Default SwCA Profiles Transitioning to Runtime Mode Only on October 1, 2026

Spencer Brown

What You Need to Know

On October 1, 2026, all existing default SwCA profiles will be updated to Runtime Mode only. Customers who want to continue using Static Mode must create and assign a new SwCA profile before that date.

Why We’re Making This Change

As organizations mature their software composition analysis programs, the challenge often shifts from finding vulnerabilities to prioritizing the vulnerabilities that matter most. Traditional static dependency analysis can identify all declared dependencies in build manifests and lock files, but many of these components may never be installed, loaded, or executed in production environments.

Runtime Mode addresses this challenge by focusing on the software components running on your systems. By collecting runtime software composition data directly from endpoints, customers gain a more accurate representation of their production attack surface and can better align remediation efforts with real-world risk.

Customers using Runtime Mode commonly experience:

  • Improved visibility into components actively installed and in use
  • Reduced alert fatigue from unused or build-only dependencies
  • More accurate vulnerability findings and SBOMs
  • Faster prioritization and remediation of exploitable risks
  • Cleaner dashboards and more meaningful security reporting

What Is Changing?

Beginning October 1, 2026, all Qualys-provided default SwCA profiles will be configured for Runtime-only data collection. Runtime Mode focuses on software components installed in the execution environment, providing a more accurate view of your production software inventory and exposure.

As a result, software composition findings and SBOMs generated from default profiles will reflect components that are actively deployed and potentially exploitable, rather than all dependencies declared during development and build processes.

What If I Still Need Static Analysis?

Customers who wish to continue collecting static dependency information must create and maintain their own custom SwCA scan profile with Static Mode enabled.

To continue collecting static dependency information after October 1:

  1. Log in to the Qualys Platform.
  2. Navigate to Cloud Agent > Configuration > SwCA Scan Profile.
  3. Create a new custom SwCA profile.
  4. Under Software Composition Analysis (SwCA) Settings, enable Static Mode or both Static and Runtime Mode.
  5. Assign the custom profile to the appropriate assets.

If your goal is to focus on runtime risk, you can enable Runtime Mode today and begin using runtime-only analysis immediately.

Expected Impact

After the transition:

  • Default profiles will collect only runtime software composition data.
  • Findings based solely on declared default profiles will no longer generate build-time dependencies.
  • SBOMs generated from default profiles will more closely represent deployed software.
  • Vulnerability counts may decrease while accuracy and prioritization improve.

This change helps organizations focus remediation efforts on software components that are truly present within their environments, improving operational efficiency and strengthening risk-based vulnerability management.

Move to Runtime Mode Today

Customers do not need to wait until October 1, 2026, to benefit from Runtime Mode only.

Runtime Mode is available today and can be enabled immediately through your SwCA scan profile settings. Organizations that want to reduce noise from build-time dependencies and focus on software components present in their environments are encouraged to make the transition now.

By moving early, customers can familiarize themselves with runtime-based findings, validate reporting workflows, and begin realizing the benefits of more accurate software inventory and vulnerability data before the default profile transition occurs.

If you have questions or need help, feel free to contact your TAM or Qualys Support.

Share your Comments

Comments

Your email address will not be published. Required fields are marked *