Industry trade group MEF stuck gold stars to Fortinet and Versa’s secure access service edge (SASE) platforms and to 10 service provider SASE offerings as part of its most recent certification process, but questions remain over how valuable the accolades are to end users.
Fortinet and Versa gained MEF’s “full SASE certification,” which means they completed all three of MEF’s certification modules. Those modules are part of a certification program MEF runs with testing lab CyberRatings.org and includes testing of SD-WAN, security service edge (SSE), and zero-trust capabilities.
MEF, which has a lengthy SD-WAN standardization history, noted products from those anointed vendors are deemed compliant with the MEF SD-WAN 70.1 standard, SASE 117 standard, and the Zero Trust 118 standard.
Service providers AT&T, BT, Colt, Comcast Business, Console Connect, Liberty Latin America, Lumen, Orange Business, TPC, and Verizon also earned the full SASE certification distinction, which they earn by integrating MEF-certified technology platforms.
MEF also noted that SASE vendors Broadcom and Palo Alto Networks, and service provider Sparkle “are expected to achieve full SASE certification shortly.”
MEF sees the need for SASE testing The MEF SASE certification program was designed to help align the ecosystem on common terminology; make it easier to integrate SD-WAN, zero trust, and SSE elements into products; and validate the cybersecurity defense effectiveness and application performance of SASE technologies and services.
“We want to make your job easier,” Stan Hubbard, principal analyst at MEF, told SDxCentral in a recent interview. “So when you’re looking to identify solutions that you can integrate into your digital transformation strategy, your cybersecurity strategy, we’re giving you standards-based solutions that can go through testing and be validated, that they perform at a certain expectation. … This is the first time the industry’s done this when it comes to SASE.”
Hubbard’s comments were tied to the release of MEF’s “State of the Industry: SASE” report that highlighted challenges enterprises face when attempting to select a SD-WAN or SASE vendor.
Historically, enterprises and vendors have struggled with defining and understanding SASE components, leading to inefficiencies. Establishing a standardized approach agreed upon by leading technology vendors and SASE service providers helps enterprises avoid lengthy initial discussions and focus on integration and deployment.
“What we’re trying to do is increase the efficiency of the industry, help that conversation along by setting out a standardized approach that the leading technology vendors have all agreed to and leading SASE service providers have agreed to, and that enterprises can step up and begin to start including in their RFPs [request for proposals] and RFIs [request for information],” Hubbard said. “It’s designed to get past this whole issue of everybody having to spend the initial hour in their discussions with each other about what is SASE.”
The program also helps managed service providers and SASE users to distinguish between a disaggregated, multivendor approach, a single-vendor solution, and a unified SASE offering, Hubbard added.
Is this the right way for SASE certification? However, Roy Chua, founder and principal analyst at AvidThink, explained that while “certification can be helpful,” the current process should not be viewed as an absolute.
“For enterprises trying to try to make a choice, or in the case of vendors with whether it's an enterprise or service trying to make a choice, one thing it provides is some peace of mind,” Chua said. “I think there's always value in certification in terms of the peace of mind.”
Chua added that the amorphous nature of SASE makes firm certification like those tied to more structured technologies or services more difficult.
“You end up certifying only the core functionality as opposed to a lot of the cool capabilities that are distinct from vendor to vendor,” Chua said, noting this is somewhat due to the way the SASE market has evolved since that term was coined by Gartner. This included legacy frameworks like Gartner’s own definition of SD-WAN and cloud access security broker (CASB).
“To use that framework for lack of a better framework, which is true at this point, it's kind of certifying for functionality that was defined in last decade or last two decades,” Chua explained, adding that this approach has drawn some push back from vendors.
“I do hear the sort of pushback from some of the other vendors and enterprises in that this is a good attempt, but it definitely doesn't make the enterprises who are choosing between vendors more secure in making a decision based on the outcome of the certification,” Chua said. “It will cut out a bunch of the not so good vendors who would choose not to be certified in the first place, but some of the top vendors are choosing not to be certified because they're not sure that it adds value to their customers.”
Despite the potential challenges, Chua did add that the MEF SASE certification process does at least get the right conversations started and it will be up to enterprises as to whether they garner value from the MEF certification process.
“I think what's valuable is putting it out there and then driving the conversation around it, because if you don't do that then there's no effort to try to create more clarity,” Chua said. “It's a hard problem so kudos to [MEF], full credit for trying and driving it and getting some of these vendors on board and the service providers on board, I think that's a good template in the long term. But it depends on the enterprises and whether they feel they need it or not.”
Comments