Every UK business running more than one office, a warehouse, or a distributed team of home workers is quietly betting its productivity on a wide area network it rarely thinks about — until the day it fails. In 2026 that bet is getting harder to place, because the three ways of building a WAN have never been further apart on cost, resilience and cloud-readiness. SD-WAN managed services now sit alongside legacy MPLS circuits and DIY internet VPNs as the third and fastest-growing option, and for most 20–500 seat organisations the choice between them is the single most consequential networking decision they will make this year.
This guide dissects all three WAN architectures — MPLS, internet VPN and SD-WAN — across the dimensions that actually decide the outcome: real UK pricing, resilience and uptime, application performance, security and Cyber Essentials v3.3 alignment, and readiness for a cloud-first estate. You will come away knowing which architecture fits which kind of organisation, what you should genuinely expect to pay, how each option maps to NCSC guidance and the ICO’s expectations, and a structured decision framework you can run against your own sites. No hype, no vendor spin — just the numbers and the trade-offs that separate a resilient network from an expensive regret.
What SD-WAN, MPLS and internet VPN actually are
Before comparing them it is worth being precise, because the three terms describe different layers of the same problem — connecting sites, users and cloud platforms together securely and reliably. SD-WAN managed services are not a replacement for your internet lines; they are an intelligent software layer that sits on top of whatever circuits you already have and decides, packet by packet, which path each application should take. MPLS and internet VPN, by contrast, are two older answers to the same question, and understanding where each came from explains why the market is moving the way it is.
MPLS (Multi-Protocol Label Switching) is a private, carrier-managed network. Your sites connect into a single provider’s cloud with dedicated tails, and the carrier guarantees performance across it with a contractual Service Level Agreement covering latency, jitter, packet loss and availability. For twenty years it was the gold standard for connecting branch offices, because it delivered predictable, business-grade performance that the public internet could not. Its weaknesses — cost, rigidity, long provisioning times and a design that assumes traffic flows back to a central data centre — only became painful once organisations moved their applications to the cloud.
An internet VPN is the do-it-yourself alternative: each site gets an ordinary business broadband or leased-line connection, and encrypted IPsec tunnels are built across the public internet to link them together, usually terminating on a firewall at each location. It is cheap and quick to stand up, which is why so many growing SMEs reached for it. The catch is that the public internet offers no performance guarantee, tunnel management becomes a full-time job as sites multiply, and a single congested link can drop voice calls and stall cloud applications with no automatic remedy.
SD-WAN emerged to take the best of both. It runs over cheap internet lines like a VPN — often two or more per site — but adds centralised policy, real-time path selection, application awareness and automatic failover, giving you something close to MPLS-grade resilience at internet-grade prices. Platforms such as Cisco Meraki, FortiGate (Fortinet) and Cisco Viptela dominate the UK market, and a growing share of deployments are delivered as fully managed network services rather than bought as boxes and self-run. The rest of this guide compares the three on the terms that matter.
The cleanest mental model: MPLS is a private motorway you rent by the mile, internet VPN is the ordinary road network you drive on for free but with no traffic control, and SD-WAN is an intelligent satnav that uses every available road, reroutes instantly around a jam, and always sends your most important journeys down the fastest clear path. You are not choosing a road — you are choosing how smart the driver is.
The UK WAN market by the numbers — a 2026 reality check
The direction of travel in the UK is not subtle. As applications have moved to Microsoft 365, Azure, Google Workspace and hundreds of SaaS platforms, the old hub-and-spoke model that MPLS was built for has become a bottleneck, and buyers have responded. The chart below sets out the market signals that shape a WAN architecture decision in 2026 — indicative of the UK SME and mid-market picture rather than a single dataset, but directionally beyond dispute.
Read those bars together and the argument for change writes itself. More than eight in ten organisations now run their most important applications somewhere other than their own data centre, yet a third are still paying a premium to backhaul that cloud traffic across a private MPLS core designed for a world that no longer exists. Meanwhile fewer than a third of sites have any automatic failover at all, and cost pressure on the WAN is now a board-level conversation for the majority of IT teams. The organisations coming out of this well are the ones treating the shift as an architecture upgrade — smarter routing, real resilience, lower recurring cost — rather than a like-for-like circuit renewal.
SD-WAN vs MPLS vs internet VPN — the UK 2026 cost breakdown
Cost is where the three architectures diverge most sharply, and where the marketing is most misleading. The comparison in the SD-WAN vs MPLS UK debate is rarely like-for-like: an MPLS circuit buys a contractual performance guarantee that raw internet bandwidth does not, so the honest comparison is not “price per megabit” but “total cost for a given level of resilience and performance.” The table below sets out realistic 2026 UK monthly pricing bands for a typical branch site under each model, on standard 36-month terms, so you can see what you are actually paying for.
| Model (per branch site) | Underlying access | Indicative monthly (ex VAT) | Provisioning | Performance guarantee | Best for |
|---|---|---|---|---|---|
| Internet VPN (DIY) | 1× business FTTP / leased line | £40–£250 | 2–6 weeks | None (best-effort) | Cost-led small sites, low-criticality traffic |
| MPLS circuit | Dedicated carrier tail 100Mbps | £350–£800+ | 30–90 working days | Full SLA (latency, jitter, loss) | Legacy hub-and-spoke, ultra-predictable estates |
| SD-WAN over single line | 1× FTTP + SD-WAN overlay | £120–£350 | Days (over existing line) | Application-aware, best-effort transport | Cloud-first single-line branches |
| SD-WAN dual-line (managed) | 2× diverse lines + overlay | £250–£600 | Days–weeks (line lead time) | Near-SLA via active-active paths | Most multi-site UK SMEs — the sweet spot |
| Hybrid MPLS + SD-WAN | MPLS primary + internet overlay | £450–£900+ | Line-dependent | SLA on MPLS, smart offload to internet | Large estates de-risking an MPLS exit |
The figures above are indicative UK market ranges for 2026, not quotes; actual pricing depends on postcode, carrier, contract length, bandwidth and the level of managed network services wrapped around the platform. Two patterns hold almost universally. First, a dual-line SD-WAN deployment typically lands well below the cost of a comparable MPLS circuit while delivering more resilience, because it uses commodity internet bandwidth intelligently rather than paying a premium for private transport. Second, the cheapest option on paper — a single-line internet VPN — is almost always the most expensive once you price in the outages, the lost productivity and the engineering time spent nursing tunnels that a smarter architecture would have avoided. Our companion piece on the business internet connectivity buying guide breaks down the underlying line costs that feed into every one of these bands.
How the architectures compare head-to-head
Strip away the acronyms and the real contest in most UK boardrooms is between the legacy incumbent — MPLS — and the modern challenger, a managed SD-WAN overlay. Internet VPN sits underneath both as the raw transport, so the meaningful architectural choice is how much intelligence you layer on top of it. The comparison below puts the two headline options side by side on the dimensions that decide the outcome.
Legacy MPLS
Private carrier network, hub-and-spoke
SD-WAN managed services
Software overlay on diverse internet lines
The highlight is not a blanket instruction to rip out MPLS tomorrow — it reflects where the market is genuinely heading and where most 20–500 seat organisations get the best return. If your estate is a handful of static sites all reaching applications hosted in one central data centre, and predictability matters more than cloud performance, MPLS can still be the right answer, and a hybrid MPLS-plus-SD-WAN design lets you keep its guarantees while offloading cloud traffic to cheaper internet paths. But if your applications live in Microsoft 365 and Azure, your headcount moves, and you resent paying a premium to send cloud traffic on a detour through your data centre, an SD-WAN overlay — ideally delivered as a managed service so someone else owns the policy, the monitoring and the firmware — is almost always the stronger architecture. It is the same conclusion buyers reach when they compare a rigid legacy circuit against a flexible modern one in the wider connectivity buying decision.
WAN readiness scoring — where most UK businesses sit today
Before choosing an architecture you need an honest picture of your current estate. The scoring grid below is the same triage we run at the start of a network review: it groups the common weak points into three cards — the transport layer, resilience, and security and management — and flags how much risk each gap carries for a cloud-dependent, multi-site organisation.
If you find yourself ticking two or more “High risk” rows, your WAN is a business-continuity problem waiting to surface, not just a performance complaint. The most common pattern we see in UK SMEs is a tangle of single-line sites stitched together with hand-built VPN tunnels on mixed-vintage firewalls, no central visibility, and no automatic failover anywhere — a design that works right up until the morning a fibre cut or a misconfigured tunnel takes a site offline and nobody can see why. Getting the security layer right also feeds directly into your Cyber Essentials posture, which we come back to below.
The WAN migration timeline — what a real SD-WAN rollout looks like
One of the biggest planning mistakes organisations make is treating a WAN change as a flip-the-switch event. Moving off MPLS or consolidating a mess of VPN tunnels onto an SD-WAN overlay is a project with discovery, design, a phased cutover and a period of running old and new in parallel. The timeline below is a realistic view of a managed SD-WAN migration for a multi-site UK organisation, from first conversation to a fully resilient live estate.
The key lesson from that timeline: never let an MPLS contract lapse before the SD-WAN estate is proven and stable. The overlay can be provisioned in days, but the diverse lines underneath it carry their own lead times, and a phased cutover with a fallback path is what turns a nerve-wracking rip-and-replace into a controlled, reversible migration. Align the whole programme with your MPLS renewal dates and your office-move plans, and start at least a quarter before any circuit is due to expire.
WAN benchmarks and KPIs — what “good” looks like
Once a network is live, a handful of metrics tell you whether it is performing to the standard you are paying for. The benchmark rows below show where a well-designed SD-WAN estate should sit in 2026 — use them as the yardstick when you review monitoring, hold a provider to its managed-service commitments, or judge whether an MPLS SLA is still earning its premium.
Well-designed UK SME WAN benchmarks
Latency, jitter and packet loss matter far more than headline bandwidth for the things organisations actually do all day — Teams and VoIP calls, interactive cloud applications, and file access across sites. This is exactly where a well-tuned SD-WAN overlay earns its keep: it measures every path continuously and moves latency-sensitive traffic onto the healthiest link in real time, something a static internet VPN cannot do and an MPLS circuit only achieves within its own private cloud. If you run a lot of voice traffic, read our guide to UCaaS and VoIP for hybrid working alongside this one — the WAN and the phone system have to be designed together.
How far the UK has moved beyond pure MPLS
The pace of the shift is the backdrop to every WAN decision in 2026. The combination of cloud-hosted applications, cheap and increasingly resilient full-fibre lines, and mature SD-WAN platforms has pulled the majority of multi-site organisations away from a pure private-circuit model. The figure below is an indicative view of how far that migration has run among UK multi-site SMEs and mid-market organisations.
The flip side is that around a third of multi-site organisations are still on a pure private-circuit model — and many of those are paying a premium to send cloud traffic on a detour through a central data centre it no longer needs to visit. If your business is in that group, the question is not whether to modernise but when and how: a hybrid design lets you keep MPLS where its guarantees genuinely matter while offloading the growing volume of cloud and internet traffic to a cheaper, smarter overlay. The organisations that come out of this well treat it as an architecture upgrade, not a like-for-like circuit swap.
The 10-point WAN architecture decision checklist
Run through these ten points before you commit to any WAN architecture. They are ordered roughly the way a good procurement and design process flows, from understanding your own estate to locking down the operational terms that matter when something breaks.
- Map where your applications actually live. If your core apps are in Microsoft 365, Azure and SaaS, an architecture that backhauls all traffic to a central data centre is fighting the way you work. Cloud-first estates favour local breakout and SD-WAN.
- Quantify downtime cost per site. Work out the pounds-per-hour each location loses when it goes offline. This single figure decides how much resilience — dual lines, auto-failover, 4G/5G backup — is worth buying.
- Audit every circuit and contract end-date. You cannot plan a migration without knowing what you have, what it costs, and when each contract can be exited without penalty. MPLS renewal dates set the timetable.
- Decide your resilience level site by site. Not every site needs dual diverse lines. A head office might warrant two fibre lines plus 4G/5G; a small satellite might be fine on a single line with mobile failover. Match spend to criticality.
- Compare on total resilience, not price per megabit. An MPLS SLA and raw internet bandwidth are not the same product. Compare the full cost of achieving a given uptime and performance level, including the outages the cheap option will cause.
- Choose the platform deliberately. Cisco Meraki suits organisations that value a simple cloud dashboard and integrated security; FortiGate suits security-led estates; Viptela suits large, complex topologies. The right fit depends on your team and your scale.
- Design security in, not on. The WAN is a security boundary. Segment guest, IoT and corporate traffic, centralise firewall policy, and align the configuration with Cyber Essentials v3.3 and NCSC guidance from day one.
- Plan cloud breakout carefully. Direct local breakout to trusted SaaS cuts latency, but it also moves the security perimeter to the branch. Make sure your firewall and inspection policies travel with the traffic.
- Decide DIY versus managed honestly. A self-run SD-WAN still needs someone to own policy, monitoring, firmware and incident response 24/7. If that is not a role your team can staff, buy it as a managed service rather than discovering the gap during an outage.
- Keep a fallback during migration. Run the new overlay alongside the old MPLS or VPN until every site is proven stable. Never decommission the legacy network until the replacement has survived a real bad day.
If you are moving premises or opening a new site in the next 18 months, fold the WAN decision into that plan early. One of the quiet advantages of SD-WAN over MPLS is speed of deployment — a new branch can be brought online in days on whatever internet line is available locally, rather than waiting out a 30–90 day MPLS provisioning cycle that can easily outlast your fit-out schedule.
Your WAN modernisation readiness score
Pulling the checklist together, most UK SMEs land somewhere in the middle: a functioning network held together with more manual effort than anyone admits, real gaps in resilience, and cloud traffic taking longer paths than it should. The gauge below is a rough self-assessment benchmark — score yourself two points for each checklist item you can confidently tick, and see where you sit against a fully modern, resilient, cloud-ready WAN.
A score under 40 means your WAN is a live business-continuity risk that deserves attention this quarter, not this year — typically a single-line, manually-tunnelled estate with no automatic failover and no central visibility. Between 40 and 70, where most organisations sit, you have a working network but almost certainly a resilience gap, a cloud-performance penalty, or a security blind spot that would bite hard on a bad day. Above 80, you have a genuinely modern estate and your job is to keep it reviewed as the business grows. The point of the exercise is not the exact number; it is spotting which layer — transport, resilience, or security and management — is dragging you down.
Common WAN architecture mistakes to avoid
Most WAN regret in UK organisations traces back to the same handful of avoidable errors. If you recognise your own estate in any of these, treat it as the prompt to fix it before the next outage does it for you.
- Comparing SD-WAN and MPLS on price per megabit. The numbers look like a landslide for internet bandwidth, but MPLS buys a performance guarantee that raw internet does not. Compare total cost for a given level of resilience, or you will draw the wrong conclusion in either direction.
- Treating internet VPN as free. Hand-built IPsec tunnels have no licence cost, but they cost engineering time to maintain, break silently, and offer no automatic remedy when a link congests. The cheapest architecture on paper is routinely the most expensive to run.
- Backhauling cloud traffic you no longer need to. Sending Microsoft 365 and Azure traffic back through a central MPLS hub adds latency and burns expensive private bandwidth. If your apps are in the cloud, your traffic should break out locally to reach them.
- Single line, no failover. A branch on one circuit is one fibre cut away from a full working day offline. Fewer than a third of sites have automatic failover — and they are the ones still trading when a digger goes through the street duct.
- Consumer kit terminating business tunnels. A consumer router doing the routing, firewalling and VPN for a whole site throws away the QoS, segmentation and security a business WAN needs — and often becomes the actual bottleneck and the actual breach.
- Buying SD-WAN as boxes, not as a capability. The platform is the easy part. Without someone owning policy, monitoring, firmware and 24/7 incident response, a self-run deployment slowly drifts out of tune. Decide DIY versus managed with your eyes open.
- Ignoring security in the redesign. Moving to local cloud breakout pushes the security perimeter out to every branch. If your firewall policy and inspection do not travel with that traffic, you have quietly widened your attack surface.
- Decommissioning the old network too early. Giving notice on MPLS before the SD-WAN estate has survived a real incident is how a smooth migration becomes an emergency. Keep the fallback until the replacement has proven itself.
The single most expensive mistake in this list is the false economy of “we’ll just run VPN tunnels ourselves.” It works beautifully with three sites and one network engineer who knows every tunnel by heart. It falls apart at a dozen sites, when that engineer is on leave, and a change nobody documented takes a site dark during month-end. If your WAN is business-critical, the resilience and the central management are not optional extras — they are the whole reason the architecture exists.
Real-world example — a UK professional-services firm’s WAN rebuild
Consider a 140-person accountancy and advisory firm with a head office in Leeds and four regional branches — an illustrative but representative example of the WAN journey we see repeatedly. The firm had grown by acquisition, and its network showed it: the head office ran an ageing MPLS circuit, two branches were connected over hand-built internet VPN tunnels, and the two newest offices were on single consumer-grade lines with no failover at all. Cloud migration to Microsoft 365 and a hosted practice-management platform had quietly made things worse, because all that cloud traffic was being backhauled across the MPLS core to break out centrally, adding latency to every login and every document open.
The rebuild followed the framework in this guide. A discovery audit put the true cost of the status quo not just in the £600-a-month MPLS premium but in the lost hour a fibre cut had cost one branch during a filing deadline — and the growing helpdesk load from tunnels that dropped without warning. The firm moved to a fully SD-WAN managed services design: dual diverse fibre lines at head office and the two busiest branches, single fibre plus 4G/5G failover at the smaller sites, and a Meraki firewall UK deployment giving one central dashboard across the whole estate. Direct local breakout sent Microsoft 365 and Azure traffic straight out to the cloud, segmented VLANs separated guest and corporate traffic in line with Cyber Essentials, and the legacy MPLS circuit was decommissioned once every site had run stable on the overlay for a month. The firm also folded in enterprise wireless solutions UK across the offices, managed from the same dashboard, so Wi-Fi and WAN were finally a single, monitored system.
“We’d been running the network like five separate companies stitched together, because that’s basically what we were. The day a branch lost its line during a deadline and we had no way to fail it over was the day it stopped being acceptable. Moving to a managed SD-WAN estate cost less per month than the old MPLS plus all the broadband we were already paying for — and the first time a line dropped, nobody in the office even noticed.”
The numbers here are illustrative rather than a specific client account, but the shape is one we see constantly: organisations that have moved everything to the cloud still running the WAN of a much smaller, more centralised company, one bad day away from an expensive lesson. The fix is rarely the biggest, fastest circuit on the market — it is the right architecture, made resilient, with security and management done properly across every site from a single pane of glass.
Security and Cyber Essentials implications of your WAN choice
WAN architecture is not just a performance and cost decision — it is a security decision, and one the ICO and your auditors will care about. Each of the three models changes your attack surface in a different way, and the shift to cloud breakout in particular moves the security perimeter in ways that catch organisations out. Aligning the design with SD-WAN vs MPLS UK security realities and Cyber Essentials v3.3 from the start is far cheaper than retrofitting it after a certification failure or an incident.
MPLS is often assumed to be “secure by default” because it is a private network, but that is a comfortable half-truth: traffic inside an MPLS cloud is separated from other customers, yet it is not encrypted end-to-end, and the single central breakout point becomes a chokepoint that has to inspect everything. Internet VPN is encrypted in transit by design, which is a genuine strength, but the security of the endpoints — the firewalls terminating each tunnel — is entirely on you, and a single mis-scoped rule or an unpatched device undermines the whole mesh. A managed SD-WAN estate, built on a platform such as a Meraki firewall UK deployment, gives you encrypted transport, centralised and consistent firewall policy across every site, and the segmentation Cyber Essentials expects — provided the security stack is designed in rather than bolted on after the fact.
Whichever architecture you choose, the Cyber Essentials v3.3 fundamentals apply: firewalls configured to deny by default, no default credentials on any network device, prompt patching of firmware, and access control that limits who can change the network. The NCSC’s guidance on network security and the ICO’s expectations under UK GDPR both point the same way — segmentation, least privilege and the ability to demonstrate control. A centrally-managed SD-WAN makes each of those materially easier to achieve and to evidence, which is one of the quieter reasons security-conscious organisations favour it. If certification is on your roadmap, work through our Cyber Essentials gap analysis and remediation guide in parallel with the network design.
Cloud-readiness — why architecture choice decides cloud performance
The final dimension, and the one that has driven the whole market shift, is cloud-readiness. When your applications lived in your own data centre, a hub-and-spoke MPLS network that pulled everything back to the centre made perfect sense. Now that they live in Microsoft 365, Azure, Google Workspace and a long tail of SaaS platforms, that same design forces every cloud interaction to take a detour, and the cost of that detour compounds with every user and every login.
SD-WAN’s decisive advantage here is direct local breakout: each site sends trusted cloud traffic straight out to the internet to reach the nearest cloud edge, rather than backhauling it across a private core. For a firm whose staff spend all day in Teams, SharePoint and a hosted line-of-business application, that difference is felt on every click. It also matters for cost: pushing cloud traffic over cheap internet bandwidth rather than premium private circuits is a large part of why the economics favour the overlay. If your organisation is actively managing its cloud spend — and most should be — the WAN is part of that picture, alongside the platform-level levers we cover in our Azure cost management and FinOps guide.
None of this makes MPLS obsolete overnight. Organisations with heavy real-time traffic between fixed sites, strict regulatory constraints, or legacy applications that genuinely need a guaranteed private path can still justify it — and a hybrid design keeps that guarantee where it matters while modernising everything else. But for the cloud-first majority of 20–500 seat UK businesses, the architecture that treats the internet as the primary transport and makes it intelligent, resilient and secure is the one that fits how they actually work in 2026.
At-a-glance summary — the WAN architecture decision in one table
If you take nothing else from this guide, take the table below. It maps the common organisational scenarios to the architecture that usually fits, so you can place your own business quickly.
| Key fact | What it means for your WAN decision |
|---|---|
| Cloud-first, multi-site SME | SD-WAN managed services with local breakout — the default sweet spot in 2026 |
| Static estate, central legacy apps | MPLS can still fit; consider hybrid MPLS + SD-WAN to modernise gradually |
| Two or three small sites, low criticality | Managed internet VPN or single-line SD-WAN — keep it simple and cheap |
| Cost of comparable circuits | SD-WAN dual-line typically undercuts MPLS while adding resilience |
| Provisioning speed | SD-WAN in days over existing lines; MPLS 30–90 working days |
| Resilience minimum | Dual diverse lines with automatic, tested failover — not a spare router |
| Backup technology | 4G/5G failover for smaller sites and instant diverse backup |
| Security baseline | Central firewall policy, segmentation, Cyber Essentials v3.3 alignment |
| Platform choice | Meraki (simple + cloud dashboard), FortiGate (security-led), Viptela (large/complex) |
| DIY vs managed | Buy managed unless you can staff policy, monitoring and 24/7 response |
| Metrics that matter | Latency, jitter and packet loss over headline bandwidth |
| Golden rule | Run new and old in parallel; decommission MPLS only once proven stable |
How Cloudswitched delivers SD-WAN and cloud networking
Choosing between MPLS, internet VPN and SD-WAN — and designing the resilience, security and cloud breakout around how your organisation actually trades — is exactly the kind of decision that benefits from an independent partner who is not tied to a single carrier or box. Cloudswitched works with UK SMEs and mid-market organisations to audit the current estate, model the real cost and resilience of each architecture on a like-for-like basis, and deliver managed SD-WAN on the platform that fits — including Cisco Meraki firewalls and enterprise wireless managed from one dashboard. We handle discovery, design, phased migration, cloud breakout and Cyber Essentials-aligned hardening, then monitor and manage the live estate. The aim is straightforward: a network that stays up, performs to the numbers you paid for, and is built to survive a bad day.
Ready to modernise your WAN?
From SD-WAN and Meraki to managed firewalls and enterprise wireless, we design and run cloud networking around how your organisation works — not a one-size-fits-all package.
Cloud NetworkingFrequently Asked Questions
What is the difference between SD-WAN, MPLS and internet VPN?
MPLS is a private, carrier-managed network with a contractual performance guarantee, traditionally used to link branch offices back to a central data centre. An internet VPN builds encrypted tunnels across the ordinary public internet between sites, cheaply but with no performance guarantee. SD-WAN managed services add an intelligent software layer on top of internet lines — often two or more per site — that selects the best path for each application in real time and fails over automatically, delivering close to MPLS-grade resilience at internet-grade prices. In short: MPLS guarantees performance at a premium, VPN is cheap but dumb, and SD-WAN makes cheap internet lines behave intelligently.
Is SD-WAN cheaper than MPLS in the UK?
In most cases, yes. A dual-line SD-WAN deployment typically lands well below the cost of a comparable MPLS circuit — often in the region of £250–£600 per site per month versus £350–£800 or more for MPLS — while delivering more resilience, because it uses commodity internet bandwidth intelligently rather than paying a premium for private transport. The important caveat is to compare total cost for a given level of resilience and performance, not raw price per megabit. Figures are indicative UK 2026 ranges and depend on postcode, bandwidth, contract term and the level of managed service.
Does SD-WAN replace MPLS completely?
Not always. For cloud-first organisations SD-WAN over internet lines usually replaces MPLS entirely, but many larger or more regulated estates adopt a hybrid design — keeping an MPLS circuit as a guaranteed primary path for latency-critical traffic between fixed sites, while offloading cloud and general internet traffic to a cheaper SD-WAN overlay. This lets you retain the MPLS SLA where it genuinely earns its cost and modernise everything else, and it is often the lowest-risk way to exit MPLS gradually rather than all at once.
What is a Meraki firewall and why is it used for SD-WAN?
A Meraki firewall UK deployment uses Cisco Meraki MX security appliances, which combine SD-WAN, next-generation firewalling and central cloud management in one platform. It is popular with UK SMEs because the whole estate — every site, firewall and often the Wi-Fi too — is managed from a single cloud dashboard, sites deploy zero-touch, and security policy is applied consistently everywhere. That central visibility and consistent configuration also make it considerably easier to evidence Cyber Essentials v3.3 controls across a multi-site network.
How long does an SD-WAN migration take?
The SD-WAN overlay itself can be provisioned in days over your existing lines, which is one of its biggest advantages over MPLS. A full estate migration for a multi-site organisation typically runs 8–12 weeks end to end, because the timeline is driven by procuring any new diverse internet lines, piloting the first site, and rolling out the rest in phases while running the old network in parallel as a fallback. The MPLS decommission — where the monthly savings land — comes only once every site is proven stable on the overlay.
Is internet VPN secure enough for business use?
An internet VPN encrypts traffic in transit, which is a genuine strength, but its overall security depends entirely on the endpoints — the firewalls terminating each tunnel — and on disciplined configuration and patching. A single mis-scoped rule, an unpatched device or a consumer-grade router undermines the whole mesh, and hand-built tunnels rarely get the consistent policy a business needs. For anything beyond a couple of low-criticality sites, a managed SD-WAN with centralised firewall policy and segmentation is both more secure and far easier to keep compliant with NCSC guidance and Cyber Essentials.
What are managed network services and do I need them?
Managed network services mean a partner owns the design, deployment, monitoring, firmware, policy and incident response for your WAN, rather than your in-house team running it. You need them if you cannot realistically staff 24/7 network management — which is most SMEs. A self-run SD-WAN still needs someone watching every site, applying updates and responding when a line drops at 2am; buying it as a managed service means that capability is guaranteed rather than dependent on one engineer being available and up to date.
How does SD-WAN improve cloud application performance?
SD-WAN improves cloud performance chiefly through direct local breakout: instead of backhauling Microsoft 365, Azure and SaaS traffic across a private core to break out centrally, each site sends trusted cloud traffic straight out to the nearest cloud edge. It also continuously measures every available path and steers latency-sensitive traffic — voice, video, interactive apps — onto the healthiest link in real time. For staff who spend all day in Teams, SharePoint and hosted applications, that means faster logins, snappier document access and calls that do not break up when a line congests.
Which SD-WAN platform is best — Meraki, FortiGate or Viptela?
There is no single best platform — the right fit depends on your priorities. Cisco Meraki suits organisations that value simplicity and a single cloud dashboard across WAN, firewall and wireless; FortiGate (Fortinet) suits security-led estates that want deep next-generation firewall capability integrated with the WAN; and Cisco Viptela suits large, complex topologies with demanding routing and scale requirements. Most UK SMEs at 20–500 seats land on Meraki or FortiGate for the balance of capability and manageability, but the honest answer is to choose based on your team’s skills, your security needs and your scale.
Can SD-WAN include our Wi-Fi and switching too?
Yes, and increasingly it should. Platforms such as Meraki manage SD-WAN, firewalls, switches and enterprise wireless solutions UK from the same cloud dashboard, so the whole network — wired, wireless and WAN — is a single monitored system rather than three separate ones. Consolidating them gives you consistent security policy from the internet edge all the way to the access point, one place to see problems, and far less operational overhead than managing wireless, switching and the WAN as independent estates.
What happens to my WAN if a line goes down?
It depends entirely on your architecture. On a single-line internet VPN, the site goes offline until the line is repaired — potentially a full working day for a street fibre cut. On MPLS, resilience means paying for a second tail, which is costly. On a dual-line SD-WAN, the overlay detects the failure and moves all traffic to the healthy line automatically, typically within one to thirty seconds and often without anyone in the office noticing. Adding a 4G/5G circuit as a diverse tertiary path protects even against a dual fixed-line failure.
Does moving to SD-WAN affect Cyber Essentials certification?
It can help, provided security is designed in. Cyber Essentials v3.3 expects firewalls configured to deny by default, no default credentials, prompt patching and controlled access to network devices — all of which are easier to apply consistently and evidence from a centrally-managed SD-WAN than across a patchwork of per-site firewalls. The one thing to plan for is cloud breakout: sending traffic out locally moves the security perimeter to each branch, so your firewall policy and inspection must travel with it. Done properly, a managed SD-WAN strengthens your certification posture rather than complicating it.
Related reading
- Business Internet Connectivity Buying Guide — Leased Lines, FTTP & SD-WAN for UK SMEs in 2026
- Business Connectivity Checklist — 18 Steps to Bulletproof Internet for UK SMEs in 2026
- UCaaS & VoIP for Remote and Hybrid Working — A Complete UK Business Guide
- Cyber Essentials Gap Analysis & Remediation: A Step-by-Step Guide
- Azure Cost Management & FinOps for UK SMEs — A 2026 Optimisation Guide
Build a WAN that’s ready for the cloud
Cloudswitched audits your current network, models SD-WAN, MPLS and internet VPN on equal terms, and designs and manages a resilient, secure cloud-networking estate — Meraki firewalls, SD-WAN and enterprise wireless from a single dashboard — so your team stays online and performs to the numbers you paid for.
Cloud Networking