PCI DSS 4.0.1 raised the bar in several places that matter directly to how organizations architect network access to the cardholder data environment (CDE). Zero trust, identity-first networking touches a meaningful share of the standard’s 12 requirements — and two of the changes in v4.0.1 specifically increase how relevant that model has become.
Three Key Takeaways
1. Two “best practice” requirements are now mandatory — and both favor a zero trust architecture. As of March 31, 2025, MFA for all non-console access into the CDE (8.4.2) — not just administrative access — became fully enforced, along with automated protection for public-facing web applications (6.4.2). A device enrolled in a zero trust network carries its own cryptographic identity via an installed certificate, which can serve as the “something you have” factor in an MFA scheme for a much broader population of users than before. And because this model can remove public-facing exposure of an application entirely — replacing an internet-routable endpoint with private, identity-based access — it directly shrinks the attack surface that the WAF/RASP requirement exists to protect in the first place.
2. NetFoundry functions as a network security control without being a traditional firewall — and v4.0.1 now explicitly recognizes that. The updated standard broadened its definition of “network security controls” beyond physical firewalls to include virtual devices, cloud access controls, and software-defined networking technology. A zero trust overlay that only allows previously authenticated and authorized traffic into a software-defined data plane — rejecting everything else by default — maps directly onto Requirement 1’s core intent of restricting and controlling traffic in and out of the CDE.
3. Overlay-based segmentation can meaningfully reduce assessment scope — but it now comes with a testing obligation attached. Network segmentation isn’t itself a PCI DSS requirement, but it’s the most effective lever for shrinking what’s actually in scope for assessment. An overlay approach can segment systems on a shared underlying network without a traditional network redesign. The catch in v4.0.1: any entity relying on segmentation to reduce scope must now penetration-test those segmentation controls at least annually (every six months for service providers) — and that testing needs to explicitly cover the boundaries the overlay is enforcing.
The Caveat Worth Remembering
Several requirements — 3 (stored account data), 9 (physical access) — simply don’t apply to a network connectivity solution, and others (5, 6, 11, 12) are primarily binding on whoever holds or processes cardholder data, with NetFoundry applying equivalent internal practices (SOC 2, annual pentesting, weekly vulnerability scanning) rather than being directly assessed against them. The alignment described here is a description of technical capability, not a compliance certification — a QSA still needs to validate how any of this maps to a specific environment and scope.