• Both sides present certificates (unlike Standard TLS (one-way))
  • The server verifies the client, AND the client verifies the server
  • Neither side trusts the other without proof of identity
  • This is the “mutual” part — authentication goes both directions