Wednesday, October 7, 2026

DigitalXForce recognized as leader in IDC MarketScape for TPRM

By

Published

5 min read

D

DigitalXForce named a Leader in the 2026 IDC MarketScape for TPRM, after its 2025 Leader recognition in GRC software.

DigitalXForce brings third-party risk management, GRC and Continuous Control Monitoring onto one AI-native platform, using continuous evidence instead of annual snapshots.”— Lalit Ahluwalia, Founder and CEO, DigitalXForceIRVING, TX, UNITED STATES, October 5, 2026 /EINPresswire.com/ — DigitalXForce, the AI-native Enterprise Trust, Risk, Security and Compliance Management (TRiSCM™) platform, today announced that it has been named a Leader in the IDC MarketScape: Worldwide Third-Party Risk Management Software 2026 Vendor Assessment (Doc #US53007725, September 2026).

The IDC MarketScape assessed third-party risk management software providers by examining their present capabilities and long-term strategies. DigitalXForce secured a spot in the Leaders category.

DigitalXForce was also recognized as a Leader in the IDC MarketScape: Worldwide Governance, Risk, and Compliance Software Vendor Assessment, 2025 (Doc #US53615325, June 2025).

Third-party risk built on evidence

Numerous third-party risk programs continue to rely on the same annual questionnaire process. A vendor gets onboarded, a questionnaire goes out, responses get evaluated, a risk tier is assigned, and the file often stays untouched until the next scheduled review. The issue is that a supplier’s security posture can shift well before the next questionnaire comes due. DORA, NIS2 and the OCC’s third-party guidance have all placed greater emphasis on continuous oversight rather than depending solely on periodic attestations.

DigitalXForce’s Automated Third-Party Risk Management with External Risk View module is designed to inject continuous evidence into that process. It ranks vendors based on business impact, compliance exposure and data access, enabling teams to prioritize the relationships that carry the highest risk. During onboarding and review, AI-powered document analysis reads and summarizes vendor submissions. External Risk View then monitors vendors from the outside for exposed services, misconfigurations, vulnerability exposure, breach intelligence, cyber ratings and fourth-party dependencies.

Between formal reviews, the vendor risk score can shift as new external evidence surfaces, rather than staying fixed to a point-in-time self-attestation. Material changes can thus emerge as they occur. Findings can be turned into remediation plans and tracked with the vendor against agreed SLAs until closure. Because the module operates on the same platform as DigitalXForce’s automated GRC and Continuous Control Monitoring (CCM), third-party evidence can be mapped to the same frameworks the enterprise already uses for risk and compliance reporting, connecting the external view of a supplier with the internal view of the organization’s own controls.

"A vendor questionnaire gives an answer with a shelf life of 1 day, and most third-party risk programs act on that answer for a year," said Lalit Ahluwalia, Founder and CEO of DigitalXForce. "We built the External Risk View so that a risk team learns about a supplier’s change from evidence, not from the next year’s questionnaire. We believe being named a Leader by the IDC MarketScape in third-party risk management, one year after being named a Leader in GRC, tells us the market is moving toward the model we built the platform on."

"Third-party risk management is moving from periodic questionnaires to continuous evidence, and the vendors pulling ahead are the ones that built AI into their operating model rather than adding it to old workflows," said Philip D. Harris, Research Director, Governance, Risk, and Compliance Solutions, IDC. "DigitalXForce runs third-party risk on the same evidence and the same platform as its GRC and posture monitoring, which is the unified approach enterprise buyers are consolidating toward."

One platform for trust, risk, security and compliance

DigitalXForce uses the TRiSCM category to describe a platform that brings automated GRC, security posture management and Continuous Control Monitoring into one real-time system. Controls are mapped once to 50+ compliance frameworks across 250+ technology integrations, allowing the same evidence to be reused across multiple risk, security and compliance requirements. Two proprietary AI engines, AI JedAI and XForce GPT, support automation across the platform, including control testing, risk quantification, policy generation and orchestrated remediation.

The 2026 IDC MarketScape for Third-Party Risk Management is available from IDC at https://my.idc.com/getdoc.jsp?containerId=US53007725. DigitalXForce maintains an IDC research library at https://digitalxforce.com/idc-research/, where every IDC document that names the company is listed. Additional information about the Automated Third-Party Risk Management with External Risk View module is available at https://digitalxforce.com/products/automated-third-party-risk-management-with-external-risk-view/.

About IDC MarketScape

IDC MarketScape vendor assessment model is designed to provide an overview of the competitive fitness of technology and service suppliers in a given market. The research utilizes a rigorous scoring methodology based on both qualitative and quantitative criteria that results in a single graphical illustration of each supplier’s position within a given market.

IDC MarketScape provides a clear framework in which product and service offerings, capabilities and strategies, and current and future market success factors of technology suppliers can be meaningfully compared. The framework also provides technology buyers with a 360-degree assessment of the strengths and weaknesses of current and prospective suppliers.

About DigitalXForce

DigitalXForce is the AI-native Enterprise Trust, Risk, Security and Compliance Management (TRiSCM™) platform. It brings automated GRC, security posture management, continuous control monitoring, third-party risk management and AI risk governance into one real-time system, giving risk, compliance and security teams a shared live data layer instead of separate periodic assessments and questionnaires.

Controls are mapped once to 50+ compliance frameworks across 250+ technology integrations, and the same evidence can be reused across them. The platform is delivered as 15 modules on a single data layer and is powered by two proprietary AI engines, AI JedAI and XForce GPT. Its cybersecurity mesh architecture allows each module to work from the same control library, evidence store and data layer.

DigitalXForce was founded in 2023 and is headquartered at 230 W John Carpenter Fwy, Suite 100, Irving, TX 75039, USA. It has been named a Leader in the IDC MarketScape: Worldwide Governance, Risk, and Compliance Software Vendor Assessment, 2025, and a Leader in the IDC MarketScape: Worldwide Third-Party Risk Management Software 2026 Vendor Assessment. TRiSCM is a trademark of DigitalXForce, filed with the United States Patent and Trademark Office. Learn more at https://digitalxforce.com/.

Lalit Ahluwalia
DigitalXForce Corporation
+ +1972-342-0073
email us here
Visit us on social media:
LinkedIn


David Hall

David Hall

David is the senior editor at FintechNewsWatch. He has a background in journalism and has worked with various media outlets, covering topics ranging from digital banking and blockchain technology to startup funding and regulatory developments. When he is not writing, David enjoys reading, hiking, photography, and exploring new coffee shops.