SASE and SD-WAN procurement, from requirement to bids
Build an SD-WAN or SASE RFP and compare vendor responses
ChatGPT can draft an RFP. Netify checks what is missing, rebuilds it against a governed question bank and prepares an anonymous Opportunity Board listing. Publishing unlocks suitable vendors, downloads and comparable bids.
Connected to 30 leading vendors and managed service providers, Netify combines specialist AI with continuously updated market intelligence and years of networking and procurement expertise across healthcare, manufacturing, retail, financial services and other sectors. Get bids. Get pricing. Get vetted responses. Send messages. Request demos. No salesperson involved.
Choose how to start. Every route creates the same private project
- What is an SD-WAN RFP?
- An SD-WAN RFP is a request for proposal that sets out an organisation's sites, underlay circuits, application performance targets, failover, security integration and managed service needs so that SD-WAN vendors and service providers can respond with comparable, priced bids.
- What is a SASE RFP?
- A SASE RFP is a request for proposal for converged networking and security delivered from the cloud: SD-WAN plus ZTNA, SWG, CASB, FWaaS and DLP, with identity, data residency, logging and operating model requirements stated so that SASE vendors can be evaluated on the same criteria.
Netify builds the document from your answers, validates the requirements against a governed question bank, and compares supplier responses side by side after you publish anonymously.
What an SD-WAN or SASE RFP covers
The eight areas below are the sections Netify builds and validates. Each row shows the SD-WAN emphasis, the SASE emphasis and the evidence Netify recommends requesting from suppliers; adapt them to your own procurement rules. Reviewed .
| RFP area | SD-WAN RFP | SASE RFP | Supplier evidence |
|---|---|---|---|
| Organisation and scale | Sites, regions, users per site, growth plans and the procurement route. | Remote and hybrid users, devices, identity provider and data residency by region. | Site list, user counts and regions stated in the RFP; supplier confirms coverage per region. |
| Network architecture | Underlay circuits, WAN topology, hub and cloud on-ramps, application performance targets, QoS and routing. | PoP footprint, cloud on-ramps, traffic steering between SD-WAN and the security edge, private application access. | Reference architecture, PoP list with locations, latency and throughput figures per region. |
| SASE security | Firewall integration, segmentation and how security is applied at the branch. | ZTNA, SWG, CASB, FWaaS, DLP, threat prevention, identity and device posture, logging and SIEM integration. | Capability statement per function, single-vendor or partner delivered, certifications and independent test results. |
| Resilience | Access diversity, failover behaviour, availability targets per site tier and disaster recovery. | PoP redundancy, fail-open or fail-closed policy, control plane availability and regional fallback. | Published SLA, availability history and a description of the last significant incident. |
| Managed service | Service ownership, service desk, change management, monitoring, reporting and co-managed options. | Policy administration, incident response, SOC integration and who owns the security policy day to day. | RACI, escalation path, sample monthly service report and named service management roles. |
| Implementation | Discovery, pilot sites, migration waves, cutover and rollback, dependencies and training. | Identity integration, agent rollout, legacy VPN and proxy retirement, phased policy migration. | Implementation plan with milestones, pilot acceptance criteria and named delivery team. |
| Pricing and contract terms | Pricing model per site and per circuit, hardware, licences, contract term, indexation and exit. | Pricing per user and per function, bundles, licence tiers, overage, term and exit provisions. | Itemised pricing schedule, total cost over the proposed contract term (Netify recommends a three-year basis for comparison) and the assumptions behind it. |
| Supplier evidence | Customer references in comparable sectors, accreditations and financial standing. | Analyst coverage, security certifications, data handling and sub-processor disclosure. | Customer references (Netify recommends at least two, in comparable sectors), certification copies, insurance and the evidence request answered in full. |
Read the SD-WAN and SASE question bank that the builder draws from, or see a finished document: the SASE sample RFP (identity, ZTNA, SWG, CASB, FWaaS and SSE) and the SD-WAN sample RFP (routing, underlay, application performance, failover and managed operations).
SD-WAN and SASE RFP questions answered
What should an SD-WAN RFP include?
An SD-WAN RFP should state the site list and regions, the underlay circuits and WAN topology, application performance and QoS targets, failover and availability requirements, security integration, the managed or co-managed operating model, the implementation and migration plan, the pricing model and contract terms, and the evidence suppliers must attach. Netify's question bank covers each of these areas with supplier questions you can select.
What should a SASE RFP include?
A SASE RFP should cover the user and device estate, identity provider and device posture, the required security functions (ZTNA, SWG, CASB, FWaaS and DLP), SD-WAN or branch connectivity, PoP coverage and data residency, logging and SIEM integration, resilience and fail-open policy, the operating model, implementation phasing, per-user pricing and contract terms, and the certifications and references suppliers must provide.
What is the difference between an RFI and an RFP?
An RFI (request for information) asks suppliers to describe their capabilities so a buyer can learn the market and build a shortlist; it carries no scoring or pricing commitment. An RFP (request for proposal) sets out defined requirements, evaluation criteria and a pricing structure so suppliers return comparable, priced proposals. Netify can produce either from the same project, depending on how far the requirement has been developed.
How should SD-WAN and SASE vendors be evaluated?
Score each supplier against the same weighted criteria: capability fit against the stated requirements, security efficacy, performance and PoP coverage in your regions, resilience and SLA, operating model fit, implementation approach, total cost over the contract term and the quality of evidence provided. Netify grades 30 vendors and service providers on 40 capabilities, and supplier responses to a published RFP land side by side against the questions you asked.
Is the Netify RFP Builder free?
Yes. Building, validating and downloading an SD-WAN or SASE RFP is free for buyers. Publishing is anonymous, pricing returned by suppliers is private to you, and nothing is published without your signature.
Why use Netify after an AI draft?ChatGPT can draft it. Netify makes it procurement-ready.
Open the validation method, factual capabilities and worked example. Last reviewed 2026-08-26.
What the checker actually does
- Checks technical, security, resilience, commercial, implementation, support and response-format coverage.
- Tests whether mandatory requirements, evidence currency, pricing structure and evaluation rules are clear enough for comparable bids.
- Applies healthcare, financial-services, retail and manufacturing considerations when that sector is stated.
- Flags named-provider wording that lacks an outcome-based or “or equivalent” alternative.
- Maps gaps to canonical Netify question IDs; recommendations are never added without buyer approval.
Example AI-generated input
“Create an SD-WAN RFP for 20 sites. Suppliers should describe their solution and provide pricing.”
Example Netify output
Procurement readiness: 9/100. 29 important requirements are missing or unclear. Baseline: incomplete. The live checker lists the exact gaps and governed questions needed to improve it.
Agentic and MCP capability
An approved AI agent can ingest an existing brief, structure stated facts with provenance, assess coverage, retrieve the governed question bank, draft the procurement document and monitor a published project. Netify does not let an agent publish, disclose buyer identity or award a supplier: those actions remain with the buyer.
Methodology and limitations: this is a deterministic coverage assessment, not legal advice or a guarantee of supplier performance. It does not invent unstated requirements. Read the public question bank, machine-readable bank, methodology data and validator data.