Zscaler SSE & SASE Review
Zscaler is a cloud-native cybersecurity company headquartered in San Jose, California, and listed on Nasdaq (ZS). Founded in 2007, Zscaler operates the Zero Trust Exchange — the world's largest inline cloud security platform, distributed across 160+ data centres globally. Unlike vendors that bolt security onto network hardware, Zscaler was built exclusively as a cloud proxy, inspecting all traffic — including encrypted SSL — without on-premises appliances. The platform is primarily positioned as a Security Service Edge (SSE) solution with SD-WAN delivered via third-party vendor integrations. Zscaler is best suited to large enterprises with distributed workforces, complex compliance requirements, and existing investment in cloud-first infrastructure.
Quick Facts — Zscaler
| Category | Detail |
|---|---|
| Full company name | Zscaler, Inc. |
| Headquarters | San Jose, California, USA |
| Founded | 2007 |
| Primary product | Zero Trust Exchange (SSE platform) |
| Architecture | Cloud-native (proxy-based, no on-premises appliances) |
| Global data centres | 160+ (as of 2025) |
| UK presence | London (EMEA HQ, The Royal Exchange); multiple UK PoPs within the global network |
| SASE capability | Partial — SSE Leader; SD-WAN requires third-party integration (e.g. Cisco Catalyst SD-WAN, VMware VeloCloud, HPE Aruba EdgeConnect) |
| SD-WAN capability | Partial (via partner ecosystem only; no native SD-WAN) |
| Target market | Mid-market to large enterprise; not recommended for SMEs |
| UK channel | Direct sales + partner/reseller ecosystem (available on G-Cloud) |
| Gartner position (SSE) | Leader — Gartner Magic Quadrant for Security Service Edge, 2025 (highest 'Ability to Execute' of all vendors) |
| Gartner position (SASE) | Visionary — Gartner Magic Quadrant for SASE Platforms, 2025 |
What Netify Thinks
Zscaler has been named a Leader in the Gartner Magic Quadrant for Security Service Edge every year since the report's inception (2022–2025), ranking highest on the 'Ability to Execute' axis in 2025. This reflects genuine market traction — Zscaler is the dominant cloud-native SSE platform for large enterprises pursuing a zero trust architecture.
Strengths
- SSE market leadership: Zscaler has been named a Leader in the Gartner Magic Quadrant for Security Service Edge every year since the report's inception (2022–2025), ranking highest on the 'Ability to Execute' axis in 2025.
- Global scale with strong UK presence: Operating 160+ data centres worldwide, Zscaler has established London as its EMEA headquarters (The Royal Exchange, 2025) and holds UK Cyber Essentials accreditation. UK enterprises benefit from low-latency access to multiple UK PoPs.
- Zero Trust depth: ZIA and ZPA together replace both legacy web proxies and VPNs in a single cloud-delivered platform. The inside-out connectivity model means applications are never exposed to the internet — a meaningful architectural advantage over firewall-and-VPN approaches.
Weaknesses
- No native SD-WAN: Zscaler does not provide its own SD-WAN. Organisations requiring a full SASE stack must procure an SD-WAN separately from a third-party vendor. This adds procurement complexity and a potential gap in unified management.
- Management complexity and cost: ZIA and ZPA are managed through separate consoles (plus a third for the Client Connector), creating operational overhead. Enterprise contracts frequently involve 7% annual uplift on renewal, and overall licensing costs are high relative to competitors.
- Not suited to SMEs or legacy environments: Zscaler is explicitly enterprise-grade. Small businesses or organisations with significant legacy application dependencies will find the complexity of deployment and management disproportionate to their needs.
Pros & Cons
Pros
- SSE market leader: ranked highest on 'Ability to Execute' in the Gartner MQ for SSE 2025
- 160+ global data centres ensure low-latency inspection close to the user
- London EMEA HQ (2025) and UK Cyber Essentials accreditation — strong local presence
- ZPA replaces VPN without exposing applications to the internet (inside-out connectivity)
- Native integrations with AWS, Azure, and Google Cloud, plus Microsoft 365 optimisation
- Comprehensive compliance coverage including GDPR, FedRAMP High, ISO 27001, PCI DSS, and HIPAA
- Red Canary acquisition (2025) adds MDR and AI-driven threat intelligence capability
Cons
- No native SD-WAN: a separate vendor is required, adding procurement complexity and cost
- Separate management consoles for ZIA, ZPA, and Client Connector — no single-pane-of-glass management
- High licensing costs with reported 7% annual renewal uplift; unsuitable for SMEs
- ZPA availability limited to approximately 50 of 160+ global PoPs, which can affect latency for private app access
- Complex initial configuration and ongoing management requires experienced security staff
- Reported variability in mobile client connector performance on iOS and Android devices
Frequently Asked Questions
What is Zscaler?
How much does Zscaler cost in the UK?
Is Zscaler a good choice for UK deployments?
How does Zscaler compare to Palo Alto Networks, Netskope, and Cloudflare One?
| Zscaler | Palo Alto Networks (Prisma) | Netskope | Cloudflare One | |
|---|---|---|---|---|
| Best for | Large enterprise SASE & SSE | Integrated SD-WAN + SASE | Data-centric security / CASB | Mid-market / cost-conscious buyers |
| Gartner position | Leader, SSE MQ 2025 | Leader, SSE MQ 2025 | Leader, SSE MQ 2025 | Challenger, SSE MQ 2025 |
| SD-WAN native? | No (third-party required) | Yes (Prisma SD-WAN) | No (third-party required) | Partial (Magic WAN) |
| Architecture | Cloud-native proxy | Cloud-native + NGFW | Cloud-native proxy | Cloud-native (Anycast) |
| UK suitability | Strong — London EMEA HQ, multiple UK PoPs | Strong — regional offices and PoPs | Strong — UK PoPs available | Good — London PoPs |
Include Zscaler in your SASE RFP
Use the Netify RFP Builder to build a structured, vendor-neutral SASE RFP and receive competitive bids.
Build Your SASE RFP