Provider evidence
Verizon Business
6 billion in revenue in 2023 (2025 consensus estimates are approximately $134-135 billion) and serving nearly all of the Fortune 500 - and its managed SD-WAN and SASE proposition sits within Verizon Business, itself organised into three named customer groups (Enterprise and Public Sector, Business Markets and Other, and Wholesale).
Managed service provider / carrier network provider · UK entity not yet reviewed
Evidence profile: Healthcare (partial evidence); Manufacturing (partial evidence); Large global enterprise; managed
Verizon federal-agency page is secure cloud video collaboration for 20,000 users. The linked case is not SD-WAN/SASE evidence. Verizon manufacturing case explicitly describes SD-WAN design, rollout and traffic segmentation; manufacturer is unnamed. This is sector experience only; scope, UK delivery and suitability for the buyer require separate confirmation. Recovered primary anonymous healthcare SASE deployment: 200 sites, supplier managed. Does not establish UK/NHS delivery or a named customer.
- https://verizon.com/business/resources/customer-success-stories/federal-agency/
- https://verizon.com/business/resources/articles/s/three-sd-wan-use-cases-for-enterprises/
- https://verizon.com/business/resources/customer-success-stories/manufacturing-giant/
- https://www.verizon.com/business/resources/articles/sase-helps-healthcare-business-privacy-concerns.pdf
Research only
https://www.verizon.com/business/resources/lp/secure-access-service-edgeThese capabilities use the same evidence as the provider shortlist and matching. A missing finding is not evidence that a provider lacks the capability.
Capability evidence
| Capability | Finding | Evidence and qualification |
|---|---|---|
| Fully managed service | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| DIY / self-managed model | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Co-managed service | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Multi-tenant MSP / white-label support | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Professional services and migration support | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Last-mile circuit management | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Lifecycle management | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Flexible commercial model | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Encrypted overlay fabric | Partner / integrated | See the published provider record for source context; confirm the scope for your deployment. |
| Dynamic path selection | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Active-active link utilisation | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Application-aware routing | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| QoS and traffic shaping | Yes | Native, confirmed directly - 'increase your overall performance through a combination of caching, application organization' and prioritisation mechanisms [18] Source · Evidence dated 2026-07-22 |
| Packet loss remediation | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Local internet breakout | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| MPLS coexistence and migration | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Cellular and 5G support | Partial | Whether you have Verizon wireline or wireless access, SD Branch can support both. Graded partial rather than yes. Wireless access as a supported transport is stated plainly, and the same page describes a wireless backup option, which covers the failover half of the definition. However the words '5G', '4G' and 'LTE' do not appear in this context, and SIM management and signal monitoring were not found on any page reviewed (sources 3, 4, 8, 9, 21). Verizon is of course a mobile network operator, but that is prior knowledge and cannot be graded from; only what the pages state is reflected here. Source · Evidence dated 2026-07-29 |
| Cloud on-ramp | Yes | Native, confirmed directly via the specifically-named Virtual Network Services (VNS) platform and its VNS Application Edge capability [6] Source · Evidence dated 2026-07-22 |
| Public cloud gateways | Partner / integrated | Integrates network operation centers (NOCs) and security operation centers (SOCs) with our Managed SD WAN and Virtual Network Services (VNS), and supports Versa, Cisco cEdge and vEdge, Zscaler ZIA, Zscaler ZPA and Palo Alto Prisma Access. This is the pivotal judgement in the record. The cloud gateways that actually enforce security and deliver remote access in Verizon's SASE service are Zscaler Internet Access, Zscaler Private Access and Palo Alto Prisma Access, all of which run on those vendors' own global PoP estates, not Verizon's. Verizon's service guide carries a Zscaler product description (source 12) confirming it resells those subscriptions. Verizon operates substantial infrastructure of its own, but that is the MPLS and IP transport layer, not a Verizon-built cloud security edge, so the definition forces partner_integrated rather than yes. An identical vendor list was found on both the UK and US product pages, so this is not a regional arrangement. Source · Evidence dated 2026-07-29 |
| Private PoPs / dedicated PoPs | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Private global backbone | Yes | Private IP is a MultiProtocol Label Switching (MPLS) network that connects locations and clouds around the globe in 185+ countries. Comfortably meets the definition and is not a single-country case. Verizon operates a genuinely global MPLS backbone reaching 185+ countries, the Private IP page states 'Traffic is completely separated from the public internet to help keep it secure', and source 11 carries the ownership claim 'we own and operate one of the largest and most reliable networks on the planet'. Inter-region predictability is contractually underwritten by the Private IP SLA (source 7), which commits to jitter of '< 5 ms' PE to PE for EF class and a packet delivery ratio of '99.995%' for EF, exactly the sort of between-PoP commitment the definition contemplates. Source · Evidence dated 2026-07-29 |
| Regional breakout and data residency | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Multi-cloud transit fabric | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Flexible edge form factors | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| High availability design | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| SLA-backed service fabric | Yes | This SLA only applies to Verizon managed NaaS components on a NaaS Order. Among the strongest evidence in this record because it rests on contractual documents rather than marketing pages. Three separate published SLAs were read. The NaaS SLA (source 6) commits to tiered site availability, to repair response of '3.5 hours (US)' or '4 hours (rest of world)' for managed devices, and to proactive incident notification 'within 15 minutes of opening such Priority 1 Trouble Ticket'. The Private IP SLA adds latency, jitter and packet delivery ratio standards. This is contractual rather than best-effort, covering uptime, response and incident handling together. Source · Evidence dated 2026-07-29 |
| Integrated next-generation firewall | Partner / integrated | Intrusion detection and prevention services (IDS/IPS) The full NGFW feature set is present in the delivered service: the Versa partner page lists IDS/IPS alongside 'Antispam, antimalware and URL filtering' and DLP, and the SASE pages describe firewall as a service. But every one of those functions is another company's technology that Verizon bundles and manages, named on Verizon's own pages as Versa, Cisco cEdge and vEdge, Palo Alto Prisma Access and Zscaler, with the SASE landing page adding Netskope and Viptela. No evidence was found of a Verizon-authored firewall engine. Under the definition's explicit instruction, third-party firewall technology that the supplier resells or bundles grades partner_integrated, not yes. Source · Evidence dated 2026-07-29 |
| Full SASE platform | Partner / integrated | See the published provider record for source context; confirm the scope for your deployment. |
| SSE ecosystem integration | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Zero Trust Network Access | Yes | Native, confirmed directly and with genuine specificity - Zscaler Private Access (ZPA) named directly [2] Source · Evidence dated 2026-07-22 |
| Secure web gateway | Yes | Native, confirmed as part of the multi-platform SASE architecture [2] Capability specifics depend on which underlying platform is proposed Source · Evidence dated 2026-07-22 |
| CASB capability | Yes | Native, confirmed directly by name as a core SASE architecture component described in Verizon's own SASE definition materials [2] Specific inline-versus-API-mode technical detail not itemised per platform Source · Evidence dated 2026-07-22 |
| Data loss prevention | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Remote user access | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| SOC/SIEM/SOAR integration | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Centralised orchestration | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Customer portal and RBAC | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Observability and digital experience monitoring | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| APIs and automation | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Managed service assurance | Yes | Support provided by Verizon's Network Operations Center (NOC) and Security Operations Center (SOC) teams Both a NOC and a SOC are Verizon's own and wrap the partner technology, which is the core of the definition. Proactive ownership is contractual rather than merely claimed: the NaaS SLA commits Verizon to open a trouble ticket for each Priority 1 incident and notify the customer within 15 minutes. The SOC services page adds 'Gain 24/7 access to monitoring, extensive global threat visibility and expert analysis', and SD Branch confirms '24/7/365 access to Managed SD Branch reporting'. Confidence is medium rather than high because two named elements of the definition, formal root cause analysis and structured periodic service reviews with change governance, were not found verbatim on any page reviewed. Source · Evidence dated 2026-07-29 |