Credential and password rotation
The shortest fixed clock in the held texts is 2,160 hours (90 days), set by PCI DSS 8.3.9. Paste one job that feeds this consumer, for example service_password_rotation, weekly, and the register reads its period against the clocks below, names the gap in hours, and carries the question for its owner.
Matched on the job name or the consumer column by these words: password, rotation, secret rotation, key rotation, credential rotation, rotate, secret rotation.
The clock each rule sets
| Regime | Clock | Clause |
|---|---|---|
| PCI DSS | 2,160h | PCI DSS 8.3.9 Password change frequency if only factorchanged at least every 90 days |
| SP 800-53 | no clock | SP 800-53 AC-2 Account managementa defined frequency |
Questions this page answers
How often does PCI DSS v4.0 require credential and password rotation?
90 days (2,160 hours): PCI DSS 8.3.9, Password change frequency if only factor. If passwords are the only authentication factor, they are changed at least every 90 days, or access to resources is dynamically analyzed and access granted based on security posture.
How often does NIST SP 800-53 Rev 5 require credential and password rotation?
The held text of SP 800-53 AC-2 (Account management) sets no fixed period: a defined frequency. Requires accounts to be managed across their full life cycle: permitted and prohibited account types defined, account managers assigned, membership prerequisites and approvals required, accounts created, modified, disabled and removed under documented criteria, usage monitored, and access reauthorized on a defined frequency.
What does the register ask the owner of a credential and password rotation job?
Which of these credentials are the only factor on their account, and do those meet the 90 days?
The clauses in full
If passwords are the only authentication factor, they are changed at least every 90 days, or access to resources is dynamically analyzed and access granted based on security posture.
What an assessor asks to see: Password expiration policy set to 90 days where applicable; Dynamic access posture tool configuration if used; Coverage matrix of password-only systems; Sample of forced password changes. Where it usually falls short: Expiration disabled with no compensating control
Requires accounts to be managed across their full life cycle: permitted and prohibited account types defined, account managers assigned, membership prerequisites and approvals required, accounts created, modified, disabled and removed under documented criteria, usage monitored, and access reauthorized on a defined frequency.
What an assessor asks to see: Account type register showing which account types are permitted and which are prohibited; Provisioning and deprovisioning tickets carrying documented approval by the responsible party; Leaver reconciliation between the human resources record and account disablement dates; Periodic account recertification results with evidence that revocations were executed. Where it usually falls short: Shared and service accounts sit outside the joiner mover leaver process entirely
Requirement text quoted from the standards themselves, published at compliance.theartofservice.com, the same publisher as this register, read against the held text of each standard: our statement of each clause, not the instrument verbatim. Run this job through the register