STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← All Controls

IA-8 (2)

Identification and AuthenticationRev 5system

Acceptance of External Authenticators

Baselines:LowModerateHigh

Control Statement

(a) Accept only external authenticators that are NIST-compliant; and (b) Document and maintain a list of accepted external authenticators.

Supplemental Guidance

Acceptance of only NIST-compliant external authenticators applies to organizational systems that are accessible to the public (e.g., public-facing websites). External authenticators are issued by nonfederal government entities and are compliant with [SP 800-63B](#e59c5a7c-8b1f-49ca-8de0-6ee0882180ce) . Approved external authenticators meet or exceed the minimum Federal Government-wide technical, security, privacy, and organizational maturity requirements. Meeting or exceeding Federal requirements allows Federal Government relying parties to trust external authenticators in connection with an authentication transaction at a specified authenticator assurance level.

CCI Identifiers (3)

CCI-002011The information system accepts FICAM-approved third-party credentials.CCI-004083Accept only external credentials that are NIST compliant.CCI-004084Document and maintain a list of accepted external authenticators.

Linked STIG Checks (17)

Across 16 STIGs. Click to expand.