Multi-factor authentication — mandatory
Every user on Bedrock CMMC is required to use MFA — no exceptions. Customers, administrators, and external assessors all authenticate with TOTP from any standard authenticator app. Infrastructure access through IAM Identity Center also requires MFA. We do not support SMS as a sole MFA factor due to known SIM-swapping vulnerabilities.
Compromised passwords are the leading cause of unauthorized access. MFA ensures that even if a password is stolen, an attacker cannot access the platform without physical possession of the user's authentication device.