Microsoft Defender for Cloud Drops Default CSPM in 2026, Qualys Adds Real-Time Posture
Microsoft will stop auto-enabling Foundational CSPM for new Azure subscriptions on October 27, 2026. Qualys launched Real-Time CSPM to shift from periodic scans to continuous monitoring.
Microsoft Makes Foundational CSPM Opt-In for New Azure Subscriptions
Microsoft Defender for Cloud will stop enabling Foundational CSPM by default for new Azure subscriptions starting October 27, 2026. The free posture tier will remain available, but security teams will need to activate it explicitly. The change matters because it removes a friction point that previously anchored Azure customers to Microsoft's native tooling and creates a formal decision gate where buyers will compare Microsoft's paid Defender CSPM tier against third-party CNAPP platforms like Wiz, Palo Alto Prisma Cloud, and Orca.
Foundational CSPM today includes 450+ assessments for CIS, ISO, and NIST compliance. Making it opt-in rather than automatic increases the risk of posture coverage gaps in new subscriptions if onboarding is not handled carefully. It also raises the stakes for security teams that assumed native Azure posture management was a given: they now need to justify the activation internally, decide whether the free tier is sufficient, or build a budget case for a paid alternative. For buyers running multi-cloud environments, this shift may accelerate the argument for a unified CNAPP platform rather than relying on cloud-native posture tools across AWS, Azure, and GCP.
Qualys Launches Real-Time CSPM to Replace Periodic Scanning
Qualys introduced Real-Time CSPM in August 2026, moving posture detection from periodic scans to continuous monitoring across multi-cloud environments. The capability is built into the Qualys Cloud Platform, which supports 40+ global compliance frameworks including NIST, PCI DSS, GDPR, SOC 2, and ISO 27001. The shift matters because it reduces the dwell time of misconfigurations and narrows the competitive gap with Wiz and Palo Alto Prisma Cloud, both of which already market real-time or near-real-time posture visibility.
For enterprise buyers, the change from periodic to continuous posture checks can improve audit readiness and reduce the window where risky misconfigurations go undetected. That creates a stronger case for replacing point-in-time CSPM tools or for reevaluating whether current tooling can support faster remediation SLAs across cloud, vulnerability, and compliance workflows. It also raises the bar for vendors that still rely on batch scanning as their primary detection mechanism: buyers are increasingly treating real-time posture as table stakes, not a premium feature.
CSPM is Becoming a Continuous Governance Layer Inside CNAPP
Frost & Sullivan projects the CSPM market will grow from $2.82 billion in 2025 to $6.96 billion by 2030, a 19.8% CAGR. The firm says CSPM is no longer a periodic compliance exercise but a continuous, risk-based governance layer inside CNAPP platforms. That forecast supports the competitive shift toward integrated platforms from Wiz, Palo Alto Prisma Cloud, and Microsoft Defender for Cloud rather than standalone posture-only products.
The broader market sizing places CSPM somewhere between $6.04 billion and $7.10 billion in 2026, depending on the analyst firm and how CSPM is defined. The spread itself is a signal that CSPM is being defined differently across reports—sometimes as standalone posture management, sometimes as part of broader cloud security and compliance. That definitional drift usually favors vendors with broader CNAPP suites, because their spending is easier to capture in larger platform budgets.
What to Watch
Microsoft's opt-in change does not take effect until October 2026, which gives Azure-heavy enterprises time to audit their subscription onboarding processes and decide whether to formalize Foundational CSPM activation or move to a paid tier. For buyers evaluating CNAPP platforms, the combination of Microsoft's pricing shift and Qualys' real-time capability reinforces the trend away from point solutions: vendors that can connect posture findings to runtime risk, identity, and remediation workflows are likely to have an advantage in renewals and competitive bake-offs. The CSPM market is growing, but the money is moving toward platforms that treat posture as one layer in a broader cloud security stack, not a standalone product.
Technology decisions, clearly explained.
Weekly analysis of the tools, platforms, and strategies that matter to B2B technology buyers. No fluff, no vendor spin.
