Skip to content

PCI DSS Requirement 5: anti-malware

By Sam Rivera, Founder, SentinelPanda · August 6, 2026 · 2 min read · PCI DSS

The old "install antivirus on Windows machines" requirement grew up in v4.0 — it now expects a reasoned argument about every system you chose not to protect.

Deploy, update, scan, log

The core of Requirement 5 is unchanged in shape: an anti-malware solution deployed on all system components commonly affected by malware (5.2.1), kept current with automatic updates (5.3.1), performing either periodic scans or continuous behavioural analysis (5.3.2), and generating audit logs retained per Requirement 10.

The solution must also not be disableable or alterable by users unless specifically authorised by management on a case-by-case basis for a limited period (5.3.5). "The developers all have local admin and turned it off" is a finding.

The systems you decided not to protect

This is where v4.0 tightened meaningfully. Historically, teams would declare Linux servers "not commonly affected by malicious software" and move on. Requirement 5.2.3 now requires a periodic evaluation — supported by a targeted risk analysis under 12.3.1 — identifying and evaluating evolving malware threats for those components, and confirming whether they continue to warrant no anti-malware protection.

The frequency of that evaluation is itself set by the targeted risk analysis. So the answer "our container hosts do not need it" is still available to you, but it now has to be a documented, periodically revisited risk decision rather than an assumption inherited from whoever built the platform.

Removable media and phishing

  • Requirement 5.3.3 requires anti-malware scans of removable electronic media when in use, or a documented technical or administrative control preventing its use entirely. Many organisations satisfy this by blocking removable media outright, which is cleaner than scanning it.
  • Requirement 5.4.1, added in v4.0, requires processes and automated mechanisms to detect and protect personnel against phishing attacks. Email filtering, link protection, and domain authentication (SPF, DKIM, DMARC) are the usual implementations.
  • Note that 5.4.1 is about protecting personnel with technical mechanisms — it is distinct from the phishing awareness training required separately under Requirement 12.6.3.1. Assessors expect both, and training alone does not satisfy 5.4.1.

Where teams get this wrong

The most common gap is coverage rather than configuration: anti-malware deployed diligently on endpoints and servers, and absent from ephemeral cloud workloads that are created and destroyed too quickly for the traditional agent model. Baking protection into base images, or using a platform-native workload protection service, addresses it — but somebody has to notice the gap first, and an accurate system component inventory is what makes that possible.

PCI DSS Requirement 6: secure systems and software Security awareness training PCI DSS Requirement 12: policies and programs

Run your compliance program in one workspace.