Most organisations buying SASE only need SSE — and are quoted for both.

SASE moves enforcement out of your rack and into a provider’s cloud, so policy applies wherever the user is. It has two halves: the security half (SSE — web gateway, CASB, ZTNA, DLP) and the network half (SD-WAN). Buying the second when your WAN is already fine is the most common overspend in this category.

Netskope documents eight data centres in India and a NewEdge management plane in Mumbai; Cloudflare’s Indian PoPs include Mumbai, Chennai, New Delhi, Bengaluru, Kolkata and Nagpur. Several major vendors publish no named Indian city list at all — and PoP distance decides user experience more than any feature.

Already decided — before the quote

Whether your WAN is a problemit decides SSE versus full SASE
Where your users actually sitPoP distance is the experience
What your regulator askedtraffic residency, and log residency

Still yours to weigh

Modulesbundled, or a second SKU
The meterper user, per site, per bandwidth
The parallel runwhile the appliances still live
If you’ve never bought one

What SASE and SSE actually are

A set of security controls delivered from a provider’s global network instead of a box in your building. The user’s device connects to the nearest point of presence, the provider inspects and enforces there — web filtering, malware inspection, data-loss rules, application access — and the traffic goes on to the internet or the private application without ever transiting your network. SSE is that security bundle. SASE is SSE plus SD-WAN, the network half that connects your sites.

Three things decide the purchase and only one is a feature comparison. Which half you need — most estates need SSE. PoP presence where your people actually are, because latency is the experience. What is genuinely bundled versus licensed separately, which is where quotes diverge from expectations. The appliance estate this replaces — and the overlap you will pay for twice during the transition — is the firewall guide.

The most common mis-purchase

Signing for SASE and discovering that DLP, CASB or browser isolation are separate SKUs — then running the new subscription alongside an unamortised firewall estate for three years. Ask which modules are in the base tier, and put the parallel-run cost in the business case before the purchase order.

Often confused withFirewall & Network Security — the estate this replaces, and the double-spend →·Zero Trust Access — the ZTNA half, bought alone →·Cloud & Workload Security — where SASE stops and CNAPP begins →

The four routes of network security — and which one is yours →

Boundary — the terms this buyer confuses

SASE vs SSE · single-vendor vs dual-vendor · what SSE excludes

One split that decides the price, one architectural choice, and one boundary buyers discover after signing. None of these is a maturity ladder.

SASE vs SSE

SSE is the security half: secure web gateway, CASB, ZTNA, DLP, and often firewall-as-a-service, delivered from the provider's cloud. SASE is SSE plus the network half — SD-WAN connecting your sites. If your WAN works and your problem is people and applications outside the building, SSE is the whole purchase. The quote will usually be for SASE.

Single-vendor vs dual-vendor SASE

Single-vendor means one policy model, one console, one negotiation — and one vendor's weakest module. Dual-vendor means best-of-breed SSE from one provider and SD-WAN from another, with two policy models to keep in step. Neither is more mature; the honest question is whether your team would rather run one console badly or two consoles well.

What SSE excludes

SSE inspects traffic to and from users and applications. It does not secure the workload itself — container runtime, cloud posture, identity entitlements in your cloud accounts are CNAPP and identity products, on other guides. It also does not replace east-west inspection inside a data centre. Buying SSE and assuming those cloud workloads are covered is a scope error, not a product failure — that ground is the Cloud & Workload Security guide under Security.

SASE is not 'firewall, evolved'

It is a different enforcement location with different failure modes. An appliance fails by running out of capacity; a SASE platform fails by PoP distance, an outage in someone else's cloud, or a module you did not license. Cost behaves differently too — subscription rather than refresh cycle — and the renewal trap is module creep rather than a hardware end-of-life.

These are not a maturity ladder. An estate with heavy site-to-site traffic and on-premises applications may be right to keep appliances; an estate whose people work from anywhere may be right to buy no appliance at all. The expensive middle — owning both, reconciling neither — is what the category page opens with, because no vendor will write it down.
The decision variables

Eight things decide this purchase. The feature grid is none of them.

Eight variables decide this purchase. The instrument tests what documentation establishes (scope, modules, bundling, India PoPs and logs, experience monitoring, firewall lineage); real latency, contractor counting and the migration path are prose because they need measurement and a contract, not a datasheet.

01

SASE or SSE — do you need the network half

SD-WAN included, or the security half alone. The single largest difference between what buyers need and what they are quoted.

02

PoP presence and performance in India

The nearest point of presence decides user experience more than any feature on the datasheet. Documented by city for Netskope, Cloudflare and Palo Alto; not established for several major vendors — flagged, never assumed.

03

Single-vendor versus best-of-breed

One policy model and one weakest module, or two consoles and two contracts. An operating-model question, not a maturity one.

04

What is genuinely included versus licensed separately

SWG, CASB, ZTNA, DLP, browser isolation and firewall-as-a-service are bundled differently by every vendor. Zscaler's ZPA is a separate subscription from ZIA; Palo Alto, Fortinet, Check Point, Cisco and Versa bundle ZTNA into the base.

05

Digital experience monitoring

The capability that tells you whether the platform is working, and where it is not. Documented at Zscaler (as its own subscription), Netskope, Palo Alto, Cisco and Versa; absent at the others here.

06

Migration path from an existing firewall estate

Same vendor (Palo Alto, Fortinet, Check Point, Versa, Cisco, Trend) or a second vendor in parallel (Zscaler, Netskope, Cloudflare, Coro). It decides whether the transition is one policy model or two.

07

Data residency for inspected traffic and logs

Where traffic is decrypted and where the logs are stored are two separate questions. Only Netskope documents the second in India here.

08

Bandwidth-based versus user-based pricing

Per user is the norm and it meets contractors, seasonal staff and service accounts awkwardly; Versa's network half is per site. Ask how a user is counted and what happens when the count moves.

The narrowing instrument · the reasoning is the product

Narrow 22 products to your shortlist

Set what is true for you. A product that misses a constraint fades with its reason printed on it; where a vendor does not document Indian PoP cities or log residency it is flagged and stays, never eliminated on an absence of evidence. Every chip is reversible.

How much of it you need

What must be in it

Where you're coming from

Running it

Bundled, not billed twice

India

Estate size

Measured latency, contractor counting and migration effort are in the notes below rather than chips — the first needs a test from your own offices, and the others need a contract.

Still in22/ 22
Zscaler logo
Price~$6–12≈ ₹498

per user / month reported (roughly $72–325 per user / year by edition); the secure web gateway is the base and CASB, DLP, browser isolation and firewall-as-a-service are edition or add-on SKUs

Estates whose internet traffic should never touch their own network again — the reference proxy-based SSE, with the largest deployed footprint and the deepest inspection.

The catch: The base edition is the web gateway; DLP, CASB and browser isolation arrive as higher editions or add-ons, which is where quotes diverge from expectations. Zscaler sells no firewall, so a migration from an appliance estate means two vendors in parallel. Named Indian PoP cities are not established from the vendor's own documentation here — flagged.

Reference SSEEditions and add-onsNo firewall estate
Open the intel page
Zscaler logo
Price~$6–11≈ ₹498

per user / month reported (ZPA Business roughly $4–7, Transformation roughly $7–11); the private-application half, sold alongside ZIA rather than inside it

Estates replacing remote-access VPN with per-application access — the most widely deployed ZTNA, and the reason many buyers arrive at Zscaler at all.

The catch: A separate subscription from ZIA: the combined bill is what most buyers actually pay, and it is rarely what they were first quoted. Server-initiated protocols need the Network Connector, an extra component to deploy.

ZTNA halfSeparate from ZIANetwork Connector for legacy
Open the intel page
Zscaler logo

per user / month add-on; hop-by-hop visibility from the device through the PoP to the application — the product that tells you whether the SASE is actually working

Estates that have deployed SSE and now need to answer “is it the network, the PoP, or the application?” when a user complains.

The catch: Monitoring, not enforcement — it protects nothing. It is a third Zscaler subscription on top of ZIA and ZPA, and the case for it only becomes obvious after the first month of unexplained complaints.

Digital experience monitoringThird subscriptionNo enforcement
Open the intel page
Zscaler logo

the platform bundle that combines ZIA, ZPA, ZDX and data protection — reported around $312,000 a year for 500 users on the Transformation edition, which is the number to reason from rather than any per-module list

Enterprises consolidating internet access, private access and experience monitoring under one platform and one negotiation.

The catch: Platform pricing is quoted, not listed, and the edition ladder decides what is included — the reported enterprise figures are large enough that a per-user comparison against point products is misleading. Still no firewall: the appliance estate remains someone else's.

The full platformEnterprise-pricedOne negotiation
Open the intel page
Netskope logo
Price~$15+≈ ₹1,245

per user / month for a fully-bundled configuration (entry bundles list lower and rise through add-on modules); NewEdge carries eight data centres in India, and a NewEdge management plane in Mumbai supports DPDP-aligned data residency

Estates where data protection is the reason for the project — CASB and DLP are in the platform's DNA rather than bolted on — and where Indian data residency must be documented, not assumed.

The catch: Module creep is the pattern to watch: entry bundles look competitive and the fully-loaded per-user figure converges with Zscaler's. No firewall estate of its own, so an appliance migration runs in parallel with another vendor.

8 India data centresMumbai management planeCASB/DLP-first
Open the intel page
Netskope logo
PricePer user

per user / month within the Netskope One platform; inline inspection of web and cloud application traffic with application-instance awareness rather than domain-level allow or block

Estates whose control requirement is by application instance — allow the corporate tenant, block the personal one — which domain-level filtering cannot express.

The catch: Instance awareness is the differentiator and the reason it is priced as a platform module rather than a cheap filter. DNS-layer-only estates will find this more product than they need — the secure web guide covers that end.

Instance-awareInline inspectionPlatform module
Open the intel page
Palo Alto Networks logo
Palo Alto Prisma SASEPalo Alto Networks
PricePer user bundle

per user / year bundles combining Prisma Access with Prisma SD-WAN; a Mumbai cloud location has been documented since 2021, and Prisma Access falls back to India West for users who cannot connect in-country

Palo Alto firewall estates moving enforcement to the cloud without changing vendor, policy model or account team — the cleanest migration path on this page.

The catch: The full SASE bundle includes the network half you may not need; buying Prisma Access alone is the SSE-shaped purchase, and the quote will not default to it. Premium-priced, and the value assumes you adopt the platform.

True SASE (with SD-WAN)Mumbai locationFirewall migration path
Open the intel page
Palo Alto Networks logo
Palo Alto Prisma AccessPalo Alto Networks
PricePer user

per user / year, quoted; the security half without SD-WAN — the same App-ID policy model as the firewall estate, delivered from Palo Alto's cloud

Estates that want the firewall's inspection model applied to users who never come back to the office, without buying the network half.

The catch: Still enterprise-priced, and the migration only feels seamless if you already run Palo Alto policy. In-country log storage for Indian buyers is not established from documentation — confirm in writing.

SSE-shapedSame policy as the NGFWIndia logs: unverified
Open the intel page
Fortinet logo
PriceQuote

quoted per user per year through partners in Standard, Advanced and Comprehensive tiers; the only public figures are a UK reseller’s 2024 G-Cloud list (£78, £101 and £304 at 50–499 users, falling with volume), not an Indian price

FortiGate estates extending the same policy and console to remote users at the lowest published entry price on this page.

The catch: Digital experience monitoring is not a documented capability here, and named Indian PoP cities are not established from vendor documentation — both flagged rather than ruled out. The Fabric discount is real and it deepens the single-vendor commitment.

Lowest published entryFabric discountIndia PoPs: unverified
Open the intel page
Check Point logo
PriceQuote

per user, quoted — the Perimeter 81 price list is no longer published; the former Perimeter 81, now integrated with Check Point's estate, with an India data-residency region (May 2025) and PoPs announced in Bengaluru, Chennai, Mumbai and New Delhi

Mid-market and distributed estates that want network-level access and web security quickly, with a Check Point firewall estate alongside.

The catch: Narrower module set than the SSE leaders — CASB and DLP depth are not its ground — and no documented digital experience monitoring. Its Indian PoP cities rest on a June 2025 announcement rather than a current admin guide.

Fast to deployNarrower modulesIndia residency region
Open the intel page
Cisco logo
PricePer user

per user / year, quoted; the successor to Umbrella's SIG tiers with ZTNA, and the natural extension for estates already running Cisco networking and Duo

Cisco estates consolidating Umbrella, VPN and firewall policy into one cloud service under an existing enterprise agreement.

The catch: Newer than Zscaler's and Netskope's platforms and carrying the Umbrella lineage; module depth varies by tier. Named Indian PoP cities are not established from vendor documentation — flagged, and worth asking for in writing given the latency stakes.

Umbrella lineageFits a Cisco EAIndia PoPs: unverified
Open the intel page
Cloudflare logo
PriceFree → $7≈ ₹581

free for up to 50 users, then $7 per user / month pay-as-you-go with no user cap; Enterprise adds expanded CASB, custom DLP, browser isolation, dedicated egress IPs and longer log retention — India PoPs include Mumbai, Chennai, New Delhi, Bengaluru, Kolkata and Nagpur

Estates that want real SSE capability at a published price they can start on today, on the largest Indian PoP footprint here.

The catch: The $7 tier is genuinely capable and genuinely not the enterprise product: DLP depth, CASB breadth and log retention move to Enterprise, which is quoted. No firewall estate, and no documented digital experience monitoring.

Published price6 India citiesEnterprise tier for depth
Open the intel page
Versa Networks logo
Versa SASEVersa Networks
PricePer site / per user

subscription per site for the network half and per user for the security half; the same software runs the branch appliance, the data centre and the cloud PoP — often delivered in India through a carrier

Estates that want one software stack from branch to cloud, and are willing to buy it through a carrier-managed service.

The catch: Frequently reached through a carrier rather than directly, which changes who owns support and how fast policy changes move. Named Indian PoP cities are not established from Versa's own documentation.

One stack, branch to cloudOften carrier-deliveredIndia PoPs: unverified
Open the intel page
Versa Networks logo
Versa SSEVersa Networks
PricePer user

per user / year for the security half alone, without committing to Versa's SD-WAN — the honest answer for estates that keep their existing network

Estates that want Versa's inspection and access controls without replacing the WAN they already run.

The catch: Smaller deployed footprint than Zscaler or Netskope in the SSE market specifically, and PoP presence in India is not documented by city. Support often sits with a partner.

SSE without the SD-WANSmaller SSE footprintIndia PoPs: unverified
Open the intel page
Coro logo
Price$10.50≈ ₹872

per user / month published for the SASE module (Coro Essentials $10.50, Complete $15 unmanaged / $20 managed); individual modules from $4 per user / month on a modular platform built for the mid-market

SMB and mid-market estates that want network access, web security and endpoint protection on one modular per-user bill with no appliance.

The catch: Built for the mid-market and documented there: inspection depth, module breadth and enterprise controls are well behind the SSE leaders, and it is unverified above 2,000 users. No documented India PoP presence.

Published SMB priceModular platformMid-market scale
Open the intel page
Cato Networks logo
Cato SASE PlatformCato Networks
PriceQuote-only

quoted by sites, bandwidth and which of the four modules you license; the whole platform runs on Cato's own private backbone of 85+ PoPs rather than public cloud, with Chennai and Mumbai among them and a stated 99.999% uptime SLA on the SD-WAN half

Estates where the network is the problem as much as the security — Cato owns and operates the backbone, so latency and local breakout are testable from your own branches before you sign.

The catch: You commit to one vendor's backbone: the traffic path becomes their architecture decision, and where their PoPs are thin no feature compensates. In-country log storage is not established — their site sits behind bot protection, so it could not be verified and should be asked for in writing.

Owns the backboneChennai + Mumbai PoPsIndia logs: unverified
Open the intel page
Cato Networks logo
Cato SSECato Networks
PriceQuote-only

per user, quoted; the security half alone, with inspection running inside the PoP the traffic already crosses rather than as a separate cloud service you hairpin to

Estates that want the security half without the network half, and value inspection happening on the path rather than beside it — particularly where TLS decryption has been quietly scoped down on branch appliances.

The catch: The no-hairpin advantage largely disappears if your network is not also on Cato, at which point you are comparing it to the SSE specialists on features alone. Private application access overlaps with their ZTNA module — confirm which one the quote covers.

Inspection in the PoPStrongest with their SD-WANZTNA overlap
Open the intel page
Cato Networks logo
Cato Universal ZTNACato Networks
PriceQuote-only

per user, quoted; one policy across user types and locations with continuous verification through the session and entitlement granted per application rather than admission to a network

Estates that secured remote users and left the office on implicit network trust — the universal half is the seam most ZTNA projects postpone into a phase that never gets funded.

The catch: Application-level segmentation needs an inventory of your applications and who legitimately needs each. That is the real project and no vendor supplies it. Private app access also appears in their SSE module.

Covers the office tooContinuous verificationNeeds an app inventory
Open the intel page
Cato Networks logo
Cato AI SecurityCato Networks
PriceQuote-only

quoted; packaging against the other three modules is worth confirming rather than assuming, since this one was added in March 2026 and recently introduced modules tend to be repackaged

Estates that cannot list the AI services their staff actually use, and where an endpoint agent rollout is the objection blocking every other option — this rides inspection that already exists.

The catch: The newest of the four modules, so ask what is generally available today versus roadmap, especially around AI agents. Network-based, so AI use that never crosses the network is outside its view.

No new agentNewest moduleNetwork-based only
Open the intel page
Trend Micro logo
PriceCredits / quote

consumed as Vision One credits alongside Trend's other modules rather than as a standalone per-user list; risk signals from the endpoint and email products feed the access decision

Trend Vision One estates that want access decisions informed by the same risk score their endpoint and email products already produce.

The catch: Credit-based billing is opaque until you run it, and the SSE module set is narrower than the platform leaders'. Its value depends on running Trend elsewhere; the Internet Access gateway runs in AWS Mumbai.

Vision One creditsRisk-informed accessNarrower SSE
Open the intel page
Skyhigh Security logo

per user, quoted through partners: Essential bundles the cloud and on-prem web gateway, shadow-IT CASB, DLP and risky-web isolation; Advanced adds unlimited sanctioned-app CASB and endpoint DLP; Complete adds Private Access and Cloud Firewall; status page lists PoPs in Bangalore, Noida and Mumbai

Estates moving to SSE without retiring their on-premises web gateway on day one — one policy runs in the cloud and on the appliance.

The catch: A Niche Player in Gartner’s 2025 SSE Magic Quadrant (a Visionary in 2024), though first of eight in the Advanced SSE use case in Gartner’s 2026 Critical Capabilities. ZTNA and firewall come only with Complete or as add-ons; all pricing is partner-quoted.

Hybrid policyIndia log storageThree suites
Open the intel page
iboss logo

per user per year, quoted: Core carries the web gateway, DNS security, HTTPS decryption and basic CASB; Advanced adds ZTNA, inline CASB and SD-WAN; Complete adds DLP and API CASB; browser isolation is always an add-on and the reporting licence is sold separately; iboss lists data centres in Mumbai and Delhi

Estates that want each customer’s gateway in its own container, with the option to run it in iboss’s cloud, a chosen country or their own data centre.

The catch: A Niche Player in Gartner’s 2025 SSE Magic Quadrant. Indian log storage is not documented, and ZTNA and DLP need the higher packages; the UK reseller prices seen online are not iboss list prices.

Mumbai + Delhi DCsContainer per customerGartner 2025: Niche
Open the intel page
Why each constraint rules out what it doesShow the reasoning ↓

The security half onlyRules out Palo Alto Prisma SASE, Fortinet FortiSASE, Check Point Harmony SASE, Versa SASE, Coro Network & SASE, Cato SASE Platform and iboss Zero Trust SASE (Core, Advanced, Complete) — sold as full SASE including the network half; the SSE-shaped purchase is a different SKU from this vendor. That leaves Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Zscaler Zero Trust Exchange (platform), Netskope One SSE Platform, Netskope Next Gen SWG, Palo Alto Prisma Access, Cisco Secure Access, Cloudflare One (Zero Trust), Versa SSE, Cato SSE, Cato Universal ZTNA, Cato AI Security, Trend Micro Zero Trust Secure Access and Skyhigh Security Service Edge (Essential, Advanced, Complete).

SD-WAN includedRules out Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Zscaler Zero Trust Exchange (platform), Netskope One SSE Platform, Netskope Next Gen SWG, Palo Alto Prisma Access, Cisco Secure Access, Cloudflare One (Zero Trust), Versa SSE, Cato SSE, Cato Universal ZTNA, Cato AI Security, Trend Micro Zero Trust Secure Access and Skyhigh Security Service Edge (Essential, Advanced, Complete) — security-only; SD-WAN comes from another product or another vendor. That leaves Palo Alto Prisma SASE, Fortinet FortiSASE, Check Point Harmony SASE, Versa SASE, Coro Network & SASE, Cato SASE Platform and iboss Zero Trust SASE (Core, Advanced, Complete).

CASBRules out Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Palo Alto Prisma Access, Check Point Harmony SASE, Coro Network & SASE and Cato Universal ZTNA — CASB is not a documented capability of this product. That leaves Zscaler Internet Access (ZIA), Zscaler Zero Trust Exchange (platform), Netskope One SSE Platform, Netskope Next Gen SWG, Palo Alto Prisma SASE, Fortinet FortiSASE, Cisco Secure Access, Cloudflare One (Zero Trust), Versa SASE, Versa SSE, Cato SASE Platform, Cato SSE, Cato AI Security, Trend Micro Zero Trust Secure Access, Skyhigh Security Service Edge (Essential, Advanced, Complete) and iboss Zero Trust SASE (Core, Advanced, Complete).

DLPRules out Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Check Point Harmony SASE, Coro Network & SASE, Cato Universal ZTNA and Trend Micro Zero Trust Secure Access — DLP is not a documented capability of this product. That leaves Zscaler Internet Access (ZIA), Zscaler Zero Trust Exchange (platform), Netskope One SSE Platform, Netskope Next Gen SWG, Palo Alto Prisma SASE, Palo Alto Prisma Access, Fortinet FortiSASE, Cisco Secure Access, Cloudflare One (Zero Trust), Versa SASE, Versa SSE, Cato SASE Platform, Cato SSE, Cato AI Security, Skyhigh Security Service Edge (Essential, Advanced, Complete) and iboss Zero Trust SASE (Core, Advanced, Complete).

Browser isolationRules out Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Netskope Next Gen SWG, Fortinet FortiSASE, Check Point Harmony SASE, Cisco Secure Access, Versa SASE, Versa SSE, Coro Network & SASE, Cato SASE Platform, Cato SSE, Cato Universal ZTNA, Cato AI Security and Trend Micro Zero Trust Secure Access — remote browser isolation is not a documented capability of this product. That leaves Zscaler Internet Access (ZIA), Zscaler Zero Trust Exchange (platform), Netskope One SSE Platform, Palo Alto Prisma SASE, Palo Alto Prisma Access, Cloudflare One (Zero Trust), Skyhigh Security Service Edge (Essential, Advanced, Complete) and iboss Zero Trust SASE (Core, Advanced, Complete).

Firewall-as-a-serviceRules out Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Netskope One SSE Platform, Netskope Next Gen SWG, Cloudflare One (Zero Trust), Versa SSE, Cato SSE, Cato Universal ZTNA, Cato AI Security and Trend Micro Zero Trust Secure Access — firewall-as-a-service is not a documented capability of this product. That leaves Zscaler Internet Access (ZIA), Zscaler Zero Trust Exchange (platform), Palo Alto Prisma SASE, Palo Alto Prisma Access, Fortinet FortiSASE, Check Point Harmony SASE, Cisco Secure Access, Versa SASE, Coro Network & SASE, Cato SASE Platform, Skyhigh Security Service Edge (Essential, Advanced, Complete) and iboss Zero Trust SASE (Core, Advanced, Complete).

Same vendor as the firewallRules out Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Zscaler Zero Trust Exchange (platform), Netskope One SSE Platform, Netskope Next Gen SWG, Cloudflare One (Zero Trust), Coro Network & SASE, Cato SASE Platform, Cato SSE, Cato Universal ZTNA, Cato AI Security, Skyhigh Security Service Edge (Essential, Advanced, Complete) and iboss Zero Trust SASE (Core, Advanced, Complete) — this vendor sells no firewall estate, so the migration runs two vendors in parallel. That leaves Palo Alto Prisma SASE, Palo Alto Prisma Access, Fortinet FortiSASE, Check Point Harmony SASE, Cisco Secure Access, Versa SASE, Versa SSE and Trend Micro Zero Trust Secure Access.

Experience monitoringRules out Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Netskope Next Gen SWG, Fortinet FortiSASE, Check Point Harmony SASE, Cloudflare One (Zero Trust), Coro Network & SASE, Cato Universal ZTNA, Cato AI Security, Trend Micro Zero Trust Secure Access and Skyhigh Security Service Edge (Essential, Advanced, Complete) — no documented digital experience monitoring; a slow user is a support ticket without evidence. That leaves Zscaler Digital Experience (ZDX), Zscaler Zero Trust Exchange (platform), Netskope One SSE Platform, Palo Alto Prisma SASE, Palo Alto Prisma Access, Cisco Secure Access, Versa SASE, Versa SSE, Cato SASE Platform, Cato SSE and iboss Zero Trust SASE (Core, Advanced, Complete).

ZTNA in the base tierRules out Zscaler Internet Access (ZIA), Zscaler Digital Experience (ZDX), Netskope Next Gen SWG and Cato AI Security — no ZTNA capability in this product; Netskope One SSE Platform, Skyhigh Security Service Edge (Essential, Advanced, Complete) and iboss Zero Trust SASE (Core, Advanced, Complete) — ZTNA exists but is a separate subscription or higher edition. That leaves Zscaler Private Access (ZPA), Zscaler Zero Trust Exchange (platform), Palo Alto Prisma SASE, Palo Alto Prisma Access, Fortinet FortiSASE, Check Point Harmony SASE, Cisco Secure Access, Cloudflare One (Zero Trust), Versa SASE, Versa SSE, Coro Network & SASE, Cato SASE Platform, Cato SSE, Cato Universal ZTNA and Trend Micro Zero Trust Secure Access.

Named India PoPsRules nothing out on published terms. It flags Zscaler Internet Access (ZIA) — An India region is served but named PoP cities are not established from the vendor's own documentation, Zscaler Private Access (ZPA) — An India region is served but named PoP cities are not established from the vendor's own documentation, Zscaler Digital Experience (ZDX) — An India region is served but named PoP cities are not established from the vendor's own documentation, Zscaler Zero Trust Exchange (platform) — An India region is served but named PoP cities are not established from the vendor's own documentation, Fortinet FortiSASE — India PoP presence not established from vendor documentation, Cisco Secure Access — India PoP presence not established from vendor documentation, Versa SASE — India PoP presence not established from vendor documentation, Versa SSE — India PoP presence not established from vendor documentation and Coro Network & SASE — India PoP presence not established from vendor documentation — marked on the cards, not removed.

In-country logsRules nothing out on published terms. It flags Zscaler Internet Access (ZIA) — In-country log storage not established from documentation, Zscaler Private Access (ZPA) — In-country log storage not established from documentation, Zscaler Digital Experience (ZDX) — In-country log storage not established from documentation, Zscaler Zero Trust Exchange (platform) — In-country log storage not established from documentation, Palo Alto Prisma SASE — In-country log storage not established from documentation, Palo Alto Prisma Access — In-country log storage not established from documentation, Fortinet FortiSASE — In-country log storage not established from documentation, Check Point Harmony SASE — In-country log storage not established from documentation, Cisco Secure Access — In-country log storage not established from documentation, Cloudflare One (Zero Trust) — In-country log storage not established from documentation, Versa SASE — In-country log storage not established from documentation, Versa SSE — In-country log storage not established from documentation, Coro Network & SASE — In-country log storage not established from documentation, Cato SASE Platform — In-country log storage not established from documentation, Cato SSE — In-country log storage not established from documentation, Cato Universal ZTNA — In-country log storage not established from documentation, Cato AI Security — In-country log storage not established from documentation, Trend Micro Zero Trust Secure Access — In-country log storage not established from documentation and iboss Zero Trust SASE (Core, Advanced, Complete) — In-country log storage not established from documentation — marked on the cards, not removed.

Above 5,000 users on the platformRules nothing out on published terms. It flags Coro Network & SASE — Not documented at this platform size, Cato AI Security — Not documented at this platform size and Skyhigh Security Service Edge (Essential, Advanced, Complete) — Not documented at this platform size — marked on the cards, not removed.

Most buyers who say SASE mean SSESASE is the security half plus the network half (SD-WAN). SSE is the security half alone. If your WAN is fine and your problem is users and applications that left the building, you need SSE — and you will be quoted for SASE, because the bundle is larger. Zscaler, Netskope, Cloudflare and Cisco are SSE-shaped; Palo Alto, Fortinet, Check Point, Versa and Coro sell the fuller SASE, and Palo Alto and Versa also sell the SSE-shaped half separately. Ask which half you are being quoted, per line.

India PoP presence decides user experience more than any featureThe nearest PoP is the difference between a platform users forget about and one they route around. Documented here from vendor sources: Netskope carries eight data centres in India with a NewEdge management plane in Mumbai supporting DPDP-aligned residency; Cloudflare's Indian PoPs include Mumbai, Chennai, New Delhi, Bengaluru, Kolkata and Nagpur; Palo Alto has documented a Mumbai cloud location since 2021, with Prisma Access falling back to India West where in-country connection is unavailable. Zscaler's published enforcement-node list includes Mumbai, Chennai, New Delhi and Hyderabad; Check Point announced an India residency region with PoPs in Bengaluru, Chennai, Mumbai and New Delhi; Trend Micro's Internet Access gateway runs in AWS Mumbai. Fortinet, Cisco, Versa and Coro are not established — all flagged, none ruled out. Ask for the city list and a latency test from your own offices before signing; real measured latency from Indian cities is delivery-team knowledge: [TechBag to confirm].

What is bundled, and what arrives as a separate SKUThis is where quotes diverge from expectations. Zscaler's base is the web gateway with CASB, DLP and browser isolation as editions or add-ons, and ZPA is a separate subscription from ZIA — the combined bill is what estates actually pay. Netskope bundles CASB with the gateway and adds modules upward. Palo Alto, Fortinet, Check Point, Cisco and Versa bundle ZTNA into the base tier. Coro is modular from $4 per user per month. Read the line items, not the platform name.

User-based pricing meets contractors and service accountsPer-user meters are simple until you count the people who are not employees: contractors, seasonal staff, partners, and the service accounts that also traverse the proxy. Ask how each vendor counts a user, whether inactive users are billed, and what happens when the number moves seasonally. Bandwidth-based and site-based meters (Versa's network half) behave differently again.

Under 500 usersNo published term excludes an estate this size: Cloudflare is free to 50 users and $7 per user per month beyond, Coro publishes $10.50 for its SASE module, and Fortinet's per-user tiers start at 50 users (a UK reseller's 2024 G-Cloud list puts Standard at £78 per user per year). The platform leaders publish no floor but carry minimums through the channel — current minimums by vendor: [TechBag to confirm].

Narrow to your situation

Eight situations, eight shortlists — with the half named

Each shortlist states whether the answer is SSE or full SASE, and what the India question does to it. If your WAN is already fine, start from the first row.

The WAN is fine — it is the users and applications that left

Why: All three are SSE-shaped: security enforcement in the cloud without buying SD-WAN you do not need. Cloudflare publishes a price you can start on today; Netskope and Zscaler are the depth options.

The trade-off: You will be quoted SASE. Ask for the SSE-shaped configuration explicitly, line by line, and check whether ZTNA is inside the base tier or a second subscription.

Migrating off a firewall estate without changing vendor

Why: Same policy model, same console, same account team — Palo Alto's App-ID policy carries across, Fortinet gives FortiGate customers Security Fabric pricing worth a reported 20–25%, and Check Point extends the Quantum estate.

The trade-off: Single-vendor continuity makes the migration easier and the lock-in deeper. It also does not recover the appliance's book value — the parallel run is still real.

Indian data residency has to be documented, not assumed

Why: Netskope documents eight Indian data centres plus a Mumbai management plane for DPDP-aligned residency; Cloudflare documents six Indian PoP cities; Palo Alto documents a Mumbai cloud location.

The trade-off: PoP presence and log residency are different questions — only Netskope documents the second here. Get both in the contract, by name.

Data protection is the reason for the project

Why: Netskope's CASB and DLP are the platform's origin rather than an add-on; Zscaler's are higher editions; Cloudflare's arrive at Enterprise.

The trade-off: The cheapest quote in this row is rarely the one with the DLP depth demonstrated — confirm which edition the demo was on.

Users complain it is slow and nobody can prove where

Why: Digital experience monitoring answers whether it is the device, the link, the PoP or the application. Zscaler sells ZDX as its own subscription; Netskope, Cisco, Palo Alto and Versa document it inside the platform.

The trade-off: Zscaler's is a third subscription on top of ZIA and ZPA. Fortinet, Check Point, Cloudflare and Coro document none — a slow user stays a support ticket without evidence.

Mid-market, no appliance, one bill

Why: Coro publishes $10.50 per user per month for SASE on a modular platform; Cloudflare starts free to 50 users and $7 beyond; Harmony SASE deploys quickly for distributed teams.

The trade-off: Coro is unverified above 2,000 users and its inspection depth is well behind the leaders. Cheap and adequate is a legitimate answer — cheap and assumed-equivalent is not.

Branch connectivity and security together, one stack

Why: Versa runs the same software in the branch, the data centre and the PoP; Palo Alto pairs Prisma Access with Prisma SD-WAN; Fortinet extends the FortiGate estate.

The trade-off: Versa is frequently delivered through a carrier in India, which changes who owns support and how fast a policy change moves. Confirm the operating model, not just the technology.

Already inside a Cisco or Trend platform agreement

Why: Cisco Secure Access consolidates Umbrella, VPN and firewall policy under an existing enterprise agreement; Trend feeds endpoint and email risk into the access decision through Vision One credits.

The trade-off: Both carry narrower SSE module sets than the leaders, and neither documents Indian PoP cities. Credit-based billing at Trend is opaque until you run it.

The spine of the decision

Two halves, six modules, and the map that decides the experience

Place every quote on this grid before comparing prices: which half it covers, which modules are in the base tier, and where the nearest point of presence to your users actually is.

Half 1

SSE — the security half

Web gateway, CASB, ZTNA, DLP, often firewall-as-a-service, delivered from the provider's cloud. What most buyers actually need, and rarely what they are first quoted.

Half 2

SASE — plus the network

SSE with SD-WAN included: sites and users under one policy and one contract. Correct when the WAN is genuinely being replaced at the same time; expensive when it is not.

The India map

Documented PoP presence

Netskope: eight Indian data centres plus a Mumbai management plane for DPDP-aligned residency. Cloudflare: Mumbai, Chennai, New Delhi, Bengaluru, Kolkata, Nagpur. Palo Alto: a documented Mumbai cloud location since 2021. Everyone else here — ask for the city list in writing.

The second bill

Modules sold separately

Zscaler's ZPA is a separate subscription from ZIA and ZDX is a third; CASB, DLP and browser isolation move up editions at several vendors. Read the line items, not the platform name.

The PoP test

Ask these before the feature demo, in this order.

  • —Name your Indian PoP cities. Not the region — the cities. Netskope, Cloudflare and Palo Alto document theirs; several major vendors on this page do not, and it is the question that decides whether users route around the platform.
  • —Where is traffic decrypted, and where are the logs stored? Two different answers, and only one vendor here documents in-country log storage.
  • —Which modules are in the tier you just demonstrated? Line by line: SWG, CASB, ZTNA, DLP, browser isolation, firewall-as-a-service.
  • —How do you count a user? Contractors, seasonal staff, service accounts, and what happens when the number moves.

The double-spend

The line no vendor will put in your business case.

  • —What it is: an unamortised firewall estate running alongside a SASE subscription, with overlapping capability nobody has reconciled. Both bills, for years, for one job.
  • —Why it happens: the refresh cycle and the subscription decision are made by different people at different times, and every vendor is selling one side of it. Nobody is incentivised to write the sentence down.
  • —What to do about it: put the parallel-run period in the business case explicitly — how many quarters, how many sites, both bills — and negotiate the appliance and the subscription in the same conversation, with the same vendor where possible.
  • —Your number: [TechBag to confirm] — TechBag models it from your refresh dates, site count and user population.
What breaks as you grow

What changes at 500, 5,000 and 20,000 users

SASE scales by users and by PoP distance, and the second is invisible until it is not. The bill follows the per-user meter; the satisfaction follows the map.

500users

Published pricing is the constraint

  • —Cloudflare ($7 per user per month beyond 50 free), Coro ($10.50 published for SASE) and Fortinet (a UK G-Cloud list from £78 per user a year) give you a number before an enterprise negotiation.
  • —One or two Indian offices means PoP distance is testable in an afternoon — do it before signing.
  • —The module question is simpler here: most estates this size need the web gateway and ZTNA, not the full data-protection stack.

Put this in your PoC

Run a two-week pilot from your actual offices and measure page-load times against the current path. If it is slower, no feature list fixes it.

5,000users

Modules and the parallel run are the constraint

  • —Module creep is now the pattern: entry bundles that looked competitive converge upward as CASB, DLP and browser isolation are added.
  • —The firewall estate is still on the books — the parallel-run quarters belong in the business case, not in a surprise.
  • —Digital experience monitoring stops being optional: at this size, unexplained slowness becomes a weekly meeting.

Put this in your PoC

Price the same estate three ways — SSE only, full SASE, and staying on appliances — over five years. If nobody has, the decision is being made blind.

20,000users

Residency and the operating model are the constraint

  • —Traffic decryption location and log residency become regulator-visible; only Netskope documents in-country log storage here.
  • —User counting matters commercially: contractors, seasonal staff and service accounts on a per-user meter add up to a negotiation of their own.
  • —Coro is flagged unverified above 2,000 users; everything else here documents large estates.

Put this in your PoC

Get the Indian PoP city list, the log-residency commitment and the user-counting definition into the contract — all three in writing, before the discount conversation.

Zscaler, Netskope, Palo Alto, Fortinet, Check Point, Cisco, Cloudflare, Versa and Trend Micro document large estates; Coro Network & SASE is flagged unverified above 2,000 users. Where a specific platform strains for your user population: [TechBag to confirm].

The switching cost

Leaving a SASE platform means re-pointing every user and every application

The platform sits in the traffic path for everyone. Switching means new agents on every device, new tunnels from every site, and every private application re-published — while the old platform still carries production.

The agent on every device

A new agent pushed to every laptop and phone, with the old one removed in the right order. It is a device-management project before it is a security one.

Exit costRe-deploy, device by device

The private applications

Every published application, connector and access policy is rebuilt on the new platform and tested — including the awkward ones that needed a workaround the first time.

Exit costRe-publish and re-test

Certificates and inspection

The decryption trust chain is per platform: new certificates to every endpoint before inspection can work, or it silently stops working for someone.

Exit costNew trust chain first

The overlap

Both platforms run while users and sites cut over. Two per-user bills for a quarter is the honest cost of not breaking access for everyone at once.

Exit costTwo bills, one quarter

Agent rollout, application re-publishing and overlap cost for your estate: [TechBag to confirm] — TechBag scopes it from your device count, application inventory and contract dates.

What it costs

Per user per month — times the modules you actually need

What you may already hold, the platforms priced per user at three estate sizes in USD and INR, and what the subscription leaves out — which, during a transition, is the estate you are still paying for.

01

Do you already own one?

Four subscriptions that may already carry part of this. Two of them genuinely do.

Your existing NGFW subscription
Often Web filtering, DNS security and application control are frequently already in the bundle you renew — for traffic that comes back to your network. It does not follow the user, which is the whole point of SSE.
Microsoft Entra ID P1 / P2
Partly Conditional access decides whether a sign-in proceeds, based on device and risk. Real access control; no traffic inspection, no DLP on the wire, no web filtering.
Cloudflare's free tier
Partly Genuinely free for up to 50 users on Zero Trust, and real DNS ground beyond that. A legitimate starting point for a small estate, not an enterprise SSE.
Your endpoint vendor's web filtering
Partly Many endpoint agents filter web traffic on the device. It travels with the user, and it is thinner than a cloud gateway on inspection, CASB and DLP.

If what you already renew covers the traffic you were worried about, we say so. It costs us a sale and saves you one.

02

What the rest actually cost

Published and reported per-user meters (INR for scale), worked at three estate sizes per year. The mid-market and published-price options are covered explicitly — they are absent from every global comparison, and at 500 users they are the honest answer more often than the leaders are.

500users · per year
  • Cloudflare One(published $7 / user / mo beyond 50 free)$42,000 ≈₹34,86,000
  • FortiSASE(quoted; UK G-Cloud list £78–304 / user / yr by tier)Quote
  • Coro Network & SASE(published $10.50 / user / mo)$63,000 ≈₹52,29,000
  • Check Point Harmony SASE(from ~$10 / user / mo published plans)$60,000 ≈₹49,80,000
  • Zscaler ZIA(reported ~$6–12 / user / mo)$36,000–72,000 ≈₹29,88,000–₹59,76,000
  • Zscaler ZPA(reported ~$6–11 / user / mo, separate from ZIA)$36,000–66,000 ≈₹29,88,000–₹54,78,000
  • Netskope One SSE(fully-bundled reported ~$15+ / user / mo)$90,000 ≈₹74,70,000
  • Palo Alto Prisma AccessQuote
  • Cisco Secure AccessQuote
  • Versa SSEQuote
  • Trend Micro ZTSA(Vision One credits)Quote
5,000users · per year
  • Cloudflare One(published $7 / user / mo beyond 50 free)$4,20,000 ≈₹3,48,60,000
  • FortiSASE(quoted; UK G-Cloud list £78–304 / user / yr by tier)Quote
  • Coro Network & SASE(published $10.50 / user / mo)$6,30,000 ≈₹5,22,90,000
  • Check Point Harmony SASE(from ~$10 / user / mo published plans)$6,00,000 ≈₹4,98,00,000
  • Zscaler ZIA(reported ~$6–12 / user / mo)$3,60,000–7,20,000 ≈₹2,98,80,000–₹5,97,60,000
  • Zscaler ZPA(reported ~$6–11 / user / mo, separate from ZIA)$3,60,000–6,60,000 ≈₹2,98,80,000–₹5,47,80,000
  • Netskope One SSE(fully-bundled reported ~$15+ / user / mo)$9,00,000 ≈₹7,47,00,000
  • Palo Alto Prisma AccessQuote
  • Cisco Secure AccessQuote
  • Versa SSEQuote
  • Trend Micro ZTSA(Vision One credits)Quote
20,000users · per year
  • Cloudflare One(published $7 / user / mo beyond 50 free)$16,80,000 ≈₹13,94,40,000
  • FortiSASE(quoted; UK G-Cloud list £78–304 / user / yr by tier)Quote
  • Coro Network & SASE(published $10.50 / user / mo)$25,20,000 ≈₹20,91,60,000
  • Check Point Harmony SASE(from ~$10 / user / mo published plans)$24,00,000 ≈₹19,92,00,000
  • Zscaler ZIA(reported ~$6–12 / user / mo)$14,40,000–28,80,000 ≈₹11,95,20,000–₹23,90,40,000
  • Zscaler ZPA(reported ~$6–11 / user / mo, separate from ZIA)$14,40,000–26,40,000 ≈₹11,95,20,000–₹21,91,20,000
  • Netskope One SSE(fully-bundled reported ~$15+ / user / mo)$36,00,000 ≈₹29,88,00,000
  • Palo Alto Prisma AccessQuote
  • Cisco Secure AccessQuote
  • Versa SSEQuote
  • Trend Micro ZTSA(Vision One credits)Quote

The parallel run — stated apart, because no vendor will quote it

Both estates, at once. The firewall subscription keeps renewing while the SASE per-user bill starts. For a 5,000-user estate on a reported $15 per user per month, that is $900000 ≈ ₹7,47,00,000 a year arriving on top of an appliance estate that has not finished depreciating.
How long. Site-by-site cut-over is quarters, not weeks, and the last sites are always the awkward ones. Budget the overlap explicitly rather than assuming a clean switch date.
The reconciliation nobody does. Web filtering, DNS security and application control frequently exist in both estates simultaneously. Audit the overlap and switch things off deliberately — that is the saving the business case was promised.
Tier-match: the base tier is not the demo. Zscaler’s ZPA is a separate subscription from ZIA and ZDX is a third; CASB, DLP and browser isolation move up editions at several vendors; Cloudflare’s $7 tier is not Enterprise. Price the tier containing what you were shown.
Term-match: per user per month, billed annually, multi-year. Every meter here is per user per month with annual or three-year commitments and real volume discount. The grid normalises to a year at published or reported rates; your quote will not be either.
The India line. Netskope (eight data centres, Mumbai management plane), Cloudflare (six cities) and Palo Alto (Mumbai) document Indian presence; the rest are flagged. Indian quotes arrive in INR with GST through the channel. TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes.

TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale at ≈₹83/$; the tier-matched INR quote is ours.

03

What isn’t in the licence price

The estate you are still paying for

The unamortised appliances, their renewing subscriptions, and the quarters during which both bills arrive. This is the double-spend the category opens with, and it belongs in the business case as a line rather than a surprise.

Circuits, bandwidth and the certificate rollout

Breakout bandwidth at each site, the links themselves, and the TLS trust chain deployed to every endpoint before inspection works. None of it is in the per-user price; all of it is in the timeline.

The users who are not employees

Contractors, seasonal staff, partners and service accounts on a per-user meter. Ask how a user is counted and whether inactive users are billed, before the count moves. Your number: [TechBag to confirm].

Before you commit

What goes wrong

Documented platform behaviour and migration outcomes, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover after the cut-over.

PoP latency from Indian cities to the nearest node

Users in a city with no nearby point of presence route through another country and notice every day. Test from your actual offices before signing — and get the city list in the contract.

Discovering DLP and CASB are separate SKUs after signing

The demo showed data protection; the quoted tier was the web gateway. Read the module line items, not the platform name.

Running SASE and an unamortised firewall estate in parallel for three years

Two enforcement estates, overlapping capability, two bills, and a saving that never materialised because nobody switched the duplicates off.

User-based pricing that ignored contractors and service accounts

The employee count was the budget; the billable count included everyone who traversed the proxy. Define a user in the contract.

Logs stored outside India when the regulator asked otherwise

Traffic residency and log residency are different commitments — only one vendor here documents the second. Ask for both by name.

No way to prove where the slowness is

Without digital experience monitoring, every complaint is an argument between the network team and the platform vendor. Four products here document none.

Assuming SSE covers cloud workloads

It inspects user and application traffic; container runtime and cloud posture are CNAPP, on another guide. A scope error, not a product failure.

Buying the network half nobody needed

SD-WAN arrived in the bundle for an estate whose WAN was fine. Ask for the SSE-shaped configuration, explicitly, and compare it against the SASE quote.

Industry guides

Where IT & ITES firms are required to have this

Our IT & ITES guide maps CERT-In, DPDP, client contracts and buyers’ demands to the controls an Indian IT services, BPO or SaaS firm needs. This category answers:

Where retailers are required to have this

Our retail & e-commerce guide maps CERT-In, DPDP, PCI DSS and what gateways, marketplaces and ONDC demand to the controls a store chain or online seller needs. This category answers:

Three doors — pick by where you are

Researching

See the whole landscape and where each product sits.

Network Security & SASE map →

Evaluating

Get your shortlist scoped against your real estate.

Scope my shortlist →

Buying

Tier-matched USD + INR quote with GST.

Get a quote →

Vendor-neutral. No gated content.