TroutTrout
Back to Blog
CMMCAuthentication

MFA for PLCs: Meeting CMMC 3.5.3 with a Compensating Control

Trout Team3 min read

NIST SP 800-171 control 3.5.3, assessed under CMMC Level 2, requires multifactor authentication for access, but a legacy PLC cannot run an MFA client. The compliant path is not to replace the PLC. It is to enforce MFA at a network access point in front of it and document that as a compensating control under an enduring exception. Your C3PAO assessor still makes the final MET determination.

What 3.5.3 actually requires

Control 3.5.3 requires MFA for local and network access to privileged accounts, and for network access to non-privileged accounts. It is about protecting access to systems, not about installing software on every device. A twenty-year-old PLC has no user accounts and no way to prompt for a second factor. Reading 3.5.3 as "every device must do MFA" is what makes people believe legacy OT can never be compliant.

Why the PLC cannot do it, and why that is fine

PLCs, RTUs, and many HMIs run closed real-time firmware with no identity layer. They cannot host an MFA agent, and adding one is usually impossible and often voids the warranty. CMMC anticipates this: some assets cannot meet a practice as written, which is exactly what the enduring exception is for.

In CMMC scoping, these legacy controllers are also typically classified as Specialized Assets: documented in your asset inventory, network diagram, and System Security Plan, and managed under a risk-based policy rather than assessed against every practice line by line. The access gateway is how you demonstrate that risk-based management for the access requirement, and how you keep the evidence to back it.

The compensating control

Move the enforcement point off the device and onto the network:

  • The operator or vendor authenticates to an access gateway with MFA, against your existing identity provider.
  • Only after that does the gateway broker the session to the specific PLC, for the specific task.
  • The MFA enforcement configuration and authentication logs are the evidence that MFA occurred; session recording is separate evidence for accountability.

The PLC installs nothing. Access to it is now behind MFA, which satisfies the objective of 3.5.3 through a compensating control. Your C3PAO assessor makes the final determination.

How to document it for an assessor

Record the legacy device as an enduring exception, describe the compensating control (MFA enforced at the access gateway, with session logging and identity binding), and keep the evidence. See our guide on the enduring exception for OT. And because the affirming official signs off on this, make sure the evidence is real, not asserted, see the affirming official's False Claims Act risk.

Trout's Access Gate enforces MFA at the network layer in front of assets that cannot do it themselves, producing exactly the tamper-evident evidence an assessor wants to see.

This article is general information, not legal or assessment advice.

FAQ

Frequently Asked Questions

Does CMMC 3.5.3 require MFA on the PLC itself?
No. NIST SP 800-171 control 3.5.3 (assessed under CMMC Level 2) requires multifactor authentication for access to accounts, not that each device run an MFA client. What matters is that access to the asset is protected by MFA. For a PLC that cannot authenticate a user, you enforce MFA at the point of access in front of it.
How do you meet 3.5.3 for a legacy device that cannot do MFA?
Put an access gateway in the path in front of the device. The user authenticates to the gateway with MFA against your identity provider, and only then is the session brokered to the PLC. The control's objective is satisfied at the enforcement point through a compensating control, and the legacy device is documented as an enduring exception with this compensating control.
Is network-layer MFA a valid compensating control for CMMC?
Yes, when it is documented and accepted by your assessor. CMMC recognizes that some assets cannot meet a practice as written. You record the enduring exception, describe the compensating control (MFA enforced at a network access point, with session logging), and keep evidence it operates: the MFA enforcement configuration and authentication logs, not only session recordings. The affirming official should be able to point to that evidence.