PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Free guide · PCI DSS v4.0.1

PCI DSS Requirement 8.3.6 — Password and passphrase strength

Requirement 8.3.6 sets the minimum strength for passwords and passphrases used as an authentication factor. Passwords must be at least 12 characters long and contain both numeric and alphabetic characters, with a narrow exception where a system cannot technically support 12.Timing: Future-dated requirement in PCI DSS v4.0 — mandatory for all assessments since 31 March 2025.

Who it applies to

All user accounts with access to system components in the cardholder data environment
Application and system accounts that use a password as an authentication factor

What Requirement 8.3.6 asks for

Paraphrased from PCI DSS v4.0.1. Read the standard itself for the authoritative wording and testing procedures.

Passwords and passphrases must be a minimum of 12 characters.
Where a system does not technically support 12 characters, the minimum is 8 characters.
Passwords must contain both numeric and alphabetic characters.

Evidence an assessor expects

System and application password policy configuration screenshots showing enforced length and character rules
A written policy that matches the enforced configuration
For any 8-character exception, evidence the platform cannot technically support 12

Common mistakes

Enforcing the rule in policy but not in system configuration.
Applying it to staff accounts only and missing service and application accounts.
Using the 8-character exception as a default rather than a documented technical limitation.

Not sure whether Requirement 8.3.6 is in your scope?

Which requirements you must answer depends on the SAQ that applies to your environment. The free SAQ selector walks the official PCI SSC decision flow, records every answer and re-derives the recommendation server-side with a confidence score.

Paraphrased from PCI DSS v4.0.1 (PCI Security Standards Council). Independent summary; not endorsed by PCI SSC. Refer to the PCI SSC Document Library for the authoritative standard.