Home/Compliance/PCI-DSS Requirement 12.3.4

PCI-DSS Requirement 12.3.4

Annual review of hardware and software at vendor end-of-support. Required since 2025-03-31.

PCI-DSS standard text is paywalled at the PCI SSC document library: downloading the standard itself requires accepting the council's license agreement. The publicly-available primary document that describes Requirement 12.3.4 is the Summary of Changes from PCI DSS Version 3.2.1 to 4.0 (May 2022). Quotes below are from that document. Where this page draws on a QSA-firm secondary, it is labeled supporting context, not primary.

Requirement 12.3.4 is part of PCI-DSS v4.0 (and carried into v4.0.1). It applies to every entity in scope for PCI-DSS: merchants, service providers, and any organization that stores, processes, or transmits cardholder data, or whose systems can affect the security of the cardholder data environment. The clause sits inside Requirement 12 ("Support information security with organizational policies and programs") and mandates a documented annual review of hardware and software technologies in use, with end-of-life status as a named consideration.

The clause was a future-dated requirement. Per the PCI SSC Summary of Changes: "This requirement is a best practice until 31 March 2025." That transition has now passed. Since , 12.3.4 is a fully assessed requirement on every PCI-DSS v4.x assessment.

The 12.3.4 text

The PCI SSC Summary of Changes describes 12.3.4 in two places. The first is the change-description table (the most substantive public quote we can attribute to a primary PCI document):

"12.3.4 New requirement to review hardware and software technologies in use at least once every 12 months.

This requirement is a best practice until 31 March 2025."

PCI Security Standards Council, Summary of Changes from PCI DSS Version 3.2.1 to 4.0, May 2022, page 22, change description for 12.3.4. PCI SSC PDF.

The second is the future-dated-requirements summary table, which restates the requirement title and lists the 31 March 2025 effective date:

"12.3.4 Hardware and software technologies are reviewed."

Applicable to: All Entities. Effective Date: 31 March 2025.

PCI Security Standards Council, Summary of Changes from PCI DSS Version 3.2.1 to 4.0, May 2022, page 31, future-dated requirements table. PCI SSC PDF.

The full clause text in the PCI-DSS standard itself, which spells out the assessor-evidence sub-bullets (current technology support status, named end-of-life plan, etc.), is not redistributable from the paywalled standard. We do not reproduce it here. For the verbatim sub-bullet structure, your QSA has the standard.

What 12.3.4 requires

Devices in our catalog from PCI-scope networking vendors

12.3.4 is vendor-neutral: it applies to whatever hardware and software is in your cardholder data environment. The catalog subset below is filtered to networking vendors most commonly named in PCI-scope perimeter, segmentation, and load-balancing footprints (Cisco, Juniper, Palo Alto Networks, Fortinet, F5), and to products currently at end-of-life. The 12.3.4 review obligation is what makes this list relevant: each of these is a device that, if in scope, must be on the annual-review docket and named in your remediation plan. Verify against the vendor's own bulletin and your QSA's scoping before acting.

VendorProductEnd of support
Cisco Cisco Select 4300ISR
Cisco Cisco Select 4300ISR
Cisco Cisco Select 4300ISR
Cisco Cisco Select 4300ISR
Cisco Cisco Select 4300ISR
Cisco Cisco Select 4300ISR
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Cisco Cisco Nexus 5500, 5600 and 6000 NX-OS 7.3 all versions
Juniper SKU Transformation to formalize EOL announcement for MX204 SKU MX204 P BASE MX204PBASE AC 1 FS S MX204 A 3 S MX204 A 5 S MX204 P 3 S MX204 P 5 S MX204 P EA 5
Juniper SKU Transformation to formalize EOL announcement for MX204 SKU MX204 P BASE MX204PBASE AC 1 FS S MX204 A 3 S MX204 A 5 S MX204 P 3 S MX204 P 5 S MX204 P EA 5
Juniper SKU: JNP10001-CHAS
Juniper SRX CFP 100G SR10
Juniper PTX 5 100G WDM
Juniper ACX500
Juniper ACX500
Juniper ACX500
Juniper ACX500
Juniper ACX500
Juniper ACX500
Juniper ACX500
Juniper ACX500
Juniper ACX500
Juniper ACX500
Juniper ACX500
Juniper ACX500
Juniper SRX MP 1SERIAL R JX CBL V35 DCE
Juniper SRX MP 1SERIAL R JX CBL V35 DCE
Juniper SFP-GE80KCW1470-ET
Juniper SFP-GE80KCW1490-ET
Juniper SFP-GE80KCW1510-ET
Juniper SFP-GE80KCW1530-ET
Juniper SFP-GE80KCW1570-ET
Juniper SFP-GE80KCW1590-ET
Juniper SFP-GE80KCW1610-ET
Juniper SKU Transformation Announcement MX license
Juniper SKU Transformation Announcement MX license
Juniper SKU Transformation Announcement MX license
Juniper SKU Transformation Announcement MX license
Palo Alto PA-7000-20GQXM-NPC
Palo Alto PA-7000-20GXM-NPC
Palo Alto K2-Series
Palo Alto PA-7000-LPC
Palo Alto K2-Series
Palo Alto PA-7050-SMC
Palo Alto K2-Series
Palo Alto PA-7080-SMC
Palo Alto M-500
Palo Alto PA-3000 Series
Palo Alto PA-3000 Series
Palo Alto PA-3000 Series
Palo Alto PA-5000 Series
Palo Alto PA-5000 Series
Palo Alto PA-5000 Series
Palo Alto PA-7000-20G-NPC
Palo Alto PA-7000-20GQ-NPC
Palo Alto PA-200
Palo Alto PA-500
Palo Alto M-100
Palo Alto GP-100
Palo Alto LightCyber Magna Detector
Palo Alto LightCyber Magna Detector
Palo Alto LightCyber Magna Detector
Palo Alto LightCyber Magna Probe
Palo Alto PA-2000 Series
Palo Alto PA-2000 Series
Palo Alto PA-4000 Series
Palo Alto PA-4000 Series
Palo Alto PA-4000 Series
Fortinet Fortinet MC155-PS
Fortinet Fortinet MC4200-PS
Fortinet FortiAP-231E
Fortinet FortiWLC-1000D
Fortinet FortiWLC-3000D
Fortinet FG-60C-PDC
Fortinet Fortinet SP-FAZ3500E-RAIL
Fortinet FortiDDos-1000B
Fortinet FortiGate-1200D
Fortinet FortiGate-1200D-LENC
Fortinet FortiGate-1200D-USG
Fortinet FortiGate-30E-USG
Fortinet FortiGate-50E-USG
Fortinet FortiWiFi-50E-USG
Fortinet FortiAuthenticator-200E
Fortinet FortiAuthenticator-400E
Fortinet FortiADC-1000F
Fortinet FortiADC-2000F
Fortinet FortiADC-4000F
Fortinet FortiWeb-400D-USG
Fortinet FortiFone-375
Fortinet FortiFone-475
Fortinet FortiFone-E570
Fortinet Fortinet AP822i(integrated antenna), AP822e (external)
Fortinet Fortinet SP-FG92D-PDC
Fortinet FortiAuthenticator-1000D
Fortinet FortiWeb-600D
Fortinet FortiRPS-100
Fortinet FortiGate-3800D
Fortinet FortiGate-3800D-DC
F5 Networks VIPRION B4340N Blade NEBS (A110)
F5 Networks 2000s (C112)
F5 Networks 2200s (C112)
F5 Networks 4000s (C113)
F5 Networks 4200v (C113)
F5 Networks 5000s LTM standalone (C109)
F5 Networks 5050s (C109)
F5 Networks 5200v LTM standalone / SSL (C109)
F5 Networks 5250v (C109)
F5 Networks 7000s LTM standalone (D110)
F5 Networks 7050s (D110)
F5 Networks 7250v (D110)
F5 Networks VIPRION B4300 Blade (A108)
F5 Networks 11000 (E101)
F5 Networks 11050 (E102)
F5 Networks VIPRION B2100 Blade (A109)
F5 Networks 6900s SSL (D104)
F5 Networks 3900 (C106)
F5 Networks 6900 (D104)
F5 Networks 8900 (D106)
F5 Networks 8950 (D107)
F5 Networks 8950s (D107)
F5 Networks 1600 (C102)
F5 Networks 3600 (C103)
F5 Networks VIPRION 4400 Chassis (J100)
F5 Networks VIPRION B4200 Blade (A107/PB200)
F5 Networks VIPRION B4100 Blade (A100/PB100)
F5 Networks 8400 (D84)
F5 Networks 8800 (D88)
F5 Networks 6400 (D63)

Showing up to 30 newest entries per vendor. See full inventories: Cisco, Juniper, Paloalto, Fortinet, F5. Fortinet is not yet in the catalog; entries will populate as collectors land.

What this means operationally

12.3.4 creates the inventory-and-review obligation; 6.3.3 creates the patch-deployment SLA. Both fail on EoL hardware, but for different reasons and in different audit findings. For the QSA evidence-collection workflow, named compensating controls (network isolation, enhanced monitoring, third-party support, risk-acceptance sign-off), and the cross-framework view that includes HIPAA 164.308 and NIST SP 800-53 SA-22, see compliance and insurance impact. For per-vendor lifecycle policy detail with citations, see the lifecycle policy hubs: Cisco, Juniper, Palo Alto. Use the 12-month and 24-month calendar feeds to populate the annual review with concrete dates for the network gear in scope.

Sources

Last reviewed .

↑ Top