# CyberArk is now Idira. Here is what changed and what did not

> Yes, CyberArk is now Idira. Palo Alto Networks announced the rebrand on 12 May 2026. Here is the full old name to new name mapping.

Source: https://fmcybersecurity.com/en/insights/identity/cyberark-is-now-idira/
Locale: English
Other locale: https://fmcybersecurity.com/insights/identity/cyberark-heter-na-idira/

## Metadata

- Date: 2026-08-09
- Author: robin-kvernevik
- Topic: identity
- Format: guide

Yes. CyberArk is now Idira.

Palo Alto Networks announced the name on [12 May 2026](https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-introduces-idira--the-next-generation-identity-security-platform-built-for-the-ai-enterprise). The vault, the connectors and the agents you ran the week before kept running. What moved was the brand on top of them, plus a handful of product names underneath.

I am chief architect on one of the world's largest deployments of this platform, and I have answered the same question in almost every customer meeting since May: did we buy something new? No. You renamed what you already have.

## When the rebrand happened

Idira launched on 12 May 2026, three months after the deal closed. Palo Alto Networks [announced the CyberArk acquisition](https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-completes-acquisition-of-cyberark-to-secure-the-ai-era) on 30 July 2025, CyberArk shareholders approved it on 13 November 2025, and the acquisition completed on 11 February 2026.

The address bar tells the story faster than any press release. Type www.cyberark.com and you land on [paloaltonetworks.com/idira](https://www.paloaltonetworks.com/idira). The old product pages redirect the same way: the Privileged Access Manager page now resolves to `/idira/human/privileged-access-management`.

## Old name to new name, module by module

The rule for most products is simple. "CyberArk X" became "Idira X". Three products broke that rule, and two more have no new page at all yet.

| CyberArk name | What it is called now |
| --- | --- |
| Human Identities (product group) | Idira Human Identity Security |
| Machine Identities (product group) | Idira Machine Identity Security |
| AI Agent Identities (product group) | Idira Agentic Identity Security |
| CyberArk Workforce Identity | Idira Identity and Access Management, shortened to Idira IAM. The password vault is sold on its own as Workforce Password Management |
| CyberArk Privileged Access Manager | Idira Privileged Access Management. Palo Alto Networks also writes it Idira Privileged Access Manager |
| CyberArk Endpoint Privilege Manager | Idira Endpoint Privilege Manager |
| CyberArk Secure Browser | Idira Secure Browser. Still a listed service in the documentation, but there is no standalone product page on paloaltonetworks.com |
| CyberArk Secure Cloud Access | Idira Secure Cloud Access. Same situation as Secure Browser |
| CyberArk Vendor PAM | Idira Vendor Privileged Access |
| CyberArk Identity Governance | Idira Identity Governance, shortened to IGA in the documentation |
| CyberArk Secrets Manager | Idira Secrets Manager, sold under the heading Secrets Management |
| CyberArk Secrets Hub | Idira Secrets Hub, sold under the heading Unified Secrets Governance |
| CyberArk Certificate Manager | Next-Generation Trust Security, shortened to NGTS. It left the identity platform |
| CyberArk Code Sign Manager | Code Sign Manager, Self-Hosted, now grouped under NGTS |
| CyberArk Workload Identity Manager | Not verified. The documentation still says CyberArk Workload Identity Manager and no Idira or NGTS page carries it yet |
| CyberArk SSH Manager for Machines | SSH Manager, Self-Hosted, now grouped under NGTS |
| CyberArk Secure AI Agents | Idira Secure AI Agents |

We keep the same slugs on our own [Idira (CyberArk) module pages](/en/products/cyberark/) so that older bookmarks and internal links survive the rename.

## The certificate products left the identity platform

Certificate Manager is no longer part of the identity platform. Palo Alto Networks moved it into network security under Next-Generation Trust Security, and says so plainly on the [NGTS page](https://www.paloaltonetworks.com/network-security/next-gen-trust-security/certificate-manager): "CyberArk Certificate Manager is now Next-Gen Trust Security." The same page confirms NGTS is the SaaS certificate service previously sold as Venafi TLS Protect and then as CyberArk Certificate Manager SaaS.

This matters for how you buy and who you call. If your certificate lifecycle work sat inside an identity project, it now sits in a different part of the Palo Alto Networks catalogue, with a different product team behind it. The self-hosted siblings, [Code Sign Manager](/en/products/cyberark/code-sign-manager/) and SSH Manager, moved with it.

## What did not change

Your licences carry over. Palo Alto Networks' launch announcement says existing CyberArk customers keep what they run, and that the new agentic and machine identity capabilities are added through new licences rather than swapped in.

Component names are untouched. The documentation still lists Central Policy Manager, Privileged Session Manager, PSM for SSH, Privilege Cloud connector, and the EPM agents for Windows, Linux and macOS as separate services. Nothing in the rename asked us to redeploy an agent or rebuild a connector on any customer we run.

Two things I cannot confirm from a public source, so do not assume them. Tenant login URLs: check yours against your own console before you update a runbook. Support contract terms: Palo Alto Networks has published continuity language for the certificate products, not a general statement about every support agreement, so put the question to your account team.

## Where the Idira documentation lives

The documentation kept its old address. The portal still sits on `docs.cyberark.com`, and the site now calls itself Idira Docs with "Idira Identity Security Platform" as the front page heading. The machine identity documentation at `docs.cyberark.com/mis-saas/` is a step behind and still uses CyberArk product names, which is the clearest sign that the rename is phased rather than finished.

One warning worth thirty seconds of your time. The domain idira.com is not the vendor. It is a parked domain listed for sale. Anything that matters goes through paloaltonetworks.com or docs.cyberark.com, and your service desk should know that before someone receives a convincing email.

## What to change on your side

Four small jobs, none of them urgent, all of them cheap to do now and annoying to do during an audit.

1. Update the supplier and asset names in your ISMS. Auditors match the name on the contract to the name in the register, and a mismatch turns into a finding.
2. Rename the vendor in your runbooks and service desk categories, keeping the old name in brackets for a year so search still works.
3. Re-point team bookmarks at the current documentation portal.
4. Decide whether the agentic and machine identity capabilities are worth a licence conversation, or whether you carry on with what you have.

We run [Idira (CyberArk)](/en/partners/cyberark/) end-to-end for our customers as our only identity platform, from [Privileged Access Manager](/en/products/cyberark/privileged-access-manager/) and [Endpoint Privilege Manager](/en/products/cyberark/endpoint-privilege-manager/) through to [Secure AI Agents](/en/products/cyberark/secure-ai-agents/). We do not resell it.

## FAQ

**Is CyberArk now Idira?**
Yes. Palo Alto Networks renamed the CyberArk identity platform to Idira on 12 May 2026, after completing the acquisition on 11 February 2026.

**What is the new name for CyberArk?**
Idira. The full platform name is the Idira Identity Security Platform, and most products moved from "CyberArk X" to "Idira X".

**Idira vs CyberArk, what is the difference?**
There is no product difference to compare. Idira is the same platform under a new name, plus new agentic and machine identity capabilities that are licensed separately. If a vendor presents them to you as competing products, that is a mistake in the presentation.

**Was CyberArk renamed to Idira, or is Idira a new product?**
Renamed. Palo Alto Networks describes Idira as built on CyberArk and positions it as an upgrade path for existing customers, not as a replacement you have to migrate to.

**Where are the Idira docs?**
Still on docs.cyberark.com. The portal is branded Idira Docs, and the machine identity section under `/mis-saas/` has not been renamed yet.

**Does the CyberArk brand still exist?**
Only in the places the rename has not reached, such as the documentation hostname, parts of the machine identity documentation, and file paths inside components. Everything customer facing on paloaltonetworks.com now says Idira.

Bring the questions your team is stuck on to a 30 minute conversation with our [identity practice](/en/services/identity/), and we will map your current licences and module names to the new ones on the call.

Drafted with AI assistance, reviewed and edited by Robin Kvernevik and the FM CyberSecurity editorial team.

---

For the full documentation index, see https://fmcybersecurity.com/llms.txt
For the complete corpus as a single document, see https://fmcybersecurity.com/llms-full.txt
