Gartner published its first Magic Quadrant for Software Supply Chain Security on 17 June 2026, evaluated eighteen vendors, and placed eight of them on the Leader rung. The analysts credited are Aaron Lord, Johnny Walters and Jason Gross, and the market is defined as of May 2026, which puts the report's frame almost exactly a year behind the point at which most large engineering organizations started buying this software.

Eight Leaders out of eighteen is not a ranking. It is a statement about how young the category still is.

The inaugural Magic Quadrant for Software Supply Chain Security, and the field it drew

The eighteen vendors, as the placements have surfaced: Apiiro, Black Duck, Chainguard, Checkmarx, Cycode, JFrog, Sonatype and OX Security on the Leader rung, with ActiveState, Arnica, Endor Labs, FOSSA, GitHub, Lineaje, Mend.io, RapidFort, Reversing Labs and Veracode named in the evaluation as well.

Seven of the eight Leaders have announced the placement themselves. JFrog reported being positioned highest for Ability to Execute across the whole field, and Chainguard reported being placed furthest right for Completeness of Vision, which means the two axes of the first quadrant are held by two different companies. Black Duck, Checkmarx, Cycode and Sonatype also confirmed Leader placements, and the Gartner reprint identifies OX Security as a Leader directly. A published tally of the quadrant adds Apiiro to the same rung; Apiiro has not announced the placement itself, so it is listed here with that single source noted rather than asserted.

The shape of the field matters more than the names. Half the vendors on the Leader rung did not exist as independent companies when Forrester last scored the nearest equivalent market, and the rest arrived at supply chain security from four different starting points: artifact repositories, open source dependency scanning, application security testing, and pipeline security.

Eight Leaders in a first edition is a statement about the category, not the vendors

A mature Magic Quadrant typically puts three to five vendors on the top rung. The endpoint protection quadrant this site covers names four. The hybrid mesh firewall quadrant names three. A first edition that names eight is doing something different, and what it is doing is buying coverage.

An analyst firm drawing a new category boundary has to decide who is inside it, and in a first edition the safer commercial and analytical choice is to include rather than exclude. The vendors on the rung are not equivalent products. They are the vendors that satisfied an inclusion threshold in a market Gartner is describing for the first time, and the criteria that separate them will only become visible in the second edition, when the field has stabilized and the report has a before and after to grade.

This is worth saying plainly because the marketing around an inaugural quadrant flattens the distinction. Eight companies will describe themselves as a Leader in the Gartner Magic Quadrant for Software Supply Chain Security, and all eight statements will be accurate. The buyer's problem is that they are not yet informative.

Forrester has been grading a slice of this since 2021 under a narrower name

This site covers the Forrester side of this ground at Software Composition Analysis, which is the Q4 2024 Wave and the successor to a 2021 edition. Software composition analysis grades the open source dependency: which libraries are in the build, which of them carry known vulnerabilities, and what the license obligations are.

That is a real market and a real budget line. It is also a subset. Software supply chain security covers the dependency plus the container image, the build pipeline, the artifact registry, the signing and attestation chain, and the provenance record that ties all of them together. Gartner's eighteen-vendor field reflects that wider perimeter, and several of its Leaders are companies that software composition analysis buyers would not have considered five years ago.

The two names are not competing labels for one thing. They describe two perimeters, one inside the other, and a buyer who reads only the Forrester document will come away with a complete picture of a smaller market.

The supply chain now includes models, and three Leaders say so

The most consequential change in the definition is the one that arrived from outside software. An application built in 2026 consumes models alongside libraries, and a model is an artifact with provenance, versioning, license terms and failure modes of its own.

Black Duck's announced strengths include AI model risk insights and AI-driven dependency remediation. Checkmarx's platform is described as spanning software composition analysis, container security, malicious package detection, secrets detection, SBOM management and AI supply chain security. Cycode's platform is described as actively discovering and enforcing policies that govern the use of AI components. Three of the seven vendors that announced placements chose to lead with the AI component as a supply chain problem, which is a stronger signal about where the category is heading than any of the criterion scores.

The practical version of this is that the inventory a supply chain platform produces now has two kinds of entry. A library has a version, a license and a vulnerability history. A model has a version, a license, a training data provenance claim and a behavioral profile that changes when the vendor updates it. Few of the eighteen products in this quadrant handle the second kind as well as the first, and the one that does will be visible in the next edition rather than this one.

What the eighteen-vendor field leaves out

Three gaps are worth naming.

The first is runtime. Everything in this quadrant grades the software before and during the build. What a compromised dependency does after deployment is a detection and response question, and it belongs to a different evaluation on this site rather than to this one.

The second is the platform vendors. GitHub is in the field and the two largest cloud application platforms are not, which reflects the revenue and reference thresholds Gartner applies rather than a capability judgment. A buyer whose entire build runs inside one cloud provider's native toolchain may find that the most consequential supply chain controls are already included in a subscription they are not evaluating here.

The third is the second edition. Every placement in this document is a first data point, and the vendors know it. The interesting question is which of the eight Leaders holds the rung when there is an earlier edition to compare against.

What to ask before you buy a supply chain security platform

Ask which artifact types the inventory actually covers, and get the answer as a list. Libraries, container base images, build tools, infrastructure as code, models and prompts are six different inventories, and most products cover three of them well.

Ask what the platform does when it finds a problem rather than when it detects one. Detection is now table stakes across all eighteen vendors. The differentiation in this category is remediation: whether the platform can open the right pull request, propose the version bump, and validate that the fix built.

Ask how the provenance record is produced and where it is stored. Attestation only matters if the record survives the pipeline and can be verified later by someone who was not there when the build ran.

Ask what happens when the model provider ships a silent update. This is the question the 2026 edition raises and does not answer. A dependency change produces a new version number and a diff. A hosted model update produces neither, and the supply chain controls that assume a version number will not see it.

Ask whether the evaluation you are reading is a first edition. In this category it is, for both firms, and a first edition tells you who is present. It does not yet tell you who is better.

Analyst Source

Gartner Magic Quadrant

Category definition, vendor inclusion, and quadrant placement in this article draw on Gartner's coverage of software supply chain security, evaluated in the Magic Quadrant for Software Supply Chain Security, published 17 June 2026, covering eighteen providers on the Ability to Execute and Completeness of Vision axes, authored by Aaron Lord, Johnny Walters and Jason Gross, with the market defined as of May 2026. This is the first Magic Quadrant Gartner has published for this category. Leader placements named here are drawn from vendor announcements and from the Gartner reprint: JFrog reported the highest position for Ability to Execute, Chainguard reported the furthest position for Completeness of Vision, and Black Duck, Checkmarx, Cycode, Sonatype and OX Security have confirmed Leader placements. Apiiro appears on the Leader rung in a published tally of the quadrant and has not announced the placement, so it is named with that limit stated. Forrester evaluates a narrower slice of this ground in The Forrester Wave: Software Composition Analysis, Q4 2024, which followed its 2021 edition.

Source research

Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

The adjacent Gartner quadrant is DevSecOps Platforms, the June 2026 Magic Quadrant for the delivery pipeline itself. Its four-Leader field and this report's eight overlap at the point where a pipeline control becomes a supply chain control, which is artifact signing and provenance. Both quadrants were published inside the same month, and neither grades the other's core question.

The testing layer underneath is graded separately by Forrester at Application Security Testing Platforms. The split between that evaluation and this one is where the money is: testing finds the defect in code the organization wrote, and a supply chain platform finds the defect in code somebody else wrote. Most large buyers now fund both from the same budget line, which is why the vendors on these two lists have started acquiring each other.