Context
While the market is maturing, there remain differences in capabilities across vendor offerings in terms of unified platforms, sovereignty controls, networking and broader security capabilities. Most vendors have substantially stronger expertise in either security or networking, but few have both. When evaluating SASE platform offerings, enterprises should focus on the following characteristics, which define a well-architected SASE platform solution:
Unified
A single management plane and policy engine to drive scale, simplicity and efficiency.
The ability to deploy a single security policy with malware/sensitive data inspection and single-pass architecture across all channels.
The ability to view analytics and provide troubleshooting capabilities across all functions in the same management console.
Single-pass decryption and inspection for malware and sensitive data.
Full SSE functionality delivered via a single software agent.
Integrated digital experience monitoring to enable end-to-end troubleshooting across the entire platform, with a focus on users and applications with drill-down capability.
Simple
Intuitive GUIs to simplify network and security set-up and ongoing operations.
Use of AI copilots/assistants to help with initial configuration and operational activities, including documentation, policy creation and troubleshooting assistance/recommendations.
Increasing use of AI agents in network and security operations.
Simplified licensing and bill of materials (BOM) to converge the network and security functions, rather than treating them like two different solutions (e.g., SD-WAN and SSE).
Network Functionality
All core networking features, as outlined in the SASE platforms definition.
Advanced SD-WAN features for more complex networking use cases.
Integration with campus networking (WLAN and LAN) for simplified network management.
Integrated cloud onramp for simplified and enhanced performance access to cloud services.
Security Functionality
Includes all core security features, as outlined in the SASE platforms market definition.
Strong ability to provide visibility into and control of sensitive data.
GenAI controls to manage enterprise data leakage and control access to GenAI applications.
Robust threat intelligence and threat protection.
Continuous adaptive access to provide near-real-time access adjustments, based on a calculated risk score and identity.
Integrated, advanced analytics across all channels for identifying and responding to risky or malicious behaviors as quickly as possible.
Infrastructure Delivery
Sovereign Controls
Location flexibility of encryption key management and storing logs/metadata.
Routing flexibility to pass through or avoid certain countries and regions.
Flexibility of management plane ownership that can be extended to a customer.
Local partnerships with SASE POP capabilities.
Hyperscale independence of infrastructure POPs.
Critical Capabilities Definition
SD-WAN
The SD-WAN capability provides advanced networking functionality to address more complex requirements.
This includes features resident in the branch gateway with more sophisticated, performance-based, application-aware path selection (based on packet loss, latency, jitter, etc.), dynamic routing (e.g., Border Gateway Protocol [BGP]) and support for more complicated meshed topologies. It also includes appliance form factors, physical WAN interfaces and supported throughput. Application performance techniques are also important, such as protocol and application optimizations, link bonding/packet striping, forward error correction (FEC), packet duplication and SaaS optimization. Finally, SD-WAN offers cloud onramp capabilities and integrations, enabling automated, high-performing and flexible architectures to access cloud workloads.
In-Line On-Premises Security
This capability includes on-premises network security features to protect the organization’s branch/campus/remote locations, including — but not limited to — local segmentation, firewalling, content filtering and intrusion prevention systems (IPS) to secure traffic bidirectionally across networks.
Securing Private Applications
This capability provides zero-trust access control to private applications (on-premises, colocated and IaaS-based) based on user/device identity and context.
It favors an architecture that uses a broker connector with no persistent inbound ports open to the internet, thereby reducing the attack surface. This is primarily associated with remote workers, but also extends to branch workers and devices, and both managed and unmanaged devices. We evaluate the ability to provide policy enforcement points through both vendor-provided, cloud-hosted services and delivered as virtual or physical appliance enforcement point onramps. Products should authenticate and authorize users, including securing privileged accounts, and/or devices using open standards.
In-Line Cloud-Enforced Security
This capability includes a granular set of in-line controls for securing access to websites and social media sites that drive policy actions based on the type of site visited.
We assess full proxy — including decryption of web traffic at scale — to enable content inspection and the ability to secure DNS traffic, as well as FWaaS and IPS capabilities to protect end users. This includes the ability to utilize lightweight controls to secure unmanaged devices in-line when accessing SaaS and private applications. Application control and malware prevention are also included.
SaaS App Control and Visibility
This capability includes visibility and control for discovery, usage and data at rest in enterprise SaaS applications.
This category also includes discovery and risk rating of SaaS applications, as well as integration with SaaS vendor application APIs to gain visibility into SaaS. We assess the range of applications that can be integrated, the depth of data security (inclusive if data at rest), threat defense and any differentiated API capabilities such as visibility, configuration or interconnection of SaaS applications.
Infrastructure Delivery
This capability covers the vendor’s infrastructure delivery of publicly shared points of presence (POPs) that support the enterprise SASE platform.
It includes the geographic distribution of metro areas where public shared POPs are deployed, as well as the functionality and consistency of capabilities available as part of that infrastructure. We also assess the capabilities of the vendor’s WAN backbone as part of the public shared POP infrastructure.
Ease of Administration
This capability includes ease of administration across networking and security to simplify use of the solution.
The goal is for the operations team to be able to perform its capabilities in a simple and efficient way. This includes UIs’ ease of use, management platforms, monitoring, integrations and automation capabilities across initial provisioning and configuration, production (e.g., moves/adds/changes), policy configuration and incident response. We also include documentation. Enterprise integrations may include vendors such as ServiceNow.
Lightweight Networking
This capability involves lightweight branch networking functionality that integrates branch WAN and LAN infrastructure.
It includes WAN, WLAN and wired LAN integrated functionality in a single platform managed from the cloud delivering unified configuration, policy, reporting, visibility and automation. Low-friction onboarding with high degrees of automation is often required. Cost competitiveness is also a driving factor for customers that require this lightweight functionality.
Unified Platform
This capability includes the unification of the vendor’s offering, including the number and integration of components required for customers to operate the offering.
Components include management/configuration, visibility/monitoring, policy engines, agents, data lakes and APIs. We also assess how well these components are integrated.
Data Security
This capability includes the efficacy of the DLP engine and its ability to reduce false positives and false negatives by providing advanced sensitive data techniques.
Advanced data security extends beyond DLP to include integration with third-party data classification and data security posture management (DSPM) providers as part of a wider data security ecosystem. It extends to inspect a wide range of file types across web, SaaS and private applications. It also evaluates the maximum file sizes supported and corresponding action taken when file size is exceeded. Data security prevents users from accidentally or maliciously sharing sensitive data.
Threat Protection
This includes the ability to detect attacks and custom threats, with features such as sandboxes, remote browser isolation (RBI), malware engines and threat intelligence. It provides multiple methods to detect and mitigate active threats concurrently across web, cloud and private applications.
Adaptive Access
This capability uses near-real-time context to determine whether to allow access to a specific resource based on a risk score, including factors such as user identity, device identification and hygiene, location and user activity.
It includes the ability to dynamically adjust user and device access to applications and resources in near real time. These adjustments are based on effective and customizable assessment of the state and behavior of both user and device, and the risks these pose (risk score). Evaluation looks at the richness and frequency of updates of the risk score. This includes enforcement across various channels and deriving risk via cross-channel behaviors, device state visibility and user entity behavior analysis (UEBA) capabilities. It also includes the ability to profile the endpoint both on connection and on application access, as well as analyze user and endpoint behaviors, adjusting access or requiring additional verification based on calculated risk.
AI Security
This capability enables the discovery and cataloging of GenAI, in-line access and sensitive data controls to prevent data leakage, as well as discovery and policy enforcement of AI agents.
It includes application control policies, reputational risk assessment and GenAI as a separate URL classification category. Advanced features include more granular control and integration for the most popular enterprise GenAI products, such as Microsoft Copilot, Google Gemini, Anthropic Claude and OpenAI ChatGPT. It also includes the ability to capture, inspect and log end-user prompt inputs; integration via API into private tenants for enhanced security; prevention of sensitive data uploads via prompts or file uploads; and visibility into the use of third-party GenAI APIs from the corporate network. This capability supports discovery, visibility and policy enforcement of sanctioned AI agents and shadow AI agents when accessing web, SaaS and private applications or communicating with MCP servers.
Sovereign Controls
We assess the ability to provide organizational control across a vendor’s SASE platform offering, including its control plane, data plane, management plane and support requirements.
For the control plane, we assess options for delivery of access and policy decisions. For the data plane, we focus primarily on delivery of traffic inspection, policy enforcement, traffic routing and encryption/decryption options. For the management plane, we evaluate delivery of the orchestration software for policy configuration, life cycle management of encryption keys. as well as options for storage of logs and other data. We analyze corporate ownership, employee citizenship and compliance with specific regulations.
"Coffee Shop" Networking Experience
This measures the ease with which end users can access the network and cloud resources, as well as the vendor’s experience in providing this capability.
It includes the simplicity of the end-user experience, which should be as consistent in an enterprise-owned location as it is working from home, a coffee shop, an airport, a hotel etc. We also factor in the vendor’s experience in offering this capability.
Use Cases
Foundational SASE Platform
This use case is driven by organizations that want to reduce products and vendors to securely connect users/devices to the web, SaaS and private applications.
Users are looking for a unified offering that converges networking and network security functionality to reduce the administrative complexity of using multiple management consoles and vendors. Organizations prioritize unified management for operations personnel over advanced features and functionality. Enterprises are aggressively leveraging public cloud services and SaaS for applications, primarily relying on the internet for cloud connectivity. Employees regularly work from anywhere, including branch locations and home offices. The SASE platform product selection is usually made collectively by a cross-functional team, composed of networking and network security personnel.
Zero-Trust SASE Platform
This use case is driven by organizations seeking to implement SASE to achieve a zero-trust posture for their users, devices, branches and remote locations.
Specifically, this entails improving the security of users and devices (both managed and unmanaged) by:
Establishing identity prior to allowing access.
Granting access only to necessary resources.
Continuously and dynamically adjusting access in near real time, based on a calculated risk score.
Providing adaptive access, AI security, data security and threat protection.
These enterprises aggressively leverage public cloud services and SaaS for applications. Employees regularly work from anywhere, including branch locations. This effort is typically led by the network security team (under the CISO) in collaboration with the network team.
Secure Branch Network Modernization
This use case is driven by organizations looking to start their SASE journey by focusing on branch network modernization with SD-WAN.
These organizations are seeking to immediately implement SD-WAN with firewall and/or SWG, while planning longer term to add additional SASE functionality such as CASB and ZTNA. These organizations leverage public cloud services, SaaS and private applications both on-premises and in the cloud, and often utilize both internet and private networking for hybrid cloud connectivity. Employees primarily work from branch locations, so more advanced SD-WAN functionality is typically desired to manage network contention and more complex routing. In-line on-premises security controls integrated with the SD-WAN appliance, along with ease of use, are typically desired over more advanced security features. SASE platform product selection is usually led by a networking team, with collaboration and input from network security personnel.
"Coffee Shop" Networking
This use case is driven by organizations aiming to replicate the user experience of a coffee shop in the branch office environment.
It is not necessarily about replicating the internal network infrastructure of a coffee shop. Rather, these organizations want to deliver a simplified and consistent networking and network security converged experience for end users, whether those employees are in a corporate office location, at a coffee shop or other remote location. They also want to simplify the IT administrative and financial burden at their corporate offices.
Organizations typically have a hybrid work model where users are accessing applications primarily delivered from the cloud while preferring to access the network via Wi-Fi connectivity. In this scenario, lightweight networking functionality is often (but not exclusively) the desired choice, with little to no east/west on-premises network security requirements. ZTNA and, increasingly, UZTNA are often prioritized, along with other SSE capabilities that may already be deployed where organizations are looking to leverage existing investments to simplify the branch office for the new hybrid work environment.
Sovereign SASE
This is an emerging use case where organizations focus on sovereign controls and flexibility across the control plane, data plane and management plane.
The enterprise is looking for a SASE platform offering where they can have various levels of control over the control plane, data plane and management plane. This includes control over where data/traffic is routed, where data/logs are stored and where the orchestration platform is hosted to manage policies/configurations.
There are various forms of sovereignty that enterprises are considering, including the use of standard public shared POPs within a country or region, delivering full SASE feature functionality in a private or dedicated POP, or deploying a branch appliance in any location owned or controlled by the customer.
Furthermore, local in-country/in-region partnerships are important to provide flexibility for global and local customers that have sovereignty requirements to work with in-country/in-region suppliers. Solutions should be standardized to not dramatically increase deployment time or cost. Sovereignty is often driven by meeting specific country or regional laws, regulations, cultural requirements and specific language. This has regional importance for areas such as the EU and Asia/Pacific. Broader security requirements are also factored in as part of this use case, as it is primarily driven by the security team.