Reduce risk and costs with fully managed Check Point firewall software infrastructure, through highly available, AI-powered threat prevention and efficient cloud native dynamic policies.
Today organizations are navigating complex cloud environments, so predictable, scalable, and consistently applied security has never been more necessary-or more challenging to deliver. Cloud Firewall as a Service addresses these pressures by providing firewall software infrastructure management by Check Point. For security and budget-minded organizations, Cloud Firewall as a Service delivers peace of mind by offloading the complexity of cloud firewall operations (like deployment, configuration, ongoing software updates, and other firewall specific maintenance tasks) to Check Point. Cloud Firewall as a Service is billed based on monthly consumption basis. Delivered through AWS Marketplace, Check Point industry-leading firewall protection (99.9% threat prevention according to Miercom tests and 100% threat prevention according to Cyberratings) delivers high security while eliminating the complex and manual effort of cloud firewall infrastructure management. Pricing is based on a Private Offer. Please reach out to Cloud_Marketplace_Support@checkpoint.com for details. Pricing is tier-structured (based on consumption per GB) for our 'NGFW', 'CloudGuard Network Security with Threat Prevention', and 'CloudGuard Network Security with Threat Prevention and SandBlast'
Highlights
ENHANCE COMPLIANCE AND INCREASE SECURITY POSTURE: Check Point is responsible for your gateway and firewall infrastructure. Cloud Firewall as a Service provides high availability and helps ensure continuous adherence to security standards such as PCI DSS, SOX, and GDPR through advanced threat prevention.
REDUCE MANUAL EFFORT: Eliminate hours of manual firewall infrastructure maintenance and need for deep cloud network architecture knowledge.
INCREASE OPERATIONAL EFFICIENCY: Free up valuable IT and security resources by leveraging expert-maintained firewall infrastructure and efficient cloud-native dynamic policies.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You pay based on usage measured per hour per gigabyte of processed traffic. This is a contract-based model that scales with the amount of data your firewall inspects. Two dimensions set the level of protection. The first, CloudGuard Network Security with Threat Prevention, covers threat prevention features. The second adds Sandblast, which extends protection with sandboxing capabilities. Both bill by data volume, so your cost tracks how much traffic passes through the gateway. Choose the dimension matching the protection depth you need.
Top-of-mind questions for buyers
What does one gigabyte mean for billing, and how is it counted?
You are billed per gigabyte of network traffic the firewall gateway inspects each hour. The unit measures data volume passing through the gateway, not the number of users or servers. Your cost rises as inspected traffic grows and falls when traffic drops.
What is the difference between the Threat Prevention dimension and the version with Sandblast?
Both dimensions bill per hour per gigabyte of inspected traffic. The Threat Prevention dimension covers firewall and threat prevention features. The version with Sandblast adds sandboxing, which runs suspect files in an isolated environment to detect unknown threats. Choose based on the protection depth you need.
Does my cost change automatically as traffic volume rises and falls?
Yes. Charges accrue per hour based on the gigabytes of traffic inspected during that hour. When traffic increases, your cost rises for that period. When less traffic passes through the gateway, you pay less. There is no fixed included amount or tier boundary to cross.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Check Point Check Point Cloud Firewall is a cloud-native security gateway that delivers automated, advanced threat prevention and multi-layered network security for assets that customers migrate to or store on AWS. Try it free for 30 days.
Advanced threat prevention security for AWS and hybrid cloud environments, with Threat Extraction and Threat Emulation, and with GWLB (starting with R81.20)
**Please note: To ensure optimal operations, Check Point recommends a 4 vCores machine size. This provides balanced efficiency and smooth performance, which most customers find ideal for their needs.
Advanced threat prevention security for AWS and hybrid cloud environments, with Threat Extraction and Threat Emulation, and a built-in security management server
Advanced threat prevention security for AWS and hybrid cloud environments, with Threat Extraction and Threat Emulation.
**Please note: To ensure optimal operations, Check Point recommends a 4 vCores machine size. This provides balanced efficiency and smooth performance, which most customers find ideal for their needs.
Secure, Policy-Driven Access with Centralized Visibility in Check Point SASE
Reviewed on Aug 18, 2026
Review provided by G2
What do you like best about the product?
What I like best about Check Point SASE is its ability to provide secure, policy-driven access while maintaining centralized visibility and control. From an OT security perspective, the combination of Zero Trust access, advanced threat prevention, and simplified management helps organizations securely connect remote users and sites without compromising security or operational reliability.
What do you dislike about the product?
One area where Check Point SASE could improve is its learning curve and administrative complexity compared to some cloud-native SASE competitors. Initial policy configuration and integration across multiple security services may require more expertise, particularly in large enterprise environments. Additionally, some organizations may find the licensing structure and overall cost higher than alternative solutions, especially for smaller deployments. However, these challenges are often outweighed by its strong security capabilities and comprehensive feature set.
What problems is the product solving and how is that benefiting you?
For me, the key benefit is simplified security management and improved risk reduction. It enables secure remote access, enhances threat protection, reduces operational complexity, and helps maintain compliance while delivering a better user experience. From an OT/critical infrastructure perspective, it also supports secure third-party and remote access without exposing critical assets unnecessarily.
Computer & Network Security
Unified Zero-Trust Security on a Single Cloud Platform
Reviewed on Aug 18, 2026
Review provided by G2
What do you like best about the product?
Checkpoint SASE provides unified zero trust security , secure internet/private access, and saas protection single cloud platform . simpler management.
What do you dislike about the product?
Higher cost compare with basic VPN solutions and initial sase deployment/config6can be complex. Also require skilled resources for troubleshooting and integration.
What problems is the product solving and how is that benefiting you?
It helps solve the business problem of securely connecting remote users, branches, and applications while enforcing consistent security policies. It also reduces security complexity, VPN dependency, and the risk of cyber threats/data breaches through a unified cloud-based security platform.
Ravindranath C.
Fast Global Connectivity with Room for Improvement
Reviewed on Aug 17, 2026
Review provided by G2
What do you like best about the product?
I like Check Point SASE for its fast global connectivity and the single intuitive dashboard. The direct routing through worldwide cloud points of presence eliminates VPN latency, which is great for efficiency. I also appreciate the centralized visibility that streamlines management and allows admins to enforce zero trust policies effectively.
What do you dislike about the product?
I find setting new granular policies and dealing with log latency to be challenging in Check Point SASE. Also, while I found the initial setup easy, configuring it to our specific code was a bit difficult.
What problems is the product solving and how is that benefiting you?
Check Point SASE provides low latency and zero trust access for remote access. I like the fast global connectivity, managed by a single intuitive dashboard that offers centralized visibility, streamlining management and enforcing zero trust policies.
Henok M.
Secure and Reliable Network Access with Check Point SASE
Reviewed on Jul 10, 2026
Review provided by G2
What do you like best about the product?
What I like most about Check Point SASE is its ability to provide secure remote access and centralized security management. In our bank environment, it helps ensure secure connectivity for users while maintaining strong network protection and visibility.
What do you dislike about the product?
One challenge with Check Point SASE is that the initial setup and configuration can be complex, especially when integrating with existing infrastructure.
What problems is the product solving and how is that benefiting you?
Check Point SASE solves challenges like secure remote access, network visibility, and centralized security management. In our bank environment, it helps protect users and applications regardless of location, reduces security risks, and simplifies management through a single platform.
Frejus K.
Powerful Filtering for Student Safety with Check Point SASE
Reviewed on Jul 09, 2026
Review provided by G2
What do you like best about the product?
I have used Check Point SASE for a project when my previous company needed a next generation firewall. I was able to apply any filter for students safety
What do you dislike about the product?
It required more technical skills and Junior IT Team takes times to learn it. I was not able to find training center hosted by Check Point online for self placed
What problems is the product solving and how is that benefiting you?
Security issue. Since I used for K12 education institution where online student safety is primordial, having feature like web filtering is very important to avoid adults site for them