What are the core benefits of Kaspersky Embedded Systems Security Compliance Edition?
Central management – Policies and reports via Kaspersky Security Center.
Default deny – Blocks every application outside the approved list.
Integrity monitoring – Flags changes to protected files and logs.
Legacy support – Runs on old Windows and low-end hardware.
Device control – Restricts USB sticks and other connected peripherals.
Important note – No EDR, patch management or encryption included.
Real-Time File Protection – Scans files, boot sectors and NTFS streams on access.
Applications Launch Control – Allows only approved executables, libraries and drivers to run.
Device Control – Clocks unauthorised USB flash drives and other peripherals.
File Integrity Monitor – Detects changes to defined files, including changes made offline.
Log Inspection – Reviews Windows event logs for signs of intrusion.
Important – No EDR, patch management, encryption or mobile coverage.
Kaspersky Embedded Systems Security Compliance Edition is a standalone protection product for Windows-based embedded devices such as ATMs, POS terminals, ticketing machines and medical equipment. It runs as an agent on each device and is managed centrally through Kaspersky Security Center, while a local application console and a command line remain available for devices with poor connectivity.
Runs on legacy Windows – Protects devices still running unsupported Windows versions.
Low resource footprint – Designed for low-end hardware and weak network links.
Default Deny mode – Can be installed without the anti-malware component.
Ransomware defences – Anti-Cryptor and Remediation Engine roll back malicious changes.
Exploit Prevention – Protects process memory against exploitation of known vulnerabilities.
SIEM export – Sends events to syslog or a SIEM platform.
The deciding factor is not headcount but whether you operate Windows terminals that cannot be patched or replaced on a normal cycle. A retailer with twelve checkout systems has the same technical problem as a bank with a national ATM fleet, but only the larger operator usually needs the central console, the audit trail and the evidence reports.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | ✓ |
| NIS 2 in the European Union | Rarely | By sector | By sector |
| Security questionnaire from large customers | Sometimes | ✓ | ✓ |
| Central console for terminals across several sites | Limited | ✓ | ✓ |
| This product fits | Only for terminals | ✓ | ✓ |
The reporting obligation under the revised Information Security Act applies to operators of critical infrastructure, including energy and drinking water suppliers, transport companies, hospitals, financial service providers and cantonal and communal administrations, not to every company that runs a payment terminal. Those operators must submit an initial report to the Federal Office for Cybersecurity (BACS) within 24 hours of discovering a qualifying cyberattack, with the remaining details following within 14 days. Two components of this edition help you hold that deadline on embedded devices: Log Inspection surfaces suspicious Windows event log patterns, and the File Integrity Monitor records changes to defined files, including changes made while the device was switched off, which is what lets an administrator reconstruct when a terminal was manipulated. Events can be forwarded to a syslog server or SIEM, so the timeline needed for the report does not have to be assembled from each device by hand. What it does not do is decide whether an incident is reportable, cover servers, workstations or mobile devices outside the embedded scope, or provide the root-cause analysis an EDR product would deliver, so the classification decision stays with your team. This is not legal advice, and whether your organisation falls under the reporting obligation must be assessed in each individual case.
No software product creates NIS 2 compliance, because the directive addresses organisational risk management, not a product feature list. NIS 2 requires categories of measures such as risk analysis and security policies, incident handling, business continuity, supply chain security, security in the acquisition and maintenance of systems including vulnerability handling, access control and asset management, cryptography, cyber hygiene and training, and multi-factor authentication. This edition contributes to a narrow but relevant part of that: system hardening through Applications Launch Control, removable media control, detection and logging on devices that no longer receive operating system patches, and event export for incident handling. It contributes nothing to multi-factor authentication, encryption, vulnerability and patch management, backup and continuity, or staff training, and it covers only Windows-based embedded devices, so the rest of your estate needs separate measures. Supply chain security is also a category where the vendor question below is part of the assessment rather than something the product resolves.
On 20 June 2024 the US Department of Commerce, Bureau of Industry and Security, issued a Final Determination prohibiting Kaspersky from providing anti-virus and cybersecurity products or services in the United States or to US persons. New sales stopped on 20 July 2024 and updates to existing US customers ended on 29 September 2024; related entities were added to the Entity List. The measure remains in force, and Kaspersky closed its US operations. Germany's Federal Office for Information Security (BSI) published a warning about Kaspersky anti-virus software on 15 March 2022 and confirmed in 2026 that it maintains it; the BSI has no legal basis for a sales ban, so the product remains legally available in Germany. Italy, the Netherlands, Canada and Australia have restricted use in government or public-sector procurement. Kaspersky states that it is a private company without ties to any government, describes the decisions as politically motivated, and points to its relocation of European data processing to Zurich in 2018 and to its Transparency Centres. Both authorities based their positions on supplier risk and the possibility of state influence, not on published findings that the software fails to detect malware. In practice this matters most if you sell to US persons, bid for public-sector contracts, or answer supply chain questionnaires that ask about vendor jurisdiction; in Switzerland and the European Union the product is sold and updated normally. Whether that residual risk is acceptable is a decision for your organisation.
Yes, for the questions about endpoint hardening and change monitoring, and not for most of the rest. You can answer positively on malware protection for systems running end-of-life operating systems, application allowlisting through Default Deny, control of removable media, file integrity monitoring on defined paths, review of system logs, centrally enforced policies, and forwarding of security events to a SIEM. You cannot answer the questions on continuous endpoint detection and response, 24/7 monitoring, patch and vulnerability management, disk encryption, multi-factor authentication, backup and restore testing, mobile device management, or security awareness training, and you will have to state that these are covered elsewhere or not at all. One item deserves particular attention here: questionnaires from regulated customers increasingly ask about vendor country of origin, and no additional Kaspersky product closes that item. For the technical gaps, extending within the same family is usually cheaper and less work than mixing vendors, since Kaspersky's endpoint and management products share the same console; the vendor-origin question, by contrast, can only be answered by documenting your risk assessment or by changing supplier.
The single decisive difference is system inspection: the File Integrity Monitor, Log Inspection and Registry Access Monitor are unlocked by the Compliance Edition licence and are not available in the standard edition. Both editions ship the same protection engine, so the choice is not about malware detection quality. Kaspersky offers the two as separate licences of the same product, and the compliance components are enabled by the licence rather than installed as a different application. Choose the Compliance Edition when you have to prove after the fact what changed on a terminal, for example for card payment audits or an incident report; choose the standard edition when you only need protection and control.
| Component | Standard edition | Compliance Edition |
|---|---|---|
| Real-Time File Protection and On-Demand Scan | ✓ | ✓ |
| Applications Launch Control | ✓ | ✓ |
| Device Control and Firewall Management | ✓ | ✓ |
| File Integrity Monitor | ✕ | ✓ |
| Log Inspection | ✕ | ✓ |
| Registry Access Monitor | ✕ | ✓ |
| EDR and patch management | ✕ | ✕ |
The components described here belong to the Windows version; embedded devices running Linux are covered by a separate Kaspersky product and are not protected by this licence. Kaspersky states in its own documentation that update functionality and Kaspersky Security Network may not be available in the software in the United States, which is the practical consequence of the US prohibition and matters for groups with American sites. The product is explicitly not intended for automated process control systems, where Kaspersky points to Kaspersky Industrial CyberSecurity for Nodes instead, so a plant with SCADA nodes needs a different licence for that part of the estate. Central policies, reports and deployment require Kaspersky Security Center, which is a separate on-premises installation to plan and maintain; without it you manage each device through its local console or the command line. The most common follow-up purchases are endpoint protection for normal office PCs and servers, and patch management, because neither is part of this product.
No. The application can be operated entirely locally through its own console or the command line, which is the usual approach for a handful of terminals. Kaspersky Security Center becomes necessary as soon as you want one policy set, one status view and one report across many devices.
Yes, that is one of its design goals. The application can be installed in a Default Deny configuration without the anti-malware component, which removes the need for regular signature downloads and suits terminals on slow or intermittent links.
No. Kaspersky distinguishes base licences from renewals, and a base licence is a new licence that does not require an existing one of the same product. A renewal, by contrast, is tied to a licence you already hold.
Not sensibly. It is built for fixed-function devices with a narrow application set, and it has no web or mail protection and no EDR. Office workstations and servers belong on Kaspersky's endpoint products, which is also why many buyers run both.
| Operating Systems | Windows XP Embedded SP3 POS Ready 32-bit Windows 7 Embedded POS Ready Standard 32-bit / 64-bit Windows 7 Embedded SP1 Standard 32-bit / 64-bit Windows 8.0 Embedded Standard 32-bit / 64-bit Windows 8.1 Embedded Industry / Pro 32-bit / 64-bit Windows 10 version 1507 IoT Enterprise 32-bit / 64-bit Windows 10 version 1607 IoT Enterprise 32-bit / 64-bit Windows 10 version 1803 IoT Enterprise 32-bit / 64-bit Windows 10 version 1809 IoT Enterprise 32-bit / 64-bit Windows 10 version 1909 IoT Enterprise 32-bit / 64-bit Windows 10 version 21H2 IoT Enterprise 32-bit / 64-bit Windows 10 version 22H2 IoT Enterprise 32-bit / 64-bit Windows 11 version 21H2 IoT Enterprise 64-bit Windows 11 version 22H2 IoT Enterprise 64-bit Windows 11 version 23H2 IoT Enterprise 64-bit Windows 11 version 24H2 IoT Enterprise 64-bit |
| Processor | Minimum 1.4 GHz single-core CPU Pentium III for 32-bit systems / Pentium IV for 64-bit systems or higher |
| Memory RAM | Windows XP Embedded: 256 MB to install Applications Launch Control component only / 512 MB to install all application components / 2 GB recommended / Windows 10 and 11 IoT: 1 GB minimum / 2 GB recommended |
| Storage | 50 MB to install Applications Launch Control component only / 2 GB to install all application components / 4 GB recommended for full installation and logs |
| Additional Requirements | SHA-2 support in Windows required for correct operation / Filter Manager component required on embedded Windows operating systems / Windows Installer 3.1 required on Windows XP family devices |