The Forrester Wave™: Cybersecurity Risk Ratings Platforms, Q2 2026
Cybersecurity risk ratings (CRR) platforms provide security and risk professionals with data and intelligence to assess cybersecurity risk across their third-party supply chains and external attack surfaces. The real value lies not in the overall ratings themselves, which S&R professionals view as a low-value commodity, but in the underlying data and intelligence that surfaces actionable risk findings when used correctly. CRR platform vendors have evolved their roadmaps to focus on gleaning better insights from their data and delivering those insights as actionable findings that concretely reduce customers' risk. The market is evolving to better support cybersecurity third-party risk management (TPRM) and external attack surface management (EASM) programs through improved remediation capabilities, generative AI integration in questionnaire workflows, and robust TPRM platform integrations.
No common features specified.
Vendors must, among other requirements:
A: This research covers an evaluation of the seven most significant cybersecurity risk ratings (CRR) platform providers. The evaluation assesses vendors across current offering capabilities (including data acquisition, ratings methodology, third-party risk management, platform collaboration, AI capabilities, and findings remediation), strategy (vision, innovation, roadmap, partner ecosystem, and pricing), and customer feedback. The report identifies Leaders (Bitsight, Panorays), Strong Performers (Black Kite, SecurityScorecard, BlueVoyant, Recorded Future), and Contenders (UpGuard) in the market.
A: This research should be used by security and risk (S&R) professionals who are evaluating or purchasing cybersecurity risk ratings platforms to support their third-party risk management (TPRM) and external attack surface management (EASM) programs. It is particularly valuable for enterprise and midmarket organizations that need to assess third-party vendor cybersecurity, manage supply chain risks, and make data-driven security decisions. Buyers should use this evaluation as a starting point and adapt the findings based on their specific priorities, focusing on vendors that enable practical remediation, use genAI effectively in workflows, and provide robust TPRM integrations.
A: All vendors must natively provide the three core use cases for CRR platforms: 1) cybersecurity risk decision prioritization, 2) third-party vendor cybersecurity assessment, and 3) cybersecurity performance peer benchmarking. Additionally, vendors must natively provide at least two of the following extended use cases: compliance evidence and attestation, cyberinsurance policy qualification, cybersecurity risk remediation management, executive reporting and communication, external attack surface management (EASM), or financial risk quantification. The solution must be available as a standalone product with its own SKU and pricing, not solely as a bundled feature.
A:
A:
A:
A: Current Offering evaluates the vendor's existing product capabilities across 15 criteria focusing on technical features, data quality, user experience, and core functionality like ratings methodology, vendor discovery, questionnaire management, AI capabilities, remediation workflows, and EASM capabilities. Strategy evaluates the vendor's future direction and business approach across 6 criteria including vision for market evolution, innovation approach, product roadmap, partner ecosystem depth, pricing flexibility, and availability of supporting services and managed offerings. Current Offering represents what vendors deliver today (vertical axis), while Strategy represents their plans and positioning for the future (horizontal axis).