Capital Cyber News
Reporting for United States defense contractors and small business KEV catalog 2026.08.14

Practical Defense

MFA: What Actually Satisfies IA.L2-3.5.3

If you handle Controlled Unclassified Information (CUI) for the Department of Defense, you are already subject to NIST SP 800-171 Rev 2 and must address all 110 controls at Level 2, including IA.L2-3.5.3: multifactor authentication. With CMMC third party certification temporarily suspended, your self-assessment and senior official affirmation are the only assurance the government has that you meet the multifactor authentication CMMC requirement. The consequences of a misstatement are significant, so getting this right matters.

What does multifactor authentication mean under CMMC?

Multifactor authentication (MFA) under CMMC, specifically control IA.L2-3.5.3, means using two or more different types of authentication factors to verify a user's identity before granting access to organizational systems. According to NIST SP 800-171 Rev 2, these factors fall into three categories: something you know (like a password), something you have (such as a hardware token), and something you are (biometrics).

You must implement MFA for both privileged and non-privileged accounts, and this applies to both local and network access. Privileged accounts, such as those with administrative rights, present a higher risk if compromised and always require MFA. Non-privileged accounts, such as standard user accounts, must also use MFA for network access. Local access by non-privileged users may not always require MFA, but you must be able to justify your approach in your policies and procedures.

Does SMS-based MFA satisfy CMMC requirements?

SMS-based MFA is widely recognized as weak and is not recommended by NIST. NIST SP 800-171 Rev 2 and the CMMC Scoping and Assessment Guides do not explicitly prohibit SMS as a second factor, but the guidance in NIST SP 800-63-3 (referenced by NIST for authentication standards) discourages its use due to the risk of interception or redirection. If you use SMS for MFA, you should expect an assessor, or the Department of Defense, in the case of a government-led assessment, to scrutinize your implementation and justification.

If your environment currently relies on SMS, you should consider moving to a more secure method, such as a hardware token or platform authenticator. These options provide a much higher level of assurance that the second factor cannot be easily intercepted or spoofed.

What is the difference between a hardware authenticator and a platform authenticator?

A hardware authenticator is a physical device that generates or stores authentication information, such as a one-time password (OTP) token or a FIDO2 security key. A platform authenticator is built into the device itself, such as a fingerprint reader or facial recognition system on a laptop or smartphone.

Both hardware and platform authenticators can satisfy the multifactor authentication CMMC requirement if properly implemented. They are much less susceptible to remote attacks than SMS or software-based tokens. When you use a hardware authenticator, the user must have the physical device in their possession. With a platform authenticator, the authentication is tied to the device, making it harder for an attacker to compromise the process remotely.

What evidence do you need to prove MFA is in place?

CMMC assessments are evidence-driven. To meet IA.L2-3.5.3, you must document your MFA policy and procedures. You also need to produce system-generated artifacts, such as authentication logs, showing that MFA is enforced for all required accounts and access types. If you claim MFA is in place for privileged and non-privileged accounts, you must be able to prove it with real, timestamped evidence.

Assessment objectives from NIST SP 800-171A require you to show that MFA is required for network access to privileged accounts, network access to non-privileged accounts, and local access to privileged accounts. Your system configuration must reflect these requirements, and your documentation must describe your approach. Documentation alone is not enough; you need proof of execution.

How do privileged and non-privileged accounts differ in MFA requirements?

Privileged accounts always require MFA for both local and network access. These accounts can make significant changes to systems and data, so they are a primary target for attackers. Non-privileged accounts must use MFA for network access, but local access requirements depend on your risk assessment and documented policies.

To be compliant, you should clearly define which accounts are privileged in your authorized user list. Your procedures should describe how MFA is enforced for each account type and access method. If you have exceptions, document them and be prepared to justify them during an assessment.

How does scoping affect MFA implementation?

CMMC scoping determines which assets and users are subject to the controls. CUI Assets and Security Protection Assets must meet all relevant requirements, including MFA. Contractor Risk Managed Assets and Specialized Assets may have different assessment approaches, but if these assets process, store, or transmit CUI, they must be protected with MFA.

Your CUI Flow Diagram, Network Boundary Diagram, Physical Site Diagram, and Authorized User List should make it clear which systems and users are in scope for MFA. If you separate CUI and non-CUI assets, ensure the separation is well documented and defensible.

What should you do if your MFA solution does not meet best practices?

If you identify gaps, such as reliance on SMS, incomplete coverage of privileged accounts, or inconsistent enforcement across systems, you need to address them as part of your System Security Plan (SSP) and Plan of Actions and Milestones (POA&M). The Department of Defense expects you to maintain an accurate SPRS score reflecting your current state. Inflating your score or claiming compliance without evidence increases your exposure under the False Claims Act.

If you are unsure whether your MFA solution is sufficient, consider a gap assessment. Many companies in the defense industrial base have not completed all required documentation or achieved a perfect SPRS score, so you are not alone.

For more on NIST authentication standards, see NIST SP 800-63-3.

Common questions

What is the current CMMC certification requirement for MFA? As of July 2026, the Department of War has suspended the requirement for third party CMMC certification. However, you must still comply with NIST SP 800-171 Rev 2, including MFA, through self-assessment and senior official affirmation.

Can I use SMS for MFA under CMMC? SMS-based MFA is not explicitly prohibited, but it is discouraged by NIST due to security weaknesses. Hardware or platform authenticators provide a higher level of assurance.

Do all users need MFA or just admins? MFA is required for all privileged accounts (admins) for both local and network access. For non-privileged users, MFA is required for network access.

Verify Your MFA Against IA.L2-3.5.3 Requirements

If you need to confirm your multifactor authentication CMMC compliance, or if you want to address other gaps in your NIST SP 800-171 Rev 2 controls, consider the in kind CMMC Gap Assessment Grant from the Cyber Grants Alliance. This grant is delivered as services by a qualified provider and covers all 110 controls for qualifying defense contractors. Learn more at cybergrantsalliance.org/cmmc-gap-assessment-grant/.

Getting MFA right is critical for your compliance and your reputation. Make sure your implementation stands up to scrutiny, and be ready to prove it with evidence if asked.

More on Defense