Assessments

Full-Stack
Assessments

Every assessment Palo Alto Networks offers across the platform — self-service tools, seller and SE-run evaluations, and Unit 42 consulting engagements. Current as of August 19, 2026. Lead with an assessment to replace assumptions with evidence and open the platform conversation.

Seller Guidance

How to Use This Catalog

Three delivery models, three motions. Self-service tools (SLR, On-Demand BPA, SecOps Readiness Report) are frictionless door-openers. Seller/SE-run assessments (BPA walkthrough, SPA journeys, CLARA, Cloud Health Check) create structured discovery meetings. Unit 42 engagements are paid services-attach that anchor platformization deals. Free assessments remove the budget objection — always have one queued for every account. See also the dedicated CLARA deep-dive and Unit 42 Services pages.

Pillar 1

Network Security / Strata

The classic firewall-attached assessments. SLR and BPA remain the highest-volume door-openers in the portfolio.

FreeSelf-Service
Security Lifecycle Review (SLR)
Cloud-based hub app reporting on applications in use (including SaaS), websites accessed, file types shared, vulnerabilities, and malware/C2 infections — benchmarked against industry peers. Free with a Strata Logging Service subscription; usable in self-serve mode, or PANW runs it in your network as the SLR Cyberthreat Assessment.
SLR Docs Cyberthreat Assessment Page
FreeSE / Partner Run
Best Practice Assessment (BPA / BPA+)
200+ security checks with pass/fail scoring, Security Policy Adoption Heatmaps, and industry benchmarks for NGFW and Panorama. A systems engineer or partner SE runs it and walks through findings — or run it yourself. BPA+ adds guided remediation.
Official BPA Page
FreeSelf-Service
On-Demand BPA (AIOps for NGFW / SCM)
The current successor to legacy portal BPA (TSF uploads to the old portal were disabled July 2023). Upload a tech-support file (PAN-OS 9.1+) in Strata Cloud Manager → Insights → Posture → On Demand BPA. Checks cover threat prevention, attack-surface reduction, visibility, and CIS Critical Security Controls. All AIOps BPA capabilities except proactive BPA are free.
On-Demand BPA Docs
In-ProductEssentials / Pro Tiers
Zero Trust Posture Center (SCM)
Quantifies posture risk and Zero Trust alignment from NGFW and Prisma Access config data — % of passed best-practice checks vs. industry average across five Zero Trust pillars, plus Policy Analyzer/Optimizer and Config Cleanup. Best-practice checks are in the free Essentials tier; Current Impact & Recommendations requires SCM Pro.
Posture Center Docs
ComplimentaryExpert-Led
CLARA — Cloud & AI Risk Assessment
NetSec-owned complimentary suite of three diagnostics: Cloud Network Risk Assessment, Cloud Firewall Benchmarking (AWS/Azure breach-and-attack simulation), and AI Risk Assessment with red teaming. Pick one to three — no cost, no obligation. Full seller playbook on the CLARA page.
Official CLARA Page
Legacy
Prevention Posture Assessment (PPA)
Questionnaire-based prevention-gap assessment with remediation suggestions, historically generated by SEs and partners via the NextWave Portal. Survives only in older docs and a partner KB — no current marketing page. Its role is absorbed by SPA and BPA. Do not lead with PPA in new opportunities.
Legacy TechDocs Reference

Cross-Portfolio

Security Posture Assessment (SPA) — 10 Journeys

One engine, ten selectable journeys. SPA analyzes the existing environment and builds a roadmap autonomously in minutes; most journeys run 60–90 minutes. This is the current umbrella assessment spanning network, SASE, endpoint, cloud, SOC, OT, and 5G. Official SPA page.

Network Security Refresh / Improvement — transformation strategy, threat prevention, web filtering, app security, data protection, device security, user control. 60–90 min.

SASE / ZTNA 2.0 Deployments — ZTNA 2.0, ADEM, SWG, CASB, DLP, SD-WAN, IoT Security. 60–90 min.

SOC Modernization — automation & orchestration, collaboration, case management, threat intelligence. 60–90 min.

Cloud and Cloud Code Security — CSPM, identity security, code security, workload protection, cloud network security. 60–90 min.

Endpoint Security Controls — asset management, endpoint protection, detection & response, ransomware protection, data protection. 60–90 min.

OT Security — risk management, physical security, ICS architecture, OT network/endpoint security, continuous monitoring, supply chain. 90 min.

Enterprise Cybersecurity (In-Depth) — network, endpoint, cloud & SaaS, SOC, and OT in one sitting. 4–5 hours.

Enterprise Cybersecurity (Concise) — cyber strategy, network, cloud & SaaS, endpoint, SecOps. 60–90 min.

5G Capability and Readiness (Telco) — 5G Core & Edge, roaming, RAN, Gi/N6; DoS & recon, segmentation, decryption, data protection. 4 hours.

Remaining journeys — the SPA page lists ten selectable journeys total; confirm the current menu with your Palo team when scoping.

Pillar 2

Prisma SASE

Know the gap: there is no standalone published SASE maturity, VPN-replacement, branch-transformation, or enterprise-browser assessment. The SASE evaluation motion runs through the SPA SASE/ZTNA 2.0 journey above, and SASE professional services cover only Design, QuickStart, and Operations. AI Access Security has in-product GenAI usage reports rather than a named assessment. Use this to your advantage — a CLARA or SPA-led discovery is the differentiated play.

SPA Journey
SPA — SASE / ZTNA 2.0 Journey
The primary published SASE/ZTNA maturity assessment: ZTNA 2.0, ADEM, SWG, CASB, DLP, SD-WAN, and IoT Security posture in 60–90 minutes with an autonomous roadmap.
SPA Page
In-Product
AI Access Security Reports
Not a named assessment, but AI Access Security generates in-product GenAI usage and risk reports that serve the same discovery purpose in SASE accounts adopting GenAI.
Report Docs

Pillar 3

Cortex / SecOps

SecOps assessments run from a free self-service questionnaire up to full Unit 42 SOC engagements powered by Xpanse and XDR telemetry.

Self-Service
SecOps Readiness Report
Interactive questionnaire that scores the current state of security operations, flags improvement areas, and generates tailored recommendations. The zero-friction SecOps door-opener.
Readiness Report
ToolSeller-Assisted
XSIAM ROI Calculator & Custom Value Assessment
Personalized ROI assessment built on data from hundreds of real XSIAM deployments — savings vs. current investments and value delivered to the SOC. The page also offers a Cortex XSIAM custom value assessment engagement.
ROI Calculator
Unit 42Paid
Unit 42 SOC Assessment
Comprehensive people/process/technology SOC evaluation: visibility and data unification, AI-driven detection and automation roadmaps, threat-actor context, attack surface, and a strategic action plan — built on lessons from the PANW SOC.
SOC Assessment
Unit 42Fixed Price
Unit 42 Attack Surface Assessment
Powered by Cortex Xpanse and delivered by Unit 42 experts — unknown/exposed internet-facing assets, vulnerabilities, gaps, allowed services, and network topologies. No agents, no aggressive scanning, fixed pricing, and 30 days of Xpanse console access included.
Attack Surface Assessment
In-Product
Attack Surface Testing (Xpanse)
In-product Xpanse capability, not a packaged engagement: daily scans that run benign exploits against exposed owned assets to confirm vulnerabilities and prioritize precisely. Pairs with the Unit 42 ASA for continuous validation.
AST Datasheet
SPA Journey
SPA — SOC Modernization Journey
Automation & orchestration, collaboration, case management, and threat intelligence maturity in 60–90 minutes. Good precursor to a paid Unit 42 SOC Assessment.
SPA Page

Pillar 4

Cloud Security

Note: the free cloud assessment assets remain Prisma Cloud-branded even after the Cortex Cloud transition — the Cortex Cloud product pages name no assessment of their own.

FreeExpert-Led
Free Cloud Security Health Check
Agentless Prisma Cloud connection scans cloud environments for misconfigurations, vulnerabilities, critical risks, and hidden attack paths. Report in 24–48 hours with a 1:1 expert review, including 10 days of Prisma Cloud.
Health Check Page
FreeSeller-Led
Free Cloud Security Risk Assessment
High-level cloud posture with a 10-day trial: top open/urgent alerts, top policy violations, violations by asset, plus incidents, misconfigurations, exposures, identity, and data findings. Includes onboarding help and a 1-hour solution-architect walkthrough.
Risk Assessment Page
No CostWorkshop
Prisma Cloud Maturity Assessment
Single technical session (up to 4 hours) working through predefined questions on the customer environment vs. Prisma Cloud and cybersecurity best practices. Ideal for existing cloud customers pre-renewal.
Maturity Assessment Datasheet
Unit 42Paid
Unit 42 Cloud Security Assessment
Technical analysis of scoped cloud environments correlated with Unit 42 threat intel — architecture deep dives, threat-led workshops, current-vs-target capability mapping, and a code-to-cloud roadmap across multi-CSP estates.
Cloud Security Assessment
ComplimentaryCLARA
CLARA — Cloud Diagnostics
Cloud Network Risk Assessment: network risk and exposure across public cloud and AI ecosystems with a detailed app and network risk report. Cloud Firewall Benchmarking: automated breach-and-attack simulation exposing gaps in CSP-native firewalls with a security validation report.
CLARA Page
SPA Journey
SPA — Cloud & Cloud Code Security Journey
CSPM, identity security, code security, workload protection, and cloud network security posture in 60–90 minutes. Container/K8s coverage rolls up under workload protection here and CLARA asset discovery — there is no separate K8s assessment.
SPA Page

Pillar 5

AI Security

The fastest-growing assessment family — including the 2026 Frontier AI Defense offers with six months of complimentary Cortex XDR, Xpanse, and Koi attached.

ComplimentaryCLARA
CLARA — AI Risk Assessment
PANW's main free GenAI risk assessment: scans AI ecosystem exposures and vulnerability to AI-specific attacks like prompt injection, scans models/datasets for malicious scripts using automated "white hat" AI agents, and outputs an AI Red Teaming report.
CLARA Page
Product Capability
Prisma AIRS AI Red Teaming
Continuous automated red teaming of AI endpoints and systems — profiles endpoints into a risk-assessment profile and attacks with 50+ techniques mapped to the OWASP Top 10 for LLMs and NIST AI RMF.
AI Red Teaming Page
Unit 42Paid
Unit 42 AI Security Assessment
Consultant-led evaluation of employee AI usage and shadow AI, AI initiatives (data/models/apps), AI dev infrastructure, runtime security, and governance vs. Unit 42 best practices — including model/data lineage and prompt-injection exposure. First item in the current Unit 42 services menu.
AI Security Assessment
New 2026Unit 42
Unit 42 External AI Hyperattack Assessment
Part of Frontier AI Defense with Armadin's swarm of autonomous AI attack agents: passive discovery plus active attacks — credential stuffing, cloud infrastructure probing, exploitation with 50,000+ templates — validating real attack paths and full attack chains across internet-facing assets, cloud resources, and secrets.
Hyperattack Datasheet
New 2026Unit 42
Frontier AI Defense — Three Offers
Frontier AI Exposure Analysis (vulnerabilities and posture gaps most likely exploited across infra, apps, code, identity, cloud), Autonomous Security Blueprint (capability benchmarking across attack surface, identity, supply chain, zero trust containment, detection/response), and Agentic Defense Transformation. Offers bundle six months of complimentary Cortex XDR, Xpanse, and Koi (exclusions apply).
Frontier AI Defense Announcement
Partner-DeliveredIBM
Rapid AI Security Assessment (IBM + PANW)
Two-week expert-led engagement by IBM Consulting with Prisma AIRS: AI models, agents, apps, shadow AI and policy violations, misconfigurations and compliance gaps benchmarked against NIST AI RMF, the EU AI Act, and ISO/IEC 42001.
IBM Announcement

Pillar 6

Unit 42 Proactive Assessments

The complete current "Assess and Test Your Security Controls" menu, verified against the live Unit 42 services navigation. All are consultant-delivered paid engagements (pricing not published). Pair with the Unit 42 Services attach playbook.

Compromise Assessment
"Am I compromised?" — unauthorized access, exfiltration, lateral movement, persistence, risky configs, unusual user activity. Uses Cortex XDR (~90% endpoint coverage required). Deliverables: exec summary, technical report, IT-hygiene findings, prioritized recommendations.
Official Page
Ransomware Readiness Assessment
Proprietary readiness framework covering operational capabilities and technical controls; tiered delivery — Tier 1: tabletop + findings report + retainer with 250 IR credits; Tier 2 adds a ransomware compromise assessment via Cortex XDR telemetry and an in-depth technical report.
Official Page
Cyber Risk Assessment
Program strengths and weaknesses — current vs. target control state via documentation review, interviews, and focused technical testing, with 1/3/5-year roadmaps.
Official Page
Breach Readiness Review
IR plans, playbooks, and governing policies tested against practice via stakeholder interviews; capabilities benchmarked vs. NIST and CISA best practices with a Findings & Recommendations report.
Official Page
BEC Readiness Assessment
Anti-BEC controls and operational capabilities: Security Configuration Assessment, BEC IR tabletop, Email Compromise Assessment, Email Attack Readiness Benchmark, tailored BEC IR playbook, Email Attack Purple Team Exercise, awareness training, and a retainer with 250 IR credits.
Official Page
Supply Chain Risk Assessment
Supply chain risk strategy, capabilities, and controls — vendor vulnerabilities, attack surface exposure, and exploitable weaknesses using a vendor due-diligence framework plus Cortex Xpanse data. Often missing from older catalogs; it is in the current menu.
Official Page
M&A Cyber Due Diligence
Target's security program, asset inventory and attack surface, IT hygiene, and exploitable weaknesses via XDR and Xpanse. Deliverables include Cyber Due Diligence Report, Compromise Assessment Report, Attack Surface Mapping, Pen Test Report, and an Aggregated Target Briefing.
Official Page
Penetration Testing
Pressure-tests technical controls and network defenses with real threat-actor TTPs. Deliverables: exec summary, technical report, prioritized recommendations, remediation steps.
Official Page
Purple Team Exercises
Red/Blue/Purple exercises simulating real Unit 42 case scenarios — network monitoring, IR processes, email security, awareness, alerting/detection, and control coverage, with phishing simulation, pen testing, and custom payloads.
Official Page
Tabletop Exercises
Customized simulated incident testing executive, operational, and technical decision-making, IR plan performance, decision speed, and ransom-payment circumstances. Remote or in person.
Official Page
Zero Trust Advisory
Under Unit 42 "Transform": current-state architecture, policies, and controls; workshop benchmarking of zero-trust capabilities and gaps; business-context prioritization with a Discover/Evaluate/Align/Accelerate report.
Official Page
IR Plan Development & Review
Closest current "incident readiness" offering alongside Breach Readiness Review: reviews IR plans, playbooks, and policies; interviews stakeholders; develops or enhances plans, playbooks, procedures, and workflows with an annual refresh. (Note: AI Security, Attack Surface, Cloud Security, and SOC Assessments are listed in their pillar sections above; the Unit 42 Retainer, Security Program Design, and Virtual CISO round out the menu but are not assessments.)
Official Page

Field Notes

Notable Changes 2025–2026

Prisma Cloud → Cortex Cloud: Cortex Cloud is the next version of Prisma Cloud merged with Cortex CDR (announced Feb 2025), but the free cloud assessments are still Prisma Cloud-branded. Don't let branding confusion stall a Health Check.

BPA lives in AIOps/SCM now: legacy portal TSF uploads were disabled July 2023; run On-Demand BPA from Strata Cloud Manager instead. All AIOps BPA capabilities except proactive BPA are free.

PPA is legacy: no current marketing page; absorbed by SPA and BPA.

New AI-era Unit 42 offers (2026): Frontier AI Defense (three consultant-delivered components with six months of complimentary XDR/Xpanse/Koi) plus the External AI Hyperattack Assessment powered by Armadin autonomous attack agents.

CLARA is the free cloud+AI motion in Network Security, bundling cloud network risk, cloud firewall benchmarking, and AI risk/red teaming diagnostics.

Menu vs. URL naming quirks: Purple Team Exercises → /purple-teaming; Tabletop Exercises → /tabletop-exercise; BEC Readiness → /business-email-compromise; M&A Cyber Due Diligence → /mergers-acquisitions-cyber-due-diligence.

Insider Threat Services appears de-emphasized — the datasheet exists but it is absent from the current Unit 42 services menu.

SASE gap: no dedicated SASE maturity, VPN-replacement, branch-transformation, or enterprise-browser assessment exists — run the SPA SASE/ZTNA 2.0 journey.