Skip to main content

New in August: Password manager research and finders updated Read more

Independent reviews. Real tests. Smarter security decisions.

SecurityChecklist

Business security

Best ZTNA solutions

ZTNA should publish private apps to verified users and devices without placing them on a flat network. Shortlist by IdP fit, device posture, and private app discovery effort.

Updated Aug 2026

Quick answer

ZTNA should publish private apps to verified users and devices without placing them on a flat network. Shortlist by IdP fit, device posture, and private app discovery effort.

  • Treat ZTNA as an application migration program
  • Device posture and IdP hygiene come first
  • SecurityCheckli.st rating: Not assigned

Shortlist to evaluate

Order reflects common buying patterns, not a scored ranking. Confirm fit in a pilot.

Rank 1

Zscaler / SSE-led ZTNA

Best for: Enterprises already considering SSE consolidation

Vendor-reported ZTNA within broader SSE portfolios. Evaluate private app onboarding effort and posture integrations.

  • SSE adjacency
  • Network change management needed
  • Confirm data residency

Rank 3

Cloudflare / modern edge ZTNA offerings

Best for: Teams wanting faster private app publishing patterns

Vendor-reported Zero Trust products emphasize simplified connectors. Validate protocol support for legacy apps.

  • Often faster pilots
  • Legacy protocol gaps possible
  • IdP integration is central

Rank 5

VPN hardening (transitional only)

Best for: Short bridge while ZTNA onboarding proceeds

Split-tunnel policy, MFA, and device checks reduce harm but keep network-level trust. Time-box this state.

  • Not a destination
  • Still useful as bridge
  • Track app migration burndown

SecurityCheckli.st rating: Not assigned for vendors on this page unless a published review states otherwise. Capability statements attributed to vendors are vendor-reported.

ZTNA shortlist matrix

Attribute SSE-led ZTNA Edge ZTNA Microsoft path Hardened VPN bridge
Trust model App-centric with SSE controls App-centric edge connectors Identity-centric private access Network-centric
Legacy app friction Medium to high Medium; protocol dependent Medium; evolving Low short-term
Ops skill focus SSE policy engineering Connector and IdP ops Entra/Intune literacy Firewall/VPN literacy
SecurityCheckli.st rating Not assigned Not assigned Not assigned Not assigned

Cells summarize buyer-relevant differences for diligence. They are not scored ratings. SecurityCheckli.st rating: Not assigned.

How to choose in this category

App inventory

You cannot publish what you have not listed.

Device posture

ZTNA without posture often recreates VPN trust on a nicer portal.

IdP alignment

SSO and lifecycle events must be clean first.

Protocol reality

Thick clients and exotic protocols break naive designs.

Contractor paths

Third parties need scoped apps, not whole networks.

Rating

SecurityCheckli.st rating: Not assigned.

How to use this shortlist

ZTNA should publish private apps to verified users and devices without placing them on a flat network. Shortlist by IdP fit, device posture, and private app discovery effort.

Start with the operating model: who owns alerts, what integrations are mandatory, and which free or included controls already cover part of the job. Paid options only earn a seat when a leftover gap remains.

Use the linked reviews and the business security checklist to turn this shortlist into company-specific requirements.

Related reading: business security hub, methodology, business security tools.

Capture must-haves before demos

Use the business security checklist for integrations, residency, and staffing constraints.

The checklist is a static worksheet on this site. No account required.

Frequently asked questions

Do you publish a numeric SecurityCheckli.st rating on this page?
No. This page does not publish a product score. Compare vendors against your requirements until a verified review score exists.
Are product capabilities independently verified?
Unless an evidence block marks a finding as confirmed, treat detailed capability claims as vendor-reported and validate them in your own tenancy or pilot.
Is ZTNA the same as SASE?
ZTNA is a private application access pattern. SASE usually bundles ZTNA with SWG, CASB, and related SSE services. See the SASE shortlist.
Can ZTNA replace VPN completely?
Often eventually, rarely on day one. Plan dual-run and exception handling for stubborn apps.
What breaks first in pilots?
Split DNS assumptions, legacy thick clients, and missing device compliance signals.
Where do I capture app lists?
Checklist plus the vendor shortlist worksheet.

Sources and further reading

  1. SecurityChecklist enterprise methodology — SecurityCheckli.st
    How ratings, commercial relationships, and limitations are handled
  2. Business security hub — SecurityCheckli.st
  3. Zero trust access — SecurityCheckli.st

Next step

Record must-haves in the checklist, then continue with the parent hub or methodology.

Page information & sources

About this page

ZTNA shortlist for replacing flat VPN access with application-centric zero trust network access. SecurityCheckli.st rating: Not assigned.

Methodology

Editorial responsibility

Published by SecurityChecklist editorial

Editorial policy

Corrections

Request a correction

Commercial disclosure

Some product links may be commercial. Affiliate relationships never set rankings. See the affiliate disclosure.