NNetify

Netify provider research record

Cloudflare, Inc. (trading and profile display name: Cloudflare; SASE platform branded Cloudflare One, previously known as Cloudflare Zero Trust) SASE and SD-WAN profile

Publication state
Published
Reviewed
01/09/2026
Dataset
sha256-0f697fc7fc4690bb
Revision
d0cb15272c6bd7b3354bcf26

Overview

Rather than building a security platform and adding network reach, or building a network and adding security, Cloudflare started as one of the internet’s largest content-delivery and DDoS-mitigation networks (founded 2009, public since 2019 on NYSE: NET) and extended that same global infrastructure - every product running in every data centre, not routed to a handful of regional security hubs - into a full SASE platform. That architecture is the platform’s clearest, most defensible claim: Cloudflare states it delivers full SASE from more than 300 cities, which it describes as more than three times the footprint of other SASE vendors, with sub-50-millisecond reach to 95% of the world’s internet-connected population. Independent analyst recognition is real but specific in kind - Cloudflare was named a Visionary (not a Leader) in Gartner’s 2023 Magic Quadrant for Single-Vendor SASE (Cloudflare named a Visionary), was named a Strong Performer in The Forrester Wave™: Zero Trust Platforms, Q3 2023, and was named a Leader in a separate IDC assessment of worldwide edge delivery services - a strong but nuanced picture worth stating precisely rather than rounding up to a generic ‘industry leader’ claim. Compliance is well-documented at the corporate level (ISO 27001 and SOC 2 Type II since 2019, ISO 27701 as one of the first companies in the industry, PCI DSS Level 1) and Cloudflare for Government has held FedRAMP Moderate authorization since 2022, spanning more than 30 US-based data centres running the full authorized stack on a single control plane - a distinctive architecture compared to hyperscalers with only a handful of data centres in their FedRAMP boundary. FedRAMP High authorization was achieved and publicly announced in May 2025. Commercially, this is one of the few vendors in this category with real, published, self-service pricing - a free tier for up to 50 users and a flat $7 per user per month Pay-as-you-go tier with no bandwidth or per-connector charges, confirmed consistently across multiple independent sources - though Enterprise-tier bundled pricing is reported to obscure individual product costs once a buyer moves beyond self-service.

Direct comparison

Put Cloudflare, Inc. (trading and profile display name: Cloudflare; SASE platform branded Cloudflare One, previously known as Cloudflare Zero Trust) beside any provider.

Open the Netify comparison engine with both providers already selected. Every result is calculated from the public 40-capability evidence matrix.

Agent and MCP connectedprovider-comparison/1.0.0

No sign-in required. The shortlist remains shareable. Publishing and supplier access stay separate.

Find which providers match your exact needs

Move from a two-provider comparison into the live Netify RFP Builder and evaluate the wider market against your project.

Open the RFP Builder

Agent-accessible research

Ask the Cloudflare, Inc. (trading and profile display name: Cloudflare; SASE platform branded Cloudflare One, previously known as Cloudflare Zero Trust) research record

Answers are calculated from the published record below. Missing evidence remains unconfirmed and every result identifies its source revision.

Record summary

Current products
11
Capabilities
67
Coverage records
12
Service models
34
Compliance records
13
Integration records
20
Sector records
10
Evaluation records
49
Public sources
47

Products and delivery

11 records
ProductCategoryRelationshipDelivery modelTarget buyer
AI Gateway / Agents SDK / MCP securityAI agent infrastructure and governanceNativeCloud-delivered, developer-platform integratedDevelopers, security teams governing AI-agent traffic
CASBCloud Access Security BrokerNativeCloud-deliveredSecurity/compliance teams
Cloudflare AccessZTNANativeCloud-delivered, identity-based per-application accessAll buyers
Cloudflare OneConverged SASE platformNativeCloud-deliveredAll buyers
Cloudflare One ApplianceBranch/LAN on-rampNativePhysical hardware or virtual machine imageBranch/retail-site buyers
Cloudflare TunnelSite/application connectorNativeOutbound-only connector, no public IP exposure requiredBranch/site buyers, application owners
Data Loss PreventionDLPNativeCloud-deliveredSecurity/compliance teams
Email SecurityEmail/phishing protectionNativeCloud-deliveredSecurity teams
Remote Browser IsolationRBINativeCloud-deliveredSecurity teams, BYOD/high-risk-access scenarios
Secure Web GatewaySWGNativeCloud-deliveredAll buyers
WARP clientDevice agentNativeClient-based, Windows/macOS/Linux/iOS/AndroidManaged and BYOD devices

Capability evidence

67 records
Ai Automation14 records
CapabilitySupportConfidenceFreshnessQualification
AI assistant/copilotRequires ConfirmationUnresolvedCurrentCloudflare's confirmed AI investment is specifically focused on AI-agent infrastructure and governance (see rows below) rather than a general administrative copilot
AI data protection controlsSupportedUnresolvedCurrentDescribes Cloudflare's own internal practise specifically; the exact customer-facing feature parity with this internal approach wasn't independently itemised
Anomaly detectionRequires ConfirmationUnresolvedCurrentUnderlying ML/detection methodology not disclosed in detail
Automated policy recommendationUnknownUnresolvedCurrentNot confirmed
Automated remediationRequires ConfirmationUnresolvedCurrentScope specific to network/DDoS-layer threats rather than broader security-incident remediation
Capacity/path optimisationRequires ConfirmationUnresolvedCurrentTier/add-on status corroborated via third-party pricing analysis rather than a primary Cloudflare pricing page in this pass
Configuration generationUnknownUnresolvedCurrentNot confirmed
Digital experience diagnosticsRequires ConfirmationUnresolvedCurrentNot confirmed
Generative AI application controlsSupportedUnresolvedCurrentAs a 'first' claim, this is Cloudflare's own characterisation and wasn't independently verified against every competitor by Netify; the underlying MCP-security technology itself, however, is genuinely, specifically documented
Natural-language queryingUnknownUnresolvedCurrentNot confirmed
Report summarisationUnknownUnresolvedCurrentNot confirmed
Root-cause analysisRequires ConfirmationUnresolvedCurrentNot confirmed
Threat detection/classificationSupportedUnresolvedCurrentSame as above
User/entity behaviour analyticsRequires ConfirmationUnresolvedCurrentNot confirmed
Architecture15 records
CapabilitySupportConfidenceFreshnessQualification
5G/LTE supportRequires ConfirmationLowCurrentNot independently confirmed as a distinct, named capability in sources reviewed
Application identificationRequires ConfirmationMedium HighCurrentNative, implied via the confirmed single-pass inspection architecture referenced directly in Cloudflare's own Enterprise materials
Branch LAN/WLAN integrationRequires ConfirmationHighCurrentNative, confirmed specifically - the Cloudflare One Appliance 'serves as the primary on-ramp for local area networks (LANs) to connect directly to the Cloudflare global network'
Brownfield migration supportSupportedMedium HighCurrentNative, well-evidenced via a specific, independently-corroborated, quantified customer example - Delivery Hero replaced VPN access for 40,000 employees using the platform
Dynamic path selectionRequires ConfirmationMedium HighCurrentNative, via the confirmed Argo Smart Routing capability, which dynamically routes traffic across Cloudflare's own network for optimal performance
Edge form factorsRequires ConfirmationHighCurrentNative, confirmed - the Cloudflare One Appliance is available as either physical hardware or a virtual machine image
Forward error correction / packet duplicationRequires ConfirmationLowCurrentNot confirmed as a distinct named capability in sources reviewed
High availabilityRequires ConfirmationMedium HighCurrentNative, implied via the confirmed Anycast architecture, which inherently provides resilience by routing traffic to any available nearby data centre rather than a single fixed destination
LEO satellite supportUnknownLowCurrentUnknown - not found in sources reviewed
Local internet breakoutSupportedHighCurrentNative, and genuinely a core, structural characteristic of the platform's entire architecture - every data centre runs every function, meaning traffic is inspected and broken out locally by design rather than backhauled to a central hub
QoS and traffic engineeringRequires ConfirmationLow MediumCurrentNot independently confirmed as a distinct, named capability at the branch/last-mile level in sources reviewed
Segmentation / VRF capabilityUnknownLowCurrentUnknown - not found in sources reviewed
Supported WAN underlaysRequires ConfirmationMediumCurrentNot independently confirmed as a distinct, named multi-underlay optimisation capability in sources reviewed, consistent with the platform's confirmed 'light branch' philosophy - the Cloudflare One Appliance connects a site's LAN to Cloudflare's network rather than actively managing multiple WAN links at the branch
Virtual/cloud edge supportRequires ConfirmationHighCurrentNative, confirmed via the virtual-machine-image deployment option for the Cloudflare One Appliance
Zero-touch provisioningRequires ConfirmationMediumCurrentNot independently confirmed as a distinct, named zero-touch mechanism for the Cloudflare One Appliance specifically in sources reviewed, though the appliance is explicitly described as designed 'to automate branch office connectivity'
Core Capabilities15 records
CapabilitySupportConfidenceFreshnessQualification
Application-aware routingRequires ConfirmationMedium HighCurrentAdd-on cost outside Enterprise tier, per third-party pricing analysis
CASB - APIRequires ConfirmationLowCurrentNot confirmed as distinct from inline CASB
CASB - inlineRequires ConfirmationHighCurrentNone identified
Cloud firewall / cloud network securityRequires ConfirmationHighCurrentNone identified
DNS securitySupportedHighCurrentNone identified
Data loss preventionRequires ConfirmationHighCurrentNone identified
Digital experience monitoringRequires ConfirmationLow MediumCurrentA dedicated, named DEM product wasn't itemised
Firewall as a ServiceRequires ConfirmationMedium HighCurrentSpecific, distinctly-named FWaaS branding wasn't separately itemised from the broader Gateway/network security capability set
Multi-cloud networkingRequires ConfirmationLow MediumCurrentNamed hyperscaler-specific integration detail (comparable to some competitors' equivalent evidence) not itemised
SD-WANUnknownHighCurrentNot designed as a multi-link, path-optimisation-centric SD-WAN in the traditional sense; buyers specifically wanting deep WAN-link optimisation should confirm this fits their requirement directly
SaaS security postureRequires ConfirmationLowCurrentNot confirmed
Secure web gatewayRequires ConfirmationHighCurrentNone identified
Threat intelligenceSupportedHighCurrentNone identified
WAN optimisationRequires ConfirmationLow MediumCurrentTraditional WAN-optimisation techniques (e.g. named FEC/compression mechanisms) weren't itemised
ZTNARequires ConfirmationHighCurrentNone identified
Remote Access9 records
CapabilitySupportConfidenceFreshnessQualification
Clientless accessRequires ConfirmationUnresolvedCurrentNone identified
Contractors/third partiesRequires ConfirmationUnresolvedCurrentNone identified
Managed laptopsSupportedUnresolvedCurrentNone identified
Mobile devicesSupportedUnresolvedCurrentNone identified
Privileged accessUnknownUnresolvedCurrentNot confirmed
Remote browser isolationRequires ConfirmationHighCurrentNone identified
Remote browser isolationRequires ConfirmationUnresolvedCurrentNone identified
Unmanaged/BYOD devicesRequires ConfirmationUnresolvedCurrentNone identified
VDI environmentsUnknownUnresolvedCurrentNot confirmed
Reporting Analytics14 records
CapabilitySupportConfidenceFreshnessQualification
Application performanceRequires ConfirmationUnresolvedCurrentNot confirmed
Compliance reportingRequires ConfirmationUnresolvedCurrentNot confirmed
Custom reportsRequires ConfirmationUnresolvedCurrentNot itemised as a distinct reporting feature specifically
DLP eventsRequires ConfirmationUnresolvedCurrentNot confirmed
Executive dashboardRequires ConfirmationUnresolvedCurrentNot confirmed
Network healthSupportedUnresolvedCurrentNot confirmed
Raw log accessRequires ConfirmationUnresolvedCurrentzerometric.net/review/cloudflare-zero-trust/ (independent review, citing specific Log Explorer pricing)
Remote-user experienceRequires ConfirmationUnresolvedCurrentNot confirmed
SLA reportingRequires ConfirmationUnresolvedCurrentNot confirmed
Scheduled reportsUnknownUnresolvedCurrentNot confirmed
Security eventsRequires ConfirmationUnresolvedCurrentNot confirmed
Site and circuit performanceRequires ConfirmationUnresolvedCurrentNot confirmed
Threat reportingRequires ConfirmationUnresolvedCurrentNot confirmed
User experienceRequires ConfirmationUnresolvedCurrentNot confirmed

Geographic coverage

12 records
GeographyDelivery typeRelationshipConfidenceQualification
Africa coverageUnknown - Not Itemised In Sources Reviewed With Country-Level SpecificityUnknownLowUnknown - not itemised in sources reviewed with country-level specificity | Unknown | Not specified | Same as above | Not found in a Tier 1-2 source in this pass | Low | Same treatment as Middle East coverage above.
Asia-Pacific coverageConfirmed At A General Level - Cloudflare Maintains An Office In Singapore, And Pursued IRAP PROTECTED Assessment Specifically For Australia (Announced February 2025), Implying Genuine Regional Investment Beyond The General Global PoP FigureOwnedMediumConfirmed at a general level - Cloudflare maintains an office in Singapore, and pursued IRAP PROTECTED assessment specifically for Australia (announced February 2025), implying genuine regional investment beyond the general global PoP figure | Direct | Singapore office confirmed; Australia-specific government-security assessment confirmed as pursued | Full regional PoP breakdown not itemised | Medium | Real, specific, dated evidence for this region - stronger than the generic global-PoP-count claim alone.
Carrier interconnectsConfirmed At A General Level Via The Platform'S Described 13,000+ Networks, Implying Extensive Peering/Interconnection Relationships, Though Specific Named Carrier/Exchange Detail Wasn'T ItemisedOwnedMediumConfirmed at a general level via the platform's described 13,000+ networks, implying extensive peering/interconnection relationships, though specific named carrier/exchange detail wasn't itemised | Direct | Global | Specific named carrier/exchange list not itemised | Medium | A specific, large, quantified figure (13,000+ networks) confirmed directly, even without granular named-carrier detail.
China coverageUnknown - No China-Specific Data-Centre Or Licensed-PoP Detail Found In Sources ReviewedUnknownLowUnknown - no China-specific data-centre or licensed-PoP detail found in sources reviewed | Unknown | Not specified | No named China presence found | Not found in a Tier 1-2 source in this pass | Low | Evidence gap.
Data residency choicesNot Independently Confirmed As A Distinct, Named General-Commercial Data-Residency Architecture In Sources Reviewed, Beyond The Specific, Confirmed FedRAMP-Scoped US Data-Centre Boundary (Table 13)UnknownMediumNot independently confirmed as a distinct, named general-commercial data-residency architecture in sources reviewed, beyond the specific, confirmed FedRAMP-scoped US data-centre boundary (Table 13) | Confirmed for the FedRAMP-scoped boundary specifically; broader commercial data-residency architecture not detailed to the same depth | United States (FedRAMP boundary); other regions not itemised | General commercial data-residency options beyond the FedRAMP-specific boundary not independently detailed | Medium for the FedRAMP boundary; Low for general commercial data residency | Confirmed and specific for the FedRAMP-scoped government boundary; worth a direct follow-up for commercial buyers with data-residency requirements outside that specific context.
Latin America coverageUnknown - No Specific, Country-Level Evidence Found In This PassUnknownLowUnknown - no specific, country-level evidence found in this pass | Unknown | Not specified | Same as above | Not found in a Tier 1-2 source in this pass | Low | Same treatment as Middle East coverage above.
Middle East coverageUnknown - Not Itemised In Sources Reviewed With Country-Level SpecificityUnknownLowUnknown - not itemised in sources reviewed with country-level specificity | Unknown | Not specified | No named data centres found beyond the general 300+-city global figure | Not found in a Tier 1-2 source in this pass | Low | Evidence gap for country-level specificity, though the general global coverage claim is genuinely strong.
Private backboneNative, Confirmed - Cloudflare For Government Materials Specifically Describe 'A Single Control Plane On Our Private Backbone', And The Platform'S Broader Architecture Is Built On Cloudflare'S Own Owned Network InfrastructureOwnedHighNative, confirmed - Cloudflare for Government materials specifically describe 'a single control plane on our private backbone', and the platform's broader architecture is built on Cloudflare's own owned network infrastructure | Direct (owned) | Global | None identified | High | Confirmed directly - Cloudflare owns and operates its own network infrastructure rather than relying on hyperscaler-hosted infrastructure, a genuine, specific architectural distinction worth noting precisely.
Public cloud on-rampsNot Independently Confirmed With Specific Named Hyperscaler Detail In Sources ReviewedUnknownLowNot independently confirmed with specific named hyperscaler detail in sources reviewed | Unknown | Unknown | Not detailed | Not found in a Tier 1-2 source in this pass | Low | Evidence gap - see Table 3, 6 for the related finding.
SD-WAN gateways / cloud gatewaysSame Infrastructure As The Security PoPs Row Above - Every Cloudflare Data Centre Runs Every Function, So There Is No Separate, Distinct 'SD-WAN Gateway' TierOwnedHighSame infrastructure as the Security PoPs row above - every Cloudflare data centre runs every function, so there is no separate, distinct 'SD-WAN gateway' tier | Direct | Same as above | N/A - consistent with the platform's unified architecture | High | Consistent with the platform's confirmed 'every function in every data centre' architecture - genuinely simpler to describe than vendors with separate SD-WAN-specific and security-specific PoP tiers.
Security PoPs / service edgesConfirmed At A Specific, Repeated, And Consistent Level Across Multiple Primary Cloudflare Sources - More Than 300 Cities (330+ Per A Separate Enterprise-Page Figure), Each Running The Full SASE Stack, Described Directly As More Than Three Times The Footprint Of Other SASE VendorsOwnedHighConfirmed at a specific, repeated, and consistent level across multiple primary Cloudflare sources - more than 300 cities (330+ per a separate Enterprise-page figure), each running the full SASE stack, described directly as more than three times the footprint of other SASE vendors | Direct (Cloudflare-owned) | Global, 300+ to 330+ cities depending on the specific source and date | The exact figure varies slightly (300+ vs 330+) between different Cloudflare pages, consistent with a continuously-growing network rather than a discrepancy | High | One of the most specifically, consistently, and repeatedly confirmed coverage claims found across this entire profile series - directly comparable, checkable, and corroborated across multiple primary Cloudflare sources.
Sovereign/regional service optionsConfirmed And Genuinely Distinctive - Cloudflare For Government'S FedRAMP-Scoped Boundary Spans More Than 30 US-Based Data Centres, Each Running The Complete Authorized Stack On A Single Control Plane, Explicitly Contrasted By Cloudflare With Hyperscalers That 'May Only Have A Handful Of Data Centres Within Their FedRAMP Environment'OwnedHighConfirmed and genuinely distinctive - Cloudflare for Government's FedRAMP-scoped boundary spans more than 30 US-based data centres, each running the complete authorized stack on a single control plane, explicitly contrasted by Cloudflare with hyperscalers that 'may only have a handful of data centres within their FedRAMP environment' | Direct | United States (federal) | None identified for the confirmed scope specifically | High | A genuinely distinctive, specific, primary-sourced architectural claim - worth quoting directly, since the '30+ data centres versus a handful' framing is a real, checkable competitive difference rather than a generic marketing claim.

Service models

34 records

Other

Requires Confirmation

Not confirmed as a distinct named service in sources reviewed | Not confirmed | N/A | Not confirmed | Not confirmed | Not confirmed | Not found in a Tier 1-2 source in this pass | Evidence gap.

Other

Requires Confirmation

Implied via the confirmed, continuous, global threat-telemetry operation described in Cloudflare's own statistics (Table 3), though not itemised as a distinct, named customer-facing service with a specific figure | Not confirmed with a specific figure for a customer-facing service | N/A | Included for platform by inference | N/A | Not confirmed | Reasonable inference from the confirmed, massive-scale, continuous threat-telemetry operation; not independently confirmed as a distinct, named customer-facing monitoring product.

Other

Requires Confirmation

Not independently confirmed with specific named hyperscaler cloud-connectivity detail in sources reviewed | Unknown | Unknown | Unknown | Unknown | Not confirmed | Not found at this specificity in a Tier 1-2 source in this pass | Evidence gap - see Table 3 Multi-cloud networking finding.

Other

Requires Confirmation

Native, via the same confirmed single control plane | N/A | N/A | Included | Customer-managed | N/A | developers.cloudflare.com/cloudflare-one/ | Same evidence and finding as Configuration management above - a genuine, structural strength given the confirmed unified architecture.

Other

Supported

Yes, and genuinely the platform's core, default, and near-universal delivery model | None - fully cloud-native | Via the nearest of 300+ Anycast-routed data centres | Centralised, single control plane | All customers - this is the platform's foundational architecture, not an option among several | Low | N/A - default | The platform's clearest architectural strength: no on-premises hardware is required for the core security/networking functions at all.

Other

Requires Confirmation

Not confirmed as a distinct, named, customer-facing NOC service in sources reviewed | Not confirmed | Not itemised | Not confirmed | Customer configures policy; Cloudflare operates the underlying global network by inference | Not itemised with specific figures | Not found at this level of detail in a Tier 1-2 source in this pass | Evidence gap for a distinctly-named, customer-facing NOC service - Cloudflare's own network-operations capability is real and implied by its massive network scale, but a customer-facing product wasn't confirmed.

Other

Supported

Yes, via the Cloudflare One Appliance specifically for LAN on-ramping | Cloudflare One Appliance | Appliance → nearest Cloudflare data centre | Central control plane | Branch/retail sites | Low | Not itemised in detail | Real, confirmed capability, though narrower in scope than a traditional multi-link SD-WAN branch appliance.

Other

Supported

Yes | Cloudflare Access (browser-based) | Browser → nearest Cloudflare data centre | Central control plane | BYOD, contractors, third parties | Low | N/A | See Table 5 - a genuinely well-evidenced capability.

Other

Unknown

Centralised via one control plane spanning ZTNA, SWG, DLP, RBI, CASB and email security together | Cloudflare dashboard | Benefits from familiarity with identity-based, per-application policy models | Not itemised further | Positioned as simplified via the confirmed single-console architecture | None significant identified | developers.cloudflare.com/cloudflare-one/ | A genuine, confirmed strength - the breadth of capabilities managed through one console is a real, structural simplification relative to multi-product, acquisition-assembled competitors.

Other

Requires Confirmation

Not confirmed as a distinct named IR service with a specific SLA in sources reviewed | Not confirmed | N/A | Not confirmed | N/A | Not itemised with a specific figure | Not found at this level of detail in a Tier 1-2 source in this pass | Evidence gap for a distinctly-named IR service.

Other

Partner Delivered

Referenced generally via Cloudflare's own materials describing access to 'expert design partners' for customising complex SASE deployments, though not itemised as a distinct, separately-priced Professional Services product with a specific cost range | N/A | N/A | Referenced generally; not itemised with specific pricing | N/A | N/A | A real, referenced capability, though without the specific cost-range detail found for some other vendors profiled in this series.

Other

Requires Confirmation

Not confirmed as a distinct, named MSP/multi-tenant capability specifically for Cloudflare One in sources reviewed | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in a Tier 1-2 source in this pass | Evidence gap - worth a direct follow-up on Cloudflare's partner/MSP-tier capabilities specifically.

Other

Unknown

WARP client install or clientless Access, provisioned via the buyer's own external identity provider | Cloudflare dashboard + WARP client or browser | End-user self-install typical for this category | SSO-based provisioning via external IdP integration | Not itemised further | Requires a separate, existing IdP relationship - Cloudflare verifies but does not itself issue identities, per independent analysis | A specific, worth-noting architectural detail - buyers without an existing identity provider (Entra ID, Okta, Google) will need to establish one as a prerequisite.

Other

Requires Confirmation

Not confirmed as a distinct, named RMA/replacement programme for the Cloudflare One Appliance specifically in sources reviewed | Not found | Not found | Not confirmed | Not confirmed | Not confirmed | Not found in a Tier 1-2 source in this pass at this level of detail | Evidence gap - worth a direct follow-up, though the appliance's role is narrower (LAN on-ramping) than a full branch-router replacement in most competitors' architectures.

Other

Requires Confirmation

Not confirmed as a distinct, named, customer-facing SOC service in sources reviewed | Not confirmed | Not itemised | Not confirmed | Not confirmed | Not itemised with specific figures | Not found at this level of detail in a Tier 1-2 source in this pass | Evidence gap.

Other

Not Supported

Fully cloud-managed for the core platform, given no on-premises hardware is required for the primary security/networking functions | Cloudflare dashboard | Low, given the fully cloud-native architecture | Automatic, given the cloud-delivered model | Low | None significant identified | developers.cloudflare.com/cloudflare-one/ | A genuine, structural strength - the absence of on-premises hardware for the core platform functions inherently minimises this operational burden.

Other

Unknown

Unknown - not found in sources reviewed | Presumably dashboard/API | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in public sources reviewed | Evidence gap.

Other

Requires Confirmation

Native, via the confirmed single, central control plane spanning all deployment models | N/A | N/A | Included | Customer-managed via the central dashboard | N/A | developers.cloudflare.com/cloudflare-one/ | A genuine, confirmed unification point - one console across client, clientless, and branch-appliance deployment types alike (Table 6).

Other

Requires Confirmation

Not confirmed as a distinct named service in sources reviewed | Not confirmed | - | - | Buyers wanting partner-led implementation | Not fully detailed | Not found in a Tier 1-2 source in this pass | Evidence gap - worth a direct follow-up on Cloudflare's partner/channel delivery model specifically.

Other

Unknown

Unknown - not found in sources reviewed | Presumably Cloudflare dashboard | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in public sources reviewed | Evidence gap.

Other

Not Supported

Cloud-based, self-service, with no on-premises hardware required for the core platform | Cloudflare dashboard | General IT admin, given the confirmed self-service pricing/onboarding model | Not itemised in detail | Genuinely fast, per G2's aggregated user-review data reporting an average implementation time of one month | None significant identified | A specific, third-party-sourced implementation-speed figure (one month) that is genuinely fast relative to several other vendors profiled in this series.

Other

Requires Confirmation

Not applicable in the same sense as a last-mile-focused SD-WAN vendor, given Cloudflare's confirmed 'light branch, heavy cloud' architecture (Table 3, 4) - Cloudflare's own network is the backbone, not a last-mile circuit it manages on the customer's behalf | N/A | N/A | N/A | N/A | N/A | N/A | Structurally clear rather than a gap - this reflects the platform's confirmed architectural philosophy rather than missing evidence.

Other

Supported

Yes | Cloudflare One Appliance (virtual machine image) | VM → nearest Cloudflare data centre | Central control plane | Virtualised branch/data-centre environments | Low | Not itemised in detail | Confirmed as a supported form factor directly by Cloudflare.

Other

Unknown

Unknown - not found in sources reviewed | Not found | Not specified | Not confirmed | N/A | Not confirmed | Not found in a Tier 1-2 source in this pass | Evidence gap.

Other

Requires Confirmation

Not confirmed as a distinct, named MSP/co-management platform in sources reviewed | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in a Tier 1-2 source in this pass | Evidence gap, consistent with the Table 9 Multi-tenancy finding.

Other

Unknown

Unknown - not found in sources reviewed | Presumably Cloudflare dashboard | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in public sources reviewed | Evidence gap.

Other

Supported

Yes | Mix of WARP client, clientless Access, and Cloudflare One Appliance at branch sites | Mixed, all routed through the nearest Cloudflare data centre | Central control plane, genuinely unified across all deployment types | Most real-world enterprise estates | Low, given the confirmed single control plane across all deployment models | Delivery Hero's confirmed 40,000-employee VPN replacement evidences real hybrid/remote-access-focused deployment at scale | A genuine, architectural strength - unlike some competitors where hybrid deployment means managing two or more distinct consoles, Cloudflare's confirmed single-control-plane architecture applies uniformly across client, clientless, and branch-appliance paths alike.

Other

Requires Confirmation

Not confirmed as a distinct named support tier with specific TAM detail in sources reviewed | Not confirmed with specific figures | Not specified | Not confirmed | N/A | Not confirmed | Not found at this level of detail in a Tier 1-2 source in this pass | Evidence gap - worth a direct follow-up on Cloudflare's Enterprise-tier support structure specifically.

Other

Requires Confirmation

Not confirmed as a distinct, named Cloudflare-delivered managed-service product in sources reviewed | Not confirmed | - | - | Buyers wanting full outsourcing | Not confirmed | Not found in a Tier 1-2 source in this pass | Evidence gap.

Other

Requires Confirmation

Not confirmed as a distinct, named, customer-facing MDR product in sources reviewed | Not confirmed | Not itemised by location | Not confirmed | N/A | Not itemised with a specific figure | Not found as a customer-facing product in a Tier 1-2 source in this pass | Evidence gap.

Other

Requires Confirmation

Not independently confirmed as a distinct, named AI-diagnostics feature in sources reviewed for network/security troubleshooting specifically | Cloudflare dashboard | Not fully detailed | Not confirmed for general troubleshooting | Not itemised | Not itemised | Not found at this specificity in a Tier 1-2 source in this pass | Evidence gap - a specific, worth-flagging finding given Cloudflare's confirmed AI capabilities are focused specifically on AI-agent governance (Table 11) rather than general network diagnostics.

Other

Unknown

Via the Cloudflare One Appliance, described as designed 'to automate branch office connectivity' | Cloudflare dashboard (remote) | Low specialist requirement implied by the confirmed automation framing | Automation implied, specific zero-touch mechanism not independently detailed (Table 4) | Not itemised with a specific figure | None significant identified | Reasonable, though the specific onboarding-speed mechanics weren't independently detailed to the same depth as the general implementation-time figure above.

Other

Supported

Yes | Cloudflare WARP client | Client → nearest Cloudflare data centre | Central control plane | Managed-device remote/hybrid workforce | Low | N/A | Confirmed across five major operating systems (Table 5).

Other

Requires Confirmation

Yes, specifically for branch LAN on-ramping via the confirmed Cloudflare One Appliance | Cloudflare One Appliance (physical) | Appliance → nearest Cloudflare data centre | Central control plane | Branch offices needing to bridge a local LAN to the Cloudflare network | Low | Not itemised in detail | Confirmed, purpose-built, but narrower in scope than a traditional SD-WAN appliance - its role is LAN on-ramping specifically, not multi-link WAN optimisation.

Compliance and assurance

13 records
FrameworkScopeSupportReview dateQualification
DORA relevanceN/AUnknownNot statedUnknown - not found in sources reviewed | N/A | Not confirmed | EU financial services | Not found in a Tier 1-2 source in this pass | Not found | Evidence gap - worth flagging for financial-services sector suitability assessment (Table 14).
Data residencyUS federal boundary confirmed; general commercial architecture not detailedRequires ConfirmationNot statedPartial - confirmed and specific for the FedRAMP-scoped US federal boundary (30+ data centres); broader commercial data-residency architecture for non-federal buyers wasn't detailed to the same depth in this pass | US federal boundary confirmed; general commercial architecture not detailed | FedRAMP Moderate boundary | United States (federal boundary); other regions not itemised for general commercial buyers | Medium for the federal boundary; Low for general commercial data residency | Well-evidenced for the specific federal-boundary context; worth a direct question for commercial buyers with data-residency requirements outside the US federal context specifically.
Encryption/key managementPlatform-wideSupportedNot statedNative, and genuinely current - Cloudflare states it is the first SASE platform with post-quantum encryption across the full stack | Platform-wide | Post-quantum encryption (full-stack claim) | None identified | cloudflare.com/sase/ | 22 Jul 2026 | A specific, current, checkable claim, consistent with Cloudflare's broader, independently-verifiable public leadership in deploying post-quantum cryptography across its network at scale.
FedRAMPUS federal government (Moderate confirmed; High in progress as of the most recent primary source found)Requires ConfirmationNot statedModerate confirmed and held since 2022, with a genuinely distinctive architecture - more than 30 US-based data centres each running the complete authorized stack on a single control plane, spanning over 325 NIST 800-53 controls. FedRAMP High was publicly announced as an active pursuit in February 2025 (alongside IRAP PROTECTED for Australia and ENS for Spain); this research pass found no confirmation that full FedRAMP High authorization has since been achieved, so it should be treated as in-progress, not complete | US federal government (Moderate confirmed; High in progress as of the most recent primary source found) | FedRAMP Moderate (since 2022, 325+ NIST 800-53 controls); FedRAMP High (announced pursuit, Feb 2025) | US federal | 22 Jul 2026 | A genuinely strong, well-evidenced, and architecturally distinctive FedRAMP Moderate story - Cloudflare should be given real credit for both the authorization itself and the unusually broad data-centre footprint within its scope - while FedRAMP High should be presented precisely as an announced, in-progress pursuit rather than an achieved fact.
GDPRPlatform/company, EU/UK relevantSupportedNot statedSupported via a specific, named privacy certification rather than a bare compliance claim - Cloudflare was one of the first companies in the industry to achieve ISO 27701:2019 certification as both a data processor and controller, explicitly aligned to GDPR | Platform/company, EU/UK relevant | ISO 27701:2019 | EU/UK relevant | 22 Jul 2026 | A genuinely specific, credible, named-certification answer to GDPR-alignment - stronger evidence than the generic 'GDPR compliant' claims found for many other vendors profiled in this series.
HIPAAN/ARequires ConfirmationNot statedNot confirmed as a formal attestation in sources reviewed | N/A | Not confirmed | US healthcare-relevant | Not found in a Tier 1-2 source in this pass at sufficient specificity | Not found | Evidence gap - worth a direct follow-up given Cloudflare's broader scale and established compliance programme.
ISO 27001Platform/companyRequires ConfirmationNot statedCertified, and confirmed with a specific date - Cloudflare has been ISO 27001:2013 certified since 2019 | Platform/company | ISO 27001:2013 | None identified | 22 Jul 2026 | Well-evidenced with a specific, dated certification history.
Logging/auditabilityPlatformRequires ConfirmationNot statedNative, confirmed and specifically priced - the Log Explorer capability (Table 10) provides raw log access with a confirmed, specific pricing structure (first 10GB included, then $1/GB/month per independent pricing analysis) | Platform | Log Explorer | None identified | 22 Jul 2026 | Well-evidenced via a specific, named, and unusually precisely-priced feature - genuinely concrete evidence for this row.
NHS DSPT relevanceN/AUnknownNot statedUnknown - not found in sources reviewed | N/A | Not confirmed | UK | Not found in a Tier 1-2 source in this pass | Not found | Evidence gap - a direct follow-up question for UK healthcare-sector suitability assessment.
NIS2 relevanceN/AUnknownNot statedUnknown - not found in sources reviewed | N/A | Not confirmed | EU | Not found in a Tier 1-2 source in this pass | Not found | Evidence gap.
PCI DSSPlatform/companyUnknownNot statedCertified - Cloudflare engages a Qualified Security Assessor annually, evaluated as both a Level 1 Merchant and a Service Provider | Platform/company | PCI DSS (Level 1 Merchant and Service Provider) | None identified | 22 Jul 2026 | Well-evidenced, with the specific dual Level-1-Merchant-and-Service-Provider scope named directly.
SOC 2Platform/companyRequires ConfirmationNot statedCertified, and confirmed with a specific date - Cloudflare obtained initial SOC 2 Type II validation in 2019, issued annually thereafter, with a public SOC 3 summary available | Platform/company | SOC 2 Type II (annual); SOC 3 (public summary) | None identified | 22 Jul 2026 | Exceptionally well-evidenced - multiple primary Cloudflare sources describe the certification process, cadence, and even the specific customer-responsibility boundary in detail.
UK public sector frameworksUKUnknownNot statedUnknown - not found in sources reviewed | UK | Not confirmed | UK | Not found in a Tier 1-2 source in this pass | Not found | Evidence gap - worth a direct follow-up given Cloudflare's London office and broader European government-certification activity (ENS for Spain confirmed).

Integrations

20 records

AWS

Cloud · Unknown

Cloud | Not independently confirmed with specific technical integration detail for Cloudflare One specifically in sources reviewed | Unknown | Not specified | Not detailed | Not found at this specificity in this pass | Low-Medium | Evidence gap - see Table 3, 7 for the related finding.

Active Directory

Identity · Unknown

Identity | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.

CrowdStrike

EDR · Unknown

EDR | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.

Google Cloud

Cloud · Unknown

Cloud | Same treatment as AWS above | Unknown | Not specified | Not detailed | Not found at this specificity in this pass | Low-Medium | Same evidence gap as AWS above.

Google Workspace

Identity/Productivity · Native

Identity/productivity | Native, confirmed as a named, supported external identity provider | Bidirectional (auth) | Not specified | Same architectural note as Entra ID/Okta above | Medium-High | Same evidence quality as the Entra ID/Okta rows above.

Intune

MDM/UEM · Unknown

MDM/UEM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.

Jamf

MDM/UEM · Unknown

MDM/UEM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.

Microsoft 365

Productivity/SaaS · Unknown

Productivity/SaaS | Not separately confirmed as a distinct named integration in sources reviewed, though the confirmed CASB/SWG architecture would plausibly support this class of SaaS application | Unknown | Not specified | Not detailed | Not found as a distinct, named integration in this pass | Low-Medium | Reasonable architectural inference; not independently confirmed by name.

Microsoft Azure

Cloud · Unknown

Cloud | Same treatment as AWS above | Unknown | Not specified | Not detailed | Not found at this specificity in this pass | Low-Medium | Same evidence gap as AWS above.

Microsoft Defender

EDR · Unknown

EDR | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.

Microsoft Entra ID

Identity · Native

Identity | Native, confirmed as a named, supported external identity provider | Bidirectional (auth) | Not specified | Cloudflare verifies identity/device posture but does not itself issue identities - confirmed via independent, vendor-neutral analysis | Medium-High | Confirmed via an independent, vendor-neutral source naming this specific IdP directly.

Microsoft Sentinel

SIEM · Unknown

SIEM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.

Okta

Identity · Native

Identity | Native, confirmed as a named, supported external identity provider, alongside Entra ID and Google | Bidirectional (auth) | Not specified | Same architectural note as Entra ID above | Medium-High | Same evidence quality as the Entra ID row above.

Palo Alto Cortex

SIEM/XDR · Unknown

SIEM/XDR | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap (unsurprising, given the two companies are direct competitors).

REST API

Platform API · Api

Platform API | Native, and genuinely well-evidenced - Cloudflare's own materials directly describe the ability to 'compose your stack with APIs and Workers' to extend security policies and app delivery with code | Bidirectional | Not specified | Reinforced by Cloudflare's much broader, well-established developer-platform ecosystem (Workers, R2, D1, KV, Durable Objects, Queues, Vectorize) | High | Genuinely one of the strongest, most credible platform-programmability claims found across this profile series - Cloudflare's core business as a developer platform gives this claim real, structural weight beyond a typical SASE vendor's API story.

SCIM/SAML/OIDC

Identity Federation · Unknown

Identity federation | SAML/SSO implied via the confirmed multi-IdP support (Entra ID, Okta, Google) | Bidirectional (auth) | Not specified | Not detailed by specific protocol name beyond the general external-IdP framing | Medium | Reasonable inference from the confirmed multi-IdP support; specific protocol names weren't spelled out.

ServiceNow

ITSM · Unknown

ITSM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.

Splunk

SIEM · Unknown

SIEM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap - a specific, worth-flagging gap given how common this pairing was for other vendors reviewed in this profile series.

Syslog

Log Export · Unknown

Log export | Not separately itemised by name in sources reviewed, though implied by the confirmed Log Explorer capability (Table 10) | Unknown | Not specified | Not detailed | Not found explicitly by name | Low-Medium | Reasonable to assume given the confirmed Log Explorer/log-export architecture, not independently confirmed by name.

Terraform

Infrastructure-As-Code · Api

Infrastructure-as-code | Not independently confirmed as a distinct, named integration in sources reviewed, though Cloudflare's broader, well-established developer-platform (Workers, APIs) makes this plausible | Unknown | Not specified | Not detailed | Not found as a distinct, named integration in this pass | Low-Medium | Reasonable inference from Cloudflare's broader, well-documented developer-platform ecosystem; not independently confirmed by name for Cloudflare One specifically.

Sector evidence

10 records

Education

Not Supported

Unknown - not assessed, no case study found | Not assessed | Not assessed | None found | N/A | No case study found | Evidence gap.

Named evidence
None found
Case study strength
None

Energy/utilities

Not Supported

Unknown - not assessed, no case study found | Not assessed | Not assessed | None found | N/A | No case study found | Evidence gap.

Named evidence
None found
Case study strength
None

Financial services

Not Supported

Unknown - not assessed, no PCI-DSS-specific named case study or DORA-specific certification found for this sector, despite the platform's general PCI DSS Level 1 certification (Table 13) | DLP, CASB, RBI plausibly relevant | PCI DSS confirmed at the platform level generally; DORA not confirmed | None found with specific detail in this research pass | N/A | General PCI certification confirmed; sector-specific named case study or DORA status not found | The confirmed platform-level PCI DSS certification is a real, relevant signal for this sector, even without a named financial-services case study to reinforce it.

Named evidence
None found with specific detail in this research pass
Case study strength
None

Government/public sector

Unknown

Strong fit, extensively evidenced | FedRAMP Moderate authorization with a genuinely distinctive, broad data-centre footprint; CISA partnership for .gov DNS security | FedRAMP Moderate (since 2022); FedRAMP High in progress | Berkeley Lab (named, chose Cloudflare as its zero-trust security partner, per Cloudflare's own materials); FBI and US Department of State referenced directly by Cloudflare's CEO as long-standing, technically demanding agency customers | US federal specifically well-evidenced; international government certification pursuits (IRAP for Australia, ENS achieved for Spain) demonstrate real, current international investment | FedRAMP High not yet confirmed achieved | Genuinely one of the best-evidenced sectors in this entire profile - a named national laboratory customer, direct CEO references to specific, technically sophisticated federal agencies, and a distinctive, primary-sourced FedRAMP architecture all combine into a credible, specific public-sector story.

Named evidence
Berkeley Lab (named, chose Cloudflare as its zero-trust security partner, per Cloudflare's own materials); FBI and US Department of State referenced directly by Cloudflare's CEO as long-standing, technically demanding agency customers
Case study strength
Strong

Healthcare/NHS

Requires Confirmation

Unknown - not assessed, no case study found, no formal HIPAA attestation confirmed | ZTNA, RBI plausibly relevant | HIPAA not confirmed as a formal attestation | None found in this research pass | N/A | No case study found, no formal HIPAA attestation | Evidence gap - do not claim healthcare/NHS suitability without direct vendor confirmation, despite Cloudflare's broader compliance programme being genuinely strong overall.

Named evidence
None found in this research pass
Case study strength
None

Hospitality

Not Supported

Unknown - not assessed, no case study found | Not assessed | Not assessed | None found | N/A | No case study found | Evidence gap.

Named evidence
None found
Case study strength
None

Manufacturing

Not Supported

Unknown - not assessed, no case study found | Not assessed in detail | Not assessed | None found | N/A | No case study found | Evidence gap.

Named evidence
None found
Case study strength
None

Professional services

Unknown

Conditional - one named, if thinly detailed, case reference exists | Not assessed in detail | Not assessed | Applied Systems (referenced specifically for 'legacy vendor costs avoided', per Cloudflare's own SASE product page) | N/A | Thin detail beyond the named customer and general cost-avoidance framing | A real, named customer reference, though with less quantified detail than the government-sector evidence above.

Named evidence
Applied Systems (referenced specifically for 'legacy vendor costs avoided', per Cloudflare's own SASE product page)
Case study strength
Strong

Retail

Not Supported

Unknown - not assessed, no case study found | Branch/site connectivity via the Cloudflare One Appliance plausibly relevant | PCI DSS confirmed at the platform level generally | None found | N/A | No case study found | Evidence gap, though the confirmed PCI DSS certification is directly relevant to this sector's typical requirements.

Named evidence
None found
Case study strength
None

Transport/logistics

Not Supported

Unknown - not assessed, no case study found | Not assessed | Not assessed | None found | N/A | No case study found | Evidence gap.

Named evidence
None found
Case study strength
None

Case studies

3 records
Customer
Named - Applied Systems
Sector and geography
Insurance technology · Not specified
Estate
Not quantified; Not quantified
Outcome
Referenced specifically for 'legacy vendor costs avoided', per Cloudflare's own SASE product page, without further quantified detail in the source reviewed

Named - Applied Systems | Insurance technology | Not specified | Not quantified | Not quantified | Not itemised in detail | Cloudflare One | Not itemised | Not itemised | Referenced specifically for 'legacy vendor costs avoided', per Cloudflare's own SASE product page, without further quantified detail in the source reviewed | Low-Medium - a real, named customer reference, but with minimal supporting detail beyond the brief cost-avoidance framing found in this pass | The thinnest of the three case studies captured here - a real, named reference worth a direct follow-up for fuller detail, since the source reviewed provided only a brief framing rather than a detailed account.

Customer
Named - Delivery Hero
Sector and geography
Food delivery / technology · Not specified (global operations implied by the company's known international footprint)
Estate
40,000 employees; Not specified
Outcome
Successfully replaced VPN access for 40,000 employees using Cloudflare One

Named - Delivery Hero | Food delivery / technology | Not specified (global operations implied by the company's known international footprint) | 40,000 employees | Not specified | Needed to replace legacy VPN infrastructure for a very large, distributed workforce | Cloudflare Access (ZTNA), Cloudflare WARP client | Client-based remote access, replacing VPN concentrators | Not itemised | Successfully replaced VPN access for 40,000 employees using Cloudflare One | Medium-High - a specific, large, named-scale figure (40,000 employees) for a real, well-known named company, though sourced via an independent review rather than a primary Cloudflare case study page in this pass | Genuinely one of the more specific, credible quantified examples found for Cloudflare in this research pass - worth a direct follow-up to locate Cloudflare's own primary-sourced version of this case study for stronger citation weight.

Customer
Named - Lawrence Berkeley National Laboratory ('Berkeley Lab')
Sector and geography
Government/public sector (federally-funded research) · United States
Estate
Not quantified; Not quantified
Outcome
Described directly by Cloudflare as having 'chosen Cloudflare as its zero trust security partner', without further quantified detail in the source reviewed

Named - Lawrence Berkeley National Laboratory ('Berkeley Lab') | Government/public sector (federally-funded research) | United States | Not quantified | Not quantified | Needed a zero-trust security partner for a technically sophisticated federal research environment | Cloudflare Zero Trust / Cloudflare One | Not itemised in detail | Not itemised | Described directly by Cloudflare as having 'chosen Cloudflare as its zero trust security partner', without further quantified detail in the source reviewed | Medium - a named, credible, technically sophisticated customer directly referenced by Cloudflare's own federal-government materials, though without a quantified outcome metric in the specific source reviewed | A real, named, credible public-sector reference, reinforcing the broader government-sector strength evidenced in Table 13/14, though thinner on quantified specifics than the Delivery Hero example above.

Netify evaluation record

49 records

Summary

Strength | Current, specific, technically detailed leadership in AI-agent and MCP-server security - a dated (April 2025 and April 2026) pair of detailed technical blog posts describe both the customer-facing capability and Cloudflare's own internal governance practise for the same emerging risk category | Buyers with an active or emerging AI-agent security requirement get a vendor with genuinely current, demonstrated technical depth rather than a generic marketing claim | Best: organisations actively deploying AI agents/MCP-based tooling. Less relevant: buyers with no near-term agentic-AI initiative | High | Genuinely one of the best-evidenced, most currently-dated AI-security capability areas found across this entire profile series, reinforced by credible 'eats its own cooking' evidence of Cloudflare's own internal practise.

Buyers with an active or emerging AI-agent security requirement get a vendor with genuinely current, demonstrated technical depth rather than a generic marketing claim

Summary

Global multinational | Strong fit, evidenced | The confirmed 300+-city, sub-50ms-to-95%-of-users architecture is directly, structurally suited to this buyer profile, reinforced by named international government-certification pursuits (IRAP for Australia, ENS achieved for Spain) | Needs Netify/buyer to verify specific-country coverage directly for any highly specific regional requirement | Custom Enterprise/Contract pricing | Table 7, 13 findings | Genuinely one of the strongest architectural fits for this buyer profile across the vendors profiled in this series, given the specific, repeated, and consistent global-coverage claims.

Summary

Sector fit | Government/public sector is genuinely the best-evidenced sector in this profile, combining a specific, dated FedRAMP architecture with named customer references (Berkeley Lab, and CEO-referenced FBI/State Department relationships); professional services has one real but thin named reference (Applied Systems); all other sectors lack detailed, quantified case-study evidence in this research pass. | Table 14 | High for government/public sector; Low for other sectors | Do not extend the strong government-sector evidence into an assumption of equal strength in sectors like healthcare or manufacturing, where no detailed case-study evidence was found in this pass.

Do not extend the strong government-sector evidence into an assumption of equal strength in sectors like healthcare or manufacturing, where no detailed case-study evidence was found in this pass.

Summary

Highly distributed branch estate | Conditional fit | The confirmed Cloudflare One Appliance supports LAN on-ramping for branch/retail sites, but the platform's deliberately different 'light branch, heavy cloud' philosophy (Table 3, 4) means buyers specifically wanting deep, multi-link WAN-optimisation at each branch should confirm this fits their requirement directly | Zero-touch provisioning implied but not independently confirmed with specific mechanism detail (Table 4) | Not itemised | Table 4, 6 findings | A genuinely nuanced finding: real, confirmed branch connectivity exists, but it is architecturally different from - not a direct substitute for - a traditional, appliance-centric, multi-link SD-WAN deployment; worth confirming this distinction matches the buyer's actual requirement.

Summary

Firewall consolidation | Not evidenced via a named case study specifically framed around firewall consolidation in sources reviewed | Existing firewall rules/policies migrated into the unified Cloudflare One policy model | IT/security team | Not itemised | Not quantified with a specific timeline | Policy translation errors during cutover (not specifically addressed in sources reviewed) | Not detailed | The underlying architectural capability (unified Gateway/network security) is confirmed, though a named customer case study specifically about firewall consolidation wasn't found in this pass.

Summary

Reporting reality | Genuinely strong specifically for network health and security-event visibility, reinforced by a named, publicly-verifiable product (Cloudflare Radar) and massive-scale, specifically-quantified threat statistics; weaker on application-performance, user-experience/DEM, executive dashboards, and compliance-specific reporting, none of which were confirmed as distinct, named products in this research pass. | Table 10 | High for network health/security events; Low for DEM/executive/compliance reporting | Present the network-health and security-visibility strengths specifically rather than imply comprehensive reporting maturity across every category.

Present the network-health and security-visibility strengths specifically rather than imply comprehensive reporting maturity across every category.

Summary

Mid-market | Good fit | The confirmed self-service pricing model remains accessible into the low-hundreds-of-users range before a Contract-tier conversation becomes necessary, per independent pricing analysis | Benefits from an existing identity-provider relationship (Entra ID, Okta, or Google), a confirmed prerequisite | Linear per-user cost scaling until the Contract tier, per independent analysis | Real, credible fit, tempered by the confirmed linear-scaling commercial structure worth budgeting for explicitly as headcount grows.

Summary

Biggest operational advantage | Genuinely rare, transparent, self-service pricing combined with a confirmed one-month average implementation time - buyers can move from evaluation to deployment with real, checkable numbers at every step, without an extended sales engagement, for at least the self-service tier. | Table 9, 16, 19 | High | Directly quotable with the specific, consistently-corroborated figures for credibility - among the strongest commercial-transparency findings across this entire profile series.

Directly quotable with the specific, consistently-corroborated figures for credibility - among the strongest commercial-transparency findings across this entire profile series.

Summary

MPLS to SD-WAN migration | Not evidenced via a named case study specifically describing MPLS retirement in sources reviewed, consistent with the platform's different, cloud-centric architectural philosophy (Table 3, 4) rather than a traditional multi-link SD-WAN migration story | Existing MPLS/WAN infrastructure | Not itemised | Not itemised | Not quantified | Not itemised | Not detailed | This scenario is architecturally less central to Cloudflare's own positioning than for traditional SD-WAN-first vendors, given the platform's confirmed 'light branch, heavy cloud' philosophy - worth confirming directly whether this specific migration path fits a buyer's requirement.

Summary

Deployment & Ops | A 2026 Forrester Total Economic Impact study commissioned around Cloudflare One reports specific, quantified outcomes - 35% time savings on security and IT management, a 90% reduction in VPN-related IT tickets, and approximately $5.2 million in connectivity-related savings. | G2's aggregated user-review data reports an average implementation time of one month, which is fast relative to several other vendors profiled in this series, but also reports 'perceived cost' at the highest band on G2's scale - worth setting buyer expectations around both facts together.

Summary

Global branch rollout | Architecturally well-suited given the confirmed 300+-city network and the Cloudflare One Appliance's LAN on-ramping role, though no named, quantified global branch-rollout case study was found in this pass specifically | Existing branch network/WAN infrastructure to integrate or replace | Not itemised | Not itemised | Not quantified | Not itemised | Not detailed | Real, credible architectural fit for this scenario, though a specific, named, quantified branch-rollout case study (comparable to some competitors' equivalent evidence) wasn't found in this pass.

Summary

Scope & Boundaries | A specific, current, first-of-its-kind claim to secure MCP server connections for AI agents, reinforced by detailed technical documentation of Cloudflare's own internal agentic-AI security practices - genuinely ahead of the curve on a risk category most competitors are still framing in general terms. | Cloudflare, Inc. reported a net loss for fiscal year 2025 (operating income of approximately -$207 million, net income of approximately -$102 million) despite $2.168 billion in revenue and 30% year-over-year growth - a normal pattern for a hypergrowth public technology company, but a factual data point worth noting rather than assuming unlimited financial runway for every product line indefinitely.

Summary

Commercials | Genuinely rare, transparent, self-service list pricing (free up to 50 users, then $7/user/month flat, no bandwidth or per-connector fees) - a real, checkable, buyer-friendly differentiator in a category where most vendors publish nothing. | An independent Enterprise-customer account describes being told that Cloudflare's larger Enterprise deals are calculated as a single bundled price with no fixed cost broken out per component - meaning the pricing transparency that exists at the self-service tier does not necessarily carry through to large, negotiated Enterprise contracts.

Summary

Merger/acquisition integration | Not documented via a named M&A-specific scenario in sources reviewed | Not itemised | Not itemised | Not itemised | Not quantified | Not itemised | Not detailed | Evidence gap - no named customer scenario specifically describing M&A-driven integration was found in this pass.

Summary

Lean IT team | Strong fit, evidenced | The confirmed single control plane spanning all deployment models, the fully cloud-native architecture requiring no on-premises hardware for core functions, and the confirmed one-month average implementation time together support a genuinely low-operational-burden story | Minimal training investment implied by the confirmed self-service model and fast implementation time | Not assessed | Table 6, 9, 15 findings | Genuinely one of the strongest 'lean IT team' fits found across this profile series - the combination of architectural simplicity and confirmed implementation speed is real, specific, and credible evidence.

Summary

Where does it stand out? (mandatory) | A structurally distinctive architecture running every function in every one of 300+ data centres rather than a limited set of regional hubs; genuinely rare, transparent, consistently-corroborated self-service pricing; and current, specific, technically detailed leadership in AI-agent and MCP-server security, reinforced by credible evidence of Cloudflare's own internal practise. | Tables 3, 7, 11, 16, 19 | High | These are the claims Netify can make most confidently and specifically to buyers, each backed by named, dated, and - for the pricing claim specifically - unusually broad independent corroboration.

These are the claims Netify can make most confidently and specifically to buyers, each backed by named, dated, and - for the pricing claim specifically - unusually broad independent corroboration.

Summary

Questions to ask before recommending it | 1) What is the current status of the FedRAMP High authorization publicly announced as an active pursuit in February 2025? 2) Can Cloudflare provide a fully itemised, per-product cost breakdown for our specific Enterprise requirements, rather than a single bundled figure? 3) For our specific CASB/DLP inspection-depth requirements, how does Cloudflare's current stack compare directly to more established competitors? 4) Which specific MCP-server security capabilities are generally available today versus still rolling out? | Synthesis of Tables 13, 16, 17, 19 | High | A direct, reusable question set for Netify's advisory conversations with buyers considering Cloudflare.

A direct, reusable question set for Netify's advisory conversations with buyers considering Cloudflare.

Summary

Global fit | Genuinely one of the strongest global-fit findings across this entire profile series - the confirmed, repeated, specific 300+-city, sub-50ms-to-95%-of-users architecture is structurally, directly suited to globally distributed organisations, reinforced by named international government-certification pursuits (IRAP for Australia, ENS achieved for Spain). | Table 7, 13, 15 | High | Present this global-coverage strength with genuine confidence - it is specific, repeated, and consistently confirmed across multiple primary Cloudflare sources, a stronger evidentiary picture than for most other vendors profiled in this series.

Present this global-coverage strength with genuine confidence - it is specific, repeated, and consistently confirmed across multiple primary Cloudflare sources, a stronger evidentiary picture than for most other vendors profiled in this series.

Summary

SSE deployment to remote users | Client-based (WARP) or clientless rollout to remote/mobile users, provisioned via the buyer's own external identity provider (Table 5, 9) | IdP integration (Entra ID, Okta, or Google) a documented prerequisite | End-user self-install typical for WARP | Not itemised | One-month average implementation time confirmed via aggregated user-review data (Table 9) | Requires an existing IdP relationship as a prerequisite | Not detailed | Well-evidenced via both the confirmed general implementation-speed figure and the specific Delivery Hero example above.

Summary

Cloud-first organisation | Good fit | The platform's entire architecture is fully cloud-native by design, with no on-premises hardware required for the core security/networking functions at all | None significant identified for the core platform | Not assessed | Table 6, 9 findings | A genuine, structural strength - this buyer profile is arguably the platform's most natural fit, given the architecture requires no on-premises infrastructure investment at all for the core platform.

Summary

Limitation | Independent analyst recognition places Cloudflare as a Visionary, not a Leader, in Gartner's 2025 Magic Quadrant for SASE Platforms - a real, specific, worth-stating distinction for buyers weighing analyst-quadrant positioning directly as part of their evaluation criteria | Buyers specifically prioritising Leader-quadrant analyst validation get a materially different signal than for some competitors with a confirmed Leader placement | Affects buyers evaluating primarily on Gartner Magic Quadrant standing specifically; less relevant to buyers weighing Cloudflare's own specific, checkable technical claims on their own merits | cloudflare.com/sase/ | High (directly confirmed by Cloudflare's own materials, which state the Visionary placement plainly) | Netify should present this precisely rather than rounding up - 'Visionary for completeness of vision and ability to execute' is Cloudflare's own accurate characterisation of its placement, not a vague or generic strength claim.

Buyers specifically prioritising Leader-quadrant analyst validation get a materially different signal than for some competitors with a confirmed Leader placement

Summary

What implementation challenges should buyers expect? (mandatory) | Expect genuinely fast, self-service onboarding for smaller deployments, backed by a confirmed one-month average implementation time - but budget for a real, existing identity-provider relationship as a confirmed prerequisite, since Cloudflare verifies identity and device posture but does not itself issue identities. For large Enterprise deals, expect a single bundled quote rather than itemised per-component pricing, and push directly for a breakdown if that matters to your procurement process. | Tables 9, 16 | High | Each expectation is traceable to a specific, evidenced finding elsewhere in this profile.

Each expectation is traceable to a specific, evidenced finding elsewhere in this profile.

Summary

Most credible differentiator | A structurally distinctive, Anycast-based architecture running every security and networking function in every one of 300+ data centres, rather than a limited set of regional inspection hubs - a genuine, checkable, foundational design principle rather than a marketing claim layered onto a more conventional architecture. | Tables 3, 4, 7, 19 | High | This is the single sentence Netify's comparison engine could most confidently quote for Cloudflare specifically.

This is the single sentence Netify's comparison engine could most confidently quote for Cloudflare specifically.

Summary

Regulated organisation | Strong fit for US federal/public sector specifically; conditional for other regulated sectors | FedRAMP Moderate (since 2022, with a distinctive, broad data-centre footprint), ISO 27001, ISO 27701, SOC 2 Type II, and PCI DSS are all confirmed and well-evidenced with specific dates and scope; FedRAMP High is confirmed only as an announced, in-progress pursuit, and HIPAA, DORA and UK-framework status were not confirmed | Buyer must independently verify sector-specific compliance status directly with Cloudflare for anything outside the confirmed scope | Not assessed | Table 13 findings | A genuinely strong overall compliance foundation - among the best-evidenced in this profile series for the certifications that were confirmed - tempered by the specific, worth-flagging gap around FedRAMP High's current (not-yet-confirmed-achieved) status and the unconfirmed HIPAA/DORA/UK-framework certifications.

Summary

Limitation | FedRAMP High was publicly announced as an active pursuit in February 2025; this research pass found no confirmation that full authorization has since been achieved | Federal buyers needing FedRAMP High specifically today cannot currently verify this from public sources and must confirm status directly before relying on it for a compliance-sensitive decision | Affects US federal buyers needing the High baseline specifically; FedRAMP Moderate is confirmed and well-evidenced for buyers who only need that level | Medium-High (confident about the announcement and the absence of a subsequent confirmation in this pass) | A precise, specific distinction worth stating clearly - FedRAMP Moderate is genuinely strong and current; FedRAMP High should be presented as an announced, in-progress pursuit rather than an achieved fact.

Federal buyers needing FedRAMP High specifically today cannot currently verify this from public sources and must confirm status directly before relying on it for a compliance-sensitive decision

Summary

Where does it fall behind competitors? (mandatory) | Gartner places Cloudflare as a Visionary, not a Leader, in the 2025 SASE Platforms Magic Quadrant; FedRAMP High is confirmed only as an announced, in-progress pursuit rather than an achieved authorization; Enterprise-tier pricing reportedly loses the itemised transparency found at the self-service tier; and the platform's core positioning favours single-vendor consolidation over the explicitly-marketed best-of-breed integration model some competitors offer. | Tables 13, 16, 17, 19 | Medium-High | Named specifically and evidenced, not a generic hedge - each of these is a real, checkable, worth-stating distinction rather than a vague weakness.

Named specifically and evidenced, not a generic hedge - each of these is a real, checkable, worth-stating distinction rather than a vague weakness.

Summary

Limitation | An independent Enterprise-customer account describes Cloudflare's larger, negotiated Enterprise deals being calculated and presented as a single bundled price with no fixed cost broken out per component | Buyers negotiating a large Enterprise contract may not get the same itemised cost transparency that makes the self-service tiers genuinely attractive | Affects large Enterprise buyers most specifically; smaller buyers on the self-service tiers are unaffected, given the confirmed transparency there | Medium (single independent account, though specific and plausible) | A real, specific, worth-flagging nuance - Netify should not extend the genuine self-service pricing transparency into an assumption that Enterprise-tier quotes will be equally itemised.

Buyers negotiating a large Enterprise contract may not get the same itemised cost transparency that makes the self-service tiers genuinely attractive

Summary

Security & Analytics | A confirmed, comprehensive, single-console capability set - Access (ZTNA), Secure Web Gateway, Cloudflare Tunnel, DLP, Remote Browser Isolation, CASB, and email security are all named directly as part of one unified control plane, not a patchwork of separately-acquired products. | Independent analyst recognition situates Cloudflare specifically as a Visionary in Gartner's SASE Magic Quadrant, not a Leader - a real, worth-stating distinction for buyers weighing analyst-quadrant positioning specifically as part of their evaluation criteria.

Summary

AI reality | Genuinely one of the strongest, most current, most specifically-evidenced AI capability areas found across this entire profile series - the confirmed, dated, technically detailed MCP-server security capability and Cloudflare's own internal AI-agent governance practise both give this claim real, checkable weight distinct from generic 'AI-powered' marketing language found elsewhere. | Table 11 | High | Represent this AI-agent-security capability with genuine confidence - it is unusually well-corroborated, current, and specifically targeted at a real, emerging risk category rather than a vague, generic AI claim.

Represent this AI-agent-security capability with genuine confidence - it is unusually well-corroborated, current, and specifically targeted at a real, emerging risk category rather than a vague, generic AI claim.

Summary

Strength | Real, transparent, consistently-corroborated self-service pricing - a genuine free tier for up to 50 users and a flat $7/user/month rate with no bandwidth or per-connector fees, confirmed identically across six or more independent sources | Buyers can self-serve a confident budget estimate without an extended sales engagement, a genuine rarity in this category | Best: SMEs, mid-market buyers, and any organisation wanting to self-shortlist based on real numbers. Less relevant: large Enterprise buyers, where bundled pricing reportedly obscures per-component costs | High | One of the strongest, most independently-corroborated commercial-transparency findings across this entire profile series - worth highlighting directly and specifically to any budget-conscious buyer.

Buyers can self-serve a confident budget estimate without an extended sales engagement, a genuine rarity in this category

Summary

Questions Netify still cannot verify | Current FedRAMP High status specifically; HIPAA, DORA, NIS2, and UK-framework status; specific, named support-tier SLA figures; hardware pricing for the Cloudflare One Appliance; named, quantified customer case studies for large-scale, complex branch rollouts specifically; and full CASB/API-mode and DSPM/SSPM capability detail. | Synthesis of Tables 3, 8, 13, 16, 17 | N/A - explicitly unresolved | This list should drive the next follow-up (a direct Cloudflare briefing) before this profile is considered fully closed out, particularly the FedRAMP High status question given its direct relevance to federal-buyer recommendations.

This list should drive the next follow-up (a direct Cloudflare briefing) before this profile is considered fully closed out, particularly the FedRAMP High status question given its direct relevance to federal-buyer recommendations.

Summary

Overall Netify Assessment | Cloudflare One's most credible, best-evidenced strengths flow directly from the company's underlying identity as one of the internet's largest existing networks, extended into SASE rather than built as a security product first - a structurally distinctive, checkable architecture (300+ cities, every function everywhere), genuinely rare commercial transparency at the self-service tier, and current, specific, technically demonstrated leadership in AI-agent security. The profile is honest about real, specific gaps: a Visionary rather than Leader analyst placement, an in-progress rather than achieved FedRAMP High authorization, thinner Enterprise-tier pricing transparency, and a core architectural philosophy favouring single-vendor consolidation over the best-of-breed flexibility some competitors explicitly offer. This profile is solid enough to support initial shortlist guidance for latency-sensitive, globally distributed, and AI-agent-security-focused buyers specifically, and is genuinely one of the better-evidenced profiles in this series overall given Cloudflare's substantial public documentation footprint - though the FedRAMP High and Enterprise-pricing questions should be closed out directly before use in a high-stakes federal or large-Enterprise procurement decision. | Whole profile | High overall | Recommend direct Cloudflare engagement to confirm current FedRAMP High status and obtain itemised Enterprise pricing before this profile supports a high-stakes federal or large-Enterprise procurement decision.

Recommend direct Cloudflare engagement to confirm current FedRAMP High status and obtain itemised Enterprise pricing before this profile supports a high-stakes federal or large-Enterprise procurement decision.

Summary

Procurement watch-out | Cloudflare's core architectural positioning centres on single-vendor platform consolidation rather than explicitly-marketed best-of-breed integration with named third-party SSE vendors, a genuine, worth-stating contrast to competitors profiled elsewhere in this series that explicitly support and market multi-vendor SASE pairings | Buyers specifically wanting to keep an existing, separate SSE vendor while adopting a different piece of the SASE stack should confirm Cloudflare's current position on this directly rather than assume the same flexibility found in some competitors | Most relevant to buyers with an existing, separate SSE investment they want to retain rather than replace | Medium-High | A specific, evidenced architectural-philosophy distinction - not a criticism, but a genuine difference in strategic positioning worth surfacing directly to any buyer comparing Cloudflare against a best-of-breed-oriented competitor.

Buyers specifically wanting to keep an existing, separate SSE vendor while adopting a different piece of the SASE stack should confirm Cloudflare's current position on this directly rather than assume the same flexibility found in some competitors

Summary

Remote-user-heavy organisation | Strong fit, extensively evidenced | A specific, independently-corroborated, large-scale customer example (Delivery Hero, 40,000 employees migrated off VPN) directly evidences this exact use case at genuine scale | Requires an existing identity-provider relationship as a confirmed prerequisite | Not assessed | Table 4, 5 findings | One of the best-evidenced buyer-profile fits in this entire profile - a specific, large, named-scale customer example is genuinely compelling, concrete evidence.

Summary

When would Netify recommend looking elsewhere? (mandatory) | When a buyer specifically requires a confirmed Gartner Leader-quadrant placement rather than Visionary; when a buyer needs current, confirmed FedRAMP High authorization today; when a buyer is negotiating a large Enterprise deal and needs fully itemised, per-product pricing as a hard requirement; or when a buyer specifically wants to retain an existing, separate SSE vendor and pair it with a different SASE component, given Cloudflare's core positioning favours single-vendor consolidation. | Synthesis of Tables 13, 16, 17, 19 | Medium-High | Each trigger is tied to a specific, evidenced gap rather than a generic 'consider alternatives' hedge.

Each trigger is tied to a specific, evidenced gap rather than a generic 'consider alternatives' hedge.

Summary

Compliance & Footprint | FedRAMP Moderate has been held since 2022 across a genuinely distinctive architecture - more than 30 US-based data centres each running the complete authorized stack on one control plane, rather than the limited FedRAMP-scoped footprint typical of hyperscalers. | FedRAMP High was publicly announced as an active pursuit in February 2025, alongside IRAP PROTECTED (Australia) and ENS (Spain) certification efforts; this research pass found no confirmation that full FedRAMP High authorization has since been achieved, so it should be treated as in-progress rather than complete.

Summary

When would Netify recommend it? (mandatory) | When a buyer wants genuine, self-service pricing transparency and fast time-to-value; when a buyer's primary technical priority is minimising latency for a globally distributed workforce; or when a buyer has a current, active need to govern AI-agent and MCP-server traffic specifically. | Synthesis of Tables 3, 7, 11, 16 | High | A clear, actionable recommendation trigger set for Netify's comparison tool to apply directly.

A clear, actionable recommendation trigger set for Netify's comparison tool to apply directly.

Summary

Mature NetOps/SecOps team | Good fit, particularly for teams building or governing AI-agent infrastructure specifically | The confirmed, current, technically detailed MCP/AI-agent security capabilities (Table 11) are genuinely well-suited to mature teams actively working on this exact, emerging risk category | Mature teams benefit from familiarity with the confirmed API/Workers programmability model for advanced customisation | Not assessed | Table 11, 12 findings | A specific, current, well-evidenced strength for exactly this buyer profile, particularly for teams with an active or emerging AI-agent security requirement.

Summary

Who is this genuinely best suited for? (mandatory) | Organisations wanting genuine self-service pricing transparency and fast time-to-value; buyers whose top priority is minimising latency for a globally distributed workforce, given the confirmed 300+-city Anycast architecture; and organisations with a current or emerging need to govern AI agent and MCP-server access specifically, given Cloudflare's demonstrated, current technical leadership in exactly this area. | Tables 1, 7, 11, 16 | High | Buyers matching this profile can proceed with genuine confidence, backed by unusually consistent, independently-corroborated evidence - particularly for pricing and network coverage, two areas where most competitors profiled in this series offer far less specific, checkable detail.

Buyers matching this profile can proceed with genuine confidence, backed by unusually consistent, independently-corroborated evidence - particularly for pricing and network coverage, two areas where most competitors profiled in this series offer far less specific, checkable detail.

Summary

Co-managed transition | Not confirmed as a distinct named service or evidenced via a case study in sources reviewed | Not itemised | Not itemised | Not itemised | Not quantified | Not itemised | Not detailed | Evidence gap, consistent with the Table 6, 8, 9 finding that no formal co-managed/MSP delivery model was confirmed.

Summary

Strength | A genuinely distinctive, structurally-embedded architecture - every security and networking function runs in every one of 300+ Anycast-routed data centres, rather than being centralised in a limited set of regional inspection hubs the way most competitors' architectures work | Buyers get consistently low latency and local policy enforcement everywhere their users are, not just in regions the vendor has chosen to invest in most heavily | Best: globally distributed organisations prioritising latency and consistency. Less relevant: buyers with a single-region, centralised workforce | High | This is genuinely Cloudflare's clearest, most architecturally fundamental differentiator - not a bolted-on feature but the platform's foundational design principle.

Buyers get consistently low latency and local policy enforcement everywhere their users are, not just in regions the vendor has chosen to invest in most heavily

Summary

Support/service reality | Confirmed to vary by plan tier, but specific, named support-tier SLA figures weren't found in this research pass - a genuine gap relative to vendors with more thoroughly documented, named support structures. | Table 8, 16 | Low-Medium | Flag internally as a priority follow-up source to strengthen before this profile supports a support-SLA-sensitive procurement decision.

Flag internally as a priority follow-up source to strengthen before this profile supports a support-SLA-sensitive procurement decision.

Summary

Multi-vendor SASE integration | Not a primary emphasis of Cloudflare's own positioning, which centres on single-vendor platform consolidation specifically - Cloudflare's own reference architecture explicitly frames the goal as replacing 'a patchwork of legacy hardware and Virtual Private Network (VPN) concentrators' with one unified platform, rather than orchestrating integration with third-party SSE vendors the way some competitors do | Not itemised | Not itemised | Not itemised | Not quantified | N/A | N/A | Worth being precise: unlike some competitors profiled in this series that explicitly support and market best-of-breed pairings with named third-party SSE vendors, Cloudflare's core positioning - per its own reference architecture - is single-vendor consolidation; buyers specifically wanting a best-of-breed, multi-vendor SASE assembly should evaluate this distinction directly.

Summary

Deployment reality | Genuinely well-evidenced as fast for the self-service tier specifically, backed by a confirmed one-month average implementation time and a specific, large-scale named customer example (Delivery Hero, 40,000 employees); less independently evidenced for large-scale, complex, multi-site branch rollouts specifically, where no named, quantified case study was found in this pass. | Table 9, 17, 18 | Medium-High for remote-access deployment specifically; Low-Medium for complex branch rollouts | Present the confirmed remote-access deployment speed with genuine confidence, while noting the thinner evidence base for large, complex branch-rollout scenarios specifically.

Present the confirmed remote-access deployment speed with genuine confidence, while noting the thinner evidence base for large, complex branch-rollout scenarios specifically.

Summary

Large enterprise | Good fit, with a specific commercial caveat | The confirmed 300+-city, Anycast-based architecture and broad, unified capability set (ZTNA, SWG, DLP, RBI, CASB, email security) are all well-suited to large, distributed enterprise estates | Requires internal or partner-supported operational ownership at scale | An independent Enterprise-customer account describes being told pricing was calculated as a single bundled figure with no fixed per-component cost - a real, specific, worth-flagging departure from the self-service tier's transparency | A genuinely important, specific nuance: the pricing transparency that makes Cloudflare attractive to smaller buyers does not appear to carry through to large, negotiated Enterprise contracts - worth setting expectations around directly.

Summary

VPN to ZTNA migration | Evidenced with genuine specificity via a named, quantified customer example - Delivery Hero replaced VPN access for 40,000 employees using Cloudflare One | Existing VPN infrastructure retired | IT team | Not itemised | Not quantified with a specific timeline, though the scale (40,000 employees) is specific and credible | Not itemised | Not detailed | One of the strongest, most specifically quantified VPN-to-ZTNA migration examples found across this profile series - a real, large, named-scale customer, even though sourced via an independent review rather than a primary Cloudflare case study in this pass.

Summary

Biggest operational concern | The pricing transparency that makes Cloudflare genuinely attractive at the self-service tier does not appear to extend to large, negotiated Enterprise contracts, where an independent account describes bundled, non-itemised pricing - a real, specific gap between Cloudflare's most visible commercial strength and the experience of its largest buyers. | Table 16, 19 | Medium | Netify should proactively flag this specific tier-dependent transparency gap to any large Enterprise buyer during the shortlist conversation.

Netify should proactively flag this specific tier-dependent transparency gap to any large Enterprise buyer during the shortlist conversation.

Summary

Commercial reality | Genuinely one of the most commercially transparent vendors in this category at the self-service tier - real, published, consistently-corroborated pricing (free up to 50 users, then $7/user/month flat, no bandwidth or per-connector fees) - though Enterprise-tier bundled pricing reportedly obscures per-component costs once a buyer moves beyond self-service. | Table 16 | High for self-service tier pricing; Medium for Enterprise-tier transparency | Use the confirmed self-service figures directly for initial budget planning at smaller scale, but push explicitly for an itemised breakdown before finalising any large, negotiated Enterprise contract.

Use the confirmed self-service figures directly for initial budget planning at smaller scale, but push explicitly for an itemised breakdown before finalising any large, negotiated Enterprise contract.

Summary

SME | Strong fit, and genuinely well-evidenced | A real, confirmed free tier (up to 50 users) and a simple, flat, self-service $7/user/month tier with no user cap give SMEs genuine, checkable accessibility without a sales conversation | Minimal internal skills needed given the confirmed self-service model and one-month average implementation time | Costs scale linearly with headcount on the Pay-as-you-go tier, with no major volume discount until the custom Contract tier, per independent pricing analysis | Genuinely one of the strongest, most concretely evidenced SME-fit findings across this entire profile series - the combination of a real free tier and simple, published pricing is a rarity worth highlighting directly.

Public evidence sources

47 records
  1. 01Cloudflare - Cloudflare Enterprise Solutions (60+ services, 330+ cities, 13,000+ networks, IDC Leader recognition, bundled-pricing claim) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  2. 02Cloudflare - Cloudflare One | The agile SASE platform (MCP-server security, post-quantum encryption, 300+ cities, Applied Systems case reference) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  3. 03Cloudflare - Cloudflare One: The agile SASE platform (product page, Forrester TEI outcomes, Gartner/Forrester recognitions) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  4. 04Cloudflare - Cloudflare for Federal Government (CISA .gov DNS partnership, Berkeley Lab reference) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  5. 05Cloudflare - Cloudflare's Unique FedRAMP Architecture (solution brief) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  6. 06Cloudflare - Customer Case Studies index page · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  7. 07Cloudflare - FedRAMP FAQs (Trust Hub) - FedRAMP Moderate Authorized since 2022, 325+ NIST 800-53 controls · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  8. 08Cloudflare - Our Story · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  9. 09Cloudflare - Reference architecture centre: Diagrams & guides · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  10. 10Cloudflare - SOC 2 (German-locale Trust Hub mirror) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  11. 11Cloudflare - SOC 2 Compliance (PDF) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  12. 12Cloudflare - SOC 2 FAQs (Trust Hub) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  13. 13Cloudflare - Trust Hub (ISO 27001, ISO 27701, PCI DSS, SOC 2 Type II overview) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  14. 14Cloudflare - What is FedRAMP? (Learning Centre) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  15. 15Cloudflare - homepage: Build for the agent era · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  16. 16Cloudflare - press release: Cloudflare Advances Public Sector Security Worldwide; Initiates Top Federal Certifications, Including FedRAMP High · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  17. 17Cloudflare Blog - Cloudflare achieves FedRAMP authorization to secure more of the public sector (30+ US data centres in FedRAMP scope, single control plane on private backbone) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  18. 18Cloudflare Blog - Modernizing with agile SASE: a Cloudflare One blog takeover · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  19. 19Cloudflare Blog - Piecing together the Agent puzzle: MCP, authentication & authorization, and Durable Objects free tier · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  20. 20Cloudflare Blog - Scaling MCP adoption: Our reference architecture for simpler, safer and cheaper enterprise deployments of MCP (Cloudflare's own internal MCP security practices) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  21. 21Cloudflare Blog - Updates to Cloudflare Security and Privacy Certifications and Reports (2021 milestones: FedRAMP In Process, ISO 27701, ISO 27001, PCI DSS, SOC 2) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  22. 22Cloudflare Developer Docs - Cloudflare One Overview · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  23. 23Cloudflare Reference Architecture - Evolving to a SASE architecture with Cloudflare (PDF) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  24. 24Cloudflare Reference Architecture Docs - Cloudflare Security Architecture · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  25. 25Bloomberg Markets - Matthew Prince, Cloudflare Inc: Profile and Biography · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 2
  26. 26Business Wire (via wire-distribution mirror) - Cloudflare Earns FedRAMP Moderate Authorization to Further Help Government Agencies Modernize and Secure U.S. Infrastructure · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 2
  27. 27Blaxel Blog - SOC 2 Compliance for AI Agents in 2026 (general AI-compliance market context, not Cloudflare-specific) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  28. 28Clay - Who is the CEO of Cloudflare in 2026? Matthew Prince's Bio (third-party executive-profile aggregator) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  29. 29Cloudflare - Cloudflare Agents (developer product page; named customer quote: Knock) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  30. 30Control D - Cloudflare Zero Trust Pricing Breakdown (independent, competitor-adjacent pricing analysis) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  31. 31CostBench - Cloudflare Zero Trust Pricing 2026: Free, $7/mo & Enterprise Plans (third-party pricing aggregator) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  32. 32Crunchbase - Matthew Prince Person Profile (third-party) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  33. 33Fini Labs - How 7 AI Support Vendors Solve PIPEDA Compliance (general compliance market context, not Cloudflare-specific) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  34. 34G2 - Cloudflare One (SASE) Pricing Overview (aggregated user-review benchmarks: implementation time, ROI, discount, perceived cost) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  35. 35G2 - Cloudflare One (SASE) Reviews 2026: Details, Pricing, & Features (third-party review aggregator) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  36. 36Grokipedia - Cloudflare (third-party, AI-assisted encyclopedia entry citing named sources) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  37. 37LinkedIn - Matthew Prince profile (network-scale quote: 'more than a trillion requests... 23 locations') · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  38. 38Martech Edge - Cloudflare Unveils AI Content Controls, AEO Analytics, and Pay-Per-Use Model for the Agentic Web (independent trade-press reporting) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  39. 39Nanosek - Cloudflare One Explained: A Clear Guide to Cloudflare's SASE Products (independent technical commentary) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  40. 40SQ Magazine - Cloudflare Statistics 2026: How Big the Network Has Become (independent statistics aggregation) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  41. 41SaaSWorthy - CloudFlare Pricing: Cost and Pricing plans (third-party pricing aggregator) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  42. 42SpendHound - Cloudflare Pricing 2026: Plans, Spend Data, and How to Pay Less (third-party pricing aggregator) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  43. 43Spendbase - Cloudflare Pricing Explained (third-party pricing aggregator) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  44. 44Truvisory - AI Agents & MCP on Cloudflare's Agentic Cloud (independent technical/consulting commentary) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  45. 45Who Is The Owner Of - Who Is the Owner of Cloudflare? (independent ownership-research site) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  46. 46ZeroMetric - Cloudflare Zero Trust - 2026 Review: Pricing & Features (independent review, named customer reference: Delivery Hero) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  47. 47ZeroTrustCost.com - Cloudflare Zero Trust Pricing 2026: Free Tier, $7/User and Hidden Costs (independent, vendor-neutral pricing/TCO reference) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3

Profile contract provider-public/1.0.0. Machine-readable record: JSON.