Quo vadis, PCI Standards Landscape: A Focus on Payment Security
The payment security landscape is undergoing its most significant transformation in over a decade. As we transition to a fully digital economy, the Payment Card Industry Data Security Standard (PCI DSS) also evolve into a dynamic, risk-based security framework. In this post, we explore the history of the PCI DSS standards and the primary challenges organizations face with the current standards—specifically the transition to version 4.0.1—and what the industry expects in the years to come.
The Evolution of PCI DSS
The PCI family of standards originated in 2006 with the PCI DSS (Payment Card Industry Data Security Standard), designed as a security requirement for merchants using payment terminals and thus handling card numbers. Interestingly, the initial adoption of PCI DSS in the Czech Republic was a bit different than in most western countries. Unlike markets such as the US, the Czech market largely skipped the phase where merchants routinely had access to card numbers. The country quickly embraced “chipification,” immediately switching to chip technology. This meant card numbers were never “released” in an open format from the payment terminal, transactions were securely verified with a PIN, etc. Furthermore, most card services were implemented through banks, which already maintained a higher level of security than the typical merchant. Consequently, the standard’s adoption was initially complicated. The scope of requirements, stakeholder responsibilities, and risk management for card acceptance were unclear. However, global pressure from card associations successfully harmonized these market differences. Today, PCI DSS is an indispensable part of routine operations for any organization accepting payment cards.
PCI SSC: More Than Just DSS
PCI DSS is not the only standard issued by the PCI Security Standards Council (SSC). The PCI SSC has systematically incorporated other standards originally developed by individual card brands. Currently, the PCI SSC standards provide comprehensive coverage for the entire card payment process, from:
- Secure issuance and personalization of payment cards.
- The payment transaction itself.
- Security of card acceptance devices.
- Secure operation of systems that manage card numbers.
- Secure verification of payment transactions.

(Standards list taken from the website PCI Security Standards)
The PCI SSC also ensures quality control by providing training and accreditation for qualified auditors (referred to as Assessors). This includes rigorous requirements for their training, insurance, operational separation of responsibilities, and maintaining up-to-date lists of certified devices and solutions. The Council’s ambition extends beyond current standards, focusing on future activities like exploring how Artificial Intelligence and Machine Learning can assist in detecting fraudulent transactions and identifying fraudulent merchants.
The strength of the PCI DSS standard, in contrast to some other legislative attempts, lies in its effort to clearly define what is and is not secure. It then even goes a step further by describing the goals, form, and verification methods of required audit controls. Crucially, it seamlessly integrates into the entire ecosystem of payment card issuance and acceptance, clearly dividing the responsibilities among all players.
A particularly commendable feature of the PCI SSC is its commitment to the strict life cycle of its standards. It constantly subjects them to checks for relevance, ensuring they remain current in the face of evolving threats, such as revising secure key lengths for cryptographic algorithms and improving authentication security. While ordinary users rarely interact with these standards—as they are aimed at companies accepting cards—their innovative potential has been demonstrated to the general public in one key area: mobile payment terminals. PCI SSC experts designed and standardized a security solution for what they call an “open device,” such as a merchant’s mobile phone. This complex process transforms a phone—a device only as secure as its user—into a robust “payment terminal” engineered for maximum security. This standardization enabled the creation of SoftPOS solutions which turn any smartphone into a payment terminal (like GP Tom, which is now a reference mobile payment terminal solution in the Czech market).
The Shifting Ground: From PCI DSS 3.2.1 to 4.0.1
The move toward a fully digital economy has brought a wave of hurdles for organizations worldwide. For years, PCI-DSS version 3.2.1 was the global benchmark. However, as of March 31, 2024, that version was officially retired and the era of the more flexible, outcome-based PCI DSS v4.0.1 began. While the flexibility is a welcome change for mature security teams, it has introduced a layer of complexity that many businesses were not prepared for.
Key Challenges Facing Organizations Handling Sensitive Payment Information
A. The Complexity of the “Customized Approach”
One of the headline features of PCI DSS v4.0 is the Customized Approach. Unlike the traditional “Defined Approach,” where an organization follows specific, prescriptive steps, the Customized Approach allows entities to design their own security controls to meet a requirement’s objective.
The Challenge: While this offers flexibility for innovative tech stacks (like serverless or complex cloud environments), it puts a massive burden on the organization to provide evidence. You must perform a rigorous Targeted Risk Analysis (TRA) for every customized control. Not every organisation has the internal expertise to document and defend these custom controls to a Qualified Security Assessor (QSA).
B. The Multi-Factor Authentication (MFA) Mandate
Under v3.2.1, MFA was largely required for administrative and remote access. Under v4.0, MFA is required for all access into the Cardholder Data Environment (CDE).
The Challenge: This sounds simple in theory but is a nightmare in legacy environments. Implementing MFA for every internal system user, service account, and third-party vendor requires a level of integration that can break older workflows and significantly increase licensing costs.
Based on next studio’s experience from migration projects, the requirement for two-factor authentication is particularly painful. During migration within the Cardholder Data Environment, a large number of users work there, from testers to security, development, and operations teams. Onboarding such a high number of ‘new users’ for multi-factor authentication can be very complicated to manage and control, as can the amount of manual intervention required to handle various exceptions. The migration naturally also puts a great emphasis on security operations teams to clean up the new infrastructure from legacy accounts and revoke authorizations and access to all user accounts that no longer require them after the migration.
C. E-commerce and “Script Scrutiny”
Cybercriminals have shifted their focus to “Magecart” style attacks—web skimming where malicious scripts are injected into checkout pages.
The Challenge: Organizations must now maintain an inventory of all scripts running on their payment pages and ensure they are authorized. In a world of third-party marketing tags, chatbots, and analytics, managing a dynamic web environment to this degree of granularity is an immense operational hurdle.
D. Continuous Compliance vs. Annual Audits
PCI DSS v4.0.1 explicitly pushes organizations away from “point-in-time” compliance and instead mandate that roles and responsibilities for each requirement be clearly assigned and documented.
The Challenge: Maintaining security as a “business-as-usual” (BAU) process requires a culture shift. Many companies struggle with “compliance drift,” where they pass an audit in June but fail to maintain those controls by December. The new standard makes this drift much harder to hide.
Future Developments and Future-Dated Expectations
As we look toward 2026 and beyond, the PCI Security Standards Council (PCI SSC) is already signaling the next phase of payment security.
Cryptographic Modernization (POI v7.0)
The physical hardware we use—Point of Interaction (POI) terminals—is getting a massive security upgrade. The release of PCI PTS POI v7.0 marks a full break from legacy protocols and we are seeing a mandatory shift to 128-bit or higher cryptography. Triple DES (TDES) is being phased out in favor of AES and other robust algorithms. This is the industry’s way of future-proofing against the rising tide of quantum computing threats.
Now this is an extremely important requirement that will keep the security community awake during the nights. With the advent of quantum computers, many current cryptographic rules and standards may become completely obsolete. The mere increase in encryption key length may not be sufficient, and it is possible that completely new types of cryptographic algorithms, known as quantum-resistant, will need to be implemented within authentication and encryption protocols.
Version 7.0 also introduces formal requirements for biometric readers. As consumers move away from PINs toward fingerprint and facial recognition on mobile devices and at terminals, the standard is evolving to ensure this biometric data is captured and stored with the same rigor as card numbers.
AI: The Double-Edged Sword
The next few years will likely see the PCI SSC addressing Artificial Intelligence (AI) in two ways:
- AI-Powered Attacks: Standards will need to evolve to defend against AI-generated phishing and automated vulnerability exploitation.
- AI for Defense: We expect future guidance on using AI for automated log review and anomaly detection, which are currently significant manual burdens for IT teams.
Preparing for 2026: Strategies for Success
To navigate these challenges, organizations should prioritize the following:
-
Automate Logging and Monitoring: Manual log reviews are no longer viable. Implementing a SIEM (Security Information and Event Management) system (with as much as possible machine learning capability) is essentially mandatory for the modern enterprise.
-
Review Third-Party Risk: Your compliance is only as strong as your weakest vendor. Under v4.0, you are more accountable than ever for the security of service providers who touch your CDE.
-
Embrace Zero Trust: The move toward MFA for all access is the first step toward a Zero Trust Architecture. Organizations that adopt Zero Trust principles now will find future PCI updates much easier to implement.
Conclusion
The evolution of PCI DSS reflects the broader shift in cybersecurity: it is no longer about building a taller wall, but about creating a resilient, observable, and adaptable environment. While the challenges of version 4.0.1 are steep—particularly regarding MFA, script management, and customized validation—the standard provides a roadmap for securing the next decade of digital commerce. The path forward is clear: move away from the annual scramble and toward a model of continuous, automated security.
Sources
- PCI Security Standards Council (2024). “PCI DSS v4.0.1 Resource Hub.”
- Spreedly (2025). “The Ultimate Guide to PCI DSS 4.0 Implementation.”
- UHY Consulting (2025). “Insights from the 2025 PCI Security Standards Council Meeting.”
- Security Journey (2024). “Top 5 PCI-DSS Compliance Challenges Businesses Face.”
- Stratica (2025). “How to Become PCI DSS Compliant in 2026.”
About us
next studio consulting has rich experience in the integration and implementation of large-scale solutions in the field of banking and payments, and we are prepared to provide our know-how and capacity in initiatives related to improving institutions’ PCI-DSS compliance and preparation for future challenges.


