• HOME
  • CATEGORIES

    • CATEGORIES

    • Browse All Categories
  • FOR VENDORS

    • FOR VENDORS

    • Log In to Vendor Portal
    • Get Started
  • REVIEWS

    • REVIEWS

    • Write a Review
    • Product Reviews
    • Vendor Directory
    • Product Comparisons
  • GARTNER PEER COMMUNITY™
  • GARTNER.COM
  • Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQPrivacyTerms of Service
    ©2026 Gartner, Inc. and/or its affiliates.
    All rights reserved.
  • Categories

    • Loading categories...

      Browse All Categories

      Loading markets...

  • For Vendors

    • Log In to Vendor Portal 

    • Get Started 

  • Write a Review

Join / Sign In
  1. Home
  2. /
  3. Black Duck Software Composition Analysis
Logo of Black Duck Software Composition Analysis

Black Duck Software Composition Analysis

byBlack Duck
in
4.5
Market Presence: Application Security Testing, Software Supply Chain Security

Overview

Product Information on Black Duck Software Composition Analysis

Updated 3rd June 2022

What is Black Duck Software Composition Analysis?

Black Duck® software composition analysis (SCA) helps teams manage the security, quality, and license compliance risks that come from the use of open source and third-party code in applications and containers. Black Duck uses multiple open source discovery techniques to generate a complete and accurate software bill of materials (SBOM), including: declared/transitive dependency analysis, filesystem scanning, binary file analysis, and embedded code snippet detection. Black Duck gives teams a complete picture of open source risks with information from the Black Duck KnowledgeBase™ of over 5 million open source projects. In addition, independently researched Black Duck Security Advisories (BDSAs) provide teams with detailed vulnerability risk and remediation guidance weeks ahead of the NVD. Teams can manage risks across the SDLC using integrated policy management capabilities as well as monitoring and alerting for newly reported vulnerabilities impacting production applications.

Black Duck Software Composition Analysis Pricing

Annual contract based on team size and number of code bases analyzed by the product.

Black Duck Software Composition Analysis Product Images

Black_Duck_Dashboard
Black_Duck_Dashboard
Black_Duck_Risk_Status
Black_Duck_Risk_Status
Black_Duck_Risk_Discription
Black_Duck_Risk_Discription

Overall experience with Black Duck Software Composition Analysis

Research and Development Associate
1B - 3B USD, Software
FAVORABLE

“Black Duck - an excellent SCA tool”

4.0
Jan 12, 2026
Black duck helps us greatly in identifying critical vulnerabilities. We did encounter a reporting buf that was not fixed over several releases, hence the non-perfect score.
DEVOPS ENGINEER
500M - 1B USD, Transportation
CRITICAL

“General review - Black Duck”

3.0
Sep 26, 2023
seamless integration to scan the binary files, provides all open vulnerabilities, easier contact since we are using other Synopsis products.

About Company

Company Description

Updated 17th February 2025

Black Duck builds trust in software by enabling organizations to manage application security, quality, and compliance risks at the speed their business demands. Black Duck solutions help developers to secure code as fast as they write it; development and DevSecOps teams to automate testing within development pipelines without compromising velocity; and security teams to proactively manage risk and focus remediation efforts on what matters most. With Black Duck, organizations can transform the way they build and deliver software, aligning people, processes, and technology to intelligently address software risks across their portfolio and at all stages of the application lifecycle.

Company Details

Updated 26th February 2025
Year Founded
2002
Head office location
Burlington, United States
Number of employees
1001 - 5000
Website
https://blackduck.com

Do You Manage Peer Insights at Black Duck?

Access Vendor Portal to update and manage your profile.

Key Insights

A Snapshot of What Matters - Based on Validated User Reviews

Reviewer Insights for: Black Duck Software Composition Analysis
Deciding Factors: Black Duck Software Composition Analysis Vs. Market Average
Performance of Black Duck Software Composition Analysis Across Market Features

Black Duck Software Composition Analysis Likes & Dislikes

Like

1. Ease of use and search capabilities. 2. Integrates with our Power BI - dashboards help us track the security posture of our products. 3. The support team is responsive, honest and overall we are satisfied.

Like

Very useful to figure out vulnerabilities in the various open-source libraries. Ensures accurate overall security, compliance, and risk management. Also, it has quick inventory scanning as well that analyzes quick.

Like

1. Ability to quickly and accurately identify components 2. CVE database, useful analysis and patches 3. Policy management to quickly address the unallowed component ands projects

Dislike

The reporting bug that they've had in the product for about 4 releases now. We have mitigated the issues and yet they still appear as open, which leads to a misleading status.

Dislike

Rather outdated UX design, the cost is too expensive. Should be more documentations for users and community.

Dislike

The database update, users/administrators have no idea about the status of the database, we dont know if the database is updating or upgrading, usually when we open a project, it shows the SBOM is refreshing, we shall check later. That should happen on the backend. Also, I don't like the idea that we can't show our CVE management to customers. We need a feature to show our CVE status, i.e., fixed, ignored, not affected with comments to customers, notify bodies or regulators. We also need Black Duck to support the CVE management deliverables, a machine-readable file generated with all your work on the project, and you can send it to up and down stream for a cooperation. That would help a lot but I haven't found it yet.

Top Black Duck Software Composition Analysis Alternatives

Logo of Veracode
1. Veracode
4.6
(401 Ratings)
Logo of Checkmarx SAST
2. Checkmarx SAST
4.6
(398 Ratings)
Logo of Appknox
3. Appknox
4.8
(246 Ratings)
View All Alternatives

Peer Discussions

Black Duck Software Composition Analysis Reviews and Ratings

Showing data for 87 ratings and reviews for Application Security Testing market. View all 100 ratings and reviews across markets for a complete picture.

4.5

(87 Ratings)

Rating Distribution

5 Star
51%
4 Star
44%
3 Star
6%
2 Star
0%
1 Star
0%
Why ratings and reviews count differ?

Customer Experience

Evaluation & Contracting

4.4

Integration & Deployment

4.4

Service & Support

4.5

Product Capabilities

4.5

Filter Reviews
Sort By:
Most helpful
Last 12 Months
Star Rating
Reviewer Type
Reviewer's Company Size
Reviewer's Industry
Reviewer's Region
Reviewer's Job Function
  • Research and Development Associate
    1B-10B USD
    Software
    Review Source

    Black Duck - an excellent SCA tool

    4.0
    Jan 12, 2026
    Black duck helps us greatly in identifying critical vulnerabilities. We did encounter a reporting buf that was not fixed over several releases, hence the non-perfect score.
  • Security & Risk Management
    50M-1B USD
    Telecommunication
    Review Source

    Transparency in CVE Status Reporting and Database Updates Remain Key User Concerns

    5.0
    Jun 24, 2025
    Black Duck is the only SCA solution we found which supports both C/C++ source code/binary detection, and can be deployed in pravacy. This solution has strong ability/power in component analysis, and the vulnerabilities database is really up-to-date. We can find further and deeply support in CVE management and fix issues. Also the vendors' technical support is so strong, any problems/issues can be solved in really short time.
  • IT Security Specialist
    Gov't/PS/Ed
    Government
    Review Source

    BlackDuck's Intuitive Interface Covers All Programming Languages

    5.0
    Nov 5, 2024
    BlackDuck was easy to setup and the vendor provided clear instructions on the configuration.
  • Senior Director of Software Development
    50M-1B USD
    Software
    Review Source

    BlackDuck SCA Tool - Strengths and Weaknesses

    4.0
    Oct 15, 2024
    SCA tool does a good job of identifying the opensource vulnerabilities and license risks. The user interface is very intuitive and simple to use.
  • Software Developer
    50M-1B USD
    Hardware
    Review Source

    Black Duck Binary Analysis (BDBA) is an excellent SCA tool.

    5.0
    Sep 30, 2024
    Using Black Duck Binary Analysis. The advantage is that we can easily create SBOMS and Reports from binary files.
...
Showing Result 1-5 of 89

Recommended Gartner Research

  • Critical Capabilities for Application Security Testing
  • Magic Quadrant for Application Security Testing

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

This site is protected by hCaptcha and its Privacy Policy and Terms of Use apply.


Software reviews and ratings for EMMS, BI, CRM, MDM, analytics, security and other platforms - Peer Insights by Gartner
Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQsPrivacyTerms of Use

©2026 Gartner, Inc. and/or its affiliates.

All rights reserved.