Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
A single-pass, unified architecture avoids the duplicate latency/policy management that multi-product 'platforms' built through acquisition often carry — ask for architectural specifics, not a marketing diagram.
Look for independently-measured or customer-validated latency figures by region, and a real PoP count/map, not just 'global coverage.'
Strong answers cover both agent and clientless modes and explain non-web app support specifically, since many ZTNA products only handle HTTP/HTTPS well.
Native inline DLP across all traffic types is stronger than DLP that only covers one channel (e.g., only CASB-managed SaaS apps).
Look for a real phased-migration case study with a stated timeline, not just 'easy migration' marketing language.
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
A single unified policy engine is materially easier to operate and audit than fragmented per-pillar policy consoles.
Look for concrete numeric SLA terms and a named incident-communication process, not vague reliability assurances.
Strong answers give a transparent, itemized pricing structure and disclose common scale-triggered add-on costs upfront.
Native RBI (versus no isolation capability at all) is a materially stronger defense against browser-based exploits; ask for a real latency figure since isolation can meaningfully degrade page-load experience if poorly implemented.
An agent-only architecture leaves IoT/OT and unmanaged devices completely uncovered — look for a specific agentless enforcement mechanism for this device class.
Strong answers show a genuine per-user visibility/diagnostic capability; without it, IT has no way to distinguish 'the SASE platform is slow' from 'the user's home internet is slow' when troubleshooting complaints.
Look for genuine least-privilege, time-bounded external-party access; treating contractors identically to full employees is a common over-provisioning risk.
Strong answers state a specific retention period and whether extended retention is a separate paid add-on — this materially affects investigation capability months after an incident.
A vendor sitting inline on all traffic is itself a significant attack surface — insist on the actual audit report rather than accepting a logo/badge as sufficient evidence.
Real-time streaming export is materially more useful for active detection than periodic batch exports that introduce detection lag.
Look for a concrete, customer-validated timeline; rapid, low-friction onboarding of acquired entities is a real differentiator for organizations that grow by acquisition.