Try our new research platform with insights from 80,000+ expert users

Mend.io vs Prisma Cloud by Palo Alto Networks comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 5, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.1
Mend.io boosts ROI by automating vulnerability management, enabling faster delivery, cost savings, and improved security insights for organizations.
Sentiment score
7.3
Prisma Cloud enhances security and efficiency, reducing risks and response times, offering significant value despite initial costs.
Mend.io has provided a good return on investment by significantly reducing vulnerabilities.
It eliminates the need for additional hardware, making it a financially and technically sound investment.
Reputation and data security are the two most important things to a financial institution.
We may have prevented a security breach with remediation of the findings.
 

Customer Service

Sentiment score
6.6
Mend.io's customer service excels with quick, knowledgeable support, proactive staff, and effective communication, ideal for large organizations.
Sentiment score
7.1
Prisma Cloud support is praised for responsiveness, though some report slow responses and varying support quality across regions.
They prioritize providing the best experience to large organizations like ours, belonging to the Fortune 100.
I have noticed that the speed to respond has decreased over time.
They can respond with technical documentation or pass on the case to the next level because it requires the development of a new feature or changing a feature due to a bug.
Their technical support comes up with good solutions for every difficulty we face.
Their technical support comes up with great solutions.
 

Scalability Issues

Sentiment score
7.7
Mend.io effectively scales for large projects, integrates with workflows, and supports CI/CD, enhancing security and collaboration.
Sentiment score
7.8
Prisma Cloud scales well across environments, integrates seamlessly, and automates operations, though costs rise with increased licenses.
It's very scalable and very easy to use.
The scalability is also a 10 out of 10.
We are growing extremely quickly, and Prisma Cloud provides all the required services without any need for us to do anything to scale.
 

Stability Issues

Sentiment score
7.7
Mend.io offers reliable performance, seamless integration, quick issue resolution, and supports diverse needs with minimal downtime and intuitive interface.
Sentiment score
8.0
Prisma Cloud offers reliable performance and stability, effectively handling environments with rare interruptions and quickly resolved issues.
AI integration in code security tools like Mend.io is still in its early stages and relatively immature.
I would rate it a ten out of ten for stability.
Prisma Cloud is a stable platform.
The solution is stable and is capable of covering large enterprises.
 

Room For Improvement

Mend.io requires UI and reporting enhancements, wider language support, improved scanning, automation, and cost-effective pricing for better user experience.
Prisma Cloud needs improvements in documentation, UI, automation, integrations, pricing, and support, with challenges in compliance and cloud support.
The actual challenge is how easy it is to integrate it in the early phase of the software development life cycle.
I strongly recommend that they start working with AI for the reporting part.
The organization decided to consolidate tools and chose Snyk since it provides multiple functionalities in one solution.
From a developer's perspective, especially for organizations like banks developing their applications, ensuring API security before deploying them to the cloud is crucial.
Prisma Cloud is an excellent tool.
Even though documentation was available, it took a while for a new person to understand what integration meant, what will be achieved after the integration, or how the integration needed to be done on the Azure or AWS side.
 

Setup Cost

Mend.io offers a competitive yearly pricing model based on developer count, appealing for enterprises but pricey for startups.
Prisma Cloud is expensive but valued for comprehensive security, flexible licensing, and potential cost savings in multi-cloud environments.
The cost of Mend.io is competitive, being quite low compared to others.
The cost was not on the higher side.
That's why a lot of our clients are shifting from cloud-native to Prisma Cloud: because of its effectiveness and because it is budget-friendly as well.
The solution is very expensive.
 

Valuable Features

Mend.io streamlines vulnerability management with automation, integration, and comprehensive tools for tracking and securing open-source dependencies.
Prisma Cloud enhances security with dynamic identity creation, compliance management, and integration across AWS and CI/CD pipelines.
We find it 100% accurate in detecting vulnerabilities.
It handles Application Security, performing SCA SAST and container scanning.
The features I find most valuable in Mend.io are the ease of use; it is very easy to access and integrate.
What I like most about Prisma Cloud is its zero-day signatures, maximum security, minimal downtime, cloud visibility, control, and ease of deployment.
All five modules are taking a preventative approach to the security of the cloud environment, from the network to the cloud, posture management and workload protection.
We use it with multi-cloud environments, and there are five cloud providers supported, including Amazon Web Services, Oracle, GCP, Azure, and Alibaba.
 

Categories and Ranking

Mend.io
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
32
Ranking in other categories
Application Security Tools (17th), Software Composition Analysis (SCA) (7th), Static Code Analysis (4th), Software Supply Chain Security (1st)
Prisma Cloud by Palo Alto N...
Average Rating
8.4
Reviews Sentiment
7.3
Number of Reviews
111
Ranking in other categories
Web Application Firewall (WAF) (8th), Container Security (1st), Cloud Security Posture Management (CSPM) (2nd), Cloud-Native Application Protection Platforms (CNAPP) (2nd), Data Security Posture Management (DSPM) (2nd)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Mend.io is designed for Software Composition Analysis (SCA) and holds a mindshare of 7.3%, down 8.2% compared to last year.
Prisma Cloud by Palo Alto Networks, on the other hand, focuses on Cloud-Native Application Protection Platforms (CNAPP), holds 14.5% mindshare, down 20.8% since last year.
Software Composition Analysis (SCA) Market Share Distribution
ProductMarket Share (%)
Mend.io7.3%
Black Duck SCA15.7%
Snyk13.2%
Other63.8%
Software Composition Analysis (SCA)
Cloud-Native Application Protection Platforms (CNAPP) Market Share Distribution
ProductMarket Share (%)
Prisma Cloud by Palo Alto Networks14.5%
Wiz23.4%
Microsoft Defender for Cloud10.9%
Other51.2%
Cloud-Native Application Protection Platforms (CNAPP)
 

Featured Reviews

meetharoon - PeerSpot reviewer
Enables smooth management of vulnerabilities and promotes a shift towards a culture of security
We have witnessed Mend.io for its high stability, consistently living up to our expectations in terms of performance and reliability. Our developers have reported very few issues and almost minimal to zero downtime, which is a critical factor for our organization to rely on Mend SCA to secure our applications. We didn't experience any major issues in the stability of the product. This level of dependability is crucial for our hundreds of development teams that need to maintain continuous integration and deployment processes without interruptions. We realize the solution's architecture is designed to support a wide range of use cases, making it suitable for organizations of varying sizes and complexities. As a SaaS (Software as a Service) offering, Mend.io eliminates the need for physical server management, which further contributes to its stability. Users can access the platform without worrying about hardware failures or maintenance issues that can affect on-premises solutions. Moreover, Mend.io's integration capabilities with existing workflows—including IDEs, repositories, and CI/CD pipelines—enhance its stability by providing a seamless user experience. This integration allows teams to incorporate security scanning into their development processes without significant disruptions, which is often a challenge with less stable solutions. Feedback from our developers and architects highlights the tool's effectiveness in reducing open-source software vulnerabilities while maintaining a streamlined development lifecycle. Our organization have experienced improved code quality and faster incident response times as a result of using Mend.io. The platform's intuitive dashboard and management views are also praised by our developers for their usability, contributing to a positive user experience. In short, Mend.io stands out as a dependable and reliable solution in the realm of software composition analysis. Its high stability, combined with robust integration capabilities and user-friendly features, makes it an excellent choice for organizations seeking to enhance their security posture while minimizing operational disruptions.
Mohammad Qaw - PeerSpot reviewer
It gives you one console to see all of your assets, review their configurations, and build your processes
Most customers use Prisma Cloud for visibility and compliance. Prisma has so many features, but many organizations do not use them. They primarily use the visibility part to connect all their cloud accounts and hosts for visibility to see if they are missing any security controls or if they have any misconfigurations. You can connect it to cloud environments such as Azure, AWS, Oracle Cloud, Alibaba, etc., or to an on-prem data center. Prisma Cloud gives you so many options to automate processes related to your daily operations. When it comes to cybersecurity, you can automate things with their existing APIs. They also have out-of-the-box integrations with many solutions. I have not seen any limitations. Everything is customizable. You can do whatever you want, defining the reporting and custom use cases. They recently updated the UI, so it's much better than before.
report
Use our free recommendation engine to learn which Software Composition Analysis (SCA) solutions are best for your needs.
872,655 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
17%
Computer Software Company
14%
Manufacturing Company
11%
Insurance Company
5%
Computer Software Company
15%
Financial Services Firm
14%
Manufacturing Company
10%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise3
Large Enterprise18
By reviewers
Company SizeCount
Small Business37
Midsize Enterprise20
Large Enterprise55
 

Questions from the Community

How does WhiteSource compare with SonarQube?
Red Hat Ceph does well in simplifying storage integration by replacing the need for numerous storage solutions. This solution allows for multiple copies of replicated and coded pools to be kept, ea...
How does WhiteSource compare with Black Duck?
We researched Black Duck but ultimately chose WhiteSource when looking for an application security tool. WhiteSource is a software solution that enables agile open source security and license compl...
What do you like most about Mend.io?
The best feature is that the Mend R&D team does their due diligence for all the vulnerabilities. In case they observe any important or critical vulnerabilities, such as the Log4j-related vulner...
What is your primary use case for Prisma Cloud by Palo Alto Networks?
Prisma Cloud helps support DevSecOps methodologies, making those responsibilities easier to manage.
What Cloud-Native Application Protection Platform do you recommend?
We like Prisma Cloud by Palo Alto Networks, since it offers us incredible visibility into our entire cloud system. We are able to easily see where our container vulnerabilities lie and and where cl...
What do you think of Aqua Security vs Prisma Cloud?
Aqua Security is easy to use and very manageable. Its main focus is on Kubernetes and Docker. Security is a very valuable feature and their speed of integration is very good. The initial setup was ...
 

Also Known As

WhiteSource, Mend SCA, Mend.io Supply Chain Defender, Mend SAST
Prisma Public Cloud, RedLock Cloud 360, RedLock, Twistlock, Aporeto
 

Overview

 

Sample Customers

Microsoft, Autodesk, NCR, Target, IBM, vodafone, Siemens, GE digital, KPMG, LivePerson, Jack Henry and Associates
Amgen, Genpact, Western Asset, Zipongo, Proofpoint, NerdWallet, Axfood, 21st Century Fox, Veeva Systems, Reinsurance Group of America
Find out what your peers are saying about Mend.io vs. Prisma Cloud by Palo Alto Networks and other solutions. Updated: February 2025.
872,655 professionals have used our research since 2012.