What does Zscaler Cellular mean?
Zscaler Cellular is an approach to routing cellular traffic from devices through a controlled, policy-based security path. It is not only the SIM that is decisive, but the end-to-end architecture of carrier, identity, target resources, policy, telemetry and responsibility.
The problem: Agentless devices get stuck between mobile communications and the corporate network
Many IoT and OT devices do not allow a classic security agent. At the same time, they need access to a few APIs, control services or cloud endpoints. Private APNs, VPNs, and on-premises firewalls can solve this, but they often create additional infrastructure and exceptions that are difficult to scale.
A Zero Trust model must therefore clarify for each device type which goals may be achievable, how devices are identified, what happens in the event of loss or misuse, and who handles carrier, platform and operational errors.
One operator manages thousands of charging points with a mobile phone connection. Each charging point requires defined backend targets, but must not be treated as a general network part. A pilot must therefore test SIM/eSIM, carrier routing, permitted destinations, failure scenarios and operational handovers together.
The five technical levels
A resilient cellular architecture separates connection, identity, access, and operations.
Device & SIM
Device type, modem, SIM/eSIM lifecycle, ownership, and locking process.
Carrier & Data Path
Roaming, APN, Breakout, Region, Latency, and Failure Behavior.
Policy & Objectives
Allowed FQDNs, IPs, protocols, APIs, and direction of traffic.
Telemetry
Connection status, policy events, device mapping, and incident data.
The establishment
RACI for Carrier, Zscaler, Device Manufacturer, Customer, and Managed Service.
Pilot
Representative use case with measuring points, exceptional cases and fallback path.
What needs to be checked before making a decision?
- What types of devices and firmware versions exist?
- What goals and protocols are really needed?
- Which carrier and eSIM partner is confirmed?
- How are devices uniquely assigned and locked?
- What are the region, privacy, and availability requirements?
- Who is responsible for support and escalation per fault domain?
Architectural note: Zscaler Cellular complements OT segmentation and device security. A suitable pilot takes into account the device type, supported product scope, carrier/eSIM model and the full operating path.
How SourcingBlox makes the use case resilient
We start with a type of equipment and a clear operational goal.
Discovery & Architecture
Capture device, data path, destinations, carrier, policy, and RACI as a verifiable target image.
Pilot
Test a representative use case with measurement points, faults and fallback option.
Managed Cellular Zero Trust
After acceptance, structure monitoring, changes, escalations and regular policy reviews.
Typical mistakes
- Only talk about the SIM and don't model backend goals.
- Do not test roaming, outage and carrier responsibility.
- Squeeze IoT, OT, and user devices into the same policy template.
- Publicly pledge performance without a confirmed SKU and partner roles.
Frequently Asked Questions
Does every device need an agent?
The specific cellular approach is aimed at devices where a classic agent is not useful. However, eligibility depends on the device, cellular profile, and supported data path.
Does Cellular replace an OT firewall?
Not automatically. Zones, local communications, and safety requirements may require additional controls.
What does a pilot start with?
With one device type, few allowed targets, and clear criteria for connection, policy, latency, telemetry, and support.
Technically classifying an IoT/OT use case.
We check the device, carrier, data path, policy and operating limits before planning a pilot.
Related Content
Sources and further information
Product scope, availability and partner roles must be verified before publication.
