All Buyer Guides
CybersecurityHigh Complexity

Buyer's Guide: Zero Trust Network Access (ZTNA)

Evaluate Zscaler, Palo Alto, Netskope, Cloudflare, Cisco, Microsoft Entra, Cato, and Check Point as the VPN-replacement pillar of SSE/SASE — judging the access broker on identity-centric policy and least privilege, not on which agent is shinier.

15 min read 8 vendors evaluated Typical deal: $100K – $2M+ Updated June 2026
Section 1

Executive Summary

ZTNA replaces the VPN, but its real value is least-privilege access to individual apps — recreate flat network access with a shinier agent and you’ve just bought a faster way to do the wrong thing.

Zscaler Private Access, Palo Alto Prisma Access, Netskope Private Access, and Cloudflare Access converge on the same idea — broker identity- and context-aware access to specific applications instead of dropping users onto the network like a VPN. The key context is that ZTNA is rarely an island: most of these vendors sell it inside a broader security service edge (SSE) alongside secure web gateway, CASB, and DLP, so the real decision is point product versus a converged SSE platform you will grow into.

This guide provides a vendor-neutral evaluation framework for 8 leading platforms, weighing identity and policy model, global network reach, agent-versus-agentless coverage, and fit within a broader SSE and SASE architecture so you can plan beyond simple VPN replacement toward least-privilege access done properly.


Section 2

Why Zero Trust Network Access (ZTNA) Matters for Enterprise Strategy

ZTNA selection is shaped by architecture as much as features: brokering access by identity and device posture demands tight integration with your identity provider and a global network that doesn’t add latency to every connection. The decisive question is whether you’re buying a standalone VPN replacement or the first module of a converged edge, because that choice governs integration, policy consistency, and cost for years.

🎯
Strategic Impact
Three forces make ZTNA a board-visible architecture decision, not a remote-access refresh: the VPN concentrator has become both a performance bottleneck and a favourite ransomware entry point, so retiring it is a security mandate; identity has replaced the network perimeter as the control plane, which puts your IdP and device-posture signals at the centre of every access decision; and ZTNA is the on-ramp to SSE/SASE, so the broker you pick quietly decides whose web-gateway, CASB, and DLP you will run for years. Pick for the platform you are joining, not just the VPN you are leaving.

ZTNA is being absorbed into SASE and security service edge, where private access, web security, and data protection share one policy engine and one global network. Weigh each vendor on the breadth and coherence of that platform and on network reach, because a point ZTNA tool that can’t grow into unified edge policy becomes another console to reconcile. The frontier is universal ZTNA — extending the same least-privilege, identity-aware policy from remote users back to the campus and branch, where it starts to displace legacy NAC and 802.1X. This is also where ZTNA and the SD-WAN conversation merge, since the branch on-ramp and the access broker increasingly ship from the same SASE fabric.


Section 3

Architecture & Sourcing Decision

ZTNA is not a build-vs-buy question — no enterprise hand-rolls an identity-aware access broker and a global edge. The real decision is scope and bundling: standalone ZTNA point product versus the access module of a full SSE/SASE platform; agent-based versus agentless coverage for the workloads and users you actually have; and whether your existing identity, firewall, or SD-WAN estate should pull the choice toward an incumbent you already run. Frame it around the platform you are joining and the protocols you must carry, not the prettiest VPN-replacement demo.

Your Situation Recommended Path Rationale
VPN at end of life and you want web security and DLP next Converged SSE platform (Zscaler, Netskope, Cloudflare, Cisco) Buying ZTNA as one module of an SSE suite means private access, secure web gateway, CASB, and DLP share one policy engine and one network — fewer consoles to reconcile and a single agent on the endpoint.
Microsoft-centric estate already standardized on Entra ID Identity-native ZTNA (Microsoft Entra Private Access) Reusing Conditional Access, MFA, and device compliance you already license avoids a second policy engine; strongest where private apps are Windows/AD-centric and a full third-party SSE is overkill.
Heavy contractor, BYOD, or M&A access with no time to push agents Agentless / browser-delivered access (Cloudflare, Prisma Access Browser) Clientless reverse-proxy or an enterprise browser onboards unmanaged devices in days without an endpoint rollout — accepting thinner device-posture signal and mostly web/SSH/RDP protocol coverage.
Branch and SD-WAN refresh happening alongside remote access Single-vendor SASE (Cato, Palo Alto, Cisco, Fortinet) When the WAN edge and the access broker ship from one fabric, branch, remote, and cloud traffic ride a common policy and backbone; see the SD-WAN guide, since this is the same decision viewed from the network side.
Legacy and non-web protocols (RDP, SSH, SMB, thick clients, OT/IoT) Agent-based ZTNA with broad protocol & device coverage Agentless tops out near HTTP/SSH/RDP; full TCP/UDP apps, server-to-client flows, and agentless devices need a connector-plus-agent model (and increasingly device-intelligence for things that can’t run an agent).
⚠️
Common Pitfall
The most common ZTNA mistake is treating it as a like-for-like VPN swap — porting over broad, flat access rules so users still reach far more than they need, just faster. Use the migration to enforce least privilege per application, fold device posture and identity context into policy, and sequence the rollout app by app rather than quietly recreating the perimeter you set out to retire.

Section 4

Key Capabilities & Evaluation Criteria

Weight these domains against your access patterns, protocol mix, and SSE ambitions. For most enterprises, the identity and policy model and the realism of the application-and-protocol coverage decide the project — not raw throughput or the demo dashboard. Score the access broker on whether it enforces least privilege per application using your identity and posture signals, and on whether it carries the awkward protocols your VPN quietly handled.

Capability Domain Weight What to Evaluate
Identity-Centric Policy & Least Privilege 25% Native integration with your IdP(s) (Entra ID, Okta, Ping) and SCIM/group sync; per-application (not per-network) policy; continuous re-evaluation, not just at logon; per-session adaptive access; how cleanly policy expresses “this user, this device, this app”
Application & Protocol Coverage 20% Agent-based for full TCP/UDP and thick clients vs. agentless/browser for unmanaged devices; legacy protocols (RDP, SSH, SMB, Kerberos/NTLM); server-to-client and client-to-client flows; private DNS; application discovery to find what users actually reach
Device Posture & Context 15% Real-time device-health and compliance signals (managed and unmanaged); EDR/MDM/UEM integration; continuous posture re-check mid-session; risk scoring; handling of agentless devices (contractors, OT/IoT) that can’t report posture
SSE/SASE Platform Coherence 15% Shared policy engine and single agent across ZTNA, SWG, CASB, and DLP; consistency of logging and analytics; universal-ZTNA reach to campus/branch and NAC displacement; co-existence with your SD-WAN; avoidance of a second console you must reconcile
Global Network & Performance 15% Edge/PoP footprint near your users and apps; peering and direct-to-cloud paths; inside-out connectors with no inbound exposure; measured latency for chatty apps; digital-experience monitoring (DEM/ADEM) to prove and troubleshoot the user path
Operations, Visibility & Resilience 10% Policy-as-code and API/Terraform coverage; clarity of access logs for audit and incident response; connector high-availability and failover; SOC 2 / ISO 27001 / FedRAMP where required; tenant isolation and the blast radius if the broker itself has an outage
💡
Evaluation Tip
Run the POC against your three ugliest applications, not your cleanest web app. Pick a chatty thick-client app, something that still speaks RDP or SMB, and an app reached by unmanaged contractor devices. Confirm the broker enforces per-app least privilege (a user on app A genuinely cannot see app B), that device posture is actually re-checked mid-session and not just at logon, and that the legacy protocol works without a side-channel VPN. The vendor that carries your worst protocols cleanly — not the one with the best dashboard — leads your shortlist.

Section 5

Vendor Landscape

The market sorts into four camps that shortlists usually compare across, not within. Cloud-security pure-plays (Zscaler, Netskope) built ZTNA as one service on a proxy cloud they already ran for web security. Network-security incumbents (Palo Alto, Cisco, Check Point) extend ZTNA from a firewall and SASE estate you may already own. The hyperscaler-and-edge entrants (Microsoft, Cloudflare) lead respectively with identity you already license and with the largest edge network. And the converged-SASE specialists (Cato) argue that one platform, one agent, and one backbone for both networking and security beat any best-of-breed stack. Where you start — from identity, from the firewall, from the WAN, or from the web proxy — tends to decide the camp before the feature comparison even begins.

Zscaler Private Access (ZPA) Leader — SSE Pure-Play

Strengths: The reference ZTNA at scale: inside-out App Connectors mean private apps make only outbound connections and are never exposed inbound, with one-to-one brokered tunnels and ML-assisted app segmentation. Pairs natively with Zscaler Internet Access for a mature, widely deployed SSE, and now extends to the campus via universal-ZTNA private service edges. Considerations: Premium pricing, and the full zero-trust story assumes commitment to the Zscaler cloud; App Connector sizing and segmentation design are real projects; clientless coverage of exotic legacy protocols is thinner than its agent-based path.

Best for: Enterprises standardizing on a dedicated, proven SSE and wanting the deepest at-scale ZTNA segmentation
Palo Alto Prisma Access Leader — Firewall-Led SASE

Strengths: ZTNA 2.0 folds least-privilege access into continuous trust verification and deep inline inspection, inside a single SASE platform spanning private access, SWG, CASB, and full NGFW-grade threat prevention with ADEM experience monitoring. Prisma Access Browser delivers agentless private-app and SaaS access on unmanaged and BYOD devices. Considerations: Among the more complex platforms to deploy and operate; premium pricing and best value when you adopt the wider Prisma/Palo Alto stack; translating legacy firewall rules into per-app ZTNA policy is non-trivial.

Best for: Palo Alto-centric enterprises wanting unified SASE with firewall-grade threat prevention on the access path
Netskope (One Private Access) Leader — Data-Centric SSE

Strengths: Strong data-centric DNA: ZTNA shares one policy engine and the NewEdge network with a leading CASB, SWG, and inline DLP, so access and data control are expressed together. Universal ZTNA combines user-to-app brokering with L3 client-to-client reach and adds context-aware device intelligence to extend zero trust to agentless OT/IoT devices. Considerations: Edge footprint and brand presence trail Zscaler and Cloudflare in some regions; the strongest value is tied to adopting the broader Netskope platform; standalone ZTNA buyers may pay for more suite than they need.

Best for: Data-security-led organizations wanting ZTNA inside a CASB/DLP-first SSE, including IoT/OT coverage
Cloudflare (Access / Cloudflare One) Strong — Edge-Native

Strengths: Runs on one of the largest global edge networks, with every service on every server, giving short paths to users almost anywhere. Genuinely strong clientless/agentless access via reverse proxy and browser isolation for fast contractor and BYOD onboarding, plus an agent (the Cloudflare One client, formerly WARP) for non-web protocols. Developer-friendly, API-first, and competitively priced. Considerations: Deepest enterprise ZTNA features and white-glove support are younger than the longtime SSE leaders; some IdP and posture integrations are less mature; non-HTTP apps (SSH, RDP, databases) push you back to the agent.

Best for: Cloud-native and developer-led organizations prioritizing fast agentless onboarding and edge performance
Cisco Secure Access Strong — Identity + Network

Strengths: A cloud-delivered SSE bundling ZTNA, SWG, CASB, FWaaS, DNS security, and even VPN-as-a-service in one license, with both client-based and clientless access for managed and unmanaged devices. Duo and identity-intelligence integration give rich identity context, and it slots into a large installed base of Cisco networking and Secure Connect SASE. Considerations: Assembled from several formerly separate Cisco assets, so integration depth and console coherence vary by capability; best leverage assumes you are already a Cisco shop; newer to the dedicated-SSE conversation than the pure-plays.

Best for: Cisco-aligned enterprises wanting ZTNA tied to Duo identity and an existing Cisco network and SASE footprint
Microsoft Entra Private Access Strong — Identity-Native

Strengths: ZTNA delivered through Global Secure Access and governed by Conditional Access, so the same MFA, device-compliance, and adaptive policies that already protect Microsoft 365 now gate private apps — no second policy engine. Notably brings Conditional Access and MFA to legacy protocols a VPN handled blindly (Kerberos, NTLM, RDP, SMB), and is licensed within the Entra Suite many enterprises already hold. Considerations: A newer entrant whose global PoP reach and breadth of non-Microsoft integrations are still maturing against the established SSE clouds; it is private access plus internet access, not yet a full CASB/SWG suite; strongest when identity is already centralized on Entra ID.

Best for: Microsoft-centric organizations wanting identity-native VPN replacement reusing Entra Conditional Access
Cato Networks Strong — Converged SASE

Strengths: Single-vendor SASE built from the ground up: its Single Pass Cloud Engine (SPACE) applies FWaaS, SWG, IPS, CASB, DLP, and ZTNA coherently on one private global backbone, so branch, remote, and cloud traffic ride one fabric and one policy. Universal ZTNA uses a single risk-based policy across Windows, macOS, Linux, iOS, and Android for managed and BYOD devices. Considerations: The converged model means you largely commit to Cato’s platform and backbone rather than assembling best-of-breed; component depth can trail specialist tools in a given domain; most compelling when you are also modernizing the WAN (overlaps the SD-WAN decision).

Best for: Lean teams wanting one converged platform for networking and security rather than a multi-vendor SSE stack
Check Point Harmony SASE (formerly Perimeter 81) Challenger — Fast Deploy

Strengths: Perimeter 81’s easy, fast-to-stand-up ZTNA, FWaaS, and SWG, now folded into Check Point’s Harmony SASE and Infinity architecture and threat-prevention pedigree. Quick onboarding and a straightforward console make it approachable for mid-market and lean security teams replacing a VPN without a heavyweight rollout. Considerations: Mid-market roots mean it is still scaling to the largest, most complex global deployments; the post-acquisition integration into the wider Check Point platform is an ongoing roadmap to track; edge footprint and ecosystem are smaller than the SSE leaders.

Best for: Mid-market and lean teams wanting quick, simple VPN replacement with Check Point security behind it
🔎
Market Insight
The center of gravity is shifting from “replace the VPN” to universal ZTNA — one identity-aware, least-privilege policy that follows the user from home to branch to campus and starts to retire legacy NAC and 802.1X. That reframes the buy: ZTNA is increasingly the access tier of an SSE/SASE platform rather than a standalone tool, which is why this decision now overlaps the SD-WAN one and why the identity provider, not the network, is the real control plane. Watch agentless coverage for OT/IoT and unmanaged devices become the next true differentiator, since that is where pure agent-based models still fall short.

Section 6

Pricing Models & Cost Structure

ZTNA pricing is overwhelmingly per-user subscription, but the headline rate is the least useful number. What actually moves spend is the edition tier and which adjacent SSE modules you bundle (web gateway, CASB, DLP), because standalone ZTNA and a full SSE suite are very different line items, and bundling several modules together usually beats buying any of them alone. Model against the user population, the protocol coverage you genuinely need, and the platform you intend to grow into — not a per-seat list price none of these vendors publish.

Vendor Pricing Model Relative Tier Key Cost Drivers
Zscaler Private Access Per-user subscription, tiered editions; often bundled with ZIA Premium User count and edition (Essentials → Transformation), ZPA-plus-ZIA bundling, add-on modules (privileged remote access, deception), term length and volume
Palo Alto Prisma Access Per-user subscription plus platform; SASE bundle tiers Premium User count and SASE edition, breadth of modules (SWG/CASB/DLP/ADEM), Prisma Access Browser, throughput/data, professional services
Netskope Per-user subscription, modular across the One platform Moderate–Premium User count, which modules (NPA, CASB, SWG, DLP), device-intelligence/IoT coverage, NewEdge usage, edition
Cloudflare Per-user (free tier to enterprise); consumption for some services Lower–Moderate Seat count and plan tier, enterprise contract and support level, add-on Cloudflare One services, non-web/agent usage
Cisco Secure Access Per-user subscription, single SSE license Moderate–Premium User count and package, breadth of bundled SSE (ZTNA/SWG/CASB/FWaaS/VPNaaS), Duo tier, existing Cisco EA leverage
Microsoft Entra Private Access Per-user subscription; included in Entra Suite or standalone Moderate User count, Entra Suite vs. standalone, existing Microsoft licensing leverage, paired Entra Internet Access
Cato Networks Per-user / per-site subscription on the converged platform Moderate Users and sites, bundled SASE capabilities (SD-WAN, SSE, ZTNA), bandwidth tier, term and global footprint
Check Point Harmony SASE Per-user subscription, packaged tiers (ex-Perimeter 81) Lower–Moderate User count and tier, gateways/locations, add-on security modules, term length
3-Year TCO Formula
TCO = (Per-User License × Users × 36 months) + Connector / Edge Deployment + Application Discovery & Policy Migration + VPN Decommission + Identity / IdP & Posture Integration + Internal FTE − Retired VPN & Concentrator Infrastructure − Consolidated SSE Tooling

Section 7

Implementation & Migration

Sequence ZTNA by application, not by user group, and run it alongside the VPN until each app is proven — the goal is least privilege per app, so cutting over flat access rules wholesale defeats the project. Application discovery, not deployment, is the work that determines the timeline.

Phase 1
Discover & Map Applications (Months 1–2)

Inventory the private apps users actually reach and their protocols, and map who needs which — this, not the install, is where ZTNA projects slip. Connect the IdP, decide agent vs. agentless per use case, and define least-privilege policy and device-posture requirements with security.

Phase 2
Deploy Brokers & Pilot (Months 2–4)

Stand up App Connectors / edge near the apps with no inbound exposure, wire in Conditional Access or equivalent policy, integrate device posture (EDR/MDM), and onboard a pilot cohort and a first set of apps in parallel with the existing VPN.

Phase 3
Cut Over App by App (Months 4–8)

Migrate applications in waves, enforcing per-app least privilege and validating the awkward protocols (RDP, SSH, SMB) and unmanaged-device access as you go. Decommission VPN access for each app only once its ZTNA path is proven, shrinking the concentrator footprint steadily.

Phase 4
Extend & Operate — toward Universal ZTNA (Months 8–14)

Retire the remaining VPN, fold in adjacent SSE policy (SWG/CASB/DLP) on the shared engine, and extend the same identity-aware policy to campus and branch where it can displace legacy NAC. Codify policy-as-code, access-log review, and connector failover as standing operations.


Section 8

Selection Checklist & RFP Questions

Use this checklist during evaluation to confirm each shortlisted platform enforces real least privilege and carries the access patterns your VPN actually handled.


Section 9

Related Resources

Spotlight Listing

Interested in getting featured here?

Put your solution in front of the CIOs evaluating this category.

Learn how
Tags:ZTNAZero TrustSSESASEZscaler Private AccessPalo Alto Prisma AccessNetskopeCloudflareCisco Secure AccessMicrosoft Entra Private AccessCato NetworksCheck Point Harmony SASEVPN ReplacementUniversal ZTNA