# IA-05 Authenticator Management — NIST 800-53 Rev5 control

> FedRAMP Consolidated Rules for 2026 v2026.07.14.01 · updated 2026-07-14
> Canonical page: /control/ia-5

Canonical id: `ia-5` · family `IA`

> Manage system authenticators by: a. Verifying, as part of the initial authenticator distribution, the identity of the individual, group, role, service, or device receiving the authenticator; b. Establishing initial authenticator content for any authenticators issued by the organization; c. Ensuring that authenticators have sufficient strength of mechanism for their intended use; d. Establishing and implementing administrative procedures for initial authenticator distribution, for lost or compromised or damaged authenticators, and for revoking authenticators; e. Changing default authenticators prior to first use; f. Changing or refreshing authenticators [time period by authenticator type] or when [events] occur; g. Protecting authenticator content from unauthorized disclosure and modification; h. Requiring individuals to take, and having devices implement, specific controls to protect authenticators; and i. Changing authenticators for group or role accounts when membership to those accounts changes.

_Control title and statement: NIST SP 800-53 Rev5 catalog (the pinned commit is in `/api` under `control_text`). The FedRAMP rules reference these controls by id only; everything below is what FedRAMP says about this id._

## Rev5 baseline membership

- certification class B (in the annual independent assessment)
- certification class C (in the annual independent assessment)
- certification class D (in the annual independent assessment)

## Key Security Indicators that reach it

- `KSI-IAM-APM` — Adopting Passwordless Methods (Identity and Access Management)
  Secure passwordless methods are used for user authentication and authorization when feasible, otherwise strong passwords with phishing-resistant MFA is used.

## FedRAMP guidance

{
  "varies_by_class": {
    "b": {
      "guidance": [
        "Authenticators must be compliant with the most recent NIST Digital Identity Guidelines IAL, AAL, FAL level 1.",
        "IA-5 Guidance: FedRAMP requires that authentication assertions be encrypted when passed through third parties, such as a browser. For example, a SAML assertion can be encrypted using XML-Encryption, or an OpenID Connect ID Token can be encrypted using JSON Web Encryption (JWE)."
      ]
    },
    "c": {
      "guidance": [
        "Authenticators must be compliant with the most recent NIST Digital Identity Guidelines IAL, AAL, FAL level 2.",
        "IA-5 Guidance: FedRAMP requires that authentication assertions be encrypted when passed through third parties, such as a browser. For example, a SAML assertion can be encrypted using XML-Encryption, or an OpenID Connect ID Token can be encrypted using JSON Web Encryption (JWE)."
      ]
    },
    "d": {
      "guidance": [
        "Authenticators must be compliant with the most recent NIST Digital Identity Guidelines IAL, AAL, FAL level 3.",
        "IA-5 Guidance: FedRAMP requires that authentication assertions be encrypted when passed through third parties, such as a browser. For example, a SAML assertion can be encrypted using XML-Encryption, or an OpenID Connect ID Token can be encrypted using JSON Web Encryption (JWE)."
      ]
    }
  },
  "updated": [
    {
      "date": "2026-07-14",
      "comment": "Update guidance to direct users to the latest NIST Digital Identity Guidelines and remove references to specific instances of SP 800-63."
    }
  ]
}

## Annual independent assessment

In the annual assessment subset for class B, C, D.
