CMMC 3.14.2 (Malicious Code Protection): AV/EDR Evidence & What Assessors Actually Check

    Control: NIST SP 800-171 Rev. 2 §3.14.2 · CMMC Practice: SI.L2-3.14.2 · Updated June 2026

    Plain-English answer

    3.14.2 says: provide protection from malicious code at designated locations. The bar isn't "we run antivirus." It's "AV or EDR is deployed everywhere it needs to be, it's centrally managed, it's current, and someone responds when it fires."

    3.14.2 vs. 3.14.4 — the line assessors draw

    3.14.2 is deploy the protection. 3.14.4 is keep it updated. You can fully satisfy 3.14.2 with managed AV on every endpoint and still fail 3.14.4 if a third of the fleet is stuck two months behind on signatures. Both are 5-point controls — they're paired but scored separately.

    Control lineage

    • CMMC Practice: SI.L2-3.14.2 (also appears at Level 1 as SI.L1-3.14.2 — same text, lower bar).
    • NIST 800-171 Rev. 2: §3.14.2 — provide protection from malicious code at designated locations within organizational information systems.
    • NIST 800-171A objectives: [a] designated locations for malicious code protection are identified; [b] protection from malicious code at designated locations is provided.

    What the assessor will EXAMINE

    • List of designated locations — workstations, servers, email gateways, web proxies, removable-media scan points — with rationale.
    • AV/EDR central console showing deployment coverage across the CUI-relevant asset inventory (the two lists must reconcile).
    • Policy configuration: real-time protection on, scheduled scans, tamper protection, behavioral/heuristic detection enabled.
    • Sample detections from the last 30–90 days with the triage notes attached.
    • Quarantine / response procedure tying detections to a named responder.
    • SSP narrative for 3.14.2 naming the product, the designated locations, and the response process.

    What the assessor will INTERVIEW

    • "Show me the last malware detection on a CUI endpoint." — open the console, show the alert, show the response.
    • "How do you know every CUI workstation has the agent installed?" — reconcile AV console vs. asset inventory live.
    • "What happens when a detection fires overnight?" — name the on-call rotation or SOC contract.

    What the assessor will TEST

    • Pick a sample CUI host and verify the agent is present, reporting in, and real-time protection is enabled.
    • Drop an EICAR test file on a non-production endpoint and watch the detection land in the console.
    • Trace one historical detection from generation → notification → quarantine → closure.

    Evidence examples (produce these)

    • Designated-locations document: endpoints, servers, email gateway, web proxy, removable-media kiosks.
    • AV/EDR console coverage report exported same day, reconciled against the CUI asset inventory.
    • Policy export showing real-time scan, behavioral detection, tamper protection, and scheduled full scans.
    • 5–10 recent detection samples with triage timestamps and responder names.
    • Email-gateway attachment-scanning configuration (Microsoft 365 Defender, Google Workspace Security Sandbox, Proofpoint, etc.).
    • Incident response procedure section covering malware containment.
    • SSP §3.14.2 referencing the product, locations, and response.

    Platform-specific

    • Microsoft GCC High: Defender for Endpoint (centrally managed via Intune/MDE console), Defender for Office 365 Safe Attachments / Safe Links, and Defender for Cloud workload protections — show coverage, policy, and a triaged incident.
    • Google Workspace: Gmail attachment scanning + Security Sandbox at the email entry point, Drive malware scanning, Safe Browsing on Chrome, and a managed EDR (CrowdStrike, SentinelOne, Defender) on endpoints — Workspace alone does not cover endpoints.
    • Athena: ACG's managed-service inheritance baseline covers SI.L2-3.14.2[a]/[b] via standard EDR deployment on all supported workstations and servers — non-supported assets remain customer-responsibility and surface as evidence requests.

    Common failure patterns

    • "We have Defender on every laptop" — but it's unmanaged, no console, no central visibility into coverage or detections.
    • AV deployed to workstations only; servers, the mail gateway, and the web proxy are forgotten "designated locations."
    • Real-time protection disabled on developer machines "because it slowed builds" — sample test fails immediately.
    • Detections fire but route to a shared inbox no one owns — no responder, no quarantine, no record.
    • AV console and asset inventory don't reconcile — 12% of CUI endpoints have no agent and no one noticed.

    SPRS impact & POA&M

    SPRS: not meeting 3.14.2 is a 5-point deduction — the heaviest tier. POA&M: 3.14.2 is a foundational L1 practice and is not generally POA&M-eligible under CMMC; confirm current rules before assuming it can be deferred.

    Assessor-ready summary

    You're good on 3.14.2 when designated locations are documented, AV/EDR is deployed and centrally managed across every one of them, real-time scanning is on, detections route to a named responder, and the SSP narrates the same picture.

    Turn your AV/EDR console into 3.14.2 evidence — not just an install count. Get a malicious-code evidence map →

    Related: 3.14.6 system monitoring · 3.11.2 vulnerability scanning · Calculate your SPRS score

    Athena prepares organizations for CMMC Level 2; certification rests with C3PAOs/DIBCAC. Verify all control facts against NIST SP 800-171 Rev. 2, NIST SP 800-171A, and current CMMC rules.