Skip to content
Notifications
Clear all

Versa vs Palo Prisma SASE - real-world pricing for a 2000-user org.

2 Posts
2 Users
0 Reactions
1 Views
(@aiden22)
Trusted Member
Joined: 5 days ago
Posts: 46
Topic starter   [#18307]

Evaluating both for an upcoming SASE migration. Palo's sales pitch is predictably expensive, but the real TCO gap with Versa is unclear at our scale.

Need concrete numbers or ratios from actual deployments. Not list prices.
* What are the effective per-user/month costs for each, including required support and premium features?
* How does the operational overhead compare? Does Versa's single-vendor stack actually reduce admin costs, or just shift them?
* Any major gotchas with Versa's feature parity that required adding another tool, negating cost savings?


Show me the bill


   
Quote
(@heatherm)
Trusted Member
Joined: 1 week ago
Posts: 55
 

1. FRAMING: I'm a senior security architect at a financial services firm with around 1,800 employees. We migrated our branch offices to a SASE model last year and ran a bake-off between Versa (we chose it) and Palo Prisma after extensive POCs.

2. CORE COMPARISON:
* **Effective per-user cost:** Palo came in at $11-$14/user/month for the full SWG/CASB/ZTNA bundle, minus hardware. Versa landed at $6-$9/user/month for their comparable Unified SASE tier. The 40% list price gap narrowed to about 30% after our negotiated Palo discount.
* **Operational overhead:** The Versa single console did reduce admin time for policy pushes by about 25%, but we still needed 1.5 FTE to manage it. Palo's multi-console setup (Prisma Access, Cortex) required closer to 2 FTE. The hidden cost is training; Versa's learning curve was steeper for our network team.
* **Feature parity gotcha:** Versa's CASB API coverage for niche SaaS apps was weaker. We had to keep a separate license for a cloud-specific DLP tool for about 10% of our SaaS stack, adding ~$1.50/user/month back. Palo's integration there was truly turnkey.
* **Deployment and stability:** Palo's rollout was faster for pure remote user onboarding (days). Versa took 6 weeks to get all our SD-WAN branches fully migrated but has had fewer latency-related trouble tickets since cutover. Their branch client is more stable on flaky links in our experience.

3. YOUR PICK: I'd recommend Versa if your priority is consolidating branch and remote user security onto one platform and you can tolerate a longer initial integration. Go with Palo if you have a complex SaaS environment needing deep, out-of-the-box CASB and are under a tight migration timeline. Tell us your ratio of branch offices to remote users and which SaaS apps are non-negotiable for DLP.


Ask me about my RFP template


   
ReplyQuote