Get Demo
↑

PCI DSS Requirement 8: Authentication, MFA (8.4.2), and 12-Character Passwords (8.3.6)

PCI DSS v4.0.1 Requirement 8 - unique IDs, strong authentication, 12-character passwords (8.3.6), MFA for CDE and remote access (8.4.1-8.4.3).

Published: September 2026 Compliance · PCI DSS 8-12 min read

PCI DSS Requirement 8 in v4.0.1 is titled Identify Users and Authenticate Access to System Components. It covers unique IDs, account lifecycle, strong authentication - including 8.3.6 twelve-character passwords - and multi-factor authentication into the CDE under 8.4.1-8.4.3 (especially 8.4.2).

Related: Requirement 2 · Requirement 10 (logging).

ID gotcha: Do not cite MFA as “8.3.2.” 8.3.2 protects authentication factors with strong cryptography. MFA for CDE access is 8.4.x.

Requirement 8 Structure

Clause
Focus
8.1
Processes and mechanisms for identification and authentication
8.2
User identification and accounts managed through the lifecycle
8.3
Strong authentication established and managed (includes 8.3.6)
8.4
MFA implemented to secure access into the CDE (8.4.1-8.4.3)
8.5
MFA systems configured to prevent misuse
8.6
Application and system accounts strictly managed

Deep Dives

How CyberSilo Helps

Map PCI DSS v4.0.1 Controls to Continuous Evidence

CyberSilo CSA and ThreatHawk SIEM help US merchants and service providers collect QSA-ready evidence across the 12 requirements.

Frequently Asked Questions

Is MFA Requirement 8.3.2?

No. 8.3.2 requires strong cryptography to protect authentication factors in transit and storage. MFA into the CDE is 8.4.1-8.4.3 - especially 8.4.2 for all access into the CDE.

What is the password length rule under 8.3.6?

If passwords/passphrases are used as an authentication factor for 8.3.1, minimum length is 12 characters (or eight if the system cannot support 12), and they must contain numeric and alphabetic characters. Mandatory since 31 March 2025.

Does phishing-resistant MFA change 8.4.2?

PCI DSS v4.0.1 added an Applicability Note: MFA for all (non-administrative) access into the CDE under 8.4.2 does not apply to user accounts authenticated only with phishing-resistant authentication factors. Confirm scope with your QSA.

PCI DSS hub · PCI DSS v4.0.1: What Changed · USA v4.0.1 services

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!