NIST SP 800-171 control 3.5.3, assessed under CMMC Level 2, requires multifactor authentication for access, but a legacy PLC cannot run an MFA client. The compliant path is not to replace the PLC. It is to enforce MFA at a network access point in front of it and document that as a compensating control under an enduring exception. Your C3PAO assessor still makes the final MET determination.
What 3.5.3 actually requires
Control 3.5.3 requires MFA for local and network access to privileged accounts, and for network access to non-privileged accounts. It is about protecting access to systems, not about installing software on every device. A twenty-year-old PLC has no user accounts and no way to prompt for a second factor. Reading 3.5.3 as "every device must do MFA" is what makes people believe legacy OT can never be compliant.
Why the PLC cannot do it, and why that is fine
PLCs, RTUs, and many HMIs run closed real-time firmware with no identity layer. They cannot host an MFA agent, and adding one is usually impossible and often voids the warranty. CMMC anticipates this: some assets cannot meet a practice as written, which is exactly what the enduring exception is for.
In CMMC scoping, these legacy controllers are also typically classified as Specialized Assets: documented in your asset inventory, network diagram, and System Security Plan, and managed under a risk-based policy rather than assessed against every practice line by line. The access gateway is how you demonstrate that risk-based management for the access requirement, and how you keep the evidence to back it.
The compensating control
Move the enforcement point off the device and onto the network:
- The operator or vendor authenticates to an access gateway with MFA, against your existing identity provider.
- Only after that does the gateway broker the session to the specific PLC, for the specific task.
- The MFA enforcement configuration and authentication logs are the evidence that MFA occurred; session recording is separate evidence for accountability.
The PLC installs nothing. Access to it is now behind MFA, which satisfies the objective of 3.5.3 through a compensating control. Your C3PAO assessor makes the final determination.
How to document it for an assessor
Record the legacy device as an enduring exception, describe the compensating control (MFA enforced at the access gateway, with session logging and identity binding), and keep the evidence. See our guide on the enduring exception for OT. And because the affirming official signs off on this, make sure the evidence is real, not asserted, see the affirming official's False Claims Act risk.
Trout's Access Gate enforces MFA at the network layer in front of assets that cannot do it themselves, producing exactly the tamper-evident evidence an assessor wants to see.
This article is general information, not legal or assessment advice.