A SASE RFP needs to test far more than which vendor ticks the most product boxes. In our view, it should genuinely test business outcomes, current network and application dependencies, and supplier accountability, alongside the full technical stack: SASE architecture and SD-WAN, global backbone, ZTNA, endpoint and third-party access, secure web gateway, CASB, DLP, FWaaS, threat prevention, logging and policy governance, resilience, implementation, managed service, compliance, pricing, and exit.
That's a lot to cover, and product-support questions alone genuinely aren't enough to get you there. Each material requirement should ask for:
The offered component itself,
The licence it sits under,
Any limitation or third-party dependency,
The evidence behind the claim.
Buyers should also flag upfront which of these claims actually need a proof test, rather than just taking a supplier at their word.
We organise all of this into 20 procurement pillars and 120 core supplier questions at Netify, with optional overlays for the likes of manufacturing, healthcare, retail and financial services depending on the sector you're buying into. The same framework can be filtered for an SD-WAN-only, SSE-only, full SASE, managed SASE or phased procurement too, so suppliers only get scored against the requirements that are actually relevant to the intended service, rather than being marked down for gaps that were never in scope to begin with.