Book an Appointment

CNAPP & CSPM: from isolated finding to attack path

How CSPM, CWPP, CIEM, KSPM and DSPM are converging into Cloud-Native Application Protection Platforms – and why context determines effectiveness.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

5disciplines converging into CNAPP: CSPM, CWPP, CIEM, KSPM, DSPM
3 out of 4organizations had already adopted a CNAPP or were planning to (2023 CSA survey, 1,201 leaders)
32%were unable to prioritize security measures because of the flood of often imprecise alerts (CSA survey)
~32 bnUS dollars: Google's acquisition of Wiz, completed in March 2026

For years, cloud security fragmented into separate disciplines: configuration checks here, workload protection there, plus standalone tools for entitlements, Kubernetes and data. Cloud-Native Application Protection Platforms (CNAPP) – a term coined by the analyst firm Gartner – bring these functions together in a single platform with a shared data model. The real added value lies less in the sum of the functions than in the context: only by correlating misconfigurations, vulnerabilities, identities and network exposure does it become clear which risks are actually exploitable. This article maps out the terminology and sets out criteria for selection and operations.

The Essentials at a Glance

Six topic blocks — tap to expand.

Terminology map: CSPM to DSPM

Five cloud security disciplines at a glance — tap a tab.

Configurations
  • Continuously checks cloud configurations against policies and benchmarks.
  • Uncovers misconfigurations and compliance deviations.
Cloud Security Posture ManagementPoliciesBenchmarksMisconfigurationsCompliance deviations

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Microsoft Learn · 2026

Microsoft Defender for Cloud Overview

Describes Defender for Cloud as a CNAPP with the core components CSPM, DevSecOps and CWPP, including attack path analysis and the cloud security graph (as of April 2026).

Wiz Academy · 2026

CNAPP 101: An Intro to Cloud Native Application Protection Platforms

Vendor perspective on CNAPP components, agentless scanning and graph-based attack path analysis; also documents that the term was coined by Gartner (accessed July 2026).

Cloud Security Alliance · 2023

Cloud Native Application Protection Platform Survey Report

Survey of 1,201 IT and security leaders (commissioned by Microsoft) on CNAPP adoption in multi-cloud environments and prioritization problems caused by the flood of alerts.

Cloud Security Alliance – AI Safety Initiative · 2026

Wiz Joins Google: CNAPP Market Consolidation Risks

Research note dated March 13, 2026 on Google's acquisition of Wiz, completed on March 11, 2026, and on managing CNAPP vendor risks.

NIST · 2017

SP 800-190: Application Container Security Guide

Foundational document on container security across the entire lifecycle – from images through registries and orchestration to runtime.

BSI · 2020

Kriterienkatalog Cloud Computing (C5)

Minimum requirements for secure cloud computing and a reference framework for compliance audits to which CSPM policies can be mapped; according to the BSI, fundamentally revised in 2025/26.

Planning a CNAPP selection or rollout?

We support you vendor-neutrally with requirements analysis, proof of value and the operation of a CNAPP – and, as a Wiz partner, bring hands-on experience from implementation and 24/7 operations. Talk to us.