What are the core benefits of Kaspersky Hybrid Cloud Security CPU Base Plus?
Central management – All workloads managed from Kaspersky Security Center.
CPU licensing – Counts processors in each virtualization host.
Virtual workloads – Protects virtual servers and virtual desktops.
Ransomware defence – Anti-Cryptor blocks encryption on shared network folders.
Cloud inventory – API integration with AWS, Azure and Google Cloud.
Important note – No patch management, SIEM connectors or EDR.
Kaspersky Security Center – Central console, on premises or as a cloud workspace.
Light agent protection – File, process and memory protection on each virtual machine.
Anti-Cryptor for shares – Blocks remote encryption of files on shared network folders.
Host IPS and firewall – Network attack blocking and firewall rules per workload.
Public cloud API – Inventory of AWS, Azure and Google Cloud workloads.
Important – Patch management, SIEM connectors and EDR are not included.
Kaspersky Hybrid Cloud Security is the Standard tier of Kaspersky's protection for virtual servers, virtual desktops and public cloud workloads, and it is the successor to Kaspersky Security for Virtualization. Every protected workload is managed centrally from Kaspersky Security Center, either on premises or as a Cloud Console workspace.
CPU based licensing – Counts processors in the host instead of individual machines.
Shared scanning machine – Light agents send file verdicts to a dedicated SVM.
Lower resource use – Kaspersky states up to 40 percent savings in private clouds.
One policy set – Same rules for on-premises hosts and cloud workloads.
Upgrade path – Standard CPU licences can move up to the Enterprise tier.
Premium support included – Base Plus adds a higher Kaspersky support tier, region dependent.
CPU licensing is only available where you control the hypervisor yourself, so this product fits companies that run their own virtualization hosts rather than renting managed virtual machines. Below is how the typical requirements line up by company size.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | Mostly excluded | By sector | By sector |
| Security questionnaire from large customers | Occasionally | ✓ | ✓ |
| Own hypervisor under your control | Rarely | ✓ | ✓ |
| This product fits | ✕ | ✓ | Enterprise tier |
The Swiss reporting obligation does not apply to every company, but to operators of critical infrastructure such as energy and drinking water suppliers, transport companies, listed hospitals, cloud computing and data centre providers, and cantonal and communal administrations. Since 1 April 2025 these organisations must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery under the revised Information Security Act, with a further 14 days to complete the report; fines for failing to report have applied since 1 October 2025. The product supports this in one concrete way: detections on protected virtual servers and desktops are raised centrally in Kaspersky Security Center with a timestamp, which gives you the discovery moment the 24-hour deadline is measured from and a description of what was blocked. It does not cover the rest of the chain, because this tier has no log inspection, no file integrity monitoring and no SIEM connector, so exporting events to a central log platform or showing which files on a server were changed requires the Enterprise tier or a separate tool. The reporting decision itself also depends on the damage potential of the attack, which is an organisational assessment rather than something software determines. This text is not legal advice, and whether your organisation falls under the reporting obligation should be clarified with a qualified specialist.
No security product makes a company compliant with the NIS 2 Directive, because the directive addresses management responsibility, risk-management processes and reporting procedures rather than the presence of a particular tool. NIS 2 names categories of measures including incident handling, business continuity and backup management, supply chain security, security in acquisition and maintenance including vulnerability handling and disclosure, policies to assess the effectiveness of measures, cryptography, access control and multi-factor authentication. This tier contributes to the incident handling and basic hygiene categories: malware and ransomware protection on virtual and cloud workloads, host intrusion prevention and firewall management, device and web control, and centrally enforced policies across every protected host. The gaps are equally clear, because vulnerability handling and patch management, encryption management, multi-factor authentication, backup and business continuity, and log export for effectiveness assessment are not part of the Standard tier and must be solved elsewhere. Supply chain security under NIS 2 also covers the origin and reliability of your suppliers, which is worth reading together with the next section.
In Switzerland there is no official warning. The National Cyber Security Centre, which became the Federal Office for Cybersecurity (BACS) on 1 January 2024, stated that it does not issue recommendations for or against individual products, that no misuse of Kaspersky antivirus software in Switzerland had been reported to it, and that it would inform the public if it obtained confirmed evidence. In Germany, the Federal Office for Information Security (BSI) has warned against the use of Kaspersky virus protection software since 15 March 2022 and recommends replacing it with alternative products; the warning was originally issued under section 7 of the BSI Act and has been regulated under section 13 since the German NIS 2 implementation act came into force on 6 December 2025. It remains in force. In the United States, the Department of Commerce issued a final determination on 20 June 2024 that prohibited new transactions with Kaspersky from 20 July 2024 and, from 29 September 2024, also prohibited signature and codebase updates and the operation of the Kaspersky Security Network for US persons; this is also still in force. Kaspersky rejects the German warning as not based on a technical assessment of its products, and points to the relocation of its data processing infrastructure to Switzerland with two data centres in Zurich, and to review options such as source code inspection, software bills of materials and external audit results. Independent testing has continued in parallel: Kaspersky business endpoint products were included in the AV-Comparatives Business Security Test for the first half of 2026 and in AV-TEST business Windows client tests up to April 2026. In practice this matters most for public sector contracts, for organisations with a German parent or German public clients, for any US connection, and for supply chain requirements that exclude software of Russian origin; a private company in Switzerland or the European Union is not legally prevented from buying or running the product, and the decision is yours.
Partly, and it is worth knowing in advance which questions it answers. It covers the malware and ransomware protection questions for virtual servers and virtual desktops, centrally enforced security policies, device and web control, role-based access to the management console, protection status and detection reporting out of Kaspersky Security Center, and an inventory of workloads in AWS, Azure and Google Cloud through the cloud API. It does not answer the questions on vulnerability and patch status evidence, file integrity monitoring, log retention and forwarding to a SIEM, endpoint detection and response telemetry with documented response actions, multi-factor authentication, disk encryption, backup and restore testing, or mobile device coverage, and none of these can be produced from this tier by configuration. It also does not help with the questionnaire item on supplier country of origin and official warnings, which no edition can resolve. If the gaps you need to close are patch evidence, file integrity monitoring, log inspection and SIEM export, upgrading to Kaspersky Hybrid Cloud Security Enterprise, CPU covers all four in the same licensing object and the same console, which is usually cheaper and faster to document than adding a second vendor; encryption, backup and multi-factor authentication have to come from elsewhere regardless of the tier you choose.
The single decisive difference is evidence and remediation: only the Enterprise tier includes vulnerability assessment with patch management and SIEM connectors, so only that tier can show an auditor what was unpatched and forward its events into a central log platform. The Standard tier carries the full protection engine and is not a reduced-protection edition; what it lacks are the hardening and audit components. Application Control on server operating systems, which is what a default deny baseline on servers requires, is also Enterprise only. Both tiers use the same CPU licensing object and the same console, and a Standard CPU licence can be upgraded to an Enterprise CPU licence.
| Feature | CPU (Standard) | Enterprise, CPU |
|---|---|---|
| File, process and memory protection | ✓ | ✓ |
| Host IPS/IDS and firewall management | ✓ | ✓ |
| Anti-Cryptor for shared folders | ✓ | ✓ |
| Application Control for desktop OS | ✓ | ✓ |
| Application Control for server OS | ✕ | ✓ |
| Vulnerability assessment and patch management | ✕ | ✓ |
| SIEM connectors | ✕ | ✓ |
| File Integrity Monitor and Log Inspection | ✕ | ✓ |
| NextGen IDS/IPS for VMware NSX | ✕ | ✓ |
The CPU licensing object only applies to virtual machines on hosts whose hypervisor you control, so physical servers and workloads running at a cloud provider are covered by the Server object instead and a CPU licence on its own will not protect them. The agentless deployment path has closed: technical support for Kaspersky Security for Virtualization Agentless ended on 31 July 2026, new licences now include the Light Agent only, security patches for Agentless stopped on the same date, only database updates are available between 1 August 2026 and 1 February 2027, and from 2 February 2027 no support of any kind will be provided, so an existing agentless installation has to be migrated to the Light Agent. The premium support level that comes with a Plus licence is region dependent, because Kaspersky offers the maintenance agreement models according to regional specifics and the available contact levels and terms have to be checked for your country before you rely on a particular response time. Within the Standard tier, the components that most often trigger a follow-up purchase are vulnerability assessment with patch management, SIEM export, file integrity monitoring and log inspection, all of which sit in the Enterprise tier. Container and Kubernetes protection is not part of this product at all and is sold separately as Kaspersky Container Security.
Base identifies a new licence rather than a renewal of an existing one, and the Plus variant is the licence type that carries a premium technical support level from Kaspersky. Plus licences are also the only ones to which Kaspersky Enhanced Support certificates can be added. Which support model is actually offered depends on your country.
The licensing object is the total number of processor cores and physical CPUs installed inside each host that runs protected virtual machines. The number of virtual machines on those hosts is not counted, which is why this model suits environments where the virtual machine count changes often.
No. Container and orchestrator protection is delivered by Kaspersky Container Security, a separate product. Kaspersky Hybrid Cloud Security combined with Kaspersky Container Security forms the Kaspersky Cloud Workload Security offering.