DKDavid Koran& Associates
Home The CMMC Guide Part III · Identification and Authentication IA.L2-3.5.6
The CMMC Guide · Identification and Authentication Family

IA.L2-3.5.6  Disable Identifiers After Inactivity

Disable identifiers after a defined period of inactivity.

Family
Identification and AuthenticationIA, 11 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
TwoPer NIST SP 800-171A

1Overview

IA.L2-3.5.6 clears away dormant identities. It requires that the organization disable identifiers after a defined period of inactivity, so that accounts no longer in use do not linger as unguarded entry points. It is a one-point requirement and may be deferred on a plan of action.

An inactive account is a quiet liability. It is not watched, its password may be stale, and its owner may have left, yet it retains its access, making it an attractive target for an attacker who wants a foothold no one is monitoring. This control asks the organization to define a period of inactivity after which an identifier is disabled, and to disable identifiers accordingly, so that access follows actual use and dormant accounts are closed before they become a problem.

The requirement · NIST SP 800-171 Rev 2, 3.5.6

Disable identifiers after a defined period of inactivity.

The requirement has two parts: define the inactivity period and disable identifiers after it. The period is set by the organization to balance security against operational disruption, and once an identifier has been inactive that long, it is disabled. This is often automated through the directory, which can flag or disable accounts that have not been used within the period, so dormant identities are closed without relying on someone to notice them.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.5.6 into two objectives: define the inactivity period and disable identifiers after it.

[a]

A period of inactivity after which an identifier is disabled is defined. The organization has set how long an account can be idle before it is disabled.

MeetsA defined inactivity period after which identifiers are disabled.
FailsNo inactivity period is defined, so dormant accounts remain active indefinitely.
[b]

Identifiers are disabled after the defined period of inactivity. Inactive identifiers are actually disabled.

MeetsIdentifiers inactive beyond the period are disabled, often automatically.
FailsInactive accounts remain enabled despite the period.

The two objectives are the definition and the disabling. The common gap is at objective [b], where a period is defined but nothing actually disables inactive accounts, so dormant identities persist. The assessor looks for inactive identifiers actually being disabled.

3Failure Patterns

The failures are about dormant accounts left enabled and periods that are not enforced.

Dormant accounts left active

Accounts of departed staff or unused service identities left enabled are unmonitored entry points. Disabling them after the defined inactivity period removes that exposure.

Period defined but not enforced

A defined inactivity period with no mechanism to act on it leaves objective [b] unmet. Automated disabling through the directory is the usual way to enforce it.

No monitoring of inactivity

Without tracking account inactivity, the organization cannot know which identifiers have crossed the period. Inactivity monitoring is what makes disabling possible.

The common root
This control fails when accounts outlive their use. A dormant identifier keeps its access while no one watches it, and unless inactivity is tracked and acted on, these forgotten accounts accumulate as quiet openings. Automating the disable is what keeps them from lingering.

4Ownership

This is an IT-owned technical control, usually automated through the directory.

RoleResponsibility for this control
IT and system administratorConfigures inactivity monitoring and disables identifiers after the defined period. Owns the technical evidence.
Security or compliance leadDefines the inactivity period and confirms inactive identifiers are actually disabled.
Program leadReviews disabled and dormant accounts periodically and retains the evidence.
See also: This control complements the account management behind IA.L2-3.5.1 and supports the access control family by closing unused access.

5Tooling

The control is delivered by directory inactivity monitoring and automated disabling.

ObjectivesToolingWhat it provides
[a]Defined inactivity periodThe threshold after which identifiers are disabled.
[b]Directory inactivity detection, automated disableDisabling of identifiers inactive beyond the period.

The caveat is that a defined period does nothing without a mechanism to act on it. Automated disabling based on last activity is what satisfies objective [b], since manual review tends to miss dormant accounts. The assessor examines whether inactive identifiers are actually disabled, so the enforcement mechanism has to be present.

6Evidence

The satisfied version of 3.5.6 shows a defined period and inactive identifiers disabled.

EvidenceWhat it demonstrates
Defined inactivity periodObjective [a]. The threshold for disabling.
Disable configuration or recordsObjective [b]. Inactive identifiers actually disabled.

The evidence should show a defined inactivity period and evidence that inactive identifiers are disabled after it. The configuration or records of disabled accounts are the clearest demonstration of the control.

An unused account is an unwatched door

Dormant identifiers keep their access while no one monitors them, and this control asks for inactive accounts to be disabled after a defined period. Automating that disable through the directory is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.5.6. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.5.6[a] and 3.5.6[b]. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in Identification and Authentication
IA.L2-3.5.5 · Identifier Reuse
Next in Identification and Authentication →
IA.L2-3.5.7 · Password Complexity
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry IA.L2-3.5.6 · Edition 2026.1 · Last reviewed July 12, 2026