to move, Enter to open, Esc to close. Try 3.5.3, AC.L2-3.1.1, MFA or unmarked.

3.14.2Run malware protection in Rev. 3

Reworded: 03.14.02 Malicious Code Protection. Gains organization-defined parameters.

Status as of 2026-09-08

Rev. 2 is what a contract requires today. DFARS 252.204-7012 and the CMMC rule at 32 CFR 170 point at NIST SP 800-171 Rev. 2, and a standing DoD class deviation keeps it there. NIST has published Rev. 3, but publishing a revision does not change an obligation. A move to Rev. 3 would arrive through the Department's reform process and formal rulemaking, a change to that deviation or an amendment to the rule, not through publication. The Department has published its organization-defined parameter values for Rev. 3 in preparation; that is groundwork, not adoption.

Side by side

Rev. 2 · in force 3.14.2 Malicious Code Protection

Provide protection from malicious code at appropriate locations within organizational systems.

Assessment objectives · 800-171A

  1. [a] designated locations for malicious code protection are identified
  2. [b] protection from malicious code is provided at designated locations

Rev. 3 · not adopted 03.14.02 Malicious Code Protection

a. Implement malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code.

b. Update malicious code protection mechanisms as new releases are available in accordance with configuration management policies and procedures.

c. Configure malicious code protection mechanisms to:

01. Perform scans of the system [Assignment: organization-defined frequency] and real-time scans of files from external sources at endpoints or system entry and exit points as the files are downloaded, opened, or executed; and

02. Block malicious code, quarantine malicious code, or take other mitigation actions in response to malicious code detection.

Determination statements · 800-171A Rev. 3

  1. 03.14.02.a[01] malicious code protection mechanisms are implemented at system entry and exit points to detect malicious code.
  2. 03.14.02.a[02] malicious code protection mechanisms are implemented at system entry and exit points to eradicate malicious code.
  3. 03.14.02.b malicious code protection mechanisms are updated as new releases are available in accordance with configuration management policy and procedures.
  4. 03.14.02.c.01[01] malicious code protection mechanisms are configured to perform scans of the system <A.03.14.02.ODP[01]: frequency>.
  5. 03.14.02.c.01[02] malicious code protection mechanisms are configured to perform real-time scans of files from external sources at endpoints or system entry and exit points as the files are downloaded, opened, or executed.
  6. 03.14.02.c.02 malicious code protection mechanisms are configured to block malicious code, quarantine malicious code, or take other actions in response to malicious code detection.

Organization-defined parameters

  • A.03.14.02.ODP[01] the frequency at which malicious code protection mechanisms perform scans is defined.

Draws on Rev. 2 3.14.2, 3.14.4, 3.14.5.

Left: NIST SP 800-171 Rev. 2 and 800-171A, verbatim. Right: NIST SP 800-171 Rev. 3 and 800-171A Rev. 3, verbatim, with organization-defined blanks highlighted.

Word by word

The Rev. 2 requirement compared with its Rev. 3 successor. A mechanical comparison of the two verbatim texts, not an interpretation.

removed in Rev. 3 added in Rev. 3

Rev. 2 3.14.2 → Rev. 3 03.14.02 Malicious Code Protection

Provide Implement malicious code protection from mechanisms at system entry and exit points to detect and eradicate malicious code. Update malicious code protection mechanisms as new releases are available in accordance with configuration management policies and procedures. Configure malicious code protection mechanisms to: Perform scans of the system [Assignment: organization-defined frequency] and real-time scans of files from external sources at appropriate locations within organizational systems. endpoints or system entry and exit points as the files are downloaded, opened, or executed; and Block malicious code, quarantine malicious code, or take other mitigation actions in response to malicious code detection.

4 words kept, 7 removed, 87 added. Rev. 3 statement labels omitted for the comparison.

What NIST says changed

  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for malicious code protection
  • Incorporates withdrawn requirements: 03.14.04, 03.14.05
  • Added new ODP: frequency to perform system scans
  • Updated discussion to provide additional guidance on malicious code protection mechanisms.

NIST, SP 800-171 Rev. 2 to Rev. 3 change analysis, class “Significant change”. At adoption, Bedrock files this under “Rework”.

NIST's Rev. 3 discussion for 03.14.02

Malicious code insertions occur through the exploitation of system vulnerabilities. Malicious code can be inserted into the system in a variety of ways, including email, the internet, and portable storage devices. Malicious code includes viruses, worms, Trojan horses, and spyware. Malicious code can be encoded in various formats, contained in compressed or hidden files, or hidden in files using techniques such as steganography. Malicious code may be present in commercial off-the-shelf software and custom-built software and could include logic bombs, backdoors, and other types of attacks that could affect organizational mission and business functions. Periodic scans of the system and real-time scans of files from external sources as files are downloaded, opened, or executed can detect malicious code. Malicious code protection mechanisms can also monitor systems for anomalous or unexpected behaviors and take appropriate actions. Malicious code protection mechanisms include signature- and non-signature-based technologies. Non-signature-based detection mechanisms include artificial intelligence techniques that use heuristics to detect, analyze, and describe the characteristics or behavior of malicious code and to provide controls against such code for which signatures do not yet exist or for which existing signatures may not be effective. Malicious code for which active signatures do not yet exist or may be ineffective includes polymorphic malicious code (i.e., code that changes signatures when it replicates). Non-signature-based mechanisms include reputation-based technologies. Pervasive configuration management, anti-exploitation software, and software integrity controls may also be effective in preventing unauthorized code execution. If malicious code cannot be detected by detection methods or technologies, organizations can rely on secure coding practices, configuration management and control, trusted procurement processes, and monitoring practices to help ensure that the software only performs intended functions. Organizations may determine that different actions are warranted in response to the detection of malicious code. For example, organizations can define actions to be taken in response to the detection of malicious code during scans, malicious downloads, or malicious activity when attempting to open or execute files.

What this means for you now

Nothing changes in what you are assessed against until a class deviation or a published rule adopts Rev. 3. Keep meeting 3.14.2 as written in Rev. 2, and if you already choose a value for the parameters above in practice, write it down where your system security plan can find it.

Bedrock CMMC shows this same comparison against your own package, with your current status on the Rev. 2 side, so the day adoption lands the migration is a review, not a rewrite.

Back to the Rev. 2 vs Rev. 3 overview

Where this page's facts come from
Rev. 2 text and objectives
bedrock-cmmc-api@89b8e8e:migrations/004_reference_requirements.sql#Requirement.basicRequirement@rev2; bedrock-cmmc-api@89b8e8e:migrations/005_reference_objectives.sql#AssessmentObjective.description@rev2
Mapping and change class
bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/r2_r3_transition_map.json#r2_to_r3
Rev. 3 03.14.02
bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/rev3.json#requirements[]