No more typing reviews! Try our Samantha, our new voice AI agent.

Check Point Cloud Firewall (formerly CloudGuard Network Security) vs CloudPassage comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Aug 13, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Ranking in Cloud Workload Protection Platforms (CWPP)
8th
Ranking in Cloud Security Posture Management (CSPM)
8th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
46
Ranking in other categories
Vulnerability Management (11th), Container Security (11th), SaaS Security Posture Management (SSPM) (2nd), Cloud-Native Application Protection Platforms (CNAPP) (7th)
Check Point Cloud Firewall ...
Ranking in Cloud Workload Protection Platforms (CWPP)
5th
Ranking in Cloud Security Posture Management (CSPM)
5th
Average Rating
8.4
Reviews Sentiment
7.3
Number of Reviews
243
Ranking in other categories
Firewalls (8th), Managed Security Services Providers (MSSP) (1st), Vulnerability Management (5th), Software Defined WAN (SD-WAN) Solutions (3rd), Cloud and Data Center Security (3rd), Container Security (6th), WAN Edge (3rd), Unified Threat Management (UTM) (4th), Cloud-Native Application Protection Platforms (CNAPP) (5th), Data Security Posture Management (DSPM) (4th), Compliance Management (5th)
CloudPassage
Ranking in Cloud Workload Protection Platforms (CWPP)
27th
Ranking in Cloud Security Posture Management (CSPM)
41st
Average Rating
8.0
Number of Reviews
2
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of September 2026, in the Cloud Workload Protection Platforms (CWPP) category, the mindshare of Qualys TotalCloud is 1.8%, up from 1.3% compared to the previous year. The mindshare of Check Point Cloud Firewall (formerly CloudGuard Network Security) is 4.2%, up from 2.9% compared to the previous year. The mindshare of CloudPassage is 1.4%, up from 0.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Cloud Workload Protection Platforms (CWPP) Mindshare Distribution
ProductMindshare (%)
Check Point Cloud Firewall (formerly CloudGuard Network Security)4.2%
Qualys TotalCloud1.8%
CloudPassage1.4%
Other92.6%
Cloud Workload Protection Platforms (CWPP)
 

Featured Reviews

reviewer2859021 - PeerSpot reviewer
Sr Security Engineer at a tech vendor with 5,001-10,000 employees
Risk-based triage has transformed container security and now prioritizes high-impact threats
The best features Qualys TotalCloud offers currently include managing cloud infrastructure and container security while facing major challenges such as alert fatigue. Traditional vulnerability scanners flag hundreds of CVEs on short-lived Kubernetes containers, some of which have no internet exposure or are gone before we can even triage them. I leverage Qualys TotalCloud to move beyond static CVSS. I use it to implement runtime exposure, correlation risk reprioritization, and shift-left integration. This notifies developers to fix a base image upstream rather than patching live ephemeral instances. In my work with cloud and container security, the biggest operational hurdle was alert fatigue. I use Qualys to shift left from static CVSS severity to context-aware risk prioritization. I correlated raw vulnerability data with real-time risk factors such as public network exposure, active runtime execution, or overly permissive IAM roles. This allows us to immediately drop the priority of isolated containers and escalate lower-severity CVEs that sit on an exposed, high-risk path. We can map these findings directly back to our CI/CD pipelines so developers can patch the root base images upstream. We have drastically cut down the signal-to-noise ratio, saved a lot of manual hours doing triage work, and ensured engineering effort goes directly towards high-impact risk reduction.
Oscar Nunez - PeerSpot reviewer
Ingeniero en redes y Telecomunicaciones at K-IT
Centralized management has reduced policy time and provides reliable multitenant protection
What I would like, what I think they should improve a little is the management of objects at large scale. When you work with multiple domains, there are thousands of network objects. Detecting duplicates and consistency across domains is a very manual process that should be more automated. Another thing: the SmartConsole interface is very powerful and very good, but the learning curve, compared to other solutions in the market from other manufacturers, could be modernized. I think it does not necessarily have to be done from a client application; it could be done via web, because via web I know that not all the options you have in SmartConsole are available. So it would be good if it could also be done from the web and all the options were available. Another thing that I would really like is more automation with Ansible or Terraform. I know it has improved in recent versions, but I think it is still not mature enough. Compared to other manufacturers that do have a bit more in terms of automation capabilities in integration flows with Ansible or Terraform, Check Point Cloud Firewall (formerly CloudGuard Network Security) could improve. Another thing that could be improved a little would be the TAC response time, because when there are very complex cases, I think there should be more speed initially, more ownership of those urgent cases, and not leave the customer waiting. This has happened to me: when I have cases open with Check Point Cloud Firewall (formerly CloudGuard Network Security) TAC, sometimes they do not respond and I have to keep insisting, and I think that part should improve. I do not know if it depends on who takes the ticket or on the severity of the ticket, but sometimes I have had to insist a lot, and that would be the only problem. Once they attend to me and become involved in the case, the responses they give are very professional and really help directly resolve the problems when there is a bug or troubleshooting to do. As I said, I would like to see a specific improvement in SmartConsole. I think if they improved it—how to say it—gave it a facelift so you could access all the options directly from a browser, that would be great, because sometimes, for one reason or another, you cannot download SmartConsole or, for some reason, the SmartConsole client does not start correctly, and you could do it directly from the browser. I think that would be a good option to improve. Another thing would be that in multidomain environments, I would like a global search function for objects and rules. That is, you could enter and search across all domains at once, because right now you have to go domain by domain, and in environments with many customers, you spend quite a bit of time; you have to exit one domain and enter another. So those would be the improvements I would like to see.
it_user854058 - PeerSpot reviewer
Lead Information Security Engineer
It helped us be more aware of what our security posture is, but not all of the features work in my environment
I would say CloudPassage is very useful for certain things. If you just want a few modules then focus on what you need and negotiate the price based on the individual module, rather than looking at the whole thing, because I didn't find all the modules very useful. Also, use Splunk in combination with it if you want reporting. I would give CloudPassage at least a seven out of 10. I rate it on the high-end because of the customer support - I've never seen any support that is comparable to that, it's very good, excellent. The support staff actually care, they actually follow up; it's very nice. And CloudPassage really listens to its customers. The product itself is very nice if you're only looking to check off your compliance requirements, but if you're looking for more of dashboarding and things like that, CloudPassage is improving but it's not quite there.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Qualys TotalCloud's most valuable feature is its ability to link clusters of assets, providing a clear model of deployments, vulnerabilities, and statuses."
"Once you have your vulnerabilities fixed and your patches pushed out using Qualys TotalCloud, then you are able to eliminate threats and cyber risk."
"We were able to realize its benefits within 24 to 48 hours."
"It is a cloud-native app that integrates with both IaaS and SaaS. It seamlessly integrates with other platforms."
"Qualys TotalCloud's most valuable feature is its agent versatility."
"TotalCloud provides the easiest and the best approach for cloud infrastructure management."
"I would definitely recommend Qualys TotalCloud to other customers."
"With TotalCloud, we can scan through the API. If we are not able to deploy cloud agents on the machine, we can use the API."
"Gives us centralized firewall management for both Windows and Linux distros. Also provides a clear view of the security configurations and connections across environments (DMZ, external and internal networks)."
"The Unified Security Management has made threat hunting a lot easier because we have it all in one view, and overall, Check Point has been a nine-plus out of 10 for me; I'm really happy with it."
"We have more visibility than ever before, appreciating the valuable and proactive insight that we receive from the platform."
"The tool's most valuable features for us are threat prevention, HTTPS inspection, and the Anti-Bot blade. Threat prevention helps to protect our assets from threats. HTTPS inspection ensures secure communication, and the Anti-Bot blade is particularly helpful in detecting C2 servers, enhancing our ability to identify malicious activities and protect our network."
"The most valuable feature is the ability to apply common tools across all accounts."
"The notifications, the visibility, and the deployment are the most valuable. It could be packaged in such a way that it took a lot of time and resources off our hands, so it was more efficient."
"The 24/7 online customer support services enhance effective operations and provide quick services in case of a system failure."
"The multiple virtual firewalls on one box are extremely useful and the interconnection with virtual switches is simple and easy to understand."
"Key features are the Software Vulnerability Assessment and the CSM, which is the configuration check."
"Policies are very easy to manage on a day-to-day basis."
"Our scores let us know when to trigger workflow to go out in a patch, it has reduced the amount of time we had to take to manually verify software and check our updates, and it helped us be more aware of what our security posture is."
"CloudPassage allowed us to implement changes that affected hundred of servers within our environments in seconds."
 

Cons

"To be honest, I would move out from this tool because it does not give a full view of vulnerability."
"From a downside perspective, the UI is not user-friendly and feels dated compared to other tools like Prisma Cloud."
"In TotalCloud, I would suggest improvements in policy checks to cater to various inventory types like VPCs, subnets, S3 buckets, or IAMs. There is a lack of data segregation according to criticality or inventory."
"The onboarding process is a bit difficult. In the initial phase, it is very difficult to understand the features, what the dashboard contains, and what criteria they are using."
"With the growing integration of AI, I would like Qualys to enhance its service offerings to better accommodate AI-related risks."
"I chose a rating of nine out of ten because there is a complex interface that sometimes overwhelms new engineers."
"The price is very expensive, actually."
"Regarding technical support from Qualys, they respond, but the response time can be too long. Sometimes we need to wait weeks for solutions to simple questions."
"Micro-Segmentation functionality for EAST-WEST traffic is not native and requires integration with a third-party OEM."
"However, when we were new in this phase, whenever an implementation was going on, there were some areas that we identified with the overall complexity of managing a cloud environment, particularly when we dealt with multiple cloud accounts and networks."
"Making it even easier is a good way to improve it more. When it's easier to use, there are fewer mistakes."
"Dome9 should also support deployments that are on-premises and in a hybrid cloud."
"Addressing the large amount of compliance information and benchmarks we need to observe, the tools are becoming our goto dashboards."
"I would focus on the implementation in the cloud, as it relies on third-party vendors like Azure and AWS. It's not seamless; the solution should be more straightforward for complicated environments."
"Zero touch removes any independence for configuring."
"The main issue that we found with Dome9 is that we have a default rule set with better recommendations that we want to use. So, you do a clone of that rule set, then you do some tweaks and customizations, but there is a problem. When they activate the default rule set with the recommendations and new security measures, it doesn't apply the new security measures to your clones profile. Therefore, you need to clone the profile again. We are already writing a report to Check Point."
"The reports and graphs are unintuitive."
"Anything outside of the software vulnerability management and the CSM, things like the GhostPort, need some improvement. The dashboard is in beta. It looks really good, I wish it would come out of beta."
"Of all the advertised functions, I only find two things that really work in my environment, even though I wanted to use all of them. They're not flexible enough to be used."
"In the CSM module the policies are really hard to work with it. It is not very flexible at all. I would suggest that they change that. Right now, the scan is based on the group that the server is in. What happens if the server is in multiple groups?"
 

Pricing and Cost Advice

"Qualys TotalCloud offers good pricing that is affordable and competitive with the market. Our partnership also provides us with additional benefits."
"Qualys TotalCloud offers competitive pricing given its comprehensive suite of features, including integration, assessment, remediation, and detection capabilities, all within a single platform."
"It isn't cheap, but it's reasonable. It helps us to manage things with very few resources."
"The pricing is comparable. It is built into our other product, so I cannot piecemeal it. It is a part of our subscription."
"The pricing for TotalCloud is attractive and competitive in the market. Given the features, especially the dashboard, I have no concerns regarding pricing."
"Its price seems higher compared to other tools, but it is worth it. If they could adjust the pricing and make it comparable with other tools, that would be great."
"Although Qualys TotalCloud is relatively expensive due to its unique automation features, its cost-effectiveness is rated an eight out of ten, with ten being the most costly."
"The cost is high, but it meets our organizational needs."
"I do not know the exact price, but it is fairly priced. It is neither cheap nor costly."
"It is the most expensive part of the product. There is a lot of room for improvement. Security comes with a price, but it is still a big chunk just for the service."
"The tool's pricing is not cheap."
"The tool's pricing is moderate. Its licensing costs are yearly."
"It is fair. Its license covers all the features. There is a cost-benefit. The licensing for the cloud is better than on-premises because, with on-premises, you have to pay separately for different things."
"The licensing part still needs some work. The issue that I have is that we do not use all the services in the cloud, but sometimes, CloudGuard identifies them as an asset."
"On average, it is normally on the lower end, being less expensive than Palo Alto or Cisco."
"The price of Check Point CloudGuard Network Security is very high compared to other solutions, such as Fortinet FortiMail. For the over 2,000 mailboxes we use with the solution it is very expensive."
"We also evaluated VMware NSX, but the pricing and features available in a CloudPassage implementation were decisive in deciding to go with CP."
"CloudPassage is a little bit on the expensive side. So my suggestion is that the company lower its price point a wee bit or sell modules, separate them in modules, because I only find two things that are useful to me, yet I pay for four or five modules. It didn't seem like it was a fair deal."
report
Use our free recommendation engine to learn which Cloud Workload Protection Platforms (CWPP) solutions are best for your needs.
913,654 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
16%
Outsourcing Company
12%
Manufacturing Company
11%
Financial Services Firm
10%
Outsourcing Company
16%
Construction Company
13%
Financial Services Firm
9%
Manufacturing Company
7%
Comms Service Provider
15%
Manufacturing Company
13%
Construction Company
11%
Financial Services Firm
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise5
Large Enterprise34
By reviewers
Company SizeCount
Small Business132
Midsize Enterprise53
Large Enterprise142
No data available
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
In terms of improvement, remediation still belongs to the cloud team, which is one of the issues we faced with Qualys...
What is your primary use case for Qualys TotalCloud?
My main use case for Qualys TotalCloud is regarding the cloud visibility that we were not having previously. Previous...
What is your experience regarding pricing and costs for Check Point CloudGuard Network Security?
Since we use a unified standard for using policies and modules in Check Point Cloud Firewall (formerly CloudGuard Net...
What needs improvement with Check Point CloudGuard Network Security?
The main limitations of Check Point Cloud Firewall (formerly CloudGuard Network Security) are not in Check Point itse...
What is your primary use case for Check Point CloudGuard Network Security?
Check Point Cloud Firewall (formerly CloudGuard Network Security) is the main manager that provides network security ...
Ask a question
Earn 20 points
 

Also Known As

Qualys TotalCloud with FlexScan
CloudGuard IaaS, Check Point vSEC, CloudGuard IaaS, Check Point Virtual Systems, Check Point CloudGuard Network Security, Check Point CloudGuard CNAPP
CloudPassage Halo
 

Overview

 

Sample Customers

Information Not Available
Physicians Choice Laboratory Services, Helvetica Insurance
Citrix
Find out what your peers are saying about Check Point Cloud Firewall (formerly CloudGuard Network Security) vs. CloudPassage and other solutions. Updated: September 2026.
913,654 professionals have used our research since 2012.