Independent reference. Not affiliated with any zero trust vendor. Updated Q1 2026.
ZeroTrustCost
ZTNA pricing

ZTNA cost - zero trust network access pricing and VPN migration

Zero Trust Network Access (ZTNA) is the network-pillar control most organisations buy first. This page covers ZTNA pricing tiers, VPN-to-ZTNA break-even analysis, the migration cost most CISOs underestimate, hidden deployment costs, and how SASE bundle economics change the calculus.

Pricing structure

What ZTNA actually costs

Three tiers cover most of the market. Tier-1 (lightweight ZTNA-only) is the cheapest and fastest to deploy. Tier-3 (full SSE) is the most comprehensive and most expensive. Tier-2 (ZTNA-plus) sits in the middle.

TierPer user / monthWhat it includesBest for
Tier 1 - Lightweight ZTNA$5 - $10Identity-based application access. Simple connectors. SaaS and private app coverage.SMBs, developer-centric organisations, VPN replacement only.
Tier 2 - ZTNA Plus$10 - $18ZTNA + DNS filtering + basic SWG. Some include CASB-lite.Mid-market without separate SWG. Tier where bundle value starts to bite.
Tier 3 - Full SSE / SASE$15 - $25ZTNA + SWG + CASB + FWaaS + DLP integration. Often called Secure Service Edge or full SASE.Enterprises replacing complex on-premise proxy infrastructure.
Free / freemium$0 (capped)Limited ZTNA seats. Often DNS filtering free, ZTNA capped at 50 users.Pilots, very small businesses, evaluation.

Tier ranges aggregate published list pricing across 12+ ZTNA platforms. Negotiated enterprise pricing typically runs 20-35% below list at high seat counts. For specific quotes, contact vendors directly.

VPN comparison

ZTNA vs VPN total cost

Comparing 3-year total cost for a 250-user organisation. ZTNA is more expensive in year 1 (no hardware sunk cost to amortise) but cheaper in years 2 and 3 with no maintenance and no hardware refresh.

Cost lineTraditional VPN (250 users)Cloud ZTNA (250 users)
Hardware (year 1)$30K - $60K$0
Implementation services$15K - $35K$25K - $60K
Year 1 licensing$12K - $25K$24K - $45K
Year 2 licensing + maintenance$18K - $35K$24K - $45K
Year 3 licensing + maintenance$18K - $35K$24K - $45K
Hardware refresh year 4-5$30K - $60K (looming)$0
3-year total$93K - $190K$97K - $195K

At 250 users, 3-year total cost is roughly comparable. The difference becomes material when (a) the VPN faces a hardware refresh in year 4-5, (b) the organisation is growing and would need additional VPN appliances, or (c) the organisation has multiple geographic regions requiring separate VPN concentrators. ZTNA scales linearly with users; VPN scales in steps with hardware.

Migration cost

The hidden VPN-to-ZTNA migration cost

Beyond ongoing licensing, migration is a discrete project with its own budget. Most organisations underestimate it by 30-50%.

Connector deployment. Most ZTNA platforms require software connectors deployed in every private application environment. For a typical mid-market estate with 4-8 distinct private environments (on-premise data centre, two AWS regions, one Azure subscription, three on-premise office locations), connector deployment is 32-128 hours of professional services labour at $200-$400/hour. Budget: $8K-$50K.

Policy migration. VPN policies are typically IP-based, allow-list source IPs to destination subnets. ZTNA policies are identity-based, allow-list user groups to specific applications. The translation is non-trivial. For a typical mid-market estate with 50-200 VPN policies, policy migration is 80-200 hours of professional services labour. Budget: $15K-$60K.

Parallel running. Run VPN and ZTNA in parallel for 60-180 days. Both licences active. Users transition gradually, business-critical apps last. Skipping parallel running is the most common cause of migration failure and typically more expensive than running the parallel because rollback under pressure is more costly.

Training and change management. ZTNA UX differs from VPN. Users accustomed to a full-tunnel VPN experience may not understand why some apps appear and others don't. Document the transition, provide a migration FAQ, run office-hours sessions during the cutover. Budget: $50-$150 per employee in training time.

Monitoring and alerting overhead. ZTNA generates significantly more telemetry than VPN. Plan to integrate ZTNA logs into the SIEM and tune alerts. First-month alert volume is typically 5-10x what the SOC expects.

Bundle economics

ZTNA-only vs SASE - which is cheaper?

ZTNA-only platforms are dramatically cheaper than full SASE if you only need ZTNA. SASE wins when you genuinely need the bundled capabilities and do not have them already.

ScenarioZTNA-only platform (annual)Full SASE platform (annual)Best fit
500 users, ZTNA-only need$48K - $72K$108K - $156KZTNA-only
500 users, ZTNA + SWG need$48K + $30K SWG = $78K$108K - $156K (bundle)Tier 2 ZTNA-Plus
500 users, ZTNA + SWG + CASB + FWaaS$48K + ~$120K bundled$108K - $156K (bundle)Full SASE
2,000 users, full SSE need$192K + ~$480K bundled$432K - $612K (bundle)Full SASE

The economics flip as you genuinely need more components. Buy ZTNA-only if ZTNA is all you need. Buy SASE if you need three or more of the bundled components and would otherwise buy them separately.

Frequently asked

ZTNA cost questions

What does ZTNA cost per user?
Per-user ZTNA pricing ranges from $5-$20 per user per month depending on tier and bundle. Lightweight ZTNA-only platforms (cloud-native, focused on app access) sit at the lower end ($5-$10/user/month). Full SSE platforms that bundle ZTNA with secure web gateway, CASB, and DNS filtering sit at the higher end ($15-$25/user/month). Free or near-free tiers exist for small workforces (Cloudflare Zero Trust free up to 50 users; some vendors offer 7-day trials of paid tiers). Add a 1.4-1.8x implementation multiplier to year-one licensing for professional services and connector deployment.
Is ZTNA cheaper than VPN?
Over a 3-year horizon, yes for most organisations. Traditional VPN appliances cost $15K-$100K upfront in hardware plus $5K-$30K/year in maintenance and licensing. Cloud ZTNA is $0 hardware and $60-$240 per user per year in licensing. For a 100-user organisation on a typical Cisco AnyConnect or Palo Alto GlobalProtect VPN setup, ZTNA break-even is typically 18-24 months. The crossover is faster for organisations that would otherwise face a hardware refresh cycle and slower for organisations with low remote-access usage.
What is the ZTNA migration cost from VPN?
Beyond ongoing licensing: $20K-$80K in professional services for mid-market migrations, plus a 60-180 day parallel-running period where both VPN and ZTNA licences are active. Migration involves connector deployment in every private application environment (Active Directory, file servers, internal SaaS, line-of-business apps), policy migration from IP-based VPN rules to identity-based ZTNA rules, and end-user training on the ZTNA client. Skipping the parallel-running period is the most common cause of migration failure and typically more expensive than running the parallel.
What is SASE and is it worth the premium over ZTNA?
Secure Access Service Edge bundles ZTNA with secure web gateway (SWG), CASB, FWaaS, and DNS filtering into a single platform at $15-$25/user/month. SASE is worth the premium if you genuinely need all the bundled capabilities and do not have them already, the integration value across all five components is real. SASE is over-spend if you only need ZTNA and have a separate, working SWG / CASB, the marginal SASE cost over a focused ZTNA platform is typically 2-4x. Audit existing tooling before signing a SASE deal.
Do we still need an identity provider with ZTNA?
Yes. ZTNA verifies user identity and device posture on every connection, but the identity itself comes from an external IdP (Microsoft Entra ID, Okta, Google, Ping, etc). ZTNA platforms federate to the IdP via SAML or OIDC. If you do not have an IdP in place, you will need to deploy one alongside the ZTNA rollout. For Microsoft 365 organisations, Entra ID is already deployed and ZTNA federation is straightforward. For organisations on Google Workspace, Google identity federates cleanly to most ZTNA platforms. Heterogeneous estates often need an identity-centric platform deployed first.
What is the hidden cost in ZTNA deployment?
Connector deployment. Most ZTNA platforms require a software connector (App Connector, Cloud Connector, Service Edge) deployed in each private application environment, on-premise data centres, AWS VPCs, Azure VNets, GCP projects. Each connector deployment is 4-16 hours of professional services work. For an organisation with 8 distinct private app environments, that is 32-128 hours of PS labour. Plan for it in the migration cost. Cloud-native organisations with all apps in SaaS need fewer connectors and benefit accordingly.