CSPM (Cloud Security Posture Management) continuously checks cloud configurations against policies and benchmarks, uncovering misconfigurations and compliance deviations. CWPP (Cloud Workload Protection Platform) protects the workloads themselves – virtual machines, containers and serverless functions – through vulnerability analysis and runtime monitoring. CIEM (Cloud Infrastructure Entitlement Management) inventories cloud identities along with their permissions and enforces the least-privilege principle. KSPM applies the posture concept to Kubernetes clusters; DSPM (Data Security Posture Management) locates sensitive data in cloud storage and assesses its exposure.
CNAPP & CSPM: from isolated finding to attack path
How CSPM, CWPP, CIEM, KSPM and DSPM are converging into Cloud-Native Application Protection Platforms – and why context determines effectiveness.
5disciplines converging into CNAPP: CSPM, CWPP, CIEM, KSPM, DSPM
3 out of 4organizations had already adopted a CNAPP or were planning to (2023 CSA survey, 1,201 leaders)
32%were unable to prioritize security measures because of the flood of often imprecise alerts (CSA survey)
~32 bnUS dollars: Google's acquisition of Wiz, completed in March 2026
For years, cloud security fragmented into separate disciplines: configuration checks here, workload protection there, plus standalone tools for entitlements, Kubernetes and data. Cloud-Native Application Protection Platforms (CNAPP) – a term coined by the analyst firm Gartner – bring these functions together in a single platform with a shared data model. The real added value lies less in the sum of the functions than in the context: only by correlating misconfigurations, vulnerabilities, identities and network exposure does it become clear which risks are actually exploitable. This article maps out the terminology and sets out criteria for selection and operations.
The Essentials at a Glance
Six topic blocks — tap to expand.
Terminology map: CSPM to DSPM
Five cloud security disciplines at a glance — tap a tab.
- Continuously checks cloud configurations against policies and benchmarks.
- Uncovers misconfigurations and compliance deviations.
Cloud Security Posture ManagementPoliciesBenchmarksMisconfigurationsCompliance deviations
- Protects the workloads themselves — virtual machines, containers and serverless functions.
- Works through vulnerability analysis and runtime monitoring.
Cloud Workload Protection PlatformVirtual machinesContainersServerless functionsRuntime monitoring
- Inventories cloud identities along with their permissions.
- Enforces the least-privilege principle.
Cloud Infrastructure Entitlement ManagementCloud identitiesPermissionsLeast-privilege principle
- Applies the posture concept to Kubernetes clusters.
Kubernetes clustersPosture
- Locates sensitive data in cloud storage and assesses its exposure.
Data Security Posture ManagementSensitive dataCloud storageExposure
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
Microsoft Defender for Cloud Overview
Describes Defender for Cloud as a CNAPP with the core components CSPM, DevSecOps and CWPP, including attack path analysis and the cloud security graph (as of April 2026).
CNAPP 101: An Intro to Cloud Native Application Protection Platforms
Vendor perspective on CNAPP components, agentless scanning and graph-based attack path analysis; also documents that the term was coined by Gartner (accessed July 2026).
Cloud Native Application Protection Platform Survey Report
Survey of 1,201 IT and security leaders (commissioned by Microsoft) on CNAPP adoption in multi-cloud environments and prioritization problems caused by the flood of alerts.
Wiz Joins Google: CNAPP Market Consolidation Risks
Research note dated March 13, 2026 on Google's acquisition of Wiz, completed on March 11, 2026, and on managing CNAPP vendor risks.
SP 800-190: Application Container Security Guide
Foundational document on container security across the entire lifecycle – from images through registries and orchestration to runtime.
Kriterienkatalog Cloud Computing (C5)
Minimum requirements for secure cloud computing and a reference framework for compliance audits to which CSPM policies can be mapped; according to the BSI, fundamentally revised in 2025/26.
Related Services
Planning a CNAPP selection or rollout?
We support you vendor-neutrally with requirements analysis, proof of value and the operation of a CNAPP – and, as a Wiz partner, bring hands-on experience from implementation and 24/7 operations. Talk to us.