Built by Velocity Technologies for defense contractors, manufacturers, and subcontractors.
(602) 425-5630

Identity, Privileged Access, and Phishing-Resistant MFA

Author: Velocity CMMC Team · Reviewer: Velocity CMMC Review Team · Last reviewed: July 21, 2026

Official sources reviewed

Contract language, current regulations, and official CMMC program guidance control identity and MFA requirement mapping.

Last reviewed July 21, 2026 for current CMMC program sources.

Why identity is not “just MFA”

DoD alignment materials call out scoring and partial credit concepts related to MFA and cryptography (FIPS), underscoring that identity controls affect compliance outcomes and assessor scrutiny. Identity controls also intersect with multiple domains (Access Control and Identification & Authentication among others), so they should be designed as a system, not deployed as a patch.

Phishing resistance and federal context

Yubico’s federal government MFA resource claims the YubiKey is the only DoD OCIO‑approved alternate hardware authenticator to a CAC supporting multiple protocols and meeting DoD cybersecurity requirements; this is a useful example of implementation stringency required at the federal level.

Yubico also publishes DoD-focused MFA material positioning YubiKeys as phishing-resistant and referencing FIPS 140‑2 validation and NIST SP 800‑63B AAL3 alignment. Even if your customers do not require those exact attributes, citing them helps establish that your architecture is oriented toward high-assurance environments rather than generic SMB “2FA.”

For an additional non-vendor anchor, a U.S. federal identity guidance site provides a YubiKey implementation guide describing FIDO2-compliant MFA use by federal employees and contractors, reinforcing that hardware-backed MFA is normalized in federal contexts.

Reference pattern

  • Use a central identity provider
  • Enforce least-privilege and privileged access separation
  • Require MFA for remote and privileged access
  • Adopt phishing-resistant factors for high-risk roles
  • Maintain policy + technical enforcement evidence (screenshots, configs, logs, user lifecycle records) because CMMC is assessed on implementation and proof, not on intent.