Cerby's $40M Series B Signals New IAM Budget Line for Unmanaged SaaS Access
Three funding rounds in 14 days—$72M total—force enterprises to treat non-human identities, IoT devices, and unmanaged apps as first-class IAM domains with separate budgets.
Cerby's $40M validates specialist identity automation for apps outside SSO
Cerby raised $40 million in Series B funding to scale its platform for managing access to SaaS applications not natively supported by major identity providers. The funding amount—substantial for a niche between core IAM and SaaS governance—means enterprises can no longer dismiss unmanaged app access as a feature gap their existing Okta or Microsoft Entra deployment will eventually close.
For buyers, this creates a new budget decision. Most large enterprises run dozens to hundreds of applications that cannot use SSO, either because the vendor does not support it or because the app predates modern federation standards. Traditional IAM suites cover these poorly or not at all, forcing security teams to accept shared credentials, manual password rotation, or shadow IT risk. Cerby's investor backing signals this gap is large enough to sustain a standalone category.
The competitive implication: if your IAM vendor claims comprehensive SaaS coverage, Cerby's existence—and funding level—provides a reference point for what "comprehensive" actually means. Buyers should map which applications fall outside their current IdP's connector library and calculate the risk or operational cost of that coverage gap. If the number is material, Cerby becomes either a complement to your core IAM stack or a negotiation lever to force your incumbent to prioritize those integrations.
Budget-wise, expect this to land as a line item under SaaS security or security operations rather than traditional IT-driven IAM budgets. That distinction matters for internal advocacy: the sponsoring executive and funding source differ, which changes the approval path and competing priorities.
Aembit's $25M Series A elevates non-human identity to peer status with workforce IAM
Aembit raised $25 million in Series A funding for workload-to-workload IAM—specifically, identity and access controls for non-human identities like services, APIs, and microservices. The funding level is at the high end for early-stage security companies and reflects investor belief that machine identity is a distinct segment, not a feature inside traditional PAM or secrets management.
For enterprises running Kubernetes, microservices, or multi-cloud architectures, this changes the IAM architecture discussion. Non-human identities now outnumber human users in most cloud-native environments, often by 10:1 or more. Breaches increasingly exploit service account keys, API tokens, and hard-coded credentials rather than compromised user accounts. Treating workload identity as an afterthought—managed ad hoc through cloud-native tools or secrets managers—leaves attack surface unaddressed.
The buyer decision: determine whether non-human IAM is handled by your existing IAM/PAM suite, absorbed into cloud security posture management platforms, or managed by a specialist like Aembit. Each approach has different cost structures. Traditional IAM vendors price per user, which breaks down when you have thousands of service identities. Cloud-native tools often bundle workload identity into broader platform licensing, which works until you need cross-cloud or legacy system coverage. Specialists price per workload or per service, which scales more predictably but adds vendor count.
This also affects compliance and governance. Identity governance programs built around user lifecycle management must now encompass service lifecycle, certificate rotation, token expiration, and API authorization. If your governance framework does not account for non-human identities, Aembit's funding—and the category it represents—is a signal to update it before auditors or breach costs force the issue.
Device Authority's $7M brings IoT identity into enterprise IAM budgets
Device Authority raised $7 million in Series A funding for IoT identity and access management. The round is smaller than the others but matters for industrial, healthcare, and critical infrastructure buyers who deploy large fleets of connected devices. IoT identity has historically been handled through PKI certificate management or device onboarding features inside broader platforms. Device Authority's funding indicates investor belief that IoT IAM is differentiated enough to justify a specialist vendor.
For buyers, this affects both architecture and compliance. Regulations increasingly require device-level identity controls—NIST guidance for operational technology, FDA requirements for connected medical devices, and sectoral mandates in energy and manufacturing all reference device authentication and authorization. Treating IoT as an extension of network security rather than identity management creates gaps that auditors will flag.
The budget implication: IAM line items traditionally cover users and applications. Devices are a third category with different licensing models—typically per-device or per-fleet pricing—and different integration requirements. IoT devices often cannot support modern authentication protocols, cannot be easily updated, and operate on isolated or air-gapped networks. This requires IAM solutions purpose-built for those constraints rather than expecting traditional user-centric IAM to stretch.
Compromised IoT devices are increasingly used as entry points in breaches, particularly in environments where operational technology and IT networks connect. Identity-based controls at the device level—rather than relying solely on network segmentation—reduce that attack surface. Device Authority's funding makes this mitigation strategy more credible by providing a funded vendor alternative to build-it-yourself or wait-for-the-platform approaches.
What to watch: IAM budgets fragment across use cases, not vendors
Three funding rounds totaling $72 million in two weeks point to the same trend: IAM is fragmenting by identity type rather than consolidating by vendor. Enterprises that assumed one IAM platform would eventually cover users, apps, workloads, and devices now face a different reality—specialist vendors are raising capital to own specific identity domains, and investors believe those niches are durable.
For buyers, this means IAM architecture and budgets must account for multiple identity types with different risk profiles, compliance requirements, and operational models. The alternative—forcing every identity type into a single platform—creates coverage gaps that attackers exploit or compliance failures that auditors penalize. The funding environment suggests the market has chosen specialization over consolidation, at least for the next 18–24 months.
Technology decisions, clearly explained.
Weekly analysis of the tools, platforms, and strategies that matter to B2B technology buyers. No fluff, no vendor spin.
