Where the Cybersecurity Market Is Actually Moving in 2026

Wait 5 sec.

Large platforms are moving into AI. Specialists are moving into Exposure. The gap matters more than the ranking.0. IntroductionTen of the eleven public security vendors I tracked moved into AI Security between July 2024 and July 2026. Of the 66 companies in the Broader Sample, eight did. In Exposure Management the picture is reversed: three of 11 against 14 of 66. Same market, two different maps — and where they diverge says more than where they agree.Part 1 argued that NGFW is no longer the architectural center of security decisions. Part 2 examined that argument across nine vendors. Part 3 asks a narrower question. It does not measure the architectural role of NGFW directly; it looks at where security vendors have committed new resources, and whether those commitments are accumulating in the data, Identity, Exposure, Data Protection, and AI capabilities that provide context beyond an individual control.The analysis uses four observation layers, with closed M&A and generally available product launches as the strictest measure of Action. Three directions show the strongest convergence across the evidence. Three others remain unresolved.This material was prepared in summer–autumn 2026, using data available up to 28 July 2026.1. Executive SummaryI tracked 77 security companies between July 2024 and July 2026: 11 large public vendors and a Broader Sample of 66 companies. The study also covers 3,075 conference talks, 31 forecast documents from 19 organizations, and patent material. For Action, the filter is deliberately strict: only closed acquisitions and products that reached general availability. Among TOP-11, this produced 34 closed M&A transactions and 33 GA launches.None of these datasets measures customer adoption. Action and Expo are mainly supply-side signals; Narrative and conference talks show what the industry is discussing; patents are used only as evidence of technical work. The article therefore describes where vendors are committing resources and where the industry is directing attention, not where customers are already spending most of their money.Three directions stand out across several layers.Data Security Analytics (DSA) has the broadest Action footprint: 10 of 11 TOP-11 vendors and 30 of 66 companies in the Broader Sample. It is an analytical cluster rather than a purchasing category — the definition matters for reading the number, and I return to it in Section 3.3. Large platforms expand it through both acquisitions and internal development; smaller vendors rely much more heavily on new products.AI Security is much more platform-led. Ten of 11 TOP-11 vendors launched qualifying products and seven also used M&A, against eight of 66 companies in the Broader Sample. Conference attention rose sharply and Expo presence doubled. The Action category here means protecting AI systems, models, prompts, agents and data flows, not simply using AI inside an existing security product.Identity shows a different pattern. Aggregate Action is lower: five of 11 and six of 66. But new activity is concentrating around machine and service identities. Identity also remains prominent in Narrative and conference data. The interesting development is therefore not a new IAM market, but a new front inside an old one.The other three directions are less settled.Exposure Management is already broad among specialists: 14 of 66 companies in the Broader Sample, against only three of TOP-11. Product development appears to be running ahead of consolidation by the large platforms.Data Protection & DSPM shows the opposite imbalance. Action remains narrow, at two of 11 and five of 66, while Expo positioning rose by 65%. Conference attention did not rise materially as a share of the overall program. That may be an early commercial category taking shape or simply positioning running ahead of demand. These data cannot distinguish between the two.Post-Quantum Cryptography sits outside the main Action taxonomy, so its current product breadth is not measured on the same basis. What can be seen is a steady presence in Narrative, rising conference attention and modest growth in Expo positioning. Much of the practical work today concerns crypto inventory and crypto-agility, while the transition itself is also being driven by standards bodies, infrastructure providers, libraries and HSM vendors.The distinction between these six directions matters more than their ranking. AI Security is being pulled into the market by large platforms. Exposure Management is being built largely by specialists. Identity is changing from within. DSPM is being packaged faster than it is appearing in Action. PQC is advancing through standards and preparation rather than through the same product path.Section 7 states five forecasts that can be checked against the same filter. In short: at least two Exposure Management specialists acquired by TOP-11 vendors by the end of 2027; at least eight of the eleven with a qualifying Machine, Service or Agent Identity event over the same period, up from four today; fewer than four with a qualifying PQC or crypto-agility launch; Data Protection & DSPM reaching at least five vendors by the end of 2028, with three of those tied to AI data; and DSA still the broadest Action cluster at that point.The broader conclusion is more cautious. Nothing here demonstrates that mature controls such as NGFW are disappearing. What the data do show is that substantial new activity is accumulating in the systems that provide telemetry, identity, asset, data and risk context around those controls. That is consistent with the argument developed in Parts 1 and 2, but it does not prove it by itself.2. Framing the QuestionThe market produces many signals about its future, but they do not all mean the same thing.A forecast shows what an organization thinks will matter. A conference program shows what practitioners and researchers are paying attention to. Expo presence shows what vendors are trying to package and sell. Patents reveal some of the technical problems being worked on. A product launch or acquisition goes further: resources have already been committed.For that reason, I separate the evidence into three types.Action is the strongest observable signal of commitment: closed M&A and products that have reached general availability.Narrative shows which problems repeatedly appear in forecasts and market outlooks.Development & Positioning combines patents, conference Talks and Expo presence. These are different datasets, but together they show where technical work, professional attention and commercial packaging appear.The important point is not that one signal is large. It is whether several different signals begin to point in the same direction.Nor do I assume that they form a sequence. A conference theme may emerge before a product exists; an acquisition may happen before analysts agree on a category name; Expo may expand before there is evidence of broad demand. Divergence is therefore as informative as convergence.This is particularly useful for mature markets. Identity, for example, may show only moderate growth as a whole while activity concentrates sharply around machine, service and other non-human identities.The question in Part 3 is therefore not simply which category is growing fastest. It is where vendors have already committed resources, where the wider market is beginning to concentrate attention, and where those two pictures disagree.There is also a second question, carried over from Parts 1 and 2. If new activity is accumulating around telemetry, Identity, assets, data and risk context rather than inside one control, does that make a more connected security decision process technically possible?I return to that question only after the market evidence has been examined. Security Analytics Decision Layer (SADL) is an architectural interpretation of the findings, not another market category and not part of the quantitative ranking.3. MethodologyThe detailed methodology, full sample composition, classification rules and source universe are available in the [research materials on GitHub]. This section retains only the definitions needed to interpret the results that follow.3.1. Two Action SamplesAction is measured separately for two groups.TOP-11 consists of Palo Alto Networks, Fortinet, Cisco, CrowdStrike, Check Point, Zscaler, SentinelOne, Cloudflare, Tenable, Rubrik and Okta.The Broader Sample contains 66 other security companies:United States — 18;Israel — 17;European Union — 16;other regions — 15.TOP-11 is a working name, not a ranking. The Broader Sample is a purposive comparison set rather than a statistically representative sample of the global security market.The two samples remain separate throughout the analysis. The purpose is to compare how large platforms and other vendors are moving, not to treat the 77 companies as one population.3.2. What Counts as ActionThe Action window is 28 July 2024 to 28 July 2026.Only closed acquisitions and products that reached general availability qualify.Preview and beta releases, feature updates, partnerships and integrations without a new standalone offering are excluded.For TOP-11, this filter produces 34 closed acquisitions and 33 GA launches.The main metric is the number of companies with at least one qualifying event in a domain, rather than the total number of events. Where a domain needs to be examined in more detail, company × direction and event × direction counts are used as secondary measures.3.3. TaxonomyAction events are mapped using a two-level model:Domain → DirectionThe taxonomy contains 10 domains and 57 directions. An event may receive several mappings where the source explicitly supports several independent capabilities.Two classification boundaries matter particularly for the results.DSA is an analytical cluster, not a purchasing category. It groups SIEM, XDR/MDR, SOAR, Threat Intelligence, Risk Engine and related analytics because the study is interested in convergence between them. As a result, its breadth should not be read as a like-for-like estimate of market size against narrower domains.AI Security means securing AI, not using AI. A SIEM or Endpoint product does not enter the AI Security domain simply because it uses machine learning or an LLM. The category covers protection of models, prompts, agents, inference and AI data flows.The complete taxonomy and mapping rules are available in the [research appendix on GitHub].3.4. NarrativeNarrative is based on 31 forecast and outlook documents published by 19 organizations.Themes are counted twice: first by document and then by organization. The second pass prevents organizations that publish more frequently from dominating the result simply through volume.Narrative is therefore a measure of recurring market attention, not evidence of future customer demand.3.5. Development & PositioningThree additional datasets provide different kinds of evidence.Patents are used qualitatively to identify technical work behind the market categories.Conference Talks measure professional and research attention. The dataset contains 3,075 presentations across 20 conferences in 2024 and 2025.Expo / Positioning measures vendor presence among exhibitors, solution providers and sponsors and is treated as evidence of commercial positioning rather than sales or adoption.These datasets are not combined numerically with Action or Narrative3.6. Different Layers, Different Time WindowsThe datasets do not operate on the same clock.Action uses a fixed two-year window. Narrative may look several years ahead. Patent publication can lag the R&D behind it, while Talks and Expo are observed year by year.For that reason, the analysis does not assume a sequence such as:patent → talk → Expo → product → M&AThe signals are compared for convergence and divergence, not treated as stages of one market-development funnel.3.7. Scope and LimitationsNone of these datasets directly measures customer adoption, production use, renewals, revenue attributable to individual capabilities or market share.The Broader Sample is manually constructed, Narrative partly reflects vendor positioning, and public disclosure varies between companies and regions. The two-year Action window should therefore be read as a period of observable market movement, not proof of a long-term trend.Within those limits, Action is used as the strongest observable signal in the study because a completed acquisition or GA launch demonstrates that resources have already been committed.Detailed sampling rules, inclusion and exclusion criteria, counting methodology, classification rules, source treatment and limitations are available in the [full methodology on GitHub].4. Action: Where Companies Directed New ActivityAction gives the clearest view of where vendors have already committed resources. Four patterns appear immediately.DSA is the broadest cluster: it ties AI Security for the lead among TOP-11 and leads outright in the Broader Sample.AI Security is concentrated among the large platforms. Almost the entire TOP-11 has entered the domain, while activity in the Broader Sample is much narrower.Exposure Management runs the other way. Only three TOP-11 vendors have qualifying events, against 14 companies in the Broader Sample.Identity is different again. The aggregate domain is not especially broad, but new activity is concentrating inside it around machine and service identities.The ranking matters less than these differences in shape.4.1. The Overall Action MapFigure 3 measures the breadth of new publicly observable activity during the two-year window. It is not a measure of market size.The Broader Sample is not sparse. Qualifying events were found for 47 of its 66 companies and covered 47 of the 57 directions in the taxonomy. Yet activity is distributed very unevenly between domains.The mechanism is different as well. The Broader Sample produced 62 qualifying product launches and 22 acquisitions. Among TOP-11, the balance is much closer. Smaller vendors are more often building their way into a direction; large platforms make greater use of acquisition.Deal value tells a different story from company count.Terms were disclosed for 21 of the 34 TOP-11 acquisitions. Together they were worth about $32.4 billion, but 77% of that total came from a single transaction — the CyberArk acquisition. The median disclosed deal was only $187 million.This difference between breadth and capital is important.AI Security ties DSA for the widest company coverage among TOP-11 and produces the largest number of event × direction signals. Yet it accounts for less than 2% of disclosed acquisition value. Platforms have entered AI Security through a series of smaller acquisitions and their own product launches.Identity is almost the reverse. Only five TOP-11 companies have qualifying Identity activity and only two acquisitions sit behind it, yet the domain accounts for roughly four-fifths of disclosed capital.The headline number therefore says little about what a typical transaction looked like. One large Identity acquisition dominates the total, while the broader movement into AI Security is spread across many smaller actions.Activity is also concentrated among the buyers. Palo Alto Networks closed six of the 34 TOP-11 acquisitions; CrowdStrike, Check Point and Cisco closed five each. Those four companies account for 21 of the 34 deals.The Action picture is therefore not simply one of large vendors moving together. Different groups of companies are using different mechanisms, and the money is even more concentrated than the activity itself.4.2. DSA: One Focus, Two Development MechanismsDSA sits at the top of both Action samples:10 of 11 TOP-11 companies;30 of 66 companies in the Broader Sample.But the mechanism is different.Among TOP-11, seven companies used M&A and five launched new products; two did both. Large platforms are extending their existing data and operations stacks partly through internal development and partly by buying missing capabilities.The Broader Sample is more product-led: 27 companies launched qualifying products, nine used M&A, and six did both.That matters because DSA is not simply the result of consolidation among large vendors. A sizeable specialist market is still building standalone SIEM, XDR/MDR, SOAR, Threat Intelligence, Risk Engine and adjacent products.So DSA is best read here as a broad analytical and Security Operations cluster, developing through two different mechanisms: consolidation at the top and product formation below it.4.3. AI Security and Exposure Management: Two Opposite PathsThe clearest asymmetry in Action is between AI Security and Exposure Management.AI Security appears in:10 of 11 TOP-11 companies;8 of 66 companies in the Broader Sample.All ten active TOP-11 vendors launched commercial products, and seven also used M&A. Among the largest platforms, protecting AI is already becoming part of the standard portfolio.Outside TOP-11, the market is narrower. Specialist activity is concentrated mainly around LLM protection, prompt filtering and AI data security rather than broad AI Security platforms.Exposure Management develops almost the other way around:3 of 11 TOP-11 companies;14 of 66 companies in the Broader Sample;13 of those 14 through new product launches.CTEM and External Attack Surface appear most often, with 11 companies in each direction.The large platforms have not yet matched that breadth. Most of the work is being done by specialists solving narrower problems around asset visibility, exposure, attack paths and risk prioritization.AI Security is therefore being pulled into the market from the top. Exposure Management is being built from below.That difference matters more than the raw number of events.4.4. Identity: A New Front Inside a Mature MarketAt the aggregate level, Identity looks moderate:5 of 11 TOP-11 companies;6 of 66 companies in the Broader Sample.But the aggregate hides where the activity is concentrated.In TOP-11, broad acquisitions create presence across several Identity directions at once. Five companies generate 26 event × direction signals, but those signals should not be read as 26 independent initiatives.The Broader Sample gives a cleaner view of the new product activity. All six active companies are represented through their own launches, with Machine Identity and Service Identity appearing most often — four companies each.The activity is increasingly concentrated around technical identities: machines, workloads, service accounts, certificates, APIs and, increasingly, autonomous agents.So, the signal is not a new wave across Identity as a whole. It is a new front inside an old market: non-human identity.Large vendors are mostly acquiring breadth. Specialists are building products around the narrower problem.4.5. Other Domains: Low Action Does Not Mean DeclineCloud, Network, Endpoint and Application Security show lower Action coverage:Cloud — 4 TOP-11 and 5 in the Broader Sample;Network — 3 and 5;Endpoint — 1 and 6;Application Security — 2 and 4.These figures should not be read as evidence that the markets are shrinking.The Action filter excludes most normal development inside mature products: feature expansion, new detection logic, integrations, policy changes and the absorption of acquired technology. Mature domains can therefore remain important while producing relatively few qualifying events.This is particularly relevant to Network and Endpoint Security.Cloud is a useful example of another point. Its TOP-11 Action coverage is actually higher than Exposure Management, but its signals are less interesting for this study because they are more consistent across the layers. Cloud already looks like a mature domain rather than a market in the middle of a visible structural change.Data Protection & DSPM is different. Action remains limited — two TOP-11 companies and five in the Broader Sample — but that is precisely where the next layer becomes useful.Action tells us where resources have already been committed. Narrative can show whether the market is beginning to treat the problem as more important than current product activity would suggest.5. Narrative: What the Market Considers ImportantThe Narrative layer produces a less tidy picture than Action.AI remains first under both counting methods. Identity and Platformization also stay near the top, although they change places depending on whether the unit is a document or an organization. Below them, agreement weakens. Exposure becomes much more visible when publications are grouped by source, while Cloud moves the other way. PQC remains present but lower in both counts.The important point is not the exact order. It is which themes survive a change in the way the evidence is counted.5.1. What Repeats Across Both PassesBy documents, the leading themes are AI, Identity, Cloud and Platformization. By organizations, AI remains first, while Platformization and Identity remain close behind.AI is the only theme whose position does not change.Identity and Platformization move slightly but remain near the top under both methods. That makes their position more convincing than a high count produced mainly by a few prolific sources.Cloud is a useful counterexample. It ranks third by documents but only fifth by organizations. Its apparent prominence is therefore more concentrated among frequent publishers.Exposure shows the reverse effect more sharply: weak as a standalone forecast category, much stronger once related themes are grouped by organization.That difference becomes important later.5.2. AI Extends Far Beyond AI SecurityThe AI Narrative is much broader than the AI Security category used in Action.Forecasts cover AI-assisted attacks, automated reconnaissance, AI in SOC operations, model protection, agent security, data flows and autonomous systems.This distinction matters. The Action dataset counts security for AI. Narrative also includes AI used in security.So the prominence of AI in forecasts is not a second measurement of the same product category. It shows something broader: the market expects AI to alter several existing security domains at once.AI agents make that overlap particularly clear. Once an agent has credentials, access to tools and access to corporate data, the problem spreads beyond AI Security into Identity, Data Protection and policy enforcement.5.3. Identity: The Perimeter Becomes Non-HumanIdentity remains near the top under both counting methods.But the language around it is changing. Forecasts increasingly refer to machine and service identities, non-human identities, ephemeral credentials, ITDR, agent identity and the permissions of autonomous systems.This does not mean that the Identity market has become an NHI market. Human IAM remains part of the same Narrative.The change is narrower and more interesting: the definition of an identity worth controlling is expanding beyond the employee account.That is consistent with Action, where Machine Identity and Service Identity are the most repeated specialist launch areas.5.4. Platformization: The Gap Between Data and ControlsPlatformization is not a product category in the Action taxonomy, but it appears repeatedly in Narrative.The vocabulary varies: Unified Data, SIEM/XDR convergence, Security Operations platforms, tool consolidation, cross-domain analytics — but the underlying problem is similar: telemetry and context remain scattered across products that do not naturally share either data or decisions.This provides a useful counterpart to DSA.There is no one-to-one mapping between Platformization in Narrative and DSA in Action. But both point to the same pressure: security data is becoming more useful when it can be combined across domains rather than kept inside separate tools.5.5. Exposure Management and PQC: Two Different PathsExposure Management behaves differently from AI, Identity or Platformization.It barely appears as a standalone forecast category when documents are counted. But when related material is grouped by organization, Exposure forms a distinct theme across 10 of the 19 sources.That fits the Action data unusually well. A specialist product market already exists, while the language used to describe it is still consolidating.In other words, the products appear to have arrived before the category name was fully settled.PQC is almost the opposite case.Post-Quantum Cryptography and crypto-agility appear consistently in Narrative, but lower in the ranking. Unlike Exposure, the Action taxonomy does not measure PQC product breadth directly.Its importance therefore comes from a different set of signals: standards, migration planning and infrastructure change. Much of that transition is being driven outside the security-vendor sample: by standards bodies, cloud and infrastructure providers, cryptographic libraries and HSM vendors.PQC is already part of the long-term agenda. This study cannot say how broad its standalone product market is.5.6. Narrative Is Also MarketingThere is an obvious bias in this layer: 11 of the 19 organizations are the TOP-11 vendors themselves.Their forecasts may reflect early visibility into customer requests, incidents and product competition. They are also part of their go-to-market.Narrative should therefore be read as evidence of what the industry is trying to make important as well as what it believes will become important.Regulation creates a different blind spot.NIS2, DORA and the EU AI Act all fall within or close to the research window, yet regulation barely appears as a separate market theme. That does not mean it is unimportant. Regulatory requirements are usually translated into demands for asset visibility, investigation, retention, reporting and control rather than bought as a category called “compliance.”Some of that demand may therefore appear indirectly inside DSA, Exposure Management, Identity or Data Protection.This study cannot measure how much. It measures supply and industry attention, not the reason a customer eventually signs a purchase order.The Narrative layer therefore adds two things to Action. It shows where market language is catching up with products, as in Exposure, and where attention is running ahead of measurable product breadth, as in PQC.The next layer asks whether the same directions are also visible in technical work, conference program and commercial positioning.6. Development & PositioningAction shows where vendors have already committed resources. Narrative shows what the industry says will matter. A third view comes from patents, conference program and Expo positioning.These datasets measure different things and should not be combined into a ranking. Patents provide evidence of technical work; Talks show professional attention; Expo shows how vendors are packaging themselves commercially.The differences between them are often more useful than the absolute growth rates.AI is rising strongly in conference attention and faster still in commercial positioning. Identity points in the same direction across both. Data Protection & DSPM is growing much faster at Expo than in conference programs. PQC remains more visible in professional discussion than in commercial presence.6.1. Patents: Technical Work Behind the Market LabelsPatent counts are not comparable between companies. Jurisdiction, company age, filing strategy and publication lag make such comparisons unreliable. I use the material only to see whether the market categories correspond to identifiable engineering problems.Four motifs occur.In Identity, the technical subject is moving beyond the employee account. The material covers device signals, machine and service access, credentials and certificates. Okta describes flexible service access driven by the identity provider (US12170676B1); Tanium covers enterprise certificate management (US12671595); SentinelOne addresses attacks that reuse or pass existing credentials (US12452273B2).In Exposure Management, the emphasis moves from finding vulnerabilities to establishing context: asset importance, network topology, attack paths and risk ranking. Palo Alto Networks describes vulnerability impact assessment tailored to the network (US12432248B2); BitSight treats asset importance ranking as a problem in its own right, ahead of prioritisation (US12348485).In Data Protection, the chain increasingly runs from discovery to classification, ownership, exposure and policy. Cyera’s material covers data discovery in cloud environments (US12499083B2) and dynamic policy generation (US12407737B1). The problem is no longer simply preventing a file from leaving a system; it begins with knowing what the data is and why it matters.In Security Operations, the recurring theme is the connection between analytics and action. Cisco describes dynamic adaptive defence that changes controls as a threat evolves (US11985160B2); SentinelOne describes endpoint controls that adapt to the current risk level (US20240089273A1); BitSight covers generation of security improvement plans (US12223060B2).Patents do not show whether these mechanisms are widely deployed in production. They do show that several categories visible in Action and Narrative correspond to concrete technical problems rather than market labels alone.6.2. Talks and Expo: Different Signal ProfilesThe conference dataset contains 3,075 Talks across 20 security conferences in 2024 and 2025.Talks are used here as a measure of professional and research attention. Expo counts represent vendor-side commercial positioning. Their absolute values are not directly comparable, but their movement can still be compared.The percentages also need context. AI Expo presence doubled from 55 to 110 vendors, but its absolute presence still remained well below Identity and Cloud. PQC increased by 20%, but that meant a rise from only 25 to 30.The useful question is therefore not which percentage is largest, but what kind of profile each direction shows.AI: Attention Rises, Positioning Rises FasterThe conference AI category is broader than AI Security in Action. It includes both security for AI and the use of AI inside security operations.Even with that limitation, the direction is clear. Talks on AI rose by 52% in raw count and Expo positioning doubled — the fastest growth of any direction in this dataset.The discussion is also moving beyond prompt injection and basic LLM vulnerabilities toward agent security, model and inference protection, AI supply chains and the use of LLMs in Detection Engineering.This does not duplicate the Action result. Action shows that large platforms have already entered AI Security. Conferences show that the surrounding technical and professional problem space is still expanding.Identity / NHI: Strong Cross-Layer AlignmentIdentity increased by 63% in Talks and 58% in Expo positioning.The two percentages should not be treated as equal growth rates: the datasets have different denominators. What matters is that both move in the same direction.Conference programs increasingly discuss non-human and agent identities, identity resilience, machine credentials and service access. This overlaps with the Machine Identity and Service Identity launches visible in Action and with the Identity Narrative.The signal is broader than NHI alone, but NHI is clearly one of the areas where new attention is concentrated.Data Protection & DSPM: Positioning Runs AheadThe profile is different for Data Protection & DSPM.Talks rose by 14% in raw count, but their share of the overall conference program remained almost unchanged at 4.9%. Expo positioning, meanwhile, increased by about 65%. AI shows the same ordering, but there conference attention is growing strongly as well. Here it is not.Vendors are increasingly packaging data discovery, classification, permission exposure, shadow data and protection of data used in AI workloads as a distinct commercial category.That is a real positioning signal. It is not evidence of equivalent buyer demand.The gap could indicate an early market taking shape. It could equally mean that vendors are moving faster than customers. These datasets cannot distinguish between the two.PQC: Preparation Before a Broad Product WavePQC rose by 33% in Talks and 20% in Expo positioning, from a much smaller base than AI or Identity.Conference programs concentrate on crypto-agility, migration planning, implementation risk and the replacement of existing cryptography.That fits the Narrative layer, where PQC is already a recurring strategic topic. But because PQC sits outside the main Action taxonomy, this study cannot compare its product breadth directly with the other directions.For now, the visible signal is preparation for an infrastructural transition rather than evidence of a broad standalone product wave.6.3. One Market, Several TrajectoriesBy this point the six directions no longer look like stages of one common maturity curve.AI already combines broad platform Action with rising attention and positioning.Identity shows one of the strongest alignments across Action, Narrative, Talks and Expo, with NHI emerging inside the broader domain.Exposure Management has a specialist product market before the large platforms have consolidated around it.Data Protection & DSPM is being packaged commercially faster than its Action or conference share is growing.PQC is advancing through professional preparation and infrastructure change, while its product breadth is outside the scope of the Action dataset.DSA follows another path again: broad Action, supported less by a named conference category than by recurring work around analytics, correlation and Security Operations.The point is not to force these signals into a single score. It is to see that several important security directions are moving, but by different mechanisms.The next step is to put those paths side by side.7. Where the Signals ConvergePutting the layers together produces a simpler picture than looking at any one of them alone.DSA, AI Security and Identity show the strongest alignment across the evidence. Exposure Management, Data Protection & DSPM and PQC do not. Their signals are real, but they take different forms. Three directions are confirmed across the layers in this sense and three are still forming.That distinction matters because markets do not necessarily move from discussion to product to consolidation in a fixed order. In this sample, some categories are being built by specialists before large platforms enter them; others are being packaged commercially before Action becomes broad; still others are being driven partly outside the security-vendor market.In Figure 6, being “in focus” refers to TOP-11 participation. A direction can already have a broad specialist market and still sit on the left of the chart.7.1. Three Aligned DirectionsDSA is the broadest Action cluster across the two samples, but the common thread is connectivity rather than a new product category. What holds the cluster together is not a single category but a common problem: connecting telemetry, analytics, investigation and response. Narrative describes much the same pressure through Platformization, Unified Data and consolidation.AI Security follows a different route. Its Action is concentrated among the large platforms, while the wider AI agenda is also expanding rapidly in forecasts, conferences and commercial positioning. Protecting AI is becoming part of the platform portfolio rather than emerging only as a specialist market.Identity is less broad in Action, but the direction of change is unusually consistent across the layers. The new activity is concentrated around machine, service and other non-human identities. This is better understood as a new front inside a mature Identity market than as a separate replacement for it.7.2. Three Divergent ProfilesExposure Management already has a relatively broad specialist product market, while TOP-11 participation remains limited. The open question is whether that specialist market remains independent or becomes consolidated into larger platforms.Data Protection & DSPM shows stronger commercial positioning than Action. Expo presence is rising much faster than its share of conference attention, while qualifying product activity remains narrow. That may indicate an early market forming; it may also be vendors positioning ahead of demand. The evidence does not resolve the difference.PQC follows another path altogether. It is visible in forecasts and professional discussion, but product breadth is outside the Action taxonomy used here. Much of the transition is likely to arrive through standards, infrastructure, libraries and cryptographic hardware rather than through a conventional security-product category.These are not three weaker versions of the same trend. They are three different market structures.7.3. What Asymmetry MeansThe important result is not that all six directions are growing. They are not moving in the same way.AI Security is already broad among the large platforms. Exposure Management, by contrast, remains mostly specialist-led. Identity is changing from within an established market rather than forming a new one beside it. DSA combines broad activity at the platform level with continued product development among specialists. Data Protection & DSPM is being positioned commercially faster than qualifying Action is appearing. PQC is moving through standards, infrastructure and preparation as much as through the security-vendor market itself.A single ranking would hide most of these differences.They also make it difficult to describe the market as moving through a common sequence from idea to product to mature category. Exposure already has products before the large platforms have consolidated around the category. DSPM has strong commercial positioning without equally broad Action. PQC is already part of the strategic agenda even though this study does not measure its product breadth on the same basis.The same market can therefore produce very different signals depending on where one looks. That is more useful than deciding which direction should be placed first or second on a trend list.7.4. What These Movements Have in Common ArchitecturallyAt the level of market categories, these directions have little in common. Look instead at the context each adds to a security decision, and the picture changes.DSA provides telemetry, correlation and risk context. Identity tells us who or what is acting. Exposure adds information about assets, dependencies and attack paths. Data Protection adds sensitivity, ownership and exposure of the data itself. AI introduces models, agents and data flows that also need to be understood and controlled.PQC is different. It is primarily an infrastructural cryptographic transition rather than another source of decision context.These capabilities can support different parts of the same decision process, but they do not create that process automatically.Products may tell an organization what happened, what is exposed, which identities are involved and which controls are technically available. They do not determine which action is appropriate for that organization, whether the action produced the intended result, or whether the same response should be used the next time a similar situation occurs.This is where the findings reconnect with Parts 1 and 2.The market is supplying more of the context required for a security decision outside any single enforcement point. The action itself may still be carried out through NGFW, IAM, EDR, cloud controls, SOAR or an ordinary operational change process.What connects those pieces is not another product category. It is the organization’s own decision process.That is the limited role of SADL in this article. It is not part of the market taxonomy and the data do not imply that organizations need another platform. It is simply one way of describing how separate sources of context, analysis and enforcement can be connected into a working cycle.The market can supply the components. The organization still has to decide how they are used together.7.5. What Would Change This PictureThe evidence above describes the period ending on 28 July 2026. The forecasts below are deliberately narrower. They are intended as tests of whether the patterns identified in the study continue.Between 29 July 2026 and 31 December 2027, I expect at least two Exposure Management specialists from the Broader Sample to be acquired by TOP-11 vendors.Over the same period, I expect at least eight of the eleven TOP-11 vendors to record a qualifying GA launch or closed acquisition in Machine Identity, Service Identity or Agent Identity. The current baseline is four TOP-11 vendors with a qualifying Machine or Service Identity event.Between 29 July 2026 and 31 December 2027, I expect PQC to move more slowly as a standalone security-product category: fewer than four TOP-11 vendors should record a qualifying GA launch explicitly positioned around PQC migration or crypto-agility.By the end of 2028, I expect Data Protection & DSPM to reach at least five TOP-11 vendors, with at least three of those qualifying events explicitly tied to AI data flows, AI applications or data used by AI systems.Over the same period to 31 December 2028, I also expect DSA to remain the broadest TOP-11 Action cluster, with at least five vendors recording further qualifying acquisitions in analytics, correlation or Security Operations capabilities.The same Action filter should be used when these forecasts are revisited: closed acquisitions by closing date, generally available products confirmed by public vendor disclosure, counted by distinct companies rather than announcement volume. Anyone re-running that count on the same eleven vendors at the stated dates should arrive at the same answer I would.Two factors outside vendor strategy could move these numbers on their own. A regulatory mandate could pull PQC migration forward. Consolidation inside TOP-11 itself would redistribute events rather than create them, because the sample is fixed. I have deliberately not built scenarios around either. The point of a falsifiable forecast is that it should be able to fail cleanly.They are forecasts rather than extensions of the dataset. If the market develops differently, the interpretation should change with it.8. Practical Conclusion: The Market Supplies the Components, the Organization Builds the CycleThe market picture above has a practical consequence, although it is not itself a finding of the study.Security vendors are supplying more of the information needed to understand a situation: telemetry, identity, asset relationships, data context and new AI actors. They are also supplying more ways to analyse that information and more ways to act on it.What they do not supply automatically is the decision between the two.A security event rarely determines its own response. The same attack path may justify immediate isolation in one system and additional monitoring in another. The difference may depend on the importance of the asset, the identity involved, the data at risk, existing controls and the operational cost of intervention.Nor does a decision require a new universal enforcement layer. The action may still be carried out through an NGFW, IAM or PAM system, EDR, a cloud control, SOAR, or an ordinary change process. The useful question is not whether one platform contains all of these functions, but whether the organization can bring together enough context to choose the right action.There is another step that is easy to lose. Applying a control is not the same as solving the problem.A blocked account may stop an incident and interrupt a critical process. A network change may reduce exposure and create an availability problem. A stricter policy may work technically while producing so many exceptions that its practical value disappears.The result therefore has to be checked.If the action worked, and its side effects were acceptable, the organization has learned something that can be used again. A repeated decision can gradually become a rule, a playbook or an automated response. Automation makes more sense after the conditions and consequences of an action are understood than before them.That distinction becomes more important as the market moves toward AI-assisted and increasingly autonomous security operations. An automatically generated recommendation and an automatically authorized action are not the same thing. For a well-understood and repeatable scenario the two may eventually converge. For a new or expensive action, there should still be a control point between them.This is the connection to the SADL cycle used in the earlier parts of the series:Profile → Assess → Decide → Act → Verify → PatternI do not treat this cycle as another product layer implied by the market data. It is simply a way to connect capabilities that increasingly exist.It also does not compete with NIST CSF. CSF describes which functions have to exist; this cycle describes the operational logic of a single decision inside them. Compared with a generic OODA loop, the difference is that Verify and Pattern are treated as explicit steps rather than as something that happens informally after the fact.An organization does not need to begin by redesigning its entire security architecture. One recurring decision is enough: isolate an endpoint, block a service account, remediate an exposure, or respond to suspicious activity by an AI agent. The useful test is whether the organization can assemble the necessary context, make the decision, execute it, verify the result and retain what it learned.The market can provide the components for that process.It cannot decide how an organization should put them together.9. ConclusionThe two samples do not describe the same market in the same way.Large platforms have moved broadly into AI Security. Exposure Management remains much more specialist-led. DSA is broad in both samples but develops through different mechanisms. Identity shows a new concentration around non-human actors. Data Protection & DSPM and PQC are visible for different reasons, but neither follows the same path as the first three.That is the main result of Part 3.It does not show that mature controls are becoming less important. The Action filter deliberately misses much of the development that happens inside established Network, Endpoint, Cloud and Application Security products. Nor does the study measure what customers have already adopted.What it does show is where new observable vendor activity is accumulating: increasingly around telemetry, analytics, identity, exposure, data and AI context that sits across several security domains.This is consistent with the argument developed in Parts 1 and 2, but it is not proof of it. NGFW remains an enforcement point. The change is that more of the information required to decide what that enforcement point should do is being produced elsewhere.The market is making a more connected security decision process technically possible.Building that process remains the organization’s job.The previous parts: “Part 1: The Evolution of the NGFW Market — Drivers, Trends, and Architectural Consequences” and “Part 2: NGFW Vendor Moves as Signals of an Architectural Shift”All reasoning, conclusions, and assessments presented in this article reflect my personal viewpoint. The material has been prepared exclusively based on publicly available sources (vendor materials, reports from analytical agencies, industry publications, and open news sources). These views do not reflect and cannot be interpreted as the official position of any organization with which I am currently or have previously been affiliated. The article is purely analytical and educational in nature and contains no internal or confidential information.More DataSupporting appendix with the Broader Sample composition, Action taxonomy and a summary of the Narrative, conference, Expo and patent source sets is available on GitHub.