February 6, 2024

PCI DSS Requirement 8: What Is It and How to Comply?

PCI DSS Requirement 8.1 is put in place to ensure that all the business’ internal users of payment transaction systems have a unique user ID based on their job responsibilities. This creates a sense of accountability that allows problems to be solved quickly.

By
Full name
Share this post
https://www.hicomply.com/hub/pci-dss-requirement-8
A woman smiles while using a tablet, surrounded by digital notifications and a data chart.

The sub-sub-requirements include:

ControlRequirement
8.1.1Assign unique IDs to all users before granting access to the CDE
8.1.2Manage which staff can add, delete, or edit user accounts and credentials
8.1.3Revoke access immediately when a user is terminated
8.1.4Terminate or disable accounts after 90 days of inactivity
8.1.5Manage, restrict, and monitor all third-party IDs used to access systems
8.1.6Lock users out after a maximum of six failed login attempts
8.1.7Set lockout durations of at least 30 minutes
8.1.8Require re-login after more than 15 minutes idle

{{snapshot}}

Managing user IDs and access

  • Assign a unique ID to every user before granting access to the cardholder data environment (CDE).
  • Revoke access immediately on termination, and disable accounts after 90 days of inactivity.
  • Lock accounts after six failed logins, hold lockouts for at least 30 minutes, and re-login after 15 minutes idle.

{{/snapshot}}

PCI DSS Requirement 8.2: Create user authentication policies.

Your business will have to establish authentication processes to identify the user. These authenticating factors can include passwords, specific devices, or a biometric scan, but must be used to safeguard accounts. The sub-sub-requirements are as follows:

  • PCI DSS 8.2.1 – Implement cryptography when transmitting and storing of user credentials.
  • PCI DSS 8.2.2 – Verify a user’s identity before editing their authentication credentials. 
  • PCI DSS 8.2.3 – Ensure user passwords have a strength limit. This usually involves including a minimum of seven characters and at least one number, a letter and special character.
  • PCI DSS 8.2.4 – Ensure user passwords are changed every 90 days.
  • PCI DSS 8.2.5 – Do not allow users to reuse passwords and passphrases.
  • PCI DSS 8.2.6 – Issue unique passwords for first-time users that they will need to change immediately after their first use.

PCI DSS Requirement 8.3: Implement Multi-Factor Authentication

Multi-factor authentication requires a user to go through more than one authentication process to prove their identity and gain access, especially when working remotely. This entails:

  • PCI DSS 8.3.1 – Incorporating MFA for all non-console access to the CDE, including for those with administration privileges.
  • PCI DSS 8.3.2 – Incorporating MFA for all user and admin access that is either remote or outside the company’s internal network.

It’s important to note that having two passwords does not constitute MFA.

{{snapshot}}

Passwords and multi-factor authentication

  • Passwords need a minimum of seven characters with at least one letter, number, and special character, changed every 90 days and never reused.
  • Encrypt credentials in transit and storage, and verify identity before changing them.
  • Apply MFA to all non-console CDE access and all remote access — two passwords do not count as MFA.

{{/snapshot}}

PCI DSS Requirement 8.4: Ensure users are properly trained on account authentication.

PCI DSS Requirement 8.4 states that all policies and procedures related to user identification and authorisation must be documented.This includes guidance that allows the user to create suitably strong account credentials and will also inform them on how to protect, maintain, and make changes to these accounts.

PCI DSS Requirement 8.5: Reduce any generic or shared credentials.

Businesses should ensure that they immediately remove and replace all generic and shared user IDs. For service providers, this includes:

  • PCI DSS 8.5.1 – Utilising unique user IDs for each customer in any situation involving remote access to the customers’ premises.

PCI DSS Requirement 8.6: Safeguard devices individually.

PCI DSS Requirement 8.6 states that if physical methods of payment, such as cards, or certificates are used, then their use needs to be carefully documented and restricted. This includes authenticating these methods by account and verifying the owner’s identity through either physical or logical controls.

{{snapshot}}

Locking down accounts and databases

  • Remove and replace generic or shared user IDs; service providers use a unique ID per customer for remote access.
  • Document and restrict physical authentication factors such as cards or certificates, tied to a verified owner.
  • Restrict CDE database access to programmatic methods, with direct queries limited to administrators.

{{/snapshot}}

PCI DSS Requirement 8.7: Ensure access to CDE databases is completely restricted.

Businesses must ensure that any user access to CDE databases takes place using programmatic methods, with all queries and direct access coming from the relevant administrators. Additionally, all user IDs for app access must be limited to in-app use.

PCI DSS Requirement 8.8: Document and distribute all policies.

All relevant staff will need to know and follow all security policies and procedures to ensure that access is limited on a ‘need-to-know’ basis. This can be done by documenting and distributing all policies throughout the workforce, ensuring staff are fully trained based on their privilege level.

{{snapshot}}

From the Hicomply team

Requirement 8 is really an identity and access-management discipline: unique IDs, MFA, password rules, and prompt de-provisioning all have to be evidenced continuously, not just at audit time. We find teams cut the effort by managing access controls in one place and reusing that evidence across frameworks, since much of it overlaps with ISO 27001 access controls. A platform tour shows how, and our free compliance tools are a good starting point.

{{/snapshot}}

Comply with PCI DSS Requirement 8 with Hicomply

PCI DSS compliance can mean incredible benefits for your business and for most, is completely mandatory. However, it can be hard to navigate, especially for those who are new to the certification.At Hicomply, we offer a full-fledged ISMS solution that takes all the stress out of the process – giving you compliance as you work! Contact us today for a demo.

Risk Management
Compliance Reporting
Policy Management
Incident Management
Audits and Assessments

Ready to Take Control of Your Privacy Compliance?

See how Hicomply can accelerate your path to CAF compliance in a 15-minute demo.

Risk Management

Identify, assess, and mitigate security risks with an integrated risk register.Hicomply’s automated risk management software maps controls across ISO 27001, SOC 2, and NIST frameworks — helping teams track risk treatment plans, assign ownership, and monitor real-time compliance status. Build a resilient ISMS that reduces audit findings and demonstrates continuous improvement.

Compliance Reporting

Generate instant, audit-ready compliance reports across multiple frameworks — from ISO 27001 and SOC 2 to GDPR, DORA, and NHS DSPT.Automated evidence collection and built-in dashboards provide a single source of truth for your compliance posture, saving weeks of manual work during audits.

Policy Management

Centralise, version, and publish all your information security policies in one place.Hicomply automates approvals, reminders, and distribution, ensuring your ISMS documentation stays current and aligned with frameworks like ISO 42001 and NIST CSF.Say goodbye to outdated PDFs — manage policies dynamically and maintain full traceability.

Incident Management

Capture, investigate, and resolve security incidents with structured workflows and automated evidence trails.Hicomply integrates with ticketing tools like Jira, Zendesk, and Azure DevOps to streamline incident response and link findings to risk and control updates — a key step for SOC 2 Type II readiness.

Audits and Assessments

Simplify internal and external audit preparation with built-in audit templates and automated task assignments.
Hicomply’s audit management platform aligns with ISO 27001, ISO 9001, and ISO 14001, giving teams a clear overview of control effectiveness, audit evidence, and corrective actions — all from one dashboard.

Getting Started
IT and Services
Growth