Broadcom’s VMware, Fortinet, and Versa SD-WAN products headlined industry trade group MEF’s first secure access service edge (SASE) certification program module honors, with Palo Alto Networks tipped to gain a similar gold star in a program designed to provide enterprises with a cheat sheet on potential SD-WAN and SASE options.

The recognition came as part of MEF’s first SASE module testing regime that was focused on SD-WAN performance. The testing was conducted in conjunction with CyberRatings.org, which developed the test program and ran the tests based on MEF’s standards and methodologies.

MEF, which has a lengthy history on attempting to standardize SD-WAN efforts, noted products from those anointed vendors are deemed compliant with the MEF SD-WAN 70.1 standard, SASE 117 standard, and the Zero Trust 118 standard.

MEF CTO Pascal Menezes noted in a statement that the recognition allows “enterprises to confidently adopt secure and reliable access solutions as they accelerate digital transformation and migrate more applications to the cloud,” and “paves the way for enterprises to confidently pursue full SASE certification.”

MEF is also working to implement two additional test modules. One of those will be focused on security service edge (SSE) and the other on zero trust. Products that gain certification in all three test modules will be deemed to have achieved MEF’s SASE certification.

Making SD-WAN, network acronyms easier to understand The MEF SASE certification program was designed to help align the ecosystem on common terminology; make it easier to integrate SD-WAN, zero trust, and SSE elements into products; and validate the cybersecurity defense effectiveness and application performance of SASE technologies and services.

“We want to make your job easier,” Stan Hubbard, principal analyst at MEF, told SDxCentral in a recent interview. “So when you’re looking to identify solutions that you can integrate into your digital transformation strategy, your cybersecurity strategy, we’re giving you standards-based solutions that can go through testing and be validated, that they perform at a certain expectation. … This is the first time the industry’s done this when it comes to SASE.”

Hubbard’s comments were tied to the release of MEF’s “State of the Industry: SASE” report that highlighted challenges enterprises face when attempting to select a SD-WAN or SASE vendor.

Historically, enterprises and vendors have struggled with defining and understanding SASE components, leading to inefficiencies. Establishing a standardized approach agreed upon by leading technology vendors and SASE service providers helps enterprises avoid lengthy initial discussions and focus on integration and deployment.

“What we’re trying to do is increase the efficiency of the industry, help that conversation along by setting out a standardized approach that the leading technology vendors have all agreed to and leading SASE service providers have agreed to, and that enterprises can step up and begin to start including in their RFPs [request for proposals] and RFIs [request for information],” Hubbard said. “It’s designed to get past this whole issue of everybody having to spend the initial hour in their discussions with each other about what is SASE.”

The program also helps managed service providers and SASE users to distinguish between a disaggregated, multivendor approach, a single-vendor solution, and a unified SASE offering, Hubbard added.

MEF has further linked SASE adoption to network-as-a-service (NaaS) offerings. Menezes earlier this year told SDxCentral in an interview that the group’s NaaS Industry Blueprint works through how enterprises can use APIs and SD-WAN-based application assurance toward selecting a NaaS offering.

“An enterprise wants connectivity across the world, the provider doesn’t have that footprint, but it works with all its ecosystem partners and turns it up with cloud-like speed, which is the absolute goal of on demand,” Menezes said. “And it can change. Whatever throughput changes you need, you can also get through third-party providers.”

Who doesn’t like to be tested? Though unrelated to the MEF SASE testing, CyberRatings’ firewall testing regime stirred up some controversy earlier this year when it placed a “caution” rating on Cisco’s Firepower 2130 Threat Defense v7.3.1 firewall. That product was the only one of several tested that did not receive a “recommended” tag.

CyberRatings’ Chairman and CEO Vikram Phatak told SDxCentral at that time that the Cisco firewall product struggled with encryption and evasions, which are two of the key metrics weighed significantly in the evaluation.

However, Cisco denied that it submitted a firewall for testing.

In an email to SDxCentral, a Cisco spokesperson stated, “Cisco actively partners with the broader security research community and we view these relationships as essential to helping secure our customers. Unfortunately, we were not engaged to provide a product for this test, which used an older firewall model and outdated software version, nor have we received details of the tests or results.”

Phatak countered in a statement that “we can confirm that the model number we used for the test is current and we had the latest software at the time of the test. We asked Cisco to engage and they said, ‘we’re not interested.’”