CNAPP & Cloud Security Posture Management
Entry signal — what decides who wins here
One thing must be trueEntry turns on a single condition that can be named and tested before much is spent. Clear it and this becomes an execution question; fail it and no amount of operating skill helps.
Displace an incumbent the screen found well defended — payments attached to the workflow, data that does not leave, a contract that renews itself. Share here means giving a buyer a reason to break something that currently works, which is a higher bar than being better.
Measured, not forecast: the share of US establishments opening in one year that were still active later. It counts good operators and bad ones together, which is exactly why it is the honest answer to “what are the odds”. It is for the whole sector rather than this market, and the ten-year figure comes from an older cohort because no younger one has reached ten years.
This is not a probability of success, and it is not a verdict on you. No survival probability is published per market, and inventing one would be worse than saying so. What the bar reads is how much of the outcome sits inside an operator's control: green means the hurdles are ones a better operator clears, red means the binding constraint is capital, an asset or a permission rather than execution. Someone arriving with an advantage this screen did not assume can win a market shown in red.
Companies named in this market · 6
The binding constraint — incumbent vulnerability
The category just set the price of entry, and it is $32 billion. Google completed its purchase of Wiz on 11 March 2026 — the largest cybersecurity acquisition on record [B]. That settles who owns the independent leader, and it points at the structural problem underneath: the three hyperscalers each ship a native posture-management service with the cloud, so the buyer's default is already bundled. Palo Alto, CrowdStrike and Microsoft fold CNAPP into platform agreements a new entrant cannot price against. Unusually for this research, a strong open-source tier exists — Prowler, Cloud Custodian, ScoutSuite, Steampipe — because the artefact is a configuration scan rather than a network or a ledger, and that sets the floor at zero from below while the platforms squeeze from above.
Sectors joined: Cybersecurity · SaaS · Technology · Dev Tools · B2B SaaS · AI
[UNVERIFIED] Sector-to-NAICS mapping is analyst judgment — see data/angel-sector-map.json. Counts are a per-record cross-reference and are not additive across records.
The incumbent
Who owns this market and who is coming for it. Fields a screen never reached say so rather than guessing.
The field
Every vendor named on this record, and what each one discloses. Most disclose nothing, which is why the market is not sized.
Competitor set · 5 named · 0 disclose revenue
| Name | Revenue | Share | Note |
|---|---|---|---|
| Wiz (Google)NASDAQ: GOOGLB | not disclosed | — | Acquired for $32B, closed 11 March 2026; no standalone revenue is published [B] |
| Palo Alto Prisma CloudNASDAQ: PANWC | not disclosed | — | Reported inside Next-Generation Security ARR, not as a CNAPP line |
| CrowdStrikeNASDAQ: CRWDC | not disclosed | — | Cloud security is a module of the platform; no separate line |
| Microsoft Defender for CloudNASDAQ: MSFTC | not disclosed | — | Never broken out; bundled into Azure and E5 agreements |
| Orca Security / Sysdig / AquaC | not disclosed | — | All private; no disclosure |
Nobody here publishes revenue. The market is not sized for that reason — an estimate built on nothing would only look like knowledge.
Vendor landscape
Market leaders, the full paid field, and every open-source alternative. Where a free tier exists it is what sets the price floor, so it is analysis rather than an appendix.
Bought by Google for $32B, closed 11 March 2026 [B]
Bundled into platform and cloud agreements; no CNAPP line reported
Paid field · 5 vendors
Agentless, multi-cloud; now Google-owned
Platform-bundled
Bundled with the cloud
Private; agentless
Private
Open source · 5 projects — the price floor
The most widely used open-source cloud security scanner; hundreds of checks across AWS, Azure and GCP
CNCF project. Policy-as-code remediation, not just detection
Multi-cloud auditing from NCC Group
Queries cloud configuration as SQL; compliance mods ship as packs
Host-level configuration compliance; the basis of many benchmark scans
The open-source tier here is real and it is the reason the floor is zero. A posture scan is a config read against a public rule set, which a community can maintain — unlike a supplier network or a card programme. The paid tier sells triage, graph context and audit evidence, not the scan.
Evidence
Evidence. Market size UNVERIFIED — no vendor reports a CNAPP line, so no revenue floor could be built. The Wiz acquisition price and close date are corroborated across trade press [B] rather than read from a Google filing. A projection that cloud security exceeds $60B annually circulates from analyst commentary [C] and is NOT treated as a finding. Open-source projects and licences are from the projects themselves [C]. Verify before acting.
Where the industry talks
The associations, forums and events where people in this trade actually talk shop — where to listen before entering, and where the first customers are found. Each link was opened on the date shown.
Publishes the Cloud Controls Matrix and STAR registry; has local chapters; no member count on the pages opened.
Independent, vendor-neutral cloud-security conference; NA edition 1-2 Jun 2026 in Bellevue WA, Europe 7-8 Sep 2026 in London; also runs a Slack.
RSS feed returned posts dated 22 Sep 2026; general security practitioners, where cloud-posture tooling gets compared.
Site claims 800+ episodes and 78k subscribers; explicitly covers CSPM and CNAPP.
Weekly security-engineering newsletter; site claims over 90,000 subscribers.
'More than 270,000 certified members and associates' per its About page; general cybersecurity body, not cloud-specific.
Blocked automated access (Cloudflare); Toronto security conference now run by Black Hat; sector.ca redirects here.