Cybersecurity GRC 16 items
Multi-Factor Authentication (MFA) Rollout Readiness
Guides planning and execution of an enterprise MFA rollout, covering scoping, authenticator selection, deployment, and support to maximize coverage and phishing resistance.
NIST 800-63BCIS v8NIST 800-53
Free PDF · enter your email to download.
Scope & Planning
- Are all applications and access points requiring MFA inventoried and prioritized? *
- Is MFA prioritized first for remote access, privileged accounts, and email? *
- Are legacy authentication protocols that bypass MFA identified for blocking? *
- Is an authentication assurance level (AAL) target defined?
Authenticator Selection
- Are phishing-resistant authenticators (FIDO2/WebAuthn, PIV) chosen for privileged users? *
- Is SMS/voice OTP avoided as a primary factor where stronger options exist? *
- Are backup/recovery methods defined that do not weaken assurance? *
- Is number-matching or push-fatigue protection enabled for push-based MFA?
Deployment & Enforcement
- Is a phased rollout plan (pilot then broad) defined with rollback criteria? *
- Are conditional access / risk-based policies configured to enforce MFA? *
- Is enrollment tracked with a target coverage metric?
- Are legacy auth protocols blocked once MFA coverage is confirmed? *
Support & Sustainment
- Is a secure account-recovery and lost-authenticator process documented for the help desk? *
- Is the help desk trained to resist social-engineering during MFA resets? *
- Are MFA bypass exceptions documented, time-limited, and reviewed?
- Is user communication and training provided ahead of enforcement?
Download the full Multi-Factor Authentication (MFA) Rollout Readiness checklist
Get it as a clean, printable PDF — free.
