Provider evidence
Zscaler
Zscaler is the vendor that effectively created the SSE category, and it’s still the one most competitors get measured against when it comes to sheer scale and security depth - the Zero Trust Exchange runs across 150+ data centres, processes over 400 billion transactions a day, and holds FedRAMP High authorisation for ZIA and ZPA (other SASE-class vendors also hold FedRAMP High or equivalent for their own components). If you’re a security-first buyer looking to retire VPN concentrators and stitch SWG, CASB, DLP and ZTNA together under one console, Zscaler is one of the most proven single-vendor routes to get there.
Technology vendor · UK entity not yet reviewed
Evidence profile: Retail and e-commerce; Manufacturing; Energy and utilities; Government and public sector; platform
NOV case documents ZIA/ZPA and zero-trust access for an energy-industry supplier. Do not infer utility-specific compliance or UK fit. CSC is Australian Commonwealth Superannuation Corporation; ZIA/ZPA deployment confirmed. Government-pension context, not a blanket public-sector accreditation. Baker and Baker case documents ZIA/ZPA alongside a separately adopted SD-WAN. Manufacturing evidence; Zscaler is not identified as the SD-WAN provider. Mindbody is a SaaS software business serving wellness firms. Its ZPA deployment does not establish professional-services or healthcare end-buyer sector evidence. AutoNation confirms ZIA deployment across retail locations. Baker and Baker must not be counted as a second retail case; it is manufacturing. This is sector experience only; scope, UK delivery and suitability for the buyer require separate confirmation.
- https://zscaler.com/customers/nov
- https://zscaler.com/customers/csc
- https://zscaler.com/customers/baker-baker
- https://zscaler.com/customers/mindbody
- https://zscaler.com/customers/autonation
Research only
https://www.zscaler.comThese capabilities use the same evidence as the provider shortlist and matching. A missing finding is not evidence that a provider lacks the capability.
Capability evidence
| Capability | Finding | Evidence and qualification |
|---|---|---|
| Fully managed service | Partial | We partner with service providers to develop comprehensive managed offers that leverage the Zero Trust Exchange, our industry-leading security platform, to enable profitable managed service provider business models. Zscaler operates the platform itself and sells one first-party managed service (Zscaler MDR, security operations). On its own partner page the comprehensive managed offer is built and delivered by service provider partners, not by Zscaler. No Zscaler page was found describing Zscaler itself designing, deploying, changing and reporting on a customer's end-to-end service, so graded partial rather than yes. Source · Evidence dated 2026-07-29 |
| DIY / self-managed model | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Co-managed service | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Multi-tenant MSP / white-label support | Partial | The Multi-Tenant Portal has long been the cornerstone for Managed Service Providers (MSPs) and large-scale enterprises to oversee multiple Zscaler instances. Tenant isolation, cross-tenant pivoting and centralised delegated administration through ZIdentity are documented for MSPs. Nothing was found on Zscaler's own pages evidencing branded or white-label portals under the partner's own brand, and the definition requires that. The definitive partner portal documentation on help.zscaler.com could not be read because it is a JavaScript-only page (register 23). Graded partial for that reason. Source · Evidence dated 2026-07-29 |
| Professional services and migration support | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Last-mile circuit management | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Lifecycle management | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Flexible commercial model | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Encrypted overlay fabric | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Dynamic path selection | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Active-active link utilisation | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Application-aware routing | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| QoS and traffic shaping | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Packet loss remediation | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Local internet breakout | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| MPLS coexistence and migration | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Cellular and 5G support | Partial | Devices use Zscaler SIMs to steer traffic securely to the Zero Trust Exchange with no need for additional software. Zscaler Cellular provides Zscaler-issued SIMs that carry cellular IoT and mobile device traffic into the Zero Trust Exchange, which covers SIM provisioning and management. The definition also asks for 4G and 5G as primary or failover WAN transport with modem and signal monitoring. Neither the Cellular product page nor the July 2025 cellular press release names 4G, 5G or LTE, the private 5G page concerns securing a customer's private 5G core rather than WAN transport, and the Zero Trust SD-WAN datasheet contains no cellular uplink specification. Graded partial on that gap. Source · Evidence dated 2026-07-29 |
| Cloud on-ramp | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Public cloud gateways | Yes | Zscaler already operates 160+ data centers and is present in most countries. This is Zscaler's own infrastructure, not a resold third party's, so yes rather than partner_integrated. The reference architecture confirms Zscaler deploys its own ZIA Service Edge devices into those data centres and that users are always directed to the nearest one for traffic processing, which is security enforcement and SaaS access delivered as the vendor's own cloud service. Source · Evidence dated 2026-07-29 |
| Private PoPs / dedicated PoPs | Yes | ZIA Private Service Edge and ZIA Virtual Service Edge devices extend the Zscaler cloud into your data center. Directly meets the definition: customer-hosted and dedicated deployments exist alongside the shared multi-tenant Public Service Edges. The March 2026 sovereignty press release additionally describes Private Service Edges as single-tenant, customer-hosted, and Zscaler-managed appliances, plus dedicated control and logging planes in six countries, which covers the sovereign case. Source · Evidence dated 2026-07-29 |
| Private global backbone | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Regional breakout and data residency | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Multi-cloud transit fabric | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Flexible edge form factors | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| High availability design | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| SLA-backed service fabric | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Integrated next-generation firewall | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Full SASE platform | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| SSE ecosystem integration | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Zero Trust Network Access | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Secure web gateway | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| CASB capability | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Data loss prevention | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Remote user access | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| SOC/SIEM/SOAR integration | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Centralised orchestration | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Customer portal and RBAC | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Observability and digital experience monitoring | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| APIs and automation | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Managed service assurance | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |