Omdia's 2026 supply-chain survey puts the annual-incident rate at 77 percent Seventy-seven percent of surveyed organizations experienced a software supply chain incident in the twelve months before Omdia's 2026 survey, according to a report sponsored by Docker. AI technology is now the top-ranked supply chain risk at 40 percent, and 51 percent of respondents rated secure containers as 'very effective' for securing third-party and open-source components. Seventy-seven percent of surveyed organizations experienced a software supply chain incident in the twelve months before Omdia ran its 2026 survey, per a research report Docker sponsored and published August 4. For teams still hardening pipelines, that sets the base rate: assume an attempt will land in the next year, and staff for it. The most common attack shape has not changed. Exploits against known vulnerabilities in third-party software were the top category at 38 percent. What has shifted is what respondents fear next. AI technology is now the top-ranked supply chain risk at 40 percent, edging past third-party and open-source code 39 percent and software dependencies 38 percent . The consequences respondents reported: 46 percent saw unauthorized access to applications and data, 37 percent had SLAs impacted during remediation, and 35 percent had developer credentials, secrets or keys stolen. On code composition, 38 percent of organizations say more than half of their code already comes from third-party sources, and Omdia projects that share to hit 58 percent within twelve months. The effectiveness ranking has one clear winner. Fifty-one percent of respondents rated secure containers as "very effective" for securing third-party and open-source components, the only category, out of eleven, where a majority landed in the top rating. Docker's blog post foregrounds that finding and points readers to Docker Hardened Images and Docker Scout. That is worth reading with the sponsor list in view: the category the sponsor sells topped a ranking the sponsor commissioned. Not disqualifying, but not the number you cite in a boardroom without a second source. Ninety-eight percent of respondents called shifting security left a high priority for their program, and 32 percent named it their single top application-security priority. SBOM adoption is more mixed: 42 percent generate an SBOM for every application as mandatory practice, and 55 percent do it case by case. The most cited SBOM payoffs, per respondents, were quicker vulnerability mitigation 73 percent , better security controls 72 percent , and compliance 68 percent . Sixty-two percent of teams expect to spend heavily on supply-chain security in the coming budget cycle. The number without a footnote is 45 percent. That is the share of respondents who do not rate their own supply chain security as solid today, and it is the constituency the report, and every vendor sponsoring one, is competing for.