Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
Look for explicit cloud-native traffic ingestion, not just on-prem TAP/SPAN, since a growing share of traffic never touches a physical network the customer controls.
Strong answers name specific encrypted-traffic-analysis techniques and give a real detection figure, not a vague 'we see through encryption' claim.
Look for a stated retention window for each data type and confirm forensic pivot-to-PCAP capability, which is often a paid add-on or missing entirely.
East-west visibility is the core NDR value proposition distinct from a firewall/IDS — a vendor that can't articulate this specifically may be reselling perimeter detection under an NDR label.
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
Look for real cross-domain correlation with a measured false-positive improvement, not just 'integrates with your SIEM.'
Strong answers describe adaptive baselining and a stated model-update cadence; a static model trained once will drift into noise as the network changes.
Look for a transparent, itemized pricing model and a real example of extending coverage, since NDR licensing is often a major hidden-cost surprise.
Look for honest disclosure of the performance overhead and privacy implications of decryption-based inspection, not just a feature checkbox.
A vendor should give an honest answer about whether smaller/remote sites get materially weaker coverage — this is a common practical gap for organizations with many small offices or remote locations.
Container/Kubernetes east-west visibility is a materially different technical challenge than traditional network monitoring — a vendor should give an explicit answer rather than implying general 'cloud visibility' covers it.
Strong answers give a concrete, customer-validated ramp-up timeline; a powerful but expert-only interface creates a real staffing bottleneck, especially for smaller SOC teams less familiar with deep packet/flow analysis.
Native compliance/forensic-evidence export is a distinct capability from raw detection — ask whether this exists as a built-in report or requires manual data extraction.
An automated or semi-automated escalation path reduces response time for genuinely critical network-based incidents versus relying purely on an analyst noticing and manually initiating escalation.
Look for a real, customer-validated false-positive figure and an honest description of the baseline-learning/tuning period — 'accurate from day one' claims should be scrutinized.
Strong answers give a concrete, customer-validated timeline and are honest about the customer-side effort required, not just vendor-side sensor deployment time.
Standard IT-focused NDR platforms frequently mishandle OT-specific protocols — a vendor should clarify this scope boundary explicitly for a customer with converged IT/OT networks.