Sonatype: 2025 Gartner Magic Quadrant for AST | Sonatype

Sonatype Named a Visionary in the 2025 Gartner® Magic Quadrant™ for Application Security Testing

October 14, 2025
By Aaron Linskens

3 minute read time

As a leader in AI-centric DevSecOps, Sonatype has been recognized as a Visionary in the 2025 Gartner Magic Quadrant for Application Security Testing (AST).

This marks our second consecutive placement in the report, highlighting our continued momentum and focus on helping organizations engineer security directly into modern software development.

According to Gartner, "Sonatype leverages curated open-source intelligence and AI-powered capabilities to provide automated policy enforcement and advanced remediation, including perimeter protection and malicious open-source component and AI/LLM model blocking via Sonatype Firewall."

Why This Matters

The AST market is evolving rapidly, as software development itself undergoes a transformation.

Traditional approaches that rely solely on inspection late in the pipeline are no longer sufficient. Today's attackers target the software supply chain, where open source components, containers, binaries, and even AI-generated code represent most of the risk surface.

Being recognized as a Visionary validates our belief that the future of security belongs to systems that:

Our Differentiated Approach

At Sonatype, we redefined software composition analysis (SCA) by uniting enterprise-grade analysis with secure binary management, container security, and SBOM life cycle governance — all backed by the world's most trusted artifact manager, Nexus Repository.

Our platform helps organizations:

This holistic, developer-first approach is why some of the largest enterprises in the world trust Sonatype to secure the foundations of their modern software factories.

A Visionary for the Future of AppSec

We believe our recognition as a Visionary underscores our role in shaping the next era of application security:

As our Chief Product Development Officer, Mitchell Johnson, puts it:

"Security can't be inspected into software at the end — it has to be engineered into how we design and develop it from the beginning. We believe our recognition as a Visionary reflects Sonatype's leadership in redefining application security through automation, curated intelligence, and developer-first solutions that optimize quality and prevent risk before it enters the software supply chain."

Driving Innovation Forward

Magic Quadrant reports are the culmination of rigorous, fact-based research in specific markets, providing a wide-angle view of vendor positioning. Providers are evaluated on their Completeness of Vision and Ability to Execute, and placed into one of four quadrants: Leaders, Challengers, Visionaries, and Niche Players.

We are honored to be recognized again this year, and even more motivated to continue building the systems that help the world deliver secure, high-quality software at scale.

Access the 2025 Gartner Magic Quadrant for Application Security Testing report today.

Written by Aaron Linskens
Aaron is a technical writer at Sonatype. He works at a crossroads of technical writing, developer advocacy, and information design. He aims to get developers and non-technical collaborators to work better together in solving problems and building software.