Mobile application should persist the information whether this Step-up AuthN has been completed for this user or not within the active session, to avoid excessive MFA / AAL2 challenge. When mobile application session is terminated (close the app, certain amount of inactivity, etc), then the user should re-obtain mobile application AAL2 as described above.