Each row is one 0.0–5.0 dimension. Every assessed offering has a consistent color, shape, and number. Numbers identify offerings, not rank. Unknown scores are omitted.
Separated marks connect to their exact positions. Separation does not change scores.
Momentum: building history. Numbers identify offerings, not rank; lines between dimensions are profiles, not time.
Missing evidence for this view
Unknown is not a low score. Select an offering above to inspect its evidence.
A position is only half the story
Momentum
Building history
Baseline recorded 2026-09-21. A second comparable review is needed to show movement.
Own movement is the score change. Relative movement subtracts the median change of matched peers, excluding this offering. Dimensions stay separate.
Tenable One· movement by dimension
Dimension
Own movement
Against peers
Operational maturity
Building history
Not available yetNo direction inferred
Shipped innovation
Building history
Not available yetNo direction inferred
Capability breadth
Building history
Not available yetNo direction inferred
Ecosystem & integration
Building history
Not available yetNo direction inferred
Governance & control
Building history
Not available yetNo direction inferred
Operator enablement
Building history
Not available yetNo direction inferred
History appears as a hollow earlier mark connected to the current solid mark in Unfold and Overview. Profile lines between dimensions do not show time. Numbers identify offerings, not rank.
Review history & what changed
The 2026-09-21 baseline incorporates the six-dimension review. Decimal calibration and research corrections are not product momentum. Unknowns stay unknown.
2026-09-21 · baseline · rubric 1.1 · Starting point; no movement inferred.
Qualys VMDR (medium confidence) has the highest documented score (4.3) for Operational maturity among assessed offerings in this comparison group.
Tenable One (low confidence) and Qualys VMDR (low confidence) and Rapid7 Exposure Command (low confidence) and Microsoft Security Exposure Management (low confidence) are tied at documented score 3.0 for Shipped innovation among assessed offerings in this comparison group. No distinction is evidenced among the scored offerings.
Unknowns and gaps
Unknown is not low quality. Marks are omitted where a required score is unknown.
Tenable One: no unknown dimensions.
Qualys VMDR: no unknown dimensions.
Rapid7 Exposure Command: no unknown dimensions.
Microsoft Security Exposure Management: no unknown dimensions.
Scenario lens
A scenario highlights priorities and validation questions only. It does not rewrite scores or claim eligibility.
Selected evidence
Tenable One · Tenable
Tenable One Exposure Management Platform (commercial; module-entitled) · Assessed 2026-09-21 · Research preview
Operational maturity
How completely does public documentation describe operating safeguards for running vulnerability and exposure assessment safely and accountably?
Documented authentication, role separation, credential and sensor handling, activity records, and named environment limits. This is not vendor age, size, uptime, or claimed reliability.
Documented Tenable One family combines entitled VM, WAS, identity, cloud, OT, and ASM products with Exposure Management attack paths, exposure cards, and third-party connectors. Several Exposure View and attack-path features are license-gated; connectors and AI path summaries are not supported in FedRAMP Moderate.
Score4.0 / 5.0medium confidence
Comparison:
Rationale and sources
Docs describe Tenable One SAML, FedRAMP Moderate product coverage, and tiered VM roles from Read-Only through Administrator plus resource permissions on tags, assets, and findings. Administrators can view and export activity logs; scan managers handle scans without full user administration; managed credentials and agent freeze windows are documented. Gaps are named: SAML assertion encryption is unsupported, and many connectors are outside FedRAMP Moderate. That maps to anchor 4, not 5, because environment and encryption gaps remain.
How this score is built
Constraints
Tenable One is a product family; VM, WAS, Identity Exposure, Cloud Exposure, OT Exposure, ASM, and AI Exposure are separately entitled.
Exposure View, custom exposure cards, and Top Attack Paths require Ratio-Based Tenable One or Tenable One Advanced licensing.
Tenable Exposure Management is only available as part of Tenable One.
Third-party connectors and AI-powered attack-path summaries are not supported in Tenable FedRAMP Moderate environments.
Tenable One SAML does not support assertion encryption.
Connector ingest delay of up to one hour is documented; connector fidelity versus source tools is unverified.
Recast rules are eventually consistent and do not modify raw scan results.
No lab assessment of scan safety, scoring accuracy, or remediation efficacy was performed.
Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition.
0 — Primary evidence affirmatively establishes that the evaluated scope does not provide operating safeguards for the scoped assessment workflow. Missing evidence is unknown, never zero.
1 — A concrete basic operating safeguard is documented for the evaluated edition.
2 — Docs describe basic roles plus some scan or agent configuration, without SSO, audit export, or scoped asset access.
3 — Docs describe role-based access, credentialed or agent assessment setup, and at least one of SSO or activity logs for the evaluated offering.
4 — Docs describe SSO/SAML or equivalent, multi-role RBAC with data-scope permissions, credential or sensor safeguards, and auditable operator actions, with named environment gaps.
5 — Docs describe a complete operating-safeguard set including SSO, least-privilege RBAC, credential vaults and scan safety, full activity export, and authorized environment coverage with no material undocumented gaps.
Assessed offerings inExposure and vulnerability management platforms. Unknown means not scored, not low quality.
First edition dated 2026-09-21; no historical assessments are available.
The four selected existing-catalog offerings form one explicitly scoped cohort. Assessment applies only to named editions and documented modules; adjacent products and managed-service outcomes are excluded.
Primary sources establish documented capabilities and their prerequisites, not actual effectiveness, reliability, deployment effort, staffing savings or return on investment.
Confidence reflects evidence and inference within the stated scope, not vendor size, age or source count.
Contemporary cohort baseline: Asset inventory, vulnerability assessment, threat/KEV and business context, risk prioritization, exposure or attack-path context where offered, remediation ownership/orchestration, and reassessment are contemporary baseline workflows. Scan-to-ticket automation, a branded risk score and graph views alone do not establish differentiation.
Innovation stage 3 indicates supported baseline workflows, not market novelty. No stage 4 or 5 differentiation is established by this first-edition evidence. Public-documentation confidence is low for cross-offering calibration.
Zero requires affirmative evidence of absence. Missing, gated or incomplete documentation remains unknown; a lower stage is not assigned merely because documentation is unavailable.
Scores were checked against cumulative stage prerequisites; selected operating/control cells remain unknown where those prerequisites could not be verified.
Rubric 1.1 adds tenths only for the new maturity anchor 5 requirements: credential-vault workflow (two), scan safety (two), full offering activity export (three), and authorized environment coverage without material undocumented gaps (three). Export completeness and coverage receive the larger shares because they close the operating program across the evaluated scope. Basic RBAC, authentication and existing operator logs do not earn duplicate credit. Qualys SAML and subscription audit-export documentation correct an earlier evidence gap. Tenable One and Rapid7 module-specific export claims are not presumed to cover their entire evaluated platforms; Microsoft’s documented coverage limits remain. Innovation baseline ties stay at 3.0.
All six dimensions were re-reviewed for the 2026-09-21 momentum baseline. Additional source-backed anchor and evidence-gap corrections are documented in docs/research/2026-09-21-momentum-baseline-b.md. These are baseline research corrections, not measured vendor progress; historical comparisons require later comparable review snapshots.
How to read these scores
Scores use tenths from 0.0 to 5.0 against published anchors. Fractional scores credit documented requirements toward the next anchor; the inspector exposes the calculation. Equal evidence can still produce a tie. Null means unknown and is never treated as zero. Views never average or blend dimensions into an overall winner. Cohort membership is the only comparison boundary.
What this edition covers.
First edition · reviewed · rubric 1.1. Historical movement will require later dated assessments; no trajectory is inferred from this snapshot.
First edition dated 2026-09-21; no historical assessments are available.
The four selected existing-catalog offerings form one explicitly scoped cohort. Assessment applies only to named editions and documented modules; adjacent products and managed-service outcomes are excluded.
Primary sources establish documented capabilities and their prerequisites, not actual effectiveness, reliability, deployment effort, staffing savings or return on investment.
Confidence reflects evidence and inference within the stated scope, not vendor size, age or source count.
Contemporary cohort baseline: Asset inventory, vulnerability assessment, threat/KEV and business context, risk prioritization, exposure or attack-path context where offered, remediation ownership/orchestration, and reassessment are contemporary baseline workflows. Scan-to-ticket automation, a branded risk score and graph views alone do not establish differentiation.
Innovation stage 3 indicates supported baseline workflows, not market novelty. No stage 4 or 5 differentiation is established by this first-edition evidence. Public-documentation confidence is low for cross-offering calibration.
Zero requires affirmative evidence of absence. Missing, gated or incomplete documentation remains unknown; a lower stage is not assigned merely because documentation is unavailable.
Scores were checked against cumulative stage prerequisites; selected operating/control cells remain unknown where those prerequisites could not be verified.
Rubric 1.1 adds tenths only for the new maturity anchor 5 requirements: credential-vault workflow (two), scan safety (two), full offering activity export (three), and authorized environment coverage without material undocumented gaps (three). Export completeness and coverage receive the larger shares because they close the operating program across the evaluated scope. Basic RBAC, authentication and existing operator logs do not earn duplicate credit. Qualys SAML and subscription audit-export documentation correct an earlier evidence gap. Tenable One and Rapid7 module-specific export claims are not presumed to cover their entire evaluated platforms; Microsoft’s documented coverage limits remain. Innovation baseline ties stay at 3.0.
All six dimensions were re-reviewed for the 2026-09-21 momentum baseline. Additional source-backed anchor and evidence-gap corrections are documented in docs/research/2026-09-21-momentum-baseline-b.md. These are baseline research corrections, not measured vendor progress; historical comparisons require later comparable review snapshots.
Exposure and vulnerability management platforms
Comparable exposure and vulnerability-management platforms and entitled editions. Exclude managed-service comparisons, BAS-only tools, and retired Cisco Vulnerability Management (formerly Kenna.VM).