Subcontractor CMMC Tracker

Identification and Authentication (IA): the 11 CMMC Level 2 requirements a subcontractor self-assesses

The Identification and Authentication family of NIST SP 800-171 Rev 2, as CMMC Level 2 numbers it: each requirement with the value it carries in the score, our statement of the clause, and the evidence an assessor asks for.

Where frameworks a subcontractor holds may supply evidence here

The requirements

11
CMMC L2 IA.L2-3.5.1Identification 5 points in the score

Identify system users, the processes acting on their behalf, and devices, so each is distinguishable before any access decision is made.

What an assessor asks to see: Identifier assignment process and records; Inventory of user, process and device identifiers; Evidence identifiers are unique and not shared
Where subcontractors usually fall short: Devices and process accounts unidentified while users are covered; Shared identifiers in use; Identifier issuance undocumented
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 IA.L2-3.5.10Cryptographically-Protected Passwords 5 points in the score

Store and transmit passwords only in cryptographically protected form.

What an assessor asks to see: Evidence of password hashing or equivalent protection at rest; Configuration showing authentication traffic is encrypted in transit; Review confirming no plaintext credential storage
Where subcontractors usually fall short: Credentials stored in scripts or configuration files in plaintext; Legacy protocols transmit credentials unprotected; Reversible encryption used instead of one way protection
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 IA.L2-3.5.11Obscure Feedback 1 point in the score

Obscure authentication feedback during entry so credentials cannot be read from the screen.

What an assessor asks to see: Configuration or screenshots showing masked credential entry; Coverage across systems, applications and mobile interfaces; Evidence error messages do not disclose credential details
Where subcontractors usually fall short: Masking present in some applications only; Error feedback reveals whether the username or password was wrong; Show password features enabled by default
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 IA.L2-3.5.2Authentication 5 points in the score

Authenticate or verify the identity of users, processes and devices as a precondition of granting access to organizational systems.

What an assessor asks to see: Authentication mechanism configuration per system; Evidence authentication precedes access in all paths; Device and service authentication configuration
Where subcontractors usually fall short: Anonymous or unauthenticated access paths remain; Device authentication absent; Legacy applications bypass central authentication
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 IA.L2-3.5.3Multifactor Authentication 5 points in the score

Require more than one authentication factor for privileged account access both locally and across the network, and for non privileged account access across the network.

What an assessor asks to see: Multifactor configuration showing coverage of the required access cases; Enrolment records for privileged account holders; Evidence of enforcement for network access by non privileged users
Where subcontractors usually fall short: Multifactor applied to remote access only, missing local privileged access; Exemptions granted for service or legacy accounts without compensating control; Second factor is another knowledge factor
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 IA.L2-3.5.4Replay-Resistant Authentication 1 point in the score

Use authentication mechanisms that resist replay for network access to both privileged and non privileged accounts.

What an assessor asks to see: Authentication protocol configuration demonstrating replay resistance; Evidence deprecated protocols vulnerable to replay are disabled; Coverage across network accessible services
Where subcontractors usually fall short: Legacy authentication protocols retained for compatibility; Replay resistance assumed rather than verified; Application level authentication outside the assessed scope
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 IA.L2-3.5.5Identifier Reuse 1 point in the score

Prevent an identifier from being reissued to a different entity until a defined period has elapsed.

What an assessor asks to see: Defined identifier reuse prohibition period; Procedure or system setting preventing early reuse; Evidence from identifier issuance history
Where subcontractors usually fall short: Reuse period undefined; Email addresses or usernames recycled for new starters; Prohibition stated but not enforced by the directory
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 IA.L2-3.5.6Identifier Handling 1 point in the score

Disable identifiers once they have been inactive for a defined period.

What an assessor asks to see: Defined inactivity period for identifier disablement; Automated or procedural disablement evidence; Report of accounts disabled for inactivity
Where subcontractors usually fall short: Inactivity period undefined; Detection exists but disablement is manual and lapses; Service accounts excluded without justification
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 IA.L2-3.5.7Password Complexity 1 point in the score

Set a minimum complexity for passwords, and require that a newly created password differ in its characters from the one it replaces.

What an assessor asks to see: Configured password complexity settings; Setting or procedure requiring changed characters on password creation; Coverage across directories and standalone systems
Where subcontractors usually fall short: Complexity enforced centrally but not on local or application accounts; Character change requirement absent so minor edits are accepted; Policy documented without technical enforcement
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 IA.L2-3.5.8Password Reuse 1 point in the score

Prohibit reuse of a password for a specified number of generations.

What an assessor asks to see: Configured password history depth; Policy stating the number of generations prohibited; Coverage across all authentication stores
Where subcontractors usually fall short: History depth set to zero or unset; Enforced in the directory only, not on local accounts; Users cycle passwords rapidly to defeat history
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 IA.L2-3.5.9Temporary Passwords 1 point in the score

Permit a temporary password for logon only where it must be changed to a permanent password immediately on use.

What an assessor asks to see: Procedure for issuing temporary passwords; Configuration forcing change at first logon; Evidence of enforcement in account creation and reset workflows
Where subcontractors usually fall short: Temporary passwords remain valid indefinitely; Change at first logon not enforced by the system; Predictable temporary password patterns
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)