
A 2026 WAF choice decides who owns edge, rules, and maintenance.
Cloudflare is the zero-operations option: its managed WAF runs at the edge, hides the origin, and receives frequent updates. The trade-off is dependency on a third-party network: proxied traffic is decrypted at Cloudflare, and regional processing controls are an Enterprise add-on. Its OWASP Core Ruleset still uses the CRS 3.3.0 scoring model.
Coraza is an Apache-2.0 Go WAF for your infrastructure, available as a library, middleware, reverse proxy, or container. It is 100% compatible with OWASP CRS 4 (current release 4.29.0), while CRS 3.3.x support ends in Q3 2026. You control TLS and data flow, but must patch the engine, update rules, tune false positives, and operate the connector. Caddy is stable; nginx and Apache integrations remain experimental.
Choose Cloudflare for small teams, global audiences, or zero-ops. Choose Coraza for data sovereignty, CRS 4, or infrastructure control. Test traffic in detection mode first, record changes, and keep a rollback path.
Sources: Cloudflare OWASP ruleset, Coraza.
Related areas
Related What I Do
These What I Do pages are matched from the subject matter of this article, creating a cleaner path from educational content to implementation work.
Continue reading
Related articles
Based on shared categories first, then the strongest overlap in tags.

