EVIDENCE COLLECTION GUIDE • COLLECTING EVIDENCE
Requirements 12 through 15: updates, malware protection, and scanning
KB-037 | Applies to: All plans | Last reviewed: October 1, 2026 | Maintained by AffirmReady Support
System and Information Integrity is about keeping computers patched and protected from malware. The good news is that one or two reports from your antivirus and update tools often cover all four requirements.
Who usually collects this
Your IT provider.
Requirement 12: Find and fix security flaws promptly
What you are showing: operating systems and software receive security updates, and unsupported software is replaced.
- A patch or update status report covering all company computers, such as from Microsoft Intune or your IT provider's management tool.
- A screenshot of the update policy showing updates install automatically or on a set schedule.
- A note confirming no unsupported operating systems are in use, such as Windows 10 without Extended Security Updates, or a plan and date to replace them.
Requirement 13: Protect against malware
What you are showing: antivirus or endpoint protection is installed and running on every company device.
- A report or console screenshot listing every protected device. Compare it against your device list from the Access Control guide.
- For a single computer, the Virus and threat protection page in Windows Security showing protection is on.
Requirement 14: Keep malware protection up to date
What you are showing: protection receives the latest updates automatically.
- A screenshot or report showing the date of the most recent protection update on your devices.
- The policy or setting showing automatic updates are turned on.
Requirement 15: Scan regularly and scan files from outside sources
What you are showing: real-time protection checks files as they are opened or downloaded, and full scans run on a schedule.
- A screenshot showing real-time protection is on.
- The scheduled scan setting, such as a weekly full scan, from your antivirus policy or console.
- If available, a recent scan history report.
- If your email service scans attachments, such as Microsoft Defender for Office 365 or the built-in protection in Microsoft 365, a screenshot of that policy is helpful supporting evidence.
Checklist
| # | Evidence | Typically from | Collected |
|---|---|---|---|
| 12 | Update status report for all devices | IT provider | ☐ |
| 12 | Automatic update policy | IT provider | ☐ |
| 12 | No unsupported operating systems | IT provider | ☐ |
| 13 | Protected device list | IT provider | ☐ |
| 14 | Latest protection update date | IT provider | ☐ |
| 14 | Automatic protection updates setting | IT provider | ☐ |
| 15 | Real-time protection on | IT provider | ☐ |
| 15 | Scheduled scan setting | IT provider | ☐ |
| 15 | Email attachment scanning policy | IT provider | ☐ |
Where to save it
Save everything from this guide in your own evidence folder under CMMC L1 Evidence / 6 System and Information Integrity, then record the location in AffirmReady for each requirement. AffirmReady does not store evidence files, so your evidence stays in systems your company controls.
Need help?
If you have questions about update or antivirus evidence, Email support@affirmready.com and include your company name and the email address on your AffirmReady account. Our team is available Monday through Friday, 8:00 AM to 5:00 PM Eastern, and typically responds within one business day.