
Multi-Factor Authentication Methods Acceptable Under CMMC
CMMC Level 2 expects MFA for specific access types; this post explains acceptable factor types, Microsoft methods that fit, and the evidence assessors request.

CMMC Level 2 expects MFA for specific access types; this post explains acceptable factor types, Microsoft methods that fit, and the evidence assessors request.

Contractors should verify Cyber AB authorization, independence, ISO/IEC 17020 status, and alignment to the CAP and NIST SP 800-171 when choosing a C3PAO for future CMMC Level 2 assessments, while using Microsoft resources as implementation references, not as assessment criteria.

Pick your CMMC target by contract and data type, not preference; FCI points to Level 1, CUI drives Level 2, and only select programs require Level 3 with added 800-172 safeguards and a DCMA DIBCAC government assessment.

Contract language and data types drive Microsoft 365 tenant selection across Commercial, GCC, GCC High, and DoD, and the right choice maps requirements such as DFARS 252.204-7012, NIST SP 800-171, CMMC, ITAR, and DoD SRG to environments Microsoft designed for those obligations.

NIST published SP 800-171 Revision 3 in May 2024, but DoD contracts and CMMC assessments still point to Revision 2; use Rev 2 for assessments now and prepare your program to absorb Rev 3’s structure, alignment with SP 800-53 Rev 5, and organization-defined parameters.

Export controls change how you select and configure Microsoft 365, and Microsoft states the customer remains the exporter who must assess cloud use.