{"synthetic":true,"version":"1.0","dateCreated":"2026-09-06","disclosure":"Fictional manufacturing example. No customer project, supplier response or procurement outcome is represented. Nothing in this demonstration is published to the Opportunity Board.","input":"We are a manufacturing company with 15 sites: 10 in the UK and five in Germany. We have 600 users, including 30 remote users. We want a managed SASE solution to replace our existing VPN and protect access to cloud applications. Please provide a proposal and pricing.","buyerDecisions":["Example buyer decision: use the existing Entra ID directory for identity, MFA and device posture. Require ZTNA, SWG, CASB, FWaaS and DLP, with logging exported to the existing SIEM. Suppliers must identify unsupported devices and application dependencies.","Example buyer decision: protect production continuity with an IT/OT segmentation boundary. Contractor access must be individually approved, time-bound and audited. SASE must not be assumed to replace plant safety controls.","Example buyer decision: request regional PoP coverage, availability SLA and latency evidence, plus a failover test. Exact bandwidths and maximum tolerable outage remain to be confirmed by each plant; suppliers must state assumptions separately.","Example buyer decision: require a managed service, 24/7 incident support, escalation contacts and a RACI defining policy ownership. Request data residency, retention and sub-processor details for UK and German operations; retention periods remain a buyer decision.","Example buyer decision: plan phased migration within six months, with a pilot, approved cutover windows, rollback and training. The dates and acceptance thresholds require buyer confirmation before contract award.","Example buyer decision: compare a 36-month contract term in GBP using one pricing table for one-off and recurring charges, licences, total cost, exclusions and exit/data-return terms. This is an illustrative evaluation basis, not a supplier quote.","Example evaluation rule: mandatory identity integration, the IT/OT boundary and a rollback plan are pass/fail. Score compliant bids on security fit (30%), resilience (25%), operations (20%), implementation (10%) and total cost (15%). Require dated evidence within the last 12 months, current certificates and expiry dates. Buyers must adapt these example weights and evidence periods.","Response format: answer each question by ID with compliance, delivery method, limitations, evidence reference and price impact. Separate confirmed capability from roadmap commitments. These supplier answers have not been provided in this demonstration."],"bespokeQuestion":{"question_id":"BUYER-OT-001","question":"How will you revoke a maintenance contractor’s access to a legacy production application during an identity outage without disrupting production or bypassing the IT/OT boundary?","evidence_required":["Proposed test procedure, access-revocation behaviour, audit trail and rollback plan"],"why_it_matters":"This buyer-specific question tests the interaction between access control and production continuity. A product checklist alone cannot settle it."},"methodology":{"validator":"2026.3","questionBank":"sase-question-bank-2026.1"},"initialAssessment":{"assessmentVersion":"2026.3","assessmentKind":"text_coverage","limitations":["Topic detection does not verify technical correctness, measurable acceptance criteria or readiness to issue an RFP.","The legacy score measures text coverage only; overlapping missing checks are not a count of distinct buyer requirements.","A buyer must confirm unresolved decisions and approve publication separately."],"score":20,"label":"Limited topic coverage","wordCount":47,"questionCount":0,"missingRequirementCount":26,"validBaseline":false,"sections":[{"key":"organisation_scale","title":"Organisation and scale","score":100,"covered":["sector or operating context","sites, users or devices","regions or countries"],"missing":[]},{"key":"solution_scope","title":"Solution scope","score":33,"covered":["SASE, SSE or SD-WAN scope"],"missing":["required security components","business outcomes or use cases"]},{"key":"current_estate","title":"Current estate","score":67,"covered":["existing WAN or underlay","cloud, SaaS or application estate"],"missing":["identity, security or operational tooling"]},{"key":"resilience_availability","title":"Resilience and availability","score":0,"covered":[],"missing":["availability or SLA targets","failover or access diversity","performance requirements"]},{"key":"security_identity_data","title":"Security, identity and data","score":0,"covered":[],"missing":["identity and access controls","threat and data controls","logging, compliance or data residency"]},{"key":"operating_model_support","title":"Operating model and support","score":0,"covered":[],"missing":["managed, co-managed or self-managed model","support and service management","roles, reporting or governance"]},{"key":"migration_implementation","title":"Migration and implementation","score":0,"covered":[],"missing":["deployment or migration approach","timeline, phases or milestones","pilot, cutover, rollback or training"]},{"key":"commercial_contractual","title":"Commercial and contractual","score":33,"covered":["pricing or total cost"],"missing":["licensing or contract term","exit, liability or contractual protections"]}],"strengths":["Organisation and scale has broad coverage"],"gaps":["Solution scope: add required security components, business outcomes or use cases","Resilience and availability: add availability or SLA targets, failover or access diversity, performance requirements","Manufacturing: add IT/OT segmentation and industrial security","Manufacturing: add plant, production or warehouse continuity","Security, identity and data: add identity and access controls, threat and data controls, logging, compliance or data residency","Operating model and support: add managed, co-managed or self-managed model, support and service management, roles, reporting or governance","Migration and implementation: add deployment or migration approach, timeline, phases or milestones, pilot, cutover, rollback or training","Commercial and contractual: add licensing or contract term, exit, liability or contractual protections","Ask suppliers for dated evidence, certificates, reports or comparable customer references","Define mandatory requirements, scoring or evaluation weightings","Specify a common response and pricing format so bids can be compared"],"recommendedQuestions":[{"id":"Q-IZ-01","category":"Identity / ZTNA","text":"Describe how your platform enforces zero trust access to private applications, including user, group, device posture and application-level controls.","reason":"Closes a gap in Identity / ZTNA."},{"id":"Q-SC-01","category":"SWG / CASB / DLP","text":"Describe your SWG, CASB and DLP capabilities and how they share a single policy engine.","reason":"Closes a gap in SWG / CASB / DLP."},{"id":"Q-FT-01","category":"FWaaS / Threat","text":"Describe your FWaaS, IPS, anti-malware and sandboxing stack and how consistent policy is applied to branch, roaming and cloud egress.","reason":"Closes a gap in FWaaS / Threat."},{"id":"Q-SD-01","category":"SD-WAN Integration","text":"Describe how your SD-WAN integrates with your SSE stack — single vendor, partnered, or third-party — and where the policy boundary sits.","reason":"Closes a gap in SD-WAN Integration."},{"id":"Q-LS-01","category":"Logging / SIEM","text":"Which log types are captured (access, threat, DLP, admin, audit), at what retention, and how can we export them to our SIEM or cold storage?","reason":"Closes a gap in Logging / SIEM."},{"id":"Q-DR-01","category":"Data Residency","text":"Where is customer data, logs and metadata stored and processed, and which regions can we select for our tenant?","reason":"Closes a gap in Data Residency."},{"id":"Q-SM-01","category":"Service Model","text":"Describe your service model — managed, co-managed or self-managed — and the exact split of responsibilities with the customer.","reason":"Closes a gap in Service Model."},{"id":"Q-DP-01","category":"Deployment","text":"Describe a typical deployment plan for an estate of our size, including pilot, phased rollout and steady-state hand-over.","reason":"Closes a gap in Deployment."}],"sector":{"detected":"manufacturing","label":"Manufacturing","gaps":["Manufacturing: add IT/OT segmentation and industrial security","Manufacturing: add plant, production or warehouse continuity"]},"comparabilityWarnings":["Mandatory and desirable requirements are not clearly separated","Suppliers are not given one common response structure","Pricing is not requested in a common one-off, recurring and total-cost structure","Evidence requests do not state how current the evidence must be"],"vendorNeutralityWarnings":[],"bank":{"version":"2026.1","totalQuestions":386,"extendedQuestions":43}},"documents":{"short":{"text":"# Short SASE RFP — fictional manufacturing example\n\nFictional manufacturing example. No customer project, supplier response or procurement outcome is represented. Nothing in this demonstration is published to the Opportunity Board.\n\n## Original buyer brief\n\nWe are a manufacturing company with 15 sites: 10 in the UK and five in Germany. We have 600 users, including 30 remote users. We want a managed SASE solution to replace our existing VPN and protect access to cloud applications. Please provide a proposal and pricing.\n\n## Example buyer decisions and response instructions\n\nExample buyer decision: use the existing Entra ID directory for identity, MFA and device posture. Require ZTNA, SWG, CASB, FWaaS and DLP, with logging exported to the existing SIEM. Suppliers must identify unsupported devices and application dependencies.\n\nExample buyer decision: protect production continuity with an IT/OT segmentation boundary. Contractor access must be individually approved, time-bound and audited. SASE must not be assumed to replace plant safety controls.\n\nExample buyer decision: request regional PoP coverage, availability SLA and latency evidence, plus a failover test. Exact bandwidths and maximum tolerable outage remain to be confirmed by each plant; suppliers must state assumptions separately.\n\nExample buyer decision: require a managed service, 24/7 incident support, escalation contacts and a RACI defining policy ownership. Request data residency, retention and sub-processor details for UK and German operations; retention periods remain a buyer decision.\n\nExample buyer decision: plan phased migration within six months, with a pilot, approved cutover windows, rollback and training. The dates and acceptance thresholds require buyer confirmation before contract award.\n\nExample buyer decision: compare a 36-month contract term in GBP using one pricing table for one-off and recurring charges, licences, total cost, exclusions and exit/data-return terms. This is an illustrative evaluation basis, not a supplier quote.\n\nExample evaluation rule: mandatory identity integration, the IT/OT boundary and a rollback plan are pass/fail. Score compliant bids on security fit (30%), resilience (25%), operations (20%), implementation (10%) and total cost (15%). Require dated evidence within the last 12 months, current certificates and expiry dates. Buyers must adapt these example weights and evidence periods.\n\nResponse format: answer each question by ID with compliance, delivery method, limitations, evidence reference and price impact. Separate confirmed capability from roadmap commitments. These supplier answers have not been provided in this demonstration.\n\n## Identity and private application access\n\nSASE-ZTNA-001\nDescribe how your platform enforces zero trust access to private applications.\nEvidence requested: Architecture diagram; Policy example; Identity provider integration list\nReason: Private application access is a core SASE use case and should be controlled by identity, device and application context rather than broad network access.\n\n## Web, SaaS and threat protection\n\nSASE-SWG-001\nDescribe your secure web gateway, including TLS inspection and URL category coverage.\nEvidence requested: SWG architecture; TLS inspection approach; Category list\nReason: The SWG is the primary control plane for web traffic and must inspect TLS to be effective.\n\n## Branch integration and resilience\n\nSASE-SDWAN-001\nDescribe how SD-WAN integrates with your SSE stack.\nEvidence requested: Reference architecture; Integration mode list\nReason: Tight SD-WAN and SSE integration determines branch user experience and policy consistency.\n\n## Logging and data residency\n\nSASE-LOG-001\nWhich log types are captured and what retention options are available?\nEvidence requested: Log schema; Retention options\nReason: Log coverage and retention drive audit, investigation and regulatory reporting.\n\n## Managed service and responsibilities\n\nSASE-SVC-001\nDescribe your service model, including managed, co-managed and self-managed options.\nEvidence requested: Service description\nReason: The service model defines the split of responsibilities and informs operational cost.\n\n## Migration and acceptance\n\nSASE-DEP-001\nDescribe a typical deployment plan for an estate of our size.\nEvidence requested: Reference deployment plan\nReason: A credible deployment plan reduces project risk and surprises.\n\n## Pricing and contractual terms\n\nSASE-COM-001\nDescribe your pricing model and what is included.\nEvidence requested: Pricing schedule\nReason: Clarity on the pricing model drives like-for-like supplier comparison.\n\n## Supplier evidence\n\nSASE-VE-001\nProvide your current certifications and expiry dates.\nEvidence requested: Certification list; Expiry dates\nReason: Current certifications support regulated buyer due diligence.\n\n## Bespoke buyer question\n\nBUYER-OT-001\nHow will you revoke a maintenance contractor’s access to a legacy production application during an identity outage without disrupting production or bypassing the IT/OT boundary?\nEvidence requested: Proposed test procedure, access-revocation behaviour, audit trail and rollback plan\n\n## Still to confirm\n\nSite bandwidths, application inventory, outage tolerances, retention periods, acceptance thresholds and approved migration dates. This coverage check does not resolve those decisions or certify technical correctness.","assessment":{"assessmentVersion":"2026.3","assessmentKind":"text_coverage","limitations":["Topic detection does not verify technical correctness, measurable acceptance criteria or readiness to issue an RFP.","The legacy score measures text coverage only; overlapping missing checks are not a count of distinct buyer requirements.","A buyer must confirm unresolved decisions and approve publication separately."],"score":100,"label":"Broad topic coverage","wordCount":734,"questionCount":9,"missingRequirementCount":0,"validBaseline":true,"sections":[{"key":"organisation_scale","title":"Organisation and scale","score":100,"covered":["sector or operating context","sites, users or devices","regions or countries"],"missing":[]},{"key":"solution_scope","title":"Solution scope","score":100,"covered":["SASE, SSE or SD-WAN scope","required security components","business outcomes or use cases"],"missing":[]},{"key":"current_estate","title":"Current estate","score":100,"covered":["existing WAN or underlay","cloud, SaaS or application estate","identity, security or operational tooling"],"missing":[]},{"key":"resilience_availability","title":"Resilience and availability","score":100,"covered":["availability or SLA targets","failover or access diversity","performance requirements"],"missing":[]},{"key":"security_identity_data","title":"Security, identity and data","score":100,"covered":["identity and access controls","threat and data controls","logging, compliance or data residency"],"missing":[]},{"key":"operating_model_support","title":"Operating model and support","score":100,"covered":["managed, co-managed or self-managed model","support and service management","roles, reporting or governance"],"missing":[]},{"key":"migration_implementation","title":"Migration and implementation","score":100,"covered":["deployment or migration approach","timeline, phases or milestones","pilot, cutover, rollback or training"],"missing":[]},{"key":"commercial_contractual","title":"Commercial and contractual","score":100,"covered":["pricing or total cost","licensing or contract term","exit, liability or contractual protections"],"missing":[]}],"strengths":["Buyer context and solution scope are stated","Suppliers are asked for supporting evidence","Evaluation or mandatory criteria are defined","A comparable supplier response format is specified","Organisation and scale has broad coverage","Solution scope has broad coverage","Current estate has broad coverage"],"gaps":[],"recommendedQuestions":[],"sector":{"detected":"manufacturing","label":"Manufacturing","gaps":[]},"comparabilityWarnings":[],"vendorNeutralityWarnings":[],"bank":{"version":"2026.1","totalQuestions":386,"extendedQuestions":43}}},"detailed":{"text":"# Detailed SASE RFP — fictional manufacturing example\n\nFictional manufacturing example. No customer project, supplier response or procurement outcome is represented. Nothing in this demonstration is published to the Opportunity Board.\n\n## Original buyer brief\n\nWe are a manufacturing company with 15 sites: 10 in the UK and five in Germany. We have 600 users, including 30 remote users. We want a managed SASE solution to replace our existing VPN and protect access to cloud applications. Please provide a proposal and pricing.\n\n## Example buyer decisions and response instructions\n\nExample buyer decision: use the existing Entra ID directory for identity, MFA and device posture. Require ZTNA, SWG, CASB, FWaaS and DLP, with logging exported to the existing SIEM. Suppliers must identify unsupported devices and application dependencies.\n\nExample buyer decision: protect production continuity with an IT/OT segmentation boundary. Contractor access must be individually approved, time-bound and audited. SASE must not be assumed to replace plant safety controls.\n\nExample buyer decision: request regional PoP coverage, availability SLA and latency evidence, plus a failover test. Exact bandwidths and maximum tolerable outage remain to be confirmed by each plant; suppliers must state assumptions separately.\n\nExample buyer decision: require a managed service, 24/7 incident support, escalation contacts and a RACI defining policy ownership. Request data residency, retention and sub-processor details for UK and German operations; retention periods remain a buyer decision.\n\nExample buyer decision: plan phased migration within six months, with a pilot, approved cutover windows, rollback and training. The dates and acceptance thresholds require buyer confirmation before contract award.\n\nExample buyer decision: compare a 36-month contract term in GBP using one pricing table for one-off and recurring charges, licences, total cost, exclusions and exit/data-return terms. This is an illustrative evaluation basis, not a supplier quote.\n\nExample evaluation rule: mandatory identity integration, the IT/OT boundary and a rollback plan are pass/fail. Score compliant bids on security fit (30%), resilience (25%), operations (20%), implementation (10%) and total cost (15%). Require dated evidence within the last 12 months, current certificates and expiry dates. Buyers must adapt these example weights and evidence periods.\n\nResponse format: answer each question by ID with compliance, delivery method, limitations, evidence reference and price impact. Separate confirmed capability from roadmap commitments. These supplier answers have not been provided in this demonstration.\n\n## Identity and private application access\n\nSASE-ZTNA-001\nDescribe how your platform enforces zero trust access to private applications.\nEvidence requested: Architecture diagram; Policy example; Identity provider integration list\nReason: Private application access is a core SASE use case and should be controlled by identity, device and application context rather than broad network access.\n\nSASE-ZTNA-002\nWhich identity providers do you support natively, and which protocols (SAML, OIDC, SCIM)?\nEvidence requested: Supported IdP list; Protocol matrix\nReason: Native IdP integration determines whether identity, group and lifecycle data drive access decisions in real time.\n\nSASE-ZTNA-003\nHow is device posture evaluated and used in access decisions?\nEvidence requested: Device posture signal list; Sample posture-based policy\nReason: Device posture lets buyers enforce different access rules for managed, unmanaged and high-risk devices.\n\nSASE-ZTNA-004\nDescribe step-up authentication and continuous session validation.\nEvidence requested: Step-up trigger list; Session validation cadence\nReason: Continuous validation reduces the risk of stale sessions being used after the risk context changes.\n\nSASE-ZTNA-005\nDescribe how third-party and contractor access is managed.\nEvidence requested: Third-party access workflow\nReason: Third-party access is a common breach vector and needs tight, audited control.\n\n## Web, SaaS and threat protection\n\nSASE-SWG-001\nDescribe your secure web gateway, including TLS inspection and URL category coverage.\nEvidence requested: SWG architecture; TLS inspection approach; Category list\nReason: The SWG is the primary control plane for web traffic and must inspect TLS to be effective.\n\nSASE-SWG-002\nDescribe browser-based isolation options and use cases.\nEvidence requested: Isolation architecture\nReason: Isolation is a useful control for risky categories without blocking access.\n\nSASE-CASB-001\nDescribe your inline and API-based CASB coverage for sanctioned and shadow SaaS.\nEvidence requested: List of API-integrated SaaS; Inline vs API coverage matrix\nReason: CASB visibility is needed to control data movement to SaaS and to detect shadow SaaS use.\n\nSASE-DLP-001\nDescribe your DLP capabilities, policy templates and incident workflow.\nEvidence requested: Sample DLP policy; Incident workflow; Template list\nReason: DLP is the primary control for preventing accidental and malicious data egress and must be content-aware.\n\nSASE-DLP-002\nHow is policy kept consistent across managed and unmanaged devices?\nEvidence requested: Unmanaged device coverage approach\nReason: Unmanaged devices are a common data egress channel and need consistent controls.\n\nSASE-FW-001\nDescribe your cloud-delivered firewall, including layer-7 application controls.\nEvidence requested: FWaaS architecture; Layer-7 application list\nReason: FWaaS replaces branch firewalls and must provide consistent layer-7 controls.\n\nSASE-IPS-001\nDescribe your IPS, anti-malware and sandboxing stack and update frequency.\nEvidence requested: Signature update cadence; Sandbox file type list; Threat intel sources\nReason: Threat protection effectiveness depends on inline inspection and timely intelligence.\n\nSASE-FW-002\nHow is policy kept consistent across branch, roaming and cloud egress traffic?\nEvidence requested: Unified policy diagram\nReason: Inconsistent policy planes create gaps and operational overhead.\n\nSASE-FW-003\nDescribe DNS-layer security and its integration with the rest of the stack.\nEvidence requested: DNS security policy example\nReason: DNS-layer controls catch threats early and protect off-network devices.\n\n## Branch integration and resilience\n\nSASE-SDWAN-001\nDescribe how SD-WAN integrates with your SSE stack.\nEvidence requested: Reference architecture; Integration mode list\nReason: Tight SD-WAN and SSE integration determines branch user experience and policy consistency.\n\nSASE-SDWAN-002\nHow are SASE PoPs selected for each branch and how is performance measured?\nEvidence requested: PoP map; Latency expectations; Telemetry samples\nReason: PoP selection drives branch latency and user experience.\n\nSASE-SDWAN-003\nDescribe link failover behaviour, including 4G/5G or LTE failover.\nEvidence requested: Failover decision tree; Convergence times\nReason: Failover behaviour determines store, plant and clinic uptime during link events.\n\nSASE-SDWAN-004\nDescribe direct internet breakout behaviour at branches.\nEvidence requested: Breakout policy example; Trust model\nReason: Local breakout reduces backhaul cost but must keep security policy consistent.\n\nSASE-SDWAN-005\nDescribe segmentation options for OT or sensitive networks at branch and plant sites.\nEvidence requested: Segmentation reference design\nReason: Segmentation between OT and IT is essential in industrial environments.\n\n## Logging and data residency\n\nSASE-LOG-001\nWhich log types are captured and what retention options are available?\nEvidence requested: Log schema; Retention options\nReason: Log coverage and retention drive audit, investigation and regulatory reporting.\n\nSASE-LOG-002\nHow can logs be exported to our SIEM or storage?\nEvidence requested: List of SIEM integrations; Sample export\nReason: Buyers need logs in their own SIEM for correlation and long-term retention.\n\nSASE-LOG-003\nHow are administrative actions audited?\nEvidence requested: Admin audit log sample\nReason: Admin audit trails are required for regulatory and forensic purposes.\n\nSASE-LOG-004\nHow are user-experience metrics collected and shared?\nEvidence requested: UX telemetry sample\nReason: UX telemetry helps prove SASE delivers a better user experience.\n\nSASE-DR-001\nWhere are customer data, logs and metadata stored and processed?\nEvidence requested: Data flow diagram; Region list\nReason: Data residency drives regulatory compliance and contractual obligations.\n\nSASE-DR-002\nList your sub-processors and their locations.\nEvidence requested: Sub-processor list with regions\nReason: Sub-processor disclosure is required for many regulated buyers.\n\nSASE-DR-003\nDescribe support access controls and the regions from which support operates.\nEvidence requested: Support access model\nReason: Support access can introduce cross-border data exposure if not controlled.\n\nSASE-DR-004\nDescribe support for customer-managed encryption keys.\nEvidence requested: CMK approach\nReason: CMK can be a requirement for highly regulated workloads.\n\n## Managed service and responsibilities\n\nSASE-SVC-001\nDescribe your service model, including managed, co-managed and self-managed options.\nEvidence requested: Service description\nReason: The service model defines the split of responsibilities and informs operational cost.\n\nSASE-SVC-002\nWhat SLAs apply to support response, restoration and change requests?\nEvidence requested: SLA matrix; Credit regime\nReason: Operational SLAs matter more than platform availability for day-to-day experience.\n\nSASE-SVC-003\nHow are service reviews structured and how often do they occur?\nEvidence requested: Sample monthly service report\nReason: Regular reviews keep the service aligned with buyer priorities.\n\nSASE-SVC-004\nDescribe escalation paths, including out-of-hours.\nEvidence requested: Escalation matrix\nReason: Escalation matters most when incidents occur outside business hours.\n\n## Migration and acceptance\n\nSASE-DEP-001\nDescribe a typical deployment plan for an estate of our size.\nEvidence requested: Reference deployment plan\nReason: A credible deployment plan reduces project risk and surprises.\n\nSASE-DEP-002\nHow is configuration automated for sites, users and policy?\nEvidence requested: Automation tooling description\nReason: Automation drives rollout speed and consistency across multi-site estates.\n\nSASE-DEP-003\nHow are changes tested and rolled back?\nEvidence requested: Test plan template; Rollback runbook\nReason: Tested change and rollback procedures reduce outage risk.\n\nSASE-DEP-004\nHow are user agents and clients distributed and updated?\nEvidence requested: Agent lifecycle approach\nReason: Agent updates impact user experience and security posture.\n\n## Pricing and contractual terms\n\nSASE-COM-001\nDescribe your pricing model and what is included.\nEvidence requested: Pricing schedule\nReason: Clarity on the pricing model drives like-for-like supplier comparison.\n\nSASE-COM-002\nProvide a worked example for our user and site count.\nEvidence requested: Worked example with assumptions\nReason: Worked examples expose hidden charges and reveal true unit cost.\n\nSASE-COM-003\nHow are growth and reductions handled within the term?\nEvidence requested: Flex terms\nReason: Flex terms determine commercial exposure if estate size changes.\n\nSASE-COM-004\nList all items priced separately, including professional services.\nEvidence requested: Add-on list\nReason: Add-ons drive total cost of ownership and must be transparent.\n\n## Supplier evidence\n\nSASE-VE-001\nProvide your current certifications and expiry dates.\nEvidence requested: Certification list; Expiry dates\nReason: Current certifications support regulated buyer due diligence.\n\nSASE-VE-002\nShare recent independent test results relevant to SASE.\nEvidence requested: Test report references\nReason: Independent test results reduce reliance on vendor claims.\n\nSASE-VE-003\nProvide customer references in our sector.\nEvidence requested: Reference list\nReason: Sector-specific references increase confidence in fit.\n\nSASE-VE-004\nProvide details of any recent security incidents and your handling of them.\nEvidence requested: Incident summary\nReason: Incident handling history shows operational maturity.\n\n## Bespoke buyer question\n\nBUYER-OT-001\nHow will you revoke a maintenance contractor’s access to a legacy production application during an identity outage without disrupting production or bypassing the IT/OT boundary?\nEvidence requested: Proposed test procedure, access-revocation behaviour, audit trail and rollback plan\n\n## Still to confirm\n\nSite bandwidths, application inventory, outage tolerances, retention periods, acceptance thresholds and approved migration dates. This coverage check does not resolve those decisions or certify technical correctness.","assessment":{"assessmentVersion":"2026.3","assessmentKind":"text_coverage","limitations":["Topic detection does not verify technical correctness, measurable acceptance criteria or readiness to issue an RFP.","The legacy score measures text coverage only; overlapping missing checks are not a count of distinct buyer requirements.","A buyer must confirm unresolved decisions and approve publication separately."],"score":100,"label":"Broad topic coverage","wordCount":1698,"questionCount":40,"missingRequirementCount":0,"validBaseline":true,"sections":[{"key":"organisation_scale","title":"Organisation and scale","score":100,"covered":["sector or operating context","sites, users or devices","regions or countries"],"missing":[]},{"key":"solution_scope","title":"Solution scope","score":100,"covered":["SASE, SSE or SD-WAN scope","required security components","business outcomes or use cases"],"missing":[]},{"key":"current_estate","title":"Current estate","score":100,"covered":["existing WAN or underlay","cloud, SaaS or application estate","identity, security or operational tooling"],"missing":[]},{"key":"resilience_availability","title":"Resilience and availability","score":100,"covered":["availability or SLA targets","failover or access diversity","performance requirements"],"missing":[]},{"key":"security_identity_data","title":"Security, identity and data","score":100,"covered":["identity and access controls","threat and data controls","logging, compliance or data residency"],"missing":[]},{"key":"operating_model_support","title":"Operating model and support","score":100,"covered":["managed, co-managed or self-managed model","support and service management","roles, reporting or governance"],"missing":[]},{"key":"migration_implementation","title":"Migration and implementation","score":100,"covered":["deployment or migration approach","timeline, phases or milestones","pilot, cutover, rollback or training"],"missing":[]},{"key":"commercial_contractual","title":"Commercial and contractual","score":100,"covered":["pricing or total cost","licensing or contract term","exit, liability or contractual protections"],"missing":[]}],"strengths":["Buyer context and solution scope are stated","Suppliers are asked for supporting evidence","Evaluation or mandatory criteria are defined","A comparable supplier response format is specified","Organisation and scale has broad coverage","Solution scope has broad coverage","Current estate has broad coverage"],"gaps":[],"recommendedQuestions":[],"sector":{"detected":"manufacturing","label":"Manufacturing","gaps":[]},"comparabilityWarnings":[],"vendorNeutralityWarnings":[],"bank":{"version":"2026.1","totalQuestions":386,"extendedQuestions":43}}}}}