What are the core benefits of Kaspersky Next EDR Foundations Base Plus?
Central console – Manage all endpoints from cloud or on-premises.
Endpoint protection – Blocks ransomware, exploits and fileless attacks on devices.
Root cause – Shows how an incident reached the endpoint.
Security controls – Device, web and application rules per policy.
Platform coverage – Windows, macOS, Linux, Android and iOS.
Important note – No patch management or encryption management included.
Download: Kaspersky Next EDR Foundations Base Plus
Endpoint protection engine – File, web, mail and network threat protection with firewall.
Behaviour based defence – Behaviour detection, exploit prevention and automatic remediation of changes.
Root cause analysis – Visual attack chain showing how an incident started.
Security controls – Device, web and application control plus host intrusion prevention.
Vulnerability and cloud discovery – Flags outdated software and cloud services used by staff.
Important – The Endpoint Detection and Response component itself is not included.
Kaspersky Next EDR Foundations is the entry tier of the Kaspersky Next business line and is managed centrally from the Kaspersky console, either cloud hosted or installed on your own server. It is the successor to Kaspersky Endpoint Security for Business Select, the name many buyers and independent test reports still use.
One console – Rollout, policies and alerts handled from a single interface.
Predefined policies – Ready made security profiles shorten first time configuration.
Deployment choice – Run the console in the cloud or on premises.
Mixed fleet coverage – Protects Windows, macOS and Linux workstations and servers.
Faster incident triage – Root cause analysis replaces manual log reconstruction after alerts.
Upgrade path – The same console scales up to the Optimum tier.
The deciding factor is not headcount but whether anyone in the organisation is expected to investigate an alert. Foundations is built for companies where IT staff, not a security team, run security alongside their other duties. Once a customer contract or a regulator expects documented response actions and retained telemetry, the tier above becomes the realistic starting point.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | ✕ | By sector | By sector |
| NIS 2 in the European Union | ✕ | By sector | By sector |
| Security questionnaire from large customers | ✓ | ✓ | ✓ |
| Needs guided response actions and retained EDR telemetry | ✕ | Sometimes | ✓ |
| This product fits | ✓ | Partly | ✕ |
The Swiss reporting obligation applies to operators of critical infrastructure: since 1 April 2025 they must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with the remaining detail due within 14 days. Companies outside the listed sectors, and smaller organisations below the thresholds set in the Cybersecurity Ordinance, are generally not covered, so the first question is whether the revised Information Security Act applies to you at all. Where it does, this product supports the duty in a narrow but useful way: the console holds detection records, device status and a root cause analysis of the incident, which is the material an initial report needs within the first day. What it does not provide is retained forensic telemetry, guided response actions or an incident picture beyond the affected endpoint, so an attack that spread across servers, mail or cloud services will need additional tooling or an external incident responder to describe fully. This text is general product information and not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.
No software product makes a company compliant with the NIS 2 Directive, because the directive sets organisational duties rather than product features. The measure categories it requires include risk analysis and security policies, incident handling, business continuity and backup, supply chain security, vulnerability handling, access control, cryptography and staff awareness training. This tier contributes to three of them: endpoint incident handling through its detection and root cause analysis, vulnerability handling through the assessment scan that flags outdated applications, and access control through device, application and web control policies. Business continuity and backup are entirely outside its scope, cryptography is not covered because encryption management begins in the Optimum tier, and neither staff awareness training nor supply chain assessment is included. Treat it as one technical building block for two or three categories, with the remaining categories requiring separate processes, documented evidence and in some cases separate products.
Germany's Federal Office for Information Security has warned against the use of Kaspersky virus protection software since 15 March 2022, and that warning remains in force, now under the amended information security act that took effect on 6 December 2025. In the United States, the Department of Commerce prohibited the sale of Kaspersky software from 20 July 2024 and the delivery of updates from 29 September 2024. Switzerland has taken neither step: the Federal Office for Cybersecurity does not issue product recommendations, has stated it has no internal directive concerning Kaspersky software, and has reported no cases of misuse in Switzerland. Kaspersky rejects the allegations, points to its Swiss data processing infrastructure and its holding structure outside Russia, and in early 2026 formally asked the German authority to withdraw the warning while reserving the right to legal steps. Independent testing has continued in parallel: Kaspersky business products took part in the AV-Comparatives Business Main-Test Series through 2025 and received the Endpoint Prevention and Response certification for that year. In practice this matters most to public sector suppliers, organisations bound by German or United States procurement rules, and companies whose large customers ask about vendor country of origin in supplier questionnaires; for a privately held Swiss or European company with no such obligations, it is a documentation question rather than a blocking one.
Partly, and it is worth knowing in advance which questions it will not answer. It covers the items on centrally managed malware protection across all workstations and servers, protection status reporting per device, removable media and device control, application control, web filtering, host intrusion prevention, and a recurring vulnerability scan that documents outdated software. It does not answer the items on patch deployment and patch evidence, disk encryption and key recovery, retained endpoint telemetry with defined storage periods, documented response actions during an incident, security awareness training records, or protection of Microsoft 365 mailboxes and files, because none of those functions exist in this tier. A question about the vendor's country of origin will also come up in supplier assessments from public sector customers and from suppliers to German authorities. Where the gaps block a contract, moving up to Kaspersky Next EDR Optimum closes patch management, encryption management, the EDR component and training in one step and keeps a single agent and console, which is usually cheaper and faster to document than adding a second vendor for patching or encryption alongside this one.
The single decisive difference is the Endpoint Detection and Response component: Foundations gives you root cause analysis so you can see how an incident started, but the EDR component with its investigation and response workflow only exists in Optimum. The second gap that drives most upgrades is operational rather than analytical, since patch management and encryption management both sit in Optimum, and those two are the functions companies most often end up buying separately if they stay on Foundations. Both tiers share the same endpoint protection engine, the same security controls and the same management console, so moving up does not mean replacing the product. The table below lists the differences that affect a buying decision.
| Feature | EDR Foundations | EDR Optimum |
|---|---|---|
| File, web, mail and network threat protection | ✓ | ✓ |
| Root cause analysis | ✓ | Within EDR |
| Endpoint Detection and Response component | ✕ | ✓ |
| Patch management | ✕ | ✓ |
| Encryption management | ✕ | ✓ |
| Adaptive Anomaly Control | ✕ | ✓ |
| Microsoft 365 protection | ✕ | ✓ |
| Cybersecurity training | ✕ | ✓ |
| Remote wiping of a Windows device | ✕ | ✓ |
The regional restriction is the one to check first: Kaspersky software may not be sold in the United States since 20 July 2024 and has not received updates there since 29 September 2024, so a company with a United States branch cannot cover those devices from the same purchase and needs a second product for that site. Platform coverage is broad but uneven, because protection runs on Windows, macOS and Linux workstations and servers while the mobile side is limited to controls for Android and supervised iOS and iPadOS devices rather than a full mobile security suite. The two omissions that most often trigger a follow-up purchase are patch management and encryption management, both of which begin in the Optimum tier and are routinely requested in customer security questionnaires. There is no backup or recovery function at any Kaspersky Next tier, so ransomware protection here means prevention and rollback of malicious changes, not a restorable copy of your data. Finally, root cause analysis explains an incident on the affected device, but it does not retain long-term telemetry or correlate events across servers, mail and cloud services.
Base Plus is a base licence, meaning it is intended for a new installation and does not require an existing licence of the same product. In Kaspersky's licence naming, the addition Plus identifies the higher technical support tier rather than an extra set of product features, so the functional scope is identical to the standard Foundations edition.
Malicious and suspicious files submitted by European users have been processed in two data centres in Zurich, Switzerland since November 2018, and Kaspersky completed the relocation of the associated storage and processing activities in 2020. This is a point worth documenting when a customer asks about data location in a supplier assessment.
Partly. Web control is available for Android and for supervised iOS and iPadOS devices, and application control is available for Android, which covers policy enforcement on company phones and tablets. It is not a full mobile threat defence product, so treat mobile as controlled rather than protected at this tier.
| Operating Systems | Windows 11 2021: 21H2 Home / Professional / Education / Enterprise 32-bit / 64-bit Windows 10 2017: RS3 1703 Home / Professional / Education / Enterprise 32-bit / 64-bit Windows 10 2018: RS4 1803 / RS5 1809 Home / Professional / Education / Enterprise 32-bit / 64-bit Windows 10 2019: 19H1 1903 / 19H2 1909 Home / Professional / Education / Enterprise 32-bit / 64-bit Windows 10 2020: 20H1 2004 / 20H2 2009 Home / Professional / Education / Enterprise 32-bit / 64-bit Windows 10 2021: 21H1 / 21H2 Home / Professional / Education / Enterprise 32-bit / 64-bit Windows 8.1: Professional / Enterprise 32-bit / 64-bit Windows 7: Home / Professional / Enterprise / Ultimate Service Pack 1 32-bit / 64-bit Windows Server 2008: Standard / Enterprise Service Pack 2 64-bit Windows Server 2008 R2: Foundation / Standard / Enterprise Service Pack 1 64-bit Windows Server 2012: Foundation / Standard / Enterprise / Datacenter 64-bit Windows Server 2012 R2: Foundation / Standard / Enterprise / Datacenter 64-bit Windows Server 2016: Essentials / Standard / Datacenter 32-bit / 64-bit Windows Server 2019: Essentials / Standard / Datacenter 32-bit / 64-bit Windows Server 2020: 20H2 Standard Core / Datacenter Core 64-bit |
| Processor | Workstation 1.4 GHz single core / Server 1.4 GHz single core |
| Memory RAM | Workstation 1 GB / Server 512 MB |
| Storage | 500 MB free disk space |
| Browser | Google Chrome for Windows is required to manage Kaspersky Endpoint Agent using Kaspersky Security Center Web Console |
| Management | Kaspersky Security Center 13.1 and later or Kaspersky Security Center Cloud Console / Managed via Kaspersky Security Center Web Console 13.1 and later or cloud Administration Console |