The 2026 Magic Quadrant for Security Service Edge was published on 29 July 2026 and is credited to John Watts, Thomas Lintemuth, Theo de Feligonde and Jonathan Forest. It arrived one day after the companion Magic Quadrant for SASE Platforms.
Three vendors are confirmed as Leaders. Netskope reports a fifth consecutive year on the rung, in every edition since the report began in 2022. Zscaler reports a fifth consecutive year as well. Palo Alto Networks reports a Leader placement in both the 2026 SASE and SSE quadrants for the fourth consecutive year.
Cloudflare states that it is the only vendor named a Visionary in both the 2026 SASE and SSE reports. Gartner also published a Critical Capabilities for Security Service Edge, in which Netskope reports being ranked among the two highest scoring vendors across all four use cases.
Placements outside the Leader rung are not established by any public material this article could verify. Several vendors appear in fragments of reproduced quadrant figures, and the fragments disagree with each other about which rung they sit on, so none are named here with a position attached.
The 2026 Magic Quadrant for Security Service Edge, and an entry bar that excludes SD-WAN
The inclusion criteria are where this report becomes interesting, because they are the near-exact inverse of the report published the day before.
A qualifying SSE product has to be deliverable as a cloud service. It has to have broad adoption independent of SD-WAN and independent of a firewall. The required features, a secure web gateway and both inline and API-based cloud access security broker, had to be generally available by 31 October 2024.
The contrast is not with the inclusion criteria of some other report. It is with the SASE premise itself. That category exists because a vendor integrates networking and security into one platform, and the SASE report grades vendors on doing exactly that.
SSE asks the opposite question. It grades whether the security half stands up on its own, sold and adopted separately from the network, by buyers who are not running the vendor's SD-WAN and may not be running the vendor's firewall either.
The two reports therefore rank the same companies against incompatible requirements in the same week, and neither is wrong to do so. They are addressed to two different buyers who happen to face the same vendors.
Two reports, one day apart, defining the market from opposite ends
The practical value of reading them together is that they separate two questions a buyer usually conflates.
The first question is whether you want one vendor for the network and the security. The SASE quadrant answers that, and its own edition carries a caution about the consolidation going too far.
The second question is whether you want the security layer without changing your network at all. The SSE quadrant answers that one, and its inclusion bar is written specifically to admit products that can be bought that way.
A vendor's position in the two reports need not agree, and the disagreement is informative rather than contradictory. A company can be a strong SSE product and an incomplete SASE platform, because the SASE report requires a network it may not sell. It can also be the reverse, which is the case for a networking vendor whose security layer is real but dependent on its own hardware and its own management plane.
That second pattern is the more common one among the enterprise networking vendors, and it is why the SSE report is the one that tells you whether a security product can be separated from the network it was built beside.
Three vendors lead both reports
Three vendors are Leaders in the 2026 SASE Platforms quadrant and the 2026 Security Service Edge quadrant at the same time. The count comes from Netskope's own announcement, and the three are Netskope, Palo Alto Networks and Zscaler.
That is a short list, and it is short for a structural reason. To lead both, a vendor has to pass an entry bar requiring the network and the security to be welded together, and a second bar requiring the security to be adoptable without the network. Very few companies sell both propositions credibly.
The three share more than a placement. Each sells a global cloud security platform with its own points of presence rather than a product deployed on customer hardware, which is what makes the independence criterion in the SSE report satisfiable in the first place. Each has spent the last several years arguing that the platform should absorb more of the surrounding security stack.
That last common trait is the one the 2026 editions have started to push back on.
The caution on a Leader is the same worry the other report introduced
The SASE edition introduced overplatformization as a named risk: vendors widening their platforms into capabilities belonging to other market segments, away from what target buyers need. The SSE edition makes the same worry concrete, and it does so on one of its own Leaders.
The cautions published against Zscaler in the SSE report are that it is typically among the most expensive options relative to functionality, that its expansion into security operations could dilute its SSE focus, and that it draws above-average customer reports of connectivity performance issues.
The middle caution is the overplatformization argument stated as a finding about one company rather than as a market-wide risk. Expansion into security operations is precisely the widening behavior the SASE edition warns about, and here it is attached to a vendor the same firm places on the Leader rung.
None of that makes the placement wrong. A Leader can carry cautions, and the cautions are usually the part of the report a buyer needs most. It does mean that the vendor with the strongest position in this market is also the one the report identifies as most exposed to the risk of losing focus on it.
For a buyer, the caution translates into a question with an answer: what share of the vendor's engineering investment over the last two years went into the products in this report, and what share went into the adjacent segment it is expanding into. That is a question vendors can answer and usually do not.
Forrester grades this market only as a component of something larger
Forrester's coverage of this ground is recorded on this site at Secure Access Service Edge Solutions (Forrester). That page carries the Q3 2025 Wave, which evaluated eight providers on their ability to fully integrate SD-WAN, security service edge and zero trust network access in single-console platforms.
Read the entry requirement there and the difference from the Gartner SSE report is immediate. Forrester admitted a vendor only if all three components were integrated in one console. Gartner's SSE bar admitted a vendor only if the security layer stands up without the network and without a firewall.
So on this site, the Forrester record grades SSE as one component of a SASE platform, priced and assessed as part of the whole. Gartner's SSE quadrant is the only place in the coverage here where the security layer is graded on its own terms, by buyers who are not buying the network.
That matters for a specific kind of purchase. If your network is already settled, run by a different team, or owned by a different vendor than your security stack, the Forrester platform Wave is answering a question you have already answered. The Gartner SSE report is the one addressed to you.
A buyer who reads the SASE Platforms (Gartner) quadrant, the SSE quadrant and the Forrester platform Wave has three views of one market, and they do not agree about where the boundary sits. That is worth knowing before a shortlist is built from whichever document arrived first.
What to ask before you buy the security layer on its own
Does this product work without your network? The SSE inclusion bar asks it of the vendor. Ask it of your own deployment. A security layer that performs well only when traffic reaches it through the vendor's own backbone is a different product from one that inspects traffic wherever it originates.
What does the price look like per user per year, all in? The most expensive vendor relative to functionality in this market is a Leader, so the placement does not settle the cost question. Ask for the total across every module you need, including the ones bundled at no apparent cost and priced at renewal.
Which expansion is your security budget funding? Every vendor here is investing in adjacent segments, and the report names it as a dilution risk for one of them. Ask what fraction of research and development goes to the products in this report, and how that fraction has moved over three years.
What did the last two quarters of connectivity complaints look like? Customer experience on the network path is the least-discussed criterion in both reports and the one users feel daily. Ask for the support ticket categories and volumes that relate to reachability and performance, not the ones that relate to policy.
If you later buy the network from the same vendor, does the price go down? This is the question that reveals which proposition the vendor is really selling. A vendor that discounts the security layer when bundled is selling a platform. One that charges the same either way is selling a product, and that is usually the better sign for a buyer who wants the security layer to stand alone.
Analyst Source
Gartner Magic Quadrant
Category definition, inclusion criteria and quadrant placement in this article draw on the Magic Quadrant for Security Service Edge published 29 July 2026 and credited to John Watts, Thomas Lintemuth, Theo de Feligonde and Jonathan Forest, together with the companion Critical Capabilities for Security Service Edge and the Magic Quadrant for SASE Platforms published the previous day. Only Leader placements and the single Visionary placement are named here, because those are the ones the vendors themselves confirmed; several vendors appear in fragments of reproduced quadrant figures that disagree with one another about their rung, and no position is assigned on that basis. The cautions quoted are the ones published against a named Leader in reporting on the report. The Forrester lineage and the single-console entry requirement draw on this site's Forrester-side coverage of the market.
Source research
- Gartner: Magic Quadrant for Security Service Edge, 29 July 2026; John Watts, Thomas Lintemuth, Theo de Feligonde and Jonathan Forest
- Gartner: Magic Quadrant for SASE Platforms, 28 July 2026; Jonathan Forest, Andrew Lerner and John Watts
- Gartner: Critical Capabilities for Security Service Edge, 2026; four use cases
- Netskope: Leader for the fifth consecutive year, in every edition since the report began in 2022; states it is one of three vendors named a Leader in both the 2026 SASE and SSE quadrants; ranked among the two highest scoring vendors in all four Critical Capabilities use cases
- Zscaler: Leader for the fifth consecutive year in SSE, and a Leader in the SASE quadrant for the first time; published cautions cover pricing relative to functionality, expansion into security operations, and above-average customer reports of connectivity performance
- Palo Alto Networks: Leader in both the 2026 SASE and SSE quadrants for the fourth consecutive year
- Cloudflare: states it is the only vendor named a Visionary in both the 2026 SASE and SSE reports
- Gartner: Security Service Edge inclusion criteria, including cloud-service delivery, adoption independent of SD-WAN and firewall, and secure web gateway with inline and API-based CASB generally available by 31 October 2024
- Forrester: The Forrester Wave: Secure Access Service Edge Solutions, Q3 2025; eight providers; single-console integration of SD-WAN, security service edge and zero trust network access as the entry requirement
Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.
The companion Gartner report defines the same ground from the other end: SASE Platforms (Gartner). That quadrant requires the network and the security to be welded into one platform, and its own 2026 edition carries a caution about that consolidation going too far. Read together, the two reports ask a buyer which half they are actually shopping for.
Forrester's side of this market is the platform scorecard at Secure Access Service Edge Solutions (Forrester), which admitted only vendors integrating SD-WAN, security service edge and zero trust network access in a single console. The services layer is graded separately, at Secure Access Service Edge Services (Forrester). Neither grades the security layer on its own, which is the question this page answers.