DKDavid Koran& Associates
Home The CMMC Guide Part III · Maintenance MA.L2-3.7.4
The CMMC Guide · Maintenance Family

MA.L2-3.7.4  Check Media for Malicious Code

Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.

Family
MaintenanceMA, 6 requirements
Point Value
3Weighted above baseline
POA&M Eligible
NoAbove one point, cannot be deferred
Objectives
OnePer NIST SP 800-171A

1Overview

MA.L2-3.7.4 guards against malware arriving through maintenance media. It requires that media containing diagnostic and test programs be checked for malicious code before it is used in organizational systems, so that a maintenance tool does not become the delivery vehicle for an infection. It is a three-point requirement with a single assessment objective, and it cannot be deferred on a plan of action.

Diagnostic and test media, the USB drives, discs, and tools that technicians bring to service systems, connect directly to the environment and often with elevated access. If that media carries malicious code, maintenance becomes the path by which malware enters, bypassing many of the defenses at the network edge. This control requires that such media be checked for malicious code before use, so a maintenance tool is verified clean rather than trusted blindly. Its three-point weight reflects that maintenance media is a direct, privileged route into systems.

The requirement · NIST SP 800-171 Rev 2, 3.7.4

Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.

The requirement is specific to diagnostic and test media and requires a malicious-code check before that media touches organizational systems. The check is typically an antimalware scan of the media, performed on every occasion before use, so that whatever a technician brings in is verified. It applies whether the media comes from staff or an outside vendor, since either can carry an infection unknowingly.

2The Assessment Objective

NIST SP 800-171A frames 3.7.4 as a single objective: check diagnostic and test media for malicious code before use.

Media containing diagnostic and test programs are checked for malicious code before the media are used in organizational systems. Maintenance media is verified clean before use.

MeetsDiagnostic and test media are scanned for malicious code before being used on systems.
FailsMaintenance media is used without any malicious-code check.

The single objective is the malicious-code check before use. The common failure is trusting a technician's media without scanning it. The assessor looks for a check performed before diagnostic and test media are used.

3Failure Patterns

The failures are about unchecked maintenance media.

Vendor media trusted without a check

Media brought by an outside technician is often trusted implicitly, yet it can carry an infection the technician is unaware of. Scanning it before use verifies it regardless of source.

No scanning step before use

Where there is no required check, diagnostic and test media are used directly, and any malware on them enters the system. A required scan before use closes this path.

Inconsistent checking

Checking media sometimes but not always leaves gaps on the occasions it is skipped. The check has to happen every time media is used.

The common root
This control fails on implicit trust. Maintenance media connects with privileged access, and it is easy to assume a technician's tools are clean, but that assumption is exactly what malware exploits. Scanning the media before every use replaces trust with verification.

4Ownership

This is an IT-owned technical control tied to the maintenance process.

RoleResponsibility for this control
IT and system administratorChecks diagnostic and test media for malicious code before use. Owns the technical evidence.
Security or compliance leadConfirms the check is required and performed on all maintenance media, including vendor media.
Program leadIncludes the media check in the maintenance process and retains the records.
See also: This control complements the maintenance controls of MA.L2-3.7.2 and the malicious-code defenses of the system and information integrity family.

5Tooling

The control is delivered by scanning maintenance media before use.

ObjectiveToolingWhat it provides
scanAntimalware scanning of mediaA malicious-code check of diagnostic and test media.
processRequired check before useA step that verifies media before it touches systems.

The caveat is that the check has to happen every time and cover media from any source. A scan performed inconsistently, or skipped for trusted vendors, leaves the gap the control addresses. The assessor examines whether diagnostic and test media are checked before use, so the check has to be a consistent, required step.

6Evidence

The satisfied version of 3.7.4 shows maintenance media checked before use.

EvidenceWhat it demonstrates
Media check procedureThe objective. A required malicious-code check before use.
Scan recordsThe objective. Evidence media is checked before use.

The evidence should show diagnostic and test media checked for malicious code before use, as a required step. The check procedure and scan records are the clearest demonstration, and because this control cannot sit on a plan of action, the check has to be a real practice at the time of assessment.

A maintenance tool should be verified, not trusted

Diagnostic media connects with privileged access, and if it carries malware, maintenance becomes the way in, so this control asks for a malicious-code check before use. Building that check into the maintenance process, for vendor media too, is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.7.4. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.7.4. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing MA.L2-3.7.4 among the three-point derived security requirements. ecfr.gov
← Previous in Maintenance
MA.L2-3.7.3 · Sanitize Equipment for Off-Site Maintenance
Next in Maintenance →
MA.L2-3.7.5 · Nonlocal Maintenance MFA
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry MA.L2-3.7.4 · Edition 2026.1 · Last reviewed July 12, 2026