What Is SASE (Secure Access Service Edge)? A Beginner’s Guide

Share
What Is SASE (Secure Access Service Edge)? A Beginner’s Guide
7:05

A plain-language introduction to SASE — with authoritative resources from CISA and NIST to go deeper.

The short answer: SASE (Secure Access Service Edge) is a cloud-delivered model that converges networking (SD-WAN) and security (SSE) into a single service. Gartner coined the term in 2019; the concept is built on Zero Trust principles defined in NIST SP 800-207. Most organizations don’t deploy the full stack at once — they adopt SASE gradually, often starting with Zero Trust network access and secure site connectivity.

 

If SSE is the security half of modern cloud access, SASE (Secure Access Service Edge) is the whole picture: networking and security delivered together as one cloud service. This guide explains what SASE is, what it includes, its guiding principles, and where to learn more from trusted public sources.

SASE in one sentence

Gartner analyst Neil MacDonald coined the term in 2019 (pronounced "sassy"). Gartner defines it as:

“Secure access service edge (SASE) delivers converged network and security as a service capabilities, including SD-WAN, SWG, CASB, NGFW and zero trust network access (ZTNA). SASE supports branch office, remote worker and on-premises secure access use cases.”

In plain terms: instead of buying separate boxes for networking and separate boxes for security, SASE merges both into a single, cloud-delivered service that follows users and sites wherever they are.

The two halves of SASE

SASE is best understood as a simple equation: SASE = networking + security.

Networking (SD-WAN): Software-defined wide-area networking connects sites, branches, and cloud resources, and steers traffic over the best available path for performance and resilience.

Security (SSE): The Security Service Edge stack, which Gartner’s market definition typically describes as Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), Zero Trust Network Access (ZTNA), and Firewall as a Service (FWaaS / NGFW). OpenVPN’s own Cyber Shield is one concrete example of this convergence in practice: it layers content filtering (43 categories) and intrusion prevention directly into CloudConnexa’s access stack, at no extra licensing tier.

Put differently: SASE = SSE + SD-WAN. Keep in mind that SASE and SSE are analyst-defined market categories from Gartner, not formal standards — the normative foundations beneath them are NIST SP 800-207 (Zero Trust) and the CISA Zero Trust Maturity Model.

openvpn_ztna-research-report_email_800x200

The four key principles of SASE

  1. Convergence: Networking and security functions are combined into one integrated service instead of stitched-together point products.

  2. Cloud-delivered: Capabilities are delivered as a service from the edge/cloud rather than from on-premises appliances.

  3. Identity-driven: Access policy is based on the identity of the user and device, not on network location — for example, device posture policies that continuously verify a device meets security requirements before granting or keeping access.

  4. Globally distributed: Policy is enforced close to the user, wherever they connect, to reduce latency and exposure.

Where to begin: Most organizations don’t deploy SASE all at once. A common starting point is consolidating remote access and site connectivity onto a single Zero Trust platform. OpenVPN’s CloudConnexa brings together secure networking and built-in ZTNA essentials — a practical foundation for an evolving SASE strategy, especially for small and mid-sized teams.

Authoritative resources to learn more

SASE is grounded in Zero Trust principles defined by public-sector authorities. These free resources are the best places to build a solid foundation:



Ready to see how OpenVPN can help protect your organization from attacks?

Try the self-hosted Access Server solution or the managed CloudConnexa service for free, no credit card required.

See Which One is Right for You

Frequently asked questions

What is SASE?

SASE is a cloud-delivered model that converges networking (SD-WAN) and security (SSE) into a single service supporting branch, remote, and on-premises access. Gartner coined the term in 2019.

What is the difference between SASE and SSE?

SSE is the security half (SWG, CASB, ZTNA, FWaaS). SASE adds the networking half (SD-WAN). SASE = SSE + networking. See the full SSE breakdown for a deeper look at the security side on its own.

How does SASE relate to Zero Trust Network Access (ZTNA)?

ZTNA is one of the security services SASE converges — it’s the component that replaces implicit network trust with identity- and context-based access to specific applications. Read how ZTNA works for the mechanics, or the full SASE vs. ZTNA comparison for how the two fit together in a rollout.

Do I need to deploy SASE all at once?

No. Most organizations adopt SASE incrementally — often starting with Zero Trust access and secure site connectivity, then expanding.

Is SASE only for large enterprises?

No. The convergence and cloud-delivery principles of SASE are especially valuable to small and mid-sized businesses that want enterprise-grade security without managing a rack of appliances.

Is SASE a single product I can buy?

Not exactly. SASE is a market category and architectural model, not one product with a fixed feature list — vendors package the SD-WAN and SSE components differently. Evaluate any SASE offering against the four principles above rather than a vendor’s marketing checklist alone.


Build your SASE foundation

Explore how CloudConnexa unifies secure networking and Zero Trust access in one easy-to-deploy platform.

Learn More Our Products

Further reading

Sources: Gartner IT Glossary; NIST SP 800-207; NIST SP 1800-35; NIST CSF 2.0; CISA Zero Trust Maturity Model v2.0; CISA Trusted Internet Connections (TIC) 3.0. This article is educational and references publicly available guidance from CISA and NIST.

Related posts from OpenVPN

Subscribe for Blog Updates