What are the core benefits of Kaspersky Next Complete Security?
Cloud console – One central web console manages all protected devices.
Managed detection – Kaspersky SOC analysts monitor and hunt threats around the clock.
Built-in EDR – Root-cause analysis and automated response on endpoints.
Patch management – Closes Windows software vulnerabilities without a separate tool.
Broad coverage – Windows, macOS, Linux, Android and iOS devices.
Important note – Cloud management only, no on-premises console available.
Download: Kaspersky Next Complete Security
Endpoint Protection Platform – File, web, mail and network threat protection plus firewall.
Endpoint Detection and Response – IoC scanning, root-cause analysis and automated or guided response.
Managed Detection and Response – Kaspersky SOC monitors your telemetry and hunts threats continuously.
Vulnerability and Patch Management – Finds and installs missing updates on Windows devices.
Encryption and Device Control – Manages BitLocker and FileVault, USB and application access.
Important – Management is cloud based only, no on-premises console option.
Kaspersky Next Complete Security is a cloud-managed package that combines the endpoint protection and EDR capabilities of the Kaspersky Next Optimum tier with Kaspersky Managed Detection and Response, all administered from one browser-based workspace. It belongs to the Kaspersky Next line, which Kaspersky positions as the successor to Kaspersky Endpoint Security Cloud, the name many buyers still search for.
One console for everything – Policies, patching, encryption and EDR alerts in one place.
SOC without hiring – Kaspersky analysts triage alerts your team has no time for.
Three months telemetry – Raw event data stays available for later incident reconstruction.
Swiss data processing – Threat data from European users is processed in Zurich.
Shadow IT visibility – Cloud Discovery reports and blocks unapproved cloud services.
REST API integration – Connects MDR incidents to an existing IRP or SOAR tool.
The deciding factor is not headcount but whether anyone in the company is available to look at security alerts outside office hours. Companies with one or two IT generalists gain the most, because the MDR component absorbs the night and weekend shift that an internal team cannot staff.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | Often |
| NIS 2 in the European Union | Rarely | By sector | Usually |
| Security questionnaire from large customers | ✓ | ✓ | ✓ |
| Round-the-clock alert monitoring without own SOC | ✓ | ✓ | Partial |
| This product fits | ✓ | ✓ | Limited |
No security product on its own satisfies the Swiss rules, and this one does not either. Since 1 April 2025 the revised Information Security Act obliges operators of critical infrastructure, including energy and drinking water supply, transport companies and cantonal and communal administrations, to report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with sanctions applying since 1 October 2025. Meeting a 24-hour deadline depends on noticing the incident in the first place, and this is the part the product supports concretely: the MDR service monitors telemetry continuously, and root-cause analysis plus three months of stored raw telemetry give you the attack path, affected devices and time of first compromise that a report has to contain. What it does not do is file the report, define who inside your company is authorised to file it, or prove that the internal escalation chain worked, and it holds no telemetry beyond the three-month window if an incident surfaces later. This text is general product information and not legal advice, so clarify your own reporting duty with qualified legal counsel.
The NIS 2 Directive addresses organisations, not software, so no purchase makes a company compliant. The directive requires risk management measures in areas such as incident handling, business continuity and backup management, supply chain security, access control and asset management, along with incident notification duties. This product maps onto incident handling through EDR and the managed SOC service, onto access control through device, web and application control and encryption management, and onto asset and vulnerability management through the vulnerability assessment and patching functions. It contributes nothing to business continuity and backup management, nothing to supply chain security assessment of your own suppliers, and nothing to the governance, training records and policy documentation that assessors ask for. Treat it as evidence for a subset of technical measures, not as a compliance package.
Two official measures are relevant and both are still in force. Germany's Federal Office for Information Security warned against the use of Kaspersky antivirus software on 15 March 2022; the warning has been maintained and, following the amendment that took effect on 6 December 2025, is now issued under Section 13 of the BSI Act. The stated reason is confidence in the reliability and independent operational capability of the manufacturer, not a specific technical flaw found in the software. Separately, the US Department of Commerce issued a final determination on 20 June 2024 prohibiting Kaspersky from supplying cybersecurity and antivirus products to US persons, with resale, integration and signature updates prohibited from 29 September 2024. Kaspersky rejects the German warning as unjustified and not based on an objective technical analysis, points to its Global Transparency Initiative, its transparency centres and third-party audits, and notes that threat-related data from European users is processed in Zurich. Independent testing has continued regardless: Kaspersky business products were included in the AV-Comparatives Business Main-Test Series through the August to November 2025 round. In practice this matters most if you sell to the public sector, if a customer contract or security questionnaire excludes vendors named in an authority warning, or if your group has US entities that would be covered by the prohibition. For a purely domestic Swiss or EU company with no such clauses, it is a documentation question rather than a legal barrier.
Yes, for the endpoint and detection sections, and not at all for several others. It answers questions on centrally managed malware protection, ransomware protection with a remediation engine, disk encryption enforced through BitLocker and FileVault, removable media and application control, vulnerability scanning and patch deployment on Windows, and round-the-clock monitoring with a documented response process, and the console produces the reports and device inventories that auditors ask to see. It answers nothing on backup and restore testing, nothing on multi-factor authentication, nothing on data loss prevention outside Microsoft 365 file discovery, nothing on on-premises mail server or gateway filtering, and nothing on your own supplier assessment process, secure development or staff vetting. A further point that catches people out: questionnaires increasingly contain a question about vendors subject to official warnings, and the answer here is not blank. To close the technical gaps, moving up within the Kaspersky Next family is usually cheaper and simpler to document than adding a second endpoint vendor, but backup and identity are separate purchases whatever tier you choose.
The decisive difference is who watches the alerts. The technical feature set is the same in both, but Complete Security adds the Kaspersky SOC as a managed service, so detection, triage and threat hunting run continuously instead of waiting for your administrator to open the console on Monday morning. If you have someone who reviews alerts daily and can act on them, EDR Optimum covers the tooling. If nobody does, the tooling produces alerts that nobody reads. The entry tier, Kaspersky Next EDR Foundations, sits below both and omits patch management, encryption management, the EDR component itself and Microsoft 365 protection.
| Capability | Kaspersky Next EDR Optimum | Kaspersky Next Complete Security |
|---|---|---|
| Endpoint protection and controls | ✓ | ✓ |
| EDR with root-cause analysis | ✓ | ✓ |
| Patch and encryption management | ✓ | ✓ |
| Monitoring and threat hunting by Kaspersky SOC | ✕ | ✓ |
| Three months of raw telemetry storage | ✕ | ✓ |
| On-premises management console | ✕ | ✕ |
| Availability in the United States | ✕ | ✕ |
The regional restriction is the one that ends evaluations: Kaspersky has been prohibited from supplying cybersecurity products to US persons since 29 September 2024, so a group with a US subsidiary cannot standardise on this product across all sites. Coverage is also uneven across platforms even though the agent runs on Windows, macOS, Linux, Android and iOS: vulnerability assessment, patch management and Cloud Discovery work on Windows devices only, and on mobile devices real-time anti-malware is available for Android while iOS and iPadOS get password protection, anti-theft and control functions. Management is cloud based with no on-premises console at this tier, and the data centre region is fixed by the country you enter when the workspace is created, which is worth checking before rollout if you have data residency requirements in a contract. Two components buyers regularly assume are included are not: there is no backup and restore function, and there is no protection for an on-premises mail server such as Exchange, which remains a separate Kaspersky product. Finally, MDR delivers recommendations and can act on your behalf, but the decision to isolate a production server still needs someone on your side who can authorise it.
Yes. The licence activates Kaspersky Security for Microsoft Office 365, which scans corporate mail, file sharing and collaboration services for malware, phishing and spam. Data Discovery additionally reports which files in Microsoft 365 storage are shared privately, internally or externally.
The workspace is hosted in a data centre region determined by the country you specify when registering the company, and the security application installation packages sit on the same servers. Separately, threat-related data submitted by users in Europe is processed and stored in Kaspersky data centres in Zurich.
Windows file servers are covered by the same agent and receive ransomware protection through behaviour detection, exploit prevention and the remediation engine, and Linux endpoints are covered by the shared security profile. Application servers with database or mail workloads normally need exclusions configured before rollout to avoid performance problems.
You enter employee email addresses in the console and the system sends each user a single installation link, which detects the operating system and downloads the matching package. A default security profile is applied automatically once a device connects, so devices are protected before an administrator configures anything.
| Operating Systems | Windows 11: Home / Pro / Pro for Workstations / Education / Enterprise Windows 10: Home / Pro / Pro for Workstations / Education / Enterprise / Enterprise multi-session Windows 8.1: Professional / Enterprise Windows 8: Professional / Enterprise Windows 7: Home / Professional / Ultimate / Enterprise Service Pack 1 or later Windows Server 2022: Standard / Datacenter / Datacenter Azure Edition / Core Mode Windows Server 2019: Essentials / Standard / Datacenter / Core Mode Windows Server 2016: Essentials / Standard / Datacenter / Core Mode Windows Server 2012 R2: Foundation / Essentials / Standard / Datacenter / Core Mode Windows Server 2012: Foundation / Essentials / Standard / Datacenter / Core Mode Windows Server 2008 R2: Foundation / Standard / Enterprise / Datacenter Service Pack 1 or later Windows Web Server 2008 R2: Service Pack 1 or later Windows Small Business Server 2011: Essentials / Standard 64-bit Windows MultiPoint Server 2011 64-bit |
| Processor | Workstation CPU 1 GHz / Server CPU 1.4 GHz / SSE2 instruction set support |
| Memory RAM | Workstation x86 1 GB / Workstation x64 2 GB / Server 2 GB / Server for EDR deployment 8 GB |
| Storage | 2 GB free disk space |
| Architecture | Arm architecture is not supported |
| Management | Kaspersky Security Center 12 / 13 / 13.1 / 13.2 / 13.2.2 / 14 / 14.1 / 14.2 / Kaspersky Security Center Linux 14.2 / 15 |