3.5 Identification & Authentication5 ptsAlso Level 1

3.5.2 — Authenticate before access

Authenticate (or verify) the identities of users, processes, or devices, as a prerequisite to allowing access to organizational systems.

Verify identity before granting any access to the system.

What it actually means

Before anything reaches CUI, its identity is verified. Users authenticate through your identity provider; devices authenticate through MDM compliance and conditional access. No anonymous or unauthenticated access to the CUI environment.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.

Calculate your SPRS score →Draft your SSP language →

Connected requirements

More in Identification & Authentication (3.5)

← Back to the Control Library

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.