Diff: FAQ #1425
What is the difference between "multi-factor" authentication and "two-factor" authentication?
Earlier Version
2016-06-17 21:03:00 UTC
2016-06-17 21:03:00 UTC
Later Version
2025-11-05 09:00:46 UTC
2025-11-05 09:00:46 UTC
Removed
Added
The term “two-factor” was replaced with the term “multi-factor” in several requirements in PCI DSS v3.2 (Requirements 8.3, 8.3.1, 8.3.2, and 8.5.1). The intent of this change was to use more consistent terminology that accurately represents the meaning of the term. This is simply a change in naming convention and does not alter its definition, which is that at least two authentication factors are used in the authentication process.