This website uses cookies to ensure you get the best experience on our website. Learn more

New MFA requirements for PCI password compliance
The Payment Card Industry Data Security Standard (PCI DSS) regulates security practices to protect cardholder data. Password compliance plays an important role in the PCI standards by dictating password complexity to strengthen defense against unauthorized access. New requirements coming into effect this January demand multi-factor authentication (MFA) for administrators, and anyone with remote access.
PCI restricted access
When it comes to accessing cardholder data, PCI requires that access only be granted to authorize personnel on a need-to-know basis. Need-to-know is defined as: “access rights are given to only the least amount of data and privileges needed to perform a job.” Each person must be assigned a unique identification so that all actions can be traced to known users.
Verify user identity
Any user with access to cardholder data must have a unique ID and a strong password for authentication. Being able to verify user identity is crucial when performing a credential-related task like resetting the password. Verifying that the user is, in fact, who they claim to be when contacting the helpdesk prevents social engineering attacks.
Administrative access and remote access require MFA
A new requirement that comes into effect on January 31, 2018 is that all individual non-console administrative access and all remote access to cardholder data require MFA. At least two factors are required from two of the three categories (something you know, something you have, something you are). See requirement 8.3 in the official PCI document for more information.
Default passwords must be changed
Computers, servers, point-of-sale terminals, routers, etc. must not use the default, factory-set passwords. Half of all point-of-sale hacks are a result of weak or default passwords, according to this report from Trustwave.
Password expiration
Whether or not passwords must expire at regular intervals is a hotly debated topic for organizations that regulate password best practice. The National Institute of Standards and Technology (NIST) says that passwords should only expire, and be forced to change, when a breach is suspected. PCI, on the other hand, requires that passwords are changed every 90 days for all personnel with access to cardholder data and all system login accounts.
Strong passwords according to PCI
The PCI password requirements for businesses include the use of strong passwords, which have a minimum length of seven characters and contain numbers and letters. Here at Specops, we believe that a strong password must meet other requirements – not appearing on a dictionary list and being longer than 15 characters. This blog, Are PCI compliant passwords good enough? challenges the PCI definition of a strong password.
For questions about PCI compliance and Specops Password Policy, contact us today.
(Last updated on March 17, 2025)
Related Articles
-
How to build a PCI-compliant password policy
The Payment Card Industry Data Security Standard (PCI DSS) is a set of guidelines designed to protect cardholder data and ensure that organizations handling payment card information maintain a secure environment. Among its many requirements, PCI DSS places significant emphasis on robust password policies to prevent unauthorized access and mitigate the risk of data breaches. …
Read More -
NIST password guidelines: Full guide to NIST password compliance
Many look to the National Institute of Standards and Technology (NIST) guidelines as the gold standard when it comes to cybersecurity best practices. But as you’ve likely heard, NIST has updated its password guidelines in the latest draft of their well-known SP 800-63B policy document. This is in an attempt to provide more protections against…
Read More -
Guide to the PCI-DSS v4.0.1 regulations [Updated for 2025]
The PCI DSS compliance framework has been a staple in the cybersecurity realm for businesses handling credit card transactions. The Payment Card Industry Data Security Standard was developed to encourage and enhance payment card account data security. It helps define consistent security measures to bolster payment card data security, processing, and storage. PCI DSS is not a government-created…
Read More