Zscaler alternatives for OT and on-premise networks
Zscaler is built to connect a distributed workforce to cloud applications. If your endpoints are PLCs and HMIs that will never run an agent, here is how the Zero Trust options actually compare, and where an in-path, on-premise approach fits.
A question of category fit, not a scoreboard
Zscaler is genuinely good at what it was built for: connecting a distributed workforce to cloud applications. Its model assumes an agent on the endpoint and a network path out to a cloud point of presence. For a fleet of laptops reaching SaaS, that is the right design, and nothing here argues otherwise.
A water treatment plant or a machine shop breaks both assumptions. The endpoint is a PLC or an HMI that will never run an agent, and it often sits on a segment with no route to the internet. Cloud-delivered Zero Trust has nothing to install on the device and nowhere to send the traffic. That is a category mismatch, not a product flaw.
So the useful comparison is not who is better. It is which model fits a plant floor. The table below is built from each vendor's own public documentation, and where a capability is not documented it says so rather than guessing.
How the Zero Trust options compare for industrial environments
Competitor cells are drawn from each vendor's public documentation, linked below. Where a capability is not publicly documented, the cell says so rather than assuming.
| Capability | Zscaler | Palo Alto Prisma Access | Netskope | Cloudflare Zero Trust | Trout Access Gate |
|---|---|---|---|---|---|
| Cloud dependency | Cloud service; on-prem data-plane option | Cloud-delivered SASE | Cloud (NewEdge) | Cloud only (global network) | None; on-premise and in-path |
| Agent required | Client Connector; clientless browser via PRA | GlobalProtect; clientless browser via PRA | Netskope client; clientless browser | WARP client; some clientless access | None; agent-free |
| Works with legacy PLC / HMI | Brokers clientless access to OT systems | Brokers OT and ICS remote access | Markets access to SCADA, PLCs, HMIs | Not documented for OT devices | Yes; the device is never touched |
| Functions air-gapped | No; needs the cloud control plane | No; cloud-delivered | No; needs the NewEdge cloud | No; needs Cloudflare's network | Yes; no cloud dependency |
| Typical deployment time | Not documented | Not documented | Not documented | Not documented | Hours; no rewiring, no downtime |
| Session recording and playback | Yes; PRA session recording | Yes; Browser PRA recording | Not documented; monitoring only | Command logging only; no replay | Yes; recorded and replayable |
| OT protocol awareness | RDP, SSH, VNC; no OT parsing documented | RDP, SSH, VNC; OT parsing lives in the NGFW, not the broker | RDP, SSH; OT discovery, not enforcement | TCP, HTTP, SSH; no OT parsing | Protocol-aware enforcement, including Modbus |
| Compliance mapping (CMMC L2 / NIS2 / NERC CIP) | NIS2 published; CMMC and NERC not documented | NIS2 and NERC referenced; CMMC not documented | NIS2 published; CMMC and NERC not documented | NIS2 and FedRAMP; CMMC and NERC not documented | CMMC L2, NIS2, and NERC CIP |
Sources: Zscaler · Palo Alto · Netskope · Cloudflare
The questions that decide it on a plant floor
Does enforcement stay on site?
Cloud-delivered Zero Trust routes the access decision through a vendor point of presence. In-path, on-premise enforcement keeps every decision and every packet inside the fence, which is what an isolated OT segment and a data-sovereignty mandate require.
Can it protect a device that will never run an agent?
A modern proxy terminates the session, authenticates the person, applies policy, records what happened, and forwards a clean request. The PLC or HMI never knows anything changed, and it never needs software installed on it.
Is the audit trail ready for an assessor?
Tamper-evident logs of who connected, to which device, and what they did are what a CMMC, NIS2, or NERC CIP assessor asks for. Generated at the enforcement point, not reconstructed after the fact.
This runs where agents cannot
Trout Access Gate secures defense manufacturers, research institutions, and critical-infrastructure operators: environments built on legacy PLCs, SCADA, and equipment that cannot take an agent. Among them are Thales, Millbrook Machine, Elna Magnetics, Irish Manufacturing Research, HUN-REN SZTAKI, and STBMA.
See customer storiesQuestions about Zscaler alternatives
Access Gate is an agent-free, on-premise Zero Trust appliance for IT and OT, built for the assets a cloud ZTNA cannot reach.
Not for what Zscaler does best. If your job is connecting a remote workforce to SaaS, Zscaler is a strong fit and Access Gate is not trying to be. Access Gate is for the other half of the problem: securing on-premise IT and OT assets, including PLCs and HMIs that cannot run an agent and often have no path to the cloud. Many sites run both.
Yes. Enforcement happens in-path on the network, not on the endpoint. A modern proxy terminates the session, authenticates identity, applies enclave policy, and records the session, then forwards a clean request to the device. A twenty-year-old PLC gets the same Zero Trust treatment as a modern workstation, with nothing installed on it.
Yes. Access Gate runs fully on-premise as a virtual machine on a host that owns the network path. There is no cloud control plane and no cloud point of presence to reach, so it keeps working on an isolated or air-gapped segment. Cloud-delivered Zero Trust services depend on reaching their provider's network.
It maps to the access-control, system-and-communications-protection, and audit families those frameworks assess: identity-bound access, segmentation, network-layer MFA, and tamper-evident logs generated at the enforcement point. Treat it as one documented control in a broader program, not a compliance box on its own.
Access Gate enforces policy over the protocols on the wire, not just the ports. For a protocol like Modbus that has no native authentication, a protocol-aware proxy can bind access to identity, restrict which function codes and registers a source may use, and record every transaction, without touching the controller.
Start from your endpoints. If they are laptops reaching SaaS, a cloud ZTNA such as Zscaler, Prisma Access, Netskope, or Cloudflare fits. If they are PLCs, HMIs, RTUs, or air-gapped servers, an in-path on-premise appliance such as Access Gate fits, because it needs no agent and no cloud. The table above shows where each one lands.
See whether Access Gate fits your plant
Thirty minutes with an engineer is usually enough to tell whether an in-path, agent-free approach fits your network, or whether a cloud ZTNA is the better call. We will tell you honestly either way.