Verify identity before granting any access to the system.
What it actually means
Before anything reaches CUI, its identity is verified. Users authenticate through your identity provider; devices authenticate through MDM compliance and conditional access. No anonymous or unauthenticated access to the CUI environment.
Pass or fail — an assessor needs a "yes" to each
- All access paths require authentication first.
- Device authentication is enforced (compliant-device checks).
- No anonymous access to CUI systems.
What to have ready
- Identity-provider authentication settings
- Conditional-access policies requiring authenticated, compliant devices
Where teams trip up
- A path into the environment that skips authentication
- Device authentication not enforced (any device can connect once a user logs in)
See where this control puts your score
Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.
Calculate your SPRS score →Draft your SSP language →Connected requirements
3.5.1 — You must identify before you can authenticate3.5.3 — MFA strengthens authentication for privileged and network access
More in Identification & Authentication (3.5)
3.5.1 — Uniquely identify users, processes, and devices3.5.3 — Multifactor authentication (MFA)3.5.4 — Replay-resistant authentication3.5.5 — Don't recycle identifiers3.5.6 — Disable dormant accounts3.5.7 — Enforce password complexity3.5.8 — Block password reuse3.5.9 — Force change of temporary passwords3.5.10 — Protect stored and transmitted passwords3.5.11 — Obscure authentication feedback