AI is transforming software development, and with it, the software supply chain. What once centered primarily on source code and open-source dependencies now extends across developer tools, identities, pipelines, code artifacts and the systems that ultimately run software in production. Coding assistants, AI models, MCP servers, skills and agents are adding even more components to that ecosystem.
As the software supply chain expands, so does the opportunity for attackers. Securing it requires more than scanning code or dependencies in isolation. Organizations need visibility across everything that enters or modifies the development lifecycle, controls that prevent risk before software reaches production and the context to respond quickly when new threats emerge.
That shift is reflected in the 2026 KuppingerCole Leadership Compass for Software Supply Chain Security, which named Palo Alto Networks Cortex Cloud™ an Overall Leader.
What KuppingerCole Says About Cortex Cloud
KuppingerCole’s report reflects an important change in how organizations are approaching software supply chain security. Point products can identify individual issues, but they often leave security teams piecing together context across development and production environments. Modern software supply chain security needs to connect those environments.

Report author Jonathan Care highlighted that breadth in his assessment of Cortex Cloud:
Palo Alto Networks earns its Overall Leadership position through the breadth of its integrated security platform, folding software supply chain security into Cortex Cloud, a unified ‘code-to-cloud-to-SOC’ Cloud-Native Application Protection Platform (CNAPP) that connects posture management with real-time threat detection and response.
Software Supply Chain risk does not end when code is committed or an artifact is built. Security teams need to understand how developer tools, identities, dependencies and artifacts connect to applications running in production, and carry that context into investigation and response.
Build Trust Across the Software Development Lifecycle
Cortex Cloud extends security across the AI-powered development ecosystem, connecting developer tools, identities, code artifacts and production assets in a single view. By combining development context with production exposure, teams can understand what is being built, prevent risks before they reach production and use Software Supply Chain Trust Scores to quickly assess the integrity of each release.

When new vulnerabilities, malicious packages or compromised developer tools emerge, teams need to act fast. Cortex Cloud’s Supply Chain Attack Threat Center automatically maps emerging threats across an organization’s environment so teams can quickly identify affected assets, understand where exposure exists, prioritize remediation and block future use of compromised tools or packages.
Ready to Secure Your Supply Chain?
Cortex Cloud helps organizations build trust into the software development lifecycle by securing AI-powered development, reducing complexity and strengthening software supply chain security.
Read the full 2026 KuppingerCole Leadership Compass for Software Supply Chain Security to learn how the market is evolving and how vendors were evaluated.