Requirement 4: Protect Cardholder Data with Strong Cryptography During Transmission Over Open, Public Networks

The use of strong cryptography provides greater assurance in preserving data confidentiality, integrity, and non-repudiation.

Any time that cardholder data is sent wirelessly, over the internet, or across any network that is not private, strong encryption must be used to protect the cardholder data. Deprecated and outdated encryption technologies such as SSL Versions 2-3, TLS version 1.0 and WEP are no longer sufficient to protect cardholder data. Wireless networks should use WPA2 at a minimum (WPA3 preferred where supported) with strong passphrases, and web traffic must be protected with TLS 1.2 or later (TLS 1.3 preferred), using strong cipher suites. In addition to HTTPS, VPN connections and IPSec tunnels using strong encryption protocols can be leveraged to meet this requirement.

Default digital certificates provided by manufacturers must be replaced with trusted certificates. Only digital certificates issued by trusted certificate authorities should be relied on for authentication. Certificate validity must be checked regularly, and organizations should maintain an inventory of trusted keys and certificates.

Unprotected cardholder data must never be sent over e-mail, instant messaging, text, or any other user messaging technology.

Go on to Requirement 5 - Malware.

Go back to Requirement 3 - Data Storage.