Armis
Cyber exposure management platform covering the full cyber-physical systems landscape, with medical device security as one of five products within Armis Centrix alongside Asset Management, OT/IoT Security, ViPR Pro for vulnerability prioritisation and remediation, and Early Warning. The platform correlates device context, behavioural anomalies, vulnerability intelligence, business impact and exposure pathways into a unified risk model, prioritising remediation by real-world operational risk rather than treating findings in isolation.
Named a Leader in the 2026 Gartner Magic Quadrant for CPS Protection Platforms for the second consecutive year, one of 13 vendors evaluated, and recognised in the companion Critical Capabilities report, with 119 Gartner Peer Insights reviews in that category rating 4.7 out of 5 as of March 2026. Offers on-premise, cloud and hybrid deployment. Two things a reader must weigh, both stated plainly by the company. First, this is a horizontal platform, not a healthcare specialist: it serves manufacturing, energy, critical infrastructure and government alongside healthcare, and medical device security is one product line rather than the business.
It is indexed on the same basis as Claroty, whose Medigate-derived healthcare capability sits inside a broader industrial security platform. Buyers should compare it against healthcare-only vendors such as Cylera and Asimily on depth of clinical device intelligence rather than on platform breadth, and independent Gartner Peer Insights commentary notes that while asset visibility is strong, some users find OT and CPS protocol depth less than top tier. Second, independence is ending: Armis has announced a planned acquisition by ServiceNow expected to complete in the second half of 2026.
The company states it will continue operating with the same mission and innovation strategy under ServiceNow investment. That should be treated as a forward-looking statement rather than a settled outcome, and buyers signing multi-year agreements should establish what contractual continuity exists. The pattern is worth watching: an independent exposure management platform absorbed by an enterprise workflow vendor raises the same question as diagnostics manufacturers acquiring open algorithm platforms.
Capability Axes
An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read
Deliberate B, applying the same reasoning used for Nanox.AI, graded down because it is one line of a larger business. The analytical work is real: Armis Centrix correlates device context, behavioural anomalies, vulnerability intelligence, business impact and exposure pathways into a unified risk model, and behavioural anomaly detection across an asset estate of this breadth is genuinely model-driven.
But medical device security is one of five products on a horizontal platform whose centre of gravity is cyber-physical systems across manufacturing, energy and critical infrastructure, and the platform's core asset is the breadth of its device intelligence across all those domains. Compare Ordr and Cylera, both graded A, where the ML is the whole product and healthcare is the whole market.
Risk prioritisation and remediation guidance integrated into enterprise workflows rather than autonomous enforcement, with the ViPR Pro product specifically handling vulnerability prioritisation and remediation. The stated design intent is addressing critical exposures quickly while minimising operational disruption, which is the correct framing for environments where enforcement error is consequential.
Graded B rather than A because no explicit human approval gate or enforcement simulation capability was described in located materials, unlike Ordr which documents simulating enforcement impact and showing blast radius before rules change.
Product architecture is clearly enumerated at the five-product level and the risk model inputs are named, covering device context, behavioural anomalies, vulnerability intelligence, business impact and exposure pathways. But no detection methodology, training data description, model detail or accuracy figures were located, and the language is consistently platform-level rather than technical.
The index's category editorial requires named detection methodologies rather than marketing language, and Armis sits below that bar relative to Cylera, which explains its Digital Twin mechanism, and Bluesight, which names unsupervised learning explicitly.
The document set here is the most complete in this lane and its accessibility is what keeps it from the top grade. Two dedicated documents exist, an artificial intelligence disclosure covering the platform and a separate data privacy and security statement for the assistant, which is more than any peer assessed here provides and reflects a company that has treated the artificial intelligence layer as raising its own questions rather than folding it into a general security page.
Alongside them sit certification specifically covering personal data held in cloud environments, a named data privacy officer, published sub processors, documented data erasure as a control, access monitoring and a separately maintained production environment, with the infrastructure provider named. Published sub processors plus a named cloud is the artifact this axis asks for.
Held below the top grade because the substance sits behind an access request, so a buyer cannot read the artificial intelligence privacy statement or establish the retention position before engaging with sales, and a document that exists but cannot be read before commitment does less work than one that can.
Nothing published addresses what device or network attributes are captured from a hospital environment specifically, which is the material question given the platform works by observing clinical network activity. Obtain both artificial intelligence documents early, and confirm retention and residency in contract rather than from the portal.
The strongest analyst validation in this category, though not healthcare-specific. Named a Leader in the 2026 Gartner Magic Quadrant for CPS Protection Platforms for the second consecutive year among 13 evaluated vendors, and recognised in the companion Critical Capabilities report which scores product functionality across four use cases.
Gartner Peer Insights carries 119 reviews in the CPS category at 4.7 out of 5 as of March 2026, with 267 ratings across all markets, which is substantial independent customer feedback. Graded B rather than A for two reasons: the recognition is for CPS protection broadly rather than medical device security specifically, so it does not establish healthcare depth, and peer reviews include a substantive criticism that OT and CPS protocol understanding is basic rather than top tier with limited ability to alert on true OT-specific threats. No healthcare outcome data or KLAS healthcare ranking was located, unlike Asimily and Ordr.
Structurally strong, and unusually the AI dimension is addressed directly. Two dedicated documents exist, an AI disclosure covering the platform and a data privacy and security statement for the AI assistant, sitting alongside ISO/IEC 27018:2019 certification for personal data held in cloud environments, a named data privacy officer, published subprocessors, employee privacy training, data erasure as a documented control, access monitoring and a separately maintained production environment.
Amazon Web Services is named as the infrastructure provider. Held below the top of the band because the substance sits behind an access request, so a buyer cannot evaluate the AI privacy statement or the retention position before engaging. No retention period is published, and nothing addresses what device or network attributes are captured from a hospital environment specifically, which is the material question given the platform works by observing clinical network activity. Worth obtaining both AI documents early and confirming retention and residency in contract.
The absence is conspicuous rather than incidental. The trust center lists fifteen compliance programmes and carries sector specific assurance for almost every market the company serves: federal government through FedRAMP Moderate and Department of Defense Impact Level 5, state government through TX-RAMP, automotive through TISAX, Spanish public sector through the ENS scheme, and higher education through completed HECVAT questionnaires.
Healthcare is the one vertical with no corresponding entry. Neither HIPAA nor HITRUST appears anywhere, and no business associate agreement is mentioned. General privacy infrastructure is present, including a named data privacy officer, published subprocessors, employee privacy training and ISO/IEC 27018 for personal data in cloud environments, so this is not an absence of privacy governance. It is specifically the healthcare frame that is missing, from a vendor that sells into hospitals. Worth asking whether a BAA is offered, and whether the company takes the position that monitoring device network activity places it outside HIPAA entirely.
The deepest published security programme in this category. Fifteen compliance items are listed, including ISO/IEC 27001 with its statement of applicability, ISO/IEC 27017 and 27018 for cloud and cloud held personal data, ISO/IEC 42001:2023, SOC 2, FedRAMP Moderate, DoD Impact Level 5, TX-RAMP Level 2, C5, CSA STAR Level 1, Cyber Essentials, the Spanish ENS scheme, TISAX and a VPAT.
Both a penetration test report and a penetration test remediation report are offered, which is rarer than the certificates, alongside a software bill of materials, code analysis, data erasure, published subprocessors, cyber insurance, a named data privacy officer and a security operations centre.
The trust center also carries a running advisory feed in which the company states its own exposure to third party vulnerabilities and supply chain incidents, including one affecting a vendor it used. Two limits: the SOC 2 type is not specified in the public listing, and documents require an access request. Worth confirming the SOC 2 is Type 2.
This is a security platform rather than a medical device, so it holds no FDA clearance and requires none, and the grade should be read against the frameworks that actually govern procurement here. On that basis the position is strong.
FedRAMP Moderate and Department of Defense Impact Level 5 are rigorous federal authorisations directly usable by federal health systems, and TX-RAMP Level 2 is the state cloud authorisation Texas public institutions require, which makes both immediately relevant to a subset of US health system buyers rather than merely adjacent. A software bill of materials is maintained, and published advisories reference federal directives when assessing the company's own exposure.
Held below the top of the band because the healthcare regulatory frame itself is unaddressed. Nothing published maps the platform to federal medical device cybersecurity requirements, health sector cybersecurity performance goals, or recognised health industry practices, which is what a hospital security team is being measured against.
The strongest structural AI governance position found in this index to date. The company holds ISO/IEC 42001:2023 certification, the international management system standard for artificial intelligence, listed among its compliance certifications rather than claimed in marketing. It also maintains a dedicated AI section in its trust center containing a platform AI disclosure and a separate data privacy and security statement for the AI assistant.
Very few vendors in any category hold an audited AI management system, and fewer still publish AI specific documentation as a distinct category. Held below the top of the band for two reasons. The documents are gated behind an access request, so the certification is verifiable but its substance is not.
And the fairness half of this axis is unanswered: for a device security platform the relevant question is whether classification accuracy varies across device types, manufacturers or clinical environments, and no performance breakdown of that kind is published. Worth requesting the AI disclosure and asking for classification accuracy by device class.
Two passes located no detection methodology, no training data description, no model detail, no accuracy or false positive figures and no warranty, indemnity or remediation commitment. The product architecture is clearly enumerated at the level of its five products and the risk model inputs are named, covering device context, behavioural anomalies, vulnerability intelligence, business impact and exposure pathways, so a buyer can see what goes in.
Nothing describes how those inputs are combined, weighted or validated, and the language stays platform level rather than technical throughout. The grade reflects the company it keeps rather than an abstract standard, and that comparison is the fair way to read it.
Three peers assessed in this same lane explain their mechanisms precisely: one sets out why device emulation is necessary and how it works, another names unsupervised learning and explains why simpler statistics fail, a third names its public data sources individually. Against that, a platform level description is a choice rather than a constraint of the category, and this vendor is larger than all three.
The cascading consequence recorded elsewhere applies here too, since device context feeds a risk rating which feeds an exposure judgement, and an error at the first step propagates while each stage looks independent. Ask for classification accuracy, the false positive rate, and how the risk model weights its named inputs.
Integration into enterprise security workflows is the platform's stated design principle, replacing fragmented point solutions with a single contextualised view spanning IT, OT, IoT, IoMT, cloud and code, and peer reviewers specifically credit smooth integration with existing security tooling and a multitude of available data sources. Breadth of asset class coverage in one platform is the differentiator against healthcare-only competitors.
The pending ServiceNow acquisition is directly relevant to this axis, since deep integration with the dominant enterprise ITSM and workflow platform would be a substantial interoperability advantage if realised, and buyers should factor that into a multi-year view.
The most flexible deployment position in this category. Armis offers on-premise, cloud AND hybrid options, explicitly so organisations can align the platform with their own infrastructure strategy while retaining a consistent security model. That materially exceeds the cloud-only posture of Asimily, Ordr and Cylera, and gives healthcare organisations with data sovereignty or residency constraints a genuine choice, which otherwise only Circle CVI provides in a different category. No specific residency terms located, but the architectural options themselves resolve most of the concern.
No pricing published and no pricing basis disclosed. The five-product platform structure means a healthcare buyer needs to establish whether Medical Device Security can be licensed independently or requires broader platform adoption, and that is not public. Independent analysis in this category has noted that enterprise configuration costs for major platforms can be very high, so the variance is material and undisclosed.
The broadest coverage of any vendor in this category, spanning IT, OT, IoT, IoMT, cloud and code assets across healthcare, manufacturing, energy, critical infrastructure and government, delivered through five products covering asset management, OT and IoT security, medical device security, vulnerability prioritisation and early warning.
For a health system that also operates industrial plant, building management systems and conventional IT, a single platform covering all of it is a genuine consolidation argument. The trade-off is the one this record flags throughout: breadth is bought at some cost in healthcare-specific depth relative to Cylera or Asimily.
Compared With
Each comparison carries a written verdict, the buyer conditions that favor each vendor, and a graded side by side. Pairs that cross a category boundary are grouped separately, and their verdicts state where the boundary sits rather than manufacturing a head to head.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | BAA Tier | Implementation | Source |
|---|---|---|---|---|
|
Not published
|
Undisclosed. Five-product platform; confirm whether Medical Device Security licenses standalone. Pending ServiceNow acquisition H2 2026 may affect future packaging. | — | — | Third Party Estimated |
No pricing published and no pricing basis disclosed. The platform structure is the first thing a healthcare buyer must resolve: Armis Centrix comprises five products, Asset Management, OT/IoT Security, Medical Device Security, ViPR Pro and Early Warning, and whether Medical Device Security can be licensed standalone or requires broader platform adoption is not public.
That determines whether Armis is competing on price against healthcare-only vendors such as Cylera and Asimily, or is a larger platform purchase justified by consolidating other security tooling. The consolidation case is the real commercial argument here, and it is legitimate: a health system that also runs building management systems, industrial plant and conventional IT may replace several point solutions with one platform, which changes the comparison entirely.
Buyers should model total tooling displaced rather than comparing licence to licence. Deployment flexibility also has cost implications worth surfacing, since on-premise deployment shifts infrastructure cost to the customer while cloud does not, and Armis is unusual in this category in offering both plus hybrid. THE TIME-SENSITIVE POINT: Armis has announced a planned acquisition by ServiceNow expected to complete in the second half of 2026.
Buyers negotiating now should seek explicit contractual continuity on pricing, product roadmap and support terms surviving the transaction, and should consider whether future packaging alongside ServiceNow licensing could change the economics. The company states it will continue operating with the same mission and innovation strategy, but that is a forward-looking statement rather than a contractual commitment.