What are the key advantages of Kaspersky Next EDR Optimum Base Plus?
Central console – One cloud console manages every protected device.
Built-in EDR – IoC scanning, host isolation and root-cause analysis.
Patch management – Updates Windows and third-party applications from the console.
Encryption management – Configures BitLocker and FileVault centrally.
Broad coverage – Windows, macOS, Linux, Android and iOS devices.
Important note – No managed service; your team handles alerts.
Download: Kaspersky Next EDR Optimum Base Plus
Endpoint protection – File, web, mail, network threat protection and firewall on every device.
Endpoint Detection and Response – IoC scanning, guided response, network isolation, execution prevention.
Patch management – Finds and installs missing Windows and third-party application updates.
Encryption management – Central BitLocker on Windows and FileVault on macOS control.
Cloud and Microsoft 365 – Blocks unwanted cloud services and protects Microsoft 365 mailboxes.
Important – No managed detection service; your own staff triage alerts.
Kaspersky Next EDR Optimum is the middle tier of the Kaspersky Next line, introduced in April 2024 to succeed the earlier business range that included Kaspersky Endpoint Security for Business and Kaspersky EDR Optimum. It combines endpoint protection with essential EDR functions and is administered from a single cloud console, with an on-premises installation available as an alternative.
One console – Replaces separate antivirus, patching and BitLocker recovery tools.
Root-cause analysis – Shows the attack chain as a visual graph.
Host isolation – Cuts an infected device off without visiting the desk.
Swiss data processing – European threat data is processed in two Zurich data centres.
Independent test results – AV-TEST rated Kaspersky Endpoint Security 6/6/6 in April 2026.
Staff training – Built-in cybersecurity training for the IT team.
The tier is built for organisations that have IT staff but no security operations centre. Below the console level it behaves like ordinary endpoint protection; above roughly a few hundred devices, the missing SIEM export and multi-tenancy start to matter.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rare | By sector | By sector |
| NIS 2 in the European Union | Mostly exempt | By sector | By sector |
| Security questionnaire from large customers | Occasionally | ✓ | ✓ |
| Own staff to triage EDR alerts | Limited | ✓ | ✓ |
| This product fits | ✓ | ✓ | Limited |
The reporting duty introduced by the revised Information Security Act applies to operators of critical infrastructure, not to every company, and has been in force since 1 April 2025. Those operators must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovering it, with a further 14 days to complete the report. Kaspersky Next EDR Optimum supports the content of that first report: the alert card, the root-cause analysis graph and the exportable alert information document how the attack entered, which devices it touched and which response measures were applied. What the product does not do is decide whether your organisation falls in scope, track the deadline, file the report, or retain correlated logs from firewalls, servers and cloud services in the way an audit-grade evidence trail requires — the EDR data covers endpoints only. This text is not legal advice; whether the reporting duty applies to your organisation should be clarified with your own legal counsel.
No software product creates compliance with the NIS 2 Directive, because the directive addresses organisational risk management, governance and reporting rather than tooling. NIS 2 requires measures in categories such as incident handling, vulnerability handling and disclosure, cryptography and encryption, cyber hygiene and security training, access control, supply chain security and business continuity. This product contributes directly to three of them: incident handling through detection, host isolation and guided response; vulnerability handling through vulnerability assessment and patch deployment; and cryptography through central management of BitLocker and FileVault. It also covers basic security training for IT staff. It contributes nothing to business continuity and backup, supply chain risk management, multi-factor authentication, or the documented policies and effectiveness reviews that assessors ask for, so those measures have to be built elsewhere in the organisation.
Two official measures are in force. Germany's Federal Office for Information Security (BSI) has warned against the use of Kaspersky antivirus software since 15 March 2022 and continues to publish that warning, which since December 2025 rests on Section 13 of the amended BSI Act. In the United States, the Department of Commerce issued a final determination in June 2024 prohibiting Kaspersky from supplying its antivirus and cybersecurity products to US persons, with new sales stopping on 20 July 2024 and signature and codebase updates on 29 September 2024. Kaspersky's own position is that the German warning is not justified and was not based on an objective technical analysis of its software; the company points to its Global Transparency Initiative, under which threat data from European users is processed in two data centres in Zurich. Independent testing has continued throughout: AV-TEST awarded Kaspersky Endpoint Security top marks of 6/6/6 for protection, performance and usability in its April 2026 business test, and AV-Comparatives included Kaspersky in its Business Security Test for the first half of 2026. Switzerland has taken a different line from Germany and the United States: BACS has issued no warning or ban, has stated that the US prohibition does not change its technical assessment, and reported that no misuse of the software had been notified to it. In practice this matters most if you bid for public-sector contracts, if a parent company or large customer applies German or US procurement rules to your supply chain, or if you operate a US entity — in those cases the origin question will be raised regardless of test results, and it is a decision for the buyer rather than one this page should make.
Yes, for the endpoint half of a typical questionnaire. It lets you answer that endpoint protection is deployed and centrally managed, that an EDR capability with detection, host isolation and execution prevention exists, that vulnerability and patch status for Windows devices is tracked and reported, that disk encryption is enforced and centrally recoverable on Windows and macOS, that removable media and application use are controlled, and that IT staff receive cybersecurity training. It does not answer the other half. There is no multi-factor authentication, no backup and recovery, no long-term log retention or SIEM export, no data loss prevention for email, no network segmentation evidence, no penetration testing, and no certification of your own organisation against ISO 27001 or SOC 2. It also produces no answer to the vendor-origin question described above, which increasingly appears in questionnaires from regulated customers. To close the technical gaps, moving up within the same family to Kaspersky Next XDR Expert or adding the managed MXDR tier is usually cheaper and less disruptive than running a second vendor's console alongside this one; the governance and certification gaps have to be closed by process work, not by software.
The decisive difference is the Endpoint Detection and Response component itself: Foundations does not include it and offers only Root-Cause Analysis as a standalone view, while Optimum adds IoC scanning with custom indicators, execution prevention, network isolation and automated or guided response. The second difference matters just as much in daily work, because patch management and encryption management are absent from Foundations, which means separate tooling for Windows updates and BitLocker recovery keys. Optimum also adds Adaptive Anomaly Control, Data Discovery, blocking of unwanted cloud services, Microsoft 365 protection and built-in cybersecurity training. Both editions share the same endpoint protection engine and the same cloud console, so an upgrade does not require redeployment.
| Feature | Kaspersky Next EDR Foundations | Kaspersky Next EDR Optimum |
|---|---|---|
| Endpoint Detection and Response | ✕ | ✓ |
| Root-Cause Analysis | ✓ | Within EDR |
| Patch Management | ✕ | Windows only |
| Encryption Management | ✕ | ✓ |
| Adaptive Anomaly Control | ✕ | ✓ |
| Cloud Discovery: blocking services | ✕ | Windows only |
| Data Discovery | ✕ | ✓ |
| Microsoft 365 protection | ✕ | ✓ |
| Cybersecurity training for IT staff | ✕ | ✓ |
The most important regional limitation concerns the United States: since the 2024 prohibition by the US Department of Commerce, the product cannot be supplied to or used by US persons, so a group with a US entity cannot standardise on it worldwide. Coverage is also uneven across platforms — patch management, vulnerability assessment and cloud service blocking work on Windows devices only, while the EDR functions run on Windows, Linux and macOS but not on mobile devices, where Android receives anti-malware protection and iOS and iPadOS are limited to anti-theft and control functions. Encryption management does not use its own encryption engine but configures BitLocker on Windows and FileVault on macOS, which means the recovery process follows Microsoft and Apple mechanics rather than Kaspersky's. No managed detection service is part of this tier, so every alert lands with your own staff; buyers who assumed a service was included typically end up adding the MXDR tier afterwards. Ransomware protection for Windows file servers is included, but a deployment dominated by Linux servers, hypervisors or Exchange on-premises will need a different product from the range.
Base denotes an initial licence in Kaspersky's business range, as opposed to a renewal of an existing one. It is a standalone product and does not require another Kaspersky licence to be in place first.
No. The default is the browser-based cloud console, which does not require the administrator to be on the same network as the managed devices, but Kaspersky also documents an on-premises installation for organisations that want the management infrastructure in their own data centre.
Yes. Kaspersky Endpoint Security for Windows provides ransomware protection for file servers running Windows in addition to workstations, and a single security profile in the console covers Windows, macOS, Linux, Android and iOS devices together.
| Operating Systems | Windows 7: Service Pack 1 Home / Professional / Enterprise / Ultimate 32-bit / 64-bit Windows 8.1: 8.1.1 Professional / Enterprise 32-bit / 64-bit Windows 10 2017: RS3 1703 Home / Professional / Education / Enterprise 32-bit / 64-bit Windows 10 2018: RS4 1803 / RS5 1809 Home / Professional / Education / Enterprise 32-bit / 64-bit Windows 10 2019: 19H1 1903 / 19H2 1909 Home / Professional / Education / Enterprise 32-bit / 64-bit Windows 10 2020: 20H1 2004 / 20H2 2009 Home / Professional / Education / Enterprise 32-bit / 64-bit Windows 10 2021: 21H1 / 21H2 Home / Professional / Education / Enterprise 32-bit / 64-bit Windows 11 2021: 21H2 Home / Professional / Education / Enterprise 32-bit / 64-bit Windows Server 2008: Service Pack 2 Standard / Enterprise 64-bit Windows Server 2008 R2: Service Pack 1 Foundation / Standard / Enterprise 64-bit Windows Server 2012: Foundation / Standard / Enterprise / Datacenter 64-bit Windows Server 2012 R2: Foundation / Standard / Enterprise / Datacenter 64-bit Windows Server 2016: Essentials / Standard / Datacenter 32-bit / 64-bit Windows Server 2019: Essentials / Standard / Datacenter 32-bit / 64-bit Windows Server 2020: 20H2 Standard Core / Datacenter Core 64-bit |
| Processor | Workstation 1.4 GHz single core / Server 1.4 GHz single core |
| Memory RAM | Workstation 1 GB / Server 512 MB |
| Storage | 500 MB free disk space |
| Management | Kaspersky Security Center 13.1 or later / Kaspersky Security Center Cloud Console / Managed via Kaspersky Security Center Web Console 13.1 or later or cloud Administration Console |
| Browser | Google Chrome for Windows is required to manage Kaspersky Endpoint Agent using Kaspersky Security Center Web Console |
| Endpoint Protection Platform | Kaspersky Endpoint Agent 3.10 installed as part of Kaspersky Endpoint Security 11.6 for Windows / Kaspersky Security 11.0.1 for Windows Server |