What are the key advantages of Kaspersky Embedded Systems Security Compliance Edition Base Plus?
Central management – Via Kaspersky Security Center, or locally per device.
Embedded focus – Protects ATMs, POS terminals and kiosk devices.
Default deny – Applications Launch Control blocks all unapproved executables.
Integrity monitoring – File Integrity Monitor and Log Inspection included.
Legacy support – Runs on Windows XP Embedded through Windows 11 IoT.
Important note – No EDR, patch management or encryption included.
Anti-malware protection – Real-time file protection and on-demand scanning, both optional components.
Applications Launch Control – Default deny mode blocks every executable not explicitly allowed.
Device Control – Restricts USB storage and other externally connected devices.
Firewall Management – Configures Windows Firewall rules centrally, useful outside domain environments.
System integrity checks – File Integrity Monitor and Log Inspection, exclusive to this edition.
Important – No EDR, patch management, encryption or mobile device coverage.
Kaspersky Embedded Systems Security Compliance Edition protects Windows-based embedded devices such as ATMs, payment terminals, kiosks and medical equipment, and is the extended licence level of the application Kaspersky now publishes as Kaspersky Embedded Systems Security for Windows, sold in earlier releases simply as Kaspersky Embedded Systems Security. Devices are managed centrally from the on-premises Kaspersky Security Center console, or individually through the local application console and the command line, which matters for terminals sitting on isolated network segments.
Works on legacy Windows – Covers Windows XP Embedded SP3 through Windows 11 IoT Enterprise.
Low connectivity tolerance – Suits devices with weak or intermittent network links.
Audit evidence – Integrity and log findings are recorded in task logs and reports.
SIEM export – Events convert to syslog format for third-party SIEM systems.
Swiss data processing – Suspicious files from European users are processed in Zurich.
Selective components – Anti-malware can be left out on weak hardware.
The deciding factor is not headcount but whether you operate Windows-based embedded devices that regular endpoint software cannot cover. A retailer with twelve POS terminals has the same technical problem as a bank with four hundred ATMs, but only the larger operator usually has the console infrastructure and the staff to review integrity findings.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | By sector |
| Security questionnaire from large customers | Sometimes | ✓ | ✓ |
| Legacy Windows devices in the field | Sometimes | ✓ | ✓ |
| This product fits | Limited | ✓ | ✓ |
The obligation applies to operators of critical infrastructure named in the revised Information Security Act, such as energy and drinking water suppliers, transport companies and cantonal and communal administrations, so most ordinary companies are not in scope. Those that are must report a significant cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery and complete the report within 14 days, with fines applying since 1 October 2025. Two capabilities in this edition support that deadline in practice: Log Inspection flags abnormal patterns in Windows event logs, and File Integrity Monitor records changes to defined files and folders, including changes made while a terminal was powered off, which is often the only usable evidence on an unattended ATM. Events can be forwarded in syslog format to a SIEM, so the 24-hour clock does not depend on someone logging into each device individually. What the product does not do is decide that an incident is reportable, assemble the report or provide an investigation timeline across the wider estate, because it has no EDR component and covers only the Windows embedded devices where the agent is installed. This text is not legal advice, and whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.
No software product creates NIS 2 compliance, because the directive obliges the organisation to run a risk-management process, not to install a particular tool. NIS 2 requires measures in defined categories: risk analysis and security policies, incident handling, business continuity, supply chain security, security in acquisition and maintenance including vulnerability handling, access control and asset management, cryptography, basic cyber hygiene and training, and multi-factor authentication. This product contributes to three of them: incident handling, through log inspection and integrity monitoring on the protected devices; access control at device level, through Applications Launch Control and Device Control; and asset hardening, by allowing an allowlist to be enforced on equipment that can no longer be patched. It contributes nothing to vulnerability handling, cryptography, multi-factor authentication, supply chain assessment, business continuity or staff training, and it produces evidence only for Windows embedded devices, not for servers, workstations, mailboxes or mobile devices. Swiss suppliers should note that they can be pulled into these expectations through customers established in the European Union even though the directive does not apply to them directly.
Two official measures are relevant and both are still in force. Germany's Federal Office for Information Security has warned against the use of Kaspersky antivirus software since 15 March 2022 and recommends replacing it with alternative products; the warning was issued under §7 of the BSI Act and has been regulated under §13 since 6 December 2025, and German administrative courts have held it lawful. In the United States, the Department of Commerce issued a Final Determination on 20 June 2024 prohibiting new sales to US persons from 20 July 2024 and prohibiting signature and codebase updates from 29 September 2024, and added AO Kaspersky Lab, OOO Kaspersky Group and Kaspersky Labs Limited to the Entity List. Kaspersky's own position is that both decisions rest on the geopolitical situation and theoretical concerns rather than a technical evaluation of its products, that no security vulnerability in the software has been demonstrated, and it has publicly asked the German authority to adjust or withdraw the warning. The authorities' reasoning concerns vendor jurisdiction and trust rather than a published defect in the code. In practical terms this matters most to public sector buyers, to suppliers who must answer origin questions in customer or tender documentation, and to any organisation with US operations or US-based devices; a privately held Swiss operator running ATMs domestically is affected differently from a supplier to a German federal customer.
Partly, and only for a clearly bounded slice of the estate. It answers questions on malware protection for systems running unsupported operating systems, application allowlisting and default deny, removable media and USB control, host firewall configuration on devices outside a domain, file integrity monitoring, review of system logs for signs of compromise, log forwarding to a SIEM, and central policy management with role-based access through Kaspersky Security Center. It answers none of the following: endpoint detection and response, continuous monitoring or a managed service, vulnerability and patch management, full disk encryption and key recovery, multi-factor authentication, mobile device management, email and phishing protection, backup and restore, and security awareness training. It also produces no evidence at all for Linux devices, macOS, mailboxes or cloud workloads. The cheaper route to closing those gaps is usually to stay inside the same vendor's endpoint line, for example Kaspersky Next EDR Optimum for workstations and servers, because both are administered from Kaspersky Security Center and the questionnaire answer stays consistent; mixing vendors means two consoles, two reporting formats and two sets of evidence to reconcile. Note that some questionnaires now also ask about vendor country of origin, which is covered in the section above.
The single decisive difference is that the Compliance Edition is the extended licence that unlocks two system inspection components, File Integrity Monitor and Log Inspection, which the standard licence does not activate. Everything else is the same application and the same installer; the licence key determines which components run. That matters if you need change records and log-based breach indicators as evidence rather than only preventive controls. If your requirement is limited to blocking unauthorised software and USB devices on a terminal, the standard licence covers it. The regional restriction below applies identically to both.
| Component | Standard licence | Compliance Edition |
|---|---|---|
| Anti-malware protection | ✓ | ✓ |
| Applications Launch Control | ✓ | ✓ |
| Device Control | ✓ | ✓ |
| Firewall Management | ✓ | ✓ |
| File Integrity Monitor | ✕ | ✓ |
| Log Inspection | ✕ | ✓ |
| Endpoint detection and response | ✕ | ✕ |
| Sale and updates in the United States | Prohibited | Prohibited |
The most important restriction is regional: Kaspersky may not sell this software to US persons and has been barred from delivering signature or codebase updates to US-based installations since 29 September 2024, so any terminal estate that includes US locations cannot be covered uniformly. The product is Windows-only; embedded devices running Linux require the separate Kaspersky Embedded Systems Security for Linux application, and Kaspersky explicitly states that this application is not intended for processes involving industrial control systems, where it points to Kaspersky Industrial CyberSecurity for Nodes instead. Central management is not self-contained: it requires an on-premises Kaspersky Security Center, and the Network Agent needed on each device is not part of the application's distribution kit. The gaps that most often trigger a follow-up purchase are endpoint detection and response, vulnerability and patch management, and disk encryption, none of which are part of this licence at any edition level. Finally, the two Compliance components generate findings but not conclusions, so someone has to review them regularly for the evidence to be worth anything in an audit.
Yes. The edition name refers to the two added system inspection components, not to the removal of anything. Real-time file protection and on-demand scanning are included, and the anti-malware component can be deliberately left out of the installation on weak hardware or slow links without affecting the control components.
It is a base licence for the application itself, not a renewal; Kaspersky sells renewals of the Compliance Edition as separate items. It does not require another Kaspersky product to be licensed first, although central management depends on Kaspersky Security Center being in place.
Central policy management, signature distribution and reporting run through Kaspersky Security Center, installed on-premises, using the matching administration or web plug-in. Each protected device also needs the Kaspersky Security Center Network Agent, which is not included in the application's distribution kit and has to be deployed separately.
Yes. The application is built for devices in remote or public locations with weak or intermittent links, and participation in the Kaspersky Security Network cloud lookup is optional. Devices can also be administered locally through the application console or the command line when no console connection is available.
| Operating Systems | Windows 11 version 24H2: IoT Enterprise 64-bit Windows 11 version 23H2: IoT Enterprise 64-bit Windows 11 version 22H2: IoT Enterprise 64-bit Windows 11 version 21H2: IoT Enterprise 64-bit Windows 10 version 22H2: IoT Enterprise 32-bit / 64-bit Windows 10 version 21H2: IoT Enterprise 32-bit / 64-bit Windows 10 version 1909: IoT Enterprise 32-bit / 64-bit Windows 10 version 1809: IoT Enterprise 32-bit / 64-bit Windows 10 version 1803: IoT Enterprise 32-bit / 64-bit Windows 10 version 1607: IoT Enterprise 32-bit / 64-bit Windows 10 version 1507: IoT Enterprise 32-bit / 64-bit Windows 8.1 Embedded: Industry / Pro 32-bit / 64-bit Windows 8.0 Embedded: Standard 32-bit / 64-bit Windows 7 Embedded SP1: Standard 32-bit / 64-bit Windows 7 Embedded POS Ready: Standard 32-bit / 64-bit Windows XP Embedded SP3: POS Ready 32-bit |
| Processor | Windows XP Embedded: 1.4 GHz single-core Pentium III x32 / Pentium IV x64 / Windows 10 and 11 IoT: 1.4 GHz single-core Pentium IV x64 |
| Memory RAM | Windows XP Embedded: 256 MB to install Applications Launch Control only / 512 MB to install all application components / Windows 10 and 11 IoT: 1 GB |
| Storage | Windows XP Embedded: 50 MB to install Applications Launch Control only / 2 GB to install all application components / Windows 10 and 11 IoT: 50 MB to install Applications Launch Control only / 2 GB to install all application components |
| Additional Requirements | Windows Installer 3.1 required on Microsoft Windows XP / Filter Manager required for embedded operating systems / SHA-2 support required in Microsoft Windows |