---
source_url: "https://guptadeepak.com/ciam-compass/vendors/ping-identity/"
title: "Ping Identity review and capability profile, CIAM Compass"
mirrored_at: 2026-08-14T03:38:23.200Z
host: guptadeepak.com
cited_in_42a: true
mirror_canonical: "https://index.42a.ai/guptadeepak.com/ciam-compass/vendors/ping-identity/index"
---

> **Original source:** https://guptadeepak.com/ciam-compass/vendors/ping-identity/

[Home](https://guptadeepak.com/ciam-compass/)/[Vendors](https://guptadeepak.com/ciam-compass/vendors/)/Ping Identity

Thoma Bravo (private equity) · Thoma Bravo (acquisition closed October 2022, $2.8B)

Last verified 2026-06-03 · Reviewed by guptadeepak

enterprisepublic-sectorcloud-saason-premhybridenterprise-quote

## Editorial verdict

Ping Identity remains the right CIAM choice for large enterprise and public-sector workloads with complex federation, on-prem requirements, or regulated-industry compliance baselines that hyperscaler CIAM cannot meet. DaVinci flow orchestration is genuinely capable for complex auth journeys. The trade-offs, opaque pricing, fragmented post-ForgeRock product family, heavy professional services, make Ping the wrong answer for everything below the enterprise-quote threshold. After the 2023 ForgeRock acquisition the combined product surface is broader but more confusing.

Last verified by @guptadeepak on 2026-06-03.

## At a glance

Best for

Large enterprise and public-sector workloads with complex federation and on-prem requirements

Pricing

enterprise-quote

Free tier

None

Deployment

cloud-saas, on-prem, hybrid

SOC 2 Type II

Yes

Passkeys

Native

Self-host

Yes

Open source

No

## Funding & business

Funding model

Private-equity owned

Total raised

Undisclosed

Latest round

Acquired · $2.8B · 2022

Years in business

24 yrs

Round led by

Thoma Bravo

Profitable

Yes

Vista Equity bought it in 2016, IPO'd it (NYSE: PING) in 2019; Thoma Bravo took it private for $2.8B in 2022 and merged ForgeRock into it.

Funding data from [primary source](https://press.pingidentity.com/2022-10-18-Thoma-Bravo-Completes-Acquisition-of-Ping-Identity). See also the [CIAM investor landscape](https://guptadeepak.com/ciam-compass/investors/).

### Strengths

-   DaVinci visual flow orchestration is among the most capable in the market for complex enterprise auth journeys.
-   FedRAMP High, PCI Level 1, HIPAA, full enterprise compliance footprint with on-prem deployment options.
-   Deep enterprise federation breadth, supports the long tail of legacy IdPs, custom SAML edge cases, and federation chaining that hyperscaler CIAM struggles with.
-   Strong governance, lifecycle, and consent capabilities suitable for regulated industries (banking, insurance, healthcare).

### Limitations

-   Pricing opacity is real, no public pricing, five-figure annual minimums, professional-services-heavy onboarding.
-   DX trails the developer-first tier substantially, slower iteration loops, heavier admin tooling, longer time-to-first-login.
-   Product family is fragmented post-ForgeRock acquisition: PingOne, PingFederate, PingAccess, DaVinci, ForgeRock Identity Cloud.
-   Vendor lock-in via DaVinci flows is significant once production journeys are deployed.

## Capability matrix

Every vendor scored on the same axes. See the [methodology](https://guptadeepak.com/ciam-compass/methodology/) for criteria.

Authentication

Password authentication

Yes

Social login

Yes

Magic links

Yes

SMS OTP

Yes

Email OTP

Yes

TOTP (authenticator app)

Yes

Push MFA

Yes

WebAuthn / passkeys

Yes

Biometric

Yes

Hardware security keys

Yes

SAML SSO

Yes

OIDC SSO

Yes

OAuth 2.0 SSO

Yes

Enterprise federation

Yes

Passwordless-only flows

Yes

Adaptive MFA

Yes

Step-up auth

Yes

Swipe table horizontally →

Authorization

RBAC

Yes

ABAC

Yes

ReBAC

Partial

FGA engine

Yes

API authorization

Yes

Fine-grained permissions

Yes

Swipe table horizontally →

User management

Self-service registration

Yes

Progressive profiling

Yes

Self-service account

Yes

Bulk user import

Yes

Admin user search

Yes

Custom user metadata

Yes

Organizations / tenants

Yes

Multi-tenancy

Yes

SCIM provisioning

Yes

Swipe table horizontally →

Developer experience

REST API

Yes

GraphQL API

No

SDKs

js, node, java, dotnet, python, go, ios, swift, android, kotlin

CLI

Yes

Terraform provider

Yes

Local emulator

No

Extension model

DaVinci flow orchestration + custom node SDK

Swipe table horizontally →

Security

Bot detection

Yes

Breached password detection

Yes

Brute-force protection

Yes

Anomaly detection

Yes

Log streams

Yes

Audit logs

Yes

GDPR data export

Yes

PII minimization

Yes

Post-quantum roadmap

Partial

Swipe table horizontally →

Agentic identity

MCP support

Partial

OAuth 2.1

Yes

Dynamic client registration

Yes

Agent vs human token separation

Partial

Web Bot Auth

No

Swipe table horizontally →

Compliance

SOC 2 Type II

Yes

ISO 27001

Yes

ISO 27018

Yes

HIPAA

Yes

PCI DSS

Level 1

GDPR

Yes

CCPA

Yes

FedRAMP

High

EU data residency

Yes

Swipe table horizontally →

Consent & privacy

Consent management

Yes

Preference center

Yes

Purpose-specific consent

Yes

Integrates with CMPs

OneTrust, TrustArc

Swipe table horizontally →

Scalability & regions

Multi-region deployment

Yes

Data residency control

Yes

Proven at high scale (1M+ MAU)

Yes

Swipe table horizontally →

Enterprise operations

Password-hash import

Yes

Lazy / just-in-time migration

Yes

Account linking & dedup

Yes

Custom domains per brand

Yes

Per-brand theming of all flows

Yes

Per-brand consent partitioning

Partial

Deletion webhooks / cascade

Yes

Event streaming / webhooks

Yes

Documented rate limits

Yes

Swipe table horizontally →

## Developer experience & lock-in

Editorial 1–5 scores and migration effort, scored on the same axes for every vendor. See the [methodology](https://guptadeepak.com/ciam-compass/methodology/) for how these are graded.

### Developer experience

DX overall3/5

Docs quality4/5

Passkey orchestration4/5

Community

Large

### Migration & lock-in

High lock-in

Migrating inHard

Effort to adopt this platform

Migrating outHard

Effort to leave later (your exit cost)

Higher exit effort means more switching cost. Ask about bulk user export (including password hashes) before you commit.

## Enterprise readiness

Enterprise-ready · 100/100

A computed read of how ready this vendor is to sell into the enterprise, derived from the capability matrix. See the [enterprise-ready pillars](https://guptadeepak.com/ciam-compass/enterprise-ready/).

-   Enterprise SSO
    
    SAML SSO · OIDC SSO · Enterprise federation
    
    100
-   Directory sync (SCIM)
    
    SCIM provisioning · Organizations
    
    100
-   Organizations & tenancy
    
    Organizations · Multi-tenancy
    
    100
-   RBAC & custom roles
    
    RBAC · ABAC / ReBAC / FGA · Fine-grained permissions
    
    100
-   Audit logs & streaming
    
    Audit logs · Log streaming
    
    100
-   Compliance certifications
    
    SOC 2 Type II · ISO 27001 · HIPAA / FedRAMP
    
    100
-   Security posture
    
    Anomaly detection · Brute-force protection · Breached-password checks · Adaptive / step-up auth
    
    100

Scored from our capability review; confirm the exact plan tier and SCIM scope with the vendor before you commit.

## Pricing

Estimated monthly cost (USD)

10,000 MAU

Quote required

100,000 MAU

$6,000/mo

500,000 MAU

$18,000/mo

1,000,000 MAU

$30,000/mo

Swipe table horizontally →

-   PingOne SaaS, PingFederate (on-prem), and DaVinci orchestration are commercially separate products
-   Per-user / per-MAU / per-feature pricing varies by deal; expect five-figure annual minimums
-   Professional services often required for complex enterprise federation deployments

Estimates use the standard assumptions in our [methodology](https://guptadeepak.com/ciam-compass/methodology/). Always confirm with the vendor.

### Best for

-   Large enterprise and public-sector workloads with complex federation and on-prem requirements
-   Regulated industries requiring deep governance, consent, and lifecycle management
-   Organizations with existing Ping or ForgeRock footprint

### Not for

-   Mid-market SaaS or startups prioritizing developer velocity
-   Cost-sensitive consumer apps below the enterprise-quote threshold
-   Teams that prefer transparent SaaS pricing

## Solves for

Enterprise pain points this vendor covers on the mapped capabilities. [See all pain points](https://guptadeepak.com/ciam-compass/pain/).

-   [AI agents authenticating on behalf of customers](https://guptadeepak.com/ciam-compass/pain/ai-agents-and-consent/)
-   [B2B multi-tenancy: the edge cases bolted-on models miss](https://guptadeepak.com/ciam-compass/pain/b2b-multi-tenancy/)
-   [Identity unification and deduplication as a program](https://guptadeepak.com/ciam-compass/pain/identity-unification/)
-   [Integration sprawl and the single customer view that wasn't scoped](https://guptadeepak.com/ciam-compass/pain/integration-sprawl/)
-   [Lifecycle management: dormancy, deletion, and the cascade](https://guptadeepak.com/ciam-compass/pain/account-lifecycle-at-scale/)
-   [Migrating millions of users without losing them](https://guptadeepak.com/ciam-compass/pain/user-migration/)
-   [Multi-brand rollout: the scenario that breaks architectures](https://guptadeepak.com/ciam-compass/pain/multi-brand-rollout/)
-   [Pricing opacity: the SSO tax and the MAU trap](https://guptadeepak.com/ciam-compass/pain/pricing-opacity/)
-   [Scaling the user directory itself](https://guptadeepak.com/ciam-compass/pain/scaling-the-user-directory/)
-   [The build-vs-buy trap: identity is bigger than it looks](https://guptadeepak.com/ciam-compass/pain/build-vs-buy-trap/)
-   [The friction-versus-security dial that never stops moving](https://guptadeepak.com/ciam-compass/pain/friction-vs-security/)
-   [Vendor differentiation and the four-veto evaluation](https://guptadeepak.com/ciam-compass/pain/vendor-differentiation/)

## Featured in

Where Ping Identity appears across CIAM Compass analysis.

-   [Microsoft Entra External ID (formerly Azure AD B2C) alternatives](https://guptadeepak.com/ciam-compass/alternatives/microsoft-entra-alternatives/)
-   [Financial services & banking vertical](https://guptadeepak.com/ciam-compass/verticals/financial-services/)
-   [Travel & hospitality vertical](https://guptadeepak.com/ciam-compass/verticals/travel-hospitality/)
-   [Government & cities vertical](https://guptadeepak.com/ciam-compass/verticals/government-cities/)
-   [iGaming, online gambling & sports betting vertical](https://guptadeepak.com/ciam-compass/verticals/igaming-gambling/)
-   [Healthcare & life sciences vertical](https://guptadeepak.com/ciam-compass/verticals/healthcare/)
-   [Education & EdTech vertical](https://guptadeepak.com/ciam-compass/verticals/education/)
-   [Media & streaming vertical](https://guptadeepak.com/ciam-compass/verticals/media-streaming/)
-   [Automotive & connected vehicle vertical](https://guptadeepak.com/ciam-compass/verticals/automotive-mobility/)
-   [Energy & utilities vertical](https://guptadeepak.com/ciam-compass/verticals/energy-utilities/)
-   [Insurance vertical](https://guptadeepak.com/ciam-compass/verticals/insurance/)

## FAQ

What is the relationship between Ping Identity and ForgeRock?

Ping acquired ForgeRock in August 2023 (announced October 2022, closed 2023). Both companies were taken private by Thoma Bravo. The combined company sells both product families under the Ping brand; ForgeRock Identity Cloud and PingOne are still distinct platforms in 2026, with cross-product integration still in progress. New customers should evaluate which platform fits their workload rather than assuming convergence.

Does Ping have a free tier?

No. All Ping deployments are enterprise quote-based, with five-figure annual minimums typical. For teams below that threshold, look at Auth0, WorkOS, or open-source alternatives.

What is DaVinci?

DaVinci is Ping's visual flow orchestration product, a no-code editor for designing complex enterprise auth journeys with conditional logic, risk decisioning, and integration nodes. Among full-platform CIAM, DaVinci is the most mature visual orchestrator for enterprise scenarios; the trade-off is vendor lock-in once production flows are deployed.

## Sources

## Where to next

-   [BlueprintB2B SaaS blueprint](https://guptadeepak.com/ciam-compass/blueprints/b2b-saas/)
-   [BlueprintEnterprise-ready checklist](https://guptadeepak.com/ciam-compass/enterprise-ready/)
-   [ToolVendor selector](https://guptadeepak.com/ciam-compass/tools/vendor-selector/)

* * *

## [What Ping Identity is](#what-ping-identity-is)

[Ping Identity](https://guptadeepak.com/ciam-compass/vendors/ping-identity/) is one of the longest-running enterprise CIAM platforms, founded in 2002, public from 2019 to 2022, taken private by Thoma Bravo in October 2022 for $2.8B, and merged with ForgeRock in 2023. The product family covers PingOne (cloud), PingFederate (on-prem), PingAccess (web access management), and DaVinci (visual flow orchestration), plus the ForgeRock Identity Cloud platform that joined the portfolio post-acquisition. The buyer is typically a large enterprise or public-sector organization that needs deep federation, on-prem deployment, or a compliance baseline that hyperscaler CIAM cannot meet.

## [Where Ping Identity wins](#where-ping-identity-wins)

The [federation](https://guptadeepak.com/ciam-compass/glossary/federation/) depth is the structural advantage. Twenty-plus years of enterprise SAML / OIDC / WS-Federation work shows up as edge-case coverage that hyperscaler CIAM lacks, older PingFederate connections, custom XACML policies, federation chaining across legacy IdPs, and the kind of healthcare-and-banking federation patterns that took decades to standardize.

DaVinci flow orchestration is genuinely capable. Among visual auth-journey builders, it sits at the top of the enterprise tier, handling conditional logic, risk decisioning, third-party integration nodes, and complex MFA step-up scenarios that smaller orchestrators cannot express. For regulated industries with multi-step [KYC](https://guptadeepak.com/ciam-compass/glossary/kyc/) / consent / verification journeys, DaVinci's expressiveness justifies the platform on its own.

Compliance is full-stack: FedRAMP High, PCI DSS Level 1, HIPAA, ISO 27001/27018, with on-prem deployment options for jurisdictions or workloads that require it. Combined with [consent management](https://guptadeepak.com/ciam-compass/glossary/consent-management/), preference center, and purpose-specific consent capabilities, uncommon in this index, Ping is appropriate for the most regulated buyer profiles.

## [Where Ping Identity hurts](#where-ping-identity-hurts)

Pricing opacity is the lasting friction. No public pricing, five-figure annual minimums typical, professional-services-heavy onboarding. For mid-market or startup buyers, the vendor selection process alone consumes weeks before pricing is even visible.

DX trails the developer-first tier substantially. The admin tooling reflects a generation of enterprise IAM design rather than a developer-product mindset; SDK ergonomics are functional but not modern; iteration loops are slower than Auth0 / [Stytch](https://guptadeepak.com/ciam-compass/vendors/stytch/) / Clerk by a noticeable margin.

The product family is fragmented post-[ForgeRock](https://guptadeepak.com/ciam-compass/vendors/forgerock/) acquisition. PingOne, PingFederate, PingAccess, DaVinci, and ForgeRock Identity Cloud are still distinct platforms in 2026, with naming overlap that confuses new buyers. Cross-product integration is in progress but not yet seamless.

Migration in or out of Ping is a multi-quarter project in either direction. DaVinci flows in particular do not port cleanly to other vendors' orchestration models.

## [How Ping Identity compares](#how-ping-identity-compares)

The closest comparisons are [Auth0 vs Ping Identity](https://guptadeepak.com/ciam-compass/compare/auth0-vs-ping-identity/) for the modernization-vs-enterprise call and [Ping Identity vs ForgeRock](https://guptadeepak.com/ciam-compass/compare/ping-identity-vs-forgerock/) for the within-Ping-portfolio decision. For modern visual orchestration at lower cost, [Descope](https://guptadeepak.com/ciam-compass/vendors/descope/) covers a similar use case for mid-market buyers. For deep federation at lower cost, [Auth0](https://guptadeepak.com/ciam-compass/vendors/auth0/) and [WorkOS](https://guptadeepak.com/ciam-compass/vendors/workos/) are the developer-first alternatives.

Editorial changelog (1 entry)

1.  June 3, 2026
    
    Full profile review: capability matrix, TCO bands, and editorial verdict re-verified against current public sources.