CMMC Level 1 · RequirementSEC / REQSI.L1-b.1.xiv
System and Information Integrity · SI.L1-b.1.xiv
Keep malicious code protection current
Requirement SI.L1-b.1.xiv of the fifteen CMMC Level 1 security requirements, in the System and Information Integrity domain.
Short Answer
Do we have to keep our malware protection up to date?
Malware protection is kept up to date, taking new definitions and engine releases as they become available.
Official Requirement
Update malicious code protection mechanisms when new releases are available.
Source · FAR 52.204-21(b)(1)
Requirement identity
- Framework
- Cybersecurity Maturity Model Certification · Level 1
- Domain
- System and Information Integrity (SI)
- Requirement ID
- SI.L1-b.1.xiv
- FAR Clause
- FAR 52.204-21(b.1.xiv)
- NIST SP 800-171 Mapping
- 3.14.4
Assessment Objectives
Related Requirements
Common Questions
- Does keeping antivirus on auto-update satisfy this?
- Generally, yes. The requirement is that your malware protection is updated when new releases are available. Antivirus or endpoint protection set to update its definitions and engine automatically is the common way suppliers cover this.
Source Authority
- Primary Authority
- FAR 52.204-21(b)(1)
- Objectives Authority
- NIST SP 800-171A
- Program Authority
- 32 CFR 170.15(c)(1)(ii) Table 2
- Framework Version
- CMMC Assessment Guide, Level 1 v2.13 (September 2024)
- Effective Date
- 2024-12-16
- Last Verified
- 2026-08
Build the Record Behind This
AssessrLog connects this requirement to its assessment objectives, your evidence, and your determination, and keeps the whole record traceable and ready to affirm. The MET, NOT MET, or N/A call is always yours to make and record.
