Cloudflare named a Leader in Forrester’s 2025 WAF Wave
Forrester Research has positioned Cloudflare as a Leader in its The Forrester Wave™: Web Application Firewall Solutions, Q1 2025 report. The evaluation assessed 10 WAF vendors across 22 criteria, covering product security, vision, and other key differentiators. Forrester noted:
“Cloudflare is a strong option for customers that want to manage an easy-to-use, unified web application protection platform that will continue to innovate.”
Cloudflare’s WAF journey began in 2013 with its first-generation product. Since then, it has evolved into a comprehensive Application Security platform that natively integrates WAF, bot mitigation, API security, client-side protection, and DDoS mitigation on a single, unified engine. This architecture runs across Cloudflare’s global network, leveraging AI and machine learning to detect threats while also improving application performance through integrated content delivery and optimization tools.
What the Evaluation Highlighted
The Forrester report recognized Cloudflare’s strengths in operational efficiency, stating that “Cloudflare stands out with features that help customers work more efficiently.” The company’s integrated approach allows threat detection across multiple vectors without requiring separate point products, and it received the highest possible scores in 15 of the 22 evaluation criteria. Notable areas of strength included:
- Detection models: AI and machine learning models that continuously evolve to identify new threats.
- Layer 7 DDoS protection: Mitigation of sophisticated application-layer attacks.
- Rule creation and modification: A rule creation experience that propagates globally within seconds.
- Management UI: An interface designed for efficient security management.
- Product security: Architecture built for enterprise-grade security.
- Infrastructure-as-code support: Integration with DevOps workflows for automated policy enforcement.
- Innovation: A roadmap focused on advancing security capabilities.
The report also highlighted significant improvements in Cloudflare’s API security offerings.
Beyond Traditional WAF Capabilities
Cloudflare’s WAF extends beyond conventional rule-based protections. It uses AI and machine learning to detect attacks, automated traffic, anomalies, and compromised JavaScript across web and API traffic, while also safeguarding client environments. Its application-layer DDoS protection is designed to neutralize volumetric attacks.
For API security, the platform offers features such as API discovery, schema validation and sequence mitigation, volumetric detection, and JWT authentication. These can be layered onto the core WAF to address specific application security challenges.
Management and Operational Flexibility
Security management is handled through an intuitive dashboard that balances ease of use with powerful configurations for advanced practitioners. All features are Terraform-supported, enabling teams to manage the entire platform as code. Security Analytics provides a comprehensive view of all traffic—whether mitigated or not—and supports what-if scenarios to test new rules before deployment. An AI agent powered by Natural Language Processing (NLP) assists users in crafting and refining custom rules and creating visualizations within the analytics engine.
Cloudflare’s development cadence includes major feature releases tied to annual initiatives like Security Week and Birthday Week, ensuring customers receive regular updates to their security toolkit.
Forrester does not endorse any company, product, brand, or service included in its research publications and does not advise any person to select the products or services of any company or brand based on the ratings included in such publications. Information is based on the best available resources. Opinions reflect judgment at the time and are subject to change.



