New PCI DSS Rules Say Merchants on Hook for Compliance, Not Providers
ID: 54e67b5a-12a9-558d-aca0-70c20fc17bac
STIX ID: report--54e67b5a-12a9-558d-aca0-70c20fc17bac
Feed Name: Dark Reading
## Executive Summary PCI DSS 4.0.1 updates tighten controls around payment card security (expanded MFA, stronger password requirements, anti-phishing measures, and new reporting controls) with enforcement effective March 31; merchants remain ultimately responsible for their payment environments even when using third-party service providers. The report highlights API security as a major risk vector (exposed documentation, weak authentication, password vs token use, card data in query parameters), explains potential fines and operational consequences for noncompliance, and recommends working with providers to define scope, collect evidence, and address gaps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
