Uniqcli

CMMC control families

CMMC System & Information Integrity (3.14 SI): 7 requirements, patching and endpoints

Seven requirements about fixing flaws, blocking malicious code and noticing attacks. This is the deepest licensing family in our catalog — endpoint, email and gateway platforms, plus the appliances under them and the rollout work on top. What no line item covers is the deciding and the doing, and we will say so before you ask.

Family
3.14 — System & Information Integrity
Requirements
7 of the 110 Level 2 requirements
Level 1
In scope — basic requirements from this family
Boundary
The capability behind the control — never a certification we hold
Overview

Fix the flaws, block the code, notice the attack

System and information integrity carries seven requirements: identify, report and correct system flaws in a timely manner (3.14.1); provide protection from malicious code at designated locations (3.14.2); monitor security alerts and advisories and take action (3.14.3); update malicious-code protection mechanisms as new releases arrive (3.14.4); perform periodic scans and real-time scans of files from external sources (3.14.5); monitor the system, including inbound and outbound traffic, to detect attacks and indicators of potential attacks (3.14.6); and identify unauthorized use of the system (3.14.7). Most of that has a subscription behind it, and this is the deepest licensing family in our catalog — endpoint and extended-detection platforms, email and gateway filtering, application control, the appliances the gateway subscriptions run on, and the rollout work that gets an agent onto every machine in scope. The remainder is a habit: defining the timeline, acting on the advisory, applying the update. The habit is the part that fails assessments, and no invoice reaches it.

Levels

What each level asks of this family

System and information integrity is one of the six families Level 1 touches. The FAR 52.204-21 basics that land here are about identifying and correcting flaws in a timely manner, providing protection from malicious code, keeping those mechanisms current, and running periodic and real-time scans of files from external sources.

Level 2 adds the monitoring end: advisories acted on under 3.14.3, traffic monitored for attack indicators under 3.14.6, and unauthorized use identified under 3.14.7. Note that 3.14.1 names no interval — "timely" is a period you define, write down and then have to hold, and the split between what gets patched here and what gets scanned under 3.11.2 is worth settling explicitly in the SSP because assessors read them together.

Level 3 layers enhanced requirements from NIST SP 800-172 onto a Final Level 2, assessed by DIBCAC.

What's quotable

What you can actually quote against this family

Each card names the requirement the line serves — hardware, software licensing or the integration work that puts either into service. Naming a control is not a coverage claim: the configuration, the procedure and the evidence stay inside your program, and no purchase — hardware, license or service — confers certification on its own. Naming a manufacturer describes the market, not a Uniqcli partnership or endorsement.

Endpoint and extended detection (3.14.2, 3.14.4, 3.14.5)

This is the deepest software line we carry. Sophos Intercept X, its endpoint-detection and extended-detection tiers are priced across tens of thousands of rows, with McAfee, Trend Micro, Bitdefender's GravityZone, ESET, Check Point and Barracuda alongside. Software is sourced through authorized US distribution rather than held on a shelf, so availability language does not apply to it. We do not carry every endpoint brand you may be running, and we will tell you plainly when a name is not in our catalog rather than promising to find it.

Flaw-remediation tooling (3.14.1)

Patching is a process, not a product — but the tooling that finds the missing update and reports what is still outstanding is licensable. Bitdefender's GravityZone patch modules and the equivalent configuration and policy lines from WatchGuard and Trend Micro are all priced in our catalog. The timeline you define, the exception path and the act of applying the update stay yours.

Application control (3.14.2)

Where malicious-code protection is answered by controlling what may execute rather than by detecting what should not, ThreatLocker's allowlisting and ringfencing lines are priced in our catalog and quoted per endpoint. It is one recognized way of implementing the permit-by-exception position, not the only one — and the policy it enforces is yours to write.

Email and gateway filtering (3.14.2, 3.14.6)

"Designated locations" usually means the gateway as much as the endpoint. Proofpoint carries thousands of priced rows in our licensing catalog for email and gateway filtering, with SonicWall, WatchGuard, Barracuda and Check Point gateway subscriptions alongside. Same rule: subscriptions are quoted against the renewal date, and availability language does not apply to them.

The appliance the subscription runs on

Gateway subscriptions need something to run on, and that half is genuine hardware. SonicWall and WatchGuard appliances are genuinely stocked; Palo Alto Networks, Sophos, Check Point and Barracuda appliance rows are priced but not stocked, so those are lead-time lines. The quote pairs the appliance with the right subscription term rather than leaving them to be reconciled later.

Getting the agent onto every machine

A platform bought is not a platform deployed, and the gap between them is where 3.14.2's "designated locations" quietly goes unmet. Agent rollout, gateway configuration and the endpoint imaging that carries the build are scoped alongside the licenses, with the configuration and change records captured as the work happens.

Limits

What stays yours to run

The tooling behind 3.14.1 is quotable; the remediation is not. Nothing in our catalog decides your timeline, judges an exception or applies an update to a system you own, and a supplier quoting a coverage claim against 3.14.1 is quoting you something else. The same is true of 3.14.3: acting on advisories is a habit, and the evidence is a record of having acted. The program stays yours to run — the policy, the decisions, the cadence and the evidence an assessor actually reads. What a supplier puts behind it is the tooling, the licensing and the integration work.

For the requirements that do have a license behind them, the license is still not the control. A subscription that expired, or that nobody tuned, satisfies nothing. We supply the capability behind the control — the appliance, the license and the work of putting them in service — never a certification we hold.

We are not an assessor, a C3PAO or an RPO, and we hold no CMMC level. We quote against the SSP you already have — hardware, licensing and the integration work around them — not a generic bundle assembled around a level number.

Questions

Patching and endpoint questions

How quickly does CMMC require security patches to be applied?

No number appears in the standard. 3.14.1 requires system flaws to be identified, reported and corrected in a timely manner, which means the interval is yours to define in the SSP and then meet consistently. Assessors look for a defined timeline, evidence that it is followed, and a documented exception path for the cases where it cannot be.

Does CMMC require antivirus or EDR?

3.14.2 requires protection from malicious code at designated locations within organizational systems, and 3.14.4 and 3.14.5 require those mechanisms to be updated and to scan periodically and in real time on files from external sources. No product category is named. What matters is that the designated locations are defined and that something is actually protecting them.

What does flaw remediation mean under 3.14.1?

Identifying flaws — through advisories, vendor notices and your own scanning — reporting them into a process, and correcting them within the timeline you defined. It overlaps deliberately with 3.11.2 and 3.11.3 in the risk assessment family, so it is worth writing down which process owns which half rather than discovering the gap during an assessment.

Is system and information integrity part of CMMC Level 1?

Yes. It is one of the six families Level 1 touches, alongside access control, identification and authentication, media protection, physical protection, and system and communications protection. Those six share the 15 FAR 52.204-21 requirements a Level 1 self-assessment covers; the monitoring requirements at 3.14.6 and 3.14.7 arrive at Level 2.

Get a CMMC estimate — CMMC System & Information Integrity (3.14 SI)

Tell us where to reach you and a Uniqcli specialist follows up by email to scope what you need across hardware, software licensing and integration, then comes back with pricing and availability — quoted against the SSP you already have, not a generic bundle.

An estimate for the capability behind the control — never a certification we hold. No purchase — hardware, license or service — confers a CMMC level on its own; what you buy makes the controls implementable.

Do not submit classified information, CUI, restricted FCI, export-controlled technical data, protected health information, payment-card data, passwords, or private keys through this form. Contact your Uniqcli representative or [email protected] to request an approved channel.

CUI, FCI and secure submission notice

Ask AI about Uniqcli

CMMC System & Information Integrity (3.14 SI)

Talk to us about endpoint and gateway licensing

Send the seat count, the renewal date and the appliance it runs on. A Uniqcli specialist replies with an estimate for the subscriptions, the appliances under them and any rollout work the deployment needs — quoted against your term, availability stated per line, and no claim that a license closes a requirement on its own.