Endpoint DLP Test Plan

A vendor-neutral plan for evaluating or validating an endpoint DLP deployment — 168 test cases across five sheets, as an Excel workbook you fill in as you go. Use one copy per product you are evaluating, or per environment you are validating.

It names no DLP product. Every row is written as a capability to test rather than a feature to look for, so it applies equally to any endpoint DLP tool.

Download the test plan (.xlsx)Last updated September 17, 2026

What is in it

1. Classification22 rows

Can the tool find the data?

Four use cases: regulatory PII, PHI and card data; intellectual property and source code; financial reporting and material nonpublic information; and bulk exports out of business applications. Covers match counting, confidence levels, exact data match, OCR and nested archives.

2. Policy88 rows

Can it act on what it found?

31 egress channels — GenAI tools, webmail, cloud storage, browsers, USB, printing, AirDrop, RDP and more — scored for Monitor / Warn and separately for Block, because seeing a channel is the easy half. One row per channel per operating system, since a channel that is table stakes on Windows is often advanced on macOS and rare on Linux.

3. Enforcement6 rows

What can it enforce in real time?

Why some classifications can block inline and others can only alert afterwards. This is the sheet that explains how a team can block card numbers going to a GenAI tool and still be unable to block AI-classified data going to the same place.

4. Investigations27 rows

What happens after an alert?

Evidence and context, timeline and lineage, pivoting from a user or a file or a destination, insider-risk behaviour, case workflow, privacy controls and response actions.

5. Usability25 rows

What does it cost to run?

AI-assisted classification, policy authoring and triage, rollout and change control, agent footprint and user-visible latency, and the end-user experience that decides whether people route around the agent.

A Read Me sheet explains how to fill the workbook in and includes a glossary, and a Scoring Summary rolls everything up with formulas — by sheet, by operating system, and by maturity tier — so the totals update as you work.

How the scoring works

Every result cell uses the same four values, picked from a dropdown. Leave a cell blank if you have not tested it yet — blank andFail mean different things, and blanks are excluded from the coverage percentage.

PassWorks as described.
PartialWorks with caveats — record them in the Notes column.
FailDoes not work, or needs a workaround you would not accept.
N/ANot applicable to your environment. Excluded from scoring.

Every row also carries a maturity tier, because not all failures are equal:

Table stakesExpect every serious product to do this. A failure here is disqualifying.
AdvancedWhere mature products separate from adequate ones.
DifferentiatorFew products do this well. A low score is information, not a verdict.

Test data

The plan refers to these pages for the files and endpoints it asks you to use. Everything here is synthetic — never use real customer, employee or patient data to test a DLP tool.

Feedback

This plan is a work in progress and suggestions are welcome — a channel we have missed, a test that does not survive contact with a real product, or a tier you would score differently. Get in touch through thecontact page.