Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
IoT and headless devices can't run an agent — look for agentless fingerprinting/profiling coverage specifically, not a product that assumes every device can host an agent.
Real environments have infrastructure age gaps; look for a described fallback enforcement method for legacy gear, not an assumption of uniformly modern network infrastructure.
Look for automated, self-service onboarding with appropriate default restriction — manual guest-network provisioning doesn't scale and often defaults to overly permissive access.
Look for continuous, not just connection-time, posture checking — a device that passes an initial check and then goes non-compliant is a real, common gap.
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
Look for real bidirectional integration (NAC acting on EDR signals, and vice versa), not a standalone NAC product operating with no awareness of other security tool findings.
Multi-vendor network environments are common after M&A or organic growth; look for explicit multi-vendor switch/AP support, not a product tuned narrowly to one network vendor's ecosystem.
Aggressive NAC enforcement can disrupt fragile OT devices; look for a described OT-aware, availability-conscious enforcement mode, not one-size-fits-all policy.
Look for a real queryable audit trail of access decisions, not just current-state device inventory — this matters both for compliance and for investigating how a compromised device got network access.
Look for transparent, predictable scaling economics tied to realistic network infrastructure scope, not just a per-device price that becomes unpredictable at real multi-site scale.
Ask for a real customer example of incident-time isolation speed, not just confirmation that automated quarantine integration exists — actual response latency during a genuine incident is what matters.
Ask for real evidence of PCI assessor acceptance, not just a generic 'PCI-ready' marketing claim.
Trend-over-time reporting is a distinct capability from a real-time device dashboard — confirm this exists as a maintained, exportable report.
NAC logs and policy are sensitive network-topology information — role-based access control over this specific asset is an often-overlooked consideration.
A false-positive quarantine directly blocks a legitimate user from network access — ask for a real, customer-validated false-positive figure and a fast resolution path.
Strong answers give a concrete, customer-validated timeline and are honest about the real disruption risk during the transition from visibility-only to active enforcement.
Cloud-managed NAC introduces a dependency on WAN connectivity to the vendor's cloud for enforcement decisions — ask for a specific answer on what happens to enforcement during a WAN outage, since network access control has an unusually high uptime requirement.