SASE Vendors in 2026: The Honest List and the Half You Probably Do Not Need

SASE Vendors in 2026: The Honest List and the Half You Probably Do Not Need

The short answer

A SASE vendor sells you two layers bolted together: networking (SD-WAN) and security (SSE). Most mid-market buyers only need the second layer. If your people work on laptops in homes, airports and hotel lobbies rather than behind branch routers, the SD-WAN half of a SASE contract is weight you pay for and never use. The honest buy is SSE, delivered as close to the user as you can get it. dope.security is the on-device option on that list: the same SWG, CASB, DLP and AI governance, inspected on the endpoint, with no point of presence in the middle. If you want the direct swaps for the biggest names on the list, start with the best Zscaler alternatives in 2026.

What people actually mean when they search for SASE vendors

Almost nobody typing this phrase wants a definition. They want a shortlist, and they want to know which names are real and which are marketing.

Here is the problem with the lists you will find. Gartner coined SASE in 2019 to describe the convergence of network and security services delivered from the cloud. Every incumbent then relabeled whatever it already sold as SASE. A firewall company called its firewall SASE. A DNS company called its resolver SASE. A proxy company called its proxy SASE. The category stopped describing an architecture and started describing an ambition.

So the useful question is not who the SASE vendors are. It is which half of SASE you are actually buying, and where that half runs. We break the two halves apart in SASE vs SSE architecture, and if you are new to the acronym soup, what is SASE covers the ground quickly.

The two halves, and why only one of them follows your people

SD-WAN secures and optimizes traffic between sites. It assumes sites. It is built around appliances or virtual appliances that sit at a branch, a factory, a store, or a data center, and it decides which link a packet takes to get somewhere else.

SSE secures traffic between a user and the internet. It assumes users. It includes Secure Web Gateway, Cloud Access Security Broker, Zero Trust Network Access and Data Loss Prevention, and it is supposed to travel with the person.

Now count your branches. If you are a 250 to 5,000 person company built after 2015, you probably have a headquarters, a couple of small offices, and several hundred laptops that are almost never in any of them. The SD-WAN layer has nothing to secure. You are buying a networking product to protect a network your employees stopped using.

That is not an argument against SD-WAN in general. Manufacturers with plant floors and retailers with hundreds of stores have real site traffic and real reasons to buy it. It is an argument against buying it by default because it came bundled in a SASE SKU.

The vendor-by-vendor read

These are the names that show up on every SASE vendor list, what each one is actually good at, and the documented friction buyers run into. Every one of these companies scores well overall. The point is not that they are bad. The point is that they share an architecture, and that architecture has a price.

Zscaler

Zscaler is the category leader and the most complete cloud proxy on the list. All traffic forwards to a Zscaler Service Edge node for inspection, which is what makes the feature set possible and also what makes latency compound: customers report the round trip stretching as more inspection modules stack up, and Gartner has cited throughput drops in the 10 to 20 percent range. Zscaler has taken itself offline through its own maintenance more than once, including a documented outage on 25 October 2022 with full packet loss traced to internal maintenance and a further disruption on 19 January 2025. Certificate-pinned traffic from Microsoft 365, WebEx and Dropbox cannot be inspected, so teams end up maintaining bypass lists. AI governance is licensed separately: prompt DLP requires the Data Protection add-on, and AI Guard and AI Scanning are their own line items. China access is sold as a Premium or Plus uplift.

Netskope

Netskope has the richest AI feature set on paper. AI Guardrails inspects prompts and responses in real time, which is genuinely more than most of this list can do, and it shipped in April 2026. The catch is where it sits: NewEdge is a proxy in the cloud, Netskope's own service levels promise under 10 ms for non-decrypted traffic and 50 ms once decryption is on (a five times penalty on exactly the traffic you care about), and the strongest AI and DLP capabilities live in the higher Max Advantage tier with CASB-API sold as a separate SKU. Reviewers consistently describe it as hard to deploy and administer, with a cluttered console and the same certificate-pinning bypass lists everyone else maintains. Netskope also had a management-plane incident affecting all regions in May 2026. The critique is not that Netskope cannot do AI. It is that the AI is an extra SKU on a bolt-on architecture.

Palo Alto Networks (Prisma Access)

Prisma Access scores highly with analysts (roughly 4.6 to 4.7 on Gartner Peer Insights) and is the natural pick if you already run Palo Alto firewalls. It runs on Google Cloud and AWS. Its Explicit Proxy mode carries hard documented limits: no HTTP/2, ALPN stripped, decryption mandatory. Strata Cloud Manager ran impaired for roughly 28 days starting 31 March 2026, and the Panorama to Strata Cloud Manager migration is one way. Setup complexity is the most common buyer complaint, and Palo Alto has itself confirmed GlobalProtect issues on macOS including battery drain, 100 percent CPU and reconnect loops. AI governance is an upsell tower: AI Access Security needs AI Access-X or CASB-X stacked with Enterprise DLP, and inline AI inspection runs through the decrypt proxy. Mainland China is partner-operated and requires an ICP filing. For the endpoint-native comparison, see Prisma Access versus an endpoint-native SWG.

Cisco (Umbrella and Secure Access)

Umbrella is a DNS product in a world where roughly 95 percent of traffic is encrypted. The DNS base tier cannot read URLs, payloads or tenant headers, so full inspection requires the SIG Secure Web Gateway add-on. Cisco's own documentation (article 225162) is explicit that allowing a corporate ChatGPT tenant while blocking personal accounts requires the intelligent proxy, SSL decryption and a root certificate. A global disruption on 19 January 2025 traced to a DNS failover misconfiguration is documented in Field Notice FN74221. There is no mainland China data center. Cisco is now steering customers toward Secure Access, so if Umbrella is your incumbent the migration decision is already on your desk. Start with the top Cisco Umbrella alternatives and Umbrella SIG versus an endpoint SWG.

Forcepoint ONE

Forcepoint runs cloud-proxy backhaul across roughly 300 AWS points of presence, with a CASB reverse proxy inherited from the Bitglass acquisition. Forrester described the result as a double integration whammy across Bitglass and Skyfence. Customers report policy changes taking 20 to 30 minutes to enforce and a dated interface. Ownership has changed repeatedly, from Raytheon to Francisco Partners to the TPG government-unit carve-out in July 2023. Forcepoint's own knowledge base confirms that its China offices are blocked. GenAI Security is a multi-SKU assembly that led with ChatGPT Enterprise and is weaker for Claude, Gemini and Copilot.

Broadcom and Symantec Cloud SWG

This is the cautionary tale on the list. The product traveled from Blue Coat to ProxySG to WSS to Cloud SWG through four owners. Broadcom's own knowledge base articles document latency and timeout behavior (KB 174576 and KB 169051). PAC redirection is being deprecated. The best-documented weakness anywhere in this market is commercial: renewals running two to four times higher for mid-market accounts, over 400 percent for small buyers, perpetual licenses eliminated, and a stated focus on Global 2000 customers. The GenAI capability is dated 13 April 2023 and has no tenant-aware corporate versus personal control. If this is your incumbent, the Symantec WSS alternative buyer's guide is the place to start.

Cloudflare One

Cloudflare has the fastest edge on this list and the youngest SSE. Gartner has placed it as a Niche Player in SSE from 2023 through 2025. Its uniform anycast design means there is no regional isolation, which is how a single oversized configuration file produced global 5xx errors for roughly five hours on 18 November 2025, the company's worst outage since 2019. Full DLP, remote browser isolation, unlimited CASB and long log retention are gated behind Contract plans. TLS inspection breaks git, aws, kubectl, terraform and Docker. AI Gateway is a developer proxy rather than employee governance, and AI Prompt Protection is a beta from 25 August 2025 covering roughly four applications. See Zscaler versus Cloudflare Gateway for the head to head.

Cato Networks and Fortinet FortiSASE

These two are the most genuinely network-first names on the list. Cato is a single-vendor SASE built around its own private backbone, which is a coherent design if you have real site-to-site traffic to move. Fortinet FortiSASE extends the FortiGate estate into the cloud, which makes sense if Fortinet already owns your perimeter. Both are strong choices for a business with branches. Both are the wrong shape for a company whose network is 800 laptops. We cover the swaps in Cato Networks alternatives and Fortinet FortiSASE alternatives.

dope.security

dope.security is not on this list to be the tenth cloud proxy. It is the architectural exception: the SSE services run in an agent on the device, in under 100 MB of RAM, and traffic goes straight to its destination after inspection instead of stopping at a vendor data center. That is Fly Direct, and it delivers up to 4x the performance of legacy proxy SWGs. One console covers dope.SWG, CASB Neural, Dopamine DLP (US Patent 12,464,023, zero-retention classification) and Cloud Application Control. AI governance is native rather than an add-on: Shadow IT discovery finds the tools, SWG policy decides allow, warn or block, and CAC restricts SaaS to your corporate tenants. There is no SD-WAN half, because we are not selling you one.

The question that splits the list in two

Strip the feature grids away and every vendor above answers one question the same way except one: where does inspection happen?

  • Backhaul: Zscaler, Netskope, Palo Alto, Cisco, Forcepoint, Broadcom, Cloudflare, Cato and Fortinet all forward traffic to a vendor point of presence, inspect it there, and send it on. dope.security inspects on the device and sends traffic straight to its destination.
  • Latency: a cloud proxy adds a fixed detour to every request, measured at roughly 40 to 80 ms near a point of presence and 150 to 400 ms when users are far from one. dope.security adds no network detour, so your latency is your load time.
  • Privacy: a cloud proxy decrypts your corporate TLS inside a third party's infrastructure. dope.security decrypts on the endpoint, so plaintext never transits a vendor cloud.
  • Blast radius: a cloud control plane is a shared dependency, and several vendors on this list have taken themselves down through their own maintenance. dope.security keeps enforcing with cached policies when the console is unreachable.
  • AI coverage: most vendors govern AI through the proxy and license it as a tier or an add-on. dope.security sees AI traffic from browsers and thick clients at the point it leaves the machine, with no separate SKU.
Want to see what the detour costs on your own connection? The interactive Fly-Direct Speed Test measures your real round-trip latency in the browser, then shows how everyday apps load with and without a cloud-proxy hop. Read how Fly Direct works or book a 20-minute demo.

Takeaway: the detour is a fixed tax on every request, and it is the one line item in a SASE contract that no feature comparison will show you.

What the SD-WAN half costs you when you have no branches

The bundled network layer is rarely free, and the cost is not only money.

It costs scope. SASE evaluations balloon because you are running a networking bake-off and a security bake-off at once, with two sets of stakeholders and two sets of requirements. Teams routinely spend a quarter on this. Buying SSE alone cuts the evaluation in half.

It costs deployment time. The network half brings tunnels, routing and appliance provisioning. The security half, if it runs on the device, is an MDM push. One Fortune 100 customer went from 900 devices to more than 18,000 in a matter of weeks, roughly 3,000 per week, deploying silently through Intune with no pre-install customization. Outreach Health secured 99 percent of devices inside one week and cut web access tickets by 70 percent in 90 days.

It costs leverage at renewal. Bundles are opaque by design. When the networking and security line items are fused, you cannot price either one honestly, and you certainly cannot walk away from half of it. That is how a mid-market renewal turns into a four-times increase.

How to run a SASE vendor evaluation that does not eat a quarter

Five questions, in this order.

  • Count your real sites. If the answer is fewer than five and they are offices rather than production facilities, drop SD-WAN from the requirement list and evaluate SSE only.
  • Test from where your people actually are. Run the proof of concept with a remote user and an international user, not someone sitting next to a point of presence. Near-PoP numbers flatter every cloud proxy on the list.
  • Ask what AI governance costs, in SKUs rather than slides. Ask specifically whether allowing a corporate AI tenant and blocking personal accounts on the same domain requires an add-on, a higher tier, or both.
  • Ask what breaks. Every proxy vendor maintains a certificate-pinning bypass list. Ask to see it, and ask what happens to developer tooling.
  • Count the consoles. One console built from scratch behaves differently from four consoles joined by acquisitions, and the difference shows up in every incident.

Where this leaves the shortlist

If you run real branches with real site traffic, buy SASE and take the SD-WAN layer seriously. Cato and Fortinet are built for you.

If your company is a few hundred to a few thousand people on laptops, you are not buying SASE. You are buying SSE, and the only decision that matters is whether inspection happens in somebody else's data center or on the machine where the data already lives. Greylock Partners made that call against Cisco Umbrella and went from first proposal to signed contract in 27 days. The full story is in how Greylock ditched Cisco Umbrella, and you can compare the wider field in secure web gateway vendors in 2026 and the top Netskope alternatives.

The SASE vendor list is long because the category swallowed everything around it. The buying decision is short: skip the network layer you do not have, and put the security layer as close to your people as it will go.

Frequently Asked Questions

Who are the main SASE vendors in 2026?

The names on almost every SASE vendor list are Zscaler, Netskope, Palo Alto Networks (Prisma Access), Cisco (Umbrella and Secure Access), Forcepoint, Broadcom and Symantec Cloud SWG, Cloudflare One, Cato Networks and Fortinet FortiSASE. All of them inspect traffic in their own cloud points of presence. dope.security is the on-device alternative, delivering the SSE half (SWG, CASB, DLP and AI governance) from an agent on the endpoint with no backhaul.

What is the difference between a SASE vendor and an SSE vendor?

SASE bundles networking (SD-WAN) with security. SSE is the security half on its own: SWG, CASB, ZTNA and DLP. A company with branch offices and site-to-site traffic has a reason to buy the full SASE bundle. A company whose network is mostly laptops is paying for an SD-WAN layer it will never route anything through, which is why many mid-market buyers shortlist SSE vendors instead.

Do I need SD-WAN if my workforce is remote?

Usually not. SD-WAN optimizes and secures traffic between physical sites. If your people connect from homes, hotels and coffee shops, there are no sites in the path to optimize. Buying SSE alone removes an entire networking evaluation from the process and takes the bundled line item off the renewal.

Which SASE vendors work in mainland China?

It varies, and it usually costs extra. Zscaler sells China access as a Premium or Plus uplift and Netskope as Premium or Elite SKUs. Palo Alto operates through a partner and requires an ICP filing. Cisco Umbrella has no mainland data center, and Forcepoint's own knowledge base confirms its China offices are blocked. dope.security works in China without a paid uplift, because inspection happens on the device rather than in a data center the traffic has to reach first.

How much does SASE cost, and why are renewals the painful part?

Most vendors on this list price per module and per tier, which makes the first quote look reasonable and the renewal look very different. The best-documented case is Broadcom and Symantec, where renewals have run two to four times higher for mid-market accounts and over 400 percent for smaller ones after perpetual licenses were eliminated. NPI Financial found some Zscaler SKUs pricing more than 35 percent higher in August 2025. Ask for the renewal math, per module, before you sign.

Can a SASE platform control personal versus corporate AI accounts?

Only if it can read and act on an HTTP header inside decrypted TLS. DNS-layer products cannot, because they only see the domain, and Cisco's own article 225162 says the intelligent proxy plus SSL decryption plus a root certificate are required. Most cloud-proxy vendors can do it with the proxy plus a data-protection add-on, usually on a higher tier. dope.security does it on the device through Cloud Application Control, with no add-on, which is why the same domain can serve your corporate tenant and be blocked for personal logins.

SSE
SSE
SASE
SASE
Secure Web Gateway
Secure Web Gateway
← back to blog Home