One use case was for compliance. The second one was for workload protection, and the third one was for threat hunting in the cloud.
VP Sales, MSSP and MDR at Torq
Makes the findings actionable and helps with compliance and threat hunting
Pros and Cons
- "The most valuable feature is the ability to work with the APIs to integrate into our own backend systems."
- "The reporting has a lot of opportunities to continuously improve so that we can continue to show value."
What is our primary use case?
How has it helped my organization?
We are able to meet compliance very easily, and we are able to feel a lot more comfortable with the fact that when we have developers deploying things in the cloud, the right guardrails are in place.
CloudGuard CNAPP's Cloud Security Posture Management capabilities are top-notch. We use it for misconfiguration and compliance reporting. I would rate it an eight out of ten for that. It is quite good.
We use CloudGuard CNAPP's Workload Protection capabilities. The security that it provides is very good. We like it because we are able to do it in both runtime and with Kubernetes Guardrails.
Threat intelligence is another piece that we use, and it is awesome because it lets us do a lot of threat hunting that we were not able to do before, especially in AWS.
What is most valuable?
The most valuable feature is the ability to work with the APIs to integrate into our own backend systems.
The threat intelligence is quite unique because we could not find another vendor that had the ability to make all the findings actionable. They have this thing called Event Risk management, and it consolidates things down to make it easy for us to take action on it.
What needs improvement?
The reporting has a lot of opportunities to continuously improve so that we can continue to show value.
I would love to see more ability to automate and integrate into even more systems for automatic remediation.
Buyer's Guide
Check Point CloudGuard CNAPP
March 2025

Learn what your peers think about Check Point CloudGuard CNAPP. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
841,152 professionals have used our research since 2012.
For how long have I used the solution?
We have been using Check Point CloudGuard CNAPP for three and a half years.
What do I think about the stability of the solution?
It is very rare to have an outage.
What do I think about the scalability of the solution?
It scaled up for us for hundreds of accounts.
How are customer service and support?
They are pretty good, but I wish they had people who are a little bit more knowledgeable at the first level. I would rate them a seven out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We used Palo Alto's Prisma Cloud. We switched because it did not have the feature sets we were looking for. The price was not very flexible, and we did not get the type of support we needed. It was not like the support that we get from Check Point as our partner.
How was the initial setup?
Its deployment is very straightforward.
What was our ROI?
We definitely got an ROI. I do not have to put as many people as I did before with Prisma Cloud. I need two full-time employees less than Prisma Cloud to work on it.
Which other solutions did I evaluate?
We looked at Wiz, and we looked at Orca. Prisma was our incumbent, but ultimately, we picked Check Point based on the outcomes we were able to get in our proof of concept, and we felt that the support was much better.
What other advice do I have?
I would rate Check Point CloudGuard CNAPP a nine out of ten. It is a pretty awesome product, but there is always room for improvement. I would have rated everything else we tested a six out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner

Network Engineer at LTTS
Secure, gives us complete visibility of cloud traffic, and the support is excellent
Pros and Cons
- "We can monitor each activity from our mobile devices, so there is complete visibility of our cloud traffic flows, with threat intelligence provided by Check Point."
- "In Dome9, there should be a policy validation option where we can validate the policy before we push it into production."
What is our primary use case?
CheckPoint Dome9 is a cloud security management solution for our Azure cloud environment, and we have Azure for our cloud services. With this solution, we manage our network security policy management and automation for our cloud environment across providers, accounts, and regions.
Dome9 provides us policy compliance based on our requirements. If we request SOX or HIPPA, based on that we will enable the policy and we will get the reports as well.
We also create users and set policies and we can monitor the logs.
How has it helped my organization?
Dome9 is a very good product for us as we are using a hybrid solution. We have some of the services on-premises and some of the services on the cloud. With Dome9, we very well manage our security policies and also set the compliance policies based on requirements.
Now, we can also support the asset management of our cloud resources, posture management, and many more.
What is most valuable?
IAM is a very good and unique feature of Dome9. IAM gives us complete control of our cloud environment. For example, if someone tries to bypass the policy and attempts to configure or create some users, then it will not allow them to do so. Also, it sends a notification to the concerned person.
We can monitor each activity from our mobile devices, so there is complete visibility of our cloud traffic flows, with threat intelligence provided by Check Point. The IAM provides us complete safety and security.
What needs improvement?
In Dome9, there should be a policy validation option where we can validate the policy before we push it into production. This option is very important, as we are working in a critical and complex environment. This option would give us more confidence in our activities or policy pushing.
We could see the option is available for on-premises devices.
Automatic remediation requires read/write access.
Otherwise, overall this product is very good for our cloud environment, and we are satisfied with this.
For how long have I used the solution?
We have been using Dome9 for the past six months.
What do I think about the stability of the solution?
It's a very stable product.
What do I think about the scalability of the solution?
Dome9 is very good in terms of scalability.
How are customer service and technical support?
The technical support is excellent.
Which solution did I use previously and why did I switch?
We did not use another solution prior to Dome9.
How was the initial setup?
The initial setup is straightforward.
What about the implementation team?
We implemented using a vendor team.
Which other solutions did I evaluate?
We did not evaluate other options.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Check Point CloudGuard CNAPP
March 2025

Learn what your peers think about Check Point CloudGuard CNAPP. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
841,152 professionals have used our research since 2012.
Geography and History Teacher at a comms service provider with 10,001+ employees
Enables us to detect incidents and vulnerabilities in our code with one click
Pros and Cons
- "CloudGuard's best feature is real-time detection. We can detect incidents and vulnerabilities in our code with one click."
- "I would like CloudGuard's pricing to be cheaper, but I think that's impossible. The pricing is the only thing I think they can improve."
What is our primary use case?
We use CloudGuard to secure apps we develop in the cloud.
How has it helped my organization?
Before Check Point, we didn't have a cloud solution. Having a CNAPP solution gives us confidence that our cloud apps are secure. From day one, we saw that the product was working and detecting issues in real-time.
What is most valuable?
CloudGuard's best feature is real-time detection. We can detect incidents and vulnerabilities in our code with one click. I was amazed by CloudGuard's VM protection. It's easy to deploy, and I feel safe. I'm absolutely satisfied with it.
For how long have I used the solution?
I have used CloudGuard for about one year.
What do I think about the stability of the solution?
CloudGuard is stable. I haven't had any issues.
What do I think about the scalability of the solution?
CloudGuard is scalable. We've had no problems implementing it for our cloud infrastructure.
How are customer service and support?
I rate Check Point support 10 out of 10. Check Point's technical support is excellent.
How would you rate customer service and support?
Positive
How was the initial setup?
The implementation was fast and easy, and Check Point's professional services are highly effective and professional. We deployed it with an in-house team of two to three people.
What was our ROI?
The cost-effectiveness of this investment was high. The money was well spent because I solved my security problems.
What's my experience with pricing, setup cost, and licensing?
I would like CloudGuard's pricing to be cheaper, but I think that's impossible. The pricing is the only thing I think they can improve.
What other advice do I have?
I rate Check Point CloudGuard CNAPP nine out of 10. I recommend that complex corporations test CloudGuard before implementing it. When you see the solution in action, you can witness its security and power.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Last updated: Jun 10, 2024
Flag as inappropriateIT Security Specialist at Unipol Assicurazioni S.p.A.
Good visibility and management with helpful visibility into permissions
Pros and Cons
- "The various CNAPP modules have granted more visibility of our cloud applications to our system engineers and developers."
- "The costs are really high if you want the entire capabilities of the platform."
What is our primary use case?
We have used CNAPP on our OpenShift test cluster but are planning to deploy it in our production clusters. We used CNAPP to enhance the visibility of our cloud-deployed applications. It offers various modules to do so. For example, the Posture Management module shows you exposed secrets and security misconfigurations and also gives you hints and ready-to-use JSON configuration files to fix them.
Cloud Infrastructure Entitlement Management (CIEM) gives you visibility and management automation of identities, roles, entitlements, and privileges in your cloud environments. This helps you find and fix identity- and role-related security holes by constructing a complex privileges graph, which shows you granted permissions and enforced ones, suggesting you enforce the stricter and more secure enforced ones over the ones you granted.
How has it helped my organization?
The various CNAPP modules have granted more visibility of our cloud applications to our system engineers and developers. Doing so helps our transition to the cloud by making the management and administrative tasks of our cloud and system engineers easier, as well as suggesting and helping to prioritize patching and updating.
What is most valuable?
The most valuable features include the Cloud Infrastructure Entitlement Management (CIEM) module, Cloud Security Posture Management (CSPM), and Cloud Workload Protection (CWP).
What needs improvement?
The costs are really high if you want the entire capabilities of the platform. However, it is really motivated by the great value of the product. Moreover, you can buy individual licenses for the different modules if you don't need some of them.
For how long have I used the solution?
I've used the solution for one year.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Cloud Security SME at a computer software company with 1-10 employees
Provides a single pane of glass and good value for money, but the account onboarding has room for improvement
Pros and Cons
- "The most valuable feature is the ability to apply common tools across all accounts."
- "The integration process could be enhanced by enabling integration at the organizational level rather than requiring the manual setup of individual accounts."
What is our primary use case?
We use Check Point CloudGuard Posture Management to maintain our organization's security posture.
How has it helped my organization?
With a bit of upscaling, it is possible to write custom rules and policies using the GSL Builder. We used the GSL Builder to build the rules for our playground environment and internet-facing environments.
It takes a couple of weeks for a nontechnical person to learn how to use GSL Builder.
The Unified Security Management console is helpful because it provides a single pane of glass.
From a control plane perspective, the solution offers excellent visibility into our framework, enabling the identification of non-compliance.
CloudGuard provides good value for money in terms of automating our security across multiple clouds.
The agentless workload posture analysis, which primarily focuses on our cloud platform, provided valuable insights into our organization's overall security posture.
CloudGuard helped to eliminate some manual processes for a few teams, freeing up some of their time.
Our organization's security operations were able to save time by using CloudGuard's unified platform.
What is most valuable?
The most valuable feature is the ability to apply common tools across all accounts.
What needs improvement?
The integration process could be enhanced by enabling integration at the organizational level rather than requiring the manual setup of individual accounts. The current workflow of creating and linking each role is time-consuming and labor-intensive. Streamlining account onboarding by allowing CloudGuard to identify and integrate at the organizational level would significantly simplify the process.
For how long have I used the solution?
I have been using Check Point CloudGuard Posture Management for one year.
What do I think about the stability of the solution?
Check Point CloudGuard Posture Management is stable.
What do I think about the scalability of the solution?
CloudGuard Posture Management is scalable, as it is a SaaS product.
Which solution did I use previously and why did I switch?
Before implementing Check Point CloudGuard Posture Management, we relied on the native CSPM of AWS Config.
For beginners in the field, AWS might be a good starting point due to its simplicity. However, for more experienced users who require more advanced features, CloudGuard offers a more mature and comprehensive solution.
What other advice do I have?
I would give Check Point CloudGuard Posture Management a rating of seven out of ten. Consolidating additional capabilities into CloudGuard, along with Fusion, would create a comprehensive package offering for customers. This, along with maintaining compatibility with the evolving AWS service, would help to avoid complicating any integration issues.
While developing our tools, there is always a need for ongoing review and updates. However, compared to AWS, the maintenance required for CloudGuard is minimal.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Project Manager at Incedo Inc.
Helpful technical support, with a seamless setup and good integration with the public cloud
Pros and Cons
- "Auto remediation is a very effective feature that helps ensure less manual intervention."
- "Almost all features are good, however, they still require improvements to the code security portion on which integration with the major source code repository is required."
What is our primary use case?
The product provides complete visibility of our cloud security posture. It supports servers and Cloud-Native Services. It provides a centralized solution for Cloud Security with risk and compliance management.
We required it to manage various compliance requirements including live ISO, SOC, PCI and it supports everything. Our Organization is in a hybrid structure and in it, we are using various AWS and Azure accounts. Earlier, we managed everything individually, however, after the implementation of it, we now manage everything from a single solution. The single solution helps with the system, network, and security administration.
How has it helped my organization?
The solution provides the complete visibility of Cloud Security, as well as a number of baseline policies and rules. This helps us to manage cloud posture with less effort. After implementation, it reduced administrative effort in terms of managed security over the cloud. Now, we are not dependent on individual tools for each account as well as cloud service providers.
After implementation, the team can generate reports from a single console for all compliance needs.
Auto Remediation is a very effective feature and it improves the need for manual intervention from the security and cloud administrator.
What is most valuable?
The baseline policy and the integration with the public cloud are very easy.
The number of compliance rulesets along with the baseline policy, support of cloud-native services, and license management are easy. Support of the CI/CD pipeline security (Code Security), Kubernetes, et cetera, is useful.
There are very helpful and various types of reports. Reporting features are very good and anyone from the compliance team can view/generate a report according to compliance support.
Auto remediation is a very effective feature that helps ensure less manual intervention.
Support of AWS Lamda and Azure Functions helps for any potential breaches.
What needs improvement?
Almost all features are good, however, they still require improvements to the code security portion on which integration with the major source code repository is required.
Integration with CI/CD is an important aspect as it is needed to secure the environment. Having it will help a lot.
Integration with Docker is also a key feature that needs some improvements.
Integration with other third parties and with SIEM is an important aspect that should be addressed.
Currently, it provides integration with Tenable, but it would be good if it had support other VAPT software as well.
For how long have I used the solution?
We have been using Check Point CloudGuard Posture management for the last 8+ months.
What do I think about the stability of the solution?
The solution is very stable and we have not found any gaps. It provides seamless integration with the public cloud.
What do I think about the scalability of the solution?
It's a highly scalable solution and integration with the public cloud is very good. The way you can centralize the dashboard of entire cloud infra is a very impressive.
How are customer service and support?
Support has been good. We implement it with the help of OEM support and whenever we've required help we've received a good response.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Earlier, we tested other tools as well, however, the features which were available via Check Point are very good and the future roadmap is also very good in regards to cloud security.
How was the initial setup?
The setup is straightforward and seamless.
What about the implementation team?
We implemented it with help of Check Point support. The rest was managed by our internal team as it's easy to handle.
What was our ROI?
Security is very important and gives us ROI from security itself. We also get an ROI as we have less administrative effort. We can see an ROI with the compliance and risk management on offer too.
What's my experience with pricing, setup cost, and licensing?
The setup cost is very affordable and very easy. Integration with the public cloud is very easy. The licensing calculation is also very good and no manual effort is required.
Which other solutions did I evaluate?
We evaluated other tools like Rapid7, Qualys, and AWS native security tools, as well as Azure native security tools.
What other advice do I have?
It's a very strong solution for cloud security posture management and very effective for large and mid-size environments. Any organization moving towards the cloud would benefit from this.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Manager at a financial services firm with 10,001+ employees
Provides granular reports, good visibility, and facilitates compliance
Pros and Cons
- "It provides complete visibility of workload hosted on different cloud platforms including AWS and Azure, along with multiple tenants."
- "Reporting should have more options."
What is our primary use case?
We primarily use this solution for:
- Visibility for cloud workloads; server, serverless & Kubernetes
- Security configuration review along with auto-remediation
- Posture management and compliance for the complete cloud environment
- Centralize visibility for the complete cloud environment hosted on multiple cloud platforms (AWS, Azure)
- The baseline for security policy as per workload based on services such as S3, EC2, etc
- Visibility of API calls within the environment
- IAM management providing access to the cloud network in a controlled manner
- Alert and notification for any security breach or changes in the cloud environment
- Flow visibility of traffic from and to the cloud environment
- Cloud availability within India
How has it helped my organization?
This solution has improved our organization in several ways, including:
- It provides complete visibility of workload hosted on different cloud platforms including AWS and Azure, along with multiple tenants.
- Helped in enhancing security for our cloud environment by providing reports both in terms of security and compliance.
- Provides complete visibility of traffic flowing from/towards the cloud platform.
- Provides best practice policy, which helps to strengthen the security of our workloads.
- Asset inventory and API calls happening from the cloud.
- Provides control in terms of accessing our cloud workloads. A policy has been created that will block direct access to the cloud environment in case the same is not defined or approved in Dome9
What is most valuable?
The most valuable features of this product are:
- IAM Role gives complete control over the cloud environment. In case someone tries to bypass and create a user or policy locally, which is not allowed or defined in Dome9, the changes will be rolled back and a notification will be sent to the concerned team.
- It is always on and even available on a mobile device using the app.
- Provides complete visibility of traffic flow with threat intel provided from Check Point. It even provides communication details for any suspicious IP.
- Provides detailed information if a workload is allowed direct access, bypassing any firewall policy.
- Provides a granular level of reports, along with issues based on compliance. The standard is defined, depending upon organizational requirements.
- Task delegation, as a particular incident can be assigned to a particular individual, and the same can be done manually or in an automated fashion.
- Customize queries for detecting any type of incident.
What needs improvement?
There are several things in need of improvement, including:
- Policy validation should be available before it is deployed in a production environment using a cloud template.
- Auto remediation requires read/write access. As providing read/write access to third-party applications can add risk, it should have some option of triggering API calls to the cloud platform, which in turn makes the required changes.
- A number of security rules need to be added in order to identify more issues.
- Reporting should have more options.
- It should support all container platforms for visibility of complete infrastructure using a single console such as PCF .
For how long have I used the solution?
I have been using Check Point CloudGuard Posture Management for three months.
Which solution did I use previously and why did I switch?
Initially, we were using tools provided by the service provider. These included Scout Suite, AWS Config, AWS Trusted Advisor, and Amazon GuardDuty. These are monitoring tools, and we used similar tools for Azure as well. We needed to go through different consoles to identify any incident, which was not convenient.
What's my experience with pricing, setup cost, and licensing?
Licensing and costs are straightforward, as they have a baseline of 100 workloads within one license and no additional charges.
Also, it does not have any impact on cloud billing because the data is shared using API calls, which is well within the limit of free API calls.
The complete solution should be provided in a single license including storage, as Check Point charges extra for logic.
Which other solutions did I evaluate?
We evaluated RedLock from Prisma (Palo Alto) and Conformity (Trend Micro).
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Manager - IT at NVCL Group
Full visibility and control with advanced threat prevention capabilities
Pros and Cons
- "The platform's full visibility and control across many cloud environments allows us to effectively monitor the security posture, uncover vulnerabilities, and consistently enforce security standards."
- "For businesses with varied IT ecosystems, increasing the integration capabilities with additional third-party products and services would increase flexibility and user-friendliness."
What is our primary use case?
As a manufacturing company, we always ensure our production and workloads are not being interrupted by anything. Therefore, we are making sure our automated processes are not hindered by any means.
As we have many cloud-based applications, CloudGuard gives us prime support in terms of the security of the system. This includes securing cloud workloads, applications, and data by integrating threat prevention, detection, and response capabilities.
It also ensures compliance and governance across multi-cloud environments.
How has it helped my organization?
It provides complete visibility and control over cloud-native applications and infrastructure, allowing our security teams to monitor and manage every part of their cloud environments.
CloudGuard CNAPP also assures compliance with industry standards and regulatory requirements by automating governance and risk management procedures. This streamlines security management and lowers the operational strain on our IT teams, allowing them to focus on strategic goals. We are able to work freely by putting aside some additional stress.
What is most valuable?
The most useful element of Check Point CloudGuard CNAPP is its advanced threat prevention capabilities. This functionality is vital because it proactively addresses security issues before they affect cloud applications and notifies a real-time incident, ensuring the integrity and availability of critical services.
Furthermore, the platform's full visibility and control across many cloud environments allows us to effectively monitor the security posture, uncover vulnerabilities, and consistently enforce security standards.
What needs improvement?
The management and monitoring of security regulations and incidents might be made easier by improving the user interface, which could be made more intuitive and user-friendly.
For businesses with varied IT ecosystems, increasing the integration capabilities with additional third-party products and services would also increase flexibility and user-friendliness.
To further reduce the amount of manual work required by security teams, the future release could benefit from more sophisticated automation capabilities, such as automated incident response and remediation workflows.
In order to facilitate better decision-making and strategic planning, improved analytics and reporting capabilities would also be beneficial. These would provide deeper insights into security occurrences and patterns.
For how long have I used the solution?
I've used the solution for two years.
What do I think about the stability of the solution?
I'd rate stability nine out of ten.
What do I think about the scalability of the solution?
I'd rate scalability nine out of ten.
How are customer service and support?
Technical support has to be improved.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We have not used a different solution previously.
How was the initial setup?
The initial setup is complex.
What about the implementation team?
We implemented it through the vendor. I'd rate the services eight out of ten.
What was our ROI?
Our inhouse IT department's workload has reduced considerably since using the product.
What's my experience with pricing, setup cost, and licensing?
Setup cost and licensing are quite expensive.
Which other solutions did I evaluate?
We did not evaluate other solutions.
What other advice do I have?
For two years the product has done its job perfectly.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Last updated: Jul 1, 2024
Flag as inappropriate
Buyer's Guide
Download our free Check Point CloudGuard CNAPP Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2025
Product Categories
Vulnerability Management Cloud and Data Center Security Container Security Cloud Workload Protection Platforms (CWPP) Cloud Security Posture Management (CSPM) Cloud-Native Application Protection Platforms (CNAPP) Data Security Posture Management (DSPM) Compliance ManagementPopular Comparisons
Microsoft Defender for Cloud
Cortex Cloud by Palo Alto Networks
Qualys VMDR
SentinelOne Singularity Cloud Security
Tenable Security Center
Orca Security
Lacework FortiCNAPP
Trend Vision One - Cloud Security
Rapid7 Metasploit
Arctic Wolf Managed Risk
Buyer's Guide
Download our free Check Point CloudGuard CNAPP Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the pricing for Check Point software?
- How inadvisable is it to use a single vulnerability analysis tool?
- What are the benefits of continuous scanning for vulnerability management?
- When evaluating Vulnerability Management, what aspect do you think is the most important to look for?
- What is a more effective approach to cyber defense: risk-based vulnerability management or vulnerability assessment?
- What are the main KPIs that need to be implemented to have better posture in vulnerability projects?
- Which is the best vulnerability scanner tool?
- What are your recommended automated penetration testing tools?
- How do you use the MITRE ATT&CK framework for improving enterprise security?
- Can you recommend API for Tenable Connector into ServiceNow