What are the primary benefits of Kaspersky Encryption for Endpoint Add-on?
Central management – Policies and keys run from one console.
Add-on licence – Extends an existing Kaspersky business endpoint licence.
Full disk – Pre-boot authentication and sector-level workstation encryption.
BitLocker management – Recovery keys escrow automatically to the console.
Removable media – USB drives encrypted by policy, not user choice.
Important note – Encryption targets Windows; Linux and mobile excluded.
Download: Kaspersky Encryption for Endpoint Add-on
Full disk encryption – AES-256 sector-level encryption of all workstation hard drive partitions.
Pre-boot authentication – Authentication Agent verifies the user before Windows loads.
BitLocker management – Console-driven BitLocker policies with master key escrow.
File level encryption – Rules encrypt selected folders, extensions and application-created files.
Removable drive encryption – Policy encrypts USB media and password-protected archives for sharing.
Important – No Linux encryption; servers limited to BitLocker only.
Kaspersky Encryption for Endpoint Add-on is a data encryption module that attaches to an existing Kaspersky business endpoint licence and is managed entirely from the Kaspersky Security Center console alongside your anti-malware policies. Distribution catalogues also list it as Kaspersky Lab Encryption for Endpoint, and the same encryption components are already built into the Advanced tier of the same family.
One console – Encryption sits beside anti-malware policies in Kaspersky Security Center.
Lost laptop response – An encrypted stolen notebook reduces a breach to hardware loss.
Password recovery workflow – Helpdesk issues a challenge-response key without reimaging the device.
Encryption reporting – Console reports show which devices are actually encrypted.
USB data control – Removable media encrypted automatically instead of relying on users.
Mixed technology support – Choose Kaspersky Disk Encryption or managed BitLocker per group.
The deciding factor is not headcount but whether you already run Kaspersky Security Center on-premises and need to prove device-level encryption to someone else. A company with ten notebooks and no console gets more from BitLocker managed through Microsoft tooling; a company that already administers Kaspersky policies centrally closes the encryption evidence gap without introducing a second vendor.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | Often |
| NIS 2 in the European Union | Rarely | By sector | Usually |
| Security questionnaire from large customers | ✓ | ✓ | ✓ |
| Central key custody and recovery needed | Optional | ✓ | ✓ |
| This product fits | Limited | ✓ | Partial |
The reporting obligation introduced by the revised Information Security Act applies to operators of critical infrastructure, not to every Swiss company, and it has been in force since 1 April 2025. Affected organisations must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete the report. This add-on supports that process in one specific way: the console records which devices are encrypted and with which technology, so a lost or stolen notebook can be documented as encrypted rather than treated as an uncontrolled outflow of information. It does not detect the attack, does not produce the report, and delivers no encryption evidence for Linux systems, mobile devices or cloud services, so detection, incident response and the reporting workflow itself have to come from other components and from your own organisation. This text is general product information and not legal advice; have your own reporting obligations assessed by qualified legal counsel.
No software product makes a company NIS 2 compliant, because the directive requires organisational risk management measures and holds management personally accountable for them. NIS 2 names measure categories including risk analysis and information system security policies, incident handling, business continuity and backup management, supply chain security, and policies on the use of cryptography and encryption. This add-on addresses the cryptography category directly: enforced full disk encryption on workstations, centrally managed BitLocker and console-held recovery keys are the technical substance behind a written encryption policy. It contributes nothing to incident handling, business continuity, backup or supply chain assessment, and it generates no encryption evidence for Linux servers, mobile fleets or SaaS data. Buyers within scope should treat it as one measure inside a larger programme rather than as a compliance component.
In June 2024 the Bureau of Industry and Security of the US Department of Commerce issued a Final Determination prohibiting Kaspersky from providing anti-virus and cybersecurity products or services in the United States or to US persons. New sales ended on 20 July 2024 and signature and codebase updates ended on 29 September 2024; the determination remains in force and applies to the United States only. Germany's federal information security authority published an advisory in 2022 recommending that users consider alternative products, without banning sales, and several European countries restrict Kaspersky in public sector procurement rather than in general commerce. Kaspersky rejects the allegations, states that the decisions rest on geopolitical assessment rather than technical evaluation, and has offered independent review of its code and update infrastructure through its transparency programme. Independent European testing laboratories have continued to include Kaspersky products in their comparative test cycles. Practically, this matters if you hold public sector contracts, supply a customer whose procurement rules exclude Russian-headquartered vendors, or answer supplier questionnaires that ask about vendor country of origin; for a company with none of those constraints, sales and updates continue normally in Switzerland and the European Union.
Partly, and only for the data-at-rest section. It answers the questions about whether company notebooks are fully encrypted, which algorithm is used, whether encryption is enforced by policy rather than left to the user, who holds the recovery keys, whether removable media is encrypted, and whether you can produce a per-device encryption report on demand. It answers none of the questions about encryption of Linux servers, mobile devices, backups, email or data held with cloud providers, and it says nothing about key rotation schedules, log retention, incident detection or patch status, which are usually the longest sections of the same questionnaire. It also introduces a question rather than closing one: questionnaires that ask about vendor country of origin will surface the Kaspersky assessments described above. To close the remaining technical gaps, moving to the Advanced tier of the same family is normally cheaper and simpler than adding a second encryption vendor, because it keeps one console, one agent and one reporting format.
The decisive difference is that Advanced already contains the encryption components, so the add-on exists only to bring encryption to the Select tier. Beyond encryption, Advanced also adds patch management, adaptive security and system image management, which the add-on does not provide at all. If you expect to need automated patching or vulnerability handling within the same term, comparing the total cost of Select plus this add-on against Advanced is worth doing before you buy, because the add-on route closes exactly one gap.
| Capability | Select + Encryption Add-on | Advanced |
|---|---|---|
| Full disk and file encryption | ✓ | ✓ |
| BitLocker management | ✓ | ✓ |
| Patch management | ✕ | ✓ |
| Adaptive security | ✕ | ✓ |
| System image management | ✕ | ✓ |
| Requires a separate base product | ✓ | ✕ |
Kaspersky Disk Encryption runs on Windows workstation operating systems only; on Windows Server systems and on Arm-based devices, BitLocker is the only available technology. Kaspersky Security Center Cloud Console can manage BitLocker but not Kaspersky Disk Encryption, file level encryption or removable drive encryption, so the full feature set requires the on-premises Administration Console or Web Console, and encryption cannot be used in offline mode because the keys are held in the console. Full disk encryption is not supported on Hyper-V or Citrix virtual desktops, and Kaspersky Disk Encryption is incompatible with other full disk encryption products, so devices already encrypted with a competing tool must be decrypted before migration. There is no encryption coverage for Linux endpoints or mobile devices, which is the most common reason buyers need a second product later. On regional availability, Kaspersky products are prohibited from sale and update in the United States, while sales and updates continue normally in Switzerland and the European Union.
Only in part. The Cloud Console can manage BitLocker, while Kaspersky Disk Encryption, file level encryption and removable drive encryption are configured in the on-premises Administration Console or Web Console.
The encryption components in this add-on are Windows components. macOS startup disks are encrypted with Apple FileVault, which Kaspersky Endpoint Security for Mac can switch on by policy and whose recovery key an administrator can retrieve from Kaspersky Security Center.
The administrator generates a recovery key through a challenge-response exchange in the console, which the user enters at the Authentication Agent screen. If the operating system will not start at all, the FDE restore utility recovers access to the encrypted drive without reimaging.