Sora Yazılım
English
Custom software solutions from Türkiye
Fortinet · Network Security

FortiSASE

Cloud SASE with a single policy for remote workers and branches: SWG, ZTNA, CASB, FWaaS.

Quick answer

FortiSASE is Fortinet's cloud-based single-vendor SASE service; it brings secure web gateway (SWG), ZTNA, CASB, FWaaS, SSPM, secure browser, secure SD-WAN and digital experience monitoring together in a single console. Remote workers and branches are governed by the same policy; traffic is inspected at the nearest Fortinet security PoP and FortiClient is used as the single agent.

FortiSASE is Fortinet's single-vendor SASE service delivered from the cloud. Secure web gateway (SWG), Zero Trust Network Access (ZTNA), cloud access security broker (CASB) and firewall-as-a-service (FWaaS) converge in the same policy engine. Whether the user is at home, in a hotel or at a customer site, their traffic is inspected at the nearest Fortinet security PoP; branches connect to the same cloud through FortiGate. The result is a single access policy that is independent of location.

Threat data explains why this architecture is on the agenda. According to Verizon's 2025 Data Breach Investigations Report, vulnerability exploitation reached 20% as an initial access vector, and edge devices and VPNs accounted for 22% of those exploitation actions — almost eight times the previous year's 3% (Verizon DBIR, 2025). The same report measures that organizations were able to fully remediate only about 54% of their edge device vulnerabilities within the year, and that this took a median of 32 days. That is the price of making a single internet-facing VPN concentrator the doorway to enterprise access; FortiSASE removes that doorway and brings access down to the level of identity, device posture and application.

Sora Yazılım is a Fortinet authorized channel partner, and we position FortiSASE not in isolation but as part of the Fortinet Security Fabric architecture. On this page we explain, with sources, which components make up FortiSASE, how it is designed for remote worker and branch scenarios, its relationship with FortiClient, its contribution to KVKK (Turkey's data protection law) and PCI DSS programs, and the limits you should know before you buy.

Which security components does FortiSASE unify on a single platform?

FortiSASE brings together in a single service eight functions that would normally have to be purchased and integrated separately: SWG, ZTNA, CASB, FWaaS, SaaS security posture management (SSPM), secure browser, secure SD-WAN and end-to-end digital experience monitoring (DEM) (Fortinet, 2026). These eight are the most useful checklist when comparing solutions that carry the "SASE" label on the market: some competitors deliver the same capabilities through different SKUs, different consoles and different log formats. The practical benefit of the single-vendor model is that the same policy language and the same telemetry apply at the endpoint, in the cloud and in the branch.

ComponentFunctionTypical use
SWG (Secure Web Gateway)Inspection of web and TLS traffic for URL category, reputation and malicious contentInspecting a remote user's internet egress without backhauling it to headquarters
ZTNAAccess at the application level rather than the network level, tied to identity and device postureExternal access to on-premises ERP, file servers and management interfaces
CASBVisibility into SaaS usage, data sharing and shadow IT controlMicrosoft 365, Google Workspace and unsanctioned cloud applications
FWaaSFull firewall and IPS inspection including non-web protocolsBranch internet egress, server-to-client traffic
SSPMContinuous auditing of the configuration posture of SaaS tenantsIncorrect sharing permissions, weak authentication settings
Secure browserIsolated browsing surface on non-corporate devicesContractor, consultant and BYOD access
Secure SD-WANApplication-aware routing and WAN redundancyReducing MPLS dependency in multi-branch estates
DEM (Digital Experience Monitoring)Latency and loss measurement from the user all the way to the applicationRoot cause analysis of "the system is slow" complaints

The threat intelligence behind these components comes from FortiGuard. The FortiSASE data sheet states that the web filtering engine classifies hundreds of millions of URLs into more than 90 categories and also analyzes TLS 1.3 traffic; on the application control side, more than 8,000 applications — including industrial control signatures — are identified and managed (FortiSASE Data Sheet, 2026). On the antivirus side, Fortinet reports that it produces 1.8 million new antivirus definitions per week using telemetry from a customer base of more than 830,000 (FortiSASE Data Sheet, 2026). At enterprise scale, FortiGuard Labs is stated to process and analyze more than 100 billion events per day (Fortinet, 2026).

Just as important as the component list is the fact that all of it reaches the endpoint through a single agent. In the FortiSASE architecture, FortiClient combines endpoint protection (EPP), ZTNA, SSE, CASB, DEM, Sandbox, vulnerability management and USB device control in the same client (FortiSASE Data Sheet, 2026). In practice, this means the end of three or four different security agents stacked on top of each other on laptops, along with the driver layers that break one another.

In a remote worker scenario, what does FortiSASE put in place of the classic VPN?

Short answer: identity instead of a tunnel, application access instead of network access. With classic remote access VPN, the user receives an IP address once authenticated and in practice lands inside a network segment; authorization is largely handled at the network layer. With FortiSASE, the user connects not to the network but to defined applications. The architecture has three parts: the FortiClient agent, the FortiSASE Endpoint Management Service and the ZTNA access proxy. FortiSASE applies ZTNA tagging rules to FortiClient; when an access request arrives, the ZTNA access proxy on the FortiGate grants or denies access based on the client certificate and those tags (Fortinet Document Library, 2026).

ZTNA was introduced with FortiOS 7.0 and its components were defined as FortiClient (the ZTNA agent), FortiClient EMS (identity and device posture) and FortiGate (the ZTNA application gateway) (Fortinet Document Library, FortiOS 7.0). FortiSASE moves the management plane of this trio into the cloud; an organization can apply the same ZTNA model without having to operate its own EMS server.

There is another reality that makes the transition mandatory: Fortinet has retired SSL-VPN on some entry-level platforms. The FortiGate 40F and 60F data sheets explicitly state that SSL-VPN is not supported on FortiOS 7.6.0 and above (FortiGate 60F Series Data Sheet, 2026). In other words, the "SSL-VPN works, let's not touch it" approach comes to an end by itself alongside the operating system upgrade calendar. That opens a planned window for moving remote access onto ZTNA or FortiSASE.

CriterionClassic remote access VPNFortiSASE (SWG + ZTNA)
Unit of accessNetwork segment / IP rangeIndividual applications
Traffic pathAll traffic is backhauled to headquartersInternet and SaaS traffic egresses from the nearest security PoP
Device postureUsually checked only at the moment of connectionContinuously evaluated through ZTNA tags
Attack surfaceInternet-facing VPN portalPublished application and intermediary proxy
Lateral movement riskHigh once the network is enteredLimited by per-application authorization
User experience measurementRequires a separate toolDEM is included in the platform
Capacity growthDepends on sizing of central hardwareScales by subscription as a cloud service

The second major gain on the remote worker side concerns web- and email-borne attacks. ENISA Threat Landscape 2025 reports that across the 4,875 incidents it analyzed between 1 July 2024 and 30 June 2025, phishing was the dominant intrusion vector at 60% (ENISA Threat Landscape, 2025). When a phishing link is clicked outside the corporate network, the firewall at headquarters is not in the path; with FortiSASE, SWG policy is applied identically wherever the user happens to be. Likewise, Verizon measures that ransomware was present in 44% of breaches, rising to 88% among SMBs (Verizon DBIR, 2025).

In a branch scenario, how do FortiSASE and FortiGate work together?

In the branch, FortiSASE does not replace FortiGate; it divides the labor. The common setup, and the one we recommend, is this: a physical FortiGate in the branch handles local segmentation, LAN/WLAN control and SD-WAN routing, while traffic bound for the internet and SaaS is steered to a FortiSASE security PoP and passes through the same inspection as at headquarters. Instead of operating a heavy UTM licence set at every location, inspection is centralized in the cloud and the branch device focuses on its networking role.

This approach also has analyst backing: Fortinet announced that it was positioned as a Leader in the 2025 Gartner Magic Quadrant for SASE Platforms and that, in the same release, it ranked first in the "Secure Branch Network Modernization" use case in the Gartner Critical Capabilities for SASE Platforms report that complements the MQ (Fortinet, 2025). In other words, the area where the platform is strongest is precisely branch modernization. (For the change in position in the 2026 report, see the analyst section below.)

In small and medium-sized branches, hardware selection usually starts with desktop models such as the FortiGate 60F; the wireless and access layers can be brought under the same management umbrella. FortiAP access points are operated using one of three management models: FortiGate's integrated WLAN controller, the FortiEdge Cloud portal, or FortiSASE directly (FortiAP Series Data Sheet, 2026). At the access layer, the FortiLink protocol turns FortiSwitch into a logical extension of the FortiGate, and depending on the FortiGate model between 8 and 300 switches can be managed from a single interface (FortiSwitch Secure Access Data Sheet, 2026).

The secure SD-WAN component of FortiSASE comes into play for application-aware routing of branch traffic; because application control recognizes more than 8,000 applications, rules such as "let Microsoft 365 break out directly, send ERP through the tunnel, block file sharing" can be written on application identity rather than bandwidth (FortiSASE Data Sheet, 2026). As scale grows, the entire estate can be brought under central management: the FortiManager product page states that 100,000 Fortinet devices are supported, including FortiGate, FortiSwitch, FortiAP, SD-WAN and FortiSASE (Fortinet, 2026).

What exactly is the relationship between FortiClient and FortiSASE?

FortiClient is the agent and FortiSASE is the cloud service; the two are layers of the same product. Under a FortiSASE subscription, FortiClient is managed from the cloud by the FortiSASE Endpoint Management Service; policy, ZTNA tags and certificate distribution are handled through that service (Fortinet Document Library, 2026). If the organization also runs FortiClient EMS on premises, both management planes must be considered together in a hybrid model — this is one of the most critical design decisions in the project and must be settled up front.

Platform coverage is broad. According to the FortiClient data sheet, Windows 10/11 and Windows Server 2019 and later, macOS 10.15+, iOS 9.0+, Android 5.0+, Linux (Ubuntu 22.04+, Red Hat 9+, CentOS 9.0+) and all Chromebook versions are supported (FortiClient Data Sheet, 2025). Platforms are not equal, however: behavior-based ransomware protection and rollback are supported on Windows only, and the Linux build does not support Sandbox integration (FortiClient Data Sheet, 2025). Organizations managing a mixed fleet need to reflect these differences in their policy design.

There is a practical licensing detail to watch: under the FortiTrust user-based FortiClient licence, a single user can install FortiClient on at most three devices (FortiClient Data Sheet, 2025). For heavily mobile teams using laptop plus phone plus tablet, that limit directly affects the user count calculation. Because pricing varies with configuration and term, we do not publish prices on this page; ask for a quote configured to your current user count.

How does FortiSASE contribute to KVKK and PCI DSS compliance work?

FortiSASE is not a compliance certificate; it does, however, directly address several concrete controls that come up in audits. The Personal Data Security Guide (Technical and Administrative Measures) issued under KVKK (Turkey's data protection law) states that the primary measure is the firewall and gateway when protecting systems containing personal data against unauthorized access attempts arriving over the internet, and that these form the first line of defense; the same guide lists regular logging of all user transaction activity, along with regular vulnerability scanning and penetration testing, among the technical measures (KVKK Personal Data Security Guide, 2018). For a remote workforce, the "gateway" is no longer the device at headquarters but the SASE PoP the user connects to.

On the PCI DSS v4.0 side, the most directly relevant requirement is 1.5.1: security controls must be implemented on devices that can connect both to an untrusted network and to the cardholder data environment (CDE) — typically a remote worker's laptop. The standard also requires, in 1.4.1, that a network security control (NSC) be placed between trusted and untrusted networks (PCI Security Standards Council, PCI DSS v4.0). Note: in v4.0 the term "firewall" was replaced with Network Security Controls (NSC); using this terminology in audit correspondence will make your life easier. FortiSASE's device posture checking and application-level access are technical controls that can be used to meet these requirements.

On the service provider assurance side, FortiSASE holds SOC 2 Type II certification against the AICPA Trust Services criteria, and Fortinet states that it commits to a latency-guaranteed 99.999% SLA for security inspection (FortiSASE Data Sheet, 2026). The SOC 2 report is one of the documents typically requested in vendor assessment files and can be requested from Fortinet during the purchasing process.

On the audit trail side, log collection and reporting are critical. FortiAnalyzer offers ready-made compliance reports such as PCI-DSS and HIPAA and separates the log ingestion load through Analyzer/Collector modes (FortiAnalyzer Data Sheet, 2026). On the SaaS side, the CASB and SSPM components make visible which cloud application corporate data is going to — particularly on organization-wide platforms such as Microsoft 365, auditing sharing permissions and external shares closes one of the hardest parts of KVKK data inventory work. The log retention region and PoP region are chosen when the tenant is created; at project kick-off we confirm which regions are offered from Fortinet's current region list.

What is FortiSASE's analyst position and which limits should be known?

The honest answer: FortiSASE is strong but it is not the undisputed leader of the category, and Gartner's category definitions have changed several times in the last two years. The table below summarizes the current picture based on Fortinet's own announcements and its own Gartner Magic Quadrant page. We suggest you use this table in place of the "leader in every category" claim often seen in marketing presentations.

ReportYearFortinet's position
Gartner MQ for Single-Vendor SASE2024Challenger
Gartner MQ for Security Service Edge (SSE)2025Challenger
Gartner MQ for SASE Platforms2025Leader
Gartner MQ for SASE Platforms2026Challenger

The sources, in order: Challenger in the 2024 Single-Vendor SASE MQ (Fortinet, 2024), Challenger in the 2025 SSE MQ (Fortinet, 2025), Leader in the 2025 SASE Platforms MQ (Fortinet, 2025) and, on Fortinet's own Gartner MQ listing, Challenger for the 2026 SASE Platforms report (Fortinet, Gartner Magic Quadrants). So Fortinet rose to Leader in this category in 2025 and slipped back to Challenger in the 2026 report. On the network security side, by contrast, the position is different: Fortinet was positioned as a Leader in the 2025 Gartner Magic Quadrant for Hybrid Mesh Firewall (Fortinet, 2025). Knowing this distinction helps with the "where FortiGate, where FortiSASE" decision.

The second limit is PoP count and latency. Fortinet's FortiSASE product page speaks of a global network of more than 200 PoPs (Fortinet, August 2026); the FortiSASE data sheet, by contrast, gives no number and uses the phrase "hundreds of security PoPs" (FortiSASE Data Sheet, 2026). Because the PoP list changes over time, we do not promise a sourced latency figure measured from Turkey; instead, during the pilot phase we take real measurements from your own locations and report the results. The DEM component can be used directly for this user experience measurement.

The third limit is that the 99.999% SLA and similar commitments are the vendor's own statements; they are not measurements by an independent test organization. During contracting, the scope of the SLA, its exclusions and its remedy mechanism should be read separately. Fourth, the FortiSASE roadmap moves in step with FortiOS: with FortiOS 8.0, announced on 10 March 2026, Fortinet introduced FortiView for shadow-AI detection, AI-aware application control, Model Context Protocol visibility, OCR-enabled DLP and post-quantum cryptography controls (Fortinet, 2026). If governing enterprise AI tools is on your agenda, clarify before purchase which release will bring these capabilities to your subscription. We also carry out a comparative assessment against our other security solutions.

Finally, the pace on the threat side: according to Fortinet's 2026 Global Threat Landscape Report, time-to-exploit on critical advisories has dropped to 24–48 hours and global exploitation attempts rose 25.49% year over year (Fortinet, 2026). The same report states that the number of confirmed ransomware victims reached 7,831 in 2025, which represents a 389% increase over the previous report (Fortinet, 2026). At that tempo, applying security updates centrally on the cloud side is the most concrete operational advantage of the SASE model.

How is a FortiSASE project sized and through which steps is it rolled out?

Sizing starts with two questions: how many users and which traffic will pass through SASE. The user count determines subscription volume; the traffic scope determines policy design. In practice, most organizations do not move everything to the cloud on day one; the phased plan below lowers both risk and the likelihood of an outage.

PhaseScopeOutput
1. Inventory and discoveryUser groups, device fleet, internal applications to be published, current VPN usageApplication-to-user access matrix
2. Tenant and identityFortiSASE tenant, identity provider federation, user/group mapping, region selectionWorking sign-on flow
3. Pilot (SWG)Inspection of internet egress for a limited user group, latency measurementPerformance report with real measurements
4. ZTNA publicationPublishing the 3–5 priority internal applications via ZTNA, device posture rulesApplication access without VPN
5. CASB and SSPMSaaS visibility, data sharing rules, configuration posture auditingShadow IT inventory and remediation list
6. Branch integrationSteering the FortiGates to SASE, SD-WAN policiesOne policy for branch and remote user
7. Retiring the VPNShutting down remaining VPN usage, handover of logging and reportingReduced attack surface

Sora Yazılım is involved in every one of these steps: needs analysis and user sizing, licensing, tenant setup, identity integration, ZTNA application publication, migration from the existing VPN, staff training and post-deployment managed service. For infrastructure work on the cloud and automation side we position our DevOps and infrastructure services within the same project; when a ZTNA gateway is needed in the data center or cloud, we deploy virtually with FortiGate-VM. We run the entire engagement with Turkish documentation and local support.

The most frequently overlooked topic during evaluation is aligning existing contracts. There may be capability overlap between FortiClient EMS, FortiGate UTM subscriptions and the FortiSASE subscription; the right design is not to buy the same capability twice. If you share your current Fortinet inventory and renewal dates, we will identify the overlaps and propose a structure containing only the components you actually need.

To move your remote worker and branch access onto a single policy with FortiSASE, all you need to do is share your user count, location distribution and the internal applications you want to publish. We will review your existing VPN setup and prepare a proposal covering the migration plan, pilot scope and licence configuration; because pricing is shaped by user count and term, we produce the configured quote specifically for the project. Contact us through our contact page and our technical team will schedule a discovery call within the same week.

Key features

What it offers

  • Single-vendor SASE unifying SWG, ZTNA, CASB, FWaaS, SSPM, secure browser, secure SD-WAN and DEM on one platform
  • Single-agent approach: EPP, ZTNA, SSE, CASB, DEM, Sandbox, vulnerability management and USB device control with FortiClient
  • Web filtering that classifies hundreds of millions of URLs into more than 90 categories and supports TLS 1.3
  • Application control and SD-WAN routing that recognize more than 8,000 applications, including industrial control signatures
  • Application-level ZTNA access tied to identity and device posture (instead of network segment access)
  • Authorization through the FortiGate ZTNA access proxy using ZTNA tagging rules and a client certificate
  • Visibility into SaaS usage and shadow IT with CASB, and SaaS configuration posture auditing with SSPM
  • End-to-end digital experience monitoring (DEM) for root cause analysis of user slowness complaints
  • Hybrid architecture with FortiGate: local segmentation and SD-WAN in the branch, cloud inspection for the remote user, one policy language
  • SOC 2 Type II certified cloud service against the AICPA Trust Services criteria
  • Fortinet's latency-guaranteed 99.999% SLA commitment (vendor statement)
  • Unified logging and ready-made PCI-DSS/HIPAA compliance reports with FortiAnalyzer
  • Central management within the FortiManager estate (FortiGate, FortiSwitch, FortiAP, SD-WAN and FortiSASE together)
  • User- and group-based policy management through enterprise identity provider federation
Tech Summary

Important technical data

Architecture
Cloud-delivered single-vendor SASE: SWG, ZTNA, CASB, FWaaS, SSPM, secure browser, secure SD-WAN, DEM
PoP network
More than 200 PoPs on the Fortinet product page (August 2026); the data sheet uses the phrase "hundreds of security PoPs"
SLA
99.999% with latency guarantee (Fortinet statement)
Certification
SOC 2 Type II (AICPA Trust Services criteria)
Web filtering
Hundreds of millions of URLs, 90+ categories, TLS 1.3 support
Application control
8,000+ applications (including industrial control signatures)
Threat intelligence
FortiGuard; 1.8 million new antivirus definitions per week
Endpoint agent
FortiClient — Windows 10/11 and Server 2019+, macOS 10.15+, iOS 9.0+, Android 5.0+, Linux (Ubuntu 22.04+, RHEL 9+, CentOS 9.0+), Chromebook
Agent functions
EPP, ZTNA, SSE, CASB, DEM, Sandbox, vulnerability management, USB device control
Devices per user
Maximum 3 devices per user under the FortiTrust user-based licence
Endpoint management
FortiSASE Endpoint Management Service (cloud); ZTNA tagging rules and client certificate
Analyst position
2025 Gartner MQ for SASE Platforms: Leader; Challenger in the 2026 report
Logging and reporting
FortiAnalyzer (Analytics) integration; ready-made PCI-DSS and HIPAA reports
Licensing
Subscription based on user count — contact us for a configured quote
Use Cases

When would you choose this product?

Software and technology

Retiring SSL-VPN in a remote-working team

In a software company whose employees connect from different cities, internet and SaaS traffic is inspected at the nearest FortiSASE PoP, while internal development and management interfaces are published at application level via ZTNA. Because SSL-VPN is not supported on platforms such as the FortiGate 40F/60F from FortiOS 7.6.0 onward, the migration is planned together with the operating system upgrade calendar.

Retail

One policy for branches and hybrid workers in a multi-branch estate

In the branches, FortiGate handles local segmentation and SD-WAN routing while internet egress is steered to FortiSASE; head office staff and field teams are governed by the same policy set. The wireless layer is brought under the same management umbrella with FortiAP, and the log stream is consolidated in FortiAnalyzer.

Finance and insurance

Narrowing remote access within PCI DSS scope

Laptops that can reach the cardholder data environment from outside fall within the scope of PCI DSS v4.0 requirement 1.5.1. With ZTNA, only the necessary application — not the network — is opened to these devices, device posture rules are evaluated continuously, and access records provide source material for compliance reports.

Consulting and professional services

Teams working at customer sites and contractor access

Consultants connect from unknown networks at customer locations; the SWG component of FortiSASE applies corporate web policy on those networks too. For contractors who do not use corporate devices, the secure browser component offers a limited access surface that requires no agent installation.

Manufacturing

Controlled application access between headquarters and production sites

Access from the engineering team at head office to applications at the plant is authorized per application via ZTNA, while a FortiGate at the plant maintains local inspection. Because application control also covers industrial control signatures, it becomes visible which protocols are passing through.

Who is it for?

Organizations with hybrid and remote workforces, multi-branch retail and service businesses, finance and insurance institutions looking to narrow remote access within PCI DSS or KVKK scope, and professional services firms wanting to bring contractor and consultant access under control.

Frequently Asked Questions

Frequently asked questions

On which points does FortiSASE differ from a classic VPN?
The most fundamental difference is the unit of access: a VPN admits the user to the network, whereas FortiSASE authorizes them to individual applications. Instead of being backhauled to headquarters, traffic is inspected at the nearest security PoP; device posture is not checked once at connection time but evaluated continuously through ZTNA tags. In addition, user experience measurement (DEM) is included in the platform and requires no separate tool.
Is a FortiGate required in order to use FortiSASE?
No, FortiSASE can be deployed on its own as a cloud service. However, for organizations with branches, the setup we recommend is hybrid: in the branch, FortiGate handles local segmentation, LAN/WLAN inspection and SD-WAN routing, while internet and SaaS traffic is steered to FortiSASE. That way the branch and the remote user share the same policy language.
What is the relationship between FortiClient and FortiSASE?
FortiClient is the agent on the endpoint and FortiSASE is the cloud service. In the FortiSASE architecture, FortiClient hosts EPP, ZTNA, SSE, CASB, DEM, Sandbox, vulnerability management and USB device control in a single agent and is managed from the cloud by the FortiSASE Endpoint Management Service; ZTNA tags and the client certificate are distributed through that service.
Which operating systems does FortiSASE support?
According to the FortiClient data sheet, Windows 10/11 and Windows Server 2019 and later, macOS 10.15+, iOS 9.0+, Android 5.0+, Linux (Ubuntu 22.04+, Red Hat 9+, CentOS 9.0+) and all Chromebook versions are supported. Capabilities are not equal across platforms: behavior-based ransomware protection and rollback work on Windows only, and the Linux build does not support Sandbox integration.
What will latency be for users connecting from Turkey?
We do not promise latency figures without a source. The Fortinet product page speaks of a network of more than 200 PoPs, while the data sheet gives no number and says "hundreds of security PoPs"; the PoP list changes over time. The correct method is to take real measurements from your own locations during the pilot phase — the DEM component can also perform this measurement continuously.
How does FortiSASE licensing work, and what does it cost?
FortiSASE is a subscription sized by user count. Because the price varies with the number of users, the components selected and the contract term, we do not publish prices on this page. If you share your user count and scope, we will prepare a configured quote. Note: under the FortiTrust user-based FortiClient licence, one user can install the agent on at most three devices; that limit affects the calculation.
What does FortiSASE provide in terms of KVKK?
The KVKK Personal Data Security Guide (2018) — under Turkey's data protection law — lists the firewall and gateway as the primary measure against unauthorized access from the internet, along with regular logging and penetration testing. In a remote workforce, the gateway function is taken over by the SASE PoP; with FortiAnalyzer, log records are centralized. FortiSASE is not a compliance certificate, but it enables these technical measures to be implemented.
Is Fortinet the leader in the SASE category?
Because the category definition has changed, a one-sentence answer would be misleading. Fortinet is listed as a Challenger in the 2024 Single-Vendor SASE MQ, a Challenger in the 2025 SSE MQ, a Leader in the 2025 SASE Platforms MQ (and first in the "Secure Branch Network Modernization" scenario in the Critical Capabilities for SASE Platforms report from the same period), and a Challenger in the 2026 SASE Platforms report. On the network security side the position is different: Leader in the 2025 Hybrid Mesh Firewall MQ.
How long does the move to ZTNA take and where should it start?
The right starting point is not migrating all applications at once but publishing the 3–5 most remotely accessed internal applications via ZTNA. Beforehand, an application-to-user access matrix is produced, identity provider integration is completed, and an SWG pilot is run with a limited user group. The duration depends on the number of applications and the readiness of the identity infrastructure; we finalize the schedule after the discovery call.
Will my existing FortiGate UTM subscriptions overlap with FortiSASE?
They may. Capability overlap between FortiGate UTM subscriptions, FortiClient EMS licences and the FortiSASE subscription is common, and buying the same capability twice creates unnecessary cost. We review your existing inventory and renewal dates, identify the overlaps and propose a structure containing only the components you need.
Can the branch wireless and access layer also be included in FortiSASE?
FortiAP access points are operated using one of three management models: FortiGate's integrated WLAN controller, the FortiEdge Cloud portal, or FortiSASE directly. At the access layer, the FortiLink protocol makes FortiSwitch a logical extension of the FortiGate, and depending on the FortiGate model between 8 and 300 switches are managed from a single interface. In this way wired, wireless and security are brought under one roof in the branch.
What are the limits of FortiSASE that should be known?
They fall under three headings. First, the 99.999% SLA is the vendor's own commitment; its scope and exclusions should be read in the contract. Second, the PoP count is stated differently across sources and latency must be measured per location. Third, the roadmap advances with FortiOS — for example, it should be clarified before purchase which release will bring capabilities such as the shadow-AI detection and OCR-enabled DLP announced with FortiOS 8.0 to your subscription.
Vendor's official product page

Opens the vendor's original technical documentation and product page in a new tab.

FortinetFortiSASE
Related Services

Services we deliver alongside this product

FortiSASE licensing + deployment + support

Sora Yazılım handles licensing, deployment, training and ongoing management — all from a single team.

WhatsApp Support