No more typing reviews! Try our Samantha, our new voice AI agent.

BMC Cloud Lifecycle Management vs Snyk comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 11, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

BMC Cloud Lifecycle Management
Ranking in Cloud Management
43rd
Average Rating
7.8
Reviews Sentiment
5.3
Number of Reviews
5
Ranking in other categories
Cloud Monitoring Software (43rd)
Snyk
Ranking in Cloud Management
12th
Average Rating
8.2
Reviews Sentiment
7.3
Number of Reviews
52
Ranking in other categories
Application Performance Monitoring (APM) and Observability (20th), Application Security Tools (7th), Static Application Security Testing (SAST) (5th), GRC (6th), Vulnerability Management (17th), Container Security (6th), Software Composition Analysis (SCA) (1st), Software Development Analytics (2nd), Cloud Security Posture Management (CSPM) (13th), DevSecOps (4th), Application Security Posture Management (ASPM) (1st), AI Security (10th)
 

Mindshare comparison

As of August 2026, in the Cloud Management category, the mindshare of BMC Cloud Lifecycle Management is 1.6%, up from 0.9% compared to the previous year. The mindshare of Snyk is 1.6%, up from 1.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Cloud Management Mindshare Distribution
ProductMindshare (%)
Snyk1.6%
BMC Cloud Lifecycle Management1.6%
Other96.8%
Cloud Management
 

Featured Reviews

VB
Enterprise Solution Architect at a computer software company with 5,001-10,000 employees
Helps design blueprints in a cloud environment but the support is a major problem
One of the major problems is that support is not so good. I used to have a support expert in Spain but they left two years ago. BMC doesn't invest a lot in network automation but network automation is a major point in CLM. There aren't any experts here in Europe, maybe they have in America, I don't know. The main problem is the support in Europe. We had a lot of problems with the people who got put on our cases. The agents that we were assigned to were not so capable. They wanted to replicate the problem. If you have an incident, it takes a lot of time to troubleshoot the problem. The incident support is not so good. The technicians don't know the platform well. BMC doesn't want to invest in CLM. Two years ago we had a lot of problems. Maybe BMC realized that CLM is an end of life product.
Abhishek-Goyal - PeerSpot reviewer
Software Engineer at a computer software company with 11-50 employees
Improves security posture by actively reducing critical vulnerabilities and guiding remediation
Snyk's main features include open-source vulnerability scanning, code security, container security, infrastructure as code security, risk-based prioritization, development-first integration, continuous monitoring and alerting, automation, and remediation. The best features I appreciate are the vulnerability checking, vulnerability scanning, and code security capabilities, as Snyk scans all open-source dependencies for known vulnerabilities and helps with license compliance for open-source components. Snyk integrates into IDEs, allowing issues to be caught as they appear in the code dynamically and prioritizes risk while providing remediation advice. Snyk provides actionable remediation advice on where vulnerabilities can exist and where code security is compromised, automatically scanning everything and providing timely alerts. Snyk has positively impacted my organization by improving the security posture across all software repositories, resulting in fewer critical vulnerabilities, more confidence in overall product security, and faster security compliance for project clients. Snyk has helped reduce vulnerabilities significantly. Initially, the repository had 17 to 31 critical and high vulnerabilities, but Snyk has helped manage them down to just five vulnerabilities, which are now lower and not high or critical.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Total build time has been reduced from four weeks to one week, then later to 24 hours."
"Allowing systems to be provisioned in a wide range of environments, such as Azure, AWS, or on-premise, reduces the level of training required as well as creates consistency across the board."
"We have many regions where more than 10000 servers are deployed, so it helps in patching and hardening of servers."
"You can tie together your public and private cloud infrastructure into a "single pane of glass"."
"Automates Java EE Application Deployment from an SCM system."
"Integrates role-based access control with pre-configured policies for CIS, DISA, HIPAA, PCI, SOX, NIST, and SCAP documentation and remediation."
"Assesses change impact or completes an audit using multiple dashboard views."
"By allowing end users to request their own services, the request process for systems is much quicker and more accurate."
"It is one of the best product out there to help developers find and fix vulnerabilities quickly. When we talk about the third-party software vulnerability piece and potentially security issues, it takes the load off the user or developer. They even provide automitigation strategies and an auto-fix feature, which seem to have been adopted pretty well."
"The dependency checks of the libraries are very valuable, but the licensing part is also very important because, with open source components, licensing can be all over the place. Our project is not an open source project, but we do use quite a lot of open source components and we want to make sure that we don't have surprises in there."
"They evolved their maturity because they could find the vulnerabilities before the pipeline runs."
"I find SCA to be valuable. It can read your libraries, your license and bring the best way to resolve your problem in the best scenario."
"It is one of the best product out there to help developers find and fix vulnerabilities quickly."
"The most effective feature in securing project dependencies stems from its ability to highlight security vulnerabilities."
"It hits ROI for us very well in a couple of areas that we want to address: to ensure that we don't have surprises when it comes to vulnerabilities on our dependencies — libraries and images — and from a compliance point of view, we don't want to be in a situation where we're forced to publish code because someone has decided to use libraries that would force us to either publish everything under GPL or put us in a situation where licenses are not compatible and we would have to redo part of the code."
"We're loving some of the Kubernetes integration as well. That's really quite cool. It's still in the early days of our use of it, but it looks really exciting. In the Kubernetes world, it's very good at reporting on the areas around the configuration of your platform, rather than the things that you've pulled in. There's some good advice there that allows you to prioritize whether something is important or just worrying. That's very helpful."
 

Cons

"One of the major problems is that support is not so good."
"The installation and configuration can be tricky due to it being built on Remedy."
"Needs integrations with other providers to provide a custom public cloud environment."
"Going to BMC for PS is not at all recommended from my experience."
"It was complex as it does not include a good, extensive feasibility and compatibility guide."
"The solution could improve the reports. They have been working on improving the reports but more work could be done."
"Basically the licensing costs are a little bit expensive."
"Scalability has some issues because we have a lot of code and its use is mandatory. Therefore, it can be slow at times, especially because there are a lot of projects and reporting. Some UI improvements could help with this."
"There is always more work to do around managing the volume of information when you've got thousands of vulnerabilities. Trying to get those down to zero is virtually impossible, either through ignoring them all or through fixing them. That filtering or information management is always going to be something that can be improved."
"They were a couple of issues which happened because Snyk lacked some documentation on the integration side."
"There are some new features that we would like to see added, e.g., more visibility into library usage for the code. Something along the lines where it's doing the identification of where vulnerabilities are used, etc. This would cause them to stand out in the market as a much different platform."
"I would like to give further ability to grouping code repositories, in such a way that you could group them by the teams that own them, then produce alerting to those teams. The way that we are seeing it right now, the alerting only goes to a couple of places. I wish we could configure the code to go to different places."
"It can be improved from the reporting perspective and scanning perspective. They can also improve it on the UI front."
 

Pricing and Cost Advice

Information not available
"Snyk is a premium-priced product, so it's kind of expensive. The big con that I find frustrating is when a company charges extra for single sign-on (SSO) into their SaaS app. Snyk is one of the few that I'm willing to pay that add-on charge, but generally I disqualify products that charge an extra fee to do integrated authentication to our identity provider, like Okta or some other SSO. That is a big negative. We had to pay extra for that. That little annoyance aside, it is expensive. You get a lot out of it, but you're paying for that premium."
"On a scale of one to ten, where one is cheap and ten is expensive, I rate the pricing a three. It is a cheap solution."
"For what Snyk offers, it has the best cost-benefit I have ever seen because you're buying the license per user."
"Cost-wise, it's similar to Veracode, but I don't know the exact cost."
"The product's price is okay."
"It's good value. That's the primary thing. It's not cheap-cheap, but it's good value."
"I would rate the pricing of Snyk at two. I'm currently using the free version, which the company offers before buying the full version. So, the price is affordable, especially for an enterprise."
"Despite Snyk's coverage, scalability, reliability, and stability, it is available at a very competitive price."
report
Use our free recommendation engine to learn which Cloud Management solutions are best for your needs.
909,725 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
17%
Insurance Company
8%
Financial Services Firm
8%
Comms Service Provider
7%
Financial Services Firm
13%
Manufacturing Company
10%
Computer Software Company
8%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business20
Midsize Enterprise10
Large Enterprise24
 

Questions from the Community

Ask a question
Earn 20 points
How does Snyk compare with SonarQube?
Snyk does a great job identifying and reducing vulnerabilities. This solution is fully automated and monitors 24/7 to find any issues reported on the internet. It will store dependencies that you a...
What needs improvement with Snyk?
There are a lot of false positives that need to be identified and separated. The inclusion of AI to remove false positives would be beneficial. So far, I've not seen any AI features to enhance vuln...
What is your primary use case for Snyk?
I use Snyk ( /products/snyk-reviews ) in the DevOps pipeline to identify vulnerabilities before deploying the application. It integrates with Jenkins ( /products/jenkins-reviews ).
 

Also Known As

BMC CLM
Fugue, Snyk AppRisk
 

Overview

 

Sample Customers

JDA Software, Morningstar, Orange Business Services, Wipro
StartApp, Segment, Skyscanner, DigitalOcean, Comic Relief
Find out what your peers are saying about BMC Cloud Lifecycle Management vs. Snyk and other solutions. Updated: August 2026.
909,725 professionals have used our research since 2012.