What PCI DSS v4 Req 2 (Hardening) requires
Requirement 2 mandates the application of secure configuration standards across all system components within the Cardholder Data Environment, explicitly prohibiting reliance on vendor-supplied defaults. Governing guidance stipulates that a formal, documented system hardening standard, based on established frameworks such as NIST or CIS, must exist and be consistently applied to all in-scope systems. Compliance necessitates the proactive removal or modification of all vendor-supplied default credentials, including specific confirmation that wireless environment vendor defaults were changed at installation. Furthermore, the operational state must reflect that all insecure protocols such as Telnet, FTP, HTTP, and early TLS versions are disabled, and any unnecessary services, daemons, or functions not directly required for a component's purpose are deactivated to minimize the attack surface. Authoritative controls enforce a strict policy of one primary function per server to prevent security-level conflicts, a mandate supported by a continuously maintained inventory of all system components. Comprehensive security policies and operational procedures for managing configurations must be documented and known by affected parties, with hardening integrity confirmed through timely automated verification scans. For entities utilizing shared hosting, it is imperative that documented confirmation from the provider defines their specific responsibility for protecting merchant environments.
Pillar: Cloud & SaaS · Authority: PCI Security Standards Council · Version: 1.1.0 · Last updated:
Primary source: https://www.pcisecuritystandards.org/document_library/
SHA-256 integrity: 52aa6daaec280df71be7519628c7850def1a765ddc17e38d249c9b30d3066370
Primary Citations — 6 traced to source
- {"citation_id":"PCI DSS v4.0 Req 2","citation_text":"Payment Card Industry Data Security Standard (PCI DSS) v4.0, Requirement 2: Apply Secure Configurations to All System Components.","url":"https://listings.pcisecuritystandards.org/documents/PCI-DSS-v4-0.pdf"}
- {"citation_id":"NIST SP 800-53 Rev. 5 CM-6","citation_text":"National Institute of Standards and Technology (NIST) Special Publication 800-53, Security and Privacy Controls for Information Systems and Organizations, Control Family: CM-6 (Configuration Settings).","url":"https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final"}
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/pci-dss-v4-requirement-2.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/pci-dss-v4-requirement-2.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/pci-dss-v4-requirement-2
- Back to registry: Browse all 10,085 compliance nodes