DKDavid Koran& Associates
Home The CMMC Guide Part III · System and Information Integrity SI.L2-3.14.4
The CMMC Guide · System and Information Integrity Family

SI.L2-3.14.4  Update Malicious Code Protection

Update malicious code protection mechanisms when new releases are available.

Family
System and Information IntegritySI, 7 requirements
Point Value
5Highest weight in the methodology
POA&M Eligible
NoCannot remain open at assessment
Objectives
OnePer NIST SP 800-171A

1Overview

SI.L2-3.14.4 keeps malicious code protection current. It requires that malicious code protection mechanisms be updated when new releases are available, so that the defenses providing malware protection stay effective against emerging threats. It is a five-point requirement that cannot be deferred on a plan of action.

Malware evolves constantly, and antimalware defenses depend on current signatures, engines, and definitions to recognize new threats. Protection that is not updated quickly falls behind, unable to detect the malware released after its last update. This control requires that malicious code protection mechanisms be updated when new releases are available, so the defenses stay current. Its five-point weight reflects that outdated malware protection provides a false sense of security while missing recent threats. The single assessment objective is that the mechanisms are updated when new releases are available.

The requirement · NIST SP 800-171 Rev 2, 3.14.4

Update malicious code protection mechanisms when new releases are available.

The requirement is to update malicious code protection mechanisms when new releases are available. In practice this means the antimalware signatures, engines, and definitions are kept current, typically through automatic updates, so protection recognizes the latest threats. The single assessment objective is that the mechanisms are updated when new releases become available.

2The Assessment Objective

NIST SP 800-171A frames 3.14.4 as a single objective: update mechanisms when new releases are available.

Malicious code protection mechanisms are updated when new releases are available. Antimalware stays current.

MeetsMalicious code protection is updated when new releases are available.
FailsAntimalware signatures and engines are allowed to fall out of date.

The single objective is timely updating. The common gap is antimalware present but not reliably updated, so its definitions lag behind current threats. The assessor looks for protection mechanisms kept current as new releases become available.

3Failure Patterns

The failures are about protection that falls behind.

Updates not automatic or not applied

Antimalware that relies on manual updates that lapse falls out of date. Automatic, applied updates keep protection current.

Some systems not updating

Where most systems update but some do not, those systems run stale protection. Updating has to reach all the protected systems.

Engine outdated, not just signatures

Updating signatures while leaving the protection engine outdated leaves detection gaps. Both the definitions and the mechanisms have to be updated.

The common root
This control fails when protection is treated as install-once. Antimalware installed and then left to age looks like a defense but recognizes only yesterday's threats, giving a false sense of security. Updating the mechanisms when new releases are available is what keeps the protection actually protective.

4Ownership

This is an IT and security-owned control.

RoleResponsibility for this control
IT and securityKeeps malicious code protection updated when new releases are available. Owns the update evidence.
System administratorConfigures and confirms automatic updates across systems.
Security or compliance leadConfirms protection is current across all protected systems.
See also: This control keeps current the protection provided by SI.L2-3.14.2 and supports the scanning of SI.L2-3.14.5.

5Tooling

The control is delivered by automatic antimalware updating.

ObjectiveToolingWhat it provides
signaturesAutomatic signature and definition updatesCurrent threat recognition.
engineEngine and mechanism updatesCurrent protection mechanisms.

The caveat is that updates have to actually apply across all protected systems, covering both definitions and mechanisms. Automatic updates that fail silently on some systems leave those running stale protection. The assessor examines whether the mechanisms are updated when new releases are available, so the updating has to be reliable and complete.

6Evidence

The satisfied version of 3.14.4 shows current malicious code protection.

EvidenceWhat it demonstrates
Update configurationThe objective. Mechanisms set to update on new releases.
Update status recordsThe objective. Protection current across systems.

The evidence should show malicious code protection mechanisms updated when new releases become available, across the protected systems. The update configuration together with update status records is the clearest demonstration, and because this control cannot sit on a plan of action, the current protection has to be real at the time of assessment.

Outdated antimalware protects against yesterday's threats

Malware evolves constantly, so protection that is not updated falls behind while looking like a defense, and this five-point control asks that the mechanisms be updated when new releases are available. Keeping malicious code protection current is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.14.4. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.14.4. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing SI.L2-3.14.4 among the five-point derived security requirements. ecfr.gov
← Previous in System and Information Integrity
SI.L2-3.14.3 · Monitor Security Alerts and Advisories
Next in System and Information Integrity →
SI.L2-3.14.5 · Scan for Malicious Code
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry SI.L2-3.14.4 · Edition 2026.1 · Last reviewed July 12, 2026