Critical Capabilities for Security Service Edge

3 August 2026 - ID G00835763 - 27 min read
By Thomas Lintemuth, Theo de Feligonde,  and 2 more
Security service edge core capabilities have commoditized, while AI security, data sovereignty, and postquantum cryptography continue to evolve. Cybersecurity leaders must evaluate vendors across four use cases: essential SSE, advanced SSE, private application access, and SaaS and AI enablement.

Overview


Key Findings

Vendor differentiation and emerging competitive trends are observed within the security service edge (SSE) market:
  • Some vendors are leading the effort to offer postquantum cryptography (PQC) algorithms within the SSE market. ML-KEM is supported by some vendors, while ML-DSA is on most vendors’ roadmaps.
  • Access controls for AI sites are widely supported, with similar functionality across vendors. However, vendors vary significantly in the number of GenAI applications they identify, assess, and risk-profile.
  • Most vendors have little flexibility in moving the management plane of their SSE platform to a different geographical region. Customization of the network points of presence (PoPs) to use is more flexible, though sometimes difficult to implement.

Recommendations

As a cybersecurity leader responsible for infrastructure security and enabling a secure workplace, you should:
  • Determine if a basic SSE product will support your key use cases, and only buy extra capabilities that can be deployed in the first year. Additional capabilities can be licensed and added as needed.
  • Select a vendor that aligns with your PQC priorities, as some vendors are taking a wait and see approach to adding support for PQC algorithms.
  • Choose a vendor that supports your sovereignty requirements not only in capabilities, but also in ease of configuration.

What You Need to Know


Buyers must compare SSE vendors using rankings based on the capabilities and criteria most relevant to enterprise needs. Evaluate based on four use cases: essential SSE, advanced SSE, private application access, and SaaS and AI enablement.

Analysis


Critical Capabilities Use-Case Graphics

Figure 1: Vendors’ Product Scores for Essential SSE Use Case
8 providers are ranked on a 1 to 5 scale according to how well their offerings meet the needs of Essential SSE in Security Service Edge, as of June 2026. This allows comparison across a set of critical differentiators.
Figure 2: Vendors’ Product Scores for Advanced SSE Use Case
8 providers are ranked on a 1 to 5 scale according to how well their offerings meet the needs of Advanced SSE in Security Service Edge, as of June 2026. This allows comparison across a set of critical differentiators.
Figure 3: Vendors’ Product Scores for Private Application Access Use Case
8 providers are ranked on a 1 to 5 scale according to how well their offerings meet the needs of Private Application Access in Security Service Edge, as of July 2026. This allows comparison across a set of critical differentiators.
Figure 4:Vendor Product Scores for SaaS and AI Enablement Use Case
8 providers are ranked on a 1 to 5 scale according to how well their offerings meet the needs of SaaS and AI Enablement in Security Service Edge, as of June 2026. This allows comparison across a set of critical differentiators.

Vendors

Broadcom

Broadcom’s SSE offering, delivered through its Symantec Enterprise Cloud portfolio, provides a unified, cloud-delivered platform that offers strong data loss prevention and advanced threat intelligence features. Broadcom has a smaller number of PoP locations than others evaluated. Broadcom does support sandboxing and content disarm and reconstruction (CDR) for advanced threat detection.
Critical capabilities summary:
  • Data protection — Broadcom’s SSE supports ML-KEM, though it must be manually enabled by the administrator. There is no published roadmap for ML-DSA. Broadcom is one of two vendors to support searchable encryption and order preserving encryption. Microsoft Purview is also fully supported.
  • AIBroadcom has risk rated nearly 300 GenAI sites using 200 attributes. GenAI is available within the management console and can analyze local product documentation to help guide the deployment of policy rules.
  • SovereigntyBroadcom provides three regional options for hosting the platform management plane. Adjustment of PoPs for associate use is accomplished via updating proxy auto-config (PAC) files.
Use-case score summary: Broadcom scored below-average for the essential SSE use case and average for the remaining three. Organizations with strong data security requirements, particularly when already utilizing other Broadcom products, should evaluate Broadcom SSE.
Broadcom declined requests for supplemental information. Gartner’s analysis is therefore based on other credible sources.
Cisco

Cisco’s SSE product, Cisco Secure Access, offers integration with Cisco’s broader security and networking portfolio, providing simplified management and consistent policy enforcement. The product is less mature than others, so it can be complex to deploy compared to competitors. Cisco’s network has the fewest number of PoPs comparative to vendors evaluated. No CDR is available, while sandbox capability is offered.
Critical capabilities summary:
  • Data protection — Cisco offers no support for PQC algorithms. It has some integration with Microsoft Purview, including data encryption. It offers no support for advanced encryption in SaaS sites.
  • AICisco has risk rated nearly 4,000 GenAI sites using 15 attributes. GenAI is integrated into the management console to help users find information in product documentation.
  • SovereigntyCisco provides two regional options for the platform management plane. Adjustment of PoPs for associate use is limited.
Use-case score summary: Cisco scored average for all use cases. Organizations looking to bundle security and networking products with a single vendor should evaluate Cisco Secure Access.
Cloudflare

Cloudflare’s SSE product is marketed as Cloudflare One. For existing Cloudflare customers, it offers ease of deployment and scalability without requiring infrastructure changes. Some advanced features require additional configuration or expertise, which can be challenging for smaller IT teams. Cloudflare has a large, global network with PoPs that surpass all vendors evaluated. No CDR is offered.
Critical capabilities summary:
  • Data protection — Cloudflare offers full support for ML-KEM at no additional cost, while participating with standards bodies to bring ML-DSA to fruition. No support for advanced encryption in SaaS sites is available.
  • AI — Cloudflare has risk rated over 200 GenAI sites using 17 attributes. GenAI does not assist with rule creation.
  • Sovereignty Isolation of the management and/or control planes is not possible, as it replicates full-time between the U.S. and European Union. Adjustment of PoPs for associate use is possible, but requires a separate utility and offers less functionality than other vendors’ options.
Use-case score summary: Cloudflare scored below-average for the SaaS and AI enablement use case, and average for the remaining three. Organizations with modest feature requirements should consider Cloudflare One if they need an SSE vendor with a strong network and a strong commitment to postquantum algorithms.
iboss

iboss’ Zero Trust SSE is a single console built on a “containerized” cloud architecture. iboss offers excellent app and user risk scoring. Advanced threat detection includes strong CDR and sandboxing capability. Its digital experience monitoring (DEM) capability identifies users experiencing poorer performance than their peers.
Critical capabilities summary:
  • Data protectioniboss offers no support for PQC algorithms. It integrates well with Microsoft Purview. It offers no support for advanced encryption in SaaS sites.
  • AIiboss has risk rated over 1,000 GenAI sites using 25 attributes. GenAI is integrated into the management console to help users find information in product documentation.
  • Sovereigntyiboss provides four regional options, more than most vendors, to deploy its control and/or management planes. An option also exists to deploy hosted on customer premises. Associates can be assigned to specific PoPs; however, restricting access to particular PoPs is more challenging.
Use-case score summary: iboss scored above-average for the essential SSE use case and average for the remaining use cases. Organizations looking for a solid SSE product with strong adaptive access capabilities should consider iboss Zero Trust SSE.
Netskope

Netskope’s SSE, Netskope One SSE, has strong data protections and integrates well with third-party products. Integration with third-party vendors typically leverages a separate product, Cloud Exchange, which is separately downloaded, installed, and configured. Most capabilities are supported in the main console, which only supports the English language. Netskope offers solid global and U.S. PoP coverage. Netskope supports sandboxing, but not CDR, for advanced threat detection.
Critical capabilities summary:
  • Data protectionNetskope offers support for the ML-KEM PQC algorithm, both to front-end clients and back-end servers. It integrates well with Microsoft Purview. It offers some support for advanced encryption in SaaS sites.
  • AINetskope has risk rated nearly 1,300 GenAI sites using 127 attributes. GenAI is available in the management console and can assist with setting up rules in the access policy, though a separate interface is likely required.
  • SovereigntyNetskope offers its control and/or management planes in 13 countries. An option also exists to deploy hosted on customer premises. Assigning associates to specific PoPs requires the command line interface (CLI), as this capability is not available in the graphical user interface (GUI). The product requires a third-party identity provider that is geolocation-aware, to limit foreign administrator updates when out of jurisdiction.
Use-case score summary: Netskope scored above-average for all use cases. Organizations looking for a comprehensive SSE product with strong data and AI security should consider Netskope One SSE.
Palo Alto Networks

Palo Alto Networks markets its SSE capabilities as Prisma Access. Most configuration and management is performed in its cloud management platform, Strata Cloud Manager, while some sovereign controls require its on-premises platform, Panorama. Prisma Access has a strong ability to deliver “just-in-time” access control. Global PoP coverage is strong, although limited to hyperscalers, while U.S. coverage trails the market. Sandbox analysis is supported, while CDR is not.
Critical capabilities summary:
  • Data protectionPalo Alto offers support for ML-KEM. It has limited integration with Microsoft Purview. No support is provided for advanced encryption in SaaS sites.
  • AIPalo Alto has risk rated over 7,500 GenAI sites using 70 attributes. GenAI is available in Strata Cloud Manager and assists with rule development, offering a step-by-step process.
  • SovereigntyPalo Alto offers no options to deploy its control and/or management planes when using its Strata Cloud Manager. While specific PoPs can be designated for users of the product, the platform does not support explicit PoP exclusions.
Use-case score summary: Palo Alto Networks scored above-average for all use cases. Organizations looking for a strong SSE product with strong support for postquantum cryptography should consider Palo Alto Networks’ Prisma Access.
Skyhigh Security

Skyhigh Security’s SSE offering is called Skyhigh Security Service Edge. Skyhigh has very strong data security and adaptive access capabilities. Global PoP coverage trails the market. A unique feature is the ability to display a risk visualization for each discovered SaaS app. No support for DNS resolution nor CDR is provided.
Critical capabilities summary:
  • Data protection.Skyhigh offers support for ML-KEM and ML-DSA. It has strong integration with Microsoft Purview. It offers support for advanced encryption in SaaS sites, including tokenization of data at the field level, searchable encryption, and order-preserving encryption.
  • AISkyhigh has risk rated over 1,900 GenAI sites using 110 attributes. GenAI is available in the management console and has an advanced capability to generate new rules, though it does require a separate interface to action the rule.
  • SovereigntySkyhigh offers its control and/or management planes in five regions, including the U.K. An option also exists to deploy the SSE platform on-premises. Users can configure specific PoPs for associates to use, but the functionality is not intuitive. Controls are available to ensure that out-of-region administrators can view policy without being able to change it.
Use-case score summary: Skyhigh Security scored average for the essential SSE use case and above-average for the remaining three. Organizations requiring a leading technical SSE product with advanced data security and GenAI capabilities should consider Skyhigh Security Service Edge.
Zscaler

Zscaler’s SSE offering, Zscaler Platform, has unified functionality managed via a single console. Threat detection includes sandbox capabilities and CDR. Global PoP coverage is solid, but coverage is average in the U.S.
Critical capabilities summary:
  • Data securityZscaler offers support for PQC by supporting ML-KEM and providing a PQC visibility report. Both are included at no additional cost. It integrates well with Microsoft Purview. It offers very limited support for advanced encryption in SaaS sites. Bring your own key for data at rest is not supported.
  • AIZscaler has risk rated over 10,000 GenAI sites using 123 attributes. GenAI is available in the management console and an advanced capability to generate new rules from the GUI is provided.
  • SovereigntyZscaler has limited locations where it offers its control and/or management planes. PoP selection is enforced through PAC technology, though it is configured by the Zscaler Experience Center. Rules can be put in place to block out-of-region administrator use, but it is all or nothing, with viewing and editing restricted.
Use-case score summary: Zscaler scored average for the essential SSE use case and above-average for the remaining three. Organizations looking for a feature-rich SSE product without leading Sovereignty controls should evaluate Zscaler.

Context

This Critical Capabilities focuses on vendors relevant to large enterprises with a broad global footprint. These vendors offer stand-alone SSE capabilities as part of a dual secure access service edge (SASE) deployment, often integrated with a multivendor edge networking capability. SSE buyers are led by security teams that do not have the budget or remit to change their edge networking at the same time that they are buying the security capabilities of a SASE framework. Vendors selling and marketing stand-alone SSE put an emphasis on partnerships and interoperability with third-party software-defined WAN (SD-WAN) providers, rather than their own SD-WAN offering. However, the trend in the market is toward SASE platforms.
Gartner sees impact to SSE buyers due to geopolitical landscape changes and an increased interest in sourcing vendors from regional providers with less dependency on foreign-provided security products. All vendors assessed in this Critical Capabilities report are headquartered in North America and typically have legal entities or subsidiaries in other countries. Most vendors offer a large cloud point of presence and various sovereignty options to address a growing demand by organizations to control networking and data within specific geographic boundaries.
The shift in SSE buying evaluations due to the rapid adoption of AI shapes buyer priority in the market, but most SSE buyers are not responsible for all AI security and governance. We assess the needs of SSE security buyers with capabilities to secure the use of AI by end users specifically, rather than the whole of AI security, which is more tightly coupled with SSE product offerings.
Finally, evaluations by SSE buyers increasingly include questions about postquantum readiness and crypto-agility. We assess a vendor’s ability to provide postquantum support today.

Market Definition

Gartner defines security service edge (SSE) as an offering that secures access to the web, cloud services and private applications regardless of the location of the user, the device they are using or where that application is hosted. SSE protects users from malicious and inappropriate content on the web and provides enhanced security and visibility for the SaaS, generative AI and private applications accessed by end users.
Security service edge provides a primarily cloud-delivered solution to control access by end users and devices to applications, websites and the internet. It provides a range of security capabilities, including adaptive access based on identity and context, malware protection, data security and threat prevention, as well as the associated analytics and visibility.
SSE reduces latency by enabling more direct connectivity for hybrid users and providing the potential for improved user experience. Capabilities that are integrated across multiple traffic types and destinations allow a more seamless experience for both users and administrators while maintaining a consistent security stance.

Mandatory Features

The mandatory features of this market include:
  • Management and data planes that are primarily cloud-delivered
  • Identity-aware forward proxy with decryption for data- and threat-protection capabilities
  • In-line threat and protection of data in generative AI, SaaS and private apps
  • Out-of-band protection of data in SaaS apps via API integration
  • Adaptive and granular access control supporting both devices with an SSE agent (or similar traffic steering method) and devices with no local SSE software or configurations
  • Integration with an identity provider

Optional Features

The optional features of this market include:
  • Single integrated console supporting all features and functions of the platform
  • Ability to apply controls consistently across multiple network and application destinations
  • Support for managing and securing traffic from all common endpoints (such as Windows, macOS, iOS and Android devices)
  • Support for managing and securing traffic from a full stack secure enterprise browser or extension
  • Integration with key enterprise technologies such as security information and event management (SIEM), workspace security, SD-WAN and other adjacent technologies
  • Support for published and documented APIs that are accessible to the customer and that allow automation of common tasks and integration with other security platforms
  • Curated, managed and risk-scored catalogs of SaaS and generative AI applications
  • Control of traffic on all ports and protocols
  • Remote browser isolation (RBI) to enhance security across all network destinations and channels
  • SaaS security posture management for visibility and remediation of SaaS configurations and visibility into SaaS plug-in applications and connections
  • Read, write and act-upon labels from common data classification platforms
  • Embedded user entity behavior analytics (UEBA) to provide automated detection and response for anomalous and risky devices and user behaviors

Product/Service Trends

SSE secures access to the web, cloud services and private applications. Capabilities include access control, threat protection, data security, security monitoring and acceptable use control enforced by network-based and API-based integration. SSE is most commonly delivered as a cloud-based service, though data sovereignty issues are forcing vendors to provide fully on-premises options.
The vendor convergence trend has been driving organizations to deploy a “single” SSE product, versus the three primary independent products: secure web gateway, zero-trust network access, and cloud access security broker (CASB). Further driving the market is organizations’ desire to have a unified access model for users, regardless of whether they are working on-premises or remotely. A constant undercurrent driving interest in SSE is the desire to use zero-trust principles for access control.

Critical Capabilities Definition

Ease of Administration

The product includes ease of administration from a security operations perspective. The goal is for the operations team to be able to perform its duties in a simple and efficient way.
This includes management platforms, monitoring, integrations, and automation capabilities across initial provisioning and configuration, ongoing operations, and incident response. The administration portal must have a clean interface and be intuitive to use. Information on the uptime of the vendors’ platform should be available. Reports relevant to the operation and status of the platform are critical.
Threat Protection

The product includes the ability to detect attacks and custom threats, with features such as sandboxes, remote browser isolation (RBI), malware engines and threat intelligence. It provides multiple methods to detect and mitigate active threats concurrently across web, SaaS and private applications.
Adaptive Access

The product uses near-real-time context to control access to a resource based on a risk score, including factors such as user identity, device identification and hygiene, location, and user activity. Access can be dynamically adjusted in near real time as the risk score changes.
Evaluation looks at the richness and frequency of updates of the risk score. This includes enforcement across various channels and derivation of risk via cross-channel behaviors, device state visibility, and user entity behavior analysis (UEBA) capabilities.
Securing Private Applications

The product provides zero-trust access control to private applications (on-premises, colocated and IaaS cloud-based) based on user/device identity and context.
It favors an architecture that uses a broker connector with no persistent inbound ports open to the internet, thereby reducing the attack surface. By default, access is limited to individual applications through policy-based controls, rather than broad access to entire network segments. This is primarily associated with remote workers, but also extends to branch workers and devices, including IoT/OT, and both managed and unmanaged devices. We evaluate the ability to provide policy enforcement points through both vendor-provided, cloud-hosted services and delivered as virtual or physical appliance enforcement point onramps. Products should facilitate authentication and authorization of users and/or devices using open standards.
Securing SaaS Applications

The product includes a granular set of controls for securing access to websites and social media sites.
These controls drive policy actions based on the type of site visited.
This capability includes proxy functions including decryption of traffic that allows content inspection, as well as support for threat defense and data security capabilities.
Further, this capability includes discovery and risk rating of SaaS applications, as well as integration with SaaS vendor application APIs to gain visibility into SaaS. We assess the range of applications that can be integrated, the depth of data security, threat defense and any differentiated API capabilities, such as visibility, configuration, or interconnection of SaaS applications. This capability includes visibility and control for data at rest in sanctioned and unsanctioned enterprise SaaS applications, including discovery and usage.
Data Security

The product includes a data loss prevention (DLP) engine providing advanced sensitive data detection techniques, such as the use of machine learning and generative AI.
The product must also integrate with third-party data classification providers as part of a wider data security ecosystem. It must support inspection across web, SaaS and private applications, regardless of file type. It can enforce policy based on file size. It prevents users from unauthorized sharing or destruction of organizational data. It also has support for postquantum algorithms.
Enterprise Integration

The product integrates with a customer’s currently deployed products. This requires it to ingest data from third-party products and to send data to other products. The product also offers native integration with leading identity providers.
It also must integrate with any SD-WAN products currently deployed. Advanced capabilities include digital experience monitoring to detect user-to-application issues. Functionality requires a minimum number of agents. PoPs must be geographically relevant for the customer.
AI Security

The product enables the discovery and cataloging of third-party generative AI, and the application of in-line access and sensitive data controls to prevent data leakage, as well as discovery and policy enforcement of nonhuman identity AI agents.
It includes application control policies, reputational risk assessment and GenAI as a separate URL classification category. Advanced features include granular control for the most popular enterprise GenAI products, including differentiation between access using a personal account versus a corporate account. It also includes the ability to capture, inspect and log end-user prompt inputs, integration via API into private tenants for enhanced security, prevention of sensitive data uploads via prompts or file uploads, and visibility into the use of third-party GenAI APIs from the corporate network. It also supports policy enforcement of sanctioned AI agents and shadow AI agents when accessing web, SaaS and private applications.
Sovereignty Controls

The product includes the ability to provide organizational control over a range of options across a vendor’s SSE offering, including its control plane, data plane, management plane and support requirements.
For the control plane, we assess options for delivery of access and policy decisions. For the data plane, we focus primarily on delivery of traffic inspection, policy enforcement, traffic routing and encryption/decryption options. For the management plane, we evaluate delivery of the orchestration software for policy configuration, life cycle management of encryption keys, and options for storage of logs and other data. We analyze corporate ownership, employee citizenship and compliance with specific regulations.

Use Cases

Essential SSE

This use case focuses on the security and accessibility capabilities of a product to connect users to enterprise resources, whether the applications are private or SaaS-based.
Advanced SSE

This use case builds on the foundational capabilities of essential SSE, adding enhanced security, including real-time access, data protection, and robust end-user monitoring.
This may include add-on products to round out the full capabilities of an advanced SSE product suite.
Private Application Access

This use case focuses on how vendors support on-premises users accessing private applications, while minimizing reliance on off-premises elements.
Products should support any type of network protocol, whether transmission control protocol or user datagram protocol-based, initiate connections from the server out to the endpoint, and support disaster-recovery options.
SaaS and AI Enablement

This use case focuses on providing secure access to SaaS, web, and AI applications.
This use case emphasizes securing the use of AI, cloud application discovery and configuration, and control of managed SaaS applications.

Vendors Added and Dropped

Added

  • Cisco

Dropped

  • Fortinet
  • Versa

Inclusion and Exclusion Criteria


To qualify for inclusion, the provider’s SSE offering must: 
  • Be operated as a service. The offering must be delivered primarily as a cloud-hosted (“SaaS”) service, securing authorized users on allowed endpoints to appropriate services running in public or private clouds and on-premises environments.
  • Demonstrate broad market adoption as an independently deployed SSE offering, separate from any SD-WAN or other networking capabilities provided by the same vendor, with strong supporting evidence available to Gartner. These capabilities must have been generally available by 1 May 2026. The capabilities are: 
    • Secure access to the internet from common managed devices (including at minimum Windows, macOS, Android, and iOS) via proxy. Provide URL filtering and advanced threat defense to protect users and enforce acceptable use policies.
    • Secure usage of SaaS, both through in-line visibility and controls AND via API integration
  • Provide visibility, compliance enforcement, data security, and threat protection for the use of SaaS and Generative AI applications.
  • Both monitor and remediate issues via a proxy product (in-line) and API integrations 
  • API integration for CASB functions must include coverage of at least five of the following SaaS apps: Microsoft Office 365, Google Workspace, Salesforce, Workday, Oracle Fusion/Oracle Business Suite, Microsoft Dynamics/Dynamics 365, ServiceNow, Snowflake, Palantir, Atlassian Suite, or GitHub. Security must include threat protection, data protection, and include both detection and prevention capabilities.
  • In-line security must be provided from managed devices to any SaaS application and be enforceable from unmanaged devices via integration with an identity provider (IdP) to control access to SaaS applications integrated with the IdP. Security must include threat protection, data protection, and include both detection and prevention capabilities.
  • Provide secure remote access to private applications hosted on-premises or in the public cloud, using zero-trust principles by incorporating identity- and context-based logical-access boundaries for access.
  • Provide visibility, basic controls (e.g., block, warn, allow), and inspection for sensitive data for at least three of the following generative AI apps: Microsoft Copilot, OpenAI ChatGPT, Google Gemini, Grok AI, Perplexity, DeepSeek, and Anthropic Claude, initiated by an end user from the endpoint.
  • Provide visibility to the state of common, managed endpoints through a native agent for third-party integrations on Windows, macOS, Android, and iOS, and enable access decisions in that context.

An SSE vendor must also demonstrate scale relevant to enterprise-class organizations, measured by all of the following criteria:
  • As of 1 March 2026, have at least 300 large enterprise customers securing web, SaaS, and private applications using their primary SSE product, independent of their SD-WAN, or grew at least 50% in number in the past 12 months. 
  • As of 1 March 2026, have at least three million seats securing web, SaaS, and private applications using their primary SSE product, independent of their SD-WAN, under paid support, or grew at least 50% in number of seats under paid support in the past 12 months.

An SSE vendor must also demonstrate relevance to global organizations by:
  • Leveraging PoP infrastructure meeting all the following requirements.
  • Presence in at least 15 distinct geographic metropolitan cities globally, with at least three distinct metropolitan cities in each of the three major regions: EMEA, North and South America, and Asia/Pacific
  • PoPs are in a highly secure facility and offer all of the following services locally (intra-PoP), with general availability to all enterprise customers: web proxy, private access, and in-line SaaS control with high availability.
  • Vendors must provide a publicly available URL with a PoP metropolitan cities list, PoP monitoring/status capability and a documented PoP SLA.
  • Providing strong evidence that 10% or more of its customer base is outside its home region (North America, EMEA or Asia/Pacific) and is actively marketing and enhancing its SSE offering.
  • Primarily selling its SSE functionality independent of its SD-WAN or SASE platform offering, as well as making strategic roadmap investments for SSE independent of SASE platforms, and/or Gartner evidence customers are primarily evaluating SSE as a stand-alone capability independent of the vendor’s SASE platform offering.

Weighting for Critical Capabilities in Use Cases

Critical CapabilitiesEssential SSEAdvanced SSEPrivate Application AccessSaaS and AI Enablement
Ease of Administration
40%
5%
5%
5%
Threat Protection
10%
15%
5%
10%
Adaptive Access
5%
20%
25%
10%
Securing Private Applications
20%
5%
30%
0%
Securing SaaS Applications
0%
10%
5%
30%
Data Security
0%
15%
5%
15%
Enterprise Integration
20%
5%
10%
10%
AI Security
5%
10%
5%
20%
Sovereignty Controls
0%
15%
10%
0%
As of 20 July 2026
Source: Gartner (August 2026)
This methodology requires analysts to identify the critical capabilities for a class of products/services. Each capability is then weighted in terms of its relative importance for specific product/service use cases.

Critical Capabilities Rating

Each of the products/services that meet our inclusion criteria has been evaluated on the critical capabilities on a scale from 1.0 to 5.0.

Product/Service Rating on Critical Capabilities

Critical CapabilitiesBroadcomCiscoCloudflareibossNetskopePalo Alto NetworksSkyhigh SecurityZscaler
Ease of Administration
2.5
3.4
3.1
4.0
3.7
4.2
3.4
3.3
Threat Protection
2.5
4.5
3.5
3.9
4.0
4.5
3.6
4.1
Adaptive Access
2.7
3.4
3.2
4.0
4.4
4.4
4.9
4.7
Securing Private Applications
3.3
3.1
3.1
3.7
3.9
4.1
3.8
4.0
Securing SaaS Applications
4.0
3.3
2.5
4.0
4.0
4.3
3.9
3.8
Data Security
2.9
3.2
2.2
3.2
4.3
3.9
4.8
4.1
Enterprise Integration
2.5
3.7
3.8
3.8
4.3
3.8
3.5
4.2
AI Security
3.6
3.7
2.9
3.5
4.3
4.1
4.0
4.4
Sovereignty Controls
4.0
2.7
1.4
4.0
4.1
3.7
4.2
3.8
As of 20 July 2026
Source: Gartner (August 2026)
Table 3 shows the product/service scores for each use case. The scores, which are generated by multiplying the use-case weightings by the product/service ratings, summarize how well the critical capabilities are met for each use case.

Product Score in Use Cases

Use CasesBroadcomCiscoCloudflareibossNetskopePalo Alto NetworksSkyhigh SecurityZscaler
Essential SSE
2.73
3.53
3.28
3.87
3.96
4.14
3.63
3.83
Advanced SSE
3.13
3.45
2.75
3.79
4.17
4.14
4.20
4.14
Private Application Access
3.09
3.33
2.96
3.82
4.13
4.13
4.12
4.16
SaaS and AI Enablement
3.25
3.54
2.87
3.75
4.16
4.18
4.06
4.10
As of 20 July 2026
Source: Gartner (August 2026)
To determine an overall score for each product/service in the use cases, multiply the ratings in Table 2 by the weightings shown in Table 1.

Acronym Key and Glossary Terms


CASB
Cloud access security broker
CDR
Content disarm and reconstruction
DEM
Digital experience monitoring
DLP
Data loss protection
EDM
Exact data matching
EDR
Endpoint detection and response
GenAI
Generative AI
IdP
Identity provider
IoT
Internet of Things
ML
Machine learning
ML-KEM
Module-Lattice-Based Key Encapsulation Mechanism
ML-DSA
Module-Lattice-Based Digital Signature Algorithm
PAC
Proxy auto-config
PoP
Point of presence
PQC
Postquantum cryptography
SD-WAN
Software-defined WAN
SASE
Secure access service edge
SSE
Security service edge
UEBA
User entity behavior analysis
UEM
Unified endpoint management

Critical Capabilities Methodology


This methodology requires analysts to identify the critical capabilities for a class of products or services. Each capability is then weighted in terms of its relative importance for specific product or service use cases. Next, products/services are rated in terms of how well they achieve each of the critical capabilities. A score that summarizes how well they meet the critical capabilities for each use case is then calculated for each product/service.
"Critical capabilities" are attributes that differentiate products/services in a class in terms of their quality and performance. Gartner recommends that users consider the set of critical capabilities as some of the most important criteria for acquisition decisions.
In defining the product/service category for evaluation, the analyst first identifies the leading uses for the products/services in this market. What needs are end-users looking to fulfill, when considering products/services in this market? Use cases should match common client deployment scenarios. These distinct client scenarios define the Use Cases.
The analyst then identifies the critical capabilities. These capabilities are generalized groups of features commonly required by this class of products/services. Each capability is assigned a level of importance in fulfilling that particular need; some sets of features are more important than others, depending on the use case being evaluated.
Each vendor’s product or service is evaluated in terms of how well it delivers each capability, on a five-point scale. These ratings are displayed side-by-side for all vendors, allowing easy comparisons between the different sets of features.
Ratings and summary scores range from 1.0 to 5.0:
1 = Poor or Absent: most or all defined requirements for a capability are not achieved
2 = Fair: some requirements are not achieved
3 = Good: meets requirements
4 = Excellent: meets or exceeds some requirements
5 = Outstanding: significantly exceeds requirements
To determine an overall score for each product in the use cases, the product ratings are multiplied by the weightings to come up with the product score in use cases.
The critical capabilities Gartner has selected do not represent all capabilities for any product; therefore, may not represent those most important for a specific use situation or business objective. Clients should use a critical capabilities analysis as one of several sources of input about a product before making a product/service decision.