What are the key advantages of Kaspersky Hybrid Cloud Security Enterprise CPU Base Plus?
Central console – Managed from Kaspersky Security Center, on-premises or cloud.
CPU licensing – Covers virtual machines on hypervisors you control.
Server hardening – Application control and file integrity monitoring included.
Log inspection – Flags suspicious events in Windows event logs.
Light agents – Shared scanning cuts load on virtualization hosts.
Important note – No EDR; physical servers are not covered.
Kaspersky Security Center – Single console for policies, tasks and reports, on-premises or cloud.
Light agent protection – One shared scanning appliance serves the virtual machines per host.
Application control – Allowlisting for server and desktop operating systems, default deny capable.
File integrity monitoring – Reports unauthorised changes to files and folders you define.
Log inspection – Analyses Windows event logs for suspicious activity patterns.
Important – No EDR component; endpoint detection and response is licensed separately.
Kaspersky Hybrid Cloud Security Enterprise, CPU protects virtual machines running on hypervisors your own team operates, and is managed centrally from Kaspersky Security Center instead of device by device. The licence includes Kaspersky Security for Virtualization Light Agent, the component many administrators still search for under its own name.
Hypervisor-level licensing – Counted per processor in the hosts running protected machines.
Lower resource use – Vendor states up to 40 percent savings in private clouds.
Patch management included – Vulnerability assessment and patching run from the same console.
SIEM connectors – Forwards events to your existing monitoring or SIEM platform.
Default deny hardening – Application control on server systems blocks unapproved binaries.
Virtual desktop support – Persistent and non-persistent desktops on licensed hosts are covered.
The CPU licensing model counts processors in the hosts that run protected virtual machines, so it only pays off once you operate your own hypervisor cluster and change the number of virtual machines regularly. Companies whose workloads sit mainly on physical servers or in a public cloud subscription need a different licensing object.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | ✓ |
| Security questionnaire from large customers | Sometimes | ✓ | ✓ |
| Own virtualization hosts under your control | Sometimes | ✓ | ✓ |
| This product fits | Rarely | ✓ | ✓ |
The reporting obligation under the revised Information Security Act applies to operators of critical infrastructure, not to every company that runs virtual machines, so most commercial buyers of this product are not directly affected. Where it does apply, a cyberattack must be reported to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, which means the affected organisation has to establish quickly what was touched and when. File integrity monitoring and log inspection contribute directly to that first report, because they record changes to defined files and suspicious events in Windows event logs with timestamps, and Kaspersky Security Center exports those records centrally. What the product does not do is reconstruct an attack chain across the estate, retain detection telemetry for later forensic analysis, or file anything with BACS on your behalf; those tasks require an EDR or MDR component and a documented internal reporting process. It also protects only the workloads covered by this licence, so physical servers, notebooks and mobile devices stay outside the evidence you can produce from this console. This description is not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal advisers.
No security product makes an organisation compliant with the NIS 2 Directive, because the directive addresses management responsibility, risk analysis and processes rather than software features. NIS 2 requires categories of measures including risk analysis and information system security policies, incident handling, business continuity and backup management, supply chain security, vulnerability handling and disclosure, and the use of cryptography and multi-factor authentication. This product supports several of those categories concretely: vulnerability assessment and patch management address vulnerability handling, application control and file integrity monitoring support system hardening and change control, and the SIEM connectors feed incident handling by exporting events into an existing monitoring platform. It does not cover backup and business continuity, encryption or key management, multi-factor authentication and identity, supplier risk assessment, or continuous detection and response staffing. Those measures have to be sourced elsewhere and documented separately, and the gap list is usually the part auditors ask about first.
Two official measures are relevant and both are still in force. The German Federal Office for Information Security issued a public warning against Kaspersky antivirus software in March 2022, originally under Section 7 of the BSI Act and now regulated under Section 13 BSIG following the amendment that took effect on 6 December 2025; the authority confirmed in 2026 that it maintains the warning, and its stated reasoning rests on trust in the manufacturer and its ability to act independently rather than on a demonstrated technical defect. In the United States, the Department of Commerce issued a Final Determination on 20 June 2024 that prohibited new agreements with US persons from 20 July 2024 and prohibited antivirus signature updates, codebase updates and operation of the Kaspersky Security Network from 29 September 2024. Kaspersky rejects both assessments as politically motivated, points to its data processing and transparency centre infrastructure in Switzerland, and has formally demanded withdrawal of the German warning while reserving legal steps. In Switzerland the position is different: BACS does not issue product recommendations, has published no warning or ban, and stated that no misuse of Kaspersky software in Switzerland had been reported to it. In practice this affects buyers in public sector tendering, buyers with German group companies, and buyers whose large customers impose country-of-origin requirements on their supply chain; for a privately held Swiss company with no such contractual clauses, the decision is an internal risk decision.
Yes, for a defined block of items, and it is worth knowing exactly which. It answers questions on malware protection for server and virtual workloads, central policy management, allowlisting and default deny on server systems, monitoring of changes to critical files, collection and inspection of security-relevant logs, vulnerability and patch status, and whether security events are forwarded to a monitoring platform, because Kaspersky Security Center produces those reports centrally rather than per machine. It does not answer questions on backup and tested restore, encryption of data at rest, multi-factor authentication and privileged access, continuous detection and response with a stated response time, security awareness training, or the country of origin and jurisdiction of your suppliers. To close the technical gaps, staying inside the same vendor family is usually the cheaper route: detection and response comes from the Kaspersky Next EDR and MDR line, container workloads from Kaspersky Container Security, and log correlation from the Kaspersky SIEM platform, all of which report into the same console family. Backup, encryption and identity are not part of this family at all and have to come from another supplier. The jurisdiction question cannot be solved by any edition of this product, and if a customer questionnaire contains it, that item should be discussed before the purchase rather than after.
The decisive difference is hardening and evidence on server operating systems: application control for server systems, file integrity monitoring and log inspection are Enterprise-only, and they are exactly the functions auditors and questionnaires ask about. Both tiers share the protection engine, the cloud API integration with public cloud platforms, vulnerability assessment and patch management, and the SIEM connectors, so the Standard tier is not a weaker scanner but a smaller feature set. Enterprise additionally includes the next generation IDS/IPS module for VMware NSX, which only matters if you actually run NSX. If you are buying primarily to satisfy a customer audit or an internal hardening baseline, the Enterprise tier is the one that carries those functions; if you only need protection for virtual workloads, the Standard tier covers it.
| Function | Standard | Enterprise |
|---|---|---|
| Cloud API integration with public clouds | ✓ | ✓ |
| Vulnerability assessment and patch management | ✓ | ✓ |
| Application control for desktop systems | ✓ | ✓ |
| Application control for server systems | ✕ | ✓ |
| File integrity monitor | ✕ | ✓ |
| Log inspection | ✕ | ✓ |
| IDS/IPS for VMware NSX | ✕ | ✓ |
| Sale and updates in the United States | Not available | Not available |
The CPU licensing object applies to virtual machines running on hosts whose hypervisor layer you control, so physical servers, workstations and public cloud instances are not covered by it and require the server or desktop licensing object instead; this is the single most common reason for a follow-up purchase. The agentless variant of Kaspersky Security for Virtualization has reached end of life: technical support ended on 31 July 2026, security patches are no longer released, only database updates are available until 1 February 2027, and from 2 February 2027 no support of any kind will be provided, so new deployments run on the light agent architecture, which is included in the licence. Containerized workloads are not part of this product and are covered by the separate Kaspersky Container Security product, and there is no coverage for mobile devices, no encryption management and no EDR component. Regionally, sale, updates and operation of the Kaspersky Security Network are prohibited in the United States and for US persons, which matters for group companies with US entities, and the availability of the bundled premium support agreements depends on the country. Verify the exact scope on the licence certificate before deployment, because the applications you may install are tied to the licensing object you purchased.
Base identifies an initial purchase rather than a renewal, so no existing licence of the same product is required. Plus identifies the licence types that come with Kaspersky's bundled premium technical support agreement instead of standard support, and Kaspersky Enhanced Support certificates can only be added on top of a Plus licence. Availability of these support agreements varies by country, so confirm the applicable option on the licence certificate.
Yes. The light agent variant of Kaspersky Security for Virtualization is included in the licence, and it is the component that places the malware databases on a dedicated security virtual machine so the protected machines on the host do not each carry their own copy.
Yes. Management runs either through Kaspersky Security Center installed on your own administration server or through the Kaspersky Security Center Cloud Console workspace. Both handle policies, activation tasks and reporting for the protected workloads.