DKDavid Koran& Associates
Home The CMMC Guide Part III · Identification and Authentication IA.L2-3.5.11
The CMMC Guide · Identification and Authentication Family

IA.L2-3.5.11  Obscure Authentication Feedback

Obscure feedback of authentication information.

Family
Identification and AuthenticationIA, 11 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
OnePer NIST SP 800-171A

1Overview

IA.L2-3.5.11 closes the Identification and Authentication family with a small but important measure. It requires that the organization obscure the feedback of authentication information, so that as a user authenticates, the information they enter is not displayed in a way that others could see. It is a one-point requirement with a single assessment objective, and it may be deferred on a plan of action.

Authentication feedback is what the system shows while someone logs in, and if it reveals the credential, a password shown on screen, a token echoed in full, then anyone watching, in person or over the shoulder of a shared display, can capture it. This control requires that such feedback be obscured, most familiarly by masking a password with dots or asterisks as it is typed, so the credential is not exposed during entry. It is a modest control, but it closes a simple avenue of credential theft.

The requirement · NIST SP 800-171 Rev 2, 3.5.11

Obscure feedback of authentication information.

The requirement is that authentication information not be displayed openly as it is entered or processed. The everyday example is the masked password field, where characters appear as dots rather than the letters typed, but the principle extends to any point where a credential might otherwise be shown, such as error messages or logs that could echo it. The control is generally met by the default masking of modern login interfaces, with attention to any custom interface that might reveal credentials.

2The Assessment Objective

NIST SP 800-171A frames 3.5.11 as a single objective: obscure authentication feedback.

Authentication information is obscured during the authentication process. Credentials are not displayed openly during authentication.

MeetsPasswords and other authentication information are masked during entry, so they are not visible.
FailsAuthentication information is displayed in the clear during login.

The single objective is obscured authentication feedback. The common failure is a custom or legacy interface that displays a credential rather than masking it. The assessor looks for authentication information obscured throughout the process.

3Failure Patterns

The failures are about credentials shown openly during authentication.

Unmasked password fields

A login interface that shows the password as it is typed exposes it to anyone watching. Masking the field is the basic protection the control expects.

Credentials echoed in messages or logs

Error messages or logs that echo a password or token back reveal the credential outside the entry field. Obscuring feedback extends to any place a credential might otherwise appear.

Custom interfaces without masking

A custom application that does not mask authentication information leaves a gap even when standard logins are masked. Every authentication interface has to obscure the credential.

The common root
This control fails in the overlooked interface. Standard logins mask credentials by default, so the gap is usually a custom or legacy screen that shows a password or echoes it in a message, exposing the credential to anyone nearby. Checking every authentication path for masking is what closes it.

4Ownership

This is an IT-owned technical control, delivered through the authentication interfaces.

RoleResponsibility for this control
IT and system administratorEnsures authentication information is masked across login interfaces, including custom ones. Owns the technical evidence.
Security or compliance leadConfirms no interface displays or echoes credentials during authentication.
Program leadIncludes authentication interfaces in periodic review and retains the evidence.
See also: This control protects the credentials used in the authentication of IA.L2-3.5.2 and complements the storage and transit protection of IA.L2-3.5.10.

5Tooling

The control is delivered by masking in authentication interfaces.

ObjectiveToolingWhat it provides
entryMasked password fieldsCredentials obscured as they are entered.
messagesSuppression of credentials in messages and logsCredentials not echoed outside the entry field.
CoverageReview of custom authentication interfacesMasking applied across every authentication path.

The caveat is that masking has to cover every authentication interface, including custom and legacy ones. Standard logins mask by default, so the control is met by confirming that no interface displays or echoes a credential. The assessor examines the authentication interfaces, so any unmasked path has to be corrected.

6Evidence

The satisfied version of 3.5.11 shows authentication information obscured throughout.

EvidenceWhat it demonstrates
Login interface behaviorThe objective. Authentication information masked during entry.
Interface reviewThe objective. No interface displays or echoes credentials.

The evidence should show authentication information obscured across the login interfaces, with no path displaying a credential. The masked interfaces and a review confirming no exposure are the clearest demonstration of the control.

A credential on screen is a credential exposed

Authentication feedback that shows a password lets anyone nearby capture it, and this control asks for credentials to be obscured throughout the login. Confirming masking across every authentication interface, including custom ones, is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.5.11. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.5.11. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in Identification and Authentication
IA.L2-3.5.10 · Cryptographically-Protected Passwords
Next: Incident Response →
IR.L2-3.6.1 · Incident Handling
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry IA.L2-3.5.11 · Edition 2026.1 · Last reviewed July 12, 2026