Digital Trust · Research expansion in progress

Secure Access Service Edge (SASE) technology and investment research

Secure Access Service Edge SASE converges network security Secure Web Gateway, Cloud Access Security Broker, Zero Trust Network Access, Firewall as a Service with Software Defined Wide Area Networking SD WAN into a single cloud delivered…

Universe
Digital Trust
Layer
Zero Trust Security
Mapped
4 stocks
Editorial status
Research expansion in progress

Secure Access Service Edge SASE converges network security Secure Web Gateway, Cloud Access Security Broker, Zero Trust Network Access, Firewall as a Service with Software Defined Wide Area Networking SD WAN into a single cloud delivered service. SASE replaces the legacy architecture of backhauling all branch traffic through a data center firewall with a distributed cloud edge that inspects traffic close to the user and applies identity and context aware policies.

SASE requires global cloud infrastructure: points of presence PoPs in 150+ locations worldwide, sub 10ms latency for inline traffic inspection, and TLS decryption at line rate for all traffic. Building this infrastructure from scratch costs billions and takes years — the barrier to entry is capital, not software. Once an enterprise routes all its branch, remote user, and cloud traffic through a SASE provider's PoPs, switching means re architecting the entire global network topology. The convergence of networking and security into a single platform also creates a procurement bundling moat: CIOs increasingly buy…

Track protected users and traffic, application coverage, service reliability, policy consolidation and replacement of legacy network appliances.

Secure Access Service Edge (SASE): technology and investment research

427 words · Vault research updated Jul 27, 2026

Function

Secure Access Service Edge (SASE) converges network security (Secure Web Gateway, Cloud Access Security Broker, Zero Trust Network Access, Firewall-as-a-Service) with Software-Defined Wide Area Networking (SD-WAN) into a single cloud-delivered service. SASE replaces the legacy architecture of backhauling all branch traffic through a data center firewall with a distributed cloud edge that inspects traffic close to the user and applies identity-and-context-aware policies.

Why it's a bottleneck

SASE requires global cloud infrastructure: points of presence (PoPs) in 150+ locations worldwide, sub-10ms latency for inline traffic inspection, and TLS decryption at line rate for all traffic. Building this infrastructure from scratch costs billions and takes years — the barrier to entry is capital, not software. Once an enterprise routes all its branch, remote user, and cloud traffic through a SASE provider's PoPs, switching means re-architecting the entire global network topology. The convergence of networking and security into a single platform also creates a procurement bundling moat: CIOs increasingly buy "secure connectivity" as one SKU, not separate firewall + VPN + SD-WAN + SWG.

Companies

  • ZS — Zscaler; cloud-native SASE pioneer, Zero Trust Exchange, 150+ PoPs globally, $2.6B+ ARR
  • PANW — Prisma Access; SASE from the leader in NGFW, combining hardware install base with cloud delivery
  • NET — Cloudflare; Zero Trust network/SASE built on global edge network (300+ cities), fastest-growing SASE player
  • FTNT — Fortinet; SASE anchored by massive SD-WAN and firewall install base, ASIC-accelerated

Related technologies

  • Zero Trust Security Architecture — SASE is the network-delivery vehicle for Zero Trust principles
  • Endpoint Detection and Response (EDR-XDR) — SASE secures the network path; EDR secures the endpoint at origin and destination
  • Cloud-Native Application Protection (CNAPP) — CNAPP secures what runs in the cloud; SASE secures the path to it

Open questions

  • [ ] What is the SASE market share split between Zscaler (cloud-native), PANW (hardware-to-cloud transition), NET (edge-native), and FTNT (SD-WAN incumbent)?
  • [ ] Can Cloudflare's edge network (300+ cities, CDN heritage) outcompete Zscaler's purpose-built security PoPs on latency and feature depth?
  • [ ] Does the SASE convergence trend accelerate or slow — are enterprises buying SASE as a single SKU, or still procuring SD-WAN, ZTNA, and SWG separately?
  • [ ] What is the total SASE TAM and growth rate — Gartner's 2025 estimate vs. company-reported SASE-specific revenue?

Sources

2 cited sources from the research vault and public framework used to define this capability.

  1. NISTNIST Zero Trust Architecture, SP 800-207Open source ↗
  2. NISTNIST Cybersecurity Framework 2.0Open source ↗
01

Stocks mapped to this technology

Compare the current investment signal, conviction, target and research freshness for each stock.

02

Technology questions

Direct answers about the technology, its infrastructure layer and mapped public stocks.

What is Secure Access Service Edge (SASE)?

Secure Access Service Edge SASE converges network security Secure Web Gateway, Cloud Access Security Broker, Zero Trust Network Access, Firewall as a Service with Software Defined Wide Area Networking SD WAN into a single cloud delivered…

Which universe and layer is Secure Access Service Edge (SASE) mapped to?

Secure Access Service Edge (SASE) is mapped to Digital Trust across Zero Trust Security.

Which stocks are mapped to Secure Access Service Edge (SASE)?

Daily PXS currently maps 4 public stocks to Secure Access Service Edge (SASE), including FTNT, NET, PANW, ZS.