No. You are free to reference nist and use a compensating control for that. No more pw changes :) Source: QSA
I guess I was under the impression that compensating controls don't really let you question the efficacy of the point of the original requirement, but instead "we're meeting the requirement in this other way"?
That's correct :(
> 8.2.4 Change user
> passwords/passphrases at least once
> every 90 days.