{"api_version":"provider-public/1.0.0","provider":{"id":"provider:netskope","slug":"netskope","display_name":"Netskope, Inc. (trading and profile display name: Netskope)","provider_types":["technology_vendor"],"primary_geographies":[]},"revision":{"id":"revision:922007c7966bdb60d5b68da6","dataset_version":"sha256-0f697fc7fc4690bb","editorial_revision":"unreviewed-import","reviewed_at":"2026-09-01T20:19:26.120Z"},"editorial":{"overview":"Netskope sits in an interesting middle ground between a pure security-first platform and a fully networked one: unlike the likes of Zscaler, it has invested in its own converged mesh network (NewEdge) and a purpose-built SD-WAN (Borderless SD-WAN, built on the 2022 Infiot acquisition), so the ‘security company bolting on networking’ story is a few years further along than Zscaler’s; unlike Cato, that network is built on peering and interconnects across 67 regions rather than an owned private backbone. Where Netskope stands out is data-centric SSE - its Cloud Confidence Index covers 85,000+ SaaS and GenAI apps, its DLP heritage runs deep (it was arguably the original CASB/DLP-first vendor in this space), and its compliance evidence is unusually comprehensive, explicitly naming DORA, UK Cyber Essentials and FedRAMP High all from primary sources. Multiple independent pricing analyses flag Netskope’s modular licensing and add-on structure as a source of renewal-time cost surprises, so budget conversations are worth having early and in writing.","page_title":"Netskope, Inc. (trading and profile display name: Netskope) SD-WAN and SASE profile","meta_description":"Net kope  it  in an intere ting middle ground between a pure  ecurity-fir t platform and a fully networked one: unlike the like  of Z caler, it ha  inve te"},"products":[{"id":"product:0ff69f4f2e3cf34b89f05ac4","name":"Borderless SD-WAN","category":"SD-WAN / branch connectivity","delivery_relationship":"native","target_buyer":"Branch/site buyers","delivery_model":"SASE Gateways, cloud-managed via NewEdge","status":"current","evidence_source_ids":["evidence:netskope:5","evidence:netskope:6","evidence:netskope:7"]},{"id":"product:342a831055c8681d8010318b","name":"Cloud Confidence Index (CCI)","category":"SaaS/GenAI app risk scoring","delivery_relationship":"native","target_buyer":"Security/IT teams","delivery_model":"Cloud-delivered","status":"current","evidence_source_ids":["evidence:netskope:21"]},{"id":"product:ff3737134d7e49c987980c39","name":"Netskope Cloud Exchange (CE)","category":"Integration/orchestration framework","delivery_relationship":"partner","target_buyer":"SecOps/integration teams","delivery_model":"Self-hosted (AWS EC2) or Cloud Exchange as a Service","status":"current","evidence_source_ids":["evidence:netskope:37"]},{"id":"product:96208c0e4005538121f5bf0d","name":"Netskope One","category":"Converged SASE/SSE platform","delivery_relationship":"native","target_buyer":"All buyers","delivery_model":"Cloud-delivered","status":"current","evidence_source_ids":["evidence:netskope:11"]},{"id":"product:575f51102c293ffd14cfecdb","name":"Netskope One AI Security / AI Guardrails","category":"AI application and runtime security","delivery_relationship":"native","target_buyer":"Security/compliance teams","delivery_model":"Cloud-delivered","status":"current","evidence_source_ids":["evidence:netskope:22"]},{"id":"product:bcffddb150dbf9778580ee58","name":"Netskope One Client","category":"Endpoint agent","delivery_relationship":"native","target_buyer":"Managed devices","delivery_model":"Client-based","status":"current","evidence_source_ids":["evidence:netskope:8","evidence:netskope:9"]},{"id":"product:59b054c93f7495e301757935","name":"Netskope One SSE","category":"Secure web gateway, inline/API CASB, DLP, cloud firewall, ZTNA","delivery_relationship":"native","target_buyer":"All buyers","delivery_model":"Cloud-delivered","status":"current","evidence_source_ids":["evidence:netskope:11"]},{"id":"product:8900b7965408f97b2330f0b3","name":"Netskope Private Access (NPA)","category":"Zero Trust Network Access","delivery_relationship":"native","target_buyer":"All buyers","delivery_model":"Cloud-delivered","status":"current","evidence_source_ids":["evidence:netskope:30"]},{"id":"product:552746aa9048ff8a77c822b0","name":"NewEdge Network","category":"Global private/peered network","delivery_relationship":"native","target_buyer":"All buyers (underlying infrastructure)","delivery_model":"Cloud-delivered","status":"current","evidence_source_ids":["evidence:netskope:8"]},{"id":"product:4ebe903433e83353a70c2f72","name":"SkopeAI","category":"AI/ML security suite (DLP, threat protection, AI Guardrails)","delivery_relationship":"native","target_buyer":"Security teams","delivery_model":"Cloud-delivered","status":"current","evidence_source_ids":["evidence:netskope:27"]}],"capabilities":[{"id":"capability:b8762d4212ab8f89574d9b16","capability_code":"ai_assistant_copilot","label":"AI assistant/copilot","category":"ai_automation","support_state":"requires_confirmation","qualification":"Depth of each copilot's actual functionality not independently tested","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:24","evidence:netskope:28"]},{"id":"capability:828efacfa97d2c20b8d28c12","capability_code":"ai_data_protection_controls","label":"AI data protection controls","category":"ai_automation","support_state":"requires_confirmation","qualification":"Same as above","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:21","evidence:netskope:25"]},{"id":"capability:c82360c42012a66cef2900f8","capability_code":"anomaly_detection","label":"Anomaly detection","category":"ai_automation","support_state":"requires_confirmation","qualification":"Depth of the ML methodology not disclosed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:27"]},{"id":"capability:cdfb42a55f72255d5711595e","capability_code":"automated_policy_recommendation","label":"Automated policy recommendation","category":"ai_automation","support_state":"requires_confirmation","qualification":"Depth not independently tested","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:28"]},{"id":"capability:6be45c22cb779bfe87dc74cf","capability_code":"automated_remediation","label":"Automated remediation","category":"ai_automation","support_state":"requires_confirmation","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:5d4055da9e739919d4b8de8f","capability_code":"capacity_path_optimisation","label":"Capacity/path optimisation","category":"ai_automation","support_state":"supported","qualification":"Sourced via reseller listing rather than primary Netskope page in this pass","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:9"]},{"id":"capability:568dc18aab4c9f5d9eb57917","capability_code":"configuration_generation","label":"Configuration generation","category":"ai_automation","support_state":"unknown","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:4b43c31e20db9bfcb8cf21cf","capability_code":"digital_experience_diagnostics","label":"Digital experience diagnostics","category":"ai_automation","support_state":"unknown","qualification":"Sourced via third-party pricing analysis only","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:43"]},{"id":"capability:848e3c1634824ba33b032e68","capability_code":"generative_ai_application_controls","label":"Generative AI application controls","category":"ai_automation","support_state":"requires_confirmation","qualification":"Depth/accuracy of AI-traffic classification not independently tested","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:22","evidence:netskope:23","evidence:netskope:28","evidence:netskope:29"]},{"id":"capability:9edc7b9bdc0c0659185f502d","capability_code":"natural_language_querying","label":"Natural-language querying","category":"ai_automation","support_state":"unknown","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:902b75b8370e6104b0942388","capability_code":"report_summarisation","label":"Report summarisation","category":"ai_automation","support_state":"unknown","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:63c1f88f85ac34746cb415fa","capability_code":"root_cause_analysis","label":"Root-cause analysis","category":"ai_automation","support_state":"requires_confirmation","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:e0f26f959812fcce1cae4f4c","capability_code":"threat_detection_classification","label":"Threat detection/classification","category":"ai_automation","support_state":"requires_confirmation","qualification":"Same as above","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:27"]},{"id":"capability:3177c66818555590d1ab75bf","capability_code":"user_entity_behaviour_analytics","label":"User/entity behaviour analytics","category":"ai_automation","support_state":"unknown","qualification":"Sourced only via a third-party pricing guide in this pass","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:43"]},{"id":"capability:43ab760842ae74d1011528f4","capability_code":"cap_5g_lte_support","label":"5G/LTE support","category":"architecture","support_state":"unknown","qualification":"Unknown - not found in sources reviewed","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:e78154df474e5c4af3a3e951","capability_code":"application_identification","label":"Application identification","category":"architecture","support_state":"supported","qualification":"Native - context-aware SD-WAN integrating with the Netskope Zero Trust Engine to support visibility/control across 85,000+ SaaS applications","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:12"]},{"id":"capability:d26cdf5114581fc404a93922","capability_code":"branch_lan_wlan_integration","label":"Branch LAN/WLAN integration","category":"architecture","support_state":"unknown","qualification":"Unknown - not found in sources reviewed","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:fcfff5ae32f2b7db9b530d23","capability_code":"brownfield_migration_support","label":"Brownfield migration support","category":"architecture","support_state":"supported","qualification":"Native - NewEdge explicitly supports 'seamless SD-WAN integration with our solutions or third-party products' and IPsec/GRE tunnels 'to integrate with existing SD-WAN investments'","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:8"]},{"id":"capability:288c41052571f7eaa29868fc","capability_code":"dynamic_path_selection","label":"Dynamic path selection","category":"architecture","support_state":"supported","qualification":"Native - NewEdge Traffic Management 2.0 on-ramps traffic to the optimal data centre based on lowest latency and data-centre health, not DNS or proximity alone","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:9"]},{"id":"capability:1d9f255e62c7765612836b23","capability_code":"edge_form_factors","label":"Edge form factors","category":"architecture","support_state":"unknown","qualification":"SASE Gateways (part of NewEdge); specific hardware model range not detailed in sources reviewed","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:5"]},{"id":"capability:adfa310e28fdb051e3c176fd","capability_code":"forward_error_correction_packet_duplication","label":"Forward error correction / packet duplication","category":"architecture","support_state":"requires_confirmation","qualification":"Not confirmed as a distinct named capability in sources reviewed, though 'sub-second failover' and active-active links are documented","confidence":"low_medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:82b66817c537d9f33be4ef73","capability_code":"high_availability","label":"High availability","category":"architecture","support_state":"supported","qualification":"Native at the network level - full mesh network built for maximum resilience with full route control, backed by SLAs for availability per a reseller-hosted description of Netskope's own NewEdge materials","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:9"]},{"id":"capability:8580acdced65cec2fb67ffcc","capability_code":"leo_satellite_support","label":"LEO satellite support","category":"architecture","support_state":"unknown","qualification":"Unknown - not found in sources reviewed","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:ca520fc81aaa1af48c011874","capability_code":"local_internet_breakout","label":"Local internet breakout","category":"architecture","support_state":"supported","qualification":"Native by design - NewEdge processes security at the edge closest to the user, eliminating backhaul to centralised data centres","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:11"]},{"id":"capability:b8cc14a242d3bde834962c03","capability_code":"qos_and_traffic_engineering","label":"QoS and traffic engineering","category":"architecture","support_state":"supported","qualification":"Native - active-active links, sub-second brownout/blackout detection, and real-time link remediation described for the unified SASE gateways","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:11"]},{"id":"capability:9621e05cfd29caa75b479324","capability_code":"segmentation_vrf_capability","label":"Segmentation / VRF capability","category":"architecture","support_state":"unknown","qualification":"Unknown - not found in sources reviewed","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:27d4aad3c6413f8fee9695b6","capability_code":"supported_wan_underlays","label":"Supported WAN underlays","category":"architecture","support_state":"unknown","qualification":"Multiple underlays implied by 'active-active links' and integration with existing SD-WAN investments via IPsec/GRE tunnels; MPLS coexistence not explicitly named","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:8"]},{"id":"capability:53fb40805ac50d80475637bd","capability_code":"virtual_cloud_edge_support","label":"Virtual/cloud edge support","category":"architecture","support_state":"supported","qualification":"Yes - cloud-native constructs connecting to AWS Cloud WAN, Azure Virtual WAN, Google Cloud WAN","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:12"]},{"id":"capability:55ba278175e3043897e84b69","capability_code":"zero_touch_provisioning","label":"Zero-touch provisioning","category":"architecture","support_state":"requires_confirmation","qualification":"Not explicitly confirmed as a named capability in sources reviewed, though the overall SASE Gateway/cloud-managed model implies low-touch deployment","confidence":"low_medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:10b326fd974d4f663ac6becf","capability_code":"application_aware_routing","label":"Application-aware routing","category":"core_capabilities","support_state":"supported","qualification":"Tier-gated","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:12"]},{"id":"capability:00dea054551a5914ef056543","capability_code":"casb_api","label":"CASB - API","category":"core_capabilities","support_state":"supported","qualification":"Per-app-seat pricing can multiply cost in ways that surprise buyers who scope on user count alone, per a third-party pricing guide's worked example","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:43"]},{"id":"capability:ce55e91e836f1cbe5d3434bd","capability_code":"casb_inline","label":"CASB - inline","category":"core_capabilities","support_state":"supported","qualification":"None identified","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:43"]},{"id":"capability:6a6e9501c395b375227fd59d","capability_code":"cloud_firewall_cloud_network_security","label":"Cloud firewall / cloud network security","category":"core_capabilities","support_state":"supported","qualification":"Same as FWaaS row","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:32"]},{"id":"capability:af798016142a1a6f57af6b47","capability_code":"dns_security","label":"DNS security","category":"core_capabilities","support_state":"requires_confirmation","qualification":"Not confirmed","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:ce2ab8093795961d55186b09","capability_code":"data_loss_prevention","label":"Data loss prevention","category":"core_capabilities","support_state":"supported","qualification":"Full-strength DLP tier-gated per third-party pricing analysis","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:27","evidence:netskope:43"]},{"id":"capability:de095370c6663dee87464ebe","capability_code":"digital_experience_monitoring","label":"Digital experience monitoring","category":"core_capabilities","support_state":"unknown","qualification":"Sourced only via third-party pricing analysis in this pass, not a primary Netskope product page","confidence":"low_medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:43"]},{"id":"capability:7f4f823141bd369b0279d68d","capability_code":"firewall_as_a_service","label":"Firewall as a Service","category":"core_capabilities","support_state":"supported","qualification":"Tier-gated","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:32","evidence:netskope:43"]},{"id":"capability:1f88536d7e8d994b0cfea04f","capability_code":"multi_cloud_networking","label":"Multi-cloud networking","category":"core_capabilities","support_state":"supported","qualification":"Tier-gated","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:12"]},{"id":"capability:7b78570096f7cfda44580b60","capability_code":"sd_wan","label":"SD-WAN","category":"core_capabilities","support_state":"supported","qualification":"Tier-gated - full SASE bundle required, not available on the entry SSE tier","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:5","evidence:netskope:43"]},{"id":"capability:22e94d095e749be13aafaff5","capability_code":"saas_security_posture","label":"SaaS security posture","category":"core_capabilities","support_state":"supported","qualification":"Tier-gated, add-on","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:43"]},{"id":"capability:60e82e9f929f4a65f81745d2","capability_code":"secure_web_gateway","label":"Secure web gateway","category":"core_capabilities","support_state":"supported","qualification":"None identified","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:11","evidence:netskope:43"]},{"id":"capability:86a137e650fac3180af7d61a","capability_code":"threat_intelligence","label":"Threat intelligence","category":"core_capabilities","support_state":"supported","qualification":"None identified","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:27"]},{"id":"capability:2f6750da5294a610d017ca37","capability_code":"wan_optimisation","label":"WAN optimisation","category":"core_capabilities","support_state":"supported","qualification":"Tier-gated (SASE tier, not base SSE)","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:10"]},{"id":"capability:676edca9479f5eccb0ae921b","capability_code":"ztna","label":"ZTNA","category":"core_capabilities","support_state":"supported","qualification":"Tier boundary not fully consistent across sources reviewed","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:30","evidence:netskope:32"]},{"id":"capability:49bb3db0c197cbcf4d8b85fa","capability_code":"clientless_access","label":"Clientless access","category":"remote_access","support_state":"requires_confirmation","qualification":"None identified","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:f6b0fe3053ef763fdd896ea1","capability_code":"contractors_third_parties","label":"Contractors/third parties","category":"remote_access","support_state":"requires_confirmation","qualification":"None identified","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:ab72dd3618bf2bcff74a8f23","capability_code":"managed_laptops","label":"Managed laptops","category":"remote_access","support_state":"supported","qualification":"None identified","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:30","evidence:netskope:31","evidence:netskope:32"]},{"id":"capability:2638b59242094446e0ef7618","capability_code":"mobile_devices","label":"Mobile devices","category":"remote_access","support_state":"requires_confirmation","qualification":"None identified","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:874117cfd3bca53f601c0c76","capability_code":"privileged_access","label":"Privileged access","category":"remote_access","support_state":"unknown","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:89dc4014617b6b5d4353b84b","capability_code":"remote_browser_isolation","label":"Remote browser isolation","category":"remote_access","support_state":"requires_confirmation","qualification":"Not confirmed","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:9edbbe7de8003d61c2b8d589","capability_code":"remote_browser_isolation","label":"Remote browser isolation","category":"remote_access","support_state":"requires_confirmation","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:b020d32cbe68b41389e457f2","capability_code":"unmanaged_byod_devices","label":"Unmanaged/BYOD devices","category":"remote_access","support_state":"requires_confirmation","qualification":"Depth of BYOD-specific policy control not independently confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:6de138845dcd15c5c80c0623","capability_code":"vdi_environments","label":"VDI environments","category":"remote_access","support_state":"unknown","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:2f9369caeb714556cdb088cf","capability_code":"application_performance","label":"Application performance","category":"reporting_analytics","support_state":"unknown","qualification":"Requires DEM add-on per third-party pricing analysis","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:83460ace7e6ea95dee5cd478","capability_code":"compliance_reporting","label":"Compliance reporting","category":"reporting_analytics","support_state":"unknown","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:e2eaf140a085cd13971f5312","capability_code":"custom_reports","label":"Custom reports","category":"reporting_analytics","support_state":"unknown","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:421353d3d2c8299f7d57d81f","capability_code":"dlp_events","label":"DLP events","category":"reporting_analytics","support_state":"requires_confirmation","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:79dd7f487e71976c8263af33","capability_code":"executive_dashboard","label":"Executive dashboard","category":"reporting_analytics","support_state":"requires_confirmation","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:67c3b87ba4025a821622ad82","capability_code":"network_health","label":"Network health","category":"reporting_analytics","support_state":"requires_confirmation","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:b4a5bfcf104bb5b2ce37d549","capability_code":"raw_log_access","label":"Raw log access","category":"reporting_analytics","support_state":"unknown","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:35","evidence:netskope:36"]},{"id":"capability:16fc517455e561ec0b9adf5d","capability_code":"remote_user_experience","label":"Remote-user experience","category":"reporting_analytics","support_state":"unknown","qualification":"Requires DEM add-on","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:a5842312f5032da401a00067","capability_code":"sla_reporting","label":"SLA reporting","category":"reporting_analytics","support_state":"requires_confirmation","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:3bca61794ff70a0d1e10cdc3","capability_code":"scheduled_reports","label":"Scheduled reports","category":"reporting_analytics","support_state":"unknown","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:8583392fdb969a840dd68971","capability_code":"security_events","label":"Security events","category":"reporting_analytics","support_state":"supported","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:26"]},{"id":"capability:3ca0868e6133a79a20457d4f","capability_code":"site_and_circuit_performance","label":"Site and circuit performance","category":"reporting_analytics","support_state":"unknown","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:a2641beaa0d5aabb57b652b2","capability_code":"threat_reporting","label":"Threat reporting","category":"reporting_analytics","support_state":"supported","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:27"]},{"id":"capability:45bb1096ac6e8d3cc3fa916e","capability_code":"user_experience","label":"User experience","category":"reporting_analytics","support_state":"unknown","qualification":"Requires DEM add-on","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]}],"geographies":[{"id":"geographies:20c833b7d2fac2787a8f7ef0","geography":"Africa coverage","delivery_type":"Unknown - not itemised in sources reviewed","delivery_relationship":"unknown","qualification":"Unknown - not itemised in sources reviewed | Unknown | Not specified | No named data centres found | Not found in a Tier 1-2 source in this pass | Low | Evidence gap, consistent across all three vendors' profiles for this region.","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"geographies:78d2dba94abd5d274da142d0","geography":"Asia-Pacific coverage","delivery_type":"Unknown in named-country detail - the general '67 regions' claim implies broad presence but no specific APAC country/city list was found in this pass","delivery_relationship":"unknown","qualification":"Unknown in named-country detail - the general '67 regions' claim implies broad presence but no specific APAC country/city list was found in this pass | Unknown | Not specified in detail | No named APAC data centres found | Not found in a Tier 1-2 source in this pass | Low | Worth checking Netskope's own NewEdge region map directly before advising APAC-heavy buyers.","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"geographies:f5968705861cd677e1c05307","geography":"Carrier interconnects","delivery_type":"Extensive peering relationships explicitly described, including private network interconnects (NewEdge Express Connect) as an alternative to MS ExpressRoute/AWS Direct Connect","delivery_relationship":"owned","qualification":"Extensive peering relationships explicitly described, including private network interconnects (NewEdge Express Connect) as an alternative to MS ExpressRoute/AWS Direct Connect | Direct | Global | Specific carrier/exchange names not disclosed | High | The explicit cost/complexity-avoidance framing versus ExpressRoute/Direct Connect mirrors a similar claim found for Cato - a genuinely useful, specific commercial argument for cloud-heavy buyers.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:8"]},{"id":"geographies:c0f30053f99c7b1b5cb02017","geography":"China coverage","delivery_type":"Unknown - no China-specific data-centre or licensed-PoP detail found in sources reviewed","delivery_relationship":"unknown","qualification":"Unknown - no China-specific data-centre or licensed-PoP detail found in sources reviewed | Unknown | Not specified | No named China presence found, in contrast to Cato's explicit Beijing/Shanghai/Shenzhen PoPs | Not found in a Tier 1-2 source in this pass | Low | Same evidence gap flagged for Zscaler - do not assume parity with Cato's specific China story.","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"geographies:040bcf7529f61b79ad4a5b6b","geography":"Data residency choices","delivery_type":"Implied via the FedRAMP High GovCloud (isolated environment) and broad international compliance certifications (C5 for Germany, IRAP for Australia), though a dedicated data-residency architecture description (like Zscaler's isolated logging planes) wasn't found in this pass","delivery_relationship":"owned","qualification":"Implied via the FedRAMP High GovCloud (isolated environment) and broad international compliance certifications (C5 for Germany, IRAP for Australia), though a dedicated data-residency architecture description (like Zscaler's isolated logging planes) wasn't found in this pass | Direct | Wherever GovCloud or region-specific certifications apply | No dedicated data-sovereignty architecture page found, unlike Zscaler's specific isolated-plane description | Medium | Compliance breadth is very strong (see Table 13), but the specific architectural mechanism for data residency is less explicitly documented than Zscaler's isolated control/data/logging-plane description - worth asking directly.","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:15"]},{"id":"geographies:2afb0c31f29379aa52b72c75","geography":"Latin America coverage","delivery_type":"Unknown - not itemised in sources reviewed","delivery_relationship":"unknown","qualification":"Unknown - not itemised in sources reviewed | Unknown | Not specified | No named data centres found | Not found in a Tier 1-2 source in this pass | Low | Evidence gap.","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"geographies:ce601b350a4d7f56043481b4","geography":"Middle East coverage","delivery_type":"Unknown - not itemised in sources reviewed","delivery_relationship":"unknown","qualification":"Unknown - not itemised in sources reviewed | Unknown | Not specified | No named data centres found | Not found in a Tier 1-2 source in this pass | Low | Evidence gap - weaker than Zscaler's evidence here (which had a specific Saudi Arabia expansion announcement).","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"geographies:d0db01164dcb76e66c5e6033","geography":"Private backbone","delivery_type":"Not present - NewEdge is a peering/interconnect-based network (public and private peering, private network interconnects via NewEdge Express Connect) rather than an owned, SLA-backed private backbone in the Cato sense","delivery_relationship":"unknown","qualification":"Not present - NewEdge is a peering/interconnect-based network (public and private peering, private network interconnects via NewEdge Express Connect) rather than an owned, SLA-backed private backbone in the Cato sense | N/A | N/A | This is a genuine architectural characteristic, not an evidence gap | 22 Jul 2026 | High | A meaningfully different architecture from Cato's owned backbone, though more network-investment-heavy than Zscaler's pure internet-peering model - Netskope sits in between.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"geographies:8010c3e159c1b9d5ddaa4cf1","geography":"Public cloud on-ramps","delivery_type":"AWS, Azure, GCP integration confirmed via cloud-native WAN constructs (AWS Cloud WAN, Azure Virtual WAN, Google Cloud WAN)","delivery_relationship":"owned","qualification":"AWS, Azure, GCP integration confirmed via cloud-native WAN constructs (AWS Cloud WAN, Azure Virtual WAN, Google Cloud WAN) | Direct | Wherever those hyperscalers have regions | Depth of on-ramp architecture not fully detailed beyond the named WAN services | High | Strong, named multi-hyperscaler story.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:12"]},{"id":"geographies:2392693e09fb360d0dd6c8af","geography":"SD-WAN gateways / cloud gateways","delivery_type":"Delivered from the same NewEdge infrastructure as the security edges via SASE Gateways","delivery_relationship":"owned","qualification":"Delivered from the same NewEdge infrastructure as the security edges via SASE Gateways | Direct | Same as above | None identified | 22 Jul 2026 | Medium-High | Consistent with a genuinely converged-platform design.","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"geographies:351512da53f5848fa433807a","geography":"Security PoPs / service edges","delivery_type":"NewEdge described as covering 67 regions, with nearly 4,000 network adjacencies to 700+ unique ASNs","delivery_relationship":"owned","qualification":"NewEdge described as covering 67 regions, with nearly 4,000 network adjacencies to 700+ unique ASNs | Direct (Netskope-owned/operated NewEdge network) | 67 regions globally | Full country-by-country list not found in sources reviewed | Medium-High | The 67-region and ASN-adjacency figures are specific and credible, though sourced via a reseller listing rather than a primary Netskope page directly stating current figures - worth a primary-source follow-up citation.","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:9"]},{"id":"geographies:0b0fea4b32ca7a138b70f112","geography":"Sovereign/regional service options","delivery_type":"Netskope GovCloud confirmed as a distinct FedRAMP High authorised offering, isolated for US government agencies and contractors","delivery_relationship":"owned","qualification":"Netskope GovCloud confirmed as a distinct FedRAMP High authorised offering, isolated for US government agencies and contractors | Direct | United States (federal/government cloud) | Sovereign offerings for non-US regions not found in sources reviewed | High | Strong for US federal buyers specifically, mirroring Zscaler's equivalent GovCloud offering; UK/EU-equivalent sovereign offerings should be asked about directly.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:20"]}],"service_models":[{"id":"service_models:044762435f33f220e1dc2f4b","model":"other","support_state":"supported","qualification":"Yes | Mix of Client, clientless, SASE Gateway | Mixed | Cloud console, unified | Most real-world enterprise estates | Moderate | Case studies (MERW: six-week rollout) suggest phased, professional-services-assisted adoption is typical | The MERW six-week timeline is a genuinely useful, specific data point for buyers estimating their own rollout.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:04ec02540cc22458ebb7b0e7","model":"other","support_state":"unknown","qualification":"Implied by the 'always-on' cloud platform model, not separately itemised as a distinct claim | Not confirmed | N/A | Included for platform | N/A | Not confirmed | Not found in a Tier 1-2 source in this pass | Reasonable inference for a cloud-delivered security platform, but not independently confirmed with a specific SLA figure the way Zscaler's was.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:21781ff5e41c56820493ad01","model":"other","support_state":"unknown","qualification":"Implied via Professional Services engagement in named case studies, not formalised into a named tiered support programme the way Zscaler's is | Not confirmed | Not specified | Involves Professional Services | N/A | Not separately quantified | Less formally documented than Zscaler's named Premium Support Advanced/Advanced Plus tiers - worth asking Netskope directly for an equivalent support-tier data sheet.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:30"]},{"id":"service_models:240e1ad121415e4a6c8b850d","model":"other","support_state":"unknown","qualification":"Skope IT 'Application Events' and AI insights dashboards allow filtering by category (e.g. identifying Generative AI tool usage and volume of data sent) to bring shadow AI into governance | Skope IT admin dashboards | Reduced specialist requirement implied by dashboard-driven insight | AI-assisted insight generation (per SkopeAI) | Positioned as accessible via dashboards rather than requiring deep specialist correlation | Sourced via a community Q&A rather than an official product page in this pass | A specific, named mechanism (Skope IT Application Events) - genuinely useful evidence, though sourced from a lower-tier community Q&A rather than official documentation; worth a primary-source follow-up.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:26"]},{"id":"service_models:2436bcd7fb1655fe1d9ed19e","model":"other","support_state":"supported","qualification":"Native - Netskope operates NewEdge directly | Not itemised | Not itemised by location | Included as part of the platform service | Customer configures policy; Netskope operates the underlying network | SLAs referenced generally ('industry-best SLAs for availability, traffic processing & security efficacy') but not itemised with specific figures in sources reviewed | Weaker primary-source evidence than Zscaler's specific, dated P1-P4 SLA figures - worth a direct follow-up for Netskope's own SLA documentation.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:9"]},{"id":"service_models:2bcf806df59bdd89a6724ee0","model":"other","support_state":"unknown","qualification":"Netskope One Client install or clientless CASB API-mode route | Admin console + Client | End-user self-install typical of this category | Not itemised | Not itemised | Not itemised | General platform pages | Standard for the category; no distinctive evidence found either way.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:35b972ff8822cdb4977f860d","model":"other","support_state":"unknown","qualification":"Cloud-based admin console setup; MERW's six-week rollout was Professional-Services-assisted | Netskope admin console | General IT/security admin, with PS support typical per case study evidence | Not itemised | Described as fast and smooth in the MERW case study ('one of the smoothest deployments... as a company') | Some third-party pricing analysis describes onboarding as 'brutal' requiring 'dedicated resources and Netskope's professional services' - a genuine tension with the positive case-study framing, worth noting both | A real, worth-flagging tension in the evidence: named customer case studies describe smooth deployments, while independent pricing/deployment analyses describe onboarding friction requiring significant PS investment - likely both are true depending on deployment complexity, and Netify should present both perspectives rather than picking one.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:32","evidence:netskope:43"]},{"id":"service_models:3bd220c037ca10ba9f5446c1","model":"other","support_state":"unknown","qualification":"Same pattern as configuration management | Not itemised | N/A | Shared, partner/PS-involved | Shared | Not itemised | Same as above | Same as above.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:4a1956f9936b21e5a6a467c1","model":"other","support_state":"unknown","qualification":"Unknown - not found in sources reviewed as a distinct MSP/multi-tenant capability | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in a Tier 1-2 source in this pass | Same evidence gap flagged for Zscaler - no equivalent to Cato's explicit MSASE multi-tenant platform was found.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:4f913714eb7d8302aa336ecc","model":"other","support_state":"unknown","qualification":"Unknown - not found in sources reviewed for SASE Gateway hardware RMA/replacement terms | Not found | Not found | Not confirmed | Not confirmed | Not confirmed | Not found in a Tier 1-2 source in this pass | Evidence gap, consistent with the equivalent gap flagged for both Cato and Zscaler.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:5093c192e04d986bc3db2114","model":"other","support_state":"unknown","qualification":"Unknown - not found in sources reviewed | Presumably admin console | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in public sources reviewed | Evidence gap.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:5b8b17fa08062d3581cc3e45","model":"other","support_state":"requires_confirmation","qualification":"Not confirmed as a distinct named service with its own SLA in sources reviewed | Not confirmed | N/A | Not confirmed | Not confirmed | Not confirmed | Not found in a Tier 1-2 source in this pass | A genuine evidence gap relative to Zscaler's specific, contractual MDR 10-minute notification SLA - worth a direct follow-up.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:5e7ca595ecc8eab858884755","model":"other","support_state":"supported","qualification":"Yes, as branch CPE via SASE Gateways, not a self-contained on-prem product | SASE Gateway | Gateway → nearest NewEdge data centre | Cloud console | Branch offices | Low (implied) | Not itemised in detail | Same 'thin edge into the cloud' pattern seen across all three vendors in this comparison set.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:5f1fc95a43e82434d5b1b603","model":"other","support_state":"supported","qualification":"Yes | CASB API-mode access | API/out-of-band → NewEdge | Cloud console | BYOD, contractors, unmanaged devices | Low | N/A | See Table 5 - a genuine relative strength for BYOD-heavy estates.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:6daabd14cc4e2c8bce212101","model":"other","support_state":"unknown","qualification":"Evidenced via Professional Services engagement in the CARE Ratings and MERW case studies | Not itemised | N/A | Involves Netskope Professional Services and/or partners | Shared | Not itemised | Real, evidenced via named case studies, though not formalised into a named tiered support structure the way Zscaler's is.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:30","evidence:netskope:32"]},{"id":"service_models:736f3e2c9c74a684adad3f10","model":"other","support_state":"partner_delivered","qualification":"Implied via Netskope's partner-centric go-to-market and professional-services involvement documented in case studies (CARE Ratings deployed via a Netskope partner) | Netskope Professional Services + partner | As above | Shared | Buyers wanting partner-led implementation | Not fully detailed | CARE Ratings case study describes partner-led deployment with Netskope Professional Services guidance | Real, evidenced via a named case study - though not as formally named as Cato's MSASE partner platform.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:7ff82e3dc939af8af5256a5e","model":"other","support_state":"requires_confirmation","qualification":"Not confirmed as a distinct, named Netskope-delivered managed-service product in sources reviewed | Not confirmed | - | - | Buyers wanting full outsourcing | Not confirmed | Not confirmed | Same gap flagged for Zscaler - no equivalent to Cato's named Managed SASE/MSASE offering was found for Netskope in this pass.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:8afc4d613a8c813b7591682e","model":"other","support_state":"requires_confirmation","qualification":"Not confirmed as a distinct customer-facing SOC service in sources reviewed | Not confirmed | Not itemised | Not confirmed | Not confirmed | Not confirmed | Not found in a Tier 1-2 source in this pass | Evidence gap - worth confirming directly whether an MDR-equivalent service exists.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:9cefd5786422c3dbb804bf07","model":"other","support_state":"unknown","qualification":"Unknown - not found in sources reviewed | Presumably admin console/API | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in public sources reviewed | Evidence gap.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:9f2ab223fd222e129442da63","model":"other","support_state":"unknown","qualification":"SASE Gateway deployment via NewEdge; specific rollout mechanics not detailed to the same depth as Cato's zero-touch documentation | Admin console (remote) | Not itemised | Not confirmed | Not confirmed | No large-scale, metric-rich branch-rollout case study found (same gap noted for Zscaler) | Not found in a Tier 1-2 source in this pass | Evidence gap - Netskope lacks an equivalent to Cato's Ulta Beauty story for branch-specific rollout at scale.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:a33a9f3bf4934f9ed7e18583","model":"other","support_state":"requires_confirmation","qualification":"Confirmed - Professional Services explicitly named across multiple case studies (CARE Ratings, MERW) and priced by third-party analysis at $150,000-$225,000 for Year 1 | N/A | N/A | Premium/required for complex deployments per case study evidence | N/A | N/A | Well evidenced that PS involvement is typical, and the third-party cost figure - while not primary-sourced - is specific enough to be useful for budget planning, with appropriate hedging.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:30","evidence:netskope:43"]},{"id":"service_models:baa081cfe42e25335186de46","model":"other","support_state":"requires_confirmation","qualification":"Not confirmed as a distinct named service in sources reviewed | Not confirmed | N/A | Not confirmed | Not confirmed | Not confirmed | Not found in a Tier 1-2 source in this pass | Evidence gap.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:c8de9fa8fc14cfe4c98f93a8","model":"other","support_state":"unknown","qualification":"Unknown - not found in sources reviewed | Not found | Not specified | Not confirmed | N/A | Not separately quantified | Not found in a Tier 1-2 source in this pass | Evidence gap.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:cbefd757a7773519230543a7","model":"other","support_state":"supported","qualification":"Yes | Netskope One / NewEdge | Via nearest NewEdge data centre | Centralised, cloud console | All customers - core delivery model | Low | N/A - default | The default and only real operating model for the security stack.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:cd1f26f06ec394277ebf173b","model":"other","support_state":"unknown","qualification":"Cloud-delivered updates for the platform are automatic by design (SaaS model); SASE Gateway firmware lifecycle not detailed in sources reviewed | N/A for cloud platform | Not confirmed for Gateway firmware specifically | Automatic for cloud platform | Low for cloud platform; Gateway firmware cadence not confirmed | Not confirmed for Gateways | General SaaS/platform architecture pages | Reasonable to assume low burden for the cloud platform; Gateway-specific patch cadence should be verified directly.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:dd314406226d0643d657684d","model":"other","support_state":"partner_delivered","qualification":"Implied via Netskope's partner-centric go-to-market strategy referenced across multiple case studies, though not formalised into a named platform the way Cato's MSASE is | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Real but less formally productised than Cato's equivalent - worth asking Netskope directly about its MSP/partner programme structure.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:30"]},{"id":"service_models:dd900d27d1acae951b2bc357","model":"other","support_state":"unknown","qualification":"Centralised policy engine (Zero Trust Engine) covering SSE and SD-WAN from one console | Netskope admin console | Not itemised in detail | Not itemised | Not itemised | Some third-party commentary describes policy configuration as 'tedious' - sourced from an anonymous review, treated with appropriate caution | Not found in a strong Tier 1-2 source in this pass beyond the general architecture claim | Insufficient strong evidence to grade confidently - flagged as a gap, with a noted but low-confidence critical data point.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:e0f783544ac42ae95a124838","model":"other","support_state":"unknown","qualification":"Not applicable in the same sense as a backbone vendor, given NewEdge is peering-based rather than an owned middle mile | N/A | N/A | N/A | N/A | N/A | N/A | Structurally similar to the equivalent Zscaler finding - an architectural non-applicability, not a gap.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:e3d5f953ca1ba30db88a1b49","model":"other","support_state":"supported","qualification":"Native via cloud-native constructs to AWS Cloud WAN, Azure Virtual WAN, Google Cloud WAN | Cloud-native WAN integration | Cloud workload → NewEdge | Cloud console | Multi-cloud/hybrid enterprises | Not fully detailed | Not itemised | Well-evidenced, named integration with all three major hyperscaler WAN services.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:e445fceff0062972cc6bd0fe","model":"other","support_state":"supported","qualification":"Yes | Netskope One Client | Client → NewEdge | Cloud console | Managed-device remote/hybrid workforce | Low | N/A | Well evidenced across all three named case studies (JLL, MERW, CARE Ratings).","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:f90bb62245a247fc225fb143","model":"other","support_state":"supported","qualification":"Yes | SASE Gateway hardware | Gateway → NewEdge | Cloud console | Distributed branch estates | Not fully detailed | Coexists with existing SD-WAN via IPsec/GRE per NewEdge documentation | Real, evidenced capability, though without a large-scale, metric-rich rollout case study equivalent to Cato's Ulta Beauty story.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:f9a0e4e6dbe64c03ec0c32d6","model":"other","support_state":"requires_confirmation","qualification":"Not confirmed as a distinct named MDR-equivalent service in sources reviewed | Not confirmed | Not itemised | Not confirmed | Not confirmed | Not confirmed | Not found in a Tier 1-2 source in this pass | A genuine, specific evidence gap relative to Zscaler's confirmed, SLA-backed MDR service - worth flagging directly to buyers who need this.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:fcb707b1d7a60a5041821478","model":"other","support_state":"requires_confirmation","qualification":"Not explicitly confirmed as a distinct virtual-appliance option in sources reviewed | Unknown | Unknown | Unknown | Unknown | Not confirmed | Not found in a Tier 1-2 source in this pass | Evidence gap - worth confirming directly whether Borderless SD-WAN offers a VM form factor equivalent to Cato's vSocket or Zscaler's Zero Trust Branch VM.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:fe85a02ab7214e5ffb7dd3a2","model":"other","support_state":"unknown","qualification":"Unknown in detail - not found in sources reviewed | Presumably admin console | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in public sources reviewed | Evidence gap.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]}],"compliance":[{"id":"compliance:de2ad42f509d4769a7b212e1","framework":"DORA relevance","scope":"EU financial services","support_state":"unknown","expiry_or_review_date":null,"qualification":"Explicitly listed as a named compliance item on Netskope's own Compliance Centre | EU financial services | Named on compliance.netskope.com under the 'COMPLIANCE' category alongside C5, Cyber Essentials, ENS and EU AI Act | EU | 22 Jul 2026 | The only one of the three vendors profiled so far with DORA explicitly named on a primary compliance page - a genuine, specific differentiator for Netify's financial-services sector suitability assessment (Table 14).","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:15"]},{"id":"compliance:83c745da26440a195e7b6b19","framework":"Data residency","scope":"Wherever GovCloud or region-specific certifications apply","support_state":"partially_supported","expiry_or_review_date":null,"qualification":"Partial - GovCloud isolation and region-specific certifications (C5 for Germany, IRAP for Australia) imply some data-residency capability, though a dedicated architectural description (like Zscaler's isolated logging planes) wasn't found | Wherever GovCloud or region-specific certifications apply | GovCloud isolation; C5, IRAP | US (GovCloud); Germany (C5); Australia (IRAP) | 22 Jul 2026 | Compliance breadth is very strong, but the specific architectural mechanism for data residency is less explicitly documented than Zscaler's - worth a direct question.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:15","evidence:netskope:20"]},{"id":"compliance:e9ad7f976f8e1b5e6e5a15dd","framework":"Encryption/key management","scope":"Platform","support_state":"unknown","expiry_or_review_date":null,"qualification":"Unknown in technical detail - not found beyond general 'secure' claims in sources reviewed at sufficient depth | Platform | Not confirmed in technical detail | None identified | Not found in a Tier 1-2 source in this pass at sufficient technical depth | Not found | Evidence gap, consistent with the equivalent gap flagged for Cato - a common RFP question Netify should source directly from Netskope's security whitepaper.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"compliance:32041fb9a00a1b1ab2196473","framework":"FedRAMP","scope":"US federal government (GovCloud)","support_state":"unknown","expiry_or_review_date":null,"qualification":"Certified/Authorized - FedRAMP High Authorization for the isolated GovCloud, plus 'FedRAMP Certified Class D' referenced on the Compliance Centre | US federal government (GovCloud) | FedRAMP High Authorization; isolated Private Security Cloud | US federal/government | 22 Jul 2026 | Strong, comparable in depth to Zscaler's equivalent FedRAMP High evidence - though DoD Impact Level and CJIS/CMMC-equivalent detail (which Zscaler documented extensively) wasn't found for Netskope in this pass.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:15","evidence:netskope:19","evidence:netskope:20"]},{"id":"compliance:5041e176cea6278077ce0d35","framework":"GDPR","scope":"Platform/company","support_state":"unknown","expiry_or_review_date":null,"qualification":"Compliant, explicitly listed on the Compliance Centre alongside UK GDPR as a separate line item | Platform/company | Compliance Centre lists GDPR and 'UK GDPR' separately | EU/UK relevant | 22 Jul 2026 | The separate UK GDPR listing is a specific, useful detail for Netify's UK-focused work.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:15"]},{"id":"compliance:165fd9b53a49e5dedd199ea2","framework":"HIPAA","scope":"Platform","support_state":"unknown","expiry_or_review_date":null,"qualification":"Assessed - 'Netskope has been assessed against the controls in place to satisfy the requirements of the HIPAA Security Rule... and the Omnibus Rule of 2013' | Platform | HIPAA Assessment Report available on request | US healthcare-relevant | 22 Jul 2026 | A specific, named assessment (not just 'HIPAA compliant' marketing language) - stronger evidence than the equivalent Zscaler row, where no formal HIPAA attestation was found.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:17"]},{"id":"compliance:e5457e323e13c0c891df43c4","framework":"ISO 27001","scope":"Platform, including office sites, development centres, support centres and data centres","support_state":"unknown","expiry_or_review_date":null,"qualification":"Certified | Platform, including office sites, development centres, support centres and data centres | ISO/IEC 27001:2013 and ISO/IEC 27001:2022 both referenced; ISO/IEC 27017 (cloud security) and ISO/IEC 27018 (cloud privacy) also referenced | None identified | 22 Jul 2026 | Unusually well-evidenced - five independent primary Netskope pages, plus a specific control-mapping document, corroborate this certification.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:13","evidence:netskope:14","evidence:netskope:15","evidence:netskope:17","evidence:netskope:18"]},{"id":"compliance:7ff416273ee4daf446d80439","framework":"Logging/auditability","scope":"Platform","support_state":"unknown","expiry_or_review_date":null,"qualification":"Implied via extensive SIEM/log-export integrations (Table 12) and the CSA STAR Level 2 certification referenced on the Compliance Centre; further corroborated by Netskope's own use of Tenable and Akamai for its internal vulnerability management and API-security practices, per those vendors' own customer-story pages about Netskope | Platform | CSA STAR Level 2; Data Flow Diagram (DFD) and Pentest Report both listed as available documents on the Compliance Centre | None identified | 22 Jul 2026 | The explicit availability of a Data Flow Diagram and Pentest Report (as named, requestable documents) is a good, specific transparency signal - and the fact that two independent named vendors (Tenable, Akamai) publish their own case studies about securing Netskope's infrastructure is a small but genuine 'practices what it preaches' signal, not something Netify found for either Cato or Zscaler.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:15","evidence:netskope:33","evidence:netskope:34"]},{"id":"compliance:6908d9e7dbd147d514d862c5","framework":"NHS DSPT relevance","scope":"N/A","support_state":"unknown","expiry_or_review_date":null,"qualification":"Unknown - not found in sources reviewed | N/A | Not confirmed | UK | Not found in a Tier 1-2 source in this pass | Not found | Evidence gap - directly relevant to Netify's UK healthcare-sector buyers, consistent with the same gap flagged for Cato and Zscaler.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"compliance:59a743a4bd4a84f4e02b66bd","framework":"NIS2 relevance","scope":"N/A","support_state":"unknown","expiry_or_review_date":null,"qualification":"Unknown - not found in sources reviewed | N/A | Not confirmed | EU | Not found in a Tier 1-2 source in this pass | Not found | Evidence gap.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"compliance:33bc887ec43e35efedfe56ff","framework":"PCI DSS","scope":"Platform","support_state":"unknown","expiry_or_review_date":null,"qualification":"Certified | Platform | PCI DSS v4.0.1 explicitly named on the Compliance Centre | None identified | 22 Jul 2026 | Explicit, version-specific (v4.0.1) confirmation - stronger evidence than the equivalent Cato and Zscaler rows, neither of which had a confirmed PCI-DSS attestation.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:15"]},{"id":"compliance:e44157aed37f7ae55d3f8aab","framework":"SOC 2","scope":"Platform","support_state":"unknown","expiry_or_review_date":null,"qualification":"Certified (Type 2) | Platform | SOC 2 Type 2 report referenced (also historically AICPA SOC 1/2/3) | None identified | 22 Jul 2026 | Confirmed via the independently-hosted Compliance Centre, which lists SOC 2 Type 2 alongside the full certification set.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:15"]},{"id":"compliance:6565675a00c0af9f6a5723b0","framework":"UK public sector frameworks","scope":"UK","support_state":"unknown","expiry_or_review_date":null,"qualification":"Cyber Essentials explicitly named on Netskope's own Compliance Centre | UK | Cyber Essentials (not confirmed whether this is the base or Plus tier) | UK | 22 Jul 2026 | Genuinely primary-sourced (unlike the equivalent Zscaler finding, which rested only on an uncorroborated third-party review) - though Netify should confirm whether this is Cyber Essentials or Cyber Essentials Plus specifically, since the two have different NHS DSPT implications per current NHS Supply Chain guidance.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:15"]}],"integrations":[{"id":"integrations:674095c33382e5923601827d","integration_name":"AWS","integration_type":"Cloud","delivery_relationship":"native","qualification":"Cloud | Native - AWS Cloud WAN integration and AWS EC2 hosting for Cloud Exchange | Bidirectional | Not specified | Cloud Exchange can be self-hosted on AWS EC2 per third-party pricing analysis | High | Confirmed via both a product integration and an operational cost detail (EC2 hosting) - good, specific evidence.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:12","evidence:netskope:43"]},{"id":"integrations:1f9de11172da899ac93e38d8","integration_name":"Active Directory","integration_type":"Identity","delivery_relationship":"unknown","qualification":"Identity | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"integrations:7ec4505f01860bd1e5240cac","integration_name":"Cribl","integration_type":"Data pipeline / observability","delivery_relationship":"native","qualification":"Data pipeline / observability | Native, explicitly named - Cribl Stream can route/format Netskope telemetry; Cribl Lake and Search referenced for cost-effective long-term storage | Netskope → Cribl | Not specified | A named, current (October 2025) integration specifically for telemetry routing and long-term log storage economics | High | Not found for either Cato or Zscaler - a genuinely distinctive, current integration worth noting given Cribl's growing role in enterprise log-management cost control.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:36"]},{"id":"integrations:b0ba6fb0b37d01fc6dd48302","integration_name":"CrowdStrike","integration_type":"EDR","delivery_relationship":"native","qualification":"EDR | Native, deeply documented - a dedicated Knowledge Portal Solution Guide covers multiple integration points: Netskope Log Streaming to CrowdStrike NG-SIEM/LogScale via AWS S3, and 'Netskope Direct to Zero Trust App' integrating with CrowdStrike Falcon Foundry for IoC management | Bidirectional (Netskope logs feed CrowdStrike NG-SIEM; CrowdStrike-detected IoCs push back to Netskope URL/File Lists) | Not specified | A formal, technical solution guide with named data-flow mechanics (S3 bucket, field mappings) exists | docs.netskope.com CrowdStrike Solution Guide | High | One of the best-evidenced integrations in this entire profile - a dedicated technical solution guide with specific data-flow architecture, comparable in depth to Zscaler's CrowdStrike alliance evidence.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"integrations:7f69166954aa8e01dc7b87fa","integration_name":"Google Cloud","integration_type":"Cloud","delivery_relationship":"native","qualification":"Cloud | Native - Google Cloud WAN integration | Bidirectional | Not specified | Not detailed further | High | Confirmed via named cloud WAN integration.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:12"]},{"id":"integrations:ecc1b6fd0740aa4a6861bcb8","integration_name":"Google Workspace","integration_type":"Identity/productivity","delivery_relationship":"unknown","qualification":"Identity/productivity | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"integrations:dac390a7319daa3fdf4f65cb","integration_name":"Intune","integration_type":"MDM/UEM","delivery_relationship":"unknown","qualification":"MDM/UEM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"integrations:4ca4f3c947771eeadc8d331c","integration_name":"Jamf","integration_type":"MDM/UEM","delivery_relationship":"unknown","qualification":"MDM/UEM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"integrations:19c5a791f9b7066a603ddd17","integration_name":"Microsoft 365","integration_type":"Productivity/SaaS","delivery_relationship":"native","qualification":"Productivity/SaaS | Native - JLL case study specifically describes Netskope identifying misconfigured personal OneDrive mappings on corporate devices | Netskope monitors/secures M365 traffic and configuration | Not specified | Not detailed further | High | Confirmed via a specific, named production use case (OneDrive misconfiguration remediation) - good evidence quality.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:31"]},{"id":"integrations:a1c5b3cdd7c262290b83df74","integration_name":"Microsoft Azure","integration_type":"Cloud","delivery_relationship":"native","qualification":"Cloud | Native - Azure Virtual WAN integration | Bidirectional | Not specified | Not detailed further | High | Confirmed via named cloud WAN integration.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:12"]},{"id":"integrations:b9759cc484b9eb55dd91043b","integration_name":"Microsoft Defender","integration_type":"EDR","delivery_relationship":"unknown","qualification":"EDR | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap - CrowdStrike is clearly the best-documented EDR partner.","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"integrations:16793d30fc846aedc909816b","integration_name":"Microsoft Entra ID","integration_type":"Identity","delivery_relationship":"unknown","qualification":"Identity | Not separately itemised from general IdP integration claims in sources reviewed (Okta is the specifically documented IdP) | Unknown | Not specified | Not detailed | Not found as a distinct integration in this pass | Low | Do not assume Entra ID parity with the Okta integration without direct confirmation - same caution applied to Zscaler's equivalent row.","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"integrations:fb88a7e6f690dad82aad6a90","integration_name":"Microsoft Sentinel","integration_type":"SIEM","delivery_relationship":"native","qualification":"SIEM | Native, confirmed via Netskope's own blog on SIEM integration | Netskope → Sentinel | Not specified | Netskope explicitly lists Sentinel alongside CrowdStrike NG-SIEM and Splunk as a direct telemetry-feed destination | High | Directly confirmed by Netskope itself, unlike the equivalent Zscaler row which was low-confidence.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:36"]},{"id":"integrations:8a029e6b900cede85b84b9f7","integration_name":"Okta","integration_type":"Identity","delivery_relationship":"native","qualification":"Identity | Native, confirmed | Bidirectional - Netskope pauses sessions and triggers Okta MFA reauthentication on policy violation/anomalous behaviour | Not specified | Documented in a formal integration whitepaper with specific session-handling mechanics | High | The session-pause-and-reauthenticate mechanic is a specific, technical, well-evidenced detail - genuinely good integration depth.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:38","evidence:netskope:39"]},{"id":"integrations:d4a87141977f79ffd7515482","integration_name":"Palo Alto Cortex","integration_type":"SIEM/XDR","delivery_relationship":"unknown","qualification":"SIEM/XDR | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"integrations:c450894b420e65ba597041ff","integration_name":"REST API","integration_type":"Platform API","delivery_relationship":"api","qualification":"Platform API | Native - Cloud Exchange (CE) framework explicitly built around plugins and customer-buildable integrations to any on-premises or cloud platform offering APIs, with all supported plugins published on GitHub and a developer's guide provided | Bidirectional | Not specified | Cloud Exchange as a Service also available | High | Genuinely strong, well-documented API/integration framework - the GitHub-published plugin approach is a specific, credible, developer-friendly detail.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:37"]},{"id":"integrations:593c8dc71599865c375ecfe1","integration_name":"SCIM/SAML/OIDC","integration_type":"Identity federation","delivery_relationship":"unknown","qualification":"Identity federation | SAML implied via the Okta integration's session/reauthentication mechanics; SCIM/OIDC not separately itemised | Bidirectional (auth) | Not specified | Not detailed further | Medium | SAML is a reasonable inference from the documented Okta mechanics; SCIM/OIDC weren't separately confirmed by name.","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:39"]},{"id":"integrations:d8ef19918d8cb0e55783bb3c","integration_name":"ServiceNow","integration_type":"ITSM","delivery_relationship":"unknown","qualification":"ITSM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"integrations:876a69d57c8c703267766439","integration_name":"Splunk","integration_type":"SIEM","delivery_relationship":"native","qualification":"SIEM | Native - 'Netskope App for Splunk' explicitly named | Netskope → Splunk (ingest, parse, normalize, search within Splunk) | Not specified | Described as providing a 'single-pane-of-glass view for security and adaptive orchestration' | High | A named, dedicated Splunk app (not just generic log export) - strong evidence.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:36"]},{"id":"integrations:6f9ce731ca0a7d8f284125ae","integration_name":"Syslog","integration_type":"Log export","delivery_relationship":"unknown","qualification":"Log export | Not separately itemised in sources reviewed, though implied by the broader SIEM integration framework | Unknown | Not specified | Not detailed | Not found explicitly | Low-Medium | Reasonable to assume given documented SIEM integrations, not independently confirmed by name.","confidence":"low_medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"integrations:321481c1550d7b7c84e9af89","integration_name":"Terraform","integration_type":"Infrastructure-as-code","delivery_relationship":"unknown","qualification":"Infrastructure-as-code | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]}],"sector_evidence":[{"id":"sector_evidence:c8ebb9b0d0a4af15d6d670ae","sector":"Education","suitability_state":"unknown","named_evidence":"None found","case_study_strength":"none","qualification":"Unknown - not assessed | Not assessed | Not assessed | None found | N/A | No case study found | Evidence gap.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"sector_evidence:a3b87cb1b682e62ff6afa2e0","sector":"Energy/utilities","suitability_state":"unknown","named_evidence":"None found","case_study_strength":"none","qualification":"Unknown - not assessed | Not assessed | Not assessed | None found | N/A | No case study found | Evidence gap - notably, Netskope lacks the energy-sector evidence Zscaler has via NOV.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"sector_evidence:e921c016515557b42b1597b2","sector":"Financial services","suitability_state":"unknown","named_evidence":"CARE Ratings (credit rating agency, India)","case_study_strength":"strong","qualification":"Good fit, evidenced | DLP, CASB, PCI DSS v4.0.1 certification | PCI DSS v4.0.1 explicitly certified; DORA explicitly named on the Compliance Centre | CARE Ratings (credit rating agency, India) | N/A | Single named case study, though the PCI-DSS and DORA compliance evidence is genuinely strong | The best-evidenced sector-compliance combination across all three vendors profiled so far - explicit PCI-DSS and DORA naming, plus a real financial-services case study.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:15","evidence:netskope:30"]},{"id":"sector_evidence:e720ed8f203b8a8ec858b8bd","sector":"Government/public sector","suitability_state":"unknown","named_evidence":"None found as a named case study specifically, though the California SLP contract is itself a form of public-sector proof point","case_study_strength":"none","qualification":"Good fit, evidenced | FedRAMP High GovCloud, isolated Private Security Cloud | FedRAMP High Authorization; State of California Software Licensing Programme contract award (2019) | None found as a named case study specifically, though the California SLP contract is itself a form of public-sector proof point | GovCloud is a distinct offering | Less deeply evidenced than Zscaler's public-sector story (which included CJIS, CMMC, DoD IL5, and a named CSC case study) | Real and credible, but Zscaler currently has the deeper, more extensively documented public-sector evidence base of the two.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:16","evidence:netskope:20"]},{"id":"sector_evidence:efa6d6a2daecd670246307be","sector":"Healthcare/NHS","suitability_state":"requires_confirmation","named_evidence":"None found in this research pass","case_study_strength":"none","qualification":"Conditional - HIPAA assessment confirmed (US), but no NHS DSPT-specific evidence found | DLP, CASB, ZTNA plausibly relevant | HIPAA assessed (US); NHS DSPT relevance not found | None found in this research pass | N/A | No named healthcare case study found | Similar profile to Zscaler on this point - do not claim NHS/UK healthcare suitability beyond the general HIPAA assessment without direct confirmation.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"sector_evidence:877966f8b5a2f83acacc7c13","sector":"Hospitality","suitability_state":"unknown","named_evidence":"None found","case_study_strength":"none","qualification":"Unknown - not assessed | Not assessed | Not assessed | None found | N/A | No case study found | Evidence gap.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"sector_evidence:55e6c8a97b55cf4ec376b14c","sector":"Manufacturing","suitability_state":"unknown","named_evidence":"None found","case_study_strength":"none","qualification":"Unknown - not assessed | Not assessed | Not assessed | None found | N/A | No case study found | Evidence gap.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"sector_evidence:185f1044ccf369e47b44f7d0","sector":"Professional services","suitability_state":"unknown","named_evidence":"JLL (real estate/professional services), MinterEllisonRuddWatts (law firm)","case_study_strength":"strong","qualification":"Good fit, evidenced | DLP, CASB for insider-risk and data-loss use cases | Not assessed | JLL (real estate/professional services), MinterEllisonRuddWatts (law firm) | N/A | Two named case studies, reasonably detailed | A genuinely well-evidenced sector for Netskope specifically - two independent, named, detailed case studies covering related professional-services use cases (insider risk, fast SSE rollout).","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:31","evidence:netskope:32"]},{"id":"sector_evidence:b5c77da6f468f04cb293638d","sector":"Retail","suitability_state":"not_supported","named_evidence":"None found","case_study_strength":"none","qualification":"Unknown - not assessed, no case study found | Not assessed | Not assessed | None found | N/A | No case study found | Evidence gap - notably, Netskope lacks the retail-specific evidence that both Cato (Ulta Beauty) and Zscaler (AutoNation) have.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"sector_evidence:73d027f332968714490f5488","sector":"Transport/logistics","suitability_state":"unknown","named_evidence":"None found","case_study_strength":"none","qualification":"Unknown - not assessed | Not assessed | Not assessed | None found | N/A | No case study found | Evidence gap.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]}],"case_studies":[{"id":"case_studies:0396aa33af38b93a8c62691e","customer_type":"Named - MinterEllisonRuddWatts","named_customer":null,"sector":"Legal services (law firm)","geography":"New Zealand","estate":"Not quantified; Not quantified","outcome":"Full rollout completed in six weeks, described by the customer as 'one of the smoothest deployments... as a company'; named executives (Stevenson, Mulder) both quoted positively","quantified_result":"Full rollout completed in six weeks, described by the customer as 'one of the smoothest deployments... as a company'; named executives (Stevenson, Mulder) both quoted positively","qualification":"Named - MinterEllisonRuddWatts | Legal services (law firm) | New Zealand | Not quantified | Not quantified | Wanted to treat each endpoint as independently secure for 'anywhere working', consolidating NG SWG, CASB, ZTNA Next and Cloud Firewall | NG SWG, CASB, ZTNA Next, Cloud Firewall (CFW) | Client-based, consolidated single-platform approach | Not itemised | Full rollout completed in six weeks, described by the customer as 'one of the smoothest deployments... as a company'; named executives (Stevenson, Mulder) both quoted positively | High - named customer, two named executives, a specific and credible timeframe (six weeks) that's unusually precise for this kind of case study | The six-week timeline is a genuinely useful, specific data point for buyer expectation-setting - directly comparable to Cato's zero-touch provisioning evidence and Mindbody's 'five times faster than VPN' claim for Zscaler.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"case_studies:127c448503cd732d886d603b","customer_type":"Named - CARE Ratings","named_customer":null,"sector":"Financial services (credit rating agency)","geography":"India","estate":"Not quantified; Not quantified","outcome":"System went live within the expected timeframe; CARE Ratings became aware of multiple previously-unmanaged risky apps","quantified_result":"System went live within the expected timeframe; CARE Ratings became aware of multiple previously-unmanaged risky apps","qualification":"Named - CARE Ratings | Financial services (credit rating agency) | India | Not quantified | Not quantified | Needed visibility into unmanaged apps posing security risks; wanted secure hybrid IT access | CASB, NG SWG, Netskope Private Access (NPA/ZTNA) | Client-based (all end-user systems) plus data-centre connectors for NPA | Not itemised | System went live within the expected timeframe; CARE Ratings became aware of multiple previously-unmanaged risky apps | Medium-High - named customer, named executive (Rawther, CITO), partner-assisted deployment described in reasonable detail, though without hard time/scale metrics | A solid, named financial-services proof point strengthening Table 14's financial-services suitability finding, though less quantified than the other two case studies below.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"case_studies:934ff4efabbbd9f532c58200","customer_type":"Named - JLL (Jones Lang LaSalle)","named_customer":null,"sector":"Real estate / professional services","geography":"United States (Chicago-headquartered, global operations)","estate":"Not quantified; Not quantified","outcome":"Specific, named remediation outcome: identified affected endpoints and restored corporate OneDrive accounts as 'an unexpected benefit'; named executives (Shepherd, Sarnowski) confirm improved technology-standard enforcement","quantified_result":"Specific, named remediation outcome: identified affected endpoints and restored corporate OneDrive accounts as 'an unexpected benefit'; named executives (Shepherd, Sarnowski) confirm improved technology-standard enforcement","qualification":"Named - JLL (Jones Lang LaSalle) | Real estate / professional services | United States (Chicago-headquartered, global operations) | Not quantified | Not quantified | Employees inadvertently mapping personal OneDrive accounts to corporate devices; developers using unapproved cloud tools/APIs; needed IT-standardisation visibility | Netskope One SSE, CASB, DLP | Client-based | Microsoft 365 / OneDrive | Specific, named remediation outcome: identified affected endpoints and restored corporate OneDrive accounts as 'an unexpected benefit'; named executives (Shepherd, Sarnowski) confirm improved technology-standard enforcement | High - named customer, two named executives, a specific and unusual remediation detail (personal OneDrive mapping) that reads as genuine rather than scripted marketing language | The specificity of the OneDrive-mapping detail is exactly the kind of concrete, slightly unusual finding that makes a case study credible - good evidence to cite directly to buyers with similar insider-risk concerns.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]}],"evaluations":[{"id":"evaluations:01b481a4f47ba31bb0070914","evaluation_type":"summary","finding":"Questions Netify still cannot verify | NHS DSPT and NIS2 relevance; whether the named Cyber Essentials certification is base or Plus tier; exact tier-to-feature mapping for RBI, DEM, UEBA and DSPM; SASE Gateway hardware charging model; formal, contractually-specific support SLAs; and whether any fully Netskope-managed (as opposed to Professional-Services-assisted or partner-delivered) service exists. | Synthesis of Tables 3, 8, 13, 16 | N/A - explicitly unresolved | This list should drive the next follow-up (a direct Netskope briefing or partner conversation) before this profile is considered fully closed out, mirroring the standard applied to both the Cato and Zscaler profiles.","buyer_implication":"This list should drive the next follow-up (a direct Netskope briefing or partner conversation) before this profile is considered fully closed out, mirroring the standard applied to both the Cato and Zscaler profiles.","qualification":"NHS DSPT and NIS2 relevance; whether the named Cyber Essentials certification is base or Plus tier; exact tier-to-feature mapping for RBI, DEM, UEBA and DSPM; SASE Gateway hardware charging model; formal, contractually-specific support SLAs; and whether any fully Netskope-managed (as opposed to Professional-Services-assisted or partner-delivered) service exists. | Synthesis of Tables 3, 8, 13, 16 | N/A - explicitly unresolved | This list should drive the next follow-up (a direct Netskope briefing or partner conversation) before this profile is considered fully closed out, mirroring the standard applied to both the Cato and Zscaler profiles.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:04875987dc247b58fc9ef055","evaluation_type":"summary","finding":"Remote-user-heavy organisation | Good fit | Client-based and clientless (CASB API-mode) access both well evidenced; CASB API-mode is a genuine relative strength for BYOD-heavy remote estates | Requires DEM add-on for full experience visibility | User licensing plus potential per-app-seat CASB API costs | Table 5 findings | The clientless CASB API-mode capability is Netskope's most distinctive strength for this buyer profile specifically - genuinely different from both Cato and Zscaler's primarily client-based remote-access models.","buyer_implication":null,"qualification":"Good fit | Client-based and clientless (CASB API-mode) access both well evidenced; CASB API-mode is a genuine relative strength for BYOD-heavy remote estates | Requires DEM add-on for full experience visibility | User licensing plus potential per-app-seat CASB API costs | Table 5 findings | The clientless CASB API-mode capability is Netskope's most distinctive strength for this buyer profile specifically - genuinely different from both Cato and Zscaler's primarily client-based remote-access models.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:0493c266f52e854b5c46cc63","evaluation_type":"summary","finding":"Overall Netify Assessment | Netskope is the most data-centric, compliance-comprehensive choice in this comparison set, with genuinely original DLP/CASB technology and the broadest single-source compliance evidence of the three vendors profiled - a credible shortlist candidate for SaaS-heavy, regulation-conscious buyers specifically. Its clearest weak points are a well-documented pattern of Year 1 cost escalation above the initial quote, thinner formal support-SLA evidence than Zscaler, and the absence of a large-scale branch-rollout proof point that Cato has. This profile is solid enough to support initial shortlist guidance for data-centric and compliance-driven buyers, but the flagged pricing-escalation risk and support-SLA gap should be closed out directly with Netskope before use in a high-stakes procurement decision. | Whole profile | Medium-High overall | Recommend direct Netskope engagement to close the flagged evidence gaps, mirroring the same next step recommended for both the Cato and Zscaler profiles.","buyer_implication":"Recommend direct Netskope engagement to close the flagged evidence gaps, mirroring the same next step recommended for both the Cato and Zscaler profiles.","qualification":"Netskope is the most data-centric, compliance-comprehensive choice in this comparison set, with genuinely original DLP/CASB technology and the broadest single-source compliance evidence of the three vendors profiled - a credible shortlist candidate for SaaS-heavy, regulation-conscious buyers specifically. Its clearest weak points are a well-documented pattern of Year 1 cost escalation above the initial quote, thinner formal support-SLA evidence than Zscaler, and the absence of a large-scale branch-rollout proof point that Cato has. This profile is solid enough to support initial shortlist guidance for data-centric and compliance-driven buyers, but the flagged pricing-escalation risk and support-SLA gap should be closed out directly with Netskope before use in a high-stakes procurement decision. | Whole profile | Medium-High overall | Recommend direct Netskope engagement to close the flagged evidence gaps, mirroring the same next step recommended for both the Cato and Zscaler profiles.","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:1532e74ca3442a5d9ad94d90","evaluation_type":"summary","finding":"Biggest operational advantage | The clientless CASB API-mode access capability, which is a genuine, distinctive strength for BYOD-heavy and contractor-heavy remote estates that neither Cato nor Zscaler evidenced as clearly. | Table 5, 15 | Medium-High | Worth highlighting specifically to buyers with significant unmanaged-device populations.","buyer_implication":"Worth highlighting specifically to buyers with significant unmanaged-device populations.","qualification":"The clientless CASB API-mode access capability, which is a genuine, distinctive strength for BYOD-heavy and contractor-heavy remote estates that neither Cato nor Zscaler evidenced as clearly. | Table 5, 15 | Medium-High | Worth highlighting specifically to buyers with significant unmanaged-device populations.","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:186cde9cd61ab9830bbdceb9","evaluation_type":"summary","finding":"Compliance & Footprint | Unusually comprehensive, primary-sourced compliance coverage - FedRAMP High Authorized GovCloud, ISO 27001/27017/27018, SOC 2 Type 2, PCI DSS v4.0.1, HIPAA, GDPR, and explicit naming of DORA, UK Cyber Essentials, C5 and IRAP on Netskope's own compliance centre. | The compliance centre is powered by a third-party trust-centre platform (SafeBase) rather than being a fully self-hosted page - a minor structural note, not a reliability concern, since the underlying certifications are independently audited regardless of hosting platform.","buyer_implication":null,"qualification":"Unusually comprehensive, primary-sourced compliance coverage - FedRAMP High Authorized GovCloud, ISO 27001/27017/27018, SOC 2 Type 2, PCI DSS v4.0.1, HIPAA, GDPR, and explicit naming of DORA, UK Cyber Essentials, C5 and IRAP on Netskope's own compliance centre. | The compliance centre is powered by a third-party trust-centre platform (SafeBase) rather than being a fully self-hosted page - a minor structural note, not a reliability concern, since the underlying certifications are independently audited regardless of hosting platform.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:1ebe1515bfb57a0a2a58e4d3","evaluation_type":"summary","finding":"Sector fit | Financial services and professional services are the best-evidenced sectors (PCI-DSS, DORA, plus three named case studies across these areas); public sector is good but less deep than Zscaler's; retail, manufacturing, education, hospitality, transport and energy all lack case-study evidence entirely. | Table 14 | High for financial/professional services; Medium for public sector; Low for other sectors | Do not extend the strong financial/professional-services evidence into an assumption of equal strength in retail or energy, where Netskope currently has no case-study evidence at all (unlike Cato and Zscaler respectively).","buyer_implication":"Do not extend the strong financial/professional-services evidence into an assumption of equal strength in retail or energy, where Netskope currently has no case-study evidence at all (unlike Cato and Zscaler respectively).","qualification":"Financial services and professional services are the best-evidenced sectors (PCI-DSS, DORA, plus three named case studies across these areas); public sector is good but less deep than Zscaler's; retail, manufacturing, education, hospitality, transport and energy all lack case-study evidence entirely. | Table 14 | High for financial/professional services; Medium for public sector; Low for other sectors | Do not extend the strong financial/professional-services evidence into an assumption of equal strength in retail or energy, where Netskope currently has no case-study evidence at all (unlike Cato and Zscaler respectively).","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:20671d870e5d5d171b70abe7","evaluation_type":"summary","finding":"Security & Analytics | Deep, long-standing DLP/CASB heritage with a genuinely large Cloud Confidence Index (85,000+ SaaS/GenAI apps) and ML-based Train Your Own Classifiers DLP. | Modular licensing means CASB API, UEBA, DSPM and DEM are explicitly add-ons per multiple third-party pricing analyses, with at least one describing a per-app-seat multiplication effect for CASB API that can produce a materially larger bill than a naive per-user estimate.","buyer_implication":null,"qualification":"Deep, long-standing DLP/CASB heritage with a genuinely large Cloud Confidence Index (85,000+ SaaS/GenAI apps) and ML-based Train Your Own Classifiers DLP. | Modular licensing means CASB API, UEBA, DSPM and DEM are explicitly add-ons per multiple third-party pricing analyses, with at least one describing a per-app-seat multiplication effect for CASB API that can produce a materially larger bill than a naive per-user estimate.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:22c7e64119593970d07f7caa","evaluation_type":"summary","finding":"Large enterprise | Good fit | JLL (large real estate/professional services firm) demonstrates enterprise-scale deployment with insider-risk use cases | Requires internal or partner-supported operational ownership | Enterprise-tier pricing, with module-creep risk most consequential at scale given multiplied add-on costs | Solid but not as scale-specific (no named user/site counts) as Cato's Ulta Beauty or Zscaler's NOV case studies.","buyer_implication":null,"qualification":"Good fit | JLL (large real estate/professional services firm) demonstrates enterprise-scale deployment with insider-risk use cases | Requires internal or partner-supported operational ownership | Enterprise-tier pricing, with module-creep risk most consequential at scale given multiplied add-on costs | Solid but not as scale-specific (no named user/site counts) as Cato's Ulta Beauty or Zscaler's NOV case studies.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:31"]},{"id":"evaluations:24bf50402a3760e10decfb72","evaluation_type":"summary","finding":"When would Netify recommend looking elsewhere? (mandatory) | When a buyer specifically wants a private, SLA-backed backbone as the architectural core (Cato fits better); when a buyer needs the deepest, most contractually-specific support-SLA and MDR evidence (Zscaler currently documents this more thoroughly); when a buyer needs a large-scale, proven branch-rollout track record (neither Netskope nor Zscaler currently match Cato's Ulta Beauty evidence); or when a buyer has a low tolerance for Year 1 cost surprises and needs the most predictable, self-serve pricing model available. | Synthesis of Tables 7, 8, 16, 17 | Medium-High | Each trigger is tied to a specific, evidenced gap rather than a generic 'consider alternatives' hedge.","buyer_implication":"Each trigger is tied to a specific, evidenced gap rather than a generic 'consider alternatives' hedge.","qualification":"When a buyer specifically wants a private, SLA-backed backbone as the architectural core (Cato fits better); when a buyer needs the deepest, most contractually-specific support-SLA and MDR evidence (Zscaler currently documents this more thoroughly); when a buyer needs a large-scale, proven branch-rollout track record (neither Netskope nor Zscaler currently match Cato's Ulta Beauty evidence); or when a buyer has a low tolerance for Year 1 cost surprises and needs the most predictable, self-serve pricing model available. | Synthesis of Tables 7, 8, 16, 17 | Medium-High | Each trigger is tied to a specific, evidenced gap rather than a generic 'consider alternatives' hedge.","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:25ca753ff6069312f6882c39","evaluation_type":"summary","finding":"Firewall consolidation | Evidenced indirectly via MERW's deployment of Cloud Firewall (CFW) alongside NG SWG, CASB and ZTNA Next as part of one consolidated platform rollout | Existing firewall rules translated into Netskope policy | IT/security team | Netskope Professional Services | Six weeks for the full SSE rollout including CFW (MERW case study) | Policy translation errors during cutover (not specifically addressed in the source) | Not detailed | Real, evidenced via a named case study, with a specific and credible six-week timeline - genuinely useful evidence for buyer expectation-setting.","buyer_implication":null,"qualification":"Evidenced indirectly via MERW's deployment of Cloud Firewall (CFW) alongside NG SWG, CASB and ZTNA Next as part of one consolidated platform rollout | Existing firewall rules translated into Netskope policy | IT/security team | Netskope Professional Services | Six weeks for the full SSE rollout including CFW (MERW case study) | Policy translation errors during cutover (not specifically addressed in the source) | Not detailed | Real, evidenced via a named case study, with a specific and credible six-week timeline - genuinely useful evidence for buyer expectation-setting.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:25f6567c6b59d9cf0d62733d","evaluation_type":"summary","finding":"Questions to ask before recommending it | 1) Which Table 3 capabilities (RBI, DEM, UEBA, DSPM, full-strength DLP) are actually included at the buyer's target tier, versus priced as separate add-ons - and specifically, how does CASB API's per-app-seat pricing apply at the buyer's expected SaaS-app count? 2) What would Professional Services realistically add to Year 1 cost given the buyer's deployment complexity? 3) Can Netskope confirm whether the Cyber Essentials certification on its Compliance Centre is base-tier or Plus, given the NHS DSPT implications? 4) For branch-heavy buyers, can Netskope provide a reference deployment comparable in scale/evidence depth to what Cato can show? | Synthesis of Tables 3, 13, 16, 17 | High | A direct, reusable question set for Netify's advisory conversations with buyers considering Netskope.","buyer_implication":"A direct, reusable question set for Netify's advisory conversations with buyers considering Netskope.","qualification":"1) Which Table 3 capabilities (RBI, DEM, UEBA, DSPM, full-strength DLP) are actually included at the buyer's target tier, versus priced as separate add-ons - and specifically, how does CASB API's per-app-seat pricing apply at the buyer's expected SaaS-app count? 2) What would Professional Services realistically add to Year 1 cost given the buyer's deployment complexity? 3) Can Netskope confirm whether the Cyber Essentials certification on its Compliance Centre is base-tier or Plus, given the NHS DSPT implications? 4) For branch-heavy buyers, can Netskope provide a reference deployment comparable in scale/evidence depth to what Cato can show? | Synthesis of Tables 3, 13, 16, 17 | High | A direct, reusable question set for Netify's advisory conversations with buyers considering Netskope.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:2a07cca8045bdc6eb1b95481","evaluation_type":"summary","finding":"Who is this genuinely best suited for? (mandatory) | Data-centric enterprises and regulated organisations whose primary risk is SaaS/GenAI data exfiltration and shadow IT, particularly those needing broad, easily-verifiable compliance coverage (FedRAMP High, PCI DSS, DORA, Cyber Essentials) checked quickly across many frameworks - and secondarily, buyers wanting a more SD-WAN-mature converged SASE platform than Zscaler currently offers, without needing Cato's owned-backbone architecture specifically. | Tables 1, 3, 11, 13, 15 | High | Buyers matching this profile - especially SaaS-heavy, compliance-conscious enterprises - can proceed with real confidence in the core data-protection and compliance claims.","buyer_implication":"Buyers matching this profile - especially SaaS-heavy, compliance-conscious enterprises - can proceed with real confidence in the core data-protection and compliance claims.","qualification":"Data-centric enterprises and regulated organisations whose primary risk is SaaS/GenAI data exfiltration and shadow IT, particularly those needing broad, easily-verifiable compliance coverage (FedRAMP High, PCI DSS, DORA, Cyber Essentials) checked quickly across many frameworks - and secondarily, buyers wanting a more SD-WAN-mature converged SASE platform than Zscaler currently offers, without needing Cato's owned-backbone architecture specifically. | Tables 1, 3, 11, 13, 15 | High | Buyers matching this profile - especially SaaS-heavy, compliance-conscious enterprises - can proceed with real confidence in the core data-protection and compliance claims.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:2a8d21f7cab19b15cf95582b","evaluation_type":"summary","finding":"SSE deployment to remote users | Client-based (Netskope One Client) or clientless (CASB API-mode) rollout to remote/mobile users; JLL's insider-risk use case demonstrates real production deployment to a distributed workforce | IdP integration (Okta) generally a prerequisite for user-aware policy | End-user self-install typical for client-based access | Not itemised | Not quantified | Not itemised | Not detailed | Solid evidence via JLL specifically, though without the scale metrics (e.g. Zscaler's NOV 27,500-user figure) that would make this a standout data point.","buyer_implication":null,"qualification":"Client-based (Netskope One Client) or clientless (CASB API-mode) rollout to remote/mobile users; JLL's insider-risk use case demonstrates real production deployment to a distributed workforce | IdP integration (Okta) generally a prerequisite for user-aware policy | End-user self-install typical for client-based access | Not itemised | Not quantified | Not itemised | Not detailed | Solid evidence via JLL specifically, though without the scale metrics (e.g. Zscaler's NOV 27,500-user figure) that would make this a standout data point.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:2d3887d14c0361b1ba248af8","evaluation_type":"summary","finding":"AI reality | A genuinely deep, specific, and current set of AI features (SkopeAI, CCI, AI Guardrails, named Copilots, MCP server) that reads as the most substantively evidenced AI story of the three vendors profiled, not just AI-washing. | Table 11 | High | Represent this AI depth confidently - it's better evidenced here than for either Cato or Zscaler on several specific points (named GA Copilots, MCP server).","buyer_implication":"Represent this AI depth confidently - it's better evidenced here than for either Cato or Zscaler on several specific points (named GA Copilots, MCP server).","qualification":"A genuinely deep, specific, and current set of AI features (SkopeAI, CCI, AI Guardrails, named Copilots, MCP server) that reads as the most substantively evidenced AI story of the three vendors profiled, not just AI-washing. | Table 11 | High | Represent this AI depth confidently - it's better evidenced here than for either Cato or Zscaler on several specific points (named GA Copilots, MCP server).","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:378de098e50dd7ec0c629a93","evaluation_type":"summary","finding":"Procurement watch-out | One pricing/review source used in this research pass (an anonymous AWS Marketplace-hosted review) was assessed as too low-reliability to use as evidence and excluded - see Evidence Register #40 | N/A - this is a methodology note, not a buyer-facing finding | N/A | Table 19 note; Evidence Register #40 | N/A | Included here for transparency about the research process, mirroring the standard applied throughout this profile and the two before it.","buyer_implication":"N/A - this is a methodology note, not a buyer-facing finding","qualification":"One pricing/review source used in this research pass (an anonymous AWS Marketplace-hosted review) was assessed as too low-reliability to use as evidence and excluded - see Evidence Register #40 | N/A - this is a methodology note, not a buyer-facing finding | N/A | Table 19 note; Evidence Register #40 | N/A | Included here for transparency about the research process, mirroring the standard applied throughout this profile and the two before it.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:3f4f57b2a984deca551abcf0","evaluation_type":"summary","finding":"Deployment reality | Genuinely mixed evidence: named case studies (MERW's six weeks) describe fast, smooth rollouts, while independent third-party analysis describes onboarding requiring significant dedicated resources and Professional Services investment. Both are likely true depending on deployment complexity. | Table 9, 17, 18 | Medium | Present both perspectives to buyers rather than defaulting to only the more flattering case-study framing.","buyer_implication":"Present both perspectives to buyers rather than defaulting to only the more flattering case-study framing.","qualification":"Genuinely mixed evidence: named case studies (MERW's six weeks) describe fast, smooth rollouts, while independent third-party analysis describes onboarding requiring significant dedicated resources and Professional Services investment. Both are likely true depending on deployment complexity. | Table 9, 17, 18 | Medium | Present both perspectives to buyers rather than defaulting to only the more flattering case-study framing.","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:411d58653f76f37b5edad50e","evaluation_type":"summary","finding":"Regulated organisation | Strong fit, broadly | The most comprehensively-evidenced compliance certification set across all three vendors profiled - FedRAMP High, PCI DSS v4.0.1, HIPAA assessed, DORA and Cyber Essentials all explicitly named on a primary compliance source | Buyer must still independently verify sector-specific frameworks (NHS DSPT, NIS2) not found in this pass | Not assessed | Table 13 findings | Genuinely the strongest overall compliance breadth of the three vendors profiled, though public-sector depth specifically (DoD IL5, CJIS-equivalent) is less deep than Zscaler's.","buyer_implication":null,"qualification":"Strong fit, broadly | The most comprehensively-evidenced compliance certification set across all three vendors profiled - FedRAMP High, PCI DSS v4.0.1, HIPAA assessed, DORA and Cyber Essentials all explicitly named on a primary compliance source | Buyer must still independently verify sector-specific frameworks (NHS DSPT, NIS2) not found in this pass | Not assessed | Table 13 findings | Genuinely the strongest overall compliance breadth of the three vendors profiled, though public-sector depth specifically (DoD IL5, CJIS-equivalent) is less deep than Zscaler's.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:4167f698c69cb5d806412af3","evaluation_type":"summary","finding":"SME | Conditional fit | Entry-tier SSE bundle pricing described as competitive at the base level, but module-creep risk documented across multiple sources | Minimal internal skills needed for the base SSE tier; PS-heavy onboarding may strain small IT teams | Multiple independent sources warn that Year 1 spend can land 30-50% above the quoted licence cost | SMEs should budget conservatively given the well-documented pattern of Year 1 cost overrun relative to the initial quote.","buyer_implication":null,"qualification":"Conditional fit | Entry-tier SSE bundle pricing described as competitive at the base level, but module-creep risk documented across multiple sources | Minimal internal skills needed for the base SSE tier; PS-heavy onboarding may strain small IT teams | Multiple independent sources warn that Year 1 spend can land 30-50% above the quoted licence cost | SMEs should budget conservatively given the well-documented pattern of Year 1 cost overrun relative to the initial quote.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:43","evidence:netskope:45"]},{"id":"evaluations:52d2cdd2c55a394ad9948428","evaluation_type":"summary","finding":"Biggest operational concern | The documented pattern of Year 1 cost escalation (30-50% above the quoted licence cost) combined with the CASB API per-app-seat multiplication risk creates real potential for budget surprises if procurement scopes only the headline per-user quote. | Table 16, 19 | Medium | Netify should proactively flag this to buyers during the shortlist conversation, mirroring the same proactive flagging recommended for Zscaler's equivalent risk.","buyer_implication":"Netify should proactively flag this to buyers during the shortlist conversation, mirroring the same proactive flagging recommended for Zscaler's equivalent risk.","qualification":"The documented pattern of Year 1 cost escalation (30-50% above the quoted licence cost) combined with the CASB API per-app-seat multiplication risk creates real potential for budget surprises if procurement scopes only the headline per-user quote. | Table 16, 19 | Medium | Netify should proactively flag this to buyers during the shortlist conversation, mirroring the same proactive flagging recommended for Zscaler's equivalent risk.","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:57e41173f7f8fb394b94bf47","evaluation_type":"summary","finding":"Scope & Boundaries | Genuinely broad SaaS/GenAI app coverage (85,000+ apps in the Cloud Confidence Index) and a real, integrated SD-WAN story via Borderless SD-WAN - a stronger combined security+network story than Zscaler's currently is. | Younger as a public company (IPO September 2025) than Cato or Zscaler as an operating entity in its current form, which is worth factoring into long-term roadmap and pricing-stability considerations, though not itself a product limitation.","buyer_implication":null,"qualification":"Genuinely broad SaaS/GenAI app coverage (85,000+ apps in the Cloud Confidence Index) and a real, integrated SD-WAN story via Borderless SD-WAN - a stronger combined security+network story than Zscaler's currently is. | Younger as a public company (IPO September 2025) than Cato or Zscaler as an operating entity in its current form, which is worth factoring into long-term roadmap and pricing-stability considerations, though not itself a product limitation.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:5e383577e374446ec826e13b","evaluation_type":"summary","finding":"VPN to ZTNA migration | Evidenced via CARE Ratings, which deployed Netskope Private Access (NPA) specifically as their ZTNA solution for hybrid IT environments, with fine-tuned Zero Trust access policies | Existing VPN/remote-access infrastructure retired or supplemented | IT team | Netskope Professional Services (partner-delivered per the case study) | 'System went live within the expected timeframe' (CARE Ratings case study, no specific duration given) | Not itemised | Not detailed | Real evidence exists, though the CARE Ratings timeline is less specific than MERW's precise six-week figure.","buyer_implication":null,"qualification":"Evidenced via CARE Ratings, which deployed Netskope Private Access (NPA) specifically as their ZTNA solution for hybrid IT environments, with fine-tuned Zero Trust access policies | Existing VPN/remote-access infrastructure retired or supplemented | IT team | Netskope Professional Services (partner-delivered per the case study) | 'System went live within the expected timeframe' (CARE Ratings case study, no specific duration given) | Not itemised | Not detailed | Real evidence exists, though the CARE Ratings timeline is less specific than MERW's precise six-week figure.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:5fc2c69d26fc81162bd21df9","evaluation_type":"summary","finding":"Merger/acquisition integration | Not documented via a named M&A-specific scenario in sources reviewed | Not itemised | Not itemised | Not itemised | Not quantified | Not itemised | Not detailed | Evidence gap - no equivalent to Zscaler's specific, dated SPLX acquisition integration example was found for Netskope.","buyer_implication":null,"qualification":"Not documented via a named M&A-specific scenario in sources reviewed | Not itemised | Not itemised | Not itemised | Not quantified | Not itemised | Not detailed | Evidence gap - no equivalent to Zscaler's specific, dated SPLX acquisition integration example was found for Netskope.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:6005c4c5692698c56c1a913b","evaluation_type":"summary","finding":"Where does it stand out? (mandatory) | The deepest, most original CASB/DLP technology heritage of the three vendors profiled (Train Your Own Classifiers ML-based DLP, an 85,000+ app Cloud Confidence Index); the most comprehensively primary-sourced compliance certification breadth in one place; and named, GA AI Copilot products plus a genuinely current MCP server integration. | Tables 3, 11, 13, 19 | High | These are the claims Netify can make most confidently and specifically to buyers, each backed by named, dated, primary-sourced evidence.","buyer_implication":"These are the claims Netify can make most confidently and specifically to buyers, each backed by named, dated, primary-sourced evidence.","qualification":"The deepest, most original CASB/DLP technology heritage of the three vendors profiled (Train Your Own Classifiers ML-based DLP, an 85,000+ app Cloud Confidence Index); the most comprehensively primary-sourced compliance certification breadth in one place; and named, GA AI Copilot products plus a genuinely current MCP server integration. | Tables 3, 11, 13, 19 | High | These are the claims Netify can make most confidently and specifically to buyers, each backed by named, dated, primary-sourced evidence.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:61cce937ffa6c8a7913c9e60","evaluation_type":"summary","finding":"Procurement watch-out | Independent pricing/deployment analyses describe onboarding as requiring 'dedicated resources' and Professional Services investment of $150,000-$225,000 in Year 1, in some tension with named case studies describing smooth, fast deployments (MERW's six weeks) | Buyers should budget for meaningful PS involvement even while taking the positive case-study evidence at face value - the two perspectives likely both hold true depending on deployment complexity | Relevant to all buyer sizes, especially lean IT teams | Table 9, 16 findings | Medium | A genuinely useful, nuanced finding - Netify should present both the positive case-study evidence and the more critical third-party cost/friction evidence rather than picking one narrative.","buyer_implication":"Buyers should budget for meaningful PS involvement even while taking the positive case-study evidence at face value - the two perspectives likely both hold true depending on deployment complexity","qualification":"Independent pricing/deployment analyses describe onboarding as requiring 'dedicated resources' and Professional Services investment of $150,000-$225,000 in Year 1, in some tension with named case studies describing smooth, fast deployments (MERW's six weeks) | Buyers should budget for meaningful PS involvement even while taking the positive case-study evidence at face value - the two perspectives likely both hold true depending on deployment complexity | Relevant to all buyer sizes, especially lean IT teams | Table 9, 16 findings | Medium | A genuinely useful, nuanced finding - Netify should present both the positive case-study evidence and the more critical third-party cost/friction evidence rather than picking one narrative.","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:67abe9069951449c342499be","evaluation_type":"summary","finding":"Global fit | Architecturally global by design (67 regions), with a strong peering story, but named-country detail is thinner than either Cato's (China-specific) or Zscaler's (Middle East-specific) equivalent evidence. | Table 7 | Medium | Always verify buyer-specific country coverage directly rather than relying on the general '67 regions' claim.","buyer_implication":"Always verify buyer-specific country coverage directly rather than relying on the general '67 regions' claim.","qualification":"Architecturally global by design (67 regions), with a strong peering story, but named-country detail is thinner than either Cato's (China-specific) or Zscaler's (Middle East-specific) equivalent evidence. | Table 7 | Medium | Always verify buyer-specific country coverage directly rather than relying on the general '67 regions' claim.","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:700529eba0a3571b4c6d8bc8","evaluation_type":"summary","finding":"Global multinational | Conditional fit | 67-region NewEdge network architecturally supports this, but named-country coverage detail is thin outside general claims | Needs Netify/buyer to verify specific-country NewEdge coverage directly | Custom enterprise pricing | Table 7 findings | Same caution applied to the other two vendors - verify buyer-specific country coverage rather than relying on the general '67 regions' claim.","buyer_implication":null,"qualification":"Conditional fit | 67-region NewEdge network architecturally supports this, but named-country coverage detail is thin outside general claims | Needs Netify/buyer to verify specific-country NewEdge coverage directly | Custom enterprise pricing | Table 7 findings | Same caution applied to the other two vendors - verify buyer-specific country coverage rather than relying on the general '67 regions' claim.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:7184f7a060fcb4884cb023f3","evaluation_type":"summary","finding":"Highly distributed branch estate | Conditional fit | Borderless SD-WAN is architecturally real and more mature than Zscaler's equivalent, but lacks a large-scale, metric-rich branch-rollout case study comparable to Cato's Ulta Beauty story | Zero-touch provisioning not explicitly confirmed with the same specificity as Cato's documentation | Site-based licensing implications not itemised | Table 4, 6, 9 findings | The architecture is genuinely more SD-WAN-mature than Zscaler's, but the evidence base for large-scale branch rollout is thinner than Cato's - a nuanced, specific finding worth stating precisely.","buyer_implication":null,"qualification":"Conditional fit | Borderless SD-WAN is architecturally real and more mature than Zscaler's equivalent, but lacks a large-scale, metric-rich branch-rollout case study comparable to Cato's Ulta Beauty story | Zero-touch provisioning not explicitly confirmed with the same specificity as Cato's documentation | Site-based licensing implications not itemised | Table 4, 6, 9 findings | The architecture is genuinely more SD-WAN-mature than Zscaler's, but the evidence base for large-scale branch rollout is thinner than Cato's - a nuanced, specific finding worth stating precisely.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:7b0fc51e07495d534504c576","evaluation_type":"summary","finding":"Global branch rollout | Borderless SD-WAN and SASE Gateways are architecturally real, but no large-scale, metric-rich branch-rollout case study (comparable to Cato's Ulta Beauty story) was found in this pass | Existing branch network/WAN infrastructure to integrate or replace | Not itemised | Not itemised | Not quantified | Unproven at Cato-Ulta-Beauty scale in the evidence available | Not detailed | The same specific gap flagged for Zscaler applies here too - this is genuinely the weakest evidence area for both Zscaler and Netskope relative to Cato's branch-rollout proof point.","buyer_implication":null,"qualification":"Borderless SD-WAN and SASE Gateways are architecturally real, but no large-scale, metric-rich branch-rollout case study (comparable to Cato's Ulta Beauty story) was found in this pass | Existing branch network/WAN infrastructure to integrate or replace | Not itemised | Not itemised | Not quantified | Unproven at Cato-Ulta-Beauty scale in the evidence available | Not detailed | The same specific gap flagged for Zscaler applies here too - this is genuinely the weakest evidence area for both Zscaler and Netskope relative to Cato's branch-rollout proof point.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:9401a3c1eacefaa449d2553d","evaluation_type":"summary","finding":"Co-managed transition | Partially evidenced via CARE Ratings' partner-led deployment model with Netskope Professional Services providing guidance | Not itemised in detail | Not itemised | Netskope Professional Services + partner | Not quantified | Not itemised | Not detailed | Real but thinly evidenced - a single case study rather than a formalised, named co-managed programme.","buyer_implication":null,"qualification":"Partially evidenced via CARE Ratings' partner-led deployment model with Netskope Professional Services providing guidance | Not itemised in detail | Not itemised | Netskope Professional Services + partner | Not quantified | Not itemised | Not detailed | Real but thinly evidenced - a single case study rather than a formalised, named co-managed programme.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:a7df2ba793e9eff73702ea84","evaluation_type":"summary","finding":"Cloud-first organisation | Good fit | Multi-cloud on-ramps (AWS, Azure, GCP) all confirmed via named cloud WAN integrations | None significant identified | Potential cost avoidance vs ExpressRoute/Direct Connect, similar to Cato's equivalent argument | Table 7 findings | Solid, evidenced by specific named hyperscaler integrations rather than platform-page claims alone.","buyer_implication":null,"qualification":"Good fit | Multi-cloud on-ramps (AWS, Azure, GCP) all confirmed via named cloud WAN integrations | None significant identified | Potential cost avoidance vs ExpressRoute/Direct Connect, similar to Cato's equivalent argument | Table 7 findings | Solid, evidenced by specific named hyperscaler integrations rather than platform-page claims alone.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:aafc5360baca553e26b701ee","evaluation_type":"summary","finding":"Reporting reality | Strong specifically around security-event visibility (Skope IT dashboards) and SaaS/GenAI app risk (Cloud Confidence Index); weaker or unconfirmed on application-performance/DEM reporting, which requires an add-on and has thinner primary-source evidence than Zscaler's ZDX. | Table 10 | Medium | Present the CCI/Skope IT strength specifically rather than imply comprehensive reporting maturity across the board.","buyer_implication":"Present the CCI/Skope IT strength specifically rather than imply comprehensive reporting maturity across the board.","qualification":"Strong specifically around security-event visibility (Skope IT dashboards) and SaaS/GenAI app risk (Cloud Confidence Index); weaker or unconfirmed on application-performance/DEM reporting, which requires an add-on and has thinner primary-source evidence than Zscaler's ZDX. | Table 10 | Medium | Present the CCI/Skope IT strength specifically rather than imply comprehensive reporting maturity across the board.","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:ad712cb31a55a22212e9d4c4","evaluation_type":"summary","finding":"Mid-market | Good fit | CARE Ratings (credit rating agency) and MinterEllisonRuddWatts (law firm) both suggest mid-sized organisations are a real, served segment | Professional Services engagement appears typical even at this scale per case study evidence | Business-tier pricing likely applies; PS costs should be budgeted explicitly | Reasonably well evidenced by two named, detailed mid-market case studies.","buyer_implication":null,"qualification":"Good fit | CARE Ratings (credit rating agency) and MinterEllisonRuddWatts (law firm) both suggest mid-sized organisations are a real, served segment | Professional Services engagement appears typical even at this scale per case study evidence | Business-tier pricing likely applies; PS costs should be budgeted explicitly | Reasonably well evidenced by two named, detailed mid-market case studies.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:30","evidence:netskope:32"]},{"id":"evaluations:b2d356be77311a07adc0ecbf","evaluation_type":"summary","finding":"Lean IT team | Conditional fit | Case studies show smooth deployments with PS support, but independent pricing/deployment analyses describe onboarding as requiring 'dedicated resources' - a genuine tension worth surfacing | PS engagement appears more consistently required than for Cato or Zscaler's equivalent claims | PS costs ($150K-225K per third-party analysis) should be budgeted explicitly for lean teams | Table 9 findings | This is the clearest 'lean IT team' caution across all three vendors profiled - the evidence genuinely points to more PS dependency than Cato or Zscaler's equivalent claims suggested.","buyer_implication":null,"qualification":"Conditional fit | Case studies show smooth deployments with PS support, but independent pricing/deployment analyses describe onboarding as requiring 'dedicated resources' - a genuine tension worth surfacing | PS engagement appears more consistently required than for Cato or Zscaler's equivalent claims | PS costs ($150K-225K per third-party analysis) should be budgeted explicitly for lean teams | Table 9 findings | This is the clearest 'lean IT team' caution across all three vendors profiled - the evidence genuinely points to more PS dependency than Cato or Zscaler's equivalent claims suggested.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:b3de7232e34867ad770b1fcc","evaluation_type":"summary","finding":"Limitation | No owned private backbone - NewEdge is a peering/interconnect-based network, architecturally between Cato's owned backbone and Zscaler's pure internet-peering model | Buyers wanting Cato-style predictable, SLA-backed middle-mile performance should weigh this directly rather than assume parity from the '67 regions' marketing claim | Affects distributed multi-site buyers most | Table 7 findings | High | A genuine, specific architectural fact worth stating plainly, consistent with the standard applied to both other vendors in this comparison set.","buyer_implication":"Buyers wanting Cato-style predictable, SLA-backed middle-mile performance should weigh this directly rather than assume parity from the '67 regions' marketing claim","qualification":"No owned private backbone - NewEdge is a peering/interconnect-based network, architecturally between Cato's owned backbone and Zscaler's pure internet-peering model | Buyers wanting Cato-style predictable, SLA-backed middle-mile performance should weigh this directly rather than assume parity from the '67 regions' marketing claim | Affects distributed multi-site buyers most | Table 7 findings | High | A genuine, specific architectural fact worth stating plainly, consistent with the standard applied to both other vendors in this comparison set.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:b9f709e43dc69e6497e93d92","evaluation_type":"summary","finding":"Strength | The most comprehensively primary-sourced compliance certification set across all three vendors profiled - FedRAMP High, PCI DSS v4.0.1, HIPAA assessed, DORA and Cyber Essentials all explicitly named on one compliance page | Regulated buyers get an unusually easy, self-service way to verify compliance breadth before engaging sales | Best: regulated multinational buyers needing to cheque many frameworks quickly. Less relevant: buyers with no regulatory compliance requirement | High | The single compliance-centre source doing this much work is itself a good sign of compliance-programme maturity - genuinely differentiated.","buyer_implication":"Regulated buyers get an unusually easy, self-service way to verify compliance breadth before engaging sales","qualification":"The most comprehensively primary-sourced compliance certification set across all three vendors profiled - FedRAMP High, PCI DSS v4.0.1, HIPAA assessed, DORA and Cyber Essentials all explicitly named on one compliance page | Regulated buyers get an unusually easy, self-service way to verify compliance breadth before engaging sales | Best: regulated multinational buyers needing to cheque many frameworks quickly. Less relevant: buyers with no regulatory compliance requirement | High | The single compliance-centre source doing this much work is itself a good sign of compliance-programme maturity - genuinely differentiated.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:15"]},{"id":"evaluations:bd03fb92128b6b480cd08476","evaluation_type":"summary","finding":"When would Netify recommend it? (mandatory) | When a buyer's primary risk is SaaS/GenAI data protection and shadow-IT visibility specifically; when a buyer needs to verify broad regulatory compliance quickly and self-serve across many frameworks; or when a buyer wants a more mature converged SD-WAN-plus-SSE story than Zscaler currently offers, without requiring Cato's owned-backbone architecture. | Synthesis of Tables 3, 13, 15 | High | A clear, actionable recommendation trigger set for Netify's comparison tool to apply directly.","buyer_implication":"A clear, actionable recommendation trigger set for Netify's comparison tool to apply directly.","qualification":"When a buyer's primary risk is SaaS/GenAI data protection and shadow-IT visibility specifically; when a buyer needs to verify broad regulatory compliance quickly and self-serve across many frameworks; or when a buyer wants a more mature converged SD-WAN-plus-SSE story than Zscaler currently offers, without requiring Cato's owned-backbone architecture. | Synthesis of Tables 3, 13, 15 | High | A clear, actionable recommendation trigger set for Netify's comparison tool to apply directly.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:c2e6ec2439ed4208633292d1","evaluation_type":"summary","finding":"Where does it fall behind competitors? (mandatory) | No owned private backbone (same architectural gap as Zscaler, though Netskope's peering investment via NewEdge is more extensive); materially weaker formal support-tier and MDR/SOC evidence than Zscaler; no large-scale, metric-rich branch-rollout case study comparable to Cato's Ulta Beauty story; and a specific, well-documented pattern of Year 1 cost escalation above the initial quote. | Tables 7, 8, 16, 17 | Medium-High | Named specifically and evidenced, not a generic hedge - Netify can state these with real confidence.","buyer_implication":"Named specifically and evidenced, not a generic hedge - Netify can state these with real confidence.","qualification":"No owned private backbone (same architectural gap as Zscaler, though Netskope's peering investment via NewEdge is more extensive); materially weaker formal support-tier and MDR/SOC evidence than Zscaler; no large-scale, metric-rich branch-rollout case study comparable to Cato's Ulta Beauty story; and a specific, well-documented pattern of Year 1 cost escalation above the initial quote. | Tables 7, 8, 16, 17 | Medium-High | Named specifically and evidenced, not a generic hedge - Netify can state these with real confidence.","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:c5be023925e752ccb878fa06","evaluation_type":"summary","finding":"Limitation | Weaker primary-source evidence for formal, named support-tier SLAs (comparable to Zscaler's detailed data sheets) and for MDR/SOC-equivalent managed security services | Buyers who need contractually-specific support SLAs or a named MDR service should confirm these directly rather than assume parity with Zscaler's documented offering | Affects buyers with strict support-SLA or managed-detection requirements | Table 8 findings | Medium | A genuine, specific gap relative to Zscaler's much more thoroughly documented support-tier and MDR evidence - worth a direct follow-up question.","buyer_implication":"Buyers who need contractually-specific support SLAs or a named MDR service should confirm these directly rather than assume parity with Zscaler's documented offering","qualification":"Weaker primary-source evidence for formal, named support-tier SLAs (comparable to Zscaler's detailed data sheets) and for MDR/SOC-equivalent managed security services | Buyers who need contractually-specific support SLAs or a named MDR service should confirm these directly rather than assume parity with Zscaler's documented offering | Affects buyers with strict support-SLA or managed-detection requirements | Table 8 findings | Medium | A genuine, specific gap relative to Zscaler's much more thoroughly documented support-tier and MDR evidence - worth a direct follow-up question.","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:cd57971b8eb4662cc1b37c62","evaluation_type":"summary","finding":"What implementation challenges should buyers expect? (mandatory) | Expect genuine tier-to-feature mapping work before committing, since CASB API, UEBA, DSPM and DEM all sit outside the base bundle and CASB API specifically carries a per-app-seat multiplication risk. Expect Professional Services involvement to be typical rather than optional for anything beyond the simplest deployment, budgeted at $150,000-$225,000 in Year 1 per third-party analysis. Expect a real (if nuanced) tension between smooth, fast named-customer deployments and more critical third-party commentary on onboarding friction - both are probably true depending on deployment complexity. | Tables 3, 9, 16 | Medium-High | Each expectation is traceable to a specific, evidenced finding elsewhere in this profile.","buyer_implication":"Each expectation is traceable to a specific, evidenced finding elsewhere in this profile.","qualification":"Expect genuine tier-to-feature mapping work before committing, since CASB API, UEBA, DSPM and DEM all sit outside the base bundle and CASB API specifically carries a per-app-seat multiplication risk. Expect Professional Services involvement to be typical rather than optional for anything beyond the simplest deployment, budgeted at $150,000-$225,000 in Year 1 per third-party analysis. Expect a real (if nuanced) tension between smooth, fast named-customer deployments and more critical third-party commentary on onboarding friction - both are probably true depending on deployment complexity. | Tables 3, 9, 16 | Medium-High | Each expectation is traceable to a specific, evidenced finding elsewhere in this profile.","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:cf95a66d7245e57ae96ca3aa","evaluation_type":"summary","finding":"Multi-vendor SASE integration | Netskope's Cloud Exchange framework, with GitHub-published plugins for CrowdStrike, Okta and other risk-engine products, is explicitly designed to let customers integrate Netskope as one component of a broader, potentially multi-vendor security stack | IdP and EDR/risk-engine products already in place | Not itemised | GitHub-published plugins, developer's guide, and formal solution guides (e.g. the CrowdStrike Solution Guide) | Not quantified | N/A | N/A | Genuinely well-suited to this scenario, similar to Zscaler's positioning and the reverse of Cato's single-vendor-consolidation pitch - worth stating plainly given how well-documented the Cloud Exchange framework is.","buyer_implication":null,"qualification":"Netskope's Cloud Exchange framework, with GitHub-published plugins for CrowdStrike, Okta and other risk-engine products, is explicitly designed to let customers integrate Netskope as one component of a broader, potentially multi-vendor security stack | IdP and EDR/risk-engine products already in place | Not itemised | GitHub-published plugins, developer's guide, and formal solution guides (e.g. the CrowdStrike Solution Guide) | Not quantified | N/A | N/A | Genuinely well-suited to this scenario, similar to Zscaler's positioning and the reverse of Cato's single-vendor-consolidation pitch - worth stating plainly given how well-documented the Cloud Exchange framework is.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:d097ac25caad340d4a2a4457","evaluation_type":"summary","finding":"Limitation | Modular licensing with a documented pattern of Year 1 spend landing 30-50% above the quoted licence cost, and a specific per-app-seat multiplication effect for CASB API that can produce a materially larger-than-expected bill | Buyers risk under-budgeting significantly if they scope only the headline per-user quote | Affects all buyer sizes, with the CASB API multiplication effect hitting SaaS-heavy buyers hardest | Table 16 findings | Medium (convergent across independent third-party sources, with one competitor-published source cross-checked rather than relied on alone) | This is a more specific, better-documented cost-escalation risk than either Cato's or Zscaler's equivalent findings - worth flagging prominently and early in any Netskope procurement conversation.","buyer_implication":"Buyers risk under-budgeting significantly if they scope only the headline per-user quote","qualification":"Modular licensing with a documented pattern of Year 1 spend landing 30-50% above the quoted licence cost, and a specific per-app-seat multiplication effect for CASB API that can produce a materially larger-than-expected bill | Buyers risk under-budgeting significantly if they scope only the headline per-user quote | Affects all buyer sizes, with the CASB API multiplication effect hitting SaaS-heavy buyers hardest | Table 16 findings | Medium (convergent across independent third-party sources, with one competitor-published source cross-checked rather than relied on alone) | This is a more specific, better-documented cost-escalation risk than either Cato's or Zscaler's equivalent findings - worth flagging prominently and early in any Netskope procurement conversation.","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:d104462a2c95dd81ebaf1374","evaluation_type":"summary","finding":"Strength | Genuinely deep, original CASB/DLP heritage - Train Your Own Classifiers ML-based DLP and a Cloud Confidence Index covering 85,000+ SaaS/GenAI apps | Buyers whose primary risk is SaaS/GenAI data exfiltration get the most mature, purpose-built data-protection stack of the three vendors profiled | Best: data-centric enterprises, regulated industries with heavy SaaS estates. Less relevant: buyers whose primary need is network/branch consolidation | High | This is Netskope's clearest, most defensible differentiator - genuinely original technology, not a bolted-on feature.","buyer_implication":"Buyers whose primary risk is SaaS/GenAI data exfiltration get the most mature, purpose-built data-protection stack of the three vendors profiled","qualification":"Genuinely deep, original CASB/DLP heritage - Train Your Own Classifiers ML-based DLP and a Cloud Confidence Index covering 85,000+ SaaS/GenAI apps | Buyers whose primary risk is SaaS/GenAI data exfiltration get the most mature, purpose-built data-protection stack of the three vendors profiled | Best: data-centric enterprises, regulated industries with heavy SaaS estates. Less relevant: buyers whose primary need is network/branch consolidation | High | This is Netskope's clearest, most defensible differentiator - genuinely original technology, not a bolted-on feature.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:21","evidence:netskope:27"]},{"id":"evaluations:d5f4eb1bb297a006d528347b","evaluation_type":"summary","finding":"Commercials | Entry-tier SSE bundle pricing is described by multiple independent sources as competitive with or below Zscaler's combined ZIA+ZPA range at the base tier. | No public list pricing; several independent analyses (not all equally reliable - one is published by a direct competitor) describe significant module creep and Year 1 spend landing 30-50% above the quoted licence cost once professional services, DLP tuning, and add-ons are included.","buyer_implication":null,"qualification":"Entry-tier SSE bundle pricing is described by multiple independent sources as competitive with or below Zscaler's combined ZIA+ZPA range at the base tier. | No public list pricing; several independent analyses (not all equally reliable - one is published by a direct competitor) describe significant module creep and Year 1 spend landing 30-50% above the quoted licence cost once professional services, DLP tuning, and add-ons are included.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:d764939060ef35e9830905e5","evaluation_type":"summary","finding":"Deployment & Ops | A genuinely converged SASE architecture - Borderless SD-WAN and SSE share one policy framework, one NewEdge network, and (where desired) one agent, rather than stitched-together consoles. | Multiple independent pricing/deployment analyses describe onboarding friction, professional-services costs in the $150K-225K range for Year 1, and a UI/console experience some third-party commentary describes as less streamlined than competitors - treat the latter with caution given the source quality, but the professional-services cost pattern recurs across sources.","buyer_implication":null,"qualification":"A genuinely converged SASE architecture - Borderless SD-WAN and SSE share one policy framework, one NewEdge network, and (where desired) one agent, rather than stitched-together consoles. | Multiple independent pricing/deployment analyses describe onboarding friction, professional-services costs in the $150K-225K range for Year 1, and a UI/console experience some third-party commentary describes as less streamlined than competitors - treat the latter with caution given the source quality, but the professional-services cost pattern recurs across sources.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:d8999ef5b2b0aad678aa9146","evaluation_type":"summary","finding":"MPLS to SD-WAN migration | Not evidenced via a named case study specifically describing MPLS retirement; NewEdge documentation describes coexistence with existing SD-WAN via IPsec/GRE tunnels, implying a gradual-migration capability similar in spirit to Cato's | Existing MPLS/SD-WAN infrastructure, integrated via tunnels rather than replaced outright per the NewEdge documentation | Not itemised | Not itemised | Not quantified | Not itemised | Not detailed | The coexistence capability is architecturally confirmed, but - unlike Cato's Baker & Baker-style case study or Zscaler's equivalent - no named customer scenario specifically walks through an MPLS migration for Netskope in this pass.","buyer_implication":null,"qualification":"Not evidenced via a named case study specifically describing MPLS retirement; NewEdge documentation describes coexistence with existing SD-WAN via IPsec/GRE tunnels, implying a gradual-migration capability similar in spirit to Cato's | Existing MPLS/SD-WAN infrastructure, integrated via tunnels rather than replaced outright per the NewEdge documentation | Not itemised | Not itemised | Not quantified | Not itemised | Not detailed | The coexistence capability is architecturally confirmed, but - unlike Cato's Baker & Baker-style case study or Zscaler's equivalent - no named customer scenario specifically walks through an MPLS migration for Netskope in this pass.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:da02c658f2cdce5bcf542c95","evaluation_type":"summary","finding":"Commercial reality | No public pricing; independent third-party analyses (including one competitor-published, cross-checked source) converge reasonably on a base SSE tier around $4-8/user/month rising to $15+/user/month fully bundled, with a specific and well-documented Year 1 cost-escalation pattern. | Table 16 | Medium (convergent third-party sourcing, one source competitor-published and treated with extra caution) | Use as a rough planning signal, always routing to a direct Netskope quote for real numbers, and flag the cost-escalation pattern proactively given how consistently it recurs across sources.","buyer_implication":"Use as a rough planning signal, always routing to a direct Netskope quote for real numbers, and flag the cost-escalation pattern proactively given how consistently it recurs across sources.","qualification":"No public pricing; independent third-party analyses (including one competitor-published, cross-checked source) converge reasonably on a base SSE tier around $4-8/user/month rising to $15+/user/month fully bundled, with a specific and well-documented Year 1 cost-escalation pattern. | Table 16 | Medium (convergent third-party sourcing, one source competitor-published and treated with extra caution) | Use as a rough planning signal, always routing to a direct Netskope quote for real numbers, and flag the cost-escalation pattern proactively given how consistently it recurs across sources.","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:e965afaa6f7d6c6761fa60ee","evaluation_type":"summary","finding":"Strength | Named AI Copilots (Copilot for Private Access, Copilot for CCI) are confirmed GA products, plus a specific, current MCP server enabling Claude Desktop, Microsoft Copilot and Amazon Bedrock to interact with the platform | Buyers evaluating AI-maturity claims get concrete, dated, named products rather than roadmap language | Best: organisations actively building AI-driven security operations. Less relevant: buyers with no near-term AI-tooling interest | Medium-High | Genuinely ahead of both Cato and Zscaler on named, GA AI-assistant products specifically, though sourced via a reporting outlet rather than Netskope's own press release directly in this pass.","buyer_implication":"Buyers evaluating AI-maturity claims get concrete, dated, named products rather than roadmap language","qualification":"Named AI Copilots (Copilot for Private Access, Copilot for CCI) are confirmed GA products, plus a specific, current MCP server enabling Claude Desktop, Microsoft Copilot and Amazon Bedrock to interact with the platform | Buyers evaluating AI-maturity claims get concrete, dated, named products rather than roadmap language | Best: organisations actively building AI-driven security operations. Less relevant: buyers with no near-term AI-tooling interest | Medium-High | Genuinely ahead of both Cato and Zscaler on named, GA AI-assistant products specifically, though sourced via a reporting outlet rather than Netskope's own press release directly in this pass.","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:netskope:28"]},{"id":"evaluations:f056cfcae4c013c558651a4e","evaluation_type":"summary","finding":"Most credible differentiator | The combination of original, deep CASB/DLP technology with the most comprehensively primary-sourced compliance certification breadth of the three vendors profiled - very few competitors can match both simultaneously. | Tables 3, 13 | High | This is the single sentence Netify's comparison engine could most confidently quote for Netskope specifically.","buyer_implication":"This is the single sentence Netify's comparison engine could most confidently quote for Netskope specifically.","qualification":"The combination of original, deep CASB/DLP technology with the most comprehensively primary-sourced compliance certification breadth of the three vendors profiled - very few competitors can match both simultaneously. | Tables 3, 13 | High | This is the single sentence Netify's comparison engine could most confidently quote for Netskope specifically.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:f58fddba4d8c8d151ad2e70c","evaluation_type":"summary","finding":"Mature NetOps/SecOps team | Good fit | Deep, technical SIEM/EDR integrations (CrowdStrike Solution Guide, Splunk App, Sentinel, Cribl) support a best-of-breed toolchain approach | Mature teams should find the Cloud Exchange framework's GitHub-published plugins and developer's guide genuinely accommodating | Not assessed | Table 12 findings | The Cloud Exchange framework's openness (GitHub plugins, developer's guide) is a genuine strength for technically mature teams wanting to build custom integrations rather than wait for a vendor roadmap.","buyer_implication":null,"qualification":"Good fit | Deep, technical SIEM/EDR integrations (CrowdStrike Solution Guide, Splunk App, Sentinel, Cribl) support a best-of-breed toolchain approach | Mature teams should find the Cloud Exchange framework's GitHub-published plugins and developer's guide genuinely accommodating | Not assessed | Table 12 findings | The Cloud Exchange framework's openness (GitHub plugins, developer's guide) is a genuine strength for technically mature teams wanting to build custom integrations rather than wait for a vendor roadmap.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:f898f29b42152f5c6ee234f2","evaluation_type":"summary","finding":"Support/service reality | Less formally documented from primary sources than Zscaler's - Professional Services involvement is well evidenced via case studies, but named, tiered support SLAs comparable to Zscaler's public data sheets weren't found. | Table 8 | Medium | Flag internally as a priority follow-up source to strengthen before this profile supports a support-SLA-sensitive procurement decision.","buyer_implication":"Flag internally as a priority follow-up source to strengthen before this profile supports a support-SLA-sensitive procurement decision.","qualification":"Less formally documented from primary sources than Zscaler's - Professional Services involvement is well evidenced via case studies, but named, tiered support SLAs comparable to Zscaler's public data sheets weren't found. | Table 8 | Medium | Flag internally as a priority follow-up source to strengthen before this profile supports a support-SLA-sensitive procurement decision.","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]}],"evidence_sources":[{"id":"evidence:netskope:25","url":"https://netskope.com/blog/10-thought-provoking-questions-to-contemplate-genai-data-security","title":"Netskope - 10 Thought-provoking Questions to Contemplate GenAI Data Security (blog)","publisher":"","publication_date":"2025-04-27T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:netskope:6","url":"https://netskope.com/blog/borderless-sd-wan-ushering-in-the-new-era-of-borderless-enterprise","title":"Netskope - Borderless SD-WAN: Ushering in the New Era of Borderless Enterprise","publisher":"","publication_date":"2023-07-31T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:netskope:30","url":"https://netskope.com/customers/care-ratings-case-study","title":"Netskope - Customer Story: CARE Ratings","publisher":"","publication_date":"2025-03-06T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:netskope:31","url":"https://netskope.com/customers/jll-case-study","title":"Netskope - Customer Story: JLL","publisher":"","publication_date":"2025-01-26T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:netskope:32","url":"https://netskope.com/customers/merw-case-study","title":"Netskope - Customer Story: MinterEllisonRuddWatts (MERW)","publisher":"","publication_date":"2025-01-26T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:netskope:18","url":"https://netskope.com/resources/compliance-guides/iso-iec-270012022-annex-a-control-mapping-to-netskope-products","title":"Netskope - ISO/IEC 27001:2022 Annex A Control Mapping to Netskope Products","publisher":"","publication_date":"2024-08-20T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:netskope:5","url":"https://netskope.com/blog/introducing-netskope-borderless-sd-wan","title":"Netskope - Introducing Netskope Borderless SD-WAN","publisher":"","publication_date":"2025-07-01T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:netskope:20","url":"https://netskope.com/solutions/government-compliance","title":"Netskope - Netskope for the Public Sector (GovCloud, FedRAMP High)","publisher":"","publication_date":"2023-05-12T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:netskope:8","url":"https://netskope.com/netskope-one/newedge","title":"Netskope - NewEdge Network product page","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:netskope:12","url":"https://netskope.com/products/sase-branch","title":"Netskope - SASE Branch / Netskope One Secure SD-WAN product page","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:netskope:11","url":"https://netskope.com/products/secure-access-service-edge","title":"Netskope - Secure Access Service Edge (SASE) product page","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:netskope:24","url":"https://netskope.com/solutions/netskope-one-ai-security","title":"Netskope - Securing AI with Netskope One (AI Security solution page)","publisher":"","publication_date":"2023-05-24T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:netskope:21","url":"https://netskope.com/products/securing-generative-ai","title":"Netskope - Securing Generative AI with Netskope One","publisher":"","publication_date":"2026-03-11T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:netskope:17","url":"https://netskope.com/company/security-compliance-and-assurance","title":"Netskope - Security, Compliance and Assurance page","publisher":"","publication_date":"2025-08-26T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:netskope:29","url":"https://netskope.com/resources/solution-briefs/skopeai-for-chatgpt-and-generative-ai","title":"Netskope - SkopeAI for ChatGPT and Generative AI (solution brief)","publisher":"","publication_date":"2025-09-25T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:netskope:27","url":"https://netskope.com/products/skopeai","title":"Netskope - SkopeAI product page","publisher":"","publication_date":"2026-04-05T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:netskope:13","url":"https://netskope.com/solutions/compliance","title":"Netskope - Supporting Your Compliance overview page","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:netskope:38","url":"https://netskope.com/partners/technology-partners-integrations","title":"Netskope - Technology & Integrations partner directory","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:netskope:10","url":"https://netskope.com/blog/the-next-level-of-network-performance-with-netskope-sase-and-borderless-sd-wan","title":"Netskope - The Next Level of Network Performance with Netskope SASE and Borderless SD-WAN","publisher":"","publication_date":"2024-04-06T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:netskope:22","url":"https://netskope.com/security-defined/what-is-ai-security","title":"Netskope - What is AI Security?","publisher":"","publication_date":"2025-06-17T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:netskope:36","url":"https://netskope.com/blog/why-real-time-siem-integration-is-the-unsung-hero-of-zero-trust-security","title":"Netskope - Why Real-time SIEM Integration is the Unsung Hero of Zero Trust Security (blog)","publisher":"","publication_date":"2025-10-28T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:netskope:16","url":"https://prnewswire.com/news-releases/netskope-awarded-state-of-california-software-licensing-programme-contract-for-security-cloud-platform-300960709.html","title":"Netskope - press release (via PRNewswire): Awarded State of California Software Licensing Programme Contract","publisher":"","publication_date":"2019-11-19T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:netskope:14","url":"https://netskope.com/press-releases/netskope-achieves-iso-iec-270012013-iso-iec-270182014-certifications","title":"Netskope - press release: Achieves ISO/IEC 27001:2013 and ISO/IEC 27018:2014 Certifications","publisher":"","publication_date":"2018-02-28T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:netskope:23","url":"https://netskope.com/press-releases/netskope-introduces-skopeai-revolutionary-ai-driven-security-for-the-future-of-data-protection-and-cyber-threat-defence","title":"Netskope - press release: Introduces SkopeAI","publisher":"","publication_date":"2023-07-25T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:netskope:7","url":"https://netskope.com/press-releases/netskope-delivers-the-next-gen-sase-branch-powered-by-borderless-sd-wan","title":"Netskope - press release: Netskope Delivers the Next Gen SASE Branch, Powered by Borderless SD-WAN","publisher":"","publication_date":"2023-11-09T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:netskope:35","url":"https://docs.netskope.com/en/crowdstrike-solution-guide","title":"Netskope Knowledge Portal - CrowdStrike and Netskope Integration Solution Guide","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:netskope:34","url":"https://akamai.com/resources/customer-story/netskope","title":"Akamai - Netskope Customer Story (Akamai's own page, independent named company)","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_2","source_status":"current"},{"id":"evidence:netskope:28","url":"https://cybersecurityasia.net/netskope-expands-ai-powered-platform/","title":"Cybersecurity Asia - Netskope Expands AI-Powered Platform Capabilities, Introduces Copilot for Private Access (independent tech journalism)","publisher":"","publication_date":"2025-08-22T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_2","source_status":"current"},{"id":"evidence:netskope:15","url":"https://compliance.netskope.com","title":"Netskope Compliance Centre (powered by SafeBase, an independent trust-centre platform)","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_2","source_status":"current"},{"id":"evidence:netskope:33","url":"https://tenable.com/case-studies/netskope","title":"Tenable - Cloud Security Leader Netskope Trusts Tenable (Tenable's own customer-story page, independent named company)","publisher":"","publication_date":"2025-06-13T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_2","source_status":"current"},{"id":"evidence:netskope:2","url":"https://accessipos.com/netskope-ipo-stock/","title":"AccessIPOs - Netskope IPO Date, Price, Terms, and S-1 Filing","publisher":"","publication_date":"2026-05-12T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"src_financial_services_fin_337","url":"https://www.netskope.com/resources/case-studies/apex-group","title":"Apex Group Case Study | Netskope","publisher":"netskope.com","publication_date":null,"verified_date":"2026-09-12T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"src_financial_services_fin_348","url":"https://www.netskope.com/resources/case-studies/ascensus","title":"Ascensus Case Study | Netskope","publisher":"netskope.com","publication_date":null,"verified_date":"2026-09-12T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:netskope:4","url":"https://cbinsights.com/investor/netskope","title":"CB Insights - Netskope company profile","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"src_financial_services_fin_335","url":"https://www.netskope.com/privacy/compliance","title":"Compliance | Netskope","publisher":"netskope.com","publication_date":null,"verified_date":"2026-09-12T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:netskope:46","url":"https://costbench.com/software/sase/netskope/","title":"CostBench - Netskope Pricing 2026: Plans & Cost Guide (median contract data from 26 verified purchases)","publisher":"","publication_date":"2026-06-09T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"src_financial_services_fin_339","url":"https://www.netskope.com/privacy/data-transfer-at-netskope","title":"Data Transfer at Netskope | Netskope","publisher":"netskope.com","publication_date":null,"verified_date":"2026-09-12T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:netskope:39","url":"https://exclusive-networks.com/uk/wp-content/uploads/sites/28/2020/12/UK_VR_Netskope_Whitepaper_integrating-the-netskope-security-cloud-with-your-existing-security-infrastructure.pdf","title":"Exclusive Networks (Netskope distributor) - Integrating the Netskope Security Cloud with Your Existing Security Infrastructure (whitepaper)","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"src_financial_services_fin_509","url":"https://www.netskope.com/fr/blog/fortune-500-financial-services-company-meets-nydfs-cybersecurity-regulations-netskope-unisys","title":"Fortune 500 Financial Services Company Meets NYDFS Cybersecurity Regulations (Netskope + Unisys)","publisher":"netskope.com","publication_date":null,"verified_date":"2026-09-15T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"src_financial_services_fin_342","url":"https://www.netskope.com/solutions/glba-cloud-compliance","title":"GLBA Cloud Compliance | Netskope","publisher":"netskope.com","publication_date":null,"verified_date":"2026-09-12T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:netskope:42","url":"https://itqlick.com/netskope/pricing","title":"ITQlick - Netskope Pricing 2026: Hidden Costs & Total ROI","publisher":"","publication_date":"2026-02-04T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:netskope:26","url":"https://community.netskope.com/video-library-20/inside-netskope-20-securing-saas-and-genai-without-saying-no-8741","title":"Netskope Community - Inside Netskope 20: Securing SaaS and GenAI Without Saying 'No' (community Q&A, not official documentation)","publisher":"","publication_date":"2026-05-28T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"src_financial_services_fin_340","url":"https://compliance.netskope.com/","title":"Netskope Compliance Center","publisher":"compliance.netskope.com","publication_date":null,"verified_date":"2026-09-12T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"src_manufacturing_mfg_043","url":"https://www.netskope.com/solutions/manufacturing","title":"Netskope For Manufacturing","publisher":"netskope.com","publication_date":null,"verified_date":"2026-07-29T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"src_financial_services_fin_347","url":"https://www.netskope.com/netskope-technical-support","title":"Netskope Technical Support","publisher":"netskope.com","publication_date":null,"verified_date":"2026-09-12T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"src_financial_services_fin_508","url":"https://www.netskope.com/resources/compliance-guides/netskope-for-dora-compliance","title":"Netskope for DORA Compliance","publisher":"netskope.com","publication_date":null,"verified_date":"2026-09-15T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"src_financial_services_fin_336","url":"https://www.netskope.com/netskope-one/newedge","title":"NewEdge Network | Netskope","publisher":"netskope.com","publication_date":null,"verified_date":"2026-09-15T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:netskope:19","url":"https://security-profiles.nudgesecurity.com/app/netskope-com","title":"Nudge Security - Is Netskope Safe? (third-party security-review aggregator)","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:netskope:37","url":"https://optiv.com/insights/discover/blog/integrate-all-things-netskope-cloud-exchange","title":"Optiv (Netskope partner) - Integrate All the Things with Netskope Cloud Exchange","publisher":"","publication_date":"2023-04-17T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"src_financial_services_fin_341","url":"https://www.netskope.com/solutions/pci-dss-cloud-compliance","title":"PCI-DSS Cloud Compliance | Netskope","publisher":"netskope.com","publication_date":null,"verified_date":"2026-09-12T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:netskope:3","url":"https://pitchbook.com/profiles/company/59273-38","title":"PitchBook - Netskope 2026 Company Profile","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"src_financial_services_fin_338","url":"https://www.netskope.com/products/sase-branch","title":"Secure SD-WAN | Netskope One SASE Branch | Netskope","publisher":"netskope.com","publication_date":null,"verified_date":"2026-09-12T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"src_financial_services_fs_052","url":"https://www.netskope.com/solutions/financial-services-and-insurance","title":"Securing Financial Services in the Cloud and AI Era","publisher":"netskope.com","publication_date":null,"verified_date":"2026-07-29T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:netskope:9","url":"https://platform.softwareone.com/product/netskope-newedge-network/PCP-3832-0499","title":"SoftwareOne Marketplace - Netskope NewEdge Network listing (third-party reseller)","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"src_financial_services_fin_344","url":"https://www.netskope.com/resources/netskope-resources/netskope-sub-processors","title":"Sub-processors | Netskope","publisher":"netskope.com","publication_date":"2026-09-01T00:00:00.000Z","verified_date":"2026-09-12T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:netskope:1","url":"https://tracxn.com/d/companies/netskope/__GCP6Lcb3V3Dr2bGgxOfSQ_jd_BNFsKIRp6nWov_nbRo","title":"Tracxn - Netskope 2026 Company Profile","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:netskope:43","url":"https://underdefense.com/blog/netskope-pricing-guide","title":"UnderDefense - Netskope Pricing Guide 2026: Actual Costs, Hidden Fees & Negotiation Tactics","publisher":"","publication_date":"2026-06-16T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:netskope:44","url":"https://vendr.com/marketplace/netskope","title":"Vendr - Netskope Software Pricing & Plans 2026","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:netskope:45","url":"https://zerotrustcost.com/netskope-pricing","title":"ZeroTrustCost.com - Netskope Pricing 2026: SSE Bundles, Module Creep and Renewal Math","publisher":"","publication_date":"2026-06-14T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:netskope:41","url":"https://dope.security/post/netskope-pricing-2026","title":"dope.security (a direct Netskope competitor) - Netskope Pricing in 2026","publisher":"","publication_date":"2026-05-27T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"}]}