Overview
BT is not a single-platform SASE company, but the UK’s largest telecommunications operator and managed service provider, delivering SASE as one service line within a vastly larger, publicly-listed (LSE: BT.A) group.
BT’s SASE proposition is delivered under its own named managed-connectivity brand, Agile Connect, and is explicitly multi-platform rather than built on a single, proprietary technology stack: BT’s own materials and Netify’s own published research confirm managed SD-WAN delivered on Cisco Meraki and Versa, with managed SASE delivered on Fortinet and Meraki, reinforced by BT’s own Managed Detection and Response service.
BT’s core differentiator is not a proprietary SASE architecture but infrastructural depth: Openreach, BT’s wholly-owned but operationally separate access-network subsidiary (established 2006 under Ofcom/Enterprise Act 2002 undertakings), gives BT direct control over one of the deepest last-mile access estates in the UK market, combined with BT’s own international core network and long-established BT Security division.
Commercially, BT’s SASE offering is confirmed as quote-based with no published enterprise pricing, and buyers should confirm directly which specific underlying vendor platform (Fortinet, Meraki, or otherwise) is being proposed for their specific deployment, since BT’s own positioning is explicit that platform choice and packaging vary by customer.
Direct comparison
Put BT beside any provider.
Open the Netify comparison engine with both providers already selected. Every result is calculated from the public 40-capability evidence matrix.
No sign-in required. The shortlist remains shareable. Publishing and supplier access stay separate.
Find which providers match your exact needs
Move from a two-provider comparison into the live Netify RFP Builder and evaluate the wider market against your project.
Open the RFP BuilderAgent-accessible research
Ask the BT research record
Answers are calculated from the published record below. Missing evidence remains unconfirmed and every result identifies its source revision.
Record summary
- Current products
- 6
- Capabilities
- 67
- Coverage records
- 12
- Service models
- 34
- Compliance records
- 13
- Integration records
- 21
- Sector records
- 6
- Evaluation records
- 49
- Public sources
- 16
Products and delivery
6 records| Product | Category | Relationship | Delivery model | Target buyer |
|---|---|---|---|---|
| Agile Connect | Managed SD-WAN | Partner | Fully managed, with mixed connectivity options per site | All buyers |
| BT Managed Fortinet Firewall | Firewall as a Service | Native | Managed, edge-deployed with SSL decryption | Buyers wanting managed firewall alongside SD-WAN specifically |
| BT Managed SASE (Fortinet-based) | Converged SASE (SD-WAN + SSE) | Native | Cloud-delivered SSE layered on managed SD-WAN | Buyers wanting a full, current-generation SASE service |
| BT Managed SASE (Meraki-based) | Converged SASE (SD-WAN + SSE) | Native | Cloud-delivered SSE layered on managed SD-WAN | Buyers preferring Cisco/Meraki-based technology specifically |
| BT Security Managed Detection and Response | Managed security service | Native | Managed, 24x7 | Buyers wanting integrated threat detection/response alongside SASE |
| BT-managed VMware SASE (legacy/historical) | Converged SASE (SD-WAN + SSE) - historical | Native | Cloud-delivered, via a global network of over 150 VMware/partner PoPs at launch | Buyers on this earlier technology generation specifically |
Capability evidence
67 recordsAi Automation14 records
| Capability | Support | Confidence | Freshness | Qualification |
|---|---|---|---|---|
| AI assistant/copilot | Requires Confirmation | Unresolved | Current | BT's confirmed AI investment centres on threat detection specifically (see Anomaly detection row) rather than a general administrative AI copilot product |
| AI data protection controls | Requires Confirmation | Unresolved | Current | Not confirmed |
| Anomaly detection | Requires Confirmation | Unresolved | Current | Underlying detection methodology and the specific technical contribution of BT versus the underlying platform (Fortinet) not itemised separately |
| Automated policy recommendation | Unknown | Unresolved | Current | Not confirmed |
| Automated remediation | Requires Confirmation | Unresolved | Current | Not confirmed |
| Capacity/path optimisation | Requires Confirmation | Unresolved | Current | Granular technical mechanics beyond the confirmed architecture description not itemised |
| Configuration generation | Unknown | Unresolved | Current | Not confirmed |
| Digital experience diagnostics | Requires Confirmation | Unresolved | Current | Not confirmed |
| Generative AI application controls | Requires Confirmation | Unresolved | Current | Not confirmed |
| Natural-language querying | Unknown | Unresolved | Current | Not confirmed |
| Report summarisation | Unknown | Unresolved | Current | Not confirmed |
| Root-cause analysis | Requires Confirmation | Unresolved | Current | Not itemised as a single, distinctly-named root-cause-analysis product |
| Threat detection/classification | Requires Confirmation | Unresolved | Current | Same underlying-platform-versus-BT-value-add distinction noted above |
| User/entity behaviour analytics | Requires Confirmation | Unresolved | Current | Not confirmed |
Architecture15 records
| Capability | Support | Confidence | Freshness | Qualification |
|---|---|---|---|---|
| 5G/LTE support | Requires Confirmation | Low Medium | Current | Not independently confirmed as a distinct, named capability for the SASE/SD-WAN service specifically in sources reviewed, though BT Group's own, much larger EE mobile network (5G+ coverage confirmed at 73% of the UK population as of FY2026) makes underlying 5G capability highly plausible at the parent-company level |
| Application identification | Requires Confirmation | Medium High | Current | Native, implied via the confirmed elastic SD-WAN, dynamic-traffic-steering capability |
| Branch LAN/WLAN integration | Requires Confirmation | Low | Current | Not independently confirmed as a distinct, named capability specifically for the SASE/SD-WAN service in sources reviewed, though BT's much broader telecommunications infrastructure business may address adjacent capability not confirmed as unified with this specific service in this pass |
| Brownfield migration support | Supported | High | Current | Native, well-evidenced via a real, detailed case study directly describing exactly this scenario - a customer migrating from a legacy approach to 'an over-the-internet connection' to 'solve many of these problems', citing the inability 'to handle a network transformation like this in-house' |
| Dynamic path selection | Requires Confirmation | High | Current | Native, confirmed directly - 'elastic SD-WAN' dynamically steers traffic, and 'traffic is prioritised from your devices to the SASE cloud node, avoiding public internet congestion' |
| Edge form factors | Requires Confirmation | Medium | Current | Not independently confirmed with specific named hardware model detail in sources reviewed - the platform's confirmed architecture centres on managed service delivery with CPE included in the commercial model, rather than a distinctly-named, purpose-built hardware line |
| Forward error correction / packet duplication | Requires Confirmation | Low | Current | Not confirmed as a distinct named capability in sources reviewed |
| High availability | Requires Confirmation | High | Current | Native, confirmed directly and with genuine specificity via Netify's own independent research - 'Dual-hub and diverse last-mile designs are standard practise for resilience' |
| LEO satellite support | Unknown | Low | Current | Unknown - not found in sources reviewed |
| Local internet breakout | Requires Confirmation | Medium High | Current | Native, implied via the confirmed 'over-the-internet connection' capability described directly in the case study, and the confirmed SASE-cloud-node architecture avoiding public internet congestion for prioritised traffic specifically |
| QoS and traffic engineering | Requires Confirmation | Medium High | Current | Native, implied via the confirmed elastic, dynamically-steered traffic architecture |
| Segmentation / VRF capability | Requires Confirmation | High | Current | Native, confirmed directly and with genuine technical specificity - 'the network is segmented too. So if a breach happens in one area, data in other areas stays protected' |
| Supported WAN underlays | Requires Confirmation | High | Current | Native, confirmed directly - Agile Connect provides 'the flexibility to mix different connectivity options for each of their sites', reinforced by the confirmed 'over-the-internet connection' capability described in the case study specifically |
| Virtual/cloud edge support | Requires Confirmation | Medium High | Current | Native, implied via the confirmed cloud-delivered SASE architecture and the 'SASE cloud node' terminology used directly by BT |
| Zero-touch provisioning | Requires Confirmation | Medium | Current | Not independently confirmed with a specific, named zero-touch mechanism in sources reviewed, though the confirmed fully-managed delivery model implies BT-led deployment rather than customer-driven manual configuration by default |
Core Capabilities15 records
| Capability | Support | Confidence | Freshness | Qualification |
|---|---|---|---|---|
| Application-aware routing | Requires Confirmation | Medium High | Current | None identified |
| CASB - API | Requires Confirmation | Low | Current | Not confirmed as distinct from inline CASB |
| CASB - inline | Requires Confirmation | High | Current | Specific inline-versus-API-mode technical detail not itemised |
| Cloud firewall / cloud network security | Requires Confirmation | High | Current | None identified |
| DNS security | Requires Confirmation | Low | Current | Not confirmed |
| Data loss prevention | Requires Confirmation | Low | Current | Not confirmed |
| Digital experience monitoring | Requires Confirmation | Medium High | Current | A distinctly-branded DEM product name wasn't itemised |
| Firewall as a Service | Requires Confirmation | High | Current | None identified |
| Multi-cloud networking | Requires Confirmation | Medium High | Current | Specific, named hyperscaler cloud on-ramp partnerships weren't itemised by name |
| SD-WAN | Supported | High | Current | None identified |
| SaaS security posture | Requires Confirmation | Low | Current | Not confirmed |
| Secure web gateway | Requires Confirmation | High | Current | Capability specifics depend on which underlying platform (Fortinet vs. Meraki) is proposed |
| Threat intelligence | Requires Confirmation | High | Current | A dedicated, separately-named threat-research organisation (comparable to some competitors' named equivalents) wasn't itemised specifically for the SASE service |
| WAN optimisation | Requires Confirmation | Medium High | Current | Named technical mechanisms (e.g. FEC, compression) not itemised |
| ZTNA | Requires Confirmation | High | Current | None identified |
Remote Access9 records
| Capability | Support | Confidence | Freshness | Qualification |
|---|---|---|---|---|
| Clientless access | Requires Confirmation | Unresolved | Current | Not confirmed |
| Contractors/third parties | Requires Confirmation | Unresolved | Current | Not confirmed by a named case study specifically about contractor access |
| Managed laptops | Requires Confirmation | Unresolved | Current | Platform-dependent; specific client detail not itemised |
| Mobile devices | Requires Confirmation | Unresolved | Current | Not confirmed |
| Privileged access | Unknown | Unresolved | Current | Not confirmed |
| Remote browser isolation | Requires Confirmation | Low | Current | Not confirmed |
| Remote browser isolation | Requires Confirmation | Unresolved | Current | Unknown |
| Unmanaged/BYOD devices | Requires Confirmation | Unresolved | Current | Not confirmed |
| VDI environments | Unknown | Unresolved | Current | Not confirmed |
Reporting Analytics14 records
| Capability | Support | Confidence | Freshness | Qualification |
|---|---|---|---|---|
| Application performance | Requires Confirmation | Unresolved | Current | Not confirmed |
| Compliance reporting | Requires Confirmation | Unresolved | Current | Not confirmed |
| Custom reports | Unknown | Unresolved | Current | Not confirmed |
| DLP events | Requires Confirmation | Unresolved | Current | Not confirmed |
| Executive dashboard | Requires Confirmation | Unresolved | Current | Not confirmed |
| Network health | Requires Confirmation | Unresolved | Current | Not confirmed |
| Raw log access | Requires Confirmation | Unresolved | Current | Not confirmed |
| Remote-user experience | Requires Confirmation | Unresolved | Current | Not confirmed |
| SLA reporting | Requires Confirmation | Unresolved | Current | Not confirmed |
| Scheduled reports | Unknown | Unresolved | Current | Not confirmed |
| Security events | Requires Confirmation | Unresolved | Current | Not confirmed |
| Site and circuit performance | Requires Confirmation | Unresolved | Current | Not confirmed |
| Threat reporting | Requires Confirmation | Unresolved | Current | Not confirmed |
| User experience | Requires Confirmation | Unresolved | Current | Not confirmed |
Geographic coverage
12 records| Geography | Delivery type | Relationship | Confidence | Qualification |
|---|---|---|---|---|
| Africa coverage | Unknown - Not Itemised For The SASE Service Specifically In Sources Reviewed | Unknown | Low | Unknown - not itemised for the SASE service specifically in sources reviewed | Unknown | Not specified | No named data centres found for the SASE service specifically | Not found in a Tier 1-2 source in this pass | Low | Evidence gap. |
| Carrier interconnects | Native, Implied Via BT'S Own Status As A Major, Established Global Telecommunications Carrier With Extensive, Long-Established Interconnection Relationships, Though Specific, Itemised Carrier/Exchange Detail Wasn'T Independently Confirmed In This Pass | Owned | Medium | Native, implied via BT's own status as a major, established global telecommunications carrier with extensive, long-established interconnection relationships, though specific, itemised carrier/exchange detail wasn't independently confirmed in this pass | Direct | Global, per BT's own established carrier status | Specific, itemised carrier/exchange detail not itemised | Not found at this specificity in a Tier 1-2 source in this pass | Medium | A reasonable, well-supported inference from BT's own established, long-standing position as a major global telecommunications carrier; granular, itemised interconnect detail wasn't independently confirmed. |
| China coverage | Unknown - No China-Specific Data-Centre Or Licensed-PoP Detail Found For The SASE/SD-WAN Service Specifically In Sources Reviewed, Though BT Group'S Own, Much Larger, Established Global Telecommunications Business Is Highly Likely To Have Some Form Of China-Relevant Presence At The Parent-Company Level, Not Confirmed As Unified With The SASE Service Specifically In This Pass | Unknown | Low | Unknown - no China-specific data-centre or licensed-PoP detail found for the SASE/SD-WAN service specifically in sources reviewed, though BT Group's own, much larger, established global telecommunications business is highly likely to have some form of China-relevant presence at the parent-company level, not confirmed as unified with the SASE service specifically in this pass | Unknown at the SASE-service-specific level | Not specified for the SASE service specifically | No named China presence confirmed for the SASE service specifically | Not found in a Tier 1-2 source in this pass at this specificity | Low | Evidence gap for the SASE service specifically, though BT Group's own broader global telecommunications footprint makes some form of parent-company-level China presence plausible. |
| Data residency choices | Native, Confirmed With Genuine Sector-Specific Detail For Financial Services Specifically - ZTNA 'Supports Data Residency By Keeping Sensitive Traffic Within Localised Data Paths' | Owned | Medium High | Native, confirmed with genuine sector-specific detail for financial services specifically - ZTNA 'supports data residency by keeping sensitive traffic within localised data paths' | Direct (via BT's own network) | UK/localised, per the confirmed financial-services-specific claim | Broader, general data-residency architecture beyond this specific sector claim wasn't itemised | Medium-High | A specific, named, sector-relevant confirmation of data-residency support - genuinely concrete evidence for this exact, named use case, even without a broader, general data-residency architecture page. |
| Latin America coverage | Unknown - No Specific Evidence Found For The SASE Service Specifically In This Pass | Unknown | Low | Unknown - no specific evidence found for the SASE service specifically in this pass | Unknown | Not specified | No named data centres or customer evidence found for this region specifically | Not found in a Tier 1-2 source in this pass | Low | Evidence gap. |
| Middle East coverage | Unknown - Not Itemised For The SASE Service Specifically In Sources Reviewed | Unknown | Low | Unknown - not itemised for the SASE service specifically in sources reviewed | Unknown | Not specified | No named data centres found for the SASE service specifically | Not found in a Tier 1-2 source in this pass | Low | Evidence gap. |
| Private backbone | Native, And Genuinely One Of BT'S Clearest, Most Distinctive Structural Strengths - Netify'S Own Independent Research Confirms BT Operates With An 'Owned Core, And Global Reach Through BT'S International Network' | Owned | High | Native, and genuinely one of BT's clearest, most distinctive structural strengths - Netify's own independent research confirms BT operates with an 'owned core, and global reach through BT's international network' | Direct (owned) | Global, via BT's own international network | None identified | High | A specific, direct, independently-sourced confirmation of an owned core network - genuinely one of BT's most concrete, structural differentiators relative to platform-only SASE vendors without equivalent owned infrastructure. |
| Public cloud on-ramps | Not Independently Confirmed With Specific Named Hyperscaler Detail In Sources Reviewed | Unknown | Low Medium | Not independently confirmed with specific named hyperscaler detail in sources reviewed | Unknown | Unknown | Not detailed by named hyperscaler | Not found at this specificity in a Tier 1-2 source in this pass | Low-Medium | See Table 3, 6 for the related finding. |
| SD-WAN gateways / cloud gateways | Delivered Via BT'S Own International Core Network And The Relevant Underlying Platform'S (Fortinet'S Or Meraki'S) Cloud Infrastructure | Partner | Medium | Delivered via BT's own international core network and the relevant underlying platform's (Fortinet's or Meraki's) cloud infrastructure | Direct (BT core network) and partner (platform-specific cloud infrastructure) | UK-anchored with global reach, per BT's own confirmed international network | Specific, quantified gateway-count figures not itemised | Medium | Reasonable, well-supported inference from BT's own confirmed international network and the relevant platform's cloud infrastructure. |
| Security PoPs / service edges | Not Confirmed With A Specific, Quantified PoP-Count Figure For The Current, Fortinet-Based Managed SASE Service Specifically In Sources Reviewed; The Earlier, Historical VMware-Based Service Was Confirmed At Launch To Use 'A Global Network Of Over 150 Points Of Presence (PoPs) Deployed By VMware And Its SASE Service Pro[Viders]' - A Figure Describing The Prior, Distinct Technology Generation Rather Than The Current Offering | Partner | Low Medium | Not confirmed with a specific, quantified PoP-count figure for the current, Fortinet-based managed SASE service specifically in sources reviewed; the earlier, historical VMware-based service was confirmed at launch to use 'a global network of over 150 points of presence (PoPs) deployed by VMware and its SASE service pro[viders]' - a figure describing the prior, distinct technology generation rather than the current offering | Partner (Fortinet's or VMware's PoP network, per the relevant technology generation) | Global, per the confirmed (historical) VMware-era figure; current, Fortinet-era figure not itemised | The confirmed 150+-PoP figure describes the historical VMware-based service specifically, not confirmed as applicable to the current Fortinet-based offering | Low-Medium (historical figure only; current-generation figure not found) | A specific, worth-noting evidentiary gap - the only quantified PoP figure found in this research pass describes BT's earlier, historical VMware-based SASE service rather than the current, Fortinet-based offering; buyers should request the current, platform-specific PoP count directly. |
| Sovereign/regional service options | Not Confirmed As A Distinct, Named FedRAMP Or Equivalent Sovereign-Cloud Authorization In Sources Reviewed; BT'S Own Confirmed HSCN Accreditation Is The Closest, Specific, Sector-Relevant Regional/Sovereign-Adjacent Credential Found In This Pass | Owned | Medium High | Not confirmed as a distinct, named FedRAMP or equivalent sovereign-cloud authorization in sources reviewed; BT's own confirmed HSCN accreditation is the closest, specific, sector-relevant regional/sovereign-adjacent credential found in this pass | Direct (HSCN accreditation) | United Kingdom, NHS/healthcare-adjacent public bodies specifically | No FedRAMP or equivalent US federal authorization found for the SASE service specifically | Medium-High | A real, specific, UK-relevant accreditation (HSCN) is confirmed; broader, international sovereign/regional credentials (e.g. FedRAMP) were not found for this service in this pass. |
| United Kingdom coverage | Strong Fit, Genuinely The Best-Evidenced Region In This Entire Table | Owned | High | Strong fit, genuinely the best-evidenced region in this entire table | Direct (owned, via Openreach) | United Kingdom, comprehensively | None identified | High | Genuinely the strongest-evidenced coverage finding in this entire profile - BT's confirmed ownership of Openreach, the UK's dominant last-mile access network, gives it a structural UK-coverage advantage no platform-only SASE vendor can replicate. |
Service models
34 recordsOther
Requires ConfirmationNative, implied via the confirmed BT Security MDR service and BT's own confirmed 'AI-powered proactive threat detection', though a distinctly-named IR service with a specific, published SLA figure wasn't itemised | Not confirmed with a specific figure | N/A | Included, or available as an enhanced managed-service tier | N/A | Not itemised with a specific numeric figure | Real, confirmed capability via the confirmed MDR service; a distinctly-named IR product with a specific, published SLA figure wasn't independently itemised.
Other
Requires ConfirmationNative, implied via Netify's own independent research confirming 'field engineering reach' as a core evaluated capability for BT specifically | N/A | UK-wide field engineering reach confirmed directly | Included, or available as an enhanced service tier | N/A | N/A | A specific, direct, independently-sourced confirmation of field-engineering capability - genuinely concrete evidence, though specific standalone Professional Services pricing wasn't itemised.
Other
Requires ConfirmationNative, implied via the confirmed CPE-inclusive, fully-managed commercial model, which by design shifts lifecycle-management responsibility to BT | BT-managed | Very low, given the confirmed fully-managed model | Automatic, given the managed-service delivery model | Very low | None significant identified | Reasonable, well-supported inference from the confirmed fully-managed, CPE-inclusive commercial model.
Other
UnknownUnknown - not found in sources reviewed | Not found | Not specified | Not confirmed | N/A | Not confirmed | Not found in a Tier 1-2 source in this pass | Evidence gap.
Other
SupportedYes, and genuinely the platform's default, most consistently evidenced delivery model | Full BT-managed service (Agile Connect plus BT Managed SASE) | N/A | Managed by BT | Buyers wanting to minimise IT operational burden entirely - BT's own core, confirmed positioning | Very low for the customer | N/A | Genuinely the platform's clearest, most consistently-evidenced delivery model - fully-managed delivery is confirmed directly as BT's primary positioning, not merely one option among several.
Other
Requires ConfirmationYes, via customer-premises equipment included in the confirmed managed commercial model | CPE (specific hardware model not itemised) | CPE → Agile Connect → cloud SASE layer | Managed by BT | Fixed branch sites | Low, given the confirmed fully-managed model | Not itemised in detail | Real, confirmed capability via the confirmed CPE-inclusive commercial model (Table 16); specific hardware model names weren't independently itemised.
Other
Requires ConfirmationNative, implied via the confirmed cloud-delivered SASE architecture | BT Managed SASE (cloud SSE) | Via the confirmed SASE cloud node | Managed by BT | Cloud-first organisations | Low | Not itemised for specific named hyperscalers | Confirmed at the architectural level; named hyperscaler-specific integration detail wasn't independently itemised.
Other
Requires ConfirmationNative, via the same confirmed fully-managed default architecture | N/A | N/A | Included | Customer or BT-managed, per the confirmed co-managed option | N/A | Same evidence and finding as Configuration management above.
Other
Requires ConfirmationNot independently confirmed as a distinct, named MSP/multi-tenant capability in sources reviewed, though BT's own scale as one of the UK's largest managed service providers, per Netify's independent research, implies real, underlying multi-tenant operational capability exists in practise | Not confirmed by name | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Reasonable inference from BT's confirmed scale as the largest UK managed network and managed security provider; a distinctly-named, customer-facing multi-tenant product feature wasn't independently itemised.
Other
Requires ConfirmationNot independently confirmed with specific detail in sources reviewed, beyond the general confirmed co-managed option | Presumably BT-managed portal | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in a Tier 1-2 source in this pass at this level of granular detail | Reasonable inference from the confirmed co-managed option; granular delegated-administration mechanics weren't independently itemised.
Other
Requires ConfirmationNative, and genuinely well-evidenced via BT's confirmed round-the-clock access to security experts and the confirmed centralised-visibility capability described directly in a real case study - 'better able to see and control their entire infrastructure and security' | BT-managed portal/support | Very low, given the confirmed managed-troubleshooting model | Not itemised as a distinct AI-diagnostics feature | Positioned as low-effort via the confirmed centralised-visibility and expert-access architecture | None significant identified | A specific, real, case-study-evidenced confirmation of centralised visibility and control - genuinely concrete evidence.
Other
Requires ConfirmationNot independently confirmed as a distinct capability in sources reviewed | Unknown | Unknown | Unknown | Unknown | Not confirmed | N/A | See Table 5 - a genuine, specific evidence gap.
Other
Requires ConfirmationNot independently confirmed with specific RMA/replacement terms in sources reviewed, though CPE is confirmed as included within the managed commercial model (Table 16), implying lifecycle management is BT's responsibility by default | Not found | Not found | Included, per the confirmed CPE-inclusive commercial model | N/A | Not confirmed | Reasonable inference from the confirmed CPE-inclusive commercial model; specific RMA/replacement terms weren't independently itemised.
Other
Requires ConfirmationNot independently confirmed with specific client-technology detail in sources reviewed | Unknown | Unknown | Unknown | Unknown | Not confirmed | N/A | See Table 5 - a genuine, specific evidence gap, likely dependent on which underlying platform (Fortinet or Meraki) is proposed.
Other
Requires ConfirmationYes, implied via the confirmed combination of on-premises CPE, managed SD-WAN, and cloud-delivered SASE together under one contract, reinforced by the confirmed case study describing protection across on-premises and internet-based connectivity together | CPE plus Agile Connect plus BT Managed SASE (cloud) | Mixed | Managed by BT, unified under one contract | Most real-world enterprise estates with mixed on-premises and cloud requirements | Low for the customer, given the confirmed fully-managed model | Confirmed directly via the case study's described transition from a legacy approach to a hybrid, internet-augmented model | A genuine, confirmed architectural strength - the combination of owned last-mile infrastructure, managed CPE, and cloud-delivered SASE under one managed contract is a real, specific characteristic of BT's offering.
Other
Requires ConfirmationNot confirmed as a distinct named support tier with specific TAM detail in sources reviewed | Not confirmed with specific figures | Not specified | Not confirmed | N/A | Not confirmed | Not found at this level of detail in a Tier 1-2 source in this pass | Evidence gap - worth a direct follow-up, particularly given BT's much broader enterprise account-management infrastructure across its wider portfolio.
Other
SupportedNative, and genuinely well-evidenced via a specifically-named BT service | BT Security MDR | 24x7 | Included, or available as an enhanced managed-service tier | N/A | Not itemised with a specific numeric figure | A specific, named, credible, independently-corroborated managed-service product - genuinely concrete evidence, backed by BT's own long-established security division.
Other
Requires ConfirmationNative, implied via Netify's own independent research confirming 'change windows' as a core evaluated capability for BT specifically | Not confirmed with a specific figure | N/A | Included | Customer requests changes within confirmed change-window processes | N/A | A specific, direct, independently-sourced confirmation of a formal change-management process ('change windows') - genuinely concrete evidence.
Other
Requires ConfirmationNot independently confirmed with specific client/agent deployment-effort detail in sources reviewed | Unknown | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in a Tier 1-2 source in this pass at this level of detail | See Table 5 - a genuine, specific evidence gap for the remote-user side of the platform specifically, likely dependent on which underlying platform is proposed.
Other
Requires ConfirmationNative, confirmed directly and repeatedly - 'Round-the-clock monitoring and access to BT security experts when you need them' | 24x7x365, confirmed directly | UK-wide, with international reach | Included | N/A | Not itemised with a specific numeric figure | A specific, direct, primary-sourced confirmation - genuinely concrete evidence.
Other
UnknownFully managed by default, evidenced via a real, detailed case study describing BT taking over an entire network transformation on the customer's behalf | BT-managed, per the confirmed fully-managed default model | Very low, given the confirmed fully-managed model | Not itemised further | Genuinely well-evidenced as low-effort for the customer via a real, primary-sourced case study - the customer explicitly 'couldn't afford to handle a network transformation like this in-house' | None significant identified | A specific, real, case-study-evidenced confirmation of low customer-side effort - genuinely concrete evidence directly addressing why the customer chose a managed approach in the first place.
Other
UnknownFully managed, evidenced via a real, detailed, multi-country customer example | BT-managed | Very low, given the confirmed fully-managed model | Not itemised as a distinct zero-touch mechanism, though implied by the managed-service model | Genuinely well-evidenced as low-effort for the customer, given the confirmed managed-service delivery and real case-study evidence | None significant identified | Well-evidenced via a real, detailed customer example at genuine, multi-country scale.
Other
SupportedYes, and genuinely well-evidenced via a real, detailed customer example | CPE plus Agile Connect managed service | Branch → Agile Connect → cloud SASE layer | Managed by BT | Distributed, multi-country branch estates | Low, given the confirmed fully-managed model | Confirmed directly via a real, detailed, multi-country case study (Table 4, 17) | Well-evidenced via specific, real, primary-sourced customer-deployment detail rather than only a generic capability claim.
Other
Requires ConfirmationNative, and genuinely well-evidenced via Netify's own independent research confirming '24×7 NOC tooling' as a core evaluated capability for BT specifically | 24x7, confirmed directly | UK-wide, per confirmed UK-wide engineering reach | Included, per the confirmed fully-managed default model | Customer configures high-level policy; day-to-day NOC operations are BT-managed by default | Not itemised with a specific numeric figure | A specific, direct, independently-sourced confirmation of 24x7 NOC capability - genuinely concrete evidence, reinforced by BT's confirmed UK-wide field-engineering reach.
Other
Not SupportedNative, and genuinely one of BT's most structurally distinctive capabilities - direct ownership of Openreach gives BT genuine, first-party accountability for UK last-mile infrastructure that no platform-only SASE vendor can replicate | 24x7, per the confirmed NOC/monitoring architecture | UK-wide | Included | N/A - BT owns the underlying access network directly via Openreach | N/A | Genuinely the strongest, most structurally distinctive finding in this entire profile for this exact row - BT's direct ownership of Openreach means last-mile accountability sits with the same corporate group delivering the SASE service, a genuine structural advantage most competitors cannot offer.
Other
UnknownUnknown - not found in sources reviewed | Presumably BT-managed portal or API | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in public sources reviewed | Evidence gap.
Other
UnknownUnknown - not found in sources reviewed | Presumably BT-managed portal | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in public sources reviewed | Evidence gap.
Other
SupportedYes, and genuinely the default model for the SSE/SASE half of the service | BT Managed SASE (Fortinet or Meraki cloud SSE) | Via the confirmed SASE cloud node architecture | Managed by BT, per the confirmed fully-managed default | All customers - core delivery model for the SASE/security layer | Low for the customer, given the confirmed fully-managed model | N/A - default | Confirmed via BT's own direct 'SASE cloud node' terminology and architecture description.
Other
Requires ConfirmationNative, via the confirmed fully-managed default delivery model | N/A | N/A | Included | Customer-managed via the co-managed option, or BT-managed by default | N/A | Confirmed via the platform's core, fully-managed default architecture.
Other
Requires ConfirmationManaged by BT by default, with a confirmed co-managed option for buyers wanting more direct involvement | BT-managed portal, or customer-accessible tools under the confirmed co-managed option | Very low under the default managed model; benefits from technical familiarity under the co-managed option | Not itemised further | Positioned as simplified via the confirmed fully-managed default architecture | Buyers should confirm the exact RACI split directly (Table 6) | Real, confirmed capability under the fully-managed default; the exact co-managed division of responsibility should be confirmed directly rather than assumed.
Other
Requires ConfirmationYes, confirmed as an available option, though Netify's own independent research specifically notes 'DIY/self-managed model is not BT's primary positioning' and recommends confirming 'customer control boundaries... via RACI and portal demo' | Not itemised with specific technical components | N/A | Shared between BT and customer IT staff, per a confirmed but not fully specified RACI split | Buyers wanting some direct operational involvement alongside BT-managed delivery | Not fully detailed - buyers should confirm the specific RACI split directly | N/A | A specific, important, independently-sourced caution - a co-managed option is confirmed to exist, but the exact division of responsibility should be confirmed directly rather than assumed, since BT's core, confirmed positioning centres on fully-managed delivery.
Other
Requires ConfirmationNot independently confirmed with specific detail in sources reviewed | Unknown | Unknown | Unknown | Unknown | Not confirmed | Not found in a Tier 1-2 source in this pass | Evidence gap.
Other
Requires ConfirmationYes, confirmed as an available option, though buyers should confirm the exact RACI split directly rather than assume equivalence with the confirmed, primary, fully-managed model (Table 6) | BT-managed portal, with confirmed customer-accessible elements under the co-managed option | Low for the customer under the confirmed managed default; moderate under the co-managed option depending on the chosen involvement level | Confirmed, real option, though not itemised with full technical detail | Low under the default managed model | Buyers should confirm the RACI split and request a portal demonstration directly, per Netify's own independent research | A genuine, confirmed option exists, though this is a specific, worth-flagging area requiring direct buyer confirmation rather than assumption, given BT's core positioning centres on fully-managed delivery by default.
Other
Requires ConfirmationNative, and genuinely well-evidenced via the confirmed BT Security division and its named Managed Detection and Response service, reinforced by Netify's own independent research confirming 'MDR and SOC capability' as a core evaluated capability for BT specifically | 24x7, per the confirmed MDR/SOC framing | UK-wide, with international reach via BT's global network | Included, or available as an enhanced managed-service tier | Customer configures high-level policy; SOC operations are BT Security-managed | Not itemised with a specific numeric figure | Real, confirmed capability via both BT's own named security division and Netify's independent research - genuinely credible, corroborated evidence.
Compliance and assurance
13 records| Framework | Scope | Support | Review date | Qualification |
|---|---|---|---|---|
| DORA relevance | N/A | Requires Confirmation | Not stated | Unknown - not found in sources reviewed, despite confirmed direct financial-services-sector positioning (Table 3, 14) | N/A | Not confirmed | EU financial services | Not found in a Tier 1-2 source in this pass | Not found | A specific, worth-flagging gap given the confirmed direct financial-services-sector positioning - worth a direct follow-up for any EU financial-services buyer specifically. |
| Data residency | UK/localised, per the confirmed financial-services-specific claim | Requires Confirmation | Not stated | Native, confirmed with genuine sector-specific detail for financial services specifically (Table 7) - 'supports data residency by keeping sensitive traffic within localised data paths' | UK/localised, per the confirmed financial-services-specific claim | Confirmed at the mechanism level for this specific sector claim | UK-relevant | 22 Jul 2026 | A specific, named, sector-relevant confirmation; a broader, general data-residency architecture beyond this specific claim wasn't itemised. |
| Encryption/key management | BT Managed Fortinet Firewall specifically | Requires Confirmation | Not stated | Native, confirmed with specific technical detail via a real case study - 'built-in Secure Sockets Layer (SSL) decryption keeps every user safe' | BT Managed Fortinet Firewall specifically | SSL decryption confirmed directly | None identified | 22 Jul 2026 | A specific, named, case-study-evidenced encryption capability - genuinely concrete evidence, though scoped specifically to the confirmed Fortinet-based firewall product rather than the platform generally. |
| FedRAMP | N/A | Requires Confirmation | Not stated | Not applicable in the traditional sense - FedRAMP is a US-specific federal-government cloud-authorization programme; BT's confirmed market orientation and accreditations (HSCN) are UK-specific instead | N/A | Not applicable (UK market orientation) | US federal only | N/A | N/A | Not applicable given BT's confirmed UK market orientation - no evidence was sought or expected for this US-specific framework. |
| GDPR | UK/EU-relevant, per BT's own market orientation | Requires Confirmation | Not stated | Not separately itemised as a distinct compliance certification in sources reviewed, though BT's own confirmed UK/European market orientation and the confirmed data-residency claim (Table 7) make GDPR-aligned data handling highly plausible in practise | UK/EU-relevant, per BT's own market orientation | Not confirmed as a distinct, named certification | EU/UK relevant | 22 Jul 2026 | A reasonable, well-supported inference from BT's own confirmed UK/EU market orientation and the confirmed data-residency claim; a distinct, named GDPR-compliance certification wasn't independently itemised. |
| HIPAA | N/A | Requires Confirmation | Not stated | Not applicable in the traditional sense - HIPAA is a US-specific healthcare regulation; BT's confirmed healthcare-adjacent accreditation (HSCN) is a UK-specific equivalent instead | N/A | Not applicable (UK market orientation) | US healthcare-relevant only | N/A | N/A | Not applicable given BT's confirmed UK market orientation - see the HSCN row below for the relevant UK-specific healthcare accreditation instead. |
| HSCN (Health and Social Care Network) accreditation | UK NHS and social-care-sector organisations specifically | Requires Confirmation | Not stated | Confirmed directly via Netify's own independent research | UK NHS and social-care-sector organisations specifically | HSCN accreditation | United Kingdom | 25 Jun 2026 | A specific, real, UK-relevant, sector-specific accreditation - genuinely concrete evidence for NHS and social-care-sector buyers specifically, and a real differentiator most non-UK-focused SASE vendors would not hold. |
| ISO 27001 | Not confirmed at the SASE-service-specific level | Requires Confirmation | Not stated | Not independently confirmed as a distinct, SASE-service-specific certification in sources reviewed; BT Group's own, much larger, established corporate scale makes broader ISO 27001 certification plausible at the parent-company level, though this wasn't confirmed as specifically applicable to the SASE service in this pass | Not confirmed at the SASE-service-specific level | Not confirmed | None identified | Not found at this specificity in a Tier 1-2 source in this pass | Not found | A genuine, specific evidence gap for the SASE service itself - worth a direct follow-up, given BT Group's own scale and established market position make some form of corporate-level ISO 27001 certification plausible even without SASE-service-specific confirmation. |
| Logging/auditability | Platform-wide, per BT's own direct claim | Requires Confirmation | Not stated | Native, confirmed directly - 'Logs, policies and controls are managed and kept up to date, so staying compliant is simpler' | Platform-wide, per BT's own direct claim | Not confirmed at granular technical detail | None identified | 22 Jul 2026 | A specific, direct, primary-sourced confirmation explicitly framed around compliance simplification - genuinely concrete evidence, even without granular, technical export/retention detail. |
| NIS2 relevance | N/A | Unknown | Not stated | Unknown - not found in sources reviewed | N/A | Not confirmed | EU | Not found in a Tier 1-2 source in this pass | Not found | Evidence gap - worth a direct follow-up given BT's genuine European market presence. |
| PCI DSS | Not confirmed at the SASE-service-specific level | Requires Confirmation | Not stated | Not independently confirmed as a distinct, named certification for the SASE service specifically in sources reviewed, despite the confirmed retail-sector positioning explicitly addressing 'payment and customer data' protection | Not confirmed at the SASE-service-specific level | Not confirmed | N/A | Not found in a Tier 1-2 source in this pass at sufficient specificity | Not found | A specific, worth-flagging gap given the confirmed, direct retail/payment-data positioning (Table 3) - worth a direct follow-up for any retail-sector buyer specifically. |
| SOC 2 | N/A | Requires Confirmation | Not stated | Not confirmed in sources reviewed | N/A | Not confirmed | N/A | Not found in a Tier 1-2 source in this pass | Not found | A genuine evidence gap worth a direct follow-up - this may reflect the UK/European market orientation, where SOC 2 (a US-originated attestation standard) is less commonly the lead certification, rather than confident evidence of absence. |
| UK public sector frameworks | UK public sector | Requires Confirmation | Not stated | Native, implied via the confirmed HSCN accreditation and BT's own established, long-standing position as a major UK public-sector technology supplier, though a comprehensive, itemised list of specific UK public-sector frameworks (e.g. G-Cloud) wasn't independently confirmed for the SASE service specifically in this pass | UK public sector | HSCN confirmed specifically; broader frameworks not itemised | United Kingdom | 25 Jun 2026 | A real, specific, confirmed UK public-sector accreditation (HSCN) exists; a broader, comprehensive framework list wasn't independently itemised in this pass. |
Integrations
21 recordsAWS
Cloud · Unknown
Cloud | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Active Directory
Identity · Unknown
Identity | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Cisco Meraki
SD-WAN/SASE Platform (Alternative Partner) · Partner
SD-WAN/SASE platform (alternative partner) | Native partnership, confirmed as an alternative underlying platform for both managed SD-WAN and managed SASE | Bidirectional (full platform integration) | Included within the Meraki-based service option | Confirmed directly via Netify's independent research as a named, distinct platform option alongside Fortinet | High | A specific, named, confirmed alternative platform - genuinely concrete evidence of real platform choice within BT's managed service.
CrowdStrike
EDR · Unknown
EDR | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Fortinet
SASE/SSE Platform (Core Partner) · Partner
SASE/SSE platform (core partner) | Native partnership, and genuinely BT's current, primary SASE technology partner | Bidirectional (full platform integration) | Included within BT Managed SASE (Fortinet-based) | Confirmed as the technology foundation for BT's current, expanded managed SASE offering, launched in its most recent form in late 2025 | High | Genuinely the deepest, most current, most extensively-evidenced integration in this entire profile - not a peripheral feature but the technology foundation of BT's current managed SASE service.
Google Cloud
Cloud · Unknown
Cloud | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Google Workspace
Identity/Productivity · Unknown
Identity/productivity | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Microsoft 365
Productivity/SaaS · Unknown
Productivity/SaaS | Not separately confirmed as a distinct named integration in sources reviewed | Unknown | Not specified | Not detailed | Not found as a distinct, named integration in this pass | Low | Evidence gap.
Microsoft Azure
Cloud · Unknown
Cloud | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Microsoft Defender
EDR · Unknown
EDR | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Microsoft Entra ID
Identity · Unknown
Identity | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Microsoft Sentinel
SIEM · Unknown
SIEM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Nokia
5G/Telco Infrastructure (Parent-Company-Level Partnership) · Api
5G/telco infrastructure (parent-company-level partnership) | Confirmed at the BT Group parent-company level - a memorandum of understanding covering 5G monetisation via telco APIs, not confirmed as unified with the SASE/SD-WAN service specifically | N/A - parent-company-level agreement | N/A | Describes BT Group's broader telco-API strategy rather than the SASE service specifically | Not found at sufficient SASE-specific detail in a Tier 1-2 source in this pass | Low (real, dated, parent-company-level agreement; not confirmed as SASE-specific) | Real, dated, parent-company-level context; not confirmed as directly relevant to the SASE/SD-WAN service specifically in this pass.
Okta
Identity · Unknown
Identity | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
REST API
Platform API · Api
Platform API | Not independently confirmed as a distinct, named public developer-API portal specifically for the SASE/SD-WAN service in sources reviewed | Unknown | Not specified | Not detailed | Not found as a distinct, named integration in this pass | Low | Evidence gap - worth a direct follow-up.
SCIM/SAML/OIDC
Identity Federation · Unknown
Identity federation | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap - a specific, worth-flagging follow-up given how central this capability is across the wider SASE/SSE category.
ServiceNow
ITSM · Unknown
ITSM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Splunk
SIEM · Unknown
SIEM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap - a specific, worth-flagging gap given how common this kind of pairing is across the wider SASE/SSE category.
Syslog
Log Export · Unknown
Log export | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
VMware (historical)
SASE Platform (Legacy/Historical Partner) · Partner
SASE platform (legacy/historical partner) | Native partnership, historical - the basis for BT's earlier, 2022-launched managed SASE service, distinct from the current Fortinet-based offering | Bidirectional (historical, full platform integration) | N/A - this was the technology foundation for an earlier, distinct product generation | Confirmed directly via a dated (January 2022), primary, wire-distributed press release - buyers should confirm current status of any legacy VMware-based deployments directly | High (for the historical fact itself; current relevance/status not confirmed) | A specific, dated, confirmed historical partnership - genuinely important context for buyers researching BT's SASE history, distinct from and predating the current, confirmed Fortinet-based offering.
Versa Networks
SD-WAN Platform (SD-WAN-Specific Partner) · Partner
SD-WAN platform (SD-WAN-specific partner) | Native partnership, confirmed specifically for managed SD-WAN (Agile Connect) | Bidirectional (SD-WAN platform integration) | Included within the Versa-based SD-WAN service option | Confirmed directly via Netify's independent research as a named SD-WAN platform partner, distinct from the SASE-specific Fortinet/Meraki partnerships | High | A specific, named, confirmed SD-WAN-specific platform partnership - genuinely concrete evidence of BT's multi-platform strategy extending to the SD-WAN layer specifically.
Sector evidence
6 recordsFinancial services
UnknownStrong fit, extensively evidenced | ZTNA-based identity-first access, data-residency support via localised traffic paths, and a real, detailed (anonymised) case study directly in this sector | PCI DSS and DORA not independently confirmed (Table 13), though data residency is confirmed directly for this sector specifically | A real, detailed, primary-sourced (anonymised) global financial-services customer case study, describing Agile Connect plus BT Managed Fortinet Firewall deployment | Multi-country deployment confirmed directly in the case study | The named certification gaps (PCI DSS, DORA) are worth flagging directly for this specific sector | Genuinely the best-evidenced sector in this entire profile - both specific, named sector-relevant product positioning (ZTNA, data residency) and a real, detailed case study exist together, even without the customer's name disclosed.
- Named evidence
- A real, detailed, primary-sourced (anonymised) global financial-services customer case study, describing Agile Connect plus BT Managed Fortinet Firewall deployment
- Case study strength
- Strong
Healthcare / NHS
UnknownStrong fit, evidenced via a specific, named UK accreditation | HSCN accreditation directly supports NHS and social-care-sector connectivity requirements | HSCN confirmed directly (Table 13) | None found as a named individual case study in this pass | United Kingdom | A specific, named accreditation exists without a named individual healthcare case study | A genuine, specific, UK-relevant differentiator - HSCN accreditation is a real, checkable credential most non-UK-focused SASE vendors would not hold, even without a named case study to reinforce it.
- Named evidence
- None found as a named individual case study in this pass
- Case study strength
- None
Manufacturing
Not SupportedUnknown - not assessed, no case study or sector-specific product positioning found in this pass | Not assessed in detail | Not assessed | None found | N/A | No case study or sector-specific positioning found | Evidence gap.
- Named evidence
- None found
- Case study strength
- None
Multi-national / global enterprise
UnknownGood fit, evidenced via a real, detailed case study describing exactly this scenario | Genuine multi-country deployment capability, confirmed directly via BT's own international network and a real, detailed case study | Not assessed for sector-specific frameworks | The same financial-services case study confirms multi-country deployment directly | Global, via BT's own confirmed international network | The available case-study evidence, while real and detailed, is specific to the financial-services sector rather than confirmed across other multinational-enterprise contexts | Real, credible, genuinely well-evidenced fit via a specific, detailed case study, even though the only such example found in this pass happens to be financial-services-specific.
- Named evidence
- The same financial-services case study confirms multi-country deployment directly
- Case study strength
- Strong
Public sector (general)
Requires ConfirmationGood fit, evidenced generally via BT's own confirmed public-sector positioning and established market position | Not assessed in specific technical detail for this sector generally, beyond the confirmed HSCN accreditation for healthcare-adjacent public bodies specifically (see Healthcare row) | HSCN confirmed for healthcare-adjacent bodies specifically; broader public-sector framework detail not itemised | None found as a named individual case study in this pass | United Kingdom | General sector confirmation exists without a named individual case study | Real, credible fit given BT's established, long-standing position as a major UK public-sector technology supplier, even without a named public-sector case study specifically for the SASE service.
- Named evidence
- None found as a named individual case study in this pass
- Case study strength
- None
Retail
UnknownGood fit, evidenced via specific, named product positioning | Elastic SD-WAN and CASB, explicitly named for dynamically steering traffic and safeguarding payment/customer data during seasonal surges and pop-up environments | PCI DSS not independently confirmed (Table 13), despite the direct payment-data positioning | None found as a named individual case study in this pass | N/A | Specific, named product positioning exists without a named individual retail case study | A genuinely specific, concrete sector-fit claim (seasonal surges, pop-up environments, payment/customer data) - worth highlighting directly, even without a named case study to reinforce it.
- Named evidence
- None found as a named individual case study in this pass
- Case study strength
- None
Case studies
1 records- Customer
- Anonymous - described only as 'our global customer' and 'our customer'; company name not disclosed
- Sector and geography
- Financial services · Multi-country (specific countries not named)
- Estate
- Not quantified; Not quantified - described generally as requiring consistent service 'in all countries'
- Outcome
- Simpler deployment and greater control over the network; centralised management providing better visibility and control over the entire infrastructure and security; network segmentation confirmed directly ('if a breach happens in one area, data in other areas stays protected'); higher bandwidth, greater connectivity and flexibility at lower cost; no specific quantified percentage or numeric outcome given
Anonymous - described only as 'our global customer' and 'our customer'; company name not disclosed | Financial services | Multi-country (specific countries not named) | Not quantified | Not quantified - described generally as requiring consistent service 'in all countries' | The customer needed to move away from an existing approach that could not provide consistent service across all its countries of operation, and could not afford to handle a network transformation of this scale in-house | Agile Connect (managed SD-WAN) combined with BT Managed Fortinet Firewall | Fully managed, over-the-internet connectivity combined with edge-based managed firewall | Fortinet (via BT Managed Fortinet Firewall) | Simpler deployment and greater control over the network; centralised management providing better visibility and control over the entire infrastructure and security; network segmentation confirmed directly ('if a breach happens in one area, data in other areas stays protected'); higher bandwidth, greater connectivity and flexibility at lower cost; no specific quantified percentage or numeric outcome given | Medium-High - a real, detailed, primary-sourced (BT's own published case study) account with specific technical detail (SSL decryption, network segmentation, centralised management) and a clear problem/solution narrative, though the customer's identity is anonymised and no specific quantified outcome figure (e.g. a percentage) is given | The strongest available customer evidence found in this research pass - genuinely detailed and technically specific rather than generic marketing language, even without the customer's name disclosed or a specific, quantified numeric outcome. Netify should treat obtaining additional, ideally fully-named, case studies as a priority follow-up item with BT directly.
Netify evaluation record
49 recordsSummary
When would Netify recommend looking elsewhere? (mandatory) | When a buyer needs confirmed, independently-verified, platform-specific compliance certifications (ISO 27001, SOC 2, PCI DSS, DORA); when a buyer specifically wants a fully self-managed, do-it-yourself platform rather than BT's confirmed fully-managed-by-default model; or when a buyer needs a fully-named, quotable customer reference as part of their procurement evidence requirements. | Synthesis of Tables 13, 15, 18 | Medium-High | Each trigger is tied to a specific, evidenced gap rather than a generic 'consider alternatives' hedge.
Each trigger is tied to a specific, evidenced gap rather than a generic 'consider alternatives' hedge.
Summary
Global branch rollout | Genuinely well-evidenced via a real, detailed case study describing a multi-country deployment specifically | Existing branch network/WAN infrastructure to integrate or replace across multiple countries | BT-managed, per the confirmed fully-managed default | BT-managed, with confirmed international network reach | Not quantified with a specific timeline | The confirmed case study directly names the challenge: 'they couldn't afford to handle a network transformation like this in-house' 'in all countries' | The confirmed fully-managed, internationally-capable delivery model directly addresses this scenario | Well-evidenced via a real, detailed, multi-country customer example - genuinely concrete evidence for this exact scenario.
Summary
Cloud-first organisation | Good fit, evidenced at a general level | Confirmed cloud-delivered SASE architecture ('SASE cloud node') supports this buyer profile | None significant identified | Not assessed | Table 3, 6 findings | Real, credible fit; specific, named hyperscaler-level integration detail is a genuine, specific gap worth closing directly.
Summary
Biggest operational concern | The combination of no independently-confirmed, SASE-service-specific compliance certifications and the absence of a fully-named customer case study together represent the two most concrete, actionable evidence gaps a buyer should resolve directly before committing, particularly for regulated-industry procurement decisions. | Tables 13, 18, 19 | Medium-High | Netify should proactively flag both specific, evidenced gaps to buyers during the shortlist conversation rather than let either surface as a surprise later.
Netify should proactively flag both specific, evidenced gaps to buyers during the shortlist conversation rather than let either surface as a surprise later.
Summary
Security & Analytics | BT Security provides a confirmed, named Managed Detection and Response service layered on top of the SASE offering, reinforced by BT's own confirmed 'unified monitoring services' and round-the-clock access to BT security experts. | The specific security-stack capabilities (RBI, DLP, granular CASB detail) depend on which underlying vendor platform (Fortinet vs. Meraki) is proposed for a given deployment - buyers should request platform-specific technical detail rather than assume uniform capability across BT's whole SASE portfolio.
Summary
VPN to ZTNA migration | Not evidenced via a named case study specifically describing VPN retirement in sources reviewed, though ZTNA itself is confirmed as a core capability (Table 3) | Existing VPN infrastructure potentially retired | IT team | BT-managed | Not quantified | Not itemised | Not detailed | The underlying ZTNA capability is confirmed and specific (identity-based access, data residency support); a named customer case study specifically for VPN retirement wasn't found in this pass.
Summary
Remote-user-heavy organisation | Unknown - thin evidence specifically for the remote-user/client side of the platform (see Table 5) | Not assessed with confidence | Not assessed | Not assessed | Table 5 findings | A genuine, specific evidence gap - this profile's research skewed toward the site-to-site SD-WAN, managed-operations, and sector-specific-positioning sides of the service, leaving remote-user/client-side evidence comparatively thin.
Summary
Limitation | BT's own confirmed positioning, per Netify's independent research, is that a DIY/self-managed model is 'not BT's primary positioning', and the confirmed co-managed model's specific customer-control boundaries should be verified directly rather than assumed | Buyers wanting a genuinely lightweight, self-administered platform experience should confirm this expectation matches BT's actual delivery model before committing | Affects buyers with a strong internal preference for self-directed, minimal-vendor-involvement operation most specifically | High (this is Netify's own, directly-stated, independently-researched finding) | A specific, important, independently-sourced caution - not necessarily a weakness for buyers wanting fully-managed delivery, but a real, worth-confirming mismatch risk for buyers with the opposite preference.
Buyers wanting a genuinely lightweight, self-administered platform experience should confirm this expectation matches BT's actual delivery model before committing
Summary
Scope & Boundaries | Genuine platform flexibility (Fortinet, Meraki, Versa) inside one managed relationship gives buyers real optionality without needing to manage multiple separate vendor contracts directly. | BT has offered managed SASE under at least two distinct underlying technology generations in recent years (VMware from January 2022, Fortinet from late 2024/2025) - buyers should confirm which specific, current generation and platform any proposal describes, rather than assume continuity with older, publicly-referenced BT SASE announcements.
Summary
Highly distributed branch estate | Strong fit, evidenced | The confirmed elastic SD-WAN and flexible connectivity-mixing capability directly supports this buyer profile, reinforced by the confirmed managed CPE model reducing per-site deployment burden | Low, given the confirmed fully-managed model | Not itemised | Table 3, 4, 6 findings | Real, confirmed capability, reinforced by BT's own long-established managed-connectivity heritage.
Summary
Compliance & Footprint | Confirmed HSCN (Health and Social Care Network) accreditation specifically supports NHS and healthcare-sector public bodies, reinforced by BT's own confirmed compliance-support materials describing managed logs, policies and controls to simplify staying compliant. | This research pass found no confirmation of platform-specific certifications (FedRAMP, ISO 27001 specifically for the SASE service, SOC 2) distinct from BT Group's broader, much larger corporate compliance posture - a genuine, specific gap worth closing directly for buyers with formal, platform-level certification requirements.
Summary
Mature NetOps/SecOps team | Conditional fit | Mature teams get real, confirmed flexibility via the confirmed co-managed option, though this platform's core, most extensively evidenced strength centres on fully-managed delivery rather than deep, self-directed technical control for sophisticated in-house teams specifically | Mature teams should confirm the exact RACI split directly, per Netify's own independent research recommendation | Not assessed | A reasonable fit for teams specifically wanting the co-managed flexibility option; teams wanting maximum self-directed, self-managed control should confirm this platform's fully-managed default model and RACI boundaries fit their preference directly.
Summary
Global multinational | Good fit, evidenced | The confirmed case study directly describes a multi-country deployment, reinforced by BT's own confirmed international network reach | Needs Netify/buyer to verify specific-country coverage directly, given the Table 7 general-versus-specific coverage-detail gap outside the UK | Custom enterprise pricing | Real, credible fit for this buyer profile, backed by a specific, real, detailed multi-country case study, though country-by-country coverage detail beyond the UK wasn't independently itemised.
Summary
Support/service reality | Genuinely well-evidenced via multiple, independently-corroborated confirmations - 24x7 NOC and SOC/MDR capability, severity SLAs, and change-window processes are all confirmed both by BT's own materials and Netify's independent research - though specific, numeric SLA figures were not found published. | Table 8 | Medium-High (structural capability well-confirmed; specific numeric SLA figures are not) | Present the confirmed, corroborated NOC/SOC/MDR capability with genuine confidence, while requesting specific, numeric SLA figures directly before finalising any support-SLA-sensitive procurement decision.
Present the confirmed, corroborated NOC/SOC/MDR capability with genuine confidence, while requesting specific, numeric SLA figures directly before finalising any support-SLA-sensitive procurement decision.
Summary
Multi-vendor SASE integration | Not the platform's primary emphasis in the sources reviewed - BT's core positioning centres on a single managed contract spanning access, CPE, and a chosen underlying vendor platform (Fortinet, Meraki, or Versa) rather than explicitly marketed best-of-breed pairings with vendors outside its own confirmed platform partnerships | Existing security/identity tools already in place | Not itemised | Not itemised | Not quantified | N/A | N/A | A specific, worth-stating architectural-philosophy distinction - BT's own confirmed strategy favours managed delivery of one of a small number of named, established vendor platforms (Fortinet, Meraki, Versa) rather than orchestrated integration with a broader ecosystem of third-party SASE/SSE vendors.
Summary
SME | Conditional fit | BT's core positioning, per Netify's own independent research, centres on fully-managed delivery for larger, more complex estates rather than confirmed SME-specific packaging; no SME-specific pricing tier or positioning was found in this pass | Minimal internal skills needed given the confirmed fully-managed default model | No confirmed entry-level pricing tier found in this pass | A genuine, specific evidence gap for SME-specific fit - worth confirming directly rather than assuming this platform is optimised for the smallest buyer segment.
Summary
What implementation challenges should buyers expect? (mandatory) | Expect a genuinely low customer-effort deployment for the core, fully-managed path, reinforced by a real, detailed case study describing exactly this experience. Expect to confirm directly which specific underlying vendor platform (Fortinet, Meraki, or Versa) is being proposed, since capability and packaging vary by platform. Expect the commercial conversation to require a direct BT quote from the start, given the confirmed absence of published, first-party pricing. | Tables 6, 9, 16, 17 | Medium-High | Each expectation is traceable to a specific, evidenced finding elsewhere in this profile.
Each expectation is traceable to a specific, evidenced finding elsewhere in this profile.
Summary
Firewall consolidation | Evidenced via the confirmed BT Managed Fortinet Firewall product, combined with SD-WAN in the confirmed case study specifically to provide centralised, edge-based security | Existing firewall infrastructure potentially retired | IT/security team | BT-managed | Not quantified with a specific timeline | Not itemised | Not detailed | The underlying capability is genuinely well-evidenced via a real, detailed case study combining SD-WAN and managed firewall together as a single, coordinated migration.
Summary
Reporting reality | Strong specifically for centralised network/security visibility and compliance-relevant logging, reinforced by both BT's own direct materials and a real case study; weaker or unconfirmed on application-performance, DLP-event, and executive-dashboard reporting, none of which were confirmed as distinct, named products in this research pass. | Table 10 | Medium-High for centralised visibility and compliance logging; Low for other reporting categories | Present the centralised-visibility and compliance-logging strengths specifically rather than imply comprehensive reporting maturity across every category.
Present the centralised-visibility and compliance-logging strengths specifically rather than imply comprehensive reporting maturity across every category.
Summary
MPLS to SD-WAN migration | Genuinely well-evidenced via a real, detailed case study directly describing a legacy-to-modern connectivity transition, with a customer moving toward an over-the-internet connection approach specifically | Existing legacy connectivity potentially coexisting during transition, per the confirmed flexible-underlay architecture | IT team, though substantially reduced given the confirmed fully-managed model | BT-managed, per the confirmed fully-managed default | Not quantified with a specific timeline in the source reviewed | The confirmed case study directly names the risk this scenario addresses: the customer 'couldn't afford to handle a network transformation like this in-house' | The confirmed fully-managed delivery model directly addresses the named in-house-resource-constraint risk | Genuinely well-evidenced via a real, detailed customer example directly describing this exact migration scenario and the specific business constraint (lack of in-house resources) that drove the decision.
Summary
Large enterprise | Strong fit, extensively evidenced | A real, detailed case study describes exactly this profile - a global, multi-country financial-services enterprise unable to manage a network transformation in-house, reinforced by BT's own established position as a major, large-scale UK and international managed service provider | Requires coordination between internal IT and BT-managed delivery, though substantially reduced by the confirmed fully-managed default | Custom enterprise pricing, quote-based | Genuinely the best-evidenced buyer profile in this entire table - a real, detailed, primary-sourced case study directly confirms fit for exactly this buyer type.
Summary
Biggest operational advantage | A real, detailed case study directly demonstrates BT's fully-managed delivery model successfully resolving a genuinely challenging scenario - a global, multi-country network transformation the customer could not handle in-house - with confirmed, specific outcomes including network segmentation and centralised visibility. | Table 9, 18 | High | Directly quotable with the specific, real case-study detail for credibility, even without the customer's name disclosed.
Directly quotable with the specific, real case-study detail for credibility, even without the customer's name disclosed.
Summary
Strength | A real, detailed, primary-sourced case study demonstrates concrete, specific technical and business outcomes for a genuinely challenging scenario (global, multi-country network transformation with insufficient in-house resources) | Buyers get real, checkable evidence of BT's capability for complex, large-scale, multi-country deployments, even without the customer's name disclosed | Best: large, multi-country enterprises, particularly in financial services. Less relevant: buyers wanting a fully-named, quotable customer reference specifically | Medium-High | Genuinely credible, specific evidence - real technical and business detail rather than generic marketing language, tempered only by the customer's anonymisation.
Buyers get real, checkable evidence of BT's capability for complex, large-scale, multi-country deployments, even without the customer's name disclosed
Summary
SSE deployment to remote users | Not evidenced with specific detail in sources reviewed, consistent with the broader Table 5 finding that remote-user/client-side evidence is thinner than the site-to-site/sector-positioning side of the platform | Not itemised | Not itemised | Not itemised | Not quantified | Not itemised | Not detailed | A genuine, specific evidence gap for this exact scenario, consistent with the pattern found throughout Table 5.
Summary
Deployment reality | Genuinely well-evidenced as low-effort for the customer under BT's confirmed fully-managed default model, backed by a real, detailed case study; the confirmed co-managed alternative requires buyers to verify the exact RACI split directly rather than assume equivalent customer control. | Tables 6, 9, 17, 18 | High for the fully-managed path specifically; Medium for the co-managed alternative pending direct RACI confirmation | Present the fully-managed deployment evidence with genuine confidence, backed by real, specific case-study detail, while flagging the co-managed RACI-confirmation need directly for buyers considering that path.
Present the fully-managed deployment evidence with genuine confidence, backed by real, specific case-study detail, while flagging the co-managed RACI-confirmation need directly for buyers considering that path.
Summary
Deployment & Ops | Genuine, confirmed field-engineering depth and UK-wide access-network ownership via Openreach, reinforced by a real, detailed (if anonymised) case study describing a full global, multi-country managed SD-WAN and firewall deployment. | BT's own positioning, per Netify's independent research, is explicit that a DIY/self-managed model is 'not BT's primary positioning' - buyers wanting a lighter-touch, self-administered platform should confirm the co-managed model and customer control boundaries directly via RACI documentation and a portal demonstration before committing.
Summary
Procurement watch-out | BT has offered managed SASE under at least two distinct underlying technology generations in recent years - a VMware-based service launched January 2022, and the current, confirmed Fortinet-based service expanded in late 2025 - buyers researching this vendor's SASE history should confirm which generation any given proposal, reference, or public materials actually describe | Buyers doing extended, multi-source due diligence should verify they are evaluating current, correctly-dated materials, and confirm the status of any legacy VMware-based deployments directly if relevant to their own situation | Most relevant to buyers doing extended research who may encounter older, VMware-era BT SASE references alongside current, Fortinet-era materials | Table 1, 12 findings | High (both technology generations are directly, primary-sourced confirmed with specific dates) | Worth flagging directly and early - Netify should note explicitly to any buyer that BT's current managed SASE offering is Fortinet-based (from late 2025), distinct from an earlier, VMware-based service BT offered from January 2022.
Buyers doing extended, multi-source due diligence should verify they are evaluating current, correctly-dated materials, and confirm the status of any legacy VMware-based deployments directly if relevant to their own situation
Summary
Questions to ask before recommending it | 1) Exactly which underlying SASE platform (Fortinet or Meraki) is being proposed for this specific deployment, and why? 2) What does the co-managed RACI split actually look like in practise, with a live portal demonstration? 3) Beyond HSCN, does the specific SASE service itself carry any independently-verified certifications distinct from BT Group's broader corporate posture? 4) Can BT provide a fully-named customer reference, and what is the current status of any legacy VMware-based SASE deployments? | Synthesis of Tables 6, 12, 13, 18 | High | A direct, reusable question set for Netify's advisory conversations with buyers considering BT Managed SASE.
A direct, reusable question set for Netify's advisory conversations with buyers considering BT Managed SASE.
Summary
Strength | Confirmed, genuine multi-platform flexibility - managed SD-WAN on Cisco Meraki and Versa, managed SASE on Fortinet and Meraki - gives buyers real platform choice within a single managed contract | Buyers can select the underlying vendor platform that best fits their specific technical requirements without needing to manage multiple separate vendor relationships directly | Best: buyers wanting platform flexibility without separate procurement relationships. Less relevant: buyers who have already firmly decided on a specific, named SASE platform vendor directly | High | A specific, confirmed, genuine differentiator, though it also means buyers must do more work to confirm exactly which platform and packaging applies to their specific proposal.
Buyers can select the underlying vendor platform that best fits their specific technical requirements without needing to manage multiple separate vendor relationships directly
Summary
AI reality | A real, direct, primary-sourced confirmation of AI-powered proactive threat detection exists, layered on top of the underlying vendor platform (principally Fortinet); the precise split between BT's own value-add and the underlying platform's native AI capability was not itemised separately, and no single, distinctly-named AI copilot product was confirmed. | Table 11 | Medium-High | Represent the confirmed AI-powered threat-detection capability with genuine confidence, while being clear that the specific technical contribution of BT versus the underlying Fortinet platform wasn't independently itemised in this pass.
Represent the confirmed AI-powered threat-detection capability with genuine confidence, while being clear that the specific technical contribution of BT versus the underlying Fortinet platform wasn't independently itemised in this pass.
Summary
Merger/acquisition integration | Not documented via a named customer M&A-specific scenario in sources reviewed | Not itemised | Not itemised | Not itemised | Not quantified | Not itemised | Not detailed | Evidence gap for this specific scenario.
Summary
Mid-market | Good fit, evidenced at a general level | BT's confirmed multi-platform flexibility and managed-service model support genuine mid-market applicability, though no named mid-market case study was found specifically | Benefits from, but doesn't strictly require, extensive internal networking expertise given the confirmed managed model | Not itemised | Not found in a Tier 1-2 source in this pass at this specificity | A reasonable, though not extensively evidenced, fit for this buyer profile.
Summary
Global fit | Genuinely the strongest coverage finding in this entire profile is specifically for the United Kingdom, via BT's confirmed ownership of Openreach; international, multi-country capability is confirmed directly via a real case study, though detailed, country-by-country coverage outside the UK was not independently itemised. | Table 7, 15 | High for the UK specifically; Medium for confirmed multi-country capability generally; Low for country-level specificity outside the UK | Present the UK-coverage strength with genuine confidence, while always verifying buyer-specific country/region delivery capability directly with BT for deployments outside the UK.
Present the UK-coverage strength with genuine confidence, while always verifying buyer-specific country/region delivery capability directly with BT for deployments outside the UK.
Summary
Sector fit | Financial services is genuinely the best-evidenced sector in this entire profile, combining specific, named product positioning (ZTNA, data residency) with a real, detailed (if anonymised) case study; retail and healthcare/NHS are well-evidenced via specific, named product positioning and accreditation respectively, without individually-named case studies; manufacturing was not assessed due to an absence of evidence. | Table 14 | High for financial services; Medium for retail and healthcare; Low for sectors with no evidence | The confirmed financial-services case study and the confirmed HSCN accreditation are both worth highlighting directly for any buyer in those specific sectors.
The confirmed financial-services case study and the confirmed HSCN accreditation are both worth highlighting directly for any buyer in those specific sectors.
Summary
Limitation | No fully-named, individually-identified customer case study was found for BT's managed SD-WAN or SASE services in this research pass - the strongest available evidence is a real, detailed, but anonymised case study | Buyers wanting a fully-named, quotable customer reference to validate against have less to draw on than the pattern found among several other vendors in this category | Affects all buyer sizes wanting fully-attributable case-study evidence before committing | Table 18 findings | Medium-High (confident about the absence found in this specific research pass, though case studies may exist that weren't surfaced) | A genuine, specific gap worth flagging as a direct follow-up request to BT, even though the anonymised evidence located is itself real and credible.
Buyers wanting a fully-named, quotable customer reference to validate against have less to draw on than the pattern found among several other vendors in this category
Summary
Where does it fall behind competitors? (mandatory) | No independently-confirmed, SASE-service-specific compliance certifications (ISO 27001, SOC 2, PCI DSS, DORA) were found distinct from BT Group's broader corporate posture; no fully-named customer case study was found; and BT's own confirmed positioning is that fully self-managed delivery is not its primary model. | Tables 13, 15, 18, 19 | Medium-High | Named specifically and evidenced, not a generic hedge - the compliance-certification gap and the fully-managed-by-default positioning specifically should be raised proactively with any relevant buyer.
Named specifically and evidenced, not a generic hedge - the compliance-certification gap and the fully-managed-by-default positioning specifically should be raised proactively with any relevant buyer.
Summary
Most credible differentiator | Genuine, structural ownership of the UK's dominant last-mile access network via Openreach, combined with confirmed multi-platform flexibility (Fortinet, Meraki, Versa) within a single managed contract - a real, checkable infrastructural advantage no platform-only SASE vendor can replicate. | Tables 7, 12, 19 | High | This is the single sentence Netify's comparison engine could most confidently quote for this vendor specifically, particularly for UK-anchored buyers.
This is the single sentence Netify's comparison engine could most confidently quote for this vendor specifically, particularly for UK-anchored buyers.
Summary
Questions Netify still cannot verify | Independently-confirmed, SASE-service-specific ISO 27001, SOC 2, PCI DSS, DORA, and NIS2 status; specific, published pricing figures at any tier; named, formal support-tier SLA figures beyond the general confirmed existence of severity SLAs; a fully-named customer case study; and the current status of any legacy VMware-based SASE deployments. | Synthesis of Tables 8, 13, 16, 18 | N/A - explicitly unresolved | This list should drive the next follow-up (a direct BT briefing) before this profile is considered fully closed out, particularly the compliance-certification and named-case-study questions given their direct relevance to regulated-sector and general procurement confidence.
This list should drive the next follow-up (a direct BT briefing) before this profile is considered fully closed out, particularly the compliance-certification and named-case-study questions given their direct relevance to regulated-sector and general procurement confidence.
Summary
Limitation | This research pass found no independently-confirmed, SASE-service-specific certifications (ISO 27001, SOC 2, PCI DSS, DORA) distinct from BT Group's much larger, broader corporate compliance posture | Buyers with formal, platform-level compliance-attestation requirements cannot currently verify these specific certifications for the SASE service itself from public sources | Affects regulated-industry buyers most specifically, particularly financial services given the confirmed direct sector positioning without matching confirmed certifications | Table 13 findings | Medium-High (confident about the absence found in this specific research pass, though this may reflect a research-pass limitation given BT Group's own substantial scale) | A genuine, specific gap worth flagging directly and early with any buyer requiring formal, platform-level compliance certification, particularly in financial services given the confirmed sector-specific positioning without matching confirmed certifications.
Buyers with formal, platform-level compliance-attestation requirements cannot currently verify these specific certifications for the SASE service itself from public sources
Summary
Overall Netify Assessment | BT's most credible, best-evidenced strength is genuinely structural rather than a proprietary technology claim: confirmed ownership of Openreach gives it a real, checkable infrastructural advantage over platform-only SASE vendors, reinforced by confirmed, genuine multi-platform flexibility (Fortinet, Meraki, Versa) within a single managed contract. That combination, backed by a real, detailed (if anonymised) case study demonstrating concrete capability for complex, multi-country deployments, makes this a credible shortlist candidate - particularly for UK-anchored organisations, large multi-country enterprises, and NHS/social-care-adjacent public bodies specifically. The profile is honest about real, specific gaps: no independently-confirmed, SASE-service-specific compliance certifications distinct from BT Group's broader corporate posture, no fully-named customer case study, and a confirmed core positioning that fully self-managed delivery is not BT's primary model. This profile is solid enough to support initial shortlist guidance for UK-anchored, large-enterprise, and public-sector buyers specifically, but the flagged compliance-certification gap and the absence of a fully-named case study should both be closed out directly with BT before use in a high-stakes, compliance-sensitive procurement decision. | Whole profile | Medium-High overall | Recommend direct BT engagement to confirm platform-specific compliance certifications and obtain a fully-named customer reference before this profile supports a high-stakes procurement decision.
Recommend direct BT engagement to confirm platform-specific compliance certifications and obtain a fully-named customer reference before this profile supports a high-stakes procurement decision.
Summary
When would Netify recommend it? (mandatory) | When a buyer specifically wants genuine underlay/last-mile accountability via BT's confirmed Openreach ownership; when a buyer wants a single managed contract spanning connectivity, hardware, and a choice of SASE platform; or when a buyer is an NHS/social-care-adjacent UK public body specifically, given confirmed HSCN accreditation. | Synthesis of Tables 7, 12, 13, 15 | High | A clear, actionable recommendation trigger set for Netify's comparison tool to apply directly.
A clear, actionable recommendation trigger set for Netify's comparison tool to apply directly.
Summary
Strength | Genuine, confirmed ownership of Openreach gives BT direct control over one of the deepest UK last-mile access networks in the market - a structural advantage no platform-only SASE vendor can replicate | Buyers get genuine underlay accountability within a single corporate group, rather than a SASE platform layered on top of a third-party-owned, separately-accountable access network | Best: UK-anchored organisations prioritising underlay accountability and field-engineering depth. Less relevant: buyers with no particular UK-connectivity dependency | High | Genuinely BT's clearest, most structurally distinctive differentiator - a real, checkable, corporate-ownership fact rather than a marketing claim.
Buyers get genuine underlay accountability within a single corporate group, rather than a SASE platform layered on top of a third-party-owned, separately-accountable access network
Summary
Co-managed transition | Confirmed as an available option (Table 6, 9), though buyers should confirm the exact RACI split and request a portal demonstration directly, per Netify's own independent research recommendation | Existing tools/processes reviewed against BT's specific co-managed delivery model | Customer chooses desired level of involvement | BT-managed, with confirmed customer-accessible elements under the co-managed option | Not quantified | N/A | N/A | Real, confirmed option exists, though this is a specific area worth confirming directly rather than assuming, given BT's core positioning centres on fully-managed delivery by default.
Summary
Who is this genuinely best suited for? (mandatory) | UK-anchored organisations wanting genuine underlay accountability via BT's confirmed ownership of Openreach; large, multi-country enterprises wanting a single managed contract combining connectivity, hardware, and a choice of SASE platform; and NHS/social-care-adjacent public bodies specifically, given confirmed HSCN accreditation. | Tables 1, 7, 13, 15 | High | Buyers matching this profile can proceed with genuine confidence, backed by real, specific, checkable evidence rather than only generic managed-service marketing claims.
Buyers matching this profile can proceed with genuine confidence, backed by real, specific, checkable evidence rather than only generic managed-service marketing claims.
Summary
Commercial reality | No pricing exists for this service in any source found in this research pass, explicitly confirmed as quote-based by Netify's own independent research; the confirmed structural commercial model (access, CPE, vendor stack, and service tier combined into one contract) gives buyers real, useful commercial framing even without published figures. | Table 16 | Medium (confident about the absence of published pricing, and about the confirmed commercial-model structure) | Route any budget conversation to a direct BT quote from the very first interaction, using the confirmed commercial-model structure (access plus CPE plus vendor stack plus service tier) to scope the conversation precisely.
Route any budget conversation to a direct BT quote from the very first interaction, using the confirmed commercial-model structure (access plus CPE plus vendor stack plus service tier) to scope the conversation precisely.
Summary
Lean IT team | Strong fit, extensively evidenced | BT's core, confirmed positioning centres on fully-managed delivery precisely to reduce internal operational burden, reinforced by a real, detailed case study describing a customer explicitly unable to manage a network transformation in-house | Minimal training investment implied by the confirmed fully-managed default model | Not assessed | A genuinely credible, well-evidenced fit - the confirmed, real customer account of exactly this scenario (insufficient in-house resources) gives this buyer profile real, concrete evidence.
Summary
Regulated organisation (UK-specific) | Strong fit specifically for UK healthcare/social-care requirements, given the confirmed HSCN accreditation; conditional for other regulated frameworks | HSCN is confirmed directly and is a genuine, specific, UK-relevant differentiator; PCI DSS, DORA, ISO 27001, and SOC 2 were not independently confirmed for the SASE service specifically | Buyer must independently verify sector-specific compliance status directly with BT for anything outside the confirmed HSCN scope | Not assessed | Table 13 findings | A genuinely strong, specific compliance foundation for UK healthcare/social-care buyers specifically, tempered by the specific, worth-flagging absence of confirmed platform-level certifications for other regulated frameworks.
Summary
Commercials | A single managed contract can combine access, CPE, the underlying vendor stack, and service-tier options together, reducing multi-vendor procurement complexity for buyers who value contractual simplicity. | No complete, public enterprise price was found in any source reviewed - pricing is confirmed quote-based, consistent with the pattern for the large majority of managed-service and carrier-delivered SASE offerings.
Summary
Where does it stand out? (mandatory) | Genuine, structural ownership of the UK's dominant last-mile access network via Openreach; confirmed, genuine multi-platform flexibility (Fortinet, Meraki, Versa) within one managed contract; and a real, detailed (if anonymised) case study demonstrating concrete capability for complex, multi-country deployments. | Tables 7, 12, 18, 19 | High | These are the claims Netify can make most confidently and specifically to buyers, each backed by real, checkable, primary-sourced or independently-researched evidence.
These are the claims Netify can make most confidently and specifically to buyers, each backed by real, checkable, primary-sourced or independently-researched evidence.
Public evidence sources
16 records- 01BT Business - Financial services SD-WAN case study (Agile Connect + BT Managed Fortinet Firewall; anonymised global financial-services customer) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 02BT Business - Managed SASE Solutions page (sector-specific positioning: retail, financial services, public sector; SASE cloud node architecture) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 03BT Business - SD-WAN & SASE Solutions overview page · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 04BT Newsroom - press release: BT launches a new managed SASE service powered by Fortinet · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 05Business Wire (via wire-distribution mirror) - VMware SASE Launched by BT As A Managed Service (historical, 2022 VMware-based managed SASE launch; 150+ PoP global network reference) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 06Investegate (RNS regulatory announcement) - BT Group plc: Results for the full year to 31 March 2026 (FY2026 revenue £19.7bn, adjusted EBITDA £8.2bn, profit before tax £1.4bn, capex £5.1bn, fibre-build and NPS detail) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 07Comms Business - BT launches new managed SASE service (independent trade-press reporting) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 2
- 08Computer Weekly - BT unveils managed SASE service (independent trade-press reporting) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 2
- 09Forbes - BT Group | Company Overview & News (segment structure: Consumer, Enterprise, Global, Openreach, Other) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 10GlobalData - BT Group Plc Company Profile (managed telecommunications, security, network and secure digital products/services portfolio description) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 11Netify - Managed Service Providers Comparison 2026 (independent Netify research; BT positioned as largest UK managed network/security provider; multi-platform confirmation: Cisco Meraki, Versa, Fortinet, Meraki SASE; BT Security MDR; HSCN accreditation) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 12Netify SASE Marketplace - BT Business / BT Global capability profile (independent Netify research; 40-feature evidence-graded capability card, reviewed 2026-05-22; dual-hub/diverse last-mile design, Openreach-adjacent last mile, owned core, quote-based commercial model) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 13PitchBook - BT Group 2026 Company Profile (market cap, trailing 12-month revenue, Openreach fibre-coverage detail) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 14Umbrex - BT Group Strategy and Business Model (independent company-profile research; FY2024 segment/revenue detail, strategic priorities) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 15Wikipedia - Openreach (used only for facts independently corroborated elsewhere in this pass: 2006 founding, Ofcom/Enterprise Act 2002 regulatory origin, 2023/24 revenue and operating income) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 16ZoomInfo - BT Group Overview & News (segment structure: Global Services, Retail, Wholesale, Openreach; named executives) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
Profile contract provider-public/1.0.0. Machine-readable record: JSON.