SASE RFP path
Build a SASE RFP
A SASE procurement covers both networking and security, which is why generic RFP templates fail: they miss the integration questions (single policy plane, PoP performance, identity integration) where SASE projects actually go wrong. This builder starts from your estate and generates a methodology-backed RFP you can publish to verified suppliers.
This opens the main RFP Builder with the SASE scope preloaded — the same builder every path uses, so you can still change scope, delivery model and questions there.
Who this path is for
- Replacing VPN with ZTNA for a hybrid workforce
- Consolidating web proxy, CASB and DLP point products
- Combining an SD-WAN refresh with cloud-delivered security
- Regulated buyers needing evidence and audit trails from suppliers
What the RFP covers
- Identity and ZTNA, including device posture and third-party access
- SWG, CASB and DLP with TLS inspection specifics
- FWaaS and threat protection
- SD-WAN integration, PoP selection and failover
- Logging, SIEM export and data residency
- Service model, deployment, commercials and vendor evidence
Sample questions from the Netify bank
Drawn from the sase-question-bank-2026.1 canonical bank (43 questions). Every question carries the evidence suppliers should provide and the red-flag answers to watch for.
Identity / ZTNA
Describe how your platform enforces zero trust access to private applications.
Evidence: Architecture diagram; Policy example; Identity provider integration list
Identity / ZTNA
Which identity providers do you support natively, and which protocols (SAML, OIDC, SCIM)?
Evidence: Supported IdP list; Protocol matrix
Identity / ZTNA
How is device posture evaluated and used in access decisions?
Evidence: Device posture signal list; Sample posture-based policy
Identity / ZTNA
Describe step-up authentication and continuous session validation.
Evidence: Step-up trigger list; Session validation cadence
Identity / ZTNA
Describe how third-party and contractor access is managed.
Evidence: Third-party access workflow
SWG / CASB / DLP
Describe your secure web gateway, including TLS inspection and URL category coverage.
Evidence: SWG architecture; TLS inspection approach; Category list
SWG / CASB / DLP
Describe browser-based isolation options and use cases.
Evidence: Isolation architecture
SWG / CASB / DLP
Describe your inline and API-based CASB coverage for sanctioned and shadow SaaS.
Evidence: List of API-integrated SaaS; Inline vs API coverage matrix
Common questions
Do I need a full SASE RFP or a shorter project notice?
If you mainly need pricing signals or discovery calls, post a project notice first — it takes minutes and you can turn it into a full RFP later. Use the RFP when you need structured, scored supplier comparison.
Single-vendor or best-of-breed?
The builder lets you set vendor approach (no preference, unified single vendor, or best-of-breed) and adjusts the integration questions accordingly.
Methodology and citations
Questions cite the Netify question bank, sample RFP and research methodology. Machine-readable bank: /question-bank.json. Other paths: Build an SD-WAN RFP · Build an SSE RFP · Not sure? Get a recommendation