Cloudflare One Named in Gartner Magic Quadrant for SSE

Gartner has recognized Cloudflare in the 2023 Gartner Magic Quadrant for Security Service Edge (SSE), positioning Cloudflare Zero Trust — part of the Cloudflare One platform — among just ten vendors highlighted in the report. Notably, Cloudflare is the only new vendor added to this year's listing.

The recognition comes less than five years after the launch of Cloudflare Access, the company's Zero Trust access control product. Since then, Cloudflare has shipped nearly a dozen additional products and hundreds of features to build out a comprehensive SSE offering now used by over 10,000 organizations. This rapid development was possible because Cloudflare One runs on the same network infrastructure that already secures and accelerates traffic for some of the world's largest Internet properties, leveraging assets like the 1.1.1.1 DNS resolver, the Workers serverless compute platform, and global traffic routing and acceleration capabilities.

Understanding Security Service Edge

SSE is defined as a cloud-delivered security model that "secures access to the web, cloud services and private applications," encompassing access control, threat protection, data security, security monitoring, and acceptable-use control enforced through network-based and API-based integration.

The SSE category emerged as traditional perimeter-based security broke down. Enterprises once protected themselves by concentrating security appliances — firewalls, proxies, and filtering hardware — at a physical office boundary, with remote users backhauling traffic through VPN clients. As applications migrated to SaaS and public cloud, and users left the office, that model became unworkable: physical appliances could no longer sit in the path of traffic, performance suffered, costs climbed, and attackers adapted to exploit the gaps.

SSE vendors answer these challenges by delivering security services from their own points of presence or cloud infrastructure. This gives enterprises a secure first hop before traffic reaches the open Internet or internal systems, eliminates the burden of maintaining on-premise appliances, and keeps filtering policies continuously updated. Some SSE capabilities replace remote access VPNs with Zero Trust access rules for internal tools; others apply similar scrutiny to general Internet traffic, replacing on-premise filtering with cloud-based firewalls, resolvers, and proxies that operate close to the user rather than requiring traffic backhaul.

Where SASE Fits In

Secure Access Service Edge (SASE) extends the SSE concept by adding management of the connectivity itself. SASE vendors handle both securing traffic and managing how users, devices, sites, and services connect. Most vendors focus on one side: network-as-a-service providers sell SD-WAN, interconnection, and optimization, but send traffic to separate SSE vendors for filtering; SSE providers offer security but require customers to source networking separately.

Cloudflare One takes a single-vendor approach to SASE. Enterprises can route all traffic to Cloudflare's network, where connectivity and performance are managed alongside security. Flexible on-ramps accommodate existing infrastructure — hardware routers, agents on laptops and mobile devices, physical or virtual interconnects, or Cloudflare's Magic WAN Connector. Security filtering happens in the same locations where traffic is routed and accelerated, on the same servers, avoiding additional hops. This reflects a design principle that has guided Cloudflare since its early reverse proxy days: security should not come at the expense of performance.

Components and Architecture

Cloudflare One consists of two primary components: Cloudflare Zero Trust products (the SSE offering) and a network-as-a-service solution. The Magic WAN network-as-a-service offering extends Cloudflare's global network for enterprise use, connecting roaming devices, offices, physical sites, and entire networks to the Internet or internal destinations.

On-ramps are designed for easy integration:

  • Roaming agent for user devices
  • Cloudflare Tunnel for application-level connectivity
  • Magic WAN Connector or existing router/SD-WAN hardware for network-level tunnels
  • Physical or virtual interconnects for dedicated connectivity to on-premises or cloud infrastructure at over 1,600 locations worldwide

Once packets arrive at the nearest Cloudflare point of presence, the platform provides optimization, acceleration, and logging. Enterprises can selectively enable SSE features from the Cloudflare Zero Trust platform — applied at the same location, generally on the same server, as the network services — allowing teams to strengthen their security posture incrementally without compromising on performance or architectural simplicity.

Inside Cloudflare One’s SSE toolkit

Cloudflare One bundles the security controls needed for a complete SSE deployment, regardless of enterprise scale. Traffic only needs to reach a nearby Cloudflare point of presence, where Zero Trust policy is enforced.

BLOG-1738 Embedded Image - cgbcav

Core security controls

Zero Trust access control. For teams hosting their own resources, Cloudflare’s Zero Trust VPN replacement supports traditional private network connectivity or agentless access for contractors. Administrators define granular per-resource or global rules, combining inputs from one or more identity providers, device posture signals, and other context to decide when and how users connect. The same controls extend to SaaS applications outside the organization’s control via Cloudflare’s identity proxy in the login flow, layering checks like device posture, country, and multifactor method on top of an existing identity provider.

DNS filtering and network firewall. DNS filtering runs on Cloudflare’s resolver, logging queries from individual devices or large network deployments. Organizations with on-premise or cloud firewalls can route traffic through Cloudflare’s firewall-as-a-service instead, which provides L3-L7 filtering, intrusion detection, and integration with Threat Intelligence feeds. This approach avoids hardware capacity planning, throughput limits, and manual patching.

Secure Web Gateway. The SWG inspects, filters, and logs traffic at a nearby point of presence. It blocks HTTP requests to dangerous destinations, scans for viruses and malware, and controls routing to the rest of the Internet without additional hardware or virtualized services.

In-line CASB and Shadow IT. Cloudflare’s in-line Cloud Access Security Broker gives administrators tenant control rules over SaaS usage, such as blocking personal account logins, restricting uploads to approved applications, and filtering unapproved services. The Shadow IT service scans and catalogs Internet traffic to help detect unauthorized SaaS use, such as ensuring users only upload files to the sanctioned cloud storage provider.

API-driven CASB and DLP. For SaaS data at rest, the API-driven CASB continuously scans applications for misconfigurations and potential data loss. Once an issue — such as an overshared document or a file sent to a personal account — is detected, it alerts administrators and provides remediation guidance. Data Loss Prevention scans traffic against prebuilt profiles (e.g., social security or credit card numbers) or custom regular expressions, and integrates with Microsoft Information Protection labels.

Remote Browser Isolation. Browser isolation renders pages in a Cloudflare data center near the user, sending only the visual output to the local browser. Administrators can isolate unknown destinations on the fly, support agentless contractor workstations, and add protections such as blocking copy-paste or printing.

Coverage beyond the SSE definition

Not every security problem fits inside the SSE category, and Cloudflare One extends to adjacent areas that customers often need alongside an SSE rollout. Email, for instance, is the entry point for many attacks but sits outside the traditional SSE scope. Cloudflare’s Area 1 email security integrates with the Zero Trust platform, so suspicious email links can be opened in an isolated browser as part of a defense-in-depth strategy.

Cloudflare’s application security suite, also recognized by Gartner, can be deployed in-line with these Zero Trust features. The Web Application Firewall, DDoS mitigation service, bot management alerts, API protection, and caching can apply to internal tools with a single toggle.

Why customers choose Cloudflare One

More than 10,000 organizations currently rely on Cloudflare One, ranging from the US Federal Government down to small teams on the free plan. Recent conversations with customers during CIO Week surfaced several recurring reasons for choosing the platform.

Broader security coverage

Most SSE vendors improve on the traditional castle-and-moat model, but Cloudflare built its access control and outbound filtering to go further. The Zero Trust VPN replacement integrates with identity providers and endpoint protection platforms such as Microsoft and CrowdStrike. Outbound filtering decisions draw on threat intelligence from Cloudforce One, the company's dedicated threat research team.

Performance is built in

Cloudflare One starts with what the company calls the world's fastest DNS resolver, and end-user connections run over a secure tunnel optimized using feedback from the consumer WARP forward proxy. Sites connect to Cloudflare's network through multiple tunnel options, which the company measures against pure connectivity providers as well as other SSE vendors. In internal testing, Cloudflare reports outperforming Zscaler by 38% to 59% depending on use case.

Management simplicity

Cloudflare One stands out in the SSE market for its free plan, which covers nearly every feature for teams of up to 50 users. That commitment forced the company to build products that don't require a large integrator to deploy. Administrators get an intuitive dashboard plus API support for every feature and a Terraform provider for configuration-as-code workflows.

Cost efficiency at scale

Because Cloudflare already operates infrastructure for millions of websites, the same hardware and data centers power Cloudflare One. Internal enterprise traffic typically doesn't approach the volume of popular internet properties, so adding SSE services doesn't require a separate network investment. That allows pricing that leverages existing infrastructure rather than building from scratch.

A single vendor for multiple security needs

Cloudflare One is the latest addition to the platform recognized in analyst reports. In 2022, Gartner named Cloudflare a Leader in Web Application and API Protection. Customers addressing SSE challenges can add DDoS protection, CDN, edge computing and bot management from the same vendor, a consolidation path multiple analyst firms have recognized.

Looking ahead

Cloudflare says today's recognition will accelerate development of Cloudflare One, with a focus on the next wave of security and connectivity features for its customers.

Gartner, "Magic Quadrant for Security Service Edge", Analyst(s): Charlie Winckless, Aaron McQuaid, John Watts, Craig Lawson, Thomas Lintemuth, Dale Koeppen, April 10, 2023.

GARTNER is a registered trademark and service mark of Gartner and Magic Quadrant is a registered trademark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and are used herein with permission. All rights reserved. Gartner does not endorse any vendor, product or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.