Datawiza

MFA compliance hub

MFA Compliance Requirements: Every Framework, One Table

MFA has moved from best practice to mandate, but every framework mandates it differently: explicit rules with auto-fail consequences, deadline-driven requirements, auditor expectations, or renewal attestations that can affect coverage.

The common thread is that the requirement follows the data and the application, not only the network. Findings concentrate on legacy web applications that cannot do MFA natively, and that gap closes at the access layer without code changes.

Compare frameworks
MFA requirements across compliance frameworks compared

Master table

Which Regulations Require MFA?

This table summarizes the live Datawiza guides linked below. When a framework changes, update the detailed guide first, then sync this row.

FrameworkWho's in scopeWhat it requiresStatus / key dateConsequence of a gapFull guide
Cyber insuranceAny policyholder completing a cyber-insurance renewal.MFA attested for privileged accounts, remote access, and business-critical applications.Attested at every renewal.Denied claims or rescinded coverage after a misstatement.Cyber insurance MFA guide
PCI DSS 4.0.1Merchants and service providers that store, process, or transmit cardholder data.Requirement 8.4.2 requires MFA for all access into the cardholder data environment; related requirements cover admin and remote access.Mandatory since March 31, 2025.Failed assessment, remediation pressure, and acquirer or contract penalties.PCI DSS MFA guide
Cyber Essentials (UK)UK Cyber Essentials certificate holders and suppliers.MFA for cloud services, administrator accounts, user accounts, and internet-facing services where the question set applies.v3.3 question set applies from April 27, 2026.Auto-fail, no certification, and supply-chain eligibility risk.Cyber Essentials MFA guide
CJISAgencies, vendors, contractors, and non-criminal-justice entities that access CJI.Advanced authentication, commonly MFA, for access paths that touch Criminal Justice Information.Sanctionable since Oct. 1, 2024; v5.9.5 remains a current audit baseline while CJIS 6.x transition work continues.Sanctions, audit findings, and possible loss of CJIS/NCIC/III access.CJIS MFA guide
CMMC / NIST 800-171Defense supply-chain organizations handling CUI.IA.L2-3.5.3 requires MFA for local and network access to privileged accounts and for network access to non-privileged accounts.CMMC Level 2 assessments are active.Assessment failure and defense-contract eligibility risk.CMMC MFA guide
NYDFS Part 500New York financial-services covered entities.23 NYCRR 500.12 requires MFA for individuals accessing covered information systems, subject to limited exemptions and CISO-approved compensating controls.Expanded MFA requirement effective Nov. 1, 2025.Examination findings, enforcement actions, and monetary penalties.NYDFS MFA guideNYDFS MFA solution
HIPAACovered entities and business associates protecting ePHI.Current Security Rule technical safeguards require access controls; the proposed Security Rule update would add explicit MFA requirements.NPRM still proposed; current Security Rule remains in effect.Corrective action plans, enforcement penalties, and breach-response findings.HIPAA MFA guideHIPAA MFA solution
SOX (ITGC)US public companies and SOX-scoped financial systems.SOX does not name MFA directly, but auditors test logical access, privileged access, and financial-system ITGC controls.Evaluated every audit cycle.Control deficiency, significant deficiency, or material weakness depending on severity and remediation.SOX MFA guide
FTC Safeguards RuleNon-bank financial institutions under FTC jurisdiction, including many dealers and lenders.MFA for anyone accessing customer information on covered systems, unless the Qualified Individual approves an equivalent secure-access control in writing.In force.FTC enforcement and breach-notification exposure.FTC MFA guide
DORA (EU)EU financial entities and covered ICT providers.Strong authentication and access controls as part of ICT risk management and digital operational resilience programs.Applies since Jan. 17, 2025.Supervisory findings, remediation orders, and regulator sanctions.DORA MFA guide
TSA Security DirectivesTSA-designated critical pipeline/LNG operators and designated freight, passenger rail, and rail transit owner/operators.Pipeline and rail cybersecurity directives require access-control measures, including MFA or justified compensating measures, for critical cyber systems and remote-access paths.Directives remain in force and are reissued periodically; the permanent surface cyber rule is still pending.TSA inspection findings, action-plan remediation, and civil-penalty exposure for unresolved gaps.TSA MFA guide
NIS2Essential and important entities across covered EU sectors, plus suppliers facing flow-down requirements.Article 21(2)(j) explicitly includes multi-factor authentication or continuous authentication as a cybersecurity risk-management measure.Transposition deadline passed Oct. 17, 2024; as of July 2026, several member states still face Commission action.Administrative fines, regulator orders, and management-accountability exposure.NIS2 MFA guide
ISO 27001Organizations certifying an ISMS under ISO/IEC 27001:2022.Annex A access-control and secure-authentication controls make MFA an expected risk treatment for sensitive and privileged access.Assessed during certification and surveillance audits.Certification nonconformity, audit observations, and corrective-action pressure.ISO 27001 MFA guide
SOC 2Service organizations seeking SOC 2 attestation.CC6 logical-access criteria do not name MFA, but auditors commonly expect MFA evidence for privileged, remote, and sensitive application access.Tested across the audit period, especially for Type II reports.SOC 2 exceptions, remediation commitments, qualified-report risk, and lost enterprise deals.SOC 2 MFA guide
Essential EightAustralian government entities and organizations aligning to the ACSC Essential Eight maturity model.MFA is one of the ACSC Essential Eight mitigation strategies, with requirements that increase across maturity levels.Reviewed against the current maturity model during assessment.Assessment failure, maturity-level gaps, and public-sector or supplier eligibility risk.Essential Eight MFA guide
TISAXAutomotive suppliers and service providers that need a TISAX label for OEM or tier-1 work.VDA ISA access-control and authentication expectations, mapped from ISO 27001/27002, drive strong authentication for high-protection and privileged access.Assessed through the ENX TISAX process.Assessment findings, delayed TISAX label, and lost automotive supply-chain opportunities.TISAX MFA guide
GLBA / FSA (higher ed)Title IV higher-education institutions.Safeguards Rule MFA expectations for student financial data and institutional systems that handle covered information.In force.FSA findings and student-financial-aid program eligibility risk.Guide coming

This page summarizes compliance requirements for planning purposes. Confirm applicability and evidence expectations with your legal, compliance, auditor, assessor, insurer, or regulator-facing team.

Honest nuance

Frameworks That Do Not Mandate MFA, But Punish Its Absence

These two never name MFA, which is exactly why the honest answer matters. The legal question becomes whether password-only access was appropriate for the data and risk after something goes wrong.

GDPR

Article 32 does not name MFA, but regulators evaluate whether security measures were appropriate to the risk after a breach. ICO actions against Advanced and 23andMe show how missing or incomplete MFA can become regulator-grade evidence of a coverage gap.

GDPR MFA guide

CCPA

CCPA/CPRA does not name MFA, but California's private right of action turns reasonable-security gaps into statutory-damages exposure after certain breaches. California guidance also points organizations toward CIS Controls and MFA for sensitive consumer accounts.

CCPA MFA guide

Access-layer pattern

The Pattern Across Every Framework

Compliance language varies, but the operational problem repeats: teams must prove MFA coverage for the real application paths that handle sensitive data. That is why enforcement at the access layer matters. It can protect legacy, custom, and packaged web applications in days, with Datawiza built-in MFA or an existing identity provider.

Coverage is the test

The finding lands on the application the IdP never reached, not the SaaS estate that already has MFA.

Evidence beats policy

Auditors and insurers ask for configs, challenge demos, policy assignments, and per-application logs.

Deadlines move faster than code

Compliance dates and renewal windows are shorter than most app rewrite or login modernization projects.

FAQ

MFA Compliance Questions

Which compliance frameworks require MFA?

Common MFA compliance drivers include PCI DSS 4.0.1, Cyber Essentials, CJIS, CMMC/NIST 800-171, NYDFS Part 500, NIS2, Essential Eight, TSA Security Directives, HIPAA, SOX ITGC audits, SOC 2, ISO 27001, TISAX, the FTC Safeguards Rule, DORA, cyber-insurance renewals, and GLBA/FSA requirements. Some mandate MFA explicitly, while others create MFA pressure through access-control, audit, or attestation requirements.

Does SOX, HIPAA, or GDPR explicitly require MFA?

Some frameworks mandate MFA by name, including NIS2, PCI DSS, Cyber Essentials, CJIS, CMMC/NIST 800-171, NYDFS, TSA Security Directives, and the FTC Safeguards Rule. SOX, HIPAA, SOC 2, ISO 27001, and TISAX are more nuanced: they drive MFA through access-control, audit, assessment, or risk-treatment expectations. GDPR and CCPA do not mandate MFA by name, but enforcement and litigation risk can still punish weak authentication after a breach. GDPR MFA guide.

What evidence do auditors and insurers ask for?

They usually ask for the application inventory, MFA policy, user and group assignments, screenshots or demos of the MFA challenge, access-flow diagrams, bypass-prevention controls, exception records, and logs showing successful, failed, allowed, and denied access decisions.

How do we add MFA to a legacy application before a deadline?

Put an access proxy in front of the application, prevent direct bypass, choose built-in MFA or your existing IdP, pilot with one user group or path, then collect policy configuration and per-application logs as evidence. This can close MFA gaps without changing application code.

Last verified

Maintenance Schedule

On each trigger, update the detailed guide first with a real content change, then sync this hub row. Do not make date-only updates.

Row verification

Cyber insurance

July 19, 2026

PCI DSS 4.0.1

July 19, 2026

Cyber Essentials (UK)

July 19, 2026

CJIS

July 19, 2026

CMMC / NIST 800-171

July 19, 2026

NYDFS Part 500

July 19, 2026

HIPAA

July 19, 2026

SOX (ITGC)

July 19, 2026

FTC Safeguards Rule

July 19, 2026

DORA (EU)

July 19, 2026

TSA Security Directives

July 21, 2026

NIS2

July 20, 2026

ISO 27001

July 20, 2026

SOC 2

July 20, 2026

Essential Eight

July 20, 2026

TISAX

July 20, 2026

GLBA / FSA (higher ed)

Guide coming

FrameworkReview triggerCadence
Cyber EssentialsAnnual question-set update in spring.Every April
CJISCJIS 6.x releases and audit-baseline changes.Quarterly
PCI DSSPCI DSS 4.x revisions and assessment guidance updates.Semiannual
HIPAAHIPAA Security Rule NPRM finalization.Monthly until final, then annual
NYDFS / FTC / DORARegulatory amendments or official guidance updates.Annual
CMMC / NIST 800-171NIST revisions and CMMC assessment-ecosystem updates.Semiannual
TSA Security DirectivesEnhancing Surface Cyber Risk Management final-rule issuance and each pipeline or rail security-directive reissuance.Monthly until final rule, then annual
NIS2Member-state transposition milestones and Commission enforcement updates.Semiannual
ISO 27001 / TISAXISO standard revisions, VDA ISA catalogue updates, and assessor guidance changes.Annual
Essential EightACSC maturity-model updates.Semiannual
GDPR / CCPASecurity-related enforcement decisions and California regulatory updates.Annual
SOX / cyber insuranceAudit season and cyber-insurance renewal season.Annual in Q3

Next step

Bring the Framework and the Application

We will map the requirement to the application path, decide whether built-in MFA or your IdP fits best, and show the evidence you can collect for the review.

Datawiza is Easy to Get Started

Sign up to secure your AI agents and critical enterprise apps

Try Datawiza