Cloudflare Zero Trust Pricing in 2026: What the Tiers Leave Out
.jpg)
Short answer: Cloudflare Zero Trust pricing is built around the network, not around the data controls. The free and self-serve tiers give you access, tunnels and basic gateway policy at a price that is genuinely hard to beat. Every capability that decides whether you can actually govern SaaS and AI egress, meaning full DLP, unlimited CASB, remote browser isolation and long log retention, sits behind the Contract plan. That makes the published per-user number a poor predictor of the bill you end up signing.
This is a falsifiable claim, and it is easy to test. Take your requirements list, walk it down Cloudflare's own plan comparison, and count how many of your must-haves fall in the Contract column. If the answer is most of them, the self-serve price was never your price.
We have covered the architectural side of this in our head-to-head on Zscaler versus Cloudflare Gateway. This post is narrower: what you are actually buying at each tier, and where the line items hide.
How Cloudflare tiers its Zero Trust product
Cloudflare sells Zero Trust in three shapes. There is a free tier aimed at small teams, a self-serve per-user plan you can buy with a credit card, and an enterprise Contract plan negotiated with sales. Cloudflare publishes current per-user pricing on its own plans page, and that number is worth reading as the floor rather than the estimate.
The structure itself is the most generous in the SSE category. Nobody else gives away working zero trust access for a small team. If your requirement is replacing a VPN for a handful of engineers reaching internal apps, Cloudflare at the self-serve tier is a strong answer and this post will not change your mind.
The gap opens when the requirement shifts from access to data. Access is a routing problem and Cloudflare is exceptional at routing. Data control is an inspection problem, and inspection is where the tiering bites.
What sits behind the Contract plan
These are the capabilities Cloudflare gates to Contract, and each one maps to a requirement most security teams treat as table stakes.
- Full DLP: real data loss prevention, rather than a limited set of detections, is a Contract capability.
- Unlimited CASB: the inline CASB covers roughly 25 application categories, and removing that ceiling is a Contract capability.
- Remote browser isolation: gated to Contract.
- Extended log retention: the retention window you need for an investigation or a compliance audit is gated to Contract.
- Enterprise support and SLAs: the response commitments that matter during an incident come with the contract, not the credit card.
None of that is unusual for the industry. It is worth naming clearly because Cloudflare's headline pricing invites a comparison against vendors whose entry price already includes DLP, and that comparison is not like for like.
The AI governance line item
If the reason you are pricing an SSE product in 2026 is AI, read this part carefully.
Cloudflare has two things with AI in the name and they solve different problems. AI Gateway is a developer product: it proxies your own application's calls to model APIs, adds caching and rate limiting, and gives developers observability. It is not employee governance and it was never meant to be.
AI Prompt Protection is the employee-facing one. It shipped in beta in August 2025 covering roughly four applications, with header-based tenant control limited to Google and Microsoft properties. That is real progress and it is also early. If your requirement is allowing the corporate ChatGPT workspace while blocking personal accounts on the same domain, check the current coverage against your actual list of AI tools before you assume it is handled.
The wider point is that AI governance at most SSE vendors is a bolt-on with its own SKU and its own tier. That is the structural thing to price for, not the feature bullet.
Cloudflare and dope.security, priced side by side
Two pricing philosophies, same set of questions.
- What the entry price covers: Cloudflare's self-serve tier covers access and basic gateway policy; dope.security includes the SWG, SSL inspection, URL filtering, Cloud Application Control and analytics in the core product rather than splitting them across tiers.
- Where DLP lives: full DLP is a Cloudflare Contract capability; Dopamine DLP runs on the dope.endpoint agent as part of the platform, classifying uploads and AI prompts through zero-retention APIs under US Patent 12,464,023.
- Where CASB lives: Cloudflare's inline CASB is capped at roughly 25 categories below Contract; CASB Neural ships with dope.security and scans Google Workspace and Microsoft 365 for exposed files with one-click remediation.
- Tenant control for AI: Cloudflare's header-based tenant control currently covers Google and Microsoft; dope.security enforces tenant restrictions on the device across the AI tools it covers, natively, without an add-on tier.
- What scale costs: proxy pricing tends to track traffic volume and module count; on-device inspection does not add a network hop per user, so the cost curve is about seats rather than throughput.
- What you can predict: multi-tier SSE contracts are notoriously hard to forecast at renewal; a single product with a single console gives you one line to model.
The reliability cost nobody prices
Cloudflare's network is fast and its uptime record is generally strong. It is also true that on November 18 2025 a single oversized configuration file produced global 5xx errors for roughly five hours, taking well-known third-party services down alongside Cloudflare itself. In November 2023, customers could not reach their logs during an incident.
The architectural reason matters more than either date. Cloudflare runs uniform anycast, which is what makes it fast, and it also means there is no regional isolation. A global control plane problem is global by design. That is not a reason to avoid Cloudflare. It is a reason to ask what your enforcement does when the control plane is unavailable, and to price the answer.
dope.security handles that case differently because inspection is already local. The agent keeps enforcing cached policy when the console is unreachable, which is a different failure mode from losing both enforcement and visibility at once.
What to model before you sign
Four numbers turn a plan comparison into a budget.
- Your seat count at the tier that actually contains your must-haves, not the tier in the marketing comparison.
- The log retention window your compliance requirement specifies, and what that window costs.
- The AI tools your people already use, checked one by one against current tenant-control coverage.
- The renewal multiple, asked directly: what does this contract look like in year three?
If you want the architectural alternative rather than the price sheet version, our roundup of Cloudflare Zero Trust alternatives and the Cloudflare Gateway alternative guide both go deeper, and the Cloudflare versus Zscaler comparison covers the other side of the shortlist.
Where this lands
Cloudflare Zero Trust is the best value in the category for network access, and that is a real compliment rather than a backhanded one. It is priced like a network product because it is one. The moment your requirement becomes what data is allowed to leave, and on whose account, the price you compared is not the price you pay.
dope.security prices the other way around, because the data controls are the product. The SWG, Fly Direct inspection on the device, CASB Neural and Dopamine DLP live in one platform under one console, so the capability you need on day one is not sitting behind a call with sales. The City of Visalia, a 700-user municipality, moved to on-device SSL decryption without adding operational overhead, and Greylock Partners went from first proposal to signed contract in 27 days.
Want a number you can actually plan against? Book a 20-minute demo and we will price your real requirement list, not a tier chart.
Frequently Asked Questions
Is Cloudflare Zero Trust really free?
There is a genuine free tier aimed at small teams, and it covers zero trust access to internal applications plus basic gateway policy. It is not a trial and it is not time limited. What it does not cover is the data-control layer: full DLP, unlimited CASB, remote browser isolation and extended log retention are Contract capabilities.
What is the difference between Cloudflare AI Gateway and AI Prompt Protection?
AI Gateway is a developer tool that proxies your application's own calls to model APIs and adds caching, rate limiting and observability. AI Prompt Protection is the employee-facing control, which shipped in beta in August 2025 across roughly four applications with header-based tenant control limited to Google and Microsoft. Only the second one is AI governance in the sense a security team means it.
Does Cloudflare Zero Trust include DLP?
Partially. Basic detections are available at lower tiers, but full DLP is gated to the Contract plan. If DLP is the reason you are buying, price the Contract tier from the start rather than the self-serve number, and compare it against products that include data controls in the core license.
How does Cloudflare Zero Trust pricing compare to Zscaler and Netskope?
Cloudflare's entry price is meaningfully lower and its free tier has no equivalent at either vendor. All three, though, put the data-protection modules in higher tiers or separate SKUs: Zscaler places prompt DLP behind its Data Protection add-on with AI Guard and AI Scanning licensed separately, and Netskope puts full inline DLP plus threat plus AI in its higher Max Advantage tier with API CASB as its own SKU.
What happens to enforcement if Cloudflare has an outage?
Because Cloudflare runs uniform anycast with no regional isolation, a control plane problem is global. The November 18 2025 incident produced global 5xx errors for roughly five hours from one oversized configuration file, and in November 2023 customers could not reach their logs mid-incident. Ask any cloud-delivered vendor what enforcement does when their control plane is unreachable; dope.security keeps enforcing cached policy on the device.
Is an on-device SWG cheaper than a cloud proxy?
It depends on how you are charged, but the cost curves differ in shape. Proxy pricing tends to track traffic volume and the number of modules turned on, while on-device inspection adds no network hop per user, so cost tracks seats. The bigger saving is usually in IT hours: dope.security deployments run in days through existing MDM, and one Fortune 100 customer scaled from 900 devices to more than 18,000 in weeks.


.jpg)
.jpg)
.jpeg)

