What are the key advantages of Kaspersky Vulnerability and Patch Management Base?
Central console – Managed from Kaspersky Security Center, not per device.
Vulnerability scanning – Covers Microsoft and 150+ third-party Windows applications.
Patch distribution – Test, approve and deploy patches after office hours.
Asset inventory – Records all hardware and installed software automatically.
Audit reporting – Documents patch status and known CVEs per device.
Important note – Contains no anti-malware engine; protection licensed separately.
Vulnerability assessment – Automated scanning of Microsoft and third-party software for known vulnerabilities.
Patch distribution – Download, test and deploy patches, with Wake-on-LAN for after-hours rollout.
Hardware and software inventory – Records every device and application found on the network.
Remote troubleshooting – Authorised remote desktop sessions, fully logged for later audit.
Operating system deployment – Captures, stores and deploys Windows images via PXE or WIM.
Important – No anti-malware engine included; endpoint protection is licensed separately.
Kaspersky Vulnerability and Patch Management is a systems management solution for Windows endpoints, administered from the Kaspersky Security Center console. It was previously sold as Kaspersky Systems Management, and the same capability set also ships inside Kaspersky Endpoint Security for Business Advanced, Kaspersky Total Security for Business and Kaspersky Next EDR Optimum.
Single patch queue – One console covers Microsoft and 150+ third-party applications.
Risk-based prioritisation – Vulnerabilities exploited by active malware are flagged critical first.
Test before rollout – Administrators approve patches after testing them on pilot machines.
Bandwidth control – A branch workstation serves as local distribution point.
WSUS replacement – The Administration Server can act as Windows Update source.
Audit-ready reporting – Reports cover patch results, scan findings and known CVEs.
The decisive question is not headcount but whether one person is accountable for a documented patch cycle across third-party software. Where nobody is, this standalone licence adds a console without closing the protection gap. Where someone is, it removes the manual version checking that consumes most of the time.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | Often |
| NIS 2 in the European Union | Rarely | By sector | Usually |
| Security questionnaire from large customers | Occasionally | ✓ | ✓ |
| Documented patch cycle for third-party software | Optional | ✓ | ✓ |
| This product fits | Limited | ✓ | Partly |
The reporting obligation under the revised Information Security Act applies to operators of critical infrastructure and has been in force since 1 April 2025; most small and medium-sized companies are not covered by it. Organisations that are covered must report a significant cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. For that report, the hardware and software inventory together with the patch history in Kaspersky Security Center show which system ran which application version at the time of the incident, which is normally the slowest fact to reconstruct under time pressure. The product does not detect attacks, does not raise alerts and does not build an incident timeline, so it cannot tell you that a report is due at all; that requires endpoint protection with detection and response, or a logging solution. It also has no submission workflow towards the authority, since reports are filed through the Cyber Security Hub. This text is not legal advice, and whether your company falls under the reporting obligation should be clarified with your legal department or a specialist lawyer.
No software product creates NIS 2 compliance, because the directive addresses organisational risk management and the measures have to be implemented, documented and reviewed by the company itself. Among other categories, NIS 2 requires risk analysis and security policies, incident handling, business continuity, supply chain security, security in the acquisition and maintenance of network and information systems including vulnerability handling, cyber hygiene, cryptography and access control. This product supports the maintenance and vulnerability-handling category and part of cyber hygiene: it identifies unpatched software, prioritises it by exploitability and records when the patch was installed. It also supports asset management, because the inventory keeps a current list of hardware and installed applications. It contributes nothing to incident handling, business continuity and backup, cryptography, access control, multi-factor authentication, supplier management or staff training, and those measures require separate products and processes. Whether an organisation falls within scope depends on the sector and size criteria set out in the directive.
On 20 June 2024 the Bureau of Industry and Security of the US Department of Commerce issued a Final Determination prohibiting Kaspersky from providing anti-virus software and cybersecurity products or services to US persons; new agreements were barred from 20 July 2024 and the delivery of updates ended on 29 September 2024. The same action added several Kaspersky entities to the US Entity List, and the determination remains in force. Kaspersky states that the decision was based on the geopolitical climate rather than on an assessment of the integrity of its products, and that it continues to contest actions it considers damaging to its reputation and commercial interests. In Switzerland the situation is different: BACS has issued no warning against Kaspersky products and there is no ban, and the office applies the rule that it warns only where confirmed technical indications of a security risk exist. Independent anti-malware laboratory results are not a decisive factor for this particular licence, because it contains no protection engine. In practice the assessment matters for buyers with US parent companies or US contracts, for public sector tenders, and for suppliers whose customers mirror US restriction lists in their own procurement rules.
Yes, for one block of questions, and not at all for the rest. It answers the items on asset inventory, on vulnerability identification in third-party applications, on how quickly critical patches are applied, and on whether patch status is documented per device, because every one of these can be exported as a report rather than assembled by hand. It also answers the item on logged administrative remote access, since remote sessions require authorisation and are recorded. It does not answer anything on malware protection, detection and response, encryption at rest, multi-factor authentication, backup, email security, mobile device management or macOS and Linux coverage, and it produces no SIEM export. A growing number of questionnaires also ask about the country of origin of security suppliers and about restriction lists, and this licence does not help you there either. To close the technical gaps, moving up within the same family is normally cheaper than adding a second vendor console, because Kaspersky Next EDR Optimum covers protection, detection and response, patching and encryption management from one console.
The decisive difference is that Kaspersky Next EDR Optimum contains the protection engine and this licence does not. Kaspersky Vulnerability and Patch Management is a targeted solution: it delivers the systems management functions only, which is why it is bought either as an add-on to Kaspersky Endpoint Security for Business Select or by companies that already run protection from another source. Kaspersky Next EDR Optimum bundles endpoint protection, detection and response, vulnerability and patch management and encryption management, and is administered from a cloud or on-premises console. The same patch management capability is also part of Kaspersky Endpoint Security for Business Advanced, Kaspersky Total Security for Business and Kaspersky Hybrid Cloud Security Enterprise, so check what you already own before buying this licence separately.
| Capability | Vulnerability and Patch Management | Next EDR Optimum |
|---|---|---|
| Vulnerability assessment | ✓ | ✓ |
| Patch management | ✓ | ✓ |
| Operating system deployment | ✓ | Not stated |
| Encryption management | ✕ | ✓ |
| Malware protection | ✕ | ✓ |
| Detection and response | ✕ | ✓ |
The solution is designed for Windows-based endpoints, so macOS and Linux systems are neither scanned for vulnerabilities nor patched by it and remain a manual task. Two functions are tied to the deployment model: the Administration Server can act as a WSUS server and synchronise with Windows Update only in on-premises installations, not in the cloud console. The most frequent follow-up purchase is protection itself, because this licence contains no anti-malware engine and no detection and response, so a second product is needed on every device it manages. On regional availability, the product is not available in the United States following the prohibition issued by the US Department of Commerce, which matters for group-wide rollouts that include US locations. Server workload protection is a separate product line, so plan servers, mail systems and hypervisors independently of this licence.
Yes. Kaspersky Security Center is the console for this solution and provides the policies, tasks, reports and role-based access control. Without it there is no interface for the vulnerability scan or the patch tasks.
In on-premises installations the Administration Server can take over the WSUS role and synchronise with Windows Update. The practical gain over WSUS is that the same task also covers non-Microsoft applications, which WSUS never handled.
Base identifies an initial licence for this product, as opposed to renewal conditions that apply to an existing licence of the same product. If you already run Kaspersky Vulnerability and Patch Management, check whether a renewal variant applies to you before ordering.