Identify users and authenticate access to systems — 11 requirements covering 27 total SPRS points.
The Identification and Authentication domain requires organizations to uniquely identify all users and devices that access CUI systems, authenticate their identity before granting access, and manage credentials and authenticators securely. You cannot enforce access control without knowing who is accessing your systems. Weak authentication — shared accounts, simple passwords, no MFA — is among the most commonly exploited vulnerabilities in small contractor environments.
Every NIST SP 800-171 Rev 2 requirement in the IA family, with SPRS point weight and POA&M eligibility.
| Requirement | Description | Points | POA&M |
|---|---|---|---|
| IA.L2-3.5.1 | Identify system users, processes acting on behalf of users, and devices. | 5 | Conditional |
| IA.L2-3.5.2 | Authenticate (or verify) the identities of users, processes, or devices, as a prerequisite to allowing access to organizational systems. | 5 | Conditional |
| IA.L2-3.5.3 | Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts. | 5 | No |
| IA.L2-3.5.4 | Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts. | 1 | Yes |
| IA.L2-3.5.5 | Employ identifier management practices for user and device identifiers. | 1 | Yes |
| IA.L2-3.5.6 | Disable identifiers after a defined inactivity period. | 1 | Yes |
| IA.L2-3.5.7 | Enforce a minimum password complexity and change of characters when new passwords are created. | 1 | Yes |
| IA.L2-3.5.8 | Prohibit password reuse for a specified number of generations. | 1 | Yes |
| IA.L2-3.5.9 | Allow temporary password use for system logons with an immediate change to a permanent password. | 1 | Yes |
| IA.L2-3.5.10 | Store and transmit only cryptographically-protected passwords. | 5 | Conditional |
| IA.L2-3.5.11 | Obscure feedback of authentication information. | 1 | Yes |
Every user, service account, and device in the platform is uniquely identified and tracked. The identity registry links accounts to their authorization level, satisfying 3.5.1 and 3.5.5 with complete audit trails.
Built-in MFA enforcement for both privileged and non-privileged accounts with replay-resistant mechanisms. The platform documents your MFA deployment to cover 3.5.2, 3.5.3, and 3.5.4 during assessment.
Configure and enforce password complexity rules, history requirements, and temporary password workflows. The platform tracks compliance with 3.5.7, 3.5.8, and 3.5.9 across all managed accounts.
Document cryptographic protection of stored and transmitted credentials, inactive account policies, and authentication feedback controls. Covers 3.5.6, 3.5.10, and 3.5.11 with evidence-ready documentation.
These tools are commonly used by defense contractors to satisfy IA requirements. During your C3PAO assessment, you’ll document exactly which tools satisfy each control.
Assessors will verify that all accounts are unique to individuals, that multi-factor authentication is enforced for privileged access and remote access, and that password policies meet minimum complexity and rotation requirements. They’ll look for shared or generic accounts and test MFA enforcement.
Identity is the new perimeter. If you can't prove who accessed CUI, you can't prove you protected it.
1TEN is the GRC platform built specifically for small defense manufacturers navigating CMMC Level 2.
Request a Demo