Frameworks / CMMC 2.0 / IA.L2-3.5.1 CMMC 2.0
Identification and Authentication
CMMC 2.0 IA.L2-3.5.1: Identification Identify system users, the processes acting on their behalf, and devices, so each is distinguishable before any access decision is made.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 55 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-ID.AM-01 Inventories of hardware managed by the organization are maintained NIST-CSF-ID.AM-02 Inventories of software, services, and systems managed by the organization are maintained NIST-CSF-ID.AM-07 Inventories of data and corresponding metadata for designated data types are maintained NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions CIS-1.1 Establish and Maintain Detailed Enterprise Asset Inventory CIS-5.1 Establish and Maintain an Inventory of Accounts CIS-5.5 Establish and Maintain an Inventory of Service Accounts CIS-5.6 Centralize Account Management IA-2 Identification and Authentication (Organizational Users) IA-2(5) Identification and Authentication (Organizational Users) | Individual Authentication with Group Authentication (IA-2(5)) IA-3 Device Identification and Authentication IA-8 Identification and Authentication (Non-Organizational Users) IA-2 Identification and Authentication (Organizational Users) IA-2(5) Identification and Authentication (Organizational Users) | Individual Authentication with Group Authentication (IA-2(5)) IA-3 Device Identification and Authentication IA-8 Identification and Authentication (Non-Organizational Users) NIST800-IA-2 IA-2 Identification and Authentication (Organizational Users) NIST800-IA-3 IA-3 Device Identification and Authentication NIST800-IA-4 IA-4 Identifier Management SP800-53-IA Identification and Authentication Family IM-1 Use centralized identity and authentication system IM-3 Manage application identities securely and automatically IM-4 Authenticate server and services ANSSI-HYG-07 Authorise Network Connection Only for Managed Equipment ANSSI-HYG-08 Identify Each Person by Name and Separate User and Administrator Roles 161R1-IA-2 Identification and Authentication (Organizational Users) 161R1-IA-3 Device Identification and Authentication 03.05.01 User Identification and Authentication 03.05.02 Device Identification and Authentication 8.2.1 8.2.1 Unique ID assigned to every user 8.2.2 8.2.2 Shared and generic IDs only by exception SOC2-CC6.1 CC6.1 Logical access security over protected information assets SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials E8-ADMIN-ML1 Restrict Administrative Privileges (ML1) ASD37-21 Disable local administrator accounts (Excellent) AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment C5-IDM-02 Granting and change of user accounts and access rights 5.14 Identification and traceability 8.3.2 Identification of strategies and solutions 6.6.2 User access management 8.5.2 Identification and traceability 3.5.1e Identification of Systems, Components, and Devices CE-AC.2 Authenticate Users Before Granting Access Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Identification and Authentication You are reading one control. How much of CMMC 2.0 have you already done? CMMC 2.0 IA.L2-3.5.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CMMC 2.0 your existing evidence covers. Hold FedRAMP Moderate and 108 of 110 CMMC 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 1 were rejected on the FedRAMP Moderate pair alone.
Query this from an agent The graph holds this control, the 55 it maps to, and the evidence behind each claim, over MCP and REST.