← Custodia
Practice 14 of 15·FAR 52.204-21(b)(1)(xiv)·SISystem & Information Integrity

SI.L1-b.1.xiv

Update malicious code protection

Anti-malware that's three years out of date is barely anti-malware. Keep signatures and engine versions current on every endpoint. In practice: turn on auto-update for whatever AV / EDR you use and confirm it's actually updating.

Official text

Update malicious code protection mechanisms when new releases are available.

FAR 52.204-21(b)(1)(xiv), CMMC Level 1 v2.13 Assessment Guide

What evidence satisfies this

Any one of these, by itself, won't satisfy the practice — but showing a few of them together is what an assessor or a prime contractor expects to see:

  • Defender update history showing recent signature updates (Security center → Virus & threat protection → Protection updates).
  • macOS XProtect data set version current (Apple ships these via the OS).
  • EDR / AV management console showing every endpoint reporting in within the last 24–48 hours.
  • Auto-update turned on at the AV / EDR product.
  • A monthly check noted in your one-pager that signatures are current.

Common ways small shops fail this

  • Defender showing "Protection updates are out of date" and never investigated.
  • Auto-update disabled on the AV / EDR because someone thought it was using too much bandwidth.
  • Endpoint not reporting in for weeks (laptop in a drawer, but it still has FCI).
  • Old machine running a vendor whose product is end-of-life.
  • macOS users on an old OS major version that no longer receives XProtect updates.

How to fix it in a weekend

  1. 1Open the AV / EDR console (Defender Security center, your vendor's portal) and confirm every endpoint reported in within 48 hours.
  2. 2Re-enable auto-update on any device where it's been disabled.
  3. 3Decommission devices on EOL operating systems or get them on a supported version.
  4. 4Add a once-a-month "are signatures current?" check to your boundary one-pager.
  5. 5Replace AV products whose vendor has gone dark or stopped shipping updates.

FAQ

Isn't this the same practice as (xiii)? Why is it separate?+

(xiii) is "run protection." (xiv) is "keep it current." The CMMC L1 model treats them as separate requirements because the historical failure modes are different: lots of shops install AV but never update it. Both have to be MET independently for the practice to pass.

Related references

Doing all 15 yourself? Use the checklist.

Custodia's free CMMC Level 1 checklist walks the same 15 requirements with a self-assessment workflow, generates your SSP and affirmation memo, and posts your SPRS score for you.

Open the checklist →
Stop reading. Start filing.

Find your SPRS score in 4 minutes. Then file it in 7 days.

Take the free SPRS quiz to see exactly where you stand on the 15 FAR 52.204-21 safeguarding requirements — no signup, no card. If you like what you see, the 7-day Custodia trial picks up where the quiz leaves off and walks you to a signed, bid-ready package.

7-day free trial · No credit card required · $249/mo Self Service ($2,496/yr on annual — two months free)