NNetifyVersion 1509261235

SD-WAN and SASE shortlist builder

Managed SD-WAN providers compared (2026)

Compare public provider evidence in alphabetical order. Publish a verified project to unlock computed fit and rankings.

Provider evidence

Provider, product and differentiator

  • AT&T Business (AT&T Dynamic Defence with Palo Alto Networks, AT&T Managed SASE with Cisco, AT&T Managed SD-WAN, AT&T Network as a Service (NaaS)): Major US carrier-led managed SD-WAN portfolio with multi-vendor platform options (including Fortinet for AT&T SASE).
  • BT (Agile Connect, BT Managed Fortinet Firewall, BT Managed SASE (Fortinet-based), BT Managed SASE (Meraki-based)): UK market leader for managed SD-WAN with deep access circuit ownership and field engineering capability.
  • Comcast Business (Comcast Business CASB, Comcast Business FWaaS, Comcast Business Managed SD-WAN, Comcast Business SASE): SASE combining SD-WAN and security available fully managed or co-managed, drawing on Masergy AIOps heritage.
  • Ericsson Cradlepoint (NetCloud Federal, NetCloud Manager, NetCloud Perimeter, NetCloud Private Networks): Wireless-first branch architecture from Ericsson with deep 5G expertise; NetCloud provides cellular-centric SD-WAN management.
  • Expereo (Expereo Enhanced Internet, Expereo Managed SD-WAN, Expereo SD-WAN/SASE with Cato Networks, Starlink (via Expereo, authorised reseller)): Rather than owning last-mile or backbone infrastructure directly, Expereo positions itself explicitly as an internet-connectivity aggregation and optimisation specialist, describing itself as a ‘world-leading Managed Network as a Service provider’ built around a ‘Global Internet’ underlay philosophy - the consistent, repeated framing across its own materials is that a strong internet underlay, not owned physical infrastructure, is the essential foundation for effective SD-WAN and SASE. Founded in Amsterdam in 2004, Expereo has passed through a complex, multi-owner private-equity history: acquired by The Carlyle Group in July 2014, sold to Apax Partners in May 2018, and majority-acquired b...
  • Lumen (Black Lotus Labs, Lumen Managed SASE Solutions, Lumen SASE with Versa, Lumen SD-WAN with Versa Networks): Fully managed or co-managed SD-WAN with strong NaaS positioning and integrated network services.
  • Open Systems (MDR+ (Managed Detection and Response), Managed SD-WAN / Secure SD-WAN, Managed, Universal SSE, Mission Control): Open Systems founded in 1990 in Basel, Switzerland, more than three decades before the SASE category itself existed, originally as a managed security service provider before evolving its platform into what it now markets as native, managed SASE Experience. The company’s ownership history took a distinctive turn in 2023: after a period under the European private-equity firm EQT, Open Systems was acquired by Swiss Post - Switzerland’s state-backed national postal and logistics institution - a materially different kind of owner from the venture-capital or private-equity structures behind most other vendors in this category.
  • Orange Business (Orange Business Evolution Platform, Orange Business SASE with Palo Alto Networks Prisma SASE, Orange Business and Fortinet SASE, Orange Cyberdefense Managed SASE): Global managed network leadership with strong service assurance, NOC depth and field operations.
  • Verizon Business (RingCentral (voice/UC integration), Verizon Managed SD Branch, Verizon Managed SD WAN, Verizon SASE Management): Global carrier-led managed SASE and SD-WAN with strong North American presence and international delivery.
  • Virgin Media O2 Business (8x8 Voice for Teams, Cloud Infrastructure as a Service / Platform as a Service, Managed Detection and Response, Success Agreement): Virgin Media O2 (VMO2) is itself a 50/50 joint venture between Liberty Global and Telefónica, formed in June 2021 from the merger of Virgin Media UK and O2 UK. On 12 May 2025, VMO2 announced it would combine substantially all of its direct business-to-business operations - including Virgin Media O2 Business - with Daisy Group, a long-established, independent UK B2B communications and IT provider founded in 2001.
  • Vodafone Business (Fortinet-based Secure Networking, Vodafone Business Managed Network Services, Vodafone Business Network as a Service (NaaS), Vodafone Business SASE): Strong UK and European market presence with NaaS positioning and integrated mobile/fixed access.

Comparison summary

Evidence for managed SD-WAN providers at a glance

Comparative overview of 11 managed SD-WAN providers, updated 2026-09-01
ProviderTypeProductsBest suited toMain strengthConfirm through RFPReviewed
AT&T Businessmanaged service provider / carrier network providerAT&T Dynamic Defence with Palo Alto Networks, AT&T Managed SASE with Cisco, AT&T Managed SD-WAN, AT&T Network as a Service (NaaS)US-headquartered enterprises wanting integrated carrier-led SD-WAN and SASE.Major US carrier-led managed SD-WAN portfolio with multi-vendor platform options (including Fortinet for AT&T SASE).DIY / self-managed model2026-09-01
BTmanaged service provider / carrier network providerAgile Connect, BT Managed Fortinet Firewall, BT Managed SASE (Fortinet-based), BT Managed SASE (Meraki-based)UK enterprises wanting a single supplier for SD-WAN platform, access circuits, security and field operations.UK market leader for managed SD-WAN with deep access circuit ownership and field engineering capability.DIY / self-managed model2026-09-01
Comcast Businessmanaged service provider / carrier network providerComcast Business CASB, Comcast Business FWaaS, Comcast Business Managed SD-WAN, Comcast Business SASENorth American enterprises wanting managed or co-managed SD-WAN and SASE from a single carrier.SASE combining SD-WAN and security available fully managed or co-managed, drawing on Masergy AIOps heritage.DIY / self-managed model2026-09-01
Ericsson Cradlepointtechnology vendor / carrier network providerNetCloud Federal, NetCloud Manager, NetCloud Perimeter, NetCloud Private NetworksDistributed enterprises with strong cellular/5G access strategy (retail, logistics, transport, public sector).Wireless-first branch architecture from Ericsson with deep 5G expertise; NetCloud provides cellular-centric SD-WAN management.Co-managed service2026-09-01
Expereomanaged service provider / carrier network providerExpereo Enhanced Internet, Expereo Managed SD-WAN, Expereo SD-WAN/SASE with Cato Networks, Starlink (via Expereo, authorised reseller)Rather than owning last-mile or backbone infrastructure directly, Expereo positions itself explicitly as an internet-connectivity aggregation and optimisation specialist, describing itself as a ‘world-leading Managed Network as a Service provider’ built around a ‘Global Internet’ underlay philosophy - the consistent, repeated framing across its own materials is that a strong internet underlay, not owned physical infrastructure, is the essential foundation for effective SD-WAN and SASE. Founded in Amsterdam in 2004, Expereo has passed through a complex, multi-owner private-equity history: acquired by The Carlyle Group in July 2014, sold to Apax Partners in May 2018, and majority-acquired b...Rather than owning last-mile or backbone infrastructure directly, Expereo positions itself explicitly as an internet-connectivity aggregation and optimisation specialist, describing itself as a ‘world-leading Managed Network as a Service provider’ built around a ‘Global Internet’ underlay philosophy - the consistent, repeated framing across its own materials is that a strong internet underlay, not owned physical infrastructure, is the essential foundation for effective SD-WAN and SASE. Founded in Amsterdam in 2004, Expereo has passed through a complex, multi-owner private-equity history: acquired by The Carlyle Group in July 2014, sold to Apax Partners in May 2018, and majority-acquired b...DIY / self-managed model2026-09-01
Lumentechnology vendor / managed service provider / carrier network providerBlack Lotus Labs, Lumen Managed SASE Solutions, Lumen SASE with Versa, Lumen SD-WAN with Versa NetworksNorth American enterprises wanting integrated managed SD-WAN, access and broader network services from one provider.Fully managed or co-managed SD-WAN with strong NaaS positioning and integrated network services.Multi-tenant MSP / white-label support2026-09-01
Open Systemstechnology vendor / managed service providerMDR+ (Managed Detection and Response), Managed SD-WAN / Secure SD-WAN, Managed, Universal SSE, Mission ControlOpen Systems founded in 1990 in Basel, Switzerland, more than three decades before the SASE category itself existed, originally as a managed security service provider before evolving its platform into what it now markets as native, managed SASE Experience. The company’s ownership history took a distinctive turn in 2023: after a period under the European private-equity firm EQT, Open Systems was acquired by Swiss Post - Switzerland’s state-backed national postal and logistics institution - a materially different kind of owner from the venture-capital or private-equity structures behind most other vendors in this category.Open Systems founded in 1990 in Basel, Switzerland, more than three decades before the SASE category itself existed, originally as a managed security service provider before evolving its platform into what it now markets as native, managed SASE Experience. The company’s ownership history took a distinctive turn in 2023: after a period under the European private-equity firm EQT, Open Systems was acquired by Swiss Post - Switzerland’s state-backed national postal and logistics institution - a materially different kind of owner from the venture-capital or private-equity structures behind most other vendors in this category.Multi-tenant MSP / white-label support2026-09-01
Orange Businesscarrier network provider / integratorOrange Business Evolution Platform, Orange Business SASE with Palo Alto Networks Prisma SASE, Orange Business and Fortinet SASE, Orange Cyberdefense Managed SASEMultinational enterprises wanting a single global managed provider for SD-WAN, SASE and access.Global managed network leadership with strong service assurance, NOC depth and field operations.DIY / self-managed model2026-09-01
Verizon Businessmanaged service provider / carrier network providerRingCentral (voice/UC integration), Verizon Managed SD Branch, Verizon Managed SD WAN, Verizon SASE ManagementNorth American and multinational enterprises wanting carrier-led managed SD-WAN and SASE.Global carrier-led managed SASE and SD-WAN with strong North American presence and international delivery.DIY / self-managed model2026-09-01
Virgin Media O2 Businessmanaged service provider / carrier network provider8x8 Voice for Teams, Cloud Infrastructure as a Service / Platform as a Service, Managed Detection and Response, Success AgreementVirgin Media O2 (VMO2) is itself a 50/50 joint venture between Liberty Global and Telefónica, formed in June 2021 from the merger of Virgin Media UK and O2 UK. On 12 May 2025, VMO2 announced it would combine substantially all of its direct business-to-business operations - including Virgin Media O2 Business - with Daisy Group, a long-established, independent UK B2B communications and IT provider founded in 2001.Virgin Media O2 (VMO2) is itself a 50/50 joint venture between Liberty Global and Telefónica, formed in June 2021 from the merger of Virgin Media UK and O2 UK. On 12 May 2025, VMO2 announced it would combine substantially all of its direct business-to-business operations - including Virgin Media O2 Business - with Daisy Group, a long-established, independent UK B2B communications and IT provider founded in 2001.DIY / self-managed model2026-09-01
Vodafone Businessmanaged service provider / carrier network providerFortinet-based Secure Networking, Vodafone Business Managed Network Services, Vodafone Business Network as a Service (NaaS), Vodafone Business SASEUK and European enterprises wanting carrier-led SD-WAN with strong mobile and 5G integration.Strong UK and European market presence with NaaS positioning and integrated mobile/fixed access.DIY / self-managed model2026-09-01

The table uses governed provider records. Unknown evidence is shown as a point to confirm, not a negative score.

Short answer: compare 30 SD-WAN providers, SD-WAN vendors, SASE providers, carriers and managed services using one governed research dataset. Compare named providers feature by feature or open their evidence profiles. Publish a short anonymous project to unlock personalised matching and supplier responses.

  • Free for buyers
  • No sales calls until you reply
  • Pricing private to you
  • No obligation to award

Written and reviewed by the Netify research team. The governed provider records were last updated on 2026-09-01. Comparison contract governed-shortlist/1.0.0. To act on a shortlist, describe the project once at the Netify RFP Builder, review and publish an anonymous brief or RFP to invite supplier responses, then compare structured responses, with pricing kept private to the buyer. Read and cite the research method.

2026 market answer

Managed SD-WAN providers compared

Compare public provider evidence in alphabetical order. Publish a verified project to unlock computed fit and rankings.

11 providers in this evidence view. Reviewed 2026-09-01. View contract shortlist-market-view/1.0.0.

Alphabetical evidence directory for managed SD-WAN providers
Provider evidence by the selected governed evidence score. Use the table above for the underlying decision fields.

Ranked shortlists

Pre-built rankings by sector, size and priority

Definitions

The 40 capabilities, defined

Every provider is graded against the same 40 capabilities. One sentence on what each row measures; grades reflect public evidence, so always confirm via RFP.

Service delivery and operating model

8 capabilities
Fully managed service.
The provider designs, deploys, monitors, changes, supports and reports on the service end to end, so the customer sets policy and outcomes rather than running day-to-day operations.
DIY / self-managed model.
The customer's own team operates the platform directly, owning the controller, policies, updates and incident response.
Co-managed service.
Responsibility is shared: the provider runs the platform and support while the customer retains selected policy and change rights.
Multi-tenant MSP / white-label support.
The platform supports tenant isolation, delegated administration, branded portals and templates, so managed service providers can operate it for many customers under their own brand.
Professional services and migration support.
Structured design and migration services are available, covering discovery, pilots, staging, migration runbooks, rollback plans and training.
Last-mile circuit management.
The provider sources, monitors and supports the underlay access circuits at each site, across broadband, dedicated internet access, LTE and 5G, MPLS and cross-connects, giving one accountable party for connectivity and overlay together.
Lifecycle management.
Hardware replacement, firmware upgrades, patching, renewals and end-of-life planning are handled as part of the service.
Flexible commercial model.
Pricing can be structured in more than one way, such as per site, per user, per bandwidth, consumption-based or as NaaS, with terms that adapt to the buyer's estate.

Network architecture and transport

10 capabilities
Encrypted overlay fabric.
Site and user traffic runs through secure tunnels built over any underlying transport, including broadband, dedicated internet, MPLS, LTE and 5G or satellite, keeping data protected across mixed networks.
Dynamic path selection.
The platform routes traffic in real time based on measured latency, jitter, packet loss and policy, steering around brownouts without manual intervention.
Application-aware routing.
Traffic is identified at application level and routed by per-application policy, so business-critical applications such as UCaaS and ERP take priority.
QoS and traffic shaping.
Bandwidth can be prioritised, reserved and policed per application or traffic class, protecting voice, video and critical traffic under congestion.
Packet loss remediation.
Techniques such as forward error correction, packet duplication, jitter buffering and TCP optimisation repair or mask loss on poor-quality links, keeping real-time applications usable.
Local internet breakout.
Internet-bound traffic exits securely and directly from the branch rather than being backhauled through a central data centre, reducing latency for cloud and SaaS traffic.
MPLS coexistence and migration.
Existing MPLS circuits can run alongside internet and cellular transport during a phased migration, so estates move site by site without a risky single cutover.
Cellular and 5G support.
4G and 5G connections are supported as primary or failover transport, with integrated or external modems, SIM management and signal monitoring.
Cloud on-ramp.
Connectivity into cloud platforms such as AWS, Microsoft Azure, Google Cloud and Oracle, and interconnect fabrics such as Equinix and Megaport, is automated and simplified rather than hand-built per cloud.

Gateway, PoP and backbone design

8 capabilities
Public cloud gateways.
The vendor operates shared gateways and points of presence that deliver SaaS optimisation, remote access or security enforcement as a cloud service; this measures the vendor's own service infrastructure, distinct from dedicated private PoPs.
Private PoPs / dedicated PoPs.
Points of presence can be supplied as customer-hosted, dedicated or sovereign deployments rather than only the provider's shared multi-tenant locations.
Private global backbone.
Traffic between regions rides a backbone owned or controlled by the vendor rather than the public internet, giving predictable latency and loss between PoPs.
Regional breakout and data residency.
Traffic can be pinned to chosen countries, regions or approved inspection locations, supporting data residency and sovereignty requirements.
Multi-cloud transit fabric.
Branch-to-cloud, cloud-to-cloud and user-to-cloud traffic runs under one common policy through the provider's fabric rather than through customer-built interconnects.
Flexible edge form factors.
The edge is available as hardware appliances, virtual machines, cloud marketplace images, containers or uCPE, so each site can use the form that suits it.
High availability design.
Redundant designs are supported across appliances, circuits, power and gateways, with clustering and automatic failover keeping sites connected through failures.
SLA-backed service fabric.
The service carries contractual commitments covering uptime, response and change handling, and in some cases latency, jitter and loss, rather than best-effort targets.

Security and SASE capability

9 capabilities
Integrated next-generation firewall.
Stateful firewalling, application control, intrusion prevention, malware inspection and URL filtering are built into the platform rather than supplied as a separate appliance.
Full SASE platform.
Networking and security converge in one platform, combining SD-WAN with cloud-delivered controls including SWG, CASB, ZTNA, firewall as a service, DLP and threat prevention.
SSE ecosystem integration.
The platform interoperates with third-party security service edge providers such as Zscaler, Netskope, Palo Alto Prisma Access and Cisco Secure Access, for buyers running a best-of-breed rather than single-vendor stack.
Zero Trust Network Access.
Users are connected to specific private applications based on identity and device posture rather than being placed on the network, replacing broad VPN access with least-privilege access.
Secure web gateway.
Web traffic is filtered and inspected, with URL filtering, SSL inspection, malware scanning and acceptable-use controls enforced in the cloud.
CASB capability.
Cloud access security broker controls provide SaaS discovery, sanctioned and unsanctioned application control and SaaS policy enforcement, including shadow IT visibility.
Data loss prevention.
Content is classified and inspected for sensitive data, which can be blocked or flagged before it leaves the organisation, with alerting and exception workflows.
Remote user access.
Remote workers, contractors and mobile users connect through the same platform and policies as sites, through a lightweight client or clientless browser access.
SOC/SIEM/SOAR integration.
Logs, events and threat intelligence export cleanly over syslog and APIs into SIEM, SOAR and security operations tooling, so the service fits an existing detection and response workflow.

Operations, assurance and automation

5 capabilities
Centralised orchestration.
Configuration and policy are managed from a single console using templates, intent-based policy and zero-touch provisioning, with changes pushed network-wide rather than device by device.
Customer portal and RBAC.
A customer-facing portal provides real-time status, reporting, tickets and change requests, with role-based access so different teams see and change only what they should.
Observability and digital experience monitoring.
Application experience, user experience, device health and path analytics are measured end to end, so degradation is visible before tickets are raised.
APIs and automation.
Documented interfaces such as REST APIs, Terraform, webhooks and event streaming allow configuration, reporting and ITSM integration to be automated.
Managed service assurance.
The provider's 24/7 NOC and SOC monitor the service proactively, own incidents through to root cause analysis, and run structured service reviews and change governance.

Questions

How the shortlist builder works

Which SD-WAN vendor is best?

There is no single best vendor for every estate. The right shortlist depends on operating model, regions, applications, security requirements and the evidence a supplier can provide for the project.

Who are the leading SD-WAN providers?

The SD-WAN vendor view lists public provider evidence alphabetically. Computed fit against your operating model, regions and requirements unlocks after verified project publication.

Is SD-WAN obsolete?

No. SD-WAN remains the network layer in many SASE designs. SASE adds cloud-delivered security and access controls rather than removing the need to control WAN traffic.

Should a business choose SD-WAN or MPLS?

Many estates use both during migration. SD-WAN can use internet, cellular and MPLS underlays, while the RFP should define application performance, resilience and any sites that must retain private circuits.

Who are the leading SASE vendors?

The SASE vendor view lists providers with public SASE, ZTNA or secure web gateway evidence in alphabetical order. Buyers should compare the networking and security components separately before accepting a single-vendor claim.

How does the shortlist builder rank vendors?

Public comparison pages show source grades and alphabetical provider lists. After verified publication, the private matching engine evaluates your requirements against the current catalogue and freezes its matching rules, evidence, ranks and scores with that publication.

Can I share or save my shortlist?

You can share a public comparison link. Your personalised shortlist is saved in your project and unlocks after verified anonymous publication.

What does Build from requirements do?

Describe your estate, review a short project notice and verify your business identity. Publishing anonymously unlocks a personalised shortlist and supplier responses; a full RFP is optional.

Is this comparison vendor neutral?

Yes, we don't have a bias to any vendor and use publicly available sources and evidence only, as well as every vendor being scored against the exact same matrix. We must mention that Netify is a BT Authorised Partner and earns commission on some routes to market, however these rankings are not influenced by commercial relationships.

How accurate are the extended dimensions?

There are two different levels of evidence here and we would rather be plain about which is which. Eighteen facts per provider were re-sourced on 29 July 2026 from the provider's own published material or an independently accountable record, and each one carries a named source, a reliability tier and a sentence quoted from that source which we then re-checked against the live page: the thirteen capabilities that genuinely separate this market, who owns the underlay, whose security service edge stack it is, whether real compliance documentation exists rather than a general assurance, plus published points of presence and availability SLA. The remaining grades, including regional coverage, cloud support, AI capability and resilience, are still indicative desk research rather than individually sourced, and we say so rather than dress them up. Where we could not evidence something we publish it as unknown with the reason. For anything you are going to sign a contract on, confirm it through a structured RFP, which Netify can create and issue to your shortlisted providers.