---
title: What Is SASE (Secure Access Service Edge)? A Beginner’s Guide
description: New to SASE? A plain-language guide to Secure Access Service Edge — what it means, its four core principles, and how it connects to SSE and Zero Trust.
image: https://blog.openvpn.net/hubfs/Blog_Insights_Blue_Dark.png
---

- [Blog](https://blog.openvpn.net)
- [Cybersecurity](https://blog.openvpn.net/tag/cybersecurity)
- [Network Security Tools](https://blog.openvpn.net/tag/network-security-tools)

# What Is SASE (Secure Access Service Edge)? A Beginner’s Guide

Sep 14, 2026 •  5 min read

![](https://blog.openvpn.net/hubfs/Blog_Insights_Blue_Dark.png)

Share

- <https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fblog.openvpn.net%2Fwhat-is-sase-secure-access-service-edge&title=What%20Is%20SASE%20%28Secure%20Access%20Service%20Edge%29%3F%20A%20Beginner%E2%80%99s%20Guide&summary=New+to+SASE%3F+A+plain-language+guide+to+Secure+Access+Service+Edge+%E2%80%94+what+it+means%2C+its+four+core+principles%2C+and+how+it+connects+to+SSE+and+Zero+Trust.&source=>
- <https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fblog.openvpn.net%2Fwhat-is-sase-secure-access-service-edge>
- <https://twitter.com/intent/tweet?url=https%3A%2F%2Fblog.openvpn.net%2Fwhat-is-sase-secure-access-service-edge&text=What+Is+SASE+%28Secure+Access+Service+Edge%29%3F+A+Beginner%E2%80%99s+Guide>
- <https://blog.openvpn.net/what-is-sase-secure-access-service-edge>

What Is SASE (Secure Access Service Edge)? A Beginner’s Guide

7:05

By Rohit Kalbag

A plain-language introduction to SASE — with authoritative resources from CISA and NIST to go deeper.

| The short answer: SASE (Secure Access Service Edge) is a cloud-delivered model that converges networking (SD-WAN) and security (SSE) into a single service. Gartner coined the term in 2019; the concept is built on Zero Trust principles defined in NIST SP 800-207. Most organizations don’t deploy the full stack at once — they adopt SASE gradually, often starting with Zero Trust network access and secure site connectivity. |
| --- |

 

If SSE is the security half of modern cloud access, SASE (Secure Access Service Edge) is the whole picture: networking and security delivered together as one cloud service. This guide explains what SASE is, what it includes, its guiding principles, and where to learn more from trusted public sources.

## SASE in one sentence

Gartner analyst Neil MacDonald coined the term in 2019 (pronounced "sassy"). Gartner defines it as:

“Secure access service edge (SASE) delivers converged network and security as a service capabilities, including SD-WAN, SWG, CASB, NGFW and zero trust network access (ZTNA). SASE supports branch office, remote worker and on-premises secure access use cases.”

In plain terms: instead of buying separate boxes for networking and separate boxes for security, SASE merges both into a single, cloud-delivered service that follows users and sites wherever they are.

## The two halves of SASE

SASE is best understood as a simple equation: SASE = networking + security.

Networking (SD-WAN): Software-defined wide-area networking connects sites, branches, and cloud resources, and steers traffic over the best available path for performance and resilience.

Security (SSE): The [Security Service Edge](https://blog.openvpn.net/what-is-security-service-edge-sse/) stack, which Gartner’s market definition typically describes as Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), [Zero Trust Network Access (ZTNA)](https://blog.openvpn.net/how-does-ztna-work/), and Firewall as a Service (FWaaS / NGFW). OpenVPN’s own [Cyber Shield](https://openvpn.net/cloud-vpn/cyber-shield/) is one concrete example of this convergence in practice: it layers content filtering (43 categories) and intrusion prevention directly into CloudConnexa’s access stack, at no extra licensing tier.

Put differently: SASE = SSE + SD-WAN. Keep in mind that SASE and SSE are analyst-defined market categories from Gartner, not formal standards — the normative foundations beneath them are [NIST SP 800-207 (Zero Trust)](https://csrc.nist.gov/pubs/sp/800/207/final) and the [CISA Zero Trust Maturity Model](https://www.cisa.gov/resources-tools/resources/zero-trust-maturity-model).

[![openvpn\_ztna-research-report\_email\_800x200](https://blog.openvpn.net/hs-fs/hubfs/openvpn_ztna-research-report_email_800x200.png?width=2500&height=625&name=openvpn_ztna-research-report_email_800x200.png)](https://go.openvpn.net/ztna-research-report-2026)

## The four key principles of SASE

1. Convergence: Networking and security functions are combined into one integrated service instead of stitched-together point products.
2. Cloud-delivered: Capabilities are delivered as a service from the edge/cloud rather than from on-premises appliances.
3. Identity-driven: Access policy is based on the identity of the user and device, not on network location — for example, [device posture policies](https://openvpn.net/cloud-vpn/features/device-posture/) that continuously verify a device meets security requirements before granting or keeping access.
4. Globally distributed: Policy is enforced close to the user, wherever they connect, to reduce latency and exposure.

Where to begin: Most organizations don’t deploy SASE all at once. A common starting point is consolidating remote access and site connectivity onto a single Zero Trust platform. OpenVPN’s [CloudConnexa](https://openvpn.net/cloud-vpn/) brings together secure networking and built-in ZTNA essentials — a practical foundation for an evolving SASE strategy, especially for small and mid-sized teams.

## Authoritative resources to learn more

SASE is grounded in Zero Trust principles defined by public-sector authorities. These free resources are the best places to build a solid foundation:

- [NIST SP 800-207, Zero Trust Architecture](https://csrc.nist.gov/pubs/sp/800/207/final) — the foundational definition of Zero Trust and its seven tenets, the conceptual backbone of SASE’s identity-driven model.
- [CISA Zero Trust Maturity Model (v2.0)](https://www.cisa.gov/resources-tools/resources/zero-trust-maturity-model) — a roadmap across five pillars (Identity, Devices, Networks, Applications & Workloads, Data) and four maturity stages.
- [CISA Trusted Internet Connections (TIC) 3.0](https://www.cisa.gov/resources-tools/programs/trusted-internet-connections-tic) — modernized guidance for securing cloud, mobile, and remote-user connectivity, with reference architectures highly relevant to SASE.
- [NIST SP 1800-35, Implementing a Zero Trust Architecture](https://csrc.nist.gov/pubs/sp/1800/35/final) — a hands-on NCCoE practice guide finalized in 2025.
- [NIST Cybersecurity Framework 2.0](https://www.nist.gov/cyberframework) — the 2024 update adding a "Govern" function, useful for SASE governance.
- [Gartner glossary: SASE](https://www.gartner.com/en/information-technology/glossary/secure-access-service-edge-sase) — the canonical analyst definition.

### Ready to see how OpenVPN can help protect your organization from attacks?

Try the self-hosted Access Server solution or the managed CloudConnexa service for free, no credit card required.

[See Which One is Right for You](https://openvpn.net/product-comparison/?_gl=1*1hi46u*_ga*NDgyODEwNDkyLjE3NzIxMjIzNDE.*_ga_E45Z33NTV7*czE3Nzc5ODY2ODIkbzExMiRnMSR0MTc3Nzk4ODMyMSRqNTUkbDAkaDE4NzIyNTczNDc.*_fplc*dVltNzJ6YmZ0bFZTdld4NjRtWVpVWXclMkJEV3AzZGhPUlRZaUppdWNxQkRjOER3MFN0VW84JTJCdEJGdnRDTmVYNlI5NlJBdTRLZ0VGOTNHMHc0U3l3bVFsR3NzQXk5RzJIQVdzNHE0QVJHcSUyQlVKUlRsNTM0S1RWZERyZ0V4NDNnJTNEJTNE*_gcl_au*MTM5NjEwNTIxNy4xNzcyMTIyMzQx*_ga_SPGM8Y8Y79*czE3Nzc5ODY2ODEkbzExMyRnMSR0MTc3Nzk4ODMyMyRqNTMkbDAkaDA.)

## Frequently asked questions

### What is SASE?

SASE is a cloud-delivered model that converges networking (SD-WAN) and security (SSE) into a single service supporting branch, remote, and on-premises access. Gartner coined the term in 2019.

### What is the difference between SASE and SSE?

SSE is the security half (SWG, CASB, ZTNA, FWaaS). SASE adds the networking half (SD-WAN). SASE = SSE + networking. See [the full SSE breakdown](https://blog.openvpn.net/what-is-security-service-edge-sse/) for a deeper look at the security side on its own.

### How does SASE relate to Zero Trust Network Access (ZTNA)?

ZTNA is one of the security services SASE converges — it’s the component that replaces implicit network trust with identity- and context-based access to specific applications. Read [how ZTNA works](https://blog.openvpn.net/how-does-ztna-work/) for the mechanics, or [the full SASE vs. ZTNA comparison](https://blog.openvpn.net/ztna-for-sase-roadmap/) for how the two fit together in a rollout.

### Do I need to deploy SASE all at once?

No. Most organizations adopt SASE incrementally — often starting with Zero Trust access and secure site connectivity, then expanding.

### Is SASE only for large enterprises?

No. The convergence and cloud-delivery principles of SASE are especially valuable to small and mid-sized businesses that want enterprise-grade security without managing a rack of appliances.

### Is SASE a single product I can buy?

Not exactly. SASE is a market category and architectural model, not one product with a fixed feature list — vendors package the SD-WAN and SSE components differently. Evaluate any SASE offering against the four principles above rather than a vendor’s marketing checklist alone.

### Build your SASE foundation

Explore how [CloudConnexa](https://openvpn.net/cloud-vpn/) unifies secure networking and Zero Trust access in one easy-to-deploy platform.

[Learn More Our Products](https://openvpn.net/product-comparison/?_gl=1*1hi46u*_ga*NDgyODEwNDkyLjE3NzIxMjIzNDE.*_ga_E45Z33NTV7*czE3Nzc5ODY2ODIkbzExMiRnMSR0MTc3Nzk4ODMyMSRqNTUkbDAkaDE4NzIyNTczNDc.*_fplc*dVltNzJ6YmZ0bFZTdld4NjRtWVpVWXclMkJEV3AzZGhPUlRZaUppdWNxQkRjOER3MFN0VW84JTJCdEJGdnRDTmVYNlI5NlJBdTRLZ0VGOTNHMHc0U3l3bVFsR3NzQXk5RzJIQVdzNHE0QVJHcSUyQlVKUlRsNTM0S1RWZERyZ0V4NDNnJTNEJTNE*_gcl_au*MTM5NjEwNTIxNy4xNzcyMTIyMzQx*_ga_SPGM8Y8Y79*czE3Nzc5ODY2ODEkbzExMyRnMSR0MTc3Nzk4ODMyMyRqNTMkbDAkaDA.)

### Further reading

- [Best SASE Solutions: What to Choose in 2026](https://blog.openvpn.net/best-sase-solution)
- [What Are the Top SASE Use Cases?](https://blog.openvpn.net/what-are-the-top-sase-use-cases-openvpn)
- [VPN’s Role in SASE](https://blog.openvpn.net/vpn-role-in-sase)
- [SASE vs. ZTNA: What You Need to Know](https://blog.openvpn.net/ztna-for-sase-roadmap)
- [Comparing OpenVPN CloudConnexa and Check Point Harmony SASE](https://blog.openvpn.net/comparing-openvpn-cloudconnexa-and-check-point-harmony-sase)

*Sources: Gartner IT Glossary; NIST SP 800-207; NIST SP 1800-35; NIST CSF 2.0; CISA Zero Trust Maturity Model v2.0; CISA Trusted Internet Connections (TIC) 3.0. This article is educational and references publicly available guidance from CISA and NIST.*

## Related posts from OpenVPN

### [![What Is Security Service Edge (SSE)? A Beginner's Guide](https://blog.openvpn.net/hubfs/openvpn-blog-header-minty.png) Network Security Tools Sep 1, 2026 What Is Security Service Edge (SSE)? A Beginner's Guide](https://blog.openvpn.net/what-is-security-service-edge-sse)

### [![How CloudConnexa Delivers the SASE Framework](https://blog.openvpn.net/hubfs/cloudconnexa-blog-header-blue.png) Zero Trust Sep 21, 2026 How CloudConnexa Delivers the SASE Framework](https://blog.openvpn.net/how-cloudconnexa-delivers-sase-networking)

### [![ZTNA — Beyond the Acronym](https://blog.openvpn.net/hubfs/Imported_Blog_Media/Featured-Image-3.png) Cybersecurity Sep 21, 2022 ZTNA — Beyond the Acronym](https://blog.openvpn.net/how-does-ztna-work/)

### Subscribe for Blog Updates

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Rohit Kalbag",
    "url" : "https://blog.openvpn.net/author/rohit-kalbag"
  },
  "dateModified" : "2026-09-14T15:22:33.953Z",
  "datePublished" : "2026-09-14T15:22:33.000Z",
  "headline" : "What Is SASE (Secure Access Service Edge)? A Beginner’s Guide",
  "image" : [ "https://blog.openvpn.net/hubfs/Blog_Insights_Blue_Dark.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.openvpn.net/what-is-sase-secure-access-service-edge",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.openvpn.net/hubfs/Dark=True%20Medium.png"
    },
    "name" : "OpenVPN"
  }
}
```