Requirements / Identification and Authentication (IA)
IA.L2-3.5.8
Password Reuse
Official Source Material
Prohibit password reuse for a specified number of generations.
Determine if:
- [a] the number of generations during which a password cannot be reused is specified; and
- [b] reuse of passwords is prohibited during the specified number of generations.
Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024
Practitioner Guidance
How to meet it
Specify the number of generations and let the directory enforce it.
Objective [a] is one number in the password policy. Twenty-four remembered passwords matches the Windows security baseline, and the matching password history setting in Group Policy or your directory satisfies [b] with a single control.
Temporary passwords are exempt by the requirement's own discussion.
The assessment guide states that password lifetime restrictions do not apply to temporary passwords, so the one-time credential a help desk issues under IA.L2-3.5.9 does not enter the generation count.
Document what each platform can enforce.
Where a system exposes a configurable history depth, set your specified number there. Where one does not, state the platform's actual reuse behavior in the policy and rely on it. The objectives ask that the number is specified and reuse prohibited, not that every product expose the same setting.