Independent assessment validates the effectiveness of controls governing antivirus database development and release processes
Kaspersky has successfully completed its latest SOC 2 Type II audit, providing independent validation of the security controls supporting its antivirus database development and release processes.
The assessment covered the period from August 2025 to July 2026 and examined the lifecycle of antivirus database development for Windows and Unix operating systems. The audit evaluated both the design and operating effectiveness of controls, including processes designed to protect databases from tampering.
Conducted by an independent auditor, the review included interviews with management and technical teams, operational observations, documentation analysis and re-performance of manual controls. The auditors concluded that Kaspersky’s development, testing and release processes continue to meet SOC 2 requirements.
“For Kaspersky customers and partners, the successful SOC 2 audit completion is more than a procedural milestone it is independent confirmation that the security controls underpinning our technologies remain consistently effective.” — Yuliya Shlychkova, Vice President of Global Public Affairs, Kaspersky
For enterprise customers, the significance of the assessment extends beyond compliance. Security software is itself part of the technology supply chain, making the integrity of threat databases, update mechanisms and development processes critical to the overall security posture of organisations.
Kaspersky has undergone SOC 2 audits regularly since 2019. The company says the independent assessments form part of its Global Transparency Initiative, giving customers and partners greater visibility into its security practices.
The SOC 2 framework, developed by the American Institute of Certified Public Accountants, evaluates controls against Trust Service Criteria covering security, availability, processing integrity, confidentiality and privacy.
Kaspersky also maintains ISO/IEC 27001 certification and Common Criteria certifications for its enterprise products. Together, these external assessments provide multiple layers of assurance around secure development and operational controls.
The latest audit reinforces a broader industry trend: as enterprises scrutinise software supply chains more closely, independent verification of how security technologies are developed, tested and released is becoming an increasingly important element of vendor trust.
