{"kind":"atlas-fold-dated-history","notice":"Documentation research, not measured product performance. The first snapshot is a baseline, not a trend. Compare unchanged scope and rubric; research corrections are not product momentum.","segment":"vulnerability-management","snapshots":[{"id":"2026-09-21","publishedAt":"2026-09-21","kind":"baseline","research":{"segment":"vulnerability-management","reviewedAt":"2026-09-21","rubricVersion":"1.1","cohorts":[{"id":"exposure-vm-platforms","name":"Exposure and vulnerability management platforms","scope":"Comparable exposure and vulnerability-management platforms and entitled editions. Exclude managed-service comparisons, BAS-only tools, and retired Cisco Vulnerability Management (formerly Kenna.VM)."}],"dimensions":[{"id":"maturity","name":"Operational maturity","question":"How completely does public documentation describe operating safeguards for running vulnerability and exposure assessment safely and accountably?","description":"Documented authentication, role separation, credential and sensor handling, activity records, and named environment limits. This is not vendor age, size, uptime, or claimed reliability.","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide operating safeguards for the scoped assessment workflow. Missing evidence is unknown, never zero.","1: A concrete basic operating safeguard is documented for the evaluated edition.","2: Docs describe basic roles plus some scan or agent configuration, without SSO, audit export, or scoped asset access.","3: Docs describe role-based access, credentialed or agent assessment setup, and at least one of SSO or activity logs for the evaluated offering.","4: Docs describe SSO/SAML or equivalent, multi-role RBAC with data-scope permissions, credential or sensor safeguards, and auditable operator actions, with named environment gaps.","5: Docs describe a complete operating-safeguard set including SSO, least-privilege RBAC, credential vaults and scan safety, full activity export, and authorized environment coverage with no material undocumented gaps."],"refinements":[{"base":4,"criteria":[{"id":"credential-vault-workflow","label":"Documented credential-vault configuration for the evaluated assessment workflow","weight":2},{"id":"scan-safety","label":"Documented controls for safely scheduling or limiting assessment activity","weight":2},{"id":"full-activity-export","label":"Exportable operator activity covering the evaluated offering","weight":3},{"id":"authorized-coverage","label":"Established authorized environment coverage without material undocumented gaps","weight":3}]}]},{"id":"innovation","name":"Shipped innovation","question":"Which current baseline workflows are supported, and is any concrete shipped difference from that shared baseline established?","description":"Ordinal evidence of shipped workflows against a contemporary shared cohort baseline. Stage 3 means supported baseline workflows, not novelty or superiority. Higher stages require concrete generally available differences supported by comparative primary evidence. Asset inventory, vulnerability assessment, threat/KEV and business context, risk prioritization, exposure or attack-path context where offered, remediation ownership/orchestration, and reassessment are contemporary baseline workflows. Scan-to-ticket automation, a branded risk score and graph views alone do not establish differentiation.","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide a shipped workflow within the scoped cohort. Missing evidence is unknown, never zero.","1: One basic in-scope workflow is confirmed shipped; no broader stage is established.","2: Several baseline components are confirmed shipped, but an integrated contemporary baseline workflow is not established.","3: An integrated contemporary baseline workflow is supported by primary evidence; this stage makes no differentiation or novelty claim.","4: Stage 3 plus one concrete generally available operator workflow difference beyond the shared contemporary baseline, supported by comparative primary evidence.","5: Stage 4 plus multiple complementary generally available workflow differences beyond that baseline, with their boundaries and prerequisites established."]},{"id":"breadth","name":"Capability breadth","question":"How many in-scope exposure and vulnerability assessment domains does the documented offering cover?","description":"Coverage of authenticated or agent VM, configuration or policy assessment, identity, cloud, OT, web or application testing, and authorized EASM as documented modules of the evaluated family. A platform name does not establish bundle contents.","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide an in-scope assessment capability. Missing evidence is unknown, never zero.","1: A bounded in-scope capability is documented for one environment or workflow.","2: Docs describe host vulnerability assessment plus one adjacent domain (agents, configuration, or inventory).","3: Docs describe host VM plus two additional domains (for example agents and patch detection, or inventory and EASM).","4: Docs describe host VM plus three or more additional domains (cloud, identity, OT, application/WAS, or EASM), with module entitlements called out.","5: Docs describe GA coverage across host VM, cloud, identity, OT, application/WAS, and authorized external surface in the evaluated family without unverified modules."]},{"id":"ecosystem","name":"Ecosystem & integration","question":"How far do documented connectors, APIs, and ticket or automation integrations extend beyond the vendor’s own sensors?","description":"Shipped, documented ingest and export paths for scanners, CMDB/ITSM, cloud, identity, and automation tools. Preview connectors are not treated as generally available.","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide an integration or supported data handoff. Missing evidence is unknown, never zero.","1: A concrete native connector or supported manual integration is documented.","2: Docs describe one major ITSM or SIEM integration plus an API.","3: Docs describe multiple native connectors or a documented ITSM workflow plus APIs, with ingest or export of findings.","4: Docs describe a substantial GA connector catalog or hundreds of listed integrations spanning scanners, CMDB/ITSM, and cloud or identity sources, with named environment exclusions.","5: Docs describe GA bidirectional orchestration across scanners, CMDB, ITSM, SOAR, and cloud or identity sources with no preview-only core connectors."]},{"id":"governance","name":"Governance & control","question":"How completely can operators document accept, recast, exception, ownership, and criticality decisions with retained evidence?","description":"Documented exception and accept workflows, criticality tagging, scoped permissions, and evidence preservation. This is not a claimed compliance outcome or audit-pass guarantee.","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide an administrative or policy control. Missing evidence is unknown, never zero.","1: A specific administrative control is documented for the scoped workflow.","2: Docs describe tagging or asset groups and a basic exception or accept action without justification or expiry.","3: Docs describe accept or exception workflows with justification, plus role-scoped access to assets or findings.","4: Docs describe accept, recast, or exception with justification and expiry or audit history, plus criticality or SLA tagging and scoped RBAC.","5: Docs describe a complete control set: inspectable exception evidence, criticality rules, owner routing, exportable audit of decisions, and least-privilege scope with no unverified gaps."]},{"id":"operations","name":"Operator enablement","question":"How completely do public guides enable an operator to deploy, run, report, and re-assess a vulnerability or exposure program?","description":"Playbooks, deployment and module-setup guides, dashboards, exportable reporting, and remediation-hub workflows. This is not staffing savings, ROI, or tested efficacy.","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide a supported operator action or guidance path. Missing evidence is unknown, never zero.","1: A concrete operator action and its basic use are documented.","2: Docs provide scan or sensor setup plus a default dashboard.","3: Docs provide deployment or quick-start, role-aware tasks, and standard reports or dashboards.","4: Docs provide playbooks or operational lifecycle guides, prioritized remediation views, scheduled or exportable reports, and named module setup steps.","5: Docs provide a complete operator kit: deployment, playbooks, SLA or owner reporting, exportable evidence packs, and a re-assessment workflow with no major undocumented steps."]}],"assessments":[{"vendor":"tenable-one","cohort":"exposure-vm-platforms","edition":"Tenable One Exposure Management Platform (commercial; module-entitled)","asOf":"2026-09-21","status":"research-preview","summary":"Documented Tenable One family combines entitled VM, WAS, identity, cloud, OT, and ASM products with Exposure Management attack paths, exposure cards, and third-party connectors. Several Exposure View and attack-path features are license-gated; connectors and AI path summaries are not supported in FedRAMP Moderate.","dimensions":{"maturity":{"score":4,"confidence":"medium","rationale":"Docs describe Tenable One SAML, FedRAMP Moderate product coverage, and tiered VM roles from Read-Only through Administrator plus resource permissions on tags, assets, and findings. Administrators can view and export activity logs; scan managers handle scans without full user administration; managed credentials and agent freeze windows are documented. Gaps are named: SAML assertion encryption is unsupported, and many connectors are outside FedRAMP Moderate. That maps to anchor 4, not 5, because environment and encryption gaps remain.","sourceIds":["s1","s2","s3","s8"]},"innovation":{"score":3,"confidence":"low","rationale":"The cited pages support exposure-context and attack-path investigation with licensed remediation prioritization, matching contemporary cohort baseline workflows (stage 3). No supported difference beyond that shared baseline is established. This is not a novelty or superiority claim; preview, beta, AI branding and unverified agentic features are excluded.","sourceIds":["s5","s6","s9"]},"breadth":{"score":4,"confidence":"medium","rationale":"The platform documentation enumerates host vulnerability management plus several adjacent domains with module and license boundaries. This establishes anchor 4. A complete generally available, jointly entitled host/cloud/identity/OT/web-app/external-surface set was not established for the selected commercial scope; family branding alone does not prove anchor 5.","sourceIds":["s1"]},"ecosystem":{"score":4,"confidence":"medium","rationale":"Exposure Management documents a large native connector catalog ingesting assets and weaknesses from Qualys, Rapid7 InsightVM, Wiz, CrowdStrike, ServiceNow, Axonius, Microsoft TVM, and others, plus an Open Connector template. Connector data can take up to an hour to appear. The catalog is explicitly not supported in Tenable FedRAMP Moderate. That is a substantial GA catalog with a named environment exclusion (anchor 4), not bidirectional orchestration with no gaps (anchor 5).","sourceIds":["s4"]},"governance":{"score":4,"confidence":"medium","rationale":"Recast, Accept, and Change Result rules adjust visible severity, hide accepted risk, or override host-audit status while preserving unaltered raw scan results. Accept rules require justification and can expire; a 25,000-rule container limit is documented. Roles are separate from data permissions; custom roles and recast/accept management are administrator-gated. VPR of accepted findings is not altered. That is justification plus expiry or history with scoped RBAC (anchor 4); exportable decision packets independent of the console were not verified (not 5).","sourceIds":["s3","s7"]},"operations":{"score":4,"confidence":"medium","rationale":"Operational Playbooks walk Discover and Assess, VPR/ACR prioritization, remediation hand-off, and CES measurement, with role and sensor prerequisites. A deployment guide, tagging and mobilization quick references, Exposure View SLA and tag-performance data, and custom exposure cards are documented. That is playbooks plus prioritized views and named setup (anchor 4). A complete evidence-pack export workflow was not verified in public docs (not 5).","sourceIds":["s5","s9"]}},"constraints":["Tenable One is a product family; VM, WAS, Identity Exposure, Cloud Exposure, OT Exposure, ASM, and AI Exposure are separately entitled.","Exposure View, custom exposure cards, and Top Attack Paths require Ratio-Based Tenable One or Tenable One Advanced licensing.","Tenable Exposure Management is only available as part of Tenable One.","Third-party connectors and AI-powered attack-path summaries are not supported in Tenable FedRAMP Moderate environments.","Tenable One SAML does not support assertion encryption.","Connector ingest delay of up to one hour is documented; connector fidelity versus source tools is unverified.","Recast rules are eventually consistent and do not modify raw scan results.","No lab assessment of scan safety, scoring accuracy, or remediation efficacy was performed.","Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition."],"sources":[{"id":"s1","title":"Tenable Exposure Management Platform documentation / What is Tenable One?","url":"https://docs.tenable.com/exposure-management.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"SAML for Tenable One","url":"https://docs.tenable.com/quick-reference/SAML/Content/T-One-Overview.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"Tenable-provided roles and privileges","url":"https://docs.tenable.com/vulnerability-management/Content/Settings/access-control/TenableRolePrivileges.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"Supported third-party integrations (Tenable Exposure Management connectors)","url":"https://docs.tenable.com/exposure-management/Content/connectors/connectors-and-supported-integrations.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s5","title":"Tenable Exposure Management operational playbooks","url":"https://docs.tenable.com/exposure-management/Content/getting-started/operational-playbooks.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s6","title":"Top Attack Paths","url":"https://docs.tenable.com/exposure-management/Content/attack-path/top-attack-paths.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s7","title":"Recast, Change Result, and Accept rules","url":"https://docs.tenable.com/vulnerability-management/Content/recast/recast-intro.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s8","title":"Tenable FedRAMP documentation","url":"https://docs.tenable.com/FedRAMP.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s9","title":"Exposure View","url":"https://docs.tenable.com/exposure-management/Content/exposure-view/exposure-view.htm","accessedAt":"2026-09-21","kind":"documentation"}]},{"vendor":"qualys-vmdr","cohort":"exposure-vm-platforms","edition":"Qualys VMDR on Enterprise TruRisk Platform","asOf":"2026-09-21","status":"research-preview","summary":"Documented VMDR is a scanner-plus-agent vulnerability workflow with TruRisk scoring, CISA KEV mitigation views, patch detection, and ServiceNow ticket mapping. Enterprise TruRisk Management aggregation of third-party tools is a related but separate Qualys application, not assumed in the VMDR SKU.","dimensions":{"maturity":{"score":4.3,"confidence":"medium","rationale":"The VM/VMDR documentation establishes subscription-enabled SAML, business-unit and asset-scoped roles, restricted editing of authentication records, and operator activity records. Windows guidance explicitly warns that reduced privileges omit checks. This corrects the earlier missed SAML evidence and satisfies anchor 4. The subscription activity-log API additionally exports operator actions, earning 0.3. This pass does not establish complete vault, scan-safety and environment-coverage evidence for anchor 5.","sourceIds":["s2","s6","s8","qualys-saml","qualys-activity-export"],"refinement":{"base":4,"evidence":[{"criterion":"full-activity-export","rationale":"The VM/PC activity-log API exports subscription actions as CSV. Managers see all users; Unit Managers see their business unit, and Scanners or Readers only their own actions. Date filters and a truncation limit are explicit.","sourceIds":["qualys-activity-export"]}]}},"innovation":{"score":3,"confidence":"low","rationale":"The cited pages support threat/KEV and business-criticality-based prioritization with remediation tracking, matching contemporary cohort baseline workflows (stage 3). No supported difference beyond that shared baseline is established. This is not a novelty or superiority claim; preview, beta, AI branding and unverified agentic features are excluded.","sourceIds":["s1","s3","s4"]},"breadth":{"score":3,"confidence":"medium","rationale":"VMDR docs combine asset discovery and inventory, vulnerability and configuration assessment, threat prioritization, and patch detection, using cloud agents and a variety of sensors. That is host VM plus agents/sensors and patch detection (anchor 3). WAS, CSAM, Policy Audit, VMDR OT, and ETM are documented as related Qualys applications, not automatic VMDR contents, so multi-domain family coverage is not scored as 4.","sourceIds":["s1","s4"]},"ecosystem":{"score":3,"confidence":"medium","rationale":"Qualys VMDR for ServiceNow documents automated import, CMDB matching, ticket assignment, custom SLAs from threat indicators and TruRisk, plus a Qualys Core connection app. VM and PA APIs are documented as an XML integration interface. ETM is described as ingesting third-party tools, but that is outside the VMDR SKU. That is a documented ITSM workflow plus APIs (anchor 3), not a large GA connector catalog (anchor 4).","sourceIds":["s1","s4","s5"]},"governance":{"score":4,"confidence":"medium","rationale":"The VM API requires stored comments for ignore/restore decisions, scopes permissions by subscription, business unit or allowed hosts, and can reopen findings on a specified date or after a selected interval. Existing criticality tags and role procedures complete anchor 4. A complete exportable decision-evidence packet is not established for anchor 5.","sourceIds":["s2","s3","s8","baseline-ignore"]},"operations":{"score":4,"confidence":"medium","rationale":"Docs publish an eight-step VMDR journey from identify assets through reports and alerts, TruRisk summary reports from dashboards or the Reports tab, QQL search, training videos, and ServiceNow SLA dashboards. Application enablement and user-role prerequisites are stated before use. That is lifecycle guidance plus exportable reports and named setup (anchor 4). A full re-assessment evidence-pack workflow independent of the console was not verified (not 5).","sourceIds":["s1","s5"]}},"constraints":["Evaluated offering is VMDR; Enterprise TruRisk Management, WAS, CSAM, Policy Audit, and VMDR OT are separate Qualys applications and must be entitled separately.","VMDR TruRisk, TruRisk FixIT, and TruRisk ProtectIT are documented as distinct packages; patch management is not assumed in base VMDR.","TruRisk is a vendor composite; operators still need to inspect QDS, ACS, KEV, and CVSS rather than treat TruRisk as a substitute for those signals.","SAML/SSO for VMDR was not verified in the reviewed role and getting-started pages.","Windows authenticated scanning recommends administrator privileges; lesser rights reduce check coverage.","Some TruRisk scoring exclusions (potential QIDs, non-running kernels) are described as limited-customer-release features requiring TAM enablement.","No lab assessment of authenticated coverage, TruRisk explainability, or patch-module entitlement was performed.","Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition."],"sources":[{"id":"s1","title":"Vulnerability Management, Detection and Response overview","url":"https://docs.qualys.com/en/vm/latest/about_qualys_vm_vmdr.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"User roles and permissions for VM/VMDR, PA/PC, SCA","url":"https://docs.qualys.com/en/vm/latest/user_accounts/setting_user_permissions.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"Qualys TruRisk","url":"https://docs.qualys.com/en/vmdr/getting-started-guide/features_of_vmdr/qualys_trurisk.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"Enterprise TruRisk Management / Risk Operations Center overview","url":"https://docs.qualys.com/en/etm/latest/introduction/overview.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s5","title":"Qualys VMDR for ServiceNow (ITSM) get started","url":"https://docs.qualys.com/en/integration/vmdr-itsm/get_started/get_started.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s6","title":"Windows authentication credentials for VM/VMDR","url":"https://docs.qualys.com/en/vm/latest/authentication/windows/windows_auth_setup.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s7","title":"Qualys Enterprise TruRisk Platform (VMDR) v2.2.0 risk acceptance rules","url":"https://docs.qualys.com/en/vm/release-notes/mergedProjects/qualys_vmdr_rn/vmdr/qualys_enterprise_truRisk_platform_lcr_(vmdr)_v2.2.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s8","title":"Manage your users in VM/VMDR","url":"https://docs.qualys.com/en/vmdr/latest/user_accounts/manage_users.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"qualys-saml","title":"Tell me about SAML SSO (VM/VMDR)","url":"https://docs.qualys.com/en/vm/latest/user_accounts/saml/about_saml.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"qualys-activity-export","title":"Export User Activity Log (Qualys VM/PC API)","url":"https://docs.qualys.com/en/vm/qweb-all-api/mergedProjects/qapi-user/activity/export_activity.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-ignore","title":"Ignore or restore vulnerabilities with comments and timed reopening (VM API)","url":"https://docs.qualys.com/en/vm/qweb-all-api/mergedProjects/qapi-rep/tickets/ignore_vulnerabilities.htm","accessedAt":"2026-09-21","kind":"documentation"}]},{"vendor":"rapid7-exposure-command","cohort":"exposure-vm-platforms","edition":"Rapid7 Exposure Command (InsightVM scanner plus Surface Command; Essentials vs Ultimate)","asOf":"2026-09-21","status":"research-preview","summary":"Documented Exposure Command layers Surface Command inventory and blast-radius mapping with InsightVM assessment, Remediation Hub, and Command Platform SSO/RBAC. Cloud security, DAST, and attack-path analysis are Ultimate-tier in the compared feature table; InsightVM remains the on-prem scanner.","dimensions":{"maturity":{"score":4,"confidence":"medium","rationale":"Command Platform docs cover SAML 2.0 SSO with FirstName, LastName, and Email assertions, optional rbacGroups group sync, MFA and password-policy health, and RBAC with product built-in roles plus custom roles for Surface Command. Pre-deployment docs require ASM Admin access, credentialed InsightVM scanning for accurate results, and IP allowlisting. That is SSO plus multi-role RBAC, credential guidance, and named setup gaps (anchor 4). Full activity-export coverage across every module was not verified (not 5).","sourceIds":["s3","s4","s6","s9"]},"innovation":{"score":3,"confidence":"low","rationale":"The cited pages support inventory and exposure-context investigation with remediation ownership, matching contemporary cohort baseline workflows (stage 3). No supported difference beyond that shared baseline is established. This is not a novelty or superiority claim; preview, beta, AI branding and unverified agentic features are excluded.","sourceIds":["s2","s5","s8"]},"breadth":{"score":4,"confidence":"medium","rationale":"All Exposure Command tiers include Surface Command inventory (devices, software, identities, controls) and external attack surface discovery. Essentials adds vulnerability and policy scanning and dynamic criticality tagging. Ultimate adds multi-cloud visibility, container assessment, IaC scanning, DAST, and attack-path analysis. That is host VM plus inventory, EASM, and entitled cloud/app domains (anchor 4). OT is not a first-party module in the compared table, and Advanced appears only on some Surface Command pages, so anchor 5 is not used.","sourceIds":["s2","s6"]},"ecosystem":{"score":4,"confidence":"medium","rationale":"Exposure Command overview states more than 450 out-of-the-box integrations; Surface Command overview cites over 150 tool integrations. Remediation Hub lists third-party connectors including Tenable, Qualys VMDR, Wiz, CrowdStrike, Amazon Inspector, and others. Essentials and Ultimate include a bulk data export API and SOAR; Remediation Hub can send work to InsightConnect workflows. Connector quality versus source tools is unverified, so this is a substantial listed catalog with exclusions by license (anchor 4), not proven bidirectional GA with no gaps (5).","sourceIds":["s1","s5","s8"]},"governance":{"score":4,"confidence":"medium","rationale":"InsightVM, within the evaluated Exposure Command scope, documents exception reasons, comments, expiration and approval paths constrained by role and asset access. Combined with dynamic criticality and scoped remediation access, this establishes anchor 4. It does not establish a unified, exportable decision packet across every Exposure Command module.","sourceIds":["s2","s4","s5","s7","baseline-exceptions"]},"operations":{"score":4,"confidence":"medium","rationale":"Configure-by-license docs split Attack Surface Management, Vulnerability Management, Automation, and Ultimate-only Cloud and AppSec setup. Remediation Hub provides top-25 impact metrics, CSV export, scheduled HTML/CSV/PDF reports, and emergent-threat banners. Security Program and Exposure Management dashboards require administrators on the contributing products. That is module setup plus prioritized remediation and scheduled reports (anchor 4). Asset counts may differ across Hub, InsightVM, and Cloud Security because of sync delay; a unified evidence pack was not verified (not 5).","sourceIds":["s5","s6","s7"]}},"constraints":["InsightVM remains the assessment engine; Exposure Command is a layered SKU, not a replacement scanner name.","Feature tables on Rapid7 docs disagree on a third Advanced tier; this assessment uses Essentials versus Ultimate as documented on the Exposure Command overview.","Cloud security, DAST, IaC scanning, and attack-path analysis are Ultimate-tier in the compared table.","Remediation Hub visibility is limited to roles and assets the user can already access.","Credentialed InsightVM scanning is required for accurate vulnerability and OS fingerprinting.","Continuous Assessment Service is documented as coming soon and was not scored.","The 450+ integration count is vendor documentation; per-connector fidelity is unverified.","No lab assessment of inventory coverage gaps, blast-radius fidelity, or export completeness was performed.","Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition."],"sources":[{"id":"s1","title":"Exposure Command overview (docs.rapid7.com)","url":"https://docs.rapid7.com/exposure-command/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"Exposure Command packages and feature comparison","url":"https://docs.rapid7.com/exposure-command/exposure-command","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"Configure single sign-on access to the Command Platform","url":"https://docs.rapid7.com/insight/single-sign-on/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"Manage Command Platform users with RBAC","url":"https://docs.rapid7.com/insight/manage-users","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s5","title":"Prioritize and act on remediations (Remediation Hub)","url":"https://docs.rapid7.com/exposure-command/remediation-hub","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s6","title":"Configure Exposure Command","url":"https://documentation.rapid7.com/exposure-command/configure-exposure-command.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s7","title":"Assess total risk / Exposure Management dashboard","url":"https://docs.rapid7.com/exposure-command/executive-risk-view","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s8","title":"Surface Command overview","url":"https://docs.rapid7.com/surface-command-offering/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s9","title":"Exposure Command pre-deployment requirements","url":"https://docs.rapid7.com/exposure-command/exposure-command-predeployment-requirements/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-exceptions","title":"Work with InsightVM vulnerability exceptions","url":"https://docs.rapid7.com/insightvm/working-with-vulnerability-exceptions/","accessedAt":"2026-09-21","kind":"documentation"}]},{"vendor":"microsoft-security-exposure-management","cohort":"exposure-vm-platforms","edition":"Microsoft Security Exposure Management with related Defender Vulnerability Management and Defender EASM","asOf":"2026-09-21","status":"research-preview","summary":"Documented MSEM is a public-cloud Defender portal exposure graph with attack paths, initiatives, and Resolve Now workflows, fed by first-party Microsoft signals. Defender Vulnerability Management and Defender EASM are related capabilities with separate licenses. Third-party data connectors are preview and were not scored as GA.","dimensions":{"maturity":{"score":4,"confidence":"medium","rationale":"Prerequisites document Microsoft Defender unified RBAC (Exposure Management read and manage, plus Core security settings for sensitive EASM actions), Entra ID role alternatives, least-privilege guidance, and device-group scoping. The service is public cloud only and is not available in national or sovereign clouds. Graph ingest freshness (72 hours) and retention (14 days, latest snapshot only) are stated. MDVM critical-asset classification requires a minimum Defender for Endpoint sensor version. That is SSO-equivalent Entra plus RBAC, named environment limits, and sensor prerequisites (anchor 4). Connector GA and sovereign coverage are absent (not 5).","sourceIds":["s1","s2"]},"innovation":{"score":3,"confidence":"low","rationale":"The cited pages support exposure-graph and attack-path investigation with critical-asset context, matching contemporary cohort baseline workflows (stage 3). No supported difference beyond that shared baseline is established. This is not a novelty or superiority claim; preview, beta, AI branding and unverified agentic features are excluded.","sourceIds":["s1","s4","s6"]},"breadth":{"score":4,"confidence":"medium","rationale":"MSEM continuously discovers endpoints, cloud environments (Azure, AWS, and GCP via Defender for Cloud), identities, and external attack surfaces. Full dashboard value requires Defender for Cloud CSPM and Microsoft Defender Vulnerability Management. EASM appears as an External Attack Surface Protection initiative. OT connectors exist in the catalog but are preview. That is host VM plus cloud, identity, and EASM with entitlements called out (anchor 4), not GA OT plus all modules (not 5).","sourceIds":["s1","s2","s7"]},"ecosystem":{"score":3,"confidence":"medium","rationale":"First-party Microsoft products (Defender for Endpoint, Identity, Cloud, Entra ID, and others) are automatically ingested. Defender Vulnerability Management documents Intune remediation tasks and Defender for Endpoint APIs. Third-party connectors for ServiceNow, Tenable, Qualys, Rapid7, Wiz, Prisma, Armis, Dragos, and Forescout are documented as public preview with future consumption pricing. Preview connectors are not scored as GA, so this is first-party graph plus APIs and one major ITSM path (anchor 3), not a GA third-party catalog (anchor 4).","sourceIds":["s3","s7","s8"]},"governance":{"score":4,"confidence":"medium","rationale":"Critical asset management supports predefined and custom classifications with four criticality levels and query-builder rules. Entra and unified RBAC tables separate view versus set-target-score, edit-metric-weight, manage-recommendations, and change-criticality actions. Defender Vulnerability Management remediation pages include recommendation exceptions. Device-group limits restrict which attack-path devices a user sees. That is exception plus criticality rules and scoped RBAC (anchor 4). Exportable exception packets independent of the portal were not verified (not 5).","sourceIds":["s2","s5","s7"]},"operations":{"score":4,"confidence":"medium","rationale":"The Overview dashboard groups Patch, Mitigate, and Fix items for internet-exposed and business-critical assets, plus domain initiative scores for Code, Endpoint, Cloud, Identity, and SaaS. Operators get an initiatives catalog, recommendations, metrics, security events, attack surface map, and Advanced Hunting schemas. That is operational lifecycle views plus reporting (anchor 4). Help is in-portal; a complete exportable evidence-pack and re-assessment runbook independent of Defender portal features was not verified (not 5).","sourceIds":["s4","s1"]}},"constraints":["Microsoft Security Exposure Management is available in public cloud only; it is not available in US Gov, China Gov, or other sovereign clouds.","Full dashboard value requires Defender for Cloud with CSPM and Microsoft Defender Vulnerability Management (standalone or Defender for Endpoint P2).","License stacking (Microsoft 365 E5 versus E3 add-ons versus Defender suite SKUs) must be confirmed; some licenses grant Secure Score only.","External data connectors are public preview with planned consumption-based pricing and were not scored as GA.","Defender Vulnerability Management navigation under Exposure Management is described as relevant for Microsoft Defender XDR + Defender for Identity preview customers.","Critical asset classification on devices requires Defender for Endpoint sensor 10.3740.XXXX or later.","Graph data from Microsoft products may lag up to 72 hours and is retained at least 14 days as the latest snapshot only.","Government-cloud feature parity and non-Microsoft asset depth are unverified.","No lab assessment of attack-path fidelity, EASM authorization against owned seeds, or remediation efficacy was performed.","Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition."],"sources":[{"id":"s1","title":"What is Microsoft Security Exposure Management?","url":"https://learn.microsoft.com/en-us/security-exposure-management/microsoft-security-exposure-management","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"Prerequisites and support in Microsoft Security Exposure Management","url":"https://learn.microsoft.com/en-us/security-exposure-management/prerequisites","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"Overview of data connectors in Microsoft Security Exposure Management","url":"https://learn.microsoft.com/en-us/security-exposure-management/overview-data-connectors","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"Start using Microsoft Security Exposure Management","url":"https://learn.microsoft.com/en-us/security-exposure-management/get-started-exposure-management","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s5","title":"Review and classify critical assets","url":"https://learn.microsoft.com/en-us/security-exposure-management/classify-critical-assets","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s6","title":"Work with attack paths in Microsoft Security Exposure Management","url":"https://learn.microsoft.com/en-us/security-exposure-management/work-attack-paths-overview","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s7","title":"Microsoft Defender Vulnerability Management","url":"https://learn.microsoft.com/en-us/defender-vulnerability-management/defender-vulnerability-management","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s8","title":"Integration and licensing for Microsoft Security Exposure Management","url":"https://learn.microsoft.com/en-us/security-exposure-management/integration-licensing","accessedAt":"2026-09-21","kind":"documentation"}]}],"scenarios":[{"id":"lean-team","name":"Small security team","description":"A small operator group needs one inventory-plus-assessment path, clear owner routing, and exportable reports without assembling many separately entitled modules.","priorities":["operations","ecosystem"],"questions":["Which modules are actually entitled, and what remains a scanner-only or inventory-only SKU after the platform name?","Can tickets reach named owners through an existing ITSM tool without a second console?"]},{"id":"exam-evidence","name":"Examination evidence pack","description":"A regulated or examined environment must show why a finding was patched, mitigated, or accepted, with CVSS, EPSS or equivalent, KEV, and business context kept inspectable.","priorities":["governance","operations"],"questions":["Do accept or exception records retain justification, expiry, and original scanner evidence without overwriting raw results?","Can a reviewer export findings with separate severity, exploitation, and criticality fields rather than a single vendor score?"]},{"id":"microsoft-estate","name":"Microsoft-centric tenant","description":"An estate standardized on Microsoft 365 and Azure is testing Exposure Management plus Defender Vulnerability Management and, if entitled, Defender EASM, including license stacking and public-cloud limits.","priorities":["breadth","ecosystem"],"questions":["Which features require Microsoft 365 E5, a Defender add-on, standalone MDVM, or a separate EASM entitlement?","Are third-party connectors still preview, and is the tenant in a sovereign cloud where MSEM is unavailable?"]},{"id":"hybrid-ot","name":"Hybrid and operational-technology estate","description":"Availability-constrained plants or mixed IT/OT networks need documented scan safety, OT or agentless inventory options, and authorization before any active test.","priorities":["maturity","breadth"],"questions":["Which OT or industrial connectors are GA versus preview, and who authorizes those assessments?","What remains uncovered when agents cannot run on controllers or air-gapped hosts?"]}],"researchNotes":["First edition dated 2026-09-21; no historical assessments are available.","The four selected existing-catalog offerings form one explicitly scoped cohort. Assessment applies only to named editions and documented modules; adjacent products and managed-service outcomes are excluded.","Primary sources establish documented capabilities and their prerequisites, not actual effectiveness, reliability, deployment effort, staffing savings or return on investment.","Confidence reflects evidence and inference within the stated scope, not vendor size, age or source count.","Contemporary cohort baseline: Asset inventory, vulnerability assessment, threat/KEV and business context, risk prioritization, exposure or attack-path context where offered, remediation ownership/orchestration, and reassessment are contemporary baseline workflows. Scan-to-ticket automation, a branded risk score and graph views alone do not establish differentiation.","Innovation stage 3 indicates supported baseline workflows, not market novelty. No stage 4 or 5 differentiation is established by this first-edition evidence. Public-documentation confidence is low for cross-offering calibration.","Zero requires affirmative evidence of absence. Missing, gated or incomplete documentation remains unknown; a lower stage is not assigned merely because documentation is unavailable.","Scores were checked against cumulative stage prerequisites; selected operating/control cells remain unknown where those prerequisites could not be verified.","Rubric 1.1 adds tenths only for the new maturity anchor 5 requirements: credential-vault workflow (two), scan safety (two), full offering activity export (three), and authorized environment coverage without material undocumented gaps (three). Export completeness and coverage receive the larger shares because they close the operating program across the evaluated scope. Basic RBAC, authentication and existing operator logs do not earn duplicate credit. Qualys SAML and subscription audit-export documentation correct an earlier evidence gap. Tenable One and Rapid7 module-specific export claims are not presumed to cover their entire evaluated platforms; Microsoft’s documented coverage limits remain. Innovation baseline ties stay at 3.0.","All six dimensions were re-reviewed for the 2026-09-21 momentum baseline. Additional source-backed anchor and evidence-gap corrections are documented in docs/research/2026-09-21-momentum-baseline-b.md. These are baseline research corrections, not measured vendor progress; historical comparisons require later comparable review snapshots."]},"changes":[]}]}