GovRAMP releases guidance on phishing-resistant MFA compliance requirements

Original title: Download Resource: Achieving Compliance for MFA in GovRAMP Rev. 5

GovRAMP has released comprehensive guidance to help Service Providers understand and implement phishing-resistant MFA requirements under GovRAMP Rev. 5. The guidance clarifies which authentication methods meet the phishing-resistance requirement and which do not. Service Providers must ensure their MFA implementations align with these requirements to maintain GovRAMP compliance. This guidance supports implementation of NIST 800-53 controls related to multi-factor authentication.

What changed

  • GovRAMP Rev. 5 introduces explicit phishing-resistant MFA requirements for Service Providers
  • Detailed guidance document published clarifying which authentication methods satisfy the phishing-resistance requirement
  • Authentication method assessment criteria provided to distinguish phishing-resistant from non-phishing-resistant MFA solutions

What the document requires

GovRAMP Rev. 5 requires Service Providers to implement phishing-resistant multi-factor authentication methods.

Who is affected

GovRAMP Service Providers offering cloud services to U.S. government agencies

Summary generated by a language model; the official text prevails. Not legal advice.