1Overview
IA.L2-3.5.9 keeps temporary passwords temporary. It requires that when a temporary password is used for a system logon, the user must immediately change it to a permanent one, so that the temporary credential does not persist as a lasting, often weak, way in. It is a one-point requirement with a single assessment objective, and it may be deferred on a plan of action.
Temporary passwords are handed out for onboarding and resets, and they are usually simple by design, sometimes shared or predictable. If a temporary password is allowed to persist, it becomes a weak, possibly known credential that lingers on the account. This control requires that a temporary password be changed to a permanent one immediately upon its first use, so the temporary credential exists only long enough to let the user set their own.
Allow temporary password use for system logons with an immediate change to a permanent password.
The requirement permits temporary passwords but conditions them on an immediate change. When a user logs on with a temporary password, the system requires them to set a permanent password before proceeding, so the temporary credential cannot remain in effect. This is enforced through the account setting that flags a password as requiring change at next logon.
2The Assessment Objective
NIST SP 800-171A frames 3.5.9 as a single objective: require an immediate change from temporary to permanent.
An immediate change to a permanent password is required when a temporary password is used for system logon. Temporary passwords must be changed at first use.
The single objective is the required immediate change. The common failure is temporary passwords issued without the change-at-next-logon flag, so they linger. The assessor looks for enforcement that a temporary password is changed immediately.
3Failure Patterns
The failures are about temporary passwords that persist.
Change-at-logon not set
Where a temporary password is issued without requiring a change at next logon, it can remain in use, which is exactly what the control prevents. Setting the change-at-next-logon flag enforces the immediate change.
Shared or predictable temporary passwords left in place
Temporary passwords are often simple or shared, so if they persist they are a known weak credential. The immediate change is what keeps them from lasting.
Reset process without enforced change
A password reset process that issues a temporary password but does not force a change leaves the same gap. The process has to require the permanent change at first use.
4Ownership
This is an IT-owned technical control, delivered through account settings and the reset process.
| Role | Responsibility for this control |
|---|---|
| IT and system administrator | Issues temporary passwords with a required change at next logon and enforces it in the reset process. Owns the technical evidence. |
| Security or compliance lead | Confirms temporary passwords require an immediate permanent change. |
| Program lead | Includes the reset process in periodic review and retains the evidence. |
5Tooling
The control is delivered by the change-at-next-logon account setting.
| Objective | Tooling | What it provides |
|---|---|---|
| enforce | Change-at-next-logon flag | A required permanent password change when a temporary one is used. |
| process | Onboarding and reset procedures | Issuance of temporary passwords that must be changed immediately. |
The caveat is that the change has to be enforced by the account setting, not left to the user's initiative. The change-at-next-logon flag is what guarantees the immediate change, so it has to be set whenever a temporary password is issued. The assessor examines whether temporary passwords require an immediate change, so the enforcement has to be present in the process.
6Evidence
The satisfied version of 3.5.9 shows temporary passwords requiring an immediate change.
| Evidence | What it demonstrates |
|---|---|
| Change-at-logon configuration | The objective. Temporary passwords require a permanent change at first use. |
| Reset process documentation | The objective. The process enforces the immediate change. |
The evidence should show that temporary passwords require an immediate permanent change at first logon. The change-at-next-logon configuration and the reset process are the clearest demonstration of the control.
Temporary should never become permanent
Temporary passwords are weak by design, and if they persist they settle into the account as a lasting risk, so this control requires an immediate change at first use. Enforcing change-at-next-logon in onboarding and resets is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.5.9. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.5.9. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov