Navigating the PCI DSS 4.0 transition and meeting compliance with phishing-resistant YubiKeys

In just a few days, on March 31, 2025, decision makers in industries that involve payment processing – including financial services, retail & hospitality and telecommunications – are tasked to finalize the transition to Payment Card Industry Data Security Standard (PCI DSS) 4.0. This deadline marks a critical juncture for all organizations handling payment card data, as compliance with the updated standards is essential for maintaining robust security and avoiding potential penalties. It’s imperative for organizations to assess current security measures and ensure alignment with PCI DSS 4.0 requirements: failing to meet this deadline could not only result in non-compliance penalties – but a continued increase in vulnerability to phishing attacks. 

The PCI Security Standards Council (SCC) continues to demonstrate investment and expertise as they enhanced the core 4.0 standard with a 4.0.1 update. The latest revision speaks to the need to ensure digital identities are tied to individuals, to prove that identity at regular intervals, and to implement strong multi-factor authentication (MFA) in line with best practices. Notably, PCI DSS 4.0 speaks to the need for MFA in line with NIST Special Publication 800-63’s definition of phishing-resistant MFA – including FIDO2/WebAuthn-based authentication like YubiKeys or a Smart Card (YubiKeys can also be used as PIV-compatible Smart Cards). The requirement also specifically references the FIDO Alliance when choosing authentication factors.

Across financial services, account lockouts due to phishing and credential theft demonstrate the need (and requirement) for strong, phishing-resistant MFA. However, PCI DSS goes one step further and acknowledges the requirement to ease the reliance on human knowledge, asking for consideration of how users interact with systems and how to make authentication as easy as possible without putting the burden on the user. When thinking about an authentication solution that meets the requirements, it’s important to consider a solution that is user-centric, strongly tied to identity, and phishing-resistant.

How YubiKeys meet PCI DSS 4.0 compliance

Financial institutions and organizations dealing with payment processing information are prime targets for cyber criminals, with phishing attacks and account takeovers posing significant risks. Even AI-driven phishing attacks exploit human vulnerabilities while leveraging phishing kits and malware-as-a-service. PCI DSS 4.0 includes a handful of requirements that were designed to address evolving security threats and ensure that organizations handling payment card data maintain robust cybersecurity practices.

Long story short: the weaker your MFA posture, the greater your compliance burden. This means longer cybersecurity policies, more user training and more controls to manage risk. 

The solution? Apply strong phishing-resistant MFA to all employees in order to create phishing-resistant users

As hardware security keys that contain device-bound passkeys, YubiKeys play a pivotal role in helping achieve this goal while maintaining PCI DSS 4.0 compliance. The use of YubiKeys ensures that even if credentials are compromised, attackers cannot gain access without the physical key. The touch sensor on the YubiKey verifies that the user is a real human and that the authentication is done with real intent as it can’t be triggered by a remote attacker or malware. Utilizing this level of  high security measures not only helps organizations comply with PCI DSS 4.0, but also reinforces commitment to protecting clients and customer data while maintaining brand reputation. 

For more about the requirements for PCI DSS 4.0, we welcome you to check out our recent webinars here and here, as well as our solution brief.

Talk to our teamTalk to our team

Share this article:


  • Ditching passwords for good: Celebrating the inaugural World Passkey DayHave you ever been stuck in a relationship with someone who constantly lets you down, exposes your secrets, and leaves you vulnerable? Odds are you cut your losses, packed up your things and moved on. Today is the day to do the same with your passwords: say goodbye forever! The reality is a majority of […]Read morepasskeyspasswordlessWorld Passkey Day
  • Digital security’s unique role in protecting our environmentAs sustainability expands to include social, economic, and technological challenges, cybersecurity has emerged as a top global threat – with cybercrime projected to cost $12 trillion this year. Stolen credentials and phishing account for 80% of breaches. At Yubico, making the world more secure is just part of how we care for the world around […]Read moreCSREarth DaySecure It ForwardSustainability
  • Breaking down Australia’s plan to combat AI-driven phishing scamsAcross Australia, cybercrime continues to be a major challenge impacting businesses, critical infrastructure and consumers alike. The use of AI by bad actors across the spectrum of cybercrime is on the rise, and as a result, credential phishing scams are becoming increasingly sophisticated. AI is effectively helping to lower the cost of phishing and increase […]Read moreAIAPACAustraliaphishing
  • 5 fast cybersecurity tips to clean up your digital lifeWith today being Identity Management Day, now is the perfect time to take stock of your online presence, update security settings, and ensure that your personal data remains protected from cyber threats like phishing. We’re also seeing increasing concerns of DeepSeek and other AI tools around data privacy making these kinds of attacks more successful […]Read morebest practices