What Is SASE (Secure Access Service Edge)? A Beginner’s Guide
By Rohit Kalbag
A plain-language introduction to SASE — with authoritative resources from CISA and NIST to go deeper.
|
The short answer: SASE (Secure Access Service Edge) is a cloud-delivered model that converges networking (SD-WAN) and security (SSE) into a single service. Gartner coined the term in 2019; the concept is built on Zero Trust principles defined in NIST SP 800-207. Most organizations don’t deploy the full stack at once — they adopt SASE gradually, often starting with Zero Trust network access and secure site connectivity. |
If SSE is the security half of modern cloud access, SASE (Secure Access Service Edge) is the whole picture: networking and security delivered together as one cloud service. This guide explains what SASE is, what it includes, its guiding principles, and where to learn more from trusted public sources.
SASE in one sentence
Gartner analyst Neil MacDonald coined the term in 2019 (pronounced "sassy"). Gartner defines it as:
“Secure access service edge (SASE) delivers converged network and security as a service capabilities, including SD-WAN, SWG, CASB, NGFW and zero trust network access (ZTNA). SASE supports branch office, remote worker and on-premises secure access use cases.”
In plain terms: instead of buying separate boxes for networking and separate boxes for security, SASE merges both into a single, cloud-delivered service that follows users and sites wherever they are.
The two halves of SASE
SASE is best understood as a simple equation: SASE = networking + security.
Networking (SD-WAN): Software-defined wide-area networking connects sites, branches, and cloud resources, and steers traffic over the best available path for performance and resilience.
Security (SSE): The Security Service Edge stack, which Gartner’s market definition typically describes as Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), Zero Trust Network Access (ZTNA), and Firewall as a Service (FWaaS / NGFW). OpenVPN’s own Cyber Shield is one concrete example of this convergence in practice: it layers content filtering (43 categories) and intrusion prevention directly into CloudConnexa’s access stack, at no extra licensing tier.
Put differently: SASE = SSE + SD-WAN. Keep in mind that SASE and SSE are analyst-defined market categories from Gartner, not formal standards — the normative foundations beneath them are NIST SP 800-207 (Zero Trust) and the CISA Zero Trust Maturity Model.
The four key principles of SASE
-
Convergence: Networking and security functions are combined into one integrated service instead of stitched-together point products.
-
Cloud-delivered: Capabilities are delivered as a service from the edge/cloud rather than from on-premises appliances.
-
Identity-driven: Access policy is based on the identity of the user and device, not on network location — for example, device posture policies that continuously verify a device meets security requirements before granting or keeping access.
-
Globally distributed: Policy is enforced close to the user, wherever they connect, to reduce latency and exposure.
Where to begin: Most organizations don’t deploy SASE all at once. A common starting point is consolidating remote access and site connectivity onto a single Zero Trust platform. OpenVPN’s CloudConnexa brings together secure networking and built-in ZTNA essentials — a practical foundation for an evolving SASE strategy, especially for small and mid-sized teams.
Authoritative resources to learn more
SASE is grounded in Zero Trust principles defined by public-sector authorities. These free resources are the best places to build a solid foundation:
-
NIST SP 800-207, Zero Trust Architecture — the foundational definition of Zero Trust and its seven tenets, the conceptual backbone of SASE’s identity-driven model.
-
CISA Zero Trust Maturity Model (v2.0) — a roadmap across five pillars (Identity, Devices, Networks, Applications & Workloads, Data) and four maturity stages.
-
CISA Trusted Internet Connections (TIC) 3.0 — modernized guidance for securing cloud, mobile, and remote-user connectivity, with reference architectures highly relevant to SASE.
-
NIST SP 1800-35, Implementing a Zero Trust Architecture — a hands-on NCCoE practice guide finalized in 2025.
-
NIST Cybersecurity Framework 2.0 — the 2024 update adding a "Govern" function, useful for SASE governance.
-
Gartner glossary: SASE — the canonical analyst definition.
Ready to see how OpenVPN can help protect your organization from attacks?
Try the self-hosted Access Server solution or the managed CloudConnexa service for free, no credit card required.
See Which One is Right for YouFrequently asked questions
What is SASE?
SASE is a cloud-delivered model that converges networking (SD-WAN) and security (SSE) into a single service supporting branch, remote, and on-premises access. Gartner coined the term in 2019.
What is the difference between SASE and SSE?
SSE is the security half (SWG, CASB, ZTNA, FWaaS). SASE adds the networking half (SD-WAN). SASE = SSE + networking. See the full SSE breakdown for a deeper look at the security side on its own.
How does SASE relate to Zero Trust Network Access (ZTNA)?
ZTNA is one of the security services SASE converges — it’s the component that replaces implicit network trust with identity- and context-based access to specific applications. Read how ZTNA works for the mechanics, or the full SASE vs. ZTNA comparison for how the two fit together in a rollout.
Do I need to deploy SASE all at once?
No. Most organizations adopt SASE incrementally — often starting with Zero Trust access and secure site connectivity, then expanding.
Is SASE only for large enterprises?
No. The convergence and cloud-delivery principles of SASE are especially valuable to small and mid-sized businesses that want enterprise-grade security without managing a rack of appliances.
Is SASE a single product I can buy?
Not exactly. SASE is a market category and architectural model, not one product with a fixed feature list — vendors package the SD-WAN and SSE components differently. Evaluate any SASE offering against the four principles above rather than a vendor’s marketing checklist alone.
Build your SASE foundation
Explore how CloudConnexa unifies secure networking and Zero Trust access in one easy-to-deploy platform.
Learn More Our ProductsFurther reading
- Best SASE Solutions: What to Choose in 2026
- What Are the Top SASE Use Cases?
- VPN’s Role in SASE
- SASE vs. ZTNA: What You Need to Know
- Comparing OpenVPN CloudConnexa and Check Point Harmony SASE
Sources: Gartner IT Glossary; NIST SP 800-207; NIST SP 1800-35; NIST CSF 2.0; CISA Zero Trust Maturity Model v2.0; CISA Trusted Internet Connections (TIC) 3.0. This article is educational and references publicly available guidance from CISA and NIST.
