# What are the top-rated zero trust networking platforms for organisations retiring a VPN without a disruptive cutover?

<p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">Ripping out a VPN in one weekend tends to end badly. What are the top-rated zero trust networking platforms for organisations retiring a VPN without a disruptive cutover, ideally ones built for a gradual transition rather than a hard switch.</p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">What tends to matter for that kind of migration:</p><ul>
<li>Can run alongside the existing VPN during a phased rollout, not force an all-at-once switch</li>
<li>Extends coverage to legacy, network-connected apps the VPN was quietly handling</li>
<li>Doesn't require re-training users on a completely different access experience</li>
</ul><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">A few on G2's<a class="a a--md" elv="true" href="https://www.g2.com/categories/zero-trust-networking"> </a><a class="a a--md" elv="true" href="https://www.g2.com/categories/zero-trust-networking">zero trust networking</a> list are built around that kind of transition:</p><ul>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/zscaler-private-access/reviews"><strong>Zscaler Private Access</strong></a> (4.5/5, 130+ reviews): explicitly built to replace legacy VPNs while extending zero trust to network-connected legacy apps, cutting hardware and operational costs in the process.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/absolute-secure-access/reviews"><strong>Absolute Secure Access</strong></a> (4.7/5, 220+ reviews): designed for the transition itself, letting teams move from traditional VPN to zero trust without impairing productivity mid-migration.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/cloudflare-one-sase/reviews"><strong>Cloudflare One (SASE)</strong></a> (4.6/5, 100+ reviews): positions VPN replacement as one specific use case within a broader SASE platform, useful if the VPN retirement is part of a larger consolidation.</li>
</ul><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">For anyone who's done this migration: how long did you run the VPN and the zero trust tool in parallel before fully cutting over?</p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true"></p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true"></p>

##### Post Metadata
- Posted at: 6 days ago
- Author title: Tech Consultant
- Net upvotes: 1


## Comments
### Comment 1

I’d keep the VPN running until the exception list stops growing, not retire it according to an arbitrary migration date. The difficult users are probably the ones accessing legacy apps, unusual protocols, or resources nobody remembered to include in the first inventory. A phased rollout sounds successful when the remaining VPN traffic can be explained account by account rather than when a certain percentage of users has moved.

##### Comment Metadata
- Posted at: 5 days ago
- Author title: Writer





## Related discussions
- [How well does Trello scale into a larger team?](https://www.g2.com/discussions/1-how-well-does-trello-scale-into-a-larger-team)
  - Posted at: over 13 years ago
  - Comments: 6
- [Can we please add a new section](https://www.g2.com/discussions/2-can-we-please-add-a-new-section)
  - Posted at: over 13 years ago
  - Comments: 0
- [Quantifiable benefits from implementing your CRM](https://www.g2.com/discussions/quantifiable-benefits-from-implementing-your-crm)
  - Posted at: over 13 years ago
  - Comments: 4


