University
CNAPP buyer university: glossary and short lessons
Cloud Security Compare editors · Matchups reviewed September 2026 · Editorial assessment
The short version
Ten short lessons in three tracks, from what a CNAPP's modules do to running one after purchase, and a glossary of 36 terms used across this site. Each lesson takes a few minutes and links to the comparisons it supports.
Which lesson should you start with?
Start with Basics if you are comparing CNAPPs for the first time. Go straight to Buying if you already have a shortlist, and to Running it once a platform is in place.
Track 1: Basics
What the modules in a CNAPP do, how vendors rank risk and what the code scanners find.
LESSON 1 · 2 MIN READ
Which CNAPP modules should you compare first?
A CNAPP bundles posture, workload, identity, data, code, AI and detection modules. Compare the ones that match why you are buying, and use the rest as tie-breakers.
LESSON 2 · 3 MIN READ
How CNAPPs rank risk: severity, exploitability and attack paths
Severity scores, exploit likelihood, runtime context and attack paths: the inputs CNAPPs combine to decide which findings to fix first, and how to test them.
LESSON 3 · 2 MIN READ
Code security in a CNAPP: SCA, SAST, IaC, secrets and code-to-cloud
The code scanners inside a CNAPP, what each one finds, and why tracing a cloud finding back to its repository and owner is the part to test.
Track 2: Buying
From a long list to two names, a scoring sheet and written questions for both vendors.
LESSON 4 · 2 MIN READ
From nine vendors to two: building a CNAPP shortlist
Three filters that take a cloud security long list down to two names: the clouds you run, the security stack you already own, and the one criterion you will not compromise on.
LESSON 5 · 2 MIN READ
Reading CNAPP vendor claims: capabilities, percentages and customer counts
Vendor pages mix capability statements, performance claims and market claims. Only the first can be tested in a proof of concept, and it is the only kind this site scores.
LESSON 6 · 2 MIN READ
Writing a CNAPP scoring sheet with your own weights
Turn requirements into weighted criteria before any vendor demo: how to pick criteria, set weights, decide what counts as evidence and handle ties.
LESSON 7 · 2 MIN READ
Questions to put to CNAPP vendors in writing
Written questions for two shortlisted CNAPP vendors on coverage, runtime, prioritization, code, AI, ownership and pricing, and why both get the same questions.
Track 3: Running it
Rolling out a sensor, measuring results and knowing when to review the decision.
LESSON 8 · 2 MIN READ
Rolling out a runtime sensor: from one cluster to the estate
A staged plan for deploying a CNAPP runtime sensor: pick a first cluster, measure overhead, tune detections, then decide where blocking is switched on.
LESSON 9 · 2 MIN READ
Measuring a CNAPP after rollout: coverage, fix time and noise
Four measures that show whether a cloud security platform is working after purchase: coverage, time to fix, alert quality and fixes made in code.
LESSON 10 · 2 MIN READ
When to re-review a CNAPP decision
Renewals, acquisitions, product mergers and changes to free tiers are the moments to re-run a CNAPP comparison. How to do it without starting from scratch.
Where are the definitions?
Glossary
36 terms, from admission controller to weighted total, with sources for terms that come from a standard or a public body.
Where are the questions and answers?
FAQ
26 common questions about CNAPPs, buying, each vendor and how this site scores, each linked to the page that goes deeper.