Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · OT cybersecurity

Multifactor authentication (MFA)

Also known as: MFA, Multi-factor authentication, Two-factor authentication (2FA)

German: Mehrfaktor-Authentifizierung (MFA)

In access control, multifactor authentication (MFA) is authentication that requires two or more independent factors from different categories: something the user knows (password, PIN), something the user has (token, smart card, phone) or something the user is (biometric characteristic).

  • OT security

In one sentence

Multifactor authentication (MFA) requires two or more independent factors, such as a password plus a hardware token, before access is granted.

Example

Service technicians connecting to the plant's remote access gateway must enter their password and confirm the login with a hardware token.

How it applies

  • Engineering: MFA is most important where attacks are most likely: Secure remote access, jump servers, administrative accounts and access from the enterprise network into OT. IEC 62443-3-3 calls for multifactor authentication at higher security levels, especially for access across untrusted networks.
  • Operation: On the shop floor, MFA must not block urgent actions. Local HMI operation often relies on physical access control plus badges instead of phone-based factors, which may be unavailable in production areas.
  • Compliance: NIS 2 lists multi-factor authentication among the risk-management measures to be used where appropriate.
  • Documentation: Documentation for remote access and engineering tools should explain how MFA is enrolled, what to do if a token is lost, and how emergency access works without weakening security.

MFA vs. two-step verification

True MFA uses factors from different categories. Two passwords, or a password plus a security question, are two steps but only one factor category.

By knowledge.aitechdoc.world · Published September 26, 2026 · Last reviewed

Source: AI TechDoc Knowledge editorial definition, based on NIST SP 800-63B and IEC 62443-3-3

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Knowledge and are not part of any standard.

Seen a mistake? Send us a note!