
Two analyst firms ran their SASE evaluations in 2025-2026.
Gartner 2025 Single-Vendor SASE Magic Quadrant put Palo Alto Networks, Fortinet, and Cato Networks in the Leaders quadrant.
Two leader-sets, only partially overlapping. The Indian buyer reading both finds five names mentioned and zero clear answers about which one to put on the shortlist.
SASE is a category now.
Not a feature inside a firewall, not a managed-service add-on for the SD-WAN contract, not a roadmap promise from your existing security vendor. A procurement category with its own evaluation framework, its own pricing logic, its own vendor lineup, and a regulatory bracket it has to fit inside.
The RFP framework most Indian buyers wrote in 2024 was scoped against a vendor landscape that no longer exists. The 2026 RFP needs to ask a different set of questions.
But first, some catch-up on infra this week.
🔍 Single-Vendor, Dual-Vendor, or SSE-Only
The first decision behind any SASE RFP is architectural, not commercial.

Single console or two vendors.
Per the SDxCentral RFP analysis, three deployment models dominate 2026 procurement.
Single-vendor SASE delivers SD-WAN and SSE from one platform through one management console. The buyer gets policy consistency, a single accountability point, simpler integration. The trade-off: the vendor's strongest capability and the vendor's weakest capability become a single procurement decision. If the SD-WAN side is the buyer's primary need and the SSE side is the buyer's primary need, single-vendor SASE forces a compromise on whichever side is less strategic.
Dual-vendor SASE combines best-of-breed SD-WAN from one vendor with best-of-breed SSE from another. The trade-off: interoperability. The two platforms have to agree on identity, on policy, on log correlation, and on the operational responsibility line when something breaks at the boundary between them. For an Indian BFSI buyer with existing Cisco Meraki or Fortinet SD-WAN deployment and a fresh SSE evaluation, dual-vendor is often the realistic answer.
SSE-only ships the identity-and-policy plane without SD-WAN. Most enterprises starting today land here, then add SD-WAN later in the network refresh cycle. For an Indian manufacturing buyer mid-cycle on MPLS-to-SD-WAN migration, SSE-only is the easy short-term answer while the underlay decision matures.
The procurement-side question changes shape across the three models.
For all three, a 5-point evaluation framework holds up. Per the SDxCentral analysis and multiple independent procurement guides:
✔ Convergence of SD-WAN and SSE within a single management console (relevant for single-vendor; tested via interoperability for dual-vendor)
✔ PoP density, especially in the geographies your users actually live in. AI-workload latency is now part of this evaluation, not just user experience.
✔ Identity-centric policy engines supporting granular Zero Trust, not just allow/deny ACL replacement
✔ API extensibility so the SASE control plane can integrate with your existing SIEM, SOAR, ITSM, and IAM stack
✔ Native Digital Experience Monitoring (DEM) so the operator sees what the user is actually experiencing
The mistake most 2024 RFPs made was leading with the feature list. The mistake the 2026 RFP risks is leading with the analyst position.
The right opening is the architecture decision. The architecture decision constrains the vendor shortlist. The shortlist constrains the feature evaluation.
How we plug in: Our Enterprise Connectivity practice sits on the buyer side of these architecture decisions. We have run single-vendor, dual-vendor, and SSE-only evaluations across Indian BFSI, manufacturing, pharma, and textile clients. The architectural decision is rarely about which vendor is "best." It is about which vendor's strengths align with your transport reality, your existing security stack, and your operational team's capacity. We will help you frame the architecture question before the vendor-comparison spreadsheet lands on your desk.
🔐 Zscaler, Netskope, Palo Alto, Cato: Read Honestly
Four vendors dominate the 2026 SASE shortlist. Each is selling a different operational story, and the differences matter for the Indian buyer's fit.

Architecture beats feature list.
Zscaler is the pure Zero Trust proxy. 150+ PoPs across six continents. The architectural commitment is "securing the connection." Best fit for the large Indian enterprise whose primary problem is replacing VPN at scale, where the data-governance layer already lives in a separate platform (Microsoft Purview, Symantec DLP, or a CASB the buyer is happy with). If the buyer's threat model leads with credential theft and lateral-movement prevention, Zscaler's depth on that side rewards the evaluation.
Netskope is the cloud-first data-governance leader. NewEdge spans 75+ compute regions globally. The architectural commitment is "securing the data." Strong DLP and CASB. The fresh piece worth knowing: Netskope launched NewEdge AI Fast Path on February 25, 2026, adding direct peering paths to AWS, Microsoft, Google, Anthropic, and OpenAI endpoints. The objective is to cut latency for AI workflows while preserving inline inspection. For an Indian BFSI buyer whose 2026 workload mix includes regulated-data-touching AI agents, that peering structure is meaningful.
Palo Alto Networks Prisma SASE is the hybrid-and-consistency play. Runs on Google Cloud backbone with 100+ globally distributed locations. The architectural commitment is "the same security posture you have on-prem, extended to the cloud edge." For an Indian buyer already running Palo Alto firewalls on-prem and managing them through Panorama, Prisma SASE is the consistent operational extension. Forrester Wave 2026 second. Gartner 2025 Single-Vendor SASE Leader. The trade-off: the buyer is consolidating their security stack with one vendor, which is operationally simpler and commercially riskier.
Cato Networks is the MPLS-replacement play. 85+ PoPs on a private global backbone. The architectural commitment is "one managed cloud service replacing your MPLS contract and your security appliances." Gartner 2025 Single-Vendor SASE Leader. Strong fit for the mid-market Indian enterprise (200-2,000 users) that wants to retire MPLS and consolidate security into one bill. For larger BFSI or manufacturing buyers with complex existing investments, the fit is less clean.
The four-vendor read-out, in one summary:
👉 Zscaler: pure ZTNA, large enterprise, VPN replacement.
👉 Netskope: data + DLP + AI workload peering.
👉 Palo Alto Prisma: hybrid environments, on-prem consistency.
👉 Cato: MPLS replacement, single managed service.
The mistake most procurement memos make is reading these four as ranked alternatives. They are positioned alternatives. The right vendor depends on the buyer's existing stack, transport reality, and threat model. The analyst position is one data point, not the answer.
How we plug in: Our Complete IT Infrastructure Solution practice runs the vendor evaluation matrix that sits behind a SASE RFP. The sales engineer leads with the feature list. The procurement memo needs the architectural-fit assessment, the existing-stack-integration test, the 5-year TCO including identity-and-policy-engine consolidation, and the operational-team-capacity match. We have done this work across Indian BFSI, manufacturing, pharma, and textile buyers for thirty-five years.
📌 The Indian Carrier-SASE Alternative
For an Indian buyer building the 2026 SASE shortlist, the global-hyperscaler list above is incomplete.
Three Indian carriers run managed-SASE-grade offerings, each with a different operational story.

Tata Communications is the established Indian managed-SASE incumbent. Enterprise-grade MPLS, SD-WAN, Ethernet, CDN, and SASE delivered on a strong owned backbone. For an Indian BFSI or large-manufacturing buyer with existing Tata Communications transport, the SASE evaluation has a natural anchor: the underlay is already paid for, the operational relationship is mature, and the contract-renewal cycle aligns with adding SSE. The trade-off: the SSE side of the Tata stack competes with global-pure-play depth on features like DLP, behavioral analytics, and AI-workload inspection. The evaluation question is whether the integration benefit outweighs the feature delta.
Airtel launched Secure Workforce in May 2026 as India's first fully managed Zero Trust Architecture platform (covered in detail in issue-03). The architectural commitment is DPDP-aligned managed ZTNA hosted on Airtel's nationwide network and Airtel Cloud. Bharti Airtel's Nxtra Data Limited raised $1 billion in March 2026 for data-center expansion; SASE PoP buildout sits inside that broader infrastructure push. For an Indian BFSI buyer evaluating Indian-resident control-plane options, Airtel Secure Workforce is the freshest carrier offering and worth pressure-testing on the same 5-point procurement framework above.
Jio has been aggressive on 5G and enterprise managed services. Public SASE-platform branding is not yet at the depth of Tata or Airtel, but Jio's enterprise-private-networks and 5G-slicing roadmap implies a managed-SASE offering within the next 12-18 months. For an Indian buyer mid-procurement today, Jio is a watch-the-roadmap entry rather than a shortlist anchor.
The carrier-SASE versus hyperscaler-SASE decision is more nuanced than it looks. For the Indian buyer:
✔ Carrier SASE: control plane and PoPs sit on Indian infrastructure under Indian jurisdiction. Operational maturity and feature depth depend on the carrier's investment cycle.
✔ Hyperscaler SASE: control plane and PoPs sit on US/EU infrastructure (with regional PoPs in India). Feature depth and analyst-validated maturity are deeper. Regulatory clauses need reading.
For most Indian BFSI buyers reading both lists, the realistic answer in 2026-2027 is hybrid: carrier SASE for the transport-plus-baseline-policy layer, hyperscaler SSE for the data-governance-and-AI-inspection layer where feature depth matters. Dual-vendor architecture by way of split jurisdiction.
How we plug in: Our Enterprise Connectivity practice runs underlay assessments for Indian buyers evaluating carrier-SASE versus hyperscaler-SASE. We have sat through Tata Communications RFPs, Airtel Secure Workforce evaluations, and Cato or Zscaler shortlist exercises across BFSI and manufacturing. The right answer is rarely the loudest analyst position. It is the architecture that aligns with your existing transport relationship and your DPDP-driven contract clauses.
📋 DPDP, Control-Plane Location, and the Contract Clauses Most Indian Buyers Skip
The compliance-side question that the 2024 SASE RFP did not have to answer is the 2026 SASE RFP's first procurement question.
Where does the control plane live?

The control plane in any SASE platform is the set of components that hold identity context, policy decisions, log aggregation, traffic-inspection signatures, and the management API. For a global vendor like Zscaler, Netskope, Palo Alto Prisma, or Cato, the control plane runs from US or EU infrastructure by default. Indian-region PoPs handle the user-facing data path; the control-plane brain is offshore.
The DPDP Act operational compliance deadline is 13 May 2027. Significant Data Fiduciaries are working backward from that deadline. The reading most Indian BFSI legal teams are converging on:
✔ Personal data of Indian data principals should not transit a non-Indian control plane unencrypted.
✔ Logs containing personal data fragments need retention controls aligned with Indian jurisdiction.
✔ Identity context for Indian employees and customers should be enforced from an Indian jurisdiction where the contract allows.
The DPDP framework does not explicitly mandate Indian-only SASE control planes (today). BFSI regulator interpretation may be tighter than the literal DPDP wording. The procurement-side reading: the vendor's contract clauses on data-residency, sub-processor location, and log-data export are now part of the SASE evaluation, not a separate legal track.
Three contract clauses worth reading before signing:
👉 What data classes (logs, identity context, decoded traffic samples, AI-inspection metadata) leave India in normal operation, and which sub-processor handles each one?
👉 What is the breach-notification SLA, and does it align with CERT-In's reporting window (six hours for serious incidents)?
👉 What is the exit-and-data-portability clause if you migrate off the platform in 3-5 years? Logs and policy artefacts are the assets you need back.
The contract clauses are not the exciting part of the SASE procurement. They are the part that determines whether the deployment survives the regulator review eighteen months in. For a Significant Data Fiduciary working backward from the May 2027 deadline, every quarter of delay on these clauses is a quarter of compounding risk that the platform you signed for in 2026 will need a renegotiation cycle before it pays back the migration cost.
How we plug in: Our Cyberdefense practice reads the DPDP-side contract clauses for Indian buyers signing SASE contracts. We have done this work across BFSI, manufacturing, and pharma engagements where the procurement team wants the operational benefit of a global SASE platform and the audit committee wants the regulator-aligned posture. The reconciliation is contract craft, not feature selection.
🔍 Links We Liked This Week
Netskope, Palo Alto Networks, Zscaler lead Forrester SASE rankings
SDxCentral, 2026.
The Forrester Wave 2026 primary source. Read alongside the Gartner 2025 Single-Vendor SASE Magic Quadrant for two-analyst triangulation before locking the shortlist.
A Smarter Way to Build a SASE RFP
SDxCentral.
The procurement-side primary source for the 5-point evaluation framework used in this issue. Read before writing the RFP.
Netify SASE Marketplace 2026
Netify.
Independent multi-vendor SASE marketplace data. Useful for the buyer who wants a vendor-agnostic shortlist filter before going into vendor briefings.
Zscaler vs Netskope vs Palo Alto vs Cato Networks: The SASE Comparison Guide 2026
TechnologyMatch.
The cleanest side-by-side technical comparison published in 2026. Pair with the SDxCentral RFP guide for procurement-side completeness.
Single-Vendor vs Multi-Vendor SASE: A Data-Driven Guide
SASECompare.
The architectural-decision deep-dive. Read before the architecture question lands on your desk in vendor-pitch form.
💡 My Take
Every SASE pitch in 2026 leads with the same word.
Convergence.
The pitch is that SD-WAN and SSE are converging into a single platform, and the buyer's procurement reality should converge with that platform, and the operational team should converge their tooling around it, and the legal team should converge their contract clauses with it.
The pitch is half right.
The convergence is happening, but it is happening at a layer most pitches do not name.
Identity is the policy plane.
What actually converges in a working 2026 SASE deployment is not the network and the security stack. It is identity-as-policy. The SASE platform is the place where the user's identity, the user's device posture, the user's data classification, and the user's geographic jurisdiction all turn into a single allow-or-deny-with-conditions decision at the moment the user touches a resource. The SD-WAN side is the transport that gets the user to the policy engine. The SSE side is the inspection that the policy engine triggers. The convergence is in the policy decision, not in the marketing logo.
For the Indian buyer drafting the 2026 SASE RFP, that reframe changes the procurement question.
The wrong opening question is "which SASE vendor has the best Magic Quadrant position?"
The right opening question is "whose identity-and-policy plane do I want my Indian users and Indian regulators to live inside for the next 5 years?"
Once that question is answered, the architectural decision (single-vendor, dual-vendor, SSE-only) follows. The vendor shortlist follows from the architecture. The feature evaluation follows from the shortlist. The contract clauses follow from the feature evaluation. The RFP itself becomes a clarification of those answers, not a discovery exercise.
VEMIO™ exists because the operational reality of running an identity-and-policy plane needs an observability layer underneath it. The SASE vendor will tell you what the policy is. The audit committee needs to see what the policy actually did. We instrument the customer side so the RFP-claimed posture stays in place twelve months and three vendor-platform-updates after the contract was signed.
The Forrester Wave will publish a new edition next year. The Gartner MQ will publish a new one too. The buyer who built the RFP around an identity-as-policy frame will not need to rewrite it.
The vendor's analyst position is one data point. Your identity-and-policy plane is the architecture.
Reply to this email with the one identity-and-policy decision you are revisiting this quarter, and we will feature the most operationally interesting reply (anonymised, with consent) next issue.
Until next time,
Ajay Salvi & the Vinay Enterprises team.
