Start with Identity
← Glossary
Compliance

PCI DSS

Payment Card Industry Data Security Standard. Required of any organization that stores, processes, or transmits cardholder data. The current major version (4.0) tightens authentication requirements and adds MFA for non-console administrative access.

PCI DSS 4.0 pushed authentication requirements up sharply: MFA for all access into the cardholder data environment rather than just remote administrative access, and stronger password rules where passwords remain. For identity teams the practical impact is scoping, since every account that can reach the environment is in scope, including service accounts and vendor support access.

See also: compliance guides, MFA, what is PAM, retail and e-commerce identity

Last reviewed By SWI Community TeamSuggest a correctionHow we research