KB-037

Evidence guide: System and Information Integrity

Applies to
All plans
Last reviewed
October 1, 2026
Version
1.0

EVIDENCE COLLECTION GUIDE • COLLECTING EVIDENCE

Requirements 12 through 15: updates, malware protection, and scanning

KB-037 | Applies to: All plans | Last reviewed: October 1, 2026 | Maintained by AffirmReady Support

System and Information Integrity is about keeping computers patched and protected from malware. The good news is that one or two reports from your antivirus and update tools often cover all four requirements.

Who usually collects this

Your IT provider.

Requirement 12: Find and fix security flaws promptly

What you are showing: operating systems and software receive security updates, and unsupported software is replaced.

  • A patch or update status report covering all company computers, such as from Microsoft Intune or your IT provider's management tool.
  • A screenshot of the update policy showing updates install automatically or on a set schedule.
  • A note confirming no unsupported operating systems are in use, such as Windows 10 without Extended Security Updates, or a plan and date to replace them.

Requirement 13: Protect against malware

What you are showing: antivirus or endpoint protection is installed and running on every company device.

  • A report or console screenshot listing every protected device. Compare it against your device list from the Access Control guide.
  • For a single computer, the Virus and threat protection page in Windows Security showing protection is on.

Requirement 14: Keep malware protection up to date

What you are showing: protection receives the latest updates automatically.

  • A screenshot or report showing the date of the most recent protection update on your devices.
  • The policy or setting showing automatic updates are turned on.

Requirement 15: Scan regularly and scan files from outside sources

What you are showing: real-time protection checks files as they are opened or downloaded, and full scans run on a schedule.

  • A screenshot showing real-time protection is on.
  • The scheduled scan setting, such as a weekly full scan, from your antivirus policy or console.
  • If available, a recent scan history report.
  • If your email service scans attachments, such as Microsoft Defender for Office 365 or the built-in protection in Microsoft 365, a screenshot of that policy is helpful supporting evidence.

Checklist

#EvidenceTypically fromCollected
12Update status report for all devicesIT provider☐
12Automatic update policyIT provider☐
12No unsupported operating systemsIT provider☐
13Protected device listIT provider☐
14Latest protection update dateIT provider☐
14Automatic protection updates settingIT provider☐
15Real-time protection onIT provider☐
15Scheduled scan settingIT provider☐
15Email attachment scanning policyIT provider☐

Where to save it

Save everything from this guide in your own evidence folder under CMMC L1 Evidence / 6 System and Information Integrity, then record the location in AffirmReady for each requirement. AffirmReady does not store evidence files, so your evidence stays in systems your company controls.

Need help?

If you have questions about update or antivirus evidence, Email support@affirmready.com and include your company name and the email address on your AffirmReady account. Our team is available Monday through Friday, 8:00 AM to 5:00 PM Eastern, and typically responds within one business day.

For CMMC Level 1 readiness purposes only. Not legal advice. Your company is responsible for the accuracy of its self-assessment and affirmation.

Did the steps match what you see?

Microsoft and other software change their screens often. If something here looks different on your screen, let us know and we'll update this article.

Please don't include passwords or sensitive company information.
Cloudflare verification

Loading verification…