What are the core benefits of Trend Micro Smart Protection Complete?
Central console – Apex Central manages endpoint, mail and web layers together.
Endpoint protection – Apex One covers Windows clients, servers and macOS.
Virtual patching – Host intrusion prevention shields unpatched Windows vulnerabilities.
Mail scanning – ScanMail filters malware and spam directly on Exchange servers.
Data protection – Template-based DLP and USB device control on endpoints.
Important note – Vendor ended suite sales; no EDR or patch deployment.
Apex Central console – Central policies and dashboards, with syslog export in CEF format.
Apex One endpoint agent – Machine learning, behaviour monitoring and ransomware protection for Windows and Mac.
Virtual patching, lockdown – Vulnerability Protection and Application Control harden Windows endpoints against exploits.
Mail, web and mobile – ScanMail for Exchange, PortalProtect, InterScan Web Security and Mobile Security.
Integrated DLP – Template-based data loss prevention across endpoints, mail and web.
Important – Vendor ended suite sales; no EDR or patch deployment included.
Trend Micro Smart Protection Complete is a user protection suite that bundles Apex One endpoint security with mail, collaboration, web and mobile protection, all managed centrally through Apex Central, on premises or partly as a service. Trend Micro, whose enterprise business now operates as TrendAI, has ended sales of the suite and moved new licensing to TrendAI Vision One packages.
One console, many layers – Admins see threats per user across endpoint, mail and web.
Time before patch rollouts – Virtual patching shields known vulnerabilities while vendor updates are tested.
Threat sharing between layers – Suspicious files found in one layer are blocked in others.
SIEM-ready event logs – Apex Central forwards logs via syslog in CEF format.
Mixed deployment models – Components run on premises or as a service, per layer.
Mail server scanning – ScanMail filters malware and spam directly on the Exchange server.
The suite was designed for organisations that run their own Windows infrastructure, often with an on-premises Exchange server, and have an administrator who maintains Apex Central. A small office without IT staff usually cannot operate this many separate components. Because Trend Micro no longer sells the suite, it mainly fits companies that already run Apex One and Apex Central and need to keep that environment protected while they plan a migration.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | By sector |
| Security questionnaire from large customers | Common | Common | Common |
| One console for endpoint, mail and web | Rarely needed | ✓ | ✓ |
| This product fits | ✕ | Existing users | Existing users |
Since 1 April 2025, the revised Information Security Act has required operators of critical infrastructure in Switzerland, such as energy suppliers, hospitals and public authorities, to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. Most other companies are not directly covered, but often receive similar expectations through their customers. Smart Protection Complete supports the detection side, because Apex Central collects detections from endpoints, mail and web in one place and can forward them to a SIEM, which helps establish when and where an attack started. The suite contains no EDR, so the root-cause analysis and attack timeline a complete report often needs require additional tooling, and the report itself remains an organisational process. This information does not replace legal advice; have your specific obligations assessed by a qualified specialist.
No security product makes a company compliant with the NIS 2 Directive, because the directive requires risk management measures that are largely organisational. Its measure categories include risk analysis, incident handling, business continuity and backup, supply chain security, vulnerability handling, cyber hygiene and training, cryptography, access control and multi-factor authentication. Smart Protection Complete supports parts of incident handling, vulnerability handling and cyber hygiene through malware protection, virtual patching, application control and central logging, while its DLP and device control support data protection. It provides no backup, no multi-factor authentication and no patch deployment, and for encryption it only manages BitLocker and FileVault. Because NIS 2 expects measures that reflect the state of the art, entities should also check how the announced component lifecycles fit their own planning.
Yes, for the malware protection and system hardening part of a typical supplier questionnaire, but not for the full list. The suite lets you answer questions on centrally managed endpoint anti-malware, mail filtering, web filtering, application control, removable media control, data loss prevention and log forwarding to a SIEM. It does not answer questions on endpoint detection and response, patch deployment and patch status evidence, backup and restore testing, multi-factor authentication, or disk encryption beyond managing BitLocker and FileVault. Questionnaires also increasingly ask whether security products are still sold and supported by the vendor, and several components of this suite already have announced end-of-life dates. Because the suite itself is no longer sold, the practical route to close the EDR gap is a TrendAI Vision One package from the same vendor rather than a third-party EDR on top of Apex One, while backup and MFA need separate solutions in either case.
The decisive difference is protection beyond the endpoint: Smart Protection Complete contains the security layers of Smart Protection for Endpoints and adds email and collaboration security plus a secure web gateway. Mail server scanning with ScanMail, SharePoint protection with PortalProtect and web filtering with InterScan Web Security are therefore only part of the Complete suite. Both suites share Apex Central, the Apex One agent, Vulnerability Protection, Application Control, Endpoint Encryption and Mobile Security. Trend Micro ended sales of both suites on the same dates.
| Component | Smart Protection for Endpoints | Smart Protection Complete |
|---|---|---|
| Apex Central console | ✓ | ✓ |
| Apex One endpoint agent | ✓ | ✓ |
| Vulnerability Protection | ✓ | ✓ |
| Mobile Security | ✓ | ✓ |
| ScanMail for Exchange | ✕ | ✓ |
| PortalProtect for SharePoint | ✕ | ✓ |
| Secure web gateway | ✕ | ✓ |
| EDR included | ✕ | ✕ |
Trend Micro ended sales of Smart Protection Complete to new customers on 1 August 2025 and for renewals on 31 December 2025. The suite has no end-of-life date of its own, but each component follows its own lifecycle: Apex One as a Service and Cloud App Security reach end of life on 31 December 2027, and the InterScan Messaging Security Virtual Appliance 9.1 already reached end of life on 31 March 2026. Endpoint Encryption no longer contains Trend Micro's own full disk and file encryption, which reached end of life on 30 June 2024, so encryption is limited to managing BitLocker and FileVault. Platform coverage is uneven, because Vulnerability Protection and Application Control run only on Windows, while Macs receive the Apex One agent. EDR, patch deployment, backup and multi-factor authentication are not part of the suite and are the most common follow-up purchases.
Trend Micro directs customers either to a newer licence package based on TrendAI Vision One or to renewing only the individual products they still need from the suite. The underlying products remain supported until their own end-of-life dates.
Yes, through Cloud App Security, which covers Office 365 email, SharePoint Online, OneDrive for Business, Box, Dropbox, Google Drive and Gmail with sandbox analysis and data loss prevention. Trend Micro has set the end of life of Cloud App Security to 31 December 2027.
The suite includes ServerProtect, which keeps malware off Windows and Linux file servers. Trend Micro lists December 2028 as the end of life for ServerProtect for Windows and for Linux and names Deep Security or TrendAI Vision One Endpoint Security as the migration path.
Combines Apex One endpoint protection with mail server and web security, managed in Apex Central. Suited to existing Trend Micro environments.
Trend Micro Smart Protection Complete, Trend Micro, TrendAI, Smart Protection Suites, Apex One, Apex Central, endpoint security suite, email security, secure web gateway, data loss prevention
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies