PCI DSS Requirement 8: What Is It and How to Comply?
PCI DSS Requirement 8.1 is put in place to ensure that all the business’ internal users of payment transaction systems have a unique user ID based on their job responsibilities. This creates a sense of accountability that allows problems to be solved quickly.

The sub-sub-requirements include:
| Control | Requirement |
|---|---|
| 8.1.1 | Assign unique IDs to all users before granting access to the CDE |
| 8.1.2 | Manage which staff can add, delete, or edit user accounts and credentials |
| 8.1.3 | Revoke access immediately when a user is terminated |
| 8.1.4 | Terminate or disable accounts after 90 days of inactivity |
| 8.1.5 | Manage, restrict, and monitor all third-party IDs used to access systems |
| 8.1.6 | Lock users out after a maximum of six failed login attempts |
| 8.1.7 | Set lockout durations of at least 30 minutes |
| 8.1.8 | Require re-login after more than 15 minutes idle |
{{snapshot}}
Managing user IDs and access
- Assign a unique ID to every user before granting access to the cardholder data environment (CDE).
- Revoke access immediately on termination, and disable accounts after 90 days of inactivity.
- Lock accounts after six failed logins, hold lockouts for at least 30 minutes, and re-login after 15 minutes idle.
{{/snapshot}}
PCI DSS Requirement 8.2: Create user authentication policies.
Your business will have to establish authentication processes to identify the user. These authenticating factors can include passwords, specific devices, or a biometric scan, but must be used to safeguard accounts. The sub-sub-requirements are as follows:
- PCI DSS 8.2.1 – Implement cryptography when transmitting and storing of user credentials.
- PCI DSS 8.2.2 – Verify a user’s identity before editing their authentication credentials.
- PCI DSS 8.2.3 – Ensure user passwords have a strength limit. This usually involves including a minimum of seven characters and at least one number, a letter and special character.
- PCI DSS 8.2.4 – Ensure user passwords are changed every 90 days.
- PCI DSS 8.2.5 – Do not allow users to reuse passwords and passphrases.
- PCI DSS 8.2.6 – Issue unique passwords for first-time users that they will need to change immediately after their first use.
PCI DSS Requirement 8.3: Implement Multi-Factor Authentication
Multi-factor authentication requires a user to go through more than one authentication process to prove their identity and gain access, especially when working remotely. This entails:
- PCI DSS 8.3.1 – Incorporating MFA for all non-console access to the CDE, including for those with administration privileges.
- PCI DSS 8.3.2 – Incorporating MFA for all user and admin access that is either remote or outside the company’s internal network.
It’s important to note that having two passwords does not constitute MFA.
{{snapshot}}
Passwords and multi-factor authentication
- Passwords need a minimum of seven characters with at least one letter, number, and special character, changed every 90 days and never reused.
- Encrypt credentials in transit and storage, and verify identity before changing them.
- Apply MFA to all non-console CDE access and all remote access — two passwords do not count as MFA.
{{/snapshot}}
PCI DSS Requirement 8.4: Ensure users are properly trained on account authentication.
PCI DSS Requirement 8.4 states that all policies and procedures related to user identification and authorisation must be documented.This includes guidance that allows the user to create suitably strong account credentials and will also inform them on how to protect, maintain, and make changes to these accounts.
PCI DSS Requirement 8.5: Reduce any generic or shared credentials.
Businesses should ensure that they immediately remove and replace all generic and shared user IDs. For service providers, this includes:
- PCI DSS 8.5.1 – Utilising unique user IDs for each customer in any situation involving remote access to the customers’ premises.
PCI DSS Requirement 8.6: Safeguard devices individually.
PCI DSS Requirement 8.6 states that if physical methods of payment, such as cards, or certificates are used, then their use needs to be carefully documented and restricted. This includes authenticating these methods by account and verifying the owner’s identity through either physical or logical controls.
{{snapshot}}
Locking down accounts and databases
- Remove and replace generic or shared user IDs; service providers use a unique ID per customer for remote access.
- Document and restrict physical authentication factors such as cards or certificates, tied to a verified owner.
- Restrict CDE database access to programmatic methods, with direct queries limited to administrators.
{{/snapshot}}
PCI DSS Requirement 8.7: Ensure access to CDE databases is completely restricted.
Businesses must ensure that any user access to CDE databases takes place using programmatic methods, with all queries and direct access coming from the relevant administrators. Additionally, all user IDs for app access must be limited to in-app use.
PCI DSS Requirement 8.8: Document and distribute all policies.
All relevant staff will need to know and follow all security policies and procedures to ensure that access is limited on a ‘need-to-know’ basis. This can be done by documenting and distributing all policies throughout the workforce, ensuring staff are fully trained based on their privilege level.
{{snapshot}}
From the Hicomply team
Requirement 8 is really an identity and access-management discipline: unique IDs, MFA, password rules, and prompt de-provisioning all have to be evidenced continuously, not just at audit time. We find teams cut the effort by managing access controls in one place and reusing that evidence across frameworks, since much of it overlaps with ISO 27001 access controls. A platform tour shows how, and our free compliance tools are a good starting point.
{{/snapshot}}
Comply with PCI DSS Requirement 8 with Hicomply
PCI DSS compliance can mean incredible benefits for your business and for most, is completely mandatory. However, it can be hard to navigate, especially for those who are new to the certification.At Hicomply, we offer a full-fledged ISMS solution that takes all the stress out of the process – giving you compliance as you work! Contact us today for a demo.
Ready to Take Control of Your Privacy Compliance?
See how Hicomply can accelerate your path to CAF compliance in a 15-minute demo.



