{"id":26198,"date":"2026-09-21T15:15:07","date_gmt":"2026-09-21T23:15:07","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2026\/09\/21\/software-supply-chain-security-just-got-its-own-magic-quadrant-and-rl-is-in-it\/"},"modified":"2026-09-21T15:15:07","modified_gmt":"2026-09-21T23:15:07","slug":"software-supply-chain-security-just-got-its-own-magic-quadrant-and-rl-is-in-it","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2026\/09\/21\/software-supply-chain-security-just-got-its-own-magic-quadrant-and-rl-is-in-it\/","title":{"rendered":"Software Supply Chain Security Just Got Its Own Magic Quadrant \u2014\u00a0and RL Is In It"},"content":{"rendered":"<div class=\"rich-text_richText__UyrDZ\" data-anchor-headings=\"true\" data-component=\"rich-text\" data-reader-view=\"false\">\n<div class=\"payload-richtext\">\n<p>For years, software supply chain security (SSCS) lived like a teenager in the basement of a bigger house. It was a line item inside the sprawling application security testing (AST) world \u2014 important, occasionally praised at dinner, but never quite trusted with its own keys. Everybody nodded along about software bills of material (SBOMs) and provenance the way you nod along about flossing.\u00a0<\/p>\n<p>On June 17, the basement kid got the keys. Gartner published its very first<a href=\"https:\/\/www.reversinglabs.com\/2026-gartner-sscs-magic-quadrant\"> <span style=\"text-decoration:underline\">Magic Quadrant\u2122 for Software Supply Chain Security<\/span><\/a> (by analysts Aaron Lord, Johnny Walters, and Jason Gross), formally retiring its older Market Guide and giving the category a front door of its own. And we&#8217;ll skip the false modesty, because false modesty is exhausting: ReversingLabs was named \u201ca Visionary.\u201d\u00a0 More on what that means in a minute. But first, let\u2019s tackle the obvious question.<\/p>\n<p><strong>[ Download now:\u00a0<\/strong><a href=\"https:\/\/www.reversinglabs.com\/2026-gartner-sscs-magic-quadrant\"><strong>Gartner\u00ae Magic Quadrant\u2122 for Software Supply Chain Security<\/strong><\/a><strong>\u00a0]<\/strong><\/p>\n<p>A Gartner Magic Quadrant is a culmination of research in a specific market, giving you a wide-angle view of the relative positions of the market\u2019s competitors. A Magic Quadrant helps you quickly ascertain how well technology providers are executing their stated visions and how well they are performing against Gartner\u2019s market view.<\/p>\n<p>Positioned in the top right and you&#8217;re a Leader in the Magic Quadrant. Placed a bit lower in the lower right and you\u2019re in the Visionary quadrant.\u00a0<\/p>\n<p>I feel that the fact that this market now warrants its own Magic Quadrant is the real headline. The basement kid is now paying rent and buying a house.\u00a0<\/p>\n<ul class=\"list-bullet\">\n<li class=\"\" value=\"1\">2025 SSCS market revenue: $2.8B\u00a0<\/li>\n<li class=\"\" value=\"2\">SSCS market revenue forecast by 2030: $5B+\u00a0<\/li>\n<\/ul>\n<h2 id=\"what-we-feel-this-report-actually-covers\"><strong>What We Feel This Report Actually Covers\u00a0<\/strong><\/h2>\n<p>If you only remember one thing, remember this: SSCS is about the software you didn&#8217;t write but absolutely depend on. Open source, commercial third-party software, containers, and , increasingly, AI models, LLMs, and even MCP servers \u2014 the stuff that arrives from upstream and quietly becomes load-bearing inside your business.\u00a0<\/p>\n<p>According to Gartner, the mandatory features for this market include:<\/p>\n<ul class=\"list-bullet\">\n<li class=\"\" value=\"1\"><strong>Third-party software risk protection:<\/strong> Finding and defanging risk in components you bring in from outside, via software composition analysis across source, containers, registries, and compiled binaries.\u00a0<\/li>\n<li class=\"\" value=\"2\"><strong>Software Bill of Materials (SBOM):<\/strong> Not just generating a bill of materials and filing it away, but storing, ingesting, and continuously analyzing it.\u00a0<\/li>\n<p><template id=\"P:8\"><\/template><\/ul>\n<p><template id=\"P:9\"><\/template><template id=\"P:a\"><\/template><template id=\"P:b\"><\/template><template id=\"P:c\"><\/template><template id=\"P:d\"><\/template><template id=\"P:e\"><\/template><template id=\"P:f\"><\/template><template id=\"P:10\"><\/template><template id=\"P:11\"><\/template><template id=\"P:12\"><\/template><template id=\"P:13\"><\/template><template id=\"P:14\"><\/template><template id=\"P:15\"><\/template><template id=\"P:16\"><\/template><template id=\"P:17\"><\/template><template id=\"P:18\"><\/template><template id=\"P:19\"><\/template><template id=\"P:1a\"><\/template><template id=\"P:1b\"><\/template><template id=\"P:1c\"><\/template><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>For years, software supply chain security (SSCS) lived like a teenager in the basement of a bigger house. It was a line item inside the sprawling application security testing (AST) world \u2014 important, occasionally praised at dinner, but never quite trusted with its own keys. Everybody nodded along about software bills of material (SBOMs) and provenance the way you nod along about flossing.On June 17, the basement kid got the keys. Gartner published its very firstMagic Quadrant\u2122 for Software Suppl<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[32775],"tags":[],"class_list":["post-26198","post","type-post","status-publish","format-standard","hentry","category-reversinglabs"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26198","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=26198"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26198\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=26198"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=26198"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=26198"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}