Skip to main content

Help us improve the Digital Marketplace - send your feedback

CyberOne

Zscaler Internet Access (ZIA) Managed Licensing

Zscaler Internet Access is a cloud delivered secure web gateway that protects users from internet threats and data loss. It enforces security policies inline, inspects traffic at scale and provides consistent protection for users wherever they work, replacing legacy perimeter security with a modern, cloud native approach.

Features

  • Cloud secure web gateway with inline URL filtering and categorisation.
  • Full SSL/TLS inspection to detect threats in encrypted traffic.
  • Advanced threat protection using sandboxing, IPS and malware analysis.
  • Cloud firewall for user and application level internet controls.
  • Data Loss Prevention with content inspection and policy enforcement.
  • CASB controls for sanctioned SaaS access, posture and governance.
  • Remote browser isolation option to contain high risk web content.
  • Real time dashboards, logs and analytics for security visibility.
  • API integration for automation, reporting and security orchestration.
  • Global cloud platform with scalable performance, resilience and uptime.

Benefits

  • Protect users anywhere without backhauling traffic through headquarters infrastructure.
  • Reduce malware and phishing risk with always on inline inspection.
  • Enforce consistent internet access policies across all users and devices.
  • Accelerate incident response with real time visibility and searchable logs.
  • Prevent data leakage by inspecting content and enforcing DLP policies.
  • Improve SaaS governance by controlling risky apps and user actions.
  • Simplify security architecture by replacing multiple legacy gateway appliances.
  • Support hybrid working securely without VPN dependency for internet access.
  • Reduce operational overhead through centralised cloud management and automation.
  • Improve user experience with local egress and optimised global routing.

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ben.harding@cyberone.security. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 1 1 4 2 0 0 4 1 7 0 0 8 6 0

Contact

CyberOne Ben Harding
Telephone: +44 3452 757575
Email: ben.harding@cyberone.security

About the service

Service categories

Applications

Production and operations

  • Other operations
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Zscaler integrates with single sign-on providers including Entra ID, Okta, OneLogin and Ping Identity to enable simplified cloud application security.
Cloud deployment model
Public cloud
Service constraints
No
System requirements
None

User support

Email or online ticketing support
Yes
Support response times
ENHANCED HOURS
24x7 x 365 Days

P1: Critical - i.e. System Outage 30 Minutes
P2: High - i.e. System Fault 1 Hour

STANDARD HOURS Monday – Friday 8am - 5:30pm
P3: Medium - i.e. Device Fault 2 Hours
P4: Low – i.e. Single User Fault 4 Hours
P5: Very Low – i.e. Request For Info, Standard MACD 8 Hours
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Fully managed service.
Support is commercially scoped pending a full discovery workshop phase.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Users are supported through a combination of documentation, guided onboarding and training. Comprehensive online documentation, deployment guides and knowledge base articles covering setup, configuration and operations are provided. Online training and certification courses are available through Zscaler training platforms for administrators and engineers. Initial onboarding is typically supported remotely, rather than onsite by default. Ongoing support is provided through technical support channels, best practice guidance and regular service updates, enabling customers to adopt and operate the service effectively.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
We explore this at a contract closure.
End-of-contract process
Any existing hosted services are transitioned to the customer.
All existing support contracts are terminated.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Zscaler documentation is delivered primarily through web based HTML documentation and knowledge base articles. Content can be accessed using standard browsers and supports common accessibility features such as zoom, text resizing and screen magnification. Documentation follows a structured layout with headings, links and searchable content to aid navigation. While no formal accessibility certification is published, the documentation is usable with standard assistive technologies supported by modern browsers. Some diagrams and embedded content may have limited alternative text, which can restrict accessibility for screen reader users.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • Linux or Unix
  • MacOS
  • Windows
  • ChromeOS
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Zscaler Internet Access supports mobile devices through the Zscaler Client Connector on iOS and Android. Core security controls such as web filtering, threat protection and policy enforcement are consistent with desktop platforms. Some advanced features, diagnostics and traffic handling options are more limited on mobile due to operating system restrictions. Mobile support is optimised for user transparency and battery efficiency, while desktop platforms provide broader visibility, configuration flexibility and troubleshooting capabilities for security and IT teams.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Zscaler Internet Access is managed through a cloud based web admin portal used to configure security policies, user access, data protection and threat controls. The interface provides dashboards, logs and reporting for visibility and investigation. End users interact through the Zscaler Client Connector, which runs in the background and provides connection status and basic controls, requiring minimal user interaction while enforcing security transparently.
Accessibility standards
None or don’t know
Description of accessibility
Zscaler Internet Access interfaces follow modern web design and operating system accessibility features but are not formally certified against WCAG 2.2 or EN 301 549. Users can navigate the admin portal using standard browsers, adjust zoom and contrast and use native OS accessibility features such as screen magnification. The Zscaler Client Connector is designed to run with minimal user interaction. Some advanced configuration workflows and dashboards may be challenging for users relying on screen readers or full keyboard-only navigation.
Accessibility testing
No formal or published interface testing has been conducted with users of assistive technology. Zscaler has not released documentation confirming usability testing with screen readers, keyboard-only navigation or other assistive technologies, so accessibility support is based on standard browser and operating system capabilities rather than validated testing outcomes.
API
Yes
What users can and can't do using the API
Zscaler Internet Access provides REST APIs that allow administrators to configure and manage the service programmatically. Users can create and update security policies, URL categories, firewall rules, DLP settings and user or group mappings. Configuration changes and bulk updates can be made through the API to support automation and integration with external systems. Reporting and log data can also be retrieved. Some initial tenant setup, advanced configuration options and certain feature enablement steps still require use of the admin portal. API access is controlled by roles and platform limits.
API documentation
Yes
API documentation formats
HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Users can customise Zscaler Internet Access through configuration rather than code changes. Customisable elements include web access policies, URL filtering, firewall rules, SSL inspection, DLP policies, CASB controls, threat protection settings and reporting. Customisation is performed through the web based admin portal or via APIs for automation and integration. Access is controlled using role based permissions, so only authorised administrators can make changes. End users cannot modify security controls, ensuring consistent enforcement and reducing operational and security risk across the organisation.

Scaling

Independence of resources
Zscaler security as a service is delivered by a next-generation security architecture built from the ground up for performance and scalability. It is distributed across more than 100 data centers on 6 continents, which means that users are always a short hop to their applications, and we peer with hundreds of partners in major internet exchanges around the world for performance and reliability.

Analytics

Service usage metrics
Yes
Metrics types
Dependent on customer requirements.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Supplier type

Supplier type
Reseller providing extra support
Organisation whose services are being resold
Zscaler

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
  • Other
Other data at rest protection approach
Strict access controls, key management processes and continuous monitoring.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Users export data through the Zscaler web-based admin portal and APIs. Administrators can download reports, logs and configuration data in standard formats such as CSV or JSON, or retrieve data programmatically via REST APIs. Operational and security logs are commonly exported by forwarding them to external SIEM or logging platforms during the contract term. Data export must be completed before tenant decommissioning, as access is removed once the service is terminated.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Standard SLA's are as follows:
< 30 minutes P1
< 90 minutes P2
< 4 Hours P3

Service credits are assigned on a company by company basis.
Approach to resilience
Zscaler security as a service is delivered by a next-generation security architecture built from the ground up for performance and scalability. It is distributed across more than 150 data centers on 6 continents, which means that users are always a short hop to their applications and we peer with hundreds of partners in major internet exchanges around the world for performance and reliability.
Outage reporting
Zscaler reports service outages and incidents through multiple channels to ensure timely visibility. A public service status dashboard provides real time and historical information on platform availability and incidents. Customers can subscribe to email alerts for service disruptions, maintenance notifications and incident updates. Service health and operational status can also be accessed through APIs and administrative notifications within the Zscaler portal. This multi-channel approach ensures customers receive clear, timely information and can respond effectively to any service impact.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Username or password
  • Other
Other user authentication
Device posture checks and certificate based trust can be enforced as part of the authentication and access decision.
Access restrictions in management interfaces and support channels
Access to Zscaler management interfaces and support channels is tightly restricted using role based access controls and strong authentication. Administrative access to the Zscaler portal requires authenticated identities, typically federated with an enterprise identity provider, and supports multi factor authentication. Permissions are granted on a least privilege basis, limiting what each administrator can view or change. Support access is controlled through authenticated support accounts, case based access and audit logging. All administrative and support actions are logged and monitored to detect misuse and support compliance and forensic review.
Access restriction testing frequency
Less than once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Username or password
  • Other
Description of management access authentication
Role based access control, least privilege enforcement and full audit logging.

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • ISO/IEC 27001
  • Other
Other security governance standards
Zscaler also complies with additional recognised security and governance frameworks, including SSAE-18 SOC 2 Type II and related assurance standards, supporting robust governance, risk management and compliance.
Information security policies and processes
Zscaler operates a formal information security management framework aligned to ISO/IEC 27001. Information security policies cover areas such as access control, risk management, incident response, data protection, vulnerability management and supplier assurance. Policies are approved at the executive level and owned by the Chief Information Security Officer, who reports to senior leadership and the board. Compliance is enforced through technical controls, mandatory training, audits and continuous monitoring. Independent third-party audits and internal reviews are used to verify adherence, with corrective actions tracked through defined governance and risk management processes.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Zscaler operates formal configuration and change management processes aligned to ISO/IEC 27001 and SOC 2 controls. Service components are tracked through their full lifecycle using centralised configuration management, asset inventories and version control. Changes are requested, reviewed and approved through controlled workflows with defined roles and segregation of duties. All changes are assessed for operational and security impact, including risk evaluation, testing and rollback planning where required. Security teams are involved in change assessment to ensure policy compliance, minimise risk and maintain service integrity across the global platform.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Threats are managed via proactive alerting with vendors.
Internal and external penetration tests. Patches are assessed through dev and test stages, then deployed as quickly as possible.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
This is handled by our proactive monitoring software which is tuned to identify threats based on specific customer requirements.

Incident response is SLA dependant.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Zscaler operates a formal, documented incident management process aligned with CSA CCM v4.0, ISO/IEC 27001 and SOC 2 requirements. Pre-defined playbooks are in place for common security and service incidents, enabling rapid, consistent response and escalation. Incidents are identified through continuous monitoring and can also be reported by customers via the support portal or support channels. Confirmed incidents are handled by dedicated response teams with clear ownership and escalation paths. Customers are kept informed through the public status dashboard and email notifications, with detailed incident reports and post-incident reviews provided where customer impact occurs.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
2%
Between £500,001 and £1,000,000
4%
Between £1,000,001 and £2,500,000
6%
Between £2,500,001 and £5,000,000
8%
Over £5,000,001
10%

Standards and certifications

ISO/IEC 27001 certification
Yes
ISO/IEC 27001 accredited by
BSI Assurance UK Limited
ISO/IEC 27001 accreditation date
Tuesday 5 December 2017
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
None of the criteria
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
Yes
Any other security certifications
  • CREST Security Operations Centre
  • CREST Cyber Incident Response
  • NCSC Assured Service Provider
  • NCSC Assured Service Provider Cyber Incident Response (Level 1)
  • Microsoft Intelligent Security Association & Verified Managed XDR Solution Partner

Social value

Mission: Kick start economic growth

To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

  • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
  • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
  • Plans to engage the contract workforce in deciding the most important workplace issues to address
  • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
  • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
  • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
  • Activities to cascade good practice on fair working conditions throughout the supply chain
  • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
  • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
  • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
  • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
  • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
  • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
  • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Volunteering opportunities for staff
  • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
  • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
  • How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
  • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain

Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

  • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
  • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering

Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

  • Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
  • Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
  • Plans for positive actions with community groups.
  • Plans to respond flexibly and adapt approaches to community engagement and initiatives
  • Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
Mission: Make Britain a clean energy superpower

To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

  • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
Mission: Break down barriers to opportunity

By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

Policy Outcome 6: Employment and training: For those who face barriers to employment

  • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
  • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
  • Introducing transparency to pay and reward processes
  • Working conditions which promote an inclusive working environment and promote retention and progression
  • Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
  • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition

Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

  • Understanding of issues relating to entering the contract workforce
  • Creation of outreach activities to create a pipeline of employees for the future contract delivery
Mission: Build an NHS fit for the future

That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

  • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
  • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
  • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
  • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ben.harding@cyberone.security. Tell them what format you need. It will help if you say what assistive technology you use.