Provider evidence
Versa Networks
Versa Networks built its SASE platform around a single-vendor, single-operating-system architecture from an early starting point - the company was founded in 2012, before the SASE category itself existed, on the thesis that legacy hardware and static WAN architectures were holding enterprises back from the cloud. That heritage shows up directly in VersaONE’s design: one operating system (VOS), one console, one policy engine and one data lake, with a single-pass parallel-processing architecture built to avoid the latency penalty of chaining separate security functions together.
Technology vendor · UK entity not yet reviewed
Evidence profile: Energy and utilities; Retail and e-commerce (partial evidence); Manufacturing (partial evidence); Small business; platform
Versa case index expressly identifies Lambton Area Water Supply Systems deploying SASE for remote offices and cloud data. Canadian utility case only. Versa identifies an anonymous Global-200 pharmaceutical manufacturer using Secure SD-WAN. Retain anonymous evidence, not a named reference. Versa documents an unnamed retailer with over 600 stores using Secure SD-WAN. Do not describe this as named customer proof. This is sector experience only; scope, UK delivery and suitability for the buyer require separate confirmation.
- https://versa-networks.com/customers/case-studies/
- https://versa-networks.com/
- https://aitranslatewpml.versa-networks.com/customers/case-studies/
- https://versa-networks.com/lp/sase-cost-savings/
Research only
https://versa-networks.comThese capabilities use the same evidence as the provider shortlist and matching. A missing finding is not evidence that a provider lacks the capability.
Capability evidence
| Capability | Finding | Evidence and qualification |
|---|---|---|
| Fully managed service | Partial | In this model Versa NOC is responsible for managing and maintaining Versa SASE, while the customer IT team is responsible for management and monitoring of the CPEs. Versa does operate a NOC and a hosted, managed head-end and gateway service under its own SLA, so part of the estate is genuinely run by Versa. But its own solution brief places CPE management with the customer IT team in that model, and the alternative model places configuration management and monitoring with a Service Provider. End-to-end design, deploy, change, support and report by Versa itself for the whole service is not evidenced, so partial rather than yes. Source · Evidence dated 2026-07-29 |
| DIY / self-managed model | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Co-managed service | Yes | In this model Versa NOC is responsible for managing and maintaining Versa SASE, while the customer IT team is responsible for management and monitoring of the CPEs. This is a textbook split of responsibility: Versa runs the platform and the customer retains CPE operations. Concerto's provider-level and tenant-level roles document the same shared model in the tooling. Source · Evidence dated 2026-07-29 |
| Multi-tenant MSP / white-label support | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Professional services and migration support | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Last-mile circuit management | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Lifecycle management | Partial | Head-end server hardware OS and security patch upgrades and updates For the hosted head-end, Versa documents software upgrades of Director, Analytics, Controller, Concerto and VMS plus OS and security patching, which is lifecycle handled as part of the service. Separately, hardware documentation covers a two-year limited warranty, next-business-day and same-business-day advance replacement, DOA handling and an end-of-life policy. Graded partial rather than yes because branch CPE firmware upgrades and renewals in a typical Versa deployment sit with the customer or the service provider partner, and hardware replacement coverage is a purchased support tier rather than something evidenced as included in the service by default. Source · Evidence dated 2026-07-29 |
| Flexible commercial model | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Encrypted overlay fabric | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Dynamic path selection | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Active-active link utilisation | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Application-aware routing | Yes | Native, per-application SLA-based routing confirmed specifically via the Adobe deployment [19] Source · Evidence dated 2026-07-22 |
| QoS and traffic shaping | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Packet loss remediation | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Local internet breakout | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| MPLS coexistence and migration | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Cellular and 5G support | Yes | The term WWAN interfaces refers to LTE, 4G, and 5G interfaces. Documentation covers LTE, 4G and 5G on a VOS WAN port, SIM activation and operator ID checks, and radio quality monitoring via RSRP, RSRQ, RSSI and SINR with banded signal states. It is documented as usable where a branch has no wired connection and alongside wired links, so both primary and failover roles are covered. On the source page the words WWAN interfaces are italicised; the italics add no characters to the rendered text. Source · Evidence dated 2026-07-29 |
| Cloud on-ramp | Yes | Native - confirmed explicitly for AWS-hosted VOS deployment, described as 'cloud edge deployment such as AWS running VOS' [24] Source · Evidence dated 2026-07-22 |
| Public cloud gateways | Yes | Versa Cloud Gateways (VCGs) are Versa SASE Gateways which are deployed in Point of Presence (PoP) locations around the world. These are Versa's own gateways running Versa's own VOS software, not a third party's PoPs resold under Versa's name, so yes rather than partner_integrated. They deliver secure internet access, ZTNA, threat protection and DLP as a cloud service, and the SASE client selects the VCG offering lowest latency. Source · Evidence dated 2026-07-29 |
| Private PoPs / dedicated PoPs | Yes | Versa SASE is delivered via the cloud, on-premises, or as a blended combination of both Versa markets Private SASE and Sovereign SASE as distinct deployment models alongside the shared cloud. Network World, a named-author dated source, reports that Sovereign SASE runs entirely on customer-controlled infrastructure with the customer choosing its own compute, on-premises or in a private cloud. Confidence is medium rather than high because the Sovereign SASE product page itself would not render without JavaScript, so the strongest Tier 1 statement of the claim could not be read directly. Source · Evidence dated 2026-07-29 |
| Private global backbone | Partial | Versa SD-WAN Traffic Engineered network which uses multiple global and regional providers for the underlay. Inter-gateway traffic rides a Versa-controlled traffic-engineered overlay that selects paths on least end-to-end latency and loss, and each VCG is connected to multiple global and multiple regional service providers with peering relationships. But the underlay is explicitly other carriers' capacity, not fibre or circuits owned by Versa. Graded partial: the control plane and path selection are Versa's, the physical backbone is not. Source · Evidence dated 2026-07-29 |
| Regional breakout and data residency | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Multi-cloud transit fabric | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Flexible edge form factors | Yes | Native - Versa-certified white-box routers (third-party hardware running VOS) confirmed specifically via the Adobe deployment account; branch edge devices, cloud edge deployment, and on-premises appliances all confirmed as supported form factors [24] Source · Evidence dated 2026-07-22 |
| High availability design | Yes | Native, confirmed at a specific, quantified level via the Adobe case study - 'four-nines of availability for critical services' was an explicit deployment requirement Versa was chosen to meet [18] Source · Evidence dated 2026-07-22 |
| SLA-backed service fabric | Yes | target Uptime average of 99.999% ("Uptime SLA Percentage") measured monthly A published, dated SLA document covering Versa Hosted and Managed Secure Services Edge Gateways, with a tiered service-credit table running from 2 days of credit for uptime below 99.999% up to 24 days below 98.0%, plus a security processing latency commitment of 10ms without TLS inspection and 50ms with anti-virus, malware detection and IPS with TLS decryption. Contractual rather than best-effort, including a two calendar day claim window. Source · Evidence dated 2026-07-29 |
| Integrated next-generation firewall | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Full SASE platform | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| SSE ecosystem integration | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Zero Trust Network Access | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Secure web gateway | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| CASB capability | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Data loss prevention | Yes | Data loss prevention (DLP) is a set of tools and processes for detecting and preventing data breaches, cyber exfiltration, and unwanted destruction of sensitive data. Native to the platform and configured from Concerto. Content passing through the organisation's ports and protocols is scanned against match rules, with enforcement actions of Alert, Allow, Block, Reject, Quarantine, Encrypt, Redact or Tokenize, and all actions reported to Versa Analytics for review. Documentation also covers offline DLP, DLP data exfiltration policies and applying Microsoft MIP sensitivity labels. Source · Evidence dated 2026-07-29 |
| Remote user access | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| SOC/SIEM/SOAR integration | Yes | Native, confirmed and well-evidenced via Versa Analytics' specific, itemised log-type list (flow logs, SD-WAN path and bandwidth usage, CGNAT, DHCP, DNS, SASE-web monitoring, secure access, traffic conditioning, URL filtering, and IDP logs) and confirmed export to CrowdStrike Falcon Next-Gen SIEM [26] Not confirmed Source · Evidence dated 2026-07-22 |
| Centralised orchestration | Yes | Native, confirmed via a named practitioner review describing the console's 'ZTP (zero touch provisioning)' capability speeding up implementation [7] Source · Evidence dated 2026-07-22 |
| Customer portal and RBAC | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Observability and digital experience monitoring | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| APIs and automation | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Managed service assurance | Partial | Versa will provide Root-Cause Analysis for customer-reported P1 issues. The NOC half is evidenced: 24x7 monitoring of head-end alarms and application health, a Versa NOC responsible for managing and maintaining Versa SASE, formal root cause analysis on P1 incidents, and scheduled periodic or quarterly customer review meetings. What I did not find on any page I read is a 24x7 SOC performing proactive security monitoring on the customer's behalf, nor a documented change governance process. Graded partial on that gap. Note also that the Premier Service datasheet carries a 2020 copyright. Source · Evidence dated 2026-07-29 |