Generic cybersecurity
– Getty Images

The proliferation of distributed devices accessing the corporate network, the shift to cloud-based applications, and the increasing complexity of cyberattacks are driving a need for a unified and simplified approach to network security.

Enter secure access service edge (SASE). SASE combines connectivity via SD-WAN and security with security services edge (SSE) and zero-trust network access (ZTNA) to securely connect users and devices with applications running at the edge, in the cloud, and in the data center, in a scalable and cost-effective manner, regardless of where users or company resources are located.

The SASE market is exploding. According to the Dell’Oro Group, SASE revenue grew 38 percent year-over-year in 2Q 2023 and broke the $2 billion mark to set a new record. Dell’Oro also noted that quarterly revenue has doubled in 10 quarters as enterprises look to improve networking and security services.

Why SASE needs standards

Because SASE encompasses both networking and security, it can require a change in how organizations think about security when considering SASE’s integrated approach. The mixture of solutions from different vendors in different departments can lead to siloed thinking and mismatched skill sets between networking and security teams. It is important that a common language set is defined to create tight coupling among these teams. A fragmented vendor ecosystem and a lack of common terminology underscore this need.

This is where standards come into play. The continuous definition and redefinition of terms has caused confusion in the market. SASE standards define common terminology, service attributes, and a service framework to help simplify solutions and enable customers to compare different SASE offerings more easily.

SASE standards enable many deployment models. Cloud security providers can make easy modifications to their implementations in order to comply with SASE standards. Likewise, for service providers. SASE standards enable them to choose secure networking and SSE vendors to create a SASE offering, which enables buyers to choose the solution that best supports the needs of the Enterprise.

Working together: Zero trust and SASE

Zero trust, a security strategy that eliminates automatic trust in network access, serves as the bedrock for SASE. These two approaches combine to safeguard data, applications, and network policies, thereby reducing vulnerabilities and reinforcing a robust security defense against cyber threats.

Zero trust adopts an identity- and data-centric security approach, removing implicit trust from the security infrastructure and necessitating verification for anyone or anything seeking network access. When coupled with established standards, SASE and zero trust offer a streamlined and comprehensive security solution that enforces policies network-wide, effectively reducing the attack surface and creating a formidable security perimeter that poses significant challenges for malicious actors.

Standards and certifications matter

Today’s hybrid work environment demands a user-centric approach that seamlessly integrates security with networking to support a distributed workforce and the services and applications they need to access. Industry standards such as those offered by MEF reduce confusion and facilitate faster decision-making and implementation.

The value and benefits for enterprises of requiring and using standardized SASE services and their component offerings, SD-WAN, SSE, and ZTNA, can be summarized as follows:

  • Faster path to protecting their organization from increasingly prevalent and damaging cyberattacks
    • Common standardized SASE terminology used between SASE service providers, SASE solution providers, and the Enterprise customer simplifies and speeds up the business requirements phase, and also increases the alignment of the resulting SASE service with the needs of the Enterprise.
  • A broader range of technology and service choices increases the strength of the SASE service and drives down overall costs for the Enterprise
    • Standardization increases interoperability between technology solution providers, making it easier for SASE service providers to pick and integrate best-of-breed and relevant solutions into robust, cost-effective service offerings.
  • Minimization of the Enterprise's attack surface and vulnerabilities
    • Standardization dramatically reduces the chances of poor technology integration that leaves open vulnerabilities that can be exploited by cyber attackers.
  • Easier identification by the Enterprise of best-of-breed services and products conforming to industry-hardened standards and approaches
    • Standardization enables broad vendor-neutral certifications that provide an important fast-track for enterprises choosing services that meet their specific needs

Lastly, as SASE becomes increasingly important to organizations that adopt cloud-native applications and work-from-anywhere, the ability to evaluate the effectiveness of SASE products and services, and to choose the right solution for their needs, is critical.

SASE certification offers a way to address this challenge by providing independent assurance that SASE products and services meet certain standards of performance and security. SASE certification enhances market confidence in security products and services and empowers enterprises on their digital transformation journey. Ensuring businesses have visibility into and confidence in what they’re buying is essential.


Pascal Menezes, CTO at MEF, His areas of expertise encompass SD-WAN, SASE, cloud-scale architectures, real-time media networks, Software-Defined Networking (SDN), NFV, and LSO. With a decade at Microsoft Skype for Business Global Carrier Group and a track record of success in five startups, Pascal has earned global thought leadership awards, presented at renowned events, contributed to industry standards in the Internet Engineering Task Force (IETF), MEF, and Broadband Forum (MPLS),and holds more than 30+ patents. Pascal hosts MEF's Executives at the Edge podcast.