Unsupported Software Findernotice of vendor support

PCI DSS 4.0: what it asks of unsupported software

Requirement 12.3.4 asks for a review of hardware and software at least every 12 months: that vendors still supply timely security fixes, documentation of end-of-life announcements, and a remediation plan for outdated technology approved by senior management. 6.3.3 sets one month for critical patches. A3.3.2 repeats the annual technology review for designated entities.

Scheme
PCI DSS 4.0 (PCI Security Standards Council)
When it is placed
Placed when you say PCI DSS applies. Appendix A3 (designated entities) attaches only when you tick that you are one.
Held text
PCI DSS 4.0 (PCI Security Standards Council) on the standards site, read 30 Sep 2026

Findings that cite it

7 of 10

The clauses cited

3 clauses
PCI DSS 4.0 6.3.3Timely installation of security patches

6.3.3 Timely installation of security patches. All system components must be shielded from known vulnerabilities by applying relevant security patches or updates such that: patches or updates addressing critical vulnerabilities, as ranked under Requirement 6.3.1, must go in within one month of their release; and every other relevant security patch or update is installed within a suitable time frame set by the entity's own assessment of how critical the risk is to its environment, using the Requirement 6.3.1 ranking process. It applies to all entities and all system components. Customized approach objective: exploitation of a known vulnerability cannot be used to compromise system components.

What an assessor asks to see: Patch management procedure stating the one-month deadline for critical patches and time frames for others; Patch compliance reports per system component showing install dates against vendor release dates; Risk-based rationale or targeted risk analysis for non-critical patch time frames; Exception register for patches that could not be applied, with compensating measures; Sample of critical advisories traced to installation evidence
Where software lists usually fall short: Critical patches applied more than one month after release because of change freeze windows; Network devices, hypervisors or appliances excluded from patch reporting; No defined time frame for non-critical patches, so they accumulate indefinitely
Source: PCI DSS 4.0 (PCI Security Standards Council), read 30 Sep 2026
PCI DSS 4.0 12.3.4Annual review of hardware and software technologies

12.3.4 Annual review of hardware and software technologies. Hardware and software in use must undergo a check at least every 12 months, covering at minimum: analysis that vendors still supply timely security fixes; analysis that the technologies still support, and do not obstruct, PCI DSS compliance; documentation of industry announcements or trends about a technology, for instance a vendor's end-of-life notice; and a remediation plan for outdated technologies, including those with announced end-of-life, approved by senior management. Objective under the customized approach: hardware and software stay current and vendor supported, and plans to retire or replace unsupported components are reviewed periodically. Future-dated: treated as a best practice up to 31 March 2025 and mandatory since then.

What an assessor asks to see: Technology review report covering support status and patch availability; End-of-life tracking register with vendor announcements; Senior management approved remediation plan for outdated technologies; Firmware and version inventory
Where software lists usually fall short: Review omits network device firmware or embedded systems; End-of-life systems identified but no approved remediation plan; Plan exists but lacks senior management approval
Source: PCI DSS 4.0 (PCI Security Standards Council), read 30 Sep 2026
PCI DSS 4.0 A3.3.2A3.3.2 Annual review of hardware and software technologies

A3.3.2 Annual review of hardware and software technologies. Hardware and software technologies must be reviewed every 12 months at a minimum to confirm whether they continue to satisfy the PCI DSS needs of the organization. Applicability: the process includes a plan to remediate any technology that no longer meets those requirements, up to replacing it where appropriate. Related PCI DSS requirements 2, 6 and 12. Guidance: consider vendor support status, firmware currency and vendor changes to products or processes. Applies only to designated entities. Objective under the customized approach: not eligible for the customized approach; only the defined approach can be used.

What an assessor asks to see: Annual technology review report; Hardware and software inventory with vendor support and end-of-life dates; Firmware version currency report; Remediation or replacement plans for non-compliant technologies
Where software lists usually fall short: Review done but no remediation plan for end-of-life items; Firmware and embedded devices left out of the review; Review older than 12 months
Source: PCI DSS 4.0 (PCI Security Standards Council), read 30 Sep 2026

See the specimen list runCheck your own list