PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Free guide · PCI DSS v4.0.1

PCI DSS Requirement 8.4.2 — MFA for all access into the CDE

Requirement 8.4.2 broadens MFA well beyond the v3.2.1 position. Multi-factor authentication is now required for all access into the cardholder data environment — including access from inside the corporate network — with a narrow exception for user accounts on a POI terminal that only have access to one card number at a time.Timing: Future-dated requirement in PCI DSS v4.0 — mandatory for all assessments since 31 March 2025.

Who it applies to

All personnel accounts with access into the cardholder data environment
Administrative and non-administrative access alike, from inside or outside the network

What Requirement 8.4.2 asks for

Paraphrased from PCI DSS v4.0.1. Read the standard itself for the authoritative wording and testing procedures.

MFA is implemented for all access into the CDE.
The exception is user accounts on point-of-interaction devices that have access to only one card number at a time to support a single transaction.
MFA must use at least two of the three factor types, and success requires all factors — no factor may reveal the outcome of another.

Evidence an assessor expects

MFA configuration for every access path into the CDE — VPN, jump host, console, cloud portal and application logins
An account inventory showing which accounts have CDE access and their MFA status
Evidence that MFA cannot be bypassed and that failure of one factor blocks access
Documentation of any POI exception applied

Common mistakes

Enforcing MFA only on remote access, leaving on-network CDE access single-factor.
Two passwords, or a password plus a security question — that is one factor type, not two.
Break-glass or vendor accounts left exempt without a compensating control.

Not sure whether Requirement 8.4.2 is in your scope?

Which requirements you must answer depends on the SAQ that applies to your environment. The free SAQ selector walks the official PCI SSC decision flow, records every answer and re-derives the recommendation server-side with a confidence score.

Paraphrased from PCI DSS v4.0.1 (PCI Security Standards Council). Independent summary; not endorsed by PCI SSC. Refer to the PCI SSC Document Library for the authoritative standard.