Compliance · Payments

PCI DSS MFA Requirements

PCI DSS is the most explicit of the major frameworks about multi factor authentication. Version 4.0 widened the scope of PCI requirement 8.4 from remote and administrative access to all access into the cardholder data environment, and Requirement 8.5 now sets rules for how the MFA system itself must behave. Here is what those requirements cover, and how Spriv maps to them.

One-time access passcode delivered by text message as a second factor for PCI 2FA
PCI 2FA · A second factor on a separate channel
0
Access types under Requirement 8.4
0
Different factor types, at minimum
0 h
Longest Spriv postponement, as a documented exception
0 ms
Typical second-factor time on a trusted pair
PCI requirement 8.4

Where PCI DSS 4.0 requires multi factor authentication

Requirement 8.4 in PCI DSS v4.0 and v4.0.1 lists three situations in which MFA must be in place. Older versions asked for two-factor authentication on remote access by employees, administrators and third parties; v4.0 keeps that and goes further.

8.4.1 Admin access into the CDE

MFA for all non-console administrative access into the cardholder data environment, such as an administrator connecting to a CDE server over RDP or SSH from another machine.

8.4.2 All access into the CDE

MFA for all access into the CDE, not only administrators. This was a future-dated requirement in v4.0 and became mandatory on 31 March 2025.

8.4.3 Remote network access

MFA for all remote network access from outside your network that could access or impact the CDE, whether by employees, administrators or third parties.

Scope comes first. Which systems sit in or connect to the CDE decides where these requirements apply, and the standard includes applicability notes and limited exceptions. Confirm your scope, and how each requirement applies to your environment, with your QSA.
Requirement 8.5

How the MFA system itself must be configured

Requirement 8.5 asks whether the MFA you deployed can actually be defeated. Under 8.5.1, MFA systems must be implemented to prevent misuse, which breaks down into four checks.

Not susceptible to replay attacks

A captured authentication response must not be reusable to log in again later. Spriv's adaptive check is made fresh, out-of-band, for each login, and TOTP codes expire after 30 seconds. Ask your QSA to review the replay resistance of each method you enable.

Cannot be bypassed, including by administrators

No user, administrators included, may skip MFA unless the exception is specifically documented and authorized by management, on an exception basis, for a limited time. This is the requirement that governs how you use Spriv's Bypass status and postponement, covered below.

At least two different types of factors

The factors must come from different categories: something you know, something you have, something you are. Spriv combines the password (know) with the user's paired phone (have), and also checks the known workstation and its environment.

All factors must succeed before access is granted

Access must not be granted when only one factor has passed. With Spriv's Credential Provider and PAM module, the Windows session or shell opens only after both the password and the Spriv check succeed.

Mapping Spriv to PCI DSS

Where Spriv adds the second factor in a CDE

The same platform covers the access paths Requirement 8.4 cares about, with Adaptive MFA as the default and other methods for exceptions.

8.4.1 · 8.4.2

Windows logon and RDP

Spriv's patented Credential Provider adds MFA to local and Remote Desktop logins on Windows 8-11 and Windows Server 2012 R2-2022. Windows login MFA.

8.4.1 · 8.4.2

SSH, su and sudo

A PAM module puts the second factor on SSH sessions and privilege escalation on Linux and Unix servers. SSH two factor authentication.

8.4.3

Remote access from outside

Every remote session is checked on a second channel: Spriv compares the phone's environment with the workstation, so a login from somewhere the phone is not gets challenged. Adaptive MFA for RDP.

Requirement 8.5.1 in practice

Handling Bypass and postponement as documented exceptions

Spriv lets an administrator set a user to Bypass, or postpone second-factor authentication for up to 72 hours when someone forgets their phone. Inside a CDE, treat both as the exceptions 8.5.1 allows, not as convenience settings.

Spriv sets the 72-hour ceiling; your policy decides who may approve an exception and for how long. Your QSA will want to see that the policy is followed.

  • Document it

    Record the user, the reason and the systems affected before the change is made.

  • Get management authorization

    A named manager approves each exception, not the administrator acting alone.

  • Keep it time-limited

    Set an end date, return the user to Active, and prefer swapping a lost phone, which takes under a minute.

  • Log and review

    Keep a record of every exception and review it alongside your other access logs.

Questions

PCI DSS MFA questions

Is PCI 2FA the same as PCI MFA?

Two factor authentication is MFA with two factors, and it meets the PCI DSS definition as long as the factors are of different types. Earlier versions of the standard said "two-factor"; v4.0 uses "multi-factor".

Does a VPN with MFA cover requirement 8.4.2?

Not necessarily. MFA at the network edge addresses remote access under 8.4.3, but 8.4.2 is about access into the CDE itself, which can mean another MFA step at the CDE boundary. How the two combine in your network is a scoping question for your QSA.

Is SMS acceptable as a factor for PCI DSS?

Your QSA makes that call for your environment. Spriv uses Adaptive MFA as the default and keeps one-way SMS for activation and as a fallback, so most logins never rely on a text message.

Does Spriv see cardholder data?

Spriv verifies identity, not payments. It is designed so that zero personally identifiable information is transferred, and it never shares the phone's actual location.

Will MFA on every CDE login slow down operations?

On a trusted workstation-and-phone pair, Spriv's second factor clears in the background in as little as 175 milliseconds. Users see a prompt only when something does not match.

Checkit!

MFA for every path into your CDE

Two free users and two free servers, no credit card. Install on a Windows or Linux server in under five minutes and walk your QSA through it.