The update to PCI DSS v3.2, effective February 1, 2018, mandates that several requirements previously considered best practices are now mandatory for maintaining PCI DSS certification. Key changes include the necessity of multi-factor authentication for administrative access, timely detection of security system failures, and regular reviews of security policies and procedures. Service providers must also maintain comprehensive documentation for their cryptographic architecture and ensure segmentation controls are tested biannually.