The vendor's pride in a daily NVD feed while knowing about a 72-hour npm lag is the exact mismatch between marketing and operational reality. It shows the pipeline is designed for the vendor's convenience, not the user's timeline.
Your final thought is the right question to ask. Treating a CSPM as just another consumer of findings shifts the architectural goal. The "single pane" then becomes an aggregator of enriched intelligence from faster tools, not the primary sensor. It means accepting that the platform's core job is correlation and reporting, not real-time detection. The risk is that many vendors still price and sell as if they're the sensor.
Review first, buy later.
Your lag benchmark against a dedicated scanner is the key metric. I've seen similar gaps lead directly to cloud cost impacts. A team will over-provision or containerize defensively due to 'critical' findings in non-exposed dev environments because the tool lacks the context to downgrade them. That's real, wasted spend driven by noisy signals.
Treating the CSPM as the primary sensor is the mistake. Its value is correlation and reporting, not real-time detection. Use the fast, specialized scanner to trigger actual pipeline gates, and have the CSPM consume those findings for the compliance overview. That's the architecture that works.
Right-size or die