Example, read only. A sample account that shows what finished CMMC looks like.

← Back to the 15 safeguards
SI · System and Information IntegrityMET

Safeguard 14 of 15 · SI.L1-b.1.xiv

SI.L1-3.14.4 · FAR 52.204-21 (b)(1)(xiv) · NIST SP 800-171 3.14.4

Update Malicious Code Protection

Update malicious code protection mechanisms when new releases are available

What it means

Keep your antivirus current, turn on automatic updates so it downloads new definitions.

Why it matters

Definitions from 2023 are the same as having no antivirus. Show automatic updates are enabled and that the latest definition date is recent.

How to do it, Microsoft 365 / Defender

  1. 1Go to security.microsoft.com → Assets → Devices
  2. 2Screenshot the device inventory showing 'Security intelligence version' and last-update timestamp per device
  3. 3Open the Defender antivirus policy and screenshot the automatic-update setting

Capture: Per-device definition-version report + policy screenshot showing auto-update.

The narrative on file

Defender definitions update automatically through Microsoft, so signatures stay current without manual work. The Intune report confirms every device has current protection updates.

You answer in plain English; Charlie writes the official narrative for your System Security Plan.

What makes it pass

  • Per-device screenshot shows definition version + last update timestamp within the last 7 days
  • Auto-update setting visible in policy or product UI
  • Inventory or dashboard covers every device in scope (no orphans)

Assessment objectives, NIST SP 800-171A

[a] Malicious-code protection mechanisms are updated when new releases are available
MET

This is one of 15

Answer in plain English, drop the proof, confirm it MET.

Cedar Ridge Machine Works, LLC walked all 15 the same way. The platform explains each one in plain English, tells you exactly what to grab, checks it, and writes the paperwork, and you confirm each one MET. The self assessment stays your act. Start free, or book a call.