You think you know your asset inventory until an incident ticket names a hostname that is not in the CMDB, not in the EDR console, and not on last quarter's license count. The same gap shows up in three places at once: a contractor laptop that never got an agent, an AWS account opened on a personal card, and a badge-in printer that has been talking to the internet since 2019.
External scanners will not save you here. This is an inside-the-perimeter problem: what you own, how it connects, and which of those things are missing the control you already paid for.
Gartner calls that work Cyber Asset Attack Surface Management, or CAASM: continuously inventory every digital asset (cloud, code, identity, endpoint, SaaS) and use that inventory to find coverage gaps. It is not EASM, not CNAPP, and not BAS.
IBM's Cost of a Data Breach Report 2026 put the global average at a record $4.99 million, up 12% year over year, with U.S. organizations at $11.5 million. You cannot contain what you cannot name.
Four platforms below do the naming from different angles: Axonius reconciles the tools you already run, JupiterOne graphs the relationships, runZero finds the devices those tools never saw, and Armis watches the unmanaged and cyber-physical estate.
Someone on HN said it in 2019, and it has not aged:
You (I'm using the generic you here, as though speaking to a CIO) cannot even inventory all the net-connected software and hardware you own, and even if you could the list would be out of date in 24 hours.
Someone else used runZero to find internal assets the company swore were gone.
Axonius

Axonius Asset Cloud is the adapter-first CAASM: it interrogates the systems that already know pieces of the estate rather than scanning the wire. The Cyber Assets page at axonius.com/platform/cyber-assets is live (the marketing site sits behind a bot check; the dedicated CAASM URL cyber-asset-attack-surface-management-caasm is the same platform).
In a 6 Aug 2026 interview on theCUBE at Black Hat USA, co-founder Dean Sysman put the integration count at "over 1,400" across cloud, security, networking, and IT. That is the vendor claim we use once.
The last 30 days were a product dump. On 21 Jul 2026 Axonius announced the Axonius AI Agent (preview), the Axonius MCP Server (early access, translating English into Axonius Query Language), and Docs for AI.
On 22 Jul it expanded Cyber Assets and Exposures: a CMDB Reconciliation Workspace and Verified Assets in early access (Verified Assets slated GA in August 2026), Business Context and Asset Criticality generally available, and Cyber-Physical Assets — the Cynerio line acquired in July 2025 — still in early access with GA expected in the second half of 2026.
Best for: Security and IT teams that already run a thick stack — EDR, MDM, IAM, cloud, CMDB — and need one reconciled record per device, identity, and SaaS user, plus the ability to push a fix back into those same tools.
Key Features:
- The Cyber Assets adapter network correlates and deduplicates records from the existing stack into one asset model, then surfaces coverage gaps (missing EDR, stale OS, unmanaged SaaS) without a new agent.
- Bi-directional enforcements: create tickets, enrich a CMDB, disable a stale account, or trigger a scan from the same query that found the gap.
- On 21 Jul they added the AI Agent and MCP Server, so a question in English can become a live AQL answer.
- Verified Assets and CMDB Reconciliation Workspace (early access as of 22 Jul 2026) aimed at the "is this one device or three?" problem that breaks audits.
Why we like it: If CrowdStrike, Intune, Okta, and AWS already know most of the estate, Axonius's job is to stop those four consoles from disagreeing. AWS Marketplace reviewers from late 2025 and 2026 keep repeating the same win: ownership and change history on a single record, which shortens incident response when the ticket has an IP and nothing else.
Notable Limitations:
- Query language and UI have a real learning curve; a Feb 2026 G2 review on the AWS listing called the interface "heavy" at large scale and said bad source data produces confusing records.
- Value tracks adapter quality. A stale or missing source makes the "single source of truth" a single source of argument.
- Cyber-Physical Assets is still early access. If OT or clinical devices are the buying reason, treat that module as a roadmap item until H2 2026 GA.
Pricing: AWS Marketplace. Two 12-month contract dimensions: AXS_500_Complete — $90,625.00 / 12 months for 500 assets with unlimited queries, adapters, and enforcements; Axonius SM: 700 Users — $88,000.00 / 12 months for 700 unique SaaS users. Private offers are available. Refunds: none. The listing shows 4.2 stars from 16 ratings.
JupiterOne

JupiterOne is the graph CAASM. The CAASM solution page is live: unify cloud, code, identity, and endpoint assets into one continuously updated graph, then ask who can reach what.
Discovery is agent-free and API-based, with 200+ native integrations (AWS, Azure, GCP, Okta, GitHub, CrowdStrike, ServiceNow among them), J1QL for engineers, and JupiterOne AI for plain-English questions. Policy-as-code evaluates controls continuously and collects evidence for SOC 2, ISO 27001, PCI, FedRAMP, HIPAA, and NIST.
The last 30 days were about putting that graph in front of an LLM. JupiterOne launched its MCP server in July 2026 and, on 10 Aug 2026, listed it as a community server in Anthropic's MCP directory, so a Claude session can ask the live graph "which internet-facing assets have admin access to something that touches customer data?"
CEO Paul Forte, interviewed 13 Aug 2026, framed the company as mapping relationships rather than listing assets.
Best for: Cloud-native and hybrid security teams that need to query blast radius — identity to workload to data — and keep audit evidence current without a quarterly spreadsheet scramble.
Key Features:
- Agent-free ingestion from 200+ sources into a relationship graph, with J1QL and JupiterOne AI.
- Coverage-gap detection across domains: workloads without EDR, over-permissioned contractors, shadow SaaS.
- Continuous Controls Monitoring priced on existing datapoints (no extra input metric), plus Unified Vulnerability Management priced on findings.
- MCP server, listed in Anthropic's directory on 10 Aug 2026, so Claude and other MCP clients can query the graph without a custom integration.
Why we like it: Most CAASM tools stop at "here is the list." JupiterOne's useful unit is the edge: this IAM role can assume that role, which can write to that bucket, which is attached to a workload missing the agent. AWS Marketplace reviewers in June 2026 describe audit prep dropping from weeks of evidence collection to a status check.
Notable Limitations:
- J1QL has a learning curve. June 2026 reviews on the AWS listing flag slow queries on large graphs, API rate limits, and alert noise.
- Unified-device matching is still imperfect. A 16 Feb 2026 AWS review asked for a way to manually bind an external Qualys view of a host to the internal record when hostname, MAC, and IP disagree; the same reviewer said the compliance module had not replaced their manual ISO 27001 tracking. Demo CCM against your framework.
- The public pricing page table is internally inconsistent (tier names and datapoint caps do not line up). Use the AWS Marketplace table below as the numbers we actually saw.
Pricing: AWS Marketplace. 12-month contract dimensions:
| Dimension | Description | Cost / 12 months |
|---|---|---|
| AWS Marketplace Private Offer | Contact JupiterOne sales for a custom quote | $0.00 (private offer) |
| Small-Market | Up to 200,000 data points | $25,000.00 |
| Mid-Market | Up to 400,000 data points | $50,000.00 |
| Enterprise | Up to 1,000,000 data points | $100,000.00 |
A data point, per the listing, is a unit of ingested cyber-asset data. Above 1,000,000 datapoints, request a private offer. Refunds: none. 4.6 stars from 10 ratings. 24- and 36-month contracts are also on the page.
runZero

runZero is the discovery CAASM: safe unauthenticated scanning, passive collection, and API integrations, with fingerprinting that is supposed to tell you the device is a specific PLC or a forgotten ESXi host, not "unknown, 22/tcp open." The homepage and platform page are live. HD Moore founded the company in 2018 (originally Rumble; rebranded 2022). A completely free tier covers home use and environments under 100 assets.
The company is in the middle of a sale. On 18 Jun 2026 Accenture announced agreements to acquire a majority stake in Dragos and 100% of runZero and NetRise at a combined enterprise value of approximately $4.175 billion, expected to close in August or September 2026 subject to regulatory approval.
After close, runZero is slated to operate under Dragos, with Moore joining Dragos leadership. The homepage banner still reads "runZero to join Dragos."
Product work has not frozen: runZero 5.1 shipped AI workflows (natural-language search, dashboard and report creation, autonomous discovery, AI-assisted custom integrations) and a native Dragos integration. A runZero Hour on 19 Aug 2026 is set to recap BSides LV, Black Hat, and DEF CON.
Published case numbers on the homepage: North Carolina's K–12 program covers 343 Public School Units and more than 1.3 million IT, OT, and IoT devices; the University of Auckland reported 20% more assets than prior inventory; York University reported 15,000 newly discovered assets.
Best for: Teams whose first problem is unknown and unmanageable devices on the wire — IT, OT, IoT, mobile, remote — especially where agents and credentials are not an option, and who want a public, incremental price they can put in a budget line.
Key Features:
- Unauthenticated active scanning designed as safe for sensitive OT and IoT, plus always-on passive discovery and API integrations with EDR, MDM, cloud, and vulnerability scanners.
- Fingerprinting so the output is a device identity, not a port list.
- SaaS, on-prem, and air-gapped / offline-scanner options; no agents, no authentication, no appliances required for a first pass.
- runZero 5.1 AI workflows and a native Dragos integration, which will matter more if the Accenture close lands on the advertised August–September 2026 window.
Why we like it: It is the only product in this set with a public, mechanical AWS price that a mid-size team can buy without a six-week private-offer dance, plus a free sub-100-asset tier for a real trial. The HN comment above is the use case: assets the owner swore were gone.
Notable Limitations:
- Acquisition risk is live. Closing is expected Aug/Sep 2026 and is not done. An HN comment on the Dragos thread was "Time to start migration planning." Get written continuity language into any new contract.
- AWS Marketplace has almost no review volume: 4.0 stars from a single external G2 review dated 10 Jul 2022.
- It will not replace a relationship graph or an adapter-reconciliation layer. If your blind spot is IAM-to-SaaS, not "what is this MAC," start with JupiterOne or Axonius.
Pricing: AWS Marketplace. One 12-month dimension: x 500 Assets — $6,000.00 / 12 months. Live description: "Adds capacity for 500 additional assets observed within the last 30 days." An asset is any device observed in that window; devices not seen in 30 days do not count. Buy more 500-asset blocks as the estate grows. That matches the previously reported public price. Free tier: fewer than 100 assets. Refunds: test during the free trial; accounts@runzero.com for requests.
Armis

Armis is the cyber-physical CAASM. armis.com is live (the homepage and the Asset Management and Security page sit behind Cloudflare bot checks; they are not 404s). The product is Armis Centrix, an agentless platform that inventories managed and unmanaged IT, IoT, OT, IoMT, cloud, and virtual assets by watching the network, then layers threat detection and vulnerability prioritization.
The 2026 ownership change already happened. ServiceNow completed its acquisition of Armis on 20 Apr 2026 for approximately $7.75 billion in cash, about six months ahead of the original H2 2026 guidance.
ServiceNow said Armis Centrix remains available as a standalone product, integrated with the ServiceNow AI Platform, with deeper integration over time. On 4 Aug 2026, inside the last 30 days, ServiceNow launched autonomous security products on top of Armis and Veza, including Agentic AI for Cyber Physical Security — agentless device discovery on OT and medical networks, behavioral baselines, and attack-path modeling. Armis was named a Leader in the 2026 Gartner Magic Quadrant for CPS Protection Platforms for a second year (ServiceNow close release).
AWS Marketplace search does return listings. Two of them: Armis Device Security Platform (Centrix SaaS, 4.3 stars from 30 ratings) and Armis Centrix ViPR Pro (finding consolidation, 0 ratings). A FedRAMP private-offer listing also exists.
Best for: Organizations whose unknown-device problem is industrial, clinical, or IoT-heavy — manufacturing, healthcare, critical infrastructure, SLED — and who want agentless, traffic-based inventory with a path into ServiceNow workflows.
Key Features:
- Agentless discovery of managed and unmanaged IT, IoT, OT, IoMT, and cloud assets by passive network analysis.
- Centrix modules on that listing: Asset Management and Security; OT/IoT Security; Medical Device Security; Actionable Threat Intelligence; Vulnerability Prioritization and Remediation.
- ViPR Pro consolidates findings from host, endpoint, cloud, and AppSec tools and assigns remediation owners.
- Standalone Centrix plus ServiceNow AI Platform integration as of the 20 Apr 2026 close, with new agentic CPS products announced 4 Aug 2026.
Why we like it: When the asset cannot run an EDR agent — a pump controller, a CT scanner, a badge reader — adapter-only CAASM is blind unless some other tool already saw it. PeerSpot reviewers on the AWS listing in May 2026 keep citing OT/IoT and unmanaged-device discovery as the reason they bought it, not a prettier CMDB.
Notable Limitations:
- ServiceNow ownership is new. Centrix is promised as standalone today; put roadmap-parity language in the next renewal.
- List prices on Marketplace are minimums that route you to a private offer. The $3,250/month figures below are floors, not a 5,000-device all-in quote.
- Several AWS/PeerSpot reviews read like partner write-ups, and at least one (11 Mar 2026) describes OpenText identity work that is not this product. Discount anecdotal ROI percentages on that listing.
Pricing: Both public listings point to private offers at aws_marketplace@armis.com.
- Device Security Platform, 1-month contract: Armis Platform — $3,250.00 / month, "Centrix Standard minimum." 12-, 24-, and 36-month contracts also offered. Fees non-cancellable and non-refundable except as required by law.
- Centrix ViPR Pro, 1-month contract: 5,000 Devices — $3,250.00 / month, "VIPR Pro Standard minimum." 24-month contracts advertise savings up to 50%; 36-month up to 67%. Volume above 5,000 devices is a private offer.
There is no public per-asset rate comparable to runZero's $6,000 / 500. Budget as an enterprise private offer with a published floor of $3,250 per month.
Four ways to learn the estate
The feature lists agree on "inventory." They do not agree on the sensor.

What it actually costs
Public AWS cards, checked this week. They do not share a meter, so a four-column price grid would invent a comparison that is not there.
runZero is the only mechanical mid-size buy: $6,000 per 12 months per 500 assets observed in 30 days, and free under 100. JupiterOne's usable numbers are the AWS Marketplace datapoint tiers in the section above, not the company's own pricing page. Axonius Complete at 500 assets is $90,625 per 12 months — a different buyer than the scanner. Armis publishes a $3,250-per-month floor that is not an all-in estate quote.
Budget the first three from those listings. Budget Armis as a private offer.
CAASM, EASM, and the two-product mistake
CAASM vs EASM vs CNAPP
CAASM is the inside-the-perimeter inventory: what you own — cloud, code, identity, endpoint, SaaS — and which of those things is missing a control you already paid for. EASM is the opposite door: domains, IPs, certificates, and exposed services an outsider can enumerate. CNAPP is cloud posture, and sometimes runtime, on the workloads you pointed it at.
An unmanaged badge printer is a CAASM miss; a forgotten public bucket can show up in all three, which is why the labels get sold as synonyms.
Do I need two of these?
Only if you can name two different holes. Adapter CAASM will not invent a badge reader no source ingested; a graph will not fingerprint a silent PLC; a scanner will not walk an Okta group to an S3 bucket; Armis is not a SaaS-to-SaaS map.
Scanner-plus-graph is a real pair. Two adapter platforms, or two traffic sensors, is the two-product mistake.
What does the ServiceNow / Accenture-Dragos ownership change mean for a contract this quarter?
Armis already closed: ServiceNow took it on 20 Apr 2026 for about $7.75 billion, said Centrix stays standalone, and shipped agentic CPS products on 4 Aug 2026. Price the next PO as a ServiceNow-owned product and put standalone-parity language in the renewal.
runZero has not closed: Accenture's Dragos / runZero / NetRise deal is still expected August or September 2026, after which runZero is slated to sit under Dragos. A new runZero contract needs written continuity, not a homepage banner.
Why is JupiterOne's public pricing page unusable?
The pricing page table does not agree with itself: tier names and datapoint caps did not line up. The AWS Marketplace listing in the JupiterOne section is the card we can defend in a budget. If a quote arrives off the marketing page, reconcile it to those Marketplace dimensions before you sign.
FAQs
What is the difference between CAASM, EASM, and CNAPP?
CAASM is the inside-the-perimeter inventory: what you own (cloud, code, identity, endpoint, SaaS) and which of those things is missing a control you already paid for. EASM is the opposite door: domains, IPs, certificates, and exposed services an outsider can enumerate. CNAPP is cloud posture, and sometimes runtime, on the workloads you pointed it at. An unmanaged badge printer is a CAASM miss. A forgotten public bucket can show up in all three.
Do I need two CAASM products?
Only if you can name two different holes. Adapter CAASM will not invent a badge reader no source ingested. A graph will not fingerprint a silent PLC. A scanner will not walk an Okta group to an S3 bucket. Armis is not a SaaS-to-SaaS map. Scanner-plus-graph is a real pair. Two adapter platforms, or two traffic sensors, is the two-product mistake.
What does the ServiceNow / Accenture-Dragos ownership change mean for a contract this quarter?
Armis already closed: ServiceNow took it on 20 Apr 2026 for about $7.75 billion, said Centrix stays standalone, and shipped agentic CPS products on 4 Aug 2026. Price the next PO as a ServiceNow-owned product and put standalone-parity language in the renewal. runZero has not closed: Accenture’s Dragos / runZero / NetRise deal is still expected August or September 2026. A new runZero contract needs written continuity, not a homepage banner.
Why is JupiterOne’s public pricing page unusable?
The pricing page table does not agree with itself: tier names and datapoint caps did not line up. The AWS Marketplace listing in the JupiterOne section is the card we can defend in a budget. If a quote arrives off the marketing page, reconcile it to those Marketplace dimensions before you sign.
Bottom Line on CAASM Platforms
Pick the discovery method that matches the hole you can already describe. Disagreeing EDR, CMDB, and cloud bills: Axonius. Blast radius from an identity: JupiterOne. A device nobody enrolled: runZero, knowing the Accenture/Dragos close is still pending. A plant floor, hospital wing, or building-management VLAN: Armis, already inside ServiceNow.
Put the matching public price in the budget. Treat every vendor statistic you have not seen in your own tenant as marketing.


