1Overview
IA.L2-3.5.7 sets a floor under password strength. It requires that the organization enforce a minimum password complexity and a change of characters when new passwords are created, so that passwords are not trivially weak or minor edits of old ones. It is a one-point requirement and may be deferred on a plan of action.
Weak passwords are among the easiest ways into an account, and passwords that change by only a character or two are barely stronger than the ones they replace. This control asks the organization to define complexity requirements and change-of-character requirements, and to enforce both when new passwords are created, so that new passwords meet a strength floor and differ meaningfully from their predecessors. It sits alongside modern guidance that favors length and screening over arbitrary complexity, but the control as written requires defined complexity and change-of-character rules, enforced at creation.
Enforce a minimum password complexity and change of characters when new passwords are created.
The requirement has two dimensions, each defined and then enforced: minimum complexity, the strength characteristics a password must have, and change of characters, the requirement that a new password differ meaningfully from the old one rather than being a trivial edit. Both have to be defined by the organization and enforced at the moment a new password is created, usually through directory password policy. The four assessment objectives come from pairing definition with enforcement across these two dimensions.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.5.7 into four objectives: define complexity, define change of characters, enforce complexity, and enforce change of characters.
Password complexity requirements are defined. The organization has set the strength characteristics passwords must have.
Password change of character requirements are defined. The organization has set how much a new password must differ from the old.
Minimum password complexity requirements as defined are enforced when new passwords are created. The complexity rules are applied at creation.
Minimum password change of character requirements as defined are enforced when new passwords are created. The change rules are applied at creation.
The four objectives pair definition and enforcement across complexity and change of characters. The common gap is at the enforcement objectives, [c] and [d], where requirements are defined in a document but the directory policy does not actually enforce them. The assessor looks for both defined and enforced at creation.
3Failure Patterns
The failures are about undefined or unenforced password rules.
Requirements on paper but not enforced
Complexity or change requirements written in a policy but not enforced by directory settings leave objectives [c] and [d] unmet. Enforcement through password policy is what applies them.
Trivial password changes accepted
Where a new password can be a minor edit of the old one, the change-of-character requirement is not enforced. New passwords have to differ meaningfully.
No defined requirements
Without defined complexity and change requirements, there is nothing to enforce, and objectives [a] and [b] are unmet. Defining both is the starting point.
Enforcement inconsistent across systems
Where some systems enforce the rules and others do not, passwords set on the unenforced systems escape the floor. Enforcement has to reach all in-scope systems.
4Ownership
This is an IT-owned technical control, delivered through directory password policy.
| Role | Responsibility for this control |
|---|---|
| IT and system administrator | Defines and enforces complexity and change-of-character requirements through password policy across systems. Owns the technical evidence. |
| Security or compliance lead | Confirms requirements are defined and enforced at creation on all in-scope systems. |
| Program lead | Reviews password policy coverage and retains the evidence. |
5Tooling
The control is delivered by password policy that enforces complexity and change at creation.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a], [b] | Defined password policy | The complexity and change-of-character requirements. |
| [c], [d] | Directory password policy enforcement | Application of the requirements when new passwords are created. |
| Coverage | Consistent policy across systems | Enforcement reaching all in-scope systems. |
The caveat is that enforcement must reach every system where passwords are set, and modern guidance favoring length and screening still has to be expressed through defined, enforced requirements. The assessor examines whether the defined rules are enforced at creation across systems, so the enforcement coverage is the substance of the control.
6Evidence
The satisfied version of 3.5.7 shows defined and enforced password requirements.
| Evidence | What it demonstrates |
|---|---|
| Password policy | Objectives [a], [b]. The defined complexity and change requirements. |
| Enforcement configuration | Objectives [c], [d]. The requirements enforced at creation. |
The evidence should show complexity and change-of-character requirements both defined and enforced at password creation across systems. The password policy paired with its enforcement configuration is the clearest demonstration of the control.
A password floor only works where it is enforced
Weak passwords and trivial changes slip through wherever the rules are written but not applied, and this control asks for complexity and meaningful change enforced at creation. Setting and enforcing password policy across every in-scope system is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.5.7. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.5.7[a] through 3.5.7[d]. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov