Generic software45% entry signalMarket screenOne thing must be trueincumbent vulnerability

CNAPP & Cloud Security Posture Management

Prepared 2026-09-16

Entry signal — what decides who wins here

One thing must be true
Structure decides One thing must be true Execution decides

Entry turns on a single condition that can be named and tested before much is spent. Clear it and this becomes an execution question; fail it and no amount of operating skill helps.

What you would have to beat

Displace an incumbent the screen found well defended — payments attached to the workflow, data that does not leave, a contract that renews itself. Share here means giving a buyer a reason to break something that currently works, which is a higher bar than being better.

How it was read
Binding constraintUNVERIFIEDincumbent vulnerability — Executional — a better operator can move it.
Measured inputsUNVERIFIEDnot applied — This is a software market. The industry’s business counts describe its BUYERS, not the market being entered, so they are left out of the signal.
How many new establishments are still tradingA
Professional, Scientific, and Technical Services, US · opened 2020
83.3%
1 year
64%
3 years
50.8%
5 years
34.3%
10 years
opened 2015

Measured, not forecast: the share of US establishments opening in one year that were still active later. It counts good operators and bad ones together, which is exactly why it is the honest answer to “what are the odds”. It is for the whole sector rather than this market, and the ten-year figure comes from an older cohort because no younger one has reached ten years.

This is not a probability of success, and it is not a verdict on you. No survival probability is published per market, and inventing one would be worse than saying so. What the bar reads is how much of the outcome sits inside an operator's control: green means the hurdles are ones a better operator clears, red means the binding constraint is capital, an asset or a permission rather than execution. Someone arriving with an advantage this screen did not assume can win a market shown in red.

Companies named in this market · 6

The binding constraint — incumbent vulnerability

The category just set the price of entry, and it is $32 billion. Google completed its purchase of Wiz on 11 March 2026 — the largest cybersecurity acquisition on record [B]. That settles who owns the independent leader, and it points at the structural problem underneath: the three hyperscalers each ship a native posture-management service with the cloud, so the buyer's default is already bundled. Palo Alto, CrowdStrike and Microsoft fold CNAPP into platform agreements a new entrant cannot price against. Unusually for this research, a strong open-source tier exists — Prowler, Cloud Custodian, ScoutSuite, Steampipe — because the artefact is a configuration scan rather than a network or a ledger, and that sets the floor at zero from below while the platforms squeeze from above.

Angel-backed companies130
in the Canadian portfolio dataset
Province mixON 43, QC 34, AB 19, NB 9, NS 8, NL 6, BC 4, PE 3, US 2, SK 1, — 1

Sectors joined: Cybersecurity · SaaS · Technology · Dev Tools · B2B SaaS · AI

[UNVERIFIED] Sector-to-NAICS mapping is analyst judgment — see data/angel-sector-map.json. Counts are a per-record cross-reference and are not additive across records.

I

The incumbent

Who owns this market and who is coming for it. Fields a screen never reached say so rather than guessing.

Incumbent
Wiz, now inside Google
Scale
Acquired by Google for $32B, closed 11 March 2026 — the largest cybersecurity acquisition in history [B]. Continues to operate under its own brand and across multiple clouds
Challengers
Palo Alto Prisma Cloud, CrowdStrike, Microsoft Defender for Cloud, Orca Security, Sysdig, Aqua
Lock-in mechanism
Agentless scanning needs cloud-account trust relationships, and those are granted once and rarely re-granted
Price movement
Compressed from both sides — hyperscaler bundling above, open-source scanners below
Is the buyer consolidating?
Yes — CSPM, CWPP, container, identity and data posture have all converged into CNAPP, and CNAPP is converging into the platform agreement
V

The field

Every vendor named on this record, and what each one discloses. Most disclose nothing, which is why the market is not sized.

Competitor set · 5 named · 0 disclose revenue

NameRevenueShareNote
Wiz (Google)NASDAQ: GOOGLB not disclosed — Acquired for $32B, closed 11 March 2026; no standalone revenue is published [B]
Palo Alto Prisma CloudNASDAQ: PANWC not disclosed — Reported inside Next-Generation Security ARR, not as a CNAPP line
CrowdStrikeNASDAQ: CRWDC not disclosed — Cloud security is a module of the platform; no separate line
Microsoft Defender for CloudNASDAQ: MSFTC not disclosed — Never broken out; bundled into Azure and E5 agreements
Orca Security / Sysdig / AquaC not disclosed — All private; no disclosure

Nobody here publishes revenue. The market is not sized for that reason — an estimate built on nothing would only look like knowledge.

V

Vendor landscape

Market leaders, the full paid field, and every open-source alternative. Where a free tier exists it is what sets the price floor, so it is analysis rather than an appendix.

WizB

Bought by Google for $32B, closed 11 March 2026 [B]

Microsoft / Palo Alto / CrowdStrikeC

Bundled into platform and cloud agreements; no CNAPP line reported

Paid field · 5 vendors

WizEnterprise

Agentless, multi-cloud; now Google-owned

Palo Alto Prisma CloudEnterprise

Platform-bundled

Microsoft Defender for CloudAzure estates

Bundled with the cloud

Orca SecurityEnterprise

Private; agentless

SysdigContainer-heavy

Private

Open source · 5 projects — the price floor

ProwlerApache-2.0

The most widely used open-source cloud security scanner; hundreds of checks across AWS, Azure and GCP

Cloud CustodianApache-2.0

CNCF project. Policy-as-code remediation, not just detection

ScoutSuiteGPL-2.0

Multi-cloud auditing from NCC Group

SteampipeAGPL-3.0

Queries cloud configuration as SQL; compliance mods ship as packs

OpenSCAPLGPL-2.1

Host-level configuration compliance; the basis of many benchmark scans

The open-source tier here is real and it is the reason the floor is zero. A posture scan is a config read against a public rule set, which a community can maintain — unlike a supplier network or a card programme. The paid tier sells triage, graph context and audit evidence, not the scan.

Evidence

Evidence. Market size UNVERIFIED — no vendor reports a CNAPP line, so no revenue floor could be built. The Wiz acquisition price and close date are corroborated across trade press [B] rather than read from a Google filing. A projection that cloud security exceeds $60B annually circulates from analyst commentary [C] and is NOT treated as a finding. Open-source projects and licences are from the projects themselves [C]. Verify before acting.

#

Where the industry talks

The associations, forums and events where people in this trade actually talk shop — where to listen before entering, and where the first customers are found. Each link was opened on the date shown.

AssociationInternationalA
Cloud Security Alliance (CSA)
cloudsecurityalliance.org

Publishes the Cloud Controls Matrix and STAR registry; has local chapters; no member count on the pages opened.

Checked 2026-09-22
EventNorth AmericaA
fwd:cloudsec
fwdcloudsec.org

Independent, vendor-neutral cloud-security conference; NA edition 1-2 Jun 2026 in Bellevue WA, Europe 7-8 Sep 2026 in London; also runs a Slack.

Checked 2026-09-22
SubredditInternationalA
r/cybersecurity
reddit.com

RSS feed returned posts dated 22 Sep 2026; general security practitioners, where cloud-posture tooling gets compared.

Checked 2026-09-22
PodcastInternationalA
Cloud Security Podcast
cloudsecuritypodcast.tv

Site claims 800+ episodes and 78k subscribers; explicitly covers CSPM and CNAPP.

Checked 2026-09-22
PublicationInternationalA
tl;dr sec
tldrsec.com

Weekly security-engineering newsletter; site claims over 90,000 subscribers.

Checked 2026-09-22
AssociationInternationalA
ISC2
isc2.org · 270,000 members (2026-09)

'More than 270,000 certified members and associates' per its About page; general cybersecurity body, not cloud-specific.

Checked 2026-09-22
EventCanadaC
SecTor (Black Hat)
blackhat.com

Blocked automated access (Cloudflare); Toronto security conference now run by Black Hat; sector.ca redirects here.

Checked 2026-09-22