No more typing reviews! Try our Samantha, our new voice AI agent.

Check Point Cloud Firewall (formerly CloudGuard Network Security) vs CloudPassage comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Aug 13, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Ranking in Cloud Workload Protection Platforms (CWPP)
8th
Ranking in Cloud Security Posture Management (CSPM)
8th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
46
Ranking in other categories
Vulnerability Management (10th), Container Security (11th), SaaS Security Posture Management (SSPM) (2nd), Cloud-Native Application Protection Platforms (CNAPP) (7th)
Check Point Cloud Firewall ...
Ranking in Cloud Workload Protection Platforms (CWPP)
5th
Ranking in Cloud Security Posture Management (CSPM)
5th
Average Rating
8.4
Reviews Sentiment
7.3
Number of Reviews
244
Ranking in other categories
Firewalls (8th), Managed Security Services Providers (MSSP) (1st), Vulnerability Management (5th), Software Defined WAN (SD-WAN) Solutions (3rd), Cloud and Data Center Security (3rd), Container Security (6th), WAN Edge (3rd), Unified Threat Management (UTM) (4th), Cloud-Native Application Protection Platforms (CNAPP) (5th), Data Security Posture Management (DSPM) (4th), Compliance Management (5th)
CloudPassage
Ranking in Cloud Workload Protection Platforms (CWPP)
25th
Ranking in Cloud Security Posture Management (CSPM)
41st
Average Rating
8.0
Number of Reviews
2
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of September 2026, in the Cloud Workload Protection Platforms (CWPP) category, the mindshare of Qualys TotalCloud is 1.8%, up from 1.4% compared to the previous year. The mindshare of Check Point Cloud Firewall (formerly CloudGuard Network Security) is 4.2%, up from 2.9% compared to the previous year. The mindshare of CloudPassage is 1.4%, up from 0.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Cloud Workload Protection Platforms (CWPP) Mindshare Distribution
ProductMindshare (%)
Check Point Cloud Firewall (formerly CloudGuard Network Security)4.2%
Qualys TotalCloud1.8%
CloudPassage1.4%
Other92.6%
Cloud Workload Protection Platforms (CWPP)
 

Featured Reviews

reviewer2859021 - PeerSpot reviewer
Sr Security Engineer at a tech vendor with 5,001-10,000 employees
Risk-based triage has transformed container security and now prioritizes high-impact threats
The best features Qualys TotalCloud offers currently include managing cloud infrastructure and container security while facing major challenges such as alert fatigue. Traditional vulnerability scanners flag hundreds of CVEs on short-lived Kubernetes containers, some of which have no internet exposure or are gone before we can even triage them. I leverage Qualys TotalCloud to move beyond static CVSS. I use it to implement runtime exposure, correlation risk reprioritization, and shift-left integration. This notifies developers to fix a base image upstream rather than patching live ephemeral instances. In my work with cloud and container security, the biggest operational hurdle was alert fatigue. I use Qualys to shift left from static CVSS severity to context-aware risk prioritization. I correlated raw vulnerability data with real-time risk factors such as public network exposure, active runtime execution, or overly permissive IAM roles. This allows us to immediately drop the priority of isolated containers and escalate lower-severity CVEs that sit on an exposed, high-risk path. We can map these findings directly back to our CI/CD pipelines so developers can patch the root base images upstream. We have drastically cut down the signal-to-noise ratio, saved a lot of manual hours doing triage work, and ensured engineering effort goes directly towards high-impact risk reduction.
Oscar Nunez - PeerSpot reviewer
Ingeniero en redes y Telecomunicaciones at K-IT
Centralized management has reduced policy time and provides reliable multitenant protection
What I would like, what I think they should improve a little is the management of objects at large scale. When you work with multiple domains, there are thousands of network objects. Detecting duplicates and consistency across domains is a very manual process that should be more automated. Another thing: the SmartConsole interface is very powerful and very good, but the learning curve, compared to other solutions in the market from other manufacturers, could be modernized. I think it does not necessarily have to be done from a client application; it could be done via web, because via web I know that not all the options you have in SmartConsole are available. So it would be good if it could also be done from the web and all the options were available. Another thing that I would really like is more automation with Ansible or Terraform. I know it has improved in recent versions, but I think it is still not mature enough. Compared to other manufacturers that do have a bit more in terms of automation capabilities in integration flows with Ansible or Terraform, Check Point Cloud Firewall (formerly CloudGuard Network Security) could improve. Another thing that could be improved a little would be the TAC response time, because when there are very complex cases, I think there should be more speed initially, more ownership of those urgent cases, and not leave the customer waiting. This has happened to me: when I have cases open with Check Point Cloud Firewall (formerly CloudGuard Network Security) TAC, sometimes they do not respond and I have to keep insisting, and I think that part should improve. I do not know if it depends on who takes the ticket or on the severity of the ticket, but sometimes I have had to insist a lot, and that would be the only problem. Once they attend to me and become involved in the case, the responses they give are very professional and really help directly resolve the problems when there is a bug or troubleshooting to do. As I said, I would like to see a specific improvement in SmartConsole. I think if they improved it—how to say it—gave it a facelift so you could access all the options directly from a browser, that would be great, because sometimes, for one reason or another, you cannot download SmartConsole or, for some reason, the SmartConsole client does not start correctly, and you could do it directly from the browser. I think that would be a good option to improve. Another thing would be that in multidomain environments, I would like a global search function for objects and rules. That is, you could enter and search across all domains at once, because right now you have to go domain by domain, and in environments with many customers, you spend quite a bit of time; you have to exit one domain and enter another. So those would be the improvements I would like to see.
it_user854058 - PeerSpot reviewer
Lead Information Security Engineer
It helped us be more aware of what our security posture is, but not all of the features work in my environment
I would say CloudPassage is very useful for certain things. If you just want a few modules then focus on what you need and negotiate the price based on the individual module, rather than looking at the whole thing, because I didn't find all the modules very useful. Also, use Splunk in combination with it if you want reporting. I would give CloudPassage at least a seven out of 10. I rate it on the high-end because of the customer support - I've never seen any support that is comparable to that, it's very good, excellent. The support staff actually care, they actually follow up; it's very nice. And CloudPassage really listens to its customers. The product itself is very nice if you're only looking to check off your compliance requirements, but if you're looking for more of dashboarding and things like that, CloudPassage is improving but it's not quite there.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Qualys TotalCloud provides a single, prioritized view of risk, reducing the workload associated with consolidating multiple sources for risk prioritization."
"One of the features I appreciate is the ability to generate daily reports without relying on anyone else."
"The platform's unified view of the organization proves particularly valuable for leadership team meetings."
"One of the most valuable features of Qualys TotalCloud is FlexScan, which is specifically for internet-facing VMs. We found this feature to be very useful. It was a key differentiator for us."
"Qualys TotalCloud has significantly reduced our workload in terms of managing risks, helping us to be more efficient and save substantial resources."
"Vulnerability and threat detection and assessment of the criticality of the vulnerabilities exposed are most valuable."
"Qualys TotalCloud is an excellent platform, and the beauty of the platform is that we can get all the vulnerabilities, see all the reports in a single dashboard, view them segregated, and easily learn about critical, high, and medium findings with appropriately provided remediation steps."
"Generally, Qualys is very good at detections, whether on cloud or on-prem, and the agent allows deployment on both infrastructures, providing continuous monitoring of your assets, which is a key selling point for us."
"It makes securing our cloud workload super easy, and we are able to push any sort of policy changes we need pretty quickly"
"Check Point CloudGuard is quick to deploy and easy for the customer to use."
"The solution learns day by day, learning from behavior, attacks, management, detections, capturing packets, and performing real-time analysis while generating knowledge from a variety of sources for an excellent analysis, which allows us to move faster and have more efficient responses to incidents."
"With Check Point Cloud Firewall (formerly CloudGuard Network Security), we are guaranteed protection from end to end, from user to cloud and cloud to user."
"Check Point CloudGuard Network Security has helped us reduce our organizational risk significantly, and I believe in Check Point strongly because it has only four critical CVEs from 2020 to 2025, compared to its competition, which has had more than fifteen to sixteen critical vulnerabilities from 2020 to 2025, which proves that Check Point's secured firewall OS security is better than its competitors and it will provide the best security to its network."
"We like the GSL Builder feature. When you're running a security operations center, you spend a lot of time monitoring endpoint activity to ensure there is no malicious traffic or anonymous access in the environment. The GSL Builder is helpful for deep investigations of a particular reason for an incident. You can use it to get more information."
"Customer Service: Highly engaged at all levels of the organization, and truly helpful, which cannot be said for many others in their space."
"The central management feature is a big plus, allowing us to manage both local and cloud gateways from one platform."
"Key features are the Software Vulnerability Assessment and the CSM, which is the configuration check."
"Policies are very easy to manage on a day-to-day basis."
"Our scores let us know when to trigger workflow to go out in a patch, it has reduced the amount of time we had to take to manually verify software and check our updates, and it helped us be more aware of what our security posture is."
"CloudPassage allowed us to implement changes that affected hundred of servers within our environments in seconds."
 

Cons

"I sometimes have difficulty detecting or uninstalling certain versions of applications, which I have to do manually."
"Some major banks and insurance companies require an on-premises solution for comprehensive vulnerability management, which TotalCloud does not offer."
"Regarding technical support from Qualys, they respond, but the response time can be too long. Sometimes we need to wait weeks for solutions to simple questions."
"The response part of the Cloud Detection and Response (CDR) module can be improved."
"With the growing integration of AI, I would like Qualys to enhance its service offerings to better accommodate AI-related risks."
"I chose a rating of nine out of ten because there is a complex interface that sometimes overwhelms new engineers."
"Their customer support needs improvement."
"The main area needing improvement is integration. Although the team is strengthening TotalCloud, integration can be enhanced with SIEM, SOAR, ITSM, and other sources."
"I am not a technical person, but generically, the user interface can be a little more intuitive. Our staff has trained network security and cloud security professionals, and they get it, but when you are trying to get to the customers to be able to pick it up and maintain it, it can be a bit difficult."
"We were demotivated by the lack of native automation modules for the Terraform and Ansible tools."
"Lacks the ability to integrate with other security solutions."
"The tool has a lot of potential, but today, it lacks a lot of Scripts/Bots for Azure."
"Check Point CloudGuard Network Security needs to focus more on the VPN side by being more flexible with configuring the VPN with route-based VPN and having a failover with it."
"The biggest thing is the documentation aspect of Dome9 is a little lacking."
"Everything we do with Check Point must go through the vendor first, which is somewhat inconvenient. It would be easier to deal with Check Point directly, however, it depends on the vendor."
"Sometimes the customer service is good. Sometimes it is very bad. And I have nightmares from it."
"Anything outside of the software vulnerability management and the CSM, things like the GhostPort, need some improvement. The dashboard is in beta. It looks really good, I wish it would come out of beta."
"In the CSM module the policies are really hard to work with it. It is not very flexible at all. I would suggest that they change that. Right now, the scan is based on the group that the server is in. What happens if the server is in multiple groups?"
"Of all the advertised functions, I only find two things that really work in my environment, even though I wanted to use all of them. They're not flexible enough to be used."
"The reports and graphs are unintuitive."
 

Pricing and Cost Advice

"I am not sure about the pricing. From what I understand, it is a bit on the higher side, but I do not have the exact numbers."
"It isn't cheap, but it's reasonable. It helps us to manage things with very few resources."
"The cost is high, but it meets our organizational needs."
"While Qualys TotalCloud's pricing is currently acceptable, it is becoming increasingly expensive and may soon be considered overpriced."
"Qualys TotalCloud is cost-efficient and was selected for its value compared to other products."
"As a middle management member, I do not have direct pricing knowledge, but based on the knowledge from our meetings, its pricing is competitive."
"The pricing is comparable. It is built into our other product, so I cannot piecemeal it. It is a part of our subscription."
"Its price seems higher compared to other tools, but it is worth it. If they could adjust the pricing and make it comparable with other tools, that would be great."
"We got discounts on pricing."
"The solution's licensing is based on the number of users of the VMs. We follow a pay-as-you-go model. Its pricing is competitive."
"We have the enterprise-level license and we renew it annually because it is worth the cost."
"It is fair. Its license covers all the features. There is a cost-benefit. The licensing for the cloud is better than on-premises because, with on-premises, you have to pay separately for different things."
"CloudGuard is fairly priced."
"Check Point CloudGuard Posture Management is expensive."
"It's not very expensive. It isn't very cheap either. Its price is okay. It depends on how much money you have. It might be expensive for some companies. Its licensing is on a yearly basis."
"We pay approximately ‎€150,000 ($166,000 USD) per year."
"We also evaluated VMware NSX, but the pricing and features available in a CloudPassage implementation were decisive in deciding to go with CP."
"CloudPassage is a little bit on the expensive side. So my suggestion is that the company lower its price point a wee bit or sell modules, separate them in modules, because I only find two things that are useful to me, yet I pay for four or five modules. It didn't seem like it was a fair deal."
report
Use our free recommendation engine to learn which Cloud Workload Protection Platforms (CWPP) solutions are best for your needs.
914,322 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
16%
Outsourcing Company
12%
Manufacturing Company
11%
Financial Services Firm
10%
Outsourcing Company
16%
Construction Company
13%
Financial Services Firm
9%
Comms Service Provider
7%
Comms Service Provider
14%
Manufacturing Company
13%
Construction Company
11%
Financial Services Firm
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise6
Large Enterprise34
By reviewers
Company SizeCount
Small Business131
Midsize Enterprise54
Large Enterprise145
No data available
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
In terms of improvement, remediation still belongs to the cloud team, which is one of the issues we faced with Qualys...
What is your primary use case for Qualys TotalCloud?
My main use case for Qualys TotalCloud is regarding the cloud visibility that we were not having previously. Previous...
What is your experience regarding pricing and costs for Check Point CloudGuard Network Security?
Since we use a unified standard for using policies and modules in Check Point Cloud Firewall (formerly CloudGuard Net...
What needs improvement with Check Point CloudGuard Network Security?
The main limitations of Check Point Cloud Firewall (formerly CloudGuard Network Security) are not in Check Point itse...
What is your primary use case for Check Point CloudGuard Network Security?
Check Point Cloud Firewall (formerly CloudGuard Network Security) is the main manager that provides network security ...
Ask a question
Earn 20 points
 

Also Known As

Qualys TotalCloud with FlexScan
CloudGuard IaaS, Check Point vSEC, CloudGuard IaaS, Check Point Virtual Systems, Check Point CloudGuard Network Security, Check Point CloudGuard CNAPP
CloudPassage Halo
 

Overview

 

Sample Customers

Information Not Available
Physicians Choice Laboratory Services, Helvetica Insurance
Citrix
Find out what your peers are saying about Check Point Cloud Firewall (formerly CloudGuard Network Security) vs. CloudPassage and other solutions. Updated: September 2026.
914,322 professionals have used our research since 2012.