We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

PCI DSS v4.0.1 · Requirement 8 of 12

Requirement 8: Identify Users and Authenticate Access

The requirement most changed by v4 — MFA now applies to ALL access into the cardholder data environment, not just remote logins. Here is what each control demands, the evidence a QSA actually accepts, and where first-year programmes fail.

Reviewed by Abhay Singh, PCI SSC-qualified QSA professional · CyberSigma is a PCI SSC-listed QSA company · Part of the Requirement 1–12 series

The controls that decide your assessment

8.2.1
Unique IDs for every user

All users get a unique ID before access to system components or cardholder data. Shared/generic accounts are the first thing an assessor greps for.

8.2.8
15-minute idle timeout

Sessions idle for more than 15 minutes require re-authentication. Applies to consoles, jump hosts and admin panels inside the CDE.

8.3.4
Lockout after 10 attempts

Invalid attempts limited to 10 or fewer; lockout for at least 30 minutes or until identity is confirmed.

8.3.6
12-character minimum passwords

Passwords/passphrases require at least 12 characters (or 8 if the system cannot support 12 — document why), with both letters and numbers.

8.3.9
90-day rotation OR dynamic analysis

If passwords are the only factor, change every 90 days — or analyse account security posture dynamically in real time. MFA everywhere removes this treadmill.

8.4.2
MFA for ALL access into the CDE

New teeth in v4: MFA applies to all access into the cardholder data environment, not just remote or admin. Fully effective as a future-dated requirement since 31 March 2025.

8.4.3
MFA for all remote network access

Every remote access session originating outside the entity network — staff, admins and third parties alike.

8.5.1
MFA that resists replay & bypass

MFA systems must not be susceptible to replay, cannot be bypassed by any user without documented management exception, and use at least two different factor types.

8.6.1–8.6.3
Interactive use of system/service accounts

Application and service accounts that can be used interactively need management approval, individual accountability and protection of embedded passwords/keys.

Control numbers reference PCI DSS v4.0.1 (June 2024). Verify wording against the standard itself — PCI SSC document library.

Where programmes actually fail

MFA scoped only to remote access

v4.0.1 requirement 8.4.2 extends MFA to all CDE access — internal console logins included. Programmes that certified under v3.2.1 and never re-scoped fail here first.

Shared admin accounts "for the firewall"

Network devices are system components. A shared enable password without individual attribution violates 8.2.1/8.2.2 even if a bastion logs the session.

Service accounts with interactive login enabled

If a human can log in with it, 8.6.1 applies: documented approval, time-bound justification and accountability — or disable interactive use.

Password policy set, never evidenced

The assessor needs configuration exports (GPO, PAM policy, IdP settings) and observation, not a policy PDF. Screenshots of the actual enforced settings are the evidence.

Vendor defaults surviving on appliances

Requirement 8 intersects 2.2/2.3: default accounts on POS terminals, HSMs and appliances must be removed or rekeyed — a favourite finding in first-year assessments.

Evidence a QSA accepts

A policy document proves intent; configuration proves control. Bring these to the assessment:

  • IdP / Active Directory password and lockout policy export (GPO screenshots or PAM configuration)
  • MFA policy configuration showing enforcement scope covers every CDE entry path
  • User access listing reconciled to HR joiners/leavers for the sample period
  • Interactive-logon settings for service accounts, with approvals for any exceptions
  • Session-timeout configuration for consoles, VPN and admin interfaces
  • Screen recording or observation notes of an actual login demonstrating MFA

Requirement 8 FAQ

Does PCI DSS v4.0.1 require MFA for internal access to the CDE?

Yes. Requirement 8.4.2 requires MFA for all access into the cardholder data environment — internal as well as remote. It became fully effective as a future-dated requirement on 31 March 2025.

What is the minimum password length under PCI DSS v4?

Requirement 8.3.6 sets a 12-character minimum (letters and numbers). Systems that cannot technically support 12 may use 8, and the limitation must be documented.

Do passwords still need changing every 90 days?

Only where passwords are the sole authentication factor (8.3.9). With MFA in place, periodic forced rotation is not required by that control — one of the strongest operational arguments for MFA everywhere.

Do service accounts fall under Requirement 8?

Yes — requirements 8.6.1 to 8.6.3 govern system and application accounts, especially any that can be used interactively, and the protection of embedded credentials.

← Requirement 7: Need-to-Know AccessRequirement 9: Physical Security

Requirement 8 in your environment

A PCI SSC-listed QSA firm can tell you in one session whether your controls will survive assessment — before the assessment.