- Both sides present certificates (unlike Standard TLS (one-way))
- The server verifies the client, AND the client verifies the server
- Neither side trusts the other without proof of identity
- This is the “mutual” part — authentication goes both directions