# Cloud Application Security and Vulnerability Management Market

> Cloud application security and vulnerability management is worth USD 13.11 billion in 2025, lifted by cloud exposures and 24-hour disclosure clocks.

Publisher: Douglas Insights  
Author: Douglas Insights Research Desk  
Report code: DI-IT-10649  
Published: 2026-10-08  
Last updated: 2026-10-08  
Next review: Apr 2027  
Page: https://www.douglasinsights.com/cloud-application-security-and-vulnerability-management-market/

## Key figures

| Measure | Value | How it is built |
| --- | --- | --- |
| Market size · 2025 | $13.11 Bn | 182,400 subscribing organisations x USD 71,850 = USD 13.11 billion |
| Forecast · 2035 | $33.07 Bn | USD 13.11 billion compounded at 9.70% for ten years |
| Revenue CAGR · 2026-2035 | 9.70% | 1.064 x 1.031 - 1 |
| Volume · 2035 | 339,200 organisations | 182,400 subscribers growing 6.4% a year |
| Leading segment | Cloud security posture management, 34.6% | USD 4.53 billion in 2025 |
| Fastest segment | Application and code security testing, 12.2% | Disclosure clocks push testing before release |
| Fastest region | Asia Pacific, 11.6% | USD 2.70 billion in 2025 to USD 8.09 billion in 2035 |
| Market leader | Palo Alto Networks, 9.1% (estimate) | Douglas Insights ledger; top three hold 24.8% |
| Event | Google completed Wiz acquisition, 11 March 2026 | https://blog.google/innovation-and-ai/infrastructure-and-cloud/google-cloud/wiz-acquisition/ |

## Key takeaways

- Cloud application security and vulnerability management revenue reaches USD 13.11 billion in 2025 and USD 33.07 billion by 2035, a 9.70% CAGR.
- Subscriber growth of 6.4% a year supplies most of the gain: 2.7 points from cloud exposure, 1.6 from disclosure clocks and 2.1 from consolidation.
- Cloud security posture management leads with 34.6%; application and code security testing grows fastest at 12.2% a year.
- North America holds 43.7% of 2025 revenue; Asia Pacific grows fastest at 11.6% a year.
- Douglas Insights estimates the top three vendors hold 24.8%, led by Palo Alto Networks at 9.1%, after Google closed the Wiz deal on 11 March 2026.

Amazon Inspector bills USD 0.09 for the first scan of a container image pushed to a registry and USD 0.01 for each rescan, so one image is checked again and again as new vulnerability records land against its packages. The Cloud Application Security and Vulnerability Management market covers the subscriptions that find, rank and track those flaws across cloud accounts, workloads, containers and application code. Douglas Insights puts 2025 revenue at USD 13.11 billion: 182,400 subscribing organisations multiplied by an average annual spend of USD 71,850. We project USD 33.07 billion by 2035, a revenue CAGR of 9.70% built from 6.4% subscriber growth and 3.1% annual price growth. The largest consolidation event so far closed on 11 March 2026, when [Google completed its acquisition of Wiz](https://blog.google/innovation-and-ai/infrastructure-and-cloud/google-cloud/wiz-acquisition/), a cloud and AI security platform working across AWS, Google Cloud, Microsoft Azure and Oracle Cloud. The study belongs to our [enterprise software](https://www.douglasinsights.com/industry/ict-semiconductors/enterprise-software/) coverage, and every number follows the [research methodology](https://www.douglasinsights.com/research-methodology/) used across Douglas Insights reports.

## Why are cloud attack surfaces and exploited CVEs pushing demand for cloud vulnerability management?

Subscriber growth of 6.4% a year drives cloud application security and vulnerability management to USD 33.07 billion by 2035. Exposures have moved into cloud accounts, regulators now set disclosure clocks and buyers are consolidating posture, workload and code scanning into one subscription.

Exposure location is the first and largest driver, worth 2.7 points of the 6.4% volume leg. Unit 42 research quoted by Palo Alto Networks found that 80% of security exposures sat in cloud attack surfaces, with a 66% increase in threats targeting cloud environments, figures published when the company [merged Prisma Cloud with Cortex CDR to form Cortex Cloud](https://www.paloaltonetworks.com/company/press/2025/palo-alto-networks-introduces-cortex-cloud--the-future-of-real-time-cloud-security) on 13 February 2025. A security team that sees four in five exposures in the cloud moves budget there. Douglas Insights counts that shift as the main reason subscriber numbers rise from 182,400 in 2025 to about 339,200 organisations by 2035.

Disclosure deadlines add 1.6 points. European manufacturers of products with digital elements must now send an early warning within 24 hours of learning about an actively exploited vulnerability and a full notification within 72 hours. No team meets a 24-hour clock with a quarterly scan. Continuous cloud vulnerability scanning, software bills of materials and exploit tracking become the evidence trail that lets a product security officer file on time, and mid-sized software makers that never bought a scanner now open accounts.

Platform consolidation contributes the remaining 2.1 points. Palo Alto Networks reported Next-Generation Security annual recurring revenue (ARR) of USD 5.6 billion for fiscal 2025, up 32%, and CrowdStrike reported ending ARR of USD 5.25 billion, up 24%. Both numbers include far more than cloud scanning. Still, they show buyers paying for platforms that fold cloud security posture management (CSPM), workload protection and detection into one console. Wiz, whose customers include 50% of the Fortune 100, is now inside Google Cloud, and that pulls multicloud scanning into deals that were once infrastructure-only.

AI workloads sharpen all three drivers. Each model endpoint, vector store and training bucket is another cloud resource to configure and scan, and Douglas Insights reckons AI services will add about 9% to the average number of scanned resources per subscriber by 2028. Those extra resources raise spend per account rather than the subscriber count, so we book them in the 3.1% price leg, not in the volume leg.

The three drivers sum to 6.4 points: 2.7 from exposure location, 1.6 from disclosure clocks and 2.1 from consolidation. Price adds 3.1% on top, giving the 9.70% revenue path.

## Which headwinds slow cloud vulnerability management budgets, from alert fatigue to free native scanners?

Three headwinds remove about 2.3 points from cloud application security and vulnerability management volume growth. They are free or cheap hyperscaler scanners, stalled renewals at legacy scanning vendors, and alert volumes that security teams cannot triage in time, across all five regions.

Native tools cap prices first, removing 0.9 points. Microsoft offers foundational CSPM in Defender for Cloud at no charge, and Amazon Inspector charges USD 1.258 per instance-month for agent-based EC2 scanning and USD 0.30 per Lambda function. A 500-instance estate costs about USD 7,548 a year to scan with the native agent. That is roughly a tenth of what an average subscriber spends with an independent vendor.

Renewal stalls at older vulnerability management vendors remove 0.8 points. Rapid7 ended 2025 with ARR of USD 840 million, flat year over year, on total revenue of USD 860 million that grew only 2%. Flat ARR at a vendor with over 11,500 customers shows that buyers are not adding seats to scanners built for data-centre networks.

Triage overload removes the last 0.6 points. Douglas Insights estimates that a typical enterprise cloud estate produces more open findings than its team can close in a quarter, so buyers delay expansion until prioritisation tools cut the queue. Without these three headwinds the volume leg would run near 8.7% rather than 6.4%.

## Which segment makes the money in cloud application security: posture management, workload scanning or code testing?

Cloud security posture management makes the most money, with 34.6% of 2025 revenue or USD 4.53 billion, because every cloud account needs configuration checks before any workload or application code is scanned for vulnerabilities. Posture licences are also the entry product most platform vendors sell first.

| Segment | Share 2025 | Value 2025 | CAGR 2026-2035 | Value 2035 |
| --- | --- | --- | --- | --- |
| Cloud security posture management | 34.6% | USD 4.53 billion | 10.6% | USD 12.42 billion |
| Cloud workload vulnerability scanning | 29.3% | USD 3.84 billion | 7.7% | USD 8.06 billion |
| Application and code security testing | 21.8% | USD 2.86 billion | 12.2% | USD 9.03 billion |
| Risk-based vulnerability prioritisation | 14.3% | USD 1.87 billion | 6.6% | USD 3.55 billion |

Cloud security posture management reaches USD 12.42 billion by 2035 at 10.6% a year, because identity and AI-service misconfigurations keep adding checks. Cloud workload vulnerability scanning holds 29.3%, or USD 3.84 billion, and grows 7.7% to USD 8.06 billion; it is the most price-pressured line, since agent-based and agentless instance scans are the features hyperscalers sell most cheaply.

Application and code security testing is the fastest-growing segment at 12.2% a year, rising from USD 2.86 billion to USD 9.03 billion. Its 21.8% share grows because the 24-hour disclosure clock pushes software makers to find flaws in code and dependencies before release. Risk-based vulnerability prioritisation carries 14.3%, worth USD 1.87 billion, and grows 6.6% to USD 3.55 billion; buyers prize it, but platforms increasingly bundle it into posture licences.

## Is agentless scanning replacing agent-based cloud workload vulnerability scanning?

Agentless scanning costs 39% more per instance on Amazon Inspector, USD 1.75 against USD 1.258 a month. It still wins most new cloud vulnerability management deployments because nothing must be installed or patched on the workload, and short-lived instances are covered from their first hour.

Agent-based scanning keeps two advantages: near real-time runtime visibility and lower list price. Agentless scanning wins on coverage, since it reaches short-lived instances that would never run an agent. Douglas Insights expects agentless methods to account for close to 58% of new cloud workload scanning seats in 2026. Container image scanning shows the same logic: USD 0.09 for the first scan and USD 0.01 per rescan, so a busy registry is billed mostly on rescans.

## Which buyers, from banks to software makers, spend most on cloud vulnerability management subscriptions?

Banking and financial services spend the most, about 27.4% of 2025 cloud application security and vulnerability management revenue by Douglas Insights estimates, because supervisors expect documented patch timelines for every internet-facing cloud workload. Software and technology firms come second and add accounts fastest.

Software and technology firms follow at about 24.9% and add accounts fastest, near 8.8% a year, because they ship the code that the 24-hour disclosure clock covers. Healthcare holds about 11.7%, government about 10.2% and retail about 8.6%, with the rest spread across energy, telecoms and manufacturing. By deployment, agentless scanning wins most new cloud accounts, while agent-based sensors stay in regulated runtime estates where a bank or a hospital wants a sensor on every host.

## Which region buys the most cloud application security and vulnerability scanning?

North America buys the most, with USD 5.73 billion or 43.7% of 2025 revenue, because the largest hyperscaler footprints and software makers sit there; Asia Pacific grows fastest. Its 11.6% annual rate is ahead of Latin America at 10.4% and Europe at 9.3%.

North America grows 8.9% a year to USD 13.43 billion by 2035. Europe holds 25.9%, worth USD 3.39 billion, and grows 9.3% to USD 8.26 billion, lifted by Cyber Resilience Act reporting. Asia Pacific starts at USD 2.70 billion, a 20.6% share, and reaches USD 8.09 billion, because Douglas Insights models banks and software exporters in India, Japan, Australia and Singapore moving production workloads into public cloud fastest. Latin America is worth USD 602.8 million, 4.6% of the total, and grows 10.4% to USD 1.62 billion on our model of multicloud adoption by Brazilian and Mexican banks. The Middle East and Africa holds USD 681.5 million, or 5.2%, and grows 9.35% to USD 1.67 billion.

The wildcard is the Gulf. Douglas Insights treats sovereign cloud programmes there as the swing factor: if buyers insist that scanners run inside national regions, the Middle East and Africa share rises above 6.0% by 2035.

## Who wins cloud application security and vulnerability management contracts after Google bought Wiz?

Platform vendors win most contracts: Douglas Insights estimates the top three, Palo Alto Networks, Google with Wiz and Tenable, hold 24.8% of 2025 revenue, with Palo Alto Networks leading on a 9.1% share. Shares are anchored on disclosed revenue, ARR and customer counts.

Palo Alto Networks builds its lead on Cortex Cloud, which joined Prisma Cloud posture and code scanning with cloud detection and response. Google entered the top tier by closing the Wiz acquisition described in the opening; Wiz links code, cloud and runtime data in one context and counts Shell, BMW, Morgan Stanley and Salesforce among its customers. Douglas Insights puts the combined Google and Wiz share at 8.2%.

Tenable is the largest independent vulnerability management vendor. It [reported 2025 revenue of USD 999.4 million](https://investors.tenable.com/node/14706/html), up 11%, added 502 new enterprise platform customers and serves over 40,000 customers; we credit it with 7.5%. Rapid7 reported revenue of USD 860 million and ARR of USD 840 million from over 11,500 customers, and holds an estimated 4.2%.

Qualys [reported 2025 revenue of USD 669.1 million](https://www.qualys.com/company/newsroom/news-releases/usa/2026-02-05-qualys-announces-fourth-quarter-and-full-year-2025-financial-results), up 10% from USD 607.6 million, from more than 10,000 subscription customers, worth an estimated 5.1% share. Microsoft, at 6.3%, sells Defender for Cloud alongside Azure consumption. CrowdStrike, at 3.9%, adds cloud workload modules to its endpoint base. The seven named vendors hold 44.3%; the remaining 55.7% is spread across code security specialists and regional providers.

| Company | What the position rests on | Douglas Insights share 2025 |
| --- | --- | --- |
| Palo Alto Networks | Cortex Cloud, merged from Prisma Cloud and Cortex CDR | 9.1% |
| Google (Wiz) | Multicloud graph across four clouds | 8.2% |
| Tenable | Exposure management, over 40,000 customers | 7.5% |
| Microsoft | Defender for Cloud on Azure | 6.3% |
| Qualys | Cloud platform, over 10,000 subscription customers | 5.1% |
| Rapid7 | Exposure command, over 11,500 customers | 4.2% |
| CrowdStrike | Falcon cloud workload modules | 3.9% |

## How much do buyers pay for cloud vulnerability scanning per instance, image and subscription?

Buyers pay from USD 15 a year for one natively scanned instance to about USD 71,850 a year for an average vendor subscription. The spread is set by how many clouds, workloads and code repositories the cloud application security contract covers.

The native floor is clear on [Amazon Inspector pricing](https://aws.amazon.com/inspector/pricing/): USD 1.258 per instance-month agent-based, USD 1.75 agentless, USD 0.30 per Lambda function for standard scanning plus USD 0.60 for code scanning. On an annual basis one agent-based instance costs USD 15.10 and one agentless instance USD 21.00.

Vendor disclosures set the middle band. Qualys revenue divided by its customer count gives under USD 66,910 per customer a year; Rapid7 gives about USD 74,780; Tenable, with a long tail of small accounts, gives about USD 24,985. The Douglas Insights average of USD 71,850 per subscriber rises 3.1% a year to about USD 97,500 by 2035, as buyers add code and AI-workload modules rather than pay higher list prices for the same scans.

## Douglas Exclusive: the Cloud Exposure Spend Ledger

The Cloud Exposure Spend Ledger is a Douglas Insights model built from 14 sourced inputs. Those are seven vendor disclosures (revenue, ARR or customer counts from Palo Alto Networks, Google, Tenable, Microsoft, Qualys, Rapid7 and CrowdStrike), four Amazon Inspector list prices and three Cyber Resilience Act reporting deadlines. It is our estimate, not an official register.

The ledger assigns each vendor an estimated slice of the USD 13.11 billion cloud application security and vulnerability management total, anchored on what it discloses.

| Vendor | Disclosed anchor | Ledger share | Ledger revenue 2025 |
| --- | --- | --- | --- |
| Palo Alto Networks | Next-Generation Security ARR USD 5.6 billion, fiscal 2025 | 9.1% | USD 1.19 billion |
| Google (Wiz) | Used by 50% of the Fortune 100; covers four clouds | 8.2% | USD 1.07 billion |
| Tenable | 2025 revenue USD 999.4 million | 7.5% | USD 982.9 million |
| Microsoft | Defender for Cloud, foundational CSPM free | 6.3% | USD 825.6 million |
| Qualys | 2025 revenue USD 669.1 million | 5.1% | USD 668.4 million |
| Rapid7 | 2025 revenue USD 860 million, ARR USD 840 million | 4.2% | USD 550.4 million |
| CrowdStrike | Ending ARR USD 5.25 billion, 31 January 2026 | 3.9% | USD 511.1 million |

The finding: the seven largest vendors capture 44.3% of spend, and an average subscription of USD 71,850 equals the native price of about 4,760 agent-based instance-years. That gap persists because buyers pay for prioritisation and remediation workflow, not the scan itself. Our ledger shows that a vendor charging only for scans competes with a USD 15.10 floor.

## What do the Cyber Resilience Act reporting rules mean for vulnerability management vendors?

Since 11 September 2026, manufacturers selling products with digital elements in the EU must report actively exploited vulnerabilities within 24 hours. That rule turns cloud vulnerability management from an audit tool into a compliance clock for every software maker selling into the 27 member states.

Under [Regulation (EU) 2024/2847 reporting obligations](https://digital-strategy.ec.europa.eu/en/policies/cra-reporting), manufacturers send an early warning within 24 hours, a full notification within 72 hours and a final report no later than 14 days after a corrective measure is available. Open-source software stewards follow from 11 December 2027. Douglas Insights counts the 24-hour deadline as worth 1.6 points of subscriber growth through 2030, because the rule reaches software makers that sell to European buyers wherever they are based.

## What would move the 2035 outlook for cloud application security and vulnerability management?

The base case reaches USD 33.07 billion in 2035, against USD 25.54 billion on a slower path and USD 41.87 billion on a faster one. The gap depends mainly on how quickly subscriber growth spreads beyond the largest cloud users.

The slower case assumes 4.6% subscriber growth and 2.2% price growth, with hyperscaler bundling eroding independent prices. The faster case assumes 8.1% subscriber growth and 3.9% price growth, with AI workloads and the Google and Wiz combination pushing posture scanning into every cloud deal. Moving volume growth up by one point lifts the 2035 total to USD 36.31 billion; moving it down one point gives USD 30.09 billion. Published forecasts for related scopes run from 8.0% to 32.6% a year, and our 9.70% sits near the lower-middle of that range, because we count subscriptions rather than total security budgets.

## Methodology: how do 182,400 security subscribers multiply into a USD 13.11 billion total?

The cloud application security and vulnerability management total is 182,400 subscribing organisations times USD 71,850, equal to USD 13.11 billion, built from 14 sourced inputs and split across five regions. Each step below can be repeated from public disclosures and list prices.

Subscriber counts start from disclosed customer bases: over 40,000 at Tenable, over 11,500 at Rapid7 and over 10,000 at Qualys, then add platform and hyperscaler buyers. The average spend checks against vendor revenue per customer: USD 71,850 sits within 4% of Rapid7's USD 74,780 and 7% above the Qualys ceiling. Regional rows sum to USD 13.11 billion in 2025 and USD 33.07 billion in 2035. Segment values sum to the 2025 total exactly and to the 2035 total within 0.02%.

For neighbouring markets, see our [Cybersecurity Mesh Market](https://www.douglasinsights.com/cybersecurity-mesh-market/), the [Industrial Cybersecurity and OT Protection Market](https://www.douglasinsights.com/industrial-cybersecurity-and-ot-protection-market/) and the [Online Cloud Backup Service Market](https://www.douglasinsights.com/online-cloud-backup-service-market/).

## Market by segment

| Segment | Share | Value |
| --- | --- | --- |
| Cloud security posture management | 34.6% | $4.53 Bn |
| Cloud workload vulnerability scanning | 29.3% | $3.84 Bn |
| Application and code security testing | 21.8% | $2.86 Bn |
| Risk-based vulnerability prioritisation | 14.3% | $1.87 Bn |

## Market by region (USD million)

| Region | 2025 | 2026 | 2035 | CAGR 2026-2035 |
| --- | --- | --- | --- | --- |
| Global | 13,105.4 | 14,376.4 | 33,071.4 | 9.7% |
| North America | 5,727.1 | 6,236.8 | 13,434.3 | 8.9% |
| Europe | 3,394.3 | 3,710 | 8,259.5 | 9.3% |
| Asia Pacific | 2,699.7 | 3,012.9 | 8,090.2 | 11.6% |
| Latin America | 602.8 | 665.5 | 1,621.3 | 10.4% |
| Middle East and Africa | 681.5 | 745.2 | 1,666.1 | 9.35% |

## Dataset

| Series | Value | Unit |
| --- | --- | --- |
| Market size 2025 | 13,105.4 | USD million |
| Market size 2035 | 33,071.4 | USD million |
| Revenue CAGR 2026-2035 | 9.7 | percent |
| Volume CAGR 2026-2035 | 6.4 | percent |
| Price per subscriber CAGR 2026-2035 | 3.1 | percent |

## Frequently asked questions

### What does an average organisation spend a year on cloud application security and vulnerability management?

USD 71,850 in 2025 by Douglas Insights estimates, rising about 3.1% a year to roughly USD 97,500 by 2035 as buyers add code and AI-workload modules.

### How much revenue does the cloud vulnerability management field generate in 2025 and 2035?

USD 13.11 billion in 2025 and USD 33.07 billion in 2035, a revenue CAGR of 9.70% from 6.4% subscriber growth and 3.1% price growth.

### Why does cloud security posture management hold the largest share?

34.6% of 2025 revenue, or USD 4.53 billion, because every cloud account needs configuration checks before workloads or code are scanned.

### Which part of cloud application security expands quickest to 2035?

12.2% a year for application and code security testing, from USD 2.86 billion to USD 9.03 billion, as disclosure deadlines push testing before release.

### What does Amazon Inspector charge to scan a cloud instance?

USD 1.258 per instance-month for agent-based EC2 scanning and USD 1.75 for agentless scanning, or USD 15.10 and USD 21.00 a year.

### How concentrated is the vendor field after the Wiz deal?

24.8% of 2025 revenue sits with Palo Alto Networks, Google with Wiz and Tenable by Douglas Insights estimates; Palo Alto Networks leads with 9.1%.

### What reporting deadlines does the Cyber Resilience Act set for exploited vulnerabilities?

24 hours for an early warning, 72 hours for a full notification and 14 days after a fix for the final report, applying to manufacturers since 11 September 2026.

### Where is spending on cloud vulnerability scanning growing quickest?

11.6% a year in Asia Pacific, from USD 2.70 billion in 2025 to USD 8.09 billion in 2035, the fastest of the five regions.

## Sources

- [Google, Google completes acquisition of Wiz](https://blog.google/innovation-and-ai/infrastructure-and-cloud/google-cloud/wiz-acquisition/)
- [European Commission, Cyber Resilience Act: reporting obligations](https://digital-strategy.ec.europa.eu/en/policies/cra-reporting)
- [Palo Alto Networks, Palo Alto Networks introduces Cortex Cloud](https://www.paloaltonetworks.com/company/press/2025/palo-alto-networks-introduces-cortex-cloud--the-future-of-real-time-cloud-security)
- [Tenable, Tenable fourth quarter and full year 2025 results](https://investors.tenable.com/node/14706/html)
- [Qualys, Qualys fourth quarter and full year 2025 results](https://www.qualys.com/company/newsroom/news-releases/usa/2026-02-05-qualys-announces-fourth-quarter-and-full-year-2025-financial-results)
- [Amazon Web Services, Amazon Inspector pricing](https://aws.amazon.com/inspector/pricing/)
- [Rapid7, Rapid7 fourth quarter and full year 2025 results](https://investors.rapid7.com/news/news-details/2026/Rapid7-Announces-Fourth-Quarter-and-Full-Year-2025-Financial-Results/)
- [Palo Alto Networks, Palo Alto Networks fiscal 2025 results](https://www.paloaltonetworks.com/company/press/2025/palo-alto-networks-reports-fiscal-fourth-quarter-and-fiscal-year-2025-financial-results)
- [CrowdStrike, CrowdStrike fourth quarter and fiscal 2026 results](https://ir.crowdstrike.com/news-releases/news-release-details/crowdstrike-reports-fourth-quarter-and-fiscal-year-2026)

## How to cite

Douglas Insights, "Cloud Application Security and Vulnerability Management Market", DI-IT-10649, updated 2026-10-08, https://www.douglasinsights.com/cloud-application-security-and-vulnerability-management-market/
