Why Zero Trust performance is a security issue
Zero Trust security products only work if employees actually use them. When access controls, secure web gateways, or browser isolation tools feel slow, users find ways around them — disabling protections or bypassing the gateway entirely. A security suite that nobody wants to use provides no security at all.
The performance bar is set by the applications themselves. Real-time tools like Slack and Zoom require low latency for smooth voice and video calls. If user traffic has to travel a long detour through a distant gateway before reaching its destination, the extra round trips degrade call quality, slow file transfers, and generally make every interaction feel sluggish. A Zero Trust provider that cannot keep latency low will push users toward risky workarounds.
Cloudflare Access vs. Zscaler and Netskope
Cloudflare measured application access performance across its own Zero Trust proxy, Zscaler Private Access, and Netskope Private Access. The tests used 300 Catchpoint nodes distributed globally, connecting to six application servers in Hong Kong, Toronto, Johannesburg, São Paulo, Phoenix, and Switzerland. In every location, Cloudflare's P95 response time was faster than both competitors — 50% faster than Zscaler and 75% faster than Netskope overall.
The testing methodology separated two distinct scenarios:
- New sessions — the user has no cached authentication and must log in through the identity provider before reaching the application
- Existing sessions — the user's credentials are already cached on the provider network, so no additional identity provider call is needed
These scenarios are measured separately because mixing them would skew results — new sessions are inherently slower due to the authentication step. Even so, Cloudflare was consistently faster in both categories across all regions.

| ZT Access - Response Time (95th Percentile) - Toronto | ||
|---|---|---|
| New Sessions (ms) | Existing Sessions (ms) | |
| Cloudflare | 1,276 | 1,022 |
| Zscaler | 2,415 | 1,797 |
| Netskope | 5,741 | 1,822 |
New sessions are slower for all providers, as expected. The gap between providers becomes more pronounced in regions with challenging connectivity. In South America and Asia Pacific, Zscaler's performance was closer to Netskope's than to Cloudflare's. Netskope showed particular weakness on new sessions, suggesting its service handles authentication flows poorly under load.
The Connect time advantage
A key differentiator is how quickly users get onto the provider's network. Cloudflare's Connect times were consistently faster across all 300 test nodes — roughly twice as fast as Zscaler and three times faster than Netskope. This is a network architecture advantage: Cloudflare ingresses connections closer to users and routes traffic along optimized paths back to the application host.

How the tests were run
Cloudflare contracted a third party to design the test methodology. Five application instances were hosted in Toronto, Los Angeles, São Paulo, and Hong Kong. The 300 Catchpoint nodes simulated browser sessions as follows:
- User connects to the application from the Catchpoint instance — a new session
- User authenticates against the identity provider
- User accesses the application resource
- User refreshes the page and accesses the same resource with credentials already present — an existing session
This approach ensures that all providers are compared on equivalent request paths, avoiding false comparisons between a cached Cloudflare session and an uncached session on a competitor's network.
Broader network performance
The Access benchmark results reflect a wider trend. Cloudflare also tracks overall network performance using Real User Measurements (RUM), where users worldwide fetch a 100kb file from multiple providers. The goal is to measure P95 TCP Connection Time across the top 3,000 networks globally (ranked by IPv4 address count).

Since Developer Week 2022, Cloudflare has extended its lead. The number of networks where Cloudflare ranks first in connection time has grown, while rivals like Akamai and Fastly have lost ground. Regionally, Cloudflare improved its standing in Brazil, South Africa, Ethiopia, Nigeria, Indonesia, Norway, Sweden, and the UK.
What drives the improvements
Much of the recent progress comes from the Edge Partner Program, which embeds Cloudflare locations inside last-mile ISP networks. Deploying partner nodes in places like Nigeria and Saudi Arabia shortens the final network hop for users, cutting round-trip time and improving performance for Zero Trust products and general web browsing alike.
The challenges in reaching these networks vary by region. Different ISPs have different peering arrangements, routing policies, and infrastructure constraints, so Cloudflare's optimization work is tailored to each network rather than applied uniformly.
The Zero Trust performance burden
Traditional corporate networking put IT teams in control of the middle mile — they managed the leased lines and MPLS circuits connecting offices to resources. Zero Trust shifts that responsibility to the provider. The public Internet becomes the network, and the Zero Trust vendor is responsible for optimizing every user's path to every application.
That changes what organizations should evaluate when choosing a Zero Trust platform. Security features matter, but performance is not a secondary concern. Every authentication request, every gateway check, and every application connection runs through the provider's network. A provider that cannot deliver low latency will create friction, reduce productivity, and push employees toward unsafe workarounds. The best Zero Trust solution is one that keeps users protected without giving them a reason to notice it exists.



