generated: '2026-09-05' method: derived source: openapi/ + https://docs.cgn.portal.checkpoint.com/reference + https://sc1.checkpoint.com/documents/CloudGuard_Dome9/Documentation/Overview/CloudGuard-CSPM-Introduction.htm description: 'Cross-cutting and domain-standard conformance for the CloudGuard (Dome9) v2 REST API. Each entry is a claim about the contract or the documentation with the evidence that supports it. Absence is recorded as conforms: false rather than omitted.' conformance: - id: openapi-3.0 conforms: true evidence: 'All 23 published definitions declare openapi: 3.0.0. Harvested from https://docs.cgn.portal.checkpoint.com/reference' - id: http-basic-auth conforms: true evidence: components.securitySchemes.basic (type http, scheme basic) in every definition; https://docs.cgn.portal.checkpoint.com/reference/authentication - id: oauth2 conforms: false evidence: No oauth2 securityScheme in any published definition; no /.well-known/oauth-authorization-server on any CloudGuard host (all 404). - id: oidc conforms: false evidence: No openIdConnect securityScheme; /.well-known/openid-configuration returns 404 on api.dome9.com, www.checkpoint.com and docs.cgn.portal.checkpoint.com. - id: rfc9457-problem-details conforms: false evidence: 'No application/problem+json media type in any definition; the live 401 returns application/json {"message": "..."}. See errors/cloudguard-problem-types.yml' - id: rfc8594-sunset-header conforms: false evidence: 'No Sunset or Deprecation header policy published; 19 operations carry only OpenAPI deprecated: true. See lifecycle/cloudguard-lifecycle.yml' - id: idempotency-key conforms: false evidence: No Idempotency-Key header on any of 396 mutating operations. See conventions/cloudguard-conventions.yml - id: pagination conforms: false evidence: No page/limit/offset/cursor parameter on any collection GET across 823 operations. - id: json:api conforms: false evidence: Responses are bare domain objects and arrays; no data/attributes/relationships envelope. - id: odata conforms: false evidence: No $metadata surface and no OData query options. - id: scim conforms: false evidence: User and role management is a proprietary surface (/v2/user, /v2/role); no urn:ietf:params:scim schema URNs appear anywhere in the 1,430 published component schemas. - id: rate-limit-headers conforms: false evidence: No RateLimit-*/X-RateLimit-* headers documented or observed. See rate-limits/cloudguard-rate-limits.yml - id: well-known-api-catalog conforms: false evidence: /.well-known/api-catalog returns 404 or an SPA shell on all seven probed CloudGuard/Check Point hosts. See well-known/cloudguard-well-known.yml domain_standards: market: cloud security posture management / CNAPP note: 'CloudGuard''s domain standards live in its compliance rulesets rather than in its wire protocol: the API exposes ruleset, bundle and assessment resources whose CONTENT implements published control frameworks, and the rulesets are addressable by id through the Posture Management API. CloudGuard does not implement a machine-readable security-content interchange standard (OSCAL, SCAP, SARIF, OCSF) on this API - findings are returned in a proprietary shape.' entries: - id: compliance-frameworks-as-rulesets conforms: true evidence: /v2/Compliance/Ruleset and /v2/AssessmentHistoryV2 in openapi/cloudguard-posture-management-openapi.yml expose CloudGuard-maintained rulesets that implement industry control frameworks (CIS Benchmarks, PCI DSS, HIPAA, GDPR, NIST 800-53, ISO 27001, SOC 2) as evaluable rules. Documented at https://sc1.checkpoint.com/documents/CloudGuard_Dome9/Documentation/Overview/CloudGuard-CSPM-Introduction.htm caveat: The frameworks are the subject matter of the rulesets, not a wire-format conformance of the API itself. - id: gsl-governance-specification-language conforms: true evidence: CloudGuard rules are authored in GSL, Check Point's published rule language, browsable at https://gsl.dome9.com/ and evaluated through the Posture Management API. A first-party domain language, not an industry standard. - id: oscal conforms: false evidence: No OSCAL catalog/profile/assessment-results representation in any published schema. - id: sarif conforms: false evidence: No SARIF output declared on the Code Security or Image Assurance surfaces in the published definitions. - id: ocsf conforms: false evidence: Findings and alerts use proprietary Dome9.Web.Api.* view models; no OCSF class/category identifiers appear in the 1,430 published schemas. - id: cve conforms: true evidence: Image Assurance and vulnerability surfaces address findings by CVE identifier (openapi/cloudguard-workload-protection-openapi.yml, KubernetesImageAssurance_GetImageVulnerabilities). CVE is the identifier scheme this market shares. certifications: published: false note: 'No trust center or certification list could be read from a first-party surface: www.checkpoint.com answers our crawler with a 202 bot challenge and an empty body on every path, and no /.well-known/security.txt or trust subdomain was found. Not recorded as absent - recorded as unreadable by us.' evidence: - url: https://www.checkpoint.com/trust/ http_status: 202 - url: https://www.checkpoint.com/.well-known/security.txt http_status: 404