Spotlight

Report:

The Forrester Wave™: Cybersecurity Risk Ratings Platforms, Q2 2026

How does Forrester define the Cybersecurity Risk Ratings Platforms market in 2026?

Cybersecurity risk ratings (CRR) platforms provide security and risk professionals with data and intelligence to assess cybersecurity risk across their third-party supply chains and external attack surfaces. The real value lies not in the overall ratings themselves, which S&R professionals view as a low-value commodity, but in the underlying data and intelligence that surfaces actionable risk findings when used correctly. CRR platform vendors have evolved their roadmaps to focus on gleaning better insights from their data and delivering those insights as actionable findings that concretely reduce customers' risk. The market is evolving to better support cybersecurity third-party risk management (TPRM) and external attack surface management (EASM) programs through improved remediation capabilities, generative AI integration in questionnaire workflows, and robust TPRM platform integrations.

Key Facts for The Forrester Wave™: Cybersecurity Risk Ratings Platforms, Q2 2026 in 2026

How did the Cybersecurity Risk Ratings Platforms market evolve in 2026?

What product features are required to be included in this year's evaluation?

What are the common features of top products in the Cybersecurity Risk Ratings Platforms space?

No common features specified.

Scope Exclusions

Inclusion Criteria

Vendors must, among other requirements:

Offering Strengths — Relative Weighting

Strategy Strength — Relative Weighting

FAQs

Q: What does this research cover?

A: This research covers an evaluation of the seven most significant cybersecurity risk ratings (CRR) platform providers. The evaluation assesses vendors across current offering capabilities (including data acquisition, ratings methodology, third-party risk management, platform collaboration, AI capabilities, and findings remediation), strategy (vision, innovation, roadmap, partner ecosystem, and pricing), and customer feedback. The report identifies Leaders (Bitsight, Panorays), Strong Performers (Black Kite, SecurityScorecard, BlueVoyant, Recorded Future), and Contenders (UpGuard) in the market.

Q: Who should use this research?

A: This research should be used by security and risk (S&R) professionals who are evaluating or purchasing cybersecurity risk ratings platforms to support their third-party risk management (TPRM) and external attack surface management (EASM) programs. It is particularly valuable for enterprise and midmarket organizations that need to assess third-party vendor cybersecurity, manage supply chain risks, and make data-driven security decisions. Buyers should use this evaluation as a starting point and adapt the findings based on their specific priorities, focusing on vendors that enable practical remediation, use genAI effectively in workflows, and provide robust TPRM integrations.

Q: What are the mandatory features of vendors included in this market?

A: All vendors must natively provide the three core use cases for CRR platforms: 1) cybersecurity risk decision prioritization, 2) third-party vendor cybersecurity assessment, and 3) cybersecurity performance peer benchmarking. Additionally, vendors must natively provide at least two of the following extended use cases: compliance evidence and attestation, cyberinsurance policy qualification, cybersecurity risk remediation management, executive reporting and communication, external attack surface management (EASM), or financial risk quantification. The solution must be available as a standalone product with its own SKU and pricing, not solely as a bundled feature.

Q: What are some reasons for not being included in this report?

A:

  • Revenue below $15 million threshold from CRR platform product over the past four quarters
  • Lack of standalone product offering with dedicated SKU and pricing
  • Insufficient coverage of core CRR platform use cases (missing one or more of: risk decision prioritization, third-party vendor assessment, or peer benchmarking)
  • Providing fewer than two extended use cases from the defined list
  • Limited mindshare among Forrester's enterprise clients with insufficient mentions in client inquiries, advisories, and consulting engagements
  • Not frequently mentioned by other vendors as a competitor in the market

Q: What should buyers consider when evaluating products in this market?

A:

  • Vendors that enable practical remediation that reduces risk through granular CRR data embedded into remediation and questionnaire workflows, portals for third-party collaboration, and improved ratings accuracy and dispute resolution
  • Platforms that use genAI in third-party risk questionnaire workflows to assess documentation and questionnaire responses against compliance requirements, identify gaps, and recommend next steps - avoiding AI hype by requiring vendors to prove agentic AI progress and productivity gains
  • Out-of-the-box TPRM integrations that reflect how customers actually use CRR data, with functional integrations for selected platforms to avoid manual API implementation

Q: How has the Cybersecurity Risk Ratings Platforms market evolved in 2026?

A:

  • Shift from ratings as commodity to focus on actionable data and intelligence
  • Evolution toward practical risk reduction through better insights and actionable findings
  • Integration of generative AI in third-party risk questionnaire workflows to assess documentation, identify gaps, and recommend next steps
  • Increased importance of TPRM platform integrations as customers prefer consuming CRR data via existing TPRM platforms
  • Focus on enabling practical remediation through granular data embedded in workflows, vendor collaboration portals, and improved dispute resolution
  • Movement toward using agentic AI to automate third-party risk workflows and execute complex tasks
  • Enhanced support for both TPRM and EASM programs as core use cases
  • Emphasis on ratings accuracy and transparency to reduce time spent debating inaccurate findings

Q: What differentiates Strength of Offering vs. Strength of Strategy?

A: Current Offering evaluates the vendor's existing product capabilities across 15 criteria focusing on technical features, data quality, user experience, and core functionality like ratings methodology, vendor discovery, questionnaire management, AI capabilities, remediation workflows, and EASM capabilities. Strategy evaluates the vendor's future direction and business approach across 6 criteria including vision for market evolution, innovation approach, product roadmap, partner ecosystem depth, pricing flexibility, and availability of supporting services and managed offerings. Current Offering represents what vendors deliver today (vertical axis), while Strategy represents their plans and positioning for the future (horizontal axis).

Reference

View Leaders
View Vendor Movements