Amazon Inspector bills USD 0.09 for the first scan of a container image pushed to a registry and USD 0.01 for each rescan, so one image is checked again and again as new vulnerability records land against its packages. The Cloud Application Security and Vulnerability Management market covers the subscriptions that find, rank and track those flaws across cloud accounts, workloads, containers and application code. Douglas Insights puts 2025 revenue at USD 13.11 billion: 182,400 subscribing organisations multiplied by an average annual spend of USD 71,850. We project USD 33.07 billion by 2035, a revenue CAGR of 9.70% built from 6.4% subscriber growth and 3.1% annual price growth. The largest consolidation event so far closed on 11 March 2026, when Google completed its acquisition of Wiz, a cloud and AI security platform working across AWS, Google Cloud, Microsoft Azure and Oracle Cloud. The study belongs to our enterprise software coverage, and every number follows the research methodology used across Douglas Insights reports.
Why are cloud attack surfaces and exploited CVEs pushing demand for cloud vulnerability management?
Subscriber growth of 6.4% a year drives cloud application security and vulnerability management to USD 33.07 billion by 2035. Exposures have moved into cloud accounts, regulators now set disclosure clocks and buyers are consolidating posture, workload and code scanning into one subscription.
Exposure location is the first and largest driver, worth 2.7 points of the 6.4% volume leg. Unit 42 research quoted by Palo Alto Networks found that 80% of security exposures sat in cloud attack surfaces, with a 66% increase in threats targeting cloud environments, figures published when the company merged Prisma Cloud with Cortex CDR to form Cortex Cloud on 13 February 2025. A security team that sees four in five exposures in the cloud moves budget there. Douglas Insights counts that shift as the main reason subscriber numbers rise from 182,400 in 2025 to about 339,200 organisations by 2035.
Disclosure deadlines add 1.6 points. European manufacturers of products with digital elements must now send an early warning within 24 hours of learning about an actively exploited vulnerability and a full notification within 72 hours. No team meets a 24-hour clock with a quarterly scan. Continuous cloud vulnerability scanning, software bills of materials and exploit tracking become the evidence trail that lets a product security officer file on time, and mid-sized software makers that never bought a scanner now open accounts.
Platform consolidation contributes the remaining 2.1 points. Palo Alto Networks reported Next-Generation Security annual recurring revenue (ARR) of USD 5.6 billion for fiscal 2025, up 32%, and CrowdStrike reported ending ARR of USD 5.25 billion, up 24%. Both numbers include far more than cloud scanning. Still, they show buyers paying for platforms that fold cloud security posture management (CSPM), workload protection and detection into one console. Wiz, whose customers include 50% of the Fortune 100, is now inside Google Cloud, and that pulls multicloud scanning into deals that were once infrastructure-only.
AI workloads sharpen all three drivers. Each model endpoint, vector store and training bucket is another cloud resource to configure and scan, and Douglas Insights reckons AI services will add about 9% to the average number of scanned resources per subscriber by 2028. Those extra resources raise spend per account rather than the subscriber count, so we book them in the 3.1% price leg, not in the volume leg.
The three drivers sum to 6.4 points: 2.7 from exposure location, 1.6 from disclosure clocks and 2.1 from consolidation. Price adds 3.1% on top, giving the 9.70% revenue path.
Which headwinds slow cloud vulnerability management budgets, from alert fatigue to free native scanners?
Three headwinds remove about 2.3 points from cloud application security and vulnerability management volume growth. They are free or cheap hyperscaler scanners, stalled renewals at legacy scanning vendors, and alert volumes that security teams cannot triage in time, across all five regions.
Native tools cap prices first, removing 0.9 points. Microsoft offers foundational CSPM in Defender for Cloud at no charge, and Amazon Inspector charges USD 1.258 per instance-month for agent-based EC2 scanning and USD 0.30 per Lambda function. A 500-instance estate costs about USD 7,548 a year to scan with the native agent. That is roughly a tenth of what an average subscriber spends with an independent vendor.
Renewal stalls at older vulnerability management vendors remove 0.8 points. Rapid7 ended 2025 with ARR of USD 840 million, flat year over year, on total revenue of USD 860 million that grew only 2%. Flat ARR at a vendor with over 11,500 customers shows that buyers are not adding seats to scanners built for data-centre networks.
Triage overload removes the last 0.6 points. Douglas Insights estimates that a typical enterprise cloud estate produces more open findings than its team can close in a quarter, so buyers delay expansion until prioritisation tools cut the queue. Without these three headwinds the volume leg would run near 8.7% rather than 6.4%.
Which segment makes the money in cloud application security: posture management, workload scanning or code testing?
Cloud security posture management makes the most money, with 34.6% of 2025 revenue or USD 4.53 billion, because every cloud account needs configuration checks before any workload or application code is scanned for vulnerabilities. Posture licences are also the entry product most platform vendors sell first.
| Segment | Share 2025 | Value 2025 | CAGR 2026-2035 | Value 2035 |
|---|---|---|---|---|
| Cloud security posture management | 34.6% | USD 4.53 billion | 10.6% | USD 12.42 billion |
| Cloud workload vulnerability scanning | 29.3% | USD 3.84 billion | 7.7% | USD 8.06 billion |
| Application and code security testing | 21.8% | USD 2.86 billion | 12.2% | USD 9.03 billion |
| Risk-based vulnerability prioritisation | 14.3% | USD 1.87 billion | 6.6% | USD 3.55 billion |
Cloud security posture management reaches USD 12.42 billion by 2035 at 10.6% a year, because identity and AI-service misconfigurations keep adding checks. Cloud workload vulnerability scanning holds 29.3%, or USD 3.84 billion, and grows 7.7% to USD 8.06 billion; it is the most price-pressured line, since agent-based and agentless instance scans are the features hyperscalers sell most cheaply.
Application and code security testing is the fastest-growing segment at 12.2% a year, rising from USD 2.86 billion to USD 9.03 billion. Its 21.8% share grows because the 24-hour disclosure clock pushes software makers to find flaws in code and dependencies before release. Risk-based vulnerability prioritisation carries 14.3%, worth USD 1.87 billion, and grows 6.6% to USD 3.55 billion; buyers prize it, but platforms increasingly bundle it into posture licences.
Is agentless scanning replacing agent-based cloud workload vulnerability scanning?
Agentless scanning costs 39% more per instance on Amazon Inspector, USD 1.75 against USD 1.258 a month. It still wins most new cloud vulnerability management deployments because nothing must be installed or patched on the workload, and short-lived instances are covered from their first hour.
Agent-based scanning keeps two advantages: near real-time runtime visibility and lower list price. Agentless scanning wins on coverage, since it reaches short-lived instances that would never run an agent. Douglas Insights expects agentless methods to account for close to 58% of new cloud workload scanning seats in 2026. Container image scanning shows the same logic: USD 0.09 for the first scan and USD 0.01 per rescan, so a busy registry is billed mostly on rescans.
Which buyers, from banks to software makers, spend most on cloud vulnerability management subscriptions?
Banking and financial services spend the most, about 27.4% of 2025 cloud application security and vulnerability management revenue by Douglas Insights estimates, because supervisors expect documented patch timelines for every internet-facing cloud workload. Software and technology firms come second and add accounts fastest.
Software and technology firms follow at about 24.9% and add accounts fastest, near 8.8% a year, because they ship the code that the 24-hour disclosure clock covers. Healthcare holds about 11.7%, government about 10.2% and retail about 8.6%, with the rest spread across energy, telecoms and manufacturing. By deployment, agentless scanning wins most new cloud accounts, while agent-based sensors stay in regulated runtime estates where a bank or a hospital wants a sensor on every host.
Which region buys the most cloud application security and vulnerability scanning?
North America buys the most, with USD 5.73 billion or 43.7% of 2025 revenue, because the largest hyperscaler footprints and software makers sit there; Asia Pacific grows fastest. Its 11.6% annual rate is ahead of Latin America at 10.4% and Europe at 9.3%.
North America grows 8.9% a year to USD 13.43 billion by 2035. Europe holds 25.9%, worth USD 3.39 billion, and grows 9.3% to USD 8.26 billion, lifted by Cyber Resilience Act reporting. Asia Pacific starts at USD 2.70 billion, a 20.6% share, and reaches USD 8.09 billion, because Douglas Insights models banks and software exporters in India, Japan, Australia and Singapore moving production workloads into public cloud fastest. Latin America is worth USD 602.8 million, 4.6% of the total, and grows 10.4% to USD 1.62 billion on our model of multicloud adoption by Brazilian and Mexican banks. The Middle East and Africa holds USD 681.5 million, or 5.2%, and grows 9.35% to USD 1.67 billion.
The wildcard is the Gulf. Douglas Insights treats sovereign cloud programmes there as the swing factor: if buyers insist that scanners run inside national regions, the Middle East and Africa share rises above 6.0% by 2035.
Who wins cloud application security and vulnerability management contracts after Google bought Wiz?
Platform vendors win most contracts: Douglas Insights estimates the top three, Palo Alto Networks, Google with Wiz and Tenable, hold 24.8% of 2025 revenue, with Palo Alto Networks leading on a 9.1% share. Shares are anchored on disclosed revenue, ARR and customer counts.
Palo Alto Networks builds its lead on Cortex Cloud, which joined Prisma Cloud posture and code scanning with cloud detection and response. Google entered the top tier by closing the Wiz acquisition described in the opening; Wiz links code, cloud and runtime data in one context and counts Shell, BMW, Morgan Stanley and Salesforce among its customers. Douglas Insights puts the combined Google and Wiz share at 8.2%.
Tenable is the largest independent vulnerability management vendor. It reported 2025 revenue of USD 999.4 million, up 11%, added 502 new enterprise platform customers and serves over 40,000 customers; we credit it with 7.5%. Rapid7 reported revenue of USD 860 million and ARR of USD 840 million from over 11,500 customers, and holds an estimated 4.2%.
Qualys reported 2025 revenue of USD 669.1 million, up 10% from USD 607.6 million, from more than 10,000 subscription customers, worth an estimated 5.1% share. Microsoft, at 6.3%, sells Defender for Cloud alongside Azure consumption. CrowdStrike, at 3.9%, adds cloud workload modules to its endpoint base. The seven named vendors hold 44.3%; the remaining 55.7% is spread across code security specialists and regional providers.
| Company | What the position rests on | Douglas Insights share 2025 |
|---|---|---|
| Palo Alto Networks | Cortex Cloud, merged from Prisma Cloud and Cortex CDR | 9.1% |
| Google (Wiz) | Multicloud graph across four clouds | 8.2% |
| Tenable | Exposure management, over 40,000 customers | 7.5% |
| Microsoft | Defender for Cloud on Azure | 6.3% |
| Qualys | Cloud platform, over 10,000 subscription customers | 5.1% |
| Rapid7 | Exposure command, over 11,500 customers | 4.2% |
| CrowdStrike | Falcon cloud workload modules | 3.9% |
How much do buyers pay for cloud vulnerability scanning per instance, image and subscription?
Buyers pay from USD 15 a year for one natively scanned instance to about USD 71,850 a year for an average vendor subscription. The spread is set by how many clouds, workloads and code repositories the cloud application security contract covers.
The native floor is clear on Amazon Inspector pricing: USD 1.258 per instance-month agent-based, USD 1.75 agentless, USD 0.30 per Lambda function for standard scanning plus USD 0.60 for code scanning. On an annual basis one agent-based instance costs USD 15.10 and one agentless instance USD 21.00.
Vendor disclosures set the middle band. Qualys revenue divided by its customer count gives under USD 66,910 per customer a year; Rapid7 gives about USD 74,780; Tenable, with a long tail of small accounts, gives about USD 24,985. The Douglas Insights average of USD 71,850 per subscriber rises 3.1% a year to about USD 97,500 by 2035, as buyers add code and AI-workload modules rather than pay higher list prices for the same scans.
Douglas Exclusive: the Cloud Exposure Spend Ledger
The Cloud Exposure Spend Ledger is a Douglas Insights model built from 14 sourced inputs. Those are seven vendor disclosures (revenue, ARR or customer counts from Palo Alto Networks, Google, Tenable, Microsoft, Qualys, Rapid7 and CrowdStrike), four Amazon Inspector list prices and three Cyber Resilience Act reporting deadlines. It is our estimate, not an official register.
The ledger assigns each vendor an estimated slice of the USD 13.11 billion cloud application security and vulnerability management total, anchored on what it discloses.
| Vendor | Disclosed anchor | Ledger share | Ledger revenue 2025 |
|---|---|---|---|
| Palo Alto Networks | Next-Generation Security ARR USD 5.6 billion, fiscal 2025 | 9.1% | USD 1.19 billion |
| Google (Wiz) | Used by 50% of the Fortune 100; covers four clouds | 8.2% | USD 1.07 billion |
| Tenable | 2025 revenue USD 999.4 million | 7.5% | USD 982.9 million |
| Microsoft | Defender for Cloud, foundational CSPM free | 6.3% | USD 825.6 million |
| Qualys | 2025 revenue USD 669.1 million | 5.1% | USD 668.4 million |
| Rapid7 | 2025 revenue USD 860 million, ARR USD 840 million | 4.2% | USD 550.4 million |
| CrowdStrike | Ending ARR USD 5.25 billion, 31 January 2026 | 3.9% | USD 511.1 million |
The finding: the seven largest vendors capture 44.3% of spend, and an average subscription of USD 71,850 equals the native price of about 4,760 agent-based instance-years. That gap persists because buyers pay for prioritisation and remediation workflow, not the scan itself. Our ledger shows that a vendor charging only for scans competes with a USD 15.10 floor.
What do the Cyber Resilience Act reporting rules mean for vulnerability management vendors?
Since 11 September 2026, manufacturers selling products with digital elements in the EU must report actively exploited vulnerabilities within 24 hours. That rule turns cloud vulnerability management from an audit tool into a compliance clock for every software maker selling into the 27 member states.
Under Regulation (EU) 2024/2847 reporting obligations, manufacturers send an early warning within 24 hours, a full notification within 72 hours and a final report no later than 14 days after a corrective measure is available. Open-source software stewards follow from 11 December 2027. Douglas Insights counts the 24-hour deadline as worth 1.6 points of subscriber growth through 2030, because the rule reaches software makers that sell to European buyers wherever they are based.
What would move the 2035 outlook for cloud application security and vulnerability management?
The base case reaches USD 33.07 billion in 2035, against USD 25.54 billion on a slower path and USD 41.87 billion on a faster one. The gap depends mainly on how quickly subscriber growth spreads beyond the largest cloud users.
The slower case assumes 4.6% subscriber growth and 2.2% price growth, with hyperscaler bundling eroding independent prices. The faster case assumes 8.1% subscriber growth and 3.9% price growth, with AI workloads and the Google and Wiz combination pushing posture scanning into every cloud deal. Moving volume growth up by one point lifts the 2035 total to USD 36.31 billion; moving it down one point gives USD 30.09 billion. Published forecasts for related scopes run from 8.0% to 32.6% a year, and our 9.70% sits near the lower-middle of that range, because we count subscriptions rather than total security budgets.
Methodology: how do 182,400 security subscribers multiply into a USD 13.11 billion total?
How this report is built
- Every figure carries a confidence grade in the fact sheet above, and the working model ships with every licence.
- Five regional models sum to the global figure, with country tables in the Excel model.
- The next scheduled review of this study is April 2027.
- Licence holders receive it as a maintained tab in the Excel model.
The cloud application security and vulnerability management total is 182,400 subscribing organisations times USD 71,850, equal to USD 13.11 billion, built from 14 sourced inputs and split across five regions. Each step below can be repeated from public disclosures and list prices.
Subscriber counts start from disclosed customer bases: over 40,000 at Tenable, over 11,500 at Rapid7 and over 10,000 at Qualys, then add platform and hyperscaler buyers. The average spend checks against vendor revenue per customer: USD 71,850 sits within 4% of Rapid7’s USD 74,780 and 7% above the Qualys ceiling. Regional rows sum to USD 13.11 billion in 2025 and USD 33.07 billion in 2035. Segment values sum to the 2025 total exactly and to the 2035 total within 0.02%.
For neighbouring markets, see our Cybersecurity Mesh Market, the Industrial Cybersecurity and OT Protection Market and the Online Cloud Backup Service Market.
Sources
- Google Google completes acquisition of Wiz (2026)
- European Commission Cyber Resilience Act: reporting obligations (2026)
- Palo Alto Networks Palo Alto Networks introduces Cortex Cloud (2025)
- Tenable Tenable fourth quarter and full year 2025 results (2026)
- Qualys Qualys fourth quarter and full year 2025 results (2026)
- Amazon Web Services Amazon Inspector pricing (2026)
- Rapid7 Rapid7 fourth quarter and full year 2025 results (2026)
- Palo Alto Networks Palo Alto Networks fiscal 2025 results (2025)
- CrowdStrike CrowdStrike fourth quarter and fiscal 2026 results (2026)
Inside the 196-page report
01Executive summary12 sections
The market in one view
- 1.1Market snapshot, 2025 and 2035
- 1.1.1Market size, 2025
- 1.1.2Forecast, 2035
- 1.1.3Growth rate, 2026–2035
- 1.2Growth decomposition
- 1.2.1Volume growth (thousand organisations)
- 1.2.2Value per unit growth
- 1.3Key findings
- 1.4Segment highlights
- 1.5Regional highlights
- 1.6Competitive highlights
- 1.7Douglas Insights verdict
02Scope and definitions17 sections
What the subscriptions cover
- 2.1Market definition
- 2.2Inclusions and exclusions
- 2.2.1Posture, workload and code scanning
- 2.2.2Exclusions
- 2.2.3Units
- 2.3Segmentation
- 2.3.1By solution
- 2.3.2By deployment
- 2.3.3By end user
- 2.3.4By region
- 2.4Years considered
- 2.4.1Base year 2025
- 2.4.2Forecast 2026–2035
- 2.5Currency and units
- 2.5.1Value in USD million
- 2.5.2Volume in thousand organisations
- 2.6Who this report is for
03Research methodology16 sections
Bottom-up: thousand organisations × value per unit
- 3.1Bottom-up market model
- 3.1.1Volume base, 2025 (thousand organisations)
- 3.1.2Value per unit
- 3.1.3Forecast legs to 2035
- 3.2Top-down cross-checks
- 3.3Data triangulation
- 3.4Sources
- 3.4.1Regulators and statistics offices
- 3.4.2Company filings and results
- 3.4.3Trade and industry bodies
- 3.4.49 primary sources cited
- 3.5Confidence grading
- 3.6Assumptions and limitations
- 3.6.1Subscriber count
- 3.6.2Average spend
- 3.6.3Reconciliation
04Growth drivers3 sections
Exposure, disclosure clocks and consolidation
- 4.1Cloud attack surface
- 4.2Cyber Resilience Act
- 4.3Platform consolidation
05Restraints3 sections
Native tools, renewal stalls, triage overload
- 5.1Hyperscaler pricing
- 5.2Legacy renewals
- 5.3Alert volumes
06Deployment: agentless and agent-based3 sections
Scanning methods compared
- 6.1Price per instance
- 6.2Coverage
- 6.3Runtime visibility
07End users3 sections
Banks, software makers, healthcare, government, retail
- 7.1Spend shares
- 7.2Growth rates
- 7.3Deployment choices
08Pricing3 sections
From native scans to vendor subscriptions
- 8.1Amazon Inspector list prices
- 8.2Revenue per customer
- 8.3Price outlook
09Regulation3 sections
Cyber Resilience Act reporting
- 9.124-hour early warning
- 9.272-hour notification
- 9.3Open-source stewards
10Market size and forecast, 2025–20355 sections
Global value, volume and value per unit
- 10.1Market value, 2025–2035
- 10.2Volume (thousand organisations), 2025–2035
- 10.3Value per unit, 2025–2035
- 10.4Year-on-year growth
- 10.5Growth decomposition
11Cloud Application Security and Vulnerability Management market, by solution13 sections
4 segments, value 2025–2035
- 11.1Overview and share, 2025 and 2035
- 11.2Cloud security posture management
- 11.2.1Market size and forecast, 2025–2035
- 11.2.2Growth outlook
- 11.3Cloud workload vulnerability scanning
- 11.3.1Market size and forecast, 2025–2035
- 11.3.2Growth outlook
- 11.4Application and code security testing
- 11.4.1Market size and forecast, 2025–2035
- 11.4.2Growth outlook
- 11.5Risk-based vulnerability prioritisation
- 11.5.1Market size and forecast, 2025–2035
- 11.5.2Growth outlook
12Cloud Application Security and Vulnerability Management market, by deployment7 sections
2 segments, value 2025–2035
- 12.1Overview and share, 2025 and 2035
- 12.2Agentless
- 12.2.1Market size and forecast, 2025–2035
- 12.2.2Growth outlook
- 12.3Agent-based
- 12.3.1Market size and forecast, 2025–2035
- 12.3.2Growth outlook
13Cloud Application Security and Vulnerability Management market, by end user16 sections
5 segments, value 2025–2035
- 13.1Overview and share, 2025 and 2035
- 13.2Banking and financial services
- 13.2.1Market size and forecast, 2025–2035
- 13.2.2Growth outlook
- 13.3Software and technology firms
- 13.3.1Market size and forecast, 2025–2035
- 13.3.2Growth outlook
- 13.4Healthcare
- 13.4.1Market size and forecast, 2025–2035
- 13.4.2Growth outlook
- 13.5Government
- 13.5.1Market size and forecast, 2025–2035
- 13.5.2Growth outlook
- 13.6Retail
- 13.6.1Market size and forecast, 2025–2035
- 13.6.2Growth outlook
14Regional analysis26 sections
5 regions
- 14.1Regional overview and share, 2025 and 2035
- 14.2North America
- 14.2.1Market size and forecast, 2025–2035
- 14.2.2By solution
- 14.2.3By deployment
- 14.2.4By end user
- 14.3Europe
- 14.3.1Market size and forecast, 2025–2035
- 14.3.2By solution
- 14.3.3By deployment
- 14.3.4By end user
- 14.4Asia Pacific
- 14.4.1Market size and forecast, 2025–2035
- 14.4.2By solution
- 14.4.3By deployment
- 14.4.4By end user
- 14.5Latin America
- 14.5.1Market size and forecast, 2025–2035
- 14.5.2By solution
- 14.5.3By deployment
- 14.5.4By end user
- 14.6Middle East and Africa
- 14.6.1Market size and forecast, 2025–2035
- 14.6.2By solution
- 14.6.3By deployment
- 14.6.4By end user
15Competitive landscape12 sections
8 companies profiled
- 15.1Market concentration
- 15.2Market share analysis, 2025
- 15.3Strategic moves: acquisitions, launches, contracts
- 15.4Company profilesEach profile: overview, products, financials where reported, position in this market, recent developments
- 15.4.1Palo Alto Networks
- 15.4.2Google
- 15.4.3Wiz
- 15.4.4Tenable
- 15.4.5Qualys
- 15.4.6Rapid7
- 15.4.7Microsoft
- 15.4.8CrowdStrike
16Scenarios to 20355 sections
Slower, base and faster cases
- 16.1Slower case
- 16.2Base case case
- 16.3Faster case
- 16.4Sensitivity of the 2035 value
- 16.5Published forecasts compared
17Douglas Exclusive: the Cloud Exposure Spend Ledger3 sections
Vendor spend model from 14 inputs
- 17.1Ledger table
- 17.2Concentration
- 17.3Native price gap
18Appendix5 sections
Data, sources and licence
- 18.1Data tables (Excel model)
- 18.2Sources (9)
- 18.3Abbreviations
- 18.4Change log and next review
- 18.5Licence and how to cite
TList of tables36
- Table 1Market value, 2025–2035 (USD million)
- Table 2Volume, 2025–2035 (thousand organisations)
- Table 3Value per unit, 2025–2035
- Table 4Cloud Application Security and Vulnerability Management market by solution, 2025–2035 (USD million)
- Table 5Cloud security posture management: market size, 2025–2035 (USD million)
- Table 6Cloud workload vulnerability scanning: market size, 2025–2035 (USD million)
- Table 7Application and code security testing: market size, 2025–2035 (USD million)
- Table 8Risk-based vulnerability prioritisation: market size, 2025–2035 (USD million)
- Table 9Cloud Application Security and Vulnerability Management market by deployment, 2025–2035 (USD million)
- Table 10Agentless: market size, 2025–2035 (USD million)
- Table 11Agent-based: market size, 2025–2035 (USD million)
- Table 12Cloud Application Security and Vulnerability Management market by end user, 2025–2035 (USD million)
- Table 13Banking and financial services: market size, 2025–2035 (USD million)
- Table 14Software and technology firms: market size, 2025–2035 (USD million)
- Table 15Healthcare: market size, 2025–2035 (USD million)
- Table 16Government: market size, 2025–2035 (USD million)
- Table 17Retail: market size, 2025–2035 (USD million)
- Table 18Cloud Application Security and Vulnerability Management market by region, 2025–2035 (USD million)
- Table 19North America: market by solution, 2025–2035 (USD million)
- Table 20North America: market by deployment, 2025–2035 (USD million)
- Table 21North America: market by end user, 2025–2035 (USD million)
- Table 22Europe: market by solution, 2025–2035 (USD million)
- Table 23Europe: market by deployment, 2025–2035 (USD million)
- Table 24Europe: market by end user, 2025–2035 (USD million)
- Table 25Asia Pacific: market by solution, 2025–2035 (USD million)
- Table 26Asia Pacific: market by deployment, 2025–2035 (USD million)
- Table 27Asia Pacific: market by end user, 2025–2035 (USD million)
- Table 28Latin America: market by solution, 2025–2035 (USD million)
- Table 29Latin America: market by deployment, 2025–2035 (USD million)
- Table 30Latin America: market by end user, 2025–2035 (USD million)
- Table 31Middle East and Africa: market by solution, 2025–2035 (USD million)
- Table 32Middle East and Africa: market by deployment, 2025–2035 (USD million)
- Table 33Middle East and Africa: market by end user, 2025–2035 (USD million)
- Table 34Company market shares, 2025
- Table 35Scenario values, 2035
- Table 36Sources and confidence grades by figure
FList of figures9
- Figure 1Market value, 2025–2035
- Figure 2Growth decomposition, 2026–2035
- Figure 3Share by solution, 2025 and 2035
- Figure 4Share by deployment, 2025 and 2035
- Figure 5Share by end user, 2025 and 2035
- Figure 6Share by region, 2025 and 2035
- Figure 7Growth by region, 2026–2035
- Figure 8Market concentration, 2025
- Figure 9Scenario paths to 2035
Questions buyers ask
What does an average organisation spend a year on cloud application security and vulnerability management?
USD 71,850 in 2025 by Douglas Insights estimates, rising about 3.1% a year to roughly USD 97,500 by 2035 as buyers add code and AI-workload modules.
How much revenue does the cloud vulnerability management field generate in 2025 and 2035?
USD 13.11 billion in 2025 and USD 33.07 billion in 2035, a revenue CAGR of 9.70% from 6.4% subscriber growth and 3.1% price growth.
Why does cloud security posture management hold the largest share?
34.6% of 2025 revenue, or USD 4.53 billion, because every cloud account needs configuration checks before workloads or code are scanned.
Which part of cloud application security expands quickest to 2035?
12.2% a year for application and code security testing, from USD 2.86 billion to USD 9.03 billion, as disclosure deadlines push testing before release.
What does Amazon Inspector charge to scan a cloud instance?
USD 1.258 per instance-month for agent-based EC2 scanning and USD 1.75 for agentless scanning, or USD 15.10 and USD 21.00 a year.
How concentrated is the vendor field after the Wiz deal?
24.8% of 2025 revenue sits with Palo Alto Networks, Google with Wiz and Tenable by Douglas Insights estimates; Palo Alto Networks leads with 9.1%.
What reporting deadlines does the Cyber Resilience Act set for exploited vulnerabilities?
24 hours for an early warning, 72 hours for a full notification and 14 days after a fix for the final report, applying to manufacturers since 11 September 2026.
Where is spending on cloud vulnerability scanning growing quickest?
11.6% a year in Asia Pacific, from USD 2.70 billion in 2025 to USD 8.09 billion in 2035, the fastest of the five regions.
Research & citation
This report was researched, written and reviewed by the Douglas Insights Research Desk under the Douglas Insights editorial standards. Material errors are logged in the corrections log. No section is sponsored.
Douglas Insights Inc (2026). Cloud Application Security and Vulnerability Management Market. Report DI-IT-10649, October 2026. https://www.douglasinsights.com/cloud-application-security-and-vulnerability-management-market/