MEF unveiled its secure access service edge (SASE) Product and Services Certification, aiming to provide much-needed clarity and confidence to a market often clouded by uncertainty and inconsistency. “This is the most comprehensive, first-in-the-industry [SASE certification] that brings confidence to the market,” MEF CTO Pascal Menezes told SDxCentral.
“It's a third-party validation that tests the SASE offering by providers or vendors to say: yes, it works out a score. And that score is continuously changing because the threat landscape is changing. And everybody's trying to race to the top to get better and better scores over time,” he added.
MEF, the global industry association of network, cloud and technology providers, introduced its SASE standard framework – MEF 117 – which defines SASE services and other related terminology including SASE agent, identity and access management, SASE edge and network termination point.
But the new certification is more than just certifying these standards, Menezes noted. “It's certifying the behavior of SASE that works correctly.”
Based upon CyberRatings’ methodologies and test programs, MEF issues a rating on product and service effectiveness, performance, functionality and management of software-defined wide area network (SD-WAN), security services edge (SSE) threat protection, and zero-trust network access (ZTNA).
The rating is calculated on a scale of 0 to 800, where, for example, 775-800 equals AAA, 720-774 being AA and 0-229 considered a D rating.
“That will have a grade like Moody Bonds in grading that everyone races to the top, the better you get as a rating, the more secure you could feel as as a customer,” Menezes said.
The MEF certification registry will list the badges with attributes and additional details including vendor name, hardware model, software version, data tested and Scorecard Categories.
Cisco, Fortinet, VMware among the beta participantsMEF’s new SASE certification is currently in beta with the participation of its Technology Advisory Board (TAB) member companies that offer SASE solutions including Cisco, Fortinet, Juniper Networks, Palo Alto Networks, Versa Networks and VMware.
The beta program is set to conclude by the end of this year to reveal the participants’ test results and scorecards, with the certification becoming available to all the SASE vendors and providers worldwide in the first half of 2024.
The GA program, open to vendors and providers worldwide, is poised to incorporate Gartner levels of integration and SASE automation capability testing.
MEF SASE certification comprises SD-WAN, SSE and ZTNA certsMEF’s new SASE certification accommodates both single-vendor and multivendor SASE providers by breaking it up into standalone certificates for SD-WAN, SSE and ZTNA.
“We're testing three different aspects and then also testing the unification of that, or the integration of that, and then get a [SASE] certificate,” Menezes said.
For SASE vendors that claim to offer single-vendor SASE, or service providers that combine components from multiple vendors to offer a unified SASE, the MEF will test their SD-WAN, SSE, and ZTNA solutions separately and their integration and then use an algorithm to calculate a score for SASE; and for vendors that only offer SSE or SD-WAN, they will receive the appropriate category of certificate.
Comments