to move, Enter to open, Esc to close. Try 3.5.3, AC.L2-3.1.1, MFA or unmarked.

3.14.5Scan on schedule and in real time in Rev. 3

Withdrawn and incorporated elsewhere: 03.14.02 Malicious Code Protection.

Status as of 2026-09-08

Rev. 2 is what a contract requires today. DFARS 252.204-7012 and the CMMC rule at 32 CFR 170 point at NIST SP 800-171 Rev. 2, and a standing DoD class deviation keeps it there. NIST has published Rev. 3, but publishing a revision does not change an obligation. A move to Rev. 3 would arrive through the Department's reform process and formal rulemaking, a change to that deviation or an amendment to the rule, not through publication. The Department has published its organization-defined parameter values for Rev. 3 in preparation; that is groundwork, not adoption.

Side by side

Rev. 2 · in force 3.14.5 System & File Scanning

Perform periodic scans of organizational systems and real-time scans of files from external sources as files are downloaded, opened, or executed.

Assessment objectives · 800-171A

  1. [a] periodic scans of the system are performed
  2. [b] real-time scans of files from external sources as files are downloaded, opened, or executed are performed

Rev. 3 · not adopted 03.14.02 Malicious Code Protection

a. Implement malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code.

b. Update malicious code protection mechanisms as new releases are available in accordance with configuration management policies and procedures.

c. Configure malicious code protection mechanisms to:

01. Perform scans of the system [Assignment: organization-defined frequency] and real-time scans of files from external sources at endpoints or system entry and exit points as the files are downloaded, opened, or executed; and

02. Block malicious code, quarantine malicious code, or take other mitigation actions in response to malicious code detection.

Determination statements · 800-171A Rev. 3

  1. 03.14.02.a[01] malicious code protection mechanisms are implemented at system entry and exit points to detect malicious code.
  2. 03.14.02.a[02] malicious code protection mechanisms are implemented at system entry and exit points to eradicate malicious code.
  3. 03.14.02.b malicious code protection mechanisms are updated as new releases are available in accordance with configuration management policy and procedures.
  4. 03.14.02.c.01[01] malicious code protection mechanisms are configured to perform scans of the system <A.03.14.02.ODP[01]: frequency>.
  5. 03.14.02.c.01[02] malicious code protection mechanisms are configured to perform real-time scans of files from external sources at endpoints or system entry and exit points as the files are downloaded, opened, or executed.
  6. 03.14.02.c.02 malicious code protection mechanisms are configured to block malicious code, quarantine malicious code, or take other actions in response to malicious code detection.

Organization-defined parameters

  • A.03.14.02.ODP[01] the frequency at which malicious code protection mechanisms perform scans is defined.

Draws on Rev. 2 3.14.2, 3.14.4, 3.14.5.

Left: NIST SP 800-171 Rev. 2 and 800-171A, verbatim. Right: NIST SP 800-171 Rev. 3 and 800-171A Rev. 3, verbatim, with organization-defined blanks highlighted.

Word by word

The Rev. 2 requirement compared with its Rev. 3 successor. A mechanical comparison of the two verbatim texts, not an interpretation.

removed in Rev. 3 added in Rev. 3

Rev. 2 3.14.5 → Rev. 3 03.14.02 Malicious Code Protection

Implement malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code. Update malicious code protection mechanisms as new releases are available in accordance with configuration management policies and procedures. Configure malicious code protection mechanisms to: Perform periodic scans of organizational systems the system [Assignment: organization-defined frequency] and real-time scans of files from external sources at endpoints or system entry and exit points as the files are downloaded, opened, or executed; and Block malicious code, quarantine malicious code, or take other mitigation actions in response to malicious code detection.

18 words kept, 3 removed, 73 added. Rev. 3 statement labels omitted for the comparison.

What NIST says changed

Rev. 3 withdraws this requirement as a separate item and folds it into another requirement. NIST's note: Addressed by 03.14.02.

NIST's Rev. 3 discussion for 03.14.02

Malicious code insertions occur through the exploitation of system vulnerabilities. Malicious code can be inserted into the system in a variety of ways, including email, the internet, and portable storage devices. Malicious code includes viruses, worms, Trojan horses, and spyware. Malicious code can be encoded in various formats, contained in compressed or hidden files, or hidden in files using techniques such as steganography. Malicious code may be present in commercial off-the-shelf software and custom-built software and could include logic bombs, backdoors, and other types of attacks that could affect organizational mission and business functions. Periodic scans of the system and real-time scans of files from external sources as files are downloaded, opened, or executed can detect malicious code. Malicious code protection mechanisms can also monitor systems for anomalous or unexpected behaviors and take appropriate actions. Malicious code protection mechanisms include signature- and non-signature-based technologies. Non-signature-based detection mechanisms include artificial intelligence techniques that use heuristics to detect, analyze, and describe the characteristics or behavior of malicious code and to provide controls against such code for which signatures do not yet exist or for which existing signatures may not be effective. Malicious code for which active signatures do not yet exist or may be ineffective includes polymorphic malicious code (i.e., code that changes signatures when it replicates). Non-signature-based mechanisms include reputation-based technologies. Pervasive configuration management, anti-exploitation software, and software integrity controls may also be effective in preventing unauthorized code execution. If malicious code cannot be detected by detection methods or technologies, organizations can rely on secure coding practices, configuration management and control, trusted procurement processes, and monitoring practices to help ensure that the software only performs intended functions. Organizations may determine that different actions are warranted in response to the detection of malicious code. For example, organizations can define actions to be taken in response to the detection of malicious code during scans, malicious downloads, or malicious activity when attempting to open or execute files.

What this means for you now

Nothing changes in what you are assessed against until a class deviation or a published rule adopts Rev. 3. Keep meeting 3.14.5 as written in Rev. 2.

Bedrock CMMC shows this same comparison against your own package, with your current status on the Rev. 2 side, so the day adoption lands the migration is a review, not a rewrite.

Back to the Rev. 2 vs Rev. 3 overview

Where this page's facts come from
Rev. 2 text and objectives
bedrock-cmmc-api@89b8e8e:migrations/004_reference_requirements.sql#Requirement.basicRequirement@rev2; bedrock-cmmc-api@89b8e8e:migrations/005_reference_objectives.sql#AssessmentObjective.description@rev2
Mapping and change class
bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/r2_r3_transition_map.json#r2_to_r3
Rev. 3 03.14.02
bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/rev3.json#requirements[]