Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Gartner’s 2023 Magic Quadrant for Security Service Edge named Netskope, Zscaler and Palo Alto Networks as Leaders among 10 vendors. Netskope ranked highest for both completeness of vision and ability to execute, Zscaler ranked second on both measures, and Palo Alto Networks placed third for execution and fourth for vision. Palo Alto’s move from Challenger to Leader was the edition’s biggest shift. The assessment reflects capabilities available as of August 30, 2022—not a current product comparison. (CRN’s report on the 2023 Magic Quadrant)

What Gartner’s SSE Magic Quadrant measures

Security Service Edge (SSE) describes the security services used to protect access to web, cloud and private applications, often for users working outside a traditional corporate network. Its core capabilities include a secure web gateway (SWG) to inspect and control web access, a cloud access security broker (CASB) to govern cloud and SaaS use, and zero-trust network access (ZTNA) to grant application-specific access rather than expose a broad network.

Other SSE platforms may add data loss prevention (DLP), threat protection, remote browser isolation, firewall as a service and digital experience monitoring. The exact bundle and depth of integration vary by vendor. SSE is commonly described as the security component of Secure Access Service Edge (SASE); SASE combines security services with networking capabilities such as SD-WAN. An SSE label does not mean that every vendor provides the same functions or a complete SASE package. (CRN on SSE and SASE)

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Magic Quadrant places vendors on two axes: completeness of vision and ability to execute. A position is a relative assessment within Gartner’s defined market and methodology—not a lab test, a single product score or a guarantee that a vendor will suit a particular organization. Market execution and strategy matter alongside features. The report was the second edition of Gartner’s SSE Magic Quadrant, and its evaluation date makes it a historical snapshot.

#1 Best Overall
FortiGate-40F Firewall Appliance plus 1 Year FortiCare Premium and FortiGuard Unified Threat Protection (UTP) (FG-40F-BDL-950-12)
  • INTEGRATED FIREWALL APPLIANCE AND SECURITY SERVICES: Comes with FortiGate-40F Firewall Appliance, 1 year of FortiCare Premium, and FortiGuard Unified Threat Protection.
  • UTP SECURITY FEATURES: Offers protection from advanced threats with DNS filtering, URL filtering, video filtering, and controls against botnets.
  • IDEAL FOR SMALLER SETTINGS: Best suited for small to mid-sized businesses needing reliable security without the complexity of larger systems.
  • CONTINUOUS SUPPORT AND MAINTENANCE: FortiCare Premium ensures that technical help is readily available to manage and troubleshoot issues.
  • COMPACT AND EFFECTIVE: Provides a powerful, yet compact security solution that effectively protects against a wide range of cyber threats.

The three Leaders at a glance

Vendor 2023 placement Reported strengths Reported cautions
Netskope Highest for vision and execution CASB, data security, DLP and ZTNA; strong revenue and frequent customer shortlisting Administration complexity and customer perceptions of higher cost
Zscaler Second for vision and execution Cloud-delivered zero-trust services, global network and broad partner ecosystem Console and configuration complexity; customer feedback cited pricing and renewal concerns
Palo Alto Networks Third for execution; fourth for vision Prisma Access, ZTNA improvements, SD-WAN integration and unified management Licensing complexity and constraints around administration choices

These strengths and cautions summarize Gartner-related findings reported by CRN. They should not be treated as current, independently verified product or pricing findings.

Netskope: data protection and CASB heritage

Gartner ranked Netskope first on both axes. The platform components discussed in the coverage included Netskope Intelligent SSE, its next-generation secure web gateway and Netskope Private Access, alongside CASB and data-security capabilities. Reported strengths included advanced data protection, DLP extending to endpoints, strong ZTNA with inline DLP inspection, revenue growth, and a simplified SKU and packaging model.

The cautions matter as much as the ranking: CRN’s account cited an administration experience split across two environments, customer perceptions that Netskope was among the more expensive options, and less advanced digital experience management than some competitors. Netskope’s 2022 acquisitions of Infiot, associated with SD-WAN, and WootCloud, associated with IoT visibility, also reflected an effort to broaden the platform. For buyers, the 2023 case for Netskope was data-security depth; the trade-off was to validate day-to-day administration and total cost rather than assume a Leader will be simple or inexpensive.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

Zscaler: cloud-delivered zero trust at scale

Zscaler ranked second for vision and execution. The assessment covered services including Zscaler Internet Access and Zscaler Private Access within its Zero Trust Exchange architecture. CRN reported strengths in growth from a large base, market position, global network reach, partner breadth and integrations with EDR, SIEM and SD-WAN technologies. The report also noted investments in digital user experience, IoT discovery, automated data classification, and email and endpoint DLP.

Reported cautions included a console that was not considered a leading user experience, convoluted configuration paths, and Gartner customer feedback citing pricing and renewal concerns. Zscaler’s 2023 profile suited organizations pursuing a cloud-first zero-trust architecture, but buyers still needed to test policy operations, support and commercial terms against their staffing and use cases.

Palo Alto Networks: the notable move into the Leaders quadrant

Palo Alto Networks moved from Challenger in 2022 to Leader in 2023, with Prisma Access at the center of the SSE story. CRN attributed the advance to an expanded platform, including closer Prisma SD-WAN integration and improvements to ZTNA. The company also promoted its “ZTNA 2.0” approach. Reported strengths included investment in the platform, a unified management console, strong ZTNA, machine-learning-supported URL categorization and DNS security. (CRN’s coverage of Palo Alto Networks’ move)

Rank #3
SonicWall NSa4700 Gen7 Firewall | High-Performance Enterprise Appliance with 18 Gbps Firewall Throughput, 9.5 Gbps UTM/Threat Protection, and Multi-Gig Ports Accelerator (02-SSC-4328)
  • SonicWall NSa4700 Appliance Only - No Service Subscription (02-SSC-4328) - Delivers very high firewall and threat prevention throughput with millions of concurrent connections for large enterprise networks and aggregation sites.
  • Defends against ransomware, zero-day exploits, and encrypted malware with Capture ATP sandboxing and RTDMI for precise detection and blocking.
  • Enterprise connectivity with multiple 10 GbE SFP+ and 1 GbE ports supports bandwidth-heavy applications and east-west segmentation.
  • Scales for thousands of VPN tunnels and large remote workforces, enabling secure connectivity across global sites and data centers.
  • Redundant power options and high availability modes provide resiliency for mission-critical operations.

The promotion indicates that Gartner saw stronger vision and execution within its framework; it does not mean Palo Alto became the best choice in every technical or commercial dimension. The fit could be especially compelling for organizations already using Palo Alto firewalls, endpoint security, SD-WAN or cloud-security products. CRN also reported cautions: customers had to choose between two administration methods at the outset and could not later change that choice, while licensing was described as complex. A “single console” claim should therefore be tested against actual policy workflows and contract structure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

All vendors in Gartner’s 2023 Magic Quadrant

CRN reported 10 vendors in the quadrant, distributed as follows:

Quadrant Vendors Context reported at the time
Leaders Netskope, Zscaler, Palo Alto Networks Highest combined placement for vision and execution
Visionaries Skyhigh Security, Forcepoint, Lookout Noted for vision or specific capabilities, with reported limits in execution, scale, integration or market presence
Challenger Cisco Strong execution, but lower placement on vision
Niche Players iboss, Broadcom, Cloudflare More limited positioning, scope, maturity or customer reach in the assessment

The coverage reported distinct considerations among the other vendors. Skyhigh Security was associated with data security and SSPM, but with weaker market presence and service availability outside North America and Europe. Forcepoint offered customizable data-security controls, although not all capabilities were integrated into SSE and endpoint DLP required a separate agent. Lookout had data-security strengths but lower market visibility and share.

Rank #4
OEM 150W 12V 12.5A Power Adapter Compatible with Sophos XGS 116 XGS 116w XGS 118 XGS 118w XGS 126 XGS 126w XGS 128 XGS 128w XGS 136 XGS 136w XGS 138 Enterprise Firewall Security Appliance Power Supply
  • 150W High Output Power Supply – Delivers stable 12V DC 12.5A output for Sophos XGS desktop firewall appliances requiring a 150W external power adapter. Designed for continuous network security operation in business and enterprise environments.
  • Compatible Sophos XGS Models – Compatible with Sophos XGS 116, XGS 116w, XGS 118, XGS 118w, XGS 126, XGS 126w, XGS 128, XGS 128w, XGS 136, XGS 136w and XGS 138 firewall security appliances.
  • Reliable Enterprise Performance – Built for firewall, network gateway and security appliance applications where stable power delivery is critical for uninterrupted network operation and security services.
  • Universal AC Input – Supports worldwide input voltage 100-240V AC, 50/60Hz for business, IT deployment and enterprise network installations across multiple regions.
  • Professional Replacement Power Solution – Ideal replacement for aging, damaged or missing power adapters used with Sophos XGS Series security appliances. Provides dependable power for long-term deployment in office, MSP, education and enterprise environments.

Cisco’s portfolio was described as a set of discrete products with incomplete integration. iboss was associated with availability and latency SLAs and lower pricing, but weaker SaaS security coverage. Broadcom had broad data-security functionality and financial strength, with a focus on very large enterprises. Cloudflare brought a global network and a broader zero-trust direction, but Gartner reportedly saw less enterprise SSE deployment depth and data-security maturity than at leading vendors at the time. These are 2023 observations, not current verdicts.

CRN also named Akamai, Cato Networks, Fortinet, Microsoft and Trend Micro as honorable mentions outside the quadrant. A vendor’s absence from the plotted group is not proof that it cannot fit a particular deployment. Existing infrastructure, geography, budget, required integrations and the balance between SSE and full SASE can make an alternative the more sensible finalist.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What changed from 2022

  • Palo Alto Networks advanced: It moved from Challenger to Leader as Prisma Access expanded, including SD-WAN integration and ZTNA improvements.
  • Cloudflare entered: It appeared in the Magic Quadrant for the first time. CRN connected its entry with Cloudflare One, its global network, the Vectrix CASB acquisition, Area 1 email security and clientless web isolation. The assessment still noted less enterprise deployment depth and data-security maturity than the leading vendors at that time.
  • Skyhigh Security’s position changed: It appeared as a Visionary in 2023 after the SSE business previously known as McAfee Enterprise had been a Leader in 2022; the business was then known as Skyhigh Security.
  • Versa was absent: CRN’s related coverage said Gartner required vendors to rank within the top 20 on its market momentum index for inclusion, and reported Versa’s exclusion.

The key story is not that one ranking proves a universal winner. Rather, Palo Alto’s movement reflected a more complete SSE proposition in Gartner’s 2023 view, while the vendor set and placements also shifted as the category developed.

Best Value
Fortinet FortiGate-70G Firewall for Branch and Small Offices with 3-Year FortiGuard AI-Powered Enterprise Security Services (FG-70G-BDL-809-36)
  • Built on a purposed-built secure processor, this compact network firewall delivers the highest level of security performance and energy efficiency in its class – 2.5 Gbps IPS throughput | 1.3 Gbps threat protection | 1.4 Gbps SSL Inspection throughput.
  • User-friendly management console gives you centralized visibility and simplifies policy enforcement across your network. Its zero-touch deployment helps you optimize your onboarding experience.
  • Compact design equipped with 10 x GE RJ45 ports (including 7 x Internal Ports, 2 x WAN Ports, 1 x DMZ Port) provide essential connectivity and flexibility for various network configurations in branch offices.

How enterprise buyers should use the ranking

Use the quadrant to build a shortlist and questions, not to choose a contract. Start with requirements and real traffic paths, then test finalists against them.

  1. Map your existing estate. List identity, endpoint, SIEM, DLP, firewall, SD-WAN and VPN systems. Determine whether consolidation would reduce operational burden or deepen lock-in. Palo Alto may be particularly relevant to an existing Palo Alto estate; Netskope may suit data-centric requirements; Zscaler may suit cloud-first zero-trust plans. These are starting hypotheses, not universal recommendations.
  2. Define the data controls you actually need. Specify inline and endpoint DLP, SaaS discovery, shadow IT controls, classification, fingerprinting, regulatory reporting, privacy controls and support for sanctioned and unsanctioned applications. “DLP included” does not establish equivalent coverage or policy behavior.
  3. Test private-application access beyond the easy case. Include on-premises and cloud apps, legacy thick clients, nonstandard protocols, administrative access, contractors, unmanaged devices and service-to-service needs. ZTNA can replace some VPN use cases, but it is not automatically a drop-in replacement for every workflow or broad network dependency.
  4. Measure administration and user experience. Ask teams to author, change, troubleshoot and roll back policies. Check console count, role-based access, audit trails, APIs, automation, reporting and the ability to correlate user, device, application and traffic events. Ask the vendor to demonstrate a policy created once and enforced consistently across web, SaaS and private applications; a common portal, shared telemetry and a shared policy engine are different levels of integration.
  5. Validate performance and resilience in your geographies. Test points of presence near users, routes to private applications, connector redundancy, inspection-related latency, regional availability and data residency. Define fail-open or fail-closed behavior for outages and review the actual SLA. A large global network does not by itself guarantee the best path to your applications.
  6. Model the full commercial commitment. Get a configuration-specific quote and identify which SWG, CASB, ZTNA, DLP, browser-isolation, digital-experience, threat-protection and support features are separate modules. Clarify user and device counts, bandwidth, minimums, connector charges, professional services, support tiers, multi-year terms, expansion, renewal, true-ups and co-termination. Build a five-year total-cost model rather than comparing first-year per-user prices alone.
  7. Plan migration, privacy and compliance. Inventory VPN dependencies, duplicate DLP policies, identity and MFA gaps, certificate deployment, TLS-inspection exceptions, connector placement and SIEM logging. Decide how to govern bypasses and prevent unmanaged-device workarounds. Review employee privacy, regulated data, regional processing, decryption exclusions, retention and access to inspected content before enabling TLS inspection broadly.

For a proof of concept, define success criteria before testing: representative user locations, applications and device types; policy outcomes; latency and failure behavior; logs reaching the SIEM; operational effort; and support response. Include difficult legacy applications and exception workflows, not just a clean demonstration scenario. Contract terms should be reviewed alongside technical results because renewal and module costs can change the economics materially.

The 2023 result is historical, not a 2026 product scorecard

The report measured capabilities available on August 30, 2022, and CRN published its coverage in April 2023. Products, management consoles, pricing, packaging, acquisitions and integrations may have changed since then. CRN later reported that Gartner again placed Zscaler, Netskope and Palo Alto Networks among the Leaders in its 2025 SSE Magic Quadrant, while noting subsequent product, console and pricing-model changes. That later result is context, not part of the 2023 ranking. (CRN’s 2025 coverage)

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Accordingly, the 2023 comparison can explain how Gartner viewed the market then, but it cannot establish which product is strongest or least expensive in August 2026. No current price comparison or independent hands-on testing is established by this historical assessment. Buyers should verify present capabilities, availability and commercial terms directly, then run their own proof of concept.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.