PCI DSS 4.0 is no longer “best practice”: your acquirer will ask

On 31 March 2025 the “future-dated” PCI DSS 4.0 requirements came due. By July that is not lab news: it is the fine print the acquirer and the gateway remind you of when you want more card volume. MFA on the data environment, long passwords, script control on the payment page, and log review are no longer optional wording.

The local temptation is to keep the PAN “for a moment” in a spreadsheet, or to put a card form on your own site “so it looks integrated.” That widens PCI scope. The serious path is not touching card data: redirect or hosted fields from a certified gateway, and the order in your system. The payment lands; the card number does not.

Three mistakes we see in stores and apps

  • A homemade checkout that asks for 16 digits and posts them to an improvised endpoint.
  • Ecommerce plugins with third-party scripts on the payment page and no inventory of them.
  • Payment “left on WhatsApp” and the order built by hand: neither PCI nor reconciliation.

Collection belongs in the operation

On payment gateways we do not sell a loose button. Cards, SINPE, and local rails have to fire inventory, invoice, and the next step. Ecommerce that looks good and charges badly loses Friday. If PCI scope scares you, the checkout design is wrong — not because “compliance is expensive.”

Not storing the card number is not shyness. It is the correct design.

If you plan to sell more in the second half, quote the collection flow before you quote the ad. The banner is useless if the gateway fails or the bank cuts you off.

What needs to be built or connected?

Tell us the systems and how the team works. You get a concrete plan.

Request a quote