Capital Cyber News
Reporting for United States defense contractors and small business KEV catalog 2026.08.14

Practical Defense

Least Privilege When Everyone Does Everything

Implementing least privilege is a challenge in any small or mid-sized business, especially when one person handles multiple roles. The principle of least privilege, required by AC.L2-3.1.5 in NIST SP 800-171 Rev 2, means granting users only the access necessary to do their jobs. But what does this requirement look like when you or a team member is responsible for IT, finance, and shipping, sometimes all in the same day? If you are preparing for a self-assessment or government-led review under DFARS 252.204-7012, you need to show that you meet this requirement, regardless of your company’s size or how many hats you wear.

What is least privilege and why does it matter for small teams?

Least privilege (AC.L2-3.1.5) requires you to limit access to systems and data to only what is strictly needed. In a larger organization, this is often done by creating narrowly defined roles and permissions. In smaller companies, however, roles overlap. One person might have to access sensitive contract information, manage payroll, and troubleshoot IT issues.

Even in these situations, the requirement stands: you must restrict access so that users do not have more permissions than necessary for their assigned tasks. According to NIST SP 800-171 Rev 2, meeting least privilege is not about job titles, but about what each user can do in your systems. Every user should have a unique account, and permissions should be set as narrowly as possible, even if that means adjusting them frequently as responsibilities shift.

How can you apply least privilege when everyone shares responsibilities?

You may be tempted to create one “admin” account and let everyone use it, or to set up shared logins for convenience. However, this approach fails more than the least privilege requirement but also the audit and accountability requirements. Specifically, AU.L2-3.3.2 requires that your system attribute actions to individual users. If multiple people use a single account, you cannot provide evidence of who did what, and you will fail both controls in an assessment.

Instead, each person must have a unique login, and you should assign permissions based on their actual responsibilities. If you are both the IT lead and the finance manager, your account might need broader access than others, but you still need to document and justify why. When responsibilities change, update permissions and keep a record of those changes. This is a best practice, and it is also a direct requirement under NIST SP 800-171 Rev 2.

What evidence do you need to show compliance with least privilege?

To demonstrate compliance, you need three things: policy, procedure, and evidence. First, your policy should state that access is granted based on least privilege. Next, your written procedure should describe how you review and assign permissions. Finally, you must have system-generated evidence, such as user access logs, permission change records, and screenshots showing unique accounts and role assignments.

Documentation alone is not enough. Assessors and government reviewers will expect to see real, timestamped artifacts showing that your system enforces these limits and that you review permissions regularly. The CMMC Scoping and Assessment Guides require you to provide artifacts like your Authorized User List and evidence that each user account is assigned only the permissions needed to do its job.

What if your business is too small for strict separation of duties?

NIST SP 800-171 Rev 2 recognizes that strict separation of duties is not always possible in small environments. However, you are still required to enforce least privilege to the greatest extent possible. If one person must perform multiple roles, document the business need and review these permissions more frequently.

Your System Security Plan (SSP) should explain how your company handles overlapping responsibilities, what compensating controls you use, and how you monitor for inappropriate access. If you cannot strictly separate duties, focus on ensuring that every action is attributable to a unique user and that permissions are not broader than necessary.

How does least privilege relate to audit and accountability?

Least privilege and auditability go hand in hand. AU.L2-3.3.2 requires you to record and attribute each action to a specific individual. Shared logins or generic accounts make this impossible. If your system cannot show who performed a specific action, you cannot meet the audit and accountability requirements, regardless of your size.

This means you must eliminate shared accounts for any system in scope for CUI. Each person needs a unique login, and you need to be able to produce logs that show who did what, when. This may require configuring your systems to generate and retain these logs, and reviewing them regularly.

What is the risk of not meeting least privilege requirements?

With the current suspension of third-party CMMC certification, your annual self-assessment and senior official affirmation are now the primary assurance to the government that you are compliant. This does not reduce your responsibility, if anything, it increases your exposure under the False Claims Act if you overstate your compliance.

Recent False Claims Act cases demonstrate the consequences: companies have been held liable for failing to implement required controls, for using shared or generic accounts, and for not keeping required documentation. These cases have included more than the contractors but also their owners and affiliates. Whistleblowers can and do file actions on the government’s behalf. If you cannot show that your system enforces least privilege and unique accountability, your company and its leadership could be at risk.

For more on the regulatory background, see NIST SP 800-171 Rev 2.

Common questions

Do I really need unique logins if my team is only two people? Yes. Both least privilege and audit requirements apply regardless of team size. Each person must have their own account so actions can be attributed.

Can I document exceptions if my business needs require broader access? You can document business needs and explain compensating controls in your SSP, but you must still minimize permissions as much as possible and regularly review them.

What happens if I fail to meet least privilege requirements during a self-assessment? You must be honest in your self-assessment. If you cannot meet a requirement, document it and develop a plan of action and milestones (POA&M). Falsely affirming compliance increases your risk under the False Claims Act.

Assess Your Gaps Against CMMC and NIST 800-171

If you are unsure whether your current system meets the least privilege requirement, or if you need help preparing for your next self-assessment, consider the Cyber Grants Alliance CMMC Gap Assessment Grant. This in kind grant is delivered as services, not cash, and covers all 110 NIST 800-171 controls for qualifying defense contractors. Learn more at https://cybergrantsalliance.org/cmmc-gap-assessment-grant/. Taking action now can help you avoid compliance pitfalls and protect your business.

More on Defense

Defense · 5 min MFA: What Actually Satisfies IA.L2-3.5.3

Understand what counts as multifactor authentication CMMC compliance, why SMS is weak, and how to meet requirements for privileged and non-privileged accounts.