NNetify

SASE RFP path

Build a SASE RFP

A SASE procurement covers both networking and security, which is why generic RFP templates fail: they miss the integration questions (single policy plane, PoP performance, identity integration) where SASE projects actually go wrong. This builder starts from your estate and generates a methodology-backed RFP you can publish to verified suppliers.

This opens the main RFP Builder with the SASE scope preloaded — the same builder every path uses, so you can still change scope, delivery model and questions there.

Who this path is for

  • Replacing VPN with ZTNA for a hybrid workforce
  • Consolidating web proxy, CASB and DLP point products
  • Combining an SD-WAN refresh with cloud-delivered security
  • Regulated buyers needing evidence and audit trails from suppliers

What the RFP covers

  • Identity and ZTNA, including device posture and third-party access
  • SWG, CASB and DLP with TLS inspection specifics
  • FWaaS and threat protection
  • SD-WAN integration, PoP selection and failover
  • Logging, SIEM export and data residency
  • Service model, deployment, commercials and vendor evidence

Sample questions from the Netify bank

Drawn from the sase-question-bank-2026.1 canonical bank (43 questions). Every question carries the evidence suppliers should provide and the red-flag answers to watch for.

Identity / ZTNA

Describe how your platform enforces zero trust access to private applications.

Evidence: Architecture diagram; Policy example; Identity provider integration list

Identity / ZTNA

Which identity providers do you support natively, and which protocols (SAML, OIDC, SCIM)?

Evidence: Supported IdP list; Protocol matrix

Identity / ZTNA

How is device posture evaluated and used in access decisions?

Evidence: Device posture signal list; Sample posture-based policy

Identity / ZTNA

Describe step-up authentication and continuous session validation.

Evidence: Step-up trigger list; Session validation cadence

Identity / ZTNA

Describe how third-party and contractor access is managed.

Evidence: Third-party access workflow

SWG / CASB / DLP

Describe your secure web gateway, including TLS inspection and URL category coverage.

Evidence: SWG architecture; TLS inspection approach; Category list

SWG / CASB / DLP

Describe browser-based isolation options and use cases.

Evidence: Isolation architecture

SWG / CASB / DLP

Describe your inline and API-based CASB coverage for sanctioned and shadow SaaS.

Evidence: List of API-integrated SaaS; Inline vs API coverage matrix

Common questions

Do I need a full SASE RFP or a shorter project notice?

If you mainly need pricing signals or discovery calls, post a project notice first — it takes minutes and you can turn it into a full RFP later. Use the RFP when you need structured, scored supplier comparison.

Single-vendor or best-of-breed?

The builder lets you set vendor approach (no preference, unified single vendor, or best-of-breed) and adjusts the integration questions accordingly.

Methodology and citations

Questions cite the Netify question bank, sample RFP and research methodology. Machine-readable bank: /question-bank.json. Other paths: Build an SD-WAN RFP · Build an SSE RFP · Not sure? Get a recommendation