What Counts as MFA Evidence? A Checklist for Small DIB Teams
Multi-factor authentication is one thing to turn on and another thing to prove. Here's the evidence a small DIB team gathers to show MFA is in place.
Turning it on vs. proving it
Enabling multi-factor authentication (MFA) is the easy part. Showing — months later — that it is enforced everywhere it should be is where small DIB teams get tripped up. This article is a generic, educational checklist of the evidence you might gather to organize proof that MFA is in place.
It does not determine whether your specific configuration meets any requirement; it just helps you collect and keep the proof. Map it to the requirements that apply to your organization.
Evidence to gather
For a small team, MFA evidence is usually a handful of dated captures and records:
- A setting or report showing MFA is required for users.
- Evidence MFA is enforced for remote access / VPN.
- Evidence MFA is enforced for privileged / administrator accounts — the highest-value targets.
- Evidence MFA is enforced for cloud email and file services.
- A record of any accounts exempt from MFA, with the reason.
- The date each piece of evidence was captured.
A few habits that help
- Date everything. A screenshot with no date does not show what is true today. Use a sortable name like
2026-06-15_mfa-enforced.png. - Capture the privileged accounts specifically. “MFA is on” is weaker than “MFA is enforced for every admin account, here’s the proof.”
- Note the exceptions. If a service account can’t do MFA, record it and how you compensate — gaps you acknowledge are stronger than gaps you hide.
- Give it an owner. Someone should be responsible for re-capturing this on a cadence.
Where it fits
MFA evidence lives in your evidence structure (an 04_MFA folder works well) alongside your access records and user inventory. Together they answer: who can sign in, and how do we know access is protected? For how this fits the bigger picture, see building a CMMC evidence checklist.
A ready checklist
You can track this in a simple list. If you would rather start from a standardized one — with owner and storage columns already laid out — the DIBStack Evidence Binder includes an MFA evidence checklist. It helps you organize the proof; it does not evaluate or score your configuration.
Related product
DIBStack Evidence Binder
Folder structures, evidence checklists, workbooks, logs, and templates for organizing cybersecurity evidence.
View DIBStack Evidence Binder