CMMC 3.5.3 (MFA): Evidence Examples & What Assessors Actually Check
Control: NIST SP 800-171 Rev. 2 §3.5.3 · CMMC Practice: IA.L2-3.5.3 · Updated June 2026
Plain-English answer
3.5.3 requires multifactor authentication (MFA) for local and network access to privileged accounts, and for network access to non-privileged accounts. "Multifactor" means two of three factor types — something you know, have, or are. A password plus a second password is not MFA.
Who this applies to
Any organization seeking CMMC Level 2 for an environment that stores, processes, or transmits CUI — covering the in-scope assets in your CUI boundary and the admin/security planes that protect them.
Why it matters
Stolen or reused credentials are the most common way in. That's why 3.5.3 is heavily weighted: under the DoD Assessment Methodology it's a 5-point requirement — among the largest single hits to your SPRS score if unmet.
Control lineage
- CMMC Practice: IA.L2-3.5.3
- NIST 800-171 Rev. 2: §3.5.3 — MFA for local and network access to privileged accounts and for network access to non-privileged accounts.
- NIST 800-171A objectives: [a] privileged accounts identified; [b] MFA for local & network access to privileged accounts; [c] non-privileged accounts identified; [d] MFA for network access to non-privileged accounts.
What the assessor will EXAMINE
- Identity provider MFA policy/config (Conditional Access / context-aware access) and which groups it applies to.
- Current list of privileged accounts (admins, break-glass, service accounts) and how they're designated.
- MFA enrollment/coverage reports across privileged and non-privileged users.
- SSP narrative for 3.5.3 and any related POA&M items.
- Exception list — accounts not on MFA, with justification and compensating controls.
What the assessor will INTERVIEW
- "Show how MFA is enforced for an admin logging in locally vs. over the network." — a good answer walks both paths and names the factors.
- "How do you identify which accounts are privileged?" — point to the documented designation and the driving group/role.
- "What about service/legacy accounts that can't do interactive MFA?" — explain the compensating control (vaulting, isolation, certificate auth) and where it's documented.
What the assessor will TEST
- Witness a privileged login locally and over the network — confirm a second factor both ways.
- Attempt a non-privileged network login — confirm MFA fires.
- Sample accounts from the enrollment report against the privileged-account list for gaps.
Evidence examples (produce these)
- Export of the MFA enforcement policy with scope and factor types.
- MFA registration/coverage report (per user/group), dated within your freshness window.
- Privileged-account inventory with the designation criteria.
- Exception register with justification + compensating control + review date.
- SSP section for 3.5.3 referencing the above by name.
Platform-specific
- Google Workspace: Admin 2-Step Verification enforcement, security-key/Authenticator policy, context-aware access rules, 2SV enrollment report (Admin → Reports).
- Microsoft GCC High / Entra ID: Conditional Access requiring MFA, Authentication Methods registration report, privileged-role MFA (PIM where used).
Common failure patterns
- MFA on email but not on the admin console or server/hypervisor console — local privileged access missed.
- "Privileged" never formally defined, so objective [a] fails even though MFA is on.
- Service/legacy accounts excluded with no documented compensating control.
- SMS-only second factor treated as sufficient without acknowledging the risk.
- Evidence is an undated one-time screenshot — can't confirm it's current.
SPRS impact & POA&M
SPRS: not meeting 3.5.3 is a 5-point deduction. POA&M: eligibility for individual requirements is restricted under CMMC and some controls can't be deferred — confirm 3.5.3's eligibility against current CMMC rules before assuming you can POA&M it.
Assessor-ready summary
You're good on 3.5.3 when: privileged and non-privileged accounts are formally identified; MFA is enforced for local and network privileged access and network non-privileged access; you can demonstrate it live both ways; exceptions are documented with compensating controls; and your evidence matches your SSP narrative.
Map your 3.5.3 evidence the way an assessor reads it. Get a Google Workspace or GCC High evidence map →
Related: All control evidence pages · Calculate your SPRS score
Athena prepares organizations for CMMC Level 2; certification rests with C3PAOs/DIBCAC. Verify all control facts against NIST SP 800-171 Rev. 2, NIST SP 800-171A, and current CMMC rules.