LUCIDTextjet - Print logo

Kaspersky Embedded Systems Security Compliance Edition Base

Short Description

Open HTML

What are the core benefits of Kaspersky Embedded Systems Security Compliance Edition?
Central management – Policies and reports via Kaspersky Security Center.
Default deny – Blocks every application outside the approved list.
Integrity monitoring – Flags changes to protected files and logs.
Legacy support – Runs on old Windows and low-end hardware.
Device control – Restricts USB sticks and other connected peripherals.
Important note – No EDR, patch management or encryption included.

Long Description

Open HTML

What is included in Kaspersky Embedded Systems Security Compliance Edition?

Real-Time File Protection – Scans files, boot sectors and NTFS streams on access.
Applications Launch Control – Allows only approved executables, libraries and drivers to run.
Device Control – Clocks unauthorised USB flash drives and other peripherals.
File Integrity Monitor – Detects changes to defined files, including changes made offline.
Log Inspection – Reviews Windows event logs for signs of intrusion.
Important – No EDR, patch management, encryption or mobile coverage.

What are the main benefits of Kaspersky Embedded Systems Security Compliance Edition?

Kaspersky Embedded Systems Security Compliance Edition is a standalone protection product for Windows-based embedded devices such as ATMs, POS terminals, ticketing machines and medical equipment. It runs as an agent on each device and is managed centrally through Kaspersky Security Center, while a local application console and a command line remain available for devices with poor connectivity.

Runs on legacy Windows – Protects devices still running unsupported Windows versions.
Low resource footprint – Designed for low-end hardware and weak network links.
Default Deny mode – Can be installed without the anti-malware component.
Ransomware defences – Anti-Cryptor and Remediation Engine roll back malicious changes.
Exploit Prevention – Protects process memory against exploitation of known vulnerabilities.
SIEM export – Sends events to syslog or a SIEM platform.

Best antivirus? Why Windows Defender alone is not enough
Explains which protection layers the built-in Windows defences do not cover and where a dedicated security product is needed.

Which company size is Kaspersky Embedded Systems Security Compliance Edition suitable for?

The deciding factor is not headcount but whether you operate Windows terminals that cannot be patched or replaced on a normal cycle. A retailer with twelve checkout systems has the same technical problem as a bank with a national ATM fleet, but only the larger operator usually needs the central console, the audit trail and the evidence reports.

RequirementSmall businessMedium-sized companyLarge company
Reporting obligation Switzerland By sector By sector ✓
NIS 2 in the European Union Rarely By sector By sector
Security questionnaire from large customers Sometimes ✓ ✓
Central console for terminals across several sites Limited ✓ ✓
This product fits Only for terminals ✓ ✓

Does Kaspersky Embedded Systems Security Compliance Edition meet the requirements of Swiss cybersecurity legislation?

The reporting obligation under the revised Information Security Act applies to operators of critical infrastructure, including energy and drinking water suppliers, transport companies, hospitals, financial service providers and cantonal and communal administrations, not to every company that runs a payment terminal. Those operators must submit an initial report to the Federal Office for Cybersecurity (BACS) within 24 hours of discovering a qualifying cyberattack, with the remaining details following within 14 days. Two components of this edition help you hold that deadline on embedded devices: Log Inspection surfaces suspicious Windows event log patterns, and the File Integrity Monitor records changes to defined files, including changes made while the device was switched off, which is what lets an administrator reconstruct when a terminal was manipulated. Events can be forwarded to a syslog server or SIEM, so the timeline needed for the report does not have to be assembled from each device by hand. What it does not do is decide whether an incident is reportable, cover servers, workstations or mobile devices outside the embedded scope, or provide the root-cause analysis an EDR product would deliver, so the classification decision stays with your team. This is not legal advice, and whether your organisation falls under the reporting obligation must be assessed in each individual case.

Data loss is expensive: How backups help you avoid outages
Covers why protection software alone does not restore operations and which backup measures reduce downtime after an incident.

Does Kaspersky Embedded Systems Security Compliance Edition meet the requirements of European cybersecurity legislation?

No software product creates NIS 2 compliance, because the directive addresses organisational risk management, not a product feature list. NIS 2 requires categories of measures such as risk analysis and security policies, incident handling, business continuity, supply chain security, security in the acquisition and maintenance of systems including vulnerability handling, access control and asset management, cryptography, cyber hygiene and training, and multi-factor authentication. This edition contributes to a narrow but relevant part of that: system hardening through Applications Launch Control, removable media control, detection and logging on devices that no longer receive operating system patches, and event export for incident handling. It contributes nothing to multi-factor authentication, encryption, vulnerability and patch management, backup and continuity, or staff training, and it covers only Windows-based embedded devices, so the rest of your estate needs separate measures. Supply chain security is also a category where the vendor question below is part of the assessment rather than something the product resolves.

What should you know about official assessments of Kaspersky?

On 20 June 2024 the US Department of Commerce, Bureau of Industry and Security, issued a Final Determination prohibiting Kaspersky from providing anti-virus and cybersecurity products or services in the United States or to US persons. New sales stopped on 20 July 2024 and updates to existing US customers ended on 29 September 2024; related entities were added to the Entity List. The measure remains in force, and Kaspersky closed its US operations. Germany's Federal Office for Information Security (BSI) published a warning about Kaspersky anti-virus software on 15 March 2022 and confirmed in 2026 that it maintains it; the BSI has no legal basis for a sales ban, so the product remains legally available in Germany. Italy, the Netherlands, Canada and Australia have restricted use in government or public-sector procurement. Kaspersky states that it is a private company without ties to any government, describes the decisions as politically motivated, and points to its relocation of European data processing to Zurich in 2018 and to its Transparency Centres. Both authorities based their positions on supplier risk and the possibility of state influence, not on published findings that the software fails to detect malware. In practice this matters most if you sell to US persons, bid for public-sector contracts, or answer supply chain questionnaires that ask about vendor jurisdiction; in Switzerland and the European Union the product is sold and updated normally. Whether that residual risk is acceptable is a decision for your organisation.

Norton vs. Kaspersky – Which antivirus program offers the best protection in 2025?
Compares detection performance, system load and feature scope of both vendors for buyers weighing up a change of supplier.

Does Kaspersky Embedded Systems Security Compliance Edition help with security questionnaires from large customers?

Yes, for the questions about endpoint hardening and change monitoring, and not for most of the rest. You can answer positively on malware protection for systems running end-of-life operating systems, application allowlisting through Default Deny, control of removable media, file integrity monitoring on defined paths, review of system logs, centrally enforced policies, and forwarding of security events to a SIEM. You cannot answer the questions on continuous endpoint detection and response, 24/7 monitoring, patch and vulnerability management, disk encryption, multi-factor authentication, backup and restore testing, mobile device management, or security awareness training, and you will have to state that these are covered elsewhere or not at all. One item deserves particular attention here: questionnaires from regulated customers increasingly ask about vendor country of origin, and no additional Kaspersky product closes that item. For the technical gaps, extending within the same family is usually cheaper and less work than mixing vendors, since Kaspersky's endpoint and management products share the same console; the vendor-origin question, by contrast, can only be answered by documenting your risk assessment or by changing supplier.

What is the difference between Kaspersky Embedded Systems Security and the Compliance Edition?

The single decisive difference is system inspection: the File Integrity Monitor, Log Inspection and Registry Access Monitor are unlocked by the Compliance Edition licence and are not available in the standard edition. Both editions ship the same protection engine, so the choice is not about malware detection quality. Kaspersky offers the two as separate licences of the same product, and the compliance components are enabled by the licence rather than installed as a different application. Choose the Compliance Edition when you have to prove after the fact what changed on a terminal, for example for card payment audits or an incident report; choose the standard edition when you only need protection and control.

ComponentStandard editionCompliance Edition
Real-Time File Protection and On-Demand Scan ✓ ✓
Applications Launch Control ✓ ✓
Device Control and Firewall Management ✓ ✓
File Integrity Monitor ✕ ✓
Log Inspection ✕ ✓
Registry Access Monitor ✕ ✓
EDR and patch management ✕ ✕

Which limitations should you know before buying?

The components described here belong to the Windows version; embedded devices running Linux are covered by a separate Kaspersky product and are not protected by this licence. Kaspersky states in its own documentation that update functionality and Kaspersky Security Network may not be available in the software in the United States, which is the practical consequence of the US prohibition and matters for groups with American sites. The product is explicitly not intended for automated process control systems, where Kaspersky points to Kaspersky Industrial CyberSecurity for Nodes instead, so a plant with SCADA nodes needs a different licence for that part of the estate. Central policies, reports and deployment require Kaspersky Security Center, which is a separate on-premises installation to plan and maintain; without it you manage each device through its local console or the command line. The most common follow-up purchases are endpoint protection for normal office PCs and servers, and patch management, because neither is part of this product.

Frequently asked questions about Kaspersky Embedded Systems Security Compliance Edition

Is Kaspersky Security Center mandatory?

No. The application can be operated entirely locally through its own console or the command line, which is the usual approach for a handful of terminals. Kaspersky Security Center becomes necessary as soon as you want one policy set, one status view and one report across many devices.

Does it work on devices with poor or no internet connectivity?

Yes, that is one of its design goals. The application can be installed in a Default Deny configuration without the anti-malware component, which removes the need for regular signature downloads and suits terminals on slow or intermittent links.

Does a base licence require an existing licence?

No. Kaspersky distinguishes base licences from renewals, and a base licence is a new licence that does not require an existing one of the same product. A renewal, by contrast, is tied to a licence you already hold.

Can it replace endpoint protection on normal office PCs?

Not sensibly. It is built for fixed-function devices with a narrow application set, and it has no web or mail protection and no EDR. Office workstations and servers belong on Kaspersky's endpoint products, which is also why many buyers run both.

 

System requirements

Operating Systems Windows XP Embedded SP3 POS Ready 32-bit
Windows 7 Embedded POS Ready Standard 32-bit / 64-bit
Windows 7 Embedded SP1 Standard 32-bit / 64-bit
Windows 8.0 Embedded Standard 32-bit / 64-bit
Windows 8.1 Embedded Industry / Pro 32-bit / 64-bit
Windows 10 version 1507 IoT Enterprise 32-bit / 64-bit
Windows 10 version 1607 IoT Enterprise 32-bit / 64-bit
Windows 10 version 1803 IoT Enterprise 32-bit / 64-bit
Windows 10 version 1809 IoT Enterprise 32-bit / 64-bit
Windows 10 version 1909 IoT Enterprise 32-bit / 64-bit
Windows 10 version 21H2 IoT Enterprise 32-bit / 64-bit
Windows 10 version 22H2 IoT Enterprise 32-bit / 64-bit
Windows 11 version 21H2 IoT Enterprise 64-bit
Windows 11 version 22H2 IoT Enterprise 64-bit
Windows 11 version 23H2 IoT Enterprise 64-bit
Windows 11 version 24H2 IoT Enterprise 64-bit
Processor Minimum 1.4 GHz single-core CPU Pentium III for 32-bit systems / Pentium IV for 64-bit systems or higher
Memory RAM Windows XP Embedded: 256 MB to install Applications Launch Control component only / 512 MB to install all application components / 2 GB recommended / Windows 10 and 11 IoT: 1 GB minimum / 2 GB recommended
Storage 50 MB to install Applications Launch Control component only / 2 GB to install all application components / 4 GB recommended for full installation and logs
Additional Requirements SHA-2 support in Windows required for correct operation / Filter Manager component required on embedded Windows operating systems / Windows Installer 3.1 required on Windows XP family devices

Meta Description

Protects Windows-based ATMs, POS terminals and kiosks, and adds file integrity monitoring and log inspection. Windows-only, no EDR included.

Keywords

Kaspersky Embedded Systems Security Compliance Edition, Kaspersky, Kaspersky Embedded Systems Security, KESS, embedded systems protection, ATM security, POS security, application launch control, file integrity monitoring, log inspection

  

   

COMPANY NAME | First Name, Last name | Address | Phone 0000 - 00 00 00 | Email info@kundendomain.com

By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about 
cookies

I agree