Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
True external discovery starting from minimal seed information finds the unknown assets that matter most; a tool requiring a pre-built asset list is really just monitoring, not discovery.
Look for automated ownership attribution logic and a real accuracy figure/example, since manual attribution doesn't scale for large or acquisitive organizations.
Strong answers state a concrete detection-latency figure, not just 'continuous monitoring' without a number.
Look for context-aware prioritization beyond raw CVSS; a flat severity list on a large discovered surface is not actionable.
Strong answers describe a specific classification methodology and an honest false-positive figure, since incorrectly flagging a legitimate SaaS vendor as shadow IT erodes trust in the tool.
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
Look for automated ticket creation with attribution, not a standalone inventory requiring manual correlation.
These are common, high-impact exposure categories — a vendor with no specific answer likely only does generic port/service scanning.
Look for a described pre-acquisition assessment workflow using only public information, a genuinely distinct and valuable use case from ongoing internal monitoring.
This is a genuine pricing-model tension specific to ASM: if pricing is purely per-asset, a successful discovery phase (finding many previously-unknown assets) directly increases cost — ask how the vendor handles this rather than being surprised by a post-onboarding price jump.
Look for a real customer reference at comparable organizational complexity; a platform tuned for single-brand discovery may struggle with the attribution complexity of a true multi-brand conglomerate.
Modern cloud-native and IPv6 assets are an increasingly common blind spot — a vendor should give a specific, current answer rather than an outdated 'we scan all IPs' claim that predates cloud-native architectures.
Discovery false-positives (flagging something as the customer's asset when it isn't) create wasted investigation time distinct from attribution errors — ask for this specific figure separately.
This cross-referencing (asset inventory plus threat intelligence) is a materially more actionable signal than either capability alone — ask whether this correlation is native or requires manually cross-referencing two separate tools.
Trend-over-time reporting is a distinct capability from a real-time current-state inventory — confirm this exists as a maintained report, not just current-snapshot data.
A continuously synced API feed keeping the customer's own CMDB current is materially more valuable than a one-time export that goes stale immediately after the initial pull.
Discovery-only ASM without exploitability validation produces more noise for the security team — look for real integration with validation tooling (CTEM, BAS) rather than a raw, unvalidated exposure list.