Zero Trust for Mobile Operators: A New Partnership Model
Cloudflare has announced a new partnership initiative aimed at mobile network operators (MNOs), designed to address the dual challenges of security and performance. The Zero Trust for Mobile Operators program formalizes how Cloudflare's products can be integrated with mobile infrastructure, particularly as 5G networks become more widespread.
The company's pitch is straightforward: the complementary nature of MNO networks and Cloudflare's distributed software platform creates opportunities to solve problems neither could tackle alone. Cloudflare's SASE suite, marketed as Cloudflare One, offers the key components that enterprises need for secure connectivity.
- Magic WAN: Network-as-a-Service (NaaS) connectivity for data centers, branch offices, and cloud VPCs, with the ability to integrate with legacy MPLS networks.
- Cloudflare Access: A Zero Trust Network Access (ZTNA) service that requires strict verification of every user and device before granting access to internal resources.
- Gateway: A Secure Web Gateway that sits between the corporate network and the Internet, enforcing security policies.
- Cloud Access Security Broker: Monitoring for external cloud services to detect security threats.
- Cloudflare Area 1: Email threat detection for phishing and malware.
The foundation of this architecture is SD-WAN connectivity. Consider a developer working from home on an application that uses an operator's IoT APIs—perhaps tracking inventory in vending machines or monitoring delivery truck routes. That developer and the fleet of devices need to be on the same wide area network (WAN), securely and cost-effectively.
This is where Cloudflare's programmable software layer fits. The operator provides the network connectivity, and Cloudflare supplies the secure overlay that makes it usable for workforce and device access. Without the underlying enterprise connectivity, the secure connection software has no purpose; without the security layer, raw connectivity is a liability. Once the connection is established, zero trust policies enforce that each user can only access explicit resources—whether via SSH or a cloud service—with single sign-on (SSO) authentication required for access.

Zero trust is a necessary evolution as networks grow increasingly distributed and complex. The days of network perimeter security are over, and explicit verification for each access attempt is the only way to enable that growth without opening the door to known risks.
Edge Compute on the Operator Network
As 5G marks its territory, the ability to move compute closer to the user becomes a differentiating factor. Running workloads in city-level data centers—or even at the base of cell towers—reduces the latency that 5G promises to eliminate.
Cloudflare's distributed compute platform, Workers, executes code at the edge by deploying across all Cloudflare data center locations globally within seconds. Once again, the operator-Cloudflare division of labor is clear: the MNO provides the connectivity and the physical infrastructure, while Cloudflare provides the compute layer that processes requests closer to subscribers.
Several workload types are already emerging on edge platforms, including:
- IoT companies implementing complex device logic and security features at the edge, adding capabilities without adding cost or latency to the device itself.
- eCommerce platforms storing and caching customized assets near visitors for a better customer experience.
- Financial data platforms, including Web3 players, providing near real-time information and transactions.
- A/B testing and experimentation at the edge, without client-side dependencies or added latency.
- Fitness devices offloading compute-heavy workloads while maintaining speed and responsiveness.
- Retail applications delivering fast, personalized service without an expensive on-prem deployment.
Cloudflare's recent General Availability release of Workers for Platforms gives MNOs a path to offer their own customers an embedded edge-computing product. For operators, supplying the means for devices to send data is only the first step; the real value is in the applications that connectivity enables. With Workers for Platforms, the operator can expose a compute layer without having to build or maintain the infrastructure for it.

Network Infrastructure Integration
Physical distance between the device and the server remains a critical performance factor. A user request from Denver that routes through a major Internet hub in Dallas or Chicago and back suffers noticeable latency. The ability of an MNO to break out traffic locally fundamentally improves speed.
With 5G, MNOs have more flexibility than ever before. Cloud-native, distributed radio access networks (RANs) allow for greater movement and multiplication of packet cores—the part of the network through which all subscriber data flows. The more locations where a packet core can exist, the closer the traffic can be terminated to the user.
With Cloudflare's data center presence in 275+ cities, the aim is that traffic connecting a user to a device, authorizing the connection, and transmitting data stays entirely within the MNO's network boundary. In some deployments, this means the user's traffic never touches the public Internet at all—no added latency, no compromise in performance.
The collaboration between Cloudflare and MNOs rests on a fundamental mutual benefit: Cloudflare's security services function best when customers have excellent enterprise connectivity underneath, and mobile operators can deliver more value to their customers by bundling the security software layer on top of their own networks. Operators interested in integrating Cloudflare One into their offerings can contact the program directly at [email protected].
The announcement marks an attempt to bridge the gap between mobile network excellence and distributed software security—a partnership that addresses the growing need for secure, low-latency connectivity as enterprises become more distributed and applications push closer to the edge.



