logo

Why Multi-Factor Authentication (MFA) is Not Enough to Meet CMMC Requirements

ID: 39f2956d-8c1e-5ccd-89e9-36b1a10befee

STIX ID: report--39f2956d-8c1e-5ccd-89e9-36b1a10befee

Feed Name: Zimperium Blog

Date Published: 2022-12-22

Date Updated: 2026-05-01

...
...

As DoD and NIST update CMMC and SP 800-171 requirements, this advisory warns that multifactor authentication alone may not sufficiently protect Controlled Unclassified Information due to evolving threats like SMS-based spearphishing and MFA-bombing; it emphasizes supply-chain risk from compromised contractors and recommends augmenting MDM/MAM with Mobile Threat Defense (MTD) solutions—highlighting Zimperium zIPS—as a practical control to provide continuous on-device detection and stronger mobile security for CMMC compliance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.