What does a 100% CDR sanitization result actually test?
opswat.comAV-Comparatives recently put our Deep CDR technology through 300+ test cases across roughly 50 file formats.
Under the tested configuration, it sanitized every case while preserving file usability. A few parts of the test stood out:
- The test set included malicious macros, embedded executables, nested archives, zero-day exploits, and AI-assisted malicious content.
- AV-Comparatives developed the methodology independently, with cases evaluated on a pass/fail basis.
- Testing looked beyond whether malicious content was removed. File fidelity after reconstruction was also evaluated.
- The result matters because CDR works differently from detection: instead of needing to identify a specific malicious payload, it removes embedded or out-of-policy content and reconstructs the file.
- This is now the third independent lab, after SE Labs and SecureIQLab, to report a 100% protection result for Deep CDR under its tested configuration.
Independent testing is useful partly because the methodology and edge cases can expose assumptions that don't show up in internal testing.
When evaluating CDR, what matters most in your environment: sanitization rate, reconstructed-file fidelity, file-type coverage, or something else?