Threats and Vulnerabilities
Credential Theft Is Still the Cheapest Way In
Credential theft is still the cheapest way for an attacker to gain access to your systems. For most small and mid-sized defense contractors, this is more than a hypothetical risk. The controls you are required to implement under NIST SP 800-171 Rev 2, specifically IA.L2-3.5.3, are designed to address this exact issue. As the owner or operations lead, understanding what this requirement actually means and what you need to do about it is critical to keeping your business in compliance and your data secure.
Why is credential theft so effective compared to software exploits?
Credential theft remains the simplest and least expensive path for attackers because it bypasses technical defenses and exploits human behavior. Unlike sophisticated attacks that require exploiting a software vulnerability, credential theft relies on obtaining valid usernames and passwords, often through phishing, social engineering, or reusing credentials from past breaches. Once an attacker has working credentials, they can access your systems as if they are a legitimate user, often going undetected.
The reality is that technical exploits can require specialized knowledge, tools, and time. In contrast, credential theft is low-cost and high-reward for attackers. This is why you see so much emphasis on identification and authentication controls in frameworks like NIST SP 800-171 Rev 2 and in the CMMC program guidance.
What does IA.L2-3.5.3 require you to do about credential theft?
IA.L2-3.5.3 is the control in NIST SP 800-171 Rev 2 that requires you to "use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts." In plain terms, this means you must require more than just a password for users to access your systems, especially for accounts with administrative privileges.
Breaking this down:
- Privileged accounts: These are accounts with elevated rights, such as system administrators. You must enforce multifactor authentication (MFA) for both local and network access to these accounts.
- Non-privileged accounts: These are regular user accounts. For these, you must enforce MFA at least for network access.
The control is clear: passwords alone are not enough. By requiring a second factor, such as a hardware token, authenticator app, or biometric, you make it much harder for attackers to use stolen credentials, even if they have a valid password.
Do you need multifactor authentication everywhere?
According to NIST SP 800-171 Rev 2 and the CMMC Scoping and Assessment Guides Level 2 v2.13, the requirement applies to all systems storing, processing, or transmitting Controlled Unclassified Information (CUI), as well as the systems that protect those systems (Security Protection Assets). If a system or user account can access CUI or provides security functions for those systems, you must implement MFA as specified by IA.L2-3.5.3.
If you have assets that are out of scope, you must be able to justify their separation and document it clearly in your system security plan (SSP), with supporting diagrams as required by the CMMC scoping guidance.
How is compliance with IA.L2-3.5.3 actually assessed?
Compliance is more than a matter of having a policy or stating that MFA is in place. The CMMC assessment methodology, referencing NIST SP 800-171A, requires you to provide real evidence that MFA is enforced according to the control’s requirements. This includes:
- Policies that define your intent to implement MFA.
- Procedures that describe how MFA is set up and managed.
- Evidence such as system configuration screenshots, authentication logs, or system-generated reports showing that MFA is required for the relevant accounts.
- Assessment by reviewing these artifacts and, if requested, demonstrating the configuration to a government-led assessment team.
Documentation alone is not proof. You need system-generated artifacts with real timestamps that show MFA was and is in use.
What happens if you don’t meet this requirement?
The Department of War has suspended the requirement for third party CMMC certification as of July 2026, but all the underlying NIST SP 800-171 Rev 2 controls, including IA.L2-3.5.3, are still fully in force under DFARS 252.204-7012. You are still required to perform annual self-assessments, post your score to the Supplier Performance Risk System (SPRS), and have your senior official affirm your compliance.
With no third-party assessor between your self-assessment and the government, the signature of your senior official is now the main assurance of compliance. This increases your exposure under the False Claims Act if you overstate your compliance or fail to implement required controls like MFA. Recent False Claims Act cases in the defense sector have shown that liability can extend to primes, subcontractors, affiliates, and even private equity owners when companies fail to meet their obligations under NIST SP 800-171 Rev 2. Whistleblowers can also file actions on the government’s behalf.
What practical steps should you take on Monday?
- Confirm which systems and accounts require MFA under IA.L2-3.5.3.
- Verify that MFA is actually enforced, more than documented in policy.
- Gather system-generated evidence showing that MFA is active for all required accounts.
- Update your SSP and supporting diagrams to reflect the current state of your MFA implementation.
- Review the separation of any out of scope assets and ensure the justification is clear and supportable.
- Prepare your senior official to affirm compliance with confidence, based on real evidence.
If you have not completed your System Security Plan (SSP) or your Plan of Actions and Milestones (POA&M) documentation, you are not alone. Fewer than half of Level 2 companies have finished this work, and the average SPRS score across the Defense Industrial Base is about 60 out of the required 110 (CMMC Scoping and Assessment Guides L2 v2.13).
Common questions
What is credential theft and why is it so common? Credential theft is when attackers obtain valid usernames and passwords to access systems. It is common because it is cheaper and faster than exploiting technical vulnerabilities, and it often relies on human error.
Does IA.L2-3.5.3 require MFA for every account? No, it requires MFA for all privileged accounts (local and network access) and for network access to non-privileged accounts on systems that store, process, or transmit CUI, or protect those systems.
Is self-assessment enough to prove compliance? No. While self-assessment is required, you must also have documented policies, procedures, and real system-generated evidence to back up your claims. The senior official’s affirmation is legally significant.
Where to get help
If you need expert help preparing for NIST SP 800-171 Rev 2 or CMMC Level 2, the Cyber Grants Alliance offers an in kind CMMC Gap Assessment Grant delivered as services. This covers all 110 controls for qualifying defense contractors and can help you identify and remediate gaps before your next self-assessment. Learn more at cybergrantsalliance.org/cmmc-gap-assessment-grant/.
For more on NIST SP 800-171 requirements, visit the official NIST Computer Security Resource Center.
By focusing on strong authentication and real evidence, you can make credential theft a much harder and more expensive proposition for attackers, and keep your business in compliance.