Kaspersky Lab Covered Entities
Overview
Federal laws, regulations, and agency requirements restrict certain hardware, software, and services developed or provided by Kaspersky Lab and related entities.
These restrictions arise through multiple federal authorities and may apply differently depending on the activity. Federal procurement requirements restrict the use of certain Kaspersky products and services in connection with covered federal contracts, while separate U.S. Department of Commerce restrictions prohibit certain transactions involving Kaspersky cybersecurity products and services in the United States.
Researchers considering the acquisition or use of Kaspersky products or services for University research activities should ensure that the proposed activity is consistent with applicable federal, sponsor, contractual, procurement, information technology, and University requirements.
The Office of Research Security (ORS) assists faculty, staff, and students in identifying applicable federal, sponsor, contractual, and research security requirements and coordinates with the appropriate University offices when additional review or implementation is required.
CONTACT ORSFederal Restrictions on Kaspersky Products & Services
Federal restrictions involving Kaspersky products and services have been established through several authorities.
Federal Procurement Restrictions
Federal procurement requirements prohibit certain federal agencies and contractors from acquiring, providing, or using covered hardware, software, or services developed or provided by Kaspersky Lab Covered Entities in connection with covered federal contracts.
These requirements may apply to federal contractors and subcontractors depending on the applicable contract clauses and circumstances.
U.S. Department of Commerce Restrictions
In June 2024, the U.S. Department of Commerce's Bureau of Industry and Security (BIS) issued a Final Determination restricting Kaspersky Lab, Inc. and certain affiliates from providing specified antivirus software and cybersecurity products and services in the United States or to U.S. persons.
These restrictions are separate from federal procurement requirements and are not limited to federally funded research.
When Might These Requirements Apply?
Kaspersky-related restrictions may be relevant when:
- Acquiring or using Kaspersky software, hardware, or cybersecurity services.
- Performing work under a federal procurement contract or subcontract.
- Using information technology in the performance of a covered federal contract.
- Procuring products or services for federally contracted research.
- Receiving sponsor or contractual requirements restricting particular products, services, or vendors.
- Evaluating software or cybersecurity products for use in University research activities.
Applicable requirements depend on the product or service, proposed activity, federal authority, sponsor requirements, contract terms, and other circumstances.
Research & Procurement Considerations
Federal restrictions on Kaspersky products and services may overlap with University procurement, information technology, cybersecurity, and other institutional requirements.
Before acquiring or using software, hardware, or cybersecurity services for research, researchers should consider whether:
- The product, service, or provider is subject to applicable federal restrictions.
- A federal contract or subcontract contains restrictions affecting the proposed acquisition or use.
- Sponsor or award terms restrict particular products, services, technologies, or vendors.
- University procurement, information technology, cybersecurity, or other institutional requirements apply.
- The product or service will be used in a research computing environment subject to sponsor, contractual, or other specialized requirements.
- Additional research security, cybersecurity, export control, or information protection requirements apply.
Researchers should contact ORS when they are uncertain whether research-specific federal, sponsor, contractual, or research security requirements apply. University procurement and technology requirements should be addressed through the appropriate University offices.
Relationship to Other Federal Technology Restrictions
Kaspersky-related restrictions are one example of federal requirements that may limit the acquisition or use of particular information technology products, applications, equipment, or services.
Other federal requirements may separately restrict certain:
- Covered applications.
- Telecommunications equipment or services.
- Information and communications technology or services.
- Hardware or software associated with identified entities.
- Products or services prohibited through sponsor or contractual requirements.
The scope and applicability of these restrictions vary. A restriction applicable to one product, entity, federal contract, or award should not be assumed to apply to another.
How ORS Can Help
ORS assists researchers by:
- Reviewing applicable sponsor, award, contract, and subcontract requirements.
- Identifying federal research security, cybersecurity, export control, and other restrictions that may affect a research activity.
- Identifying whether restrictions involving particular technologies, software, services, or vendors apply to federally sponsored or otherwise covered research activities.
- Identifying overlapping sponsor, contractual, research information protection, or cybersecurity requirements, when applicable.
- Coordinating with Procurement, Research Computing & Informatics (RCI), DoIT and/or SBM-IT, the Office of Sponsored Programs, and other appropriate University offices when additional institutional review or implementation is required.
- Providing research-specific guidance throughout the proposal, award, and research lifecycle.
Federal Regulatory References
| Reference | Description |
|---|---|
| National Defense Authorization Act (NDAA) for Fiscal Year 2018, Section 1634 | Establishes statutory restrictions related to hardware, software, and services developed or provided by Kaspersky Lab Covered Entities. |
| Federal Acquisition Regulation (FAR) | Implements federal procurement requirements applicable to covered contracts, including restrictions related to Kaspersky Lab Covered Entities. |
| U.S. Department of Commerce – Bureau of Industry and Security (BIS) | Issued the June 2024 Final Determination prohibiting certain Kaspersky Lab software and cybersecurity products and services in the United States and to U.S. persons. |
Related Guidance
| Reference Guide | Description |
|---|---|
| Covered Applications | Learn about federal restrictions on certain software applications that may apply to federally funded research and University devices. |
| Covered Telecommunications Equipment & Services | Learn about federal restrictions on certain telecommunications and video surveillance equipment and services that may affect federally funded research, purchases, and research infrastructure. |
| Research Cybersecurity Baseline | Review baseline cybersecurity practices that support University research activities. |
| Research Information Protection | Learn how administrative, physical, and technical safeguards are identified and applied to protect research information. |
Need Assistance?
If a federally sponsored research activity, sponsor requirement, contract, subcontract, or award may involve restrictions on Kaspersky products or services or other restricted technologies or vendors, contact the Office of Research Security if you are uncertain what research-specific requirements apply.
ORS will assist in identifying applicable federal, sponsor, contractual, cybersecurity, export control, and research security requirements and coordinate with the appropriate University offices when additional review or implementation is required.