DKDavid Koran& Associates
Home The CMMC Guide Part III · Identification and Authentication IA.L2-3.5.7
The CMMC Guide · Identification and Authentication Family

IA.L2-3.5.7  Password Complexity

Enforce a minimum password complexity and change of characters when new passwords are created.

Family
Identification and AuthenticationIA, 11 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
FourPer NIST SP 800-171A

1Overview

IA.L2-3.5.7 sets a floor under password strength. It requires that the organization enforce a minimum password complexity and a change of characters when new passwords are created, so that passwords are not trivially weak or minor edits of old ones. It is a one-point requirement and may be deferred on a plan of action.

Weak passwords are among the easiest ways into an account, and passwords that change by only a character or two are barely stronger than the ones they replace. This control asks the organization to define complexity requirements and change-of-character requirements, and to enforce both when new passwords are created, so that new passwords meet a strength floor and differ meaningfully from their predecessors. It sits alongside modern guidance that favors length and screening over arbitrary complexity, but the control as written requires defined complexity and change-of-character rules, enforced at creation.

The requirement · NIST SP 800-171 Rev 2, 3.5.7

Enforce a minimum password complexity and change of characters when new passwords are created.

The requirement has two dimensions, each defined and then enforced: minimum complexity, the strength characteristics a password must have, and change of characters, the requirement that a new password differ meaningfully from the old one rather than being a trivial edit. Both have to be defined by the organization and enforced at the moment a new password is created, usually through directory password policy. The four assessment objectives come from pairing definition with enforcement across these two dimensions.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.5.7 into four objectives: define complexity, define change of characters, enforce complexity, and enforce change of characters.

[a]

Password complexity requirements are defined. The organization has set the strength characteristics passwords must have.

MeetsDefined complexity requirements for new passwords.
FailsNo complexity requirements are defined.
[b]

Password change of character requirements are defined. The organization has set how much a new password must differ from the old.

MeetsDefined requirements for how new passwords must differ from prior ones.
FailsNo change-of-character requirements are defined.
[c]

Minimum password complexity requirements as defined are enforced when new passwords are created. The complexity rules are applied at creation.

MeetsComplexity requirements are enforced by password policy when passwords are set.
FailsComplexity is defined but not enforced, so weak passwords can be set.
[d]

Minimum password change of character requirements as defined are enforced when new passwords are created. The change rules are applied at creation.

MeetsChange-of-character requirements are enforced, so new passwords differ meaningfully.
FailsTrivial edits of old passwords are accepted.

The four objectives pair definition and enforcement across complexity and change of characters. The common gap is at the enforcement objectives, [c] and [d], where requirements are defined in a document but the directory policy does not actually enforce them. The assessor looks for both defined and enforced at creation.

3Failure Patterns

The failures are about undefined or unenforced password rules.

Requirements on paper but not enforced

Complexity or change requirements written in a policy but not enforced by directory settings leave objectives [c] and [d] unmet. Enforcement through password policy is what applies them.

Trivial password changes accepted

Where a new password can be a minor edit of the old one, the change-of-character requirement is not enforced. New passwords have to differ meaningfully.

No defined requirements

Without defined complexity and change requirements, there is nothing to enforce, and objectives [a] and [b] are unmet. Defining both is the starting point.

Enforcement inconsistent across systems

Where some systems enforce the rules and others do not, passwords set on the unenforced systems escape the floor. Enforcement has to reach all in-scope systems.

The common root
This control fails at enforcement more than definition. Organizations write password requirements readily, but unless the directory policy actually enforces complexity and meaningful change at creation across every system, weak or barely-changed passwords slip through where the enforcement does not reach.

4Ownership

This is an IT-owned technical control, delivered through directory password policy.

RoleResponsibility for this control
IT and system administratorDefines and enforces complexity and change-of-character requirements through password policy across systems. Owns the technical evidence.
Security or compliance leadConfirms requirements are defined and enforced at creation on all in-scope systems.
Program leadReviews password policy coverage and retains the evidence.
See also: This control strengthens the authentication of IA.L2-3.5.2 and works with the password reuse prohibition of IA.L2-3.5.8.

5Tooling

The control is delivered by password policy that enforces complexity and change at creation.

ObjectivesToolingWhat it provides
[a], [b]Defined password policyThe complexity and change-of-character requirements.
[c], [d]Directory password policy enforcementApplication of the requirements when new passwords are created.
CoverageConsistent policy across systemsEnforcement reaching all in-scope systems.

The caveat is that enforcement must reach every system where passwords are set, and modern guidance favoring length and screening still has to be expressed through defined, enforced requirements. The assessor examines whether the defined rules are enforced at creation across systems, so the enforcement coverage is the substance of the control.

6Evidence

The satisfied version of 3.5.7 shows defined and enforced password requirements.

EvidenceWhat it demonstrates
Password policyObjectives [a], [b]. The defined complexity and change requirements.
Enforcement configurationObjectives [c], [d]. The requirements enforced at creation.

The evidence should show complexity and change-of-character requirements both defined and enforced at password creation across systems. The password policy paired with its enforcement configuration is the clearest demonstration of the control.

A password floor only works where it is enforced

Weak passwords and trivial changes slip through wherever the rules are written but not applied, and this control asks for complexity and meaningful change enforced at creation. Setting and enforcing password policy across every in-scope system is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.5.7. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.5.7[a] through 3.5.7[d]. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in Identification and Authentication
IA.L2-3.5.6 · Disable Identifiers After Inactivity
Next in Identification and Authentication →
IA.L2-3.5.8 · Password Reuse Prohibition
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry IA.L2-3.5.7 · Edition 2026.1 · Last reviewed July 12, 2026