Analyst firms do not usually publish a vendor evaluation and then explain, in the same week, why the thing being evaluated is losing its reason to exist.
That is what happened here. Forrester released The Forrester Wave: Cybersecurity Risk Ratings Platforms, Q2 2026 in April 2026, and the accompanying commentary carried the title Cyber Risk Ratings Fade Out. The analyst reached for a musical term, "al niente", meaning a diminuendo to near silence, and applied it to the market being scored.
The position is precise rather than dismissive. Ratings will not disappear. Their influence will diminish, because the value has moved to the intelligence underneath them.
Anyone currently building a third-party risk programme around a score should understand why.
What a rating is and where it comes from
A cybersecurity risk rating is an outside-in assessment. The platform scans internet-facing infrastructure belonging to a company, expired certificates, exposed services, patching latency, email authentication configuration, leaked credentials, botnet activity, and compiles the observations into a number or a letter grade.
Crucially, no cooperation is required. The rated company does not opt in, provide access, or fill in a questionnaire. Everything is observed from outside.
That property is what made the category commercially viable. An enterprise with four thousand suppliers cannot audit four thousand suppliers. It can rate them tomorrow, at scale, without asking any of them for anything. Three use cases followed: third-party risk management, self-monitoring of your own external posture, and cyber insurance underwriting.
The category also does real work in attack surface management and exposure management, which is why the platforms have survived scepticism about the ratings themselves.
The analogy that shaped the category and then broke it
Everything about cyber risk ratings was designed to evoke credit ratings. A score. A letter grade. A third party assessing an entity for the benefit of counterparties who cannot assess it themselves.
The analogy carried the category into procurement conversations quickly, and it has aged badly, for a reason worth stating plainly.
A credit rating assesses something the rated entity substantially controls and reports on: financial position, debt structure, cash flow. The inputs are audited. The methodologies are published and contested by an industry of analysts. And the thing being predicted, default, is a well-defined event with decades of outcome data to calibrate against.
A cyber rating assesses observable externals as a proxy for internal security posture, which is a different and much weaker relationship. An organisation with excellent internal controls and a neglected marketing subdomain can rate poorly. An organisation with a tidy external footprint and no segmentation, no logging, and shared administrator credentials can rate well.
The proxy is not worthless. It is genuinely correlated with breach likelihood, and Bitsight's Leader citation in the 2024 evaluation credited exactly that work, describing a commitment to ratings model validation and correlation studies testing alignment with real-world incidents.
But a correlation used as a gate is a different thing from a correlation used as a signal, and this market spent a decade being used as a gate.
The blood pressure problem
Forrester's own framing of this market is unusually candid about how it is experienced by the people subject to it.
The analyst covering it observed that of all the markets covered across various roles at Forrester, none raises CISOs' blood pressure quite like this one, and identified why. Procurement leaders and cyber insurers have used ratings as a due diligence instrument, with the memorable characterisation that beatings continue until ratings improve.
The mechanics of that frustration are specific. A CISO receives notice that a customer's procurement team has downgraded the company's rating and requires remediation before contract renewal. The CISO then discovers that the finding relates to an IP range the company divested two years ago, or a subsidiary it does not operate, or a certificate on a domain parked for brand protection.
Attribution is the root problem. To rate a company, a platform must first decide which internet assets belong to it, and that decision is made algorithmically, at scale, without the company's input. Errors are inevitable and the burden of correcting them falls entirely on the rated party, who must find the dispute process, prove a negative, and wait.
This is why asset discovery and attribution shows up as a scored criterion in Forrester's evaluations and why vendors compete on it. Panorays took the highest possible score in that criterion in both the 2024 and 2026 editions. Accuracy of attribution is not a feature of these platforms. It is the foundation everything else rests on.
Inside The Forrester Wave: Cybersecurity Risk Ratings Platforms, Q2 2024
The evaluation scored ten providers against twenty five criteria across current offering, strategy, and market presence.
SecurityScorecard placed as a Leader with the highest score of all vendors in the current offering category, positioned around turning ratings insight into action, with third-party risk scaling, AI-driven insight, and automated board reporting.
Bitsight also placed as a Leader, taking the highest possible score in eighteen criteria, credited for commitment to innovation and for the validation and correlation work described above.
Panorays placed as a Leader with top scores in asset discovery and attribution, vendor discovery and mapping, and exposure prioritisation and remediation, alongside the highest reference customer satisfaction rating for overall business value and recognition for its partner strategy.
Recorded Future placed as a Strong Performer, positioned for security teams needing comprehensive threat intelligence across multiple use cases, which is a description of a threat intelligence company that happens to be evaluated here.
Black Kite also placed as a Strong Performer, and its citation is the most revealing line in the entire evaluation. Forrester credited its standards-based approach with addressing the industry's ratings integrity problem directly, and noted that it was the only vendor in the evaluation whose customers were unanimously satisfied with rating accuracy.
Read that carefully. In a ten-vendor evaluation of a market whose entire product is a number, exactly one vendor's customers unanimously believed the number was right.
Forrester's guidance in that edition followed logically: trust would make or break the future of this market, and CISOs should look for providers that obsess over it.
The fork, and which way it went
By the Q4 2025 Landscape, Forrester described the market as at a fork in the road, and framed the choice explicitly. There is value in the data collected to produce ratings, not only in the ratings themselves, but realising it requires moving from static scorecards to driving remediation actions that demonstrably reduce risk.
The Q2 2026 Wave answered the question. The analyst's assessment was that the limitation identified in 2021, that these platforms provided plenty of data and some insight while lacking the ability to translate signals into action, had become indisputably clear.
Note the timeline. The same analyst wrote in 2021 that this market was not ready for enterprise prime time. Five years and two evaluations later, the verdict is that the core limitation persists.
That is a rare thing to find in analyst research, and it is worth more than any tier placement. A category that receives the same criticism across five years and multiple generations of product has a structural problem rather than a maturity problem.
Panorays held Leader status in the 2026 edition with above-average customer feedback, taking top scores in asset discovery and attribution, reporting and visualisation, and in-platform collaboration, with Forrester crediting its combination of ratings data, vendor discovery, and questionnaire management.
The composition of that praise is the tell. Ratings data appears as one input among three. Questionnaire management, the thing ratings were supposed to replace, is back in the value proposition.
What replaces the score
The direction Forrester describes is that intelligence driving risk reduction becomes the primary source of value for vendors and users alike.
In practice that means several shifts already visible in the vendor positioning.
Findings over grades. A letter grade tells a supplier nothing actionable. A specific, evidenced, attributed finding with a remediation path tells them exactly what to fix, and produces a measurable change when they fix it.
Context over uniformity. A single score applied identically to every supplier ignores that a payroll processor holding employee data and a landscaping contractor present entirely different exposure. Panorays' current positioning around context-based assessment reflecting sensitivity, criticality, and AI usage points directly at this.
Workflow over reporting. In-platform collaboration appearing as a scored criterion means the platform is expected to host the conversation between the enterprise and its supplier rather than generate a report that someone emails.
And the questionnaire returns, automated. The outside-in view cannot see internal controls, governance, or process. The inside view requires asking. The mature version of this category does both and reconciles them, which is a considerably harder product than a scanner with a scoring model.
What this means if you run a third-party risk programme
The practical consequence is about programme design rather than vendor selection, and it is uncomfortable if your programme was built in the era Forrester is describing as fading.
If your supplier tiering, contractual security requirements, and renewal gates are anchored to a rating threshold, you have built a process on a proxy that the analyst community has spent five years questioning. That process is defensible to an auditor and increasingly hard to defend to a supplier who can show you the finding is misattributed.
The alternative is not abandoning the platforms, which do genuine work in attack surface discovery and continuous monitoring. It is demoting the score from a gate to a signal. Use the rating to prioritise attention. Use the underlying findings to have a specific conversation. Use assessments to see what the outside-in view cannot.
There is a second implication for anyone whose own company is being rated. Your rating is being consumed by your customers' procurement teams regardless of whether you subscribe to anything, and the errors in it are yours to correct. Knowing what your external footprint looks like to these platforms is now part of managing customer relationships rather than a security exercise.
The category is not dying. It is being demoted from a verdict to an input, which is roughly where the evidence always supported it sitting. Forrester's contribution has been to say so in the same breath as scoring the vendors, which is the most useful thing an analyst firm can do for a market that got ahead of its own credibility.
Analyst Source
Forrester Research
Category definition, vendor inclusion, and evaluation findings in this article draw on Forrester's coverage of cybersecurity risk ratings platforms. The Q2 2024 Wave scored 10 providers against 25 criteria and was accompanied by a Buyer's Guide built from reference customer data; the Q4 2025 Landscape mapped the market ahead of the Q2 2026 Wave, which Forrester published alongside commentary arguing that the influence of ratings themselves is diminishing.
Source research
- The Forrester Wave: Cybersecurity Risk Ratings Platforms, Q2 2026
- Buyer's Guide: Cybersecurity Risk Ratings Platforms, 2024
- The Forrester Wave: Cybersecurity Risk Ratings Platforms, Q2 2024
- The Cybersecurity Risk Ratings Platforms Landscape, Q4 2025
Forrester does not endorse any vendor named here, and tier placement should not be read as a recommendation to buy.