SASE and Zero Trust Vendor Evaluation

Written by Steve Mitchell | Aug 20, 2026, 3:00:02 PM

Vendors use the same language to describe very different solutions, so separate the terms, standardize your questions, score every vendor on the same criteria, treat critical requirements as pass/fail, and validate claims with evidence throughout, not just at the end.

A Procurement Guide for the Public Sector

Beyond choosing the best platform, the biggest challenge in Secure Access Service Edge (SASE) vendor evaluations is figuring out what each vendor is actually selling.

Gartner projects that worldwide SASE spending will reach $28.5 billion by 2028, with a compound annual growth rate (CAGR) of 26%. As the market has grown, vendor offerings, packaging, and terminology have come to vary significantly. The labels may be the same, but the solutions often are not.

It’s common for vendors to claim Zero Trust support, and many position themselves as offering SASE. Yet, two departments can procure SASE and end up with very different capabilities, costs, and risk profiles.

As Shared Services Canada moves federal networks toward Zero Trust, departments are making vendor decisions that could shape their security architecture for years. A rushed or inconsistent evaluation can create capability gaps, unnecessary cost, and difficult-to-reverse technology choices.

In our work with Canadian public sector procurement teams, we hear this same challenge again and again: proposals use identical language to describe different scopes of work. This makes it difficult to compare vendors consistently and show exactly how a decision maps back to security and procurement requirements.

This guide breaks the evaluation into five practical steps for a defensible, repeatable SASE and Zero Trust vendor evaluation, so you can compare proposals on what vendors actually deliver, not how they market it.

Step 1. Know what you're actually comparing

First, you need to separate the terms.

Zero Trust is a security strategy, not a product. It shifts defence from broad network perimeters to individual resources, applying continuous verification and least-privilege access across identity, endpoints, applications, and infrastructure. No single vendor delivers it alone

SASE, on the other hand, is a cloud-native architecture. It's the convergence of software-defined wide area network (SD-WAN) with cloud-delivered security functions, including secure web gateway (SWG), cloud access security broker (CASB), firewall-as-a-service (FWaaS), and Zero Trust network access (ZTNA).

SASE can enable parts of a Zero Trust strategy, particularly through ZTNA, but a SASE platform alone does not deliver Zero Trust across the full environment.

It's also worth distinguishing SASE from Security Service Edge (SSE). SSE covers the same security functions as SASE (SWG, CASB, ZTNA, and FWaaS) but without the SD-WAN networking layer.

Some vendors offer a full SASE stack. Others offer just one component, such as ZTNA or SSE, but market it under a Zero Trust or SASE label. The same language can therefore describe very different solutions.

Step 2. Ask these questions before evaluating any proposal

Since proposals often use the same words for different things, standardize the questions before you compare the answers. Ask:

  • What's included? A full SASE platform, or a single Zero Trust component?
  • Who’s actually involved? The platform vendor, underlying cloud or network providers, OEM components, resellers, and delivery partners each play a different role.
  • How is maturity measured? Against a recognized framework or an internal model?
  • What's the compliance baseline? Does the solution support the applicable controls in your organization's security control profile? Does it provide the evidence needed for security assessment and authorization at the required Government of Canada security level?
  • Who supports delivery? Internal teams, the product vendor, an MSSP/MSP, a systems integrator, or specialist consultants?

Step 3. Score pricing, scope, compliance, and delivery risk

Evaluate and score every vendor against the same four areas, noting that some items must be assessed as pass/fail. A high total score cannot offset a failure on a mandatory requirement.

1. Pricing structure

Is pricing per user, per site, or usage-based? Is it itemized or bundled?

2. Scope clarity

 Does the SOW name specific capabilities (ZTNA, SWG, CASB) rather than broad terms like "full SASE"?

3. Compliance

Does the solution meet the required security level, support your ITSG-33 control profile, and satisfy both Canadian data residency and data sovereignty?

4. Delivery risk

Can the vendor deliver and support the work reliably? Review supplier maturity, subcontractor dependencies, and how   staffing gaps are managed.

The delivery risk, in particular, is easy to overlook. The World Economic Forum found 65% of large organizations rank third-party and supply chain vulnerabilities as their greatest cyber-resilience challenge. A vendor's subcontractors and staffing partners are part of that risk.

Step 4. Check architecture and maturity fit 

At this stage, look beyond individual features and assess how well the solution fits your environment.

For SASE, review the architecture. Is it a genuinely integrated platform, or separate products assembled under one brand? Check policy consistency across components, points of presence, latency, TLS inspection performance, and service resilience.

For Zero Trust, review maturity alignment. Can the vendor map its capabilities to a recognized Zero Trust model and show how they support your objectives?

Step 5. Validate and document the decision

Validate material claims as you go, not only after a vendor is shortlisted. During evaluation, confirm critical claims about compliance, architecture, and delivery. A proof of concept can come later, to test the shortlisted solution in your environment.

Ask for supporting evidence, such as architecture documentation, security assessments, customer references, and proof of required capabilities.

Then document the results, any gaps, and the reasons for the final selection.

Download our IT Vendor Evaluation Scorecard to compare SASE and Zero Trust partners with one consistent framework.

How S.i. Systems supports SASE and Zero Trust delivery

For more than 20 years, S.i. Systems has helped public-sector and enterprise clients build and scale IT delivery teams. Today, we support SASE and Zero Trust initiatives, offering services across IT contractor staffing, IT consulting, and contractor management, including payrolling.

Whether you're evaluating vendors or have already selected one, reach out to discuss how we can help you move from assessment to delivery. This includes assessing delivery requirements, securing specialized networking and cybersecurity expertise, and assembling teams for implementation and ongoing operations.

Speak to an IT Consultant