PCI DSS 4.0.1 and DORA Are Now Fully Enforced. Grace Periods Are Over.
For the past two years, payment and financial-services security regulation has mostly been about preparation. That window has closed. PCI DSS 4.0.1, the EU's Digital Operational Resilience Act (DORA), and New York's NYDFS Part 500 are all now in full enforcement, with no grace periods remaining for the requirements that used to carry "future-dated" caveats.
What actually changed
DORA became enforceable in January 2025 and requires regulated financial entities to run formal ICT risk management programmes, conduct resilience testing, maintain oversight of critical technology providers, and report major incidents within hours rather than days - with penalties that can reach 2% of global annual turnover. Through 2026, EU supervisors have shifted from checking whether firms have a DORA plan on paper to demanding evidence of ongoing operational resilience: real test results, real third-party risk registers, not intentions.
PCI DSS 4.0.1 closes out the last of the standard's "future-dated" requirements that were previously optional best practice, including stronger multi-factor authentication coverage and more rigorous scoping of the cardholder data environment. If your platform touches card data - even indirectly, through a payment processor's hosted fields - PCI DSS 4.0.1 requirements now apply in full.
What this means for fintech and payments operators
- Multi-factor authentication is no longer a "nice to have" for any access path into systems that touch cardholder or customer financial data - phishing-resistant MFA based on FIDO2 is fast becoming the expected baseline across DORA, PCI DSS, and NYDFS alike.
- Vendor oversight is now an explicit, auditable requirement, not an assumption - DORA's Critical Third-Party Provider designations, PCI DSS's TPSP requirements, and NYDFS's third-party service provider guidance all now expect documented, ongoing monitoring of the vendors in your payment chain.
- Incident reporting clocks are short and unforgiving. Know, in advance, who declares an incident "material," and how fast your organisation can actually produce a report once that call is made - not just what the policy document says.
The common thread across DORA, PCI DSS 4.0.1, and NYDFS Part 500 is that regulators now expect proof, not policy. A penetration test report, a resilience test result, and a current vendor risk register are the kind of evidence that satisfies all three at once.
Sources
Have a security question of your own?
Talk to a Security Expert →