NNetify

SASE and SD-WAN shortlist builder

Compare the SASE & SD-WAN UK and North American market

Publish an RFP within minutes. Build your bespoke shortlist from 30 graded providers by filtering on operating model, region, cloud support, security features, AI capability and resilience, or describe your requirements in plain language and the AI advisor builds it for you. Then send one brief and your shortlisted vendors respond with structured answers and pricing that stays private to you.

  • Free for buyers
  • No sales calls until you reply
  • Pricing private to you
  • No obligation to award

Written and reviewed by the Netify research team. Every vendor record was re-verified against named primary sources on 2026-07-29, with a quoted sentence behind each graded fact. To act on a shortlist, describe the project once at netify.co.uk, raise it to a full RFP and publish to the providers it names, then compare structured responses, with pricing kept private to the buyer.

The market, compared

SD-WAN and SASE providers compared

The word provider means two different things in this market. Some companies build the SD-WAN or SASE platform and sell it as a product. Others operate a managed service on top of a platform, usually someone else's, and own the circuits underneath it. Buyers asking about providers mean one or the other, so the tables below are split by that question rather than by company.

30 vendors and service providers. 19 build the technology,22 run it as a service, 11do both and appear in both tables. Every value is graded from the company's own published material or an independently accountable record, with a quoted sentence behind each fact. 1570 sources in total, of which 300 were found and rejected.

Who builds the technology

19 vendors, compared on 6 points

Vendors that author the platform. Sold direct, through partners, and resold by most of the managed providers below. The columns are the ones that separate builders: whose security stack it is, whether there is a real backbone behind it, and how large the published footprint actually is.

Who builds the technology. 19 vendors compared on sse layer, private backbone, pops, integrated ngfw, published sla, fully managed. Verified 2026-07-29.
VendorSSE layerPrivate backbonePoPsIntegrated NGFWPublished SLAFully managedSources
Arista / VeloCloudPartnerNot published150+PartialNot publishedPartner53
AryakaNativeYes40+Yes99.999Yes66
Cato NetworksNativeYes100Yes99.999Yes46
Check PointNativeYes80+YesNot publishedPartial43
CiscoNativePartialNot publishedYes99.999Not primary48
Cloudflare OneNativeYes300+Yes100Not primary45
Cradlepoint / EricssonNativeNot publishedNot publishedYesNot publishedNot primary60
FatPipe NetworksNativeNot publishedNot publishedYesNot publishedPartial44
ForcepointNativeNot publishedNot publishedYesNot publishedNot primary51
FortinetNativePartial170+Yes99.999Yes42
HPE Aruba NetworkingNot publishedNot publishedNot publishedYesNot publishedYes54
Juniper NetworksNativeNot publishedNot publishedNot publishedNot publishedPartial42
NetskopeNativeNot published120+Yes99.999Via managed service60
NTT DATA / NTT Ltd.PartnerYes75+Partner100Yes53
Palo Alto NetworksNativePartner100+Yes99.999Via managed service58
PeplinkNativeNot primary28PartialNot publishedNot primary53
SonicWallNativeNot publishedNot publishedYesNot publishedPartial78
Versa NetworksNativePartial90Yes99.999Partial47
ZscalerNativeNot primary160Yes99.999Partial51

Who runs it for you

22 vendors, compared on 7 points

Service providers that operate the service. Most run a technology vendor's platform, so feature lists do not separate them. What separates them is who owns the circuits, how much of the operation they take on, and whether the compliance documentation actually exists.

Who runs it for you. 22 vendors compared on underlay, sse layer, fully managed, co-managed, 24/7 noc and soc, compliance docs, published sla. Verified 2026-07-29.
VendorUnderlaySSE layerFully managedCo-managed24/7 NOC and SOCCompliance docsPublished SLASources
AryakaMixedNativeYesYesPartialDocumented99.99966
AT&T BusinessOwnsPartnerYesYesPartialAssurance only10046
BT Business / BT GlobalMixedPartnerYesYesYesAssurance onlyNot published58
Cato NetworksMixedNativeYesYesYesDocumented99.99946
Check PointMixedNativePartialYesPartialNone foundNot published43
CiscoCustomer suppliedNativeNot primaryPartialNot primaryDocumented99.99948
Colt Technology ServicesMixedPartnerYesYesPartialDocumented99.9046
Comcast Business / MasergyMixedPartnerYesYesPartialNone found10039
FatPipe NetworksCustomer suppliedNativePartialNot publishedPartialAssurance onlyNot published44
FortinetNot publishedNativeYesNot publishedNot publishedDocumented99.99942
GTTMixedPartnerYesYesYesDocumented99.9944
HPE Aruba NetworkingCustomer suppliedNot publishedYesYesPartialDocumentedNot published54
HughesNot publishedPartnerYesPartialPartialAssurance only99.99957
LumenMixedPartnerYesYesPartialDocumented99.9955
NTT DATA / NTT Ltd.MixedPartnerYesPartialYesDocumented10053
Orange BusinessOwnsPartnerYesPartialYesDocumented10062
SonicWallCustomer suppliedNativePartialYesPartialDocumentedNot published78
Telefónica TechMixedPartnerYesNot publishedPartialDocumentedNot published51
Verizon BusinessOwnsPartnerYesPartialYesNone found10058
Versa NetworksMixedNativePartialYesPartialDocumented99.99947
Vodafone BusinessMixedPartnerYesYesYesDocumented99.9960
ZscalerCustomer suppliedNativePartialPartialPartialDocumented99.99951

Where evidence was not found, a cell reads Not published rather than being inferred. Full sources for each one sit on its profile page, including the sources we found and rejected.

Ranked shortlists

Pre-built rankings by sector, size and priority

Definitions

The 40 capabilities, defined

Every provider is graded against the same 40 capabilities. One sentence on what each row measures; grades reflect public evidence, so always confirm via RFP.

Service delivery and operating model

8 capabilities
Fully managed service.
The provider designs, deploys, monitors, changes, supports and reports on the service end to end, so the customer sets policy and outcomes rather than running day-to-day operations.
DIY / self-managed model.
The customer's own team operates the platform directly, owning the controller, policies, updates and incident response.
Co-managed service.
Responsibility is shared: the provider runs the platform and support while the customer retains selected policy and change rights.
Multi-tenant MSP / white-label support.
The platform supports tenant isolation, delegated administration, branded portals and templates, so managed service providers can operate it for many customers under their own brand.
Professional services and migration support.
Structured design and migration services are available, covering discovery, pilots, staging, migration runbooks, rollback plans and training.
Last-mile circuit management.
The provider sources, monitors and supports the underlay access circuits at each site, across broadband, dedicated internet access, LTE and 5G, MPLS and cross-connects, giving one accountable party for connectivity and overlay together.
Lifecycle management.
Hardware replacement, firmware upgrades, patching, renewals and end-of-life planning are handled as part of the service.
Flexible commercial model.
Pricing can be structured in more than one way, such as per site, per user, per bandwidth, consumption-based or as NaaS, with terms that adapt to the buyer's estate.

Network architecture and transport

10 capabilities
Encrypted overlay fabric.
Site and user traffic runs through secure tunnels built over any underlying transport, including broadband, dedicated internet, MPLS, LTE and 5G or satellite, keeping data protected across mixed networks.
Dynamic path selection.
The platform routes traffic in real time based on measured latency, jitter, packet loss and policy, steering around brownouts without manual intervention.
Application-aware routing.
Traffic is identified at application level and routed by per-application policy, so business-critical applications such as UCaaS and ERP take priority.
QoS and traffic shaping.
Bandwidth can be prioritised, reserved and policed per application or traffic class, protecting voice, video and critical traffic under congestion.
Packet loss remediation.
Techniques such as forward error correction, packet duplication, jitter buffering and TCP optimisation repair or mask loss on poor-quality links, keeping real-time applications usable.
Local internet breakout.
Internet-bound traffic exits securely and directly from the branch rather than being backhauled through a central data centre, reducing latency for cloud and SaaS traffic.
MPLS coexistence and migration.
Existing MPLS circuits can run alongside internet and cellular transport during a phased migration, so estates move site by site without a risky single cutover.
Cellular and 5G support.
4G and 5G connections are supported as primary or failover transport, with integrated or external modems, SIM management and signal monitoring.
Cloud on-ramp.
Connectivity into cloud platforms such as AWS, Microsoft Azure, Google Cloud and Oracle, and interconnect fabrics such as Equinix and Megaport, is automated and simplified rather than hand-built per cloud.

Gateway, PoP and backbone design

8 capabilities
Public cloud gateways.
The vendor operates shared gateways and points of presence that deliver SaaS optimisation, remote access or security enforcement as a cloud service; this measures the vendor's own service infrastructure, distinct from dedicated private PoPs.
Private PoPs / dedicated PoPs.
Points of presence can be supplied as customer-hosted, dedicated or sovereign deployments rather than only the provider's shared multi-tenant locations.
Private global backbone.
Traffic between regions rides a backbone owned or controlled by the vendor rather than the public internet, giving predictable latency and loss between PoPs.
Regional breakout and data residency.
Traffic can be pinned to chosen countries, regions or approved inspection locations, supporting data residency and sovereignty requirements.
Multi-cloud transit fabric.
Branch-to-cloud, cloud-to-cloud and user-to-cloud traffic runs under one common policy through the provider's fabric rather than through customer-built interconnects.
Flexible edge form factors.
The edge is available as hardware appliances, virtual machines, cloud marketplace images, containers or uCPE, so each site can use the form that suits it.
High availability design.
Redundant designs are supported across appliances, circuits, power and gateways, with clustering and automatic failover keeping sites connected through failures.
SLA-backed service fabric.
The service carries contractual commitments covering uptime, response and change handling, and in some cases latency, jitter and loss, rather than best-effort targets.

Security and SASE capability

9 capabilities
Integrated next-generation firewall.
Stateful firewalling, application control, intrusion prevention, malware inspection and URL filtering are built into the platform rather than supplied as a separate appliance.
Full SASE platform.
Networking and security converge in one platform, combining SD-WAN with cloud-delivered controls including SWG, CASB, ZTNA, firewall as a service, DLP and threat prevention.
SSE ecosystem integration.
The platform interoperates with third-party security service edge providers such as Zscaler, Netskope, Palo Alto Prisma Access and Cisco Secure Access, for buyers running a best-of-breed rather than single-vendor stack.
Zero Trust Network Access.
Users are connected to specific private applications based on identity and device posture rather than being placed on the network, replacing broad VPN access with least-privilege access.
Secure web gateway.
Web traffic is filtered and inspected, with URL filtering, SSL inspection, malware scanning and acceptable-use controls enforced in the cloud.
CASB capability.
Cloud access security broker controls provide SaaS discovery, sanctioned and unsanctioned application control and SaaS policy enforcement, including shadow IT visibility.
Data loss prevention.
Content is classified and inspected for sensitive data, which can be blocked or flagged before it leaves the organisation, with alerting and exception workflows.
Remote user access.
Remote workers, contractors and mobile users connect through the same platform and policies as sites, through a lightweight client or clientless browser access.
SOC/SIEM/SOAR integration.
Logs, events and threat intelligence export cleanly over syslog and APIs into SIEM, SOAR and security operations tooling, so the service fits an existing detection and response workflow.

Operations, assurance and automation

5 capabilities
Centralised orchestration.
Configuration and policy are managed from a single console using templates, intent-based policy and zero-touch provisioning, with changes pushed network-wide rather than device by device.
Customer portal and RBAC.
A customer-facing portal provides real-time status, reporting, tickets and change requests, with role-based access so different teams see and change only what they should.
Observability and digital experience monitoring.
Application experience, user experience, device health and path analytics are measured end to end, so degradation is visible before tickets are raised.
APIs and automation.
Documented interfaces such as REST APIs, Terraform, webhooks and event streaming allow configuration, reporting and ITSM integration to be automated.
Managed service assurance.
The provider's 24/7 NOC and SOC monitor the service proactively, own incidents through to root cause analysis, and run structured service reviews and change governance.

Questions

How the shortlist builder works

How does the shortlist builder rank vendors?

The Netify shortlist builder ranks each and every provider based on their capabilities to deliver 40 different in-built features, alongside the likes of regional coverage, cloud support, AI capabilities, resilience and deployment speed, all of which is drawn from information we've been able to publicly source or find evidence for.

Can I share or save my shortlist?

Yes absolutely, every filter combination is matched to an associated page URL, enabling you to copy a link to take you (or board directors) straight back to the same filtered list again at a later date, as well as being able to download a PDF version or have the ranked list emailed to you.

What does the AI advisor do?

We've built our AI advisor to make everything easier for you: you describe your estate in plain language (for example site count, regions, security requirements and operating model) and the advisor will take your instructions to map them onto the same filters and scoring engine used by the manual controls, then the advisor will explain the resulting shortlist to you.

Is this comparison vendor neutral?

Yes, we don't have a bias to any vendor and use publicly available sources and evidence only, as well as every vendor being scored against the exact same matrix. We must mention that Netify is a BT Authorised Partner and earns commission on some routes to market, however these rankings are not influenced by commercial relationships.

How accurate are the extended dimensions?

There are two different levels of evidence here and we would rather be plain about which is which. Eighteen facts per provider were re-sourced on 29 July 2026 from the provider's own published material or an independently accountable record, and each one carries a named source, a reliability tier and a sentence quoted from that source which we then re-checked against the live page: the thirteen capabilities that genuinely separate this market, who owns the underlay, whose security service edge stack it is, whether real compliance documentation exists rather than a general assurance, plus published points of presence and availability SLA. The remaining grades, including regional coverage, cloud support, AI capability and resilience, are still indicative desk research rather than individually sourced, and we say so rather than dress them up. Where we could not evidence something we publish it as unknown with the reason. For anything you are going to sign a contract on, confirm it through a structured RFP, which Netify can create and issue to your shortlisted providers.