Atlas Fold / VM

VM, unfolded.

Vulnerability & exposure management

Atlas Fold / VM / First edition

Vulnerability & exposure management

Provisional editorial research based on public documentation, not tested effectiveness.

First edition · Reviewed · Rubric 1.1

Six dimensions, each scored 0.0–5.0 in tenths. Gaps stay visible.

Comparable exposure and vulnerability-management platforms and entitled editions. Exclude managed-service comparisons, BAS-only tools, and retired Cisco Vulnerability Management (formerly Kenna.VM).

Download JSON

Six dimensions, with gaps listed

Each row is one 0.0–5.0 dimension. Every assessed offering has a consistent color, shape, and number. Numbers identify offerings, not rank. Unknown scores are omitted.

Separated marks connect to their exact positions. Separation does not change scores.

Momentum: building history. Numbers identify offerings, not rank; lines between dimensions are profiles, not time.

A position is only half the story

Momentum

Building history

Baseline recorded 2026-09-21. A second comparable review is needed to show movement.

Download dated history

Own movement is the score change. Relative movement subtracts the median change of matched peers, excluding this offering. Dimensions stay separate.

History appears as a hollow earlier mark connected to the current solid mark in Unfold and Overview. Profile lines between dimensions do not show time. Numbers identify offerings, not rank.

Review history & what changed

The 2026-09-21 baseline incorporates the six-dimension review. Decimal calibration and research corrections are not product momentum. Unknowns stay unknown.

  • 2026-09-21 · baseline · rubric 1.1 · Starting point; no movement inferred.
How momentum is calculated →

Documented scores

Qualys VMDR (medium confidence) has the highest documented score (4.3) for Operational maturity among assessed offerings in this comparison group.

Tenable One (low confidence) and Qualys VMDR (low confidence) and Rapid7 Exposure Command (low confidence) and Microsoft Security Exposure Management (low confidence) are tied at documented score 3.0 for Shipped innovation among assessed offerings in this comparison group. No distinction is evidenced among the scored offerings.

Unknowns and gaps

Unknown is not low quality. Marks are omitted where a required score is unknown.

  • Tenable One: no unknown dimensions.
  • Qualys VMDR: no unknown dimensions.
  • Rapid7 Exposure Command: no unknown dimensions.
  • Microsoft Security Exposure Management: no unknown dimensions.

Scenario lens

A scenario highlights priorities and validation questions only. It does not rewrite scores or claim eligibility.

Selected evidence

Tenable One · Tenable

Tenable One Exposure Management Platform (commercial; module-entitled) · Assessed 2026-09-21 · Research preview

Operational maturity

How completely does public documentation describe operating safeguards for running vulnerability and exposure assessment safely and accountably?

Documented authentication, role separation, credential and sensor handling, activity records, and named environment limits. This is not vendor age, size, uptime, or claimed reliability.

Documented Tenable One family combines entitled VM, WAS, identity, cloud, OT, and ASM products with Exposure Management attack paths, exposure cards, and third-party connectors. Several Exposure View and attack-path features are license-gated; connectors and AI path summaries are not supported in FedRAMP Moderate.

Score4.0 / 5.0medium confidence

Rationale and sources

Docs describe Tenable One SAML, FedRAMP Moderate product coverage, and tiered VM roles from Read-Only through Administrator plus resource permissions on tags, assets, and findings. Administrators can view and export activity logs; scan managers handle scans without full user administration; managed credentials and agent freeze windows are documented. Gaps are named: SAML assertion encryption is unsupported, and many connectors are outside FedRAMP Moderate. That maps to anchor 4, not 5, because environment and encryption gaps remain.

Constraints

  • Tenable One is a product family; VM, WAS, Identity Exposure, Cloud Exposure, OT Exposure, ASM, and AI Exposure are separately entitled.
  • Exposure View, custom exposure cards, and Top Attack Paths require Ratio-Based Tenable One or Tenable One Advanced licensing.
  • Tenable Exposure Management is only available as part of Tenable One.
  • Third-party connectors and AI-powered attack-path summaries are not supported in Tenable FedRAMP Moderate environments.
  • Tenable One SAML does not support assertion encryption.
  • Connector ingest delay of up to one hour is documented; connector fidelity versus source tools is unverified.
  • Recast rules are eventually consistent and do not modify raw scan results.
  • No lab assessment of scan safety, scoring accuracy, or remediation efficacy was performed.
  • Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition.

Sources

0–5 rubric anchors

  • 0 — Primary evidence affirmatively establishes that the evaluated scope does not provide operating safeguards for the scoped assessment workflow. Missing evidence is unknown, never zero.
  • 1 — A concrete basic operating safeguard is documented for the evaluated edition.
  • 2 — Docs describe basic roles plus some scan or agent configuration, without SSO, audit export, or scoped asset access.
  • 3 — Docs describe role-based access, credentialed or agent assessment setup, and at least one of SSO or activity logs for the evaluated offering.
  • 4 — Docs describe SSO/SAML or equivalent, multi-role RBAC with data-scope permissions, credential or sensor safeguards, and auditable operator actions, with named environment gaps.
  • 5 — Docs describe a complete operating-safeguard set including SSO, least-privilege RBAC, credential vaults and scan safety, full activity export, and authorized environment coverage with no material undocumented gaps.
Assessed offerings inExposure and vulnerability management platforms. Unknown means not scored, not low quality.
OfferingOperational maturityShipped innovationCapability breadthEcosystem & integrationGovernance & controlOperator enablement
Tenable One4.0 (medium)3.0 (low)4.0 (medium)4.0 (medium)4.0 (medium)4.0 (medium)
Qualys VMDR4.3 (medium)3.0 (low)3.0 (medium)3.0 (medium)4.0 (medium)4.0 (medium)
Rapid7 Exposure Command4.0 (medium)3.0 (low)4.0 (medium)4.0 (medium)4.0 (medium)4.0 (medium)
Microsoft Security Exposure Management4.0 (medium)3.0 (low)4.0 (medium)3.0 (medium)4.0 (medium)4.0 (medium)

Not yet assessed

Unknown is explicitly not low quality. These catalog offerings have no Atlas Fold scores.

Research notes

First edition dated 2026-09-21; no historical assessments are available.

The four selected existing-catalog offerings form one explicitly scoped cohort. Assessment applies only to named editions and documented modules; adjacent products and managed-service outcomes are excluded.

Primary sources establish documented capabilities and their prerequisites, not actual effectiveness, reliability, deployment effort, staffing savings or return on investment.

Confidence reflects evidence and inference within the stated scope, not vendor size, age or source count.

Contemporary cohort baseline: Asset inventory, vulnerability assessment, threat/KEV and business context, risk prioritization, exposure or attack-path context where offered, remediation ownership/orchestration, and reassessment are contemporary baseline workflows. Scan-to-ticket automation, a branded risk score and graph views alone do not establish differentiation.

Innovation stage 3 indicates supported baseline workflows, not market novelty. No stage 4 or 5 differentiation is established by this first-edition evidence. Public-documentation confidence is low for cross-offering calibration.

Zero requires affirmative evidence of absence. Missing, gated or incomplete documentation remains unknown; a lower stage is not assigned merely because documentation is unavailable.

Scores were checked against cumulative stage prerequisites; selected operating/control cells remain unknown where those prerequisites could not be verified.

Rubric 1.1 adds tenths only for the new maturity anchor 5 requirements: credential-vault workflow (two), scan safety (two), full offering activity export (three), and authorized environment coverage without material undocumented gaps (three). Export completeness and coverage receive the larger shares because they close the operating program across the evaluated scope. Basic RBAC, authentication and existing operator logs do not earn duplicate credit. Qualys SAML and subscription audit-export documentation correct an earlier evidence gap. Tenable One and Rapid7 module-specific export claims are not presumed to cover their entire evaluated platforms; Microsoft’s documented coverage limits remain. Innovation baseline ties stay at 3.0.

All six dimensions were re-reviewed for the 2026-09-21 momentum baseline. Additional source-backed anchor and evidence-gap corrections are documented in docs/research/2026-09-21-momentum-baseline-b.md. These are baseline research corrections, not measured vendor progress; historical comparisons require later comparable review snapshots.

How to read these scores

Scores use tenths from 0.0 to 5.0 against published anchors. Fractional scores credit documented requirements toward the next anchor; the inspector exposes the calculation. Equal evidence can still produce a tie. Null means unknown and is never treated as zero. Views never average or blend dimensions into an overall winner. Cohort membership is the only comparison boundary.

What this edition covers.

First edition · reviewed · rubric 1.1. Historical movement will require later dated assessments; no trajectory is inferred from this snapshot.

  • First edition dated 2026-09-21; no historical assessments are available.
  • The four selected existing-catalog offerings form one explicitly scoped cohort. Assessment applies only to named editions and documented modules; adjacent products and managed-service outcomes are excluded.
  • Primary sources establish documented capabilities and their prerequisites, not actual effectiveness, reliability, deployment effort, staffing savings or return on investment.
  • Confidence reflects evidence and inference within the stated scope, not vendor size, age or source count.
  • Contemporary cohort baseline: Asset inventory, vulnerability assessment, threat/KEV and business context, risk prioritization, exposure or attack-path context where offered, remediation ownership/orchestration, and reassessment are contemporary baseline workflows. Scan-to-ticket automation, a branded risk score and graph views alone do not establish differentiation.
  • Innovation stage 3 indicates supported baseline workflows, not market novelty. No stage 4 or 5 differentiation is established by this first-edition evidence. Public-documentation confidence is low for cross-offering calibration.
  • Zero requires affirmative evidence of absence. Missing, gated or incomplete documentation remains unknown; a lower stage is not assigned merely because documentation is unavailable.
  • Scores were checked against cumulative stage prerequisites; selected operating/control cells remain unknown where those prerequisites could not be verified.
  • Rubric 1.1 adds tenths only for the new maturity anchor 5 requirements: credential-vault workflow (two), scan safety (two), full offering activity export (three), and authorized environment coverage without material undocumented gaps (three). Export completeness and coverage receive the larger shares because they close the operating program across the evaluated scope. Basic RBAC, authentication and existing operator logs do not earn duplicate credit. Qualys SAML and subscription audit-export documentation correct an earlier evidence gap. Tenable One and Rapid7 module-specific export claims are not presumed to cover their entire evaluated platforms; Microsoft’s documented coverage limits remain. Innovation baseline ties stay at 3.0.
  • All six dimensions were re-reviewed for the 2026-09-21 momentum baseline. Additional source-backed anchor and evidence-gap corrections are documented in docs/research/2026-09-21-momentum-baseline-b.md. These are baseline research corrections, not measured vendor progress; historical comparisons require later comparable review snapshots.

Exposure and vulnerability management platforms

Comparable exposure and vulnerability-management platforms and entitled editions. Exclude managed-service comparisons, BAS-only tools, and retired Cisco Vulnerability Management (formerly Kenna.VM).

Find your next idea.

Tip: press / to open search. Escape closes this window.