Market Guide for SD-WAN

5 August 2026 - ID G00854373 - 16 min read
By Karen Brown, Jonathan Forest
While the software-defined WAN market is mature and becoming a feature of SASE, vendors are adding AI, data sovereignty and quantum-safe networking support. As a result, there continues to be vendor product differentiation, so heads of I&O can use this analysis to optimize SD-WAN investment.

Overview


Key Findings

  • SD-WAN solutions are a feature within secure access service edge (SASE) offerings, but a subset of vendors also sell SD-WAN as a standalone product.
  • While mature, the SD-WAN market is adding new features, driven by growing enterprise demand for post-quantum cryptography (PQC) protection, AI-based management efficiency and digital sovereignty capabilities.
  • SD-WAN vendors are expanding their AI technology to include agentic NetOps to support streamlined workflows and evolve toward autonomous network operations.
  • Incumbent provider preference, ease of use, cloud onramp and security enforcement are key SD-WAN features that drive many enterprises’ buying decisions.

Recommendations

  • Choose an SD-WAN vendor that aligns with your enterprise’s security service edge (SSE) and/or SASE vendor strategy.
  • When selecting SD-WAN products, prioritize vendors that support PQC protection, integrated AI and sovereignty enforcement, the latter depending on your organization’s policies.
  • Pilot SD-WAN vendors’ offerings to determine effectiveness and value of automation, AI and agentic AI capabilities.
  • If your organization has a cloud-only or cloud-first applications strategy, select SD-WAN vendors that offer strong cloud onramp and features and ease of use.

Strategic Planning Assumption


  • By 2029, 75% of SD-WAN purchases will be part of a single-vendor SASE platform offering, up from 35% in 2026.
  • By 2030, 70% of enterprise SD-WAN deployments will be self-managed or co-managed, up from less than 50% in 2026.

Market Definition


Gartner defines software-defined WAN (SD-WAN) as products that connect branch locations to other enterprise and cloud locations. SD-WAN products provide application-aware, dynamic path selection based on business or application policy. They also support routing, centralized orchestration of policy and management of appliances, virtual private networks (VPNs), and zero-touch configuration. SD-WAN products are WAN transport/carrier-agnostic and create secure paths across physical WAN connections.
SD-WAN products enable secure connectivity between enterprise locations and the cloud. They aid enterprise evolution from private to internet-based networks as traffic shifts from applications hosted in private data centers to public cloud and SaaS.

Mandatory Features

The mandatory features for SD-WAN offerings include:
  • Ability to replace a branch router (for example, support for Border Gateway Protocol [BGP])
  • Application-aware dynamic path selection (for example, Layer 7 traffic steering) across multiple physical interfaces
  • Virtual private networks
  • Automated IPsec/GRE tunnel setup to connect with security service edge (SSE) vendor POPs
  • A centralized mechanism for:
    • Configuration (zero-touch configuration)
    • Programmability via API
    • Management
    • Visibility/analytics/troubleshooting
    • Reporting
  • Form factors for branch, data center and cloud locations:
    • Software that can be deployed on a branded hardware appliance or third-party hardware at a branch, data center or other enterprise location
    • Software deployed in the public cloud as a virtual instance

Optional Features

The optional features for SD-WAN offerings include:
  • Branded hardware appliances
  • Software delivered as a virtual network function (VNF), virtual machine (VM) or container
  • Software-only solution deployable on an end-user device for remote users
  • API support
  • URL/content filtering and anti-malware features
  • Service chaining capabilities, and the ability to integrate with third-party SSE vendors
  • Advanced on-premises security (for example, Layer 7 firewalls and data loss prevention [DLP])
  • Support for postquantum cryptography (PQC) algorithms to enhance data security and prevent harvest now/decrypt later attacks
  • Application performance optimization capabilities (for example, WAN optimization, forward error correction [FEC], packet duplication and SaaS optimization)
  • Controls that limit data traffic within specific geographic boundaries to support data sovereignty use cases.
  • Orchestration and integration with cloud service providers to simplify cloud onramp
  • Native cloud gateways for service insertion
  • Extended orchestration beyond SD-WAN to include wireless LAN (WLAN)/LAN/security to form SD-Branch
  • Agentic NetOps, where AI agents can perform goal-oriented configuration management, incident management and documentation access tasks

Market Description


The focus of this research is SD-WAN solutions that organizations purchase from vendors and resellers to self-manage their WAN environments. Customers can also purchase SD-WAN as a managed service through a network or managed services provider.
The SD-WAN market is diverse, consisting of dozens of competitor offerings. Vendors commonly sell SD-WAN either as part of a SASE platform offering or integrated with partner SSE offerings for deployment as dual-vendor SASE.
Most major vendor offerings support routing and “good enough” network management features such as path selection. However, SD-WAN’s network management capabilities are expanding, as vendors add agentic AI integration to support better life cycle management, visibility and analytics. Vendors also are adding support for new requirements such as digital sovereignty and quantum-safe networking.
That said, support for these more sophisticated features varies among vendor products. Because of this, there are several key purchasing drivers buyers must consider, including:
  • Administrative ease of use: Support for Day 1 setup and Day 2 management. This is delivered through a centralized GUI.
  • Cloud onramp: Gateway functions, orchestration and integration to simplify connectivity to a broad range of popular infrastructure as a service (IaaS) providers such as AWS, Microsoft Azure and Google Cloud and SaaS providers such as SAP and Salesforce.
  • AI traffic management: Strong dynamic path steering and network performance monitoring features to manage and optimize growing agent traffic.
  • Security support: Integrated firewall and added postquantum cryptography (PQC) algorithms and pre-sharded security keys to enhance data security and prevent harvest now/decrypt later attacks.
  • Sovereignty: Routing controls that can pass through or avoid certain countries or regions. This also sets policies as to where SD-WAN telemetry is stored and where the orchestration platform is hosted, all based on customers’ data sovereignty policies.
  • Advanced path selection: Rapid failover resulting from brownout conditions such as elevated packet loss, latency and jitter.
  • Support for complex environments: Support for varied topologies and additional routing protocols.
  • Deployment flexibility: Software and physical form factors that can scale to manage low- to high-bandwidth connections and connection types including wireline and cellular links.
  • Cost: Hardware, software and support investments during a three- to five-year life cycle.

Market Direction


As with the rest of the enterprise networking market, SD-WAN products are evolving with agentic NetOps capabilities, moving from manual to more autonomous management control. Fed by word of mouth and market hype, enterprise customers are seeking products with greater agentic AI integration. They also are placing high priorities on additional security and sovereignty control in response to more sophisticated cyberattacks and increased geopolitical tensions.

Agentic AI Technology Integration Deepens

Capitalizing on AI technology evolution, SD-WAN vendors are embedding agentic NetOps into their products to automate and streamline their SD-WAN products’ Day 1 and Day 2 life cycle management workflows. Agentic NetOps introduces AI agents, which are autonomous or semiautonomous software entities that use AI techniques to perceive, make decisions, take actions and achieve goals. Initially, implementations will be semiautonomous, with human oversight; gradually, this will transition to more autonomous agentic NetOps once there is sufficient confidence in the technology.
AI agents built into SD-WAN products can sense network conditions, interpret goals, produce explainable multistep plans and execute approved actions with verification, rollback and policy guardrails. As a result, agentic NetOps improves SD-WAN products’ ability to detect, troubleshoot and resolve network configuration issues and incidents. This benefit is evolving beyond single products, as SD-WAN vendors add Model Context Protocol (MCP) support allowing agents from other network products such as ITSM tools to interact with their products.
SD-WAN vendors also will continue to support network AI assistants, which are interactive digital tools backed by GenAI and machine learning (ML) technologies that allow human users to communicate via conversational, natural language chat interfaces. These assistants serve as the communications interface between human engineers and AI agents.
SD-WAN offerings in the near future will add AI agent traffic management through expanded applications health monitoring and applications-aware path steering capabilities. These features will become a greater priority for enterprises investing in private AI inference and LLMs.

PQC Protection Is a Priority

SD-WAN vendors are adding PQC capabilities to their offerings via hardware upgrades and post-quantum algorithms supported by standards bodies such as the National Institute of Standards and Technology (NIST). This includes ML-KEM for quantum-safe key exchange, ML-DSA for quantum-safe digital signatures and LMS to protect firmware and software at a systems level.
This also includes PQC post-quantum pre-shared keys (PPK) that can strengthen traditional IPsec encryption keys. Layered within traditional IPsec session keys, PPK are unique and cannot be captured even using a cryptographically relevant quantum computer (CRQC). So even if hackers armed with a CRQC manage eventually to break IPsec encryption, they cannot capture the session keys to harvest any data from network traffic.

Organizations Seek Sovereignty Controls

Driven by geopolitical developments and new regulatory requirements such as the European Union’s General Data Protection Regulation (GDPR), more organizations are prioritizing SD-WAN offerings that enforce sovereignty policies. This includes not only regulating the flow of data traffic within specific geographical boundaries but also where network data and logs are stored and where the SD-WAN orchestrator is hosted.
In response, SD-WAN vendors are adding network traffic steering controls that set geographic routing policy, including router hops and cloud POP locations used to access applications and hosted SD-WAN gateways. This also includes analytics to ensure sovereign policy compliance. By extension, vendor SASE products also offer sovereignty network and security capabilities including geographically aware access control.

Security Convergence Strengthens

Network and security convergence continues to be the dominant trend in the SD-WAN market, often driving enterprise buyer decisions. Standalone SD-WAN with no security capabilities is rare, as most major vendor products at minimum support Layer 4 firewalls and commonly, Layer 7 firewalls.
The SASE migration path, in turn, may be changing. Enterprises have favored dual-vendor, tightly integrated SASE deployments, where a vendor’s SD-WAN product is integrated with a third-party cloud-delivered SSE offering. This pairing offers enterprises best-of-breed network and security management. However, Gartner sees more growth potential for SASE platform offerings where the SD-WAN and SSE elements are offered by a single vendor as part of an integrated platform (see Magic Quadrant for SASE Platforms).
At the same time, there is growing concern about SD-WAN products’ security, thanks in part to the rise of AI. Hackers using sophisticated, frontier AI LLMs can more easily discover and exploit SD-WAN software vulnerabilities, potentially increasing the number of Common Vulnerabilities and Exposures (CVEs), and potentially exposing enterprise customers’ networks. In response, network teams will need to accelerate SD-WAN patching to reduce the risk.

Additional Trends

Other trends Gartner sees based on SD-WAN vendor product roadmaps and enterprise buying trends include:

Coffee Shop Networking

While many organizations have reinstituted in-office work policies in the post-COVID-19 era, there is still interest in distributed work-from-anywhere connectivity management, commonly referred to as coffee shop networking. In this scenario, users split time between corporate offices and remote locations, accessing corporate applications in the cloud using internet-based connectivity. Application traffic primarily flows from cloud service provider points of presence (POPs) to users, lessening the need for east-west traffic control between a corporate branch and data center.
This, combined with fewer people working in offices at any given time, reduces the need for full-featured SD-WAN functionality to reduce bandwidth contention or support complex topologies such as dynamic full-mesh routing. Security integrated with on-premises SD-WAN appliances is also less of a need in favor of cloud-based security orchestration delivered by SSE.
As a result, enterprises opting for coffee shop networking management require lower-cost, lighter-weight SD-WAN products. In rare scenarios, enterprises eliminate SD-WAN altogether. That said, overall interest in coffee-shop networking is limited, as many organizations still use private network connectivity and rely on private applications hosted at a corporate data center or colocation facility. Gartner estimates that approximately 10% to 20% of enterprise sites are interested in coffee shop networking.

SD-Branch

Customer interest is growing for SD-WAN offerings that unify WAN, LAN/WLAN and security orchestration and control via a single GUI. This offers customers simplified vendor management as well as greater visibility and consistent network and security policy management across LAN and WAN environments, particularly for small branch locations. As with more full-featured SD-WAN offerings, SD-Branch vendor products increasingly are being integrated with SSE to deliver a SASE solution.

Connectivity Support

SD-WAN offerings commonly support a variety of underlay connectivity options such as MPLS and dedicated internet access. However, vendors are expanding this to include additional support for WAN connectivity options such as fixed wireless access, including 5G cellular fixed wireless access. This can include added features such as link bonding across satellite and cellular wireless connections and support for cellular eSIM provisioning.

Market Analysis


Gartner sees continued interest in SD-WAN based on client conversations. Gartner expects end-user spending on SD-WAN equipment (measured in constant currency) to grow from $7.4 billion in 2026 to $12 billion by 2030, representing a 14.8% compound annual growth rate (CAGR) for the period (see Forecast: Enterprise Network Equipment, Worldwide, 2024-2030, 2Q26 Update). See Figure 1 below. This market revenue includes standalone SD-WAN revenue but much of the growth is driven by SD-WAN purchased as part of a SASE.
Figure 1: SD-WAN Equipment End User Spending (in Billions)
Worldwide SD-WAN equipment end user spending is projected to rise steadily from $7.41 billion in 2026 to $11.98 billion in 2030, indicating strong and sustained market growth over this period.
Larger vendors may also market more than one SD-WAN offering, often including a full-featured option targeting large, complex WAN customers and a lower-cost small branch option that offers easy configuration with more basic routing and traffic controls. To avoid overpaying, it is important for enterprises to focus on SD-WAN vendor offerings that meet — but do not significantly exceed — their networking needs. Enterprises must also require SD-WAN vendors to confirm that they can provide the necessary geographic support availability to ensure that the SD-WAN offering aligns with their networking needs.
Among enterprise SD-WAN deployments, Gartner sees the following use cases:
  • Small branch: Secure branch networking for small offices, typically with fewer than 10 people, such as convenience stores, fast-food restaurants and gas stations. The focus is on lower-cost products that leverage broadband connectivity, offer simplicity and ease of deployment via a centralized management GUI, with standardized configuration templates that can apply to up to 10,000 branches or more. There is also increasing demand for integration with campus network management, creating unified SD-Branch SD-WAN, LAN/WLAN and security orchestration. This simplifies small-branch networking management.
  • Large hybrid global WAN: Network support for a hybrid WAN with hundreds to thousands of sites of varying sizes across multiple geographic regions, plus connectivity support for on-premises and cloud-based applications. Use case priorities include granular routing and application steering controls, performance optimization, the ability to support a wide range of location sizes and scalability. Security is also a priority, somewhat favoring cloud over on-premises control.
  • Cloud-first WAN: Networking for enterprises that are primarily cloud-first or cloud-only, relying on public cloud and SaaS services as part of an automated, high-performance and flexible cloud architecture. Priorities include access to multiple SaaS, platform as a service (PaaS) and infrastructure as a service (IaaS) workloads in cloud environments through either native or tightly integrated third-party partner capabilities. Cloud onramp capabilities can also include cloud service providers’ public and private cloud ports and can offer integration with cloud hub and software-defined cloud interconnect service providers.
  • On-premises security-sensitive WAN: SD-WAN networking integrated with a network firewall to protect east/west and north/south traffic, usually via a single on-premises appliance. Other high-demand on-premises security features include segmentation, PQC protection, IPS/IDS, anti-malware, URL and content filtering and DLP. Geographic preferences may also be a requirement if there is limited cloud application adoption. Customer verticals include healthcare, financial services and government organizations.
  • SD-WAN with partner-integrated cloud security: Provides SD-WAN with security features through tight integration with SSE vendor partners as part of a dual-vendor SASE implementation. In this use case, enterprises typically have already selected an SSE vendor based on its security capabilities but prefer the SD-WAN solution offered by an SSE vendor partner. Priorities include SaaS optimization, automation, cloud connectivity orchestration and support for complex network topologies.
  • Sovereign WAN: Network support for WAN topologies of any size that require strict controls limiting network traffic to specific geographic boundaries, including traffic routes, cloud POPs and corporate locations. This also requires that the SD-WAN orchestration and management plane is hosted within specific jurisdictions. Priorities for this use case include granular routing controls, ability to preset circuit failover policies and enhanced traffic monitoring to ensure compliance with organizations’ data sovereignty policies.
In line with the larger transition toward SASE, SD-WAN vendors are focusing on managed SASE, SASE platform and dual-vendor SASE product offerings. Several vendors, including Cloudflare and Check Point Software Technologies, do not market standalone SD-WAN but rather as part of their SASE platform offerings.

Representative Vendors


The vendors listed in this Market Guide do not imply an exhaustive list. This section is intended to provide more understanding of the market and its offerings.

Vendor Selection

The sample vendors highlighted in this research were selected based on their SD-WAN offering’s ability to deliver secure connectivity management for branch and cloud locations that address all or most of the above-mentioned enterprise use cases. This includes vendors with SD-WAN offerings that individually address specific use cases.
The representative list includes a range of large infrastructure vendors as well as niche providers that market differentiated SD-WAN offerings, which can be purchased either standalone or as part of a SASE package.

Representative Vendors in SD-WAN

VendorProduct nameProduct offering
Arista Networks
VeloCloud SD-WAN
SD-WAN
Aryaka
Aryaka Secure SD-WAN
SD-WAN, SASE Platform
Barracuda
Barracuda Secure SD-WAN and Barracuda SecureEdge
SD-WAN, SASE Platform
Cato Networks
Cato SD-WAN
SD-WAN, SASE Platform
Check Point Software Technologies
Check Point Quantum SD-WAN
SD-WAN, SASE Platform
Cisco
Cisco Catalyst SD-WAN and Cisco Meraki SD-WAN
SD-WAN, SASE
Cloudflare
Magic WAN Connector
SASE Platform
Ericsson (Cradlepoint)
Ericsson NetCloud Manager, Ericsson Cradlepoint E-series and Ericsson NetCloud Exchange Service Gateway
SD-WAN, SASE Platform
FatPipe
FatPipe SD-WAN
SD-WAN, SASE Platform
Fortinet
Fortinet Secure SD-WAN
SD-WAN, SASE Platform
H3C
H3C Cloudnet
SD-WAN, SASE Platform
HPE
HPE Aruba Networking EdgeConnect SD-WAN, HPE Aruba Networking EdgeConnect SD-Branch and Juniper AI-Native SD-WAN
SD-WAN, SASE Platform
Huawei
Huawei SD-WAN Solution
SD-WAN, SASE Platform
iboss
iboss Zero Trust SD-WAN
SASE Platform
Netskope
Netskope One Secure SD-WAN
SASE Platform
Palo Alto Networks
Prisma SD-WAN
SD-WAN, SASE Platform
Peplink
Balance and SDX Series (enterprise branch) and MAX (industrial IoT and mobility)
SD-WAN, SASE Platform
Sangfor
Secure SD-WAN
SD-WAN, SASE Platform
SonicWall
Secure SD-WAN
SD-WAN, SASE Platform
Sophos
Xstream SD-WAN
SD-WAN, SASE Platform
Versa Networks
Versa Secure SD-WAN and Versa Titan SD-WAN
SD-WAN, SASE Platform
Zscaler
Zero Trust SD-WAN
SASE Platform
Source: Gartner (August 2026)

Market Recommendations


  • Verify that SD-WAN vendors support sovereign traffic management capabilities that meet your organization’s data sovereignty policies.
  • To ward off harvest now, attack later hacker attacks, prioritize SD-WAN vendors that support PQC protection.
  • If your organization has or plans to invest in private AI, prioritize SD-WAN vendors that offer strong dynamic path steering and application performance monitoring to better manage AI agent traffic.
  • Cloud-first organizations must prioritize vendors that offer broad cloud onramp integrations and SaaS optimization capabilities to enable simpler, higher-performing connectivity to cloud workloads.
  • Using a cross-functional network and security team, validate SD-WAN vendors’ integrated third-party SSE capabilities by focusing on automated traffic redirection and management plane integration when implementing a dual-vendor SASE architecture.

Evidence


Gartner inquiries on SD-WAN among enterprise customers totaled more than 1,500 inquiries between July 2025 and July 2026.

Note 1: Gartner’s Initial Market Coverage


This Market Guide provides Gartner’s initial coverage of the market and focuses on the market definition, rationale for the market and market dynamics.