Gartner released its first Market Guide for Single-Vendor SASE, revealing to infrastructure and operations leaders that interest in secure access service edge has exploded since its introduction in 2019 – and particularly toward single-vendor solutions.

The analyst firm specifies that a complete SASE offering combines network edge capabilities – most notably SD-WAN – and a set of cloud-centric security services edge (SSE) capabilities, most notably secure web access gateway (SWG), Cloud Access Security Broker, and zero-trust network access (ZTNA).

Gartner analyst Andrew Lerner explained that a well-architected single-vendor (or unified) SASE solution specifically includes a unified management plane covering the breadth of all these functionalities with a “single policy engine, single place to define or import apps and users, and single Application Programming Interface that exposes most capabilities and a common data lake.”

“This generally means that a vendor should have a single code base versus a bunch of separate software products loosely integrated via API,” he told SDxCentral.

Lerner added the biggest benefits of a single-vendor solution are improved security posture, administrative simplicity with less consoles to manage and troubleshoot, and traffic efficiency due to single-pass encryption and optimal routing decisions instead of needing to integrate between two pieces.

Gartner estimates that by 2025, 50% of new SD-WAN purchases will be part of a single-vendor SASE offering, up from 10% in 2022.

Single-Vendor SASE Standouts Surface

While the market for well-architected single-vendor SASE offerings is immature, it’s “developing quickly,” Gartner said.

Many leading SD-WAN vendors have moved fast to add a cloud-based security stack to build out a single-vendor SASE, and a few SSE vendors have acquired SD-WAN to deliver single-vendor SASE.

Fortinet – recognized by the Gartner guide as a “representative vendor in the single-vendor SASE market” – just announced enhanced secure private access and secure Software-as-a-Service access capabilities to bolster its unified solution. Cato Networks, Cisco, Citrix, Forcepoint, Netskope, Palo Alto Networks, Versa Networks, and VMware were also recognized by the analyst firm as representative vendors in the single-vendor market.

By 2025, Gartner predicts 65% of enterprises will have consolidated individual SASE components into one or two explicitly partnered SASE vendors, up from 15% in 2021.

But Lerner noted that single-vendor SASE can have its pitfalls too.

These solutions present challenges with commercial lock-ins to a single vendor and an immaturity of the offerings in the market, as many vendors today offer “loose integration versus well-architected capabilities,” he said, adding, “somewhat related is the implementation challenge as it can be difficult to align renewals and refresh cycles to get on a single platform quickly.”

Lerner recommends choosing single-vendor SASE offerings that provide single-pass scanning, a single unified console, and data lakes covering all functions to improve user experience and staff efficacy.

Before settling on a solution, he also suggests running a “functional pilot” with real-world users and locations to ensure functionality and performance meet requirements, and engaging security organizations to establish a cross-functional SASE strategy team to “speed the time to value and increase the chances of a successful implementation.”