The inaugural Magic Quadrant for Exposure Assessment Platforms, published November 10, 2025, is built on a number that indicts the market it replaced. Gartner's data from more than 15,000 environments shows 74 percent of identified exposures are dead ends, assets with no viable path to critical systems, and legacy vulnerability management teams spend roughly 90 percent of remediation effort on them. The new category exists because the old one was grading the wrong thing.
The market that replaced vulnerability management
Vulnerability management was built on the CVE list: find every vulnerability, prioritize by severity, patch until the queue is empty. The queue never empties, and the dead-end statistic says why: most of what the scanner finds cannot be reached by an attacker in the first place.
Exposure assessment changes the question. Instead of what is broken, the platform asks what can the attacker actually reach, and how: which assets matter, which access paths connect the attacker to them, and which exposures sit on those paths. The category is built around Gartner's continuous threat exposure management model, and the quadrant is its first scorecard.
Exposure assessment replaced vulnerability management by changing the question, and the question change is worth the whole category.
The November 2025 Magic Quadrant for Exposure Assessment Platforms, first edition of a renamed market
The inaugural edition published November 10, 2025, authored by Mitchell Schneider, Dhivya Poole, and Jonathan Nunez, evaluating twenty vendors, and it formally replaces the prior Market Guide for Vulnerability Assessment.
The evaluation's criteria run on continuous discovery across internal networks, cloud workloads, identity layers, and unmanaged assets; context-based prioritization on asset importance, access paths, exploitability, and control coverage rather than severity alone; integration into operational workflows and ticketing systems; and lifecycle tracking of exposures through remediation.
The confirmed placements from the public record: Tenable as a Leader, NopSec as a Visionary at the edge of the Leader quadrant, and Brinqa and PlexTrac both recognized in the field. The midmarket companion report, published January 5, 2026, adds a separate lens for midsize enterprises.
The dead-end math
The 74 percent dead-end statistic deserves the slow reading, because it re-prices the whole discipline.
Legacy teams spending 90 percent of remediation effort on exposures with no viable path to critical systems are not failing at patching. They are succeeding at an activity with zero risk reduction value, and the budget that funds it is the market's real cost. The statistic is the business case for the new category: the platform that distinguishes the dead ends from the attack paths converts a compliance treadmill into a risk reduction program.
The projection attached to the category makes the stakes concrete: Gartner expects organizations using exposure assessment platforms to reduce unplanned downtime by 30 percent by 2027.
The definition of done
The category's deepest change is in what counts as finished. Vulnerability management measured success by vulnerabilities patched. Exposure assessment measures success by risk reduction outcomes.
The difference sounds semantic and is structural. Under the old definition, a team that patched a thousand dead-end CVEs looked productive. Under the new one, the same effort is waste, and the platform's job is to make the waste visible before it happens. The vendor that tracks the exposure through remediation to the reduced risk is selling the new definition, and the quadrant is scored around it.
The definition of done moved from patches to outcomes, and the market's vendors are being re-scored against the move.
The incumbents and the natives
The report's market split, described in the coverage around it, is the field's defining tension: legacy incumbents bolting exposure features onto existing scanning engines, against native exposure management players who modeled attacker behavior from the start.
The split matters because the dead-end finding indicts the incumbents' core engine. A scanner built to find everything is structurally oriented toward the 74 percent; retrofitting access-path analysis onto it is harder than building the path model first. The natives' advantage is the attacker's perspective as the founding architecture, and the quadrant's first edition is the market's first public scoring of the two approaches.
What the first edition leaves to the second
An inaugural quadrant has no placements to defend, and the market is moving faster than the chart. The Brinqa acquisition of PlexTrac, announced in August 2026, consolidated two of the field's recognized vendors months after the edition published, which means the first scorecard is already describing a field that no longer exists in that formation.
The honest limit is the record: twenty vendors were evaluated, a handful of placements are publicly confirmed, and the full field remains in the report itself. The midmarket companion is the buyer's other necessary read, because the criteria that serve a large enterprise security team do not transfer cleanly to a lean one.
Four questions for the security buyer
Can the platform show the attack path, not just the vulnerability? The dead-end distinction is the category's whole point. Ask for a live demonstration of an exposure traced to a critical asset, with the path drawn, on your own environment.
What counts as done in the contract? If the vendor's reports count patches, you are buying the old definition with the new name. Demand risk reduction outcomes with the measurement attached.
Where does identity fit? The criteria include identity layers, which is where most real attack paths now run. Ask how credentials, entitlements, and access paths are modeled alongside the vulnerabilities.
Is the platform native to the path model or retrofitted? The incumbent-native split is the field's deepest difference. Ask how the access-path analysis was built, and let the architecture question surface in the demo's edge cases.
Analyst Source
Gartner Magic Quadrant
Category definition, vendor inclusion, and quadrant placement in this article draw on the inaugural Magic Quadrant for Exposure Assessment Platforms, published November 10, 2025, authored by Mitchell Schneider, Dhivya Poole, and Jonathan Nunez, evaluating twenty vendors. The category replaces the Market Guide for Vulnerability Assessment and is built around continuous threat exposure management. Confirmed placements include Tenable as a Leader, NopSec as a Visionary, and Brinqa and PlexTrac in the field. Gartner's data shows 74 percent of identified exposures are dead ends and legacy teams spend roughly 90 percent of remediation effort on them, and projects a 30 percent reduction in unplanned downtime by 2027 for platform adopters. The companion Midmarket Context report published January 5, 2026.
Source research
Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.
A closely related read is IT Service Management Platforms. Gartner's ITSM quadrant just returned after a multi-year hiatus to a market that grew to nearly 9 billion dollars while it was gone, and its new criteria treat a unified data fabric as a prerequisite for AI, not a bonus feature.
This market sits next to Vulnerability Risk Management, covered separately on this site. Forrester's final scorecard under this retired category name crowned a scanner and a remediation orchestrator as joint Leaders, which is the market announcing its own successor before the rename made it official.