PCI DSS v4.0: a bite-size guide to minimum password length requirements

To help organisations transition from PCI V3.2.1 to PCI V4.0 and maintain PCI compliance, Securious has developed a series of articles explaining how to implement the evolved requirements of the standard. 

PCI DSS v4.0 has introduced a stricter minimum password length requirement of 12 characters (however, it’s important to note that there’s an exception for legacy systems that can only support passwords up to 8 characters. In such cases, 8 characters remain the minimum acceptable length).

The PCI DSS v4.0 password length requirement is a significant jump from the PCI DSS v3.2.1’s requirement of 7 characters. It applies to any system that stores, processes, or transmits cardholder data. This essentially covers any platform involved in the flow of credit card information, regardless of whether the system is on-premise, cloud-based or a third party application. 

The primary reason for this change is to improve password security. Longer passwords are exponentially more difficult to crack by brute-force attacks, a common hacking technique. 

The method for enforcing a minimum password length requirement depends on the platform you’re using. Here are some examples of some common systems and how to update user password requirements:

Windows

You can enforce password length through Group Policy Management (GPMC) for domain environments. For standalone systems, adjustments can be made within the Windows Registry. Search online for specific instructions based on your Windows version (“Enforce minimum password length Windows [version]”).

Linux

Many Linux distributions allow setting password policies through command-line tools or configuration files. Look for documentation related to “password policy” or “passwdqc” for your specific distribution.

Web applications

This will typically involve modifying configuration settings within the application’s administration panel. Look for options related to “password policy” or “user settings” in your application’s documentation.

Custom-developed applications

The implementation depends on your development framework. Security libraries or frameworks often have built-in functionalities for password validation. Refer to your framework’s documentation for password policy enforcement.

Major cloud providers (AWS, Azure, GCP)

These platforms offer security features that allow setting password policies for user accounts or resources. Search the provider’s documentation for keywords like “IAM password policy” or “Identity and Access Management password policy”.

Additional considerations 

Remember that minimum length is just one aspect of good password practice. Complexity and exclusivity are also important (you can read more about this in one of our blogs by clicking here). 

A 12-character password with a combination of uppercase and lowercase letters, numbers, and symbols offers significantly more protection compared to a shorter password. 

But if that password is being reused across multiple accounts, suddenly the risk increases, because if there is a breach and that password somehow falls into the hands of an attacker, that attacker can then gain access to all the other accounts using that password.

This makes user education critical in ensuring the cardholder data environment is as secure as possible. The new minimum length requirements are a great step and can be enforced technically, but it’s up to you, your policies and your users to make sure that your environment isn’t exposed to a high level of risk due to poor password practice. 

To summarise

The PCI DSS v4.0 password minimum length requirement is a good step towards better security for the cardholder data environment. 

While implementing these changes might require adjustments to your systems and user training, the benefits are undeniable. And remember, stronger passwords are not just about complying with regulations; they are a fundamental part of protecting sensitive information and building trust with your customers. 

If you would like to discuss password security or PCI DSS v4.0 with our team, get in touch using the contact form below.

More PCI DSS content

PCI DSS Compliance – the Ultimate Guide

PCI DSS V4.0 Free Online Readiness Assessment

PCI DSS Free Online Quote Generator