The next evaluation in this category is planned, and for the first time in Forrester's coverage of this market, it will not rank anyone. The report coming is a Landscape, not a Wave: The Web Application Protection Platforms Landscape, Q3 2026. It is the first evaluation under the new name, and it was announced in a blog post whose title doubles as an obituary: "Move Over WAF. The Web Application Protection Platform Takes Over."
The obituary ran under a friendly headline. Sandy Carielli, the VP, Principal Analyst who has carried Forrester's web application security research since the Q3 2022 Wave, wrote it in June 2026 to say what the market had already done. WAF stopped being a standalone capability. Modern applications are APIs, microservices, third-party scripts, and cloud components, not monolithic sites behind a perimeter. Attackers moved to API abuse, automated fraud, bot-driven business logic attacks, and client-side compromise. Vendors had already rebuilt their WAFs into platforms. Forrester is now renaming the category to match.
The name change that was already true
The vendors renamed the category in their roadmaps years before Forrester renamed it in the catalog.
Forrester's own Q1 2025 Wave citations show it. Cloudflare, a Leader, was described as "a strong option for customers that want to manage an easy-to-use, unified web application protection platform that will continue to innovate." Unified web application protection platform. In a report still titled Web Application Firewall Solutions. Akamai's App & API Protector, evaluated as a WAF, has combined WAF, bot mitigation, API security, and DDoS protection in one solution since the 2022 edition. The 2025 scorecard was the new category wearing the old name.
What Forrester is doing in Q3 2026 is catching the catalog up to the product sheets. The planned Landscape defines web application protection platforms as unified, integrated solutions that examine input to and responses from web applications, mobile apps, and APIs. They filter application traffic per policy, detect and block application, volumetric, and business logic attacks, and enforce policy through signatures, protocol standards, and anomaly detection. The capability list now spans core WAF, API discovery and security, bot management, Layer 7 DDoS mitigation, client-side and third-party script protection, and emerging AI runtime security. A firewall filters traffic. A platform reads a whole attack surface.
The final WAF Wave: The Forrester Wave: Web Application Firewall Solutions, Q1 2025
Until the new Landscape lands, the operative scorecard is the last Wave under the old name, published Q1 2025: ten vendors, twenty two criteria, across current offering and strategy.
The Leaders were Cloudflare, Akamai, and Imperva.
Cloudflare took the highest score in current offering and five-out-of-five marks in fifteen criteria, including detection models, DevOps and scanning integrations, infrastructure-as-code support, policy automation, Layer 7 DDoS protection, security operations integrations, and product security. Forrester says it "stands out with features that help customers work more efficiently."
Akamai earned the highest possible scores in vision, roadmap, detection models, pricing flexibility and transparency, Layer 7 DDoS protection, and data leak prevention. Reference customers "loved Akamai's detection capabilities and appreciated how easy it is to automate functionality." Forrester also noted a lag in DevOps and scanning integrations.
Imperva took maximum scores in innovation, roadmap, and adoption. More than ninety percent of its Cloud WAF customers run in blocking mode, a figure the report connects to near-zero false positives, automated policy creation, and rapid rule updates. Imperva is now part of Thales, which acquired it in late 2023.
The Strong Performers were F5, cited for built-in web application scanning and strong API security, Fastly, cited for a developer-focused vision and pre-deployment rule testing while still building out API security, and Radware, cited for AI-assisted SOC tooling and tunable detection. Fortinet sat in the Contender tier, strong on API security and pricing, weaker on roadmap depth. Amazon Web Services, Microsoft, and Google completed the field of ten.
Notice what the 2025 tiers actually measure. Detection models, API security, bot and DDoS integration, policy automation, DevOps integrations. The criteria read like a platform checklist. The WAF name was already cosmetic.
The 2022 edition and the Log4Shell detail
One detail from the earlier edition explains why the market moved, and why buyers let it.
The Forrester Wave: Web Application Firewalls, Q3 2022, authored by Sandy Carielli, evaluated twelve providers across twenty four criteria spanning current offering, strategy, and market presence. Cloudflare and Akamai led, with Imperva also in the Leader group. Cloudflare took the highest strategy score and maximum marks in ten criteria. Akamai took the top score in attack detection and the highest current-offering mark, with Forrester describing a threat research team "that numbers in the hundreds."
Then there is the Log4Shell line. Forrester credited Cloudflare with protecting all of its customers against Log4Shell through managed rules in under seventeen hours, globally, via virtual patching. Seventeen hours from disclosure to protection, globally.
That number is the reason WAF became a platform. A rule set alone did not do that. A distributed network, a managed rule pipeline, automated deployment, and a team watching the threat feed did. The product that produced seventeen hours is not the product the word firewall describes. It is infrastructure. The 2026 rename is the industry finally writing that down.
What the Landscape will and will not do
The planned Q3 2026 Landscape is worth understanding precisely, because buyers are already planning around it.
A Landscape names the field. A Wave ranks it. The coming report will map the market, its segments, and its use cases. It will not produce tiers, scores, or Leaders. Buyers waiting for the Landscape to tell them who to shortlist are waiting for a map, not a verdict. The verdict instrument for this category is the Q1 2025 Wave, which is aging, and the next Wave under the new name has not been announced.
The Landscape arrives with a supporting report already published: The Rise of Web Application Protection Platforms, which makes the consolidation case. Forrester's blog relays a representative detail from a security architect at a multinational telecom: roughly seventy percent savings from consolidating separate WAF, anti-DDoS, and load-balancing tools onto one platform. Consolidation is the product now. The single vendor, the single pane of glass, the single correlation dataset. That is what the new category sells, and what the Landscape will map.
The capability Forrester already excluded
The honest gap in the new category is visible in its own definition.
Forrester states plainly that bot and agent trust management, including AI agent trust, is not typically included in these platforms today. Read that sentence twice. The category renamed itself for a threat model where bots and AI agents are the attackers and the users. And the definition of the category excludes the capability that decides whether an automated visitor is a friend or a fraud, before the first evaluation under the new name is even published.
AI runtime security makes the same point from inside. It is listed as an emerging component, not a core one. The platform category is being built one threat generation behind the threats. That is normal for analyst research. It is still the single most important line for a buyer to read in the announcement, because it tells you what the Landscape will not score, and what you will have to diligence on your own.
The adjacent scorecard: Gartner's WAAP quadrant
Gartner made the same move earlier, and it is worth knowing both catalogs when you shop.
Gartner retired its Magic Quadrant for Web Application Firewalls and replaced it with the Magic Quadrant for Web Application and API Protection, the WAAP name the market now uses on Gartner's side. Two analyst firms, working from the same market signals, both concluded that the firewall name no longer described the product. The Forrester category is the platform framing of the same shift. A buyer running a Forrester shortlist and a Gartner shortlist is now comparing a platform definition against a WAAP definition, which overlap heavily but are not identical, and neither is a WAF definition anymore.
Forrester's framing adds client-side protection and AI runtime security explicitly. Gartner's framing centers the API. When the new Forrester Landscape lands, the productive exercise is not reading it alone. It is putting it next to the WAAP quadrant and marking the criteria each one excludes, because those exclusions are where your unmanaged risk will live.
Three questions while the Landscape is pending
The planned report gives buyers time. Use it on these three questions instead of waiting.
One: what are you actually consolidating? The platform promise is one vendor, one pane, and real savings, the telecom architect's seventy percent is the anecdote every vendor will cite. Map your own stack first: WAF, bot management, API security, DDoS, client-side protection, and price the consolidation against the lock-in. The savings are real and so is the dependency.
Two: which 2025 criteria still matter to you? Detection, DevOps and scanning integrations, API security, pricing transparency. The Q1 2025 Wave remains the operative ranking until the Landscape and any future Wave publish. Use it, but date it: client-side protection and AI runtime security have moved since Q1 2025, and they moved toward exactly the capabilities the new category names.
Three: who covers agent trust? Forrester's own definition says bot and agent trust management is not typically included in these platforms today. If AI agents are hitting your applications in 2027, that question decides your stack more than any scorecard from 2025 will. Ask every vendor on your list, including the ones the upcoming Landscape will feature.
The supply-chain half of the application security stack this platform sits beside is scored separately in Software Composition Analysis, where the category's longtime leader changed ownership six weeks before Forrester's newest scorecard published.
Analyst Source
Forrester Research
This article draws on Forrester's web application security research. The Web Application Protection Platforms Landscape, Q3 2026, is planned and not yet published; it was announced in the June 3, 2026 blog post "Move Over WAF. The Web Application Protection Platform Takes Over" by VP, Principal Analyst Sandy Carielli, and follows the supporting report The Rise of Web Application Protection Platforms. Forrester defines web application protection platforms as unified, integrated solutions that examine input to and responses from web applications, mobile apps, and APIs, filtering traffic and detecting and blocking application, volumetric, and business logic attacks. The category replaces the WAF framing scored in The Forrester Wave: Web Application Firewall Solutions, Q1 2025 (ten vendors, twenty two criteria) and The Forrester Wave: Web Application Firewalls, Q3 2022 (twelve vendors, twenty four criteria). Gartner covers the adjacent market as the Magic Quadrant for Web Application and API Protection.
Source research
- Move Over WAF. The Web Application Protection Platform Takes Over (Forrester blog, Sandy Carielli)
- The Rise of Web Application Protection Platforms (RES187552)
- The Forrester Wave: Web Application Firewall Solutions, Q1 2025
- The Forrester Wave: Web Application Firewalls, Q3 2022
- Cloudflare press release: named a Leader in The Forrester Wave: Web Application Firewalls, Q3 2022
- Akamai blog: named a Leader in The Forrester Wave: Web Application Firewalls, Q3 2022
Forrester does not endorse any vendor named here, and tier placement should not be read as a recommendation to buy.