Overview
FortiSASE runs the same FortiOS operating system, and the same single-pass inspection engine, that has powered Fortinet’s physical FortiGate firewalls for over two decades. That’s a meaningfully different starting point from building a SASE platform natively for the cloud from scratch - the practical result is that FortiGate customers get a consistent policy and inspection model whether traffic is inspected on-premises or in a FortiSASE cloud point of presence, and Fortinet’s own commercial materials lean hard into a ‘Security Fabric’ discount for exactly these existing customers. Fortinet is also unusually forthright about its scale: it describes itself as the number-one firewall vendor by unit market share (55% as of fiscal year 2025), and backs that with a claim of ‘significantly lower total cost of ownership than the competition’ directly from its own CEO. The compliance picture is a mixed bag worth understanding precisely - Fortinet has GovRAMP (formerly StateRAMP) authorization at the Moderate impact level for two named services, but as of its own April 2025 announcement was still describing FedRAMP itself as a future intention rather than an achieved authorization, and no FortiSASE-specific FedRAMP Marketplace listing was found in our research. Commercially, FortiSASE pricing is opaque like most of the category, but two independent analyses converge on a distinctive finding: existing FortiGate customers get a documented 20-25% discount on FortiSASE specifically, which is Fortinet’s most concrete, quantifiable competitive argument for its installed base.
Direct comparison
Put Fortinet, Inc. (trading and profile display name: Fortinet; SASE product line branded FortiSASE) beside any provider.
Open the Netify comparison engine with both providers already selected. Every result is calculated from the public 40-capability evidence matrix.
No sign-in required. The shortlist remains shareable. Publishing and supplier access stay separate.
Find which providers match your exact needs
Move from a two-provider comparison into the live Netify RFP Builder and evaluate the wider market against your project.
Open the RFP BuilderAgent-accessible research
Ask the Fortinet, Inc. (trading and profile display name: Fortinet; SASE product line branded FortiSASE) research record
Answers are calculated from the published record below. Missing evidence remains unconfirmed and every result identifies its source revision.
Record summary
- Current products
- 9
- Capabilities
- 67
- Coverage records
- 12
- Service models
- 34
- Compliance records
- 13
- Integration records
- 20
- Sector records
- 10
- Evaluation records
- 50
- Public sources
- 35
Products and delivery
9 records| Product | Category | Relationship | Delivery model | Target buyer |
|---|---|---|---|---|
| Fabric Connectors | Integration/orchestration framework | Partner | One-click activation against partner platforms via the Security Fabric architecture | SecOps/integration teams |
| FortiClient | Endpoint agent / Fabric Agent | Native | Client-based; delivers protection, compliance and secure access in one modular client | Managed devices |
| FortiGuard AI-Powered Security Services | Threat intelligence and AI-driven detection services | Native | Cloud-delivered | Security teams |
| FortiManager / FortiAnalyzer | Centralised management and analytics | Native | On-premises or cloud | NetOps/SecOps admins |
| FortiSASE | Converged SASE platform | Native | Cloud-delivered, FortiOS running as VM instances in cloud PoPs | All buyers |
| FortiSASE Sovereign | Private, self-operated SASE cloud | Native | Customer-operated private cloud, turnkey | Service providers, large organisations, governments in highly regulated environments |
| FortiSOC / FortiSIEM / FortiSOAR | Security operations, SIEM, SOAR | Native | Cloud or on-premises | SOC teams |
| Fortinet Secure SD-WAN | SD-WAN / branch connectivity | Native | FortiGate appliances, cloud-managed via FortiManager | Branch/site buyers |
| Universal ZTNA | Zero Trust Network Access | Native | Automatic, encrypted per-session tunnels via FortiClient | All buyers |
Capability evidence
67 recordsAi Automation14 records
| Capability | Support | Confidence | Freshness | Qualification |
|---|---|---|---|---|
| AI assistant/copilot | Requires Confirmation | Unresolved | Current | Not confirmed |
| AI data protection controls | Requires Confirmation | Unresolved | Current | Not confirmed |
| Anomaly detection | Requires Confirmation | Unresolved | Current | Depth of the ML methodology not disclosed |
| Automated policy recommendation | Unknown | Unresolved | Current | Not confirmed |
| Automated remediation | Requires Confirmation | Unresolved | Current | Not confirmed |
| Capacity/path optimisation | Requires Confirmation | Unresolved | Current | Sourced via third-party technical analysis rather than a primary Fortinet datasheet in this pass |
| Configuration generation | Unknown | Unresolved | Current | Not confirmed |
| Digital experience diagnostics | Requires Confirmation | Unresolved | Current | Not confirmed |
| Generative AI application controls | Requires Confirmation | Unresolved | Current | Announced only months before this profile's research; specific sub-capability GA status not itemised |
| Natural-language querying | Unknown | Unresolved | Current | Not confirmed |
| Report summarisation | Unknown | Unresolved | Current | Not confirmed |
| Root-cause analysis | Requires Confirmation | Unresolved | Current | Not confirmed |
| Threat detection/classification | Requires Confirmation | Unresolved | Current | Same as above |
| User/entity behaviour analytics | Requires Confirmation | Unresolved | Current | Not confirmed |
Architecture15 records
| Capability | Support | Confidence | Freshness | Qualification |
|---|---|---|---|---|
| 5G/LTE support | Requires Confirmation | High | Current | Native - explicitly named as one of the WAN transports monitored by the SD-WAN fabric's SLA monitoring |
| Application identification | Requires Confirmation | High | Current | Native - DPI-based application identification feeding the SD-WAN fabric's routing decisions |
| Branch LAN/WLAN integration | Supported | Medium High | Current | Native, implied via Fortinet's broader networking hardware line (FortiSwitch, FortiAP) sitting alongside FortiGate in the same Security Fabric and managed through the same FortiManager/FortiAnalyzer console |
| Brownfield migration support | Supported | High | Current | Native - Fortinet Advanced Deployment Services (ADS) explicitly described as simplifying onboarding through guided planning, automated configuration, and rapid policy migration with minimal disruption to users and operations |
| Dynamic path selection | Requires Confirmation | High | Current | Native - automatic path selection based on per-application performance thresholds for latency, jitter and packet loss across all WAN transports |
| Edge form factors | Unknown | Medium | Current | FortiGate physical and virtual appliances across the standard Fortinet hardware range, connecting to FortiSASE via IPsec/GRE overlay tunnels; specific model/throughput range not itemised in a single source in this pass |
| Forward error correction / packet duplication | Requires Confirmation | Low | Current | Not confirmed as a distinct named capability in sources reviewed |
| High availability | Supported | Medium | Current | Native, referenced specifically for FortiSASE Sovereign deployments ('global redundancy' at the higher subscription tier per third-party pricing analysis) and implied more broadly via FortiGate's established HA/clustering capability |
| LEO satellite support | Unknown | Low | Current | Unknown - not found in sources reviewed |
| Local internet breakout | Supported | Medium High | Current | Native, implied via the SD-WAN Overlay to IaaS capability and automatic best-path discovery for major SaaS providers |
| QoS and traffic engineering | Requires Confirmation | Medium High | Current | Native, implied via the confirmed per-application SLA monitoring and path-selection thresholds |
| Segmentation / VRF capability | Unknown | Low | Current | Unknown - not found in sources reviewed |
| Supported WAN underlays | Requires Confirmation | High | Current | Native - MPLS, broadband, and LTE/5G all explicitly monitored and routed by the SD-WAN fabric's SLA monitoring and automatic path selection |
| Virtual/cloud edge support | Requires Confirmation | High | Current | Native - FortiOS runs as virtual machine instances in FortiSASE's cloud points of presence, and FortiGate itself is available in virtual-appliance form for private/public cloud deployment |
| Zero-touch provisioning | Supported | High | Current | Native, implied via FortiManager's orchestration stack, which is 'designed to manage thousands of sites without linear growth in operational complexity', with new branch FortiGates registering via serial number or pre-shared token |
Core Capabilities15 records
| Capability | Support | Confidence | Freshness | Qualification |
|---|---|---|---|---|
| Application-aware routing | Requires Confirmation | High | Current | None identified |
| CASB - API | Requires Confirmation | Low | Current | Not confirmed as distinct from inline CASB |
| CASB - inline | Supported | Medium High | Current | None identified |
| Cloud firewall / cloud network security | Requires Confirmation | High | Current | None identified |
| DNS security | Requires Confirmation | Medium High | Current | None identified |
| Data loss prevention | Requires Confirmation | Low Medium | Current | Not confirmed as included in FortiSASE specifically versus the broader FortiOS/FortiGate line |
| Digital experience monitoring | Requires Confirmation | Low Medium | Current | FortiMonitor exists as a named product but its integration depth with FortiSASE specifically wasn't confirmed in this pass |
| Firewall as a Service | Requires Confirmation | High | Current | None identified |
| Multi-cloud networking | Supported | Medium High | Current | Hyperscaler-by-hyperscaler cloud on-ramp detail (comparable to named AWS/Azure/GCP integration architecture) not itemised to the same depth |
| SD-WAN | Requires Confirmation | High | Current | None identified |
| SaaS security posture | Requires Confirmation | Low | Current | Not confirmed |
| Secure web gateway | Supported | High | Current | None identified |
| Threat intelligence | Requires Confirmation | High | Current | None identified |
| WAN optimisation | Supported | Medium High | Current | None identified |
| ZTNA | Requires Confirmation | High | Current | None identified |
Remote Access9 records
| Capability | Support | Confidence | Freshness | Qualification |
|---|---|---|---|---|
| Clientless access | Requires Confirmation | Unresolved | Current | Unknown |
| Contractors/third parties | Requires Confirmation | Unresolved | Current | Unknown |
| Managed laptops | Supported | Unresolved | Current | None identified |
| Mobile devices | Requires Confirmation | Unresolved | Current | None identified |
| Privileged access | Requires Confirmation | Unresolved | Current | Appears to be a separate product line, not confirmed as a native FortiSASE feature |
| Remote browser isolation | Requires Confirmation | Low | Current | Not confirmed |
| Remote browser isolation | Requires Confirmation | Unresolved | Current | Unknown |
| Unmanaged/BYOD devices | Requires Confirmation | Unresolved | Current | Depth of BYOD-specific policy control not independently confirmed |
| VDI environments | Unknown | Unresolved | Current | Not confirmed |
Reporting Analytics14 records
| Capability | Support | Confidence | Freshness | Qualification |
|---|---|---|---|---|
| Application performance | Requires Confirmation | Unresolved | Current | Not confirmed |
| Compliance reporting | Unknown | Unresolved | Current | Not confirmed |
| Custom reports | Unknown | Unresolved | Current | Not confirmed |
| DLP events | Requires Confirmation | Unresolved | Current | Not confirmed |
| Executive dashboard | Requires Confirmation | Unresolved | Current | Not confirmed |
| Network health | Supported | Unresolved | Current | Not confirmed |
| Raw log access | Requires Confirmation | Unresolved | Current | Not confirmed |
| Remote-user experience | Requires Confirmation | Unresolved | Current | Not confirmed |
| SLA reporting | Requires Confirmation | Unresolved | Current | Not confirmed |
| Scheduled reports | Unknown | Unresolved | Current | Not confirmed |
| Security events | Supported | Unresolved | Current | Not confirmed |
| Site and circuit performance | Requires Confirmation | Unresolved | Current | Not confirmed |
| Threat reporting | Supported | Unresolved | Current | Not confirmed |
| User experience | Requires Confirmation | Unresolved | Current | Not confirmed |
Geographic coverage
12 records| Geography | Delivery type | Relationship | Confidence | Qualification |
|---|---|---|---|---|
| Africa coverage | Unknown - Not Itemised In Sources Reviewed | Unknown | Low | Unknown - not itemised in sources reviewed | Unknown | Not specified | No named data centres found | Not found in a Tier 1-2 source in this pass | Low | Evidence gap. |
| Asia-Pacific coverage | Partially Evidenced Via The Confirmed China-Specific Ordering Process; Broader APAC Coverage Detail (Japan, Australia, Southeast Asia By Name) Not Found In This Pass | Partner | Low Medium | Partially evidenced via the confirmed China-specific ordering process; broader APAC coverage detail (Japan, Australia, Southeast Asia by name) not found in this pass | Partner (China specifically); unknown elsewhere in the region | China confirmed; other APAC countries not itemised | No formal regional PoP map found beyond the China-specific process | Low-Medium | The China-specific finding is a genuine, useful data point; broader APAC coverage remains an open question worth closing directly. |
| Carrier interconnects | Unknown - Not Itemised In Sources Reviewed | Unknown | Low | Unknown - not itemised in sources reviewed | Unknown | Unknown | No specific carrier/exchange detail found | Not found in a Tier 1-2 source in this pass | Low | Evidence gap. |
| China coverage | Confirmed As A Distinct, Separately-Ordered Service - 'FortiSASE China Must Be Ordered Separately Via An Authorised SASE Partner In China', Per Fortinet'S Own Ordering Guide | Partner | High | Confirmed as a distinct, separately-ordered service - 'FortiSASE China must be ordered separately via an authorised SASE partner in China', per Fortinet's own ordering guide | Partner (authorised in-country SASE partner) | China, via a named partner-delivery model | The specific partner(s) and licensing arrangement weren't detailed in this pass | High | A specific, primary-sourced, unusually precise piece of evidence - Fortinet's own ordering documentation explicitly separates the China ordering process, which is genuinely useful for a multinational buyer to know upfront. |
| Data residency choices | Confirmed At The Architectural Level Via FortiSASE Sovereign, Which Gives Buyers Full Control Over Deployment, Architecture And Services Specifically To Ensure Compliance And Data Sovereignty | Owned | High | Confirmed at the architectural level via FortiSASE Sovereign, which gives buyers full control over deployment, architecture and services specifically to ensure compliance and data sovereignty | Direct (customer-operated private cloud) | Wherever a FortiSASE Sovereign deployment is stood up | Specific country/region deployment options for Sovereign not itemised | High | A genuinely strong, distinctive data-residency answer - a dedicated, named product built specifically for this requirement rather than a generic assurance. |
| Latin America coverage | Unknown - No Specific Evidence Found In This Pass | Unknown | Low | Unknown - no specific evidence found in this pass | Unknown | Not specified | No named data centres or customer evidence found for this region specifically | Not found in a Tier 1-2 source in this pass | Low | Evidence gap. |
| Middle East coverage | Unknown - Not Itemised In Sources Reviewed | Unknown | Low | Unknown - not itemised in sources reviewed | Unknown | Not specified | No named data centres found | Not found in a Tier 1-2 source in this pass | Low | Evidence gap. |
| Private backbone | Not Confirmed As An Owned Private Backbone In Sources Reviewed; FortiSASE'S Cloud PoP Model Implies Either Owned Or Hyperscaler-Hosted Infrastructure, But The Specific Architecture Wasn'T Detailed In This Pass | Unknown | Low | Not confirmed as an owned private backbone in sources reviewed; FortiSASE's cloud PoP model implies either owned or hyperscaler-hosted infrastructure, but the specific architecture wasn't detailed in this pass | Unknown | Unknown | Architecture detail not found at sufficient depth to characterise confidently | Not found in a Tier 1-2 source in this pass | Low | A genuine evidence gap - this profile cannot currently state with confidence whether FortiSASE PoPs run on owned infrastructure, a hyperscaler backbone, or internet peering. |
| Public cloud on-ramps | Native, Via SD-WAN Overlay To IaaS With Automatic Best-Path Discovery To Named SaaS Providers (Microsoft 365, Salesforce, Zoom Specifically) | Owned | Medium High | Native, via SD-WAN Overlay to IaaS with automatic best-path discovery to named SaaS providers (Microsoft 365, Salesforce, Zoom specifically) | Direct | Wherever those providers have regions | Broader IaaS hyperscaler-specific architecture (AWS/Azure/GCP by name) less itemised than the named SaaS provider optimisation | Medium-High | The named SaaS provider optimisation is concrete and credible; deeper hyperscaler IaaS architecture detail is a gap worth closing directly. |
| SD-WAN gateways / cloud gateways | Delivered Via The Same FortiSASE PoP Infrastructure That FortiGate Appliances Connect To Via IPsec/GRE Overlay Tunnels | Owned | Medium | Delivered via the same FortiSASE PoP infrastructure that FortiGate appliances connect to via IPsec/GRE overlay tunnels | Direct | Same as above | None identified beyond the general PoP-count gap above | 22 Jul 2026 | Medium | Consistent with the confirmed converged-platform architecture. |
| Security PoPs / service edges | Referenced As Points Of Presence (PoPs) On Fortinet'S Own 'Universal SASE Platform', Without A Specific Published Count Found In This Pass | Owned | Low Medium | Referenced as points of presence (PoPs) on Fortinet's own 'Universal SASE platform', without a specific published count found in this pass | Direct (Fortinet-operated) | Global, unspecified count | No specific PoP count or region-by-region map found in sources reviewed | fortinet.com Secure SD-WAN Customer Success Stories eBook (referencing FortiSASE PoPs generally) | Low-Medium | A specific, worth-flagging evidence gap - no headline PoP count comparable to competitors' published figures was found in this research pass; worth a direct question to Fortinet. |
| Sovereign/regional service options | Confirmed - FortiSASE Sovereign Is Explicitly Described As An 'Industry-First Turnkey Solution' For Service Providers, Large Organisations And Governments Needing Their Own Private Cloud SASE Service | Owned | High | Confirmed - FortiSASE Sovereign is explicitly described as an 'industry-first turnkey solution' for service providers, large organisations and governments needing their own private cloud SASE service | Direct | Deployable wherever the customer chooses to operate it | None identified | High | The 'industry-first' framing is Fortinet's own claim and not independently verified by Netify, but the underlying product - a genuinely turnkey, customer-operated private SASE cloud - is well-documented and credible. |
Service models
34 recordsOther
UnknownUnknown - not found in sources reviewed | Not found | Not specified | Not confirmed | N/A | Not confirmed | Not found in a Tier 1-2 source in this pass | Evidence gap.
Other
Requires ConfirmationNot applicable in the same sense as an owned-backbone vendor, though the underlying FortiSASE PoP architecture (owned, hyperscaler-hosted, or peering-based) isn't independently confirmed | N/A | N/A | N/A | N/A | N/A | N/A | Structurally uncertain rather than clearly non-applicable, given the unresolved architecture question in Table 7.
Other
Requires ConfirmationNot confirmed as a distinct named support tier in sources reviewed | Not confirmed | Not specified | Not confirmed | N/A | Not confirmed | Not found at this level of detail in a Tier 1-2 source in this pass | Evidence gap - worth a direct follow-up on whether a named TAM-equivalent support tier exists for FortiSASE.
Other
UnknownCloud-delivered FortiSASE updates are managed centrally; FortiGate appliance firmware updates are managed via FortiManager, a well-established Fortinet operational pattern | FortiManager | Low, given FortiManager's established firmware-management role | Centralised via FortiManager | Low | None significant identified | FortiManager's long-standing role in Fortinet's operating model is a genuine, credible operational strength.
Other
Requires ConfirmationFortiClient install, provisioned via SAML SSO (Okta confirmed) | FortiManager / FortiSASE console + FortiClient | End-user self-install typical, benefiting from FortiClient's established track record | SSO-based provisioning confirmed via Okta integration | Low, given FortiClient's maturity and confirmed SSO support | None significant identified | okta.com Integrate FortiSASE with Okta (Okta's own integration catalogue page) | A named, independently-confirmed SSO integration (via Okta's own page, not just Fortinet's marketing) is genuinely credible, corroborated evidence.
Other
Requires ConfirmationNot confirmed as a distinct named service in sources reviewed, beyond the general Advanced Deployment Services migration offering | Fortinet Advanced Deployment Services | As above | Shared | Buyers wanting guided/assisted implementation | Not fully detailed as an ongoing co-managed model versus a one-time migration service | fortinet.com FortiSASE Ordering Guide | ADS is confirmed as a real, named migration-assistance service; whether an ongoing co-managed operational model exists beyond initial deployment wasn't separately confirmed in this pass.
Other
UnknownUnknown - not found in sources reviewed for FortiGate appliance RMA/replacement terms specifically within a FortiSASE/SASE context | Not found | Not found | Not confirmed | Not confirmed | Not confirmed | Not found in a Tier 1-2 source in this pass | Evidence gap.
Other
Requires ConfirmationConfirmed, specifically for FortiSASE Sovereign - 'simplifies operations and enables centralized management of multiple customers or business units on a single platform, with strict data isolation' | FortiSASE Sovereign console | MSP/partner-level or large-organisation administrators | Not itemised further | Confirmed to exist with specific, named mechanics (data isolation, RBAC) | None significant identified for Sovereign specifically | Well-evidenced specifically for the Sovereign product line - a genuine, named multi-tenancy capability rather than an inferred one.
Other
SupportedYes | FortiGate physical appliance | Appliance → FortiSASE PoP | FortiManager | Distributed branch/hospitality/retail estates | Low (per named customer evidence) | See Table 4 - zero-touch registration, Advanced Deployment Services for migration | Well evidenced via multiple named customer case studies describing distributed-site deployment at genuine scale.
Other
Requires ConfirmationNot confirmed as a distinct, named Fortinet-operated NOC service for FortiSASE specifically in sources reviewed | Not confirmed | Not itemised | Not confirmed | Customer configures policy; Fortinet operates the underlying cloud infrastructure by inference | Not itemised with specific figures | Not found at this level of detail in a Tier 1-2 source in this pass | A genuine evidence gap - worth a direct follow-up with Fortinet's own support documentation for specific SLA figures.
Other
Requires ConfirmationNot confirmed as a distinct named service in sources reviewed | Not confirmed | N/A | Not confirmed | Not confirmed | Not confirmed | Not found in a Tier 1-2 source in this pass | Evidence gap.
Other
SupportedCloud-based FortiSASE tenant setup, with a proof-of-concept tenant available that can be extended to a production tenant per Fortinet's own ordering documentation | FortiManager / FortiSASE cloud console | General IT admin | PoC-to-production extension confirmed as a supported path | Positioned as straightforward, reinforced by a named customer executive describing user experience as seamless post-deployment | None significant identified in sources reviewed | The confirmed PoC-to-production extension path is a genuinely useful, practical detail for buyers wanting to trial before committing fully.
Other
Requires ConfirmationConfirmed at a specific level for FortiCare Support Services - '24x7 technical support and access to over 1,900 experts' per Fortinet's own GovRAMP announcement | 24x7, with a specific named expert-count figure (1,900+) | Global (implied) | Included with FortiCare Support Services | N/A | Not itemised with a further specific SLA figure beyond the 24x7 claim | fortinet.com press release - Achieves GovRAMP Security Authorization | A specific, quantified detail (1,900+ experts) is genuinely more concrete evidence than a generic '24x7 support' claim.
Other
Requires ConfirmationConfirmed via Fortinet Advanced Deployment Services, which explicitly includes guided planning and automated configuration as part of onboarding | Not itemised | N/A | A named, distinct service (ADS) | Shared between customer and Fortinet during onboarding | Not itemised | Real, specific, primary-sourced evidence for the onboarding phase specifically; ongoing configuration-management support beyond initial deployment wasn't separately detailed.
Other
Requires ConfirmationNot confirmed as a distinct named IR service with a specific SLA in sources reviewed, though FortiGuard AI-Powered Security Services and FortiSOC both plausibly support this function | Not confirmed | N/A | Not confirmed | N/A | Not itemised with a specific figure | Not found at this level of detail in a Tier 1-2 source in this pass | Evidence gap for a distinctly-named IR service with its own SLA, though underlying capability (FortiGuard, FortiSOC) is real.
Other
Requires ConfirmationNot confirmed as a distinct, separately-branded MDR service (comparable to a named MDR product with its own SLA) in sources reviewed, though FortiSOC, FortiSIEM/FortiSOAR and SOC-as-a-Service all provide adjacent, real capability | Not confirmed | Not itemised by location | SOC-as-a-Service implies a managed offering exists in some form | N/A | Not itemised with a specific figure | A specific evidence gap for a single, clearly-named MDR product with its own contractual SLA - worth a direct follow-up on whether SOC-as-a-Service functions as this equivalent.
Other
SupportedYes | FortiClient | Client → FortiSASE PoP | FortiManager | Managed-device remote/hybrid workforce | Low | N/A | FortiClient's long, established track record as Fortinet's endpoint agent is a genuine maturity advantage for this deployment model.
Other
Requires ConfirmationNot confirmed as a distinct, named AI-driven troubleshooting/diagnostics capability comparable to a dedicated DEM correlation feature, though FortiOS 8.0 introduces fabric-based AI agents more broadly across the Security Fabric | Not fully detailed for FortiSASE specifically | Reduced specialist requirement implied by the broader AI-agent investment, though not itemised for troubleshooting specifically | Fabric-based AI agents confirmed as a March 2026 FortiOS 8.0 capability | Not itemised | Not itemised | The fabric-based AI agents capability is real, current and confirmed, but its specific application to FortiSASE troubleshooting/diagnostics (as opposed to the broader Security Fabric) wasn't detailed with the same specificity as some competitors' named DEM correlation features.
Other
Requires ConfirmationConfirmed - FortiSOC named specifically as a unified SOC offering, alongside SOC-as-a-Service (SOCaaS) as a distinct, separately-listed product | Not confirmed with a specific figure | Not itemised by location | SOC-as-a-Service implies a distinct, premium managed offering | Depends on tier/product chosen | Not itemised with specific figures | Confirmed to exist as named, distinct products; specific SLA/operational detail wasn't found in this pass.
Other
UnknownUnified policy management via FortiManager across FortiSASE and any existing FortiGate estate | FortiManager | Benefits from prior FortiGate/FortiOS familiarity, though not confirmed as a strict requirement | Not itemised | Positioned as simple for existing Fortinet customers specifically, given shared policy constructs across the product family | None significant identified | The single-console, single-policy-model story is a genuine, credible strength for existing FortiGate customers, and a less differentiated story for buyers with no prior Fortinet estate.
Other
Requires ConfirmationConfirmed at a specific level for FortiSASE Sovereign specifically - 'strict data isolation and role-based access to keep environments secure and separated' in multi-tenant Sovereign deployments | FortiSASE Sovereign console | Not fully detailed for the standard multi-tenant FortiSASE product specifically | Not itemised further | Confirmed for Sovereign deployments; standard FortiSASE RBAC detail not separately itemised | None significant identified for Sovereign specifically | Confirmed specifically for the Sovereign product; whether the same granularity applies to standard multi-tenant FortiSASE wasn't separately detailed in this pass.
Other
Requires ConfirmationConfirmed specifically via FortiSASE Sovereign, explicitly designed to let service providers create customised SASE offerings for their own customers with full autonomy over features and architecture | FortiSASE Sovereign console | MSP/partner-level administrators | Not itemised further | Not itemised | Not itemised | A real, specifically-named route for service-provider delivery - genuinely distinctive given how explicitly it's positioned for this exact buyer type.
Other
Requires ConfirmationUnknown for standard FortiSASE specifically - role-based access is confirmed for Sovereign deployments (see above), but delegated administration for standard multi-tenant FortiSASE wasn't separately detailed | Presumably FortiManager | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found at this level of detail in a Tier 1-2 source in this pass for standard FortiSASE | Evidence gap for the standard product specifically.
Other
SupportedYes | Mix of FortiClient, FortiGate appliances, FortiSASE cloud PoPs | Mixed | FortiManager, unified across on-premises and cloud | Most real-world enterprise estates, especially those with existing FortiGate footprint | Moderate, with named migration services available | Multiple case studies (large hospitality operator, large US school district evolving from Secure SD-WAN through NAC to FortiSASE) evidence real, phased hybrid adoption | The school district's specific, multi-stage evolution (SD-WAN, then NAC, then FortiSASE) is a genuinely credible, realistic picture of how hybrid deployment actually unfolds over time for a real customer.
Other
Requires ConfirmationNot independently confirmed as a distinct capability in sources reviewed | Unknown | Unknown | Unknown | Unknown | Not confirmed | Not confirmed | See Table 5 - a genuine, specific evidence gap.
Other
Requires ConfirmationConfirmed via Fortinet Advanced Deployment Services, though a specific cost range or scope boundary for this service wasn't itemised | N/A | N/A | A named, distinct service; cost not disclosed | N/A | N/A | Real, named service confirmed; specific cost detail is a gap worth closing directly with Fortinet.
Other
SupportedNative, implied via SD-WAN Overlay to IaaS with automatic best-path discovery to major SaaS providers | SD-WAN Overlay to IaaS | Cloud workload → FortiSASE | FortiManager | Multi-cloud/hybrid enterprises | Not fully detailed | Not itemised in detail | Confirmed as a named capability with specific SaaS providers cited (Microsoft 365, Salesforce, Zoom); broader IaaS hyperscaler architecture less granularly detailed.
Other
SupportedYes, via FortiGate appliances, not a self-contained on-prem product | FortiGate physical or virtual appliance | FortiGate → nearest FortiSASE PoP via IPsec/GRE overlay | FortiManager | Branch offices, data centres | Low (zero-touch registration via serial number/token) | Coexists with existing WAN transports (MPLS, broadband) per confirmed multi-transport support | Well-evidenced zero-touch registration mechanism, reinforced by a named migration service (ADS) for existing customers specifically.
Other
SupportedYes | FortiSASE (FortiOS as VM instances in cloud PoPs) | Via nearest FortiSASE point of presence | Centralised, FortiManager/cloud console | All customers - core delivery model | Low-Moderate | N/A - default | The default operating model, using the same operating system that runs on physical hardware - a genuinely consistent architectural story.
Other
SupportedFortiGate zero-touch registration via serial number or pre-shared token, supported by Advanced Deployment Services for guided migration | FortiManager (remote) | Low specialist requirement per the described zero-touch mechanism | Zero-touch registration confirmed | Positioned as low-effort via the confirmed automated registration and guided ADS migration path | None significant identified | Well-evidenced via a specific technical mechanism (serial-number/token registration) combined with a named migration-assistance service - solid, concrete evidence.
Other
Requires ConfirmationNot confirmed as a distinct, named Fortinet-delivered managed-service product in sources reviewed | Not confirmed | - | - | Buyers wanting full outsourcing | Not confirmed | Not found in a Tier 1-2 source in this pass | A specific evidence gap worth a direct follow-up - Fortinet's large channel/partner ecosystem likely supports this in practise even without a single named managed-SASE product surfaced in this research pass.
Other
UnknownUnknown - not found in sources reviewed | Presumably FortiManager/API | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in public sources reviewed | Evidence gap.
Other
UnknownUnified via FortiManager across FortiSASE, FortiGate appliances, and the broader Security Fabric product line | N/A | N/A | Included | Customer-managed via FortiManager, with ADS support available during onboarding | N/A | A genuine, confirmed unification point across a very broad product range - a real operational strength for buyers standardising on Fortinet across networking and security.
Other
SupportedYes | FortiGate virtual appliance (VM) | VM → nearest FortiSASE PoP | FortiManager | Cloud/virtualised data centres | Low | Deploy as VM image; same FortiOS as physical appliances | A genuine, architecturally consistent option given FortiOS runs identically whether physical or virtual.
Compliance and assurance
13 records| Framework | Scope | Support | Review date | Qualification |
|---|---|---|---|---|
| DORA relevance | N/A | Unknown | Not stated | Unknown - not found in sources reviewed | N/A | Not confirmed | EU financial services | Not found in a Tier 1-2 source in this pass | Not found | Evidence gap - worth flagging for financial-services sector suitability assessment (Table 14). |
| Data residency | Wherever a Sovereign deployment is stood up by the customer | Unknown | Not stated | Strong - FortiSASE Sovereign is a dedicated, named product built specifically to give buyers full control over where and how SASE is deployed, enforcing policies aligned to local regulations | Wherever a Sovereign deployment is stood up by the customer | FortiSASE Sovereign | Customer-determined, by design | 22 Jul 2026 | A genuinely strong, distinctive answer to data residency - a purpose-built product rather than a general assurance, worth highlighting specifically to buyers with strict data-location requirements. |
| Encryption/key management | Platform-wide, as of the March 2026 FortiOS 8.0 release | Requires Confirmation | Not stated | Confirmed at a specific, current level - FortiOS 8.0 introduces quantum-resilient cryptographic controls securing critical management access paths (including agentless VPN connectivity) using Post-Quantum Cryptography certificates such as ML-DSA, plus SSL deep inspection strengthened by hybrid key exchange and post-quantum-safe cryptography | Platform-wide, as of the March 2026 FortiOS 8.0 release | Post-Quantum Cryptography (ML-DSA), hybrid key exchange for SSL deep inspection | None identified | 22 Jul 2026 | Genuinely current, specific, and technically detailed - naming an actual PQC algorithm (ML-DSA) rather than a vague 'quantum-ready' marketing claim is a real, credible technical commitment. |
| FedRAMP | US state/local government (GovRAMP Moderate confirmed); US federal (FedRAMP status unconfirmed/pending as of the most recent source found) | Requires Confirmation | Not stated | Not confirmed as achieved as of the most recent primary source found in this pass - Fortinet's own April 2025 announcement explicitly states the company 'intends to also pursue' FedRAMP certification, framing it as a future goal rather than a current authorization; no FortiSASE-specific listing was found on the official FedRAMP Marketplace in this pass. GovRAMP (formerly StateRAMP) authorization at the Moderate impact level is confirmed for FortiGuard AI-Powered Security Services and FortiCare Services specifically, following an independent third-party assessing organisation audit | US state/local government (GovRAMP Moderate confirmed); US federal (FedRAMP status unconfirmed/pending as of the most recent source found) | GovRAMP Moderate (two named services); FedRAMP status not confirmed as achieved | US state/local and federal government | 22 Jul 2026 | A precise, important distinction: GovRAMP Moderate is genuinely confirmed and audited, but FedRAMP itself - a materially different, federal-specific programme - was described by Fortinet's own most recent public statement as a future intention rather than an achieved authorization. Buyers needing FedRAMP specifically should confirm current status directly with Fortinet rather than assume GovRAMP is equivalent. |
| GDPR | N/A | Unknown | Not stated | Not separately itemised as a distinct compliance line item in sources reviewed | N/A | Not confirmed | EU/UK relevant | Not found in a Tier 1-2 source in this pass | Not found | Worth a direct follow-up; Fortinet's established European operations make broader GDPR compliance infrastructure likely, even without FortiSASE-specific documentation surfaced in this pass. |
| HIPAA | Confirmed for one named customer's specific regulatory context; not confirmed as a formal, general HIPAA attestation by Fortinet itself | Unknown | Not stated | Referenced qualitatively via a named customer case study - encryption of data in transit is described as meeting 'compliance requirements of the California Department of Health Care Services' for one customer's specific deployment | Confirmed for one named customer's specific regulatory context; not confirmed as a formal, general HIPAA attestation by Fortinet itself | Customer-specific compliance outcome, not a formal Fortinet attestation | US healthcare-relevant, California-specific in the case study | avfirewalls.com Case Study: The Guidance Centre (third-party reseller, quoting the customer's compliance outcome) | Medium | A real-world compliance outcome for one named customer is useful corroborating evidence, but it is not the same evidentiary weight as a formal, general Fortinet HIPAA attestation - the distinction is worth being precise about. |
| ISO 27001 | Platform/company, with a specific named FortiAnalyzer feature producing an 'ISO 27001:2022 Compliance Security Rating Report' | Unknown | Not stated | Certified | Platform/company, with a specific named FortiAnalyzer feature producing an 'ISO 27001:2022 Compliance Security Rating Report' | ISO/IEC 27001:2022 explicitly referenced, alongside a broader Fortinet product-certifications page listing ISO/IEC 27001 generally | None identified | 22 Jul 2026 | Unusually well-evidenced via a specific, dated, product-level feature (a named compliance report generator) rather than just a general certification claim. |
| Logging/auditability | Platform | Requires Confirmation | Not stated | Native, via FortiAnalyzer's confirmed compliance-reporting feature and the broader Fabric ecosystem's integration with external SIEM/ITSM tools | Platform | FortiAnalyzer; Fabric Connector/API integrations | None identified | 22 Jul 2026 | Well-evidenced via a specific, named, dated compliance-reporting feature - genuinely useful, concrete evidence. |
| NHS DSPT relevance | N/A | Unknown | Not stated | Unknown - not found in sources reviewed | N/A | Not confirmed | UK | Not found in a Tier 1-2 source in this pass | Not found | Evidence gap - a direct follow-up question for Netify's UK healthcare-sector work. |
| NIS2 relevance | N/A | Unknown | Not stated | Unknown - not found in sources reviewed | N/A | Not confirmed | EU | Not found in a Tier 1-2 source in this pass | Not found | Evidence gap. |
| PCI DSS | N/A | Requires Confirmation | Not stated | Not confirmed in sources reviewed | N/A | Not confirmed | N/A | Not found in a Tier 1-2 source in this pass | Not found | Same treatment as SOC 2 above - a research-pass limitation to close directly rather than a confident negative finding. |
| SOC 2 | N/A | Requires Confirmation | Not stated | Not confirmed in sources reviewed | N/A | Not confirmed | N/A | Not found in a Tier 1-2 source in this pass | Not found | A genuine evidence gap worth a direct follow-up given Fortinet's scale and established compliance programme - this likely reflects a research-pass limitation rather than confident evidence of absence. |
| UK public sector frameworks | UK | Unknown | Not stated | Unknown - not found in sources reviewed | UK | Not confirmed | UK | Not found in a Tier 1-2 source in this pass | Not found | Evidence gap - worth a direct follow-up given Fortinet's established UK operations more broadly. |
Integrations
20 recordsAWS
Cloud · Native
Cloud | Native, confirmed via Fabric Connectors - 'Dynamic Policy - Cloud: AWS' explicitly named among Fortinet's first set of Fabric Connectors | Bidirectional | Not specified | A specific, named, dated (2018) integration, part of the original Fabric Connector launch set | High | Confirmed, named, and long-standing - one of the original Fabric Connector integrations, giving it a genuinely proven track record.
Active Directory
Identity · Unknown
Identity | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
CrowdStrike
EDR · Unknown
EDR | Not independently confirmed via a primary Fortinet source in this pass; third-party pricing-comparison sources reference CrowdStrike's own integrations with Splunk, Cortex XSOAR, ServiceNow and others generally, but not a confirmed, named Fortinet-CrowdStrike integration specifically | Unknown | Not specified | Not detailed | Not found as a confirmed, named integration in a Tier 1-2 source in this pass | Low | A specific, worth-flagging gap - given Fortinet's own competing EDR product line (FortiEDR), a formal CrowdStrike partnership may be less central to Fortinet's own ecosystem messaging than for other vendors; worth confirming directly.
Google Cloud
Cloud · Unknown
Cloud | Not separately named in the specific Fabric Connector list found in this pass (AWS, Azure, Oracle were named; Google Cloud was not) | Unknown | Not specified | Not detailed | Low-Medium | A specific, worth-noting gap - the sources reviewed named AWS, Azure and Oracle Fabric Connectors explicitly, but not Google Cloud; this may reflect incomplete research rather than an actual product gap, and is worth a direct confirmation.
Google Workspace
Identity/Productivity · Unknown
Identity/productivity | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Intune
MDM/UEM · Unknown
MDM/UEM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Jamf
MDM/UEM · Unknown
MDM/UEM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Microsoft 365
Productivity/SaaS · Native
Productivity/SaaS | Native, confirmed - explicitly named as one of the SaaS providers automatically path-optimised by the SD-WAN fabric's application intelligence | Fortinet monitors/optimises traffic to Microsoft 365 | Not specified | Not detailed beyond the confirmed path-optimisation claim | Medium-High | A specific, named integration (not a generic 'works with Office 365' claim) - reasonably good evidence quality.
Microsoft Azure
Cloud · Native
Cloud | Native, confirmed via Fabric Connectors - 'Dynamic Policy - Cloud: Microsoft Azure' explicitly named | Bidirectional | Not specified | Same original Fabric Connector launch set as AWS | High | Same evidence quality as the AWS row above.
Microsoft Defender
EDR · Unknown
EDR | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Microsoft Entra ID
Identity · Unknown
Identity | Not separately itemised from general SSO/SAML integration claims in sources reviewed (Okta is the specifically documented IdP) | Unknown | Not specified | Not detailed | Not found as a distinct integration in this pass | Low | Do not assume Entra ID parity with the confirmed Okta integration without direct confirmation.
Microsoft Sentinel
SIEM · Unknown
SIEM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Okta
Identity · Native
Identity | Native, confirmed via Okta's own integration catalogue - 'Okta integration with FortiSASE allows end users to authenticate to FortiSASE SSL VPN using Okta SAML SSO' | Bidirectional (auth) | Not specified | Listed in Okta's own catalogue with a specific integration description and a documented last-update date | High | Independently confirmed by the identity provider itself, not just Fortinet's own marketing - genuinely solid, corroborated evidence.
Palo Alto Cortex
SIEM/XDR · Unknown
SIEM/XDR | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap (unsurprising, given the two companies are direct competitors).
REST API
Platform API · Api
Platform API | Native, confirmed - Fabric APIs explicitly described as 'partner-developed Fabric API integrations for a broad range of ecosystem solutions', with an open, extensible architecture supporting a growing list of connector types | Bidirectional | Not specified | The Security Fabric ecosystem is reported at over 400 technology integrations in total across Fabric Connectors and Fabric APIs combined, spanning the full Open Ecosystem Partners directory | High | The 400+-integration figure is a genuinely large, specific, checkable claim - one of the broader integration ecosystems evidenced across the sources reviewed for this profile.
SCIM/SAML/OIDC
Identity Federation · Unknown
Identity federation | SAML explicitly confirmed via the Okta integration ('Okta SAML SSO') | Bidirectional (auth) | Not specified | Confirmed by name for SAML specifically; SCIM/OIDC not separately itemised | Medium-High | SAML is explicitly, independently confirmed; SCIM/OIDC support is a reasonable inference from standard IdP integration practise but wasn't separately named.
ServiceNow
ITSM · Native
ITSM | Native, confirmed via Fabric Connectors - 'Security Incident Response/ITSM: ServiceNow, Webhook' explicitly named among the original Fabric Connector set | Bidirectional (incident/ticket automation) | Not specified | Named, dated (2018) integration, part of the original Fabric Connector launch set | High | Confirmed, named, and long-standing - genuinely solid evidence.
Splunk
SIEM · Unknown
SIEM | Not independently confirmed via a primary Fortinet source in this pass, though third-party pricing/comparison sources reference Splunk as a common SIEM pairing for security platforms generally | Unknown | Not specified | Not detailed | Not found as a confirmed, named Fortinet-Splunk integration in a Tier 1-2 source in this pass | Low | A specific gap worth closing directly - Fortinet's Fabric API framework and 400+-integration ecosystem make a Splunk integration plausible, but it wasn't independently confirmed by name in this research pass.
Syslog
Log Export · Api
Log export | Not separately itemised in sources reviewed, though implied by the broader FortiAnalyzer/Fabric API integration framework | Unknown | Not specified | Not detailed | Not found explicitly by name | Low-Medium | Reasonable to assume given the confirmed broader integration ecosystem, not independently confirmed by name.
Terraform
Infrastructure-As-Code · Unknown
Infrastructure-as-code | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Sector evidence
10 recordsEducation
UnknownStrong fit, evidenced | Large-scale, phased deployment (Secure SD-WAN, then NAC, then FortiSASE) at genuine scale | Not assessed for sector-specific frameworks | A named top-five-largest US school district, 375,000+ students and staff | Single-country (US) evidence; UK/EU education-specific case studies not found in this pass | No case-study limitations beyond the single-country evidence noted | A genuinely large, well-evidenced, named-scale customer story - one of the strongest sector-fit findings in this profile, given both the scale (375K+) and the specific, credible multi-stage adoption narrative.
- Named evidence
- A named top-five-largest US school district, 375,000+ students and staff
- Case study strength
- Strong
Energy/utilities
UnknownUnknown - not assessed in detail, though Fortinet's own customer-story index references a power grid operator by category (not named) deploying a Fortinet SecOps solution for zero-day protection and IT/OT convergence | IT/OT convergence relevant per the referenced use case | Not assessed | Referenced but not independently detailed (unnamed power grid operator) | N/A | Reference exists but wasn't followed up to a named, detailed case study in this pass | A real, relevant use case is referenced in Fortinet's own materials but wasn't independently verified to the same depth as the hospitality or education evidence in this pass.
- Named evidence
- Referenced but not independently detailed (unnamed power grid operator)
- Case study strength
- Strong
Financial services
Not SupportedUnknown - no PCI-DSS, DORA, or named financial-services case study found in this pass | DLP, CASB plausibly relevant, though DLP itself is not confirmed as a distinct FortiSASE capability (Table 3) | Not confirmed | None found | N/A | No case study or compliance evidence found | A genuine, specific evidence gap - worth a direct follow-up given how many customer case studies Fortinet publishes overall, several of which weren't individually reviewed in this pass.
- Named evidence
- None found
- Case study strength
- None
Government/public sector
UnknownGood fit, evidenced | GovRAMP Moderate authorization; FortiSASE Sovereign for data-sovereignty requirements | GovRAMP Moderate (two named services); FedRAMP status unconfirmed as achieved | None found as a named FortiSASE-specific customer case study in this pass, though Fortinet's own customer-story index references a power grid operator and other public-infrastructure-adjacent deployments | GovRAMP confirmed at Moderate; FedRAMP-specific buyers should confirm current status directly | The precise GovRAMP-versus-FedRAMP distinction (Table 13) is the single most important nuance for this sector | A genuinely real, confirmed public-sector compliance foundation (GovRAMP Moderate, audited), but buyers needing FedRAMP specifically must verify current status directly rather than assume GovRAMP is sufficient or equivalent.
- Named evidence
- None found as a named FortiSASE-specific customer case study in this pass, though Fortinet's own customer-story index references a power grid operator and other public-infrastructure-adjacent deployments
- Case study strength
- None
Healthcare/NHS
Not SupportedConditional - one named customer's specific HIPAA-adjacent compliance outcome (California Department of Health Care Services) is evidenced, but no formal, general Fortinet HIPAA attestation was found | ZTNA, encryption confirmed relevant to the named case study specifically | Case-specific compliance outcome confirmed; general attestation not confirmed | The Guidance Centre (community mental-health-adjacent organisation, California) | N/A | A single, real-world compliance outcome rather than a formal attestation | Genuine, credible evidence for one specific regulatory context, but Netify should not extrapolate a general HIPAA-compliant claim from this single case without direct vendor confirmation.
- Named evidence
- The Guidance Centre (community mental-health-adjacent organisation, California)
- Case study strength
- Strong
Hospitality
UnknownStrong fit, evidenced | Distributed-site SD-WAN and cloud security consolidation at genuine global scale | Not assessed | A named global hospitality operator (4,000+ locations, 325,000+ employees, $19.4B gross annual revenue) reporting a 60% efficiency improvement for network and security teams; separately, IHG Hotels & Resorts is referenced as boosting IT efficiency 'close to 60%' with Fortinet Secure SD-WAN, which may be the same underlying customer story | Global, multi-location deployment evidenced directly at scale | The two hospitality references may describe the same underlying deployment rather than two independent proof points - worth confirming directly rather than double-counting as separate evidence | Genuinely the best-evidenced sector for Fortinet in this profile - specific, large, checkable scale figures (4,000+ locations, 325,000+ employees) and a consistent, repeated 60% efficiency figure across multiple Fortinet materials.
- Named evidence
- A named global hospitality operator (4,000+ locations, 325,000+ employees, $19.4B gross annual revenue) reporting a 60% efficiency improvement for network and security teams; separately, IHG Hotels & Resorts is referenced as boosting IT efficiency 'close to 60%' with Fortinet Secure SD-WAN, which may be the same underlying customer story
- Case study strength
- Strong
Manufacturing
Not SupportedUnknown - no named manufacturing case study found in this pass | SD-WAN/branch capability plausibly relevant | Not assessed | None found | N/A | No case study found | Evidence gap.
- Named evidence
- None found
- Case study strength
- None
Professional services
Not SupportedUnknown - no named professional-services case study found in this pass | Not assessed | Not assessed | None found | N/A | No case study found | Evidence gap.
- Named evidence
- None found
- Case study strength
- None
Retail
Requires ConfirmationUnknown - no named retail case study found specifically in this pass, though the confirmed hospitality and large-distributed-site evidence (below) is adjacent | SD-WAN/branch capability plausibly relevant | Not assessed | None found as a distinctly retail-labelled case study | N/A | No case study found | Evidence gap, though the underlying distributed-site SD-WAN capability evidenced elsewhere in this profile is directly relevant to this sector.
- Named evidence
- None found as a distinctly retail-labelled case study
- Case study strength
- None
Transport/logistics
Not SupportedUnknown - not assessed, no case study found in this pass, though Fortinet's own customer-story index separately references an airport operator and a major bank's remote-ATM/5G deployment | Not assessed in detail | Not assessed | Referenced but not independently detailed in this pass (airport operator, bank ATM network) | N/A | Named but under-detailed references exist and weren't followed up individually in this research pass | A specific, worth-flagging follow-up opportunity - Fortinet's own materials reference relevant transport/financial-infrastructure customers that weren't fully explored in this pass.
- Named evidence
- Referenced but not independently detailed in this pass (airport operator, bank ATM network)
- Case study strength
- Strong
Case studies
3 records- Customer
- Named - The Guidance Centre
- Sector and geography
- Healthcare-adjacent (community/social services) · United States (California)
- Estate
- Not quantified; Not quantified
- Outcome
- IT Director quote: 'Performance was one of my main concerns before we deployed, but we have received no feedback. It is like our end users do not even notice the security solution is there, which means it is working perfectly' (named executive: Ian Adduru, IT Director)
Named - The Guidance Centre | Healthcare-adjacent (community/social services) | United States (California) | Not quantified | Not quantified | Needed high-performance, enterprise-grade security for remote users on potentially unsecured networks, while meeting California Department of Health Care Services encryption requirements for sensitive data relating to disadvantaged children | FortiSASE, FortiClient (Fabric Agent), Universal ZTNA | Client-based remote access | Not itemised | IT Director quote: 'Performance was one of my main concerns before we deployed, but we have received no feedback. It is like our end users do not even notice the security solution is there, which means it is working perfectly' (named executive: Ian Adduru, IT Director) | Medium-High - named customer, named executive quoted directly, a specific regulatory-compliance context (California DHCS encryption requirements), though the organisation's overall scale (user/site count) wasn't quantified in the source reviewed | The named IT Director's specific quote about invisible, frictionless security is genuinely credible, qualitative evidence for user-experience claims, and the California DHCS compliance detail gives this case study real value for evaluating Fortinet's fit with regulated, sensitive-data use cases specifically.
- Customer
- Named - described as a global hospitality company; a separately-referenced IHG Hotels & Resorts case study reports a very similar outcome and may describe the same underlying deployment
- Sector and geography
- Hospitality · Global (4,000+ locations)
- Estate
- 325,000+ global employees; 4,000+ locations
- Outcome
- Network and security teams' efficiency improved by 60%; company reports $19.4 billion gross annual revenue, establishing the scale of the operation
Named - described as a global hospitality company; a separately-referenced IHG Hotels & Resorts case study reports a very similar outcome and may describe the same underlying deployment | Hospitality | Global (4,000+ locations) | 325,000+ global employees | 4,000+ locations | High bandwidth cost, complex operations, unable to meet cloud and security requirements at scale | Fortinet Secure SD-WAN, FortiSASE points of presence on the Fortinet Universal SASE platform | Distributed branch/site deployment across a very large global estate | Not itemised | Network and security teams' efficiency improved by 60%; company reports $19.4 billion gross annual revenue, establishing the scale of the operation | High - specific, large, checkable scale figures (4,000+ locations, 325,000+ employees, $19.4B revenue) and a consistent, repeated 60% efficiency figure appearing across separate Fortinet materials | One of the strongest pieces of quantified evidence found for Fortinet - genuinely large scale combined with a specific, consistent efficiency metric. Worth confirming directly whether this and the separately-referenced IHG Hotels & Resorts story are the same underlying customer before citing both as independent proof points.
- Customer
- Named as 'one of the top five largest school districts in the United States', though the specific district name wasn't captured in the source reviewed
- Sector and geography
- Education · United States
- Estate
- 375,000+ students and staff; Not itemised
- Outcome
- Successfully scaled to deliver secure remote access for 375,000+ students and staff; the phased SD-WAN-to-NAC-to-FortiSASE progression itself is the notable finding
Named as 'one of the top five largest school districts in the United States', though the specific district name wasn't captured in the source reviewed | Education | United States | 375,000+ students and staff | Not itemised | Facing challenges with remote security at very large scale, needing to deliver consistent learning experiences for staff and students from any location | Fortinet Secure SD-WAN (starting point), Fortinet NAC (added next), FortiSASE (current state) | Phased, multi-stage evolution across three distinct product adoptions over time | Not itemised | Successfully scaled to deliver secure remote access for 375,000+ students and staff; the phased SD-WAN-to-NAC-to-FortiSASE progression itself is the notable finding | High - a specific, large, named-scale figure (375,000+) combined with a credible, multi-stage adoption narrative that reads as a realistic account of how large organisations actually evolve toward SASE rather than a single big-bang deployment | The phased-adoption narrative (SD-WAN, then NAC, then FortiSASE) is genuinely useful, realistic evidence for buyers planning their own multi-year SASE journey rather than expecting an all-at-once transformation.
Netify evaluation record
50 recordsSummary
Global fit | A named, very large-scale hospitality customer (4,000+ locations globally) demonstrates real multinational deployment capability, and a specific, confirmed China-specific ordering process shows genuine operational maturity in that market, but a named-country network-coverage map (comparable to a published PoP-by-region breakdown) was not found in this research pass. | Table 7, 14 | Medium-High for evidenced customer scale; Low for the underlying network-coverage map specifically | Always verify buyer-specific country/region coverage directly with Fortinet rather than relying on the general scale evidenced by named customers, and note the confirmed distinct China ordering process specifically for any buyer with China-based operations.
Always verify buyer-specific country/region coverage directly with Fortinet rather than relying on the general scale evidenced by named customers, and note the confirmed distinct China ordering process specifically for any buyer with China-based operations.
Summary
SSE deployment to remote users | Client-based (FortiClient) rollout to remote/mobile users, provisioned via confirmed SAML SSO (Okta) | IdP integration (Okta confirmed) a documented prerequisite for SSO-based provisioning | End-user self-install typical for FortiClient | Not itemised | Not quantified with a specific duration | Not itemised | Not detailed | A named customer executive quote specifically describes remote users' security being effectively invisible to them post-deployment - a genuinely positive, specific piece of user-experience evidence for this exact scenario.
Summary
Reporting reality | Strong specifically for compliance reporting (a named, dated FortiAnalyzer feature producing an ISO 27001:2022 report) and for the underlying SD-WAN SLA-monitoring telemetry; weaker or unconfirmed on application-performance, user-experience, and executive dashboards, none of which have a confirmed, named, FortiSASE-specific product comparable to a dedicated DEM module. | Table 10 | Medium | Present the compliance-reporting strength specifically rather than imply comprehensive digital-experience-monitoring maturity across the board.
Present the compliance-reporting strength specifically rather than imply comprehensive digital-experience-monitoring maturity across the board.
Summary
Strength | A single operating system (FortiOS) and single-pass inspection engine runs identically across physical FortiGate hardware and FortiSASE's cloud points of presence, giving genuinely consistent security policy and behaviour regardless of where traffic is inspected | Buyers with an existing FortiGate estate get real architectural and operational consistency extending into the cloud, not a separately-engineered cloud product with different behaviour | Best: existing FortiGate customers extending into SASE. Less relevant: buyers with no interest in the on-premises/cloud consistency story specifically | sase.cloud FortiSASE Review 2026 (third-party technical analysis) | High | This is Fortinet's clearest, most defensible, most architecturally distinctive claim in this entire profile.
Buyers with an existing FortiGate estate get real architectural and operational consistency extending into the cloud, not a separately-engineered cloud product with different behaviour
Summary
Biggest operational concern | The documented gap between FortiSASE's headline list price and real total cost of ownership after common add-ons, combined with the sharply non-linear cost curve between subscription tiers, creates genuine risk of budget surprise for buyers who scope only the entry-tier headline figure. | Table 16, 19 | Medium | Netify should proactively flag this specific pricing-structure risk to buyers during the shortlist conversation.
Netify should proactively flag this specific pricing-structure risk to buyers during the shortlist conversation.
Summary
Scope & Boundaries | FortiSASE Sovereign gives Fortinet a genuinely distinctive private-cloud SASE offering for buyers who cannot use a shared multi-tenant platform at all, a capability not every SASE vendor offers in this specific turnkey form. | Advanced capabilities and global redundancy are concentrated in the higher (Comprehensive) tier specifically, per third-party pricing analysis - buyers evaluating only the entry tier should confirm exactly which capabilities in this profile's feature matrix are actually included at their target tier before assuming parity with the full platform.
Summary
When would Netify recommend it? (mandatory) | When a buyer already has, or is actively building, a FortiGate estate and wants architectural and commercial consistency extending into SASE; when a buyer specifically needs a fully sovereign, self-operated SASE cloud rather than a shared multi-tenant service; or when a buyer is a large, distributed-site organisation in hospitality, education, or a similar sector where the case-study evidence is genuinely strong. | Synthesis of Tables 1, 14, 15 | High | A clear, actionable recommendation trigger set for Netify's comparison tool to apply directly.
A clear, actionable recommendation trigger set for Netify's comparison tool to apply directly.
Summary
Remote-user-heavy organisation | Conditional fit | FortiClient's confirmed, independently-verified SSO integration (via Okta's own catalogue) and a specific, positive named-customer user-experience quote both support this use case, but the confirmed absence of a clientless/BYOD access route (Table 5) is a real, specific gap for this buyer profile specifically | Requires further direct confirmation on BYOD/clientless capability before recommending confidently | Not assessed | Table 5 findings | A genuinely bifurcated finding: strong for managed-device remote access specifically, materially weaker-evidenced for BYOD/unmanaged/clientless scenarios - worth a direct, specific follow-up question before recommending confidently to a BYOD-heavy buyer.
Summary
Questions to ask before recommending it | 1) Can Fortinet confirm current FedRAMP status specifically, distinct from the already-confirmed GovRAMP Moderate authorization? 2) Does our existing FortiGate estate (if any) qualify for Security Fabric pricing, and what is the actual discount at our scale? 3) Exactly which Table 3 capabilities are included at our target subscription tier, and what would the jump to Comprehensive tier actually cost given its documented non-linear pricing? 4) Can Fortinet confirm BYOD/clientless remote-access capability directly, given this wasn't found in public sources? | Synthesis of Tables 3, 13, 16 | High | A direct, reusable question set for Netify's advisory conversations with buyers considering Fortinet.
A direct, reusable question set for Netify's advisory conversations with buyers considering Fortinet.
Summary
Mature NetOps/SecOps team | Strong fit, especially for existing Fortinet customers | The confirmed, large (400+ integration) Fabric ecosystem, named long-standing integrations (AWS, Azure, ServiceNow since 2018), and the unified FortiManager/FortiAnalyzer console all support a mature toolchain approach for teams already invested in the Fortinet ecosystem | Mature teams benefit substantially from prior FortiOS/Security Fabric familiarity | Not assessed | Table 12 findings | Genuinely strong for teams already standardised on Fortinet's broader Security Fabric - the scale and age of the integration ecosystem is real, specific, and well-evidenced.
Summary
Procurement watch-out | FortiSASE China requires a separate ordering process through an authorised in-country SASE partner rather than the standard global ordering process, per Fortinet's own ordering documentation | Multinational buyers with China-based operations need to plan for a distinct procurement and delivery process for that specific market rather than assuming uniform global ordering | Most relevant to multinational buyers with China-based operations specifically | Table 7 findings | High (directly confirmed by Fortinet's own primary documentation) | A specific, primary-sourced, easy-to-overlook operational detail - genuinely useful for Netify to surface proactively to any multinational buyer during the shortlist conversation.
Multinational buyers with China-based operations need to plan for a distinct procurement and delivery process for that specific market rather than assuming uniform global ordering
Summary
Multi-vendor SASE integration | Evidenced via the confirmed, large (400+-integration) Fabric ecosystem, built specifically to synchronise security with 'dynamic operational changes' across 'complex multi-vendor ecosystems' per Fortinet's own materials | Existing security/identity tools already in place (Okta, AWS, Azure, ServiceNow all specifically documented as named, long-standing integrations) | Not itemised | Fabric Connectors and Fabric APIs, both confirmed | Not quantified | N/A | N/A | Fortinet's own Fabric Connector/API architecture is explicitly designed and marketed for exactly this scenario - genuinely well-suited by design, evidenced by a large, specific, long-standing (since at least 2018) integration ecosystem rather than a handful of recent partnerships.
Summary
Large enterprise | Strong fit, evidenced | A named global hospitality operator (4,000+ locations, 325,000+ employees) and a named top-five US school district (375,000+ students/staff) both demonstrate genuine enterprise-scale deployment | Requires internal or partner-supported operational ownership at scale | Comprehensive-tier pricing likely, with the Security Fabric discount most valuable at this scale for existing FortiGate estates | fortinet.com Secure SD-WAN Customer Success Stories eBook; fortinet.com Unified SASE Customer Success Stories eBook | Well evidenced via two independently named, large-scale customers with genuinely large, specific figures - strong evidence quality for this buyer profile.
Summary
Commercial reality | No public list pricing, though Fortinet's own ordering guide is genuinely specific about licensing mechanics (a confirmed 500-user Dedicated IP threshold); two independently-sourced third-party analyses converge on a directionally consistent per-user pricing picture and both confirm a genuinely distinctive, quantified loyalty discount (20-25%) for existing FortiGate customers, alongside a well-documented, steep non-linear cost curve between subscription tiers. | Table 16 | Medium (convergent third-party sourcing, no primary Fortinet pricing found) | Use as a rough planning signal, always routing to a direct Fortinet quote for real numbers, and proactively raise the Security Fabric discount as a specific, quantifiable negotiation point for any buyer with an existing FortiGate estate.
Use as a rough planning signal, always routing to a direct Fortinet quote for real numbers, and proactively raise the Security Fabric discount as a specific, quantifiable negotiation point for any buyer with an existing FortiGate estate.
Summary
Most credible differentiator | A single operating system and inspection engine running identically across physical firewall hardware and cloud-delivered SASE points of presence - a genuinely consistent architectural story, reinforced by a specific, quantified commercial incentive (the Security Fabric discount) for the exact customer base this consistency matters most to. | Tables 1, 3, 19 | High | This is the single sentence Netify's comparison engine could most confidently quote for Fortinet specifically.
This is the single sentence Netify's comparison engine could most confidently quote for Fortinet specifically.
Summary
Strength | A documented, quantified loyalty discount (20-25% preferred Security Fabric pricing) for existing FortiGate customers buying FortiSASE, confirmed independently across separate third-party pricing analyses | Buyers with an existing FortiGate estate get a real, checkable, specific commercial incentive rather than a vague 'loyalty discount may apply' claim | Best: existing FortiGate customers. Less relevant: greenfield buyers with no prior Fortinet investment | Medium-High (independently corroborated commercial claim, though not primary-sourced) | A specific, quantified, genuinely useful commercial data point for Netify to relay directly to buyers evaluating Fortinet against a standalone cost basis.
Buyers with an existing FortiGate estate get a real, checkable, specific commercial incentive rather than a vague 'loyalty discount may apply' claim
Summary
Where does it stand out? (mandatory) | Architectural consistency between physical and cloud-delivered inspection via a single operating system (FortiOS); a genuinely distinctive, purpose-built sovereign SASE product (FortiSASE Sovereign) for data-residency-sensitive buyers; a large, long-standing (since at least 2018) technology-integration ecosystem; and current, technically specific post-quantum cryptography investment as of the March 2026 FortiOS 8.0 release. | Tables 3, 12, 13, 19 | High | These are the claims Netify can make most confidently and specifically to buyers, each backed by named, dated, primary-sourced evidence.
These are the claims Netify can make most confidently and specifically to buyers, each backed by named, dated, primary-sourced evidence.
Summary
When would Netify recommend looking elsewhere? (mandatory) | When a buyer specifically requires FedRAMP authorization (not GovRAMP) and needs it confirmed before procurement can proceed; when a buyer needs confirmed BYOD/clientless remote-access capability; when a buyer has no existing FortiGate estate and would be evaluating FortiSASE purely as a standalone cloud-native product without the architectural-consistency or commercial-discount advantages that are central to Fortinet's pitch; or when a buyer's requirements would push them toward the Comprehensive tier and they have a low tolerance for the documented steep, non-linear cost jump to reach it. | Synthesis of Tables 5, 13, 16, 19 | Medium-High | Each trigger is tied to a specific, evidenced gap rather than a generic 'consider alternatives' hedge.
Each trigger is tied to a specific, evidenced gap rather than a generic 'consider alternatives' hedge.
Summary
Commercials | A documented, quantified loyalty discount - existing FortiGate customers reportedly receive 20-25% preferred 'Security Fabric' pricing on FortiSASE compared to a standalone FortiSASE quote, a specific and checkable competitive argument. | List pricing is not published, and even the tiered structure (Standard/Advanced/Comprehensive) shows a sharply non-linear cost curve in third-party analysis - the step from Advanced to Comprehensive is described as costing nearly 200% more than the step from Standard to Advanced, reflecting a shift from Fortinet's own point-of-presence infrastructure to public-cloud-delivered redundancy.
Summary
Where does it fall behind competitors? (mandatory) | FedRAMP status specifically (as distinct from the confirmed GovRAMP Moderate authorization) was described by Fortinet's own most recent public statement as a future intention rather than an achieved authorization; several general compliance certifications (SOC 2, PCI-DSS, formal HIPAA attestation) were not confirmed; no confirmed BYOD/clientless remote-access capability was found; and no confirmed DEM-equivalent digital-experience-monitoring product tightly integrated with FortiSASE was found. | Tables 3, 5, 10, 13 | Medium-High | Named specifically and evidenced, not a generic hedge - though several of these (general compliance certifications, DEM) may reflect research-pass limitations rather than confirmed product gaps, and should be treated as open questions to close directly rather than confident negative findings.
Named specifically and evidenced, not a generic hedge - though several of these (general compliance certifications, DEM) may reflect research-pass limitations rather than confirmed product gaps, and should be treated as open questions to close directly rather than confident negative findings.
Summary
Lean IT team | Good fit, particularly for existing FortiGate customers | The confirmed zero-touch registration mechanism, named migration service (ADS), and a specific positive named-customer quote about not noticing the security solution's presence all support a low-operational-burden story | Benefits from prior FortiGate familiarity, though the confirmed guided-migration service (ADS) is specifically designed to reduce this dependency for new customers too | Entry-tier real total cost of ownership should be modelled carefully given the documented gap between list price and actual spend after common add-ons | Table 9, 15, 16 findings | A genuinely credible fit operationally (named migration support, zero-touch mechanisms), tempered by the specific, well-documented commercial caution about total-cost-of-ownership creep that a lean team with less negotiating leverage should plan for explicitly.
Summary
Who is this genuinely best suited for? (mandatory) | Existing FortiGate customers wanting a consistent security policy and inspection model extending from on-premises firewalls into cloud-delivered SASE, who can also capture the documented Security Fabric pricing discount; service providers and government bodies needing a fully sovereign, self-operated private SASE cloud; and large, distributed-site organisations in hospitality and education specifically, given the credible, quantified case-study evidence for exactly these profiles. | Tables 1, 14, 15, 19 | High | Buyers matching this profile - especially existing FortiGate customers - can proceed with genuine confidence, backed by specific, checkable named-customer evidence and a quantified commercial incentive.
Buyers matching this profile - especially existing FortiGate customers - can proceed with genuine confidence, backed by specific, checkable named-customer evidence and a quantified commercial incentive.
Summary
Limitation | FedRAMP itself - as distinct from the confirmed GovRAMP Moderate authorization - was described by Fortinet's own most recent public statement as a future intention rather than an achieved authorization, and no FortiSASE-specific listing was found on the official FedRAMP Marketplace in this research pass | US federal buyers specifically requiring FedRAMP (not GovRAMP) cannot currently verify this from public sources and must confirm current status directly with Fortinet | Affects US federal government buyers most specifically; GovRAMP-sufficient state/local buyers are less affected | Table 13 findings | Medium-High (confident about the most recent primary source's own language, though status may have changed since) | A precise, specific, easy-to-miss distinction - exactly the kind of nuance a buyer could otherwise overlook by assuming GovRAMP and FedRAMP are interchangeable.
US federal buyers specifically requiring FedRAMP (not GovRAMP) cannot currently verify this from public sources and must confirm current status directly with Fortinet
Summary
SME | Conditional fit | Entry-tier (Standard) FortiSASE pricing is described by third-party analysis as accessible at list, though real total cost of ownership after common add-ons (FortiToken, FortiClient EMS, compute-region fees) is reported to land materially higher than the headline figure | Minimal internal skills needed for FortiGate-experienced teams; steeper for greenfield buyers with no prior Fortinet exposure | The Security Fabric discount is less valuable for SMEs with no existing FortiGate estate to qualify against | A genuinely nuanced finding: the headline entry price is accessible, but the well-documented gap between list price and real total cost of ownership is a specific, worth-flagging risk for smaller buyers with less negotiating leverage.
Summary
Deployment reality | Genuinely well-evidenced for existing FortiGate customers specifically, via a confirmed technical zero-touch mechanism and a named migration service; less differentiated for buyers with no existing Fortinet estate, where the architectural-consistency advantage that anchors most of this profile's strongest evidence doesn't apply in the same way. | Table 9, 17, 18 | Medium-High | Set expectations specifically based on whether the buyer has existing FortiGate investment - this is a more consequential distinction for Fortinet than a simple deployment-speed claim alone would suggest.
Set expectations specifically based on whether the buyer has existing FortiGate investment - this is a more consequential distinction for Fortinet than a simple deployment-speed claim alone would suggest.
Summary
Limitation | Several general compliance certifications commonly checked by regulated buyers (SOC 2, PCI-DSS, formal HIPAA attestation, DORA, UK-specific frameworks) were not confirmed for FortiSASE in this research pass | Regulated buyers outside the confirmed GovRAMP/ISO 27001 scope cannot currently verify Fortinet's compliance posture with the same confidence as for the certifications that were confirmed | Affects regulated-sector buyers most, especially payment-handling and healthcare-specific buyers | Table 13 findings | Medium (likely reflects a research-pass limitation given Fortinet's genuine scale, rather than confident evidence these certifications don't exist) | Netify should treat this as an open research question to close directly with Fortinet rather than either assuming parity with other vendors or asserting these certifications don't exist - Fortinet's scale makes the latter unlikely, but this profile cannot currently confirm the former.
Regulated buyers outside the confirmed GovRAMP/ISO 27001 scope cannot currently verify Fortinet's compliance posture with the same confidence as for the certifications that were confirmed
Summary
Mid-market | Good fit | The confirmed proof-of-concept-to-production upgrade path and named migration service (Advanced Deployment Services) both suit a mid-sized buyer wanting a structured, guided adoption | Benefits from, but doesn't strictly require, prior FortiGate experience | Standard/Advanced tier pricing likely applies; volume discounts confirmed to begin at 500 and 2,000 users per third-party analysis | A reasonably well-evidenced fit, with concrete volume-discount thresholds giving genuine, specific budget-planning value.
Summary
Security & Analytics | The single-pass, single-OS architecture is a genuinely long-proven inspection model (FortiOS has powered FortiGate firewalls for over two decades), and FortiOS 8.0 (March 2026) adds fabric-based AI agents and post-quantum cryptographic controls, including quantum-resilient authentication for management access paths. | Independent technical analysis notes that SSL/TLS decryption is hardware-offloaded on physical FortiGate appliances but software-based in FortiSASE's cloud virtual machines - a real architectural distinction worth understanding for performance-sensitive, high-TLS-volume deployments specifically.
Summary
Highly distributed branch estate | Strong fit, evidenced | The named global hospitality operator's 4,000+-location deployment, combined with the confirmed zero-touch FortiGate registration mechanism (serial number/token) and named migration service (ADS), together make a credible, specific case for this buyer profile | Zero-touch provisioning well-evidenced via a specific technical mechanism | Site-based/per-appliance licensing implications not fully itemised | Table 4, 6, 9, 14 findings | Genuinely one of the stronger, most specifically-evidenced suitability findings in this profile - the combination of named large-scale customer evidence and a concrete technical zero-touch mechanism is credible and specific.
Summary
Regulated organisation | Conditional fit, strongest for US state/local government specifically | GovRAMP Moderate confirmed and audited; FortiSASE Sovereign offers a genuinely strong, purpose-built data-residency answer; SOC 2, PCI-DSS, HIPAA (general attestation), DORA and UK frameworks all not confirmed in this pass, and FedRAMP itself was described by Fortinet's own most recent statement as a future intention rather than an achieved authorization | Buyer must independently verify sector-specific compliance status directly with Fortinet for anything outside confirmed GovRAMP Moderate scope | Not assessed | Table 13 findings | A genuinely precise, important distinction for this buyer profile: GovRAMP Moderate is real and audited, FortiSASE Sovereign is a genuine, distinctive data-residency answer, but broader general-compliance-certification evidence (SOC 2, PCI-DSS) and FedRAMP specifically are gaps worth closing directly before a high-stakes regulated-sector recommendation.
Summary
Procurement watch-out | The confirmed real-world total cost of ownership for FortiSASE is described by third-party analysis as landing materially above the headline list price once common add-ons (FortiToken, FortiClient EMS, compute-region fees, bandwidth) are included | Buyers risk under-budgeting if they scope only the headline per-user list price without accounting for commonly-required add-ons | Affects all buyer sizes, though smaller buyers with less negotiating leverage are likely most exposed | Table 16 findings | Medium | Netify should proactively flag this pattern to buyers during the shortlist conversation rather than let it surface as a budget surprise partway through procurement.
Buyers risk under-budgeting if they scope only the headline per-user list price without accounting for commonly-required add-ons
Summary
Overall Netify Assessment | FortiSASE's most credible, distinctive evidence all flows from a single architectural claim - one operating system, one inspection engine, running identically on physical hardware and in the cloud - reinforced by a genuinely quantified commercial incentive (the Security Fabric discount) for the exact customer base that architectural consistency matters most to. That's a real, well-evidenced strength for existing FortiGate customers specifically, and a less differentiated proposition for a buyer with no prior Fortinet investment evaluating FortiSASE purely on cloud-native merits. The compliance picture requires precision: GovRAMP Moderate is genuinely confirmed and audited, but FedRAMP itself was described by Fortinet's own most recent public statement as a future intention, and several other common certifications weren't confirmed in this research pass. This profile is solid enough to support initial shortlist guidance for existing-FortiGate-customer and sovereignty-focused buyers specifically, but the flagged compliance gaps and BYOD/clientless evidence gap should be closed out directly with Fortinet before use in a high-stakes procurement decision. | Whole profile | Medium-High overall | Recommend direct Fortinet engagement to close the flagged evidence gaps before this profile supports a high-stakes procurement decision.
Recommend direct Fortinet engagement to close the flagged evidence gaps before this profile supports a high-stakes procurement decision.
Summary
Global multinational | Conditional fit | The confirmed global hospitality operator's scale (4,000+ locations) implies real multinational capability, though a specific, named-country PoP coverage map wasn't found in this pass | Needs Netify/buyer to verify specific-country coverage directly, given the coverage-map gap in Table 7 | Custom Comprehensive-tier pricing, Security Fabric discount applicable | Table 7, 15 findings | Real capability evidenced via scale of named customers, though the underlying network coverage map itself is a genuine, specific gap worth closing directly before making confident global-coverage claims to a buyer.
Summary
MPLS to SD-WAN migration | Evidenced via confirmed multi-transport SLA monitoring covering MPLS alongside broadband and LTE/5G, implying gradual coexistence rather than a forced cutover | Existing MPLS circuits can coexist during transition per the multi-transport monitoring architecture | IT team, with Advanced Deployment Services available for guided migration | Fortinet Advanced Deployment Services | Not quantified with a specific timeline in sources reviewed | Coexistence-period complexity if not carefully sequenced | Named migration service (ADS) explicitly designed to minimise disruption | The multi-transport monitoring architecture supports gradual migration in principle, and a named migration-assistance service exists, though no single customer case study specifically walks through an MPLS-to-SD-WAN timeline in the sources reviewed.
Summary
Deployment & Ops | A structured, named onboarding path (Fortinet Advanced Deployment Services) for new customers migrating to FortiSASE, with guided planning, automated configuration and policy migration explicitly designed to minimise disruption. | FortiSASE China must be ordered separately through an authorised SASE partner rather than through the standard global ordering process, per Fortinet's own ordering guide - a specific, worth-flagging operational wrinkle for multinational buyers with China-based operations.
Summary
What implementation challenges should buyers expect? (mandatory) | Expect genuine ease of onboarding for teams with prior FortiGate experience, given the confirmed zero-touch registration mechanism and named migration service (Advanced Deployment Services); expect a materially steeper learning curve and less commercial advantage for greenfield buyers with no existing Fortinet estate. Expect the real total cost of ownership to land above the headline list price once common add-ons are factored in - budget for this explicitly rather than assuming the entry-tier list price is the full picture. For China-based operations specifically, expect a separate, partner-mediated ordering process. | Tables 7, 9, 16 | Medium-High | Each expectation is traceable to a specific, evidenced finding elsewhere in this profile.
Each expectation is traceable to a specific, evidenced finding elsewhere in this profile.
Summary
Compliance & Footprint | GovRAMP (formerly StateRAMP) authorization at the Moderate impact level is confirmed for FortiGuard AI-Powered Security Services and FortiCare Services specifically, following an independent third-party assessing organisation audit against a NIST SP 800-53 Rev. 4-based framework. | As of Fortinet's own most recent public statement on the topic, FedRAMP itself was described as a future intention rather than an achieved authorization, and no FortiSASE-specific listing was found on the official FedRAMP Marketplace in this research pass - a materially different assurance level from GovRAMP for buyers who specifically require FedRAMP.
Summary
Co-managed transition | Evidenced specifically via FortiSASE Sovereign's multi-tenancy design, which explicitly enables 'centralized management of multiple customers or business units on a single platform, with strict data isolation' | Not itemised in detail beyond the confirmed Sovereign multi-tenancy mechanics | Not itemised | FortiSASE Sovereign infrastructure | Not quantified | Not itemised | Not detailed | Real, evidenced specifically for the Sovereign product line's service-provider/multi-business-unit use case, though not evidenced via a single named case study walking through an actual co-managed transition.
Summary
Sector fit | Hospitality and education are both strongly evidenced with specific, large, named-scale customer figures; government/public sector is well-evidenced on the GovRAMP-Moderate compliance side specifically; healthcare has one credible but narrow (single-customer, compliance-specific) proof point; financial services, retail, manufacturing, professional services, transport/logistics and energy/utilities all lack confirmed, detailed case-study evidence in this research pass, though some are referenced without detail. | Table 14 | High for hospitality/education; Medium for government/healthcare; Low for other sectors | Do not extend the strong hospitality/education evidence into an assumption of equal strength in sectors like financial services or manufacturing, which currently have no detailed case-study evidence in this profile.
Do not extend the strong hospitality/education evidence into an assumption of equal strength in sectors like financial services or manufacturing, which currently have no detailed case-study evidence in this profile.
Summary
Firewall consolidation | Evidenced indirectly via the confirmed single-OS, single-inspection-engine architecture, which by design consolidates functions (SWG, CASB, FWaaS, ZTNA) that might otherwise sit on separate point products | Existing firewall rules/policies migrated into FortiManager's unified policy model | IT/security team | Fortinet Advanced Deployment Services | Not quantified with a specific timeline | Policy translation errors during cutover (not specifically addressed in sources reviewed) | Not detailed | The underlying architectural consolidation story is genuinely strong (same OS, same inspection engine), though a named customer case study specifically framed around firewall consolidation wasn't found in this pass.
Summary
VPN to ZTNA migration | Evidenced via the confirmed statement that 'Zero Trust is included with all FortiSASE deployments', implying this is a standard, not exceptional, part of onboarding rather than a distinct migration project | Existing VPN infrastructure retired or supplemented | IT team | Not itemised | Not quantified with a specific timeline | Not itemised | Not detailed | The confirmed universal inclusion of Zero Trust access with every FortiSASE deployment is a genuinely useful, specific piece of evidence, even without a named customer case study specifically about VPN retirement.
Summary
Biggest operational advantage | A confirmed, specific, technical zero-touch branch-registration mechanism (serial number or pre-shared token) combined with a named, structured migration-assistance service (Advanced Deployment Services), evidenced concretely by a named large-scale hospitality customer's 60% efficiency improvement. | Table 4, 9, 18 | High | Directly quotable with the specific named-customer figure for credibility.
Directly quotable with the specific named-customer figure for credibility.
Summary
Merger/acquisition integration | Not documented via a named M&A-specific scenario in sources reviewed | Not itemised | Not itemised | Not itemised | Not quantified | Not itemised | Not detailed | Evidence gap - no named customer scenario specifically describing M&A-driven integration was found in this pass.
Summary
Cloud-first organisation | Good fit, with a specific nuance | FortiOS running identically as physical or virtual instances gives genuine architectural consistency for cloud-first buyers wanting the same policy model everywhere | None significant identified | Hyperscaler-specific technical depth (named AWS/Azure/GCP integration architecture) is a genuine gap relative to the confirmed named-SaaS-provider optimisation evidence | Table 3, 4, 6 findings | Real, credible architectural consistency, though the specific hyperscaler-by-hyperscaler cloud-provider integration depth is thinner in this pass than the confirmed SaaS-provider (Microsoft 365, Salesforce, Zoom) optimisation evidence.
Summary
Strength | FortiSASE Sovereign is a genuinely distinctive, purpose-built, turnkey private-cloud SASE product for buyers who cannot use a shared multi-tenant platform, with confirmed multi-tenancy, data isolation and full architectural control | Buyers with strict data-residency or sovereignty requirements get a specific, named product built for exactly this need rather than a general assurance | Best: service providers, governments, and highly regulated large organisations. Less relevant: buyers with no data-sovereignty requirement beyond standard commercial cloud assurances | High | A genuine, well-evidenced differentiator for a specific, important buyer segment - worth highlighting proactively to any buyer with sovereignty/data-residency concerns.
Buyers with strict data-residency or sovereignty requirements get a specific, named product built for exactly this need rather than a general assurance
Summary
Questions Netify still cannot verify | Current FedRAMP status specifically (distinct from the confirmed GovRAMP Moderate authorization); SOC 2, PCI-DSS, formal HIPAA, DORA and UK-framework status; confirmed BYOD/clientless remote-access capability; a named-country network-coverage/PoP map; and whether a fully Fortinet-managed (as opposed to Advanced-Deployment-Services-assisted) SASE service exists. | Synthesis of Tables 5, 7, 8, 13 | N/A - explicitly unresolved | This list should drive the next follow-up (a direct Fortinet briefing or partner conversation) before this profile is considered fully closed out.
This list should drive the next follow-up (a direct Fortinet briefing or partner conversation) before this profile is considered fully closed out.
Summary
Support/service reality | Real, confirmed underlying capability (FortiGuard AI-Powered Security Services, FortiSOC, a specific 1,900+-expert support figure) but no single, clearly-named, contractually-specific support-tier SLA structure (comparable to a detailed published data sheet) was found for FortiSASE specifically in this research pass. | Table 8, 16 | Medium | Flag internally as a priority follow-up source to strengthen before this profile supports a support-SLA-sensitive procurement decision.
Flag internally as a priority follow-up source to strengthen before this profile supports a support-SLA-sensitive procurement decision.
Summary
Limitation | The confirmed FortiSASE pricing structure shows a sharply non-linear cost curve between tiers, with the jump from Advanced to Comprehensive described by independent third-party analysis as costing nearly 200% more than the jump from Standard to Advanced | Buyers who need Comprehensive-tier capabilities (global redundancy, advanced features) should budget for a materially steeper cost increase than a naive linear extrapolation from Standard/Advanced pricing would suggest | Affects buyers needing high-availability/global-redundancy capabilities most, since these concentrate in the Comprehensive tier specifically | Table 16 findings | Medium (single detailed third-party source, though internally specific and consistent) | A specific, quantified, genuinely actionable procurement risk - worth flagging proactively to any buyer whose requirements might push them toward the Comprehensive tier.
Buyers who need Comprehensive-tier capabilities (global redundancy, advanced features) should budget for a materially steeper cost increase than a naive linear extrapolation from Standard/Advanced pricing would suggest
Summary
AI reality | A real, current, dated investment (fabric-based AI agents and Secure AI Controls, both announced as part of FortiOS 8.0 in March 2026) sits alongside well-established, independently-audited AI/ML threat-detection capability (FortiGuard AI-Powered Security Services), though the newest agentic-AI-specific capabilities are less granularly detailed in terms of specific mechanisms than the confirmed, audited threat-detection product. | Table 11 | Medium-High | Represent the confirmed, audited AI capabilities (FortiGuard AI-Powered Security Services) with high confidence, while presenting the newer FortiOS 8.0 AI-agent capabilities as real but less granularly detailed as of this profile's research.
Represent the confirmed, audited AI capabilities (FortiGuard AI-Powered Security Services) with high confidence, while presenting the newer FortiOS 8.0 AI-agent capabilities as real but less granularly detailed as of this profile's research.
Summary
Global branch rollout | Zero-touch FortiGate registration (serial number/token) and Fortinet Advanced Deployment Services are architecturally real for this scenario, and a named global hospitality operator's 4,000+-location, 325,000+-employee deployment is directly relevant, reporting a 60% efficiency improvement for network and security teams specifically | Existing branch network/WAN infrastructure to integrate or replace | Not itemised at the full 4,000-location scale specifically | Fortinet Advanced Deployment Services | Not quantified beyond the confirmed 60% efficiency figure | Not itemised | Not detailed | Genuinely strong, specific, large-scale evidence for this exact scenario - the combination of a concrete efficiency figure (60%) and a very large, named customer scale (4,000+ locations) is credible and quotable.
Public evidence sources
35 records- 01Fortinet - Customer Success Stories blog index (large school district, airport operator, mining company, power grid operator references) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 02Fortinet - Fabric Connectors solutions page · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 03Fortinet - FortiSASE Ordering Guide (subscription tiers, licensing mechanics, Advanced Deployment Services) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 04Fortinet - FortiSASE Sovereign Data Sheet · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 05Fortinet - FortiSASE Sovereign product page · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 06Fortinet - Global Customers and Case Studies page (IHG Hotels & Resorts, Carolina Panthers, Red Bull references) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 07Fortinet - Open Ecosystem Partners / Fabric-Ready Technology Alliance Partner directory · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 08Fortinet - Secure SD-WAN Customer Success Stories eBook (10 case studies, including a global hospitality operator) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 09Fortinet - Security and Trust / Product Certifications page (ISO 27001, MEF 3.0 SD-WAN Certification, NetSecOPEN, NSS Labs) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 10Fortinet - Unified SASE Customer Success Stories eBook (large US school district, 375K+ students/staff) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 11Fortinet - press release: Fortinet Achieves GovRAMP Security Authorization · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 12Fortinet - press release: Fortinet Expands Fabric-Ready Partner Programme with Fabric Connectors (AWS, Azure, Oracle, Cisco ACI, ServiceNow named) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 13Fortinet - press release: Fortinet Introduces FortiOS 8.0 to Expand Secure Networking with Secure AI Controls, Fabric-based AI Agents, Flexible SASE, and Simplified SD-WAN · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 14Fortinet Blog - Expansive Open Fabric Ecosystem Enables Seamless Integrations with Fortinet Security Fabric · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 15Fortinet Blog - Fortinet Fabric Connectors: Enabling Deep Fabric Integration With Third Party Solutions · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 16Fortinet Document Library - ISO 27001:2022 Compliance Security Rating Report (FortiAnalyzer) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 17GlobeNewswire (Fortinet's own wire-distributed release) - Fortinet Achieves GovRAMP Security Authorization · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 2
- 18GlobeNewswire (Fortinet's own wire-distributed release) - Fortinet Introduces FortiOS 8.0 · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 2
- 19GlobeNewswire (Fortinet's own wire-distributed release) - Fortinet Reports Strong Fourth Quarter and Full Year 2025 Financial Results · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 2
- 20Okta - Integrate FortiSASE with Okta (Okta's own integration catalogue page, independent named company) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 2
- 21Stock Titan (wire-service reprint) - Fortinet's Rapidly Growing Open Fabric Ecosystem Helps Customers Achieve Integrated Security (400+ integrations) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 2
- 22AVFirewalls.com (Fortinet reseller) - Case Study: The Guidance Centre · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 23AVFirewalls.com (Fortinet reseller) - FortiSASE Customer Success Stories page · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 24Amtivo - Supporting FedRAMP Phase 3 With ISO 27001 Certification (independent compliance-consulting commentary, general FedRAMP context) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 25FeaturedCustomers - Fortinet Case Studies, Success Stories & Customer Stories (third-party review aggregator) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 26FedRAMP Marketplace (official US government registry - checked for a FortiSASE listing, none found in this pass) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 27Futurum Group - Fortinet's FortiOS 8.0 Pushes Secure Networking Toward AI Governance (independent analyst commentary) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 28Ingram Micro (Fortinet distributor) - FortiSASE Customer Success Stories eBook (hosted copy of Fortinet's own content) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 29Jimber.io - FortiSASE Pricing 2026: What 200 Users Actually Costs (third-party, drawing partly on UK G-Cloud framework published pricing) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 30The Network DNA - Introduction to Fortinet Secure SD-WAN Architecture (third-party technical blog) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 31Tracxn - Fortinet 2026 Company Profile · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 32Umbrex - Fortinet Strategy and Business Model (third-party) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 33Vendor Benchmark - Fortinet Pricing 2026: What Enterprises Actually Pay (third-party, drawing on 180+ benchmarked contracts) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 34ZoomInfo - Fortinet company overview (third-party) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 35sase.cloud - Fortinet FortiSASE Review 2026: SD-WAN, Sovereign SASE, Scores (independent vendor comparison site) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
Profile contract provider-public/1.0.0. Machine-readable record: JSON.