cd /news/ai-safety/gartner-sase-2026-rankings-netskope-… · home topics ai-safety article
[ARTICLE · art-84691] src=sdxcentral.com ↗ pub= topic=ai-safety verified=true sentiment=· neutral

Gartner SASE 2026 rankings: Netskope leads, Cato Networks leaps, and Palo Alto Networks falls

Netskope took the top spot in Gartner's 2026 Magic Quadrant for SASE Platforms, while Cato Networks rose to second place and Palo Alto Networks fell from first to third. Gartner praised Netskope's broad and deep capabilities and comprehensive points of presence infrastructure, while citing Palo Alto's expensive pricing and constrained on-premises security as reasons for its drop. Cato's rise was attributed to above-average customer experience and planned developments around suppressing agentic threats, aided by its acquisition of Aim Security.

read5 min views1 publishedAug 3, 2026
Gartner SASE 2026 rankings: Netskope leads, Cato Networks leaps, and Palo Alto Networks falls
Image: Sdxcentral (auto-discovered)

Netskope took top position in Gartner’s latest rankings of secure access service edge (SASE) vendors, while Cato Networks moved up the charts to pip the likes of Palo Alto Networks and Zscaler.

In its latest Magic Quadrant for SASE Platforms report, Gartner lauded Netskope’s “broad and deep” capabilities covering networking and security across on-premises and cloud, as well as its comprehensive points of presence (PoP) infrastructure strategy. The firm moved up from its position in last year’s “leaders” box to lead on execution; Palo Alto Networks was downgraded in this regard to fall from top position to third place, giving Netskope the upper hand over Gartner's other three leaders.

Cato Networks now sits in second place, with its leveling up put down to above-average customer experience and planned developments around suppressing agentic threats such as shadow AI. That feature will be helped along by its recent acquisition of fellow Israeli firm Aim Security.

Whether Cato will leapfrog Netskope next time around depends on its Gartner-perceived weaknesses: adopting a modular SASE adoption when it’s more known as a unified platform offering, and higher pricing than others in the market.

Gartner also said it gave both Cato and Netskope a comparatively low financial score, although how the powerhouse calculates such financial profiles was not disclosed, along with the exact scores themselves.

Rounding out the four Leaders with a sunnier financial profile was new entry Zscaler. Besides that health status, the vendor was also commended for feature enhancements to its networking capabilities, along with its PoP infrastructure.

Challengers to the SASE throne #

Digging deeper into the report reveals Netskope was recommended to stop “overly” focusing on securing AI at risk of overlooking core SASE buyer needs. According to Gartner, those buyers will likely expand to the small and midsize business (SMB) market thanks to its partner outreach with the Netskope Customer Workspace solution.

That SMB SASE focus was recently brought up via a managed SASE security offering from AT&T Business, which sees Palo Alto Networks’ Prisma Access cloud security capabilities integrated into its Dynamic Defense service for smaller firms. While it has ties with Cisco and Fortinet, AT&T opted for Palo Alto as its software of choice.

Andy Foerstner, AT&T Business director for edge/cybersecurity products, told this title that SMBs, like larger enterprises, have "pretty significant security concerns about the evolving threat landscape."

"They're interested in what additional capabilities could be brought to the table to help make them more secure," Foerstner said.

While Palo Alto’s footprint in the SMB field wasn’t noted in Gartner's report, its reportedly expensive pricing was one reason for its drop this year, perhaps giving Netskope another win with firms both big and small. Palo Alto Networks also saw on-premises security for its Instant On-Network (ION) appliances’ intrusion prevention system and content filtering described as “more constrained and cloud-reliant” than those of other vendors.

Keeping Palo Alto Networks in the leaders throng were enhancements around post-quantum cryptography (PQC), securing AI agent-borne traffic flows, simplifying manageability with agentic SASE operations capabilities, sovereign controls, and reduced time from vulnerability discovery to exploitation via AI.

Fortinet was dropped out of the leaders box just one year after its debut in the division. The firm was due to delayed feature enhancements, below-average customer experience, and how its large installed base makes its firewall platforms a frequent target for attackers.

“This has resulted in frequent patching and elevated customer concerns in production and when making buying decisions,” Gartner commented on Fortinet.

Fortinet now sits in the “challengers” box with Cisco and Versa Networks.

The former was gilded for its PoP infrastructure and sales execution, but knocked down for many of the same reasons as Fortinet was, alongside a management complexity in fully operating its SD-WAN and secure service edge (SSE) functionalities.

Versa Networks was warned over the introduction of non-SASE-adjacent features, but received plaudits over its product capabilities and – at risk of repetition – its PoP estate.

On the PoP question, Zeus Kerravala, founder and principal analyst with ZK Research, recently told this title that while the number of PoPs can be critical, security professionals place more importance on quality and capabilities.

“The features customers are looking for are low latency, high performance, consistency of service across PoPs and data residency. More can become less when vendors have any kind of inconsistency," Kerravala said. "As an example, a vendor might leverage a hyperscaler to turn the PoP up quickly but did not do the due diligence to ensure network connectivity is where it needs to be for their volume."

Niche players and a solo visionary #

Rounding out the latest Gartner SASE quadrant was the “niche players” category, as home to Hewlett Packard Enterprise (HPE) and a host of less-than-household names, including China’s Sangfor Technologies.

HPE, which was estimated to have approximately 600 active SASE platform enterprise customers, was also tipped to integrate the Juniper Networks SRX firewall stack in its SASE platform; SSE into its EdgeConnect SD-WAN fabric; and Juniper Mist with HPE Networking Central for full-stack, agentic-based networking operations. Whether this reduces what Gartner labeled as HPE’s management complexity remains to be seen; it also won’t solve the issue of HPE’s comparatively low-PoP count, according to Gartner.

Cloudflare sat on its own in the “visionaries” box, with Gartner applauding the vendor for its AI and PQC security leanings, and concern over “a narrow view of sovereignty” due its focusing on encryption and decryption location.

Gartner also gave honorable mentions to “noteworthy providers” such as Ericsson with its Cradlepoint line, SonicWall, and Huawei.

The research giant predicts the overall SASE market will reach more than $18 billion in 2026, with a 2025 through 2030 compound annual growth rate (CAGR) of 23%.

── more in #ai-safety 4 stories · sorted by recency
── more on @netskope 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/gartner-sase-2026-ra…] indexed:0 read:5min 2026-08-03 ·