Between the last edition under this market's old name and the first edition under its new one, the two Leaders of the old name merged. Forrester's predecessor category, Vulnerability Risk Management, crowned Tenable and Vulcan Cyber as its final Leader pair in Q3 2023. In early 2025, Tenable bought Vulcan Cyber, and the category renamed itself to match what the transaction did: Unified Vulnerability Management Solutions.
The new name is a job description. Forrester defines the category as a centralized repository that "empowers security and risk professionals to coordinate appropriate actions and drive tactical risk reduction with greater efficiency and clarity." Unified means one book of record for vulnerabilities, one place where findings from every scanner, agent, and security tool land, and one pipeline where response is orchestrated and remediation tracked until the fix is closed. The old name scored the risk. The new name scores what happens after.
What the name promises
The definition deserves a careful read, because the word unified carries the whole category.
Forrester's announcement separates UVM from its neighbors explicitly. Exposure management and continuous security testing emphasize visibility and prioritization. UVM exists because those practices neglect the third principle of proactive security: remediation. The centralized repository is the promise. Findings from endpoint agents, network scanners, SecOps systems, cloud and application tooling converge in one place. Then the platform coordinates who fixes what, tracks it, and reports progress to whoever owns the risk.
Two shifts define the field. Data sourcing moved toward existing tools: organizations keep their scanners and agents and expect the platform to ingest from them, rather than the platform shipping its own sensors. And prioritization moved beyond CVE scores toward attack path analysis, exploitability validation, and commercial threat intelligence beyond public feeds like CISA KEV. Both shifts assume the hard problem is no longer finding things. The hard problem is the queue.
The merged scorecard: The Forrester Wave: Unified Vulnerability Management Solutions, Q3 2025
The first UVM Wave, published July 2025 and announced July 29 by Senior Analyst Erik Nost, evaluates ten providers across current offering, strategy, and customer feedback.
Two Leader placements are publicly confirmed.
Tenable took the highest strategy score of the field, with five-out-of-five marks in seven criteria including vision and roadmap, and top scores for breadth of assets supported, exposure assessment and prioritization, reporting, and benchmarking. Forrester's line is the continuity line: Tenable "continues to extend its established vulnerability management offerings into exposure management" through Tenable One. It also credits flexible asset-ratio-based pricing and a roadmap built around remediation orchestration. The roadmap matters, because it is where the Vulcan Cyber acquisition lands: the fixer Tenable bought is now the orchestration layer it sells.
Armis took the highest current-offering score, on the strength of its Centrix platform's VIPR prioritization and remediation offering. Top marks in data normalization, customizations, vulnerability risk scoring, response augmentation, innovation, and roadmap. Forrester positions Armis as "an excellent fit for either beginner organizations starting their proactive security journey or mature organizations that need leading vulnerability response capabilities." Armis was not in the Q3 2023 VRM field. Its first appearance in this research stream is a Leader placement with the highest current offering.
Two routes to the same destination, and the scorecard rewarded both.
The Strong Performers and what they confirm
Three Strong Performer placements are publicly confirmed, and together they describe what the category values under the Leader tier.
Rapid7 took the highest possible scores in community, pricing flexibility and transparency, and data normalization, with Forrester describing it as "best for organizations looking for a cost-effective strategic partner that can support proactive and reactive security programs." The community score nods to Metasploit and Rapid7's open-source pedigree. The data normalization score is the more telling one: in a category built on ingesting everyone else's findings, normalizing them is the product.
Nucleus Security is cited for an "open, transparent data model" with "no black-box inputs," well-integrated exception management, and a customer-driven roadmap. Forrester calls it "a good fit for enterprises with modern vulnerability management teams that need a data fabric to facilitate vulnerability prioritization and response." Nucleus was a Contender in the final VRM edition. Its promotion to Strong Performer under the new name is evidence that the rename is not cosmetic: a data-fabric specialist moved up when the scorecard started scoring unification.
CrowdStrike is publicly reported as a Strong Performer, extending its Falcon platform's endpoint and cloud security into unified vulnerability management. The remaining five placements sit with Forrester clients.
Read the confirmed field as a map. The two Leaders are a continuity play and an entry play. The Strong Performers include a platform-security giant, a data-fabric specialist, and an open-source-rooted incumbent. Every confirmed placement is a vendor answering the same question differently: what do you do once the findings arrive.
The deal that renamed the market
The category's origin story is a transaction, and it is worth telling precisely.
Tenable announced its acquisition of Vulcan Cyber in early 2025, closing by the end of March. The price was roughly one hundred forty seven million dollars in cash plus three million in restricted stock units, for a business with about twenty five million in annual recurring revenue and around one hundred enterprise customers. Forrester's own analysis of the deal is the clearest statement of what unification means in money: Tenable bought Vulcan's third-party connector ecosystem and its application security posture management capabilities, to pull in vulnerability sources from SAST, DAST, and cloud security providers and improve remediation workflows. The scorer bought the fixer.
Then SAFE, a cyber risk quantification vendor, acquired Balbix, a 2023 VRM Strong Performer, for its asset intelligence and prioritization engine.
Two acquisitions, two directions: the vulnerability incumbent buying remediation, and the risk-quantification vendor buying vulnerability intelligence. Both deals are the market defining itself by transaction. When Forrester renamed the category months later, the word unified was already priced into the balance sheets.
The ticket-shaped reality
The honest half of the new report is Forrester's own list of what stayed the same.
Remediation remains a persistent challenge. UVM solutions can initiate and monitor workflows, but they cannot fix broken processes. Organizations still need strong patch management and committed remediation owners. Many teams still track response in ITSM platforms. Automation such as auto-patching remains underutilized, and most organizations favor automated ticket creation over fully automated remediation.
A unified tool ends where the ticket begins. The scorecard grades the platform's capability to orchestrate the fix. The deployment reality, by Forrester's own description, is a ticket created automatically and closed by hand. The category's entire premise, one pipeline from finding to fix, is true on the vendor side and aspirational on the buyer side. Every score in this Wave measures the offer. None of them measures your organization's willingness to adopt the automation the offer assumes.
That is not a knock on the vendors. It is the precise reason to read the scorecard as a direction of travel, not a description of your present state. If your shop still runs a scanner and a spreadsheet, the UVM scorecard is grading a destination you have not reached.
Where this sits next to Gartner
Gartner named the same market with a different word.
Where Forrester says unified, Gartner says exposure: it retired the vulnerability-management framing and now publishes a Magic Quadrant for Exposure Assessment Platforms, in which Tenable also announced a Leader placement in 2025. Forrester treats continuous exposure as a neighboring practice that neglects remediation. Gartner folds it into the same quadrant. Same market, two catalogs, different exclusions.
For a buyer this decides vocabulary. Vendor marketing will quote whichever catalog ranks it higher. Your team will inherit one framing for RFP language, internal metrics, and board reporting. If your organization runs on exposure language, Gartner's definition is yours. If it runs on remediation pipelines, Forrester's is. Decide before you trust the quotes.
Three questions for the unified buyer
One: which route fits your estate? Tenable is the continuity play, the incumbent extending outward, now with the acquired fixer inside its roadmap. Armis is the response-first entry that arrived at the top of current offering. If your estate already runs the incumbent's scanners, continuity compounds. If your bottleneck is a backlog of findings nobody owns and you are vendor-neutral, response-first matters more than pedigree.
Two: what does unification stop at in your organization? Forrester says most organizations stop at the automated ticket. Ask every shortlisted vendor for reference deployments with fully automated remediation, and be equally honest about whether your own change-control culture would ever allow auto-patching. The score assumes adoption the market does not have. Your contract will live where your culture actually is.
Three: who owns your book of record in five years? In a market consolidating this fast, the acquisition question outranks the tier question. Ask each shortlisted vendor the same question you would ask of their balance sheet: who buys you, and what happens to the repository when they do.
Analyst Source
Forrester Research
This article is built on The Forrester Wave: Unified Vulnerability Management Solutions, Q3 2025, published July 2025 and announced July 29, 2025 by Senior Analyst Erik Nost, evaluating ten providers on current offering, strategy, and customer feedback. Forrester defines UVM as a centralized repository that empowers security and risk professionals to coordinate appropriate actions and drive tactical risk reduction, unifying remediation across systems and teams as the primary book of record for vulnerabilities. The category renames The Forrester Wave: Vulnerability Risk Management, Q3 2023 (covered separately as the old category), which followed the Q4 2019 VRM Wave. Market context includes Forrester's analyses of the Tenable acquisition of Vulcan Cyber and the SAFE acquisition of Balbix. Gartner covers the adjacent market as the Magic Quadrant for Exposure Assessment Platforms.
Source research
- The Forrester Wave: Unified Vulnerability Management Solutions, Q3 2025
- Announcing The Forrester Wave: Unified Vulnerability Management Solutions, Q3 2025 (Forrester blog, Erik Nost)
- Tenable To Acquire Vulcan Cyber: More Consolidation In The Vulnerability Management Market (Forrester blog)
- SAFE Acquires Balbix (Forrester blog)
- Tenable press release: named a Leader in Unified Vulnerability Management Solutions
- Armis: named a Leader in The Forrester Wave: Unified Vulnerability Management Solutions, Q3 2025
- Rapid7 blog: named a Strong Performer in the 2025 Forrester Wave for Unified Vulnerability Management
- Nucleus Security: named a Strong Performer in the 2025 UVM Solutions report
Forrester does not endorse any vendor named here, and tier placement should not be read as a recommendation to buy.