The Question
SASE consolidation is genuinely compelling. Replace four to six point products with one platform, eliminate the integration overhead, and capture a meaningful discount from a single vendor. Every major analyst firm positions SASE as the direction enterprise networking and security are heading. The problem is that consolidation and lock-in are not separate phenomena — they are the same economic mechanism viewed from different angles.
When a vendor offers you a 30% discount to bundle their SD-WAN, SWG, CASB, ZTNA, and DLP under a single contract, they are not being generous. They are making it economically painful to disaggregate the stack later. The proprietary policy formats, the hardware appliances with vendor-specific firmware, the SD-WAN tunnels using protocols that don't interoperate with other platforms — these are features from the vendor's perspective and liabilities from yours.
Enterprise buyers who approach SASE procurement the same way they approach traditional software licensing end up signing contracts that look like good deals on day one and feel like traps in year three.
SASE's consolidation value proposition and its lock-in risk are the same thing — understanding both is what separates buyers who negotiate good contracts from those who discover the exit costs after signing.
Why This Matters Now
In Q3 2024, a major financial services institution completed a two-year migration off a leading SASE platform — a migration that cost an estimated $4.2 million in professional services, retraining, and parallel-run infrastructure, according to reporting from network security trade publications. The migration was triggered by a pricing dispute at contract renewal, but the cost of leaving was so high that the institution had effectively lost all negotiating leverage. They renewed on the vendor's terms.
This is not an isolated case. As SASE contracts signed during the 2021–2023 consolidation wave have come up for renewal, enterprise security teams have discovered that the operational dependencies they built over three years — the policy structures, the agent configurations, the branch appliance deployments — created switching costs that weren't visible when they signed.
The market dynamics are reinforcing this trend. Gartner's 2025 Market Guide for SSE noted that incumbent advantage was the primary factor in over 60% of SASE renewals, citing operational dependency rather than product satisfaction as the leading driver of retention. Vendors know this, and their product roadmaps reflect it: features that deepen integration within the platform stack are prioritized over features that would make the platform easier to disaggregate.
The regulatory dimension adds a second pressure. SOC 2, PCI DSS, and HIPAA compliance postures built on a single SASE vendor's logging, policy, and audit trail infrastructure create compliance dependencies that make migration even more complex than the pure technical switching cost.
What the CURVE™ Data Shows
The 2026 Stackcurve SASE/SSE CURVE™ Report evaluated the major SASE platforms across a portability dimension that most analyst frameworks omit entirely. The findings are significant.
Cato Networks scores highest on policy portability, with a documented JSON-based policy export format and publicly available migration guides. Zscaler supports policy export for ZIA configurations but uses a proprietary format that requires transformation tooling to migrate to competing platforms — a gap the company has not publicly committed to closing. Palo Alto Networks Prisma SASE policy format reflects the architectural complexity of its acquisition-driven build: CloudGenix SD-WAN policies and Prisma Access SSE policies live in different consoles with different export mechanisms.
On the hardware dependency dimension, vendors that require proprietary edge appliances for SD-WAN — including some Cisco and Fortinet SASE configurations — create a physical infrastructure lock-in layer that compounds the software switching cost. Cato and Zscaler, both cloud-native, avoid this exposure entirely for the SSE layer, though SD-WAN edge still requires hardware considerations.
The CURVE™ analysis found that enterprises that negotiated explicit portability provisions at contract signing — including policy export commitments, API access guarantees, and data export SLAs — consistently reported better renewal negotiating leverage.
The full vendor rankings are in the 2026 Stackcurve SASE/SSE CURVE™ Report — free to download.
The Gap Most Buyers Miss
Most SASE procurement teams evaluate lock-in risk too narrowly, focusing only on contract terms. The deeper lock-in mechanisms are technical and operational — and they don't appear in the vendor's sales materials.
Policy format portability
Every major SASE vendor uses a proprietary policy representation. Zscaler's ZIA and ZPA policy engines store rules in formats that are not exportable in a vendor-neutral schema. Palo Alto Prisma SASE policy is expressed in Panorama-derived XML that requires significant transformation to migrate. When you have invested 18 months building and tuning your URL filtering policies, your DLP rules, your ZTNA access policies, and your SD-WAN traffic steering rules — none of that work is portable without a migration project.
Ask every vendor before signing: "If we migrate away from your platform in three years, can we export our complete policy set in a format that reduces our migration effort?" The quality of the answer tells you a great deal about their portability posture.
Component disaggregation
SASE is sold as a bundle. The question buyers rarely ask is: if we want to replace one component, do we have to replace all of them?
Zscaler has built an ecosystem of SD-WAN partnerships (Cisco Meraki, Fortinet, Aruba, Silver Peak) specifically because they don't offer native SD-WAN. This is actually a portability advantage — you can replace Zscaler's SSE without touching your SD-WAN, and you can replace your SD-WAN without touching Zscaler's SSE. Palo Alto Prisma SASE's bundled architecture creates tighter interdependencies that make component-level replacement harder.
Evaluate explicitly: If we replace the SD-WAN component, can we keep the SSE? If we replace the SSE, can we keep the SD-WAN?
Contractual consolidation discounts
The discount you receive for bundling is typically structured so that removing any component triggers reprice of the entire contract. This is the consolidation discount as a lock-in mechanism: it's not that disaggregation is technically impossible, it's that disaggregation is economically painful even when technically possible.
Negotiate this provision directly. Request contract language that guarantees component-level pricing that does not reprice the remaining bundle if you remove one element. Vendors who won't negotiate this clause are telling you something important about their lock-in intent.
Data portability and audit trail continuity
If your logging, SIEM integration, and compliance audit trail are built on the SASE vendor's native logging infrastructure, migration means rebuilding three years of compliance documentation. Require standard log formats (CEF or LEEF) and direct SIEM forwarding from contract inception.
Questions Your Buying Team Should Be Asking
1. What is the documented process for exporting our complete security policy — URL filters, DLP rules, ZTNA access policies, and SD-WAN steering rules — if we decide to migrate to a different platform?
Vendors with mature portability posture have documented migration guides and export utilities. Vendors with weak portability posture will give you a vague answer about professional services. The quality of this answer is a direct indicator of your future negotiating leverage.
2. If we want to replace your SD-WAN component with a third-party SD-WAN three years from now, will your SSE pricing and contract remain unaffected?
This question surfaces the consolidation discount trap. Require explicit contract language — not a verbal commitment from your account executive — that addresses component-level disaggregation pricing.
3. Does your platform support standard log formats (CEF, LEEF, or equivalent) with direct SIEM forwarding, so our logging infrastructure is not dependent on your proprietary log management?
Logging dependency is often overlooked until migration, when it becomes one of the most expensive components of the switch.
4. Which SD-WAN vendors publish certified integration guides with your SSE platform, and what specifically is supported versus constrained in those integrations?
Zscaler's SD-WAN integration ecosystem is its primary defense against SD-WAN lock-in. Ask every SSE vendor to be specific about what works and what doesn't in their third-party SD-WAN integrations — particularly around policy enforcement consistency across the integration boundary.
5. What are the exit provisions in your standard enterprise contract — specifically, what are the penalties for early termination, and what data and configuration export assistance do you contractually commit to providing?
Exit provisions are negotiable at signing and non-negotiable once the contract is executed. Require 90-day notice provisions, full data export assistance at no additional charge, and explicit prohibition on vendor-side data deletion before a defined post-termination period.
The Stackcurve Take
SASE lock-in is a structural feature of the market, not a bug in specific vendor contracts. The business model of SASE consolidation depends on switching costs being high enough to anchor renewals. Vendors who offer the deepest discounts for bundling are, in most cases, the vendors who are most confident their switching costs will hold.
This doesn't mean SASE consolidation is a bad decision — for most enterprises, the cost savings, operational simplification, and security improvement are genuine and significant. It means the procurement strategy needs to account for exit optionality from the beginning.
The buyers who negotiate the best SASE contracts are not the ones who threaten to leave — they're the ones who, at signing, establish the technical and contractual conditions under which leaving would be feasible. That credibility changes the renewal conversation three years later.
Portability provisions, component-level pricing guarantees, standard log format requirements, and documented policy export processes are not nice-to-haves. They are the difference between a SASE investment that gives you leverage and one that eliminates it.
The 2026 Stackcurve SASE/SSE CURVE™ Report covers platform portability, component disaggregation, and contractual lock-in risk across all major SASE vendors. Download it free →
Stackcurve Advisory Briefs are independent research. No vendor pays for placement, tier assignment, or editorial influence. The CURVE™ methodology is disclosed in full at stackcurve.net/research/methodology.