Top 10 DSPM Tools of 2026, and DSPM vs CSPM vs DLP
Data security posture management compared: Cyera, Varonis, Microsoft Purview DSPM, BigID, Sentra, Veeam, Concentric AI, Zscaler, IBM Guardium and Rubrik, with who owns what as of September 2026.
The short answer, by problem. If your sensitive data is concentrated in Microsoft 365 and you already pay for E5 or Purview, check Microsoft Purview DSPM before you shortlist anything, because it went generally available in May 2026 and you may already own it. If you are buying DSPM as its own programme across cloud, SaaS and on-premises, Cyera has the deepest classification and the broadest coverage. If the risk sits in Windows file shares, Active Directory and SharePoint, buy Varonis. If privacy drives the programme, or you are a US federal agency, buy BigID. If you want cloud-native classification and nothing else attached to it, buy Sentra. If the risk is in documents rather than databases, buy Concentric AI.
Last verified: 18 September 2026. Ownership, product naming and published pricing were re-checked on each vendor's own site this session. Four of the ten platforms here are no longer independent companies, and one of those changes happened four months ago.
First: DSPM, CSPM, DLP and "data security platform" are four different purchases
This is the confusion that sends the most money to the wrong place, so state it plainly before any vendor appears.
| Category | The question it answers | What it acts on | Where it fails alone |
|---|---|---|---|
| DSPM | Where is sensitive data, who and what can reach it, what is exposed? | The data itself, across cloud, SaaS and on-premises | Finds risk, does not stop movement, and is not a detection platform |
| CSPM | Is my cloud infrastructure configured safely? | Accounts, networks, resources, IAM configuration | Will pass a perfectly hardened bucket that is full of unclassified customer records |
| DLP | Should this specific movement of data be allowed right now? | Data in motion and in use, at an enforcement point | Needs to already know what is sensitive, which is the input DSPM produces |
| Data security platform | Nothing. It is a commercial bundle, not a technical category | Whatever modules the vendor has bought | Bundle depth is uneven, because most of it arrived by acquisition |
The sequence that works: DSPM finds and classifies, DLP enforces on the result, CSPM hardens the infrastructure underneath, and you buy the bundle only when the commercial terms beat best-of-breed for your estate rather than because the category name sounded comprehensive.
Two adjacent pages cover the neighbours properly: the top 5 CSPM tools of 2026 and the top 5 DLP tools of 2026. If you are looking at converged cloud coverage instead, the top 10 CNAPP solutions of 2026 explains why CSPM, CWPP, CIEM and DSPM keep getting sold together.
Do I still need DSPM if I have a CNAPP?
Usually yes, and for a specific reason. A CNAPP secures infrastructure and workloads. It reports that a bucket is public, an identity is over-permissioned and an image carries a critical CVE. It does not report that the bucket holds forty thousand unredacted health records. Nor that a second copy sits in a forgotten Snowflake table, or that a vector database built for a Copilot rollout was populated from an unclassified SharePoint site.
Several CNAPP vendors now ship a DSPM module, and that is reasonable when your data lives entirely inside the clouds the CNAPP covers. It stops being reasonable the moment a meaningful share of sensitive data sits in Microsoft 365, in SaaS, or on a file server. Palo Alto is the clearest example: it bought Dig Security in December 2023 and ships DSPM inside Cortex Cloud, which is a sound choice if you already run Cortex and an odd one if you do not.
Check what you already own first
The single most valuable action on this page costs nothing. Microsoft rebuilt Purview DSPM and rolled general availability worldwide through May 2026, replacing the products now labelled DSPM (classic) and DSPM for AI (classic). It consolidates Purview DLP, Insider Risk Management, sensitivity labels and Data Security Investigations into one posture view, adds AI observability across Microsoft and third-party agents, and extends beyond Microsoft into Google Cloud, Snowflake and Databricks.
Sign into the Purview portal, open Solutions then DSPM, and look at what your tenant already surfaces. Microsoft's own documentation is explicit that the Asset explorer's Microsoft locations currently include Microsoft 365 only, with non-Microsoft locations made possible by partner integrations, and that the Sentinel data lake path for third-party sources was in preview. That is a real limit. It is also a limit that does not matter if most of your regulated data is in SharePoint and OneDrive, which for a lot of enterprises it is.
Microsoft's documentation also names Varonis, Cyera, BigID and OneTrust as integration partners feeding risk insights into the Purview view. The realistic architecture for a large hybrid estate in 2026 is Purview on the Microsoft side plus one specialist for everything else, not one tool for the whole estate.
The ownership map, because half of this market changed hands
DSPM was never a durable standalone market. Discovery and classification are an input that other platforms want, so backup vendors, CNAPP vendors, zero trust vendors and Microsoft bought or built their way in. As of 18 September 2026:
- Independent: Cyera, Varonis, BigID, Sentra, Concentric AI.
- Veeam completed its $1.725 billion acquisition of Securiti AI on 11 December 2025 and launched the DataAI Command Platform at VeeamON on 12 May 2026. Securiti is not an independent purchase.
- Zscaler announced its acquisition of Symmetry Systems on 21 May 2026, for the access graph rather than for the classification.
- IBM has owned the former Polar Security since 2023 and now presents it inside Guardium Data Security Center rather than as a named DSPM.
- Rubrik has owned Laminar since 2023 and sells it as Rubrik DSPM inside Rubrik Security Cloud.
- Palo Alto has owned Dig Security since December 2023, shipping DSPM inside Cortex Cloud.
Cyera moved the other direction this year: a $600 million round in June 2026 at a reported $12 billion valuation, and a $1 billion acquisition of non-human identity vendor Oasis Security that completed on 3 September 2026. The lesson for a buyer is not that acquisition is bad. It is that a standalone DSPM contract is a three-year bet on the vendor still being standalone, so negotiate roadmap and support commitments in writing rather than assuming continuity.
Related reading
- Top 10 AI-SPM tools of 2026 for the part DSPM does not cover: model supply chain integrity, adversarial robustness and prompt injection defence.
- Top 5 CSPM tools of 2026 and top 5 DLP tools of 2026 for the two neighbours most often confused with this one.
- Top 10 CNAPP solutions of 2026 for the converged cloud platform argument and where it genuinely holds.
Quick Comparison
| Platform | Best For | Ownership (checked 18 Sep 2026) | Coverage Scope | Published Pricing |
|---|---|---|---|---|
| Cyera | A standalone DSPM programme across cloud, SaaS and on-prem | Independent; $600M raised June 2026 at a $12B valuation | AWS, Azure, GCP, SaaS, on-prem, AI agents | Not published; two plans for DSPM and DLP |
| Varonis Data Security Platform | Windows file shares, Active Directory and Microsoft 365 | Independent, NASDAQ listed | On-prem, M365, AWS, Azure, GCP, SaaS, email | Not published |
| Microsoft Purview DSPM | Microsoft 365 estates already licensed for E5 or Purview | Microsoft | M365, Azure, Fabric, plus GCP, Snowflake and Databricks | Not published as a line item; included with Purview and E5 licensing |
| BigID | Privacy-led programmes and US federal workloads | Independent; FedRAMP authorised March 2026 | Cloud, SaaS, on-prem, structured databases | Not published |
| Sentra | Cloud-native estates that want classification depth and nothing else | Independent; $50M Series B, over $100M raised | AWS, Azure, GCP, SaaS | Not published |
| Veeam DSPM (formerly Securiti AI) | Veeam backup customers unifying resilience and data security | Veeam; $1.725B deal completed 11 December 2025 | Multi-cloud, SaaS, AI workloads, backup estate | Not published |
| Concentric AI | Unstructured business content where regex classification fails | Independent | M365, Google Workspace, file shares, AI tools | Not published |
| Zscaler DSPM (formerly Symmetry Systems) | Object-level access path analysis alongside a Zscaler estate | Zscaler; acquisition announced 21 May 2026 | AWS, Azure, GCP, SaaS, on-prem | Not published |
| IBM Guardium DSPM (formerly Polar Security) | Existing Guardium customers extending into cloud | IBM; now inside Guardium Data Security Center | Multi-cloud, SaaS | Not published |
| Rubrik DSPM (formerly Laminar) | Rubrik customers wanting backup-aware data security | Rubrik | Multi-cloud, SaaS, backup estate | Not published |
Cyera
- Best For
- A standalone DSPM programme across cloud, SaaS and on-prem
- Ownership (checked 18 Sep 2026)
- Independent; $600M raised June 2026 at a $12B valuation
- Coverage Scope
- AWS, Azure, GCP, SaaS, on-prem, AI agents
- Published Pricing
- Not published; two plans for DSPM and DLP
Varonis Data Security Platform
- Best For
- Windows file shares, Active Directory and Microsoft 365
- Ownership (checked 18 Sep 2026)
- Independent, NASDAQ listed
- Coverage Scope
- On-prem, M365, AWS, Azure, GCP, SaaS, email
- Published Pricing
- Not published
Microsoft Purview DSPM
- Best For
- Microsoft 365 estates already licensed for E5 or Purview
- Ownership (checked 18 Sep 2026)
- Microsoft
- Coverage Scope
- M365, Azure, Fabric, plus GCP, Snowflake and Databricks
- Published Pricing
- Not published as a line item; included with Purview and E5 licensing
BigID
- Best For
- Privacy-led programmes and US federal workloads
- Ownership (checked 18 Sep 2026)
- Independent; FedRAMP authorised March 2026
- Coverage Scope
- Cloud, SaaS, on-prem, structured databases
- Published Pricing
- Not published
Sentra
- Best For
- Cloud-native estates that want classification depth and nothing else
- Ownership (checked 18 Sep 2026)
- Independent; $50M Series B, over $100M raised
- Coverage Scope
- AWS, Azure, GCP, SaaS
- Published Pricing
- Not published
Veeam DSPM (formerly Securiti AI)
- Best For
- Veeam backup customers unifying resilience and data security
- Ownership (checked 18 Sep 2026)
- Veeam; $1.725B deal completed 11 December 2025
- Coverage Scope
- Multi-cloud, SaaS, AI workloads, backup estate
- Published Pricing
- Not published
Concentric AI
- Best For
- Unstructured business content where regex classification fails
- Ownership (checked 18 Sep 2026)
- Independent
- Coverage Scope
- M365, Google Workspace, file shares, AI tools
- Published Pricing
- Not published
Zscaler DSPM (formerly Symmetry Systems)
- Best For
- Object-level access path analysis alongside a Zscaler estate
- Ownership (checked 18 Sep 2026)
- Zscaler; acquisition announced 21 May 2026
- Coverage Scope
- AWS, Azure, GCP, SaaS, on-prem
- Published Pricing
- Not published
IBM Guardium DSPM (formerly Polar Security)
- Best For
- Existing Guardium customers extending into cloud
- Ownership (checked 18 Sep 2026)
- IBM; now inside Guardium Data Security Center
- Coverage Scope
- Multi-cloud, SaaS
- Published Pricing
- Not published
Rubrik DSPM (formerly Laminar)
- Best For
- Rubrik customers wanting backup-aware data security
- Ownership (checked 18 Sep 2026)
- Rubrik
- Coverage Scope
- Multi-cloud, SaaS, backup estate
- Published Pricing
- Not published
Cyera
Best OverallBest for: A standalone DSPM programme across cloud, SaaS, on-premises and AI agents
“Cyera is the default choice if you are buying DSPM as its own programme rather than as a module of something you already own. It is also the best capitalised independent in the category: $600 million raised in June 2026 at a reported $12 billion valuation, and a $1 billion acquisition of non-human identity vendor Oasis Security that completed on 3 September 2026. The platform now spans DSPM, Omni DLP, Agent Guardian, Cyera Identity, Access Trail and Privacy, which means it is no longer a DSPM product so much as a data security platform with DSPM at the centre.”
Pros
- Strongest classification depth in the category across structured and unstructured cloud data, and the discovery that downstream workflows depend on
- Coverage spans AWS, Azure, GCP, the major SaaS suites and on-premises systems under one classification model
- Agent Guardian, launched 3 August 2026, extends discovery to sanctioned and unsanctioned AI tools and governs what agents can reach
- The Oasis Security acquisition, completed 3 September 2026, brings non-human identity governance into the same platform as the data it reaches
Cons
- No published pricing at any tier, and the enterprise positioning excludes most mid-market budgets
- Platform scope has widened fast through acquisition, so module maturity is uneven
- Detection and response is thinner than the discovery and classification core, so it pairs with a SIEM rather than replacing one
Classification is still the reason to buy it
Every downstream DSPM workflow inherits the quality of classification, and this is where Cyera earns its position. The models are tuned for cloud-native sources and cover structured stores such as Snowflake and BigQuery alongside unstructured object storage and document repositories. False positives are the thing that kills a DSPM programme, because a remediation queue nobody trusts stops being worked within a quarter.
What the 2026 acquisitions actually change
Oasis Security was a non-human identity vendor, and folding it in means Cyera can tie a sensitive dataset to the service accounts and agents that can reach it, not only to the humans. That is a genuinely useful join, and it is also the join most DSPM tools cannot make. Treat the integration depth as something to verify in a proof of concept rather than assume, because the deal closed on 3 September 2026 and product integration takes longer than a press release.
Where it stops
Cyera tells you where sensitive data is, who and what can reach it, and what is exposed. It does not do general-purpose threat detection and does not pretend to. Data exfiltration in progress, ransomware encryption behaviour and insider patterns belong in a SIEM that receives Cyera findings as context. Architect for that split rather than expecting one tool to carry both.
Not published. Cyera's pricing page describes two plans covering DSPM and DLP with optional add-ons and routes to a custom quote. No figures are published.
Varonis Data Security Platform
Best for EnterpriseBest for: Windows file shares, Active Directory and Microsoft 365 with deep activity audit
“Varonis remains the strongest answer when the sensitive data lives in places DSPM startups were never built for: NTFS file shares, Active Directory, SharePoint, Exchange and OneDrive. Its differentiator is not discovery, it is the activity record. Varonis logs every access event and permission change at object level and builds behavioural baselines on top, which produces insider threat and exfiltration detections that posture-only tools cannot generate. It acquired AI email security vendor SlashNext in a deal announced September 2025 at up to $150 million, extending the platform to the initial access point rather than only the data.”
Pros
- Twenty years of depth on Microsoft file shares, Active Directory and Microsoft 365, unmatched by any cloud-first DSPM
- Behavioural analytics on real access activity, which produces detection rather than only posture findings
- Mature remediation: automated permission cleanup, broken access path repair and least-privilege enforcement at scale
- SlashNext acquisition extends coverage to email and collaboration as the initial access vector
Cons
- No published pricing, and deal sizes routinely surprise procurement
- Heavier to deploy and operate than agentless competitors, because collecting activity data is the point
- Cloud-native classification is competent but not differentiated against Cyera or Sentra
The activity record is the differentiator
Most DSPM tools take a snapshot: here is the data, here are the effective permissions, here is the exposure. Varonis additionally keeps the event stream, which is what lets it say that a user who normally opens forty files a day opened four thousand this morning. That is a detection, not a posture finding, and it is the capability gap that separates the incumbent data security vendors from the 2021 DSPM cohort.
Hybrid is the actual use case
Cloud and SaaS coverage across AWS, Azure, GCP and the major suites is real and has matured, but it is not where Varonis wins. It wins when one platform has to cover a twenty-year-old file estate, Active Directory, Microsoft 365 and cloud with one risk model. Organizations that split that across two vendors end up reconciling two inventories, which is its own ongoing cost.
Not published. Varonis lists no prices and routes to sales.
Microsoft Purview DSPM
Best ValueBest for: Microsoft 365 estates already licensed for E5 or Purview
“The most important change to this category in 2026 is that Microsoft shipped a credible DSPM you may already be paying for. The rebuilt Purview DSPM reached general availability worldwide through May 2026, replacing the products now labelled DSPM (classic) and DSPM for AI (classic). It consolidates Purview DLP, Insider Risk Management, sensitivity labels and Data Security Investigations into one posture view, adds AI observability across Microsoft and third-party agents, and extends beyond Microsoft into Google Cloud, Snowflake and Databricks. Anyone shortlisting DSPM without first checking what their existing Purview entitlement covers is potentially buying a second copy of something they own.”
Pros
- Likely already licensed: it is part of Purview rather than a separate SKU, so the marginal cost for an E5 estate can be zero
- Deepest possible integration with Microsoft 365, Azure and Fabric, which is where most enterprise sensitive data actually sits
- AI observability tracks oversharing, exfiltration and unusual access by AI apps and agents, including Microsoft Agent 365
- Integrates with Varonis, Cyera, BigID and OneTrust rather than requiring you to rip them out, which is a genuinely unusual posture from Microsoft
Cons
- Asset explorer's Microsoft locations currently cover Microsoft 365 only; non-Microsoft sources depend on partner integrations
- Non-Microsoft source coverage via the Microsoft Sentinel data lake was still in preview when checked
- Licensing is genuinely hard to work out, because Purview capability is spread across E5, add-ons and pay-as-you-go
Check your entitlement before you shortlist
This is the single highest-value action on this page. Sign into the Purview portal, open Solutions then DSPM, and see what your tenant already surfaces. For an estate whose sensitive data concentration is Microsoft 365, the answer is frequently good enough to change the shortlist, and the procurement conversation shifts from choosing a DSPM vendor to justifying why you need a second one.
AI observability is the reason it is ranked this high
Purview DSPM inventories AI apps and agents with activity in the last thirty days, flags high-risk ones and those with sensitive interactions, and tracks oversharing and exfiltration by agent. Because Microsoft controls Copilot and Agent 365, it sees agent behaviour no third party can. If your immediate DSPM driver is an AI rollout rather than a compliance finding, that visibility is worth more than a marginally better classifier.
It is a complement more often than a replacement
Microsoft's documentation explicitly names Varonis, Cyera, BigID and OneTrust as integration partners feeding risk insights into the Purview view. The realistic 2026 architecture for a large hybrid enterprise is Purview as the Microsoft-side posture layer plus one specialist for everything else, rather than one tool for the whole estate.
Not published as a standalone DSPM price. Capability is licensed through Microsoft Purview and Microsoft 365 E5, with some features available pay-as-you-go. Confirm entitlement against your existing agreement before shortlisting anything else.
BigID
Honorable MentionBest for: Privacy-led data security programmes and US federal workloads
“BigID approaches data security from privacy and governance rather than from cloud posture, which produces a different shape of product. It is the right answer when the programme's sponsor is a privacy officer, when data subject rights processing is a real operational load, and when regulatory framework mapping matters more than classification speed. Two 2026 developments matter to buyers. FedRAMP authorisation in March 2026, in partnership with Knox Systems, opens US federal agency use. A set of RSA 2026 launches extended the platform into AI security, including DLP Prism, AskBigID GPT and agentic access governance.”
Pros
- Strongest regulatory framework mapping in the category, covering GDPR, CCPA, LGPD, India DPDP and emerging AI rules
- FedRAMP authorised in March 2026, which makes it directly procurable by US federal agencies
- Mature data subject rights automation and consent management, which no cloud-first DSPM matches
- 2026 AI releases extend the same inventory into employee AI tool usage and agent access governance
Cons
- No published pricing
- Cloud-native classification accuracy and deployment simplicity trail the cloud-first specialists
- Platform breadth carries deployment and operational complexity
Privacy heritage shapes the product
Native handling of GDPR Article 9 special categories, CCPA, LGPD, India DPDP and China PIPL sits alongside security classification for credentials, intellectual property and payment data. Data subject access request automation, consent management and deletion workflows are mature in a way that security-first DSPMs have never needed to be. If you process DSARs at volume, that capability is not a nice-to-have.
The federal angle is new
FedRAMP authorisation in March 2026 changes who can buy this. For a US federal agency or a contractor working in that environment, the authorised vendor list is short, and BigID entering it is more decisive than any classification benchmark.
Not published. BigID routes pricing to sales.
Sentra
Honorable MentionBest for: Cloud-native estates that want classification depth and deliberately nothing else
“Sentra is the focused alternative to Cyera and competes on close to the same ground: agentless cloud-native discovery, strong classification and fast time to first finding across AWS, Azure, GCP and the major SaaS suites. It has raised over $100 million, including a $50 million Series B led by Key1 Capital, and has deliberately not expanded into privacy automation or broad platform scope. In a category where every competitor is bolting on adjacent modules, staying narrow is a real position.”
Pros
- Classification accuracy on cloud-native sources is genuinely close to the category leader
- Agentless deployment, with first findings typically inside a few days
- Narrow product scope means engineering effort goes into core DSPM rather than into adjacent categories
- A credible second quote against Cyera, which matters when neither vendor publishes pricing
Cons
- No published pricing
- On-premises and long-tail SaaS coverage is thinner than the broad platforms
- Smaller company, which is a procurement risk in a category that has consolidated this hard
Focus as a product strategy
Sentra does not sell privacy automation, AI governance or identity. Organizations that need those buy them elsewhere and integrate. For a team that wants one job done well and already owns a privacy platform, that is cleaner than paying for a suite. For a team consolidating vendors, it is the wrong shape.
How to run the bake-off
Load a representative sample with known ground truth into both Sentra and its nearest competitor and measure precision and recall on your own data, not on the vendor's benchmark. Published accuracy claims in this category describe the vendor's test set. The number that matters is how much of your remediation queue is noise after ninety days.
Not published. Sentra routes pricing to sales.
Veeam DSPM (formerly Securiti AI)
Honorable MentionBest for: Veeam backup customers unifying data resilience and data security
“Securiti AI is no longer an independent purchase. Veeam completed its $1.725 billion acquisition on 11 December 2025, and the technology now sits inside the Veeam DataAI Command Platform announced at VeeamON on 12 May 2026. The Securiti knowledge graph became the Veeam Data Command Graph, embedded into the backup architecture so classification, access permissions and risk scoring attach to the recovery pipeline rather than sitting beside it. That is a real architectural idea, and it also means the buying decision is now a Veeam decision.”
Pros
- The knowledge graph joins classification, lineage and continuous risk scoring across data, identities and AI assets
- Embedding posture into the backup estate turns a passive repository into something you can actually govern
- Privacy automation and AI governance capability carried over from Securiti is among the most developed in the category
- Broad coverage across multi-cloud, SaaS and on-premises sources
Cons
- Not available as an independent purchase since December 2025
- No published pricing, and licensing is now entangled with Veeam platform agreements
- Platform breadth means real deployment and policy authoring effort before value appears
What the acquisition changed
Veeam announced the deal in 2025 and completed it on 11 December 2025 for $1.725 billion. At VeeamON on 12 May 2026 it launched the DataAI Command Platform, integrating resilience, DSPM, compliance and AI governance behind a single knowledge graph. Securiti's Data Command Graph became the Veeam Data Command Graph. Vendor pages under securiti.ai still resolve, which is exactly how a stale shortlist survives a year after the company stopped being independent.
Backup-aware posture is the actual differentiator
Most DSPM tools ignore the backup estate, which is a large, long-lived and frequently over-permissioned copy of everything sensitive you own. Linking classification and access analysis into the recovery pipeline is a genuinely under-served angle. Whether it justifies a platform decision depends entirely on whether Veeam is already your backup vendor.
Not published. Now licensed through Veeam platform agreements rather than as a standalone Securiti subscription.
Concentric AI
Honorable MentionBest for: Unstructured business content where pattern-matching classification fails
“Concentric AI classifies by meaning rather than by pattern, which is the right approach for the documents that make up most of an enterprise's actual risk. A contract, a board pack or a design document is sensitive because of what it is, not because it contains a string that matches a regex. The platform covers Microsoft 365, Google Workspace and file repositories, and integrates with ChatGPT Enterprise, Microsoft Copilot, Claude Enterprise, Snowflake and AWS S3. It was named a 2026 Gartner Peer Insights Customers' Choice for DSPM.”
Pros
- Semantic classification identifies sensitive documents that contain no matchable pattern at all
- Strong coverage of Microsoft 365, Google Workspace and file repositories where unstructured content concentrates
- Integrations with the enterprise AI tools that are now the main route by which documents leak
- 2026 Gartner Peer Insights Customers' Choice recognition for DSPM
Cons
- No published pricing
- Structured database and cloud-native data store coverage is thinner than the broad platforms
- Usually deployed alongside a broader DSPM rather than instead of one
Semantic versus pattern classification
A regex classifier calls a file sensitive because it found something shaped like a payment card number. That misses the merger agreement with no numbers in it and flags the marketing brochure that happens to quote one. Semantic classification reads structure and context to decide what the document is. For unstructured business content that distinction is the difference between a usable queue and an unusable one.
The AI tool angle
Documents now leave the building through an AI assistant as often as through email. Concentric's integrations with ChatGPT Enterprise, Microsoft Copilot and Claude Enterprise put classification at that boundary, which is a more relevant control surface in 2026 than another cloud storage scanner.
Not published. Concentric routes pricing to a demo request.
Zscaler DSPM (formerly Symmetry Systems)
Honorable MentionBest for: Object-level access path analysis, now inside a Zscaler estate
“Symmetry Systems built the best access path analysis in the category and is no longer independent. Zscaler announced its intent to acquire the company on 21 May 2026, positioning the Symmetry access graph as the map of how human and non-human identities, applications and data connect, and Symmetry's own site now leads with the announcement. The technical capability is unchanged and remains differentiated: not that a bucket has ten policies attached, but which specific identities can read which specific dataset, through which paths, with which permissions.”
Pros
- Object-level effective permissions analysis that traverses IAM roles, resource policies, sharing configuration and trust relationships
- Five deployment models including in-VPC, geographically federated and air-gapped, which matters for regulated and sovereign estates
- DataGuard and AIGuard cover data access governance and AI agent identity governance respectively
- The access graph answers the question most classification-led DSPMs answer badly
Cons
- Acquired by Zscaler, so the standalone purchase and roadmap are now subject to a platform strategy
- No published pricing
- Classification depth was never the differentiator, so it usually runs alongside a classification-led DSPM
Access path analysis, precisely
The analysis traverses IAM roles, resource policies, sharing configuration and trust relationships to produce effective permissions at the object level. In an estate where permissions have accumulated for a decade, that surfaces exposure no single configuration scan finds, because the exposure is created by the combination rather than by any one misconfiguration.
Why Zscaler bought it
Zscaler's stated rationale was mapping and securing AI agent communication: which identities, human and non-human, can reach which data, enforced at the network and access layer. That is a coherent thesis. It also means the product's future is a feature of a zero trust platform, which is a different thing from a DSPM you can buy on its own.
Not published. Symmetry routed pricing to demo and trial requests before the acquisition, and Zscaler has not published a separate price.
IBM Guardium DSPM (formerly Polar Security)
Honorable MentionBest for: Existing IBM Guardium customers extending data security into cloud
“IBM acquired Polar Security in 2023 and the technology now sits inside IBM Guardium Data Security Center rather than being marketed as a standalone DSPM product. For an enterprise already running Guardium for database activity monitoring, extending the same console into cloud and SaaS discovery is a reasonable consolidation. For anyone else, this is not a product you would shortlist on its merits, and the IBM product pages no longer really present it as one.”
Pros
- Natural extension for existing Guardium customers, with one console across database activity monitoring and cloud data posture
- IBM enterprise support, procurement and contractual posture, which some regulated buyers require
- Agentless cloud and SaaS discovery inherited from the Polar acquisition
- Fits an IBM-standardised data security estate without adding a vendor
Cons
- No longer positioned as a standalone DSPM product; it is a capability inside Guardium Data Security Center
- No published pricing
- Product velocity and cloud-native classification depth trail the specialists
What happened to the product name
IBM bought Polar Security in 2023, reportedly for around $60 million, and shipped it as IBM Security Guardium DSPM. In 2026 the IBM product pages lead with Guardium Data Security Center, with discovery and classification presented as capabilities inside it rather than as a separately named DSPM. If your shortlist still says Polar, it is three years stale.
The consolidation case
The honest argument for this entry is one vendor, one support contract and one console across database activity monitoring and cloud data posture. That is worth real money to a large regulated enterprise with an existing IBM relationship, and worth nothing at all to anybody else.
Not published. Licensed through IBM Guardium agreements.
Rubrik DSPM (formerly Laminar)
Honorable MentionBest for: Rubrik customers wanting backup-aware data security
“Rubrik acquired Laminar in 2023 and sells the capability as Rubrik DSPM inside Rubrik Security Cloud. The strategic idea is the same one Veeam is now pursuing: your backup platform already holds a complete copy of everything sensitive, so it is a natural place to run discovery, classification and exposure analysis. That logic is sound. It also means this is a Rubrik purchase, and the decision is usually made by whoever owns data protection rather than by the security team.”
Pros
- Backup-aware posture: discovery runs against an estate the platform already indexes
- Agentless multi-cloud and SaaS coverage inherited from Laminar
- Consolidates cyber recovery and data posture under one vendor and one console
- Sensible fit for organizations already standardised on Rubrik Security Cloud
Cons
- Effectively tied to a Rubrik platform decision rather than sold as an independent DSPM
- No published pricing
- Classification and access analysis depth trail the specialists
Backup as a discovery surface
The backup estate is a complete, long-lived and often badly permissioned copy of production. Most DSPM tools never look at it. Running classification and exposure analysis against an index the platform already maintains is efficient, and it surfaces retention-driven risk that a production-only scan cannot see.
Who makes this decision
In practice this is bought by infrastructure and data protection teams with security as a stakeholder, not the reverse. That is worth knowing before you put it on a security shortlist, because the evaluation criteria and the budget line are different from the other nine entries here.
Not published. Licensed through Rubrik Security Cloud agreements.
Which One Should You Pick?
| Use Case | Our Recommendation |
|---|---|
| Microsoft 365 heavy estate, already licensed for E5 or Purview | Check Microsoft Purview DSPM first. It went generally available in May 2026 and the marginal cost may be zero, which changes whether you need a second vendor at all. |
| Buying DSPM as a standalone programme across cloud, SaaS and on-premises | Cyera has the strongest classification depth and the broadest coverage, and is the best capitalised independent in the category after a $600 million round in June 2026. |
| Sensitive data concentrated in Windows file shares, Active Directory and SharePoint | Varonis is the only platform here with twenty years of depth on that estate, plus the activity record that produces detection rather than only posture. |
| Privacy-led programme, or a US federal agency that needs an authorised vendor | BigID has the deepest regulatory framework mapping and was FedRAMP authorised in March 2026. |
| Cloud-native estate that wants classification depth and no platform sprawl | Sentra stays deliberately narrow and is the credible second quote against Cyera when neither vendor publishes a price. |
| Risk concentrated in contracts, board papers and design documents rather than databases | Concentric AI classifies by meaning rather than by pattern, which is the only approach that works on documents containing nothing matchable. |
| The real question is which identities and agents can reach which dataset | Symmetry Systems, now being acquired by Zscaler, produces object-level effective permissions across IAM roles, resource policies and trust relationships. |
| Already standardised on Veeam for data resilience | Veeam DSPM, built from Securiti AI, embeds classification and risk scoring into the recovery pipeline. Securiti is no longer purchasable independently. |
| Existing IBM Guardium customer extending into cloud data posture | IBM Guardium Data Security Center absorbs the former Polar Security DSPM capability into the console you already run. |
| Already standardised on Rubrik Security Cloud | Rubrik DSPM runs discovery and exposure analysis against the backup estate Rubrik already indexes, which most DSPM tools never scan. |
How we evaluated
Last verified: 18 September 2026.
This is a research-based comparison, not a hands-on bake-off. It publishes no classification accuracy benchmark, no head-to-head detection result and no scan performance figure, because those numbers cannot be produced honestly without running every platform against the same data under the same conditions. What it does claim is that the following were checked, vendor by vendor, on 18 September 2026.
- Ownership and corporate status. Who owns each product today, when the deal closed, and whether a standalone purchase still exists. Four of the ten platforms here are no longer independent companies. That finding alone invalidates most DSPM shortlists more than a year old, and it is why ownership is a column in the comparison table rather than a footnote.
- Product naming. Every vendor page was re-resolved. Securiti AI is now Veeam's and its technology sits in the DataAI Command Platform. Polar Security is a capability inside IBM Guardium Data Security Center rather than a named DSPM. Laminar is Rubrik DSPM. Symmetry Systems is being absorbed by Zscaler. Dig Security is inside Palo Alto Cortex Cloud.
- Published pricing, and its absence. Every price claim on this page comes from the vendor's own pricing page and nowhere else. No vendor here publishes a figure, and the page says so ten times rather than quoting an aggregator once. Cyera publishes a pricing page describing two plans with no numbers on it, which is the closest anybody gets.
- Category boundaries. Capability was read against what distinguishes DSPM from CSPM, DLP and CNAPP, because the most expensive mistake in this category is buying the wrong one of the four. Vendor documentation was checked for what each product acts on, not for what its marketing calls itself.
- Licensing entitlement. For Microsoft Purview DSPM, the Microsoft Learn documentation was read directly for scope and current limits. That includes the statement that Asset explorer's Microsoft locations currently include Microsoft 365 only, and that third-party source integration via the Sentinel data lake was in preview.
What we did not do
No vendor paid for placement and there are no affiliate links on this page. Nothing here reports hands-on testing or comparative classification accuracy measured by us. Where an accuracy claim is described, the page says whose benchmark produced it. Where pricing is not published, the page says it is not published.
Accuracy claims in this category deserve particular scepticism. Every DSPM vendor's published precision and recall figures describe that vendor's own test set, and they do not transfer to your data. The only evaluation that means anything is a proof of concept on a representative sample where you already know the ground truth, measuring precision and recall separately. Include the awkward cases deliberately: sensitive documents containing nothing matchable, non-English content, and synthetic test data that should not be flagged.
How to read the ranking
Ranking reflects fit for the stated use case, weighted toward three things.
The first is coverage against where your sensitive data actually is, which is why a Microsoft-only tool ranks third and a Microsoft-and-file-share tool ranks second. The second is whether the product is still a standalone purchase, because a capability inside somebody else's platform is a different commercial decision even when the technology is identical. The third is whether findings can be acted on, since a DSPM that produces a backlog nobody owns has not reduced risk.
One structural caution applies to every entry. DSPM produces findings that are remediated by data owners and platform teams who do not report to security. Organizations without a functioning data governance process deploy DSPM and accumulate a queue rather than reduce exposure. Fix the ownership question before the tooling question, or the tool will simply measure the problem more precisely.
Editorial independence: this is a vendor-neutral comparison with no paid placements, sponsorships, or affiliate links. Rankings reflect fit for the stated use cases, not commercial relationships.
Frequently Asked Questions
What is the difference between DSPM, CSPM, DLP and a data security platform?
Do I still need DSPM if I have a CNAPP?
Who owns each DSPM vendor now, and why does it keep changing?
What does DSPM cost, and why does nobody publish a price?
How accurate is DSPM classification, and how do I test it?
Should DSPM replace my SIEM for data threat detection?
How long does DSPM deployment actually take?
Does DSPM cover AI data, or do I need AI-SPM as well?
Related Comparisons
Security Control Validation
Top 5 Breach and Attack Simulation Tools for 2026: Cymulate vs SafeBreach vs Picus vs AttackIQ vs Pentera
5 tools compared
Secure Design and Threat Modeling
Top 5 Threat Modeling Tools for 2026: IriusRisk vs SD Elements vs ThreatModeler vs Threat Dragon vs Microsoft TMT
5 tools compared
Secure Data Exchange
Top 6 Managed File Transfer and Secure File Sharing Tools for 2026: Compared on Patch Record
6 tools compared
Application Security Testing
Top 5 Intercepting Proxy Tools for 2026: Burp Suite vs mitmproxy vs ZAP vs Proxyman vs Charles
5 tools compared