Leadership Compass

This is an update of our report on Software Supply Chain Security (SSCS) that was published in August 2023. If you would like to look at this report, please click this link

This Leadership Compass takes a different approach to SSCS. Unlike traditional SSCS evaluations that focus exclusively on tools for software developers and DevOps teams, this analysis recognizes that the software supply chain includes two distinct but equally important audiences:

  • Software Producers - Organizations that develop, build, and release software, requiring tools for code analysis, build integrity, and artifact signing.
  • Software Consumers - Organizations that procure, deploy, and operate third-party software without access to source code, requiring tools for vendor assessment, Software Bill of Materials (SBOM) validation, and ongoing risk monitoring.

Most organizations occupy both roles simultaneously, developing some software while consuming vast quantities of commercial and open-source components from external suppliers. This Leadership Compass evaluates platforms that can serve either or both audiences, from pure development-focused solutions to pure consumption-focused risk management platforms, and solutions that span the entire spectrum.

Inclusion Criteria

Minimum Core Requirements

In this Leadership Compass, we are looking for solutions that demonstrate active capability in at least 60% of the following core areas:

  1. Source code integrity with provenance tracking and verification
  2. Build integrity throughout the CI/CD pipeline with attestation and signing
  3. Vulnerability management of code and deployment artifacts
  4. Third-party supplier risk measurement and monitoring including automated security posture assessment, continuous scoring, and vendor evaluation workflows
  5. Dependency graph analysis with full transitive dependency mapping and risk propagation tracking
  6. SBOM generation and management with export/import capabilities in standard formats (SPDX, CycloneDX)
  7. Secrets management and credential protection with automated detection, prevention, and historical repository scanning
  8. Package repository security including typosquatting detection, namespace confusion prevention, and malicious package pattern detection
  9. Integration with CI/CD tools via APIs/SDKs/CLIs with workflow integration
  10. Policy-based security controls and governance with configurable rules and automated enforcement
  11. Continuous monitoring and alerting for supply chain events across the entire pipeline
  12. Runtime monitoring and behavioral analysis of supply chain components with anomaly detection
  13. Industry compliance framework support including regulatory alignment (EU Cyber Resilience Act, NIST SSDF, EO 14028)
  14. Incident response and remediation workflows for supply chain compromises including impact assessment and rollback capabilities
  15. Code signing and attestation with SLSA framework compliance and cryptographic verification throughout the pipeline
  16. Developer environment security including compromised credential detection and workstation protection

Essential Foundation Requirements

All solutions evaluated must provide:

  • Active vulnerability scanning capabilities across the software supply chain
  • Basic third-party dependency tracking and risk assessment
  • Integration with at least one major CI/CD platform (e.g., Jenkins, GitLab, GitHub Actions, Azure DevOps)
  • SBOM export functionality in standard formats (e.g., SPDX, CycloneDX)
  • Evidence of production deployment and verifiable customer references

Market Maturity Threshold

Solutions should demonstrate:

  • At least 12 months of active customer deployments in production environments
  • Published documentation and integration guides for implementation
  • Vendor support and maintenance commitments with defined SLAs
  • Clear roadmap for capability expansion and feature development
    This framework ensures that evaluated solutions represent mature, deployable platforms capable of addressing real-world SSCS challenges rather than experimental or incomplete offerings.

Exclusion Criteria

The following will not be considered:

  • Vendors without active production deployments at customer sites
  • Point solutions that only provide vulnerability scanning without pipeline integration
  • Traditional SCA tools that lack build integrity and supply chain orchestration capabilities
  • Solutions that address only container security or only source code analysis without broader supply chain coverage
  • Vendors in stealth mode without verifiable customer references
    There are no exclusion criteria based on company size, revenue, or geographic region. We evaluate vendors from start-ups to large enterprises, provided they meet the minimum maturity and capability thresholds outlined above.
How to Book a Briefing
  1. Go to the KuppingerCole Booking tool webpage.
  2. Under Select a Service, select Leadership Compass briefing (55 min).
  3. Under Select Staff, use the drop-down menu, scroll down and select Jonathan Care.
  4. Choose a date and time between January 19th - February 13th (note that the times are shown in your time zone).
  5. You will receive a MS Teams invite which you can also forward to your team.
  6. Please prepare a slide deck, and if possible, send to us ahead of your briefing.

SSCS Briefing Guidelines

Core SSCS Capabilities to Cover:

Source and Build Integrity:

  • Software Bill of Materials (SBOM) generation and management
  • Software Composition Analysis (SCA) and code signing capabilities
  • Static Application Security Testing (SAST) integration
  • Build artifacts provenance tracking and validation
  • Code tampering detection and prevention measures

Third-Party Risk Management:

  • Automated vendor and supplier security posture assessment
  • Continuous monitoring and scoring of third-party dependencies
  • Open-source maintainer reputation and community health evaluation
  • License compliance and legal risk tracking capabilities

Vulnerability Management:

  • Multi-environment scanning (DAST, IAST, API, Container, IaC)
  • Automated vulnerability detection, alerts, and remediation workflows
  • Intelligence-driven vulnerability prioritization and risk scoring
  • Integration with existing security tools and workflows

Supply Chain Visibility and Governance:

  • End-to-end software supply chain visibility and reporting
  • Configurable security policies and compliance management
  • Real-time dashboards showing supply chain statistics and trends
  • Audit trails and user activity monitoring

Developer Experience and Integration:

  • CI/CD tool integration options (APIs, SDKs, CLIs)
  • Source control management integration capabilities
  • Developer workflow integration with minimal friction
  • DevSecOps practice enablement

Intelligence and Automation:

  • AI/ML-driven analytics and anomaly detection
  • Workflow automation and orchestration capabilities
  • Predictive risk analysis and threat intelligence integration

Product Demonstration

The demo can be live, video, or pre-recorded, although the analyst would like to be walked through the demonstration to understand the product's key capabilities, including dashboards, user interfaces, and workflow integrations.

Demo should highlight:

  • User interface and dashboard functionality
  • Key workflow demonstrations (e.g., vulnerability detection to remediation)
  • Integration examples with common CI/CD tools
  • Reporting and visibility capabilities
  • Policy configuration and management features

Additional Topics (If Time Allows):

  • Operational and Administrative Support:
  • User administration and role-based access controls
  • System configuration and customization options
  • Deployment models (on-premises, cloud, hybrid)

Technical Integration:

  • Available APIs, SDKs, and CLI support
  • Integration with IAM, SIEM, XDR, and ITSM solutions
  • Container and Kubernetes environment support

Compliance and Standards:

  • Regulatory compliance support (EU Cyber Resilience Act, NIST SSDF, EO 14028)
  • Industry standards and protocol compliance
  • Audit and compliance reporting capabilities

Advanced Capabilities:

  • Incident response and recovery workflows
  • Zero trust architecture integration
  • Supply chain threat intelligence capabilities

Strategic Direction:

  • Product roadmap and upcoming features
  • Market positioning and competitive differentiation
  • Customer success stories and use cases

Briefing Duration: Please plan for a comprehensive overview that can be completed within the allocated time while ensuring adequate coverage of core capabilities and meaningful product demonstration.

Your Benefits of Participation

Benefit from Third-Party Attestation

Receive an objective evaluation of your solution that you can easily integrate into your marketing strategy. Our vendor neutral approach ensures results are trustworthy and credible. Use this assessment as a powerful marketing asset to enhance customer trust.

Increase Brand Awareness

Share your cybersecurity expertise with the world. By participating in our analysis, you gain a platform to spotlight your company. Boost your visibility and establish yourself as a leading provider in the industry. If you take part in this Leadership Compass, your solution will be featured on KC Open Select at no cost to you.

Get Insights Into Competing Solutions

Discover how your solution compares with others in the industry. Our analysis provides insights not only into your solution but also valuable information about competitors. Utilize this knowledge to strengthen your position in the market.

Gain Valuable Insights on Your Market Standing

Benefit from a thorough, complimentary evaluation of your solution. KuppingerCole Analysts will evaluate not only your product but also your positioning in the market. Seize this opportunity to receive valuable feedback and make your solution even more effective.

Switch to dark theme

Research Assistant

Hi, I'm Kuppi, your AI-powered research assistant. Ask me about KuppingerCole Analysts' research, events, or analysts.
As an AI assistant, I can make mistakes. Please verify important information.