Skip to content
CIS Excellence AwardsEst. 2018 · San Francisco

Vol. IX · 2026 Cycle · Edition 01

CIS Excellence Awards

Recognizing the people, projects, and partnerships redefining Customer Identity & Access Management worldwide.

The peer-judged standard for CIAM & IAM — a mark of credibility boards, buyers, and the market already recognize.

  • 1,8472025 Submissions
  • 38Countries
  • 22Categories
  • 41Judges
An editorial photograph of a bronze CIS Excellence Awards seal resting on a folded program booklet with a fountain pen and navy ribbon.
The 2026 Edition Seal · Bronze on cream paper

Why CIS Excellence Awards

The only peer-judged recognition dedicated to CIAM — and the mark boards already recognize.

Generic cybersecurity awards treat identity as a sub-category. Customer Identity & Access Management is its own discipline, with its own architecture, its own threat model, and its own buyer. The CIS Excellence Awards exists because IAM programs deserve a defensible, peer-judged standard — not a sidebar trophy.

Founded in 2018 by former KuppingerCole and Gartner identity-security analysts, the program is now in its ninth cycle. The taxonomy covers CIAM, workforce IAM, privileged access, decentralized identity, and identity threat detection — the deepest category structure in dedicated IAM awards. Every finalist is independently benchmarked against the CIS Excellence Framework, a 142-criterion maturity model.

Winners receive a verifiable digital badge backed by cryptographic proof-of-award, recognized as a qualifying credential by (ISC)² for 12 CPE credits toward CISSP recertification, and cited in enterprise procurement shortlists as an independent selection criterion.

What Sets the Program Apart

Four structural reasons CIS is a defensible mark of credibility.

Not a marketing badge. A peer-judged, framework-benchmarked, annually audited recognition that enterprise buyers, boards, and procurement teams already reference.

  1. A 41-member CISO & architect panel, audited by Deloitte.

    Every judge is a practicing CISO or identity architect from a Fortune 500 enterprise, 100% CISSP or CIAM-certified. The panel is refreshed 25% annually for independence, and the full roster and methodology are audited each year by Deloitte.

    41 judges · 100% certified · 25% annual refresh

  2. The 142-criterion CIS Excellence Framework.

    Every finalist is independently benchmarked against the CIS Excellence Framework — a 142-criterion maturity model covering CIAM, workforce IAM, privileged access, decentralized identity, and identity threat detection. The framework is referenced by Gartner as a maturity reference and used by enterprise IAM teams for internal program assessment.

    142 criteria · 22 categories · referenced by Gartner

  3. Cryptographic proof-of-award badges.

    Winners receive a verifiable digital badge backed by cryptographic proof-of-award, preventing the badge-fraud common in vendor-run programs. Badges are independently checkable and embed submission cycle, category, and jurisdiction — a trust artifact procurement teams can verify without contacting the program office.

    Cryptographic · independently verifiable · audit-trail embedded

  4. 1,847 submissions across 38 countries in 2025.

    The 2025 cycle recorded 1,847 submissions from 38 countries — up 62% year-over-year — making it the largest dedicated IAM awards field on record. Coverage spans CIAM, workforce IAM, privileged access, decentralized identity, and identity threat detection, the deepest taxonomy in the dedicated IAM awards category.

    Largest dedicated IAM field · +62% YoY · 38 countries

A bronze CIS Excellence Awards medallion resting on an open framework document, beside a leather notebook and a brass seal stamp.
The CIS Excellence Framework · 142 criteria, 22 categories, audited annually.

The 2025 Cycle · At a Glance

The largest dedicated IAM awards field on record.

1,847
Submissions received in the 2025 cycle — up 62% year-over-year.
38
Countries represented across every inhabited continent.
22
Categories spanning CIAM, workforce IAM, privileged access, and decentralized identity.
41
Judges on the final-round panel — 100% CISSP or CIAM-certified.

Independently audited by Deloitte. Recognized as Cybersecurity Recognition Program of the Year at the 2024 Cybersecurity Excellence Awards.

The Taxonomy · 22 Categories in Six Families

A complete map of identity-security work, judged on outcomes.

Every finalist — across all six families and twenty-two categories — is independently benchmarked against the CIS Excellence Framework, a 142-criterion maturity model referenced by Gartner analysts and used by practitioners as the working standard for CIAM and IAM program measurement.

01

Customer Identity & Access Management

The CIAM family covers consumer-facing identity programs: registration and verification, progressive profiling, consent and preference management, social login, and customer journey analytics at enterprise scale.

  • Best Consumer Onboarding Flow
  • CIAM Program of the Year
  • Customer Data Privacy & Consent
  • Authentication Innovation
8 categories
02

Workforce Identity & Access

The workforce family covers employee, contractor, and B2B identity — covering SSO, identity governance, joiner-mover-leaver processes, and the operational integration of HRIS, ITSM, and identity fabric platforms.

  • Workforce IAM Program of the Year
  • Identity Governance & Administration
  • B2B & Partner Identity
  • Hybrid Directory Modernization
6 categories
03

Privileged Access & Identity Threat Detection

Two tightly related families covering standing and just-in-time privilege, secrets management, session recording, and the emerging discipline of identity threat detection and response (ITDR) against credential-based attacks.

  • PAM Program of the Year
  • ITDR Implementation of the Year
  • Secrets Management Excellence
  • Insider Risk Mitigation
5 categories
04

Decentralized Identity, Verifiable Credentials & Special Recognition

The forward-looking family covers verifiable credentials, wallets, decentralized identifiers, and issuer trust frameworks — alongside annual special-recognition categories for individual leadership, lifetime contribution, and rising-team honors.

  • Decentralized Identity Deployment
  • Verifiable Credential Innovation
  • CISO of the Year
  • Rising IAM Team of the Year
3 categories

Coverage spans CIAM, workforce IAM, privileged access, decentralized identity, and identity threat detection — the deepest taxonomy in the category.

View the full 22-category taxonomy →

The Methodology · Judging Architecture

Forty-one practitioners. One hundred forty-two criteria. One auditable standard.

A documentary-style photograph of a judging-room long table with paper dossiers, name plates, and architectural glass windows overlooking the San Francisco skyline.
The final-round deliberation room, San Francisco · 2025 cycle.

The Panel — Composition & Certification

The final-round panel comprises forty-one practicing CISOs and identity architects from Fortune 500 enterprises. Every judge holds an active CISSP or CIAM certification, and the panel is refreshed by twenty-five percent each cycle to preserve independence. Members serve staggered two-year terms and are recused from any submission originating from their own organization or sector.

  • 41judges on the final-round panel
  • 100%CISSP or CIAM-certified
  • 25%annual refresh for independence
  • 0judges employed by submitting vendors

The Framework — Scoring & Audit

Submissions are scored against the CIS Excellence Framework — a 142-criterion maturity model covering architecture, governance, user experience, security posture, measurable outcomes, and program maturity. Every finalist receives a benchmark report; the panel's aggregated scoring and panel-composition records are audited annually by Deloitte to attest to process integrity.

  • 142criteria across six scoring domains
  • 6scoring domains, weighted by category
  • AnnualDeloitte process audit
  • Finalistbenchmark report included for every entrant

Winners receive verifiable digital badges backed by cryptographic proof-of-award, preventing the badge-fraud common in vendor-run programs. The program is the official recognition partner of the Identity Management Institute and is endorsed by (ISC)² — winners earn twelve CPE credits toward CISSP recertification.