What are the essential features of Kaspersky Vulnerability and Patch Management Add-On?
Central console – Managed from Kaspersky Security Center on-premises
Automated patching – Scans and deploys updates for 150+ applications
Patch testing – Test updates on pilot devices before rollout
Asset inventory – Records all hardware and installed software automatically
Deployment control – Schedules after hours using Wake-on-LAN and multicast
Important note – No malware protection, requires a Kaspersky base product
Vulnerability scanning – Detects missing updates in Microsoft and third-party software.
Patch distribution – Downloads, approves and installs updates across managed Windows devices.
Patch testing – Verifies updates on a test group before a wider rollout.
Hardware and software inventory – Records devices, installed applications and their version status.
Operating system deployment – Creates, stores and rolls out Windows images to workstations.
Important – No anti-malware engine, a Kaspersky endpoint product is required.
Kaspersky Vulnerability and Patch Management, previously sold as Kaspersky Systems Management, adds vulnerability assessment, patch deployment and IT inventory functions to an existing Kaspersky endpoint installation. It is managed centrally from Kaspersky Security Center, the same on-premises console that already runs the underlying Kaspersky Endpoint Security for Business deployment.
Faster patch cycles – Replaces manual per-device update checks with scheduled scans.
Prioritised remediation – Ranks vulnerabilities so actively exploited flaws are fixed first.
Fewer broken rollouts – Approved patch lists keep untested updates off production devices.
Lower branch bandwidth – One local device distributes patches to remote office machines.
Evidence for audits – Reports show which devices received which patch and when.
One console – Avoids a second management server beside endpoint protection.
The add-on is aimed at organisations that already run Kaspersky Security Center and have enough Windows devices that walking to each machine has stopped being realistic. Companies without their own server infrastructure are usually better served by a cloud-managed endpoint product with patching already included, because the console itself has to be hosted and maintained.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | ✓ |
| NIS 2 in the European Union | Rarely | By sector | ✓ |
| Security questionnaire from large customers | Occasionally | ✓ | ✓ |
| Own on-premises patch management server | Often unrealistic | ✓ | ✓ |
| This product fits | Limited | ✓ | ✓ |
No security product makes a company compliant with Swiss law, and this add-on is no exception. Since 1 April 2025 the revised Information Security Act (ISG) obliges operators of critical infrastructure, including energy and water suppliers, transport companies, listed hospitals and cantonal and municipal administrations, to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete the report; organisations outside those sectors and below the defined thresholds are not covered. Where the add-on contributes is preparation and reconstruction: its vulnerability and patch reports document which device was missing which update at which point in time, which is exactly what an incident report needs when the question is how an attacker got in. What it does not do is detect the attack, raise the alarm or generate the report, because it contains no detection, monitoring or incident response function, so the 24-hour clock still depends entirely on your endpoint protection and your internal escalation process. It also does nothing for the organisational side, such as naming a responsible person, defining escalation paths and testing them before an incident. This text is general product information and not legal advice; whether your organisation falls under the reporting obligation should be clarified with qualified legal counsel.
No product creates NIS 2 compliance, because the directive addresses risk management measures, governance and reporting processes rather than individual software purchases. NIS 2 requires essential and important entities to cover measure categories including risk analysis and security policies, incident handling, business continuity, supply chain security, security in the acquisition, development and maintenance of network and information systems including vulnerability handling and disclosure, and procedures to assess whether the measures actually work. This add-on maps cleanly onto one of those categories: vulnerability handling and patching as part of system maintenance, backed by inventory data that establishes which assets exist and which software versions run on them. It does not address incident handling, business continuity and backup, supply chain assessment, cryptography and encryption, access control, multi-factor authentication or staff awareness training, and it produces no evidence about the effectiveness of your overall measures. Management bodies remain responsible for approving and supervising the measures, which is a duty no software can absorb.
Two official measures are relevant and both are still in force. Germany's Federal Office for Information Security (BSI) has warned against the use of Kaspersky virus protection software since 15 March 2022; following the amendment that took effect on 6 December 2025 the warning is issued under Section 13 of the BSI Act, and the BSI confirmed in early 2026 that it maintains it. In the United States, the Department of Commerce's Bureau of Industry and Security issued a Final Determination on 20 June 2024 prohibiting the supply of Kaspersky anti-virus and cybersecurity products to US persons from 20 July 2024, and from 29 September 2024 prohibiting signature and codebase updates, the operation of the Kaspersky Security Network in the US, and resale or integration by third parties; three Kaspersky entities were added to the Entity List at the same time. Kaspersky rejects both assessments, states that it does not engage in activities that threaten national security, argues that the US decision reflects the geopolitical situation rather than a technical evaluation of its products, has offered independent third-party verification of its code, and is pressing the BSI to withdraw the warning. Neither measure is a Swiss decision: the US determination applies to US persons, and the BSI warning is a recommendation under German law rather than a sales ban. In practice this matters most if you bid for public sector contracts, operate or supply into the United States, follow a German parent company's group IT policy, or answer supplier questionnaires that ask about the jurisdiction and sanction status of your security vendors, because in those situations the vendor question will be raised independently of the product's technical merits.
Yes, for the patch and vulnerability block, and only for that block. Questionnaires typically ask whether you maintain an inventory of hardware and software, whether you scan for known vulnerabilities on a defined schedule, how quickly critical patches are applied, and whether you can prove that a specific patch reached a specific device: the Kaspersky Security Center reports answer all four with exportable data instead of a written assertion, and the CVE information attached to detected vulnerabilities lets you reference findings the customer can verify. It answers nothing about malware detection and response times, endpoint detection and response, disk or file encryption, multi-factor authentication, backup and restore testing, mail and phishing protection, mobile device management, security awareness training or your incident notification process, and it says nothing about the documented policies, named responsibilities and tested procedures that auditors usually weight most heavily. If the open items are ones a higher Kaspersky tier already covers, moving the endpoint base up within the same family is normally the cheaper route: Endpoint Security for Business Advanced and Total Security for Business include vulnerability and patch management by default, and in the newer Kaspersky Next line the same functions sit in the EDR Optimum tier and above. Running a second vendor's patch console alongside Kaspersky Security Center means two agents, two policy models and two sets of evidence to reconcile at audit time.
The decisive difference is what you already own: the add-on assumes a Kaspersky endpoint deployment is in place and supplies only the systems management layer, whereas Endpoint Security for Business Advanced contains the same vulnerability and patch management capabilities inside the endpoint product itself. Kaspersky names the add-on route explicitly for Endpoint Security for Business Select, and includes the capability by default in Advanced, in Total Security for Business and in Hybrid Cloud Security Enterprise. Since the Kaspersky Next line was introduced in April 2024, these functions sit in the EDR Optimum tier and above rather than being licensed on their own, so the add-on route is primarily relevant to existing Kaspersky Security Center installations. Neither option is available in the United States.
| Capability | Vulnerability and Patch Management Add-On | Endpoint Security for Business Advanced |
|---|---|---|
| Vulnerability assessment and patching | ✓ | ✓ |
| Anti-malware endpoint protection | Base product required | ✓ |
| Hardware and software inventory | ✓ | ✓ |
| Managed in Kaspersky Security Center | ✓ | ✓ |
| Patch workflow on macOS and Linux | ✕ | ✕ |
| Available in the United States | ✕ | ✕ |
Four limitations decide most purchase questions. First, patching is a Windows function: Kaspersky states the product is designed for Windows-based endpoints, so Macs and Linux machines on the same network are protected by the base product but stay outside the patch workflow, which is the most frequent reason a second tool ends up being bought anyway. Second, the product is not available in the United States following the 2024 Commerce Department determination, which is a practical problem for Swiss and European companies with US subsidiaries or US-based staff, because those devices need a different solution and a separate process. Third, it runs on Kaspersky Security Center as an on-premises administration server, so an organisation with no server infrastructure of its own, or one that has already moved to the cloud-managed Kaspersky Next console, will find the operating model does not match. Fourth, the add-on brings no detection, response, encryption or mobile device management, so it closes the patching gap and leaves every other gap exactly as it was.
Kaspersky states that the product can take on the role of a Windows Update (WSUS) server, and Windows Update synchronisation is available in on-premises installations. In practice that means Microsoft updates and third-party application patches are approved and tracked in one console instead of two, which removes the usual split between the WSUS approval list and whatever handles Adobe, Java and browser updates.
No, Kaspersky Security Center is the application inside this product and is the console through which it is operated. It is installed on a Windows server in your own environment, and the same console also manages the underlying Kaspersky endpoint protection, so no second management server is introduced.