Kaspersky US Government Ban: Legal Implications & Analysis

In an era where cybersecurity is critical to national security, the relationship between governments and foreign tech companies has grown increasingly fraught. Few cases illustrate this tension better than the U.S. government's ban on Kaspersky Lab, a Russian cybersecurity firm once widely used by federal agencies and private organizations. What began in 2017 as a directive removing Kaspersky from federal systems escalated into a comprehensive commercial prohibition in 2024, when the Commerce Department banned all Kaspersky software sales and updates in the United States. Rooted in alleged ties between Kaspersky and the Russian government, the ban raised fundamental questions about data espionage, national security, and the limits of executive power. This blog provides a detailed legal analysis of the ban, exploring its origins, legal basis, court challenges, and broader implications for global tech and national security policy.

Table of Contents#

  1. Background of the Kaspersky US Government Ban
  2. Legal Basis for the Ban
  3. Kaspersky's Legal Challenges
  4. Court Decisions and Reasoning
  5. Impact on Kaspersky Lab
  6. Broader Legal and Industry Implications
  7. Conclusion
  8. References

Background of the Kaspersky US Government Ban#

Kaspersky Lab, founded in 1997 by Eugene Kaspersky, rose to prominence as a leading provider of antivirus software, endpoint security, and threat intelligence. By the 2010s, its products were used by millions of consumers and hundreds of U.S. federal agencies, including the Department of Defense (DoD) and the Department of Homeland Security (DHS). However, concerns about its Russian origins began to mount amid growing U.S.-Russia tensions.

In 2017, the U.S. government escalated its scrutiny. Media reports alleged that Kaspersky software had been used to access classified U.S. government data, potentially at the behest of Russian intelligence. One widely reported incident involved an NSA contractor whose home computer running Kaspersky software detected and extracted source code for offensive hacking tools. Another report claimed Israeli intelligence caught Russian government hackers using Kaspersky to search customer systems for U.S. secrets. These claims were never publicly proven, but they fueled fears that the company's products could be weaponized for espionage.

On September 13, 2017, DHS issued Binding Operational Directive 17-01 (BOD 17-01), ordering all federal agencies to remove Kaspersky software from their networks within 90 days. This marked the first formal step in the ban. Subsequent legislative and executive actions expanded the restrictions, effectively barring Kaspersky from federal contracts. In March 2022, the Federal Communications Commission (FCC) added Kaspersky to its "Covered List" of communications equipment and services posing a threat to national security. The restrictions culminated in June 2024, when the Commerce Department's Bureau of Industry and Security (BIS) issued a Final Determination prohibiting Kaspersky from selling or updating its software in the United States entirely, effectively ending its commercial operations in the country.

The U.S. government relied on multiple legal authorities to justify the Kaspersky ban, reflecting a coordinated effort to address perceived national security risks:

1. DHS Binding Operational Directive (BOD 17-01)#

DHS invoked its authority under the Homeland Security Act of 2002 (6 U.S.C. § 143), which empowers the Secretary of Homeland Security to issue directives to protect federal information systems. BOD 17-01 cited "credible reports" that Kaspersky products "pose an unacceptable risk to the national security of the United States" due to potential Russian government influence. The directive required agencies to identify, isolate, and remove Kaspersky software.

2. National Defense Authorization Act (NDAA) for Fiscal Year 2018#

Congress codified the ban in the NDAA 2018 (Pub. L. No. 115-91), signed into law in December 2017. Section 889 of the NDAA prohibited federal agencies from using or procuring "information technology" or "services" from Kaspersky Lab, as well as any entity "owned or controlled" by the company. The law defined "information technology" broadly, including software, hardware, and cloud services, making the ban far-reaching.

3. Executive Order 13873 (May 2019)#

To strengthen enforcement, President Trump issued Executive Order 13873, which expanded the NDAA's restrictions. It directed federal agencies to implement "risk management measures" to avoid Kaspersky products and required contractors to certify they were not using the company's software. The order also authorized the government to block transactions involving Kaspersky if they posed a national security threat. Critically, Executive Order 13873 also granted the Commerce Department authority to review and prohibit information and communications technology and services (ICTS) transactions that pose undue national security risks—an authority that would later be used to impose the 2024 commercial ban.

4. Federal Acquisition Regulation (FAR) Amendments#

The General Services Administration (GSA) amended the FAR in 2018 to align with the NDAA, barring federal contractors from using Kaspersky products in projects funded by government contracts. This ensured the ban extended beyond direct agency use to include third-party vendors.

5. FCC Covered List (March 2022)#

In March 2022, the Federal Communications Commission added Kaspersky to its "Covered List" under the Secure and Trusted Communications Networks Act. The listing identified Kaspersky's information security products and services as posing an "unacceptable risk to the national security" of the United States. This was the first time a cybersecurity company—and the first Russian entity—was added to the list, which previously focused on Chinese telecommunications firms like Huawei and ZTE.

6. Commerce Department ICTS Prohibition (June 2024)#

On June 20, 2024, the Commerce Department's Bureau of Industry and Security (BIS) issued a Final Determination prohibiting Kaspersky Lab, Inc. and its affiliates from directly or indirectly providing antivirus software and cybersecurity products or services in the United States or to U.S. persons. This was the first use of the ICTS authority under Executive Order 13873 and its implementing regulations (15 C.F.R. Part 7).

BIS determined that Kaspersky posed an undue or unacceptable national security risk for several reasons: Kaspersky is subject to Russian government jurisdiction and must comply with requests for information; its software has broad access to and administrative privileges over customer data; it has the capability to install malicious software or withhold critical updates; and third-party integrations create unknown code exposure risks. Simultaneously, BIS added three Kaspersky entities to the Entity List, and the Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned 12 senior Kaspersky executives.

The prohibition took effect in phases: Kaspersky was barred from entering new agreements with U.S. persons effective July 20, 2024, and was prohibited from providing any software updates—including antivirus signature updates—effective September 29, 2024. The penalty for violations is $307,922 per violation or twice the transaction amount.

Kaspersky Lab vehemently denied the allegations and challenged the ban in federal court, arguing it violated U.S. law and constitutional rights. In October 2017, the company filed a lawsuit against DHS in the U.S. District Court for the District of Columbia (Kaspersky Lab USA, Inc. v. U.S. Department of Homeland Security, 316 F. Supp. 3d 160 (D.D.C. 2018)). Its legal arguments focused on three key claims:

1. Violation of Due Process (Fifth Amendment)#

Kaspersky argued that the ban deprived it of property (its ability to do business with the U.S. government) without "due process of law." Specifically, the company claimed it was not given notice of the allegations against it or an opportunity to respond before the ban was imposed. It also argued the government failed to provide "specific, credible evidence" of wrongdoing, making the ban arbitrary and capricious.

2. First Amendment Violation#

Kaspersky asserted that the ban restricted its "speech" by preventing federal agencies from using its software—a product the company argued was a form of "expressive conduct." The First Amendment, it claimed, protects the right to distribute software as a form of communication, and the ban unconstitutionally suppressed this speech.

3. Overbreadth and Vagueness#

The company challenged the NDAA's definition of "owned or controlled," arguing it was vague and could apply to entities with tenuous connections to Kaspersky, harming innocent third parties. It also claimed the ban was overbroad, as it applied to all Kaspersky products, even those with no national security risk. Kaspersky separately challenged the NDAA as an unconstitutional bill of attainder—a legislative punishment directed at a specific entity without a judicial trial.

Court Decisions and Reasoning#

The legal battle unfolded over several years, with courts consistently siding with the government.

District Court Ruling (2018)#

In May 2018, the District Court for the District of Columbia dismissed Kaspersky's claims. Judge Colleen Kollar-Kotelly held that:

  • Due Process: The government was not required to provide Kaspersky with a hearing because the ban was a "policy decision" rooted in national security, an area where courts defer to executive branch expertise. The court noted that "the risk of foreign government access to sensitive data" was a plausible threat, even without public evidence of specific harm.
  • First Amendment: Software is not "speech" under the First Amendment, as it is primarily a functional tool, not an expressive medium. Even if it were, the ban was a "content-neutral regulation" justified by national security interests.
  • Overbreadth/Vagueness: The NDAA's definitions were sufficiently clear, and the ban was narrowly tailored to address national security risks.
  • Bill of Attainder: The court concluded that Kaspersky failed to adequately allege that Congress enacted a bill of attainder, as the NDAA served non-punitive legislative purposes.

Appeals Court Affirmation (2018)#

Kaspersky appealed to the U.S. Court of Appeals for the D.C. Circuit, which upheld the district court's ruling in Kaspersky Lab, Inc. v. DHS, No. 18-5176 (D.C. Cir. 2018). The appeals court emphasized that courts must give "great deference" to the executive branch on matters of national security, especially when Congress has authorized such action (via the NDAA). It rejected Kaspersky's due process claim, stating that "the government need not wait for a breach to act" to prevent potential harm. The D.C. Circuit also affirmed that the NDAA did not constitute a bill of attainder.

Supreme Court Denial (2019)#

The U.S. Supreme Court declined to hear Kaspersky's appeal, leaving the lower court rulings intact. This effectively cemented the federal government ban as legally enforceable. Kaspersky did not mount a significant legal challenge to the 2024 Commerce Department prohibition, instead announcing in July 2024 that it would "gradually wind down" its U.S. operations.

Impact on Kaspersky Lab#

The ban had a profound and escalating impact on Kaspersky's U.S. operations:

  • Loss of Government Contracts: Kaspersky was barred from all federal contracts, costing the company an estimated $100 million annually. State and local governments also followed the federal lead, further shrinking its public-sector market share.
  • Reputational Damage: The ban stigmatized Kaspersky as a "national security risk," leading many private-sector customers (e.g., banks, healthcare providers) to drop its products. By 2020, its U.S. consumer market share had fallen significantly.
  • Strategic Shifts: To rebuild trust, Kaspersky launched transparency initiatives, including opening a "Transparency Center" in Switzerland in 2018, where third-party auditors could review its source code. It also moved some data storage and operations to regions outside Russia, though these steps did not reverse the U.S. ban.
  • FCC Covered List Impact: The 2022 FCC listing triggered "rip and replace" requirements for certain communications providers using Kaspersky products, further reducing its U.S. footprint.
  • Complete Commercial Ban (2024): The Commerce Department's June 2024 prohibition ended all commercial sales and software updates. On September 29, 2024, the ban on providing antivirus signature updates took effect, rendering existing Kaspersky software unable to detect new threats.
  • Closure of U.S. Operations: In July 2024, Kaspersky announced it was laying off its U.S. workforce (fewer than 50 employees) and closing its U.S. division entirely. The company had been selling software in the United States since 2005, and U.S. sales had comprised "just under 10%" of its global revenue of $721 million.
  • UltraAV Controversy: In September 2024, Kaspersky automatically replaced its software on U.S. customers' computers with a product called UltraAV, a partner antivirus solution. The move angered many users and raised concerns in the national security community about providing root-level access to a new, less-established vendor.

The Kaspersky ban set a precedent for government action against foreign tech companies, with far-reaching consequences:

1. Expanded Executive Power in Cybersecurity#

The case reinforced the executive branch's authority to restrict foreign tech companies based on national security concerns, even without concrete evidence of misconduct. The 2024 Commerce Department action demonstrated that the government could escalate from federal procurement bans to complete commercial prohibitions. This has emboldened governments globally to adopt similar measures (e.g., China's restrictions on U.S. tech firms like Google and Facebook).

2. The ICTS Authority as a New Enforcement Tool#

The 2024 Kaspersky prohibition was the first use of the Commerce Department's ICTS authority under Executive Order 13873. This established a blueprint for future actions against foreign technology companies. The ICTS framework allows the government to review and prohibit transactions involving technology from companies "owned by, controlled by, or subject to the jurisdiction or direction of" a foreign adversary. Legal analysts expect the authority to be used against other Russian and Chinese technology providers.

3. Balancing National Security and Due Process#

The courts' deference to national security interests raised questions about due process for foreign companies. Critics argue that the lack of transparency in the Kaspersky case—no public evidence of espionage was ever released—sets a dangerous precedent, allowing governments to target companies based on geopolitical tensions rather than proven harm. The Commerce Department's 2024 determination similarly relied on "theoretical concerns" rather than documented incidents, according to Kaspersky's response.

4. Fragmentation of the Global Tech Market#

The ban contributed to a "splinternet" effect, where countries increasingly wall off their tech markets to foreign firms. This trend raises costs for businesses, limits innovation, and complicates global cybersecurity cooperation. Research by Bitsight found that the U.S. ban had a significant spillover effect, reducing Kaspersky usage even in countries without formal bans, including Germany, the United Kingdom, and Italy.

5. Regulatory Scrutiny of Foreign-Owned Tech#

The Kaspersky case accelerated efforts to regulate foreign tech, including expanded reviews by the Committee on Foreign Investment in the United States (CFIUS) and new laws targeting "high-risk" vendors (e.g., the 2021 Secure Equipment Act, which bans telecom equipment from Chinese firms like Huawei). The FCC's Covered List has continued to expand, and policymakers are increasingly focused on supply chain risk in critical technology sectors.

6. Compliance Challenges for Businesses#

The phased implementation of the 2024 ban—prohibiting new sales in July and software updates in September—created compliance challenges for U.S. businesses. Research found that more than 40% of U.S. organizations observed using Kaspersky products before the June 2024 announcement were still using them three months after the ban took effect. Some government agencies were also observed to still be communicating with Kaspersky update servers. This highlighted the difficulty of enforcing technology bans across complex enterprise environments.

Conclusion#

The Kaspersky US government ban remains a landmark case in the intersection of cybersecurity, national security, and law. What started as a 2017 directive to remove software from federal networks evolved into a complete commercial prohibition by 2024, demonstrating the government's willingness to escalate restrictions when national security concerns persist. While the government successfully justified the ban as a necessary step to protect sensitive data, the legal battle highlighted tensions between executive power, due process, and the global nature of the tech industry. The 2024 use of the ICTS authority established a new precedent for how the Commerce Department can target foreign technology companies, with implications extending well beyond Kaspersky. As governments continue to grapple with cybersecurity threats, the Kaspersky case will serve as a reference for how to balance security concerns with the rights of foreign companies—and whether transparency and evidence should play a larger role in such decisions.

References#

  • Department of Homeland Security. (2017). Binding Operational Directive 17-01: Mitigating the Risk of Kaspersky Lab Products on Federal Information Systems.
  • National Defense Authorization Act for Fiscal Year 2018, Pub. L. No. 115-91, § 889 (2017).
  • Executive Order 13873, 84 Fed. Reg. 21,269 (May 15, 2019).
  • Kaspersky Lab USA, Inc. v. U.S. Department of Homeland Security, 316 F. Supp. 3d 160 (D.D.C. 2018).
  • Kaspersky Lab, Inc. v. DHS, No. 18-5176 (D.C. Cir. 2018).
  • Federal Communications Commission. (2022). Announcement of Additions to the Covered List.
  • U.S. Department of Commerce, Bureau of Industry and Security. (2024). Final Determination: Case No. ICTS-2021-002, Kaspersky Lab, Inc.
  • U.S. Department of Commerce, Bureau of Industry and Security. (2024). Commerce Department Prohibits Russian Kaspersky Software for U.S. Customers [Press Release].
  • Kaspersky Lab. (2018). Kaspersky Transparency Center: Building Trust Through Openness. [Press Release].
  • Zetter, K. (2024). Kaspersky Lab Closing U.S. Division; Laying Off Workers. Zero Day.
  • Bitsight. (2024). The Aftermath of the Kaspersky Ban.
  • Crowell & Moring. (2024). Growing Technology Supply Chain Risks: Kaspersky Lab Software Banned in First Use of ICTS Supply Chain Prohibition.

Legalwin Team

Welcome to Legalwin, where our team of dedicated professionals brings clarity to the complexities of the law.

Legal Disclaimer

No content on this website should be considered legal advice, as legal guidance must be tailored to the unique circumstances of each case. You should not act on any information provided by Legalwin without first consulting a professional attorney who is licensed or authorized to practice in your jurisdiction. Legalwin assumes no responsibility for any individual who relies on the information found on or received through this site and disclaims all liability regarding such information.

Although we strive to keep the information on this site up-to-date, the owners and contributors of this site make no representations, promises, or guarantees about the accuracy, completeness, or adequacy of the information contained on or linked to from this site.