No more typing reviews! Try our Samantha, our new voice AI agent.

Check Point WAF (formerly CloudGuard WAF) vs Zscaler Zero Trust Exchange Platform comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Aug 13, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.2
Check Point WAF boosts cost savings, efficiency, and security, enhancing ROI through reduced ownership costs and streamlined operations.
Sentiment score
7.3
Zscaler Zero Trust Exchange enhances ROI through cost savings, improved security, productivity, and reduced operational expenses and support issues.
When we are attacked, we can understand how important the solution is.
Cyber security manager at a government with 1,001-5,000 employees
When you migrate to the cloud, it feels like saving 90% of your time.
Manager, Managed Security Services at a tech vendor with 51-200 employees
Most of the operations happen in the background, so I do not spend much time on it.
Principal Cybersecurity Specialist at Unitel S.A.
When I see that I am trying to cut costs, for example, even when replacing Prisma, we have managed to save about over half a million dollars a year.
Cybersecurity Senior Program Manager at Dayforce
In terms of time savings, since users no longer manually connect to the VPN, access became seamless, improving user productivity, especially for remote users.
Technical Team Lead - Content Security at Valuepoint Systems
We don't have to purchase many components such as load balancers and proxy servers that were necessary in traditional setups.
Lead Engineer at FIS Global
 

Customer Service

Sentiment score
6.5
Check Point WAF support is responsive and knowledgeable but occasionally delayed, needing improvement in service proficiency and availability.
Sentiment score
4.9
Zscaler's support is praised for knowledge and responsiveness but varies in resolution time and regional quality.
They need to increase the number of people for 24/7 support.
Principal Cybersecurity Specialist at Unitel S.A.
They were responsive even before we committed to buying their solution.
Infrastructure Manager at FPMH
I also received full technical support, especially during the implementation.
Cyber security manager at a government with 1,001-5,000 employees
The support engineers are technically knowledgeable, particularly for Zscaler Private Access related issues, providing clear guidance and documentation for troubleshooting.
Technical Team Lead - Content Security at Valuepoint Systems
Sometimes, support takes time since the solution has some bugs that need fixing.
architect at Tata Consultancy
They have provided the numbers and contact supports, and it is almost immediate.
Cybersecurity Senior Program Manager at Dayforce
 

Scalability Issues

Sentiment score
7.2
Check Point WAF excels with scalable, cloud-native design, seamless AWS integration, and adaptable SaaS deployment for multi-cloud support.
Sentiment score
7.6
Zscaler Zero Trust Exchange is scalable and cloud-native, facilitating easy, hardware-free user expansion with high performance and adaptability.
If I need to scale, I open a Whatsapp group with the director and the team, and we quickly proceed to do so.
Cyber security manager at a government with 1,001-5,000 employees
They have sufficient resources, and there are no challenges from a scalability perspective.
Project Manager at a outsourcing company with 1,001-5,000 employees
Check Point CloudGuard WAF's scalability is very good.
Sr. VP of Creative & Development at a non-tech company with 51-200 employees
The only limitation I was mentioning is that it was unable to identify the sources of vulnerability, which they are going to embed by the mid of this year.
Cybersecurity Senior Program Manager at Dayforce
Zscaler Zero Trust Exchange Platform is highly scalable, primarily because it is built on a cloud-native, globally distributed architecture.
Technical Team Lead - Content Security at Valuepoint Systems
 

Stability Issues

Sentiment score
8.2
Check Point WAF is praised for its exceptional stability and reliability, with users rating it highly for performance and robustness.
Sentiment score
7.8
Zscaler’s platform is highly reliable and stable, with minor connectivity issues and occasional slight latency during data transfers.
It is very stable.
Team Leader, Cloudops & Cloud Architect at a consultancy with 501-1,000 employees
It is very stable, never crashing or giving me an error that I can see.
Sysadmin at a government with 501-1,000 employees
I did not have any issues in the last three years during which I had more than ten critical services running on CloudGuard.
Information Technology - Infrastructure and Security at Cyprus Development Bank
Zscaler Zero Trust Exchange Platform is very stable, especially in enterprise environments.
Technical Team Lead - Content Security at Valuepoint Systems
Zscaler Zero Trust Exchange Platform is very stable.
Cybersecurity Senior Program Manager at Dayforce
 

Room For Improvement

Check Point WAF requires improvements in customization, integration, pricing, and support, with users desiring simplified setup and enhanced features.
Zscaler's platform needs latency and usability improvements, better multi-tenancy and support, clearer pricing, and enhanced SIEM integration.
The provider could improve by providing better guidance and support during the configuration process.
Infrastructure Manager at FPMH
Future releases should include better bot mitigation, behavioral anomaly detection, compliance templates, advanced threat intel integration, and streamlined multi-cloud support to boost protection and usability.
Senior Cyber Security Engineer at a computer software company with 501-1,000 employees
A machine learning-based adaptive mode could help the WAF learn over time and auto-tune policies.
Technical Support Executive at a computer software company with 501-1,000 employees
It would be beneficial to have more granular centralized visibility, allowing for quick end-to-end tracing of a user request from authentication to application access without switching between multiple views.
Technical Team Lead - Content Security at Valuepoint Systems
Zscaler Zero Trust Exchange Platform probably needs to be more efficient because scanning takes a lot of time.
Cybersecurity Senior Program Manager at Dayforce
They might be able to identify if something is missing with Zscaler.
architect at Tata Consultancy
 

Setup Cost

Check Point WAF is seen as costly but justified by its robust features, flexible licensing, and ease of renewal.
Zscaler Zero Trust Exchange Platform has high subscription costs but offers ROI by reducing infrastructure needs and enhancing security.
It is more expensive than f5, where we purchased everything as bundles, and Check Point costs more, but it is worth the money.
Cyber security manager at a government with 1,001-5,000 employees
It is less costly than Cloudflare, Fortinet, and other vendors.
Project Manager at a outsourcing company with 1,001-5,000 employees
I know that its price is relatively expensive compared to other products but it gives benefits that are worth it.
Ciso at a government with 1,001-5,000 employees
There is minimal setup cost since it is a cloud-delivered platform, eliminating the need to invest in additional hardware such as VPN gateways or maintain infrastructure.
Technical Team Lead - Content Security at Valuepoint Systems
Zscaler Zero Trust Exchange Platform is much, much cheaper when comparing price.
Cybersecurity Senior Program Manager at Dayforce
 

Valuable Features

Check Point WAF offers AI-driven protection with easy deployment, low false positives, scalability, and integration with Azure, enhancing security.
Zscaler Zero Trust Exchange offers scalable security with zero trust access, app segmentation, and flexible identity-based control for organizations.
Upon implementation and evaluation with third-party penetration testing, it meets rigorous security standards required for dealing with financial institutions.
Infrastructure Manager at FPMH
It can protect against zero-day attacks and hidden anomalies.
Amministratore Della Sicurezza Di Rete at a government with 1,001-5,000 employees
The solution preemptively blocks zero-day attacks and detects hidden anomalies effectively.
Information Technology - Infrastructure and Security at Cyprus Development Bank
The solution is cloud-based with the latest inspection engines, which I find to be amazing.
architect at Tata Consultancy
We have excellent account management, smooth marketplace engagement, and processing in how my team or organization uses Zscaler Zero Trust Exchange Platform.
Manager, Software Development at a outsourcing company with 201-500 employees
Since we started using Zscaler Zero Trust Exchange Platform, it has auto-configuration, and wherever we have deployed the auto-configuration, we have not encountered any problem.
Cybersecurity Senior Program Manager at Dayforce
 

Categories and Ranking

Check Point WAF (formerly C...
Ranking in Data Loss Prevention (DLP)
8th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
76
Ranking in other categories
Application Security Tools (5th), Web Application Firewall (WAF) (5th), DevSecOps (2nd)
Zscaler Zero Trust Exchange...
Ranking in Data Loss Prevention (DLP)
6th
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
67
Ranking in other categories
Cloud Access Security Brokers (CASB) (8th), Application Control (5th), ZTNA as a Service (1st), Secure Access Service Edge (SASE) (2nd), Remote Browser Isolation (RBI) (1st)
 

Mindshare comparison

As of August 2026, in the Data Loss Prevention (DLP) category, the mindshare of Check Point WAF (formerly CloudGuard WAF) is 0.7%, up from 0.3% compared to the previous year. The mindshare of Zscaler Zero Trust Exchange Platform is 4.0%, down from 5.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Data Loss Prevention (DLP) Mindshare Distribution
ProductMindshare (%)
Zscaler Zero Trust Exchange Platform4.0%
Check Point WAF (formerly CloudGuard WAF)0.7%
Other95.3%
Data Loss Prevention (DLP)
 

Featured Reviews

Krishnakumar Mahadevan - PeerSpot reviewer
CISO at Spink Solutions Private Limited
Cloud security has strengthened risk posture and improved advanced threat visibility
There are some API gateway and API securities I mentioned. If these are incorporated with AI-related features, particularly those seven key vulnerabilities I mentioned—token theft and tool poisoning—that would be beneficial. AI-related features are not included yet in Check Point CloudGuard WAF. However, they are present in FortiGate. That is the advantage of FortiGate now. FortiGate is stopping all AI-related vulnerabilities now. FortiGate has this capability. It is unfortunate that even Palo Alto also lacks one or two of these features. Check Point Quantum is very good, without a doubt. However, their capabilities are not in comparison with Palo Alto. There are some features, but there are some gaps in comparison with Palo Alto.
Vibin Thomas - PeerSpot reviewer
Technical Team Lead - Content Security at Valuepoint Systems
Zero trust access has transformed remote connectivity and now simplifies secure app usage
Zscaler Zero Trust Exchange Platform, especially Zscaler Private Access, is very strong, though there are a few areas where improvements can be made. One challenge observed is around initial troubleshooting and visibility. While Zscaler Private Access provides logs, it can sometimes take time to pinpoint the exact cause of access issues, especially in complex environments with multiple policies and identity integration. Another area is the dependency on identity and connector health. Since Zscaler Private Access is heavily reliant on app connectors and identity providers, any issues with these components can impact user access, making proper monitoring critical. During the initial setup, policy configuration and application onboarding require careful planning, especially for larger environments with many applications. These challenges are manageable with proper design and monitoring. Overall, the platform delivers strong security and user experience. I would recommend a few improvements, especially around user interface, reporting, and troubleshooting experience. From a user interface perspective, while the platform is powerful, the policy configuration and navigation can feel complex, especially for new users. A more simplified and intuitive layout for policy mapping and application access would help reduce the learning curve. In terms of reporting, Zscaler Private Access provides logs, but having more built-in customizable dashboards and analytics would be very helpful. Better visibility into user access patterns, application performance, and real-time troubleshooting insights would improve operational efficiency. From a support and troubleshooting standpoint, it would be beneficial to have more granular centralized visibility, allowing for quick end-to-end tracing of a user request from authentication to application access without switching between multiple views. These improvements would make the platform even more efficient, especially for large-scale enterprise environments.
report
Use our free recommendation engine to learn which Data Loss Prevention (DLP) solutions are best for your needs.
909,725 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
18%
Outsourcing Company
13%
Financial Services Firm
9%
Construction Company
9%
Financial Services Firm
12%
Manufacturing Company
10%
Outsourcing Company
8%
Computer Software Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business54
Midsize Enterprise23
Large Enterprise34
By reviewers
Company SizeCount
Small Business16
Midsize Enterprise12
Large Enterprise46
 

Questions from the Community

What is your experience regarding pricing and costs for CloudGuard for Application Security?
It is a little bit expensive, but the pricing model is acceptable, though a reduction would make it more competitive with leaders such as Palo Alto.
What needs improvement with CloudGuard for Application Security?
The false positive rate is a concern, but I could recommend improvements where false positives have to be minimized better. This all depends on how the rules are customized and configured, and it c...
What is your primary use case for CloudGuard for Application Security?
The main purpose is to have network security through machine learning, which can offer threat detection and intelligence for my endpoints, and I am looking for application security. I am looking fo...
What is the better solution - Prisma Access or Zscaler Private Access?
We looked into Prisma Access before choosing Zscaler Private Access (ZPA). Palo Alto’s Prisma Access is a secure access service edge (SASE) designed to deliver network security in a cloud-deliver...
How to minimize false positives for PII and PCI around different data systems across the globe?
Personal information always should be under high protection from manipulations which is why it is the responsibility of those collecting the data to keep the integrity of these data and check and u...
What is your experience regarding pricing and costs for Zscaler Cloud Protection?
This is an area where I have candid feedback from our organization regarding pricing, setup cost, and licensing for Zscaler Zero Trust Exchange Platform. Overall, I would assess the pricing as a si...
 

Also Known As

Check Point CloudGuard Application Security, CloudGuard Application Security, CloudGuard AppSec, Check Point CloudGuard Code Security
Zscaler SASE, Zscaler DLP, Zscaler CASB, Zscaler CSPM, Zscaler Browser Isolation, Zscaler Posture Control
 

Overview

 

Sample Customers

Orange España, Paschoalotto
Siemens, AutoNation, GE, NOV
Find out what your peers are saying about Microsoft, Forcepoint, Check Point Software Technologies and others in Data Loss Prevention (DLP). Updated: July 2026.
909,725 professionals have used our research since 2012.