Zscaler Private Access (ZPA) Managed Licensing
Zscaler Private Access delivers zero trust access to private applications without exposing networks to the internet. Users connect securely based on identity, device posture and policy. Cloud native enforcement replaces VPNs, reducing attack surface while providing fast, resilient access for modern hybrid workforces across cloud and data centre environments globally.
Features
- Zero trust, per-application access replacing traditional network-level VPNs for users
- Encrypted microtunnels broker user-to-app connections without exposing networks to internet
- Outbound-only App Connectors remove inbound ports and public application exposure
- Client and clientless access options supporting RDP, SSH and web
- Identity integration for single sign-on and conditional access policies enforcement
- Device posture checks from endpoint management gates access to applications
- Comprehensive logging to SIEM platforms plus detailed audit-ready reports generated
- Global service edges deliver high availability, scale and consistent performance
- Granular policy controls by user, device, location and application context
- Multi-cloud and data centre coverage without new hardware appliances required
Benefits
- Reduces business risk by eliminating broad network access and exposure
- Improves user experience with fast, direct access to applications everywhere
- Simplifies operations by consolidating remote access into one cloud service
- Accelerates deployments using proven blueprints, pilots and phased migration approach
- Strengthens compliance through centralised logging, auditing and clear evidence trails
- Enables secure third-party access without jump hosts or network changes
- Cuts support tickets by removing fragile VPN gateways and complexity
- Supports hybrid work consistently across headquarters, branches, partners and remote
- Improves visibility with dashboards, alerts and real-time policy insights everywhere
- Optimises spend with right-sized licensing and transparent usage-based reporting capabilities
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 7 6 8 8 2 1 4 6 7 8 9 1 0 5
Contact
CyberOne
Ben Harding
Telephone: +44 3452 757575
Email: ben.harding@cyberone.security
About the service
- Service categories
-
Applications
Production and operations
- Other operations
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Zscaler integrates with single sign-on providers including Entra ID, Okta, OneLogin and Ping Identity to enable simplified cloud application security.
- Cloud deployment model
- Public cloud
- Service constraints
- No
- System requirements
- None
User support
- Email or online ticketing support
- Yes
- Support response times
-
ENHANCED HOURS
24x7 x 365 Days
P1: Critical - i.e. System Outage 30 Minutes
P2: High - i.e. System Fault 1 Hour
STANDARD HOURS Monday – Friday 8am - 5:30pm
P3: Medium - i.e. Device Fault 2 Hours
P4: Low – i.e. Single User Fault 4 Hours
P5: Very Low – i.e. Request For Info, Standard MACD 8 Hours - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Fully managed service.
Support is commercially scoped pending a full discovery workshop phase. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Users are supported through a combination of documentation, guided onboarding and training. Comprehensive online documentation, deployment guides and knowledge base articles covering setup, configuration and operations are provided. Online training and certification courses are available through Zscaler training platforms for administrators and engineers. Initial onboarding is typically supported remotely, rather than onsite by default. Ongoing support is provided through technical support channels, best practice guidance and regular service updates, enabling customers to adopt and operate the service effectively.
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- We explore this at a contract closure.
- End-of-contract process
-
Any existing hosted services are transitioned to the customer.
All existing support contracts are terminated. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Zscaler documentation is delivered primarily through web based HTML documentation and knowledge base articles. Content can be accessed using standard browsers and supports common accessibility features such as zoom, text resizing and screen magnification. Documentation follows a structured layout with headings, links and searchable content to aid navigation. While no formal accessibility certification is published, the documentation is usable with standard assistive technologies supported by modern browsers. Some diagrams and embedded content may have limited alternative text, which can restrict accessibility for screen reader users.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Windows
- ChromeOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Desktop ZPA provides the most complete experience, with broad support for private apps, deeper device posture checks and richer logging and troubleshooting. It is better suited to full-time users and admin workflows. Mobile ZPA on iOS and Android delivers secure access through Zscaler Client Connector but is optimised for mobile usage and constrained by operating system limitations. Some advanced controls, diagnostic visibility and traffic handling options can be reduced compared to desktop. In practice, mobile is ideal for internal web apps and approved services on the move, while desktop supports wider application types and operational management needs.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The Zscaler Private Access service interface consists of a cloud-based admin portal and an endpoint client interface. The admin portal is web-based and used by administrators to configure access policies, manage users and applications, monitor activity and review logs and analytics. It provides centralised control with role-based access. End users interact through the Zscaler Client Connector on their device, which runs in the background and provides status visibility, authentication prompts and connection information. The interface is designed to be simple for users while giving administrators granular control and clear operational insight.
- Accessibility standards
- None or don’t know
- Description of accessibility
- Zscaler Private Access interfaces follow modern web design and operating system accessibility features but are not formally certified against WCAG 2.2 or EN 301 549. Users can navigate the admin portal using standard browsers, adjust zoom and contrast and use native OS accessibility features such as screen magnification. The Zscaler Client Connector is designed to run with minimal user interaction. Some advanced configuration workflows and dashboards may be challenging for users relying on screen readers or full keyboard-only navigation.
- Accessibility testing
- No formal or published interface testing has been conducted with users of assistive technology. Zscaler has not released documentation confirming usability testing with screen readers, keyboard-only navigation or other assistive technologies, so accessibility support is based on standard browser and operating system capabilities rather than validated testing outcomes.
- API
- Yes
- What users can and can't do using the API
- Zscaler Private Access provides REST APIs that allow administrators to set up and manage the service programmatically. Users can create and update application segments, access policies, connectors and user mappings, supporting automation and infrastructure-as-code approaches. Configuration changes, updates and bulk operations can be performed through the API, reducing reliance on the admin portal. Reporting and operational data can also be retrieved. Some advanced features and initial tenant provisioning still require use of the admin portal, and API actions are subject to role-based access controls and platform limits.
- API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Zscaler Private Access allows configuration-driven customisation. Buyers can customise application access policies, user and group mappings, identity provider integration, device posture requirements, connector deployment and logging levels. Customisation is carried out through the Zscaler web-based admin portal or via APIs for automation. Changes are controlled through role based access, so only authorised administrators can configure or modify the service. End users have no ability to change security policies, ensuring consistent enforcement and reducing operational risk.
Scaling
- Independence of resources
- Zscaler security as a service is delivered by a next-generation security architecture built from the ground up for performance and scalability. It is distributed across more than 100 data centers on 6 continents, which means that users are always a short hop to their applications, and we peer with hundreds of partners in major internet exchanges around the world for performance and reliability.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Dependent on customer requirements.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Zscaler
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Other
- Other data at rest protection approach
- Strict access controls, key management processes and continuous monitoring.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Users export data through the Zscaler web-based admin portal and APIs. Administrators can download reports, logs and configuration data in standard formats such as CSV or JSON, or retrieve data programmatically via REST APIs. Operational and security logs are commonly exported by forwarding them to external SIEM or logging platforms during the contract term. Data export must be completed before tenant decommissioning, as access is removed once the service is terminated.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Standard SLA's are as follows:
< 30 minutes P1
< 90 minutes P2
< 4 Hours P3
Service credits are assigned on a company by company basis. - Approach to resilience
- Zscaler security as a service is delivered by a next-generation security architecture built from the ground up for performance and scalability. It is distributed across more than 150 data centers on 6 continents, which means that users are always a short hop to their applications and we peer with hundreds of partners in major internet exchanges around the world for performance and reliability.
- Outage reporting
- Zscaler reports service outages and incidents through multiple channels to ensure timely visibility. A public service status dashboard provides real time and historical information on platform availability and incidents. Customers can subscribe to email alerts for service disruptions, maintenance notifications and incident updates. Service health and operational status can also be accessed through APIs and administrative notifications within the Zscaler portal. This multi-channel approach ensures customers receive clear, timely information and can respond effectively to any service impact.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Username or password
- Other
- Other user authentication
- Device posture checks and certificate based trust can be enforced as part of the authentication and access decision.
- Access restrictions in management interfaces and support channels
- Access to Zscaler management interfaces and support channels is tightly restricted using role based access controls and strong authentication. Administrative access to the Zscaler portal requires authenticated identities, typically federated with an enterprise identity provider, and supports multi factor authentication. Permissions are granted on a least privilege basis, limiting what each administrator can view or change. Support access is controlled through authenticated support accounts, case based access and audit logging. All administrative and support actions are logged and monitored to detect misuse and support compliance and forensic review.
- Access restriction testing frequency
- Less than once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Username or password
- Other
- Description of management access authentication
- Role based access control, least privilege enforcement and full audit logging.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Other
- Other security governance standards
- Zscaler also complies with additional recognised security and governance frameworks, including SSAE-18 SOC 2 Type II and related assurance standards, supporting robust governance, risk management and compliance.
- Information security policies and processes
- Zscaler operates a formal information security management framework aligned to ISO/IEC 27001. Information security policies cover areas such as access control, risk management, incident response, data protection, vulnerability management and supplier assurance. Policies are approved at the executive level and owned by the Chief Information Security Officer, who reports to senior leadership and the board. Compliance is enforced through technical controls, mandatory training, audits and continuous monitoring. Independent third-party audits and internal reviews are used to verify adherence, with corrective actions tracked through defined governance and risk management processes.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Zscaler operates formal configuration and change management processes aligned to ISO/IEC 27001 and SOC 2 controls. Service components are tracked through their full lifecycle using centralised configuration management, asset inventories and version control. Changes are requested, reviewed and approved through controlled workflows with defined roles and segregation of duties. All changes are assessed for operational and security impact, including risk evaluation, testing and rollback planning where required. Security teams are involved in change assessment to ensure policy compliance, minimise risk and maintain service integrity across the global platform.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Threats are managed via proactive alerting with vendors.
Internal and external penetration tests. Patches are assessed through dev and test stages, then deployed as quickly as possible. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
This is handled by our proactive monitoring software which is tuned to identify threats based on specific customer requirements.
Incident response is SLA dependant. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Zscaler operates a formal, documented incident management process aligned with CSA CCM v4.0, ISO/IEC 27001 and SOC 2 requirements. Pre-defined playbooks are in place for common security and service incidents, enabling rapid, consistent response and escalation. Incidents are identified through continuous monitoring and can also be reported by customers via the support portal or support channels. Confirmed incidents are handled by dedicated response teams with clear ownership and escalation paths. Customers are kept informed through the public status dashboard and email notifications, with detailed incident reports and post-incident reviews provided where customer impact occurs.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2%
- Between £500,001 and £1,000,000
- 4%
- Between £1,000,001 and £2,500,000
- 6%
- Between £2,500,001 and £5,000,000
- 8%
- Over £5,000,001
- 10%
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- ISO/IEC 27001 accredited by
- BSI Assurance UK Limited
- ISO/IEC 27001 accreditation date
- Tuesday 5 December 2017
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
-
- CREST Security Operations Centre
- CREST Cyber Incident Response
- NCSC Assured Service Provider
- NCSC Assured Service Provider Cyber Incident Response (Level 1)
- Microsoft Intelligent Security Association & Verified Managed XDR Solution Partner
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Plans for positive actions with community groups.
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
- Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
- Mission: Make Britain a clean energy superpower
-
To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
- Mission: Break down barriers to opportunity
-
By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Introducing transparency to pay and reward processes
- Working conditions which promote an inclusive working environment and promote retention and progression
- Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of issues relating to entering the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
- Mission: Build an NHS fit for the future
-
That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce