# IA-02 (08) Access to Accounts — Replay Resistant — NIST 800-53 Rev5 control

> FedRAMP Consolidated Rules for 2026 v2026.07.14.01 · updated 2026-07-14
> Canonical page: /control/ia-2.8

Canonical id: `ia-2.8` · family `IA`

> Implement replay-resistant authentication mechanisms for access to [assignment].

_Control title and statement: NIST SP 800-53 Rev5 catalog (the pinned commit is in `/api` under `control_text`). The FedRAMP rules reference these controls by id only; everything below is what FedRAMP says about this id._

## Rev5 baseline membership

- certification class B (in the annual independent assessment)
- certification class C (in the annual independent assessment)
- certification class D (in the annual independent assessment)

## Key Security Indicators that reach it

- `KSI-IAM-APM` — Adopting Passwordless Methods (Identity and Access Management)
  Secure passwordless methods are used for user authentication and authorization when feasible, otherwise strong passwords with phishing-resistant MFA is used.

## FedRAMP guidance

{
  "parameters": [
    {
      "parameterId": "ia-02.08_odp",
      "value": "privileged accounts; non-privileged accounts"
    }
  ]
}

## Annual independent assessment

In the annual assessment subset for class B, C, D.
