This requirement is in section 8.3.9 of the PCI DSS[0], and only applies to single-factor authentication implementations, two-factor auth removes this requirement.
[0] https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard...
[0] https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard...
[0] https://www.finra.org/filing-reporting/entitlement/password-...
> If the password length is 16 to 32 characters, it will be valid for 365 days
Madness.
On my first Wireguard testbed, WG's keygen dropped one at the front of the key. It remains my most treasured digital possession.