CMMC Level 2 maps directly to the 110 security controls in NIST 800-171, and authentication is addressed across both the Identification and Authentication and the Access Control practice families. The IA domain focuses on verifying who is permitted to access your systems. The AC domain governs what those authenticated users are allowed to do once inside. Together, these practice families define the framework your assessor will use when reviewing whether your MFA compliance actually protects CUI the way the standard requires.
For Level 2 certification, your MFA compliance posture has to hold across the full scope of your CMMC environment. That scope includes every system, application, and network segment where CUI is processed, stored, or transmitted, not just cloud-based services or VPN entry points, but on-premise systems, endpoints, and administrative interfaces that could provide indirect access to CUI. Understanding the real boundary of your environment is the foundational step before you can confirm that your authentication controls actually cover everything they need to.