What are the key advantages of Kaspersky Hybrid Cloud Security CPU Base?
Central management – All virtual workloads controlled from Kaspersky Security Center.
Light agent – Shared scan cache lowers virtualization resource use.
Hypervisor coverage – VMware, Hyper-V, Citrix, KVM and Proxmox supported.
Server workloads – Protects virtualized Windows and Linux server guests.
Ransomware rollback – Blocks encryption and restores the affected files.
Important note – No EDR, patch management or encryption included.
Download: Kaspersky Hybrid Cloud Security CPU Base
Light Agent protection – Anti-malware for virtual machines using a shared Security Virtual Machine.
Hypervisor platform support – VMware vSphere, Hyper-V, Citrix Hypervisor, KVM and Proxmox VE.
Windows and Linux guests – Covers virtualized Windows Server and common Linux server distributions.
Anti-ransomware and rollback – Blocks encryption attempts and restores modified files afterwards.
Central management console – Policies, roles and reports through Kaspersky Security Center.
Important – No EDR, patch management, encryption or macOS coverage included.
Kaspersky Hybrid Cloud Security CPU Base is the Standard edition of Kaspersky's workload protection for virtual machines, licensed against the physical CPUs in the virtualization hosts you control and managed centrally from Kaspersky Security Center. The components delivered under this name are Kaspersky Security for Virtualization Light Agent and Agentless, so buyers who still search for the older Kaspersky Security for Virtualization name arrive at the same technology.
Lower virtualization overhead – Shared scan cache avoids rescanning identical files across VMs.
Stable count under growth – CPU licensing absorbs changing virtual machine numbers per host.
Failover between hosts – Light agents switch to another SVM when one fails.
Faster VDI provisioning – Cloned desktops are protected without updating the golden image.
Role-based administration – Kaspersky Security Center separates policy, audit and operator duties.
Swiss data processing – Threat data from European users is processed in Zurich.
This licence type only makes sense if you run your own hypervisor hosts and control the virtualization layer. Companies that rent virtual machines from a provider, or run everything on physical servers, cannot use per-CPU licensing and need a workload-based licence instead.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | ✕ | By sector | ✓ |
| Security questionnaire from large customers | Sometimes | ✓ | ✓ |
| Own hypervisor hosts under your control | Rarely | ✓ | ✓ |
| This product fits | ✕ | ✓ | ✓ |
No security product makes a company compliant, and this one is no exception. Under the revised Information Security Act, operators of critical infrastructure must report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, and whether your organisation falls under that duty depends on sector and role rather than on headcount. The product supports the duty in one narrow way: the Kaspersky Security Center console records detections, blocked network attacks and remediation actions on protected virtual machines, which is the material an administrator needs in order to describe an incident inside the reporting window. It does not cover the parts that usually decide whether a report can be filed on time, because there is no incident case management, no forensic timeline across systems, and no cross-system log retention. In this Standard edition there is also no log inspection and no file integrity monitoring, so configuration drift and tampering on protected servers are not evidenced. This text is a product description and not legal advice.
No product creates NIS 2 compliance, because the directive obliges organisations to establish risk management measures and processes, not to buy specific software. NIS 2 names measure categories including risk analysis and security policies, incident handling, business continuity and backup, supply chain security, vulnerability handling, cryptography, access control, multi-factor authentication and cyber hygiene. This product contributes to a limited number of them: malware protection and system hardening for virtualized workloads, application, device and web control on protected guests, and centrally enforced policies with role separation in the console. It contributes nothing to backup and business continuity, cryptography and encryption management, multi-factor authentication, supply chain assessment or staff training. In the Standard edition it also leaves vulnerability handling and audit-grade logging open, because vulnerability assessment, patch management, file integrity monitoring, log inspection and SIEM export sit in the Enterprise edition of the same family.
In Switzerland, the Federal Office for Cybersecurity (BACS) has issued neither a warning nor a ban concerning Kaspersky. BACS has stated that no misuse of Kaspersky software has been reported to it, that it only warns where it has confirmed technical indications of a security risk, and that the decision therefore rests with each organisation. In Germany, the Federal Office for Information Security (BSI) published a formal product warning on 15 March 2022 recommending that Kaspersky anti-virus software be replaced with alternative products; that warning remains published and in force, and the BSI states in its own FAQ that use of the products is not prohibited in Germany. In the United States, the Department of Commerce issued a Final Determination on 20 June 2024 that barred Kaspersky from entering new agreements with US persons from 20 July 2024 and from supplying signature and codebase updates, or operating the Kaspersky Security Network on US systems, from 29 September 2024. Kaspersky rejects the German warning as not based on an objective technical analysis of its software, has asked the BSI to withdraw or amend it, and points to its Zurich data centres and Transparency Center as evidence of its position. The authority statements concern trust in the vendor's country of origin and supply chain rather than a published technical defect in the product, and Kaspersky continues to take part in independent laboratory testing. In practice this matters most if you bid for public sector contracts, supply German federal customers, answer supplier questionnaires that ask about vendor origin, or belong to a group with US entities.
Partly. It answers the items on malware protection for server and desktop workloads, centrally enforced and documented policies, role-based access and duty separation in the administration console, application allowlisting on desktop guests, control over removable devices in VDI sessions, network attack blocking, ransomware rollback, and where threat data from European users is processed, which is Zurich. It does not answer the items on endpoint detection and response, telemetry scope and retention periods, patch and vulnerability status reporting, file integrity monitoring and log inspection evidence, disk encryption, multi-factor authentication, backup and restore testing, mobile device management, or macOS coverage, and it will raise rather than close the country-of-origin question that increasingly appears in supplier due diligence. To close the technical gaps, moving to the Enterprise edition of the same family is normally the cheaper route than mixing vendors, because it adds Application Control for server operating systems, file integrity monitoring, log inspection, vulnerability assessment and patch management, container security and SIEM connectors under one console. Detection and response has to come from a separate Kaspersky product, and no edition change addresses the vendor-origin question.
The decisive difference is that everything an auditor typically asks to see, meaning file integrity monitoring, log inspection and application allowlisting on server operating systems, sits in the Enterprise edition only. This SKU is the Standard edition, which delivers the protection engine and the controls for desktop guests. Enterprise additionally covers vulnerability assessment and patch management, container and DevOps scanning, SIEM connectors and IDS/IPS for VMware NSX. Kaspersky permits an upgrade from Standard CPU to Enterprise CPU, so starting on Standard does not lock you out of the Enterprise feature set later.
| Capability | Standard (this product) | Enterprise |
|---|---|---|
| Anti-malware for Windows and Linux guests | ✓ | ✓ |
| Application Control for desktop guests | ✓ | ✓ |
| Anti-Cryptor for shared folders | ✓ | ✓ |
| Application Control for server operating systems | ✕ | ✓ |
| File Integrity Monitoring | ✕ | ✓ |
| Log Inspection | ✕ | ✓ |
| Vulnerability assessment and patch management | ✕ | ✓ |
| Container security and DevOps integration | ✕ | ✓ |
| SIEM connectors | ✕ | ✓ |
| IDS/IPS for VMware NSX | ✕ | ✓ |
Per-CPU licensing applies only to virtual machines running on hypervisors you control yourself; physical servers and workloads hosted in a public cloud must be licensed per workload, so a mixed estate needs a second licence type alongside this one. Guest operating system coverage is Windows and Linux, with no macOS agent, which leaves Mac desktops and Mac build machines outside the deployment. Since the US Department of Commerce prohibition took effect, Kaspersky cannot supply its cybersecurity products to US persons, so a Swiss or European group cannot extend this deployment to a US subsidiary or to US-resident staff, and the Kaspersky Security Network cannot operate on US systems. The Standard edition gaps listed in the comparison above, in particular file integrity monitoring, log inspection, server application control and patch management, are the most common reason for a follow-up purchase once an audit or a customer questionnaire arrives. Detection and response is not part of this product at all and requires a separate Kaspersky product.
No. Per-CPU licensing is available only for virtual machine protection where the customer controls the hypervisor layer. Physical machines and cloud workloads are licensed per workload instead, and Kaspersky allows both models to run side by side when each is deployed in a separate part of the infrastructure.
Kaspersky Security for Virtualization Light Agent and Kaspersky Security for Virtualization Agentless are the components delivered under the Kaspersky Hybrid Cloud Security name. Buyers searching for the older product name are looking at the same technology under current branding.
Base identifies a new licence rather than a renewal or an upgrade of an existing one. Kaspersky handles renewals and upgrades as separate types, including the documented upgrade path from Kaspersky Hybrid Cloud Security CPU to Kaspersky Hybrid Cloud Security Enterprise CPU.