No more typing reviews! Try our Samantha, our new voice AI agent.

IBM OpenPages vs Snyk comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 11, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

IBM OpenPages
Ranking in GRC
8th
Average Rating
7.2
Reviews Sentiment
7.2
Number of Reviews
9
Ranking in other categories
IT Governance (5th)
Snyk
Ranking in GRC
6th
Average Rating
8.2
Reviews Sentiment
7.3
Number of Reviews
52
Ranking in other categories
Application Performance Monitoring (APM) and Observability (20th), Application Security Tools (7th), Static Application Security Testing (SAST) (5th), Cloud Management (12th), Vulnerability Management (17th), Container Security (6th), Software Composition Analysis (SCA) (1st), Software Development Analytics (2nd), Cloud Security Posture Management (CSPM) (13th), DevSecOps (4th), Application Security Posture Management (ASPM) (1st), AI Security (10th)
 

Mindshare comparison

As of August 2026, in the GRC category, the mindshare of IBM OpenPages is 2.2%, down from 5.5% compared to the previous year. The mindshare of Snyk is 1.5%, down from 1.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
GRC Mindshare Distribution
ProductMindshare (%)
Snyk1.5%
IBM OpenPages2.2%
Other96.3%
GRC
 

Featured Reviews

Gabriele  Meneguzzi - PeerSpot reviewer
GRC Practice Leader at Stratos Analytics
Have improved operational control and simplified internal workflows through a clear user interface
The most useful features in IBM OpenPages are the workflow features and front-end. The workflow feature in IBM OpenPages is very flexible, easy to configure, and can help design every kind of process, while the front-end is very useful, clear, simple, and dynamic. The benefit of a centralized platform in risk management, such as IBM OpenPages, is that it allows sharing information and guarantees a central framework of risk and control. The dashboards in IBM OpenPages help with monitoring processes for different users and profiles, and we use the dashboard extensively to show the state of different processes to control them. IBM OpenPages integrates effectively with other tools and existing infrastructure for my customers as we integrate other tools, using APIs to match different information, though some other tools may better support integration. IBM offers Connect, an add-on for integration, but we do not use it, relying solely on API. The reporting tools in IBM OpenPages have very strong potential because they are linked with Cognos IBM, a business intelligence tool, allowing for very good and complex reports, though creating these reports requires skills in business intelligence to get the most out of IBM OpenPages.
Abhishek-Goyal - PeerSpot reviewer
Software Engineer at a computer software company with 11-50 employees
Improves security posture by actively reducing critical vulnerabilities and guiding remediation
Snyk's main features include open-source vulnerability scanning, code security, container security, infrastructure as code security, risk-based prioritization, development-first integration, continuous monitoring and alerting, automation, and remediation. The best features I appreciate are the vulnerability checking, vulnerability scanning, and code security capabilities, as Snyk scans all open-source dependencies for known vulnerabilities and helps with license compliance for open-source components. Snyk integrates into IDEs, allowing issues to be caught as they appear in the code dynamically and prioritizes risk while providing remediation advice. Snyk provides actionable remediation advice on where vulnerabilities can exist and where code security is compromised, automatically scanning everything and providing timely alerts. Snyk has positively impacted my organization by improving the security posture across all software repositories, resulting in fewer critical vulnerabilities, more confidence in overall product security, and faster security compliance for project clients. Snyk has helped reduce vulnerabilities significantly. Initially, the repository had 17 to 31 critical and high vulnerabilities, but Snyk has helped manage them down to just five vulnerabilities, which are now lower and not high or critical.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Good in ORM and compliance, analytics, custom reporting, features for our board including risk management, and good support for Basel regulations."
"With OpenPages, the risks and controls are registered and monitored continuously."
"The content, reporting, and workflow features stand out as the most valuable aspects."
"The most useful features in IBM OpenPages are the workflow features and front-end, as noted by Ian Francis, an IBM expert lab, with the workflow feature being very flexible, easy to configure, and able to help design every kind of process, while the front-end is very useful, clear, simple, and dynamic."
"IBM OpenPages saves time in my work as a developer."
"The most valuable features are the workflow engine, calculations, and security rules."
"The ability to keep a record of internal incidents in the company, and also the monitoring of Key Indicators."
"Everything about IBM OpenPages is valuable, particularly when compared to other solutions in the market like MetricStream, from which we switched due to its feasibility, user-friendliness, and performance."
"The most effective feature in securing project dependencies stems from its ability to highlight security vulnerabilities."
"The fact that it provides visibility, compliance-related visibility, that is not readily available by cloud suppliers themselves, is its most valuable aspect."
"It is one of the best product out there to help developers find and fix vulnerabilities quickly. When we talk about the third-party software vulnerability piece and potentially security issues, it takes the load off the user or developer. They even provide automitigation strategies and an auto-fix feature, which seem to have been adopted pretty well."
"The most valuable feature of Snyk is the software composition analysis."
"Snyk is paramount and extremely important for us because anything that goes to production should not have any security vulnerabilities, and every application that goes into production must pass Snyk vulnerability scanning before it can be deployed."
"From the software composition analysis perspective, it first makes sure that we understand what is happening from a third-party perspective for the particular product that we use. This is very difficult when you are building software and incorporating dependencies from other libraries, because those dependencies have dependencies and that chain of dependencies can go pretty deep. There could be a vulnerability in something that is seven layers deep, and it would be very difficult to understand that is even affecting us. Therefore, Snyk provides fantastic visibility to know, "Yes, we have a problem. Here is where it ultimately comes from." It may not be with what we're incorporating, but something much deeper than that."
"From a compliance and visibility reporting perspective, the fact that it can be applicable for multi-cloud environments is very helpful."
"The most valuable features of Snyk are vulnerability scanning and automation. The automation the solution brings around vulnerability scanning is useful."
 

Cons

"IBM OpenPages could improve by adding more conditions to workflows, as some existing conditions might not work and can produce errors."
"Pricing! It's very expensive just for the licenses."
"IBM OpenPages needs improvement in its UI. Currently, it is difficult to see the relationships (associations/parents) between all items unless you click on the item itself."
"It would be useful to have more out-of-the-box functionality, especially triggers and calculations."
"The reporting tools in IBM OpenPages have very strong potential because they are linked with Cognos IBM, a business intelligence tool, allowing for very good and complex reports, though creating these reports requires skills in business intelligence to get the most out of IBM OpenPages."
"I believe there's room for improvement in establishing connections with external information."
"IBM needs to work on pricing for organizations with around 100 users, as the licensing model is not competitive enough for SMEs."
"Some self-relationships are not available in OpenPages' relationship model."
"For the areas that they're new in, it's very early stages for them. For example, their expertise is in looking at third-party components and packages, which is their bread-and-butter and what they've been doing for ages, but for newer features such as static analysis I don't think they've got compatibility for all the languages and frameworks yet."
"There are a lot of false positives that need to be identified and separated."
"Snyk could improve by reducing the alert noise because in large projects, security tools can surface a lot of findings."
"Generating reports and visibility through reports are definitely things they can do better."
"We were using Microsoft Docker images. It was reporting some vulnerabilities, but we were not able to figure out the fix for them. It was reporting some vulnerabilities in the Docker images given by Microsoft, which were out of our control. That was the only limitation. Otherwise, it was good."
"The tool should provide more flexibility and guidance to help us fix the top vulnerabilities before we go into production."
"Snyk has several limitations, including issues with Gradle, NPM, and Xcode, and trouble with AutoPR."
"Fugue capabilities are not well understood on the market."
 

Pricing and Cost Advice

Information not available
"It's inexpensive and easy to license. It comes in standard package sizing, which is straightforward. This information is publicly found on their website."
"Snyk is an expensive solution."
"The price is good. Snyk had a good price compared to the competition, who had higher pricing than them. Also, their licensing and billing are clear."
"The product's price is okay."
"Snyk is a premium-priced product, so it's kind of expensive. The big con that I find frustrating is when a company charges extra for single sign-on (SSO) into their SaaS app. Snyk is one of the few that I'm willing to pay that add-on charge, but generally I disqualify products that charge an extra fee to do integrated authentication to our identity provider, like Okta or some other SSO. That is a big negative. We had to pay extra for that. That little annoyance aside, it is expensive. You get a lot out of it, but you're paying for that premium."
"Compared to Veracode, Snyk is definitely a cheaper tool."
"We are using the open-source version for the scans."
"The solution is less expensive than Black Duck."
report
Use our free recommendation engine to learn which GRC solutions are best for your needs.
909,725 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
21%
Outsourcing Company
9%
Manufacturing Company
8%
Comms Service Provider
7%
Financial Services Firm
13%
Manufacturing Company
10%
Computer Software Company
8%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise1
By reviewers
Company SizeCount
Small Business20
Midsize Enterprise10
Large Enterprise24
 

Questions from the Community

What needs improvement with IBM OpenPages?
There is nothing in particular that needs improvement in IBM OpenPages, although reporting could be improved to make it easier to create reports.
What is your primary use case for IBM OpenPages?
My customers' main use cases for IBM OpenPages include ICT risk, operational risk management, and regulatory and compliance management.
What advice do you have for others considering IBM OpenPages?
For those planning to use IBM OpenPages, I recommend defining exactly what you want and understanding how IBM OpenPages can help you before starting to use it. I rate IBM OpenPages a nine out of ten.
How does Snyk compare with SonarQube?
Snyk does a great job identifying and reducing vulnerabilities. This solution is fully automated and monitors 24/7 to find any issues reported on the internet. It will store dependencies that you a...
What needs improvement with Snyk?
There are a lot of false positives that need to be identified and separated. The inclusion of AI to remove false positives would be beneficial. So far, I've not seen any AI features to enhance vuln...
What is your primary use case for Snyk?
I use Snyk ( /products/snyk-reviews ) in the DevOps pipeline to identify vulnerabilities before deploying the application. It integrates with Jenkins ( /products/jenkins-reviews ).
 

Comparisons

 

Also Known As

OpenPages
Fugue, Snyk AppRisk
 

Overview

 

Sample Customers

Nationwide, Process Innovation AG, OSRAM Licht AG, Dep‹sito Central de Valores (DCV), Delta Lloyd Group, Unum
StartApp, Segment, Skyscanner, DigitalOcean, Comic Relief
Find out what your peers are saying about IBM OpenPages vs. Snyk and other solutions. Updated: August 2026.
909,725 professionals have used our research since 2012.