Provider evidence
Check Point
Check Point’s SASE platform has been through two names in under three years. The underlying technology began life as Perimeter 81, an independent Israeli SSE/ZTNA vendor founded in 2018 that had grown to more than 3,000 customers and a Forrester Zero Trust Wave recognition before Check Point Software Technologies - the much larger, long-established Israeli cybersecurity vendor behind Check Point Firewall-1, founded in 1993 - acquired it for approximately $490 million in a deal announced September 2023.
Technology vendor · UK entity not yet reviewed
Evidence profile: Sector evidence not yet reviewed; platform
Research only
https://www.checkpoint.com/harmony/saseThese capabilities use the same evidence as the provider shortlist and matching. A missing finding is not evidence that a provider lacks the capability.
Capability evidence
| Capability | Finding | Evidence and qualification |
|---|---|---|
| Fully managed service | Partial | Managed Firewall Services with 24/7 monitoring, policy management, tuning, patching, upgrades, incident handling, and expert support for Check Point and third-party NGFWs. Check Point sells first-party managed services covering firewall, EDR, vulnerability management and Microsoft 365, with 24/7 monitoring, policy management and incident handling. I did not find a page describing Check Point itself designing, deploying, changing and reporting on the SASE service end to end for the customer, so partial rather than yes. The Managed Firewall as a Service page (register 20) could not be read. Source · Evidence dated 2026-07-29 |
| DIY / self-managed model | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Co-managed service | Yes | Delivering co-managed services with partners and customers for optimal protection through unified collaboration and robust security strategies. Check Point explicitly frames its managed security offer as co-managed, with its experts acting as an extension of the customer team while the customer retains its own operations. Source · Evidence dated 2026-07-29 |
| Multi-tenant MSP / white-label support | Partial | Leverage true multi-tenancy, a wide range of security services, and full API integration to streamline customer management and accelerate service delivery. Multi-tenant architecture, delegated multi-customer management through one portal and API integration are all stated on the MSSP programme page. I found no statement of branded or white-label portals under the MSP's own brand, which the definition requires, so partial rather than yes. Source · Evidence dated 2026-07-29 |
| Professional services and migration support | Yes | As your security infrastructure becomes more complicated, our Professional Services team can assist you with your security design, deployment, operation, and optimization needs. The same page lists a Jumpstart Program, Maestro Deployment, SmartOptimize, Gateway Health Check and Lifecycle Management Services, and states delivery covers adding new features and layers while ensuring smooth migrations and scheduled updates. Training programmes are listed separately. Explicit runbook and rollback wording was not found. Source · Evidence dated 2026-07-29 |
| Last-mile circuit management | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Lifecycle management | Yes | Check Point shall use commercially reasonable efforts to ship the replacement hardware on the same business day, however, shipment my occur on the next business day if required for operational reasons. Support programmes include RMA hardware replacement with same business day shipment and onsite delivery options, plus Latest Hot Fixes & Service Packs and Major Upgrades & Enhancements on every tier, and Lifecycle Management Services is a named professional service. This is a purchased support or services contract rather than something bundled into every subscription. The dedicated lifecycle management page (register 15) could not be read. The quote reproduces the page's own typo. Source · Evidence dated 2026-07-29 |
| Flexible commercial model | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Encrypted overlay fabric | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Dynamic path selection | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Active-active link utilisation | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Application-aware routing | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| QoS and traffic shaping | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Packet loss remediation | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Local internet breakout | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| MPLS coexistence and migration | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Cellular and 5G support | Partial | Sub-second failover to any WAN link: MPLS, 5G, broadband 5G is named as a supported WAN failover transport for SD-WAN, and the NGFW page notes a Wi-Fi 5G option on small business appliances and 1 GbE & 5G wireless secure connectivity on industrial appliances. I found no statement covering SIM management or signal monitoring, which the definition requires, so partial. The Quantum SD-WAN page (register 14) could not be read. Source · Evidence dated 2026-07-29 |
| Cloud on-ramp | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Public cloud gateways | Yes | Our high-performance network provides fast delivery between corporate sites worldwide thanks to multiple tier-1 links at each point-of-presence (PoP), reserved bandwidth, and peering agreements. Check Point operates its own PoP and data centre estate for SASE internet access, private access and SaaS security, described as 80+ to 85+ global data centres depending on the page. This is Check Point's own infrastructure rather than a resold third party edge, so yes rather than partner_integrated. Source · Evidence dated 2026-07-29 |
| Private PoPs / dedicated PoPs | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Private global backbone | Yes | Our high-performance network provides fast delivery between corporate sites worldwide thanks to multiple tier-1 links at each point-of-presence (PoP), reserved bandwidth, and peering agreements. The heading above this text is Global Private Backbone, and the SASE overview separately states Private Access delivers high performance with a full mesh global private backbone. The backbone is global rather than national. Check Point describes it as built on purchased tier-1 links, reserved bandwidth and peering rather than fibre it owns, so it is a controlled overlay backbone rather than owned infrastructure. Source · Evidence dated 2026-07-29 |
| Regional breakout and data residency | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Multi-cloud transit fabric | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Flexible edge form factors | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| High availability design | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| SLA-backed service fabric | Partial | Get advanced access to our large, self-service knowledge base and a committed 30-minute response time to issues with level one severity. Check Point publishes contractual support SLAs with per-severity response times (30 minutes for Severity 1 across all tiers), 7x24 coverage on Premium and above, and named SLA documents including the Check Point Direct Support Program Service Level Agreement. I found no published availability, latency, jitter or loss commitment for the SASE cloud service, so partial rather than yes. Source · Evidence dated 2026-07-29 |
| Integrated next-generation firewall | Yes | Native, via the confirmed FWaaS capability [24] [28] Source · Evidence dated 2026-07-22 |
| Full SASE platform | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| SSE ecosystem integration | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Zero Trust Network Access | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Secure web gateway | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| CASB capability | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Data loss prevention | Yes | Inline and API-based enforcement with Application Control for 10,000+ cloud apps, tenant restrictions, DLP, and Threat Prevention powered by ThreatCloud AI The same pages state AI-powered data classification with 800+ predefined data types, and the Internet Access page cites in-browser data loss prevention. Content classification and inline enforcement are clearly evidenced. Explicit alerting and exception workflow detail was not found on the pages read. Source · Evidence dated 2026-07-29 |
| Remote user access | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| SOC/SIEM/SOAR integration | Yes | Native, confirmed with genuine technical specificity as part of the platform's SOC 2 Type 2 compliance architecture - 'monitor system activity, view system configuration changes and assign user access controls', with audit trails covering 'the modification, addition, or removal of key system components' [18] Not confirmed Source · Evidence dated 2026-07-22 |
| Centralised orchestration | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Customer portal and RBAC | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Observability and digital experience monitoring | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| APIs and automation | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Managed service assurance | Partial | Our 24/7 global service team will be there whenever and wherever you need them to help make sure your organization is always protected. 24/7 coverage, incident handling and NOC and SOC oriented managed services are stated, and the services pages claim 99% of threats responded to within 1 hour. I found no statement of provider-owned root cause analysis, structured service reviews or change governance, so partial. The Managed Detection and Response page (register 19) could not be read. Source · Evidence dated 2026-07-29 |