Back to GRC

Antivirus requirements for SOC 2 and ISO 27001: MDM enforcement and audit evidence

Photo by Scott Graham on Unsplash

Antivirus requirements for SOC 2 and ISO 27001: MDM enforcement and audit evidence

Antivirus requirements for SOC 2 and ISO 27001 center on a practical question: can you prove employee endpoints run real-time malware protection with current definitions? Frameworks rarely prescribe a vendor, but they expect preventive controls on devices that access production and customer data—and auditors sample endpoints to verify it.

"We use built-in Windows Defender" or "IT installs AV during onboarding" is not evidence. Compliance programs need continuous visibility: protection enabled today, definitions updated this week, exceptions documented and rare.

This guide covers:

  • How SOC 2 and ISO 27001 commonly address anti-malware on endpoints
  • Technical requirements: real-time protection, updates, and central reporting
  • MDM workflows to deploy, verify, and remediate AV gaps
  • How Anti-Virus fits SecureSlate's five endpoint security checks
  • Evidence artifacts and workflows auditors expect during fieldwork

Malware protection scanning

GIF via GIPHY

Related guides:


Key takeaways

  • Real-time protection plus updated definitions is the baseline auditors expect—not install-only checks.
  • SOC 2 CC7 and ISO 27001 Annex A themes cover malware defense; exact control mapping depends on your system description.
  • MDM verifies AV state on managed devices; it may deploy agents or confirm corporate-standard software is running.
  • Anti-Virus is check 2 of 5 in SecureSlate Asset Management—part of the X/5 endpoint security score.
  • Remediation tickets prove you detect and fix AV gaps, not just mandate them in policy.

What SOC 2 and ISO 27001 expect

Neither framework publishes a checklist titled "antivirus requirements," but assessors consistently test malware protection on endpoints in scope for the audit.

SOC 2 (Trust Services Criteria)

CC7.x themes address system operations and threat response. While SOC 2 is principles-based, typical system descriptions for SaaS and technology companies include:

  • Anti-malware software on employee workstations and laptops
  • Automatic signature or definition updates
  • Monitoring that protection has not been disabled

Type II audits test operating effectiveness—was AV running throughout the observation period, not only at onboarding?

ISO 27001

Annex A controls around malware protection (commonly mapped to control themes in the 2022 revision) expect:

  • Detection, prevention, and recovery controls for malware
  • User awareness combined with technical measures
  • Regular updates aligned with vendor guidance

ISO certification audits sample endpoints and may compare your Statement of Applicability to actual device configuration.

Customer security reviews

Enterprise questionnaires often ask verbatim: "Is anti-malware deployed on all corporate devices? How do you verify? Frequency?" Align your AV program answers with evidence you can export from MDM and SecureSlate.


Technical antivirus requirements

Build organizational standards around measurable criteria MDM and GRC can monitor:

Requirement Typical standard How to verify
Real-time / on-access scanning Enabled MDM compliance rule or AV console API
Definition updates At least daily check; stale ≤7 days AV agent report timestamp
Agent installed Approved corporate product MDM inventory
Tamper protection User cannot disable without admin AV policy + MDM lock
Scan on removable media Optional but recommended for high-risk roles AV policy documentation

macOS endpoints may use XProtect and corporate MDM-verified tools; Windows commonly uses Defender for Endpoint or third-party corporate AV. The compliance question is consistent: approved agent, running, current.

Document approved products in endpoint security policy. Deviations require exception approval—not silent one-off installs.


MDM enforcement for anti-virus

MDM plays two roles in AV compliance:

  1. Deployment — push approved AV package to new enrollments (when not pre-baked in image)
  2. Compliance verification — report whether real-time protection is on and definitions meet staleness threshold

Typical workflow:

  1. Define approved AV list and minimum version in IT standards
  2. Configure MDM to install or require AV at enrollment
  3. Create compliance rule: fail if real-time off OR definitions older than N days
  4. Integrate with conditional access: block corporate apps when AV check fails
  5. Auto-ticket non-compliant devices; IT remediates or reimages
  6. Sync compliance status to SecureSlate weekly minimum

For teams using cloud-managed AV (e.g., Defender linked to tenant), MDM may supplement console reporting—what matters is one source of truth GRC can export for auditors.

Offboarding note: AV logs on departing devices may matter for incident investigation. Wipe timing should balance data retention policy with device recovery needs.

Roles and ownership

Clear ownership prevents AV compliance from becoming "someone else's problem" between audit cycles:

Role Typical AV responsibilities
Security / GRC lead Map AV controls to framework IDs; define evidence cadence; review fleet pass rates monthly
IT / endpoint admin Maintain approved AV list; configure MDM deployment and compliance rules; remediate failures
Helpdesk Reinstall or re-enable AV when users report conflicts; escalate repeat offenders
People Ops Ensure offboarding triggers device wipe before AV telemetry is lost
Executive sponsor Approve rare exceptions with documented risk acceptance

When AV compliance sits only in IT without GRC visibility, audit prep rediscovers gaps that continuous monitoring would have surfaced weeks earlier.


Anti-virus vs EDR for compliance

Capability Traditional AV EDR
Primary focus Known malware signatures Behavioral detection, investigation
Compliance familiarity Long-established audit expectation Increasingly accepted, sometimes requested
MDM check fit Often straightforward pass/fail May require separate integration
Resource impact Lighter on endpoints Heavier; more telemetry

Many mature programs run EDR that satisfies AV requirements—but confirm with your auditor before relying on EDR alone. SecureSlate Anti-Virus check maps to your defined standard: if policy says "Defender real-time on," that is what passes.

Do not assume EDR deployment automatically clears audit samples without configured reporting. Map tools to control language explicitly in your system description.


Decision table — AV program design

Organization profile Recommended approach Evidence source
Early-stage, mostly macOS Defender/XProtect + MDM verification MDM + SecureSlate
Mixed fleet, Microsoft shop Defender for Endpoint MDE console + MDM
Regulated, mature security Corporate AV + EDR AV/EDR console + MDM
Contractors on personal devices Require MDM + AV before access Enrollment gate
Air-gapped or dev machines Isolated network + compensating controls Exception register

Choose one row per device class. Complexity creates audit gaps when different teams interpret "protected" differently.


Evidence collection workflow

Structure AV evidence like other continuous controls:

Design evidence

  • Endpoint security policy naming AV requirement
  • Approved software list and configuration baseline
  • MDM profile or deployment documentation

Operating evidence

  • Fleet Anti-Virus pass rate over audit period (SecureSlate export)
  • Sample devices showing real-time on + definition date
  • Remediation tickets for devices that failed and were fixed
  • Change records when AV vendor or policy updated

Cadence

Activity Owner Frequency
Compliance sync GRC / IT Weekly
Non-compliant remediation IT Per SLA (often 48h)
Policy review Security lead Annual
Internal sample audit GRC Quarterly

Auditors may request 10–25 endpoint samples. Pre-build a query: "show all devices that failed AV check during Q2"—if the list is empty or remediated with tickets, operating effectiveness is easy to defend.


Common audit findings

  • AV installed but real-time off — user or malware disabled protection
  • Stale definitions — laptop offline for weeks; no alert on reconnect
  • Developer exemptions — engineering laptops without AV accessing production
  • No remediation proof — non-compliant list exists but no tickets closed
  • Policy mismatch — policy says daily updates; samples show 30-day-old defs
  • Unmanaged devices — contractors outside MDM without compensating control

SecureSlate Anti-Virus check integrated with MDM reduces surprise samples by surfacing failures continuously—not when the auditor connects to VPN.


Anti-Virus check in SecureSlate

SecureSlate Asset Management tracks Anti-Virus as the second of five endpoint security checks. The platform shows:

  • Per-device pass/fail for real-time protection and definition freshness (per your configured standard)
  • Fleet Anti-Virus compliance rate
  • Contribution to X/5 overall endpoint score
  • Historical trend for Type II observation windows
  • Export mapped to SOC 2 / ISO control IDs

MDM and AV consoles enforce and detail; SecureSlate aggregates for GRC leadership and audit packaging. When Anti-Virus drops fleet-wide after a bad update, you see one chart—not 200 separate support emails.


Streamline AV compliance with SecureSlate

Antivirus requirements for SOC 2 and ISO 27001 are straightforward to describe and easy to fail in practice. SecureSlate connects endpoint AV status to your compliance automation program.

  • Anti-Virus check as part of 5/5 SecureSlate Asset Management scoring
  • Automated MDM sync for continuous operating evidence
  • Framework mapping to CC7 and ISO malware control themes
  • Remediation workflows when devices fall out of compliance
  • Single export for auditors covering AV alongside encryption, password, screen, and firewall checks

Get started for free


FAQ: Antivirus requirements

Does macOS need third-party antivirus for SOC 2?

Not necessarily. Many programs rely on XProtect plus MDM-verified configuration if policy defines acceptable macOS protection. Confirm with your auditor and document the standard.

Is Windows Defender sufficient?

For many organizations, yes—when real-time protection is on, tamper-protected, and centrally monitored. Enterprise customers may still ask about EDR depth.

How stale can definitions be before failing?

Commonly 7 days maximum; some teams use 24–72 hours for stricter posture. Document your threshold and apply consistently.

What if AV conflicts with developer tools?

Use dedicated dev machine policy with compensating controls (network isolation, no customer data) and documented exceptions—not silent AV disable.

Can MDM install AV silently?

Yes on corporate-owned devices. BYOD may require user consent depending on jurisdiction and policy—see BYOD policy.

How does SecureSlate know AV status?

SecureSlate integrates with MDM and asset sources that report endpoint compliance, aggregating Anti-Virus pass/fail for GRC dashboards and exports.


Disclaimer (legal note)

SecureSlate is not a law firm, and this article does not constitute legal advice or create an attorney-client relationship. Security and compliance obligations vary by industry, contract, and jurisdiction—consult qualified counsel as needed.

Need compliance without the complexity?

SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.

Find compliance gaps in 30 seconds

Filed under:

Author: SecureSlate Team

4.7(203 reviews)

Keep reading

Aug 12, 2026 · GRC

Building an endpoint security baseline for startups

Aug 12, 2026 · GRC

BYOD and MDM: balancing flexibility and endpoint security

Aug 12, 2026 · GRC

Common MDM security check failures and how to fix them

View more posts
Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?