This guide was written and maintained by Gizmodo’s cybersecurity software team, who independently test antivirus software for malware detection, system impact, bundled features, and value. Our recommendations are editorially independent and affiliate commissions do not influence our rankings. Gizmodo may earn a commission when you buy through links on the site.
Who does the testing
Our antivirus coverage is handled by a cybersecurity software team. Everyone who contributes to an antivirus review has hands-on experience with security software. Before publishing, each review goes through a factual check by a second team member.
Vendors cannot pay to be included in our guides or to improve their position. Rankings are determined by test results and editorial judgment. If a product we cover has a flaw, whether that is weak offline detection, a scan that hammers the CPU, or a renewal price that triples, that finding is written up and reflected in the score.
Our testing environment
In-house performance figures come from a single Windows machine, so that results are comparable across products rather than across hardware. The bench is a Ryzen 7 5800X with 32 GB of DDR4-2666, running Windows 11 Pro, with two M.2 SSDs: a 222 GB drive holding 79 GB free and a 931 GB drive holding 541 GB free. Free disk space affects scan duration, so we record it alongside the timings.
Scan durations are wall-clock, measured from the moment a scan starts to the moment its summary appears, with nothing else running. Peak CPU, memory, and disk throughput are sampled during those runs. Every product is installed on a clean image and given a full first scan before any measured run, because the first sweep after installation catalogues the whole drive and is not representative.
Mac, Android, and iOS clients are tested on their native platforms rather than emulated. We do not assume parity between a vendor’s Windows build and its mobile apps, because vendors frequently ship a smaller feature set outside Windows.
What we test
Malware detection
We run each product against a sample set and record detection separately with the cloud reachable and with the machine offline. The offline figure is the one most reviews skip and the one that matters on a laptop, or on a machine already compromised in a way that interferes with its own network access.
Sample sets are not always uniform, and we say so when they differ. A network-layer product that only inspects what crosses the connection has to be tested against files pulled individually over the wire, which produces a smaller set than a full scanner tested against files already on a drive. Those two numbers are not directly comparable and we do not present them as though they are.
False positives are counted and reported. A product that flags ordinary documents is a product people will eventually switch off.
Independent lab results
We use AV-TEST and AV-Comparatives, and we name the report and the month every time we cite one. The two labs measure different things and we use them for different purposes. AV-TEST scores protection, performance, and usability out of six each, which is useful for ruling products out and useless at the top of the table, because several vendors now score a perfect 18 out of 18 in the same round. AV-Comparatives reports to two decimal places and separates detection from protection from false alarms, which is where the remaining differences are visible.
We also read those tables for repeated rows. Engines get licensed and rebadged constantly, so several brands in a lab table are often the same product in different packaging. A ranking that treats them as independent results is a ranking that misleads.
System impact
We record quick scan and full scan durations, peak CPU, peak memory, and disk throughput during a scan, plus resource use while the machine sits idle.
Our working thresholds are idle CPU below 5%, scan CPU below 40% on a current processor, and a full scan finishing inside an hour. A product that clears all three is acceptable. How far below those ceilings it lands is what separates a suite we recommend for an eight-year-old laptop from one we recommend for a desktop that stays plugged in.
Lab performance scores are reported alongside our own where they exist, including when they disagree with us. They usually measure everyday operations such as copying files and launching applications rather than load during a deliberate scan, so the two can point in opposite directions without either being wrong.
Bundled features
Most antivirus products are sold as suites, and a feature list is not the same as a useful product. We test what is included rather than counting it.
Firewalls are checked for whether the default configuration is sensible and whether the rules are readable. Cloud backup is tested for restore, not just upload, since backup is the only feature in this category that recovers you after ransomware rather than trying to prevent it. Bundled VPNs are checked for data caps, because several are limited tightly enough to be unusable. Password managers are compared against dedicated ones rather than against nothing. Scam and phishing protection is tested against live URLs, and ad blockers against a measured benchmark.
We also record which features are missing from which tier, because vendors frequently advertise a capability that only exists at a price above the one in the headline.
Privacy and telemetry
Antivirus software reads your files, watches your processes, and inspects the URLs you open, because it cannot function otherwise. That makes the vendor’s data handling part of the product rather than a side issue.
We read the privacy policy in full and look for whether browsing data is collected at all, whether anything reaches third parties, how long data is retained, and whether the company publishes a transparency report or submits to external audit. Where a vendor has published technical detail on how detection works without profiling users, we read it and report what it claims. Where a vendor has a relevant enforcement history, we describe it and let readers weigh it.
Value and the renewal price
First-year antivirus pricing is a customer acquisition cost. The renewal is the real price, and it is frequently two or three times higher. We record the first-year rate and the renewal rate for every tier, and we compare products over two years rather than one. A suite that is ten dollars cheaper in year one and fifty dollars dearer in year two is not the cheaper suite. We also note the refund window, whether the vendor bills ahead of the renewal date, and how difficult auto-renewal is to switch off.
Discount percentages advertised by vendors are calculated against the renewal price rather than against anything a customer would otherwise have paid, and we say so rather than repeating the figure.
Support
We send at least one real question per vendor through chat or email, describing an actual problem rather than a generic query, and we log the response time and whether the answer was correct. We note when support opens with a bot and how much work it takes to reach a person.
Why the EICAR file proves nothing
The EICAR test file is a 68-character string that every antivirus vendor has agreed to detect. It has never been malware and it is not a test of anything. Dropping it on a drive confirms that a scanner is switched on and reacting, which is worth doing once after installation. It tells you nothing about how that product handles a real threat, and any review that presents it as a detection test should be read with that in mind.
How we score
Each area is scored out of 10 by the reviewer. The final score is a weighted average. Detection carries the most weight, and no amount of bundled software compensates for a product that misses threats.
- Malware protection: 35%
- System impact and performance: 20%
- Value and two-year cost: 20%
- Bundled features: 15%
- Support: 10%
From score to ranking
One reviewer tests the product across every area and submits scores with supporting notes and raw figures. A second team member checks those scores against the underlying data and flags anything inconsistent and the score is then compared against the products currently ranked. A new entry does not automatically displace an existing one; it has to outscore it.
When a vendor makes a material change, the product returns to the testing queue before the ranking is updated. That includes a restructured plan lineup, a new price or renewal rate, a feature moving between tiers, a change of ownership, a rebrand, or a reported security incident.
We also re-verify pricing on a fixed schedule, independently of testing, because plans in this category change more often than the software does.
What affiliate relationships do not change
We earn commissions on some of the antivirus products we recommend, but it does not determine rankings.
- The top position is determined by test scores alone.
- Scores are submitted before commercial terms are reviewed.
- Products are bought at retail rather than supplied by the vendor.
- Flaws in a product we earn commission from are reported the same way as flaws in any other.
- Vendors cannot ask us to edit or remove a review they dislike.
- Products we earn nothing from, including software built into the operating system, are ranked on the same basis as everything else.