Stricter Guidelines. Smarter Security
Here’s what merchants need to know about PCI DSS v4.0

Share via

Table of Contents

Ready to #ThinkBigger?

Imagine your house has a safe where you store your most valuable possessions. Now, picture leaving one door to your house open. Even though the safe is locked, your valuables remain at risk because that open door compromises your home’s overall security. This illustrates the importance of securing not just your payment form (the safe) but also the entire parent page that hosts it.

This is where e-skimming attacks come into play. Even if your card capture form is secure, a vulnerability on your website can allow attackers to intercept sensitive data before it reaches your secure payment form.

The Evolution of Payment Security: From Securing the Room to Securing the Entire House

In the past, merchants relied on iframes to collect card data, which isolated the secure payment form from the rest of the website. As long as the payment form (or “the room with the safe”) was secure, vulnerabilities elsewhere on the site were less of a concern. But with the rise of sophisticated attacks like e-skimming — where malicious code is injected into the website, not the payment form — this approach is no longer sufficient.

To combat these modern threats, the Payment Card Industry (PCI) Security Standards Council introduced PCI DSS v4.0, which enforces stricter security measures for the entire website (more specifically the “parent page” hosting the card capture widget), not just the card capture widget. With these new standards, protecting your entire site is mandatory to prevent attacks like e-skimming and ensure secure payment processing.

What is PCI DSS v4.0?

PCI DSS 4.0 is designed to enhance the security of cardholder data by adopting a comprehensive approach to security measures and access controls. Merchants must now secure every part of the payment flow, ensuring not only the payment form but also the hosting web environment is protected. The deadline for full compliance with PCI DSS v4.0 is March 2025, when the future-dated requirements become mandatory.

What’s New in PCI DSS v4.0?

The Future-Dated Requirements:

  • Requirement 6.4.3: Merchants must maintain a list of all scripts running on payment pages, with processes to detect and address unauthorized changes. This combats e-skimming by ensuring no rogue scripts sneak into the payment page.
  • Requirement 11.6.1: Regular testing for unauthorized scripts on these pages is mandatory to prevent digital theft of sensitive payment data.

The Bottom Line: Protect the Entire House

PCI DSS v4.0 marks a shift from securing just the “safe” (payment form) to securing the entire house (your website). With new threats like e-skimming, every entry point must be fortified. The standard emphasizes a holistic approach—because if one window or door is left unsecured, everything is at risk.

The clock is ticking. March 2025 is closer than you think. Now’s the time to lock every door, window, and digital lock.

Coming Soon: Stay tuned for our next blog, where we’ll explore merchant vs. Peach Payments’ responsibilities under PCI DSS v4.0 compliance.

To learn more about how we protect merchants today, check out our Security at Scale page.<\/p>

Scale with Peach
Learn how we help scale some of Africa's most exciting businesses

Business tips, case studies, interviews with online store owners and business trends…

Black Friday up 93% over 2024, R1,86bn processed

South Africa-based digital payments platform Peach Payments shares 2025 Black Friday, Cyber Monday weekend results.

Samsonite in-store payment methods

Choose your favourite way to pay! Samsonite offers MoneyBadger, Payflex, RCS and Mobicred.

How global and regional companies can use the Mauritius IFC to centralise online payments and treasury functions

Learn how the IFC is swiftly becoming a pivotal hub for global and regional companies seeking to optimise online payment acceptance and centralise treasury operations.

# PeachFriday Merchant Deals 2025

Check out the amazing Black Friday sales that some of our favourite stores are running!

A merchant’s guide to chargebacks

Payments 101: Chargebacks won't disappear. Here is a guide on how to manage them. Chargebacks aren’t simply refunds wrapped in admin. They’re a formal, bank-led reversal of a card payment after a customer disputes a transaction.

Four Black Friday payment realities for merchants

Discover the four Black Friday payment realities Enterprise merchants need to consider to build trust with customers and grow revenue with help from a world-class payment gateway.

What are Direct Merchant Accounts (ISO) versus Aggregation Accounts?

What payments processing model should you consider, thinking of diving into the world of online payments? It's more than just accepting a transaction payment.

What Is 3RI? Everthing you need to know about Requestor-Initiated Authentication

Payments 101: Why 3RI is set to change recurring transactions, subscription renewal, installment payment, or delayed shipping charges.

Highlights from the 2025 World Wide Worx Online Retail Report

The 2025 World Wide Worx report, sponsored by Peach Payments, Mastercard and AskAfrika, reveals that convenience is now the benchmark, trust is the currency and payments are the bridge.

What is Interchange? Everything you need to know about interchange fees

Payments 101 : A clear guide for SA merchants on fee flows. Interchange fees can feel like a complex part of the payments world, but they're a big deal for any business that accepts card payments.

Cadana Pay x Peach Payments: Unlocking seamless global Payouts

The API integration process was one of the smoothest they had experienced, completed by an engineer in just two to three days. With 50-55% cost savings, Cadana Pay significantly reduced costs by switching to Peach Payments.

Peach Payments announces real-time clearance Payouts

The new payouts solution lets merchants top up their float and make disbursements to merchants and recipients in just minutes, through either a single API or through the Peach Payments dashboard.

Peach Payments x MoneyBadger partnership goes live

From light fittings and spades to groceries and tickets, Bitcoin-savvy consumers are keen to spend their crypto

Peach Payments launches enterprise-level POS terminal

Delivers a single view of all transactions, with customisable checkout flow and easy integration into existing POS solutions.

iTickets x Peach Payments Point of Sale

By partnering with Peach Payments, iTickets transformed its payment infrastructure into a strategic asset. Building unforgettable experiences at their events and a better experience for their valued customers.

Peach Payments x Digicape: Powering Premium Apple Experiences with Seamless Payments

By partnering with Peach Payments, Digicape transformed its payment infrastructure into a strategic asset, driving significant growth, enhancing operational efficiency, and providing a better experience for their valued customers.

Peach Payments acquires West-African payments gateway PayDunya

Peach Payments expands into six West African countries representing an exciting chapter in their journey to build a truly pan-African payment ecosystem.

The Battle for Card Security

How Your Payment Integration Defines Your PCI DSS Scope

Navigating International Transactions

Understanding Dynamic Currency Conversion (DCC) and Multi-Currency Pricing (MCP)

Seize the Sale with Buy Now, Pay Later

Discover how South Africans are embracing BNPL, and merchants are reaping the rewards.

2024 Wrapped: A Year of Innovation and Growth at Peach Payments

Peach Payments is paving the way for a transformative 2025. From Pay by Bank to Embedded Checkout, explore how we revolutionised payments in 2024

RCS payment option now available through Peach Payments

RCS allows customers to make seamless online purchases with their card, enhancing the overall shopping experience

Peach Payments sees impressive growth this Black Friday Weekend

The Leisure & Entertainment industry grew its share of online sales over the four-day Black Friday weekend by 113% from last year

#PeachFriday Merchant Deals 2024

Check out the amazing Black Friday sales that some of our favourite stores are running!

Your Ultimate Guide to Payment Security for Black Friday

What You Need to Know About PCI DSS 4.x

Scaling with Peach Payments: Unveiling the Product Roadmap

Peach Payments' latest innovations and future plans, emphasising customer-centric solutions and trailblazing advancements in the African payments industry.

Scaling with Peach Payments: Revolutionising Reconciliation

Streamline your transaction reconciliation with Peach Payments' new Recon API, designed for speed, accuracy, and scalability in high-volume operations.

Scaling with Peach Payments: The Future of Payments

Learn how Peach Payments is leading the future of digital payments, by offering the top payment methods consumers are demanding today.

Scaling with Peach Payments: How Peach Payments is Keeping Your Business Safe

A Deep Dive into the Importance of Payment Security and How Peach Payments Ensures Robust Protection.

Scaling with Peach Payments: Insights from the Think Bigger Summit 2024

Discover the impactful journey of Peach Payments innovating payment solutions over the past 12 years, and future plans to empower businesses across Africa.

Peach Payments named Top 100 Fintech Startups by CB Insights

Learn how Peach Payments made the 2024 Top 100 Fintech Startups by CB Insights, recognised for innovation and excellence in financial technology

Peach Payments partners with Sukhiba for conversational commerce

Partnership opens up WhatsApp sales channel for merchants preparing for Black Friday

What are you looking for?

Côte d'Ivoire
Burkina Faso
Benin
Dakar
Senegal
Moka
Mauritius
Nairobi
Kenya
Johannesburg
South Africa
Cape Town
South Africa