Check Point CloudGuard CNAPP
Check Point CloudGuard CNAPP: comprehensive cloud protection - CSPM, CWPP, CIEM and CDR for AWS, Azure and GCP in a single platform.

Key Features
- CSPM - Cloud Security Posture Management with auto-remediation
- CWPP - Cloud Workload Protection for containers and serverless
- CIEM - Cloud Infrastructure Entitlement Management
- CDR - Cloud Detection & Response
- Multi-cloud support: AWS, Azure, GCP, Kubernetes
Table of Contents
Why do you need Check Point CloudGuard CNAPP?
Over 75% of organizations have experienced a cloud security incident in the past 12 months. The most common causes are misconfigurations, excessive permissions, and lack of visibility in multi-cloud environments. Traditional network security tools are not adapted to the dynamic nature of the cloud, where resources are created and destroyed within minutes.
Check Point CloudGuard CNAPP (Cloud-Native Application Protection Platform) is a unified cloud protection platform that combines CSPM, CWPP, CIEM, and CDR in a single solution. CloudGuard provides full visibility and protection across AWS, Azure, GCP, and Kubernetes environments — from source code to runtime.
How does it work?
Cloud Security Posture Management (CSPM)
Continuous cloud configuration verification:
- Over 2,500 built-in compliance rules (CIS, SOC2, GDPR, NIS2, HIPAA)
- Automated remediation — automatic fixing of misconfigurations
- Drift detection — detecting unauthorized changes
- Risk scoring with prioritization based on business context
- Support for 50+ services across each major cloud provider
Cloud Workload Protection (CWPP)
Runtime workload protection:
- Container security — image scanning, runtime protection
- Serverless security — protection for AWS Lambda, Azure Functions, GCP Cloud Functions
- Vulnerability management with exploitability prioritization
- Runtime protection with behavioral analysis
- Network segmentation for cloud microsegmentation
Cloud Infrastructure Entitlement Management (CIEM)
Cloud permissions management:
- Automatic detection of excessive permissions
- Least-privilege recommendations
- Cross-cloud identity mapping
- Unused permissions detection and cleanup
- Just-in-time access provisioning
Cloud Detection & Response (CDR)
Threat detection and response:
- Real-time threat detection powered by ThreatCloud AI
- Automated investigation with attack chain visualization
- Cross-cloud correlation — event correlation between providers
- Integration with Infinity XDR for full-stack visibility
Key features
Shift-Left Security
- Infrastructure as Code (IaC) scanning — Terraform, CloudFormation, ARM
- CI/CD pipeline integration — Jenkins, GitLab, GitHub Actions
- Container image scanning in registry
- Secret detection in source code
- Automated policy gates before deployment
Compliance and Governance
- 50+ compliance frameworks out-of-the-box
- Custom policy creation with Rego and GSL
- Continuous compliance monitoring
- Automated evidence collection for audits
- Executive dashboards and reporting
Visibility and Inventory
- Full real-time cloud asset inventory
- Network topology visualization
- Data flow mapping between services
- Cost optimization recommendations
- Asset tagging and grouping
Who is it for?
- Organizations with infrastructure in AWS, Azure, or GCP
- Companies deploying Kubernetes and containers in production
- DevOps teams looking for shift-left security
- Organizations subject to regulations (NIS2, GDPR, SOC2)
- Enterprises with a multi-cloud strategy needing unified visibility
FAQ
Does CloudGuard support multi-cloud? Yes. CloudGuard CNAPP natively supports AWS, Azure, GCP, Alibaba Cloud, and Kubernetes (EKS, AKS, GKE, on-premises). A single console provides consistent visibility and security policies across all cloud environments.
How quickly does CloudGuard detect misconfigurations? CloudGuard scans cloud configuration continuously. New resources are assessed within minutes of creation. Automated remediation allows critical misconfigurations to be fixed automatically without team intervention.
Does CloudGuard integrate with CI/CD pipelines? Yes. CloudGuard offers native integrations with Jenkins, GitLab CI, GitHub Actions, Azure DevOps, and other CI/CD tools. Shift-left scanning enables detecting security issues in Infrastructure as Code and container images before production deployment.
What does CloudGuard licensing look like? CloudGuard is licensed per protected cloud resource (billable assets). Available modules include CSPM, CWPP, CIEM, and CDR — purchasable individually or as a full CNAPP package. Annual or multi-year licensing with tiered pricing.
Inquire about Check Point CloudGuard CNAPP
Contact your product specialist and get a custom quote.

Related Services
Our services supporting the implementation and management of this solution
Cloud Security Audit and Protection
Cybersecurity
Check AWS/Azure/GCP security before attackers find misconfigurations. CSPM + manual review.
Financial Services Cloud Compliance
Compliance
Move financial systems to cloud without regulatory risk. Due diligence + exit strategy.
Managed Endpoint Protection (EDR/XDR)
Cybersecurity
Every endpoint protected. Every alert analyzed. Ransomware blocked in 15 minutes.
Active Directory Security Audit
Cybersecurity
We find paths to Domain Admin before attackers do.
From Our Knowledge Base
Articles related to this solution
CVE-2026-40702: WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate...
Security Alert - CVE-2026-40702. CVSS: 9.4 (critical).
CVE-2026-12046: Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/...
Security Alert - CVE-2026-12046. CVSS: 9.0 (critical).
CVE-2026-54414: FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api...
Security Alert - CVE-2026-54414. CVSS: 9.8 (critical).
Related Products
Other solutions you might be interested in
Aruba ClearPass
Aruba Networks
Aruba ClearPass: NAC platform with profiling of 70+ thousand device types. Zero Trust access control for users, BYOD, and IoT.
Barracuda CloudGen Firewall
Barracuda Networks
Barracuda CloudGen Firewall: next-gen firewall with SD-WAN. IPS, application control, VPN, threat protection. Appliance, virtual, cloud.
Barracuda Email Protection
Barracuda Networks
Barracuda Email Protection: AI-powered email security against phishing, ransomware, BEC and account takeover. Gateway + API for Microsoft 365 and Google.
Barracuda SecureEdge
Barracuda Networks
Barracuda SecureEdge: SASE platform combining SD-WAN with cloud security. Zero Trust, SWG, CASB, FWaaS. Protection for distributed workforce.
Want to Reduce IT Risk and Costs?
Book a free consultation - we respond within 24h
Or download free guide:
Download NIS2 Checklist