You are the identity administrator at a merchant whose password policy was inherited from a corporate standard, and the assessor has asked which floor applies to accounts that reach the cardholder data environment.
What is the minimum password length required under PCI DSS?
- A.7 characters
- B.6 characters
- C.8 characters
- D.12 characters
Why D is correct
PCI DSS v4.0 Requirement 8.3.6 sets the minimum at 12 characters. Eight characters is permitted only where a system cannot technically support 12, so it is a documented exception rather than the requirement. Seven characters was the v3.2.1 floor, and v3.2.1 retired on 31 March 2024, so it no longer applies to any assessment. Six characters has never been acceptable under any version of the standard.
Know someone studying for PCI DSS? Send them this one.