You secured the remote path. The office kept its old assumptions — Most ZTNA secures remote users and leaves the office implicitly trusted — Cato applies one policy to both, with verification that continues through the session.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Universal ZTNA — access control. The rest of the platform:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
One access policy for every location — office, home and mobile alike, with continuous verification and entitlement to applications rather than admission to a network.
What consolidation actually replaces, dimension by dimension.
| Dimension | A VPN, or implicit network trust | Universal ZTNA (Cato) |
|---|---|---|
| The office | Implicitly trusted network | The same policy as everywhere else |
| The check | Once, at login | Continuously, through the session |
| What access means | A place on the network | Entitlement to one application |
| Contractors | A VPN account nobody revoked | One application, time-bounded |
| Investigating access | Correlate across three systems | One data lake with network context |
| What it is NOT | — | Not an application inventory — you build that |
Application segmentation needs an inventory of your applications and who needs each: that is the project, and no vendor can supply it. Also confirm whether SSE or ZTNA covers private app access in your quote.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
The same access rules whether a user is in an office, at home or on a phone. Most deployments secure the remote path and leave the office implicitly trusted, which is two policy models and a gap that attackers understand well.
Identity and device posture re-evaluated during a session rather than once at the door. A device that was compliant at login and is not twenty minutes later should not keep its access, and with one-time checks it does.
A user reaches the specific application they are entitled to rather than being placed on a network from which other things are reachable. This is what limits lateral movement, and it needs an application inventory to define.
ZTNA policy lives in the framework SD-WAN and SSE also read, so an access decision and the network context behind it sit together. It also means the private-access overlap with SSE is a scoping question.
One telemetry fabric across endpoint, cloud, and network — threats correlated once, not chased console to console.
Cato Universal ZTNA replaces implicit trust everywhere — continuous checks and the portfolio, and paired with the human firewall.
One rule set across user types and locations. Closing the office gap is the harder half, and the half most ZTNA projects quietly postpone into a phase that never arrives.
Posture and identity evaluated as the session runs, not only at login. A device that falls out of compliance mid-session loses access rather than keeping it until logout.
Entitlement to a specific application rather than admission to a network. This is the control that limits lateral movement when a credential is compromised.
Patch level, encryption, agent presence factored into the decision. Useful precisely to the degree your posture signals are accurate, which is worth verifying rather than assuming.
Granting a supplier access to one application without issuing network access. Often the clearest early win, because the alternative is usually a VPN account nobody revoked.
Session records in the same data lake as the network and security events, so an access question can be answered from one place rather than correlated across three.
Private access in practice, the modular platform, and agentic threats.
Private application access in practice.
How the modules deploy independently.
Why implicit trust ages badly.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Most ZTNA projects follow the same path: remote access is the visible problem, so remote users get zero trust, and the office keeps working the way it always did — on a network where being connected implies being trusted. That leaves two policy models and a seam between them, and the seam is precisely what an attacker who reaches any device inside the office gets to exploit. Closing it is the harder engineering problem, which is why it is usually deferred to a phase two that competes for funding with whatever became urgent. The word universal is doing real work in this product name, and the useful question in any evaluation is not whether a vendor supports zero trust for remote users — they all do — but what happens to the office.
A one-time login check asks whether this user, on this device, is allowed in right now — and then stops asking. Anything that changes afterwards is invisible until the session ends: a device that falls out of compliance, a credential used from a second location, posture that degrades mid-afternoon. Continuous verification re-evaluates during the session, so access can be withdrawn when the conditions that justified it stop holding. The practical value depends entirely on the quality of your posture signals: continuous evaluation of information that is wrong produces confident wrong decisions faster. Worth confirming what signals feed the decision and how current they are, rather than accepting continuous as a feature checkbox.
The control that limits blast radius is entitlement to a specific application rather than admission to a network — a compromised credential reaches one thing instead of everything reachable from a subnet. That is genuinely the right model, and it has a prerequisite most organisations underestimate: you must know what your applications are, who legitimately needs each, and how they are reached. Many enterprises do not have that inventory in usable form, and building it is the actual project. The software cannot supply it. Budget the discovery work honestly rather than treating it as configuration, because a segmentation programme against an incomplete inventory either blocks legitimate work or leaves the gaps it was bought to close.
Private application access appears in both this module and SSE, deliberately — they share a policy framework, so the capability is reachable from either direction. That is architecturally sensible and commercially confusing, and reviewers report nearly licensing the same capability twice. The question to put in scoping is simple and specific: which module in this quote covers private application access, and if we license both, what are we paying for that we would otherwise get once. A vendor should be able to answer that precisely. It is not a criticism of the product — overlapping modules are inevitable when a platform is broken into independently sellable parts — but it is exactly the kind of detail that a category-level quote obscures.
Where does implicit network trust still exist? For most organisations it is the office, and naming it is the start of the business case.
Contractor access is the clearest early win, and auditing existing VPN accounts usually produces an uncomfortable and persuasive list.
What the applications are, who needs each, how they are reached. This is the project; the software cannot supply it and it takes longer than expected.
Continuous verification of stale data produces confident wrong decisions faster. Check what feeds the decision and how current it is.
The harder half, and the reason universal is in the product name. Deferring it to a phase two is how the seam survives for years.
Applications change and people move roles. An entitlement model nobody reviews drifts back toward the flat access it replaced.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We had zero trust for remote users and an office that trusted anything plugged into it. Closing that seam was the whole reason we bought.”
“Contractor access without VPN accounts was the fastest win. We found VPN credentials for people who had finished projects two years earlier.”
“The application inventory was the project, not the software. Budget that honestly — nobody can hand it to you and it takes longer than you think.”
“Clarify whether SSE or ZTNA covers private app access before signing. We nearly paid for the same capability twice in one contract.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the zero trust access market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
One policy, office included.
The grid nobody publishes — coverage across every location vs how tightly access is scoped to an application.
Continuous, per application, everywhere.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against remote-only ZTNA, a VPN, and flat network trust — on whether the office is covered and what a credential reaches.
| Dimension | Cato Universal ZTNA | Remote-only ZTNA | VPN | Flat network trust |
|---|---|---|---|---|
| Covers the office | Yes — the point | No | No | No |
| Verification model | Continuous | Usually one-time | One-time | None |
| Blast radius | One application | Per app, remotely | The whole subnet | Everything |
| Third-party access | One app, bounded | Good | A VPN account | Worse |
| Prerequisite work | App inventory | App inventory | Little | None |
| Published pricing | Quote-only | Varies | Often bundled | Free |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Universal ZTNA is one of 20 sase & sse products TechBag carries. The SASE & SSE guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (users and contractors; IT-hour cost as a loaded rate). Estimates model VPN account administration and the blast radius of a credential that reaches a whole subnet. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote-only — no published price, typically per user. TechBag checks the SSE overlap and how contractor users are counted, then quotes in INR with GST.
Best when the office is still trusted
Best for a broader rollout
Best with SSE alongside
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Where does implicit network trust still exist in your estate? For most organisations it is the office, and that is the gap.
Do you know what your applications are and who needs each? Segmentation depends on it and the software cannot supply it.
What feeds the device posture decision, and how current is it? Continuous evaluation of stale data is worse than useless.
How many VPN accounts belong to contractors who finished? That audit is usually the most persuasive part of the case.
Does SSE or Universal ZTNA cover private application access in your quote? They overlap and can be paid for twice.
Is extending policy to the office funded, or deferred to a phase two? Deferral is how the seam survives for years.
Who reviews entitlements as people change roles? An unreviewed model drifts back toward flat access.
Is ZTNA priced per user, and how does it combine with SSE? There is no published figure to anchor against.
Audit your existing VPN accounts first — the contractors who finished years ago are usually the most persuasive part of the case — or let a TechBag advisor scope the application inventory work.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.