# IA-05 (01) Password-based Authentication — NIST 800-53 Rev5 control

> FedRAMP Consolidated Rules for 2026 v2026.07.14.01 · updated 2026-07-14
> Canonical page: /control/ia-5.1

Canonical id: `ia-5.1` · family `IA`

> For password-based authentication: (a) Maintain a list of commonly-used, expected, or compromised passwords and update the list [frequency] and when organizational passwords are suspected to have been compromised directly or indirectly; (b) Verify, when users create or update passwords, that the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5(1)(a); (c) Transmit passwords only over cryptographically-protected channels; (d) Store passwords using an approved salted key derivation function, preferably using a keyed hash; (e) Require immediate selection of a new password upon account recovery; (f) Allow user selection of long passwords and passphrases, including spaces and all printable characters; (g) Employ automated tools to assist the user in selecting strong password authenticators; and (h) Enforce the following composition and complexity rules: [composition and complexity rules].

_Control title and statement: NIST SP 800-53 Rev5 catalog (the pinned commit is in `/api` under `control_text`). The FedRAMP rules reference these controls by id only; everything below is what FedRAMP says about this id._

## Rev5 baseline membership

- certification class B
- certification class C
- certification class D

## Key Security Indicators that reach it

- `KSI-IAM-APM` — Adopting Passwordless Methods (Identity and Access Management)
  Secure passwordless methods are used for user authentication and authorization when feasible, otherwise strong passwords with phishing-resistant MFA is used.

## FedRAMP guidance

_No FedRAMP-specific guidance attaches to this control._
