# cyberark

Source: https://startwithidentity.com/vendors/pam/cyberark/
Last updated: 2026-09-20
License: content by Start with Identity. Cite the source URL.

---

## Overview

CyberArk is the [privileged access management](https://startwithidentity.com/guides/fundamentals/what-is-pam/) category leader and the reference architecture auditors expect in regulated enterprises. It no longer exists under that name. Palo Alto Networks [completed its acquisition](https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-completes-acquisition-of-cyberark-to-secure-the-ai-era) on 11 February 2026, paying 45 dollars in cash plus 2.2005 Palo Alto shares per CyberArk share, then [relaunched the portfolio as Idira](https://investors.paloaltonetworks.com/news-releases/news-release-details/palo-alto-networks-introduces-idira-next-generation-identity) on 12 May 2026, with brand changes reaching customers from 31 May. We keep this profile under the CyberArk name because that is what buyers search for, but every product is now branded Idira.

It arrived in strong shape: FY2025 revenue of 1.361 billion dollars, up 36 percent, and total ARR of 1.440 billion.

## What it is good at

Credential vaulting, rotation, and privileged session isolation and recording are the deepest in the market, which is what matters in audited environments. Coverage spans human admins, Windows and Unix, databases, network gear, cloud consoles, and machine identities through Conjur (now Idira Secrets Hub) and [Venafi](https://startwithidentity.com/vendors/machine-identity/venafi/), acquired October 2024 for about 1.54 billion dollars. Zilla Security added governance in February 2025. Compliance breadth is unmatched in the category, including ISO/IEC 42001:2023 for AI management and three active NIST CMVP cryptographic module validations. CORA AI now runs behaviour analysis and response recommendations across the platform.

## Where it falls short

CyberArk is heavy. Deploying and operating it well takes dedicated staff or a partner, and the component breadth has a real learning curve. Developer experience and self-service ergonomics trail [Teleport](https://startwithidentity.com/vendors/pam/teleport/). Pricing is unpublished and premium. For small teams the overhead outweighs the benefit.

Two acquisition-driven risks are new. Vendor neutrality is gone: privileged access now sits inside a platform vendor, which is the point for Palo Alto customers and a problem for everyone else. And the FedRAMP documentation pages have 404'd since the migration, so federal buyers cannot currently confirm that the March 2024 High authorization carried over.

## Pricing

Quote-based, modular, premium, and entirely unpublished. Budget for implementation services and model the all-in cost with our [TCO calculator](https://startwithidentity.com/tools/tco-calculator/).

## Best for, and who should look elsewhere

Choose CyberArk, or Idira, for large regulated enterprises with broad privileged estates, especially if you already run Palo Alto Networks. Look at [Delinea](https://startwithidentity.com/vendors/pam/delinea/) or [BeyondTrust](https://startwithidentity.com/vendors/pam/beyondtrust/) for a lighter footprint or genuine vendor neutrality, or Teleport for modern infrastructure access. See [CyberArk vs Delinea](https://startwithidentity.com/compare/cyberark-vs-delinea/).

## Bottom line

The deepest PAM platform available, and still the safe choice for large regulated enterprises, provided the loss of vendor neutrality is a trade you want to make.
