LICENSEWARE

Zscaler workload, branch and consumption metrics

This article is about the Zscaler licence metrics that are not per-user seats: workloads, gateways, sites and devices, cellular data pools, data stores, assets, user identities, SaaS applications and AI tokens. For seats and the vendor overview, see Zscaler licensing. It is not legal advice.

On This Page

Zscaler workload, branch and consumption metrics are the licence units Zscaler uses for things other than people: servers and cloud workloads, branch sites and the devices behind them, cellular SIMs, cloud data stores, vulnerability assets, identities, SaaS applications and generative AI tokens. Each product has its own licensing and fair use article on the Zscaler Help Portal. Most follow the same pattern: a purchased quantity, a periodic review by Zscaler “to ensure license compliance”, and a fair use threshold expressed as an average.[3][4][8] Under the End User Subscription Agreement, usage above purchased quantities, including usage limits in the Documentation, must be purchased promptly.[15] Several of these metrics are forms of subscription and consumption licensing rather than device licensing in the classic sense, because the unit is observed traffic or objects, not installations.

Editions

The products covered here are sold as standalone subscriptions or add-ons. They include Zero Trust for Workloads (Workload Communications and Zero Trust Gateway), Zero Trust Branch and Branch Connector, Zero Trust Device Segmentation, Zscaler Cellular, Data Security Posture Management (DSPM), Unified Vulnerability Management (UVM), Identity Protection, SaaS Security Posture Management (SSPM) and AI Guard.[3][4][5][7][8][9][10][11][12] Package names and sizes are listed on Zscaler platform bundles and editions.

Metrics

Product Zscaler metric Catalog row Zscaler definition (summary) 
ZIA / ZPA workloads Workload Workload A unique domain name, an IP address, or a set of IP addresses; VMs, VDI, serverless functions and containers[1] 
Zero Trust Gateway Gateway Instance; Monthly Traffic Gateway Instance A Zero Trust Gateway instance in an Availability Zone in any AWS region; GB of workload traffic per month[3] 
Branch Connector; Device Segmentation Device Device An endpoint such as a printer, camera, badge reader, RF scanner, IoT, IIoT, IoMT, server or desktop instance with a unique IP address[5] 
Device Segmentation Gateway Gateway Hardware or a virtual machine sitting between different networks or applications[5] 
Zero Trust SD-WAN, IoT Site Site A site or location subscription[1] 
Zscaler Cellular Cellular device Cellular Device An endpoint with a Zscaler SIM or e-SIM, or a unique IP address accessing Cellular Edge[7] 
DSPM Data store Data Store A single cloud service instance such as a VM, storage bucket or database[8] 
UVM Asset Asset Total assets processed and stored in UVM[9] 
Identity Protection User identity User Identity Each unique individual represented in the application, whether or not they log in[10] 
AI Guard Token Token Generally four characters (UTF-8 code points, excluding white space)[12] 
DNS-Based Guest WiFi Security DNS Transaction; Location DNS Transaction, Location A recursive DNS query; a specific access point to the internet[13] 

The SLA document defines further terms: a Device as a subscription for each physical or virtual machine running an operating system on which the agent is installed, and a Workload as a subscription for a single cloud workload (virtual machines, database services, cloud storage and similar IaaS and PaaS resources).[13] These differ from the Help Portal wording above. The document used for a given SKU is the one referenced in the Order.

Counting / floors

Workloads (replacement effective 2024-04-19). The separate Workload Communications policy was replaced on 19 April 2024 by the ZIA and ZPA policies and their Workload metric.[2] Where a subscription is licensed per workload instead of per GB of monthly traffic, each unique domain name, IP address or set of IP addresses counts as one workload.[1] Platform bundles include a workload traffic allowance per subscribed user, covered on the bundles page. Catalog proof: Workload Communications policy replaced by ZIA and ZPA Workload metric.

Zero Trust Gateway (undated, retrieved 2026-09-26). Two licences apply: Monthly Traffic (workload GB, which includes ZIA and ZPA entitlements for workloads) and Gateway Instance. Each 1 GB of ZIA and ZPA egress traffic brings 10 GB for Layer-4 policy enforcement on east-west and ingress flows. At least two gateway instances are needed to use a gateway in an AWS region.[3] Catalog proof: Zero Trust Gateway: 10 GB of Layer-4 enforcement per 1 GB egress; two instances per region.

Zero Trust Branch Connector (undated, retrieved 2026-09-26). Licensed by the number of sites or locations protected and the data usage of protected devices. Devices are counted as unique IP addresses at an hourly interval, averaged over the month. Endpoints and gigabytes covered by Guest Wi-Fi SKUs are excluded.[4] Fair use is an average data transfer of 100 GB per month from 50 devices or servers per site.[4] Because the count is an hourly average, a device that appears briefly counts less than one that is always online. Catalog proof: Branch Connector devices counted hourly by unique IP and averaged monthly.

Zero Trust Branch and Device Segmentation (undated, retrieved 2026-09-26). Zero Trust Branch is licensed by the number of appliances enabled for protected devices during the term.[6] Zero Trust Device Segmentation (formerly Airgap) is licensed by gateways and devices. Installed gateways are counted and applied to the subscription term, and additional entitlements allow more devices per gateway.[5] Catalog proof: Device Segmentation counts installed gateways over the term.

Zscaler Cellular (undated, retrieved 2026-09-26). Protected devices are the Zscaler SIMs purchased, or the unique IP addresses accessing Cellular Edge. A data pool is purchased for them. It resets on the first day of each calendar month, and unused data does not carry over.[7] Above the pool, service continues and overage is charged automatically at the per-GB rate in the Order Form. The overage is co-terminous with the Subscription Term and “uncapped unless otherwise expressly stated”. Zscaler provides no real-time usage alerts, spending caps or throttling.[7] Catalog proof: Zscaler Cellular data pool resets monthly and overage is uncapped.

DSPM (undated, retrieved 2026-09-26). Data stores are counted as the unique VMs (every instance counts as one), storage buckets, databases and other supported services configured for scanning over the subscription period. Scanned volume should not exceed 1 TB per data store on average across all subscribed data stores, and exceeding it requires a volume add-on.[8] Catalog proof: DSPM fair use: average scanned volume under 1 TB per data store.

UVM and Identity Protection (undated, retrieved 2026-09-26). UVM counts assets processed and stored. Its fair use limits are no more than 3 MB of uncompressed data per asset per day and 4K queries per account per day, both on average.[9] Identity Protection counts user identities processed and stored, “regardless of whether such individual directly accesses or logs into” the application, with the same 3 MB and 4K limits per user identity.[10] Catalog proof: UVM fair use: 3 MB per asset per day and 4K queries per day, Identity Protection counts every represented identity.

SSPM (undated, retrieved 2026-09-26). Licensed by seat (unique users over the previous rolling 90 days) and by application. A “2 Apps” subscription covers up to two supported SaaS applications, with one tenant each. “The seat-based licensing requirement continues to apply in conjunction with any application-based licenses.”[11] Fair use is average data transfer per seat below two times the cloud-wide average, currently 8 GB per seat per month.[11] Catalog proof: SSPM seat licensing applies alongside application licenses.

AI Guard (undated, retrieved 2026-09-26). Licensed on a platform subscription fee plus the number of tokens purchased. Consumption is the total number of tokens in prompts and responses.[12] For the wider topic, see generative AI licensing. Catalog proof: AI Guard counts tokens in prompts and responses.

Virtualization & partitioning

Virtual machines matter to these metrics only as objects to count. A VM can be a workload,[1] a DSPM data store,[8] or a Device Segmentation gateway.[5] No processor, core or host-level rules apply, and nothing like the partitioning rules described in virtualization and partitioning. Zscaler-provided hardware, such as Zero Trust Branch appliances, is governed by the Hardware Usage Terms. The hardware stays Zscaler property and may not be moved to another location without prior written approval.[14] If Zscaler determines that usage exceeds hardware capacity, the customer must add or upgrade hardware, or reduce utilization, within 30 days.[14] Hardware must be returned within 21 calendar days after the term ends.[14] Catalog proof: Hardware remains Zscaler property and must be returned within 21 days of term end.

Cloud / BYOL

Zero Trust Gateway instances are provisioned in AWS regions and Availability Zones, and each instance licence is valid “in any Amazon Web Services (AWS) region”.[3] DSPM data stores are cloud service instances in the customer’s public cloud environments.[8] None of these products has a bring-your-own-license model.

Programs

These products follow the general Support Services and SLA Service Credits programs. The SLA document lists separate SLAs for DSPM, UVM, Zscaler Cellular, Zero Trust Device Segmentation, Zero Trust Gateway, Zero Trust Branch, AI Guard, Identity Protection and others.[13]

Out of scope

  • Workload Communications feature tiers (Standard, Advanced, Advanced Plus), apart from their listing on the bundles page.
  • Posture Control (ZPC) and other products under End-of-Sale notices.
  • Per-GB overage rates and add-on prices, which are set in the Order Form.
  • Agentic SecOps, AI Asset Management, Endpoint AI Security and other newer products whose licensing articles were not catalogued in this pass.

Catalog rows

Catalog rows for this article, grouped by table.

References

  1. ZIA Licensing and Fair UseWorkload and Site definitions. Zscaler Help Portal (help.zscaler.com). Undated.Retrieved 2026-09-26.
  2. Zscaler Workload Communications Licensing and Fair UseReplacement notice.Effective 2024-04-19. Retrieved 2026-09-26.
  3. Zscaler Zero Trust Gateway Licensing and Fair UseZscaler Help Portal. Undated.Retrieved 2026-09-26.
  4. Zero Trust Branch Connector Licensing and Fair UseZscaler Help Portal. Undated.Retrieved 2026-09-26.
  5. Zscaler Zero Trust Device Segmentation Licensing and Fair UseZscaler Help Portal. Undated.Retrieved 2026-09-26.
  6. Zscaler Zero Trust Branch Licensing and Fair UseZscaler Help Portal. Undated.Retrieved 2026-09-26.
  7. Zscaler Cellular (SIM and Cellular Edge) Licensing and Fair UseZscaler Help Portal. Undated.Retrieved 2026-09-26.
  8. DSPM Licensing and Fair UseZscaler Help Portal. Undated.Retrieved 2026-09-26.
  9. Zscaler Unified Vulnerability Management (UVM) Licensing and Fair UseZscaler Help Portal. Undated.Retrieved 2026-09-26.
  10. Zscaler Identity Protection Licensing and Fair UseZscaler Help Portal. Undated.Retrieved 2026-09-26.
  11. Zscaler SaaS Security Posture Management (SSPM) Licensing and Fair UseZscaler Help Portal. Undated.Retrieved 2026-09-26.
  12. Zscaler AI Guard Licensing and Fair UseZscaler Help Portal. Undated.Retrieved 2026-09-26.
  13. Service Level Agreements and Support ServiceDefinitions 1.2, 1.3, 1.7, 1.15.Effective 2026-09-21. Retrieved 2026-09-26.
  14. Hardware Usage Terms§1, §2.1(f), §4.3, §7. Undated.Retrieved 2026-09-26.
  15. End User Subscription Agreement§4.2.Effective 2026-08-01. Retrieved 2026-09-26.

See also

Esc