Lesson 6 · Buying · 2 min read
Writing a CNAPP scoring sheet with your own weights
Cloud Security Compare editors · Matchups reviewed September 2026 · Editorial assessment
The short version
A scoring sheet is the list of criteria you will judge vendors on, the weight each carries and the evidence that counts, written down before any vendor presents. Start from our seven criteria, change the weights to fit your estate, and agree how ties and missing evidence are scored. The sheet is what turns a proof of concept into a comparison rather than two demos.
Which criteria should go on the sheet?
Start from the reason for the purchase and the modules it touches, then add the vendor-level criteria that matter to your organization. Our seven are a reasonable default for a multicloud buyer: agentless coverage and time to value, runtime protection depth, risk prioritization and attack paths, code-to-cloud and AppSec, AI workload security, ecosystem and integrations, and pricing transparency. Remove any criterion you would not act on. If AI workloads are out of scope for the next two years, a 12% weight on AI security only adds noise.
How should you set the weights?
Give the heaviest weights to the criteria that would make you reject a vendor on their own. Our default puts 18% each on agentless coverage and risk prioritization and 16% on runtime, because nearly every buyer needs coverage and a usable fix list. A Kubernetes-heavy team that must block attacks inside containers might move runtime to the top. An Azure-first team with a fixed budget might raise pricing transparency. Set the weights with the people who will sign off the purchase, and fix them before you see results.
The score calculator lets you try weights against our criterion scores and see how the order of nine platforms changes. If a small change in weights swaps your top two, the decision will turn on the proof of concept, not on the sheet.
What counts as evidence?
- What you saw on your own accounts during the proof of concept.
- Documentation for generally available features in the plan you are quoted.
- Written answers from the vendor to your written questions.
Demos, roadmaps and vendor performance claims do not score until you can reproduce them. We apply the same rule: our scores come from public vendor material, and vendor claims such as detection times are attributed to the vendor rather than scored.
How do you handle ties and gaps?
Score each criterion 0 to 5 with a one-line reason, and treat equal scores as ties rather than forcing a winner. Where a vendor could not show something, score what you saw and note why. Keep the reasons with the sheet: when someone asks why you chose the product that scored lower on one criterion, the reasons are the answer. Our head-to-head pages use the same structure, one written reason per score.
Related pages
- Score calculatorTry your weights on nine platforms
- How to read these comparisonsOur rubric and tie rules
- How to run a CNAPP proof of conceptWhere the sheet gets used
Next lesson: Questions to put to CNAPP vendors in writing