FortiSASE is Fortinet's single-vendor SASE service delivered from the cloud. Secure web gateway (SWG), Zero Trust Network Access (ZTNA), cloud access security broker (CASB) and firewall-as-a-service (FWaaS) converge in the same policy engine. Whether the user is at home, in a hotel or at a customer site, their traffic is inspected at the nearest Fortinet security PoP; branches connect to the same cloud through FortiGate. The result is a single access policy that is independent of location.
Threat data explains why this architecture is on the agenda. According to Verizon's 2025 Data Breach Investigations Report, vulnerability exploitation reached 20% as an initial access vector, and edge devices and VPNs accounted for 22% of those exploitation actions — almost eight times the previous year's 3% (Verizon DBIR, 2025). The same report measures that organizations were able to fully remediate only about 54% of their edge device vulnerabilities within the year, and that this took a median of 32 days. That is the price of making a single internet-facing VPN concentrator the doorway to enterprise access; FortiSASE removes that doorway and brings access down to the level of identity, device posture and application.
Sora Yazılım is a Fortinet authorized channel partner, and we position FortiSASE not in isolation but as part of the Fortinet Security Fabric architecture. On this page we explain, with sources, which components make up FortiSASE, how it is designed for remote worker and branch scenarios, its relationship with FortiClient, its contribution to KVKK (Turkey's data protection law) and PCI DSS programs, and the limits you should know before you buy.
Which security components does FortiSASE unify on a single platform?
FortiSASE brings together in a single service eight functions that would normally have to be purchased and integrated separately: SWG, ZTNA, CASB, FWaaS, SaaS security posture management (SSPM), secure browser, secure SD-WAN and end-to-end digital experience monitoring (DEM) (Fortinet, 2026). These eight are the most useful checklist when comparing solutions that carry the "SASE" label on the market: some competitors deliver the same capabilities through different SKUs, different consoles and different log formats. The practical benefit of the single-vendor model is that the same policy language and the same telemetry apply at the endpoint, in the cloud and in the branch.
| Component | Function | Typical use |
|---|
| SWG (Secure Web Gateway) | Inspection of web and TLS traffic for URL category, reputation and malicious content | Inspecting a remote user's internet egress without backhauling it to headquarters |
| ZTNA | Access at the application level rather than the network level, tied to identity and device posture | External access to on-premises ERP, file servers and management interfaces |
| CASB | Visibility into SaaS usage, data sharing and shadow IT control | Microsoft 365, Google Workspace and unsanctioned cloud applications |
| FWaaS | Full firewall and IPS inspection including non-web protocols | Branch internet egress, server-to-client traffic |
| SSPM | Continuous auditing of the configuration posture of SaaS tenants | Incorrect sharing permissions, weak authentication settings |
| Secure browser | Isolated browsing surface on non-corporate devices | Contractor, consultant and BYOD access |
| Secure SD-WAN | Application-aware routing and WAN redundancy | Reducing MPLS dependency in multi-branch estates |
| DEM (Digital Experience Monitoring) | Latency and loss measurement from the user all the way to the application | Root cause analysis of "the system is slow" complaints |
The threat intelligence behind these components comes from FortiGuard. The FortiSASE data sheet states that the web filtering engine classifies hundreds of millions of URLs into more than 90 categories and also analyzes TLS 1.3 traffic; on the application control side, more than 8,000 applications — including industrial control signatures — are identified and managed (FortiSASE Data Sheet, 2026). On the antivirus side, Fortinet reports that it produces 1.8 million new antivirus definitions per week using telemetry from a customer base of more than 830,000 (FortiSASE Data Sheet, 2026). At enterprise scale, FortiGuard Labs is stated to process and analyze more than 100 billion events per day (Fortinet, 2026).
Just as important as the component list is the fact that all of it reaches the endpoint through a single agent. In the FortiSASE architecture, FortiClient combines endpoint protection (EPP), ZTNA, SSE, CASB, DEM, Sandbox, vulnerability management and USB device control in the same client (FortiSASE Data Sheet, 2026). In practice, this means the end of three or four different security agents stacked on top of each other on laptops, along with the driver layers that break one another.
In a remote worker scenario, what does FortiSASE put in place of the classic VPN?
Short answer: identity instead of a tunnel, application access instead of network access. With classic remote access VPN, the user receives an IP address once authenticated and in practice lands inside a network segment; authorization is largely handled at the network layer. With FortiSASE, the user connects not to the network but to defined applications. The architecture has three parts: the FortiClient agent, the FortiSASE Endpoint Management Service and the ZTNA access proxy. FortiSASE applies ZTNA tagging rules to FortiClient; when an access request arrives, the ZTNA access proxy on the FortiGate grants or denies access based on the client certificate and those tags (Fortinet Document Library, 2026).
ZTNA was introduced with FortiOS 7.0 and its components were defined as FortiClient (the ZTNA agent), FortiClient EMS (identity and device posture) and FortiGate (the ZTNA application gateway) (Fortinet Document Library, FortiOS 7.0). FortiSASE moves the management plane of this trio into the cloud; an organization can apply the same ZTNA model without having to operate its own EMS server.
There is another reality that makes the transition mandatory: Fortinet has retired SSL-VPN on some entry-level platforms. The FortiGate 40F and 60F data sheets explicitly state that SSL-VPN is not supported on FortiOS 7.6.0 and above (FortiGate 60F Series Data Sheet, 2026). In other words, the "SSL-VPN works, let's not touch it" approach comes to an end by itself alongside the operating system upgrade calendar. That opens a planned window for moving remote access onto ZTNA or FortiSASE.
| Criterion | Classic remote access VPN | FortiSASE (SWG + ZTNA) |
|---|
| Unit of access | Network segment / IP range | Individual applications |
| Traffic path | All traffic is backhauled to headquarters | Internet and SaaS traffic egresses from the nearest security PoP |
| Device posture | Usually checked only at the moment of connection | Continuously evaluated through ZTNA tags |
| Attack surface | Internet-facing VPN portal | Published application and intermediary proxy |
| Lateral movement risk | High once the network is entered | Limited by per-application authorization |
| User experience measurement | Requires a separate tool | DEM is included in the platform |
| Capacity growth | Depends on sizing of central hardware | Scales by subscription as a cloud service |
The second major gain on the remote worker side concerns web- and email-borne attacks. ENISA Threat Landscape 2025 reports that across the 4,875 incidents it analyzed between 1 July 2024 and 30 June 2025, phishing was the dominant intrusion vector at 60% (ENISA Threat Landscape, 2025). When a phishing link is clicked outside the corporate network, the firewall at headquarters is not in the path; with FortiSASE, SWG policy is applied identically wherever the user happens to be. Likewise, Verizon measures that ransomware was present in 44% of breaches, rising to 88% among SMBs (Verizon DBIR, 2025).
In a branch scenario, how do FortiSASE and FortiGate work together?
In the branch, FortiSASE does not replace FortiGate; it divides the labor. The common setup, and the one we recommend, is this: a physical FortiGate in the branch handles local segmentation, LAN/WLAN control and SD-WAN routing, while traffic bound for the internet and SaaS is steered to a FortiSASE security PoP and passes through the same inspection as at headquarters. Instead of operating a heavy UTM licence set at every location, inspection is centralized in the cloud and the branch device focuses on its networking role.
This approach also has analyst backing: Fortinet announced that it was positioned as a Leader in the 2025 Gartner Magic Quadrant for SASE Platforms and that, in the same release, it ranked first in the "Secure Branch Network Modernization" use case in the Gartner Critical Capabilities for SASE Platforms report that complements the MQ (Fortinet, 2025). In other words, the area where the platform is strongest is precisely branch modernization. (For the change in position in the 2026 report, see the analyst section below.)
In small and medium-sized branches, hardware selection usually starts with desktop models such as the FortiGate 60F; the wireless and access layers can be brought under the same management umbrella. FortiAP access points are operated using one of three management models: FortiGate's integrated WLAN controller, the FortiEdge Cloud portal, or FortiSASE directly (FortiAP Series Data Sheet, 2026). At the access layer, the FortiLink protocol turns FortiSwitch into a logical extension of the FortiGate, and depending on the FortiGate model between 8 and 300 switches can be managed from a single interface (FortiSwitch Secure Access Data Sheet, 2026).
The secure SD-WAN component of FortiSASE comes into play for application-aware routing of branch traffic; because application control recognizes more than 8,000 applications, rules such as "let Microsoft 365 break out directly, send ERP through the tunnel, block file sharing" can be written on application identity rather than bandwidth (FortiSASE Data Sheet, 2026). As scale grows, the entire estate can be brought under central management: the FortiManager product page states that 100,000 Fortinet devices are supported, including FortiGate, FortiSwitch, FortiAP, SD-WAN and FortiSASE (Fortinet, 2026).
What exactly is the relationship between FortiClient and FortiSASE?
FortiClient is the agent and FortiSASE is the cloud service; the two are layers of the same product. Under a FortiSASE subscription, FortiClient is managed from the cloud by the FortiSASE Endpoint Management Service; policy, ZTNA tags and certificate distribution are handled through that service (Fortinet Document Library, 2026). If the organization also runs FortiClient EMS on premises, both management planes must be considered together in a hybrid model — this is one of the most critical design decisions in the project and must be settled up front.
Platform coverage is broad. According to the FortiClient data sheet, Windows 10/11 and Windows Server 2019 and later, macOS 10.15+, iOS 9.0+, Android 5.0+, Linux (Ubuntu 22.04+, Red Hat 9+, CentOS 9.0+) and all Chromebook versions are supported (FortiClient Data Sheet, 2025). Platforms are not equal, however: behavior-based ransomware protection and rollback are supported on Windows only, and the Linux build does not support Sandbox integration (FortiClient Data Sheet, 2025). Organizations managing a mixed fleet need to reflect these differences in their policy design.
There is a practical licensing detail to watch: under the FortiTrust user-based FortiClient licence, a single user can install FortiClient on at most three devices (FortiClient Data Sheet, 2025). For heavily mobile teams using laptop plus phone plus tablet, that limit directly affects the user count calculation. Because pricing varies with configuration and term, we do not publish prices on this page; ask for a quote configured to your current user count.
How does FortiSASE contribute to KVKK and PCI DSS compliance work?
FortiSASE is not a compliance certificate; it does, however, directly address several concrete controls that come up in audits. The Personal Data Security Guide (Technical and Administrative Measures) issued under KVKK (Turkey's data protection law) states that the primary measure is the firewall and gateway when protecting systems containing personal data against unauthorized access attempts arriving over the internet, and that these form the first line of defense; the same guide lists regular logging of all user transaction activity, along with regular vulnerability scanning and penetration testing, among the technical measures (KVKK Personal Data Security Guide, 2018). For a remote workforce, the "gateway" is no longer the device at headquarters but the SASE PoP the user connects to.
On the PCI DSS v4.0 side, the most directly relevant requirement is 1.5.1: security controls must be implemented on devices that can connect both to an untrusted network and to the cardholder data environment (CDE) — typically a remote worker's laptop. The standard also requires, in 1.4.1, that a network security control (NSC) be placed between trusted and untrusted networks (PCI Security Standards Council, PCI DSS v4.0). Note: in v4.0 the term "firewall" was replaced with Network Security Controls (NSC); using this terminology in audit correspondence will make your life easier. FortiSASE's device posture checking and application-level access are technical controls that can be used to meet these requirements.
On the service provider assurance side, FortiSASE holds SOC 2 Type II certification against the AICPA Trust Services criteria, and Fortinet states that it commits to a latency-guaranteed 99.999% SLA for security inspection (FortiSASE Data Sheet, 2026). The SOC 2 report is one of the documents typically requested in vendor assessment files and can be requested from Fortinet during the purchasing process.
On the audit trail side, log collection and reporting are critical. FortiAnalyzer offers ready-made compliance reports such as PCI-DSS and HIPAA and separates the log ingestion load through Analyzer/Collector modes (FortiAnalyzer Data Sheet, 2026). On the SaaS side, the CASB and SSPM components make visible which cloud application corporate data is going to — particularly on organization-wide platforms such as Microsoft 365, auditing sharing permissions and external shares closes one of the hardest parts of KVKK data inventory work. The log retention region and PoP region are chosen when the tenant is created; at project kick-off we confirm which regions are offered from Fortinet's current region list.
What is FortiSASE's analyst position and which limits should be known?
The honest answer: FortiSASE is strong but it is not the undisputed leader of the category, and Gartner's category definitions have changed several times in the last two years. The table below summarizes the current picture based on Fortinet's own announcements and its own Gartner Magic Quadrant page. We suggest you use this table in place of the "leader in every category" claim often seen in marketing presentations.
| Report | Year | Fortinet's position |
|---|
| Gartner MQ for Single-Vendor SASE | 2024 | Challenger |
| Gartner MQ for Security Service Edge (SSE) | 2025 | Challenger |
| Gartner MQ for SASE Platforms | 2025 | Leader |
| Gartner MQ for SASE Platforms | 2026 | Challenger |
The sources, in order: Challenger in the 2024 Single-Vendor SASE MQ (Fortinet, 2024), Challenger in the 2025 SSE MQ (Fortinet, 2025), Leader in the 2025 SASE Platforms MQ (Fortinet, 2025) and, on Fortinet's own Gartner MQ listing, Challenger for the 2026 SASE Platforms report (Fortinet, Gartner Magic Quadrants). So Fortinet rose to Leader in this category in 2025 and slipped back to Challenger in the 2026 report. On the network security side, by contrast, the position is different: Fortinet was positioned as a Leader in the 2025 Gartner Magic Quadrant for Hybrid Mesh Firewall (Fortinet, 2025). Knowing this distinction helps with the "where FortiGate, where FortiSASE" decision.
The second limit is PoP count and latency. Fortinet's FortiSASE product page speaks of a global network of more than 200 PoPs (Fortinet, August 2026); the FortiSASE data sheet, by contrast, gives no number and uses the phrase "hundreds of security PoPs" (FortiSASE Data Sheet, 2026). Because the PoP list changes over time, we do not promise a sourced latency figure measured from Turkey; instead, during the pilot phase we take real measurements from your own locations and report the results. The DEM component can be used directly for this user experience measurement.
The third limit is that the 99.999% SLA and similar commitments are the vendor's own statements; they are not measurements by an independent test organization. During contracting, the scope of the SLA, its exclusions and its remedy mechanism should be read separately. Fourth, the FortiSASE roadmap moves in step with FortiOS: with FortiOS 8.0, announced on 10 March 2026, Fortinet introduced FortiView for shadow-AI detection, AI-aware application control, Model Context Protocol visibility, OCR-enabled DLP and post-quantum cryptography controls (Fortinet, 2026). If governing enterprise AI tools is on your agenda, clarify before purchase which release will bring these capabilities to your subscription. We also carry out a comparative assessment against our other security solutions.
Finally, the pace on the threat side: according to Fortinet's 2026 Global Threat Landscape Report, time-to-exploit on critical advisories has dropped to 24–48 hours and global exploitation attempts rose 25.49% year over year (Fortinet, 2026). The same report states that the number of confirmed ransomware victims reached 7,831 in 2025, which represents a 389% increase over the previous report (Fortinet, 2026). At that tempo, applying security updates centrally on the cloud side is the most concrete operational advantage of the SASE model.
How is a FortiSASE project sized and through which steps is it rolled out?
Sizing starts with two questions: how many users and which traffic will pass through SASE. The user count determines subscription volume; the traffic scope determines policy design. In practice, most organizations do not move everything to the cloud on day one; the phased plan below lowers both risk and the likelihood of an outage.
| Phase | Scope | Output |
|---|
| 1. Inventory and discovery | User groups, device fleet, internal applications to be published, current VPN usage | Application-to-user access matrix |
| 2. Tenant and identity | FortiSASE tenant, identity provider federation, user/group mapping, region selection | Working sign-on flow |
| 3. Pilot (SWG) | Inspection of internet egress for a limited user group, latency measurement | Performance report with real measurements |
| 4. ZTNA publication | Publishing the 3–5 priority internal applications via ZTNA, device posture rules | Application access without VPN |
| 5. CASB and SSPM | SaaS visibility, data sharing rules, configuration posture auditing | Shadow IT inventory and remediation list |
| 6. Branch integration | Steering the FortiGates to SASE, SD-WAN policies | One policy for branch and remote user |
| 7. Retiring the VPN | Shutting down remaining VPN usage, handover of logging and reporting | Reduced attack surface |
Sora Yazılım is involved in every one of these steps: needs analysis and user sizing, licensing, tenant setup, identity integration, ZTNA application publication, migration from the existing VPN, staff training and post-deployment managed service. For infrastructure work on the cloud and automation side we position our DevOps and infrastructure services within the same project; when a ZTNA gateway is needed in the data center or cloud, we deploy virtually with FortiGate-VM. We run the entire engagement with Turkish documentation and local support.
The most frequently overlooked topic during evaluation is aligning existing contracts. There may be capability overlap between FortiClient EMS, FortiGate UTM subscriptions and the FortiSASE subscription; the right design is not to buy the same capability twice. If you share your current Fortinet inventory and renewal dates, we will identify the overlaps and propose a structure containing only the components you actually need.
To move your remote worker and branch access onto a single policy with FortiSASE, all you need to do is share your user count, location distribution and the internal applications you want to publish. We will review your existing VPN setup and prepare a proposal covering the migration plan, pilot scope and licence configuration; because pricing is shaped by user count and term, we produce the configured quote specifically for the project. Contact us through our contact page and our technical team will schedule a discovery call within the same week.