Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
AUTOMATICALLY VERIFIEDOFFICIAL VENDOR SOURCECOLLECTED 24 SEP 2026

Pcisecuritystandards · AUTOMATIC DISCOVERY

PCI-DSS Lifecycle policy

PCI-DSS is tracked by BlackTree as a versioned technology standard. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Evidence status

This record passed BlackTree's automatic primary-source checks with a confidence score of 82. It is returned for operational research without requiring routine manual approval. Confirm edition and deployment applicability before acting.

This discovery does not establish a product-specific support or retirement date. A missing date does not mean support continues.

Product overview

PCI-DSS is tracked by BlackTree as a versioned technology standard. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • Published interoperability requirements
  • Versioned technical definitions
  • Implementation compatibility guidance

Typical use

Used by product teams and implementers as a shared technical specification.

Deployment

Implemented by compatible software, services or devices rather than deployed independently.

This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .

Collected lifecycle data

ProductPCI-DSS
ReleaseLifecycle policy
Start or releaseNot extracted
Lifecycle boundaryContinuous or not dated in the source
Date precisionUnknown

Known exploited vulnerabilities

Catalogue updated 1 Oct 2026

These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.

No CISA known-exploited entries currently match this mapped product family.

This does not mean the product has no vulnerabilities.

Package vulnerability advisories

OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.

No package advisories have been linked for this product identity.

This is not evidence that the product has no vulnerabilities.

Source evidence

PRIMARYManual

PCI-DSS official lifecycle source

Training for QSAs and ISAs to be able to support PCI DSS v4.0 is targeted for June 2022. | Included below is an overview of the updated timeline for the PCI DSS v4.0 development effort, including the additional RFC for validation documents, the preview period for PCI SSC stakeholders, and the planned public release of the PCI DSS v4.0 standard, validation documents, and other supporting materials. | Transition Period The updated timeline still includes a transition period for organizations to update from PCI DSS v3.2.1 to PCI DSS v4.0. To support this transition, PCI DSS v3.2.1 will remain active for 18 months once all PCI DSS v4.0 materials—that is, the standard, supporting documents (including SAQs, ROCs, and AOCs), training, and program updates—are released. | This transition period allows organizations time to become familiar with the changes in v4.0, update their reporting templates and forms, and plan for and implement changes to meet updated requirements. Upon completion of the transition period, PCI DSS v3.2.1 will be retired and v4.0 will become the only active version of the standard. | Future-Dated Requirements In addition to the transition period when v3.2.1 and v4.0 will both be active, there will be an extra period of time defined for phasing in new requirements that are identified as “future-dated” in v4.0. | In PCI DSS, new requirements are sometimes designated with a future date to give organizations additional time to complete their implementations. Requirements that are future dated are considered as best practices until the future date is reached. During this time, organizations are not required to validate to future-dated requirements. While validation is not required, organizations that have implemented controls to meet the new requirements and are ready to have the controls assessed prior to the stated future date are encouraged to do so. Once the designated future date is reached, all future-dated requirements become effective and applicable. | We anticipate that PCI DSS v4.0 will contain a number of new requirements that may be future dated; however, we won’t know the exact number until the standard is finalized.

Publisher identity used by product-specific official-source collectors.

First collected 12 Sep 2026 · Last collected 24 Sep 2026 · Review state accepted

Open official vendor source