As digital services evolve, consumer identity has become a core architectural concern rather than a simple access layer. CIAM must scale to millions of users while addressing regulation, automated abuse, and expectations for seamless interaction. The latest Leadership Compass on CIAM frames how platforms respond to these pressures, outlining market dynamics and evaluation criteria that help organizations assess capabilities such as onboarding, orchestration, access controls, consent, and ecosystem integration.
John Tolbert, Lead Analyst at KuppingerCole will explain why organizations are re-evaluating their CIAM strategies, outline core CIAM requirements for 2026, and explore what distinguishes market leaders from innovators. He will also provide insight into the Leadership Compass methodology and clarify the differences between CIAM and B2B IAM.
Who Should Attend
This webinar is designed for IT, security, and identity professionals responsible for consumer-facing digital platforms. It is especially relevant for decision-makers evaluating or modernizing CIAM solutions.
Hello everybody. I'm John Tolbert, Director of Cybersecurity Research here at KuppingerCole Analysts. Glad you could join me today. Today I'm going to be talking about CIAM and giving you a preview of the results from the latest leadership compass that we published on the subject. So a little bit of info before we start. Everybody's muted centrally so there's no need to mute or unmute yourself. I'm going to run two poll questions about halfway through and we'll talk about the results at the end when we do Q&A.
And there will be a Q&A session so if you encounter anything you'd like to ask feel free to use the control panel in the live storm application here and I will take those questions at the end. Then lastly we're recording this so both the recording and the slides will be ready in a few days. I'm going to start off talking about what are the challenges of CIAM, some of the trends, key findings from this latest round of research. Then we'll look at the leadership compass process and methodology and then I'll show you some results and then we'll do the poll results as well and then Q&A.
So how do we define CIAM? What does the C stand for? In previous editions of the report I was combining both consumers and customers in the business to business context and also G to C, government to citizen. But this time around I feel like there's been enough change in the market not only from the demand side but also in what vendors are offering that I'm focusing on consumer mostly here in this report and in the next few weeks I'll be publishing a dedicated report on B2B CIAM solutions. So just for clarity this report is about consumer identity and access management.
So what are the goals that you might have when you set up to get a new CIAM system? I'm assuming most probably already have some sort of CIAM system or maybe not but if you're looking it's probably because it's not as effective as it needs to be. It may not be efficient. You need to be able to offer different kinds of registration options, social logins of course being a primary way in as well as you know associating email addresses with major IDPs. You want to be able to convert unknown users that might be hitting your site into known customers or consumers.
Depending on where you're operating you've got to think about regulatory compliance and generally that means getting consent from users to use their information and you want that information because you want to be able to run it through marketing analytics programs, maybe marketing automation tools with the ultimate goal of increasing revenue. You might need to be able to offer better and stronger authentication options. Passwords are fraught with problems as we all know. You need to be able to offer strong account recovery mechanisms and then integrate with fraud prevention solutions.
And then lastly here you need good identity analytics so that you can do investigations when unfortunate events happen. So let's assume maybe you have an early generation CIM solution. What are some of the problems that you might have encountered or might be experiencing right now? Particularly if it was on-prem it might have been difficult to deploy. It might be difficult to maintain because of that. You've got to deal with scalability issues on-prem solutions.
If you're running a retail site or some e-commerce site you probably have several peak periods during the year where you have massive load and then the rest of the year may not be as intensive. So in order to build up to support those peak loads you have to have a lot of infrastructure that might be sitting idle most of the time. So in that sense it can be quite inefficient. Older generation CIM solutions you know tended to be monolithic.
Particularly the on-prem versions they may not have had good API exposure and in order to connect it with other applications you need you know at least REST API exposure. You may be trying to connect it to legacy applications and finding that you don't get that rich connectivity that you need. You want to be able to leverage those identity and marketing analytics. CIM might be a silo for you. It might be difficult to get that information out. Probably one of the most pervasive problems is older generation CIM solutions didn't really offer a lot of good authentication choices.
And if you're still only able to offer username password authentication that's problematic for a number of reasons. Security, user convenience, perception of not being able to offer the latest and greatest technologies that maybe other websites are using. You might find that consent collection in these jurisdictions where there are privacy regulations is more difficult. And then there's a cost. If you do it on-prem then you're probably paying per server or per CPU or you know maybe some odd mix of ways of trying to price the solution. Then we also have cybercrime and fraud.
You know we'll just talk about there's many different kinds of fraud but we'll just talk about the two most common that you have to deal with. ATO fraud, account takeover fraud, and AO fraud or account opening fraud. ATO fraud comes from you know bad guys using breach passwords running credential stuffing attacks. They'll take a username password combo that's been found on the dark web and a data breach and then spray that all over all sorts of sites knowing that many users reuse username password combinations hoping to get in.
There's still brute force password attacks and they're used for any kind of value transfer. You might think of banks and credit cards you know at the top of the list but there's also you know the hospitality industry, frequent flyer programs, any other loyalty program, anything that can be used and converted into money. For account opening fraud they use PII. They get this from school, work, health records.
I think this is why we've seen so many data breaches against healthcare companies over the last several years because there's an awful lot of information about individuals there and unfortunately a lot of healthcare sites have not focused on security. These can be used for major financial fraud. I mean because think when you construct an account with real people's data then you can use that as a fraudster to go out and try to get loans, lines of credit. They can also be used as mule accounts for money laundering so trying to prevent AO and ATO fraud is really important.
We say the best mitigation for ATO prevention is multi-factor authentication plus risk-based authentication. I think we're all well aware of MFA fatigue so there are ways around that unfortunately but trying to balance that out with a myriad of different technical solutions and risk-based authentication can certainly help mitigate some of that and then the mitigation for account opening fraud is really really good identity verification.
So the requirements we see this time around are similar to those that we've been looking at for the last few years plus as you'll see at the bottom some AI related stuff. We do notice that many organizations are asking for more full-featured identity verification for anti-money laundering, know your customer, trying to prevent AO fraud. We see that instantiated in let's say the remote mobile onboarding apps that can take selfies and compare that to official government issued IDs.
Hopefully they're doing liveness detection, preferably active liveness detection because we see a lot of deep fake attacks against this enrollment process. Fraud is increasing. Consumer facing organizations really need to do what they can to protect their customers. Not only protect themselves against loss but protecting customers helps to ensure your reputation is intact and this is where I think integrations with solutions like fraud reduction intelligence platforms is really key. We cover fraud reduction intelligence platforms and other reports and you can find those on our website too.
Happy to talk about that later also. I mentioned privacy regulatory compliance. GDPR has gotten a lot of attention over the last eight years or so but many other countries and states have enacted privacy regulations that in some cases are similar to GDPR or different so being able to have a CIM solution that can help you comply with the various different regulations is certainly advantageous. Passwordless authentication authentication. Passwordless is I think where we all want to be.
We've been hearing for many many years about the perils of passwords, why they're bad from security as well as user convenience point of view. So passwordless I think is is a real key requirement. We need to be able to integrate and interoperate with lots of other kinds of line of business applications. I'll talk about that more later. Hopefully you know many of these solutions do have out-of-the-box connectors for different kinds of line of business and customer facing applications or at least offer rest API exposure.
IoT device identity management and being able to link your accounts to that and manage your devices. If you think about smart home, home automation, you know fitness wearables, connected cars, home electronics, all those now have some notion of device identity and consumers want to be able to manage that in conjunction with their own let's say email address or whoever their favorite identity provider is. And last but not least of course the AI items like LLM powered chatbots.
We see there are a number of leading LLM provider platforms and some of these CIM solutions have out-of-the-box integrations with those as well. And then we need to be able to accommodate AI agents that are operating on behalf of consumers. This one's tricky. I think we're just starting to see some of them. The leading edge solution providers here are coming up with good innovative ways of differentiating between human users and AI agents and being able to write policies that can help move those along in their workflows.
So now I'll talk a little bit about the integrations that we like to see between CIM and other types of solutions here like customer data platforms. A CDP wants to be able to pull information in from your CIM, maybe from your CRM, your customer relationship management software, email, social media. So it's really an omni-channel pull from lots of different sources to try to get a unified view of the customer across all these different channels.
It tends to want to resolve those different identities, tie it to a unique identifier, and then be able to segment those by, you know, different kinds of characteristics like demographics or customer preferences or even behavior. Why? So that they can do personalization and make recommendations, which of course helps with marketing and increasing revenue. It can help with managing all that data. Sometimes CDPs also offer integration with consent and privacy management solutions, which I'll talk about in just a minute.
And again, this is to facilitate what they call in the industry multi-channel activations, getting your customers, your consumers engaging with your web estate in a variety of different ways, including the web as well as mobile applications, those consumer devices, social media, and ad platforms. I mentioned consent and privacy management. Many of the CIM solutions that we're looking at here do have some notion of consent and privacy management built in, but others offer integrations with these third-party platforms.
The third-party platforms may in some cases offer, you know, more robust features in terms of being able to collect the consent, manage it, you know, deploy privacy policies and specific terms of service for different applications. They may offer DSAR portals. These are data subject access request portals. They can help you on the management side by performing PII inventories, helping you out with audits, and of course, the ubiquitous cookie option management.
Chatbots, I mentioned those just a minute ago. A lot of organizations are using chatbots as a mean to offer additional services and reduce tech support costs. There are a few CIM solutions that have some out-of-the-box connectors for popular AI-powered chatbot services, and then payment integration. There are payment service providers out there, and some of the CIM solutions have deep integration with those as well. I've mentioned AI agents a couple of times.
I think we need to be thinking about where this is going, what standards are available today, and how to secure them, because they're going to look and act a bit differently than just the human user they represent. Fortunately, we've got things like dynamic client registration and pushed authorization requests that can help with that. Emerging standards, I would imagine there will be others to come in the near future. These will generate even more and more data. You'll need continuous machine learning powered assessments to help differentiate between human user behavior and AI agent behavior.
The fraud reduction intel platforms need to work on discerning human user from AI agent and also what might constitute fraud coming from an AI agent. Data minimization is always a good practice for not only the privacy compliance area, but also making it easier to figure out what's legit and what's not.
Then also, just monitoring all your access and keeping your logs. I think it will become interesting, to say the least, when there are, let's say, contentions between what a user's AI agent has done and what they may claim they wanted. Having audit logs will be very important in cases to come. Some of the most interesting findings, passkey authentication is widely available.
In fact, 88% of the respondents to the survey offer passkey authentication. They might not all be FIDO certified, but they claim to have passkey authentication, which, of course, for me begs the question, why don't I see passkeys offered 88% of the time when I'm out there acting as a consumer myself? I think there's still a lot of work to be done on the part of deploying organizations to get this out as an option for everyone. Basic identity governance, life cycle management are offered by about half of the solutions, maybe a little more, in varying degrees.
This covers everything from how you go about registering to how do you deal with orphaned accounts or abandoned accounts. I think this becomes a real concern when there are many digital properties out there that have not just millions, but in some cases billions of users.
In a way, orphaned or abandoned accounts represent a liability, so it's good to be able to have processes that can clean that up. Built-in IDV services are great. I talked about the remote onboarding apps. We see about 40% of the CIM solutions that offer some degree of built-in IDV capabilities. For those that don't, I think it's more imperative to offer integrations with third-party IDV services, of which there are many, and they tend to be highly regionalized. Organizations that are looking for CIM probably need integration with some sort of fraud reduction intel platform.
Again, that can be facilitated often through APIs or dedicated connectors. Sort of in line with that, about 80% of the CIM solutions that are out there today have at least some notion of device intelligence capabilities. This includes looking at the device type, device ID, maybe operating system and patch level, and then maybe being able to do device posture checks. That's the more advanced side, but those are really good at helping to cut down fraud, particularly ATOs. Orchestration is increasingly important because onboarding workflows, authentication policies need to be orchestrated.
A lot of times it's not just what comes out of the box in the CIM solution that's important, but also what can you sort of plumb into the workflow. Things like calls out to IDV services or FRIP services or maybe other authoritative attribute providers. Here's where you need good orchestration capabilities. Usually that to me looks like a nice flow chart style interface that maybe you can drag and drop various elements into it and configure it in such a way that doesn't require a lot of heavy coding.
Only about half of the products offer really integrated consent and privacy management that are good enough to help you with GDPR, CCPA, and other regulatory compliance mandates. Most of the solutions offer at least some basic IoT device management capabilities, and by basic we're really just saying support for OAuth2 device authorization grants. Some have much more sophisticated capabilities like built-in portals for managing the devices in conjunction with their primary identifier. And then AI agents again. I think this is an emerging area.
We've got five solutions that I looked at that have what I think are pretty good nascent capabilities for helping customer organizations deal with AI agents. So for more information you'll want to read the details in the report. So let's stop and take a couple of poll questions. I'm curious to see where you all are thinking about CIM. So which of the following are the main motivations that your organization has for implementing or upgrading CIM? Is it about improving the consumer experience, improving security, enhancing marketing, or increasing revenue?
So feel free to answer that, and we'll talk about the results in a minute. And while we're doing polls, let's take another one. When you get done with that one, the next one is what's the biggest obstacle that you face in deploying or upgrading CIM? I can imagine the budget might be a primary consideration, or maybe you can't get your IT teams and your business teams to agree on what the goals of it are. It could be a legacy app integration, it might be scalability or difficulty in managing it, or just a lack of customizability. So feel free to select what matters most to you there.
Now we'll go on and talk about the Leadership Compass methodology process. So when we identify a field, we also look at all the different vendors that are in the field, we invite them to participate, we get briefings, we see demos of what the experience is like from both the user side as well as the admin side. We create these giant questionnaires that look like RFPs to try to find out what can these products really do. We look at the information that they give us, we evaluate it, we rate them in the charts you'll see in a minute, and we do a nice write-up. We send it out for fact check.
Once fact check is complete, then we publish it on our website. We have nine major categories of standard functionality or standard categories that we look at, including security, which means internal product security, how to admins authenticate, what kind of authorization, what kinds of encryption. We look at functionality, does it do everything that we expect it to do? We look at deployment, is it on-prem only?
Very, very few are on-prem only these days. But is that still offered, or can you run it in a hybrid configuration, or is it completely SAS delivered?
Is it, you know, limited by regional support? Is it easy to deploy? Interoperability, this is where standard support is really key. Everything from LDAP, SCIM, SAML, OIDC, FIDO, increases interoperability scores here.
Usability, we try to look at both the user side as well as the administrative experience. Innovation, you know, is it leading edge, or is it playing catch-up compared to everyone else?
Market, you know, really looks at, you know, numbers of customers, how geographically distributed are they? Are they targeting industries, you know, in many different sectors?
And then, you know, where is it being used around the world? Ecosystem looks at the support network, you know, systems integrators, VARs, where are they, how many?
And then, lastly, financial strength. Is it a big profitable company? Is it a brand new startup? Is it somewhere in between? I think these are also things that a lot of buyers are interested in knowing.
So, we come up with four categories of leadership. One is product leadership. This looks at, you know, the functionality, security, deployment, interoperability, and usability aspects. Market leadership considers the financial strength, market size, ecosystem. Innovation is purely innovation.
And then, we put them all together in overall leadership. So, let's take a look at the result.
So, this time around, you'll see we have quite a number of participants, including some new participants this time around. We've had E-Trust, Front Egg, and Kind are new to the report. And here's a quick look at the overall leadership graphic. And it's probably not too surprising. We've got a lot of large, well-known IM or IDAS vendors out here, as well as some pretty well-known CIM specialists.
And again, this takes into account all the nine primary categories, you know, security through market size and innovation. And you can see the other charts in the report itself. We also do a spider chart for every company that we look at.
And here, we try to drill down on specific bits of functionality or features that we think are important. In this case, I've chosen onboarding, which is what it sounds like, you know, what's the process like for onboarding.
You know, orchestration, lifecycle management, authentication, authorization, consent management, IoT device management. And then, the last one here, dashboards and reports, is about the admin user experience.
So, these will look different depending on the vendor and their capabilities. I mentioned B2B-IM. I'm not covering it this time around, but sometime in the next month, this should be out, too. It's a leadership compass dedicated to looking at B2B-IM use cases.
Some of the key features here that I'm looking at are, you know, really good IDV, plus the ability to do call-outs to HR background check services, maybe do name watch list screening, integrated compromise credential checking, communication with all your downstream partners, being able to offer terms of service per application and per audience.
I think one of the most important requirements here is hierarchical delegated administration, because thinking about very large supply chain ecosystems, you may have a prime contractor, you may need to, you know, you may have thousands or tens of thousands of users, not only in your own organization, but in all these down-level organizations that need to get access to your resources.
Well, it would be far too complicated and onerous to try to do that as the prime contractor, so you need to be able to offer delegated administration, and you need to be able to sort of fine-tune what each one of these delegated admins can do. So, for that, we see things like RBAC, ABAC, PBAC support as necessary.
So, I'm really drilling down into that in particular for this report. You need to be able to offer things like just-in-time account creation and then be able to place various kinds of account restrictions on that, like making time-limited accounts or single-use accounts or even geo-fencing accounts. You need self-service portals, and this will be a little bit different from what you're looking at in CIN. The self-service portals here will need to be able to accept access requests and track status on those.
You need a central admin console for the operator, and in this report, I'm defining operator as the one who, you know, sort of sits at the center and delegates administration to other parts of the ecosystem. You need granular authentication policies and per-entity reports, for example, you know, getting log-in reports, log-in failure and success reports for all the down-level organizations that are part of your ecosystem.
So, again, a separate B2B IM report is coming soon. So, let's stop for a moment and take a look at the polls. Just a minute here.
So, for the first question, what, which of the following are the main motivations that your organization has for implementing or upgrading CIN? 43% said improving the consumer experience. 41% said improving security. Then we have enhancing marketing at 3%. Which of the biggest, what is the biggest obstacle your organization faces in deploying or upgrading CIN? 29% say business versus IT alignment on the goals. 24% say budget.
19%, 18% say legacy app integration. Scalability also comes in at 18, and lack of customizability shows up at 9.
So, thank you for participating. Let's see. We have a number of questions here, so I will start off.
One says, in the retail industry, social log-in is still a favorite for customers, while passkey adoption remains a challenge. From your research, what are the most effective ways to transition users to passkeys without creating friction?
I think, you know, we have to live in hybrid mode for a while, but start by offering passkeys. I still don't see that offered nearly as much as I would like.
Yes, there are technical limitations for deploying it, and I think we have to live in hybrid mode for a while, but, you know, make it prominent when a person logs in that there is a passkey option and encourage them to sign up and use the passkey. That's what I would like to see. How does Coop and Coal approach and understand IoT device management as part of CIM? Like I was saying, I think most of us, let's say when you buy some sort of consumer electronics product or, you know, a smart home gadget, we know we're going to register with, you know, one of our favorite identifiers.
We want to be able to manage that device in conjunction with that. We don't want to have to create separate accounts.
So, you know, a good notion of single sign-on if it's between you and your customer or, you know, some other supporting organization is important, but also I think having out-of-the-box or at least easily customizable portals for managing that are really a key means to make it easy for users to get the most out of their consumer electronics devices. Let's see. Next one. Are digital wallets a strategic driver for CIM future or just an incremental upgrade to our authentication? I definitely think they're coming.
I think there's some work in this area that is showing up as, you know, what I would consider innovative at this time. Same thing with decentralized identity. And I think a lot of that depends on where you live in the world.
Of course, European audiences are a little bit more interested in rolling out things like digital wallets and decentralized IDs than other parts. So looking at solution providers that come from those parts of the world where digital wallets are already starting to gain some prominence is probably your best bet. Let's see. Next one is, which CIM capabilities flip from nice to have to mandatory when you move to B2B? Okay. I'll give you a preview of that one. And I think I was hinting at it already.
Really good IDB options, including, you know, where necessary, being able to integrate with HR or background checking services. You know, you think there's a wide variety of different kinds of environments that are doing B2B.
You know, it could be something like a big complex manufacturing supply chain where you've got lots and lots of different companies that need to get into, let's say, a collaborative environment and maybe co-develop products together or, you know, offer services together. And then on the other side, you know, you've got organizations that sort of deal with thousands or even millions of independent contractors. So in that case, you know, things like identity verification become very important as well as being able to scale it and do it quickly.
Those companies in that latter situation where you've got thousands or millions of contractors will also need different kinds of account restrictions. You may see, you know, time-limited accounts. Maybe one example I heard about is in the logistics industry. You need to be able to create accounts for drivers that may do, you know, a particular job, you know, and that job might last two days. So you want to limit the life cycle of that account to only two days of having access. But maybe that person is going to come back and work for you in a week or a month or a year.
So you probably don't want to eliminate the account altogether. So in that case, things like really granular account life cycle management matter a lot too.
So yeah, I'm looking forward to getting that report done and I'll do a webinar on that one too. So that looks like the end of our questions for now. I want to thank everyone for attending. I hope it was enjoyable or you learned something. And if you have any questions, feel free to reach out. I do encourage you to take a look at the report. The report is live on our website and it also is accompanied by a buyer's compass that takes a different look at this content, kind of giving you the precursors for being able to do your own RFPs for CIM also.
And with that, I thank you and hope you have a great rest of your day.
See All Locations
See All Locations