CMMC Level 1 · RequirementSEC / REQSI.L1-b.1.xiii
System and Information Integrity · SI.L1-b.1.xiii
Protect against malicious code
Requirement SI.L1-b.1.xiii of the fifteen CMMC Level 1 security requirements, in the System and Information Integrity domain.
Short Answer
Does CMMC Level 1 require antivirus or malware protection?
Protection against malware runs at the right places in the environment, such as endpoints, email, and network entry points.
Official Requirement
Provide protection from malicious code at appropriate locations within organizational information systems.
Source · FAR 52.204-21(b)(1)
Requirement identity
- Framework
- Cybersecurity Maturity Model Certification · Level 1
- Domain
- System and Information Integrity (SI)
- Requirement ID
- SI.L1-b.1.xiii
- FAR Clause
- FAR 52.204-21(b.1.xiii)
- NIST SP 800-171 Mapping
- 3.14.2
Assessment Objectives
Related Requirements
Common Questions
- Does CMMC Level 1 require antivirus?
- Yes. Providing protection against malicious code at the right places in your systems is one of the fifteen Level 1 requirements. Two related requirements go with it. Keep that protection updated as new releases come out, and run periodic scans plus real-time scans of files from outside. Ordinary business antivirus or endpoint protection, kept current, is the common way suppliers cover these.
Source Authority
- Primary Authority
- FAR 52.204-21(b)(1)
- Objectives Authority
- NIST SP 800-171A
- Program Authority
- 32 CFR 170.15(c)(1)(ii) Table 2
- Framework Version
- CMMC Assessment Guide, Level 1 v2.13 (September 2024)
- Effective Date
- 2024-12-16
- Last Verified
- 2026-08
Build the Record Behind This
AssessrLog connects this requirement to its assessment objectives, your evidence, and your determination, and keeps the whole record traceable and ready to affirm. The MET, NOT MET, or N/A call is always yours to make and record.
