What WCAG says
WCAG 2.2 Success Criterion 3.3.8 addresses accessible authentication, generally requiring that authentication not depend on a cognitive function test unless an exception applies. The specification describes alternatives such as allowing password managers and copy-and-paste.
This criterion is one part of a broader standard and does not prescribe one universal login product. The W3C source provides requirements and exceptions that teams should read in context before making implementation decisions.
Consider the full CMS access path
For Custom CMS Creation, review how editors sign in, recover accounts, use multi-factor authentication, and move between identity providers and the authoring tool. Security controls and accessible ways to complete them need to be considered together.
Test the actual authentication flow with password managers, assistive technology, and the supported user devices. If a vendor’s login creates friction, document the issue and evaluate configuration or a supported alternative rather than weakening account security casually.
Treat access as part of editorial continuity
An inaccessible login can prevent a qualified editor from publishing a correction, while an insecure workaround can expose the whole content operation. Include recovery and emergency publishing roles in the same workflow review.
The practical reading is to make the access path both secure and usable, then validate it against relevant criteria. A CMS’s editorial experience starts before the first draft; it starts when the right person can enter the system.