What are the key advantages of Kaspersky Container Security Standard Base?
Central console – One web console for all connected registries.
Registry scanning – Checks images in Docker Hub, Harbor, Artifactory.
Pipeline integration – Blocks failing builds in Jenkins and TeamCity.
Threat coverage – Vulnerabilities, malware and secrets in one scan.
IaC checks – Configuration files scanned for errors before deployment.
Important note – Runtime protection needs the Advanced tier.
Management console – Web interface for scans, policies and findings.
Registry integration – Docker Hub, Harbor, Artifactory, Nexus, Quay, ECR.
Image scanning – Vulnerabilities, malware and secrets such as keys and tokens.
IaC scanning – Configuration files checked for errors and bad practice.
CI/CD integration – Jenkins, TeamCity and CircleCI can block failing builds.
Important – Runtime protection and cluster checks require the Advanced tier.
Kaspersky Container Security is a dedicated platform for containerised applications with its own web management console, and it belongs to the Kaspersky Cloud Workload Security range alongside Kaspersky Hybrid Cloud Security. Standard is the scanning tier of that platform: it covers image registries, CI/CD pipelines and infrastructure-as-code files, which is the stage before anything reaches a cluster.
Findings before deployment – Problems surface at build, not in production.
Secret detection – Finds passwords, access keys and tokens inside images.
Two vulnerability sources – NIST and Kaspersky databases feed the same scan.
Build gate – The pipeline stage fails when a policy is broken.
Own infrastructure – Installs in a public or private corporate network.
Alerting targets – Syslog to SIEM, LDAP, e-mail, Telegram, webhook.
The deciding factor is not headcount but whether your developers build and publish their own container images. A twelve-person software house with a GitLab pipeline and a Harbor registry has more use for this tier than a 300-person manufacturer that only buys finished software. The Standard tier assumes someone owns the build process and can act on a failed scan.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | Often |
| NIS 2 in the European Union | Rarely | By sector | Often |
| Security questionnaire from large customers | Sometimes | Often | Usually |
| Own container images built in-house | Sometimes | Often | Usually |
| This product fits | Only with own builds | ✓ | Advanced usually |
No product does that on its own, and this one addresses only one part of the picture. Under the revised Information Security Act the reporting obligation has applied since 1 April 2025: operators of critical infrastructure must report a qualifying cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with up to 14 days to complete the report. What the Standard tier contributes to that 14-day window is documentation: the scan history and the reporting system show which image version carried which vulnerability and when it was flagged, which is usually the slowest part of an incident report to reconstruct. What it does not contribute is the detection itself, because Standard does not watch running containers, so it will not be the system that tells you an attack is under way. This text is not legal advice; whether your organisation falls under the reporting obligation should be clarified with a specialist.
No software makes an organisation compliant, because the NIS 2 Directive addresses management processes and not products. Among the measure categories the directive requires are risk management policies, incident handling, business continuity, supply chain security, and security in the acquisition, development and maintenance of network and information systems, including vulnerability handling. The Standard tier maps onto two of those: vulnerability handling during development, and supply chain security, since scanning a third-party base image before it is built into your own application is a supply chain control. It does not map onto incident handling, business continuity, access control, cryptography or staff training, and it produces no evidence for any of them. Organisations that need documented configuration checks against recognised benchmarks will not find them in this tier.
Two published measures affect this vendor, and both remain in force. Germany's federal information security authority has warned against the use of Kaspersky virus protection software since 15 March 2022 and recommends replacing such applications with alternative products; the warning is still published, and Kaspersky rejects it as not being based on an objective technical analysis and has continued to press for its withdrawal. Separately, the US Department of Commerce issued a final determination in June 2024 prohibiting the supply of Kaspersky cybersecurity and antivirus products to US persons, with new agreements barred from 20 July 2024 and updates from 29 September 2024; Kaspersky states the decision reflects the geopolitical climate rather than an evaluation of its products, and its own product page confirms that trials and downloads are unavailable for US customers. No comparable sales prohibition has been published in Switzerland. In practice this matters most to public-sector tenders, to suppliers of German public bodies, and to companies whose customers impose vendor-origin conditions in supply chain requirements; for a purely internal development pipeline with no such conditions, the decision is yours to make.
Partly, and only in the software development section. It gives you a documented answer to questions about scanning container images for known vulnerabilities, detecting hard-coded credentials and tokens in build artefacts, checking infrastructure-as-code before deployment, enforcing a security gate in the CI/CD pipeline, and forwarding events to a SIEM. It gives you no answer at all to questions about runtime detection and response, endpoint protection, patch management evidence, disk encryption, multi-factor authentication, backup, or documented configuration checks of the cluster itself. If the questionnaire that is blocking a contract asks for runtime monitoring or benchmark-based configuration evidence, the Advanced tier of the same product closes those items and is usually cheaper than adding a second vendor's platform alongside this one. Note that questionnaires increasingly ask where each security supplier is headquartered, which is a separate question this product cannot answer for you.
The dividing line is whether the container is running yet. Standard works on artefacts before deployment: images in registries, images and IaC files in the pipeline, and the risk assessment of what those scans find. Advanced adds everything that concerns live workloads and the platform underneath them, including scanning images already present in a cluster, controlling which containers may launch, behavioural analytics, node operating system scanning, and configuration analysis against regulatory requirements. Advanced Pro sits above that and adds integration with an AI assistant deployed in your own infrastructure, plus security benchmarks you can adapt to your own standards. Kaspersky's own licensing examples make the split explicit: a customer securing container images only is quoted Standard, while a customer who also wants runtime and compliance checks is quoted Advanced.
| Capability | Standard | Advanced | Advanced Pro |
|---|---|---|---|
| Registry and CI/CD image scanning | ✓ | ✓ | ✓ |
| IaC configuration scanning | ✓ | ✓ | ✓ |
| SIEM, LDAP, e-mail and webhook notification | ✓ | ✓ | ✓ |
| Scanning images already in a cluster | ✕ | ✓ | ✓ |
| Container launch control | ✕ | ✓ | ✓ |
| Runtime behavioural analytics | ✕ | ✓ | ✓ |
| Node operating system scanning | ✕ | ✓ | ✓ |
| Configuration analysis for regulatory compliance | ✕ | ✓ | ✓ |
| Cluster event log sent directly to SIEM | ✕ | ✓ | ✓ |
| AI assistant integration | ✕ | ✕ | ✓ |
| Customised security benchmarks | ✕ | ✕ | ✓ |
The most common reason for a follow-up purchase is the runtime gap: teams buy Standard to clean up their images, then discover that nothing is watching the containers once they are running, and move up to Advanced within the year. There is a regional restriction as well, because the platform is not available to US customers, so a Swiss or European group with a US subsidiary cannot roll it out uniformly across all sites. Platform coverage is limited to container environments — Kubernetes, Red Hat OpenShift, Azure AKS and Amazon ECS, with AWS, Microsoft Azure and Google Cloud Platform as supported public clouds — so Windows workstations, file servers, mailboxes and mobile devices are outside its scope entirely and need a separate product. Standard also does not scan the operating system of the nodes themselves, which surprises buyers who expect a security platform on a cluster to cover the hosts under it.
No. Base is the retail licence designation Kaspersky uses across its range for a first purchase, as opposed to a Renewal listing for an existing licence of the same product. The platform runs on its own with its own management console and does not require Kaspersky Hybrid Cloud Security or any other Kaspersky product, although it is positioned alongside Hybrid Cloud Security in the Kaspersky Cloud Workload Security range.
No, and the two are not interchangeable. This platform scans container images, deployment artefacts and configuration files, and its findings are vulnerabilities, malware, secrets and misconfigurations inside those artefacts. Laptops, physical and virtual servers, mailboxes and mobile devices are not in scope at any tier and require a separate endpoint or workload product.
The platform is installed in your own environment, in either a public or a private corporate network, and is operated through a web console reached with Chrome, Edge, Safari or Firefox. It can be pointed at external database and storage systems you already run, including PostgreSQL, ClickHouse and MinIO, so the scan history and findings remain in infrastructure you control. That matters for buyers who have to state in a questionnaire where security telemetry is processed.
| Operating Systems | CentOS 8.2.2004 or later: Linux kernel 4.18.0-193 or later Ubuntu 18.04.2 or later: Linux kernel 4.18.0 or later Debian 10 or later: Linux kernel 4.19.0 or later Astra Linux SE 1.7.*: Linux kernel 6.1.50-1-generic and CONFIG_DEBUG_INFO_BTF=y RHEL 9.4 or later: Linux kernel 5.14 or later Red Hat Enterprise Linux CoreOS 416.94.202408200132-0: Linux kernel 5.14.0-427.33.1.el9_4.x86_64 RED OS 7.3 or later: Linux kernel 6.1 or later / CRI CRI-O / CNI Calico Sber Linux 8.9 / 9.3: Linux kernel 5.14 / CRI CRI-O / CNI Calico / Cilium |
| Orchestration Platforms | Kubernetes 1.21 or later / OpenShift 4.8 / 4.11 or later / DeckHouse 1.70.17 or 1.71.3 / Platform V DropApp 2.1 / Shturval 2.10 |
| Linux Kernel | Linux kernel 4.18 or later for runtime monitoring with container runtime profiles |
| Container Runtime Interface | containerd / CRI-O |
| Container Network Interface | Flannel / Calico / Cilium |
| Package Manager | Helm 3.10.0 or later |
| Architecture | x86 |
| Cluster Resources | Three worker nodes with three scanner pods and max image scan size 10 GB: at least 12 processor cores / at least 20 GB RAM / 40 GB free disk space / at least 1 Gbps bandwidth between cluster components |
| Agent Resources | Per worker node baseline: 0.2 processor cores / 200 MB RAM / 15 GB free disk space / All agent functionalities enabled: 2 processor cores / 4 GB RAM |
| Database Support | ClickHouse 25.x / PostgreSQL Postgres Pro Standard Enterprise 15 / 17 / Pangolin 6.2.0 |
| Image Registries | Amazon Elastic Container Registry / Azure Container Registry API 2023-01-01-preview / Docker Hub v2 API / Docker Registry v2 API / GitLab Registry 14.2 or later / Google Artifact Registry / Harbor 2.x / JFrog Artifactory 7.55 or later / Red Hat Quay 3.x / Sfera 2.0 / Sonatype Nexus Repository OSS 3.43 or later / Yandex Registry |
| Network Support | IPv4 / IPv6 |
| Cloud Platforms | Yandex Cloud / Amazon AWS EKS / Microsoft Azure AKS |
| User Workstation | Permanent internet connection for public corporate network deployments / access to Management Console page in corporate network / communication channels at least 10 Mbit/s |
| Supported Browsers | Google Chrome 140 or later / Mozilla Firefox 143 or later |