The analyst who wrote the current Forrester Wave on this market opened his announcement of it by quoting a joke. James Plouffe writes that vendors and security leaders have told him "some version of a joke about how starting a microsegmentation project is a great way to get fired."

He is not being flippant. A few paragraphs later he describes microsegmentation as a market that has "moved aggressively to carve out a niche that addresses emerging threats, as well as the implementation challenges that, facetiously or otherwise, caused microsegmentation to be viewed as a catalyst for career moves."

That is the 2026 edition's real subject. The joke describes a specific failure, and the evaluation now scores vendors on how well they prevent it.

From prevention to breach readiness

Microsegmentation spent a decade being sold as prevention: divide the network so that a compromise in one place cannot reach another. The current generation still does that, and it has added a second proposition that is more honest about how incidents actually go.

The 2026 report states the case for containment directly. Forrester's argument is that patching has become a second-order remediation, and in some systems is not possible at all, so containment is the only viable option left. The shortest path to making containment feasible, without rebuilding infrastructure, is "enforcement that is decoupled from network topology." That is what these products do.

The 2024 edition carried a similar theme through vendor capabilities, crediting Illumio for letting an operator run incident response activities during an attack, including quarantine, mass quarantine, and live recovery. Live recovery is the striking one. Restoring systems while an adversary is still present, in a segmented environment where the restored systems are protected from re-infection, is a materially different situation from the traditional sequence of contain, eradicate, then rebuild.

ColorTokens' stated strategy is still to make customers breach ready, which remains a different promise from keeping attackers out and a more defensible one. Breach ready accepts the premise that the breach happens.

The compliance argument has strengthened too. The report notes that more regulations now include implicit or explicit requirements for Zero Trust in general and network segmentation in particular, up to mandating its use, and that the products decouple access controls from network topology while also producing "the reporting necessary to produce evidence of compliance." That last clause matters more than it reads. A segmentation mandate is only satisfiable if someone can demonstrate the segmentation exists.

The same four Leaders, two years apart

The Q3 2026 edition names four Leaders: Illumio, Akamai Technologies, ColorTokens, and Cisco.

Those are the same four vendors the Q3 2024 edition named as Leaders. Two years, two evaluations, and the top of the chart did not move.

The field beneath it did. The 2024 report scored eleven providers. The 2026 report scores ten. Two of the 2024 names, TrueFort and Hillstone Networks, are not in the new edition. One vendor is new to it: Zscaler, which acquired Airgap Networks in 2024 and added agentless east-west segmentation for on-premises networks to a portfolio built around secure access and Zero Trust network access. Eleven minus two plus one is ten, and that is the whole of the change in membership.

The reason the field is this size is stated in the inclusion criteria, and it is not a judgement about capability. To be scored, a vendor needs at least 40 million dollars in annual revenue from the microsegmentation product in the last four quarters, a generally available solution that applies network access control at the level of individual hosts or devices, and enough mindshare that Forrester's clients keep naming it. Vendors whose business is exclusively or primarily in one region are excluded, as are vendors focused on specific non-IT verticals.

Read those together and the shape of the market is explained. This is a category where a working product and a real customer base are not sufficient to be scored. The report points readers to The Microsegmentation Solutions Landscape, Q1 2026 for the fuller field, and the distance between a landscape and a Wave is a revenue threshold rather than a verdict on the software.

Inside The Forrester Wave: Microsegmentation Solutions, Q3 2026

Ten providers are scored across current offering, strategy, and customer feedback. Customer feedback appears as a halo on the vendor's marker, with a double halo marking a Customer Favorite, the designation for the vendor whose reference customers were most positive.

The Leaders are Illumio, Akamai Technologies, ColorTokens, and Cisco. The Strong Performers are Elisity, Zero Networks, and Hewlett Packard Enterprise. The Contenders are Zscaler, Broadcom, and ORDR. The scored products are Illumio Breach Containment Platform, Akamai Guardicore Segmentation, Xshield Enterprise Microsegmentation Platform, Cisco Secure Workload 4.0.2, Elisity Identity-Based Microsegmentation Platform, Zero Networks Segment, HPE Aruba Networking Central, Zscaler Zero Trust Exchange, VMware vDefend 9.1, and ORDR AI Protect for Segmentation.

Illumio is a Leader, is named a Customer Favorite, and reports the highest scores of any vendor in both the current offering and strategy categories. Forrester's summary says it "excels at essential microsegmentation functions," supports a rich mix of agent-based and agentless methods across hybrid cloud, data centers, containers, endpoints, and operational technology, and automatically creates labels for use in policy.

Read that against what the same pages said two years ago. In 2024 Forrester called Illumio the original microsegmentation specialist, described its interface as the most powerful evaluated, and credited it with maximum scores in sixteen of twenty three criteria. In 2026 the report says the interface "is very dense and may be overly detailed for some users," that OT and IoT support is "on par but not as strong as vendors with more direct focus in this area," that the roadmap "will have to reframe table-stakes functionality to compete in adjacent markets," and that the pricing model "may result in higher costs for legacy workloads."

None of that displaces a Leader that holds the highest scores on both axes and the customer halo. It does describe a different position from the one the 2024 report described. Leading this category now means being good at the essentials while others differentiate above and below you.

Akamai is a Leader on the strength of flow data. Its large corpus of network data produces strong flow enrichment, which feeds policy administration across the entire policy lifecycle, from creation through testing, enforcing, fine-tuning and retiring, and anchors an administrative experience that requires minimal pivoting. Its constraint is the on-premises agentless path: it requires either DPU-based switches or PacketFence NAC, and the latter "adds deployment complexity and makes the solution less well suited to addressing the microsegmentation requirements of IoT/OT."

ColorTokens is a Leader and the report credits it with "some of the most flexible deployment options of any vendor." It runs on its own Xshield agent, on existing endpoint detection and response agents, or agentless, and it takes an iterative approach in which policies are proposed, simulated and refined before enforcement. The constraints named are narrower: a bug bounty program "not as robust as others," a community that is "somewhat less structured and active," and customer concerns about deploying its Gatekeeper appliance.

Cisco is a Leader because it owns the infrastructure underneath. Secure Workload is positioned as a hybrid agent-based and agentless solution using host-based hooks including eBPF, DPU-based switches, firewalls, application delivery controllers and load balancers, and Kubernetes clusters, which the report says translates to "superior enforcement in on-premises and cloud-native network environments." Its exposure reporting is more limited than other vendors', and its execution is partly constrained by the ongoing integration of technology from its acquisition of Isovalent.

Among the Strong Performers, Elisity is the fully agentless option, using existing network hardware as the enforcement point without replacing it, with a simple pricing model Forrester calls a differentiator and strong results in healthcare, OT and IoT. Its cloud-native enforcement is less mature and its lack of direct endpoint visibility weakens threat detection and response. Zero Networks scores well on administrivia: automated policy generation, a good mix of prebuilt compliance and audience-specific reports, and multi-factor authentication for privileged Layer 3 and Layer 4 access, with a narrower ecosystem and less formalized services. Hewlett Packard Enterprise is scored on its Aruba networking portfolio and an open-standards approach, with public cloud and cloud-native enforcement not available at all.

One line in the methodology is worth pausing on. Hewlett Packard Enterprise declined to participate in the full evaluation process and did not provide reference customers. Forrester scored it anyway, using public information, briefings, independently sourced customer interviews, and where necessary estimates, and published its positioning alongside the vendors that did participate and provided references. That is how the process is designed to work, and it is also a reminder that a placement is an analyst's assessment of a vendor, not a vendor's submission about itself.

The Contenders carry the report's least flattering details, and its most useful ones. Zscaler brings the Zero Trust Exchange and the Airgap acquisition, with a containment workflow that enriches policies with "fire danger" style levels and a single kill switch that activates them, and integration with its own network access product that no other vendor can match. The report also says integration work currently outweighs new feature development and that it is "still playing catch-up to other vendors in many key areas," with cloud-native deployments limited to visibility.

Broadcom's VMware vDefend marries policy enforcement with threat detection and response in a way the report says most other solutions cannot or do not, and it replaces a conventional four-stage professional services engagement with product features that walk an administrator from assessment to full segmentation. Those benefits are limited to specific scenarios, the roadmap does not address campus networks or public clouds, and some customers reported difficulty exporting logs to their SIEM.

ORDR has asset discovery strong enough that other vendors in the evaluation use it as a technology partner, an enormous fingerprinting database, and a name for turning device intelligence into action. It is also the clearest statement of the report's central problem. Forrester writes that ORDR's approach "comes at the expense of addressing the most pressing problem in microsegmentation: time to value as measured by deployment speed and policy enforcement," that its interface is dense to the point of being difficult to read, and that its use of network access control for enforcement lengthened customer deployment timelines.

The gap between deployed and enforcing

Time to value as measured by deployment speed and policy enforcement is now Forrester's own phrase for the most pressing problem in the market. The gap between owning these tools and enforcing with them is no longer an observation a reader has to supply. It is a scoring axis.

Here is the pattern it names, and it remains the thing that determines whether a deployment delivers anything.

A great many run in monitoring mode indefinitely.

The sequence is familiar. The platform is installed, agents are deployed, flows are mapped, and policy is generated. The team reviews it, and someone asks what happens if a rule is wrong. The answer is that a business-critical application stops working, possibly at an unpredictable moment, and the cause will be difficult to identify quickly.

Nobody wants to own that risk. So enforcement is deferred to the next quarter, then to after the next major release, then to after the peak trading period. Meanwhile the environment changes, the policy ages, and the confidence required to enforce it declines rather than grows.

The organization now has excellent visibility into its network flows and no segmentation. That is the state the joke describes, and the reason the joke is about the person who started the project rather than the software.

Two things have changed since the previous edition. The first is that the vendors are now selling against the deferral. Akamai's stated innovation focus is an autonomous containment platform that requires less toil and expertise while improving the speed and accuracy of enforcement. Elisity's simple pricing and Zero Networks' low administrative overhead are framed the same way. ColorTokens proposes, simulates and refines policy before enforcement, which is an attempt to make approval safe enough to give. The market has concluded that the operator's confidence is the product.

The second is that the report says plainly what the delay costs. Its purchase guidance states that the time adversaries take to move laterally after an initial compromise has fallen sharply while times to investigate, respond and contain have not kept pace.

The practical countermeasures remain unglamorous, and the first of them has not changed. Start with a small number of high-value assets rather than the whole estate. Enforce in one direction before both. Use test-mode enforcement that logs what would have been blocked. And settle beforehand who is accountable for turning enforcement on, because in the absence of a named owner the default is indefinitely deferred.

That last point is still the one to settle before purchase. A microsegmentation platform bought without a decision about who will accept the enforcement risk is a visibility tool with an enforcement engine nobody will switch on, and the 2026 report has now put a number on how much that costs the vendor selling it.

The hard problem is knowing what should talk to what

Every capability above depends on somebody deciding which workloads are permitted to communicate, and that decision is where these deployments actually fail.

The information required does not exist in most organizations. Application documentation is stale or absent. The engineers who built the system have moved on. The dependency between two services is discovered when one of them stops working.

So microsegmentation begins with observation. The platform watches traffic, builds a map of what actually communicates with what, and proposes policy from observed behavior rather than from documentation. The report's own framing is that this effort helps "plumb the depths of technical debt," because the disconnect between network and security teams and the application owners who know how things actually work has always been profound, and automation is what closes it.

There is a second benefit in that framing which the earlier editions did not name. A dependency map is institutional knowledge, and the report points out that this is exactly the kind of knowledge that has "a habit of getting lost, buried, or forgotten." Every organization that has lost the person who understood a system has paid for it. A segmentation project is one of the few IT initiatives that produces a durable record of it as a byproduct.

The honest limitation has not moved either. Traffic observed over four weeks reveals the flows that occurred in four weeks. The quarterly batch job, the annual reconciliation, the disaster recovery test, and the vendor support connection used twice a year will not appear, and each will fail the first time it runs under enforcement.

Where this sits in zero trust

Forrester's 2026 position is blunter than the one the previous edition carried: any Zero Trust strategy without microsegmentation is incomplete.

The reasoning is specific. Zero Trust network access partly satisfied the requirement while most users were remote, but it was usually separate from data center segmentation and rarely covered campus networks, especially once employees returned to the office. Microsegmentation picks up where conventional network access leaves off, and is what makes policy enforcement coherent rather than partial.

That is accurate and it is worth being precise about which part. Zero trust removes implicit trust based on network location. Microsegmentation is how that principle gets applied to workload-to-workload communication, which is the traffic that dominates a modern data center and the traffic that lateral movement uses.

It sits alongside rather than inside the zero trust platform category Forrester evaluates separately, and the same caution applies to both: no product makes an organization zero trust, because the model is a framework combining technology and non-technology decisions.

The integration point that matters most is identity. Segmentation policy expressed in terms of workload identity rather than IP address survives infrastructure change, which is why identity became a policy input across every edition. An environment where addresses shift constantly, which describes any cloud deployment, cannot be segmented durably by network rules alone.

Which returns the category to where it started. The 2024 edition was about what these products had learned to do. The 2026 edition is about whether an organization can bring itself to let them do it, and it scores the vendors on how much of that decision they can take off the buyer's hands. Forrester naming the same four Leaders twice is the least interesting fact in it, and the analyst opening with a joke about getting fired is the most.

Analyst Source

Forrester Research

Category definition, vendor inclusion, and evaluation findings in this article draw on Forrester's coverage of microsegmentation, evaluated as an emerging market in The Forrester New Wave: Microsegmentation, Q1 2022, covering nine providers against 10 criteria, and scored in The Forrester Wave: Microsegmentation Solutions, Q3 2024, covering 11 providers against 23 criteria across current offering, strategy, and market presence, and again in The Forrester Wave: Microsegmentation Solutions, Q3 2026, authored by James Plouffe with three contributors. The 2026 edition scores 10 providers across current offering, strategy, and customer feedback, with customer feedback shown as a halo and a double halo marking a Customer Favorite. The four Leaders are Illumio, Akamai Technologies, ColorTokens, and Cisco, the same four the Q3 2024 edition named. Illumio is also the Customer Favorite. Inclusion requires at least 40 million dollars in annual revenue from the microsegmentation product in the last four quarters. Hewlett Packard Enterprise declined to participate in the full evaluation process and did not provide reference customers; Forrester scored it using primary and secondary research and published its positioning with the participating vendors. Vendors supplied evaluation materials by 26 May 2026. The Microsegmentation Solutions Landscape, Q1 2026 covers the wider market. Forrester evaluates zero trust platforms as a separate market.

Source research

Forrester does not endorse any vendor named here, and tier placement should not be read as a recommendation to buy.

Worth reading alongside Operational Technology Security Solutions: the specialist that publicly challenged Forrester's framing in 2024 is now a Leader with the highest strategy score, and the 2026 edition says discovery no longer separates these vendors.