# Datadog Cloud Security Management vs Lacework

| Attribute | Datadog Cloud Security Management | Lacework |
|---|---|---|
| **Vioscale score** | 50.4 (48% (low)) | 60.3 (27% (low)) |
| deployment.options | `{"cloud":true}` | - |
| description.long | Cloud security platform providing posture management, entitlement management, threat detection, workload protection, and compliance monitoring with integrated observability. | - |
| features.capabilities | `{"ciem":true,"cspm":true,"cwpp":true,"dspm":false,"kspm":true,"iac_scanning":false,"cloud_coverage":"Cloud accounts, hosts, containers, and Kubernetes deployments","open_core_scanner":false,"agentless_scanning":true,"runtime_protection":false,"compliance_frameworks":"Compliance violations and gaps detection"}` | - |
| integrations.count | 9 | - |
| integrations.list | `[{"name":"AWS"},{"name":"Azure"},{"name":"Google Cloud"},{"name":"Oracle Cloud"},{"name":"Kubernetes"},{"name":"Red Hat OpenShift"},{"name":"OpenAI"},{"name":"SAP"},{"name":"OpenTelemetry"}]` | - |
| platform.support | `{"web":true}` | - |
| pricing.model | commercial | commercial |
| reliability.status_page | yes | yes |
| security.disclosure_policy | yes | - |
| security.gdpr | yes | - |
| security.iso27001 | - | yes |
| security.soc2 | yes | yes |

## Capabilities (Cloud Security Software)

| Capability | Datadog Cloud Security Management | Lacework |
|---|:--:|:--:|
| **Posture** |  |  |
| CSPM (posture / misconfig) | ✓ | - |
| KSPM (Kubernetes posture) | ✓ | - |
| **Workload** |  |  |
| CWPP (workload protection) | ✓ | - |
| **Entitlements** |  |  |
| CIEM (entitlements) | ✓ | - |
| **Data** |  |  |
| DSPM (data posture) | ✗ | - |
| **Pipeline** |  |  |
| IaC / pipeline scanning | ✗ | - |
| **Architecture** |  |  |
| Agentless scanning | ✓ | - |
| **Runtime** |  |  |
| Runtime protection | ✗ | - |
| **Coverage** |  |  |
| Cloud coverage | Cloud accounts, hosts, containers, and Kubernetes deployments | - |
| **Compliance** |  |  |
| Compliance frameworks assessed | Compliance violations and gaps detection | - |
| **Licensing** |  |  |
| Open-core scanner available | ✗ | - |

*Source: Vioscale. Generated 2026-09-01T14:27:35.549Z. "-" = undocumented, not absent.*
