At a glance
| Founded | 1999 |
|---|---|
| Headquarters | Petach Tikva, Israel / Newton, MA |
| Category | PAM / machine identity / secrets, broadest surface among incumbents |
| Key products (NHI-relevant) | Secrets Manager (incl. Conjur), Secure Cloud Access, Venafi TLS Protect, Venafi Firefly (workload identity) |
| Recent M&A | Acquired Venafi Oct 2024 (~$1.54B); acquired by Palo Alto Networks (closed 11 Feb 2026, ~$25B) |
| Position in category | Incumbent platform with the deepest privileged-NHI heritage; now under PANW |
What they do (in NHI terms)
CyberArk's NHI-relevant surface spans three distinct product lineages that have been pulled together under one portfolio:
- Secrets management. Conjur (acquired 2017) and the CyberArk Secrets Manager hub remain serious competitors in enterprise secrets-management deployments, particularly where integration with existing CyberArk PAM is already in place.
- Privileged access for NHIs. The core CyberArk vault has been storing privileged service-account credentials for two decades. Much of what the industry now calls "NHI governance" was, in regulated enterprises, historically addressed partially by CyberArk PAM.
- Machine identity (Venafi lineage). TLS Protect, Firefly (workload identity), and the CodeSign Protect product cover the PKI/certificate side of machine identity that most NHI-platform startups don't touch.
The PANW transaction and what it signals
Palo Alto Networks closing the CyberArk acquisition in February 2026 is the most consequential identity-security M&A event of the decade. The strategic logic is that identity, including NHI, becomes a component of a broader security platform rather than a standalone category. For CyberArk customers, the immediate product continuity is expected; the longer question is how the identity roadmap converges (or doesn't) with PANW's platform direction.
For buyers evaluating CyberArk today, the relevant considerations are:
- Existing CyberArk footprint makes continuing attractive and reduces integration cost for NHI-adjacent modules.
- Greenfield NHI buyers without CyberArk PAM tend to find the startup NHI platforms easier to deploy and faster to value, but narrower in scope.
- Certificate/PKI-heavy enterprises benefit specifically from the Venafi lineage, which has little direct competition.
Differentiators
- Breadth. No startup covers human PAM + NHI secrets + PKI + workload identity under one contract.
- Enterprise track record. Regulated, global deployments, complex integration stacks, auditor familiarity.
- PANW platform leverage. If an organisation is already a PANW platform buyer, the commercial and integration calculus tilts.
Practical notes
- Complexity: CyberArk deployments are heavier than startup NHI platforms. The breadth is real but has an operational cost.
- Licensing: Enterprise-negotiated; post-PANW, watch for platform-bundle pricing.
- Integration surface: Large, mature, but older in places. The Venafi lineage and the Conjur lineage have distinct operational models.
- Cloud-native: Steady investment; historically the startup NHI platforms have been faster to ship cloud-native workflow UX, though the gap is narrowing.
When CyberArk makes sense
CyberArk is a reasonable shortlist candidate when the driver is:
- "We already have CyberArk PAM and need to extend to NHIs without adding another platform."
- "We need certificate/PKI governance alongside secrets and privileged identity."
- "We're standardising on a PANW platform and identity consolidation is part of that."
Less obvious fit when the driver is:
- "We need SaaS OAuth-app discovery and posture as our first problem", startup NHI platforms are better there.
- "We need agent-less, fast-to-deploy NHI inventory with minimal integration work", the startup platforms have less weight.
- "We're avoiding PANW platform lock-in", worth noting in the decision frame.
What we don't know
- The full shape of the CyberArk product roadmap under PANW at the 18-24 month horizon. Guidance has been continuity-oriented; execution is the question.
- Whether discrete CyberArk products will converge into PANW-branded platform modules, and on what timeline.
Assess your own NHI programme.
Run the free maturity assessment or the OWASP NHI Top 10 self-audit, get your score in the browser, and unlock the full written report.