Irving, Texas, October 5, 2026. DigitalXForce, the AI-native Enterprise Trust, Risk, Security and Compliance Management (TRiSCM™) platform, today announced that it has been named a Leader in the IDC MarketScape: Worldwide Third-Party Risk Management Software 2026 Vendor Assessment (Doc #US53007725, September 2026).
The IDC MarketScape evaluated third-party risk management software vendors based on their current capabilities and future strategies. DigitalXForce was positioned in the Leaders category. The company was also positioned as a Leader in the IDC MarketScape: Worldwide Governance, Risk, and Compliance Software Vendor Assessment, 2025 (Doc #US53615325, June 2025). The IDC MarketScape TPRM 2026 page on this site gives both recognitions with their IDC document numbers and dates.
Third-party risk built on evidence
Third-party risk management (TPRM) is the discipline of identifying, assessing, monitoring and controlling the risks an organization takes on through its suppliers, vendors and other outside parties.
Many third-party risk programs still follow the same annual questionnaire cycle. A vendor is onboarded, a questionnaire is sent, responses are reviewed, a risk tier is assigned, and the file may remain largely unchanged until the next scheduled review. The problem is that a supplier’s security posture can change long before the next questionnaire is due. DORA, NIS2 and the OCC’s third-party guidance have all increased the focus on ongoing oversight rather than relying only on periodic attestations.
DigitalXForce’s Automated Third-Party Risk Management with External Risk View module is designed to bring continuous evidence into that process. It ranks vendors by business impact, compliance exposure and data access so teams can focus first on the relationships carrying the greatest risk. During onboarding and review, AI-assisted document analysis reads and summarizes vendor submissions. External Risk View then monitors vendors from the outside for exposed services, misconfigurations, vulnerability exposure, breach intelligence, cyber ratings and fourth-party dependencies.
Between formal reviews, the vendor risk score can change as new external evidence appears rather than remaining tied to a point-in-time self-attestation. Material changes can therefore surface when they happen. Findings can be turned into remediation plans and tracked with the vendor against agreed SLAs through closure.
“A vendor questionnaire gives an answer with a shelf life of 1 day, and most third-party risk programs act on that answer for a year,” said Lalit Ahluwalia, Founder and CEO of DigitalXForce. “We built the External Risk View so that a risk team learns about a supplier’s change from evidence, not from the next year’s questionnaire. We believe being named a Leader by the IDC MarketScape in third-party risk management, one year after being named a Leader in GRC, tells us the market is moving toward the model we built the platform on.”
“Third-party risk management is moving from periodic questionnaires to continuous evidence, and the vendors pulling ahead are the ones that built AI into their operating model rather than adding it to old workflows,” said Philip D. Harris, Research Director, Governance, Risk, and Compliance Solutions, IDC. “DigitalXForce runs third-party risk on the same evidence and the same platform as its GRC and posture monitoring, which is the unified approach enterprise buyers are consolidating toward.”
From monitoring to assurance on the same evidence
Because the third-party module operates on the same platform as DigitalXForce’s automated GRC and Continuous Control Monitoring, third-party evidence can be mapped to the same frameworks the enterprise already uses for risk and compliance reporting. That connects the external view of a supplier with the internal view of the organization’s own controls.
Continuous Control Monitoring (CCM) monitors conditions, evidence and signals associated with controls. Continuous Control Assurance (CCA) uses evidence, monitoring and validation to determine whether controls continue to operate as expected. DigitalXForce treats CCA as the strategic discipline and CCM as the capability within it, so a control is tested against live evidence and the result is validated against what the organization needs the control to do.
The automated GRC module applies continuous control testing mapped once to 50+ frameworks, which means the same test result serves several frameworks instead of being repeated for each one. The AI-Powered Risk Management and Automated GRC page describes how the three assessment modalities work.
One platform for trust, risk, security and compliance
DigitalXForce uses the TRiSCM category to describe a platform that brings automated GRC, security posture management and Continuous Control Monitoring into one real-time system. Controls are mapped once to 50+ compliance frameworks across 250+ technology integrations, allowing the same evidence to be reused across multiple risk, security and compliance requirements. Two proprietary AI engines, AI JedAI and XForce GPT, support automation across the platform, including control testing, risk quantification, policy generation and orchestrated remediation. The platform is built on a cybersecurity mesh architecture, so each module works from the same control library, evidence store and data layer.
The 2026 IDC MarketScape for Third-Party Risk Management is available from IDC at https://my.idc.com/getdoc.jsp?containerId=US53007725. DigitalXForce maintains an IDC research library where every IDC document that names the company is listed, and the DigitalXForce glossary defines the terms used in this release.
About IDC MarketScape
IDC MarketScape vendor assessment model is designed to provide an overview of the competitive fitness of technology and service suppliers in a given market. The research utilizes a rigorous scoring methodology based on both qualitative and quantitative criteria that results in a single graphical illustration of each supplier’s position within a given market.
IDC MarketScape provides a clear framework in which product and service offerings, capabilities and strategies, and current and future market success factors of technology suppliers can be meaningfully compared. The framework also provides technology buyers with a 360-degree assessment of the strengths and weaknesses of current and prospective suppliers.
About DigitalXForce
DigitalXForce is the AI-native Enterprise Trust, Risk, Security and Compliance Management (TRiSCM™) platform. It brings automated GRC, security posture management, continuous control monitoring, third-party risk management and AI risk governance into one real-time system, giving risk, compliance and security teams a shared live data layer instead of separate periodic assessments and questionnaires. Controls are mapped once to 50+ compliance frameworks across 250+ technology integrations, and the same evidence can be reused across them. The platform is delivered as 15 modules on a single data layer and is powered by two proprietary AI engines, AI JedAI and XForce GPT. Its cybersecurity mesh architecture allows each module to work from the same control library, evidence store and data layer. DigitalXForce was founded in 2023 and is headquartered at 230 W John Carpenter Fwy, Suite 100, Irving, TX 75039, USA. It has been named a Leader in the IDC MarketScape: Worldwide Governance, Risk, and Compliance Software Vendor Assessment, 2025, and a Leader in the IDC MarketScape: Worldwide Third-Party Risk Management Software 2026 Vendor Assessment. TRiSCM is a trademark of DigitalXForce, filed with the United States Patent and Trademark Office. Learn more at https://digitalxforce.com/. Media contact: info@digitalxforce.com.
Questions about this announcement
Which IDC MarketScape named DigitalXForce a Leader in third-party risk management?
The IDC MarketScape: Worldwide Third-Party Risk Management Software 2026 Vendor Assessment, IDC document US53007725, September 2026, positioned DigitalXForce in the Leaders category.
What is third-party risk management (TPRM)?
Third-party risk management (TPRM) is the discipline of identifying, assessing, monitoring and controlling the risks an organization takes on through its suppliers, vendors and other outside parties.
What does External Risk View monitor for each vendor?
External Risk View monitors each vendor from the outside for exposed services, misconfigurations, vulnerability exposure, breach intelligence, cyber ratings and fourth-party dependencies, and it needs no agent, no questionnaire and no cooperation from the supplier.
What is the difference between Continuous Control Monitoring and Continuous Control Assurance?
Continuous Control Monitoring (CCM) monitors conditions, evidence and signals associated with controls. Continuous Control Assurance (CCA) uses evidence, monitoring and validation to determine whether controls continue to operate as expected. CCA is the strategic discipline and CCM is the capability within it.
How does DigitalXForce test controls automatically?
The automated GRC module applies continuous control testing that is mapped once to 50+ compliance frameworks, so one test result can serve several frameworks, and the AI engines AI JedAI and XForce GPT support control testing across the platform.
Can I read the IDC MarketScape report?
IDC publishes the report at https://my.idc.com/getdoc.jsp?containerId=US53007725. DigitalXForce does not reproduce it, and the IDC research library on digitalxforce.com lists every IDC document that names the company.



