The 2026 Cybersecurity
Tool Landscape Report
147 tools across 25 categories. Pricing, deployment, standards, and reported pros and considerations, side by side. As a downloadable spreadsheet (CSV).
No spam. Unsubscribe any time. Or scroll down and browse the listings free.
Inside the report
- ✓ Downloadable spreadsheet (CSV) you can sort and filter
- ✓ 147 tools listed alphabetically per category
- ✓ Public pricing per tool (free tiers, per-seat, enterprise)
- ✓ Reported pros and considerations from practitioner discussions
- ✓ Deployment model, standards, and certifications
147
Tools listed
25
Categories covered
0
Scoring weights
0
Hidden placements
What's inside
Alphabetical category listings
Every tool in every category, in alphabetical order. No editorial scoring, no “Top 5”. Just the listings, side by side.
Aggregated public pricing
Free tiers, per-seat costs, and enterprise ranges pulled from official vendor pages and what practitioners report paying. Verify with the vendor before any purchase.
Reported pros and considerations
What real practitioners say on Reddit, Hacker News, Stack Overflow, and verified review sites. Not vendor marketing. We report; we don't verdict.
AI Agent Security
See all 9 tools →Tools that secure AI agents and LLM applications: the guardrails, gateways and controls that sit between a model and the actions it can take. They intercept tool and MCP calls, file access and shell c…
| Tool | Best fit for | Pricing model |
|---|---|---|
| HiddenLayer | Large enterprises and government buyers that want agent runtime enforcement, red teaming and model scanning from one platform with self-hosted and air-gapped options. | Subscription (annual contract via AWS Marketplace; private offers) |
| HOL GuardOSS | Developers and teams using AI coding agents who want local pre-execution controls on risky actions without sending data to a cloud service. | Open source (Apache-2.0) with optional paid cloud subscription |
| Lakera | Enterprises that want runtime guardrails, agent tool governance and red teaming from a vendor now inside a large security platform (Check Point). | Contact sales (free account sign-up offered, tiers not published) |
| Lasso Security | Enterprises deploying agents across platforms such as Bedrock, Vertex AI, Microsoft Copilot and Salesforce Agentforce that want one gateway-level policy and detection layer. | Subscription (annual contract via AWS Marketplace; private offers) |
| Noma Security | Enterprises that want one independent platform spanning agent posture, MCP and tool permissions, runtime detection and red teaming across SaaS, homegrown and endpoint agents. | Contact sales |
| Pillar Security | Security teams that want one inventory and policy layer across agents, MCP servers and skills, with the option to run it inside their own cloud account. | Contact sales |
Application Security
See all 4 tools →Application security testing tools for finding and fixing vulnerabilities in code, dependencies, and containers. Compare SCA, SAST, and open-source application security solutions.…
| Tool | Best fit for | Pricing model |
|---|---|---|
| AISafe Labs | Development teams wanting on-demand AI-driven code audits and web application pentests without a traditional engagement. | Freemium |
| Snyk | Developer-first application security platform for finding and fixing vulnerabilities in code, dependencies, containers, and IaC | Per-developer (monthly) |
| Vulert | Small and mid-sized teams that want continuous open-source dependency and licence monitoring without granting a scanner access to their repositories. | Per-tier subscription capped by number of applications and users, billed monthly or annually, with extra applications charged monthly. Add-on modules are priced per application per month, including licence compliance, SBOM, container and Docker SBOM export. |
| WebSlurpOSS | Web and API testers who want quick capture, edit and replay of a page's own requests without standing up an intercepting proxy. | Free and open source |
Automotive Cybersecurity
See all 5 tools →Automotive cybersecurity companies protect connected and software-defined vehicles across their lifecycle. From ECUs, in-vehicle networks, and telematics to cloud backends, fleets, and EV charging. Th…
| Tool | Best fit for | Pricing model |
|---|---|---|
| PCA Cyber Security | Payment-device makers and operators wanting offensive, real-world security testing of terminals beyond baseline PCI PTS certification | Project-based engagements |
| Upstream Security | OEMs and fleet operators that want cloud-scale detection, response, and a managed Vehicle SOC for connected fleets | Subscription (custom) |
| Vector Informatik | Automotive OEMs and Tier 1 suppliers needing production-grade ECU security software and ISO 21434 verification tooling inside an existing AUTOSAR toolchain. | Quote-based licensing for embedded software and tools, with separate fees for consulting and training |
| VicOne | OEMs and suppliers wanting a broad, lifecycle automotive security portfolio backed by an established cybersecurity parent | Subscription (custom) |
| VxLabs | OEM and Tier 1 teams wanting an integrated TARA, SBOM and compliance evidence workspace, or project-based automotive security engineering. | Subscription for the ThreatZ platform; time and materials, fixed price or retainer for engineering services |
Cloud Security & CNAPP
See all 0 tools →Cloud-native application protection platforms for securing cloud workloads, containers, and infrastructure. Compare CNAPP, agentless cloud security, and cloud workload protection solutions.…
| Tool | Best fit for | Pricing model |
|---|
Cyber Resilience Act Compliance
See all 8 tools →Companies that help manufacturers comply with the EU Cyber Resilience Act (Regulation 2024/2847), the mandatory cybersecurity rules for products with digital elements sold in the EU. From hands-on emb…
| Tool | Best fit for | Pricing model |
|---|---|---|
| pi3g | SME manufacturers of embedded-Linux and IoT products that need hands-on engineering help to reach CRA compliance, not just an audit | Consulting + engineering engagements |
| Bureau Veritas | Manufacturers wanting one TIC partner spanning hands-on pen testing, RED/IEC 62443 testing, and CRA conformity advisory | Consulting + testing + certification |
| ConformOps | Small software teams that want a first, evidence-led CRA readiness pass on a repository at a fixed published price. | One-off assessment plus subscription, with free preview tier |
| CVD Portal | EU manufacturers, importers and distributors that need an Article 13 disclosure contact and Article 14 reporting workflow in place before the 11 September 2026 deadline. | Freemium subscription with a permanent free tier and three paid tiers |
| DEKRA | Manufacturers planning ahead for CRA conformity assessment who want an EUCC-accredited evaluator and future notified body | Training + evaluation + certification |
| ONEKEY | Device manufacturers wanting automated SBOM, vulnerability management, and CRA evidence generation across the product lifecycle | Platform subscription + advisory |
Data Security & Governance
See all 2 tools →Data security and governance platforms for discovering, classifying, and protecting sensitive data across your organization. Compare enterprise DLP, cloud data security, and data discovery solutions.…
| Tool | Best fit for | Pricing model |
|---|---|---|
| Lepide Data Security Platform | Organisations wanting unstructured-data security, access governance and auditing across AD, Microsoft 365 and file servers, as a per-user alternative to Varonis or Netwrix | Quote-based (per user, per year, by platform) |
| Varonis | Data security and governance platform for access visibility, insider threat detection, and sensitive data protection | Subscription (per-user or per-TB) |
Email Security
See all 3 tools →Email security platforms for protecting against phishing, BEC, malware, and other email-borne threats. Compare cloud email security, AI-powered, enterprise gateway, and email encryption solutions.…
| Tool | Best fit for | Pricing model |
|---|---|---|
| Mailinblack | French and European organisations wanting email filtering, awareness training and password management from a single locally registered vendor. | Subscription, quote on request |
| Proofpoint | Enterprise email security platform for advanced threat protection, compliance, and data loss prevention | Per-user subscription |
| veriBIMI | Brands that want a managed DMARC audit and VMC or CMC application handled for a fixed fee rather than dealing with the certificate authority directly. | One-off professional service fees plus certificate authority fee |
Endpoint & EDR
See all 2 tools →Endpoint detection and response platforms for protecting devices against malware, ransomware, and advanced threats. Compare enterprise EDR, XDR, and SMB endpoint solutions.…
| Tool | Best fit for | Pricing model |
|---|---|---|
| Acronis Cyber Protect | Teams and MSPs that want backup, disaster recovery, and endpoint security (anti-ransomware, EDR) in one platform | Subscription (per workload or per GB; MSP consumption-based) |
| CrowdStrike | Cloud-native endpoint protection platform with AI-powered threat detection | Per-device subscription |
Firewall & NGFW
See all 1 tools →Next-generation firewall platforms for network security, intrusion prevention, and application-layer protection. Compare enterprise NGFW, cloud firewalls, and SMB solutions.…
| Tool | Best fit for | Pricing model |
|---|---|---|
| Palo Alto Networks | Enterprise next-generation firewall platform with advanced threat prevention, application visibility, and centralized management | Appliance purchase + annual subscription licenses per feature |
Identity & Access Management
See all 9 tools →Managing who can access what across cloud apps, internal tools, and infrastructure. Whether you need enterprise SSO with thousands of integrations, developer-friendly CIAM for your SaaS app, or open-s…
| Tool | Best fit for | Pricing model |
|---|---|---|
| Auth0 | SaaS teams that need customer login with a great developer experience | Per monthly active user (MAU) |
| Cloudflare Access | Teams replacing a VPN with zero trust access to internal apps | Per-user (free tier + paid tiers) |
| JumpCloud | SMBs and mid-market teams wanting IAM plus MDM without buying both | Per-user (billed annually) |
| KeycloakOSS | Teams that need full control, auditability, and zero license cost | Open Source + Enterprise Subscription |
| Microsoft Entra ID | Organizations already committed to Microsoft 365 and Azure | Per-user (bundled with Microsoft licenses) |
| Okta Workforce Identity | Enterprises with large SaaS portfolios needing a proven, broadly-integrated IAM backbone | Per-user tiers (billed annually) |
Managed Security Service Providers
See all 7 tools →Managed Security Service Providers and MDR firms compared on services, EDR-stack neutrality, transparency posture, and delivery model. From vendor-neutral cloud-native MDR to traditional 24/7 SOC outs…
| Tool | Best fit for | Pricing model |
|---|---|---|
| UnderDefense | Mid-market organisations that want a 24/7 outsourced SOC layered onto security tools they already own, often alongside SOC 2 or ISO 27001 readiness work. | Per device or asset per month on an annual contract, plus project fees for penetration testing and compliance work |
| Arctic Wolf | Organizations without in-house security expertise wanting fully managed vulnerability scanning and prioritized remediation guidance | Per-asset managed service (annual contract) |
| Critical Start | Mid-market and enterprise teams that already own EDR/XDR and want managed response with strong noise reduction | Subscription per integrated surface |
| eSentire | Financial services, legal, and insurance firms that want a mature MDR partner with deep vertical playbooks | Subscription tiers (Atlas Essentials / Advanced / Complete) |
| Expel | Teams that already own a quality EDR/SIEM/cloud stack and want a transparent, vendor-neutral SOC layered on top | Subscription per integrated surface |
| Red Canary (a Zscaler company) | Microsoft-centric organisations wanting Defender / Sentinel telemetry analysed by a high-fidelity detection-engineering team | Subscription per managed surface |
Network Detection & Response (NDR)
See all 7 tools →Network detection and response (NDR) tools monitor network traffic to detect, investigate, and respond to threats that bypass endpoint and perimeter controls. This directory lists NDR tools and vendor…
| Tool | Best fit for | Pricing model |
|---|---|---|
| Arista NDR | Organizations wanting agentless, AI-assisted network detection | Subscription |
| CorelightOSS | Teams wanting open, Zeek-based network evidence and forensics | Open source + Enterprise subscription |
| Darktrace | Organizations wanting AI-driven detection of unknown threats across hybrid environments | Enterprise |
| ExtraHop | Organizations needing deep network visibility and forensics across hybrid environments | SaaS / Appliance |
| Fidelis Network | Government and enterprise buyers wanting deep session inspection NDR | Appliance + Subscription |
| Stamus NetworksOSS | Teams wanting Suricata-based NDR with an open-source edition | Open source + Enterprise |
Observability Pipelines
See all 7 tools →General-purpose telemetry pipelines that route, filter and transform logs, metrics and traces before they reach a backend. These tools carry security data but are not sold specifically for security op…
| Tool | Best fit for | Pricing model |
|---|---|---|
| Azure Data Explorer | Microsoft-centric organizations wanting a scalable security data lake with powerful KQL analytics at lower cost than SIEM | Consumption-based (compute + storage) |
| Datadog Observability Pipelines | Organizations already using Datadog that want managed pipeline capabilities with enterprise support and monitoring | Volume-based (per GB processed) |
| FluentdOSS | Cloud-native teams wanting a lightweight, proven open-source data collector with a massive plugin ecosystem | Open source |
| Mezmo | Teams wanting combined log management and pipeline capabilities with a developer-friendly experience | Ingest-based (per GB) |
| Sawmills | Teams on Datadog, Splunk or similar that want to cut observability cost by filtering and optimising telemetry before ingestion | Usage-based (ingest volume; annual commitment) |
| Splunk Data Stream Processor | Existing Splunk customers wanting to optimize data flows and reduce ingest costs within the Splunk ecosystem | Bundled with Splunk licensing |
PCI PTS Compliance Testing Companies
See all 6 tools →Companies involved in PCI PTS compliance for payment devices, split into two distinct roles. PCI Recognized evaluation laboratories perform the formal PCI PTS POI and HSM evaluations (and related EMVC…
| Tool | Best fit for | Pricing model |
|---|---|---|
| PCA Cyber Security | Payment-device makers and operators wanting offensive, real-world security testing of terminals beyond baseline PCI PTS certification | Project-based engagements |
| Keysight (Riscure Device Security) | Payment device, terminal and mobile payment vendors needing accredited EMVCo or PCI security evaluation of hardware and secure elements | Project-based engagements |
| SERMA Safety & Security | Manufacturers needing PCI PTS and payment-acceptance device evaluation from an accredited European lab | Project-based engagements |
| SGS Brightsight | Payment terminal and HSM manufacturers needing formal PCI PTS, EMVCo or Common Criteria evaluation | Project-based engagements |
| SRC Security Research & Consulting | Manufacturers needing PCI PTS plus German DK/OSeC/JTEMS terminal evaluation | Project-based engagements |
| UL Solutions | Manufacturers needing PCI PTS and EMVCo evaluation from a large, globally accredited lab | Project-based engagements |
Penetration Testing Firms
See all 8 tools →Independent penetration testing firms compared on services, specialisms, delivery model, and standards coverage. From global FTSE 250 consultancies to boutique research-driven firms.…
| Tool | Best fit for | Pricing model |
|---|---|---|
| A-LIGN | Companies running testing alongside a formal audit who want one accredited firm across both | Project-based testing + audit engagements |
| SBS CyberSecurity | Community banks, credit unions and other regulated financial institutions that want testing, audit and governance from one firm, plus organizations preparing for a CMMC Level 1 or Level 2 assessment | Project-based testing and advisory engagements |
| Bishop Fox | Mid-to-large enterprises wanting continuous offensive testing rather than annual point-in-time pentests | Project + Cosmos subscription |
| IOActive, Inc. | OEMs, semiconductor vendors, automotive, and critical-infrastructure operators that need silicon-to-cloud security expertise | Project-based engagements |
| Mandiant (part of Google Cloud) | Enterprises needing top-tier incident response, nation-state threat intelligence, or board-defensible breach engagement | Project-based engagements |
| NCC Group | Regulated enterprises and public-sector buyers wanting CREST-accredited testing, MDR, and software escrow under one global vendor | Project + retainer + managed services |
Privileged Access Management
See all 13 tools →Controlling who can access privileged accounts, servers, databases, and cloud infrastructure. PAM is what you reach for when secrets management alone is not enough: when you need session recording, ju…
| Tool | Best fit for | Pricing model |
|---|---|---|
| Delinea Secret Server | Enterprises focused on privileged access management and compliance | Annual license |
| SplitSecure | Highest-sensitivity accounts, regulated industries, and MSPs needing zero vendor dependency | Tiered (free / per-seat / enterprise) |
| BeyondTrust Password Safe | Enterprises with mixed Unix/Linux/Windows estates needing unified privilege management | Enterprise (contact sales) |
| CyberArk | Enterprise privileged access management and identity security platform | Per-user subscription + modules |
| CyberArk ConjurOSS | Large enterprises with complex compliance and PAM requirements | Enterprise license |
| CyberArk Privilege Cloud | Large enterprises and government agencies with complex legacy environments and compliance requirements | Enterprise (contact sales) |
Product Threat Intelligence Providers
See all 5 tools →Companies that provide threat intelligence focused on specific products and devices, rather than general enterprise or network threat intelligence. This covers vulnerability intelligence tailored to a…
| Tool | Best fit for | Pricing model |
|---|---|---|
| PCA Cyber Security | Payment-device makers and operators wanting offensive, real-world security testing of terminals beyond baseline PCI PTS certification | Project-based engagements |
| Eclypsium | Banks needing firmware-level integrity assurance across a large estate of laptops, servers and network devices | Enterprise subscription |
| Finite State | Manufacturers of connected devices across IoT, automotive, medical, and industrial sectors needing firmware-level vulnerability and exploit intelligence tied to compliance evidence. | Not publicly disclosed |
| Upstream Security | OEMs and fleet operators that want cloud-scale detection, response, and a managed Vehicle SOC for connected fleets | Subscription (custom) |
| VicOne | OEMs and suppliers wanting a broad, lifecycle automotive security portfolio backed by an established cybersecurity parent | Subscription (custom) |
SASE & Zero Trust
See all 0 tools →Secure access service edge and zero trust platforms for securing distributed workforces and cloud applications. Compare enterprise SASE, cloud-native, and SMB zero trust solutions.…
| Tool | Best fit for | Pricing model |
|---|
SBOM Analysis
See all 9 tools →Tools and providers that build, validate or act on a software bill of materials. They differ most in what they start from: some read source code, manifests or an existing SBOM, while others reconstruc…
| Tool | Best fit for | Pricing model |
|---|---|---|
| PCA Cyber Security | Payment-device makers and operators wanting offensive, real-world security testing of terminals beyond baseline PCI PTS certification | Project-based engagements |
| Black Duck | Enterprises needing the deepest open-source detection including undeclared components, M&A due diligence, and regulatory compliance for software supply chain | Enterprise license (project-based) |
| Finite State | Manufacturers of connected devices across IoT, automotive, medical, and industrial sectors needing firmware-level vulnerability and exploit intelligence tied to compliance evidence. | Not publicly disclosed |
| NetRise | Financial institutions and device makers needing a binary-derived component inventory where source code is not available | Enterprise subscription |
| ONEKEY | Device manufacturers wanting automated SBOM, vulnerability management, and CRA evidence generation across the product lifecycle | Platform subscription + advisory |
| TrivyOSS | DevOps and platform engineering teams that need a fast, open-source vulnerability scanner for containers and Kubernetes environments with zero configuration overhead | Open source with commercial Aqua Platform |
Secrets Management
See all 19 tools →Managing API keys, database credentials, certificates, and machine identities across CI/CD pipelines, Kubernetes clusters, and cloud infrastructure. Whether you need enterprise-grade compliance, open-…
| Tool | Best fit for | Pricing model |
|---|---|---|
| Bitwarden (Business)OSS | Security-conscious organizations wanting an affordable, auditable, and self-hostable password manager | Per-user |
| Delinea Secret Server | Enterprises focused on privileged access management and compliance | Annual license |
| HashiCorp VaultOSS | Teams needing flexible, self-hosted secrets management with extensive plugin ecosystem | Open Source + Enterprise |
| Keeper (Business) | Compliance-focused enterprises needing zero-knowledge security and dark web monitoring | Per-user |
| SplitSecure | Highest-sensitivity accounts, regulated industries, and MSPs needing zero vendor dependency | Tiered (free / per-seat / enterprise) |
| 1Password (Business) | Teams wanting combined password management and developer secrets automation | Per-user |
Security Data Pipeline
See all 4 tools →Platforms built specifically for security telemetry: collecting, filtering, normalising and routing security data before it reaches a SIEM or data lake. This category covers tools their own vendors po…
| Tool | Best fit for | Pricing model |
|---|---|---|
| Realm.Security | Security teams wanting a purpose-built security data fabric with centralized visibility and policy-based routing across their entire security stack | Custom |
| CeTu | Security teams seeking an AI-driven, no-code approach to managing and optimizing security data pipelines without dedicated data engineering resources | Custom |
| Cribl | Security data pipeline platform for routing, reducing, and transforming observability data | Volume-based (daily throughput) |
| TenzirOSS | Security teams wanting an open-source, security-native data pipeline with transparent code and no vendor lock-in | Open source with commercial support |
SIEM & Security Analytics
See all 1 tools →Security information and event management platforms for log analysis, threat detection, and incident response. Compare enterprise, cloud, and open-source SIEM solutions.…
| Tool | Best fit for | Pricing model |
|---|---|---|
| Splunk | Enterprise SIEM and security analytics platform for threat detection and incident response | Workload-based or ingest-based |
Tier 1 SOC Automation
See all 8 tools →Platforms that automate tier 1 security operations work: alert triage, enrichment, investigation, and first-line escalation. These tools ingest alerts from SIEM, EDR, email, identity, and cloud source…
| Tool | Best fit for | Pricing model |
|---|---|---|
| Legion Security | SOC teams that want to automate their existing analyst workflows without building or maintaining API integrations. | . |
| Dropzone AI | SOC teams that want to offload tier-1 alert triage and investigation to an AI analyst working across their existing tool stack. | Subscription, priced by investigation volume |
| Intezer | Enterprise SOC teams and MSSPs that want forensic-depth automated alert investigation on top of existing detection stacks. | Subscription priced by endpoint, Starter and Complete tiers, custom quote |
| Prophet Security | Security teams that want autonomous alert investigation with visible reasoning layered onto their existing SIEM, EDR and identity stack. | . |
| Qevlar AI | SOC teams and MSSPs that want alert investigations automated on top of an existing detection stack, including EU-based organizations. | . |
| Radiant Security | SOC teams that want automated triage and investigation layered over existing detection tools, with optional log management. | Flat-rate subscription, custom quote |
Tier 2 SOC Automation
See all 5 tools →Platforms that automate tier 2 security operations work: the investigation that follows an escalation. These tools take an incident that triage has judged real, pull evidence across endpoint, identity…
| Tool | Best fit for | Pricing model |
|---|---|---|
| Legion Security | SOC teams that want to automate their existing analyst workflows without building or maintaining API integrations. | . |
| Andesite AI | Regulated and public-sector SOCs needing investigation, hunting and response automation with FedRAMP High and air-gapped options. | Contact sales (outcome-based, vendor-stated) |
| AtlasCyber | Critical infrastructure and OT-adjacent operators, especially utilities and municipal government, that need detection and investigation to run on-premises or fully air-gapped. | Enterprise, quote on request |
| Conifers.ai | Enterprises and MSSPs wanting agentic multi-tier investigation with blast-radius scoping and reviewable remediation over an existing stack. | Contact sales |
| Exaforce | Cloud and SaaS-heavy enterprises that want agent-driven investigation and hunting with automated containment behind approval gates. | Contact sales |
Vulnerability Management
See all 5 tools →Vulnerability scanning and management platforms for identifying, prioritizing, and remediating security weaknesses. Compare enterprise, cloud, and open-source vulnerability management tools.…
| Tool | Best fit for | Pricing model |
|---|---|---|
| GuardNest | Organisations using WorkNest Secure for penetration testing who want continuous scanning, live reporting, and retesting in the same platform | Subscription |
| RoboShadow | Small and mid-sized organisations and MSPs running Microsoft-centric estates that want vulnerability scanning and automated third-party patching from a single console, with a usable free tier for evaluation. | Freemium with a paid subscription tier priced per account plus per-agent overage, and a quoted enterprise tier |
| CVETodo | Small teams and MSPs that want CVE alerting tied to a live software inventory without an enterprise scanner | Freemium; monthly or annual subscription |
| KUMOOSS | Security researchers and pentesters who want fast, free domain reconnaissance from the command line. | Open Source |
| Tenable | Vulnerability management platform with Nessus scanning, cloud-native VM, and exposure management | Per-asset (annual subscription) |
Get the full 2026 report
All 147tool listings, pricing, and deployment notes in one downloadable spreadsheet (CSV) you can sort and filter. We'll email you the download link.
You'll also get future editions as we add categories. No spam, unsubscribe any time.