YazamTech yazamtech.com ↗

How to Evaluate a CDR Solution

CDR Evaluation Checklist

Evaluating a CDR solution requires looking beyond a simple "CDR" or "Flattening" label. Some products expose CDR-like functionality without making it clear what actually happens to the file. The process may rely on surface-level inspection, format conversion, or antivirus capabilities rather than dedicated CDR logic. A thorough evaluation should examine how the solution analyzes file content recursively, identifies and remediates risky components according to policy, reconstructs files into a safe, usable state, and handles nested objects, password-protected files, digitally signed files, and different file and email sources. The checklist below organizes the key technical and operational criteria and highlights approaches that may provide only superficial sanitization.

Red Flags When Choosing a CDR Vendor

The following indicators may reveal limited depth, format understanding, remediation control, or reconstruction.

01
CDR Added to a Broader Security Platform
When CDR-like functionality is added to a broader security platform, such as an email gateway, sandbox, secure web gateway, or EDR/XDR solution, it may not provide the depth, format understanding, or remediation control expected from a dedicated CDR product.
02
Lack of Transparency and Buzzword Labeling
Some products expose a simple "CDR" or "Flattening" checkbox without making it clear what actually happens to the file. If the customer cannot see or control the depth of analysis, remediation, and reconstruction, it is difficult to know whether the file was meaningfully sanitized.
03
Reliance on Antivirus Capabilities
A CDR solution that relies on multiple antivirus capabilities rather than dedicated CDR logic may not provide genuine structural sanitization.
04
Surface Level URL Inspection
If the CDR solution only compares against malicious URL repositories at the visible surface of files and email bodies, it may miss URLs embedded at deeper structural levels.
05
Format Conversion Instead of Reconstruction
When the CDR process relies on format conversion instead of understanding how to analyze and synthesize the file format, it may not deliver the depth of protection expected from a dedicated CDR solution. Conversion-based approaches may also degrade file quality and usability.

CDR Evaluation Checklist

01

Deep Analysis, Remediation, and Reconstruction

Start with the core process and determine what happens inside the file.

  • How does the solution analyze file content recursively, including files and objects nested inside other files?
  • How does it identify risky active or structural components inside the file?
  • Can it remediate those components according to policy?
  • Does it reconstruct the file into a safe, usable state?
  • If antivirus capabilities, external utilities, or format conversions are used, what role do they play in the sanitization process?
  • How does the vendor ensure that the process provides deep structural analysis rather than superficial sanitization?
02

Supported File Types and Contained Objects

Verify support for the required formats and for objects contained recursively inside other files.

  • PDF, including password-protected files
  • Microsoft Word, Excel, PowerPoint, and Visio, including password-protected files
  • OASIS OpenDocument Writer, Calc, and Impress
  • Images, including OCR and QR-code filtering
  • Audio and video
  • Plain text, HTML, XML, and JSON
  • Multiple archive formats, including password-protected archives
  • Message formats
  • CAD/CAM files
  • Certificate Revocation Lists (CRL)
  • Medical imaging files (DICOM)
  • Bioinformatics formats
  • Links, macros, and scripts, both as file families and as objects contained recursively inside other files
03

Supported File and Email Sources

Evaluate how the solution receives files and email across the required entry points.

  • Emails from on-premises mail servers, Microsoft 365, and Google Workspace
  • Files downloaded through web browsers, including Chrome, Edge, Firefox, and Opera
  • Files received through chat and collaboration services, including WhatsApp, Telegram, Teams, Zoom, Signal, and WeChat
  • Files received through removable media, including USB devices, iOS and Android mobile devices, and CD/DVD
  • Removable media connected through dedicated kiosks or user workstations
  • Files received through cloud shared locations and network directories
  • Files received from other applications through API
  • Files received from other security solutions through ICAP
  • Files transferred between organizations through Managed File Transfer (MFT)
04

Supported Deployment Topologies

Confirm which deployment topologies the solution supports.

  • An isolated CDR engine for classified or OT networks
  • A cloud CDR engine for SaaS
  • A cloud CDR engine for self-use (private cloud)
  • Hybrid deployment for flexible user locations
  • Parallel CDR engines for load balancing and redundancy
05

Policy and Filtering Options

Examine how policies are defined and how potentially malicious content is handled.

  • Can policies and security rules be defined by user role, user group, departments, and risk levels?
  • Can the solution remove potentially malicious objects from files and emails?
  • Can it test and remediate potentially malicious content in complex files instead of removing every active object?
  • How does it handle macros, scripts, ActiveX, OLE, attachments, and embedded objects?
06

Fidelity, Usability, and Functionality

Evaluate what the filtered file preserves after processing.

  • Does the filtered file preserve its original format, usability, and functionality?
  • Does it preserve file metadata?
  • Does it preserve image quality, sound effects, and video quality?
  • If external utilities or temporary conversions are used, how is fidelity verified after the file is converted back?
07

Password-Protected Files

Check how protected files are decrypted, filtered, and protected again.

  • Can the solution receive passwords from the user or an external system and use them to decrypt protected files for filtering?
  • Can it protect the filtered file again using the original password?
  • Does it support nested password-protected files that use different passwords at different levels?
  • Which protected PDF, Microsoft Office, and archive formats are supported?
08

Digitally Signed Files

Determine how the original signature and the file itself are handled before filtering changes the content.

  • Can the solution validate the digital signature of the original file before active filtering changes its content?
  • Can it store the original digitally signed file and filter a copy?
09

Processing Performance and Licensing

Assess resource use, hardware requirements, licensing, throughput, and latency.

  • Does the solution use available hardware cores efficiently?
  • What hardware is required for the expected traffic volume and file sizes?
  • Does the licensing model depend on the number of hardware cores?
  • What throughput and latency can the solution provide under the required load?
10

Findings, Auditing, and Outputs

Review what the solution records, presents, sends, and reports.

  • Do the logs present the contents of complex files, including intact, blocked, removed, and remediated objects?
  • Do they record the actions applied to each object?
  • Can significant findings be sent to administrators by email?
  • Can significant findings be sent to SIEM/SOC through Syslog?
  • Can the solution produce on-demand security reports?
  • Can it produce automatic periodic security reports?
11

Quarantine

Examine how quarantined content is stored, released, and explained.

  • Are quarantined files, emails, and contained objects stored securely, for example through encryption or in locations inaccessible to unauthorized users?
  • Can an authorized administrator release quarantined files, emails, and contained objects?
  • Is a detailed explanation of the quarantine reason available for every file, email, and contained object?

Effective CDR evaluation requires transparency into how files are analyzed, remediated, and reconstructed. Use this checklist to compare the depth, control, usability, and operational fit provided by each solution, and to identify approaches that may rely on superficial sanitization rather than dedicated CDR logic.