Requirement 2 · Apply secure configurations to all system components

2.2 System components are configured and managed securely

SCOPEEVIDENCERISKEVIDENCETESTEVIDENCEREPORTEVIDENCEAUDIT TRAIL2.2 Audit PathPOLICY / CONTROL / EVIDENCE / REVIEW

How to meet it

Apply hardening baselines, change all vendor defaults, and remove unnecessary services/accounts.

Defined requirements

The individual PCI DSS v4.0.1 requirements under 2.2, in plain English.

2.2.1Configuration standards cover all system components, fix known vulnerabilities, align with hardening guidance, and are applied before a component goes into production.
2.2.2Vendor default accounts are handled by changing the default password if kept, or removing/disabling the account if unused.
2.2.3Primary functions needing different security levels are kept apart, isolated, or all secured to the highest level required.
2.2.4Only necessary services, protocols, daemons, and functions are enabled; anything unnecessary is removed or disabled.
2.2.5When insecure services or protocols are present, a business reason is documented and extra security features are applied to reduce risk.
2.2.6System security parameters are set to prevent misuse.
2.2.7All non-console administrative access is encrypted with strong cryptography.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to Requirement 2, or see PCI DSS templates. To run PCI controls with automation, read how AI manages controls.