An RFP is a poor place to make strategy. Vendors will answer whatever you ask, and if the underlying decisions have not been made, the responses will be impossible to compare. These five are worth settling internally first.
1. Who owns the outcome: network or security?
SASE merges two disciplines that often sit in separate teams with separate budgets and vendor relationships. Decide up front who holds the decision, who operates the result, and how disagreements get resolved. Without that, the evaluation becomes a negotiation between your own teams.
2. Single vendor, or best of each?
A single-vendor platform simplifies operations and policy. Pairing a networking vendor with a separate security vendor can preserve existing investments and strengths, at the cost of integration work. Either can be right. Choosing before the RFP lets you invite the right vendors and ask the right questions.
3. What do you operate yourself?
Fully managed, co-managed, and self-operated models differ in cost, staffing, and control. Be honest about the team you have today and the one you can realistically hire and keep. The operating model shapes the requirements more than any feature list.
4. What has to keep working during the migration?
Existing firewalls, voice platforms, legacy applications, and carrier contracts rarely disappear on day one. Inventory what must coexist with the new environment and for how long. Coexistence requirements are where many designs, and many timelines, come apart.
5. How will you know it worked?
Define the measures of success before selecting a vendor: application performance, site turn-up time, incident volume, cost per site, or audit findings closed. Those measures should drive the pilot design and the contract terms.
The takeaway
None of these questions is technical, and none can be answered by a vendor. Organizations that settle them first tend to run shorter evaluations and face fewer surprises during rollout.