FortiCNAPP
Posture, workload protection and IaC scanning across cloud accounts
- Licensing
- By cloud account and protected workload
- Platforms
- AWS, Azure, Google Cloud
- Modules
- CSPM, CWPP, CIEM, IaC scanning
FortiCNAPP combines cloud security posture management, cloud workload protection, infrastructure-as-code scanning and entitlement management across the lifecycle from commit to running workload.
Where it fits, and where it stops fitting
Cloud breaches are overwhelmingly misconfiguration and over-permission rather than exploited vulnerabilities, so finding the public bucket and the over-scoped role before an attacker does is the whole job. Posture management is the fast win and needs no agents; runtime workload protection is deeper and takes deployment effort.
Highlights
- Finds misconfiguration and over-permission before attackers do
- Agentless posture assessment as the fast first win
- IaC scanning catches issues in the pull request
- Entitlement management across multi-cloud
Typical deployments
- Establishing a baseline posture across many cloud accounts
- Continuous compliance evidence for cloud workloads
- Reducing over-scoped IAM roles
What to work out first
FortiCNAPP combines cloud security posture management, cloud workload protection, infrastructure-as-code scanning and entitlement management into one platform covering the whole lifecycle from commit to running workload.
It exists because cloud breaches are overwhelmingly misconfiguration and over-permission rather than exploited vulnerabilities. Finding the public storage bucket and the over-scoped role before an attacker does is the entire job.
Questions worth answering before you order
How many cloud accounts and which providers?
Licensing follows accounts and workloads. An accurate inventory is required, and organisations routinely discover they have more accounts than they thought, which is itself a finding.
Posture only, or workload protection too?
Posture management is the fast win and needs no agents. Runtime workload protection is deeper and requires deployment effort.
Do you want to shift left?
IaC scanning catches the misconfiguration in the pull request instead of in production, but only if your pipelines are somewhere it can hook in.
What this includes
Fortinet publishes no throughput table for this product; it is licensed per user, endpoint, workload or account. What follows is capability and sizing, not benchmarks.
What you are buying
| Licensing | By cloud account and protected workload |
|---|---|
| Platforms | AWS, Azure, Google Cloud |
| Modules | CSPM, CWPP, CIEM, IaC scanning |
How this is sized
Fortinet licenses this product per user, endpoint, workload or account rather than by appliance throughput, so there is no comparable performance table to publish. We size it from your actual environment, tell us the numbers and we will work it through with you.
| Licensing | By cloud account and protected workload |
|---|
Sources
- Fortinet product line overview, retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order; we will.