Kaspersky has once again successfully passed the SOC 2 Type II audit, reaffirming the reliability of its internal security controls and antivirus database development processes. The assessment demonstrates that the company’s antivirus database development and release processes consistently meet internationally recognized standards, reinforcing trust in the integrity and resilience of Kaspersky technologies.
Developed by the American Institute of Certified Public Accountants (AICPA) and acknowledged worldwide, the SOC 2 framework evaluates an organization’s adherence to the AICPA Trust Service Criteria: security, availability, processing integrity, confidentiality, and privacy. Kaspersky has been regularly undergoing the SOC 2 audit since 2019, reaffirming its long-term commitment to independently verified security practices.
The current audit was carried out by an independent auditor and covered the period from August 2025 to July 2026, applying to the lifecycle of antivirus database development for Windows and Unix operating systems. The auditor reviewed the design and operating effectiveness of controls through a combination of:
- Stakeholder interviews with management and technical teams;
- Operational observations of implemented procedures;
- Documentation analysis covering policies, workflows, and control evidence;
- Re-performance of manual controls to validate consistency and reliability.
The auditors concluded that Kaspersky’s antivirus database development, testing, and release processes continue to meet SOC 2 requirements and remain protected against tampering. A full audit report is available upon request.
“For Kaspersky customers and partners, the successful SOC 2 audit completion is more than procedural milestone, it is independent confirmation that the security controls underpinning our technologies remain consistently effective,” says Yuliya Shlychkova, Vice President of Global Public Affairs at Kaspersky. “The assessment affirms that the technologies our users trust everyday remain protected and operate securely, reliably, giving customers confidence in every update and interaction.”
Regular independent audits remain a core part of Kaspersky’s Global Transparency Initiative, enabling customers and partners to verify the trustworthiness of Kaspersky solutions and make informed conclusions about its security practices. Alongside SOC 2, Kaspersky maintains ISO/IEC 27001 certification and Common Criteria certifications for its enterprise products, reaffirming the company’s commitment to accountability, secure development practices and internationally recognized standards.