Try our new research platform with insights from 80,000+ expert users

Check Point Application Control vs Zscaler Zero Trust Exchange Platform comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 20, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Check Point Application Con...
Ranking in Application Control
4th
Average Rating
8.8
Reviews Sentiment
7.6
Number of Reviews
41
Ranking in other categories
No ranking in other categories
Zscaler Zero Trust Exchange...
Ranking in Application Control
3rd
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
63
Ranking in other categories
Data Loss Prevention (DLP) (2nd), Cloud Access Security Brokers (CASB) (5th), ZTNA as a Service (1st), Secure Access Service Edge (SASE) (1st), Cloud Security Posture Management (CSPM) (12th), Cloud-Native Application Protection Platforms (CNAPP) (10th), Remote Browser Isolation (RBI) (1st)
 

Mindshare comparison

As of June 2025, in the Application Control category, the mindshare of Check Point Application Control is 5.5%, down from 8.2% compared to the previous year. The mindshare of Zscaler Zero Trust Exchange Platform is 8.7%, up from 8.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Control
 

Featured Reviews

Jivesh Sharma - PeerSpot reviewer
Control application access and optimize bandwidth for enhanced productivity
Check Point Application Control can be improved, particularly in policy management. When we add applications in the policy, we currently have the option to select individual applications, but a feature allowing categorization of applications based on types, such as social media applications, would make it easier to add multiple or bulk applications in the policy. This feature would be very valuable if introduced. Feedback from management about how these changes improved productivity and network performance has been positive. Users were spending their time watching videos on YouTube or streaming content, wasting time on Instagram and Facebook while in the office. Managers complained about this, leading to compliance policies being defined to restrict access to these kinds of applications.
Sumit Bhanwala - PeerSpot reviewer
Cloud-based platform simplifies device and data center management
I find it to be good. The solution is cloud-based with the latest inspection engines, which I find to be amazing. We are less dependent on data centers and device management, which reduces our efforts significantly. It improves our device management, data center management, and updating devices. We need fewer engineers for this management, and it reduces time and efforts for data center management, device upgrades, and IT support.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The overall security of the environment has been greatly improved by the Check Point NGFWs. Before implementing the Check Point solutions, we relied on the Cisco ACLs and Zone-Based firewalls configured on the switches and routers, which in fact a simple stateful firewall, and currently appear to be not an efficient solution for protecting from the advanced threats."
"The most important characteristic is granularity, which allows our teams to have different security profiles depending on the department to be protected."
"We love Check Point Application Control for its granular control and to be able to apply policies between groups, hosts, and networks depending on the need."
"They have an excellent support team. They are fast and it is easy to escalate any situation."
"Its implementation is simple."
"It has many important features that have greatly helped the company and the IT department."
"We can easily switch from a classical firewall to a next-gen firewall using application security."
"Check Point Application Control offers a wide selection of applications, and even within those, you can configure uploads, downloads, et cetera, on a very granular level."
"As a cloud-based service, it is very easily implemented."
"The most valuable feature is its ability to establish connectivity for remote users and remote endpoints. It offers a high level of granularity compared to typical VPNs, which also encapsulate a lot of I/O."
"I like the web filtering capabilities."
"The most valuable features of Zscaler SASE include web filtering, application control, and the private access configuration."
"The most valuable features of Zscaler CASB are API integration and DLP."
"The scalability is pretty good."
"Users get direct secure access to applications over the internet."
"I find all Zscaler Private Access features valuable because each replaces flawed technologies, such as EPAs being replacements for VPN and PR as a replacement for PAM, so I can't mention only one valuable feature. Overall, Zscaler Private Access is a good solution."
 

Cons

"The learning curve for new users is challenging since the integrated data models are complicated."
"More and more product specifications should be infused with new incumbent features in the market to stay relevant and concurrent with the organization's needs."
"Seeing the capabilities and features that we are using today, we can say that we could expect an additional feature that could allow us to integrate this management and even security with APIs."
"SD-WAN functionality can be added."
"Improving the scalability and performance to handle larger networks and increasing traffic volumes would ensure consistent reliability under heavy usage conditions."
"At this time, Check Point Application control is the best on the market."
"The initial setup was a bit difficult."
"I think that the pricing for the Check Point products should be reconsidered - we found it to be quite expensive to purchase and to maintain (the licenses and the support services need to be prolonged regularly), or create some additional bundles of the software blades with significant discounts in addition to the current Next Generation Threat Prevention & SandBlast (NGTX) and Next Generation Threat Prevention (NGTP) offers."
"The pricing for Private Access seems to be on the expensive side, and I believe they should consider making it more competitive with other solutions."
"There aren't really any missing features that I have witnessed."
"The only issue with Zscaler Cloud DLP is that it only gives you DLP protection from web traffic, which is flowing out, while a full-blown DLP solution such as Forcepoint or Symantec gives you DLP coverage for multiple channels. Zscaler Cloud DLP doesn't give you coverage for email, fax, and USB channels, and this is the only challenge or room for improvement in the solution. It's just an extension on top of what you're buying on the proxy, so it's just an added layer, and it doesn't cover DLP on a very broad level. I'm unsure if Zcaler is in the business of competing with a full-blown DLP solution, and if there's a plan to expand the features of Zscaler Cloud DLP beyond the web channel because you'll have to deploy a full-blown agent for it. I'm unsure if this is on the cards because the solution is just an added layer that you get with your proxy. I've asked the Zcaler team whether there's a plan to go full DLP in the future, but I didn't get a positive response. There isn't any feature I'd like added to Zscaler Cloud DLP currently, because anything you could think of that should be in cloud or SaaS solutions is already there, except for machine learning, as it's the only functionality that seems to be lacking in the solution. Machine learning is an additional policy available in other DLP solutions in the market, but my team didn't find it in Zscaler Cloud DLP."
"The menu for the ZIA portal could be organized a little bit differently. The most-used modules should be at the top of the menus, not somewhere near the bottom, some of them are not organized well in my opinion."
"The interface needs a bit of work."
"We'd like to have two-factor authentication that is quite simple."
"There are some performance issues with the solution once the module addition begins"
"Another area of improvement is implementation through non-client connectors. The solution can be implemented in two ways. One uses the back file; the other one uses client connectors. So the client connector is pretty fast, but when it comes to non-client connectors and procedures, it's kind of delayed and slow."
 

Pricing and Cost Advice

"Check Point Application Control is expensive. The tool's licensing costs are yearly."
"The price of Check Point Application Control is high. The support and ecosystem around the solution are expensive."
"The blade has its cost but you can take advantage of the license package to pay less for it."
"It's a bit expensive and it could be cheaper, but it's part of business politics."
"I think application control has become a basic feature and it should be enabled automatically, without having to purchase a separate license for it."
"The pricing is expensive and on the higher end. Honestly, in my opinion, it is not worth the price."
"The price is competitive."
"Zscaler SASE software is quite expensive compared to other solutions"
"My company is a Zscaler Private Access partner, so the customers pay for the license fees."
"The product is a little more expensive than other tools."
"The solution has increased prices this year."
"The licensing model for Zscaler Cloud DLP allows you to only buy what you need. You don't need to buy it as a whole, so it's good."
"The product is a bit expensive."
report
Use our free recommendation engine to learn which Application Control solutions are best for your needs.
859,129 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
18%
Computer Software Company
16%
Construction Company
9%
Manufacturing Company
7%
Computer Software Company
15%
Financial Services Firm
13%
Manufacturing Company
10%
Insurance Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Check Point Application Control?
It has many important features that have greatly helped the company and the IT department.
What is your experience regarding pricing and costs for Check Point Application Control?
The experience with pricing, setup costs, and licensing for Check Point Application Control was straightforward.
What needs improvement with Check Point Application Control?
Check Point Application Control ( /products/check-point-application-control-reviews ) can be improved by offering more granular levels of control. For example, in WhatsApp, there should be deep-lev...
What is the better solution - Prisma Access or Zscaler Private Access?
We looked into Prisma Access before choosing Zscaler Private Access (ZPA). Palo Alto’s Prisma Access is a secure access service edge (SASE) designed to deliver network security in a cloud-deliver...
What do you like most about Zscaler SASE?
The most valuable features of Zscaler Private Access are reliability, scalability, and availability.
What is your experience regarding pricing and costs for Zscaler SASE?
Zscaler SASE is quite expensive compared to other solutions. The price is not fixed and it does not include all of the features, so my advice for organizations would be to evaluate their specific n...
 

Also Known As

No data available
Zscaler SASE, Zscaler DLP, Zscaler CASB, Zscaler CSPM, Zscaler Browser Isolation, Zscaler Posture Control
 

Overview

 

Sample Customers

SEB, Luma Arles, Terma, Aerospace, Midwest Rubber
Siemens, AutoNation, GE, NOV
Find out what your peers are saying about Check Point Application Control vs. Zscaler Zero Trust Exchange Platform and other solutions. Updated: June 2025.
859,129 professionals have used our research since 2012.