CSPM in 2026: Wiz, Google, and the $32B Question
Anyone who has ever sat in a Monday morning cloud bill review knows misconfigurations aren't the exciting part of security, they're the boring part that keeps taking down production. That's why the CSPM market matters, and why the pending Google-Wiz deal has every platform lead I talk to rewriting their 2026 shortlists in pencil, not pen.
The category is consolidating fast, the price tags are historic, and the buyer choice you make in Q4 will determine whether your compliance team ships evidence in April or spends the quarter arguing about connectors.
What Happened
A ranked round-up of the ten leading Cloud Security Posture Management tools for 2026 landed this week, and the headline isn't the ranking, it's the corporate action sitting on top of it. As CyberSecurityNews reported, Google announced in March 2025 an agreement to acquire Wiz for approximately $32 billion, described as the largest deal in security industry history. At time of publication the transaction was still working through regulatory review toward closing.
Wiz continues to operate and sell independently during the review window, with stated intentions of multicloud neutrality under Google Cloud and shared threat intelligence feeds. The rest of the field lines up predictably: Microsoft Defender for Cloud winning on Azure-centric economics with a free basic tier, Palo Alto's Prisma Cloud covering the broadest code-to-cloud module set, Orca Security carrying the agentless side-scanning flag with DSPM depth, and CrowdStrike bolting posture onto Falcon runtime and endpoint telemetry.
The mid-tier tells its own consolidation story. Tenable folded its Ermetic CIEM acquisition into the Tenable One exposure platform alongside vulnerability management, identity, and OT. Fortinet absorbed Lacework and its Polygraph ML anomaly baseline, bundling it into the broader fabric with aggressive pricing. Trend Micro's posture sits inside Vision One. Check Point's CloudGuard leans on CloudBots automation and microsegmentation. Rapid7's InsightCloudSec pitches policy-as-code flexibility with approachable pricing aimed at mid-market consolidators.
Ten vendors, four independent, six now living inside larger platforms or pending acquisition. That ratio alone tells you where the category is going.
Technical Anatomy
CSPM at its core does one job: continuously inventory cloud resources across accounts and providers, evaluate configurations against security and compliance baselines, and surface the exploitable exposures. The 2026 version of that job has changed shape in two ways that matter for architecture decisions.
First, agentless scanning is now table stakes. Wiz built the reference implementation with full-estate scanning in minutes and no workload agents to deploy, and Orca's side-scanning approach proved the pattern could scale to data-security posture. If a vendor still wants you to roll out agents everywhere just to see what buckets are public, they're selling you 2021.
Second, and more important, the value has moved from "list of misconfigurations" to attack-path context. Wiz's security graph correlates misconfiguration, identity, vulnerability, and network exposure into ranked paths a real attacker could walk. That matters because cloud breaches increasingly run through over-privileged identities, not just open S3 buckets. A CSPM that spits out ten thousand findings without telling you which three chain into domain compromise is producing noise, not signal. The MITRE ATT&CK cloud matrix reflects the same shift: initial access via misconfig is only step one, the damage happens through identity abuse and lateral movement.
This is why CSPM is increasingly one module inside a consolidated CNAPP that also covers CWPP, DSPM, CIEM, IaC scanning, and code security. Wiz ships all of those. Prisma Cloud ships all of those plus API security and secrets. Defender for Cloud ships posture, attack-path analysis, DevOps security, and deep Entra ID integration on Azure, with AWS and GCP via connectors. The pure-play "posture only" vendor is a shrinking category.
My take: if your shortlist still separates CSPM, CWPP, and CIEM into three RFPs, you're going to buy three overlapping tools and staff three overlapping on-call rotations. That's the operational tax of ignoring the consolidation trend.
Who Gets Burned
The most exposed group right now is anyone about to sign a three-year Wiz commitment without roadmap-protection language. Wiz remains an excellent product, that's not the question. The question is what happens to AWS-first and Azure-first customers after close, when Google's incentives and Wiz's incentives fully align. Neutrality is a stated intention, not a contractual guarantee. In production incidents I've seen after past security acquisitions, "neutrality" tends to mean "we still support it, just not with the same release cadence."
Azure-majority estates are the least burned. Defender for Cloud's basic tier is free for native Azure posture, and paid plans add regulatory dashboards, attack-path analysis, and DevOps security while integrating natively with Entra ID and Defender XDR. On a ten-person platform team, avoiding a premium multicloud CSPM contract can free up budget equivalent to a mid-level engineer's salary. That's real money for a mid-market shop, not a rounding error.
AWS-heavy shops face the hardest call. The genuine multicloud pure-plays are Wiz (now uncertain), Orca (independent, strong on DSPM), and Prisma Cloud (broadest but credit-based licensing that needs careful modelling). CrowdStrike shops already standardized on Falcon get a single-agent runtime story, but cloud-native depth on IaC and dev tooling trails the pure-plays.
The uncomfortable read: Fortinet-Lacework and Tenable-Ermetic customers should be asking hard questions about console convergence timelines. Post-acquisition integration work has a way of eating a full year of product roadmap, and teams I've worked with have watched features they were promised at signing slip two renewal cycles. Contract accordingly.
Playbook for Security Teams
Concrete actions for the next 90 days, in priority order.
One: if a Wiz renewal or new contract is on your desk this quarter, add roadmap-protection clauses. Specifically, guaranteed feature parity for AWS and Azure scanning versus GCP for the contract term, and an exit clause tied to material degradation of multicloud support. Wiz's competitors will discount aggressively against the deal uncertainty. That's your use, use it.
Two: audit your identity blast radius before you audit your misconfigurations. Cloud breaches now run through over-privileged identities. Any CSPM shortlist that doesn't include CIEM (either native or via integration) is solving yesterday's problem. Cross-reference your findings against the CISA KEV catalog for cloud-adjacent CVEs actively exploited in the wild.
Three: consolidate deliberately. If you're already a Falcon, Defender, or Fortinet shop, the incremental cost of adding native posture is usually lower than a best-of-breed pure-play, and one console at 2am beats three. But only consolidate where the module is genuinely competitive, not just present.
Four: model the licensing before you pilot. Prisma Cloud's credit-based model, Defender's tier sprawl, and Wiz's premium pricing all have very different budget shapes at scale. Get the twelve-month bill in writing before the POC starts, not after procurement is committed.
Five: for mid-market teams, look hard at InsightCloudSec. Rapid7's policy-as-code approach and approachable pricing hit a sweet spot the enterprise pure-plays ignore.
Key Takeaways
- Google's $32B Wiz acquisition is the largest security deal in history and is still in regulatory review; sign multi-year Wiz contracts only with roadmap-protection language.
- CSPM is now one module of a consolidated CNAPP; buying posture in isolation from CIEM and CWPP produces overlapping tools and duplicated on-call cost.
- Attack-path context beats finding volume; prioritize vendors whose graphs correlate misconfig, identity, vulnerability, and exposure into ranked chains.
- Azure-majority estates get the best economics from Defender for Cloud's free basic tier plus paid attack-path and DevOps modules.
- Post-acquisition integration risk (Lacework into Fortinet, Ermetic into Tenable, Wiz into Google) is the single biggest hidden cost in 2026 shortlists.
Frequently Asked Questions
Q: Is Wiz still safe to buy while the Google acquisition is pending?
Yes, Wiz continues to operate and sell independently through the regulatory review period and remains an excellent product. The risk is contractual, not technical: multi-year commitments should include roadmap-protection clauses covering AWS and Azure feature parity post-close, and AWS-heavy shops should get neutrality commitments in writing.
Q: What's the difference between CSPM and CNAPP in 2026?
CSPM continuously inventories cloud resources and evaluates configurations against security baselines. CNAPP is the broader consolidated platform that includes CSPM alongside CWPP (workload protection), CIEM (identity entitlements), DSPM (data posture), IaC scanning, and code security. The market has moved toward CNAPP because cloud breaches now chain misconfiguration with identity abuse, and single-purpose CSPM misses that context.
Q: Which CSPM tool is best for Azure-first organizations?
Microsoft Defender for Cloud offers the strongest Azure economics with native posture free at the basic tier, and paid plans adding regulatory dashboards, attack-path analysis, and DevOps security. It also integrates natively with Entra ID access control and the Defender XDR platform. Multicloud depth trails Wiz and Orca, but for Azure-majority estates the value is hard to beat.
Cisco FMC Zero-Days Exploited by Sandworm and Qilin
Two Cisco FMC bugs are being exploited by Sandworm and a Qilin ransomware operator. The management plane is now the breach vector, and platform leads need to reprice vendor risk.
DeepSeek Harness CVE-2026-82533: Sandbox Escape at CVSS 9.4
A single shell command lets a DeepSeek Harness AI agent flip itself to danger-full-access. CVSS 9.4, shipped defaults, no credentials, 215,000 GitHub stars.
PayPal's PYUSDx Puts a Stablecoin On Top of a Stablecoin
PayPal, M0 and MoonPay launched PYUSDx, letting businesses mint branded stablecoins backed 1:1 by PYUSD. The two-tier design sidesteps the GENIUS Act entirely.




