Kaspersky Lab Covered Entities

Overview 

Federal laws, regulations, and agency requirements restrict certain hardware, software, and services developed or provided by Kaspersky Lab and related entities.

These restrictions arise through multiple federal authorities and may apply differently depending on the activity. Federal procurement requirements restrict the use of certain Kaspersky products and services in connection with covered federal contracts, while separate U.S. Department of Commerce restrictions prohibit certain transactions involving Kaspersky cybersecurity products and services in the United States.

Researchers should not acquire or use Kaspersky products or services for University research activities without first confirming that the proposed activity is permitted and consistent with applicable University requirements.

The Office of Research Security (ORS) assists faculty, staff, and students in identifying applicable federal, sponsor, contractual, and research security requirements and coordinates with the appropriate University offices to support compliance.

CONTACT ORS

Federal Restrictions on Kaspersky Products & Services

Federal restrictions involving Kaspersky products and services have been established through several authorities.

Federal Procurement Restrictions

Federal procurement requirements prohibit certain federal agencies and contractors from acquiring, providing, or using covered hardware, software, or services developed or provided by Kaspersky Lab Covered Entities in connection with covered federal contracts.

These requirements may apply to federal contractors and subcontractors depending on the applicable contract clauses and circumstances.

U.S. Department of Commerce Restrictions

In June 2024, the U.S. Department of Commerce's Bureau of Industry and Security (BIS) issued a Final Determination restricting Kaspersky Lab, Inc. and certain affiliates from providing specified antivirus software and cybersecurity products and services in the United States or to U.S. persons.

These restrictions are separate from federal procurement requirements and are not limited to federally funded research.


When Might These Requirements Apply?

Kaspersky-related restrictions may be relevant when:

  • Acquiring or using Kaspersky software, hardware, or cybersecurity services.
  • Performing work under a federal procurement contract or subcontract.
  • Using information technology in the performance of a covered federal contract.
  • Procuring products or services for federally contracted research.
  • Receiving sponsor or contractual requirements restricting particular products, services, or vendors.
  • Evaluating software or cybersecurity products for use in University research activities.

Applicable requirements depend on the product or service, proposed activity, federal authority, sponsor requirements, contract terms, and other circumstances.


Research & Procurement Considerations

Before acquiring or using software, hardware, or cybersecurity services for research, researchers should consider whether:

  • The product or service is subject to federal restrictions.
  • A federal contract or subcontract contains applicable procurement restrictions.
  • Sponsor terms and conditions prohibit particular products or vendors.
  • University information security or procurement requirements apply.
  • The product will be installed or used within a research computing environment.
  • Additional cybersecurity, export control, or research security requirements apply.

Researchers should consult ORS when they are uncertain whether federal or sponsor restrictions apply.


Relationship to Other Federal Technology Restrictions

Kaspersky-related restrictions are one example of federal requirements that may limit the acquisition or use of particular information technology products, applications, equipment, or services.

Other federal requirements may separately restrict certain:

  • Covered applications.
  • Telecommunications equipment or services.
  • Information and communications technology or services.
  • Hardware or software associated with identified entities.
  • Products or services prohibited through sponsor or contractual requirements.

The scope and applicability of these restrictions vary. A restriction applicable to one product, entity, federal contract, or award should not be assumed to apply to another.


How ORS Can Help

ORS assists researchers by:

  • Reviewing sponsor, award, and contractual requirements.
  • Identifying federal research security and cybersecurity restrictions that may apply to a research activity.
  • Determining when additional review of proposed technology, software, or services is required.
  • Coordinating with Procurement, the Information Security Office, Research Computing & Informatics (RCI), the Office of Sponsored Programs, and other University offices, as appropriate.
  • Providing guidance regarding research security, cybersecurity, and sponsor requirements.

Federal Regulatory References

Reference Description
National Defense Authorization Act (NDAA) for Fiscal Year 2018, Section 1634 Establishes statutory restrictions related to hardware, software, and services developed or provided by Kaspersky Lab Covered Entities.
Federal Acquisition Regulation (FAR) Implements federal procurement requirements applicable to covered contracts, including restrictions related to Kaspersky Lab Covered Entities.
U.S. Department of Commerce – Bureau of Industry and Security (BIS) Issued the June 2024 Final Determination prohibiting certain Kaspersky Lab software and cybersecurity products and services in the United States and to U.S. persons.

Related Guidance

Reference Guide Description
Covered Applications Learn about federal restrictions on certain software applications that may apply to federally funded research and University devices.
Government Information Learn about government information that may be encountered in research and the safeguarding, cybersecurity, and contractual requirements that may apply.
Research Cybersecurity Baseline Review baseline cybersecurity practices that support University research activities.
Research Information Protection Learn how administrative, physical, and technical safeguards are identified and applied to protect research information.

Need Assistance?

If you are considering acquiring or using Kaspersky products or services for a University research activity, or if a sponsor, contract, or award includes restrictions involving particular technology products or vendors, contact the Office of Research Security before proceeding.

ORS will assist in identifying applicable federal, sponsor, contractual, cybersecurity, and research security requirements and coordinate with the appropriate University offices, as needed.

CONTACT ORS