Your audit may already have a finding.
RC4 in Active Directory predates the Microsoft deadline as a compliance concern by a decade. NIST SP 800-131A disallowed RC4 in 2016. PCI-DSS 4.0 Requirement 12.3.3 requires inventory of weak cipher suites and a documented remediation plan. HIPAA's 2024–2025 Security Rule updates moved encryption from addressable to required. SOC 2 audit periods running through 2026 will include post-April enforcement dates in their evidence window. The question is no longer whether RC4 is a finding — it is whether your documentation is ready when the auditor asks.
