

Find out in this report how the two ZTNA solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI.
At Amazon, we knew exactly how much it would cost if a fulfillment center was down for an hour.
The AI features further contribute by expediting threat detection and incident response, ensuring tangible returns through operational savings.
It is one of those tools that needs to work right out of the box, and thankfully, it does; it is reliable, and the setup time was quick and straightforward.
If I compare this to an on-premises environment using Cisco ISE or Aruba ClearPass, it would require phenomenally large teams for infrastructure management.
If you were moving from a traditional on-premise NAC that was 100% managed by the IT department, there would be great savings in going to a cloud-based NAC with Portnox.
By automating the device containment and remediation processes, we save countless hours weekly.
Cisco TAC is very competent.
With our established point of contact within Cisco, our experience has greatly improved; we no longer log all issues through technical cases, as we can go directly to our account managers or customer service team, which expedites resolution.
I would rate the technical support ten out of ten. Hands down.
The main area needing improvement is the technical knowledge of support staff.
For very high severity issues where the entire office is non-functional, response time is within 30 minutes.
In terms of support, it is usually quite impressive. I usually get support in a matter of minutes or seconds, depending on the priority of the ticket.
We turn the traffic to the Cisco Secure Access cloud, and we can manage and apply the policies that are necessary, making it very easy to scale the solution.
Cisco has a great benefit in that you can integrate with other solutions in an easy way because it has a lot of protocols to integrate with others and sophisticated steps that we can apply for integration.
Performance has remained consistent, usage has increased, and we have not experienced scalability-related limitations.
We have never had any challenge based on a customer who has 1,000 devices versus a customer who has 30,000 devices; the feel is the same.
Its infrastructure scales automatically in the background, eliminating concerns about capacity or backend upgrades.
It has a centralized cloud-based architecture, so we do not have to worry about other considerations such as local infrastructure or purchasing additional equipment.
Cisco is renowned for their reliability, and their products perform well under high data usage.
The service consistently provides secure connectivity for remote users, contractors, and hybrid environments with minimal disruption.
I rate the stability of Cisco Secure Access as ten out of ten.
The product itself is available and its uptime is 100%.
In the four years that I used Portnox, if it crashed or the server crashed, that would not have been more than once.
If there is a version one and another version, the communication between the organization using it and Portnox should be firm so they can coordinate effectively.
Modernization is needed, specifically in the enhancement of security features and functionality.
It was challenging to learn because it has a significant learning curve and requires considerable training to become proficient.
The granular access issue is coming from the product limitation at the moment, as it does not offer us the option to tell it that a particular role can only manage websites, allowed sites, and blocked sites.
Ideally, we should be able to search for any MAC address in the database, regardless of its authentication status, to see all its associated groups and potential conflicts.
When I reach the technical support, they give solutions that do not help me much, so I try to search the internet for other users' experiences to find solutions.
I would definitely request a UI refresh that makes the dashboard more modern and surfaces critical logs so they are easier to access in a pinch.
The solution is cheaper than premium options such as Palo Alto, existing Cisco licenses facilitate replacing previous solutions with Cisco Secure Access smoothly and affordably.
It is good because you want to push Cisco Secure Access, and regarding the price, it is very much below other products.
Improvement on the pricing will help in expanding the market for Cisco Secure Access and then it can be affordable to much more number of companies than what it is right now.
If you compare Portnox with all other well-known standard products, it is the cheapest.
The pricing is a bit high, possibly due to the cloud features and running instances across regions like the US, Asia, and Europe.
You are charged according to the number of users.
It eliminates the hassle of switching on VPNs and provides a direct connection to resources via Cisco Secure Access.
They are sending the traffic encrypted and categorizing the traffic based on the type, whether web traffic or internet traffic, and doing the security mechanism that is needed for the traffic type.
Using ZTNA in Cisco Secure Access has positively affected my transition and my clients' transition to Zero Trust and least privilege principles, reinforcing the security posture.
It's notable how Portnox has improved operational efficiency.
It is a very robust application because three teams use that part: the network team, the security team, and the support people.
It is possible to find the MAC address in the switch, but in Portnox, it is very useful to see the status of those ports, and that increases our security.
| Product | Mindshare (%) |
|---|---|
| Cisco Secure Access | 2.9% |
| Portnox | 3.3% |
| Other | 93.8% |

| Company Size | Count |
|---|---|
| Small Business | 29 |
| Midsize Enterprise | 13 |
| Large Enterprise | 36 |
| Company Size | Count |
|---|---|
| Small Business | 19 |
| Midsize Enterprise | 9 |
| Large Enterprise | 15 |
Cisco Secure Access is a comprehensive Security Service Edge (SSE) solution (a key component of a SASE solution) that addresses the complexities of securing a hybrid enterprise. Cloud-delivered and grounded in zero trust, it delivers a unique blend of user simplicity and IT efficiency for frictionless, secure access to all applications—SaaS (with gen AI), private apps, and the internet—regardless of user location or device. Secure Access protects users, data, and devices against relentless, sophisticated, and constantly evolving threats including AI-driven attacks and identity breaches.
Provides all core SSE components (ZTNA, SWG, CASB, and FWaaS) plus extended capabilities.
Includes VPN-as-a-Service (VPNaaS), data loss prevention (DLP), AI Assistant, visibility/control/guardrails for generative AI use, digital experience monitoring (DEM), reserved IP, remote browser isolation (RBI), DNS-layer security, flexible security enforcement (in cloud or on-premises), policy verification, and more.
Protects users as they seamlessly access resources and apps with no extra steps needed, regardless of protocol, port, or level of customization
Simplifies IT operations through a single client, single dashboard, single license, and unified policies.
Lowers risk with least privilege, granular controls backed with unmatched threat intelligence of Cisco Talos.
Eases interoperability with other products from Cisco and third-party vendors with common administrative controls, data structures, and policy management.
Robust integrations
Integrates with Cisco Identity Intelligence to protect against the startling increase in identity-based attacks.
Integrates with many SAML Identity Providers (IDPs) such as AD, Azure AD, Okta, Ping, etc.
Integrates with Cisco offerings including SD-WAN, Splunk, XDR, Thousand Eyes, third party technologies such as Menlo RBI, Chrome Enterprise Browser, and AppOmni for SSPM.
Portnox NAC is a cloud-native network access control solution built for today's hybrid, distributed enterprises. Get real-time visibility into every device on your network, enforce risk-based access policies automatically, and maintain continuous compliance — all without deploying a single on-premises appliance.
----------
About Portnox Security
Portnox is a cloud-native enterprise access control provider that helps organizations secure every identity - human and non-human - across networks, applications, and infrastructure. As identities, devices, and workloads multiply across modern environments, Portnox enables continuous access verification based on identity context, device posture, and risk signals. Its unified platform brings together passwordless authentication, access control, continuous policy enforcement, and automated response through a single policy engine.
Portnox gives security and IT teams real-time visibility into everything connecting and the ability to quickly restrict, quarantine, or revoke non-compliant access. Today, Portnox actively manages more than one million devices worldwide, secures 40 million authentication sessions, and blocks over one million unauthorized access attempts every day. Learn more at portnox.com.
CAPABILITIES:
• Discover and assess users, devices, and identities connecting to corporate resources
• Unify continuous zero trust access control on networks, applications, and infrastructure
• Enforce identity- and context-aware access policies
• Enable secure remote work without complexity
• Deliver passwordless authentication, device posture checks, and continuous access enforcement
• Control administrative access to routers, switches, firewalls, and other network devices
• Improve audit readiness with visibility, access logs, and policy-based compliance controls
BUILT FOR:
Portnox is designed for distributed organizations that need to manage access across employees, contractors, service accounts, managed devices, unmanaged devices, IoT, network infrastructure, SaaS applications, private applications, and AI agents. The platform helps reduce reliance on on-premises appliances, legacy VPNs, and fragmented access tools by centralizing access policy enforcement from a single cloud-native policy engine.
INTEGRATIONS:
Portnox integrates with the tools you already use (including Azure AD / Entra ID, Okta) and works with your existing network appliances, (such as Meraki, Fortinet, and more), and many other identity and network infrastructure tools.
We monitor all ZTNA reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.