CATEGORY GUIDE · SD-WAN

Buyer's Guide · SD-WAN

SD-WAN sourcing: a buyer's guide for mid-market.

Nine platforms worth considering. Six scoring dimensions that move the contract. Five mistakes multi-location operators make in network sourcing — and what a buyer-side engagement produces in their place. Built for IT directors who own the network, the security stack, and the budget for both.

12 min · Updated June 2026

Questions this guide answers

  • What is the buyer actually trying to decide in an SD-WAN sourcing process?
  • Why does vendor-led SD-WAN buying break down for multi-location operators?
  • Which SD-WAN vendors belong on a mid-market shortlist — Cato Networks, Aryaka, Bigleaf, Cisco, Fortinet, Versa, Palo Alto Prisma, Cloudflare Magic WAN, VeloCloud?
  • What are the common mistakes mid-market operators make in SD-WAN and SASE sourcing?
  • What scoring dimensions matter — single-pane management, MPLS-to-internet migration, SASE convergence, per-location pricing, multi-cloud connectivity, application-aware routing?
  • Should we converge network and security on one vendor (SASE) or keep them separate?
  • What does a Cardinal SD-WAN sourcing engagement produce?
Section 1

What the buyer is actually trying to decide.

SD-WAN sourcing looks, from the outside, like a network contract. From the inside it is three intertwined decisions pretending to be one. The buyer is deciding the network architecture for the next five years, the security architecture that converges on top of it, and the operational model — managed, co-managed, or self-run — for both. Picking the wrong SD-WAN is not a network mistake. It is a strategic mistake that shows up in the security budget two years later.

The actual decision is: which platform delivers application-aware connectivity across every location at a defensible per-site cost, with a security stack that converges cleanly, and an operational model the internal team can actually run. Four variables. No vendor demo answers all four simultaneously.

The operational trigger is usually one of three things. The MPLS contract is up for renewal and the carrier just doubled the price. A new location rollout exposed the fact that the current network can't scale past 30 sites. Or a security incident forced a conversation about ZTNA, CASB, and SWG that no one wanted to have last year.

Section 2

Why vendor-led buying breaks down for SD-WAN specifically.

Vendor-led SD-WAN buying breaks down for three reasons specific to the category.

One — the demo runs on the vendor's lab, not your locations. Every SD-WAN platform demos on a clean three-site lab with idealized circuits. The buyer's actual conditions — heterogeneous broadband and fiber across forty sites, three carriers with different SLAs, fifteen-year-old cabling at the worst stores, and a hub-and-spoke MPLS topology that is being unwound in phases — don't show up. The platform that demos best is rarely the platform that deploys best.

Two — the security stack convergence is hidden behind separate quotes. Modern SD-WAN is half the conversation. The other half is secure web gateway, CASB, ZTNA, FWaaS, and DNS security — the SASE bundle. Cato Networks, Cloudflare Magic WAN, Palo Alto Prisma, Fortinet, and Versa converge these natively. Cisco, VeloCloud, Aryaka, and Bigleaf depend on partner integrations or separate SKUs. The buyer who sources SD-WAN as a network deal alone usually rediscovers the security half at month nine.

Three — per-location pricing hides material variance. A quote of one hundred dollars per location per month sounds comparable across vendors. It is not. The included bandwidth tier varies. The on-site hardware model varies. The included security services vary. The managed-service component varies. Two quotes at the same per-site number can produce a three-year cost variance of 40 percent. The buyer-side fix is to normalize across a written specification before the comparison runs.

Section 3

What Cardinal compares.

Nine SD-WAN platforms regularly appear on mid-market Cardinal shortlists. The right two or three for any operator depend on the scoring weights — the platforms below are the candidate set, not a ranking.

Cato Networks

Single-vendor SASE pioneer — converged SD-WAN, SWG, CASB, ZTNA, and FWaaS on a private global backbone. Best for operators who want one vendor for network and security with a single management plane.

Aryaka

Fully managed SD-WAN and Unified SASE with global private network and built-in WAN optimization. Best for operators with international locations and predictable performance demands.

Bigleaf Networks

Operator-friendly SD-WAN with native circuit bonding, self-healing failover, and minimal configuration. Best for multi-location SMB and lower mid-market where simplicity and uptime outweigh feature breadth.

Cisco

Cisco Catalyst SD-WAN (formerly Viptela) plus Meraki MX. Deep ecosystem, broad partner channel, native integration with Cisco network and security stack. Best in Cisco-standardized environments.

Fortinet

FortiSASE with native SD-WAN on FortiGate hardware. Aggressive total-cost-of-ownership story, strong security DNA, single-vendor convergence at competitive price. Best for security-led organizations.

Versa Networks

Versa SASE with deep feature breadth — SD-WAN, NGFW, SWG, CASB, ZTNA, and SD-LAN. Best for operators with sophisticated network engineering teams who want maximum architectural flexibility.

Palo Alto Networks Prisma

Prisma SD-WAN (formerly CloudGenix) plus Prisma Access for SASE. Strong cloud-delivered security, premium positioning. Best for security-mature operators with Palo Alto already in the stack.

Cloudflare Magic WAN

Cloudflare's global edge network as the SD-WAN fabric, with Cloudflare One for ZTNA, SWG, and CASB. Best for cloud-native operators and SaaS-heavy traffic profiles.

VMware VeloCloud

Mature SD-WAN platform with broad service-provider distribution. Best where a managed-service provider relationship is the primary delivery model and operator co-management is acceptable.

Adjacent vendors — Open Systems, HPE Aruba EdgeConnect, Juniper Session Smart, Fatpipe — appear on engagements with specific architectural requirements but are evaluated against the same rubric.

Section 4

Common mistakes mid-market operators make in SD-WAN sourcing.

  1. 1
    Sourcing SD-WAN as a network deal when it is a network plus security deal. Operators sign an SD-WAN contract, then rediscover the security stack at month nine. Scope security convergence — SWG, CASB, ZTNA, FWaaS — into the SD-WAN decision up front, even if you do not converge in year one.
  2. 2
    Comparing per-location prices on the quote line. Two vendors at the same per-site monthly number can produce 40 percent total-cost variance over three years once bandwidth tier, hardware model, included security, and managed-service component are normalized. The number on the quote is not the cost.
  3. 3
    Underestimating the MPLS unwind. Migrating off MPLS is a multi-quarter project. Some sites need MPLS as a backup. Some sites need it through a contract-term-end milestone. The migration sequence belongs in the sourcing brief, not the implementation kickoff.
  4. 4
    Treating the management plane as a feature instead of an operating model. A single pane of glass that the internal team cannot run is worse than three separate tools they can. Score the management plane against the actual operator profile of the buying organization, not against the vendor's preferred persona.
  5. 5
    Skipping the multi-cloud connectivity audit. Locations no longer connect only to a data center. They connect to AWS, Azure, GCP, and ten SaaS platforms. The SD-WAN that doesn't peer well into the buyer's actual cloud topology is a constraint on every application decision for the next five years.
Section 5

Sample scoring dimensions.

Cardinal scores every SD-WAN shortlist against a six-dimension rubric. The weights vary by buyer context — a multi-state retailer weighs PCI scope and per-location cost differently than a regional healthcare network weighing HIPAA and multi-cloud — but the dimensions are constant.

Scoring dimension What it actually measures
Single-pane management One management plane across SD-WAN, security, and reporting versus stitched-together consoles. Measured against the operating team's actual capacity, not against a vendor's ideal persona.
MPLS-to-internet migration support How the platform handles a phased MPLS unwind — site-by-site migration, hybrid operation during the transition, MPLS-as-backup posture. Material for any operator still on legacy circuits.
Security stack convergence (SASE) Native SWG, CASB, ZTNA, FWaaS, and DNS security on the same platform versus partner-stitched integrations versus separate procurement. The decision compounds over three to five years.
Per-location pricing Total monthly cost per site normalized across bandwidth tier, hardware, security inclusions, and managed-service component. The list price is rarely the comparable price.
Multi-cloud connectivity How the platform peers into AWS, Azure, GCP, and major SaaS destinations. Native cloud on-ramps, application-aware routing into cloud workloads, and predictable performance for SaaS-heavy traffic.
Application-aware routing How granularly the platform identifies and steers application traffic — voice, video, Salesforce, Microsoft 365, SaaS apps — versus generic traffic shaping. Material for UCaaS, CCaaS, and SaaS-led operators.
Section 6

What you get from Cardinal.

An SD-WAN sourcing engagement runs 45 to 120 days for the contract decision and continues through the location-by-location rollout. Five named deliverables. Each one defined in advance. None of them billable.

Deliverable 1

Sourcing Brief

Written intake — current network topology, location list, circuit inventory, MPLS contract end dates, security stack, multi-cloud destinations, internal operating capacity. The brief is the input every vendor responds against, identically.

Deliverable 2

Benchmark Report

Where you sit against peer median on the current network spend — per location, per circuit, per managed-service line. The benchmark sets the negotiation floor and exposes the cost of staying on MPLS another renewal.

Deliverable 3

Vendor Scorecard

Three shortlisted vendors, scored against the six-dimension rubric with weights tuned to your buyer context. Written reasoning, not a feature checklist.

Deliverable 4

Decision Memo

Our recommendation and the reasoning behind it. Defensible to your CFO and your board, with cross-references back to the benchmark and the scorecard, including the SASE convergence position.

Deliverable 5

Negotiation + rollout oversight

We negotiate the contract on your side of the table. Then we stay in the room through site-by-site rollout, MPLS unwind, and the security-stack cutover. Then we exit. The MSP or in-house network team runs day-two.

In short

  • SD-WAN sourcing is three decisions pretending to be one — network, security convergence, and operating model. Treating it as a network procurement is the dominant failure mode.
  • Vendor-led buying hides the security stack, the per-location math, and the MPLS-unwind sequencing. A buyer-side process exposes them before signature.
  • Nine vendors regularly appear on a mid-market SD-WAN shortlist — Cato Networks, Aryaka, Bigleaf, Cisco, Fortinet, Versa, Palo Alto Prisma, Cloudflare Magic WAN, VeloCloud. The right two or three depend on the scoring weights.
  • Per-location list prices are rarely comparable. Normalize bandwidth tier, hardware, security inclusions, and managed-service component before any vendor comparison.
  • A Cardinal engagement produces five named deliverables across the contract decision and the rollout. You owe us nothing.