Secure Internet Access, Secure Private Access and Secure SaaS Access from one cloud-delivered agent — Standard, Advanced and Comprehensive subscriptions
FortiSASE converges Fortinet's Secure Web Gateway, Firewall-as-a-Service, Universal ZTNA, next-gen dual-mode CASB and cloud-delivered SD-WAN into a single-vendor Unified SASE platform, powered by the same FortiOS and FortiGuard AI/ML threat intelligence that runs FortiGate. One unified agent (FortiClient) — or agentless for BYOD and Chromebooks — secures users on and off the network from an expanding footprint of global Security PoPs. Buy live, user-based subscriptions from a Canadian Fortinet specialist.

The hybrid workforce has stretched the network perimeter to the breaking point. Remote users, branch offices and a surge of SaaS apps now live outside the data center, and stitching together separate VPNs, proxies, firewalls and SD-WAN leaves security gaps, inconsistent policy and shadow IT for attackers to exploit. SASE (Secure Access Service Edge) closes those gaps by converging networking and security in the cloud — so one consistent policy follows every user and device, on or off the network.
FortiSASE is Fortinet's cloud-delivered Secure Access Service Edge (SASE) platform. It converges Secure Web Gateway (SWG), Firewall-as-a-Service (FWaaS), Universal Zero Trust Network Access (ZTNA), next-generation dual-mode Cloud Access Security Broker (CASB), Data Loss Prevention (DLP) and cloud-delivered SD-WAN into one single-vendor Unified SASE architecture. It runs on the same FortiOS operating system and FortiGuard AI/ML-powered threat intelligence as FortiGate, and extends protection to remote users (agent or agentless), branch offices (Secure SD-WAN) and thin edges such as wireless access points. FortiSASE is SOC 2 Type II certified and delivers a 99.999% SLA with a latency guarantee, backed by Fortinet's install base of 830,000+ customers feeding real-time threat intelligence to FortiGuard Labs.
Cloud-based FWaaS and SWG with SSL inspection, AI-powered antivirus, IPS, web and DNS filtering, and botnet C&C filtering for managed and unmanaged devices.
Verifies user and device posture before every application session — on-premises or remote — shifting implicit access to explicit, continuously re-assessed control.
Inline and API-based CASB identifies sanctioned and shadow-IT SaaS applications; SSPM scans SaaS configurations for misconfigurations and threats.
Application-aware steering and dynamic routing find the shortest path to corporate applications, backed by Fortinet's ASIC-powered, organically developed SD-WAN.
FortiClient combines EPP, ZTNA, SSE, CASB, DEM, Sandbox, vulnerability management and USB device control into a single lightweight SASE agent.
Secures BYOD and Chromebooks agentlessly via PAC files or reverse proxy, and extends protection to FortiAP and FortiBranchSASE thin-edge locations.
Identify and protect sensitive data in motion and at rest with thousands of pre-defined patterns and DLP fingerprinting, plus ready-made SOX, GDPR, PCI, HIPAA, NIST and ISO 27001 reports.
The web is the #1 attack vector: Remote Browser Isolation renders risky sites in a safe container, and the Secure Browser extension blocks phishing and stops data exfiltration via copy/paste, printing and screen sharing.
All three tiers include Secure Internet Access, Secure SaaS Access and Secure Private Access with up to 3 devices per user, FortiCare Premium 24x7 support and a 50-user minimum order quantity. Advanced and Comprehensive layer on more NOC/SOC integration and PoP coverage. Start here, then jump to live pricing.
Sourced from the Fortinet FortiSASE Ordering Guide. All tiers include Universal ZTNA, FortiGate Private Access, sandboxing, endpoint protection, SASE Cloud management and 24x7 FortiCare Premium support.
| Capability | Standard | Advanced | Comprehensive |
|---|---|---|---|
| Secure Internet Access — SSL inspection, AV, IPS, Web & DNS filtering, botnet C&C | ✓ | ✓ | ✓ |
| Secure Browser | — | ✓ | ✓ |
| Secure SaaS Access — inline CASB, inline DLP, API CASB/SSPM | ✓ | ✓ | ✓ |
| Secure Private Access — FortiGate Private Access + Universal ZTNA | ✓ | ✓ | ✓ |
| Agentless ZTNA | — | — | ✓ |
| Sandbox, vulnerability management & endpoint protection | ✓ | ✓ | ✓ |
| SASE Cloud logging, reporting & log forwarding | ✓ | ✓ | ✓ |
| Digital Experience Monitoring (DEM) | — | ✓ | ✓ |
| SOC-as-a-Service integration | — | — | ✓ |
| FortiGuard Forensics (Response) Service | — | ✓ | ✓ |
| SASE Cloud management + REST API | ✓ | ✓ | ✓ |
| 24x7 FortiCare Premium support | ✓ | ✓ | ✓ |
| Assisted on-boarding | — | ✓ | ✓ |
| Data center locations | Fortinet Cloud | Fortinet + Public Cloud | Fortinet + Public Cloud |
| Global Security PoP coverage | — | — | Add-on |
Prices are live in your selected currency and update automatically. FortiSASE is licensed per user (minimum order quantity of 50 users) and delivered electronically worldwide, usually within hours. Need fewer than 50 users, a custom mix, or help sizing devices and locations? Request a quote and we will size it same day.
Expand a tier to buy by user band (50-499, 500-1,999, 2,000-9,999 or 10,000+) with live 1, 3 and 5-year pricing.
Fortinet cloud-delivered Secure Internet Access (SSL inspection, antivirus, IPS, web and DNS filtering, botnet C&C filtering), Secure SaaS Access (inline CASB, inline DLP, API CASB/SSPM) and Secure Private Access (Universal ZTNA plus FortiGate Private Access) delivered from Fortinet Cloud Security PoPs. Includes up to 3 devices per user, sandboxing, vulnerability management, endpoint protection and FortiCare Premium 24x7 support.
| User band | 1 Yr | 3 Yr | 5 Yr |
|---|---|---|---|
| 50-499 Users | View productFC2-10-EMS05-547-02-12 | View productFC2-10-EMS05-547-02-36 | View productFC2-10-EMS05-547-02-60 |
| 500-1,999 Users | View productFC3-10-EMS05-547-02-12 | View productFC3-10-EMS05-547-02-36 | View productFC3-10-EMS05-547-02-60 |
| 2,000-9,999 Users | View productFC4-10-EMS05-547-02-12 | View productFC4-10-EMS05-547-02-36 | View productFC4-10-EMS05-547-02-60 |
| 10,000+ Users | View productFC5-10-EMS05-547-02-12 | View productFC5-10-EMS05-547-02-36 | View productFC5-10-EMS05-547-02-60 |
Everything in Standard, plus the Secure Browser extension, delivery from both Fortinet Cloud AND Public Cloud Security PoPs, Digital Experience Monitoring, the FortiGuard Forensics (Response) Service and Assisted On-boarding — the recommended tier for NOC/SOC-integrated teams.
| User band | 1 Yr | 3 Yr | 5 Yr |
|---|---|---|---|
| 50-499 Users | View productFC2-10-EMS05-676-02-12 | View productFC2-10-EMS05-676-02-36 | View productFC2-10-EMS05-676-02-60 |
| 500-1,999 Users | View productFC3-10-EMS05-676-02-12 | View productFC3-10-EMS05-676-02-36 | View productFC3-10-EMS05-676-02-60 |
| 2,000-9,999 Users | View productFC4-10-EMS05-676-02-12 | View productFC4-10-EMS05-676-02-36 | View productFC4-10-EMS05-676-02-60 |
| 10,000+ Users | View productFC5-10-EMS05-676-02-12 | View productFC5-10-EMS05-676-02-36 | View productFC5-10-EMS05-676-02-60 |
Everything in Advanced, plus Agentless ZTNA and SOC-as-a-Service integration. Comprehensive is the only tier that can add the Global Security PoP coverage add-on for every current and future Fortinet and Public Cloud location. Comprehensive subscriptions under 200 users have limited PoP availability — talk to us for the right fit.
| User band | 1 Yr | 3 Yr | 5 Yr |
|---|---|---|---|
| 50-499 Users | View productFC2-10-EMS05-759-02-12 | View productFC2-10-EMS05-759-02-36 | View productFC2-10-EMS05-759-02-60 |
| 500-1,999 Users | View productFC3-10-EMS05-759-02-12 | View productFC3-10-EMS05-759-02-36 | View productFC3-10-EMS05-759-02-60 |
| 2,000-9,999 Users | View productFC4-10-EMS05-759-02-12 | View productFC4-10-EMS05-759-02-36 | View productFC4-10-EMS05-759-02-60 |
| 10,000+ Users | View productFC5-10-EMS05-759-02-12 | View productFC5-10-EMS05-759-02-36 | View productFC5-10-EMS05-759-02-60 |
Layer these onto an existing FortiSASE user subscription: SaaS posture management, extra data transfer, dedicated IPs, additional Security PoP locations, worldwide PoP coverage, branch on-ramp connectivity, a standalone application connector, or Sovereign SASE for data-residency deployments.
Scans provisioned SaaS application configurations for misconfigurations and threats. Layers on top of any FortiSASE user subscription.
| User band | 1 Yr | 3 Yr | 5 Yr |
|---|---|---|---|
| 50-499 users | View productFC1-10-EMS05-1282-02-12 | View productFC1-10-EMS05-1282-02-36 | View productFC1-10-EMS05-1282-02-60 |
| 500-1,999 users | View productFC2-10-EMS05-1282-02-12 | View productFC2-10-EMS05-1282-02-36 | View productFC2-10-EMS05-1282-02-60 |
| 2,000-9,999 users | View productFC3-10-EMS05-1282-02-12 | View productFC3-10-EMS05-1282-02-36 | View productFC3-10-EMS05-1282-02-60 |
| 10,000+ users | View productFC4-10-EMS05-1282-02-12 | View productFC4-10-EMS05-1282-02-36 | View productFC4-10-EMS05-1282-02-60 |
Every FortiSASE user subscription includes a tenant-level data transfer entitlement (roughly 250GB per user — a 100-user subscription entitles about 25TB globally). Add stackable 250GB or 100TB blocks if your account needs more, up to 10,000 units.
| Block size | 1 Yr | 3 Yr | 5 Yr |
|---|---|---|---|
| 250GB block (stackable, up to 10,000 units) | View productFC1-10-EMS05-471-02-12 | View productFC1-10-EMS05-471-02-36 | View productFC1-10-EMS05-471-02-60 |
| 100TB block (stackable, up to 10,000 units) | View productFC2-10-EMS05-471-02-12 | View productFC2-10-EMS05-471-02-36 | View productFC2-10-EMS05-471-02-60 |
Assign dedicated public egress IPs to your FortiSASE Security PoPs for IP reputation and geo-location services with source IP anchoring. Requires a Standard, Advanced or Comprehensive subscription with a minimum of 500 users. Each Security PoP supports up to 5 dedicated egress IPs (4 usable for source IP anchoring).
| Quantity | 1 Yr | 3 Yr | 5 Yr |
|---|---|---|---|
| 4 dedicated public IPs | View productFC1-10-EMS05-658-02-12 | View productFC1-10-EMS05-658-02-36 | View productFC1-10-EMS05-658-02-60 |
| 32 dedicated public IPs | View productFC2-10-EMS05-658-02-12 | View productFC2-10-EMS05-658-02-36 | View productFC2-10-EMS05-658-02-60 |
Add extra Fortinet or Public Cloud Security PoP locations beyond the 4 included with Standard/Advanced (or the 1-2 included with Comprehensive under 200 users). Up to 16 additional locations, 20 total. The Region add-on can only be mixed into a FortiSASE Comprehensive subscription.
| PoP type | 1 Yr | 3 Yr | 5 Yr |
|---|---|---|---|
| Fortinet Security PoP add-on (1-16 PoPs) | View productFC1-10-EMS05-752-02-12 | View productFC1-10-EMS05-752-02-36 | View productFC1-10-EMS05-752-02-60 |
| Public Cloud Security PoP add-on (1-16 PoPs) | View productFC1-10-EMS05-766-02-12 | View productFC1-10-EMS05-766-02-36 | View productFC1-10-EMS05-766-02-60 |
Unlocks every existing Fortinet and Public Cloud Security PoP, plus all future locations, with a single subscription. Requires a Comprehensive user subscription.
| Coverage | 1 Yr | 3 Yr | 5 Yr |
|---|---|---|---|
| All existing + future Fortinet & Public Cloud PoPs | View productFC-10-EMS05-1136-02-12 | View productFC-10-EMS05-1136-02-36 | View productFC-10-EMS05-1136-02-60 |
Connect FortiGate or third-party IPsec devices directly to a FortiSASE Security PoP. Each location delivers 1 Gbps of shared bandwidth for up to 2,000 connections. Standard connects to Fortinet Cloud PoPs only; Advanced and Comprehensive connect to both Fortinet and Public Cloud PoPs. Up to 20 locations per account (2+ recommended for redundancy).
| PoP type | 1 Yr | 3 Yr | 5 Yr |
|---|---|---|---|
| Fortinet Cloud PoP — 1 Gbps, up to 2,000 connections | View productFC1-10-EMS05-769-02-12 | View productFC1-10-EMS05-769-02-36 | View productFC1-10-EMS05-769-02-60 |
| Public Cloud PoP — 1 Gbps, up to 2,000 connections | View productFC1-10-EMS05-770-02-12 | View productFC1-10-EMS05-770-02-36 | View productFC1-10-EMS05-770-02-60 |
A virtual-machine connector that securely publishes private applications to Secure Private Access without deploying a full FortiGate SD-WAN hub.
| Connector | 1 Yr | 3 Yr | 5 Yr |
|---|---|---|---|
| Standalone Application Connector (VM) — includes FortiCare Premium | View productFC-10-PAVM4-1272-02-12 | View productFC-10-PAVM4-1272-02-36 | View productFC-10-PAVM4-1272-02-60 |
Sovereign SASE pairs a dedicated cloud orchestrator subscription with per-user licenses for organizations that must keep SASE management, data and inspection inside a sovereign or data-residency boundary. Requires a FortiGate Sovereign SASE entitlement for security inspection. This is a specialized, quote-driven deployment — talk to us to scope it correctly.
| Component | 1 Yr | 3 Yr | 5 Yr |
|---|---|---|---|
| Sovereign SASE cloud orchestrator + web portal — includes FortiCare Premium | View productFC-10-OVSAE-1081-02-12 | View productFC-10-OVSAE-1081-02-36 | View productFC-10-OVSAE-1081-02-60 |
| User band | 1 Yr | 3 Yr | 5 Yr |
|---|---|---|---|
| up to 1,999 users | View productFC3-10-EMSSS-552-02-12 | View productFC3-10-EMSSS-552-02-36 | View productFC3-10-EMSSS-552-02-60 |
| 2,000-9,999 users | View productFC4-10-EMSSS-552-02-12 | View productFC4-10-EMSSS-552-02-36 | View productFC4-10-EMSSS-552-02-60 |
| 10,000+ users | View productFC5-10-EMSSS-552-02-12 | View productFC5-10-EMSSS-552-02-36 | View productFC5-10-EMSSS-552-02-60 |

Every Fortinet purchase from DataCenter360.ca is backed by hands-on services across the full lifecycle — from rollout to round-the-clock protection.
SWG, Advanced Threat Protection and FWaaS for managed and unmanaged devices, with real-time SSL/TLS 1.3 inspection and FortiGuard AI-powered protection from ransomware and sophisticated attacks.
Anywhere access to corporate applications in the data center and cloud, with identity and device-context zero-trust access and continuous posture re-assessment.
Inline CASB blocks malicious applications; API-based CASB, SSPM and DLP control content and files, and detect and quarantine malicious files from unmanaged devices.
Secures sites without a client agent or on-prem firewall using the built-in hardware agent in FortiAP and FortiBranchSASE, with cloud-delivered management and zero-touch provisioning.
FortiSASE inspects traffic with the same FortiGuard AI/ML security stack that protects FortiGate — updated in near real time from Fortinet's install base of 830,000+ customers. Every tier includes these enterprise-grade services, delivered from the cloud with real-time SSL/TLS 1.3 deep inspection.
Hyperscale, FortiOS-powered NGFW in the cloud with security efficacy matching a FortiGate firewall — web filtering, ATP, IPS and DNS security in one service.
Patented CPRL antivirus with ~1.8M new definitions weekly, Content Disarm & Reconstruction on Office/PDF files, and an AI-powered sandbox that detonates zero-day threats in isolation.
Near-real-time IPS with thousands of rules and deep packet inspection blocks known and suspicious threats before they reach your users, augmented by FortiGuard Labs research.
Hundreds of millions of URLs across 90+ categories, plus DNS filtering that stops newly-registered and parked domains, DNS tunneling, C2 callbacks and DGAs — even over DoH/DoT.
Identify and steer 8,000+ applications (including industrial/ICS signatures) with SLA-based path selection for a fast, reliable experience to every app.
SAML SSO with Entra ID and Okta, native FortiTrust ID, FIDO2, LDAP and RADIUS, plus SCIM auto-provisioning — enforcing continuous, per-session zero-trust posture checks.
Unlike cloud-only SSE point products, FortiSASE is a single-vendor Unified SASE platform — not an isolated service, but an extension of the Fortinet Security Fabric running the same FortiOS and FortiClient agent as the rest of your deployment. That means one operating system and one policy model everywhere, organically built (ASIC-accelerated) SD-WAN rather than bolted-on, and the only SASE cloud that integrates directly with wireless access points and FortiBranchSASE thin edges — so a legacy VPN, SD-WAN or SSE point product can migrate to FortiSASE without re-architecting your network.
One lightweight agent supports EPP, ZTNA, SSE, CASB, DEM, Sandbox, vulnerability management and USB device control — no separate agents per use case.
The FortiGate SD-WAN Service Bundle lets you start SASE adoption with as few as 5 users on a 60G-series+ FortiGate. Branch On-Ramp connects existing FortiGate or third-party IPsec devices to a Security PoP.
FortiSASE is the only SASE platform that integrates directly with wireless access points and FortiBranchSASE, extending SASE-grade security to micro-branches without a client agent on every device.
FortiManager 7.4.4 and higher can synchronize Security Profiles, Users, Groups and Firewall Objects with FortiSASE. FortiManager is purchased separately and counts FortiSASE as one managed device — no extra FortiSASE license required.
Fortinet Select Partner and MSSP, FCP-certified. Genuine subscriptions registered correctly the first time.
FortiSASE subscriptions are electronic and delivered worldwide, usually within hours of purchase.
Users, devices, PoP locations, add-ons — we help you pick the right tier and quantity before you buy.
Talk to an FCP-certified engineer about migrating from VPN, SD-WAN or a legacy SSE point product to FortiSASE.
Tell us your user count, devices and where your applications live. We will size the tier, add-ons and term, and quote it, usually same day.
FortiSASE is Fortinet's cloud-delivered Secure Access Service Edge platform, converging Secure Web Gateway, Firewall-as-a-Service, Universal ZTNA, dual-mode CASB, DLP and cloud-delivered SD-WAN into a single-vendor Unified SASE architecture built on FortiOS and FortiGuard AI/ML threat intelligence.
Standard covers core Secure Internet, SaaS and Private Access from Fortinet Cloud PoPs. Advanced adds Secure Browser, Fortinet + Public Cloud PoPs, Digital Experience Monitoring, FortiGuard Forensics and assisted on-boarding. Comprehensive adds Agentless ZTNA and SOC-as-a-Service integration, and is the only tier eligible for the Global Security PoP add-on.
FortiSASE has a 50-user minimum order quantity — the industry's lowest. If you have an F-series or G-series FortiGate (60G and above), the FortiGate SD-WAN Service Bundle lets you start with as few as 5 users.
Tenant-level data transfer is calculated by adding up the entitlement across all purchased contracts — roughly 250GB per user. For example, a 100-user subscription entitles about 25TB of data transfer globally. Add stackable Data Transfer blocks if you need more.
No — all components in an account must use the same tier, except the Region add-on, which can be mixed into a Comprehensive subscription. Use separate accounts if you need different tiers for different parts of your organization.
Dedicated Public IPs give your FortiSASE traffic a fixed egress IP for IP reputation and geo-location services with source IP anchoring. The add-on requires a subscription with a minimum of 500 users. Each Security PoP supports up to 5 dedicated egress IPs, 4 of which can be used for source IP anchoring.
Yes. Branch On-Ramp connects existing FortiGate or third-party IPsec devices to a FortiSASE Security PoP, and SASE points of presence join natively with existing FortiGate NGFW, SD-WAN or Data Center Firewall deployments — no need to re-architect routing. FortiManager 7.4.4+ can also manage FortiSASE as a single device.
FortiSASE is software, so there is nothing to ship — licenses are delivered electronically worldwide as an Authorized Fortinet Select Partner, usually within hours of purchase. FortiSASE is SOC 2 Type II certified and backed by a 99.999% SLA with a latency guarantee for security inspection.
SSE (Security Service Edge) is the security half — Secure Web Gateway, Universal ZTNA, CASB, FWaaS and DLP delivered from the cloud. SASE (Secure Access Service Edge) is SSE plus the networking half: cloud-delivered SD-WAN and optimized connectivity. FortiSASE delivers both in one platform, so you get consistent security and a fast user experience from the same console rather than buying SSE and SD-WAN separately.
Yes — FortiSASE Universal ZTNA replaces broad, implicit VPN access with explicit, per-application access that is verified on every session with continuous device-posture checks, which is both more secure and a better user experience than a traditional VPN. The same FortiClient agent still supports VPN during the transition, so you can migrate from VPN to ZTNA at your own pace without swapping agents.
No. FortiSASE is the cloud-delivered SASE platform (the Security PoPs, policy engine and management console). FortiClient is the lightweight unified agent that connects an endpoint to FortiSASE for ZTNA, traffic redirection and endpoint protection. A FortiSASE user subscription includes the FortiClient SASE agent entitlement, and agentless access is available for BYOD and Chromebooks.
DataCenter360.ca is an Authorized Fortinet Select Partner. Specifications and capabilities shown are from the FortiSASE datasheet and the FortiSASE Ordering Guide (effective June 8, 2026). Pricing is live from our catalogue and may vary with currency and promotions. FortiSASE, FortiGate, FortiClient, FortiCare, FortiGuard and FortiManager are trademarks of Fortinet, Inc.