Cyber asset attack surface management (CAASM) builds one inventory of everything an organisation owns by pulling asset data through APIs from tools it already runs: EDR, vulnerability scanners, cloud consoles, identity providers and the CMDB. It merges duplicates and shows coverage gaps, such as laptops with no EDR agent or servers the scanner never sees, so teams can fix them.
Gartner defines CAASM tools as those that “collect and consolidate information about internal and external assets through API integrations with existing IT, security, infrastructure, and cloud management tools” to find assets that are unknown, unmanaged or inadequately protected (Gartner Peer Insights). This guide explains how that works in practice, how CAASM differs from EASM, and which tools are worth a look in 2026.

How CAASM works
A CAASM tool does not scan your network the way a vulnerability scanner does. It connects to the systems that already know about your assets and merges what they say:
- Connect: read-only API connectors pull asset records from EDR, vulnerability scanners, cloud accounts (AWS, Azure, Google Cloud), identity providers, MDM, the CMDB, network gear and SaaS admin consoles.
- Correlate: records that describe the same device, user or cloud resource are merged into one entry, using hostnames, MAC and IP addresses, serial numbers and cloud IDs.
- Query: analysts ask questions across the merged inventory, such as “Windows servers with no EDR agent” or “cloud hosts with a public IP that the scanner has never seen”.
- Act: gaps open tickets, trigger alerts or run automated actions, and the inventory refreshes on a schedule so the answers stay current.
The value is in the gaps. Each tool you own sees part of the estate. CAASM shows where they disagree, which is usually where the risk is.
CAASM vs EASM vs a CMDB
| CMDB / IT asset management | EASM | CAASM | |
|---|---|---|---|
| Main question | What do we own, and who looks after it? | What can an attacker reach from the internet? | What do we have across every tool, and where are the control gaps? |
| How it finds assets | Manual entry, discovery agents, procurement records | Outside-in scanning of DNS, certificates, IP ranges and the web | API connectors to your existing security and IT tools |
| Sees unknown internet assets | Rarely | Yes, that is its purpose | Only if one of the connected tools already knows about them |
| Sees internal assets | Yes | No | Yes |
| Typical owner | IT operations | Security (threat and exposure teams) | Security operations and vulnerability management |
The short version: EASM finds what you did not know was exposed, CAASM reconciles what your own tools already know, and the CMDB is the system of record that both should feed. Mature teams run EASM and CAASM together, because each covers the other’s blind spot. Gartner still tracks CAASM as its own market, next to separate markets for EASM and exposure assessment platforms, and several vendors now sell CAASM and EASM as modules of one exposure management platform.
How to evaluate a CAASM tool
When we assess asset visibility for customers, these are the questions that separate tools in practice:
- Connector depth, not count. Ask whether the connectors you need read the fields you care about (agent health, last scan date, owner, tags), not just whether a logo appears on the integrations page.
- Correlation quality. Give the vendor a sample of your messy data during the trial. Duplicate and orphaned records are the main reason CAASM projects stall.
- Unmanaged assets. API-only tools cannot see devices that no tool manages. Check whether the product also does active or passive network discovery.
- Query and automation. Can analysts write their own queries, save them as policies and trigger tickets without vendor help?
- Pricing unit. Most vendors price per asset or per device, and almost all are quote-based. Count your assets before the first call.
Common pitfalls
- Treating the CAASM inventory as the CMDB. It is a security view; feed corrections back to the system of record.
- Connecting every tool on day one. Start with EDR, the vulnerability scanner, identity and your main cloud account, then add sources once correlation looks right.
- Ignoring the outside view. An internet-facing host that none of your tools know about will never appear in CAASM. That is the job of external attack surface management.
CAASM tools compared
We checked each vendor’s website on 6 October 2026. The CAASM market has consolidated fast: four of the products below changed owner in the last three years, which matters for roadmap and contract terms. Strengths and limits are from vendor documentation and our own experience of customer evaluations; we did not run scored tests.
| Tool | Owner (Oct 2026) | How it finds assets | Pricing (checked 6 Oct 2026) |
|---|---|---|---|
| Axonius | Independent | API integrations (1,400+ claimed), no agents | From $8.55 per asset at 15,000 to 24,999 assets; quote |
| JupiterOne | Independent | API integrations (200+), graph model | From $25,000 a year (priced on data points) |
| runZero | Dragos (acquisition announced 21 Sep 2026) | Active and passive network scanning plus integrations | Free up to 100 assets; platform from $5,000 |
| Rapid7 Surface Command | Rapid7 (includes former Noetic Cyber) | API integrations plus Rapid7 external scanning | Quote-based |
| Qualys CSAM | Qualys | Qualys agents and sensors plus external discovery | Quote-based; 30-day trial |
| Armis Centrix | ServiceNow (completed April 2026) | Agentless, network traffic plus integrations | Quote-based |
| Arctic Wolf Aurora Attack Surface Management | Arctic Wolf (bought Sevco Security, Feb 2026) | API integrations (100+) | Quote-based |
| Lansweeper | Independent | Network scanning and agents, IT asset management | Free up to 100 assets; Starter from $299 a month |
| Panaseer | Independent | Integrations, continuous controls monitoring | Quote-based |
Axonius
The best-known pure CAASM product. Axonius connects to existing tools through more than 1,400 integrations, correlates and deduplicates the results, and lets teams build queries and automated actions on top.
- Who it’s for: mid-sized and large organisations with many overlapping IT and security tools.
- Strengths: integration breadth, query and automation engine, add-ons for SaaS, identities and OT.
- Limitations: it sees only what connected tools see; passive OT and IoT discovery is a separate product.
- Pricing: device-based tiers, published as starting at $8.55 per asset for 15,000 to 24,999 assets (pricing).
JupiterOne
JupiterOne stores assets and their relationships in a graph and lets analysts query it with its J1QL language, which is useful for questions like “which internet-facing hosts can reach this database”.
- Who it’s for: cloud-heavy engineering organisations and teams doing M&A integration.
- Strengths: relationship graph, flexible queries, 200+ integrations.
- Limitations: integrations only, no scanning of its own; high entry price.
- Pricing: from $25,000 a year, priced on data points (pricing).
runZero
runZero discovers assets itself, using active and passive network scanning without agents or credentials, and adds integrations on top. That makes it strong on unmanaged devices that API-only tools miss. Dragos announced on 21 September 2026 that it is acquiring runZero.
- Who it’s for: organisations with many unmanaged, OT or IoT devices.
- Strengths: fingerprinting of unmanaged assets, free Community Edition, hosted external scanning.
- Limitations: its roadmap is now tied to Dragos, an industrial security company; check how that affects IT-focused buyers.
- Pricing: free up to 100 assets; platform from $5,000 (pricing).
Rapid7 Surface Command

Rapid7 bought Noetic Cyber, a CAASM vendor, in 2024 and combined it with Rapid7’s own external scanning in Surface Command, so one product covers both the inside and the outside view.
- Who it’s for: teams that want CAASM and EASM together, especially existing Rapid7 customers.
- Strengths: internal correlation and external discovery in one inventory, feeding Rapid7’s exposure tools.
- Limitations: best value inside Rapid7’s Exposure Command; no public price.
- Pricing: quote-based.
Qualys CyberSecurity Asset Management (CSAM)
Qualys CSAM builds its inventory mainly from Qualys’s own agents and passive sensors, adds external discovery, and syncs with the CMDB.
- Who it’s for: organisations already using Qualys.
- Strengths: agent data is detailed and current; end-of-life software tracking; CMDB sync.
- Limitations: depends on the Qualys platform; less useful if your main tools come from other vendors.
- Pricing: quote-based, 30-day trial.
- India relevance: Qualys lists an office in Pune.
Armis Centrix
Armis discovers assets agentlessly, including OT, IoT and medical devices, from network traffic and integrations. ServiceNow completed its acquisition of Armis in April 2026 and plans to integrate it into the ServiceNow platform.
- Who it’s for: hospitals, manufacturers and others with large numbers of unmanaged connected devices; ServiceNow customers.
- Strengths: device coverage beyond IT, non-intrusive discovery.
- Limitations: roadmap now tied to ServiceNow; no public pricing.
- Pricing: quote-based.
Arctic Wolf Aurora Attack Surface Management (formerly Sevco Security)
Arctic Wolf bought Sevco Security in February 2026; Sevco’s product is now Aurora Attack Surface Management, with 100+ IT and security integrations.
- Who it’s for: Arctic Wolf managed detection customers.
- Strengths: asset correlation from the former Sevco platform, combined with a managed security provider.
- Limitations: the standalone Sevco brand is gone; buyers outside Arctic Wolf should check whether it is sold separately.
- Pricing: quote-based.
Lansweeper
Lansweeper is an IT asset management tool with network scanning, agents and cloud discovery. It is not marketed as CAASM, but many smaller teams use it to answer the same questions.
- Who it’s for: IT teams that need a reliable inventory first and security views second.
- Strengths: published prices, free tier, IT, OT and cloud discovery.
- Limitations: fewer security integrations, and the Starter plan limits integrations to service desk tools.
- Pricing: free up to 100 assets; Starter from $299 a month for 2,000 assets, billed annually (pricing).
Panaseer
Panaseer positions itself as continuous controls monitoring built on a CAASM foundation: it ingests vulnerability, endpoint, directory, CMDB and HR data to measure whether security controls cover every asset.
- Who it’s for: large regulated organisations, especially banks, that report control coverage to boards and regulators.
- Strengths: control coverage metrics and reporting.
- Limitations: it measures and reports rather than discovers; integrations only.
- Pricing: quote-based.
Our product: TIKAJ external attack surface management
TIKAJ’s own platform, powered by Hunto.ai, is not a CAASM tool, so it is not in the list above. It covers the outside view that CAASM misses: it discovers internet-facing domains, subdomains and services from the outside, and watches for phishing sites and lookalike domains that impersonate you, with takedowns included. If your CAASM inventory looks complete but you have never checked what an attacker can see, see our external attack surface management page. Its limits: it does not inventory internal assets, and pricing is quote-based.
Products removed from this guide, and why
| Product on the old list | Why it is not listed |
|---|---|
| Wiz | Cloud security platform (CNAPP), now owned by Google; cloud-only, not CAASM |
| Orca Security | Agentless cloud security (CNAPP); cloud-only, not CAASM |
| CrowdStrike Falcon | Endpoint and exposure platform; its external discovery is covered in our ASM tools comparison |
| Tenable.io | Renamed; Tenable’s exposure products are covered in our ASM tools comparison |
| Hunto.ai | Our own product and an EASM platform, not CAASM; described separately above |
For external discovery tools, see our attack surface management tools comparison, and for the basics of the outside view, what is external attack surface management.
FAQ
What is CAASM?
CAASM, cyber asset attack surface management, is a way of building one complete asset inventory by pulling data through APIs from the IT and security tools you already run. It merges records for the same device, user or cloud resource, then shows gaps, such as assets missing an EDR agent or never scanned for vulnerabilities, so security teams can close them.
What is the difference between CAASM and EASM?
CAASM works from the inside: it collects asset data from your existing tools and reconciles it. EASM works from the outside: it scans the internet for assets that belong to you, including ones none of your tools know about. CAASM finds control gaps on known assets; EASM finds unknown internet-facing assets. Most mature programmes use both.
Is CAASM the same as a CMDB?
No. A CMDB is the IT system of record for what you own and who looks after it, usually maintained by IT operations. CAASM is a security view that checks what your tools report against each other and shows coverage gaps. A good CAASM tool reads from the CMDB and helps correct it, but it does not replace it.
How much does a CAASM tool cost?
Most CAASM tools are priced per asset or device and sold on annual contracts. Published prices we found on 6 October 2026: Axonius from $8.55 per asset at 15,000 to 24,999 assets, JupiterOne from $25,000 a year, runZero from $5,000 with a free tier up to 100 assets, and Lansweeper from $299 a month. Others are quote-based.
