PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Free guide · PCI DSS v4.0.1

PCI DSS Requirement 2.2.1 — Secure configuration standards

Requirement 2.2.1 requires configuration standards that cover all system components in scope, address known vulnerabilities, follow industry-accepted hardening standards or vendor recommendations, are updated as new vulnerabilities emerge, and are applied and verified before or immediately after a system joins production.Timing: Applies in PCI DSS v4.0.1 and is assessed at every annual assessment.

Who it applies to

Every in-scope system component: servers, workstations, network devices, cloud instances, containers and appliances
Entities completing SAQ C, SAQ D-Merchant or SAQ D for Service Providers

What Requirement 2.2.1 asks for

Paraphrased from PCI DSS v4.0.1. Read the standard itself for the authoritative wording and testing procedures.

Configuration standards are developed, implemented and maintained for all system components.
The standards address all known security vulnerabilities.
They are consistent with industry-accepted system hardening standards or vendor hardening recommendations.
They are updated as new vulnerability issues are identified, per Requirement 6.3.1.
They are applied when new systems are configured and verified as in place before or immediately after the system is connected to production.

Evidence an assessor expects

Written hardening standards per platform, with the benchmark or vendor guide they derive from
Build or image documentation showing the standard applied
Configuration scan or compliance-check output against the standard
Change records showing verification before or immediately after a system entered production

Common mistakes

A single generic policy document instead of per-platform standards for each technology in scope.
Standards written once and never updated as new vulnerabilities and benchmark revisions appear.
Cloud images and containers built outside the documented pipeline and never checked against the standard.

Not sure whether Requirement 2.2.1 is in your scope?

Which requirements you must answer depends on the SAQ that applies to your environment. The free SAQ selector walks the official PCI SSC decision flow, records every answer and re-derives the recommendation server-side with a confidence score.

Paraphrased from PCI DSS v4.0.1 (PCI Security Standards Council). Independent summary; not endorsed by PCI SSC. Refer to the PCI SSC Document Library for the authoritative standard.