If your organization handles payment card data, PCI DSS is no longer a deadline on the horizon. It’s the standard your assessor is testing against right now.
The future-dated requirements introduced with PCI DSS 4.0 became mandatory on March 31, 2025. This is no longer best practice. They are scored in every assessment, and a large share of them land squarely on identity: who can reach the cardholder data environment, how they authenticate and whether the accounts that run your payment systems are under control.
Learn about what has changed, the identity requirements that matter most now and how the Delinea Platform helps you meet them.
The PCI Standards Council (PCI SCC) released PCI DSS in March 2022, marking a shift toward outcome-based security. Instead of prescribing exact controls, it set the security goal and gave organizations room to meet it in ways that fit their environments.
That flexibility raised questions, so the Council published PCI DSS 4.0.1 in June 2024. It’s a limited revision: it added no requirements, removed none, corrected formatting and typographical errors and clarified the intent of some requirements and their guidance. The Council retired PCI DSS 4.0 on December 31, 2024, so 4.0.1 is the only active version today. If you’re working toward 4.0, following the 4.0.1 guidance keeps you aligned.
For identity teams, one clarification in 4.0.1 matters: the requirement for MFA on all access to the cardholder data environment doesn’t apply to accounts that authenticate with only phishing-resistant factors.
Several of the requirements that became mandatory in March 2025 are identity controls. These are the ones to focus on:
Requirement 8.4.2 now requires MFA for all access to the cardholder data environment (CDE), not just administrative access. Requirement 8.5.1 sets expectations for implementing MFA so cybercriminals can’t bypass it. MFA at the perimeter is no longer enough. It belongs at every door into the environment.
Passwords used for access to the CDE must be at least 12 characters. The standard also opens the door to replacing a fixed 90-day rotation with a dynamic analysis of an account’s security posture, where you can support it.
This is the biggest change for identity, and the one most organizations underestimate.
Requirement 8.6.1 requires application and system accounts with interactive login be uniquely identified, justified and managed. Requirement 8.6.2 prohibits hardcoding passwords for those accounts in scripts, configurations or source code. Requirement 8.6.3 sets expectations for password strength and password changes on application and system accounts. Requirement 7.2.5 requires you to assign the privileges these accounts hold and review them regularly.
Service accounts have always been the quiet risk in a payment environment. They carry standing privilege, they rarely get reviewed, and their credentials too often sit in plain text where a cybercriminal can find them. PCI DSS now treats these accounts as first-class identities to manage and review. AI agents are the newest type of non-human identity entering these environments and are subject to the same system and application account requirements.
Requirement 7 continues to press least privilege and regular review of who has access, which is the direct answer to access creep. Requirement 10 expects continuous monitoring of access activity so anomalies surface quickly rather than months later. Cloud and hybrid environments raise the stakes because misconfigured entitlements and unmanaged credentials multiply fast.
Human access is well understood. You authenticate the person, apply least privilege and watch the session. Machine identities break that model. A service account or an AI agent doesn’t pause for an MFA prompt and often needs credentials to do its job. The old answer was to hand it a static secret and hope it stayed hidden. PCI DSS 4.x closes that path.
The durable fix is to remove the credential from the equation. When access is brokered through the platform, the connecting identity, human or machine or AI agent, never holds the credential to the target system. The platform authenticates to the resource, runs the session under a named identity, and logs every action is. The platform checks access before each action, so an AI agent can reach only what it’s entitled to. A stolen session or a compromised agent has no credential to take.
Meeting these requirements takes more than one tool. Privileged access management, secrets management, machine and AI agent access, cloud entitlements, threat detection, governance and reporting all play a part. The Delinea Platform brings them together, so the controls work as one rather than as a stack of point products with gaps between them.
At its core, the platform approaches every identity problem the same way: visibility, posture and control. Visibility means discovering every human, machine and AI account that can access the environment, which answers the account inventory and unique-identification requirements. Posture means reducing risk before access is used, through least privilege, access reviews and taking secrets out of code.
Control means enforcing the decision at the moment of action, with MFA, per-action authorization and the credential never reaching the user or the agent. The table below maps this framework to the specific requirements.
| Discipline | How the Delinea Platform helps | PCI focus |
| Privileged access management | Secret Server vaults privileged credentials and rotates them automatically. Privilege Control for Servers grants elevation just-in-time and enforces least privilege to limit lateral movement. Privilege Manager removes local admin rights and controls applications on endpoints. Privileged Remote Access gives third parties browser-based sessions that inject the credential, never exposed on the endpoint. | 7, 8, 10 |
| Secrets management | DevOps Secrets Vault issues application, service and machine credentials on demand, so you never hardcode passwords in scripts, configuration files or source code. | 8.6.2 |
| Machine and AI agent identity | The platform brokers the connection to servers, databases, Kubernetes and cloud so the credential never reaches the user, the service account or the AI agent. Each session runs under a named identity and is fully logged, and agent access is checked before each action. | 7.2.5, 8.6 |
| Cloud entitlement management | Privilege Control for Cloud Entitlements discovers entitlements across cloud and identity providers, right-sizes them to least privilege and vaults unprotected credentials it finds. | 7.2 |
| Identity threat detection and response | Identity Threat Protection baselines identities with behavioral analytics, flags anomalies in real time and responds by pulling access, resetting credentials or forcing step-up authentication. | 10 |
| Identity governance | Fastpath Access Review runs periodic reviews and certifications of who can reach CDE systems. Fastpath Access Provisioning grants access with real-time segregation-of-duties and sensitive-access checks. | 7 |
| Governance, risk and compliance | Fastpath Access Control finds and resolves segregation-of-duties conflicts across applications and produces audit-ready reports. | 12 |
| Multi-factor authentication | The platform challenges for MFA at the vault, at credential request, at asset login and at privilege elevation, with adaptive checks based on risk. | 8.4.2, 8.5.1 |
For a fuller view across frameworks, the identity security compliance mapping whitepaper compares the major standards side by side. If your identity controls satisfy PCI DSS, they carry over to NIST, ISO and similar frameworks. over to NIST, ISO and similar frameworks.
The cost of non-compliance is real: fines, higher transaction fees, the loss of card-processing privileges. The cost of a breach is higher. Weak control over privileged and service accounts is one of the most common ways cyber criminals reach cardholder data, and a clean report on paper won’t stop that if the controls are not operating.
Treat the PCI DSS identity requirements as the floor, not the goal:
Vault and rotate credentials.
Take secrets out of code.
Broker access so the credential never reaches the identity using it.
Review who and what can reach the environment.
Watch for anomalies in real time.
Do that and you pass the assessment. You also raise the bar for the cyber criminal, which is the point.
Explore the Delinea Platform to extend least privilege across every human, machine and AI identity in your payment environment.