Home/Compliance/PCI-DSS Requirement 12.3.4

PCI-DSS Requirement 12.3.4

Annual review of hardware and software at vendor end-of-support. Required since 2025-03-31.

PCI-DSS standard text is paywalled at the PCI SSC document library: downloading the standard itself requires accepting the council's license agreement. The publicly-available primary document that describes Requirement 12.3.4 is the Summary of Changes from PCI DSS Version 3.2.1 to 4.0 (May 2022). Quotes below are from that document. Where this page draws on a QSA-firm secondary, it is labeled supporting context, not primary.

Requirement 12.3.4 is part of PCI-DSS v4.0 (and carried into v4.0.1). It applies to every entity in scope for PCI-DSS: merchants, service providers, and any organization that stores, processes, or transmits cardholder data, or whose systems can affect the security of the cardholder data environment. The clause sits inside Requirement 12 ("Support information security with organizational policies and programs") and mandates a documented annual review of hardware and software technologies in use, with end-of-life status as a named consideration.

The clause was a future-dated requirement. Per the PCI SSC Summary of Changes: "This requirement is a best practice until 31 March 2025." That transition has now passed. Since , 12.3.4 is a fully assessed requirement on every PCI-DSS v4.x assessment.

The 12.3.4 text

The PCI SSC Summary of Changes describes 12.3.4 in two places. The first is the change-description table (the most substantive public quote we can attribute to a primary PCI document):

"12.3.4 New requirement to review hardware and software technologies in use at least once every 12 months.

This requirement is a best practice until 31 March 2025."

PCI Security Standards Council, Summary of Changes from PCI DSS Version 3.2.1 to 4.0, May 2022, page 22, change description for 12.3.4. PCI SSC PDF.

The second is the future-dated-requirements summary table, which restates the requirement title and lists the 31 March 2025 effective date:

"12.3.4 Hardware and software technologies are reviewed."

Applicable to: All Entities. Effective Date: 31 March 2025.

PCI Security Standards Council, Summary of Changes from PCI DSS Version 3.2.1 to 4.0, May 2022, page 31, future-dated requirements table. PCI SSC PDF.

The full clause text in the PCI-DSS standard itself, which spells out the assessor-evidence sub-bullets (current technology support status, named end-of-life plan, etc.), is not redistributable from the paywalled standard. We do not reproduce it here. For the verbatim sub-bullet structure, your QSA has the standard.

What 12.3.4 requires

Devices in our catalog from PCI-scope networking vendors

12.3.4 is vendor-neutral: it applies to whatever hardware and software is in your cardholder data environment. The catalog subset below is filtered to networking vendors most commonly named in PCI-scope perimeter, segmentation, and load-balancing footprints (Cisco, Juniper, Palo Alto Networks, Fortinet, F5), and to products currently at end-of-life. The 12.3.4 review obligation is what makes this list relevant: each of these is a device that, if in scope, must be on the annual-review docket and named in your remediation plan. Verify against the vendor's own bulletin and your QSA's scoping before acting.

VendorProductEnd of support
Cisco Cisco ASR 9000 400-Gbps IPoDWDM Line Card
Cisco Cisco ASR 9000 Modular Port adapters 1X40GE, 2X10GE
Cisco Cisco ASR 9000 Modular Port adapters 1X40GE, 2X10GE
Cisco Cisco ASR 9000 400-Gbps IPoDWDM Line Card
Cisco Cisco ASR 9000 400-Gbps IPoDWDM Line Card
Cisco Cisco Select ISR 890
Cisco Cisco Select ISR 890
Cisco Cisco Select ISR 890
Cisco Cisco Select 4300ISR
Cisco Cisco Select 4300ISR
Cisco Cisco Select 4300ISR
Cisco Cisco Select 4300ISR
Cisco Cisco Select 4300ISR
Cisco Cisco Select 4300ISR
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Juniper SRX/MX Regional Power cables
Juniper SRX/MX Regional Power cables
Juniper SRX/MX Regional Power cables
Juniper SRX/MX Regional Power cables
Juniper SRX/MX Regional Power cables
Juniper SRX/MX Regional Power cables
Juniper SRX/MX Regional Power cables
Juniper SRX/MX Regional Power cables
Juniper SRX/MX Regional Power cables
Juniper SRX/MX Regional Power cables
Juniper MX legacy MX5 MX10 MX40 MX80 MPCs MICs Routing Engines Switch Fabrics and affected Chassis bundles
Juniper MX legacy MX5 MX10 MX40 MX80 MPCs MICs Routing Engines Switch Fabrics and affected Chassis bundles
Juniper MX legacy MX5 MX10 MX40 MX80 MPCs MICs Routing Engines Switch Fabrics and affected Chassis bundles
Juniper CTP150-IM-T1E1
Juniper MX legacy MX5 MX10 MX40 MX80 MPCs MICs Routing Engines Switch Fabrics and affected Chassis bundles
Juniper MX legacy MX5 MX10 MX40 MX80 MPCs MICs Routing Engines Switch Fabrics and affected Chassis bundles
Juniper MX legacy MX5 MX10 MX40 MX80 MPCs MICs Routing Engines Switch Fabrics and affected Chassis bundles
Juniper MX legacy MX5 MX10 MX40 MX80 MPCs MICs Routing Engines Switch Fabrics and affected Chassis bundles
Juniper MX legacy MX5 MX10 MX40 MX80 MPCs MICs Routing Engines Switch Fabrics and affected Chassis bundles
Juniper MX legacy MX5 MX10 MX40 MX80 MPCs MICs Routing Engines Switch Fabrics and affected Chassis bundles
Juniper MX legacy MX5 MX10 MX40 MX80 MPCs MICs Routing Engines Switch Fabrics and affected Chassis bundles
Juniper MX legacy MX5 MX10 MX40 MX80 MPCs MICs Routing Engines Switch Fabrics and affected Chassis bundles
Juniper MX legacy MX5 MX10 MX40 MX80 MPCs MICs Routing Engines Switch Fabrics and affected Chassis bundles
Juniper MX legacy MX5 MX10 MX40 MX80 MPCs MICs Routing Engines Switch Fabrics and affected Chassis bundles
Juniper MX legacy MX5 MX10 MX40 MX80 MPCs MICs Routing Engines Switch Fabrics and affected Chassis bundles
Juniper MX legacy MX5 MX10 MX40 MX80 MPCs MICs Routing Engines Switch Fabrics and affected Chassis bundles
Juniper MX legacy MX5 MX10 MX40 MX80 MPCs MICs Routing Engines Switch Fabrics and affected Chassis bundles
Juniper MX legacy MX5 MX10 MX40 MX80 MPCs MICs Routing Engines Switch Fabrics and affected Chassis bundles
Juniper MX legacy MX5 MX10 MX40 MX80 MPCs MICs Routing Engines Switch Fabrics and affected Chassis bundles
Juniper MX legacy MX5 MX10 MX40 MX80 MPCs MICs Routing Engines Switch Fabrics and affected Chassis bundles
Palo Alto PAN-OS 10.1
Palo Alto PAN-OS 11.0
Palo Alto PAN-OS 9.1
Palo Alto PAN-OS 10.0
Palo Alto PAN-OS 8.1
Palo Alto PAN-OS 9.0
Palo Alto PAN-OS 7.1
Palo Alto PAN-OS 8.0
Palo Alto PAN-OS 6.1
Palo Alto PAN-OS 7.0
Palo Alto PAN-OS 6.0
Palo Alto PAN-OS 5.0
Palo Alto PAN-OS 4.1
Palo Alto PAN-OS 4.0
Palo Alto PAN-OS 3.1
Palo Alto PAN-OS 2.1
Palo Alto PAN-OS 3.0
Palo Alto PAN-OS 2.0
Palo Alto PAN-OS 1.3
Fortinet Fortinet SP-CABLE-KVM1
Fortinet Fortinet SP-FAZ3500E-PS
Fortinet Fortinet SP-FG3600C-PS
Fortinet Fortinet SP-FG3700D-PS
Fortinet Fortinet SP-FWB3000-PS
Fortinet Fortinet ANT-O6ABGN-0606-O
Fortinet FortiGate-101E
Fortinet FortiGate-140E-POE
Fortinet FortiGate-300E
Fortinet FortiGate-301E
Fortinet FortiGate-500E
Fortinet FortiGate-501E
Fortinet FortiGate-61E
Fortinet FortiGate-Rugged-60D
Fortinet FortiGateRugged 90D
Fortinet FortiWiFi-60E
Fortinet FortiWiFi-61E
Fortinet FortiAnalyzer-400E
Fortinet FortiAnalyzer-200F
Fortinet FortiAnalyzer-300F
Fortinet FortiManager-200F
Fortinet FortiManager-3000F
Fortinet FortiWeb-3010E
Fortinet FortiTokenMobile-LIC-20
Fortinet FAP-224E
Fortinet FAP-421E
Fortinet FAP-423E
Fortinet FortiAP-222E
Fortinet FortiAP-321E
Fortinet FortiRecorder-200D
F5 Networks BIG-IP 16.1
F5 Networks VIPRION B4340N Blade NEBS (A110)
F5 Networks 2000s (C112)
F5 Networks 2200s (C112)
F5 Networks 4000s (C113)
F5 Networks 4200v (C113)
F5 Networks 5000s LTM standalone (C109)
F5 Networks 5050s (C109)
F5 Networks 5200v LTM standalone / SSL (C109)
F5 Networks 5250v (C109)
F5 Networks 7000s LTM standalone (D110)
F5 Networks 7050s (D110)
F5 Networks 7250v (D110)
F5 Networks VIPRION B4300 Blade (A108)
F5 Networks BIG-IP 15.1
F5 Networks BIG-IP 13.1
F5 Networks BIG-IP 14.1
F5 Networks BIG-IP 17.0
F5 Networks 11000 (E101)
F5 Networks 11050 (E102)
F5 Networks VIPRION B2100 Blade (A109)
F5 Networks 6900s SSL (D104)
F5 Networks BIG-IP 12.1
F5 Networks BIG-IP 11.6
F5 Networks 3900 (C106)
F5 Networks 6900 (D104)
F5 Networks 8900 (D106)
F5 Networks 8950 (D107)
F5 Networks 8950s (D107)
F5 Networks BIG-IP 16.0

Showing up to 30 newest entries per vendor. See full inventories: Cisco, Juniper, Paloalto, Fortinet, F5. Fortinet is not yet in the catalog; entries will populate as collectors land.

What this means operationally

12.3.4 creates the inventory-and-review obligation; 6.3.3 creates the patch-deployment SLA. Both fail on EoL hardware, but for different reasons and in different audit findings. For the QSA evidence-collection workflow, named compensating controls (network isolation, enhanced monitoring, third-party support, risk-acceptance sign-off), and the cross-framework view that includes HIPAA 164.308 and NIST SP 800-53 SA-22, see compliance and insurance impact. For per-vendor lifecycle policy detail with citations, see the lifecycle policy hubs: Cisco, Juniper, Palo Alto. Use the 12-month and 24-month calendar feeds to populate the annual review with concrete dates for the network gear in scope.

Sources

Last reviewed .

↑ Top