Overview
Open Systems founded in 1990 in Basel, Switzerland, more than three decades before the SASE category itself existed, originally as a managed security service provider before evolving its platform into what it now markets as native, managed SASE Experience. The company’s ownership history took a distinctive turn in 2023: after a period under the European private-equity firm EQT, Open Systems was acquired by Swiss Post - Switzerland’s state-backed national postal and logistics institution - a materially different kind of owner from the venture-capital or private-equity structures behind most other vendors in this category. Dennis Monner was appointed CEO in late 2023, following earlier leadership under Daniel Neuhaus. The platform’s defining characteristic, repeated consistently across every source reviewed in our research, is its fully managed operating model delivered through a specifically-named service organisation, Mission Control - staffed exclusively by Level-3 engineers who complete more than 400 hours of additional internal training, providing 24x7 follow-the-sun support with a specific, quantified 8-minute ticket-escalation commitment. This is a well-evidenced vendor by the standards of this category: five real, named customer case studies were found (KEMET, Mammut, SOS Children’s Villages, Mikron, and Altana), several with specific, quantified outcomes - KEMET’s engagement is described as cutting costs by 50%, and Mammut’s WAN replacement was completed in under two months. Compliance evidence includes a confirmed, primary-sourced ISO 27001 certification, and Gartner Peer Insights data shows strong ratings - 4.8 out of 5.0 based on 70 reviews in the Security Service Edge market as of August 2026 reinforced by specific, verbatim customer quotes. A specific, worth-noting transparency point: an independent competitor comparison, citing Open Systems’ own published subprocessor statement, describes several core platform components as delivered through named third-party partners rather than fully in-house - ZTNA through Cyolo Security (Israel) and the SWG antivirus engine through Avira (Germany) - a checkable architectural detail rather than a fully native, single-vendor security stack in every respect.
Direct comparison
Put Open Systems AG, operating this platform as Open Systems SASE Experience (formerly marketed around Secure SD-WAN as a managed security service provider) beside any provider.
Open the Netify comparison engine with both providers already selected. Every result is calculated from the public 40-capability evidence matrix.
No sign-in required. The shortlist remains shareable. Publishing and supplier access stay separate.
Find which providers match your exact needs
Move from a two-provider comparison into the live Netify RFP Builder and evaluate the wider market against your project.
Open the RFP BuilderAgent-accessible research
Ask the Open Systems AG, operating this platform as Open Systems SASE Experience (formerly marketed around Secure SD-WAN as a managed security service provider) research record
Answers are calculated from the published record below. Missing evidence remains unconfirmed and every result identifies its source revision.
Record summary
- Current products
- 7
- Capabilities
- 67
- Coverage records
- 13
- Service models
- 34
- Compliance records
- 13
- Integration records
- 20
- Sector records
- 8
- Evaluation records
- 49
- Public sources
- 21
Products and delivery
7 records| Product | Category | Relationship | Delivery model | Target buyer |
|---|---|---|---|---|
| MDR+ (Managed Detection and Response) | Managed security service | Native | Fully managed | Buyers wanting 24/7 threat hunting and incident response |
| Managed SD-WAN / Secure SD-WAN | SD-WAN | Native | Fully managed | Buyers wanting to replace MPLS with software-defined connectivity |
| Managed, Universal SSE | Security Service Edge | Partner | Cloud-native, fully managed | Buyers wanting Zero Trust without operational complexity |
| Mission Control | Managed operations organisation | Native | 24x7x365 follow-the-sun, Level-3 engineers only | All buyers - the platform's core service-delivery organisation |
| OT Firewall | Operational technology security | Native | Not fully detailed | Buyers with critical infrastructure/industrial environments |
| Open Systems SASE Experience | Converged, managed SASE platform | Native | Fully managed or co-managed, cloud-native | All buyers |
| Zero Trust Service | ZTNA (standalone) | Partner | Cloud-native, fully managed | Buyers wanting to replace legacy VPN specifically |
Capability evidence
67 recordsAi Automation14 records
| Capability | Support | Confidence | Freshness | Qualification |
|---|---|---|---|---|
| AI assistant/copilot | Requires Confirmation | Unresolved | Current | Open Systems' confirmed AI investment is framed generally around Mission Control's 'intelligent systems' rather than a single, separately-branded copilot product |
| AI data protection controls | Requires Confirmation | Unresolved | Current | Not confirmed |
| Anomaly detection | Requires Confirmation | Unresolved | Current | Underlying detection methodology and specific technical mechanisms not itemised in granular detail |
| Automated policy recommendation | Unknown | Unresolved | Current | Not confirmed |
| Automated remediation | Requires Confirmation | Unresolved | Current | Not confirmed |
| Capacity/path optimisation | Requires Confirmation | Unresolved | Current | Granular technical mechanics beyond the confirmed dynamic-path-selection description not itemised |
| Configuration generation | Unknown | Unresolved | Current | Not confirmed |
| Digital experience diagnostics | Requires Confirmation | Unresolved | Current | Technical depth beyond the named capability itself not itemised in full |
| Generative AI application controls | Requires Confirmation | Unresolved | Current | Not confirmed |
| Natural-language querying | Unknown | Unresolved | Current | Not confirmed |
| Report summarisation | Unknown | Unresolved | Current | Not confirmed |
| Root-cause analysis | Requires Confirmation | Unresolved | Current | Not itemised as a single, distinctly-named root-cause-analysis product |
| Threat detection/classification | Requires Confirmation | Unresolved | Current | Same as above |
| User/entity behaviour analytics | Requires Confirmation | Unresolved | Current | Not confirmed |
Architecture15 records
| Capability | Support | Confidence | Freshness | Qualification |
|---|---|---|---|---|
| 5G/LTE support | Requires Confirmation | Low | Current | Not independently confirmed as a distinct, named capability in sources reviewed |
| Application identification | Requires Confirmation | Medium High | Current | Native, implied via the confirmed 'Application Visibility' and 'Application Control' Mission Control capabilities, which require application-level identification to function |
| Branch LAN/WLAN integration | Requires Confirmation | Low | Current | Not independently confirmed as a distinct, named capability in sources reviewed - Open Systems does not appear to compete in campus LAN/Wi-Fi hardware based on the sources reviewed |
| Brownfield migration support | Supported | High | Current | Native, well-evidenced via a real, named, quantified customer migration example - Mammut 'replaced its aging WAN' with Open Systems SASE, with bandwidth management taken over 'in less than two months' |
| Dynamic path selection | Requires Confirmation | High | Current | Native, confirmed directly by name - 'Application Control (QoS, Dynamic Path selection)' |
| Edge form factors | Requires Confirmation | Low Medium | Current | Not independently confirmed with specific named hardware model detail in sources reviewed - the platform's confirmed architecture centres on cloud-native, fully managed delivery via Mission Control rather than a named, purpose-built branch hardware appliance line |
| Forward error correction / packet duplication | Requires Confirmation | Low | Current | Not confirmed as a distinct named capability in sources reviewed |
| High availability | Requires Confirmation | Medium High | Current | Native, implied via the confirmed 24x7x365 Mission Control monitoring architecture and the platform's genuinely long, multi-decade operating track record across approximately 10,000 deployments |
| LEO satellite support | Unknown | Low | Current | Unknown - not found in sources reviewed |
| Local internet breakout | Requires Confirmation | High | Current | Native, confirmed directly via real, named customer-deployment detail - 'low-cost and secure internet breakouts' specifically described in the Mammut case study |
| QoS and traffic engineering | Requires Confirmation | High | Current | Native, confirmed directly by name - 'Application Control (QoS, Dynamic Path selection)' |
| Segmentation / VRF capability | Requires Confirmation | Low | Current | Not independently confirmed with specific technical detail in sources reviewed |
| Supported WAN underlays | Requires Confirmation | Medium High | Current | Native, implied via the confirmed 'low-cost and secure internet breakouts' and 'bandwidth management' capabilities described directly in a real, named customer case study (Mammut) |
| Virtual/cloud edge support | Requires Confirmation | High | Current | Native, confirmed via the platform's fully cloud-native, single-pass architecture |
| Zero-touch provisioning | Requires Confirmation | Medium | Current | Not independently confirmed with a specific, named zero-touch mechanism in sources reviewed, though the confirmed fully-managed Mission Control delivery model implies Open-Systems-led deployment rather than customer-driven manual configuration by default |
Core Capabilities15 records
| Capability | Support | Confidence | Freshness | Qualification |
|---|---|---|---|---|
| Application-aware routing | Requires Confirmation | Medium High | Current | None identified |
| CASB - API | Requires Confirmation | Low | Current | Not confirmed as distinct from inline CASB |
| CASB - inline | Requires Confirmation | Medium High | Current | Specific inline-versus-API-mode technical detail not itemised |
| Cloud firewall / cloud network security | Requires Confirmation | High | Current | None identified |
| DNS security | Requires Confirmation | Low | Current | Not confirmed |
| Data loss prevention | Requires Confirmation | Low | Current | Not confirmed |
| Digital experience monitoring | Requires Confirmation | Medium High | Current | None identified |
| Firewall as a Service | Requires Confirmation | High | Current | None identified |
| Multi-cloud networking | Requires Confirmation | Medium High | Current | Specific, named hyperscaler cloud on-ramp partnerships weren't itemised by name |
| SD-WAN | Supported | High | Current | None identified |
| SaaS security posture | Requires Confirmation | Low | Current | Not confirmed |
| Secure web gateway | Requires Confirmation | Medium High | Current | Antivirus scanning engine specifically confirmed delivered via Avira (Germany), per an independent source citing Open Systems' own subprocessor statement |
| Threat intelligence | Requires Confirmation | High | Current | None identified |
| WAN optimisation | Requires Confirmation | Medium High | Current | None identified |
| ZTNA | Requires Confirmation | Medium High | Current | ZTNA engine specifically confirmed delivered via Cyolo Security (Israel), per an independent source citing Open Systems' own subprocessor statement |
Remote Access9 records
| Capability | Support | Confidence | Freshness | Qualification |
|---|---|---|---|---|
| Clientless access | Requires Confirmation | Unresolved | Current | Not confirmed |
| Contractors/third parties | Requires Confirmation | Unresolved | Current | Not confirmed by a named case study specifically about contractor access |
| Managed laptops | Requires Confirmation | Unresolved | Current | None identified |
| Mobile devices | Requires Confirmation | Unresolved | Current | Not confirmed |
| Privileged access | Unknown | Unresolved | Current | Not confirmed |
| Remote browser isolation | Requires Confirmation | Unresolved | Current | Unknown |
| Remote browser isolation | Requires Confirmation | Low | Current | Not confirmed |
| Unmanaged/BYOD devices | Requires Confirmation | Unresolved | Current | Not confirmed |
| VDI environments | Unknown | Unresolved | Current | Not confirmed |
Reporting Analytics14 records
| Capability | Support | Confidence | Freshness | Qualification |
|---|---|---|---|---|
| Application performance | Requires Confirmation | Unresolved | Current | Not confirmed |
| Compliance reporting | Requires Confirmation | Unresolved | Current | Not confirmed |
| Custom reports | Unknown | Unresolved | Current | Not confirmed |
| DLP events | Requires Confirmation | Unresolved | Current | Not confirmed |
| Executive dashboard | Requires Confirmation | Unresolved | Current | Not confirmed |
| Network health | Requires Confirmation | Unresolved | Current | Not confirmed |
| Raw log access | Requires Confirmation | Unresolved | Current | Not confirmed |
| Remote-user experience | Requires Confirmation | Unresolved | Current | Not confirmed |
| SLA reporting | Requires Confirmation | Unresolved | Current | Not confirmed |
| Scheduled reports | Unknown | Unresolved | Current | Not confirmed |
| Security events | Requires Confirmation | Unresolved | Current | Not confirmed |
| Site and circuit performance | Requires Confirmation | Unresolved | Current | Not confirmed |
| Threat reporting | Requires Confirmation | Unresolved | Current | Not confirmed |
| User experience | Requires Confirmation | Unresolved | Current | Not confirmed |
Geographic coverage
13 records| Geography | Delivery type | Relationship | Confidence | Qualification |
|---|---|---|---|---|
| Africa coverage | Unknown - Not Itemised In Sources Reviewed | Unknown | Low | Unknown - not itemised in sources reviewed | Unknown | Not specified | No named data centres found | Not found in a Tier 1-2 source in this pass | Low | Evidence gap. |
| Asia-Pacific coverage | Confirmed At A General Level Via The Platform'S Overall 180+-Country Deployment Claim, Reinforced By A Real, Named Customer Example (Altana) Connecting 60+ Global Locations, Though Specific Asia-Pacific Country-Level Detail Wasn'T Independently Itemised | Owned | Medium | Confirmed at a general level via the platform's overall 180+-country deployment claim, reinforced by a real, named customer example (Altana) connecting 60+ global locations, though specific Asia-Pacific country-level detail wasn't independently itemised | Direct | 180+ countries claimed generally; specific Asia-Pacific detail not itemised | No formal regional PoP map found beyond the general global-coverage claim | Medium | A real, general, primary-sourced global-reach claim reinforced by named multi-site customer evidence; country-level Asia-Pacific specificity wasn't independently confirmed. |
| Carrier interconnects | Unknown - Not Itemised In Sources Reviewed | Unknown | Low | Unknown - not itemised in sources reviewed | Unknown | Unknown | No specific carrier/exchange detail found | Not found in a Tier 1-2 source in this pass | Low | Evidence gap. |
| China coverage | Unknown - No China-Specific Data-Centre Or Licensed-PoP Detail Found In Sources Reviewed | Unknown | Low | Unknown - no China-specific data-centre or licensed-PoP detail found in sources reviewed | Unknown | Not specified | No named China presence found | Not found in a Tier 1-2 source in this pass | Low | Evidence gap. |
| Data residency choices | Not Independently Confirmed As A Distinct, Named Data-Residency Architecture In Sources Reviewed | Unknown | Low | Not independently confirmed as a distinct, named data-residency architecture in sources reviewed | Unknown | Unknown | No dedicated data-sovereignty architecture page found | Not found in a Tier 1-2 source in this pass at sufficient detail | Low | Evidence gap - worth a direct, specific follow-up, particularly relevant given the company's Swiss/EU orientation and the confirmed named subprocessor disclosure practise (Table 3). |
| Europe coverage | Strong Fit, Genuinely Well-Evidenced - The Company'S Own Swiss Origin And Headquarters, ISO 27001 Certification, And Confirmed Named European Customers (Mammut, A Swiss/International Apparel Brand) Together Give This Region The Strongest, Most Specific Evidence In This Table | Owned | High | Strong fit, genuinely well-evidenced - the company's own Swiss origin and headquarters, ISO 27001 certification, and confirmed named European customers (Mammut, a Swiss/international apparel brand) together give this region the strongest, most specific evidence in this table | Direct | Switzerland (headquarters), broader Europe implied via named customer base | Full regional PoP breakdown not itemised beyond the confirmed headquarters and customer evidence | High | Genuinely the strongest-evidenced region in this entire table - a real, named European headquarters, a confirmed European compliance certification, and real, named European customer evidence together. |
| Latin America coverage | Unknown - No Specific Evidence Found In This Pass | Unknown | Low | Unknown - no specific evidence found in this pass | Unknown | Not specified | No named data centres or customer evidence found for this region specifically | Not found in a Tier 1-2 source in this pass | Low | Evidence gap. |
| Middle East coverage | Unknown - Not Itemised In Sources Reviewed | Unknown | Low | Unknown - not itemised in sources reviewed | Unknown | Not specified | No named data centres found | Not found in a Tier 1-2 source in this pass | Low | Evidence gap. |
| Private backbone | Native, Confirmed Directly - 'Edge-To-Edge Software Defined Network Connectivity With A Global Backbone' | Owned | Medium High | Native, confirmed directly - 'Edge-to-edge software defined network connectivity with a global backbone' | Direct (owned) | Global | Specific, itemised infrastructure detail (owned vs. hyperscaler-hosted) not itemised | Medium-High | A specific, direct, primary-sourced confirmation of a global backbone; granular infrastructure-ownership detail (fully owned versus hyperscaler-hosted) wasn't independently itemised. |
| Public cloud on-ramps | Not Independently Confirmed With Specific Named Hyperscaler Detail In Sources Reviewed | Unknown | Low Medium | Not independently confirmed with specific named hyperscaler detail in sources reviewed | Unknown | Unknown | Not detailed by named hyperscaler | Not found at this specificity in a Tier 1-2 source in this pass | Low-Medium | See Table 3, 6 for the related finding. |
| SD-WAN gateways / cloud gateways | Delivered Via The Same Confirmed Global-Backbone Infrastructure Described Above | Owned | Medium | Delivered via the same confirmed global-backbone infrastructure described above | Direct | Same as above | None identified beyond the general PoP-count gap above | 22 Jul 2026 | Medium | Consistent with the confirmed unified, global-backbone architecture. |
| Security PoPs / service edges | Not Confirmed With A Specific, Quantified PoP-Count Figure In Sources Reviewed, Beyond The Confirmed 'Global Backbone' Framing And The Confirmed Approximately-10,000-Deployment, 180+-Country Scale | Owned | Medium | Not confirmed with a specific, quantified PoP-count figure in sources reviewed, beyond the confirmed 'global backbone' framing and the confirmed approximately-10,000-deployment, 180+-country scale | Direct | 180+ countries, per multiple, independently-corroborated sources | No specific, itemised PoP count found | Medium | A real, specific, quantified deployment-scale figure (10,000 deployments, 180+ countries) exists, even without a distinct, named PoP-count figure specifically. |
| Sovereign/regional service options | Not Confirmed As A Distinct, Named FedRAMP Or Equivalent US Sovereign-Cloud Authorization In Sources Reviewed; The Company'S Confirmed EU/Swiss Orientation And State-Backed Ownership (Swiss Post) May Be Independently Relevant To European Data-Sovereignty-Focused Buyers, Though This Wasn'T Itemised As A Formal, Named Sovereign-Service Programme | Unknown | Low Medium | Not confirmed as a distinct, named FedRAMP or equivalent US sovereign-cloud authorization in sources reviewed; the company's confirmed EU/Swiss orientation and state-backed ownership (Swiss Post) may be independently relevant to European data-sovereignty-focused buyers, though this wasn't itemised as a formal, named sovereign-service programme | Unknown | Not specified | No confirmed FedRAMP or equivalent US authorization found; no formal, named European sovereign-service programme confirmed either | Not found in a Tier 1-2 source in this pass at sufficient specificity | Low-Medium | A genuine, specific, worth-flagging gap for US federal buyers specifically - see Table 13 for the related compliance finding - though the company's Swiss/EU orientation may itself be a relevant, informal factor for European data-sovereignty-focused buyers worth confirming directly. |
Service models
34 recordsOther
UnknownUnknown - not found in sources reviewed | Presumably Mission Control-managed or co-managed customer portal | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in public sources reviewed | Evidence gap.
Other
SupportedNative, and genuinely well-evidenced via a specifically-named service with a specific, named, credible SIEM integration | MDR+ (Managed Detection and Response) | 24x7x365 | Global | Included, or available as an enhanced managed-service tier | N/A | A specific, named, credible managed-service product with a specific, named SIEM integration (Microsoft Sentinel) - genuinely one of the stronger, more concretely-evidenced findings for this row found in this profile.
Other
SupportedYes, and genuinely the platform's default, most extensively and consistently evidenced delivery model throughout this entire profile | Full Open Systems Mission Control managed service | N/A | Mission Control (fully managed) | Buyers wanting to minimise IT operational burden entirely - the platform's own core, stated identity | Very low for the customer | N/A | Genuinely the single most consistently, extensively evidenced characteristic of this vendor across every table in this profile - fully managed delivery via Mission Control is not a product feature but the company's entire identity and value proposition.
Other
Requires ConfirmationNot applicable in the traditional sense given the confirmed cloud-native, fully-managed architecture; branch connectivity is delivered and managed via Mission Control rather than a named, standalone branch appliance product line | Not itemised with specific hardware detail | Branch → global backbone | Mission Control | Distributed branch estates | Very low, given the confirmed fully-managed model | Real, confirmed customer evidence at multi-site scale (Table 4, 18) | Real, confirmed branch-connectivity capability, evidenced via multiple named customers with distributed, multi-site operations; a distinct hardware appliance product line specifically wasn't independently confirmed.
Other
Requires ConfirmationNative, implied via the confirmed cloud-native, global-backbone architecture | Open Systems SASE Experience | Via the global backbone | Mission Control | Cloud-first organisations | Low | Not itemised for specific named hyperscalers | Confirmed at the architectural level; named hyperscaler-specific integration detail is a genuine, specific gap worth closing directly.
Other
UnknownFully managed, with real, named, quantified customer evidence at genuine multi-site scale - Altana 'connected 60+ locations worldwide and securely integrated new acquisitions' | Mission Control (managed) | Very low, given the confirmed fully-managed model | Not itemised further | Genuinely well-evidenced as low-effort via a specific, named, quantified customer example at real scale | None significant identified | A specific, real, named, quantified (60+ locations) customer example - genuinely concrete evidence of branch-onboarding capability at real, multi-site scale.
Other
SupportedNative, and genuinely one of this platform's clearest, best-evidenced identity traits - the Mission Control Operations Centre is explicitly named, described, and repeatedly evidenced across essentially every source reviewed in this research pass | 24x7x365, confirmed directly as 'follow the sun' | Multiple global locations, confirmed directly | Included - this is the platform's core, default delivery model, not a premium add-on | Customer configures high-level policy; day-to-day operations are Mission-Control-managed by default | Confirmed, specific: 'Customer tickets are escalated to a Mission Control engineer within 8 minute[s]' | Genuinely the single strongest, most specifically-evidenced NOC finding across this entire profile series - a real, named, quantified (8-minute) escalation commitment is concrete, checkable evidence rather than a vague 'responsive support' claim.
Other
Requires ConfirmationYes, implied via the confirmed combination of cloud-native SASE delivery with real, named customer examples spanning on-premises, data-centre, and cloud environments together - the Mammut case study specifically confirms protection 'on-premises, at data centres, or in the cloud' | Open Systems SASE Experience, managed via Mission Control across all environments | Mixed | Mission Control (unified across all environments) | Most real-world enterprise estates with mixed on-premises/cloud infrastructure | Very low for the customer, given the confirmed fully-managed model | Confirmed directly via named customer evidence (Mammut) | A genuine, confirmed architectural strength - real, named, primary-sourced customer evidence directly confirms unified protection spanning on-premises, data-centre, and cloud environments together under one managed service.
Other
SupportedYes | Client-based, per confirmed ZTNA architecture | Client → cloud platform | Mission Control | Managed-device remote/hybrid workforce | Low | N/A | Confirmed directly, though specific client-technology detail wasn't independently itemised (Table 5).
Other
Requires ConfirmationNot confirmed as a distinct, separately-priced Professional Services product in sources reviewed, though the confirmed, extensive Mission Control managed-service model implies real implementation support is core to, rather than separate from, the platform's default delivery | N/A | N/A | Included within the core managed-service model, per the confirmed architecture | N/A | N/A | Consistent with the confirmed, extensively-evidenced fully-managed delivery model found throughout this profile | A genuine, structural finding rather than a gap - this platform's entire value proposition centres on included, managed implementation and ongoing operations rather than a separately-priced Professional Services line item.
Other
SupportedNative, and genuinely one of this platform's most specifically and repeatedly evidenced capabilities - real, named-verbatim Gartner Peer Insights customer reviews directly praise the operational simplicity: 'streamlined operation by 24*7 mission control team that simplifies global network management and reduces complexity' | Mission Control | Very low, given the confirmed fully-managed troubleshooting model | Confirmed, AI and machine-learning-assisted proactive/reactive systems, per the company's own materials | Genuinely well-evidenced as low-effort via multiple independent, real, verbatim customer accounts | None significant identified | Genuinely one of the strongest, most specifically-evidenced findings in this entire profile - real, verbatim, independently-hosted customer review language directly confirms reduced operational complexity, reinforced by the company's own confirmed AI/ML-assisted proactive monitoring claim.
Other
Requires ConfirmationNative, implied via the confirmed 'Mission Control Support with unlimited changes and incidents' framing | Mission Control | Very low, given the confirmed unlimited-changes model | Confirmed, unlimited changes included | Genuinely well-evidenced as low-effort via a specific, direct, primary-adjacent claim | None significant identified | A specific, direct confirmation of unlimited included changes - genuinely concrete, favourable evidence, though sourced from an older (2020) independent profile.
Other
Requires ConfirmationNative, via the same confirmed centralised Mission Control architecture | N/A | N/A | Included | Customer or Mission-Control-managed, per the confirmed co-managed option | N/A | Same evidence and finding as Configuration management above.
Other
Requires ConfirmationNative, confirmed directly and repeatedly across multiple independent sources | 24x7x365, follow-the-sun | Global | Included | N/A | Confirmed, specific 8-minute escalation commitment | One of the most specifically, consistently, and repeatedly confirmed capabilities found across this entire profile - genuinely concrete, credible evidence.
Other
UnknownFully managed onboarding via Mission Control, with real, named, quantified customer evidence - Mammut's bandwidth management was taken over 'in less than two months' | Mission Control (managed) | Very low, given the confirmed fully-managed model | Not itemised further | Genuinely well-evidenced via a specific, named, quantified customer example | None significant identified | A specific, real, named, quantified deployment-timeline confirmation - genuinely concrete evidence rather than a generic 'easy setup' claim.
Other
Requires ConfirmationNative, confirmed via the specifically-named MDR+ service, described directly as providing '24/7 monitoring, threat detection, and incident response' | 24x7x365 | Global | Included, or available as an enhanced managed service (MDR+) depending on tier | N/A | Not itemised with a specific numeric SLA beyond the general confirmed 8-minute escalation commitment | A specific, named, primary-adjacent confirmation directly naming incident response as a core MDR+ function - genuinely concrete evidence.
Other
Requires ConfirmationNot applicable in the same sense as a vendor with a named branch hardware line, given the platform's confirmed cloud-native, fully-managed architecture (Table 4, 6) | N/A | N/A | N/A | N/A | N/A | N/A | Consistent with the confirmed, primarily cloud-native, software-centric architecture described throughout this profile.
Other
Requires ConfirmationNative, implied via the confirmed 'Mission Control Support with unlimited changes and incidents' framing | 24x7x365 | Global | Included | N/A | N/A | A specific, direct, primary-adjacent confirmation of unlimited included changes - genuinely concrete, favourable commercial/operational detail, though sourced from an older (2020) independent profile.
Other
Requires ConfirmationNative, implied via the confirmed co-managed option, which by design requires some form of delegated administrative access between Mission Control and customer IT staff | Mission Control / co-managed customer access | Not fully detailed at a granular RBAC level | Not confirmed | Not itemised | Not itemised | Reasonable inference from the confirmed co-managed option; granular delegated-administration mechanics weren't independently itemised.
Other
Requires ConfirmationNative, confirmed directly as part of the same Mission Control organisation - described as encompassing both NOC and SOC functions together, reinforced by the confirmed, named MDR+ managed detection and response service | 24x7x365, follow-the-sun | Multiple global locations | Included, or available as an enhanced managed service (MDR+) depending on tier | Customer configures high-level policy; SOC operations are Mission-Control-managed | Same confirmed 8-minute escalation commitment applies | Genuinely well-evidenced via the same strong, primary-sourced Mission Control confirmation, reinforced by the specifically-named MDR+ service and its confirmed Microsoft Sentinel integration.
Other
Requires ConfirmationCloud-delivered updates for the core platform are managed centrally via Mission Control, given the confirmed cloud-native, fully-managed architecture | Mission Control | Very low, given the confirmed fully-managed model | Automatic, given the managed-service delivery model | Very low | None significant identified | Reasonable inference from the confirmed cloud-native, fully-managed architecture.
Other
Requires ConfirmationNot independently confirmed as a distinct capability in sources reviewed | Unknown | Unknown | Unknown | Unknown | Not confirmed | N/A | See Table 5 - a genuine, specific evidence gap.
Other
Requires ConfirmationNative, and genuinely a core, confirmed architectural option - the confirmed co-managed model allows customers to directly participate alongside Mission Control's default, fully-managed operations | Mission Control (co-managed mode) | Low for the customer, with real flexibility in choosing the desired level of involvement | Confirmed, real alternative to the fully-managed default | Low, given the confirmed managed-service default with genuine co-managed flexibility | None significant identified | A specific, confirmed, real architectural choice - genuinely credible evidence that this platform accommodates a spectrum of customer involvement rather than being strictly all-or-nothing.
Other
Requires ConfirmationNative, confirmed directly - 'ISP outage notifications and support with persistent ISP issues' is named specifically as a Mission Control capability | 24x7x365 | Global | Included | Customer procures the last-mile link; Mission Control manages and troubleshoots it | N/A | A specific, named capability directly confirming proactive ISP-issue management - genuinely concrete evidence, though sourced from an older (2020) independent profile.
Other
Requires ConfirmationNot independently confirmed as a distinct, named MSP/multi-tenant capability in sources reviewed, though the company's own operating model as a managed service provider serving thousands of distinct customer deployments implies some form of multi-tenant operational capability exists in practise | Not confirmed by name | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found as a distinctly-named capability in a Tier 1-2 source in this pass | Reasonable inference from the company's confirmed scale (approximately 10,000 deployments) and MSP-style operating model; a distinctly-named, customer-facing multi-tenant product feature wasn't independently itemised.
Other
Requires ConfirmationManaged via Mission Control by default, with a confirmed co-managed option for customers wanting direct involvement | Mission Control, or customer-accessible tools under the co-managed option | Very low under the default managed model; benefits from technical familiarity under the co-managed option | Not itemised further | Positioned as simplified via the confirmed fully-managed default architecture | None significant identified | A genuine, confirmed strength - the platform's default, fully-managed model minimises customer-side policy-creation effort, with a real, confirmed alternative for customers wanting more control.
Other
Requires ConfirmationYes, and genuinely a confirmed, named architectural option - 'If an organization has the time, resources, and inclination to get involved, a co-managed option is available' | Open Systems SASE Experience (co-managed mode) | N/A | Shared between Mission Control and customer IT staff | Buyers wanting some direct operational involvement alongside managed delivery | Low-Moderate, depending on the customer's chosen level of involvement | N/A | A specific, direct, independently-sourced confirmation of genuine co-managed flexibility - real, credible evidence that the platform isn't strictly all-or-nothing on the managed-versus-self-service spectrum.
Other
Requires ConfirmationNative, implied via the confirmed 'Service Experience Promise' - described directly as 'backing up our experience with an explicit promise that is measurable' across defined measurement areas, reinforced by the company's own confirmed practise of publishing independent Gartner Peer Insights customer review counts directly on its own site | N/A | N/A | Included | N/A | N/A | A specific, named, primary-sourced commitment framework with defined, measurable service-experience areas - genuinely concrete evidence of a structured service-review approach, even without the full, itemised measurement criteria independently confirmed.
Other
Requires ConfirmationNot confirmed as a distinct, named on-premises hardware appliance line in sources reviewed - the platform's confirmed architecture centres on cloud delivery managed via Mission Control rather than dedicated branch hardware | Not itemised with specific hardware detail | N/A | N/A | N/A | N/A | N/A | A specific, worth-noting architectural characteristic - this platform does not appear to be centred on named, purpose-built on-premises branch hardware in the sources reviewed.
Other
SupportedYes, and genuinely the platform's default, core delivery model | Open Systems SASE Experience (fully managed SaaS) | Via the platform's global backbone | Mission Control (centralised, managed) | All customers - core delivery model | Very low for the customer, given the confirmed fully-managed model | N/A - default | Confirmed as fully cloud-native by design, reinforced by consistent, primary-sourced 'managed' framing across every source reviewed.
Other
Requires ConfirmationNot independently confirmed with specific client/agent deployment-effort detail in sources reviewed | Unknown | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in a Tier 1-2 source in this pass at this level of detail | Evidence gap for this specific row, though the platform's broader fully-managed model (Table 6, 8) makes low customer-side effort plausible even without direct, itemised confirmation for this exact scenario.
Other
Requires ConfirmationNative, via the confirmed centralised Mission Control organisation | N/A | N/A | Included | Customer-managed via co-managed option, or fully Mission-Control-managed by default | N/A | Confirmed via the specifically-named, centralised Mission Control architecture, with a genuine, confirmed co-managed alternative for customers wanting more direct involvement.
Other
Requires ConfirmationNative, implied via the confirmed Level-3-only engineer staffing model, though a distinctly-named TAM role/tier specifically wasn't itemised separate from the general Mission Control engineering team | 24x7x365 | Global | Included | N/A | N/A | A genuine, confirmed, high-quality engineering-support model (Level-3-only, 400+ hours additional training); a distinctly-named, separate TAM role/tier wasn't independently itemised.
Other
Requires ConfirmationNot independently confirmed with specific detail in sources reviewed | Unknown | Unknown | Unknown | Unknown | Not confirmed | Not found in a Tier 1-2 source in this pass | Evidence gap.
Compliance and assurance
13 records| Framework | Scope | Support | Review date | Qualification |
|---|---|---|---|---|
| DORA relevance | N/A | Requires Confirmation | Not stated | Unknown - not found in sources reviewed, despite confirmed general customer presence in the financial-services sector generally (Table 14) | N/A | Not confirmed | EU financial services | Not found in a Tier 1-2 source in this pass | Not found | A specific, worth-flagging gap given the confirmed general financial-services customer base - worth a direct follow-up for any EU financial-services buyer specifically. |
| Data residency | Unknown | Requires Confirmation | Not stated | Not independently confirmed as a distinct, named data-residency architecture in sources reviewed | Unknown | Not confirmed | Not specified | Not found in a Tier 1-2 source in this pass at sufficient detail | Not found | Evidence gap - worth a direct, specific follow-up, particularly relevant given the company's Swiss/EU orientation and the confirmed named subprocessor disclosure practise (Table 3, 12). |
| Encryption/key management | Platform | Requires Confirmation | Not stated | Not independently confirmed with specific technical detail (e.g. FIPS validation) in sources reviewed | Platform | Not confirmed at this technical depth | None identified | Not found in a Tier 1-2 source in this pass at sufficient specificity | Not found | Evidence gap - a common RFP question Netify should source directly from Open Systems. |
| FedRAMP | N/A | Requires Confirmation | Not stated | Not confirmed in sources reviewed | N/A | Not confirmed | N/A | Not found in a Tier 1-2 source in this pass at sufficient specificity | Not found | A genuine, specific, worth-flagging gap for US federal buyers specifically - consistent with the company's primarily European/Swiss orientation rather than a US-federal-market focus. |
| GDPR | Company-wide (implied) | Unknown | Not stated | Not separately itemised as a distinct, named compliance-certification line item in sources reviewed, though the company's Swiss/EU headquarters and orientation make GDPR-aligned data handling highly plausible in practise | Company-wide (implied) | Not confirmed as a distinct, named certification/attestation | EU/UK/Switzerland relevant | Not found as a distinctly-named certification in a Tier 1-2 source in this pass | Not found | A reasonable, though unconfirmed, inference from the company's genuine European/Swiss orientation; a distinct, named GDPR-compliance attestation or certification wasn't independently itemised. |
| HIPAA | N/A | Requires Confirmation | Not stated | Not confirmed as a formal attestation in sources reviewed | N/A | Not confirmed | US healthcare-relevant | Not found in a Tier 1-2 source in this pass at sufficient specificity | Not found | Evidence gap - worth a direct follow-up given the company's confirmed presence in the higher-education and NGO sectors, which sometimes carry adjacent data-sensitivity requirements. |
| ISO 27001 | Company-wide | Requires Confirmation | Not stated | Certified, confirmed directly via a dedicated, primary-sourced Open Systems certification page | Company-wide | ISO 27001 | None identified | 22 Jul 2026 | Genuinely well-evidenced via a dedicated, primary-sourced Open Systems page - a real, direct confirmation rather than a third-party inference. |
| Logging/auditability | Platform, per the confirmed ISO 27001 scope | Requires Confirmation | Not stated | Native, implied via the confirmed ISO 27001 certification, which by design requires documented, auditable logging and monitoring controls | Platform, per the confirmed ISO 27001 scope | Not confirmed at granular technical detail | None identified | 22 Jul 2026 | Reasonable, well-supported inference from the confirmed ISO 27001 certification; granular, product-level logging/export detail is a genuine, specific gap worth closing directly (see Table 10's Raw log access row). |
| NHS DSPT relevance | N/A | Unknown | Not stated | Unknown - not found in sources reviewed | N/A | Not confirmed | UK | Not found in a Tier 1-2 source in this pass | Not found | Evidence gap. |
| NIS2 relevance | N/A | Unknown | Not stated | Unknown - not found in sources reviewed | N/A | Not confirmed | EU | Not found in a Tier 1-2 source in this pass | Not found | Evidence gap - worth a direct follow-up given the company's genuine EU/Swiss orientation, where NIS2 relevance is increasingly a live procurement question. |
| PCI DSS | N/A | Requires Confirmation | Not stated | Not confirmed in sources reviewed | N/A | Not confirmed | N/A | Not found in a Tier 1-2 source in this pass | Not found | Evidence gap. |
| SOC 2 | N/A | Requires Confirmation | Not stated | Not confirmed in sources reviewed | N/A | Not confirmed | N/A | Not found in a Tier 1-2 source in this pass | Not found | A genuine evidence gap worth a direct follow-up - this may reflect the company's primarily European orientation (where SOC 2 is less commonly the lead certification) rather than confident evidence of absence. |
| UK public sector frameworks | UK | Unknown | Not stated | Unknown - not found in sources reviewed | UK | Not confirmed | UK | Not found in a Tier 1-2 source in this pass | Not found | Evidence gap. |
Integrations
20 recordsAWS
Cloud · Unknown
Cloud | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Active Directory
Identity · Unknown
Identity | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Avira
SWG Antivirus Engine (Partner-Delivered) · Partner
SWG antivirus engine (partner-delivered) | Confirmed via the same named subprocessor disclosure - the SWG antivirus scanning engine specifically is delivered through this named, Germany-based partner | Bidirectional (file/traffic scanning) | Included within the confirmed SWG/Managed Universal SSE product | Same confirmed disclosure as the Cyolo Security row above | Medium-High (same sourcing caveat as above) | Same specific, rare architectural-transparency finding as the Cyolo Security row above.
Commtouch (historical)
Threat Detection/Security Analytics (Legacy, Per An Older, 2020 Source) · Unknown
Threat detection/security analytics (legacy, per an older, 2020 source) | Referenced in the same older (2020) independent consultancy profile; current status not independently confirmed in this pass | Unknown | Not specified | Current status unconfirmed | Low (dated, current status unconfirmed) | Same treatment as the McAfee row above - retained for historical transparency, not presented as a confirmed, current integration.
CrowdStrike
EDR · Unknown
EDR | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Cyolo Security
ZTNA Engine (Partner-Delivered) · Partner
ZTNA engine (partner-delivered) | Confirmed via a named subprocessor disclosure - the ZTNA capability is delivered through this named, Israel-based partner | Bidirectional (ZTNA session brokering) | Included within the confirmed Zero Trust Service / Truly Universal ZTNA product | A genuinely rare, specific architectural transparency disclosure - most vendors in this category do not name their underlying ZTNA engine partner this specifically | Medium-High (confirmed via an independent source citing Open Systems' own subprocessor statement; not independently cross-verified against a primary Open Systems source in this pass) | A specific, named, genuinely rare architectural disclosure - worth confirming directly with Open Systems given it was sourced via an independent, competitor-published comparison rather than Open Systems' own primary materials in this research pass.
Google Cloud
Cloud · Unknown
Cloud | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Google Workspace
Identity/Productivity · Unknown
Identity/productivity | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
McAfee (historical)
Antivirus (Legacy, Per An Older, 2020 Source) · Unknown
Antivirus (legacy, per an older, 2020 source) | Referenced in an older (2020), independent consultancy profile as a 'managed application' for antivirus, though not corroborated by the more current (2026) subprocessor disclosure, which instead names Avira specifically | Unknown | Not specified | Likely superseded - the more current, 2026 subprocessor disclosure names Avira rather than McAfee for this function | Low (dated, likely superseded) | A specific, worth-flagging discrepancy between an older (2020) and more current (2026) source - this profile treats the more recent Avira disclosure as the current, authoritative answer, with the McAfee reference retained only for historical transparency.
Microsoft 365
Productivity/SaaS · Unknown
Productivity/SaaS | Not separately confirmed as a distinct named integration in sources reviewed | Unknown | Not specified | Not detailed | Not found as a distinct, named integration in this pass | Low | Evidence gap.
Microsoft Azure
Cloud · Unknown
Cloud | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Microsoft Defender
EDR · Unknown
EDR | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Microsoft Entra ID
Identity · Unknown
Identity | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Microsoft Sentinel
SIEM · Native
SIEM | Native, confirmed directly and with genuine specificity - MDR+ 'integrates deeply with Microsoft Sentinel' | Bidirectional (log/telemetry export and threat correlation) | Confirmed specifically for the MDR+ service tier | Named directly as a specific, deep integration point for the MDR+ managed-service tier | High | One of the strongest, most specifically-named integrations found in this entire profile - a real, credible, named SIEM platform, not a generic 'SIEM integration available' claim.
Okta
Identity · Unknown
Identity | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
REST API
Platform API · Api
Platform API | Not independently confirmed as a distinct, named public developer-API portal in sources reviewed | Unknown | Not specified | Not detailed | Not found as a distinct, named integration in this pass | Low | Evidence gap - worth a direct follow-up.
SCIM/SAML/OIDC
Identity Federation · Unknown
Identity federation | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap - a specific, worth-flagging follow-up given how central this capability is across the wider SASE/SSE category.
ServiceNow
ITSM · Unknown
ITSM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Splunk
SIEM · Unknown
SIEM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap - a specific, worth-flagging gap given how common this kind of pairing is across the wider SASE/SSE category, though the confirmed Microsoft Sentinel integration provides real, named SIEM capability regardless.
Syslog
Log Export · Unknown
Log export | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.
Sector evidence
8 recordsChemicals
UnknownGood fit, evidenced at a general level | Not assessed in specific technical detail for this sector | Not assessed for sector-specific frameworks | Confirmed directly as a served sector generally, per multiple independent sources' sector breakdowns, though no named individual chemicals-sector case study was found in this pass | N/A | General sector confirmation exists without a named individual customer example | A real, consistently-repeated sector confirmation across multiple independent sources, though without a named individual case study to reinforce it directly.
- Named evidence
- Confirmed directly as a served sector generally, per multiple independent sources' sector breakdowns, though no named individual chemicals-sector case study was found in this pass
- Case study strength
- Strong
Financial services
Requires ConfirmationConditional - confirmed as a general customer-base sector, without a named individual case study or DORA/PCI-specific certification | Not assessed in specific technical detail for this sector | PCI DSS, DORA not confirmed (Table 13) | None found as a named individual case study in this pass, though confirmed directly as a served sector generally | N/A | General sector confirmation exists without a named individual customer example or specific compliance certification | A real, primary-adjacent confirmation of sector fit exists, though without a named financial-services case study or the specific compliance certifications (PCI DSS, DORA) this sector often requires.
- Named evidence
- None found as a named individual case study in this pass, though confirmed directly as a served sector generally
- Case study strength
- None
Government/public sector
Requires ConfirmationUnknown - not assessed, no case study found, and no FedRAMP or equivalent authorization confirmed (Table 13) | Not assessed in detail | FedRAMP not confirmed | None found | N/A | The confirmed absence of FedRAMP evidence is a specific, relevant factor for US federal buyers specifically | Given the confirmed FedRAMP evidence gap and the company's primarily European orientation, Netify should not present confident US federal government suitability without direct vendor confirmation; European public-sector suitability wasn't independently assessed in this pass either.
- Named evidence
- None found
- Case study strength
- None
Higher education
Requires ConfirmationConditional - confirmed as a general customer-base sector, without a named individual case study | Not assessed in specific technical detail for this sector | Not assessed for sector-specific frameworks | None found as a named individual case study in this pass, though confirmed directly as a served sector generally | N/A | General sector confirmation exists without a named individual customer example | A real, consistently-repeated sector confirmation, though without a named individual case study to reinforce it directly.
- Named evidence
- None found as a named individual case study in this pass, though confirmed directly as a served sector generally
- Case study strength
- None
Logistics / multi-site global operations
UnknownStrong fit, evidenced via a real, named, quantified customer example | SD-WAN and Mission Control's global, multi-site management capability directly relevant, evidenced via genuine, quantified scale (60+ locations) | Not assessed for sector-specific frameworks | Altana (named customer, connecting 60+ locations worldwide and integrating new acquisitions) | Global, per the confirmed 60+-location customer example | A single, though genuinely specific and quantified, named case study | Genuinely well-evidenced via a real, named, specifically-quantified (60+ locations) customer example directly relevant to large-scale, distributed, multi-site operations.
- Named evidence
- Altana (named customer, connecting 60+ locations worldwide and integrating new acquisitions)
- Case study strength
- Strong
Manufacturing
UnknownStrong fit, extensively evidenced | The confirmed, dedicated OT Firewall product, plus SD-WAN and Mission Control's proactive monitoring, are directly relevant to distributed manufacturing operations | Not assessed for sector-specific frameworks beyond the confirmed general ISO 27001 certification | Mikron (named customer, described directly as strengthening security specifically to 'protect critical production systems'), confirmed directly as a served sector generally | N/A | Real, named customer evidence exists for this sector specifically | Genuinely well-evidenced via both a real, named customer case study directly referencing production-system protection and a dedicated, purpose-built OT Firewall product.
- Named evidence
- Mikron (named customer, described directly as strengthening security specifically to 'protect critical production systems'), confirmed directly as a served sector generally
- Case study strength
- Strong
Non-governmental organisations (NGOs)
UnknownStrong fit, extensively evidenced | Mission Control's global, follow-the-sun operational model is directly relevant to internationally-distributed NGO operations | Not assessed for sector-specific frameworks | SOS Children's Villages (named, major, well-known international NGO customer, described directly as having optimized its global network 'worldwide') | Global, per the confirmed customer example spanning worldwide operations | A single, if genuinely well-known and credible, named case study | Genuinely well-evidenced via a real, named, globally-recognised international NGO customer - SOS Children's Villages is a substantial, credible, easily-verifiable organisation, making this a specific, checkable reference.
- Named evidence
- SOS Children's Villages (named, major, well-known international NGO customer, described directly as having optimized its global network 'worldwide')
- Case study strength
- Strong
Retail / consumer goods
UnknownGood fit, evidenced via a real, named, well-known customer | Not assessed in specific technical detail for this sector beyond the confirmed WAN-replacement and internet-breakout capabilities evidenced directly | Not assessed for sector-specific frameworks | Mammut (named, well-known international outdoor-apparel brand, with specific, quantified deployment detail: WAN replacement completed in under two months) | N/A | A single, though genuinely well-known, named, and specifically-quantified case study | A real, credible, named customer - Mammut is a well-known international outdoor-apparel brand - reinforced by specific, quantified deployment-timeline detail, making this a genuinely strong reference despite being a single example.
- Named evidence
- Mammut (named, well-known international outdoor-apparel brand, with specific, quantified deployment detail: WAN replacement completed in under two months)
- Case study strength
- Strong
Case studies
3 records- Customer
- Named - SOS Children's Villages (a major, well-known international non-governmental organisation)
- Sector and geography
- Non-governmental organisation (international child welfare/development) · Global (SOS Children's Villages operates internationally)
- Estate
- Not quantified; Not quantified - described as optimising the network 'worldwide'
- Outcome
- Confirmed directly: 'Mission Control and cloud security improved performance, connectivity, and IT efficiency worldwide' - though without a specific, quantified percentage or figure attached
Named - SOS Children's Villages (a major, well-known international non-governmental organisation) | Non-governmental organisation (international child welfare/development) | Global (SOS Children's Villages operates internationally) | Not quantified | Not quantified - described as optimising the network 'worldwide' | Needed to optimise its global network to improve performance, connectivity, and IT efficiency across a worldwide operation | Open Systems SASE Experience, with Mission Control managed operations and cloud security | Fully managed, global | Not itemised | Confirmed directly: 'Mission Control and cloud security improved performance, connectivity, and IT efficiency worldwide' - though without a specific, quantified percentage or figure attached | Medium-High - a real, named, globally-recognised, credible international NGO, though the specific outcome language is qualitative rather than quantified | A genuinely credible reference given SOS Children's Villages' substantial, well-known, easily-verifiable international profile, even though the confirmed outcome language is qualitative ('improved... worldwide') rather than a specific, quantified figure.
- Customer
- Named - Mammut (a well-known international outdoor-apparel brand)
- Sector and geography
- Retail / consumer goods (outdoor apparel) · Not specified (Mammut is a Swiss-founded, internationally-operating brand)
- Estate
- Not quantified; Not quantified - described generally as connecting 'sites and users'
- Outcome
- 'In less than two months, we took over bandwidth management and added low-cost and secure internet breakouts and VPNs to connect sites and users'; built-in cybersecurity protected assets 'on-premises, at data centres, or in the cloud'; 360° security and network visibility confirmed via Mission Control; Mammut's IT team was freed to focus on other priorities
Named - Mammut (a well-known international outdoor-apparel brand) | Retail / consumer goods (outdoor apparel) | Not specified (Mammut is a Swiss-founded, internationally-operating brand) | Not quantified | Not quantified - described generally as connecting 'sites and users' | Had an aging WAN in need of replacement, and wanted a single provider for both fully managed SD-WAN and global network connectivity to reduce complexity | Open Systems SASE Experience (SD-WAN, secure internet breakouts, VPNs, built-in cybersecurity, 24x7 Mission Control monitoring) | Fully managed | Not itemised | 'In less than two months, we took over bandwidth management and added low-cost and secure internet breakouts and VPNs to connect sites and users'; built-in cybersecurity protected assets 'on-premises, at data centres, or in the cloud'; 360° security and network visibility confirmed via Mission Control; Mammut's IT team was freed to focus on other priorities | High - a real, named, well-known international brand, with specific, quantified deployment-timeline detail and a direct, primary-sourced customer narrative | A genuinely strong, credible case study - Mammut is a real, well-known, easily-verifiable international brand, and the specific two-month deployment timeline gives this case study real, checkable substance beyond generic marketing language.
- Customer
- Named - KEMET (an electronic components manufacturer)
- Sector and geography
- Manufacturing / electronics · Not specified
- Estate
- Not quantified; Not quantified - described as spanning hybrid cloud and on-premises environments
- Outcome
- Confirmed directly: 'simplified operations, improved security, and cut costs by 50%' - a specific, quantified cost-reduction outcome
Named - KEMET (an electronic components manufacturer) | Manufacturing / electronics | Not specified | Not quantified | Not quantified - described as spanning hybrid cloud and on-premises environments | Needed to manage a complex hybrid cloud and on-premises network more effectively, simplifying operations while improving security | Open Systems SASE Experience, with Mission Control managed operations | Fully managed, spanning hybrid cloud and on-premises environments together | Not itemised | Confirmed directly: 'simplified operations, improved security, and cut costs by 50%' - a specific, quantified cost-reduction outcome | High - a real, named customer with a specific, quantified (50%) cost outcome, hosted directly on Open Systems' own customer-story index | Genuinely one of the strongest, most specifically-quantified case studies found in this research pass - a real, named customer with a concrete, checkable percentage outcome rather than vague, qualitative language.
Netify evaluation record
49 recordsSummary
Strength | A specifically-named, quantified, extensively and consistently evidenced fully-managed operations model (Mission Control) - Level-3-engineer-only staffing, 400+ hours of additional training per engineer, and a confirmed 8-minute ticket-escalation commitment | Buyers get a genuinely low-operational-burden platform backed by concrete, checkable operational commitments rather than vague 'great support' marketing language | Best: buyers specifically wanting fully managed delivery with minimal internal operational burden. Less relevant: buyers wanting a self-service, do-it-yourself platform with minimal vendor involvement | High | Genuinely the single strongest, most specifically and consistently evidenced characteristic of this vendor across the entire profile - not a single feature but the company's whole operating identity.
Buyers get a genuinely low-operational-burden platform backed by concrete, checkable operational commitments rather than vague 'great support' marketing language
Summary
Overall Netify Assessment | Open Systems' most credible, best-evidenced strength is genuinely consistent across this entire profile: a specifically-named, quantified, fully-managed operations model (Mission Control) delivering real, checkable operational commitments, reinforced by five real, named customer case studies spanning genuinely varied scenarios with several quantified outcomes. That evidence, combined with a confirmed ISO 27001 certification and a genuinely rare degree of architectural transparency about partner-delivered components, makes this a credible shortlist candidate - particularly for large, multi-site organisations and European/Swiss-oriented buyers specifically. The profile is honest about real, specific gaps: no confirmed US-centric compliance certification, recent ownership and leadership changes, and comparatively thin remote-user/BYOD-specific evidence. This profile is solid enough to support initial shortlist guidance for large-enterprise, managed-service-preferring, and European-oriented buyers specifically, but the flagged compliance gaps and the recent ownership transition should both be discussed directly with Open Systems before use in a high-stakes, long-term, or US-regulated procurement decision. | Whole profile | Medium-High overall | Recommend direct Open Systems engagement to confirm current compliance-certification status and understand Swiss Post's strategic intent before this profile supports a high-stakes procurement decision.
Recommend direct Open Systems engagement to confirm current compliance-certification status and understand Swiss Post's strategic intent before this profile supports a high-stakes procurement decision.
Summary
Support/service reality | Genuinely one of the strongest, most specifically-evidenced support findings across this entire profile - a real, named, quantified 8-minute escalation commitment, Level-3-only engineer staffing with 400+ hours of additional training, and real, verbatim, independently-hosted customer reviews all reinforce the same, consistent picture. | Table 8 | High | Present this support-model evidence with genuine confidence - it is unusually specific, quantified, and consistently corroborated relative to the vague 'support available' finding common across this category.
Present this support-model evidence with genuine confidence - it is unusually specific, quantified, and consistently corroborated relative to the vague 'support available' finding common across this category.
Summary
Compliance & Footprint | A confirmed, primary-sourced, dedicated ISO 27001 certification page, reinforced by the company's genuinely long, three-decades-plus operating history and a specific, quantified global footprint (approximately 10,000 deployments across more than 180 countries). | No FedRAMP, SOC 2, PCI DSS, or HIPAA certification was found confirmed in any source reviewed in this research pass - a real, specific gap for buyers with US-specific compliance-attestation requirements, worth understanding given the company's genuinely European (Swiss) primary orientation.
Summary
Cloud-first organisation | Good fit, evidenced at a general level | Confirmed cloud-native, single-pass architecture and real, named customer evidence explicitly confirming protection across on-premises, data-centre, and cloud environments together (Mammut) | None significant identified | Not assessed | Table 3, 6 findings | Real, credible fit, reinforced by specific, primary-sourced, named-customer confirmation of unified multi-environment protection.
Summary
SSE deployment to remote users | Not evidenced with specific detail in sources reviewed, consistent with the broader Table 5 finding that remote-user/client-side evidence is thinner than the site-to-site/managed-operations side of the platform | Not itemised | Not itemised | Not itemised | Not quantified | Not itemised | Not detailed | A genuine, specific evidence gap for this exact scenario, consistent with the pattern found throughout Table 5.
Summary
Who is this genuinely best suited for? (mandatory) | Buyers specifically wanting genuinely fully managed SASE delivery with concrete, quantified operational commitments (8-minute escalation, Level-3-only engineers) rather than a self-service platform; large, multi-site, or internationally-distributed organisations, given the confirmed named case-study evidence at genuine scale (60+ locations); and European or Swiss-oriented buyers, or those with a specific preference for a state-backed rather than venture/private-equity-owned provider. | Tables 1, 8, 14, 15 | High | Buyers matching this profile can proceed with genuine confidence, backed by real, specific, quantified evidence rather than only generic managed-service marketing claims.
Buyers matching this profile can proceed with genuine confidence, backed by real, specific, quantified evidence rather than only generic managed-service marketing claims.
Summary
Limitation | Remote-user and BYOD-specific evidence is comparatively thin relative to the platform's well-evidenced site-to-site SD-WAN, managed-operations, and branch-connectivity capabilities (see Table 5) | Buyers whose primary requirement is remote/hybrid-workforce access specifically, rather than site-to-site connectivity, have less specific evidence to evaluate | Affects remote-user-heavy organisations most specifically | Table 5, 15 findings | Medium-High (confident about the specific gap found in this research pass) | A genuine, specific evidence gap - this profile's strongest evidence clusters around site-to-site SD-WAN and managed operations; buyers with a primarily remote-workforce use case should confirm ZTNA/remote-access specifics directly.
Buyers whose primary requirement is remote/hybrid-workforce access specifically, rather than site-to-site connectivity, have less specific evidence to evaluate
Summary
Global branch rollout | Genuinely one of the best-evidenced scenarios in this entire profile - the confirmed Altana case study describes connecting '60+ locations worldwide and securely integrated new acquisitions' | Existing branch network/WAN infrastructure to integrate or replace | Mission Control (fully managed) | Mission Control | Not quantified with a specific overall timeline, though the confirmed fully-managed model implies reduced customer-side effort | Not itemised | Not detailed | Genuinely one of the strongest, most specifically-quantified global-rollout scenarios found in this research pass - real, named-scale (60+ locations) evidence.
Summary
Questions to ask before recommending it | 1) Does Open Systems have any current FedRAMP, SOC 2, PCI DSS, or HIPAA certification, or a stated roadmap toward one? 2) Given the confirmed subprocessor disclosure, which platform components are native versus partner-delivered (beyond ZTNA and SWG antivirus), and how does support/SLA accountability work for partner-delivered components specifically? 3) What is Swiss Post's specific strategic intent for Open Systems following the 2024 acquisition, and what direction has the newly-appointed CEO signalled? 4) What does a realistic quote look like at our expected scale, given the confirmed absence of published, first-party pricing? | Synthesis of Tables 1, 12, 13, 16 | High | A direct, reusable question set for Netify's advisory conversations with buyers considering Open Systems.
A direct, reusable question set for Netify's advisory conversations with buyers considering Open Systems.
Summary
Deployment & Ops | A specifically-named, quantified managed-operations model (Mission Control) with a confirmed 8-minute escalation SLA and Level-3-engineer-only staffing, reinforced by real, named, quantified customer outcomes - Mammut's WAN replacement was completed in under two months, and KEMET's engagement cut costs by 50%. | The platform's entire value proposition centres on fully managed delivery; buyers specifically wanting a self-service, do-it-yourself platform with minimal vendor involvement should confirm this model fits their preferred operating approach, since a genuinely self-managed option was not confirmed as the platform's primary path in this research pass.
Summary
Biggest operational concern | The combination of no confirmed US-centric compliance certification (FedRAMP, SOC 2, HIPAA) and the recent, short-period ownership/leadership changes together represent the two most concrete, actionable considerations a buyer should resolve directly before committing to a long-term, high-stakes relationship. | Tables 1, 13, 19 | Medium-High | Netify should proactively flag both specific, evidenced considerations to buyers during the shortlist conversation rather than let either surface as a surprise later.
Netify should proactively flag both specific, evidenced considerations to buyers during the shortlist conversation rather than let either surface as a surprise later.
Summary
Where does it fall behind competitors? (mandatory) | No FedRAMP, SOC 2, PCI DSS, or HIPAA certification was found confirmed in this research pass; the company underwent two ownership/leadership changes in a short period (Swiss Post acquisition 2024, new CEO late 2025); remote-user/BYOD-specific evidence is comparatively thin; and no first-party, published pricing was found. | Tables 1, 5, 13, 16 | Medium-High | Named specifically and evidenced, not a generic hedge - the compliance-certification gap specifically should be raised proactively with any US-regulated or US-federal buyer.
Named specifically and evidenced, not a generic hedge - the compliance-certification gap specifically should be raised proactively with any US-regulated or US-federal buyer.
Summary
Firewall consolidation | Evidenced via the confirmed single-pass architecture integrating firewall alongside SD-WAN, SWG, NDR and unified threat detection together | Existing firewall infrastructure potentially retired | IT/security team | Mission Control | Not quantified with a specific timeline | Not itemised | Not detailed | The underlying architectural capability is genuinely well-evidenced (confirmed single-pass, no-service-chaining design), though a named customer case study specifically about firewall consolidation wasn't found in this pass.
Summary
Strength | A genuinely rare degree of architectural transparency - a confirmed, named subprocessor disclosure identifying Cyolo Security (ZTNA) and Avira (SWG antivirus) as the specific, named partners delivering two core platform functions | Buyers get real, specific, checkable visibility into exactly which components are native versus partner-delivered, rather than an undifferentiated 'fully native, single-vendor stack' claim | Best: buyers who specifically value vendor transparency and want to understand exact component provenance. Less relevant: buyers with no particular concern about native-versus-partner component delivery | Medium-High (confirmed via an independent source citing Open Systems' own subprocessor statement, though not independently cross-verified against a primary Open Systems source in this specific research pass) | A genuinely distinctive, worth-highlighting transparency practise, though Netify should confirm this disclosure directly with Open Systems given the sourcing caveat noted.
Buyers get real, specific, checkable visibility into exactly which components are native versus partner-delivered, rather than an undifferentiated 'fully native, single-vendor stack' claim
Summary
Co-managed transition | Genuinely a core, confirmed architectural option - the platform explicitly supports choosing a co-managed model alongside the confirmed fully-managed default, giving customers a real, structured path to increase direct involvement over time if desired | Existing tools/processes reviewed against Open Systems' co-managed model | Customer chooses desired level of involvement | Mission Control (co-managed mode) | Not quantified | N/A | N/A | A specific, confirmed, real architectural option - genuinely credible evidence that this platform accommodates a spectrum of customer involvement rather than being strictly all-or-nothing.
Summary
Mature NetOps/SecOps team | Conditional fit | Mature teams get real, confirmed flexibility via the confirmed co-managed option for direct involvement, though this platform's core, most extensively evidenced strength centres on fully-managed delivery rather than deep, named technical differentiation for sophisticated in-house teams wanting maximum self-directed control | Mature teams benefit from familiarity with the confirmed co-managed model specifically | Not assessed | Table 6, 9 findings | A reasonable fit specifically for mature teams wanting the co-managed flexibility option; teams wanting maximum self-directed, self-managed control should confirm this platform's fully-managed default model fits their preference.
Summary
Procurement watch-out | The confirmed subprocessor disclosure (Cyolo Security for ZTNA, Avira for SWG antivirus) means buyers evaluating this platform as a fully native, single-vendor security stack should confirm the practical implications directly - including support-escalation accountability when an issue originates in a partner-delivered component specifically | Buyers should ask directly how support and SLA accountability work when an issue traces back to a partner-delivered component, rather than assuming the same escalation path applies uniformly across every platform layer | Most relevant to buyers with strict single-vendor-accountability requirements, or those specifically evaluating vendor lock-in and dependency risk | Table 3, 12, 19 findings | Medium-High | A specific, worth-flagging nuance - this is not necessarily a weakness (partner-delivered components can reflect a sensible best-of-breed choice for specific functions), but buyers should understand the practical support implications directly rather than assume full, single-vendor accountability by default.
Buyers should ask directly how support and SLA accountability work when an issue traces back to a partner-delivered component, rather than assuming the same escalation path applies uniformly across every platform layer
Summary
Most credible differentiator | A specifically-named, quantified, consistently-evidenced fully-managed operations model - Mission Control's 8-minute escalation commitment and Level-3-only engineer staffing - reinforced by five real, named customer case studies with several quantified outcomes, rather than a generic 'great managed service' claim. | Tables 8, 18, 19 | High | This is the single sentence Netify's comparison engine could most confidently quote for this vendor specifically.
This is the single sentence Netify's comparison engine could most confidently quote for this vendor specifically.
Summary
VPN to ZTNA migration | Evidenced via the confirmed Zero Trust Service / Truly Universal ZTNA product, though a named customer case study specifically describing VPN retirement wasn't found in this pass | Existing VPN infrastructure retired | IT team | Mission Control | Not quantified with a specific timeline | Not itemised | Not detailed | Real, confirmed product capability exists; a named customer case study specifically for this exact migration scenario wasn't found in this pass, a genuine, specific gap worth noting.
Summary
Reporting reality | Strong specifically for network health, application/user-experience visibility, and site/circuit performance, reinforced by real, named customer evidence and a specific, named Microsoft Sentinel integration for MDR+; weaker or unconfirmed on compliance reporting, executive dashboards, and scheduled/custom reports, none of which were confirmed as distinct, named products in this research pass. | Table 10 | Medium-High for network/user-experience reporting; Low for compliance/executive reporting | Present the network-visibility and user-experience-monitoring strengths specifically rather than imply comprehensive reporting maturity across every category.
Present the network-visibility and user-experience-monitoring strengths specifically rather than imply comprehensive reporting maturity across every category.
Summary
Scope & Boundaries | Genuinely strong, named customer evidence - five real, named case studies (KEMET, Mammut, SOS Children's Villages, Mikron, Altana) spanning manufacturing, apparel/retail, international NGO, and multi-site acquisition-integration scenarios, several with specific, quantified outcomes. | Open Systems has changed ownership twice in a short period - from EQT private equity to Swiss Post in 2024 - and appointed a new CEO in late 2025; buyers making very long-term commitments may want to understand the current owner's specific strategic intentions directly, given how recently both changes occurred.
Summary
Commercials | A confirmed 'fully OPEX cost model', per Gartner Peer Insights' own hosted product description - a specific, distinctive commercial positioning point for buyers wanting to avoid capital expenditure on networking/security infrastructure entirely. | No first-party, published pricing was found in any source reviewed in this research pass, consistent with the pattern across most vendors in this category.
Summary
Highly distributed branch estate | Strong fit, extensively evidenced | The confirmed Altana case study (60+ locations, including newly-acquired sites) and the confirmed Mission Control global operations model together give this buyer profile genuine, specific, quantified evidence | Very low, given the confirmed fully-managed model | Not itemised | Table 4, 14 findings | One of the more specifically-quantified branch-estate findings in this profile - real, named-scale (60+ locations) evidence rather than a generic capability claim.
Summary
Mid-market | Good fit, evidenced | Real, named customer examples (Mikron, KEMET) suggest genuine mid-market applicability, reinforced by the confirmed fully-managed model's appeal to organisations without large internal IT/security teams | Benefits from, but doesn't strictly require, extensive internal networking expertise given the confirmed managed model | Not itemised | Table 14, 18 findings | Real, credible fit for this buyer profile, backed by named case-study evidence.
Summary
Multi-vendor SASE integration | Not a primary emphasis of Open Systems' own positioning in the sources reviewed, which centres on a single-vendor, fully-managed SASE platform rather than explicitly marketed best-of-breed pairings with named third-party SASE/SD-WAN vendors - though the confirmed subprocessor disclosures (Cyolo Security for ZTNA, Avira for SWG antivirus) show the platform itself already incorporates named third-party technology internally | Existing security tools already in place | Not itemised | Not itemised | Not quantified | N/A | N/A | A specific, worth-stating architectural-philosophy distinction - Open Systems presents a single, unified, fully-managed SASE proposition to buyers, even though internally it confirms sourcing specific components (ZTNA, SWG antivirus) from named third-party partners rather than building every layer entirely in-house.
Summary
MPLS to SD-WAN migration | Genuinely well-evidenced via a real, named, quantified customer example - Mammut 'replaced its aging WAN' with Open Systems SASE, with bandwidth management taken over in under two months | Existing WAN infrastructure retired or coexisting during transition | IT team, though substantially reduced given the confirmed fully-managed model | Mission Control (fully managed) | Genuinely well-evidenced - 'in less than two months, we took over bandwidth management' | Not itemised | The confirmed fully-managed model shifts most migration-execution risk to Open Systems' own Mission Control team | One of the better-evidenced migration scenarios in this profile - a real, named customer directly describing WAN replacement with a specific, quantified timeline.
Summary
AI reality | A real, direct, primary-sourced confirmation of AI/ML investment supporting Mission Control's proactive and reactive operations, reinforced by real, independent, verbatim customer-review language describing reduced operational complexity; a single, separately-branded AI product name (comparable to some competitors' named AI products) was not independently confirmed in this pass. | Table 11 | Medium-High | Represent the confirmed, real AI/ML investment with genuine confidence, while being clear that a single, distinctly-branded AI product name wasn't independently confirmed - the evidence here is genuine but framed generally rather than around one flagship product.
Represent the confirmed, real AI/ML investment with genuine confidence, while being clear that a single, distinctly-branded AI product name wasn't independently confirmed - the evidence here is genuine but framed generally rather than around one flagship product.
Summary
Merger/acquisition integration | Genuinely and specifically evidenced - the confirmed Altana case study directly describes securely integrating 'new acquisitions' as part of the same 60+-location deployment | Newly-acquired sites' existing network infrastructure integrated or replaced | Mission Control (fully managed) | Mission Control | Not quantified with a specific integration timeline | Not itemised | Not detailed | A specific, real, named-context example of exactly this scenario - genuinely credible, concrete evidence rather than a generic capability claim, reinforced by the vendor's own recent, direct experience of being acquired (Swiss Post, 2024) - worth noting as parallel, if unrelated, context.
Summary
Security & Analytics | A confirmed single-pass architecture spanning SD-WAN, SWG, firewall, NDR and unified threat detection together, reinforced by Gartner Peer Insights' own hosted description of 'no service chaining' for improved line-rate performance. | An independent source citing Open Systems' own subprocessor statement confirms ZTNA and SWG antivirus scanning are delivered through named third-party partners (Cyolo Security and Avira respectively) rather than fully in-house - a genuine, worth-understanding architectural characteristic rather than a fully native, single-vendor stack in every respect.
Summary
Lean IT team | Strong fit, extensively evidenced | The confirmed, extensively-evidenced fully-managed Mission Control model, with a specific, quantified 8-minute escalation SLA and Level-3-only engineer staffing, directly and consistently supports a genuinely low-operational-burden story throughout this entire profile | Minimal training investment implied by the confirmed fully-managed default model | Not assessed | Table 8, 9 findings | Genuinely one of the strongest, most consistently-evidenced buyer-profile fits in this entire profile - this vendor's core identity centres on minimising exactly this buyer type's operational burden.
Summary
Commercial reality | No pricing exists for this platform in any source found in this research pass, though the confirmed 'fully OPEX cost model' and the confirmed multi-product structure (SASE Experience, Managed Universal SSE, MDR+, Zero Trust Service) give buyers some real, useful commercial framing even without published figures. | Table 16 | Medium (confident about the absence of published pricing, and about the confirmed OPEX-model and product-structure detail) | Route any budget conversation to a direct Open Systems quote from the very first interaction - Netify currently has no benchmark figure of any kind to offer a buyer for this vendor.
Route any budget conversation to a direct Open Systems quote from the very first interaction - Netify currently has no benchmark figure of any kind to offer a buyer for this vendor.
Summary
When would Netify recommend looking elsewhere? (mandatory) | When a buyer needs confirmed, current FedRAMP, SOC 2, PCI DSS, or HIPAA certification; when a buyer specifically wants a fully self-service, minimally-managed platform rather than the confirmed, consistently fully-managed default model; or when a buyer wants a fully native, single-vendor security stack with no confirmed third-party component delivery. | Synthesis of Tables 3, 6, 13 | Medium-High | Each trigger is tied to a specific, evidenced gap rather than a generic 'consider alternatives' hedge.
Each trigger is tied to a specific, evidenced gap rather than a generic 'consider alternatives' hedge.
Summary
Global fit | Confirmed, specific global scale (approximately 10,000 deployments across 180+ countries), reinforced by real, named customer deployments spanning multiple continents, with Europe specifically the strongest-evidenced region given the company's Swiss origin and headquarters. | Table 7, 14 | High for Europe specifically; Medium for global reach generally; Low for country-level specificity outside Europe | The confirmed European/Swiss strength is worth highlighting directly for any buyer with a European or data-sovereignty-adjacent preference; always verify other-region delivery capability directly with Open Systems.
The confirmed European/Swiss strength is worth highlighting directly for any buyer with a European or data-sovereignty-adjacent preference; always verify other-region delivery capability directly with Open Systems.
Summary
Limitation | Two changes to the company's ownership and leadership structure occurred in a relatively short period - EQT's exit and Swiss Post's acquisition in 2024, followed by a new CEO appointment (Dennis Monner) in late 2025 | Buyers making very long-term commitments face genuine, if manageable, uncertainty about the current owner's specific strategic intentions, given how recently both changes occurred | Affects buyers prioritising long-term vendor stability and roadmap predictability as a selection criterion most specifically | Table 1 findings | Medium (the events themselves are well-corroborated across multiple sources; their long-term strategic implications are inherently forward-looking and not something this research pass can resolve) | Worth flagging directly, though tempered by the fact that Swiss Post is a stable, state-backed institution rather than a typical private-equity owner with a defined exit timeline - a genuinely different, and arguably more stable, ownership profile worth understanding on its own terms.
Buyers making very long-term commitments face genuine, if manageable, uncertainty about the current owner's specific strategic intentions, given how recently both changes occurred
Summary
When would Netify recommend it? (mandatory) | When a buyer specifically wants genuinely fully managed SASE delivery with concrete, quantified operational commitments; when a buyer is a large, multi-site, or internationally-distributed organisation wanting proven, at-scale evidence; or when a buyer has a specific preference for a European/Swiss-oriented, state-backed provider. | Synthesis of Tables 1, 8, 14, 15 | High | A clear, actionable recommendation trigger set for Netify's comparison tool to apply directly.
A clear, actionable recommendation trigger set for Netify's comparison tool to apply directly.
Summary
Remote-user-heavy organisation | Unknown - thin evidence specifically for the remote-user/client side of the platform (see Table 5) | Not assessed with confidence | Not assessed | Not assessed | Table 5 findings | A genuine, specific evidence gap - this profile's research skewed toward the site-to-site SD-WAN, managed-operations, and branch-connectivity sides of the platform, leaving remote-user/client-side evidence comparatively thin.
Summary
Deployment reality | Genuinely well-evidenced as low-effort and effective, backed by real, named, quantified customer deployments - Mammut's under-two-month WAN replacement and Altana's 60+-location, acquisition-inclusive rollout are both specific, credible, concrete examples rather than generic capability claims. | Table 4, 9, 17, 18 | High | Present the deployment evidence with genuine confidence, backed by specific, named, quantified outcomes across two genuinely distinct scenarios.
Present the deployment evidence with genuine confidence, backed by specific, named, quantified outcomes across two genuinely distinct scenarios.
Summary
Limitation | No FedRAMP, SOC 2, PCI DSS, or HIPAA certification was found confirmed in any source reviewed in this research pass, consistent with the company's primarily European/Swiss orientation | US-regulated and US-federal buyers cannot currently verify these specific certifications for this platform from public sources | Affects US federal government and US-regulated-industry buyers most specifically and directly | Table 13 findings | Medium-High (confident about the absence found in this specific research pass, though this may reflect a research-pass limitation or a genuinely European-market-focused certification strategy rather than confirmed permanent absence) | A specific, worth-flagging gap Netify should raise directly and early with any US-regulated or US-federal buyer evaluating this platform.
US-regulated and US-federal buyers cannot currently verify these specific certifications for this platform from public sources
Summary
Regulated organisation | Conditional fit, strongest for European/ISO 27001-relevant requirements specifically | ISO 27001 is confirmed directly via a dedicated, primary-sourced certification page; SOC 2, PCI DSS, HIPAA, and - most notably - FedRAMP were not confirmed | Buyer must independently verify sector-specific compliance status directly with Open Systems for anything outside the confirmed ISO 27001 scope | Not assessed | Table 13 findings | A real, confirmed ISO 27001 foundation exists, tempered by the specific, worth-flagging absence of US-centric certifications (FedRAMP, SOC 2, HIPAA) - a real, important distinction for any US-regulated or US-federal buyer specifically.
Summary
Global multinational | Strong fit, evidenced | Confirmed approximately 10,000 deployments across 180+ countries, reinforced by real, named customer examples spanning multiple continents and, in Altana's case, direct acquisition-integration across 60+ global locations | Needs Netify/buyer to verify specific-country coverage directly, given the Table 7 general-versus-specific coverage-detail gap | Custom enterprise pricing | Table 7, 14 findings | Genuinely well-evidenced multinational capability, reinforced by specific, named customer deployments spanning multiple distinct global regions.
Summary
SME | Conditional fit | The confirmed fully-managed model reduces internal skill requirements to near zero, though the platform's evidenced customer base (KEMET, Mammut, SOS Children's Villages, Mikron, Altana) skews toward genuinely large, multi-site, or internationally-distributed organisations rather than small businesses specifically | Minimal internal skills needed given the confirmed fully-managed model | No confirmed entry-level pricing tier or SME-specific positioning found in this pass | Table 14, 18 findings | A reasonable, though not extensively evidenced, fit - this vendor's evidenced case-study base and enterprise-oriented positioning suggest it may be better suited to larger, more complex estates than to the smallest SMEs specifically.
Summary
Strength | Five real, named customer case studies (KEMET, Mammut, SOS Children's Villages, Mikron, Altana) - genuinely more than found for most vendors in this category - several with specific, quantified outcomes (KEMET's 50% cost reduction, Mammut's under-two-month deployment, Altana's 60+ integrated locations) | Buyers get concrete, checkable, named-customer proof across a genuine variety of scenarios (cost reduction, WAN replacement speed, global NGO operations, OT/manufacturing security, M&A integration) rather than a single, isolated reference | Best: any buyer wanting named-customer evidence across multiple distinct scenarios before committing. Less relevant: N/A - this benefits any evaluation | Table 18 findings | High | Genuinely one of the richer, more varied case-study sets found in this research pass - five distinct, named, real customers spanning five different scenarios is a real, substantive evidence base.
Buyers get concrete, checkable, named-customer proof across a genuine variety of scenarios (cost reduction, WAN replacement speed, global NGO operations, OT/manufacturing security, M&A integration) rather than a single, isolated reference
Summary
Biggest operational advantage | A confirmed, specific, quantified 8-minute ticket-escalation commitment combined with real, verbatim customer-review language directly praising reduced operational complexity - concrete, real-customer evidence rather than only marketing language. | Table 8, 9 | High | Directly quotable with the specific, quantified SLA and real, verbatim customer-review language for credibility.
Directly quotable with the specific, quantified SLA and real, verbatim customer-review language for credibility.
Summary
What implementation challenges should buyers expect? (mandatory) | Expect a genuinely low-effort deployment experience under the confirmed fully-managed default model, reinforced by real, named, quantified customer examples (Mammut's under-two-month WAN replacement). Expect a real, confirmed choice between fully-managed and co-managed delivery for buyers wanting more direct involvement. Expect the commercial conversation to require a direct Open Systems engagement from the start, given the complete absence of published, first-party pricing. | Tables 6, 9, 16, 17 | Medium-High | Each expectation is traceable to a specific, evidenced finding elsewhere in this profile.
Each expectation is traceable to a specific, evidenced finding elsewhere in this profile.
Summary
Where does it stand out? (mandatory) | A specifically-named, quantified, extensively-evidenced fully-managed operations model (Mission Control); five real, named customer case studies spanning genuinely varied scenarios with several quantified outcomes; and a genuinely rare degree of architectural transparency about partner-delivered components (Cyolo Security, Avira). | Tables 8, 12, 18, 19 | High | These are the claims Netify can make most confidently and specifically to buyers, each backed by named, dated, primary-sourced or credible independent evidence.
These are the claims Netify can make most confidently and specifically to buyers, each backed by named, dated, primary-sourced or credible independent evidence.
Summary
Questions Netify still cannot verify | Current FedRAMP, SOC 2, PCI DSS, HIPAA, GDPR-specific-attestation, NIS2, and DORA status; specific, published pricing figures at any tier; the current, confirmed scope of native-versus-partner-delivered components beyond ZTNA and SWG antivirus; Swiss Post's specific strategic intent for the company; and remote-user/BYOD-specific client/agent technology detail. | Synthesis of Tables 5, 12, 13, 16 | N/A - explicitly unresolved | This list should drive the next follow-up (a direct Open Systems briefing) before this profile is considered fully closed out, particularly the compliance-certification and partner-component-scope questions given their direct relevance to regulated-sector and vendor-dependency-sensitive recommendations.
This list should drive the next follow-up (a direct Open Systems briefing) before this profile is considered fully closed out, particularly the compliance-certification and partner-component-scope questions given their direct relevance to regulated-sector and vendor-dependency-sensitive recommendations.
Summary
Large enterprise | Strong fit, extensively evidenced | Real, named, large-scale customer examples (Altana's 60+ locations, SOS Children's Villages' worldwide operations) directly demonstrate genuine large-enterprise, multi-site capability | Requires coordination between internal IT and Mission Control, though substantially reduced by the confirmed fully-managed default | Custom enterprise pricing likely, under the confirmed OPEX model | Table 7, 14, 18 findings | Genuinely one of the stronger large-enterprise findings in this profile - real, named, large-scale customer evidence rather than only architectural claims.
Summary
Sector fit | Manufacturing and non-governmental organisations are the best-evidenced sectors in this profile, each backed by a real, named, credible customer (Mikron, SOS Children's Villages respectively); retail/consumer goods and logistics/multi-site operations are also well-evidenced via named customers (Mammut, Altana); financial services and higher education are confirmed as general customer-base sectors without named individual case studies to the same depth. | Table 14 | High for manufacturing, NGOs, retail, and logistics; Medium for the generally-confirmed sectors; Low for sectors with no evidence | The five named case studies together span a genuinely diverse set of sectors - worth highlighting the specific, matching case study directly to any buyer in one of these confirmed sectors.
The five named case studies together span a genuinely diverse set of sectors - worth highlighting the specific, matching case study directly to any buyer in one of these confirmed sectors.
Public evidence sources
21 records- 01EQT Group - Open Systems portfolio page (company history, EQT Mid Market Europe investment) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 02Open Systems - About Us page (400+ hours additional engineer training, Great Place to Work certification) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 03Open Systems - Customer Reviews on Gartner Peer Insights (34 and 27 user ratings respectively, as of Feb 2025, across two review categories) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 04Open Systems - Customer Success Stories (named case studies: KEMET, Mammut, SOS Children's Villages, Mikron, Altana) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 05Open Systems - ISO 27001 Certification page · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 06Open Systems - Mammut and SASE Experience Customer Story (named, quantified: under-two-month deployment) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 07Open Systems - SASE Experience: Mission Control Operations Centre detail (8-minute escalation SLA, Level-3 engineer certification) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 08Open Systems - What is SASE (Secure Access Service Edge)? (Mission Control Experience Delivery, named product list) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 09Open Systems - homepage (SASE Experience overview, follow-the-sun Mission Control support) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 10Open Systems - press release: Customers Give High Ratings to SD-WAN Service From SASE Pioneer Open Systems on Gartner Peer Insights (4.9/5.0 rating, 14 reviews, as of 31 Dec 2020; Gartner Hype Cycle Sample Vendor references) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 11Open Systems - press release: Zero Trust Without the Headaches: Open Systems Launches Managed, Universal SSE · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 1
- 12SDxCentral - What is the Open Systems SASE Platform? (independent trade-press analysis, co-managed model detail) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 2
- 13CB Insights - Compare Open Systems vs Versa Networks (named CEO reference: Daniel Neuhaus; sector breakdown: manufacturing, chemicals, financial services, insurance, higher education, NGOs) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 14CXponent - Open Systems | Managed SASE & SD-WAN Security Solutions (independent vendor-directory profile; dual HQ, ~10,000 locations/180+ countries, named product-line breakdown, sector focus) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 15Cybersecurity Excellence Awards - Open Systems SASE Experience (candidate profile; $100M+ annual revenue, 60,000+ employees among customer base, 180+ countries) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 16Gartner Peer Insights - Open Systems Managed SASE Reviews & Ratings 2026 (verbatim user review excerpts, single-pass engine description, OPEX cost-model reference) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 17Gartner Peer Insights - Open Systems SD-WAN Reviews & Ratings 2026 (verbatim user review excerpt: Mission Control team praise) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 18Jimber - Open Systems vs Jimber: European SASE Compared 2026 (independent, competitor-published comparison; named CEO: Dennis Monner; EQT exit/Swiss Post ownership; named subprocessor partners: Cyolo Security, Avira) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 19PitchBook - Open Systems 2026 Company Profile: Valuation, Investors, Acquisition (260 employees; EQT/Zobito investors; Swiss Post acquisition dated 21 Oct 2024) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 20SASE Experts - Open Systems (independent reseller/consultancy profile; legacy named integrations: McAfee, Avira, Commtouch; Mission Control feature detail) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
- 21Tracxn - Open Systems - 2026 Company Profile, Team, Funding & Competitors (428 employees as of 31 Mar 2026; Post acquisition reference) · verified Wed Jul 22 2026 00:00:00 GMT+0000 (Coordinated Universal Time)tier 3
Profile contract provider-public/1.0.0. Machine-readable record: JSON.