PCI_DSS_v4Requirement 8voice-validated

PCI_DSS_v4 R8: Requirement 8

PCI_DSS_v4

AL
Adam Lundqvist
Founder at SQUR · last verified 2026-10-06

Regulation text

Two fundamental principles of identifying and authenticating users are to (1) establish the identity of an individual or process and (2) verify the user or process is who or what they claim to be. The identification of a user or process on a system can be established in multiple ways with each providing a different level of assurance. PCI DSS 4.0 requires MFA for all access into the CDE.

ATT&CK techniques this article tests · 15

TechniqueWhy it mapsConfidence
T10781. PCI DSS 4.0 Requirement 8 mandates MFA for all CDE access, directly countering the use of compromised valid accounts for initial access, persistence, or lateral movement. 2. This reduces the risk of unauthorized system access.
90%
T11331. External remote services are a common entry point. 2. PCI DSS 4.0 Requirement 8's MFA mandate secures these services, preventing unauthorized access to the CDE.
90%
T10981. Unauthorized account manipulation can lead to persistence. 2. Strong authentication, including MFA as per PCI DSS 4.0 Requirement 8, protects against illicit account modifications.
80%
T15551. Even if credentials are stolen from password stores, PCI DSS 4.0 Requirement 8's MFA requirement prevents their direct use for CDE access. 2. This adds a critical layer of security.
90%
T15501. Attackers may attempt to bypass standard authentication. 2. PCI DSS 4.0 Requirement 8's MFA mandate significantly increases the complexity and difficulty of such bypass attempts.
80%
T10031. OS credential dumping provides credentials. 2. PCI DSS 4.0 Requirement 8's MFA ensures that dumped credentials alone are insufficient for gaining access to the CDE.
90%
T11101. Brute-force attacks attempt to guess credentials. 2. PCI DSS 4.0 Requirement 8's MFA requirement drastically increases the effort and time needed for successful brute-force attacks.
90%
T10871. Account discovery identifies potential targets. 2. While not directly preventing discovery, PCI DSS 4.0 Requirement 8's MFA makes discovered accounts less exploitable without the second factor.
70%
T1078.0011. Domain accounts are frequently targeted. 2. PCI DSS 4.0 Requirement 8 mandates MFA for all CDE access, including those using domain accounts, enhancing security.
90%
T1078.0021. Local accounts can be compromised. 2. PCI DSS 4.0 Requirement 8's MFA requirement applies to local accounts accessing the CDE, providing robust protection.
90%
T1078.0031. Cloud accounts are increasingly used for CDE access. 2. PCI DSS 4.0 Requirement 8 extends MFA requirements to these accounts, securing cloud environments.
90%
T1078.0041. Shared accounts pose a significant risk. 2. PCI DSS 4.0 Requirement 8's MFA, if applied to shared accounts, adds a layer of individual accountability and security.
80%
T10401. Network sniffing can capture credentials. 2. While encryption is primary, PCI DSS 4.0 Requirement 8's MFA ensures captured credentials are not sufficient for CDE access.
70%
T1071.0011. Command and control often relies on initial authentication. 2. PCI DSS 4.0 Requirement 8's MFA can prevent unauthorized C2 channel establishment if it requires user authentication.
70%
T10211. Remote services are critical access points. 2. PCI DSS 4.0 Requirement 8 mandates MFA for all access into the CDE, directly securing these remote services.
90%

Defending mitigations · 5

MitigationWhat it doesConfidence
M10321. PCI DSS 4.0 Requirement 8 explicitly mandates Multi-Factor Authentication for all access into the CDE. 2. This is a direct and primary mitigation.
100%
M10301. Account use policies define authentication requirements. 2. PCI DSS 4.0 Requirement 8's MFA mandate is implemented via such policies, ensuring proper user identification and verification.
90%
M10271. Strong password policies complement MFA. 2. PCI DSS 4.0 Requirement 8's focus on authentication includes robust password practices alongside MFA for comprehensive security.
80%
M10171. Effective user account management ensures proper setup of authentication mechanisms. 2. PCI DSS 4.0 Requirement 8 relies on this for correct MFA implementation and enforcement.
80%
M10361. Privileged accounts require heightened security. 2. PCI DSS 4.0 Requirement 8's MFA mandate is especially critical for these accounts, protecting sensitive CDE access.
90%

Underlying weaknesses · 6

CWEWhy it persistsConfidence
CWE-2871. Improper authentication is the core vulnerability addressed. 2. PCI DSS 4.0 Requirement 8 directly combats this by mandating robust identification and verification, including MFA.
100%
CWE-3061. Missing authentication for critical functions allows unauthorized access. 2. PCI DSS 4.0 Requirement 8 explicitly requires MFA for all CDE access, closing this gap.
90%
CWE-3071. Excessive authentication attempts enable brute-force attacks. 2. PCI DSS 4.0 Requirement 8's MFA significantly raises the bar for such attacks, often combined with lockout policies.
90%
CWE-5211. Weak password requirements undermine single-factor authentication. 2. PCI DSS 4.0 Requirement 8's MFA requirement compensates for this weakness by adding a second verification factor.
80%
CWE-2881. Authentication bypasses exploit alternative paths. 2. PCI DSS 4.0 Requirement 8's MFA makes it substantially harder to bypass the required authentication mechanisms.
80%
CWE-7981. Hard-coded credentials bypass standard authentication flows. 2. While MFA doesn't directly prevent hard-coding, PCI DSS 4.0 Requirement 8 emphasizes proper user identification, discouraging such practices.
70%

What SQUR Covers

Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.

What SQUR Does Not Cover

Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.

Provenance

Mapped Q2.2026 using gemini-2.5-flash · €0.0189 compute · voice-rubric self-validated · 1 hallucination(s) dropped at validation