NNetify

SSE / SASE platform

Zscaler

Sources evidence Zscaler ZIA/ZPA integration with SD-WAN and Zscaler Zero Trust SASE with fresh SD-WAN approach; historically SSE-led.


Netify profile

Zscaler in depth

Platform and architecture

Zscaler runs the Zero Trust Exchange, a security cloud of 160+ PoPs processing hundreds of billions of transactions daily. Users, workloads and devices connect to the nearest PoP where policy is enforced; there is no network to join, which is the architectural point. Zscaler does not ship SD-WAN appliances: branch connectivity pairs the Exchange with third-party SD-WAN, and Zscaler Zero Trust Branch options reduce branch hardware needs.

Security and SASE capability

ZIA (internet and SaaS security) and ZPA (private application access) are category-defining: SWG, CASB, DLP, sandboxing, browser isolation and the most widely deployed ZTNA in the market, with AI-powered phishing and command-and-control detection. Zscaler Digital Experience (ZDX) adds user experience monitoring. For SSE capability depth and scale, Zscaler sets the benchmark most rivals are measured against.

Service, support and channel

Strong UK presence direct and through security partners and carriers; BT, Vodafone and global SIs deliver managed Zscaler. Deployment is agent and tunnel based with substantial professional services ecosystems. Support tiers run to 24x7 with TAM options; operating Zscaler well still demands skilled policy ownership in-house or via partner.

Commercials and the Netify verdict

Per-user subscription bundles (Editions) that are quote based and premium; transaction volumes justify it for large estates. The Netify verdict: shortlist Zscaler when a zero trust programme leads the agenda, when SSE depth and global PoP scale matter, and when SD-WAN is solved separately. Small organisations and single-site estates are outside its sweet spot.

Evaluate Zscaler properly

An AI can summarise Zscaler. It cannot gather structured, evidence-backed responses from Zscaler and its closest competitors. Describe your requirement once at netify.co.uk and Zscaler arrives pinned for an evidence-graded evaluation: the market takes position around your words, one signature publishes an anonymous notice free, and matched vendors respond side by side with pricing private to you.

AI assistants can score Zscaler against a requirements list directly with the score_vendor_fit tool on the Netify connector, and build the same position with workspace_ingest.

Questions

Zscaler: common buyer questions

Does Zscaler replace my SD-WAN?

Not entirely. Zscaler replaces the security stack and removes much branch security hardware, while site-to-site connectivity still wants an SD-WAN layer; common pairings include Catalyst, EdgeConnect, Fortinet and VeloCloud feeding traffic into the Exchange.

What is the difference between ZIA and ZPA?

ZIA secures traffic to internet and SaaS destinations (SWG, CASB, DLP, sandboxing). ZPA brokers least-privilege access to private applications without placing users on the network, replacing VPN concentrators. Most deployments run both.

Is Zscaler suitable for mid-market UK organisations?

Yes via managed routes: BT, Vodafone and UK MSPs wrap Zscaler with deployment and operations. Direct DIY suits organisations with capable security teams; smaller estates often find the licensing premium harder to justify.

Key differentiators

  • Category leader in SSE with ZIA, ZPA and ZDX; widely adopted as the security layer in best-of-breed SASE architectures.
  • Strong ecosystem of SD-WAN partners (Cisco, others) for buyers wanting Zscaler security with a separate SD-WAN platform.
  • Mature Zero Trust platform with substantial enterprise deployment history.

Best fit for

  • Enterprises selecting best-of-breed SSE alongside a separate SD-WAN platform.
  • Security-driven SASE strategies where the SSE layer is the primary architectural decision.
  • Buyers consolidating multiple security point solutions onto a single SSE vendor.

Watch-outs

  • Historically SSE-led; native SD-WAN capability is less mature than dedicated SD-WAN platforms (validate path selection, QoS and packet loss in RFP).
  • Premium pricing; typically per-user/workload/location with security modules adding cost.
  • Buyers needing one vendor for both SD-WAN and security may prefer a converged platform (Cato, FortiSASE, Prisma).

40 features, 6 categories

Capability matrix

Each capability is graded against public source evidence. Hover any status grade for a definition. Where evidence is limited, the grade reflects that uncertainty rather than assuming the capability is present.

Service delivery and operating model

#CapabilityStatusDefinition
F01Fully managed servicePartialProvider designs, deploys, monitors, changes, supports and reports on the service.
F02DIY / self-managed modelYesCustomer operates SD-WAN controller, policies, updates and incident response.
F03Co-managed servicePartialProvider runs platform/support while customer retains selected policy or change rights.
F04Multi-tenant MSP / white-label supportPartialTenant isolation, delegated administration, branded portals, templates and service-provider scale.
F05Professional services and migration supportYesDiscovery, design, pilot, staging, migration runbooks, rollback and training.
F06Last-mile circuit managementPartner / integratedSourcing, monitoring and support for broadband, DIA, LTE/5G, MPLS and cross-connects.
F07Lifecycle managementUnknownHardware replacement, firmware upgrades, patching, renewals and EoL planning.
F08Flexible commercial modelYesPer-site, per-bandwidth, per-user, per-device, consumption, NaaS or bundled pricing.

Network architecture and transport

#CapabilityStatusDefinition
F09Encrypted overlay fabricPartialSecure tunnels across broadband, DIA, MPLS, LTE/5G, satellite or private WAN.
F10Dynamic path selectionPartialReal-time routing based on latency, jitter, packet loss, brownouts, MOS and policy.
F11Active-active link utilisationPartialUse multiple links concurrently rather than passive backup only.
F12Application-aware routingPartialIdentification and routing for SaaS, UCaaS, ERP and custom applications.
F13QoS and traffic shapingPartialPer-application and per-class prioritisation, reservation and policing.
F14Packet loss remediationPartialFEC, packet duplication, jitter buffering, TCP optimisation and WAN optimisation.
F15Local internet breakoutPartialSecure direct internet access from branch sites.
F16MPLS coexistence and migrationPartialHybrid MPLS/internet/cellular during transition.
F17Cellular and 5G supportPartialIntegrated/external modem, SIM management, signal monitoring and failover.
F18Cloud on-rampYesAutomated/simplified connectivity to AWS, Azure, Google Cloud, Oracle, Equinix, Megaport and SaaS.

Gateway, PoP and backbone design

#CapabilityStatusDefinition
F19Public cloud gatewaysYesVendor-operated gateways/PoPs for SaaS optimisation, remote access or security enforcement.
F20Private PoPs / dedicated PoPsYesCustomer-hosted, dedicated or sovereign PoP options.
F21Private global backboneNot primaryVendor-owned or controlled backbone between PoPs.
F22Regional breakout and data residencyYesPin traffic to countries, regions or approved inspection locations.
F23Multi-cloud transit fabricYesBranch-to-cloud, cloud-to-cloud and user-to-cloud connectivity under common policy.
F24Flexible edge form factorsPartialPhysical, virtual, cloud marketplace, container or uCPE.
F25High availability designPartialDual appliances, dual circuits, dual power, HA clustering and gateway redundancy.
F26SLA-backed service fabricYesSLA for uptime, response, change handling and possibly latency/jitter/loss.

Security and SASE capability

#CapabilityStatusDefinition
F27Integrated next-generation firewallYesStateful firewall, app control, IPS/IDS, malware inspection and URL filtering.
F28Full SASE platformYesSD-WAN plus SWG, CASB, ZTNA, FWaaS, DLP, RBI, DNS security and threat prevention.
F29SSE ecosystem integrationYesInteroperation with Zscaler, Netskope, Palo Alto Prisma Access, Cisco Secure Access, Cloudflare etc.
F30Zero Trust Network AccessYesIdentity and posture-based access to private applications.
F31Secure web gatewayYesURL filtering, SSL inspection, malware scanning and acceptable-use controls.
F32CASB capabilityYesSaaS discovery, sanctioned/unsanctioned app control and SaaS policy enforcement.
F33Data loss preventionYesData classification, inspection, blocking, alerting and exception workflow.
F34Remote user accessYesClient or clientless access for remote workers, contractors and mobile users.
F35SOC/SIEM/SOAR integrationYesSyslog, APIs, event export, threat intelligence and workflow integration.

Operations, assurance and automation

#CapabilityStatusDefinition
F36Centralised orchestrationYesTemplates, intent-based policy, zero-touch provisioning and configuration compliance.
F37Customer portal and RBACYesReal-time status, role-based access, reporting, tickets and change requests.
F38Observability and digital experience monitoringYesApp experience, user experience, device health, SaaS telemetry and path analytics.
F39APIs and automationYesREST APIs, Terraform, webhooks, event streaming and ITSM integration.
F40Managed service assurancePartial24/7 NOC/SOC, proactive monitoring, incident ownership, RCA, service reviews and change governance.

Commercial

Cost model and pricing visibility

Public pricing visibility

Quote-based. No complete public enterprise price was found in reviewed sources.

Cost model

Quote-based subscription; typically per-user/workload/location modules; SD-WAN integrations may add partner/vendor cost.


Evidence

Sources and exclusions

40 facts about Zscaler were re-verified on 2026-07-29 against named sources, each carrying a sentence quoted from the source and confirmed present on that page. 37 sources were used. 14 more were read and rejected, and are listed below with the reason.

Sourced facts for Zscaler, each with its grade, the source it rests on and the sentence quoted from that source.
FactFindingEvidenceQuoted from the source
Fully managed servicePartial[10] [12] [13]"We partner with service providers to develop comprehensive managed offers that leverage the Zero Trust Exchange, our industry-leading security platform, to enable profitable managed service provider business models."
Co-managed servicePartial[1] [12] [13]"Human-led, hands-on-keyboard response acts as an extension of your security team and ensures threats can be mitigated even when your team is unavailable, 24x7x365."
Multi-tenant MSP / white-label supportPartial[11] [10]"The Multi-Tenant Portal has long been the cornerstone for Managed Service Providers (MSPs) and large-scale enterprises to oversee multiple Zscaler instances."
Professional services and migration supportYes[7]"Review current Zscaler implementation and operations, provide leading practices, recommendations and remediation plan"
Lifecycle managementNot found[15] [16] [17]Not found in public sources reviewed. The Zero Trust Branch product page, the Zero Trust SD-WAN datasheet and the Zero Trust Branch datasheet were all read specifically for hardware replacement or RMA, firmware upgrade, patching, renewals and end-of-life statements. The datasheets list appliance models (ZT 400, ZT 600, ZT 800, ZT 8010) and single-touch provisioning but say nothing about who owns firmware upgrades, hardware replacement or end-of-life planning. Absence is not being treated as a no.
Cellular and 5G supportPartial[8] [19] [18] [16]"Devices use Zscaler SIMs to steer traffic securely to the Zero Trust Exchange with no need for additional software."
Public cloud gatewaysYes[4] [3] [14]"Zscaler already operates 160+ data centers and is present in most countries."
Private PoPs / dedicated PoPsYes[14] [4] [3]"ZIA Private Service Edge and ZIA Virtual Service Edge devices extend the Zscaler cloud into your data center."
Private global backboneNot primary[3] [14] [20]"Direct peering with major internet and SaaS providers and public cloud destinations ensures the fastest traffic path possible."
SLA-backed service fabricYes[1] [3]"The SaaS will be available to accept Customer's Transactions and Sessions 99.999% of the total hours during every month Customer uses the SaaS"
Integrated next-generation firewallYes[5] [3]"Built on a cloud native platform, a zero trust firewall protects web and non-web traffic for all users, apps, locations, and clouds."
Data loss preventionYes[6] [3]"Deliver high-performance DLP inspection across web and email data."
Managed service assurancePartial[13] [12] [1]"Human-led, hands-on-keyboard response acts as an extension of your security team and ensures threats can be mitigated even when your team is unavailable, 24x7x365."
delivery modelboth[10] [12] [13]"We partner with service providers to develop comprehensive managed offers that leverage the Zero Trust Exchange, our industry-leading security platform, to enable profitable managed service provider business models."
underlay ownershipcustomer_supplied_only[3] [14] [8]"Direct peering with major internet and SaaS providers and public cloud destinations ensures the fastest traffic path possible."
sse layer ownershipnative[3] [5] [4] [14]"Distributed across more than 160 data centers globally, the SSE-based Zero Trust Exchange™ is the world's largest in-line cloud security platform."
regulatory documentationdocumented[9]"Zscaler compliance enablers are built on foundational programs focusing on data protection and regulatory requirements, including ISO 27001, ISO 27701, SOC 2, and various others."
pop count160[4] [3]"Zscaler already operates 160+ data centers and is present in most countries."
sla availability pct99.999[1] [3]"The SaaS will be available to accept Customer's Transactions and Sessions 99.999% of the total hours during every month Customer uses the SaaS"
sectors.healthcareYes[27] [25]"Leverage a HIPAA- and HITECH-compliant zero trust architecture"
sectors.financial servicesYes[28] [34] [25]"We embraced security as a journey that ran in parallel with our exploration of our applications, data, and transaction processing."
sectors.retail ecommerceNot found[25] [26] [49]No retail or ecommerce industry page exists on the industries index, which lists only banking and financial services, healthcare, US public sector, Australian government, China, education and manufacturing. Retail-looking names (Kingfisher, Belkin International, J&P Cycles, Sunkist) appear in the customers logo wall, but that page carries no per-customer industry labelling and no case study behind those names, so there is nothing to quote. The customer success stories index that would have carried industry filter labels returned 404. Graded unknown rather than partial because the word 'retail' was not found in any sector list or sentence on the pages read.
sectors.manufacturingYes[29] [25]"Zero trust principles are incredibly relevant to smart factory initiatives."
sectors.energy utilitiesNot found[25] [38] [49]No energy or utilities industry page on the industries index and the words energy and utilities were not found as a sector label on any page read. NOV, an oilfield equipment company, appears as a named customer on the platform page under the headline 'NOV secures access for 27,000 employees across 60 countries', and Viridor Waste Management and SemGroup Corporation appear in the customer logo wall, but none of these is presented by Zscaler as energy sector evidence. Deliberately not inferring an energy grade from a customer that happens to operate in that industry.
sectors.government public sectorYes[30] [37] [25]"Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) have been FedRAMP Moderate authorized since 2018."
sectors.educationYes[31] [37] [25]"Comply with CIPA, StateRAMP, CMMC, and more"
sectors.transport logisticsYes[38] [26]"United Airlines detects and blocks evolving threats"
sectors.professional servicesNot found[25] [26] [49]No professional services industry page and the sector is not named in any list or sentence on the pages read. Intertek, MindTree, AGC Partners and Applied Systems appear in the customer logo wall with no case study or industry label behind them. Nothing quotable, so unknown rather than partial.
sectors.hospitality leisureNot found[25] [26]No hospitality or leisure industry page and no named hospitality customer or case study found. The closest names in the customer logo wall are sports and entertainment organisations (Houston Rockets, Miami Heat, Village Roadshow, NBC Universal), which are not hospitality or leisure operators in the sense this field measures. No evidence either way.
regions.uk irelandPartial[39] [28] [26]"160+ Global data centers, with users in 185 countries"
regions.europeYes[29] [38] [39]"Zero trust principles are incredibly relevant to smart factory initiatives."
regions.north americaYes[30] [31] [27]"Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) are both JAB-High authorized."
regions.asia pacificYes[37] [27]"The Zscaler Zero Trust Exchange™ has completed its IRAP assessment at PROTECTED, providing details on the implementation, appropriateness, and effectiveness of the system's security controls."
regions.middle east africaPartial[28] [38] [39]"…we're constantly asking ourselves, 'What is the best thing we can do to serve our clients?'"
regions.latin americaNot found[41] [39] [25]Actively checked and not found. The company news blog index was searched specifically for Latin America, Brazil and Mexico coverage or expansion announcements and returned nothing. No Latin American customer appears in the customer logo wall, no Spanish or Portuguese language regional page was surfaced, and the investor relations global figure of '160+ Global data centers, with users in 185 countries' is an aggregate that says nothing about the region. The unreadable config.zscaler.com node list would very likely show Latin American cities, so this unknown reflects a retrieval limit, not a claim that coverage is absent.
regions.china mainlandYes[32] [25]"Zscaler helps multinational organizations provide fast, consistent, reliable, and secure internet connectivity to international websites and SaaS applications, such as Microsoft 365, Salesforce, and ServiceNow, for their employees in mainland China."
organisation fit.large global enterpriseYes[35] [39] [26]"9.4K+ customers, including 40% of the Forbes Global 2000"
organisation fit.mid marketNot found[33] [40] [35]Checked deliberately and found nothing. The pricing page names bundles (Essentials Platform marked 'RECOMMENDED', and Zscaler Platform) but does not segment them by organisation size, and the products and solutions hub contains no mid-market or SMB language. No case study of a mid-sized organisation was found; the smallest named deployment encountered was Seattle Children's Hospital at '4,000+ users47 sites4 US states'. The Essentials Platform bundle could plausibly be a mid-market entry point but Zscaler does not describe it that way, and inferring that would be exactly the reasoning this exercise exists to remove.
organisation fit.small businessNot found[40] [33] [35]No small business or SMB targeting language found on the products hub, the pricing page or the about page. Zscaler does not explicitly say small business is out of scope, so this is unknown rather than not_primary. The observable evidence, a customer base described by Global 2000 penetration and a case study set consisting entirely of large organisations, points away from small business, but there is no published statement to grade against.
published pricingnot_publishednoneNo price is published that we could quote. The value_tier field on this record is a Netify assessment of relative cost position, not a supplier claim.

Sources used

  1. [1] Tier 1. Zscaler SLA Support | Service Level Agreement Documentation Undated. Read 2026-07-29. Vendor's own published contractual SLA schedule. Highest quality source for availability, latency and support response commitments. No publication date printed.
  2. [2] Tier 1. Zscaler Extends Edge Compute, Now Operating Over 150 Data Centers (press release) Published 2019-09-17. Read 2026-07-29. Vendor press release, dated. Reliable for its date but superseded on PoP count by later 2026 material. Retained because it documents a conflicting figure.
  3. [3] Tier 1. Zscaler Internet Access data sheet (PDF) Undated. Read 2026-07-29. Vendor datasheet. Strong for product capability and headline figures. Undated, and PDF text extraction may reflow line breaks.
  4. [4] Tier 1. Zscaler Significantly Expands Global Sovereignty on Zero Trust Exchange Platform (press release) Published 2026-03-12. Read 2026-07-29. Vendor press release with an explicit date, most recent statement of data centre count and sovereign or dedicated deployment options.
  5. [5] Tier 1. Zero Trust Cloud Firewall | Zscaler Undated. Read 2026-07-29. Vendor product page. Reliable for whether the firewall is native to the platform. Marketing register, undated.
  6. [6] Tier 1. Zscaler Data Protection product page Undated. Read 2026-07-29. Vendor product page for DLP and data classification. Undated marketing page but explicit on capability.
  7. [7] Tier 1. Zscaler Professional Services (PDF datasheet) Undated. Read 2026-07-29. Vendor services datasheet listing deployment package scope, pilots and education credits. Undated; content is largely tabular so extracted strings are short fragments rather than prose.
  8. [8] Tier 1. Simplify IoT & Mobile Security with Zscaler Cellular Undated. Read 2026-07-29. Vendor product page for the Zscaler Cellular SIM-based service. Undated.
  9. [9] Tier 1. Zscaler's Compliance Center Undated. Read 2026-07-29. Vendor-operated compliance portal listing named certifications and attestations. Undated but is the vendor's authoritative compliance index.
  10. [10] Tier 1. Service Provider Partners - Zscaler Undated. Read 2026-07-29. Vendor partner programme page. Reliable for how managed offers are routed to market. Undated, light on operational detail.
  11. [11] Tier 1. Streamlining Multi-Tenant Management: Announcing Integration of the Multi-Tenant Portal (Zscaler blog) Published 2026-03-25. Read 2026-07-29. Vendor blog with an explicit publication date, describing the Multi-Tenant Portal for MSPs. Dated vendor material so usable as Tier 1, but it is product marketing rather than documentation.
  12. [12] Tier 1. Zscaler Managed Detection & Response (MDR) product page Undated. Read 2026-07-29. Vendor product page for Zscaler's own managed service. Undated.
  13. [13] Tier 1. Zscaler MDR: 24/7 Managed Detection & Response (PDF brochure) Undated. Read 2026-07-29. Vendor brochure. Explicit on 24x7x365 human-led response. Undated.
  14. [14] Tier 1. Traffic Forwarding in Zscaler Internet Access Reference Architecture (PDF) Undated. Read 2026-07-29. Vendor reference architecture, the most technical source read. Strong on Service Edge types and peering. Undated and states 150+ data centres, which conflicts with newer material.
  15. [15] Tier 1. Zero Trust Branch: Secure, Simplify, and Connect with Zscaler Undated. Read 2026-07-29. Vendor product page. Read for lifecycle and cellular evidence; contained neither beyond a zero touch provisioning table entry.
  16. [16] Tier 1. Zscaler Zero Trust SD-WAN (PDF datasheet) Undated. Read 2026-07-29. Vendor datasheet with appliance models. Read specifically for cellular uplinks, firmware update and RMA or lifecycle statements; none were present.
  17. [17] Tier 1. Zero Trust Branch: A simpler, safer, more cost-effective way to connect (PDF datasheet) Undated. Read 2026-07-29. Vendor datasheet. Read for lifecycle management and cellular; neither documented.
  18. [18] Tier 1. Zero Trust 5G Architecture for Private 5G | Zscaler Undated. Read 2026-07-29. Vendor product page. Concerns securing a customer's private 5G core, not 4G or 5G as WAN transport, so of limited use for the cellular capability definition.
  19. [19] Tier 1. Zscaler Extends Zero Trust Platform to Enable Cellular Communications for IoT/OT (press release) Published 2025-07-08. Read 2026-07-29. Dated vendor press release. Confirms SIM-based cellular service but does not name 4G, 5G or LTE.
  20. [20] Tier 3. Internet 2.0: A Quantum Leap for Secure Global Connectivity (Zscaler blog, Teridion partnership) Published 2023-04-02. Read 2026-07-29. Corroboration only. Describes a third party (Teridion Liquid Network) overlay rather than Zscaler-owned infrastructure, and is three years old. Not sufficient to grade backbone ownership on its own.
  21. [25] Tier 1. Zscaler Industries index Undated. Read 2026-07-29. Supplier's own industries hub. Used to establish which industries Zscaler actually publishes dedicated pages for: banking and financial services, healthcare, US public sector (federal, state and local), Australian government, China, education, manufacturing. Absence of retail, energy, transport, professional services and hospitality pages is itself informative.
  22. [26] Tier 1. Zscaler Customer Journeys Undated. Read 2026-07-29. Supplier's own customer index. Large logo wall with named customers but no verbatim sector labelling per customer, so it supports scale claims rather than per-sector grading.
  23. [27] Tier 1. Zscaler for Healthcare Undated. Read 2026-07-29. Supplier's own dedicated healthcare industry page with four named healthcare customers and named executives, plus HIPAA/HITECH framework claims. Strong for sector grading, vendor-claimed.
  24. [28] Tier 1. Zscaler for Financial Services Undated. Read 2026-07-29. Supplier's own dedicated financial services page with four named customers and attributed quotes. Strong for sector grading, vendor-claimed.
  25. [29] Tier 1. Zscaler for Manufacturing Undated. Read 2026-07-29. Supplier's own dedicated manufacturing page with four named manufacturers (Siemens AG, AkzoNobel, Coats, Sanmina) and attributed executive quotes. Strong for sector grading, vendor-claimed.
  26. [30] Tier 1. Zscaler for Public Sector Undated. Read 2026-07-29. Supplier's own public sector page. Carries verifiable third-party accreditation claims (FedRAMP JAB-High, FedRAMP Moderate, TIC 3.0, CJIS) plus named agency case studies (FCC, State of Oklahoma). Accreditation claims are checkable against the FedRAMP marketplace, raising reliability above ordinary marketing copy.
  27. [31] Tier 1. Zscaler for Education (public sector) Undated. Read 2026-07-29. Supplier's own education page with named institutions (New York City Department of Education, University of South Carolina, Virginia Commonwealth University, MCNC) and CIPA compliance claim. Strong for sector grading, vendor-claimed.
  28. [32] Tier 1. Zscaler China Premium Access Undated. Read 2026-07-29. Supplier's own dedicated mainland China product page. Establishes a specific named China offering rather than a generic global claim. Does NOT disclose the licensing arrangement, in-country data centres or local carrier partner, so it evidences a service offering but not the regulatory mechanism behind it.
  29. [33] Tier 1. Zscaler Pricing and Plans Undated. Read 2026-07-29. Supplier's own pricing page. Names bundles (Essentials Platform, Zscaler Platform) and add-on modules but publishes no per-user or list prices. Reliable evidence that pricing is NOT published.
  30. [34] Tier 1. Zscaler digital transformation for the banking sector Undated. Read 2026-07-29. Supplier's own banking landing page, linked from the industries index. Corroborates the same four named financial services customers as source 4.
  31. [35] Tier 1. About Zscaler Undated. Read 2026-07-29. Supplier's own corporate page. Customer count and Forbes Global 2000 penetration figure are the clearest published statement of target organisation size.
  32. [36] Tier 1. Zscaler Company FAQ Undated. Read 2026-07-29. Supplier's own FAQ. Contains employee and customer counts that CONFLICT with sources 11 and 15 (states 'nearly 8,000 customers' against 9.4K+ elsewhere), suggesting a stale page. Recorded, not relied on. Contains no data centre or country figures.
  33. [37] Tier 1. Zscaler for Australian Government Undated. Read 2026-07-29. Supplier's own page carrying an IRAP assessment at PROTECTED plus a long list of named Australian government and education bodies. The IRAP claim is an independently checkable accreditation, making this the strongest single region-specific delivery evidence found.
  34. [38] Tier 1. Zscaler Unified Platform Undated. Read 2026-07-29. Supplier's own platform page carrying named customer story headlines (United Airlines, NOV, Baker & Baker, Careem) with attributed CIO/CISO quotes. Used for transport evidence. Headlines do not state each customer's industry label.
  35. [39] Tier 1. Zscaler Investor Relations Undated. Read 2026-07-29. Supplier's own investor relations site. Infrastructure and scale figures aimed at investors carry securities-disclosure exposure, so more accountable than marketing copy. However the data centre figure is a global aggregate with no regional breakdown, so it cannot grade an individual region on its own.
  36. [40] Tier 1. Zscaler Products and Solutions Undated. Read 2026-07-29. Supplier's own product hub. Checked specifically for SMB or mid-market segmentation and found none. Used as negative evidence for organisation fit.
  37. [41] Tier 1. Zscaler Company News blog Undated. Read 2026-07-29. Supplier's own news index. Checked for Latin America, Brazil and Mexico coverage or expansion announcements; none present. Used as negative evidence for the Latin America region.

Sources found and not used

These were read and rejected as evidence. They are listed so the record can be audited rather than taken on trust, and because what a comparison refuses to rely on says as much as what it cites.

  1. [21] Understanding Private Service Edge for Internet & SaaS (Zscaler Help Portal). https://help.zscaler.com/zia/understanding-private-service-edge Not used as evidence: the help portal is a JavaScript single-page application and returned only an enable-JS stub, so no content was actually retrieved and no quote could be verified.
  2. [22] About Private Service Edges (Zscaler Help Portal, ZPA). https://help.zscaler.com/zpa/about-private-service-edges Not used as evidence: JavaScript-only page, returned an enable-JS stub with no retrievable text.
  3. [23] What Is Zscaler Management Portal for Partners? (Zscaler Help Portal). https://help.zscaler.com/zia/what-zscaler-management-portal-partners Not used as evidence: JavaScript-only page, returned an enable-JS stub, so the partner multi-tenancy documentation could not be quoted.
  4. [24] Zscaler Zero Trust Exchange platform page (attempted). https://www.zscaler.com/products-and-solutions/zscaler-zero-trust-exchange Not used as evidence: returned HTTP 404, no content retrieved.
  5. [42] Zscaler industries/education (guessed URL). https://www.zscaler.com/industries/education Not used as evidence. Returned HTTP 404. The real education page sits under the public sector path (source 7).
  6. [43] Zscaler industries/education-cybersecurity (guessed URL). https://www.zscaler.com/industries/education-cybersecurity Not used as evidence. Returned HTTP 404. Speculative URL tried before the real link list was extracted.
  7. [44] Zscaler data centres (guessed URL). https://www.zscaler.com/company/data-protection/data-centers Not used as evidence. Returned HTTP 404.
  8. [45] Zscaler Experience Center data centre locations (guessed URL). https://www.zscaler.com/experience-center/data-center-locations Not used as evidence. Returned HTTP 404.
  9. [46] Zscaler Cloud Enforcement Node ranges (config portal). https://config.zscaler.com/zscaler.net/cenr Not used as evidence. This is the authoritative per-city data centre list, but the page is a JavaScript single-page application and returned only an 'enable JS' stub to a text fetcher. This is the main reason region grading rests on named customers and accreditations rather than a published points-of-presence list.
  10. [47] Zscaler Trust Portal. https://trust.zscaler.com/ Not used as evidence. JavaScript-only application; returned an 'enable JS' stub with no retrievable cloud or data centre content.
  11. [48] Zscaler help portal, ZIA data centre locations. https://help.zscaler.com/zia/data-center-locations Not used as evidence. JavaScript-only documentation portal; returned an 'enable JS' stub.
  12. [49] Zscaler customer success stories index (guessed URL). https://www.zscaler.com/resources/customer-success-stories Not used as evidence. Returned HTTP 404. Was sought specifically to obtain per-customer industry filter labels that would have allowed retail, energy, professional services and hospitality grading.
  13. [50] Zscaler company data centre locations (guessed URL). https://www.zscaler.com/company/data-center-locations Not used as evidence. Returned HTTP 404.
  14. [51] AWS Marketplace Zscaler listing attempt. https://aws.amazon.com/marketplace/pp/prodview-jvzhmr6mhqqoi Not used as evidence. The fetch resolved to the AWS Marketplace navigation shell rather than the product detail pane, returning no listed contract pricing. Marketplace pricing remains the most likely route to a real price point and was not obtainable in this task.

Claims that disagree

Where two sources conflict, both are recorded rather than one being chosen quietly. Confirm these directly with the vendor.

  • pop count. [4] Zscaler already operates 160+ data centers and is present in most countries. [2] It is now distributed across more than 150 data centers on six continents
  • pop count. [3] Distributed across more than 160 data centers globally, the SSE-based Zero Trust Exchange™ is the world's largest in-line cloud security platform. [14] Zscaler has deployed ZIA Service Edge devices in 150+ data centers around the world.

Verification notes

Re-verified 2026-07-29 against named primary sources. Every graded fact carries a source, a tier and a verbatim quote confirmed present on the cited page by an independent check. Industry, region, organisation-size and pricing evidence was sourced on the same basis. Facts that could not be sourced are published as unknown with the reason. The value_tier field is a Netify assessment of relative cost position, not a supplier claim: most of this market publishes no price. Sources found and rejected are listed at tier 4.

Where next

Continue your Zscaler evaluation

AI advisor · Continue from this page · Zscaler · evaluated 29 Jul 2026

Describe what you need

Your first sentence is drafted from this page. Edit it, or replace it with your own words: sites, regions, what must not go down.

Drafted from this page. Everything you type stays yours to edit before anything is published.

Zscaler arrives pinned; the evaluated market takes position around your words. Nothing runs until you go, and nothing publishes without your signature.

Opens your procurement on Netify

Working with an assistant? Connect netify.co.uk/sase/api/mcp/ and use workspace_ingest with this page as context.