PCI DSS 4.0.1 DMARC enforcement is mandatory for every entity in scope
PCI DSS 4.0.1 closed out the transition period from 4.0 in early 2025. Requirements 5.4.1 (anti-phishing / DMARC), 12.3.3 (cryptography inventory), and the service-provider appendix requirements all apply now. Vysiro maps every finding to the specific requirement ID so the evidence is auditor-ready.
The four PCI requirements Vysiro covers end-to-end
Anti-phishing controls (DMARC)
Req 5.4.1Processes and mechanisms detect and protect personnel from phishing attacks. In practice: DMARC enforced (p=quarantine or p=reject) on every domain that sends mail.
Vysiro covers: DMARC presence, DMARC policy strength, SPF alignment, DKIM signing, BIMI logo authority.
MFA / strong authentication on cardholder access
Req 8.3.6Not a DNS check, but Vysiro flags exposed auth endpoints (RDP, SSH, admin panels) that should be behind MFA + VPN.
Vysiro covers: Exposed-port flags, banner fingerprinting for admin panels.
Cryptography inventory
Req 12.3.3Document all cryptographic cipher suites and protocols in use, including expected expiry of certificates and a plan to migrate. PQC-aware preferred.
Vysiro covers: TLS protocol + cipher inventory, certificate chain audit, certificate lifecycle alerts, PQC readiness check.
Service providers + appendix A requirements
Req A1 / A3If you're a PCI service provider, your supply-chain hygiene (DMARC + DNSSEC + CAA + cert lifecycle) is the customer's audit evidence too.
Vysiro covers: Multi-tenant scan + per-domain evidence pack export.
The non-compliance math
Acquirer fines for PCI non-compliance: $5,000 - $100,000 per month per merchant tier. A single breach without DMARC enforcement triggers forensic-investigation costs that scale from $10K (level 4) to $500K+ (level 1) before any card-brand penalties. The DMARC fix is a TXT record.
Have the evidence pack before the QSA asks
Free scan returns the requirement-mapped findings. Growth tier exports the full PDF the QSA can attach to the ROC.
Run PCI readiness scan