HeadlinesBriefing favicon HeadlinesBriefing.com

PCI DSS 4.0.1: DMARC Requirement Explained

Hacker News •
×

PCI DSS v4.0.1 does not explicitly mandate DMARC. Requirement 5.4.1 makes automated anti-phishing mechanisms mandatory, with DMARC, SPF, and DKIM listed as examples in the Guidance column. This requirement became fully effective on March 31, 2025.

While the standard doesn't name DMARC, it is the control most assessors expect to see. The PCI DSS v4.0.1 standard, published by the PCI Security Standards Council, applies to organizations handling cardholder data. Requirement 5.4.1, new in v4.0, focuses on protecting users against phishing attacks through automated mechanisms.

Organizations can satisfy this requirement via a defined approach (implementing controls as written) or a customized approach (using alternative controls with documented risk analysis). While DMARC is not a direct mandate, vendors like Skysnag and Proofpoint suggest demonstrating an enforcement policy (p=quarantine or p=reject) for active protection, though the standard itself does not require a specific enforcement level.