Future-Dated Requirements
Future-dated requirements are a set of new PCI DSS controls introduced with version 4.x that organizations were given extra time to adopt. During the transition period they were treated as a recommended best practice, and they became mandatory as of 31 March 2025. This staged approach gave organizations time to implement the newer, often more complex controls before they were formally assessed against them.
Future-dated requirements are a subset of the new requirements added in PCI DSS v4.0 (and carried through v4.0.1) that were designated as best practice until their effective date of 31 March 2025, after which they became mandatory and are assessed as part of a normal PCI DSS assessment. According to PCI Security Standards Council material cited here, of the 64 new requirements introduced in v4.x, 51 were future-dated with that 31 March 2025 effective date. Applicability of a given future-dated requirement depends on whether it is in scope for the specific entity and environment being assessed; entities should confirm exact requirement numbering, wording, applicability, and dates against the current published PCI DSS standard rather than relying on a fixed citation, since these differ between versions. This term is specific to PCI DSS and should not be conflated with timelines or requirements under separate standards such as PA-DSS, the PCI Software Security Framework, PCI PIN, PCI P2PE, or PCI 3DS.
Why it matters
Future-dated requirements represented the most operationally significant part of the PCI DSS v4.x transition. Of the 64 new requirements introduced in v4.x, 51 were future-dated with an effective date of 31 March 2025, meaning organizations were assessed against them only after that date. Because many of these controls are more complex than earlier requirements—touching areas such as authentication, automated log review, and continuous monitoring—the staged timeline gave entities room to plan, budget, and implement before formal assessment. Missing that transition window can leave an organization out of compliance against controls that are now fully in effect and assessed as part of a normal PCI DSS assessment.
Who it's relevant to
Inside Future-Dated Requirements
Common questions
Answers to the questions practitioners most commonly ask about Future-Dated Requirements.