For a global enterprise replacing MPLS, I’d put Palo Alto Networks Prisma SASE, Cato SASE, Netskope, Fortinet, and Zscaler into the final evaluation—but the right choice depends heavily on whether your priority is network transformation, security depth, or operational simplicity.
As of September 2026, Gartner’s latest SASE Platforms research was published July 28, 2026 and evaluates Cato, Cisco, Cloudflare, Fortinet, HPE, Netskope, Palo Alto Networks, Sangfor, Versa, Zscaler and others. Gartner’s companion Critical Capabilities research specifically evaluates SD-WAN, private applications, cloud security, data security, threat protection, adaptive access, administration and branch modernization.
Shortlist
| Platform | Particularly strong for | Watch-outs |
|---|
| Palo Alto Prisma SASE | Deep security + SD-WAN + existing Palo Alto ecosystem | Can be complex; potentially expensive |
| Cato SASE | Replacing MPLS with a highly integrated cloud WAN | Less attractive if you need very deep security/data controls |
| Netskope SASE | SSE, CASB, DLP and data-centric security | WAN/SD-WAN capabilities need careful validation for a large branch estate |
| Fortinet | Branch networking, SD-WAN and integrated security | Cloud-native SSE experience may differ from the pure-play SSE vendors |
| Zscaler | Zero-trust/SSE, internet and SaaS access | Treat the WAN/SD-WAN portion as a separate evaluation |
| Cisco | Existing Cisco-heavy environments and broad enterprise networking | Validate how unified the operational experience is across the portfolio |
Gartner's 2025 research explicitly notes meaningful differences between vendors and evaluates capabilities such as SD-WAN, branch modernization, private applications, SaaS visibility, data security and threat protection—not simply a generic "SASE" score.
If MPLS replacement is the primary objective
I'd structure the evaluation around five things, rather than asking vendors for a generic SASE demo:
- WAN performance
- Dual broadband/Internet + 5G failover
- Application-aware routing
- Voice/video performance
- Brownout detection
- Regional breakout
- SLA monitoring
- Global connectivity
- PoP density where you actually operate
- Latency between your major regions
- Private backbone versus Internet-based transport
- Local Internet breakout
- China and other difficult connectivity regions, if applicable
- Security convergence
- SWG
- ZTNA
- CASB
- DLP
- FWaaS
- Remote-user security
- Private-application access
- DNS security
- Migration
- Can you run MPLS and Internet simultaneously?
- Automated brownfield deployment?
- How quickly can a branch be migrated?
- Can you retain existing routers/firewalls temporarily?
- What happens when the SASE service is unavailable?
- Operations
- One policy/control plane
- Centralized logging
- Troubleshooting/DEM
- API/automation
- Role-based administration
- Integration with your SIEM/SOC/ITSM
This last point matters more than vendor presentations suggest: Gartner's research has found that although most vendors call their offerings "unified," fewer than half provided a genuinely unified platform with a single management console and policy engine in its 2024 analysis.
Where I'd start
If you're already a substantial Palo Alto shop: evaluate Prisma SASE first. Prisma combines Prisma Access with Prisma SD-WAN, and Palo Alto documents SD-WAN specifically as a mechanism for transforming legacy WANs into a hybrid, application-driven WAN.
If the goal is specifically "kill MPLS and simplify the WAN": make Cato a serious contender. Its architectural model is particularly relevant when you want networking and security delivered as one cloud service rather than assembling multiple products.
If security/data protection is driving the project: put Netskope and Zscaler prominently into the proof of concept, while separately stress-testing their WAN capabilities against your branch requirements. Gartner treats SSE as a distinct market and its 2026 SSE research includes Netskope, Palo Alto, Zscaler, Cloudflare, Cisco and others.
If you're heavily invested in Fortinet at branches: Fortinet deserves a serious evaluation because minimizing the number of technologies at the branch can materially affect deployment and operations.
My recommended procurement approach
Don't select the platform from an RFP spreadsheet. Run a 60–90 day bake-off with 5–10 representative sites:
- HQ
- large regional office
- small branch
- remote/low-bandwidth branch
- manufacturing/IoT site, if applicable
- cloud-heavy site
- site in a difficult international region
- remote-user population
Give each vendor identical Internet circuits and test real applications, especially Microsoft 365, SaaS, voice/video, private applications and your most latency-sensitive workloads.
I'd also make vendors demonstrate MPLS failure, Internet degradation, tunnel failure, PoP failure, identity-provider failure and security-policy changes live. Those tests tend to reveal much more than feature matrices.
If you tell me roughly (1) number of sites, (2) countries/regions, (3) users, (4) current Cisco/Palo Alto/Fortinet/Zscaler/Netskope footprint, (5) percentage of traffic going to SaaS vs private datacenters, and (6) your MPLS spend, I can turn this into a shortlist + weighted SASE evaluation matrix tailored to your environment.
My recommended procurement approach
Don't select the platform from an RFP spreadsheet. Run a 60–90 day bake-off with 5–10 representative sites: