Top Tools / August 18, 2026
StartupStash

StartupStash is an editorial team. Each Top Tools shortlist is researched by a writer who works in that category, then checked against first-party product pages, public pricing, and recent product changes. A second editor reviews the piece before it goes live. We also run a directory of startup tools. A paid listing does not buy a place on a shortlist.

Best CAASM Platforms (2026 Guide)

EDR says one estate. The CMDB says another. The cloud bill names accounts nobody enrolled. Three inventories, three counts, and the incident ticket has a hostname that sits in none of them. Nobody on the call knows which list to believe. That disagreement is why this page exists.

Gartner calls the job Cyber Asset Attack Surface Management, or CAASM: continuously inventory every digital asset - cloud, code, identity, endpoint, SaaS - and use that inventory to find coverage gaps. The feature lists all say “inventory.” They do not agree on how they see the estate. Adapter, graph, scanner, and traffic sensor are all agentless. EDR is a different sensor: the agent on the endpoint, not the naming layer those agents missed.

The shortlist is four products on that split: whether a tool you already run ingested the asset, whether you are asking for a device list or a blast-radius path, and whether any price is public. If CrowdStrike, Intune, Okta, and AWS already disagree, start with Axonius. If the question is who can reach what from an identity, JupiterOne is the graph. If a device nobody enrolled is on the wire, runZero is the scanner. If the unknown lives on a plant floor, a hospital wing, or a building-management VLAN, Armis is the traffic sensor, already inside ServiceNow. How we picked these four is on How we review tools.

What usually goes wrong when buying a CAASM platform

The demo often shows one inventory. The hole you have is usually a different kind of missing asset.

Problem Solution
EDR, the CMDB, and the cloud bill already disagree, but the quote is a network scanner Start with adapters that reconcile tools you already run, not a new scan of the wire
The hole is a device nobody enrolled, but the quote is a relationship graph Use a scanner or a traffic sensor. A graph will not fingerprint a silent PLC
The list price is a teaser for a different product or a private-offer floor Reconcile the quote to the billed unit: 500 assets, datapoints, or a monthly minimum
The hole you have is a CMDB cleanup, not an attack-surface graph Match the product to the job.

How we evaluated CAASM platforms

Four public-page checks decided the four: how it sees the estate, whether any price is public, whether a pending or completed acquisition changes the next contract, and whether the hole you can already name is a missing device or a missing path. Neighbor products sit under Other CAASM platforms worth considering.

TL;DR: The Four Compared

Platform Best For Pricing Model Highlights
Axonius EDR, CMDB, and cloud bills already disagree AWS: $90,625 / 12 months for 500 assets, or $88,000 / 12 months for 700 SaaS users Adapter-first. Reconciles tools you already run. Cyber-Physical Assets is still early access
JupiterOne Blast radius from an identity to a workload to data AWS: $25,000 / 200k datapoints, $50,000 / 400k, $100,000 / 1M, all per 12 months Relationship graph. Agent-free API ingest. Marketing table and AWS listing put the datapoint caps on different tiers
runZero A device nobody enrolled is on the wire AWS: $6,000 / 12 months per 500-asset block. Free under 100 assets Unauthenticated scan plus passive collection. Accenture / Dragos close still pending
Armis Plant floors, hospitals, and unmanaged IoT AWS floors: $3,250 / month on Device Security Platform and on ViPR Pro (5,000 devices). Private-offer minimums Traffic sensor. Agentless IT, IoT, OT, IoMT. Now inside ServiceNow; Centrix promised standalone

Axonius

Axonius

Axonius Asset Cloud is the adapter-first CAASM: it interrogates the systems that already know pieces of the estate rather than scanning the wire. The Cyber Assets page is the product surface; the dedicated CAASM URL is the same platform. In a 6 Aug 2026 interview, co-founder Dean Sysman put the integration count at “over 1,400.” Homepage connector counts are marketing. Budget from adapters you will actually connect.

On 21 Jul 2026 Axonius announced the Axonius AI Agent (preview), the Axonius MCP Server (early access), and Docs for AI. On 22 Jul it expanded Cyber Assets and Exposures: a CMDB Reconciliation Workspace and Verified Assets in early access, Business Context and Asset Criticality generally available, and Cyber-Physical Assets - the Cynerio line - still in early access, with GA expected in the second half of 2026. If OT or clinical devices are the buying reason, treat that module as a roadmap item.

Best for: Security and IT teams that already run a thick stack (EDR, MDM, IAM, cloud, CMDB) and need one reconciled record per device, identity, and SaaS user, plus the ability to push a fix back into those same tools.

What you get:

  • An adapter network that correlates and deduplicates records from the existing stack into one asset model, then surfaces coverage gaps - missing EDR, stale OS, unmanaged SaaS - without a new agent.
  • Bi-directional enforcements: create tickets, enrich a CMDB, disable a stale account, or trigger a scan from the same query that found the gap.
  • AI Agent and MCP Server so a question in English can become a live AQL answer. Both were announced 21 Jul 2026 as preview / early access.
  • Verified Assets and a CMDB Reconciliation Workspace aimed at the “is this one device or three?” problem that breaks audits.

Why we like it: If CrowdStrike, Intune, Okta, and AWS already know most of the estate, the job is to stop those four consoles from disagreeing. Ownership and change history on a single record is the incident win when the ticket has an IP and nothing else.

Limits:

  • Query language and UI have a real learning curve. Bad source data produces confusing records.
  • Value tracks adapter quality. A stale or missing source makes the “single source of truth” a single source of argument.
  • Cyber-Physical Assets is still early access. The plan grid does not say whether that module rides the same $90,625 bundle.

Price: AWS Marketplace. Two 12-month contract dimensions: AXS_500_Complete $90,625.00 / 12 months for 500 assets with unlimited queries, adapters, and enforcements; Axonius SM: 700 Users $88,000.00 / 12 months for 700 unique SaaS users. Private offers are available. Refunds: none.

Before buying

Ask whether Cyber-Physical Assets is on the $90,625.00 bundle or a separate line. If OT is the reason you are here, an early-access module is not a plant-floor order.

JupiterOne

JupiterOne

JupiterOne is the graph CAASM. The CAASM solution page is live: unify cloud, code, identity, and endpoint assets into one continuously updated graph, then ask who can reach what. Discovery is agent-free and API-based, with 200+ native integrations. J1QL is for engineers. JupiterOne AI is for plain-English questions.

The useful unit is the edge: this IAM role can assume that role, which can write to that bucket, which is attached to a workload missing the agent. Policy-as-code evaluates controls continuously and collects evidence for SOC 2, ISO 27001, PCI, FedRAMP, HIPAA, and NIST. JupiterOne launched its MCP server in July 2026 and, on 10 Aug 2026, listed it as a community server in Anthropic’s MCP directory. Continuous Controls Monitoring is priced on existing datapoints. Unified Vulnerability Management is priced on findings.

Best for: Cloud-native and hybrid security teams that need to query blast radius from identity to workload to data, and keep audit evidence current without a quarterly spreadsheet scramble.

What you get:

  • Agent-free ingestion from 200+ sources into a relationship graph, with J1QL and JupiterOne AI.
  • Coverage-gap detection across domains: workloads without EDR, over-permissioned contractors, shadow SaaS.
  • Continuous Controls Monitoring on existing datapoints, plus Unified Vulnerability Management priced on findings.
  • MCP server, listed in Anthropic’s directory on 10 Aug 2026, so Claude and other MCP clients can query the graph.

Why we like it: A list of assets will not tell you the path. The graph will. Audit prep that drops from weeks of evidence collection to a status check is the buyer story on the Marketplace listing.

Limits:

  • J1QL has a learning curve. Public reviews flag slow queries on large graphs, API rate limits, and alert noise.
  • Unified-device matching is still imperfect. Hostname, MAC, and IP can disagree across scanners. Demo CCM against your framework.
  • The public pricing page table is internally inconsistent: Small-Market prints $25,000 against a contact-sales description; Mid-Market prints $50,000 against a 200,000-datapoint cap. The AWS listing puts those caps one tier lower.

Price: Prefer AWS Marketplace. 12-month contract dimensions: Small-Market $25,000.00 up to 200,000 data points; Mid-Market $50,000.00 up to 400,000; Enterprise $100,000.00 up to 1,000,000. A data point, per the listing, is a unit of ingested cyber-asset data. Above 1,000,000 datapoints, request a private offer. Refunds: none. 24- and 36-month contracts are also on the page.

Before buying

If a quote arrives off the marketing page, reconcile it to the AWS dimensions - 200k / 400k / 1M datapoints at $25,000.00 / $50,000.00 / $100,000.00 - before you buy.

runZero

runZero

runZero is the discovery CAASM: safe unauthenticated scanning, passive collection, and API integrations, with fingerprinting that is supposed to tell you the device is a specific PLC or a forgotten ESXi host. A free tier covers home use and environments under 100 assets. SaaS, on-prem, and air-gapped / offline-scanner options exist. No agents, no authentication, and no appliances required for a first pass.

Accenture announced on 18 Jun 2026 that it would acquire runZero (and a majority stake in Dragos), expected to close in August or September 2026. After close, runZero is slated to operate under Dragos. The homepage still says “runZero to join Dragos.” Product work has not frozen: runZero 5.1 shipped AI workflows and a native Dragos integration. A new contract still needs written continuity.

Best for: Teams whose first problem is unknown and unmanageable devices on the wire - IT, OT, IoT, mobile, remote - especially where agents and credentials are not an option, and who want a public, incremental price they can put in a budget line.

What you get:

  • Unauthenticated active scanning designed as safe for sensitive OT and IoT, plus always-on passive discovery and API integrations with EDR, MDM, cloud, and vulnerability scanners.
  • Fingerprinting so the output is a device identity, not just an IP.
  • SaaS, on-prem, and air-gapped / offline-scanner options.
  • runZero 5.1 AI workflows and a native Dragos integration.

Why we like it: It is the only product in this set with a public, mechanical AWS price that a mid-size team can buy without a six-week private-offer dance, plus a free sub-100-asset tier for a real trial. Assets the owner swore were gone are the use case.

Limits:

  • The Accenture / Dragos close is expected Aug/Sep 2026 and is not done. Get written continuity language into any new contract.
  • AWS Marketplace has almost no review volume: 4.0 stars from a single external G2 review dated 10 Jul 2022.
  • It will not replace a relationship graph or an adapter-reconciliation layer. If your blind spot is IAM-to-SaaS, start with JupiterOne or Axonius.

Price: AWS Marketplace. One 12-month dimension: x 500 Assets $6,000.00 / 12 months. An asset is any device observed in the last 30 days; devices not seen in that window do not count. Buy more 500-asset blocks as the estate grows. Free tier on runzero.com: fewer than 100 assets. For refund requests, accounts@runzero.com. Use the free trial first.

Before buying

Ask what happens to the product name, support, and data after the Dragos close. If continuity is a slide and not a clause, wait or pick another scanner.

Armis

Armis

Armis is the cyber-physical CAASM. The product is Armis Centrix, an agentless platform that inventories managed and unmanaged IT, IoT, OT, IoMT, cloud, and virtual assets by watching the network, then layers threat detection and vulnerability prioritization. When the asset cannot run an EDR agent - a pump controller, a CT scanner, a badge reader - adapter-only CAASM is blind unless some other tool already saw it.

ServiceNow completed its acquisition of Armis on 20 Apr 2026. ServiceNow says Armis Centrix remains available as a standalone product, with a path into the ServiceNow AI Platform. A new order is a ServiceNow conversation. Ask whether Centrix stays standalone on the next renewal.

Best for: Organizations whose unknown-device problem is industrial, clinical, or IoT-heavy - manufacturing, healthcare, critical infrastructure, SLED - and who want agentless, traffic-based inventory with a path into ServiceNow workflows.

What you get:

  • Agentless discovery of managed and unmanaged IT, IoT, OT, IoMT, and cloud assets by passive network analysis.
  • Centrix modules on the listing: Asset Management and Security; OT/IoT Security; Medical Device Security; Actionable Threat Intelligence; Vulnerability Prioritization and Remediation.
  • ViPR Pro consolidates findings from host, endpoint, cloud, and AppSec tools and assigns remediation owners.
  • Standalone Centrix plus a ServiceNow AI Platform path since the 20 Apr 2026 close.

Why we like it: Traffic is the sensor when the device will not take an agent and no adapter has ingested it. The ServiceNow path is why a hospital or a plant already on that platform will look here first.

Limits:

  • ServiceNow ownership is new. Centrix is promised as standalone today. Put that in the next renewal if standalone matters.
  • List prices on Marketplace are minimums that route you to a private offer. The $3,250.00 / month figures are floors.
  • There is no public per-asset rate comparable to runZero’s 500-asset block. Budget as an enterprise private offer with that published monthly floor.

Price: Both public listings point to private offers at aws_marketplace@armis.com. Device Security Platform, 1-month contract: Armis Platform $3,250.00 / month, “Centrix Standard minimum.” 12-, 24-, and 36-month contracts also offered. Centrix ViPR Pro, 1-month contract: 5,000 Devices $3,250.00 / month, “VIPR Pro Standard minimum.” 24-month contracts advertise savings up to 50%; 36-month up to 67%. Volume above 5,000 devices is a private offer. Fees are non-cancellable and non-refundable except as required by law. A FedRAMP private-offer listing also exists.

Did a tool already see it, and is the question a device or a path?

This grid plots two questions. Across is whether a source you already run ingested the asset: yes on the left, nobody enrolled it on the right. Up is the question you are asking: blast radius from an identity at the top, a device inventory at the bottom.

PathAlready ingestedGraph from APIs you already have
PathNobody enrolled itNone on this list
InventoryAlready ingestedAdapters reconcile the consoles
InventoryNobody enrolled itScan or traffic on the wire

Placement follows how each vendor’s product page sees the estate: adapter reconciliation, a relationship graph, an unauthenticated scan, or traffic-based inventory. A graph will not fingerprint a silent PLC. A scanner will not walk an Okta group to an S3 bucket. This is a map of the products, not a ranking.

Pricing and usage costs compared

Platform How pricing works What to confirm before buying
Axonius 12-month asset or SaaS-user bundle on AWS Confirm whether Cyber-Physical Assets rides the asset bundle or is a separate line
JupiterOne 12-month datapoint tiers on AWS Confirm the quote against the AWS datapoint tiers. The marketing table and the AWS listing put the caps on different tiers
runZero 500-asset blocks, billed on devices seen in the last 30 days Confirm the 500-asset block and whether devices outside the 30-day window count
Armis Private-offer monthly minimum, not a public per-asset rate Confirm the private-offer monthly floor and which product it applies to

Other CAASM platforms worth considering

These are real products. We left each one off because it answers a different inventory question than the four sensors on this page.

  • EASM is the outside view: domains, IPs, certificates, and exposed services an outsider can enumerate. An unmanaged badge printer is a CAASM miss. A forgotten public bucket can show up in both, which is why the labels get sold as synonyms.
  • CNAPP is cloud posture, and sometimes runtime, on the workloads you pointed it at. It will not name the badge reader on the plant VLAN.
  • EDR is the agent on the endpoint. CAASM is the naming layer those agents missed. Buying a second EDR does not close an inventory hole.
  • A second adapter platform, or a second traffic sensor is a duplicate method. Scanner-plus-graph is a real pair. Two of the same method is not.

Questions before you buy a CAASM platform

Until a quote answers these three, you are still buying a second inventory that will disagree with the first three.

  1. Which sensor matches the hole you can already name? Adapter CAASM will not invent a badge reader no source ingested. A graph will not fingerprint a silent PLC. A scanner will not walk an Okta group to an S3 bucket.
  2. What is the billed unit on the listing you will use? 500 assets, 200k datapoints, and a $3,250.00 monthly floor are not interchangeable. Reconcile the quote to that unit.
  3. Who owns the product on renewal? Armis already closed into ServiceNow. The runZero close is still expected. Continuity and standalone-parity are clauses, not homepage banners.

Which CAASM platform should you pick

Disagreeing EDR, CMDB, and cloud bills: Axonius. Blast radius from an identity: JupiterOne. A device nobody enrolled: runZero, knowing the Accenture / Dragos close is still pending. A plant floor, hospital wing, or building-management VLAN: Armis, already inside ServiceNow. Put the matching public price in the budget. Treat every vendor statistic you have not seen in your own tenant as marketing.

Frequently asked questions

Is CAASM the same purchase as EASM or CNAPP?

No. CAASM is the inside-the-perimeter inventory: what you own and which of those things is missing a control you already paid for. EASM is the outside view. CNAPP is cloud posture, and sometimes runtime, on the workloads you pointed it at. An unmanaged badge printer is a CAASM miss. A forgotten public bucket can show up in all three.

Do I need two of these?

Only if you can name two different holes. Scanner-plus-graph is a real pair. Two adapter platforms, or two traffic sensors, is a duplicate sensor. If the blind spot is IAM-to-SaaS, start with the graph or the adapters. If the blind spot is a device nobody enrolled, start on the wire.

What do the ServiceNow and Accenture-Dragos deals mean for a contract this quarter?

Armis already closed: ServiceNow took it on 20 Apr 2026 and said Centrix stays standalone. Price the next order as a ServiceNow-owned product and ask whether standalone Centrix is still on the renewal. runZero has not closed: Accenture’s Dragos / runZero deal is still expected August or September 2026. A new runZero contract needs written continuity. The homepage still says “runZero to join Dragos.”



List your product on Startup Stash

A listing is not a paid rank on this page.
Get listed

About the author

How we review tools

Written by

StartupStash

StartupStash

Editorial team

StartupStash is an editorial team. Each Top Tools shortlist is researched by a writer who works in that category, then checked against first-party product pages and public prices before it goes live.

Reviewed by

Manaal

Manaal

Content Manager, Startup Stash

Manaal is Content Manager at Startup Stash. She reviews the shortlist, the priced claims, and the sourcing before a Top Tools piece goes live.

Best CAASM Platforms (2026 Guide)
StartupStash

StartupStash is an editorial team. Each Top Tools shortlist is researched by a writer who works in that category, then checked against first-party product pages, public pricing, and recent product changes. A second editor reviews the piece before it goes live. We also run a directory of startup tools. A paid listing does not buy a place on a shortlist.