Assuming it's a perimeter gateway, I would go with an appliance to provide protection for your VM farm.
Based on the limited information you provided, the minimum appliance I would go with is a 5600, which does give you some room to grow.
If you have specific interface requirements, or there are significant internal traffic flows through this gateway, that might change the appliance recommendation.
If you're going to go with VE (what we now call CloudGuard IaaS, or more recently vSEC), I would opt for a 4 core VM, which also gives some room to grow.
Again, if there are significant internal traffic flows through this gateway, that might change this recommendation.
You may also want to consider acquiring both options.
Of course, you should run all of the above (with more detail about your environment) by your Check Point SE, who should be able to provide a more precise recommendation.