CMMC 3.5.3 (MFA): Evidence Examples & What Assessors Actually Check

    Control: NIST SP 800-171 Rev. 2 §3.5.3 · CMMC Practice: IA.L2-3.5.3 · Updated June 2026

    Plain-English answer

    3.5.3 requires multifactor authentication (MFA) for local and network access to privileged accounts, and for network access to non-privileged accounts. "Multifactor" means two of three factor types — something you know, have, or are. A password plus a second password is not MFA.

    Who this applies to

    Any organization seeking CMMC Level 2 for an environment that stores, processes, or transmits CUI — covering the in-scope assets in your CUI boundary and the admin/security planes that protect them.

    Why it matters

    Stolen or reused credentials are the most common way in. That's why 3.5.3 is heavily weighted: under the DoD Assessment Methodology it's a 5-point requirement — among the largest single hits to your SPRS score if unmet.

    Control lineage

    • CMMC Practice: IA.L2-3.5.3
    • NIST 800-171 Rev. 2: §3.5.3 — MFA for local and network access to privileged accounts and for network access to non-privileged accounts.
    • NIST 800-171A objectives: [a] privileged accounts identified; [b] MFA for local & network access to privileged accounts; [c] non-privileged accounts identified; [d] MFA for network access to non-privileged accounts.

    What the assessor will EXAMINE

    • Identity provider MFA policy/config (Conditional Access / context-aware access) and which groups it applies to.
    • Current list of privileged accounts (admins, break-glass, service accounts) and how they're designated.
    • MFA enrollment/coverage reports across privileged and non-privileged users.
    • SSP narrative for 3.5.3 and any related POA&M items.
    • Exception list — accounts not on MFA, with justification and compensating controls.

    What the assessor will INTERVIEW

    • "Show how MFA is enforced for an admin logging in locally vs. over the network." — a good answer walks both paths and names the factors.
    • "How do you identify which accounts are privileged?" — point to the documented designation and the driving group/role.
    • "What about service/legacy accounts that can't do interactive MFA?" — explain the compensating control (vaulting, isolation, certificate auth) and where it's documented.

    What the assessor will TEST

    • Witness a privileged login locally and over the network — confirm a second factor both ways.
    • Attempt a non-privileged network login — confirm MFA fires.
    • Sample accounts from the enrollment report against the privileged-account list for gaps.

    Evidence examples (produce these)

    • Export of the MFA enforcement policy with scope and factor types.
    • MFA registration/coverage report (per user/group), dated within your freshness window.
    • Privileged-account inventory with the designation criteria.
    • Exception register with justification + compensating control + review date.
    • SSP section for 3.5.3 referencing the above by name.

    Platform-specific

    • Google Workspace: Admin 2-Step Verification enforcement, security-key/Authenticator policy, context-aware access rules, 2SV enrollment report (Admin → Reports).
    • Microsoft GCC High / Entra ID: Conditional Access requiring MFA, Authentication Methods registration report, privileged-role MFA (PIM where used).

    Common failure patterns

    • MFA on email but not on the admin console or server/hypervisor console — local privileged access missed.
    • "Privileged" never formally defined, so objective [a] fails even though MFA is on.
    • Service/legacy accounts excluded with no documented compensating control.
    • SMS-only second factor treated as sufficient without acknowledging the risk.
    • Evidence is an undated one-time screenshot — can't confirm it's current.

    SPRS impact & POA&M

    SPRS: not meeting 3.5.3 is a 5-point deduction. POA&M: eligibility for individual requirements is restricted under CMMC and some controls can't be deferred — confirm 3.5.3's eligibility against current CMMC rules before assuming you can POA&M it.

    Assessor-ready summary

    You're good on 3.5.3 when: privileged and non-privileged accounts are formally identified; MFA is enforced for local and network privileged access and network non-privileged access; you can demonstrate it live both ways; exceptions are documented with compensating controls; and your evidence matches your SSP narrative.

    Map your 3.5.3 evidence the way an assessor reads it. Get a Google Workspace or GCC High evidence map →

    Related: All control evidence pages · Calculate your SPRS score

    Athena prepares organizations for CMMC Level 2; certification rests with C3PAOs/DIBCAC. Verify all control facts against NIST SP 800-171 Rev. 2, NIST SP 800-171A, and current CMMC rules.