Kenna Security Is Reaching End of Life
Upgrade to an Agentic AI Platform for Unified Exposure Management
Cisco has announced the end of life for Kenna Security.
Preserve the independent governance model you trust while modernizing your security program with agentic AI.
ArmorCode extends Kenna’s scanner-agnostic approach with a Unified Exposure Management (UEM) platform that unifies, prioritizes, and remediates risk across infrastructure, the software supply chain, apps, and AI systems.
Limited-time 3-for-2 offer for Kenna customers
Eligible Kenna customers can receive 3 years of ArmorCode for the price of 2. Under this limited-time offer, customers commit to a three-year agreement and pay for only two years, with the third year provided at no additional cost.
The program also includes guided migration, training, complimentary onboarding services, and a risk-free switch guarantee.
Kenna’s End-of-Life timeline is well underway
March 10, 2026
End-of-Sale: new subscriptions are no longer available.
June 11, 2026
End of Renewal: existing contracts can no longer be renewed or extended.
June 30, 2028
All subscription entitlements, service, and technical support will completely shut down, making the product obsolete.
Cisco has confirmed that it has stopped developing new features, connector updates, and algorithm improvements. No future support will be added for major framework updates such as CVSS 4.0 or EPSS v4.
Vendor Lock-in Risk
Why scanner vendors aren’t always the best
Kenna Security alternative
In the wake of Cisco’s announcement, vendors for security scanning tools are now pitching themselves as Kenna Security alternatives. However, moving from an independent governance layer to a scanner vendor’s platform reintroduces the prioritization bias and vendor lock-in Kenna customers originally chose to avoid.
If you chose Kenna to prioritize risk independently of any single security tool, ArmorCode preserves the same scanner-agnostic architecture:
Scanner Vendors
Built-in bias, growing lock-in
Detection first, governance second. Scanners are their core product with risk prioritization tacked onto that foundation
Risk scoring is calibrated around their own scanner’s output
Increased dependency on a specific vendor
The architecture shifts away from the independent governance model that Kenna championed
The ArmorCode Upgrade
Independent governance, zero lock-in
An unbiased system of action that sits above your existing security tools, making your scanners work better together
Risk prioritization based on EPSS, CISA KEV, exploitability, business context, and asset criticality
Preserve your existing security investments with no vendor lock-in
Replace or add best-of-breed security tools at any time
ArmorCode vs Cisco Vulnerability Management (Kenna): Feature Comparison
| Feature/Category | ArmorCode | Kenna Security (Cisco VM) |
| Scanner Independent Platform | ✔️ Unifies, normalizes, and prioritizes data from security tools as an independent governance layer. | ✔️ Scannerless platform that ingested data from third-party tools. |
| Vendor Agnostic | ✔️ Every tool’s findings enter on equal footing. You can add, swap, or remove any scanner without disrupting your risk program. | ✔️ Ingested data from scanners across infrastructure, endpoints, and applications without favoring any vendor. |
| Scope | Unified Exposure Management across AppSec, infrastructure vulnerability management, software supply chain security, and AI exposure management. | Focused primarily on infrastructure vulnerability management (RBVM) |
| Platform Data Model | ArmorCode’s Context Risk Graph is a unified model of software risk that correlates security findings, assets, code repositories, cloud resources, identities, network topology, business context, and ownership. | A flat asset-vulnerability model organized through Risk Meters – a filtered group of assets and their associated vulnerabilities, each assigned an aggregate risk score. |
| Integrations | 400+ Integrations across infrastructure scanners, AppSec tools, cloud security platforms, container/IaC scanners, ticketing and pentest management. | 40+ Cisco will support current connectors but will not build any new connectors or data schema changes. The integration library is frozen. |
| Risk Prioritization | ✔️ Adaptive Risk Scoring combining CVSS, EPSS, CISA KEV, exploit availability, asset criticality, and business context. | ✔️ Proprietary risk score but opaque and static. No CVSS 4.0 or EPSS v4 support. |
| ASPM | ✔️ Native core solution. Named a Leader in the IDC MarketScape: Worldwide ASPM 2025 Vendor Assessment. | ⚠️ Bolt-on module with no code-to-cloud correlation or developer workflow depth. It was a secondary module layered onto an infrastructure product. |
| Dashboards and Reporting | ✔️ Customizable and role-specific dashboards for CISOs, AppSec leaders, and developers. | ⚠️ Provided risk dashboards and summary views for security teams. Reporting was functional but limited in customization. |
| Software Supply Chain Security | ✔️ Software Supply Chain Security (SSCS) is a native solution within the platform, covering SBOM generation, CI/CD posture management, and support for the EU Cyber Resilience Act. | ❌ |
| Threat Intelligence Feed | ✔️ ArmorCode has AATI (ArmorCode Advanced Threat Intelligence), a proprietary feed that enriches every finding with real-world exploit activity, threat actor data, and active exploitation signals. ArmorCode also supports integration with public and third-party threat intelligence sources. | ⚠️ Kenna combined intelligence from 15+ threat and exploit intelligence sources with proprietary data science and exploit prediction models to prioritize risk. |
| Exception Management | ✔️ Formal approval workflows, centralized Risk Register, compliance-ready audit trails, and risk-scored exception records. | ⚠️ Risk acceptance existed as a vulnerability status flag.Exception management was a DIY workflow built on custom fields, manual processes, and external tools |
| SLA Tracking | ✔️ Track SLA compliance across findings, automate remediation workflows, and monitor overdue risks through centralized governance and reporting. | ⚠️ Functional for monitoring, but enforcement and escalation required manual effort outside the platform. |
| Workflow Automation | ✔️ Runbooks automate ticket creation, ownership assignment, bidirectional ticketing integrations, finding status updates and release gate failure notifications via Slack and email. | ⚠️ Basic automation limited to pushing prioritized findings toward ticketing tools. Operationalizing remediation was explicitly outside the platform’s scope. |
| Agentic AI Framework | ✔️ ArmorCode’s Agentic Control Plane unifies security data from 400+ tools into a single Context Risk Graph, giving AI agents the complete organizational context needed to analyze, prioritize, and remediate risk autonomously. | ❌ |
| AI Exposure Management | ✔️ Dedicated AIEM solution providing visibility and governance over AI tools, models, agents, APIs, MCP servers, and shadow AI | ❌ |
See how easy it is to migrate from Kenna
Experience what migrating from Kenna to ArmorCode looks like. Explore the platform through an interactive tour and see how quickly you can connect your existing tools, unify findings, prioritize risk, and streamline remediation.
Proven outcomes with ArmorCode
Reduction in critical security technical debt
Reduction in MTTR with AI-powered remediation guidance
Reduction in open vulnerabilities
240→7 days
Reduced remediation time with automated workflows and risk-based prioritization
“Strong exposure management platform with effective risk prioritization and broad integrations. ArmorCode provides effective centralized exposure data, improves prioritization through contextual risk scoring, and helps operationalize remediation across teams. It scales well in complex environments and supports a mature, risk-based exposure management program, with continued opportunities to enhance reporting flexibility and remediation guidance. Overall, our experience with ArmorCode has been great.”
“[ArmorCode] is effective in unifying security findings and using AI to prioritize critical vulnerabilities. It seamlessly integrates with existing workflows and offers proactive remediation of issues. Aggregating security findings from multiple tools in an enterprise is a challenge. ArmorCode has helped us overcome this challenge to a large extent.”
“ArmorCode is an excellent Exposure Assessment Platform! [ArmorCode] has completely transformed our security operations. By unifying dozens of disconnected scanning tools into a single, vendor-agnostic control plane, the platform has provided us with visibility across our entire software and infrastructure ecosystem.”
“Without ArmorCode, we would not be able to do what we are doing today. The impact is huge. We have reduced our critical security tech debt by 80%. We are able to automate the creation of grouped tickets in Jira, and we are seeing teams fixing issues because they have that visibility. They see those tickets on their boards, plan remediation, and work on them to resolve the issues and close those tickets.”
Resources to support your transition
Frequently Asked Questions
Q: What is happening to Kenna Security?
A: Cisco is officially sunsetting the entire Kenna Security platform, officially known as Cisco Vulnerability Management. Cisco has outlined the End of Sale and End of Life for Cisco Vulnerability Management, Vulnerability Intelligence, and AppSec. Hence, customers that use Kenna are required to come up with a migration plan and make an assessment of available choices.
Q: Why should I migrate before Kenna reaches the End of Support?
A: Cisco has stated that the End of Renewal date is June 11, 2026, and the Last Date of Support (LDOS) is June 30, 2028. According to Cisco, there will not be any development of new features, connectors, and algorithms updates anymore. Also, they won’t support major framework updates like CVSS 4.0 or EPSS v4. Therefore, migrating at the last minute could place unnecessary pressure on security teams. Migrating ahead of time allows organizations to evaluate the available solutions in the market and develop migration plans.
Q: Which Kenna Security alternative is best?
A: At present, the best alternative to Kenna Security would be ArmorCode.
Organizations started using Kenna Security because it provided a vendor-neutral, risk-based approach to vulnerability management without requiring them to replace their existing security tools. Similar to Kenna Security, ArmorCode also offers these features.
What differentiates ArmorCode is that it extends beyond traditional risk-based vulnerability management into broader exposure management. It helps organizations address application security posture management (ASPM), software supply chain security, and AI Exposure Management from a single platform.
ArmorCode provides an Agentic AI Control Plane for Unified Exposure Management (UEM), helping security teams identify, prioritize, and remediate risks across applications, cloud environments, code, infrastructure, and AI systems.
Q: How do I choose among Kenna Security alternatives?
A: When evaluating alternatives to the Kenna Security platform, make sure to look for the following capabilities. Consider whether the platform can:
- Integrations with your existing security tools
- Remain scanner-agnostic and vendor-independent
- Normalize and correlate findings from multiple sources
- Prioritize risk using business context
- Automate remediation processes
- Evolve beyond vulnerability management into exposure management that covers applications, infrastructure, code, cloud environments, and AI
- Scale with your security program
- Preserve existing security investments
Q: Does ArmorCode support application security and risk-based vulnerability management use cases?
A: Yes, ArmorCode fully supports both Application Security Posture Management (ASPM) and Risk-Based Vulnerability Management (RBVM) use cases.
Application Security Posture Management (ASPM): ArmorCode acts as an independent governance layer that consolidates findings from any application security scanner, provides a unified view from cloud to code, prioritizes risks based on business context, and accelerates triage to match development velocity.
Risk-Based Vulnerability Management (RBVM): ArmorCode unifies and prioritizes vulnerabilities across physical infrastructure, cloud environments, containers, and applications. Vendor-agnostic and scannerless by design, ArmorCode automates workflows, identifies asset owners, eliminates cross-team friction, and drives systematic risk reduction at enterprise scale.
Q: How long does a Kenna migration typically take?
A: It largely depends on the size of your environment, the number of integrations involved, and your migration goals.
However, we’ve seen that most organizations start realizing value from the platform within a few weeks. Teams can quickly connect their existing security tools, unify data, and start generating actionable insights early in the migration process.
Since ArmorCode integrates with your existing security ecosystem, you don’t need to replace scanners or rebuild your entire program before getting started. Many customers begin gaining visibility and prioritization insights shortly after onboarding, while continuing to mature and expand their implementation over time.
Q: Can I keep my existing vulnerability scanners and security tools?
A: Yes, you can absolutely keep your existing scanners and security tools. ArmorCode is intentionally designed to be a vendor-agnostic platform that acts as an independent governance layer, allowing you to avoid scanner bias and leverage the best-of-breed tools you already have in your security stack.
ArmorCode connects with 400+ tools across AppSec, cloud, infrastructure, container and API security, threat intelligence, CMDBs, ticketing systems, and beyond.
In fact, our customers continue using their preferred scanners, testing tools, and security platforms. ArmorCode helps unify data from those tools to centralize visibility, prioritize risk, and coordinate remediation efforts.
Q: Is There Any Offer for Kenna Customers Migrating to ArmorCode?
A: Yes. Eligible Kenna customers can receive 3 years of ArmorCode for the price of 2. The program includes guided migration, training, complimentary onboarding services, and a risk-free switch guarantee. Contact us to determine your eligibility.