← Custodia
Practice 13 of 15·FAR 52.204-21(b)(1)(xiii)·SISystem & Information Integrity

SI.L1-b.1.xiii

Provide protection from malicious code

Run anti-malware (a.k.a. endpoint protection / EDR) on every system that handles FCI. The bar is not enterprise XDR — it's "something real and current is running." Microsoft Defender on Windows and the built-in protections on modern macOS qualify.

Official text

Provide protection from malicious code at appropriate locations within organizational information systems.

FAR 52.204-21(b)(1)(xiii), CMMC Level 1 v2.13 Assessment Guide

What evidence satisfies this

Any one of these, by itself, won't satisfy the practice — but showing a few of them together is what an assessor or a prime contractor expects to see:

  • Microsoft Defender enabled and reporting on every Windows endpoint (screenshot from Security center).
  • macOS XProtect / Gatekeeper enabled (default on modern macOS) plus optional third-party AV.
  • Email scanning at the tenant level (Exchange Online Protection, Google's spam / malware scanning).
  • Web filtering / safe browsing on browsers.
  • An asset list showing AV is installed on every endpoint that touches FCI.

Common ways small shops fail this

  • Defender disabled because someone installed a free "PC optimizer."
  • Old standalone AV from 2018 still installed and conflicting with Defender (so neither works).
  • macOS users assuming "Macs don't get viruses" and disabling Gatekeeper.
  • Servers in the office with no AV at all ("it's a server, it doesn't need one").
  • Email going to personal Gmail that doesn't run the tenant's malware scanning.

How to fix it in a weekend

  1. 1Walk every endpoint. Defender / equivalent must be on and current. Remove conflicting AV products.
  2. 2Confirm tenant-level email scanning is on (default in M365 and Workspace).
  3. 3On macOS, leave Gatekeeper and XProtect on. Add a paid product only if you have a specific reason.
  4. 4Add AV / EDR to your server endpoints if you run any.
  5. 5Document which product covers which device in your scoping artifact.

FAQ

Is Microsoft Defender good enough for Level 1?+

Yes. Microsoft Defender is a current, vendor-supported anti-malware product that meets (b)(1)(xiii) on Windows. You may decide to upgrade to a managed EDR for operational reasons, but Defender alone satisfies the practice.

Related references

Doing all 15 yourself? Use the checklist.

Custodia's free CMMC Level 1 checklist walks the same 15 requirements with a self-assessment workflow, generates your SSP and affirmation memo, and posts your SPRS score for you.

Open the checklist →
Stop reading. Start filing.

Find your SPRS score in 4 minutes. Then file it in 7 days.

Take the free SPRS quiz to see exactly where you stand on the 15 FAR 52.204-21 safeguarding requirements — no signup, no card. If you like what you see, the 7-day Custodia trial picks up where the quiz leaves off and walks you to a signed, bid-ready package.

7-day free trial · No credit card required · $249/mo Self Service ($2,496/yr on annual — two months free)