Multi-factor authentication (MFA): what the CNIL really expects
A username and password are no longer enough to protect sensitive access. The CNIL now states this clearly in its recommendations: beyond enabling MFA, you must ensure it actually covers all your user journeys. We help you deploy it where it matters, and verify that it holds up against real bypass attempts.
What is MFA?
Multi-factor authentication (MFA, or 2FA for two factors) consists of validating an identity via at least two distinct factors, among: something the user knows (password, PIN), something they have (smartphone, physical FIDO2 key, authentication app) and something they are (fingerprint, facial recognition). The objective: prevent access from being granted solely on the basis of a username and password that may have been stolen, reused or guessed.
In its March 2025 recommendation on authentication, the CNIL specifically targets sensitive data processing and remote access to user accounts: administration interfaces, customer portals, features that make it possible to modify or delete data. It announces reinforced checks from 2026, with the absence of MFA potentially being considered a breach of the security obligation under the GDPR.
Why deploy it properly?
Regulatory requirement
The CNIL treats it as a minimum expectation for access to sensitive data or remote access. Its absence may be qualified as a breach during an inspection.
Reduced account compromise risk
A password alone, even a complex one, can leak or be reused. MFA blocks the vast majority of account takeover attempts.
Customer and partner trust
Demonstrating robust authentication reassures your customers and facilitates audits by your partners and principals.
Consistency with your ISMS
MFA is a central control in an ISO 27001 ISMS and fits naturally into a certification initiative already under way.
Who is concerned?
Any organization that exposes personal or sensitive data through an online interface: customer portal, back office, business email, remote access to the information system, API. The approach primarily involves IT departments, CISOs and DPOs, but also concerns any employee with privileged access or an account exposed on the internet.
Our methodology
Ticking an “MFA” box in a back office is not enough. During our security audits, we regularly find MFA that exists but is poorly implemented: absent from certain journeys (password reset, email change, device enrolment), not covered on the API or mobile app, or vulnerable to replay of an intercepted code and to push bombing (mass sending of validation requests until a user approves by mistake or fatigue — often combined withsocial engineering).
Our approach consists of mapping all your sensitive journeys, verifying that MFA covers them all consistently, and actively testing its resistance — not merely its presence.
The 6 steps of a robust deployment
Access mapping
Identification of high-risk interfaces, accounts and features: administration, customer portals, remote access, actions to modify or delete data.
Choice of factors
Prioritise proven methods (TOTP, FIDO2 keys/Passkeys) rather than SMS, which is more exposed to interception and SIM swapping.
Coverage of all journeys
Extension of MFA to login, but also to password reset, email change, device enrolment, API and mobile app access.
Bypass testing
Active verification of resistance to code replay, push bombing and unprotected alternative journeys, as in a penetration test.
User awareness
Training teams never to approve an unsolicited MFA request, and to report any abnormal behaviour.
Monitoring & continuous improvement
Regular review of access rights, methods used and suspicious attempts, as a continuation of your compliance approach.
Why choose BCIT for support? ⚡
Beyond ticking the box
We verify that MFA really works across all your journeys, not only that it is enabled.
Integrated view
Assessment, security audit or support GDPR : MFA fits into a comprehensive approach to your access controls.
Awareness included
Teams trained in the right reflexes against bypass attempts, including push bombing and social engineering.
Ready to secure your sensitive access? 🚀
Let’s take 15 minutes to assess the real coverage of your MFA and identify the journeys that still escape this essential control.
Multi-factor authentication (MFA): what the CNIL really expects
A username and password are no longer enough to protect sensitive access. The CNIL now states this clearly in its recommendations: beyond enabling MFA, you must ensure it actually covers all your user journeys. We help you deploy it where it matters, and verify that it holds up against real bypass attempts.
What is MFA?
Multi-factor authentication (MFA, or 2FA for two factors) consists of validating an identity via at least two distinct factors, among: something the user knows (password, PIN), something they have (smartphone, physical FIDO2 key, authentication app) and something they are (fingerprint, facial recognition). The objective: prevent access from being granted solely on the basis of a username and password that may have been stolen, reused or guessed.
In its March 2025 recommendation on authentication, the CNIL specifically targets sensitive data processing and remote access to user accounts: administration interfaces, customer portals, features that make it possible to modify or delete data. It announces reinforced checks from 2026, with the absence of MFA potentially being considered a breach of the security obligation under the GDPR.
Why deploy it properly?
Regulatory requirement
The CNIL treats it as a minimum expectation for access to sensitive data or remote access. Its absence may be qualified as a breach during an inspection.
Reduced account compromise risk
A password alone, even a complex one, can leak or be reused. MFA blocks the vast majority of account takeover attempts.
Customer and partner trust
Demonstrating robust authentication reassures your customers and facilitates audits by your partners and principals.
Consistency with your ISMS
MFA is a central control in an ISO 27001 ISMS and fits naturally into a certification initiative already under way.
Who is concerned?
Any organization that exposes personal or sensitive data through an online interface: customer portal, back office, business email, remote access to the information system, API. The approach primarily involves IT departments, CISOs and DPOs, but also concerns any employee with privileged access or an account exposed on the internet.
Our methodology
Ticking an “MFA” box in a back office is not enough. During our security audits, we regularly find MFA that exists but is poorly implemented: absent from certain journeys (password reset, email change, device enrolment), not covered on the API or mobile app, or vulnerable to replay of an intercepted code and to push bombing (mass sending of validation requests until a user approves by mistake or fatigue — often combined withsocial engineering).
Our approach consists of mapping all your sensitive journeys, verifying that MFA covers them all consistently, and actively testing its resistance — not merely its presence.
The 6 steps of a robust deployment
Access mapping
Identification of high-risk interfaces, accounts and features: administration, customer portals, remote access, actions to modify or delete data.
Choice of factors
Prioritise proven methods (TOTP, FIDO2 keys/Passkeys) rather than SMS, which is more exposed to interception and SIM swapping.
Coverage of all journeys
Extension of MFA to login, but also to password reset, email change, device enrolment, API and mobile app access.
Bypass testing
Active verification of resistance to code replay, push bombing and unprotected alternative journeys, as in a penetration test.
User awareness
Training teams never to approve an unsolicited MFA request, and to report any abnormal behaviour.
Monitoring & continuous improvement
Regular review of access rights, methods used and suspicious attempts, as a continuation of your compliance approach.
Why choose BCIT for support? ⚡
Beyond ticking the box
We verify that MFA really works across all your journeys, not only that it is enabled.
Integrated view
Assessment, security audit or support GDPR : MFA fits into a comprehensive approach to your access controls.
Awareness included
Teams trained in the right reflexes against bypass attempts, including push bombing and social engineering.
Ready to secure your sensitive access? 🚀
Let’s take 15 minutes to assess the real coverage of your MFA and identify the journeys that still escape this essential control.