Austin, Texas – September 29, 2026 -- CyberRatings.org has published new Cloud Network Firewall (CNFW) test results showing security effectiveness among nine evaluated products ranging from 0% to 99.95%, with only four earning a Recommended rating.
Four vendors clear the bar with 99.7% or higher security effectiveness
Fortinet FortiGate Next-Generation Firewall, HPE Juniper Networking vSRX Next Generation Firewall, Palo Alto Networks VM-Series Next-Generation Firewall, and Versa Networks Next Generation Firewall each achieved 99.7% or higher in Security Effectiveness, earning Recommended ratings. Tests were conducted by NSS Labs, CyberRatings' official testing partner, using the Cloud Network Firewall Test Methodology v4.1.
Check Point posts the top score but misses Recommended status on price
Check Point CloudGuard Network Security Next-Gen Firewall recorded the highest Security Effectiveness score at 99.95% but received a Neutral rating due to an above-average price per Mbps.
AWS and Microsoft native firewalls score 0% on security effectiveness
AWS Network Firewall and Microsoft Azure Firewall both received 0% for Security Effectiveness, placing them in the Caution category. Google Cloud Platform NGFW Enterprise scored 77.45% and Cisco Secure Firewall Threat Defense Virtual scored 66.10%, both also landing in Caution.
Testing spans 5,004 attacks across 43 evasion techniques
Products from cloud service providers and third-party vendors deployed on Amazon Web Services were evaluated under identical conditions, incorporating real-world exploits, evasion techniques, malware, false-positive samples, and sustained enterprise traffic loads. Evasion resistance was tested with 5,004 attacks spanning 43 techniques across OSI Layers 3, 4, and 7.
Vikram Phatak, CEO of CyberRatings.org, said buyers should weigh evasion resistance and TLS inspection as heavily as raw block rates, noting that products earning Recommended ratings this year proved they can hold up under real conditions despite attackers routinely using evasion techniques.
CyberRatings urges buyers to treat native cloud firewalls as a baseline only
CyberRatings.org recommends enterprises validate exploit blocking, malware blocking, and evasion resistance before relying on native cloud offerings as primary controls, require TLS inspection to avoid blind spots, and re-evaluate firewall requirements for AI and agentic workloads that will drive larger, more complex east-west traffic policies. NSS Labs used proprietary technologies alongside Keysight's CyPerf tool to test security, performance, TLS functionality, and stability across the nine products.