Blog, Invicti Blog
Invicti Named a Leader in 2026 IDC MarketScape for DAST — and What It Says About the Future of Runtime Testing
Invicti Security has been positioned in the Leaders Category in the IDC MarketScape: Worldwide Dynamic Application Security Testing 2026 Vendor Assessment (Doc #US54119126, September 2026).
The IDC MarketScape evaluated 16 DAST vendors based on current capabilities and future strategy, drawing on vendor surveys, briefings, public information, and customer feedback.
Invicti was recognized for strengths in:
-
Exploitability validation through proof-based scanning
-
AI-assisted business logic and abuse case testing without predefined scripts
-
End-to-end API discovery and testing
According to Neil Roseman, CEO of Invicti Security, DAST has always been about understanding what software actually does when it runs, and that runtime perspective is becoming even more important as AI changes how quickly software is created and shipped. He noted that being named a Leader validates both the strength of the DAST technology customers rely on today and the direction the company is taking it: bringing proven runtime intelligence together with application security testing during development and agentic pentesting so teams can find, validate, and prioritize the risks that matter.
Why This Matters Now: AI Is Changing the Risk Equation
The recognition comes as AI-assisted development accelerates both delivery speed and the importance of runtime testing.
Key findings from IDC’s DevSecOps and Software Supply Chain Security Survey (July 2026):
-
90% of organizations are piloting or have adopted AI coding tools
-
Nearly three-quarters agree these tools raise the risk that developers merge code they do not fully understand, even when scans pass
-
48% of organizations using AI coding tools reported a moderate or significant increase in security issues reaching production
The IDC MarketScape notes that as security issues increasingly reach production, DAST provides an essential backstop by testing applications as they run and exposing weaknesses and behaviors that may escape manual review and earlier-stage scanning.
Katie Norton, Research Director for Cloud Security at IDC, observed that code is moving into production faster and with less scrutiny, and applications themselves are becoming more nondeterministic, making runtime testing more critical than it has been in the past.
The Three Invicti Strengths Recognized by IDC
1. Exploitability Validation Through Proof-Based Scanning
Rather than reporting a candidate vulnerability, Invicti’s engine executes a nondestructive follow-on payload to retrieve verifiable evidence, such as a database version or system output, and tags confirmed findings distinctly from unconfirmed ones.
Why it matters: Provides teams with a basis for prioritizing remediation without routing every finding to a security team for manual confirmation.
2. AI-Assisted Business Logic and Abuse Case Testing Without Predefined Scripts
-
AI-driven login agent handles authentication
-
AI-assisted form filler supplies contextually valid data
-
Stateful API scanning infers parameter relationships to catch workflow manipulation and business rule bypass
Why it matters: Extends coverage beyond signature-based detection without scripted test cases.
3. End-to-End API Discovery and Testing
-
Multilayer API discovery across scanning, source code, traffic, and eBPF analysis
-
AI-enriched schemas add source code context to improve testing depth
-
Native CI/CD integration automates API security testing throughout the SDLC
Why it matters: Connects inventory to security, ensuring APIs are tested across the entire development lifecycle.
What Customers Say
According to the IDC MarketScape report, customers describe Invicti’s output as trustworthy and largely free of false positives, requiring limited additional triage before a finding reaches a developer. They also cite the platform’s configuration flexibility, such as the ability to scope scans to a specific technology stack, as a strength. Customers also value the vendor relationship itself, citing direct access to engineering staff rather than sales contacts, and a responsive technical account team.
DAST Has Grown Beyond the Vulnerability Scanner
The IDC MarketScape makes an important observation about the evolving definition of DAST. IDC does not limit the evaluation to a single DAST architecture or testing approach. The defining criterion is the solution’s core function: detecting vulnerabilities by analyzing the behavior of a running application. Solutions may accomplish this through traditional external black box scanning, instrumentation within the application runtime, AI agents that adapt testing based on application responses, or a combination of these methods.
This matters because the defining question for DAST is less about how a scanner is implemented and more about what security teams can learn by exercising an application in its running state.
Runtime Testing Has to Follow Where Applications Have Gone
Modern applications increasingly span APIs, authentication states, multistep workflows, and distributed services. Security testing has to follow that behavior rather than stopping at the browser interface.
Invicti’s multi-layered API discovery helps connect inventory to security before testing begins. Crawling pages and submitting generic payloads remains useful, but it cannot tell the whole story when the application is a collection of interconnected services, APIs, identities, and workflows. Modern DAST needs to be API-aware, with enough visibility into application architecture and context to exercise meaningful behavior.
DAST as the Connective Tissue of AppSec
No single testing technique can see every type of application risk. A modern AppSec toolkit combines multiple methods:
-
SAST sees vulnerable code before an application runs
-
SCA identifies risk in third-party and open-source dependencies
-
Other techniques cover secrets, infrastructure definitions, containers, and APIs
The challenge is turning all those signals into coherent risk-based decisions rather than another stack of disconnected findings.
Invicti’s DAST-first strategy:
-
Grounds a broader AppSec program in evidence about what applications actually do when they run
-
Brings runtime evidence together with signals from source code, dependencies, APIs, and infrastructure
-
Uses correlation, reachability, exploitability, business context, and threat intelligence to turn signals into risk decisions
Key capabilities:
-
DAST-to-SAST correlation: Connects compatible dynamic findings with relevant source-code paths
-
ASPM: Aggregates and deduplicates findings, applies policies, automates workflows, tracks remediation
The IDC MarketScape states that Invicti is well suited to organizations that want a vendor combining an established DAST engine with visible, active investment in where the technology is heading next, and that view this purchase as an early step toward potential broader application security consolidation.
Agentic Pentesting Extends the Runtime Foundation
The next step in this evolution is already taking shape as the boundary between automated DAST and autonomous pentesting begins to narrow.
The IDC MarketScape describes this relationship directly: DAST can provide the foundation for broad coverage and validated evidence, while agentic reasoning enables tools to adapt their techniques and pursue connected attack paths.
Autonomous reasoning builds on the runtime foundation rather than discarding it. An agent may decide what to try next, but effective testing still depends on the ability to navigate applications, maintain state, exercise inputs, identify weaknesses, and validate what happens.
Additional Independent Recognition in 2026
Latio 2026 Application Security Market Report
Named Invicti an Application Security Testing Leader and DAST Innovator.
Miercom Benchmark Testing
Invicti DAST was the only tested solution to detect all 31 critical vulnerabilities across 11 modern application targets, earning the Miercom Certified Secure designation.
Bottom Line
For security leaders, finding counts alone are not the goal. They need to understand application risk with enough confidence and context to act on it. That is the opportunity in the next generation of DAST: not as an isolated scanner, but as the runtime foundation for a more connected and increasingly adaptive approach to application security.
Ready to see why Invicti is a DAST Leader?
LOGON Software Asia – the trusted Invicti partner in Asia – offers:
-
✅ Free Proof of Concept (POC)
-
✅ Preferred pricing
-
✅ Priority support
-
✅ Local expertise


Keeping The Internet Secure
Invicti’s DAST solutions help protect web applications around the world.
Get a Demo with Invicti
Get a demo with LOGON Team to learn how to dramatically reduce your risk of attacks with the accurate, automated application security testing


