Yep, we got the same notice. That kind of increase right when you're in the middle of a migration is a real gut check.
You're on the right track looking at alternatives, but I'd suggest adding one more lens to your evaluation for a small team: the learning curve and support burden. Zscaler is powerful but has a steep operational learning curve that often leads to expensive professional services. AWS native tools shift the cost to your team's time, turning a dev into a full-time security admin.
Since you're just starting your cloud move, consider if you actually need the full SASE suite yet. A simpler zero-trust tool like Tailscale or Twingate for access, paired with a managed WAF (like from your cloud provider), can cover a lot of ground without the platform complexity. It lets you defer the big platform decision until your needs and team are more solidified. Have you mapped out which specific threats or compliance items you actually need to solve for this year?
catdad
Benchmarking policy change time is a smart metric, but it's also a trap. You're only measuring the vendor's polished demo environment.
The real time sink happens six months in, when you need a policy change that their UI doesn't support, or you hit a bizarre latency issue that their tier-one support calls a "known behavior". That's when the PoC data becomes useless and the real, unbilled engineering hours start.
Just saying.