Suggestions appear as you type. Use the up and down arrows to choose one and Enter to open it.

This page's audience real numbers from our own analytics — open to see them
–Visitors
–Page views
–Clicks to vendors
–Time on page
–Reading now
Clicks to vendors, by tool
  • –
Top countries
  • –
Devices
  • –

– · counted by iTechGuides's own first-party analytics, bots removed, every figure rounded down · how we count

Black Duck Continuous Dynamic review

#19 of 26 in Dynamic Application Security Testing Software

A cloud DAST service combining continuous assessments with expert-validated findings.

7.6/10Editor score
Black Duck Continuous Dynamic7.6 Visit Black Duck

Reviewed by iTechGuides Editors · Editorial team · Updated Oct 2026

Black Duck Continuous Dynamic is a cloud-based dynamic application security testing service for security and development teams. It continuously assesses modern and traditional web applications, including production applications, while detecting application code and configuration changes. Authenticated scanning uses supplied logins, and production-safe testing uses low-and-slow payloads and benign injectors. The service also supports API testing, making it suited to organizations monitoring web application portfolios and APIs over time.

Pricing is handled through a customized quote rather than published plan tiers. That approach may fit organizations seeking an assessment aligned with their application portfolio, but buyers will need to engage Black Duck to understand the commercial scope. The service is delivered through the cloud, and its feature set centers on continuous and concurrent assessments, change detection, expert validation, and on-demand retesting. Security engineers can also perform business-logic assessments, extending coverage beyond automated vulnerability checks.

Black Duck Continuous Dynamic connects with Jira, SIEM platforms, web application firewalls, and HashiCorp Vault. Its API supports SIEM, bug-tracking, and WAF workflows, while runtime retrieval of authentication secrets from HashiCorp Vault supports authenticated assessment processes. These capabilities make it a strong fit for teams that want findings validated by experts and connected to existing security operations. Organizations needing continuous web and API coverage, production-safe scanning, and retesting should consider it; teams looking specifically for self-hosted deployment or a broader security-testing platform may prefer another option.

Black Duck Continuous Dynamic pros and cons

  • Where it wins
    • Continuous, concurrent assessments with automatic change detection
    • Production-safe authenticated scanning and on-demand retesting
    • Expert validation, business-logic assessments, and workflow integrations
  • Where it doesn't
    • Pricing requires a customized quote
    • Cloud delivery may not suit self-hosted deployment requirements
    • Focused on web applications and APIs rather than broader security testing

Black Duck Continuous Dynamic fact sheet, pricing and score →

Advertiser disclosure: iTechGuides is reader-supported. We may earn a commission when you click some links. How we rank.

Last updated · How we research and update