Fortinet Cloud Security provides an integrated set of security technologies for protecting applications, workloads, networks, APIs, identities, and cloud configurations across public, private, hybrid, and multi-cloud environments. Rather than relying on one product, Fortinet combines several security layers. FortiGate VM and FortiGate CNF protect cloud network traffic, FortiCNAPP addresses cloud-native risk and workload protection, while FortiAppSec Cloud and FortiWeb protect web applications and APIs. Central management and analytics can then extend through products such as FortiManager and FortiAnalyzer. Fortinet describes this architecture as providing security from code to runtime across cloud environments.
Quick Benefits
- Security across public, private, hybrid, and multi-cloud infrastructure
- Consistent firewall policies between cloud and on-premises environments
- Cloud workload and configuration risk visibility
- CNAPP capabilities for posture, workload, identity, and runtime security
- Web application and API protection
- Support for AWS, Microsoft Azure, Google Cloud, OCI, and Kubernetes environments
- Agent-based and agentless cloud-security options
- Automated deployment through APIs and infrastructure workflows
- Flexible BYOL, marketplace, subscription, and usage-based licensing options
- FortiFlex support for dynamically changing cloud deployments
- Integration with Fortinet Security Fabric management and analytics

Fortinet Cloud Security At a Glance
What it is: Fortinet’s cloud-security product and solution portfolio
Parent category: Fortinet License
Primary environments: Public cloud, private cloud, hybrid cloud, multi-cloud and Kubernetes
Cloud network security: FortiGate VM and FortiGate CNF
Cloud-native protection: FortiCNAPP
Application/API security: FortiAppSec Cloud and FortiWeb
Application delivery: FortiADC and related services
Management: FortiManager and supported cloud management services
License Overview
A Fortinet Cloud Security License should be built around the components actually required by the cloud architecture. For cloud firewall deployments, FortiGate VM can be purchased as BYOL or provisioned on demand through supported public-cloud marketplaces. Fortinet currently offers FortiGate VM sizes ranging from smaller single-vCPU instances through larger VM configurations, with licensing tied to the required virtual resources and security services.
FortiCNAPP uses a different metric. Fortinet’s current ordering guide licenses its main cloud-security tiers according to protected compute resources measured in vCPUs. Current Standard, Professional and Enterprise tiers also have different minimum order quantities. Code Security is instead licensed per code-contributing developer. This difference is important. A cloud firewall quote cannot be sized using the same inputs as a CNAPP deployment.
Product Overview
Cloud Network Security
FortiGate VM extends FortiOS NGFW capabilities into cloud and virtual environments. It can inspect north-south traffic entering or leaving cloud environments as well as east-west traffic moving between applications, networks, or cloud resources. Fortinet supports automated deployment and integration with native cloud services, including environments built around AWS, Azure and Google Cloud.
FortiGate CNF provides another approach. Instead of deploying and maintaining firewall VMs, it delivers cloud-native firewall functionality as a service, including traffic inspection and policy enforcement while reducing infrastructure-management overhead. Current Fortinet material identifies both AWS and Azure support.
Cloud-Native Application Protection
FortiCNAPP addresses risks that a network firewall alone cannot solve. It combines capabilities including:
- Cloud Security Posture Management (CSPM)
- Cloud Workload Protection (CWPP)
- Cloud Infrastructure Entitlement Management (CIEM)
- Kubernetes security
- Infrastructure-as-Code security
- Code security
- Runtime threat detection
- Cloud detection and response
Web Application and API Protection
Cloud applications also need protection at the application layer. FortiAppSec Cloud combines web application and API security, bot protection, threat analytics and DDoS mitigation as a SaaS service. FortiWeb provides additional WAF deployment choices where organizations need dedicated web application protection.

How Fortinet Cloud Security Works
A typical deployment can follow this flow:
1. Connect the cloud environment
AWS accounts, Azure subscriptions, Google Cloud projects, Kubernetes environments or private-cloud workloads are identified.
2. Protect cloud network traffic
FortiGate VM or FortiGate CNF applies firewall, IPS, web/DNS security and segmentation policies.
3. Discover cloud resources
FortiCNAPP inventories cloud workloads, identities, resources and configurations.
4. Assess posture and exposure
Misconfigurations, excessive permissions, vulnerabilities and compliance problems are evaluated.
5. Protect applications and APIs
FortiAppSec Cloud or FortiWeb inspects application-layer traffic and API activity.
6. Correlate and respond
Security findings can be centralized and connected with Fortinet management, analytics and automation tools.
Core Technical Flow
Users / Internet / Branches
↓
Cloud Network Edge – FortiGate VM / FortiGate CNF
↓
Cloud Applications and Workloads
↓
FortiCNAPP – Posture, Workload, Identity and Runtime Risk
↓
FortiAppSec / FortiWeb – Application and API Protection
↓
Fortinet Security Fabric – Management, Analytics and Response
The result is layered protection rather than expecting one control to secure every cloud attack surface.
Options and Licensing Models
| Requirement | Typical Fortinet option |
|---|---|
| Virtual NGFW | FortiGate VM |
| Managed cloud-native firewall | FortiGate CNF |
| Cloud posture and workload protection | FortiCNAPP |
| Web/API protection | FortiAppSec Cloud / FortiWeb |
| Application delivery | FortiADC |
| Centralized firewall management | FortiManager |
| Analytics and logging | FortiAnalyzer |
| Fixed virtual deployment | BYOL/subscription |
| Cloud-provider purchasing | Marketplace licensing |
| Dynamic usage | FortiFlex |
| Large multi-product estate | Enterprise/points-based purchasing where applicable |
FortiFlex is particularly relevant to cloud environments because it allows supported Fortinet virtual and cloud services to scale through a points-based consumption model. Fortinet states that capacity can be scaled up, down, in or out, with consumption calculated according to the selected entitlement.
Features and Benefits
One of the main benefits of Fortinet Cloud Security is consistency between environments. A business running FortiGate in its data center can extend similar network-security controls into virtual and public-cloud infrastructure rather than creating a completely separate firewall policy model.
Cloud-native security addresses another problem: visibility. FortiCNAPP can discover assets across AWS, Azure, Google Cloud, OCI and Kubernetes while evaluating configuration, identity and workload risk. For application teams, FortiAppSec and FortiWeb add controls closer to the application itself, where network firewall policies alone cannot adequately address API abuse, application vulnerabilities or sophisticated bot activity.
Compatibility and Requirements
Before selecting Fortinet Cloud Security licensing, check:
- Cloud provider: AWS, Azure, Google Cloud, OCI or private cloud
- Number of cloud accounts/subscriptions/projects
- Number and size of workloads
- vCPU requirements
- Kubernetes usage
- Required inbound, outbound and east-west inspection
- Required FortiGuard security services
- Number of web applications and APIs
- CNAPP requirements
- Compliance frameworks
- Identity/IAM exposure
- Agent-based versus agentless requirements
- FortiManager/FortiAnalyzer integration
- High-availability and scaling architecture
How Activation and Deployment Work
Deployment depends on the selected component. FortiGate VM can be deployed into supported cloud or virtual platforms using a BYOL entitlement or an on-demand marketplace model. After deployment, licensing and FortiGuard services are associated with the instance and the firewall is integrated into the cloud network architecture.
For FortiFlex, Fortinet generates entitlements corresponding to the selected VM size and services. Usage-based VM deployments receive an entitlement token that can be supplied to the virtual appliance during deployment. FortiCNAPP follows a different onboarding process, connecting to cloud accounts and workloads through supported agentless and agent-based methods so resources can be inventoried and assessed.
Pricing and Quote Process
Pricing for Fortinet Cloud Security depends heavily on which security layers are required. For an accurate quote, provide:
- Cloud provider(s)
- Number of cloud accounts or subscriptions
- FortiGate VM size or estimated vCPU requirement
- Number of firewall instances
- Required FortiGuard bundle
- BYOL, PAYG or FortiFlex preference
- Number of protected FortiCNAPP vCPUs
- Required FortiCNAPP tier
- Number of applications/APIs requiring protection
- Expected traffic
- Required support term
- Current Fortinet licenses
- Expected scaling pattern
Fortinet pricing depends on your product edition, FortiGate model, security services, license term, deployment model, and support requirements.
