ZScaler Zero Trust Exchange
The Zscaler Zero Trust Exchange connects users directly to apps. ZIA secures outbound internet traffic against threats, whilst ZPA replaces VPNs, granting secure access to private internal applications without exposing the network. This unified cloud platform ensures comprehensive protection and seamless connectivity for users, regardless of their location or device.
Features
- Secure cloud gateway inspecting all internet traffic for threats.
- Zero Trust access to internal apps, replacing legacy VPNs.
- ZDX monitors user device, network, and app performance issues
- Deception deploys decoys to lure and detect active lateral attackers.
- SWG filters web traffic to enforce policy and block malware
- DLP blocks sensitive data from leaving the organisation unauthorised.
- CASB secures data across SaaS apps and controls sharing permissions
- Cloud Sandbox detonates suspicious files to block zero day threats
- Browser Isolation renders risky content safely in a remote container
- Secures app-to-app traffic inside public clouds and data centres.
Benefits
- Stops cyber threats before they reach your network perimeter.
- Eliminates lateral movement by connecting users only to apps
- Rapidly resolves performance issues across device, network, and application
- Detects sophisticated active attackers inside your network environment early
- Enforces compliance and prevents infection from malicious websites
- Prevents costly data breaches and ensures strict regulatory compliance
- Stops shadow IT and secures data within cloud applications
- Blocks unknown, advanced malware before it infiltrates user endpoints
- Neutralises web-based threats without impacting end-user productivity
- Prevents lateral spread of compromised workloads in the cloud.
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 5 7 2 7 5 7 0 6 7 2 3 1 4 2
Contact
NG-IT LTD
Operations Team
Telephone: 0330 223 3915
Email: gcloud@ng-it.co.uk
About your service
- Service categories
-
Systems Infrastructure Software
Security
- Security analytics
- Governance, risk and compliance
Identity and access management
- Access
- Privilege
Network security
- Trusted network access and protection
- Active application security
Data security
- Information protection
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
-
Maintenance: Weekly updates occur during off-peak hours; typically transparent.
Customisation: Multi-tenant SaaS; customisation limited to configuration, not code.
Connectivity: Requires active internet and outbound port 443 access.
Device Support: Legacy OS versions may not support current Client Connector.
Bandwidth: Usage is subject to fair use policies.
Data Residency: Traffic processing is global; log storage is region-specific.
Deprecation: Features retired with advance notice. - System requirements
-
- Requires a SAML 2.0 compliant IdP like Azure AD.
- Devices need a supported OS (Windows, macOS, or Linux)
- Hypervisor or cloud platform needed to deploy App Connectors
- Firewall must permit outbound traffic on port 443
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
-
We provide 24×7×365 email and ticketing support, with response times governed by strict SLAs.
For critical (P1) and high‑impact (P2) issues, we respond within 30 minutes.
Medium‑impact (P3) tickets receive a response within 2 hours, and standard requests (P4) within 4 hours.
All tickets raised via email, phone, or the customer portal enter our ITSM system immediately, where they are prioritised and actioned by the service desk. Our monitoring systems also auto‑generate tickets to ensure rapid response without user intervention. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- No
- Support levels
- Remote support can be provided and is priced based on each customer environment.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Our onboarding process ensures a smooth transition from the initial sale through to long‑term service and support. Once a project is confirmed, we engage in structured onboarding that includes a full requirements review, stakeholder alignment, and handover from the sales team to project management. A dedicated project manager oversees delivery, coordinating timelines, dependencies, and customer expectations.
Training is tailored to customer needs: we offer onsite training, online/remote sessions, and comprehensive user documentation to ensure all users can adopt the solution confidently. As part of onboarding, we provide access to knowledge bases, operational guides, and support contacts so customers know exactly how to get assistance.
When a project moves into operations, we complete a formal service handover, including technical documentation, asset registers, support SLAs, and escalation paths. Support teams are fully briefed to ensure continuity.
Offboarding follows the same structured approach. If a service ends, we manage asset recovery, user deactivation, data management, and service closure tasks professionally and securely. Final documentation and confirmation ensure all contractual and operational obligations are completed. - Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
-
- Microsoft Word
- Microsoft Excel
- End-of-contract data extraction
- Make a formal request into the servicedesk via a case
- End-of-contract process
- The contract expires user accounts are disabled and removed. Customer Monitoring is removed where required.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Provided to end users at onboarding project kickoff
Using the service
- Web browser interface
- No
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Our service is accessible through the Principle Networks Customer Portal, which provides a single, easy‑to‑use interface for managing your service. Through the portal, users can log and track support tickets, view all open and historic cases, update case details, and add additional information. You can also view contracts, check contract terms and end dates, manage approved contacts, and update company information. Administrators can manage user permissions and request reporting. The portal ensures customers have full visibility of their service at any time, with secure access controlled through Microsoft authentication.
- Accessibility standards
- None or don’t know
- Description of accessibility
- Our service is accessible through the Principle Networks Customer Portal, which provides a single, easy‑to‑use interface for managing your service. Through the portal, users can log and track support tickets, view all open and historic cases, update case details, and add additional information. You can also view contracts, check contract terms and end dates, manage approved contacts, and update company information. Administrators can manage user permissions and request reporting. The portal ensures customers have full visibility of their service at any time, with secure access controlled through Microsoft authentication.
- Accessibility testing
- Internally, we validate accessibility through standard browser‑based accessibility tools, automated audits, and manual checks to ensure key functions such as viewing tickets, updating cases, managing contacts, and reviewing contracts remain accessible to all users. As part of our continuous‑improvement approach, we review user feedback and adjust the interface where necessary to improve clarity, readability, and ease of interaction for customers who rely on assistive tools.
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
-
Zscaler leverages a purpose-built multi-tenant cloud architecture (Zero Trust Exchange) rather than virtual appliances. The platform is massively over-provisioned across 150+ global data centres, ensuring that demand spikes from one customer do not impact the performance of others. Key mechanisms include:
Elastic Scalability: The cloud platform automatically allocates computing resources to handle load variations instantly.
Logical Isolation: Customer traffic is processed in memory with strict separation; data never persists on the gateway.
Bandwidth Control: Customers can enforce granular policies to prioritise their own business-critical traffic (e.g., Teams, Zoom) over recreational usage, ensuring consistent performance.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Principle Networks measures service performance through clearly defined SLA‑driven metrics, including rapid incident response and resolution times across all priority levels, 24×7 monitoring of device and service availability, and continual tracking of case volumes, service origins, closure reasons, and overall SLA compliance. These metrics are reviewed through structured service reports and monthly service reviews to ensure consistent first‑response performance, timely resolution, proactive issue detection, and continuous service improvement, all under an ISO 20000‑1 accredited service management framework.
- Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- ZScaler Inc.
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- This is a formal request to the servicedesk
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- JSON
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- Other
- Other protection within supplier network
- Principle Networks protect data within our network by applying strong security controls across our infrastructure, ensuring that information remains confidential, available, and tamper‑free. This includes enforcing encryption for data both in transit and at rest, tightly controlling and reviewing access through least‑privilege andauthentication mechanisms, and maintaining secure configurations across firewalls, endpoints, and cloud services. Our environment is continuously monitored using threat‑intelligence‑driven tools, automated alerting, and vulnerability notifications to detect and respond to risks quickly. We use Data Loss Prevention controls to prevent unauthorised sharing of sensitive information, alongside structured incident‑response processes to ensure any issues are contained and resolved promptly.
Availability and resilience
- Guaranteed availability
-
We guarantee high availability across our managed services through 24×7×365 monitoring, proactive alerting, and resilient architecture. Our services operate under IS 20000‑1‑aligned service management, with strict SLAs governing response and resolution. For incident availability, we commit to a 30‑minute response for P1 and P2 incidents, with target fix times of 2–5 hours for critical issues, depending on whether the solution is resilient, hardware‑based, or dependent on third‑party circuits. Lower‑priority issues follow defined SLA timelines to maintain consistent service quality.
Where contractual availability SLAs are in place, we provide service credits if availability falls below the agreed threshold. Credits are calculated using a transparent formula based on the number of hours outside SLA multiplied by the proportional hourly service cost. This ensures customers receive fair compensation for any material downtime.
Our approach combines continuous monitoring, resilient design, rapid engineering response, and clear escalation paths to maintain service uptime and minimise disruption. - Approach to resilience
-
Zscaler’s service is built upon the Zero Trust Exchange, a cloud-native platform distributed across over 150 data centres globally, removing reliance on traditional network perimeters.
Here is how resilience is embedded in the design:
Global Redundancy: Traffic is processed by the nearest ‘Service Edge’. If a specific node or data centre fails, connections automatically failover to the next available location without user intervention.
Elastic Scalability: The multi-tenant architecture scales horizontally, dynamically allocating compute resources to handle massive traffic surges or DDoS attacks instantly.
Disaster Recovery (DR): For private apps (ZPA), Private Service Edges can maintain local connectivity and enforce policies even if the global cloud is unreachable. For internet access (ZIA), configurable ‘safe modes’ ensure continuity during blackouts.
Brownout Mitigation: Intelligent traffic steering detects latency or packet loss, re-routing traffic to optimal paths to maintain performance.
Essentially, the system decouples security from physical appliances, ensuring consistent protection and uptime regardless of localised disruptions. - Outage reporting
-
Zscaler maintains transparency regarding service availability primarily through the Zscaler Trust Portal (trust.zscaler.com). This public dashboard provides granular, real-time visibility into the health of the entire global infrastructure.Here is how outage reporting is handled:
Public Dashboard: The Trust Portal displays the live status of all clouds (ZIA, ZPA, ZDX) and individual data centres. You can filter views by region to see specific service degradation or maintenance events.
Email Alerts: You can subscribe to the Trust Portal to receive proactive email notifications for incidents, scheduled maintenance, and security advisories relevant to your specific cloud instance.
API & Feeds: The Trust Portal provides JSON and RSS feeds for incidents. These allow you to programmatically ingest status updates into your internal monitoring tools (like ServiceNow or Splunk) rather than manually checking the website.
Additionally, for internal troubleshooting, Zscaler Digital Experience (ZDX) can alert your IT team if users face connectivity issues, helping distinguish between a local network fault and a Zscaler service anomaly.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
-
We restrict access to management interfaces by ensuring they are never exposed to the public internet; configuration access is limited to internal networks or VPN/Zscaler‑protected connections, with MFA enforced for all administrators. Only named, authorised users with role‑based access can perform changes, and all administrative access is logged and periodically reviewed.
Support channels are similarly restricted: only authenticated users on compliant corporate devices can access systems, governed by conditional access policies enforcing location, device posture, and MFA. Users must request changes through the servicedesk using verified identities, ensuring only authorised personnel can engage support functions. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 6 months and 12 months
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
We follow a comprehensive set of information security policies that cover access control, secure configuration, encryption, incident management, risk management, acceptable use, business continuity, data handling, and secure development. These policies define how we protect data, manage systems securely, and ensure confidentiality, integrity, and availability across all services.
Our governance structure is led by the Information Security Team, with overall accountability held by senior leadership. Operational responsibility for maintaining and enforcing the Information Security Management System sits with the Head of Service Operations, supported by technical leads and policy owners.
To ensure policies are consistently followed, we use controlled documentation, mandatory annual security and GDPR training for all staff, formal onboarding/offboarding processes, and strict access‑control reviews. Compliance is reinforced through internal audits, continuous monitoring, and a defined incident‑reporting process that requires any suspected breach or security event to be reported immediately for investigation.
This structured approach ensures security responsibilities are clear, risks are managed, and policies are embedded in day‑to‑day operations. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
We comply with formal configuration and change‑management processes that form part of our ISO‑2000-1 aligned Information Security Management System (ISMS) and IT Service Management framework.
Our configuration management approach ensures that all assets, systems, and device configurations are documented, version‑controlled, and maintained through approved configuration baselines. Configuration changes are tracked, reviewed, and stored centrally, ensuring accuracy, traceability, and rollback capability where required.
Change management follows a structured, risk‑aware workflow. All must be requested, assessed for impact and risk. High‑risk changes follow enhanced governance, including technical peer review. Emergency changes are documented retrospectively and reviewed to ensure control effectiveness. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- We assess threats through continuous monitoring, regular vulnerability scanning, and risk evaluation across all services. Threat intelligence is sourced from vendor security advisories, industry feeds, government alerts (e.g., NCSC), and community CVE databases. Patches are prioritised by severity: critical vulnerabilities are actioned and deployed as quickly as possible, typically within 24–72 hours, with lower‑risk issues scheduled into routine maintenance cycles. Findings are tracked through our internal change and incident management processes to ensure full remediation and verification.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- We assess threats continuously using vendor advisories, CVE feeds, security bulletins, and monitoring tools to identify vulnerabilities relevant to our services. High‑ or critical‑risk vulnerabilities are patched proactively, typically within 24 hours where they present an immediate threat, while all other vendor‑rated high/critical patches are deployed within a 14‑day target window. Lower‑risk issues follow scheduled maintenance cycles. Threat intelligence comes from vendor notifications, industry security alerts, and active monitoring of supported platforms. This ensures rapid mitigation, stable patching, and consistent protection across all managed environments.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We operate a defined incident‑management process with predefined workflows for common events, including priority‑based handling and a dedicated P1/Major Incident procedure with automated bridges and communication steps. Incidents are reported via email, phone, proactive monitoring alerts, or directly through the Customer Portal, all of which create a case in our ITSM system with full classification and prioritisation. We provide incident reports through post‑incident reviews, including Major Incident Reports, which are generated and shared with affected customers after resolution.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- We offer proof of concept evaluation to a limited number of users. The proof of concept scope and term is defined based on the requirements of the customer.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 10%
- Between £250,000 and £500,000
- 22%
- Between £500,001 and £1,000,000
- 30%
- Between £1,000,001 and £2,500,000
- 30%
- Between £2,500,001 and £5,000,000
- 30%
- Over £5,000,001
- 30%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- CDL Group
- ISO 9001 accreditation date
- Tuesday 1 July 2025
- What the ISO 9001 doesn’t cover
- N/a
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- E29042f9-0029-4a93-840f-4178125bdd61
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 76366978-ee23-40f3-80dd-8b48234414fd
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Volunteering opportunities for staff
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Measures for making facilities used in the delivery of the contract available for community groups, education or training
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-