About the Cybersecurity Product / Service awards
What belongs in this group
This group is for products and services: software, platforms, hardware and delivered services that protect organizations.
The other three groups cover different kinds of nominee. Enter the company itself in Cybersecurity Company, its leaders and teams in Cybersecurity Professional / Team, and a deployment built for a specific sector in Cybersecurity Industry Solution. A vendor commonly enters more than one group in the same season.
Choosing a category
Start with the category that matches what the product mainly does, then add the related categories that also fit. A platform that spans several areas can be entered in each matching category with its own nomination, and every one is judged separately. The most specific category is usually the strongest place to start.
Browse categories by theme
The categories below are grouped by the problem they address. This is a selection of the main categories in each theme, not the full list.
- Identity and access — Identity and Access Management (IAM), Access Control, Privileged Access Management (PAM), Customer Identity and Access Management (CIAM), Identity Verification (IDV), Multi-Factor Authentication (MFA), Passwordless Authentication, Single Sign-On (SSO), Identity Security Posture Management (ISPM), Identity Threat Detection and Response (ITDR)
- Machine and non-human identity — Non-Human Identity (NHI) Security, Machine Identity Security, Secret and Credential Management, Certificate Lifecycle Management, AI Agent Identity Security
- AI security — Security for AI, AI-Powered Security Solution, AI Usage Control, AI Application and Runtime Security, Agentic AI Security, Agentic Security Platform, Guardian Agents, MCP Security, AI Data Security and Governance, AI Model Security, AI SOC Platform
- Data security — Data Security, Data Security Platform, Data Security Posture Management (DSPM), Data Loss Prevention (DLP), Encryption and Key Management
- Cloud security — Cloud Security, Cloud-Native Application Protection Platform (CNAPP), Cloud Workload Protection Platform (CWPP), Cloud Detection and Response (CDR), SaaS Security Posture Management (SSPM)
- Network and edge — Network Security, Zero Trust Security, Secure Access Service Edge (SASE), Security Service Edge (SSE), Zero Trust Network Access (ZTNA), Hybrid Mesh Firewall (HMF), Network Detection and Response (NDR), Microsegmentation, Network Security Policy Management (NSPM)
- Endpoint and device — Endpoint Security, Endpoint Detection and Response (EDR), Browser Security, Mobile Security, Unified Endpoint Management (UEM), Internet of Things (IoT) Security, Consumer Cybersecurity
- Application and software supply chain — Application Security, Application Security Posture Management (ASPM), Web Application and API Protection (WAAP), API Security, DevSecOps, Software Supply Chain Security, Open Source Security
- Detection, response and operations — Threat Detection and Response, Extended Detection and Response (XDR), Security Information and Event Management (SIEM), Security Data Pipeline Platform, AI SOC Platform, Security Orchestration, Automation and Response (SOAR), Managed Detection and Response (MDR), Security Operations, SOC-as-a-Service, Deception Technology
- Threat intelligence and digital risk — Cyber Threat Intelligence (CTI), Digital Risk Protection (DRP), Disinformation Security
- Exposure and vulnerability — Continuous Threat Exposure Management (CTEM), Exposure Assessment Platform, Attack Surface Management, Vulnerability Management, Adversarial Exposure Validation (AEV), Pentest-as-a-Service (PtaaS), Bug Bounty and Crowdsourced Security
- Email, phishing and human risk — Email Security, Anti-Phishing, Security Awareness Training, Human Risk Management, Insider Risk Management, Social Engineering and Deepfake Defense
- Governance, risk and compliance — Governance, Risk and Compliance (GRC), Compliance Automation, Third Party Risk Management (TPRM), Data Privacy Management
- Resilience and recovery — Cyber Resilience, Business Continuity / Disaster Recovery (BCDR), Ransomware Recovery, Incident Response, Digital Forensics
- OT, ICS and connected systems — OT Security, ICS / SCADA Security, Embedded Security, Critical Infrastructure Security
- Delivered services — Managed Security Service, Cybersecurity-as-a-Service (CSaaS), Virtual CISO
See the full list of award categories.
How entries are judged
An independent jury of security practitioners, analysts and CISOs scores each nomination on leadership, innovation and impact. Each nomination competes in its category against organizations of similar size and region, so a mid-sized firm is not ranked against a global enterprise. Your entry package, any sponsorship and public votes do not affect the jury's scores.
Strong product and service entries show:
- Leadership — that the product is trusted in demanding environments, and that customers rely on it where failure would be costly.
- Innovation — a problem solved that others in the category have not solved, rather than a feature list.
- Impact — what measurably changed for customers after deployment. Specific numbers and named outcomes carry more weight than adjectives.
Useful evidence includes customer references, deployment scale and before-and-after figures. Each category page explains what the jury looks for in that category.
The jury awards Gold, Silver or Bronze, or a Finalist badge, and results are published on this site and announced to the 600,000+ member Cybersecurity Insiders community. Every approved nomination also enters the separate Community Choice award, decided by public votes.
Past recipients are listed on each category page and on the season winners pages for 2026, 2025 and 2024.
How to enter
A vendor can enter its own product or service, and a PR agency can enter it on a client's behalf. The nomination form has a confidential field for detail that is shared with the judges and not published, such as customer names, deployment figures or roadmap. Deadlines, pricing and entry steps are on the How it Works page.