NNetify

Netify SASE & SD-WAN Procurement Framework

The Living SASE & SD-WAN RFP Template

A continuously updated, vendor-neutral procurement framework for specifying requirements, collecting evidence and comparing SASE and SD-WAN vendors and managed service providers.

Use the complete template on this page as it stands, or turn it into a living Request for Proposal tailored to your organisation, sites, users, applications, security obligations and operating model. From there, Netify can identify relevant vendors and providers, publish an anonymous opportunity to the market, and collect structured technical and commercial responses for side-by-side evaluation.

Your project stays private until you choose to publish it. A public opportunity can be listed anonymously, with you controlling when your identity is disclosed.

How to use this living template

Not every buyer needs all 120 questions, and sending the full set regardless of what you're actually procuring is one of the quickest ways to waste a supplier's time and your own. Before anything goes out the door, there are three things we'd recommend getting straight first: which scope you're actually running (SD-WAN, SSE, full SASE, managed or phased), what the M/W/I/PoC tags against each question mean for how strictly you'll hold suppliers to them, and how you're going to turn a stack of written answers into something you can defend to a board or an auditor. Get those three sorted and the rest of the framework more or less runs itself. Skip them, and you'll end up arguing about method halfway through evaluation, which is a miserable place for any procurement team to be.

Question classifications

  • M, Mandatory: a failed requirement can disqualify a response.
  • W, Weighted: the answer contributes to the evaluated score.
  • I, Informational: the answer provides context but is not scored by default.
  • PoC, Validate: the claim should be tested before contract award.

Recommended scoring method

Score each weighted response from 0 to 5, then multiply it by the question weight. Keep mandatory requirements as separate pass or fail gates. A high weighted score must not compensate for a failed mandatory control.

Suggested citation

Netify Living SASE & SD-WAN RFP Template, 120 questions across 20 procurement pillars, Netify, available at https://netify.co.uk/sase/rfp-builder/questions/

Question bank version: sase-question-bank-2026.1

Methodology version: sase-rfp-methodology-2026.1

Last reviewed: 2026-05-18

Public framework: 120 questions across 20 pillars

Governed bank retained: 386 questions plus canonical metadata

Canonical URL: /sase/rfp-builder/questions/

Machine-readable: /question-bank.json

Licence: public methodology. Reuse permitted with attribution to Netify and the canonical URL. Agents can also read the bank over the marketplace MCP at /sase/api/mcp/.

The 20-pillar supplier question set

120 core questions across 20 procurement pillars. Each question carries a classification tag, the exact wording suppliers must answer, and the evidence, strong-response and red-flag markers evaluators should use.

P01 - Business outcomes and project understanding

Suppliers should be solving your actual operational problem here, not just mapping their product catalogue onto whatever the RFP happens to ask for. The questions in this pillar exist to expose assumptions early, and, just as importantly, to make sure whatever outcome gets proposed is genuinely measurable rather than described nicely and left vague.

P01.01I | All

Understanding of the requirement

Restate the buyer's business objectives, technical scope, material constraints and intended outcomes in your own words. Identify any area where the requirement is ambiguous.

Evidence requested
Requirements traceability table.
Strong response
Maps every objective to a proposed outcome.
Red flag
Generic executive summary that could describe any customer.

P01.02W | All

Outcome measures

For each stated objective, propose a measurable baseline, target, measurement source and reporting frequency. Distinguish technical service measures from business outcomes.

Evidence requested
Benefits and KPI register.
Strong response
Names data sources and owners.
Red flag
Benefits are described only as “improved”, “simplified” or “optimised”.

P01.03M | All

Assumptions and exclusions

List every architectural, service, resource, volume, commercial and timing assumption used in the response, together with the consequence if it proves false.

Evidence requested
Numbered assumptions and exclusions schedule.
Strong response
Prices or bounds material assumptions.
Red flag
Assumptions remain embedded in narrative or small print.

P01.04W | All

Scope deviations and alternatives

Identify every deviation from the stated requirement. Where an alternative is proposed, explain the buyer outcome it improves, the trade-off introduced and any effect on price, risk or timescale.

Evidence requested
Compliance and deviation matrix.
Strong response
Separates compliant base bid from options.
Red flag
Reframes a missing capability as an innovation without acknowledging the gap.

P01.05W | All

Critical service mapping

Show how the proposed service supports the buyer's critical applications and business services, including the network, identity, security, cloud and third-party dependencies for each.

Evidence requested
Service dependency map.
Strong response
Connects business impact to technical controls.
Red flag
Treats every application as having the same availability and security need.

P01.06W | All

Responsibility for outcomes

Name the party accountable for achieving each proposed outcome during design, migration and live service, including responsibilities retained by the buyer and passed to subcontractors.

Evidence requested
Outcome-level RACI.
Strong response
One accountable owner per outcome.
Red flag
“Shared responsibility” without decision or escalation ownership.
P02 - Current estate, discovery and application dependency

An incomplete estate inventory is where a lot of RFPs quietly go wrong, since it produces an optimistic design on paper followed by change requests once reality actually catches up with it. Discovery, in this pillar, should be validating what the buyer already knows about their own estate, not replacing it with the supplier's assumptions without anyone noticing.

P02.01W | All

Discovery method

Describe the discovery process, data sources, tooling, sampling period and buyer access required to validate sites, circuits, devices, applications, identities and traffic flows.

Evidence requested
Discovery plan and example output.
Strong response
Uses multiple sources and reconciles conflicts.
Red flag
Relies only on a buyer spreadsheet or a short packet capture.

P02.02M | SD-WAN/Full SASE

Circuit and site baseline

Explain how you will verify circuit inventory, demarcation, provider, bandwidth, utilisation, diversity, contract status and site criticality before design approval.

Evidence requested
Site and circuit inventory template.
Strong response
Includes physical diversity validation.
Red flag
Assumes two access products from different brands are physically diverse.

P02.03W | All

Application identification

Explain how applications and services are discovered, classified and associated with owners, data sensitivity, performance needs and business criticality.

Evidence requested
Application catalogue example.
Strong response
Supports custom and encrypted applications.
Red flag
Depends solely on public application signatures.

P02.04W | All

Traffic and capacity baseline

State how normal, peak and failure-state traffic will be measured and translated into edge, tunnel, PoP and licence sizing, including seasonal or event-driven peaks.

Evidence requested
Capacity model with headroom assumptions.
Strong response
Models failover and security inspection overhead.
Red flag
Sizes only from contracted circuit bandwidth.

P02.05W | All

Identity and device baseline

Describe how users, service accounts, contractors, devices and unmanaged endpoints will be inventoried and mapped to identity providers, device-management systems and access policies.

Evidence requested
Identity and device source map.
Strong response
Includes non-human identities.
Red flag
Treats all access as employee access from managed laptops.

P02.06W | All

Discovery risk and remediation

Explain how unknown applications, shadow IT, duplicate address space, unsupported devices, undocumented firewall rules and other discovery findings will be reported and resolved.

Evidence requested
Risk register and remediation workflow.
Strong response
Defines decision gates before migration.
Red flag
Defers all findings to implementation without commercial or schedule impact.
P03 - Service model, supplier structure and accountability

We come across buyers comparing a technology vendor, a reseller and a managed service provider fairly often as though the three carry identical responsibilities, and they don't, not even close. Who actually designs, operates, supports and contracts each component is what this pillar is trying to expose, rather than just who's named on the cover page of the proposal.

P03.01M | All

Contracting and delivery parties

Identify the contracting entity, technology vendors, carriers, cloud providers, distributors, implementation partners, support partners and subcontractors involved in the service.

Evidence requested
Legal and delivery-party diagram.
Strong response
Names every material dependency.
Red flag
Describes third parties only as “strategic partners”.

P03.02M | All

End-to-end accountability

State which party owns end-to-end service accountability when an incident crosses SD-WAN, underlay, SASE security, identity, endpoint or cloud boundaries.

Evidence requested
Incident RACI and escalation path.
Strong response
Provides one accountable service owner.
Red flag
Requires the buyer to coordinate multiple suppliers during a P1 incident.

P03.03W | Managed

Management boundary

Define the activities included in self-managed, co-managed and fully managed options, including monitoring, policy changes, upgrades, incident response, reporting and optimisation.

Evidence requested
Comparative service matrix.
Strong response
Identifies buyer permissions in each model.
Red flag
“Managed” means alert forwarding rather than operational ownership.

P03.04W | All

Supplier viability and service commitment

Provide the service's general-availability date, customer adoption, investment roadmap, end-of-life policy and evidence that support can continue for the proposed contract term.

Evidence requested
Product lifecycle policy and audited corporate information where available.
Strong response
Contractually addresses acquisition or product withdrawal.
Red flag
Relies on market-growth claims instead of support commitments.

P03.05W | All

Skills and geographic coverage

Quantify certified engineering, service-management and security resources by relevant region and shift. Explain which skills are employees and which are subcontracted.

Evidence requested
Anonymised resource and certification matrix.
Strong response
Matches skills to the proposed technology.
Red flag
Global support is a call-handling centre without regional engineering depth.

P03.06W | All

Conflicts and commercial incentives

Disclose rebates, exclusivity, preferred-vendor status or other incentives that could influence the recommended architecture, carrier or security platform.

Evidence requested
Conflict-of-interest declaration.
Strong response
Explains controls around recommendations.
Red flag
Claims “vendor neutral” while proposing only products tied to undisclosed incentives.
P04 - SASE architecture and component provenance

There's a lot hiding behind a single SASE label, and it can mean a genuinely unified platform, a set of integrated products, or a managed bundle stitched together behind the scenes, none of which is automatically the better option over the others. What actually matters is understanding the operational, performance and contractual consequences of whichever one's actually being sold to you.

P04.01M | Full SASE

Component provenance

For SD-WAN, ZTNA, SWG, CASB, DLP, FWaaS, DNS security, RBI, DEM and threat prevention, identify whether the capability is native, acquired, OEM, third-party integrated or roadmap.

Evidence requested
Component provenance matrix with product and version names.
Strong response
States limitations and separate licences.
Red flag
Uses a single “included” label for materially different integrations.

P04.02W | Full SASE

Control-plane and policy integration

Explain which network and security policies share the same data model, administration plane, identity context, workflow and audit trail. Identify policies that must be recreated between products.

Evidence requested
Live demonstration and policy architecture.
Strong response
Shows a single change propagating end to end.
Red flag
Multiple consoles are hidden behind single sign-on and presented as unified management.

P04.03PoC | Full SASE

Traffic-processing path

Show the packet and session path through decryption, security inspection, routing and re-encryption for web, private application, branch-to-branch and cloud traffic. Quantify repeated processing.

Evidence requested
Architecture diagram, packet capture or test trace.
Strong response
Documents the real data path under full policy.
Red flag
Supplies only a conceptual marketing diagram.

P04.04W | All

Deployment forms and boundaries

Describe supported physical, virtual, cloud-native, browser-based, client-based and clientless deployment forms, including the functional differences between them.

Evidence requested
Feature-parity table.
Strong response
Identifies unsupported controls by form.
Red flag
Calls a browser extension or downloaded helper “clientless” without qualification.

P04.05W | Full SASE

Incremental adoption and coexistence

Explain how the buyer can deploy SD-WAN first, SSE first or region by region without duplicating policies or preventing later convergence.

Evidence requested
Phased reference architecture and migration sequence.
Strong response
Defines interim operating states.
Red flag
Convergence requires replacement of the initially purchased product.

P04.06W | All

Standards and interoperability

Identify the open standards, routing protocols, identity protocols, log formats and APIs used at each integration boundary, plus any proprietary dependency that limits replacement or coexistence.

Evidence requested
Interface catalogue and API documentation.
Strong response
Shows export and third-party integration.
Red flag
“Open API” is available only through paid professional services.
P05 - SD-WAN underlay, edge and site architecture

Underlay, edge design and where responsibility gets handed off between parties, that's really what SD-WAN performance comes down to in practice. Worth remembering too that logical diversity isn't the same thing as physical diversity, and headline throughput figures rarely reflect what you'll actually see once full policy gets applied on top.

P05.01M | SD-WAN/Full SASE

Underlay support and independence

List supported MPLS, Ethernet, DIA, broadband, 4G/5G, satellite and customer-provided services. State whether the buyer can retain existing circuits and carriers.

Evidence requested
Supported-access matrix and design constraints.
Strong response
Applies consistent monitoring and policy across carrier types.
Red flag
“Carrier agnostic” excludes support responsibility for third-party circuits.

P05.02W | SD-WAN/Full SASE

Physical diversity

Explain how access-path, duct, exchange, carrier, power and building-entry diversity will be verified for resilient sites.

Evidence requested
Site diversity report or provider confirmation.
Strong response
Distinguishes logical from physical separation.
Red flag
Assumes different carrier names mean diverse infrastructure.

P05.03W | SD-WAN/Full SASE

Edge form factors and sizing

Provide physical, virtual and cloud edge options with encrypted and full-security throughput, tunnel limits, interfaces, environmental tolerances and high-availability models.

Evidence requested
Current data sheets plus sizing calculation.
Strong response
Sizes against measured traffic and failover.
Red flag
Quotes firewall throughput with security functions disabled.

P05.04W | SD-WAN/Full SASE

Zero-touch provisioning

Describe the order, staging, shipping, activation, authentication and rollback process for a new site, including what local skills and access are required.

Evidence requested
Workflow and typical elapsed times by region.
Strong response
Prevents unauthorised device activation.
Red flag
“Zero touch” still requires local CLI configuration.

P05.05W | SD-WAN/Full SASE

Addressing, routing and segmentation

Explain support for IPv4, IPv6, overlapping address space, BGP, OSPF, static routing, multicast, VRFs or equivalent segmentation and route-leak controls.

Evidence requested
Configuration examples and scale limits.
Strong response
Demonstrates IPv4/IPv6 feature parity.
Red flag
IPv6 is routed but bypasses equivalent security or analytics.

P05.06W | SD-WAN/Full SASE

Hardware lifecycle and sparing

State hardware warranty, RMA service, regional sparing, software support, end-of-sale and end-of-support notice periods, and migration assistance.

Evidence requested
Lifecycle and RMA policy.
Strong response
Contract term fits within support life.
Red flag
Proposed hardware is already within the vendor's published retirement window.
P06 - Routing, application performance and quality of service

How the service behaves when something's actually gone wrong is really what application experience comes down to, not just whether a link's technically up or down. Brownouts, real-time applications and policy behaviour under failure are worth testing specifically, since that's usually where the real difference between suppliers shows up.

P06.01PoC | SD-WAN/Full SASE

Path measurement and selection

Identify the loss, latency, jitter, availability and application metrics used for path selection, their sampling interval and configurable thresholds.

Evidence requested
Policy example and telemetry output.
Strong response
Supports application-specific thresholds.
Red flag
Changes path only after physical link failure.

P06.02PoC | SD-WAN/Full SASE

Brownout and failover behaviour

Demonstrate how active sessions respond when packet loss, latency or jitter gradually exceeds policy, including failover time, packet loss and session preservation.

Evidence requested
Controlled impairment test.
Strong response
Meets a pre-agreed application threshold.
Red flag
Demonstrates cable removal rather than degradation.

P06.03W | SD-WAN/Full SASE

Application identification

Explain signature, heuristic, DNS, TLS, user-defined and machine-learning methods used to identify applications, including custom and encrypted applications.

Evidence requested
Recognition catalogue and custom-app workflow.
Strong response
Reports confidence and fallback behaviour.
Red flag
Unknown traffic silently inherits an unsafe default class.

P06.04PoC | SD-WAN/Full SASE

Voice, video and real-time traffic

Show how QoS, prioritisation, duplication, forward-error correction or other mechanisms protect voice and video during impairment, and quantify their overhead.

Evidence requested
Call-quality test with MOS, loss, latency and jitter.
Strong response
Includes failure-state results.
Red flag
Relies on bandwidth alone.

P06.05W | SD-WAN/Full SASE

WAN optimisation and acceleration

Describe supported optimisation for SaaS, private applications, file transfer and high-latency paths, including protocol limitations and interactions with encryption.

Evidence requested
Feature matrix and measured use case.
Strong response
Separates routing improvement from genuine optimisation.
Red flag
Rebrands local breakout as WAN optimisation.

P06.06W | All

Digital experience monitoring

Describe endpoint, network, DNS, SaaS and application measurements available to isolate whether poor experience originates at the device, access circuit, backbone, security inspection, cloud or application.

Evidence requested
Example troubleshooting timeline.
Strong response
Correlates user experience with service telemetry.
Red flag
Provides only aggregate tunnel uptime.
P07 - Global backbone, PoPs and cloud connectivity

A big PoP count on a slide doesn't prove much on its own, certainly not usable regional capacity, resilience or control. We'd want to understand where traffic's actually processed, who owns each dependency along the way, and what's contractually assured here versus what's just been implied in the pitch.

P07.01M | All

PoP and processing-location disclosure

List production PoPs relevant to the buyer, their country, facility or cloud region, services processed there and whether the infrastructure is owned, leased, colocated or cloud-hosted.

Evidence requested
Dated PoP inventory.
Strong response
Separates control, data and logging locations.
Red flag
Provides city dots without underlying facility or platform detail.

P07.02W | All

Capacity and oversubscription

Explain how PoP, backbone and inspection capacity are planned, monitored and expanded, including customer isolation, oversubscription policy and peak utilisation thresholds.

Evidence requested
Capacity-management policy and anonymised trend.
Strong response
Defines action thresholds.
Red flag
States “elastic cloud scale” without limits or evidence.

P07.03W | All

Backbone and transit model

Describe inter-PoP connectivity, ownership or control, internet transit, peering, routing authority and how path changes affect performance guarantees.

Evidence requested
Network architecture and representative route evidence.
Strong response
Distinguishes a private operational backbone from leased capacity.
Red flag
Equates good peering with wholly owned infrastructure.

P07.04PoC | All

Regional latency and performance

Provide current median and 95th-percentile latency, loss and jitter for the buyer's relevant site-to-PoP, PoP-to-PoP and PoP-to-cloud paths under the proposed security policy.

Evidence requested
Dated measurement methodology and test data.
Strong response
Allows buyer validation.
Red flag
Quotes global averages or laboratory minimums.

P07.05W | All

Public cloud integration

Describe connectivity to the buyer's specified AWS, Azure, Google Cloud or other regions, including native constructs, routing, redundancy, inspection and egress-cost implications.

Evidence requested
Reference design and responsibility matrix.
Strong response
Prices cloud networking dependencies.
Red flag
“Cloud on-ramp” is an unmanaged IPsec tunnel.

P07.06W | All

Egress IP and allow-list stability

Provide the egress-IP model by region, change-notice process, dedicated-IP options and continuity arrangements for applications that allow-list source addresses.

Evidence requested
Current ranges and contractual notice proposal.
Strong response
Supports controlled transition between ranges.
Red flag
Changes are communicated only through a portal after implementation.
P08 - Zero Trust Network Access and identity integration

Removing implicit trust based on network location, and putting the access decision on users, devices and resources instead, that's NIST's definition of zero trust in a nutshell. An RFP should be testing the actual policy decision and enforcement chain in this pillar, not just accepting a ZTNA label at face value because it's on the box.

P08.01M | SSE/Full SASE

Identity-provider integration

List supported SAML, OIDC, OAuth, SCIM, LDAP and certificate-based integrations for the buyer's identity providers, including high availability and failure behaviour.

Evidence requested
Supported-integration matrix and reference architecture.
Strong response
Describes token, attribute and group handling.
Red flag
Requires directory duplication into a vendor-owned identity store.

P08.02M | SSE/Full SASE

Resource-level access

Demonstrate how a user receives access to a named application or resource without receiving broad network access, and how lateral movement is prevented.

Evidence requested
Policy configuration and network test.
Strong response
Default-deny is visible and auditable.
Red flag
ZTNA establishes a network tunnel equivalent to a legacy VPN.

P08.03W | SSE/Full SASE

Continuous policy evaluation

Explain which identity, device, risk, location, application and behaviour signals can change access during a session and what action is taken when risk changes.

Evidence requested
Signal catalogue and live demonstration.
Strong response
Supports step-up, restriction and termination.
Red flag
Evaluation occurs only at initial login.

P08.04W | SSE/Full SASE

Strong authentication and phishing resistance

Describe supported MFA and passwordless methods, including FIDO2/WebAuthn, certificate and device-bound options, and how policy varies by risk and resource.

Evidence requested
Authentication policy examples.
Strong response
Supports phishing-resistant controls for privileged access.
Red flag
All MFA methods are treated as equivalent.

P08.05PoC | SSE/Full SASE

Client and clientless access

Provide a side-by-side comparison of client, browser and clientless access for private web, SSH, RDP and other required applications, including security and audit differences.

Evidence requested
Feature-parity matrix and demonstration.
Strong response
Clearly states limitations.
Red flag
Browser extension or temporary executable is presented as no-client access.

P08.06W | SSE/Full SASE

Service and workload identity

Explain how non-human identities, APIs, workloads and machine-to-machine flows are authenticated, authorised, inventoried and revoked across on-premises and multi-cloud environments.

Evidence requested
Workload identity architecture.
Strong response
Does not depend solely on source IP.
Red flag
Zero trust applies only to interactive human users.
P09 - Third-party access, endpoints and device posture

Contractors, suppliers and unmanaged devices often need access without accepting a full corporate endpoint client, and it's a genuinely awkward problem that most suppliers don't solve particularly well. Controls need to match the actual risk involved here, and hold onto evidence of who accessed what, for when it actually matters.

P09.01M | SSE/Full SASE

Third-party access lifecycle

Describe request, approval, provisioning, time limitation, review and revocation for contractor and supplier access, including sponsor accountability.

Evidence requested
Workflow and audit example.
Strong response
Supports expiry by default.
Red flag
External identities become permanent directory accounts.

P09.02W | SSE/Full SASE

Device posture signals

List supported operating system, patch, encryption, EDR, firewall, certificate, jailbreak, management and custom posture signals, including refresh frequency.

Evidence requested
Posture catalogue.
Strong response
Shows signal provenance and stale-state handling.
Red flag
“Compliant device” is a single opaque vendor score.

P09.03PoC | SSE/Full SASE

Access from unmanaged devices

Demonstrate policy for a personally owned or partner device accessing a sensitive application, including download, clipboard, print, upload and session controls.

Evidence requested
Live test and resulting audit trail.
Strong response
Applies resource-specific restrictions.
Red flag
Unmanaged access is either wholly blocked or receives the same rights as a managed device.

P09.04W | SSE/Full SASE

Privileged and administrative access

Explain controls for administrators and high-risk users, including separate identities, step-up authentication, just-in-time access, session recording and emergency access.

Evidence requested
Privileged-access design.
Strong response
Administrative actions are attributable and reviewable.
Red flag
Shared administrative accounts or bypass paths exist.

P09.05W | SSE/Full SASE

Endpoint-client operations

Describe supported operating systems, deployment tools, upgrade rings, rollback, coexistence, resource use, diagnostics and behaviour when the service is unavailable.

Evidence requested
Client lifecycle guide and performance data.
Strong response
Includes locked-down and VDI environments.
Red flag
Forced updates cannot be staged or reversed.

P09.06W | SSE/Full SASE

Connector and application-publisher security

Describe how private-application connectors are authenticated, updated, segmented, monitored and made resilient without exposing inbound services.

Evidence requested
Connector architecture and hardening guide.
Strong response
Uses outbound-only connectivity and least privilege.
Red flag
Broad network reach or inbound firewall rules are required.
P10 - Secure web gateway, DNS, TLS and remote browser isolation

Modern encryption, pinned certificates, non-web protocols and bypass lists can all create real blind spots in web controls, more than people tend to expect. What's actually inspected, what gets bypassed, and what's logged is what we'd want stated plainly in the response, rather than a general claim of full coverage that doesn't hold up under questioning.

P10.01M | SSE/Full SASE

Web and protocol coverage

List the protocols, ports, applications and traffic classes inspected by SWG policy, including HTTP/2, HTTP/3, QUIC, FTP, WebSockets and non-standard ports.

Evidence requested
Coverage and limitation matrix.
Strong response
States fallback and bypass behaviour.
Red flag
“All web traffic” is claimed without protocol detail.

P10.02PoC | SSE/Full SASE

TLS inspection

Describe TLS versions and features that can be decrypted and inspected, certificate deployment, unsupported cases, latency impact and treatment of ECH, pinning and mutual TLS.

Evidence requested
Current technical documentation and controlled performance test.
Strong response
Publishes a bypass inventory.
Red flag
Support for TLS is confused with ability to inspect it.

P10.03W | SSE/Full SASE

Inspection exceptions

Provide the default and mandatory bypass lists for financial, health, certificate-pinned, real-time and other applications, with the security functions and logs lost for each exception.

Evidence requested
Current exception catalogue.
Strong response
Allows policy-level control and change notification.
Red flag
Bypasses are undisclosed or globally fixed.

P10.04W | SSE/Full SASE

DNS security

Explain protection and logging for conventional DNS, DNS over HTTPS, DNS over TLS, direct-to-IP access, newly observed domains, domain generation and internal DNS.

Evidence requested
Policy and detection examples.
Strong response
Prevents simple resolver bypass.
Red flag
Only vendor-resolver queries are inspected.

P10.05W | SSE/Full SASE

Web threat and content controls

Describe URL categorisation, malware analysis, file-type control, content disarm, sandboxing and action while a verdict is pending, including encrypted archives.

Evidence requested
Detection flow and verdict-time data.
Strong response
States whether content is held or released.
Red flag
Retrospective alerting is presented as prevention.

P10.06PoC | SSE/Full SASE

Remote browser isolation

Describe isolation modes, supported browsers and applications, file and clipboard controls, rendering method, accessibility, privacy and performance on constrained links.

Evidence requested
Demonstration under buyer-defined latency and bandwidth.
Strong response
Measures click-to-paint experience.
Red flag
Demonstration uses only a low-latency office connection.
P11 - CASB, SaaS, DLP and generative AI controls

Governing data wherever people actually work is really the goal here, not simply blocking a list of websites and calling it done. Inline and API controls reach differently and behave differently on remediation, and generative AI's added a genuinely new layer of data-sharing and account-governance risk that a lot of older frameworks just don't cover yet.

P11.01M | SSE/Full SASE

SaaS discovery and risk

Explain how sanctioned and unsanctioned SaaS use is discovered, attributed and risk-scored, including unknown applications, personal accounts and traffic that cannot be decrypted.

Evidence requested
Current cloud-app catalogue, scoring methodology and sample discovery report.
Strong response
Exposes scoring factors and confidence.
Red flag
A proprietary risk score is provided without supporting attributes.

P11.02W | SSE/Full SASE

Inline and API-mode CASB

Compare inline and API coverage for the buyer's priority SaaS platforms, including actions, data latency, historical scanning, remediation, supported object types and licensing dependencies.

Evidence requested
Application-by-control coverage matrix.
Strong response
Separates prevent, detect and remediate.
Red flag
API discovery is described as real-time prevention.

P11.03PoC | SSE/Full SASE

Data loss prevention

Demonstrate detection and control of buyer-defined sensitive data in web, email, SaaS, uploads, posts and generative-AI prompts, including structured, unstructured, image and source-code content.

Evidence requested
Test results for true positives, false positives, action and user experience.
Strong response
Supports exact data, fingerprint and contextual matching.
Red flag
DLP capability is evidenced only by a list of regular expressions.

P11.04W | SSE/Full SASE

Tenant and account restrictions

Explain how policy distinguishes corporate and personal tenants, accounts and instances for services such as Microsoft 365, Google Workspace, storage, source-code repositories and generative AI.

Evidence requested
Supported application and action matrix.
Strong response
Applies granular upload, download and login controls.
Red flag
Control depends only on URL category.

P11.05W | SSE/Full SASE

Generative AI governance

Describe discovery, allow, block, coach, redact and log controls for public and enterprise generative-AI services, including browser, desktop client, API and embedded AI features.

Evidence requested
Named-service coverage and dated release documentation.
Strong response
Distinguishes consumer and enterprise tenancy and explains prompt handling.
Red flag
All AI traffic is treated as one web category.

P11.06W | SSE/Full SASE

DLP incident lifecycle

Describe policy authoring, testing, exception approval, end-user coaching, incident review, evidence preservation and tuning, including integration with case-management and data-governance workflows.

Evidence requested
End-to-end incident example and role matrix.
Strong response
Provides privacy-aware evidence access and measurable tuning.
Red flag
Every match creates an unactionable alert with no ownership workflow.
P12 - FWaaS, threat prevention and segmentation

Network and threat controls that actually hold up across sites, users and cloud workloads, not just on paper, that's what a converged service needs to deliver here. Marketing labels aren't really enough unless the supplier's willing to state inspection coverage, enforcement location, efficacy and failure behaviour explicitly.

P12.01M | SD-WAN/SSE/Full SASE

Firewall coverage and state

Describe Layer 3 through Layer 7 firewall controls for site, user, cloud and internet traffic, including application identification, user identity, state synchronisation, NAT, IPv6 and non-web protocols.

Evidence requested
Feature matrix by enforcement point and architecture diagram.
Strong response
Shows consistent policy objects and explicit limitations.
Red flag
Remote-user and branch firewalls have materially different engines without disclosure.

P12.02PoC | SSE/Full SASE

Intrusion prevention

Demonstrate prevention of buyer-agreed exploit and evasion scenarios in inspected traffic, including signature update timing, severity handling, custom exceptions and action during engine failure.

Evidence requested
Test plan, detection logs, packet evidence and current third-party test results where available.
Strong response
Separates block efficacy from alert visibility.
Red flag
Lab test claims cannot be reproduced or scoped.

P12.03W | SSE/Full SASE

Malware and sandbox controls

Explain static, behavioural and sandbox analysis for files and content, including supported types and sizes, encrypted archives, verdict latency, hold-versus-release behaviour and retrospective action.

Evidence requested
Analysis flow, coverage table and time-to-verdict data.
Strong response
Makes pre-delivery and post-delivery controls explicit.
Red flag
Retrospective detection is presented as pre-execution prevention.

P12.04M | SD-WAN/SSE/Full SASE

Segmentation and lateral movement

Describe how business, guest, operational technology, partner, regulated and management zones remain segmented across sites, users, cloud and shared services, including route leaking and policy exceptions.

Evidence requested
Buyer-specific segmentation design and reachability test.
Strong response
Uses default-deny and centrally auditable exceptions.
Red flag
Segmentation ends when traffic enters the provider backbone.

P12.05W | SSE/Full SASE

Encrypted and evasive traffic

Explain control of TLS, QUIC, DNS tunnelling, fragmented traffic, uncommon ports, password-protected files and other evasive techniques, stating when traffic is blocked, bypassed or loses security inspection.

Evidence requested
Coverage and exception matrix.
Strong response
Quantifies blind spots and offers compensating controls.
Red flag
The response claims universal inspection without protocol constraints.

P12.06W | SSE/Full SASE

Threat intelligence and emergency response

Describe intelligence sources, indicator confidence, update frequency, customer-specific indicators, false-positive handling and emergency protection for actively exploited vulnerabilities.

Evidence requested
Dated response timeline for a recent material threat and sample indicator provenance.
Strong response
Shows time from intelligence to enforced protection.
Red flag
Protection depends on a future software upgrade at every site.
P13 - Logging, analytics, integrations and automation

A control that can't produce evidence which is timely, usable and exportable is genuinely difficult to operate or audit down the line, however good it looks in a demo. We'd test data completeness, latency, portability and automation directly, rather than accepting a nice-looking dashboard screenshot as proof of anything.

P13.01M | SD-WAN/SSE/Full SASE

Event and telemetry coverage

List the events, metrics and flow records available for network, security, identity, policy, administration, endpoint client, connector and supplier-service activity, including fields omitted under each licence.

Evidence requested
Current data dictionary and sample records.
Strong response
Includes event IDs, timestamps, actors, policy and enforcement outcome.
Red flag
The dashboard contains details that cannot be exported.

P13.02W | SD-WAN/SSE/Full SASE

Retention, search and data location

State searchable and archive retention by data type, indexing delay, query limits, export options, storage location, time synchronisation and the process for legal hold or extended retention.

Evidence requested
Retention and location matrix with pricing.
Strong response
Separates hot, archive and customer-exported data.
Red flag
Retention is described as unlimited without search or retrieval terms.

P13.03PoC | SD-WAN/SSE/Full SASE

SIEM and SOC integration

Stream buyer-agreed events to the chosen SIEM or data platform and measure completeness, delivery latency, schema stability, duplicate handling, back pressure and recovery after interruption.

Evidence requested
Reconciled source-to-destination counts and field mapping.
Strong response
Supports reliable replay or checkpointing.
Red flag
Best-effort syslog is the only export method.

P13.04W | SD-WAN/SSE/Full SASE

APIs and ecosystem integrations

Document read and write APIs, webhooks, rate limits, pagination, versioning, authentication, service accounts and integrations with ITSM, SOAR, identity, endpoint, cloud and observability platforms.

Evidence requested
API documentation and working buyer-relevant example.
Strong response
Commits to deprecation notice and version compatibility.
Red flag
Automation requires undocumented interfaces or shared administrator credentials.

P13.05W | SD-WAN/SSE/Full SASE

Experience and root-cause analytics

Explain how the service separates user, device, Wi-Fi/LAN, access circuit, provider backbone, cloud, application and policy causes when performance degrades.

Evidence requested
Root-cause example using correlated network and application data.
Strong response
Shows uncertainty and supporting measurements.
Red flag
Every incident is reduced to a single opaque health score.

P13.06W | SD-WAN/SSE/Full SASE

AI-assisted operations and guardrails

Describe any AI-generated insight or action, the data used, customer-data isolation, human approval, explainability, error handling, audit trail and opt-out controls.

Evidence requested
Architecture, governance statement and sample recommendation with source evidence.
Strong response
Keeps autonomous changes within explicit policy and rollback controls.
Red flag
An AI label is applied to unverified alerts or unreviewed configuration changes.
P14 - Policy governance, administration and audit

Convergence doesn't really count for much if network and security policy stays fragmented behind the scenes regardless. What you actually want is a controlled lifecycle, design and approval through to deployment, verification, rollback and audit, the whole thing, not just the parts that make for a good demo.

P14.01M | SD-WAN/SSE/Full SASE

Policy model and consistency

Describe which network and security policies share objects, identity, workflow and enforcement, and identify any separate consoles, engines, replication delays or feature gaps.

Evidence requested
Console and policy architecture demonstration.
Strong response
Clearly maps a rule to every enforcement point.
Red flag
A unified dashboard merely links to separate products.

P14.02M | SD-WAN/SSE/Full SASE

Administrative identity and access

Explain SSO, MFA, delegated roles, least privilege, separation of duties, break-glass access, just-in-time administration, managed-service access and periodic access review.

Evidence requested
Role-permission matrix and administrator audit sample.
Strong response
Supports granular read, propose, approve and deploy roles.
Red flag
Broad super-administrator access is required for routine support.

P14.03W | SD-WAN/SSE/Full SASE

Change workflow and infrastructure as code

Describe draft, peer review, approval, scheduled deployment, API or infrastructure-as-code support, pre-checks, staged rollout and integration with the buyer's change-management process.

Evidence requested
End-to-end change demonstration and API example.
Strong response
Produces an attributable change record.
Red flag
Console changes cannot be reviewed before they take effect.

P14.04PoC | SD-WAN/SSE/Full SASE

Versioning and rollback

Deploy a buyer-defined policy change, verify its enforcement, show the exact difference, then roll it back while preserving the full audit history.

Evidence requested
Timestamped configuration versions and enforcement logs.
Strong response
Rollback has bounded, measured propagation time.
Red flag
Recovery requires manual recreation of rules.

P14.05W | SD-WAN/SSE/Full SASE

Policy assurance

Explain conflict, shadow, redundancy, excessive-access and unintended-route analysis before and after deployment, including simulation or reachability testing.

Evidence requested
Analysis against a buyer-defined rule set.
Strong response
Identifies affected users, resources and paths before change.
Red flag
Assurance consists only of syntax validation.

P14.06M | SD-WAN/SSE/Full SASE

Auditability and evidence export

Demonstrate an immutable record of login, view, create, approve, change, delete, override, support and emergency actions, including export, retention and supplier-personnel attribution.

Evidence requested
Sample audit trail and integrity controls.
Strong response
Records before-and-after values and delegated-service activity.
Red flag
Supplier changes appear under a generic service account.
P15 - Resilience, continuity and performance assurance

The whole user journey is what availability claims should reflect, not just one isolated cloud component that happens to have a good uptime figure attached to it. Dependencies, failure domains, service credits, and how continuity actually gets tested rather than just promised, all of that needs understanding properly before you take the claim at face value.

P15.01M | SD-WAN/SSE/Full SASE

End-to-end service levels

Provide proposed service levels and objectives for site, remote user, policy, security inspection, management, reporting, support response and change, including measurement points, exclusions and service credits.

Evidence requested
Draft service-level schedule and calculation examples.
Strong response
Aligns metrics to user and business impact.
Red flag
Availability covers only the management portal or provider core.

P15.02PoC | SD-WAN/SSE/Full SASE

Failure-mode behaviour

For loss of an access circuit, edge, PoP, tunnel, DNS service, identity provider, endpoint client, connector, control plane and inspection engine, state detection time, failover action, security posture, recovery time and user impact.

Evidence requested
Failure-mode and effects analysis plus buyer-observed tests.
Strong response
Makes fail-open and fail-closed decisions explicit.
Red flag
Security controls silently disappear during a resilience event.

P15.03W | SD-WAN/SSE/Full SASE

PoP and platform concentration risk

Describe availability-zone, data-centre, carrier, cloud, software and control-plane dependencies for the buyer's proposed locations, including whether primary and backup paths share a failure domain.

Evidence requested
Dependency and diversity map.
Strong response
Identifies correlated risk and validates physical diversity.
Red flag
Logical diversity is assumed to prove physical diversity.

P15.04PoC | SD-WAN/SSE/Full SASE

Capacity and scale under failure

Demonstrate or provide reproducible evidence that the design meets required throughput, session, tunnel, user, policy and log rates in normal operation and after the largest planned component failure.

Evidence requested
Sized design, test conditions and headroom calculation.
Strong response
Includes encrypted inspection and realistic traffic mix.
Red flag
Appliance data-sheet throughput is used as end-to-end capacity evidence.

P15.05W | SD-WAN/SSE/Full SASE

Continuity and disaster recovery

Provide recovery time and recovery point objectives, backup scope, configuration restore, cyber-recovery arrangements and the frequency and result of platform and operational recovery exercises.

Evidence requested
Redacted recent exercise report and improvement actions.
Strong response
Tests people, process, platform and customer communication.
Red flag
The supplier equates infrastructure redundancy with a tested recovery plan.

P15.06W | SD-WAN/SSE/Full SASE

Incident communication and post-incident evidence

Describe status notification, severity classification, named escalation, update cadence, estimated restoration, root-cause analysis, corrective action tracking and access to service-health history.

Evidence requested
Redacted material-incident timeline and post-incident report.
Strong response
Provides facts, timestamps and owned corrective actions.
Red flag
Root-cause reports are optional or contractually unavailable.
P16 - Implementation, migration and acceptance

Transition is where most procurement risk actually shows up, and it's usually the part suppliers rush past in a pitch to get to the good bit. What you want from a credible response is the target architecture turned into an owned sequence: discoveries, dependencies, waves, acceptance gates, rollback decisions, the works, rather than a single migration slide with an arrow pointing at it.

P16.01M | SD-WAN/SSE/Full SASE

Mobilisation and governance

Provide the proposed programme structure, named supplier roles, buyer dependencies, decision rights, workstreams, reporting cadence, risk process and escalation path from contract signature through service acceptance.

Evidence requested
Draft mobilisation plan, RACI and sample status pack.
Strong response
Names accountable roles and buyer effort.
Red flag
The delivery plan begins only after an undefined discovery phase.

P16.02M | SD-WAN/SSE/Full SASE

Discovery and design

Describe how sites, circuits, addressing, routes, applications, users, identities, security policy, certificates, cloud, third parties and operational constraints will be discovered, validated and converted into low-level design.

Evidence requested
Discovery workbook, design contents and validation process.
Strong response
Reconciles source data and manages unknowns.
Red flag
The buyer is solely responsible for supplying a perfect inventory.

P16.03W | SD-WAN/SSE/Full SASE

Migration waves and coexistence

Provide a buyer-specific wave strategy covering pilot selection, coexistence with current WAN, VPN and security services, change freezes, high-risk sites, rollback, blackout periods and decommissioning.

Evidence requested
Indicative wave plan and migration runbook.
Strong response
Uses measurable entry and exit criteria for each wave.
Red flag
A big-bang cutover is proposed without a tested rollback path.

P16.04W | SD-WAN/SSE/Full SASE

Integration and dependency management

Identify dependencies on identity, endpoint management, PKI, DNS, DHCP, LAN/Wi-Fi, cloud, carrier, SIEM, ITSM, application owners and third parties, including owners and lead times.

Evidence requested
Dependency register and integration test plan.
Strong response
Distinguishes supplier, buyer and shared responsibility.
Red flag
Dependencies are deferred until implementation.

P16.05PoC | SD-WAN/SSE/Full SASE

Acceptance and operational readiness

Propose objective technical, security, performance, resilience, support, documentation and knowledge-transfer acceptance criteria, including defect severity, retest and authority to reject a wave.

Evidence requested
Draft acceptance schedule with measurable thresholds.
Strong response
Acceptance depends on observed outcomes, not installation completion.
Red flag
Service billing begins when equipment ships or a licence is activated.

P16.06W | SD-WAN/SSE/Full SASE

Knowledge transfer and legacy exit

Describe as-built documentation, administrator and service-desk training, runbooks, shadow support, hypercare, skills verification, legacy-policy archive and secure disposal or return of replaced assets.

Evidence requested
Deliverables list, training plan and sample runbook.
Strong response
Leaves the buyer able to operate, audit and exit the service.
Red flag
Essential knowledge remains with an individual engineer or chargeable professional service.
P17 - Managed service, support and operating model

This pillar is really about evaluating technology and operations together, since treating them as separate conversations misses half the picture. Find out who's watching, deciding, changing, communicating and improving the service at 3am, because that tells you a lot more than who turns up for the quarterly review does.

P17.01M | SD-WAN/SSE/Full SASE

Responsibility model

Provide a RACI for monitoring, incident, problem, request, change, vulnerability, policy, capacity, lifecycle, identity, certificate, carrier, vendor and audit activities across the buyer, prime contractor and subcontractors.

Evidence requested
Buyer-specific RACI and service boundaries.
Strong response
Every recurring task has one accountable owner.
Red flag
Gaps are described as shared responsibility without a decision maker.

P17.02M | SD-WAN/SSE/Full SASE

Support coverage and escalation

State service-desk locations, hours, channels, languages, severity definitions, response and restoration targets, named escalation, engineering access and support entitlement for buyer and partner personnel.

Evidence requested
Support schedule and redacted severity-one case timeline.
Strong response
Provides direct, time-bound technical escalation.
Red flag
The prime supplier can only relay tickets to another vendor.

P17.03PoC | SD-WAN/SSE/Full SASE

Monitoring and incident ownership

Demonstrate how a buyer-relevant network or security degradation is detected, enriched, prioritised, communicated, assigned, diagnosed and closed across supplier boundaries.

Evidence requested
Simulated incident record, communications and timestamps.
Strong response
Maintains one incident owner through resolution.
Red flag
The buyer must coordinate separate carrier, platform and managed-security queues.

P17.04W | SD-WAN/SSE/Full SASE

Problem, change and release management

Describe recurring-problem analysis, known-error control, emergency change, maintenance notice, release rings, regression testing, feature retirement and the buyer's ability to defer or reverse change.

Evidence requested
Process, sample problem record and release calendar.
Strong response
Connects incidents to owned prevention actions.
Red flag
Supplier-initiated changes are excluded from the buyer's change visibility.

P17.05W | SD-WAN/SSE/Full SASE

Service review and continual improvement

Propose operational and executive review packs covering outcomes, availability, experience, security, incidents, changes, risks, adoption, capacity, licences, roadmap, savings and an owned improvement register.

Evidence requested
Sample pack and improvement log.
Strong response
Tracks benefits and actions, not only ticket volume.
Red flag
Reviews are sales presentations with no measurable service trend.

P17.06W | SD-WAN/SSE/Full SASE

Skills, access and subcontracted operations

Identify service roles, competence requirements, vetting, privileged access, delivery locations, language coverage, staff continuity and all operational work performed by subcontractors or the platform vendor.

Evidence requested
Role and location matrix plus competence framework.
Strong response
The prime supplier governs all parties to the same standard.
Red flag
Material operations are outsourced but absent from the service description.
P18 - Compliance, privacy, assurance and supply chain

Certifications are useful evidence and we wouldn't dismiss them outright, though on their own they don't prove the proposed service, locations and operating model actually satisfy your obligations. We'd push responses to map controls, data and suppliers against the exact scope being offered here, rather than settling for a generic version of the product.

P18.01M | SD-WAN/SSE/Full SASE

Regulatory and control mapping

Map the proposed service to the buyer's stated legal, regulatory, contractual and control-framework requirements, identifying in-scope service components, customer responsibilities, exceptions and available audit evidence.

Evidence requested
Control-by-control applicability statement.
Strong response
Avoids claiming that a certification transfers compliance to the buyer.
Red flag
A logo sheet replaces a requirements mapping.

P18.02M | SD-WAN/SSE/Full SASE

Data inventory, residency and transfer

For configuration, identity, traffic metadata, content, logs, support, telemetry, analytics and backup data, state purpose, fields, location, transfer mechanism, retention, deletion and parties with access.

Evidence requested
Data-flow and location schedule for the offered service.
Strong response
Includes support and disaster-recovery copies.
Red flag
“Customer data stays in region” excludes telemetry or administrator access.

P18.03W | SD-WAN/SSE/Full SASE

Cryptography and key management

Describe encryption in transit and at rest, algorithms, protocol versions, certificate lifecycle, key ownership, hardware protection, rotation, revocation, customer-managed-key options and treatment of decrypted content.

Evidence requested
Cryptographic architecture and key-responsibility matrix.
Strong response
Identifies boundaries where plaintext exists.
Red flag
“Military-grade encryption” is offered without algorithms or key controls.

P18.04M | SD-WAN/SSE/Full SASE

Secure development and vulnerability management

Explain secure design, code review, dependency and software-bill-of-materials practices, penetration testing, vulnerability intake, remediation targets, disclosure, patch deployment and customer notification.

Evidence requested
Secure-development summary, recent independent test scope and remediation policy.
Strong response
Provides time-bound handling by severity.
Red flag
Independent test results or material unresolved findings cannot be discussed under NDA.

P18.05M | SD-WAN/SSE/Full SASE

Supply-chain governance and assurance

List the platform vendor, carriers, hosting providers, data processors, support parties and other material subcontractors; describe due diligence, flow-down obligations, concentration risk, change notification and right-to-audit arrangements.

Evidence requested
Current supplier register and assurance schedule.
Strong response
Shows how the prime verifies dependencies rather than merely contracting them.
Red flag
The supplier cannot identify who operates or stores material service data.

P18.06W | SD-WAN/SSE/Full SASE

Security incident and data-breach response

State detection, containment, evidence preservation, buyer notification, cooperation, regulatory support, forensic access, lessons learned and contract obligations for incidents affecting the service or its supply chain.

Evidence requested
Redacted exercise or incident timeline and draft notification clause.
Strong response
Notification is time-bound and not delayed until full root cause is known.
Red flag
Notification occurs only when the supplier decides an incident is legally reportable.
P19 - Commercials, licensing, contract and exit

Users, sites, bandwidth, features, logs, support, implementation effort, any of these can move SASE and SD-WAN pricing, and sometimes several move together. Get consumption risk, assumptions, exclusions and exit cost exposed during evaluation, before a preferred supplier's chosen, since it's a much harder conversation to have afterwards.

P19.01M | SD-WAN/SSE/Full SASE

Itemised price schedule

Price implementation, hardware, software, users, sites, bandwidth, security features, logging, support, managed service, circuits, cloud connectivity, training, travel, tax and optional services for the requested term.

Evidence requested
Completed price workbook with units, quantities and recurring/non-recurring totals.
Strong response
Every required outcome has a priced line or is explicitly included.
Red flag
Material costs are deferred to discovery or described as consumption-based without rates.

P19.02M | SD-WAN/SSE/Full SASE

Licence metrics and demand change

Define licence metrics, minimum commits, pooling, burst, true-up, true-down, inactive users, contractors, seasonal sites, mergers, divestments, test environments and the treatment of replaced or failed equipment.

Evidence requested
Worked scenarios for buyer-defined growth and contraction.
Strong response
Permits downward adjustment and avoids double charging during transition.
Red flag
All variability benefits the supplier while buyer commitments only increase.

P19.03W | SD-WAN/SSE/Full SASE

Total cost of ownership

Provide a five-year TCO showing implementation, parallel running, buyer resource, carriers, equipment, licences, managed service, log storage, integration, change, refresh, training, inflation, exit and decommissioning assumptions.

Evidence requested
Editable cost model with assumptions and sensitivity cases.
Strong response
Separates cash cost, buyer effort and avoidable legacy cost.
Red flag
Savings are claimed against an undocumented baseline.

P19.04M | SD-WAN/SSE/Full SASE

Price protection and change control

State indexation, foreign-exchange treatment, pass-through charges, rate-card validity, benchmark or review rights, technology refresh, new-feature pricing and approval requirements for out-of-scope work.

Evidence requested
Draft commercial schedule.
Strong response
Caps or defines exposures and requires written approval.
Red flag
The supplier can reclassify core functions as paid add-ons during term.

P19.05M | SD-WAN/SSE/Full SASE

Contract performance and remedies

Propose service credits, chronic-failure thresholds, remediation plans, termination rights, liability, security obligations, audit rights, subcontractor responsibility and order-of-precedence for proposal commitments.

Evidence requested
Marked-up terms or departures schedule.
Strong response
Repeated material failure has a meaningful remedy beyond small credits.
Red flag
Marketing, demonstrations and response commitments are expressly non-binding.

P19.06M | SD-WAN/SSE/Full SASE

Exit, portability and transition assistance

Describe configuration, policy, log, event, asset, circuit, number, certificate and documentation export; data deletion; licence wind-down; assistance rates; continuing service; and support for migration to a successor.

Evidence requested
Draft exit plan, export formats and maximum charges.
Strong response
Uses documented, machine-readable formats and preserves service during transition.
Red flag
The buyer must manually recreate policy or loses access immediately at contract end.
P20 - Evidence, validation and provider selection

A fair evaluation really comes down to comparable answers and evidence, and very little to do with presentation quality or roadmap promises dressed up nicely for the room. This final pillar makes supplier claims genuinely testable, and it's what turns the whole RFP into something you can actually point back to as a decision record.

P20.01M | SD-WAN/SSE/Full SASE

Compliance and deviation schedule

For every requirement, mark Comply, Partially Comply, Does Not Comply or Roadmap; name the component and licence; state assumptions, limitations, dependencies and any proposed alternative.

Evidence requested
Completed response matrix with no blank cells.
Strong response
Partial compliance is specific and costed.
Red flag
“Comply” relies on custom work, a partner or future functionality that is not disclosed.

P20.02M | SD-WAN/SSE/Full SASE

Claim-to-evidence register

Link every material architecture, feature, performance, security, service and compliance claim to dated product documentation, contract wording, test evidence, a demonstration or a named reference.

Evidence requested
Evidence register with source, owner, date, scope and access method.
Strong response
Evidence applies to the proposed version and region.
Red flag
Evidence is an undated marketing page or relates to a different product tier.

P20.03W | SD-WAN/SSE/Full SASE

Customer references

Provide references comparable in geography, scale, sector, service scope, migration complexity and managed-service model, stating what each reference can validate and any material differences.

Evidence requested
Reference matrix and buyer-authorised contact route.
Strong response
Includes a live customer beyond a curated case study.
Red flag
References use a different platform, deployment model or supplier role.

P20.04PoC | SD-WAN/SSE/Full SASE

Proof of capability commitment

Accept, amend or decline each buyer-defined proof test; state prerequisites, duration, data, equipment, people, cost, success threshold, evidence capture and remediation if a test fails.

Evidence requested
Signed proof plan and test-environment design.
Strong response
Representative production components are used.
Red flag
The proof is replaced by a scripted supplier demonstration.

P20.05M | SD-WAN/SSE/Full SASE

Roadmap and exception treatment

For any roadmap or exception response, state current gap, interim control, committed release, contractual status, dependencies, price and buyer remedy if delivery is late or absent.

Evidence requested
Product-owner confirmation and proposed contract commitment.
Strong response
The solution remains viable if roadmap items never arrive.
Red flag
Selection depends on an uncommitted feature or acquisition integration.

P20.06M | SD-WAN/SSE/Full SASE

Response ownership and accuracy

Name the executive, technical, service and commercial owners who attest that the response describes the exact proposed service, all material suppliers, charges and limitations, and can be incorporated into contract.

Evidence requested
Signed declaration and departures schedule.
Strong response
Commitments survive into the statement of work and service schedules.
Red flag
The supplier reserves the right to redefine the service after award.

Optional sector packs

The governed bank remains available beneath Harry's public 120-question framework. These deeper, sector-specific sets carry buyer and vendor lenses on every question. Browse them in full inside the RFP Builder or via the machine-readable bank.

Retail and e-commerce: 130 questions in 32 sections
SD-WAN: Payment Resilience & Connectivity (3)
  1. Does the solution support per-packet steering to ensure that a primary link "brownout" does not cause a timeout on a live PDQ/POS credit card transaction?
  2. Detail the appliance's ability to manage 4G/5G and Satellite (e.g. Starlink) as active-active underlays. How does the system handle the high-frequency latency spikes inherent in satellite?
  3. Can the appliance trigger a failover based on RSRP/RSRQ (cellular signal quality) thresholds rather than just "Up/Down" status?
SD-WAN: PCI DSS 4.0 & Security Segmentation (2)
  1. Can the solution enforce a hard VRF-level isolation between the Cardholder Data Environment (CDE) and the Guest WiFi network across all sites?
  2. Does the integrated IPS include virtual patching to protect legacy POS hardware that can no longer receive official security updates?
SD-WAN: In-Store WiFi & Customer Analytics (2)
  1. Does the integrated WiFi capability support the export of presence data (RSSI/MAC) to third-party analytics platforms to view dwell times and busy areas of the store?
  2. Can the solution enforce dynamic bandwidth caps on the Guest WiFi VLAN to ensure that a customer watching video doesn't slow down the stock-check application?
SD-WAN: Deployment & Rapid Provisioning (2)
  1. Describe the Zero-Touch Provisioning (ZTP) process for a store using only 4G/5G for the first 30 days. Can the device configure itself via cellular?
  2. How does the solution handle a golden template push to 1,000+ stores? Can site-specific variables (local IPs, VLAN IDs) be managed centrally?
SD-WAN: SLAs, Uptime & Performance (2)
  1. Does the vendor provide a financial SLA based on application performance (latency/jitter) rather than just link uptime?
  2. What is the Mean Time to Repair (MTTR) for a hardware failure in a Tier-1 city versus a remote regional town?
SD-WAN: Support & Operational Models (2)
  1. Can we grant our store managers read-only access to view their own shop's status while keeping write access with the central IT team?
  2. What is the average time for a configuration change to be pushed from the orchestrator to 500 edge devices?
SD-WAN: Reporting & Traffic Performance (2)
  1. Does the reporting dashboard distinguish between in-store sales, inventory sync, and guest traffic?
  2. Can the dashboard show per-user or per-device performance metrics for the last 60 minutes?
SD-WAN: Disaster Recovery & Backup (2)
  1. If the primary data centre hosting the SD-WAN orchestrator fails, what is the recovery time for store management?
  2. Are device configurations backed up automatically? Can a replacement device be restored simply by plugging it in (ZTP)?
SD-WAN: Device Capability & Throughput (2)
  1. What is the total PoE+ power budget of the appliance? Can it power 4 Access Points and 2 IP cameras simultaneously?
  2. What is the maximum throughput when AES-256 encryption and Deep Packet Inspection (DPI) are both enabled?
SD-WAN: Cloud Integration (1)
  1. How does the solution optimise the path from the store directly to our Azure-hosted ERP?
SD-WAN: WiFi Analytics & Customer Profile Data (2)
  1. Does the integrated WiFi solution support the export of anonymised MAC address and RSSI data via API to third-party retail analytics engines?
  2. Does the edge hardware include an integrated BLE radio for push-notifications and wayfinding within large-format stores?
SD-WAN: Traffic Performance & Application Failover (2)
  1. In the event of a link failure, does the solution maintain the session state for persistent TCP applications such as Inventory Management Systems (IMS)?
  2. Can the orchestrator dynamically adjust QoS profiles based on a schedule, such as Black Friday or Boxing Day peak trading hours?
SD-WAN: Admin, Ease of Configuration & Templates (2)
  1. Does the orchestrator provide automated alerts if a local store's configuration deviates from the golden template?
  2. Describe the process for pushing a security policy update to 500+ stores simultaneously. Can these be scheduled for out-of-hours windows automatically?
SD-WAN: DIY, Co-Managed & Fully Managed Models (2)
  1. Can the management portal provide granular Role-Based Access Control (RBAC) so our internal UK IT team can manage store WiFi while the vendor manages core routing?
  2. If a managed service is selected, do you take full ownership of third-party ISP fault reporting and escalation?
SD-WAN: Support, Backup & Disaster Recovery (2)
  1. Is the SD-WAN orchestrator hosted in a geo-redundant cloud environment? What is the impact on store operations if the orchestrator is offline?
  2. Does the edge appliance store a last known good configuration locally for emergency recovery without internet access?
SD-WAN: Reporting & Global Visibility (2)
  1. Can the reporting engine generate a top 10 worst performing sites report based on application latency and jitter?
  2. Can a service desk agent view the real-time performance of a single MAC address (e.g. a specific till) to see its current latency and signal strength?
SD-WAN: Device Capability & Throughput (Continued) (2)
  1. How many LAN ports are available on the branch appliance, and how many support PoE+ (802.3at)?
  2. Is the appliance fanless and rated for deployment in non-ventilated areas, such as a small cabinet under a till?
SD-WAN: Cloud Integration (Omnichannel ERP) (1)
  1. How does the solution automate the on-ramp to our cloud-hosted ERP? Does it use virtual appliances or API-integrated peering?
SSE: Zero Trust Network Access (ZTNA) (10)
  1. Describe the process for providing agentless, browser-based access to internal web-based POS management tools for third-party vendors.
  2. How does the ZTNA policy handle identity-aware access for staff who float between different retail branches?
  3. Does the ZTNA service mask internal store assets from public internet discovery (the dark cloud effect)?
  4. Can the solution enforce least privilege access, restricting a maintenance vendor to a single IP/Port on a specific store controller?
  5. Detail the session persistence logic when a store manager switches from the back-office WiFi to a 4G/5G mobile connection.
  6. Describe the inside-out connectivity model. Does it require any inbound ports (e.g. 443) to be opened on the store firewall?
  7. How does the ZTNA service handle high-latency links (e.g. Starlink or busy 4G) for RDP-based machine maintenance?
  8. Can the solution trigger a re-authentication prompt specifically when a user attempts to access sensitive production databases?
  9. Does the solution support continuous identity verification throughout the duration of the session?
  10. What is the average millisecond overhead added by your UK-based ZTNA brokers for a UK-to-UK connection?
SSE: Secure Web Gateway (SWG) (10)
  1. Can the SWG enforce a read-only policy for web-based personal email to prevent store staff from exfiltrating customer lists?
  2. Detail the latency overhead for TLS 1.3 decryption for users accessing web-based POS systems.
  3. How does the gateway handle newly registered domains (NRDs) registered within the last 24 hours?
  4. Can the SWG block specific in-app functions, such as disabling the share button in LinkedIn or upload in Dropbox?
  5. Does the solution provide coaching pages that explain to a staff member why a site was blocked, in plain English?
  6. Describe the local breakout logic for trusted UK government or banking sites to reduce PoP load.
  7. How does the SWG handle credential phishing detection at the page-rendering level?
  8. Is there a bypass mechanism for specific mission-critical URLs that may break under SSL inspection?
  9. Can the SWG generate a top 10 high-risk users report based on web-browsing behaviour across the retail estate?
  10. Does the SWG integrate with your remote browser isolation (RBI) for uncategorised or suspicious URLs?
SSE: Cloud Access Security Broker (CASB) (10)
  1. Can the CASB distinguish between our corporate Microsoft 365 tenant and an employee's personal OneDrive account?
  2. Does the CASB provide real-time user entity behaviour analytics (UEBA) to detect bulk downloads from the cloud ERP?
  3. How does the CASB secure data accessed from unmanaged devices (e.g. an executive's home iPad)?
  4. Can the solution automatically redact sensitive customer data (like card numbers) as it appears in a cloud-based CRM?
  5. Describe the process for automatically unsharing a file that has been shared with an external Gmail/Outlook account.
  6. Does the CASB offer API-based scanning of our existing cloud data (at rest)?
  7. Can the CASB block app-to-app permissions (OAuth) for high-risk third-party integrations?
  8. How frequently is the cloud app discovery database updated with new SaaS ratings?
  9. Can the CASB detect impossible travel alerts (e.g. a login from London and Manchester within 5 minutes)?
  10. Does the CASB support self-healing remediation for M365 configuration drift?
SSE: Data Loss Prevention (DLP) (10)
  1. Can the DLP engine perform OCR on images to identify PDQ receipts or credit card numbers?
  2. Does the solution support exact data matching (EDM) for our specific 12-digit loyalty card formats?
  3. How does the DLP handle data in motion across encrypted chat applications like Slack or Teams?
  4. Can the DLP engine detect partial document matching for engineering or marketing designs?
  5. Describe the justification workflow when a user is blocked from sending a file.
  6. Can the DLP scan within compressed file formats (e.g. .zip, .rar) and multi-level nested folders?
  7. Does the system provide pre-built templates for the UK Data Protection Act 2018?
  8. Can the system prevent data exfiltration via print screen or copy to clipboard for web-based apps?
  9. How does the DLP engine handle fingerprinting of sensitive PDF or Excel templates?
  10. What is the process for triaging DLP alerts? Is there a dedicated forensics dashboard for our UK security officer?
SSE: Remote Browser Isolation (RBI) (10)
  1. Can RBI be triggered automatically for uncategorised websites visited from in-store kiosks?
  2. Does the RBI support pixel-pushing rendering to ensure no active code reaches the store endpoint?
  3. Can you enforce read-only mode within an RBI session to prevent any file downloads?
  4. How does the RBI handle clipboard controls? Can we block copy/paste between the isolated browser and the local machine?
  5. Does the RBI service sanitise downloaded files by converting them to safe PDFs?
  6. Describe the performance impact for streaming video (e.g. YouTube training) through an isolated browser.
  7. Can the RBI be used for safe previewing of email attachments?
  8. Is the RBI solution natively integrated into your SWG agent, or is it a separate client?
  9. Can we set a timed session for RBI to automatically log out users after their break?
  10. Does the RBI solution support in-session keyboard and mouse event monitoring for forensics?
SSE: Firewall as a Service (FWaaS) (10)
  1. Does the cloud firewall support geo-blocking to prevent all traffic from high-risk regions from hitting our till systems?
  2. Can the FWaaS enforce different security rules based on the store format (e.g. Flagship vs. Express)?
  3. Describe the local breakout capability for direct internet access at the store edge while maintaining cloud-delivered security.
  4. How does the FWaaS handle IP reputation filtering for incoming connections?
  5. Does the FWaaS provide dedicated egress IPs for our retail estate?
  6. Can the FWaaS perform Layer-7 application inspection to block proxy-bypass tools like Ultrasurf?
  7. Describe the failover process between your cloud PoPs. If your London PoP goes down, where does our traffic go?
  8. Can the FWaaS generate a top 10 blocked attacks report for our monthly security board meeting?
  9. How does the FWaaS integrate with our identity provider (Azure AD) for user-aware firewall rules?
  10. Is the FWaaS policy engine version controlled? Can we roll back a change if it breaks store connectivity?
SSE: IPS / IDS (5)
  1. Does the IPS provide virtual patching for legacy POS hardware that can no longer receive official security updates?
  2. How quickly are zero-day signatures updated in your global IPS engine?
  3. Does the IPS identify lateral movement attempts between store till VLANs and office VLANs?
  4. Does the IPS support high-throughput inspection for busy data centre backhaul links?
  5. Can the IPS generate an automated alert for DDoS activity targeting a specific store?
SSE: DNS Security (5)
  1. How does the DNS security layer handle command & control (C2) callbacks from infected IIoT devices?
  2. Can we enforce different DNS policies for guest WiFi versus staff WiFi?
  3. Does the DNS filtering support SafeSearch enforcement for search engines and YouTube?
  4. How does the system handle DNS over HTTPS (DoH) which often bypasses traditional filters?
  5. Can the DNS service provide a geo-heatmap of where blocked requests are trying to go?
SSE: Device Posture / Endpoint Context (10)
  1. Can access to the central Inventory system be denied if the device's antivirus is disabled or out of date?
  2. Does the posture check verify that disk encryption (BitLocker) is active before granting a ZTNA session?
  3. Can the system distinguish between a corporate managed laptop and a personal device?
  4. Does the posture check integrate natively with our EDR (e.g. CrowdStrike) to pull risk scores?
  5. Can we enforce a minimum OS version for all handheld scanners on the floor?
  6. Describe the remediation workflow for a user whose device fails a posture check.
  7. Can the posture check verify the presence of a specific corporate certificate in the local store?
  8. How frequently is the device posture re-evaluated during an active session?
  9. Can we set different posture requirements based on the sensitivity of the application?
  10. Does the posture check support geo-fencing? (e.g. deny access if the device is physically outside the UK).
SSE: SaaS Security Posture Management (SSPM) (2)
  1. Does the SSPM tool provide automated remediation for misconfigurations in our SAP S/4HANA or Microsoft 365 tenants?
  2. Can the SSPM audit the app-to-app permissions (OAuth) granted by our employees to third-party cloud tools?
SSE: Cloud Email Security (1)
  1. How does the solution protect against Business Email Compromise (BEC) and look-alike domain attacks targeting our supply chain?
SSE: Threat / Malware Protection — ATP & Sandboxing (1)
  1. Does the sandbox environment support human-interaction simulation to defeat malware that waits for a mouse click before executing?
SSE: Identity & Access (IdP) Integration (1)
  1. Does the solution support SCIM for automated user provisioning and de-provisioning?
SASE: Converged Outcomes (10)
  1. Does the SASE solution utilise a SLA-backed private Tier-1 backbone for the middle mile?
  2. Describe the techniques used to optimise traffic across the global backbone, specifically regarding TCP Window Scaling and Packet Loss Mitigation.
  3. Detail how the SASE fabric provides direct cloud on-ramp to our ERP instance in Azure (UK South) without hair-pinning traffic.
  4. Can the SASE orchestrator manage Transit Gateway Peering across multiple cloud providers (e.g. AWS and Google Cloud) through a single interface?
  5. Does the solution offer application-specific acceleration for non-web protocols such as CIFS/SMB or MAPI?
  6. How does the solution ensure low-latency access for UK-based mobile users who are travelling to high-risk regions or areas with poor local peering?
  7. In a fully managed SASE model, who is the single point of contact for an end-to-end performance issue?
  8. What is the SLA for emergency security changes (e.g. blocking a specific IP during an active attack)?
  9. Does the managed SASE portal allow our internal team to view real-time digital experience metrics for individual store users?
  10. Can you provide static, dedicated egress IPs for our SASE traffic to ensure compatibility with our suppliers' IP-whitelisting firewalls?
Manufacturing: 117 questions in 15 sections
SD-WAN: The "OT-First" Performance Fabric (35)
  1. Can the solution dynamically steer traffic based on a Jitter threshold of <5ms?
  2. Can the system enable 1:1 Packet Duplication across dual-active circuits for critical safety/PLC traffic?
  3. Can the appliance trigger a failover based on RSRP/RSRQ thresholds rather than just a simple "Up/Down" ping?
  4. Detail the bandwidth overhead of your FEC algorithm when set to "Aggressive" mode.
  5. Does the solution support Starlink, 4G, and Fibre as active-active underlays without proprietary exchange equipment, especially in regions with diverse infrastructure risks?
  6. How does the solution specifically optimise non-cacheable SAP S/4HANA traffic into Azure/AWS?
  7. State the average millisecond latency between your primary UK PoP and the London Azure region (UK South).
  8. Does the system support "Local Breakout" for Microsoft 365 based on URL-path recognition?
  9. Do you offer TCP Termination to mitigate the impact of high-latency global hops on large file transfers?
  10. Can the orchestrator automatically provision VPN peering into Google Cloud (GCP) via a native API?
  11. State the AES-256 encrypted throughput with all security features (IPS/DPI) enabled.
  12. Do you offer hardware with IP67 rating or fanless designs for high-temperature machine cabinets?
  13. Does the edge appliance feature physical RS-232/485 ports for legacy machine connectivity?
  14. Does the appliance support Native WiFi 6 for rugged handheld scanners on the plant floor?
  15. Does the hardware support dual internal power supplies or 24V/48V DC inputs?
  16. Can we push a single "Golden Configuration" to 100+ sites simultaneously while maintaining site-specific variables?
  17. Describe the ZTP process: Does it require a "Staging" phase or is it truly "Plug-and-Play"?
  18. Describe the safety mechanism if a scheduled firmware update fails at a remote site.
  19. Can we grant "Read-Only" access to local OT engineers for diagnostics while central IT retains "Write" rights?
  20. Can the platform export network health data via REST API into our existing OEE dashboard?
  21. Can we retain control over Application Routing Policies while you manage the physical hardware and OS?
  22. What is the Mean Time to Repair (MTTR) for a hardware failure at a global site?
  23. What is the average "Config Propagation Time" from the orchestrator to 50 edge devices globally?
  24. Can your service desk manage third-party ISP tickets on our behalf using our existing LOAs?
  25. What site-specific documentation (e.g. "As-Built" diagrams) is provided post-deployment?
  26. Can the system map internal DSCP/CoS tags from the factory floor directly into SD-WAN priority queues?
  27. Can the SD-WAN create isolated "Islands" for OT vs IT traffic at Layer 2?
  28. Does the dashboard provide per-packet granularity reporting for the last 24 hours of traffic?
  29. Does the integrated IPS include specific signatures for SCADA/ICS vulnerabilities?
  30. What is the financial penalty/service credit if the "Application Performance SLA" is missed?
  31. Is the solution fully IPv6-ready for modern Industrial IoT (IIoT) sensor integration?
  32. How many PoE+ ports are available on the branch appliance to power local IP cameras?
  33. Can the IPS shield Legacy Windows XP/7 machines from "EternalBlue" style exploits?
  34. Quantify the latency overhead added by the encryption engine during high-throughput loads.
  35. Does the solution include DNS-layer protection to stop malware "phone-home" attempts from the factory?
SSE: Zero Trust Network Access (ZTNA) (10)
  1. Does the solution support an "Inside-Out" connectivity model that allows internal factory resources to remain invisible to the public internet?
  2. Describe the process for providing agentless, browser-based access to legacy web HMIs for third-party maintenance contractors.
  3. Can the ZTNA policy be restricted by time-of-day and specific geographical location for shop-floor management systems?
  4. How does the solution handle session persistence for industrial applications that are sensitive to micro-outages or IP address changes?
  5. Does the ZTNA service provide full Layer-4 protocol support, including RDP, SSH, and specific industrial protocols like Modbus/TCP?
  6. Can the solution perform a "Posture Check" to verify that a contractor's laptop has active antivirus and disk encryption before allowing a ZTNA connection?
  7. Describe the logging granularity: Does the system record every click/action within a session, or just the initial connection event? How does this logging stand up to forensic requirements in high-risk regions?
  8. How does the ZTNA solution mitigate the risk of "Lateral Movement" if a single user account is compromised?
  9. Can the ZTNA connector be deployed in a high-availability (HA) cluster within our local data centre?
  10. What is the average latency overhead introduced by the ZTNA cloud broker for a user in the UK accessing a resource in a UK-based factory?
SSE: Secure Web Gateway (SWG) (10)
  1. Detail your capability to inspect TLS 1.3 encrypted traffic at scale without impacting the performance of cloud-hosted ERP systems.
  2. Can the SWG enforce a "Read-Only" policy for web-based personal email or social media to prevent attachment uploads?
  3. How does the gateway handle URL filtering for sites categorised as "Malicious," "Newly Registered Domains," or those associated with known state-sponsored threats prevalent in high-risk regions?
  4. Does the SWG provide native protection against "Credential Phishing" by identifying when a user is typing their corporate password into a non-corporate site?
  5. Can you apply different web-filtering profiles based on the machine type (e.g. a kiosk on the floor vs a designer's workstation)?
  6. Describe the "Safe Search" enforcement for image and video platforms used for staff training.
  7. How does the solution handle "File Type Control"? Can we block the download of executable (.exe) files while allowing PDFs?
  8. Is the SWG capable of "Inline Sandboxing" for files downloaded from the internet?
  9. How does the system handle "Bandwidth Throttling" for non-essential web traffic (e.g. video streaming) during high-production hours?
  10. Can the gateway generate reports showing "High Risk" user behaviour that could indicate a compromised account or an insider threat?
SSE: Cloud Access Security Broker (CASB) (10)
  1. Can the CASB distinguish between a corporate-managed instance of a cloud application and a personal instance of the same application?
  2. Describe the process for automatically "quarantining" sensitive files found in cloud storage that have been shared with unauthorised external email addresses.
  3. How does the solution identify anomalous behaviour, such as a single user downloading an unusually high volume of data from the ERP or cloud storage, especially when originating from or destined for high-risk regions?
  4. Does the CASB provide a "Risk Score" for new cloud applications discovered on the network, and what criteria are used for this score?
  5. Can the solution enforce "Step-up Authentication" (MFA) specifically when a user attempts to access a high-risk folder within a SaaS application?
  6. How does the CASB protect data being accessed from unmanaged devices (e.g. an employee's home PC) without requiring an agent?
  7. Can the CASB inspect the content of encrypted files (e.g. password-protected ZIPs) being uploaded to cloud services?
  8. Describe the integration between the CASB and the Secure Web Gateway (SWG) for consistent policy enforcement.
  9. Can the system automatically "Mask" or "Redact" sensitive data (like customer credit card numbers) as it is being viewed in a cloud application?
  10. How frequently is the "Cloud App Discovery" database updated with new SaaS applications and their security ratings?
SSE: Data Loss Prevention (DLP) (10)
  1. Does the DLP engine support "Exact Data Matching" (EDM) for protecting our specific manufacturing part numbers or chemical formulas, especially considering the increased risk of industrial espionage in certain regions?
  2. Can the DLP solution identify sensitive information within images or scanned documents (OCR)?
  3. How does the system handle DLP for "Data in Motion" versus "Data at Rest" in cloud storage?
  4. Can the DLP engine detect "Partial Matches" or "Small Snippets" of proprietary code or engineering data?
  5. What is the process for a user to "Justify" a DLP block if they believe it is a false positive?
  6. How does the solution prevent the exfiltration of data via "Printing" or "Copying to Clipboard" for remote users?
  7. Can the DLP system scan compressed files (e.g. .7z, .rar) and nested folders within those files?
  8. Does the DLP solution offer a "Unified Policy Builder" that works across Email, Web, and Cloud?
  9. How are DLP incidents triaged? Is there a dedicated "Incident Management" dashboard for our security officer?
  10. Does the system provide "Out-of-the-Box" templates for UK-specific regulations like the Data Protection Act 2018?
SSE: Remote Browser Isolation (RBI) (10)
  1. Does the RBI solution support "Pixel-pushing" rendering to ensure that no active web content or code ever reaches the local endpoint?
  2. Can the solution enforce "Read-Only" mode for web-based document viewing to prevent the downloading of proprietary engineering files?
  3. Describe the user experience impact (latency) when RBI is triggered for "Uncategorised" or "High-Risk" websites.
  4. How does the RBI handle "Clipboard Controls" between the isolated browser and the user's local applications?
  5. Can the RBI service "Sanitise" downloaded files by converting them to a safe PDF before they reach the user?
  6. Does the solution support "Targeted RBI" where only high-risk URLs are isolated, rather than the entire web session?
  7. Can RBI be used as a "Secure Virtual Desktop" for third-party vendors to access internal web-based HMIs?
  8. Describe how the RBI handles streaming media (e.g. training videos) and interactive web elements like maps or 3D CAD viewers.
  9. How are "Isolated Sessions" logged for audit purposes? Do you record a video of the session or just text-based activity?
  10. Is the RBI solution natively integrated into the SSE agent, or does it require a separate browser extension or client?
SSE: Firewall as a Service (FWaaS) (10)
  1. Does the FWaaS support Identity-Aware Rules that follow a user from the factory floor to their home office?
  2. Detail the FWaaS capability to perform Layer-7 Application Identification for industrial protocols like Modbus, S7, and OPC-UA.
  3. Can the FWaaS enforce Geo-Blocking at the network layer to prevent any traffic from high-risk regions reaching our production servers, with dynamic threat intelligence for rapidly changing geopolitical landscapes?
  4. How does the FWaaS handle IPsec VPN Terminations from small, remote IoT gateways or sensors?
  5. What is the "Egress IP" strategy? Do our sites share a public IP with other customers, or can we have a Dedicated Static IP for our cloud firewall?
  6. Describe the FQDN-based Filtering capabilities for managing software update paths for factory machinery.
  7. Does the FWaaS include a Global Policy Manager to push rule changes to all international sites simultaneously?
  8. How does the FWaaS handle Large File Transfers (FTP/SFTP) between manufacturing sites and external partners?
  9. Can the FWaaS generate an alert if it detects "Port Scanning" or "Reconnaissance" activity originating from within our own factory floor?
  10. What is the SLA for Service Availability for the FWaaS? Is it backed by financial credits if the cloud firewall goes offline?
SSE: Intrusion Prevention & Detection (IPS/IDS) (4)
  1. Does the IPS service include a dedicated signature set for Industrial Control Systems (ICS) and SCADA protocols?
  2. Can the IPS perform Virtual Patching for legacy operating systems (e.g. Windows XP, Windows 7) that can no longer receive official security updates?
  3. Describe the "Fail-Open" vs "Fail-Closed" logic of the IPS engine during a period of extreme traffic congestion or cloud PoP resource exhaustion.
  4. How does the IDS/IPS identify Lateral Movement attempts between different factory segments or VLANs?
SSE: DNS Security (Protective DNS) (2)
  1. How does the DNS filtering layer handle "Newly Registered Domains" (NRDs) and "Domain Generation Algorithms" (DGAs)?
  2. Can we enforce different DNS policies for IIoT sensors versus office-based staff laptops?
SSE: SaaS Security Posture Management (SSPM) (2)
  1. Does the SSPM tool provide automated remediation for misconfigurations in our SAP S/4HANA or Microsoft 365 tenants?
  2. Can the SSPM audit the "App-to-App" permissions (OAuth) granted by our employees to third-party cloud tools?
SSE: Cloud Email Security (1)
  1. How does the solution protect against Business Email Compromise (BEC) and "Look-alike" domain attacks targeting our supply chain?
SSE: Threat / Malware Protection (ATP & Sandboxing) (1)
  1. Does the sandbox environment support "Human-Interaction Simulation" to defeat malware that waits for a mouse click before executing?
SSE: Identity & Access (IdP) Integration (1)
  1. Does the solution support SCIM (System for Cross-domain Identity Management) for automated user provisioning and de-provisioning?
SSE: Device Posture / Endpoint Context (1)
  1. Can the system deny access to the production environment if the device's Anti-Virus (EDR) is disabled or if a specific "Corporate Certificate" is missing?
SASE: Converged Outcomes (10)
  1. Does the SASE solution utilise a SLA-backed Private Tier-1 Backbone for the "Middle Mile", or does it rely on encrypted tunnels over the public internet?
  2. Describe the techniques used to optimise traffic across the global backbone, specifically regarding TCP Window Scaling and Packet Loss Mitigation.
  3. Detail how the SASE fabric provides Direct Cloud On-Ramp to our SAP S/4HANA instance in Azure (UK South) without "Hair-pinning" traffic through a central data centre.
  4. Can the SASE orchestrator manage Transit Gateway Peering across multiple cloud providers (e.g. AWS and Google Cloud) through a single interface?
  5. Does the solution offer Application-Specific Acceleration for non-web protocols such as CIFS/SMB or MAPI?
  6. How does the solution ensure low-latency access for UK-based mobile users who are travelling to high-risk regions or areas with poor local peering?
  7. In a Fully Managed SASE model, who is the "Single Point of Contact" for an end-to-end performance issue involving a third-party ISP and the cloud security layer?
  8. What is the SLA for Emergency Security Changes (e.g. blocking a specific IP during an active attack) in a managed service environment?
  9. Does the Managed SASE Portal allow our internal team to view real-time "Digital Experience" metrics for individual shop-floor users?
  10. Can you provide Static, Dedicated Egress IPs for our SASE traffic to ensure compatibility with our suppliers' IP-whitelisting firewalls?
Financial services: 82 questions in 15 sections
SD-WAN: Low-Latency Financial Network Fabric (16)
  1. Can the solution perform per-packet path steering in under 1ms to prevent trading order execution delays during link degradation?
  2. Does the solution support 1:1 packet duplication across dual-active circuits for real-time payment processing and settlement traffic?
  3. Can the SD-WAN enforce dedicated QoS queues for real-time market data feeds, separating them from general branch internet and voice traffic?
  4. Detail the bandwidth overhead of your Forward Error Correction (FEC) algorithm in Aggressive mode on a 1Gbps trading floor uplink.
  5. How does the solution optimise the path from branch offices to cloud-hosted core banking platforms (e.g. Temenos, Finastra on Azure/AWS)?
  6. State the average millisecond latency between your primary UK PoP and the London Azure region (UK South) and AWS eu-west-2.
  7. State the AES-256 encrypted throughput when IPS, DPI, and application identification are all simultaneously enabled on the branch appliance.
  8. Does the solution support 4G/5G and satellite as active-active underlays? How is high-frequency jitter from satellite smoothed for payment traffic?
  9. Describe the ZTP process for a new bank branch. Can a non-technical branch manager plug in the device and have it configure itself automatically?
  10. Can a single golden security and routing template be pushed to 200+ financial services branches simultaneously, with site-specific variables managed centrally?
  11. Can we grant regional IT teams read-only diagnostics access while central security operations retain full write access to routing and firewall policies?
  12. Does the orchestrator generate automated alerts if a branch device's configuration deviates from the approved golden template?
  13. Describe the safety mechanism if a firmware update fails at a remote branch during overnight maintenance windows.
  14. Do you offer a financial SLA based on application-level performance metrics (latency and jitter) rather than simply link uptime percentage?
  15. If a managed service is selected, do you take full ownership of third-party ISP fault reporting, escalation, and resolution on our behalf?
  16. If the primary SD-WAN orchestrator suffers an outage, what is the impact on branch operations and what is the RTO for management restoration?
SSE: Zero Trust Network Access (ZTNA) (9)
  1. Does the ZTNA solution use an inside-out connectivity model, ensuring internal banking applications are never exposed to public internet scanning?
  2. Can the solution provide agentless, browser-based ZTNA access to internal systems for external auditors or regulatory inspectors who cannot install software?
  3. Can ZTNA policies be restricted by time-of-day, such as blocking access to trading platforms outside market hours unless explicitly authorised?
  4. How does the ZTNA solution prevent lateral movement if a trader or advisor's account is compromised?
  5. Does the solution continuously re-evaluate user risk scores throughout the duration of a session, and can it terminate an active session if risk increases?
  6. Can the ZTNA policy trigger a step-up MFA prompt when a user attempts to access specific high-value transaction systems or payment authorisation portals?
  7. Does the system provide granular, immutable audit logs of every access event, including session duration, actions taken, and data accessed, for regulatory examination?
  8. Can the ZTNA connector be deployed in a high-availability cluster to ensure that a single connector failure does not interrupt access to critical banking systems?
  9. What is the average latency overhead introduced by the ZTNA cloud broker for a UK-based user accessing a UK data centre application?
SSE: Secure Web Gateway (SWG) (7)
  1. Detail your capability to inspect TLS 1.3 encrypted web traffic at scale without impacting the performance of cloud-hosted financial applications.
  2. Does the SWG provide protection against credential phishing by detecting when a user is typing their corporate credentials into a fraudulent login page?
  3. How does the gateway handle newly registered domains (NRDs) and domain generation algorithm (DGA) traffic used by malware command-and-control infrastructure?
  4. Can the SWG enforce a read-only policy for personal cloud storage and webmail to prevent staff from uploading customer financial data to personal accounts?
  5. Can the SWG allow trusted financial and regulatory domains (e.g. FCA, Bank of England, SWIFT) to break out locally without full SSL inspection?
  6. Can the SWG generate reports identifying high-risk user browsing behaviour patterns that could indicate a compromised account or insider threat?
  7. Is the SWG capable of inline sandboxing for files downloaded by financial staff, holding delivery until the sandbox verdict confirms the file is safe?
SSE: Cloud Access Security Broker (CASB) (8)
  1. Can the CASB distinguish between a corporate-managed Microsoft 365 or Salesforce tenant and an employee's personal account of the same application?
  2. How does the CASB identify anomalous behaviour such as a staff member bulk-downloading customer account records or pricing models from cloud systems?
  3. Does the CASB provide a risk score for unsanctioned cloud applications discovered on the network, assessed against financial services compliance standards?
  4. Can the CASB automatically redact sensitive customer financial data (account numbers, sort codes, card numbers) as it appears in cloud-based CRM systems?
  5. How does the CASB protect financial data accessed from unmanaged devices such as an employee's personal laptop or a contractor's device?
  6. Can the CASB automatically quarantine or remove sharing permissions on files containing financial data that have been accidentally shared with external email addresses?
  7. Can the CASB audit and revoke OAuth app-to-app permissions that employees have granted to third-party cloud integrations?
  8. Does the CASB offer API-based scanning of existing cloud data at rest to identify historical exposure of customer financial data?
SSE: Data Loss Prevention (DLP) (9)
  1. Does the DLP engine support Exact Data Matching (EDM) for specific customer account numbers, IBAN formats, and sort codes held in our systems?
  2. Can the DLP engine perform OCR on images and scanned documents to identify account numbers, payment details, or regulatory classifications within image files?
  3. Can the DLP engine detect partial matches of proprietary financial models, pricing schedules, or regulatory reports if only a fragment is copied or sent?
  4. How does the DLP solution handle data in motion across encrypted collaboration tools such as Microsoft Teams, Slack, or Bloomberg Terminal chat?
  5. Can the solution prevent exfiltration of financial data via clipboard copy or screen capture from web-based banking and trading applications?
  6. What is the process for a user to justify and override a DLP block if they believe it is a false positive on a legitimate financial communication?
  7. Can the DLP system scan inside compressed files (.zip, .7z, password-protected archives) to inspect financial data before it leaves the network?
  8. Does the DLP system include out-of-the-box policy templates for UK GDPR, the Financial Services and Markets Act, and PCI DSS 4.0?
  9. How are DLP incidents triaged? Is there a dedicated forensics dashboard providing a clear chain of evidence for the information security officer and legal team?
SSE: Remote Browser Isolation (RBI) (6)
  1. Does the RBI solution use pixel-pushing rendering so that no active web content from counterparty or vendor portals ever executes on a financial staff member's endpoint?
  2. Can RBI enforce read-only mode for specific financial or regulatory portal sessions, preventing downloads of documents to the local endpoint?
  3. Can the RBI service sanitise downloaded documents — stripping macros and active content — before they reach a financial staff member's endpoint?
  4. Does the SWG integrate with RBI so that uncategorised or high-risk websites are automatically isolated rather than blocked outright?
  5. How are isolated sessions logged for compliance and forensic purposes? Are URL access logs and session activity captured with timestamps?
  6. What is the latency overhead when RBI is triggered for financial research or market data sites used by analysts and traders?
SSE: Firewall as a Service (FWaaS) (6)
  1. Does the FWaaS enforce identity-aware firewall policies that follow a staff member from the office to their home network without requiring policy reconfiguration?
  2. Can the FWaaS enforce geo-blocking to prevent inbound connections from high-risk regions to payment systems and core banking infrastructure?
  3. Can you provide static, dedicated egress IPs for our SASE traffic to maintain compatibility with correspondent banks and financial counterparties that enforce IP whitelisting?
  4. If your primary UK PoP fails, how is financial services traffic rerouted and what is the maximum expected performance degradation during failover?
  5. Is the FWaaS policy engine version-controlled? Can a change that causes unintended disruption to payment processing be rolled back within minutes?
  6. Can the FWaaS generate board-ready threat reports showing top blocked attack categories, source geographies, and threat trends for our quarterly security committee?
SSE: Intrusion Prevention & Detection (IPS/IDS) (4)
  1. Does the IPS include specific threat intelligence and signatures for financial malware families targeting banking systems (e.g. Emotet, Dridex, QakBot, TrickBot)?
  2. How quickly are zero-day signatures pushed to the IPS engine following a new threat disclosure targeting financial services infrastructure?
  3. Can the IPS detect and block lateral movement attempts between financial system VLANs, such as a workstation attempting to scan the payment processing subnet?
  4. Can the IPS generate automated alerts for DDoS activity targeting specific payment gateway or core banking IP ranges?
SSE: DNS Security (Protective DNS) (2)
  1. How does the DNS security layer block newly registered domains and command-and-control infrastructure used by financially motivated threat actors?
  2. Can different DNS filtering policies be enforced for payment processing systems versus general staff endpoints?
SSE: SaaS Security Posture Management (SSPM) (2)
  1. Does the SSPM tool provide automated remediation for misconfigurations in Microsoft 365, Salesforce Financial Services Cloud, or other critical SaaS platforms?
  2. Can the SSPM benchmark SaaS configurations against CIS Controls and FCA operational resilience expectations, generating evidence for regulatory examination?
SSE: Cloud Email Security (2)
  1. How does the solution protect against Business Email Compromise (BEC) and look-alike domain attacks targeting financial counterparties and correspondent banks?
  2. Does the solution enforce DMARC, DKIM, and SPF validation for all inbound email, and can it prevent spoofing of the organisation's own domain?
SSE: Threat / Malware Protection (ATP & Sandboxing) (1)
  1. Does the sandbox support human-interaction simulation to detonate evasive malware specifically designed to remain dormant in automated analysis environments?
SSE: Identity & Access (IdP) Integration (1)
  1. Does the solution support SCIM for automated user provisioning and immediate de-provisioning when a staff member leaves the organisation?
SSE: Device Posture / Endpoint Context (2)
  1. Can the solution block access to financial systems if a device's EDR agent is disabled, disk encryption is inactive, or the device OS is below the minimum approved version?
  2. Can the solution distinguish between a corporate-managed device and a personal device, enforcing significantly more restrictive access policies for personal devices?
SASE: Converged Outcomes (7)
  1. Does the SASE solution use a contractually backed private Tier-1 backbone for the middle mile, rather than encrypted tunnels over the public internet?
  2. How does the SASE fabric provide direct cloud on-ramp to cloud-hosted financial platforms (e.g. Temenos on Azure, Finastra on AWS) without hair-pinning through a central data centre?
  3. Describe the TCP optimisation techniques used to accelerate SWIFT messaging and settlement traffic across high-latency global WAN paths.
  4. In a fully managed SASE model, who is the single point of accountability for an end-to-end performance issue spanning the ISP, the SASE backbone, and the cloud application?
  5. What is the contractual SLA for emergency security changes — such as blocking a specific IP during an active payment fraud campaign or ransomware attack?
  6. Does the managed SASE portal provide real-time digital experience monitoring at a per-user level, enabling rapid triage of performance complaints from branch staff?
  7. Can the SASE platform generate reports aligned to DORA (Digital Operational Resilience Act) requirements, including ICT incident classification, third-party dependency mapping, and resilience testing evidence?
Healthcare: 30 questions in 6 sections
Vendor Pedigree & Healthcare Track Record (4)
  1. Healthcare Operational Scale
  2. Peer References & Customers
  3. Specialised Clinical Support Teams
  4. Financial Stability & Long-term Strategy
Infrastructure, PoPs & Connectivity Underlay (6)
  1. Private Backbone & PoP Proximity
  2. Private vs. Public Gateway Options
  3. Managed Connectivity Underlay
  4. LTE/5G Failover for Community Sites
  5. HSCN Peering & Integration
  6. FirstNet & Public Safety LTE
SASE Features & Clinical Security (7)
  1. Clinical Application-Aware Routing
  2. Sub-Second Session Persistence
  3. Medical Protocol Support
  4. IoMT & Medical Device Isolation
  5. ZTNA for Shared Workstations
  6. DLP for Clinical Identifiers
  7. TLS 1.3 Inspection Performance
Operations, Reporting & SLAs (5)
  1. Digital Experience Monitoring (DEM)
  2. Managed vs. Co-Managed Flexibility
  3. Support SLA for Acute Sites (Clinical P1)
  4. Automated Compliance Reporting
  5. Real-Time Analytics & Shift-Change Heatmaps
Deployment & Regional Compliance (8)
  1. Zero-Touch Provisioning Lead Times
  2. Adds, Moves, and Changes (MACDs)
  3. DSPT Version 8 & DTAC Alignment
  4. Clinical Safety Officer (CSO) & DCB0129
  5. Business Associate Agreement (BAA)
  6. TEFCA & QHIN Connectivity
  7. Patient Data Residency & Sovereignty
  8. NHS Net Zero & Social Value
Bespoke Requirements (0)

    Frequently asked questions

    What questions should a SASE RFP include?

    A SASE RFP needs to test far more than which vendor ticks the most product boxes. In our view, it should genuinely test business outcomes, current network and application dependencies, and supplier accountability, alongside the full technical stack: SASE architecture and SD-WAN, global backbone, ZTNA, endpoint and third-party access, secure web gateway, CASB, DLP, FWaaS, threat prevention, logging and policy governance, resilience, implementation, managed service, compliance, pricing, and exit.

    That's a lot to cover, and product-support questions alone genuinely aren't enough to get you there. Each material requirement should ask for:

    The offered component itself,

    The licence it sits under,

    Any limitation or third-party dependency,

    The evidence behind the claim.

    Buyers should also flag upfront which of these claims actually need a proof test, rather than just taking a supplier at their word.

    We organise all of this into 20 procurement pillars and 120 core supplier questions at Netify, with optional overlays for the likes of manufacturing, healthcare, retail and financial services depending on the sector you're buying into. The same framework can be filtered for an SD-WAN-only, SSE-only, full SASE, managed SASE or phased procurement too, so suppliers only get scored against the requirements that are actually relevant to the intended service, rather than being marked down for gaps that were never in scope to begin with.

    How can buyers compare SASE vendors fairly?

    The short answer is that fairness comes down to consistency: every supplier needs the same scope, response fields, evidence standard, commercial model and scoring scale, or you're not really comparing like for like at all. Mandatory requirements should sit as straightforward pass/fail gates, whilst weighted answers get scored somewhere on a 0 to 5 scale, depending on the quality and applicability of the evidence behind them.

    It's also worth the evaluation distinguishing between what's actually generally available versus what's beta, roadmap, custom or dependent on a third party, since these get conflated far more often than they should. Five-year cost should be normalised too, assumptions recorded, and the claims most likely to actually change the decision tested properly rather than taken on trust.

    We built our own framework around stable question IDs, a claim-to-evidence register and buyer-observed proof tests, so evaluators can trace any given score right back to the supplier's response and its source. In our experience, that creates a genuinely more defensible shortlist than comparing sales presentations, product matrices, or headline licence prices that all use different definitions and quietly exclude different delivery costs.

    Why use a vendor-neutral SASE RFP template?

    Starting from your own services, risks and operating model rather than one vendor's product architecture is really the whole point of going vendor-neutral in the first place. It lets suppliers propose different ways of meeting the same outcome, whilst still forcing them to disclose the gaps, third-party components, licensing and evidence that a lot of them would rather leave out.

    Vendor templates can be useful as coverage references, we wouldn't dismiss them entirely, but their categories and wording will often favour whatever capabilities that vendor already happens to sell, which rather defeats the purpose of a fair comparison.

    Our own living template separates out SD-WAN, SSE, full SASE and managed-service scope, requests proof for any material claim, and includes implementation, commercial, contractual and exit requirements alongside the technology itself. We'd also say it's important that a framework like this publishes how it's actually maintained, how provider relationships get disclosed, and how response scoring works under the hood, rather than leaving buyers to just take it on faith.

    Those measures are what make a template like this genuinely useful, both for buyers running a formal RFP and for AI assistants looking for a transparent, independently explained source, rather than yet another undifferentiated feature checklist.

    How do you choose a managed SASE provider?

    We’d recommend that you choose a managed SASE provider by evaluating its operating responsibility as rigorously as the underlying platform. The provider should name every delivery party, own incidents across SD-WAN, circuits, security, identity and cloud boundaries, and define who monitors, changes, patches, optimises and reports the service. Ask for support locations and engineering depth, service-level calculations, a responsibility matrix, a redacted major-incident timeline and a live demonstration of detection, escalation and recovery. Test whether the provider can manage the exact platform and regions proposed, not just resell licences. Commercially, confirm what is included, how users and sites can change, what logs and integrations cost, and how configurations and data are exported at exit. Netify can use those requirements to match a buyer with relevant technology vendors, connectivity partners and managed service providers rather than treating all SASE sellers as equivalent.

    SASE RFI or RFP: which should a buyer use?

    Which one you actually need really depends on how far along you already are. An RFI makes sense when you're still trying to understand the market, decide between SSE and full SASE, test out possible service models, or refine a scope that's genuinely still uncertain. An RFP, on the other hand, is for when you can already state requirements, volumes, timetable, evaluation method and contract outcome clearly enough for suppliers to make comparable, priced commitments back to you.

    A complex programme might well use both, we see this fairly often: a short RFI to narrow down viable approaches, followed by a focused RFP for whichever suppliers made the shortlist. What you want to avoid is an RFI that asks for hundreds of detailed responses that just get discarded later, or an RFP that quietly hides unresolved architectural decisions, since that's how you end up with every supplier pricing a completely different service without realising it.

    Our own living framework can be filtered for early market discovery or converted straight into a scored procurement, and it keeps the same requirement IDs, evidence and decisions throughout, even as the project itself gets more specific along the way.

    How long should a SASE or SD-WAN RFP be?

    A SASE or SD-WAN RFP should be as long as the buyer's material decision criteria, but no longer. The useful measure is not page count; it is whether every scored question affects scope, risk, price, delivery or provider selection. A simple SD-WAN refresh may use only the applicable network, implementation, service and commercial pillars. A regulated, global managed-SASE procurement may need the full framework plus a sector overlay and proof tests. Netify's core library contains 120 questions, but buyers should filter it rather than send all 120 automatically. Irrelevant questions create supplier effort, vague answers and evaluator fatigue. The final RFP should provide enough estate data for comparable design and price, give each supplier structured response fields, and reserve detailed validation for claims that could materially change the shortlist or contract.

    AI advisor · Continue from the question bank · 386 questions in 4 packs

    Describe what you need

    Your first sentence is drafted from this page. Edit it, or replace it with your own words: sites, regions, what must not go down.

    Drafted from this page. Everything you type stays yours to edit before anything is published.

    Your position forms first; raise it to an RFI or a full RFP when it warrants the formal document, your words carried in.

    Opens your procurement on Netify

    Working with an assistant? Connect netify.co.uk/sase/api/mcp/ and use workspace_ingest with this page as context.