SI.L1-b.1.xiv
Update malicious code protection
Anti-malware that's three years out of date is barely anti-malware. Keep signatures and engine versions current on every endpoint. In practice: turn on auto-update for whatever AV / EDR you use and confirm it's actually updating.
Official text
“Update malicious code protection mechanisms when new releases are available.”
— FAR 52.204-21(b)(1)(xiv), CMMC Level 1 v2.13 Assessment Guide
What evidence satisfies this
Any one of these, by itself, won't satisfy the practice — but showing a few of them together is what an assessor or a prime contractor expects to see:
- ✓Defender update history showing recent signature updates (Security center → Virus & threat protection → Protection updates).
- ✓macOS XProtect data set version current (Apple ships these via the OS).
- ✓EDR / AV management console showing every endpoint reporting in within the last 24–48 hours.
- ✓Auto-update turned on at the AV / EDR product.
- ✓A monthly check noted in your one-pager that signatures are current.
Common ways small shops fail this
- ✗Defender showing "Protection updates are out of date" and never investigated.
- ✗Auto-update disabled on the AV / EDR because someone thought it was using too much bandwidth.
- ✗Endpoint not reporting in for weeks (laptop in a drawer, but it still has FCI).
- ✗Old machine running a vendor whose product is end-of-life.
- ✗macOS users on an old OS major version that no longer receives XProtect updates.
How to fix it in a weekend
- 1Open the AV / EDR console (Defender Security center, your vendor's portal) and confirm every endpoint reported in within 48 hours.
- 2Re-enable auto-update on any device where it's been disabled.
- 3Decommission devices on EOL operating systems or get them on a supported version.
- 4Add a once-a-month "are signatures current?" check to your boundary one-pager.
- 5Replace AV products whose vendor has gone dark or stopped shipping updates.
FAQ
Isn't this the same practice as (xiii)? Why is it separate?+
(xiii) is "run protection." (xiv) is "keep it current." The CMMC L1 model treats them as separate requirements because the historical failure modes are different: lots of shops install AV but never update it. Both have to be MET independently for the practice to pass.
Related references
Doing all 15 yourself? Use the checklist.
Custodia's free CMMC Level 1 checklist walks the same 15 requirements with a self-assessment workflow, generates your SSP and affirmation memo, and posts your SPRS score for you.
Open the checklist →