SI.L1-b.1.xiii
Provide protection from malicious code
Run anti-malware (a.k.a. endpoint protection / EDR) on every system that handles FCI. The bar is not enterprise XDR — it's "something real and current is running." Microsoft Defender on Windows and the built-in protections on modern macOS qualify.
Official text
“Provide protection from malicious code at appropriate locations within organizational information systems.”
— FAR 52.204-21(b)(1)(xiii), CMMC Level 1 v2.13 Assessment Guide
What evidence satisfies this
Any one of these, by itself, won't satisfy the practice — but showing a few of them together is what an assessor or a prime contractor expects to see:
- ✓Microsoft Defender enabled and reporting on every Windows endpoint (screenshot from Security center).
- ✓macOS XProtect / Gatekeeper enabled (default on modern macOS) plus optional third-party AV.
- ✓Email scanning at the tenant level (Exchange Online Protection, Google's spam / malware scanning).
- ✓Web filtering / safe browsing on browsers.
- ✓An asset list showing AV is installed on every endpoint that touches FCI.
Common ways small shops fail this
- ✗Defender disabled because someone installed a free "PC optimizer."
- ✗Old standalone AV from 2018 still installed and conflicting with Defender (so neither works).
- ✗macOS users assuming "Macs don't get viruses" and disabling Gatekeeper.
- ✗Servers in the office with no AV at all ("it's a server, it doesn't need one").
- ✗Email going to personal Gmail that doesn't run the tenant's malware scanning.
How to fix it in a weekend
- 1Walk every endpoint. Defender / equivalent must be on and current. Remove conflicting AV products.
- 2Confirm tenant-level email scanning is on (default in M365 and Workspace).
- 3On macOS, leave Gatekeeper and XProtect on. Add a paid product only if you have a specific reason.
- 4Add AV / EDR to your server endpoints if you run any.
- 5Document which product covers which device in your scoping artifact.
FAQ
Is Microsoft Defender good enough for Level 1?+
Yes. Microsoft Defender is a current, vendor-supported anti-malware product that meets (b)(1)(xiii) on Windows. You may decide to upgrade to a managed EDR for operational reasons, but Defender alone satisfies the practice.
Related references
Doing all 15 yourself? Use the checklist.
Custodia's free CMMC Level 1 checklist walks the same 15 requirements with a self-assessment workflow, generates your SSP and affirmation memo, and posts your SPRS score for you.
Open the checklist →