Just spent the last quarter wrestling with both of these because management insisted we needed "options." The sales pitch for both is the same: secure, global, cloud-delivered firewall for your roaming users. The reality, as always, is in the details you only find after the contract is signed.
Prisma Access feels like you're renting a meticulously organized, incredibly expensive penthouse. Everything works seamlessly because Palo Alto decides how everything works. Need to tweak a policy for a quirky legacy app? Hope you enjoy their workflow. The performance is solid, but you're paying a premium for the privilege of being locked into their ecosystem. Their bandwidth-based pricing is a particular joy—you get to guess how much you'll need next year, and if you're wrong, it's just more money.
CloudGen, on the other hand, is like buying a very capable toolbox and then being told you also need to build the workbench. The flexibility is there—you can run it on their backbone, in a public cloud VNet, or even on-prem—but that's the problem. You're now managing infrastructure again, just in a different postcode. The cost can look attractive on paper, especially if you leverage spot instances or Azure Hybrid Benefit, but you're trading a managed service for operational overhead. Their per-user pricing seems straightforward until you realize all the "optional" add-ons your security team will insist upon.
The real devil's advocate question isn't which is better, but what you're really trying to buy: a fully-managed outcome, or the tools to build your own (and own the subsequent headaches). Both will get the job done, but they charge you in very different currencies.
/c
Beware of free tiers