NNetifyVersion 1010261227

Provider evidence

Versa Networks

Versa Networks built its SASE platform around a single-vendor, single-operating-system architecture from an early starting point - the company was founded in 2012, before the SASE category itself existed, on the thesis that legacy hardware and static WAN architectures were holding enterprises back from the cloud. That heritage shows up directly in VersaONE’s design: one operating system (VOS), one console, one policy engine and one data lake, with a single-pass parallel-processing architecture built to avoid the latency penalty of chaining separate security functions together.

Technology vendor · UK entity not yet reviewed

Evidence profile: Energy and utilities; Retail and e-commerce (partial evidence); Manufacturing (partial evidence); Small business; platform

    Versa case index expressly identifies Lambton Area Water Supply Systems deploying SASE for remote offices and cloud data. Canadian utility case only. Versa identifies an anonymous Global-200 pharmaceutical manufacturer using Secure SD-WAN. Retain anonymous evidence, not a named reference. Versa documents an unnamed retailer with over 600 stores using Secure SD-WAN. Do not describe this as named customer proof. This is sector experience only; scope, UK delivery and suitability for the buyer require separate confirmation.

    Research only

    https://versa-networks.com

    These capabilities use the same evidence as the provider shortlist and matching. A missing finding is not evidence that a provider lacks the capability.

    Capability evidence

    CapabilityFindingEvidence and qualification
    Fully managed servicePartial

    In this model Versa NOC is responsible for managing and maintaining Versa SASE, while the customer IT team is responsible for management and monitoring of the CPEs. Versa does operate a NOC and a hosted, managed head-end and gateway service under its own SLA, so part of the estate is genuinely run by Versa. But its own solution brief places CPE management with the customer IT team in that model, and the alternative model places configuration management and monitoring with a Service Provider. End-to-end design, deploy, change, support and report by Versa itself for the whole service is not evidenced, so partial rather than yes.

    Source · Evidence dated 2026-07-29
    DIY / self-managed modelYesSee the published provider record for source context; confirm the scope for your deployment.
    Co-managed serviceYes

    In this model Versa NOC is responsible for managing and maintaining Versa SASE, while the customer IT team is responsible for management and monitoring of the CPEs. This is a textbook split of responsibility: Versa runs the platform and the customer retains CPE operations. Concerto's provider-level and tenant-level roles document the same shared model in the tooling.

    Source · Evidence dated 2026-07-29
    Multi-tenant MSP / white-label supportNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Professional services and migration supportYesSee the published provider record for source context; confirm the scope for your deployment.
    Last-mile circuit managementNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Lifecycle managementPartial

    Head-end server hardware OS and security patch upgrades and updates For the hosted head-end, Versa documents software upgrades of Director, Analytics, Controller, Concerto and VMS plus OS and security patching, which is lifecycle handled as part of the service. Separately, hardware documentation covers a two-year limited warranty, next-business-day and same-business-day advance replacement, DOA handling and an end-of-life policy. Graded partial rather than yes because branch CPE firmware upgrades and renewals in a typical Versa deployment sit with the customer or the service provider partner, and hardware replacement coverage is a purchased support tier rather than something evidenced as included in the service by default.

    Source · Evidence dated 2026-07-29
    Flexible commercial modelNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Encrypted overlay fabricYesSee the published provider record for source context; confirm the scope for your deployment.
    Dynamic path selectionNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Active-active link utilisationNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Application-aware routingYes

    Native, per-application SLA-based routing confirmed specifically via the Adobe deployment [19]

    Source · Evidence dated 2026-07-22
    QoS and traffic shapingNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Packet loss remediationNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Local internet breakoutNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    MPLS coexistence and migrationNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Cellular and 5G supportYes

    The term WWAN interfaces refers to LTE, 4G, and 5G interfaces. Documentation covers LTE, 4G and 5G on a VOS WAN port, SIM activation and operator ID checks, and radio quality monitoring via RSRP, RSRQ, RSSI and SINR with banded signal states. It is documented as usable where a branch has no wired connection and alongside wired links, so both primary and failover roles are covered. On the source page the words WWAN interfaces are italicised; the italics add no characters to the rendered text.

    Source · Evidence dated 2026-07-29
    Cloud on-rampYes

    Native - confirmed explicitly for AWS-hosted VOS deployment, described as 'cloud edge deployment such as AWS running VOS' [24]

    Source · Evidence dated 2026-07-22
    Public cloud gatewaysYes

    Versa Cloud Gateways (VCGs) are Versa SASE Gateways which are deployed in Point of Presence (PoP) locations around the world. These are Versa's own gateways running Versa's own VOS software, not a third party's PoPs resold under Versa's name, so yes rather than partner_integrated. They deliver secure internet access, ZTNA, threat protection and DLP as a cloud service, and the SASE client selects the VCG offering lowest latency.

    Source · Evidence dated 2026-07-29
    Private PoPs / dedicated PoPsYes

    Versa SASE is delivered via the cloud, on-premises, or as a blended combination of both Versa markets Private SASE and Sovereign SASE as distinct deployment models alongside the shared cloud. Network World, a named-author dated source, reports that Sovereign SASE runs entirely on customer-controlled infrastructure with the customer choosing its own compute, on-premises or in a private cloud. Confidence is medium rather than high because the Sovereign SASE product page itself would not render without JavaScript, so the strongest Tier 1 statement of the claim could not be read directly.

    Source · Evidence dated 2026-07-29
    Private global backbonePartial

    Versa SD-WAN Traffic Engineered network which uses multiple global and regional providers for the underlay. Inter-gateway traffic rides a Versa-controlled traffic-engineered overlay that selects paths on least end-to-end latency and loss, and each VCG is connected to multiple global and multiple regional service providers with peering relationships. But the underlay is explicitly other carriers' capacity, not fibre or circuits owned by Versa. Graded partial: the control plane and path selection are Versa's, the physical backbone is not.

    Source · Evidence dated 2026-07-29
    Regional breakout and data residencyNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Multi-cloud transit fabricYesSee the published provider record for source context; confirm the scope for your deployment.
    Flexible edge form factorsYes

    Native - Versa-certified white-box routers (third-party hardware running VOS) confirmed specifically via the Adobe deployment account; branch edge devices, cloud edge deployment, and on-premises appliances all confirmed as supported form factors [24]

    Source · Evidence dated 2026-07-22
    High availability designYes

    Native, confirmed at a specific, quantified level via the Adobe case study - 'four-nines of availability for critical services' was an explicit deployment requirement Versa was chosen to meet [18]

    Source · Evidence dated 2026-07-22
    SLA-backed service fabricYes

    target Uptime average of 99.999% ("Uptime SLA Percentage") measured monthly A published, dated SLA document covering Versa Hosted and Managed Secure Services Edge Gateways, with a tiered service-credit table running from 2 days of credit for uptime below 99.999% up to 24 days below 98.0%, plus a security processing latency commitment of 10ms without TLS inspection and 50ms with anti-virus, malware detection and IPS with TLS decryption. Contractual rather than best-effort, including a two calendar day claim window.

    Source · Evidence dated 2026-07-29
    Integrated next-generation firewallYesSee the published provider record for source context; confirm the scope for your deployment.
    Full SASE platformYesSee the published provider record for source context; confirm the scope for your deployment.
    SSE ecosystem integrationNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Zero Trust Network AccessYesSee the published provider record for source context; confirm the scope for your deployment.
    Secure web gatewayYesSee the published provider record for source context; confirm the scope for your deployment.
    CASB capabilityYesSee the published provider record for source context; confirm the scope for your deployment.
    Data loss preventionYes

    Data loss prevention (DLP) is a set of tools and processes for detecting and preventing data breaches, cyber exfiltration, and unwanted destruction of sensitive data. Native to the platform and configured from Concerto. Content passing through the organisation's ports and protocols is scanned against match rules, with enforcement actions of Alert, Allow, Block, Reject, Quarantine, Encrypt, Redact or Tokenize, and all actions reported to Versa Analytics for review. Documentation also covers offline DLP, DLP data exfiltration policies and applying Microsoft MIP sensitivity labels.

    Source · Evidence dated 2026-07-29
    Remote user accessYesSee the published provider record for source context; confirm the scope for your deployment.
    SOC/SIEM/SOAR integrationYes

    Native, confirmed and well-evidenced via Versa Analytics' specific, itemised log-type list (flow logs, SD-WAN path and bandwidth usage, CGNAT, DHCP, DNS, SASE-web monitoring, secure access, traffic conditioning, URL filtering, and IDP logs) and confirmed export to CrowdStrike Falcon Next-Gen SIEM [26] Not confirmed

    Source · Evidence dated 2026-07-22
    Centralised orchestrationYes

    Native, confirmed via a named practitioner review describing the console's 'ZTP (zero touch provisioning)' capability speeding up implementation [7]

    Source · Evidence dated 2026-07-22
    Customer portal and RBACNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Observability and digital experience monitoringNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    APIs and automationNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Managed service assurancePartial

    Versa will provide Root-Cause Analysis for customer-reported P1 issues. The NOC half is evidenced: 24x7 monitoring of head-end alarms and application health, a Versa NOC responsible for managing and maintaining Versa SASE, formal root cause analysis on P1 incidents, and scheduled periodic or quarterly customer review meetings. What I did not find on any page I read is a 24x7 SOC performing proactive security monitoring on the customer's behalf, nor a documented change governance process. Graded partial on that gap. Note also that the Premier Service datasheet carries a 2020 copyright.

    Source · Evidence dated 2026-07-29