Reduce risk and costs with fully managed Check Point firewall software infrastructure, through highly available, AI-powered threat prevention and efficient cloud native dynamic policies.
Today organizations are navigating complex cloud environments, so predictable, scalable, and consistently applied security has never been more necessary-or more challenging to deliver. Cloud Firewall as a Service addresses these pressures by providing firewall software infrastructure management by Check Point. For security and budget-minded organizations, Cloud Firewall as a Service delivers peace of mind by offloading the complexity of cloud firewall operations (like deployment, configuration, ongoing software updates, and other firewall specific maintenance tasks) to Check Point. Cloud Firewall as a Service is billed based on monthly consumption basis. Delivered through AWS Marketplace, Check Point industry-leading firewall protection (99.9% threat prevention according to Miercom tests and 100% threat prevention according to Cyberratings) delivers high security while eliminating the complex and manual effort of cloud firewall infrastructure management. Pricing is based on a Private Offer. Please reach out to Cloud_Marketplace_Support@checkpoint.com for details. Pricing is tier-structured (based on consumption per GB) for our 'NGFW', 'CloudGuard Network Security with Threat Prevention', and 'CloudGuard Network Security with Threat Prevention and SandBlast'
Highlights
ENHANCE COMPLIANCE AND INCREASE SECURITY POSTURE: Check Point is responsible for your gateway and firewall infrastructure. Cloud Firewall as a Service provides high availability and helps ensure continuous adherence to security standards such as PCI DSS, SOX, and GDPR through advanced threat prevention.
REDUCE MANUAL EFFORT: Eliminate hours of manual firewall infrastructure maintenance and need for deep cloud network architecture knowledge.
INCREASE OPERATIONAL EFFICIENCY: Free up valuable IT and security resources by leveraging expert-maintained firewall infrastructure and efficient cloud-native dynamic policies.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You pay based on usage measured per hour per gigabyte of processed traffic. This is a contract-based model that scales with the amount of data your firewall inspects. Two dimensions set the level of protection. The first, CloudGuard Network Security with Threat Prevention, covers threat prevention features. The second adds Sandblast, which extends protection with sandboxing capabilities. Both bill by data volume, so your cost tracks how much traffic passes through the gateway. Choose the dimension matching the protection depth you need.
Top-of-mind questions for buyers
What does one gigabyte mean for billing, and how is it counted?
You are billed per gigabyte of network traffic the firewall gateway inspects each hour. The unit measures data volume passing through the gateway, not the number of users or servers. Your cost rises as inspected traffic grows and falls when traffic drops.
What is the difference between the Threat Prevention dimension and the version with Sandblast?
Both dimensions bill per hour per gigabyte of inspected traffic. The Threat Prevention dimension covers firewall and threat prevention features. The version with Sandblast adds sandboxing, which runs suspect files in an isolated environment to detect unknown threats. Choose based on the protection depth you need.
Does my cost change automatically as traffic volume rises and falls?
Yes. Charges accrue per hour based on the gigabytes of traffic inspected during that hour. When traffic increases, your cost rises for that period. When less traffic passes through the gateway, you pay less. There is no fixed included amount or tier boundary to cross.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
A single pane-of-glass security management console delivers consistent visibility, policy management, logging, reporting and control across all cloud environments and networks
Check Point Check Point Cloud Firewall is a cloud-native security gateway that delivers automated, advanced threat prevention and multi-layered network security for assets that customers migrate to or store on AWS. Try it free for 30 days.
Advanced threat prevention security for AWS and hybrid cloud environments, with Threat Extraction and Threat Emulation, and with GWLB (starting with R81.20)
**Please note: To ensure optimal operations, Check Point recommends a 4 vCores machine size. This provides balanced efficiency and smooth performance, which most customers find ideal for their needs.
Advanced threat prevention security for AWS and hybrid cloud environments, with Threat Extraction and Threat Emulation, and a built-in security management server
Secure and Reliable Network Access with Check Point SASE
Reviewed on Jul 10, 2026
Review provided by G2
What do you like best about the product?
What I like most about Check Point SASE is its ability to provide secure remote access and centralized security management. In our bank environment, it helps ensure secure connectivity for users while maintaining strong network protection and visibility.
What do you dislike about the product?
One challenge with Check Point SASE is that the initial setup and configuration can be complex, especially when integrating with existing infrastructure.
What problems is the product solving and how is that benefiting you?
Check Point SASE solves challenges like secure remote access, network visibility, and centralized security management. In our bank environment, it helps protect users and applications regardless of location, reduces security risks, and simplifies management through a single platform.
Frejus K.
Powerful Filtering for Student Safety with Check Point SASE
Reviewed on Jul 09, 2026
Review provided by G2
What do you like best about the product?
I have used Check Point SASE for a project when my previous company needed a next generation firewall. I was able to apply any filter for students safety
What do you dislike about the product?
It required more technical skills and Junior IT Team takes times to learn it. I was not able to find training center hosted by Check Point online for self placed
What problems is the product solving and how is that benefiting you?
Security issue. Since I used for K12 education institution where online student safety is primordial, having feature like web filtering is very important to avoid adults site for them
Isiyak S.
Powerful Zero Trust Security, Simple Centralized Management
Reviewed on Jul 08, 2026
Review provided by G2
What do you like best about the product?
What I like the most about Check Point SASE is that it combines networking and security in one platform. It greatly simplifies secure connection of remote users, branch offices and cloud applications, without the need for multiple separate solutions. I also like the centralized management to make it easier to enforce policies and see what’s going on in the environment. Its Zero Trust approach, secure web gateway and cloud-based security help improve protection, while still allowing for good performance for users. Overall, it makes it easier to operate, more secure, and easier to support a modern, hybrid workforce.
What do you dislike about the product?
One thing I’ve seen with Check Point SASE is that getting it up and running and creating policies isn’t always easy, particularly for organizations that are new to SASE or Zero Trust architectures. Some advanced features are not ready to be used by administrator immediately, they need the learning curve. However, the number of security layers involved sometimes makes troubleshooting connectivity or policy issues time consuming. Pricing can also be an issue for smaller organizations especially when there is a need to buy more licenses or advanced features. Overall, while the platform is powerful and feature-rich, it requires proper planning, training, and ongoing management to get the most value from it.
What problems is the product solving and how is that benefiting you?
“Check Point SASE has enabled us to address several business challenges, from secure remote access to cloud application security and centralized policy management. Instead of a multitude of disparate security tools, we can manage network access and security from a single platform, reducing operational complexity and improving visibility. It has also reinforced our Zero Trust security posture, constantly authenticating users and devices before they are allowed to access resources. As a result, we've improved security for remote and hybrid employees, simplified administration, reduced the risk of cyber threats, and provided a more consistent user experience with reliable and secure access to business applications.
Sameer S.
Smooth Setup, Comprehensive Security Solutions
Reviewed on Jun 29, 2026
Review provided by G2
What do you like best about the product?
I find Check Point SASE valuable for its ability to eliminate the need to route all remote traffic through a central data center, replacing fragmented point products with a cloud-native platform. I like that administrators can manage security policies from a single cloud-based dashboard instead of handling multiple security appliances and firewalls. The setup process was smooth with limited workload, and I would rate Check Point SASE a 10 out of 10 as it is a superb product.
What do you dislike about the product?
Issues configuring multiple tunnels with overlapping subnets and limits on dynamic IP tunnels.
What problems is the product solving and how is that benefiting you?
It replaces fragmented products with a cloud native platform, avoiding the need to route remote traffic through a central datacenter.
Surya P.
Unified Security and Networking with Check Point SASE
Reviewed on Jun 20, 2026
Review provided by G2
What do you like best about the product?
I appreciate how Check Point SASE unifies networking and security into a single cloud-delivered service, which is crucial for today's hybrid work environments where users connect from various locations. It efficiently solves the issue of managing fragmented security tools by combining VPN, firewall, CASB, and SD-WAN into one platform. I really like the Zero Trust Network Access feature, as every connection is verified based on user identity, device posture, and application context, offering strong protection against insider threats and compromised accounts. The cloud-native scalability is another standout feature, making it easy to add new users or extend protection to new applications without requiring significant infrastructure changes. Furthermore, Check Point SASE works well with identity and access management platforms like Azure AD, Okta, and Ping Identity, allowing for strong authentication before granting access.
What do you dislike about the product?
Deployment Complexity - Without powerful, initial setup can be challenging for smaller IT teams without prior Check Point experience.
What problems is the product solving and how is that benefiting you?
Check Point SASE unifies networking and security tools like VPN, firewall, CASB, and SD-WAN into a single platform, simplifying management. Its zero trust network access strengthens security by verifying connections. Cloud-native scalability allows easy user and application additions without major infrastructure changes.