Feature sheets look almost identical. The differences show up under load, across distance, during an outage, and in the fine print of where your data is handled. Tick the requirements that apply to you, then read down the columns to see which architecture types tend to fit.
The circles show tendencies by architecture type, not specific products, and the page never picks a winner for you. If you want a personalized read on which approach fits, pair this with the architecture assessment.
The requirements matrix
Your requirements & how each type fits
Check the rows that matter to you. Columns are architecture types, not vendors. A type earns a full circle where it meets a requirement by design, a half circle where it is possible with trade-offs or add-ons, and an empty circle where it is a weak fit.
| Requirement | Cloud- nativevendor cloud PoPs |
Hybridcloud + appliances | Self- hostedyour gear, central |
Distributed Sovereigneverywhere, yours |
|---|---|---|---|---|
| 01What you need to protect | ||||
| 02Where enforcement can run | ||||
| 03Data sovereignty & control Where types differ | ||||
| 04Performance & traffic path Where types differ | ||||
| 05Resilience & availability Where types differ | ||||
| 06Operations & delivery Where types differ | ||||
* Cloud-native can approach this only with an additional on-prem device or license.
The distributed and self-hosted columns show more full circles across these rows, because most of them are about control, locality, and resilience, which those architectures are built for. Cloud-native trades some of that for the simplicity, scale, and low operational effort in the Operations and delivery rows. More circles is not better. Weigh only the rows you actually checked.
Assumed baseline
What a full SASE platform should include
This checklist assumes you want a complete SASE platform, so these are treated as table stakes rather than differentiators. Every serious option should include them. Confirm each is present and works at every enforcement point you plan to use.
Ask each vendor
Questions that depend on the vendor
These are not settled by architecture type, so they are not in the matrix. They depend on the specific product and company. Tick the ones to raise with each vendor you shortlist.
How to read this
No architecture type is the right answer on its own, and most environments end up as a blend. Look at the circles across the rows you checked: a type with mostly full circles there is worth a closer look, and a type with empty circles on requirements you care about is worth questioning hard. Give extra weight to sovereignty, performance, and resilience, since those are the hardest to change later.
SASE.net is an educational resource published by Zenarmor, a provider of distributed SASE, SSE, ZTNA, and network security. This matrix is written to be vendor-neutral. If your requirements point toward the distributed and sovereign column, see how Zenarmor implements distributed SASE.