No more typing reviews! Try our Samantha, our new voice AI agent.

AWS Secrets Manager vs CyberArk Privileged Access Manager comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 16, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

AWS Secrets Manager
Ranking in Enterprise Password Managers
2nd
Average Rating
9.0
Reviews Sentiment
6.8
Number of Reviews
17
Ranking in other categories
Secrets Management Tools (3rd)
CyberArk Privileged Access ...
Ranking in Enterprise Password Managers
3rd
Average Rating
8.6
Reviews Sentiment
6.8
Number of Reviews
230
Ranking in other categories
User Activity Monitoring (1st), Privileged Access Management (PAM) (1st), Mainframe Security (1st), Operational Technology (OT) Security (3rd)
 

Mindshare comparison

As of May 2026, in the Enterprise Password Managers category, the mindshare of AWS Secrets Manager is 14.7%, down from 18.7% compared to the previous year. The mindshare of CyberArk Privileged Access Manager is 6.7%, down from 7.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Enterprise Password Managers Mindshare Distribution
ProductMindshare (%)
AWS Secrets Manager14.7%
CyberArk Privileged Access Manager6.7%
Other78.6%
Enterprise Password Managers
 

Featured Reviews

Mahadev Metre - PeerSpot reviewer
DevOps Engineer at Paydoh
Consistent security and efficiency improvements optimize IT infrastructure with effective management
When creating AWS Secrets Manager, it should be automated using tools such as Terraform, Puppet, or Ansible. With Terraform code, you specify the encryption key, secret name, rotation policy, and secret replication. Human error occurs when feeding secret values manually, especially with large amounts of secrets to input. Secrets should never be protected only by IAM. They should be protected by multiple layers, such as IAM and one or two KMS keys. Additional security measures could be beneficial if necessary. The rotation policy is crucial because some secrets may become obsolete, require updates, or get compromised. With a weekly rotation policy, if unauthorized access occurs, the exposure is limited to seven days. The rotation policy can be customized according to needs.
Atul-Gujar - PeerSpot reviewer
CyberArk manager at a comms service provider with 10,001+ employees
Secures critical infrastructures with essential user session audit records
A potential area for improvement is enhancing support for cluster environments and distributed Vaults. Clients in multiple countries that need central access have different challenges that require better solutions from CyberArk. For financial services, CyberArk can improve incident response by ensuring fast support for critical priority tickets to meet compliance requirements. Providing more documentation on CyberArk is recommended for new team members to enhance their troubleshooting capabilities. I understand it's up to the client, but 99% fail to change the demo key, so it's crucial for CyberArk to emphasize changing the key and documenting it as part of the installation process.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature of AWS Secrets Manager is the ability to keep data secret and assign access permissions to people to grant or restrict access."
"Secrets Manager helps in retrieving the enrollment variables used by the code."
"If your workloads are running on AWS and you want a quick and easy integration with a solution to manage your secrets, AWS Secrets Manager can do the job."
"The most valuable feature is the management of credentials."
"The most valuable feature is usability, as it is quite user-friendly."
"It's highly scalable, so I'd rate it a ten out of ten."
"The most valuable feature of AWS Secrets Manager is its seamless integration with various AWS services."
"Overall, this is a good product, we are satisfied with the support, and I recommend it."
"Auditing and control are the most valuable, as you can control password management almost to the max, giving you, your users and your auditors great flexibility without compromising security."
"The benefit of it is it's stable, it's old-school, it just works."
"With PAM in place, we've experienced a significant reduction in potential security breaches."
"CyberArk makes our environment more secure and prevents possible attacks by compromised accounts."
"Implementing the CyberArk solution helps these companies to think about their privileged accounts, organize them in the CyberArk solution, and then get control of their privileged accounts to safely store and manage these, knowing that only the correct persons can access these accounts and that the different devices can only be managed via one central entry point to the datacenter."
"In terms of stability, there are no complaints."
"CyberArk Privileged Access Manager provides granularity. You can break things down into individual safes. You have specific access to safes by individual or group. The interface is with AD, with LDAP, or with local CyberArk passwords. You also have the ability to establish policies for your individual credentials."
"The biggest feature is the security of the overall solution. It's very secure. The vaulting technology and the number of security layers involved in the vault, where privileged accounts are actually stored, is the heart of the solution."
 

Cons

"AWS Secrets Manager could support hybrid infrastructure."
"The solution's initial setup process is complicated."
"It would be good if the AWS Secrets Manager were more customizable."
"The price of the solution could improve."
"It would be good if the AWS Secrets Manager were more customizable."
"There is room for improvement in terms of integrating with certain other platforms."
"There is a need for better environmental implementation, such as having a security fund as a solution."
"An area for improvement in AWS Secrets Manager could be expanding integration options beyond AWS services."
"The challenge with the product is pricing since it's expensive. It also needs to improve the customization. We encountered some stability issues as well."
"The solution needs better features for end users to manage their own whitelisting for API retrieval."
"I'm not a fan of technical support with CyberArk. It's like jumping through red tape and hoops."
"There is a bit of a learning curve, but it's a pretty complex solution."
"With regards to potential improvements for the CyberArk product, I find the product quite expensive and I would like to see the cost reduced."
"Having a centralized place to manage the solution has been something that I have always wanted, and they are starting to understand that and bring things back together."
"Enhanced PSM support for Java based applications."
"If you are an administrator or architect, then the solution is kind of complicated, as it is mostly focused on the end user. So, they need to also focus on the people who are implementing it."
 

Pricing and Cost Advice

"We purchase a monthly license for the product."
"The cost is somewhat high."
"I don't believe there is a license cost for the solution."
"We've observed that AWS Secrets Manager pricing is based on a per-secret-per-month model. As a result, we prefer to divide our secrets into individual pieces to increase security and grant specific access permissions to certain secrets, systems, or individuals. However, this approach results in higher costs. Therefore, we have been exploring ways to combine our secrets into groups to reduce expenses and simplify management. Nonetheless, we acknowledge that this issue may not be related to the secret manager's functionality."
"The solution is expensive."
"The product's licensing is yearly. I would rate the solution's pricing a six out of ten."
"Pricing is a problem. CyberArk is expensive compared to other products I know. It is similar to buying a German car. It comes with all the bells and whistles, but some companies may find it too expensive."
"CyberArk DNA is free if you purchase the CyberArk solution. There is no additional charge for CyberArk DNA, which is great."
"I'm a technician so I don't handle the licensing for CyberArk Privileged Access Manager, but I know that the price for the core license is about €140 per year. There's another type of license, the external vendor license, and that's about €600 and you can manage twenty devices. From what I know, the price for one device in a subscription is about €65 per year. You can buy the CyberArk Endpoint Privilege Manager too, or you can buy some other application or application license with CyberArk Privileged Access Manager, but all other features, such as the Analytics Server is included in the basic CyberArk license. With WALLIX, you need to buy separate licenses for the features."
"It's per-company, license-based."
"If you are looking at implementing this solution, buy the training and go to it."
"They have two types of licensing: purchase and subscription. You have to pay for each admin user, such as Microsoft admin, mail admin, database admin, etc."
"I haven't seen the numbers. I know it is not cheap, but I don't know what it is. I would rate it a six out of ten in terms of pricing. It is definitely more expensive than the other product, but it also provides more functionality, and it is modular too. So, we pay for the functionality we're actually going to use, and that's nice."
report
Use our free recommendation engine to learn which Enterprise Password Managers solutions are best for your needs.
893,244 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Computer Software Company
9%
Manufacturing Company
8%
Comms Service Provider
7%
Financial Services Firm
13%
Manufacturing Company
11%
Computer Software Company
7%
Comms Service Provider
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Large Enterprise10
By reviewers
Company SizeCount
Small Business59
Midsize Enterprise42
Large Enterprise174
 

Questions from the Community

Which is better - Azure Key Vault or AWS Secrets Manager?
Azure Key Vault is a SaaS solution. You can easily store passwords and secrets securely and encrypt them. Azure Key Vault is a great solution to ensure you are compliant with security and governanc...
Which is better - HashiCorp Vault or AWS Secrets Manager?
HashiCorp Vault was designed with your needs in mind. One of the features that makes this evident is its ability to work as both a cloud-agnostic and a multi-cloud solution. As a cloud-agnostic sol...
What needs improvement with AWS Secrets Manager?
AWS Secrets Manager could not be better because there has been no frustration with the product.
How does Sailpoint IdentityIQ compare with CyberArk PAM?
We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to manage risks in cloud enterprise environments. It automates and streamlines the m...
What do you like most about CyberArk Privileged Access Manager?
The most valuable features of the solution are control and analytics.
What is your experience regarding pricing and costs for CyberArk Privileged Access Manager?
My thoughts on the pricing of CyberArk Privileged Access Manager depend entirely on the vendors' requirements. If they want their things to be secure, they have to spend accordingly. We have four t...
 

Also Known As

No data available
CyberArk Privileged Access Security, CyberArk Enterprise Password Vault
 

Overview

 

Sample Customers

Autodesk, Clevy, Stackery
Rockwell Automation
Find out what your peers are saying about AWS Secrets Manager vs. CyberArk Privileged Access Manager and other solutions. Updated: April 2026.
893,244 professionals have used our research since 2012.