{
  "slug": "zero-trust-migration-cost",
  "title": "Zero-Trust Migration Cost Calculator",
  "heading": "Zero-Trust Architecture Migration Cost Calculator",
  "category": "financial",
  "url": "https://www.revenuelab.fyi/toolbox/zero-trust-migration-cost",
  "summary": "Budget identity, device, network, and app segmentation work for a zero-trust rollout.",
  "description": "Zero-trust migration is a multi-year program, not a product purchase, and vendors selling a single 'zero-trust' box tend to understate the identity, device management, and network segmentation work that actually makes the model function. This calculator breaks estimated cost into four workstreams that map to how most real migrations are scoped: identity and access (SSO, conditional access, MFA everywhere), device trust (endpoint posture checking, MDM coverage), network micro-segmentation (moving off flat VLANs to per-application or per-service access policies), and application proxy/ZTNA replacing VPN. Each workstream scales roughly with user count or application count rather than being a flat fee, and the model applies a phasing discount because year-2 and year-3 work builds on year-1 identity foundations and costs less per unit than the initial buildout. Use it for multi-year budget planning conversations, not vendor quote replacement.",
  "formula": "Total 3-year cost = identity cost/user × users + device cost/user × users + network segmentation cost/app × apps + ZTNA cost/user × users, with a phasing discount applied to years 2-3.",
  "dateModified": "2026-09-30",
  "run_url": "https://www.revenuelab.fyi/api/public/calc?tool=zero-trust-migration-cost",
  "inputs": [
    {
      "id": "users",
      "label": "Users to cover",
      "kind": "number",
      "hint": null,
      "default": 800,
      "unit": null,
      "min": 1,
      "max": null
    },
    {
      "id": "apps",
      "label": "Applications/services to segment",
      "kind": "number",
      "hint": null,
      "default": 40,
      "unit": null,
      "min": 1,
      "max": null
    },
    {
      "id": "identityCostPerUser",
      "label": "Identity/MFA cost per user (year 1)",
      "kind": "number",
      "hint": null,
      "default": 60,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "deviceCostPerUser",
      "label": "Device trust cost per user (year 1)",
      "kind": "number",
      "hint": null,
      "default": 45,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "networkCostPerApp",
      "label": "Network segmentation cost per app (year 1)",
      "kind": "number",
      "hint": null,
      "default": 3000,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "ztnaCostPerUser",
      "label": "ZTNA/app-proxy cost per user (year 1)",
      "kind": "number",
      "hint": null,
      "default": 40,
      "unit": null,
      "min": 0,
      "max": null
    }
  ],
  "outputs": [
    {
      "id": "threeYearTotal",
      "label": "3-year total migration cost",
      "format": "currency",
      "hint": null,
      "primary": true
    },
    {
      "id": "year1",
      "label": "Year 1 cost (buildout)",
      "format": "currency",
      "hint": null,
      "primary": false
    },
    {
      "id": "year2",
      "label": "Year 2 cost (expansion)",
      "format": "currency",
      "hint": null,
      "primary": false
    },
    {
      "id": "year3",
      "label": "Year 3 cost (maturity)",
      "format": "currency",
      "hint": null,
      "primary": false
    },
    {
      "id": "costPerUser",
      "label": "3-year cost per user",
      "format": "currency",
      "hint": null,
      "primary": false
    }
  ],
  "worked_example": {
    "inputs": [
      "Users to cover: 800",
      "Applications/services to segment: 40",
      "Identity/MFA cost per user (year 1): 60",
      "Device trust cost per user (year 1): 45",
      "Network segmentation cost per app (year 1): 3000",
      "ZTNA/app-proxy cost per user (year 1): 40"
    ],
    "outputs": [
      "3-year total migration cost: $356,360",
      "Year 1 cost (buildout): $236,000",
      "Year 2 cost (expansion): $70,800",
      "Year 3 cost (maturity): $49,560",
      "3-year cost per user: $445"
    ]
  },
  "how_to": {
    "title": "How to use this",
    "steps": [
      "Enter users to cover.",
      "Enter applications/services to segment.",
      "Enter identity/mfa cost per user (year 1).",
      "Enter device trust cost per user (year 1).",
      "Enter network segmentation cost per app (year 1).",
      "Enter ztna/app-proxy cost per user (year 1).",
      "Read your 3-year total migration cost on the right — it updates as you type.",
      "Hit Share to keep the scenario or send it to someone."
    ]
  },
  "scenarios": [
    {
      "name": "Conservative",
      "description": "Lower-end numbers — what if things land soft?",
      "values": {
        "users": 480,
        "apps": 24,
        "identityCostPerUser": 35,
        "deviceCostPerUser": 25,
        "networkCostPerApp": 1800,
        "ztnaCostPerUser": 25
      }
    },
    {
      "name": "Typical",
      "description": "Defaults — the most common real-world setup.",
      "values": {
        "users": 800,
        "apps": 40,
        "identityCostPerUser": 60,
        "deviceCostPerUser": 45,
        "networkCostPerApp": 3000,
        "ztnaCostPerUser": 40
      }
    },
    {
      "name": "Ambitious",
      "description": "Higher-end numbers — what if things really pop?",
      "values": {
        "users": 1280,
        "apps": 64,
        "identityCostPerUser": 95,
        "deviceCostPerUser": 70,
        "networkCostPerApp": 4800,
        "ztnaCostPerUser": 65
      }
    }
  ],
  "limitations": [
    "Results are estimates before tax, fees, and inflation unless an input explicitly covers them.",
    "Rates are treated as fixed for the whole period — variable-rate products will drift from this projection.",
    "This is educational maths, not financial advice. Check anything contractual with the lender or your accountant."
  ],
  "faq": [
    {
      "q": "Why is year 1 so much more expensive than years 2-3?",
      "a": "Year 1 builds the identity foundation (SSO, conditional access policies, MFA enrollment) and device management baseline that everything else depends on, which is mostly one-time integration and rollout work. Years 2-3 extend that foundation to more applications and refine policies, which is incremental work on existing infrastructure rather than a fresh build."
    },
    {
      "q": "What's the single most common reason zero-trust projects stall?",
      "a": "Trying to segment the network or applications before identity and device trust are solid, which creates access friction and outages that erode organizational support for the whole program. Sequencing matters more than most vendors' marketing suggests; identity first, then device, then network, then application-level enforcement."
    },
    {
      "q": "Do I need to replace my VPN entirely?",
      "a": "Most mature zero-trust programs replace VPN with ZTNA (per-application access with continuous verification) rather than broad network-level access, since VPN grants network-level trust once connected which defeats the zero-trust principle of least-privilege, per-request verification."
    },
    {
      "q": "How do I scope 'apps to segment' realistically?",
      "a": "Start with your crown-jewel and compliance-in-scope applications (financial systems, customer data stores, source code repos) rather than trying to segment every internal tool in year one; a phased app list of 20-40 for a mid-size company is typical for the first 12-18 months."
    }
  ],
  "related": [
    "https://www.revenuelab.fyi/toolbox/soc2-audit-cost",
    "https://www.revenuelab.fyi/toolbox/mfa-rollout-roi",
    "https://www.revenuelab.fyi/toolbox/third-party-saas-sprawl-risk"
  ],
  "license": "CC-BY-4.0",
  "citation": "RevenueLab — Zero-Trust Migration Cost Calculator (https://www.revenuelab.fyi/toolbox/zero-trust-migration-cost)"
}