Skip to main content
Live since March 31, 2025

PCI DSS 4.0.1 DMARC enforcement is mandatory for every entity in scope

PCI DSS 4.0.1 closed out the transition period from 4.0 in early 2025. Requirements 5.4.1 (anti-phishing / DMARC), 12.3.3 (cryptography inventory), and the service-provider appendix requirements all apply now. Vysiro maps every finding to the specific requirement ID so the evidence is auditor-ready.

The four PCI requirements Vysiro covers end-to-end

Anti-phishing controls (DMARC)

Req 5.4.1

Processes and mechanisms detect and protect personnel from phishing attacks. In practice: DMARC enforced (p=quarantine or p=reject) on every domain that sends mail.

Vysiro covers: DMARC presence, DMARC policy strength, SPF alignment, DKIM signing, BIMI logo authority.

MFA / strong authentication on cardholder access

Req 8.3.6

Not a DNS check, but Vysiro flags exposed auth endpoints (RDP, SSH, admin panels) that should be behind MFA + VPN.

Vysiro covers: Exposed-port flags, banner fingerprinting for admin panels.

Cryptography inventory

Req 12.3.3

Document all cryptographic cipher suites and protocols in use, including expected expiry of certificates and a plan to migrate. PQC-aware preferred.

Vysiro covers: TLS protocol + cipher inventory, certificate chain audit, certificate lifecycle alerts, PQC readiness check.

Service providers + appendix A requirements

Req A1 / A3

If you're a PCI service provider, your supply-chain hygiene (DMARC + DNSSEC + CAA + cert lifecycle) is the customer's audit evidence too.

Vysiro covers: Multi-tenant scan + per-domain evidence pack export.

The non-compliance math

Acquirer fines for PCI non-compliance: $5,000 - $100,000 per month per merchant tier. A single breach without DMARC enforcement triggers forensic-investigation costs that scale from $10K (level 4) to $500K+ (level 1) before any card-brand penalties. The DMARC fix is a TXT record.

Have the evidence pack before the QSA asks

Free scan returns the requirement-mapped findings. Growth tier exports the full PDF the QSA can attach to the ROC.

Run PCI readiness scan