Software Supply Chain Security Just Got Its Own Magic Quadrant — and RL Is In It
For years, software supply chain security (SSCS) lived like a teenager in the basement of a bigger house. It was a line item inside the sprawling application security testing (AST) world — important, occasionally praised at dinner, but never quite trusted with its own keys. Everybody nodded along about software bills of material (SBOMs) and provenance the way you nod along about flossing.
On June 17, the basement kid got the keys. Gartner published its very first Magic Quadrant™ for Software Supply Chain Security (by analysts Aaron Lord, Johnny Walters, and Jason Gross), formally retiring its older Market Guide and giving the category a front door of its own. And we’ll skip the false modesty, because false modesty is exhausting: ReversingLabs was named “a Visionary.” More on what that means in a minute. But first, let’s tackle the obvious question.
[ Download now: Gartner® Magic Quadrant™ for Software Supply Chain Security ]
A Gartner Magic Quadrant is a culmination of research in a specific market, giving you a wide-angle view of the relative positions of the market’s competitors. A Magic Quadrant helps you quickly ascertain how well technology providers are executing their stated visions and how well they are performing against Gartner’s market view.
Positioned in the top right and you’re a Leader in the Magic Quadrant. Placed a bit lower in the lower right and you’re in the Visionary quadrant.
I feel that the fact that this market now warrants its own Magic Quadrant is the real headline. The basement kid is now paying rent and buying a house.
- 2025 SSCS market revenue: $2.8B
- SSCS market revenue forecast by 2030: $5B+
What We Feel This Report Actually Covers
If you only remember one thing, remember this: SSCS is about the software you didn’t write but absolutely depend on. Open source, commercial third-party software, containers, and , increasingly, AI models, LLMs, and even MCP servers — the stuff that arrives from upstream and quietly becomes load-bearing inside your business.
According to Gartner, the mandatory features for this market include:
- Third-party software risk protection: Finding and defanging risk in components you bring in from outside, via software composition analysis across source, containers, registries, and compiled binaries.
- Software Bill of Materials (SBOM): Not just generating a bill of materials and filing it away, but storing, ingesting, and continuously analyzing it.