Coverage is the test
The finding lands on the application the IdP never reached, not the SaaS estate that already has MFA.
MFA compliance hub
MFA has moved from best practice to mandate, but every framework mandates it differently: explicit rules with auto-fail consequences, deadline-driven requirements, auditor expectations, or renewal attestations that can affect coverage.
The common thread is that the requirement follows the data and the application, not only the network. Findings concentrate on legacy web applications that cannot do MFA natively, and that gap closes at the access layer without code changes.

Master table
This table summarizes the live Datawiza guides linked below. When a framework changes, update the detailed guide first, then sync this row.
| Framework | Who's in scope | What it requires | Status / key date | Consequence of a gap | Full guide |
|---|---|---|---|---|---|
| Cyber insurance | Any policyholder completing a cyber-insurance renewal. | MFA attested for privileged accounts, remote access, and business-critical applications. | Attested at every renewal. | Denied claims or rescinded coverage after a misstatement. | Cyber insurance MFA guide |
| PCI DSS 4.0.1 | Merchants and service providers that store, process, or transmit cardholder data. | Requirement 8.4.2 requires MFA for all access into the cardholder data environment; related requirements cover admin and remote access. | Mandatory since March 31, 2025. | Failed assessment, remediation pressure, and acquirer or contract penalties. | PCI DSS MFA guide |
| Cyber Essentials (UK) | UK Cyber Essentials certificate holders and suppliers. | MFA for cloud services, administrator accounts, user accounts, and internet-facing services where the question set applies. | Danzell v3.3 question set applies from April 27, 2026. | Auto-fail, no certification, and supply-chain eligibility risk. | Cyber Essentials MFA guide |
| CJIS | Agencies, vendors, contractors, and non-criminal-justice entities that access CJI. | Advanced authentication, commonly MFA, for access paths that touch Criminal Justice Information. | Sanctionable since Oct. 1, 2024; v5.9.5 remains a current audit baseline while CJIS 6.x transition work continues. | Sanctions, audit findings, and possible loss of CJIS/NCIC/III access. | CJIS MFA guide |
| CMMC / NIST 800-171 | Defense supply-chain organizations handling CUI. | IA.L2-3.5.3 requires MFA for local and network access to privileged accounts and for network access to non-privileged accounts. | CMMC Level 2 assessments are active. | Assessment failure and defense-contract eligibility risk. | CMMC MFA guide |
| NYDFS Part 500 | New York financial-services covered entities. | 23 NYCRR 500.12 requires MFA for individuals accessing covered information systems, subject to limited exemptions and CISO-approved compensating controls. | Expanded MFA requirement effective Nov. 1, 2025. | Examination findings, enforcement actions, and monetary penalties. | NYDFS MFA guideNYDFS MFA solution |
| HIPAA | Covered entities and business associates protecting ePHI. | Current Security Rule technical safeguards require access controls; the proposed Security Rule update would add explicit MFA requirements. | NPRM still proposed; current Security Rule remains in effect. | Corrective action plans, enforcement penalties, and breach-response findings. | HIPAA MFA guideHIPAA MFA solution |
| SOX (ITGC) | US public companies and SOX-scoped financial systems. | SOX does not name MFA directly, but auditors test logical access, privileged access, and financial-system ITGC controls. | Evaluated every audit cycle. | Control deficiency, significant deficiency, or material weakness depending on severity and remediation. | SOX MFA guide |
| FTC Safeguards Rule | Non-bank financial institutions under FTC jurisdiction, including many dealers and lenders. | MFA for anyone accessing customer information on covered systems, unless the Qualified Individual approves an equivalent secure-access control in writing. | In force. | FTC enforcement and breach-notification exposure. | FTC MFA guide |
| DORA (EU) | EU financial entities and covered ICT providers. | Strong authentication and access controls as part of ICT risk management and digital operational resilience programs. | Applies since Jan. 17, 2025. | Supervisory findings, remediation orders, and regulator sanctions. | DORA MFA guide |
| GLBA / FSA (higher ed) | Title IV higher-education institutions. | Safeguards Rule MFA expectations for student financial data and institutional systems that handle covered information. | In force. | FSA findings and student-financial-aid program eligibility risk. | Guide coming |
| SOC 2 | Service organizations seeking SOC 2 attestation. | CC6 logical-access controls; MFA is commonly expected as evidence for privileged, remote, and sensitive application access. | Per audit period. | Qualified report risk, remediation commitments, and lost enterprise deals. | Guide coming |
This page summarizes compliance requirements for planning purposes. Confirm applicability and evidence expectations with your legal, compliance, auditor, assessor, insurer, or regulator-facing team.
Access-layer pattern
Compliance language varies, but the operational problem repeats: teams must prove MFA coverage for the real application paths that handle sensitive data. That is why enforcement at the access layer matters. It can protect legacy, custom, and packaged web applications in days, with Datawiza built-in MFA or an existing identity provider.
The finding lands on the application the IdP never reached, not the SaaS estate that already has MFA.
Auditors and insurers ask for configs, challenge demos, policy assignments, and per-application logs.
Compliance dates and renewal windows are shorter than most app rewrite or login modernization projects.
FAQ
Common MFA compliance drivers include PCI DSS 4.0.1, Cyber Essentials, CJIS, CMMC/NIST 800-171, NYDFS Part 500, HIPAA, SOX ITGC audits, the FTC Safeguards Rule, DORA, cyber-insurance renewals, GLBA/FSA requirements, and SOC 2 audits. Some mandate MFA explicitly, while others create MFA pressure through access-control, audit, or attestation requirements.
Some frameworks mandate MFA by name, including PCI DSS, Cyber Essentials, CJIS, CMMC/NIST 800-171, NYDFS, and the FTC Safeguards Rule. SOX and HIPAA are more nuanced: SOX auditors test ITGC access controls, while the current HIPAA Security Rule requires access controls and the proposed update would add explicit MFA. GDPR does not mandate MFA by name.
They usually ask for the application inventory, MFA policy, user and group assignments, screenshots or demos of the MFA challenge, access-flow diagrams, bypass-prevention controls, exception records, and logs showing successful, failed, allowed, and denied access decisions.
Put an access proxy in front of the application, prevent direct bypass, choose built-in MFA or your existing IdP, pilot with one user group or path, then collect policy configuration and per-application logs as evidence. This can close MFA gaps without changing application code.
Last verified
On each trigger, update the detailed guide first with a real content change, then sync this hub row. Do not make date-only updates.
Cyber insurance
July 19, 2026
PCI DSS 4.0.1
July 19, 2026
Cyber Essentials (UK)
July 19, 2026
CJIS
July 19, 2026
CMMC / NIST 800-171
July 19, 2026
NYDFS Part 500
July 19, 2026
HIPAA
July 19, 2026
SOX (ITGC)
July 19, 2026
FTC Safeguards Rule
July 19, 2026
DORA (EU)
July 19, 2026
GLBA / FSA (higher ed)
Guide coming
SOC 2
Guide coming
| Framework | Review trigger | Cadence |
|---|---|---|
| Cyber Essentials | Annual question-set update in spring. | Every April |
| CJIS | CJIS 6.x releases and audit-baseline changes. | Quarterly |
| PCI DSS | PCI DSS 4.x revisions and assessment guidance updates. | Semiannual |
| HIPAA | HIPAA Security Rule NPRM finalization. | Monthly until final, then annual |
| NYDFS / FTC / DORA | Regulatory amendments or official guidance updates. | Annual |
| CMMC / NIST 800-171 | NIST revisions and CMMC assessment-ecosystem updates. | Semiannual |
| SOX / cyber insurance | Audit season and cyber-insurance renewal season. | Annual in Q3 |
| NIS2 / ISO 27001 | Future cluster additions after published guide coverage exists. | Semiannual |
Next step
We will map the requirement to the application path, decide whether built-in MFA or your IdP fits best, and show the evidence you can collect for the review.
Sign up to secure your AI agents and critical enterprise apps