
Portnox
Cloud-native zero trust access control for every identity — human, device and AI — across networks, applications and infrastructure.
By Portnox · 4.0/5 Value-Position score (estimate)
Positioning guardrails
Best for
- Mid-market to Fortune 500 IT/security teams replacing legacy on-premises NAC appliances
- Organizations standardizing passwordless 802.1X access across wired, wireless and VPN
- Teams that want agentless ZTNA to replace or reduce dependence on VPN for remote staff
- Regulated environments needing audit-ready visibility of devices, connections and privileged admin actions
- Environments with large BYOD, IoT/OT and unmanaged device populations that must be profiled and quarantined
Ideal size: 100–5,000+ devices people · Mid-market to enterprise with a dedicated network or security team
Not for
- Buyers who need public list pricing before talking to sales
- Organizations requiring fully on-premises or air-gapped deployment of the access control layer
- Very small sites with a few hundred devices and no compliance driver
- Teams looking for a broad SASE/SSE suite rather than network and application access control
- Networks that cannot deploy 802.1X or certificate-based authentication at all
Value metrics scorecard
Time-to-Value
Days to a few weeks
~14 days to first production value
Total Cost of Ownership
On request
Per-device / per-user subscription, quoted by sales; 12, 24 or 36-month terms with volume discounts. TACACS+ is licensed per admin, with 1 admin covering 100 devices.
Implementation Friction
2/5
Engineering + admin effort required
Value-Position score
out of 5 · model estimate
Full cost breakdown
Mandatory implementation fee
None
Seat tiers
Device-count based (TACACS+: 1 admin per 100 devices); volume discounts available; full-capability free trial for 30 days
Add-on costs
- Extended device data retention: +30 days at $0.99 per device per year
- Extended guest package (50 guests) and additional SMS package (1,000 messages)
- Certificate authority services at $1 per device
- Optional onboarding, device provisioning and certificate enrollment services
Company & support
Who is behind Portnox, and how your team gets help once it is live.
Company
- Founded
- Not recorded
- Headquarters
- Not recorded
How you get support
- PhoneNot listed
- EmailPaid plans
- Live chatNot listed
- Support portal / ticketsPaid plans
- Community forumAll plans
- Help centre / docsAll plans
- Dedicated account managerNot listed
- In person / on-siteNot listed
- Hours
- 24/7
- Response time
- Not stated
Support page states a global support team available 24x7x365 plus regional coverage during local business hours (AMER 8-5, EMEA/APAC 7-4). Cases are submitted via success.portnox.com or by email; the pricing page lists 24x7x365 Support and Community Support across plans.
“Not listed” means the vendor’s public pages don’t mention that channel, not that it is unavailable. Ask about it during evaluation.
Market position
Where Portnox sits against its closest alternatives. Pick any two of cost, speed, friction and buyer score, and up to 9 companies to compare.
Quadrant view
Typical annual cost × Time-to-value
The lines cross at the median of the solutions shown, so about half sit on each side of each line.
Companies on the chart 6 / 10
- Portnox
- Zluri
- Flagright
- Vanta
- Worksuite
- Expel
Add or change companies
Up to 10 companies including Portnox. Listed closest first.
Stack fit signal
Compatibility with standard B2B ecosystems.
No supported MCP path today, so it cannot be driven from an AI client.
AI & MCP readiness
What Portnox ships in AI, and what it asks of your ecosystem.
Compliance attestations
* IAPP AIGP certifies individuals, not products. It means named staff hold the credential — not that the platform does.
Bottom line
Portnox is a cloud-native zero trust access control platform that combines NAC, RADIUS, ZTNA and cloud TACACS+ in one subscription. It discovers and profiles managed, unmanaged, IoT and BYOD devices, enforces passwordless 802.1X and certificate-based access across wired, wireless and VPN, and continuously verifies device posture and risk with automated quarantine. Priced per device or per admin on a quote basis with 12/24/36-month terms, it targets mid-market and Fortune 500 security teams in healthcare, finance, hospitality and education.
Frequently asked questions
How is Portnox priced, and what commitment is required?
Portnox sells per-device and per-user subscriptions rather than publishing list prices. The vendor states subscription terms of 12, 24 or 36 months with further discounts for longer terms, volume discounts available through sales, and a free 30-day trial of its zero trust access control capabilities. Add-ons are charged separately: extended device data retention at $0.99 per device per year per additional 30 days, extended guest and SMS packages, and certificate authority services at $1 per device. TACACS+ is licensed per admin, with each license covering 1 admin and 100 devices.
How long does deployment take and is professional services required?
Portnox states deployments are operational in days rather than quarters because the platform is cloud-native with no on-premises appliances, and that customers can scale to 100,000 devices without professional services. Optional onboarding, device provisioning and certificate enrollment service tiers exist for organizations wanting extra help. Realistic effort rises if you must roll out 802.1X and certificate-based passwordless authentication across a large wired, wireless and VPN estate.
Can Portnox replace our VPN for remote and hybrid workers?
According to the vendor, yes. Portnox ZTNA is described as cloud-native, passwordless, agentless and clientless, and is positioned as a replacement for traditional VPNs. Users reach only the applications they are authorized for instead of the whole network, and every access attempt is evaluated in real time against device posture signals such as OS version, endpoint protection and encryption, with non-compliant devices blocked or guided through automated remediation.
What does Portnox integrate with?
Portnox publishes integrations across identity (Entra ID, Okta, Active Directory, JumpCloud, OneLogin, OpenLDAP, Google Workspace), endpoint and MDM (Intune, Jamf, Kandji, CrowdStrike, SentinelOne, Huntress, Sophos), SIEM and monitoring (Splunk, Azure Sentinel, Sumo Logic, Datadog, PagerDuty) and network vendors (Cisco, Aruba, Juniper, Meraki, Fortinet, Palo Alto). A documented REST API described in Swagger supports custom integrations and CRUD automation for devices, accounts, NASs and sites.
What security and compliance assurances does Portnox provide?
Portnox's site states the platform is continuously validated through third-party penetration testing and an active bug bounty program, and that it is SOC 2 Type II compliant, with 99.999% uptime design and cloud regions in the US, EU and APAC. No dedicated trust-centre or compliance page was among the sources reviewed, so buyers should request current reports, the shared-responsibility matrix and data-residency commitments directly from the vendor before relying on any certification claim.