# Short SASE RFP — fictional manufacturing example Fictional manufacturing example. No customer project, supplier response or procurement outcome is represented. Nothing in this demonstration is published to the Opportunity Board. ## Original buyer brief We are a manufacturing company with 15 sites: 10 in the UK and five in Germany. We have 600 users, including 30 remote users. We want a managed SASE solution to replace our existing VPN and protect access to cloud applications. Please provide a proposal and pricing. ## Example buyer decisions and response instructions Example buyer decision: use the existing Entra ID directory for identity, MFA and device posture. Require ZTNA, SWG, CASB, FWaaS and DLP, with logging exported to the existing SIEM. Suppliers must identify unsupported devices and application dependencies. Example buyer decision: protect production continuity with an IT/OT segmentation boundary. Contractor access must be individually approved, time-bound and audited. SASE must not be assumed to replace plant safety controls. Example buyer decision: request regional PoP coverage, availability SLA and latency evidence, plus a failover test. Exact bandwidths and maximum tolerable outage remain to be confirmed by each plant; suppliers must state assumptions separately. Example buyer decision: require a managed service, 24/7 incident support, escalation contacts and a RACI defining policy ownership. Request data residency, retention and sub-processor details for UK and German operations; retention periods remain a buyer decision. Example buyer decision: plan phased migration within six months, with a pilot, approved cutover windows, rollback and training. The dates and acceptance thresholds require buyer confirmation before contract award. Example buyer decision: compare a 36-month contract term in GBP using one pricing table for one-off and recurring charges, licences, total cost, exclusions and exit/data-return terms. This is an illustrative evaluation basis, not a supplier quote. Example evaluation rule: mandatory identity integration, the IT/OT boundary and a rollback plan are pass/fail. Score compliant bids on security fit (30%), resilience (25%), operations (20%), implementation (10%) and total cost (15%). Require dated evidence within the last 12 months, current certificates and expiry dates. Buyers must adapt these example weights and evidence periods. Response format: answer each question by ID with compliance, delivery method, limitations, evidence reference and price impact. Separate confirmed capability from roadmap commitments. These supplier answers have not been provided in this demonstration. ## Identity and private application access SASE-ZTNA-001 Describe how your platform enforces zero trust access to private applications. Evidence requested: Architecture diagram; Policy example; Identity provider integration list Reason: Private application access is a core SASE use case and should be controlled by identity, device and application context rather than broad network access. ## Web, SaaS and threat protection SASE-SWG-001 Describe your secure web gateway, including TLS inspection and URL category coverage. Evidence requested: SWG architecture; TLS inspection approach; Category list Reason: The SWG is the primary control plane for web traffic and must inspect TLS to be effective. ## Branch integration and resilience SASE-SDWAN-001 Describe how SD-WAN integrates with your SSE stack. Evidence requested: Reference architecture; Integration mode list Reason: Tight SD-WAN and SSE integration determines branch user experience and policy consistency. ## Logging and data residency SASE-LOG-001 Which log types are captured and what retention options are available? Evidence requested: Log schema; Retention options Reason: Log coverage and retention drive audit, investigation and regulatory reporting. ## Managed service and responsibilities SASE-SVC-001 Describe your service model, including managed, co-managed and self-managed options. Evidence requested: Service description Reason: The service model defines the split of responsibilities and informs operational cost. ## Migration and acceptance SASE-DEP-001 Describe a typical deployment plan for an estate of our size. Evidence requested: Reference deployment plan Reason: A credible deployment plan reduces project risk and surprises. ## Pricing and contractual terms SASE-COM-001 Describe your pricing model and what is included. Evidence requested: Pricing schedule Reason: Clarity on the pricing model drives like-for-like supplier comparison. ## Supplier evidence SASE-VE-001 Provide your current certifications and expiry dates. Evidence requested: Certification list; Expiry dates Reason: Current certifications support regulated buyer due diligence. ## Bespoke buyer question BUYER-OT-001 How will you revoke a maintenance contractor’s access to a legacy production application during an identity outage without disrupting production or bypassing the IT/OT boundary? Evidence requested: Proposed test procedure, access-revocation behaviour, audit trail and rollback plan ## Still to confirm Site bandwidths, application inventory, outage tolerances, retention periods, acceptance thresholds and approved migration dates. This coverage check does not resolve those decisions or certify technical correctness.