Datawiza

MFA compliance hub

MFA Compliance Requirements: Every Framework, One Table

MFA has moved from best practice to mandate, but every framework mandates it differently: explicit rules with auto-fail consequences, deadline-driven requirements, auditor expectations, or renewal attestations that can affect coverage.

The common thread is that the requirement follows the data and the application, not only the network. Findings concentrate on legacy web applications that cannot do MFA natively, and that gap closes at the access layer without code changes.

Compare frameworks
MFA requirements across compliance frameworks compared

Master table

Which Regulations Require MFA?

This table summarizes the live Datawiza guides linked below. When a framework changes, update the detailed guide first, then sync this row.

FrameworkWho's in scopeWhat it requiresStatus / key dateConsequence of a gapFull guide
Cyber insuranceAny policyholder completing a cyber-insurance renewal.MFA attested for privileged accounts, remote access, and business-critical applications.Attested at every renewal.Denied claims or rescinded coverage after a misstatement.Cyber insurance MFA guide
PCI DSS 4.0.1Merchants and service providers that store, process, or transmit cardholder data.Requirement 8.4.2 requires MFA for all access into the cardholder data environment; related requirements cover admin and remote access.Mandatory since March 31, 2025.Failed assessment, remediation pressure, and acquirer or contract penalties.PCI DSS MFA guide
Cyber Essentials (UK)UK Cyber Essentials certificate holders and suppliers.MFA for cloud services, administrator accounts, user accounts, and internet-facing services where the question set applies.Danzell v3.3 question set applies from April 27, 2026.Auto-fail, no certification, and supply-chain eligibility risk.Cyber Essentials MFA guide
CJISAgencies, vendors, contractors, and non-criminal-justice entities that access CJI.Advanced authentication, commonly MFA, for access paths that touch Criminal Justice Information.Sanctionable since Oct. 1, 2024; v5.9.5 remains a current audit baseline while CJIS 6.x transition work continues.Sanctions, audit findings, and possible loss of CJIS/NCIC/III access.CJIS MFA guide
CMMC / NIST 800-171Defense supply-chain organizations handling CUI.IA.L2-3.5.3 requires MFA for local and network access to privileged accounts and for network access to non-privileged accounts.CMMC Level 2 assessments are active.Assessment failure and defense-contract eligibility risk.CMMC MFA guide
NYDFS Part 500New York financial-services covered entities.23 NYCRR 500.12 requires MFA for individuals accessing covered information systems, subject to limited exemptions and CISO-approved compensating controls.Expanded MFA requirement effective Nov. 1, 2025.Examination findings, enforcement actions, and monetary penalties.NYDFS MFA guideNYDFS MFA solution
HIPAACovered entities and business associates protecting ePHI.Current Security Rule technical safeguards require access controls; the proposed Security Rule update would add explicit MFA requirements.NPRM still proposed; current Security Rule remains in effect.Corrective action plans, enforcement penalties, and breach-response findings.HIPAA MFA guideHIPAA MFA solution
SOX (ITGC)US public companies and SOX-scoped financial systems.SOX does not name MFA directly, but auditors test logical access, privileged access, and financial-system ITGC controls.Evaluated every audit cycle.Control deficiency, significant deficiency, or material weakness depending on severity and remediation.SOX MFA guide
FTC Safeguards RuleNon-bank financial institutions under FTC jurisdiction, including many dealers and lenders.MFA for anyone accessing customer information on covered systems, unless the Qualified Individual approves an equivalent secure-access control in writing.In force.FTC enforcement and breach-notification exposure.FTC MFA guide
DORA (EU)EU financial entities and covered ICT providers.Strong authentication and access controls as part of ICT risk management and digital operational resilience programs.Applies since Jan. 17, 2025.Supervisory findings, remediation orders, and regulator sanctions.DORA MFA guide
GLBA / FSA (higher ed)Title IV higher-education institutions.Safeguards Rule MFA expectations for student financial data and institutional systems that handle covered information.In force.FSA findings and student-financial-aid program eligibility risk.Guide coming
SOC 2Service organizations seeking SOC 2 attestation.CC6 logical-access controls; MFA is commonly expected as evidence for privileged, remote, and sensitive application access.Per audit period.Qualified report risk, remediation commitments, and lost enterprise deals.Guide coming

This page summarizes compliance requirements for planning purposes. Confirm applicability and evidence expectations with your legal, compliance, auditor, assessor, insurer, or regulator-facing team.

Access-layer pattern

The Pattern Across Every Framework

Compliance language varies, but the operational problem repeats: teams must prove MFA coverage for the real application paths that handle sensitive data. That is why enforcement at the access layer matters. It can protect legacy, custom, and packaged web applications in days, with Datawiza built-in MFA or an existing identity provider.

Coverage is the test

The finding lands on the application the IdP never reached, not the SaaS estate that already has MFA.

Evidence beats policy

Auditors and insurers ask for configs, challenge demos, policy assignments, and per-application logs.

Deadlines move faster than code

Compliance dates and renewal windows are shorter than most app rewrite or login modernization projects.

FAQ

MFA Compliance Questions

Which compliance frameworks require MFA?

Common MFA compliance drivers include PCI DSS 4.0.1, Cyber Essentials, CJIS, CMMC/NIST 800-171, NYDFS Part 500, HIPAA, SOX ITGC audits, the FTC Safeguards Rule, DORA, cyber-insurance renewals, GLBA/FSA requirements, and SOC 2 audits. Some mandate MFA explicitly, while others create MFA pressure through access-control, audit, or attestation requirements.

Does SOX, HIPAA, or GDPR explicitly require MFA?

Some frameworks mandate MFA by name, including PCI DSS, Cyber Essentials, CJIS, CMMC/NIST 800-171, NYDFS, and the FTC Safeguards Rule. SOX and HIPAA are more nuanced: SOX auditors test ITGC access controls, while the current HIPAA Security Rule requires access controls and the proposed update would add explicit MFA. GDPR does not mandate MFA by name.

What evidence do auditors and insurers ask for?

They usually ask for the application inventory, MFA policy, user and group assignments, screenshots or demos of the MFA challenge, access-flow diagrams, bypass-prevention controls, exception records, and logs showing successful, failed, allowed, and denied access decisions.

How do we add MFA to a legacy application before a deadline?

Put an access proxy in front of the application, prevent direct bypass, choose built-in MFA or your existing IdP, pilot with one user group or path, then collect policy configuration and per-application logs as evidence. This can close MFA gaps without changing application code.

Last verified

Maintenance Schedule

On each trigger, update the detailed guide first with a real content change, then sync this hub row. Do not make date-only updates.

Row verification

Cyber insurance

July 19, 2026

PCI DSS 4.0.1

July 19, 2026

Cyber Essentials (UK)

July 19, 2026

CJIS

July 19, 2026

CMMC / NIST 800-171

July 19, 2026

NYDFS Part 500

July 19, 2026

HIPAA

July 19, 2026

SOX (ITGC)

July 19, 2026

FTC Safeguards Rule

July 19, 2026

DORA (EU)

July 19, 2026

GLBA / FSA (higher ed)

Guide coming

SOC 2

Guide coming

FrameworkReview triggerCadence
Cyber EssentialsAnnual question-set update in spring.Every April
CJISCJIS 6.x releases and audit-baseline changes.Quarterly
PCI DSSPCI DSS 4.x revisions and assessment guidance updates.Semiannual
HIPAAHIPAA Security Rule NPRM finalization.Monthly until final, then annual
NYDFS / FTC / DORARegulatory amendments or official guidance updates.Annual
CMMC / NIST 800-171NIST revisions and CMMC assessment-ecosystem updates.Semiannual
SOX / cyber insuranceAudit season and cyber-insurance renewal season.Annual in Q3
NIS2 / ISO 27001Future cluster additions after published guide coverage exists.Semiannual

Next step

Bring the Framework and the Application

We will map the requirement to the application path, decide whether built-in MFA or your IdP fits best, and show the evidence you can collect for the review.

Datawiza is Easy to Get Started

Sign up to secure your AI agents and critical enterprise apps

Try Datawiza