Verified
Reviewed byOleh KemOleh Kem
Plans checked29 / 8 vendors
“Contact sales”19/29
Median entry$36/mo
Entry range$7.99-291.67
Publish a price3/8
Free tier1/8
Leader96 Sysdig

Cloud security platforms compared: pricing, CDR, CIEM and DSPM

Few vendors here post a storefront price at all: most scope a quote to your cloud footprint and print nothing. This page reads what each one does publish, scores how much of the cost is readable before you ever talk to sales, and shows how the same bill gets metered by host, workload, vCPU or device.

What does cloud security software actually cost, when so few vendors post one?

Cloud security software is priced per unit, and the unit is rarely the same twice: a host, a workload, a vCPU, a device or an asset, with published entry prices starting at $7.99. The rest is a quote. Most plans here show no public number, and only Sysdig prices every tier. Checked July 29, 2026.

  • These pricing pages list 29 plans between them, and nineteen show no number at all. That is the category default: cloud protection sells as a yearly contract sized to your footprint, not a seat you can total off a page.
  • Sysdig is the only one of the eight that prices each tier on its page. Three show a figure of some kind; the remaining four send the entire lineup to a quote, verified July 29, 2026.
  • The meter differs by almost every vendor: by host, by workload, by vCPU, by device, by asset and by consumption credit. Two entry figures at the same amount can describe completely different buys.
  • The cheapest published tier and the dearest published entry are not the same kind of buy: a self-serve per-device plan at one end, a per-asset scanner licence at the other.
  • Free plans barely exist: 1 of the 8 vendors, Tenable, keeps one you can stay on, its Nessus Essentials scanner. Every other free door is a timed trial, and a plan that outlives the evaluation is rare here.

Two inputs make the score. The larger share, sixty against forty, is pricing transparency: how much of the true bill shows up front, before a sales call. The rest is how users rate each tool. Capability counts for nothing in the score and lives only in the grid, so a well-regarded platform can sit low here even when its own users score it well.

01 / 06

Cloud security ranked: pricing transparency, CDR, CIEM and DSPM

Ranked on how much of the cost you can read in advance, not on how much each tool scans.

Sorted by transparency scorePriced tiers 10 / 29Full disclosure 1 / 8
How to read this table
01SysdigNo free tierAll tiers pricedCDR listedMalware detect listedCIEM not on the recordAttack surface not on the recordIaC scanning listedDSPM not on the record$36/host96Alternatives to Sysdig
02CrowdStrike Falcon CloudNo free tier1 of 5 tiers unpricedCDR listedMalware detect listedCIEM listedAttack surface listedIaC scanning not on the recordDSPM not on the record$7.99flat81Alternatives to CrowdStrike Falcon Cloud
03TenableFree tier4 of 8 tiers unpricedCDR not on the recordMalware detect not on the recordCIEM not on the recordAttack surface listedIaC scanning not on the recordDSPM not on the record$291.67/asset59Alternatives to Tenable
04WizMarketplace estimatefrom $24,000 / yrNo free tier0 of 4 tiers pricedCDR listedMalware detect not on the recordCIEM listedAttack surface listedIaC scanning listedDSPM listedSales only34Alternatives to Wiz
05Orca SecurityMarketplace estimatefrom $7,000 / moNo free tier0 of 4 tiers pricedCDR listedMalware detect listedCIEM listedAttack surface listedIaC scanning listedDSPM listedSales only32Alternatives to Orca Security
06LaceworkNo published priceNo free tier0 of 1 tiers pricedCDR listedMalware detect not on the recordCIEM listedAttack surface not on the recordIaC scanning not on the recordDSPM not on the recordSales only28Alternatives to Lacework
07Aqua SecurityMarketplace estimatefrom $50,000 / yrNo free tier0 of 3 tiers pricedCDR not on the recordMalware detect listedCIEM not on the recordAttack surface not on the recordIaC scanning listedDSPM not on the recordSales only24Alternatives to Aqua Security
08Prisma CloudNo published priceNo free tier0 of 2 tiers pricedCDR listedMalware detect not on the recordCIEM listedAttack surface listedIaC scanning listedDSPM listedSales only22Alternatives to Prisma Cloud
GrantedSome tiers sealedNot on the recordCheapest paid seatFlat account fee, not per seat* score is user satisfaction alone: the vendor publishes no pricesScore ranks pricing transparency and user ratings, not capability. Capability is the grid.
8 vendorsMedian entry $36Coverage span 61 of sixSealed tiers 19 / 29

Scroll the console sideways to reach the remaining conditions.

02 / 06

Every platform's plans, verdicts and the date we checked each price

The order runs from the vendors that post a real figure down to the ones that quote the lot. These products increasingly chase the same buyer, but they meter the bill by different things, by host, by workload, by asset and by device, so even the published entry figures are not counting the same unit.

Transparency scorePricing transparency 60%User satisfaction 40%

01

Sysdig, the cloud and container security platform built on the open-source Falco project
Sysdig

96Disclosure$36Host / mo

Teams living in Kubernetes that want runtime container detection built around Falco, the open-source project it sponsors. Sysdig alone prices each tier it lists, at $36 a host for Monitor Enterprise, though a public purchase starts at twenty hosts and stacks per-event and per-metric overages on top of the committed rate.

Critical gapThe platform takes significant configuration and engineering time to run well.

Plan table and expert take

Sysdig: expert take

Sysdig built its runtime container detection on Falco, the CNCF project it created. It is also the one vendor here that prices every tier: $36 a host on Monitor Enterprise. The catch: public purchase starts at 20 hosts, with per-event overages stacked on top.

Where Sysdig holds up

  • Creator and primary sponsor of CNCF Falco: community trust
  • Best runtime container security in the market
  • Strong Kubernetes-native architecture
  • Open source roots give strong community support

4.9CE scoreG2 4.8 · 112 reviewsFounded 2013Verified July 8, 2026

2 plans, as published
PlanMonthlyAnnual
Monitor Enterprise$36Not published
CNAPP Enterprise$72Not published
02

CrowdStrike Falcon, endpoint and cloud security run from one agent and console
CrowdStrike Falcon Cloud

81Disclosure$7.99Flat / mo

Security teams already on CrowdStrike's endpoint agent that want cloud signals in the same console. It carries the category's only self-serve entry, Falcon Go at $7.99 a device up to 100 devices, with the annual term paid in full at signup, a 30-day refund window, and the managed detection tier held on a quote.

Critical gapKernel-level monitoring frequently triggers false positives that block legitimate application processes during initial deployment phases.

Plan table and expert take

CrowdStrike Falcon Cloud: expert take

CrowdStrike is the rare cloud-security name you buy without a call: Falcon Go self-serves up to 100 devices. The catches are structural. The annual term is paid in full at signup, and modules like Device Control bolt on as paid add-ons over the per-device base.

Where CrowdStrike Falcon Cloud holds up

  • Unmatched threat intelligence integrated with cloud security
  • Unified endpoint + cloud telemetry in one graph
  • 29k+ customers provide massive threat data network effect
  • AI-native detection with proactive threat hunting

4.7CE scoreG2 4.6 · 86 reviewsCapterra 4.7Founded 2011Verified July 16, 2026

5 plans, as published
PlanMonthlyAnnual
Falcon Free Trial$0Not published
Falcon Go$7.99$5
Falcon Pro$14.99$8.33
Falcon Enterprise$19.99$15.42
Falcon Complete Next-Gen MDRContact sales
03

Tenable, the vulnerability management vendor behind the Nessus scanner
Tenable

59Disclosure$291.67Asset / mo, billed yearly

Programs standardising on the Nessus engine for vulnerability management across cloud, OT and identity. Tenable is the only name here with a free scanner you can keep, Nessus Essentials, then prices the scanner per licence and cloud management per asset, while Tenable One and Security Center stay on a quote. Catalogue figures read in local currency, so confirm the dollar rate.

Critical gapThe platform necessitates significant manual effort to configure asset tagging and navigate search interfaces.

Plan table and expert take

Tenable: expert take

Tenable is the Nessus company, the default scanner for vulnerability management across cloud, OT and identity. It runs a genuinely free Essentials tier, then meters the rest per licence or per asset. The catch: the cloud platform and Tenable One stay quote-only, and storefront prices are geo-localised.

Where Tenable holds up

  • 43k+ customers: industry standard for vulnerability management
  • Nessus scanner is the most widely trusted vuln scanner
  • Tenable One covers cloud, OT, identity and web in one platform
  • Strong risk-based prioritization engine

4.6CE scoreG2 4.5 · 122 reviewsCapterra 4.4Founded 2002Verified July 16, 2026

8 plans, as published
PlanMonthlyAnnual
Nessus EssentialsFreeFree
Nessus ProfessionalNot published$365.83
Nessus ExpertNot published$532.50
Tenable Vulnerability ManagementNot published$291.67
Tenable Web App ScanningContact sales
Tenable One FoundationContact sales
Tenable One AdvancedContact sales
Tenable Security CenterContact sales
The three above put some figure in front of you. Past this line the numbers disappear: three show only an outside marketplace estimate, and two send the whole lineup to sales.
04

Wiz, the agentless CNAPP known for graph-based attack-path analysis
Wiz

34DisclosureSales onlyNo price

Mid-to-large cloud teams that weigh attack-path context over raw alert volume. Wiz quotes its full platform privately and publishes no public rate card; its Wiz Essential bundle opens at $24,000 for a hundred workloads on the AWS Marketplace listing, not on wiz.io. The SMB Go bundle locks a 36-month term, and letting it lapse ends the entitlements.

Critical gapAPI rate limits constrain data ingestion during large-scale environment audits.

Plan table and expert take

Wiz: expert take

Wiz's pull is the security graph: it ranks which exposures are actually reachable, not just present. The cost is opacity: wiz.io prints no number at all, and the figures that exist are AWS Marketplace listings, not vendor list prices.

Where Wiz holds up

  • Agentless deployment: live in minutes, not months
  • Security Graph surfaces critical risks others miss
  • Covers CSPM + CWPP + CIEM + CDR in one platform
  • Trusted by 45% of Fortune 100

4.8CE scoreG2 4.7 · 792 reviewsFounded 2020Verified July 16, 2026

4 plans, as published
PlanMonthlyAnnual
Wiz EssentialContact sales
Wiz AdvancedContact sales
Wiz Go BundleContact sales
WIZ Cloud Infrastructure Security PlatformContact sales
05

Orca Security, the agentless cloud platform that scans from snapshots and cloud APIs
Orca Security

32DisclosureSales onlyNo price

Cloud teams that want one agentless pass across the whole estate from snapshots, not agents. The coverage is wide, though DSPM and network security stay outside its scope, and the figures are not Orca's own: the four size bands you see are AWS Marketplace estimates, and the yearly figure is exactly twelve times the monthly, with no multi-year discount.

Critical gapThe architecture mandates cloud-native read-access and lacks support for air-gapped environments.

Plan table and expert take

Orca Security: expert take

Orca's SideScanning reads from snapshots, mapping the whole estate in hours with zero agent load. The trade is runtime: agentless means no live blocking. Coverage runs wide, though DSPM and network security sit outside its scope, and it posts no price of its own; the four size bands are AWS Marketplace estimates.

Where Orca Security holds up

  • SideScanning provides deep visibility with zero performance impact on live workloads.
  • Unified data model contextualizes risks across the entire cloud estate.
  • Attack Path Analysis prioritizes threats that pose the most immediate danger.
  • Covers VMs, containers, serverless, and PaaS services in a single platform.
  • Comprehensive compliance reporting for PCI-DSS, SOC 2, NIST, and more.

4.7CE scoreG2 4.6 · 260 reviewsFounded 2019Verified July 16, 2026

4 plans, as published
PlanMonthlyAnnual
SmallContact sales
Small-MediumContact sales
MediumContact sales
LargeContact sales
06

Lacework, the cloud security platform built around machine-learning anomaly detection
Lacework

28DisclosureSales onlyNo price

Anyone drowning in multi-cloud alerts that wants behavioural anomaly detection to cut the noise. Lacework, now inside Fortinet, leaves its price to a sales call, and its public starter packs share one entry price while the vCPU allowance drops from 500 to 250 as the tier rises, so a higher tier buys fewer machines for the same money.

Critical gapThe platform lacks native GitHub CI/CD integration and static code analysis.

Plan table and expert take

Lacework: expert take

Lacework's Polygraph learns an environment's normal and flags the anomalies, cutting multi-cloud alert fatigue. Its pricing hides the category's oddest quirk: three starter packs at one price, but the vCPU cap falls from 500 to 250 as the tier climbs. Now inside Fortinet, the roadmap is the open question.

Where Lacework holds up

  • Polygraph behavioral analytics reduces false positive fatigue
  • Strong anomaly detection for dynamic cloud environments
  • Now backed by Fortinet's enterprise distribution
  • Good compliance framework automation

4.5CE scoreG2 4.4 · 386 reviewsFounded 2015Verified July 8, 2026

1 plans, as published
PlanMonthlyAnnual
EnterpriseContact sales
07

Aqua Security, the container and cloud-native platform built on the open-source Trivy scanner
Aqua Security

24DisclosureSales onlyNo price

DevSecOps groups building container and pipeline scanning around the open-source Trivy engine. Aqua's own site shows no dollar figure; the three annual tiers that do surface a number, Standard through Ultimate, appear only as AWS Marketplace contract floors, and any larger deal routes to a private offer sized to your environment.

Critical gapThe platform exhibits persistent UI/UX limitations regarding authentication flows, alert management, and result display integration.

Plan table and expert take

Aqua Security: expert take

Aqua's strength is supply-chain and CI/CD scanning, anchored by the open-source Trivy engine already widely adopted in CI pipelines. CSPM is a second string to that bow, and its own site shows no price: the three tiers surface only as AWS Marketplace floors.

Where Aqua Security holds up

  • Open source Trivy widely adopted in CI/CD pipelines
  • Best software supply chain security in cloud-native space
  • Comprehensive serverless and VM coverage
  • Strong developer integration and shift-left approach

4.3CE scoreG2 4.2 · 57 reviewsFounded 2015Verified July 16, 2026

3 plans, as published
PlanMonthlyAnnual
Shift Left (Standard)Contact sales
Protect (Advanced)Contact sales
UltimateContact sales
08

Prisma Cloud, Palo Alto Networks' cloud-native application protection platform
Prisma Cloud

22DisclosureSales onlyNo price

Palo Alto Networks shops consolidating cloud security onto a platform they already buy from. Prisma Cloud prices both editions through a quote and meters usage in credits, where each module, from posture to runtime, burns credits at a different rate, so the bill is a running sum of modules, not a single plan price.

Critical gapThe platform architecture relies on stitched-together modules rather than a unified graph-based data model.

Plan table and expert take

Prisma Cloud: expert take

Prisma Cloud is the broadest CNAPP in Palo Alto's stack, and it prices in credits: each module burns them at its own rate, so the bill is a sum you model in advance.

Where Prisma Cloud holds up

  • Broadest CNAPP feature set: covers every cloud security use case
  • Deep PANW ecosystem integration
  • Strong WAF and network security integration
  • Checkov open-source IaC scanner drives community adoption

4.2CE scoreG2 4.1 · 112 reviewsFounded 2018Verified July 8, 2026

2 plans, as published
PlanMonthlyAnnual
Business EditionContact sales
Enterprise EditionContact sales
03 / 06

Compare any two cloud security platforms: plans, limits and score

vs

What the records say

For 6 hosts, CrowdStrike Falcon Cloud bills $7.99 / mo and Sysdig bills $216 / mo, $208.01 / mo between them.

CrowdStrike Falcon Cloud carries 4 of the 6 capability columns on the record; Sysdig shows 3.

Users side with Sysdig: 4.8 on G2 against 4.6 for CrowdStrike Falcon Cloud.

Sysdig prices everything it sells; CrowdStrike Falcon Cloud leaves part of its lineup unpriced.

Pick Sysdig for: Teams living in Kubernetes that want runtime container detection built around Falco, the open-source project it sponsors.

Pick CrowdStrike Falcon Cloud for: Security teams already on CrowdStrike's endpoint agent that want cloud signals in the same console.

01

Sysdig

CE 96 · G2 4.8
Published plans, US$/mo
Monitor Enterprise$36
CNAPP Enterprise$72
Team of 6$216 / mo

Verified July 8, 2026

02

CrowdStrike Falcon Cloud

CE 81 · G2 4.6
Published plans, US$/mo
Falcon Free Trial$0
Falcon Pro$14.99
Falcon Complete Next-Gen MDRContact sales
Team of 6$7.99 / mo

Verified July 16, 2026

Both price lists on the category axis

Sysdig
CrowdStrike Falcon Cloud

Where they differ

Only Sysdig has on the record

  • Every tier priced
  • IaC scanning

Only CrowdStrike Falcon Cloud has on the record

  • CIEM
  • Attack surface
04 / 06

Cloud security questions: smallest contract, CNAPP quotes, workloads

What is the smallest cloud security contract you can buy?

Bigger than a seat, and measured in units rather than dollars. Sysdig's CNAPP Enterprise charges by the host and will not go below twenty. Tenable's Vulnerability Management starts at a hundred assets, and Wiz sizes its bundles per hundred workloads. Orca sells fixed bands instead, and its Small band lists at $7,000 a month. A small estate still pays the floor.

What exactly am I buying in a CNAPP quote?

A count of your cloud estate. A cloud-native application protection platform bills by a unit, and the unit is whatever the vendor picked: a workload, a host, a vCPU, a device or a consumption credit. The quote sizes that unit against your accounts and scales with them, so it tracks your footprint, not your headcount, and two vendors' numbers rarely line up.

What counts as a workload in cloud security pricing?

It depends on who is billing you. Orca meters concurrent EC2 workloads in size bands; Wiz counts cloud workloads per hundred; Sysdig charges per host; Lacework caps a starter pack by vCPU. Each is a billable unit with a different definition, so a price per workload from one vendor and a price per host from another are not measuring the same thing.

Which cloud security tools actually publish a price?

Four of the eight show a figure of some kind, and only Sysdig prices each tier it lists, per host. CrowdStrike publishes self-serve per-device tiers, Tenable runs a free Nessus scanner and prices the rest per asset or licence, and Wiz posts annual figures for its lower bundles. The other four, Orca, Aqua, Lacework and Prisma, quote everything.

How much does cloud security software cost at small scale?

On the cheap end, an endpoint-led tier runs single dollars per device each month, so a small fleet stays modest. That is the cheap corner. A full cloud-native platform is another purchase entirely: a yearly contract scoped to your accounts and workloads, quoted well into five figures and up, with no self-serve checkout to click through.

Is there a cheaper alternative to Wiz?

Within this list, the self-serve options undercut it plainly: CrowdStrike's per-device tiers and Sysdig's per-host rate both carry a public number you can add up, where Wiz quotes its platform. The trade is scope. Wiz is an agentless graph across the whole estate; a per-host or per-device tool prices lower because it is solving a narrower slice of the same problem.

Which tier do the add-ons force you onto?

The one above the tier you priced. Wiz keeps its runtime Sensor and Defend add-on on Advanced, so Essential stops being an option once you want either. CrowdStrike holds detection and response for the $19.99 Falcon Enterprise tier, and Tenable keeps attack path analysis for Tenable One Advanced. Price the add-on first. The base tier follows from it.

Does a bigger cloud security tier lower the per-unit rate?

No, it usually raises it. Lacework's three starter packs all cost the same for the year, but the vCPU allowance falls from 500 on Standard to 250 on Enterprise, so the effective rate per vCPU doubles across the tiers. Wiz charges more per workload on Advanced than on Essential. You are paying for depth in each unit, not volume.

Do the prices on AWS Marketplace mean I am getting a set rate?

No. The public marketplace figures are listing floors, not a rate card; the real deals route through private offers sized to your environment. On the listings that show a yearly figure, Orca and Wiz both scale it linearly, so the annual is exactly the monthly times twelve with no multi-year discount. Treat a marketplace number as an opening position.

Do any cloud security vendors offer a free plan?

Barely. Tenable's Nessus Essentials is the one free plan you keep, and it scans a small number of assets. CrowdStrike gives a timed trial, not a lasting free plan, and everyone else is a yearly contract with an evaluation at best. A free scan of one account is common; a plan you can run a real environment on is not.
Field note 01

One number per vendor, six meters underneath

Every vendor here bills by something different. Sysdig charges per host, CrowdStrike per device, Tenable per asset or per licence, Lacework by vCPU allotment, Orca by concurrent workload band, Wiz per hundred workloads and Prisma by consumption credit. The axis on this page folds all of that onto one line so the markers sit at honest distances, but the units underneath are not the same, and no single conversion turns one into another.

So a cheap-looking per-device tier and an expensive-looking per-asset licence can be closer than they seem once you count your own estate, or much further apart. The only reliable comparison is to take your real account, workload and host counts to each vendor and ask what meters the bill, then price the same environment across all of them. The published entry figure, where one exists, is a floor for that exercise, not the answer to it.

Field note 02

Most of this category will only quote you a price, and that is the model

Cloud-native protection is sold as a yearly contract scoped to your footprint, the count of accounts, workloads or assets you run, not a headcount. So the standard answer to what it costs is a quote, and the plans checked here run to 29, with nineteen showing no number at all. That is a pricing model, not plain evasion, but it makes a list-price comparison impossible, because there is no list. It also lands some of the most recognised names in cloud security near the bottom of a transparency ranking while their users still rate them well.

To get numbers you can compare, ask each vendor to quote against one written description of your environment, the same account and workload counts, and ask outright what meters the bill and what the overages cost once you cross the committed amount. Expect the figure to track the size of your estate rather than your team, and expect the marketplace listings and outside estimates to be opening positions, not the price you will actually pay.

The verdict on cloud security platformSigned review · Updated
Oleh KemOleh KemFounder & Lead AnalystComparEdge Editorial

Almost nothing in cloud security is priced in public: the numbers that exist are marketplace listings per hundred workloads, and the platform you actually deploy is scoped on a call. Count your workloads honestly before that call, because the unit is where the bill grows.

The ranking reads disclosure ahead of brand. A vendor that prints one real tier outranks a bigger name that prints none, and that is deliberate.

MethodEvery price on this page is read from the vendor's own pricing page: 29 plans across eight vendors, last verified .
DisclosureCollection is tool-assisted; every verdict is written and signed by a human analyst.
06 / 06

Read next: cost guides for cloud security platform, plus related categories

How this review is made. Prices are read from vendor pricing pages and re-checked on the dates shown against each product. Condition columns reflect the feature set recorded on the vendor’s own pages on that date. ComparEdge sells no cloud security platform and takes no vendor payment for placement. Where a vendor publishes nothing, this page says so rather than estimating. Ranking is by transparency score: pricing transparency 60%, user satisfaction 40%. What a product can do is shown in the condition columns and carries no weight in the number.