Skip to main content

New in August: Password Manager ratings updated and expanded Read more

Business security

Best ZTNA solutions

ZTNA should publish private apps to verified users and devices without placing them on a flat network. Shortlist by IdP fit, device posture, and private app discovery effort.

Updated Aug 2026

Quick answer

Quick answer

ZTNA should publish private apps to verified users and devices without placing them on a flat network. Shortlist by IdP fit, device posture, and private app discovery effort.

  • Treat ZTNA as an application migration program
  • Device posture and IdP hygiene come first
  • SecurityCheckli.st rating: Not assigned

Shortlist to evaluate

Order reflects common buying patterns, not a scored ranking. Confirm fit in a pilot.

Rank 1

Zscaler / SSE-led ZTNA

Best for: Enterprises already considering SSE consolidation

Vendor-reported ZTNA within broader SSE portfolios. Evaluate private app onboarding effort and posture integrations.

  • SSE adjacency
  • Network change management needed
  • Confirm data residency

Rank 3

Cloudflare / modern edge ZTNA offerings

Best for: Teams wanting faster private app publishing patterns

Vendor-reported Zero Trust products emphasize simplified connectors. Validate protocol support for legacy apps.

  • Often faster pilots
  • Legacy protocol gaps possible
  • IdP integration is central

Rank 5

VPN hardening (transitional only)

Best for: Short bridge while ZTNA onboarding proceeds

Split-tunnel policy, MFA, and device checks reduce harm but keep network-level trust. Time-box this state.

  • Not a destination
  • Still useful as bridge
  • Track app migration burndown

SecurityCheckli.st rating: Not assigned for vendors on this page unless a published review states otherwise. Capability statements attributed to vendors are vendor-reported.

ZTNA shortlist matrix

Attribute SSE-led ZTNA Edge ZTNA Microsoft path Hardened VPN bridge
Trust model App-centric with SSE controls App-centric edge connectors Identity-centric private access Network-centric
Legacy app friction Medium to high Medium; protocol dependent Medium; evolving Low short-term
Ops skill focus SSE policy engineering Connector and IdP ops Entra/Intune literacy Firewall/VPN literacy
SecurityCheckli.st rating Not assigned Not assigned Not assigned Not assigned

Cells summarize buyer-relevant differences for diligence. They are not scored ratings. SecurityCheckli.st rating: Not assigned.

How to choose in this category

App inventory

You cannot publish what you have not listed.

Device posture

ZTNA without posture often recreates VPN trust on a nicer portal.

IdP alignment

SSO and lifecycle events must be clean first.

Protocol reality

Thick clients and exotic protocols break naive designs.

Contractor paths

Third parties need scoped apps, not whole networks.

Rating

SecurityCheckli.st rating: Not assigned.

Buying guidance

ZTNA success is an application migration program

Zero trust network access projects fail when treated as a weekend VPN swap. They succeed when application owners accept connector changes, DNS patterns, and user communication plans.

Buyer fit diverges: Microsoft-standardized firms should pressure-test Entra private access paths before adding another agent. Multi-cloud and heavy third-party access environments often benefit from dedicated ZTNA/SSE vendors. Always compare against the remote workforce stack guidance.

Limitations

ZTNA does not encrypt SaaS-to-SaaS abuse inside approved apps, nor does it replace email security. It also cannot invent device compliance if MDM enrollment is optional and unenforced.

Capture must-haves before demos

Use the business security checklist for integrations, residency, and staffing constraints.

The checklist is a static worksheet on this site. No account required.

Frequently asked questions

Do you publish a numeric SecurityCheckli.st rating on this page?
No. SecurityCheckli.st rating: Not assigned until evidence supports a published score. We will not invent a number to fill a table.
Are product capabilities independently verified?
Unless an evidence block marks a finding as confirmed, treat detailed capability claims as vendor-reported and validate them in your own tenancy or pilot.
Is ZTNA the same as SASE?
ZTNA is a private application access pattern. SASE usually bundles ZTNA with SWG, CASB, and related SSE services. See the SASE shortlist.
Can ZTNA replace VPN completely?
Often eventually, rarely on day one. Plan dual-run and exception handling for stubborn apps.
What breaks first in pilots?
Split DNS assumptions, legacy thick clients, and missing device compliance signals.
Where do I capture app lists?
Checklist plus the vendor shortlist worksheet.

Sources and further reading

  1. SecurityChecklist enterprise methodology — SecurityCheckli.st
    How ratings, commercial relationships, and limitations are handled
  2. Business security hub — SecurityCheckli.st
  3. Zero trust access — SecurityCheckli.st

Next step

Record must-haves in the checklist, then continue with the parent hub or methodology.