The 2026 Magic Quadrant for SASE Platforms was published on 28 July 2026 and is credited to Jonathan Forest, Andrew Lerner and John Watts, with the evaluation taken as of June 2026. Twelve vendors met the inclusion criteria.

Four are Leaders: Palo Alto Networks, Netskope, Cato Networks and Zscaler. Three are Challengers: Fortinet, Cisco and Versa Networks. Cloudflare is the only Visionary. Hewlett Packard Enterprise, iboss, Sangfor Technologies and Check Point Software Technologies are Niche Players.

Two changes define the edition. Fortinet lost its Leader position and dropped to the Challenger rung, and Zscaler took the place it vacated. A companion Critical Capabilities for SASE Platforms, published a day later, scored the same vendors against fifteen criteria across five use cases.

The 2026 Magic Quadrant for SASE Platforms, under a name it has not always carried

The report has not always carried this title. The 2023 and 2024 editions ran as the Magic Quadrant for Single-Vendor SASE. The rename is not cosmetic, and it is the first thing worth understanding about the 2026 edition.

Single-vendor SASE was a bet about buyer behavior: that organizations would stop buying networking and security from separate suppliers and would consolidate onto one platform. The category existed to grade the vendors making that bet. The 2026 edition keeps essentially the same vendor set, drops the behavioral claim from the title, and in the same document introduces a caution about the consolidation being taken too far. Both of those things are true of the edition. How they sit together is the interesting part.

Overplatformization is the new caution, and the category was built on the opposite bet

Gartner's term for the risk is overplatformization, and coverage of this edition treats it as a first. The concern is that SASE vendors keep widening their platforms into capabilities belonging to other market segments, naming network detection and response and extended detection and response among them, with endpoint detection and response, data loss prevention, DSPM, SSPM and basic branch LAN networking also on the expansion path.

The stated risk is that this drifts away from what target buyers actually need. Gartner's own language, as reported, is that overplatforming may lead to quality problems and eventually affect customer satisfaction and loyalty. Coverage also records an expectation that some vendors will leave the market, because maintaining a platform this broad is expensive.

That caution sits awkwardly beside the category's own premise, and the buying data explains why rather than resolving it. Most purchases are still not single-vendor. The figure in circulation for 2026 is that roughly 65 percent of SASE purchases still separate the network from the security stack. The single-vendor share is growing against that, and the projections for how far it grows do not agree with each other.

Coverage of the Magic Quadrant puts single-vendor at 35 percent of purchases in 2026, rising to 75 percent by 2029. The Critical Capabilities reprint gives a different baseline and a different endpoint: 40 percent in 2026 rising to 60 percent of new deployments by 2029. Those are different populations, purchases against new deployments, and this article does not choose between them. It is worth knowing that both numbers are circulating before either is quoted in a business case.

The vendor that lost the rung tops the use case table

The companion report scores vendors across five use cases on fifteen criteria. Only one use case has had its scores republished in vendor coverage, the one for secure branch network modernization, and it is the most useful table in the edition.

Fortinet scores 4.33, the highest of the twelve. Netskope is second at 4.13, Versa third at 4.11 and Cisco fourth at 4.01. Palo Alto Networks scores 3.78, Sangfor 3.77, Cato 3.76, iboss 3.57, Hewlett Packard Enterprise 3.50 and Check Point 3.43. Zscaler scores 3.22, eleventh of twelve. Cloudflare is last at 2.88.

Read that against the quadrant and the two documents point in opposite directions at the top. Fortinet holds the best score on the one use case that can be inspected and sits on the Challenger rung. Zscaler took the Leader place Fortinet lost and sits near the bottom of that same use case.

Neither document is wrong, and the reason is worth stating precisely. Ability to Execute weighs a whole business: revenue, customer base, operations, support, and the capacity to sell and deliver globally. A use case score weighs one scenario against fifteen criteria. A vendor can be strong on the second and weaker on the first, or the reverse, and this edition contains a clean example of each.

The consequence is about shortlisting. A buyer who reads only the quadrant will put Zscaler on the list and may not consider Fortinet. A buyer who reads only the Critical Capabilities table will do the opposite. The right list depends on whether the problem is a branch network that has to perform, or a platform the organization has to run, patch and support for the next five years. Those are different purchases that share a name.

Cisco is a Challenger here and was absent there

The most instructive comparison in this market is not between two vendors. It is between two firms looking at the same product.

Cisco is a Challenger in the 2026 quadrant, and the criticism attached to it is that its SASE products still require two management consoles. Hewlett Packard Enterprise carries a similar note and lands as a Niche Player.

Forrester applied the same test and reached a different conclusion about how much it costs. Its SASE platform Wave evaluated eight providers that fully integrate SD-WAN, security service edge and zero trust network access in single-console platforms. Cisco is not in that field, because it did not clear the entry bar, and the reason given is the same one: the consoles.

One firm kept the vendor in the report and marked it down. The other removed it from the field entirely. That is a rare case where the analytical disagreement is not about the shape of a market but about a single measurable property. Count the consoles. Both firms agree on what they counted.

For a buyer, that is the one question in this market with an answer that does not depend on trusting either analyst. It is also the question most likely to be answered evasively in a demo, because the count is usually visible only after the proof of concept.

The Forrester side of this market is two scorecards, not one

Forrester covers this ground with two evaluations rather than one, and the split is worth knowing before reading either.

The platform side is recorded on this site under Secure Access Service Edge Solutions (Forrester). That page carries the Q3 2025 Wave: eight providers, assessed on their ability to integrate SD-WAN, security service edge and zero trust network access in a single console, using vendor materials as of June 2025. It is the successor to the Zero Trust Edge Solutions Wave of Q3 2023, which evaluated ten providers.

The delivery side runs separately, at Secure Access Service Edge Services (Forrester). That page covers the Q3 2026 Wave, published 24 July 2026, which grades the operator who answers the phone when the network goes dark rather than the platform itself. Its predecessor, the Zero Trust Edge Service Providers Wave of Q2 2024, evaluated nine providers against thirty-four criteria.

So the two firms have cut the same market along different lines. Gartner grades one platform that has to do everything, and in the same edition warns that vendors are doing too much. Forrester grades the platform in one report and the managed service in another, which means a buyer choosing a managed SASE offering is reading a scorecard about a different subject from the buyer choosing a product to run in house.

A buyer who reads the Gartner quadrant has a shortlist. A buyer who also reads the Critical Capabilities table, the platform Wave and the services Wave has a shortlist, a use case ranking and a delivery assessment, and those three do not always agree.

What to ask before you consolidate the network and the security stack

How many consoles, and will that number go down? This is the question both firms are asking, and it has a factual answer. Ask for the console count today and the committed count at your next renewal. A vendor that needs two consoles now and has a date for one is a different proposition from one that will need two indefinitely.

Which use case are you actually buying? The Critical Capabilities table ranks vendors very differently depending on the scenario. Ask a vendor for its scores across all five use cases, not the one where it placed best. A single strong use case score carried into a general claim of leadership is the most common misreading of this report.

What sits on the platform that you will never turn on? Overplatformization is a price and attack surface question, not only a licensing one. Every module you own is code to keep patched and policy to keep correct. Ask what share of the vendor's customers actually run the module you are being sold.

Is the consolidation saving money or reducing risk? Gartner's guidance to buyers is to aim consolidation at improving risk posture through simplification rather than at cost savings. Those two goals produce different shortlists, and the cost-saving version usually produces the larger platform.

What does sovereignty mean for the deployment you are buying? On-premises deployment does not by itself make a solution sovereign, and this edition added a sovereign SASE use case. If sovereignty is a requirement, ask where the management plane runs, where logs are held, and which regions traffic can traverse.

Who is the platform's user in 2029? Gartner's working assumption is that by 2029 around 60 percent of secure access requests will originate from non-human identities, against less than 5 percent in 2026. If that holds, the policy engine's real user base is machines, and most of the platforms in this quadrant were designed for people.

Analyst Source

Gartner Magic Quadrant

Category definition, vendor inclusion and quadrant placement in this article draw on the Magic Quadrant for SASE Platforms published 28 July 2026 and credited to Jonathan Forest, Andrew Lerner and John Watts, with the evaluation taken as of June 2026, together with the companion Critical Capabilities for SASE Platforms published 29 July 2026. The edition assessed twelve vendors. Quadrant placements are corroborated by the vendors' own announcements and by independent coverage of the report; the Critical Capabilities scores quoted here are limited to the one use case whose figures have been republished, and no score is attributed to a vendor for any of the other four. The two single-vendor adoption figures circulating are reported side by side and neither is presented as the settled number. The Forrester lineage, the Wave criteria counts and the Cisco console finding draw on this site's Forrester-side coverage of the market.

Source research

  • Gartner: Magic Quadrant for SASE Platforms, 28 July 2026; twelve vendors; renamed from the Magic Quadrant for Single-Vendor SASE, which ran in 2023 and 2024
  • Gartner: Critical Capabilities for SASE Platforms, 29 July 2026; fifteen criteria across five use cases; secure branch network modernization scores as republished
  • Zscaler: Leader in the SASE quadrant for the first time, and a Leader in the 2026 SSE quadrant for the fifth consecutive year
  • Netskope: Leader for the third consecutive year
  • Cato Networks: Leader for the third consecutive year
  • Palo Alto Networks: Leader; states it is the only vendor named a Leader in both the SASE and SSE quadrants for four consecutive years
  • Fortinet: moved from the Leader rung to the Challenger rung; highest score of the twelve on the republished secure branch network modernization use case
  • Cisco: Challenger, with the two-console criticism that also kept it out of Forrester's SASE platform field
  • Versa Networks: Challenger; Cloudflare: the only Visionary; Hewlett Packard Enterprise, iboss, Sangfor Technologies and Check Point Software Technologies: Niche Players
  • Forrester: The Forrester Wave: Secure Access Service Edge Solutions, Q3 2025; eight providers; single-console integration as the entry bar
  • Forrester: The Forrester Wave: Secure Access Service Edge Services, Q3 2026, published 24 July 2026; predecessor Zero Trust Edge Service Providers, Q2 2024, nine providers against thirty-four criteria

Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

The platform side of the Forrester record for this market is kept at Secure Access Service Edge Solutions (Forrester), which carries the Q3 2025 Wave and the finding that Cisco did not clear its entry bar. The console test applied there is the same one Gartner applies here, and the two firms reach different conclusions about what it costs a buyer.

Forrester grades the managed delivery of this market in a separate scorecard, at Secure Access Service Edge Services (Forrester). That page covers the Q3 2026 Wave and the operator rather than the platform, which matters because a managed SASE purchase and a product purchase are assessed against different questions.