The Question
Your procurement team has issued a SASE RFP. The vendor responses arrive. Each one is between 80 and 120 pages. Each one claims to be the market leader. Each one checks every box you included in the requirements matrix.
You read through the Zscaler response and the Palo Alto response and the Netskope response and the Cato response. They are indistinguishable. The capabilities section describes the same features in slightly different language. The architecture diagrams have different colors but the same topology. The customer reference lists include the Fortune 500 logos in different orders.
This is not a coincidence. Generic SASE RFPs produce this result by design. When you ask "Does your platform support ZTNA?", every vendor answers yes. When you ask "Does your platform support Cloud SWG?", every vendor answers yes. When you ask "Does your platform support CASB?", every vendor answers yes.
The RFP has not filtered anything. It has collected proposals from vendors who are good at writing proposals. The vendor who wins a generic SASE RFP is the vendor with the best proposal writer, not the vendor with the best platform.
An RFP that vendors can answer in four hours with boilerplate is an RFP that selects for proposal quality, not platform quality.
Why This Matters Now
In 2025, a large financial services firm completed a SASE procurement using what its CISO later described as a "checkbox RFP." The winning vendor scored highest on the requirements matrix because every single requirement was framed as a yes/no capability question.
The deployment began. Within 90 days, the project team discovered that the vendor's TLS inspection throughput was insufficient for the firm's traffic volume — a limitation that had never appeared in the RFP response because throughput was not a scored requirement. The vendor's DLP was generating false positives on financial data at a rate that made the legal team demand a DLP bypass for an entire application category. The CASB's SaaS application library had limited coverage for the firm's fintech applications, which appeared as uncategorized traffic.
None of these gaps would have been hidden by a sophisticated vendor in a well-structured RFP process. They were hidden by the structure of the RFP itself. The questions did not exist, so the answers were never provided.
The firm spent an additional eight months in remediation, including a partial platform re-deployment and a separate DLP tuning engagement. Total additional cost was estimated at $1.2 million beyond the original contract value.
This incident illustrates the downstream cost of procurement process failure. A SASE RFP that does not filter for real capability does not just select the wrong vendor — it creates a deployment that underperforms and then requires expensive remediation. The RFP is the most important document in the SASE procurement process.
What the CURVE™ Data Shows
The 2026 Stackcurve SASE/SSE CURVE™ Report includes a procurement process evaluation dimension that assessed how well each vendor's sales and technical teams responded to capability-specific, technically demanding questions.
The findings were consistent with what procurement teams report in the field: vendors who perform well in detailed technical evaluations are not always the same vendors who perform well in generic RFP responses. Zscaler and Palo Alto Prisma Access performed consistently well across both RFP-style and technical deep-dive evaluations. Cato Networks showed strong technical transparency on WAN architecture questions but had less detailed responses on DLP accuracy. Netskope's responses were technically precise on CASB and DLP questions but less detailed on SD-WAN integration scenarios.
Cloudflare One showed strong capability on ZTNA and SWG questions but acknowledged limitations on private WAN replacement — a differentiation that only appeared when asked directly.
The CURVE™ Report scoring includes vendor-specific assessment of DLP false positive rates, TLS inspection throughput benchmarks, and CASB application library coverage depth — data that does not appear in any vendor's standard RFP response.
The full vendor rankings are in the 2026 Stackcurve SASE/SSE CURVE™ Report — free to download.
The Gap Most Buyers Miss
The most effective SASE RFP questions are the ones that require the vendor to describe their architecture, not confirm a capability. Here is a section-by-section framework for RFP questions that actually differentiate.
1. Architecture Questions
Ask: "Is your SSE stack born-in-cloud or is it an acquisition integration? If the latter, identify the acquisition and the integration timeline."
Ask: "Describe the architecture of your private backbone: number of Points of Presence, peering relationships with major cloud providers (AWS, Azure, GCP), and your latency SLA by region for the regions relevant to our workforce."
Ask: "What happens to user traffic if your nearest PoP goes offline? What is the automatic failover path and what is the documented latency impact?"
These questions cannot be answered with boilerplate. The vendor must describe their actual architecture.
2. TLS Inspection
Ask: "What is your TLS inspection throughput per node, and what is your documented throughput degradation when TLS inspection is enabled versus disabled?"
Ask: "What percentage of your enterprise customer base has TLS inspection enabled?"
Ask: "What is your recommended bypass policy for regulated domains (financial data regulators, health data systems)? Provide your standard bypass list and describe how we customize it."
TLS inspection throughput is one of the most consistent performance differentiators between SASE vendors and one of the least-asked RFP questions.
3. DLP Accuracy
Ask: "What is your false positive rate for [your specific data type — source code, financial data, PII] detection using your default policy? Provide results from an independent DLP accuracy test or allow us to run a controlled accuracy test with synthetic data."
Ask: "Describe your DLP policy tuning process. What is the typical engagement required from your team versus our team to tune a DLP policy from out-of-box to production accuracy?"
4. AI and ML Tool Governance
Ask: "How does your CASB classify AI tools such as ChatGPT Enterprise, GitHub Copilot, Anthropic Claude, and Cursor? Are these in your app library, and what DLP coverage do you provide for AI-bound traffic?"
Ask: "Describe how your platform detects sensitive data in natural language queries sent to AI assistants, as opposed to structured PII patterns in file transfers."
5. Incident Response
Ask: "Walk us through your SASE-layer incident response workflow for a detected data exfiltration event. What is the timeline from detection to analyst notification? What is your SOAR integration capability?"
Reference Requirements That Filter
Require a minimum of three customer references in your industry vertical with a similar WAN profile: comparable number of branch locations, comparable percentage of remote workers, and comparable cloud-first vs. hybrid application profile. References must be available for a 30-minute call — written testimonials do not qualify. References must be reachable within 10 business days of RFP award.
This reference requirement alone eliminates vendors who are new to your industry vertical and vendors who cannot produce satisfied customers willing to speak.
Questions Your Buying Team Should Be Asking
1. What is your TLS inspection throughput per node under production load, and do you have independent benchmark data we can review before award?
This question surfaces one of the most common hidden performance bottlenecks in SASE deployments. Every vendor claims high performance; few have independent benchmark data. Asking for it before award changes the vendor's incentive to be precise.
2. What percentage of the AI tools our research team has identified as high-risk are currently in your CASB application library with DLP coverage?
Provide the vendor with your actual list of AI tools used in your environment before the RFP is issued. This turns an abstract capability question into a concrete coverage test.
3. Describe a deployment failure you have had with a customer in our industry vertical and what the resolution was.
This question is almost never asked in RFPs and almost always produces the most useful information. Vendors who answer this question honestly reveal their real-world failure modes. Vendors who refuse to answer it reveal something else.
4. What is your documented process for managing TLS inspection bypass policies for regulated data categories, and which of your enterprise customers in regulated industries can serve as a reference for that process?
Bypass policy management is an ongoing operational challenge that most customers do not anticipate at procurement. A vendor with a mature bypass management process has learned this lesson from their customer base.
5. If we selected you today and began deployment in 90 days, what are the top three implementation risks for our environment profile, and how would you mitigate them?
This question asks the vendor to think like an implementation partner rather than a sales team. Vendors who can give a specific, honest answer to this question are vendors who have actually deployed their platform at scale.
The Stackcurve Take
The SASE market has matured to the point where every major vendor has a complete feature set on paper. The differentiation is in depth of implementation, performance under load, accuracy of data controls, and quality of operational support. None of these differentiators appear in a checkbox RFP.
The organizations that run the most effective SASE procurements treat the RFP as a technical evaluation, not a compliance exercise. They build their question set around the specific risks and requirements of their environment — TLS inspection load, DLP data types, AI tool governance, industry compliance requirements — and they require vendors to answer with specifics, not generalities.
The result is a procurement that selects the platform that will actually perform, rather than the proposal that looks the best.
The 2026 Stackcurve SASE/SSE CURVE™ Report covers vendor-by-vendor capability depth across all major SASE functional areas. Download it free →
Stackcurve Advisory Briefs are independent research. No vendor pays for placement, tier assignment, or editorial influence. The CURVE™ methodology is disclosed in full at stackcurve.net/research/methodology.