Netify

SSE / SASE platform

Zscaler

Sources evidence Zscaler ZIA/ZPA integration with SD-WAN and Zscaler Zero Trust SASE with fresh SD-WAN approach; historically SSE-led.

www.zscaler.comLast verified 2026-05-22

Key differentiators

  • Category leader in SSE with ZIA, ZPA and ZDX; widely adopted as the security layer in best-of-breed SASE architectures.
  • Strong ecosystem of SD-WAN partners (Cisco, others) for buyers wanting Zscaler security with a separate SD-WAN platform.
  • Mature Zero Trust platform with substantial enterprise deployment history.

Best fit for

  • Enterprises selecting best-of-breed SSE alongside a separate SD-WAN platform.
  • Security-driven SASE strategies where the SSE layer is the primary architectural decision.
  • Buyers consolidating multiple security point solutions onto a single SSE vendor.

Watch-outs

  • Historically SSE-led; native SD-WAN capability is less mature than dedicated SD-WAN platforms (validate path selection, QoS and packet loss in RFP).
  • Premium pricing; typically per-user/workload/location with security modules adding cost.
  • Buyers needing one vendor for both SD-WAN and security may prefer a converged platform (Cato, FortiSASE, Prisma).

40 features, 6 categories

Capability matrix

Each capability is graded against public source evidence. Hover any status grade for a definition. Where evidence is limited, the grade reflects that uncertainty rather than assuming the capability is present.

Service delivery and operating model

#CapabilityStatusDefinition
F01Fully managed servicePartner / integratedProvider designs, deploys, monitors, changes, supports and reports on the service.
F02DIY / self-managed modelYesCustomer operates SD-WAN controller, policies, updates and incident response.
F03Co-managed servicePartner / integratedProvider runs platform/support while customer retains selected policy or change rights.
F04Multi-tenant MSP / white-label supportPartner / integratedTenant isolation, delegated administration, branded portals, templates and service-provider scale.
F05Professional services and migration supportPartner / integratedDiscovery, design, pilot, staging, migration runbooks, rollback and training.
F06Last-mile circuit managementPartner / integratedSourcing, monitoring and support for broadband, DIA, LTE/5G, MPLS and cross-connects.
F07Lifecycle managementPartner / integratedHardware replacement, firmware upgrades, patching, renewals and EoL planning.
F08Flexible commercial modelYesPer-site, per-bandwidth, per-user, per-device, consumption, NaaS or bundled pricing.

Network architecture and transport

#CapabilityStatusDefinition
F09Encrypted overlay fabricPartialSecure tunnels across broadband, DIA, MPLS, LTE/5G, satellite or private WAN.
F10Dynamic path selectionPartialReal-time routing based on latency, jitter, packet loss, brownouts, MOS and policy.
F11Active-active link utilisationPartialUse multiple links concurrently rather than passive backup only.
F12Application-aware routingPartialIdentification and routing for SaaS, UCaaS, ERP and custom applications.
F13QoS and traffic shapingPartialPer-application and per-class prioritisation, reservation and policing.
F14Packet loss remediationPartialFEC, packet duplication, jitter buffering, TCP optimisation and WAN optimisation.
F15Local internet breakoutPartialSecure direct internet access from branch sites.
F16MPLS coexistence and migrationPartialHybrid MPLS/internet/cellular during transition.
F17Cellular and 5G supportUnknownIntegrated/external modem, SIM management, signal monitoring and failover.
F18Cloud on-rampYesAutomated/simplified connectivity to AWS, Azure, Google Cloud, Oracle, Equinix, Megaport and SaaS.

Gateway, PoP and backbone design

#CapabilityStatusDefinition
F19Public cloud gatewaysYesVendor-operated gateways/PoPs for SaaS optimisation, remote access or security enforcement.
F20Private PoPs / dedicated PoPsUnknownCustomer-hosted, dedicated or sovereign PoP options.
F21Private global backbonePartialVendor-owned or controlled backbone between PoPs.
F22Regional breakout and data residencyYesPin traffic to countries, regions or approved inspection locations.
F23Multi-cloud transit fabricYesBranch-to-cloud, cloud-to-cloud and user-to-cloud connectivity under common policy.
F24Flexible edge form factorsPartialPhysical, virtual, cloud marketplace, container or uCPE.
F25High availability designPartialDual appliances, dual circuits, dual power, HA clustering and gateway redundancy.
F26SLA-backed service fabricPartner / integratedSLA for uptime, response, change handling and possibly latency/jitter/loss.

Security and SASE capability

#CapabilityStatusDefinition
F27Integrated next-generation firewallYesStateful firewall, app control, IPS/IDS, malware inspection and URL filtering.
F28Full SASE platformYesSD-WAN plus SWG, CASB, ZTNA, FWaaS, DLP, RBI, DNS security and threat prevention.
F29SSE ecosystem integrationYesInteroperation with Zscaler, Netskope, Palo Alto Prisma Access, Cisco Secure Access, Cloudflare etc.
F30Zero Trust Network AccessYesIdentity and posture-based access to private applications.
F31Secure web gatewayYesURL filtering, SSL inspection, malware scanning and acceptable-use controls.
F32CASB capabilityYesSaaS discovery, sanctioned/unsanctioned app control and SaaS policy enforcement.
F33Data loss preventionYesData classification, inspection, blocking, alerting and exception workflow.
F34Remote user accessYesClient or clientless access for remote workers, contractors and mobile users.
F35SOC/SIEM/SOAR integrationYesSyslog, APIs, event export, threat intelligence and workflow integration.

Operations, assurance and automation

#CapabilityStatusDefinition
F36Centralised orchestrationYesTemplates, intent-based policy, zero-touch provisioning and configuration compliance.
F37Customer portal and RBACYesReal-time status, role-based access, reporting, tickets and change requests.
F38Observability and digital experience monitoringYesApp experience, user experience, device health, SaaS telemetry and path analytics.
F39APIs and automationYesREST APIs, Terraform, webhooks, event streaming and ITSM integration.
F40Managed service assurancePartner / integrated24/7 NOC/SOC, proactive monitoring, incident ownership, RCA, service reviews and change governance.

Commercial

Cost model and pricing visibility

Public pricing visibility

Quote-based. No complete public enterprise price was found in reviewed sources.

Cost model

Quote-based subscription; typically per-user/workload/location modules; SD-WAN integrations may add partner/vendor cost.


Evidence

Primary sources

Every capability grade traces back to one of these sources. Reviewed 2026-05-22.

  1. https://www.zscaler.com/blogs/partner/managing-sase-momentum-ntt-data-and-zscaler
  2. https://www.cisco.com/c/en/us/td/docs/solutions/CVD/SDWAN/cisco-sdwan-zscaler-deploy-guide.html

Verification notes

Capability matrix sourced from Netify internal vendor research (May 2026). Status grades reflect public source evidence only. Confirm via RFP. Qualitative fields (differentiators, best fit, watch-outs) are Netify editorial synthesis based on the evidence summary and capability profile; review before publishing. Extended dimensions (regions, clouds, AI, resilience, deployment speed, sectors, organisation fit, identity, platforms, support, logging) are indicative desk research grades from June 2026; confirm via RFP.