What are the key advantages of Bitdefender GravityZone Full Disk Encryption Add-On?
Central management – encryption policies and keys from the GravityZone console.
Native encryption – manages BitLocker on Windows, FileVault on macOS.
Key recovery – stored recovery keys unlock volumes after forgotten passwords.
Pre-boot authentication – blocks disk access before the operating system starts.
Encryption reporting – per-device status reports usable as audit evidence.
Important note – removable drives and Linux endpoints are not encrypted.
BitLocker management – Encrypts boot and non-boot volumes on Windows fixed disks.
FileVault and diskutil – Encrypts boot and non-boot volumes on macOS endpoints.
Central key recovery – Control Center stores recovery keys for locked volumes.
Pre-boot authentication – Password required before the operating system loads on Windows.
Encryption status reports – Per-endpoint reports showing which volumes are encrypted.
Important – Removable drives, USB sticks and Linux endpoints stay unencrypted.
Full Disk Encryption is an optional GravityZone module that switches on and supervises the encryption already built into Windows and macOS, driven by policy from the same Control Center used for endpoint protection. It attaches to any GravityZone endpoint product, including the tiers Bitdefender renamed in 2022, when GravityZone Ultra became Business Security Enterprise and Advanced Business Security was replaced by Business Security Premium.
No second console – Encryption policy sits beside antimalware policy in Control Center.
No extra agent – The endpoint agent already installed performs the encryption tasks.
Escrowed recovery keys – Helpdesk unlocks a laptop without visiting the user.
Policy-driven rollout – One policy encrypts every fixed drive in scope.
Audit evidence – Exportable reports show disk encryption state per device.
Native AES-256 – Uses operating system encryption instead of proprietary disk drivers.
Suitability follows device type rather than headcount. Any organisation with laptops that leave the building has the same theft and loss exposure, so a five-person architecture office and a 500-person manufacturer both benefit. Regulatory pressure, by contrast, follows sector and size, and that is where the difference appears.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | ✕ | By sector | By sector |
| Security questionnaire from large customers | Often | ✓ | ✓ |
| Central key escrow and encryption proof | Useful | ✓ | ✓ |
| This product fits | ✓ | ✓ | Partial |
The reporting duty in the revised Information Security Act applies to operators of critical infrastructure, not to every company, so most SMEs are affected indirectly through their customers rather than directly by law. Those who are covered must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, which means someone has to be able to say quickly whether the data on a lost or stolen device was readable. Full Disk Encryption supports precisely that step: the encryption status report shows, per device and per volume, whether the disk was encrypted at the time, which is the evidence that turns a possible data breach into a documented non-event. What it does not do is detect the incident, produce the report, or tell you what left the machine over the network, because it only protects data at rest on a powered-off or locked device and has no visibility into running processes or traffic. Detection, alerting and forensic timeline reconstruction come from the endpoint protection and EDR components of the base GravityZone product, not from this module. This text is a practical overview and not legal advice; whether your organisation falls under the reporting duty should be clarified with your own legal advisers.
No software product makes an organisation NIS 2 compliant, because the directive addresses management responsibility, risk analysis and process, not the presence of a particular tool. NIS 2 asks entities in its scope to implement risk management measures across categories including incident handling, business continuity and backup, supply chain security, access control, asset handling, and the use of cryptography and encryption where appropriate. This add-on maps to one of those categories: it delivers cryptography for data at rest on managed workstations and laptops, with documented key custody and a per-device status report that an auditor can read. It contributes nothing to incident handling, backup and restore, supply chain assessment, or identity and access management, and it does not cover data in transit, data in cloud storage, or data on servers whose disks are not managed by the module. Treat it as evidence for the encryption line item and plan the other categories separately.
Yes, for a narrow but frequently asked set of items. It answers questions on whether company laptops use full disk encryption, which algorithm is applied, whether encryption is enforced centrally rather than left to users, who holds the recovery keys, and whether you can produce a device-level report proving the state on a given date. Those are usually the first four or five encryption questions in a supplier assessment, and being able to attach an exported report instead of writing a prose assurance shortens the exchange considerably. It does not answer questions about USB and removable media encryption, encryption of Linux servers, email or file transfer encryption, database or backup encryption, key rotation policy beyond what BitLocker and FileVault provide natively, or FIPS 140 validated cryptography, because Bitdefender states the module is not FIPS compliant. It also says nothing about detection, logging or incident response, which are separate questionnaire blocks. To close the nearest gaps, the practical route is to stay inside the GravityZone family rather than adding a second vendor: Device Control in the base product blocks or restricts USB storage where you cannot encrypt it, and Patch Management, Email Security and the EDR capability in Business Security Premium or Business Security Enterprise cover the vulnerability, email and detection sections. Server-side and removable-media encryption remain genuinely outside this product and need a different tool.
The most consequential limitation is scope: the module encrypts boot and non-boot volumes on fixed disks in desktops and laptops, and Bitdefender states plainly that removable drives are not encrypted, so USB sticks and external disks remain an open channel that has to be handled by Device Control or a separate product. Coverage is Windows and macOS only, because the module drives BitLocker, FileVault and diskutil; Linux endpoints and Linux servers cannot be encrypted through it at all, and on Windows Server BitLocker is not installed by default and must be added by an administrator before the module can do anything. If the fleet already runs a third-party encryption product, those disks must be fully decrypted with the existing tool before GravityZone can take over, which is a real project on a large estate rather than a switch you flip. Two smaller points cause recurring support tickets: the module is not FIPS 140 compliant, which rules it out where a customer contract demands validated cryptography, and pre-boot password entry uses a US keyboard layout, so passwords containing characters that move on a Swiss German, French or Italian layout will fail at the pre-boot prompt even though they are correct.
GravityZone stores the recovery key for every encrypted volume in Control Center, and an administrator retrieves it through the Recovery Manager in the network inventory. The user reads the recovery ID from the pre-boot screen, the administrator looks it up and returns the key, and the machine boots without a reinstall or a desk visit.
Yes. Bitdefender supports BitLocker version 1.2 and later on Windows endpoints both with and without a Trusted Platform Module, which matters for older desktops and for virtual machines that present no TPM. The documented exceptions are Windows 7 and Windows Server 2008 R2, where a TPM of version 1.2 or higher is required.
It can, but with a prerequisite: BitLocker is not part of a default Windows Server installation and has to be added as a feature by an administrator first. Once BitLocker is present, the server is managed by the same policy as workstations. Linux servers cannot be encrypted through this module under any configuration.
Manages BitLocker and FileVault encryption on Windows and macOS endpoints from the GravityZone console. Requires a GravityZone base product.
Bitdefender GravityZone Full Disk Encryption Add-On, Bitdefender, GravityZone, full disk encryption, BitLocker management, FileVault, recovery key escrow, endpoint encryption
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies