48 CFR 1252.239-81
1252.239-81 Cloud Identification and Authentication (Organizational Users) Multi-Factor Authentication.
United States · 48 CFR — Federal Acquisition Regulations System · Status: effective
Cite this
- Citation
- 48 CFR 1252.239-81, 1252.239-81 Cloud Identification and Authentication (Organizational Users) Multi-Factor Authentication, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/249148
- Permanent ID
ys:prov:249148@1- SHA-256
50495e1b63a60ec85f9d9d4316beb607c8a2adabf366980ed24763ec4bf3b0ec
The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.
Full text
As prescribed in 1239.7204(f), insert the following clause:
The Contractor shall support a secure, multi-factor method of remote authentication and authorization to identified Government Administrators that will allow Government-designated personnel the ability to perform management duties on the system. The Contractor shall support multi-factor authentication in accordance with National Institute of Standards and Technology (NIST) Federal Information Processing Standards (FIPS) Publication (PUB) Number 201-2, Personal Identity Verification (PIV) of Federal Employees and Contractors, and OMB implementation guidance for personal identity verification.
Legislative history
This is a federal regulation, adopted through agency rulemaking under the Administrative Procedure Act — not enacted by a recorded vote of Congress.