Author: Velocity CMMC Team · Reviewer: Velocity CMMC Review Team · Last reviewed: July 21, 2026
Official sources reviewed
Contract language, current regulations, and official CMMC program guidance control identity and MFA requirement mapping.
- NIST SP 800-171 Rev. 2
- CMMC Level 2 Assessment Guide via DoD CMMC Resources & Documentation
- CMMC Level 2 Scoping Guidance via DoD CMMC Resources & Documentation
- 32 CFR Part 170
Last reviewed July 21, 2026 for current CMMC program sources.
Why identity is not “just MFA”
DoD alignment materials call out scoring and partial credit concepts related to MFA and cryptography (FIPS), underscoring that identity controls affect compliance outcomes and assessor scrutiny. Identity controls also intersect with multiple domains (Access Control and Identification & Authentication among others), so they should be designed as a system, not deployed as a patch.
Phishing resistance and federal context
Yubico’s federal government MFA resource claims the YubiKey is the only DoD OCIO‑approved alternate hardware authenticator to a CAC supporting multiple protocols and meeting DoD cybersecurity requirements; this is a useful example of implementation stringency required at the federal level.
Yubico also publishes DoD-focused MFA material positioning YubiKeys as phishing-resistant and referencing FIPS 140‑2 validation and NIST SP 800‑63B AAL3 alignment. Even if your customers do not require those exact attributes, citing them helps establish that your architecture is oriented toward high-assurance environments rather than generic SMB “2FA.”
For an additional non-vendor anchor, a U.S. federal identity guidance site provides a YubiKey implementation guide describing FIDO2-compliant MFA use by federal employees and contractors, reinforcing that hardware-backed MFA is normalized in federal contexts.
Reference pattern
- Use a central identity provider
- Enforce least-privilege and privileged access separation
- Require MFA for remote and privileged access
- Adopt phishing-resistant factors for high-risk roles
- Maintain policy + technical enforcement evidence (screenshots, configs, logs, user lifecycle records) because CMMC is assessed on implementation and proof, not on intent.