Atlas Fold / CNAPP / CSPM

CNAPP / CSPM, unfolded.

Cloud & workload security

Atlas Fold / CNAPP / CSPM / First edition

Cloud & workload security

Provisional editorial research based on public documentation, not tested effectiveness.

First edition · Reviewed · Rubric 1.1

Six dimensions, each scored 0.0–5.0 in tenths. Gaps stay visible.

Comparable independently sold CNAPP/posture platforms with agentless cloud inventory plus optional runtime sensors: Wiz, Palo Alto Networks Cortex Cloud (Prisma Cloud lineage; not a separate prisma-cloud catalog slug), Microsoft Defender for Cloud, and Orca Security. Excludes native-only CSP suites (AWS Security Hub, Google Security Command Center), runtime-first specialists scored elsewhere, managed SOC services, and CyberArk/Idira identity products. Agentless API or snapshot findings are not live process coverage. Preview features are not scored as GA. Cohort baseline is agentless CSPM plus optional runtime sensing plus some graph or attack-path context.

Download JSON

Six dimensions, with gaps listed

Each row is one 0.0–5.0 dimension. Every assessed offering has a consistent color, shape, and number. Numbers identify offerings, not rank. Unknown scores are omitted.

Separated marks connect to their exact positions. Separation does not change scores.

Momentum: building history. Numbers identify offerings, not rank; lines between dimensions are profiles, not time.

A position is only half the story

Momentum

Building history

Baseline recorded 2026-09-21. A second comparable review is needed to show movement.

Download dated history

Own movement is the score change. Relative movement subtracts the median change of matched peers, excluding this offering. Dimensions stay separate.

History appears as a hollow earlier mark connected to the current solid mark in Unfold and Overview. Profile lines between dimensions do not show time. Numbers identify offerings, not rank.

Review history & what changed

The 2026-09-21 baseline incorporates the six-dimension review. Decimal calibration and research corrections are not product momentum. Unknowns stay unknown.

  • 2026-09-21 · baseline · rubric 1.1 · Starting point; no movement inferred.
How momentum is calculated →

Documented scores

Palo Alto Networks Cortex Cloud (medium confidence) and Microsoft Defender for Cloud (medium confidence) are tied at documented score 4.0 for Operational maturity among assessed offerings in this comparison group. No distinction is evidenced among the scored offerings. 2 offerings remain unknown for this dimension.

Wiz (low confidence) and Palo Alto Networks Cortex Cloud (low confidence) and Microsoft Defender for Cloud (low confidence) and Orca Security (low confidence) are tied at documented score 3.0 for Shipped innovation among assessed offerings in this comparison group. No distinction is evidenced among the scored offerings.

Unknowns and gaps

Unknown is not low quality. Marks are omitted where a required score is unknown.

  • Wiz: Operational maturity, Governance & control, Operator enablement
  • Palo Alto Networks Cortex Cloud: no unknown dimensions.
  • Microsoft Defender for Cloud: no unknown dimensions.
  • Orca Security: Operational maturity, Governance & control

Scenario lens

A scenario highlights priorities and validation questions only. It does not rewrite scores or claim eligibility.

Selected evidence

Wiz · Wiz

Wiz platform (agentless CNAPP plus separately deployed Wiz Sensor) · Assessed 2026-09-21 · Research preview

Operational maturity

How completely do public operator docs describe safeguards for connectors, sensors, coverage gaps, and lifecycle change?

Scores documented operating safeguards only: onboarding permissions, connector or sensor health, rollback, and how a missing collector is distinguished from a clean finding. Does not score vendor age, uptime, staffing, or measured reliability.

Public pages document API-first agentless inventory, a Security Graph investigation path, code-to-cloud ownership, and a separately deployed runtime sensor whose coverage must be mapped rather than assumed from account connection. Tenant operator runbooks on docs.wiz.io were not independently readable in this pass.

ScoreUnknownlow confidence

Rationale and sources

Public pages describe account connections and inventory/sensor scope. Connector-health and removal or rollback instructions required by the cumulative rubric were not independently readable behind the documentation checkpoint. Operating safeguards remain unknown, not absent.

Constraints

  • Evaluated edition is the Wiz platform plus optional Wiz Sensor; agentless API or snapshot visibility is not runtime monitoring.
  • docs.wiz.io returned a Vercel security checkpoint during this review; connector permission matrices, sensor OS support, and rollback steps remain unverified from primary docs.
  • Google completed a Wiz acquisition in 2026; brand retention is catalog context only and is not scored.
  • Sensor deployment, supported kernels, and module packaging are unverified from public operator docs.
  • Plans, SKU splits, and data-processing locations are unverified.
  • Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition.
  • Unknown dimensions reflect incomplete evidence for cumulative stage requirements, not proof that capabilities are absent.

Sources

0–5 rubric anchors

  • 0 — Primary evidence affirmatively establishes that the evaluated scope does not provide operating safeguards for the scoped assessment workflow. Missing evidence is unknown, never zero.
  • 1 — A concrete basic operating safeguard is documented for the evaluated edition.
  • 2 — Documented connector permissions, data handling, and enablement prerequisites for a bounded lab.
  • 3 — Documented connector or sensor health or status plus documented removal or rollback of integrations.
  • 4 — Documented coverage-gap visibility that distinguishes a missing connector or sensor from a clean finding, plus lifecycle or enablement notices.
  • 5 — Documented multi-control operating model covering connector and sensor health, account onboarding, module changes, and continuity together.
Assessed offerings inCNAPP and cloud posture platforms. Unknown means not scored, not low quality.
OfferingOperational maturityShipped innovationCapability breadthEcosystem & integrationGovernance & controlOperator enablement
WizUnknown3.0 (low)4.0 (medium)4.0 (medium)UnknownUnknown
Palo Alto Networks Cortex Cloud4.0 (medium)3.0 (low)4.0 (medium)4.0 (medium)2.0 (medium)4.0 (medium)
Microsoft Defender for Cloud4.0 (medium)3.0 (low)5.0 (medium)4.0 (medium)5.0 (medium)4.0 (medium)
Orca SecurityUnknown3.0 (low)4.0 (medium)4.0 (medium)Unknown3.0 (low)

Not yet assessed

Unknown is explicitly not low quality. These catalog offerings have no Atlas Fold scores.

Research notes

First edition dated 2026-09-21; no historical assessments are available.

The four selected existing-catalog offerings form one explicitly scoped cohort. Assessment applies only to named editions and documented modules; adjacent products and managed-service outcomes are excluded.

Primary sources establish documented capabilities and their prerequisites, not actual effectiveness, reliability, deployment effort, staffing savings or return on investment.

Confidence reflects evidence and inference within the stated scope, not vendor size, age or source count.

Contemporary cohort baseline: Multicloud posture and vulnerability assessment, identity/data context, graph or attack-path investigation, optional runtime telemetry, and routing or remediation orchestration are contemporary CNAPP baseline capabilities. Graph views, SideScanning architecture, plan packaging and a runtime sensor alone do not establish differentiated operator workflows.

Innovation stage 3 indicates supported baseline workflows, not market novelty. No stage 4 or 5 differentiation is established by this first-edition evidence. Public-documentation confidence is low for cross-offering calibration.

Zero requires affirmative evidence of absence. Missing, gated or incomplete documentation remains unknown; a lower stage is not assigned merely because documentation is unavailable.

Scores were checked against cumulative stage prerequisites; selected operating/control cells remain unknown where those prerequisites could not be verified.

Rubric 1.1 rechecked maturity and innovation primary sources. No partial step beyond maturity anchor 4 was established for Cortex Cloud or Defender for Cloud without re-awarding onboarding, connector health or lifecycle notices already required by earlier anchors. Wiz and Orca operating safeguards remain unknown where full procedures were not verified. Contemporary baseline innovation remains 3.0 for all four offerings; decimal support does not require breaking an evidence-supported tie.

All six dimensions were reviewed for the 2026-09-21 momentum baseline. Source-backed corrections and retained evidence gaps are recorded in docs/research/2026-09-21-momentum-baseline-a.md. These are baseline research decisions, not longitudinal vendor movement; unknowns remain unknown and the rubric/edition scopes are unchanged.

How to read these scores

Scores use tenths from 0.0 to 5.0 against published anchors. Fractional scores credit documented requirements toward the next anchor; the inspector exposes the calculation. Equal evidence can still produce a tie. Null means unknown and is never treated as zero. Views never average or blend dimensions into an overall winner. Cohort membership is the only comparison boundary.

What this edition covers.

First edition · reviewed · rubric 1.1. Historical movement will require later dated assessments; no trajectory is inferred from this snapshot.

  • First edition dated 2026-09-21; no historical assessments are available.
  • The four selected existing-catalog offerings form one explicitly scoped cohort. Assessment applies only to named editions and documented modules; adjacent products and managed-service outcomes are excluded.
  • Primary sources establish documented capabilities and their prerequisites, not actual effectiveness, reliability, deployment effort, staffing savings or return on investment.
  • Confidence reflects evidence and inference within the stated scope, not vendor size, age or source count.
  • Contemporary cohort baseline: Multicloud posture and vulnerability assessment, identity/data context, graph or attack-path investigation, optional runtime telemetry, and routing or remediation orchestration are contemporary CNAPP baseline capabilities. Graph views, SideScanning architecture, plan packaging and a runtime sensor alone do not establish differentiated operator workflows.
  • Innovation stage 3 indicates supported baseline workflows, not market novelty. No stage 4 or 5 differentiation is established by this first-edition evidence. Public-documentation confidence is low for cross-offering calibration.
  • Zero requires affirmative evidence of absence. Missing, gated or incomplete documentation remains unknown; a lower stage is not assigned merely because documentation is unavailable.
  • Scores were checked against cumulative stage prerequisites; selected operating/control cells remain unknown where those prerequisites could not be verified.
  • Rubric 1.1 rechecked maturity and innovation primary sources. No partial step beyond maturity anchor 4 was established for Cortex Cloud or Defender for Cloud without re-awarding onboarding, connector health or lifecycle notices already required by earlier anchors. Wiz and Orca operating safeguards remain unknown where full procedures were not verified. Contemporary baseline innovation remains 3.0 for all four offerings; decimal support does not require breaking an evidence-supported tie.
  • All six dimensions were reviewed for the 2026-09-21 momentum baseline. Source-backed corrections and retained evidence gaps are recorded in docs/research/2026-09-21-momentum-baseline-a.md. These are baseline research decisions, not longitudinal vendor movement; unknowns remain unknown and the rubric/edition scopes are unchanged.

CNAPP and cloud posture platforms

Comparable independently sold CNAPP/posture platforms with agentless cloud inventory plus optional runtime sensors: Wiz, Palo Alto Networks Cortex Cloud (Prisma Cloud lineage; not a separate prisma-cloud catalog slug), Microsoft Defender for Cloud, and Orca Security. Excludes native-only CSP suites (AWS Security Hub, Google Security Command Center), runtime-first specialists scored elsewhere, managed SOC services, and CyberArk/Idira identity products. Agentless API or snapshot findings are not live process coverage. Preview features are not scored as GA. Cohort baseline is agentless CSPM plus optional runtime sensing plus some graph or attack-path context.

Find your next idea.

Tip: press / to open search. Escape closes this window.