Three editions carried this category name. Forrester published the third in September 2023, and then walked away from the name itself. That third edition, The Forrester Wave: Vulnerability Risk Management, Q3 2023, is the scorecard this article is about. It is the last time Forrester evaluated this market under the name you are shopping by, and it reads like a farewell.
The name retired. The market did not. In July 2025 Forrester came back with the same research stream under a new title: Unified Vulnerability Management Solutions. But the last VRM scorecard still stands on its own as a record of what this category was, what it rewarded, and who was winning it when the name was retired. That is what matters for a buyer holding this category name in their shortlist: you need the final edition, read honestly, not the successor's scorecard retrofitted onto it.
What the category was scoring by 2023
Vulnerability Risk Management, as Forrester defined it in its final edition, is the discipline of finding weaknesses that could lead to a breach, scoring them against the assets they sit on, and deciding which fixes happen first.
The 2023 announcement blog sets out three trends that defined the category at the end. First, asset visibility and vulnerability risk: every evaluated solution took an asset-centric approach to risk scoring, and the buyer's decision was which asset types are in scope, from operational technology to cloud workloads, and whether to buy one tool for everything or point solutions per asset class. Second, remediation prioritization: this is where the vendors differentiated hardest, on threat intelligence, asset contextualization, and compensating controls, and buyers chose between customized risk scores and out-of-the-box ones. Third, vulnerability response: every vendor supported ITSM integrations, and differentiation came down to automation, customizability, and emergency handling of headline vulnerabilities, which Forrester says "can make the difference between a breach or non-event."
Read that last trend and you can see the rename coming. The category already knew the fix was the hard part. It just had not renamed itself around it yet.
The last edition under this name: The Forrester Wave: Vulnerability Risk Management, Q3 2023
The final VRM Wave, announced September 21, 2023 by Senior Analyst Erik Nost, evaluated eleven vendors. The field, tier by tier:
Leaders: Tenable and Vulcan Cyber.
Strong Performers: Microsoft, Brinqa, Balbix, NopSec, Rapid7, and Qualys.
Contenders: Cisco, Nucleus Security, and Skybox Security.
Tenable was the top-ranked vendor, holding the highest position in both strategy and current offering, with five-out-of-five marks on fourteen criteria including vision, roadmap, and innovation. In a category built on scoring risk, the incumbent scorer scored highest at scoring.
Vulcan Cyber is the more interesting name, because it explains the category's fate. Vulcan is not a scanner. It is a remediation orchestration platform that ingests findings from scanners and turns them into prioritized, owned, trackable fixes. Its Leader placement in the final VRM edition is the market saying, in tier form, that the bottleneck had moved. Finding vulnerabilities was solved. The queue of unfixed findings was the problem. The category died of its own success: once everyone scores risk, the name stops differentiating.
The 2019 edition and its thirteen vendors
The final edition is easier to read with its predecessor in view.
The Forrester Wave: Vulnerability Risk Management, Q4 2019, published October 17, 2019 by Josh Zelonis and Trevor Lyness, evaluated thirteen vendors across fourteen criteria, grouped into current offering, strategy, and market presence. The inclusion bar was high: annual product revenue above ten million dollars with double-digit growth, the VRM product making up more than half of firm revenue, at least one hundred enterprise customers, and demonstrated product improvement over the prior two years. The report's organizing line was that "prioritization and reporting are key differentiators."
The Leaders were the traditional vulnerability management big three: Tenable, Rapid7, and Qualys. Strong Performers: Kenna Security, NopSec, RiskIQ, Expanse. Contenders: Digital Defense, Brinqa, RiskSense, RedSeal, Skybox Security. Challenger: Outpost24.
Much of that roster was gone before the next edition could re-measure it. Kenna went to Cisco. RiskIQ went to Microsoft. Expanse went to Palo Alto Networks. RiskSense went to Ivanti. Digital Defense went to HelpSystems. The 2023 announcement names mergers first among the reasons the market looked so different, ahead of the CVE volume explosion and Log4j.
The Big Three's breakup
Set the two editions side by side and the final VRM scorecard records the end of an era.
In 2019, three scanner incumbents led. In 2023, two of them sat in the Strong Performer tier, and a remediation orchestrator nobody would have called a VRM vendor in 2019 joined the incumbent on top. Cisco, having bought Kenna Security, landed in the Contender tier with Nucleus Security and Skybox Security. Microsoft entered as a Strong Performer. The eleven names of 2023 do not form the same market as the thirteen of 2019. They form the same market in the middle of being redefined around its bottleneck.
Tenable's arc deserves separate attention because it is the exception that proves the rule. Highest overall score in 2019. Top-ranked in both dimensions in 2023. The one vendor that survived the redefinition without leaving the Leader tier did it by stretching the same asset: a scanning and scoring platform that keeps widening, from vulnerability management toward exposure. Two of the three names that defined this market in 2019 did not stay Leaders. The third never stopped.
The name it took next
Where the market went is not a mystery. It went toward the fix.
In July 2025 Forrester published The Forrester Wave: Unified Vulnerability Management Solutions, Q3 2025, again authored by Erik Nost, evaluating ten providers. The category's center of gravity moved from risk scoring to remediation unification: a centralized repository for findings, orchestration of response, tracking of remediation progress, attack path analysis, and workflow automation. Third-party ingestion from existing scanners and agents became standard. The old category's final edition predicted exactly this. Its third trend, vulnerability response, became the new category's whole name.
Two placements from the successor are worth noting for anyone carrying this old shortlist forward. Armis, which was not in the 2023 VRM field at all, took the highest current-offering score in the 2025 UVM edition. And Tenable led on strategy, with Forrester noting it "continues to extend its established vulnerability management offerings into exposure management." The 2023 scorecard's central insight, that the bottleneck moved to the fix, was confirmed by the rename. It was also confirmed by the fact that a response-first vendor could enter the successor market at the top of its current offering on first appearance.
The shelf life of a retiring scorecard
The honest limitation of this article's subject is simple and specific.
A scorecard of a retired market definition is a historical document. The Q3 2023 VRM Wave answers one question precisely: who was strongest at vulnerability risk management in late 2023, under that name. It does not tell you who to buy today. Criteria changed when the category renamed itself. A vendor ranked in 2023 could be absent from the successor field, or present under different scoring, as Armis's trajectory shows in reverse. The 2023 tiers do not transfer to the new definition, and no vendor will tell you that.
But the historical document still carries two things the successor scorecard cannot give you. It records which vendors were winning while the market was still called what you are buying. And it records the mechanism of the rename itself: the Leader pair of the final edition, a scorer and a fixer, is the clearest available evidence of where the market's value actually moved. Use the old scorecard for those two things, and nothing more.
Three questions for the last scorecard
One: which half of the final Leader pair is your actual problem? If your pain is visibility and scoring across assets, the 2023 scoring half is your side of the ledger. If your pain is a backlog of known findings nobody owns, the fixer half is, and that side of the market is where the category moved. The 2023 pair maps the fork more honestly than either scorecard's marketing does.
Two: how much of the 2023 field still exists in scored form? Mergers consumed a large slice of the 2019 roster before 2023, and the same force has not stopped. Ask every shortlisted vendor who owns them now and what the acquirer's roadmap does to the product you evaluated. Tiers describe a vendor at a moment. Ownership rewrites the vendor.
Three: are you buying the old category or the new one? If your RFP says vulnerability risk management, you are buying a definition Forrester retired. If what you need is unified remediation, the successor report is the scorecard to consult. Decide which question you are asking before you let any tier answer it, because the 2023 edition can only answer the first.
Analyst Source
Forrester Research
This article is built on the final Forrester evaluation of this category under its own name: The Forrester Wave: Vulnerability Risk Management, Q3 2023, announced September 21, 2023 by Senior Analyst Erik Nost, evaluating eleven vendors across asset-centric risk scoring, remediation prioritization, and vulnerability response. It follows The Forrester Wave: Vulnerability Risk Management, Q4 2019 (thirteen vendors, fourteen criteria, by Josh Zelonis and Trevor Lyness), with the companion Vulnerability Risk Management Landscape published in Q2 2023. Forrester has since retired the category name: the successor is The Forrester Wave: Unified Vulnerability Management Solutions, Q3 2025, covered here only as the destination the market moved to.
Source research
- Announcing The Forrester Wave: Vulnerability Risk Management, Q3 2023 (Forrester blog, Erik Nost)
- Announcing The Vulnerability Risk Management Landscape, Q2 2023 (Forrester blog)
- Tenable blog: named a Leader in Vulnerability Risk Management (2023 edition)
- Announcing The Forrester Wave: Unified Vulnerability Management Solutions, Q3 2025 (successor category, Forrester blog)
- Armis: named a Leader in the successor UVM evaluation, Q3 2025
- The Forrester Wave: Vulnerability Risk Management, Q4 2019 (vendor-licensed copy)
Forrester does not endorse any vendor named here, and tier placement should not be read as a recommendation to buy.
The related category on this site is Exposure Assessment Platforms. Across 15,000 environments, Gartner found that 74 percent of flagged vulnerabilities are dead ends no attacker could ever reach, and legacy teams still spend 90 percent of their patching effort chasing them anyway.