NNetifyVersion 1010261227

Provider evidence

Zscaler

Zscaler is the vendor that effectively created the SSE category, and it’s still the one most competitors get measured against when it comes to sheer scale and security depth - the Zero Trust Exchange runs across 150+ data centres, processes over 400 billion transactions a day, and holds FedRAMP High authorisation for ZIA and ZPA (other SASE-class vendors also hold FedRAMP High or equivalent for their own components). If you’re a security-first buyer looking to retire VPN concentrators and stitch SWG, CASB, DLP and ZTNA together under one console, Zscaler is one of the most proven single-vendor routes to get there.

Technology vendor · UK entity not yet reviewed

Evidence profile: Retail and e-commerce; Manufacturing; Energy and utilities; Government and public sector; platform

    NOV case documents ZIA/ZPA and zero-trust access for an energy-industry supplier. Do not infer utility-specific compliance or UK fit. CSC is Australian Commonwealth Superannuation Corporation; ZIA/ZPA deployment confirmed. Government-pension context, not a blanket public-sector accreditation. Baker and Baker case documents ZIA/ZPA alongside a separately adopted SD-WAN. Manufacturing evidence; Zscaler is not identified as the SD-WAN provider. Mindbody is a SaaS software business serving wellness firms. Its ZPA deployment does not establish professional-services or healthcare end-buyer sector evidence. AutoNation confirms ZIA deployment across retail locations. Baker and Baker must not be counted as a second retail case; it is manufacturing. This is sector experience only; scope, UK delivery and suitability for the buyer require separate confirmation.

    Research only

    https://www.zscaler.com

    These capabilities use the same evidence as the provider shortlist and matching. A missing finding is not evidence that a provider lacks the capability.

    Capability evidence

    CapabilityFindingEvidence and qualification
    Fully managed servicePartial

    We partner with service providers to develop comprehensive managed offers that leverage the Zero Trust Exchange, our industry-leading security platform, to enable profitable managed service provider business models. Zscaler operates the platform itself and sells one first-party managed service (Zscaler MDR, security operations). On its own partner page the comprehensive managed offer is built and delivered by service provider partners, not by Zscaler. No Zscaler page was found describing Zscaler itself designing, deploying, changing and reporting on a customer's end-to-end service, so graded partial rather than yes.

    Source · Evidence dated 2026-07-29
    DIY / self-managed modelYesSee the published provider record for source context; confirm the scope for your deployment.
    Co-managed serviceNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Multi-tenant MSP / white-label supportPartial

    The Multi-Tenant Portal has long been the cornerstone for Managed Service Providers (MSPs) and large-scale enterprises to oversee multiple Zscaler instances. Tenant isolation, cross-tenant pivoting and centralised delegated administration through ZIdentity are documented for MSPs. Nothing was found on Zscaler's own pages evidencing branded or white-label portals under the partner's own brand, and the definition requires that. The definitive partner portal documentation on help.zscaler.com could not be read because it is a JavaScript-only page (register 23). Graded partial for that reason.

    Source · Evidence dated 2026-07-29
    Professional services and migration supportYesSee the published provider record for source context; confirm the scope for your deployment.
    Last-mile circuit managementNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Lifecycle managementNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Flexible commercial modelNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Encrypted overlay fabricYesSee the published provider record for source context; confirm the scope for your deployment.
    Dynamic path selectionNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Active-active link utilisationNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Application-aware routingNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    QoS and traffic shapingNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Packet loss remediationNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Local internet breakoutNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    MPLS coexistence and migrationNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Cellular and 5G supportPartial

    Devices use Zscaler SIMs to steer traffic securely to the Zero Trust Exchange with no need for additional software. Zscaler Cellular provides Zscaler-issued SIMs that carry cellular IoT and mobile device traffic into the Zero Trust Exchange, which covers SIM provisioning and management. The definition also asks for 4G and 5G as primary or failover WAN transport with modem and signal monitoring. Neither the Cellular product page nor the July 2025 cellular press release names 4G, 5G or LTE, the private 5G page concerns securing a customer's private 5G core rather than WAN transport, and the Zero Trust SD-WAN datasheet contains no cellular uplink specification. Graded partial on that gap.

    Source · Evidence dated 2026-07-29
    Cloud on-rampYesSee the published provider record for source context; confirm the scope for your deployment.
    Public cloud gatewaysYes

    Zscaler already operates 160+ data centers and is present in most countries. This is Zscaler's own infrastructure, not a resold third party's, so yes rather than partner_integrated. The reference architecture confirms Zscaler deploys its own ZIA Service Edge devices into those data centres and that users are always directed to the nearest one for traffic processing, which is security enforcement and SaaS access delivered as the vendor's own cloud service.

    Source · Evidence dated 2026-07-29
    Private PoPs / dedicated PoPsYes

    ZIA Private Service Edge and ZIA Virtual Service Edge devices extend the Zscaler cloud into your data center. Directly meets the definition: customer-hosted and dedicated deployments exist alongside the shared multi-tenant Public Service Edges. The March 2026 sovereignty press release additionally describes Private Service Edges as single-tenant, customer-hosted, and Zscaler-managed appliances, plus dedicated control and logging planes in six countries, which covers the sovereign case.

    Source · Evidence dated 2026-07-29
    Private global backboneNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Regional breakout and data residencyNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Multi-cloud transit fabricYesSee the published provider record for source context; confirm the scope for your deployment.
    Flexible edge form factorsNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    High availability designNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    SLA-backed service fabricNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Integrated next-generation firewallYesSee the published provider record for source context; confirm the scope for your deployment.
    Full SASE platformYesSee the published provider record for source context; confirm the scope for your deployment.
    SSE ecosystem integrationNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Zero Trust Network AccessYesSee the published provider record for source context; confirm the scope for your deployment.
    Secure web gatewayYesSee the published provider record for source context; confirm the scope for your deployment.
    CASB capabilityNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Data loss preventionYesSee the published provider record for source context; confirm the scope for your deployment.
    Remote user accessYesSee the published provider record for source context; confirm the scope for your deployment.
    SOC/SIEM/SOAR integrationYesSee the published provider record for source context; confirm the scope for your deployment.
    Centralised orchestrationNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Customer portal and RBACNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Observability and digital experience monitoringYesSee the published provider record for source context; confirm the scope for your deployment.
    APIs and automationNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Managed service assuranceNot confirmedSee the published provider record for source context; confirm the scope for your deployment.