What are the core benefits of Kaspersky Container Security Advanced Base?
Central console – One web console manages all monitored clusters.
Runtime protection – Blocks suspicious activity inside running containers.
Image scanning – Finds vulnerabilities, malware and secrets before deployment.
Launch control – Stops non-compliant or unregistered images from starting.
Pipeline integration – Scans images inside Jenkins, TeamCity and CircleCI.
Important note – No endpoint or virtual machine protection included.
Management console – Browser-based console for policies, scan results and cluster status.
Registry and CI/CD scanning – Checks images in Harbor, GitLab Registry, Jenkins and TeamCity.
Runtime container protection – eBPF-based file threat protection for containers already running.
Launch control – Blocks unregistered, privileged or policy-failing images from starting.
Node OS scanning – Vulnerability scanning and file threat protection on cluster nodes.
Important – AI scan summaries and custom benchmarks require Advanced Pro.
Kaspersky Container Security Advanced is the middle of three tiers of Kaspersky's dedicated container platform, which is sold as part of the Kaspersky Cloud Workload Security offering. It is managed centrally from one web console covering image registries, CI/CD pipelines and running Kubernetes or OpenShift clusters.
Build-stage blocking – Failed images never reach the orchestrator at all.
Runtime visibility – Container traffic and process activity monitored while services run.
Integrity monitoring – Flags running containers that drift from their scanned image.
Direct SIEM export – Cluster event logs transmitted straight to SIEM systems.
Benchmark audits – Automated best-practice checks across clusters and platform components.
Air-gapped deployment – Runs on-premises in isolated networks without cloud dependency.
This tier is aimed at organisations that already run containers in production and have someone responsible for cluster policy. A company with no Kubernetes or OpenShift footprint gains nothing from it, because every function starts at an image registry, a pipeline or a cluster node.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | ✓ |
| NIS 2 in the European Union | ✕ | By sector | ✓ |
| Security questionnaire from large customers | Occasional | ✓ | ✓ |
| Kubernetes or OpenShift in production | Rare | Partial | ✓ |
| This product fits | ✕ | Partial | ✓ |
The obligation applies to operators of critical infrastructure named in the revised Information Security Act, for example energy and drinking water suppliers, transport companies, hospitals, financial service providers and cantonal and communal administrations, not to every Swiss company. Those organisations must report a qualifying cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery and complete the report within 14 days. Where containerised applications form part of that infrastructure, this product supports the deadline in one specific way: it logs host syscalls, changes to RBAC cluster objects and container events, and transmits those logs directly from monitored clusters to a SIEM, which is what turns a container incident into evidence a team can describe inside a single day. It does not decide whether an incident is reportable, does not submit anything to BACS, and covers nothing outside the container environment, so workstations, virtual machines, mailboxes and network devices remain uncovered gaps in the same reporting chain. This text describes product capabilities and is not legal advice.
No product makes an organisation compliant with the NIS 2 Directive, because the directive addresses management responsibility, processes and risk governance rather than software features. NIS 2 requires categories of measure including risk analysis and information system security policies, incident handling, business continuity, supply chain security, security in the acquisition, development and maintenance of systems including vulnerability handling, access control and asset management, cryptography, and cyber hygiene and training. This product maps to three of those categories: vulnerability handling, through image and infrastructure-as-code scanning against the NIST database and Kaspersky's own base; supply chain security, through registry scanning and integrity checks between a scanned image and the container actually running from it; and incident handling input, through cluster event forwarding to a SIEM. It contributes nothing to business continuity, cryptography, access control enforcement, staff training, or asset management outside the container estate, and it produces no governance documentation. Organisations relying on it should treat it as evidence for one technical layer, not as coverage of the measure catalogue.
On 20 June 2024 the US Department of Commerce, through its Bureau of Industry and Security, issued a Final Determination prohibiting Kaspersky from providing antivirus software and cybersecurity products or services in the United States or to US persons. New sales stopped on 20 July 2024 and the provision of updates stopped on 29 September 2024, and three Kaspersky entities in Russia and the United Kingdom were added to the Entity List. The determination rests on risk factors relating to Russian jurisdiction and possible influence over the company rather than on a published defect found in product code. Germany's Federal Office for Information Security issued a warning in March 2022 recommending that organisations replace Kaspersky antivirus software, and confirmed after the US action that its warning still stands; Germany imposed no sales ban. Italy, the Netherlands, Canada and the United Kingdom have restricted use on government systems rather than in the private sector. Kaspersky's own position is that the US decision reflects the geopolitical climate and theoretical concerns rather than a full technical evaluation, and the company proposed independent third-party verification of its products, updates and detection rules. In practice this matters most to three groups: organisations bidding for public sector contracts, companies with a US parent or US-person staff who fall inside the scope of the prohibition, and suppliers whose customers ask directly about restricted vendors in procurement questionnaires. In Switzerland and most of the European Union the product is sold and updated without restriction.
Yes, but only for the container section of a questionnaire. It answers items on vulnerability scanning of application artefacts, detection of hard-coded secrets such as passwords, access keys and tokens, misconfiguration checks on infrastructure-as-code, admission control that prevents unapproved or privileged images from starting, logging of privilege changes in the cluster, and audit reports that can be downloaded from the log on demand. It answers none of the following, and questionnaires almost always ask them: workstation and server antivirus, patch management for operating systems and third-party applications, disk and removable media encryption, multi-factor authentication, email and phishing protection, backup and restore testing, and security awareness training. It also does not answer questions about vendor restrictions, which are increasingly asked, and which the section above is relevant to. To close the container-side gap within the same family, Advanced Pro adds customisable security benchmarks so audits can be phrased against your own internal standard rather than a preset one; for virtual machines and physical servers outside the cluster, Kaspersky Hybrid Cloud Security sits in the same Cloud Workload Security offering and is usually cheaper to add than introducing a second vendor with a separate console.
The decisive difference is when protection stops: Standard covers images before they run, Advanced also covers containers that are already running. Both tiers scan registries, pipelines and infrastructure-as-code, integrate with SIEM by syslog, and share the same management console. Advanced adds admission control, behavioural analytics, traffic monitoring between containers and clusters, file operation monitoring, host syscall logging, and vulnerability scanning plus file threat protection on the node operating system itself. Advanced Pro sits above Advanced and adds two items only, so buyers choosing between Advanced and Advanced Pro are deciding about audit customisation and AI assistance, not about protection depth.
| Capability | Standard | Advanced | Advanced Pro |
|---|---|---|---|
| Image, registry and IaC scanning | ✓ | ✓ | ✓ |
| Container launch control | ✕ | ✓ | ✓ |
| Runtime file threat protection | ✕ | ✓ | ✓ |
| Container traffic monitoring | ✕ | ✓ | ✓ |
| Node OS vulnerability scanning | ✕ | ✓ | ✓ |
| Cluster event logs sent to SIEM | ✕ | ✓ | ✓ |
| Customised security benchmarks | ✕ | ✕ | ✓ |
| AI assistant via OpenAI API | ✕ | ✕ | ✓ |
The most significant regional limitation is the United States: since the Bureau of Industry and Security determination, Kaspersky products cannot be newly sold there and updates ceased on 29 September 2024, so a group with US entities cannot standardise on this product across all sites. Switzerland and the European Union are unaffected. The scope is containers and the nodes they run on, so virtual machines, physical servers, workstations, mailboxes and mobile devices need separate products and produce a second console to operate. Verified orchestrator support covers Kubernetes, Red Hat OpenShift, Azure AKS and Amazon ECS, with public cloud integration for AWS, Microsoft Azure and Google Cloud Platform; anything outside that list should be confirmed before purchase. An agent has to be deployed on each node you want protected, which makes the rollout an infrastructure task rather than a software install, and the two capabilities most often assumed to be present, customisable security benchmarks and the AI-based interpretation of scan results, sit in Advanced Pro and are the usual cause of a follow-up purchase.
Yes. The platform is designed for on-premises installation and is available for isolated networks, so clusters in segmented or air-gapped environments can be covered without an outbound cloud dependency.
No. It is a standalone platform consisting of a scanner, agents and a control server with its own web console. It belongs to the Kaspersky Cloud Workload Security offering alongside Kaspersky Hybrid Cloud Security, but neither product requires the other.
Verified integrations cover Docker Hub, JFrog Artifactory, Sonatype Nexus OSS, GitLab Registry, VMware Harbor, Red Hat Quay, Amazon ECR, Azure Container Registry and Google Container Registry. Scans run manually or automatically against predefined parameters.
Yes, in this tier. Container integrity monitoring compares a running container against the image it was scanned from, and eBPF-based file operation monitoring records changes such as creation, modification and ownership or permission changes.
| Operating Systems | CentOS 8.2.2004 or later: Linux kernel 4.18.0-193 or later Ubuntu 18.04.2 or later: Linux kernel 4.18.0 or later Debian 10 or later: Linux kernel 4.19.0 or later Astra Linux SE 1.7.* or later: Linux kernel 6.1.50-1-generic / CONFIG_DEBUG_INFO_BTF=y RHEL 9.4 or later: Linux kernel 5.14 or later Red Hat Enterprise Linux CoreOS 416.94.202408200132-0: Linux kernel 5.14.0-427.33.1.el9_4.x86_64 RED OS 7.3 or later: Linux kernel 6.1 or later / CRI CRI-O / CNI Calico Sber Linux 8.9 / 9.3: Linux kernel 5.14 / CRI CRI-O / CNI Calico / Cilium |
| Orchestration Platforms | Kubernetes 1.21 or later / OpenShift 4.8 / 4.11 or later / DeckHouse 1.70.17 / 1.71.3 / Platform V DropApp 2.1 / Shturval 2.10 |
| CI System | CI system for image scanning in development process such as GitLab CI |
| Package Manager | Helm 3.10.0 or later |
| Linux Kernel | Linux kernel 4.18 or later for runtime monitoring with container runtime profiles / Some mechanisms for process privilege management require Linux kernel 5.8 or later |
| Container Runtime Interface | containerd / CRI-O |
| Container Network Interface | Flannel / Calico / Cilium |
| Architecture | x86 |
| Service Mesh | Istio service mesh supported |
| Secrets Storage | HashiCorp Vault 1.7 or later |
| Database Support | ClickHouse v25.* / PostgreSQL Postgres Pro Standard Enterprise 15 / 17 / Pangolin 6.2.0 |
| Image Registries | Amazon Elastic Container Registry / Azure Container Registry API 2023-01-01-preview / Docker Hub v2 API / Docker Registry v2 API / GitLab Registry 14.2 or later / Google Artifact Registry / Harbor 2.x / JFrog Artifactory 7.55 or later / Red Hat Quay 3.x / Sfera 2.0 / Sonatype Nexus Repository OSS 3.43 or later / Yandex Registry |
| Network Support | IPv4 / IPv6 |
| Cloud Platforms | Yandex Cloud / Amazon AWS EKS / Microsoft Azure AKS |
| Cluster Resources | Three worker nodes with three scanner pods and max image scan size 10 GB: at least 12 processor cores / at least 20 GB RAM / 40 GB free disk space / at least 1 Gbps bandwidth between cluster components |
| Agent Resources | Per worker node baseline: 0.2 processor cores / 200 MB RAM / 15 GB free disk space / Add for network and process monitoring: 2 processor cores / 2 GB added RAM / Add for anti-malware protection: 2 processor cores / 2 GB added RAM / All agent functionalities enabled: 2 processor cores / 4 GB RAM |
| Database Storage | ClickHouse persistent volume: 1 GB free disk space per monitored node |
| User Workstation | Permanent internet connection for public corporate network deployments / Access to Management Console page in corporate network / Communication channels at least 10 Mbit/s |
| Supported Browsers | Google Chrome 140 or later / Mozilla Firefox 143 or later |