TL;DR: Forrester named Orca Security a Strong Performer in The Forrester Wave for CNAPP after 14-vendor evaluation results that highlighted top scores in CSPM, CIEM, agentless cloud workload protection, IaC security, agentic AI and co-pilots, and third-party integrations. CNAPP is now being judged on whether it can connect visibility, identity, and runtime action across cloud and AI workloads, not just surface findings.
Editorial analysis by NHI Mgmt Group, based on content published by Orca Security: “Orca Security: A Strong Performer in the 2026 Forrester Wave™ for Cloud Native Application Protection Solutions”.
Key questions
Q: How should teams respond when CNAPP is expected to govern both cloud access and runtime risk?
A: Treat CNAPP as part of the identity control plane, not just a posture tool.
Q: Why does CIEM matter more when cloud workloads include AI and third-party integrations?
A: Because access graphs become useful only when they explain how identities actually interact with workloads, data, and external dependencies.
Q: What are the signs that a CNAPP programme is still posture-only?
A: The clearest signs are good visibility but weak response, limited entitlement context, and no clear path from detection to enforcement.
Practitioner guidance
- Audit entitlement graphs for cloud blast radius Review whether your CNAPP can expose excessive access across human users, service accounts, and third-party identities, then tie those findings to remediation ownership.
- Test runtime enforcement on high-risk workloads Validate that the platform can do more than alert by enforcing policy against privilege escalation, suspicious process activity, or unusual network behaviour in live workloads.
- Map AI workload telemetry into identity governance Check whether AI-related workload events, access grants, and integrations flow into the same governance workflow used for cloud roles and machine identities.
Bottom line: CNAPP is moving beyond visibility toward identity-aware runtime control, which makes entitlement data and enforcement capability equally important.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
CNAPP is being evaluated as an identity and action control plane. The significance of this wave is that cloud security platforms are no longer judged mainly on what they can observe. They are being compared on how well they connect entitlement context, workload behaviour, and enforcement decisions across cloud and AI workloads. For identity practitioners, that means CNAPP is moving into the same governance conversation as CIEM, runtime policy, and workload authorisation.
A few things that frame the scale:
- 88% of organisations have embedded AI agents in their workflows, according to KPMG's 2026 report.
A question worth separating out:
Q: What does the move toward agentic AI support mean for cloud security architecture?
A: It means cloud security tools must understand AI-driven execution paths as part of the same governance model used for workloads and identities. Teams need correlation across access, integrations, and runtime signals so AI behaviour is assessed in context, not treated as a separate silo.
👉 Read our full editorial: Cloud-native application protection is shifting toward AI and access control