Future-Dated Requirement

PCIComplianceHubLast updated

A requirement published in PCI DSS v4.0 but marked as a best practice until 31 March 2025, giving organizations time to plan and budget for it before it was assessed. Future-dated requirements were not tested for compliance before that date. All of them are now in force: since 31 March 2025 every v4.x requirement is mandatory and assessed like any other. The label still appears in v4.0 documents and older guidance, so treat it as historical context rather than a live exemption.