Overview
Zscaler is the vendor that effectively created the SSE category, and it’s still the one most competitors get measured against when it comes to sheer scale and security depth - the Zero Trust Exchange runs across 150+ data centres, processes over 400 billion transactions a day, and holds FedRAMP High authorisation for ZIA and ZPA (other SASE-class vendors also hold FedRAMP High or equivalent for their own components). If you’re a security-first buyer looking to retire VPN concentrators and stitch SWG, CASB, DLP and ZTNA together under one console, Zscaler is one of the most proven single-vendor routes to get there. Where it’s less straightforward is on the networking side and on price: there’s no owned private backbone underneath it (it leans on internet peering rather than Cato-style middle-mile infrastructure), the SD-WAN/branch story is newer and less mature than the core security stack, and the tiered per-user pricing model can escalate fast once ZDX, workload licensing and Data Protection add-ons come into play - all worth mapping out early rather than discovering at renewal.
Direct comparison
Put Zscaler, Inc. (trading and profile display name: Zscaler) beside any provider.
Open the Netify comparison engine with both providers already selected. Every result is calculated from the public 40-capability evidence matrix.
No sign-in required. The shortlist remains shareable. Publishing and supplier access stay separate.
Find which providers match your exact needs
Move from a two-provider comparison into the live Netify RFP Builder and evaluate the wider market against your project.
Open the RFP BuilderAgent-accessible research
Ask the Zscaler, Inc. (trading and profile display name: Zscaler) research record
Answers are calculated from the published record below. Missing evidence remains unconfirmed and every result identifies its source revision.
Record summary
- Current products
- 10
- Capabilities
- 67
- Coverage records
- 12
- Service models
- 34
- Compliance records
- 13
- Integration records
- 20
- Sector records
- 10
- Evaluation records
- 50
- Public sources
- 73
Products and delivery
10 records| Product | Category | Relationship | Delivery model | Target buyer |
|---|---|---|---|---|
| AI Security / GenAI Security | AI application and data-security module | Native | Cloud-delivered | Security/compliance teams |
| Data Fabric for Security | Security data aggregation / unified vulnerability management | Native | Cloud-delivered | SecOps/vulnerability management teams |
| Risk360 | Cyber risk quantification | Native | Cloud-delivered | CISO/risk teams |
| Zero Trust Branch | SD-WAN / branch connectivity | Native | Hardware appliance or VM, cloud-managed | Branch/site buyers |
| Zero Trust Exchange | Converged SSE/SASE platform | Native | Cloud-delivered | All buyers |
| Zscaler Client Connector | Endpoint agent | Native | Client-based | Remote/mobile users |
| Zscaler Deception | Deception technology | Native | Cloud-delivered | Security teams |
| Zscaler Digital Experience | Digital experience monitoring (DEM) | Native | Cloud-delivered, add-on | IT operations/helpdesk |
| Zscaler Internet Access | Secure web gateway, inline CASB, DLP, cloud firewall | Native | Cloud-delivered | All buyers |
| Zscaler Private Access | Zero Trust Network Access (ZTNA) | Native | Cloud-delivered | All buyers |
Capability evidence
67 recordsAi Automation14 records
| Capability | Support | Confidence | Freshness | Qualification |
|---|---|---|---|---|
| AI assistant/copilot | Unknown | Unresolved | Current | Marketing language ('AI-driven', '5 trillion daily signals') is broad - Netify should ask Zscaler to name the specific assistant product rather than accept the general claim at face value, applying the same standard used for Cato. |
| AI data protection controls | Requires Confirmation | Unresolved | Current | Same as above |
| Anomaly detection | Requires Confirmation | Unresolved | Current | Depth of the ML methodology not disclosed |
| Automated policy recommendation | Unknown | Unresolved | Current | Not confirmed |
| Automated remediation | Requires Confirmation | Unresolved | Current | Full auto-remediation (without human action) not confirmed |
| Capacity/path optimisation | Requires Confirmation | Unresolved | Current | Applies at the last-mile/ISP level, not a private middle-mile network |
| Configuration generation | Unknown | Unresolved | Current | Not confirmed |
| Digital experience diagnostics | Requires Confirmation | Unresolved | Current | Same third-party sourcing caveat as above |
| Generative AI application controls | Requires Confirmation | Unresolved | Current | Depth/accuracy of AI-traffic classification not independently tested |
| Natural-language querying | Unknown | Unresolved | Current | Not confirmed |
| Report summarisation | Unknown | Unresolved | Current | Not confirmed |
| Root-cause analysis | Requires Confirmation | Unresolved | Current | The '98% faster' and 'auto-reroute' claims are relayed via a third-party summary and not independently verified against a primary Zscaler source |
| Threat detection/classification | Requires Confirmation | Unresolved | Current | '5 trillion daily signals' is a vendor-originated scale claim relayed by a partner, not independently audited |
| User/entity behaviour analytics | Requires Confirmation | Unresolved | Current | Not confirmed |
Architecture15 records
| Capability | Support | Confidence | Freshness | Qualification |
|---|---|---|---|---|
| 5G/LTE support | Requires Confirmation | Low | Current | Zscaler Cellular is referenced as a named product area in secondary financial-data commentary, but not independently confirmed via a primary Zscaler product page in this pass |
| Application identification | Requires Confirmation | Medium | Current | Native - DNS requests for ZPA application segments are forwarded distinctly from other DNS resolution |
| Branch LAN/WLAN integration | Unknown | Low | Current | Unknown |
| Brownfield migration support | Supported | Medium | Current | Evidenced via case study - Baker & Baker adopted SD-WAN alongside ZIA when its MPLS contract expired, implying a supported migration path from legacy WAN |
| Dynamic path selection | Requires Confirmation | Low | Current | Not confirmed as a distinct capability in sources reviewed |
| Edge form factors | Unknown | High | Current | Physical hardware appliance (plug-and-play, standard gigabit Ethernet, AC power) or virtual machine |
| Forward error correction / packet duplication | Requires Confirmation | Low | Current | Not confirmed in sources reviewed |
| High availability | Unknown | Low Medium | Current | Unknown at the branch-hardware level in sources reviewed; the cloud platform itself is inherently multi-data-centre redundant given 160+ data centres globally |
| LEO satellite support | Unknown | Low | Current | Unknown |
| Local internet breakout | Requires Confirmation | Medium High | Current | Native, by design - traffic is tunnelled directly to the nearest Zscaler cloud data centre via DTLS (ZIA) or TLS (ZPA), which is itself a direct-to-cloud breakout model |
| QoS and traffic engineering | Requires Confirmation | Low | Current | Not confirmed as a distinct Zero Trust Branch capability in sources reviewed |
| Segmentation / VRF capability | Unknown | Low | Current | Unknown |
| Supported WAN underlays | Not Supported | Medium | Current | Broadband/internet implied as the primary underlay; no MPLS-coexistence capability found in sources reviewed |
| Virtual/cloud edge support | Requires Confirmation | High | Current | Yes - deployable as a VM in customer data centres |
| Zero-touch provisioning | Requires Confirmation | High | Current | Native - described as plug-and-play with a TPM 2.0 chip for secure device authentication on connect |
Core Capabilities15 records
| Capability | Support | Confidence | Freshness | Qualification |
|---|---|---|---|---|
| Application-aware routing | Requires Confirmation | Medium | Current | Depth of routing logic beyond DNS-based segment forwarding not fully detailed in sources reviewed |
| CASB - API | Requires Confirmation | Low | Current | Not confirmed as distinct from inline CASB or from SaaS Security capability in Table 3's 'SaaS security posture' row |
| CASB - inline | Requires Confirmation | High | Current | None identified |
| Cloud firewall / cloud network security | Supported | High | Current | None identified |
| DNS security | Requires Confirmation | Low | Current | General web/DNS filtering is plausible given ZIA's scope, but a distinct DNS security product/feature was not independently confirmed |
| Data loss prevention | Supported | Medium High | Current | Full DLP capability may require Transformation/Unlimited tier - verify at quoting stage |
| Digital experience monitoring | Requires Confirmation | High | Current | Requires separate ZDX licence |
| Firewall as a Service | Supported | High | Current | None identified |
| Multi-cloud networking | Supported | Medium | Current | Depth of multi-cloud on-ramp capability sourced only via a third-party blog in this pass |
| SD-WAN | Supported | Medium High | Current | Newer and less independently documented than the core SSE stack; Gartner positions Zscaler as a Visionary (not Leader) in the SASE MQ specifically because of this |
| SaaS security posture | Supported | Medium | Current | Depth beyond Microsoft 365/Copilot not independently confirmed |
| Secure web gateway | Supported | High | Current | None identified |
| Threat intelligence | Supported | Medium High | Current | None identified |
| WAN optimisation | Requires Confirmation | Low | Current | Zscaler's proxy-cloud architecture does not appear to include backbone-based WAN optimisation the way backbone-first vendors do - consistent with having no owned private backbone |
| ZTNA | Supported | High | Current | None identified |
Remote Access9 records
| Capability | Support | Confidence | Freshness | Qualification |
|---|---|---|---|---|
| Clientless access | Supported | Unresolved | Current | None identified |
| Contractors/third parties | Supported | Unresolved | Current | None identified |
| Managed laptops | Supported | Unresolved | Current | None identified |
| Mobile devices | Supported | Unresolved | Current | None identified |
| Privileged access | Supported | Unresolved | Current | Tier-gated (Transformation, not Business) |
| Remote browser isolation | Supported | Medium | Current | Tier-gated rather than universally included |
| Remote browser isolation | Supported | Unresolved | Current | Tier-gated rather than universally included |
| Unmanaged/BYOD devices | Supported | Unresolved | Current | Depth of BYOD-specific policy control not independently confirmed |
| VDI environments | Unknown | Unresolved | Current | Not confirmed |
Reporting Analytics14 records
| Capability | Support | Confidence | Freshness | Qualification |
|---|---|---|---|---|
| Application performance | Supported | Unresolved | Current | Requires ZDX licence |
| Compliance reporting | Unknown | Unresolved | Current | Not confirmed |
| Custom reports | Unknown | Unresolved | Current | Not confirmed |
| DLP events | Requires Confirmation | Unresolved | Current | Not confirmed |
| Executive dashboard | Requires Confirmation | Unresolved | Current | Not confirmed |
| Network health | Supported | Unresolved | Current | Requires ZDX licence |
| Raw log access | Unknown | Unresolved | Current | Not confirmed |
| Remote-user experience | Supported | Unresolved | Current | Requires ZDX licence |
| SLA reporting | Requires Confirmation | Unresolved | Current | Not confirmed |
| Scheduled reports | Unknown | Unresolved | Current | Not confirmed |
| Security events | Supported | Unresolved | Current | Not confirmed |
| Site and circuit performance | Supported | Unresolved | Current | Requires ZDX licence |
| Threat reporting | Supported | Unresolved | Current | Not confirmed |
| User experience | Supported | Unresolved | Current | Requires ZDX licence |
Geographic coverage
12 records| Geography | Delivery type | Relationship | Confidence | Qualification |
|---|---|---|---|---|
| Africa coverage | Unknown - Not Itemised In Sources Reviewed | Unknown | Low | Unknown - not itemised in sources reviewed | Unknown | Not specified | No named data centres found | Not found in a Tier 1-2 source in this pass | Low | Evidence gap - same treatment as Cato's equivalent row. |
| Asia-Pacific coverage | Unknown In Named-Country Detail - General 'Six Continents' And 'Most Countries' Claims Imply Presence But No Specific APAC Country/City List Was Found In This Pass | Unknown | Low | Unknown in named-country detail - general 'six continents' and 'most countries' claims imply presence but no specific APAC country/city list was found in this pass | Unknown | Not specified in detail | No named APAC data centres found | Not found in a Tier 1-2 source in this pass | Low | Evidence gap - worth checking Zscaler's own data-centre location page directly for a country-level breakdown before advising APAC-heavy buyers. |
| Carrier interconnects | Zscaler 'Peers With Hundreds Of ISPs And Cloud Service Providers In Major Internet Exchanges Around The World' | Owned | Medium | Zscaler 'peers with hundreds of ISPs and cloud service providers in major internet exchanges around the world' | Direct | Global | Specific carrier/exchange names not disclosed | Zscaler press material (2019, reaffirmed in later releases) | Medium | Standard practise for a cloud-native security vendor; nothing unusual to flag. |
| China coverage | Unknown - No China-Specific Data-Centre Or Licensed-PoP Detail Found In Sources Reviewed | Unknown | Low | Unknown - no China-specific data-centre or licensed-PoP detail found in sources reviewed | Unknown | Not specified | No named China presence found, in contrast to Cato's explicit Beijing/Shanghai/Shenzhen PoPs | Not found in a Tier 1-2 source in this pass | Low | A genuine point of comparison for multinational buyers with China-inclusive estates - do not assume parity with Cato's specific China story. |
| Data residency choices | Confirmed - Dedicated Logging Planes In Six Countries As Of March 2026, Expanding To Canada, With Fully Isolated Control, Data And Logging Planes By Design | Owned | High | Confirmed - dedicated logging planes in six countries as of March 2026, expanding to Canada, with fully isolated control, data and logging planes by design | Direct | Six named-count countries (specific names not given in the source), expanding to Canada | Exact list of the six countries not itemised in the source reviewed | 12 Mar 2026 | High | A well-evidenced, architecturally serious data-sovereignty story - genuinely stronger and more specific than what was found for Cato's equivalent Private PoP-based approach. |
| Latin America coverage | Unknown - Not Itemised In Sources Reviewed, Though The 'Present In Most Countries' Claim Implies Some Presence | Unknown | Low | Unknown - not itemised in sources reviewed, though the 'present in most countries' claim implies some presence | Unknown | Not specified | No named data centres found | Not found in a Tier 1-2 source in this pass | Low | Do not infer specific coverage from the general 'most countries' claim - ask directly. |
| Middle East coverage | Confirmed - Active Data-Centre Expansion In Saudi Arabia Announced July 2025, Described As Part Of A Broader Middle East Growth Strategy | Owned | High | Confirmed - active data-centre expansion in Saudi Arabia announced July 2025, described as part of a broader Middle East growth strategy | Direct | Saudi Arabia (named); wider Middle East implied | Other specific Middle East countries not itemised | 1 Jul 2025 | High | Better-evidenced than Cato's Middle East coverage (which was a total gap in that profile) - a fair point of comparison to make to buyers with Middle East estates. |
| Private backbone | Not Present - Zscaler'S Architecture Relies On Internet Peering And Cloud-Provider Interconnects Rather Than An Owned, SLA-Backed Private Backbone | Unknown | High | Not present - Zscaler's architecture relies on internet peering and cloud-provider interconnects rather than an owned, SLA-backed private backbone | N/A | N/A | This is a genuine architectural characteristic, not an evidence gap | Ongoing (platform architecture) | High | The single clearest, most consequential architectural difference from Cato in this entire comparison - Netify should present this plainly rather than softening it. |
| Public cloud on-ramps | AWS, Azure, GCP Peering/Integration Referenced Across Multiple Sources (Baker & Baker On Azure; Zscaler Workload Segmentation For Multi-Cloud) | Owned | Medium High | AWS, Azure, GCP peering/integration referenced across multiple sources (Baker & Baker on Azure; Zscaler Workload Segmentation for multi-cloud) | Direct | Wherever those hyperscalers have regions | Depth of on-ramp architecture (dedicated interconnects vs standard peering) not fully detailed | 22 Jul 2026 | Medium-High | Strong multi-hyperscaler story, evidenced by named customer deployments rather than marketing claims alone. |
| SD-WAN gateways / cloud gateways | Delivered From The Same Global Data-Centre Infrastructure As The Security Edges - No Separate SD-WAN-Only Gateway Network Identified | Owned | Medium | Delivered from the same global data-centre infrastructure as the security edges - no separate SD-WAN-only gateway network identified | Direct | Same as above | None identified | Ongoing (platform architecture) | Medium | Consistent with a converged-platform design, though Zscaler's SD-WAN maturity is genuinely newer (see Table 4). |
| Security PoPs / service edges | 160+ Data Centres Globally As Of March 2026 (Earlier Press Material From 2019-2021 Cited 150+, Showing Steady Growth Over Time) | Owned | High | 160+ data centres globally as of March 2026 (earlier press material from 2019-2021 cited 150+, showing steady growth over time) | Direct (Zscaler-owned/operated cloud) | Six continents, present in most countries | Full country-by-country list not found in sources reviewed | High | Zscaler's data-centre count is, like Cato's PoP count, an actively growing figure - cite with the publication date rather than as a fixed spec. |
| Sovereign/regional service options | Government Cloud (ZGC) Confirmed As A Distinct FedRAMP High Authorised Offering, Separate From The Commercial Cloud | Owned | Medium High | Government Cloud (ZGC) confirmed as a distinct FedRAMP High authorised offering, separate from the commercial cloud | Direct | United States (federal/government cloud) | Sovereign offerings for non-US regions (e.g. EU sovereign cloud) not found in sources reviewed | 22 Jul 2026 | Medium-High | Strong for US federal buyers specifically; UK/EU-equivalent sovereign offerings should be asked about directly rather than assumed to exist on the same basis. |
Service models
34 recordsOther
SupportedYes | Zero Trust Branch hardware | Appliance → Zscaler cloud | Cloud console | Distributed branch estates | Low (per Zscaler's own claims) | See Table 4 - newer capability than the core security stack | Real, but with thinner independent evidence than Cato's equivalent, retail-proven branch rollout story.
Other
Requires ConfirmationConfirmed at Premium Support Advanced/Advanced Plus tiers - 'a designated resource to help you execute your digital transformation' | Per tier | Not specified | Premium tier | N/A | Not separately quantified | Concrete, named ('Focal Support', dedicated resource) - good evidence quality.
Other
UnknownSame tiered structure as configuration management | Per tier | N/A | Premium tier | Shared | Not separately quantified | Same as above | Same as above.
Other
UnknownUnknown - not found in sources reviewed | Presumably Admin Portal/API | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in public sources reviewed | Evidence gap - flag for direct vendor follow-up.
Other
SupportedNative - Zscaler Technical Assistance Centre (ZTAC) operates the cloud platform | 24x7x365 | Not itemised by location | Included as part of the platform service | Customer configures policy; Zscaler operates the underlying cloud | P1 (Urgent) initial response as fast as 15 minutes on premium tiers, 30 minutes on Standard | Well-documented, specific SLA figures rather than a vague 'we have a NOC' claim - a genuine strength of the primary-source evidence available for Zscaler.
Other
SupportedNative - MDR is a named, SLA-backed service | 24x7 (implied) | Not itemised by location | Premium/add-on | N/A | 10-minute notification SLA | zscaler.com SLA & Support legal page | One of the best-evidenced managed-service claims in this profile, with a specific contractual SLA rather than a vague marketing figure.
Other
Requires ConfirmationNot confirmed as a distinct customer-facing SOC service in sources reviewed, though Managed Detection and Response (MDR) exists as a named service with its own SLA | 24x7 for MDR (implied by a 10-minute notification SLA) | Not itemised by location | MDR appears to be a premium/add-on service | Not fully detailed | MDR Response Time Agreement: customer notified within 10 minutes of a Zscaler analyst confirming a threat | zscaler.com SLA & Support legal page | The 10-minute MDR notification SLA is a specific, credible, contractually-stated commitment - stronger evidence than a marketing claim of '24x7 SOC'.
Other
SupportedYes | Zero Trust Branch VM | VM → nearest Zscaler data centre | Cloud console | Data centres wanting to avoid physical hardware | Low | Deploy as VM image | Reasonable option for virtualised data-centre estates.
Other
SupportedYes | Zscaler Client Connector | Client → Zscaler cloud | Cloud console | Managed-device remote/hybrid workforce | Low | N/A | Zscaler's most mature, longest-standing deployment pattern.
Other
Requires ConfirmationNot confirmed as a distinct capability in sources reviewed | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in a Tier 1-2 source in this pass | See Table 6 - no equivalent to Cato's MSASE partner platform was found for Zscaler in this pass.
Other
SupportedYes, as branch CPE only, not a self-contained on-prem product | Zero Trust Branch hardware appliance | Appliance → nearest Zscaler data centre via DTLS/TLS | Cloud console | Branch offices | Low (zero-touch provisioning) | Plug-and-play install per Zscaler's own reference architecture | Same 'thin edge into the cloud' pattern seen across SASE vendors - the appliance is an on-ramp, not an independent security boundary.
Other
SupportedYes | Browser-based ZPA access | Browser → Zscaler cloud | Cloud console | BYOD, contractors | Low | N/A | See Table 5.
Other
SupportedAvailable at higher support tiers (Premium Support Advanced/Advanced Plus include 'Focal Support' and a designated resource) | Per tier | N/A | Premium tier | Shared, depending on tier purchased | Not separately quantified beyond the tiered SLA table | A genuinely tiered, well-documented support structure rather than a single flat offering.
Other
SupportedNative via MDR | 24x7 (per MDR SLA) | N/A | Premium/add-on | Depends on MDR being purchased | 10-minute notification SLA (see above) | zscaler.com SLA & Support legal page | Concrete, contractual SLA - one of the better-evidenced specific commitments in this entire profile.
Other
UnknownNot applicable in the same sense as an SD-WAN/backbone vendor, given Zscaler does not manage a private middle mile (see Table 7) | N/A | N/A | N/A | N/A | N/A | N/A | This row is structurally different for Zscaler than for a backbone-based vendor - not a gap, but an architectural non-applicability worth stating plainly.
Other
Requires ConfirmationUnknown in detail; role-based access is documented for end-user application access (Mindbody case study) but administrator-level RBAC was not separately confirmed | Presumably Admin Portal | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Do not conflate the well-evidenced end-user role-based access with administrator-level RBAC, which wasn't separately confirmed.
Other
UnknownUnknown - not found in sources reviewed | Presumably Admin Portal | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in public sources reviewed | Evidence gap.
Other
SupportedNative | 24x7 | N/A (cloud service) | Included for platform; MDR is the premium security-monitoring tier | N/A | See above | Same as above | N/A
Other
UnknownImplied via Customer Success team engagement at Premium Support tiers, though not itemised as a distinct professional-services SKU in sources reviewed | N/A | N/A | Premium tier engagement | N/A | N/A | zscaler.com Premium Support data sheets | Less concretely evidenced as a standalone PS product than Cato's AWS Marketplace-listed Managed Deployment package - worth asking Zscaler directly for a PS-specific data sheet.
Other
UnknownCloud-based admin console setup; branch hardware is plug-and-play per Zscaler's own reference architecture | Zscaler Admin Portal | General IT/network admin per case study evidence | Zero-touch provisioning for Zero Trust Branch hardware | Low, per multiple customer case studies describing fast, straightforward rollouts | None significant identified in sources reviewed | Consistently described as low-effort across independent case studies, similar in tone to Cato's equivalent evidence.
Other
UnknownUnknown - not found in sources reviewed for Zero Trust Branch appliance RMA/replacement terms | Not found | Not found | Not confirmed | Not confirmed | Not confirmed | Not found in a Tier 1-2 source in this pass | Evidence gap - matters for branch-heavy buyers doing hardware rollouts, same caveat as flagged for Cato.
Other
UnknownZscaler Client Connector install or browser-based clientless route | Admin Portal + Client Connector | End-user self-install typical of this category | Not itemised | Not itemised | Not itemised | General platform pages | Standard for the category; no distinctive evidence found either way.
Other
Requires ConfirmationConfirmed - 'Support Case Reviews, Operational Reviews' listed as part of the base support offering, expanding at higher tiers to include 'Business Continuity Plan', 'Configuration Audit' and 'Service Resiliency Audit' | Per tier | Not specified | Included at base, expands with tier | N/A | Not separately quantified | Specific, itemised list of review types - stronger evidence than a generic 'we do reviews' claim.
Other
Requires ConfirmationNot confirmed as a distinct named service in sources reviewed | Not confirmed | N/A | Not confirmed | Not confirmed | Not confirmed | Not found in a Tier 1-2 source in this pass | Evidence gap - flag for direct vendor follow-up.
Other
SupportedYes | Mix of Client Connector, clientless, Zero Trust Branch | Mixed | Cloud console, unified | Most real-world enterprise estates | Moderate | Case studies (Baker & Baker, AutoNation) show phased adoption starting with ZIA/ZPA and adding further modules over time | A realistic, evidenced pattern - customers typically start with the security core and expand rather than deploying the whole platform at once.
Other
UnknownCloud-delivered updates for the platform are automatic by design (SaaS model); Zero Trust Branch appliance firmware lifecycle not detailed in sources reviewed | N/A for cloud platform | Not confirmed for appliance firmware specifically | Automatic for cloud platform | Low for cloud platform; appliance firmware cadence not confirmed | Not confirmed for appliances | General SaaS/platform architecture pages | Reasonable to assume low burden for the cloud platform given the SaaS model; appliance-specific patch cadence should be verified directly for hardware-heavy branch buyers.
Other
SupportedNative via Zscaler Workload Segmentation / Cloud Connector | Cloud Connector for AWS/Azure/GCP | Cloud workload → Zscaler cloud | Cloud console | Multi-cloud/hybrid enterprises | Not fully detailed | Evidence for this row sourced mainly via a third-party blog (see Table 3) | Directionally credible but less independently evidenced than the branch/client deployment models.
Other
UnknownNot clearly documented as a distinct model in sources reviewed | Not confirmed | - | - | Not confirmed | Not confirmed | Not confirmed | Zscaler's support-tier structure (Table 8) implies varying degrees of Zscaler involvement, but a formal 'co-managed' service model distinct from support tiers was not found - flag as a gap rather than assume it doesn't exist.
Other
UnknownZDX Network Intelligence (added October 2025) has Client Connector probe every 5 minutes for latency/jitter/packet loss and uses AI to pinpoint ISP bottlenecks and auto-reroute | ZDX dashboards within Admin Portal | Reduced specialist requirement implied by AI-assisted diagnostics | AI-assisted correlation and auto-rerouting | Positioned as low-effort | Depends on ZDX licence being active | A genuinely specific, dated product update (not generic 'AI-powered' language) - though sourced via a third-party report rather than a primary Zscaler product page in this pass, worth a follow-up citation to Zscaler's own ZDX release notes.
Other
Requires ConfirmationNot confirmed as a distinct Zscaler-delivered managed-service offering in sources reviewed; delivered primarily through partners/MSSPs in the broader market rather than as a named Zscaler product | Not confirmed | - | - | Buyers wanting full outsourcing | Not confirmed | Not confirmed | Unlike Cato's explicit Managed SASE / MSASE partner programme, no equivalent named Zscaler-delivered managed-service product was found in this pass - worth asking directly if a buyer needs this.
Other
UnknownUnknown - not found in sources reviewed as a distinct MSP/multi-tenant capability | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in a Tier 1-2 source in this pass | In contrast to Cato's explicit MSASE multi-tenant partner platform, no equivalent named Zscaler capability was found - flag as a genuine evidence gap.
Other
UnknownShip Zero Trust Branch hardware, plug-and-play connect via TPM 2.0-authenticated tunnel | Admin Portal (remote) | No on-site specialist required per the reference architecture description | Zero-touch | Low, per Zscaler's own documentation, though not independently proven at the operational scale Cato's Ulta Beauty case study demonstrates | No large-scale, metric-rich branch-rollout case study was found in this pass (in contrast to Cato's Ulta Beauty story) | help.zscaler.com Zero Trust Branch reference architecture | The mechanism is well documented, but Zscaler lacks an equivalent to Cato's Ulta Beauty proof point - a fair, specific gap to flag rather than assume away.
Other
SupportedYes | Zscaler cloud (Zero Trust Exchange) | Via nearest Zscaler data centre | Centralised, cloud console | All customers - core delivery model | Low | N/A - default | The default and only real operating model for the security stack, consistent with Zscaler's proxy-cloud architecture.
Other
UnknownCentralised policy engine covering ZIA/ZPA/ZDX from one console | Zscaler Admin Portal | Not itemised in detail | Not itemised | Not itemised | Not itemised | General platform pages | Insufficient specific evidence to grade granularly - flagged as a gap rather than assumed easy based on general marketing.
Compliance and assurance
13 records| Framework | Scope | Support | Review date | Qualification |
|---|---|---|---|---|
| DORA relevance | N/A | Unknown | Not stated | Unknown - not found in sources reviewed | N/A | Not confirmed | EU financial services | Not found in a Tier 1-2 source in this pass | Not found | Evidence gap - relevant to Netify's financial-services sector suitability assessment (Table 14). |
| Data residency | Wherever the sovereignty architecture is deployed | Requires Confirmation | Not stated | Confirmed - isolated control/data/logging planes by design, with dedicated logging planes in six countries and expansion to Canada announced | Wherever the sovereignty architecture is deployed | Zscaler's data-sovereignty architecture (unnamed as a discrete product, described as a platform-wide capability) | Six named-count countries (not itemised by name in the source), expanding to Canada | 22 Jul 2026 | One of the stronger, more technically specific data-residency stories in this profile - genuinely differentiated evidence, not just marketing language. |
| Encryption/key management | Government Cloud confirmed; commercial cloud not separately detailed | Requires Confirmation | Not stated | Partial - FIPS 140-2 validated cryptographic modules confirmed for the Government Cloud specifically; general commercial-cloud encryption/key-management detail not itemised in sources reviewed | Government Cloud confirmed; commercial cloud not separately detailed | FIPS 140-2 Level 1 validated cryptographic modules (Government Cloud) | None identified | 22 Jul 2026 | FIPS validation for the Government Cloud is credible and specific; Netify should ask directly whether the same validation extends to the commercial cloud before assuming parity. |
| FedRAMP | US federal government | Unknown | Not stated | Authorized - High and Moderate baselines, both JAB and Agency authorizations referenced across ZIA, ZPA and ZDX; also GovRAMP Authorized | US federal government | FedRAMP High ATO (JAB), FedRAMP Moderate; DoD IL5 (ZPA) and IL4 Provisional Authorization referenced for Zscaler Government Cloud; DoD Approved Products List | US federal/government | 22 Jul 2026 | A major, extensively documented differentiator - very few SASE/SSE-class vendors clear FedRAMP High, and Zscaler's evidence here is unusually deep (multiple primary press releases and dedicated public-sector pages). |
| GDPR | Platform/company | Supported | Not stated | Compliant (self-attested), supported by a documented data-sovereignty architecture | Platform/company | Isolated control/data/logging planes; dedicated logging planes in six countries as of March 2026 | EU/UK relevant | 22 Jul 2026 | Better-evidenced than a bare self-attestation - the isolated-plane architecture is a specific, technical data-sovereignty mechanism, not just a policy statement. |
| HIPAA | N/A | Requires Confirmation | Not stated | Not separately confirmed via a dedicated attestation in sources reviewed, though healthcare is listed among served industries | N/A | Not confirmed as a formal attestation | US healthcare-relevant | Not found in a Tier 1-2 source in this pass | Do not assume a formal HIPAA attestation exists just because healthcare is listed as a served industry - a genuine distinction Netify should hold Zscaler to the same standard on as any other vendor. |
| ISO 27001 | Platform/company ISMS, following ISO/IEC 27002:2013 best practise | Unknown | Not stated | Certified | Platform/company ISMS, following ISO/IEC 27002:2013 best practise | ISO 27001 certificate; ISO 27017 (cloud security) and ISO 27018 (cloud privacy) also referenced | None identified | 22 Jul 2026 | Consistently repeated across multiple primary Zscaler pages - high confidence. |
| Logging/auditability | Platform, especially sovereignty-relevant deployments | Requires Confirmation | Not stated | Confirmed at an architectural level - dedicated, isolated logging planes distinct from control and data planes, described as ensuring 'sensitive data never leaves its required jurisdiction' | Platform, especially sovereignty-relevant deployments | Isolated logging plane architecture | Six named-count countries, expanding to Canada | 22 Jul 2026 | A genuinely distinctive architectural claim (separate logging plane as a first-class architectural layer) rather than a generic 'we keep logs' statement. |
| NHS DSPT relevance | N/A | Unknown | Not stated | Unknown - not found in sources reviewed | N/A | Not confirmed | UK | Not found in a Tier 1-2 source in this pass | Not found | Evidence gap - directly relevant to Netify's UK healthcare-sector buyers; ask directly rather than infer from US healthcare positioning. |
| NIS2 relevance | N/A | Unknown | Not stated | Unknown - not found in sources reviewed | N/A | Not confirmed | EU | Not found in a Tier 1-2 source in this pass | Not found | Evidence gap. |
| PCI DSS | N/A | Requires Confirmation | Not stated | Not confirmed in sources reviewed | N/A | Not confirmed | N/A | Not found in a Tier 1-2 source in this pass | Not found | In contrast to Cato's explicit PCI-DSS Level 1 claim, no equivalent Zscaler PCI-DSS statement was found - flag as a genuine evidence gap for payment-handling buyers rather than assume parity. |
| SOC 2 | Platform | Unknown | Not stated | Certified (Type II) | Platform | SOC 2 Type II report, audited annually by a third party | None identified | 22 Jul 2026 | Confirmed across multiple primary Zscaler pages, including a specific note that it's audited annually. |
| UK public sector frameworks | UK | Requires Confirmation | Not stated | Unknown - not found in sources reviewed; a third-party review (not independently corroborated) separately claims Cyber Essentials Plus, but this was not confirmed on Zscaler's own compliance pages in this pass | UK | Not confirmed | UK | Not found in a Tier 1-2 source in this pass | This is a direct, important follow-up question for Netify's UK-focused work - do not repeat the Cyber Essentials Plus claim as fact until it's confirmed on a primary Zscaler source. |
Integrations
20 recordsAWS
Cloud · Native
Cloud | Native (Cloud Connector; also marketplace-listed pricing editions) | Bidirectional (connectivity + optional Marketplace billing) | Not specified | AWS Marketplace listings referenced by third-party pricing analysis | Medium | Directionally confirmed but sourced mainly via third-party summaries in this pass rather than a direct AWS Marketplace visit - worth a primary-source follow-up.
Active Directory
Identity · Unknown
Identity | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
CrowdStrike
EDR · Partner
EDR | Native, deeply documented - three-way Okta/CrowdStrike/Zscaler alliance, plus a dedicated Zscaler Operations Technology Partners entry ('CrowdStrike integrates with Zscaler to provide threat intelligence and automation') | Bidirectional (Zscaler reads CrowdStrike Falcon Zero Trust Assessment device-posture scores; threat intel shared both ways) | Not specified | Formal joint deployment guide, hands-on integration lab (WWT ATC), and a dedicated Okta/CrowdStrike/Zscaler business-development guide (Feb 2024) all found | High | Unusually well-documented - four independent pieces of evidence (alliance blog, partner page, formal guide, hands-on lab) for a single integration.
Google Cloud
Cloud · Unknown
Cloud | Referenced generically alongside Google Workspace integration | Not detailed | Not specified | Not detailed | zscaler.com Operations Technology Partners page | Medium | Present but not independently detailed to the same depth as the Azure evidence.
Google Workspace
Identity/Productivity · Unknown
Identity/productivity | Referenced generically ('Google and Zscaler provide secure, fast access to... Google Drive and Gmail') | Not detailed | Not specified | Not detailed | zscaler.com Operations Technology Partners page | Medium | Confirmed present but with less depth than the Okta alliance.
Intune
MDM/UEM · Unknown
MDM/UEM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Jamf
MDM/UEM · Unknown
MDM/UEM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap - relevant to verify given Apple-heavy enterprise estates.
Microsoft 365
Productivity/SaaS · Native
Productivity/SaaS | Native - specifically documented for Microsoft Copilot misconfiguration scanning and CASB-based permission management | Zscaler monitors/secures M365 and Copilot traffic and configuration | Not specified | Detailed in a dedicated blog post on securing Copilot specifically | High | Genuinely detailed, current integration (Copilot-specific), not just a generic 'works with Office 365' claim.
Microsoft Azure
Cloud · Native
Cloud | Native - confirmed in production via the Baker & Baker case study (ZPA securing private apps running on Azure) | Bidirectional | Not specified | Not detailed further | High | Confirmed via a named customer's real production use, stronger evidence than a generic capability claim.
Microsoft Defender
EDR · Unknown
EDR | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap - CrowdStrike is clearly the best-documented EDR partner; Defender-specific integration wasn't found in this pass.
Microsoft Entra ID
Identity · Unknown
Identity | Not separately itemised from general IdP integration claims in sources reviewed (Okta is the specifically documented IdP) | Unknown | Not specified | Not detailed | Not found as a distinct integration in this pass | Low | Do not assume Entra ID parity with the well-documented Okta integration without direct confirmation.
Microsoft Sentinel
SIEM · Unknown
SIEM | Not separately itemised as a distinct Sentinel integration in sources reviewed, though general SIEM/TIP integration claims exist | Unknown | Not specified | Not detailed | zscaler.com Operations Technology Partners page (general SIEM/TIP language, not Sentinel-specific) | Low-Medium | Do not assume a Sentinel-specific integration is documented to the same depth as CrowdStrike/Okta without direct confirmation.
Okta
Identity · Native
Identity | Native, deeply documented - a three-way Okta/CrowdStrike/Zscaler alliance with a joint deployment guide | Bidirectional (Zscaler reads Okta identity/device-trust context; policies act on it) | Not specified | Formal joint Business Development Guide and deployment guide published | High | One of the best-evidenced integrations in this entire profile - a formal three-way alliance with named joint collateral, not just a listed logo.
Palo Alto Cortex
SIEM/XDR · Unknown
SIEM/XDR | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
REST API
Platform API · Partner
Platform API | Implied by the existence of formal partner integrations (Okta, CrowdStrike) and third-party threat-intel feeds (Anomali, Recorded Future, Cyware, EclecticIQ via TIP integration) | Bidirectional | Not specified | Not detailed as a standalone developer product in sources reviewed | zscaler.com Operations Technology Partners page (TIP integrations) | Medium | API existence is a reasonable inference from the documented integrations, but a standalone API/developer portal page wasn't independently confirmed in this pass.
SCIM/SAML/OIDC
Identity Federation · Unknown
Identity federation | SAML confirmed via the Okta/CrowdStrike joint guide ('Online help for configuring SAML 2.0 for Zscaler') | Bidirectional (auth) | Not specified | Documented in the joint deployment guide | Medium-High | SAML is explicitly confirmed; SCIM/OIDC support is a reasonable inference from standard IdP integration practise but wasn't separately itemised by name.
ServiceNow
ITSM · Unknown
ITSM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap - do not assume ITSM integration exists without confirmation.
Splunk
SIEM · Unknown
SIEM | Confirmed via a named public-sector deployment architecture (Red River Zero Trust Accelerator combines AWS, CrowdStrike, Okta, Splunk and Zscaler) | Zscaler → Splunk (implied) | Not specified | Part of a validated, field-tested reference architecture for public sector/regulated industries | AWS Marketplace listing - Red River Zero Trust Accelerator | Medium-High | Evidenced via a named, validated reference architecture rather than a generic 'integrates with Splunk' claim.
Syslog
Log Export · Unknown
Log export | Not separately itemised in sources reviewed | Unknown | Not specified | Not detailed | Not found | Low | Evidence gap - reasonable to assume given SIEM integrations exist, but not independently confirmed.
Terraform
Infrastructure-As-Code · Unknown
Infrastructure-as-code | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap - worth checking Zscaler's developer/API documentation directly.
Sector evidence
10 recordsEducation
UnknownUnknown - not assessed | Not assessed | Not assessed | None found | N/A | No case study found | Evidence gap.
- Named evidence
- None found
- Case study strength
- None
Energy/utilities
UnknownConditional fit | Global remote-access capability plausibly relevant | Not assessed | NOV (oilfield services/energy, 27,500 users, global remote-access rollout during COVID-19) | Global distributed workforce use case well evidenced | Single case study, but a genuinely substantial, named, metric-rich one | NOV is a strong, credible case study for this sector specifically - a real enterprise-scale (27,500-user) deployment with a clear before/after narrative.
- Named evidence
- NOV (oilfield services/energy, 27,500 users, global remote-access rollout during COVID-19)
- Case study strength
- Strong
Financial services
Not SupportedConditional - no PCI-DSS or DORA evidence found in this pass, in contrast to Cato's explicit PCI-DSS Level 1 | DLP, CASB plausibly relevant | Not confirmed | None found in this research pass | N/A | No named financial-services case study or PCI-DSS attestation found | A genuine, specific gap relative to Cato's profile on this exact point - flag it plainly rather than assume parity.
- Named evidence
- None found in this research pass
- Case study strength
- None
Government/public sector
UnknownStrong fit, extensively evidenced | FedRAMP High/Moderate, DoD IL5, GovRAMP, CJIS, CMMC Level 2 | FedRAMP High/Moderate, GovRAMP Authorized, CJIS, CMMC Level 2, DoD IL4/IL5 | CSC (public-sector case study, VPN-to-Zero-Trust productivity gains) | Zscaler Government Cloud is a distinct FedRAMP High authorised offering | US-federal-specific; UK/EU public-sector framework listings not found in this pass | By far the best-evidenced sector in this entire profile - genuinely strong, multi-source, dated evidence. The clear standout differentiator versus Cato, which had no equivalent public-sector compliance depth.
- Named evidence
- CSC (public-sector case study, VPN-to-Zero-Trust productivity gains)
- Case study strength
- Strong
Healthcare/NHS
Not SupportedConditional - US healthcare listed as a served industry, but no formal HIPAA attestation or NHS DSPT evidence found | DLP, ZTNA, CASB plausibly relevant | Healthcare listed as served industry (company FAQ); no HIPAA/NHS DSPT confirmation found | None found in this research pass | N/A | No named healthcare case study or formal healthcare-specific compliance attestation found | Do not claim healthcare/NHS suitability beyond 'lists healthcare as a served industry' without a supporting case study or direct compliance confirmation.
- Named evidence
- None found in this research pass
- Case study strength
- None
Hospitality
UnknownUnknown - not assessed | Not assessed | Not assessed | None found | N/A | No case study found | Evidence gap.
- Named evidence
- None found
- Case study strength
- None
Manufacturing
UnknownConditional fit | SD-WAN/branch capability plausibly relevant | Not assessed | Baker & Baker (food manufacturing) | N/A | Single case study, not deeply metric-rich beyond the ransomware-reduction claim | Some evidence exists but is thinner than the retail/public-sector case studies.
- Named evidence
- Baker & Baker (food manufacturing)
- Case study strength
- Strong
Professional services
UnknownConditional fit | Not assessed | Not assessed | Mindbody (business software/services company) | N/A | Single case study, not sector-specific in focus | Some evidence exists but isn't a deep sector-specific case.
- Named evidence
- Mindbody (business software/services company)
- Case study strength
- Strong
Retail
UnknownGood fit, evidenced | SD-WAN/ZIA for distributed sites, M365 security | Not assessed | AutoNation (retail/automotive dealerships), Baker & Baker (food manufacturing/retail supply) | Multi-site retail benefits from ZIA's direct-to-cloud model avoiding centralised backhaul | US-centric case evidence; UK/EU retail-specific case studies not found in this pass | Reasonably well evidenced via AutoNation specifically, though not as singularly strong as Cato's Ulta Beauty story.
- Named evidence
- AutoNation (retail/automotive dealerships), Baker & Baker (food manufacturing/retail supply)
- Case study strength
- Strong
Transport/logistics
UnknownUnknown - not assessed | Not assessed | Not assessed | None found | N/A | No case study found | Evidence gap.
- Named evidence
- None found
- Case study strength
- None
Case studies
3 records- Customer
- Named - AutoNation
- Sector and geography
- Retail (automotive dealerships) · United States
- Estate
- Not quantified; Multiple retail and corporate locations
- Outcome
- Eliminated ~500 GB/month of unwanted P2P traffic (named-executive quote); improved Microsoft 365 performance enterprise-wide
Named - AutoNation | Retail (automotive dealerships) | United States | Not quantified | Multiple retail and corporate locations | Needed a cloud-based security stack to support Microsoft 365 rollout and control unauthorised P2P traffic consuming bandwidth | ZIA, Cloud Sandbox, Bandwidth Control | Cloud-delivered, direct-to-cloud with ZIA peering with Microsoft in 150+ data centres | Microsoft 365, AWS, Azure | Eliminated ~500 GB/month of unwanted P2P traffic (named-executive quote); improved Microsoft 365 performance enterprise-wide | High - named customer, named CISO (Athanasiou), specific bandwidth metric | A concrete, quantified operational outcome (500 GB/month) rather than a vague efficiency claim - good evidence quality.
- Customer
- Named - NOV (National Oilwell Varco)
- Sector and geography
- Energy (oilfield services) · Global (150+ years of operating history, described as a global energy-industry supplier)
- Estate
- 27,500 users; Not quantified (global distributed enterprise)
- Outcome
- Leadership able to commit that all 27,500 users could work remotely on short notice - a specific, dated (2020 pandemic-era), verifiable capability claim
Named - NOV (National Oilwell Varco) | Energy (oilfield services) | Global (150+ years of operating history, described as a global energy-industry supplier) | 27,500 users | Not quantified (global distributed enterprise) | Needed to secure a globally distributed enterprise and enable work-from-anywhere, which proved fortuitous when COVID-19 required an immediate, complete remote-work pivot | ZPA, Zscaler Identity Proxy, Okta (identity), SentinelOne DataSet (log management/threat hunting) | Client-based remote access (ZPA) reducing data-centre traffic | Okta, SentinelOne | Leadership able to commit that all 27,500 users could work remotely on short notice - a specific, dated (2020 pandemic-era), verifiable capability claim | High - named customer, named executive (Philips), specific user count and a clearly dated real-world stress test | Genuinely the strongest case study Zscaler has for the 'remote-user-heavy organisation' suitability claim (Table 15) - real scale, a real crisis stress-test, and a named source.
- Customer
- Named - Baker & Baker
- Sector and geography
- Food manufacturing · Not specified (implied European/international given Zscaler customer profile)
- Estate
- Not quantified; Not quantified
- Outcome
- Ransomware incidents dropped from ~10/month to zero in the weeks and months immediately following deployment (named-executive quote)
Named - Baker & Baker | Food manufacturing | Not specified (implied European/international given Zscaler customer profile) | Not quantified | Not quantified | MPLS contract expiry prompted a rethink of connectivity and security; averaging ~10 ransomware incidents per month prior to Zscaler | ZIA, ZPA, SD-WAN | Hybrid - SD-WAN for connectivity, ZIA/ZPA for security, Azure and data-centre application access via ZPA | Microsoft Azure | Ransomware incidents dropped from ~10/month to zero in the weeks and months immediately following deployment (named-executive quote) | High - named customer, named executive (Erler), specific before/after metric | A genuinely strong, specific security outcome - the kind of concrete before/after figure that's more persuasive to a buyer than general marketing language.
Netify evaluation record
50 recordsSummary
Commercial reality | No public pricing; multiple independent third-party analyses converge reasonably well on per-user ranges (roughly $140-390/user/year combined ZIA+ZPA depending on tier) and describe a real risk of 30-100% cost escalation from common add-ons - directionally useful for budget conversations but not authoritative. | Table 16 | Medium (convergent third-party sourcing - stronger than a single anecdote, still not primary-sourced) | Use as a rough planning signal with buyers, always routing to a direct Zscaler quote for real numbers, exactly as advised for Cato's equivalent finding.
Use as a rough planning signal with buyers, always routing to a direct Zscaler quote for real numbers, exactly as advised for Cato's equivalent finding.
Summary
Reporting reality | Strong specifically around ZDX (network/application/user experience, AI-assisted root-cause diagnostics); weaker or unconfirmed on executive dashboards, compliance reporting, and scheduled/custom reporting, which weren't found in sources reviewed. | Table 10 | Medium | Present the ZDX strength specifically rather than imply comprehensive reporting maturity across the board - same approach used for Cato's equivalent finding.
Present the ZDX strength specifically rather than imply comprehensive reporting maturity across the board - same approach used for Cato's equivalent finding.
Summary
Security & Analytics | FedRAMP High + DoD IL5 authorisation, a Data Fabric for Security pulling from 150+ third-party sources, and deep native AI processing trillions of daily signals behind detection, remediation and digital-experience diagnostics. | ZIA and ZPA started life as related-but-separate products and still carry some of that history in licensing and console structure; higher-value DLP, analytics and AI capability is frequently gated behind Transformation/Unlimited tiers rather than the entry tier.
Summary
Large enterprise | Strong fit | NOV (27,500 users), AutoNation (large multi-site retailer) demonstrate enterprise-scale deployment | Requires internal or partner-supported operational ownership at scale | Enterprise-tier (Transformation/Unlimited) pricing likely, with meaningful cost escalation from add-ons per multiple independent third-party analyses | Well evidenced at the large end, comparable in evidence quality to Cato's Ulta Beauty story, via NOV specifically.
Summary
Firewall consolidation | Evidenced via AutoNation: 'full packet inspection firewall' replaced prior approach, eliminating unwanted P2P traffic | Existing firewall rules translated into ZIA policy | IT/security team | Not itemised | Not quantified | Policy translation errors during cutover (not specifically addressed in the source) | Not detailed | Real-world evidence exists via a named customer, though process detail (e.g. rule-migration tooling) wasn't found - same caveat applied to Cato's equivalent row.
Summary
SME | Conditional fit | Entry-level AWS Marketplace editions exist (e.g. a 50-user Business edition), but overall commercial evidence points toward mid-market/enterprise economics and per-user tier structures that reward scale | Minimal internal skills needed for the security core; branch/SD-WAN less proven at small scale | Smaller AWS Marketplace-listed editions give SMEs a concrete entry point, though pricing still climbs quickly with add-ons per third-party analysis | SMEs have a clearer self-serve entry point via Marketplace editions than was found for Cato, though the same tier-escalation caution applies once add-ons are needed.
Summary
Deployment & Ops | Massive global footprint (160+ data centres on six continents) with documented, tiered support SLAs (P1 response as fast as 15 minutes on premium tiers) and a mature Zero Trust Branch reference architecture that's largely plug-and-play hardware. | No owned private backbone - traffic relies on internet peering and cloud interconnects rather than a dedicated, SLA-backed middle mile, so performance is more exposed to public internet variability than backbone-based competitors like Cato.
Summary
When would Netify recommend looking elsewhere? (mandatory) | When a buyer specifically wants a private, SLA-backed backbone as the architectural core of their SASE deployment; when a buyer needs a large, already-proven branch/retail rollout track record at Ulta-Beauty-like scale; when a buyer needs pre-verified PCI-DSS, HIPAA, or UK/EU regulated-sector compliance out of the box; or when a buyer wants a single converged console replacing their existing security stack rather than a best-of-breed addition to it. | Synthesis of Tables 4, 7, 13, 15, 17 | Medium-High | Each trigger is tied to a specific, evidenced gap rather than a generic 'consider alternatives' hedge.
Each trigger is tied to a specific, evidenced gap rather than a generic 'consider alternatives' hedge.
Summary
Global multinational | Good fit, with coverage caveats | 160+ data centres, present in most countries, active regional expansion (e.g. Saudi Arabia) | Needs Netify/buyer to verify specific-country data-centre coverage, since named-country detail is thin outside North America, Europe and the Middle East (see Table 7) | Custom enterprise pricing | Table 7 findings | The architecture supports multinational buyers well, but - same caution as for Cato - don't assume complete country-level coverage without checking Zscaler's own current data-centre map.
Summary
Lean IT team | Good fit | Cloud-delivered, SaaS-model platform reduces on-prem hardware/patch burden; case studies (UST, Mindbody) describe reduced operational overhead | None significant for the security core; branch/SD-WAN operational maturity less proven | Support-tier upgrades (Premium, Premium Advanced) available to further reduce internal burden | Well evidenced for the security/access side; less proven for branch operations specifically, consistent with the pattern seen throughout this profile.
Summary
Commercials | Concrete, vendor-published price anchors exist via AWS Marketplace listings, giving buyers something real to plan a budget against even without a public list price. | No public list pricing; multiple independent third-party analyses describe steep step-ups between Business, Transformation and Unlimited tiers, and warn that ZDX, workload licensing and Data Protection add-ons can each add 30-100% to a baseline ZIA+ZPA quote.
Summary
Support/service reality | A credible, unusually well-documented tiered support structure (Standard through Premium Support Advanced Plus) with specific, contractual SLA figures (P1 response as fast as 15 minutes; MDR 10-minute notification) sourced directly from Zscaler's own data sheets. | Table 8 | High | One of the better-evidenced operational areas in this whole profile - genuinely strong primary-source material.
One of the better-evidenced operational areas in this whole profile - genuinely strong primary-source material.
Summary
Sector fit | US federal/public sector is by a wide margin the best-evidenced sector; retail and energy have credible single case studies; healthcare, financial services, education, hospitality, transport and manufacturing all lack the same depth of evidence found for the public-sector claim. | Table 14 | High for public sector; Medium for retail/energy; Low for other sectors | Do not extend the strong public-sector evidence into an assumption of equally strong healthcare/financial-services fit - those need separate verification.
Do not extend the strong public-sector evidence into an assumption of equally strong healthcare/financial-services fit - those need separate verification.
Summary
Regulated organisation | Strong fit for US federal/public sector specifically; conditional for other regulated sectors | FedRAMP High/Moderate, DoD IL5, GovRAMP, CJIS, CMMC Level 2 all confirmed for US government; PCI-DSS, HIPAA attestation, and UK/EU frameworks (NHS DSPT, DORA, NIS2) not confirmed | Buyer must independently verify sector-specific compliance status directly with Zscaler for anything outside US federal/public sector | Not assessed | Table 13 findings | A genuinely bifurcated picture: exceptionally strong for US federal/public sector, materially less evidenced for UK/EU-regulated sectors and for PCI-DSS/HIPAA specifically - don't let the federal strength imply blanket regulated-sector coverage.
Summary
What implementation challenges should buyers expect? (mandatory) | Expect a genuine need to map tier-to-feature detail carefully before committing, since advanced DLP, browser isolation and privileged access all appear to be gated to Transformation/Unlimited tiers rather than universally included. Expect total cost to grow meaningfully once ZDX, workload licensing and Data Protection add-ons are factored in - multiple independent analyses describe 30-100% uplifts from these. Branch-heavy buyers should expect to pilot Zero Trust Branch carefully given the thinner independent evidence base relative to the core security stack. | Tables 3, 5, 16, 17 | Medium-High | Each expectation is traceable to a specific finding elsewhere in this profile, not a generic caution.
Each expectation is traceable to a specific finding elsewhere in this profile, not a generic caution.
Summary
Scope & Boundaries | Very mature, long-standing SSE feature depth - Zscaler has been named a Gartner Secure Web Gateway Leader ten times running - spanning SWG, inline and API CASB, DLP, ZTNA and browser isolation. | Zscaler is fundamentally a security company that added branch/SD-WAN later (Zero Trust Branch, Zscaler Cellular), the reverse emphasis of a networking-first vendor - branch-heavy buyers should weigh that history against vendors built backbone-first from day one.
Summary
Procurement watch-out | Several compliance claims relevant to UK/EU buyers specifically (Cyber Essentials Plus, NHS DSPT, NIS2, DORA) were found via only a single, uncorroborated third-party review, or not found at all | UK/EU regulated-sector buyers cannot currently get a fully evidenced compliance answer from public sources alone and must request direct confirmation | Most relevant to Netify's UK healthcare, financial-services, and public-sector audiences specifically | Table 13 findings | Medium | A direct, practical follow-up item - mirrors the equivalent gap flagged for Cato, and equally important to close before this profile supports a high-stakes UK regulated-sector recommendation.
UK/EU regulated-sector buyers cannot currently get a fully evidenced compliance answer from public sources alone and must request direct confirmation
Summary
Deployment reality | Fast and well-evidenced on the security/remote-access side (Mindbody's 'five times faster than VPN' claim, NOV's rapid pandemic-era scale-up); genuinely less proven on the branch/SD-WAN side given the absence of a large-scale rollout case study. | Table 9, 17, 18 | Medium-High | Set expectations differently for the security core versus the branch/networking side - they're not equally mature.
Set expectations differently for the security core versus the branch/networking side - they're not equally mature.
Summary
MPLS to SD-WAN migration | Evidenced via Baker & Baker: MPLS contract expiry triggered adoption of SD-WAN alongside ZIA for internet/SaaS security | Existing MPLS circuits retired at contract end rather than coexisting mid-transition (in contrast to Cato's explicit coexistence capability) | IT team, per case study | Not itemised | Not quantified | Less gradual than Cato's documented MPLS-coexistence model - potentially a harder cutover point | Not detailed in sources reviewed | A real migration scenario is evidenced, but the mechanism (contract-expiry-triggered switch) is less flexible than a purpose-built coexistence feature - a fair, specific point of comparison.
Summary
Questions Netify still cannot verify | PCI-DSS and HIPAA attestation status; UK Cyber Essentials Plus and NHS DSPT/NIS2/DORA relevance; exact tier-to-feature mapping for DLP, browser isolation and privileged access; Zero Trust Branch hardware charging model; a large-scale, metric-rich branch rollout case study; and whether any Zscaler-delivered (as opposed to partner-delivered) fully-managed service exists. | Synthesis of Tables 4, 6, 13, 16 | N/A - explicitly unresolved | This list should drive the next follow-up (a direct Zscaler briefing or partner conversation) before this profile is considered fully closed out, in exactly the same spirit as the equivalent list in the Cato profile.
This list should drive the next follow-up (a direct Zscaler briefing or partner conversation) before this profile is considered fully closed out, in exactly the same spirit as the equivalent list in the Cato profile.
Summary
Cloud-first organisation | Good fit | Multi-cloud on-ramps (AWS, Azure, GCP) evidenced via Baker & Baker (Azure) specifically | None significant identified | Not itemised | Solid, evidenced by a real production deployment rather than platform-page claims alone.
Summary
Merger/acquisition integration | Referenced via the Zscaler-on-Zscaler case study describing the SPLX acquisition, where ZIA and DLP policies were deployed within five days of deal close | Not itemised beyond the five-day timeframe | Not itemised | Zscaler's own internal security team ('customer zero') | Five days from deal close to ZIA + DLP policy deployment (specific, dated) | Not itemised | Not detailed | A genuinely specific, dated, quantified M&A integration example - better evidence than Cato's equivalent row, which relied on general marketing-page positioning rather than a named scenario.
Summary
Biggest operational concern | Tier-to-feature opacity combined with documented add-on cost escalation creates real risk of buyers under-scoping their initial quote and facing a larger-than-expected bill once DLP, browser isolation, ZDX or workload licensing are actually needed. | Table 16, 19 | Medium | Netify should proactively flag this to buyers during the shortlist conversation rather than let it surface as a surprise at renewal.
Netify should proactively flag this to buyers during the shortlist conversation rather than let it surface as a surprise at renewal.
Summary
Highly distributed branch estate | Conditional fit | Zero Trust Branch exists and is architecturally sound, but lacks an equivalent to Cato's large-scale, metric-rich branch-rollout proof point (e.g. Ulta Beauty) | Zero-touch provisioning documented at the mechanism level, not proven at large operational scale in the evidence found | Site-based licensing implications not itemised | help.zscaler.com Zero Trust Branch reference architecture | This is the clearest area where Cato currently has a stronger evidence base than Zscaler - a fair, specific point to make to a branch-heavy buyer rather than assuming parity.
Summary
Compliance & Footprint | Exceptionally well-documented US federal and public-sector credentials - FedRAMP High/Moderate, GovRAMP, CJIS, CMMC Level 2 - alongside broad ISO 27001/27017/27018/27701 and SOC 2 Type II coverage. | UK- and region-specific certifications (Cyber Essentials Plus, NHS DSPT relevance) were found via only a single third-party review in this pass and are not independently confirmed on Zscaler's own compliance pages - don't assume coverage without asking directly.
Summary
Limitation | SD-WAN/branch capability (Zero Trust Branch) is real but has materially thinner independent evidence than the core security stack - no large-scale, metric-rich branch-rollout case study equivalent to Cato's Ulta Beauty story was found | Branch-heavy buyers should not assume the same maturity/proof-point depth on the networking side as on the security side | Affects highly distributed branch/retail buyers most | Table 4, 15, 17 findings | Medium-High | A fair, specific, well-evidenced gap rather than a vague impression - worth stating to buyers directly rather than softening.
Branch-heavy buyers should not assume the same maturity/proof-point depth on the networking side as on the security side
Summary
Global branch rollout | Zero Trust Branch reference architecture describes plug-and-play hardware install, but no large-scale, metric-rich branch rollout case study (comparable to Cato's Ulta Beauty story) was found in this pass | Existing branch network/Wi-Fi infrastructure to integrate or replace | Not itemised | Not itemised | Not quantified | Unproven at Cato-Ulta-Beauty-scale in the evidence available | Not detailed | The clearest, most specific gap in Zscaler's evidence base relative to Cato - worth being direct about this with buyers who need branch-rollout proof points specifically.
Summary
VPN to ZTNA migration | Evidenced via Baker & Baker and Mindbody: both explicitly describe eliminating VPNs in favour of ZPA | Existing VPN concentrator/client footprint retired | IT team | Not itemised | Mindbody: 'ZPA deploys five times more quickly than traditional VPN solutions' (customer quote) | Not itemised | Not detailed | This is Zscaler's best-evidenced migration scenario by a clear margin - two independent named customers specifically describing VPN elimination, with a concrete relative-speed claim from one of them.
Summary
Multi-vendor SASE integration | Well evidenced, in a different direction than Cato - Zscaler's strongest partner alliances (Okta, CrowdStrike) are explicitly built around being one best-of-breed component in a multi-vendor security architecture, not a single converged replacement for it | IdP and EDR already in place | Not itemised | Formal joint deployment guides and a hands-on integration lab | Not quantified | N/A | N/A | Worth stating plainly in the Netify View: Zscaler is, by design and by its strongest evidenced partnerships, genuinely well-suited to buyers wanting a best-of-breed multi-vendor stack - the reverse of Cato's positioning on this exact scenario.
Summary
Where does it fall behind competitors? (mandatory) | No owned private backbone, which is a genuine architectural gap against backbone-first SASE vendors like Cato for buyers prioritising predictable site-to-site WAN performance; SD-WAN/branch maturity and proof points are materially thinner than the security stack; and PCI-DSS/HIPAA attestations, which some competitors publish explicitly, were not found for Zscaler in this pass. | Tables 4, 7, 13, 15, 17 | Medium-High | Named specifically and evidenced, not a generic hedge - Netify can state these gaps with real confidence.
Named specifically and evidenced, not a generic hedge - Netify can state these gaps with real confidence.
Summary
Strength | Unmatched US federal/public-sector compliance depth - FedRAMP High, DoD IL5, GovRAMP, CJIS, CMMC Level 2, serving 14 of 15 US Cabinet-level agencies | Removes a major procurement blocker for US federal and regulated public-sector buyers that most SASE/SSE competitors can't clear | Best: US federal/state/local government. Less relevant: buyers with no US federal/government exposure | High | This is Zscaler's single clearest, most defensible differentiator in the entire profile.
Removes a major procurement blocker for US federal and regulated public-sector buyers that most SASE/SSE competitors can't clear
Summary
Limitation | No owned private backbone - the architecture relies on internet peering and cloud interconnects rather than an SLA-backed middle mile | Buyers wanting Cato-style predictable, backbone-based performance across a distributed estate should weigh this architectural difference directly, not assume parity | Affects distributed multi-site buyers most; less relevant to buyers whose primary need is internet/SaaS security rather than site-to-site WAN performance | Table 7 findings | High | The single most consequential architectural fact in this whole profile - should be stated plainly and early to any buyer comparing Zscaler against a backbone-first vendor.
Buyers wanting Cato-style predictable, backbone-based performance across a distributed estate should weigh this architectural difference directly, not assume parity
Summary
Questions to ask before recommending it | 1) Which Table 3 capabilities (advanced DLP, browser isolation, privileged remote access) are actually included at the buyer's target tier, versus requiring Transformation or Unlimited? 2) What would ZDX, workload licensing, and Data Protection add-ons realistically add to the buyer's total cost at their expected scale? 3) Can Zscaler confirm PCI-DSS, HIPAA, Cyber Essentials Plus, and NHS DSPT-relevant status directly, given none were independently confirmed in this pass? 4) For branch-heavy buyers specifically, can Zscaler provide a large-scale reference deployment comparable in evidence depth to what competitors can show? | Synthesis of Tables 3, 5, 13, 16, 17 | High | A direct, reusable question set for Netify's advisory conversations with buyers considering Zscaler.
A direct, reusable question set for Netify's advisory conversations with buyers considering Zscaler.
Summary
Mid-market | Good fit | Sweet spot implied by several case studies (Mindbody, UST) describing mid-sized, distributed organisations | Low - case studies show non-specialist IT teams managing rollouts successfully | Business-tier pricing likely applies; volume discounts documented above 1,000 users per third-party analysis (a reported 34-35% discount threshold) | Reasonably well evidenced by multiple mid-sized case studies.
Summary
Biggest operational advantage | Demonstrated ability to support a rapid, large-scale shift to secure remote access under real-world pressure, evidenced concretely via NOV's 27,500-user COVID-19-era pivot rather than just claimed in the abstract. | Table 15, 17, 18 | High | Directly quotable with the specific NOV figures for credibility.
Directly quotable with the specific NOV figures for credibility.
Summary
Procurement watch-out | PCI-DSS and HIPAA attestations, both explicitly confirmed for Cato in that profile, were not found for Zscaler in this research pass despite healthcare being listed as a served industry | Payment-handling and healthcare buyers should not assume compliance parity with competitors that do explicitly publish these attestations | Most relevant to retail/payments and healthcare buyers specifically | Table 13 findings | Medium | A specific, comparative finding worth surfacing directly - this is exactly the kind of vendor-to-vendor compliance gap Netify's comparison tool exists to catch.
Payment-handling and healthcare buyers should not assume compliance parity with competitors that do explicitly publish these attestations
Summary
When would Netify recommend it? (mandatory) | When a buyer needs FedRAMP High/DoD IL5-level government assurance; when a buyer's primary pain point is legacy VPN/firewall-appliance elimination and internet/SaaS/private-app security specifically; or when a buyer wants to add best-of-breed SSE into an existing security stack (particularly one already built around Okta and/or CrowdStrike, given the depth of that specific alliance). | Synthesis of Tables 12, 13, 15, 17 | High | A clear, actionable recommendation trigger set for Netify's comparison tool to apply directly.
A clear, actionable recommendation trigger set for Netify's comparison tool to apply directly.
Summary
Limitation | Commercial opacity plus documented tier-escalation risk - no public pricing, and multiple independent third-party analyses describe steep step-ups between Business/Transformation/Unlimited tiers with 30-100% cost increases from common add-ons (ZDX, workload licensing, Data Protection) | Buyers risk under-budgeting if they scope only the entry tier without accounting for the add-ons they'll likely need | Affects all buyer sizes, though the absolute cost impact is largest for large enterprises with big user/workload counts | Table 16 findings | Medium (convergent across multiple independent third-party sources) | The convergence across several independent pricing analyses makes this a reasonably confident finding despite the lack of primary-source pricing - Netify should flag the tier-escalation risk proactively rather than waiting for a buyer to discover it at quoting.
Buyers risk under-budgeting if they scope only the entry tier without accounting for the add-ons they'll likely need
Summary
Mature NetOps/SecOps team | Good fit, with a caveat | Deep, formally documented integrations (Okta, CrowdStrike) support a mature best-of-breed toolchain approach | Mature teams may find the still-separate ZIA/ZPA console history less unified than a platform designed as one product from day one | Not assessed | Table 12 findings | Worth noting candidly: Zscaler's strength is genuinely deep point-integration into an existing security stack (Okta/CrowdStrike alliance) rather than replacing that stack with a single converged console the way Cato pitches itself.
Summary
Strength | Genuinely mature, long-standing SSE stack (10x Gartner SWG MQ Leader) with a well-evidenced VPN-elimination migration story | Buyers retiring legacy VPN/proxy infrastructure get a proven, widely-adopted replacement path | Best: security-first enterprises with a VPN/firewall-appliance-heavy legacy estate. Less relevant: buyers without significant legacy VPN debt | High | Two independently named customers specifically describing VPN elimination is good, concrete evidence.
Buyers retiring legacy VPN/proxy infrastructure get a proven, widely-adopted replacement path
Summary
AI reality | A genuinely evidenced, actively-developing set of specific AI functions (Data Fabric threat correlation, ZDX AI diagnostics, agentic-AI guardrails) sits inside broader 'AI-driven' marketing language that extends further than what's independently confirmed for every claimed function. | Table 11 | Medium-High | Represent the narrower, evidenced AI feature set in buyer-facing content rather than the full marketing scope - consistent with the standard applied throughout this profile.
Represent the narrower, evidenced AI feature set in buyer-facing content rather than the full marketing scope - consistent with the standard applied throughout this profile.
Summary
Co-managed transition | Not documented as a distinct migration scenario in sources reviewed | Not itemised | Not itemised | Not itemised | Not quantified | Not itemised | Not detailed | Evidence gap - consistent with the broader finding that Zscaler doesn't appear to have a named co-managed service model (see Table 6).
Summary
Strength | Specific, current, well-evidenced AI investment - Data Fabric for Security, ZDX AI diagnostics, and a June 2026 agentic-AI security launch with 11 named Technology Alliance Partners | Buyers with active or planned agentic-AI/GenAI initiatives get security controls that are demonstrably being actively developed, not just marketed | Best: organisations rolling out GenAI/agentic AI tools who need governance controls now. Less relevant: buyers with no near-term AI-security need | Medium-High | One of the more concretely dated, named AI announcements found across this entire research pass - a genuine signal of active investment, not just AI-washing.
Buyers with active or planned agentic-AI/GenAI initiatives get security controls that are demonstrably being actively developed, not just marketed
Summary
Remote-user-heavy organisation | Strong fit, Zscaler's core strength | Client Connector, clientless access, ZDX all mature; NOV's 27,500-user remote pivot during COVID-19 is a strong, dated proof point | Requires ZDX licence for full experience visibility | User licensing is Zscaler's primary commercial model | Arguably Zscaler's single best-evidenced suitability claim in the whole profile - this is the core use case the platform was built for.
Summary
Most credible differentiator | The combination of FedRAMP High/DoD IL5 authorisation with a decade-plus-mature, independently-validated SSE stack - very few competitors clear the compliance bar and have the platform maturity to match it simultaneously. | Tables 3, 13 | High | This is the single sentence Netify's comparison engine could most confidently quote for Zscaler specifically.
This is the single sentence Netify's comparison engine could most confidently quote for Zscaler specifically.
Summary
Where does it stand out? (mandatory) | FedRAMP High/DoD IL5 government authorisation that very few SASE-class competitors clear; a decade-plus-mature SSE stack (10x Gartner SWG Leader) with well-evidenced VPN-elimination case studies; and a specific, actively-dated AI security investment (agentic AI guardrails launched June 2026 with 11 named partners). | Tables 3, 11, 13, 19 | High | These are the claims Netify can make most confidently and specifically to buyers, each backed by named, dated evidence rather than generic marketing language.
These are the claims Netify can make most confidently and specifically to buyers, each backed by named, dated evidence rather than generic marketing language.
Summary
Global fit | Architecturally global by design (160+ data centres, six continents), with genuinely better-evidenced Middle East coverage than Cato's profile showed, but named-country detail is thin outside North America, Europe and the Middle East. | Table 7 | Medium-High | Always verify buyer-specific country coverage directly rather than relying on the general 'most countries' claim.
Always verify buyer-specific country coverage directly rather than relying on the general 'most countries' claim.
Summary
Who is this genuinely best suited for? (mandatory) | Large enterprises and US federal/public-sector agencies wanting to retire legacy VPN and perimeter-firewall infrastructure and consolidate SWG, CASB, DLP and ZTNA under one security-first console - particularly where FedRAMP High or DoD IL5 authorisation is a hard requirement, and particularly for organisations whose primary need is securing internet/SaaS/private-app access rather than building out branch WAN infrastructure. | Tables 1, 13, 14, 15 (FedRAMP depth, remote-access maturity, case study evidence) | High | Buyers matching this profile can proceed with real confidence in the core security claims; buyers whose primary need is branch/SD-WAN maturity should weigh Table 4's evidence gaps carefully.
Buyers matching this profile can proceed with real confidence in the core security claims; buyers whose primary need is branch/SD-WAN maturity should weigh Table 4's evidence gaps carefully.
Summary
Overall Netify Assessment | Zscaler is the most credible, deeply-evidenced choice in this comparison set for buyers whose primary need is mature, government-grade SSE - the FedRAMP High/DoD IL5 authorisation and decade-plus-proven security stack are genuinely differentiated and well-documented. Its clearest weak points relative to a backbone-first competitor like Cato are the absence of an owned private backbone and a materially thinner evidence base for large-scale branch/SD-WAN deployment. Commercial opacity and tier-gating risk are real but at least directionally corroborated by multiple independent analyses, which is a stronger evidentiary position than a single anecdote would give. This profile is solid enough to support initial shortlist guidance for security-first and US public-sector buyers specifically, but the flagged UK/EU compliance gaps and branch-evidence gap should be closed out with Zscaler directly before use in a high-stakes procurement decision. | Whole profile | Medium-High overall | Recommend direct Zscaler engagement to close the flagged evidence gaps, mirroring the same next step recommended for the Cato profile.
Recommend direct Zscaler engagement to close the flagged evidence gaps, mirroring the same next step recommended for the Cato profile.
Summary
SSE deployment to remote users | Client Connector or clientless rollout to remote/mobile users; NOV's COVID-19-driven scale-up to 27,500 remote users is the standout evidence point | IdP integration (Okta) generally a prerequisite for user-aware policy | End-user self-install typical | Not itemised | NOV: leadership described being able to commit to supporting all 27,500 users working remotely on short notice | Not itemised | Not detailed | Genuinely strong, large-scale, real-world evidence - arguably stronger than the equivalent Cato row, since NOV's story includes both scale (27,500 users) and a clear time-pressure context (pandemic onset).
Public evidence sources
73 records- 01Techzine - Zscaler optimizes Zero Trust for agentic AI security (reporting on a Zscaler announcement) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 02Zscaler - Company FAQ · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 03Zscaler - Compliance Centre overview · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 04Zscaler - Compliance and Security Standards · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 05Zscaler - Customer Story: AutoNation · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 06Zscaler - Customer Story: Baker & Baker · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 07Zscaler - Customer Story: CSC · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 08Zscaler - Customer Story: Mindbody · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 09Zscaler - Customer Story: NOV · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 10Zscaler - Customer Story: UST · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 11Zscaler - Customer Story: Zscaler on Zscaler · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 12Zscaler - Data Security product page · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 13Zscaler - Government Cybersecurity / Federal Cybersecurity (CJIS, CMMC Level 2) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 14Zscaler - How Zero Trust Architecture Supports Regulatory Compliance · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 15Zscaler - Operations Technology Partners page (CrowdStrike, Okta, SentinelOne, Anomali, Recorded Future, Cyware, EclecticIQ integrations) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 16Zscaler - Premium Support Advanced Plus data sheet · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 17Zscaler - Premium Support Advanced data sheet · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 18Zscaler - Products & Solutions FAQ · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 19Zscaler - SLA & Support legal page (MDR, Business Insights SLAs) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 20Zscaler - Secure Internet Access with Zscaler Zero Trust Branch (reference architecture guide) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 21Zscaler - Securely Use Generative AI with Zscaler Zero Trust Exchange · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 22Zscaler - Securing GenAI and Microsoft Copilot with Zscaler Data Security · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 23Zscaler - Support Essentials data sheet (P1-P4 SLA response times) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 24Zscaler - Support Guide for US Government Cloud Customers data sheet · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 25Zscaler - Support Plus data sheet · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 26Zscaler - Zero Trust Cybersecurity Solutions for State and Local Government · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 27Zscaler - Zero Trust Security with Zscaler, Okta, and CrowdStrike (partner page) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 28Zscaler - Zero Trust Solutions for Federal Government · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 29Zscaler - Zscaler and the CCPA · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 30Zscaler - press release (via Reuters/TradingView): Zscaler Expands Public Data Centre Footprint in KSA · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 31Zscaler - press release: Extends Edge Compute, Now Operating in Over 150 Data Centres · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 32Zscaler - press release: Powers its Global Data Centres and Offices with 100% Renewable Energy (150+ data centres) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 33Zscaler - press release: Significantly Expands Global Sovereignty on Zero Trust Exchange Platform (160+ data centres, dedicated logging planes) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 34Zscaler - press release: Unveils New Product Innovations to Secure Agentic AI · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 35Zscaler - press release: Zscaler Achieves FedRAMP High Authorization · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 36Zscaler - press release: Zscaler Achieves ISO 27001 Certification for Cloud Security · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 37Zscaler Help Portal - Support Offerings · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 38Zscaler, Inc. - SEC Form 8-K (FY2026 earnings release) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 39Zscaler/Okta/CrowdStrike - joint Business Development / Deployment Guide · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 40Okta - Beyond the perimeter: How Okta, CrowdStrike, and Zscaler deliver end-to-end Zero Trust (Okta's own blog, independent named company) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 2
- 41ABANCA Case Study | Customer Stories | Zscalerzscaler.com · verified Sat Sep 12 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 42Best Negotiation Consulting Firms - Zscaler Enterprise Licensing & Pricing Guide 2026 (third-party) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 43Cabrillo Club - Zscaler Government Cloud FedRAMP Finder entry (third-party) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 44Capitec Bank Limited | Zscalerzscaler.com · verified Sat Sep 12 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 45CheckThat.ai - Zscaler Pricing 2026: Plans, Costs & TCO (third-party) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 46CyberSecurityO - Zscaler Review 2026: Zero Trust Platform (third-party) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 47Fannie Mae Case Study | Customer Stories | Zscalerzscaler.com · verified Sat Sep 12 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 48Hastings Direct Case Study | Customer Stories | Zscalerzscaler.com · verified Sat Sep 12 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 49How Zscaler DSPM Helps Europe's Financial Sector Achieve DORA Compliancezscaler.com · verified Sat Sep 12 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 50ITQlick - Zscaler Pricing 2026: Hidden Costs & Total ROI (third-party) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 51Luminix - Zscaler Company Overview report (third-party) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 52NoSaveNoPay - Zscaler Pricing: Zero Trust Network Access Enterprise Cost (third-party) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 53OneMain Financial Case Study | Customer Stories | Zscalerzscaler.com · verified Sat Sep 12 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 54PitchBook - Zscaler company profile · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 55Redress Compliance - Zscaler Enterprise Licensing Guide 2026 · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 56SASE Solutions for PCI DSS 4.0 Compliance & Enhanced Securityzscaler.com · verified Sat Sep 12 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 57SASE.cloud - Zscaler vendor profile (third-party comparison site) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 58The Network DNA - Zscaler ZTNA Architecture & Configuration Guide (third-party technical blog) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 59Understanding Digital Sovereignty in the Modern Erazscaler.com · verified Sat Sep 12 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 60Vendr - Zscaler Software Pricing & Plans 2026 · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 61Venn - Zscaler Pricing in 2026 (third-party) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 62WWT (Zscaler partner) - ZIA/CrowdStrike/Okta Integration Lab · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 63WWT (Zscaler partner) - Zscaler AI Security overview · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 64Web Asha Technologies - Zscaler Zero Trust Exchange in 2026 (third-party blog) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 65ZeroMetric - Zscaler Zero Trust Exchange 2026 Review (third-party) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 66ZeroTrustCost.com - Zscaler Pricing 2026 (third-party analysis summarising AWS Marketplace listing prices) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 67Zscaler Nanolog Streaming Service data sheetzscaler.com · verified Sat Sep 12 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 68Zscaler SLA Support | Service Level Agreement Documentationzscaler.com · verified Sat Sep 12 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 69Zscaler Security Cloud Receives FIPS 140-2 Validation for Encryptionir.zscaler.com · verified Sat Sep 12 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 70Zscaler Sub-Processors: Security & Privacy Standardszscaler.com · verified Sat Sep 12 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 71Zscaler Support Best Practices Guide (third-party-hosted slide deck of Zscaler material) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 72Zscaler for Manufacturingzscaler.com · verified Wed Jul 29 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 73Zscaler's Compliance Centercompliance.zscaler.com · verified Mon Sep 14 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
Profile contract provider-public/1.0.0. Machine-readable record: JSON.