Multi-Factor Authentication (MFA) in OpenCCC and CCCApply

California Community College logo

Multi-Factor Authentication (MFA) in OpenCCC and CCCApply

To protect your personal data, the OpenCCC/CCCApply system uses Multi-Factor Authentication (MFA). This means that even if someone steals your password, they cannot access your account without the unique security code sent directly to your private email account or mobile device.

Passwords are no longer enough [to protect our account security] because cybercriminals use automated tools and AI to steal them at scale. Multi-Factor Authentication (MFA) stops these attacks in their tracks by requiring a second layer of defense—like a code on your phone or a facial scan. Because it blocks 99% of automated account takeover attempts, global security agencies, insurance companies, and compliance regulations now recognize MFA as the mandatory foundation of modern identity protection.

MFA is a new step in the CCCApply process. To successfully submit an application you must have these in place:

  • an OpenCCC account that is verified through email

  • at least one Multi Factor Authentication method added to your OpenCCC account

  • identity verification through DMV Wallet, ID.me, or manual verification done with your home college admissions office

Shows these steps - 1. Access account. 2. Add MFA options. 3. Verifiy account. 4. Verify identity.
Required Elements for OpenCCC

Contents


Create A New Account Using MFA

Account creation begins on the CCCApply Sign In page. You will create the account and then verify your account by email.

Steps showing 1. Create Account. 2. Retrieve security code. 3. Enter security code. 4. Account verified by Email.
Verifying Your OpenCCC Account with Email

Note: If you have submitted a CCCApply application in the past, you most likely have an existing OpenCCC account. Skip to Sign In With MFA - Verified User to learn about the ways MFA will be used in the sign in process and account recovery.

Create Your Account

Pilot Testing? See the Pilot Testing. Guide for assistance.

  1. Go to CCCApply.org and navigate to the college of your choice. Click their Apply link. The Sign In page appears.

Sign in page with Create an Account link displayed.
Sign In Screen
  1. Click Create An Account. The Create Your Account page appears.

Create Your Account page with the email field and Email My Security Code button.
Create Your Account Screen
  1. Enter your email address and click Email My Security Code. The Verify Your Account page appears.

Verify your account page with the Security Code field.
Verify Your Account Screen
  1. Retrieve the security code from your email inbox and enter it on the Verify Your Account page.

You have 10 minutes to enter the correct code and click the Verify Email button before the code expires. If the code expires, click the Resend email link to get another code.

Didn’t receive your security code? If you don’t find your security code in your inbox within a few seconds, check your All Mail, Spam and Junk folders. If you still don’t find the email, click Resend email. You are allowed three (3) security codes per sign in session. If you do not enter a valid security code successfully, you will be blocked from the system for 48 hours. For more information, see Troubleshooting and FAQs.

  1. Click Verify Email. The Did You Know? page appears, explaining why verifying a second method of authentication, will give you more sign in options in the future.

Did you know page with the Mobile Phone field.
Add Additional MFA Screen
  1. Enter your mobile phone number in the Mobile Phone field and click Text My Security Code. This will send a new security code to your mobile phone or device. This step is optional, but it is highly recommended.

Verifying a mobile number in addition to your email address gives you two ways (factors) to request your security codes in the future.

  1. If you have not received a text after 1 minute, click Resend Code.

  2. Get the security code from your phone and enter it on the Security Code page.

  3. Click Next.

Security code page with Enter Security Code field.
Security Code Prompt

Following the validation of your mobile number, the user can select which method of contact they want to receive their code from the Keep Your Account Secure page moving forward.  

Complete Account Profile

  1. After verifying your credentials, finish entering your account information on the Create Profile page. After entering all required fields, including creating your password, click Save.

Create Profile page with fields for email address and primary phone number.
Create Profile Screen
  1. After entering all required fields, including creating your unique password, click Create Account.

Create-PW.png
Set Your Password Screen

Verify your identity 

  1. After your account has been created, the CCC Students are Expected to Verify Their Identity page displays and you are encouraged to verify your identity using one of our two trusted vendors: CA DMV Wallet or ID.me.  

Verification page showing the option to use DMV Wallet or ID.me to verify your account.
ID Verification Options
  1. You will have three options to verify your identity:

    1. Verify using the CA DMV Wallet

    2. Verify using ID.me

    3. Verify Later (this will temporarily skip the verification process)

You will be taken to the CCCApply My Applications page to start a new application or resume an in-progress application. 


Sign In With MFA - Verified User (Happy Path)

If you have an existing OpenCCC account, you will have already validated your email address and password when you created your account. Now, each time you sign in to CCCApply (or other OpenCCC systemwide application), you will follow this simple process using MFA:

1. Sign in to Openccc. 2. Retrieve Security Code. 3. Enter Code. 4. Proceed with application.
MFA Process
  1. On the CCCApply Sign In page, enter your email address and click Next.

  2. Enter your account password on the Password page and click Sign In

Sign in page with Email or mobile phone field displayed.
Sign In Screen
  1. If the system locates your account, the Keep Your Account Secure page appears.

  2. Select your preferred method for receiving your one-time security code. If your email address is the only method that’s verified, select the radio button next to your email address and click Next.  

MFA selection page with radio buttons for Email and Helpdesk.
Select Contact Method Screen
  1. Retrieve the security code from your email. If you don’t see the email, check your All Mail, Spam, and Junk folders.

  2. Enter the code promptly on the Security Code page and click Next. Be sure to enter the code within 10 minutes or it will expire, and you will have to request another code. 

Security Code page with the Security Code field.
Security Code Screen
  1. If your code is entered correctly, you will be signed in and taken to the CCCApply My Applications page to start a new application or resume an in-progress application. 

  2. To exit the My Applications page, click Sign Out in the upper right corner of the page.

Security Code Tips:

  • If you don’t see the code in your inbox within a few seconds, check your All Mail, Spam or Junk folders right away.  

  • You have three tries to enter the six-digit code correctly. If for some reason the code is rejected, you can request another code by clicking the Resend Code link.  

  • You can request three codes total per sign in session. If, however, you are unable to enter any of the three allowed codes, the system will automatically block you from further sign in attempts. If you are blocked, you can recover access to your account using the CA DMV Wallet account recovery process.


Sign In with MFA - Unverified User

The sign in flow for users who are ID verified users is described in the section above.  

However, if you are signing in with MFA as an unverified user, the process includes a step to encourage you to verify your identity for security purposes (and fewer sign in steps in the future).

Step 1: Follow the Steps in the Happy Path for Verified Users Process

The sign in flow is the same for all existing users (including verified and unverified users). 

Step 2: Verify Your Identity (optional, but recommended)

For unverified users, after entering your security code on the Security Code page, you are taken to the CCC Students are Expected to Verify Their Identity page, which encourages students to verify their identity using one of the two trusted vendor options: CA DMV Wallet and ID.me.

To complete the identity verification process, find step-by-step instructions for each vendor below. 

Currently ID verification is not mandatory. Users may still bypass the verification process; however, there are many benefits to verifying your identity, including expedited admissions, identity security, and account recovery.  

Once completed with the verification process, you will be taken automatically to the CCCApply My Applications page to start a new application or resume an in-progress application. 

To exit, click Sign Out in the upper right corner of the page. 

Adding a Second Method of Authentication (Mobile Number)

Adding a mobile phone number as a second method of authentication greatly increases the security of your personal information and expedites the sign in and account self-recovery workflows.

  1. Sign in to CCCApply using MFA.

  2. From the My Applications page, select Edit My Account from the Account Information section, or select Edit Account from the Settings link in the main menu. 

My applications page with the Settings and the Edit My Account buttons highlighted.
Edit Account Options
  1. On the Edit Account screen, add or update your mobile number in the Phone field and ensure the Phone Type field is set to Mobile. Phone numbers set to “Landline” cannot be used for MFA or as your preferred method of contact. Once your mobile number is entered, click the Update button at the bottom of the page to save your changes.

Edit Account page with the Phone field highlighted.
Set Preferred Method of Contact

For more information, see the Setting Your Preferred Method of Contact section below.

  1. On the CCCApply Sign In page, enter your mobile phone number in the Email or mobile phone input field. Click Next.

  2. Enter your password, then click Sign In.

  3. On the Keep Your Account Secure page, select your mobile phone number from the list of contact methods, then click Next.

MFA selection page with radio buttons for Email and Helpdesk.
Select Contact Method Screen
  1. Retrieve your code from you mobile phone or device and enter it in the Enter Security Code field. Click Next.

Security Code page with the Security Code field.
Security Code Screen

Benefits of using a Mobile Number: If you didn’t choose to provide a mobile number during the first step of account creation, you can add that information here on the Create Profile page before saving your new account at the bottom of the page. You’ll receive a security code on your mobile phone and then enter it on the Security Code page that appears.

Note: After verifying your mobile number, you can select which method of contact you want to receive you code from the Keep Your Account Secure page.


Setting Your Preferred Method of Contact

Setting your preferred method of contact in the Edit Account page lets you which way you prefer to receive security codes, notifications, and other SMS messages regarding your account.

Steps:

  1. On the Edit Account page, ensure that both your mobile phone and email address are entered correctly. For your mobile number, ensure the Phone Type field is set to Mobile.

  2. Choose your preferred method by clicking the Make Preferred button; there is one under each credential type.

  3. Scroll to the bottom of the Edit Account page and click Update.

  4. If needed, repeat the steps to verify your preferred credential using MFA.

Edit Account page with the Phone field highlighted.
Set Preferred Method of Contact

Recovering Your Account Using MFA

If you have an existing OpenCCC account that you are unable to log into, please do not create a new account. This could delay your objective including submitting or resuming a CCCApply application. Several options are available to help you self-recover your credentials and get back moving forward without contacting the Helpdesk support.

Recovering Your Password

The Forgot your password? process works great for users who still have access to their email address but have simply forgotten their password.

Get Your Security Code

  1. From the Sign In page, enter your email address, then click Next.

  2. On the Password page, click Forgot your password? and click Next. The Keep Your Account Secure page appears.

  3. Select a contact method and click Next. You will receive a message containing a security code that you will input on the next step.

MFA selection page with radio buttons for Email and Helpdesk.
Select Contact Method Screen
  1. Retrieve your code from your email inbox, then enter it in the Security Code field.

Security Code page with the Security Code field.
Security Code Screen

Change Your Password

  1. After verifying your security code, the Update Password page appears. Users are then required to create and verify a new password.

  2. Enter a string of letters, numbers, and special characters into the Password input field. The combination must meet the criteria requirements listed on the left, next to the input fields.

  3. Re-enter the password in the Confirm Password field to ensure it matches the Password field exactly (both fields must match).

  4. Click the Submit button to validate your password.

Update password screen. Password requirements are listed in the next paragraph.
Update Password Screen

Reminder: The password you choose must meet the following security requirements:

  • be at least 8 characters in length

  • contain at least one uppercase letter

  • contain at least one lowercase letter

  • contain at least one number

  • contain at least one of the following special characters ( !, @, #, $, %, ^, &, or *)

  • must NOT contain your name

Password Security: If your updated password meets the required criteria, the “Password must” box will display solid green, as shown in the screenshot below.

Screenshot showing that all password security requirements have been successfully met.
Update Password Screen with Acceptable Password

If your old email is still accessible, we can send a reset link. But if not, and you are a California resident, try the CA DMV Wallet option for account recovery and identity verification.


Recovering Your Account with California DMV Wallet

If you have forgotten your email address and/or password, the first step towards account self-recovery using MFA begins with the Forgot your password? process on the Sign In page without entering your email address.

If you are a California resident, we recommend choosing the CA DMV Wallet option for fastest account recovery and identity verification.

  1. From the CCCApply Sign In page, click the Forgot your password? link without entering an email address. The Recover Your Account page appears.

  2. Click on the Verify with DMV Wallet button to start the CA DMV Wallet process.

Recover Your Account screen with DMV Wallet and Manual Recovery options.
Account Recovery Options
  1. Follow the steps outlined here in Verify using the CA DMV Wallet and keep in mind the following requirements:

    1. You will be required to download the CA DMV Wallet app to a smartphone or desktop (smartphone is recommended).

    2. You will be required to scan a QR code and receive a security code from the DMV.

Using the CA DMV Wallet to recover your account credentials also requires that you verify your identity through the CA DMV’s verification service. This not only helps you regain your sign in credentials easily, it verifies your identity for the CCC system. 


Recovering Your Account Manually

If you have forgotten your email address and/or password, the first step towards account self-recovery using MFA begins with the Forgot your password? process on the Sign In page without entering your email address.

If you are a NOT a California resident, we recommend using this manual option to locate your account and recover your credentials.

Step 1: Click the Forgot your password? link on the Sign In page

  1. From the CCCApply Sign In page, select the Forgot your password? link without entering an email address. The Recover Your Account page appears.

  2. Click on the Recover Manually button to start finding your account.

  3. Follow the screen prompts to enter locate your account manually by entering personal information used to create your account. 

Recover Your Account screen with DMV Wallet and Manual Recovery options.
Account Recovery Options

Troubleshooting & FAQs

Issue

Solution

Issue

Solution

Security code didn’t arrive (Email)

Check your Spam/Junk and All Mail folders first before requesting a new code. Ensure no-reply@cccmypath.org is on your safe-sender list.

Security code didn’t arrive (mobile device/SMS)

Ensure you have cellular signal. If you are using a VoIP number (like Google Voice), some carriers may block these messages. If you’re having trouble, try using your email address instead.

Security code doesn’t work

Security codes expire after 10 minutes. If your code expired, click Resend Code.

Too many attempts entering a security code

Each security code permits three input attempts. After the third try, the security code expires.

Email address isn’t working

If your email address is not working for signing in, refresh the page and then (without entering anything in the Email address or mobile number input field) click the Forgot your password? link and select a self-recovery option.

Mobile number isn’t working

If your mobile phone number is saved in your account. sign in with your email address and navigate to the Settings > Edit Account link in your CCCApply My Applications page. Add or update the mobile number, set the Phone Type to Mobile. and save your changes.
Recommended: If you prefer to use a mobile phone number for future logins, set your Preferred Method of Contact to Mobile Phone before saving your changes.

Password isn’t working

User should follow the Forgot Password? link on CCCApply or OpenCCC Sign In page.

Email address changed by user

You must log in using your Email MFA first, then navigate to settings to update your mobile number.

No longer has access to original Email account

If you have a mobile phone number saved and verified in your account, use your mobile number for sign in. If you don’t have a mobile number saved, refresh the page and then (without entering anything in the Email address or mobile number input field) click the Forgot your password? link and select a self-recovery option.

Mobile number changed by user

You must log in using your Email MFA first, then navigate to settings to update your mobile number.

No longer has mobile number

You may recover your account using one of these methods:

Received “Important: Your CCCApply Account Information was Changed” message

Possible spam/fraud activity (bad actor). 

If you receive this auto-message, it’s because a change was made to one of your contact methods. If you did make the change, ignore the message. If you did NOT make the change, please reach out to CCC Staff Support to report the activity.

The message contains directions and links to help update your information.

Security Best Practices

  • Never share your security code: Support staff will never ask you for your MFA code over the phone or via email.

  • Report unauthorized codes: If you receive an MFA code via text or email when you are not trying to sign in, someone may have your password. Change your password immediately.

  • If you complete the account recovery process and see any applications or other information that you do not recognize, please reach out to our CCC Staff Support team to report potential fraudulent activity.