This is an update of the previously published Leadership Compass Enterprise Secrets Management 2025.
The KuppingerCole Leadership Compass: Enterprise Secrets Management for Humans, Workloads, and Machines 2026 examines vendors that provide enterprise-grade capabilities for discovering, storing, distributing, rotating, revoking, renewing, auditing, governing, and protecting secrets across the organization. The market includes and extends the former Enterprise Key and Certificate Management (EKCM) market. Keys and certificates remain central, while ESM also covers passwords, Application Programming Interface (API) keys, OAuth and OpenID Connect (OIDC) tokens, Secure Shell (SSH) keys, encryption keys, database credentials, passkeys, cloud access credentials, service account credentials, Continuous Integration/Continuous Delivery (CI/CD) secrets, Kubernetes secrets, signing keys, webhook secrets, AI agent secrets, Model Context Protocol (MCP) credentials, device credentials, and other secrets used to establish access, identity, trust, encryption, signing, and automation.
For this Leadership Compass, an enterprise secret is any credential, key, certificate, token, or configuration value that grants access, proves identity, protects data, signs code, establishes trust, or enables privileged automation.
Inclusion Criteria
Solutions should support human, workload, and device credential and secrets management, or a combination of these areas.
Human secrets management includes software token issuance and storage, password and passkey support, key-pair issuance and management, certificate-based authentication, privileged credentials, and integration with identity providers and directories.
Workload secrets management includes secrets associated with applications, services, service accounts, APIs, bots, Robotic Process Automation (RPA) agents, AI agents, containers, Kubernetes workloads, CI/CD pipelines, and cloud-native services. AI agent identities are treated as an emerging subtype of workload identity. Like other NHIs, they require credentials, tokens, API keys, certificates, and other secrets to authenticate to systems and perform authorized actions. They require explicit attention because they may operate autonomously, invoke tools dynamically, chain actions across systems, access sensitive data, and exercise delegated authority. Increasingly, AI agents connect to enterprise applications, tools, and data through emerging protocols such as MCP and agent-to-agent (A2A) interactions, whose tokens and credentials become high-value access paths that ESM solutions must discover, scope, and govern.
Device secrets management includes identifiers and related secrets for IoT, IIoT, OT, edge, and connected devices, including certificates, embedded keys, tokens, passwords, and cryptographic credentials used for signing, encryption, authentication, and secure provisioning.
Solutions should provide discovery functions, including scanning of source code repositories, CI/CD pipelines, and collaboration tools for hardcoded or leaked secrets (secrets sprawl), inventory, ownership assignment, secure storage, brokering and distribution, lifecycle management, ephemeral and Just-in-Time (JIT) credential issuance, governance, policy enforcement, delegated administration, Role-Based Access Control (RBAC), auditing, reporting, behavioral monitoring and anomaly detection for credential and agent activity, compliance support, support for multiple secret types, key and certificate lifecycle management, PKI and Hardware Security Module (HSM) support, open APIs, multiple deployment models, enterprise-grade security architecture, and integration with identity, PAM, DevOps, cloud, Kubernetes, CI/CD, SIEM/SOC, and AI platforms or orchestration layers where applicable.
Exclusion Criteria
Pure-play password management solutions and PAM solutions are not in scope unless they provide broader ESM capabilities beyond password vaulting, password rotation, or privileged session management. Also excluded are local or narrowly scoped tools used only for self-signed certificates or isolated key storage; developer-only tools lacking enterprise governance, lifecycle management, access control, or auditability; point solutions managing only one narrow type of secret without broader applicability; consulting, integration, or managed service offerings without a generally available product or platform; solutions that are not commercially available products; and solutions without active production customers.
There are no exclusion criteria based on revenue, company size, or geography. However, vendors must have an established base of production customers; freshly launched startups with only proof-of-concept or pilot deployments are out of scope.