Map Before You Buy: The 2026 Identity Market After the Consolidation Wave
The identity market consolidated in 2026, from Palo Alto Networks closing CyberArk to four NHI startups changing hands in ten weeks. The Identity Map sorts 255 vendors into 14 branches so buyers pick the right category before they pick a vendor.

Between June and September 2026, four of the best-known non-human identity startups were bought by larger companies: Astrix by Cisco, Entro by SailPoint, Permiso by Okta and Oasis by Cyera. Earlier in the year, Palo Alto Networks closed its CyberArk deal. The identity market now has fewer independent vendors and more overlapping platforms, and the Identity Map sorts the result into 255 vendors across 14 branches so you can pick the category before you pick a vendor.
Verified as of 25 September 2026 against the sources linked inline.
What is happening: the identity market consolidated in 2026
The biggest deal came first. Palo Alto Networks completed its acquisition of CyberArk on 11 February 2026. Its release describes extending "privilege security controls beyond a narrow set of administrators to every identity across the enterprise". CyberArk's products now sit under a Palo Alto platform called Idira, which covers privileged access, machine identity and agentic identity.
Customer identity did not make that trip. CyberArk's old customer identity product page now redirects to Idira, and Idira lists no customer identity offering. Anyone still running that product is looking at a migration, not a renewal.
Then came a run on non-human identity (NHI). NHI means the identities that belong to software rather than people: service accounts, API keys, OAuth tokens, workloads and AI agents. Within about ten weeks, four specialists changed hands.
- 29 June 2026: Cisco completed its acquisition of Astrix Security.
- 29 June 2026: SailPoint closed its Entro Security deal, framing it as "closing the AI governance gap".
- 26 August 2026: Okta closed its Permiso Security acquisition, adding threat detection across human, non-human and agent identities.
- 3 September 2026: Cyera completed its acquisition of Oasis Security, which now sells as Cyera Identity.
The customer identity tier moved too, just before the year began. Twilio acquired Stytch on 14 November 2025 for $104.1 million in cash, according to its 2025 Form 10-K. The filing describes Stytch as "an identity platform for AI agents".
Look at who the buyers are. A governance vendor, an access management vendor, a network vendor and a data security vendor all bought the same capability. The strategic logic behind those deals is covered in why identity giants bought AI agent security. This post is about what the consolidation means when you are the one buying.
Why it matters to you: the category comes before the vendor
The expensive mistake in identity buying is rarely picking the wrong vendor. It is picking from the wrong category. A team runs a workforce single sign-on evaluation when the real problem is customer signup conversion. Or it buys a password vault when the real problem is thousands of machine credentials nobody owns.
Two terms cause most of that confusion. Workforce identity (often called IAM) serves the people who work for you: thousands of accounts, a central directory, and compliance at the centre. Customer identity (CIAM) serves the people who buy from you: millions of accounts, with signup conversion, developer experience and scale at the centre. They share protocols such as OIDC and SAML, but almost nothing else in their buying criteria. The older comparison of IAM vs CIAM covers the split in more detail.
Consolidation makes the category question harder, not easier. The same NHI capability now arrives through four different doors: your governance tool, your access management tool, your network security vendor or your data security vendor. A buyer who starts with a vendor name can end up comparing a standalone startup with a module of a platform that solves a different problem.
An acquisition also changes three things you should price in. Roadmap control moves from the product's customers to the parent's platform strategy. Packaging often shifts from a standalone product to a module of a larger suite. Exit cost rises if the parent retires a product line, as happened to CyberArk's customer identity product.
I founded LoginRadius in 2013 and scaled it past a billion customer identities, so I have seen these buying decisions from the vendor side. The shortlists that went well almost always started from the problem and the population, not from a brand name.
What the Identity Map shows
The Identity Map is a vendor-neutral tree of the identity market. It places 255 vendor listings in 14 branches, from workforce access management to password management. Each branch has its own page with a short editorial intro, a strip of five top picks, and every vendor the map places there. The A to Z directory lists all 255 in one table you can search and filter by category.
A few vendors appear in two branches because they genuinely sell into both. Ping Identity sits in access management and customer identity. Transmit Security sits in customer identity and passwordless. Keeper Security sits in privileged access and password management. That overlap is useful information in itself: it tells you which vendors can cover two of your problems with one contract.
The 14 branches and how crowded each one is
Branch size tells you where you will need a longer evaluation and where the field is already thin. The counts below come from the map's own dataset.
| Branch | Vendors | The question it answers |
|---|---|---|
| Access Management (IAM) | 17 | How do employees sign in once to every app? |
| Governance (IGA) | 18 | Who keeps which access, and can we prove it to an auditor? |
| Privileged Access (PAM) | 20 | Who can use admin and root accounts, and when? |
| Customer Identity (CIAM) | 43 | How do customers sign up and log in to our product? |
| Authorization (AuthZ) | 9 | What may a signed-in user or agent actually do? |
| Passwordless and MFA | 16 | How do we make login resistant to phishing? |
| Non-Human Identity (NHI) | 13 | Which service accounts, tokens and agents exist, and who owns them? |
| Secrets Management | 7 | Where are machine credentials stored and rotated? |
| PKI and Certificates | 8 | How do we issue and renew certificates at scale? |
| Threat Detection (ITDR) | 17 | How do we catch an attacker using a valid login? |
| Identity Verification (IDV) | 44 | Is this new customer a real person? |
| Decentralized Identity | 13 | Do we need wallets and verifiable credentials? |
| Cloud Entitlements (CIEM) | 6 | Are cloud permissions in AWS, Azure and GCP right-sized? |
| Password Management | 24 | Where do people keep the passwords they still use? |
How it was built
Every listing records a headquarters, a one-line focus and a status note. The status notes carry ownership changes, so an acquired vendor shows an "Acquired" badge on its card. On the non-human identity branch, the notes already read "Acquired by Cisco (2026)", "Acquired by SailPoint (2026)", "Acquired by Okta (2026)" and "Acquired by Cyera (2026); now Cyera Identity".
A map shows placement, not depth. Each vendor card deep-links to a full profile on Start with Identity, a separate identity knowledge site that keeps one canonical profile per vendor. The map's links were reconciled against that site's sitemap in June 2026. Two of the 255 listings have no profile yet, and their buttons open the matching category index instead.
The profiles are where ownership detail lives. The Astrix Security profile is titled "Now Cisco, No Longer Sold Standalone". The CyberArk profile is titled "CyberArk (now Idira)". Profile paths do not always match the map's branch names, since the site files NHI startups under an "ai-identity" segment. Follow the card's button rather than guessing a URL.
Three findings from the map
The NHI branch lost its independent leaders. The non-human identity branch has 13 vendors. Four of them were acquired in 2026, and three of those four (Astrix, Oasis and Entro) were among the branch's five top picks. Token Security and Aembit are the two top picks the map does not record as acquired. If you shortlisted NHI vendors in 2025, your list is probably out of date.
The biggest branches are the ones buyers confuse most. Identity verification (44 vendors) and customer identity (43) are the two largest branches. Both touch customer onboarding, yet they are separate purchases. Verification proves a person matches a real document or record. Customer identity handles their signup and login afterwards. Most B2B SaaS products need the second and not the first.
The smallest branches are being absorbed. Cloud entitlements (6 vendors) and secrets management (7) are the two thinnest branches. The map's own intro for secrets management notes that it "has merged with non-human identity and secrets detection into one continuous problem". Before you buy in either branch, check whether a platform you already own now covers it.
How to use it: four steps to a shortlist
This sequence fits into an afternoon. It ends with three to five vendors in the right branch, each checked for current ownership.
- Name the population. Write down whose identities the problem concerns: employees, customers, partners, machines or agents. That one choice rules out most of the tree. Employees point to access management, customers to customer identity, and machines or agents to non-human identity.
- Match your question to a branch. Use the question column in the table above. If two branches fit, you probably have two purchases. Sequence them rather than hunting for one vendor that does both.
- Read the whole branch, then open the profiles. On the branch page, read the intro and every vendor row, not just the top picks. Top picks are the best-known names, not a ranking for your requirements. Open the Start with Identity profile for the five or six vendors that match your needs.
- Check ownership before the first call. Look for an "Acquired" badge on each card, then read the profile for what the new owner said. For agent and NHI vendors, the Agent Security Map deals ledger lists each transaction with its primary source. Drop any retired product and flag any that is no longer sold standalone.
If you are unsure which branch you are in, start from the directory instead. Search for a vendor you already run, note which branch it sits in, and read that branch's neighbours.
What to do next
Consolidation gives buyers a short window of leverage, because incumbents have new questions to answer. This checklist fits one quarter and one owner.
- List every identity product you run today and place each on its branch in the Identity Map. Gaps and overlaps show up quickly.
- For each product, check whether its vendor was acquired since January 2025. Record the acquirer and the close date.
- If you run CyberArk's customer identity product, open a migration plan now.
- If you bought from Astrix, Entro, Permiso or Oasis, ask the new owner in writing whether the product stays standalone and what your renewal will look like.
- Before renewing a separate NHI contract, check whether your governance, access management or security platform now includes NHI through one of these deals.
- For every new identity purchase, write the branch name into the purchase request before any vendor is named.
Frequently Asked Questions
How many identity vendors are there in 2026?
The Identity Map lists 255 vendors across 14 categories as of September 2026. The largest categories are identity verification with 44 vendors and customer identity with 43. The smallest are cloud entitlements with 6 and secrets management with 7. A few vendors appear in two categories because they sell into both.
Which non-human identity vendors were acquired in 2026?
Cisco completed its acquisition of Astrix Security on 29 June 2026, and SailPoint closed its Entro Security deal the same day. Okta closed its Permiso Security acquisition on 26 August 2026. Cyera completed its acquisition of Oasis Security on 3 September 2026, and Oasis now sells as Cyera Identity.
What is the difference between IAM and CIAM?
IAM (workforce identity) manages employee access to internal apps, with a directory, single sign-on and compliance at the centre. CIAM (customer identity) manages signup and login for a company's own users, with conversion and scale to millions of accounts at the centre. They share standards such as OIDC and SAML but are separate purchases.
Is CyberArk's customer identity product still available?
No. Palo Alto Networks completed its CyberArk acquisition on 11 February 2026. The CyberArk customer identity product page now redirects to Palo Alto's Idira platform, which lists no customer identity offering. Existing customers should plan a migration rather than a renewal.
Where can I find detailed profiles for identity vendors?
Each vendor card on the Identity Map links to a full profile on Start with Identity, a separate identity knowledge site. The map shows where a vendor sits in the market. The profile covers what the vendor sells and changes such as acquisitions.
More like this
All Identity & CIAM- Identity & CIAMWhat is Enterprise Identity, And Why Most Companies Get SSO & RBAC Catastrophically WrongAuthentication requirements block 75-80% of enterprise deals, costing B2B SaaS companies millions annually.
- Identity & CIAMUnderstanding the Complete Identity Management EcosystemConfused by the growing identity management landscape? This comprehensive guide breaks down every IAM category, from traditional…
- Identity & CIAMTop IAM Solutions: 21 Platforms Compared (2026)Which IAM platform fits your organization? 21 workforce platforms compared with verified 2026 pricing, the year's acquisitions, and…
Get new Identity & CIAM writing
Enjoyed this? Subscribe and tell us what you read most. Identity & CIAM is already ticked for you. No tracking pixels, unsubscribe with one click.