DIBStack
All resources

What Counts as MFA Evidence? A Checklist for Small DIB Teams

Multi-factor authentication is one thing to turn on and another thing to prove. Here's the evidence a small DIB team gathers to show MFA is in place.

Turning it on vs. proving it

Enabling multi-factor authentication (MFA) is the easy part. Showing — months later — that it is enforced everywhere it should be is where small DIB teams get tripped up. This article is a generic, educational checklist of the evidence you might gather to organize proof that MFA is in place.

It does not determine whether your specific configuration meets any requirement; it just helps you collect and keep the proof. Map it to the requirements that apply to your organization.

Evidence to gather

For a small team, MFA evidence is usually a handful of dated captures and records:

  • A setting or report showing MFA is required for users.
  • Evidence MFA is enforced for remote access / VPN.
  • Evidence MFA is enforced for privileged / administrator accounts — the highest-value targets.
  • Evidence MFA is enforced for cloud email and file services.
  • A record of any accounts exempt from MFA, with the reason.
  • The date each piece of evidence was captured.

A few habits that help

  • Date everything. A screenshot with no date does not show what is true today. Use a sortable name like 2026-06-15_mfa-enforced.png.
  • Capture the privileged accounts specifically. “MFA is on” is weaker than “MFA is enforced for every admin account, here’s the proof.”
  • Note the exceptions. If a service account can’t do MFA, record it and how you compensate — gaps you acknowledge are stronger than gaps you hide.
  • Give it an owner. Someone should be responsible for re-capturing this on a cadence.

Where it fits

MFA evidence lives in your evidence structure (an 04_MFA folder works well) alongside your access records and user inventory. Together they answer: who can sign in, and how do we know access is protected? For how this fits the bigger picture, see building a CMMC evidence checklist.

A ready checklist

You can track this in a simple list. If you would rather start from a standardized one — with owner and storage columns already laid out — the DIBStack Evidence Binder includes an MFA evidence checklist. It helps you organize the proof; it does not evaluate or score your configuration.

Related product

DIBStack Evidence Binder

Folder structures, evidence checklists, workbooks, logs, and templates for organizing cybersecurity evidence.

View DIBStack Evidence Binder