
- 01CNAPP litmus test: single graph linking misconfig + identity + vulnerability + exposure, reachability analysis, unified policy across CSPM and CWPP, native CI/CD integration, and runtime sensors that close the loop on posture findings.
- 02Reachability analysis is the killer feature. Pure CSPM reports thousands of misconfigurations; CNAPP with reachability reports the dozens an attacker could actually exploit. The signal-to-noise improvement justifies the price premium.
- 03Where CNAPP still falls short: multi-cloud coverage is uneven (one provider always weakest), Kubernetes runtime is a moving target, CIEM for non-cloud identities (on-prem AD groups for cloud access) is often shallow.
- 04Evaluate against your actual estate, not a pristine reference. The vendor's strongest cloud is rarely your hardest cloud — and the evaluation rubric should reflect that.
Gartner's CNAPP category bundles cloud security posture management (CSPM), cloud workload protection (CWPP), Kubernetes security posture management (KSPM), cloud infrastructure entitlement management (CIEM), and increasingly DSPM and software supply-chain coverage. The buyer's question is whether the integration is meaningful.
The CNAPP litmus test
- 01Single graph linking misconfiguration, identity, vulnerability, and exposure
- 02Reachability analysis — does the misconfig actually allow exploitation?
- 03Unified policy across CSPM and CWPP
- 04Native CI/CD integration for shift-left
- 05Runtime sensors that close the loop on posture findings
Reachability analysis: the killer feature
Pure CSPM reports thousands of misconfigurations. CNAPP with reachability analysis reports the dozens that an attacker could actually exploit given current network paths, identity entitlements, and workload exposure. The signal-to-noise improvement is substantial — and is what justifies the price premium over single-pillar tools.
Where CNAPP still falls short
Coverage of multi-cloud is uneven; one provider is always weakest. Deep Kubernetes runtime is a moving target. CIEM for non-cloud identities (on-prem AD groups still used for cloud access) is often shallow. Evaluate against your actual estate, not a pristine reference.


