Cloud Security Alliance Publishes Zero Trust Guidance as ZTNA Market Hits $20.7B
CSA released vendor-neutral zero trust program management and microsegmentation guidance in September 2026, giving buyers a framework to unbundle platform purchases from discrete workstreams.
CSA guidance creates vendor-neutral evaluation standard
The Cloud Security Alliance published separate guidance documents on Zero Trust Program Management (Sept. 10) and Zero Trust Microsegmentation (Sept. 9, 2026), giving enterprise buyers a vendor-neutral reference against proprietary methodologies from Microsoft, Cisco, Palo Alto Networks, Zscaler, Netskope, and Fortinet. The guidance lets procurement teams separate a broad "zero trust platform" purchase into discrete workstreams: identity modernization, workload segmentation, endpoint posture, and policy operations.
The impact is structural rather than technical. Buyers can now shift budgets toward architecture, integration, and professional services rather than consolidating spend into a single product license. The documents do not include implementation costs, performance benchmarks, or adoption figures, but they provide a framework for evaluating identity, segmentation, policy enforcement, and operational ownership without vendor lock-in assumptions.
ZTNA market forecast reaches $20.71 billion
A market forecast dated Sept. 16 puts the zero trust network access market at $20.71 billion, supporting the treatment of ZTNA as a material infrastructure category rather than a niche VPN replacement. The forecast does not disclose the target year, methodology, base-year revenue, or regional breakdown, limiting its value as a budget benchmark. The figure likely includes revenue across Zscaler Private Access, Cloudflare Access, Palo Alto Networks Prisma Access, Netskope Private Access, Cisco Secure Access, Fortinet FortiSASE, Twingate, and Akamai Enterprise Application Access.
Buyers should avoid using this figure alone to set budgets. The lack of disclosed methodology means the forecast may include adjacent SASE, identity, consulting, or hardware revenue. It does confirm continued competition between standalone ZTNA products and broader SSE/SASE suites, which matters for vendors positioning product roadmaps and for buyers deciding whether to consolidate or separate access control from other security functions.
Pricing benchmarks show five-fold variance by deployment scope
Estimated zero trust costs range from $35–$80 per user per month for 100-user organizations to $50–$150 for deployments above 10,000 users. Cloudflare's Zero Trust bundle—covering ZTNA, secure web gateway, CASB, and DLP—costs approximately $40–$60 per seat annually for 500–2,000 seats. Standalone ZTNA products such as Twingate are listed around $5 per user per month, while Cloudflare One sits at $7–$12 per user per month for applicable tiers. Zscaler and similar enterprise products use negotiated contracts rather than public list pricing.
The variance matters because a low-cost ZTNA overlay is not financially equivalent to an SSE/SASE bundle that includes DLP, CASB, secure web access, digital experience monitoring, and policy analytics. Buyers comparing vendor proposals should separate base access control costs from feature-set expansion costs and confirm whether published per-user pricing includes professional services, policy tuning, or architecture work.
Genians launches security platform combining NAC and security operations
Genians announced the Genians Security Platform at GISEC Global 2026 (Sept. 16–18, Dubai), positioning it as part of a "Pinpoint Security Operations" approach. The platform combines the company's network access control capabilities with broader security operations functions. The announcement does not include pricing, customer counts, deployment scale, detection performance metrics, or contract values.
Genians competes with Cisco Identity Services Engine, Fortinet FortiNAC, HPE Aruba ClearPass, Forescout, and Microsoft Defender-related access controls. Combining NAC with security operations could appeal to organizations managing device identity, access decisions, and incident response in a single console rather than across separate tools. Buyers evaluating zero trust access for unmanaged devices, operational technology, or sovereign cloud environments should add Genians to NAC and network visibility evaluations, but the absence of published pricing or customer evidence makes cost savings claims impossible to verify.
Fortinet ZTNA vulnerability increases architecture scrutiny
A high-severity vulnerability in FortiOS and FortiProxy's agentless ZTNA portal could allow an unauthenticated remote attacker to intercept traffic between the ZTNA portal and a backend destination through a man-in-the-middle attack. The disclosure does not include a CVSS score in available reports. The issue increases the importance of comparing certificate validation, portal isolation, patching processes, and agentless access architecture across Fortinet, Zscaler, Palo Alto Networks, Cloudflare, Cisco, and Netskope.
Buyers should confirm whether evaluated ZTNA products separate portal functions from policy enforcement, how certificate validation is handled in agentless deployments, and what the vendor's patching timeline looks like for high-severity access control flaws. The Fortinet issue is not a category-wide problem, but it shows why agentless access architecture requires the same scrutiny as agent-based deployments.
What to watch
The CSA guidance creates a decision point: buyers can now evaluate zero trust implementations against a vendor-neutral framework rather than accepting a vendor's product roadmap as the definition of zero trust. That shifts negotiating leverage toward buyers who can articulate specific workstream requirements and away from vendors selling "zero trust platforms" without clear scope boundaries. The ZTNA market forecast supports continued product investment from incumbent vendors but does not clarify whether consolidation or specialization will dominate the next 12 months. Buyers should track whether vendors price ZTNA as a standalone module or require bundling with SSE/SASE features that may not be needed.
Technology decisions, clearly explained.
Weekly analysis of the tools, platforms, and strategies that matter to B2B technology buyers. No fluff, no vendor spin.
