How to Pass Your PCI Audit in 2025

Get quick and important advice for tackling PCI audits in 2025.

Audit
Auditor Tips
PCI
How to Pass Your PCI Audit in 2025

What You Need to Know about PCI Audits In 2025

There are several key changes that those conducting PCI audits in 2025 will experience. The first is PCI DSS 4.0.1. While 4.0.1 only includes minor changes, additional guidance was provided to further clarify requirement 11.6.1 by stating that the list of example solution techniques was not a set of independent solutions and that a full solution could include but is not limited to a combination of the listed techniques. Remember, until PCI 3.2.1 retires on March 31, 2025, your process won’t significantly change, but it’s better to be prepared for 4.0 ahead of time.

Another change businesses experienced this past year when getting their PCI DSS 4 audit is that the bar has been raised a bit on their overall documentation. This new version of PCI DSS requires some new, specific documentation, which can be challenging to continuously stay on top of. 

Some quick advice for tackling PCI audits in 2025 includes: 

  • Doing your homework
  • Having excellent project management, milestones, and goals
  • Ensuring you create good network and data flow diagrams
  • Scoping, get the right group together
  • Planning for extra assessment time
  • Addressing future dated requirements
  • Noting report writing by your QSA

PCI Audits in 2025: Struggles and Successes

Some of the new requirements have proven more of a struggle than others. QSAs have noted that this includes:

  • Service provider responsibility acknowledgment documentation (12.8.2)
  • VA scanning for small merchants with iFrame ecommerce
  • Most are putting off future-dated requirements, even simple ones
  • More overall documentation paperwork is required

However, some successes surrounding audits in 2025 have been noted by QSAs as well, including: 

  • Clients say 4.0 is easy to complete without the future-dated
  • Most clients are taking preparation for future dated requirements seriously
  • QSAs have been receiving more interest and questions about future requirements since July

While many of the new requirements can seem daunting, they are not necessarily “brand new” but rather enhancements of previous requirements. 

New PCI v4 Requirements

Scanning Requirement Changes

SAQ A merchants now need to conduct vulnerability scans, which was not the case with prior versions of PCI DSS and may represent a new compliance process that these small merchants are not used to. These scans should not represent a large service cost, but the process of setting them up, monitoring the results, and acting on them represents a new challenge to the SAQ A community.

New Ecommerce Security Requirements

Merchants using iFrames to help control PCI DSS scope on their ecommerce pages must now address security on their website even though they contract with a 3rd party for the payment page shown in the iFrame. These “referring payment pages” (e.g., a merchant has a small website fully under their control and they display a 3rd party payment page in an iFrame) are the pages at most risk of e-commerce skimming and merchants often believe these pages are safe because they have contracted with a 3rd party for collecting payment data.  These referring payment pages have to comply with the new PCI DSS requirements 6.4.3 and 11.6.1

Requirement 6.4.3 focuses on merchants and service providers being aware of all scripts on their websites, especially payment pages or referring payment pages where third-party scripts can be included without their knowledge by other 3rd party included scripts. The goal of 6.4.3 is to reduce unnecessary scripts, as these can create security risks. 

Requirement 11.6.1 builds on this by ensuring that companies know when page headers or script contents change, and new or unauthorized scripts have been added.

What Future Requirements for PCI DSS Compliance are Anticipated? 

Gary Glover (VP of Assessments) and Brian Cole (Enterprise Sales Manager) speculate that there will be several future requirements to meet PCI compliance, including: 

  • Keyed Hashes: This will require key management similar to encryption, posing potential challenges for organizations using hashing algorithms (3.5.1.1)
  • Phishing Protection and Training: New email filtering and phishing training mechanisms will be required (5.4.1, 12.6.3.1)
  • Payment Page Script Monitoring: This is a response to increased attacks on iframes used for payment, requiring more security measures for websites (6.4.3 & 11.6.1)
  • Multi-factor Authentication (MFA) for all access to CDE and system features: MFA will now be required for internal access to the card data environment, and stricter rules are being set for MFA solutions to prevent replay attacks and avoid disclosing whether passwords or tokens failed during authentication. (8.4.2, 8.5.1)
  • Scope Validation Process and Documentation: Another challenge is documenting scope validation yearly. You will now need to provide clear documentation on how your business’ scope has changed and been validated. This was often done informally in the past. (12.5.2.x)

This is not an exhaustive list, but it includes the most significant changes that are often being put off until 2025. 

What Will Be the More Difficult Changes to Address? 

Payment page script monitoring for requirements 6.4.3 and 11.6.1 are anticipated to be the most difficult changes to address for PCI audits in 2025. It’s important for everyone to understand that script monitoring is a problem for merchants, not service providers. Merchants need to be responsible for their own script analysis and choose solutions that monitor the entire transaction process. This means that from the very first to the last stage of purchase, you’re monitoring for malicious scripts that can be added. 

So, merchants becoming responsible for their own cybersecurity can be a major hurdle that must be addressed in 2025. 

Luckily, SecurityMetrics offers two tools that help merchants comply with this: Shopping Cart Monitor and Shopping Cart Inspect. These tools are for merchants of all sizes and are designed to regularly monitor and scan your ecommerce website, looking for unauthorized scripts and malicious activity. Shopping Cart Monitor and Inspect can work with almost any size budget, so if you’re interested in learning more about these tools, please speak with a SecurityMetrics expert. 

Final Thoughts: PCI Audits in 2025 Will Require More Planning

One vital thing you can do to prepare for your PCI audit in 2025 is to ensure that you have both the budget and the buy-in necessary to succeed. In fact, Brian Cole says that currently, “We’re fielding lots of calls and answering questions so people can plan to fit these requirements into their 2025 budgets.” 

Remember, here are the biggest items you can anticipate to address in 2025:

  • There are no real big secrets: organize, manage, and do your homework
  • Have good data flow diagrams
  • Know your service providers, collect all needed documentation
  • Spend time on your scoping process and document it
  • ROC reporting generally takes more time; plan accordingly
  • Don’t push off future dated requirements anymore 

Another important thing you can do for your 2025 PCI audit is choose a reputable PCI audit partner. If you’re partnering with SecurityMetrics for your 2025 audit, rest assured that most SecurityMetrics QSAs have been with the company for at least ten years, meaning “you can expect a very similar experience with SecurityMetrics year after year, from QSA to QSA.” SecurityMetrics also “prides itself on your ability to easily get someone on the phone” (Brian Cole). 

So, if you’re unsure about who to partner with, consider speaking with an expert who can help you understand your PCI compliance requirements and the best way to move forward. Luckily, the PCI assessment process “hasn’t changed a whole lot in the last twenty years... As far as the customer is concerned, there is no change in the way we work” (Gary Glover). 

To get a better understanding of how PCI audits work with SecurityMetrics, read about Anedot’s journey to PCI compliance.

Join thousands of security professionals.

Subscribe Now

Get the Guide To PCI Compliance

Download

Get Quote for PCI Compliance

Request a Quote