• HOME
  • CATEGORIES

    • CATEGORIES

    • Browse All Categories
  • FOR VENDORS

    • FOR VENDORS

    • Log In to Vendor Portal
    • Get Started
  • REVIEWS

    • REVIEWS

    • Write a Review
    • Product Reviews
    • Vendor Directory
    • Product Comparisons
  • GARTNER PEER COMMUNITY™
  • GARTNER.COM
  • Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQPrivacyTerms of Service
    ©2026 Gartner, Inc. and/or its affiliates.
    All rights reserved.
  • Categories

    • Loading categories...

      Browse All Categories

      Loading markets...

  • For Vendors

    • Log In to Vendor Portal 

    • Get Started 

  • Write a Review

Join / Sign In
  1. Home
  2. /
  3. Black Duck Software Composition Analysis
Logo of Black Duck Software Composition Analysis

Black Duck Software Composition Analysis

byBlack Duck
in
4.0
Market Presence: Application Security Testing, Software Supply Chain Security

Overview

Product Information on Black Duck Software Composition Analysis

Updated 7th June 2022

What is Black Duck Software Composition Analysis?

Black Duck® software composition analysis (SCA) helps teams manage the security, quality, and license compliance risks that come from the use of open source and third-party code in applications and containers. Black Duck uses multiple open source discovery techniques to generate a complete and accurate software bill of materials (SBOM), including: declared/transitive dependency analysis, filesystem scanning, binary file analysis, and embedded code snippet detection. Black Duck gives teams a complete picture of open source risks with information from the Black Duck KnowledgeBase™ of over 5 million open source projects. In addition, independently researched Black Duck Security Advisories (BDSAs) provide teams with detailed vulnerability risk and remediation guidance weeks ahead of the NVD. Teams can manage risks across the SDLC using integrated policy management capabilities as well as monitoring and alerting for newly reported vulnerabilities impacting production applications.

Black Duck Software Composition Analysis Pricing

Annual contract based on team size and number of code bases analyzed by the product.

Black Duck Software Composition Analysis Product Images

Black_Duck_Dashboard
Black_Duck_Dashboard
Black_Duck_Risk_Status
Black_Duck_Risk_Status
Black_Duck_Risk_Description
Black_Duck_Risk_Description

Overall experience with Black Duck Software Composition Analysis

VP, COMPLIANCE AND RISK MANAGEMENT
<50M USD, Services (non-Government)
FAVORABLE

“Best-in-class SCA tool with Flexible Policy Management”

5.0
Oct 13, 2025
Best in class Software Composition Analysis tool. Wide language support. Open Source components identification using various scanners, including binary analysis and a rich knowledgebase.
Manager, It Security And Risk Management
10B - 30B USD, Banking
CRITICAL

“Dated User Interface and Deployment Challenges Highlighted in Platform Feedback”

3.0
Jan 12, 2026
The design of the on-prem version of the platform is a bit dated. It required a considerable amount of the engineering effort to operate the platform.

About Company

Company Description

Updated 17th February 2025

Black Duck builds trust in software by enabling organizations to manage application security, quality, and compliance risks at the speed their business demands. Black Duck solutions help developers to secure code as fast as they write it; development and DevSecOps teams to automate testing within development pipelines without compromising velocity; and security teams to proactively manage risk and focus remediation efforts on what matters most. With Black Duck, organizations can transform the way they build and deliver software, aligning people, processes, and technology to intelligently address software risks across their portfolio and at all stages of the application lifecycle.

Company Details

Updated 26th February 2025
Year Founded
2002
Head office location
Burlington, United States
Number of employees
1001 - 5000
Website
https://blackduck.com

Do You Manage Peer Insights at Black Duck?

Access Vendor Portal to update and manage your profile.

Key Insights

A Snapshot of What Matters - Based on Validated User Reviews

Reviewer Insights for: Black Duck Software Composition Analysis
Performance of Black Duck Software Composition Analysis Across Market Features

Black Duck Software Composition Analysis Likes & Dislikes

Like

The combination of high security and license compliance capabilities with flexible policies makes BlackDuck Software Composition Analysis the perfect tool for companies that wish to manage Open Source at a high level. There is no need for any additional complementary tools to manage Open Source.

Like

1. Responsive and professional support team. Very fast response time to support tickets and can always resolve our issues in one or two rounds of communication. 2. Good documentation of the product. 3. Black duck has it's own research team with it's own vulnerability database.

Like

Excellent potential to eradicate security threats, many features, easy to integrate

Dislike

Black Duck Software Composition Analysis tool comes with a high price tag and a minimum developer plan, which may not fit many small software companies.

Dislike

1. The UX is a bit dated and not the most intuitive to use. 2. Deployment is hard to manage. HA requires two full stack deployments. Also, the product is only released quarterly, hence a lot of vulnerabilities in the product itself can't be patched in a timely manner. 3. Tend to have many bugs in every version.

Dislike

Cost wise slightly expensive, UI can be improved and strengthen to cover many more security parts

Top Black Duck Software Composition Analysis Alternatives

Logo of Mend
1. Mend
4.4
(111 Ratings)
Logo of Veracode
2. Veracode
4.5
(16 Ratings)
Logo of Snyk Open Source
3. Snyk Open Source
4.2
(12 Ratings)
View All Alternatives

Peer Discussions

Black Duck Software Composition Analysis Reviews and Ratings

Showing data for 13 ratings and reviews for Software Supply Chain Security market. View all 100 ratings and reviews across markets for a complete picture.

4.0

(13 Ratings)

Rating Distribution

5 Star
23%
4 Star
54%
3 Star
23%
2 Star
0%
1 Star
0%
Why ratings and reviews count differ?

Customer Experience

Evaluation & Contracting

4.2

Integration & Deployment

4.1

Service & Support

4.3

Product Capabilities

4.4

Filter Reviews
Sort By:
Most helpful
Last 12 Months
Star Rating
Reviewer Type
Reviewer's Company Size
Reviewer's Industry
Reviewer's Region
Reviewer's Job Function
  • VP, COMPLIANCE AND RISK MANAGEMENT
    <50M USD
    Services (non-Government)
    Review Source

    Best-in-class SCA tool with Flexible Policy Management

    5.0
    Oct 13, 2025
    Best in class Software Composition Analysis tool. Wide language support. Open Source components identification using various scanners, including binary analysis and a rich knowledgebase.
  • Manager, It Security And Risk Management
    10B+ USD
    Banking
    Review Source

    Dated User Interface and Deployment Challenges Highlighted in Platform Feedback

    3.0
    Jan 12, 2026
    The design of the on-prem version of the platform is a bit dated. It required a considerable amount of the engineering effort to operate the platform.
  • ASSOCIATE SOFTWARE DEVELOPMENT ENGINEER
    1B-10B USD
    Hardware
    Review Source

    Great tool for functionally safe projects

    4.0
    Aug 2, 2022
    Recently started using Blackduck SCA and it's been great using it for identifying potential threats and potential data threats
  • PRINCIPAL SECURITY ENGINEER
    50M-1B USD
    Miscellaneous
    Review Source

    Great for tracking OSS in use and generating SBOM

    3.0
    Jul 15, 2022
    Black Duck provides a critical service for us with Open Source Software we use. As long as this product has been around, it is still not ideal to be used at Enterprise level. It is not a product easy to scale out and does not support any type of load balancing.
  • CYBER SECURITY
    50M-1B USD
    Banking
    Review Source

    Black Duck helps us to find vulnerabilities in our application

    4.0
    Jul 7, 2022
    Black Duck helps us find vulnerabilities in our application by categories into 3 components. 1. Security risk in library 2. Library licensing agreement 3. Operation risk in library Which is really strange forward and easy for developer to understand and flexible for fixing. Black duck has ability to go through every part in the code to scan for vulnerabilities and show specific dependency.
Showing Result 1-5 of 13

Recommended Gartner Research

  • Market Guide for Software Supply Chain Security

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

This site is protected by hCaptcha and its Privacy Policy and Terms of Use apply.


Software reviews and ratings for EMMS, BI, CRM, MDM, analytics, security and other platforms - Peer Insights by Gartner
Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQsPrivacyTerms of Use

©2026 Gartner, Inc. and/or its affiliates.

All rights reserved.