Cloudflare’s Descaler Program: Faster Exits from Legacy Security Stacks
When an organization decides to leave an incumbent security vendor, the speed of the exit often matters as much as the destination. Cloudflare’s Descaler Program, introduced in March 2023, targets this pain point by offering a structured migration path from Zscaler to Cloudflare One. The program leverages a toolkit that exports configuration data from a Zscaler account, transforms it, and loads it into a new Cloudflare One environment using supported API calls.
The core promise is straightforward: derisking the transition process while minimizing manual effort. According to Cloudflare, the tooling has been refined through repeated customer deployments to the point where migrations are measured in hours rather than days. For many organizations, the practical bottleneck is not technical but logistical—simply coordinating a meeting with the right administrators takes longer than the actual configuration transfer.
Customer Migration Timelines
The following examples illustrate the varying scales and constraints of recent Descaler engagements.
Seven Days: A UK Ecommerce Platform
A UK-based ecommerce company with 7,500 employees used the program to replace Zscaler services before a renewal deadline. The primary motivation was cost reduction coupled with a need for faster, safer access to corporate resources and SaaS applications. The migration was completed in one week, with minimal operational disruption. During this engagement, customer feedback highlighted the need for a simplified view of the objects available for transfer. This input led to a new feature: the Descaler tool now offers a summary output detailing what will be moved into Cloudflare Gateway.
Sample Descaler summary output.
Two Days: A Fortune 100 Oil and Gas Company
A US-based Fortune 100 energy company with nearly 20,000 employees faced a different challenge: consolidating application, network, and security services into a single operational pane. Their migration was completed in under two days. The speed of the process was critical for integrating thousands of curated items—IP addresses, hostnames, and URLs—that were embedded in their filtering policies. These list entries were transformed and loaded into the production Cloudflare account nearly instantaneously, preserving existing security intelligence while eliminating hours of manual copying and pasting.
Under 24 Hours: An Australian Telecommunications Provider
A major Australian telecommunications company, operating one of the country’s largest fiber networks, prioritized employee internet security and malware prevention. Their configuration migration was completed in less than 24 hours. A key requirement for this enterprise was the ability to manage resources as infrastructure-as-code utilizing Terraform. Based on such feedback, the Descaler team added an export option that generates a shareable Terraform file containing the migrated configuration, allowing customers to maintain their established workflows for building and versioning infrastructure.

Continuous Iteration for Smoother Transitions
The evolution of the Descaler toolkit reflects a pattern of feedback-driven development. Features such as summary output and Terraform export were not part of the initial release but were added in response to specific customer requests during production migrations. This iterative approach is intended to reduce friction for new adopters who may have highly customized legacy configurations.
For organizations considering a move to Cloudflare One, the Descaler Program is positioned as a low-risk entry point. The Cloudflare team handles the technical extraction and transformation, while customers primarily need to allocate time for testing and validation. Interested parties can sign up through Cloudflare’s dedicated migration page, after which the team provides enrollment details and coordinates the transition.




