Two memorandums issued in January set binding timelines for multi-factor authentication (MFA) across federal agencies. The National Security Memorandum from January 19 gives National Security Systems (NSS) 180 days to adopt MFA. The Office of Management and Budget memorandum from January 26 requires all agencies to achieve zero trust security goals by FY2024, with MFA integration as a foundational requirement.
These aren't aspirational targets. They're compliance deadlines that will determine whether your agency meets federal cybersecurity baselines.
What the Mandates Require
The January directives build on Executive Order 14028 by extending zero trust requirements across the federal enterprise. Here's what changed:
National Security Systems face a hard 180-day clock. From January 19, NSS organizations must deploy MFA across their environments. This timeline compresses implementation cycles that typically span 12-18 months into six months.
All agencies must reach zero trust maturity by FY2024. The OMB memorandum treats MFA not as an optional enhancement but as a critical part of the government's security baseline. You can't claim zero trust compliance without it.
The scope extends beyond user authentication. While the mandates emphasize MFA for human access, zero trust architecture requires identity verification for every access request, including Non-Person Entity authentication for service accounts and system-to-system communications.
These requirements align with NIST SP 800-207 (Zero Trust Architecture), which defines identity as the primary security perimeter. Without MFA protecting that perimeter, your zero trust implementation fails at the foundation.
Five Implementation Priorities
Your agency likely manages hundreds of applications and systems. Attempting simultaneous MFA rollout across all of them will overwhelm your team and frustrate users. Here's how to sequence the work:
1. Protect Single Sign-On first. If you operate an SSO platform, integrating MFA there protects every downstream application in one implementation cycle. This approach delivers immediate coverage across your application portfolio while giving your team experience with your chosen MFA solution before tackling more complex integrations.
2. Secure remote access immediately after SSO. Virtual private networks remain a primary attack vector. Multiple breaches start with compromised VPN credentials. Implementing MFA for VPN access, or better, replacing VPN with Zero Trust Network Access solutions, addresses one of your highest-risk exposure points. This step satisfies the zero trust principle of "never trust, always verify" for remote connections.
3. Use FIDO2-enabled mobile authentication instead of physical tokens. Physical token programs create logistics nightmares: procurement delays, distribution tracking, replacement workflows, and helpdesk burden. Your users already carry mobile devices. FIDO2-based push authentication to these devices simplifies enrollment, reduces friction, and improves security posture compared to legacy one-time password tokens. Reserve physical tokens for specialized use cases where mobile devices can't be used.
4. Prioritize by criticality after initial wins. Once SSO and VPN are protected, assess remaining systems by risk. Protect applications handling Controlled Unclassified Information first. Then secure administrative interfaces for infrastructure systems. Finally, extend MFA to lower-risk applications. This risk-based sequencing ensures your most sensitive assets receive protection first if you hit timeline constraints.
5. Integrate MFA training into existing security awareness programs. Don't launch MFA as a standalone initiative requiring separate training sessions. Fold MFA instruction into your regular cybersecurity awareness cadence. This approach prevents training fatigue and positions MFA as a normal security control rather than a special project.
What This Means for Your Team
Your FY2024 budget cycle must account for MFA implementation costs now. If you haven't allocated resources for MFA solutions, user training, and integration labor, your timeline is already compressed. The mandate doesn't provide funding, but it does create an unfunded requirement you must satisfy.
Your Identity, Credential, and Access Management architecture needs immediate assessment. MFA doesn't work effectively without strong Identity Management systems linking authenticated users to access policies. If your IdM solution is outdated or poorly integrated, you'll struggle to enforce consistent access controls even after deploying MFA. Consider parallel investment in IdM infrastructure.
Your Risk Management Framework authorization packages must reflect MFA implementation status. NIST SP 800-53 Rev 5 control IA-2 (Identification and Authentication) requires multi-factor authentication for privileged accounts and network access. Your system security plans and authorization documentation must demonstrate MFA coverage. Gaps become findings during assessments.
Your vendor relationships need review. If you rely on cloud service providers or managed service providers, verify their MFA capabilities support FIDO2 standards and integrate with your chosen authentication platform. Legacy providers offering only SMS-based authentication don't satisfy modern Authenticator Assurance Level requirements.
Action Items by Priority
Immediate (next 30 days):
- Inventory all applications and systems requiring MFA integration
- Select an MFA solution supporting FIDO2 standards and mobile push authentication
- Implement MFA for your SSO platform
- Brief leadership on timeline, resource requirements, and risks
Short-term (30-90 days):
- Deploy MFA for VPN or migrate to Zero Trust Network Access
- Establish user enrollment workflows and helpdesk procedures
- Integrate MFA training into scheduled security awareness sessions
- Begin risk-based prioritization of remaining systems
Medium-term (90-180 days):
- Complete MFA integration for CUI-handling applications
- Extend MFA to administrative interfaces
- Assess IdM architecture and plan necessary upgrades
- Update RMF authorization packages with MFA implementation evidence
Ongoing:
- Monitor MFA adoption rates and address user friction points
- Review authentication logs for anomalies
- Maintain FIDO2 authenticator inventory
- Align MFA deployment with zero trust maturity model progression



