Delinea
Capability scores
Methodology →- Authentication
- 4.0
- SSO & Federation
- 3.5
- Authorization
- 4.0
- Lifecycle & Provisioning
- 3.5
- MFA & Passwordless
- 3.5
- Governance & Audit
- 4.0
- Developer Experience
- 3.5
- Deployment Flexibility
- 4.0
- Pricing Transparency
- 2.5
- Support & Ecosystem
- 4.0
Scored 0–5 against a published rubric. Independent analysis, no vendor sponsorship.
Overview
Delinea formed from the 2021 merger of Thycotic and Centrify under TPG and is the largest independent PAM vendor now that CyberArk sits inside Palo Alto Networks. Its positioning is deliberate: strong privileged access that is faster to stand up and easier to operate than the heaviest enterprise suites. The company reported passing 400 million dollars in ARR in August 2025, with SaaS the majority of that footprint.
What it is good at
Time to value and usability. Secret Server (the Thycotic heritage) is an approachable vault, paired with privileged session management, just-in-time access, and cloud entitlement features. Three acquisitions filled the historical gaps: Authomize (January 2024) added ITDR and CIEM, Fastpath (April 2024) added identity governance, and StrongDM (closed 5 March 2026) added just-in-time runtime authorization for human and non-human identities. Secret Server reached FedRAMP High authorization on 8 July 2026 under partner UberEther, which opens US public sector deals. The platform runs on Azure across seven hosting geographies with active-active regional pairs, though data is replicated within a geography and not across them.
Where it falls short
At the very top of the enterprise market CyberArk still goes further in breadth and reference depth. Pricing transparency is poor even by PAM standards: there is no public pricing page, and every quote runs through sales.
The bigger current concern is patch exposure. In September 2026 Delinea disclosed four critical on-premises Secret Server flaws in two weeks, including a FIDO2 registration authentication bypass scored 9.8 and a SAML bypass scored 9.5. Cloud tenants were unaffected in every case, which is a real argument for Secret Server Cloud over self-hosting, but self-hosted operators need a fast patch cycle. See Delinea's security advisories for current versions.
Pricing
Quote-based across vaulting, session management, and cloud privilege modules, SaaS or self-hosted. Delinea publishes no list prices, so model the all-in cost with our TCO calculator and expect to negotiate.
Best for, and who should look elsewhere
Choose Delinea for audit-ready PAM a normal-sized team can run, especially in the mid-market or where FedRAMP High is required. Choose CyberArk for the largest estates, BeyondTrust for a similar footprint with stronger remote access, or Teleport if the need is purely modern infrastructure access. See CyberArk vs Delinea.
Bottom line
The leading independent PAM for buyers who want enterprise-grade privileged access without enterprise-grade operational overhead, provided they can patch on-premises deployments promptly.
Delinea: frequently asked questions
- How much does Delinea cost?
- Delinea does not publish list pricing. Its pricing page returns a 404 and all quotes route through a sales request form, so expect a quote-based deal scoped across vaulting, session management, and cloud privilege modules. The only published figure we can point to is a UK Government G-Cloud listing for Secret Server at 1,100 pounds per user per year, dated May 2024, which is a reseller submission rather than a Delinea price list and is now well over two years old. Treat the per-user figures published by procurement aggregators as unsourced.
- Is Delinea FedRAMP authorized?
- Yes. Delinea Secret Server achieved FedRAMP High authorization on 8 July 2026, listed on the FedRAMP Marketplace under partner UberEther. The process ran from May 2025 to July 2026. Delinea's trust center also lists SOC 1 Type 2, SOC 2 Type 2, ISO/IEC 27001:2022, PCI DSS v4.0.1, and the EU-US Data Privacy Framework. It does not list FIPS 140-3 validation, Common Criteria certification, or StateRAMP.
- Are there known Delinea security vulnerabilities?
- Yes, and they are recent. Delinea disclosed four critical Secret Server vulnerabilities in September 2026: CVE-2026-19117 (CVSS 9.8, a FIDO2 credential-registration authentication bypass leading to account takeover) on 2 September, then CVE-2026-15640 (9.5, SAML authentication bypass), CVE-2026-15639 (9.3), and CVE-2026-15638 (9.1, a cryptographic padding oracle) on 15 September. All four affect on-premises Secret Server only; Secret Server Cloud tenants are not affected. None appear in the CISA KEV catalog as of 20 September 2026, so there is no public evidence of exploitation, which is not the same as confirmation that none occurred. On-premises operators should confirm they are on 12.2.7 or later, or the relevant hotfix.
- Did Delinea acquire StrongDM?
- Yes. Delinea announced the StrongDM acquisition on 15 January 2026 and closed it on 5 March 2026; terms were not disclosed. StrongDM brings just-in-time runtime authorization for human and non-human identities, which directly addresses Delinea's weakest historical area, developer-facing infrastructure access. Delinea also acquired Authomize in January 2024 for ITDR and cloud entitlements, and Fastpath in April 2024 for identity governance.
- Delinea vs CyberArk: which is better?
- CyberArk goes deeper for the largest and most complex privileged estates and carries more auditor recognition, which matters in heavily regulated environments. Delinea is the better fit for mid-market and mainstream enterprise buyers who want audit-ready privileged access a normal-sized team can operate. One structural difference now matters: CyberArk was acquired by Palo Alto Networks in February 2026, while Delinea remains independent under TPG, so buyers weighing platform consolidation against vendor neutrality have a real choice to make.
- Delinea or Keeper Security: which fits enterprise versus SMB?
- Keeper Security starts from a password manager and extends into privileged access, which makes it cost-effective and quick to deploy for SMBs and smaller mid-market teams. Delinea starts from enterprise PAM and covers privileged session management, just-in-time access, and cloud entitlements at a depth Keeper does not match. Below roughly a few hundred privileged users, Keeper is usually the better value; above that, Delinea's session isolation and governance features start to justify the cost.
- What are the best Delinea alternatives?
- CyberArk for the largest regulated estates, BeyondTrust for a comparable mid-market to enterprise footprint with strong remote access, and Keeper Security or ManageEngine PAM360 for cost-sensitive smaller deployments. For purely cloud-native infrastructure access, Teleport is the main remaining independent specialist now that Delinea owns StrongDM.
- Is Delinea going public?
- Unconfirmed. Bloomberg reported in March 2025 that TPG was considering an IPO for Delinea and had hired Goldman Sachs and Morgan Stanley, following a private sale process that did not conclude. No S-1 filing exists as of September 2026 and Delinea remains privately held. Delinea reported surpassing 400 million dollars in ARR in August 2025.
Delinea comparisons
More PAM vendors
All PAM →- CyberArk4.6/5
- BeyondTrust4.5/5
- HashiCorp Boundary4.2/5
- Teleport4.2/5
- Keeper Security4.1/5
Related on Start with Identity
- Comparisondelinea-vs-beyondtrust
The two vendors most PAM shortlists reach for besides CyberArk, pulling apart by acquisition. Delinea bought Fastpath and StrongDM. BeyondTrust bought Entitle a
- Comparisonwallix-vs-delinea
WALLIX and Delinea are both established privileged access management vendors competing below and alongside the category giants. WALLIX is known for a streamline
- VendorApono
strong
- VendorARCON
strong
- Comparisoncyberark-vs-beyondtrust
CyberArk is the deepest privileged access platform and is now part of Palo Alto Networks. BeyondTrust is strongest where endpoint privilege management and remot
- VendorFudo Security
niche
By SWI Community Team · Last evaluated 2026-09-20
Independent, community-driven analysis. No vendor sponsorship. Compiled from public research and community input and verified on a best-effort basis, so details may be incomplete or out of date. Scores are opinions, not advice. Trademarks belong to their owners; mention does not imply affiliation or endorsement. See the full disclaimer, or send corrections to [email protected].