GovRAMP releases guidance on phishing-resistant MFA compliance requirements
Original title: Download Resource: Achieving Compliance for MFA in GovRAMP Rev. 5
GovRAMP has released comprehensive guidance to help Service Providers understand and implement phishing-resistant MFA requirements under GovRAMP Rev. 5. The guidance clarifies which authentication methods meet the phishing-resistance requirement and which do not. Service Providers must ensure their MFA implementations align with these requirements to maintain GovRAMP compliance. This guidance supports implementation of NIST 800-53 controls related to multi-factor authentication.
What changed
- GovRAMP Rev. 5 introduces explicit phishing-resistant MFA requirements for Service Providers
- Detailed guidance document published clarifying which authentication methods satisfy the phishing-resistance requirement
- Authentication method assessment criteria provided to distinguish phishing-resistant from non-phishing-resistant MFA solutions
What the document requires
GovRAMP Rev. 5 requires Service Providers to implement phishing-resistant multi-factor authentication methods.
Who is affected
GovRAMP Service Providers offering cloud services to U.S. government agencies
Summary generated by a language model; the official text prevails. Not legal advice.