Updated: October 2026
Every multi-site client eventually asks why their branch offices are connected like it's 2009 and billed like it's a private jet. SD-WAN (software-defined wide area networking, often written SDWAN) is the answer they've half-heard about, and this guide explains what it is, what it costs, and how it compares to MPLS and VPN. It's written for the people who'll get the question: MSP owners pricing a network refresh and the technicians who'll run it.
TL;DR
- SD-WAN in one line. Software that steers traffic across any mix of broadband, LTE, 5G, or MPLS circuits based on real-time link quality and per-app policy, managed from one console.
- The money. SD-WAN runs $100-500 per site per month; a 100 Mbps MPLS circuit runs $1,500-3,000.
- The catch. By 2026, 60% of new SD-WAN purchases ship inside a single-vendor SASE bundle, so the buying decision now includes security.
- For MSPs. Multi-site clients are asking for co-managed SD-WAN by name.
What SD-WAN Is in Plain Words
A wide area network is just the connections between a company's locations: branches, headquarters, data centers, and the cloud. The traditional way to build one is to lease a dedicated private circuit into every site and let the carrier manage the path. SD-WAN takes a different approach: it puts a smart edge device at each site, lets that site use whatever connectivity is available, and moves the intelligence into software.
The word "software-defined" carries the whole idea. The physical circuits (a cable broadband line, a fiber link, a 5G modem, an old MPLS circuit) become interchangeable transport. The software layer on top decides, packet by packet, which traffic takes which path. Change the policy in the console and every site updates. No truck rolls, no per-site CLI sessions, no waiting on a carrier change ticket.
That's the pitch in one sentence: SD-WAN separates what your network does from what your circuits are. The circuits become a commodity you shop for, and the behavior becomes a policy you control.
How SD-WAN Works Under the Hood
Each site gets an edge appliance, physical or virtual, that builds encrypted tunnels to the other sites and to the cloud over every available link. The appliances measure each link continuously: latency, jitter, packet loss. That telemetry feeds the path decisions.
Application-aware routing is the part that sells demos. The edge device identifies the application on the first packets of a flow, then applies the policy you set: voice and video get the cleanest path, Microsoft 365 traffic breaks out locally to the internet instead of hairpinning through headquarters, and bulk backup traffic gets shoved onto the cheapest link. When a link degrades mid-call, the flow moves to a better path without dropping.
The orchestrator ties it together. One console, cloud-hosted or on-prem, holds the configuration, policies, and monitoring for every site. New sites come up with zero-touch provisioning: ship the box, plug it in, it phones home and pulls its config. For anyone who has driven three hours to reconfigure a branch router, that one feature justifies the category.
A worked example makes it concrete. A regional accounting firm has 8 offices, each with cable broadband and a fiber line. Policy says client video calls ride the fiber, file sync rides cable, and if fiber latency crosses 40ms, calls shift to cable automatically. Head office writes that policy once. The Tulsa branch doesn't need a network engineer; it needs a power outlet.
Two terms you'll meet in every datasheet: the underlay is the physical circuits (the broadband, fiber, LTE), and the overlay is the encrypted tunnel fabric SD-WAN builds on top of them. Underlay problems (a flaky cable segment) are still circuit problems you chase with the ISP. The overlay is what keeps users working while you chase them.
SD-WAN vs MPLS
MPLS is the incumbent SD-WAN displaces. It's a carrier-managed private network with strong, predictable performance and a price to match. The comparison MSP buyers care about looks like this:
| MPLS | SD-WAN | |
|---|---|---|
| Typical cost per site | $1,500-3,000/month for 100 Mbps | $100-500/month plus commodity circuits |
| Bandwidth pricing | $50-100 per Mbps in the US mid-market | Broadband rates, a fraction of that |
| New site provisioning | Weeks to months, carrier-dependent | Days; zero-touch once circuits exist |
| Cloud and SaaS traffic | Hairpins through a data center | Breaks out locally, direct to cloud |
| Failover | Depends on a second circuit and BGP tuning | Automatic, per-flow, sub-second |
| Who controls changes | The carrier | You (or your MSP) |
The cost figures above are per Lightyear's 2026 procurement benchmarks, and the fine print matters: comparing a managed 1 Gbps SD-WAN deployment against 1 Gbps of MPLS shows about 25% savings, while raw bandwidth-for-bandwidth comparisons run 50-84% cheaper. The spread depends on how much management and security you wrap around the broadband.
MPLS isn't going away tomorrow, and ripping it out isn't always the play. Sites running latency-critical legacy applications sometimes keep one MPLS link and let SD-WAN blend it with broadband, using the private circuit only for the traffic that needs it. That hybrid pattern is a feature, not a compromise: it's how you draw down an MPLS contract without a forklift cutover.
If the routing side still feels abstract, this walks the MPLS-to-SD-WAN swap through a real topology:
SD-WAN vs VPN
The comparison that comes up with smaller clients is site-to-site VPN, because it's what they already have. A mesh of IPsec tunnels between firewalls does connect sites over the internet, and for two or three locations with light traffic it can be enough.
The difference shows up as sites and applications multiply. VPN tunnels are static: one path, no awareness of what's inside, failover only as good as your manual configuration. SD-WAN adds per-application steering, continuous path measurement, central policy, and reporting per site and per app. A 12-site client on hub-and-spoke VPN is running a network held together by one senior engineer's memory. The same client on SD-WAN is running a policy anyone on the team can read.
The rule of thumb: VPN connects sites, SD-WAN operates a network. Clients under five sites with no cloud performance complaints can wait. Clients above that, or anyone hairpinning Teams calls through a headquarters firewall, are already paying the difference in user experience.
Who Needs SD-WAN and Who Can Skip It
The strongest fit is any organization where multiple sites plus cloud applications meet a lean IT team. Retail and restaurant chains with POS systems that can't drop. Clinic groups moving imaging between locations under compliance rules. Logistics firms with warehouses in places where the only fast option is cable plus 5G. Professional services firms whose Teams and Zoom quality is the product. In each case the pattern is the same: many sites, cloud-hosted core apps, and no appetite for a WAN engineer on payroll.
The skip list is just as clear. A single-office client with everything in SaaS has no WAN to define; a decent firewall and good internet do the job. A two-site client with a stable VPN and no performance complaints can wait for the next hardware refresh. And a client mid-contract on MPLS with heavy termination fees should plan the transition around expiry dates, not around a vendor's quarter-end discount.
The gray zone is the hub-and-spoke client whose "hub" is now an empty office. If the data center moved to Azure and half the staff went hybrid, the WAN design is solving a problem that no longer exists, and that client is closer to needing SD-WAN than their site count suggests.
The SASE Shift Changes the Buying Decision
SD-WAN stopped being a standalone purchase. Gartner's projection, reported by Fierce Network, is that by 2026, 60% of new SD-WAN purchases will be part of a single-vendor SASE offering, up from 15% in 2022. SASE (secure access service edge) bundles the networking layer with cloud-delivered security: secure web gateway, zero trust network access, cloud firewall.
The consolidation is already visible in market share: the top six SASE and SD-WAN vendors held 71% of the market in late 2024, up from 64% a year earlier. The practical consequence for a buyer is that the SD-WAN decision and the security stack decision have merged. Pick an SD-WAN vendor today and you've probably also picked your web filtering, your remote access model, and your firewall roadmap for the next contract cycle.
That has a sharp implication for MSPs: quoting SD-WAN without asking about the client's security roadmap sets up a rip-and-replace conversation two years in. The vendors driving the category (Cisco, Fortinet, Palo Alto Networks, Versa, VMware, Cato) are all selling the bundle, and the bundle is where the pricing power sits.
The shortlist MSPs are working from in 2026, and where each platform stops being multi-tenant:
What SD-WAN Costs
Budget in three lines: the SD-WAN licensing and hardware, the circuits underneath it, and the management on top. Licensing and edge devices land in the $100-500 per site per month band for typical mid-market deployments, with premium bundles that fold in advanced security running $500-1,000+ per Socium's 2026 cost guide. Circuits are whatever broadband, fiber, and LTE cost in each market, which is the line where the MPLS savings come from. Managed service wraps add $125-375 per site per month depending on scope.
Watch the quiet costs. Per-site licensing tiers jump at bandwidth thresholds, so a client upgrading circuits can trigger a license step they didn't budget. High-availability pairs double the hardware line at sites that need it. And decommissioning MPLS has exit costs: early termination fees on circuits with years left can erase first-year savings, which is why migrations usually track contract expiry dates site by site.
For an MSP, the pricing story is the good news. Every line above converts into a monthly per-site number a client can compare against their MPLS bill, and the delta funds the managed service. This is the rare infrastructure conversation where the cheaper option is also the operational upgrade.
Why MSPs Should Care
SD-WAN turned network transformation into a recurring service, and demand is arriving in exactly the shape MSPs sell. Buyers at multi-location organizations are searching for partners that offer co-managed SD-WAN: they want the platform run for them, with their own team keeping visibility and change rights. That co-managed middle is underserved, because carriers sell fully-managed black boxes and vendors sell DIY consoles.
The service line stacks naturally. Design and migration are project revenue. Monitoring, policy management, and circuit vendor management are monthly recurring. QBRs get a report that shows per-site uptime and per-app performance, which is the kind of evidence that renews contracts. Our guide to network management software covers the tooling layer that sits alongside it.
Pricing the service follows the same per-site logic as the platform. A managed SD-WAN line at $150-300 per site per month sits comfortably inside the $125-375 managed-wrap band the market already pays, and it anchors against an MPLS bill the client can see shrinking. Bundle the circuit vendor management in, because chasing ISPs is the chore clients most want gone, and it's the part they can't do without you.
There's also a defensive reason. If your client's SD-WAN comes fully managed by a carrier, the carrier owns the network conversation, the performance data, and eventually the security conversation too. The MSP that brings co-managed SD-WAN keeps all three.
How to Evaluate Without Getting Burned
Start from operating model, not vendor. Fully managed means the provider makes every change and your client waits in their queue. DIY means your team owns a console and a learning curve. Co-managed splits it: the provider handles the platform, you keep policy control and visibility. Decide which model fits the client's team before comparing feature matrices, because the wrong model with the best vendor still fails.
Then test the things demos skip. Ask what happens to an active voice call when the primary link dies, and make the vendor show it, not describe it. Check how the platform reports per-application performance to someone who isn't a network engineer, because that report is what your client's CFO will judge the project by. Confirm local breakout for Microsoft 365 and the client's other core SaaS. And read the licensing table for the bandwidth tier jumps.
Plan the migration site by site, not big bang. The standard play is to stand up SD-WAN at two or three pilot sites alongside the existing network, run both for a billing cycle, and use the telemetry to prove the case before touching the rest. MPLS circuits drop off as their contracts expire, which turns a scary cutover into a 12-month glide path with a savings line that grows each quarter.
Finally, instrument it from day one. SD-WAN gives you telemetry no MPLS carrier ever shared, and it's only useful if someone watches it. Baseline before migration, compare after, and put the delta in the first QBR; our breakdown of network performance management software covers what to measure. Migrations that skip the baseline never get credit for the improvement.
A 15-site evaluation runs in the open here, down to the OpEx gap between the two finalists:
Where OpenFrame Fits
SD-WAN hands you a stream of alerts, telemetry, and per-site tickets, and that stream lands somewhere. If it lands in a technician's inbox next to eight other consoles, the visibility you just sold becomes noise. The operational layer around the network edge (ticketing, monitoring, automation, client reporting) is where Flamingo's OpenFrame sits: an AI-native all-in-one MSP/IT platform with PSA included, where AI agents work the alert queue instead of adding another dashboard to check.
A degraded-link alert at a client site is a textbook agent task: correlate it with the circuit vendor's status, open the ticket, attach the telemetry, escalate only if it breaches SLA. OpenFrame doesn't ship SD-WAN, and the edge platform stays the client's choice, with no lock-in on the layer above it. Consolidating that layer is what keeps a 40-site network from consuming a 4-person team; our guide to IT infrastructure management maps the full stack around it.
Own the Edge Conversation
SD-WAN is the rare technology where the plain-words version survives contact with the datasheet: software steers traffic across cheap circuits, policy replaces carrier tickets, and the savings against MPLS fund the management layer. The buying decision now travels with SASE, the demand is arriving as co-managed, and the telemetry only pays off if someone operates it.
Your clients will have this conversation with someone this year. The carrier wants it, the vendors want it, and the MSP who walks in with per-site numbers and an operating model wins it.

Aliaska Varieva
Head of Platform
Hi! I’m Aliaska, and I’ve been working as a software engineer (mostly Java + a bit Kotlin) for over 8 years now. I mostly spend my time building backend services, integrating systems, fixing bugs (the fun part 🙃), and making sure things don’t fall apart behind the scenes.
