No more typing reviews! Try our Samantha, our new voice AI agent.

Check Point CloudGuard CNAPP vs Qualys VMDR vs Threat Stack Cloud Security Platform [EOL] comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.3
Check Point CloudGuard CNAPP improves security and compliance, reduces manual tasks, boosting efficiency and ROI with automation.
Sentiment score
7.0
Qualys VMDR enhances ROI by streamlining management, improving compliance, reducing vulnerabilities, saving time, and minimizing breaches effectively.
Sentiment score
7.3
Threat Stack Cloud Security boosted compliance and revenue, reduced staffing needs, enhanced security, and expanded infrastructure dramatically.
The compliance has improved as our overall compliance score against CIS benchmark has improved from around 72 to 92% within the first three months of adoption.
Assistant Manager at a computer software company with 201-500 employees
This helped my team cut manual review time by roughly twenty to twenty-five percent, allowing me to reallocate effort to proactive cloud security improvements.
Networking and System Consultant at Orbcom,Lda.
Monitoring cloud security automatically ensures a return on investment.
Cloud Engineer at Cloudar
We saw a return on investment through significant savings in time, money, and resources.
System Admin at a tech services company with 10,001+ employees
 

Customer Service

Sentiment score
6.6
Check Point CloudGuard CNAPP offers excellent, knowledgeable support but could improve initial response times at the basic support level.
Sentiment score
6.6
Qualys VMDR support is responsive and helpful, but users note occasional delays and suggest better response time and depth.
Sentiment score
7.4
Threat Stack Cloud Security Platform's support is praised for responsiveness, precise solutions, and effective communication with technical representatives.
When I need help or have open questions, or if I require the capability to deploy a quick test environment, there are always people I can contact at Check Point to get my information or the environment as fast as I need it.
Cloud Security Architect at controlware
I have a dedicated support engineer and a presales engineer dedicated to me.
Cloud Engineer at Cloudar
Customer support for Check Point CloudGuard CNAPP has been responsive and knowledgeable.
Assistant Manager at a computer software company with 201-500 employees
We usually get on calls with tech support, and they are very helpful.
Works at a comms service provider with 1-10 employees
The response time takes a while.
Security Engineer at a consultancy with 10,001+ employees
The technical support provided by Qualys is pretty good.
System Admin at a tech services company with 10,001+ employees
 

Scalability Issues

Sentiment score
7.7
Check Point CloudGuard CNAPP scales well across clouds, with reliable performance and strong security compliance, despite licensing concerns.
Sentiment score
7.9
Qualys VMDR is highly scalable, supporting numerous assets efficiently with customizable management and seamless cloud-based architecture.
Sentiment score
8.2
Threat Stack Cloud Security Platform is scalable, easy to deploy, and efficient across AWS accounts, with minor configuration concerns.
Visibility scales without performance issues as my environment expands.
Networking and System Consultant at Orbcom,Lda.
Check Point CloudGuard CNAPP scales efficiently in the multi-cloud environment.
Assistant Manager at a computer software company with 201-500 employees
I never had any performance-related issues.
Cloud Security Architect at controlware
Scalability depends on the license and the number of assets being monitored.
System Admin at a tech services company with 10,001+ employees
Qualys VMDR can handle scalability, although increasing the inventory can raise the licensing costs.
Information Security Analyst at a tech services company with 51-200 employees
Qualys VMDR's scalability is good, and the customer support is good.
Cyber Security Solution Engineer at a computer software company with 201-500 employees
 

Stability Issues

Sentiment score
8.1
Check Point CloudGuard CNAPP is reliable and efficient, handling large-scale workloads with minimal downtime despite occasional minor latency issues.
Sentiment score
7.9
Qualys VMDR is highly stable, reliable, and effective, with minimal downtime and challenges mostly due to user-side issues.
Sentiment score
7.5
Threat Stack Cloud Security Platform [EOL] is stable and efficient, with minor GUI and agent issues for some users.
If there are errors, it is sometimes challenging to elaborate or troubleshoot since it is not transparent enough to understand what to search for.
Cloud Security Architect at controlware
It is rapidly evolving, and sometimes mistakes occur, necessitating testing.
Cloud Engineer at Cloudar
Qualys VMDR is stable.
Cyber Security Solution Engineer at a computer software company with 201-500 employees
 

Room For Improvement

Check Point CloudGuard CNAPP needs better integrations, user interfaces, support, automation, and documentation to enhance functionality and user satisfaction.
Qualys VMDR needs improved support, efficient reporting, UI, asset notifications, reduced tool dependency, better pricing, and comprehensive resources.
Threat Stack Cloud Security Platform needs UI improvements, better API alignment, and enhanced integrations, especially for serverless and container environments.
I need more integration from the code-to-cloud principle.
Cloud Security Architect at controlware
It would be nice to have periodic updates on what people should do, maybe with some analysis or something.
Information Security Officer at Cargus
I require consistency in the user interface to ensure everything is streamlined into the same look and feel.
Cloud Engineer at Cloudar
It does not automate patching unless the patch management module is purchased separately.
System Admin at a tech services company with 10,001+ employees
If AI features were integrated, it could enhance the capabilities significantly.
Information Security Analyst at a tech services company with 51-200 employees
One area where Qualys VMDR can be improved is the missing feature for deploying agents for over 1,000 assets, as we need to do it manually.
Cyber Security Solution Engineer at a computer software company with 201-500 employees
 

Setup Cost

Check Point CloudGuard CNAPP offers flexible licensing with varied costs, seen as high but valuable for security management.
Qualys VMDR pricing is high for small businesses but offers flexibility, discounts, and comprehensive features for larger enterprises.
Threat Stack Cloud Security Platform offers value with transparent pricing, ranging $15-$20 monthly, seen as competitively priced by users.
In terms of ROI, we can see time savings for audit preparation of at least 30-40%.
Assistant Manager at a computer software company with 201-500 employees
It is not cheap, of course, yet it is a necessity.
Cloud Security Architect at controlware
From a licensing and cost perspective, it is really competitive.
Cloud Engineer at Cloudar
I would rate the pricing between seven to eight out of ten.
System Admin at a tech services company with 10,001+ employees
I have a notion that Qualys might be more expensive than Rapid7.
Information Security Analyst at a tech services company with 51-200 employees
Qualys offers better pricing and is feature-packed compared to other tools.
Works at a comms service provider with 1-10 employees
 

Valuable Features

Check Point CloudGuard CNAPP offers visibility, compliance, and threat intelligence, enhancing security management and governance across multi-cloud environments.
Qualys VMDR offers user-friendly management, real-time insights, and powerful integrations, significantly improving vulnerability prioritization and remediation efficiency.
Threat Stack Cloud Security platform is esteemed for its configurability, integration, monitoring capabilities, and effective alert management.
One of the main reasons we use the solution is that it is great at identifying risks that are critical to our business.
Information Security Officer at Cargus
The CDR helps detect anomalous behavior and respond to threats before they become an issue.
Cloud Engineer at Cloudar
Check Point CloudGuard CNAPP offers a unified, modular platform that combines CSPM, CWPP, CIEM, code security, and cloud detection and response.
Assistant Manager at a computer software company with 201-500 employees
The prioritization of vulnerabilities has improved our remediation efforts by around thirty to thirty-five percent.
Works at a comms service provider with 1-10 employees
It impacts my workflow overall, with the patch management features as it has the missing patches listed in detail, making it easier to get a comprehensive report and providing some dashboards that offer visual representation.
JMS, RPSG Ventures Limited at RP Sanjiv Goenka Group
Qualys VMDR's continuous monitoring capabilities help us respond to emergent threats by enabling my team to reach out to the security engineers whenever there is any detection of a vulnerability, informing them about it, and creating an incident.
Soc Lead & Edr Administration at Persistent Systems
 

Featured Reviews

reviewer2751468 - PeerSpot reviewer
Assistant Manager at a computer software company with 201-500 employees
Boosts security and compliance in multi-cloud environments while real-time threat detection enhances risk management
Check Point CloudGuard CNAPP flagged a misconfiguration in our AWS S3 bucket that had overly permissive access settings. That configuration could have exposed our sensitive data to the public internet. The platform not only identified the issue but also provided remediation that our team was able to apply immediately. This prevented a potential data exposure. Check Point CloudGuard CNAPP offers a unified, modular platform that combines CSPM, CWPP, CIEM, code security, and cloud detection and response. The agentless workload posture, real-time threat detection and response, multi-cloud coverage and visibility, compliance automation, and one-click remediations stand out as its best features. I find myself relying on the risk management engine and prioritization the most day-to-day. In any cloud environment, you are flooded with findings, misconfigurations, vulnerabilities, and compliance gaps. Without prioritization, it is overwhelming for our team to take care of the posture. CloudGuard's risk scoring helps us cut through incidents. This makes remediation faster and focused instead of wasting time checking every alert. We get to fix the issues that pose real business risks. Check Point CloudGuard CNAPP has positively impacted our organization at a significant level. We get greater visibility and control across all our cloud environments. Some biggest benefits we have seen are faster detection and remediation of misconfigurations, improved compliance posture, reduced risk exposure, operational efficiency, and cost savings. Overall, it has made our cloud environment more secure, compliant, and easier to manage while freeing up our teams to focus on projects instead of chasing alerts.
Vaibhav Ghule - PeerSpot reviewer
Soc Lead & Edr Administration at Persistent Systems
Continuous risk-based monitoring has strengthened incident response and vulnerability prioritization
I haven't explored Qualys VMDR's vulnerability lifecycle automation yet. One of my analysts mentioned that queries lack grouping operators in Qualys VMDR. From my experience, I would appreciate improvements in the query options in Qualys VMDR, specifically in the query-building process where I would need more features and operators. Additionally, we have been facing issues with Qualys on the cloud level. We cannot download the configuration profile from the cloud agent, and it is showing a pending action for download. During 2025, we noticed outages of Qualys a couple of times. I want to mention that there is an issue with receiving timely RCA deliveries. While this is not necessarily about the tool, it relates to support. The support has not been very responsive, and we are receiving RCAs a little delayed whenever we raise support cases or communicate with the TAMs. Additionally, the UI has a slight latency, which I and my team have experienced. They have also reported this latency issue when navigating through different pages.
SC
Software Development Manager at Rent Dynamics
SecOps program for us, as a smaller company, is amazing; they know what to look for
They could give a few more insights into security groups and recommendations on how to be more effective. That's getting more into the AWS environment, specifically. I'm not sure if that's Threat Stack's plan or not, but I would like them to help us be efficient about how we're setting up security groups. They could recommend separation of VPCs and the like - really dig into our architecture. I haven't seen a whole lot of that and I think that's something that, right off the bat, could have made us smarter. Even as part of the SecOps Program, that could be helpful; a quick analysis. They're analyzing our whole infrastructure and saying, "You have one VPC and that doesn't make a lot of sense, that should be multiple VPCs and here's why." The architecture of the servers in whatever cloud-hosting provider you're on could be helpful. Other than that, they should continue to expand on their notifications and on what's a vulnerability. They do a great job of that and we want them to continue to do that. It would be cool, since the agent is already deployed and they know about the server, they know the IP address, and they know what vulnerability is there, for them to test the vulnerability and see if they can actually exploit it. Or, once we patch it, they could double-check that it can't be. I don't know how hard that would be to build. Thinking on it off the top off my head, it could be a little challenging but it could also be highly interesting. It would also be great if we could test a couple of other features like hammering a server with 100 login attempts and see what happens. Real test scenarios could be really helpful. That is probably more something close to what they do with the SOC 2 audit or the report. But more visualization of that, being able to test things out on our infrastructure to make sure we can or can't hit this box could be interesting.
report
Use our free recommendation engine to learn which Container Security solutions are best for your needs.
885,444 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
No data available
No data available
Performing Arts
14%
Manufacturing Company
8%
Comms Service Provider
6%
Construction Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business55
Midsize Enterprise18
Large Enterprise56
By reviewers
Company SizeCount
Small Business20
Midsize Enterprise12
Large Enterprise70
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise5
Large Enterprise2
 

Questions from the Community

What is your experience regarding pricing and costs for CloudGuard Workload Protection?
My experience with pricing, setup cost, and licensing has been reasonable for the value it delivers. The initial setu...
What do you like most about CloudGuard for Cloud Intelligence?
The new scanning function is a valuable feature that wasn't available until recently.
What needs improvement with CloudGuard for Cloud Intelligence?
One area that Check Point CloudGuard CNAPP could use improvement is the navigation when switching between modules. A ...
What do you like most about Qualys VMDR?
I like that we have many scanners and channels that don't overload. It helps us scan and track easily. Also, the tagg...
What is your experience regarding pricing and costs for Qualys VMDR?
My experience with pricing, setup cost, and licensing shows that we can consider both time and money saved.
What needs improvement with Qualys VMDR?
I haven't explored Qualys VMDR's vulnerability lifecycle automation yet. One of my analysts mentioned that queries la...
Ask a question
Earn 20 points
 

Also Known As

Check Point CloudGuard Posture Management, Dome9, Check Point CloudGuard Workload Protection, Check Point CloudGuard Intelligence
Qualys VM, QualysGuard VM, Qualys Asset Inventory, Qualys Container Security
Threat Stack, CSP,
 

Overview

 

Sample Customers

Symantec, Citrix, Car and Driver, Virgin, Cloud Technology Partners
Agrokor Group, American Specialty Health, American State Bank, Arval, Life:), Axway, Bank of the West, Blueport Commerce, BSkyB, Brinks, CaixaBank, Cartagena, Catholic Health System, CEC Bank, Cegedim, CIGNA, Clickability, Colby-Sawyer College, Commercial Bank of Dubai, University of Utah, eBay Inc., ING Singapore, National Theatre, OTP Bank, Sodexo, WebEx
StatusPage.io, Walkbase, Spanning, DNAnexus, Jobcase, Nextcapital, Smartling, Veracode, 6sense
Find out what your peers are saying about Wiz, Palo Alto Networks, SentinelOne and others in Container Security. Updated: March 2026.
885,444 professionals have used our research since 2012.