What you are evaluating
Scope the existing Check Point CNAPP deployment separately from Cloud Firewall and web-application firewall products. Use the partnership FAQ for migration planning; older CNAPP marketing pages should not be treated as proof that every module remains unchanged.
A useful evaluation context
A Check Point customer can evaluate continuity of cloud posture and network-security workflows during the documented CNAPP transition.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- The partnership materials describe Wiz as the forward CNAPP platform for the affected Check Point offering.
- Documented integration connects cloud exposure context with Check Point cloud network-security workflows.
- Cloud Firewall and web-application firewall remain distinct network and application controls outside the stated CNAPP transition.
Where it fits in the work
- Inventory the exact CNAPP modules, policies, finding exports and integrations currently used, keeping firewall subscriptions in a separate list.
- Map each required CNAPP workflow to its proposed Wiz destination and verify support, contractual ownership and any evidence export needs.
- Demonstrate the intended replacement workflow with synthetic resources before scheduling a production migration or changing an existing enforcement path.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
Export a representative synthetic CNAPP finding and map its owner, policy and downstream ticket workflow to the proposed Wiz deployment.
Evidence to look for
The replacement demonstration preserves the required investigation context and ticket ownership, while the inventory explicitly separates unaffected firewall functions.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Which existing CNAPP functions have a demonstrated replacement rather than only a similarly named feature?
- Who owns the post-transition contract, support and data-processing responsibilities?
- Which firewall or web-application-firewall policies remain separately managed and outside the CNAPP migration?