Identity & Access Management capability of SimpliKeys (SK), mapped to the IAM-relevant controls
Reference version: PCI DSS v4.0.1 · Prepared mid-2026 · Capability mapping, not a compliance attestation
Coverage of the 48 IAM-relevant requirements
PCI DSS v4.0.1 — the current and only active version. v4.0 was retired 31 Dec 2024; the future-dated v4.0/v4.0.1 requirements became mandatory 31 Mar 2025. Verify against the PCI SSC document library if your assessment uses a different scope (e.g., a specific SAQ).
The IAM-centric requirements: Requirement 7 (restrict access by business need-to-know) and Requirement 8 (identify & authenticate), plus a short ‘IAM-adjacent’ section covering default-account and access-logging controls an IAM/PAM platform directly touches. This is NOT a full PCI DSS mapping — Requirements 1–6, 9, 11, most of 10, and 12 are out of scope here.
SimpliKeys is a single unified platform: the capabilities described below are facets of one system applied to each control, not separate products. It protects every identity with the same vaulting, brokering and session recording, and applies strong authentication from a configurable spectrum of factors that can be targeted per system, chained, and stepped up within a session.
Every rating below holds only to the extent of two things: (1) breadth — the scope of the environment SimpliKeys is protecting; a control is supported only where SimpliKeys sits in the access path, not for systems outside its reach; and (2) depth — how SimpliKeys is configured. The analysis assumes SimpliKeys is deployed and configured as the central authentication manager for the in-scope environment.
Entries describe summarised SimpliKeys capability under common circumstances and when appropriately configured. They do not represent verified or certified behaviour.
No IAM platform ‘provides’ or ‘achieves’ PCI DSS compliance — a tool can at most support a control. Compliance is achieved by the assessed entity through implementation, configuration to the exact PCI thresholds, documented processes, and QSA/SAQ validation. Treat every ‘Supports’ as ‘capability provided when appropriately configured.’
Supports
SimpliKeys provides the capability that meets this control when appropriately configured; configuration to the applicable thresholds and implementation still apply.
Partial
SimpliKeys addresses part of this control; full compliance needs additional measures, or depends on coverage or architecture beyond SimpliKeys alone.
Assists
SimpliKeys does not perform this control (it is organisational or process), but supplies information, logs, visibility, or evidence that makes it easier to complete or to demonstrate.
Out of scope / N/A
Outside SimpliKeys’ role — purely organisational, or not applicable to SimpliKeys (e.g., applies only to third-party service providers).
Filter by coverage
Processes and mechanisms for restricting access by need-to-know are defined and understood.
What SimpliKeys does
Acts as the access-control system that authenticates requests and enforces access by policy across the environment.
Customer responsibility & notes
Customer documents the access-restriction process; SimpliKeys enforces it and provides supporting evidence.
Security policies and operational procedures for Req 7 are documented, current, in use, and known to affected parties.
What SimpliKeys does
Provides configuration and records that evidence the procedures are in use.
Customer responsibility & notes
Customer maintains the documented policies and procedures; SimpliKeys configuration evidences they are in use.
Roles and responsibilities for Req 7 activities are documented, assigned, and understood.
What SimpliKeys does
Reflects assigned roles and responsibilities in its access model.
Customer responsibility & notes
Customer assigns roles and responsibilities; SimpliKeys' role model reflects them.
Access to system components and data is appropriately defined and assigned.
What SimpliKeys does
Enforces access by policy from a single platform and console, with one role and entitlement model across the environment.
Customer responsibility & notes
Customer models roles and entitlements in SimpliKeys to match business need.
An access-control model is defined that grants access appropriate to business need.
What SimpliKeys does
Enforces a defined access model that grants access to business need.
Customer responsibility & notes
Customer defines the access-control model to express the need-to-know granularity required for the CDE.
Access is assigned based on job classification/function and on least privilege.
What SimpliKeys does
Enforces least-privilege access by job function under one policy model.
Customer responsibility & notes
Customer configures least-privilege role assignments.
Required privileges are approved by authorised personnel.
What SimpliKeys does
Routes access grants through request and approval workflows.
Customer responsibility & notes
Customer defines approvers and approval rules in SimpliKeys' request/approval workflow.
All user accounts and related access privileges are reviewed at least once every 6 months.
What SimpliKeys does
Runs periodic access reviews over identities and entitlements from a single console.
Customer responsibility & notes
Customer schedules and runs SimpliKeys access-review/certification campaigns at least every 6 months.
All application and system accounts and their privileges are assigned and managed at least privilege.
What SimpliKeys does
Enforces the same policy-based access control over application and system accounts at least privilege, with the same vaulting and brokering it applies to every identity.
Customer responsibility & notes
Customer brings application/system accounts under SimpliKeys management at least privilege.
Application/system account access is reviewed at a frequency set by a targeted risk analysis.
What SimpliKeys does
Runs the same access reviews over application and system accounts.
Customer responsibility & notes
Customer sets the machine-account review frequency from its targeted risk analysis and runs the campaigns.
Access to query repositories of stored cardholder data is restricted to least privilege via authorised methods.
What SimpliKeys does
Brokers and records access to cardholder-data repositories through the platform.
Customer responsibility & notes
Customer routes data-query access for cardholder-data repositories through SimpliKeys brokering.
Access control is enforced through an access-control system.
What SimpliKeys does
Is itself the access-control system, authenticating identities and enforcing access by policy.
Customer responsibility & notes
Customer places SimpliKeys in the enforcement path for in-scope components.
The access-control system(s) covers all system components.
What SimpliKeys does
Enforces access across cloud, on-premises and legacy systems, agentlessly, from one platform.
Customer responsibility & notes
Customer confirms coverage extends to any legacy or edge systems in scope.
The access-control system enforces permissions per job classification/function.
What SimpliKeys does
Enforces permissions by job function through its policy engine.
Customer responsibility & notes
Customer authors the per-function permission policies.
The access-control system is set to deny-all by default.
What SimpliKeys does
Enforces a default-deny posture by policy.
Customer responsibility & notes
Customer sets the default-deny posture.
Policies, procedures, roles and responsibilities for Req 8 are documented, current, and assigned.
What SimpliKeys does
Provides configuration and records that evidence the procedures are in use.
Customer responsibility & notes
Customer maintains the Req 8 policies and roles; SimpliKeys configuration evidences them.
User identification and accounts are managed across the identity lifecycle.
What SimpliKeys does
Governs the identity lifecycle for every identity from a single platform.
Customer responsibility & notes
Customer manages the identity lifecycle in SimpliKeys.
Every user is assigned a unique ID before access is granted.
What SimpliKeys does
Issues a unique identity to every user and brings shared or built-in accounts under management.
Customer responsibility & notes
Customer issues unique IDs and eliminates or vaults shared/built-in accounts (see 8.2.2).
Group, shared, generic or other shared authentication is only used when necessary and is managed.
What SimpliKeys does
Vaults and brokers credentials for every identity, giving individual accountability and recorded sessions for shared or high-privilege use.
Customer responsibility & notes
Customer vaults shared/privileged credentials in SimpliKeys for individual accountability.
(Service providers) use unique authentication per customer premises.
What SimpliKeys does
n/a (service-provider requirement)
Customer responsibility & notes
Applies to third-party service providers; not SimpliKeys' role.
Adding, deleting and modifying IDs, factors and privileges is controlled and logged.
What SimpliKeys does
Provisions, de-provisions and modifies identities and entitlements, recording each change.
Customer responsibility & notes
Customer uses SimpliKeys provisioning/de-provisioning; change events are logged (links to Req 10).
Access for terminated users is immediately revoked.
What SimpliKeys does
De-provisions access on termination, driven by joiner/mover/leaver events from connected HR and source systems.
Customer responsibility & notes
Customer connects HR/source systems so termination triggers de-provisioning across connected systems.
Inactive user accounts are removed or disabled within 90 days.
What SimpliKeys does
Disables accounts automatically after a configurable period of inactivity.
Customer responsibility & notes
Customer sets the inactivity period; SimpliKeys auto-disables accounts accordingly.
Accounts used by third parties for remote access are managed and monitored.
What SimpliKeys does
Governs third-party and contractor access with brokered, recorded sessions.
Customer responsibility & notes
Customer manages contractor/third-party accounts and enables session monitoring/recording.
An idle user session is re-authenticated after 15 minutes of inactivity.
What SimpliKeys does
Re-authenticates idle sessions after a configurable period.
Customer responsibility & notes
Customer sets the idle-session timeout to 15 minutes.
Strong authentication for users and administrators is established and managed.
What SimpliKeys does
Applies strong authentication from a configurable spectrum of factors — targetable per application or system, chainable (several factors for one resource), and able to step up within a session, pulling an additional factor such as FIDO2 or biometric at the moment a more sensitive activity begins.
Customer responsibility & notes
Customer configures the strong-authentication methods (SSO / MFA / passwordless).
Access is authenticated with at least one factor type (knowledge / possession / inherence).
What SimpliKeys does
Authenticates each request with one or more factor types (knowledge, possession, inherence).
Customer responsibility & notes
Customer selects the factor types for in-scope access.
Authentication factors are protected with strong cryptography in transmission and storage.
What SimpliKeys does
Protects stored authentication factors with strong cryptography and encrypts them in transit.
Customer responsibility & notes
Stored factors are protected with strong cryptography and encrypted in transit; customer manages the key/certificate lifecycle.
A user's identity is verified before any authentication factor is modified.
What SimpliKeys does
Verifies identity before any authentication factor is changed.
Customer responsibility & notes
Customer enables identity verification on factor reset or change.
Invalid authentication attempts are limited: lock after <=10 attempts; lockout >=30 min or until identity confirmed.
What SimpliKeys does
Limits invalid authentication attempts and locks accounts by policy.
Customer responsibility & notes
Customer sets lockout to the PCI minimums (<=10 attempts, >=30 min).
First-time and reset credentials are set to a unique value and changed after first use.
What SimpliKeys does
Issues unique first-time and reset credentials and forces a change on first use.
Customer responsibility & notes
Customer enables forced credential change on first use.
If passwords/passphrases are used, they are >=12 characters and contain numeric and alphabetic characters.
What SimpliKeys does
Enforces password composition by policy.
Customer responsibility & notes
Customer sets the password policy to >=12 characters, alphanumeric.
Users cannot reuse any of the last 4 passwords/passphrases.
What SimpliKeys does
Enforces password history by policy.
Customer responsibility & notes
Customer sets password history to at least the last 4.
Authentication policies and procedures are documented and communicated to users.
What SimpliKeys does
Provides configuration and records that evidence the authentication policy.
Customer responsibility & notes
Customer documents and communicates the authentication policy; SimpliKeys configuration evidences it.
If passwords are the ONLY factor for user access: change >=every 90 days OR dynamically analyse account posture.
What SimpliKeys does
Where a password is the only factor, enforces expiry and/or applies adaptive, risk-based analysis of the session.
Customer responsibility & notes
Where MFA is not used, customer enables >=90-day expiry and/or adaptive risk-based analysis.
(Service providers) controls/guidance where customer passwords are the sole factor.
What SimpliKeys does
n/a (service-provider requirement)
Customer responsibility & notes
Applies to third-party service providers.
Where possession factors (tokens, smart cards, certificates) are used, each is assigned to an individual and not shared.
What SimpliKeys does
Binds possession factors to individual identities.
Customer responsibility & notes
Customer issues possession factors bound to individuals.
Multi-factor authentication is implemented to secure access into the CDE.
What SimpliKeys does
Requires strong authentication into the CDE under one policy — targetable per system, chainable, and able to step up mid-session to an additional factor such as FIDO2 or biometric.
Customer responsibility & notes
Customer enforces MFA into the CDE (see 8.4.1-8.4.3).
MFA is required for all non-console administrative access.
What SimpliKeys does
Applies that same authentication policy to all non-console administrative access.
Customer responsibility & notes
Customer enforces MFA for all non-console administrative access.
MFA is required for ALL access into the CDE, for all users and from all locations. (Mandatory since 31 Mar 2025.)
What SimpliKeys does
Applies that same authentication policy at every CDE entry point, for all users and locations, including phishing-resistant factors such as FIDO2/passkeys.
Customer responsibility & notes
Customer enforces MFA at every CDE entry point, for all users and locations.
MFA is required for all remote network access from outside the entity's network.
What SimpliKeys does
Applies that same authentication policy to remote network access (VPN/ZTNA).
Customer responsibility & notes
Customer integrates SimpliKeys MFA with the remote-access path (VPN/ZTNA).
MFA systems resist replay, cannot be bypassed (except documented exceptions), use >=2 distinct factor types, and require all factors to succeed.
What SimpliKeys does
Authenticates with replay-resistant factors and can require two distinct factor types, all of which must succeed.
Customer responsibility & notes
SimpliKeys' MFA resists replay and requires two distinct factors; customer avoids any documented bypass exceptions.
Interactive login for application/system accounts is prevented or tightly managed.
What SimpliKeys does
Restricts and brokers interactive use of application and system accounts.
Customer responsibility & notes
Customer restricts or brokers interactive use of application/system accounts.
Passwords/passphrases for application/system accounts are not hard-coded in scripts, config or source.
What SimpliKeys does
Supplies application and system-account credentials from the vault, so they need not be embedded in code or configuration.
Customer responsibility & notes
Customer integrates applications to fetch credentials from SimpliKeys rather than hard-coding them.
Passwords/passphrases for application/system accounts are protected and changed periodically / on suspicion of compromise.
What SimpliKeys does
Vaults application and system-account credentials and rotates them automatically.
Customer responsibility & notes
Customer sets rotation cadence and complexity for application/system-account credentials.
Vendor default accounts are removed/disabled, or default passwords changed if the account is used.
What SimpliKeys does
Identifies default and local accounts in use; where local login is disabled, blocks the credential and flags it for cleanup, and alerts on any use.
Customer responsibility & notes
SimpliKeys identifies default/local accounts in use; where local login is disabled it blocks the credential and flags it for cleanup, and alerts on any use. Customer acts on cleanup alerts.
Audit logs capture: individual user access to CHD; admin actions; access to audit logs; invalid access attempts; changes to credentials / privilege elevation; start/stop/pause of logging; creation/deletion of system-level objects.
What SimpliKeys does
Records identity and access activity — sessions with recording and playback, plus device, location and keystroke detail — and forwards it to SIEM (e.g., Splunk, QRadar).
Customer responsibility & notes
SimpliKeys captures access/identity events; log retention, protection and review across the wider environment remain the customer's.
Each audit log entry records user ID, event type, date & time, success/failure, origination, and the affected data/component/resource.
What SimpliKeys does
Records identity and access events with the identifying detail of each event and forwards them to SIEM.
Customer responsibility & notes
Customer confirms SimpliKeys log records include every required field before relying on them for Req 10.
Mapping reflects PCI DSS v4.0.1 as understood in mid-2026, reviewed control-by-control with SimpliKeys. 'Supports' = capability provided when appropriately configured; the customer configures, documents and operates its deployment. Confirm against your environment and your QSA before relying on it for compliance.
30 minutes against a real environment — we’ll walk your controls line by line.
Book demo