What are the core benefits of Kaspersky Hybrid Cloud Security Enterprise CPU Base?
Central management – All workloads managed from Kaspersky Security Center.
CPU licensing – Counts physical CPUs in virtualisation hosts.
Server hardening – Application control and file integrity monitoring included.
Patch management – Vulnerability assessment and patching in the Enterprise tier.
Light agents – Reduce private cloud resource consumption up to 40 percent.
Important note – No EDR component; Kaspersky Next EDR is separate.
Kaspersky Security Center – Single console for on-premises, virtual and cloud workloads.
Multi-layered threat protection – File, process and memory protection with behaviour analysis.
Application Control – Server and desktop allowlisting up to default deny mode.
File Integrity Monitoring – Flags changes to protected system files and folders.
Vulnerability and patch management – Finds missing updates and deploys patches centrally.
Important – No EDR component; Kaspersky Next EDR Expert is sold separately.
Kaspersky Hybrid Cloud Security Enterprise is the upper of the two tiers of Kaspersky's workload protection product and is managed centrally through Kaspersky Security Center or the Kaspersky Security Center Cloud Console. It follows on from Kaspersky Security for Virtualization, whose licences Kaspersky migrates to Hybrid Cloud Security at renewal, and the CPU variant licenses the physical CPUs installed in each host that runs protected virtual machines.
Hypervisor-level licensing – Tied to host CPUs rather than individual virtual machines.
Lower virtualisation overhead – Light agents reduce private cloud resource consumption up to 40 percent.
Default deny hardening – Application Control plus FIM creates an auditable baseline.
SIEM connectors – Forwards workload events to an existing SIEM platform.
VMware NSX protection – NextGen IDS/IPS detects suspicious network activity between VMs.
Public cloud inventory – Cloud API integration covers AWS, Azure and Google Cloud.
CPU licensing only pays off where you run your own virtualisation hosts and control the hypervisor layer. A company with a handful of physical servers and no virtualisation platform will not benefit from this licensing object, regardless of company size.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rare | By sector | Likely |
| NIS 2 in the European Union | Rare | By sector | Likely |
| Security questionnaire from large customers | Occasional | Frequent | Standard |
| Own virtualisation hosts under your control | ✕ | Often | ✓ |
| This product fits | ✕ | Partial | ✓ |
The reporting obligation under the revised Information Security Act (ISG) applies to operators of critical infrastructure, not to every company, and obliges them to report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. Log Inspection, File Integrity Monitoring and the event data collected in Kaspersky Security Center supply the technical detail a first report needs, namely when a change occurred, on which workload, and which process caused it, and the SIEM connectors in the Enterprise tier forward those events to a central platform where they can be preserved. What the product does not do is decide whether an incident is reportable, produce the report itself, or track the 24-hour deadline; it holds no case management, no reporting workflow and no defined retention period for evidence. It also does not replace the organisational duties around the obligation, such as naming responsible people and rehearsing the reporting path. This text is general product information and not legal advice; assess your own obligations with qualified legal support.
No software product makes an organisation compliant with the NIS 2 Directive, because the directive addresses management responsibility, risk analysis and processes rather than tooling. NIS 2 requires measure categories including risk management, incident handling, business continuity, supply chain security, secure system acquisition and maintenance, access control and cryptography. This product covers parts of the technical layer: system hardening through Application Control and File Integrity Monitoring, vulnerability assessment and patch management for the maintenance category, and event export for incident handling. It does not cover business continuity, because it contains no backup or recovery function, and it does not cover cryptography, because encryption management is not part of the feature set. Supply chain security and access governance also remain outside its scope and must be handled organisationally.
In Switzerland the Federal Office for Cybersecurity (BACS) has issued no warning and no restriction against Kaspersky. BACS has stated that it warns only where it holds confirmed technical evidence of a security risk, that no misuse of Kaspersky software has been reported to it in Switzerland, and that there is no internal federal directive banning the products. In Germany, the Federal Office for Information Security (BSI) has warned against the use of Kaspersky antivirus software since 15 March 2022; following the amendment of the BSI Act on 6 December 2025 the warning is now issued under Section 13 BSIG, it remains in force, and the BSI states explicitly that use is not prohibited. The United States went further and imposed a sales ban on Kaspersky products in 2024, and several other countries have restricted use in public administration. Kaspersky rejects the German warning as unjustified and not based on an objective technical analysis, states that it has no ties to any government, and points to its transparency centre in Zurich and the relocation of its data processing infrastructure to Switzerland. The stated grounds of these assessments concern vendor trustworthiness and jurisdiction rather than published detection performance. In practice this matters most if you bid for public sector contracts, operate critical infrastructure, or answer supplier questionnaires from customers who exclude vendors on a country-of-origin basis; for a Swiss private company with no such exposure there is currently no regulatory obstacle.
Partly, and the gaps are predictable. It answers the questionnaire items on malware protection for server and virtual workloads, application allowlisting, host intrusion prevention, integrity monitoring of critical files, vulnerability scanning, patch deployment, central policy management and log forwarding to a SIEM. It does not answer the items on endpoint detection and response, on encryption of data at rest and removable media, on backup and restore testing, on mobile device management, or on multi-factor authentication, because none of those components exist in this product. It also cannot answer the vendor-origin question that an increasing number of questionnaires now include. To close the technical gaps, the cheaper route is usually to stay inside the Kaspersky family and add Kaspersky Next EDR Expert for detection and response or Kaspersky Container Security for container workloads, rather than mixing consoles from two vendors; the origin question, however, cannot be closed with a product and needs a documented risk assessment.
The decisive difference is server hardening: Application Control for server operating systems, File Integrity Monitoring and Log Inspection exist only in the Enterprise tier, and these are the three features auditors and questionnaires ask about most often. Enterprise adds vulnerability assessment with patch management, SIEM connectors, container security and DevOps integration interfaces, and NextGen IDS/IPS for VMware NSX. The Standard tier covers the protection engine itself and is sufficient where the goal is malware defence rather than a documented security baseline. Both tiers are managed from the same console and both support the CPU licensing object.
| Feature | Standard | Enterprise |
|---|---|---|
| File, process and memory protection | ✓ | ✓ |
| Cloud API integration with AWS, Azure and Google Cloud | ✓ | ✓ |
| Application Control for server OS | ✕ | ✓ |
| File Integrity Monitoring | ✕ | ✓ |
| Log Inspection | ✕ | ✓ |
| Vulnerability assessment and patch management | ✕ | ✓ |
| SIEM connectors | ✕ | ✓ |
| Container security and DevOps integrations | ✕ | ✓ |
| NextGen IDS/IPS for VMware NSX | ✕ | ✓ |
| EDR component included | ✕ | ✕ |
| Sale in the United States | Not available | Not available |
The CPU licensing object only applies to virtual machines in an environment where you control the hypervisor layer; physical servers and cloud workloads are licensed per workload instead, so a mixed estate usually needs more than one licensing model. There is a hard regional restriction: Kaspersky products cannot be sold in the United States following the 2024 sales ban, which matters if your group has a US entity or a US-based parent that standardises tooling. On the platform side, KSV Agentless reaches end of technical support on 31 July 2026 and Kaspersky recommends switching to KSV Light Agent, which is already covered by the licence but requires a migration project rather than a switch of a setting. The components that most often trigger a follow-up purchase are endpoint detection and response, encryption management, mobile device coverage and backup, none of which are part of this product; full container platform security also sits in the separate Kaspersky Container Security, with this tier providing the integration interfaces rather than the platform.
Base identifies a new licence for the Enterprise tier rather than a renewal or a successive licence, which Kaspersky lists as separate types. It is not an add-on, so it does not require an existing base product underneath it.
No. The CPU licensing object counts the physical CPUs installed in each host that runs protected virtual machines, and it is only available where you control the hypervisor. Physical servers and public cloud workloads are covered by the Server licensing object instead, and Kaspersky permits combining licensing models when each is deployed in a separate part of the infrastructure.
No. The Enterprise tier provides container security and DevOps integration interfaces so that scanning can be attached to a CI/CD pipeline, but the dedicated container platform is Kaspersky Container Security, a separate product. Together the two form the Kaspersky Cloud Workload Security offering.