DKDavid Koran& Associates
Home The CMMC Guide Part III · Identification and Authentication IA.L2-3.5.9
The CMMC Guide · Identification and Authentication Family

IA.L2-3.5.9  Temporary Password Use

Allow temporary password use for system logons with an immediate change to a permanent password.

Family
Identification and AuthenticationIA, 11 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
OnePer NIST SP 800-171A

1Overview

IA.L2-3.5.9 keeps temporary passwords temporary. It requires that when a temporary password is used for a system logon, the user must immediately change it to a permanent one, so that the temporary credential does not persist as a lasting, often weak, way in. It is a one-point requirement with a single assessment objective, and it may be deferred on a plan of action.

Temporary passwords are handed out for onboarding and resets, and they are usually simple by design, sometimes shared or predictable. If a temporary password is allowed to persist, it becomes a weak, possibly known credential that lingers on the account. This control requires that a temporary password be changed to a permanent one immediately upon its first use, so the temporary credential exists only long enough to let the user set their own.

The requirement · NIST SP 800-171 Rev 2, 3.5.9

Allow temporary password use for system logons with an immediate change to a permanent password.

The requirement permits temporary passwords but conditions them on an immediate change. When a user logs on with a temporary password, the system requires them to set a permanent password before proceeding, so the temporary credential cannot remain in effect. This is enforced through the account setting that flags a password as requiring change at next logon.

2The Assessment Objective

NIST SP 800-171A frames 3.5.9 as a single objective: require an immediate change from temporary to permanent.

An immediate change to a permanent password is required when a temporary password is used for system logon. Temporary passwords must be changed at first use.

MeetsAccounts with temporary passwords require a permanent password to be set at first logon.
FailsTemporary passwords persist and can be used indefinitely.

The single objective is the required immediate change. The common failure is temporary passwords issued without the change-at-next-logon flag, so they linger. The assessor looks for enforcement that a temporary password is changed immediately.

3Failure Patterns

The failures are about temporary passwords that persist.

Change-at-logon not set

Where a temporary password is issued without requiring a change at next logon, it can remain in use, which is exactly what the control prevents. Setting the change-at-next-logon flag enforces the immediate change.

Shared or predictable temporary passwords left in place

Temporary passwords are often simple or shared, so if they persist they are a known weak credential. The immediate change is what keeps them from lasting.

Reset process without enforced change

A password reset process that issues a temporary password but does not force a change leaves the same gap. The process has to require the permanent change at first use.

The common root
This control fails when a temporary password is allowed to become permanent by neglect. Temporary credentials are weak by design, and if the immediate change is not enforced, that weakness settles into the account, so requiring the change at first logon is what keeps temporary genuinely temporary.

4Ownership

This is an IT-owned technical control, delivered through account settings and the reset process.

RoleResponsibility for this control
IT and system administratorIssues temporary passwords with a required change at next logon and enforces it in the reset process. Owns the technical evidence.
Security or compliance leadConfirms temporary passwords require an immediate permanent change.
Program leadIncludes the reset process in periodic review and retains the evidence.
See also: This control works with the password rules of IA.L2-3.5.7 and supports the authentication of IA.L2-3.5.2.

5Tooling

The control is delivered by the change-at-next-logon account setting.

ObjectiveToolingWhat it provides
enforceChange-at-next-logon flagA required permanent password change when a temporary one is used.
processOnboarding and reset proceduresIssuance of temporary passwords that must be changed immediately.

The caveat is that the change has to be enforced by the account setting, not left to the user's initiative. The change-at-next-logon flag is what guarantees the immediate change, so it has to be set whenever a temporary password is issued. The assessor examines whether temporary passwords require an immediate change, so the enforcement has to be present in the process.

6Evidence

The satisfied version of 3.5.9 shows temporary passwords requiring an immediate change.

EvidenceWhat it demonstrates
Change-at-logon configurationThe objective. Temporary passwords require a permanent change at first use.
Reset process documentationThe objective. The process enforces the immediate change.

The evidence should show that temporary passwords require an immediate permanent change at first logon. The change-at-next-logon configuration and the reset process are the clearest demonstration of the control.

Temporary should never become permanent

Temporary passwords are weak by design, and if they persist they settle into the account as a lasting risk, so this control requires an immediate change at first use. Enforcing change-at-next-logon in onboarding and resets is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.5.9. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.5.9. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in Identification and Authentication
IA.L2-3.5.8 · Password Reuse Prohibition
Next in Identification and Authentication →
IA.L2-3.5.10 · Cryptographically-Protected Passwords
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry IA.L2-3.5.9 · Edition 2026.1 · Last reviewed July 12, 2026