Photo by Scott Graham on Unsplash
Antivirus requirements for SOC 2 and ISO 27001: MDM enforcement and audit evidence
Antivirus requirements for SOC 2 and ISO 27001 center on a practical question: can you prove employee endpoints run real-time malware protection with current definitions? Frameworks rarely prescribe a vendor, but they expect preventive controls on devices that access production and customer data—and auditors sample endpoints to verify it.
"We use built-in Windows Defender" or "IT installs AV during onboarding" is not evidence. Compliance programs need continuous visibility: protection enabled today, definitions updated this week, exceptions documented and rare.
This guide covers:
- How SOC 2 and ISO 27001 commonly address anti-malware on endpoints
- Technical requirements: real-time protection, updates, and central reporting
- MDM workflows to deploy, verify, and remediate AV gaps
- How Anti-Virus fits SecureSlate's five endpoint security checks
- Evidence artifacts and workflows auditors expect during fieldwork

GIF via GIPHY
Related guides:
Key takeaways
- Real-time protection plus updated definitions is the baseline auditors expect—not install-only checks.
- SOC 2 CC7 and ISO 27001 Annex A themes cover malware defense; exact control mapping depends on your system description.
- MDM verifies AV state on managed devices; it may deploy agents or confirm corporate-standard software is running.
- Anti-Virus is check 2 of 5 in SecureSlate Asset Management—part of the X/5 endpoint security score.
- Remediation tickets prove you detect and fix AV gaps, not just mandate them in policy.
What SOC 2 and ISO 27001 expect
Neither framework publishes a checklist titled "antivirus requirements," but assessors consistently test malware protection on endpoints in scope for the audit.
SOC 2 (Trust Services Criteria)
CC7.x themes address system operations and threat response. While SOC 2 is principles-based, typical system descriptions for SaaS and technology companies include:
- Anti-malware software on employee workstations and laptops
- Automatic signature or definition updates
- Monitoring that protection has not been disabled
Type II audits test operating effectiveness—was AV running throughout the observation period, not only at onboarding?
ISO 27001
Annex A controls around malware protection (commonly mapped to control themes in the 2022 revision) expect:
- Detection, prevention, and recovery controls for malware
- User awareness combined with technical measures
- Regular updates aligned with vendor guidance
ISO certification audits sample endpoints and may compare your Statement of Applicability to actual device configuration.
Customer security reviews
Enterprise questionnaires often ask verbatim: "Is anti-malware deployed on all corporate devices? How do you verify? Frequency?" Align your AV program answers with evidence you can export from MDM and SecureSlate.
Technical antivirus requirements
Build organizational standards around measurable criteria MDM and GRC can monitor:
| Requirement | Typical standard | How to verify |
|---|---|---|
| Real-time / on-access scanning | Enabled | MDM compliance rule or AV console API |
| Definition updates | At least daily check; stale ≤7 days | AV agent report timestamp |
| Agent installed | Approved corporate product | MDM inventory |
| Tamper protection | User cannot disable without admin | AV policy + MDM lock |
| Scan on removable media | Optional but recommended for high-risk roles | AV policy documentation |
macOS endpoints may use XProtect and corporate MDM-verified tools; Windows commonly uses Defender for Endpoint or third-party corporate AV. The compliance question is consistent: approved agent, running, current.
Document approved products in endpoint security policy. Deviations require exception approval—not silent one-off installs.
MDM enforcement for anti-virus
MDM plays two roles in AV compliance:
- Deployment — push approved AV package to new enrollments (when not pre-baked in image)
- Compliance verification — report whether real-time protection is on and definitions meet staleness threshold
Typical workflow:
- Define approved AV list and minimum version in IT standards
- Configure MDM to install or require AV at enrollment
- Create compliance rule: fail if real-time off OR definitions older than N days
- Integrate with conditional access: block corporate apps when AV check fails
- Auto-ticket non-compliant devices; IT remediates or reimages
- Sync compliance status to SecureSlate weekly minimum
For teams using cloud-managed AV (e.g., Defender linked to tenant), MDM may supplement console reporting—what matters is one source of truth GRC can export for auditors.
Offboarding note: AV logs on departing devices may matter for incident investigation. Wipe timing should balance data retention policy with device recovery needs.
Roles and ownership
Clear ownership prevents AV compliance from becoming "someone else's problem" between audit cycles:
| Role | Typical AV responsibilities |
|---|---|
| Security / GRC lead | Map AV controls to framework IDs; define evidence cadence; review fleet pass rates monthly |
| IT / endpoint admin | Maintain approved AV list; configure MDM deployment and compliance rules; remediate failures |
| Helpdesk | Reinstall or re-enable AV when users report conflicts; escalate repeat offenders |
| People Ops | Ensure offboarding triggers device wipe before AV telemetry is lost |
| Executive sponsor | Approve rare exceptions with documented risk acceptance |
When AV compliance sits only in IT without GRC visibility, audit prep rediscovers gaps that continuous monitoring would have surfaced weeks earlier.
Anti-virus vs EDR for compliance
| Capability | Traditional AV | EDR |
|---|---|---|
| Primary focus | Known malware signatures | Behavioral detection, investigation |
| Compliance familiarity | Long-established audit expectation | Increasingly accepted, sometimes requested |
| MDM check fit | Often straightforward pass/fail | May require separate integration |
| Resource impact | Lighter on endpoints | Heavier; more telemetry |
Many mature programs run EDR that satisfies AV requirements—but confirm with your auditor before relying on EDR alone. SecureSlate Anti-Virus check maps to your defined standard: if policy says "Defender real-time on," that is what passes.
Do not assume EDR deployment automatically clears audit samples without configured reporting. Map tools to control language explicitly in your system description.
Decision table — AV program design
| Organization profile | Recommended approach | Evidence source |
|---|---|---|
| Early-stage, mostly macOS | Defender/XProtect + MDM verification | MDM + SecureSlate |
| Mixed fleet, Microsoft shop | Defender for Endpoint | MDE console + MDM |
| Regulated, mature security | Corporate AV + EDR | AV/EDR console + MDM |
| Contractors on personal devices | Require MDM + AV before access | Enrollment gate |
| Air-gapped or dev machines | Isolated network + compensating controls | Exception register |
Choose one row per device class. Complexity creates audit gaps when different teams interpret "protected" differently.
Evidence collection workflow
Structure AV evidence like other continuous controls:
Design evidence
- Endpoint security policy naming AV requirement
- Approved software list and configuration baseline
- MDM profile or deployment documentation
Operating evidence
- Fleet Anti-Virus pass rate over audit period (SecureSlate export)
- Sample devices showing real-time on + definition date
- Remediation tickets for devices that failed and were fixed
- Change records when AV vendor or policy updated
Cadence
| Activity | Owner | Frequency |
|---|---|---|
| Compliance sync | GRC / IT | Weekly |
| Non-compliant remediation | IT | Per SLA (often 48h) |
| Policy review | Security lead | Annual |
| Internal sample audit | GRC | Quarterly |
Auditors may request 10–25 endpoint samples. Pre-build a query: "show all devices that failed AV check during Q2"—if the list is empty or remediated with tickets, operating effectiveness is easy to defend.
Common audit findings
- AV installed but real-time off — user or malware disabled protection
- Stale definitions — laptop offline for weeks; no alert on reconnect
- Developer exemptions — engineering laptops without AV accessing production
- No remediation proof — non-compliant list exists but no tickets closed
- Policy mismatch — policy says daily updates; samples show 30-day-old defs
- Unmanaged devices — contractors outside MDM without compensating control
SecureSlate Anti-Virus check integrated with MDM reduces surprise samples by surfacing failures continuously—not when the auditor connects to VPN.
Anti-Virus check in SecureSlate
SecureSlate Asset Management tracks Anti-Virus as the second of five endpoint security checks. The platform shows:
- Per-device pass/fail for real-time protection and definition freshness (per your configured standard)
- Fleet Anti-Virus compliance rate
- Contribution to X/5 overall endpoint score
- Historical trend for Type II observation windows
- Export mapped to SOC 2 / ISO control IDs
MDM and AV consoles enforce and detail; SecureSlate aggregates for GRC leadership and audit packaging. When Anti-Virus drops fleet-wide after a bad update, you see one chart—not 200 separate support emails.
Streamline AV compliance with SecureSlate
Antivirus requirements for SOC 2 and ISO 27001 are straightforward to describe and easy to fail in practice. SecureSlate connects endpoint AV status to your compliance automation program.
- Anti-Virus check as part of 5/5 SecureSlate Asset Management scoring
- Automated MDM sync for continuous operating evidence
- Framework mapping to CC7 and ISO malware control themes
- Remediation workflows when devices fall out of compliance
- Single export for auditors covering AV alongside encryption, password, screen, and firewall checks
FAQ: Antivirus requirements
Does macOS need third-party antivirus for SOC 2?
Not necessarily. Many programs rely on XProtect plus MDM-verified configuration if policy defines acceptable macOS protection. Confirm with your auditor and document the standard.
Is Windows Defender sufficient?
For many organizations, yes—when real-time protection is on, tamper-protected, and centrally monitored. Enterprise customers may still ask about EDR depth.
How stale can definitions be before failing?
Commonly 7 days maximum; some teams use 24–72 hours for stricter posture. Document your threshold and apply consistently.
What if AV conflicts with developer tools?
Use dedicated dev machine policy with compensating controls (network isolation, no customer data) and documented exceptions—not silent AV disable.
Can MDM install AV silently?
Yes on corporate-owned devices. BYOD may require user consent depending on jurisdiction and policy—see BYOD policy.
How does SecureSlate know AV status?
SecureSlate integrates with MDM and asset sources that report endpoint compliance, aggregating Anti-Virus pass/fail for GRC dashboards and exports.
Disclaimer (legal note)
SecureSlate is not a law firm, and this article does not constitute legal advice or create an attorney-client relationship. Security and compliance obligations vary by industry, contract, and jurisdiction—consult qualified counsel as needed.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds
