What are the core benefits of Kaspersky Next EDR Foundations Base?
Central console – Cloud or on-premises management for all endpoints.
Layered protection – File, web, mail and network threat protection.
Attack analysis – Root cause analysis shows the full infection chain.
Security controls – Device, web and application control policies per group.
Broad coverage – Windows, macOS, Linux, iOS, Android and file servers.
Important note – No patch management, encryption or full EDR component.
Download: Kaspersky Next EDR Foundations Base
Endpoint protection engine – File, web, mail and network threat protection with behaviour detection.
Root-cause analysis – Visual attack chain for every detection, without a separate console.
Security controls – Device, web and application control, plus host intrusion prevention.
Vulnerability assessment – Flags outdated third-party software on managed Windows devices.
Cloud discovery – Monitors which cloud services staff use; blocking needs Optimum.
Important – The Endpoint Detection and Response component itself requires Optimum.
Kaspersky Next EDR Foundations is the entry tier of the Kaspersky Next line and is managed centrally from one console, either as a cloud workspace or from an on-premises installation. Companies moving up from Kaspersky Endpoint Security Cloud keep the same Business Hub workspace and Pro View console.
One agent – One installer covers workstations, file servers and mobile devices.
Faster incident triage – The attack chain view removes manual log correlation work.
Predefined policies – Default security profiles apply protection without prior tuning work.
European data hosting – Swiss and EU workspaces run from the Ireland data centre.
Directory integration – Microsoft Entra ID import keeps user lists in sync.
Upgrade path – The same console moves you to Optimum or Expert.
The deciding factor is not headcount but whether anyone in your organisation has to investigate an incident after the fact. Foundations shows you the attack chain of a blocked detection; it does not give you the search, containment and guided response tools that an analyst uses to work a case.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | Often |
| Security questionnaire from large customers | Often | ✓ | ✓ |
| Needs full EDR investigation and response | ✕ | ✓ | ✓ |
| This product fits | ✓ | Partly | ✕ |
The reporting obligation under the revised Information Security Act has applied since 1 April 2025 and covers operators of critical infrastructure, including energy and water suppliers, transport companies, listed hospitals, data centre and cloud providers, and cantonal and communal administrations. Those organisations must report a significant cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with 14 days to complete the report. Kaspersky Next EDR Foundations supports that deadline in one concrete way: the root-cause analysis view reconstructs the process chain of a detection, so the initial report can state what was executed and on which device instead of stating that something was blocked. What it does not provide is long-term telemetry retention, threat hunting across historical data, syslog or SIEM export from the Pro View console, or any form of guided containment, which means the deeper investigation an authority follow-up usually requires still has to happen elsewhere. It also cannot tell you whether you are in scope, because that assessment depends on your sector and on the exemption thresholds in the Cybersecurity Ordinance. This page is a product description and not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.
No software product makes an organisation compliant with the NIS 2 Directive, because the directive addresses governance, risk management and process rather than tooling. NIS 2 requires categories of measure that include risk analysis and information system security policies, incident handling, business continuity and backup, supply chain security, vulnerability handling and disclosure, access control, cryptography and encryption, and basic cyber hygiene. Kaspersky Next EDR Foundations contributes to a subset of these: it delivers endpoint protection and access-related controls over devices, applications and web use, it produces the vulnerability assessment data that feeds vulnerability handling, and it gives incident handling a technical starting point through root-cause analysis. It does not address business continuity or backup, it carries no encryption management, no patch deployment to close the vulnerabilities it reports, and no supply chain or multi-factor authentication capability. Management responsibility, incident reporting workflows and supplier oversight remain organisational tasks that sit outside any endpoint product.
Germany's Federal Office for Information Security (BSI) issued a formal warning against the use of Kaspersky antivirus software on 15 March 2022 and has maintained it since; following the December 2025 amendment of the German BSI Act, the warning is now issued under Section 13 of that act. In the United States, the Department of Commerce prohibited the sale and distribution of Kaspersky software in June 2024, with sales ending in July 2024 and update delivery to US customers ending in September 2024. Kaspersky rejects the German warning as procedurally and factually unjustified, states that no substantiated misuse of its software has been documented, and points to its Global Transparency Initiative, under which threat-related files submitted by European users have been processed in two data centres in Zurich since November 2018. Switzerland has taken a different line: the Federal Office for Cybersecurity, formerly the NCSC, has not issued a warning, has stated that no misuse of Kaspersky software in Switzerland has been reported to it, and takes the position that product choice and the associated risk assessment are the responsibility of each organisation. The assessments concern supplier trust and jurisdiction rather than detection quality, which is a separate question. In practice this matters most if you bid for public sector contracts, supply German public bodies, operate or sell into the United States, or answer supply chain questionnaires that ask about vendor country of origin; for a purely domestic Swiss company with no such exposure it may not matter at all.
Partly, and it is worth knowing in advance which lines you will be able to tick. Foundations answers yes to centrally managed anti-malware on all endpoints, protection against ransomware and fileless attacks, removable media and BadUSB control, application allowlisting and blocking, web filtering, host intrusion prevention, regular vulnerability scanning of installed software, and central visibility of protection status across the estate. It answers no to full-disk encryption of notebooks, deployment of security patches, multi-factor authentication, data loss prevention, mailbox or Microsoft 365 protection, backup and restore, security awareness training, log forwarding to a SIEM, and continuous monitoring or 24/7 response. On incident investigation the honest answer is partial: root-cause analysis documents what happened on a single device, but there is no case management, no retrospective search and no guided containment. If the gaps that block a deal are encryption, patch deployment or training, moving up to Kaspersky Next EDR Optimum closes all three inside the same console and the same agent, which is usually cheaper and faster than adding a second vendor. Backup and multi-factor authentication are not part of any Kaspersky Next tier and have to be sourced separately whatever you choose.
The decisive difference is that the Endpoint Detection and Response component is only in Optimum. Foundations includes root-cause analysis as a standalone visualisation of an attack chain, whereas in Optimum the same analysis sits inside a working EDR module with indicator-of-compromise scanning and response actions. Optimum then adds the two manageability features that most often force a later upgrade, patch management and encryption management, plus adaptive anomaly control, Microsoft 365 protection and cybersecurity training. Both tiers share the identical protection engine and the identical set of device, web and application controls, so upgrading changes what you can do after a detection, not how well threats are blocked in the first place.
| Feature | EDR Foundations | EDR Optimum |
|---|---|---|
| Endpoint protection and security controls | ✓ | ✓ |
| Root-cause analysis | ✓ | Within EDR |
| Endpoint Detection and Response component | ✕ | ✓ |
| Patch management | ✕ | ✓ |
| Encryption management | ✕ | ✓ |
| Adaptive anomaly control | ✕ | ✓ |
| Microsoft 365 protection | ✕ | ✓ |
| Cybersecurity training | ✕ | ✓ |
The cloud workspace is subject to a regional restriction: it is not available for companies registered in the United States or its territories, and the hosting region is derived automatically from the country you enter when you create the workspace rather than being freely selectable. Companies registered in Switzerland, Germany, Austria, France, Italy and most other European countries are placed in the Ireland data centre region, which is worth confirming against your own data residency policy before you deploy. Coverage is broadest on Windows, where the full protection stack, root-cause analysis and the complete set of controls apply; macOS, Linux, iOS and Android are protected and managed but with a narrower feature set, and mobile device management for iOS requires an Apple Push Notification service certificate that you must create and renew yourself. Foundations protects file servers with the same agent, but it is not a dedicated server product and does not cover Exchange, mail gateways or containerised workloads. The two limitations that most often trigger a follow-up purchase are the missing patch management, which leaves you reading vulnerability reports without a way to act on them from the console, and the missing encryption management, which is the first item most large customers ask about for notebooks.
Yes. Kaspersky Next manages endpoints, mobile devices and file servers from the same console, and Kaspersky Endpoint Security for Windows supports Windows Server operating systems including Core installations. For Exchange, SharePoint or database servers you would need a dedicated Kaspersky server or mail product instead.
Yes. Kaspersky offers Foundations with either a cloud-hosted workspace or an on-premises management installation, so organisations that cannot place management data with a hosted service can run the console on their own infrastructure. The protection components on the endpoints are the same in both cases.
| Operating Systems | Windows 11: Home / Pro / Pro for Workstations / Education / Enterprise Windows 10: Home / Pro / Pro for Workstations / Education / Enterprise / Enterprise multi-session Windows 8.1: Professional / Enterprise Windows 8: Professional / Enterprise Windows 7: Home / Professional / Ultimate / Enterprise Service Pack 1 or later Windows Server 2022: Standard / Datacenter / Datacenter Azure Edition / Core Mode Windows Server 2019: Essentials / Standard / Datacenter / Core Mode Windows Server 2016: Essentials / Standard / Datacenter / Core Mode Windows Server 2012 R2: Foundation / Essentials / Standard / Datacenter / Core Mode Windows Server 2012: Foundation / Essentials / Standard / Datacenter / Core Mode Windows Server 2008 R2: Foundation / Standard / Enterprise / Datacenter Service Pack 1 or later Windows Web Server 2008 R2: Service Pack 1 or later Windows Small Business Server 2011: Essentials / Standard 64-bit Windows MultiPoint Server 2011 64-bit |
| Processor | CPU Workstation 1 GHz / CPU Server 1.4 GHz / SSE2 instruction set support |
| Memory RAM | Workstation x86 1 GB / Workstation x64 2 GB / Server 2 GB / Server for EDR deployment 8 GB |
| Storage | 2 GB free disk space |