Lesson 1 · Basics · 2 min read
Which CNAPP modules should you compare first?
Cloud Security Compare editors · Matchups reviewed September 2026 · Editorial assessment
The short version
Compare the modules that match the reason you are buying, and treat the rest as tie-breakers. Replacing a posture tool means comparing posture and risk ranking first; a workload incident means comparing runtime first; developer-owned fixes mean comparing code-to-cloud tracing first.
What are the main modules?
- Posture (CSPM): misconfigurations and compliance across cloud accounts.
- Workload protection (CWPP): vulnerabilities, malware and runtime threats inside VMs, containers and serverless functions.
- Identity (CIEM): excess permissions and risky identities.
- Data (DSPM): where sensitive data sits and who can reach it.
- Code: SCA, SAST, IaC and secrets scanning, and tracing cloud risk back to code.
- AI (AI-SPM): inventory and posture for models, AI services and agents.
- Detection and response (CDR): threats in cloud activity and workloads.
Which should you compare first?
Start from the reason for the purchase. If you are replacing a posture tool, compare posture coverage and risk prioritization first. If you had an incident inside a workload, compare runtime depth first. If developers own most fixes, compare code-to-cloud tracing. Our seven criteria follow the same logic: agentless coverage and risk prioritization carry the most weight (18% each) because they apply to almost every buyer, and runtime protection (16%) comes next.
What should you do with the other modules?
Once two vendors are close on the modules you care about, use the others to break the tie. Then check that every module you need is in the plan you are quoted. At Microsoft Defender for Cloud, for example, attack path analysis and agentless scanning are in the paid Defender CSPM plan, not the free Foundational CSPM tier.
How do the modules show up in our criteria?
Our seven criteria map onto the modules rather than copying them. Agentless coverage and runtime protection split workload protection by method. Risk prioritization sits on top of posture, identity and data findings and asks how well they are combined into attack paths. Code-to-cloud covers the code module, AI workload security the AI module, and detection and response is scored inside runtime. Ecosystem and pricing transparency are not modules at all; they describe the vendor rather than the product. That is why a vendor can have every module and still trail on a criterion: having a module is not the same as leading on it.
Which questions tell you a module is real?
- Is it included in the plan you are being quoted, or sold separately?
- Is it generally available, or a preview?
- Does it cover every cloud you run, or only some?
- Can you test it in your proof of concept, on your own accounts?
Related pages
- How to read these comparisonsThe seven criteria and their weights
- Comparison matrixEvery vendor on every criterion
- GlossaryAll module names defined
- How CNAPPs rank riskThe next lesson
Next lesson: How CNAPPs rank risk: severity, exploitability and attack paths