No more typing reviews! Try our Samantha, our new voice AI agent.
Black Duck SCA Logo

Black Duck SCA Reviews

Vendor: Black Duck
3.8 out of 5
Badge Leader

What is Black Duck SCA?

Featured Black Duck SCA reviews

Black Duck SCA mindshare

As of June 2026, the mindshare of Black Duck SCA in the Software Composition Analysis (SCA) category stands at 9.2%, down from 18.1% compared to the previous year, according to calculations based on PeerSpot user engagement data.
Software Composition Analysis (SCA) Mindshare Distribution
ProductMindshare (%)
Black Duck SCA9.2%
Snyk11.1%
Veracode5.9%
Other73.80000000000001%
Software Composition Analysis (SCA)

PeerResearch reports based on Black Duck SCA reviews

TypeTitleDate
CategorySoftware Composition Analysis (SCA)Jun 21, 2026Download
ProductReviews, tips, and advice from real usersJun 21, 2026Download
ComparisonBlack Duck SCA vs SnykJun 21, 2026Download
ComparisonBlack Duck SCA vs VeracodeJun 21, 2026Download
ComparisonBlack Duck SCA vs GitLabJun 21, 2026Download
Suggested products
TitleRatingMindshareRecommending
Snyk4.111.1%100%51 interviewsAdd to research
GitLab4.23.5%97%91 interviewsAdd to research
 
 
Key learnings from peers
Last updated Mar 22, 2026

Valuable Features

Room for Improvement

ROI

Pricing

Popular Use Cases

Service and Support

Deployment

Scalability

Stability

Review data by company size

By reviewers
Company SizeCount
Small Business6
Large Enterprise13
By reviewers
By visitors reading reviews
Company SizeCount
Small Business353
Midsize Enterprise174
Large Enterprise906
By visitors reading reviews

Top industries

By visitors reading reviews
Manufacturing Company
16%
Financial Services Firm
16%
Computer Software Company
11%
University
5%
Healthcare Company
5%
Comms Service Provider
4%
Government
3%
Outsourcing Company
3%
Construction Company
3%
Educational Organization
3%
Insurance Company
3%
Retailer
3%
Media Company
3%
Performing Arts
3%
Real Estate/Law Firm
2%
Energy/Utilities Company
2%
Consumer Goods Company
2%
Transportation Company
2%
Hospitality Company
1%
Wholesaler/Distributor
1%
Legal Firm
1%
Marketing Services Firm
1%
Non Profit
1%
Recreational Facilities/Services Company
1%
Logistics Company
1%
Aerospace/Defense Firm
1%

Compare Black Duck SCA with alternative products

Learn more about Black Duck SCA

Black Duck SCA customers

Related questions

 
Black Duck SCA Reviews Summary
Author infoRatingReview Summary
Project Lead at ABB3.5I find Black Duck SCA acceptable for compliance. However, its SBOMs are incomplete, vulnerability reporting is inaccurate, and usability is poor. The tool requires too much manual effort and has inadequate documentation. I rate it 6/10.
IP Head at a tech services company with 10,001+ employees3.5I find Black Duck to be robust and accurate, particularly in identifying dependencies and licenses, but it needs improvement in security vulnerability identification. It's pricier and complex to set up, impacting direct ROI assessment in some cases.
Director at a healthcare company with 10,001+ employees3.0I recommend Black Duck for its ability to identify software components and manage security, operational, and license risks effectively. While it excels in risk management, improvements are needed in addressing false positives, reporting, and container scanning.
Director at a healthcare company with 10,001+ employees4.0I use Black Duck primarily for software composition analysis. Its composition analysis and automated code scanning features are valuable for managing security risks and audit readiness. However, the absence of SBOM management is a notable drawback for me.
Senior Manager at Happiest Minds Technologies3.5We use Black Duck for open-source security management in DevOps and DevSecOps, appreciating its integration capabilities and community resources. It effectively secures 400 to 500 applications, although more open APIs would enhance its functionality further.
DevOps Engineer at a manufacturing company with 1,001-5,000 employees3.5As a DevOps engineer, I integrate Black Duck in our CI/CD pipeline for product vulnerability scans. The UI is valuable for easy integration, but improvements are needed in pricing, documentation, and scalability. Debugging can be challenging without adequate documentation.
Solutions Architect at a tech services company with 10,001+ employees4.0I use Synopsys Black Duck for security-focused project scans, identifying vulnerabilities through source code and binary analysis. It provides precise fixes and dependency insights, but sometimes lacks consistency, particularly in differentiating between direct and transitive vulnerabilities.
Project Manager at a manufacturing company with 11-50 employees4.5I use Black Duck to detect vulnerabilities in open-source software, valuing its effective binary file scanning. However, its reporting capabilities need improvement for clarity and comprehensiveness. Compared to competitors, it's superior in deployment, scalability, and its comprehensive vulnerability database.
Project Lead at ABB2.0Black Duck offers a large database, but I find the product unsatisfactory due to poor documentation and inadequate support. Although I've used other solutions like FossID and FOSSA, I believe our company should consider switching from Black Duck soon.
Head of Procurement and Vendor Manger at twoday4.5I use Black Duck to detect non-compliance in third-party applications. Its valuable features include policy and license management at a group level. Despite its power, documentation needs improvement. I evaluated other solutions like FOSSA but chose Black Duck for its customization.
SS
SanjeevKumar26
Project Lead at ABB
Mar 18, 2026
Compliance checks have improved while vulnerability coverage and SBOM accuracy still need work
reviewer2587080 - PeerSpot reviewer
reviewer2587080
IP Head at a tech services company with 10,001+ employees
May 16, 2025
Delivers robust accuracy for identifying and mitigating risks but setup and security can improve
reviewer1610562 - PeerSpot reviewer
reviewer1610562
Director at a healthcare company with 10,001+ employees
Nov 11, 2024
Effective risk management and automated code scanning with room for improved reporting
reviewer1610562 - PeerSpot reviewer
reviewer1610562
Director at a healthcare company with 10,001+ employees
Apr 4, 2025
Automated scanning enhances security risk management and audit readiness
Saravanan_Radhakrishnan - PeerSpot reviewer
Saravanan_Radhakrishnan
Senior Manager at Happiest Minds Technologies
Mar 5, 2024
Enables applications to be secure, but it must provide more open APIs
Aaron  P - PeerSpot reviewer
Aaron P
DevOps Engineer at a manufacturing company with 1,001-5,000 employees
Sep 15, 2023
A tool with a great UI to conduct a vulnerability scan that needs to provide better scalability options
Sagar Mody - PeerSpot reviewer
Sagar Mody
Solutions Architect at a tech services company with 10,001+ employees
Apr 12, 2024
Effectively flags operational vulnerabilities and recommendations for fixes are very helpful
DH
Doan Hieu
Project Manager at a manufacturing company with 11-50 employees
Apr 19, 2024
Scans binary files effectively
SS
SanjeevKumar26
Project Lead at ABB
Apr 19, 2024
The documentation needs improvement, while its cloud takes care of the installation part smoothly
Alina-Eugenia Negulescu - PeerSpot reviewer
Alina-Eugenia Negulescu
Head of Procurement and Vendor Manger at twoday
Aug 25, 2023
A scalable and customizable solution that has a very strong knowledge base