ℹ️
Reference Content: This is a copy of content from the PCI Security Standards Council FAQ database, preserved for tracking changes over time.
View Original →
FAQ #1253 Published

Does hashing of passwords meet the intent of PCI DSS Requirement 8.2.1?

Using strong cryptography to hash the password meets the intent of the PCI DSS Requirement 8.2.1, which is to prevent unintentional disclosure of the passwords during transmission over the network or during storage.

Please refer to the PCI DSS and PA-DSS Glossary of Terms, Abbreviations, and Acronyms for additional information on hashing.

(Note: PCI DSS Requirement numbers refer to PCI DSS version 3)

Disclaimer: This FAQ has been processed for display on this website and may contain errors. Please check the original FAQ on the PCI SSC website for the authoritative version.