SD-WAN vs Managed SD-WAN: Differences & Benefits

Choosing an SD-WAN platform is only half of the decision. You must also decide who will design, operate, monitor, secure, and improve the network. A self-managed SD-WAN gives your internal team the most direct control. By contrast, a fully managed SD-WAN moves most daily operational work to a service provider. Meanwhile, a co-managed SD-WAN sits between these options and divides responsibilities between both teams.

Therefore, the right choice depends on more than technology. Organizations should also consider internal skills, number of locations, geographic coverage, budget, security requirements, operational maturity, service-level expectations, and the level of control they want to retain.

This distinction is important because SD-WAN is the networking technology and service framework, while managed SD-WAN describes how that environment is operated. In practice, enterprises need to define not only what the WAN must deliver but also which party is responsible for each outcome.

Security must also be considered from the beginning. An SD-WAN overlay can provide capabilities such as encrypted connectivity, segmentation, traffic control, and centralized policies. However, it does not automatically create a complete enterprise security architecture. Consequently, organizations should determine how networking integrates with firewalls, cloud security, Zero Trust, SSE, SASE, logging, and incident response.

Regardless of the management model selected, the enterprise remains accountable for its business risks.

This guide compares self-managed, co-managed, and fully managed SD-WAN. In addition, it examines control, staffing, cost, deployment, troubleshooting, security, service-level agreements, multi-carrier operations, scalability, migration, and provider selection.

If you first need a technical introduction, read our complete guide to SD-WAN architecture, benefits, and operation.

SD-WAN vs Managed SD-WAN: Quick Answer

Managed SD-WAN and SD-WAN are not two competing networking technologies.

SD-WAN is the underlying networking architecture. Managed SD-WAN is an operating and service model in which a provider assumes agreed responsibilities for deploying, monitoring, supporting, and operating that SD-WAN environment.

There are three main approaches:

  • Self-managed SD-WAN: the enterprise manages most of the platform internally.
  • Co-managed SD-WAN: operational responsibilities are shared between the enterprise and a service provider.
  • Fully managed SD-WAN: the provider performs most day-to-day network operations according to an agreed service scope and SLA.

Therefore, the key question is not simply whether an organization should buy SD-WAN. The real question is:

How much operational responsibility, technical control, and expertise should remain inside the enterprise?

A Brief SD-WAN Refresher

SD-WAN stands for Software-Defined Wide Area Network. It is a software-defined approach for connecting branch offices, data centers, cloud platforms, and other distributed environments.

Instead of treating every branch router primarily as an independent configuration point, SD-WAN uses centralized software and policies to manage network behavior across many locations.

An SD-WAN edge can use connections such as:

  • MPLS
  • Dedicated internet access
  • Business broadband
  • Fiber
  • Carrier Ethernet
  • 4G/LTE
  • 5G

For example, the platform can measure latency, packet loss, jitter, and availability across different paths. Based on those measurements and configured business policies, it can then select an appropriate path for application traffic.

A company might give voice and video applications higher priority than large software downloads. If a preferred circuit begins to experience poor performance, application-aware routing can potentially move important traffic to another path that still meets the required service conditions.

In addition, SD-WAN generally creates a logical overlay across the physical or logical connectivity underneath it. The overlay provides the software-defined networking layer, whereas MPLS, internet, fiber, and wireless connections can form the underlay.

For a standardized service perspective, MEF 70.2 defines the externally visible behavior of an SD-WAN service and formalizes the relationship between the SD-WAN subscriber, service provider and agreed service attributes.

For a deeper comparison of these concepts, see our guide to SD-WAN vs traditional WAN.

Why the SD-WAN Management Model Matters

The same SD-WAN technology can produce very different business results depending on how it is operated.

A technically capable platform can still perform poorly if nobody reviews alerts, updates policies, manages software, coordinates carriers, investigates recurring circuit problems, or responds effectively during major incidents.

Therefore, the management model determines important responsibilities such as:

  • Who designs the WAN architecture?
  • Who selects and manages underlay connectivity?
  • Who installs and activates branch equipment?
  • Who can modify routing and application policies?
  • Who monitors the service outside normal working hours?
  • Who contacts carriers when a circuit fails?
  • Who performs software upgrades and certificate management?
  • Who handles security integration?
  • Who creates performance reports?
  • Who leads major incidents involving multiple suppliers?

These questions cannot be answered simply by comparing product feature lists. They require a clear operating model covering people, processes, tools, access rights, approvals, service levels, and accountability.

It is also important to distinguish the management model from the deployment architecture. On-premises, cloud-hosted, and hybrid architectures describe where technology components operate. Self-managed, co-managed, and fully managed describe who performs the operational work.

What Is Self-Managed SD-WAN?

In a self-managed SD-WAN model, the enterprise operates the solution primarily with its own employees or dedicated contractors.

This approach is sometimes called:

  • DIY SD-WAN
  • Customer-managed SD-WAN
  • In-house SD-WAN
  • Self-operated SD-WAN

As a result, the internal network team normally owns most design, configuration, monitoring, troubleshooting, and lifecycle activities.

Responsibilities can include:

  • Creating the SD-WAN architecture and technical standards
  • Selecting platforms, licences, and edge devices
  • Selecting connectivity providers
  • Designing routing
  • Creating application policies
  • Configuring QoS
  • Designing segmentation
  • Deploying and activating branch equipment
  • Monitoring network health
  • Troubleshooting overlay and underlay issues
  • Coordinating carriers and vendors
  • Managing software upgrades
  • Managing certificates
  • Handling hardware lifecycle
  • Integrating security platforms

Self-managed does not mean the organization receives no external assistance. A technology vendor may provide product support, documentation, replacement hardware, professional services, and software updates.

However, the enterprise remains the primary operator.

This approach generally provides the greatest technical control. At the same time, it creates the greatest internal operational responsibility.

What Is Co-Managed SD-WAN?

By comparison, a co-managed SD-WAN divides operational responsibility between the enterprise and a service provider.

This approach can be attractive for organizations that want external operational support without surrendering all network control.

For example, a provider might manage:

  • WAN edge infrastructure
  • Underlay circuits
  • Hardware lifecycle
  • Platform health
  • Monitoring
  • Carrier incidents
  • Software maintenance

Meanwhile, the enterprise could retain responsibility for:

  • Application priorities
  • Business policies
  • Segmentation strategy
  • Selected configuration changes
  • Cloud architecture
  • Security policy
  • Major business-risk decisions

However, there is no universal co-managed model.

One provider may allow customers to modify application policies directly. Another may offer read-only visibility and require changes to pass through its service desk. A third may allow customers to manage routine business-hour changes while the provider handles monitoring and incidents outside those hours.

Current enterprise SD-WAN platforms can support separation between service-provider and customer roles. Therefore, co-management is not simply an organizational concept; modern platforms can provide technical mechanisms for different administrative privileges and management views.

Nevertheless, successful co-management depends on clearly documented responsibilities. Without them, two problems can appear:

  • Both parties perform the same task.
  • Neither party performs the task because each expects the other to act.

A responsibility matrix and clear escalation model are therefore essential.

What Is Fully Managed SD-WAN?

At the other end of the spectrum, a fully managed SD-WAN places most routine operational responsibilities with a telecommunications provider, managed service provider, network integrator, or specialist network provider.

Depending on the agreement, the provider may perform:

  • Solution design
  • Hardware procurement
  • Licensing
  • Branch deployment
  • Configuration
  • Underlay provisioning
  • Monitoring
  • Incident management
  • Carrier coordination
  • Performance analysis
  • Software upgrades
  • Hardware replacement
  • Reporting
  • Technical support

The customer typically interacts with the service through a portal, service desk, service manager, or other governance process.

Routine configuration changes may come from a service catalogue. More complex changes may require design review, approval, and a maintenance window.

Nevertheless, fully managed does not mean the customer has no responsibilities.

The enterprise still needs to:

  • Define business and application requirements
  • Approve architecture
  • Identify critical sites and applications
  • Define risk tolerance
  • Approve major changes
  • Review performance
  • Manage internal applications
  • Maintain business continuity planning
  • Govern the provider
  • Hold the provider accountable against contracts and SLAs

A fully managed service can reduce operational workload. However, it cannot transfer all business accountability to the provider.

Self-Managed vs Co-Managed vs Managed SD-WAN Comparison

Comparison Factor Self-Managed SD-WAN Co-Managed SD-WAN Fully Managed SD-WAN
Daily operations Enterprise Shared Provider
Policy control High Shared or negotiated Depends on service model
Internal expertise High requirement Medium to high Lower operational requirement
Monitoring Enterprise Usually shared/provider-led Typically provider-led
Deployment Enterprise-led Joint Provider-led
Customization Usually highest High within agreed boundaries Depends on service catalogue
Carrier management Enterprise Shared Often provider
Troubleshooting Enterprise leads Joint process Provider usually leads
Lifecycle management Enterprise Shared Typically provider-led
Change speed Direct internal action Depends on access rights Depends on change SLA
Service accountability Distributed across suppliers Shared More centralized
Best suited for Mature network teams Enterprises wanting control plus support Organizations wanting operational outsourcing

This table shows the general pattern. However, specific contracts can significantly change the details.

SD-WAN operating models comparison showing self-managed, co-managed and fully managed SD-WAN responsibilities
Comparison of self-managed, co-managed and fully managed SD-WAN, highlighting differences in ownership, operations, control and service-provider responsibility.

10 Key Differences Between Self-Managed and Managed SD-WAN

1. Strategy and Architecture

Under self-management, the enterprise normally owns the target architecture. Its technical teams decide how to connect branches, cloud environments, data centers, internet gateways, and third-party networks.

They also determine whether locations should use MPLS, dedicated internet, broadband, cellular connectivity, or a combination of several transports.

In a co-managed arrangement, the enterprise typically provides business requirements while the provider contributes reference architecture and operational experience.

Finally, with a fully managed service, the provider may produce much of the detailed design. However, the customer should still review design assumptions, security implications, scalability, and business requirements.

The underlay decision deserves particular attention. SD-WAN can use MPLS without being dependent on MPLS. Read our analysis of the changing role of MPLS in enterprise networks.

2. Procurement and Deployment

For deployment, a self-managed enterprise may need to coordinate:

  • Hardware ordering
  • Software licences
  • Carrier circuits
  • Shipping
  • Site contacts
  • Installation
  • Testing
  • Acceptance

Zero-touch provisioning can simplify device configuration. However, it does not eliminate physical logistics such as power, cabling, rack space, shipping, and circuit activation.

Meanwhile, in a co-managed model, the provider may handle hardware and connectivity while the enterprise provides site information, architecture standards, security policies, and acceptance criteria.

At larger scale, a fully managed provider may operate a repeatable deployment process across many sites.

This can be particularly useful for retail, banking, hospitality, healthcare, and other organizations with large branch networks.

3. Policy and Configuration Control

Another important consideration is policy control.

With self-managed SD-WAN, internal engineers can usually modify application routing, segmentation, QoS, security integrations, and traffic-steering policies directly.

In comparison, co-managed customers may receive selected administrative privileges while the provider protects the underlying infrastructure.

By contrast, fully managed customers may request many changes through a provider service desk or service catalogue.

Neither approach is inherently better.

The correct model depends on how frequently the business needs network changes and how much operational risk the organization wants to manage internally.

4. Monitoring

Self-managed organizations must build their own monitoring capability.

That includes deciding:

  • Which events create alerts
  • Who watches alerts
  • Who works outside business hours
  • How application performance is measured
  • How recurring problems are identified
  • How incidents are escalated

By contrast, managed services may provide continuous monitoring and proactive incident detection.

However, enterprises should not assume that every service includes 24/7 monitoring or proactive remediation. These capabilities should be explicitly defined in the service description and SLA.

5. Incident Management and Troubleshooting

One of the most important operational differences is troubleshooting responsibility.

An application problem might involve:

  • The SD-WAN edge
  • The overlay
  • An MPLS circuit
  • An internet provider
  • A firewall
  • DNS
  • A cloud platform
  • A SaaS provider

With self-management, internal engineers must determine where the problem exists and coordinate the relevant suppliers.

In a co-managed environment, troubleshooting becomes a shared process.

With a fully managed service, the provider can become the primary operational interface for technologies and connectivity included within its scope.

As a result, strong operational integration can sometimes provide more business value than an individual SD-WAN feature.

6. Carrier and Underlay Management

An SD-WAN overlay still depends on connectivity underneath it.

A global deployment may use different carriers, access technologies, contracts, and regulatory environments in different countries.

With self-management, the enterprise can select providers independently. This provides commercial flexibility but creates operational complexity.

A managed provider may instead coordinate multiple carriers behind one service-management interface.

For multinational organizations, this can significantly simplify incident escalation and service governance.

7. Internal Skills

Operating SD-WAN requires more than basic WAN knowledge.

Depending on the architecture, an internal team may need expertise in:

  • Routing
  • BGP
  • QoS
  • Network segmentation
  • Internet connectivity
  • Cloud networking
  • Cybersecurity
  • Automation
  • Application performance
  • Network operations

Organizations with mature engineering and network operations teams may be comfortable retaining those responsibilities.

On the other hand, organizations with smaller IT teams may prefer to consume operational expertise through a managed provider.

8. Lifecycle Management

SD-WAN platforms evolve continuously.

Therefore, operations must also account for:

  • Software upgrades
  • Security patches
  • Controller upgrades
  • Hardware replacement
  • Certificate renewal
  • Feature testing
  • Configuration migration

A self-managed enterprise performs these activities directly.

Meanwhile, managed providers typically perform some or most of them according to the service contract.

9. Cost and Total Cost of Ownership

It is tempting to describe self-managed SD-WAN as CapEx and fully managed SD-WAN as OpEx. However, real costs are more complex.

Many modern platforms use subscription licences even when operated internally. Likewise, a managed service may include hardware in a recurring fee or charge separately for equipment.

Therefore, a meaningful comparison should consider the complete Total Cost of Ownership (TCO).

A complete SD-WAN cost analysis should consider:

  • Platform licences
  • Hardware
  • Underlay connectivity
  • Security services
  • Cloud services
  • Monitoring platforms
  • Engineering staff
  • Training
  • 24/7 operational coverage
  • Vendor support
  • Managed-service fees
  • Implementation
  • Migration
  • Hardware replacement

Self-management may be economical when the necessary people, tools, and processes already exist.

By contrast, a managed service can provide more predictable recurring operational costs, although organizations should examine exclusions carefully.

Co-management provides another option by outsourcing selected activities while preserving some internal capabilities.

10. Scalability

A small SD-WAN environment may be relatively straightforward to operate internally.

However, complexity increases when an organization expands to hundreds or thousands of sites across multiple countries.

Scale introduces challenges such as:

  • Carrier diversity
  • Local regulation
  • Multiple languages
  • Time zones
  • 24/7 support
  • Hardware logistics
  • Field services
  • Service-level management

A managed provider can absorb some of this operational complexity.

Nevertheless, very large enterprises may already maintain global engineering and operations capabilities and therefore prefer significant internal control.

Advantages of Self-Managed SD-WAN

The biggest advantage of self-management is control. Internal teams can decide how policies are designed, when changes occur, and how the platform integrates with other enterprise systems.

Greater Technical Control

Engineers can directly modify the environment without depending on a service provider for every change.

Greater Customization

Organizations with specialized routing, cloud, security, or automation requirements can create highly customized architectures.

Direct Platform Access

Network teams can have deeper access to configuration, telemetry, APIs, and troubleshooting data.

Provider Flexibility

The enterprise can select SD-WAN technology and connectivity providers independently.

Internal Knowledge Development

Finally, operating the environment internally helps develop expertise in software-defined networking, automation, cloud networking, and modern network operations.

Challenges of Self-Managed SD-WAN

However, greater control creates greater responsibility.

Common challenges include:

  • Recruiting specialist engineers
  • Retaining network expertise
  • Providing monitoring coverage
  • Managing multiple carriers
  • Troubleshooting across suppliers
  • Maintaining security integrations
  • Managing software lifecycle
  • Supporting global logistics

Therefore, organizations should evaluate operational capabilities just as carefully as technical platform features.

Advantages of Managed SD-WAN

For fully managed SD-WAN, the primary advantage is operational focus. Internal IT teams can spend less time managing connectivity incidents and infrastructure lifecycle tasks and more time supporting applications and business transformation.

Reduced Operational Burden

A provider can assume responsibility for routine network operations.

Access to Specialized Expertise

Managed providers can maintain teams experienced in WAN platforms, carriers, network operations, and service management.

Carrier Coordination

Some providers can manage different access carriers through a single operational interface.

Defined Service Levels

Managed services can provide contractual objectives for support, availability, response, restoration, and other operational functions.

Lifecycle Support

The provider may coordinate platform upgrades, patches, and hardware replacement.

Global Scalability

Managed providers can help businesses expand across many locations without building equivalent internal operational capabilities in every geography.

Challenges of Managed SD-WAN

On the other hand, outsourcing introduces trade-offs.

Reduced Direct Control

Provider processes may restrict access to selected platform functions.

Change-Management Delays

A configuration change that an internal engineer could perform directly may need to pass through provider processes and approval workflows.

Provider Dependency

The user experience can depend heavily on the provider’s operational maturity.

Contract Complexity

Service scope, exclusions, responsibilities, and SLAs must be understood clearly.

Potential Lock-In

Bundling technology, connectivity, hardware, and operations with one provider can make a future migration more complex.

Co-Managed SD-WAN: The Middle Ground

Co-management aims to combine enterprise control with external operational support.

For example, responsibilities could be divided as follows:

Responsibility Enterprise Provider
Business application priorities Primary Support
WAN infrastructure operation Visibility Primary
Carrier incidents Visibility Primary
Application policies Primary/shared Shared
Software upgrades Approval Execution
Architecture Primary Advisory/shared
Monitoring Visibility Primary
Security policy Primary Implementation/support

This table is illustrative rather than universal.

Nevertheless, every important activity should have a documented owner. Otherwise, unclear boundaries can lead to duplicate work, delayed responses, or accountability gaps.

SD-WAN Security: Who Is Responsible?

Security deserves special attention because managed WAN does not automatically mean managed cybersecurity.

Technology Security

First, consider the technical controls. Depending on the platform and service, these may include:

  • Encrypted overlay connectivity
  • Secure device identity
  • Segmentation
  • Firewall integration
  • Application policies
  • Cloud security integration

Operational Security

Technical features alone are not enough. Operational security can include:

  • Software patching
  • Certificate renewal
  • Configuration review
  • Alert triage
  • Log retention
  • Vulnerability remediation
  • Backup management
  • Incident response

Zero Trust should also be treated as a broader security architecture rather than an SD-WAN feature.

NIST SP 800-207

explains that Zero Trust shifts security away from implicit trust based on network location and toward explicit protection of users, devices, assets and resources.

Governance and Shared Responsibility

Finally, governance connects technical and operational security.

The enterprise should clearly determine who is responsible for:

  • Firewalls
  • Secure Web Gateway
  • DNS security
  • Intrusion prevention
  • Cloud Access Security Broker
  • Zero Trust Network Access
  • Threat detection
  • Security logging
  • Incident response

Even in a fully managed model, the enterprise retains responsibility for its business risk and security governance.

Managed SD-WAN responsibility model showing enterprise governance, shared security policy and provider technical operations
Managed SD-WAN redistributes operational responsibilities across the enterprise and service provider while business accountability remains internal.

Managed SD-WAN vs SASE

SASE and Managed SD-WAN should not be treated as interchangeable terms.

Managed SD-WAN describes how the WAN service is operated.

SASE describes a broader architecture that brings networking and cloud-delivered security capabilities together.

A SASE architecture may combine SD-WAN with capabilities such as:

  • Secure Web Gateway (SWG)
  • Cloud Access Security Broker (CASB)
  • Firewall-as-a-Service
  • Zero Trust Network Access (ZTNA)

Therefore, an enterprise could use:

  • Self-managed SD-WAN
  • Co-managed SD-WAN
  • Fully managed SD-WAN
  • Managed SD-WAN integrated with SSE
  • A broader managed SASE service

The correct model depends on both network and security requirements.

Why SLAs Matter in Managed SD-WAN

One reason organizations purchase managed networking services is to establish clearer service accountability.

However, an SLA is useful only when its scope and measurement methodology are clearly defined.

Enterprises should examine:

  • Service availability
  • Edge availability
  • Underlay availability
  • Incident response targets
  • Restoration targets
  • Change-management targets
  • Support availability
  • Performance reporting
  • Escalation procedures

In addition, organizations should distinguish between overlay service performance and underlay circuit performance.

A managed provider may rely on third-party access carriers and therefore may not have equal operational control over every part of the end-to-end service.

Multi-Carrier Managed SD-WAN

Multi-carrier operations are particularly important for global enterprises.

A multinational WAN can include dozens of local connectivity providers. Although the SD-WAN overlay creates a common logical architecture, the enterprise still has to manage operational activities such as:

  • Carrier ordering
  • Installations
  • Fault management
  • Billing
  • Escalations
  • Local regulations
  • Contract renewals

A managed provider may consolidate some of these activities.

Therefore, when evaluating a service, ask whether the provider:

  • Owns the underlying circuits
  • Resells third-party connectivity
  • Supports customer-provided access
  • Supports hybrid carrier models
  • Provides end-to-end incident coordination

These operational details can significantly influence the real value of the managed service.

When Should You Choose Self-Managed SD-WAN?

Self-managed SD-WAN may be the strongest fit when your organization:

  • Has a mature network engineering team
  • Operates a capable internal NOC
  • Wants maximum configuration control
  • Has specialized routing or security requirements
  • Has strong automation capabilities
  • Can manage multiple carriers
  • Wants direct platform access
  • Views networking expertise as a strategic internal capability

When Should You Choose Managed SD-WAN?

By contrast, managed SD-WAN may be more appropriate when your organization:

  • Has limited network operations resources
  • Operates many distributed locations
  • Needs multi-carrier coordination
  • Wants clearer service accountability
  • Requires extended-hours or 24/7 support
  • Wants to reduce day-to-day WAN operations
  • Needs global deployment support
  • Prefers service-based lifecycle management

When Should You Choose Co-Managed SD-WAN?

Meanwhile, a co-managed model can work particularly well when the enterprise wants to retain strategic control but outsource repetitive operational tasks.

For example, it may fit when:

  • The internal team wants application-policy control.
  • The provider handles carrier incidents.
  • The enterprise wants direct platform visibility.
  • Architecture remains an internal competency.
  • The provider handles monitoring.
  • The provider manages infrastructure lifecycle.
  • Both teams collaborate on significant changes.

For many large enterprises, this provides a practical compromise between technical autonomy and operational efficiency.

SD-WAN Management Model Decision Matrix

Requirement Self-Managed Co-Managed Fully Managed
Maximum technical control Strong fit Good fit Depends on provider
Limited internal network staff Weak fit Good fit Strong fit
Strong internal expertise Strong fit Strong fit Optional
Global multi-carrier network Resource intensive Good fit Strong fit
Highly customized policies Strong fit Strong fit Verify flexibility
Outsourced 24/7 operations Weak fit Good fit Strong fit when included
Develop internal expertise Strong fit Strong fit Lower priority
Single operational interface Weak fit Good fit Strong fit

How to Choose the Right SD-WAN Operating Model

First, assess your internal skills and staffing. Do not count only the number of IT employees. Instead, determine whether the organization has people who can design routing, build SD-WAN policies, troubleshoot internet performance, understand security controls, test software upgrades, and lead major incidents.

Next, consider operational coverage. A company with ten local offices has very different requirements from an organization with hundreds of branches across multiple continents.

Another important factor is change speed. Some organizations change WAN policies only a few times per year. Others open locations, migrate applications, or modify cloud connectivity every week.

Security and compliance must also influence the decision. Regulated organizations should document responsibilities for administrator access, separation of duties, logging, encryption, certificate management, patching, vulnerability remediation, and incident notification.

Finally, compare three-to-five-year total cost. Include platform costs, salaries, training, support, monitoring, after-hours coverage, service-provider charges, hardware replacement, integration, and eventual migration costs.

Questions to Ask a Managed SD-WAN Provider

Once you select a preferred operating model, the next step is evaluating providers.

An effective RFP should focus on operational outcomes and responsibilities rather than simply asking whether a feature exists.

Therefore, ask providers questions such as:

  • Which SD-WAN platform do you use?
  • Who operates the controllers?
  • What administrative access will our team receive?
  • Can we modify application policies ourselves?
  • Who manages underlay circuits?
  • Can we keep our existing carriers?
  • Do you support customer-provided internet access?
  • Who handles incidents involving third-party carriers?
  • Is monitoring provided 24/7?
  • Which alerts create proactive incidents?
  • Which SLAs apply?
  • How is application performance measured?
  • Who manages software upgrades?
  • How are emergency changes handled?
  • Which security functions are included?
  • How does the service integrate with SSE or SASE?
  • Who owns configuration data?
  • Can customers export telemetry and logs?
  • What happens when the contract ends?
  • How can we migrate to another provider?

How to Migrate to Managed SD-WAN

Moving from an existing WAN to a managed SD-WAN service should be treated as an operational transformation rather than simply a hardware installation.

Step 1: Assess the Current WAN

Document sites, circuits, providers, routing, devices, applications, security dependencies, operational processes, and existing contracts.

Step 2: Define the Target Operating Model

Decide which responsibilities should remain internal and which should move to the provider.

Step 3: Build a RACI Matrix

Clearly define responsibility for:

  • Architecture
  • Policy changes
  • Incident management
  • Carrier escalation
  • Security
  • Upgrades
  • Reporting
  • Governance

A RACI matrix can make these operational boundaries explicit before migration. See our

SD-WAN and network migration RACI example

for a practical responsibility model covering the project manager, network architecture, operations, security, business teams and service provider.

Step 4: Define Service Levels

Agree measurable objectives for availability, incident response, restoration, support, and change management.

Step 5: Pilot Representative Sites

Test both the technology and the operating model.

A technically successful pilot can still expose weaknesses in provider communication, incident management, escalation, or change processes.

Step 6: Migrate in Waves

A phased approach allows both teams to improve deployment and operational procedures before expanding to the entire WAN.

Step 7: Establish Ongoing Governance

After deployment, regularly review:

  • SLA performance
  • Incidents
  • Application experience
  • Network changes
  • Capacity
  • Security
  • Recurring problems
  • Service-improvement actions

A managed service still requires active customer governance.

Frequently Asked Questions

What is the difference between SD-WAN and Managed SD-WAN?

SD-WAN is the networking architecture and technology. Managed SD-WAN is an operating model in which a service provider manages agreed parts of the SD-WAN environment for the enterprise.

What is self-managed SD-WAN?

Self-managed SD-WAN means the enterprise takes primary responsibility for architecture, configuration, monitoring, troubleshooting, carrier management, and lifecycle operations.

What is co-managed SD-WAN?

Co-managed SD-WAN divides responsibilities between the enterprise and service provider. For example, the provider may operate infrastructure and manage incidents while the enterprise retains application-policy control.

Is Managed SD-WAN more expensive?

Not necessarily. A managed service adds recurring service charges but may reduce internal operating requirements and carrier-management overhead. Organizations should compare total cost of ownership rather than only the provider fee.

Does Managed SD-WAN include internet circuits?

It depends on the service. Some providers include underlay connectivity, while others manage customer-provided circuits or support a combination of provider and customer connectivity.

Does Managed SD-WAN include security?

Not automatically. Security capabilities vary by platform and service. Organizations should confirm which functions, including encryption, segmentation, firewall services, SSE, and SASE integration, are actually included.

Does Managed SD-WAN provide 24/7 monitoring?

Many managed services offer 24/7 monitoring, but organizations should verify this explicitly. Monitoring hours, proactive incident handling, and response targets should be defined in the service description and SLA.

Who controls policies in Managed SD-WAN?

It depends on the operating model. Some providers control most configuration, whereas co-managed services may allow customers to create or modify selected application and networking policies.

Can Managed SD-WAN use multiple carriers?

Yes. Depending on the service design, a managed SD-WAN can use connectivity from the provider, third-party carriers, customer-provided access, or a combination of these models.

Is Managed SD-WAN the same as SASE?

No. Managed SD-WAN describes how an SD-WAN service is operated. SASE is a broader architecture combining networking with cloud-delivered security capabilities.

Can a company move from Managed SD-WAN to self-managed SD-WAN later?

Potentially, yes. However, organizations should consider platform ownership, licences, administrative access, configuration portability, carrier contracts, hardware ownership, and exit conditions before signing a managed-service agreement.

Which SD-WAN model is best?

There is no universally best operating model. Self-managed SD-WAN can suit organizations with strong networking capabilities and a requirement for maximum control. Managed SD-WAN can suit organizations that want to outsource day-to-day operations. Co-managed SD-WAN can provide a balance between the two.

Conclusion: SD-WAN vs Managed SD-WAN

The choice between SD-WAN and Managed SD-WAN is fundamentally an operating-model decision.

The underlying technology can be similar, but responsibility can be very different.

Self-managed SD-WAN provides direct control and can work well for enterprises with mature engineering and operations capabilities.

Fully managed SD-WAN transfers more routine operational responsibility to a provider and can simplify monitoring, lifecycle management, carrier coordination, and support.

Co-managed SD-WAN provides a middle ground, allowing organizations to preserve strategic control while outsourcing selected operational functions.

Therefore, the decision should consider:

  • Internal network expertise
  • Required control
  • Number of sites
  • Geographic coverage
  • Carrier complexity
  • Security architecture
  • Operational coverage
  • Service-level expectations
  • Change requirements
  • Total cost of ownership

Ultimately, the strongest SD-WAN operating model is not necessarily the model that outsources the most work or provides the most internal control. It is the model that places each responsibility with the organization best equipped to perform it while maintaining clear accountability.


Continue exploring SD-WAN:

Get Practical Insights from TechTeamSynergy

Join TechTeamSynergy Weekly for practical insights, frameworks, templates and resources covering Technology, Team and Transformation.

Join TechTeamSynergy Weekly →

Comments are closed.