Zero trust was coined at Forrester. The firm has spent fifteen years developing the model, and it now publishes a vendor evaluation for platforms that claim to deliver it.

In the announcement of that evaluation, Forrester wrote that no solution or platform makes an organisation zero trust, because zero trust is a framework consisting of technology and non-technology pieces.

An analyst firm scoring a market while stating that buying from it does not produce the outcome is not a contradiction. It is the most important thing a buyer in this category needs to understand, and it is stated more plainly here than almost anywhere else in analyst research.

What the model actually says

Zero trust replaced an architectural assumption rather than a product.

The older model was perimeter-based. Build a hard boundary, authenticate people crossing it, and treat everything inside as trusted. That worked while the boundary was real: employees in offices, applications in data centres, one network.

It stopped working for reasons everyone now recognises. Applications moved to cloud services outside the perimeter. Employees moved outside it too. Partners and contractors needed access. And attackers who got inside found a flat, trusting network where lateral movement was trivial, which is why a single compromised laptop keeps turning into an enterprise-wide incident.

Zero trust removes the assumption. Trust is never implicit and must be continuously verified regardless of user, device, or location. Access is granted per request, based on identity, device posture, and context, at the minimum level required, and re-evaluated rather than granted once at a boundary.

Forrester organises the model into seven domains: data, workload, network, user, device, automation and orchestration, and visibility and analytics. That structure matters because it is deliberately not a product list. It describes what has to be governed, not what to buy.

Why a platform market exists

If no platform delivers zero trust, the obvious question is what these products are for.

The answer is complexity reduction. Implementing the model across seven domains using best-of-breed tooling means a dozen vendors, a dozen policy engines, a dozen consoles, and a dozen definitions of what a user is. The policy you intended is then distributed across systems that do not agree with each other, and the gaps between them are where the model fails.

Forrester's definition of the category reflects this. A zero trust platform is a unified set of core security technologies serving as the foundation for the model, delivering functionality across data, workloads, networks, users, and devices, and improving automation, orchestration, and visibility for analytics, using both native integrated products and third-party integrations.

The operative words are unified and foundation. These platforms reduce the number of places policy lives. They do not decide what the policy should be, which is the part that is not technology and the part that determines whether the model works.

Forrester's own framing is direct about where the difficulty sits. The value of zero trust is well understood; the real challenge is implementing it effectively, particularly for organisations navigating misalignment across disciplines and business functions alongside a complex technology landscape.

Misalignment across business functions is not a product problem. Network, identity, endpoint, and application teams each own a piece of the model, and in most organisations they report to different people with different priorities.

Dropping the eXtended

The name history is compact and informative.

Forrester's 2020 evaluation was titled Zero Trust eXtended Ecosystem Platform Providers. The extended framing distinguished a core set of capabilities from a broader ecosystem around it.

The Q3 2023 evaluation dropped the word, and Forrester explained why: many capabilities previously considered extended had become core. That edition scored fourteen vendors against twenty eight criteria covering areas including analyst experience, centralised management, and ecosystem.

Microsoft placed as a Leader in that edition, with Forrester noting a vision for end-to-end guidance on implementing the model while leveraging AI.

The Q3 2025 edition dropped Providers as well, leaving Zero Trust Platforms, following a Landscape published in Q1 2025 that mapped the market first.

Fourteen vendors in 2023, ten in 2025. Criteria from twenty eight to twenty two, split as fourteen current offering and eight strategy. A market consolidating and an evaluation narrowing, which is the signature of capabilities becoming table stakes.

Inside The Forrester Wave: Zero Trust Platforms, Q3 2025

Published on 10 July 2025 by Joseph Blankenship with Faith Born and Peter Harrison, the evaluation scored ten vendors using vendor questionnaires, executive strategy briefings and demonstrations, and interviews with up to three reference customers each.

The full field: Akamai Technologies, Broadcom, Check Point Software Technologies, Cisco, Cloudflare, Fortinet, Microsoft, Palo Alto Networks, Trend Micro, and Zscaler.

Palo Alto Networks placed as a Leader with the highest score in the current offering category, on a combination of zero trust, secure access service edge, and network security capability.

Microsoft placed as a Leader with the highest score in the strategy category. Forrester cited its vision for proactive security architecture powered by AI agents automating complex security, IT, and productivity tasks.

Check Point Software also placed as a Leader, recognised for an AI-first strategy and unified management.

What the vendor list tells you

Read those ten names and notice what kind of company they are.

Akamai, Cloudflare, and Zscaler come from content delivery and network edge. Check Point, Fortinet, and Palo Alto Networks are network security companies. Cisco is networking. Broadcom holds a portfolio assembled from network and endpoint security acquisitions. Trend Micro is endpoint and workload security. Microsoft is the outlier, arriving from identity and productivity.

What is absent is more revealing. No pure identity providers. No dedicated privileged access management vendors. No standalone endpoint detection specialists. No data security posture vendors.

Zero trust is, in principle, an identity-centric model. Every access decision turns on who is asking, on what device, in what context. Yet the platform market that formed around it is dominated by companies whose heritage is inspecting and controlling network traffic.

The reason is not that identity does not matter. It is that consolidation happened where the enforcement points already were. A vendor with agents on endpoints, gateways in the network path, and a policy engine in between can enforce decisions. An identity vendor knows who the user is and generally depends on someone else to act on that knowledge.

For a buyer this has a practical consequence. If your identity infrastructure is the weakest part of your zero trust programme, and for many organisations it is, a platform from this evaluation improves enforcement without fixing the input those enforcement decisions rely on. The categories are complementary rather than substitutable, and no tier placement in this Wave tells you about the identity side.

The identity problem is about to get larger

Microsoft's citation points at something that changes the model's arithmetic.

Systems built for human identities now have to manage a growing population of machine identities, each with its own access profile and risk. Agentic AI accelerates this, because agents create and collaborate with other agents and scale faster than traditional identity models were designed to handle.

Zero trust assumes every access request can be attributed to an identity whose context is evaluable. That assumption was built around humans, who have managers, joiners-movers-leavers processes, and a finite rate of creation.

An agent acting on behalf of a user, calling another agent, which calls a service, breaks several things at once. Which identity is making the request? Does the agent inherit the user's full permissions, which is almost never what anyone intends? Can the chain be reconstructed afterwards? Is the agent's context, a thing with no device posture and no location, evaluable at all?

None of these have settled answers, and they are the same questions that produced Forrester's separate category for agentic control planes. A zero trust platform that treats agents as service accounts is applying a model designed for a different problem.

Anyone buying in this category with a serious AI programme should be asking specifically how the platform handles non-human identities, delegated authority narrower than the delegator, and provenance across an agent chain. The vendors will differ considerably, and the criteria in this Wave were not designed to surface it.

What you can actually buy

Return to the statement Forrester leads with. No platform makes an organisation zero trust.

What a platform buys is consolidation of enforcement, fewer policy engines to keep consistent, and a reduction in the integration work that otherwise consumes the programme. Those are real and worth paying for, and they are the reason this market exists.

What it cannot buy is the decision about who should have access to what, the organisational alignment between the teams that own each domain, the data classification work that determines what needs protecting most, or the willingness to remove access that people currently have and would rather keep.

Every one of those is a decision, not a capability, and each is harder than the procurement.

The organisations that get value from this category are the ones that made those decisions first and bought a platform to enforce them. The ones that buy first end up with a well-integrated set of controls enforcing a policy nobody agreed on, which is a more expensive version of the position they started in.

Forrester has been saying a version of this since it named the model. It is worth noticing that the firm keeps saying it in the same documents that vendors use to sell against.

Analyst Source

Forrester Research

The zero trust model originated at Forrester, and the firm evaluates the platform market that formed around it. Coverage was published as Zero Trust eXtended Ecosystem Platform Providers in Q3 2020, Zero Trust Platform Providers in Q3 2023 covering 14 vendors against 28 criteria, and Zero Trust Platforms in Q3 2025 covering 10 vendors against 14 current offering and eight strategy criteria, following a Landscape published in Q1 2025.

Source research

Forrester does not endorse any vendor named here, and tier placement should not be read as a recommendation to buy.