Kaspersky Passed SOC 2 Type II Audit
The assessment confirmed the integrity of antivirus database development systems for Windows and Unix platforms.
Updated on Sept. 21, 2026 in Cybersecurity

Live Poll
Do independent security audits increase your trust in the software products you use?
Kaspersky completed a SOC 2 Type II audit covering the period from August 2025 to July 2026. The independent assessment validated the company's protection against tampering in its antivirus database production.
Why it matters
The audit is part of the Global Transparency Initiative, intended to provide external verification of the company's internal security controls. It functions to demonstrate the operational effectiveness of security measures during database development.
The audit reviewed controls across security, availability, processing integrity, confidentiality, and privacy for Windows and Unix development environments. It specifically verified the effectiveness of security protocols designed to prevent unauthorized database tampering.
The players
Kaspersky
A global cybersecurity firm specializing in antivirus software, endpoint security, and threat intelligence tools.
The details
An independent auditor evaluated the design and operating effectiveness of security controls through a rigorous process of stakeholder interviews, documentation analysis, and operational observation. The auditors re-performed manual controls to confirm that the development pipeline for antivirus databases operates as intended. This process ensures that the software components remain protected from modification throughout the lifecycle from creation to deployment.
Timeline
2019: Kaspersky initiated a recurring program of annual SOC 2 audits.
August 2025 to July 2026: The specific period evaluated by the audit.
September 21, 2026: Official announcement of the audit results.
The Tech Race
This audit follows the trajectory of security vendors seeking to formalize trust through external, standardized compliance frameworks like SOC 2. It represents a shift toward regular, evidence-based reporting as a response to the demand for transparency in software supply chains.
The audit results provide enterprise users with validated assurance regarding the integrity of the antivirus updates they deploy. It does not alter existing product features, but it confirms the consistency of security practices underlying the software stack.
The takeaway
Third-party compliance assessments like SOC 2 remain the primary benchmark for verifying the security posture of software developers. Users should look for subsequent annual audit updates to monitor for sustained compliance in future development cycles.
Further reading
Learn more about the latest developments in Cybersecurity.
Source note: This article includes information reported by TahawulTech.
Live Poll
Do independent security audits increase your trust in the software products you use?






