CMMCpedia Download

Requirements / Identification and Authentication (IA)

IA.L2-3.5.7

Password Complexity

Official Source Material

Enforce a minimum password complexity and change of characters when new passwords are created.

Determine if:

  1. [a] password complexity requirements are defined;
  2. [b] password change of character requirements are defined;
  3. [c] minimum password complexity requirements as defined are enforced when new passwords are created; and
  4. [d] minimum password change of character requirements as defined are enforced when new passwords are created.

Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024

Practitioner Guidance

How to meet it

This requirement asks for composition rules, so define composition rules.

Current NIST password guidance in SP 800-63B moved away from complexity requirements, but the requirement text and objectives here have not. Objectives [a] and [c] are defined and enforced complexity. [b] and [d] are defined and enforced change of characters. You are assessed against this text, not against the newer guidance, so meet the text in front of you.

You set the minimums, so set ones you can defend.

The objectives leave the numbers to you. A minimum length of twelve or more characters with three of the four character types is defensible and enforceable in Active Directory and Microsoft Entra ID. Choosing a longer minimum and citing the evolution of password guidance as the reason is equally defensible. Choosing eight characters is enforceable but weak.

Change of characters is the pair of objectives that gets missed. Define it even though enforcement is thin.

Objectives [b] and [d] want a rule about characters changing when a password changes, and mainstream platforms do not count changed characters natively. Define a minimum of at least one changed character, and enforce it through the platform's password history setting, which blocks the fully identical case. State that implementation in your system security plan, the document that describes how your system meets each requirement.

No objective requires password expiration.

Nothing in [a] through [d] mentions a maximum password age. Long passwords that never expire, paired with the MFA this family already requires, are consistent with every objective here. If you keep expiration, keep it as your own policy choice, not because this requirement demands it.

What falls short

  • Platform defaults with nothing defined in writing. Objectives [a] and [b] are definitions, and enforcement of an undefined rule cannot satisfy [c] or [d].

CMMCpedia is independently maintained and is not affiliated with the U.S. Department of Defense. The content is educational. It is not legal advice, and it does not guarantee certification.