CMMC Level 1 · RequirementSEC / REQSI.L1-b.1.xv

System and Information Integrity · SI.L1-b.1.xv

Perform periodic and real-time scans

Requirement SI.L1-b.1.xv of the fifteen CMMC Level 1 security requirements, in the System and Information Integrity domain.

Short Answer

Does Level 1 require scanning our systems and files?

Systems are scanned on a schedule, and files from outside are scanned in real time as they are downloaded, opened, or run.

Official Requirement

Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.
Source · FAR 52.204-21(b)(1)

Requirement identity

Framework
Cybersecurity Maturity Model Certification · Level 1
Domain
System and Information Integrity (SI)
Requirement ID
SI.L1-b.1.xv
FAR Clause
FAR 52.204-21(b.1.xv)
NIST SP 800-171 Mapping
3.14.5

Assessment Objectives

Common Questions

What scans does Level 1 expect?
Two kinds. Periodic scans of your systems on a schedule, and real-time scans of files from outside as they are downloaded, opened, or run. Most business antivirus and endpoint tools do both by default once they are enabled.

Source Authority

Primary Authority
FAR 52.204-21(b)(1)
Objectives Authority
NIST SP 800-171A
Framework Version
CMMC Assessment Guide, Level 1 v2.13 (September 2024)
Effective Date
2024-12-16
Last Verified
2026-08

Build the Record Behind This

AssessrLog connects this requirement to its assessment objectives, your evidence, and your determination, and keeps the whole record traceable and ready to affirm. The MET, NOT MET, or N/A call is always yours to make and record.