CyberArk
Capability scores
Methodology →- Authentication
- 4.5
- SSO & Federation
- 4.0
- Authorization
- 4.5
- Lifecycle & Provisioning
- 4.0
- MFA & Passwordless
- 4.0
- Governance & Audit
- 5.0
- Developer Experience
- 3.0
- Deployment Flexibility
- 4.0
- Pricing Transparency
- 2.0
- Support & Ecosystem
- 4.5
Scored 0–5 against a published rubric. Independent analysis, no vendor sponsorship.
Overview
CyberArk is the privileged access management category leader and the reference architecture auditors expect in regulated enterprises. It no longer exists under that name. Palo Alto Networks completed its acquisition on 11 February 2026, paying 45 dollars in cash plus 2.2005 Palo Alto shares per CyberArk share, then relaunched the portfolio as Idira on 12 May 2026, with brand changes reaching customers from 31 May. We keep this profile under the CyberArk name because that is what buyers search for, but every product is now branded Idira.
It arrived in strong shape: FY2025 revenue of 1.361 billion dollars, up 36 percent, and total ARR of 1.440 billion.
What it is good at
Credential vaulting, rotation, and privileged session isolation and recording are the deepest in the market, which is what matters in audited environments. Coverage spans human admins, Windows and Unix, databases, network gear, cloud consoles, and machine identities through Conjur (now Idira Secrets Hub) and Venafi, acquired October 2024 for about 1.54 billion dollars. Zilla Security added governance in February 2025. Compliance breadth is unmatched in the category, including ISO/IEC 42001:2023 for AI management and three active NIST CMVP cryptographic module validations. CORA AI now runs behaviour analysis and response recommendations across the platform.
Where it falls short
CyberArk is heavy. Deploying and operating it well takes dedicated staff or a partner, and the component breadth has a real learning curve. Developer experience and self-service ergonomics trail Teleport. Pricing is unpublished and premium. For small teams the overhead outweighs the benefit.
Two acquisition-driven risks are new. Vendor neutrality is gone: privileged access now sits inside a platform vendor, which is the point for Palo Alto customers and a problem for everyone else. And the FedRAMP documentation pages have 404'd since the migration, so federal buyers cannot currently confirm that the March 2024 High authorization carried over.
Pricing
Quote-based, modular, premium, and entirely unpublished. Budget for implementation services and model the all-in cost with our TCO calculator.
Best for, and who should look elsewhere
Choose CyberArk, or Idira, for large regulated enterprises with broad privileged estates, especially if you already run Palo Alto Networks. Look at Delinea or BeyondTrust for a lighter footprint or genuine vendor neutrality, or Teleport for modern infrastructure access. See CyberArk vs Delinea.
Bottom line
The deepest PAM platform available, and still the safe choice for large regulated enterprises, provided the loss of vendor neutrality is a trade you want to make.
CyberArk: frequently asked questions
- Is CyberArk still called CyberArk?
- No. Palo Alto Networks completed its acquisition of CyberArk on 11 February 2026, then relaunched the portfolio as Idira on 12 May 2026, with customer-visible brand changes beginning 31 May 2026. The CyberArk brand is retired: cyberark.com press and investor pages now redirect to Palo Alto Networks, and several documentation paths return 404. Products are now Idira Privileged Access Manager, Idira Secrets Hub, Idira Certificate Manager, Idira Endpoint Privilege Manager, and Idira Secure AI Agents. Palo Alto Networks describes Idira as built on CyberArk's legacy. We keep this profile under the CyberArk name because that is what buyers still search for.
- How much does CyberArk cost?
- Neither CyberArk nor Palo Alto Networks publishes list pricing. The official pricing page carries no figures and routes to a demo request, and AWS Marketplace listings direct buyers to a private offer rather than a rate card. Every dollar figure circulating online, whether per privileged user per year or per application, comes from procurement aggregators and lead-generation sites with no disclosed methodology, and those figures contradict each other. We do not repeat them. Expect a quote-based, modular, premium deal, and budget separately for implementation services. Idira SKUs are grouped as Traditional PAM, Modern PAM, Workforce Access, and Machine and AI Identity Security.
- How big was CyberArk before the acquisition?
- FY2025 was its last full year as an independent public company, and it was a strong one. Revenue reached 1.361 billion dollars, up 36 percent year over year, with subscription revenue of 1.105 billion, up 51 percent. Total ARR stood at 1.440 billion dollars at 31 December 2025, up 23 percent, of which subscription ARR was 1.267 billion, or 88 percent of the total. The company posted a GAAP net loss of 146.9 million dollars alongside non-GAAP net income of 233.4 million and free cash flow of 259.3 million, holding 2.095 billion in cash and securities. Press reports valued the Palo Alto deal at roughly 25 billion dollars, though neither the completion release nor Palo Alto's quarterly filing states a total purchase price.
- Is CyberArk FedRAMP authorized?
- It was, and the current status is genuinely unclear. CyberArk announced FedRAMP High Authority to Operate for Endpoint Privilege Manager and Workforce Identity in March 2024. However, the CyberArk FedRAMP documentation pages now return 404 following the migration to Palo Alto Networks, and we could not confirm whether the authorization transferred under the Idira rebrand. Federal buyers should verify directly on the FedRAMP Marketplace before relying on it. Note also that FedRAMP is replacing Low, Moderate and High impact levels with certification classes from January 2027, so the terminology itself will change.
- Are there known CyberArk security vulnerabilities?
- Several, including critical ones, though none is known to be exploited. CVE-2025-49831 scored 9.8 and allowed an IAM authenticator bypass in Conjur OSS below 1.22.1 and Secrets Manager Self-Hosted below 13.5.1. In June 2026 three more landed against the rebranded products: CVE-2026-45177 (9.1, identity-verification bypass in Idira Secrets Manager SaaS Edge), CVE-2026-45176 (8.9, improper access control in the Endpoint Privilege Manager agent), and CVE-2026-45178 (8.4, cluster endpoint access control). Earlier agent flaws include CVE-2026-2914 (8.5) and CVE-2025-66374 (7.8). No CyberArk, Conjur, Venafi, or Idira entry appears in the CISA KEV catalog as of September 2026.
- What did CyberArk acquire before being acquired?
- Two purchases reshaped the portfolio. Venafi was announced in May 2024 at roughly 1.54 billion dollars, about 1.0 billion in cash plus 540 million in shares, closing 1 October 2024 and adding an estimated 150 million dollars in ARR along with machine identity and certificate management. Zilla Security followed in February 2025 for a reported 165 million dollars plus a 10 million dollar earn-out, adding identity governance. CyberArk also owns Conjur for secrets management, now sold as Idira Secrets Hub.
- What are the best CyberArk alternatives?
- Delinea is the closest like-for-like and now the largest independent PAM vendor, with a lighter operational footprint. BeyondTrust competes across a similar enterprise range with stronger remote access. Teleport is the specialist choice if modern cloud infrastructure access is the actual requirement. One structural point matters for shortlists: buyers who chose CyberArk for vendor neutrality no longer have it, since the platform now sits inside Palo Alto Networks, and that alone is pushing some renewals toward Delinea and BeyondTrust.
- What certifications does CyberArk hold?
- Its trust centre lists SOC 2 Type II and SOC 3, ISO/IEC 27001:2022, 27017:2015, 27018:2019, ISO 9001:2015, ISO 22301, PCI DSS v4.0.1, FedRAMP High, Common Criteria via NIAP, CSA STAR, Cyber Essentials and Cyber Essentials Plus, and IRAP, plus alignment statements for GDPR, CCPA and HIPAA. Notably it also holds ISO/IEC 42001:2023 for AI management systems, still uncommon among identity vendors. On FIPS, three CyberArk cryptographic modules hold active NIST CMVP validations: certificates 5205 and 5122 validated in 2026, and 4949 in 2025.
CyberArk comparisons
More PAM vendors
All PAM →- BeyondTrust4.5/5
- Delinea4.3/5
- HashiCorp Boundary4.2/5
- Teleport4.2/5
- Keeper Security4.1/5
Related on Start with Identity
- Comparisoncyberark-vs-beyondtrust
CyberArk is the deepest privileged access platform and is now part of Palo Alto Networks. BeyondTrust is strongest where endpoint privilege management and remot
- Comparisonstrongdm-vs-cyberark
Neither of these is an independent vendor now. Delinea closed its StrongDM acquisition in March 2026, three weeks after Palo Alto Networks closed CyberArk.
- VendorApono
strong
- VendorARCON
strong
- Comparisondelinea-vs-beyondtrust
The two vendors most PAM shortlists reach for besides CyberArk, pulling apart by acquisition. Delinea bought Fastpath and StrongDM. BeyondTrust bought Entitle a
- VendorFudo Security
niche
By SWI Community Team · Last evaluated 2026-09-20
Independent, community-driven analysis. No vendor sponsorship. Compiled from public research and community input and verified on a best-effort basis, so details may be incomplete or out of date. Scores are opinions, not advice. Trademarks belong to their owners; mention does not imply affiliation or endorsement. See the full disclaimer, or send corrections to [email protected].