Top 7 CNAPP Platforms for Cloud Security in 2026
The category consolidated hard this year, and the biggest name in it now belongs to a hyperscaler. Wiz, Cortex Cloud, CrowdStrike, Defender for Cloud, Sysdig, Orca and Upwind compared on coverage, deployment and price.
A cloud-native application protection platform — CNAPP — folds posture management, workload protection, entitlement analysis and code scanning into one product instead of five. The leaders heading into late 2026 are Wiz, now part of Google Cloud after a $32 billion deal closed in March; Palo Alto Networks' Cortex Cloud; CrowdStrike Falcon Cloud Security; Microsoft Defender for Cloud; Sysdig; Orca Security; and Upwind, which raised at a $3.8 billion valuation in September. The real split between them is no longer feature checklists. It is whether you want agentless breadth, runtime depth, or a platform you already own.
How we picked these
Four criteria, applied the same way to every vendor.
Coverage across the CNAPP pillars. A platform had to do posture management, workload protection, identity and entitlement analysis, and some form of pre-deployment scanning — not one pillar with adjacent marketing.
Verifiable market position. Independent analyst placement, disclosed funding or revenue, public customer counts, or documented government and enterprise adoption. Vendor self-description alone did not qualify.
Deployment model and operational cost. Agentless, agent-based, or hybrid — and what that means for time to first result versus runtime fidelity.
Pricing that can be described. Where a vendor publishes rates, we state them. Where it does not, we say so rather than estimating.
Ranking runs roughly from broadest proven enterprise footprint to most specialised. It is not a quality order — three of these are better than the top pick for specific jobs, and we say which.
Quick comparison
| Company | Best for | Deployment | Pricing model |
|---|---|---|---|
| Wiz | Fast multicloud visibility at enterprise scale | Agentless, optional sensor | Quote only |
| Cortex Cloud | Palo Alto shops unifying cloud and SOC | Agent + agentless | Credit-based, quote |
| CrowdStrike | Teams already running Falcon on endpoints | Agent + agentless | Quote only |
| Defender for Cloud | Azure-centric estates wanting per-resource billing | Agentless + optional agents | Published per-resource rates |
| Sysdig | Deep Linux and container runtime detection | Agent (eBPF) + agentless | Quote only |
| Orca | Smaller teams that cannot deploy agents | Agentless (SideScanning) | Quote only |
| Upwind | Runtime-first prioritisation of cloud risk | eBPF sensor | Quote only |
1. Wiz
Wiz built the agentless CNAPP template most of this list now answers to. It connects to a cloud account with read permissions, scans workload snapshots out of band, and assembles the results into a graph — the Wiz Security Graph — that links a vulnerability to the identity, network path and data store that would make it exploitable. The output is an attack path rather than a vulnerability count, which is why the product became shorthand for prioritisation rather than scanning.
Google completed its acquisition of Wiz on 11 March 2026 in a deal valued at $32 billion, one of the largest in cybersecurity history. Google said Wiz would keep its brand and continue supporting AWS, Azure and Oracle Cloud alongside Google Cloud. That commitment is now the central question for buyers: the platform's value has always rested on being neutral across clouds, and it is now owned by one of them.
Best for: enterprises that need broad multicloud coverage working within days, not quarters.
Pros - Agentless connection means coverage of an entire cloud account without touching workloads or asking application teams for anything. - Graph-based attack-path analysis surfaces exploitable combinations rather than raw CVE lists. - Backed by Google Cloud since March 2026, which removes the acquisition uncertainty that hung over the product through 2025. - Broad third-party coverage across AWS, Azure, Google Cloud and Oracle Cloud, per Google's own acquisition announcement.
Cons - Now owned by a hyperscaler that competes with AWS and Azure — a procurement and strategy risk for organisations standardised on those clouds, however the roadmap actually plays out. - No published pricing at all; every deal is a negotiation, and the platform has a reputation for pricing at the top of the market. - Snapshot-based scanning is periodic by design, so a purely agentless deployment sees runtime events after the fact rather than as they happen. - Depth of Linux runtime detection is not the product's strength relative to Sysdig or CrowdStrike, which is why Wiz added an optional sensor.
2. Palo Alto Networks Cortex Cloud
Palo Alto retired the Prisma Cloud brand in February 2025 and re-released the technology as Cortex Cloud, folded into its Cortex XSIAM security-operations platform. Dell'Oro Group described the move as a re-architecture rather than a rename: the pitch is that cloud findings and SOC detections should live in one data layer and one console, instead of a cloud security team filing tickets at an incident response team.
That consolidation instinct runs through everything Palo Alto has done this year, including its $500 million move into the help desk. It is a genuine architectural argument and the most differentiated one on this list. It is also the most demanding. The value shows up when you run Palo Alto's SOC tooling already; if you do not, you are buying into a platform whose logic assumes you eventually will.
Best for: organisations already standardised on Palo Alto who want cloud alerts and SOC investigation in one workflow.
Pros - Unifies CNAPP findings with XSIAM security operations, reducing the handoff between cloud security and incident response. - Both agent-based and agentless collection, so runtime depth does not require abandoning fast onboarding. - Palo Alto offers existing Prisma Cloud customers migration paths to Cortex Cloud, including like-for-like upgrades. - Backed by one of the largest security vendors, with the support, compliance and procurement apparatus that implies.
Cons - Credit-based licensing is difficult to forecast: credits vary by resource type and by which modules you enable, and Palo Alto publishes guides rather than rates. - The Prisma-to-Cortex transition means documentation, integrations and community knowledge are split across two product identities. - Strongest value is conditional on adopting the wider Cortex platform — a meaningful lock-in consideration. - Heavier to deploy and tune than the agentless-first options, which matters for small security teams.
3. CrowdStrike Falcon Cloud Security
CrowdStrike arrived at CNAPP from the endpoint, and the product still reflects it. Falcon Cloud Security combines agentless posture scanning with the same Falcon sensor that runs on endpoints, so a container process spawning a shell and a laptop doing something unusual land in one detection pipeline with shared threat intelligence behind both. For organisations already running Falcon, cloud coverage is a module rather than a new deployment.
The company describes its approach as adversary-focused — a claim of its own — and says it combines continuous agentless visibility with runtime detection and response. CrowdStrike was named a leader in the 2026 Frost Radar for CNAPP, the fourth consecutive year.
Best for: security teams running Falcon on endpoints who want cloud detections in the same console.
Pros - Shared sensor and threat intelligence across endpoint and cloud, which collapses two detection stacks into one. - Genuine runtime detection and response, not just posture findings with a runtime label. - Repeated independent analyst placement, including leader positioning in the 2026 Frost Radar for CNAPP. - Existing Falcon customers add cloud coverage without a separate agent rollout.
Cons - Much of the advantage evaporates if you are not already a Falcon customer — as a standalone CNAPP it competes on narrower ground. - Agent-based runtime coverage means deployment friction on workloads where teams resist installing sensors. - Pricing is quote-only and module-based, and the platform's overall cost tends to rise as modules accumulate. - Posture and code-scanning breadth is generally considered behind the agentless-native vendors, which had a head start on the graph model.
4. Microsoft Defender for Cloud
Defender for Cloud is the only platform here that publishes its rates. Microsoft's Defender CSPM tier is billed per billable resource — compute, databases, storage and serverless — at roughly $5 per resource per month as of August 2026, prorated hourly, with separate per-plan pricing for servers, containers, databases and APIs. It covers Azure natively and extends to AWS and Google Cloud through connectors.
The practical effect of per-resource, hourly billing is that cost scales with what you actually run and can be modelled in advance. That is unusual in this category and worth real money in a procurement cycle. What you trade away is best-of-breed depth: this is the cloud provider's own security product, competent across a wide surface and exceptional on its home cloud.
Best for: Azure-heavy estates that want predictable, published per-resource pricing.
Pros - Published pricing with hourly proration — the only vendor on this list where you can model spend without a sales conversation. - Native Azure integration, including identity signals from Entra ID that third parties can only approximate through APIs. - Multicloud connectors extend CSPM to AWS and Google Cloud without a separate product. - Included in existing Microsoft enterprise agreements for many buyers, simplifying procurement.
Cons - Coverage depth on AWS and Google Cloud trails what it does on Azure; genuinely multicloud estates often end up supplementing it. - Plan structure is fragmented across servers, containers, storage, databases and APIs, so the bill is predictable per unit but easy to under-scope overall. - Attack-path analysis and graph reasoning are not as mature as Wiz's, which is the feature buyers most often compare. - Enabling the full stack across a large multicloud estate can end up costing more than the headline per-resource rate suggests.
5. Sysdig
Sysdig is the runtime specialist. It created Falco in 2016, donated it to the Cloud Native Computing Foundation in 2017, and saw it graduate in 2024; Sysdig reports Falco has passed 175 million downloads. Sysdig Secure is the commercial platform built on that kernel-level instrumentation, and in November 2025 the company launched Falco Feeds, a curated detection ruleset maintained by its threat research team.
If your risk model is an attacker doing something inside a running container right now — cryptomining, lateral movement, a reverse shell — this is the deepest instrumentation available, and the open-source core means you can inspect how detection actually works rather than trusting a vendor's description of it.
Best for: container-heavy Linux environments where runtime threat detection is the primary concern.
Pros - Built on Falco, a CNCF graduated project, so the detection engine is open source and independently auditable. - Kernel-level syscall visibility gives detection fidelity that snapshot scanning cannot reach. - Falco Feeds provides vendor-maintained detections for teams that do not want to write their own rules. - A large open-source community means public rules, integrations and troubleshooting knowledge exist outside the vendor.
Cons - Agent-based by architecture, so onboarding requires deploying to every cluster and node — slower than the agentless options. - Posture management, entitlement analysis and code scanning are less developed than the runtime side. - No published pricing; enterprise quote only. - Kernel instrumentation demands more operational care than a read-only cloud connector, particularly across mixed kernel versions.
6. Orca Security
Orca pioneered agentless cloud scanning with its patented SideScanning technique, which reads workload storage out of band and reconstructs the software inventory, vulnerabilities, secrets and misconfigurations without running code inside the workload. Nothing is installed, no packets are sent, and coverage is complete rather than limited to the hosts where someone remembered to deploy an agent.
Orca describes its commercial model as a single SKU priced on protected cloud workloads, which is simpler than credit systems even though the rates are not public. The company's position has narrowed as larger vendors added agentless scanning, but the approach remains the lowest-friction way to get full cloud visibility.
Best for: teams that need complete coverage quickly and cannot get agents deployed.
Pros - Zero-install deployment, so coverage extends to workloads no agent rollout would reach. - Single-SKU model avoids per-module credit arithmetic even though rates are quote-only. - No runtime performance overhead on protected workloads, since scanning happens out of band. - Covers posture, vulnerabilities, secrets, identity and compliance in one product.
Cons - Periodic snapshot scanning means live attacker activity is detected later than agent-based tools detect it. - The agentless advantage has been substantially commoditised by Wiz, Microsoft and CrowdStrike adding equivalent capabilities. - Pricing is not published, making comparison against per-resource models difficult. - Smaller company than the platform vendors it competes with, which weighs in long-horizon enterprise procurement.
7. Upwind
Upwind is the newest platform here and the one arguing hardest against the prevailing design. Its position is that agentless posture scanning produces too many findings without the context to rank them, so Upwind leads with a lightweight eBPF runtime sensor and uses live process, network and API behaviour to decide which risks are actually reachable. Vulnerability findings get filtered by whether the affected package is loaded and executing.
Investors have moved quickly. Upwind raised $250 million at a $1.5 billion valuation in January 2026, then roughly $300 million at about $3.8 billion in September — a valuation that more than doubled in under eight months, led by Bessemer Venture Partners and TCV.
Best for: teams drowning in posture alerts who want runtime evidence to rank them.
Pros - Runtime-derived context filters vulnerability findings down to what is actually loaded and executing. - eBPF sensor is lighter than traditional kernel modules and covers containers, VMs and serverless. - Well capitalised after roughly $550 million raised across two 2026 rounds, which reduces near-term viability risk. - Extends runtime context to APIs and data flows, not just workload processes.
Cons - The youngest platform on this list, with correspondingly less enterprise deployment history at very large scale. - Sensor-based deployment carries the same rollout friction as Sysdig's, contrary to the agentless trend. - No published pricing and a shorter track record of negotiated enterprise terms. - A $3.8 billion valuation eight months after a $1.5 billion round sets expectations that constrain future pricing and independence.
How to choose
If you need visibility across several clouds and you need it this quarter, Wiz or Orca will get you there fastest, with the caveat that Wiz's ownership now sits inside Google Cloud.
If your threat model is active compromise of running workloads — container escapes, cryptomining, lateral movement — weight runtime depth and look at Sysdig, CrowdStrike or Upwind. Agentless scanning will tell you the door was unlocked; it will not reliably tell you someone walked through it.
If you already own a platform, use it. Falcon customers should evaluate Falcon Cloud Security before anything else. Palo Alto shops should evaluate Cortex Cloud. Azure-centric organisations should start with Defender for Cloud, if only because it is the one option you can price before the first call.
If finance needs a forecastable number, Defender for Cloud is the only platform here with published per-resource rates. Everything else is a negotiation.
One name worth adding to a shortlist that did not make this seven: Aqua Security, whose open-source Trivy scanner is embedded in a very large number of CI pipelines and is the easiest way to put container scanning in front of deployment without buying a platform first.
Whichever you pick, the security question that has moved fastest this year sits one layer up: the same teams evaluating CNAPP are now also being asked to secure model traffic, which is a different problem with a different set of vendors. Platform teams standardising cloud access controls alongside developer workflow should also look at how this overlaps with internal developer platforms, where policy enforcement increasingly lives.
Frequently Asked Questions
What does CNAPP stand for?
CNAPP stands for cloud-native application protection platform. Gartner introduced the term to describe products that combine cloud security posture management, cloud workload protection, identity and entitlement management, and pre-deployment code scanning in a single platform, rather than requiring separate tools for each function.
Is agentless or agent-based CNAPP better?
Neither is universally better. Agentless scanning deploys in hours and reaches every workload, but detects activity periodically rather than live. Agent-based runtime sensors see kernel-level events as they happen but require rollout to every node. Most leading platforms now offer both and let buyers choose per workload.
Does Google owning Wiz affect AWS and Azure customers?
Google stated when the acquisition closed in March 2026 that Wiz would retain its brand and continue supporting AWS, Azure and Oracle Cloud. Multicloud support is unchanged in product terms. Whether a hyperscaler-owned security tool remains a comfortable choice for organisations standardised on competing clouds is a procurement judgement, not a technical one.
How much does a CNAPP platform cost?
Only Microsoft publishes rates: Defender CSPM runs roughly $5 per billable resource per month as of August 2026, with separate per-plan pricing for servers, containers and databases. Every other vendor on this list quotes privately, with pricing driven by workload counts, enabled modules and negotiated contract terms.
Can one CNAPP replace all cloud security tools?
Not entirely. A CNAPP consolidates posture, workload, identity and code scanning, but most organisations still run separate tooling for network security, SIEM, secrets management and application security testing. Cortex Cloud's SOC integration is the most direct attempt to extend a CNAPP into security operations.
Editor's note — sources: Google Cloud acquisition announcement; Cybersecurity Dive on the $32B close; Dell'Oro Group on the Prisma-to-Cortex shift; CrowdStrike CNAPP product documentation; Microsoft Defender for Cloud pricing; Sysdig on Falco; Orca SideScanning; TechCrunch on Upwind's Series B; Bloomberg on Upwind's $3.8B round. Pricing and feature claims are stated as of September 2026.