SD-WAN and SASE shortlist builder
Compare SD-WAN and SASE providers, vendors and managed services
Compare 30 researched SD-WAN and SASE providers across operating model, network and security capability. Build a ranked shortlist, inspect the evidence, compare two providers directly, then hand your requirements to the Netify RFP Builder.
Short answer: compare 30 SD-WAN providers, SD-WAN vendors, SASE providers, carriers and managed services using one governed research dataset. Build a ranked shortlist, compare two providers feature by feature, or open each evidence profile before issuing an RFP.
- Free for buyers
- No sales calls until you reply
- Pricing private to you
- No obligation to award
Written and reviewed by the Netify research team. The governed provider records were last updated on 2026-09-01. Comparison contract governed-shortlist/1.0.0. To act on a shortlist, describe the project once at the Netify RFP Builder, raise it to a full RFP and publish to the providers it names, then compare structured responses, with pricing kept private to the buyer. Read and cite the research method.
2026 market answer
Managed SD-WAN providers compared
This view ranks providers with public evidence for both managed service delivery and an encrypted SD-WAN overlay, with extra weight on migration, last-mile and lifecycle management.
11 eligible providers. Reviewed 2026-09-01. View contract shortlist-market-view/1.0.0.
Leading providers
Provider, product and differentiator
- Lumen (Black Lotus Labs, Lumen Managed SASE Solutions, Lumen SASE with Versa, Lumen SD-WAN with Versa Networks): Fully managed or co-managed SD-WAN with strong NaaS positioning and integrated network services.
- Expereo (Expereo Enhanced Internet, Expereo Managed SD-WAN, Expereo SD-WAN/SASE with Cato Networks, Starlink (via Expereo, authorised reseller)): Rather than owning last-mile or backbone infrastructure directly, Expereo positions itself explicitly as an internet-connectivity aggregation and optimisation specialist, describing itself as a ‘world-leading Managed Network as a Service provider’ built around a ‘Global Internet’ underlay philosophy - the consistent, repeated framing across its own materials is that a strong internet underlay, not owned physical infrastructure, is the essential foundation for effective SD-WAN and SASE. Founded in Amsterdam in 2004, Expereo has passed through a complex, multi-owner private-equity history: acquired by The Carlyle Group in July 2014, sold to Apax Partners in May 2018, and majority-acquired b...
- Open Systems (MDR+ (Managed Detection and Response), Managed SD-WAN / Secure SD-WAN, Managed, Universal SSE, Mission Control): Open Systems founded in 1990 in Basel, Switzerland, more than three decades before the SASE category itself existed, originally as a managed security service provider before evolving its platform into what it now markets as native, managed SASE Experience. The company’s ownership history took a distinctive turn in 2023: after a period under the European private-equity firm EQT, Open Systems was acquired by Swiss Post - Switzerland’s state-backed national postal and logistics institution - a materially different kind of owner from the venture-capital or private-equity structures behind most other vendors in this category.
- Orange Business (Orange Business Evolution Platform, Orange Business SASE with Palo Alto Networks Prisma SASE, Orange Business and Fortinet SASE, Orange Cyberdefense Managed SASE): Global managed network leadership with strong service assurance, NOC depth and field operations.
- Vodafone Business (Fortinet-based Secure Networking, Vodafone Business Managed Network Services, Vodafone Business Network as a Service (NaaS), Vodafone Business SASE): Strong UK and European market presence with NaaS positioning and integrated mobile/fixed access.
- BT (Agile Connect, BT Managed Fortinet Firewall, BT Managed SASE (Fortinet-based), BT Managed SASE (Meraki-based)): UK market leader for managed SD-WAN with deep access circuit ownership and field engineering capability.
- Ericsson Cradlepoint (NetCloud Federal, NetCloud Manager, NetCloud Perimeter, NetCloud Private Networks): Wireless-first branch architecture from Ericsson with deep 5G expertise; NetCloud provides cellular-centric SD-WAN management.
- Verizon Business (RingCentral (voice/UC integration), Verizon Managed SD Branch, Verizon Managed SD WAN, Verizon SASE Management): Global carrier-led managed SASE and SD-WAN with strong North American presence and international delivery.
- Comcast Business (Comcast Business CASB, Comcast Business FWaaS, Comcast Business Managed SD-WAN, Comcast Business SASE): SASE combining SD-WAN and security available fully managed or co-managed, drawing on Masergy AIOps heritage.
- Virgin Media O2 Business (8x8 Voice for Teams, Cloud Infrastructure as a Service / Platform as a Service, Managed Detection and Response, Success Agreement): Virgin Media O2 (VMO2) is itself a 50/50 joint venture between Liberty Global and Telefónica, formed in June 2021 from the merger of Virgin Media UK and O2 UK. On 12 May 2025, VMO2 announced it would combine substantially all of its direct business-to-business operations - including Virgin Media O2 Business - with Daisy Group, a long-established, independent UK B2B communications and IT provider founded in 2001.
Comparison summary
Leading managed sd-wan providers at a glance
| Rank and provider | Type | Products | Best suited to | Main strength | Confirm through RFP | Reviewed |
|---|---|---|---|---|---|---|
| 1Lumen | technology vendor / managed service provider / carrier network provider | Black Lotus Labs, Lumen Managed SASE Solutions, Lumen SASE with Versa, Lumen SD-WAN with Versa Networks | North American enterprises wanting integrated managed SD-WAN, access and broader network services from one provider. | Fully managed or co-managed SD-WAN with strong NaaS positioning and integrated network services. | Multi-tenant MSP / white-label support | 2026-09-01 |
| 2Expereo | managed service provider / carrier network provider | Expereo Enhanced Internet, Expereo Managed SD-WAN, Expereo SD-WAN/SASE with Cato Networks, Starlink (via Expereo, authorised reseller) | Rather than owning last-mile or backbone infrastructure directly, Expereo positions itself explicitly as an internet-connectivity aggregation and optimisation specialist, describing itself as a ‘world-leading Managed Network as a Service provider’ built around a ‘Global Internet’ underlay philosophy - the consistent, repeated framing across its own materials is that a strong internet underlay, not owned physical infrastructure, is the essential foundation for effective SD-WAN and SASE. Founded in Amsterdam in 2004, Expereo has passed through a complex, multi-owner private-equity history: acquired by The Carlyle Group in July 2014, sold to Apax Partners in May 2018, and majority-acquired b... | Rather than owning last-mile or backbone infrastructure directly, Expereo positions itself explicitly as an internet-connectivity aggregation and optimisation specialist, describing itself as a ‘world-leading Managed Network as a Service provider’ built around a ‘Global Internet’ underlay philosophy - the consistent, repeated framing across its own materials is that a strong internet underlay, not owned physical infrastructure, is the essential foundation for effective SD-WAN and SASE. Founded in Amsterdam in 2004, Expereo has passed through a complex, multi-owner private-equity history: acquired by The Carlyle Group in July 2014, sold to Apax Partners in May 2018, and majority-acquired b... | DIY / self-managed model | 2026-09-01 |
| 3Open Systems | technology vendor / managed service provider | MDR+ (Managed Detection and Response), Managed SD-WAN / Secure SD-WAN, Managed, Universal SSE, Mission Control | Open Systems founded in 1990 in Basel, Switzerland, more than three decades before the SASE category itself existed, originally as a managed security service provider before evolving its platform into what it now markets as native, managed SASE Experience. The company’s ownership history took a distinctive turn in 2023: after a period under the European private-equity firm EQT, Open Systems was acquired by Swiss Post - Switzerland’s state-backed national postal and logistics institution - a materially different kind of owner from the venture-capital or private-equity structures behind most other vendors in this category. | Open Systems founded in 1990 in Basel, Switzerland, more than three decades before the SASE category itself existed, originally as a managed security service provider before evolving its platform into what it now markets as native, managed SASE Experience. The company’s ownership history took a distinctive turn in 2023: after a period under the European private-equity firm EQT, Open Systems was acquired by Swiss Post - Switzerland’s state-backed national postal and logistics institution - a materially different kind of owner from the venture-capital or private-equity structures behind most other vendors in this category. | Multi-tenant MSP / white-label support | 2026-09-01 |
| 4Orange Business | carrier network provider / integrator | Orange Business Evolution Platform, Orange Business SASE with Palo Alto Networks Prisma SASE, Orange Business and Fortinet SASE, Orange Cyberdefense Managed SASE | Multinational enterprises wanting a single global managed provider for SD-WAN, SASE and access. | Global managed network leadership with strong service assurance, NOC depth and field operations. | DIY / self-managed model | 2026-09-01 |
| 5Vodafone Business | managed service provider / carrier network provider | Fortinet-based Secure Networking, Vodafone Business Managed Network Services, Vodafone Business Network as a Service (NaaS), Vodafone Business SASE | UK and European enterprises wanting carrier-led SD-WAN with strong mobile and 5G integration. | Strong UK and European market presence with NaaS positioning and integrated mobile/fixed access. | DIY / self-managed model | 2026-09-01 |
| 6BT | managed service provider / carrier network provider | Agile Connect, BT Managed Fortinet Firewall, BT Managed SASE (Fortinet-based), BT Managed SASE (Meraki-based) | UK enterprises wanting a single supplier for SD-WAN platform, access circuits, security and field operations. | UK market leader for managed SD-WAN with deep access circuit ownership and field engineering capability. | DIY / self-managed model | 2026-09-01 |
| 7Ericsson Cradlepoint | technology vendor / carrier network provider | NetCloud Federal, NetCloud Manager, NetCloud Perimeter, NetCloud Private Networks | Distributed enterprises with strong cellular/5G access strategy (retail, logistics, transport, public sector). | Wireless-first branch architecture from Ericsson with deep 5G expertise; NetCloud provides cellular-centric SD-WAN management. | Co-managed service | 2026-09-01 |
| 8Verizon Business | managed service provider / carrier network provider | RingCentral (voice/UC integration), Verizon Managed SD Branch, Verizon Managed SD WAN, Verizon SASE Management | North American and multinational enterprises wanting carrier-led managed SD-WAN and SASE. | Global carrier-led managed SASE and SD-WAN with strong North American presence and international delivery. | DIY / self-managed model | 2026-09-01 |
| 9Comcast Business | managed service provider / carrier network provider | Comcast Business CASB, Comcast Business FWaaS, Comcast Business Managed SD-WAN, Comcast Business SASE | North American enterprises wanting managed or co-managed SD-WAN and SASE from a single carrier. | SASE combining SD-WAN and security available fully managed or co-managed, drawing on Masergy AIOps heritage. | DIY / self-managed model | 2026-09-01 |
| 10Virgin Media O2 Business | managed service provider / carrier network provider | 8x8 Voice for Teams, Cloud Infrastructure as a Service / Platform as a Service, Managed Detection and Response, Success Agreement | Virgin Media O2 (VMO2) is itself a 50/50 joint venture between Liberty Global and Telefónica, formed in June 2021 from the merger of Virgin Media UK and O2 UK. On 12 May 2025, VMO2 announced it would combine substantially all of its direct business-to-business operations - including Virgin Media O2 Business - with Daisy Group, a long-established, independent UK B2B communications and IT provider founded in 2001. | Virgin Media O2 (VMO2) is itself a 50/50 joint venture between Liberty Global and Telefónica, formed in June 2021 from the merger of Virgin Media UK and O2 UK. On 12 May 2025, VMO2 announced it would combine substantially all of its direct business-to-business operations - including Virgin Media O2 Business - with Daisy Group, a long-established, independent UK B2B communications and IT provider founded in 2001. | DIY / self-managed model | 2026-09-01 |
The table uses governed provider records. Unknown evidence is shown as a point to confirm, not a negative score.

Ranked shortlists
Pre-built rankings by sector, size and priority
Definitions
The 40 capabilities, defined
Every provider is graded against the same 40 capabilities. One sentence on what each row measures; grades reflect public evidence, so always confirm via RFP.
Service delivery and operating model
8 capabilities
- Fully managed service.
- The provider designs, deploys, monitors, changes, supports and reports on the service end to end, so the customer sets policy and outcomes rather than running day-to-day operations.
- DIY / self-managed model.
- The customer's own team operates the platform directly, owning the controller, policies, updates and incident response.
- Co-managed service.
- Responsibility is shared: the provider runs the platform and support while the customer retains selected policy and change rights.
- Multi-tenant MSP / white-label support.
- The platform supports tenant isolation, delegated administration, branded portals and templates, so managed service providers can operate it for many customers under their own brand.
- Professional services and migration support.
- Structured design and migration services are available, covering discovery, pilots, staging, migration runbooks, rollback plans and training.
- Last-mile circuit management.
- The provider sources, monitors and supports the underlay access circuits at each site, across broadband, dedicated internet access, LTE and 5G, MPLS and cross-connects, giving one accountable party for connectivity and overlay together.
- Lifecycle management.
- Hardware replacement, firmware upgrades, patching, renewals and end-of-life planning are handled as part of the service.
- Flexible commercial model.
- Pricing can be structured in more than one way, such as per site, per user, per bandwidth, consumption-based or as NaaS, with terms that adapt to the buyer's estate.
Network architecture and transport
10 capabilities
- Encrypted overlay fabric.
- Site and user traffic runs through secure tunnels built over any underlying transport, including broadband, dedicated internet, MPLS, LTE and 5G or satellite, keeping data protected across mixed networks.
- Dynamic path selection.
- The platform routes traffic in real time based on measured latency, jitter, packet loss and policy, steering around brownouts without manual intervention.
- Active-active link utilisation.
- All available links carry traffic concurrently rather than one sitting idle as passive backup, increasing usable capacity and smoothing failover.
- Application-aware routing.
- Traffic is identified at application level and routed by per-application policy, so business-critical applications such as UCaaS and ERP take priority.
- QoS and traffic shaping.
- Bandwidth can be prioritised, reserved and policed per application or traffic class, protecting voice, video and critical traffic under congestion.
- Packet loss remediation.
- Techniques such as forward error correction, packet duplication, jitter buffering and TCP optimisation repair or mask loss on poor-quality links, keeping real-time applications usable.
- Local internet breakout.
- Internet-bound traffic exits securely and directly from the branch rather than being backhauled through a central data centre, reducing latency for cloud and SaaS traffic.
- MPLS coexistence and migration.
- Existing MPLS circuits can run alongside internet and cellular transport during a phased migration, so estates move site by site without a risky single cutover.
- Cellular and 5G support.
- 4G and 5G connections are supported as primary or failover transport, with integrated or external modems, SIM management and signal monitoring.
- Cloud on-ramp.
- Connectivity into cloud platforms such as AWS, Microsoft Azure, Google Cloud and Oracle, and interconnect fabrics such as Equinix and Megaport, is automated and simplified rather than hand-built per cloud.
Gateway, PoP and backbone design
8 capabilities
- Public cloud gateways.
- The vendor operates shared gateways and points of presence that deliver SaaS optimisation, remote access or security enforcement as a cloud service; this measures the vendor's own service infrastructure, distinct from dedicated private PoPs.
- Private PoPs / dedicated PoPs.
- Points of presence can be supplied as customer-hosted, dedicated or sovereign deployments rather than only the provider's shared multi-tenant locations.
- Private global backbone.
- Traffic between regions rides a backbone owned or controlled by the vendor rather than the public internet, giving predictable latency and loss between PoPs.
- Regional breakout and data residency.
- Traffic can be pinned to chosen countries, regions or approved inspection locations, supporting data residency and sovereignty requirements.
- Multi-cloud transit fabric.
- Branch-to-cloud, cloud-to-cloud and user-to-cloud traffic runs under one common policy through the provider's fabric rather than through customer-built interconnects.
- Flexible edge form factors.
- The edge is available as hardware appliances, virtual machines, cloud marketplace images, containers or uCPE, so each site can use the form that suits it.
- High availability design.
- Redundant designs are supported across appliances, circuits, power and gateways, with clustering and automatic failover keeping sites connected through failures.
- SLA-backed service fabric.
- The service carries contractual commitments covering uptime, response and change handling, and in some cases latency, jitter and loss, rather than best-effort targets.
Security and SASE capability
9 capabilities
- Integrated next-generation firewall.
- Stateful firewalling, application control, intrusion prevention, malware inspection and URL filtering are built into the platform rather than supplied as a separate appliance.
- Full SASE platform.
- Networking and security converge in one platform, combining SD-WAN with cloud-delivered controls including SWG, CASB, ZTNA, firewall as a service, DLP and threat prevention.
- SSE ecosystem integration.
- The platform interoperates with third-party security service edge providers such as Zscaler, Netskope, Palo Alto Prisma Access and Cisco Secure Access, for buyers running a best-of-breed rather than single-vendor stack.
- Zero Trust Network Access.
- Users are connected to specific private applications based on identity and device posture rather than being placed on the network, replacing broad VPN access with least-privilege access.
- Secure web gateway.
- Web traffic is filtered and inspected, with URL filtering, SSL inspection, malware scanning and acceptable-use controls enforced in the cloud.
- CASB capability.
- Cloud access security broker controls provide SaaS discovery, sanctioned and unsanctioned application control and SaaS policy enforcement, including shadow IT visibility.
- Data loss prevention.
- Content is classified and inspected for sensitive data, which can be blocked or flagged before it leaves the organisation, with alerting and exception workflows.
- Remote user access.
- Remote workers, contractors and mobile users connect through the same platform and policies as sites, through a lightweight client or clientless browser access.
- SOC/SIEM/SOAR integration.
- Logs, events and threat intelligence export cleanly over syslog and APIs into SIEM, SOAR and security operations tooling, so the service fits an existing detection and response workflow.
Operations, assurance and automation
5 capabilities
- Centralised orchestration.
- Configuration and policy are managed from a single console using templates, intent-based policy and zero-touch provisioning, with changes pushed network-wide rather than device by device.
- Customer portal and RBAC.
- A customer-facing portal provides real-time status, reporting, tickets and change requests, with role-based access so different teams see and change only what they should.
- Observability and digital experience monitoring.
- Application experience, user experience, device health and path analytics are measured end to end, so degradation is visible before tickets are raised.
- APIs and automation.
- Documented interfaces such as REST APIs, Terraform, webhooks and event streaming allow configuration, reporting and ITSM integration to be automated.
- Managed service assurance.
- The provider's 24/7 NOC and SOC monitor the service proactively, own incidents through to root cause analysis, and run structured service reviews and change governance.
Questions
How the shortlist builder works
Which SD-WAN vendor is best?
There is no single best vendor for every estate. The right shortlist depends on operating model, regions, applications, security requirements and the evidence a supplier can provide for the project.
Who are the leading SD-WAN providers?
The SD-WAN vendor view ranks the current governed records using network-led criteria. The order changes when a buyer adds required regions, managed service delivery, cloud platforms or individual capabilities.
Is SD-WAN obsolete?
No. SD-WAN remains the network layer in many SASE designs. SASE adds cloud-delivered security and access controls rather than removing the need to control WAN traffic.
Should a business choose SD-WAN or MPLS?
Many estates use both during migration. SD-WAN can use internet, cellular and MPLS underlays, while the RFP should define application performance, resilience and any sites that must retain private circuits.
Who are the leading SASE vendors?
The SASE vendor view ranks providers with public SASE, ZTNA or secure web gateway evidence. Buyers should compare the networking and security components separately before accepting a single-vendor claim.
How does the shortlist builder rank vendors?
The Netify shortlist builder ranks each and every provider based on their capabilities to deliver 40 different in-built features, alongside the likes of regional coverage, cloud support, AI capabilities, resilience and deployment speed, all of which is drawn from information we've been able to publicly source or find evidence for.
Can I share or save my shortlist?
Yes absolutely, every filter combination is matched to an associated page URL, enabling you to copy a link to take you (or board directors) straight back to the same filtered list again at a later date, as well as being able to download a PDF version or have the ranked list emailed to you.
What does Build from requirements do?
Describe your estate in plain language, including site count, regions, security requirements and operating model. Netify maps the description to the same filters and scoring engine used by the manual controls, then explains the resulting shortlist.
Is this comparison vendor neutral?
Yes, we don't have a bias to any vendor and use publicly available sources and evidence only, as well as every vendor being scored against the exact same matrix. We must mention that Netify is a BT Authorised Partner and earns commission on some routes to market, however these rankings are not influenced by commercial relationships.
How accurate are the extended dimensions?
There are two different levels of evidence here and we would rather be plain about which is which. Eighteen facts per provider were re-sourced on 29 July 2026 from the provider's own published material or an independently accountable record, and each one carries a named source, a reliability tier and a sentence quoted from that source which we then re-checked against the live page: the thirteen capabilities that genuinely separate this market, who owns the underlay, whose security service edge stack it is, whether real compliance documentation exists rather than a general assurance, plus published points of presence and availability SLA. The remaining grades, including regional coverage, cloud support, AI capability and resilience, are still indicative desk research rather than individually sourced, and we say so rather than dress them up. Where we could not evidence something we publish it as unknown with the reason. For anything you are going to sign a contract on, confirm it through a structured RFP, which Netify can create and issue to your shortlisted providers.