DKDavid Koran& Associates
Home The CMMC Guide Part III · Identification and Authentication IA.L2-3.5.5
The CMMC Guide · Identification and Authentication Family

IA.L2-3.5.5  Identifier Reuse

Prevent reuse of identifiers for a defined period.

Family
Identification and AuthenticationIA, 11 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
TwoPer NIST SP 800-171A

1Overview

IA.L2-3.5.5 prevents identifiers from being recycled too soon. It requires that the organization define a period during which identifiers cannot be reused and prevent reuse within it, so that a username or identifier once assigned to one person is not handed to another while the old association still matters. It is a one-point requirement and may be deferred on a plan of action.

When an identifier such as a username is reassigned to a new person too quickly, confusion follows: old audit records, permissions, or references now appear to belong to the new holder, and accountability blurs. This control asks the organization to set a period during which a retired identifier stays retired, and to prevent its reuse within that period, so the association between an identifier and a person remains clean. It keeps the identity records unambiguous as people come and go.

The requirement · NIST SP 800-171 Rev 2, 3.5.5

Prevent reuse of identifiers for a defined period.

The requirement has two parts: define the period and prevent reuse within it. The period is set by the organization to be long enough that the old association no longer causes confusion, and within it the identifier is not reassigned. This is usually a matter of directory practice and account records rather than a technical enforcement, but the period has to be defined and reuse actually prevented.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.5.5 into two objectives: define the period and prevent reuse within it.

[a]

A period within which identifiers cannot be reused is defined. The organization has set how long a retired identifier stays retired.

MeetsA defined period during which identifiers cannot be reassigned.
FailsNo period is defined, so identifiers can be reused at any time.
[b]

Reuse of identifiers is prevented within the defined period. Retired identifiers are not reassigned within the period.

MeetsIdentifiers are not reassigned within the defined period, keeping associations clean.
FailsIdentifiers are reused quickly, so a new person inherits an old identifier's associations.

The two objectives are the definition and the prevention. The common gap is at objective [a], where no period is defined, leaving reuse ungoverned. The assessor looks for a defined period and evidence that reuse is prevented within it.

3Failure Patterns

The failures are about undefined periods and quick reassignment.

No defined period

Without a defined reuse period, there is no rule governing reassignment, and objective [a] is unmet. Defining the period is the necessary first step.

Immediate reassignment

Reassigning an identifier to a new person soon after the old holder leaves lets the new person inherit old associations, confusing accountability. Preventing reuse within the defined period avoids this.

Period defined but not observed

A defined period that is not actually observed in practice leaves objective [b] unmet. The prevention has to be real, not just stated.

The common root
This control fails when identifiers are treated as freely reusable. Reassigning a username quickly seems harmless but carries the old holder's history into a new person's identity, and unless a period is defined and observed, the records blur exactly where accountability needs them clear.

4Ownership

This is an IT-owned control, delivered through directory and account management practice.

RoleResponsibility for this control
IT and system administratorObserves the defined reuse period and avoids reassigning identifiers within it. Owns the account records.
Security or compliance leadDefines the reuse period and confirms reuse is prevented within it.
Program leadIncludes identifier reuse in account management practice and retains the evidence.
See also: This control keeps the identities of IA.L2-3.5.1 unambiguous and supports the accountability of AU.L2-3.3.2.

5Tooling

The control is largely a matter of account management practice with a defined period.

ObjectivesToolingWhat it provides
[a]Defined identifier reuse periodThe period during which identifiers cannot be reassigned.
[b]Account management practice, retained account recordsPrevention of reassignment within the period.

The caveat is that the control rests on practice more than technology, so the defined period has to be observed in account management. Retaining records of retired identifiers helps demonstrate that reuse is prevented within the period. The assessor examines the defined period and account practice, so both have to be evident.

6Evidence

The satisfied version of 3.5.5 shows a defined period and prevented reuse.

EvidenceWhat it demonstrates
Defined reuse periodObjective [a]. The period during which identifiers cannot be reused.
Account management recordsObjective [b]. Evidence identifiers are not reassigned within the period.

The evidence should show a defined reuse period and account practice that prevents reassignment within it. The defined period paired with account records is the clearest demonstration of the control.

A retired username should stay retired long enough

Reassigning an identifier too soon carries an old holder's history into a new person's identity, and this control asks for a defined period during which reuse is prevented. Setting that period and observing it in account management is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.5.5. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.5.5[a] and 3.5.5[b]. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in Identification and Authentication
IA.L2-3.5.4 · Replay-Resistant Authentication
Next in Identification and Authentication →
IA.L2-3.5.6 · Disable Identifiers After Inactivity
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry IA.L2-3.5.5 · Edition 2026.1 · Last reviewed July 12, 2026