CMMC Level 1 · RequirementSEC / REQSI.L1-b.1.xiii

System and Information Integrity · SI.L1-b.1.xiii

Protect against malicious code

Requirement SI.L1-b.1.xiii of the fifteen CMMC Level 1 security requirements, in the System and Information Integrity domain.

Short Answer

Does CMMC Level 1 require antivirus or malware protection?

Protection against malware runs at the right places in the environment, such as endpoints, email, and network entry points.

Official Requirement

Provide protection from malicious code at appropriate locations within organizational information systems.
Source · FAR 52.204-21(b)(1)

Requirement identity

Framework
Cybersecurity Maturity Model Certification · Level 1
Domain
System and Information Integrity (SI)
Requirement ID
SI.L1-b.1.xiii
FAR Clause
FAR 52.204-21(b.1.xiii)
NIST SP 800-171 Mapping
3.14.2

Assessment Objectives

Common Questions

Does CMMC Level 1 require antivirus?
Yes. Providing protection against malicious code at the right places in your systems is one of the fifteen Level 1 requirements. Two related requirements go with it. Keep that protection updated as new releases come out, and run periodic scans plus real-time scans of files from outside. Ordinary business antivirus or endpoint protection, kept current, is the common way suppliers cover these.

Source Authority

Primary Authority
FAR 52.204-21(b)(1)
Objectives Authority
NIST SP 800-171A
Framework Version
CMMC Assessment Guide, Level 1 v2.13 (September 2024)
Effective Date
2024-12-16
Last Verified
2026-08

Build the Record Behind This

AssessrLog connects this requirement to its assessment objectives, your evidence, and your determination, and keeps the whole record traceable and ready to affirm. The MET, NOT MET, or N/A call is always yours to make and record.