Provider evidence
Cisco
Cisco’s own materials describe SASE explicitly as ‘a journey - you can start with SD-WAN or SSE and converge over time’, which is a different pitch to Cato’s, Zscaler’s, Netskope’s or Palo Alto’s single-platform-from-day-one story. In practise, ‘Cisco SASE’ means choosing between Cisco Secure Access (cloud-delivered SSE, evolved from Cisco Umbrella), Cisco Catalyst SD-WAN (the enterprise-grade fabric, formerly Viptela) or Meraki SD-WAN (the simpler, cloud-first option), and Cisco Secure Connect (a turnkey bundle of Secure Access plus Meraki SD-WAN specifically).
Technology vendor · UK entity not yet reviewed
Evidence profile: Manufacturing; Professional services; Hospitality and leisure; Large global enterprise; platform
Peco Foods is identified as food manufacturing with a Cisco SASE deployment. Manufacturing evidence is US-based. The separate Mitchells and Butlers case documents UK hospitality SASE and Meraki SD-WAN. Regional coverage remains partial: it does not establish coverage of every UK/Ireland site or a contracting entity. Neither case certifies compliance or suitability for a particular estate. Recovered Cisco George Sink PDF: Secure Connect deployed in a law firm; SD-WAN expansion described as a next step. This is sector experience only; scope, UK delivery and suitability for the buyer require separate confirmation.
- https://www.cisco.com/c/dam/en/us/products/security/secure-access/customer-highlight-peco-foods.pdf
- https://www.cisco.com/site/us/en/about/case-studies-customer-stories/mitchells-butlers.html
- https://cisco.com/site/us/en/solutions/secure-access-service-edge-sase/index.html
- https://www.cisco.com/c/en/us/products/collateral/plus-as-a-service/george-sink-law-customer-cs.pdf
Research only
https://www.cisco.com/site/us/en/solutions/networking/sdwan/index.htmlThese capabilities use the same evidence as the provider shortlist and matching. A missing finding is not evidence that a provider lacks the capability.
Capability evidence
| Capability | Finding | Evidence and qualification |
|---|---|---|
| Fully managed service | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| DIY / self-managed model | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Co-managed service | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Multi-tenant MSP / white-label support | Yes | Managed Service Providers (MSPs) can now take advantage of custom branding options within the Cisco Meraki Dashboard. All four elements of the definition are evidenced. Branded portals from the Meraki dashboard branding documentation, which also states "Any logos that are applied to Dashboard should be the logo of the MSP and not of the end customer." Tenant isolation and delegated administration from multi-organisation management, corroborated on the Secure Access datasheet: "Large enterprise customers can manage multiple organizations (orgs) through a single user interface, with central access and license management." Branding is configured per organisation and can be cloned to new organisations as a template. Source · Evidence dated 2026-07-29 |
| Professional services and migration support | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Last-mile circuit management | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Lifecycle management | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Flexible commercial model | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Encrypted overlay fabric | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Dynamic path selection | Not primary | See the published provider record for source context; confirm the scope for your deployment. |
| Active-active link utilisation | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Application-aware routing | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| QoS and traffic shaping | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Packet loss remediation | Yes | Native, specifically confirmed in the AI-traffic context - the February 2026 AI-aware SASE announcement explicitly names 'packet duplication' as an AI traffic optimization technique [25] Source · Evidence dated 2026-07-22 |
| Local internet breakout | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| MPLS coexistence and migration | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Cellular and 5G support | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Cloud on-ramp | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Public cloud gateways | Yes | Cisco Secure Connect services operate in the Cisco Umbrella global cloud architecture which is network of data centers located throughout the world interconnected with a high speed, low latency backbone. Yes rather than partner_integrated. This is Cisco's own service infrastructure, not a third party's PoPs that Cisco resells: Cisco owns and operates the Umbrella global cloud architecture, publishes its data centre list, and enforces security and delivers remote access from it. Corroborated by the Umbrella global network page, "The Cisco Umbrella global cloud architecture serves more than 30,000 customers daily in 190+ countries." AWS, Azure and GCP connectivity was disregarded as it does not meet the definition. Source · Evidence dated 2026-07-29 |
| Private PoPs / dedicated PoPs | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Private global backbone | Partial | Cisco Secure Connect services operate in the Cisco Umbrella global cloud architecture which is network of data centers located throughout the world interconnected with a high speed, low latency backbone. Partial rather than yes. A global, not national, footprint is clearly evidenced and the documentation states the data centres are interconnected by a backbone. What is not evidenced is the ownership or control test in the definition: no page reviewed states that Cisco owns or controls that backbone rather than buying transit or leased capacity. The Umbrella global cloud architecture page instead emphasises internet peering and anycast, "Umbrella peers directly with more than 1000 organizations", which points towards an internet-peering-centric design. Graded partial on the ownership gap. See conflicts. Source · Evidence dated 2026-07-29 |
| Regional breakout and data residency | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Multi-cloud transit fabric | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Flexible edge form factors | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| High availability design | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| SLA-backed service fabric | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Integrated next-generation firewall | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Full SASE platform | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| SSE ecosystem integration | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Zero Trust Network Access | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Secure web gateway | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| CASB capability | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Data loss prevention | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Remote user access | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| SOC/SIEM/SOAR integration | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Centralised orchestration | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Customer portal and RBAC | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Observability and digital experience monitoring | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| APIs and automation | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Managed service assurance | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |