Line up the three vendor lists Forrester has published for this market and the pattern is not competition. It is absorption.
The 2020 evaluation named eight providers: The Climate Service, ESGAnalytics.Ai, Esri, Four Twenty Seven, Jupiter Intelligence, Risk Management Solutions, Verisk, and XDI.
By the 2022 evaluation, four of those eight had gone from the list. In their place: AccuWeather, IBM, Moody's, Planalytics, PlanetIQ, and Tomorrow.io.
Moody's appearing there is the tell. Four Twenty Seven and Risk Management Solutions did not lose this market. They were bought by Moody's, which then showed up in the next edition holding what it had acquired. The Climate Service went to S&P Global on a similar logic.
Climate science startups built the models. Ratings agencies, insurers, and data conglomerates bought them. Understanding why explains what this category is actually selling.
Physical risk and transition risk
The software divides along a line that buyers need to get right before anything else.
Physical risk is the direct exposure of assets to climate hazards. Will this warehouse flood, and how often by 2050. Will this substation face heat beyond its design tolerance. Is this port in a region where cyclone intensity is projected to increase. The modelling here is geospatial and hazard-specific, and the output attaches to locations.
Transition risk is exposure to the response rather than to the climate. Carbon pricing, regulation, technology substitution, shifting demand, stranded assets, reputational and legal exposure. The modelling is economic and policy-driven, and the output attaches to business models rather than to buildings.
An oil and gas company faces enormous transition risk and moderate physical risk. A logistics operator with three hundred distribution centres faces the reverse. A bank holding mortgages against coastal property faces physical risk it does not own, transmitted through a loan book.
Vendors specialise. XDI's Leader position in the current evaluation rests on granular asset-level physical risk data and financial metrics derived from it. That is a different product from one built to model carbon price scenarios across a portfolio, and no tier placement tells you which you need.
Credibility is the product
Here is why the startups got acquired.
The output of this software does not sit in a dashboard. It goes into regulatory filings, financial disclosures, investor communications, underwriting decisions, and capital allocation. Someone external reads the number, and the question that determines the software's value is not whether the model is sophisticated. It is whether the number will be accepted.
That acceptance is institutional rather than technical. When a ratings agency produces a climate-adjusted risk figure, a market that has spent a century learning to price that agency's judgements has a framework for receiving it. When a fourteen-person startup with excellent climate scientists produces a better figure, the recipient has no such framework, and the burden of establishing credibility falls on the buyer who chose them.
This is an unusual property for a software market. In most categories the best product can win on merit. Here the product is an assertion about the future that has to survive scrutiny by auditors, regulators, and counterparties, and the institution making the assertion is part of what is being evaluated.
Which is exactly why the acquisitions made sense in both directions. The startups had models and no standing. The incumbents had standing and no models. The combination is worth more than either half.
XDI is the notable counterexample, holding a Leader position while remaining independent, on the strength of specialisation deep enough that generalists have not replicated it.
From New Wave to Wave
The format Forrester used tells its own story.
The Q3 2020 and Q4 2022 evaluations were New Waves, the format Forrester reserves for emerging markets, both scoring ten criteria. The 2020 edition covered eight providers and was addressed to risk professionals. The 2022 edition covered ten and was addressed to sustainability leaders and risk managers, which is the moment sustainability functions entered the buying conversation.
The Q2 2025 edition is a full Forrester Wave, and the category name gained the word Software.
That transition is the formal marker of a market Forrester now considers mature rather than emerging. Five years from first evaluation to full Wave treatment is quick, and the compression came from regulation rather than from technology.
Inside The Forrester Wave: Climate Risk Analytics Software, Q2 2025
Published in Q2 2025, the evaluation scored providers against a full Wave criteria set rather than the ten-criterion New Wave format used previously. Forrester's coverage of this market sits with Abhijit Sunil, who leads its evaluation research across sustainability management software, climate risk analytics, and IT sustainability services.
XDI placed as a Leader, credited for granular physical risk data and for the strength of its financial metrics analysis, on a specialisation in asset-level assessment across multiple hazards, timeframes, and climate scenarios. Its client base spans banks, utilities, insurers, and governments, which is a reasonable description of who actually buys in this category.
The vendors evaluated across the three editions give a fair map of the market: Esri, Jupiter Intelligence, Verisk, IBM, Moody's, AccuWeather, Planalytics, PlanetIQ, Tomorrow.io, and S&P Global through its acquired capability.
Esri's position across editions is worth noting because it comes from an entirely different direction. Esri is a geographic information systems company that has been doing spatial analysis since 1969, and Forrester's 2020 assessment credited it with leading on data, analytics, and visualisation by applying established spatial technology to physical climate risk. That is a reminder that the underlying discipline here is geospatial analysis with a climate layer, not a new field.
The problem with a single number
There is a methodological tension in this category that no vendor resolves and that buyers should understand before relying on the output.
Climate projections are inherently probabilistic and scenario-dependent. A physical risk assessment for 2050 depends on which emissions pathway the world follows, and those pathways diverge substantially. Underneath that sit model uncertainty, downscaling uncertainty when global models are resolved to a specific building, and hazard-specific uncertainty that is much larger for some perils than others.
The honest representation of that is a range across scenarios with stated confidence bounds.
What a disclosure process wants is a number.
Every product in this market performs that compression, and the compression is where the judgement lives. Two vendors modelling the same warehouse can produce materially different figures, not because one is wrong, but because they made different defensible choices about scenario weighting, time horizon, damage functions, and how to translate physical damage into financial loss.
The practical consequence is that you should never evaluate these products on the headline number. Evaluate them on whether they will show you how the number was produced, which scenarios and horizons it assumes, and how sensitive it is to those assumptions. A vendor that cannot decompose its own output is asking you to put an unauditable figure into an audited document.
The buyer moved
Forrester's shift in stated audience across editions tracks something real. In 2020 this was risk professionals. In 2022 sustainability leaders had joined them. The direction since has been back toward finance, and the reason is that climate disclosure moved from voluntary to mandatory across several major jurisdictions.
Once a figure appears in a regulated filing, the people who care about it change. A sustainability team can live with a directionally useful estimate. A finance function signing a disclosure needs methodology documentation, version control, audit trail, and the ability to explain a year-on-year change to someone who suspects the change came from the model rather than the world.
That is a considerably higher bar than the category was originally built to clear, and it is a large part of why institutional credibility ended up mattering more than model quality.
If you are evaluating now, work out which function will own the output before you shortlist. A tool selected by a sustainability team for scenario planning and a tool selected by finance for disclosure are different purchases with different requirements, and organisations that discover this after signing end up buying twice.
What to test
Bring your actual asset register. Not a sample of representative sites. The real list, including the facilities with imprecise addresses and the leased sites where you are unsure of the footprint. Data quality on your side determines output quality far more than model sophistication does, and vendors differ considerably in how they handle incomplete location data.
Ask for the same asset from two vendors. Run a genuine parallel assessment on a subset and compare. Where the figures diverge, ask both to explain why. The explanations will teach you more about the category than any demonstration.
Interrogate the resolution claim specifically. Ask what spatial resolution the underlying hazard data actually has, and how it gets from that resolution to a statement about one building. Downscaling is where a lot of unstated assumption enters, and the answer separates serious providers from ones reselling coarse public data with a nice interface.
Establish the audit position early. Ask what documentation the vendor provides for a disclosure process, whether its methodology has been reviewed externally, and whether other clients have used its output in filings your auditor would recognise. This is the institutional credibility question stated plainly, and it is fair to ask directly.
Check the update cadence and what happens when models change. Climate science advances, and a vendor updating its models will change your numbers without your business changing at all. Understand in advance how that gets explained, because you will have to explain it.
And be clear about which risk you are buying for. Physical and transition are different problems with different vendors and different specialists. A provider excellent at one is frequently adequate at best on the other, and a category label that covers both hides that difference entirely.
Analyst Source
Forrester Research
Category definition, vendor inclusion, and evaluation findings in this article draw on Forrester's coverage of climate risk analytics, published as New Wave evaluations for an emerging market in Q3 2020 and Q4 2022, and as a full Forrester Wave from Q2 2025. Its sustainability and climate risk evaluation research is led by principal analyst Abhijit Sunil.
Source research
Forrester does not endorse any vendor named here, and tier placement should not be read as a recommendation to buy.