CNAPP was supposed to be the answer to multi-cloud security sprawl. The pitch from 2021 was one platform, one agent, one data lake, one console. Five years later the category has split into four overlapping sub-markets, the platforms are stitching them back together, and the buyers are asking why they are paying for a single product that contains four products that do not share a database.
This is the field guide. The goal is to explain what each piece does, where they overlap, where they do not, and what to actually look at if you are buying in 2026.

What CNAPP was supposed to be
Gartner coined the term in 2021 to describe a platform that consolidates four cloud security functions. Cloud security posture management (CSPM). Cloud infrastructure entitlement management (CIEM). Container security. Cloud workload protection (CWPP). The promise was that these were all looking at the same cloud, the same workloads, the same identities, and they should be looking at them together. One agent. One data model. One UI.
The first wave of CNAPP vendors had different ideas about which of the four to lead with. Wiz led with agentless CSPM scanning. Palo Alto Prisma Cloud led with CWPP. Lacework led with behavioral baselining. They all claimed the whole thing. None of them actually delivered all of it on day one.
What the category looks like in 2026
The category has split. The current state, roughly:
CSPM is the oldest piece. It scans cloud configurations against best practices and regulatory frameworks. It produces findings, not incidents. A misconfigured S3 bucket. A public-facing database. An IAM role with too many permissions. Most CSPMs are good at this now. The differentiation is in how they prioritize the findings, not in finding them.
CIEM is the entitlements piece. It answers the question of who can do what in your cloud. This turned out to be much harder than anyone expected. Effective CIEM requires understanding the effective permission graph, not just the assigned permissions, and that graph is huge. The vendors that did this well built it on graph databases. The vendors that faked it produced long lists of unused permissions and called it a feature.
DSPM (data security posture management) is the newer addition. It answers where your sensitive data is in the cloud and who can access it. This is the sub-category that grew the most in 2024 and 2025, partly because GDPR enforcement and the US state privacy laws made data mapping a board-level concern. The good DSPM tools can scan structured and unstructured data stores and classify what is in them. The bad ones are glorified regex matchers.
CWPP is the runtime piece. It monitors workloads (VMs, containers, serverless functions) for runtime threats. This is closest to traditional endpoint security, but in the cloud. The interesting work is in containers and Kubernetes, where the workload lifecycle is short and the attack surface is the orchestration layer, not the OS.
CIEM and DSPM merged in a few vendors. Wiz acquired a DSPM startup in 2024. Palo Alto folded DSPM into Prisma Cloud. Microsoft bought both a Sufficient and a CIEM vendor. The buyers wanted one pane of glass. The vendors delivered it by acquisition, not by integration.
The integration problem
This is the part the marketing does not want you to look at. A vendor that acquired a DSPM company in 2024 and tells you it has a unified data model in 2026 is, in most cases, lying. The acquisition bought a logo. The integration is partial. The findings from CSPM and the findings from DSPM live in different databases. The UI shows them together. The queries underneath are separate. You find this out the first time you try to do something the UI does not support, which is usually within the first month.
The way to test this. Pick a real workload in your cloud. Ask the platform to tell you everything about it. The configuration findings, the entitlements, the data classification, the runtime alerts. If the answer comes back in under 60 seconds from a single query, the platform has done the integration work. If the answer takes longer or requires you to click into four different tabs, it has not.
What to actually look for if you are buying
The buying criteria that matter in 2026:
Effective permissions, not assigned permissions. The CIEM feature is the make-or-break. If the platform cannot tell you what an identity can actually do across your cloud accounts, it is not a CNAPP. It is a CSPM with entitlement marketing.
Container and Kubernetes support that goes beyond the cluster. The runtime layer is where the new attacks are. A platform that only scans your EKS clusters for misconfigurations is missing the workload-level threats. Look for runtime threat detection, not just configuration scanning.
A data model you can query. If the platform is opaque, you cannot extend it. Look for SQL or GraphQL access, not just a UI. The vendors that expose a query layer are the ones that have done the integration work.
Compliance report generation that does not require a contractor. The frameworks (PCI, HIPAA, SOC 2, ISO 27001, the new EU AI Act obligations) all need evidence. If the platform produces a 200-page PDF and calls it done, you will spend the next quarter arguing with your auditor about the findings. If it produces a working evidence trail with source data, the audit is faster.
Pricing that does not punish you for growing. A lot of these vendors price by workload or by data volume. When you scale, the bill scales faster than the value. Lock the pricing model in writing, including the per-workload unit, the per-data-volume unit, and the cap.
The bottom line
CNAPP is the right idea executed in the wrong order. The platforms that did the integration work are useful. The platforms that did the marketing work are not. Ask the integration question, the effective permissions question, and the data model question. The answers will tell you which category the vendor is in. The 2026 buyers who skip these questions are the 2027 buyers complaining about the renewal.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor technical disclosures, and Gartner market research. CNAPP category definition from Gartner’s 2021 Hype Cycle for Cloud Security. The four sub-markets (CSPM, CIEM, DSPM, CWPP) are tracked separately in the 2025 and 2026 Gartner Magic Quadrants for Cloud Native Application Protection Platforms. The integration test described in “The integration problem” is drawn from the CSA Cloud Controls Matrix v4.0 cross-domain query recommendations.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



