AV-Comparatives has published its Endpoint Prevention and Response (EPR) Comparative Report for 2026.
Across 50 targeted attack scenarios, Bitdefender GravityZone Business Security Enterprise shut down every attack automatically in the first phase, before any of them established a foothold. No lateral movement to chase. No asset breach to contain.
The attacks ended where they started, and Bitdefender GravityZone did it without blocking a single legitimate program or leaving an analyst waiting on a sandbox verdict.
That is the result of the 2026 evaluation, and what follows is the context around it.
The EPR test is not a malware scan. AV-Comparatives builds complete attack chains and runs them end to end, which is a much harder thing to defend against and a much more useful thing to measure.
Each of the 50 scenarios moves through three phases:
Phase 1, Endpoint Compromise and Foothold: Initial access, execution, and persistence. This is the attacker getting in and staying in.
Phase 2, Internal Propagation: Privilege escalation, defense evasion, credential access, discovery, and lateral movement. This is the attacker spreading.
Phase 3, Asset Breach: collection, command and control, exfiltration, and impact. This is the attacker getting what they came for.
If a product fails to stop an attack in one phase, the scenario continues into the next. Every product is scored on two different abilities. Active response, which means the product stopped the attack by itself, and passive response, which means it did not stop the attack, but it raised an alert an administrator could act on. The scenarios map to the MITRE ATT&CK framework and draw on the tradecraft of real groups, including APT28, APT29, Lazarus, Kimsuky, FIN7, Black Basta, and LockBit.
Phase 1 active response is the cleanest measure of prevention in the report, because it shows how often a product stopped an attack before the attacker had anything to work with.
Image: Bitdefender GravityZone stopped all 50 attack scenarios automatically during Phase 1, one of three products in the test to do so.
Bitdefender GravityZone stopped 100% of the 50 scenarios in Phase 1. Eleven other products let somewhere between 4% and 32% of attacks past the foothold stage, where they then had to be caught later in the chain.
That gap is critical.
An attack stopped in Phase 1 costs you nothing: no investigation, no containment, no cleanup, no incident report. An attack stopped in Phase 2 has already escalated privileges or moved laterally, and now somebody on your team owns a ticket. AV-Comparatives prices this directly into its model, applying 0% of the breach impact when an attack is actively stopped and reported in Phase 1, 25% when it is stopped in Phase 2, and 75% when it is stopped in Phase 3.
In simplest terms: you’re either catching an intruder at the door or catching them in the server room. Both are technically successes, but only one of the scenarios means you sleep that night.
Prevention is easy to buy if you are willing to block everything that moves. But what if you need prevention and productivity? The EPR test is built to catch that trade-off, and it does so through two cost categories.
Operational Accuracy: This measures whether the product interferes with legitimate work. AV-Comparatives runs a battery of clean scenarios: opening executables, scripts, and macro-enabled documents; browsing clean sites; and running the administrator tools and scripts real IT teams use every day. Over-blocking is expensive because every false positive requires an investigation and a restore. As the report puts it, “The greater the number of false alerts, the more difficult it becomes to recognize a genuine alert.”
Workflow Delay: This measures whether the product stalls people while it thinks, typically by holding an unknown file for sandbox analysis while the user waits.
GravityZone recorded no operational accuracy costs and no workflow delay costs. Zero in both categories. Six of the fourteen tested products incurred operational accuracy costs, and one of those incurred workflow delay costs on top. This is the number to look at if you only have time for one thing besides the Phase 1 result. Full prevention with zero friction says something about how you achieved prevention, not just that it happened.
To certify, a product needs a 92% or higher average across the combined active and passive response phases, plus a low modeled operational impact. It is a real bar, and several products failed it. Of those that passed, earning the badge shows a product is competent; however, you will find significant performance differences in the underlying numbers. Bitdefender is in the upper-right portion of the quadrant.
Image: The AV-Comparatives Enterprise CyberRisk Quadrant for the 2026 EPR Test. Prevention and response capability runs up the vertical axis; the five-year operational impact score runs right to left, so further right is lower impact.
On combined prevention and response capability, Bitdefender GravityZone scored 99.7%, the second-highest result in the test.
Three products separated themselves at the top of the quadrant, and Bitdefender GravityZone is one of them. Landing a top-tier result on both axes at once is something only three of the fourteen tested products managed, and Bitdefender GravityZone did it while stopping every attack at the point of entry.
Image: The test results illustrate what a miss can mean for the success of a security breach.
One caution on that cost axis, and AV-Comparatives is explicit about it: these are standardized list-price inputs used for comparability, not real contract pricing. Product price is also only one input among several, and the report notes it carries less influence compared with prevention effectiveness, operational accuracy, and workflow efficiency.
AV-Comparatives notes that Bitdefender GravityZone, along with ESET, G Data, VIPRE, WithSecure and Vendor C, produced some silent blocks in Phase 1. A silent block means the attack was stopped, but the product did not generate a corresponding report for it. The attack is dead either way, which is why the active response score stayed at 100%, and the Bitdefender GravityZone Phase 1 passive response came in at 98%.
AV-Comparatives says it used AI-assisted development techniques to build its testing tools and generate scenario variations. A lab that can generate many variants of an attack chain, rather than assembling a fixed set of samples by hand, is testing your defenses against something they have not seen before, on every run.
Detection logic tuned to a specific sample’s artifacts, its hashes, its file names, its exact command lines, degrades quickly under that kind of pressure. Prevention anchored to behavior holds up better, because what an attack does at the end of the chain is far more stable than the tooling it uses at the front of it.
That is precisely what we build for at Bitdefender. The clearest illustration remains WannaCry, where a Bitdefender model trained in 2014 blocked the 2017 outbreak on behavioral grounds, with no knowledge of the specific vulnerability being exploited.
Today, fifty scenarios stopped in Phase 1 show what that looks like when a testing lab deliberately varies the attacks.
Fifty attacks, and Bitdefender GravityZone stopped every one of them automatically at the point of entry, with nobody left waiting on a sandbox. GravityZone didn't block anything it shouldn't have. The result translates most directly into work your security team doesn't have to do.
The combination of complete Phase 1 prevention and zero operational cost puts Bitdefender in a select group, and Bitdefender GravityZone is in it.
Read More
Full AV-Comparatives EPR Comparative Report 2026
See How GravityZone Fits Your Environment
Learn more about Bitdefender GravityZone