News

OPSWAT Deep CDR Achieves 100% Sanitization in AV-Comparatives Test 2026

News | 17.09.2026

File-borne attacks remain one of the most persistent threats to critical infrastructure, with adversaries increasingly using malicious macros, embedded executables, nested archives and AI-generated payloads to bypass traditional detection. For CISOs and security architects, the question is no longer whether detection catches every threat, but how organizations can neutralize risky content before it reaches endpoints. OPSWAT Deep CDR Technology has now been independently validated as a prevention-first answer to that challenge.

What was announced

On September 9, 2026, OPSWAT announced that AV-Comparatives, an Austrian ISO 9001:2015-certified testing lab, recorded a 100% sanitization rate for Deep CDR Technology across more than 300 test cases. This makes AV-Comparatives the third independent lab to confirm a 100% protection result for Deep CDR, following SE Labs and SecureIQLab. Deep CDR was also the first CDR technology to record a 100% accuracy score in SE Labs testing.

AV-Comparatives evaluated Deep CDR on three dimensions: sanitization effectiveness by attack scenario, coverage across approximately 50 file types, and file fidelity after reconstruction. The test set included AI-assisted malicious content, zero-day exploits, malicious macros, embedded executables, nested archives and other evasive file-borne attacks.

Macros, embedded executables, nested archives, AI-assisted payloads — 300-plus cases, and nothing came through. Our test is pass or fail. There is no partial credit.

Thomas Uhlemann, Cybersecurity Evangelist, AV-Comparatives

Why this matters

Attack campaigns evolve quickly, but the underlying exploitation techniques such as malicious macros, embedded executables, steganography and malformed archives remain attackers' preferred choice. For CIOs, CISOs and procurement leaders responsible for OT, IT and cross-domain environments, detection-based tools alone cannot address unknown or AI-generated file threats. A prevention-first approach that removes risky content regardless of whether the threat is known becomes a strategic control point.

At OPSWAT, we do not grade our own homework. Our commitment to CDR means repeatedly putting Deep CDR Technology in front of leading independent security testing organizations and asking them to stress test it against the newest file-borne attack techniques, including threats created or adapted with AI. Three independent labs have now reported 100% protection results. That is the level of evidence critical infrastructure deserves.

Benny Czarny, Founder and CEO of OPSWAT

Technical details

  • Approach: Prevention-first Content Disarm and Reconstruction that treats every file as untrusted.
  • Processing: Disarms and rebuilds each file in milliseconds, removing embedded and out-of-policy content.
  • Fidelity: Preserves layout, formatting, tables and formulas so files remain fully usable.
  • File coverage: Supports more than 200 file types across email, web, file-transfer and endpoint workflows.
  • Threat coverage: Neutralizes malicious macros, embedded executables, nested archives, steganography, zero-day exploits and AI-assisted payloads.
  • Deployment: Part of the MetaDefender platform, available on-premises, in the cloud or air-gapped.
  • Independent validation: 100% protection results confirmed by AV-Comparatives, SE Labs and SecureIQLab.

Softprom and OPSWAT

Softprom is the official distributor of OPSWAT. Enterprise and critical infrastructure organizations can access Deep CDR Technology and the full MetaDefender platform through Softprom, including licensing, technical consulting and deployment support.

This content was prepared as part of the Softprom DistriFlow project — an automated system for monitoring and adapting vendor news. Original source: original article.