Most organisations buying SASE only need SSE — and are quoted for both.

SASE moves enforcement out of your rack and into a provider’s cloud, so policy applies wherever the user is. It has two halves: the security half (SSE — web gateway, CASB, ZTNA, DLP) and the network half (SD-WAN). Buying the second when your WAN is already fine is the most common overspend in this category.

Netskope documents eight data centres in India and a NewEdge management plane in Mumbai; Cloudflare’s Indian PoPs include Mumbai, Chennai, New Delhi, Bengaluru, Kolkata and Nagpur. Several major vendors publish no named Indian city list at all — and PoP distance decides user experience more than any feature.

Already decided — before the quote

Whether your WAN is a problemit decides SSE versus full SASE
Where your users actually sitPoP distance is the experience
What your regulator askedtraffic residency, and log residency

Still yours to weigh

Modulesbundled, or a second SKU
The meterper user, per site, per bandwidth
The parallel runwhile the appliances still live
If you’ve never bought one

What SASE and SSE actually are

A set of security controls delivered from a provider’s global network instead of a box in your building. The user’s device connects to the nearest point of presence, the provider inspects and enforces there — web filtering, malware inspection, data-loss rules, application access — and the traffic goes on to the internet or the private application without ever transiting your network. SSE is that security bundle. SASE is SSE plus SD-WAN, the network half that connects your sites.

Three things decide the purchase and only one is a feature comparison. Which half you need — most estates need SSE. PoP presence where your people actually are, because latency is the experience. What is genuinely bundled versus licensed separately, which is where quotes diverge from expectations. The appliance estate this replaces — and the overlap you will pay for twice during the transition — is the firewall guide.

The most common mis-purchase

Signing for SASE and discovering that DLP, CASB or browser isolation are separate SKUs — then running the new subscription alongside an unamortised firewall estate for three years. Ask which modules are in the base tier, and put the parallel-run cost in the business case before the purchase order.

Often confused withFirewall & Network Security — the estate this replaces, and the double-spend·Zero Trust Access — the ZTNA half, bought alone·Cloud & Workload Security — where SASE stops and CNAPP begins

The four routes of network security — and which one is yours

Boundary — the terms this buyer confuses

SASE vs SSE · single-vendor vs dual-vendor · what SSE excludes

One split that decides the price, one architectural choice, and one boundary buyers discover after signing. None of these is a maturity ladder.

SASE vs SSE

SSE is the security half: secure web gateway, CASB, ZTNA, DLP, and often firewall-as-a-service, delivered from the provider's cloud. SASE is SSE plus the network half — SD-WAN connecting your sites. If your WAN works and your problem is people and applications outside the building, SSE is the whole purchase. The quote will usually be for SASE.

Single-vendor vs dual-vendor SASE

Single-vendor means one policy model, one console, one negotiation — and one vendor's weakest module. Dual-vendor means best-of-breed SSE from one provider and SD-WAN from another, with two policy models to keep in step. Neither is more mature; the honest question is whether your team would rather run one console badly or two consoles well.

What SSE excludes

SSE inspects traffic to and from users and applications. It does not secure the workload itself — container runtime, cloud posture, identity entitlements in your cloud accounts are CNAPP and identity products, on other guides. It also does not replace east-west inspection inside a data centre. Buying SSE and assuming those cloud workloads are covered is a scope error, not a product failure — that ground is the Cloud & Workload Security guide under Security.

SASE is not 'firewall, evolved'

It is a different enforcement location with different failure modes. An appliance fails by running out of capacity; a SASE platform fails by PoP distance, an outage in someone else's cloud, or a module you did not license. Cost behaves differently too — subscription rather than refresh cycle — and the renewal trap is module creep rather than a hardware end-of-life.

These are not a maturity ladder. An estate with heavy site-to-site traffic and on-premises applications may be right to keep appliances; an estate whose people work from anywhere may be right to buy no appliance at all. The expensive middle — owning both, reconciling neither — is what the category page opens with, because no vendor will write it down.
The decision variables

Six things decide this purchase. The feature grid is none of them.

Eight variables decide this purchase. The instrument tests what documentation establishes (scope, modules, bundling, India PoPs and logs, experience monitoring, firewall lineage); real latency, contractor counting and the migration path are prose because they need measurement and a contract, not a datasheet.

01

SASE or SSE — do you need the network half

SD-WAN included, or the security half alone. The single largest difference between what buyers need and what they are quoted.

02

PoP presence and performance in India

The nearest point of presence decides user experience more than any feature on the datasheet. Documented by city for Netskope, Cloudflare and Palo Alto; not established for several major vendors — flagged, never assumed.

03

Single-vendor versus best-of-breed

One policy model and one weakest module, or two consoles and two contracts. An operating-model question, not a maturity one.

04

What is genuinely included versus licensed separately

SWG, CASB, ZTNA, DLP, browser isolation and firewall-as-a-service are bundled differently by every vendor. Zscaler's ZPA is a separate subscription from ZIA; Palo Alto, Fortinet, Check Point, Cisco and Versa bundle ZTNA into the base.

05

Digital experience monitoring

The capability that tells you whether the platform is working, and where it is not. Documented at Zscaler (as its own subscription), Netskope, Palo Alto, Cisco and Versa; absent at the others here.

06

Migration path from an existing firewall estate

Same vendor (Palo Alto, Fortinet, Check Point, Versa, Cisco, Trend) or a second vendor in parallel (Zscaler, Netskope, Cloudflare, Coro). It decides whether the transition is one policy model or two.

07

Data residency for inspected traffic and logs

Where traffic is decrypted and where the logs are stored are two separate questions. Only Netskope documents the second in India here.

08

Bandwidth-based versus user-based pricing

Per user is the norm and it meets contractors, seasonal staff and service accounts awkwardly; Versa's network half is per site. Ask how a user is counted and what happens when the count moves.

The narrowing instrument · the reasoning is the product

Narrow 16 products to your shortlist

Set what is true for you. A product that misses a constraint fades with its reason printed on it; where a vendor does not document Indian PoP cities or log residency it is flagged and stays, never eliminated on an absence of evidence. Every chip is reversible.

How much of it you need

What must be in it

Running it

Where you're coming from

Bundled, not billed twice

India

Estate size

Measured latency, contractor counting and migration effort are in the notes below rather than chips — the first needs a test from your own offices, and the others need a contract.

Still in16/ 16
Zscaler logo
~$6–12₹498

per user / month reported (roughly $72–325 per user / year by edition); the secure web gateway is the base and CASB, DLP, browser isolation and firewall-as-a-service are edition or add-on SKUs

Estates whose internet traffic should never touch their own network again — the reference proxy-based SSE, with the largest deployed footprint and the deepest inspection.

The catch: The base edition is the web gateway; DLP, CASB and browser isolation arrive as higher editions or add-ons, which is where quotes diverge from expectations. Zscaler sells no firewall, so a migration from an appliance estate means two vendors in parallel. Named Indian PoP cities are not established from the vendor's own documentation here — flagged.

Reference SSEEditions and add-onsNo firewall estate
Intel page →
Zscaler logo
~$6–11₹498

per user / month reported (ZPA Business roughly $4–7, Transformation roughly $7–11); the private-application half, sold alongside ZIA rather than inside it

Estates replacing remote-access VPN with per-application access — the most widely deployed ZTNA, and the reason many buyers arrive at Zscaler at all.

The catch: A separate subscription from ZIA: the combined bill is what most buyers actually pay, and it is rarely what they were first quoted. Server-initiated protocols need the Network Connector, an extra component to deploy.

ZTNA halfSeparate from ZIANetwork Connector for legacy
Intel page →
Zscaler logo

per user / month add-on; hop-by-hop visibility from the device through the PoP to the application — the product that tells you whether the SASE is actually working

Estates that have deployed SSE and now need to answer “is it the network, the PoP, or the application?” when a user complains.

The catch: Monitoring, not enforcement — it protects nothing. It is a third Zscaler subscription on top of ZIA and ZPA, and the case for it only becomes obvious after the first month of unexplained complaints.

Digital experience monitoringThird subscriptionNo enforcement
Intel page →
Zscaler logo

the platform bundle that combines ZIA, ZPA, ZDX and data protection — reported around $312,000 a year for 500 users on the Transformation edition, which is the number to reason from rather than any per-module list

Enterprises consolidating internet access, private access and experience monitoring under one platform and one negotiation.

The catch: Platform pricing is quoted, not listed, and the edition ladder decides what is included — the reported enterprise figures are large enough that a per-user comparison against point products is misleading. Still no firewall: the appliance estate remains someone else's.

The full platformEnterprise-pricedOne negotiation
Intel page →
Netskope logo
~$15+₹1,245

per user / month for a fully-bundled configuration (entry bundles list lower and rise through add-on modules); NewEdge carries eight data centres in India, and a NewEdge management plane in Mumbai supports DPDP-aligned data residency

Estates where data protection is the reason for the project — CASB and DLP are in the platform's DNA rather than bolted on — and where Indian data residency must be documented, not assumed.

The catch: Module creep is the pattern to watch: entry bundles look competitive and the fully-loaded per-user figure converges with Zscaler's. No firewall estate of its own, so an appliance migration runs in parallel with another vendor.

8 India data centresMumbai management planeCASB/DLP-first
Intel page →
Netskope logo
Per user

per user / month within the Netskope One platform; inline inspection of web and cloud application traffic with application-instance awareness rather than domain-level allow or block

Estates whose control requirement is by application instance — allow the corporate tenant, block the personal one — which domain-level filtering cannot express.

The catch: Instance awareness is the differentiator and the reason it is priced as a platform module rather than a cheap filter. DNS-layer-only estates will find this more product than they need — the secure web guide covers that end.

Instance-awareInline inspectionPlatform module
Intel page →
Palo Alto Networks logo
Palo Alto Prisma SASEPalo Alto Networks
Per user bundle

per user / year bundles combining Prisma Access with Prisma SD-WAN; a Mumbai cloud location has been documented since 2021, and Prisma Access falls back to India West for users who cannot connect in-country

Palo Alto firewall estates moving enforcement to the cloud without changing vendor, policy model or account team — the cleanest migration path on this page.

The catch: The full SASE bundle includes the network half you may not need; buying Prisma Access alone is the SSE-shaped purchase, and the quote will not default to it. Premium-priced, and the value assumes you adopt the platform.

True SASE (with SD-WAN)Mumbai locationFirewall migration path
Intel page →
Palo Alto Networks logo
Palo Alto Prisma AccessPalo Alto Networks
Per user

per user / year, quoted; the security half without SD-WAN — the same App-ID policy model as the firewall estate, delivered from Palo Alto's cloud

Estates that want the firewall's inspection model applied to users who never come back to the office, without buying the network half.

The catch: Still enterprise-priced, and the migration only feels seamless if you already run Palo Alto policy. In-country log storage for Indian buyers is not established from documentation — confirm in writing.

SSE-shapedSame policy as the NGFWIndia logs: unverified
Intel page →
Fortinet logo
$8–18₹664

per user / month list depending on bundle tier (roughly $90–350 per user / year in the 50–499 band); FortiGate customers receive Security Fabric pricing that reportedly saves 20–25%

FortiGate estates extending the same policy and console to remote users at the lowest published entry price on this page.

The catch: Digital experience monitoring is not a documented capability here, and named Indian PoP cities are not established from vendor documentation — both flagged rather than ruled out. The Fabric discount is real and it deepens the single-vendor commitment.

Lowest published entryFabric discountIndia PoPs: unverified
Intel page →
Check Point logo
From ~$10₹830

per user / month from published plans (roughly $15–40 per user / year at some tiers depending on feature set and protected applications); the former Perimeter 81, now integrated with Check Point's estate

Mid-market and distributed estates that want network-level access and web security quickly, with a Check Point firewall estate alongside.

The catch: Narrower module set than the SSE leaders — CASB and DLP depth are not its ground — and no documented digital experience monitoring. Indian PoP cities are not established from this vendor's own documentation.

Fast to deployNarrower modulesIndia PoPs: unverified
Intel page →
Cisco logo
Per user

per user / year, quoted; the successor to Umbrella's SIG tiers with ZTNA, and the natural extension for estates already running Cisco networking and Duo

Cisco estates consolidating Umbrella, VPN and firewall policy into one cloud service under an existing enterprise agreement.

The catch: Newer than Zscaler's and Netskope's platforms and carrying the Umbrella lineage; module depth varies by tier. Named Indian PoP cities are not established from vendor documentation — flagged, and worth asking for in writing given the latency stakes.

Umbrella lineageFits a Cisco EAIndia PoPs: unverified
Intel page →
Cloudflare logo
Free → $7₹581

free for up to 50 users, then $7 per user / month pay-as-you-go with no user cap; Enterprise adds expanded CASB, custom DLP, browser isolation, dedicated egress IPs and longer log retention — India PoPs include Mumbai, Chennai, New Delhi, Bengaluru, Kolkata and Nagpur

Estates that want real SSE capability at a published price they can start on today, on the largest Indian PoP footprint here.

The catch: The $7 tier is genuinely capable and genuinely not the enterprise product: DLP depth, CASB breadth and log retention move to Enterprise, which is quoted. No firewall estate, and no documented digital experience monitoring.

Published price6 India citiesEnterprise tier for depth
Intel page →
Versa Networks logo
Versa SASEVersa Networks
Per site / per user

subscription per site for the network half and per user for the security half; the same software runs the branch appliance, the data centre and the cloud PoP — often delivered in India through a carrier

Estates that want one software stack from branch to cloud, and are willing to buy it through a carrier-managed service.

The catch: Frequently reached through a carrier rather than directly, which changes who owns support and how fast policy changes move. Named Indian PoP cities are not established from Versa's own documentation.

One stack, branch to cloudOften carrier-deliveredIndia PoPs: unverified
Intel page →
Versa Networks logo
Versa SSEVersa Networks
Per user

per user / year for the security half alone, without committing to Versa's SD-WAN — the honest answer for estates that keep their existing network

Estates that want Versa's inspection and access controls without replacing the WAN they already run.

The catch: Smaller deployed footprint than Zscaler or Netskope in the SSE market specifically, and PoP presence in India is not documented by city. Support often sits with a partner.

SSE without the SD-WANSmaller SSE footprintIndia PoPs: unverified
Intel page →
Coro logo
$10.50₹872

per user / month published for the SASE module (Coro Essentials $10.50, Complete $15 unmanaged / $20 managed); individual modules from $4 per user / month on a modular platform built for the mid-market

SMB and mid-market estates that want network access, web security and endpoint protection on one modular per-user bill with no appliance.

The catch: Built for the mid-market and documented there: inspection depth, module breadth and enterprise controls are well behind the SSE leaders, and it is unverified above 2,000 users. No documented India PoP presence.

Published SMB priceModular platformMid-market scale
Intel page →
Trend Micro logo
Credits / quote

consumed as Vision One credits alongside Trend's other modules rather than as a standalone per-user list; risk signals from the endpoint and email products feed the access decision

Trend Vision One estates that want access decisions informed by the same risk score their endpoint and email products already produce.

The catch: Credit-based billing is opaque until you run it, and the SSE module set is narrower than the platform leaders'. Its value depends on running Trend elsewhere; India PoP presence is not documented.

Vision One creditsRisk-informed accessNarrower SSE
Intel page →
Why each constraint rules out what it doesShow the reasoning ↓

The security half onlyRules out Palo Alto Prisma SASE, Fortinet FortiSASE, Check Point Harmony SASE, Versa SASE and Coro Network & SASE — sold as full SASE including the network half; the SSE-shaped purchase is a different SKU from this vendor. That leaves Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Zscaler Zero Trust Exchange (platform), Netskope One SSE Platform, Netskope Next Gen SWG, Palo Alto Prisma Access, Cisco Secure Access, Cloudflare One (Zero Trust), Versa SSE and Trend Micro Zero Trust Secure Access.

SD-WAN includedRules out Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Zscaler Zero Trust Exchange (platform), Netskope One SSE Platform, Netskope Next Gen SWG, Palo Alto Prisma Access, Cisco Secure Access, Cloudflare One (Zero Trust), Versa SSE and Trend Micro Zero Trust Secure Access — security-only; SD-WAN comes from another product or another vendor. That leaves Palo Alto Prisma SASE, Fortinet FortiSASE, Check Point Harmony SASE, Versa SASE and Coro Network & SASE.

CASBRules out Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Palo Alto Prisma Access, Check Point Harmony SASE and Coro Network & SASE — CASB is not a documented capability of this product. That leaves Zscaler Internet Access (ZIA), Zscaler Zero Trust Exchange (platform), Netskope One SSE Platform, Netskope Next Gen SWG, Palo Alto Prisma SASE, Fortinet FortiSASE, Cisco Secure Access, Cloudflare One (Zero Trust), Versa SASE, Versa SSE and Trend Micro Zero Trust Secure Access.

DLPRules out Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Check Point Harmony SASE, Coro Network & SASE and Trend Micro Zero Trust Secure Access — DLP is not a documented capability of this product. That leaves Zscaler Internet Access (ZIA), Zscaler Zero Trust Exchange (platform), Netskope One SSE Platform, Netskope Next Gen SWG, Palo Alto Prisma SASE, Palo Alto Prisma Access, Fortinet FortiSASE, Cisco Secure Access, Cloudflare One (Zero Trust), Versa SASE and Versa SSE.

Browser isolationRules out Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Netskope Next Gen SWG, Fortinet FortiSASE, Check Point Harmony SASE, Cisco Secure Access, Versa SASE, Versa SSE, Coro Network & SASE and Trend Micro Zero Trust Secure Access — remote browser isolation is not a documented capability of this product. That leaves Zscaler Internet Access (ZIA), Zscaler Zero Trust Exchange (platform), Netskope One SSE Platform, Palo Alto Prisma SASE, Palo Alto Prisma Access and Cloudflare One (Zero Trust).

Firewall-as-a-serviceRules out Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Netskope One SSE Platform, Netskope Next Gen SWG, Cloudflare One (Zero Trust), Versa SSE and Trend Micro Zero Trust Secure Access — firewall-as-a-service is not a documented capability of this product. That leaves Zscaler Internet Access (ZIA), Zscaler Zero Trust Exchange (platform), Palo Alto Prisma SASE, Palo Alto Prisma Access, Fortinet FortiSASE, Check Point Harmony SASE, Cisco Secure Access, Versa SASE and Coro Network & SASE.

Experience monitoringRules out Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Netskope Next Gen SWG, Fortinet FortiSASE, Check Point Harmony SASE, Cloudflare One (Zero Trust), Coro Network & SASE and Trend Micro Zero Trust Secure Access — no documented digital experience monitoring; a slow user is a support ticket without evidence. That leaves Zscaler Digital Experience (ZDX), Zscaler Zero Trust Exchange (platform), Netskope One SSE Platform, Palo Alto Prisma SASE, Palo Alto Prisma Access, Cisco Secure Access, Versa SASE and Versa SSE.

Same vendor as the firewallRules out Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Zscaler Zero Trust Exchange (platform), Netskope One SSE Platform, Netskope Next Gen SWG, Cloudflare One (Zero Trust) and Coro Network & SASE — this vendor sells no firewall estate, so the migration runs two vendors in parallel. That leaves Palo Alto Prisma SASE, Palo Alto Prisma Access, Fortinet FortiSASE, Check Point Harmony SASE, Cisco Secure Access, Versa SASE, Versa SSE and Trend Micro Zero Trust Secure Access.

ZTNA in the base tierRules out Zscaler Internet Access (ZIA), Zscaler Digital Experience (ZDX) and Netskope Next Gen SWG — no ZTNA capability in this product; Netskope One SSE Platform — ZTNA exists but is a separate subscription or higher edition. That leaves Zscaler Private Access (ZPA), Zscaler Zero Trust Exchange (platform), Palo Alto Prisma SASE, Palo Alto Prisma Access, Fortinet FortiSASE, Check Point Harmony SASE, Cisco Secure Access, Cloudflare One (Zero Trust), Versa SASE, Versa SSE, Coro Network & SASE and Trend Micro Zero Trust Secure Access.

Named India PoPsRules nothing out on published terms. It flags Zscaler Internet Access (ZIA) — An India region is served but named PoP cities are not established from the vendor's own documentation, Zscaler Private Access (ZPA) — An India region is served but named PoP cities are not established from the vendor's own documentation, Zscaler Digital Experience (ZDX) — An India region is served but named PoP cities are not established from the vendor's own documentation, Zscaler Zero Trust Exchange (platform) — An India region is served but named PoP cities are not established from the vendor's own documentation, Fortinet FortiSASE — India PoP presence not established from vendor documentation, Check Point Harmony SASE — India PoP presence not established from vendor documentation, Cisco Secure Access — India PoP presence not established from vendor documentation, Versa SASE — India PoP presence not established from vendor documentation, Versa SSE — India PoP presence not established from vendor documentation, Coro Network & SASE — India PoP presence not established from vendor documentation and Trend Micro Zero Trust Secure Access — India PoP presence not established from vendor documentation — marked on the cards, not removed.

In-country logsRules nothing out on published terms. It flags Zscaler Internet Access (ZIA) — In-country log storage not established from documentation, Zscaler Private Access (ZPA) — In-country log storage not established from documentation, Zscaler Digital Experience (ZDX) — In-country log storage not established from documentation, Zscaler Zero Trust Exchange (platform) — In-country log storage not established from documentation, Palo Alto Prisma SASE — In-country log storage not established from documentation, Palo Alto Prisma Access — In-country log storage not established from documentation, Fortinet FortiSASE — In-country log storage not established from documentation, Check Point Harmony SASE — In-country log storage not established from documentation, Cisco Secure Access — In-country log storage not established from documentation, Cloudflare One (Zero Trust) — In-country log storage not established from documentation, Versa SASE — In-country log storage not established from documentation, Versa SSE — In-country log storage not established from documentation, Coro Network & SASE — In-country log storage not established from documentation and Trend Micro Zero Trust Secure Access — In-country log storage not established from documentation — marked on the cards, not removed.

Above 5,000 users on the platformRules nothing out on published terms. It flags Coro Network & SASE — Not documented at this platform size — marked on the cards, not removed.

Most buyers who say SASE mean SSESASE is the security half plus the network half (SD-WAN). SSE is the security half alone. If your WAN is fine and your problem is users and applications that left the building, you need SSE — and you will be quoted for SASE, because the bundle is larger. Zscaler, Netskope, Cloudflare and Cisco are SSE-shaped; Palo Alto, Fortinet, Check Point, Versa and Coro sell the fuller SASE, and Palo Alto and Versa also sell the SSE-shaped half separately. Ask which half you are being quoted, per line.

India PoP presence decides user experience more than any featureThe nearest PoP is the difference between a platform users forget about and one they route around. Documented here from vendor sources: Netskope carries eight data centres in India with a NewEdge management plane in Mumbai supporting DPDP-aligned residency; Cloudflare's Indian PoPs include Mumbai, Chennai, New Delhi, Bengaluru, Kolkata and Nagpur; Palo Alto has documented a Mumbai cloud location since 2021, with Prisma Access falling back to India West where in-country connection is unavailable. Zscaler serves the region but named Indian PoP cities are not established from its own documentation here; Fortinet, Check Point, Cisco, Versa, Coro and Trend Micro are not established either — all flagged, none ruled out. Ask for the city list and a latency test from your own offices before signing; real measured latency from Indian cities is delivery-team knowledge: [TechBag to confirm].

What is bundled, and what arrives as a separate SKUThis is where quotes diverge from expectations. Zscaler's base is the web gateway with CASB, DLP and browser isolation as editions or add-ons, and ZPA is a separate subscription from ZIA — the combined bill is what estates actually pay. Netskope bundles CASB with the gateway and adds modules upward. Palo Alto, Fortinet, Check Point, Cisco and Versa bundle ZTNA into the base tier. Coro is modular from $4 per user per month. Read the line items, not the platform name.

User-based pricing meets contractors and service accountsPer-user meters are simple until you count the people who are not employees: contractors, seasonal staff, partners, and the service accounts that also traverse the proxy. Ask how each vendor counts a user, whether inactive users are billed, and what happens when the number moves seasonally. Bandwidth-based and site-based meters (Versa's network half) behave differently again.

Under 500 usersNo published term excludes an estate this size: Cloudflare is free to 50 users and $7 per user per month beyond, Coro publishes $10.50 for its SASE module, and Fortinet's $8–18 band starts at 50 users. The platform leaders publish no floor but carry minimums through the channel — current minimums by vendor: [TechBag to confirm].

Narrow to your situation

Eight situations, eight shortlists — with the half named

Each shortlist states whether the answer is SSE or full SASE, and what the India question does to it. If your WAN is already fine, start from the first row.

The WAN is fine — it is the users and applications that left

Why: All three are SSE-shaped: security enforcement in the cloud without buying SD-WAN you do not need. Cloudflare publishes a price you can start on today; Netskope and Zscaler are the depth options.

The trade-off: You will be quoted SASE. Ask for the SSE-shaped configuration explicitly, line by line, and check whether ZTNA is inside the base tier or a second subscription.

Migrating off a firewall estate without changing vendor

Why: Same policy model, same console, same account team — Palo Alto's App-ID policy carries across, Fortinet gives FortiGate customers Security Fabric pricing worth a reported 20–25%, and Check Point extends the Quantum estate.

The trade-off: Single-vendor continuity makes the migration easier and the lock-in deeper. It also does not recover the appliance's book value — the parallel run is still real.

Indian data residency has to be documented, not assumed

Why: Netskope documents eight Indian data centres plus a Mumbai management plane for DPDP-aligned residency; Cloudflare documents six Indian PoP cities; Palo Alto documents a Mumbai cloud location.

The trade-off: PoP presence and log residency are different questions — only Netskope documents the second here. Get both in the contract, by name.

Data protection is the reason for the project

Why: Netskope's CASB and DLP are the platform's origin rather than an add-on; Zscaler's are higher editions; Cloudflare's arrive at Enterprise.

The trade-off: The cheapest quote in this row is rarely the one with the DLP depth demonstrated — confirm which edition the demo was on.

Users complain it is slow and nobody can prove where

Why: Digital experience monitoring answers whether it is the device, the link, the PoP or the application. Zscaler sells ZDX as its own subscription; Netskope, Cisco, Palo Alto and Versa document it inside the platform.

The trade-off: Zscaler's is a third subscription on top of ZIA and ZPA. Fortinet, Check Point, Cloudflare and Coro document none — a slow user stays a support ticket without evidence.

Mid-market, no appliance, one bill

Why: Coro publishes $10.50 per user per month for SASE on a modular platform; Cloudflare starts free to 50 users and $7 beyond; Harmony SASE deploys quickly for distributed teams.

The trade-off: Coro is unverified above 2,000 users and its inspection depth is well behind the leaders. Cheap and adequate is a legitimate answer — cheap and assumed-equivalent is not.

Branch connectivity and security together, one stack

Why: Versa runs the same software in the branch, the data centre and the PoP; Palo Alto pairs Prisma Access with Prisma SD-WAN; Fortinet extends the FortiGate estate.

The trade-off: Versa is frequently delivered through a carrier in India, which changes who owns support and how fast a policy change moves. Confirm the operating model, not just the technology.

Already inside a Cisco or Trend platform agreement

Why: Cisco Secure Access consolidates Umbrella, VPN and firewall policy under an existing enterprise agreement; Trend feeds endpoint and email risk into the access decision through Vision One credits.

The trade-off: Both carry narrower SSE module sets than the leaders, and neither documents Indian PoP cities. Credit-based billing at Trend is opaque until you run it.

The spine of the decision

Two halves, six modules, and the map that decides the experience

Place every quote on this grid before comparing prices: which half it covers, which modules are in the base tier, and where the nearest point of presence to your users actually is.

Half 1

SSE — the security half

Web gateway, CASB, ZTNA, DLP, often firewall-as-a-service, delivered from the provider's cloud. What most buyers actually need, and rarely what they are first quoted.

Half 2

SASE — plus the network

SSE with SD-WAN included: sites and users under one policy and one contract. Correct when the WAN is genuinely being replaced at the same time; expensive when it is not.

The India map

Documented PoP presence

Netskope: eight Indian data centres plus a Mumbai management plane for DPDP-aligned residency. Cloudflare: Mumbai, Chennai, New Delhi, Bengaluru, Kolkata, Nagpur. Palo Alto: a documented Mumbai cloud location since 2021. Everyone else here — ask for the city list in writing.

The second bill

Modules sold separately

Zscaler's ZPA is a separate subscription from ZIA and ZDX is a third; CASB, DLP and browser isolation move up editions at several vendors. Read the line items, not the platform name.

The PoP test

Ask these before the feature demo, in this order.

  • Name your Indian PoP cities. Not the region — the cities. Netskope, Cloudflare and Palo Alto document theirs; several major vendors on this page do not, and it is the question that decides whether users route around the platform.
  • Where is traffic decrypted, and where are the logs stored? Two different answers, and only one vendor here documents in-country log storage.
  • Which modules are in the tier you just demonstrated? Line by line: SWG, CASB, ZTNA, DLP, browser isolation, firewall-as-a-service.
  • How do you count a user? Contractors, seasonal staff, service accounts, and what happens when the number moves.

The double-spend

The line no vendor will put in your business case.

  • What it is: an unamortised firewall estate running alongside a SASE subscription, with overlapping capability nobody has reconciled. Both bills, for years, for one job.
  • Why it happens: the refresh cycle and the subscription decision are made by different people at different times, and every vendor is selling one side of it. Nobody is incentivised to write the sentence down.
  • What to do about it: put the parallel-run period in the business case explicitly — how many quarters, how many sites, both bills — and negotiate the appliance and the subscription in the same conversation, with the same vendor where possible.
  • Your number: [TechBag to confirm] — TechBag models it from your refresh dates, site count and user population.
What breaks as you grow

What changes at 500, 5,000 and 20,000 users

SASE scales by users and by PoP distance, and the second is invisible until it is not. The bill follows the per-user meter; the satisfaction follows the map.

500users

Published pricing is the constraint

  • Cloudflare ($7 per user per month beyond 50 free), Coro ($10.50 published for SASE) and Fortinet ($8–18 by tier) let you start without an enterprise negotiation.
  • One or two Indian offices means PoP distance is testable in an afternoon — do it before signing.
  • The module question is simpler here: most estates this size need the web gateway and ZTNA, not the full data-protection stack.

Put this in your PoC

Run a two-week pilot from your actual offices and measure page-load times against the current path. If it is slower, no feature list fixes it.

5,000users

Modules and the parallel run are the constraint

  • Module creep is now the pattern: entry bundles that looked competitive converge upward as CASB, DLP and browser isolation are added.
  • The firewall estate is still on the books — the parallel-run quarters belong in the business case, not in a surprise.
  • Digital experience monitoring stops being optional: at this size, unexplained slowness becomes a weekly meeting.

Put this in your PoC

Price the same estate three ways — SSE only, full SASE, and staying on appliances — over five years. If nobody has, the decision is being made blind.

20,000users

Residency and the operating model are the constraint

  • Traffic decryption location and log residency become regulator-visible; only Netskope documents in-country log storage here.
  • User counting matters commercially: contractors, seasonal staff and service accounts on a per-user meter add up to a negotiation of their own.
  • Coro is flagged unverified above 2,000 users; everything else here documents large estates.

Put this in your PoC

Get the Indian PoP city list, the log-residency commitment and the user-counting definition into the contract — all three in writing, before the discount conversation.

Zscaler, Netskope, Palo Alto, Fortinet, Check Point, Cisco, Cloudflare, Versa and Trend Micro document large estates; Coro Network & SASE is flagged unverified above 2,000 users. Where a specific platform strains for your user population: [TechBag to confirm].

The switching cost

Leaving a SASE platform means re-pointing every user and every application

The platform sits in the traffic path for everyone. Switching means new agents on every device, new tunnels from every site, and every private application re-published — while the old platform still carries production.

The agent on every device

A new agent pushed to every laptop and phone, with the old one removed in the right order. It is a device-management project before it is a security one.

Exit costRe-deploy, device by device

The private applications

Every published application, connector and access policy is rebuilt on the new platform and tested — including the awkward ones that needed a workaround the first time.

Exit costRe-publish and re-test

Certificates and inspection

The decryption trust chain is per platform: new certificates to every endpoint before inspection can work, or it silently stops working for someone.

Exit costNew trust chain first

The overlap

Both platforms run while users and sites cut over. Two per-user bills for a quarter is the honest cost of not breaking access for everyone at once.

Exit costTwo bills, one quarter

Agent rollout, application re-publishing and overlap cost for your estate: [TechBag to confirm] — TechBag scopes it from your device count, application inventory and contract dates.

What it costs

Per user per month — times the modules you actually need

What you may already hold, the platforms priced per user at three estate sizes in USD and INR, and what the subscription leaves out — which, during a transition, is the estate you are still paying for.

01

Do you already own one?

Four subscriptions that may already carry part of this. Two of them genuinely do.

Your existing NGFW subscription
Often Web filtering, DNS security and application control are frequently already in the bundle you renew — for traffic that comes back to your network. It does not follow the user, which is the whole point of SSE.
Microsoft Entra ID P1 / P2
Partly Conditional access decides whether a sign-in proceeds, based on device and risk. Real access control; no traffic inspection, no DLP on the wire, no web filtering.
Cloudflare's free tier
Partly Genuinely free for up to 50 users on Zero Trust, and real DNS ground beyond that. A legitimate starting point for a small estate, not an enterprise SSE.
Your endpoint vendor's web filtering
Partly Many endpoint agents filter web traffic on the device. It travels with the user, and it is thinner than a cloud gateway on inspection, CASB and DLP.

If what you already renew covers the traffic you were worried about, we say so. It costs us a sale and saves you one.

02

What the rest actually cost

Published and reported per-user meters (INR for scale), worked at three estate sizes per year. The mid-market and published-price options are covered explicitly — they are absent from every global comparison, and at 500 users they are the honest answer more often than the leaders are.

500users · per year
  • Cloudflare One(published $7 / user / mo beyond 50 free)$42,000 ₹34,86,000
  • FortiSASE(list $8–18 / user / mo by tier)$48,0001,08,000 ₹39,84,000₹89,64,000
  • Coro Network & SASE(published $10.50 / user / mo)$63,000 ₹52,29,000
  • Check Point Harmony SASE(from ~$10 / user / mo published plans)$60,000 ₹49,80,000
  • Zscaler ZIA(reported ~$6–12 / user / mo)$36,00072,000 ₹29,88,000₹59,76,000
  • Zscaler ZPA(reported ~$6–11 / user / mo, separate from ZIA)$36,00066,000 ₹29,88,000₹54,78,000
  • Netskope One SSE(fully-bundled reported ~$15+ / user / mo)$90,000 ₹74,70,000
  • Palo Alto Prisma AccessQuote
  • Cisco Secure AccessQuote
  • Versa SSEQuote
  • Trend Micro ZTSA(Vision One credits)Quote
5,000users · per year
  • Cloudflare One(published $7 / user / mo beyond 50 free)$4,20,000 ₹3,48,60,000
  • FortiSASE(list $8–18 / user / mo by tier)$4,80,00010,80,000 ₹3,98,40,000₹8,96,40,000
  • Coro Network & SASE(published $10.50 / user / mo)$6,30,000 ₹5,22,90,000
  • Check Point Harmony SASE(from ~$10 / user / mo published plans)$6,00,000 ₹4,98,00,000
  • Zscaler ZIA(reported ~$6–12 / user / mo)$3,60,0007,20,000 ₹2,98,80,000₹5,97,60,000
  • Zscaler ZPA(reported ~$6–11 / user / mo, separate from ZIA)$3,60,0006,60,000 ₹2,98,80,000₹5,47,80,000
  • Netskope One SSE(fully-bundled reported ~$15+ / user / mo)$9,00,000 ₹7,47,00,000
  • Palo Alto Prisma AccessQuote
  • Cisco Secure AccessQuote
  • Versa SSEQuote
  • Trend Micro ZTSA(Vision One credits)Quote
20,000users · per year
  • Cloudflare One(published $7 / user / mo beyond 50 free)$16,80,000 ₹13,94,40,000
  • FortiSASE(list $8–18 / user / mo by tier)$19,20,00043,20,000 ₹15,93,60,000₹35,85,60,000
  • Coro Network & SASE(published $10.50 / user / mo)$25,20,000 ₹20,91,60,000
  • Check Point Harmony SASE(from ~$10 / user / mo published plans)$24,00,000 ₹19,92,00,000
  • Zscaler ZIA(reported ~$6–12 / user / mo)$14,40,00028,80,000 ₹11,95,20,000₹23,90,40,000
  • Zscaler ZPA(reported ~$6–11 / user / mo, separate from ZIA)$14,40,00026,40,000 ₹11,95,20,000₹21,91,20,000
  • Netskope One SSE(fully-bundled reported ~$15+ / user / mo)$36,00,000 ₹29,88,00,000
  • Palo Alto Prisma AccessQuote
  • Cisco Secure AccessQuote
  • Versa SSEQuote
  • Trend Micro ZTSA(Vision One credits)Quote

The parallel run — stated apart, because no vendor will quote it

Both estates, at once. The firewall subscription keeps renewing while the SASE per-user bill starts. For a 5,000-user estate on a reported $15 per user per month, that is $900000 ≈ ₹7,47,00,000 a year arriving on top of an appliance estate that has not finished depreciating.
How long. Site-by-site cut-over is quarters, not weeks, and the last sites are always the awkward ones. Budget the overlap explicitly rather than assuming a clean switch date.
The reconciliation nobody does. Web filtering, DNS security and application control frequently exist in both estates simultaneously. Audit the overlap and switch things off deliberately — that is the saving the business case was promised.
Tier-match: the base tier is not the demo. Zscaler’s ZPA is a separate subscription from ZIA and ZDX is a third; CASB, DLP and browser isolation move up editions at several vendors; Cloudflare’s $7 tier is not Enterprise. Price the tier containing what you were shown.
Term-match: per user per month, billed annually, multi-year. Every meter here is per user per month with annual or three-year commitments and real volume discount. The grid normalises to a year at published or reported rates; your quote will not be either.
The India line. Netskope (eight data centres, Mumbai management plane), Cloudflare (six cities) and Palo Alto (Mumbai) document Indian presence; the rest are flagged. Indian quotes arrive in INR with GST through the channel. TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes.

TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale at ≈₹83/$; the tier-matched INR quote is ours.

03

What isn’t in the licence price

The estate you are still paying for

The unamortised appliances, their renewing subscriptions, and the quarters during which both bills arrive. This is the double-spend the category opens with, and it belongs in the business case as a line rather than a surprise.

Circuits, bandwidth and the certificate rollout

Breakout bandwidth at each site, the links themselves, and the TLS trust chain deployed to every endpoint before inspection works. None of it is in the per-user price; all of it is in the timeline.

The users who are not employees

Contractors, seasonal staff, partners and service accounts on a per-user meter. Ask how a user is counted and whether inactive users are billed, before the count moves. Your number: [TechBag to confirm].

Before you commit

What goes wrong

Documented platform behaviour and migration outcomes, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover after the cut-over.

PoP latency from Indian cities to the nearest node

Users in a city with no nearby point of presence route through another country and notice every day. Test from your actual offices before signing — and get the city list in the contract.

Discovering DLP and CASB are separate SKUs after signing

The demo showed data protection; the quoted tier was the web gateway. Read the module line items, not the platform name.

Running SASE and an unamortised firewall estate in parallel for three years

Two enforcement estates, overlapping capability, two bills, and a saving that never materialised because nobody switched the duplicates off.

User-based pricing that ignored contractors and service accounts

The employee count was the budget; the billable count included everyone who traversed the proxy. Define a user in the contract.

Logs stored outside India when the regulator asked otherwise

Traffic residency and log residency are different commitments — only one vendor here documents the second. Ask for both by name.

No way to prove where the slowness is

Without digital experience monitoring, every complaint is an argument between the network team and the platform vendor. Four products here document none.

Assuming SSE covers cloud workloads

It inspects user and application traffic; container runtime and cloud posture are CNAPP, on another guide. A scope error, not a product failure.

Buying the network half nobody needed

SD-WAN arrived in the bundle for an estate whose WAN was fine. Ask for the SSE-shaped configuration, explicitly, and compare it against the SASE quote.

Three doors — pick by where you are

Researching

See the whole landscape and where each product sits.

Network Security & SASE map →

Evaluating

Get your shortlist scoped against your real estate.

Scope my shortlist →

Buying

Tier-matched USD + INR quote with GST.

Get a quote →

Vendor-neutral. No gated content.