The short answer

Federal regulations now mandate multi-factor authentication in specific contexts, but determining what qualifies as compliant and who owns implementation remains unclear in many organizations. This guide explains which regulations require MFA, what technical approaches satisfy those requirements, and how leadership should allocate accountability.

Multi-factor authentication has moved from security best practice to legal requirement in specific regulated contexts. Yet many organizations face implementation without clear ownership, defined acceptance criteria, or a method to demonstrate compliance. Leadership is accountable for an outcome without the structure to achieve it.

1What Multi-Factor Authentication Means in Regulatory Terms

NIST SP 800-53 Rev. 5 defines multi-factor authentication as an authentication system or authenticator that requires more than one authentication factor for successful authentication. The three recognized factors are something you know (password or PIN), something you have (cryptographic device or token), and something you are (biometric).

MFA can be performed using a single authenticator that provides more than one factor, or by a combination of authenticators that provide different factors. Entering two different passwords does not qualify, because both credentials come from the same category.

This technical definition matters because regulatory compliance requires specific implementations, not general security improvements. What counts as compliant in one context may be insufficient in another.

2Where Federal Regulations Mandate MFA

The clearest federal mandate appears in the Criminal Justice Information Systems (CJIS) Security Policy. NIST IR 8523, published in final form in September 2025, provides implementation guidance for MFA requirements in CJIS Security Policy versions 5.9.2 and later. These policies require MFA to protect access to criminal justice information.

According to NIST IR 8523, MFA is important for protecting against credential compromises and other cyber risks that may threaten criminal justice information. As agencies around the country begin to implement MFA solutions, the approaches they use require careful consideration and planning.

Beyond CJIS, specific sectors face requirements through federal contracts, grants, or compliance frameworks. NIST SP 800-171r3, which governs controlled unclassified information in non-federal systems, defines multi-factor authentication as authentication using two or more different factors. Organizations handling CUI must implement MFA where the framework requires it.

The absence of a universal federal MFA mandate does not reduce organizational risk. Contractual obligations, insurance requirements, and state regulations create enforceable expectations independent of federal law.

3What Qualifies as a Compliant MFA Implementation

Not all MFA provides equivalent protection. NIST guidance distinguishes between standard multi-factor authentication and phishing-resistant authentication, a higher standard that some contexts require.

According to NIST's small business cybersecurity guidance, some forms of MFA can be susceptible to phishing threats, including one-time PINs (OTPs) and SMS-based codes. FIDO authenticators paired with W3C's Web Authentication API are the most common form of phishing-resistant authenticators widely available today.

These phishing-resistant authenticators can take the form of separate hardware keys or be embedded directly into platforms such as phones or laptops. NIST refers to embedded implementations as platform authenticators. The availability and security of platform authenticators increasingly puts strong, phishing-resistant authentication into users' hands without the need for additional devices.

NIST IR 8523 outlines how public safety-specific technologies can support standards and best practices that provide agencies with maximum optionality to implement MFA in a way that promotes security, interoperability, usability, and cost savings. The document provides specific examples of use cases that agencies face today.

When Phishing-Resistant MFA Becomes Necessary

Not every transaction requires phishing-resistant authentication. However, for applications that protect sensitive information such as health information or personally identifiable data, or for users that have elevated privileges such as administrators or security personnel, organizations should be enforcing, or at least offering, phishing-resistant authenticators.

This distinction creates an implementation decision that requires business judgment, not just technical configuration. Determining which systems contain sufficiently sensitive information to warrant phishing-resistant MFA is a risk decision that belongs at the executive level.

4Why Organizations Fail MFA Compliance

The most common compliance failure is not technical implementation but organizational structure. MFA sits at the intersection of security policy, user experience, system administration, and regulatory interpretation. Without clear ownership, it becomes everyone's problem and no one's accountability.

IT teams can configure authentication systems but typically lack authority to determine which business processes require phishing-resistant methods. Compliance officers understand regulatory language but rarely have visibility into which systems contain the regulated data. General counsel can interpret legal obligations but cannot assess whether a specific authenticator satisfies a technical requirement.

This gap explains why organizations often discover compliance deficiencies during audits rather than through internal review. The structure needed to answer compliance questions does not exist in most organizational charts.

5Who Should Own MFA Strategy and Compliance

Adequate ownership requires someone with authority to make risk decisions, translate regulatory requirements into technical specifications, and hold implementation teams accountable to measurable outcomes. This is the function a chief information security officer provides.

A CISO determines where phishing-resistant authentication is necessary based on data classification and user privilege levels. They establish the governance framework that defines acceptable authenticator types for each risk tier. They coordinate between compliance, IT, and business units to ensure implementation satisfies both regulatory requirements and operational constraints.

Organizations that lack a full-time CISO face a choice: leave the accountability gap unresolved, or establish executive oversight through another structure. Virtual CISO leadership provides the strategic function without the permanent overhead, giving boards and executive teams a clear point of accountability for regulatory position and implementation progress.

6How MFA Compliance Connects to Broader Identity Strategy

MFA is one component of identity and access management, not a standalone compliance checkbox. How users authenticate affects session management, privilege escalation, access review processes, and audit logging. Implementing MFA without considering these dependencies creates technical debt and operational friction.

A coherent identity strategy addresses how authentication strength varies by context, how access decisions incorporate device trust and network location, and how the organization manages the credential lifecycle from provisioning through revocation. These decisions require coordination across security, IT, HR, and compliance functions.

Organizations that treat MFA as an isolated project typically face repeated rework as they discover conflicts with existing access patterns, integration limitations with legacy systems, or user resistance driven by poor experience design. Strategic planning prevents these outcomes.

7Practical Questions Leadership Should Ask

NIST's small business guidance suggests specific questions organizations should consider:

  • Have we completed an inventory of all our systems to determine which ones offer multi-factor authentication?
  • Have we enabled MFA on our most sensitive accounts? Are phishing-resistant options available to us for use on our most sensitive applications?
  • Do employees understand how to enable MFA and its importance in protecting the business?
  • Do we have a policy for requiring use of MFA and phishing-resistant MFA?

Beyond MFA, organizations should consider related access management practices: whether access to systems and data is limited to only those who need it to do their jobs, whether access is removed when needs change or when employees leave the business, whether administrative privileges to systems and devices are limited to only certain employees, and whether the organization uses a password manager to create and store strong passwords.

These questions reveal whether the organization has the governance structure to make and enforce access decisions, not just the technical capability to configure authentication.

8What to Do Next

Start with a clear regulatory position. Determine which specific regulations, contractual obligations, or insurance requirements create enforceable MFA expectations for your organization. Document the technical standards each requirement imposes and identify where sources conflict.

Inventory systems and categorize them by the sensitivity of data they contain and the privilege level of users who access them. This classification determines where standard MFA suffices and where phishing-resistant authentication is necessary.

Assign clear ownership for MFA strategy, not just implementation. Someone must have authority to make risk-based decisions about authentication strength, resolve conflicts between usability and security, and report compliance status to the board.

If your organization lacks the internal structure to own this function, consider whether strategic cybersecurity leadership would close the gap. Heights Consulting Group provides virtual CISO services that establish governance, translate regulatory requirements into implementation roadmaps, and give executive teams a single point of accountability for security outcomes.

A confidential consultation can clarify where your current structure leaves accountability gaps and what alternatives would resolve them. Contact Heights Consulting Group to discuss your specific situation.

Related service: Identity and Access Management Strategy

A defensible answer to who has access to what, how they got it, and how it is removed, the question every assessment asks and most organizations answer from memory.

Read about Identity and Access Management Strategy