The short answer: for most mid-market organisations the best VPN alternative is ZTNA — delivered either as a focused point solution or inside a full SASE platform — because it removes the exposed gateway that drove 70% of Benelux ransomware intrusions in 2025. Which product fits depends on your scenario: a hybrid workforce shortlists differently than a factory with OT, a contractor-heavy firm, or a pure Microsoft shop. This comparison walks the categories, the published prices and the sovereignty facts, then maps them to those scenarios.
Key takeaways
- The replacement wave is real: Gartner projects 70% of new remote-access deployments on ZTNA rather than VPN, and the single-vendor SASE market is growing at 29% CAGR toward $25 billion+.
- Seven distinct categories exist — ZTNA point solutions, single-vendor SASE, WireGuard mesh, Microsoft-ecosystem SSE, clientless browser access, enterprise browsers, and modernised VPN concentrators — and they replace different things.
- Sticker prices ($5–$10/user/month) rarely equal real cost: IdP-tier upgrades, dedicated-gateway fees ($40–$50/month), bandwidth surcharges and seat minimums stack on top.
- Jurisdiction is a feature: most big-name vendors are US-headquartered and subject to the CLOUD Act and FISA 702 wherever their EU PoPs sit — EU-owned platforms avoid that exposure structurally.
- A VPN is still fine for three things: fixed site-to-site links, Layer-2 OT discovery protocols, and air-gapped networks. For workforce remote access, the era is over.
Why is everyone replacing the VPN now?
Because the claims and breach data made the argument unanswerable. In the Benelux, 70% of successful 2025 ransomware intrusions traced to exploited SSL VPN gateways, with 96% involving data exfiltration before encryption — the analysis behind our legacy VPN risk report. Globally, the Verizon 2025 DBIR measured an eightfold jump in edge-device exploitation (to 22% of vulnerability breaches), Mandiant put internet-facing VPNs, firewalls and edge routers in four of the top five exploited categories, and Sophos found 63% of breached organisations lacked enforced MFA on exposed remote access. An internet-facing listening port plus broad Layer-3 access on login is simply the wrong architecture for 2026 — the full deprecation picture per vendor sits in the SSL VPN timeline.
How to evaluate: six criteria that matter at mid-market size
- Deployment effort: days, not consulting quarters — SCIM provisioning, simple IdP hookup, one console.
- Mixed OS and BYOD: Windows, macOS, Linux, mobile — plus something for devices you don’t manage.
- Agentless third-party access: contractors shouldn’t install your agent; browser-based access is the test.
- OT and legacy protocols: RDP, SMB, raw UDP, fixed IPs — without granting whole subnets.
- Inline inspection: SWG and DLP in the same platform, or you’ll buy them separately later.
- Cost transparency: published prices, low seat floors, no surcharge maze.
The master comparison
All prices are published list figures as of August 2026 — vendors adjust often, so verify at purchase.
| Product | Category | Published entry price | Agent needed? | HQ / jurisdiction | Best fit |
|---|---|---|---|---|---|
| Zscaler Private Access | ZTNA / SSE | Custom quote | Client; web agentless | USA (CLOUD Act) | Large enterprise SSE |
| Palo Alto Prisma Access | Single-vendor SASE | Custom quote | GlobalProtect + Prisma Browser | USA (CLOUD Act) | Enterprise SASE estates |
| Cloudflare One | ZTNA / SSE edge | Free ≤50 users; from $7/user/mo | WARP; web agentless | USA (CLOUD Act) | Developer teams, fast rollouts |
| Netskope One | Single-vendor SASE | Custom quote | Client; web agentless | USA (CLOUD Act) | Data-centric DLP focus |
| Cato Networks | Single-vendor SASE | Custom quote | Client + Socket appliances | Israel | Converged branch + remote |
| Check Point Harmony SASE | Mid-market SASE | $8–$16/user/mo | Client; web portal | Israel | Check Point shops |
| Fortinet FortiSASE | Single-vendor SASE | Custom quote | FortiClient | USA (CLOUD Act) | FortiGate SD-WAN estates |
| Twingate | ZTNA point | Free ≤5 users; $5–$10/user/mo | Client required | USA (CLOUD Act) | Agile VPN replacement |
| Tailscale | WireGuard mesh | Free ≤3 users; from $6/user/mo | Client on every peer | Canada/USA | DevOps peer-to-peer mesh |
| NordLayer | Business VPN / ZTNA | $6.40–$14/user/mo | App required | Lithuania roots / US ops | Growing SMB teams |
| Microsoft Entra Private Access | Microsoft SSE | $5/user/mo + Entra ID P1 base | GSA client | USA (CLOUD Act) | Pure M365 shops |
| OpenVPN Access Server | Managed classic VPN | Free 2–3 connections; per-connection fee | OpenVPN client | USA (self-host option) | Self-hosted classic VPN |
| WireGuard DIY | Open-source mesh | Software free; you run it | Native client | Your infrastructure | In-house Linux engineering |
| Island Enterprise Browser | Enterprise browser | ~$250,000/year minimum | Browser replacement | USA (CLOUD Act) | High-DLP BYOD at enterprise scale |
| Jimber | Full EU-sovereign SASE (ZTNA + SWG + FWaaS + SD-WAN + isolation) | EU flat rate — see pricing | Client for workforce; agentless for third parties/OT | Belgium (EU jurisdiction) | EU mid-market, mixed estates, OT, contractors |
The categories, briefly — and who leads them
ZTNA point solutions (Twingate, Cloudflare Access, Zscaler ZPA) replace the inbound VPN concentrator with identity-verified per-app sessions; they do not give you web filtering or branch networking. Twingate earns its G2 4.6/5 on developer ergonomics; Cloudflare’s free tier up to 50 users is the lowest-friction pilot in the market. Single-vendor SASE (Cato, Palo Alto, Netskope as Gartner Leaders; Fortinet as Challenger; Cloudflare as Visionary) folds ZTNA, SWG, CASB, FWaaS and SD-WAN into one cloud — the consolidation route when firewalls and web filters are up for renewal anyway. WireGuard mesh (Tailscale) is beloved by engineers for peer-to-peer speed, but brings no inline inspection or clientless option — a network tool, not a security platform. Microsoft SSE reuses your Entra investment but is not in E3/E5: it is a $5 add-on on a mandatory P1 base, Windows-centric, and Entra-ID-only. Clientless browser ZTNA and enterprise browsers both target unmanaged devices; the browser route (Island, rated 5.0/5 but from ~$250,000/year) prices out the mid-market, while reverse-proxy clientless access delivers the same no-agent outcome per application. Modernised VPN concentrators (NordLayer, OpenVPN AS) fix the crypto and the console but keep the network-level access model — better VPNs, not alternatives to the architecture.
The sovereignty question nobody puts in the datasheet
Under the US CLOUD Act (18 U.S.C. § 2713), US-headquartered vendors must produce data in their possession or control on a lawful US warrant — regardless of whether the servers sit in Frankfurt or Amsterdam. FISA 702 adds warrantless surveillance authority over non-US persons. That covers Zscaler, Palo Alto, Cloudflare, Netskope, Fortinet, Twingate, Microsoft and (via its US presence) Tailscale: your session metadata, authentication logs and inspected traffic transit infrastructure answerable to a foreign legal system. An EU PoP changes latency, not jurisdiction. For organisations under GDPR and NIS2, the structural fix is a vendor whose ownership sits inside the EU — the argument developed in European SASE alternatives. Jimber is the Belgian entry in that column.
Which shortlist fits your scenario?
- Hybrid office + remote, ~200 seats: you need fast rollout, clean clients, IdP integration. Shortlist: Twingate, Cloudflare One, NordLayer — or Jimber if you want the SWG/firewall consolidation and EU jurisdiction in the same move rather than a second project later.
- Multi-site with OT and legacy protocols: you need UDP, fixed IPs, branch networking, inline inspection. Shortlist: FortiSASE, Cato — or Jimber, whose agentless network isolation covers the PLCs and machines no client can be installed on, from the same platform as workforce ZTNA.
- Heavy contractor/BYOD use: the test is zero installation with DLP control. Island does it at enterprise contract minimums; clientless ZTNA does it per application. Jimber’s browser-based web application isolation is exactly this pattern at mid-market economics.
- Pure Microsoft shop: Entra Private Access is the path of least resistance if every device is Entra-joined, Intune-managed and Windows — mind the P1 prerequisite maths and single-IdP lock-in (compared in detail in our NordLayer, Tailscale and Twingate head-to-heads).
When is a VPN still fine?
Three honest cases: fixed site-to-site branch interconnects between routers you control; OT environments that genuinely need Layer-2 broadcast discovery (mDNS, NetBIOS) that Layer-7 proxies cannot carry; and air-gapped networks with no path to a cloud broker. If your use case is “employees and third parties reaching applications”, none of these apply — and the alternatives covered in the Always On VPN analysis show even Microsoft has reached the same conclusion.
Choose the category first, then the vendor
The decision tree is shorter than the market makes it look. Decide whether you need access only (ZTNA point solution) or consolidation (SASE); decide whether unmanaged devices and OT matter (they usually do at mid-market, which demands agentless options); decide whether your data’s jurisdiction matters (under NIS2 and GDPR, it does). Apply those three filters and the EU mid-market shortlist gets short indeed: Jimber is the option built precisely for that intersection — full SASE with agentless third-party and OT access, Belgian jurisdiction beyond CLOUD Act reach, and one flat price instead of a surcharge maze. Migrations run three months on average with zero downtime, old and new side by side. Book a demo to test your own scenario against the table above.
Frequently asked questions
What is the main difference between a VPN and ZTNA?
A VPN connects your device to a network segment at Layer 3 — once in, you can move laterally. ZTNA establishes identity-verified sessions to specific applications at Layer 7, keeping everything else invisible to scanning and unreachable to malware on the endpoint.
Why are legacy SSL VPNs so exposed to ransomware?
They require permanently exposed listening ports that automated scanners probe continuously. One unpatched flaw or stolen credential grants authenticated network access — the pattern behind 70% of Benelux ransomware intrusions in 2025, 96% of which exfiltrated data before encrypting.
Can ZTNA fully replace our corporate VPN?
For workforce remote access — web apps, SSH, RDP, standard TCP/UDP services — yes. Site-to-site branch routing and OT environments needing Layer-2 broadcast discovery may keep a routed tunnel or SD-WAN link alongside.
Is Entra Private Access included in Microsoft 365 E3 or E5?
No. It requires a standalone licence ($5/user/month) on top of an Entra ID P1 base, or the $12 Entra Suite; only the E7 tier includes it natively. As of August 2026 — verify current Microsoft pricing.
What hidden costs should we watch for with cheap ZTNA tools?
Four recur: SSO/SAML gated behind higher tiers, dedicated gateway or static-IP fees around $40–$50 per month, bandwidth surcharges on cloud-routed traffic, and minimum seat floors — up to $250,000-a-year contract minimums for enterprise browsers.
How does the US CLOUD Act affect EU companies using US-based vendors?
US-headquartered vendors must comply with US data demands regardless of server location, and FISA 702 adds surveillance authority over non-US persons. EU PoPs don’t change the legal position — only EU ownership does.
How does clientless ZTNA work for contractors?
The external user authenticates in a standard browser via your identity provider; a reverse proxy then renders the internal web, SSH or RDP session in the browser. Nothing installs on their device, and no network path exists to abuse.
How long does a VPN-to-ZTNA migration take?
Enterprise deployments average about three months from scoping to decommissioning, run with zero downtime by operating both systems in parallel, and typically reach ROI within ten months.