NNetifyVersion 1010261227

Provider evidence

Check Point

Check Point’s SASE platform has been through two names in under three years. The underlying technology began life as Perimeter 81, an independent Israeli SSE/ZTNA vendor founded in 2018 that had grown to more than 3,000 customers and a Forrester Zero Trust Wave recognition before Check Point Software Technologies - the much larger, long-established Israeli cybersecurity vendor behind Check Point Firewall-1, founded in 1993 - acquired it for approximately $490 million in a deal announced September 2023.

Technology vendor · UK entity not yet reviewed

Evidence profile: Sector evidence not yet reviewed; platform

    Research only

    https://www.checkpoint.com/harmony/sase

    These capabilities use the same evidence as the provider shortlist and matching. A missing finding is not evidence that a provider lacks the capability.

    Capability evidence

    CapabilityFindingEvidence and qualification
    Fully managed servicePartial

    Managed Firewall Services with 24/7 monitoring, policy management, tuning, patching, upgrades, incident handling, and expert support for Check Point and third-party NGFWs. Check Point sells first-party managed services covering firewall, EDR, vulnerability management and Microsoft 365, with 24/7 monitoring, policy management and incident handling. I did not find a page describing Check Point itself designing, deploying, changing and reporting on the SASE service end to end for the customer, so partial rather than yes. The Managed Firewall as a Service page (register 20) could not be read.

    Source · Evidence dated 2026-07-29
    DIY / self-managed modelYesSee the published provider record for source context; confirm the scope for your deployment.
    Co-managed serviceYes

    Delivering co-managed services with partners and customers for optimal protection through unified collaboration and robust security strategies. Check Point explicitly frames its managed security offer as co-managed, with its experts acting as an extension of the customer team while the customer retains its own operations.

    Source · Evidence dated 2026-07-29
    Multi-tenant MSP / white-label supportPartial

    Leverage true multi-tenancy, a wide range of security services, and full API integration to streamline customer management and accelerate service delivery. Multi-tenant architecture, delegated multi-customer management through one portal and API integration are all stated on the MSSP programme page. I found no statement of branded or white-label portals under the MSP's own brand, which the definition requires, so partial rather than yes.

    Source · Evidence dated 2026-07-29
    Professional services and migration supportYes

    As your security infrastructure becomes more complicated, our Professional Services team can assist you with your security design, deployment, operation, and optimization needs. The same page lists a Jumpstart Program, Maestro Deployment, SmartOptimize, Gateway Health Check and Lifecycle Management Services, and states delivery covers adding new features and layers while ensuring smooth migrations and scheduled updates. Training programmes are listed separately. Explicit runbook and rollback wording was not found.

    Source · Evidence dated 2026-07-29
    Last-mile circuit managementNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Lifecycle managementYes

    Check Point shall use commercially reasonable efforts to ship the replacement hardware on the same business day, however, shipment my occur on the next business day if required for operational reasons. Support programmes include RMA hardware replacement with same business day shipment and onsite delivery options, plus Latest Hot Fixes & Service Packs and Major Upgrades & Enhancements on every tier, and Lifecycle Management Services is a named professional service. This is a purchased support or services contract rather than something bundled into every subscription. The dedicated lifecycle management page (register 15) could not be read. The quote reproduces the page's own typo.

    Source · Evidence dated 2026-07-29
    Flexible commercial modelNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Encrypted overlay fabricYesSee the published provider record for source context; confirm the scope for your deployment.
    Dynamic path selectionNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Active-active link utilisationNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Application-aware routingNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    QoS and traffic shapingNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Packet loss remediationNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Local internet breakoutNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    MPLS coexistence and migrationNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Cellular and 5G supportPartial

    Sub-second failover to any WAN link: MPLS, 5G, broadband 5G is named as a supported WAN failover transport for SD-WAN, and the NGFW page notes a Wi-Fi 5G option on small business appliances and 1 GbE & 5G wireless secure connectivity on industrial appliances. I found no statement covering SIM management or signal monitoring, which the definition requires, so partial. The Quantum SD-WAN page (register 14) could not be read.

    Source · Evidence dated 2026-07-29
    Cloud on-rampNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Public cloud gatewaysYes

    Our high-performance network provides fast delivery between corporate sites worldwide thanks to multiple tier-1 links at each point-of-presence (PoP), reserved bandwidth, and peering agreements. Check Point operates its own PoP and data centre estate for SASE internet access, private access and SaaS security, described as 80+ to 85+ global data centres depending on the page. This is Check Point's own infrastructure rather than a resold third party edge, so yes rather than partner_integrated.

    Source · Evidence dated 2026-07-29
    Private PoPs / dedicated PoPsNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Private global backboneYes

    Our high-performance network provides fast delivery between corporate sites worldwide thanks to multiple tier-1 links at each point-of-presence (PoP), reserved bandwidth, and peering agreements. The heading above this text is Global Private Backbone, and the SASE overview separately states Private Access delivers high performance with a full mesh global private backbone. The backbone is global rather than national. Check Point describes it as built on purchased tier-1 links, reserved bandwidth and peering rather than fibre it owns, so it is a controlled overlay backbone rather than owned infrastructure.

    Source · Evidence dated 2026-07-29
    Regional breakout and data residencyNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Multi-cloud transit fabricNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Flexible edge form factorsNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    High availability designNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    SLA-backed service fabricPartial

    Get advanced access to our large, self-service knowledge base and a committed 30-minute response time to issues with level one severity. Check Point publishes contractual support SLAs with per-severity response times (30 minutes for Severity 1 across all tiers), 7x24 coverage on Premium and above, and named SLA documents including the Check Point Direct Support Program Service Level Agreement. I found no published availability, latency, jitter or loss commitment for the SASE cloud service, so partial rather than yes.

    Source · Evidence dated 2026-07-29
    Integrated next-generation firewallYes

    Native, via the confirmed FWaaS capability [24] [28]

    Source · Evidence dated 2026-07-22
    Full SASE platformYesSee the published provider record for source context; confirm the scope for your deployment.
    SSE ecosystem integrationNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Zero Trust Network AccessYesSee the published provider record for source context; confirm the scope for your deployment.
    Secure web gatewayYesSee the published provider record for source context; confirm the scope for your deployment.
    CASB capabilityYesSee the published provider record for source context; confirm the scope for your deployment.
    Data loss preventionYes

    Inline and API-based enforcement with Application Control for 10,000+ cloud apps, tenant restrictions, DLP, and Threat Prevention powered by ThreatCloud AI The same pages state AI-powered data classification with 800+ predefined data types, and the Internet Access page cites in-browser data loss prevention. Content classification and inline enforcement are clearly evidenced. Explicit alerting and exception workflow detail was not found on the pages read.

    Source · Evidence dated 2026-07-29
    Remote user accessYesSee the published provider record for source context; confirm the scope for your deployment.
    SOC/SIEM/SOAR integrationYes

    Native, confirmed with genuine technical specificity as part of the platform's SOC 2 Type 2 compliance architecture - 'monitor system activity, view system configuration changes and assign user access controls', with audit trails covering 'the modification, addition, or removal of key system components' [18] Not confirmed

    Source · Evidence dated 2026-07-22
    Centralised orchestrationYesSee the published provider record for source context; confirm the scope for your deployment.
    Customer portal and RBACNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Observability and digital experience monitoringYesSee the published provider record for source context; confirm the scope for your deployment.
    APIs and automationNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Managed service assurancePartial

    Our 24/7 global service team will be there whenever and wherever you need them to help make sure your organization is always protected. 24/7 coverage, incident handling and NOC and SOC oriented managed services are stated, and the services pages claim 99% of threats responded to within 1 hour. I found no statement of provider-owned root cause analysis, structured service reviews or change governance, so partial. The Managed Detection and Response page (register 19) could not be read.

    Source · Evidence dated 2026-07-29