cmmc remote worker antivirus scanning requires an organization to define how often managed systems receive malicious-code scans, perform those scans on schedule, and automatically scan externally sourced files when they are downloaded, opened, or executed. For CMMC 2.0 Level 2 and NIST SP 800-171 Rev. 2 SI.L2-3.14.5, remote work does not reduce the obligation: laptops, virtual desktops, and other systems that process CUI must remain covered by centrally managed anti-malware protections and auditable scan evidence.
The practical goal is straightforward: a file arriving through email, a supplier portal, cloud storage, removable media, a browser download, or a collaboration platform should be evaluated before it can harm a system or expose Controlled Unclassified Information. Periodic scanning provides the second layer by checking files already stored on endpoints against newly updated malware signatures and detection logic.
What does SI.L2-3.14.5 require an organization to do?
SI.L2-3.14.5 requires three distinct outcomes. First, the organization defines a frequency for malicious-code scans. Second, it performs scans at that frequency. Third, it performs real-time scans of externally sourced files as they are downloaded, opened, or executed.
A vCISO should help clients avoid treating this as a simple “antivirus installed” control. Assessors commonly need to see that the anti-malware tool is enabled, centrally managed, updated, configured for real-time protection, and producing evidence that periodic scans actually ran. A license invoice, a screenshot of a product logo, or an endpoint agent deployment report alone does not establish all three objectives.
- Defined frequency: A written standard identifies when full or targeted scans occur, such as weekly full scans and daily quick scans.
- Performed frequency: Management reports, scan histories, or SIEM logs demonstrate that devices completed scheduled scans and that failures are investigated.
- Real-time external-file scanning: On-access protection evaluates files arriving from outside the environment before users open, save, or run them.
Why is cmmc remote worker antivirus scanning different from office-only scanning?
Remote endpoints operate outside the organization’s network perimeter for long periods. They may connect through residential routers, personal internet service providers, public networks, home printers, personal cloud storage, and supplier collaboration sites. This makes endpoint enforcement and reporting more important, not less.
For remote users, the anti-malware agent must continue enforcing policy when the user is not connected to a corporate VPN. Cloud-managed platforms such as Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne Singularity, and Sophos Central are often practical because policies, alerts, signature updates, and scan-status reporting can operate over the internet.
Remote worker anti-malware scanning should also account for laptops that are powered off during an assigned scan window. The policy should state whether the tool retries at next check-in, runs missed scans on startup, or escalates devices that have not checked in within a defined period.
What counts as a file from an external source?
An external source is any origin outside the controlled system or trusted internal process. The definition is broader than email attachments. A defensible implementation includes browser downloads, email attachments, files synchronized from cloud collaboration platforms, removable media, files transferred through supplier portals, chat attachments, and files obtained through remote-access sessions.
For example, a 420-person manufacturer of aircraft brackets and machined aerospace components may receive customer drawings, inspection plans, and supplier certificates through Microsoft 365, a customer-managed secure portal, and a managed file-transfer service. The files may be PDFs, STEP models, CNC program archives, spreadsheets, or compressed packages. Each inbound source should be included in the endpoint protection policy, even if the organization considers the sender to be a trusted customer or supplier.
Trusting a supplier is not the same as trusting every file delivered from that supplier. Supplier mailboxes, portals, and workstations can be compromised, and malicious files may be disguised as routine production documentation.
How should periodic scans be defined and scheduled?
The scan frequency should be risk-based, realistic for the endpoint fleet, and written in a policy or endpoint security standard. There is no single CMMC-mandated interval, but an organization must be able to explain why its schedule is appropriate and show that it is enforced.
A commonly supportable baseline is daily quick scanning, weekly full scanning, real-time protection at all times, and immediate scans when a removable device is connected. Devices that are frequently disconnected may need a catch-up requirement. Avoid scheduling full scans only during a narrow overnight window if remote laptops are routinely shut down then.
| Endpoint protection setting | Example baseline | Evidence to retain |
|---|---|---|
| Real-time protection | Enabled continuously; scan downloaded and opened files | Central policy export and endpoint compliance report |
| Quick scan | Daily at 12:30 p.m. local device time | Scheduled task status and scan-completion logs |
| Full scan | Weekly Sunday at 2:00 a.m.; run missed scan at next device check-in | Weekly scan report and exception tickets |
| Security intelligence updates | Cloud-delivered protection enabled; update check every 4 hours | Update compliance dashboard and alert records |
| Removable media | Scan on insertion; block unauthorized USB storage where feasible | Device-control policy and endpoint event logs |
How do real-time scans protect files as they are downloaded, opened, or executed?
Real-time scanning, sometimes called on-access or behavior-based protection, evaluates a file during user activity rather than waiting for the next scheduled scan. The anti-malware engine may use signatures, reputation, cloud-based analysis, exploit detection, behavioral indicators, and attack-surface reduction rules.
For SI.L2-3.14.5, configure the product so it does not merely alert after execution. The intended control behavior is to inspect external files at the download, open, or execution event and block or quarantine malicious content where the product can do so. Any exclusions must be documented, narrowly scoped, approved, time-limited, and reviewed.
In the aerospace manufacturing example, an engineering team may use CAD/CAM tools that create large temporary files and archives. Rather than broadly excluding an engineering workstation or an entire project share from scanning, document a tested, path-specific exclusion for the exact application cache if needed. Maintain real-time scanning for downloaded archives, macros, executable installers, and files received from external portals.
What evidence will support compliance during an assessment?
A strong evidence package ties written requirements to technical configuration and operating records. The assessor should be able to follow the chain from policy, to endpoint management settings, to representative endpoint logs, to remediation of failed or unhealthy devices.
- The malicious-code protection policy or system security plan statement identifying periodic scan frequency and real-time scanning requirements.
- A central-console screenshot or export showing the active anti-malware policy, scan schedules, tamper protection, signature-update configuration, and external media settings.
- A device inventory showing that systems used to process, store, or transmit CUI have the required agent installed and reporting.
- Scan-completion reports covering a representative period, such as the prior 90 days.
- Alerts, tickets, or case records showing how missed scans, inactive agents, malware detections, and outdated signatures are addressed.
- Approved exclusion records, including business justification, scope, owner, approval date, and review date.
How should a vCISO implement SI.L2-3.14.5 step by step?
- Define the scope. Identify endpoints that process CUI, including remote laptops, engineering workstations, virtual desktops, and administrator systems. Confirm whether personally owned devices are prohibited or technically controlled.
- Select or validate the endpoint protection platform. Confirm the platform supports centrally enforced real-time scanning, scheduled scans, cloud reporting, tamper protection, and retention of security events.
- Write the scan standard. Define full-scan frequency, quick-scan frequency, missed-scan handling, update requirements, removable-media treatment, exclusions, alert triage, and escalation timelines.
- Deploy and enforce the policy. Use Intune, Group Policy, an RMM tool, or the endpoint security console to apply settings consistently. Do not rely on users to configure their own protection.
- Test the control safely. Validate download and execution protections using the EICAR test file in accordance with your organization’s testing procedure. Record the result and confirm that the file is blocked or quarantined.
- Monitor operational health. Review agent status, signature currency, scan success, and unremediated detections at least monthly. Establish a remediation workflow for endpoints that stop reporting.
- Preserve evidence. Export quarterly reports and retain policy versions, dashboards, exceptions, and remediation tickets according to the organization’s assessment-evidence retention practices.
Microsoft Defender for Endpoint baseline example Real-time protection: Enabled Behavior monitoring: Enabled Cloud-delivered protection: Enabled Scan downloaded files and attachments: Enabled PUA protection: Block Daily quick scan: 12:30 local time Weekly full scan: Sunday 02:00 local time Catch up full scan: Enabled Tamper protection: Enabled USB scan on insertion: Enabled
What is the SI.L2-3.14.5 compliance checklist?
- □ The organization has identified all CUI-capable remote endpoints in scope.
- □ A written standard defines the periodic malicious-code scan frequency.
- □ Real-time protection is enabled on managed endpoints.
- □ Downloaded, opened, and executed files are scanned or evaluated by the endpoint protection platform.
- □ Email attachments, browser downloads, cloud-synchronized files, removable media, and supplier-portal downloads are covered.
- □ Scheduled scans run automatically and missed scans are retried or escalated.
- □ Malware definitions, engines, and cloud protection services are kept current.
- □ Endpoint protection health is monitored from a central console.
- □ Scan failures, inactive agents, and malware detections generate documented remediation actions.
- □ Exclusions are minimal, approved, periodically reviewed, and supported by business justification.
- □ Policy documents, configuration exports, scan reports, and remediation records are retained as assessment evidence.
Frequently asked questions about remote file scanning
Does SI.L2-3.14.5 require a full antivirus scan every day?
No. The requirement does not prescribe a daily full scan. It requires the organization to define a frequency and perform scans at that frequency. Daily quick scans combined with weekly full scans and continuous real-time protection are a common, supportable approach when documented and enforced.
Does Microsoft Defender satisfy CMMC SI.L2-3.14.5?
Microsoft Defender can support the practice when it is properly configured and centrally managed. The organization still needs evidence that real-time protection, scheduled scans, update settings, alert handling, and endpoint coverage are operating as required. Product selection alone does not equal compliance.
Do remote workers need to connect to the VPN for antivirus scans?
Not necessarily. Cloud-managed endpoint protection can receive policies, updates, and report status directly over the internet. If a client relies on an on-premises management server, however, it must establish how remote systems receive updates and report scan results while away from the office.
Are files in OneDrive, SharePoint, or Teams considered external files?
They can be, particularly when content originates from customers, suppliers, external collaborators, or unmanaged devices. Configure endpoint and cloud protections so synced or downloaded files are inspected, and avoid assuming that a file is safe simply because it appears in a corporate collaboration folder.
Can we exclude engineering or CAD folders because scans affect performance?
Only with a documented, narrowly tailored exception. Test the actual performance issue, exclude the smallest viable path or process, obtain approval, set a review date, and preserve scanning for incoming files and executable content. Broad exclusions can undermine both security and assessment defensibility.
Next step: Have your endpoint-management owner produce a 90-day scan-completion and real-time-protection report, then use it with your vCISO to identify coverage gaps before your next CMMC readiness review.