REPORT

Sonatype named as a Leader in Leadership Compass:

Software Supply Chain Security Report

We’re pleased to share that Sonatype is named as a leader in the 2026 KuppingerCole Leadership Compass: Software Supply Chain Security report. 

The report delivers an independent assessment of the software supply chain security market, evaluating leading vendors on product, innovation and market strength.

It examines how well solutions help organisations secure the software development lifecycle through visibility, risk management and vulnerability mitigation, while also highlighting market trends and providing guidance for buyers.

The report covers some key themes:

  • Visibility Challenge: The attack surface has expanded beyond proprietary code to include open source, build systems, CI/CD pipelines and third-party artefacts. The biggest challenge is that many organisations still don't know what's in their software or where it came from.
  • Regulatory Expectations: SBOMs are no longer a ‘nice-to-have’ to regulatory expectation, driven by the US Executive Order and the EU Cyber Resilience Act. Most organizations are still at the compliance stage.
  • Speed: AI-generated code is the immediate pressure. More code, more dependencies pulled in uncritically, and a new provenance risk where AI suggests packages that do not exist, creating slopsquatting targets. Controls designed for human-paced review need rethinking.
  • Market Consolidation: The market is consolidating, with SCA, SAST, secrets scanning and posture management folding into ASPM platforms. Consolidation helps where it unifies context across the SDLC, and not where it is a dashboard over the same disconnected scanners.
2026_LC-logo-black

Download the Report

Do business with a leader

Book a Demo