Market Direction
As with the rest of the enterprise networking market, SD-WAN products are evolving with agentic NetOps capabilities, moving from manual to more autonomous management control. Fed by word of mouth and market hype, enterprise customers are seeking products with greater agentic AI integration. They also are placing high priorities on additional security and sovereignty control in response to more sophisticated cyberattacks and increased geopolitical tensions.
Agentic AI Technology Integration Deepens
Capitalizing on AI technology evolution, SD-WAN vendors are embedding agentic NetOps into their products to automate and streamline their SD-WAN products’ Day 1 and Day 2 life cycle management workflows. Agentic NetOps introduces AI agents, which are autonomous or semiautonomous software entities that use AI techniques to perceive, make decisions, take actions and achieve goals. Initially, implementations will be semiautonomous, with human oversight; gradually, this will transition to more autonomous agentic NetOps once there is sufficient confidence in the technology.
AI agents built into SD-WAN products can sense network conditions, interpret goals, produce explainable multistep plans and execute approved actions with verification, rollback and policy guardrails. As a result, agentic NetOps improves SD-WAN products’ ability to detect, troubleshoot and resolve network configuration issues and incidents. This benefit is evolving beyond single products, as SD-WAN vendors add Model Context Protocol (MCP) support allowing agents from other network products such as ITSM tools to interact with their products.
SD-WAN vendors also will continue to support network AI assistants, which are interactive digital tools backed by GenAI and machine learning (ML) technologies that allow human users to communicate via conversational, natural language chat interfaces. These assistants serve as the communications interface between human engineers and AI agents.
SD-WAN offerings in the near future will add AI agent traffic management through expanded applications health monitoring and applications-aware path steering capabilities. These features will become a greater priority for enterprises investing in private AI inference and LLMs.
PQC Protection Is a Priority
SD-WAN vendors are adding PQC capabilities to their offerings via hardware upgrades and post-quantum algorithms supported by standards bodies such as the National Institute of Standards and Technology (NIST). This includes ML-KEM for quantum-safe key exchange, ML-DSA for quantum-safe digital signatures and LMS to protect firmware and software at a systems level.
This also includes PQC post-quantum pre-shared keys (PPK) that can strengthen traditional IPsec encryption keys. Layered within traditional IPsec session keys, PPK are unique and cannot be captured even using a cryptographically relevant quantum computer (CRQC). So even if hackers armed with a CRQC manage eventually to break IPsec encryption, they cannot capture the session keys to harvest any data from network traffic.
Organizations Seek Sovereignty Controls
Driven by geopolitical developments and new regulatory requirements such as the European Union’s General Data Protection Regulation (GDPR), more organizations are prioritizing SD-WAN offerings that enforce sovereignty policies. This includes not only regulating the flow of data traffic within specific geographical boundaries but also where network data and logs are stored and where the SD-WAN orchestrator is hosted.
In response, SD-WAN vendors are adding network traffic steering controls that set geographic routing policy, including router hops and cloud POP locations used to access applications and hosted SD-WAN gateways. This also includes analytics to ensure sovereign policy compliance. By extension, vendor SASE products also offer sovereignty network and security capabilities including geographically aware access control.
Security Convergence Strengthens
Network and security convergence continues to be the dominant trend in the SD-WAN market, often driving enterprise buyer decisions. Standalone SD-WAN with no security capabilities is rare, as most major vendor products at minimum support Layer 4 firewalls and commonly, Layer 7 firewalls.
The SASE migration path, in turn, may be changing. Enterprises have favored dual-vendor, tightly integrated SASE deployments, where a vendor’s SD-WAN product is integrated with a third-party cloud-delivered SSE offering. This pairing offers enterprises best-of-breed network and security management. However, Gartner sees more growth potential for SASE platform offerings where the SD-WAN and SSE elements are offered by a single vendor as part of an integrated platform (see Magic Quadrant for SASE Platforms).
At the same time, there is growing concern about SD-WAN products’ security, thanks in part to the rise of AI. Hackers using sophisticated, frontier AI LLMs can more easily discover and exploit SD-WAN software vulnerabilities, potentially increasing the number of Common Vulnerabilities and Exposures (CVEs), and potentially exposing enterprise customers’ networks. In response, network teams will need to accelerate SD-WAN patching to reduce the risk.
Additional Trends
Other trends Gartner sees based on SD-WAN vendor product roadmaps and enterprise buying trends include:
Coffee Shop Networking
While many organizations have reinstituted in-office work policies in the post-COVID-19 era, there is still interest in distributed work-from-anywhere connectivity management, commonly referred to as coffee shop networking. In this scenario, users split time between corporate offices and remote locations, accessing corporate applications in the cloud using internet-based connectivity. Application traffic primarily flows from cloud service provider points of presence (POPs) to users, lessening the need for east-west traffic control between a corporate branch and data center.
This, combined with fewer people working in offices at any given time, reduces the need for full-featured SD-WAN functionality to reduce bandwidth contention or support complex topologies such as dynamic full-mesh routing. Security integrated with on-premises SD-WAN appliances is also less of a need in favor of cloud-based security orchestration delivered by SSE.
As a result, enterprises opting for coffee shop networking management require lower-cost, lighter-weight SD-WAN products. In rare scenarios, enterprises eliminate SD-WAN altogether. That said, overall interest in coffee-shop networking is limited, as many organizations still use private network connectivity and rely on private applications hosted at a corporate data center or colocation facility. Gartner estimates that approximately 10% to 20% of enterprise sites are interested in coffee shop networking.
SD-Branch
Customer interest is growing for SD-WAN offerings that unify WAN, LAN/WLAN and security orchestration and control via a single GUI. This offers customers simplified vendor management as well as greater visibility and consistent network and security policy management across LAN and WAN environments, particularly for small branch locations. As with more full-featured SD-WAN offerings, SD-Branch vendor products increasingly are being integrated with SSE to deliver a SASE solution.
Connectivity Support
SD-WAN offerings commonly support a variety of underlay connectivity options such as MPLS and dedicated internet access. However, vendors are expanding this to include additional support for WAN connectivity options such as fixed wireless access, including 5G cellular fixed wireless access. This can include added features such as link bonding across satellite and cellular wireless connections and support for cellular eSIM provisioning.