Skip to Content Facebook Feature Image

F5 Placed in the Leader Tier of the SecureIQLab 2026 Cloud WAAP v5.0 CyberRisk Validation Comparative Report

Business

F5 Placed in the Leader Tier of the SecureIQLab 2026 Cloud WAAP v5.0 CyberRisk Validation Comparative Report
Business

Business

F5 Placed in the Leader Tier of the SecureIQLab 2026 Cloud WAAP v5.0 CyberRisk Validation Comparative Report

2026-08-04 00:01 Last Updated At:00:10

SEATTLE--(BUSINESS WIRE)--Aug 3, 2026--

F5 (NASDAQ: FFIV), the global leader in delivering and securing every app and API, announced that F5 Distributed Cloud Web App and API Protection (WAAP), part of the F5 Application Delivery and Security Platform (ADSP), was placed in the Leader tier of SecureIQLab’s 2026 Cloud WAAP v5.0 CyberRisk Validation Comparative Report. F5 was one of a select few evaluated vendors to earn both the Secure-by-Design and Secure-by-Default certifications.

This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260803509155/en/

Enterprises buying application security products have long faced a trade-off. Some solutions stop sophisticated attacks but demand constant tuning and specialized staff to run. Others deploy easily but leave gaps that only surface after a breach. Security teams end up choosing which problem they would rather have.

The SecureIQLab evaluation measured both sides of the efficiency/efficacy trade-off. F5 was placed in the Leader tier of the CyberRisk Ripple—the report’s highest classification, reserved for solutions scoring in the top tier for protection and operations. F5 scored 92.7% Security Efficacy and 94.7% Operational Efficiency, exceeding the measured group averages of 86.8% and 93.8%, respectively.

“Frontier AI has made traditional security approaches untenable, compressing or inverting the time between vulnerability disclosure and working exploit,” said John Maddison, Chief Marketing Officer at F5. “Enterprises are protecting more applications, more APIs, and now more AI—and security that only works when you staff a skilled team around it isn’t security that scales.”

Today’s enterprises need a WAAP solution with virtual patching tools such as web application firewall (WAF) capabilities in front of the application—blocking exploitation on day one, without new signatures and without constant tuning. At the same time, modern organizations can’t afford to take any single vendor’s word for how well their solutions work. Security leaders benefit from independent testing to verify which tools sufficiently provide advertised protections.

Protection that holds up under test conditions

SecureIQLab subjected each solution to more than 1,600 attack scenarios spanning OWASP web application attacks, API attacks, bot and AI-assisted bot attacks, Layer 7 DoS and DDoS, security resiliency, and a WAAP vulnerability assessment, with legitimate traffic running throughout to measure false positive avoidance. Testing was AMTSO-compliant (Testing Protocol Standard v1.3) under AMTSO Test ID AMTSO-LS1-TP169 and executed on SOCx ®, SecureIQLab’s AI-Driven Cloud Security Validation Platform, to ensure consistent execution across vendors.

Operations without the drag

F5’s 94.7% Operational Efficiency score reflects an architecture designed to reduce work rather than create it. F5 Distributed Cloud WAAP fuses WAF, API security, bot defense, and Layer 3–4 and 7 DDoS mitigation into a single-pass inspection architecture, so traffic is decrypted and evaluated once rather than passing between loosely integrated products for inspection and enforcement. Platform teams can deploy and scale policy without stacking latency or configuration overhead, and the same battle-tested WAF engine runs across F5 Distributed Cloud Services, F5 BIG-IP Advanced WAF, and F5 NGINX solutions.

Security built in, not bolted on

The Secure-by-Design and Secure-by-Default certifications are awarded to solutions that do not expand the attack surface of the environments they protect and that deliver meaningful protection without additional configuration. Earning both requires a score above 85% in each category and a perfect 100% on the WAAP vulnerability assessment. F5 was one of five solutions to clear that bar.

F5 also scored above the group average on compliance, a category assessing how effectively a solution supports regulatory, data protection, audit, and governance requirements drawn from frameworks including NIST SP 800-53, the NIST AI Risk Management Framework, ISO/IEC 27001, ISO/IEC 42001, PCI DSS, GDPR, HIPAA, and SOC 2. In addition, F5 scored 100% on the OWASP LLM Top 10 subset in scope for v5.0, which covers two risk categories: Prompt Injection (LLM01:2025) and Improper Output Handling (LLM05:2025). Testing also included 35 benign test cases to measure false positives.

“The cloud WAAP market has matured significantly. The group average security score rose roughly 12.3% over the previous edition of this test, and for the first time we scored AI application security as its own category, because that is where the attack surface is expanding,” said David Ellis, VP of Research, SecureIQLab. “Solutions placed in the Leader tier demonstrated coverage across web application, API, advanced threat, and AI-enabled application attacks.”

Supporting materials

About the SecureIQLab evaluation

SecureIQLab tested the products named in the Cloud WAAP v5.0 CyberRisk Validation Comparative Report on the dates listed in the report methodology section. SecureIQLab does not endorse, certify, warrant, or guarantee the performance or safety of any tested product. Test results reflect performance under the specific methodology and scenarios in that section only. The findings referenced in this release apply to the specific product versions, deployment configurations, and test scenarios listed in the report. Performance under other versions, configurations, or scenarios is not implied. Past performance is not a forecast of future results.

About F5

F5, Inc. (NASDAQ: FFIV) is the global leader that delivers and secures every app. Backed by three decades of expertise, F5 has built the industry’s premier platform—F5 Application Delivery and Security Platform (ADSP)—to deliver and secure every app, every API, anywhere: on-premises, in the cloud, at the edge, and across hybrid, multicloud environments. F5 is committed to innovating and partnering with the world’s largest and most advanced organizations to deliver fast, available, and secure digital experiences. Together, we help each other thrive and bring a better digital world to life.

For more information visit f5.com
Explore F5 Labs threat research at f5.com/labs
Follow to learn more about F5, our partners, and technologies: Blog | LinkedIn | X | YouTube | Instagram | Facebook

F5, BIG-IP, Advanced WAF, and NGINX are trademarks, service marks, or tradenames of F5, Inc. or its affiliates in the U.S. and other countries. All other product and company names herein may be trademarks of their respective owners. The validation described herein does not create a partnership, joint venture, agency relationship, or endorsement between the parties.

Source: F5, Inc.

F5 in the Leader tier of the SecureIQLab Cloud WAAP v5.0 CyberRisk Validation Comparative Report.

F5 in the Leader tier of the SecureIQLab Cloud WAAP v5.0 CyberRisk Validation Comparative Report.

WASHINGTON (AP) — Two Republican senators who threatened to block acting Attorney General Todd Blanche's confirmation to lead the Justice Department said Monday that they will support his nomination, ending an impasse over plans to create a fund to compensate allies of President Donald Trump.

The endorsement from GOP Sens. John Cornyn and Thom Tillis paves the way for the Senate Judiciary Committee to advance Blanche's nomination on Tuesday after the Justice Department and lawmakers reached a deal to formally rescind the $1.8 billion “Anti-Weaponization Fund" proposed to settle Trump's lawsuit against the Internal Revenue Service.

Cornyn and Tillis had refused to back Blanche's bid for the permanent post without official confirmation killing the fund meant to compensate people who believe they were unfairly prosecuted by the Justice Department. Blanche's written order, issued late Sunday, came after the days of negotiations between the Justice Department and the Republican senators who are leaving Capitol Hill when their terms end in January.

“We want to express our gratitude to Mr. Blanche and his staff for working with us on this, and we look forward to voting to advance his nomination out of the Senate Judiciary Committee soon," Cornyn, of Texas, and Tillis, of North Carolina, said in a statement.

Blanche has repeatedly said that the Justice Department was scrapping plans for the fund, which sparked bipartisan outcry over the possibility that violent rioters who attacked police at the U.S. Capitol on Jan. 6, 2021, could be considered for payments. But skeptical lawmakers said they were concerned that could be revived without a commitment in writing, especially because Trump has continued to defend the idea.

In his order posted on social media late Sunday, Blanche wrote that the department was confirming "beyond any doubt, that there is no Fund.”

Since the settlement of the president's lawsuit against the IRS was announced, “No Members were appointed; no funds were transferred; no process for receiving claims was established; no claims were paid,” the order said. “This order establishes, beyond any doubt, that there is no Fund.”

Cornyn and Tillis had also pressed the Justice Department to limit the scope of a separate piece of the settlement that provided broad immunity for Trump and members of his family from tax audits.

Under the deal, the Justice Department clarified in writing that the tax audit immunity agreement “applies by its terms only retroactively” to claims open at the time of the settlement and does not protect the president from examination of future tax filings. It also makes clear that only the parties that brought the lawsuit — Trump, two of his sons, and the Trump Organization — are covered by the tax agreement.

Cornyn and Tillis said in their statement that they were “pleased” with the concessions made by Blanche.

“From the outset, we were clear that we needed a written document addressing our concerns on the IRS audit agreement and the anti-weaponization fund that included constraining the scope of audit protection by limiting it to the parties of the Settlement Agreement and legally ending the anti-weaponization fund," they wrote.

Blanche’s nomination was thrown into doubt last week after the Judiciary Committee postponed a vote that had been scheduled for Thursday morning as Tillis and Cornyn said they needed more from the administration before they could provide the necessary votes.

After the Thursday vote was delayed, Trump said in a social media post that he might pull Blanche’s nomination and resubmit it after Cornyn and Tillis leave office next year. And on Saturday the president threatened to push forward with the fund if the two Republicans blocked Blanche's nomination.

On Sunday evening, Trump said that people who had faced charges from the Jan. 6, attack on the Capitol and could have benefited from the fund had “their lives destroyed.”

“This would be a reimbursement for the pain that they suffered,” Trump said. “A lot of people like it.”

Blanche, who served as Trump’s defense lawyer in his criminal cases, entered the Justice Department last year as deputy attorney general. He was elevated to the top post after Pam Bondi was fired in April by Trump, who was frustrated by her failure to successfully prosecute his political enemies.

Though Blanche insisted he wasn’t auditioning for the permanent job, he has moved quickly since taking the reins of the department to promote the Trump administration’s agenda and accelerate investigations into the president’s perceived foes.

FILE - Acting Attorney General Todd Blanche appears before the Senate Judiciary Committee on Capitol Hill in Washington, July 15, 2026. (AP Photo/Mark Schiefelbein, File)

FILE - Acting Attorney General Todd Blanche appears before the Senate Judiciary Committee on Capitol Hill in Washington, July 15, 2026. (AP Photo/Mark Schiefelbein, File)

Recommended Articles