Zero trust arrived as an enterprise product category and stayed one for a decade. It was priced for organisations with a security budget, staffed by teams running a security operations centre, and pitched to buyers already fluent in identity providers and policy engines. Smaller firms read the same headlines, nodded along at the same conferences, and went back to a flat network and a legacy VPN, because nobody was forcing the issue.
Something specific changed this year, and it has little to do with smaller firms developing an appetite for security architecture. Regulators have started writing supply chains into scope, insurers have started auditing controls at renewal, and companies of every size have begun wiring AI tools into daily operations. The result is that a 60-person business can now inherit obligations it was never named in.
The Compliance Clock Is The Loudest Driver
The Cyber Security and Resilience Bill is the clearest UK example. Introduced to Parliament in November 2025, it cleared all its Commons stages in June 2026 and is now before the House of Lords, with Royal Assent expected later this year and duties phased in toward 2028. It modernises the NIS Regulations 2018, puts the NCSC’s Cyber Assessment Framework on a statutory footing, and introduces a 24-hour early warning duty alongside penalties reaching £17 million or 4% of global turnover for serious breaches.
The provision that matters for smaller organisations is the designated critical supplier. Regulators gain the power to name a supplier whose failure could seriously disrupt an essential service, and once named, that supplier carries duties comparable to an operator of essential services. The Bill also brings managed service providers into a statutory regime for the first time. A firm can therefore find itself in scope without operating in energy, health or transport, purely on the basis of who it sells to.
The EU picture has its own near-term date. The Cyber Resilience Act’s reporting obligation applies from 11 September 2026, requiring manufacturers to report actively exploited vulnerabilities within 24 hours. It covers hardware, embedded and downloadable software, and a manufacturer’s own backend where a shipped product depends on it. Browser-delivered SaaS generally sits outside, and that boundary is one of the regulation’s harder scoping questions. The obligation reaches back to products already on the market, so a small vendor is accountable for what it shipped years ago.
NIS2 remains the most uneven of the set. Only four member states met the 17 October 2024 transposition deadline. The European Commission opened infringement procedures against 23 of the rest, and national laws have been switching on at different speeds since. Its size threshold reaches medium and large entities in covered sectors, generally 50 or more employees or more than €10 million in turnover. DORA applies a different mechanism, obligating financial entities who then pass requirements to their technology suppliers by contract. PCI DSS 4.0 applies to any business touching card data, whatever the size of its IT function.
None of these frameworks say the words “buy zero trust.” What they demand, in practice, are controls a flat network and a shared VPN credential cannot honestly satisfy: least-privilege access, verified device state, segmented resources, and an audit trail showing who reached what and when.
That list is, in effect, a specification for Zero Trust Network Access, which is why vendors including OpenVPN now deliver it as a service to organisations that will never staff a security operations centre.
Cyber-insurance underwriters apply the same logic from the commercial side. Renewal questionnaires now ask about multi-factor authentication, segmentation and access control in specific terms. Between them, the regulator and the insurer have become the two most effective zero-trust salespeople in the market.
The AI-Agent Access Problem Most Coverage Has Missed
A second driver is arriving fast at exactly the companies least prepared for it. As smaller firms adopt AI copilots, assistants and increasingly autonomous agents, they create a new population of non-human identities that need access to data, systems and other software.
A copilot that reads a shared drive, a bot that queries a customer database, an agent that triggers an action in another application: each is an identity that should be governed by the same least-privilege thinking applied to an employee. In most small environments it is not. Machine identities receive broad standing access because that was the fastest route to a working integration, and they tend to outlive the project that created them.
This collides directly with the supply-chain provisions above. A designated critical supplier asked to demonstrate control over access to an essential service will struggle if a portion of that access belongs to software nobody inventoried. Network-layer policy is the practical answer for a small team, because a rule that limits what a connected identity can reach binds a bot on the same terms as an employee. That principle is what ZTNA services such as CloudConnexa from OpenVPN are built on.
Does Zero Trust Make Sense For A Smaller Business?
It does, provided the implementation matches the team that has to run it. The obstacle for most small businesses has never been the logic of zero trust. It has been the shape of the products sold under the name.
The common error is shopping in the enterprise aisle. Zscaler, Palo Alto Networks and Cisco’s Duo serve large security organisations, and their deployment models presume analysts available to tune policy and wire in telemetry. A firm that has just been named a critical supplier, and needs demonstrable controls inside a contract cycle, cannot wait two quarters for a platform to reach production however capable it is.
The opposite end has its own trap. Tools such as Tailscale, Twingate and NordLayer prioritise rapid rollout and straightforward connectivity between devices and resources, which is a real benefit to a stretched team. Connectivity answers a different question from the one a regulator asks. An auditor wants to know which identity reached which system, under what conditions, and whether anyone can evidence it afterwards. Device posture enforcement, access groups and least-privilege segmentation are what produce that answer, and buyers should compare products on those specifics before treating any two as equivalent.
The more useful framing is to buy for the maturity you have. Fast onboarding, clear pricing and controls a small team can configure matter more than a feature list nobody has time to use.
That gap is what a handful of vendors now target with ZTNA for SMBs, packaging the core zero-trust controls of verified identity, device posture and segmented access into something a lean team can stand up in an afternoon instead of a quarter.
What Right-Sized ZTNA Looks Like In Practice
CloudConnexa from OpenVPN is one of those products, delivering Zero Trust Network Access as a cloud service with device posture checks, access groups and least-privilege segmentation, sized for a business with one or two IT administrators instead of a full security team.
CloudConnexa’s relevance to the supply-chain question is practical. Access policy is applied per application, so a verified user or connected system reaches the services its role permits and has no lateral path elsewhere. Application servers and devices connect through Connectors authenticated by digital certificate. CloudConnexa streams access and DNS logs to external tooling, which is what converts a claim about access control into the evidence a regulator, an auditor or a customer’s questionnaire will ask for.
Provenance is a fair question to put to any vendor selling to teams without security engineers. OpenVPN’s open-source protocol has been running in production environments for over two decades and carries a large share of the business VPN connectivity organisations still depend on, which is a longer track record than most products marketed at small businesses can claim. Pricing runs on the same logic, with plans published from $7 per month per connection instead of six-figure platform contracts.
The Shift Is The Story
Smaller companies are not adopting zero trust because a vendor persuaded them it was visionary. They are adopting it because a regulator wrote it into a framework, an insurer wrote it into a renewal, and their own AI adoption wrote a new set of identities into their network.
For the IT lead at a growing business, the practical takeaway is to move before an audit finding or a customer questionnaire forces the decision. The building blocks of a workable zero trust solution for an SMB are now available in forms a small team can run: verified identity, device posture and least-privilege access. The firms treating 2026 as the year to start will find the transition considerably less painful than those still hoping the enterprise story stays an enterprise problem.





