CNAPP is not a capability. It is five capabilities sold together, and the only reason to buy them together is that they talk to each other.
The short answer
CNAPP stands for cloud-native application protection platform. It is an analyst category describing a suite that combines cloud posture, workload protection, cloud entitlements, infrastructure-as-code scanning and container security in one product. The claim is not that any one of those is new, but that combining them reveals risks none of them can see alone.
Judge a CNAPP on whether it delivers that combination. Several are five acquired tools behind one login.
On this page
What is inside a CNAPP
| Component | What it does |
|---|---|
| CSPM Cloud security posture management | Checks cloud accounts for misconfiguration: public storage, open security groups, unencrypted volumes, disabled logging |
| CWPP Cloud workload protection | Protects the running thing itself, whether a virtual machine, container or serverless function, through vulnerability detection and runtime monitoring |
| CIEM Cloud infrastructure entitlement management | Analyses who and what can do what in the cloud, and how far permissions could be chained beyond their intended reach |
| IaC scanning | Checks Terraform, CloudFormation and similar definitions before deployment, so a misconfiguration is caught in review rather than in production |
| Container and Kubernetes posture | Image vulnerability scanning, registry checks and cluster configuration review |
Some vendors also fold in DSPM for sensitive data discovery. The boundary of the category is set by marketing rather than by any standard, so two products both called a CNAPP can differ substantially.
The combination is the product
Four separate tools produce four findings on four dashboards. Each looks moderate. Together they are one exploitable path.
This is the only argument for buying a suite
Each of those findings sits in a backlog of hundreds. Ranked by severity in isolation, none of them reaches the top. What makes the combination urgent is reachability crossed with permission crossed with what sits at the end of the path, and no single-layer tool can compute it. If a CNAPP cannot show you that chain, you have bought a bundle discount rather than a platform.
Do you need one?
The category was designed for organisations running large multi-cloud estates with hundreds of engineers. Below that scale the honest answer changes.
| Situation | What is actually needed |
|---|---|
| One cloud, under 50 people | Posture management, image scanning and disciplined entitlements. A full suite mostly surfaces findings nobody has capacity to act on |
| Multi-cloud, growing engineering team | Correlation starts to earn its cost, because the paths now cross accounts and nobody holds the whole picture |
| Heavy Kubernetes footprint | Cluster and image posture become genuinely hard to do manually, and this is where the category is strongest |
| Regulated and audited | Continuous posture evidence matters more than attack path analysis. That is a narrower requirement |
| Mostly managed services, little container use | Much of a CNAPP would go unused. Posture and identity carry the weight |
Alert volume is the practical constraint. A suite that finds everything and prioritises nothing produces a backlog rather than a security improvement.
What frameworks ask for
No framework names CNAPP. They ask for outcomes the components happen to produce.
| Requirement | Which component evidences it |
|---|---|
| Secure configuration baselines | Posture management, with a record of drift and remediation |
| Vulnerability management | Image and workload scanning, with time-to-remediate by severity |
| Least privilege | Entitlement analysis and periodic role review |
| Change control | Infrastructure-as-code scanning results attached to the pull request that changed the environment |
| Logging and monitoring | Runtime detection feeding a SIEM with retained records |
| Risk-based prioritisation | Evidence that severity ratings account for exposure, not just CVSS score |
SOC 2, ISO 27001 and PCI DSS all sample the same underlying thing: a finding, a decision, a date and a fix.
Where Osto fits
Osto is not sold as a CNAPP suite. There is no Kubernetes posture module and no container runtime agent, and a heavy Kubernetes estate is a genuine reason to look at the dedicated category.
What Osto does cover is most of the ground a small cloud team actually stands on. Cloud posture management runs across AWS, Azure and GCP. Code security covers SAST, SCA and SBOM generation, so dependency risk is caught before deployment. Web and API protection covers the reachable surface at runtime, and access management governs who holds what.
The correlation argument still applies, from a different direction. Cloud posture, endpoint, identity and application events land in one SIEM on one stack, so a misconfiguration and the identity exploiting it appear in the same view rather than in two products that were integrated afterwards.
Platform walkthrough
Correlation without the integration project
Cloud posture, code security, API protection and access control on one stack, with findings and identity events in the same view. One owner, one dashboard.
Book a demoEvidence from live controls · 200+ frameworks mapped · One platform, everything
Frequently asked questions
What is CNAPP?
Cloud-native application protection platform. A suite combining cloud posture management, workload protection, entitlement analysis, infrastructure-as-code scanning and container security, on the argument that correlating those layers reveals risk none of them shows alone.
What is the difference between CNAPP and CSPM?
CSPM is one component of a CNAPP. It checks cloud configuration. A CNAPP adds workload protection, entitlements, code scanning and container posture on top, and attempts to connect their findings.
What is an attack path?
A chain of individually moderate findings that together allow real compromise: an exploitable workload that is internet reachable, holds an over-permissive role, and can access sensitive data. Computing that chain is the main thing a suite offers over separate tools.
Does a startup need a CNAPP?
Usually not the full suite. On one cloud with a small engineering team, posture management, dependency scanning and disciplined entitlements cover most of the risk. Full suites tend to generate more findings than a small team can work through.

