Skip to main content

Help us improve the Digital Marketplace - send your feedback

NG-IT LTD

ZScaler Zero Trust Exchange

The Zscaler Zero Trust Exchange connects users directly to apps. ZIA secures outbound internet traffic against threats, whilst ZPA replaces VPNs, granting secure access to private internal applications without exposing the network. This unified cloud platform ensures comprehensive protection and seamless connectivity for users, regardless of their location or device.

Features

  • Secure cloud gateway inspecting all internet traffic for threats.
  • Zero Trust access to internal apps, replacing legacy VPNs.
  • ZDX monitors user device, network, and app performance issues
  • Deception deploys decoys to lure and detect active lateral attackers.
  • SWG filters web traffic to enforce policy and block malware
  • DLP blocks sensitive data from leaving the organisation unauthorised.
  • CASB secures data across SaaS apps and controls sharing permissions
  • Cloud Sandbox detonates suspicious files to block zero day threats
  • Browser Isolation renders risky content safely in a remote container
  • Secures app-to-app traffic inside public clouds and data centres.

Benefits

  • Stops cyber threats before they reach your network perimeter.
  • Eliminates lateral movement by connecting users only to apps
  • Rapidly resolves performance issues across device, network, and application
  • Detects sophisticated active attackers inside your network environment early
  • Enforces compliance and prevents infection from malicious websites
  • Prevents costly data breaches and ensures strict regulatory compliance
  • Stops shadow IT and secures data within cloud applications
  • Blocks unknown, advanced malware before it infiltrates user endpoints
  • Neutralises web-based threats without impacting end-user productivity
  • Prevents lateral spread of compromised workloads in the cloud.

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at gcloud@ng-it.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 5 7 2 7 5 7 0 6 7 2 3 1 4 2

Contact

NG-IT LTD Operations Team
Telephone: 0330 223 3915
Email: gcloud@ng-it.co.uk

About your service

Service categories

Systems Infrastructure Software

Security

  • Security analytics
  • Governance, risk and compliance

Identity and access management

  • Access
  • Privilege

Network security

  • Trusted network access and protection
  • Active application security

Data security

  • Information protection
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
  • Hybrid cloud
Service constraints
Maintenance: Weekly updates occur during off-peak hours; typically transparent.
Customisation: Multi-tenant SaaS; customisation limited to configuration, not code.
Connectivity: Requires active internet and outbound port 443 access.
Device Support: Legacy OS versions may not support current Client Connector.
Bandwidth: Usage is subject to fair use policies.
Data Residency: Traffic processing is global; log storage is region-specific.
Deprecation: Features retired with advance notice.
System requirements
  • Requires a SAML 2.0 compliant IdP like Azure AD.
  • Devices need a supported OS (Windows, macOS, or Linux)
  • Hypervisor or cloud platform needed to deploy App Connectors
  • Firewall must permit outbound traffic on port 443

User support

Email or online ticketing support
Yes, at extra cost
Support response times
We provide 24×7×365 email and ticketing support, with response times governed by strict SLAs.
For critical (P1) and high‑impact (P2) issues, we respond within 30 minutes.
Medium‑impact (P3) tickets receive a response within 2 hours, and standard requests (P4) within 4 hours.
All tickets raised via email, phone, or the customer portal enter our ITSM system immediately, where they are prioritised and actioned by the service desk. Our monitoring systems also auto‑generate tickets to ensure rapid response without user intervention.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
No
Support levels
Remote support can be provided and is priced based on each customer environment.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Our onboarding process ensures a smooth transition from the initial sale through to long‑term service and support. Once a project is confirmed, we engage in structured onboarding that includes a full requirements review, stakeholder alignment, and handover from the sales team to project management. A dedicated project manager oversees delivery, coordinating timelines, dependencies, and customer expectations.
Training is tailored to customer needs: we offer onsite training, online/remote sessions, and comprehensive user documentation to ensure all users can adopt the solution confidently. As part of onboarding, we provide access to knowledge bases, operational guides, and support contacts so customers know exactly how to get assistance.
When a project moves into operations, we complete a formal service handover, including technical documentation, asset registers, support SLAs, and escalation paths. Support teams are fully briefed to ensure continuity.
Offboarding follows the same structured approach. If a service ends, we manage asset recovery, user deactivation, data management, and service closure tasks professionally and securely. Final documentation and confirmation ensure all contractual and operational obligations are completed.
Service documentation
Yes
Documentation formats
  • PDF
  • Other
Other documentation formats
  • Microsoft Word
  • Microsoft Excel
End-of-contract data extraction
Make a formal request into the servicedesk via a case
End-of-contract process
The contract expires user accounts are disabled and removed. Customer Monitoring is removed where required.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Provided to end users at onboarding project kickoff

Using the service

Web browser interface
No
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Our service is accessible through the Principle Networks Customer Portal, which provides a single, easy‑to‑use interface for managing your service. Through the portal, users can log and track support tickets, view all open and historic cases, update case details, and add additional information. You can also view contracts, check contract terms and end dates, manage approved contacts, and update company information. Administrators can manage user permissions and request reporting. The portal ensures customers have full visibility of their service at any time, with secure access controlled through Microsoft authentication.
Accessibility standards
None or don’t know
Description of accessibility
Our service is accessible through the Principle Networks Customer Portal, which provides a single, easy‑to‑use interface for managing your service. Through the portal, users can log and track support tickets, view all open and historic cases, update case details, and add additional information. You can also view contracts, check contract terms and end dates, manage approved contacts, and update company information. Administrators can manage user permissions and request reporting. The portal ensures customers have full visibility of their service at any time, with secure access controlled through Microsoft authentication.
Accessibility testing
Internally, we validate accessibility through standard browser‑based accessibility tools, automated audits, and manual checks to ensure key functions such as viewing tickets, updating cases, managing contacts, and reviewing contracts remain accessible to all users. As part of our continuous‑improvement approach, we review user feedback and adjust the interface where necessary to improve clarity, readability, and ease of interaction for customers who rely on assistive tools.
API
No
Customisation available
No

Scaling

Independence of resources
Zscaler leverages a purpose-built multi-tenant cloud architecture (Zero Trust Exchange) rather than virtual appliances. The platform is massively over-provisioned across 150+ global data centres, ensuring that demand spikes from one customer do not impact the performance of others. Key mechanisms include:

Elastic Scalability: The cloud platform automatically allocates computing resources to handle load variations instantly.
Logical Isolation: Customer traffic is processed in memory with strict separation; data never persists on the gateway.
Bandwidth Control: Customers can enforce granular policies to prioritise their own business-critical traffic (e.g., Teams, Zoom) over recreational usage, ensuring consistent performance.

Analytics

Service usage metrics
Yes
Metrics types
Principle Networks measures service performance through clearly defined SLA‑driven metrics, including rapid incident response and resolution times across all priority levels, 24×7 monitoring of device and service availability, and continual tracking of case volumes, service origins, closure reasons, and overall SLA compliance. These metrics are reviewed through structured service reports and monthly service reviews to ensure consistent first‑response performance, timely resolution, proactive issue detection, and continuous service improvement, all under an ISO 20000‑1 accredited service management framework.
Reporting types
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
ZScaler Inc.

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
NCSC approved service provider
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
This is a formal request to the servicedesk
Data export formats
  • CSV
  • Other
Other data export formats
  • PDF
  • JSON
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
Other
Other protection within supplier network
Principle Networks protect data within our network by applying strong security controls across our infrastructure, ensuring that information remains confidential, available, and tamper‑free. This includes enforcing encryption for data both in transit and at rest, tightly controlling and reviewing access through least‑privilege andauthentication mechanisms, and maintaining secure configurations across firewalls, endpoints, and cloud services. Our environment is continuously monitored using threat‑intelligence‑driven tools, automated alerting, and vulnerability notifications to detect and respond to risks quickly. We use Data Loss Prevention controls to prevent unauthorised sharing of sensitive information, alongside structured incident‑response processes to ensure any issues are contained and resolved promptly.

Availability and resilience

Guaranteed availability
We guarantee high availability across our managed services through 24×7×365 monitoring, proactive alerting, and resilient architecture. Our services operate under IS 20000‑1‑aligned service management, with strict SLAs governing response and resolution. For incident availability, we commit to a 30‑minute response for P1 and P2 incidents, with target fix times of 2–5 hours for critical issues, depending on whether the solution is resilient, hardware‑based, or dependent on third‑party circuits. Lower‑priority issues follow defined SLA timelines to maintain consistent service quality.
Where contractual availability SLAs are in place, we provide service credits if availability falls below the agreed threshold. Credits are calculated using a transparent formula based on the number of hours outside SLA multiplied by the proportional hourly service cost. This ensures customers receive fair compensation for any material downtime.
Our approach combines continuous monitoring, resilient design, rapid engineering response, and clear escalation paths to maintain service uptime and minimise disruption.
Approach to resilience
Zscaler’s service is built upon the Zero Trust Exchange, a cloud-native platform distributed across over 150 data centres globally, removing reliance on traditional network perimeters.
Here is how resilience is embedded in the design:

Global Redundancy: Traffic is processed by the nearest ‘Service Edge’. If a specific node or data centre fails, connections automatically failover to the next available location without user intervention.
Elastic Scalability: The multi-tenant architecture scales horizontally, dynamically allocating compute resources to handle massive traffic surges or DDoS attacks instantly.
Disaster Recovery (DR): For private apps (ZPA), Private Service Edges can maintain local connectivity and enforce policies even if the global cloud is unreachable. For internet access (ZIA), configurable ‘safe modes’ ensure continuity during blackouts.
Brownout Mitigation: Intelligent traffic steering detects latency or packet loss, re-routing traffic to optimal paths to maintain performance.
Essentially, the system decouples security from physical appliances, ensuring consistent protection and uptime regardless of localised disruptions.
Outage reporting
Zscaler maintains transparency regarding service availability primarily through the Zscaler Trust Portal (trust.zscaler.com). This public dashboard provides granular, real-time visibility into the health of the entire global infrastructure.Here is how outage reporting is handled:
Public Dashboard: The Trust Portal displays the live status of all clouds (ZIA, ZPA, ZDX) and individual data centres. You can filter views by region to see specific service degradation or maintenance events.
Email Alerts: You can subscribe to the Trust Portal to receive proactive email notifications for incidents, scheduled maintenance, and security advisories relevant to your specific cloud instance.
API & Feeds: The Trust Portal provides JSON and RSS feeds for incidents. These allow you to programmatically ingest status updates into your internal monitoring tools (like ServiceNow or Splunk) rather than manually checking the website.
Additionally, for internal troubleshooting, Zscaler Digital Experience (ZDX) can alert your IT team if users face connectivity issues, helping distinguish between a local network fault and a Zscaler service anomaly.

Identity and authentication

User authentication needed
Yes
User authentication
Multi-Factor Authentication (MFA)
Access restrictions in management interfaces and support channels
We restrict access to management interfaces by ensuring they are never exposed to the public internet; configuration access is limited to internal networks or VPN/Zscaler‑protected connections, with MFA enforced for all administrators. Only named, authorised users with role‑based access can perform changes, and all administrative access is logged and periodically reviewed.

Support channels are similarly restricted: only authenticated users on compliant corporate devices can access systems, governed by conditional access policies enforcing location, device posture, and MFA. Users must request changes through the servicedesk using verified identities, ensuring only authorised personnel can engage support functions.
Access restriction testing frequency
At least every 6 months
Management access authentication
Multi-Factor Authentication (MFA)

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
Between 6 months and 12 months
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
We follow a comprehensive set of information security policies that cover access control, secure configuration, encryption, incident management, risk management, acceptable use, business continuity, data handling, and secure development. These policies define how we protect data, manage systems securely, and ensure confidentiality, integrity, and availability across all services.
Our governance structure is led by the Information Security Team, with overall accountability held by senior leadership. Operational responsibility for maintaining and enforcing the Information Security Management System sits with the Head of Service Operations, supported by technical leads and policy owners.
To ensure policies are consistently followed, we use controlled documentation, mandatory annual security and GDPR training for all staff, formal onboarding/offboarding processes, and strict access‑control reviews. Compliance is reinforced through internal audits, continuous monitoring, and a defined incident‑reporting process that requires any suspected breach or security event to be reported immediately for investigation.
This structured approach ensures security responsibilities are clear, risks are managed, and policies are embedded in day‑to‑day operations.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
We comply with formal configuration and change‑management processes that form part of our ISO‑2000-1 aligned Information Security Management System (ISMS) and IT Service Management framework.
Our configuration management approach ensures that all assets, systems, and device configurations are documented, version‑controlled, and maintained through approved configuration baselines. Configuration changes are tracked, reviewed, and stored centrally, ensuring accuracy, traceability, and rollback capability where required.
Change management follows a structured, risk‑aware workflow. All must be requested, assessed for impact and risk. High‑risk changes follow enhanced governance, including technical peer review. Emergency changes are documented retrospectively and reviewed to ensure control effectiveness.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
We assess threats through continuous monitoring, regular vulnerability scanning, and risk evaluation across all services. Threat intelligence is sourced from vendor security advisories, industry feeds, government alerts (e.g., NCSC), and community CVE databases. Patches are prioritised by severity: critical vulnerabilities are actioned and deployed as quickly as possible, typically within 24–72 hours, with lower‑risk issues scheduled into routine maintenance cycles. Findings are tracked through our internal change and incident management processes to ensure full remediation and verification.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
We assess threats continuously using vendor advisories, CVE feeds, security bulletins, and monitoring tools to identify vulnerabilities relevant to our services. High‑ or critical‑risk vulnerabilities are patched proactively, typically within 24 hours where they present an immediate threat, while all other vendor‑rated high/critical patches are deployed within a 14‑day target window. Lower‑risk issues follow scheduled maintenance cycles. Threat intelligence comes from vendor notifications, industry security alerts, and active monitoring of supported platforms. This ensures rapid mitigation, stable patching, and consistent protection across all managed environments.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
We operate a defined incident‑management process with predefined workflows for common events, including priority‑based handling and a dedicated P1/Major Incident procedure with automated bridges and communication steps. Incidents are reported via email, phone, proactive monitoring alerts, or directly through the Customer Portal, all of which create a case in our ITSM system with full classification and prioritisation. We provide incident reports through post‑incident reviews, including Major Incident Reports, which are generated and shared with affected customers after resolution.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
We offer proof of concept evaluation to a limited number of users. The proof of concept scope and term is defined based on the requirements of the customer.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
10%
Between £250,000 and £500,000
22%
Between £500,001 and £1,000,000
30%
Between £1,000,001 and £2,500,000
30%
Between £2,500,001 and £5,000,000
30%
Over £5,000,001
30%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
CDL Group
ISO 9001 accreditation date
Tuesday 1 July 2025
What the ISO 9001 doesn’t cover
N/a
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
E29042f9-0029-4a93-840f-4178125bdd61
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
76366978-ee23-40f3-80dd-8b48234414fd
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Volunteering opportunities for staff
    • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
    • Measures for making facilities used in the delivery of the contract available for community groups, education or training
    • Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
    • Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Other measures to offer development opportunities for the target cohort(s) in the contract workforce
    • Creation of outreach activities to create a pipeline of employees for the future contract delivery
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at gcloud@ng-it.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.