Zero Trust Edge (ZTE) describes one way to secure how people and offices reach applications: access is checked against who the user is and the state of their device, and those checks happen near the user, typically in a provider’s cloud, instead of after traffic has been hauled back to a head-office firewall. In practice that means buying network connectivity and zero trust access controls together, largely as a cloud service. The term was coined by the analyst firm Forrester, and it covers much the same ground as Gartner’s secure access service edge (SASE), with a different emphasis.
At a glance
- ZTE is an analyst-coined architecture label from Forrester, not a product standard.
- It combines network connectivity, such as SD-WAN, with cloud-delivered security, such as zero trust network access and secure web gateway.
- The framing starts from zero trust: connections are checked by identity and context, not network location.
- Vendors often market the same platform as ZTE, SASE or both.
- Many organizations start with remote-access replacement and extend to branch sites over time.
What problem it solves
Traditional network security assumed users sat in offices behind a firewall and applications sat in a data center. Remote work and cloud applications broke that model. Sending remote and branch traffic back through a central data center or VPN concentrator to be inspected adds delay, creates bottlenecks and treats anyone on the network as trusted.
ZTE addresses this by moving security to the edge, close to users and sites, and by basing access on who the user is and the state of their device rather than which network they are on. It also aims to reduce the number of separate boxes and consoles: instead of a VPN, a branch firewall, a web proxy and a router at each location, many functions are delivered as cloud services with one policy.
How it works
Connectivity. Branch sites connect to the internet and to each other, often with SD-WAN, and send traffic to nearby cloud points of presence. Remote users run an agent, or use a browser-based option, that connects to the same service.
Zero trust access. Access to private applications is granted per application, based on identity, device posture and other context, typically through zero trust network access (ZTNA), rather than by placing users on the network.
Cloud-delivered security. Internet and cloud traffic passes through security services such as secure web gateway, cloud access security broker, data loss prevention and firewall as a service (FWaaS). This security stack on its own is often called security service edge (SSE).
Central policy. Administrators set access and security rules once and apply them to users and sites wherever they connect, with shared logging and reporting. How unified that policy and console really are varies a lot between vendors.
When it matters for buyers
- When replacing remote-access VPN. ZTE vendors usually start with ZTNA as the first step.
- When branch firewalls or routers reach end of life. It is a chance to consider cloud-delivered security instead of like-for-like replacement.
- When reading analyst reports and vendor marketing. Knowing that ZTE and SASE are overlapping labels from different firms avoids comparing the wrong things.
- When adopting a wider zero trust program. ZTE covers the network and access part of zero trust security, not identity, data or workload protection on their own.
- When consolidating vendors. Single-vendor and multi-vendor designs have different trade-offs in cost, flexibility and integration.
Questions to ask vendors
- Which services are included: ZTNA, secure web gateway, CASB, DLP, firewalling, SD-WAN? Which cost extra?
- Is everything managed from one console with one policy model, or several products linked together?
- Where are your points of presence, and how will our users’ traffic be routed to them?
- Which applications and protocols does your ZTNA support, and which would still need a VPN?
- Can we start with remote users and add branch sites later without re-platforming?
- What happens to traffic if your cloud service or a point of presence is unavailable?
Our secure access service edge advisors help buyers compare platforms whether vendors call them SASE or ZTE.
How it differs from SASE
Secure access service edge (SASE) is Gartner’s term; Zero Trust Edge is Forrester’s. Both describe combining networking and security services delivered mostly from the cloud, and the vendor lists for each overlap heavily. The difference is mainly in framing: SASE is usually described as the convergence of wide area networking and network security services, while ZTE puts zero trust access at the center and treats it as the organizing principle. Forrester has also described ZTE as a path that can begin with remote access before extending to sites. For a buyer, the label matters less than the services, coverage, policy model and performance a given platform delivers. Forrester’s broader zero trust model, Zero Trust eXtended (ZTX), covers far more than the network edge.
