Requirement 2: Apply Secure Configurations to All System Components
Requirement 2 is the hardening requirement: vendor defaults die here. The assessor compares your running configurations against your own hardening standard — so the standard must exist, map to an accepted benchmark, and actually be applied.
Reviewed by Abhay Singh, PCI SSC-qualified QSA professional · CyberSigma is a PCI SSC-listed QSA company · Part of the Requirement 1–12 series
The controls that decide your assessment
Control numbers reference PCI DSS v4.0.1 (June 2024). Verify wording against the standard itself — PCI SSC document library.
Where programmes actually fail
A one-page policy saying "systems shall be hardened" fails 2.2.1. The standard must specify settings per platform, traceable to CIS or vendor baselines.
Servers get hardened; the HSM, printer, POS terminal or load balancer keeps admin/admin. Requirement 2 applies to every system component in scope.
"public/private" strings on network devices are a classic 2.2.2 finding that internal vulnerability scans should have caught quarters earlier.
2.2.7 has no temporary exception — unencrypted admin channels are findings the day the assessor sees them.
Evidence a QSA accepts
A policy document proves intent; configuration proves control. Bring these to the assessment:
- Hardening standards per platform with benchmark references and review dates
- Configuration exports or benchmark-scan results demonstrating application
- Account listings showing vendor defaults removed or disabled
- Service/port inventories per component type against documented necessity
- Wireless configuration showing all defaults changed
Requirement 2 FAQ
Do we have to use CIS Benchmarks?
No specific benchmark is mandated — 2.2.1 requires standards consistent with industry-accepted hardening sources, and CIS or vendor security guides are the accepted route in practice.
Does Requirement 2 apply to cloud PaaS services?
Yes, to the configuration surface you control: platform hardening options, exposed services, default credentials in managed services, and administrative access channels.
One system, multiple functions — allowed?
Primary functions with different security levels on one system must be isolated or all secured to the level of the highest-risk function (2.2.3).
Requirement 2 in your environment
A PCI SSC-listed QSA firm can tell you in one session whether your controls will survive assessment — before the assessment.
