You encrypt the data. You still fail the assessment.
Encryption is present, so the control feels done. But PCI DSS v4.0 tests against a precise definition of strong cryptography, not a general concept, and assessors trace algorithm name, key length, mode of operation, and key management together. Teams that treat cryptography as an implementation detail rather than a control discipline routinely produce findings at assessment time. If you cannot show your AES key length, cipher mode, and ECC curve choices are defensible, you carry compensating controls or remediation commitments that delay your Report on Compliance.