Endpoint Management
Backup & Cyber Resilience
Identity & Access
Network Security & SASE
SASE moves enforcement out of your rack and into a provider’s cloud, so policy applies wherever the user is. It has two halves: the security half (SSE — web gateway, CASB, ZTNA, DLP) and the network half (SD-WAN). Buying the second when your WAN is already fine is the most common overspend in this category.
Netskope documents eight data centres in India and a NewEdge management plane in Mumbai; Cloudflare’s Indian PoPs include Mumbai, Chennai, New Delhi, Bengaluru, Kolkata and Nagpur. Several major vendors publish no named Indian city list at all — and PoP distance decides user experience more than any feature.
Already decided — before the quote
Still yours to weigh
A set of security controls delivered from a provider’s global network instead of a box in your building. The user’s device connects to the nearest point of presence, the provider inspects and enforces there — web filtering, malware inspection, data-loss rules, application access — and the traffic goes on to the internet or the private application without ever transiting your network. SSE is that security bundle. SASE is SSE plus SD-WAN, the network half that connects your sites.
Three things decide the purchase and only one is a feature comparison. Which half you need — most estates need SSE. PoP presence where your people actually are, because latency is the experience. What is genuinely bundled versus licensed separately, which is where quotes diverge from expectations. The appliance estate this replaces — and the overlap you will pay for twice during the transition — is the firewall guide.
The most common mis-purchase
Signing for SASE and discovering that DLP, CASB or browser isolation are separate SKUs — then running the new subscription alongside an unamortised firewall estate for three years. Ask which modules are in the base tier, and put the parallel-run cost in the business case before the purchase order.
Often confused withFirewall & Network Security — the estate this replaces, and the double-spend →·Zero Trust Access — the ZTNA half, bought alone →·Cloud & Workload Security — where SASE stops and CNAPP begins →
The four routes of network security — and which one is yours →
One split that decides the price, one architectural choice, and one boundary buyers discover after signing. None of these is a maturity ladder.
SASE vs SSE
SSE is the security half: secure web gateway, CASB, ZTNA, DLP, and often firewall-as-a-service, delivered from the provider's cloud. SASE is SSE plus the network half — SD-WAN connecting your sites. If your WAN works and your problem is people and applications outside the building, SSE is the whole purchase. The quote will usually be for SASE.
Single-vendor vs dual-vendor SASE
Single-vendor means one policy model, one console, one negotiation — and one vendor's weakest module. Dual-vendor means best-of-breed SSE from one provider and SD-WAN from another, with two policy models to keep in step. Neither is more mature; the honest question is whether your team would rather run one console badly or two consoles well.
What SSE excludes
SSE inspects traffic to and from users and applications. It does not secure the workload itself — container runtime, cloud posture, identity entitlements in your cloud accounts are CNAPP and identity products, on other guides. It also does not replace east-west inspection inside a data centre. Buying SSE and assuming those cloud workloads are covered is a scope error, not a product failure — that ground is the Cloud & Workload Security guide under Security.
SASE is not 'firewall, evolved'
It is a different enforcement location with different failure modes. An appliance fails by running out of capacity; a SASE platform fails by PoP distance, an outage in someone else's cloud, or a module you did not license. Cost behaves differently too — subscription rather than refresh cycle — and the renewal trap is module creep rather than a hardware end-of-life.
Eight variables decide this purchase. The instrument tests what documentation establishes (scope, modules, bundling, India PoPs and logs, experience monitoring, firewall lineage); real latency, contractor counting and the migration path are prose because they need measurement and a contract, not a datasheet.
SASE or SSE — do you need the network half
SD-WAN included, or the security half alone. The single largest difference between what buyers need and what they are quoted.
PoP presence and performance in India
The nearest point of presence decides user experience more than any feature on the datasheet. Documented by city for Netskope, Cloudflare and Palo Alto; not established for several major vendors — flagged, never assumed.
Single-vendor versus best-of-breed
One policy model and one weakest module, or two consoles and two contracts. An operating-model question, not a maturity one.
What is genuinely included versus licensed separately
SWG, CASB, ZTNA, DLP, browser isolation and firewall-as-a-service are bundled differently by every vendor. Zscaler's ZPA is a separate subscription from ZIA; Palo Alto, Fortinet, Check Point, Cisco and Versa bundle ZTNA into the base.
Digital experience monitoring
The capability that tells you whether the platform is working, and where it is not. Documented at Zscaler (as its own subscription), Netskope, Palo Alto, Cisco and Versa; absent at the others here.
Migration path from an existing firewall estate
Same vendor (Palo Alto, Fortinet, Check Point, Versa, Cisco, Trend) or a second vendor in parallel (Zscaler, Netskope, Cloudflare, Coro). It decides whether the transition is one policy model or two.
Data residency for inspected traffic and logs
Where traffic is decrypted and where the logs are stored are two separate questions. Only Netskope documents the second in India here.
Bandwidth-based versus user-based pricing
Per user is the norm and it meets contractors, seasonal staff and service accounts awkwardly; Versa's network half is per site. Ask how a user is counted and what happens when the count moves.
Set what is true for you. A product that misses a constraint fades with its reason printed on it; where a vendor does not document Indian PoP cities or log residency it is flagged and stays, never eliminated on an absence of evidence. Every chip is reversible.
How much of it you need
What must be in it
Running it
Where you're coming from
Bundled, not billed twice
India
Estate size
Measured latency, contractor counting and migration effort are in the notes below rather than chips — the first needs a test from your own offices, and the others need a contract.

per user / month reported (roughly $72–325 per user / year by edition); the secure web gateway is the base and CASB, DLP, browser isolation and firewall-as-a-service are edition or add-on SKUs
Estates whose internet traffic should never touch their own network again — the reference proxy-based SSE, with the largest deployed footprint and the deepest inspection.
The catch: The base edition is the web gateway; DLP, CASB and browser isolation arrive as higher editions or add-ons, which is where quotes diverge from expectations. Zscaler sells no firewall, so a migration from an appliance estate means two vendors in parallel. Named Indian PoP cities are not established from the vendor's own documentation here — flagged.

per user / month reported (ZPA Business roughly $4–7, Transformation roughly $7–11); the private-application half, sold alongside ZIA rather than inside it
Estates replacing remote-access VPN with per-application access — the most widely deployed ZTNA, and the reason many buyers arrive at Zscaler at all.
The catch: A separate subscription from ZIA: the combined bill is what most buyers actually pay, and it is rarely what they were first quoted. Server-initiated protocols need the Network Connector, an extra component to deploy.

per user / month add-on; hop-by-hop visibility from the device through the PoP to the application — the product that tells you whether the SASE is actually working
Estates that have deployed SSE and now need to answer “is it the network, the PoP, or the application?” when a user complains.
The catch: Monitoring, not enforcement — it protects nothing. It is a third Zscaler subscription on top of ZIA and ZPA, and the case for it only becomes obvious after the first month of unexplained complaints.

the platform bundle that combines ZIA, ZPA, ZDX and data protection — reported around $312,000 a year for 500 users on the Transformation edition, which is the number to reason from rather than any per-module list
Enterprises consolidating internet access, private access and experience monitoring under one platform and one negotiation.
The catch: Platform pricing is quoted, not listed, and the edition ladder decides what is included — the reported enterprise figures are large enough that a per-user comparison against point products is misleading. Still no firewall: the appliance estate remains someone else's.

per user / month for a fully-bundled configuration (entry bundles list lower and rise through add-on modules); NewEdge carries eight data centres in India, and a NewEdge management plane in Mumbai supports DPDP-aligned data residency
Estates where data protection is the reason for the project — CASB and DLP are in the platform's DNA rather than bolted on — and where Indian data residency must be documented, not assumed.
The catch: Module creep is the pattern to watch: entry bundles look competitive and the fully-loaded per-user figure converges with Zscaler's. No firewall estate of its own, so an appliance migration runs in parallel with another vendor.

per user / month within the Netskope One platform; inline inspection of web and cloud application traffic with application-instance awareness rather than domain-level allow or block
Estates whose control requirement is by application instance — allow the corporate tenant, block the personal one — which domain-level filtering cannot express.
The catch: Instance awareness is the differentiator and the reason it is priced as a platform module rather than a cheap filter. DNS-layer-only estates will find this more product than they need — the secure web guide covers that end.

per user / year bundles combining Prisma Access with Prisma SD-WAN; a Mumbai cloud location has been documented since 2021, and Prisma Access falls back to India West for users who cannot connect in-country
Palo Alto firewall estates moving enforcement to the cloud without changing vendor, policy model or account team — the cleanest migration path on this page.
The catch: The full SASE bundle includes the network half you may not need; buying Prisma Access alone is the SSE-shaped purchase, and the quote will not default to it. Premium-priced, and the value assumes you adopt the platform.

per user / year, quoted; the security half without SD-WAN — the same App-ID policy model as the firewall estate, delivered from Palo Alto's cloud
Estates that want the firewall's inspection model applied to users who never come back to the office, without buying the network half.
The catch: Still enterprise-priced, and the migration only feels seamless if you already run Palo Alto policy. In-country log storage for Indian buyers is not established from documentation — confirm in writing.

per user / month list depending on bundle tier (roughly $90–350 per user / year in the 50–499 band); FortiGate customers receive Security Fabric pricing that reportedly saves 20–25%
FortiGate estates extending the same policy and console to remote users at the lowest published entry price on this page.
The catch: Digital experience monitoring is not a documented capability here, and named Indian PoP cities are not established from vendor documentation — both flagged rather than ruled out. The Fabric discount is real and it deepens the single-vendor commitment.

per user / month from published plans (roughly $15–40 per user / year at some tiers depending on feature set and protected applications); the former Perimeter 81, now integrated with Check Point's estate
Mid-market and distributed estates that want network-level access and web security quickly, with a Check Point firewall estate alongside.
The catch: Narrower module set than the SSE leaders — CASB and DLP depth are not its ground — and no documented digital experience monitoring. Indian PoP cities are not established from this vendor's own documentation.

per user / year, quoted; the successor to Umbrella's SIG tiers with ZTNA, and the natural extension for estates already running Cisco networking and Duo
Cisco estates consolidating Umbrella, VPN and firewall policy into one cloud service under an existing enterprise agreement.
The catch: Newer than Zscaler's and Netskope's platforms and carrying the Umbrella lineage; module depth varies by tier. Named Indian PoP cities are not established from vendor documentation — flagged, and worth asking for in writing given the latency stakes.

free for up to 50 users, then $7 per user / month pay-as-you-go with no user cap; Enterprise adds expanded CASB, custom DLP, browser isolation, dedicated egress IPs and longer log retention — India PoPs include Mumbai, Chennai, New Delhi, Bengaluru, Kolkata and Nagpur
Estates that want real SSE capability at a published price they can start on today, on the largest Indian PoP footprint here.
The catch: The $7 tier is genuinely capable and genuinely not the enterprise product: DLP depth, CASB breadth and log retention move to Enterprise, which is quoted. No firewall estate, and no documented digital experience monitoring.

subscription per site for the network half and per user for the security half; the same software runs the branch appliance, the data centre and the cloud PoP — often delivered in India through a carrier
Estates that want one software stack from branch to cloud, and are willing to buy it through a carrier-managed service.
The catch: Frequently reached through a carrier rather than directly, which changes who owns support and how fast policy changes move. Named Indian PoP cities are not established from Versa's own documentation.

per user / year for the security half alone, without committing to Versa's SD-WAN — the honest answer for estates that keep their existing network
Estates that want Versa's inspection and access controls without replacing the WAN they already run.
The catch: Smaller deployed footprint than Zscaler or Netskope in the SSE market specifically, and PoP presence in India is not documented by city. Support often sits with a partner.

per user / month published for the SASE module (Coro Essentials $10.50, Complete $15 unmanaged / $20 managed); individual modules from $4 per user / month on a modular platform built for the mid-market
SMB and mid-market estates that want network access, web security and endpoint protection on one modular per-user bill with no appliance.
The catch: Built for the mid-market and documented there: inspection depth, module breadth and enterprise controls are well behind the SSE leaders, and it is unverified above 2,000 users. No documented India PoP presence.
consumed as Vision One credits alongside Trend's other modules rather than as a standalone per-user list; risk signals from the endpoint and email products feed the access decision
Trend Vision One estates that want access decisions informed by the same risk score their endpoint and email products already produce.
The catch: Credit-based billing is opaque until you run it, and the SSE module set is narrower than the platform leaders'. Its value depends on running Trend elsewhere; India PoP presence is not documented.
The security half onlyRules out Palo Alto Prisma SASE, Fortinet FortiSASE, Check Point Harmony SASE, Versa SASE and Coro Network & SASE — sold as full SASE including the network half; the SSE-shaped purchase is a different SKU from this vendor. That leaves Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Zscaler Zero Trust Exchange (platform), Netskope One SSE Platform, Netskope Next Gen SWG, Palo Alto Prisma Access, Cisco Secure Access, Cloudflare One (Zero Trust), Versa SSE and Trend Micro Zero Trust Secure Access.
SD-WAN includedRules out Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Zscaler Zero Trust Exchange (platform), Netskope One SSE Platform, Netskope Next Gen SWG, Palo Alto Prisma Access, Cisco Secure Access, Cloudflare One (Zero Trust), Versa SSE and Trend Micro Zero Trust Secure Access — security-only; SD-WAN comes from another product or another vendor. That leaves Palo Alto Prisma SASE, Fortinet FortiSASE, Check Point Harmony SASE, Versa SASE and Coro Network & SASE.
CASBRules out Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Palo Alto Prisma Access, Check Point Harmony SASE and Coro Network & SASE — CASB is not a documented capability of this product. That leaves Zscaler Internet Access (ZIA), Zscaler Zero Trust Exchange (platform), Netskope One SSE Platform, Netskope Next Gen SWG, Palo Alto Prisma SASE, Fortinet FortiSASE, Cisco Secure Access, Cloudflare One (Zero Trust), Versa SASE, Versa SSE and Trend Micro Zero Trust Secure Access.
DLPRules out Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Check Point Harmony SASE, Coro Network & SASE and Trend Micro Zero Trust Secure Access — DLP is not a documented capability of this product. That leaves Zscaler Internet Access (ZIA), Zscaler Zero Trust Exchange (platform), Netskope One SSE Platform, Netskope Next Gen SWG, Palo Alto Prisma SASE, Palo Alto Prisma Access, Fortinet FortiSASE, Cisco Secure Access, Cloudflare One (Zero Trust), Versa SASE and Versa SSE.
Browser isolationRules out Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Netskope Next Gen SWG, Fortinet FortiSASE, Check Point Harmony SASE, Cisco Secure Access, Versa SASE, Versa SSE, Coro Network & SASE and Trend Micro Zero Trust Secure Access — remote browser isolation is not a documented capability of this product. That leaves Zscaler Internet Access (ZIA), Zscaler Zero Trust Exchange (platform), Netskope One SSE Platform, Palo Alto Prisma SASE, Palo Alto Prisma Access and Cloudflare One (Zero Trust).
Firewall-as-a-serviceRules out Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Netskope One SSE Platform, Netskope Next Gen SWG, Cloudflare One (Zero Trust), Versa SSE and Trend Micro Zero Trust Secure Access — firewall-as-a-service is not a documented capability of this product. That leaves Zscaler Internet Access (ZIA), Zscaler Zero Trust Exchange (platform), Palo Alto Prisma SASE, Palo Alto Prisma Access, Fortinet FortiSASE, Check Point Harmony SASE, Cisco Secure Access, Versa SASE and Coro Network & SASE.
Experience monitoringRules out Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Netskope Next Gen SWG, Fortinet FortiSASE, Check Point Harmony SASE, Cloudflare One (Zero Trust), Coro Network & SASE and Trend Micro Zero Trust Secure Access — no documented digital experience monitoring; a slow user is a support ticket without evidence. That leaves Zscaler Digital Experience (ZDX), Zscaler Zero Trust Exchange (platform), Netskope One SSE Platform, Palo Alto Prisma SASE, Palo Alto Prisma Access, Cisco Secure Access, Versa SASE and Versa SSE.
Same vendor as the firewallRules out Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Zscaler Zero Trust Exchange (platform), Netskope One SSE Platform, Netskope Next Gen SWG, Cloudflare One (Zero Trust) and Coro Network & SASE — this vendor sells no firewall estate, so the migration runs two vendors in parallel. That leaves Palo Alto Prisma SASE, Palo Alto Prisma Access, Fortinet FortiSASE, Check Point Harmony SASE, Cisco Secure Access, Versa SASE, Versa SSE and Trend Micro Zero Trust Secure Access.
ZTNA in the base tierRules out Zscaler Internet Access (ZIA), Zscaler Digital Experience (ZDX) and Netskope Next Gen SWG — no ZTNA capability in this product; Netskope One SSE Platform — ZTNA exists but is a separate subscription or higher edition. That leaves Zscaler Private Access (ZPA), Zscaler Zero Trust Exchange (platform), Palo Alto Prisma SASE, Palo Alto Prisma Access, Fortinet FortiSASE, Check Point Harmony SASE, Cisco Secure Access, Cloudflare One (Zero Trust), Versa SASE, Versa SSE, Coro Network & SASE and Trend Micro Zero Trust Secure Access.
Named India PoPsRules nothing out on published terms. It flags Zscaler Internet Access (ZIA) — An India region is served but named PoP cities are not established from the vendor's own documentation, Zscaler Private Access (ZPA) — An India region is served but named PoP cities are not established from the vendor's own documentation, Zscaler Digital Experience (ZDX) — An India region is served but named PoP cities are not established from the vendor's own documentation, Zscaler Zero Trust Exchange (platform) — An India region is served but named PoP cities are not established from the vendor's own documentation, Fortinet FortiSASE — India PoP presence not established from vendor documentation, Check Point Harmony SASE — India PoP presence not established from vendor documentation, Cisco Secure Access — India PoP presence not established from vendor documentation, Versa SASE — India PoP presence not established from vendor documentation, Versa SSE — India PoP presence not established from vendor documentation, Coro Network & SASE — India PoP presence not established from vendor documentation and Trend Micro Zero Trust Secure Access — India PoP presence not established from vendor documentation — marked on the cards, not removed.
In-country logsRules nothing out on published terms. It flags Zscaler Internet Access (ZIA) — In-country log storage not established from documentation, Zscaler Private Access (ZPA) — In-country log storage not established from documentation, Zscaler Digital Experience (ZDX) — In-country log storage not established from documentation, Zscaler Zero Trust Exchange (platform) — In-country log storage not established from documentation, Palo Alto Prisma SASE — In-country log storage not established from documentation, Palo Alto Prisma Access — In-country log storage not established from documentation, Fortinet FortiSASE — In-country log storage not established from documentation, Check Point Harmony SASE — In-country log storage not established from documentation, Cisco Secure Access — In-country log storage not established from documentation, Cloudflare One (Zero Trust) — In-country log storage not established from documentation, Versa SASE — In-country log storage not established from documentation, Versa SSE — In-country log storage not established from documentation, Coro Network & SASE — In-country log storage not established from documentation and Trend Micro Zero Trust Secure Access — In-country log storage not established from documentation — marked on the cards, not removed.
Above 5,000 users on the platformRules nothing out on published terms. It flags Coro Network & SASE — Not documented at this platform size — marked on the cards, not removed.
Most buyers who say SASE mean SSESASE is the security half plus the network half (SD-WAN). SSE is the security half alone. If your WAN is fine and your problem is users and applications that left the building, you need SSE — and you will be quoted for SASE, because the bundle is larger. Zscaler, Netskope, Cloudflare and Cisco are SSE-shaped; Palo Alto, Fortinet, Check Point, Versa and Coro sell the fuller SASE, and Palo Alto and Versa also sell the SSE-shaped half separately. Ask which half you are being quoted, per line.
India PoP presence decides user experience more than any featureThe nearest PoP is the difference between a platform users forget about and one they route around. Documented here from vendor sources: Netskope carries eight data centres in India with a NewEdge management plane in Mumbai supporting DPDP-aligned residency; Cloudflare's Indian PoPs include Mumbai, Chennai, New Delhi, Bengaluru, Kolkata and Nagpur; Palo Alto has documented a Mumbai cloud location since 2021, with Prisma Access falling back to India West where in-country connection is unavailable. Zscaler serves the region but named Indian PoP cities are not established from its own documentation here; Fortinet, Check Point, Cisco, Versa, Coro and Trend Micro are not established either — all flagged, none ruled out. Ask for the city list and a latency test from your own offices before signing; real measured latency from Indian cities is delivery-team knowledge: [TechBag to confirm].
What is bundled, and what arrives as a separate SKUThis is where quotes diverge from expectations. Zscaler's base is the web gateway with CASB, DLP and browser isolation as editions or add-ons, and ZPA is a separate subscription from ZIA — the combined bill is what estates actually pay. Netskope bundles CASB with the gateway and adds modules upward. Palo Alto, Fortinet, Check Point, Cisco and Versa bundle ZTNA into the base tier. Coro is modular from $4 per user per month. Read the line items, not the platform name.
User-based pricing meets contractors and service accountsPer-user meters are simple until you count the people who are not employees: contractors, seasonal staff, partners, and the service accounts that also traverse the proxy. Ask how each vendor counts a user, whether inactive users are billed, and what happens when the number moves seasonally. Bandwidth-based and site-based meters (Versa's network half) behave differently again.
Under 500 usersNo published term excludes an estate this size: Cloudflare is free to 50 users and $7 per user per month beyond, Coro publishes $10.50 for its SASE module, and Fortinet's $8–18 band starts at 50 users. The platform leaders publish no floor but carry minimums through the channel — current minimums by vendor: [TechBag to confirm].
Each shortlist states whether the answer is SSE or full SASE, and what the India question does to it. If your WAN is already fine, start from the first row.
Why: All three are SSE-shaped: security enforcement in the cloud without buying SD-WAN you do not need. Cloudflare publishes a price you can start on today; Netskope and Zscaler are the depth options.
The trade-off: You will be quoted SASE. Ask for the SSE-shaped configuration explicitly, line by line, and check whether ZTNA is inside the base tier or a second subscription.
Why: Same policy model, same console, same account team — Palo Alto's App-ID policy carries across, Fortinet gives FortiGate customers Security Fabric pricing worth a reported 20–25%, and Check Point extends the Quantum estate.
The trade-off: Single-vendor continuity makes the migration easier and the lock-in deeper. It also does not recover the appliance's book value — the parallel run is still real.
Why: Netskope documents eight Indian data centres plus a Mumbai management plane for DPDP-aligned residency; Cloudflare documents six Indian PoP cities; Palo Alto documents a Mumbai cloud location.
The trade-off: PoP presence and log residency are different questions — only Netskope documents the second here. Get both in the contract, by name.
Why: Netskope's CASB and DLP are the platform's origin rather than an add-on; Zscaler's are higher editions; Cloudflare's arrive at Enterprise.
The trade-off: The cheapest quote in this row is rarely the one with the DLP depth demonstrated — confirm which edition the demo was on.
Why: Digital experience monitoring answers whether it is the device, the link, the PoP or the application. Zscaler sells ZDX as its own subscription; Netskope, Cisco, Palo Alto and Versa document it inside the platform.
The trade-off: Zscaler's is a third subscription on top of ZIA and ZPA. Fortinet, Check Point, Cloudflare and Coro document none — a slow user stays a support ticket without evidence.
Why: Coro publishes $10.50 per user per month for SASE on a modular platform; Cloudflare starts free to 50 users and $7 beyond; Harmony SASE deploys quickly for distributed teams.
The trade-off: Coro is unverified above 2,000 users and its inspection depth is well behind the leaders. Cheap and adequate is a legitimate answer — cheap and assumed-equivalent is not.
Why: Versa runs the same software in the branch, the data centre and the PoP; Palo Alto pairs Prisma Access with Prisma SD-WAN; Fortinet extends the FortiGate estate.
The trade-off: Versa is frequently delivered through a carrier in India, which changes who owns support and how fast a policy change moves. Confirm the operating model, not just the technology.
Why: Cisco Secure Access consolidates Umbrella, VPN and firewall policy under an existing enterprise agreement; Trend feeds endpoint and email risk into the access decision through Vision One credits.
The trade-off: Both carry narrower SSE module sets than the leaders, and neither documents Indian PoP cities. Credit-based billing at Trend is opaque until you run it.
Place every quote on this grid before comparing prices: which half it covers, which modules are in the base tier, and where the nearest point of presence to your users actually is.
Half 1
SSE — the security half
Web gateway, CASB, ZTNA, DLP, often firewall-as-a-service, delivered from the provider's cloud. What most buyers actually need, and rarely what they are first quoted.
Half 2
SASE — plus the network
SSE with SD-WAN included: sites and users under one policy and one contract. Correct when the WAN is genuinely being replaced at the same time; expensive when it is not.
The India map
Documented PoP presence
Netskope: eight Indian data centres plus a Mumbai management plane for DPDP-aligned residency. Cloudflare: Mumbai, Chennai, New Delhi, Bengaluru, Kolkata, Nagpur. Palo Alto: a documented Mumbai cloud location since 2021. Everyone else here — ask for the city list in writing.
The second bill
Modules sold separately
Zscaler's ZPA is a separate subscription from ZIA and ZDX is a third; CASB, DLP and browser isolation move up editions at several vendors. Read the line items, not the platform name.
The PoP test
Ask these before the feature demo, in this order.
The double-spend
The line no vendor will put in your business case.
SASE scales by users and by PoP distance, and the second is invisible until it is not. The bill follows the per-user meter; the satisfaction follows the map.
Published pricing is the constraint
Put this in your PoC
Run a two-week pilot from your actual offices and measure page-load times against the current path. If it is slower, no feature list fixes it.
Modules and the parallel run are the constraint
Put this in your PoC
Price the same estate three ways — SSE only, full SASE, and staying on appliances — over five years. If nobody has, the decision is being made blind.
Residency and the operating model are the constraint
Put this in your PoC
Get the Indian PoP city list, the log-residency commitment and the user-counting definition into the contract — all three in writing, before the discount conversation.
Zscaler, Netskope, Palo Alto, Fortinet, Check Point, Cisco, Cloudflare, Versa and Trend Micro document large estates; Coro Network & SASE is flagged unverified above 2,000 users. Where a specific platform strains for your user population: [TechBag to confirm].
The platform sits in the traffic path for everyone. Switching means new agents on every device, new tunnels from every site, and every private application re-published — while the old platform still carries production.
The agent on every device
A new agent pushed to every laptop and phone, with the old one removed in the right order. It is a device-management project before it is a security one.
The private applications
Every published application, connector and access policy is rebuilt on the new platform and tested — including the awkward ones that needed a workaround the first time.
Certificates and inspection
The decryption trust chain is per platform: new certificates to every endpoint before inspection can work, or it silently stops working for someone.
The overlap
Both platforms run while users and sites cut over. Two per-user bills for a quarter is the honest cost of not breaking access for everyone at once.
Agent rollout, application re-publishing and overlap cost for your estate: [TechBag to confirm] — TechBag scopes it from your device count, application inventory and contract dates.
What you may already hold, the platforms priced per user at three estate sizes in USD and INR, and what the subscription leaves out — which, during a transition, is the estate you are still paying for.
Four subscriptions that may already carry part of this. Two of them genuinely do.
If what you already renew covers the traffic you were worried about, we say so. It costs us a sale and saves you one.
Published and reported per-user meters (INR for scale), worked at three estate sizes per year. The mid-market and published-price options are covered explicitly — they are absent from every global comparison, and at 500 users they are the honest answer more often than the leaders are.
The parallel run — stated apart, because no vendor will quote it
TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale at ≈₹83/$; the tier-matched INR quote is ours.
The unamortised appliances, their renewing subscriptions, and the quarters during which both bills arrive. This is the double-spend the category opens with, and it belongs in the business case as a line rather than a surprise.
Breakout bandwidth at each site, the links themselves, and the TLS trust chain deployed to every endpoint before inspection works. None of it is in the per-user price; all of it is in the timeline.
Contractors, seasonal staff, partners and service accounts on a per-user meter. Ask how a user is counted and whether inactive users are billed, before the count moves. Your number: [TechBag to confirm].
Documented platform behaviour and migration outcomes, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover after the cut-over.
PoP latency from Indian cities to the nearest node
Users in a city with no nearby point of presence route through another country and notice every day. Test from your actual offices before signing — and get the city list in the contract.
Discovering DLP and CASB are separate SKUs after signing
The demo showed data protection; the quoted tier was the web gateway. Read the module line items, not the platform name.
Running SASE and an unamortised firewall estate in parallel for three years
Two enforcement estates, overlapping capability, two bills, and a saving that never materialised because nobody switched the duplicates off.
User-based pricing that ignored contractors and service accounts
The employee count was the budget; the billable count included everyone who traversed the proxy. Define a user in the contract.
Logs stored outside India when the regulator asked otherwise
Traffic residency and log residency are different commitments — only one vendor here documents the second. Ask for both by name.
No way to prove where the slowness is
Without digital experience monitoring, every complaint is an argument between the network team and the platform vendor. Four products here document none.
Assuming SSE covers cloud workloads
It inspects user and application traffic; container runtime and cloud posture are CNAPP, on another guide. A scope error, not a product failure.
Buying the network half nobody needed
SD-WAN arrived in the bundle for an estate whose WAN was fine. Ask for the SSE-shaped configuration, explicitly, and compare it against the SASE quote.
Vendor-neutral. No gated content.