Leadership Compass

This is an update of the previously published Leadership Compass Enterprise Secrets Management 2025.

The KuppingerCole Leadership Compass: Enterprise Secrets Management for Humans, Workloads, and Machines 2026 examines vendors that provide enterprise-grade capabilities for discovering, storing, distributing, rotating, revoking, renewing, auditing, governing, and protecting secrets across the organization. The market includes and extends the former Enterprise Key and Certificate Management (EKCM) market. Keys and certificates remain central, while ESM also covers passwords, Application Programming Interface (API) keys, OAuth and OpenID Connect (OIDC) tokens, Secure Shell (SSH) keys, encryption keys, database credentials, passkeys, cloud access credentials, service account credentials, Continuous Integration/Continuous Delivery (CI/CD) secrets, Kubernetes secrets, signing keys, webhook secrets, AI agent secrets, Model Context Protocol (MCP) credentials, device credentials, and other secrets used to establish access, identity, trust, encryption, signing, and automation.

For this Leadership Compass, an enterprise secret is any credential, key, certificate, token, or configuration value that grants access, proves identity, protects data, signs code, establishes trust, or enables privileged automation.

Inclusion Criteria

Solutions should support human, workload, and device credential and secrets management, or a combination of these areas.

Human secrets management includes software token issuance and storage, password and passkey support, key-pair issuance and management, certificate-based authentication, privileged credentials, and integration with identity providers and directories.

Workload secrets management includes secrets associated with applications, services, service accounts, APIs, bots, Robotic Process Automation (RPA) agents, AI agents, containers, Kubernetes workloads, CI/CD pipelines, and cloud-native services. AI agent identities are treated as an emerging subtype of workload identity. Like other NHIs, they require credentials, tokens, API keys, certificates, and other secrets to authenticate to systems and perform authorized actions. They require explicit attention because they may operate autonomously, invoke tools dynamically, chain actions across systems, access sensitive data, and exercise delegated authority. Increasingly, AI agents connect to enterprise applications, tools, and data through emerging protocols such as MCP and agent-to-agent (A2A) interactions, whose tokens and credentials become high-value access paths that ESM solutions must discover, scope, and govern.

Device secrets management includes identifiers and related secrets for IoT, IIoT, OT, edge, and connected devices, including certificates, embedded keys, tokens, passwords, and cryptographic credentials used for signing, encryption, authentication, and secure provisioning.

Solutions should provide discovery functions, including scanning of source code repositories, CI/CD pipelines, and collaboration tools for hardcoded or leaked secrets (secrets sprawl), inventory, ownership assignment, secure storage, brokering and distribution, lifecycle management, ephemeral and Just-in-Time (JIT) credential issuance, governance, policy enforcement, delegated administration, Role-Based Access Control (RBAC), auditing, reporting, behavioral monitoring and anomaly detection for credential and agent activity, compliance support, support for multiple secret types, key and certificate lifecycle management, PKI and Hardware Security Module (HSM) support, open APIs, multiple deployment models, enterprise-grade security architecture, and integration with identity, PAM, DevOps, cloud, Kubernetes, CI/CD, SIEM/SOC, and AI platforms or orchestration layers where applicable.

Exclusion Criteria

Pure-play password management solutions and PAM solutions are not in scope unless they provide broader ESM capabilities beyond password vaulting, password rotation, or privileged session management. Also excluded are local or narrowly scoped tools used only for self-signed certificates or isolated key storage; developer-only tools lacking enterprise governance, lifecycle management, access control, or auditability; point solutions managing only one narrow type of secret without broader applicability; consulting, integration, or managed service offerings without a generally available product or platform; solutions that are not commercially available products; and solutions without active production customers.

There are no exclusion criteria based on revenue, company size, or geography. However, vendors must have an established base of production customers; freshly launched startups with only proof-of-concept or pilot deployments are out of scope.

How to Book a Briefing
  1. Go to the KuppingerCole Booking tool webpage.
  2. Under Select a Service, select Leadership Compass Briefing 55 mins.
  3. Under Select Staff, scroll down and select Warwick Ashford
  4. Choose date and time between Aug 5th – Sept 18th, 2026 that are convenient for your team. Please note: Times will be shown in your time zone.
  5. You will receive an MS Teams invite that you can forward along to others in your company. Alternatively, you can use this as a placeholder and send us an invite with another app.
  6. Please prepare a slide deck and provide it to the analyst

Briefing Outline

As part of the document preparation, you are invited to participate in a briefing regarding your product/solution. With “secrets” encompassing a wide range of types from certificates and keys to passwords, and serving human, machine, and workload identities, it is important that we identify your area of specialty and ensure that it is correctly positioned and adequately described in the document.

- Company Overview

  • Facts & Figures (e.g., revenue/growth/funding, # of employees etc.)
  • Partner Ecosystem and regional/global focus

- Product Overview

  • Components and structure
  • Pricing/licensing model
  • Areas of Secrets Management served (passwords, tokens, keys/certificates etc.)
  • Lifecycle management of credentials
  • Technologies ensuring secure storage and management of secrets
  • Connectivity support to identity management systems
  • Tools for reporting and governance
  • Other details not covered above.

- Current development roadmap

- Competitive positioning and Unique Selling Propositions

- Demo (approx. 30 minutes) covering:

  • The complete lifecycle of a high-risk secret, from creation to rotation and revocation.
  • Secure consumption of secrets by a cloud-native workload, application, or CI/CD pipeline.
  • Discovery, prioritization, and remediation of exposed, stale, overprivileged, or risky secrets.
  • Enterprise governance, including policy management, approvals, delegated administration, separation of duties, audit, reporting, and event logging.
  • Automation at scale, including secure secret delivery, policy-driven rotation, remediation workflows, and integrations with ITSM, SIEM, SOAR, DevOps, cloud, and identity tools.

Please prepare a slide deck. We would appreciate a copy.
The demo should be live and aimed at demonstrating the solution’s key capabilities and tools.

Your Benefits of Participation

Benefit from Third-Party Attestation

Receive an objective evaluation of your solution that you can easily integrate into your marketing strategy. Our vendor neutral approach ensures results are trustworthy and credible. Use this assessment as a powerful marketing asset to enhance customer trust.

Increase Brand Awareness

Share your cybersecurity expertise with the world. By participating in our analysis, you gain a platform to spotlight your company. Boost your visibility and establish yourself as a leading provider in the industry. If you take part in this Leadership Compass, your solution will be featured in our Research Library at no cost to you.

Get Insights Into Competing Solutions

Discover how your solution compares with others in the industry. Our analysis provides insights not only into your solution but also valuable information about competitors. Utilize this knowledge to strengthen your position in the market.

Gain Valuable Insights on Your Market Standing

Benefit from a thorough, complimentary evaluation of your solution. KuppingerCole Analysts will evaluate not only your product but also your positioning in the market. Seize this opportunity to receive valuable feedback and make your solution even more effective.

Switch to dark theme

Research Assistant

Hi, I'm Kuppi, your AI-powered research assistant. Ask me about KuppingerCole Analysts' research, events, or analysts.
As an AI assistant, I can make mistakes. Please verify important information.