Critical Capabilities for SASE Platforms

29 July 2026 - ID G00840454 - 43 min read
By Jonathan Forest, Andrew Lerner,  and 2 more
While the SASE platforms market is maturing, differences remain among vendors’ core capabilities and new functionality around securing AI, sovereign controls and postquantum cryptography. Heads of I&O and cybersecurity leaders can use this analysis to help determine the vendor offering that best aligns with their needs.

Overview


Key Findings

  • Two-thirds of vendors in this research support unified management (via a single console) across software-defined wide-area network (SD-WAN) and security service edge (SSE) functions.
  • Most vendors lack feature breadth and depth of networking and security capabilities across on-premises and cloud.
  • There is vendor differentiation in the discovery, risk ratings, access control and prompt inspection of generative AI (GenAI) applications.
  • There is increasing customer interest in sovereign controls with secure access service edge (SASE) platform solutions, which is a substantial point of differentiation between vendor offerings.

Recommendations

  • Select a SASE platform that features a single management console when prioritizing simplicity, ensuring it includes strong automation and agentic capabilities across configuration management, policy management, analytics and troubleshooting.
  • Hybrid cloud customers should investigate SASE platform capabilities that have security parity between on-premises and cloud-delivered capabilities, and validate SD-WAN functionality across application performance, maximum throughput and routing protocols supported.
  • Evaluate vendor capabilities in AI security by verifying their ability to identify GenAI applications, conduct risk ratings, control access and provide prompt inspection.
  • Determine SASE platform sovereignty capabilities by validating encryption and logging controls, management plane flexibility, routing flexibility, regional partner capabilities and hyperscale independence of point-of-presence (POP) infrastructure. Just because a solution is deployed on-premises doesn’t make it sovereign.

Strategic Planning Assumptions


  • By 2029, 60% of new SASE deployments will be based on a single-vendor SASE platform offering, up from 40% in 2026.
  • By 2029, 60% of secure access requests will originate from nonhuman identity enforcement and collaborative access between identities, up from less than 5% in 2026.

What You Need to Know


The SASE platform offerings in this research provide capabilities that connect and secure distributed users, devices and locations to resources in the cloud, at the edge and on-premises, all via a platform from a single vendor. In this market, a vendor must own all of the core product capabilities.
This research assesses SASE platform offerings from 12 vendors across 15 capabilities:
  • SD-WAN
  • In-line on-premises security
  • Securing private applications
  • In-line cloud-enforced security
  • SaaS app control and visibility
  • Infrastructure delivery
  • Ease of administration
  • Lightweight networking
  • Unified platform
  • Data security
  • Threat protection
  • Adaptive access
  • AI security
  • Sovereign controls
  • “Coffee shop” networking experience
SASE platforms are also evaluated across five use cases:
  • Foundational SASE platforms
  • Zero-trust SASE platforms
  • Secure branch network modernization
  • Coffee shop” networking
  • Sovereign SASE
Capabilities and use cases are assessed on a 1 to 5 scale for each vendor’s offering, in which:
  • 1 = Poor or Absent: most or all defined requirements for a capability are not achieved
  • 2 = Fair: some requirements are not achieved
  • 3 = Good: meets requirements
  • 4 = Excellent: meets or exceeds some requirements
  • 5 = Outstanding: significantly exceeds requirements

Analysis


Critical Use-Case Graphics

Vendors’ Product Scores for Foundational SASE Platform Use Case
12 providers are ranked on a 1 to 5 scale according to how well their offerings meet the needs of the Foundational SASE Platform use case in the SASE Platforms market, as of 15 June 2026. This allows comparison across a set of critical differentiators.
Vendors’ Product Scores for Zero-Trust SASE Platform Use Case
12 providers are ranked on a 1 to 5 scale according to how well their offerings meet the needs of the Zero-Trust SASE Platform use case in the SASE Platforms market, as of 15 June 2026. This allows comparison across a set of critical differentiators.
Vendors’ Product Scores for Secure Branch Network Modernization Use Case
12 providers are ranked on a 1 to 5 scale according to how well their offerings meet the needs of the Secure Branch Network Modernization use case in the SASE Platforms market, as of 15 June 2026. This allows comparison across a set of critical differentiators.
Vendors’ Product Scores for “Coffee Shop” Networking Use Case
12 providers are ranked on a 1 to 5 scale according to how well their offerings meet the needs of the "Coffee Shop" Networking use case in the SASE Platforms market, as of 15 June 2026. This allows comparison across a set of critical differentiators.
Vendor Product Scores for the Sovereign SASE Use Case
12 providers are ranked on a 1 to 5 scale according to how well their offerings meet the needs of the Sovereign SASE use case in the SASE Platforms market, as of 15 June 2026. This allows comparison across a set of critical differentiators.

Vendors

Cato Networks

See verified user reviews and ratings for Cato Networks on Peer Insights.
Cato Networks is based in Tel Aviv, Israel, and its SASE platform offering is the Cato SASE Cloud Platform. Gartner estimates that the vendor has approximately 4,000 active SASE platform enterprise customers. The offering is delivered via the integrated Cato Management Application (CMA), which manages all relevant SSE functionality, Cato Socket edge SD-WAN, Cato Client and Cato Global Private Backbone. While the offering is targeted at customers of all sizes, it is most aligned with those organizations seeking a simpler experience and has had notable success with midsize enterprises.
In the last year, Cato integrated Aim Security (acquired in September 2025) into the Cato SASE Cloud Platform for AI governance and AI runtime protection. It also added a modular solution to target SSE and zero-trust network access (ZTNA)-specific use cases and Cato Neural Edge, which uses GPUs in its POPs to optimize performance across its Global Private Backbone. However, the vendor lacks local content filtering functionality integrated with its Cato Socket edge SD-WAN appliances.
Cato SASE Cloud Platform scores excellent in the foundational SASE platform use case, and good in the remaining four use cases. These scores are driven by the offering’s strengths in infrastructure delivery, ease of administration and unified platform capabilities. At the same time, Cato Networks’ offering is comparatively weaker in lightweight networking, sovereign controls and in-line on-premises security capabilities.
Check Point Software Technologies

See verified user reviews and ratings for Check Point Software Technologies on Peer Insights.
Check Point Software Technologies is based in Tel Aviv, Israel, and its SASE platform offering is Check Point SASE. Gartner estimates that the vendor has approximately 1,000 active SASE platform enterprise customers. The offering requires two management consoles integrated in the Infinity Portal, with Check Point SASE providing the SSE functionality and Check Point SD-WAN providing the SD-WAN functions. The offering is most suitable for security-focused organizations that require a hybrid of on-premises and cloud security needs.
In the last year, Check Point delivered its AI Defense Plane, a unified AI security control plane, and a unified policy management across hybrid mesh firewall and SASE. It also delivered an enterprise browser providing zero-trust access for unmanaged devices. However, the vendor still requires two management consoles across SD-WAN and SSE to operate the offering, which adds complexity.
Check Point SASE scores good in the foundational SASE platform, zero-trust SASE platform, secure branch network modernization and sovereign SASE use cases, and fair in the remaining use case. These scores are driven by the offering’s strength in in-line on-premises security, securing private applications and AI security capabilities. At the same time, Check Point’s offering has weaknesses in in-line cloud-enforced security, lightweight networking, ease of administration and adaptive access capabilities.
Cisco

See verified user reviews and ratings for Cisco Systems on Peer Insights.
Cisco is based in San Jose, California, and its primary SASE platform offering is Cisco SASE. Gartner estimates that the vendor has approximately 1,500 active SASE platform enterprise customers using this product. Cisco SASE integrates Cisco’s Catalyst SD-WAN and Cisco Secure Access, requiring two management consoles to fully deliver the SSE and SD-WAN functionality. While Cisco leads with Catalyst SD-WAN, Meraki SD-WAN is also supported. The offering is suitable for customers of all sizes and use cases, but primarily those with stronger networking needs or an existing Cisco SD-WAN deployment.
In the last year, Cisco added AI usage protection to prevent data leakage in GenAI applications and continuous adaptive access (which is a separate but integrated product). It also launched hybrid private access with relay-based ZTNA and a unified policy framework for web, SaaS, private application and internet security. However, the vendor requires two management consoles to operate the full offering (which adds complexity) and has had an elevated number of security vulnerabilities related to its Catalyst SD-WAN offering.
Cisco SASE scores excellent in the secure branch network modernization use case, and good in the remaining four use cases. These scores are driven by the offering’s strengths in SD-WAN, in-line on-premises security and threat protection capabilities. At the same time, Cisco SASE has weaknesses in ease of administration, sovereign controls and infrastructure delivery capabilities.
Cloudflare

See verified user reviews and ratings for Cloudflare on Peer Insights.
Cloudflare is based in San Francisco, California, and its SASE platform offering is Cloudflare One. Gartner estimates that the vendor has approximately 4,500 active SASE platform enterprise customers. Cloudflare One is an integrated offering that provides all SSE functionality, with Cloudflare WAN, Cloudflare One Client and Cloudflare One appliances managed via the Cloudflare Dashboard. Cloudflare’s core market is enterprise customers looking for a simpler experience.
In the last year, Cloudflare added Model Context Protocol (MCP) server portals for AI agent governance and AI prompt protection to protect from data leakage. It also added a private networking solution to secure autonomous agentic workflows, end-to-end postquantum SASE and Border Gateway Protocol (BGP) support for peering over Cloudflare’s WAN onramps. However, Cloudflare lacks on-premises networking and security capabilities required by many customers.
Cloudflare One scores good in the foundational SASE platform and “coffee shop” networking use cases, and fair in the remaining three use cases. These scores are driven by the offering’s strengths in infrastructure delivery, ease of administration and unified platform capabilities. At the same time, Cloudflare’s offering has weaknesses in in-line on-premises security, lightweight networking, SD-WAN and sovereign controls capabilities.
Fortinet

See verified user reviews and ratings for Fortinet on Peer Insights.
Fortinet is based in Sunnyvale, California, and its SASE platform offering is Fortinet Unified SASE. Gartner estimates that the vendor has over 3,000 active SASE platform enterprise customers. Fortinet’s Unified SASE offering includes FortiSASE (for the SSE functions) and Fortinet Secure SD-WAN integrated in the FortiSASE portal. The offering is targeted at all customers, with a particular focus on organizations that have a hybrid of on-premises and cloud security needs.
In the last year, Fortinet delivered its secure browser extension, which allows customers to retain their existing browsers to enforce data loss prevention (DLP) and GenAI usage controls. Additionally, it introduced SaaS security posture management (SSPM) and SASE outpost for sovereign use cases where there is a desire to run some SASE functions closer to the users and data. However, Fortinet’s large installed base makes its firewall platforms a target for attackers exposing vulnerabilities, resulting in some Gartner clients questioning the security posture of the vendor’s products.
Fortinet Unified SASE scores excellent in the secure branch network modernization use case, and good in the remaining four use cases. These scores are driven by the offering’s strengths in lightweight networking, SD-WAN, in-line on-premises security and AI security capabilities. At the same time, Fortinet’s offering has weaknesses in SaaS app control and visibility, and ease of administration capabilities.
Hewlett Packard Enterprise

See verified user reviews and ratings for Hewlett Packard Enterprise on Peer Insights.
Hewlett Packard Enterprise (HPE) is based in Spring, Texas, and its primary SASE platform offering is HPE Networking Unified SASE. Gartner estimates that the vendor has approximately 600 active SASE platform enterprise customers. The offering requires two management consoles, with HPE Networking EdgeConnect Cloud Orchestrator for SD-WAN and HPE Networking SSE. While the vendor has multiple SD-WAN products, it leads with HPE Networking EdgeConnect SD-WAN. HPE Networking Unified SASE is better suited for more networking-led use cases.
In the last year, HPE delivered firewall as a service (FWaaS), web content and reputation filtering support in the branch SD-WAN gateways. Additionally, the vendor introduced on-premises sovereign SASE capabilities, which also enable universal ZTNA. However, HPE requires two management consoles for SD-WAN and SSE to operate the offering, which adds complexity.
HPE Networking Unified SASE scores good in the foundational SASE platform, secure branch network modernization and “coffee shop” networking use cases, and fair in the remaining two use cases. These scores are driven by the offering’s strengths in SD-WAN and in-line on-premises security capabilities. At the same time, HPE’s offering has weaknesses in infrastructure delivery, ease of administration, data security and AI security capabilities.
iboss

See verified user reviews and ratings for iboss on Peer Insights.
iboss is based in Boston, Massachusetts, and its SASE platform offering is iboss AI-Powered SASE Platform. Gartner estimates that the vendor has approximately 300 active SASE platform enterprise customers. The offering includes iboss unified management via the Cloud Management Console for both the SD-WAN and SSE components, along with branch gateways and software licenses. It is targeted at all customers, but particularly those with security-driven use cases and those that prioritize product simplification.
In the last year, iboss delivered an AI-powered cloud access security broker (CASB) with GenAI prompt and response data security, integration with Microsoft Purview for inline data discovery, and a SASE offering that enables channel partners to self-provision new customer accounts in minutes. However, the vendor lacks networking functionality such as packet duplication, cloud integrations and LAN integrations.
The iboss AI-Powered SASE Platform scores good for all use cases in this evaluation. These scores are driven by the offering’s strengths in in-line cloud-enforced security, SaaS app control and visibility, and sovereign controls capabilities. At the same time, iboss’s offering has weaknesses in lightweight networking, SD-WAN and ease of administration capabilities.
Netskope

See verified user reviews and ratings for Netskope on Peer Insights.
Netskope is based in Santa Clara, California, and its SASE platform offering is Netskope One SASE. Gartner estimates that the vendor has approximately 2,000 active SASE platform enterprise customers. It is an integrated offering that includes Netskope One Security Service Edge, Netskope One SD-WAN, Netskope One Client and NewEdge POP infrastructure managed via Netskope One SASE Orchestrator. The offering is targeted at all types of networking and security use cases.
In the last year, Netskope delivered Netskope One AgentSkope, which is an architectural foundation for deploying Netskope AI agents that execute SASE workflows. The vendor also delivered Netskope One AI Security covering user-to-application, agents and private built AI use cases, DNS-as-a-service (DNSaaS), and AI network optimization with NewEdge AI Fast Path and AI Application Quality of Experience (AppQoE). However, the vendor lacks stand-alone access points and switches that integrate with its SD-WAN gateways.
Netskope One SASE scores excellent in the foundational SASE platform, zero-trust SASE platform, secure branch network modernization and sovereign SASE use cases, and good in the remaining use case. These scores are driven by the offering’s strengths in sovereign controls, data security, in-line cloud enforced security, and SaaS app control and visibility capabilities. At the same time, Netskope is comparatively weaker in the lightweight networking and “coffee shop” networking experience capabilities.
Palo Alto Networks

See verified user reviews and ratings for Palo Alto Networks on Peer Insights.
Palo Alto Networks is based in Santa Clara, California, and its SASE platform offering is Prisma SASE. Gartner estimates that the vendor has approximately 6,500 active SASE platform enterprise customers. It is an integrated offering, which includes Prisma Access (SSE), Prisma SD-WAN with its ION appliances, and corresponding software managed via Strata Cloud Manager. The traditional next-generation firewall (NGFW) is not part of the vendor’s SASE offering and was not part of this evaluation. Prisma SASE is primarily suitable for cloud-first networking and security use cases.
In the last year, Palo Alto Networks delivered proactive agentic operations across networking and security operations, securing the AI life cycle and support for postquantum cryptography (PQC). It also delivered the data security foundation for securing AI. However, the vendor lacks stand-alone access points and switches that integrate with its ION appliances.
Prisma SASE scores excellent in the foundational SASE platform and zero-trust SASE platform use cases, and good in the remaining three use cases. These scores are driven by the offering’s strengths in unified platform, threat protection, adaptive access, and SaaS app control and visibility capabilities. At the same time, Palo Alto Networks’ offering is weaker in the lightweight networking and in-line on-premises security capabilities.
Sangfor Technologies

Sangfor Technologies is based in Shenzhen, China, and its SASE platform offering is Athena SASE. Gartner estimates that the vendor has approximately 1,000 active SASE platform enterprise customers. It includes two separate management consoles: Sangfor Access Secure for the unified agent and cloud security; and NGAF Platform for the SD-WAN and firewall appliance. Athena SASE is primarily suitable for organizations in Asia/Pacific, Europe and South America with security-first use cases.
In the last year, Sangfor Technologies delivered user workspace management (UWM), providing a native sandbox-based execution environment on the endpoint. It also launched the Sangfor Athena SASE unified client and AI Application Analytics to secure GenAI usage. However, the vendor requires two management consoles to operate Athena SASE (which adds complexity) and has limited POPs in North America.
Athena SASE scores good in all use cases. These scores are driven by its strengths in lightweight networking, in-line on-premises security and in-line cloud-enforced security capabilities. At the same time, Sangfor’s offering has weaknesses in securing private applications, SaaS app control and visibility, ease of administration and unified platform capabilities.
Versa Networks

See verified user reviews and ratings for Versa Networks on Peer Insights.
Versa Networks is based in Santa Clara, California, and its SASE platform offering is Versa Secure Access Fabric (VSAF). Gartner estimates that the vendor has approximately 5,000 active SASE platform enterprise customers. It is an integrated offering that includes Versa SSE and Versa Secure SD-WAN using Versa CSG appliances managed via Versa Concerto. Versa Networks also offers Titan for more streamlined SD-WAN use cases, although this was not part of this evaluation. The VSAF offering is targeted at all networking and security use cases.
In the last year, Versa launched Sovereign SASE-as-a-Service and AI-Enhanced Data Protection. The vendor also introduced VersaAI for operational intelligence to automate networking and security operations. However, VSAF is one of the more complex SASE platforms to operate compared with other vendors’ offerings in this research.
VSAF scores excellent in the secure branch network modernization use case, and good in the remaining four use cases. These scores are driven by the offering’s strengths in SD-WAN, unified platform, in-line on-premises security and sovereign controls capabilities. At the same time, VSAF has weaknesses in securing private applications, ease of administration and AI security capabilities.
Zscaler

See verified user reviews and ratings for Zscaler on Peer Insights.
Zscaler is based in San Jose, California, and its SASE platform offering is Zero Trust SASE. Gartner estimates that the vendor has approximately 1,000 active SASE platform enterprise customers. It is a fully integrated offering that provides the Zero Trust Exchange SSE platform and Zero Trust SD-WAN functionality via the Experience Center management console. The offering is primarily aligned with cloud-first security-driven use cases or existing Zscaler SSE customers.
In the last year, Zscaler expanded its Zero Trust Branch routing features and its global sovereignty capabilities by enabling enterprises to manage assets locally. The vendor also introduced its AI security suite and launched the Zscaler B2B Exchange, leveraging its Zscaler Private Access functionality. However, it lacks advanced on-premises SD-WAN and security capabilities.
Zscaler Zero Trust SASE scores excellent in the foundational SASE platform, zero-trust SASE platform and “coffee shop” networking use cases, and good in the remaining two use cases. These scores are driven by the offering’s strengths in securing private applications, unified platform, AI security and “coffee shop” networking experience capabilities. At the same time, Zscaler’s offering has weaknesses in lightweight networking, SD-WAN and in-line on-premises security capabilities.

Context

While the market is maturing, there remain differences in capabilities across vendor offerings in terms of unified platforms, sovereignty controls, networking and broader security capabilities. Most vendors have substantially stronger expertise in either security or networking, but few have both. When evaluating SASE platform offerings, enterprises should focus on the following characteristics, which define a well-architected SASE platform solution:
Unified
  • A single management plane and policy engine to drive scale, simplicity and efficiency.
  • The ability to deploy a single security policy with malware/sensitive data inspection and single-pass architecture across all channels.
  • The ability to view analytics and provide troubleshooting capabilities across all functions in the same management console.
  • Single-pass decryption and inspection for malware and sensitive data.
  • Full SSE functionality delivered via a single software agent.
  • Integrated digital experience monitoring to enable end-to-end troubleshooting across the entire platform, with a focus on users and applications with drill-down capability.
Simple
  • Intuitive GUIs to simplify network and security set-up and ongoing operations.
  • Use of AI copilots/assistants to help with initial configuration and operational activities, including documentation, policy creation and troubleshooting assistance/recommendations.
  • Increasing use of AI agents in network and security operations.
  • Simplified licensing and bill of materials (BOM) to converge the network and security functions, rather than treating them like two different solutions (e.g., SD-WAN and SSE).
Network Functionality
  • All core networking features, as outlined in the SASE platforms definition.
  • Advanced SD-WAN features for more complex networking use cases.
  • Integration with campus networking (WLAN and LAN) for simplified network management.
  • Integrated cloud onramp for simplified and enhanced performance access to cloud services.
Security Functionality
  • Includes all core security features, as outlined in the SASE platforms market definition.
  • Strong ability to provide visibility into and control of sensitive data.
  • GenAI controls to manage enterprise data leakage and control access to GenAI applications.
  • Robust threat intelligence and threat protection.
  • Continuous adaptive access to provide near-real-time access adjustments, based on a calculated risk score and identity.
  • Integrated, advanced analytics across all channels for identifying and responding to risky or malicious behaviors as quickly as possible.
Infrastructure Delivery
  • Globally distributed POPs with full functionality, so policy enforcement can be as close as needed to remote worker and branch locations.
  • The ability to deliver private POPs and private SASE for sovereignty and performance reasons.
  • WAN backbone to deliver enhanced service levels.
Sovereign Controls
  • Location flexibility of encryption key management and storing logs/metadata.
  • Routing flexibility to pass through or avoid certain countries and regions.
  • Flexibility of management plane ownership that can be extended to a customer.
  • Local partnerships with SASE POP capabilities.
  • Hyperscale independence of infrastructure POPs.

Market Definition

Gartner defines secure access service edge (SASE) platforms as offerings that deliver converged network and security capabilities.This includes software-defined WAN (SD-WAN) and secure access to the web, cloud services and private applications regardless of the user’s location, the device used or where that application is hosted. These offerings primarily use a cloud-centric architecture delivered as a platform by one vendor.
SASE securely connects users and devices with applications, services and other users. It supports branch office and remote worker connectivity and on-premises general internet security, private application access and public cloud service provider access use cases.

Mandatory Features

The mandatory features for this market include:
  • Resilient global point-of-presence (POP) infrastructure providing functionality for secure access to the web, cloud services and private applications.
  • Centralized management with no more than two consoles covering all the capabilities listed below, accessible via both GUI and API, enabling visibility, troubleshooting, reporting and granular configuration and policy changes:
    • Secure web access via proxy.
    • SaaS visibility and access controls.
    • Identity-, context- and policy-based secure remote access to private applications.
    • A branch appliance that supports performance-based dynamic traffic steering (such as packet loss, latency and jitter) across multiple physical WAN interfaces, based on applications (not just IPs/ports).
    • Layer 7 firewalling to secure traffic bidirectionally across networks.
  • Sensitive data visibility and control.

Optional Features

The optional features for this market include:
  • Unified management delivered by a single console covering all capabilities of the offering (with GUI and API), enabling visibility, troubleshooting, reporting and granular configuration and policy changes.
  • The ability to securely connect end users to the SASE platform using a variety of techniques, including software agents, agentless portals, browser plug-ins, secure enterprise browsers and remote browser isolation.
  • The ability to support next-generation firewall (NGFW) functionality as both a cloud service and as part of a branch appliance.
  • Additional security capabilities, including network sandboxing, DNS protection, API-based access to SaaS for data context and configuration information, application layer visibility and protection, and continuous adaptive risk scoring.
  • Advanced network functionality, including enhanced internet, private backbone transport, cloud onramps (simplified and automated integration with public cloud networking services) and broader application optimization technologies.
  • The ability to replace a branch router (such as support for Border Gateway Protocol [BGP]) and support meshed topologies.
  • Integrated digital experience monitoring (DEM) capabilities.
  • Support native capabilities or integration with third-party offerings to provide security controls for unmanaged operational technology (OT) and unmanaged Internet of Things (IoT).
  • GenAI reporting and controls to restrict access and protect enterprise data.
  • The ability to deliver SASE functionality in an environment controlled by the customer for sovereign use cases.
  • Threat protection and intelligence.

Product/Service Trends

The adoption of cloud and edge computing, along with work-from-anywhere initiatives, continues to drive a unified approach to enterprise access requirements. Customers are looking to converge the number of vendors for simplicity or sourcing, management and security posture. SASE platforms can improve and simplify both the end-user and operator experience by enabling the same access to applications, regardless of the user’s location or the location of the application. SASE can help organizations adopt a zero-trust security posture by applying consistent identity- and context-based policies in near real time, regardless of the type of resource the user is accessing. SASE platforms consolidate this functionality into a unified platform offering.
At the same time, enterprises are moving beyond merely pursuing zero-trust strategies to now focusing on how to secure the AI enterprise, address sovereignty concerns, leverage AI to improve Day 2 operations and implement PQC. We also see vendors extending their offerings beyond traditional SASE functions and risking overplatforming, which can have collateral impacts by reducing choice, limiting innovation and focusing less on the intended targeted SASE buyers.

Critical Capabilities Definition

SD-WAN

The SD-WAN capability provides advanced networking functionality to address more complex requirements.
This includes features resident in the branch gateway with more sophisticated, performance-based, application-aware path selection (based on packet loss, latency, jitter, etc.), dynamic routing (e.g., Border Gateway Protocol [BGP]) and support for more complicated meshed topologies. It also includes appliance form factors, physical WAN interfaces and supported throughput. Application performance techniques are also important, such as protocol and application optimizations, link bonding/packet striping, forward error correction (FEC), packet duplication and SaaS optimization. Finally, SD-WAN offers cloud onramp capabilities and integrations, enabling automated, high-performing and flexible architectures to access cloud workloads.
In-Line On-Premises Security

This capability includes on-premises network security features to protect the organization’s branch/campus/remote locations, including — but not limited to — local segmentation, firewalling, content filtering and intrusion prevention systems (IPS) to secure traffic bidirectionally across networks.
Securing Private Applications

This capability provides zero-trust access control to private applications (on-premises, colocated and IaaS-based) based on user/device identity and context.
It favors an architecture that uses a broker connector with no persistent inbound ports open to the internet, thereby reducing the attack surface. This is primarily associated with remote workers, but also extends to branch workers and devices, and both managed and unmanaged devices. We evaluate the ability to provide policy enforcement points through both vendor-provided, cloud-hosted services and delivered as virtual or physical appliance enforcement point onramps. Products should authenticate and authorize users, including securing privileged accounts, and/or devices using open standards.
In-Line Cloud-Enforced Security

This capability includes a granular set of in-line controls for securing access to websites and social media sites that drive policy actions based on the type of site visited.
We assess full proxy — including decryption of web traffic at scale — to enable content inspection and the ability to secure DNS traffic, as well as FWaaS and IPS capabilities to protect end users. This includes the ability to utilize lightweight controls to secure unmanaged devices in-line when accessing SaaS and private applications. Application control and malware prevention are also included.
SaaS App Control and Visibility

This capability includes visibility and control for discovery, usage and data at rest in enterprise SaaS applications.
This category also includes discovery and risk rating of SaaS applications, as well as integration with SaaS vendor application APIs to gain visibility into SaaS. We assess the range of applications that can be integrated, the depth of data security (inclusive if data at rest), threat defense and any differentiated API capabilities such as visibility, configuration or interconnection of SaaS applications.
Infrastructure Delivery

This capability covers the vendor’s infrastructure delivery of publicly shared points of presence (POPs) that support the enterprise SASE platform.
It includes the geographic distribution of metro areas where public shared POPs are deployed, as well as the functionality and consistency of capabilities available as part of that infrastructure. We also assess the capabilities of the vendor’s WAN backbone as part of the public shared POP infrastructure.
Ease of Administration

This capability includes ease of administration across networking and security to simplify use of the solution.
The goal is for the operations team to be able to perform its capabilities in a simple and efficient way. This includes UIs’ ease of use, management platforms, monitoring, integrations and automation capabilities across initial provisioning and configuration, production (e.g., moves/adds/changes), policy configuration and incident response. We also include documentation. Enterprise integrations may include vendors such as ServiceNow.
Lightweight Networking

This capability involves lightweight branch networking functionality that integrates branch WAN and LAN infrastructure.
It includes WAN, WLAN and wired LAN integrated functionality in a single platform managed from the cloud delivering unified configuration, policy, reporting, visibility and automation. Low-friction onboarding with high degrees of automation is often required. Cost competitiveness is also a driving factor for customers that require this lightweight functionality.
Unified Platform

This capability includes the unification of the vendor’s offering, including the number and integration of components required for customers to operate the offering.
Components include management/configuration, visibility/monitoring, policy engines, agents, data lakes and APIs. We also assess how well these components are integrated.
Data Security

This capability includes the efficacy of the DLP engine and its ability to reduce false positives and false negatives by providing advanced sensitive data techniques.
Advanced data security extends beyond DLP to include integration with third-party data classification and data security posture management (DSPM) providers as part of a wider data security ecosystem. It extends to inspect a wide range of file types across web, SaaS and private applications. It also evaluates the maximum file sizes supported and corresponding action taken when file size is exceeded. Data security prevents users from accidentally or maliciously sharing sensitive data.
Threat Protection

This includes the ability to detect attacks and custom threats, with features such as sandboxes, remote browser isolation (RBI), malware engines and threat intelligence. It provides multiple methods to detect and mitigate active threats concurrently across web, cloud and private applications.
Adaptive Access

This capability uses near-real-time context to determine whether to allow access to a specific resource based on a risk score, including factors such as user identity, device identification and hygiene, location and user activity.
It includes the ability to dynamically adjust user and device access to applications and resources in near real time. These adjustments are based on effective and customizable assessment of the state and behavior of both user and device, and the risks these pose (risk score). Evaluation looks at the richness and frequency of updates of the risk score. This includes enforcement across various channels and deriving risk via cross-channel behaviors, device state visibility and user entity behavior analysis (UEBA) capabilities. It also includes the ability to profile the endpoint both on connection and on application access, as well as analyze user and endpoint behaviors, adjusting access or requiring additional verification based on calculated risk.
AI Security

This capability enables the discovery and cataloging of GenAI, in-line access and sensitive data controls to prevent data leakage, as well as discovery and policy enforcement of AI agents.
It includes application control policies, reputational risk assessment and GenAI as a separate URL classification category. Advanced features include more granular control and integration for the most popular enterprise GenAI products, such as Microsoft Copilot, Google Gemini, Anthropic Claude and OpenAI ChatGPT. It also includes the ability to capture, inspect and log end-user prompt inputs; integration via API into private tenants for enhanced security; prevention of sensitive data uploads via prompts or file uploads; and visibility into the use of third-party GenAI APIs from the corporate network. This capability supports discovery, visibility and policy enforcement of sanctioned AI agents and shadow AI agents when accessing web, SaaS and private applications or communicating with MCP servers.
Sovereign Controls

We assess the ability to provide organizational control across a vendor’s SASE platform offering, including its control plane, data plane, management plane and support requirements.
For the control plane, we assess options for delivery of access and policy decisions. For the data plane, we focus primarily on delivery of traffic inspection, policy enforcement, traffic routing and encryption/decryption options. For the management plane, we evaluate delivery of the orchestration software for policy configuration, life cycle management of encryption keys. as well as options for storage of logs and other data. We analyze corporate ownership, employee citizenship and compliance with specific regulations.
"Coffee Shop" Networking Experience

This measures the ease with which end users can access the network and cloud resources, as well as the vendor’s experience in providing this capability.
It includes the simplicity of the end-user experience, which should be as consistent in an enterprise-owned location as it is working from home, a coffee shop, an airport, a hotel etc. We also factor in the vendor’s experience in offering this capability.

Use Cases

Foundational SASE Platform

This use case is driven by organizations that want to reduce products and vendors to securely connect users/devices to the web, SaaS and private applications.
Users are looking for a unified offering that converges networking and network security functionality to reduce the administrative complexity of using multiple management consoles and vendors. Organizations prioritize unified management for operations personnel over advanced features and functionality. Enterprises are aggressively leveraging public cloud services and SaaS for applications, primarily relying on the internet for cloud connectivity. Employees regularly work from anywhere, including branch locations and home offices. The SASE platform product selection is usually made collectively by a cross-functional team, composed of networking and network security personnel.
Zero-Trust SASE Platform

This use case is driven by organizations seeking to implement SASE to achieve a zero-trust posture for their users, devices, branches and remote locations.
Specifically, this entails improving the security of users and devices (both managed and unmanaged) by:
  • Establishing identity prior to allowing access.
  • Granting access only to necessary resources.
  • Continuously and dynamically adjusting access in near real time, based on a calculated risk score.
  • Providing adaptive access, AI security, data security and threat protection.
These enterprises aggressively leverage public cloud services and SaaS for applications. Employees regularly work from anywhere, including branch locations. This effort is typically led by the network security team (under the CISO) in collaboration with the network team.
Secure Branch Network Modernization

This use case is driven by organizations looking to start their SASE journey by focusing on branch network modernization with SD-WAN.
These organizations are seeking to immediately implement SD-WAN with firewall and/or SWG, while planning longer term to add additional SASE functionality such as CASB and ZTNA. These organizations leverage public cloud services, SaaS and private applications both on-premises and in the cloud, and often utilize both internet and private networking for hybrid cloud connectivity. Employees primarily work from branch locations, so more advanced SD-WAN functionality is typically desired to manage network contention and more complex routing. In-line on-premises security controls integrated with the SD-WAN appliance, along with ease of use, are typically desired over more advanced security features. SASE platform product selection is usually led by a networking team, with collaboration and input from network security personnel.
"Coffee Shop" Networking

This use case is driven by organizations aiming to replicate the user experience of a coffee shop in the branch office environment.
It is not necessarily about replicating the internal network infrastructure of a coffee shop. Rather, these organizations want to deliver a simplified and consistent networking and network security converged experience for end users, whether those employees are in a corporate office location, at a coffee shop or other remote location. They also want to simplify the IT administrative and financial burden at their corporate offices.
Organizations typically have a hybrid work model where users are accessing applications primarily delivered from the cloud while preferring to access the network via Wi-Fi connectivity. In this scenario, lightweight networking functionality is often (but not exclusively) the desired choice, with little to no east/west on-premises network security requirements. ZTNA and, increasingly, UZTNA are often prioritized, along with other SSE capabilities that may already be deployed where organizations are looking to leverage existing investments to simplify the branch office for the new hybrid work environment.
Sovereign SASE

This is an emerging use case where organizations focus on sovereign controls and flexibility across the control plane, data plane and management plane.
The enterprise is looking for a SASE platform offering where they can have various levels of control over the control plane, data plane and management plane. This includes control over where data/traffic is routed, where data/logs are stored and where the orchestration platform is hosted to manage policies/configurations.
There are various forms of sovereignty that enterprises are considering, including the use of standard public shared POPs within a country or region, delivering full SASE feature functionality in a private or dedicated POP, or deploying a branch appliance in any location owned or controlled by the customer.
Furthermore, local in-country/in-region partnerships are important to provide flexibility for global and local customers that have sovereignty requirements to work with in-country/in-region suppliers. Solutions should be standardized to not dramatically increase deployment time or cost. Sovereignty is often driven by meeting specific country or regional laws, regulations, cultural requirements and specific language. This has regional importance for areas such as the EU and Asia/Pacific. Broader security requirements are also factored in as part of this use case, as it is primarily driven by the security team.

Vendors Added and Dropped

Added

  • iboss
  • Sangfor Technologies

Dropped

  • SonicWall

Inclusion Criteria


Magic Quadrants and Critical Capabilities identify and analyze the most relevant vendors and their products in a market. The inclusion criteria are the specific attributes that a vendor must have to be included in this research.
In addition to Gartner client relevance, as determined by analyst expertise and opinion, each vendor needed to meet the following criteria to qualify for inclusion:
General:
  • Provide a generally available SASE platform offering as of 1 May 2026. The SASE platform offering must be publicly available, shipping and included on the vendor’s published price list as of this date. Products shipping after this date only may influence the Completeness of Vision axis on the Magic Quadrant.
  • Provide commercial support and maintenance for its enterprise SASE platform offering (24/7) to support deployments on multiple continents. This includes hardware/software support, access to software upgrades, security patches, troubleshooting and technical assistance.
  • Participate in the enterprise SASE platforms market, including actively investing, selling and publicly marketing its branded SASE platform to enterprises.
  • Must be highly relevant to Gartner end-user clients.
Gartner defines “general availability” (GA) as the release of a product to all customers. When a product reaches GA, it becomes available through the company’s general sales channel — as opposed to a limited or controlled release, pre-GA, or beta version.
Product
Vendors must have a SASE platform offering that includes all of the below functionality, generally available as of 1 May 2026.
  • All of the following must be available to customers as a shared service from the cloud:
    • Secure web access via proxy.
    • Enforce SaaS access controls in-line. This requires support for in-line malware scanning and data security to cover at least two of the following three SaaS enterprise suites: Microsoft 365, Salesforce, Google Workspace.
    • Ensure least privileged user access based on continuous identity- and context-based secure remote policy-based access to private applications (not just network-level access).
  • Layer 7 firewall capability to secure traffic bidirectionally across networks.
  • A branch appliance that supports performance-based dynamic traffic steering (supporting at least two of the following criteria: latency, packet loss or jitter) across multiple physical WAN interfaces; based on well-known applications (not IPs/ports). This appliance is deployable at a customer’s physical branch location to directly terminate connectivity.
  • The ability to provide sensitive data visibility and for customers to define sensitive data protection policies and apply them via in-line network data inspection.
  • An endpoint software agent (supporting Windows and Mac operating systems) for connecting users to the vendor’s SASE platform offering.
  • Provide visibility, basic controls (e.g., block, warn, allow) and end users for at least three common GenAI applications (e.g., OpenAI ChatGPT, Perplexity AI, Microsoft Copilot, Google Gemini) initiated by an end user from the endpoint.
  • Centralized management (with both GUI and API) that enables provisioning, visibility, troubleshooting and reporting, and that enables granular configuration and policy changes.
  • The vendor must have no more than two management consoles to operate its enterprise SASE platform offering for the foundational SASE use case.
  • The ability for customers to directly manage and administer the full SASE platform offering themselves, including granular configuration and policy of all SASE functions (commonly referred to as do it yourself [DIY]).
  • Single-pass scanning for malware and sensitive data (may be parallelized) for in-line security controls.
  • Support single sign-on (SSO) integration with third-party identity providers.
  • Leverage POP infrastructure meeting all of the following requirements:
    • Presence in at least 15 distinct metropolitan cities globally, including at least three distinct metropolitan cities on each of three separate continents.
    • POPs must be in a highly secure facility and offer the following services locally (intra-POP): web proxy, private access, and in-line SaaS control with high availability; and be generally available to all enterprise customers.
    • Vendors must provide a publicly available URL with POP metropolitan cities list, POP monitoring/status capability and a documented POP SLA.
  • The vendor must be able to provide a single-support experience to customers, meaning customers must engage only with the vendor for support.
  • The vendor must natively deliver all of the core SASE functionality (SD-WAN, firewall, ZTNA, CASB and SWG) as part of the SASE platform offering.
Global Customer Adoption
Vendors must achieve at least one of the following as of 1 March 2026, with the SSE functionality (ZTNA, CASB and SWG) of SASE delivered as a service from the cloud:
  • Overall adoption: At least 300 unique enterprise customers using SD-WAN and, at a minimum, one of the SSE components (ZTNA, CASB or SWG) with the vendor’s primary SASE platform offering in a production environment and under an active commercial support license.
  • Large enterprise adoption: At least 100 unique large enterprise customers using SD-WAN and, at a minimum, one of the SSE components (ZTNA, CASB or SWG) with the vendor’s primary SASE platform offering in a production environment and under an active commercial support license.
Vendors must achieve each of the following as of 1 March 2026:
  • The primary offering must address at least three of the Critical Capabilities use cases for SASE platforms, with one of them being the foundational SASE use case.
  • At least 50 unique SASE platform enterprise customers, each headquartered in two continents using SD-WAN and, at a minimum, one of the SSE components (ZTNA, CASB or SWG) in a production environment under active support contracts and under an active commercial support license; for example, 50 customers in Asia and 50 separate customers in North America.
Gartner defines “enterprise” as an organization with at least $50 million in annual revenue and/or 100 to 1,000 employees. Gartner defines “large enterprise” as an organization with at least $1 billion in annual revenue and/or over 1,000 employees. Enterprises can be private for-profit organizations or not-for-profit entities such as charitable organizations, government and education institutions.
Gartner defines “customer” as a paying end-user organization for the consumption of a service and under active support. This excludes trials, proofs of concept, paid pilots, “try and buys,” lab trials, etc. Customers may include both DIY organizations and those serviced through a managed SASE provider (i.e., any organization using a vendor’s solution fully deployed, regardless of how it is delivered).

Weighting for Critical Capabilities in Use Cases

Critical CapabilitiesFoundational SASE PlatformZero-Trust SASE PlatformSecure Branch Network Modernization"Coffee Shop" NetworkingSovereign SASE
SD-WAN
8%
0%
30%
5%
5%
In-Line On-Premises Security
1%
3%
15%
0%
10%
Securing Private Applications
5%
15%
0%
10%
5%
In-Line Cloud-Enforced Security
8%
7%
15%
10%
5%
SaaS App Control and Visibility
8%
15%
0%
5%
5%
Infrastructure Delivery
10%
5%
5%
5%
10%
Ease of Administration
24%
0%
5%
10%
0%
Lightweight Networking
8%
0%
15%
10%
5%
Unified Platform
24%
0%
5%
5%
0%
Data Security
1%
15%
0%
0%
5%
Threat Protection
1%
5%
5%
5%
5%
Adaptive Access
1%
25%
0%
5%
5%
AI Security
1%
10%
5%
0%
5%
Sovereign Controls
0%
0%
0%
0%
35%
"Coffee Shop" Networking Experience
0%
0%
0%
30%
0%
As of 15 June 2026
Source: Gartner (July 2026)
This methodology requires analysts to identify the critical capabilities for a class of products/services. Each capability is then weighted in terms of its relative importance for specific product/service use cases.

Critical Capabilities Rating

Each of the products/services that meet our inclusion criteria has been evaluated on the critical capabilities on a scale from 1.0 to 5.0.

Product/Service Rating on Critical Capabilities

Critical CapabilitiesCato NetworksCheck Point Software TechnologiesCiscoCloudflareFortinetHewlett Packard EnterpriseibossNetskopePalo Alto NetworksSangfor TechnologiesVersa NetworksZscaler
SD-WAN
3.9
3.4
4.5
2.5
4.5
4.4
3.1
4.2
4.1
3.6
4.6
2.7
In-Line On-Premises Security
3.5
4.8
4.6
1.9
4.7
4.4
4.4
4.3
3.1
4.7
4.5
2.4
Securing Private Applications
3.9
3.9
3.3
3.2
3.8
3.4
3.8
3.9
4.1
3.1
2.8
4.2
In-Line Cloud-Enforced Security
4.0
2.9
3.7
3.5
4.5
2.4
4.7
4.9
4.3
4.5
4.1
4.1
SaaS App Control and Visibility
3.9
2.9
4.0
2.0
2.9
3.2
4.5
4.6
4.5
2.8
4.0
4.3
Infrastructure Delivery
4.5
4.0
3.6
4.9
4.2
3.0
4.1
4.7
4.3
3.4
4.3
4.1
Ease of Administration
4.2
2.8
3.2
4.0
3.4
2.8
3.2
3.8
3.9
2.9
3.2
3.9
Lightweight Networking
2.7
2.4
3.1
2.1
3.9
3.0
2.0
2.7
2.3
3.5
3.1
2.4
Unified Platform
4.9
3.3
3.8
4.7
4.2
3.2
4.5
4.7
4.7
2.7
4.9
4.9
Data Security
3.1
2.7
3.4
2.4
4.0
2.0
3.4
4.4
4.1
2.6
3.0
4.1
Threat Protection
4.0
3.7
4.7
3.7
4.6
2.7
4.1
4.2
4.7
3.5
4.0
4.3
Adaptive Access
4.0
2.9
3.5
3.2
4.4
3.1
4.0
4.6
4.6
3.3
4.5
4.7
AI Security
3.6
4.1
3.7
2.9
3.9
2.5
3.5
4.3
4.2
3.1
3.1
4.4
Sovereign Controls
2.7
2.5
2.1
1.7
3.4
2.3
3.6
3.9
3.2
2.7
3.6
3.4
"Coffee Shop" Networking Experience
3.8
2.6
3.7
3.6
3.7
2.9
3.1
3.5
3.8
3.0
3.2
4.6
As of 15 June 2026
Source: Gartner (July 2026)
Table 3 shows the product/service scores for each use case. The scores, which are generated by multiplying the use-case weightings by the product/service ratings, summarize how well the critical capabilities are met for each use case.

Product Score in Use Cases

Use CasesCato NetworksCheck Point Software TechnologiesCiscoCloudflareFortinetHewlett Packard EnterpriseibossNetskopePalo Alto NetworksSangfor TechnologiesVersa NetworksZscaler
Foundational SASE Platform
4.17
3.17
3.63
3.69
3.91
3.10
3.78
4.24
4.12
3.16
3.97
4.01
Zero-Trust SASE Platform
3.80
3.29
3.66
2.95
3.98
2.90
3.97
4.43
4.32
3.22
3.74
4.28
Secure Branch Network Modernization
3.76
3.43
4.01
2.88
4.33
3.50
3.57
4.13
3.78
3.77
4.11
3.22
"Coffee Shop" Networking
3.88
2.99
3.65
3.41
3.91
3.01
3.51
3.93
3.95
3.27
3.59
4.08
Sovereign SASE
3.40
3.20
3.25
2.55
3.90
2.88
3.76
4.16
3.71
3.26
3.80
3.60
As of 15 June 2026
Source: Gartner (July 2026)
To determine an overall score for each product/service in the use cases, multiply the ratings in Table 2 by the weightings shown in Table 1.

Acronym Key and Glossary Terms


BGP
Border Gateway Protocol
BOM
bill of material
CASB
cloud access security broker
CDR
content disarm and reconstruction
DLP
data loss prevention
DNS
Domain Name System
DSPM
data security posture management
FEC
forward error correction
IDPS
intrusion detection and prevention system
IoT
Internet of Things
LAN
local-area network
MCP
Model Context Protocol
MSE
midsize enterprise
NOC
network operations center
OT
operational technology
POP
point of presence
RBI
remote browser isolation
RFI
request for information
SaaS
software as a service
SASE
secure access service edge
SD-WAN
software-defined wide-area network
SKU
stock keeping unit
SSE
security service edge
SWG
secure web gateway
UEBA
user and entity behavior analytics
UI
user interface
UZTNA
universal zero-trust network access
WAN
wide-area network
WLAN
wireless local-area network
ZTNA
zero-trust network access

Evidence


  • Gartner analysts have conducted inquiries with over 800 vendor mentions discussing SASE platforms with end user clients over the last 12 months ending 20 April 2026.
  • AskGartner data, with over 100 vendor mentions related to SASE platforms from 1 September 2025 through 23 April 2026.
  • Gartner.com data, with approximately 200 vendor mentions related to SASE platforms in the last 12 months from 23 April 2026.
  • All vendors in this research responded to a prequalification survey to help determine their relevance to enterprise clients.
  • All vendors in this research responded to a request for information (RFI) regarding current and planned capabilities.
  • All vendors submitted a video demonstration following a script to show specific product capabilities.
  • Gartner analysts reviewed relevant reviews from Gartner Peer Insights for the 12 months ending 27 April 2026.
  • Gartner analysts reviewed publicly available information, including blogs, vendor technical documentation, product specification sheets and financial information.

Critical Capabilities Methodology


This methodology requires analysts to identify the critical capabilities for a class of products or services. Each capability is then weighted in terms of its relative importance for specific product or service use cases. Next, products/services are rated in terms of how well they achieve each of the critical capabilities. A score that summarizes how well they meet the critical capabilities for each use case is then calculated for each product/service.
"Critical capabilities" are attributes that differentiate products/services in a class in terms of their quality and performance. Gartner recommends that users consider the set of critical capabilities as some of the most important criteria for acquisition decisions.
In defining the product/service category for evaluation, the analyst first identifies the leading uses for the products/services in this market. What needs are end-users looking to fulfill, when considering products/services in this market? Use cases should match common client deployment scenarios. These distinct client scenarios define the Use Cases.
The analyst then identifies the critical capabilities. These capabilities are generalized groups of features commonly required by this class of products/services. Each capability is assigned a level of importance in fulfilling that particular need; some sets of features are more important than others, depending on the use case being evaluated.
Each vendor’s product or service is evaluated in terms of how well it delivers each capability, on a five-point scale. These ratings are displayed side-by-side for all vendors, allowing easy comparisons between the different sets of features.
Ratings and summary scores range from 1.0 to 5.0:
1 = Poor or Absent: most or all defined requirements for a capability are not achieved
2 = Fair: some requirements are not achieved
3 = Good: meets requirements
4 = Excellent: meets or exceeds some requirements
5 = Outstanding: significantly exceeds requirements
To determine an overall score for each product in the use cases, the product ratings are multiplied by the weightings to come up with the product score in use cases.
The critical capabilities Gartner has selected do not represent all capabilities for any product; therefore, may not represent those most important for a specific use situation or business objective. Clients should use a critical capabilities analysis as one of several sources of input about a product before making a product/service decision.