Corvus

Market analysis

Analysis

Positioning

IAM is a market-shaped subject — a public software category with named leaders, defined subsegments, active M&A, and observable customer economics. Full competitive exhibits below. Late-July 2026 M&A wave: Cyera-Oasis at USD 1B, Okta-Permiso at ~USD 200M, SailPoint unified Identity Security platform shipped at Black Hat USA 2026 on 2026-08-04.

Competitors

SWOT

Strengths
  • Identity is now the operational security control point for cloud-and-SaaS environments, giving IAM a structurally central role in enterprise architecture. Zero-trust doctrine and CISA guidance treat identity as the decision surface, not the network.
  • Open standards (SAML, OAuth, OIDC, WebAuthn) protect the category from single-vendor lock-in on the wire and enable interoperable federation across suites. Standards stewardship by FIDO, OpenID Foundation, OASIS, and IETF keeps switching mechanically feasible.
Weaknesses
  • Heavy reliance on third-party support and helpdesk processes creates a systemically targetable attack surface across the category. The 2022 Lapsus$/Sitel incident against Okta and 2023 Scattered Spider helpdesk-pivot pattern targeted operational identity processes rather than product vulnerabilities.
  • Bundled Entra ID economics constrain pricing power for pure-play vendors, particularly in mid-market. Microsoft 365 E3/E5 licensing includes identity capabilities many customers will not double-pay for.
Opportunities
  • Non-human / AI-agent identity is the fastest-growing subsegment and is now visibly consolidating rather than remaining startup-only. SailPoint's completed acquisition of Entro Security (2026-06-29) is the first material NHI roll-up by a public IAM leader; further consolidation is likely.
  • Regulatory tailwinds (NIS2, DORA, SEC cyber disclosure, eIDAS 2.0/EUDI Wallet) sustain compliance-driven IAM spend across cycles. Compliance obligations turn IAM into a required cost rather than a discretionary purchase.
  • AI-agent / non-human identity emerged as a discrete USD 1B+ category in a single week of late July 2026, and IBM's 2026 Cost of a Data Breach Report highlights inadequate AI-model access controls as the dominant AI-breach failure mode. Cyera-Oasis (USD 1B), Okta-Permiso (~USD 200M), and SailPoint's unified Agentic-Fabric platform launch at Black Hat 2026 collectively priced the AI-agent identity control plane above USD 1B in one week and positioned incumbent IAM suites to capture a new AI-model-access-control budget line in FY 2027.
Threats
  • Microsoft bundling pressure is structurally hostile to standalone IAM economics. Entra ID ships with Microsoft 365 and is offered at price points many Microsoft customers will not refuse, squeezing the addressable market for pure-play access management.
  • The identity plane is now the primary target of the most consequential enterprise breaches, so vendor reputation is exposed to any single major incident. The Lapsus$, Storm-0558, and Scattered Spider incidents each linked directly to identity systems and drove significant customer scrutiny of vendors involved.

Porter's Five Forces

Threat of New Entry moderate

Barriers to entry in workforce IAM and access management are very high (sticky enterprise sales, certification overhead, FedRAMP, integration breadth) — a new standalone Leader is unlikely in 24 months. In non-human-identity and AI-agent identity the barriers are lower and a new generation of startups is entering, though the SailPoint-Entro deal signals incumbents will acquire rather than cede that category.

Supplier Power low

Open standards (SAML, OAuth, OIDC, WebAuthn) and hyperscale cloud commodity inputs limit any single supplier's leverage over IAM vendors. Standards bodies (FIDO Alliance, OpenID Foundation, NIST) act as neutral arbiters rather than commercial gatekeepers.

Competitive Rivalry high

A small number of well-capitalized platforms (Microsoft, Okta, Ping-ForgeRock, SailPoint, Palo Alto Networks-CyberArk) compete head-to-head for the same enterprise budgets, with heavy PE-backed consolidation and Microsoft bundling pressure intensifying the fight. Okta's mid-2026 launch of OIG and OPA directly overlaps SailPoint and CyberArk territory. The July-August 2026 wave — Cyera-Oasis USD 1B (2026-07-28), Okta-Permiso ~USD 200M (2026-07-30), and SailPoint's unified human/machine/AI-agent Identity Security platform launched at Black Hat USA 2026 (2026-08-04) — accelerated the head-to-head collision between incumbent IAM suites and cybersecurity+data-security platforms on the AI-agent identity control plane.

Buyer Power moderate

Enterprise buyers face high switching costs once federated with a directory or IDP, which limits price sensitivity mid-contract, but multi-vendor procurement and open federation standards give buyers real optionality at renewal and RFP time.

Threat of Substitution low

There is no viable substitute for an identity plane in cloud-and-SaaS-heavy organizations. Credible substitution is in-suite (Microsoft Entra displacing third-party IDPs) or category-redefinition (NHI/AI-agent identity emerging as a parallel plane), not abandonment of IAM. Legacy on-prem directories cannot satisfy zero-trust or regulatory baselines.