Who / What / When / Where / Why: As of September 2026 large enterprises, managed security service providers and regulated organisations in finance, healthcare and government are accelerating migrations from traditional IPsec/SSL VPN concentrators to Zero Trust Network Access (ZTNA) and SASE-style architectures. The shift is driven by identity‑centric controls, tighter regulator and auditor expectations for session-level evidence, cloud migration patterns, and new operational integrations (identity, EDR/XDR, CASB) that make ZTNA practical at scale.
Context: why this matters now
ZTNA replaces broad network tunnels with per-application, identity-and-context checks. That model has been on enterprise roadmaps for several years, but two forces pushed it forward in 2026: (1) vendors matured integrations for device posture, workload identity and data protection across cloud providers and SaaS; and (2) procurement and audit teams now expect demonstrable session-level controls and least-privilege access rather than “connected-to-network = trusted.” For security teams managing distributed workforces and hybrid cloud estates, those changes reduce lateral‑movement risk and simplify compliance evidence.
What's new in 2026
- Deeper XDR and CASB integrations: Major ZTNA/SASE vendors have added richer telemetry hooks into EDR/XDR and CASB platforms, enabling action‑based policies (e.g., block download if EDR sees suspicious behavior).
- Clientless browser isolation is mainstream: Organizations that must support unmanaged devices increasingly use browser‑isolation + ZTNA brokers rather than issuing full VPN clients.
- Service-to-service ZTNA: Platforms now commonly offer mTLS-based service identity features for east‑west controls inside cloud VPCs, reducing reliance on overlay tunnels between data centers.
- Regulatory pressure persists: Existing guidance—NIST SP 800‑207 and CISA’s Zero Trust Maturity Model—continues to be referenced in audits; compliance teams are asking for identity-linked session logs and stronger proof of device posture.
- Hybrid economics and vendor consolidation: Procurement teams are evaluating bundled SASE offerings vs. best-of-breed stacks; concerns about vendor lock‑in and edge availability are shaping purchase decisions.
How organizations are migrating in 2026
Migrations remain phased and tactical. Successful patterns we see across enterprises and large MSPs:
- Business‑driven inventory (Q1–Q2): Map applications by business criticality, protocol, and latency sensitivity. Include non‑HTTP services, IoT, and third‑party managed systems in inventory.
- Pilot and telemetry alignment (Q2): Run a brokered proxy pilot for a subset of web/TCP apps while streaming ZTNA logs into SIEM/XDR. Verify fields and timestamps match compliance requirements.
- Policy ramp and resilience testing (Q3): Migrate user groups incrementally; test failover, regional edge routing and egress behaviour for VoIP, trading, or UCaaS workloads.
- Legacy path management (Q4+): Maintain hardened VPN exits for low‑latency or legacy‑protocol workloads, instrument them with session logging, and set deprecation timelines tied to application refactoring.
Current technical hurdles and mitigations
- Legacy, non‑HTTP protocols: SIP, SMB, legacy RPC and industrial protocols still require tunneling or application refactoring. Mitigation: use a narrow, hardened VPN egress or per‑application TCP proxies rather than broad network tunnels.
- Latency‑sensitive workloads: Real‑time voice/video and trading platforms may need regional egress points or on‑prem edge appliances; test SLOs and include synthetic latency tests in pilots.
- Visibility model changes: Moving from packet‑level taps to identity‑ and session‑level logs requires SIEM/XDR pipeline changes—normalize fields, preserve original flow metadata, and validate forensic timelines.
- IoT and OT devices: Non‑manageable devices often cannot run agents; isolate them on purpose‑built VLANs with service proxies or hardened VPN gateways and monitor east‑west flows.
- Operational complexity: Identity lifecycle gaps (onboarding/offboarding) cause policy drift. Automate via SCIM and integrate HR systems into identity lifecycle workflows.
Impact: who wins and who should adapt
Security teams that adopt ZTNA with strong identity and telemetry integrations gain reduced lateral movement risk, clearer audit trails and simplified user experience for SaaS/cloud apps. Vendors that fail to support non‑HTTP protocols, regional edge presence or clean SIEM integration risk being bypassed. For VPN enthusiasts and appliance vendors, there’s a clear opportunity: build bridge products—WireGuard/OpenVPN connectors, secure egress appliances, telemetry translators—that support hybrid ZTNA/VPN deployments and legacy protocols.
Reactions from the field
CIOs in regulated industries report that auditors are pushing for identity-linked session records and proof of device posture, not merely perimeter controls. Network engineers note that while everyday remote access is moving to brokers and zero‑trust agents, specialist teams still manage a small fleet of dedicated VPN exits for trading, SCADA and vendor remote support.
Recommendations and best practices (September 2026)
- Validate identity maturity: Ensure OIDC/SAML and SCIM automation are fully implemented before mass migration.
- Plan for telemetry parity: Map packet‑level evidence to session logs and validate forensic scenarios end‑to‑end.
- Keep small hardened VPN escapes: Retain them for latency‑sensitive or protocol‑dependent workloads, but treat them as controlled, auditable islands, not general‑purpose exits.
- Test service‑to‑service controls: Use mTLS and workload identity in cloud fabrics to reduce intrusion paths between services.
- Procure for edge coverage and SLAs: Verify regional PoPs, egress behaviour, and measurable SLOs for performance‑sensitive use cases.
What to watch next
Through the remainder of 2026 watch for deeper automation between identity systems and policy engines, expanded support for service identity in cloud-native stacks, and new marketplace tooling that remediates protocol gaps (containerized protocol proxies, managed legacy tunnels). Procurement teams will also increasingly demand clear migration roadmaps and forensic parity guarantees as part of purchasing contracts.
FAQs
Do I need to rip out all VPN concentrators now?
No. Most organisations benefit from a phased approach. Keep a minimal, hardened set of VPN exits for legacy or low‑latency workloads while moving day‑to‑day access to ZTNA. Define deprecation timelines tied to application refactoring and telemetry parity tests.
How do I keep forensic visibility when I stop using packet tunnels?
Map packet capture use cases to session logs early. Ensure your ZTNA broker and edge components export rich session fields (identity, device posture, timestamps, source/destination IPs, URL/hostname, and raw connection metadata) and validate ingestion into SIEM/XDR for investigative scenarios.
Will ZTNA handle unmanaged devices?
Yes — with caveats. For unmanaged devices, use clientless access patterns like browser isolation or ephemeral browser sessions and apply strict policy—restrict downloads, require MFA and pair with CASB controls. For higher risk access, require managed devices with posture agents.
Should I trust single‑vendor SASE bundles?
Evaluate them on integration, performance (regional PoPs), and exit behaviours. Bundles reduce integration overhead but can increase lock‑in. Keep exportable logs, APIs for telemetry, and contract SLAs to avoid being constrained later.