Lesson 3 · Basics · 2 min read
Code security in a CNAPP: SCA, SAST, IaC, secrets and code-to-cloud
Cloud Security Compare editors · Matchups reviewed September 2026 · Editorial assessment
The short version
A CNAPP's code module usually bundles several scanners: software composition analysis for vulnerable packages, static analysis for flaws in your own code, infrastructure-as-code checks, secrets scanning and container image scanning. What separates vendors is less the scanner list than whether a problem found in the cloud can be traced back to the file and the team that caused it.
What does each scanner find?
- SCA: open-source and third-party packages with known vulnerabilities, often recorded in an SBOM.
- SAST: flaws in the code your team wrote, found without running it.
- IaC scanning: misconfigurations in infrastructure templates before they reach an account.
- Secrets scanning: credentials stored in code, images or disks.
- Container image scanning: vulnerable packages and secrets inside image layers.
- DAST: flaws in a running application, found by sending it requests.
Why does code-to-cloud tracing matter more than the scanner list?
Many cloud misconfigurations and vulnerabilities start in code: a Terraform module that creates an open storage bucket, a base image with an old library. If the fix is made in the console, the next deployment brings the problem back. Code-to-cloud tracing links the running resource to the repository, file and owner, so the fix goes into the source and stays fixed. It also routes the work to the team that can do it, rather than to a central security queue.
What do the vendors list?
Scanner lists vary. Orca Security lists SCM posture, SCA, SAST, secrets, IaC and container image scanning, with GitHub, GitLab and Azure DevOps, and cloud-to-code tracing that opens pull requests. Wiz Code lists SCA and SBOM, IaC, secrets and malware scanning, IDE and GitHub integration, ASPM and code-to-cloud tracing. Upwind lists IaC security, SCA and SBOM, DAST and a container admission controller; SAST is not among its listed modules. Aqua Security scans images and repositories and blocks noncompliant artifacts in the pipeline. CrowdStrike's code coverage centers on ASPM, mapping business applications onto cloud infrastructure. The vendor-by-vendor view, with scores, is in our note on code-to-cloud security in CNAPPs.
What should you test?
- Connect the same repositories and CI systems to both products.
- Pick one real cloud finding and ask each product to trace it to a file and an owner.
- Check whether a fix can be proposed as a pull request, and who approves it.
- Check how findings from code and from the cloud are merged, so one problem becomes one ticket.
How is code security scored on this site?
Our code-to-cloud and AppSec criterion carries a 14% weight. It scores the breadth of scanners a vendor lists and, more heavily, whether a cloud risk can be traced back to the code and owner that caused it. Wiz leads at 4.6, with Cortex Cloud at 4.5 and Orca Security at 4.4. Sysdig scores lowest at 3.4, because source-code scanning is not a stated focus on the pages we reviewed.
Related pages
- Code-to-cloud security in CNAPPsWhat nine vendors scan
- Glossary: code-to-cloud tracingThe term in one paragraph
- Wiz vs Prisma CloudThe two code-security leaders head to head
Next lesson: From nine vendors to two: building a CNAPP shortlist