CMMC Level 1 · RequirementSEC / REQSI.L1-b.1.xiv

System and Information Integrity · SI.L1-b.1.xiv

Keep malicious code protection current

Requirement SI.L1-b.1.xiv of the fifteen CMMC Level 1 security requirements, in the System and Information Integrity domain.

Short Answer

Do we have to keep our malware protection up to date?

Malware protection is kept up to date, taking new definitions and engine releases as they become available.

Official Requirement

Update malicious code protection mechanisms when new releases are available.
Source · FAR 52.204-21(b)(1)

Requirement identity

Framework
Cybersecurity Maturity Model Certification · Level 1
Domain
System and Information Integrity (SI)
Requirement ID
SI.L1-b.1.xiv
FAR Clause
FAR 52.204-21(b.1.xiv)
NIST SP 800-171 Mapping
3.14.4

Assessment Objectives

Common Questions

Does keeping antivirus on auto-update satisfy this?
Generally, yes. The requirement is that your malware protection is updated when new releases are available. Antivirus or endpoint protection set to update its definitions and engine automatically is the common way suppliers cover this.

Source Authority

Primary Authority
FAR 52.204-21(b)(1)
Objectives Authority
NIST SP 800-171A
Framework Version
CMMC Assessment Guide, Level 1 v2.13 (September 2024)
Effective Date
2024-12-16
Last Verified
2026-08

Build the Record Behind This

AssessrLog connects this requirement to its assessment objectives, your evidence, and your determination, and keeps the whole record traceable and ready to affirm. The MET, NOT MET, or N/A call is always yours to make and record.