US General Services Administration removes Kaspersky Lab from two lists of approved vendors used by government agencies to purchase IT
WASHINGTON (Reuters) - The Trump administration on Tuesday removed Moscow-based Kaspersky Lab from two lists of approved vendors used by government agencies …
Context & Ripple Effects
This delisting is the opening move in what became a seven-year escalation between Washington and Kaspersky Lab. The GSA's removal from two approved vendor lists cut off the easiest purchasing channel before the administration followed up months later with a directive giving agencies 90 days to discontinue existing use, citing concerns about ties to the Russian government.
What makes the July 2017 step worth tracking is how it set the template for everything after it: a statutory ban signed into law that December, a due-process lawsuit from Kaspersky, researchers finding the software still on federal networks nearly two years later, and ultimately a Commerce Department ban on US sales in 2024 paired with Treasury sanctions on twelve executives.
First-order effects
- Government agencies lose the ability to purchase Kaspersky products through standard IT procurement channels, since the company no longer appears on either approved-vendor list.
- Kaspersky Lab's US public-sector revenue channel is severed at the purchasing level, ahead of any formal directive about software already deployed inside agencies.
Second-order effects
- Once the DHS directive lands, agencies must fund removal-and-replacement projects for Kaspersky software already running on their systems, shifting spend toward rival antivirus vendors.
- Kaspersky's response — challenging the government in court on due-process grounds rather than exiting quietly — turns a procurement decision into a legal fight over how the state can blacklist a foreign vendor.
Third-order effects
- If the pattern holds, procurement lists become the first rung of a ladder that ends in statutory bans and personal sanctions, as it did for Kaspersky by 2024 — but the 2019 finding of Kaspersky software still on military and federal networks shows list-based exclusion enforces poorly without active remediation.
- Foreign-headquartered security vendors face a structural problem: their deep system access, the very feature that makes antivirus effective, becomes the national-security argument used against them in buyer governments.
The trend: US treatment of Russian software vendors has escalated from quiet procurement-list removals to statutory bans, sales prohibitions, and executive-level sanctions, with enforcement lagging each step.