Replay-resistant Authentication
Practice statement
Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.
Quoted verbatim from NIST SP 800-171 Rev. 2 §3.5.4.Source
The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.
Assessment Objectives(1)
An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.
- [a]
replay-resistant authentication mechanisms are implemented for network account access to privileged and non-privileged accounts.
1 example covers this
Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.
Implementation examples(1)
Submit your own example- addresses
IA.L2-3.5.4Replay-resistant Authentication
Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.
[a]
replay-resistant authentication mechanisms are implemented for network account access to privileged and non-privileged accounts.
Network access requires FIDO2 or certificate; OTP not accepted for VPN or SSO
ControlVerdict Corpus@cv-corpusOSCJul 31, 2026Community is just starting — add yours. No verdicts yet.Implementation
AO coverage. Addresses all replay-resistant authentication objectives for this practice.
Policy. Authentication strength for all CUI applications and the VPN requires a phishing-/replay-resistant method: FIDO2 security key, platform authenticator bound to a compliant device, or device certificate (EAP-TLS) for the VPN. Authenticator-app TOTP and SMS are enrolled for account recovery only and are excluded from the strength used by CUI Conditional Access / VPN policies.
Enrollment. New hires receive two FIDO2 keys (primary + backup) before CUI access is granted. Platform authenticators are allowed only on MDM-enrolled, encrypted endpoints. Lost-key process: disable the credential in the IdP within one business day; temporary access uses the backup key only—no temporary SMS bypass for CUI apps.
VPN. Client certificate issued by the org CA via MDM; password+OTP VPN profiles are removed. Split tunnel is disabled for the CUI routes.
Maintenance. Monthly authentication-methods report for privileged and CUI-group users (methods in use). Quarterly purge of stale device certificates. Annual tabletop of lost-key and break-glass FIDO2 procedures.
Accepted gap. Two partner portals that we must use cannot accept FIDO2. Users reach them only through a browser on a PAW after phishing-resistant SSO to the PAW; partner passwords are vaulted and not reused.
What the evidence looks like
- Authentication strength / Conditional Access export listing allowed methods
- VPN profile showing certificate auth and no OTP profile
- Enrollment checklist and key inventory (serial ↔ person)
- Sign-in logs showing method claims for a sample of CUI app access
- Exception register for the two partner portals
Environment
Hybrid workforce; CUI apps behind SSO and a full-tunnel VPN for a small on-prem lab.Tools
Discussion(0)
No discussion on this control yet
Edge cases, scoping questions, and “would this pass?” scenarios belong here.
Sign in to start a thread.