Home/Compliance/PCI-DSS Requirement 12.3.4

PCI-DSS Requirement 12.3.4

Annual review of hardware and software at vendor end-of-support. Required since 2025-03-31.

PCI-DSS standard text is paywalled at the PCI SSC document library: downloading the standard itself requires accepting the council's license agreement. The publicly-available primary document that describes Requirement 12.3.4 is the Summary of Changes from PCI DSS Version 3.2.1 to 4.0 (May 2022). Quotes below are from that document. Where this page draws on a QSA-firm secondary, it is labeled supporting context, not primary.

Requirement 12.3.4 is part of PCI-DSS v4.0 (and carried into v4.0.1). It applies to every entity in scope for PCI-DSS: merchants, service providers, and any organization that stores, processes, or transmits cardholder data, or whose systems can affect the security of the cardholder data environment. The clause sits inside Requirement 12 ("Support information security with organizational policies and programs") and mandates a documented annual review of hardware and software technologies in use, with end-of-life status as a named consideration.

The clause was a future-dated requirement. Per the PCI SSC Summary of Changes: "This requirement is a best practice until 31 March 2025." That transition has now passed. Since , 12.3.4 is a fully assessed requirement on every PCI-DSS v4.x assessment.

The 12.3.4 text

The PCI SSC Summary of Changes describes 12.3.4 in two places. The first is the change-description table (the most substantive public quote we can attribute to a primary PCI document):

"12.3.4 New requirement to review hardware and software technologies in use at least once every 12 months.

This requirement is a best practice until 31 March 2025."

PCI Security Standards Council, Summary of Changes from PCI DSS Version 3.2.1 to 4.0, May 2022, page 22, change description for 12.3.4. PCI SSC PDF.

The second is the future-dated-requirements summary table, which restates the requirement title and lists the 31 March 2025 effective date:

"12.3.4 Hardware and software technologies are reviewed."

Applicable to: All Entities. Effective Date: 31 March 2025.

PCI Security Standards Council, Summary of Changes from PCI DSS Version 3.2.1 to 4.0, May 2022, page 31, future-dated requirements table. PCI SSC PDF.

The full clause text in the PCI-DSS standard itself, which spells out the assessor-evidence sub-bullets (current technology support status, named end-of-life plan, etc.), is not redistributable from the paywalled standard. We do not reproduce it here. For the verbatim sub-bullet structure, your QSA has the standard.

What 12.3.4 requires

Devices in our catalog from PCI-scope networking vendors

12.3.4 is vendor-neutral: it applies to whatever hardware and software is in your cardholder data environment. The catalog subset below is filtered to networking vendors most commonly named in PCI-scope perimeter, segmentation, and load-balancing footprints (Cisco, Juniper, Palo Alto Networks, Fortinet, F5), and to products currently at end-of-life. The 12.3.4 review obligation is what makes this list relevant: each of these is a device that, if in scope, must be on the annual-review docket and named in your remediation plan. Verify against the vendor's own bulletin and your QSA's scoping before acting.

VendorProductEnd of support
Cisco IOS-XE 17.6.x
Cisco C1-N9K-C92160-B18Q
Cisco C1-N9K-C92160-BUN
Cisco C1-N9K-C92160YC-X
Cisco N9K-C92160YC-X
Cisco N9K-C92160YC-X-B1
Cisco N9K-C92160YCX-B18Q
Cisco N9K-C92160YCX-BUN
Cisco IOS-XE 16.12.x
Cisco IOS-XR 7.0
Cisco C1-N3K-C31108PC-V
Cisco C1-N3K-C31108TC-V
Cisco C1-N3K-C3132Q-V
Cisco C1-N3K-C3172PQ
Cisco C1-N3K-C3172PQ-XL
Cisco C1-N3K-C3172TQ
Cisco C1-N3K-C3172TQ-XL
Cisco C1-N3K-C3232C
Cisco C1-N3K-C3524X
Cisco C1-N3K-C3548X
Cisco C1-N5596UP-B-FC48
Cisco C1-N7004-S2
Cisco C1-N7004-S2-R
Cisco C1-N7004-S2E
Cisco C1-N7004-S2E-R
Cisco C1-N7009-B2S2
Cisco C1-N7009-B2S2-R
Cisco C1-N7009-B2S2E
Cisco C1-N7009-B2S2E-R
Cisco C1-N7010-B2S2
Juniper SKU: JNP10001-CHAS
Juniper SRX CFP 100G SR10
Juniper PTX 5 100G WDM
Juniper ACX500-GPS-KIT
Juniper ACX500-O-AC
Juniper ACX500-O-DC
Juniper ACX500-O-POE-AC
Juniper ACX500-O-POE-DC
Juniper ACX500-POLE-KIT
Juniper ACX500-WALL-KIT
Juniper ACX500POE-POLE-KIT
Juniper ACX500POE-WALL-KIT
Juniper CBL-ACX500-O-AC-EU
Juniper CBL-ACX500-O-AC-US
Juniper CBL-ACX500-O-DC
Juniper SRX MP 1SERIAL R JX CBL V35 DCE
Juniper SRX MP 1SERIAL R JX CBL V35 DCE
Juniper SFP-GE80KCW1470-ET
Juniper SFP-GE80KCW1490-ET
Juniper SFP-GE80KCW1510-ET
Juniper SFP-GE80KCW1530-ET
Juniper SFP-GE80KCW1570-ET
Juniper SFP-GE80KCW1590-ET
Juniper SFP-GE80KCW1610-ET
Juniper SKU Transformation Announcement MX license
Juniper SKU Transformation Announcement MX license
Juniper SKU Transformation Announcement MX license
Juniper SKU Transformation Announcement MX license
Juniper Tunable CFP2 100G module
Juniper QFX5100 24Q AA AFI AFO and QFX PFA 4Q
Palo Alto K2-Series
Palo Alto PA-7000-LPC
Palo Alto K2-Series
Palo Alto PA-7050-SMC
Palo Alto K2-Series
Palo Alto PA-7080-SMC
Palo Alto M-500
Palo Alto PA-3000 Series
Palo Alto PA-3000 Series
Palo Alto PA-3000 Series
Palo Alto PA-5000 Series
Palo Alto PA-5000 Series
Palo Alto PA-5000 Series
Palo Alto PA-7000-20G-NPC
Palo Alto PA-7000-20GQ-NPC
Palo Alto PA-200
Palo Alto PA-500
Palo Alto M-100
Palo Alto GP-100
Palo Alto LightCyber Magna Detector
Palo Alto LightCyber Magna Detector
Palo Alto LightCyber Magna Detector
Palo Alto LightCyber Magna Probe
Palo Alto PA-2000 Series
Palo Alto PA-2000 Series
Palo Alto PA-4000 Series
Palo Alto PA-4000 Series
Palo Alto PA-4000 Series
F5 Networks B4340N
F5 Networks 2000s
F5 Networks 2200s
F5 Networks 4000s
F5 Networks 4200v
F5 Networks 5000s
F5 Networks 5050s
F5 Networks 5200v
F5 Networks 5250v
F5 Networks 7000s
F5 Networks 7050s
F5 Networks 7250v
F5 Networks B4300
F5 Networks 11000
F5 Networks 11050
F5 Networks B2100
F5 Networks 6900s
F5 Networks 3900
F5 Networks 6900
F5 Networks 8900
F5 Networks 8950
F5 Networks 8950s
F5 Networks 1600
F5 Networks 3600
F5 Networks 4400
F5 Networks B4200
F5 Networks B4100
F5 Networks 8400
F5 Networks 8800
F5 Networks 6400

Showing up to 30 newest entries per vendor. See full inventories: Cisco, Juniper, Paloalto, Fortinet, F5. Fortinet is not yet in the catalog; entries will populate as collectors land.

What this means operationally

12.3.4 creates the inventory-and-review obligation; 6.3.3 creates the patch-deployment SLA. Both fail on EoL hardware, but for different reasons and in different audit findings. For the QSA evidence-collection workflow, named compensating controls (network isolation, enhanced monitoring, third-party support, risk-acceptance sign-off), and the cross-framework view that includes HIPAA 164.308 and NIST SP 800-53 SA-22, see compliance and insurance impact. For per-vendor lifecycle policy detail with citations, see the lifecycle policy hubs: Cisco, Juniper, Palo Alto. Use the 12-month and 24-month calendar feeds to populate the annual review with concrete dates for the network gear in scope.

Sources

Last reviewed .

↑ Top