Buyer notes
Buyer notes on comparing cloud security platforms
Cloud Security Compare editors · Matchups reviewed September 2026 · Editorial assessment
The short version
Buyer notes go one level below the head-to-heads: how to test two shortlisted vendors, what changed in the market this year, how nine vendors cover one criterion in detail, and which public standards sit behind vendor claims. Each note is desk research from public vendor material, dated, with its sources listed at the end.
FedRAMP, GovRAMP, EPSS, SBOM and CVE: the public standards behind CNAPP claims
Which public standards and programs appear in cloud security vendor claims, what each one means, and which of the nine vendors we compare cite them.
Six CNAPP comparison myths, checked against vendor pages
Agentless means no sensor, Google owns Wiz so it is Google-only, Prisma Cloud is still sold, free CSPM is a free CNAPP: six common assumptions checked against vendor material.
Code-to-cloud security in CNAPPs: what nine vendors scan
Which CNAPPs list SCA, SAST, IaC, secrets and image scanning, which trace cloud risks back to code, and how nine vendors score on our code-to-cloud criterion.
Risk prioritization in CNAPPs: how nine vendors decide what to fix first
Attack paths, exploit validation, runtime context and adversary intelligence: how nine CNAPPs describe ranking findings, with our risk prioritization scores.
What changed for CNAPP buyers in 2026: nine months of vendor news
Google now owns Wiz, Upwind raised a $250 million Series B, Defender for Cloud changes its free tier and vendors shipped AI agents. What each 2026 change means for a CNAPP evaluation.
Runtime protection in CNAPPs: how nine vendors detect and block attacks
How Wiz, Orca, Upwind, Cortex Cloud, Defender for Cloud, CrowdStrike, SentinelOne, Sysdig and Aqua describe runtime detection and blocking, with our runtime scores.
AI workload security in CNAPPs: what nine vendors say they cover
What Wiz, Orca, Upwind, Cortex Cloud, Defender for Cloud, CrowdStrike, SentinelOne, Aqua and Sysdig publish about AI-SPM, AI-BOM, MCP servers and AI runtime detection.
How to run a CNAPP proof of concept between two shortlisted vendors
A practical plan for a CNAPP proof of concept: fix scope and weights first, then test agentless coverage, runtime, risk ranking, code, AI and cost the same way for both vendors.