No more typing reviews! Try our Samantha, our new voice AI agent.

AWS WAF vs Prisma Cloud by Palo Alto Networks comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 1, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
5.7
AWS WAF offers cost-effective security by reducing the need for extra staff and effectively blocking threats.
Sentiment score
6.8
Prisma Cloud boosts productivity and security through automation, reducing vulnerabilities, saving time, and streamlining compliance for organizations.
With AWS WAF, it is easier for us to block unwanted malicious DDoS attacks and threats from coming into our web application.
Dev Ops Engineer at a tech vendor with 1,001-5,000 employees
It eliminates the need for additional hardware, making it a financially and technically sound investment.
Partner at Quasys
There was a cost reduction. That was the benefit that we had visualized while evaluating Prisma Cloud as one of the possible solutions.
Technical Architect at a tech services company with 1,001-5,000 employees
 

Customer Service

Sentiment score
6.6
AWS WAF support is prompt and knowledgeable, but experiences vary in resolution speed and service costs.
Sentiment score
7.1
Prisma Cloud support quality varies; clients experience quick resolutions or slow responses, with satisfaction depending on region and support level.
Resolving issues can take time because the support personnel may lack product expertise, leading to delays.
Security Engineer at a computer software company with 1,001-5,000 employees
They reach out when you send them a ticket, and within 24 hours or less, someone is able to get back to you to solve your problem.
Dev Ops Engineer at a tech vendor with 1,001-5,000 employees
They can respond with technical documentation or pass on the case to the next level because it requires the development of a new feature or changing a feature due to a bug.
Technical Lead at a consultancy with 11-50 employees
Anywhere we raise a tech case, they revert back within an hour.
Cloud Security Engineer at a tech vendor with 201-500 employees
I would give them 10 out of 10.
Sector Manager at a comms service provider with 51-200 employees
 

Scalability Issues

Sentiment score
7.5
AWS WAF is highly scalable, versatile for various infrastructures, but some users desire expanded features for broader adaptability.
Sentiment score
7.5
Prisma Cloud offers scalable, flexible multi-cloud support, efficiently accommodating large enterprises with performance, albeit needing credit purchases for optimal use.
AWS WAF does scale in the sense that it is fully managed and has automatic scaling.
Dev Ops Engineer at a tech vendor with 1,001-5,000 employees
Scalability within the credit limit is good. It is 100%.
Cloud security architect at a tech vendor with 10,001+ employees
I would rate it a ten out of ten for scalability.
Cloud Security Support at a tech vendor with 501-1,000 employees
I would rate it a nine out of ten for scalability.
Cloud Security Engineer (Team lead) at a tech services company with 201-500 employees
 

Stability Issues

Sentiment score
8.3
AWS WAF is stable, effectively blocking threats, with minor issues in custom rules, and continuous improvements enhance reliability.
Sentiment score
7.9
Prisma Cloud by Palo Alto Networks is highly reliable and trustworthy, with minimal downtime and effective maintenance communication.
Since it protects web applications from common attacks such as SQL injection and XSS, it is very stable.
Dev Ops Engineer at a tech vendor with 1,001-5,000 employees
In terms of reliability, I would rate AWS WAF about six out of ten due to the need for improved signature sets.
Security Engineer at a computer software company with 1,001-5,000 employees
We faced issues with AWS WAF when writing the custom rules.
Infrastructure Lead at Danat Fz LLC
I would rate it a ten out of ten for stability.
Cloud Security Engineer (Team lead) at a tech services company with 201-500 employees
We had issues whenever we were downloading the vulnerability report. It did not include all the information.
Cloud Security Support at a tech vendor with 501-1,000 employees
Once the issues were identified, Palo Alto applied the correct solutions to ensure high availability and scalability.
Technical Lead at a consultancy with 11-50 employees
 

Room For Improvement

AWS WAF requires enhanced features, security, user interface, documentation, seamless integrations, and added automation for improved effectiveness.
Prisma Cloud needs user interface, integration, automation, cost, and support improvements, with better multi-cloud support and visibility.
Compared to firewalls, WAFs generally provide limited stateful analysis capabilities.
Security Engineer at a computer software company with 1,001-5,000 employees
The way we see it now is just mentioned as a percentage from bots and actual users, which should include proper graphs and detailed information.
Infrastructure Lead at Danat Fz LLC
The level of granularity is not great, and as you cross a certain threshold, the cost goes up by twenty or thirty percent every time.
Security Engineer Dev Sec Ops at a outsourcing company with 1,001-5,000 employees
We could have deployed the runtime monitoring with Prisma Cloud by Palo Alto Networks, but within our organization at our company, it was very difficult to find who would be the owner for the alerts.
Cyber Security Architect at a comms service provider with 10,001+ employees
Even though documentation was available, it took a while for a new person to understand what integration meant, what will be achieved after the integration, or how the integration needed to be done on the Azure or AWS side.
Technical Architect at a tech services company with 1,001-5,000 employees
Having auto Defender upgrades so that we do not have to upgrade Defender manually would be helpful.
Cloud Security Support at a tech vendor with 501-1,000 employees
 

Setup Cost

AWS WAF pricing is seen as affordable but can be costly in high-demand scenarios like DDoS attacks.
Enterprise buyers find Prisma Cloud expensive but valuable, with flexible pricing benefiting multi-cloud enterprises despite additional costs.
Due to our status as an AWS shop, AWS WAF is cost-effective for us, and we benefit from discounts due to our extensive use of AWS services.
Security Engineer at a computer software company with 1,001-5,000 employees
The licensing cost for AWS WAF is just pay-as-you-go; it is a service-based model.
Infrastructure Lead at Danat Fz LLC
The cost was not on the higher side.
Technical Architect at a tech services company with 1,001-5,000 employees
However, its price can be better so that small banks or small organizations can afford it and adopt it to secure their environment and data.
Cloud Security Engineer (Team lead) at a tech services company with 201-500 employees
The pricing for Prisma Cloud is high.
Technical Lead at a consultancy with 11-50 employees
 

Valuable Features

AWS WAF enhances security with configurable rules, seamless AWS integration, scalability, and ease of deployment for threat protection.
Prisma Cloud enhances cloud security with real-time monitoring, automation, and CSPM for effective DevOps and multi-cloud protection.
The biggest benefit of AWS WAF for us is to filter malicious requests, so we can protect our environment and application from malicious actors.
Infrastructure Lead at Danat Fz LLC
It has also helped to improve the posture of our application, prevent all DDoS attacks, and unnecessary traffic and SQL injection that is reducing the performance of our application.
Dev Ops Engineer at a tech vendor with 1,001-5,000 employees
The specific outcomes showing how AWS WAF has helped our organization include improving our security posture by reducing the attack surface and reducing malicious attacks.
Senior Cloud Security at a healthcare company with 5,001-10,000 employees
Its ability to centralize and address security vulnerabilities across these diverse environments makes it a crucial and decisive element within the Prisma Cloud ecosystem.
Partner at Quasys
For CWP, the runtime protection is the most valuable feature. Every tool does vulnerability monitoring through tools such as Qualys, but the additional feature we get here is runtime protection in CWP.
Cloud Security Engineer at a tech vendor with 201-500 employees
It is as easy as registering a new subscription to AWS, and you start seeing all that data.
Technical Architect at a tech services company with 1,001-5,000 employees
 

Categories and Ranking

AWS WAF
Ranking in Web Application Firewall (WAF)
8th
Average Rating
8.0
Reviews Sentiment
6.8
Number of Reviews
63
Ranking in other categories
No ranking in other categories
Prisma Cloud by Palo Alto N...
Ranking in Web Application Firewall (WAF)
7th
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
114
Ranking in other categories
Container Security (2nd), Cloud Security Posture Management (CSPM) (2nd), Cloud-Native Application Protection Platforms (CNAPP) (2nd), Data Security Posture Management (DSPM) (2nd)
 

Mindshare comparison

As of September 2026, in the Web Application Firewall (WAF) category, the mindshare of AWS WAF is 3.9%, down from 6.9% compared to the previous year. The mindshare of Prisma Cloud by Palo Alto Networks is 1.9%, up from 1.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Web Application Firewall (WAF) Mindshare Distribution
ProductMindshare (%)
Prisma Cloud by Palo Alto Networks1.9%
AWS WAF3.9%
Other94.2%
Web Application Firewall (WAF)
 

Featured Reviews

Azam S M - PeerSpot reviewer
Infrastructure Lead at Danat Fz LLC
Has successfully filtered malicious traffic and allowed country-specific access controls
For improvement in AWS WAF, we can have better monitoring. One of the things that should be improved in AWS WAF is the monitoring; we need to identify the requests and where they are coming from. If it's a bot, we should differentiate the requests, whether they are automated or not. The way we see it now is just mentioned as a percentage from bots and actual users, which should include proper graphs and detailed information. We also need a feature where we can filter specific requests. If there are scripts in the requests, we should be able to filter those requests to see if there are any scripts running from them.
reviewer2776578 - PeerSpot reviewer
Cyber Security Architect at a comms service provider with 10,001+ employees
Image scanning has supported consistent security practices during cloud deployment
On a scale of ten, we would say people are happy with Prisma Cloud by Palo Alto Networks for the part we use. People are okay with it. We probably would give an eight. We don't give ten because if we don't use the other parts of Prisma Cloud by Palo Alto Networks, it's because it was difficult to implement from an operational point of view. We could have deployed the runtime monitoring with Prisma Cloud by Palo Alto Networks, but within our organization at our company, it was very difficult to find who would be the owner for the alerts. People have other tools and in the end, we don't use the full capabilities of a product that we pay for. It's partially related to the difficulty to integrate Prisma Cloud by Palo Alto Networks runtime in our company's support process. We don't use the real-time monitoring part of Prisma Cloud by Palo Alto Networks. We don't know about the automated remediation feature of Prisma Cloud by Palo Alto Networks.
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
914,109 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Manufacturing Company
9%
Comms Service Provider
8%
Outsourcing Company
6%
Financial Services Firm
13%
Computer Software Company
8%
Manufacturing Company
8%
Outsourcing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise12
Large Enterprise28
By reviewers
Company SizeCount
Small Business37
Midsize Enterprise21
Large Enterprise58
 

Questions from the Community

What are the limitations of AWS WAF vs alternative WAFs?
Hi Varun, I have had experienced with several WAF deployments and deep technical assessments of the following: 1. Imperva WAF 2. F5 WAF 3. Polarisec Cloud WAF Typical limitations on cloud WAF is t...
How does AWS WAF compare to Microsoft Azure Application Gateway?
Our organization ran comparison tests to determine whether Amazon’s Web Service Web Application Firewall or Microsoft Azure Application Gateway web application firewall software was the better fit ...
What is your experience regarding pricing and costs for AWS WAF?
AWS WAF is affordable; it depends on the number of rules you apply. The licensing cost for AWS WAF is just pay-as-you-go; it is a service-based model.
What is your primary use case for Prisma Cloud by Palo Alto Networks?
Prisma Cloud helps support DevSecOps methodologies, making those responsibilities easier to manage.
What Cloud-Native Application Protection Platform do you recommend?
We like Prisma Cloud by Palo Alto Networks, since it offers us incredible visibility into our entire cloud system. We are able to easily see where our container vulnerabilities lie and and where cl...
What do you think of Aqua Security vs Prisma Cloud?
Aqua Security is easy to use and very manageable. Its main focus is on Kubernetes and Docker. Security is a very valuable feature and their speed of integration is very good. The initial setup was ...
 

Also Known As

AWS Web Application Firewall
Prisma Public Cloud, RedLock Cloud 360, RedLock, Twistlock, Aporeto
 

Overview

 

Sample Customers

eVitamins, 9Splay, Senao International
Amgen, Genpact, Western Asset, Zipongo, Proofpoint, NerdWallet, Axfood, 21st Century Fox, Veeva Systems, Reinsurance Group of America
Find out what your peers are saying about AWS WAF vs. Prisma Cloud by Palo Alto Networks and other solutions. Updated: September 2026.
914,109 professionals have used our research since 2012.