By HumanAudit Inc. editorial teamLast reviewed 5 August 2026
VerifiedLast reviewed 5 August 2026 by the HumanAudit Inc. editorial team.Corrections logEditorial policy
On this page
  1. At a glance
  2. What they do (in NHI terms)
  3. The PANW transaction and what it signals
  4. Differentiators
  5. Practical notes
  6. When CyberArk makes sense
  7. What we don't know

At a glance

Founded1999
HeadquartersPetach Tikva, Israel / Newton, MA
CategoryPAM / machine identity / secrets, broadest surface among incumbents
Key products (NHI-relevant)Secrets Manager (incl. Conjur), Secure Cloud Access, Venafi TLS Protect, Venafi Firefly (workload identity)
Recent M&AAcquired Venafi Oct 2024 (~$1.54B); acquired by Palo Alto Networks (closed 11 Feb 2026, ~$25B)
Position in categoryIncumbent platform with the deepest privileged-NHI heritage; now under PANW

What they do (in NHI terms)

CyberArk's NHI-relevant surface spans three distinct product lineages that have been pulled together under one portfolio:

  • Secrets management. Conjur (acquired 2017) and the CyberArk Secrets Manager hub remain serious competitors in enterprise secrets-management deployments, particularly where integration with existing CyberArk PAM is already in place.
  • Privileged access for NHIs. The core CyberArk vault has been storing privileged service-account credentials for two decades. Much of what the industry now calls "NHI governance" was, in regulated enterprises, historically addressed partially by CyberArk PAM.
  • Machine identity (Venafi lineage). TLS Protect, Firefly (workload identity), and the CodeSign Protect product cover the PKI/certificate side of machine identity that most NHI-platform startups don't touch.

The PANW transaction and what it signals

Palo Alto Networks closing the CyberArk acquisition in February 2026 is the most consequential identity-security M&A event of the decade. The strategic logic is that identity, including NHI, becomes a component of a broader security platform rather than a standalone category. For CyberArk customers, the immediate product continuity is expected; the longer question is how the identity roadmap converges (or doesn't) with PANW's platform direction.

For buyers evaluating CyberArk today, the relevant considerations are:

  • Existing CyberArk footprint makes continuing attractive and reduces integration cost for NHI-adjacent modules.
  • Greenfield NHI buyers without CyberArk PAM tend to find the startup NHI platforms easier to deploy and faster to value, but narrower in scope.
  • Certificate/PKI-heavy enterprises benefit specifically from the Venafi lineage, which has little direct competition.

Differentiators

  • Breadth. No startup covers human PAM + NHI secrets + PKI + workload identity under one contract.
  • Enterprise track record. Regulated, global deployments, complex integration stacks, auditor familiarity.
  • PANW platform leverage. If an organisation is already a PANW platform buyer, the commercial and integration calculus tilts.

Practical notes

  • Complexity: CyberArk deployments are heavier than startup NHI platforms. The breadth is real but has an operational cost.
  • Licensing: Enterprise-negotiated; post-PANW, watch for platform-bundle pricing.
  • Integration surface: Large, mature, but older in places. The Venafi lineage and the Conjur lineage have distinct operational models.
  • Cloud-native: Steady investment; historically the startup NHI platforms have been faster to ship cloud-native workflow UX, though the gap is narrowing.

When CyberArk makes sense

CyberArk is a reasonable shortlist candidate when the driver is:

  • "We already have CyberArk PAM and need to extend to NHIs without adding another platform."
  • "We need certificate/PKI governance alongside secrets and privileged identity."
  • "We're standardising on a PANW platform and identity consolidation is part of that."

Less obvious fit when the driver is:

  • "We need SaaS OAuth-app discovery and posture as our first problem", startup NHI platforms are better there.
  • "We need agent-less, fast-to-deploy NHI inventory with minimal integration work", the startup platforms have less weight.
  • "We're avoiding PANW platform lock-in", worth noting in the decision frame.

What we don't know

  • The full shape of the CyberArk product roadmap under PANW at the 18-24 month horizon. Guidance has been continuity-oriented; execution is the question.
  • Whether discrete CyberArk products will converge into PANW-branded platform modules, and on what timeline.

Assess your own NHI programme.

Run the free maturity assessment or the OWASP NHI Top 10 self-audit, get your score in the browser, and unlock the full written report.