Zscaler ZIA, ZPA and Z-App Cloud Security Software Licensing and Deployment
Cloud security service providing licensing and deployment of Zscaler ZIA, ZPA, and Z-App solutions. Supports Zero Trust Network Architecture aligned with NCSC guidance, enabling secure access to cloud and legacy applications without traditional VPNs, while improving security, resilience, and centralised policy control.
Features
- Licensing, configuration, and deployment of Zscaler ZIA, ZPA, and Z-App
- Zero Trust Network Architecture configuration aligned with organisational security policies
- Centralised policy management, dashboards, and reporting
- Secure multi-device access including desktop, mobile, and browser-based users
- Integration with enterprise identity providers including LDAP, ADFS, and Okta
- Web filtering, cloud access control, and traffic management
- Integration with Microsoft 365 and SaaS applications
- Phased migration of applications to cloud-based access services
- Controlled decommissioning of legacy VPN services
- Cloud-hosted service with no on-premises hardware or appliances required
Benefits
- Faster deployment of Zscaler ZIA, ZPA, and Z-App through experts
- Aligned with ISO 27001, 20000-1, 14001, 9001, Cyber Essentials Plus
- Reduced reliance on traditional VPNs, lowering operational complexity and risk
- Secure access to cloud and legacy applications from any location
- Improved application performance through cloud-based traffic routing
- Consistent and simplified user access across devices and locations
- Automated blocking of malicious or unauthorised web traffic
- Reduced attack surface through Zero Trust Network Architecture principles
- Improved security visibility through centralised logging, dashboards, and reporting
- Centralised management of licences, policies, and platform configuration
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 3 1 0 0 0 8 6 6 3 8 6 4 6 7
Contact
VISIONIST LIMITED
Elaine Glock
Telephone: +44 (0)330 223 5000
Email: elaine.glock@visionist.com
About your service
- Service categories
-
Applications
Production and operations
- Other operations
Service industry and public sector operations
- Other
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No constraints
- System requirements
- NA
User support
- Email or online ticketing support
- Yes
- Support response times
- Within the hour
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AAA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AAA
- Web chat accessibility testing
- Our chat software has been tested with various web browsers which support various assistive technologies, including Dragon and Jaws.
- Onsite support
- Yes
- Support levels
- Smarter Technologies Group provides comprehensive, UK-based support across all services, aligned to ITIL best practice and customer requirements, with standard business hours support (09:00–17:30, Monday–Friday) included within the service price, covering incident, request, and change management via our Service Desk; extended or 24x7 support is available for mission-critical services at an additional, clearly defined cost agreed at contract or call-off stage based on service criticality, SLAs, and response requirements, with no hidden or per-incident charges. All our services are supported, at no additional cost, by a dedicated Technical Account Manager (TAM) who has over 20 years’ experience delivering successful transition and transformation services across the UK Public Sector, having operated on both the client and supplier side, and therefore bringing strong supplier management and communication skills at all levels. The TAM acts as the client’s first point of contact for any service issues, with a clear escalation route to the Client Director if required, and together the Client Director and TAM meet with clients on a regular basis to track service deliverables against requirements, manage risks, and ensure ongoing client satisfaction.
- Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
- At service commencement, we configure the platform to customer requirements, set up user access, and deliver onboarding sessions aligned to agreed use cases. Training can be provided remotely or onsite where required and covers dashboards, data visualisation, APIs, data flows, and operational processes. We provide clear, role-based user documentation, including platform guides, runbooks, and operational procedures, which are maintained and updated throughout the service lifecycle. Online training materials and recorded walkthroughs are made available to support self-service learning and onboarding of new users. Where required, we deliver bespoke training sessions for technical, operational, and business users to ensure they can confidently access data, interpret insights, and integrate the platform into day-to-day operations. Ongoing support and guidance are provided through the Service Desk and a dedicated Technical Account Manager, who ensures users receive continued assistance, best-practice advice, and support as their use of the data platform evolves.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
-
At the end of the contract, we supports customers with a structured and secure data extraction and service exit process to ensure full access to their data and a smooth transition. All customer data remains the property of the customer and can be extracted in standard, open formats appropriate to the service, such as CSV, JSON, or agreed database exports, to support reuse and migration to alternative platforms. Data can be provided via secure transfer methods, including encrypted download links or secure file transfer services, in line with agreed security requirements.
The data extraction process is planned in advance as part of service off-boarding, with the scope, format, and timelines agreed with the customer to minimise disruption. We provide reasonable technical support during the exit period to assist with data validation, clarification of schemas, and handover to a replacement supplier if required. Once data extraction has been completed and formally confirmed by the customer, remaining customer data is securely deleted from our systems in accordance with contractual obligations, data protection legislation, and our information security policies. - End-of-contract process
-
At the end of the contract, we follow a structured and transparent service exit process designed to ensure continuity, protect customer data, and minimise disruption. We work with the customer to agree an exit plan covering timelines, responsibilities, and dependencies, including data extraction, service wind-down, and transition to an alternative supplier or in-house operation if required. Customers are supported through the orderly decommissioning of services, removal of access, and confirmation of service cessation. All customer data remains the property of the customer and is handled in line with contractual and data protection requirements.
Included in the contract price is standard service off-boarding, including exit planning, coordination meetings, support for data extraction in agreed formats, and confirmation of secure deletion of customer data following customer sign-off. Reasonable administrative and technical support during the exit period is also included.
Additional costs may apply where the customer requests non-standard activities, such as extended exit periods beyond the contract end date, bespoke data transformation or migration support, additional documentation, or ongoing access to systems after service termination. Any additional costs are agreed in advance, are transparent, and are charged at pre-agreed rates to ensure clarity and cost control. - Documentation accessibility standard
- WCAG 2.2 AAA
Using the service
- Web browser interface
- No
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Optimised for mobile use.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AAA
- Description of service interface
- We offer a configurable service interface for real-time acquisition, processing, and presentation of utility and environmental data. The cloud-hosted platform ingests various data streams and normalises data at capture. Customer-specific models, tagging, and access policies are applied through the configuration layer. A unified data surface is exposed through secure browser access and APIs, enabling tailored dashboards, alerts, and analytics.
- Accessibility standards
- WCAG 2.2 AAA
- Accessibility testing
- Dragon and Jaws
- API
- Yes
- What users can and can't do using the API
- Can connect to data stream visualisation
- API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
- The dashboard for data is customised to your company and alerts are configurable
Scaling
- Independence of resources
- We ensure independence of resources through a segmented, cloud-based service architecture designed to prevent one customer’s demand from impacting another. Services are deployed using logical separation of environments, role-based access controls, and controlled resource allocation to isolate workloads. Platform capacity is actively monitored, with auto-scaling and threshold alerts used to manage demand peaks and maintain performance. We apply capacity management and forecasting as part of our service management process to ensure sufficient headroom is maintained at all times. Where required, customers can be supported using dedicated resources or environments, agreed at contract stage, to provide additional assurance for mission-critical services.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Metrics include service availability and uptime, incident volumes and resolution times, SLA compliance, and mean time to respond and restore (MTTR). We also report on change success rates, platform performance and capacity, and security and compliance indicators where applicable. Customer experience is measured through service review feedback and trend analysis. Metrics are reviewed regularly with customers via dashboards and service review meetings to ensure transparency, accountability, and continuous service optimisation.
- Reporting types
-
- API access
- Real-time dashboards
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Zscaler
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
- Physical access control, complying with CSA CCM v4.0
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Users export their data through secure, controlled, and standardised mechanisms designed to support reuse and portability. Data can be exported directly via platform APIs, allowing users to retrieve live or historical data programmatically in common, open formats such as JSON or CSV. For non-technical users, data exports can be generated from platform dashboards or reporting tools, enabling scheduled or ad-hoc downloads of datasets. Where larger volumes of data are required, we support bulk data exports delivered via secure file transfer methods, such as encrypted download links or secure transfer services. Export permissions are governed by role-based access controls.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- Private network or public sector network
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- 99%
- Approach to resilience
-
We design our services to meet the intent of NCSC Cloud Security Principle 2: Asset Protection and Resilience, ensuring services continue to operate in the face of faults, failures, or malicious activity. Our services are delivered using resilient cloud architectures designed to avoid single points of failure, with critical components deployed with redundancy and protected through secure configuration and access controls.
We implement defence in depth, including monitoring, alerting, and automated recovery mechanisms, to detect issues early and enable rapid response. Regular backups are performed, and tested recovery procedures are in place to restore services and data within agreed Recovery Time and Recovery Point Objectives. Capacity management and scaling controls ensure that unexpected demand or component failure does not degrade service availability.
Resilience is supported by documented incident management and service continuity processes, which are regularly reviewed and tested to ensure ongoing effectiveness.
Our services are hosted on high-availability cloud infrastructure, using resilient datacentre designs with geographic separation and fault tolerance appropriate to the service. Detailed information on datacentre locations, redundancy models, and resilience controls is available on request to support customer assurance and security assessments in line with NCSC guidance. - Outage reporting
-
We report service outages through a clear, timely, and multi-channel communication approach designed to ensure customers are promptly informed and kept up to date. Where appropriate, customers are provided access to a service status dashboard that shows current service health, planned maintenance, and any active incidents, giving visibility of impact and progress in near real time.
For customers requiring system-to-system integration, API-based status information can be made available to allow service health and incident updates to be consumed directly into customer monitoring or service management tools.
During an outage or service degradation, email alerts are issued to agreed customer contacts, providing confirmation of the incident, an initial impact assessment, and regular status updates until resolution. Notifications are aligned to agreed SLAs and escalation procedures to ensure the right stakeholders are informed at the right time.
In addition, outages are logged and tracked through our IT service management platform, with updates available via the Service Desk and the customer’s Technical Account Manager. Following resolution, customers receive a summary of the incident and, where appropriate, a post-incident review outlining root cause, actions taken, and any preventative measures implemented.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
-
We use role-based access control (RBAC), least-privilege principles, and strong authentication. Access to administrative and management interfaces is limited to authorised personnel only and protected using multi-factor authentication, secure credentials, and network controls. Permissions are granted based on job role and regularly reviewed.
Support channels are controlled through authenticated service desk access, with user identity verified before any action is taken. Segregation of duties is enforced to prevent unauthorised or inappropriate changes, and all access to management interfaces and support systems is logged and auditable. Access rights are promptly revoked when no longer required.. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
We follow a comprehensive set of information security policies and processes aligned to recognised standards and best practice, including ISO/IEC 27001 principles, ISO/IEC 20000-1 service management, NCSC guidance, and the UK Government’s Cyber Essentials and Cyber Essentials Plus schemes. Our policies cover information security governance, risk and asset management, access control, secure configuration, incident management, supplier security, data protection, and service continuity, and are supported by documented procedures that define how controls are implemented and operated across all services.
Accountability for information security sits with senior management, with clear reporting lines from operational and service teams through Service Owners to the CTO, who has overall responsibility for security, risk, and compliance. Security risks, incidents, and compliance status are reported through defined escalation paths and reviewed within regular management and service review forums.
We ensure policies are followed through mandatory staff security training, adherence to Cyber Essentials technical controls, role-based access management, formal change and incident management processes, and regular internal audits and assurance activities, including Cyber Essentials and Cyber Essentials Plus assessments. Policies and processes are reviewed at least annually, or following significant change, to ensure continued effectiveness and compliance. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
We adhere to ISO/IEC 20000-1, ISO/IEC 27001, Cyber Essentials and Cyber Essentials Plus. All service components are recorded within a controlled configuration management system and tracked throughout their lifecycle from design and deployment through to change and decommissioning. Configuration items are version controlled, auditable, and aligned to security baselines.
All changes are managed through a formal change management process aligned to ISO 20000-1, with mandatory security impact assessment in line with ISO 27001 and Cyber Essentials controls. Each change is assessed for risk to confidentiality, integrity, availability, and compliance before approval, tested prior to release, and subject to post-implementation review. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- We operate a structured vulnerability management process aligned to ISO 27001, ISO 20000-1, and Cyber Essentials / Cyber Essentials Plus. Potential threats are assessed through continuous monitoring, vulnerability scanning, and risk assessment against the confidentiality, integrity, and availability of our services. We prioritise vulnerabilities based on severity and impact, applying patches in line with defined SLAs, with critical security patches deployed as soon as practicable following validation and testing. Information on emerging threats is sourced from vendor security advisories, NCSC guidance, CERT alerts, and trusted industry sources, with findings reviewed by technical and security leads to ensure effective remediation.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
Potential compromises are identified through continuous monitoring of systems, logs, and alerts using security monitoring and SIEM tooling, combined with automated alerting and analyst review. Indicators such as anomalous behaviour, unauthorised access attempts, or configuration changes trigger investigation.
When a potential compromise is identified, incidents are logged and managed through our formal security incident response process, including containment, impact assessment, remediation, and escalation to senior technical and security leads where required. High-severity security incidents are responded to immediately, with rapid containment actions initiated and customers informed in line with agreed SLAs, followed by root cause analysis and corrective actions. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Our formal incident management processes align to ISO/IEC 20000-1 and ITIL best practice, with pre-defined procedures for common incident types to enable rapid and consistent response. Users can report incidents via our Service Desk, using email, phone, or our IT service management platform, which provides a single point of contact and full audit trail. Incidents are categorised, prioritised, and managed against agreed SLAs, with clear escalation paths for high-impact issues. Customers are kept informed through regular updates during an incident, and incident reports are provided following resolution, including impact, root cause (where applicable), actions taken, and any preventative measures implemented.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 7%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Peers Quality Assurance Limited
- ISO/IEC 27001 accreditation date
- Saturday 30 March 2024
- What the ISO/IEC 27001 doesn’t cover
- It covers everything,
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Alcumus ISOQAR
- ISO 9001 accreditation date
- Tuesday 6 June 2023
- What the ISO 9001 doesn’t cover
- Covers all management.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 5d246ce1-a8c5-4f64-8b5b-36e02b3ae9a6
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 1fa1061b-dee9-48b5-8a88-b499d9478d90
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-