Listing Thumbnail

    Zscaler U.S. Government Solutions, Zscaler for Users, FedRAMP Authorized

     Info
    Zscaler for Users consists of three FedRAMP and StateRAMP authorized services, Zscaler Internet Access Gov, Zscaler Private Access Gov, and Zscaler Digital Experience Gov, to improve security, data protection, and digital experience. All three solutions are powered by the Zscaler Zero Trust Exchange, a cloud-native security platform that securely connects any user, device, and application, regardless of location. Following the principle of least-privileged access, the platform establishes trust through user identity and context, including location, device, application, and content, and then creates secure, direct connections based on policy enforcement. The platform supports IT federal mission transformation by reducing costs, eliminating the internet attack surface, and preventing lateral threat movement while providing an excellent user experience.

    Overview

    Play video

    Zscaler is leading the effort to implement Zero Trust government solutions with the first Zero Trust Architecture and SASE platform offered end to end at FedRAMP Moderate and High baseline. Zscaler for Users helps agencies achieve the target goals of the Executive Order 14028 and resulting OMB mandates as well as CISA guidance and directives, supporting the CISA approved Branch Office, Remote User, and Cloud use cases. Zscaler offers the most accredited cloud security platform in the world, serving over 400 public sector customers including 12 of the 15 cabinet-level agencies.

    Superior cyber protection: Apply zero trust principles and AI-powered cyberthreat and data loss prevention services with the world's most comprehensive cyber threat protection solution to eliminate the attack surface, prevent compromise, halt lateral movement, and stop data loss.

    Powerful data protection: Prevent data loss from users, SaaS apps, and public cloud infrastructure due to accidental exposure, theft, or ransomware.

    Third-party Agentless Access: Secure, direct connectivity from authorized users to named applications without putting third parties on the network. With integrated agentless access, users can access applications from any browser, on any device, without the need to install a client or log into a VPN.

    Secure Cloud-Based Hybrid: Migrate to a cloud-first, cloud-secure Trusted Internet Connections (TIC) 3.0 zero-trust architecture that can accelerate cloud migration, enhance user productivity, and improve support for cloud applications.

    Lower cost and complexity: Eliminate legacy security and networking technology costs, including firewalls, VPNs, and the additional overhead that comes with keeping them up to date.

    Enhanced user experience: The hybrid workforce has increased ticket resolution time by over 30%. Zscaler can detect issues that impact user experience, reduce mean time to resolution, and keep employee productivity high no matter where they are with integrated views of application, network, and device health as well as the audio, video, and sharing quality of Microsoft Teams and Zoom calls.

    Agencies requiring verification of public pricing for Zscaler services can do so at the following:

    GSA Advantage (GS-35F-0119Y) - https://www.gsaadvantage.gov/advantage/ws/search/advantage_search?q=0:8Zscaler&db=0&searchType=0 

    Highlights

    • Zscaler Internet Access (ZIA) includes a comprehensive suite of AI-powered security and data protection services to help protect against advanced cyberattacks and data loss. As a fully cloud-delivered SaaS solution, you can add new capabilities without any additional hardware or lengthy deployment cycles. ZIA is FedRAMP Moderate, FedRAMP High and StateRAMP Authorized.
    • Zscaler Private Access (ZPA) applies the principles of least privilege to give users secure, direct connectivity to private applications running on-prem or in the public cloud while eliminating unauthorized access and lateral movement. As a cloud-native service, ZPA can be deployed in a matter of hours to replace legacy VPNs and remote access solutions. ZPA is FedRAMP Moderate, FedRAMP JAB High and StateRAMP Authorized as well as P-ATO at IL5.
    • Zscaler Digital Experience (ZDX) helps IT teams monitor digital experiences from the end user perspective to optimize performance and rapidly fix application, network, and device issues. ZDX increases the agility and collaboration among desktop, security, network, and helpdesk teams while triaging and resolving user experience issues. ZDX is FedRAMP Moderate, FedRAMP High and StateRAMP Authorized. Support information

    Details

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Zscaler U.S. Government Solutions, Zscaler for Users, FedRAMP Authorized

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    36-month contract (4)

     Info
    Dimension
    Description
    Cost/36 months
    ZS-USER-BUSINESS-EDITION
    Zscaler for Users Business Edition - 50 User Minimum
    $44,895.00
    ZIA-TFORM-EDITION
    Zscaler Internet Access Transformation Edition - 50 User Minimum
    $31,320.00
    ZPA-TFORM-EDITION
    Zscaler Private Access Transformation Edition - 500 User Minimum
    $448,950.00
    ZDX-ADVANCED-EDITION
    Zscaler Digital Experience Advanced Edition - 500 User Minimum
    $149,700.00

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Network Infrastructure, Infrastructure as Code
    Top
    10
    In Continuous Integration and Continuous Delivery, Network Infrastructure, Security

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    2 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    20 reviews
    Insufficient data
    Insufficient data
    34 reviews
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Zero Trust Architecture
    Cloud-native security platform implementing zero trust principles with least-privileged access based on user identity and contextual factors
    Threat Prevention
    AI-powered cyberthreat protection solution that eliminates attack surface, prevents compromise, and stops lateral movement
    Agentless Application Access
    Secure direct connectivity to applications from any browser and device without client installation or VPN requirements
    Cloud Security Compliance
    FedRAMP Moderate, High, and StateRAMP authorized platform supporting government cybersecurity mandates and directives
    Digital Experience Monitoring
    Integrated monitoring of application, network, and device health with performance optimization and issue resolution capabilities
    Network Protocol
    "Programmable networking software built on the WireGuard protocol for secure connectivity"
    Identity-Based Access Control
    "Network access control based on user identity, groups, services, and subnet ranges"
    Connection Management
    "Automatic network connection migration and direct device connections without manual port forwarding configuration"
    Infrastructure Compatibility
    "Cloud and hardware-agnostic overlay network deployment across multiple operating systems and platforms"
    DNS Resolution
    "Automatic hostname resolution with MagicDNS for simplified device and resource access without IP address management"
    Zero Trust Network Access
    Direct-routed, software-defined perimeter model securing user-to-resource and resource-to-resource connections
    Network Segmentation
    One-to-one encrypted network segment for each user with explicitly granted resource access
    Dynamic Access Control
    Entitlements that change dynamically based on user, device, and system context like AWS tags
    Multi-Environment Connectivity
    Cloud-native, API-enabled solution supporting multi-cloud, on-premises, and legacy application connections
    Authentication Architecture
    Supports access from managed and unmanaged devices across different locations with consistent security model

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.3
    2 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    100%
    0%
    0%
    0%
    2 AWS reviews
    |
    39 external reviews
    Star ratings include only reviews from verified AWS customers. External reviews can also include a star rating, but star ratings from external reviews are not averaged in with the AWS customer star ratings.
    TarunKumar5

    Elevating security with cost-effective features and robust integration

    Reviewed on Jul 29, 2025
    Review from a verified AWS customer
    ">

    What is our primary use case?

    In terms of our main use cases, the Zscaler Zero Trust Exchange Platform  was typically introduced to replace our traditional VPN methods, and Zscaler Internet Access  was used for secure internet access for all users.

    What is most valuable?

    The platform offers advanced threat protection features and embedded AI/ML capabilities, making it more proactive in blocking threats. We can create different types of controls such as access controls, file type controls, and cloud app controls to manage user access.

    The solution is beneficial for remote work environments by providing extra security features that VDI  cannot provide.

    Data loss prevention features are available, particularly network data loss prevention. We can create various regex and other rules in Zscaler DLP .

    The platform saves workforce hours and integrates with various tools and technologies, which has increased our security posture. We can integrate with SIEM , our AV platform, XDR , and EDR.

    What needs improvement?

    There are connection errors sometimes when users move from one location to another location, which can cause latency issues.

    Regarding the initial setup and deployment, there should be an export option from older tools to the Zscaler Zero Trust Exchange Platform. This export function would eliminate the need to start from basics. Some rules should be exportable and directly importable to the platform. Additionally, more automation efforts could be included.

    For how long have I used the solution?

    I have been working with the Zscaler Zero Trust Exchange Platform for more than four years.

    What was my experience with deployment of the solution?

    The implementation process is moderate but overall manageable.

    Which solution did I use previously and why did I switch?

    Netskope  is a similar tool to the Zscaler Zero Trust Exchange Platform. Both are similar tools, but the Zscaler Zero Trust Exchange Platform proved to be better. The Zscaler Zero Trust Exchange Platform has global coverage and low latency regarding support, and it provides a robust Zero Trust architecture. Netskope  provides flexible pricing and has granular visibility, and it surpasses the Zscaler Zero Trust Exchange Platform in cloud security capabilities.

    What about the implementation team?

    The implementation takes approximately six months to complete.

    What was our ROI?

    The platform is cost-effective regarding overall benefits. We don't have to purchase many components such as load balancers and proxy servers that were necessary in traditional setups. Being a cloud platform, many aspects are managed by the cloud, making it more beneficial.

    What other advice do I have?

    The Zscaler Zero Trust Exchange Platform is the industry's first zero-trust SaaS built on an AI platform. The platform deserves a rating of 9 out of 10 due to its extensive features and ease of administration.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Sumit Bhanwala

    Cloud-based platform simplifies device and data center management

    Reviewed on Jan 23, 2025
    Review provided by PeerSpot
    ">

    What is our primary use case?

    We are not resellers. We are utilizing it. We come from consulting firms, providing it to customers along with services, operational support, implementation support, and more. It involves various users in our organization.

    What is most valuable?

    I find it to be good. The solution is cloud-based with the latest inspection engines, which I find to be amazing. We are less dependent on data centers and device management, which reduces our efforts significantly. 

    It improves our device management, data center management, and updating devices. We need fewer engineers for this management, and it reduces time and efforts for data center management, device upgrades, and IT support.

    What needs improvement?

    There is not much room for improvement. We are users and operational engineers, so we might not have the insight that solution providers have when they compare different solutions. They might be able to identify if something is missing with Zscaler.

    For how long have I used the solution?

    I have been using it for three years now.

    What do I think about the stability of the solution?

    I would rate its stability as a ten out of ten. It is very high, and it is good.

    What do I think about the scalability of the solution?

    It is instant and very flexible according to requirements.

    How are customer service and support?

    Customer service is good, you could say. I would rate it a nine out of ten. Sometimes, support takes time since the solution has some bugs that need fixing.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    We did not evaluate other options before choosing Zscaler. It was proposed, and we used it.

    How was the initial setup?

    The initial setup is easy and user-friendly, engineer-friendly, and environment-friendly.

    What about the implementation team?

    There is nothing announced. It is a third-party issue.

    What was our ROI?

    The ROI is good.

    Which other solutions did I evaluate?

    We did not evaluate other options; this was proposed, and we used it.

    What other advice do I have?

    I recommend the solution. It's amazing. I would rate it a nine out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    DeepakBhaskaran

    Enhanced remote access with advanced web filtering and user-based control

    Reviewed on Oct 02, 2024
    Review provided by PeerSpot
    ">

    What is our primary use case?

    We primarily use Zscaler SASE  as a web filter to have secure internet connectivity for all our endpoints, users, and branch offices. The agent installed on all endpoints controls individual internet access, ensuring that only approved sites and applications are available for end users. It also blocks access to any website identified as a threat or security-compromised. Additionally, it is used to enable zero trust network configuration, allowing users from their homes to connect to Zscaler Zero Trust network using Zscaler private access component.

    How has it helped my organization?

    Zscaler has positively impacted our organization by providing a seamless configuration for remote access needs. Our employees are satisfied with the accessibility, as it eliminates the need for a VPN, allowing users to access required resources from anywhere seamlessly. This enhances user experience significantly.

    What is most valuable?

    The most valuable features of Zscaler SASE  include web filtering, application control, and the private access configuration. The private access configuration is particularly valuable as it allows user-based access control, limiting access to only what is needed for specific users and applications.

    What needs improvement?

    The connectivity monitoring part should be included in the core license without any extra charges. As a user, I should be able to see how seamlessly end users are connecting, but currently, this feature is an add-on that requires an additional license fee.

    For how long have I used the solution?

    I have been working with Zscaler SASE  for approximately over a year now.

    What do I think about the stability of the solution?

    The stability of Zscaler SASE  has been rated an eight out of ten. There have been issues with some of the edge networks where users were unable to access the internet, which is why it's not rated higher.

    What do I think about the scalability of the solution?

    The scalability of Zscaler SASE is rated a ten. As an agile cloud solution, it is easily scalable by adding licenses. However, since we are not a company that frequently adds a lot of users, scalability is not a primary concern for us at this point.

    How are customer service and support?

    Customer service and support have been excellent. We typically raise a call via email or using a portal, and the support we receive is very seamless and timely within the SLA. They have been very supportive and provided the necessary solutions and clarifications.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    Before Zscaler, we evaluated other solutions such as Netskope . We chose Zscaler due to its stability and the product roadmap, which were far better.

    How was the initial setup?

    The initial setup was somewhat complex due to the need to review and tweak the network configuration, particularly for legacy networks. However, these challenges were resolved through collaboration with multiple vendors and internal teams.

    What about the implementation team?

    For deployment, vendor support included two or three resources. Internally, we had one person handle the deployment via Microsoft Intune , and additional internal team members assisted with testing and rolling out to around 2,300 users. In total, there were three people from the vendor and three from our side, although the internal resources were not dedicated full-time.

    What's my experience with pricing, setup cost, and licensing?

    The pricing of Zscaler SASE is quite high, rated at nine out of ten.

    Which other solutions did I evaluate?

    We considered Netskope  before deciding on Zscaler.

    What other advice do I have?

    I'd rate the solution nine out of ten.

    Which deployment model are you using for this solution?

    Public Cloud
    reviewer2170611

    Offers an in-line DLP and policy copying features along with impressive stability

    Reviewed on Jun 05, 2024
    Review provided by PeerSpot
    ">

    What is our primary use case?

    In Qatar industries, the legacy systems like the Bluecoat Proxy is still being used, these solutions work at a limited capacity. For instance, one of our organization's customers is in the Oil & Gas transportation business with tankers, if a company like them wants to deploy a proxy solution, physical proxy deploy is very complicated for such companies, therefore our organization proposes a cloud proxy solution to them like Zscaler DLP. 

    There are several cloud proxy solutions in the market, but Zscaler DLP provides the lowest latency rates due to the presence of global enforcement nodes in the solution. Whenever a potential customer approaches our company, which has a large workforce, has offices distributed across a wide geography and is in need of a cloud-based solution, we suggest Zscaler DLP for comprehensive global control. 

    What is most valuable?

    The in-line DLP feature is one of the most vital features of the solution. Data security is a global concern, like in Europe there is the EDPR, while Qatar has its own data protection laws, so at our organization while data gets classified using different tools like Boldon James, security control in transit remains a concern so the in-line DLP policy is a valuable feature in Zscaler DLP that remains absent in most other products. Zscaler DLP takes care of the security when data is in motion. 

    What needs improvement?

    The technical team in our company suggests there are some performance issues with the solution once the module addition begins. For instance, suppose I am using Zscaler Internet Access, and the connectivity speed is excellent, but the moment I start integrating some add-ons like DLP, then the solution considerably slows down in functionality.

    But I believe the aforementioned instance or scenario is acceptable because an initial data check gets performed upon integration and it probably can be solved by the vendor through some alterations in the architecture. The set of features provided by Zscaler DLP is enough for the market in which our company operates. 

    For how long have I used the solution?

    I have been using Zscaler DLP for two and a half years. 

    What do I think about the stability of the solution?

    I would rate the stability an eight out of ten. It's a highly stable solution. The product consistently functions all the time, but it slows down a couple of times when a large-scale data transfer is being processed that involves multiple policy checks. 

    Zscaler DLP almost never crashes, and when it does rarely, it's very specific to the customer environment. When some changes are made to the deployed product upon the customer's suggestion, initially, some instability arrives, which is then fixed through fine-tuning. 

    What do I think about the scalability of the solution?

    I would rate the scalability an eight out of ten. The Zscaler DLP is extremely scalable and we have experienced it hands-on in our organization. One of the customers of our company was beginning operations in the Philippines, and they were already using Zscaler DLP in other locations like Kuwait and Jordan; they asked us to increase the license numbers and deploy the same Zscaler DLP solution for their Philippines location as well, the entire process was smoothly completed by our team.

    I believe the downscaling of the solution is as easy as upscaling. Around 80 to 90 customers of our organization are using Zscaler DLP. The customer portfolio of our company for Zscaler DLP comprises 20% government enterprises, 60% are medium-scale businesses, and the rest are small-scale businesses. 

    How are customer service and support?

    The customer support team has been responsive enough to our organization's queries in Qatar. In our company, we had to reach out for customer support on very few occasions. I would rate the tech support an eight out of ten. 

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    I would rate the initial setup an eight out of ten. Our organization implements the setup operations and transitions of Zscaler DLP for each customer. Rarely the deployment team of our company has faced some challenges, but it has been due to the unique customer environments, server placements and connection requirements.

    About 95% of the deployments have been carried out in our organization without any obstacles. Our organization always deploys Zscaler DLP on the cloud. 

    What's my experience with pricing, setup cost, and licensing?

    It's an affordable solution. I would rate the pricing a six out of ten. Once after deployment, you start bundling up additional components, the cost significantly increases. When compared to the cost of a competitor solution and the quality of Zscaler DLP, the price of the solution is justified.

    Some customers who are familiar with other product environments of Palo Alto or Cisco might find Zscaler DLP a bit expensive when looking at it from an environment compatibility or opportunity perspective. 

    What other advice do I have?

    For companies that have operations across the globe, it's crucial for them to have the same set of data security controls and measures across all locations; Zscaler DLP helps in such implementations. For instance, if there are certain enforcement policies or data security norms implemented for the headquarters of an organization, Zscaler DLP allows a professional to just copy the implemented policies of one location to another, irrespective of the site members or users.

    Overall, I would rate the solution an eight out of ten. I would advise others to perform due diligence before directly adopting the product, but just because the product is the market leader doesn't mean it will fit perfectly into every environment.

    I always analyze the customer's requirements and existing environment before proposing the best solution. If integrating Zscaler DLP into a Palo Alto environment will create difficulties, then it's better to choose a solution from Palo Alto. 

    Mohd Amir

    It provides security and is connected to manage the security level, which is good

    Reviewed on May 22, 2024
    Review provided by PeerSpot
    ">

    What is our primary use case?

    We are using Zscaler Zero Trust Exchange for its Zscaler Internet Access service. It provides web security, DLP, data protection, prevention, and lots more features.

    How has it helped my organization?

    It has improved our organization’s working process and efficiency.

    What is most valuable?

    It has some good data security and WIP features, providing secure Internet access. We get seamless access with our agents and users. It has some fantastic hardware. They have AI-powered integration with in-built features for the scheduler. It provides security and is connected to manage the security level, which is good.

    What needs improvement?

    The solution needs to improve a lot of aspects.

    For how long have I used the solution?

    I have been using Zscaler Zero Trust Exchange for more than one year.

    How are customer service and support?

    I don’t contact the support, but my team usually does.

    Which solution did I use previously and why did I switch?

    Previously, I used Citrix.

    How was the initial setup?

    The initial setup was straightforward. It took almost three months to deploy, but it was smooth.

    What other advice do I have?

    Overall, I rate the solution a nine out of ten. 

    View all reviews