Cloud Security Compare

Buyer note

FedRAMP, GovRAMP, EPSS, SBOM and CVE: the public standards behind CNAPP claims

Cloud Security Compare editors · · Editorial assessment

The short version

Five public standards and programs come up repeatedly in CNAPP material: CVE identifiers for vulnerabilities, EPSS for exploit likelihood, SBOMs for software inventories, and FedRAMP and GovRAMP authorizations for selling to US government, both assessed against NIST SP 800-53 controls. They are useful because they are defined outside any vendor, but each one answers a narrower question than the claim it is attached to.

Why do public standards matter in a comparison?

Most of what a CNAPP vendor publishes is its own description of its own product. A public standard is different: it is defined and maintained by a body outside the vendor, so two vendors that cite it are describing the same thing. That makes standards useful anchors in a comparison. The catch is that citing a standard says only that a product uses or holds it, not how well it uses it.

What are CVE and EPSS?

CVE, run by the CVE Program, gives each publicly disclosed vulnerability an identifier. Almost every vulnerability finding in a CNAPP refers to a CVE, so it is the common key when you compare two products' findings on the same workload. EPSS, run by a special interest group at FIRST, estimates the probability that a published CVE will be exploited in the wild in the next 30 days. Aqua Security names EPSS among the inputs it uses to rank vulnerabilities, alongside reachability and evidence of active exploitation.

In a proof of concept, CVE identifiers let you line up two products' vulnerability lists for the same workload and see which findings one product ranks high and the other ranks low. Exploit-likelihood inputs such as EPSS are one reason two products can rank the same CVE differently.

What is an SBOM, and where does it appear?

A software bill of materials is, in CISA's description, a nested inventory of the ingredients that make up software components. In CNAPPs, SBOMs appear in the code module: Wiz Code lists SCA and SBOM, and Upwind lists SCA and SBOM among its modules. An SBOM tells you what is inside an application or image; the scanner compares that list with known vulnerabilities. If customers or auditors will ask you for SBOMs, ask whether the product can export them.

What do FedRAMP and GovRAMP authorizations mean?

FedRAMP is the US federal government's authorization program for cloud services. GovRAMP plays a similar role for US state and local government. Both assess a cloud service against controls from NIST SP 800-53. Among the vendors we compare, Aqua Security lists FedRAMP High authorization, and Wiz says Wiz for Gov achieved GovRAMP High authorization on 10 September 2026, validated against NIST SP 800-53 revision 5 controls. Upwind's newsroom said in November 2025 that it was pursuing FedRAMP.

Two points matter to a buyer. Authorizations apply to a specific offering, such as Wiz for Gov rather than every Wiz deployment, so check which one you are being sold. And the level matters: High is the most demanding baseline. If you do not sell to or work for US government, an authorization is a signal of control maturity rather than a requirement.

What do the open-source projects add?

Two open-source projects sit under commercial products in this market. Falco, created by Sysdig, is a CNCF graduated project, the Cloud Native Computing Foundation's highest maturity level. Trivy is maintained by Aqua Security under the Apache-2.0 license. Neither is a standard in the formal sense, but both give buyers a public reference point: you can read the detection rules or the scanner's behavior before talking to the vendor.

How should you use standards in an evaluation?

  • Use CVE identifiers to line up two products' findings on the same workload.
  • Ask which exploit-likelihood inputs, such as EPSS, feed the ranking, and whether you can see them per finding.
  • Ask for SBOM export if customers or auditors will ask you for one.
  • Check that any authorization covers the exact offering and region you are buying.
  • Treat a cited standard as the start of a question, not the answer.

Sources

Related pages