Kaspersky has successfully completed another SOC 2 Type II audit, with an independent assessment confirming the effectiveness of controls supporting its antivirus database development and release processes.
The audit covered the period from August 2025 to July 2026 and examined the lifecycle of antivirus database development for Windows and Unix operating systems. Auditors evaluated the design and operating effectiveness of Kaspersky’s security controls through stakeholder interviews, operational observations, documentation reviews, and re-performance of manual controls.
The SOC 2 framework, developed by the American Institute of Certified Public Accountants (AICPA), evaluates organizations against Trust Service Criteria covering security, availability, processing integrity, confidentiality, and privacy.
According to the audit findings, Kaspersky’s antivirus database development, testing, and release processes continue to meet SOC 2 requirements, including controls designed to protect the databases against tampering.
Kaspersky has undergone SOC 2 audits regularly since 2019 as part of its broader security and transparency efforts. The company said independent assessments provide customers and partners with additional verification of its security practices.
Kaspersky also maintains ISO/IEC 27001 certification and Common Criteria certifications for its enterprise products.


