Update of PCI Password Requirements on the Fastly Application

Informational
15 September 2025, 22:00 UTC

Update of PCI Password Requirements on the Fastly Application

Status: closed
Date: 15 September 2025, 18:00 UTC
End: 15 September 2025, 22:00 UTC
Duration: 4 hours
Affected Components:
Fastly Customer Services Fastly Application API & Configuration Management Notification Center General Updates API Services Configuration Management Services
Affected Groups:
All Public Users
Update

15 September 2025, 18:00 UTC

15 September 2025, 18:00 UTC

Starting on the 15th of September 2025, Fastly will strengthen how password expiration is enforced for organizations with PCI password requirements enabled. Users with expired passwords will be prompted to set a new password at their next login.

What’s Changing?

This change in our system's behavior ensures that all customers who have enabled PCI (Payment Card Industry) password requirements will experience consistent and robust enforcement of password expiration policies. This update is crucial for maintaining the highest security standards and compliance with industry regulations.

By aligning user login behavior with established security best practices and compliance standards, we are taking a proactive step to safeguard sensitive data and enhance overall system integrity. This consistency in password expiration helps to mitigate risks associated with stagnant or compromised credentials, thereby protecting both our customers and their valuable information

What’s next? What do I have to do?

Users with expired passwords will need to perform a password reset when logging in. 

Contact Information

Customers with any questions or concerns may engage with our Support team by emailing support@fastly.com .

Resolved

15 September 2025, 22:00 UTC

15 September 2025, 22:00 UTC

This event has been resolved.

To offer feedback on our status page, click " Give Feedback "

Status Post, Created Date/Time: 0001-01-01 00:00:00 UTC



Note:  Our Customer Escalation Management team will update the start date and time of the initial "investigating" status post upon the resolution of this incident. This update is meant to provide our customers and their end users with a potential impact window. The date and time mentioned in the message above indicates when the status post was requested by our Acute Incident Response team.