{"kind":"atlas-fold-public-documentation-research","notice":"Provisional editorial anchored assessments in tenths (0.0–5.0), not hands-on effectiveness or purchasing recommendations. Fractional scores include shared rubric criteria and credited source evidence. Unknown scores remain null. Compare only within the same segment, cohort and rubric version.","methodology":"https://atlasofsecurity.com/landscape/explore/methodology/","segment":{"slug":"cloud-security","name":"Cloud & workload security","short":"CNAPP / CSPM"},"reviewedAt":"2026-09-21","rubricVersion":"1.1","cohorts":[{"id":"cnapp-posture-platforms","name":"CNAPP and cloud posture platforms","scope":"Comparable independently sold CNAPP/posture platforms with agentless cloud inventory plus optional runtime sensors: Wiz, Palo Alto Networks Cortex Cloud (Prisma Cloud lineage; not a separate prisma-cloud catalog slug), Microsoft Defender for Cloud, and Orca Security. Excludes native-only CSP suites (AWS Security Hub, Google Security Command Center), runtime-first specialists scored elsewhere, managed SOC services, and CyberArk/Idira identity products. Agentless API or snapshot findings are not live process coverage. Preview features are not scored as GA. Cohort baseline is agentless CSPM plus optional runtime sensing plus some graph or attack-path context."}],"dimensions":[{"id":"maturity","name":"Operational maturity","question":"How completely do public operator docs describe safeguards for connectors, sensors, coverage gaps, and lifecycle change?","description":"Scores documented operating safeguards only: onboarding permissions, connector or sensor health, rollback, and how a missing collector is distinguished from a clean finding. Does not score vendor age, uptime, staffing, or measured reliability.","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide operating safeguards for the scoped assessment workflow. Missing evidence is unknown, never zero.","1: A concrete basic operating safeguard is documented for the evaluated edition.","2: Documented connector permissions, data handling, and enablement prerequisites for a bounded lab.","3: Documented connector or sensor health or status plus documented removal or rollback of integrations.","4: Documented coverage-gap visibility that distinguishes a missing connector or sensor from a clean finding, plus lifecycle or enablement notices.","5: Documented multi-control operating model covering connector and sensor health, account onboarding, module changes, and continuity together."]},{"id":"innovation","name":"Shipped innovation","question":"Which current baseline workflows are supported, and is any concrete shipped difference from that shared baseline established?","description":"Ordinal evidence of shipped workflows against a contemporary shared cohort baseline. Stage 3 means supported baseline workflows, not novelty or superiority. Higher stages require concrete generally available differences supported by comparative primary evidence. Multicloud posture and vulnerability assessment, identity/data context, graph or attack-path investigation, optional runtime telemetry, and routing or remediation orchestration are contemporary CNAPP baseline capabilities. Graph views, SideScanning architecture, plan packaging and a runtime sensor alone do not establish differentiated operator workflows.","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide a shipped workflow within the scoped cohort. Missing evidence is unknown, never zero.","1: One basic in-scope workflow is confirmed shipped; no broader stage is established.","2: Several baseline components are confirmed shipped, but an integrated contemporary baseline workflow is not established.","3: An integrated contemporary baseline workflow is supported by primary evidence; this stage makes no differentiation or novelty claim.","4: Stage 3 plus one concrete generally available operator workflow difference beyond the shared contemporary baseline, supported by comparative primary evidence.","5: Stage 4 plus multiple complementary generally available workflow differences beyond that baseline, with their boundaries and prerequisites established."]},{"id":"breadth","name":"Capability breadth","question":"How many distinct CNAPP capability areas are documented, with module and cloud dependencies made explicit?","description":"Scores documented capability areas (posture, identity, workload or runtime, code, data) and whether coverage depends on separate plans, sensors, or clouds. Does not score efficacy or completeness of every cloud service.","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide an in-scope assessment capability. Missing evidence is unknown, never zero.","1: A bounded in-scope capability is documented for one environment or workflow.","2: CSPM plus one of runtime or CWPP, CIEM, or code/IaC.","3: Multicloud posture plus at least two of runtime, CIEM, vulnerability, or code.","4: Documented CNAPP span across posture, identity, workload or runtime, and code or data, with module dependencies explicit.","5: Broad CNAPP including DSPM, AI posture, or CDR with documented coverage matrices per cloud or workload type."]},{"id":"ecosystem","name":"Ecosystem & integration","question":"Which cloud, identity, pipeline, and SOC integrations are documented with explicit scope?","description":"Scores documented connectors and exports to clouds, identity providers, repositories or pipelines, and ticketing or SIEM systems. Preview integrations are not treated as GA.","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide an integration or supported data handoff. Missing evidence is unknown, never zero.","1: A concrete native connector or supported manual integration is documented.","2: Multiple major cloud connectors (AWS, Azure, GCP, or equivalent) are documented.","3: Cloud connectors plus ticketing, SIEM, or export integrations.","4: Documented ecosystem spanning clouds, identity or repos/pipelines, and SOC or ticketing, with some scope notes.","5: Broad documented integration catalog including IaC or repos, SIEM or SOAR, identity, and multiple clouds with explicit per-integration boundaries."]},{"id":"governance","name":"Governance & control","question":"What policy, RBAC, exception, owner-routing, and evidence-export controls are documented?","description":"Scores documented policy customization, role isolation, framework mappings (not certifications), exception handling, and export for independent review. Mappings do not prove audit success.","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide an administrative or policy control. Missing evidence is unknown, never zero.","1: A specific administrative control is documented for the scoped workflow.","2: Documented policy frameworks or compliance mappings (not a certification claim).","3: Custom policies plus RBAC or tenant isolation documented.","4: Framework mappings, custom or assignable policy, RBAC, and evidence export for review.","5: Documented governance including owner assignment or exception workflow, policy controls, RBAC, and evidence export together."]},{"id":"operations","name":"Operator enablement","question":"Do public docs enable an operator to onboard, investigate, route ownership, and see coverage gaps without treating marketing as a runbook?","description":"Scores operator-facing onboarding, investigation, remediation routing, and coverage-health documentation. Does not score staffing savings or measured mean-time-to-remediate.","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide a supported operator action or guidance path. Missing evidence is unknown, never zero.","1: A concrete operator action and its basic use are documented.","2: Documented onboarding of a cloud account or subscription.","3: Investigation or remediation workflow docs that take a finding to an owner or correction path.","4: Operator docs covering inventory versus runtime distinction, health or coverage, and routing to owners.","5: Runbooks for connector and sensor health, coverage gaps, export, and lifecycle or module-change operations together."]}],"assessments":[{"vendor":"wiz","cohort":"cnapp-posture-platforms","edition":"Wiz platform (agentless CNAPP plus separately deployed Wiz Sensor)","asOf":"2026-09-21","status":"research-preview","summary":"Public pages document API-first agentless inventory, a Security Graph investigation path, code-to-cloud ownership, and a separately deployed runtime sensor whose coverage must be mapped rather than assumed from account connection. Tenant operator runbooks on docs.wiz.io were not independently readable in this pass.","dimensions":{"maturity":{"score":null,"confidence":"low","rationale":"Public pages describe account connections and inventory/sensor scope. Connector-health and removal or rollback instructions required by the cumulative rubric were not independently readable behind the documentation checkpoint. Operating safeguards remain unknown, not absent.","sourceIds":["wiz-s1","wiz-s2"]},"innovation":{"score":3,"confidence":"low","rationale":"The cited pages support cloud risk/context investigation with ownership and remediation routing, matching contemporary cohort baseline workflows (stage 3). No supported difference beyond that shared baseline is established. This is not a novelty or superiority claim; preview, beta, AI branding and unverified agentic features are excluded.","sourceIds":["wiz-s1","wiz-s2"]},"breadth":{"score":4,"confidence":"medium","rationale":"Anchor 4: documented areas include agentless CSPM, identities, vulnerabilities, IaC/code, attack paths, and separately deployed runtime protection. DSPM and AI inventory are described on the platform page without a Microsoft-style per-cloud GA matrix, so anchor 5 is not met.","sourceIds":["wiz-s1","wiz-s2"]},"ecosystem":{"score":4,"confidence":"medium","rationale":"The official evaluation FAQ names cloud, repository/pipeline, identity, ticketing and SIEM/SOAR connections, confirming stage 4. The dynamic integration catalog did not expose individual entries to the reader in this pass. Per-integration permission and data-handling boundaries remain unverified, so the broad catalog alone does not earn stage 5.","sourceIds":["wiz-s1","wiz-s3","wiz-s4"]},"governance":{"score":null,"confidence":"low","rationale":"The public platform page describes ownership and role concepts, but gated operator documentation prevented verification of the cumulative policy, RBAC and evidence-export requirements. Product governance remains unknown in this public evidence pass.","sourceIds":["wiz-s1"]},"operations":{"score":null,"confidence":"low","rationale":"The public pages describe graph investigation, ownership routing and sensor coverage. They do not verify the cloud-account onboarding procedure and operating guidance required by earlier cumulative stages; detailed operator docs were gated. Operator enablement remains unknown rather than inferred from product-page workflows.","sourceIds":["wiz-s1","wiz-s2"]}},"constraints":["Evaluated edition is the Wiz platform plus optional Wiz Sensor; agentless API or snapshot visibility is not runtime monitoring.","docs.wiz.io returned a Vercel security checkpoint during this review; connector permission matrices, sensor OS support, and rollback steps remain unverified from primary docs.","Google completed a Wiz acquisition in 2026; brand retention is catalog context only and is not scored.","Sensor deployment, supported kernels, and module packaging are unverified from public operator docs.","Plans, SKU splits, and data-processing locations are unverified.","Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition.","Unknown dimensions reflect incomplete evidence for cumulative stage requirements, not proof that capabilities are absent."],"sources":[{"id":"wiz-s1","title":"Wiz Cloud and AI Security Platform","url":"https://www.wiz.io/platform","accessedAt":"2026-09-21","kind":"documentation"},{"id":"wiz-s2","title":"Wiz Runtime Sensor","url":"https://www.wiz.io/solutions/runtime-sensor","accessedAt":"2026-09-21","kind":"documentation"},{"id":"wiz-s3","title":"Wiz Integrations","url":"https://www.wiz.io/integrations","accessedAt":"2026-09-21","kind":"documentation"},{"id":"wiz-s4","title":"Wiz evaluation FAQ: scope and integrations","url":"https://www.wiz.io/academy/cloud-security/how-to-evaluate-wiz-faq","accessedAt":"2026-09-21","kind":"product"}],"name":"Wiz","company":"Wiz","profileUrl":"/landscape/vendors/wiz/"},{"vendor":"palo-alto-cortex-cloud","cohort":"cnapp-posture-platforms","edition":"Cortex Cloud (Cloud Posture Security and/or Cloud Runtime Security; Prisma Cloud lineage)","asOf":"2026-09-21","status":"research-preview","summary":"Cortex Cloud docs describe CSP onboarding with always-on asset discovery and CSPM, optional runtime and identity or data modules, connection health distinct from completed discovery, and investigation via cases, XQL, and graph search. Application code scanning is an add-on; Prisma Cloud remains a lineage name, not a separate catalog slug.","dimensions":{"maturity":{"score":4,"confidence":"medium","rationale":"Anchor 4: onboarding docs distinguish Connected (trust established) from completed resource discovery, run connection health checks for permission or quota issues, expire pending templates, and keep excluded accounts visible as excluded rather than silently clean. Capability selection is encoded in the auth template. A full continuity runbook across every module change is not documented as a single operating model, so this is not anchor 5.","sourceIds":["pan-s2","pan-s5"]},"innovation":{"score":3,"confidence":"low","rationale":"The cited pages support posture/runtime investigation, cases and graph-assisted remediation workflows, matching contemporary cohort baseline workflows (stage 3). No supported difference beyond that shared baseline is established. This is not a novelty or superiority claim; preview, beta, AI branding and unverified agentic features are excluded.","sourceIds":["pan-s1","pan-s3","pan-s4"]},"breadth":{"score":4,"confidence":"medium","rationale":"Anchor 4: docs cover always-on CSPM, optional runtime, identity, data security, WAAS, serverless, ASM, vulnerability management, and application security with explicit license splits. DSPM and AI-SPM appear as optional or datasheet capabilities without a per-cloud GA matrix comparable to Defender for Cloud, so anchor 5 is not scored.","sourceIds":["pan-s1","pan-s2","pan-s3"]},"ecosystem":{"score":4,"confidence":"medium","rationale":"Anchor 4: CSP onboarding documents AWS, Azure, GCP, OCI, and Alibaba Cloud, with XSIAM Premium as an alternate base license and Cortex CLI for image, API, and code scans. Identity products acquired through CyberArk are out of this cohort. Per-integration SIEM catalogs are thinner than Wiz or Orca directories, so this is not anchor 5.","sourceIds":["pan-s2","pan-s3","pan-s4"]},"governance":{"score":2,"confidence":"medium","rationale":"Deployment/compliance material establishes framework mappings and the current access guide confirms RBAC, scoped administration and license-aware visibility (stage 2 retained). Official indexed excerpts describe custom cloud-security policies, but the relocated policy procedure did not resolve to readable current content in this pass. Stage 3 and later remain unawarded pending that verification; this is an evidence limit, not a claim that custom policies are absent.","sourceIds":["pan-s1","pan-s5","pan-s6"]},"operations":{"score":4,"confidence":"medium","rationale":"Anchor 4: the deployment checklist, health check, Connected-versus-discovery distinction, cases and issues, dashboards, XQL, and graph search give operators onboarding, investigation, and coverage-health paths. Combined export-plus-lifecycle runbooks for every module remain incomplete on the pages reviewed, so this is not anchor 5.","sourceIds":["pan-s1","pan-s2","pan-s5"]}},"constraints":["Confirm whether a quotation is Cortex Cloud, Prisma Cloud lineage, Cloud Posture Security, Cloud Runtime Security, or XSIAM Premium; naming change is not a mandatory migration by itself.","Asset discovery and CSPM are always enabled; other capabilities are optional and change the auth template permissions.","Code security requires a separate Application Security Add-on on a Cloud Posture, Cloud Runtime, or XSIAM Premium base license.","Outpost scan mode deploys scanner infrastructure in a customer CSP account and may incur extra cloud cost; Alibaba Cloud and OCI do not support outpost scanning.","CyberArk/Idira identity products are out of this CNAPP cohort.","Sensor or defender-component coverage for a given workload type is unverified beyond the module list.","Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition."],"sources":[{"id":"pan-s1","title":"Navigate the Cortex Cloud Runtime Security docs","url":"https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security","accessedAt":"2026-09-21","kind":"documentation"},{"id":"pan-s2","title":"Cloud service provider (CSP) onboarding","url":"https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding","accessedAt":"2026-09-21","kind":"documentation"},{"id":"pan-s3","title":"About Cortex Cloud Application Security","url":"https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-application-security/about-cortex-cloud-application-security","accessedAt":"2026-09-21","kind":"documentation"},{"id":"pan-s4","title":"Cortex Cloud product page","url":"https://www.paloaltonetworks.com/cortex/cloud","accessedAt":"2026-09-21","kind":"documentation"},{"id":"pan-s5","title":"Deployment steps and checklist","url":"https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist","accessedAt":"2026-09-21","kind":"documentation"},{"id":"pan-s6","title":"Cortex Cloud users, groups and roles","url":"https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/set-up-users-and-roles","accessedAt":"2026-09-21","kind":"documentation"}],"name":"Palo Alto Networks Cortex Cloud","company":"Palo Alto Networks","profileUrl":"/landscape/vendors/palo-alto-cortex-cloud/"},{"vendor":"microsoft-defender-for-cloud","cohort":"cnapp-posture-platforms","edition":"Microsoft Defender for Cloud (Foundational CSPM plus optional Defender CSPM and workload plans)","asOf":"2026-09-21","status":"research-preview","summary":"Learn documentation splits free Foundational CSPM from paid Defender CSPM (graph, attack paths, governance) and from workload plans that need Arc, sensors, or service integrations. Connecting an account for posture is not the same as enabling every CWPP plan.","dimensions":{"maturity":{"score":4,"confidence":"medium","rationale":"Anchor 4: planning docs list CSPM as agentless after connector onboarding, while CWPP plans require Arc, Defender for Endpoint, Defender sensor, or other extensions, with explicit AWS and GCP permission tables. Foundational CSPM becomes opt-in for new Azure subscriptions after 27 October 2026. A single published continuity model covering every plan retirement together is not documented, so this is not anchor 5.","sourceIds":["ms-s2","ms-s5","ms-s1"]},"innovation":{"score":3,"confidence":"low","rationale":"The cited pages support cloud graph exploration, attack-path investigation and plan-scoped remediation, matching contemporary cohort baseline workflows (stage 3). No supported difference beyond that shared baseline is established. This is not a novelty or superiority claim; preview, beta, AI branding and unverified agentic features are excluded.","sourceIds":["ms-s3","ms-s2","ms-s1"]},"breadth":{"score":5,"confidence":"medium","rationale":"Anchor 5: introduction and CSPM plan tables document Foundational CSPM, paid Defender CSPM (DSPM, AI SPM, attack paths, explorer), DevOps connectors, and workload plans for servers, containers, storage, databases, APIs, and more, with Azure/AWS/GCP support matrices. Breadth is plan-split; several GCP or AWS cells are unsupported or preview.","sourceIds":["ms-s1","ms-s2"]},"ecosystem":{"score":4,"confidence":"medium","rationale":"Anchor 4: AWS and GCP connectors, GitHub/Azure DevOps/GitLab, Arc hybrid machines, and GA alert streaming to Sentinel, Splunk, QRadar, ServiceNow, and other SIEM/SOAR/ITSM tools are documented. The Defender portal ServiceNow ticketing integration is preview and is not counted toward anchor 5.","sourceIds":["ms-s1","ms-s6","ms-s2"]},"governance":{"score":5,"confidence":"medium","rationale":"Anchor 5: Azure RBAC plus Security Reader and Security Admin, policy and MCSB recommendations, recommendation exemptions, and Defender CSPM governance rules that assign owners, due dates, notifications, and a governance report are documented together with continuous export of alerts and recommendations. Regulatory compliance assessments are paid Defender CSPM capabilities, not proof of certification.","sourceIds":["ms-s4","ms-s7","ms-s6"]},"operations":{"score":4,"confidence":"medium","rationale":"Anchor 4: operators have secure score and recommendations, attack-path remediation, workflow automation, planning/operations guidance, and explicit Arc versus agentless coverage distinctions. Combined sensor-health plus module-lifecycle runbooks across every Defender plan were not verified as a single operator handbook, so this is not anchor 5.","sourceIds":["ms-s1","ms-s5","ms-s7"]}},"constraints":["Foundational CSPM, paid Defender CSPM, and each workload plan have different coverage and billing; account connection is not full CNAPP onboarding.","Attack path analysis and cloud security explorer require Defender CSPM plus agentless VM scanning or Defender for Servers vulnerability assessment.","AWS/GCP CWPP for servers, containers, and SQL generally requires Azure Arc and additional sensors or extensions.","Owner role is required to enable all capabilities of a plan, including agentless scanning.","Unified RBAC/cloud scopes, ServiceNow recommendation ticketing, and the AKS security dashboard are preview and were not scored as GA.","Starting 27 October 2026, Foundational CSPM is opt-in for new Azure subscriptions.","Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition."],"sources":[{"id":"ms-s1","title":"Microsoft Defender for Cloud Overview","url":"https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-cloud-introduction","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ms-s2","title":"What is Cloud Security Posture Management (CSPM)","url":"https://learn.microsoft.com/en-us/azure/defender-for-cloud/concept-cloud-security-posture-management","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ms-s3","title":"Security explorer and attack paths","url":"https://learn.microsoft.com/en-us/azure/defender-for-cloud/concept-attack-path","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ms-s4","title":"User roles and permissions","url":"https://learn.microsoft.com/en-us/azure/defender-for-cloud/permissions","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ms-s5","title":"Determine multicloud CSPM and CWPP dependencies","url":"https://learn.microsoft.com/en-us/azure/defender-for-cloud/plan-multicloud-security-determine-multicloud-dependencies","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ms-s6","title":"Stream alerts to monitoring solutions","url":"https://learn.microsoft.com/en-us/azure/defender-for-cloud/export-to-siem","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ms-s7","title":"Drive recommendation remediation by using governance rules","url":"https://learn.microsoft.com/en-us/azure/defender-for-cloud/governance-rules","accessedAt":"2026-09-21","kind":"documentation"}],"name":"Microsoft Defender for Cloud","company":"Microsoft","profileUrl":"/landscape/vendors/microsoft-defender-for-cloud/"},{"vendor":"orca-security","cohort":"cnapp-posture-platforms","edition":"Orca Cloud Security Platform (SideScanning plus optional Orca Sensor)","asOf":"2026-09-21","status":"research-preview","summary":"Public product docs describe out-of-band SideScanning of runtime block storage combined with a unified data model and a separately deployed eBPF Orca Sensor. Snapshot or disk state is not continuous process prevention; tenant RBAC and connector-health runbooks were not found at operator-doc depth.","dimensions":{"maturity":{"score":null,"confidence":"low","rationale":"Public pages describe SideScanning and a separate runtime sensor. They do not verify connector health and removal or rollback controls required by the cumulative rubric. Operating safeguards remain unknown, not absent.","sourceIds":["orca-s2","orca-s3"]},"innovation":{"score":3,"confidence":"low","rationale":"The cited pages support agentless workload/context investigation and attack-path prioritization, matching contemporary cohort baseline workflows (stage 3). No supported difference beyond that shared baseline is established. This is not a novelty or superiority claim; preview, beta, AI branding and unverified agentic features are excluded.","sourceIds":["orca-s2","orca-s4"]},"breadth":{"score":4,"confidence":"medium","rationale":"Anchor 4: platform pages list cloud risk, AI, code, workload protection, CDR, SideScanning, Sensor, unified data model, and attack-path analysis, and the FAQ names CSPM, CWPP, CIEM, and DSPM. No Defender-style per-cloud GA matrix was found, so anchor 5 is not scored.","sourceIds":["orca-s1","orca-s4"]},"ecosystem":{"score":4,"confidence":"medium","rationale":"Anchor 4: the integration directory lists SIEM, SOAR, ticketing, CI/CD, SSO/IAM, repositories, and cloud services including Jira, ServiceNow, Splunk, GitHub, Okta, and cloud-native sinks. Per-integration permission boundaries are catalog-level, not a full matrix, so this is not anchor 5.","sourceIds":["orca-s1","orca-s5"]},"governance":{"score":null,"confidence":"low","rationale":"Public descriptions of contextual configuration, IAM and PII findings do not establish the specific policy-framework mappings or administrative controls required by this rubric. Governance remains unknown; missing documentation is not affirmative non-support.","sourceIds":["orca-s2","orca-s4"]},"operations":{"score":3,"confidence":"low","rationale":"Anchor 3: docs describe connecting an account, viewing prioritized attack paths, tracing runtime exposure to IaC or commits, and sending work through ticketing or SIEM integrations. Sensor-health versus SideScanning coverage runbooks are thin on public pages, so inventory-versus-runtime operator enablement at anchor 4 is inferred and left below that bar.","sourceIds":["orca-s3","orca-s4","orca-s5"]}},"constraints":["SideScanning reads runtime block storage out of band; it is not equivalent to continuous process prevention.","Orca Sensor is a separately deployed runtime component with its own OS and workload support, unverified here.","SaaS versus in-account (Orca Pod) processing locations and snapshot permissions are unverified beyond product FAQs.","Supported clouds named on product pages include AWS, Azure, GCP, Alibaba, Oracle, and Tencent; exact feature parity is unverified.","No public operator handbook equivalent to Learn or Cortex docs was found for RBAC, connector health, or rollback.","Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition.","Unknown dimensions reflect incomplete evidence for cumulative stage requirements, not proof that capabilities are absent."],"sources":[{"id":"orca-s1","title":"Orca Platform","url":"https://orca.security/platform","accessedAt":"2026-09-21","kind":"documentation"},{"id":"orca-s2","title":"Orca SideScanning","url":"https://orca.security/platform/agentless-sidescanning/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"orca-s3","title":"Orca Sensor","url":"https://orca.security/platform/runtime-sensor/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"orca-s4","title":"Orca Unified Data Model","url":"https://orca.security/platform/unified-data-model/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"orca-s5","title":"Orca Integration Directory","url":"https://orca.security/integrations/","accessedAt":"2026-09-21","kind":"documentation"}],"name":"Orca Security","company":"Orca Security","profileUrl":"/landscape/vendors/orca-security/"}],"scenarios":[{"id":"lean-team","name":"Small security team","description":"A small team connecting one lab cloud account for posture first, adding a runtime sensor only where process evidence is required.","priorities":["operations","maturity"],"questions":["Can the team see a disconnected connector or missing sensor before treating an empty finding list as coverage?","Which permissions and snapshot or disk access does agentless scanning require, and how is the integration removed?"]},{"id":"microsoft-centered","name":"Microsoft-centered multicloud","description":"An Azure-centered team evaluating Defender for Cloud for Azure plus AWS or GCP connectors alongside existing incident processes.","priorities":["governance","breadth"],"questions":["Which functions are Foundational CSPM, paid Defender CSPM, or a workload plan?","Does each AWS or GCP workload path require Azure Arc, a Defender sensor, or only the agentless connector?"]},{"id":"sensor-split","name":"Agentless versus runtime split","description":"A platform team that must keep API or snapshot posture distinct from eBPF or host runtime evidence on supported workloads.","priorities":["operations","innovation"],"questions":["Which finding types are produced only after a sensor is installed on a supported OS or cluster?","How does the inventory flag workloads that are connected for posture but not instrumented for runtime?"]},{"id":"prisma-lineage","name":"Prisma Cloud to Cortex Cloud naming","description":"A team with Prisma Cloud materials mapping them to current Cortex Cloud modules without treating the rename as a scored product.","priorities":["ecosystem","maturity"],"questions":["Which SKU is Cloud Posture Security, Cloud Runtime Security, XSIAM Premium, or the Application Security Add-on?","Which Prisma-lineage functions have a documented Cortex destination rather than a similar name only?"]}],"researchNotes":["First edition dated 2026-09-21; no historical assessments are available.","The four selected existing-catalog offerings form one explicitly scoped cohort. Assessment applies only to named editions and documented modules; adjacent products and managed-service outcomes are excluded.","Primary sources establish documented capabilities and their prerequisites, not actual effectiveness, reliability, deployment effort, staffing savings or return on investment.","Confidence reflects evidence and inference within the stated scope, not vendor size, age or source count.","Contemporary cohort baseline: Multicloud posture and vulnerability assessment, identity/data context, graph or attack-path investigation, optional runtime telemetry, and routing or remediation orchestration are contemporary CNAPP baseline capabilities. Graph views, SideScanning architecture, plan packaging and a runtime sensor alone do not establish differentiated operator workflows.","Innovation stage 3 indicates supported baseline workflows, not market novelty. No stage 4 or 5 differentiation is established by this first-edition evidence. Public-documentation confidence is low for cross-offering calibration.","Zero requires affirmative evidence of absence. Missing, gated or incomplete documentation remains unknown; a lower stage is not assigned merely because documentation is unavailable.","Scores were checked against cumulative stage prerequisites; selected operating/control cells remain unknown where those prerequisites could not be verified.","Rubric 1.1 rechecked maturity and innovation primary sources. No partial step beyond maturity anchor 4 was established for Cortex Cloud or Defender for Cloud without re-awarding onboarding, connector health or lifecycle notices already required by earlier anchors. Wiz and Orca operating safeguards remain unknown where full procedures were not verified. Contemporary baseline innovation remains 3.0 for all four offerings; decimal support does not require breaking an evidence-supported tie.","All six dimensions were reviewed for the 2026-09-21 momentum baseline. Source-backed corrections and retained evidence gaps are recorded in docs/research/2026-09-21-momentum-baseline-a.md. These are baseline research decisions, not longitudinal vendor movement; unknowns remain unknown and the rubric/edition scopes are unchanged."],"history":{"segment":"cloud-security","snapshots":[{"id":"2026-09-21","publishedAt":"2026-09-21","kind":"baseline","research":{"segment":"cloud-security","reviewedAt":"2026-09-21","rubricVersion":"1.1","cohorts":[{"id":"cnapp-posture-platforms","name":"CNAPP and cloud posture platforms","scope":"Comparable independently sold CNAPP/posture platforms with agentless cloud inventory plus optional runtime sensors: Wiz, Palo Alto Networks Cortex Cloud (Prisma Cloud lineage; not a separate prisma-cloud catalog slug), Microsoft Defender for Cloud, and Orca Security. Excludes native-only CSP suites (AWS Security Hub, Google Security Command Center), runtime-first specialists scored elsewhere, managed SOC services, and CyberArk/Idira identity products. Agentless API or snapshot findings are not live process coverage. Preview features are not scored as GA. Cohort baseline is agentless CSPM plus optional runtime sensing plus some graph or attack-path context."}],"dimensions":[{"id":"maturity","name":"Operational maturity","question":"How completely do public operator docs describe safeguards for connectors, sensors, coverage gaps, and lifecycle change?","description":"Scores documented operating safeguards only: onboarding permissions, connector or sensor health, rollback, and how a missing collector is distinguished from a clean finding. Does not score vendor age, uptime, staffing, or measured reliability.","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide operating safeguards for the scoped assessment workflow. Missing evidence is unknown, never zero.","1: A concrete basic operating safeguard is documented for the evaluated edition.","2: Documented connector permissions, data handling, and enablement prerequisites for a bounded lab.","3: Documented connector or sensor health or status plus documented removal or rollback of integrations.","4: Documented coverage-gap visibility that distinguishes a missing connector or sensor from a clean finding, plus lifecycle or enablement notices.","5: Documented multi-control operating model covering connector and sensor health, account onboarding, module changes, and continuity together."]},{"id":"innovation","name":"Shipped innovation","question":"Which current baseline workflows are supported, and is any concrete shipped difference from that shared baseline established?","description":"Ordinal evidence of shipped workflows against a contemporary shared cohort baseline. Stage 3 means supported baseline workflows, not novelty or superiority. Higher stages require concrete generally available differences supported by comparative primary evidence. Multicloud posture and vulnerability assessment, identity/data context, graph or attack-path investigation, optional runtime telemetry, and routing or remediation orchestration are contemporary CNAPP baseline capabilities. Graph views, SideScanning architecture, plan packaging and a runtime sensor alone do not establish differentiated operator workflows.","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide a shipped workflow within the scoped cohort. Missing evidence is unknown, never zero.","1: One basic in-scope workflow is confirmed shipped; no broader stage is established.","2: Several baseline components are confirmed shipped, but an integrated contemporary baseline workflow is not established.","3: An integrated contemporary baseline workflow is supported by primary evidence; this stage makes no differentiation or novelty claim.","4: Stage 3 plus one concrete generally available operator workflow difference beyond the shared contemporary baseline, supported by comparative primary evidence.","5: Stage 4 plus multiple complementary generally available workflow differences beyond that baseline, with their boundaries and prerequisites established."]},{"id":"breadth","name":"Capability breadth","question":"How many distinct CNAPP capability areas are documented, with module and cloud dependencies made explicit?","description":"Scores documented capability areas (posture, identity, workload or runtime, code, data) and whether coverage depends on separate plans, sensors, or clouds. Does not score efficacy or completeness of every cloud service.","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide an in-scope assessment capability. Missing evidence is unknown, never zero.","1: A bounded in-scope capability is documented for one environment or workflow.","2: CSPM plus one of runtime or CWPP, CIEM, or code/IaC.","3: Multicloud posture plus at least two of runtime, CIEM, vulnerability, or code.","4: Documented CNAPP span across posture, identity, workload or runtime, and code or data, with module dependencies explicit.","5: Broad CNAPP including DSPM, AI posture, or CDR with documented coverage matrices per cloud or workload type."]},{"id":"ecosystem","name":"Ecosystem & integration","question":"Which cloud, identity, pipeline, and SOC integrations are documented with explicit scope?","description":"Scores documented connectors and exports to clouds, identity providers, repositories or pipelines, and ticketing or SIEM systems. Preview integrations are not treated as GA.","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide an integration or supported data handoff. Missing evidence is unknown, never zero.","1: A concrete native connector or supported manual integration is documented.","2: Multiple major cloud connectors (AWS, Azure, GCP, or equivalent) are documented.","3: Cloud connectors plus ticketing, SIEM, or export integrations.","4: Documented ecosystem spanning clouds, identity or repos/pipelines, and SOC or ticketing, with some scope notes.","5: Broad documented integration catalog including IaC or repos, SIEM or SOAR, identity, and multiple clouds with explicit per-integration boundaries."]},{"id":"governance","name":"Governance & control","question":"What policy, RBAC, exception, owner-routing, and evidence-export controls are documented?","description":"Scores documented policy customization, role isolation, framework mappings (not certifications), exception handling, and export for independent review. Mappings do not prove audit success.","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide an administrative or policy control. Missing evidence is unknown, never zero.","1: A specific administrative control is documented for the scoped workflow.","2: Documented policy frameworks or compliance mappings (not a certification claim).","3: Custom policies plus RBAC or tenant isolation documented.","4: Framework mappings, custom or assignable policy, RBAC, and evidence export for review.","5: Documented governance including owner assignment or exception workflow, policy controls, RBAC, and evidence export together."]},{"id":"operations","name":"Operator enablement","question":"Do public docs enable an operator to onboard, investigate, route ownership, and see coverage gaps without treating marketing as a runbook?","description":"Scores operator-facing onboarding, investigation, remediation routing, and coverage-health documentation. Does not score staffing savings or measured mean-time-to-remediate.","anchors":["0: Primary evidence affirmatively establishes that the evaluated scope does not provide a supported operator action or guidance path. Missing evidence is unknown, never zero.","1: A concrete operator action and its basic use are documented.","2: Documented onboarding of a cloud account or subscription.","3: Investigation or remediation workflow docs that take a finding to an owner or correction path.","4: Operator docs covering inventory versus runtime distinction, health or coverage, and routing to owners.","5: Runbooks for connector and sensor health, coverage gaps, export, and lifecycle or module-change operations together."]}],"assessments":[{"vendor":"wiz","cohort":"cnapp-posture-platforms","edition":"Wiz platform (agentless CNAPP plus separately deployed Wiz Sensor)","asOf":"2026-09-21","status":"research-preview","summary":"Public pages document API-first agentless inventory, a Security Graph investigation path, code-to-cloud ownership, and a separately deployed runtime sensor whose coverage must be mapped rather than assumed from account connection. Tenant operator runbooks on docs.wiz.io were not independently readable in this pass.","dimensions":{"maturity":{"score":null,"confidence":"low","rationale":"Public pages describe account connections and inventory/sensor scope. Connector-health and removal or rollback instructions required by the cumulative rubric were not independently readable behind the documentation checkpoint. Operating safeguards remain unknown, not absent.","sourceIds":["wiz-s1","wiz-s2"]},"innovation":{"score":3,"confidence":"low","rationale":"The cited pages support cloud risk/context investigation with ownership and remediation routing, matching contemporary cohort baseline workflows (stage 3). No supported difference beyond that shared baseline is established. This is not a novelty or superiority claim; preview, beta, AI branding and unverified agentic features are excluded.","sourceIds":["wiz-s1","wiz-s2"]},"breadth":{"score":4,"confidence":"medium","rationale":"Anchor 4: documented areas include agentless CSPM, identities, vulnerabilities, IaC/code, attack paths, and separately deployed runtime protection. DSPM and AI inventory are described on the platform page without a Microsoft-style per-cloud GA matrix, so anchor 5 is not met.","sourceIds":["wiz-s1","wiz-s2"]},"ecosystem":{"score":4,"confidence":"medium","rationale":"The official evaluation FAQ names cloud, repository/pipeline, identity, ticketing and SIEM/SOAR connections, confirming stage 4. The dynamic integration catalog did not expose individual entries to the reader in this pass. Per-integration permission and data-handling boundaries remain unverified, so the broad catalog alone does not earn stage 5.","sourceIds":["wiz-s1","wiz-s3","wiz-s4"]},"governance":{"score":null,"confidence":"low","rationale":"The public platform page describes ownership and role concepts, but gated operator documentation prevented verification of the cumulative policy, RBAC and evidence-export requirements. Product governance remains unknown in this public evidence pass.","sourceIds":["wiz-s1"]},"operations":{"score":null,"confidence":"low","rationale":"The public pages describe graph investigation, ownership routing and sensor coverage. They do not verify the cloud-account onboarding procedure and operating guidance required by earlier cumulative stages; detailed operator docs were gated. Operator enablement remains unknown rather than inferred from product-page workflows.","sourceIds":["wiz-s1","wiz-s2"]}},"constraints":["Evaluated edition is the Wiz platform plus optional Wiz Sensor; agentless API or snapshot visibility is not runtime monitoring.","docs.wiz.io returned a Vercel security checkpoint during this review; connector permission matrices, sensor OS support, and rollback steps remain unverified from primary docs.","Google completed a Wiz acquisition in 2026; brand retention is catalog context only and is not scored.","Sensor deployment, supported kernels, and module packaging are unverified from public operator docs.","Plans, SKU splits, and data-processing locations are unverified.","Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition.","Unknown dimensions reflect incomplete evidence for cumulative stage requirements, not proof that capabilities are absent."],"sources":[{"id":"wiz-s1","title":"Wiz Cloud and AI Security Platform","url":"https://www.wiz.io/platform","accessedAt":"2026-09-21","kind":"documentation"},{"id":"wiz-s2","title":"Wiz Runtime Sensor","url":"https://www.wiz.io/solutions/runtime-sensor","accessedAt":"2026-09-21","kind":"documentation"},{"id":"wiz-s3","title":"Wiz Integrations","url":"https://www.wiz.io/integrations","accessedAt":"2026-09-21","kind":"documentation"},{"id":"wiz-s4","title":"Wiz evaluation FAQ: scope and integrations","url":"https://www.wiz.io/academy/cloud-security/how-to-evaluate-wiz-faq","accessedAt":"2026-09-21","kind":"product"}]},{"vendor":"palo-alto-cortex-cloud","cohort":"cnapp-posture-platforms","edition":"Cortex Cloud (Cloud Posture Security and/or Cloud Runtime Security; Prisma Cloud lineage)","asOf":"2026-09-21","status":"research-preview","summary":"Cortex Cloud docs describe CSP onboarding with always-on asset discovery and CSPM, optional runtime and identity or data modules, connection health distinct from completed discovery, and investigation via cases, XQL, and graph search. Application code scanning is an add-on; Prisma Cloud remains a lineage name, not a separate catalog slug.","dimensions":{"maturity":{"score":4,"confidence":"medium","rationale":"Anchor 4: onboarding docs distinguish Connected (trust established) from completed resource discovery, run connection health checks for permission or quota issues, expire pending templates, and keep excluded accounts visible as excluded rather than silently clean. Capability selection is encoded in the auth template. A full continuity runbook across every module change is not documented as a single operating model, so this is not anchor 5.","sourceIds":["pan-s2","pan-s5"]},"innovation":{"score":3,"confidence":"low","rationale":"The cited pages support posture/runtime investigation, cases and graph-assisted remediation workflows, matching contemporary cohort baseline workflows (stage 3). No supported difference beyond that shared baseline is established. This is not a novelty or superiority claim; preview, beta, AI branding and unverified agentic features are excluded.","sourceIds":["pan-s1","pan-s3","pan-s4"]},"breadth":{"score":4,"confidence":"medium","rationale":"Anchor 4: docs cover always-on CSPM, optional runtime, identity, data security, WAAS, serverless, ASM, vulnerability management, and application security with explicit license splits. DSPM and AI-SPM appear as optional or datasheet capabilities without a per-cloud GA matrix comparable to Defender for Cloud, so anchor 5 is not scored.","sourceIds":["pan-s1","pan-s2","pan-s3"]},"ecosystem":{"score":4,"confidence":"medium","rationale":"Anchor 4: CSP onboarding documents AWS, Azure, GCP, OCI, and Alibaba Cloud, with XSIAM Premium as an alternate base license and Cortex CLI for image, API, and code scans. Identity products acquired through CyberArk are out of this cohort. Per-integration SIEM catalogs are thinner than Wiz or Orca directories, so this is not anchor 5.","sourceIds":["pan-s2","pan-s3","pan-s4"]},"governance":{"score":2,"confidence":"medium","rationale":"Deployment/compliance material establishes framework mappings and the current access guide confirms RBAC, scoped administration and license-aware visibility (stage 2 retained). Official indexed excerpts describe custom cloud-security policies, but the relocated policy procedure did not resolve to readable current content in this pass. Stage 3 and later remain unawarded pending that verification; this is an evidence limit, not a claim that custom policies are absent.","sourceIds":["pan-s1","pan-s5","pan-s6"]},"operations":{"score":4,"confidence":"medium","rationale":"Anchor 4: the deployment checklist, health check, Connected-versus-discovery distinction, cases and issues, dashboards, XQL, and graph search give operators onboarding, investigation, and coverage-health paths. Combined export-plus-lifecycle runbooks for every module remain incomplete on the pages reviewed, so this is not anchor 5.","sourceIds":["pan-s1","pan-s2","pan-s5"]}},"constraints":["Confirm whether a quotation is Cortex Cloud, Prisma Cloud lineage, Cloud Posture Security, Cloud Runtime Security, or XSIAM Premium; naming change is not a mandatory migration by itself.","Asset discovery and CSPM are always enabled; other capabilities are optional and change the auth template permissions.","Code security requires a separate Application Security Add-on on a Cloud Posture, Cloud Runtime, or XSIAM Premium base license.","Outpost scan mode deploys scanner infrastructure in a customer CSP account and may incur extra cloud cost; Alibaba Cloud and OCI do not support outpost scanning.","CyberArk/Idira identity products are out of this CNAPP cohort.","Sensor or defender-component coverage for a given workload type is unverified beyond the module list.","Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition."],"sources":[{"id":"pan-s1","title":"Navigate the Cortex Cloud Runtime Security docs","url":"https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security","accessedAt":"2026-09-21","kind":"documentation"},{"id":"pan-s2","title":"Cloud service provider (CSP) onboarding","url":"https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding","accessedAt":"2026-09-21","kind":"documentation"},{"id":"pan-s3","title":"About Cortex Cloud Application Security","url":"https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-application-security/about-cortex-cloud-application-security","accessedAt":"2026-09-21","kind":"documentation"},{"id":"pan-s4","title":"Cortex Cloud product page","url":"https://www.paloaltonetworks.com/cortex/cloud","accessedAt":"2026-09-21","kind":"documentation"},{"id":"pan-s5","title":"Deployment steps and checklist","url":"https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist","accessedAt":"2026-09-21","kind":"documentation"},{"id":"pan-s6","title":"Cortex Cloud users, groups and roles","url":"https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/set-up-users-and-roles","accessedAt":"2026-09-21","kind":"documentation"}]},{"vendor":"microsoft-defender-for-cloud","cohort":"cnapp-posture-platforms","edition":"Microsoft Defender for Cloud (Foundational CSPM plus optional Defender CSPM and workload plans)","asOf":"2026-09-21","status":"research-preview","summary":"Learn documentation splits free Foundational CSPM from paid Defender CSPM (graph, attack paths, governance) and from workload plans that need Arc, sensors, or service integrations. Connecting an account for posture is not the same as enabling every CWPP plan.","dimensions":{"maturity":{"score":4,"confidence":"medium","rationale":"Anchor 4: planning docs list CSPM as agentless after connector onboarding, while CWPP plans require Arc, Defender for Endpoint, Defender sensor, or other extensions, with explicit AWS and GCP permission tables. Foundational CSPM becomes opt-in for new Azure subscriptions after 27 October 2026. A single published continuity model covering every plan retirement together is not documented, so this is not anchor 5.","sourceIds":["ms-s2","ms-s5","ms-s1"]},"innovation":{"score":3,"confidence":"low","rationale":"The cited pages support cloud graph exploration, attack-path investigation and plan-scoped remediation, matching contemporary cohort baseline workflows (stage 3). No supported difference beyond that shared baseline is established. This is not a novelty or superiority claim; preview, beta, AI branding and unverified agentic features are excluded.","sourceIds":["ms-s3","ms-s2","ms-s1"]},"breadth":{"score":5,"confidence":"medium","rationale":"Anchor 5: introduction and CSPM plan tables document Foundational CSPM, paid Defender CSPM (DSPM, AI SPM, attack paths, explorer), DevOps connectors, and workload plans for servers, containers, storage, databases, APIs, and more, with Azure/AWS/GCP support matrices. Breadth is plan-split; several GCP or AWS cells are unsupported or preview.","sourceIds":["ms-s1","ms-s2"]},"ecosystem":{"score":4,"confidence":"medium","rationale":"Anchor 4: AWS and GCP connectors, GitHub/Azure DevOps/GitLab, Arc hybrid machines, and GA alert streaming to Sentinel, Splunk, QRadar, ServiceNow, and other SIEM/SOAR/ITSM tools are documented. The Defender portal ServiceNow ticketing integration is preview and is not counted toward anchor 5.","sourceIds":["ms-s1","ms-s6","ms-s2"]},"governance":{"score":5,"confidence":"medium","rationale":"Anchor 5: Azure RBAC plus Security Reader and Security Admin, policy and MCSB recommendations, recommendation exemptions, and Defender CSPM governance rules that assign owners, due dates, notifications, and a governance report are documented together with continuous export of alerts and recommendations. Regulatory compliance assessments are paid Defender CSPM capabilities, not proof of certification.","sourceIds":["ms-s4","ms-s7","ms-s6"]},"operations":{"score":4,"confidence":"medium","rationale":"Anchor 4: operators have secure score and recommendations, attack-path remediation, workflow automation, planning/operations guidance, and explicit Arc versus agentless coverage distinctions. Combined sensor-health plus module-lifecycle runbooks across every Defender plan were not verified as a single operator handbook, so this is not anchor 5.","sourceIds":["ms-s1","ms-s5","ms-s7"]}},"constraints":["Foundational CSPM, paid Defender CSPM, and each workload plan have different coverage and billing; account connection is not full CNAPP onboarding.","Attack path analysis and cloud security explorer require Defender CSPM plus agentless VM scanning or Defender for Servers vulnerability assessment.","AWS/GCP CWPP for servers, containers, and SQL generally requires Azure Arc and additional sensors or extensions.","Owner role is required to enable all capabilities of a plan, including agentless scanning.","Unified RBAC/cloud scopes, ServiceNow recommendation ticketing, and the AKS security dashboard are preview and were not scored as GA.","Starting 27 October 2026, Foundational CSPM is opt-in for new Azure subscriptions.","Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition."],"sources":[{"id":"ms-s1","title":"Microsoft Defender for Cloud Overview","url":"https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-cloud-introduction","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ms-s2","title":"What is Cloud Security Posture Management (CSPM)","url":"https://learn.microsoft.com/en-us/azure/defender-for-cloud/concept-cloud-security-posture-management","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ms-s3","title":"Security explorer and attack paths","url":"https://learn.microsoft.com/en-us/azure/defender-for-cloud/concept-attack-path","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ms-s4","title":"User roles and permissions","url":"https://learn.microsoft.com/en-us/azure/defender-for-cloud/permissions","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ms-s5","title":"Determine multicloud CSPM and CWPP dependencies","url":"https://learn.microsoft.com/en-us/azure/defender-for-cloud/plan-multicloud-security-determine-multicloud-dependencies","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ms-s6","title":"Stream alerts to monitoring solutions","url":"https://learn.microsoft.com/en-us/azure/defender-for-cloud/export-to-siem","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ms-s7","title":"Drive recommendation remediation by using governance rules","url":"https://learn.microsoft.com/en-us/azure/defender-for-cloud/governance-rules","accessedAt":"2026-09-21","kind":"documentation"}]},{"vendor":"orca-security","cohort":"cnapp-posture-platforms","edition":"Orca Cloud Security Platform (SideScanning plus optional Orca Sensor)","asOf":"2026-09-21","status":"research-preview","summary":"Public product docs describe out-of-band SideScanning of runtime block storage combined with a unified data model and a separately deployed eBPF Orca Sensor. Snapshot or disk state is not continuous process prevention; tenant RBAC and connector-health runbooks were not found at operator-doc depth.","dimensions":{"maturity":{"score":null,"confidence":"low","rationale":"Public pages describe SideScanning and a separate runtime sensor. They do not verify connector health and removal or rollback controls required by the cumulative rubric. Operating safeguards remain unknown, not absent.","sourceIds":["orca-s2","orca-s3"]},"innovation":{"score":3,"confidence":"low","rationale":"The cited pages support agentless workload/context investigation and attack-path prioritization, matching contemporary cohort baseline workflows (stage 3). No supported difference beyond that shared baseline is established. This is not a novelty or superiority claim; preview, beta, AI branding and unverified agentic features are excluded.","sourceIds":["orca-s2","orca-s4"]},"breadth":{"score":4,"confidence":"medium","rationale":"Anchor 4: platform pages list cloud risk, AI, code, workload protection, CDR, SideScanning, Sensor, unified data model, and attack-path analysis, and the FAQ names CSPM, CWPP, CIEM, and DSPM. No Defender-style per-cloud GA matrix was found, so anchor 5 is not scored.","sourceIds":["orca-s1","orca-s4"]},"ecosystem":{"score":4,"confidence":"medium","rationale":"Anchor 4: the integration directory lists SIEM, SOAR, ticketing, CI/CD, SSO/IAM, repositories, and cloud services including Jira, ServiceNow, Splunk, GitHub, Okta, and cloud-native sinks. Per-integration permission boundaries are catalog-level, not a full matrix, so this is not anchor 5.","sourceIds":["orca-s1","orca-s5"]},"governance":{"score":null,"confidence":"low","rationale":"Public descriptions of contextual configuration, IAM and PII findings do not establish the specific policy-framework mappings or administrative controls required by this rubric. Governance remains unknown; missing documentation is not affirmative non-support.","sourceIds":["orca-s2","orca-s4"]},"operations":{"score":3,"confidence":"low","rationale":"Anchor 3: docs describe connecting an account, viewing prioritized attack paths, tracing runtime exposure to IaC or commits, and sending work through ticketing or SIEM integrations. Sensor-health versus SideScanning coverage runbooks are thin on public pages, so inventory-versus-runtime operator enablement at anchor 4 is inferred and left below that bar.","sourceIds":["orca-s3","orca-s4","orca-s5"]}},"constraints":["SideScanning reads runtime block storage out of band; it is not equivalent to continuous process prevention.","Orca Sensor is a separately deployed runtime component with its own OS and workload support, unverified here.","SaaS versus in-account (Orca Pod) processing locations and snapshot permissions are unverified beyond product FAQs.","Supported clouds named on product pages include AWS, Azure, GCP, Alibaba, Oracle, and Tencent; exact feature parity is unverified.","No public operator handbook equivalent to Learn or Cortex docs was found for RBAC, connector health, or rollback.","Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition.","Unknown dimensions reflect incomplete evidence for cumulative stage requirements, not proof that capabilities are absent."],"sources":[{"id":"orca-s1","title":"Orca Platform","url":"https://orca.security/platform","accessedAt":"2026-09-21","kind":"documentation"},{"id":"orca-s2","title":"Orca SideScanning","url":"https://orca.security/platform/agentless-sidescanning/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"orca-s3","title":"Orca Sensor","url":"https://orca.security/platform/runtime-sensor/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"orca-s4","title":"Orca Unified Data Model","url":"https://orca.security/platform/unified-data-model/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"orca-s5","title":"Orca Integration Directory","url":"https://orca.security/integrations/","accessedAt":"2026-09-21","kind":"documentation"}]}],"scenarios":[{"id":"lean-team","name":"Small security team","description":"A small team connecting one lab cloud account for posture first, adding a runtime sensor only where process evidence is required.","priorities":["operations","maturity"],"questions":["Can the team see a disconnected connector or missing sensor before treating an empty finding list as coverage?","Which permissions and snapshot or disk access does agentless scanning require, and how is the integration removed?"]},{"id":"microsoft-centered","name":"Microsoft-centered multicloud","description":"An Azure-centered team evaluating Defender for Cloud for Azure plus AWS or GCP connectors alongside existing incident processes.","priorities":["governance","breadth"],"questions":["Which functions are Foundational CSPM, paid Defender CSPM, or a workload plan?","Does each AWS or GCP workload path require Azure Arc, a Defender sensor, or only the agentless connector?"]},{"id":"sensor-split","name":"Agentless versus runtime split","description":"A platform team that must keep API or snapshot posture distinct from eBPF or host runtime evidence on supported workloads.","priorities":["operations","innovation"],"questions":["Which finding types are produced only after a sensor is installed on a supported OS or cluster?","How does the inventory flag workloads that are connected for posture but not instrumented for runtime?"]},{"id":"prisma-lineage","name":"Prisma Cloud to Cortex Cloud naming","description":"A team with Prisma Cloud materials mapping them to current Cortex Cloud modules without treating the rename as a scored product.","priorities":["ecosystem","maturity"],"questions":["Which SKU is Cloud Posture Security, Cloud Runtime Security, XSIAM Premium, or the Application Security Add-on?","Which Prisma-lineage functions have a documented Cortex destination rather than a similar name only?"]}],"researchNotes":["First edition dated 2026-09-21; no historical assessments are available.","The four selected existing-catalog offerings form one explicitly scoped cohort. Assessment applies only to named editions and documented modules; adjacent products and managed-service outcomes are excluded.","Primary sources establish documented capabilities and their prerequisites, not actual effectiveness, reliability, deployment effort, staffing savings or return on investment.","Confidence reflects evidence and inference within the stated scope, not vendor size, age or source count.","Contemporary cohort baseline: Multicloud posture and vulnerability assessment, identity/data context, graph or attack-path investigation, optional runtime telemetry, and routing or remediation orchestration are contemporary CNAPP baseline capabilities. Graph views, SideScanning architecture, plan packaging and a runtime sensor alone do not establish differentiated operator workflows.","Innovation stage 3 indicates supported baseline workflows, not market novelty. No stage 4 or 5 differentiation is established by this first-edition evidence. Public-documentation confidence is low for cross-offering calibration.","Zero requires affirmative evidence of absence. Missing, gated or incomplete documentation remains unknown; a lower stage is not assigned merely because documentation is unavailable.","Scores were checked against cumulative stage prerequisites; selected operating/control cells remain unknown where those prerequisites could not be verified.","Rubric 1.1 rechecked maturity and innovation primary sources. No partial step beyond maturity anchor 4 was established for Cortex Cloud or Defender for Cloud without re-awarding onboarding, connector health or lifecycle notices already required by earlier anchors. Wiz and Orca operating safeguards remain unknown where full procedures were not verified. Contemporary baseline innovation remains 3.0 for all four offerings; decimal support does not require breaking an evidence-supported tie.","All six dimensions were reviewed for the 2026-09-21 momentum baseline. Source-backed corrections and retained evidence gaps are recorded in docs/research/2026-09-21-momentum-baseline-a.md. These are baseline research decisions, not longitudinal vendor movement; unknowns remain unknown and the rubric/edition scopes are unchanged."]},"changes":[]}]},"unassessed":[{"slug":"aws-cloud-security","name":"AWS Security Hub and Workload Security","company":"Amazon Web Services","profileUrl":"/landscape/vendors/aws-cloud-security/"},{"slug":"google-security-command-center","name":"Google Security Command Center","company":"Google Cloud","profileUrl":"/landscape/vendors/google-security-command-center/"},{"slug":"crowdstrike-falcon-cloud-security","name":"CrowdStrike Falcon Cloud Security","company":"CrowdStrike","profileUrl":"/landscape/vendors/crowdstrike-falcon-cloud-security/"},{"slug":"sysdig","name":"Sysdig","company":"Sysdig","profileUrl":"/landscape/vendors/sysdig/"},{"slug":"fortinet-forticnapp","name":"Fortinet FortiCNAPP","company":"Fortinet","profileUrl":"/landscape/vendors/fortinet-forticnapp/"},{"slug":"tenable-cloud-security","name":"Tenable Cloud Security","company":"Tenable","profileUrl":"/landscape/vendors/tenable-cloud-security/"},{"slug":"checkpoint-cloudguard","name":"Check Point CloudGuard and Wiz CNAPP","company":"Check Point","profileUrl":"/landscape/vendors/checkpoint-cloudguard/"},{"slug":"aqua-security","name":"Aqua Security","company":"Aqua Security","profileUrl":"/landscape/vendors/aqua-security/"},{"slug":"trendai-cloud-security","name":"TrendAI Vision One Cloud Security","company":"Trend Micro","profileUrl":"/landscape/vendors/trendai-cloud-security/"},{"slug":"upwind","name":"Upwind","company":"Upwind","profileUrl":"/landscape/vendors/upwind/"}]}