SAQs, eligible merchants and service providers can prove their compliance with PCI DSS by means of a self-assessment. The SAQs according to PCI DSS v4.0.1 are valid exclusively from January 1, 2025. Until then, companies can decide for themselves whether they wish to complete their self-assessment with an SAQ according to PCI DSS v4.0 or v4.0.1.  

The update of the SAQs according to PCI DSS v4.0.1 reflects changes to the requirements of PCI DSS v4.0.1 on the one hand and also implements feedback from the industry:

  • Aligning requirement content with PCI DSS v4.0.1
  • Clarifying SAQ Eligibility Criteria in SAQs A, A-EP, and C-VT
  • Adding a requirement to SAQ A and removing a requirement from SAQ C
  • Updating SAQ Completion Guidance in SAQs A and A-EP

The SAQ Instructions and Guidelines document has also been published to align with the SAQ updates for PCI DSS v4.0.1. This document provides information on all PCI DSS v4.0.1 SAQs, including an explanation of the intent of the SAQs, the eligibility criteria for the SAQs, and how to complete an SAQ. The PCI DSS v4.0.1 SAQs and the document “PCI DSS v4.0.1 SAQ Instructions and Guidelines” can be found using the “SAQ” filter in the PCI SSC Document Library on the PCI SSC website.


Do you need help preparing for or implementing PCI DSS v4.0.1 in your company? Get in touch - our experts are happy to help.

Also interesting:

DORA Countdown: One Month Left Until the Deadline

DORA Countdown: One Month Left Until the Deadline

DORA, the Digital Operational Resilience Act, will fully apply as of 17 January 2025. We have summarized everything you need to know about the EU regulation, preparation and best practices from our news blog.

Sunset of PCI DSS v4.0 on 31 December 2024: Get Ready!

Sunset of PCI DSS v4.0 on 31 December 2024: Get Ready!

PCI DSS v4.0: In March 2024, version 4.0 of the Payment Card Industry Data Security Standard became mandatory after a two-year transition phase. Just a few months later, version 4.0.1 was released as a minor update of the standard, which will become mandatory on...

Top 3 Vulnerabilities in SSO Pentests

Top 3 Vulnerabilities in SSO Pentests

During their penetration tests (pentests), our security analysts at usd HeroLab repeatedly uncover vulnerabilities that pose significant risks to corporate security. They increasingly encounter the same vulnerabilities. Our blog series "Top 3 Vulnerabilities" presents...

Categories

Categories