Rapid7 Command: Top Competitors, Alternatives and Reviews

A side-by-side comparison of Rapid7 Command with its main competitors. Easily compare performance across multiple categories and understand what the market is saying with independent reviews.

Rapid7 Command feature-by-feature comparisons

A side-by-side comparison of Rapid7 Command with its main competitors. Easily compare performance across multiple categories and understand what the market is saying with independent reviews.

Rapid7 Command feature-by-feature comparisons
Category UpGuard Rapid7 Command CyCognito Tenable One Cortex Xpanse
General summary
UpGuard manages cyber risk everywhere it lives: your vendors, your internet-facing attack surface, and your workforce. You get one platform that connects all three risk areas instead of separate tools and spreadsheets stitched together. A risk in one surfaces in the others automatically. A breached vendor flags your own exposure. A leaked employee credential links straight to the account and the vendor involved. AI handles the repetitive work of triaging alerts, reviewing vendor evidence, and completing questionnaires. That means lean security teams can run programs that would otherwise need much bigger teams. UpGuard fits mid-market teams, deploys quickly, and slots in without replacing what you already have.
Rapid7 Command is a unified Exposure Management platform that combines internal vulnerability management, cloud security posture, and external visibility by bundling Surface Command (built on its Noetic CAASM acquisition) and Exposure Command. It excels at correlating asset-level exposures, identifying toxic combinations, and mapping internal infrastructure dependencies for Security Operations (SecOps) teams. However, its architectural scope is strictly bounded by what an organization owns or configures; it lacks native third-party risk management (TPRM) lifecycles, fourth-party concentration mapping, and multi-framework compliance evidence engines for external supplier networks.
CyCognito provides automated External Attack Surface Management (EASM) and continuous exposure mapping to uncover internet-facing assets across multi-subsidiary environments. It employs graph-modeling algorithms to automatically trace corporate attribution alongside active security testing to validate exploitable pathways. However, it lacks native depth in internal network scanning, local endpoint posture, and third-party vendor questionnaire workflow management.
Tenable One is an Exposure Management Platform that unifies vulnerability management, web application scanning, cloud security, identity exposure, and external attack surface management (EASM) into a single risk-based framework. It excels at translating raw technical vulnerabilities into a prioritized Business Risk Score using its proprietary Vulnerability Priority Rating (VPR). However, because it relies on aggregating distinct legacy tools, users frequently note inconsistencies across the user interface and fragmented reporting modules.
Cortex Xpanse is an enterprise-grade External Attack Surface Management (EASM) platform that continuously scans the global internet to discover, inventory, and monitor internet-facing corporate assets. It acts as a massive data engine that catalogs over 500 billion network ports daily to flag security blind spots, unmanaged infrastructure, and shadow IT. While its visibility across the public internet IPv4 space is exceptionally comprehensive, it functions essentially as an external perimeter discovery machine; it features significant data-overload challenges, lacks native third-party vendor risk assessment (TPRM) workflows, and requires deep platformization with the broader Palo Alto Networks ecosystem to execute advanced remediation.
Key strengths
UpGuard unifies vendor, attack surface, and workforce risk in one console. Customers describe finally seeing the whole picture, rather than paying for three tools that each cover only part of it. UpGuard also surfaces exposures that ratings tools and scanners miss, without the multi-week delay of a typical scan cycle. Lean teams can run the entire program without expanding headcount or adding a managed service.
Exceptionally deep vulnerability scanning heritage derived from the InsightVM engine; centralized asset normalization across multi-cloud and on-premise infrastructure; intuitive asset correlation capabilities that cleanly connect visible vulnerabilities to defined business logic and groups.
CyCognito excels at graph-driven asset attribution, making it exceptionally strong at discovering unmanaged shadow IT, forgotten development servers, and legacy infrastructure across complex M&A holdings without requiring prior manual input or IP seeding. Additionally, its automated security testing (AST) capabilities go beyond passive port checking by performing active security tests to validate whether a discovered vulnerability is truly exploitable by attackers. These insights feed into its path of least resistance mapping, which visualizes exact attack paths to help security operations teams prioritize remediation based on actual environmental risk rather than static vulnerability scores.
Industry-leading vulnerability discovery backed by Nessus-heritage scanning engines; highly accurate risk prioritization via Vulnerability Priority Rating (VPR); excellent operational visibility across hybrid infrastructures combining on-premises IT, cloud workloads, Active Directory configurations, and operational technology (OT).
Unparalleled global internet-scale scanning capable of mapping complete enterprise perimeters without agents or instrumentation; seamless automated integration pathways into Palo Alto networks infrastructure (including Cortex XSOAR and XSIAM); dynamic machine-learning attribution models that accurately discover unknown cloud storage buckets and rogue corporate child subsidiaries.
Key weaknesses
UpGuard focuses on managing live, connected risk, not heavy, standalone compliance software. Full governance features, including policy and controls management, arrive later this year. Teams that need a mature governance, risk, and compliance (GRC) system of record today can run UpGuard alongside one for now. UpGuard also doesn’t translate risk into dollar figures. If financial risk quantification is a must-have, factor that into your evaluation.
High baseline subscription and maintenance costs that strain smaller IT security budgets; significant noise and false-positive filtering required during initial perimeter discoveries; virtually non-existent capabilities for third-party supply chain or direct vendor risk assessment workflows.
The platform presents high cost barriers due to enterprise-centric pricing mechanics that make it cost-prohibitive for small to mid-sized businesses (SMBs). Furthermore, it delivers no internal telemetry because it focuses completely on the external perimeter, meaning it provides zero native coverage into internal vulnerability management, internal asset posture, or local endpoints. Finally, CyCognito features minimal third-party lifecycles, lacking specialized workflows for third-party questionnaire management, automated supplier risk tiering, or collaborative external compliance tracking.
UI layout remains fragmented across consolidated legacy components; built-in reporting dashboards are structurally rigid and often require raw data exports via API to build complex executive views; secondary platform features, such as standalone Third-Party Risk Management (TPRM), are virtually non-existent.
Highly prohibitive enterprise pricing thresholds that price out mid-market organizations; extensive alert noise and raw data volumes that require dedicated engineering teams to manually triage; complete absence of third-party risk lifecycle management tools, fourth-party concentration registers, or supply chain assessment questionnaires.
Usability and learning curve
Teams deploy quickly and get up and running without an extended onboarding period. New employees can learn the interface without lengthy training. A single console consolidates workflows that would otherwise require multiple tools, reducing the ongoing burden of learning and maintaining separate systems. Operating the platform doesn’t require a professional services engagement.
The platform has a noticeable learning curve for mid-market teams, requiring technical expertise to properly fine-tune network discovery ranges and local agent permissions. While the modernized unified command panel improves day-to-day navigation compared to legacy point modules, setting up robust, custom security reporting logic still demands administrative heavy lifting.
Features an intuitive, modern web dashboard that separates distinct business units or digital scopes into manageable logical blocks. While the initial setup requires minimal effort due to its agentless, outside-in design, users occasionally report performance sluggishness when filtering or searching through highly dense, multi-subsidiary global asset maps.
Onboarding and initial platform configuration carry a steep learning curve. While core vulnerability metrics are intuitive to navigate, moving between separate underlying assets (like Tenable Cloud Security and Identity Exposure) feels fragmented. Manual asset tagging and complex access control logic are required to maintain a consistent posture across business units.
The onboarding lifecycle for large enterprise footprints is rapid due to its outside-in, non-intrusive scanning model. However, long-term usability demands a heavy learning curve. The management interface can feel complex and dense, frequently overwhelming analysts with data overload. Teams must spend substantial initial cycles fine-tuning ownership attribution boundaries to prevent false positives where cloud environments map incorrectly to their profiles.
Cyber risk data accuracy
UpGuard’s data remains current. Vendor postures refresh continuously, and users can initiate a scan on demand instead of waiting for a fixed cycle. UpGuard attributes findings accurately, so teams do not spend weeks correcting assets assigned to the wrong company, a common issue with ratings tools. Threat Monitoring scans the open, deep, and dark web, along with social media, for leaked data, exposed credentials, and brand impersonation. AI filters out noise so the alerts that reach your team are worth acting on.
Data fidelity for internal assets, container environments, and active cloud workloads is remarkably high, driven by deep agent and API telemetry. However, its external attack surface mapping can generate significant noise, requiring technical teams to spend roughly 43% of their time gathering context to manually filter out false positives from dynamic cloud allocations or unassigned IP ranges.
The platform achieves high data accuracy and low false-positive rates through its dual-engine approach, combining continuous mapping with active validation testing. This ensures alerts focus on verifiable paths of exposure, though lean teams may still experience high overall alert volume if filtering profiles are not properly customized.
Data collection is exceptionally reliable, drawing from active network scanning, agent-based local monitoring, and cloud-native API integrations. New vulnerability definitions (plugins) are typically distributed within 24 to 72 hours of public disclosure. False-positive rates remain low due to extensive, mature threat-intelligence correlation.
Perimeter data accuracy is outstanding, drawing on continuous global internet sweeps that index the entire public IPv4 space multiple times a day. It maintains an extraordinarily low latency for detecting structural changes or exposed services, though some findings can still require secondary internal validation when processing dynamically changing cloud allocations shared across multiple corporate tenants.
Vendor risk management features
UpGuard runs the complete third-party risk management (TPRM) process in one platform: onboarding, assessing, remediating, monitoring, and reporting on vendors. Each vendor’s live external exposure and any linked leaked credentials appear directly within the vendor program, so teams can act on verified risk instead of relying on paperwork. AI-powered security questionnaires read vendor evidence and complete assessments automatically, cutting completion time by up to 95%. Instant risk assessments return a point-in-time report in under a minute, mapped to frameworks like ISO 27001 and NIST CSF 2.0.
Rapid7 Command provides zero native capabilities for managing third-party vendor risk. The platform cannot generate or process security questionnaires (such as SIG, ISO, or NIST templates), track fourth-party concentration risk, orchestrate external vendor remediation, or output the board-ready supplier risk registers demanded by modern supply chain regulations.
CyCognito is not engineered as a dedicated Third-Party Risk Management (TPRM) or Vendor Risk Management (VRM) engine. While it can map out the external perimeter of partner organizations or M&A targets via standalone digital scopes, it lacks native features for distributing questionnaires, managing vendor compliance documents, or scoring third-party operational risk.
Tenable One is fundamentally an internal infrastructure exposure platform and does not offer dedicated third-party risk management features. It lacks automated vendor questionnaires, supply-chain monitoring watchlists, or third-party compliance tracking workflows out of the box.
Cortex Xpanse does not possess built-in Third-Party Risk Management (TPRM) or supply chain risk assessment features. It cannot orchestrate external vendor remediation, build external supplier risk registers, or issue compliance questionnaires. While it can map public-facing vulnerabilities on an external IP, it cannot track fourth-party concentration vectors or gauge supply chain software dependencies.
Attack surface management features
UpGuard continuously monitors your internet-facing footprint. It maps assets, flags exposures such as misconfigurations, expired certificates, and open ports, and ranks remediation priorities. The UpGuard platform also detects typosquatting and lookalike domains set up to impersonate your brand before they’re used for phishing. Because attack surface monitoring runs alongside vendor and workforce risk, an exposed asset or leaked credential automatically links to the person and vendor involved. This gives teams visibility into both external exposure and vendor risk in a single view.
Its Cyber Asset Attack Surface Management (CAASM) and external mapping tools are highly capable for tracking down known perimeters and active cloud instances. However, because its architecture builds primarily on what it is told about (CMDBs, EDR hooks, and cloud APIs), it faces structural limitations when exposing completely unseeded shadow IT, corporate divestitures, or unauthorized rogue developer environments.
A best-in-class capability, the tool provides deep, recursive discovery of shadow IT, orphan domains, cloud buckets, and external exposures. Its continuous scanning architecture ensures that changes to the external perimeter, such as developer-deployed cloud resources or recently divested entities, are caught quickly without manual seeding.
External attack surface management (EASM) capabilities are robust, leveraging automated domain attribution and continuous external scans to identify internet-facing assets, rogue subsidiaries, and exposed ports. However, licensing is structurally separate: discovering external assets can incur additional per-asset costs even if they mirror existing internal inventories.
This is the platform's primary design capability. It delivers top-tier external attack surface visibility, continually mapping internet-exposed infrastructure, cloud storage instances, forgotten dev boxes, and corporate M&A inheritance. By monitoring the entire external perimeter from an outside-in stance, it actively exposes systems omitted from internal configuration databases.
Customer support
UpGuard supports every customer across all plan tiers, from the smallest plan to the largest. Support teams assist with both technical setup and larger program decisions. Customers frequently cite responsive, hands-on support as a reason they continue with UpGuard.
Rapid7 generally receives favorable feedback for its technical support. Users frequently note that the technical support staff is knowledgeable and effective at resolving standard issues. However, due to the comprehensive scope of the Command Platform, the initial deployment process can be complex, occasionally resulting in scheduling bottlenecks for available implementation specialists. Additionally, while standard support is included, advanced services like dedicated Customer Success Managers (CSMs) and accelerated SLAs are structured within premium service tiers or specific enterprise contracts.
Standard support models feature responsive technical assistance and dedicated customer success management for larger enterprise tiers. Peer feedback highlights strong technical competence during platform onboarding, though resolving highly nuanced asset attribution discrepancies through the traditional support ticket queue can occasionally take time.
Technical support is structured across tiered SLA frameworks. Premium tiers like Elite Support offer highly responsive round-the-clock telephone and digital troubleshooting with active escalation pathways. Standard business-hours support may have slightly longer response times for complex configuration requests.
Customer support is delivered through Palo Alto Networks' established, highly structured enterprise Customer Success channels. Response timelines and technical tiering are governed by rigid SLAs, with standard support tiers that reliably handle general queries. Enterprise accounts can leverage dedicated technical account managers to guide scoping for complex, multi-subsidiary deployments.
Workflow automation
Risk Automations turns a risk signal into action across the platform, with no code and no engineering ticket. On the vendor side, it automates onboarding from questionnaire data, triages vendor score drops, schedules recurring vendor reports, and opens remediation tickets in ServiceNow or Jira. On the threat side, a Breach Risk detection can trigger a workflow that alerts Teams or Slack and runs a system-level fix, like blocking a malicious IP or forcing a credential reset. This is the difference between a tool that reports on risk and one that resolves it.
Automation capabilities are a standout feature, powered by direct underlying integrations with Rapid7's InsightConnect engine. Security teams can configure granular automation playbooks to automatically route discovery tickets to Jira or ServiceNow, trigger localized rescans, and prompt infrastructure teams when high-risk exposures bypass defined SLA windows.
Provides out-of-the-box integration playbooks that automate ticket generation across major enterprise IT Service Management (ITSM) platforms like Jira and ServiceNow. It exposes granular remediation playbooks that can seamlessly ingest threat events directly into downstream corporate SOAR platforms.
Remediation management features include built-in ticket routing, automated scanning updates, and direct integrations with ITSM tools like ServiceNow and Jira. While internal remediation tracking is automated smoothly, it lacks native security orchestration (SOAR) playbooks for automated network-level blocking.
Workflow automation is exceptionally advanced when utilizing the native Active Response module alongside Cortex XSOAR. Security personnel can launch sophisticated automation playbooks to execute closed-loop remediation, auto-generate tickets in external ITSM tools, and coordinate automated network-blocking defenses, which substantially reduces manual analyst work.
Artificial intelligence features
UpGuard’s AI performs specific, defined tasks, rather than vague “AI-powered” work. The AI Threat Analyst sorts and scores incoming threats across your attack surface, the dark web, and social media. It clears out approximately 60% of alerts as noise, so your team only reviews what matters. The same triage logic extends to vendor and workforce signals as well. Every AI result carries a citation back to the source, so your team can verify it before acting.
Incorporates specialized ML modules and automated analytics layer functions to prioritize vulnerabilities based on real-world threat intelligence rather than static scoring matrices. The platform regularly releases updated generative insights and natural-language query tools, although fully autonomous configuration adjustment playbooks remain in early operational growth.
Leverages mature machine learning algorithms to drive its core asset attribution logic, autonomously identifying organizational relationships, parent-subsidiary connections, and brand ownership structures. It uses automated execution heuristics to plan and prioritize active testing vectors against exposed hosts.
Exposure analysis is enhanced by Tenable's AI assistant, "Hexa". These features reliably generate context-aware prioritization lists and step-by-step remediation guidance, though interactive predictive simulation models are still maturing.
Uses robust, embedded machine learning engines to handle automated domain and asset attribution across billions of public data points without manual tagging. The platform successfully utilizes advanced algorithmic patterning to classify external exposures and simulate common ransomware paths, though predictive security profiling elements are still maturing.
API and integrations
A well-documented REST API and webhooks let teams pull risk data into their own tools and trigger actions programmatically, without waiting on engineering support. For no-code work, Risk Automations adds more than 100 native integrations, including Jira, ServiceNow, Microsoft Entra, Slack, and Cloudflare. A Universal API Connector Node extends its reach to any open API.
Provides an open, highly capable REST and GraphQL API ecosystem that allows technical teams to cleanly export normalization data into local data lakes or corporate SIEMs. Native connectors integrate with major infrastructure platforms (AWS, Azure, GCP) and leading pipeline tools, though maintaining custom API integrations during major platform updates can add maintenance overhead.
Offers robust, well-documented REST APIs that provide comprehensive access to discovered asset inventories, exposure details, and remediation statuses. Mainstream integrations focus primarily on SIEM, SOAR, cloud service providers, and ticket-tracking systems rather than on broader risk-ecosystem marketplaces.
Offers highly robust, unrestrained REST APIs that allow engineering teams to perform frequent automated queries without strict rate-limiting barriers. Platform connections extend seamlessly to major public cloud providers (AWS, Azure, GCP), CI/CD developer pipelines, and leading SIEM configurations.
Integrations are incredibly deep for organizations running Palo Alto hardware or software overlays (including Prisma Cloud, Cortex XDR, XSOAR, and XSIAM). For external third-party tools, it provides highly capable enterprise REST APIs, though it lacks a broad selection of native out-of-the-box SIEM connectors, which often forces development teams to build custom syslog ingestion engines.
Purchasing & licensing transparency
UpGuard publishes its pricing rather than hiding it behind a sales call. A free tier lets teams monitor up to five vendors and use Trust Exchange, UpGuard’s AI-powered questionnaire tool, at no cost. Paid Vendor Risk plans start at USD 1,750 per month, billed annually. Teams can start with one product and add others as they scale. One license covers both monitoring and assessments, so pricing doesn’t fragment across separate products.
Pricing is not transparent or transactional; it scales directly through custom enterprise consultations based on total monitored asset quotas. Because licensing calculations consider combinations of active IP ranges, external domains, and unique cloud resources, tracking and projecting annual security spend can become confusing as corporate assets auto-scale.
Employs a strict enterprise-grade, opaque pricing structure with no publicly listed price sheets, automated self-service tier enrolments, or open-access free trials. All potential deployments must route directly through a consultative enterprise sales cycle to construct a custom asset-band quote.
Pricing information is entirely opaque, requiring interactive, direct enterprise quotes from a representative or authorized channel partner. Licensing maps strictly to a progressive per-asset structure (IPs, cloud workloads, containers), creating complex billing tracking as operational environments scale dynamically.
Purchasing transparency is low. Pricing is entirely confidential and transactional, structured around complex enterprise asset-under-management (AUM) tiers and specific platform module licenses. Costs are targeted at large enterprise budgets, and tracking license utilization can become complicated as multi-cloud networks scale.
Customers
UpGuard customers include Intercontinental Exchange (NYSE: ICE), Morningstar, TDK, PagerDuty, Hopin, and IAG. Read UpGuard’s customer stories to learn more.
Broadly deployed across mid-market enterprises and extensive Fortune 1000 organizations that operate highly complex hybrid-cloud networks, active software pipelines, and distributed remote workforces.
Successfully adopted by Fortune 500 enterprises, large-scale telecommunications providers, global manufacturing conglomerates, and complex multi-national financial institutions requiring comprehensive mapping across highly fragmented global digital perimeters.
Extensively deployed across Fortune 500 enterprises, massive government agencies, global financial institutions, and tier-one healthcare infrastructure networks that manage expansive, hybrid attack surfaces.
Cortex Xpanse is deployed across a premium tier of highly demanding global organizations. Notable customers include the U.S. Department of Defense, all six branches of the U.S. armed forces, Accenture, AT&T, American Express, AIG, and Pfizer.
G2 rating Accurate as of March 2025
More than 700 verified reviews give UpGuard a 4.5 out of 5 rating on G2. UpGuard also holds G2’s top ranking as the leader in Third-Party & Supplier Risk Management for 15 consecutive quarters. The 2026 G2 Best Software Awards recognized UpGuard as one of the Top 100 Global Software Companies. Among verified reviewers, 98% give UpGuard four- or five-star ratings, and 94% approve of its product direction.
4.3, based on 258 reviews.
4.3, based on 5 reviews.
4.5, based on 566 reviews.
Currently not rated.
Security ratings

Competitor Comparison Guide

A transparent comparison of top solutions

Download comparison PDF

Rapid7 Command pricing overview

Rapid7 Command utilizes an asset-indexed enterprise subscription billing architecture where cost metrics tie directly to the scale of an organization’s active operational environment. Licenses are allocated based on total resource counts, factoring in factors such as discovered internal IP addresses, active cloud workloads, and public-facing external domains. Pricing details are strictly confidential and require direct sales engagement, with mid-market enterprise agreements typically starting at around USD 30,000 annually and increasing significantly based on asset scale and modular ecosystem add-ons.

Here’s an overview of Rapid7 Command’s plans and services:

Free plan

Rapid7 Command does not provide a permanent free operational plan for its enterprise exposure platform, though the company actively maintains and distributes the open-source community edition of the Metasploit Framework for standalone local penetration testing.

Free trial

Evaluations of the platform are provided on a request-only basis through the Rapid7 account team, giving prospective corporate accounts a time-limited enterprise proof-of-concept deployment window to discover hidden assets and evaluate local infrastructure risk.

Surface Command

This package focuses primarily on asset inventory correlation and external attack surface visibility. It ingests existing configuration endpoints, cloud APIs, and CMDB logs to establish a normalized baseline of an enterprise’s known digital perimeter and internal asset footprint.

Exposure Command

Rapid7’s advanced exposure management tier that blends the discovery engine of Surface Command with deep vulnerability analysis and attack path mapping. It is designed to identify complex, multi-stage exposure combinations and simulate active threat trajectories across hybrid infrastructures.

Add-ons and additional costs

  • Vector Command: Adds automated, ongoing red-teaming validation and attack simulation playbooks to actively stress-test internal configuration boundaries.
  • Threat Command: A distinct digital risk protection module licensed separately or bundled into premium retainers to monitor credential leaks, phishing infrastructure, and targeted external threat indicators.
  • Managed Threat Complete (MTC) Overlay: A premium managed service overlay that wraps the Command platform telemetry in a 24/7 human-led Managed Detection and Response (MDR), incident response, and forensic service.

How does Rapid7 Command’s pricing compare to its competitors?

UpGuard

UpGuard’s pricing starts at USD 1,750 per month. The platform maximizes value by offering out-of-the-box workflows supporting the entire TPRM lifecycle—saving users from having to purchase additional tools to fill TPRM workflow gaps.

It offers a free plan that lets you monitor up to five vendors, with access to assessment and remediation workflows. UpGuard’s Trust Exchange tool, which streamlines vendor questionnaires and trust management, is also free.

A 14-day free trial of paid tiers is available.

For a detailed breakdown of UpGuard’s pricing packages, visit UpGuard’s pricing page.

CyCognito

CyCognito utilizes an entirely external, non-intrusive scanning pricing matrix structured strictly around the overall complexity of a company’s external attack surface rather than traditional agent-based internal node licensing. Because it operates strictly from an outside-in cloud model, it eliminates the need to calculate individual local endpoints or agent licenses. Its multi-tiered enterprise licensing remains completely confidential and requires a tailored corporate evaluation.

Learn more about CyCognito’s pricing.

Tenable One

Tenable One employs a unified asset token billing architecture in which all monitored targets, including web applications, internal cloud nodes, Active Directory identities, and standard network devices, are counted against a single asset credit pool. While similar in cost to Rapid7 Command, Tenable One’s custom annual quotes vary based on how organizations distribute their asset tokens across internal or cloud security tools.

Learn more about Tenable One’s pricing.

Cortex Xpanse

Cortex Xpanse by Palo Alto Networks leverages an expansive global index subscription model focused on mapping the full corporate perimeter and discovering external internet assets. Rather than measuring the volume of internal systems or software clients, it bases pricing packages on the total volume of public-facing routing setups, active domains, and cloud edges. Licensing targets major enterprise operations and is available exclusively through custom sales channels.

Learn more about Cortex Xpanse’s pricing.

Rapid7 Command reviews

Reviews of the Rapid7 Command platform and its top competitors, based on independent third-party sources and customer insights.

Rapid7 Command reviews
Category UpGuard Rapid7 Command CyCognito Tenable One Cortex Xpanse
Gartner Peer Insights Overall ratings for the IT VRM Solutions market. Accurate as of January 2024
4.4, based on 160 reviews. Named a Representative Vendor in the 2022 Gartner Market Guide for IT VRM Solutions
4.3, based on 753 reviews.
4.7, based on 39 reviews.
4.6, based on 131 reviews.
4.5, based on 77 reviews.
G2 rating Accurate as of March 2025
More than 700 verified reviews give UpGuard a 4.5 out of 5 rating on G2. UpGuard also holds G2’s top ranking as the leader in Third-Party & Supplier Risk Management for 15 consecutive quarters. The 2026 G2 Best Software Awards recognized UpGuard as one of the Top 100 Global Software Companies. Among verified reviewers, 98% give UpGuard four- or five-star ratings, and 94% approve of its product direction.
4.3, based on 258 reviews.
4.3, based on 5 reviews.
4.5, based on 566 reviews.
Currently not rated.
Glassdoor Accurate as of March 2025
4.4, based on 95 reviews.
3.6, based on 1120 reviews.
Currently not rated.
3.8, based on 624 reviews.
Currently not rated.

A transparent comparison of top solutions

Download comparison PDF

Experience superior visibility and a simpler approach to cyber risk management