By HumanAudit Inc. editorial teamLast reviewed 5 August 2026
VerifiedLast reviewed 5 August 2026 by the HumanAudit Inc. editorial team.Corrections logEditorial policy
On this page
  1. What changed in 2026
  2. Diligence that matters now
  3. The pricing trap
  4. Terms to secure
  5. Vendor-written requirements
  6. Whether to buy at all
  7. FAQ

TL;DR

  • All three leading independent NHI platforms were acquired or placed under agreement between May and July 2026. Any shortlist predating that is invalid.
  • You are now buying a platform relationship. Lock-in is a first-class evaluation criterion, not a footnote.
  • Per-identity pricing is the trap. Discovery routinely finds several times the estimated count, and the bill scales with the finding.
  • Secure standalone purchasability, price protection and exit in writing before the parent restructures the portfolio.
  • If the organisation has no inventory or ownership model, the correct procurement decision is not yet.

What changed in 2026

Between May and July 2026, Astrix was acquired by Cisco, SailPoint completed its acquisition of Entro, and Cyera signed a letter of intent for Oasis. Related transactions included Cisco acquiring WideField and 1Password acquiring Apono. Our consolidation tracker records each with dates, status and reported values.

Two procurement consequences follow. First, the incumbent-versus-challenger framing no longer applies, because the challengers are now inside incumbents. Second, the decision has moved up a level: you are choosing which platform governs identity in your organisation for the next several years, and the NHI module is one expression of that choice.

Diligence that matters now

  1. Ownership and integration status. Who owns this product today, when did that change, and where is it in the integration programme? A product six months into absorption behaves differently from one twelve months in.
  2. Standalone availability. Is it separately purchasable, on what terms, and for how long is that guaranteed? Vendors have made public statements on this; get the commercial version in the contract.
  3. Roadmap authority. Which parts of the roadmap are now set by the parent rather than the acquired team? This determines whether your requirements can influence anything.
  4. Team retention. Are the people who built the discovery engine still working on it? Post-acquisition attrition is the leading cause of roadmap slippage and is visible in public professional profiles.
  5. Support model. Whose support organisation answers, at what tier, under whose SLA. This changes during integration and is rarely volunteered.

The pricing trap

Per-identity pricing is common and creates a specific, predictable problem: the product's core value is finding identities you did not know about, and the bill scales with how well it does that.

Discovery routinely surfaces two to five times the estimated count. If the commercial model is per identity and the estimate came from your existing partial inventory, the first true-up is substantial and arrives after the tool is embedded and switching costs are real.

Three protections, in order of usefulness:

  • Price on a band, not a count, with a defined and generous band width. This removes the incentive misalignment entirely.
  • Cap the first-year true-up at a stated percentage regardless of discovery outcome. Vendors confident in their estimate will accept this.
  • Run discovery during the POC and price afterwards. The cleanest option where the vendor will agree to it, and a meaningful signal if they will not.

Ask directly what happens if discovery finds three times the estimate. The answer, and how quickly it comes, tells you how often it has happened.

Terms to secure

  • Standalone continuity. The product remains separately purchasable and supported for a defined term irrespective of parent portfolio decisions.
  • Price protection on renewal, capped, and explicitly surviving a change of control.
  • Data portability and exit. Your inventory, ownership mappings and historical evidence are exportable in a documented machine-readable format on termination. This matters more than usual here, because the audit history is the asset.
  • Change-of-control notification with a defined window and a termination right if material terms change.
  • Evidence retention for the period your audit cycle requires, and clarity on whether retention beyond the default is a separate charge.
  • Remediation blast-radius limits in the SLA where automated revocation is in scope. A tool that can revoke can cause an outage.

Spotting vendor-written requirements

Requirements documents in this category are frequently assembled from vendor material, sometimes by well-meaning internal teams using a preferred vendor's datasheet as a starting point. That produces a specification only one bidder can satisfy, which is a competition problem and often a governance one.

Signals worth checking:

  • Proprietary category names used as if they were standards. Terms like NHIDR are vendor coinages, not defined categories. See the standards tracker for what is actually ratified.
  • Claims of compliance with a non-existent standard. There is no NHI standard and no certification scheme for non-human identity governance. A requirement to be "compliant with the NHI standard" was not written by someone who checked.
  • Integration lists matching one vendor's published coverage exactly, including the unusual entries.
  • Feature language that reads as a product tour rather than an outcome. Requirements should state what the organisation must be able to do, not which screens exist.

Whether to buy at all

For a meaningful number of organisations the correct decision is not yet. If there is no inventory, no ownership model and no rotation policy, a platform will produce a well-organised list of problems the organisation is not structured to fix, at six-figure annual cost, and the programme will stall while the licence renews.

The sequence that works: establish inventory and ownership using existing and cloud-native tooling, define what good looks like for the highest-risk identity classes, then buy a platform to scale a process that already exists. Our maturity model gives a scoring method; below level 2 the honest recommendation is usually internal work first. The RFP question bank covers the evaluation itself.

Frequently asked questions

How has NHI vendor procurement changed after the 2026 consolidation?

The decision has moved from choosing a point tool to choosing a platform relationship. Astrix is now part of Cisco, Entro part of SailPoint, and Oasis is under a signed letter of intent from Cyera, so capability sits inside larger platforms. Ownership status, standalone purchasability, roadmap authority and support model are now first-order diligence questions rather than footnotes, and platform lock-in is a legitimate evaluation criterion.

What is the risk of per-identity pricing for NHI platforms?

The product's core value is discovering identities you did not know about, and per-identity pricing means the bill scales with how well it performs. Discovery routinely finds two to five times the estimated count, so the first true-up can be substantial and arrives after switching costs are real. Price on a generous band rather than a count, cap the first-year true-up, or run discovery during the POC and price afterwards.

What contract terms matter most when the vendor has been acquired?

Standalone continuity for a defined term irrespective of parent portfolio decisions, renewal price protection that survives change of control, documented machine-readable data portability on exit because the audit history is the asset, change-of-control notification with a termination right, and clarity on evidence retention periods and whether extended retention is chargeable.

How can you tell if a requirements document was written from vendor material?

Look for proprietary category names used as if they were standards, requirements to comply with a non-existent NHI standard, integration lists that match one vendor's published coverage exactly including unusual entries, and feature language that reads as a product tour rather than an outcome statement. Any of these narrows the field to a single bidder and is worth challenging before issue.

Should we buy an NHI platform if we have no inventory yet?

Usually not. Without an inventory, an ownership model or a rotation policy, a platform delivers a well-organised list of problems the organisation is not structured to fix, at six-figure annual cost, and the programme stalls while the licence renews. Establish inventory and ownership with existing tooling first, then procure to scale a process that already works.

Running an NHI procurement?

HumanAudit supports vendor-neutral evaluations: requirements definition that no single vendor wrote, POC design against your own estate, and a scored recommendation. We take no vendor fees.