News Security

Kaspersky Clears SOC 2 Type II Audit for Security Controls

Kaspersky

Independent assessment validates the effectiveness of controls governing antivirus database development and release processes

Kaspersky has successfully completed its latest SOC 2 Type II audit, providing independent validation of the security controls supporting its antivirus database development and release processes.

The assessment covered the period from August 2025 to July 2026 and examined the lifecycle of antivirus database development for Windows and Unix operating systems. The audit evaluated both the design and operating effectiveness of controls, including processes designed to protect databases from tampering.

Conducted by an independent auditor, the review included interviews with management and technical teams, operational observations, documentation analysis and re-performance of manual controls. The auditors concluded that Kaspersky’s development, testing and release processes continue to meet SOC 2 requirements.

“For Kaspersky customers and partners, the successful SOC 2 audit completion is more than a procedural milestone it is independent confirmation that the security controls underpinning our technologies remain consistently effective.” — Yuliya Shlychkova, Vice President of Global Public Affairs, Kaspersky

For enterprise customers, the significance of the assessment extends beyond compliance. Security software is itself part of the technology supply chain, making the integrity of threat databases, update mechanisms and development processes critical to the overall security posture of organisations.

Kaspersky has undergone SOC 2 audits regularly since 2019. The company says the independent assessments form part of its Global Transparency Initiative, giving customers and partners greater visibility into its security practices.

The SOC 2 framework, developed by the American Institute of Certified Public Accountants, evaluates controls against Trust Service Criteria covering security, availability, processing integrity, confidentiality and privacy.

Kaspersky also maintains ISO/IEC 27001 certification and Common Criteria certifications for its enterprise products. Together, these external assessments provide multiple layers of assurance around secure development and operational controls.

The latest audit reinforces a broader industry trend: as enterprises scrutinise software supply chains more closely, independent verification of how security technologies are developed, tested and released is becoming an increasingly important element of vendor trust.

Related posts

VMRay Takes Aim at Conventional Cyber Defense at GISEC 2026

Enterprise IT World MEA

TripleFast Cuts Quoting Time by 80% with Epicor Kinetic Cloud

Enterprise IT World MEA

The Future of Enterprise IT Is Measured in Uninterrupted Work, Not Faster Fixes

Enterprise IT World MEA

Leave a Comment