Example, read only. A sample account that shows what finished CMMC looks like.
Safeguard 6 of 15 · IA.L1-b.1.vi
IA.L1-3.5.2 · FAR 52.204-21 (b)(1)(vi) · NIST SP 800-171 3.5.2
Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems
Before letting anyone into your systems, verify they are who they say they are, typically a password plus a second factor (MFA).
This is the control primes scrutinize most. Password-only access is a near-automatic rejection in 2026. MFA on all admin accounts is the floor.
Capture: Two screenshots: (1) the Conditional Access policy or Security Defaults page showing MFA is on, (2) the user list showing MFA enforced per account.
Every file is checked by Charlie the moment it is uploaded, so a gap is caught on the spot, not at the assessment.
All accounts require a password meeting the company policy plus multi factor authentication through Microsoft Authenticator. MFA is enforced by a Conditional Access policy for every user in the tenant, verified in the admin center screenshot on file.
You answer in plain English; Charlie writes the official narrative for your System Security Plan.
This is one of 15
Cedar Ridge Machine Works, LLC walked all 15 the same way. The platform explains each one in plain English, tells you exactly what to grab, checks it, and writes the paperwork, and you confirm each one MET. The self assessment stays your act. Start free, or book a call.