| Cyber insurance | Any policyholder completing a cyber-insurance renewal. | MFA attested for privileged accounts, remote access, and business-critical applications. | Attested at every renewal. | Denied claims or rescinded coverage after a misstatement. | Cyber insurance MFA guide |
|---|
| PCI DSS 4.0.1 | Merchants and service providers that store, process, or transmit cardholder data. | Requirement 8.4.2 requires MFA for all access into the cardholder data environment; related requirements cover admin and remote access. | Mandatory since March 31, 2025. | Failed assessment, remediation pressure, and acquirer or contract penalties. | PCI DSS MFA guide |
|---|
| Cyber Essentials (UK) | UK Cyber Essentials certificate holders and suppliers. | MFA for cloud services, administrator accounts, user accounts, and internet-facing services where the question set applies. | v3.3 question set applies from April 27, 2026. | Auto-fail, no certification, and supply-chain eligibility risk. | Cyber Essentials MFA guide |
|---|
| CJIS | Agencies, vendors, contractors, and non-criminal-justice entities that access CJI. | Advanced authentication, commonly MFA, for access paths that touch Criminal Justice Information. | Sanctionable since Oct. 1, 2024; v5.9.5 remains a current audit baseline while CJIS 6.x transition work continues. | Sanctions, audit findings, and possible loss of CJIS/NCIC/III access. | CJIS MFA guide |
|---|
| CMMC / NIST 800-171 | Defense supply-chain organizations handling CUI. | IA.L2-3.5.3 requires MFA for local and network access to privileged accounts and for network access to non-privileged accounts. | CMMC Level 2 assessments are active. | Assessment failure and defense-contract eligibility risk. | CMMC MFA guide |
|---|
| NYDFS Part 500 | New York financial-services covered entities. | 23 NYCRR 500.12 requires MFA for individuals accessing covered information systems, subject to limited exemptions and CISO-approved compensating controls. | Expanded MFA requirement effective Nov. 1, 2025. | Examination findings, enforcement actions, and monetary penalties. | NYDFS MFA guideNYDFS MFA solution |
|---|
| HIPAA | Covered entities and business associates protecting ePHI. | Current Security Rule technical safeguards require access controls; the proposed Security Rule update would add explicit MFA requirements. | NPRM still proposed; current Security Rule remains in effect. | Corrective action plans, enforcement penalties, and breach-response findings. | HIPAA MFA guideHIPAA MFA solution |
|---|
| SOX (ITGC) | US public companies and SOX-scoped financial systems. | SOX does not name MFA directly, but auditors test logical access, privileged access, and financial-system ITGC controls. | Evaluated every audit cycle. | Control deficiency, significant deficiency, or material weakness depending on severity and remediation. | SOX MFA guide |
|---|
| FTC Safeguards Rule | Non-bank financial institutions under FTC jurisdiction, including many dealers and lenders. | MFA for anyone accessing customer information on covered systems, unless the Qualified Individual approves an equivalent secure-access control in writing. | In force. | FTC enforcement and breach-notification exposure. | FTC MFA guide |
|---|
| DORA (EU) | EU financial entities and covered ICT providers. | Strong authentication and access controls as part of ICT risk management and digital operational resilience programs. | Applies since Jan. 17, 2025. | Supervisory findings, remediation orders, and regulator sanctions. | DORA MFA guide |
|---|
| TSA Security Directives | TSA-designated critical pipeline/LNG operators and designated freight, passenger rail, and rail transit owner/operators. | Pipeline and rail cybersecurity directives require access-control measures, including MFA or justified compensating measures, for critical cyber systems and remote-access paths. | Directives remain in force and are reissued periodically; the permanent surface cyber rule is still pending. | TSA inspection findings, action-plan remediation, and civil-penalty exposure for unresolved gaps. | TSA MFA guide |
|---|
| NIS2 | Essential and important entities across covered EU sectors, plus suppliers facing flow-down requirements. | Article 21(2)(j) explicitly includes multi-factor authentication or continuous authentication as a cybersecurity risk-management measure. | Transposition deadline passed Oct. 17, 2024; as of July 2026, several member states still face Commission action. | Administrative fines, regulator orders, and management-accountability exposure. | NIS2 MFA guide |
|---|
| ISO 27001 | Organizations certifying an ISMS under ISO/IEC 27001:2022. | Annex A access-control and secure-authentication controls make MFA an expected risk treatment for sensitive and privileged access. | Assessed during certification and surveillance audits. | Certification nonconformity, audit observations, and corrective-action pressure. | ISO 27001 MFA guide |
|---|
| SOC 2 | Service organizations seeking SOC 2 attestation. | CC6 logical-access criteria do not name MFA, but auditors commonly expect MFA evidence for privileged, remote, and sensitive application access. | Tested across the audit period, especially for Type II reports. | SOC 2 exceptions, remediation commitments, qualified-report risk, and lost enterprise deals. | SOC 2 MFA guide |
|---|
| Essential Eight | Australian government entities and organizations aligning to the ACSC Essential Eight maturity model. | MFA is one of the ACSC Essential Eight mitigation strategies, with requirements that increase across maturity levels. | Reviewed against the current maturity model during assessment. | Assessment failure, maturity-level gaps, and public-sector or supplier eligibility risk. | Essential Eight MFA guide |
|---|
| TISAX | Automotive suppliers and service providers that need a TISAX label for OEM or tier-1 work. | VDA ISA access-control and authentication expectations, mapped from ISO 27001/27002, drive strong authentication for high-protection and privileged access. | Assessed through the ENX TISAX process. | Assessment findings, delayed TISAX label, and lost automotive supply-chain opportunities. | TISAX MFA guide |
|---|
| GLBA / FSA (higher ed) | Title IV higher-education institutions. | Safeguards Rule MFA expectations for student financial data and institutional systems that handle covered information. | In force. | FSA findings and student-financial-aid program eligibility risk. | Guide coming |
|---|