An agent on a laptop and an agent on a container are not the same problem. Most endpoint vendors sell you the former and call it cloud security.

Cloud security is two purchases wearing one name: posture — what is misconfigured, over-privileged or vulnerable across your accounts, read agentlessly from APIs — and protection — something running on the workload or in the cluster that can block and respond. Every vendor sells one well and the other as a module.

Tenable Cloud Security is 100% agentless by design and provides no runtime protection. Wiz Defend needs the Wiz Sensor to act at runtime. Same category; opposite halves.

Already decided — before the architecture review

Whether agents are alloweddecides posture-only or runtime
Which clouds, and whether VMware still existsdecides depth, not logos
The sensor already on your serversis a candidate for the workload half

Still yours to weigh

Posture or protectionCSPM · CWPP · both
Agentless or agentAPI reads · sensor · both
What's in the boxCIEM · code · containers
If you’ve never bought one

What cloud and workload security actually is

Your workloads are in someone else’s data centre, built by engineers, changed by pipelines, and exposed by configuration rather than by malware. Two disciplines grew up around that. Posture reads your cloud accounts through their APIs — with no agent — and finds misconfiguration, vulnerable images, over-privileged identities and the paths that join them. Workload protection runs on the VM, the container host or in the Kubernetes cluster and can block, isolate and respond at runtime.

The market has stitched them into one word, CNAPP — but every product here has a home half. The agentless specialists (Wiz, Tenable, Check Point) are posture-first and add runtime by module or agent; the endpoint vendors (CrowdStrike, SentinelOne, Trend, Sophos, Bitdefender, Kaspersky) are runtime-first and add posture by acquisition; the vulnerability vendors (Qualys, Tenable) extend their risk model into the cloud. Knowing which half a vendor was born in tells you where its depth is.

The line that matters most

A laptop agent watches one user’s machine; a workload sensor must survive immutable images, autoscaling, ephemeral containers and Kubernetes admission — and often is not allowed at all. Ask every endpoint vendor how their cloud product works without their agent; ask every agentless vendor what happens at runtime.

Often confused withEndpoint Protection — an agent on a laptop is not an agent on a container·Vulnerability Management — where posture and vulnerability merge·SIEM & Log Management — where the cloud logs land·SASE & SSE — where SSE stops and cloud workload protection begins

The six routes of security — and which one is yours

Boundary — the terms this buyer confuses

CSPM vs CWPP vs CIEM vs CNAPP

Four acronyms this buyer confuses, and nothing more. Three are scopes; the fourth is the bundle. None is a tier of quality — each adds something to read or run, costs more, and needs more owners on your side.

CSPM — Cloud Security Posture Management

Reads your cloud accounts through their APIs and finds misconfiguration, exposure and drift against benchmarks — agentless by nature. The foundation, and the half the agentless specialists were born in. Finds; does not block.

CWPP — Cloud Workload Protection Platform

Runs on the VM, the container host or in the cluster: vulnerability and malware detection, runtime behaviour, blocking and response. The half the endpoint vendors were born in. Needs something installed — a sensor, an agent, an admission controller.

CIEM — Cloud Infrastructure Entitlement Management

Who (human or machine) can do what, to which resource, across accounts — effective permissions, toxic combinations, least-privilege recommendations. Identity is the cloud's perimeter; CIEM is the only scope that reads it. Agentless; findings need an owner in the platform team.

CNAPP — Cloud-Native Application Protection Platform

The bundle: CSPM + CWPP + CIEM, usually plus code / IaC scanning and data posture, on one risk graph. Not a product you can buy whole from most vendors — it is the label on whichever half they started with plus the modules they added.

Scopes, not tiers. CSPM reads, CWPP runs, CIEM reads identity, CNAPP is the label for all of them together. Each adds cost and an owner; the posture-only buyer and the runtime-only buyer are both buying half — deliberately is fine, by accident is the failure mode of this category.
The decision variables

Six things decide this purchase. The feature grid is none of them.

Six variables decide this purchase. The instrument tests posture-vs-runtime, agentless-vs-agent, CIEM, code scanning, on-prem coverage and the small-estate floor; cloud depth and container depth are prose because every datasheet lists all three clouds and every product scans images.

01

CSPM vs CWPP vs CIEM vs code — what's actually included

Every vendor sells the bundle name; the chips name which scopes each SKU actually contains, and which are separate modules.

02

Agentless vs agent-based vs both

Agentless reads accounts in hours with nothing installed and cannot block; agents run on the workload and can. Most vendors now do both — the chip shows which side is native.

03

Which clouds are genuinely covered at depth

All list AWS, Azure, GCP; depth follows where each vendor's customers live. Ask for the supported-services list per cloud and test your smallest one.

04

Container and Kubernetes depth

Image scanning is universal; admission control and in-cluster runtime are not. Kaspersky Container Security, Wiz Defend, CrowdStrike, SentinelOne, Trend, FortiCNAPP, Check Point and Qualys document runtime.

05

Shift-left / IaC scanning

Terraform, CloudFormation, Kubernetes manifests and images scanned in CI, tied to the production graph — only worth it if engineering wires the gate in.

06

Runtime protection vs posture only

The honest split: Tenable and the Wiz posture modules never block; the endpoint-heritage vendors and Wiz Defend do. Buying half is fine if you know which half.

The narrowing instrument · the reasoning is the product

Narrow 16 products to your shortlist

Set what holds for you. Products that fail a constraint fade with the reason on them; where a scope is not documented either way the card is flagged and stays. Unset a chip and everything returns.

What's included

Posture, or protection

Where the workloads are

Agent or agentless

Estate size

Cloud depth, container depth and India residency are in the notes below, not chips — every datasheet lists all three clouds, every product scans images, and three vendors document an India region.

Still in16/ 16
Wiz logo
~$15–30₹1,245

per workload / year reported under 500 workloads (Essential ~$24k / yr for 100; $8–20 at 2,000–10,000; $6–15 above); agentless snapshot scanning; Google-owned (2026)

The agentless reference: posture, vulnerabilities and attack paths across AWS, Azure and GCP in hours, with no agent — and the Security Graph everyone else now copies.

The catch: Posture SKU — runtime protection is Wiz Defend with the Sensor, and CIEM, Code and DSPM are separate modules; reported minimums rule out very small estates; India region not documented.

Agentless referencePosture SKUModular
Intel page →
Wiz logo
Module

add-on module to Wiz — identities, entitlements, effective permissions, least-privilege recommendations

Wiz estates that need to know which identity can reach which data, and what to take away.

The catch: A module over Wiz's graph — not standalone; findings need an owner or they age.

CIEMModule
Intel page →
Wiz logo
Module

add-on (reported ~$58,500 / yr) — IaC, container images, secrets and code-to-cloud tracing in CI

Teams fixing cloud risk in the pull request rather than in production.

The catch: A module; useful only with engineering adoption; priced as an enterprise add-on.

Shift-leftModule
Intel page →
Wiz logo

add-on (reported ~$18,000 / yr) + Wiz Sensor (eBPF, reported ~$28,000 / yr) — cloud detection and response on running workloads and Kubernetes

Wiz estates that need runtime detection and response, not just a prioritised posture list.

The catch: Needs the Sensor on the workloads — the agentless story ends here; on-prem coverage not documented; priced as modules on top of Wiz.

Runtime (CDR)Needs SensorModule
Intel page →
Wiz logo
Module

add-on — data discovery and classification in cloud stores, joined to exposure paths

Wiz estates that want the sensitive data in the graph next to the path to it.

The catch: Data posture, not data protection — it finds and ranks; it does not encrypt or block; a module.

DSPMModule
Intel page →
Check Point logo

consumption-based per billable asset; Agentless Workload Posture (AWP), CIEM, Effective Risk Management, pipeline security; runtime via workload agents

Check Point estates wanting a prevention-first CNAPP — posture, entitlements and code scanning agentless, runtime where you deploy agents.

The catch: Quote-only consumption pricing; depth of runtime is agent-dependent; India region not documented.

Agentless + agentCIEM + codeQuote-only
Intel page →
Qualys logo

per cloud connector (CSPM) + per workload (CWPP); FlexScan agent and agentless; TruRisk scoring; India platform

Qualys estates extending VMDR's TruRisk into cloud posture, workload protection and IaC — one tenant for hosts and clouds.

The catch: Quote-only on two meters; strongest for Qualys customers; CIEM is newer than the rest of the suite.

Agentless + agentTruRiskIndia platform
Intel page →
Tenable logo

per billable resource (VMs, container hosts, functions, images, data stores); 100% agentless; CSPM + CIEM (Ermetic lineage) + vulnerability + IaC

Tenable estates — and anyone who wants posture, entitlements and vulnerabilities with nothing installed — and accepts there is no runtime blocking.

The catch: Posture only by design: 100% agentless means no runtime protection on the workload; quote-only; India region not documented.

100% agentlessCIEM (Ermetic)No runtime
Intel page →
Trend Micro logo

Vision One credits — Conformity posture (agentless), workload protection agents (Deep Security lineage), container security, template scanning

Trend estates — including on-prem VMware servers — wanting posture and agent-based runtime in the same XDR as endpoint and email.

The catch: Credit-priced and opaque until you run it; CIEM depth not documented; strongest inside Vision One.

Agentless + agentOn-prem workloadsCredit-based
Intel page →
Fortinet logo
from ~$25,000₹20,75,000

per year starter pack (annual or BYOL); agentless + Lacework agent; CSPM, CIEM, CWPP, code; Security Fabric integration

Fortinet estates — and Lacework's behavioural-anomaly fans — wanting a CNAPP with a published starter price.

The catch: A starter-pack floor, then quote; on-prem coverage via the agent is not documented here; India region not documented.

Agentless + agentPublished starterSecurity Fabric
Intel page →
Bitdefender logo

CSPM+ (agentless posture) per account; workload and container protection via GravityZone agents incl. on-prem virtualised servers

GravityZone estates adding cloud posture to the workload protection they already run on VMs and containers, cloud or on-prem.

The catch: CIEM and code scanning are not documented; quote-only; cloud posture is newer than the workload protection.

Agentless + agentOn-prem workloadsQuote-only
Intel page →
SentinelOne logo

agentless CNAPP (PingSafe lineage) + Cloud Workload Security agent; CSPM, CIEM, IaC, Kubernetes runtime; Mumbai region

SentinelOne estates wanting agentless posture plus the Singularity agent's runtime on servers and Kubernetes, with an India region.

The catch: Quote-only; CNAPP breadth is newer than the endpoint heritage; strongest when SentinelOne is already the agent.

Agentless + agentMumbai regionQuote-only
Intel page →
CrowdStrike logo

Falcon sensor for workload protection + agentless snapshot scanning; CSPM, CIEM, IaC, cloud detection and response; quote-only

Falcon estates that want the sensor's runtime on servers and containers plus agentless posture in the same console as endpoint.

The catch: Quote-only; agentless is a fallback for where the sensor cannot go, not the design centre; India in-country cloud announced, not yet documented live.

Sensor + agentlessCDRQuote-only
Intel page →
Kaspersky logo

per node (VM / server), agent-based; VMware, Hyper-V, OpenStack and AWS / Azure / GCP workloads

Estates that want agent-based workload protection across private and public clouds from one console, including VMware and OpenStack.

The catch: Workload protection, not a CNAPP — no CSPM, CIEM or code scanning; procurement caveats in some sectors; quote-only.

Agent-basedPrivate cloudProcurement caveat
Intel page →
Kaspersky logo

per node; image scanning in CI / registry, admission control, runtime for Kubernetes on-prem or in cloud

Kubernetes estates — on-prem included — wanting image, admission and runtime security from one vendor.

The catch: Containers only; no cloud posture or entitlements; procurement caveats; quote-only.

KubernetesAgent-basedProcurement caveat
Intel page →
Sophos logo

per user and per server, pay-as-you-go on AWS Marketplace or via partners; Intercept X for Server runtime + Cloud Optix posture / IAM visualisation / IaC; Sophos Central (Mumbai region)

Sophos Central estates that want server runtime (Intercept X) and cloud posture (Cloud Optix) beside their MDR — and a published PAYG meter.

The catch: Posture depth trails the agentless specialists; PAYG rates are on the marketplace, not a list; strongest inside Sophos.

Agent + agentlessPAYGIndia region (Mumbai)
Intel page →
Why each constraint rules out what it doesShow the reasoning ↓

CIEMRules out Wiz CSPM (Wiz Essential / Advanced), Wiz Code, Wiz Defend (runtime, with Wiz Sensor), Wiz DSPM, Kaspersky Hybrid Cloud Security and Kaspersky Container Security — no cloud identity / entitlement management in this SKU. That leaves Wiz CIEM, Check Point CloudGuard CNAPP, Qualys TotalCloud, Tenable Cloud Security, Trend Vision One Cloud Security, Fortinet FortiCNAPP (Lacework), Bitdefender GravityZone Cloud Security (CSPM+), SentinelOne Singularity Cloud Security, CrowdStrike Falcon Cloud Security and Sophos Cloud Native Security. It flags Trend Vision One Cloud Security — CIEM depth not documented and Bitdefender GravityZone Cloud Security (CSPM+) — CIEM depth not documented — marked on the cards, not removed.

Shift-left and IaC scanningRules out Wiz CSPM (Wiz Essential / Advanced), Wiz CIEM, Wiz Defend (runtime, with Wiz Sensor), Wiz DSPM and Kaspersky Hybrid Cloud Security — no IaC / code scanning in this SKU. That leaves Wiz Code, Check Point CloudGuard CNAPP, Qualys TotalCloud, Tenable Cloud Security, Trend Vision One Cloud Security, Fortinet FortiCNAPP (Lacework), Bitdefender GravityZone Cloud Security (CSPM+), SentinelOne Singularity Cloud Security, CrowdStrike Falcon Cloud Security, Kaspersky Container Security and Sophos Cloud Native Security. It flags Bitdefender GravityZone Cloud Security (CSPM+) — Code scanning not documented — marked on the cards, not removed.

Runtime protection on the workloadRules out Wiz CSPM (Wiz Essential / Advanced) — a posture SKU; runtime is a separate module (Wiz Defend + Sensor) from the same vendor; Wiz CIEM, Wiz Code, Wiz DSPM and Tenable Cloud Security — posture and visibility only; nothing runs on the workload to block or respond. That leaves Wiz Defend (runtime, with Wiz Sensor), Check Point CloudGuard CNAPP, Qualys TotalCloud, Trend Vision One Cloud Security, Fortinet FortiCNAPP (Lacework), Bitdefender GravityZone Cloud Security (CSPM+), SentinelOne Singularity Cloud Security, CrowdStrike Falcon Cloud Security, Kaspersky Hybrid Cloud Security, Kaspersky Container Security and Sophos Cloud Native Security.

Private-cloud and on-prem workloadsRules out Wiz CSPM (Wiz Essential / Advanced), Wiz CIEM, Wiz Code, Wiz DSPM and Tenable Cloud Security — public-cloud accounts only. That leaves Wiz Defend (runtime, with Wiz Sensor), Check Point CloudGuard CNAPP, Qualys TotalCloud, Trend Vision One Cloud Security, Fortinet FortiCNAPP (Lacework), Bitdefender GravityZone Cloud Security (CSPM+), SentinelOne Singularity Cloud Security, CrowdStrike Falcon Cloud Security, Kaspersky Hybrid Cloud Security, Kaspersky Container Security and Sophos Cloud Native Security. It flags Wiz Defend (runtime, with Wiz Sensor) — On-prem workload coverage not documented, Check Point CloudGuard CNAPP — On-prem workload coverage not documented and Fortinet FortiCNAPP (Lacework) — On-prem workload coverage not documented — marked on the cards, not removed.

Agentless onlyRules out Wiz Defend (runtime, with Wiz Sensor), Kaspersky Hybrid Cloud Security and Kaspersky Container Security — agent-based only. That leaves Wiz CSPM (Wiz Essential / Advanced), Wiz CIEM, Wiz Code, Wiz DSPM, Check Point CloudGuard CNAPP, Qualys TotalCloud, Tenable Cloud Security, Trend Vision One Cloud Security, Fortinet FortiCNAPP (Lacework), Bitdefender GravityZone Cloud Security (CSPM+), SentinelOne Singularity Cloud Security, CrowdStrike Falcon Cloud Security and Sophos Cloud Native Security. It flags Check Point CloudGuard CNAPP — Agentless posture; runtime protection needs its agent / sensor, Qualys TotalCloud — Agentless posture; runtime protection needs its agent / sensor, Trend Vision One Cloud Security — Agentless posture; runtime protection needs its agent / sensor, Fortinet FortiCNAPP (Lacework) — Agentless posture; runtime protection needs its agent / sensor, Bitdefender GravityZone Cloud Security (CSPM+) — Agentless posture; runtime protection needs its agent / sensor, SentinelOne Singularity Cloud Security — Agentless posture; runtime protection needs its agent / sensor, CrowdStrike Falcon Cloud Security — Agentless posture; runtime protection needs its agent / sensor and Sophos Cloud Native Security — Agentless posture; runtime protection needs its agent / sensor — marked on the cards, not removed.

Under 100 workloadsRules nothing out on published terms. It flags Wiz CSPM (Wiz Essential / Advanced) — Essential ≈ $24,000 / yr for 100 workloads, Wiz Code — Reported ~$58,500 / yr add-on, Wiz Defend (runtime, with Wiz Sensor) — Reported ~$18,000 / yr add-on; Sensor ~$28,000 / yr and Fortinet FortiCNAPP (Lacework) — Starter packs from ~$25,000 / yr — marked on the cards, not removed.

Which clouds are genuinely covered at depthRules nothing out on documentation — every product here lists AWS, Azure and GCP. Depth is the question the datasheet cannot answer: the agentless specialists (Wiz, Tenable, Check Point AWP) document the widest service coverage across all three; the endpoint-heritage vendors are deepest on the cloud their customers run most; Kaspersky Hybrid Cloud is deepest on private virtualisation. Ask for the list of supported services per cloud, and test the one you use least.

Containers and Kubernetes depthRules nothing out as a chip because every product here scans images; what differs is admission control and runtime in the cluster: Kaspersky Container Security, Wiz Defend, CrowdStrike, SentinelOne, Trend, FortiCNAPP, Check Point and Qualys document runtime; Tenable and the Wiz posture modules scan images and configuration without running in the cluster; Bitdefender and Sophos run via their server agents. Ask which Kubernetes distributions and which node types.

India data residencyDocumented: SentinelOne (Mumbai), Sophos Central (Mumbai), Qualys (India platform). CrowdStrike's India in-country cloud is announced (January 2026); Wiz, Check Point, Tenable, Trend, Fortinet, Bitdefender and Kaspersky do not document an India region for cloud-security telemetry — flagged, not ruled out. Note that the workloads themselves already live in a region; the question is where the findings and snapshots are stored.

Narrow to your situation

Eight situations, eight shortlists — starting from whether agents are allowed

Every shortlist begins with posture or protection, agent or not. The vendor's home half follows.

Three clouds, no agents allowed, answer in a week

Why: Agentless posture, vulnerabilities, entitlements and attack paths across AWS, Azure and GCP from API access alone — Wiz's design centre, Tenable's 100%-agentless stance, Check Point's AWP.

The trade-off: Posture only: nothing blocks at runtime until you add Wiz Defend's Sensor or Check Point's agents; Tenable never does. Reported minimums put Wiz out of reach below ~100 workloads.

Something is running in the cluster and must be stopped

Why: Runtime detection and response on workloads and Kubernetes: Wiz Defend with the eBPF Sensor, the Falcon sensor, the Singularity agent — the endpoint vendors' strength.

The trade-off: All three need something installed; the agentless story ends at runtime. Kaspersky Container Security and Trend are the on-prem-friendly alternatives.

You already run CrowdStrike, SentinelOne, Trend or Sophos on servers

Why: The sensor you already run becomes the workload-protection agent, with agentless posture added in the same console — one agent estate, one XDR.

The trade-off: Posture depth trails the agentless specialists; quote-only (Trend in credits); an agent on a laptop is still not an agent on a container — test the Kubernetes story specifically.

You already run Qualys or Tenable for vulnerabilities

Why: TruRisk or VPR extended into cloud accounts and workloads from the tenant you already use — one risk model for hosts and clouds.

The trade-off: Qualys meters per connector and per workload on quote; Tenable is posture only with no runtime. Neither is a reason to skip runtime protection if you need it.

Private cloud — VMware, OpenStack, on-prem Kubernetes

Why: Agent-based workload and container protection that documents VMware, Hyper-V and OpenStack alongside the public clouds; Trend and Sophos server agents are the other on-prem-friendly paths.

The trade-off: Kaspersky carries procurement caveats in some sectors and brings no posture or CIEM; Bitdefender's posture is newer than its workload protection.

Cloud identity is the attack surface — who can reach what

Why: Entitlement analysis and least-privilege recommendations: Wiz's CIEM module, Tenable's Ermetic lineage, CloudGuard's CIEM with effective risk.

The trade-off: CIEM findings need an owner in the platform team; a list of over-privileged roles nobody removes is the cloud version of scan results nobody actions.

Fix it in the pull request — IaC, images, secrets

Why: Shift-left scanning tied to the same risk graph as production: Wiz Code's code-to-cloud tracing, CloudGuard pipeline security, FortiCNAPP's IaC and image scanning — CrowdStrike, SentinelOne, Qualys, Trend and Tenable also scan IaC.

The trade-off: Engineering adoption decides the value; a CI gate nobody wired in is a licence. Wiz Code is priced as an enterprise add-on.

Published price, Fortinet fabric, or a PAYG meter

Why: FortiCNAPP publishes a ~$25,000 starter pack; Sophos Cloud Native Security is pay-as-you-go per user and server on AWS Marketplace; Wiz's tiers are reported by resellers (~$24k Essential for 100 workloads).

The trade-off: Starter packs and PAYG are floors, not ceilings; the rest of the field is quote-only or credit-priced — the normal state of this market.

The spine of the decision

Every vendor was born in one half. That is where its depth is.

Three lineages sell the same acronym. Place each product by where it started and you know what to test hardest.

Lineage 1

Agentless posture first

Born reading cloud APIs: snapshot the workload, analyse it off-box, draw the graph. Hours to deploy, nothing installed, widest service coverage across clouds — and nothing blocks at runtime until a sensor or agent is added (Wiz Defend + Sensor; Check Point agents). Tenable stays 100% agentless on purpose.

Lineage 2

Endpoint agent first

Born on the server agent: runtime detection, blocking, response on VMs and containers — and on-prem VMware too. Posture was added by acquisition (SentinelOne's PingSafe, Sophos's Cloud Optix, Trend's Conformity, CrowdStrike's builds) and is newer than the runtime. Test the agentless and Kubernetes stories specifically.

Lineage 3

Vulnerability platform first

Born on the risk model: extend TruRisk or VPR into cloud accounts and workloads, one tenant for hosts and clouds. Qualys runs both agent and agentless (FlexScan) with workload protection; Tenable stays posture-only; FortiCNAPP (Lacework) is the behavioural-anomaly outlier with agentless and agent.

Agentless vs agent — what each can and cannot do

Read in hours, or act at runtime. Rarely both from one install.

  • Agentless (API reads, snapshot scans): every account in a day, no change to images or pipelines, no runtime overhead — and no blocking, no live process view, and a blind spot between snapshots. Wiz, Tenable, Check Point AWP, Qualys FlexScan, CrowdStrike snapshot scanning, SentinelOne agentless CNAPP, FortiCNAPP, Trend Conformity, Bitdefender CSPM+, Sophos Cloud Optix.
  • Agent / sensor (eBPF, kernel module, admission controller): live runtime, blocking, forensics — and an install into images, autoscaling groups and clusters that platform teams resist. Wiz Sensor, Falcon, Singularity, Trend, Intercept X for Server, GravityZone, Kaspersky, Lacework agent, CloudGuard agents.
  • Both is the mature answer — and most vendors now offer it. The question is which side is native and which is the add-on.

The PoC that tells the truth

Five tests, in this order.

  • Connect your smallest cloud and count supported services against the vendor’s list for your biggest one.
  • Deploy to one Kubernetes namespace with admission control on; push a known-bad image; see what is blocked and where the alert lands.
  • Create a toxic entitlement (a role that can read a data store and assume admin) and see whether CIEM names it and the path to it.
  • Break a Terraform module in a branch and see whether the pipeline gate fires with the same finding the production graph shows.
  • Start a process in a running container and time the detection — posture tools will not see it; that is the point of the test.
What breaks as you grow

What changes at 100, 1,000 and 10,000 workloads

Cloud estates scale by workloads that appear and vanish hourly. The meter, the alert volume and the number of owners are what change.

100workloads

The floor is the constraint

  • Reported minimums (Wiz Essential ~$24k / yr for 100 workloads; FortiCNAPP ~$25k starter) decide the field before features do.
  • Your cloud provider's native tools (Defender for Cloud, Inspector, Security Command Center) may be the honest posture layer at this size.
  • One platform engineer owns everything — including the findings.

Put this in your PoC

Connect one account to a trial, count the findings, and ask who will close the top ten this week.

1,000workloads

Ownership and noise are the constraint

  • Intentional misconfigurations (public buckets that are meant to be public) generate alerts nobody wants; exceptions need an owner.
  • CIEM findings pile up in the platform team's queue; runtime alerts in the SOC's — two owners, one graph.
  • Agent rollout into autoscaling groups and clusters is an engineering project, not a security one.

Put this in your PoC

Measure alert volume per owner for a month; test the exception workflow; deploy the agent through your image pipeline, not by hand.

10,000workloads

Multi-cloud depth and meters are the constraint

  • Per-workload and per-resource meters climb with ephemeral workloads; ask how short-lived containers are counted.
  • Depth on your second and third cloud is where the agentless specialists and the endpoint lineage diverge most.
  • Data residency for snapshots and findings becomes a question — three vendors document an India region.

Put this in your PoC

Pull the full inventory through the API and reconcile it with the cloud billing export; price ephemeral workloads explicitly.

Wiz, CrowdStrike, SentinelOne, Check Point, Qualys, Tenable, Trend and FortiCNAPP document very large estates; Bitdefender’s and Sophos’s cloud posture and Kaspersky’s container product document less at scale — flagged in prose, not ruled out. Where a specific console strains for your estate: [TechBag to confirm].

The switching cost

Switching posture tools is a re-connect; switching runtime is a re-deploy

Agentless products leave in an afternoon; agents leave with the next image build. The findings, exceptions and pipeline gates are what move slowly.

Agentless connectors

Revoke the old read-only roles, grant the new; findings repopulate in hours. The lightest switch in security — which is also why agentless vendors fight hardest on renewals.

Exit costRe-connect

Agents and sensors

Rebuild images, roll autoscaling groups, redeploy DaemonSets; the old sensor lingers on long-lived VMs until someone removes it.

Exit costRe-deploy

Exceptions and risk acceptances

Every accepted public bucket, every tolerated permission and every suppressed rule is rebuilt by hand in the new graph.

Exit costRebuild

Pipeline gates and integrations

CI gates, ticketing, SIEM and MDR integrations are re-wired; a different risk model re-baselines every SLA.

Exit costRe-wire

Re-connect, re-deploy and exception-rebuild effort for your estate: [TechBag to confirm] — TechBag scopes it from your accounts, clusters and pipeline.

What it costs

Per workload, per resource, per connector, per credit — and the native tools you already pay for

What your cloud already includes, the meters compared in USD and INR at three estate sizes, and what the licence leaves out.

01

Do you already own one?

Four places posture or protection may already be on the invoice.

Your cloud provider
Partly AWS (Inspector, GuardDuty, Security Hub), Azure (Defender for Cloud) and Google (Security Command Center) each secure their own cloud natively, on consumption. One cloud each, deep on their services — the honest posture layer at small scale.
Your endpoint vendor
Often CrowdStrike, SentinelOne, Trend, Sophos, Bitdefender and Kaspersky all sell the workload half on the sensor you run; posture is the newer add-on.
Your vulnerability vendor
Often Qualys TotalCloud and Tenable Cloud Security extend the risk model you already pay for into cloud accounts. Tenable stays posture-only.
Microsoft 365 E5
No E5 is endpoints, mail and identity. Defender for Cloud is a separate Azure consumption bill — and it covers AWS and GCP too, which is why it is the comparator for every agentless quote on an Azure-heavy estate.

If the native tool covers your one cloud, we say so — and then talk about the second cloud and the runtime half.

02

What the rest actually cost

Reported and published meters (INR for scale), then worked at 100 / 1,000 / 10,000 workloads. Most of this market is quote-only or credit-priced; the grid says so rather than inventing a number.

100workloads · per year
  • Wiz(reported: Essential ~$24k / yr @100; $15–30 / wl <500; $8–20 @2k–10k; $6–15 above)$24,00038,000 ₹19,92,000₹31,54,000
  • FortiCNAPP starter pack(~$25,000 / yr), then quote$25,000 ₹20,75,000
  • Wiz Defend + Sensor add-ons(reported ~$18k + ~$28k / yr)$46,000 ₹38,18,000
  • Wiz Code add-on(reported ~$58,500 / yr)$58,500 ₹48,55,500
  • Check Point CloudGuard CNAPP(consumption, quote)Quote
  • Qualys TotalCloud(per connector + per workload, quote)Quote
  • Tenable Cloud Security(per billable resource, quote)Quote
  • CrowdStrike Falcon Cloud Security(quote)Quote
  • SentinelOne Singularity Cloud Security(quote)Quote
  • Trend Vision One Cloud Security(credits)Quote
  • Sophos Cloud Native Security(PAYG per user / server)Quote
  • Bitdefender GravityZone Cloud Security(quote)Quote
  • Kaspersky Hybrid Cloud / Container Security(per node, quote)Quote
1,000workloads · per year
  • Wiz(reported: Essential ~$24k / yr @100; $15–30 / wl <500; $8–20 @2k–10k; $6–15 above)$15,00030,000 ₹12,45,000₹24,90,000
  • FortiCNAPP starter pack(~$25,000 / yr), then quoteQuote
  • Wiz Defend + Sensor add-ons(reported ~$18k + ~$28k / yr)$46,000 ₹38,18,000
  • Wiz Code add-on(reported ~$58,500 / yr)$58,500 ₹48,55,500
  • Check Point CloudGuard CNAPP(consumption, quote)Quote
  • Qualys TotalCloud(per connector + per workload, quote)Quote
  • Tenable Cloud Security(per billable resource, quote)Quote
  • CrowdStrike Falcon Cloud Security(quote)Quote
  • SentinelOne Singularity Cloud Security(quote)Quote
  • Trend Vision One Cloud Security(credits)Quote
  • Sophos Cloud Native Security(PAYG per user / server)Quote
  • Bitdefender GravityZone Cloud Security(quote)Quote
  • Kaspersky Hybrid Cloud / Container Security(per node, quote)Quote
10,000workloads · per year
  • Wiz(reported: Essential ~$24k / yr @100; $15–30 / wl <500; $8–20 @2k–10k; $6–15 above)$80,0002,00,000 ₹66,40,000₹1,66,00,000
  • FortiCNAPP starter pack(~$25,000 / yr), then quoteQuote
  • Wiz Defend + Sensor add-ons(reported ~$18k + ~$28k / yr)$46,000 ₹38,18,000
  • Wiz Code add-on(reported ~$58,500 / yr)$58,500 ₹48,55,500
  • Check Point CloudGuard CNAPP(consumption, quote)Quote
  • Qualys TotalCloud(per connector + per workload, quote)Quote
  • Tenable Cloud Security(per billable resource, quote)Quote
  • CrowdStrike Falcon Cloud Security(quote)Quote
  • SentinelOne Singularity Cloud Security(quote)Quote
  • Trend Vision One Cloud Security(credits)Quote
  • Sophos Cloud Native Security(PAYG per user / server)Quote
  • Bitdefender GravityZone Cloud Security(quote)Quote
  • Kaspersky Hybrid Cloud / Container Security(per node, quote)Quote
Four meters. Per workload (Wiz), per billable resource (Tenable — VMs, container hosts, functions, images, data stores), per connector plus per workload (Qualys), per node (Kaspersky), credits (Trend), PAYG per user and server (Sophos), consumption (Check Point). Ask how an ephemeral container that lived an hour is counted on each.
The bundle is modules. Wiz’s reported Essential / Advanced tiers are posture; Defend, Sensor, Code and DSPM add up fast. Every CNAPP quote should name which of CSPM / CWPP / CIEM / code is in the number.
The native comparator. Defender for Cloud, Inspector / GuardDuty and Security Command Center are consumption-priced and already half-bought; every quote here should be compared against switching them on first.

TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale at ≈₹83/$; the tier-matched INR quote is ours.

03

What isn’t in the licence price

The owners

Posture findings belong to the platform team; runtime alerts to the SOC; CIEM findings to identity; pipeline gates to engineering. A CNAPP without four owners is four queues nobody reads.

The agent rollout

Runtime protection means a sensor in images, autoscaling groups and clusters — an engineering project the security licence does not include. Price it as one.

The exceptions

Intentional public buckets, tolerated permissions, accepted CVEs — the exception workflow is the product in year two. It is rebuilt by hand if you switch (switching cost); your count is [TechBag to confirm].

Before you commit

What goes wrong

Documented architectural behaviour, cross-checked against TechBag engagements before any becomes a named case. Most of these are halves bought as wholes.

Posture-only tools mistaken for runtime protection

The graph was perfect; the cryptominer ran for a week. Tenable and the Wiz posture modules never block — by design. Know which half you bought.

Agentless blind spots at runtime

Snapshots every few hours miss what happens between them. Agentless is for posture; runtime needs something running.

Multi-cloud support deep on one and thin elsewhere

All three logos on the datasheet; service coverage on the third cloud was a checklist. Test your smallest cloud first.

CIEM findings nobody owns

A list of over-privileged roles in the security console; the platform team never saw it. Findings need an owner in the team that can change the role.

Alert volume from intentional misconfigurations

Public buckets that should be public, open ports that are meant to be open — flagged forever until exceptions are designed in.

An endpoint agent sold as cloud security

The laptop sensor would not survive the immutable image; the container story was a roadmap. Ask every endpoint vendor how it works without the agent.

Ephemeral workloads on a per-workload meter

Containers that lived an hour counted like servers; the renewal was a surprise. Ask how the meter counts before the first connector.

The native tool already switched on

Defender for Cloud or Security Hub was already doing the posture the new tool was bought for. Compare against the native tool first.

Three doors — pick by where you are

Researching

See the whole landscape and where each product sits.

Security map →

Evaluating

Get your shortlist scoped against your real estate.

Scope my shortlist →

Buying

Tier-matched USD + INR quote with GST.

Get a quote →

Vendor-neutral. No gated content.