NetSec Platform: Cloud-Delivered Security Services (CDSS)
Cloud-Delivered Security Services (CDSS) is an umbrella term for subscription-based security capabilities leveraged across the Palo Alto network security platform.
CDSS provide the inspection and threat detection logic used by the enforcement fabric as a shared inspection layer. The same threat intelligence, detection models, and inspection logic apply consistently regardless of where enforcement is happening. This means that if a user is connecting via Prisma Access, they get the same protection as traffic passing through a data centre NGFW.
CDSS policies and insights are managed through Strata Cloud Manager (SCM), which provides the control plane for both CDSS and the enforcement fabric it runs on.
Platform Security Capabilities
Traditional security models often rely on point-in-time decisions. Cloud-Delivered Security Services evaluate traffic throughout the session, with updated threat intelligence and detection logic applied in real time. This means trust is continuously evaluated and not implicitly inherited.
The following security capabilities are delivered through the CDSS model:
- Advanced Threat Prevention: intrusion prevention and exploit detection
- Advanced WildFire: malware analysis and sandboxing
- Advanced URL Filtering & Advanced DNS Security: web and DNS-layer protection
- Device / IoT Security: discovery and risk classification for devices
- SaaS Security / CASB: SaaS application classification and control
- AI Access Security: AI application classification and control
- Enterprise DLP: content inspection and data loss prevention
Although it's easy to focus on the headline feature, the shared capability layer is equally as important. Overall visibility and intelligence is strengthened by context from other capabilities.

CDSS isn't tied to a single enforcement point, it's consumed wherever traffic needs inspection:
- Physical, Virtual, and Cloud NGFW all apply CDSS inspection
- Prisma Access consumes CDSS as its inspection layer
- Prisma Browser embeds CDSS directly within the browser workflow, applying inspection at the application layer without requiring network-level decryption
Regardless of where CDSS is consumed, content updates, threat intelligence, and detection models are managed centrally by Palo Alto Networks. Administrators configure policy and subscriptions.
Platform Security Architecture
The need for AI-driven inspection is now foundational to effective security operations. Behavioural and contextual analysis is required to identify threats that evade traditional signature and port-based inspection models.
Precision AI is Palo Alto's overarching ML/AI brand, not a separate product or feature that is enabled independently. Cloud-Delivered Security Services are powered by Precision AI under the hood.
Precision AI describes how inspection, classification, and threat detection are performed using Machine Learning and Deep Learning models, trained on large-scale threat intelligence.
Anonymised security telemetry is ingested to refine threat detection algorithms, such as file hashes, sandbox logs, and malicious URL patterns. This real-world input creates a feedback loop that strengthens detection for every other CDSS consumer globally.
Precision AI is designed to operate within a Single Pass Parallel Processing (SP3) architecture. At a high level this means traffic is decrypted once, inspected once, and evaluated against multiple security controls in parallel.
With traditional security tooling, teams are forced to compromise on security services by applying controls selectively for performance and licensing. Separate inspection engines are chained together which directly impacts quality, latency, and operational complexity.
The single-pass inspection is one of the key reasons a platform approach scales. Additional capabilities and policies can be added iteratively as new requirements emerge. They hook directly into the existing security inspection without changing traffic flow or design, and the SP3 architecture ensures there is no additional performance overhead.

Putting all of this together, CDSS provides an important shared detection, inspection, and prevention layer within the platform, that enables the following outcomes:
- Consistent security controls across locations
- Improved visibility and higher confidence in security posture
- Faster response to emerging threats
- Reduced policy and operational drift
- Lower operational overhead