FortiCNAPP Cloud-Native Application Protection

Cloud security platform • UAE buyer guidance

FortiCNAPP Cloud-Native Application Protection in Dubai, UAE

Bring cloud posture, workload, identity, code and runtime risk into a more connected security workflow. FortiCNAPP is designed for organisations that want clearer cloud risk prioritisation without operating a disconnected collection of point tools.

Planning a FortiCNAPP purchase?

Prepare your cloud providers, approximate protected vCPU count, required security tier, developer count if Code Security is needed, subscription term and integration requirements. FourTeck can use those details to structure a more accurate quotation.

Delivery model
Cloud-based SaaS
Primary clouds
AWS, Azure, Google Cloud
Cloud licensing
Protected vCPU based
Code Security
Purchased independently
UAE purchase
Quote after requirement review

Direct answer for cloud-security buyers

FortiCNAPP is Fortinet’s Cloud-Native Application Protection Platform, a SaaS platform intended to help security, cloud and development teams understand cloud risk from code through runtime. It brings together capabilities such as cloud security posture management, workload protection, cloud infrastructure entitlement management, attack-path analysis, vulnerability assessment, cloud detection and response, Kubernetes security and code-security functions. Organisations operating AWS, Microsoft Azure, Google Cloud or Kubernetes should consider it when fragmented security tooling makes prioritisation and investigation difficult. Before proceeding, buyers should confirm which cloud-security tier is required, how many protected vCPUs are in scope, whether Code Security is needed, which cloud accounts and pipelines will be connected, and what onboarding, integration and support services should be included in the quotation.

What FortiCNAPP does

FortiCNAPP is built to help organisations see security posture, identity exposure, vulnerable workloads, cloud activity and development-stage weaknesses in a more unified context. Instead of treating a misconfiguration, a vulnerable package, an overprivileged identity and suspicious runtime activity as unrelated findings, the platform is designed to correlate risk information so teams can understand which issues deserve attention first.

That distinction matters in complex cloud estates. A cloud team may already have native cloud controls, vulnerability scanners, source-code tools, SIEM workflows and ticketing systems. The operational problem is often not a lack of findings but the difficulty of deciding which findings are materially connected to an attack path or an active threat. FortiCNAPP addresses that decision problem through consolidated visibility, risk prioritisation and behaviour-based detection.

Who should consider it

FortiCNAPP is most relevant to organisations running meaningful workloads in public cloud, Kubernetes or cloud-native development environments. Security operations teams can use it to investigate risk and active threats; cloud security teams can use posture and entitlement information to improve configuration hygiene; and DevSecOps teams can bring code, dependency and Infrastructure-as-Code checks closer to development workflows.

It is less appropriate to select the platform solely because an organisation uses cloud services. A buyer should first identify the cloud assets that require protection, the security gaps that existing tools do not cover well, the operational teams that will use the platform, and the licensing scale. The practical decision is whether FortiCNAPP can replace or rationalise enough fragmented controls while improving visibility and response in the organisation’s actual cloud architecture.

Cloud-security problems the platform is intended to address

Too many disconnected findings

Cloud posture scanners, vulnerability tools, identity reviews and runtime alerts can create parallel queues. FortiCNAPP is designed to connect context so teams can focus on risk relationships rather than process every finding independently.

Misconfiguration at cloud scale

Cloud environments change continuously. Posture management can identify configuration drift and policy violations across cloud resources, helping teams move from periodic review toward continuous assessment.

Excessive cloud privileges

CIEM capabilities help identify effective permissions and highlight identities whose access may be broader than required. Buyers should still align remediation with their organisation’s access-governance process.

Threats hidden in normal activity

Behaviour-based detection looks for unusual cloud and workload activity. This can help surface compromised credentials, cryptomining or other suspicious activity without relying only on manually maintained detection rules.

Security defects reaching production

Code Security capabilities can bring SAST, SCA, IaC checks and related application-security functions into development workflows, helping teams identify certain weaknesses before deployment.

Audit preparation across clouds

Continuous posture checks and framework mapping can support evidence collection and compliance monitoring. They do not replace governance, legal interpretation or an external audit where those are required.

Core FortiCNAPP capability band

CSPM

Cloud resource discovery, configuration assessment, policy checks and compliance-oriented posture visibility.

Cloud Workload Protection

Workload vulnerability and runtime protection capabilities for supported virtual machines, containers and Kubernetes environments, with tier dependencies.

CIEM

Visibility into cloud identities and effective permissions, with guidance for reducing excessive privileges and supporting least-privilege practices.

Cloud Detection and Response

Behaviour-driven detection intended to identify unusual activity and active threats across cloud accounts and supported workloads.

Code Security

Application-security functions including supported SAST, SCA, IaC security, secrets-related analysis, SBOM capabilities and CI/CD integrations.

Risk Prioritisation

Attack-path and relationship context designed to help teams understand exploitability, exposure and the potential impact of combined risks.

Which FortiCNAPP approach fits the requirement?

RequirementSuitable directionConfirm before ordering
Baseline cloud posture and configuration visibilityReview Standard tier capabilities firstCloud providers, protected vCPU scope, required posture features and support term
Broader risk prioritisation and advanced cloud-security workflowsCompare Professional tier against operational needsRequired features, minimum order quantity, integrations and workload coverage
Expanded workload security and enterprise-scale controlsEvaluate Enterprise tierProtected workloads, runtime requirements, tier-specific capability mapping and minimum quantity
Secure software development and CI/CD workflowsEvaluate FortiCNAPP Code Security separatelyCode-contributing developer count, repositories, CI/CD platforms and DAST requirements
Need onboarding assistanceAdd suitable QuickStart or professional servicesDesired workshops, integrations, documentation, training and deployment scope

Verified product and ordering information

FortiCNAPP is a software platform rather than a fixed hardware appliance, so buyers should evaluate licensing scope and capability tier instead of looking for ports, throughput or appliance dimensions. The information below reflects current Fortinet ordering guidance and should still be checked against the final bill of materials before purchase.

BrandFortinet
ProductFortiCNAPP Cloud-Native Application Protection Platform
Delivery typeCloud-based SaaS
Supported cloud environmentsAmazon Web Services, Microsoft Azure, Google Cloud and supported Kubernetes environments; exact integration and feature coverage should be checked for the intended service and environment.
Cloud Security tiersStandard, Professional and Enterprise
Cloud Security licensing metricProtected compute resources measured in vCPUs across cloud workloads. Current ordering guidance notes that DSPM and Agentless Workload Scanning are not included in the vCPU usage calculation.
Cloud Security bundle SKUsStandard: FC1-10-LACWK-1063-02-DD; Professional: FC1-10-LACWK-1064-02-DD; Enterprise: FC1-10-LACWK-1065-02-DD
Current cloud bundle minimumsStandard 500 vCPUs; Professional 375 vCPUs; Enterprise 250 vCPUs. Confirm current minimums when requesting a quote.
Cloud subscription terms1, 3 or 5 years for the referenced cloud-security bundles
Code Security SKUFC1-10-LACWK-1306-02-DD, licensed per code-contributing developer with a current minimum of 20 developers; Code Security may be purchased independently.
FortiDAST add-onFC1-10-DEVSC-216-02-DD adds five application entitlements and requires the FortiCNAPP Code Security base license.
Support guidanceCurrent FortiCNAPP license bundles generally include FortiCare Premium; confirm the exact support entitlement and contract term in the quotation.
UAE availabilityContact FourTeck for current options. Availability and commercial terms can depend on tier, quantity, subscription term and vendor lead time.

Licensing, feature and integration dependencies

FortiCNAPP should not be ordered as though every capability is included in every subscription. Fortinet separates the cloud-security platform from Code Security, and the cloud-security platform itself has Standard, Professional and Enterprise tiers. Some workload, threat-detection and advanced security capabilities are tier dependent. Code Security has its own developer-based licensing approach, and additional FortiDAST application entitlements can be added through a separate add-on that requires the Code Security base license.

The protected-resource calculation also matters. Cloud Security licensing is based on protected compute resources measured in vCPUs. Organisations should therefore inventory the workloads that are actually intended for protection rather than estimate purely from cloud-account count. Where an environment includes ephemeral compute, Kubernetes, multiple cloud providers or rapidly changing development workloads, the quotation should be based on a realistic capacity discussion rather than a static snapshot alone.

Integration coverage can also change over time. FortiCNAPP supports cloud providers and development-tool integrations, but a buyer should confirm the exact repository, CI/CD, ticketing, SIEM, SOAR and cloud-service integrations needed for the project. FourTeck can help capture these dependencies before the bill of materials is finalised.

A practical FortiCNAPP purchase and onboarding journey

01

Define the security outcome

Identify whether the priority is posture, workload protection, entitlement governance, runtime detection, code security, compliance visibility, tool consolidation or a combination.

02

Map the cloud estate

List cloud providers, accounts, subscriptions, projects, Kubernetes clusters, protected workloads, approximate vCPU quantities and key production environments.

03

Select the tier

Compare Standard, Professional and Enterprise capabilities against the actual controls required. Avoid selecting a tier only by name or price.

04

Include development scope

If application security is part of the project, identify developer counts, repositories, SAST, SCA, IaC, SBOM, DAST and CI/CD requirements for Code Security.

05

Plan integrations

Define which workflow, security operations, cloud and development systems need to exchange findings, alerts or remediation actions.

06

Quote and onboard

Confirm terms, support, services and final quantities, then plan account connection, policy review, tuning, ownership, reporting and operating procedures.

Risk context rather than a longer alert queue

A common cloud-security failure mode is treating every detected weakness as equally urgent. Public cloud estates can generate large volumes of configuration findings and vulnerability records, but actual risk depends on exposure, privilege, reachability, workload role and whether suspicious behaviour is occurring. FortiCNAPP is designed to connect these relationships through attack-path and contextual risk analysis.

For a buyer, the operational question is not simply whether the platform can find vulnerabilities. The more useful test is whether it helps analysts decide which vulnerabilities, identities and configurations create a credible path to important assets. During evaluation, organisations should review how their own high-value workloads appear in risk visualisations, how remediation ownership is assigned and how alerts move into existing SecOps workflows.

Cloud identity and entitlement visibility

Cloud permissions are difficult to assess because effective access can be created through users, groups, roles, inherited policies and service identities. CIEM functions in FortiCNAPP are intended to provide continuous visibility into cloud identities and their effective permissions, then help teams identify access that may be excessive for the role being performed.

Least privilege is not a one-time clean-up task. Development teams deploy new services, cloud roles evolve and automation accounts accumulate permissions. Buyers should therefore assess whether identity findings can be incorporated into an ongoing governance process. Remediation guidance should be reviewed against production dependencies, change-control requirements and the organisation’s identity architecture before permissions are reduced.

Security earlier in the development cycle

FortiCNAPP Code Security addresses a different part of the lifecycle from runtime cloud protection. It can identify certain weaknesses in first-party code, third-party dependencies and Infrastructure-as-Code before those issues reach production. Current integration guidance includes major development platforms such as GitHub, GitLab, Bitbucket and Azure DevOps for supported scanning workflows, with integration details depending on the specific scanning function.

The purchasing implication is important: Code Security is a separate product component and is licensed by code-contributing developer. A cloud-security buyer who also wants SAST, SCA, IaC scanning or related application-security capabilities should therefore include developer counts and repository workflow information in the initial requirement. This avoids discovering after the cloud-platform purchase that development security needs a separate licensing and implementation workstream.

Ideal business environments and use cases

Multi-cloud enterprises

Organisations using AWS, Azure and Google Cloud can evaluate FortiCNAPP when they want a common risk and threat perspective across cloud providers rather than entirely separate operating processes for each platform.

Kubernetes and container environments

Teams operating managed Kubernetes and container workloads can use supported posture, vulnerability and runtime capabilities to bring cluster and workload risk into the same broader cloud-security view.

DevSecOps programmes

Development organisations that want to find selected code, dependency and IaC issues earlier can evaluate Code Security alongside cloud runtime protection, while keeping licensing and workflow ownership distinct.

Compliance-sensitive workloads

Businesses preparing for standards or control frameworks can use continuous configuration assessment and mapped reporting as evidence-support tools, while retaining appropriate audit, governance and policy processes.

Security-tool consolidation projects

Organisations with separate CSPM, workload, entitlement and cloud-detection products may assess whether a unified CNAPP can reduce operational fragmentation and duplicated findings.

Cloud transformation programmes

Enterprises expanding cloud adoption can include CNAPP requirements in architecture planning so security visibility, development controls and runtime monitoring mature with the environment rather than after migration.

Integration and operating-model considerations

A CNAPP deployment has more value when its findings fit the organisation’s operating model. Before onboarding cloud accounts, decide who owns cloud posture findings, who approves identity remediation, who investigates behavioural alerts, who manages vulnerabilities, and which teams receive development-stage findings. Without clear ownership, a consolidated platform can still produce a consolidated backlog.

Consider integration requirements early. Security teams may need FortiCNAPP events in a SIEM or SOAR process, cloud teams may need findings routed to service-management systems, and developers may need results surfaced in source-control or CI/CD workflows. The Fortinet Security Fabric can be relevant where other Fortinet products are already in the environment, but integration scope must be confirmed for the specific product versions and desired workflow.

Data-access design is equally important. Connecting cloud accounts for posture assessment, enabling workload monitoring or integrating code repositories can require permissions and organisational approvals. The project plan should document what access is required, which accounts are in scope, how credentials or tokens are handled, and whether different business units need separate administrative boundaries. These decisions are part of deployment governance, not merely technical setup.

Buyer questions to resolve before requesting a quotation

How many protected vCPUs are realistically in scope?

The cloud-security license is capacity based. Include production, non-production and expected growth where they are intended to be protected.

Which cloud-security tier matches the required controls?

Standard, Professional and Enterprise are not interchangeable labels. Compare feature requirements before deciding.

Is Code Security part of the requirement?

If yes, count code-contributing developers and identify repositories, CI/CD tools and application-security functions required.

Which clouds and Kubernetes services will be connected?

Document cloud accounts, subscriptions, projects, clusters and regions so onboarding and feature support can be reviewed.

What existing security tools should FortiCNAPP integrate with?

Identify SIEM, SOAR, ticketing, source-control, CI/CD and other workflow systems so integration scope is included from the beginning.

What service level is needed for onboarding?

Decide whether internal teams will self-deploy or whether QuickStart, consulting, workshops, integration assistance, training or documentation are required.

FortiCNAPP procurement checklist

✓ Confirm cloud-security tier: Standard, Professional or Enterprise

✓ Estimate protected vCPU quantity and expected growth

✓ List AWS, Azure and Google Cloud accounts in scope

✓ Identify Kubernetes clusters and workload-monitoring needs

✓ Confirm subscription term and renewal alignment requirements

✓ Decide whether Code Security is required

✓ Count code-contributing developers if Code Security is included

✓ Identify source-control and CI/CD platforms

✓ Define FortiDAST add-on needs, if applicable

✓ Document SIEM, SOAR and ticketing integration requirements

✓ Confirm onboarding, consulting or QuickStart scope

✓ Clarify reporting, compliance and administrative ownership

✓ Confirm support entitlement in the final quotation

✓ Validate UAE availability, commercial terms and vendor lead time

How FourTeck can assist

FourTeck can help turn a broad CNAPP requirement into a quotation-ready scope. The process can include reviewing the intended cloud providers, approximate protected workload size, license tier, developer count, subscription term, security priorities, integration dependencies and deployment assistance required. This is useful when procurement teams receive a product name but not a complete licensing bill of materials.

Where a project also includes Fortinet firewalls, cloud network security or broader Security Fabric integration, FourTeck can help identify the questions that should be resolved before different product workstreams are combined. Explore FourTeck cybersecurity products or review technology services and deployment assistance for related planning.

What to send for an accurate quote

A useful enquiry should include the desired FortiCNAPP tier if already known, the number of protected vCPUs, the cloud environments involved, the requested subscription term and whether the project is new, an expansion or a renewal. If Code Security is needed, include the code-contributing developer count and expected development-tool integrations. For onboarding services, explain whether the requirement includes architecture workshops, cloud-account connection, policy tuning, CI/CD integration, training or documentation.

If these figures are not yet available, share the current environment and business objective instead. FourTeck can help structure the discovery questions before a final commercial request is prepared. Use the FourTeck contact page to start the discussion.

UAE availability and support guidance

FortiCNAPP availability in the UAE should be confirmed against the required tier, license quantity, term and services scope. Because this is a subscription platform with capacity and developer-based licensing rather than a single physical appliance, the commercial process depends on the exact bill of materials. Vendor lead time, subscription start dates, ordering minimums and support terms can change, so they should be validated at quotation stage rather than assumed from a generic product page.

FourTeck can assist with requirement review, license selection, quotation coordination and planning for configuration or onboarding support where required. Organisations can also review Fortinet solutions in the UAE for related security products. Installation or configuration scope should be explicitly included in the quotation when needed.

Dubai, Abu Dhabi, Sharjah and Ajman coverage

Businesses operating from Dubai, Abu Dhabi, Sharjah and Ajman can contact FourTeck for FortiCNAPP requirement review and quotation coordination. The same licensing questions apply across the UAE: cloud tier, protected vCPU quantity, developer count where Code Security is required, subscription duration, onboarding needs and integration scope. For multi-site companies, it is usually more useful to define the cloud environment and organisational ownership than to treat each office as a separate deployment, because FortiCNAPP protects cloud and development environments rather than a branch appliance at each location. Delivery coordination, commercial terms, services and support should be confirmed after the final scope is established. For broader company information, visit about FourTeck.

GCC Availability

FortiCNAPP requirements can also be coordinated for organisations planning cloud-security projects across GCC markets such as the United Arab Emirates, Saudi Arabia, Kuwait, Qatar, Bahrain and Oman. The practical starting point is not the country name alone but the exact cloud and licensing scope: protected vCPUs, desired FortiCNAPP tier, developer count for Code Security, subscription term, required integrations and any professional-services requirement. FourTeck can assist with requirement review, quotation coordination, configuration scope, onboarding planning, renewal guidance and multi-country project discussions where appropriate. Availability, license ordering conditions, vendor lead times, service visits and commercial terms can vary by destination, quantity and project scope. Buyers should therefore provide the destination country, requested product or service, capacity, subscription term, deployment context and expected timeline before treating a price or lead time as final. For Kuwait-related technology enquiries, buyers may also review FourTeck Kuwait resources.

Africa Availability

Organisations planning FortiCNAPP deployments in Africa can engage FourTeck to clarify licensing, cloud scope, development-security needs and regional procurement requirements before a quotation is prepared. For cloud-security projects, the destination country may influence commercial arrangements, but the technical requirement still needs to identify protected workloads, cloud providers, Kubernetes usage, license tier, subscription term and integrations. Where Code Security is included, developer counts, repositories and CI/CD platforms should also be documented. Availability and fulfilment can depend on the destination, license region, quantity, vendor lead time, service scope and local project conditions. Buyers should share the country, exact requirement, expected capacity, preferred schedule and any configuration or support expectations so the project can be evaluated appropriately. FourTeck maintains regional resources for markets including Kenya, Uganda and broader Africa technology requirements.

Related FourTeck options to consider

Fortinet cloud network security

Consider alongside CNAPP when the project also requires network-level controls, segmentation, cloud firewalling or security policy enforcement.

Explore Fortinet security →

FortiCNAPP Code Security

Relevant when the project extends into SAST, SCA, IaC security, software supply-chain visibility and developer workflows. Licensing is separate from cloud security.

FortiDAST add-on

May be considered when additional application-scan entitlements are needed with Code Security. Confirm the base license and required application quantity.

Deployment and configuration services

Useful when internal teams need assistance with onboarding, cloud-account connection, integration, policy review, training or operational handover.

Why businesses contact FourTeck for FortiCNAPP planning

The difficult part of a FortiCNAPP purchase is often not identifying the product name. It is translating the cloud estate into the correct commercial and deployment scope. A procurement request that says only “FortiCNAPP” does not define which cloud tier is needed, how many vCPUs should be protected, whether Code Security is part of the requirement, which contract term is preferred or what services should be included.

FourTeck can help organisations organise those decisions before a quote is requested. This can include clarifying whether the requirement is primarily posture management, workload protection, identity entitlement analysis, active threat detection, application security or consolidation; identifying the information needed for capacity sizing; reviewing SKU and term options; discussing compatibility and integration questions; and separating license requirements from professional-services scope. The objective is to reduce ambiguity in the bill of materials and make technical and procurement conversations easier to align.

What buyers are trying to understand before choosing a CNAPP

A business researching FortiCNAPP is usually trying to answer a larger question than “what features does it have?” The real decision is whether a CNAPP platform can reduce operational fragmentation across cloud security without creating a new layer of complexity. Security teams want to know if findings are prioritised in a way that reflects real exposure. Cloud teams want to know whether configuration and identity issues can be understood without constant manual policy tuning. Developers want feedback early enough to fix problems before production. Procurement wants licensing quantities that can be defended against the current environment and forecast growth.

CNAPP versus separate CSPM and workload tools

The main value of the CNAPP model is consolidation of related cloud-security functions and the ability to correlate context. A separate CSPM product may identify misconfigurations very well, while another workload tool handles runtime protection. CNAPP aims to connect posture, vulnerability, identity, workload and threat information. That does not automatically mean every organisation should replace every existing tool. A useful evaluation should compare duplicated capabilities, data quality, workflow integration, investigation time and whether existing controls provide context that the unified platform cannot replace.

Agentless visibility versus workload runtime monitoring

Buyers often ask whether cloud security can be fully agentless. Agentless approaches are useful for broad discovery and assessment because they can examine cloud resources without installing software on every workload. Runtime monitoring, however, may require deeper workload visibility depending on the control. FortiCNAPP supports multiple methods, so the design should be based on what needs to be detected and protected rather than on an “agentless only” preference. Identify workloads that are sensitive, ephemeral, containerised or subject to stricter monitoring requirements, then confirm how the selected tier covers them.

How cloud risk becomes actionable

A long vulnerability list is rarely the desired outcome. Teams need to know which weaknesses are reachable, linked to excessive privileges, associated with exposed secrets or connected to suspicious activity. FortiCNAPP uses contextual relationships and attack-path analysis to help prioritise remediation. During a proof of concept or technical evaluation, test the platform using workloads that the business actually cares about. Ask whether the highest-ranked risks make operational sense, whether the supporting evidence is understandable and whether remediation can be routed to the team that owns the affected asset.

What “code to cloud” should mean in a project

“Code to cloud” is useful only when the development and runtime parts of the lifecycle are connected to the organisation’s process. For FortiCNAPP, the cloud-security platform and Code Security can be purchased independently. A buyer therefore needs to decide whether the project begins with production cloud risk, development-stage security, or both. If Code Security is in scope, confirm the developer count, repositories, pull-request workflows, CI/CD systems and the types of scanning required. If it is not in scope, do not assume that cloud-platform licensing automatically covers application-security workflows.

Licensing is another frequent point of confusion because there is no single universal “FortiCNAPP price” that meaningfully describes a deployment. Cloud Security is licensed by protected vCPU and is available in tiered packages, while Code Security is licensed per code-contributing developer. Minimum order quantities apply to current bundles. Public web prices for individual entitlements can be useful as rough references, but they are not a substitute for a bill of materials because an enterprise order depends on capacity, tier, term, quantity and commercial conditions. For UAE procurement, a better approach is to provide FourTeck with a workload estimate and required control set, then request a quotation tied to the actual environment.

Buyers also increasingly ask whether CNAPP replaces a SIEM, SOAR, cloud firewall or identity platform. It generally should not be evaluated as a one-for-one replacement for every adjacent security category. FortiCNAPP specialises in cloud-native risk, workload, identity and application-security context. SIEM and SOAR platforms may remain central to enterprise-wide detection and response. Cloud firewalls enforce network security policy. Identity providers manage authentication and access. The decision is therefore architectural: determine which system is authoritative for each control, where FortiCNAPP contributes context, and how findings or actions should move between platforms.

Another high-value question is how quickly a platform can be operationalised. Technical onboarding can include cloud account connection, permission setup, policy review, workload coverage, integration, ownership mapping, alert tuning and reporting. The effort depends on the scale and governance of the cloud estate. Fortinet lists QuickStart and consulting services for customers that want structured onboarding. FourTeck can help buyers decide whether those services should be included in the commercial scope or whether internal cloud and security teams are prepared to handle deployment directly.

Finally, organisations should evaluate CNAPP against operating outcomes rather than a feature checklist alone. Useful measures include whether teams can identify high-risk attack paths faster, reduce duplicate findings, improve accountability for remediation, provide clearer compliance evidence, detect unusual cloud activity and integrate application-security checks without blocking development. These outcomes are environment dependent, so they should be tested with representative workloads and workflows rather than assumed from a product description.

Questions cloud teams ask during evaluation

Can we start with posture management and expand later?

Potentially, but the expansion path should be planned against the licensing tiers and contract structure. Start by defining the controls required now and what is likely to be added later. If broader workload or risk capabilities will be needed soon, compare the cost and operational impact of the appropriate higher tier before committing to a baseline package.

How should we estimate vCPUs in an elastic cloud?

Use a representative view of protected compute rather than a one-day peak or a low static baseline. Consider production scale, normal elasticity, new projects and whether non-production workloads are in scope. Fortinet’s licensing calculation has specific usage rules, so final sizing should be checked with the current ordering guidance and quotation process.

Do developers need FortiCNAPP access if we only buy cloud security?

Not necessarily. The cloud-security platform can be operated by security and cloud teams without deploying the separate Code Security product. If developers need pull-request scanning, SAST, SCA, IaC checks or related development feedback, include Code Security and developer licensing in the project design.

What should we test in a proof of concept?

Use real but controlled cloud environments that include representative accounts, identities, Kubernetes or workloads, and existing security workflows. Test discovery, prioritisation, investigation, alert quality, remediation ownership and integrations. A useful proof of concept should answer whether the platform improves decision-making, not merely whether it can connect to the cloud account.

Can CNAPP support compliance without replacing our GRC process?

Yes, that is the more realistic role. FortiCNAPP can map cloud posture and activity to recognised frameworks and generate evidence-oriented reporting, but governance decisions, risk acceptance, control ownership and formal audits remain organisational responsibilities. Treat platform reporting as continuous technical evidence rather than the entire compliance programme.

When should professional services be included?

Include services when the project spans many cloud accounts, multiple teams, complex integrations, new security processes or a tight deployment window. Internal teams may self-onboard smaller environments, but structured consulting can help with architecture, policy tuning, workflows, training and handover when the scope is broader.

Frequently asked questions

What is FortiCNAPP used for?

FortiCNAPP is used to help organisations manage cloud-native security risk across cloud posture, workloads, identities, Kubernetes, vulnerabilities, active threats and, with Code Security, development-stage application security. Its purpose is to provide more connected visibility and prioritisation from code through runtime.

Does FortiCNAPP support AWS, Azure and Google Cloud?

Yes. Fortinet positions FortiCNAPP for AWS, Microsoft Azure and Google Cloud environments, with support for Kubernetes and other cloud-native resources. Exact service, integration and feature coverage should be confirmed for the buyer’s intended environment.

How is FortiCNAPP Cloud Security licensed?

Current Fortinet ordering guidance licenses FortiCNAPP Cloud Security by protected compute resources measured in vCPUs across cloud workloads. Buyers should calculate the intended protected scope and confirm current usage rules, minimum quantities and subscription terms before ordering.

What FortiCNAPP cloud-security tiers are available?

Current ordering guidance lists Standard, Professional and Enterprise tiers. Capabilities differ by tier, so organisations should compare the specific posture, threat, workload, risk and data-security functions they need rather than choose by tier name alone.

Is FortiCNAPP Code Security included with the cloud platform?

No assumption should be made that it is included. Fortinet states that the Cloud Security platform and Code Security are independent parts that can be purchased separately. Code Security has developer-based licensing and its own minimum quantity.

Can FortiCNAPP help secure Kubernetes environments?

FortiCNAPP includes Kubernetes-related security capabilities such as posture assessment and supported workload or behaviour monitoring functions. Exact coverage depends on the Kubernetes environment, selected tier and deployment method, so compatibility should be checked before rollout.

Can FortiCNAPP support cloud compliance programmes?

FortiCNAPP can continuously assess cloud configurations and map findings to recognised compliance frameworks, helping teams collect technical evidence and identify misconfigurations. It supports a compliance programme but does not replace governance, legal review or an independent audit where required.

What information does FourTeck need for a FortiCNAPP quotation?

Provide the desired tier if known, protected vCPU estimate, cloud providers, subscription term, developer count if Code Security is required, integration requirements and any onboarding or professional-services scope. If sizing is not yet available, FourTeck can help organise the discovery questions.

Can FourTeck assist with FortiCNAPP deployment and configuration?

FourTeck can discuss onboarding, configuration and integration requirements and coordinate appropriate service scope. The exact activities, deliverables, timeline and whether Fortinet professional services are required should be agreed in the quotation rather than assumed as part of the license.

Build the FortiCNAPP quote around your actual cloud estate

Share your protected vCPU estimate, cloud providers, preferred tier, developer count where relevant and onboarding requirements. FourTeck can help convert that information into a clearer licensing and services request for Dubai and the wider UAE.

Scroll to Top
Powered by Joinchat