Why Application Security Testing Isn’t Disappearing — and How Veracode is Shaping What Comes Next

Application security testing (AST) is the practice of scanning software for vulnerabilities using static, dynamic, and component-level analysis – then managing those flaws through remediation, validation, and certification. A new independent report from FOURCASTERS and Lionfish Tech Advisors confirms that AST is not becoming obsolete. AI and cloud platforms are changing how testing gets delivered, but the need for independent testing, flaw lifecycle management, and validation has only grown. Veracode sits at the top of the report’s PYRAMID™ ranking, one of only three vendors to reach that tier.

Is Application Security Testing Becoming Obsolete?

No. Application security testing is not becoming obsolete, despite years of predictions that cloud platforms and AI would replace it.

For the last few years, a familiar narrative has made the rounds in security circles: AST is dying. Cloud platforms were supposed to absorb it. AI was supposed to make it unnecessary. The old combo of static, dynamic, and component scanning was declared dead.

The new FOURCASTERS and Lionfish Tech Advisors AST Market Overview and PYRAMID™ Buyer’s Guide 2026 pushes back hard. The rumors of AST’s demise, as the report puts it, “have been seriously incorrect.”

The reality is different. And it explains why Veracode is one of three leaders at the very top of the pyramid.

Does AI Replace the Need for Application Security Testing?

AI makes application security testing more necessary, not less. AI helps developers write more code faster, but it still can’t reliably produce flaw-free code. More code means more surface area for vulnerabilities… and a greater need for independent testing.

The logic behind “AI will replace testing” sounds reasonable on the surface. If AI can write code and fix flaws, who needs scanners?

The report dismantles that argument. AI is helping developers produce more code at higher velocity, but it still can’t reliably produce flaw-free code. The need for testing has only become more pressing.

There’s a deeper point worth pausing on. The same AI system used to create code can’t be used to fix it and shouldn’t be treated as an independent security control. Even the best AI fix produces a code change, but that change still needs validation before anyone can call the flaw resolved.

Finding is not fixing. Fixing is not validation. That redundancy is the foundation of a real testing program, and AI doesn’t change that.

Do Cloud Platforms (CNAPP) Replace Application Security Testing?

No. Cloud security platforms add context and prioritization on top of testing, but they still depend on testing technologies underneath for detection, flaw identity, and validation. The report excluded CNAPP vendors from its research because they can’t yet deliver the full components needed to establish and support the organizational function that an application security program provides.

Cloud security vendors pitch an end-to-end solution where testing is just a small piece of a larger platform. The report is blunt about this: pulling in results from testing vendors or having a few scanning types inside a platform “is not an application security program.”

Posture management tools add value when they accurately correlate findings across tools. But that’s substantially harder than it sounds. The same flaw can show up in multiple places. Normal code changes can move or alter a flaw without changing the underlying issue. Different tools describe the same defect differently. Get the matching wrong and resolved findings come back as new noise, or worse, an old risk decision gets attached to a genuinely new finding.

A control layer on top may become where risk is viewed and prioritized. But it still depends on testing technologies underneath for detection, identity, and validation. The engines and the program underneath aren’t replaced. They’re essential.

That’s why the report excluded cloud platform vendors from the research entirely. They’re not there yet.

What Does It Take to Be a Leader in the AST Market?

THE PYRAMID™ requires vendors to offer seven components: static analysis, dynamic analysis, component analysis, reporting and trending, secure code training, remediation assistance, and pentesting services.

Vendors offering one or two testing types, or lacking the completeness and scale to support a real program, are excluded. Posture management capabilities alone don’t qualify a vendor unless they also deliver the underlying testing and program capabilities the research requires.

A successful program goes beyond scanning. Flaws must be assigned, owned, fixed, certified, or accepted and recertified. Secure coding is a program, not a feature. Organizations need to show how they’re doing and that they’re improving over time. These are business functions, not scanner features.

Why Is Veracode at the Top of the AST Pyramid?

Veracode is one of only three vendors – alongside Snyk and Checkmarx – to reach the top tier of THE PYRAMID™. The placement reflects Veracode’s completeness across all seven required components: testing, lifecycle management, training, remediation, and proof of progress.

The report specifically names Veracode among the vendors providing posture management capabilities through acquisition, internal development, or both. That matters because the market is moving toward a broader, more continuous function than the old static-dynamic-component combination. Veracode is already there.

What the report says matters most is the full flaw lifecycle. Finding flaws is the easy part. The hard part (that determines whether a program actually works) is managing flaws through assignment, ownership, remediation, certification, and recertification, all while keeping the right history attached to the right finding over time. That’s where development and security cooperate. It’s where programs succeed or fail.

Veracode’s platform is built for exactly that lifecycle. Independent testing. Validation that a fix actually resolved the issue. Reporting and trending that prove the program is improving. Secure code training that treats developer education as a program pillar, not a checkbox. AI-assisted remediation that reduces security debt without abandoning the independent validation layer the report calls non-negotiable.

What Is Security Debt and Why Does It Matter?

Security debt is the accumulation of unresolved vulnerabilities in software applications over time. As applications age, unresolved flaws compound and eventually can become the reason a breach succeeds. Reducing security debt is a critical capability for any application security program.

The report notes that testing vendors have introduced AI to help find flaws and fix code involved in common vulnerabilities, and calls reducing security debt “a very desirable addition for any program as part of the vendor selection process.”

Veracode delivers AI-assisted remediation that targets exactly this problem. The key is that it does so without abandoning the independent testing and validation layer the report insists is non-negotiable.

How Is the Application Security Testing Market Evolving?

The AST perimeter is expanding. API testing, software supply-chain security, secrets detection, infrastructure-as-code testing, runtime context, and automated remediation are increasingly part of the conversation. The direction is toward a more continuous, always-on model where testing, prioritization, remediation, and validation happen throughout the development lifecycle.

Higher development velocity, AI-generated code, and increasingly automated remediation are making fragmented, periodic testing less practical. The need for testing doesn’t go away. Its frequency and operation change.

This shift favors vendors with the breadth and program-level depth to handle continuous, integrated testing at scale. It favors vendors that can deliver the full lifecycle — not just a scanner, not just a dashboard, but the complete business process of identifying, owning, and resolving application risk.

That gap separates the top of the pyramid from everyone else. And it’s where Veracode leads.

The Bottom Line

As AI accelerates code production without eliminating flaws and cloud platforms add context without replacing independent testing, the AST layer becomes even more important. The vendors that win will be the ones that deliver the complete program: testing, lifecycle management, training, remediation, and proof of progress.

THE PYRAMID™ puts Veracode at the top for a reason. The question for security and engineering leaders isn’t whether to invest in application security testing. It’s whether to choose a point solution or a complete program.

Download the full FOURCASTERS and Lionfish Tech Advisors AST Market Overview and PYRAMID™ Buyer’s Guide 2026 to see the complete vendor landscape, methodology, and positioning analysis. The report breaks down exactly what separates true program providers from the rest — and why that distinction matters for any organization serious about application security.

Download the full report →

Frequently Asked Questions

Why isn’t application security testing going away despite AI and cloud platforms?

AI produces more code at higher velocity but can’t reliably produce flaw-free code. More code means more vulnerabilities, making continuous testing[RR6]  more pressing. Cloud and posture management platforms add context but still depend on testing technologies underneath for detection and validation. None of these developments eliminates the need to independently identify flaws, assign ownership, fix or accept risk, validate results, and demonstrate program improvement over time.

Can AI automatically find and fix all vulnerabilities?

No. The same AI system used to create code shouldn’t be used to fix it and shouldn’t be considered an independent security control. Even the best AI fixes produce a code change that requires validation before the flaw can reliably be considered resolved. Finding is not fixing, and fixing is not validation.

What’s the difference between scanning tools and an application security program?

Pulling in results from testing vendors or having a few scanning types inside a platform is not a program. A successful program is an organizational function that requires[RR7]  that flaws are assigned, owned, fixed, certified, or accepted and recertified. It includes secure code training, reporting, trending, and remediation assistance — demonstrating how the organization is improving over time.

Why was Veracode placed at the top of THE PYRAMID™?

THE PYRAMID™ includes only vendors that offer all seven required components: static and dynamic analysis, component analysis, reporting and trending, secure code training, remediation assistance, and pentesting services. Veracode appears at the top alongside Snyk and Checkmarx, reflecting the breadth and depth of its program-level capabilities.

Should organizations consolidate security tools into a single cloud platform?

The report suggests caution. Cloud platform vendors are not yet able to provide the necessary components that make up the testing segment — which is why they were excluded from the research. Posture management capabilities alone are insufficient unless the vendor also provides the underlying testing and program capabilities required. The testing function itself is not becoming obsolete.

What is posture management and why does flaw correlation matter?

Application security posture management (ASPM) correlates security findings across tools and contexts. Accurate correlation is substantially harder than simply normalizing results. The same flaw can appear in multiple locations, code changes can move flaws, and different tools describe the same defect differently. Poor matching can recreate resolved findings as new noise — or attach an old risk decision to a genuinely new finding.

How does Veracode handle the expanding testing perimeter?

The testing perimeter now includes API testing, software supply-chain security, secrets detection, infrastructure-as-code testing, runtime context, and automated remediation. Veracode is specifically named among the vendors providing posture management capabilities through acquisition, internal development, or both — moving toward the broader, more continuous function the market demands.

What does reducing security debt mean?

Security debt is the accumulation of unresolved vulnerabilities as applications age. Reducing it directly addresses the backlog of flaws that grows over time. The report calls reducing security debt “a very desirable addition for any program as part of the vendor selection process.” Veracode delivers AI-assisted remediation to reduce this debt while maintaining independent validation that fixes actually worked.