Gartner’s $247.5B security forecast makes post-quantum firewall refreshes the only upgrade through 2030

The 3Q26 Gartner information security forecast raised exactly one growth rate.
Gartner now projects firewall equipment spending to grow 13.4% in 2027 in constant currency, up from the 7.8% in its June forecast. Network security equipment overall rises to 12.8% from 8.7%. Post-quantum cryptography (PQC) is the cause. Many installed firewalls can’t run the new algorithms, which forces early replacement.
Every other business category in the 41-category forecast kept the constant-currency outlook it had 91 days earlier.
Published September 24, the forecast puts worldwide end-user spending at $247.5 billion in 2026, up 13.6% in current U.S. dollars and 12.7% in constant currency.
Spending reaches $372.8 billion by 2030. Gartner frames that as $373 billion and a 10.8% compound annual growth rate in constant currency from 2025 through 2030.
I built this analysis from Gartner’s 3Q26 report (G00862059), the full detailed dataset of 13,489 rows covering 47 countries, 9 regions, 41 categories and 7 years, and a line-by-line comparison against the 2Q26 file Gartner released in June (G00855892).
For the 2Q26 update that first counted securing AI inside the forecast, see Gartner’s $248.2B security forecast makes securing AI the only segment accelerating through 2030.
Each bar in the hero chart stacks four parts of Gartner’s forecast in current U.S. dollars. Navy is business security software, mid-blue is security services, sky blue is network security and light blue is consumer security software. Bold figures above the bars give each year’s total, with Gartner’s constant-currency growth rate in italics.
Six tiles underneath carry the 2026 and 2030 totals, the $125.4 billion in new spending between 2026 and 2030, the 2030 firewall revision in constant currency, the change in Gartner’s 2027 firewall growth forecast and the securing AI trajectory.
Both the 56% software share and the $80.5 billion software tile include consumer security software.
Gartner information security forecast puts 2026 at $247.5B and 2030 at $372.8B
Gartner splits the market into security software, security services and network security. Software keeps gaining share in every year of the forecast.
Each column in the chart below adds to 100% of total spending. Navy is security software, including consumer. Mid-blue is security services and sky blue is network security.
A panel on the right lists each market’s 2024 and 2030 spending and share. I calculated the shares from Gartner’s current-dollar figures.

Total market 2026. $247.5 billion, up $29.7 billion from $217.7 billion in 2025.
Security software 2026. $126.9 billion including $9.0 billion of consumer security software. Software reaches $207.4 billion by 2030, 55.6% of all spending, up from 49.6% in 2024.
Security services 2026. $93.5 billion. Services reach $125.4 billion by 2030, but their share falls from 39.3% in 2024 to 33.6%. Constant-currency CAGR is 7.5%, the slowest of the three markets.
Network security 2026. $27.0 billion, growing 15.0% in constant currency. It reaches $40.0 billion by 2030. Gartner raised the 2025 to 2030 CAGR for this market to 10.9%, up from 9.8% in 2Q26.
2026 to 2030 net new spending. $125.4 billion. Security software captures $80.5 billion of it, or 64%. Services add $31.9 billion. Network security adds $13.0 billion.
Gartner’s near-term call is unchanged from June. Growth slows to 11.2% in 2027 in constant currency, then decelerates to 9.6% by 2030.
Gartner names security service edge (SSE), cloud-native application protection platforms (CNAPPs), cloud security posture management, cloud access security brokers, web application firewalls, encryption and enterprise data loss prevention as the areas where 2027 budgets will grow.
It also expects AI trust, risk and security management (AI TRiSM) adoption to rise as generative AI use widens data, application and governance risk.
Post-quantum firewall refreshes drew the only growth upgrade
Gartner’s revision table compares 3Q26 against 2Q26 for all 11 subsegments. Ten of them show 0.0% growth-rate change in every year from 2026 through 2030. Network security equipment is the exception, at +4.1 points in 2027, +1.1 in 2028, +0.4 in 2029 and -0.2 in 2030.
I ran the same comparison across all 41 categories in the detailed files. In constant currency, firewall equipment is the only category Gartner raised.
It gains $1.08 billion in 2027, $1.50 billion in 2028, $1.77 billion in 2029 and $1.84 billion in 2030. The other 40 categories, including consumer security software, match the June file to the dollar in constant currency.
In the chart below, each bar is the firewall equipment increase in constant currency. Because no other category moved, the bars are also the net change for the whole market. The total is unchanged in 2025 and 2026 and turns positive in 2027, when the firewall upgrade starts.

Gartner states the cause directly. “Postquantum cryptography (PQC) requirements will drive premature hardware refreshes, initially among government, financial and defense organizations, due to the inability of many existing firewalls to support the processing demands and crypto-agility required through software or firmware updates,” the report says.
Gartner’s timing is specific. The report says “selected products may support algorithms such as FIPS 203/ML-KEM by late 2026.” Broader vendor availability follows in 2027. By 2028, Gartner expects every major firewall vendor to offer PQC-capable platforms.
Gartner expects at least 20% of customers in government, financial services and defense to upgrade in 2027, rising to more than 30% in 2028.

In the top panel, the chart compares firewall equipment spending in Gartner’s 2Q26 forecast (light blue) with 3Q26 (sky blue), in constant currency. Revised values carry dark-blue labels and the 2027 and 2030 increases are marked above the bars.
Year-over-year growth sits in the bottom panel, with June’s forecast dashed and September’s solid. Both lines match through 2026, split in 2027 and converge by 2030.
That shift shows up in one year. In June, Gartner expected firewall equipment growth to fall from 16.1% in 2026 to 7.8% in 2027. Now 2027 growth holds at 13.4%.
Gartner’s revision lifts the 2027 firewall market from $20.8 billion to $21.9 billion in constant currency, and the 2030 market from $25.7 billion to $27.6 billion.
In current dollars firewall equipment reaches $28.6 billion by 2030, still the largest network security category by a wide margin.
Every region gets the upgrade at nearly the same rate. Each region’s 2030 firewall forecast rose between 6.9% and 7.8%. North America takes $834 million of the $1.84 billion. Europe takes $414 million. Together they account for 68%.
Each bar in the next chart is one region’s 2030 firewall revision in constant currency. The label shows the dollar increase, that region’s share of the $1.84 billion total and its revised 2030 firewall market. Sky-blue bars mark North America and Europe. Lighter bars are the other seven regions.

Why a firmware update will not close the gap
Gartner’s argument rests on hardware. Many installed firewalls cannot meet PQC processing and crypto-agility demands through software or firmware updates. The engineering behind that is straightforward. ML-KEM public keys and ciphertexts are larger than the elliptic-curve exchanges they replace, and hybrid key exchange runs both algorithms in the same handshake.
A firewall that inspects encrypted traffic at line rate has to absorb that overhead on every session.
Federal policy points the same way. The National Security Agency’s CNSA 2.0 guidance says traditional networking equipment such as VPNs and routers should “support and prefer CNSA 2.0 by 2026, and exclusively use CNSA 2.0 by 2030.”
According to Keyfactor’s summary of the federal timeline, new National Security System acquisitions are expected to be CNSA 2.0-compliant by default from January 1, 2027, and NIST IR 8547 proposes deprecating RSA, ECDSA, EdDSA and Diffie-Hellman at the 112-bit security level after 2030, with disallowance in 2035.
Vendor roadmaps line up with Gartner’s 2027 inflection. Cisco’s Secure Firewall PQC roadmap targets ML-KEM support in Secure Firewall Threat Defense 10.5 and ASA 9.25 for general availability in late 2026.
ML-DSA signature support is planned for FTD/ASA 11.0 in the second half of 2027, and SLH-DSA support is also planned for 11.0.
Gartner names the sectors with procurement mandates first. That is why the revision lands in 2027 and fades by 2030. Gartner models the refresh as a pull-forward, with 2030 growth now slightly below the June forecast at 6.8% versus 7.0%.
After two increases, the 2026 number dips
I have tracked Gartner’s 2026 security number through four quarterly updates. The 4Q25 update projected $244.2 billion. 1Q26 raised it to $246.2 billion. 2Q26 raised it again to $248.2 billion. 3Q26 is the first update in that run to come in lower, at $247.5 billion.

Each bar in the chart above is the 2026 total as published in one quarterly update. The labels inside the bars show the change from the previous update, at +$2.0 billion, +$2.0 billion and -$0.8 billion.
An axis starting at $240 billion keeps the revisions visible. All four estimates sit within 2% of each other.
The entire $788 million drop is currency, not lower demand. Gartner’s revision table puts the 2026 change at -$788 million in current dollars, with 0.0% change in every 2026 growth rate. In the detailed files, the 2026 total is unchanged in constant currency.
Japan shows the currency effect most clearly. Its 2030 forecast is $1.37 billion lower in current dollars than in June, yet $49 million higher in constant currency, all of it from the firewall increase.
Gartner’s notes flag exchange-rate volatility, Strait of Hormuz disruption expected to continue into 2027, energy prices more than 50% above pre-war levels and the risk that inflation and rising interest rates erode business confidence.
Gartner expects the conflict’s main near-term effect on IT spending to be a rebalancing of sourcing, vendor relationships and regional exposure rather than a material cut.
Where the $125.4 billion in new spending goes
Growth rates show where momentum is. Dollar additions show where budgets actually move. Fifteen of the 41 categories capture 76% of all new spending between 2026 and 2030.
Bars in the next chart show the dollars each of the 15 largest categories adds between 2026 and 2030, colored by market. The indigo line, read on the right axis, is the cumulative share of the $125.4 billion total.
It reaches 15% with the first category, 46% after five, 65% after ten and 76% after fifteen.

Other security software, including securing AI. +$19.2 billion, from $18.3 billion to $37.5 billion. The largest single dollar gain in the forecast.
Endpoint protection platforms (enterprise). +$11.7 billion, from $21.3 billion to $32.9 billion.
Cloud security posture management. +$9.8 billion, from $6.3 billion to $16.1 billion.
Firewall equipment. +$8.8 billion, from $19.7 billion to $28.6 billion. Post-quantum refreshes make firewalls the fourth-largest source of new dollars, ahead of cloud workload protection.
Cloud workload protection platforms. +$8.2 billion, from $7.5 billion to $15.7 billion.
Managed security operations. +$7.0 billion, from $15.6 billion to $22.7 billion. The largest services gain.
Five categories alone account for $57.8 billion, or 46% of new spending. Three of them sit in cloud security or in other security software, where Gartner counts securing AI. Endpoint protection and the firewall, a category many security leaders had written off as a replacement-cycle business, make up the other two.
The 10 fastest-growing categories through 2030
Ranked by 2025 to 2030 CAGR in constant currency, cloud security takes the top three spots. Gartner’s cloud security subsegment grows from $16.6 billion in 2026 to $38.4 billion by 2030, a 24.1% CAGR and the fastest of the 11 subsegments.
In the chart, bar length is each category’s 2025 to 2030 CAGR in constant currency. The label gives the CAGR and the category’s 2026 and 2030 market size in current dollars.
Navy marks security software and sky blue marks network security. The dashed line is the 10.8% market CAGR, so every bar crosses it by at least 1.2 points.

- Cloud security posture management. 27.6% CAGR. $6.3 billion in 2026 to $16.1 billion in 2030.
- Cloud access security brokers. 24.3%. $2.8 billion to $6.5 billion.
- Cloud workload protection platforms. 21.0%. $7.5 billion to $15.7 billion.
- Zero trust network access. 20.9%. $3.0 billion to $6.4 billion. The fastest-growing network security category.
- Threat intelligence. 19.0%. $3.1 billion to $6.1 billion.
- Consent and preference management. 18.6%. $1.0 billion to $2.0 billion.
- Other security software, including securing AI. 18.5%. $18.3 billion to $37.5 billion.
- Network detection and response. 12.4%. $2.6 billion to $4.1 billion.
- Subject rights request automation. 12.3%. $1.5 billion to $2.3 billion.
- Vulnerability assessment. 12.0%. $4.1 billion to $6.4 billion.
Gartner’s own opportunity map plots the 11 subsegments on two axes. The horizontal axis is the 2025 to 2030 CAGR. The vertical axis is dollars added over the same period. Bubble size is the 2030 market. The dashed vertical line marks the overall 10.8% CAGR.
Cloud security and other security software sit alone on the right, the only two subsegments growing faster than 15%. Infrastructure protection is the largest subsegment at $62.7 billion by 2030 and adds the most dollars, about $26 billion, while growing at the market average.

Securing AI becomes the largest line item in 2029
Gartner places securing AI inside other security software. The report sizes the market for securing AI ecosystems and AI agents at $3 billion in 2026 and $16 billion by 2030, citing its companion analysis, Forecasting the $16.4 Billion Opportunity in Securing AI.
That makes securing AI about 16% of the other security software category in 2026 and about 43% by 2030, by my calculation.
Of the $19.2 billion the category adds over the period, roughly $13 billion comes from securing AI. The rest of the category grows from about $15.3 billion to about $21.5 billion.
Other security software is also the only category whose growth accelerates every year of the forecast, from 16.3% in 2026 to 20.1% in 2030 in constant currency. It passes enterprise endpoint protection in 2029, $31.1 billion against $30.1 billion, and finishes 2030 at $37.5 billion against $32.9 billion.
By 2030 securing AI alone, at $16 billion, is roughly the size of cloud security posture management ($16.1 billion), managed detection and response ($15.7 billion) or cloud workload protection ($15.7 billion), and larger than SIEM ($11.2 billion).
Gartner’s second AI number is larger. Gartner’s AI-amplified security forecast projects AI-amplified security, meaning existing security products with AI built in, rising from $49 billion in 2026 to $204 billion by 2030.
I covered the full AI-amplified forecast in Gartner’s AI security forecast exposes 162x services growth that still trails software 2 to 1 in new spending.
Each bar in the next chart equals Gartner’s 3Q26 total for that year. The navy segment is Gartner’s AI-amplified security spending. The light-blue segment is everything else in the information security market, calculated by subtracting AI-amplified spending from the total.
Each segment shows its dollars and its share of that year’s total. The indigo note repeats Gartner’s securing AI figures, which sit inside other security software rather than in the AI-amplified total.
Everything else, the light-blue segment, shrinks from $182.9 billion (95%) in 2024 to $168.4 billion (45%) in 2030, even as the total nearly doubles.

Set against the 3Q26 totals, AI-amplified spending rises from 20% of the market in 2026 to 39% in 2028, 47% in 2029 and 55% in 2030. Treat that as an illustration of direction, since the two forecasts were built separately.
By the end of the decade, most security dollars will buy products where AI does part of the detection, triage or response work.
Gartner’s report expects AI code security assistants and cybersecurity AI assistants to automate event triage, false-positive reduction and code remediation, and it expects organizations to shift from reactive defense toward continuous threat exposure management (CTEM).
North America is 53% of 2030 spending, and China grows fastest
On the left, the chart shows each region’s 2030 spending in current dollars and its share of the world total. On the right is each region’s 2025 to 2030 CAGR in constant currency. The dashed line marks the 10.8% world rate, and indigo marks China and Japan, the two fastest-growing regions.

North America. $129.2 billion in 2026, 52.2% of the world. $197.7 billion by 2030, 53.0%. 11.4% CAGR. The United States alone reaches $181.1 billion in 2030.
Europe. $64.0 billion in 2026 to $91.3 billion by 2030. 8.6% CAGR, the slowest of the nine regions.
China. $10.7 billion in 2026, up 24.5% in current dollars. $18.7 billion by 2030. 15.4% CAGR, the fastest region.
Japan. $12.6 billion in 2026 to $22.2 billion by 2030. 13.1% CAGR, second fastest, with 17.6% constant-currency growth in 2026.
Emerging markets. Emerging Asia/Pacific grows at 11.1%, Sub-Saharan Africa at 10.5%, Latin America at 9.3%, and the Middle East and North Africa at 9.1%.
At the country level, China (16.2%), Indonesia (13.9%), Japan (13.1%) and Taiwan (12.4%) post the fastest constant-currency CAGRs among the 47 countries in the file.
All 41 categories, ranked
Growth rates spread wide across the full ranking. Seven categories grow faster than 18% a year. Twenty-nine grow below the 10.8% market rate. Two shrink.
Bars rank all 41 categories by 2025 to 2030 CAGR in constant currency. Each bar carries its CAGR, and the right-hand column lists the category’s 2030 market size in current dollars. Click the chart to open it full size.
Navy is security software, mid-blue is security services and sky blue is network security. Indigo marks the two shrinking categories, and a dashed line marks the 10.8% market rate.

Network access control declines at a 17.7% CAGR, from $922 million in 2026 to $382 million in 2030. Intrusion detection and prevention systems fall at 8.3% a year, from $785 million to $548 million.
Both sit inside network security equipment, the same subsegment where firewalls, zero trust network access and network detection and response all grow. My read is that standalone network appliances are being absorbed into firewall platforms and ZTNA, which is consistent with Gartner’s comments on platform consolidation.
User authentication grows at 3.1%, the slowest positive rate in the forecast, while access management grows at 9.2% to $12.1 billion and identity governance and administration at 10.2% to $7.1 billion. My read is that identity spending is shifting from the login event to governing who and what holds access.
A reading note on Gartner’s Table 1
Readers working from the PDF of the Gartner information security forecast should check the growth columns in Table 1. For the last three rows, the growth rates appear offset by one row. The table shows 16.3% to 20.1% growth next to security consulting services and 9.0% to 5.6% next to other security software.
Gartner’s detailed dataset shows the reverse. Other security software accelerates from 16.3% to 20.1%, security consulting services slows from 9.6% to 5.0%, and security professional services slows from 9.0% to 5.6%. The dollar values in the table are correct. Every growth rate in this post comes from the detailed file.
What security leaders should do with this forecast
Inventory every firewall and VPN concentrator for PQC capability now. Gartner’s refresh window opens in 2027 for government, financial services and defense. Organizations that sell into those sectors, or connect to them, will face the same questions in their own procurement and supplier reviews. Ask vendors which appliance generations support ML-KEM in hardware at full inspection throughput, and get the answer in writing.
Budget the refresh as a 2027 and 2028 capital item. Gartner’s revision adds $1.08 billion to 2027 and another $0.43 billion in 2028, then only $0.26 billion and $0.07 billion more in 2029 and 2030. Waiting for 2029 means buying when lead times and pricing reflect peak demand.
Plan for securing AI as a line item, not a pilot. At $16 billion by 2030, securing AI will be comparable in size to CSPM and MDR. Governance gaps are already visible. Gartner’s first AI governance hype cycle found 34% of enterprises govern AI with policies they only partly follow, which I covered in Gartner’s 2026 AI Governance Hype Cycle.
Push cloud security consolidation. CSPM, CASB and CWPP are the three fastest-growing categories, and Gartner lists SSE and CNAPP adoption alongside tool consolidation and cost control as 2027 budget priorities. Consolidating onto those platforms is the most direct way to fund the growth without adding consoles and contracts.
Re-test services contracts against AI-assisted operations. Services share drops from 39.3% to 33.6% by 2030. Managed security operations still adds $7.0 billion, so outsourcing is not shrinking. What changes is the mix of human hours and AI triage inside each contract, and pricing should reflect it.
Frequently asked questions
How much will worldwide information security spending be in 2026? Gartner forecasts $247.5 billion in 2026, up 13.6% in current U.S. dollars and 12.7% in constant currency.
How big will the security market be by 2030? $372.8 billion, which Gartner frames as $373 billion and a 10.8% constant-currency CAGR from 2025 through 2030.
What changed in the 3Q26 Gartner information security forecast? Firewall equipment growth for 2027 rose to 13.4% from 7.8% in constant currency, driven by post-quantum firewall refreshes. Every other business category kept its constant-currency outlook from June.
Which security category grows fastest? Cloud security posture management, at a 27.6% CAGR from 2025 to 2030, reaching $16.1 billion.
How large is the securing AI market? Gartner sizes securing AI at $3 billion in 2026 and $16 billion by 2030, counted inside other security software.
How I built this analysis
All market sizes are Gartner end-user spending from the 3Q26 detailed forecast file (G00862059), in current U.S. dollars unless noted. All growth rates and CAGRs are constant currency, matching Gartner’s reporting convention, with 2024 as the constant-currency base year.
Revisions compare the 3Q26 and 2Q26 (G00855892) detailed files category by category in constant currency, which separates forecast changes from exchange-rate effects. Dollar additions, shares, rankings, regional splits and the AI-amplified ratio are my calculations.
Securing AI figures ($3 billion in 2026, $16 billion by 2030) are Gartner’s, as stated in the 3Q26 report. The AI-amplified figures come from Gartner’s August 2026 AI-amplified security forecast.
Earlier analysis in this series:
- Gartner’s $248.2B security forecast makes securing AI the only segment accelerating through 2030 (2Q26)
- Gartner’s $246.2B Security Forecast shows 10 categories growing 2x to 3x the market (1Q26)
- Gartner’s $244.2B security forecast shows enterprises spend 17x more on AI tools than securing AI itself
- Gartner’s 4Q25 Information Security forecast shows 15 categories capturing half of all new security spending through 2029
- Gartner’s $239B AI forecast: Agentic workflows take half of GenAI model revenue
For each month’s AI agent attacks, exploited CVEs and breaches with primary sources, see my monthly AI security news briefing.
This post is my personal analysis of Gartner’s information security research and does not represent my employer.
Sources
- Gartner, Forecast: Information Security, Worldwide, 2024-2030, 3Q26, Shailendra Upadhyay, Christian Canales, Ruggero Contu, Frank Marsala, Rahul Yadav, 24 September 2026, G00862059.
- Gartner, Forecast: Information Security, Worldwide, 2024-2030, 2Q26, June 2026, G00855892.
- Gartner, Forecast Analysis: AI-Amplified Security, Worldwide, 2026, Shailendra Upadhyay, 4 August 2026, G00846160.
- Gartner, Forecasting the $16.4 Billion Opportunity in Securing AI, Shailendra Upadhyay, 30 July 2026, G00853861.
- NSA, Announcing the Commercial National Security Algorithm Suite 2.0, cybersecurity advisory, updated May 30, 2025.
- NIST, IR 8547 (initial public draft), Transition to Post-Quantum Cryptography Standards, November 2024.
- Cisco, Preparing for Post-Quantum Cryptography: The Secure Firewall Roadmap.
- Keyfactor, Post-Quantum Readiness for Software Vendors: The Timeline Is Now Written Down.
Discover more from Software Strategies Blog
Subscribe to get the latest posts sent to your email.





