PCI DSS 4.0: What Changed and What You Need to Do
By Michael Torres
PCI DSS 4.0 went into full effect in March 2025, replacing the 3.2.1 standard that most companies had been certified against. The update includes 64 new requirements, many of which fundamentally change how payment data must be handled.
What Actually Changed
The biggest shift is from prescriptive requirements to outcome-based security. Instead of saying “you must have a firewall,” PCI 4.0 says “you must have network security controls that restrict traffic.” This gives organizations more flexibility in implementation but requires more documentation of why your approach meets the intent.
What Meridian Handles
If you are using Meridian’s hosted payment fields (Elements), you inherit our PCI DSS Level 1 certification. Card data never touches your servers. Specifically:
- Requirement 3 (Protect stored account data) — Meridian tokenizes all card data. Your systems only see tokens.
- Requirement 6 (Secure systems and software) — Our payment processing code undergoes continuous security review.
- Requirement 8 (Identify users and authenticate access) — MFA is enforced on all Meridian dashboard access.
What You Still Own
Even with Meridian handling card data, you are responsible for your SAQ-A attestation, which covers how you protect your Meridian API keys, secure your webhook endpoints, and manage access to your dashboard.