> Source: [sk182464](https://support.checkpoint.com/results/sk/sk182464)

# sk182464 - End of Support: Non-compliant versions

| Property | Value |
|----------|-------|
| Solution ID | sk182464 |
| Date Created | 2024-07-04 |
| Last Modified | 2024-10-21 |
| Technical Level | General |

## Solution

**Summary**
-----------

In accordance with the decision made by the Department of Commerce and Bureau of Industry and Security, as published in the US Federal Register (decision details [here](https://www.federalregister.gov/d/2024-13532/p-53)), Check Point will cease support for non-compliant versions of Harmony Endpoint (for instance, E1 which utilizes the Kaspersky Anti-Malware blade for static file analysis) starting from September 29th, 2024. To ensure uninterrupted updates for your Endpoint clients, we urge you to migrate your Endpoint clients to versions that comply with the US DoC regulations (i.e., migrate to E2 which does not use the Kaspersky Anti-Malware blade) by the end of September.  

Background
----------

As per the decision of the Department of Commerce and Bureau of Industry and Security, US vendors are barred from selling Kaspersky products starting from September 29th, 2024. For more details about this decision, see <https://www.federalregister.gov/d/2024-13532/>.  

Some Harmony Endpoint engines (in E1 versions) utilize a portion of the Kaspersky SDK. Over five years ago, Check Point introduced a version of Harmony Endpoint devoid of any Kaspersky components (these Harmony Endpoint packages are referred to as "E2" or "DHS Compliant" versions). Since then, we have been gradually transitioning Harmony Endpoint customers to the E2 version upon request. Today, the E2 version (which many of our customers are already using) is the default installation in new environments. The E1 and E2 versions are now comparable, offering the same features and security level, and the transition from E1 to E2 is seamless and non-disruptive.  

After thoughtful consideration and in alignment with this strategic goal, expedited by the US Government decision, we have decided to officially terminate support for Harmony Endpoint E1 versions on September 29th, 2024.  

<br />

Key Details
-----------

* **End of Support Date:** September 29, 2024
* **Impact:** Post this date, Harmony Endpoint E1 versions will no longer receive updates, including security patches, signatures updates, bug fixes, or technical support.
* **Upgrade Recommendation:** We recommend upgrading to the latest or recommended versions.
* **Licensing Requirements:** Transitioning from the E1 Kaspersky Anti-Malware blade to the E2 compliant Anti-Malware blade does not necessitate new licenses.
* **Relevancy:**

<!-- -->

*
  * Check Point is obligated to terminate support for non-compliant Harmony Endpoint versions on September 29th, 2024, impacting both US and non-US customers, including Technical Requests opened prior to the deadline. We will support customers if they are having difficulties with upgrading to the E2 client.
  * The update is relevant to all devices with Microsoft Windows operating systems, it is not related to Linux or Mac (both Mac and Linux are compliant).
  * This update is also applicable to the Zone Alarm line of products which incorporate a subset of Harmony Endpoint functionality.

Transition
----------

Complete details for transitioning from E1 (non-compliant version) to E2 (compliant version) can be found here: [https://support.checkpoint.com/results/sk/sk178307.](https://support.checkpoint.com/results/sk/sk178307)   
It is important to note that once the upgrade from E1 to E2 is completed, the affected machines will restart automatically ensure all updates are effectively implemented.  

<br />

Related documents
-----------------

1. [sk178307](https://support.checkpoint.com/results/sk/sk178307) - Replacing Kaspersky Anti-Malware Blade in Harmony Endpoint with a Department of Homeland Security (DHS) Compliant or EU recommended Anti-Malware Blade
2. [sk173243](https://support.checkpoint.com/results/sk/sk173243) - How to change to a new Endpoint Security Client DHS-Compliant Anti-Malware engine
3. [sk181635](https://support.checkpoint.com/results/sk/sk181635) - Harmony Endpoint Security Client switches to scheduling upgrade when performing a simple upgrade

Frequently Asked Questions (FAQs)
---------------------------------

Click Here to Show all Answers
******Q1: How to verify whether my client is E1 or E2?******  
> There are several options to verify whether your clients are E1 or E2 based on different deployment methods and included capabilities. For more details, please refer to the section "How to verify whether the client is E1 or E2?" in [sk178307](https://support.checkpoint.com/results/sk/sk178307).
******Q2: Does switching from E1 to E2 requires licensing update?******  
> Replacing the E1 Kaspersky Anti-Malware blade with the E2 compliant Anti-Malware blade does not require new or updated licenses.
******Q3: Should I expect the same performance when using E1 or E2?******  
> Yes, the performance of both engines is the same.
******Q4: Are there any security gaps between the engines?******  
> No. For our recommended versions, both engines provide the same features and the same security level.
******Q5: Is there anything different between a regular upgrade to this change?******  
> Yes, once the upgrade from E1 to E2 is done, the affected machines will restart automatically ensure all updates are effectively implemented.
******Q6: Do all supported Endpoint versions have an E2 version available?******  
> Yes, We recommend upgrading to the latest or recommended versions (E88.00 or above).
******Q7: I have a BASIC or PREVENT license and the version installed is older then E88.30, what should I do?******  
> For customers with Basic or Prevent license, using Endpoint version lower than E88.30, it is recommended to keep the TE blade active.  
> For these versions, TE enables static analysis and reputation services that are needed to improve protection (these are included in the license).  
> Customers should be advised to turn off the policy for Download protection to reduce end-user notifications on license violations.
******Q8: I have decided to upgrade all my machines, are there any measurements I should take?******  
> As in any other software upgrade, the best practice is to gradually upgrade your machines.
******Q9: Does the E1 agent need to be uninstalled completely prior to E2 agent install?******  
> As part of switching from E1 to E2, the E1 engine will be completely removed from the machine. Once it is done, the new E2 engine will be installed. After the installation is completed, the affected machines will restart automatically and ensures all updates are effectively implemented.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
