For a $500K–$2M Zero Trust program, the ZTNA license is only one budget line. Six major cost centers drive the real bill. They include identity repair, app integration, policy design, dual-run operations, support, and lost productivity. A credible three-year budget must price each cost by migration phase. Do not treat deployment as a one-time platform purchase.
Hidden Costs of Zero Trust Projects CTOs Miss: Zero Trust projects rarely exceed budget because of ZTNA licenses alone. The expensive surprises are identity cleanup, legacy-app integration, parallel VPN operations, policy redesign, support, and delayed productivity.
The costs that sit outside a ZTNA license quote
A ZTNA license is only one budget line. Total cost depends on identity quality, old apps, third-party access, endpoint health, and VPN overlap length.
Costs vendor quotes usually omit
Professional services can cost $150,000 to $600,000 for a mid-market company. This covers architecture, policy design, pilot tests, and app onboarding. The total changes with app count and identity maturity.
Budget separately for IAM, MFA, PAM, MDM, SIEM, EDR/XDR, SOC, and service-desk integrations. Each integration must report the right state, fail safely, and be tested when policies change.
These costs often appear after procurement rather than before it.
Drivers bigger than per-user pricing
Identity sprawl creates unreliable access policies. Orphaned accounts, excess privilege, and copied VPN groups make the problem worse.
Conditional Access should check identity, device posture, app, location, and current risk. It should not rely on network groups created years ago. A policy engine cannot make sound choices from stale accounts or broad rights.
Identity debt and old apps raise the real project cost
Identity debt and old app work often require more effort than the access gateway. Unclear roles, shared accounts, stale rights, and weak ownership block least-privilege access.
Price identity cleanup as real work
Start with user accounts, service identities, privileged accounts, groups, and app owners. Then remove duplicates, close orphaned accounts, and confirm access approvers.
A focused cleanup for one business unit may take 4 to 10 weeks. Broader IGA work can continue after the first migration wave. RBAC and ABAC are effective only when employee, device, and role data are accurate.
The most frequent mistake here is treating account cleanup as free work. It needs named owners, analyst time, and business decisions.
Identify apps that need a different answer
Older apps may depend on hard-coded IP addresses or shared passwords. They may also use LDAP queries, network file shares, unsupported browsers, or latency-sensitive protocols.
Such systems may need connectors, proxies, authentication upgrades, segmentation, or modernization. OT and manufacturing systems may not tolerate an extra access hop. Isolate them with strict vendor-access controls instead of forcing them into the first ZTNA wave.
Not every old app belongs in migration.
Build a 36-month TCO model before buying
A useful Total Cost of Ownership model forecasts one-time work and recurring OPEX. It also forecasts CAPEX, opportunity costs, and risk costs. Show these monthly or quarterly for 36 months.
Put each cost in the right bucket
| Cost type | Typical items | Budget treatment |
|---|
| One-time | Assessment, policy design, app testing, training | Fund by phase and track variance |
| Recurring OPEX | ZTNA, IAM, SIEM, SOC, support | Forecast for all 36 months |
| CAPEX | Network refresh, approved appliances | Depreciate under finance policy |
| Opportunity and risk | Engineer time, outage exposure, audit findings | Show assumptions and owners |
A cost is avoidable when a planned VPN shutdown or tool retirement ends it. It is unavoidable when identity, logging, or compliance requires it. It is postponable when safe isolation can delay app modernization.
Budget by operating complexity
For 1,000 to 5,000 users, a three-year program commonly costs $500,000 to $2 million. This includes identity work, integrations, migration, and operations.
A 1,000-user SaaS-heavy firm may spend $500,000 to $900,000. A 3,000-user hybrid organization may need $900,000 to $1.6 million. A distributed firm with OT, many sites, or weak identity records should reserve $1.4 million to $2 million or more.
36-month cost sequence:Months 1-3
Inventory, identity cleanup, architecture
Months 4-12
Pilots, integrations, priority apps
Months 13-24
Migration waves, VPN reduction
Months 25-36
Optimization, tool retirement, audit proof
A practical TCO model assigns costs to each migration phase. Do not place most of the budget in deployment.
Assessment costs include asset discovery, identity baselining, and app ownership checks. Design costs include access policy redesign and reference architecture. Implementation costs include professional services, IAM and MFA links, connectors, and testing.
Migration adds app onboarding costs and dual-run operations. Steady-state spending includes ZTNA licenses, telemetry retention, and security operations support.
For example, a 3,000-user hybrid organization may find license fees predictable. Remediation and migration labor can change sharply when app counts are poorly documented.
Dual VPN and ZTNA operations can erase savings
Running VPN and ZTNA together is sometimes needed. Each overlap month duplicates policy work, logging, incident response, troubleshooting, documentation, and support.
Users can fail on MFA, device posture, split tunneling, DNS, or app connectors. The service desk must identify the route used and the owner of the fix.
Support volume often rises during the first 30 to 90 days of a migration wave. Security teams must keep two rule sets and two log sources. Broad VPN access remains an exposure that ZTNA has not removed.
Dual-run time has a measurable operating cost.
A short dual run is justified for apps with protocol, latency, or authentication limits. It also fits acquisitions with third-party devices that cannot meet posture rules.
Every exception needs a business owner, target date, and stated delay cost. Count a user as migrated only after VPN rights are removed. Required apps must work through the approved path.
The financial comparison must include the security and operating effects of app-specific access. Do not compare only VPN hardware or subscription costs.
A legacy VPN user may reach dozens of internal subnets. That user may need only three business apps. Limiting access reduces lateral movement chances after an account or endpoint compromise.
ZTNA can cut firewall-rule work and remote-access troubleshooting. It can also reduce exposure from public services. These savings appear only when teams retire redundant VPN paths, appliances, and support processes.
In the 36-month model, show reduced perimeter-security complexity. Also show residual breach-risk cost while old access remains active.
Choose migrate, modernize, retire, or isolate per app
App criticality alone is a poor migration order. Each app needs a clear choice based on identity readiness, data sensitivity, dependencies, latency, repair cost, and business value.
Start with identity-ready applications
The best first wave includes valuable apps with clear owners. These apps support SSO and MFA, use managed endpoints, and have known access groups. They also offer a direct path to removing broad VPN access.
SaaS and hybrid-cloud apps let teams test Conditional Access and device posture checks. Teams can also test Single Sign-On and SIEM logging. This avoids forcing a large code change.
Starting with the oldest app can create user distrust. It can also stall executive support.
Use a decision matrix, not intuition
| App condition | Best action | Cost signal |
|---|
| SSO, MFA, owner, managed devices | Migrate | Low remediation, early VPN savings |
| High value, weak authentication, active owner | Modernize | Fund code and identity changes |
| Low usage, duplicate function, no owner | Retire | Avoid future license and support cost |
| OT, latency-sensitive, unsupported auth | Isolate | Contain risk while deferring change |
Measure value after each wave
Track cost per migrated app and cost per user removed from VPN. Track dual-run months, access blocks, and time to restore access. Also track orphaned accounts and reduced privileged accounts.
For board reports, link results to NIST Cybersecurity Framework outcomes. Use the CISA Zero Trust Maturity Model too. Use HIPAA, PCI DSS, SOC 2, and CMMC 2.0 as audit evidence where they apply.
This approach does not apply in the same way to a small startup. It may have few SaaS apps, one central identity system, and no legacy VPN. That company may start with SSO, MFA, device management, and basic access controls. Also, do not frame ZTNA as an isolated project when unmanaged identities or ownerless apps cause the real problem.
Before selecting migration waves, create an app inventory for every in-scope service. Record the business owner, user group, data sensitivity, and authentication method. Also record hosting location, network needs, protocol behavior, support status, and third-party access.
This inventory supports app rationalization. Teams can retire duplicate, low-use, or ownerless apps before they create integration work. It also prevents teams from copying broad VPN groups into new Conditional Access policies.
During policy redesign, translate former network membership into app rights. Test IAM and MFA links for each access path. This cuts rework, limits exceptions, and improves app onboarding forecasts.
Your questions answered
Is zero trust architecture expensive?
It can be expensive when teams ignore identity debt, old apps, and VPN overlap. For 1,000 to 5,000 users, a three-year program often ranges from $500,000 to $2 million. Integration and remediation needs set the final amount.
What costs more than ZTNA licenses?
Identity cleanup, app repair, professional services, support training, and parallel VPN operations often cost more than licenses. This is most likely when apps lack SSO, MFA, or a named owner.
How long should VPN and ZTNA run together?
Keep overlap as short as app testing allows. It often lasts between 3 and 12 months by migration wave. Any exception beyond one quarter needs a named owner and documented cost.
Should we migrate every legacy application?
No. Retire low-value apps and modernize valuable apps with fixable authentication. Isolate systems that cannot safely change now. Migration is only one of four valid choices.
What is the first zero trust budget line to add?
Add a separate identity remediation workstream before setting the ZTNA rollout date. Cover account cleanup, access reviews, role design, privileged accounts, and app ownership.
How do we prove financial value after launch?
Measure VPN users removed, tools retired, support tickets, access recovery time, and cost per migrated app. Compare each quarter with the approved 36-month TCO model. Do not compare results with enrollment alone.
Fund the foundation, then retire old access paths
Fund identity cleanup and app decisions before promising VPN savings. Then use measured migration waves to remove old access paths and recurring costs.
A CFO-ready approval test
Approve the first phase only when it names apps, owners, and one-time costs. It must also name recurring OPEX, expected VPN reductions, and exit dates. Without these items, the proposal is a platform purchase, not a managed business program.
A realistic first-year target
Aim to build reliable identity data and migrate a priority app set. Remove VPN access for a defined user group within 6 to 12 months.
Reserve the hardest old systems for modernization, retirement, or isolation decisions. This keeps their cost visible. It prevents those costs from hiding inside a license quote.