Multi-Factor Authentication (MFA) in OpenCCC and CCCApply
To protect your personal data, the OpenCCC/CCCApply system uses Multi-Factor Authentication (MFA). This means that even if someone steals your password, they cannot access your account without the unique security code sent directly to your private email account or mobile device.
Passwords are no longer enough [to protect our account security] because cybercriminals use automated tools and AI to steal them at scale. Multi-Factor Authentication (MFA) stops these attacks in their tracks by requiring a second layer of defense—like a code on your phone or a facial scan. Because it blocks 99% of automated account takeover attempts, global security agencies, insurance companies, and compliance regulations now recognize MFA as the mandatory foundation of modern identity protection.
MFA is a new step in the CCCApply process. To successfully submit an application you must have these in place:
an OpenCCC account that is verified through email
at least one Multi Factor Authentication method added to your OpenCCC account
identity verification through DMV Wallet, ID.me, or manual verification done with your home college admissions office
Contents
- 1 Create A New Account Using MFA
- 2 Sign In With MFA - Verified User (Happy Path)
- 3 Sign In with MFA - Unverified User
- 4 Adding a Second Method of Authentication (Mobile Number)
- 5 Setting Your Preferred Method of Contact
- 6 Recovering Your Password
- 7 Recovering Your Account with California DMV Wallet
- 8 Recovering Your Account Manually
- 9 Troubleshooting & FAQs
Create A New Account Using MFA
Account creation begins on the CCCApply Sign In page. You will create the account and then verify your account by email.
Note: If you have submitted a CCCApply application in the past, you most likely have an existing OpenCCC account. Skip to Sign In With MFA - Verified User to learn about the ways MFA will be used in the sign in process and account recovery.
Create Your Account
Pilot Testing? See the Pilot Testing. Guide for assistance.
Go to CCCApply.org and navigate to the college of your choice. Click their Apply link. The Sign In page appears.
Click Create An Account. The Create Your Account page appears.
Enter your email address and click Email My Security Code. The Verify Your Account page appears.
Retrieve the security code from your email inbox and enter it on the Verify Your Account page.
You have 10 minutes to enter the correct code and click the Verify Email button before the code expires. If the code expires, click the Resend email link to get another code.
Didn’t receive your security code? If you don’t find your security code in your inbox within a few seconds, check your All Mail, Spam and Junk folders. If you still don’t find the email, click Resend email. You are allowed three (3) security codes per sign in session. If you do not enter a valid security code successfully, you will be blocked from the system for 48 hours. For more information, see Troubleshooting and FAQs.
Click Verify Email. The Did You Know? page appears, explaining why verifying a second method of authentication, will give you more sign in options in the future.
Enter your mobile phone number in the Mobile Phone field and click Text My Security Code. This will send a new security code to your mobile phone or device. This step is optional, but it is highly recommended.
Verifying a mobile number in addition to your email address gives you two ways (factors) to request your security codes in the future.
If you have not received a text after 1 minute, click Resend Code.
Get the security code from your phone and enter it on the Security Code page.
Click Next.
Following the validation of your mobile number, the user can select which method of contact they want to receive their code from the Keep Your Account Secure page moving forward.
Complete Account Profile
After verifying your credentials, finish entering your account information on the Create Profile page. After entering all required fields, including creating your password, click Save.
After entering all required fields, including creating your unique password, click Create Account.
Verify your identity
After your account has been created, the CCC Students are Expected to Verify Their Identity page displays and you are encouraged to verify your identity using one of our two trusted vendors: CA DMV Wallet or ID.me.
You will have three options to verify your identity:
Verify Later (this will temporarily skip the verification process)
You will be taken to the CCCApply My Applications page to start a new application or resume an in-progress application.
Sign In With MFA - Verified User (Happy Path)
If you have an existing OpenCCC account, you will have already validated your email address and password when you created your account. Now, each time you sign in to CCCApply (or other OpenCCC systemwide application), you will follow this simple process using MFA:
On the CCCApply Sign In page, enter your email address and click Next.
Enter your account password on the Password page and click Sign In.
If the system locates your account, the Keep Your Account Secure page appears.
Select your preferred method for receiving your one-time security code. If your email address is the only method that’s verified, select the radio button next to your email address and click Next.
Retrieve the security code from your email. If you don’t see the email, check your All Mail, Spam, and Junk folders.
Enter the code promptly on the Security Code page and click Next. Be sure to enter the code within 10 minutes or it will expire, and you will have to request another code.
If your code is entered correctly, you will be signed in and taken to the CCCApply My Applications page to start a new application or resume an in-progress application.
To exit the My Applications page, click Sign Out in the upper right corner of the page.
Security Code Tips:
If you don’t see the code in your inbox within a few seconds, check your All Mail, Spam or Junk folders right away.
You have three tries to enter the six-digit code correctly. If for some reason the code is rejected, you can request another code by clicking the Resend Code link.
You can request three codes total per sign in session. If, however, you are unable to enter any of the three allowed codes, the system will automatically block you from further sign in attempts. If you are blocked, you can recover access to your account using the CA DMV Wallet account recovery process.
Sign In with MFA - Unverified User
The sign in flow for users who are ID verified users is described in the section above.
However, if you are signing in with MFA as an unverified user, the process includes a step to encourage you to verify your identity for security purposes (and fewer sign in steps in the future).
Step 1: Follow the Steps in the Happy Path for Verified Users Process
The sign in flow is the same for all existing users (including verified and unverified users).
Step 2: Verify Your Identity (optional, but recommended)
For unverified users, after entering your security code on the Security Code page, you are taken to the CCC Students are Expected to Verify Their Identity page, which encourages students to verify their identity using one of the two trusted vendor options: CA DMV Wallet and ID.me.
To complete the identity verification process, find step-by-step instructions for each vendor below.
Currently ID verification is not mandatory. Users may still bypass the verification process; however, there are many benefits to verifying your identity, including expedited admissions, identity security, and account recovery.
Once completed with the verification process, you will be taken automatically to the CCCApply My Applications page to start a new application or resume an in-progress application.
To exit, click Sign Out in the upper right corner of the page.
Adding a Second Method of Authentication (Mobile Number)
Adding a mobile phone number as a second method of authentication greatly increases the security of your personal information and expedites the sign in and account self-recovery workflows.
Sign in to CCCApply using MFA.
From the My Applications page, select Edit My Account from the Account Information section, or select Edit Account from the Settings link in the main menu.
On the Edit Account screen, add or update your mobile number in the Phone field and ensure the Phone Type field is set to Mobile. Phone numbers set to “Landline” cannot be used for MFA or as your preferred method of contact. Once your mobile number is entered, click the Update button at the bottom of the page to save your changes.
For more information, see the Setting Your Preferred Method of Contact section below.
On the CCCApply Sign In page, enter your mobile phone number in the Email or mobile phone input field. Click Next.
Enter your password, then click Sign In.
On the Keep Your Account Secure page, select your mobile phone number from the list of contact methods, then click Next.
Retrieve your code from you mobile phone or device and enter it in the Enter Security Code field. Click Next.
Benefits of using a Mobile Number: If you didn’t choose to provide a mobile number during the first step of account creation, you can add that information here on the Create Profile page before saving your new account at the bottom of the page. You’ll receive a security code on your mobile phone and then enter it on the Security Code page that appears.
Note: After verifying your mobile number, you can select which method of contact you want to receive you code from the Keep Your Account Secure page.
Setting Your Preferred Method of Contact
Setting your preferred method of contact in the Edit Account page lets you which way you prefer to receive security codes, notifications, and other SMS messages regarding your account.
Steps:
On the Edit Account page, ensure that both your mobile phone and email address are entered correctly. For your mobile number, ensure the Phone Type field is set to Mobile.
Choose your preferred method by clicking the Make Preferred button; there is one under each credential type.
Scroll to the bottom of the Edit Account page and click Update.
If needed, repeat the steps to verify your preferred credential using MFA.
Recovering Your Account Using MFA
If you have an existing OpenCCC account that you are unable to log into, please do not create a new account. This could delay your objective including submitting or resuming a CCCApply application. Several options are available to help you self-recover your credentials and get back moving forward without contacting the Helpdesk support.
Recovering Your Password
The Forgot your password? process works great for users who still have access to their email address but have simply forgotten their password.
Get Your Security Code
From the Sign In page, enter your email address, then click Next.
On the Password page, click Forgot your password? and click Next. The Keep Your Account Secure page appears.
Select a contact method and click Next. You will receive a message containing a security code that you will input on the next step.
Retrieve your code from your email inbox, then enter it in the Security Code field.
Change Your Password
After verifying your security code, the Update Password page appears. Users are then required to create and verify a new password.
Enter a string of letters, numbers, and special characters into the Password input field. The combination must meet the criteria requirements listed on the left, next to the input fields.
Re-enter the password in the Confirm Password field to ensure it matches the Password field exactly (both fields must match).
Click the Submit button to validate your password.
Reminder: The password you choose must meet the following security requirements:
be at least 8 characters in length
contain at least one uppercase letter
contain at least one lowercase letter
contain at least one number
contain at least one of the following special characters ( !, @, #, $, %, ^, &, or *)
must NOT contain your name
Password Security: If your updated password meets the required criteria, the “Password must” box will display solid green, as shown in the screenshot below.
If your old email is still accessible, we can send a reset link. But if not, and you are a California resident, try the CA DMV Wallet option for account recovery and identity verification.
Recovering Your Account with California DMV Wallet
If you have forgotten your email address and/or password, the first step towards account self-recovery using MFA begins with the Forgot your password? process on the Sign In page without entering your email address.
If you are a California resident, we recommend choosing the CA DMV Wallet option for fastest account recovery and identity verification.
From the CCCApply Sign In page, click the Forgot your password? link without entering an email address. The Recover Your Account page appears.
Click on the Verify with DMV Wallet button to start the CA DMV Wallet process.
Follow the steps outlined here in Verify using the CA DMV Wallet and keep in mind the following requirements:
You will be required to download the CA DMV Wallet app to a smartphone or desktop (smartphone is recommended).
You will be required to scan a QR code and receive a security code from the DMV.
Using the CA DMV Wallet to recover your account credentials also requires that you verify your identity through the CA DMV’s verification service. This not only helps you regain your sign in credentials easily, it verifies your identity for the CCC system.
Recovering Your Account Manually
If you have forgotten your email address and/or password, the first step towards account self-recovery using MFA begins with the Forgot your password? process on the Sign In page without entering your email address.
If you are a NOT a California resident, we recommend using this manual option to locate your account and recover your credentials.
Step 1: Click the Forgot your password? link on the Sign In page
From the CCCApply Sign In page, select the Forgot your password? link without entering an email address. The Recover Your Account page appears.
Click on the Recover Manually button to start finding your account.
Follow the screen prompts to enter locate your account manually by entering personal information used to create your account.
Troubleshooting & FAQs
Issue | Solution |
|---|---|
Security code didn’t arrive (Email) | Check your Spam/Junk and All Mail folders first before requesting a new code. Ensure no-reply@cccmypath.org is on your safe-sender list. |
Security code didn’t arrive (mobile device/SMS) | Ensure you have cellular signal. If you are using a VoIP number (like Google Voice), some carriers may block these messages. If you’re having trouble, try using your email address instead. |
Security code doesn’t work | Security codes expire after 10 minutes. If your code expired, click Resend Code. |
Too many attempts entering a security code | Each security code permits three input attempts. After the third try, the security code expires. |
Email address isn’t working | If your email address is not working for signing in, refresh the page and then (without entering anything in the Email address or mobile number input field) click the Forgot your password? link and select a self-recovery option. |
Mobile number isn’t working | If your mobile phone number is saved in your account. sign in with your email address and navigate to the Settings > Edit Account link in your CCCApply My Applications page. Add or update the mobile number, set the Phone Type to Mobile. and save your changes. |
Password isn’t working | User should follow the Forgot Password? link on CCCApply or OpenCCC Sign In page. |
Email address changed by user | You must log in using your Email MFA first, then navigate to settings to update your mobile number. |
No longer has access to original Email account | If you have a mobile phone number saved and verified in your account, use your mobile number for sign in. If you don’t have a mobile number saved, refresh the page and then (without entering anything in the Email address or mobile number input field) click the Forgot your password? link and select a self-recovery option. |
Mobile number changed by user | You must log in using your Email MFA first, then navigate to settings to update your mobile number. |
No longer has mobile number | You may recover your account using one of these methods: |
Received “Important: Your CCCApply Account Information was Changed” message | Possible spam/fraud activity (bad actor). If you receive this auto-message, it’s because a change was made to one of your contact methods. If you did make the change, ignore the message. If you did NOT make the change, please reach out to CCC Staff Support to report the activity. The message contains directions and links to help update your information. |
Security Best Practices
Never share your security code: Support staff will never ask you for your MFA code over the phone or via email.
Report unauthorized codes: If you receive an MFA code via text or email when you are not trying to sign in, someone may have your password. Change your password immediately.
If you complete the account recovery process and see any applications or other information that you do not recognize, please reach out to our CCC Staff Support team to report potential fraudulent activity.
