Push back on PCI DSS by showing you’re NIST compliant, which is generally considered higher grade and acceptable.
Sharing details, as many “sacred cows” are slain:
- User-generated passwords should be at least 8 characters in length
- Machine-generated passwords should be at least 6 characters in length
- Users should be able to create passwords up to at least 64 characters
- All ASCII/Unicode characters should be allowed, including emojis and spaces
- Stored passwords should be hashed and salted, and never truncated
- Prospective passwords should be compared against password breach databases and rejected if there’s a match
- Passwords should not expire
- Users should be prevented from using sequential (ex. “1234”) or repeated (ex. “aaaa”) characters
- Two-factor authentication (2FA) should not use SMS for codes
- Knowledge-based authentication (KBA), such as “What was the name of your first pet?”, should not be used
- Users should be allowed 10 failed password attempts before being locked out of a system or service
- Passwords should not have hints
- Complexity requirements should not be used, ex. requiring special characters, numbers, uppercase, etc.
- Context-specific words, such as the name of the service, the user’s username, etc. should not be permitted
https://pages.nist.gov/800-63-3/sp800-63b.html