Worked example · Created 6 September 2026
A SASE RFP, from first brief to supplier questions.
Follow a manufacturer with 15 sites and 600 users. See what Netify’s checker flags, which decisions a buyer still needs to make, and how Short and Detailed RFPs request evidence.
Fictional manufacturing example. No customer project, supplier response or procurement outcome is represented. Nothing in this demonstration is published to the Opportunity Board. Read and download both examples freely. They are assembled from Netify’s question bank and the explicit example decisions below; the checker does not invent those decisions.
1. The original buyer brief
We are a manufacturing company with 15 sites: 10 in the UK and five in Germany. We have 600 users, including 30 remote users. We want a managed SASE solution to replace our existing VPN and protect access to cloud applications. Please provide a proposal and pricing.
This is useful starting context. It leaves important security, operational and procurement decisions unstated.
2. What the actual checker finds
The production checker assessed the exact brief above. Confirm the following information before developing it into supplier instructions.
This is a deterministic text-coverage check. Some checks overlap. Mentioning a topic can satisfy a check without specifying an adequate design or measurable target. The score is not certification that an RFP is ready to issue.
- Solution scope: add required security components, business outcomes or use cases
- Resilience and availability: add availability or SLA targets, failover or access diversity, performance requirements
- Manufacturing: add IT/OT segmentation and industrial security
- Manufacturing: add plant, production or warehouse continuity
- Security, identity and data: add identity and access controls, threat and data controls, logging, compliance or data residency
- Operating model and support: add managed, co-managed or self-managed model, support and service management, roles, reporting or governance
- Migration and implementation: add deployment or migration approach, timeline, phases or milestones, pilot, cutover, rollback or training
- Commercial and contractual: add licensing or contract term, exit, liability or contractual protections
- Ask suppliers for dated evidence, certificates, reports or comparable customer references
- Define mandatory requirements, scoring or evaluation weightings
- Specify a common response and pricing format so bids can be compared
All section checks and comparison warnings
Organisation and scale
Not detected: No missing topic checks.
Solution scope
Not detected: required security components; business outcomes or use cases.
Current estate
Not detected: identity, security or operational tooling.
Resilience and availability
Not detected: availability or SLA targets; failover or access diversity; performance requirements.
Security, identity and data
Not detected: identity and access controls; threat and data controls; logging, compliance or data residency.
Operating model and support
Not detected: managed, co-managed or self-managed model; support and service management; roles, reporting or governance.
Migration and implementation
Not detected: deployment or migration approach; timeline, phases or milestones; pilot, cutover, rollback or training.
Commercial and contractual
Not detected: licensing or contract term; exit, liability or contractual protections.
- Mandatory and desirable requirements are not clearly separated
- Suppliers are not given one common response structure
- Pricing is not requested in a common one-off, recurring and total-cost structure
- Evidence requests do not state how current the evidence must be
3. Decisions supplied by the example buyer
These additions are illustrative choices, not facts extracted from the original brief. A real buyer must confirm their own requirements.
- Example buyer decision: use the existing Entra ID directory for identity, MFA and device posture. Require ZTNA, SWG, CASB, FWaaS and DLP, with logging exported to the existing SIEM. Suppliers must identify unsupported devices and application dependencies.
- Example buyer decision: protect production continuity with an IT/OT segmentation boundary. Contractor access must be individually approved, time-bound and audited. SASE must not be assumed to replace plant safety controls.
- Example buyer decision: request regional PoP coverage, availability SLA and latency evidence, plus a failover test. Exact bandwidths and maximum tolerable outage remain to be confirmed by each plant; suppliers must state assumptions separately.
- Example buyer decision: require a managed service, 24/7 incident support, escalation contacts and a RACI defining policy ownership. Request data residency, retention and sub-processor details for UK and German operations; retention periods remain a buyer decision.
- Example buyer decision: plan phased migration within six months, with a pilot, approved cutover windows, rollback and training. The dates and acceptance thresholds require buyer confirmation before contract award.
- Example buyer decision: compare a 36-month contract term in GBP using one pricing table for one-off and recurring charges, licences, total cost, exclusions and exit/data-return terms. This is an illustrative evaluation basis, not a supplier quote.
- Example evaluation rule: mandatory identity integration, the IT/OT boundary and a rollback plan are pass/fail. Score compliant bids on security fit (30%), resilience (25%), operations (20%), implementation (10%) and total cost (15%). Require dated evidence within the last 12 months, current certificates and expiry dates. Buyers must adapt these example weights and evidence periods.
- Response format: answer each question by ID with compliance, delivery method, limitations, evidence reference and price impact. Separate confirmed capability from roadmap commitments. These supplier answers have not been provided in this demonstration.
4. Inspect the resulting RFPs
The Short example selects one bank question per area. The Detailed example includes all 43 extended SASE questions. Both retain the same buyer context, decisions and bespoke question. These are example selections; you control the questions and depth in your own project.
Short SASE RFP
Includes the original brief and all example buyer decisions above. The expected topics are covered by these example questions and decisions. Technical adequacy and the open decisions below still require buyer review.
Download the complete Short example (text)Identity and private application access
Describe how your platform enforces zero trust access to private applications.
Evidence: Architecture diagram; Policy example; Identity provider integration list.
Why it matters: Private application access is a core SASE use case and should be controlled by identity, device and application context rather than broad network access.
Question bank reference: SASE-ZTNA-001
Web, SaaS and threat protection
Describe your secure web gateway, including TLS inspection and URL category coverage.
Evidence: SWG architecture; TLS inspection approach; Category list.
Why it matters: The SWG is the primary control plane for web traffic and must inspect TLS to be effective.
Question bank reference: SASE-SWG-001
Branch integration and resilience
Describe how SD-WAN integrates with your SSE stack.
Evidence: Reference architecture; Integration mode list.
Why it matters: Tight SD-WAN and SSE integration determines branch user experience and policy consistency.
Question bank reference: SASE-SDWAN-001
Logging and data residency
Which log types are captured and what retention options are available?
Evidence: Log schema; Retention options.
Why it matters: Log coverage and retention drive audit, investigation and regulatory reporting.
Question bank reference: SASE-LOG-001
Managed service and responsibilities
Describe your service model, including managed, co-managed and self-managed options.
Evidence: Service description.
Why it matters: The service model defines the split of responsibilities and informs operational cost.
Question bank reference: SASE-SVC-001
Migration and acceptance
Describe a typical deployment plan for an estate of our size.
Evidence: Reference deployment plan.
Why it matters: A credible deployment plan reduces project risk and surprises.
Question bank reference: SASE-DEP-001
Pricing and contractual terms
Describe your pricing model and what is included.
Evidence: Pricing schedule.
Why it matters: Clarity on the pricing model drives like-for-like supplier comparison.
Question bank reference: SASE-COM-001
Supplier evidence
Provide your current certifications and expiry dates.
Evidence: Certification list; Expiry dates.
Why it matters: Current certifications support regulated buyer due diligence.
Question bank reference: SASE-VE-001
Bespoke buyer question
How will you revoke a maintenance contractor’s access to a legacy production application during an identity outage without disrupting production or bypassing the IT/OT boundary?
Evidence: Proposed test procedure, access-revocation behaviour, audit trail and rollback plan.
This buyer-specific question tests the interaction between access control and production continuity. A product checklist alone cannot settle it.
Buyer reference: BUYER-OT-001
Still to confirm: site bandwidths, application inventory, outage tolerances, retention periods, acceptance thresholds and approved migration dates. No supplier capabilities or prices have been verified.
Detailed SASE RFP
Includes the original brief and all example buyer decisions above. The expected topics are covered by these example questions and decisions. Technical adequacy and the open decisions below still require buyer review.
Download the complete Detailed example (text)Identity and private application access
Describe how your platform enforces zero trust access to private applications.
Evidence: Architecture diagram; Policy example; Identity provider integration list.
Why it matters: Private application access is a core SASE use case and should be controlled by identity, device and application context rather than broad network access.
Question bank reference: SASE-ZTNA-001
Which identity providers do you support natively, and which protocols (SAML, OIDC, SCIM)?
Evidence: Supported IdP list; Protocol matrix.
Why it matters: Native IdP integration determines whether identity, group and lifecycle data drive access decisions in real time.
Question bank reference: SASE-ZTNA-002
How is device posture evaluated and used in access decisions?
Evidence: Device posture signal list; Sample posture-based policy.
Why it matters: Device posture lets buyers enforce different access rules for managed, unmanaged and high-risk devices.
Question bank reference: SASE-ZTNA-003
Describe step-up authentication and continuous session validation.
Evidence: Step-up trigger list; Session validation cadence.
Why it matters: Continuous validation reduces the risk of stale sessions being used after the risk context changes.
Question bank reference: SASE-ZTNA-004
Describe how third-party and contractor access is managed.
Evidence: Third-party access workflow.
Why it matters: Third-party access is a common breach vector and needs tight, audited control.
Question bank reference: SASE-ZTNA-005
Web, SaaS and threat protection
Describe your secure web gateway, including TLS inspection and URL category coverage.
Evidence: SWG architecture; TLS inspection approach; Category list.
Why it matters: The SWG is the primary control plane for web traffic and must inspect TLS to be effective.
Question bank reference: SASE-SWG-001
Describe browser-based isolation options and use cases.
Evidence: Isolation architecture.
Why it matters: Isolation is a useful control for risky categories without blocking access.
Question bank reference: SASE-SWG-002
Describe your inline and API-based CASB coverage for sanctioned and shadow SaaS.
Evidence: List of API-integrated SaaS; Inline vs API coverage matrix.
Why it matters: CASB visibility is needed to control data movement to SaaS and to detect shadow SaaS use.
Question bank reference: SASE-CASB-001
Describe your DLP capabilities, policy templates and incident workflow.
Evidence: Sample DLP policy; Incident workflow; Template list.
Why it matters: DLP is the primary control for preventing accidental and malicious data egress and must be content-aware.
Question bank reference: SASE-DLP-001
How is policy kept consistent across managed and unmanaged devices?
Evidence: Unmanaged device coverage approach.
Why it matters: Unmanaged devices are a common data egress channel and need consistent controls.
Question bank reference: SASE-DLP-002
Describe your cloud-delivered firewall, including layer-7 application controls.
Evidence: FWaaS architecture; Layer-7 application list.
Why it matters: FWaaS replaces branch firewalls and must provide consistent layer-7 controls.
Question bank reference: SASE-FW-001
Describe your IPS, anti-malware and sandboxing stack and update frequency.
Evidence: Signature update cadence; Sandbox file type list; Threat intel sources.
Why it matters: Threat protection effectiveness depends on inline inspection and timely intelligence.
Question bank reference: SASE-IPS-001
How is policy kept consistent across branch, roaming and cloud egress traffic?
Evidence: Unified policy diagram.
Why it matters: Inconsistent policy planes create gaps and operational overhead.
Question bank reference: SASE-FW-002
Describe DNS-layer security and its integration with the rest of the stack.
Evidence: DNS security policy example.
Why it matters: DNS-layer controls catch threats early and protect off-network devices.
Question bank reference: SASE-FW-003
Branch integration and resilience
Describe how SD-WAN integrates with your SSE stack.
Evidence: Reference architecture; Integration mode list.
Why it matters: Tight SD-WAN and SSE integration determines branch user experience and policy consistency.
Question bank reference: SASE-SDWAN-001
How are SASE PoPs selected for each branch and how is performance measured?
Evidence: PoP map; Latency expectations; Telemetry samples.
Why it matters: PoP selection drives branch latency and user experience.
Question bank reference: SASE-SDWAN-002
Describe link failover behaviour, including 4G/5G or LTE failover.
Evidence: Failover decision tree; Convergence times.
Why it matters: Failover behaviour determines store, plant and clinic uptime during link events.
Question bank reference: SASE-SDWAN-003
Describe direct internet breakout behaviour at branches.
Evidence: Breakout policy example; Trust model.
Why it matters: Local breakout reduces backhaul cost but must keep security policy consistent.
Question bank reference: SASE-SDWAN-004
Describe segmentation options for OT or sensitive networks at branch and plant sites.
Evidence: Segmentation reference design.
Why it matters: Segmentation between OT and IT is essential in industrial environments.
Question bank reference: SASE-SDWAN-005
Logging and data residency
Which log types are captured and what retention options are available?
Evidence: Log schema; Retention options.
Why it matters: Log coverage and retention drive audit, investigation and regulatory reporting.
Question bank reference: SASE-LOG-001
How can logs be exported to our SIEM or storage?
Evidence: List of SIEM integrations; Sample export.
Why it matters: Buyers need logs in their own SIEM for correlation and long-term retention.
Question bank reference: SASE-LOG-002
How are administrative actions audited?
Evidence: Admin audit log sample.
Why it matters: Admin audit trails are required for regulatory and forensic purposes.
Question bank reference: SASE-LOG-003
How are user-experience metrics collected and shared?
Evidence: UX telemetry sample.
Why it matters: UX telemetry helps prove SASE delivers a better user experience.
Question bank reference: SASE-LOG-004
Where are customer data, logs and metadata stored and processed?
Evidence: Data flow diagram; Region list.
Why it matters: Data residency drives regulatory compliance and contractual obligations.
Question bank reference: SASE-DR-001
List your sub-processors and their locations.
Evidence: Sub-processor list with regions.
Why it matters: Sub-processor disclosure is required for many regulated buyers.
Question bank reference: SASE-DR-002
Describe support access controls and the regions from which support operates.
Evidence: Support access model.
Why it matters: Support access can introduce cross-border data exposure if not controlled.
Question bank reference: SASE-DR-003
Describe support for customer-managed encryption keys.
Evidence: CMK approach.
Why it matters: CMK can be a requirement for highly regulated workloads.
Question bank reference: SASE-DR-004
Managed service and responsibilities
Describe your service model, including managed, co-managed and self-managed options.
Evidence: Service description.
Why it matters: The service model defines the split of responsibilities and informs operational cost.
Question bank reference: SASE-SVC-001
What SLAs apply to support response, restoration and change requests?
Evidence: SLA matrix; Credit regime.
Why it matters: Operational SLAs matter more than platform availability for day-to-day experience.
Question bank reference: SASE-SVC-002
How are service reviews structured and how often do they occur?
Evidence: Sample monthly service report.
Why it matters: Regular reviews keep the service aligned with buyer priorities.
Question bank reference: SASE-SVC-003
Describe escalation paths, including out-of-hours.
Evidence: Escalation matrix.
Why it matters: Escalation matters most when incidents occur outside business hours.
Question bank reference: SASE-SVC-004
Migration and acceptance
Describe a typical deployment plan for an estate of our size.
Evidence: Reference deployment plan.
Why it matters: A credible deployment plan reduces project risk and surprises.
Question bank reference: SASE-DEP-001
How is configuration automated for sites, users and policy?
Evidence: Automation tooling description.
Why it matters: Automation drives rollout speed and consistency across multi-site estates.
Question bank reference: SASE-DEP-002
How are changes tested and rolled back?
Evidence: Test plan template; Rollback runbook.
Why it matters: Tested change and rollback procedures reduce outage risk.
Question bank reference: SASE-DEP-003
How are user agents and clients distributed and updated?
Evidence: Agent lifecycle approach.
Why it matters: Agent updates impact user experience and security posture.
Question bank reference: SASE-DEP-004
Pricing and contractual terms
Describe your pricing model and what is included.
Evidence: Pricing schedule.
Why it matters: Clarity on the pricing model drives like-for-like supplier comparison.
Question bank reference: SASE-COM-001
Provide a worked example for our user and site count.
Evidence: Worked example with assumptions.
Why it matters: Worked examples expose hidden charges and reveal true unit cost.
Question bank reference: SASE-COM-002
How are growth and reductions handled within the term?
Evidence: Flex terms.
Why it matters: Flex terms determine commercial exposure if estate size changes.
Question bank reference: SASE-COM-003
List all items priced separately, including professional services.
Evidence: Add-on list.
Why it matters: Add-ons drive total cost of ownership and must be transparent.
Question bank reference: SASE-COM-004
Supplier evidence
Provide your current certifications and expiry dates.
Evidence: Certification list; Expiry dates.
Why it matters: Current certifications support regulated buyer due diligence.
Question bank reference: SASE-VE-001
Share recent independent test results relevant to SASE.
Evidence: Test report references.
Why it matters: Independent test results reduce reliance on vendor claims.
Question bank reference: SASE-VE-002
Provide customer references in our sector.
Evidence: Reference list.
Why it matters: Sector-specific references increase confidence in fit.
Question bank reference: SASE-VE-003
Provide details of any recent security incidents and your handling of them.
Evidence: Incident summary.
Why it matters: Incident handling history shows operational maturity.
Question bank reference: SASE-VE-004
Bespoke buyer question
How will you revoke a maintenance contractor’s access to a legacy production application during an identity outage without disrupting production or bypassing the IT/OT boundary?
Evidence: Proposed test procedure, access-revocation behaviour, audit trail and rollback plan.
This buyer-specific question tests the interaction between access control and production continuity. A product checklist alone cannot settle it.
Buyer reference: BUYER-OT-001
Still to confirm: site bandwidths, application inventory, outage tolerances, retention periods, acceptance thresholds and approved migration dates. No supplier capabilities or prices have been verified.
Create your own SASE project
Build a Short or Detailed RFP, bring your own RFP or RFI, or start with a basic statement of requirements. Add your own questions, then review the anonymous notice and verify your work email and company before publishing to the Opportunity Board.
Publication records your requirement for supplier discovery as participation develops. It does not guarantee responses, quotations or an award. You approve publication; reading this example creates no project.