S/SASE.NET

Buyer's tool

SASE evaluation checklist.

Check the requirements that matter to you. The matrix shows how each architecture type tends to meet them, so you can see which approach fits your needs before you talk to a single vendor. It assumes you want a complete SASE platform, so the standard features are listed as a baseline rather than scored.

Everything stays in your browser, and the page prints as a comparison sheet you can take into demos and vendor calls.

0 requirements selected 0 of 6 areas addressed

Feature sheets look almost identical. The differences show up under load, across distance, during an outage, and in the fine print of where your data is handled. Tick the requirements that apply to you, then read down the columns to see which architecture types tend to fit.

The circles show tendencies by architecture type, not specific products, and the page never picks a winner for you. If you want a personalized read on which approach fits, pair this with the architecture assessment.

The requirements matrix

Your requirements & how each type fits

Check the rows that matter to you. Columns are architecture types, not vendors. A type earns a full circle where it meets a requirement by design, a half circle where it is possible with trade-offs or add-ons, and an empty circle where it is a weak fit.

Strong fit Partial, often with trade-offs Limited
Requirement Cloud-
nativevendor cloud PoPs
Hybridcloud + appliances Self-
hostedyour gear, central
Distributed
Sovereigneverywhere, yours
01What you need to protect
02Where enforcement can run
03Data sovereignty & control Where types differ
04Performance & traffic path Where types differ
05Resilience & availability Where types differ
06Operations & delivery Where types differ

* Cloud-native can approach this only with an additional on-prem device or license.

The distributed and self-hosted columns show more full circles across these rows, because most of them are about control, locality, and resilience, which those architectures are built for. Cloud-native trades some of that for the simplicity, scale, and low operational effort in the Operations and delivery rows. More circles is not better. Weigh only the rows you actually checked.

Assumed baseline

What a full SASE platform should include

This checklist assumes you want a complete SASE platform, so these are treated as table stakes rather than differentiators. Every serious option should include them. Confirm each is present and works at every enforcement point you plan to use.

ZTNA never trust, always verify SWG secure web gateway CASB cloud app control FWaaS firewall + IPS/IDS SD-WAN intelligent path selection DLP data loss prevention TLS inspection with reviewable exclusions App control allow / block Identity & posture SSO, MFA, device checks

Ask each vendor

Questions that depend on the vendor

These are not settled by architecture type, so they are not in the matrix. They depend on the specific product and company. Tick the ones to raise with each vendor you shortlist.

How to read this

No architecture type is the right answer on its own, and most environments end up as a blend. Look at the circles across the rows you checked: a type with mostly full circles there is worth a closer look, and a type with empty circles on requirements you care about is worth questioning hard. Give extra weight to sovereignty, performance, and resilience, since those are the hardest to change later.

SASE.net is an educational resource published by Zenarmor, a provider of distributed SASE, SSE, ZTNA, and network security. This matrix is written to be vendor-neutral. If your requirements point toward the distributed and sovereign column, see how Zenarmor implements distributed SASE.

Take the architecture assessment → Back to the SASE guide