NNetify

Netify provider research record

Cisco Systems, Inc. (trading and profile display name: Cisco; SASE portfolio branded Cisco SASE, spanning Cisco Secure Access, Cisco Catalyst SD-WAN, Meraki SD-WAN and Cisco Secure Connect) SASE and SD-WAN profile

Publication state
Published
Reviewed
01/09/2026
Dataset
sha256-0f697fc7fc4690bb
Revision
3e7b3c72170a8c6cadaf8368

Overview

Cisco’s own materials describe SASE explicitly as ‘a journey - you can start with SD-WAN or SSE and converge over time’, which is a different pitch to Cato’s, Zscaler’s, Netskope’s or Palo Alto’s single-platform-from-day-one story. In practise, ‘Cisco SASE’ means choosing between Cisco Secure Access (cloud-delivered SSE, evolved from Cisco Umbrella), Cisco Catalyst SD-WAN (the enterprise-grade fabric, formerly Viptela) or Meraki SD-WAN (the simpler, cloud-first option), and Cisco Secure Connect (a turnkey bundle of Secure Access plus Meraki SD-WAN specifically). That breadth is a strength for existing Cisco networking customers - the case-study evidence (Peco Foods, George Sink P.A., Mitchells & Butlers) is credible and specific - and a source of buyer confusion for anyone evaluating ‘Cisco’ as a single SASE product the way they would Zscaler or Netskope. Cisco’s compliance story is solid at FedRAMP Moderate (not High), and its AI investment is current - a February 2026 announcement specifically addressing agentic AI traffic and MCP visibility within SASE is one of the more recent, specific AI announcements to come out of the SASE market.

Direct comparison

Put Cisco Systems, Inc. (trading and profile display name: Cisco; SASE portfolio branded Cisco SASE, spanning Cisco Secure Access, Cisco Catalyst SD-WAN, Meraki SD-WAN and Cisco Secure Connect) beside any provider.

Open the Netify comparison engine with both providers already selected. Every result is calculated from the public 40-capability evidence matrix.

Agent and MCP connectedprovider-comparison/1.0.0

No sign-in required. The shortlist remains shareable. Publishing and supplier access stay separate.

Find which providers match your exact needs

Move from a two-provider comparison into the live Netify RFP Builder and evaluate the wider market against your project.

Open the RFP Builder

Agent-accessible research

Ask the Cisco Systems, Inc. (trading and profile display name: Cisco; SASE portfolio branded Cisco SASE, spanning Cisco Secure Access, Cisco Catalyst SD-WAN, Meraki SD-WAN and Cisco Secure Connect) research record

Answers are calculated from the published record below. Missing evidence remains unconfirmed and every result identifies its source revision.

Record summary

Current products
10
Capabilities
67
Coverage records
12
Service models
34
Compliance records
13
Integration records
20
Sector records
10
Evaluation records
50
Public sources
49

Products and delivery

10 records
ProductCategoryRelationshipDelivery modelTarget buyer
Cisco AI DefenceAI application and agentic-AI securityNativeCloud-deliveredSecurity/compliance teams
Cisco Catalyst SD-WANEnterprise-grade SD-WAN fabric (formerly Viptela)NativeCloud-managed, on-premises appliancesLarger, complex WAN estates
Cisco DuoMulti-factor authentication, identity securityNativeCloud-deliveredIdentity/security teams
Cisco ISENetwork access control, identity-based policyNativeOn-premises or cloud, integrates via pxGrid CloudNetwork/security admins
Cisco Secure AccessCloud-delivered SSE (evolved from Cisco Umbrella)NativeCloud-deliveredAll buyers
Cisco Secure ConnectTurnkey unified SASE bundleNativeCloud-delivered, managed via Meraki dashboardBuyers wanting one bundled Meraki SD-WAN + Secure Access subscription
Cisco XDRExtended detection and responseNativeCloud-deliveredSOC teams
Meraki SD-WANCloud-first SD-WANNativeCloud-managed via Meraki dashboardDistributed, simpler estates wanting cloud-first management
Splunk (via Cisco acquisition)SIEM, security analyticsNativeCloud or on-premises Splunk deploymentSOC/SecOps teams
ThousandEyesDigital experience monitoring and network assuranceNativeCloud-delivered, agent-basedIT operations, NetOps teams

Capability evidence

67 records
Ai Automation14 records
CapabilitySupportConfidenceFreshnessQualification
AI assistant/copilotRequires ConfirmationUnresolvedCurrentNot confirmed
AI data protection controlsRequires ConfirmationUnresolvedCurrentSame as above
Anomaly detectionRequires ConfirmationUnresolvedCurrentDepth of the ML methodology not disclosed
Automated policy recommendationUnknownUnresolvedCurrentNot confirmed
Automated remediationRequires ConfirmationUnresolvedCurrentNot confirmed
Capacity/path optimisationSupportedUnresolvedCurrentSpecific to the Meraki path; Catalyst SD-WAN-equivalent detail thinner in this pass
Configuration generationUnknownUnresolvedCurrentNot confirmed
Digital experience diagnosticsSupportedUnresolvedCurrentSame as above
Generative AI application controlsRequires ConfirmationUnresolvedCurrentAnnounced only months before this profile's research; real-world GA/maturity status for each sub-capability should be confirmed directly given the announcement's newness
Natural-language queryingUnknownUnresolvedCurrentNot confirmed
Report summarisationUnknownUnresolvedCurrentNot confirmed
Root-cause analysisSupportedUnresolvedCurrentSourced via a case study summary rather than a detailed technical mechanism description
Threat detection/classificationRequires ConfirmationUnresolvedCurrentSame as above
User/entity behaviour analyticsRequires ConfirmationUnresolvedCurrentSourced via a customer quote on a marketing page rather than a technical product datasheet
Architecture15 records
CapabilitySupportConfidenceFreshnessQualification
5G/LTE supportSupportedMedium HighCurrentNative, implied via Meraki Z-series and MG-series cellular gateway devices referenced in Cisco's own SASE/SD-WAN documentation index
Application identificationSupportedMedium HighCurrentNative - application-aware routing referenced for both SD-WAN products
Branch LAN/WLAN integrationSupportedHighCurrentNative - Meraki's portfolio includes switches and access points managed through the same dashboard as MX/MG SD-WAN appliances, a genuine differentiator versus the other four vendors profiled, none of which compete directly in campus LAN/Wi-Fi
Brownfield migration supportSupportedHighCurrentNative - the Peco Foods case study explicitly describes migrating from Umbrella DNS to Secure Access while deploying Cisco SD-WAN, and Meraki spokes maintain existing tunnels during Secure Access onboarding
Dynamic path selectionNot SupportedHighCurrentNative - Meraki Auto VPN establishes multiple tunnels across available uplinks to two data centres with automatic no-touch failover
Edge form factorsUnknownMedium HighCurrentMeraki MX/MG appliances (multiple size tiers, MX75 through MX450 per reseller product listings) for Meraki SD-WAN; separate Catalyst SD-WAN edge devices for the enterprise-grade product
Forward error correction / packet duplicationRequires ConfirmationMedium HighCurrentNative, specifically confirmed in the AI-traffic context - the February 2026 AI-aware SASE announcement explicitly names 'packet duplication' as an AI traffic optimization technique
High availabilitySupportedHighCurrentNative - Meraki spokes maintain existing MX Hub tunnels while establishing new Auto VPN tunnels to Secure Access, ensuring 'zero disruption to your current routing architecture' per Cisco's own materials
LEO satellite supportUnknownLowCurrentUnknown - not found in sources reviewed
Local internet breakoutRequires ConfirmationHighCurrentNative - Cisco Umbrella (now Secure Access) has been positioned as the direct-internet-breakout security layer for branch sites since well before the SASE category existed
QoS and traffic engineeringSupportedMediumCurrentNative, implied via application-aware routing and traffic optimization language across multiple sources
Segmentation / VRF capabilityUnknownLowCurrentUnknown - not found in sources reviewed
Supported WAN underlaysSupportedMedium HighCurrentNative - standard IPSec VPN support alongside native SD-WAN, per Cisco Secure Connect's own solution overview; MPLS coexistence implied by 'any MX/MG licence tier' compatibility statement
Virtual/cloud edge supportRequires ConfirmationLow MediumCurrentNot independently confirmed as a distinct virtual-appliance form factor for either SD-WAN product in sources reviewed
Zero-touch provisioningRequires ConfirmationHighCurrentNative - Meraki's cloud-managed dashboard model is built around zero-touch deployment, consistent with the George Sink P.A. customer quote describing a 2-hour full SASE deployment
Core Capabilities15 records
CapabilitySupportConfidenceFreshnessQualification
Application-aware routingSupportedHighCurrentNone identified
CASB - APIRequires ConfirmationLowCurrentNot confirmed as distinct from inline CASB
CASB - inlineSupportedMediumCurrentSame tier-gating caution as SWG above
Cloud firewall / cloud network securitySupportedHighCurrentTier-gated
DNS securitySupportedHighCurrentNone identified
Data loss preventionSupportedMedium HighCurrentTier placement not fully detailed
Digital experience monitoringSupportedHighCurrentSeparate product/licence from core SASE tiers
Firewall as a ServiceSupportedHighCurrentTier-gated per third-party analysis
Multi-cloud networkingSupportedMedium HighCurrentSpecific hyperscaler-by-hyperscaler detail not itemised to the same depth as Netskope's named cloud WAN integrations
SD-WANSupportedHighCurrentBuyers must choose between two distinct SD-WAN products, each with different management models - a genuine decision point unique to Cisco among the vendors profiled
SaaS security postureRequires ConfirmationLowCurrentNot confirmed
Secure web gatewaySupportedMedium HighCurrentTier-gated - lower Umbrella-heritage tiers (DNS-only) do not include full SWG per third-party analysis
Threat intelligenceRequires ConfirmationHighCurrentNone identified
WAN optimisationSupportedMedium HighCurrentDepends on which of the two SD-WAN products is chosen
ZTNASupportedHighCurrentNone identified
Remote Access9 records
CapabilitySupportConfidenceFreshnessQualification
Clientless accessRequires ConfirmationUnresolvedCurrentUnknown
Contractors/third partiesRequires ConfirmationUnresolvedCurrentUnknown
Managed laptopsSupportedUnresolvedCurrentNone identified
Mobile devicesRequires ConfirmationUnresolvedCurrentNone identified
Privileged accessUnknownUnresolvedCurrentNot confirmed
Remote browser isolationRequires ConfirmationUnresolvedCurrentUnknown
Remote browser isolationRequires ConfirmationLow MediumCurrentNot confirmed
Unmanaged/BYOD devicesRequires ConfirmationUnresolvedCurrentDepth of BYOD-specific policy control not independently confirmed
VDI environmentsUnknownUnresolvedCurrentNot confirmed
Reporting Analytics14 records
CapabilitySupportConfidenceFreshnessQualification
Application performanceSupportedUnresolvedCurrentRequires separate ThousandEyes licence
Compliance reportingUnknownUnresolvedCurrentNot confirmed
Custom reportsUnknownUnresolvedCurrentNot confirmed
DLP eventsRequires ConfirmationUnresolvedCurrentNot confirmed
Executive dashboardRequires ConfirmationUnresolvedCurrentNot confirmed
Network healthSupportedUnresolvedCurrentRequires separate ThousandEyes licence
Raw log accessRequires ConfirmationUnresolvedCurrentNot confirmed
Remote-user experienceSupportedUnresolvedCurrentRequires separate ThousandEyes licence
SLA reportingRequires ConfirmationUnresolvedCurrentNot confirmed
Scheduled reportsUnknownUnresolvedCurrentNot confirmed
Security eventsSupportedUnresolvedCurrentNot confirmed
Site and circuit performanceSupportedUnresolvedCurrentRequires separate ThousandEyes licence
Threat reportingSupportedUnresolvedCurrentNot confirmed
User experienceSupportedUnresolvedCurrentRequires separate ThousandEyes licence

Geographic coverage

12 records
GeographyDelivery typeRelationshipConfidenceQualification
Africa coverageUnknown - Not Itemised In Sources ReviewedUnknownLowUnknown - not itemised in sources reviewed | Unknown | Not specified | No named data centres found | Not found in a Tier 1-2 source in this pass | Low | Evidence gap, consistent across all five vendors' profiles for this region.
Asia-Pacific coverageUnknown - No Specific Evidence Found In This PassUnknownLowUnknown - no specific evidence found in this pass | Unknown | Not specified | No named data centres or customer evidence found for this region specifically | Not found in a Tier 1-2 source in this pass | Low | Evidence gap.
Carrier interconnectsUnknown - Not Itemised In Sources ReviewedUnknownLowUnknown - not itemised in sources reviewed | Unknown | Unknown | No specific carrier/exchange detail found | Not found in a Tier 1-2 source in this pass | Low | Evidence gap.
China coverageUnknown - No China-Specific Data-Centre Or Licensed-PoP Detail Found In Sources ReviewedUnknownLowUnknown - no China-specific data-centre or licensed-PoP detail found in sources reviewed | Unknown | Not specified | No named China presence found, in contrast to Cato's explicit Beijing/Shanghai/Shenzhen PoPs; Cisco's own general corporate materials do reference operating in China as a market, but not specific to Secure Access infrastructure | Not found in a Tier 1-2 source in this pass | Low | Same evidence gap flagged for Zscaler, Netskope and Palo Alto - do not assume parity with Cato's specific China story.
Data residency choicesUnknown - No Dedicated Data-Sovereignty Architecture Description Found For Cisco Secure Access In This PassUnknownLowUnknown - no dedicated data-sovereignty architecture description found for Cisco Secure Access in this pass | Unknown | Not specified | A genuine gap relative to Zscaler's isolated-plane architecture and even Netskope's region-specific certifications | Not found in a Tier 1-2 source in this pass at sufficient detail | Low | Worth a direct question - Cisco's FedRAMP-authorized government boundary (Table 13) at least implies some US data-residency capability, but the broader commercial-platform architecture isn't independently confirmed.
Latin America coverageUnknown - No Specific Evidence Found In This PassUnknownLowUnknown - no specific evidence found in this pass | Unknown | Not specified | No named data centres or customer evidence found for this region specifically | Not found in a Tier 1-2 source in this pass | Low | A genuine gap - weaker than the partial evidence found for Palo Alto (via Grupo Bimbo's Colombian operation).
Middle East coverageUnknown - Not Itemised In Sources ReviewedUnknownLowUnknown - not itemised in sources reviewed | Unknown | Not specified | No named data centres found | Not found in a Tier 1-2 source in this pass | Low | Evidence gap - weaker than Zscaler's specific Saudi Arabia evidence.
Private backboneNot Confirmed As An Owned Private Backbone In Sources ReviewedUnknownLowNot confirmed as an owned private backbone in sources reviewed | Unknown | Unknown | Architecture detail not found at sufficient depth to characterise confidently | Not found in a Tier 1-2 source in this pass | Low | A genuine evidence gap - Netify cannot currently state with confidence whether Cisco Secure Access relies on owned infrastructure, hyperscaler backbone, or internet peering, unlike the other four vendors profiled where this was established with reasonable confidence.
Public cloud on-rampsNative Via Direct SaaS And IaaS Peering, Referenced For Cisco Secure Connect Specifically, Though Hyperscaler-By-Hyperscaler Detail Not ItemisedOwnedMediumNative via direct SaaS and IaaS Peering, referenced for Cisco Secure Connect specifically, though hyperscaler-by-hyperscaler detail not itemised | Direct | Not specified by hyperscaler | Less specific than Netskope's or Palo Alto's named cloud-provider integrations | Medium | Confirmed to exist as a capability; specific technical depth is a genuine gap relative to the strongest competitor evidence.
SD-WAN gateways / cloud gatewaysMeraki Auto VPN References 'Two Data Centres' For Hub Redundancy Specifically, Though A Broader Gateway/PoP Map Wasn'T FoundOwnedLow MediumMeraki Auto VPN references 'two data centres' for hub redundancy specifically, though a broader gateway/PoP map wasn't found | Direct | Not specified beyond the two-data-centre redundancy model | Thin evidence relative to competitors | Low-Medium | The two-data-centre model is a specific, if narrow, piece of evidence - worth a direct follow-up for the full picture.
Security PoPs / service edgesUnknown - No Specific PoP Count Or Map Found In Sources Reviewed For Cisco Secure AccessUnknownLowUnknown - no specific PoP count or map found in sources reviewed for Cisco Secure Access | Unknown | Not specified | A genuine, notable evidence gap relative to the other four vendors profiled, all of which had at least a headline PoP/region figure | Not found in a Tier 1-2 source in this pass | Low | This is the single clearest 'weaker evidence' finding in this entire profile - Netify should flag this as a direct follow-up question rather than assume parity with competitors' publicly-stated PoP counts.
Sovereign/regional service optionsFedRAMP Moderate-Authorized Government Boundary Confirmed For US Federal/Public Sector (See Table 13); Non-US Sovereign Offerings Not Found In Sources ReviewedOwnedMedium HighFedRAMP Moderate-authorized government boundary confirmed for US federal/public sector (see Table 13); non-US sovereign offerings not found in sources reviewed | Direct | United States (federal/government boundary) | Sovereign offerings for non-US regions not found in sources reviewed | cisco.com Secure Access for Government At-a-Glance | Medium-High for US federal; Low for other regions | Confirmed for US federal specifically, at the Moderate baseline; UK/EU-equivalent sovereign offerings should be asked about directly.

Service models

34 records

Other

Unknown

Implied via the always-on cloud platform model, not separately itemised as a distinct claim with a specific figure | Not confirmed with a specific figure | N/A | Included for platform by inference | N/A | Not confirmed | Not found at this level of detail in a Tier 1-2 source in this pass | Reasonable inference; not independently confirmed with the specificity of Zscaler's or Netskope's equivalent evidence.

Other

Unknown

Unknown in detail - not found in sources reviewed | Presumably Meraki dashboard / Cisco Cloud Control | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in public sources reviewed | Evidence gap.

Other

Supported

ThousandEyes provides genuinely mature, well-regarded network/application assurance and root-cause diagnosis, integrating natively with Catalyst, Meraki and Webex per Cisco's own materials | ThousandEyes dashboard (separate product) | Reduced specialist requirement implied by ThousandEyes' visual, workflow-driven diagnostics | Not AI-branded to the same degree as competitors' equivalent tools in the sources reviewed | Positioned as a genuine strength given ThousandEyes' strong independent reputation in the market | Requires separate ThousandEyes licensing | ThousandEyes is genuinely one of the most respected, longest-track-record network assurance products in the industry - a real strength, evidenced by a credible public-sector case reference, though it's a separate product/licence rather than a bundled SASE feature.

Other

Requires Confirmation

Not confirmed as a distinct named service in sources reviewed | Not confirmed | N/A | Not confirmed | Not confirmed | Not confirmed | Not found in a Tier 1-2 source in this pass | Evidence gap.

Other

Unknown

Unknown - not found in sources reviewed for Meraki MX/MG or Catalyst SD-WAN device RMA/replacement terms | Not found | Not found | Not confirmed | Not confirmed | Not confirmed | Not found in a Tier 1-2 source in this pass | Evidence gap, consistent with the equivalent gap flagged for all five vendors profiled.

Other

Requires Confirmation

Implied via Cisco Talos (threat intelligence) and Cisco XDR (Advantage/Premier tiers) as named, real capabilities, though a customer-facing 'Cisco SOC service' distinct from these products wasn't confirmed | Not confirmed with a specific figure | Not itemised by location | XDR Advantage/Premier are named, tiered products per Cisco's own CrowdStrike partner page | Depends on tier | Not itemised with specific figures | cisco.com Cisco Security and CrowdStrike partner page (confirms XDR Advantage/Premier as named licensing tiers) | Talos and XDR are both genuine, well-established capabilities - the evidence gap is around a distinct managed-SOC-as-a-service offering specifically, not around Cisco's underlying threat-detection capability.

Other

Requires Confirmation

Not confirmed as a distinct named service with a specific SLA in sources reviewed, though Cisco Talos and XDR both plausibly support this function | Not confirmed | N/A | Not confirmed | N/A | Not itemised with a specific figure | Not found at this level of detail in a Tier 1-2 source in this pass | Evidence gap for a distinctly-named IR service, though the underlying Talos/XDR capability is real and well-established.

Other

Supported

Yes | Cisco Secure Access | Via nearest Secure Access cloud edge (specific PoP count/map not found in this pass) | Centralised, Cisco Cloud Control / Meraki dashboard | All customers - core delivery model for the security layer | Low-Moderate | N/A - default | The default operating model for the security layer; underlying PoP infrastructure detail is a genuine evidence gap relative to the other four vendors profiled.

Other

Supported

Yes, via either Meraki MX/MG or Catalyst SD-WAN edge devices | Meraki MX/MG appliance or Catalyst SD-WAN edge device (buyer's choice) | Edge → Secure Access via Auto VPN (Meraki) or equivalent Catalyst mechanism | Meraki dashboard or Catalyst SD-WAN manager, depending on product chosen | Branch offices | Low (per Meraki's zero-touch, dashboard-driven model) | Coexists with existing MX Hub tunnels during Secure Access onboarding per Cisco's own materials | Genuinely well-evidenced for the Meraki path specifically; Catalyst SD-WAN-specific onboarding detail is thinner in the sources reviewed.

Other

Requires Confirmation

Not confirmed as a distinct named MDR service (comparable to Zscaler's or Palo Alto's Unit 42-equivalent) in sources reviewed, though Cisco XDR Advantage/Premier tiers and Talos threat intelligence provide the underlying technical capability | Not confirmed | Not itemised by location | XDR Advantage/Premier are named tiers | N/A | Not itemised with a specific figure | cisco.com Cisco Security and CrowdStrike partner page | A genuine evidence gap for a distinctly-branded MDR service specifically, though the underlying XDR/Talos capability is real and well-documented - worth a direct follow-up on whether Cisco offers a fully-managed MDR service under a specific name.

Other

Unknown

Cisco Secure Client install, provisioned via Duo, Okta, or Entra ID per Cisco's own integration documentation | Meraki dashboard / Cisco Cloud Control + Secure Client | End-user self-install typical, benefiting from Secure Client's long AnyConnect-lineage track record | Provisioning automation confirmed via Okta/Duo/Entra ID integration guides | Low, given Secure Client's maturity | None significant identified | Genuinely well-documented, current (May 2026-dated) integration guides for three major IdPs - solid, specific, recent evidence.

Other

Partner Delivered

Implied via Cisco's partner ecosystem (BlueAlly/CloudWifiWorks explicitly offers 'consulting' and design services for Cisco SASE), though not itemised with a specific cost range the way it was for Zscaler, Netskope or Palo Alto | N/A | N/A | Available via partners | N/A | N/A | Real but the least specifically evidenced Professional Services picture of the five vendors profiled - no cost range or scope detail was found in this pass.

Other

Requires Confirmation

Not independently confirmed as a distinct capability in sources reviewed | Unknown | Unknown | Unknown | Unknown | Not confirmed | See Table 5 - a genuine, specific evidence gap relative to three of the other four vendors profiled.

Other

Unknown

Cloud-delivered updates for Secure Access are automatic by design; Meraki MX/MG firmware updates are cloud-managed and scheduled via the dashboard, a well-established Meraki operating pattern | Meraki dashboard | Low, given Meraki's long-standing cloud-managed firmware model | Automatic/scheduled via dashboard | Low | None significant identified for the Meraki path | documentation.meraki.com (general Meraki cloud-management architecture) | Meraki's cloud-managed firmware model is one of its most established, well-regarded operational strengths - genuinely low burden for administrators.

Other

Partner Delivered

Implied via Cisco's extensive reseller/partner ecosystem, though not formalised into a single named platform the way Cato's MSASE or Palo Alto's Prisma SASE for MSPs are | Meraki dashboard / Cisco Cloud Control (partner tier) | MSP/partner-level administrators | Not itemised | Not itemised | Not itemised | Real in practise given Cisco's channel scale, but the weakest formally-named MSP programme evidence among the five vendors profiled - worth a direct follow-up on Cisco's specific MSP/partner-tier SASE offering.

Other

Requires Confirmation

Not confirmed as a distinct named support tier in sources reviewed | Not confirmed | Not specified | Not confirmed | N/A | Not confirmed | Not found at this level of detail in a Tier 1-2 source in this pass | A genuine evidence gap relative to Zscaler's named Premium Support Advanced/Advanced Plus tiers with dedicated TAM language.

Other

Requires Confirmation

Not independently confirmed as a distinct virtual-appliance option in sources reviewed | Unknown | Unknown | Unknown | Unknown | Not confirmed | Not found in a Tier 1-2 source in this pass | Evidence gap.

Other

Unknown

Meraki MX/MG zero-touch, dashboard-driven deployment; Peco Foods and George Sink P.A. both evidence real, fast branch/site onboarding | Meraki dashboard (remote) | Low specialist requirement per named customer evidence | Zero-touch (implied by the Meraki cloud-managed model and the 2-hour deployment claim) | Genuinely fast per multiple named customers | None significant identified for the Meraki-centric path | cisco.com SASE Connect Anywhere page | Well-evidenced, though - as with most rows in this profile - specifically strongest for the Meraki/Secure Connect path rather than the Catalyst SD-WAN path, which has thinner onboarding-speed evidence in this pass.

Other

Requires Confirmation

Not confirmed as a distinct, named Cisco-operated NOC service for Secure Access specifically in sources reviewed | Not confirmed | Not itemised | Not confirmed | Customer configures policy; Cisco operates the underlying cloud infrastructure by inference | Not itemised with specific figures | Not found at this level of detail in a Tier 1-2 source in this pass | A genuine evidence gap relative to the specific SLA data sheets found for Zscaler - worth a direct follow-up with Cisco's own support documentation.

Other

Unknown

Unknown - not found in sources reviewed | Presumably Meraki dashboard/API or Cisco Cloud Control | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in public sources reviewed | Evidence gap.

Other

Unknown

Unknown - not found in sources reviewed | Presumably Meraki dashboard / Cisco Cloud Control | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in public sources reviewed | Evidence gap.

Other

Unknown

Cloud-based, via the Meraki dashboard for Meraki/Secure Connect deployments, or Cisco Cloud Control for the broader security platform | Meraki dashboard or Cisco Cloud Control (depends on product choice) | General IT admin; named customer evidence suggests genuinely low specialist requirement for the Meraki-centric path specifically | Not itemised in detail | Described as fast and simple by multiple named customers, most strikingly a 2-hour full deployment | None significant identified for the Meraki path in sources reviewed | cisco.com SASE Connect Anywhere page (named quote: Timothy Mullen, CIO, George Sink, P.A.: '...literally just deployed the access points and configured the network using the unified dashboard. It only took 2 hours') | One of the strongest, most specific, most quotable deployment-speed claims found across all five vendors profiled - a named CIO citing a precise 2-hour timeline for a full SASE platform is genuinely compelling evidence.

Other

Supported

Yes | Meraki MX/MG or Catalyst SD-WAN edge device | Edge → Secure Access | Meraki dashboard or Catalyst SD-WAN manager | Distributed branch estates, especially existing Cisco/Meraki customers | Low for Meraki (per named customer evidence) | Peco Foods, George Sink P.A. both evidence real branch/site deployment | Well evidenced via two independent, named, credible customer case studies - genuinely solid evidence for this row specifically.

Other

Partner Delivered

Implied via Cisco's extensive partner/reseller ecosystem, evidenced indirectly via CloudWifiWorks/BlueAlly's SASE quoting and consulting services | Not itemised | N/A | Involves Cisco partners/resellers | Shared | Not itemised | Real, evidenced indirectly via the scale of Cisco's partner ecosystem, though not formalised into a named Cisco-delivered support tier in the primary sources reviewed.

Other

Unknown

Unified within whichever console applies (Meraki dashboard or Cisco Cloud Control), reinforced by ISE for identity-based policy where deployed | Meraki dashboard / Cisco Cloud Control / ISE | Benefits from prior Cisco/Meraki familiarity, though named customer evidence suggests a manageable learning curve even without it | Not itemised | Positioned as simple via named customer testimonials | None significant identified | cisco.com SASE Connect Anywhere page (named quotes across multiple customers) | Consistently positive across multiple independent named customers - a genuine strength, in contrast to the well-corroborated learning-curve caution found for Palo Alto specifically.

Other

Not Supported

Referenced specifically for Secure Access - 'No additional PID is required for multi-org. End customer must contact Cisco TAC to activate their multi-org dashboard' per Cisco's own ordering guide | Meraki dashboard / Cisco Cloud Control (multi-org mode) | Requires a TAC activation step per Cisco's own documentation | Not itemised further | Confirmed to exist, with a specific, named activation process | cisco.com Secure Access Subscription Ordering Guide | High | A specific, primary-sourced, technical detail - genuinely credible evidence that multi-tenancy exists, with an unusually precise activation-process description for a feature that was often just 'implied' for other vendors.

Other

Unknown

Unified via Cisco Cloud Control for Secure Access, or the Meraki dashboard for Meraki-based deployments - genuinely two distinct unification points depending on product choice | N/A | N/A | Included | Customer-managed via dashboard, with partner support available | N/A | cisco.com Secure Access Data Sheet (Cisco Cloud Control as unified operating experience) | A real, confirmed unification point, though - same caveat throughout this profile - which console applies depends on which Cisco SASE product a buyer has chosen.

Other

Supported

Yes | Mix of Secure Client, Meraki/Catalyst SD-WAN edge devices | Mixed | Meraki dashboard / Cisco Cloud Control, with varying degrees of unification depending on product choice | Most real-world enterprise estates, especially those with existing Cisco footprint | Moderate, given the multi-product decision point | Peco Foods (SD-WAN + Secure Access), Mitchells & Butlers (cloud-first Meraki + Secure Connect) both evidence real hybrid deployment | Two independently named, credible customer stories evidencing hybrid deployment specifically - solid evidence, though the underlying complexity of choosing between products is a real, distinct consideration for Cisco specifically.

Other

Requires Confirmation

Not applicable in the same sense as an owned-backbone vendor, though the underlying architecture itself (owned, hyperscaler-hosted, or peering-based) isn't independently confirmed for Cisco Secure Access (Table 7) | N/A | N/A | N/A | N/A | N/A | N/A | Structurally uncertain rather than clearly non-applicable, given the unresolved Table 7 architecture question - a genuine, specific evidence gap worth flagging.

Other

Unknown

Unknown - not found in sources reviewed | Not found | Not specified | Not confirmed | N/A | Not confirmed | Not found in a Tier 1-2 source in this pass | Evidence gap.

Other

Supported

Yes | Cisco Secure Client | Client → Secure Access | Meraki dashboard / Cisco Cloud Control | Managed-device remote/hybrid workforce | Low (mature, long-standing client via AnyConnect lineage) | N/A | Secure Client's AnyConnect heritage is a genuine maturity advantage, similar in kind to Palo Alto's GlobalProtect and Zscaler's Client Connector.

Other

Supported

Native, via direct SaaS and IaaS Peering referenced for Cisco Secure Connect | Direct peering | Cloud workload → Secure Access | Meraki dashboard / Cisco Cloud Control | Multi-cloud/hybrid enterprises | Not fully detailed | Not itemised in detail | Confirmed as a named capability, less granularly detailed than Netskope's or Palo Alto's equivalent hyperscaler-specific evidence.

Other

Requires Confirmation

Not confirmed as a distinct named service in sources reviewed, though Cisco's large partner/reseller ecosystem (evidenced via BlueAlly/CloudWifiWorks) implies real partner-delivered deployment is common | Cisco partner/reseller ecosystem | As above | Shared | Buyers wanting partner-led implementation | Not fully detailed | cloudwifiworks.com (third-party reseller, itself evidence of the partner ecosystem's existence) | Real, evidenced indirectly via the scale and specificity of Cisco's reseller ecosystem, though not formalised into a named co-managed programme in the primary sources reviewed.

Other

Requires Confirmation

Not confirmed as a distinct, named Cisco-delivered managed-service product in sources reviewed | Not confirmed | - | - | Buyers wanting full outsourcing | Not confirmed | Not found in a Tier 1-2 source in this pass | A genuine evidence gap relative to Cato's and Palo Alto's named MSP/managed-service programmes - worth a direct follow-up, particularly given Cisco's channel-heavy go-to-market model likely supports this in practise even without a single named product.

Compliance and assurance

13 records
FrameworkScopeSupportReview dateQualification
DORA relevanceN/AUnknownNot statedUnknown - not found in sources reviewed | N/A | Not confirmed | EU financial services | Not found in a Tier 1-2 source in this pass | Not found | In contrast to Netskope's explicit DORA naming, no equivalent Cisco statement was found - a specific gap worth flagging for Netify's financial-services sector suitability assessment (Table 14).
Data residencyUS federal boundary confirmed; commercial platform architecture not detailedPartially SupportedNot statedPartial - the FedRAMP Moderate government boundary provides some US data-residency assurance for federal buyers; a broader, dedicated data-sovereignty architecture description for the commercial platform wasn't found | US federal boundary confirmed; commercial platform architecture not detailed | FedRAMP Moderate boundary | United States (federal boundary) | cisco.com Secure Access for Government At-a-Glance | Medium for US federal; Low for other regions/commercial buyers | Worth a direct question for non-US, non-federal buyers specifically, given the broader Table 7 architecture gap (no confirmed PoP map or data-residency architecture for the commercial platform).
Encryption/key managementDuo specifically confirmed; broader Secure Access platform encryption detail not itemisedRequires ConfirmationNot statedConfirmed at a specific level for Duo's MFA component - 'FIPS 140-2 and NIST SP 800-63-3' compliant, supporting AAL2 and AAL3 authenticators | Duo specifically confirmed; broader Secure Access platform encryption detail not itemised | FIPS 140-2, NIST SP 800-63-3 (Duo) | US federal (FedRAMP context) | 22 Jul 2026 | Specific, technical, primary-sourced detail for Duo specifically - good evidence quality for that one component, though broader Secure Access-wide encryption/key-management detail wasn't found in this pass.
FedRAMPUS federal government (Moderate baseline)SupportedNot statedAuthorized - Cisco Secure Access for Government is FedRAMP Moderate authorized, integrating with other FedRAMP-authorized Cisco components (Duo, Cisco Catalyst SD-WAN) to build a single-vendor FedRAMP-authorized SASE stack; Cisco ThousandEyes achieved FedRAMP Moderate authorization separately as of March 2026 | US federal government (Moderate baseline) | FedRAMP Moderate (Secure Access, ThousandEyes, Duo, Catalyst SD-WAN) | US federal/government | 22 Jul 2026 | A genuinely coherent, multi-component FedRAMP story (several named products all authorized together), though capped at Moderate rather than High - a materially lower bar than Zscaler's or Palo Alto's FedRAMP High GovCloud boundaries, and DoD Impact Level authorization wasn't found for Cisco Secure Access in this pass.
GDPRN/AUnknownNot statedNot separately itemised as a distinct compliance line item for Secure Access specifically in sources reviewed | N/A | Not confirmed | EU/UK relevant | Not found in a Tier 1-2 source in this pass | Not found | Cisco is a large, long-established multinational and almost certainly has broader GDPR compliance infrastructure, but Secure Access-specific documentation wasn't located in this pass - worth a direct follow-up rather than treating as a genuine gap in Cisco's actual compliance posture.
HIPAAN/ARequires ConfirmationNot statedNot confirmed in sources reviewed | N/A | Not confirmed | US healthcare-relevant | Not found in a Tier 1-2 source in this pass | Not found | Same caveat as GDPR above - a research-pass limitation rather than a confident finding of absence, given Cisco's established presence in healthcare IT more broadly.
ISO 27001N/ARequires ConfirmationNot statedNot confirmed in sources reviewed for Cisco Secure Access specifically | N/A | Not confirmed | N/A | Not found in a Tier 1-2 source in this pass | Not found | A genuine, specific evidence gap relative to the other four vendors profiled, all of which had confirmed ISO 27001 evidence - worth a direct follow-up given how large and established Cisco is; the certification likely exists somewhere in Cisco's broader compliance programme but wasn't located for Secure Access specifically in this pass.
Logging/auditabilityPlatformRequires ConfirmationNot statedImplied via the confirmed, detailed Splunk integration (Cisco Security Cloud app) providing external audit trails across a broad set of named Cisco products | Platform | Splunk integration documentation | None identified | 22 Jul 2026 | Well-evidenced via the detailed, current Splunk integration specifically - a real strength for logging/auditability, even without a dedicated 'logging architecture' page comparable to Zscaler's isolated logging planes.
NHS DSPT relevanceN/AUnknownNot statedUnknown - not found in sources reviewed | N/A | Not confirmed | UK | Not found in a Tier 1-2 source in this pass | Not found | Evidence gap, consistent across all five vendors profiled - a direct follow-up question for Netify's UK healthcare-sector work.
NIS2 relevanceN/AUnknownNot statedUnknown - not found in sources reviewed | N/A | Not confirmed | EU | Not found in a Tier 1-2 source in this pass | Not found | Evidence gap.
PCI DSSN/ARequires ConfirmationNot statedNot confirmed in sources reviewed | N/A | Not confirmed | N/A | Not found in a Tier 1-2 source in this pass | Not found | Same gap flagged for Zscaler and Palo Alto - in contrast to Cato's and Netskope's explicit PCI-DSS attestations.
SOC 2N/ARequires ConfirmationNot statedNot confirmed in sources reviewed for Cisco Secure Access specifically | N/A | Not confirmed | N/A | Not found in a Tier 1-2 source in this pass | Not found | Same gap as ISO 27001 above - a genuine research limitation to flag for follow-up rather than a confident negative finding, given Cisco's scale.
UK public sector frameworksUKUnknownNot statedUnknown - not found in sources reviewed | UK | Not confirmed | UK | Not found in a Tier 1-2 source in this pass | Not found | Evidence gap - worth a direct follow-up given Cisco's substantial, long-standing UK public-sector presence more broadly, even though Secure Access-specific framework evidence wasn't found in this pass.

Integrations

20 records

AWS

Cloud · Native

Cloud | Native, implied via 'direct SaaS and IaaS Peering' for Cisco Secure Connect, though AWS-specific detail not itemised | Bidirectional | Not specified | Not detailed by named hyperscaler | Medium | Confirmed to exist as a capability; AWS-specific technical depth is a genuine gap relative to Netskope's or Palo Alto's named AWS integrations.

Active Directory

Identity · Unknown

Identity | Implied via Duo's documented support for importing users from Active Directory, Entra ID, Google, Okta and OpenLDAP external directories | Bidirectional | Not specified | Documented directly in Duo's own documentation | Medium-High | Confirmed for Duo specifically; Secure Access-native AD integration (as opposed to via Duo) not separately itemised.

CrowdStrike

EDR · Partner

EDR | Native, confirmed via a dedicated Cisco partner page - cross-domain telemetry ingestion (file, network, email, host, process identifiers), IoC blocklisting, host isolation, and CrowdStrike Falcon Insight XDR ingesting telemetry from Cisco ASA and Cisco Secure Email Gateway specifically | Bidirectional | Requires Cisco XDR Advantage or XDR Premier licensing tier for the query/blocklist functionality specifically | A specific, named, technically detailed integration with an explicit licensing-tier requirement stated by Cisco directly; broader ecosystem context confirmed via Cisco's Security Technical Alliance Partners directory and integration-focused blog posts, and corroborated independently by Okta's own Okta + CrowdStrike partner page describing the adjacent three-way identity/EDR alliance pattern | High | One of the best-evidenced integrations in this profile - Cisco's own partner page states the exact licensing tier required, which is unusually precise, actionable detail for buyer cost modelling.

Google Cloud

Cloud · Unknown

Cloud | Same general IaaS Peering capability, not separately itemised by hyperscaler | Bidirectional | Not specified | Not detailed | Medium | Same evidence quality as the AWS and Azure rows above.

Google Workspace

Identity/Productivity · Unknown

Identity/productivity | Implied via Duo's documented support for Google as an external directory source | Bidirectional | Not specified | Documented for Duo specifically | Medium | Confirmed for Duo; Secure Access-native detail not separately itemised.

Intune

MDM/UEM · Unknown

MDM/UEM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.

Jamf

MDM/UEM · Unknown

MDM/UEM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.

Microsoft 365

Productivity/SaaS · Unknown

Productivity/SaaS | Not separately confirmed as a distinct named integration for Secure Access specifically in sources reviewed | Unknown | Not specified | Not detailed | Not found as a distinct, named integration in this pass | Low-Medium | Evidence gap relative to the M365-specific detail found for Zscaler and Netskope.

Microsoft Azure

Cloud · Unknown

Cloud | Same general IaaS Peering capability as AWS above, not separately itemised by hyperscaler | Bidirectional | Not specified | Not detailed | Medium | Same evidence quality as the AWS row above.

Microsoft Defender

EDR · Unknown

EDR | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap - CrowdStrike is clearly the best-documented EDR partner.

Microsoft Entra ID

Identity · Native

Identity | Native, confirmed - a specific, dated (11 May 2026) Cisco support article covers provisioning users and groups to Secure Access via Entra ID | Bidirectional (provisioning + auth context) | Not specified | Documented alongside equivalent Okta and Duo provisioning guides, published the same week | High | Confirmed via a specific, current, primary Cisco support article - genuinely stronger evidence than the equivalent 'not found' rows for several other vendors.

Microsoft Sentinel

SIEM · Unknown

SIEM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap relative to Netskope's confirmed Sentinel integration.

Okta

Identity · Native

Identity | Native, confirmed - a specific, dated (11 May 2026) Cisco support article covers provisioning users and groups to Secure Access via Okta | Bidirectional | Not specified | Published alongside the Entra ID and Duo provisioning guides | High | Same strong, current, primary-sourced evidence quality as the Entra ID row.

Palo Alto Cortex

SIEM/XDR · Unknown

SIEM/XDR | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap (unsurprising, given the two companies are direct competitors).

REST API

Platform API · Api

Platform API | Implied via 'standards-based integrations, APIs, webhooks, and ecosystem connectors' referenced directly in Cisco's own Secure Access datasheet, plus the documented webhook firewall/IP-range configuration guide | Bidirectional | Not specified | A specific webhook configuration guide exists, dated 1 Apr 2026 | Medium-High | Confirmed via both a general datasheet statement and a specific, dated technical configuration guide - reasonably solid evidence, though not as centred around a single named developer portal as Palo Alto's pan.dev or Netskope's GitHub-published plugins.

SCIM/SAML/OIDC

Identity Federation · Unknown

Identity federation | SAML/SCIM implied via the documented Okta, Duo and Entra ID provisioning guides (provisioning inherently requires SCIM or an equivalent mechanism) | Bidirectional (auth + provisioning) | Not specified | Not detailed by protocol name specifically | Medium | Reasonable inference from the confirmed provisioning capability; the specific protocol names (SCIM/SAML/OIDC) weren't spelled out in the sources reviewed the way they were for some competitors.

ServiceNow

ITSM · Unknown

ITSM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.

Splunk

SIEM · Native

SIEM | Native, deeply documented - the Cisco Security Cloud app on Splunkbase covers AI Defence, Duo, Email Threat Defence, Identity Intelligence, Multicloud Defence, Secure Endpoint, Secure Firewall (FTD/eStreamer/ASA), Secure Workload, Isovalent, Secure Malware Analytics, Secure Network Analytics, Vulnerability Intelligence and XDR | Bidirectional (Cisco products → Splunk; Cisco XDR can import Splunk-sourced incidents) | Not specified | An unusually broad, current (17 Jun 2026-dated) integration covering more than a dozen named Cisco products in one app | High | Genuinely one of the best-documented, broadest single integrations found across any vendor profiled - the sheer number of named Cisco products covered in one Splunk app is a real, specific strength, unsurprising given Cisco now owns Splunk.

Syslog

Log Export · Unknown

Log export | Not separately itemised in sources reviewed, though implied by the broader SIEM integration framework (Splunk specifically documented) | Unknown | Not specified | Not detailed | Not found explicitly by name | Low-Medium | Reasonable to assume given documented SIEM integrations exist, not independently confirmed by name.

Terraform

Infrastructure-As-Code · Unknown

Infrastructure-as-code | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.

Sector evidence

10 records

Education

Not Supported

Unknown - not assessed, no case study found, though DNS Essentials/Advantage tiers reference 'EDU' variants in third-party pricing analysis, implying an education-specific commercial track exists | Not assessed in detail | Not assessed | None found as a named case study | N/A | Named 'EDU' pricing tier variant found, but no case study | A specific, if thin, signal (a named EDU pricing tier) worth noting even without full case-study evidence - Cisco has a long-standing K-12/higher-ed presence that likely isn't fully captured by this research pass.

Named evidence
None found as a named case study
Case study strength
None

Energy/utilities

Not Supported

Unknown - not assessed, no case study found | Not assessed | Not assessed | None found | N/A | No case study found | Evidence gap - notably weaker here than Zscaler's NOV case study for this sector.

Named evidence
None found
Case study strength
None

Financial services

Not Supported

Unknown - no PCI-DSS, DORA, or named financial-services case study found in this pass | DLP, CASB plausibly relevant | Not confirmed | None found | N/A | Weaker evidence than Cato's, Netskope's, or Palo Alto's equivalent findings | Evidence gap - a specific, worth-flagging weak point given Cisco's genuine broader presence in financial-services networking.

Named evidence
None found
Case study strength
None

Government/public sector

Unknown

Good fit, evidenced | FedRAMP Moderate across Secure Access, ThousandEyes, Duo and Catalyst SD-WAN together | FedRAMP Moderate (multiple named components) | Indiana Office of Technology (ThousandEyes specifically, not confirmed for the full Secure Access stack) | Coherent multi-component FedRAMP story, capped at Moderate | Weaker than Zscaler's or Palo Alto's FedRAMP High/DoD IL evidence | A genuinely multi-product, coherent public-sector compliance story, though it caps out at a lower assurance level (Moderate) than two of the other four vendors profiled - a specific, worth-stating nuance.

Named evidence
Indiana Office of Technology (ThousandEyes specifically, not confirmed for the full Secure Access stack)
Case study strength
Strong

Healthcare/NHS

Not Supported

Unknown - no HIPAA attestation or NHS DSPT evidence found, and no named healthcare case study found in this pass | DLP, ZTNA plausibly relevant | Not confirmed | None found | N/A | Weaker evidence than several other vendors profiled on this specific sector | Evidence gap - do not claim healthcare/NHS suitability without direct vendor confirmation, despite Cisco's substantial broader healthcare-IT presence.

Named evidence
None found
Case study strength
None

Hospitality

Unknown

Good fit, evidenced | Cloud-first, hardware-light deployment relevant to multi-site hospitality operators | Not assessed | Mitchells & Butlers (UK pub/restaurant operator) | UK-based customer specifically - directly relevant to Netify's UK-focused work | Single case study | Genuinely useful for Netify specifically: this is the only UK-named customer found across all five vendor profiles produced so far, evidenced by a named Head of Technology and Support quote about cloud-first infrastructure alignment.

Named evidence
Mitchells & Butlers (UK pub/restaurant operator)
Case study strength
Strong

Manufacturing

Unknown

Strong fit, evidenced | Distributed-facility SD-WAN and security consolidation; ThousandEyes for multi-site assurance | Not assessed for sector-specific frameworks | Peco Foods (poultry processing, 7,500+ employees, 20 facilities across the Southeast US) | Multi-facility deployment evidenced directly | US-centric case evidence; single company rather than the multi-country breadth of Palo Alto's Grupo Bimbo evidence | A genuinely credible, named, quoted manufacturing case study - not as expansive as Grupo Bimbo's 35-country story, but solid, specific evidence (a 200% user-experience improvement, named IT manager) for a real distributed-facility food-processing operation.

Named evidence
Peco Foods (poultry processing, 7,500+ employees, 20 facilities across the Southeast US)
Case study strength
Strong

Professional services

Unknown

Good fit, evidenced | Fast, low-complexity deployment relevant to smaller professional-services firms specifically | Not assessed | George Sink, P.A. (law firm) | N/A | Single case study, though genuinely specific and quotable (2-hour deployment, named CIO) | A real, credible, if narrow, professional-services proof point - the 2-hour deployment claim specifically is one of the standout pieces of evidence in this entire profile.

Named evidence
George Sink, P.A. (law firm)
Case study strength
Strong

Retail

Not Supported

Unknown - no named retail case study found in this pass | SD-WAN/branch capability plausibly relevant | Not assessed | None found in this research pass | N/A | No case study found | Evidence gap - worth a direct follow-up given Cisco's very large customer base likely includes retail examples not surfaced in this pass.

Named evidence
None found in this research pass
Case study strength
None

Transport/logistics

Not Supported

Unknown - not assessed, no case study found | Not assessed | Not assessed | None found | N/A | No case study found | Evidence gap.

Named evidence
None found
Case study strength
None

Case studies

3 records
Customer
Named - Peco Foods
Sector and geography
Manufacturing (poultry processing) · United States (Tuscaloosa, Alabama, headquartered; 20 facilities across the Southeast)
Estate
Not quantified for the SASE deployment specifically; company has 7,500+ total employees per its own corporate site; 20 facilities across the Southeast US
Outcome
'The user experience has improved twofold, by 200%. All they need is an internet connection, and they're connected to the same resources every time' (named executive quote, Mario Manzano, IT Infrastructure, Security and Collaboration Manager)

Named - Peco Foods | Manufacturing (poultry processing) | United States (Tuscaloosa, Alabama, headquartered; 20 facilities across the Southeast) | Not quantified for the SASE deployment specifically; company has 7,500+ total employees per its own corporate site | 20 facilities across the Southeast US | Needed to modernise security by replacing legacy systems, unify networking and security, enable zero trust and streamline management, migrating from Umbrella DNS specifically | Cisco Secure Access (migrated from Umbrella DNS), Cisco SD-WAN | Hybrid - DNS/SIG-layer security plus SD-WAN across distributed manufacturing/processing facilities | Not itemised beyond the named Cisco product combination | 'The user experience has improved twofold, by 200%. All they need is an internet connection, and they're connected to the same resources every time' (named executive quote, Mario Manzano, IT Infrastructure, Security and Collaboration Manager) | A genuinely credible, well-corroborated manufacturing case study - the 200% figure recurs consistently across multiple Cisco pages rather than appearing once, which adds confidence, though it's a single specific metric rather than the multi-category quantification found in Palo Alto's Grupo Bimbo evidence.

Customer
Named - Mitchells & Butlers
Sector and geography
Hospitality (pub/restaurant operator) · United Kingdom
Estate
Not quantified; Not quantified (Mitchells & Butlers operates a large multi-site UK pub/restaurant estate per general market knowledge, though the specific site count wasn't stated in the source reviewed)
Outcome
'The decision to go with Cisco Meraki and now Secure Connect not only saved us time but also aligned with our cloud-first infrastructure goals, allowing us to deploy swiftly without the burden of physical hardware. Plus, using the single dashboard to manage it all simplifies our operations' (named executive quote, Martyn Eddins, Head of Technology and Support)

Named - Mitchells & Butlers | Hospitality (pub/restaurant operator) | United Kingdom | Not quantified | Not quantified (Mitchells & Butlers operates a large multi-site UK pub/restaurant estate per general market knowledge, though the specific site count wasn't stated in the source reviewed) | Wanted to align technology infrastructure with cloud-first goals while deploying swiftly without the burden of physical hardware | Cisco Meraki, Cisco Secure Connect | Cloud-first, hardware-light deployment via the single Meraki dashboard | Not itemised | 'The decision to go with Cisco Meraki and now Secure Connect not only saved us time but also aligned with our cloud-first infrastructure goals, allowing us to deploy swiftly without the burden of physical hardware. Plus, using the single dashboard to manage it all simplifies our operations' (named executive quote, Martyn Eddins, Head of Technology and Support) | High - named customer, named executive, specific and credible qualitative outcome (cloud-first alignment, operational simplification), though without a quantified metric the way Peco Foods' 200% figure provides | The only named UK customer found across all five vendor profiles produced so far - genuinely useful for Netify's UK-focused work specifically, even though the evidence is more qualitative than Peco Foods' or George Sink P.A.'s more quantified/timed claims.

Customer
Named - George Sink, P.A.
Sector and geography
Legal/professional services (law firm) · United States
Estate
Not quantified; Not quantified
Outcome
'Since I was installing a robust SASE platform, I thought it would be more difficult. However, the technology sophistication made it so simple that I literally just deployed the access points and configured the network using the unified dashboard. It only took 2 hours - yet the result was powerful' (named executive quote, Timothy Mullen, CIO)

Named - George Sink, P.A. | Legal/professional services (law firm) | United States | Not quantified | Not quantified | Wanted a robust SASE platform, expecting deployment to be difficult given the technology's sophistication | Cisco SASE (Meraki-based, per the 'unified dashboard' and 'access points' language in the quote) | Cloud-managed, Meraki dashboard-driven | Not itemised | 'Since I was installing a robust SASE platform, I thought it would be more difficult. However, the technology sophistication made it so simple that I literally just deployed the access points and configured the network using the unified dashboard. It only took 2 hours - yet the result was powerful' (named executive quote, Timothy Mullen, CIO) | High - named customer, named executive (CIO), a specific and highly quotable timeframe (2 hours) that's unusually precise for this kind of case study | One of the single best pieces of deployment-speed evidence found across all five vendors profiled - a named CIO's precise 2-hour figure is genuinely compelling, concrete evidence for lean-team, fast-deployment buyer conversations.

Netify evaluation record

50 records

Summary

Mid-market | Good fit | Peco Foods (7,500+ employees) and Mitchells & Butlers both suggest mid-to-large organisations are well served, particularly those wanting to build on existing Cisco/Meraki networking | Benefits from existing Cisco footprint, though not strictly required per the named case studies | Tiered pricing structure with genuine entry points, per Table 16 | cisco.com/customers evidence (Peco Foods, Mitchells & Butlers) | Real, evidenced across multiple named customers with genuine business scale.

Summary

SME | Good fit, particularly via Meraki/Secure Connect | George Sink, P.A.'s 2-hour deployment and DNS Essentials' documented entry-tier pricing (approximately $3.20/user/month list at the 1,000-user band per third-party analysis) both suggest a genuinely accessible entry point | Minimal internal skills needed for the Meraki-centric path specifically | Entry-tier pricing (DNS Essentials/Advantage) is more granularly documented by third-party analysis than for some competitors, though not confirmed directly by Cisco | A genuinely strong SME fit for the Meraki/Secure Connect path specifically - the named 2-hour deployment and documented entry-tier structure are real, concrete advantages, though the Catalyst SD-WAN path is a different, less SME-oriented story.

Summary

Most credible differentiator | Genuinely native, single-dashboard coverage from campus LAN/WLAN through SD-WAN to cloud-delivered SASE via Meraki - no other vendor among the five profiled offers this specific combination, and it's a structural consequence of Cisco's broader networking-hardware heritage that a security-first or cloud-native competitor cannot easily replicate. | Tables 4, 19 | High | This is the single sentence Netify's comparison engine could most confidently quote for Cisco specifically - the campus-to-cloud story, not the SASE security stack in isolation, is Cisco's real edge.

This is the single sentence Netify's comparison engine could most confidently quote for Cisco specifically - the campus-to-cloud story, not the SASE security stack in isolation, is Cisco's real edge.

Summary

Questions Netify still cannot verify | ISO 27001, SOC 2, PCI-DSS, HIPAA, DORA and UK Cyber Essentials/NHS DSPT status for Secure Access specifically; the actual global PoP count and network architecture; BYOD/clientless remote-access capability; named, formal support-tier SLA figures; and Professional Services typical cost range. | Synthesis of Tables 5, 7, 8, 13, 16 | N/A - explicitly unresolved | This list should drive the next follow-up (a direct Cisco briefing or partner conversation) before this profile is considered fully closed out, in exactly the same spirit as the equivalent lists in the Cato, Zscaler, Netskope and Palo Alto profiles - several of these gaps likely reflect this research pass's limitations against Cisco's genuine scale rather than actual product gaps, which makes closing them directly with Cisco especially worthwhile.

This list should drive the next follow-up (a direct Cisco briefing or partner conversation) before this profile is considered fully closed out, in exactly the same spirit as the equivalent lists in the Cato, Zscaler, Netskope and Palo Alto profiles - several of these gaps likely reflect this research pass's limitations against Cisco's genuine scale rather than actual product gaps, which makes closing them directly with Cisco especially worthwhile.

Summary

Security & Analytics | Deep, long-standing security portfolio behind the SASE layer - Cisco Talos threat intelligence, Cisco XDR, and the 2024 Splunk acquisition (contributing to 54% security-revenue growth in Q3 FY25 per Cisco's own reporting) all feed into a genuinely broad detection and response capability. | That breadth again cuts both ways: evaluating 'Cisco SASE security' in isolation is harder than for a single-product vendor, since capability and value are spread across Secure Access, XDR, Talos and Splunk rather than concentrated in one SKU.

Summary

MPLS to SD-WAN migration | Not evidenced via a named case study specifically describing MPLS retirement; standard IPSec VPN support alongside native SD-WAN implies coexistence capability | Existing MPLS/VPN infrastructure, integrated via IPSec per the Secure Connect solution overview | Not itemised | Cisco partner ecosystem (implied) | Not quantified | Not itemised | Not detailed | Architecturally plausible given the confirmed IPSec/SD-WAN flexibility, but no named customer scenario specifically walks through an MPLS migration for Cisco in this pass - an evidence gap relative to Cato's and Palo Alto's more explicit coexistence evidence.

Summary

When would Netify recommend it? (mandatory) | When a buyer already has meaningful Cisco/Meraki networking investment and wants to extend it into SASE incrementally; when a buyer specifically wants unified campus LAN/WLAN-to-cloud coverage under one vendor; when a buyer is a lean IT team prioritising fast, simple deployment; or when a buyer is a US federal/public-sector agency for whom FedRAMP Moderate (not High) is sufficient. | Synthesis of Tables 1, 4, 9, 13 | High | A clear, actionable recommendation trigger set for Netify's comparison tool to apply directly.

A clear, actionable recommendation trigger set for Netify's comparison tool to apply directly.

Summary

Support/service reality | Real underlying capability (Talos, XDR Advantage/Premier, the deep Splunk integration) but the least specifically evidenced formal support-tier/SLA structure and Professional Services cost range among the five vendors profiled. | Table 8, 16 | Medium | Flag internally as a priority follow-up source to strengthen before this profile supports a support-SLA-sensitive procurement decision.

Flag internally as a priority follow-up source to strengthen before this profile supports a support-SLA-sensitive procurement decision.

Summary

SSE deployment to remote users | Client-based (Secure Client) rollout to remote/mobile users, provisioned via Okta/Duo/Entra ID per Cisco's own documentation | IdP integration (Okta, Duo, or Entra ID) confirmed as a documented prerequisite | End-user self-install typical for Secure Client | Not itemised | Not quantified with a specific duration | Not itemised | Not detailed | The IdP provisioning documentation is genuinely current and specific (May 2026-dated), though a named, scaled remote-user deployment case study (comparable to Zscaler's NOV 27,500-user story) wasn't found for Cisco in this pass.

Summary

Global branch rollout | Meraki's zero-touch, dashboard-driven model and the confirmed Auto VPN dual-data-centre failover mechanism are architecturally real for this scenario, and Peco Foods' 20-facility footprint is directly relevant, though the sources reviewed don't quantify the rollout at the same scale/speed detail as Cato's Ulta Beauty story | Existing branch network/WAN infrastructure to integrate or replace | Not itemised | Not itemised | Not quantified at Peco Foods' full 20-facility scale specifically | Not itemised | Not detailed | Real, credible evidence exists (Peco Foods, George Sink P.A.'s specific 2-hour figure), but - same gap noted for Zscaler, Netskope and Palo Alto - Cisco lacks a single, large-scale, fully quantified branch-rollout proof point comparable to Cato's Ulta Beauty evidence specifically.

Summary

What implementation challenges should buyers expect? (mandatory) | Expect genuine upfront scoping work to determine which Cisco SASE product combination (Secure Access alone, plus Catalyst SD-WAN, plus Meraki SD-WAN, or the bundled Secure Connect) fits the buyer's estate before a fair comparison against single-platform competitors is possible. Expect the Meraki/Secure Connect path specifically to be genuinely fast and low-complexity based on named-customer evidence; expect the Catalyst SD-WAN path to be a different, less-evidenced proposition in this research pass. Expect to ask directly about BYOD/clientless capability and about specific network coverage/architecture, since both were confirmed gaps in this pass. | Tables 3, 5, 7, 9 | Medium-High | Each expectation is traceable to a specific, evidenced finding elsewhere in this profile.

Each expectation is traceable to a specific, evidenced finding elsewhere in this profile.

Summary

Strength | Named-customer deployment-speed evidence is genuinely exceptional for the Meraki/Secure Connect path - a precise, quoted 2-hour full-platform deployment and a corroborated 200% user-experience-improvement figure repeated across multiple Cisco pages | Lean IT teams and buyers prioritising fast time-to-value get concrete, named, quotable proof points | Best: SME/mid-market buyers with lean IT teams. Less relevant: buyers already expecting a complex, phased enterprise rollout | cisco.com SASE Connect Anywhere page (multiple named executive quotes) | High | Genuinely some of the strongest, most specific deployment-experience evidence found across all five vendors profiled - worth quoting directly and confidently to buyers.

Lean IT teams and buyers prioritising fast time-to-value get concrete, named, quotable proof points

Summary

Who is this genuinely best suited for? (mandatory) | Existing Cisco networking customers (Meraki, Catalyst, ISE, Duo, Umbrella) wanting to extend familiar infrastructure into SASE incrementally; organisations wanting genuinely native campus LAN/WLAN-to-WAN-to-SASE coverage under one vendor; lean IT teams prioritising fast, simple deployment via the Meraki/Secure Connect path specifically; and US federal/public-sector buyers needing a coherent, multi-component FedRAMP Moderate stack. | Tables 1, 4, 9, 13, 15 | High | Buyers matching this profile - especially existing Cisco/Meraki customers - can proceed with genuine confidence, backed by credible, specific named-customer evidence for exactly this use case.

Buyers matching this profile - especially existing Cisco/Meraki customers - can proceed with genuine confidence, backed by credible, specific named-customer evidence for exactly this use case.

Summary

Commercial reality | No public list pricing, though Cisco's own ordering guide is genuinely more transparent about the licensing mechanism (tiered, user-based, with a specific confirmed 50-user minimum for certain packages) than several competitors; third-party analysis suggests SASE-grade tiers land in a broadly similar $9-40/user/month range to the other vendors profiled, with no clear independently-evidenced pricing advantage or disadvantage found. | Table 16 | Medium (mechanism confirmed directly; specific pricing third-party only) | Use as a rough planning signal, always routing to a direct Cisco quote for real numbers - no confident pricing-advantage or pricing-premium claim can currently be made for Cisco relative to the other four vendors profiled.

Use as a rough planning signal, always routing to a direct Cisco quote for real numbers - no confident pricing-advantage or pricing-premium claim can currently be made for Cisco relative to the other four vendors profiled.

Summary

Large enterprise | Conditional fit | Catalyst SD-WAN specifically targets larger, more complex WAN estates, though the sources reviewed had thinner large-enterprise-scale case-study evidence than Palo Alto's Grupo Bimbo or Zscaler's NOV | Requires internal or partner-supported operational ownership at scale; the Catalyst SD-WAN path in particular likely needs more specialist skill than the Meraki path | Not itemised at enterprise scale with the same specificity as competitors | Table 6, 14 findings | Real capability exists (Catalyst SD-WAN is explicitly positioned for this scale) but the evidence base for large-enterprise-scale, quantified outcomes is thinner in this research pass than for Palo Alto or Zscaler specifically - worth a direct follow-up for large-scale reference customers.

Summary

Remote-user-heavy organisation | Conditional fit | Secure Client's AnyConnect-lineage maturity is a genuine strength for managed-device remote access specifically, but the confirmed absence of clientless/BYOD evidence (Table 5) is a real, specific gap for this buyer profile | Requires further direct confirmation on BYOD/clientless capability before recommending confidently | Not assessed | Table 5 findings | A genuinely bifurcated finding: strong for managed-device remote access, materially weaker-evidenced for BYOD/unmanaged/clientless scenarios relative to Zscaler, Netskope and Palo Alto - worth a direct, specific follow-up question before recommending Cisco to a BYOD-heavy buyer.

Summary

Commercials | A confirmed, tiered, user-based licensing structure (Essentials and Advantage packages) is documented directly in Cisco's own ordering guide - more transparent about packaging structure, if not price, than some competitors. | Actual per-user pricing is not published, and third-party analyses estimate SASE-grade tiers (SIG Advantage-equivalent) in the same $9-40/user/month range as the other vendors profiled - no clear, independently-evidenced pricing advantage or disadvantage was found in this pass.

Summary

Global multinational | Unknown - no named multinational-scale case study (comparable to Grupo Bimbo's 35 countries or Zscaler's global NOV deployment) was found in this pass | Cisco's genuinely global corporate footprint (Americas, EMEA, APAC, Japan, China per its own 10-K-style descriptions) suggests real capability, but SASE-specific multinational deployment evidence is thin | Needs Netify/buyer to verify specific-country coverage directly, given the Table 7 coverage-map gap | Custom enterprise pricing | Table 7, 15 findings | A genuine, specific evidence gap - Cisco is unquestionably a global company, but this research pass didn't surface a SASE-specific multinational case study or coverage map to substantiate global-estate suitability with the same confidence as for Palo Alto, Zscaler or Netskope.

Summary

Sector fit | Manufacturing (Peco Foods), government/public sector (multi-component FedRAMP Moderate story), professional services (George Sink P.A.) and hospitality (Mitchells & Butlers, the only UK-named customer across all five profiles) are all credibly evidenced; healthcare, financial services, retail, transport and energy all lack case-study or compliance evidence in this research pass. | Table 14 | Medium-High for the four evidenced sectors; Low for the others | The Mitchells & Butlers evidence specifically is worth highlighting for Netify's UK-focused work - it's the only UK-named customer found across all five vendor profiles produced so far.

The Mitchells & Butlers evidence specifically is worth highlighting for Netify's UK-focused work - it's the only UK-named customer found across all five vendor profiles produced so far.

Summary

Procurement watch-out | A thin, unattributable TrustRadius pricing-aggregator page was found during this research pass but assessed as too low-reliability (no specific attributable pricing data) to use as evidence and was excluded - see Evidence Register #43 | N/A - this is a methodology note, not a buyer-facing finding on its own | N/A | Table 19 note; Evidence Register #43 | N/A | Included here for transparency about the research process, mirroring the standard applied throughout all five profiles produced so far.

N/A - this is a methodology note, not a buyer-facing finding on its own

Summary

Where does it fall behind competitors? (mandatory) | Genuinely weaker network-coverage evidence (no PoP count or architecture map found); materially thinner general compliance-certification evidence (ISO 27001, SOC 2, PCI-DSS, HIPAA all unconfirmed) with FedRAMP capped at Moderate rather than High; a confirmed BYOD/clientless-access evidence gap; and the structural complexity of choosing between four distinct product paths before a fair competitor comparison is even possible. | Tables 5, 7, 13, 19 | Medium-High | Named specifically and evidenced, not a generic hedge - though several of these (compliance, coverage) may reflect research-pass limitations given Cisco's genuine scale rather than confirmed product gaps, and Netify should treat them as open questions to close directly rather than confident negative findings.

Named specifically and evidenced, not a generic hedge - though several of these (compliance, coverage) may reflect research-pass limitations given Cisco's genuine scale rather than confirmed product gaps, and Netify should treat them as open questions to close directly rather than confident negative findings.

Summary

Procurement watch-out | The BYOD/clientless/contractor remote-access evidence gap (Table 5) is specific and worth flagging directly - three of the four other vendors profiled had at least some confirmed clientless-access evidence, while Cisco's remote-access story in the sources reviewed centred entirely on the Secure Client agent | BYOD-heavy or contractor-heavy buyers should get direct confirmation of Cisco's clientless-access capability before assuming parity with competitors | Most relevant to organisations with significant unmanaged-device or third-party-contractor populations | Table 5, 15 findings | Medium-High | A specific, actionable, buyer-relevant gap - exactly the kind of nuance Netify's comparison tool exists to surface rather than let a buyer discover during a proof-of-concept.

BYOD-heavy or contractor-heavy buyers should get direct confirmation of Cisco's clientless-access capability before assuming parity with competitors

Summary

Reporting reality | Strong specifically via ThousandEyes (network/application/user-experience monitoring, with a credible public-sector proof point) and via the exceptionally broad Splunk integration for security-event visibility; weaker on executive dashboards, compliance reporting, and scheduled/custom reporting, none of which were confirmed in this pass. | Table 10 | Medium-High | Present the ThousandEyes and Splunk strengths specifically rather than imply comprehensive reporting maturity across the board.

Present the ThousandEyes and Splunk strengths specifically rather than imply comprehensive reporting maturity across the board.

Summary

Lean IT team | Strong fit, particularly via Meraki/Secure Connect | Multiple named customers (George Sink P.A., Peco Foods) independently describe genuinely simple, fast, low-specialist-effort deployment - a positive counterpoint to the well-corroborated learning-curve caution found for Palo Alto specifically | Minimal training investment implied by the 2-hour deployment claim and consistently positive named-customer language | Entry-tier pricing structure documented with reasonable specificity by third-party analysis | Table 9, 15 findings | Genuinely one of the strongest 'lean IT team' fits among the five vendors profiled, at least for the Meraki/Secure Connect path - a real, specific, named-customer-evidenced strength worth highlighting directly to lean-team buyers.

Summary

AI reality | Genuinely current and specific for agentic-AI/SASE traffic security (the February 2026 announcement is among the most technically detailed AI-security announcements found across all five vendors), though a single named AI-assistant/copilot product (comparable to Netskope's Copilots or Palo Alto's Strata Copilot) for general SASE administration wasn't confirmed. | Table 11 | Medium-High | Represent the confirmed, current agentic-AI-traffic capabilities confidently, while noting the administrative-copilot gap rather than assuming parity with competitors on that specific point.

Represent the confirmed, current agentic-AI-traffic capabilities confidently, while noting the administrative-copilot gap rather than assuming parity with competitors on that specific point.

Summary

VPN to ZTNA migration | Not evidenced via a named case study specifically describing VPN retirement in favour of ZTNA; Secure Client's AnyConnect lineage implies this is a well-trodden path architecturally, but no specific named scenario was found | Existing VPN infrastructure | Not itemised | Not itemised | Not quantified | Not itemised | Not detailed | A genuine evidence gap relative to the specific, named VPN-to-ZTNA evidence found for Baker & Baker (Zscaler) and Mindbody (Zscaler) - worth a direct follow-up.

Summary

Highly distributed branch estate | Strong fit, particularly for existing Meraki customers | Meraki's genuinely native LAN/WLAN/switching integration alongside SD-WAN (Table 4) is a real, distinctive strength for exactly this buyer profile, reinforced by the Peco Foods multi-facility evidence | Zero-touch provisioning well-evidenced via named customer deployment speed | Site-based/per-appliance licensing implications not fully itemised | Table 4, 6, 9 findings | Genuinely one of Cisco's strongest suitability findings - the native campus-to-WAN Meraki story, combined with credible named-customer deployment-speed evidence, makes this a real differentiator versus the other four vendors, none of which compete directly in campus LAN/Wi-Fi.

Summary

Regulated organisation | Conditional fit, strongest for US federal/public sector specifically | FedRAMP Moderate confirmed and well-evidenced across multiple named Cisco products working together; PCI-DSS, HIPAA, ISO 27001, SOC 2, DORA and UK Cyber Essentials/NHS DSPT all not confirmed for Secure Access specifically in this pass | Buyer must independently verify sector-specific compliance status directly with Cisco for anything outside US federal/public sector at the Moderate baseline | Not assessed | Table 13 findings | The weakest overall regulated-sector compliance evidence base among the five vendors profiled, capped at FedRAMP Moderate rather than High - though this likely reflects a genuine research-pass limitation given Cisco's real scale and established compliance programme, rather than a confident finding that these certifications don't exist somewhere in Cisco's broader portfolio.

Summary

Where does it stand out? (mandatory) | Native campus LAN/WLAN-to-SASE integration via Meraki (a structural differentiator none of the other four vendors can match); exceptionally specific, quotable named-customer deployment-speed evidence (a precise 2-hour full-platform deployment); and a genuinely current, technically detailed agentic-AI-security announcement (February 2026, naming MCP visibility and intent-aware inspection specifically). | Tables 4, 9, 11, 19 | High | These are the claims Netify can make most confidently and specifically to buyers, each backed by named, dated, primary-sourced or exceptionally specific evidence.

These are the claims Netify can make most confidently and specifically to buyers, each backed by named, dated, primary-sourced or exceptionally specific evidence.

Summary

Global fit | Cisco is unquestionably a large, genuinely global corporation, but SASE-specific global coverage evidence (PoP map, architecture, multinational case study) is the weakest of the five vendors profiled in this research pass - a specific, worth-flagging research gap rather than a confident finding about the product's actual global capability. | Table 7, 15 | Low-Medium (research-pass limitation, not a confident negative finding) | Always verify buyer-specific country/region coverage directly with Cisco rather than either assuming parity with or inferiority to the other four vendors on this specific point.

Always verify buyer-specific country/region coverage directly with Cisco rather than either assuming parity with or inferiority to the other four vendors on this specific point.

Summary

Merger/acquisition integration | Not documented via a named M&A-specific scenario in sources reviewed | Not itemised | Not itemised | Not itemised | Not quantified | Not itemised | Not detailed | Evidence gap - no equivalent to Zscaler's SPLX example or Palo Alto's Grupo Bimbo M&A quote was found for Cisco in this pass.

Summary

Strength | Exceptionally deep, current Splunk integration (a dozen-plus named Cisco products in one app, dated June 2026) reflecting Cisco's 2024 Splunk acquisition - genuinely differentiated ecosystem depth for existing Splunk shops | SecOps teams already using Splunk get an unusually broad, native integration surface | Best: organisations with an existing Splunk deployment. Less relevant: buyers with no SIEM investment or a different SIEM vendor | High | A direct, structural consequence of Cisco owning Splunk - genuinely a differentiator none of the other four vendors can replicate in the same way.

SecOps teams already using Splunk get an unusually broad, native integration surface

Summary

Limitation | Materially weaker general compliance-certification evidence (ISO 27001, SOC 2, PCI-DSS, HIPAA all unconfirmed for Secure Access specifically) than any of the other four vendors, and FedRAMP capped at Moderate rather than High | Regulated buyers outside the confirmed FedRAMP Moderate US-federal scope cannot currently verify Cisco's compliance posture from the sources reviewed with the same confidence as for competitors | Affects regulated-sector buyers most, especially those needing FedRAMP High/DoD IL-level assurance specifically | Table 13 findings | Medium (likely reflects a research-pass limitation given Cisco's scale, rather than confident evidence of absence) | Netify should treat this explicitly as an open research question to close directly with Cisco, rather than either assuming parity with competitors or asserting these certifications don't exist - Cisco's genuine scale makes the latter unlikely, but this profile cannot currently confirm the former.

Regulated buyers outside the confirmed FedRAMP Moderate US-federal scope cannot currently verify Cisco's compliance posture from the sources reviewed with the same confidence as for competitors

Summary

Biggest operational concern | The structural complexity of choosing between four distinct product paths before deployment even begins creates real risk of a buyer purchasing the wrong Cisco combination for their estate, or comparing 'Cisco' unfavourably against a single-platform competitor simply because they scoped the wrong Cisco product. | Table 3, 6, 19 | High | Netify should proactively surface this to buyers early in the shortlist conversation - the product-selection step is genuinely more consequential for Cisco than for any of the other four vendors profiled.

Netify should proactively surface this to buyers early in the shortlist conversation - the product-selection step is genuinely more consequential for Cisco than for any of the other four vendors profiled.

Summary

Compliance & Footprint | Cisco Secure Access for Government is FedRAMP Moderate authorized, integrating with other FedRAMP-authorized Cisco components (Duo, Catalyst SD-WAN, ThousandEyes) to build a genuinely single-vendor FedRAMP SASE stack for government agencies. | FedRAMP Moderate specifically, not High - a materially lower bar than Zscaler's or Palo Alto's FedRAMP High GovCloud boundaries, and DoD Impact Level authorization wasn't found for Cisco Secure Access in this research pass.

Summary

Cloud-first organisation | Good fit, via Secure Connect specifically | Direct SaaS and IaaS Peering confirmed, and Mitchells & Butlers' named quote specifically praises alignment with 'our cloud-first infrastructure goals' | None significant identified | Hyperscaler-specific technical depth is a genuine gap relative to Netskope's or Palo Alto's more granular cloud-provider integration evidence | cisco.com SASE Connect Anywhere page (Mitchells & Butlers quote) | Real, evidenced via a specific named customer quote directly addressing cloud-first alignment, even without deep hyperscaler-by-hyperscaler technical detail.

Summary

Multi-vendor SASE integration | Genuinely well-suited to this scenario by design - Cisco's own positioning explicitly frames SASE as 'a journey' where buyers 'start with SD-WAN or SSE and converge over time', and the deep, specifically-detailed CrowdStrike and Splunk integrations (Table 12) demonstrate real interoperability with non-Cisco security stacks | Existing security/identity tools already in place (Okta, CrowdStrike, Splunk all specifically documented) | Not itemised | Formal, dated integration guides for multiple named third-party products | Not quantified | N/A | N/A | Arguably the best-suited vendor of the five profiled for this exact scenario - Cisco's modular, 'converge over time' philosophy and its unusually deep CrowdStrike/Splunk integration evidence both point toward genuine strength for buyers wanting to add Cisco components to an existing multi-vendor stack rather than replace it wholesale.

Summary

Scope & Boundaries | ThousandEyes (also FedRAMP Moderate authorized as of March 2026) gives Cisco a genuinely differentiated, named digital-experience and network-assurance capability with real public-sector proof points (the Indiana Office of Technology case specifically). | The sheer number of distinct product names a buyer needs to understand (Secure Access, Umbrella legacy naming, Catalyst SD-WAN, Meraki SD-WAN, Secure Connect, ThousandEyes, Talos, XDR) is itself a genuine evaluation burden relative to the simpler naming structures of the other four vendors.

Summary

Limitation | The weakest network-coverage evidence base of the five vendors profiled - no PoP count, region map, or architecture description (owned backbone, hyperscaler-hosted, or peering-based) was found for Cisco Secure Access in this research pass | Buyers wanting to compare global performance/coverage claims like-for-like against Cato, Zscaler, Netskope or Palo Alto currently cannot do so for Cisco with the same confidence | Affects globally distributed buyers most | Table 7 findings | Medium-High (confident about the absence in sources reviewed, though this may reflect a research-pass limitation given Cisco's real scale rather than a genuine product gap) | A specific, actionable follow-up item - Netify should request Cisco's own Secure Access architecture/coverage documentation directly before making global-coverage claims with the same confidence extended to the other four vendors.

Buyers wanting to compare global performance/coverage claims like-for-like against Cato, Zscaler, Netskope or Palo Alto currently cannot do so for Cisco with the same confidence

Summary

When would Netify recommend looking elsewhere? (mandatory) | When a buyer needs FedRAMP High or DoD Impact Level authorization specifically (Zscaler or Palo Alto fit better); when a buyer needs confirmed BYOD/clientless remote-access capability (Zscaler, Netskope or Palo Alto currently document this more clearly); when a buyer needs a fully independently-verifiable global network-coverage map before committing (all four other vendors profiled had at least a headline coverage figure); or when a buyer specifically wants one clearly-named, single product to evaluate rather than choosing between several Cisco SASE paths. | Synthesis of Tables 5, 7, 13, 19 | Medium-High | Each trigger is tied to a specific, evidenced gap rather than a generic 'consider alternatives' hedge.

Each trigger is tied to a specific, evidenced gap rather than a generic 'consider alternatives' hedge.

Summary

Questions to ask before recommending it | 1) Given our estate size, existing footprint and requirements, which specific combination of Secure Access, Catalyst SD-WAN, Meraki SD-WAN and Secure Connect does Cisco recommend, and why? 2) Can Cisco confirm BYOD/clientless remote-access capability directly, given this wasn't found in public sources? 3) What is Cisco Secure Access's actual global PoP count and architecture (owned, hyperscaler-hosted, or peering-based)? 4) Does Cisco hold ISO 27001, SOC 2, PCI-DSS or HIPAA attestations for Secure Access specifically, even though these weren't found in public sources for this profile? | Synthesis of Tables 3, 5, 7, 13 | High | A direct, reusable question set for Netify's advisory conversations with buyers considering Cisco.

A direct, reusable question set for Netify's advisory conversations with buyers considering Cisco.

Summary

Deployment & Ops | Named customer evidence describes genuinely fast, simple deployment - one law firm CIO reported a 2-hour SASE rollout using the unified Meraki dashboard, and Peco Foods reports a 200% user-experience improvement after migrating from Umbrella DNS to Secure Access plus Cisco SD-WAN. | The multi-product structure (Secure Access, Catalyst SD-WAN, Meraki SD-WAN, Secure Connect) means the 'right' deployment path genuinely depends on which components a buyer chooses - a real source of pre-purchase complexity that the other four vendors' single-platform pitches don't have.

Summary

Co-managed transition | Implied via the scale and specificity of Cisco's reseller/partner ecosystem (BlueAlly/CloudWifiWorks explicitly offering consulting and design services), though not evidenced via a single named case study describing a co-managed transition specifically | Not itemised in detail | Not itemised | Cisco partner/reseller network | Not quantified | Not itemised | Not detailed | Real in practise given Cisco's channel scale, but thinly evidenced by a single named case study compared to Palo Alto's Infosys example or Cato's MSASE partner evidence.

Summary

Strength | Genuinely native campus LAN/WLAN-to-WAN-to-SASE integration via Meraki - the only vendor of the five profiled with confirmed, single-dashboard coverage from access points and switches through to SD-WAN and cloud security | Buyers wanting single-vendor coverage from campus to cloud get a materially different, broader proposition than any of the other four vendors profiled | Best: organisations wanting to consolidate campus networking and SASE under one vendor/dashboard. Less relevant: buyers with no campus LAN/WLAN consolidation need | High | A genuine, structural differentiator flowing from Cisco's broader networking-hardware heritage that none of the other four (security-first or cloud-native) vendors can match.

Buyers wanting single-vendor coverage from campus to cloud get a materially different, broader proposition than any of the other four vendors profiled

Summary

Mature NetOps/SecOps team | Good fit, especially for existing Cisco customers | Deep, technical SIEM/EDR integrations (the Splunk app covering a dozen-plus named Cisco products, the specifically-detailed CrowdStrike licensing-tier requirement) support a mature toolchain approach for teams already in the Cisco ecosystem | Mature teams benefit from prior Cisco/Meraki/ISE familiarity, though the multi-product structure itself (Table 3) requires genuine navigation even for experienced teams | Not assessed | Table 12 findings | Strong for teams already invested in Cisco's ecosystem specifically, given the exceptional Splunk integration depth (unsurprising, given Cisco owns Splunk) - a genuine, specific strength for this buyer profile.

Summary

Deployment reality | Genuinely fast and well-evidenced for the Meraki/Secure Connect path specifically, via multiple named, credible customer quotes; the Catalyst SD-WAN path is architecturally real but has thinner deployment-speed evidence in this research pass. | Table 9, 17, 18 | Medium-High | Set expectations specifically by product path - this is a more consequential distinction for Cisco than for any of the other four vendors profiled.

Set expectations specifically by product path - this is a more consequential distinction for Cisco than for any of the other four vendors profiled.

Summary

Firewall consolidation | Evidenced indirectly via Peco Foods' migration from Umbrella DNS to the broader Secure Access platform, implying consolidation of previously separate DNS/firewall functions | Existing firewall/DNS security rules migrated into Secure Access policy | IT/security team (named executive: Mario Manzano, IT Infrastructure, Security and Collaboration Manager, Peco Foods) | Not itemised | Not quantified with a specific timeline | Policy translation errors during cutover (not specifically addressed in the source) | Not detailed | Real, evidenced via a named executive and a specific outcome (200% UX improvement), though the case study centres more on the Umbrella-to-Secure-Access transition than a distinctly firewall-focused consolidation narrative.

Summary

Limitation | The multi-product structure (Secure Access, Catalyst SD-WAN, Meraki SD-WAN, Secure Connect) creates genuine, structural pre-purchase complexity - a buyer must understand which combination applies to them before a like-for-like comparison against a single-product competitor is even possible | Buyers evaluating 'Cisco' alongside single-platform competitors need materially more scoping work upfront to compare fairly | Affects all buyer sizes, though most acutely those without existing Cisco relationships to guide the product-selection decision | Table 1, 3, 6 findings | High | The single most structurally distinctive finding in this entire profile - Netify's comparison tool should flag this prominently, since a naive feature-by-feature comparison against a single-platform vendor risks comparing the wrong Cisco product entirely.

Buyers evaluating 'Cisco' alongside single-platform competitors need materially more scoping work upfront to compare fairly

Summary

Biggest operational advantage | Demonstrated, named, specific deployment speed for the Meraki/Secure Connect path - a precise 2-hour full-platform deployment quoted by a named CIO, corroborated by a second named customer's 200% user-experience-improvement figure repeated consistently across multiple Cisco materials. | Table 9, 18 | High | Directly quotable with the specific named-executive figures for credibility - among the strongest deployment-speed evidence found across any of the five vendors profiled.

Directly quotable with the specific named-executive figures for credibility - among the strongest deployment-speed evidence found across any of the five vendors profiled.

Summary

Overall Netify Assessment | Cisco SASE is the modular-by-design choice among the five vendors profiled - its most credible, distinctive evidence (native campus-to-cloud Meraki integration, genuinely fast named-customer deployments, a current and technically specific agentic-AI-security investment) all flow from Cisco's broader networking-hardware heritage and its deliberate 'converge over time' philosophy, rather than from a single converged SASE product built from scratch. That's a genuine strength for existing Cisco/Meraki customers specifically, and a genuine source of pre-purchase complexity for buyers with no existing Cisco relationship who must first work out which of four product paths applies to them. This profile is solid enough to support initial shortlist guidance for existing-Cisco-customer and campus-to-cloud-consolidation buyers specifically, but the flagged coverage-map and general-compliance-certification gaps - which may well reflect this research pass's limitations rather than genuine product gaps, given Cisco's real scale - should be closed out directly with Cisco before use in a high-stakes procurement decision. | Whole profile | Medium-High overall | Recommend direct Cisco engagement to close the flagged evidence gaps, mirroring the same next step recommended for the Cato, Zscaler, Netskope and Palo Alto profiles.

Recommend direct Cisco engagement to close the flagged evidence gaps, mirroring the same next step recommended for the Cato, Zscaler, Netskope and Palo Alto profiles.

Public evidence sources

49 records
  1. 01Cisco - Cisco Security and CrowdStrike partner page (specific licensing-tier requirements for the integration) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  2. 02Cisco - FedRAMP-Authorized Cisco Secure Access Solution page · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  3. 03Cisco - Framework Foundations: FedRAMP Solution Brief · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  4. 04Cisco - SASE with Meraki At a Glance · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  5. 05Cisco - Secure Access Data Sheet (Cisco Cloud Control, SD-WAN/ISE/Splunk/ThousandEyes integrations) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  6. 06Cisco - Secure Access Service Edge (SASE) Connect Anywhere page (named customer quotes: Peco Foods, Mitchells & Butlers, George Sink P.A.) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  7. 07Cisco - Secure Access Service Edge (SASE) with Meraki SD-WAN Design Guide · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  8. 08Cisco - Secure Access Subscription Ordering Guide (tiered, user-based licensing model) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  9. 09Cisco - Secure Access for Government At-a-Glance · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  10. 10Cisco - Secure Access for Government Data Sheet · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  11. 11Cisco - Secure Access product page (named customer highlights: Peco Foods, additional 60% faster access quote) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  12. 12Cisco - Security Products and Solutions for Cloud and Workforce Protection (SIEM/SOAR/UEBA unification, single-vendor SASE) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  13. 13Cisco - Security Technical Alliance Partners directory · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  14. 14Cisco - State of AI Security Report 2026 · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  15. 15Cisco Blogs - CSTA Turns 400 (Cisco Security Technical Alliance ecosystem growth) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  16. 16Cisco Blogs - Cisco Bolsters Security for Government With New FedRAMP Authorizations · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  17. 17Cisco Blogs - The Power of Cybersecurity Product Technology Integrations · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  18. 18Cisco Investor Relations - press release: Cisco Redefines Security for the Agentic Era with AI Defence Expansion and AI-Aware SASE · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  19. 19Cisco Meraki - Secure Connect SASE Solution page · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  20. 20Cisco Meraki Documentation - Cisco Secure Connect Solution Overview · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  21. 21Cisco Meraki Documentation - Cisco Secure Connect overview · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  22. 22Cisco Meraki Documentation - SASE and SD-WAN overview · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  23. 23Cisco Meraki Documentation - SASE deep dive page · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  24. 24Cisco Newsroom - Cisco Redefines Security for the Agentic Era (newsroom mirror of the AI Defence/AI-aware SASE release) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  25. 25Cisco Support - Secure Access integration guides (Okta, Duo, Entra ID provisioning; ISE pxGrid Cloud) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  26. 26Cisco Systems, Inc. - SEC Form 8-K (FY2026 press release) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  27. 27Cisco ThousandEyes - Assurance for Modern Federal IT (FedRAMP Moderate), including Indiana Office of Technology case reference · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  28. 28Cisco ThousandEyes - press release: ThousandEyes Achieves FedRAMP Moderate Authorization · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  29. 29Cisco ThousandEyes Documentation - ThousandEyes for Government: FedRAMP Moderate · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  30. 30Cisco Umbrella - Migrate from Umbrella to Secure Access (Peco Foods migration detail) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  31. 31Cisco Umbrella - homepage (Peco Foods quote: 200% user-experience improvement) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  32. 32Cisco Video Portal - Peco Foods Goes Zero Trust: Modern Security with Cisco SASE · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
  33. 33Cisco Duo Documentation - supported SSO/IdP integrations (Duo's own documentation, a Cisco-owned but independently-branded product) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 2
  34. 34Okta - Okta + CrowdStrike partner page (Okta's own, independent named company) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 2
  35. 35PRNewswire (wire distribution of Cisco's own release) - Cisco Redefines Security for the Agentic Era · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 2
  36. 36Peco Foods, Inc. - company website (independent named company, corroborating scale: 7,500+ employees, 20 facilities) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 2
  37. 37Splunk - Cisco Security Cloud app on Splunkbase (Splunk's own platform listing, independent named company) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 2
  38. 38Atonement Licensing - Cisco Security Licensing 2026: Suites, Bundles, and Cost (third-party) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  39. 39CloudWifiWorks.com (Cisco authorized reseller, BlueAlly) - Cisco SASE overview page · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  40. 40Database Trends and Applications - Cisco Rolls Out Suite of Capabilities with AI Defence and AI-Aware SASE (independent tech-news reporting) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  41. 41Futurum Group - Cisco AI Defence: Checking the Reckless Charge Toward AI (independent analyst commentary) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  42. 42Market Report Analytics - Cisco Systems (CSCO) Stock Price, Market Cap, Segmented Revenue & Earnings (third-party) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  43. 43PitchBook - Cisco Systems 2026 Company Profile · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  44. 44RocketReach - Peco Foods Technology Stack (third-party technographic data) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  45. 45Software Contract Negotiation - Cisco Umbrella Pricing: 2026 SIG, DNS & SASE Licensing Guide (third-party) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  46. 46Software Finder - Cisco Secure Access: Pricing, Free Demo & Features (third-party review aggregator) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  47. 47The Motley Fool - Cisco Systems (CSCO) Stock Price & News (third-party) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  48. 48UnderDefense - Cisco Pricing 2026: Ultimate Guide for Security Products (third-party) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
  49. 49sase.cloud - SASE Licensing & Pricing Guide (independent vendor comparison site) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3

Profile contract provider-public/1.0.0. Machine-readable record: JSON.