Three assessment types over the same review areas. The scan is automated and broad, the pentest is scoped and manual, and the maturity assessment adds the operation around the estate. Operational resilience is out of scope for the scoped review, which is a boundary worth knowing before you buy rather than after.
ScanPentestMaturity
Resources
Workloads: instances, functions, containers, hardening Scan covered Pentest covered Maturity covered
Storage: buckets, volumes, secrets, policy misconfiguration Scan covered Pentest covered Maturity covered
Network: firewalls, load balancers, exposure and remote access Scan covered Pentest covered Maturity covered
Identity and access
Access rules, credential management, authentication Scan covered Pentest covered Maturity covered
Privileged identities, least-privilege violations, overprivileged accounts Scan not covered Pentest covered Maturity covered
Role design and privileged account management Scan not covered Pentest covered Maturity covered
Operational resilience
Native logging, alerting and response capability Scan not covered Pentest not covered Maturity covered
Backups, resilience features, native security tooling Scan not covered Pentest not covered Maturity covered
Integration: hybrid directory, external identities, third-party apps, devices Scan not covered Pentest not covered Maturity covered
Processes and people
Detection coverage and response process Scan not covered Pentest not covered Maturity covered
Change and lifecycle management, patching, periodic review Scan not covered Pentest not covered Maturity covered
A full-scope review covers all of these. It is not a claim that these are all of cloud security.