Requirement 8: Identify Users and Authenticate Access
The requirement most changed by v4 — MFA now applies to ALL access into the cardholder data environment, not just remote logins. Here is what each control demands, the evidence a QSA actually accepts, and where first-year programmes fail.
Reviewed by Abhay Singh, PCI SSC-qualified QSA professional · CyberSigma is a PCI SSC-listed QSA company · Part of the Requirement 1–12 series
The controls that decide your assessment
Control numbers reference PCI DSS v4.0.1 (June 2024). Verify wording against the standard itself — PCI SSC document library.
Where programmes actually fail
v4.0.1 requirement 8.4.2 extends MFA to all CDE access — internal console logins included. Programmes that certified under v3.2.1 and never re-scoped fail here first.
Network devices are system components. A shared enable password without individual attribution violates 8.2.1/8.2.2 even if a bastion logs the session.
If a human can log in with it, 8.6.1 applies: documented approval, time-bound justification and accountability — or disable interactive use.
The assessor needs configuration exports (GPO, PAM policy, IdP settings) and observation, not a policy PDF. Screenshots of the actual enforced settings are the evidence.
Requirement 8 intersects 2.2/2.3: default accounts on POS terminals, HSMs and appliances must be removed or rekeyed — a favourite finding in first-year assessments.
Evidence a QSA accepts
A policy document proves intent; configuration proves control. Bring these to the assessment:
- IdP / Active Directory password and lockout policy export (GPO screenshots or PAM configuration)
- MFA policy configuration showing enforcement scope covers every CDE entry path
- User access listing reconciled to HR joiners/leavers for the sample period
- Interactive-logon settings for service accounts, with approvals for any exceptions
- Session-timeout configuration for consoles, VPN and admin interfaces
- Screen recording or observation notes of an actual login demonstrating MFA
Requirement 8 FAQ
Does PCI DSS v4.0.1 require MFA for internal access to the CDE?
Yes. Requirement 8.4.2 requires MFA for all access into the cardholder data environment — internal as well as remote. It became fully effective as a future-dated requirement on 31 March 2025.
What is the minimum password length under PCI DSS v4?
Requirement 8.3.6 sets a 12-character minimum (letters and numbers). Systems that cannot technically support 12 may use 8, and the limitation must be documented.
Do passwords still need changing every 90 days?
Only where passwords are the sole authentication factor (8.3.9). With MFA in place, periodic forced rotation is not required by that control — one of the strongest operational arguments for MFA everywhere.
Do service accounts fall under Requirement 8?
Yes — requirements 8.6.1 to 8.6.3 govern system and application accounts, especially any that can be used interactively, and the protection of embedded credentials.
Requirement 8 in your environment
A PCI SSC-listed QSA firm can tell you in one session whether your controls will survive assessment — before the assessment.
