Overview
Cisco Secure Access makes life better for users, easier for IT, and safer for everyone. It addresses cybersecurity challenges driven by the rapid software as a service (SaaS) adoption and the expansion of hybrid work.
Cisco Secure Access is a cloud-delivered Security Service Edge (SSE) solution that fundamentally reduces risk, radically simplifies IT operations, and eliminates remote access complexity for end users. With Secure Access, IT and security teams can effectively protect and defend their users from fast-moving internet-based attacks while providing them secure connectivity to the public and private applications they need, all in a single platform.
Cisco Secure Access is a full SSE solution, with ZTNA, SWG, DLP, CASB, RBI, and FWaaS with further differentiated capabilities including VPN-as-a-Service (VPNaaS), AI Assistant for policy creation help, and AI Access for visibility, control, and exclusive guardrails for third-party AI applications. Further, Secure Access is the only SSE which includes a recursive DNS-layer security service for lower latency, Experience Insights monitoring by Cisco ThousandEyes, and much more, in one license and management platform, all delivered with a single client.
Highlights
- Deliver unified and secure end user access to AWS apps.
- Simplify IT operations via a single console, with a single policy construct, featuring aggregated reporting across datacenter-hosted and AWS environments.
- Reduce business risk with advanced cybersecurity protection, zero trust, and granular security policies.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Custom pricing options
How can we make this page better?
Legal
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
You can reach for the Cisco Secure Access support at: https://www.cisco.com/c/en/us/support/web/tsd-cisco-worldwide-contacts.html
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products
Customer reviews
Unified access control has strengthened zero trust while integration and automation still need work
What is our primary use case?
We use Cisco SD-WAN in our own company for our own needs, and we are also selling this to our customers while performing operations for customer networks. My personal customer scope is the large enterprise customer. We have integrated Cisco Identity Intelligence with Cisco Secure Access using Cisco ISE.
How has it helped my organization?
This integration has influenced our identity management and security measures significantly, as we use Cisco ISE to harmonize the access control, leading us towards a zero-trust network environment.
What is most valuable?
The advantages I see in Cisco Catalyst SD-WAN compared to their competitors is the seamless service scope, where I can have from Cisco the LAN, Wi-Fi environment, the SD-WAN environment, and the security environment, and as now announced from Cisco, all the management is combined in one orchestrator, which is the most beneficial aspect for me, not looking for the best of breed but more looking for the best fit.
I have used the policy verification to help reduce policy misconfigurations.
The multi-organization management capability of Cisco Secure Access in terms of usability and efficiency is quite good, as there is an RBAC system, allowing me to granularly define the access roles. I would rate this an eight.
What needs improvement?
For SD-WAN, I do not see any room for improvement, but for Cisco Secure Access, I think there is a lot to do for Cisco to integrate that in the Telco enterprise environment for seamless operation.
I am not talking about the integration with third-party solutions; you need to control the SD-WAN security policies in the same hand with the cloud security, and currently, both are managed by two different management systems, so you need to integrate that seamlessly.
It could be better from Cisco. The API interfaces, for example, Terraform integration, could be quite useful because there are some customers looking for full automation, and therefore it would be good to have a Terraform integration.
Some other companies are better on the market currently when it comes to the AI Access feature of Cisco Secure Access for providing deep visibility and control over AI applications, tools, and LLMs. If you compare it with the AI capability of Juniper Mist, Cisco needs to do a little bit more.
IPsec is a very old protocol, and sometimes it is good to see if there are some alternatives for VPNs in Cisco Secure Access.
I would like to see flexible access to the cloud in the next release to make it better. Currently, you set up one IPsec tunnel and that is all, which I think is not sufficient. There could be a better way, and what is missing are some virtualization services and security services in Cisco Secure Access cloud environment, especially for dedicated customers, such as governance and so on.
For how long have I used the solution?
I have been dealing with Cisco SD-WAN for ten to fifteen years.
How are customer service and support?
Technical support is perfect, and I find it fine. I would rate their support an eight out of ten.
There is still room for improvement when it comes to response time, especially if you need some response from the US. If you need support from the US side, you can see the different countries, and sometimes it takes very long to get an approval from the US side, which is something that could be better.
How was the initial setup?
The initial setup of Cisco Secure Access was not straightforward. There were a lot of discussions, especially with our customer about what the benefits are, particularly regarding the cost and the cost-benefits ratio, with discussions being more governance-driven or management-driven rather than technical, which meant it took a lot of time.
What's my experience with pricing, setup cost, and licensing?
In my experience with the Experience Insights feature or Digital Experience Monitoring of Cisco Secure Access, ThousandEyes is a fine tool, but currently, my experience with our customer is that it is too expensive just to have it. It is nice to have, but it is not business-critical, and therefore it is too expensive.
The overall pricing of Cisco Secure Access has changed dramatically in the last half year, and I would say it is too high.
I think Cisco should consider their licensing model, as anything could be improved.
What other advice do I have?
Currently, AI Supply Chain Risk Management is not really an issue for us today. I would rate Cisco Secure Access a seven out of ten overall.
Unified cloud security has simplified zero trust access and protected hybrid users
What is our primary use case?
My main use case for Cisco Secure Access is for one client, where I deployed DNS security. Previously, Cisco DNS security was part of Umbrella; now, it has been moved to Cisco Secure Access. I implemented DNS security, which provided the client with cloud-based DNS security and intelligent proxy features, so they are protected from day-zero attacks with policy management in place. That was one use case for Cisco Secure Access, and for another client, I have recently deployed ZTNA using Cisco Duo MFA.
For a specific example of how I used Cisco Secure Access for one of these clients, I will provide the example of one client where I deployed ZTNA through MFA. The client has around 1500 users working in a hybrid environment, so connecting every user on the VPN, whether hardware-hosted, VM-hosted, or anywhere else, causes unnecessary burden. SASE is the best use case of Cisco Secure Access in the hybrid environment, where if users want to access any of their private applications, they connect to Cisco Secure Cloud. From the cloud, the traffic is tunneled, providing zero-trust access and requiring MFA to access any internal application. This way, since it is cloud-based security, the routing and everything is taken care of in the cloud, avoiding dependency on hardware infrastructure or overusing the link in the data center itself.
What is most valuable?
The best feature that Cisco Secure Access offers is a single platform where DNS security, ZTNA, and everything are in one place, all managed through a single cloud dashboard.
Having everything in a single platform and dashboard has made things easier for me and my clients because everything is available for checking or troubleshooting.
Cisco Secure Access has positively impacted my organization because we are Cisco preferred partners. We deploy everything for our clients, so it is not just about deploying it in our organization. Since we are a preferred partner, many clients requiring Cisco Secure Access are routed to us from Cisco.
After deploying Cisco Secure Access, I received specific positive outcomes and feedback from my clients. For the use case concerning DNS security over the last three months, their AD integration with Cisco Secure Access allows them to create user-based policies for DNS security based on identity and username. They also receive a dashboard to monitor reports on threats and everything online in the cloud. The customer is very happy that they are able to overview their organization, seeing the number of users utilizing maximum applications, the top talkers, and everything.
Cisco Secure Access has greatly impacted protecting my organization and clients from threats such as phishing and ransomware. Because it has ZTNA and is cloud-based with VMs deployed inside the network, it creates best practice tunnels required for accessing applications from day one. Thus, we can deploy with peace of mind without juggling best practices or opening only specific ports.
What needs improvement?
Cisco Secure Access can be improved by providing information about the location of the PoPs where users are connected. The guidelines in KSA say it is mandatory for the PoPs to be regional, similar to how Fortinet SASE discloses its PoP locations.
In terms of needed improvements around documentation and support, the documentation has been good for me. Since I deployed for the first time, I went through Cisco documents, which helped me a lot, and their program on the T-Cloud labs also provided great support. Completing the lab gave me the confidence to deploy for the customer. The documentation and the labs provided by Cisco are very good.
For how long have I used the solution?
I have been using Cisco Secure Access for the last six months.
What other advice do I have?
For others looking into using Cisco Secure Access, my advice is that it is a good solution and they should experience it.
I chose eight out of ten primarily due to only the PoP presence. I would rate the ease of managing Cisco Secure Access through its single cloud-managed console an eight.
In my experience, it is easy to navigate and manage everything from the console, but compared to the FortiGate SASE platform, FortiGate has a unified platform for all their products, while Cisco has each platform operating differently.
I use the Zero Trust Network Access (ZTNA) feature of Cisco Secure Access, and it is a great feature. We do not need to worry about the security of accessing applications from outside the environment. With ZTNA, each application access requires authentication, which is a truly great feature.
This ZTNA approach has positively changed my client's security posture, and there are no significant challenges or surprises. I rate this product eight out of ten.