IA Domain

Identification & Authentication CMMC Level 2

Identify users and authenticate access to systems — 11 requirements covering 27 total SPRS points.

11 Requirements
27 SPRS Points at Risk
100% Complete Coverage

Identification & Authentication Domain Overview

The Identification and Authentication domain requires organizations to uniquely identify all users and devices that access CUI systems, authenticate their identity before granting access, and manage credentials and authenticators securely. You cannot enforce access control without knowing who is accessing your systems. Weak authentication — shared accounts, simple passwords, no MFA — is among the most commonly exploited vulnerabilities in small contractor environments.

All 11 Identification & Authentication Requirements

Every NIST SP 800-171 Rev 2 requirement in the IA family, with SPRS point weight and POA&M eligibility.

RequirementDescriptionPointsPOA&M
IA.L2-3.5.1Identify system users, processes acting on behalf of users, and devices.5Conditional
IA.L2-3.5.2Authenticate (or verify) the identities of users, processes, or devices, as a prerequisite to allowing access to organizational systems.5Conditional
IA.L2-3.5.3Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.5No
IA.L2-3.5.4Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.1Yes
IA.L2-3.5.5Employ identifier management practices for user and device identifiers.1Yes
IA.L2-3.5.6Disable identifiers after a defined inactivity period.1Yes
IA.L2-3.5.7Enforce a minimum password complexity and change of characters when new passwords are created.1Yes
IA.L2-3.5.8Prohibit password reuse for a specified number of generations.1Yes
IA.L2-3.5.9Allow temporary password use for system logons with an immediate change to a permanent password.1Yes
IA.L2-3.5.10Store and transmit only cryptographically-protected passwords.5Conditional
IA.L2-3.5.11Obscure feedback of authentication information.1Yes

How 1TEN Covers This Domain

User & Device Identification

Every user, service account, and device in the platform is uniquely identified and tracked. The identity registry links accounts to their authorization level, satisfying 3.5.1 and 3.5.5 with complete audit trails.

Multifactor Authentication

Built-in MFA enforcement for both privileged and non-privileged accounts with replay-resistant mechanisms. The platform documents your MFA deployment to cover 3.5.2, 3.5.3, and 3.5.4 during assessment.

Password Policy Management

Configure and enforce password complexity rules, history requirements, and temporary password workflows. The platform tracks compliance with 3.5.7, 3.5.8, and 3.5.9 across all managed accounts.

Credential Protection & Lifecycle

Document cryptographic protection of stored and transmitted credentials, inactive account policies, and authentication feedback controls. Covers 3.5.6, 3.5.10, and 3.5.11 with evidence-ready documentation.

Common Tools for IA Compliance

These tools are commonly used by defense contractors to satisfy IA requirements. During your C3PAO assessment, you’ll document exactly which tools satisfy each control.

What C3PAO Assessors Verify

Assessors will verify that all accounts are unique to individuals, that multi-factor authentication is enforced for privileged access and remote access, and that password policies meet minimum complexity and rotation requirements. They’ll look for shared or generic accounts and test MFA enforcement.

Why This Domain Matters
Identity is the new perimeter. If you can't prove who accessed CUI, you can't prove you protected it.

Related Domains

Know your posture.

1TEN is the GRC platform built specifically for small defense manufacturers navigating CMMC Level 2.

Request a Demo