Security Without Compromise: What the 2026 NSS Labs Cloud Network Firewall Tests Tell Us

NSS Labs 2026 testing shows Versa NGFW pairs 99.91% security effectiveness with the fastest throughput and lowest cost per Mbps of nine cloud firewalls tested.

Kevin Sheu
VP of Product Marketing
  • Read Time: 6 min read
  • Published: September 30, 2026
  • Modified: September 30, 2026
  • 6 min read read
  • September 30, 2026
  • September 30, 2026

Summary

The 2026 NSS Labs Comparative Test Report for Cloud Network Firewalls evaluated nine leading cloud-native and third-party firewalls under identical conditions, measuring security effectiveness, performance, TLS support, stability, and cost. As AI drives up encrypted traffic volumes and enables more evasive attacks, the results show that enterprises no longer have to trade protection against performance or cost. Versa NGFW earned NSS Labs' "Recommended" rating for the second consecutive year, pairing 99.91% security effectiveness with the fastest rated throughput and the second-lowest cost per Mbps of any vendor tested.

  • NSS Labs tested nine cloud firewalls and plotted them on its Security Value Map.
  • Performance was measured on a 95% TLS/5% HTTP traffic mix, reflecting the encrypted reality of AI-era cloud traffic, where decryption and inspection cause many firewalls to lose most of their throughput.
  • Versa NGFW achieved 99.91% overall security effectiveness, with 100% scores in six of eight security tests.
  • Versa delivered a rated throughput of 3,201 Mbps, 66% to 1,382% faster than every other vendor tested, while posting the second-lowest cost per Mbps.
  • Because cloud compute is billed by consumption, more inspected throughput per instance means fewer instances and a lower cloud bill.

As AI reshapes cloud traffic and the threat landscape, independent testing of nine leading cloud firewalls shows that protection, performance, and cost no longer have to be traded against each other.

The perimeter didn’t disappear when enterprises moved to the cloud. It multiplied. Today’s applications run across AWS, Azure, Google Cloud, and private data centers, and a growing share of them now call AI models and services. Every one of those environments needs a firewall that can inspect traffic and stop threats without slowing traffic or inflating cloud costs. Understanding how well the many firewall options on the market perform in each of these dimensions is important, but knowing if they force effective trade-offs between protection, performance, and cost, under realistic conditions, is what really matters.

The just-released 2026 NSS Labs Comparative Test Report on cloud network firewalls, updating their April 2025 report, offers an independent side-by-side look at how leading solutions actually perform under the same rigorous conditions. Download a complimentary copy of the full NSS Labs test results here. Below I give a quick overview and point to some contextual factors to help interpret the results and understand the current world in which cloud firewalls operate.

A Level Playing Field for Nine Leading Solutions

NSS Labs evaluated nine cloud firewall offerings, spanning cloud-native services and third-party platforms: Amazon Web Services, Check Point, Cisco, Fortinet, Google Cloud Platform, HPE Juniper Networking, Microsoft Azure, Palo Alto Networks, and Versa.

Each solution went through a battery of tests and evaluation across security effectiveness, performance, false-positive management, TLS support, stability and reliability, and cost of the tested configuration. NSS Labs then plotted each vendor on its Security Value Map. The result is a clear picture of which solutions deliver strong protection at a reasonable cost, and which fall short.

Cloud Firewall Challenges in the AI Era

NSS Labs didn’t test AI traffic specifically. But read against today’s market, the report’s test categories map closely onto the pressures AI is putting on cloud security. Things I believe are important to keep in mind in evaluating one’s firewall requirements are:

AI is driving traffic up, and nearly all of it is encrypted. AI workloads move large volumes of data between applications, models, and APIs, and autonomous agents are adding machine-to-machine traffic at a remarkable pace. Virtually all of this runs over TLS. NSS Labs reflected this encrypted reality by testing performance against a mix of 95% TLS and just 5% plain HTTP. Decrypting and inspecting traffic takes heavy compute resources, and it is where many firewalls lose most of their throughput.

Attackers are using AI to evade defenses. Generative AI makes it cheap to produce endless variants of malware and exploits, each disguised a little differently. Blocking a known threat is “table stakes.” The harder test is whether a firewall still catches it once it has been obfuscated, fragmented, or otherwise altered. Evasion resistance is what separates solutions that pass a checklist from those that protect in the real world.

Shadow AI makes visibility essential. Employees and applications increasingly send sensitive data to external AI services, and they do it over encrypted connections. Organizations can only see and govern that traffic if their firewall can decrypt and inspect it at speed.

In the cloud, performance is cost. Cloud firewalls consume compute that is billed by consumption. A solution that delivers more inspected throughput per instance needs fewer instances and results in a smaller bill at the end of the month. With AI initiatives competing for the same budgets, efficiency is a financial requirement, not just a technical one, and the price-per-Mbps metric deserves close attention.

Stability matters too. A firewall that fails under load or when it meets malformed traffic creates exposure precisely when the network is most stressed.

What This Means for Enterprise Security and Network Leaders

Cloud firewall decisions often come down to perceived trade-offs: more inspection means less speed, and more speed means more cost. As AI raises traffic volumes and the sophistication of attacks, those trade-offs only get sharper. The 2026 NSS Labs results show they aren’t inevitable.

When evaluating options, leaders should ask vendors hard questions. How does the firewall perform with decryption turned on? How does it handle evasion techniques? What does protected throughput actually cost per Mbps in production, and how will that scale as AI traffic grows?

Independent testing provides a foundation for getting to the answers.

Download a complimentary copy of the 2026 NSS Labs Comparative Test Report for Cloud Network Firewalls to review the full results for all nine vendors.

Kevin Sheu

By Kevin Sheu

VP of Product Marketing

Kevin Sheu leads product marketing for Versa's Universal SASE portfolio, a role he stepped into in 2023. He previously held senior product marketing and product management roles at Bitglass, Vectra, Okta, FireEye, and Barracuda Networks, and began his career as a management consultant at Booz Allen Hamilton and L.E.K. Consulting. He holds bachelor's and master's degrees in computer science from Johns Hopkins University and an MBA from the MIT Sloan School of Management.

FAQs

It is an independent, side-by-side evaluation of nine leading cloud firewall offerings, updating NSS Labs' April 2025 report. Each solution was tested for security effectiveness, performance, false-positive management, TLS support, stability and reliability, and the cost of the tested configuration, then plotted on NSS Labs' Security Value Map.

Versa NGFW earned NSS Labs' top "Recommended" rating for the second year in a row. It achieved 99.91% overall security effectiveness, the fastest rated throughput at 3,201 Mbps, and the second-lowest cost per Mbps among the nine vendors tested.

AI workloads and autonomous agents are rapidly increasing traffic volumes, and nearly all of that traffic is encrypted with TLS. Decrypting and inspecting it takes heavy compute, and attackers are using generative AI to create evasive malware variants, so firewalls must deliver deep inspection at high throughput without driving up consumption-based cloud costs.

Cloud firewalls consume compute that is billed by usage, so a solution that delivers more inspected throughput per instance needs fewer instances. A lower cost per Mbps translates directly into a smaller monthly cloud bill, which matters more as AI initiatives compete for the same budgets.

Leaders should ask how the firewall performs with decryption turned on, how it handles evasion techniques, what protected throughput actually costs per Mbps in production, and how that cost will scale as AI traffic grows. Independent testing such as the NSS Labs report provides a foundation for answering these questions.

Subscribe to the Versa Blog

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.