<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Kaspersky Vulnerability and Patch Management Base Plus?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Vulnerability assessment</strong> – Detects and prioritises flaws across more than 150 applications.<br /> <strong>Patch distribution</strong> – Downloads, tests and deploys patches on a defined schedule.<br /> <strong>Hardware and software inventory</strong> – Records every device, application and licence expiry date.<br /> <strong>Operating system deployment</strong> – Creates, stores and clones Windows images for PXE rollout.<br /> <strong>Remote troubleshooting</strong> – Authorised desktop sessions with full logging for audit purposes.<br /> <strong>Important</strong> – No anti-malware engine; endpoint protection must be licensed separately.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Kaspersky Vulnerability and Patch Management Base Plus?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">This is a systems management product for Windows endpoints that adds vulnerability scanning, patch deployment and IT inventory to Kaspersky Security Center, the console where all tasks, policies and reports are configured. Kaspersky lists it as the successor to Kaspersky Systems Management, the name under which many administrators still know it, and Base denotes a new licence rather than a renewal of an existing one.<br /> <br /> <strong>One console</strong> – Patching and protection tasks share the same administration server.<br /> <strong>Exploit-based prioritisation</strong> – Flaws already used by malware are ranked critical first.<br /> <strong>Bandwidth control</strong> – One branch machine distributes patches to its local colleagues.<br /> <strong>Out-of-hours patching</strong> – Wake-on-LAN starts machines so users lose no working time.<br /> <strong>Evidence reporting</strong> – Per-device results show which patches actually installed successfully.<br /> <strong>WSUS replacement</strong> – The administration server can serve Windows updates directly.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Kaspersky Vulnerability and Patch Management Base Plus suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The deciding factor is not headcount but how many different third-party applications you run on Windows and whether anyone has to prove that they were patched. A company with twenty PCs all running the same three Microsoft applications gets little that Windows Update does not already provide. A company with sixty machines running Adobe, Java, browsers and specialist tools has a real inventory problem, and that is where this product starts paying for itself.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Patching beyond Microsoft products</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Partial</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">As component</td>
</tr>
</tbody>
</table>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-server-2025-vs-2022-vs-2019"><strong>Windows Server 2025 vs. 2022 vs. 2019: Is It Worth Upgrading?</strong><br />Compares the current Windows Server versions and their support end dates, which determine how long a server can still receive security patches at all.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Vulnerability and Patch Management Base Plus meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Since 1 April 2025 the revised Information Security Act has obliged operators of critical infrastructure in Switzerland to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete an incomplete first report. The accompanying Cybersecurity Ordinance exempts smaller organisations and those below sector thresholds, so most SMEs are not directly obliged to report, although many supply organisations that are. This product supports that obligation in two concrete ways: the hardware and software inventory tells you within minutes which Windows machines run an affected version, and the patch reports document when each fix was actually installed on each device. What it does not do is detect the attack, because it contains no anti-malware and no EDR component, so it will never be the system that starts your 24-hour clock. It also produces no incident timeline and no report format designed for the authority, so the report itself remains manual work. This information is not legal advice; whether your organisation falls under the reporting obligation should be clarified with a qualified adviser.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Vulnerability and Patch Management Base Plus meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No software makes a company NIS 2 compliant, because the directive addresses governance, processes and management accountability rather than tooling. NIS 2 requires essential and important entities to take risk-management measures across areas that include incident handling, business continuity, supply chain security, and the handling and disclosure of vulnerabilities. This product maps directly onto the last of those: it identifies known vulnerabilities in Windows software, ranks them by whether malware is already exploiting them, and records the remediation afterwards. It contributes indirectly to supply chain security by keeping an inventory of installed software and its licence status. It does not cover incident handling, business continuity and backup, cryptography or access control policies, staff training, or the governance documentation that auditors ask for first, and none of the accountability the directive places on management can be delegated to a tool.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What should you know about official assessments of Kaspersky?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Two authorities have published measures concerning Kaspersky and both remain in force. On 15 March 2022 the German Federal Office for Information Security (BSI) warned against using Kaspersky antivirus software, on the reasoning that a manufacturer based in Russia could be coerced into offensive operations or be compromised without its own knowledge; the warning has not been withdrawn and was carried over unchanged when Germany revised its information security legislation in December 2025. In the United States, the Department of Commerce issued a final determination in June 2024 barring Kaspersky from new business with US persons from 20 July 2024 and from supplying software updates from 29 September 2024, after which Kaspersky stopped US sales and wound down its US operations. Kaspersky rejects the BSI warning as not based on an objective technical analysis, points to its transparency programme and independent source code reviews, and has formally asked for the warning to be withdrawn. Neither measure rests on a published finding of malicious code in the software; both rest on the vendor's jurisdiction and on the deep system privileges that any security software holds. In practice this matters most if you sell to the public sector, operate under a customer supply chain policy, or have to answer country-of-origin questions in a security questionnaire, and it is a procurement question rather than a functional one.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Vulnerability and Patch Management Base Plus help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, for the asset and patching sections, and not at all for the rest. It answers the questions on whether you maintain an inventory of hardware and software, how you identify known vulnerabilities, how you prioritise them, how quickly patches reach endpoints, and whether privileged remote access to workstations is logged, and it produces per-device reports you can attach as evidence rather than describing a process you cannot demonstrate. It does not answer anything about malware protection, detection and response, encryption of laptops and removable media, multi-factor authentication, backup and restore testing, email security, or mobile devices, and it covers only Windows, so any question about your macOS or Linux estate stays unanswered. Country of origin questions are also worth anticipating, given the official assessments described above. To close the patching-adjacent gaps, moving up to Kaspersky Endpoint Security for Business Advanced is usually cheaper and administratively simpler than adding a second vendor, because it includes this same vulnerability and patch management functionality alongside anti-malware and encryption management in one console.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between Vulnerability and Patch Management and Endpoint Security for Business Advanced?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive difference is that this product does not protect anything: it manages and patches, while Endpoint Security for Business Advanced contains the same patch management functionality plus the anti-malware engine and encryption management. Kaspersky sells vulnerability and patch management in four ways: as this standalone targeted solution, as an add-on to Endpoint Security for Business Select, and as an included component of both Endpoint Security for Business Advanced and Total Security for Business. The standalone route makes sense when your endpoint protection is already covered by another vendor or an existing licence and you only need to close the patching gap. If you are buying protection and patching at the same time, compare the Advanced tier before deciding, because buying both separately is rarely the cheaper path.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Capability</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Vulnerability and Patch Management</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Endpoint Security for Business Advanced</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Vulnerability scanning and patching</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Anti-malware protection</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Encryption management</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Operating system deployment</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Endpoint platforms covered</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Windows only</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Windows, macOS, Linux</td>
</tr>
</tbody>
</table>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains what the protection built into Windows does and does not cover, which matters because this product contains no anti-malware of its own.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The product is designed for Windows-based endpoints, so macOS and Linux machines stay outside its scope entirely and mobile devices are not covered at all. It requires a Kaspersky Security Center installation to run, which means the console is a prerequisite rather than an optional extra. Vulnerability detection covers more than 150 popular applications; anything outside that list can still be distributed through custom deployment packages, but it will not be scanned for known vulnerabilities, so verify your specialist software against the supported list before you buy. One regional restriction exists but does not affect this market: Kaspersky has been barred from supplying updates to customers in the United States since 29 September 2024, which is a US-specific measure with no bearing on operation in Switzerland or the European Union. The limitation that most often triggers a follow-up purchase is the absence of anti-malware, because a patching licence alone leaves you without endpoint protection.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-10-support-end-2026-option"><strong>End of support for Windows 10: free extension until October 2026 for some users</strong><br />Sets out how long Windows 10 machines will still receive security updates, which is the point at which no patch management tool can close the gap any further.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Kaspersky Vulnerability and Patch Management Base Plus</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can it replace an existing WSUS server?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. The Kaspersky Security Center administration server can take on the role of a Windows Server Update Services server and distribute Microsoft updates itself. The practical gain is that Microsoft and third-party updates are then approved, scheduled and reported in one place instead of two separate systems.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which applications can it patch besides Microsoft products?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Vulnerability scanning and update distribution cover more than 150 popular applications, including the browser, runtime and document software that attackers target most often. Severity is assessed by Kaspersky's own analysts alongside additional threat sources, and any flaw known to be actively exploited by malware is automatically treated as critical.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can it deploy software that is not on the supported list?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. Applications outside the supported list can be distributed as custom installation packages, scheduled for after hours, and given additional installation parameters where the installer allows it. They will be deployed and inventoried, but not scanned for known vulnerabilities.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-patch,sec-console,compliance-nis2" data-audience="b2b" data-count="3"> </div>