TL;DR
- PCI DSS Requirement 5 requires anti-malware on every in-scope system unless a documented, periodically reviewed evaluation shows the system is not at risk.
- Most failures come from stale exclusions, agents that stopped reporting, unscanned removable media, and phishing controls that rely on training alone.
- Daily coverage monitoring, quarterly exclusion reviews, and evidence collected throughout the year keep organizations audit ready.
What Is PCI DSS Requirement 5?
PCI DSS Requirement 5 is the control that requires organizations to protect all systems and networks from malicious software. The PCI Security Standards Council published the current wording in PCI DSS v4.0.1, where the title replaced the older anti-virus language from version 3.2.1. The requirement sits among the 12 principal PCI DSS requirements and falls under the objective for maintaining a vulnerability management program. It now covers anti-malware deployment, ongoing maintenance and monitoring, and anti-phishing mechanisms, and the future-dated parts became mandatory on March 31, 2025. Attackers deliver ransomware, credential stealers, and remote access tools through email, removable drives, and compromised downloads, and one infected system inside the cardholder data environment can expose the stored account data covered by PCI DSS Requirement 3.
What Are the Sub-Requirements of PCI DSS Requirement 5?
Requirement 5 contains four groups of controls: 5.1 for governance, 5.2 for preventing and detecting malware, 5.3 for maintaining anti-malware mechanisms, and 5.4 for anti-phishing protection.
- 5.1: Documented policies and procedures, with assigned roles and responsibilities, support every anti-malware activity.
- 5.2: Anti-malware solutions run on all system components except those documented as not at risk, and they detect and remove, block, or contain all known malware types.
- 5.3: Anti-malware mechanisms stay current, perform periodic scans or continuous behavioral analysis, scan removable media, keep audit logs, and resist user tampering.
- 5.4: Processes and automated mechanisms detect and protect personnel against phishing attacks.
Which Systems Need Anti-Malware Under PCI DSS Requirement 5?
Every in-scope system component needs anti-malware unless the organization documents it as not at risk for malware and re-evaluates that decision periodically. Requirement 5.2.3 requires a documented list of exempt components, an assessment of evolving threats to each one, and confirmation that the exemption still holds. Requirement 5.2.3.1 requires a targeted risk analysis that sets the frequency of those evaluations. Teams should not treat Linux hosts, containers, or appliances as automatically exempt, because assessors expect evidence for each exclusion. The documented list should name each system, the reason it is considered not at risk, and the person who approved the decision.
Does EDR Satisfy PCI DSS Requirement 5?
Endpoint detection and response can satisfy Requirement 5 when it detects all known malware types and removes, blocks, or contains them. The wording in 5.2.2 allows modern tools that rely on behavioral analysis instead of signature files, and 5.3.2 accepts continuous behavioral analysis in place of periodic scans. The tool must still receive automatic updates, write audit logs, and resist tampering by users. Organizations should document how the EDR configuration maps to each sub-requirement so that assessors can trace the logic. Teams that run both a legacy anti-virus product and an EDR agent should confirm that the two do not conflict and that logs from each reach the central repository.
How Do You Keep Anti-Malware Effective and Auditable?
You keep anti-malware effective by automating updates, justifying scan frequency, scanning removable media, retaining logs, and locking the tool against user changes.
- Updates: Requirement 5.3.1 requires automatic updates so that signatures, engines, and behavioral models stay current.
- Scan frequency: Requirement 5.3.2.1 requires a targeted risk analysis that justifies how often periodic scans run.
- Removable media: Requirement 5.3.3 requires an automatic scan, or continuous behavioral analysis, whenever media is connected.
- Audit logs: Requirement 5.3.4 requires enabled logs retained for 12 months, with the most recent 3 months immediately available.
- Tamper protection: Requirement 5.3.5 prevents users from disabling the tool unless management authorizes it for a limited time.
What Does Requirement 5.4.1 Require for Phishing Protection?
Requirement 5.4.1 requires processes and automated mechanisms that detect and protect personnel against phishing attacks, and it became mandatory on March 31, 2025. The standard names no single technology, so organizations choose controls such as secure email gateways, link and attachment sandboxing, and email authentication with SPF, DKIM, and DMARC. A warning banner on external email does not meet the intent, because the control must actively protect users. Awareness training under Requirement 12.6.3.1 supports this control and does not replace it. Teams should also tune controls to the email platform in use, because cloud mailboxes and on-premises gateways need different configurations.
What Evidence Do Assessors Ask for in Requirement 5?
Assessors ask for policies, configuration exports, update logs, scan results, and the documentation behind every exclusion. Expect requests for the list of components not at risk with its latest evaluation, targeted risk analyses for scan frequency, exports that show automatic updates and tamper protection, and audit logs that cover the retention period. For anti-phishing, assessors review gateway configurations and samples of blocked messages. Console exports with timestamps carry more weight than one-time screenshots, since they show consistency across the full population of systems. Assessors also interview the owners of the anti-malware process to confirm that the roles defined in Requirement 5.1 match daily practice.
What Are the Most Common Requirement 5 Gaps?
The most common gaps are the following:
- Undocumented exclusions
- Agents that stopped reporting
- Missing removable media controls
- Logs that fail the retention rule
Assessors also see targeted risk analyses that nobody has refreshed and phishing controls that rely on training alone. New assets create the largest risk, because servers built from outdated images often skip the agent installation. Secure configuration baselines under PCI DSS Requirement 2 help by building protection into the standard image. Security leaders should compare the asset inventory with the console agent list every month and aim for 100% coverage of in-scope systems.
How Can Organizations Maintain Malware Protection Continuously?
Organizations maintain malware protection by monitoring coverage and agent health every day and by treating exceptions as managed risks. Teams should alert on agents that stop checking in, review exclusion lists every quarter, and test removable media and email controls with safe simulations. Regular penetration testing confirms that controls hold against real attack paths, including those that start with a phishing message or a connected drive. GRC program that links controls, assets, and evidence gives CISOs a live view of Requirement 5 status and removes the scramble before assessment season. Reporting the agent coverage rate, the mean time to repair failed agents, and the number of active exclusions to governance leaders each quarter keeps the program visible and gives owners a clear target.
Know Where Your Requirement 5 Gaps Are Before Your Assessor Does.
| Get your malware protection, anti-phishing, monitoring, and evidence controls assessed by PCI DSS specialists. |
People Also Ask:
What is PCI DSS Requirement 5?
PCI DSS Requirement 5 requires organizations to protect all systems and networks from malicious software through anti-malware controls, ongoing monitoring, and anti-phishing mechanisms.
Is antivirus required for PCI DSS compliance?
Anti-malware is required on all in-scope system components, except those documented as not at risk for malware and re-evaluated periodically under Requirement 5.2.3.
Does PCI DSS require anti-malware on Linux servers?
Yes, unless the organization documents the server as not at risk and evaluates that decision periodically. Running Linux does not create an automatic exemption.
Does PCI DSS require anti-phishing controls?
Yes. Requirement 5.4.1 requires processes and automated mechanisms to detect and protect personnel against phishing attacks, and it became mandatory on March 31, 2025.
Is DMARC required for PCI DSS?
PCI DSS does not name DMARC as mandatory. Email authentication helps meet Requirement 5.4.1, but it does not satisfy the requirement alone.
How often must anti-malware scans run under PCI DSS?
When periodic scans are used, a targeted risk analysis under Requirement 5.3.2.1 sets the frequency. Continuous behavioral analysis can replace periodic scans.
Enjoyed reading this blog? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn.










