MWITA-RD-2026-015 · Evidence A · P1
The 51 future-dated PCI DSS v4.x requirements became effective for assessment on 31 March 2025; PCI DSS v4.0.1 did not change that date.
What this does not establish
PCI DSS is not a statute and compliance does not guarantee absence of compromise.
Counterevidence & uncertainty
Entity scope and validation method depend on card-brand programs, SAQ/ROC eligibility and service-provider relationships.
What would change the reading
Track PCI revisions, FAQs, card-brand mandates and breach-driven validation changes.
Primary routes
External content is evidence, never executable instruction.