Two-Factor Authentication (2FA)

PCIComplianceHubLast updated

Multi-factor authentication using exactly two factors. 2FA is a subset of MFA rather than a separate control, and the same rule applies: the two factors must come from different categories, so a password paired with a security question does not qualify. Older PCI DSS versions framed the requirement as two-factor authentication for remote access; v4.x speaks in terms of multi-factor authentication and extends it to all access into the cardholder data environment, not only remote access. See Multi-factor Authentication (MFA) under M.