CNAPP

CNAPP components and how correlated findings form an attack path

CNAPP is not a capability. It is five capabilities sold together, and the only reason to buy them together is that they talk to each other.

  • Glossary
  • Cloud

The short answer

CNAPP stands for cloud-native application protection platform. It is an analyst category describing a suite that combines cloud posture, workload protection, cloud entitlements, infrastructure-as-code scanning and container security in one product. The claim is not that any one of those is new, but that combining them reveals risks none of them can see alone.

Judge a CNAPP on whether it delivers that combination. Several are five acquired tools behind one login.

What is inside a CNAPP

ComponentWhat it does
CSPM
Cloud security posture management
Checks cloud accounts for misconfiguration: public storage, open security groups, unencrypted volumes, disabled logging
CWPP
Cloud workload protection
Protects the running thing itself, whether a virtual machine, container or serverless function, through vulnerability detection and runtime monitoring
CIEM
Cloud infrastructure entitlement management
Analyses who and what can do what in the cloud, and how far permissions could be chained beyond their intended reach
IaC scanningChecks Terraform, CloudFormation and similar definitions before deployment, so a misconfiguration is caught in review rather than in production
Container and Kubernetes postureImage vulnerability scanning, registry checks and cluster configuration review

Some vendors also fold in DSPM for sensitive data discovery. The boundary of the category is set by marketing rather than by any standard, so two products both called a CNAPP can differ substantially.

The combination is the product

Four separate tools produce four findings on four dashboards. Each looks moderate. Together they are one exploitable path.

Container has a critical CVE Found by image scanning It is reachable from the internet Found by posture management Its role is over-permissive Found by entitlement analysis That role reaches customer data Found by data discovery correlate One attack path, not four medium findings Internet reachable, exploitable, over-permissioned, and one hop from the data that matters

This is the only argument for buying a suite

Each of those findings sits in a backlog of hundreds. Ranked by severity in isolation, none of them reaches the top. What makes the combination urgent is reachability crossed with permission crossed with what sits at the end of the path, and no single-layer tool can compute it. If a CNAPP cannot show you that chain, you have bought a bundle discount rather than a platform.

Do you need one?

The category was designed for organisations running large multi-cloud estates with hundreds of engineers. Below that scale the honest answer changes.

SituationWhat is actually needed
One cloud, under 50 peoplePosture management, image scanning and disciplined entitlements. A full suite mostly surfaces findings nobody has capacity to act on
Multi-cloud, growing engineering teamCorrelation starts to earn its cost, because the paths now cross accounts and nobody holds the whole picture
Heavy Kubernetes footprintCluster and image posture become genuinely hard to do manually, and this is where the category is strongest
Regulated and auditedContinuous posture evidence matters more than attack path analysis. That is a narrower requirement
Mostly managed services, little container useMuch of a CNAPP would go unused. Posture and identity carry the weight

Alert volume is the practical constraint. A suite that finds everything and prioritises nothing produces a backlog rather than a security improvement.

What frameworks ask for

No framework names CNAPP. They ask for outcomes the components happen to produce.

RequirementWhich component evidences it
Secure configuration baselinesPosture management, with a record of drift and remediation
Vulnerability managementImage and workload scanning, with time-to-remediate by severity
Least privilegeEntitlement analysis and periodic role review
Change controlInfrastructure-as-code scanning results attached to the pull request that changed the environment
Logging and monitoringRuntime detection feeding a SIEM with retained records
Risk-based prioritisationEvidence that severity ratings account for exposure, not just CVSS score

SOC 2, ISO 27001 and PCI DSS all sample the same underlying thing: a finding, a decision, a date and a fix.

Where Osto fits

Osto is not sold as a CNAPP suite. There is no Kubernetes posture module and no container runtime agent, and a heavy Kubernetes estate is a genuine reason to look at the dedicated category.

What Osto does cover is most of the ground a small cloud team actually stands on. Cloud posture management runs across AWS, Azure and GCP. Code security covers SAST, SCA and SBOM generation, so dependency risk is caught before deployment. Web and API protection covers the reachable surface at runtime, and access management governs who holds what.

The correlation argument still applies, from a different direction. Cloud posture, endpoint, identity and application events land in one SIEM on one stack, so a misconfiguration and the identity exploiting it appear in the same view rather than in two products that were integrated afterwards.

Platform walkthrough

Correlation without the integration project

Cloud posture, code security, API protection and access control on one stack, with findings and identity events in the same view. One owner, one dashboard.

Book a demo

Evidence from live controls · 200+ frameworks mapped · One platform, everything

Frequently asked questions

What is CNAPP?

Cloud-native application protection platform. A suite combining cloud posture management, workload protection, entitlement analysis, infrastructure-as-code scanning and container security, on the argument that correlating those layers reveals risk none of them shows alone.

What is the difference between CNAPP and CSPM?

CSPM is one component of a CNAPP. It checks cloud configuration. A CNAPP adds workload protection, entitlements, code scanning and container posture on top, and attempts to connect their findings.

What is an attack path?

A chain of individually moderate findings that together allow real compromise: an exploitable workload that is internet reachable, holds an over-permissive role, and can access sensitive data. Computing that chain is the main thing a suite offers over separate tools.

Does a startup need a CNAPP?

Usually not the full suite. On one cloud with a small engineering team, posture management, dependency scanning and disciplined entitlements cover most of the risk. Full suites tend to generate more findings than a small team can work through.

Is CNAPP required by any compliance framework?

No framework names it. SOC 2, ISO 27001 and PCI DSS ask for secure baselines, vulnerability management, least privilege and change control. Those outcomes can be evidenced with or without a suite.