SSE / SASE platform
Zscaler
Sources evidence Zscaler ZIA/ZPA integration with SD-WAN and Zscaler Zero Trust SASE with fresh SD-WAN approach; historically SSE-led.
Netify profile
Zscaler in depth
Platform and architecture
Zscaler runs the Zero Trust Exchange, a security cloud of 160+ PoPs processing hundreds of billions of transactions daily. Users, workloads and devices connect to the nearest PoP where policy is enforced; there is no network to join, which is the architectural point. Zscaler does not ship SD-WAN appliances: branch connectivity pairs the Exchange with third-party SD-WAN, and Zscaler Zero Trust Branch options reduce branch hardware needs.
Security and SASE capability
ZIA (internet and SaaS security) and ZPA (private application access) are category-defining: SWG, CASB, DLP, sandboxing, browser isolation and the most widely deployed ZTNA in the market, with AI-powered phishing and command-and-control detection. Zscaler Digital Experience (ZDX) adds user experience monitoring. For SSE capability depth and scale, Zscaler sets the benchmark most rivals are measured against.
Service, support and channel
Strong UK presence direct and through security partners and carriers; BT, Vodafone and global SIs deliver managed Zscaler. Deployment is agent and tunnel based with substantial professional services ecosystems. Support tiers run to 24x7 with TAM options; operating Zscaler well still demands skilled policy ownership in-house or via partner.
Commercials and the Netify verdict
Per-user subscription bundles (Editions) that are quote based and premium; transaction volumes justify it for large estates. The Netify verdict: shortlist Zscaler when a zero trust programme leads the agenda, when SSE depth and global PoP scale matter, and when SD-WAN is solved separately. Small organisations and single-site estates are outside its sweet spot.
Evaluate Zscaler properly
An AI can summarise Zscaler. It cannot gather structured, evidence-backed responses from Zscaler and its closest competitors. Describe your requirement once at netify.co.uk and Zscaler arrives pinned for an evidence-graded evaluation: the market takes position around your words, one signature publishes an anonymous notice free, and matched vendors respond side by side with pricing private to you.
AI assistants can score Zscaler against a requirements list directly with the score_vendor_fit tool on the Netify connector, and build the same position with workspace_ingest.
Questions
Zscaler: common buyer questions
Does Zscaler replace my SD-WAN?
Not entirely. Zscaler replaces the security stack and removes much branch security hardware, while site-to-site connectivity still wants an SD-WAN layer; common pairings include Catalyst, EdgeConnect, Fortinet and VeloCloud feeding traffic into the Exchange.
What is the difference between ZIA and ZPA?
ZIA secures traffic to internet and SaaS destinations (SWG, CASB, DLP, sandboxing). ZPA brokers least-privilege access to private applications without placing users on the network, replacing VPN concentrators. Most deployments run both.
Is Zscaler suitable for mid-market UK organisations?
Yes via managed routes: BT, Vodafone and UK MSPs wrap Zscaler with deployment and operations. Direct DIY suits organisations with capable security teams; smaller estates often find the licensing premium harder to justify.
Key differentiators
- Category leader in SSE with ZIA, ZPA and ZDX; widely adopted as the security layer in best-of-breed SASE architectures.
- Strong ecosystem of SD-WAN partners (Cisco, others) for buyers wanting Zscaler security with a separate SD-WAN platform.
- Mature Zero Trust platform with substantial enterprise deployment history.
Best fit for
- Enterprises selecting best-of-breed SSE alongside a separate SD-WAN platform.
- Security-driven SASE strategies where the SSE layer is the primary architectural decision.
- Buyers consolidating multiple security point solutions onto a single SSE vendor.
Watch-outs
- Historically SSE-led; native SD-WAN capability is less mature than dedicated SD-WAN platforms (validate path selection, QoS and packet loss in RFP).
- Premium pricing; typically per-user/workload/location with security modules adding cost.
- Buyers needing one vendor for both SD-WAN and security may prefer a converged platform (Cato, FortiSASE, Prisma).
40 features, 6 categories
Capability matrix
Each capability is graded against public source evidence. Hover any status grade for a definition. Where evidence is limited, the grade reflects that uncertainty rather than assuming the capability is present.
Service delivery and operating model
| # | Capability | Status | Definition |
|---|---|---|---|
| F01 | Fully managed service | Partial | Provider designs, deploys, monitors, changes, supports and reports on the service. |
| F02 | DIY / self-managed model | Yes | Customer operates SD-WAN controller, policies, updates and incident response. |
| F03 | Co-managed service | Partial | Provider runs platform/support while customer retains selected policy or change rights. |
| F04 | Multi-tenant MSP / white-label support | Partial | Tenant isolation, delegated administration, branded portals, templates and service-provider scale. |
| F05 | Professional services and migration support | Yes | Discovery, design, pilot, staging, migration runbooks, rollback and training. |
| F06 | Last-mile circuit management | Partner / integrated | Sourcing, monitoring and support for broadband, DIA, LTE/5G, MPLS and cross-connects. |
| F07 | Lifecycle management | Unknown | Hardware replacement, firmware upgrades, patching, renewals and EoL planning. |
| F08 | Flexible commercial model | Yes | Per-site, per-bandwidth, per-user, per-device, consumption, NaaS or bundled pricing. |
Network architecture and transport
| # | Capability | Status | Definition |
|---|---|---|---|
| F09 | Encrypted overlay fabric | Partial | Secure tunnels across broadband, DIA, MPLS, LTE/5G, satellite or private WAN. |
| F10 | Dynamic path selection | Partial | Real-time routing based on latency, jitter, packet loss, brownouts, MOS and policy. |
| F11 | Active-active link utilisation | Partial | Use multiple links concurrently rather than passive backup only. |
| F12 | Application-aware routing | Partial | Identification and routing for SaaS, UCaaS, ERP and custom applications. |
| F13 | QoS and traffic shaping | Partial | Per-application and per-class prioritisation, reservation and policing. |
| F14 | Packet loss remediation | Partial | FEC, packet duplication, jitter buffering, TCP optimisation and WAN optimisation. |
| F15 | Local internet breakout | Partial | Secure direct internet access from branch sites. |
| F16 | MPLS coexistence and migration | Partial | Hybrid MPLS/internet/cellular during transition. |
| F17 | Cellular and 5G support | Partial | Integrated/external modem, SIM management, signal monitoring and failover. |
| F18 | Cloud on-ramp | Yes | Automated/simplified connectivity to AWS, Azure, Google Cloud, Oracle, Equinix, Megaport and SaaS. |
Gateway, PoP and backbone design
| # | Capability | Status | Definition |
|---|---|---|---|
| F19 | Public cloud gateways | Yes | Vendor-operated gateways/PoPs for SaaS optimisation, remote access or security enforcement. |
| F20 | Private PoPs / dedicated PoPs | Yes | Customer-hosted, dedicated or sovereign PoP options. |
| F21 | Private global backbone | Not primary | Vendor-owned or controlled backbone between PoPs. |
| F22 | Regional breakout and data residency | Yes | Pin traffic to countries, regions or approved inspection locations. |
| F23 | Multi-cloud transit fabric | Yes | Branch-to-cloud, cloud-to-cloud and user-to-cloud connectivity under common policy. |
| F24 | Flexible edge form factors | Partial | Physical, virtual, cloud marketplace, container or uCPE. |
| F25 | High availability design | Partial | Dual appliances, dual circuits, dual power, HA clustering and gateway redundancy. |
| F26 | SLA-backed service fabric | Yes | SLA for uptime, response, change handling and possibly latency/jitter/loss. |
Security and SASE capability
| # | Capability | Status | Definition |
|---|---|---|---|
| F27 | Integrated next-generation firewall | Yes | Stateful firewall, app control, IPS/IDS, malware inspection and URL filtering. |
| F28 | Full SASE platform | Yes | SD-WAN plus SWG, CASB, ZTNA, FWaaS, DLP, RBI, DNS security and threat prevention. |
| F29 | SSE ecosystem integration | Yes | Interoperation with Zscaler, Netskope, Palo Alto Prisma Access, Cisco Secure Access, Cloudflare etc. |
| F30 | Zero Trust Network Access | Yes | Identity and posture-based access to private applications. |
| F31 | Secure web gateway | Yes | URL filtering, SSL inspection, malware scanning and acceptable-use controls. |
| F32 | CASB capability | Yes | SaaS discovery, sanctioned/unsanctioned app control and SaaS policy enforcement. |
| F33 | Data loss prevention | Yes | Data classification, inspection, blocking, alerting and exception workflow. |
| F34 | Remote user access | Yes | Client or clientless access for remote workers, contractors and mobile users. |
| F35 | SOC/SIEM/SOAR integration | Yes | Syslog, APIs, event export, threat intelligence and workflow integration. |
Operations, assurance and automation
| # | Capability | Status | Definition |
|---|---|---|---|
| F36 | Centralised orchestration | Yes | Templates, intent-based policy, zero-touch provisioning and configuration compliance. |
| F37 | Customer portal and RBAC | Yes | Real-time status, role-based access, reporting, tickets and change requests. |
| F38 | Observability and digital experience monitoring | Yes | App experience, user experience, device health, SaaS telemetry and path analytics. |
| F39 | APIs and automation | Yes | REST APIs, Terraform, webhooks, event streaming and ITSM integration. |
| F40 | Managed service assurance | Partial | 24/7 NOC/SOC, proactive monitoring, incident ownership, RCA, service reviews and change governance. |
Commercial
Cost model and pricing visibility
Public pricing visibility
Quote-based. No complete public enterprise price was found in reviewed sources.
Cost model
Quote-based subscription; typically per-user/workload/location modules; SD-WAN integrations may add partner/vendor cost.
Evidence
Sources and exclusions
40 facts about Zscaler were re-verified on 2026-07-29 against named sources, each carrying a sentence quoted from the source and confirmed present on that page. 37 sources were used. 14 more were read and rejected, and are listed below with the reason.
| Fact | Finding | Evidence | Quoted from the source |
|---|---|---|---|
| Fully managed service | Partial | [10] [12] [13] | "We partner with service providers to develop comprehensive managed offers that leverage the Zero Trust Exchange, our industry-leading security platform, to enable profitable managed service provider business models." |
| Co-managed service | Partial | [1] [12] [13] | "Human-led, hands-on-keyboard response acts as an extension of your security team and ensures threats can be mitigated even when your team is unavailable, 24x7x365." |
| Multi-tenant MSP / white-label support | Partial | [11] [10] | "The Multi-Tenant Portal has long been the cornerstone for Managed Service Providers (MSPs) and large-scale enterprises to oversee multiple Zscaler instances." |
| Professional services and migration support | Yes | [7] | "Review current Zscaler implementation and operations, provide leading practices, recommendations and remediation plan" |
| Lifecycle management | Not found | [15] [16] [17] | Not found in public sources reviewed. The Zero Trust Branch product page, the Zero Trust SD-WAN datasheet and the Zero Trust Branch datasheet were all read specifically for hardware replacement or RMA, firmware upgrade, patching, renewals and end-of-life statements. The datasheets list appliance models (ZT 400, ZT 600, ZT 800, ZT 8010) and single-touch provisioning but say nothing about who owns firmware upgrades, hardware replacement or end-of-life planning. Absence is not being treated as a no. |
| Cellular and 5G support | Partial | [8] [19] [18] [16] | "Devices use Zscaler SIMs to steer traffic securely to the Zero Trust Exchange with no need for additional software." |
| Public cloud gateways | Yes | [4] [3] [14] | "Zscaler already operates 160+ data centers and is present in most countries." |
| Private PoPs / dedicated PoPs | Yes | [14] [4] [3] | "ZIA Private Service Edge and ZIA Virtual Service Edge devices extend the Zscaler cloud into your data center." |
| Private global backbone | Not primary | [3] [14] [20] | "Direct peering with major internet and SaaS providers and public cloud destinations ensures the fastest traffic path possible." |
| SLA-backed service fabric | Yes | [1] [3] | "The SaaS will be available to accept Customer's Transactions and Sessions 99.999% of the total hours during every month Customer uses the SaaS" |
| Integrated next-generation firewall | Yes | [5] [3] | "Built on a cloud native platform, a zero trust firewall protects web and non-web traffic for all users, apps, locations, and clouds." |
| Data loss prevention | Yes | [6] [3] | "Deliver high-performance DLP inspection across web and email data." |
| Managed service assurance | Partial | [13] [12] [1] | "Human-led, hands-on-keyboard response acts as an extension of your security team and ensures threats can be mitigated even when your team is unavailable, 24x7x365." |
| delivery model | both | [10] [12] [13] | "We partner with service providers to develop comprehensive managed offers that leverage the Zero Trust Exchange, our industry-leading security platform, to enable profitable managed service provider business models." |
| underlay ownership | customer_supplied_only | [3] [14] [8] | "Direct peering with major internet and SaaS providers and public cloud destinations ensures the fastest traffic path possible." |
| sse layer ownership | native | [3] [5] [4] [14] | "Distributed across more than 160 data centers globally, the SSE-based Zero Trust Exchange™ is the world's largest in-line cloud security platform." |
| regulatory documentation | documented | [9] | "Zscaler compliance enablers are built on foundational programs focusing on data protection and regulatory requirements, including ISO 27001, ISO 27701, SOC 2, and various others." |
| pop count | 160 | [4] [3] | "Zscaler already operates 160+ data centers and is present in most countries." |
| sla availability pct | 99.999 | [1] [3] | "The SaaS will be available to accept Customer's Transactions and Sessions 99.999% of the total hours during every month Customer uses the SaaS" |
| sectors.healthcare | Yes | [27] [25] | "Leverage a HIPAA- and HITECH-compliant zero trust architecture" |
| sectors.financial services | Yes | [28] [34] [25] | "We embraced security as a journey that ran in parallel with our exploration of our applications, data, and transaction processing." |
| sectors.retail ecommerce | Not found | [25] [26] [49] | No retail or ecommerce industry page exists on the industries index, which lists only banking and financial services, healthcare, US public sector, Australian government, China, education and manufacturing. Retail-looking names (Kingfisher, Belkin International, J&P Cycles, Sunkist) appear in the customers logo wall, but that page carries no per-customer industry labelling and no case study behind those names, so there is nothing to quote. The customer success stories index that would have carried industry filter labels returned 404. Graded unknown rather than partial because the word 'retail' was not found in any sector list or sentence on the pages read. |
| sectors.manufacturing | Yes | [29] [25] | "Zero trust principles are incredibly relevant to smart factory initiatives." |
| sectors.energy utilities | Not found | [25] [38] [49] | No energy or utilities industry page on the industries index and the words energy and utilities were not found as a sector label on any page read. NOV, an oilfield equipment company, appears as a named customer on the platform page under the headline 'NOV secures access for 27,000 employees across 60 countries', and Viridor Waste Management and SemGroup Corporation appear in the customer logo wall, but none of these is presented by Zscaler as energy sector evidence. Deliberately not inferring an energy grade from a customer that happens to operate in that industry. |
| sectors.government public sector | Yes | [30] [37] [25] | "Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) have been FedRAMP Moderate authorized since 2018." |
| sectors.education | Yes | [31] [37] [25] | "Comply with CIPA, StateRAMP, CMMC, and more" |
| sectors.transport logistics | Yes | [38] [26] | "United Airlines detects and blocks evolving threats" |
| sectors.professional services | Not found | [25] [26] [49] | No professional services industry page and the sector is not named in any list or sentence on the pages read. Intertek, MindTree, AGC Partners and Applied Systems appear in the customer logo wall with no case study or industry label behind them. Nothing quotable, so unknown rather than partial. |
| sectors.hospitality leisure | Not found | [25] [26] | No hospitality or leisure industry page and no named hospitality customer or case study found. The closest names in the customer logo wall are sports and entertainment organisations (Houston Rockets, Miami Heat, Village Roadshow, NBC Universal), which are not hospitality or leisure operators in the sense this field measures. No evidence either way. |
| regions.uk ireland | Partial | [39] [28] [26] | "160+ Global data centers, with users in 185 countries" |
| regions.europe | Yes | [29] [38] [39] | "Zero trust principles are incredibly relevant to smart factory initiatives." |
| regions.north america | Yes | [30] [31] [27] | "Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) are both JAB-High authorized." |
| regions.asia pacific | Yes | [37] [27] | "The Zscaler Zero Trust Exchange™ has completed its IRAP assessment at PROTECTED, providing details on the implementation, appropriateness, and effectiveness of the system's security controls." |
| regions.middle east africa | Partial | [28] [38] [39] | "…we're constantly asking ourselves, 'What is the best thing we can do to serve our clients?'" |
| regions.latin america | Not found | [41] [39] [25] | Actively checked and not found. The company news blog index was searched specifically for Latin America, Brazil and Mexico coverage or expansion announcements and returned nothing. No Latin American customer appears in the customer logo wall, no Spanish or Portuguese language regional page was surfaced, and the investor relations global figure of '160+ Global data centers, with users in 185 countries' is an aggregate that says nothing about the region. The unreadable config.zscaler.com node list would very likely show Latin American cities, so this unknown reflects a retrieval limit, not a claim that coverage is absent. |
| regions.china mainland | Yes | [32] [25] | "Zscaler helps multinational organizations provide fast, consistent, reliable, and secure internet connectivity to international websites and SaaS applications, such as Microsoft 365, Salesforce, and ServiceNow, for their employees in mainland China." |
| organisation fit.large global enterprise | Yes | [35] [39] [26] | "9.4K+ customers, including 40% of the Forbes Global 2000" |
| organisation fit.mid market | Not found | [33] [40] [35] | Checked deliberately and found nothing. The pricing page names bundles (Essentials Platform marked 'RECOMMENDED', and Zscaler Platform) but does not segment them by organisation size, and the products and solutions hub contains no mid-market or SMB language. No case study of a mid-sized organisation was found; the smallest named deployment encountered was Seattle Children's Hospital at '4,000+ users47 sites4 US states'. The Essentials Platform bundle could plausibly be a mid-market entry point but Zscaler does not describe it that way, and inferring that would be exactly the reasoning this exercise exists to remove. |
| organisation fit.small business | Not found | [40] [33] [35] | No small business or SMB targeting language found on the products hub, the pricing page or the about page. Zscaler does not explicitly say small business is out of scope, so this is unknown rather than not_primary. The observable evidence, a customer base described by Global 2000 penetration and a case study set consisting entirely of large organisations, points away from small business, but there is no published statement to grade against. |
| published pricing | not_published | none | No price is published that we could quote. The value_tier field on this record is a Netify assessment of relative cost position, not a supplier claim. |
Sources used
- [1] Tier 1. Zscaler SLA Support | Service Level Agreement Documentation Undated. Read 2026-07-29. Vendor's own published contractual SLA schedule. Highest quality source for availability, latency and support response commitments. No publication date printed.
- [2] Tier 1. Zscaler Extends Edge Compute, Now Operating Over 150 Data Centers (press release) Published 2019-09-17. Read 2026-07-29. Vendor press release, dated. Reliable for its date but superseded on PoP count by later 2026 material. Retained because it documents a conflicting figure.
- [3] Tier 1. Zscaler Internet Access data sheet (PDF) Undated. Read 2026-07-29. Vendor datasheet. Strong for product capability and headline figures. Undated, and PDF text extraction may reflow line breaks.
- [4] Tier 1. Zscaler Significantly Expands Global Sovereignty on Zero Trust Exchange Platform (press release) Published 2026-03-12. Read 2026-07-29. Vendor press release with an explicit date, most recent statement of data centre count and sovereign or dedicated deployment options.
- [5] Tier 1. Zero Trust Cloud Firewall | Zscaler Undated. Read 2026-07-29. Vendor product page. Reliable for whether the firewall is native to the platform. Marketing register, undated.
- [6] Tier 1. Zscaler Data Protection product page Undated. Read 2026-07-29. Vendor product page for DLP and data classification. Undated marketing page but explicit on capability.
- [7] Tier 1. Zscaler Professional Services (PDF datasheet) Undated. Read 2026-07-29. Vendor services datasheet listing deployment package scope, pilots and education credits. Undated; content is largely tabular so extracted strings are short fragments rather than prose.
- [8] Tier 1. Simplify IoT & Mobile Security with Zscaler Cellular Undated. Read 2026-07-29. Vendor product page for the Zscaler Cellular SIM-based service. Undated.
- [9] Tier 1. Zscaler's Compliance Center Undated. Read 2026-07-29. Vendor-operated compliance portal listing named certifications and attestations. Undated but is the vendor's authoritative compliance index.
- [10] Tier 1. Service Provider Partners - Zscaler Undated. Read 2026-07-29. Vendor partner programme page. Reliable for how managed offers are routed to market. Undated, light on operational detail.
- [11] Tier 1. Streamlining Multi-Tenant Management: Announcing Integration of the Multi-Tenant Portal (Zscaler blog) Published 2026-03-25. Read 2026-07-29. Vendor blog with an explicit publication date, describing the Multi-Tenant Portal for MSPs. Dated vendor material so usable as Tier 1, but it is product marketing rather than documentation.
- [12] Tier 1. Zscaler Managed Detection & Response (MDR) product page Undated. Read 2026-07-29. Vendor product page for Zscaler's own managed service. Undated.
- [13] Tier 1. Zscaler MDR: 24/7 Managed Detection & Response (PDF brochure) Undated. Read 2026-07-29. Vendor brochure. Explicit on 24x7x365 human-led response. Undated.
- [14] Tier 1. Traffic Forwarding in Zscaler Internet Access Reference Architecture (PDF) Undated. Read 2026-07-29. Vendor reference architecture, the most technical source read. Strong on Service Edge types and peering. Undated and states 150+ data centres, which conflicts with newer material.
- [15] Tier 1. Zero Trust Branch: Secure, Simplify, and Connect with Zscaler Undated. Read 2026-07-29. Vendor product page. Read for lifecycle and cellular evidence; contained neither beyond a zero touch provisioning table entry.
- [16] Tier 1. Zscaler Zero Trust SD-WAN (PDF datasheet) Undated. Read 2026-07-29. Vendor datasheet with appliance models. Read specifically for cellular uplinks, firmware update and RMA or lifecycle statements; none were present.
- [17] Tier 1. Zero Trust Branch: A simpler, safer, more cost-effective way to connect (PDF datasheet) Undated. Read 2026-07-29. Vendor datasheet. Read for lifecycle management and cellular; neither documented.
- [18] Tier 1. Zero Trust 5G Architecture for Private 5G | Zscaler Undated. Read 2026-07-29. Vendor product page. Concerns securing a customer's private 5G core, not 4G or 5G as WAN transport, so of limited use for the cellular capability definition.
- [19] Tier 1. Zscaler Extends Zero Trust Platform to Enable Cellular Communications for IoT/OT (press release) Published 2025-07-08. Read 2026-07-29. Dated vendor press release. Confirms SIM-based cellular service but does not name 4G, 5G or LTE.
- [20] Tier 3. Internet 2.0: A Quantum Leap for Secure Global Connectivity (Zscaler blog, Teridion partnership) Published 2023-04-02. Read 2026-07-29. Corroboration only. Describes a third party (Teridion Liquid Network) overlay rather than Zscaler-owned infrastructure, and is three years old. Not sufficient to grade backbone ownership on its own.
- [25] Tier 1. Zscaler Industries index Undated. Read 2026-07-29. Supplier's own industries hub. Used to establish which industries Zscaler actually publishes dedicated pages for: banking and financial services, healthcare, US public sector (federal, state and local), Australian government, China, education, manufacturing. Absence of retail, energy, transport, professional services and hospitality pages is itself informative.
- [26] Tier 1. Zscaler Customer Journeys Undated. Read 2026-07-29. Supplier's own customer index. Large logo wall with named customers but no verbatim sector labelling per customer, so it supports scale claims rather than per-sector grading.
- [27] Tier 1. Zscaler for Healthcare Undated. Read 2026-07-29. Supplier's own dedicated healthcare industry page with four named healthcare customers and named executives, plus HIPAA/HITECH framework claims. Strong for sector grading, vendor-claimed.
- [28] Tier 1. Zscaler for Financial Services Undated. Read 2026-07-29. Supplier's own dedicated financial services page with four named customers and attributed quotes. Strong for sector grading, vendor-claimed.
- [29] Tier 1. Zscaler for Manufacturing Undated. Read 2026-07-29. Supplier's own dedicated manufacturing page with four named manufacturers (Siemens AG, AkzoNobel, Coats, Sanmina) and attributed executive quotes. Strong for sector grading, vendor-claimed.
- [30] Tier 1. Zscaler for Public Sector Undated. Read 2026-07-29. Supplier's own public sector page. Carries verifiable third-party accreditation claims (FedRAMP JAB-High, FedRAMP Moderate, TIC 3.0, CJIS) plus named agency case studies (FCC, State of Oklahoma). Accreditation claims are checkable against the FedRAMP marketplace, raising reliability above ordinary marketing copy.
- [31] Tier 1. Zscaler for Education (public sector) Undated. Read 2026-07-29. Supplier's own education page with named institutions (New York City Department of Education, University of South Carolina, Virginia Commonwealth University, MCNC) and CIPA compliance claim. Strong for sector grading, vendor-claimed.
- [32] Tier 1. Zscaler China Premium Access Undated. Read 2026-07-29. Supplier's own dedicated mainland China product page. Establishes a specific named China offering rather than a generic global claim. Does NOT disclose the licensing arrangement, in-country data centres or local carrier partner, so it evidences a service offering but not the regulatory mechanism behind it.
- [33] Tier 1. Zscaler Pricing and Plans Undated. Read 2026-07-29. Supplier's own pricing page. Names bundles (Essentials Platform, Zscaler Platform) and add-on modules but publishes no per-user or list prices. Reliable evidence that pricing is NOT published.
- [34] Tier 1. Zscaler digital transformation for the banking sector Undated. Read 2026-07-29. Supplier's own banking landing page, linked from the industries index. Corroborates the same four named financial services customers as source 4.
- [35] Tier 1. About Zscaler Undated. Read 2026-07-29. Supplier's own corporate page. Customer count and Forbes Global 2000 penetration figure are the clearest published statement of target organisation size.
- [36] Tier 1. Zscaler Company FAQ Undated. Read 2026-07-29. Supplier's own FAQ. Contains employee and customer counts that CONFLICT with sources 11 and 15 (states 'nearly 8,000 customers' against 9.4K+ elsewhere), suggesting a stale page. Recorded, not relied on. Contains no data centre or country figures.
- [37] Tier 1. Zscaler for Australian Government Undated. Read 2026-07-29. Supplier's own page carrying an IRAP assessment at PROTECTED plus a long list of named Australian government and education bodies. The IRAP claim is an independently checkable accreditation, making this the strongest single region-specific delivery evidence found.
- [38] Tier 1. Zscaler Unified Platform Undated. Read 2026-07-29. Supplier's own platform page carrying named customer story headlines (United Airlines, NOV, Baker & Baker, Careem) with attributed CIO/CISO quotes. Used for transport evidence. Headlines do not state each customer's industry label.
- [39] Tier 1. Zscaler Investor Relations Undated. Read 2026-07-29. Supplier's own investor relations site. Infrastructure and scale figures aimed at investors carry securities-disclosure exposure, so more accountable than marketing copy. However the data centre figure is a global aggregate with no regional breakdown, so it cannot grade an individual region on its own.
- [40] Tier 1. Zscaler Products and Solutions Undated. Read 2026-07-29. Supplier's own product hub. Checked specifically for SMB or mid-market segmentation and found none. Used as negative evidence for organisation fit.
- [41] Tier 1. Zscaler Company News blog Undated. Read 2026-07-29. Supplier's own news index. Checked for Latin America, Brazil and Mexico coverage or expansion announcements; none present. Used as negative evidence for the Latin America region.
Sources found and not used
These were read and rejected as evidence. They are listed so the record can be audited rather than taken on trust, and because what a comparison refuses to rely on says as much as what it cites.
- [21] Understanding Private Service Edge for Internet & SaaS (Zscaler Help Portal). https://help.zscaler.com/zia/understanding-private-service-edge Not used as evidence: the help portal is a JavaScript single-page application and returned only an enable-JS stub, so no content was actually retrieved and no quote could be verified.
- [22] About Private Service Edges (Zscaler Help Portal, ZPA). https://help.zscaler.com/zpa/about-private-service-edges Not used as evidence: JavaScript-only page, returned an enable-JS stub with no retrievable text.
- [23] What Is Zscaler Management Portal for Partners? (Zscaler Help Portal). https://help.zscaler.com/zia/what-zscaler-management-portal-partners Not used as evidence: JavaScript-only page, returned an enable-JS stub, so the partner multi-tenancy documentation could not be quoted.
- [24] Zscaler Zero Trust Exchange platform page (attempted). https://www.zscaler.com/products-and-solutions/zscaler-zero-trust-exchange Not used as evidence: returned HTTP 404, no content retrieved.
- [42] Zscaler industries/education (guessed URL). https://www.zscaler.com/industries/education Not used as evidence. Returned HTTP 404. The real education page sits under the public sector path (source 7).
- [43] Zscaler industries/education-cybersecurity (guessed URL). https://www.zscaler.com/industries/education-cybersecurity Not used as evidence. Returned HTTP 404. Speculative URL tried before the real link list was extracted.
- [44] Zscaler data centres (guessed URL). https://www.zscaler.com/company/data-protection/data-centers Not used as evidence. Returned HTTP 404.
- [45] Zscaler Experience Center data centre locations (guessed URL). https://www.zscaler.com/experience-center/data-center-locations Not used as evidence. Returned HTTP 404.
- [46] Zscaler Cloud Enforcement Node ranges (config portal). https://config.zscaler.com/zscaler.net/cenr Not used as evidence. This is the authoritative per-city data centre list, but the page is a JavaScript single-page application and returned only an 'enable JS' stub to a text fetcher. This is the main reason region grading rests on named customers and accreditations rather than a published points-of-presence list.
- [47] Zscaler Trust Portal. https://trust.zscaler.com/ Not used as evidence. JavaScript-only application; returned an 'enable JS' stub with no retrievable cloud or data centre content.
- [48] Zscaler help portal, ZIA data centre locations. https://help.zscaler.com/zia/data-center-locations Not used as evidence. JavaScript-only documentation portal; returned an 'enable JS' stub.
- [49] Zscaler customer success stories index (guessed URL). https://www.zscaler.com/resources/customer-success-stories Not used as evidence. Returned HTTP 404. Was sought specifically to obtain per-customer industry filter labels that would have allowed retail, energy, professional services and hospitality grading.
- [50] Zscaler company data centre locations (guessed URL). https://www.zscaler.com/company/data-center-locations Not used as evidence. Returned HTTP 404.
- [51] AWS Marketplace Zscaler listing attempt. https://aws.amazon.com/marketplace/pp/prodview-jvzhmr6mhqqoi Not used as evidence. The fetch resolved to the AWS Marketplace navigation shell rather than the product detail pane, returning no listed contract pricing. Marketplace pricing remains the most likely route to a real price point and was not obtainable in this task.
Claims that disagree
Where two sources conflict, both are recorded rather than one being chosen quietly. Confirm these directly with the vendor.
- pop count. [4] Zscaler already operates 160+ data centers and is present in most countries. [2] It is now distributed across more than 150 data centers on six continents
- pop count. [3] Distributed across more than 160 data centers globally, the SSE-based Zero Trust Exchange™ is the world's largest in-line cloud security platform. [14] Zscaler has deployed ZIA Service Edge devices in 150+ data centers around the world.
Verification notes
Re-verified 2026-07-29 against named primary sources. Every graded fact carries a source, a tier and a verbatim quote confirmed present on the cited page by an independent check. Industry, region, organisation-size and pricing evidence was sourced on the same basis. Facts that could not be sourced are published as unknown with the reason. The value_tier field is a Netify assessment of relative cost position, not a supplier claim: most of this market publishes no price. Sources found and rejected are listed at tier 4.
Where next
Continue your Zscaler evaluation
AI advisor · Continue from this page · Zscaler · evaluated 29 Jul 2026
Describe what you need
Your first sentence is drafted from this page. Edit it, or replace it with your own words: sites, regions, what must not go down.
Drafted from this page. Everything you type stays yours to edit before anything is published.
Zscaler arrives pinned; the evaluated market takes position around your words. Nothing runs until you go, and nothing publishes without your signature.
Opens your procurement on Netify
Working with an assistant? Connect netify.co.uk/sase/api/mcp/ and use workspace_ingest with this page as context.