PCI DSS 4.0: what it asks of unsupported software
Requirement 12.3.4 asks for a review of hardware and software at least every 12 months: that vendors still supply timely security fixes, documentation of end-of-life announcements, and a remediation plan for outdated technology approved by senior management. 6.3.3 sets one month for critical patches. A3.3.2 repeats the annual technology review for designated entities.
- Scheme
- PCI DSS 4.0 (PCI Security Standards Council)
- When it is placed
- Placed when you say PCI DSS applies. Appendix A3 (designated entities) attaches only when you tick that you are one.
- Held text
- PCI DSS 4.0 (PCI Security Standards Council) on the standards site, read 30 Sep 2026
Findings that cite it
7 of 10- 1 Past vendor security support, still installed
- 2 Extended or paid support only
- 3 Ends before your next assessment
- 4 Ends within the window you set
- 7 Not in the lifecycle record
- 9 Unsupported with no exception recorded
- 10 Evergreen product behind the current release
The clauses cited
3 clausesPCI DSS 4.0 6.3.3Timely installation of security patches6.3.3 Timely installation of security patches. All system components must be shielded from known vulnerabilities by applying relevant security patches or updates such that: patches or updates addressing critical vulnerabilities, as ranked under Requirement 6.3.1, must go in within one month of their release; and every other relevant security patch or update is installed within a suitable time frame set by the entity's own assessment of how critical the risk is to its environment, using the Requirement 6.3.1 ranking process. It applies to all entities and all system components. Customized approach objective: exploitation of a known vulnerability cannot be used to compromise system components.
PCI DSS 4.0 12.3.4Annual review of hardware and software technologies12.3.4 Annual review of hardware and software technologies. Hardware and software in use must undergo a check at least every 12 months, covering at minimum: analysis that vendors still supply timely security fixes; analysis that the technologies still support, and do not obstruct, PCI DSS compliance; documentation of industry announcements or trends about a technology, for instance a vendor's end-of-life notice; and a remediation plan for outdated technologies, including those with announced end-of-life, approved by senior management. Objective under the customized approach: hardware and software stay current and vendor supported, and plans to retire or replace unsupported components are reviewed periodically. Future-dated: treated as a best practice up to 31 March 2025 and mandatory since then.
PCI DSS 4.0 A3.3.2A3.3.2 Annual review of hardware and software technologiesA3.3.2 Annual review of hardware and software technologies. Hardware and software technologies must be reviewed every 12 months at a minimum to confirm whether they continue to satisfy the PCI DSS needs of the organization. Applicability: the process includes a plan to remediate any technology that no longer meets those requirements, up to replacing it where appropriate. Related PCI DSS requirements 2, 6 and 12. Guidance: consider vendor support status, firmware currency and vendor changes to products or processes. Applies only to designated entities. Objective under the customized approach: not eligible for the customized approach; only the defined approach can be used.