SOC 2 Type II audit confirms effectiveness of Kaspersky’s security controls

Source: Promo Sunday, 26.10.2025. 11:39
Comments
Podeli
(Photo: Pixabay / StartupStockPhotos)
Kaspersky reaffirmed its commitment to high cybersecurity standards with the successful completion of the Service Organization Control for Service Organizations (SOC 2) Type II audit.

The assessment covered the integrity and security of the company’s antivirus database development and deployment processes and confirmed the reliability of existing protection mechanisms against unauthorized changes.

As part of its ongoing efforts to independently verify the integrity of its solutions, Kaspersky has maintained compliance with the SOC 2 standard since 2019.

The SOC 2 framework, developed by the American Institute of Certified Public Accountants (AICPA), assesses security controls against five principles: security, availability, process integrity, confidentiality, and privacy.

The audit, which covered the period from August 2024 to July 2025, analyzed Kaspersky’s workflows related to the development and implementation of antivirus databases for Windows and Unix operating systems, including the supporting infrastructure, procedures, software, data, and employees involved in these processes.


To assess the effectiveness of existing controls, the following tests were conducted:

• in-depth interviews with relevant stakeholders;

• operational observations of implemented controls;

• analysis of relevant documentation;

• re-execution of manual controls and monitoring activities.

(Photo: Shutterstock)
As a result of these checks, the auditors confirmed that Kaspersky’s antivirus database development services and testing and publishing system meet SOC 2 standards and are resistant to unauthorized changes.

The full audit report is available upon request.

“Kaspersky places great importance on external verification of its security practices to ensure compliance with global standards and stakeholder expectations,” said Alexander Liskin, Head of Threat Research at Kaspersky.

“The latest SOC 2 audit highlights the effectiveness of our controls and the integrity of the lifecycle of our antivirus database,” said Liskin.

These audits are a key part of Kaspersky’s Global Transparency Initiative, designed to build trust through accountability.

In addition to the SOC 2 standard, the company has also achieved ISO/IEC 27001 certification for its information security management system, as well as Common Criteria certifications for its leading business products – Kaspersky Endpoint Security and Kaspersky Security Center, a management console for corporate solutions.

Companies:
Kaspersky Kaspersky
Comments
Your comment
Full information is available only to commercial users-subscribers and it is necessary to log in.

Forgot your password? Click here HERE

For free test use, click HERE

Pratite na našem portalu vesti, tendere, investicione projekte, grantove i pravnu regulativu.
Registracija na eKapiji vam omogućava pristup potpunim informacijama i dnevnom biltenu
Naš dnevni ekonomski bilten će stizati na vašu mejl adresu krajem svakog radnog dana. Bilteni su personalizovani prema interesovanjima svakog korisnika zasebno, uz konsultacije sa našim ekspertima.