No more typing reviews! Try our Samantha, our new voice AI agent.

Cisco Identity Services Engine (ISE) vs Sophos Network Access Control comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Nov 5, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco Identity Services Eng...
Ranking in Network Access Control (NAC)
2nd
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
144
Ranking in other categories
Cisco Security Portfolio (4th)
Sophos Network Access Control
Ranking in Network Access Control (NAC)
9th
Average Rating
8.4
Reviews Sentiment
6.2
Number of Reviews
24
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of September 2026, in the Network Access Control (NAC) category, the mindshare of Cisco Identity Services Engine (ISE) is 18.4%, down from 24.5% compared to the previous year. The mindshare of Sophos Network Access Control is 3.1%, up from 1.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Network Access Control (NAC) Mindshare Distribution
ProductMindshare (%)
Cisco Identity Services Engine (ISE)18.4%
Sophos Network Access Control3.1%
Other78.5%
Network Access Control (NAC)
 

Featured Reviews

NF
IT Network Manager at a tech services company with 10,001+ employees
Has improved authentication management and simplified visitor network access
The log capacity in Cisco Identity Services Engine (ISE) could be enhanced because today natively on the ISE can only have a look at the logs from the day before. You cannot search into the oldest logs; you have to use another tool for that. This can be blocking if you don't have any log consolidation solution. To do a search for an issue or something that happened two days ago, you cannot search directly in there. The capacity of Cisco Identity Services Engine (ISE) could be enhanced. Something between one week and one month for the log capacity would be nice.
HirenPatel2 - PeerSpot reviewer
Manager at rspl
Have faced delays in support despite strong multi-layer policy configuration
I have observed some disadvantages as we have experienced one particular problem. We were facing an issue of synchronization of the endpoint with our firewall with help on a cloud for heartbeat syncing. However, it was not syncing as per our requirement. The user has to connect our firewall with the help of VPN. We were supposed to assume a solution on a cloud, which has good synchronization on a cloud with Sophos Central. It will sync with our firewall as well with the help of Sophos Central. Endpoint and firewall synchronization is not as smooth as we are expecting from Sophos Network Access Control. We have to connect with VPN. We are expecting that if we have already installed an endpoint on our system and it is connected to the internet, then it must be synchronized on a cloud with Sophos Central. Through Sophos Central, it must connect with our firewall. If the endpoint is configured on Sophos Central and the firewall is also configured in Sophos Central, then there should be no need to connect to VPN.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The general usefulness of the product is not specific to a particular feature, as this is a comprehensive solution covering access to the network to create a zero trust environment, including Network Access Control, Network Segmentation and policy control, while integrating well with other Cisco solutions and offering very good functionality that is simple to configure, reliable, and scalable, with helpful technical support."
"The ROI we have seen is because Cisco gives us what they promised us; they deliver, our requirements are being met, and that results in getting value for what we pay."
"The solution is great for establishing trust for every access request no matter where it comes from."
"I found the CMDB Direct Connect in Cisco ISE 3.2 the most promising feature for my use case."
"I like the automation of the collection of information."
"The solution is very reliable."
"The most valuable thing in ISE is the adoption of EAP deep that came in [version] 2.7, so we can do authentication based on user and machine certificates in one authentication."
"Cisco ISE has enabled my customers to deploy secure wireless and secure wired networks and gave them a lot of flexibility to do security enforcement."
"The system right now covers all my needs and it's very comfortable to work with."
"The installation is very straightforward."
"The wifi control is fantastic and makes it very easy to administer."
"There is good documentation that helps to deploy a new wireless access point and a controller in a very easy way."
"We get full visibility into the network as a product, which is one of the key features of the product because recently they have acquired another product called Secure Wave, which is integrated into Sophos Network Access Control and provides advanced capabilities for managed detection and remediation, MDR, a major plus for customers."
"Sophos Network Access Control has many valuable features: for access controls, MAC binding is available, the authentication page is useful, and continuous device assessments have a positive impact on our network security management."
"Sophos' technical support is great, very fast and responsive, and they always know how to fix the problem."
"Sophos has helped us to save time and money and to better manage web activities. It has also helped us to reduce misuse of the network and restrict hacking attempts."
 

Cons

"This solution is a bit more complex to set up than in comparison to other options - it can take anywhere from two to five months depending on the use case."
"There should be more visibility into TrustSec policy actions. When TrustSec blocks something or makes any kind of changes to the network, we don't always see that. We have to log into the switch itself, or we have to get some type of Syslog parsing to do that."
"Whenever we see the authentication logs, we can't see what device we're logging into... We can see who logged in, but we can't see the IP address of the device... I'm sure that's available. We just haven't figured out how to properly deploy it."
"Because we have a large database and 4,000 network devices, the solution can lag a bit when you're running updates or different things because of the fact that it's so big and it is such a resource hog."
"Adding new devices was a little cumbersome. I haven't done it that many times, but I remember that adding new devices to the authentication piece of it was a little cumbersome. The way I was shown to do it, I thought it was odd because we had to go into the active device, copy the file down, export it, make some changes to it, and then reimport it as opposed to being able to click it and having a template to fill out."
"Deploying to a machine, as opposed to a dedicated appliance, can be a bit difficult."
"Its user interface could be better. It's not bad. They've just redesigned the whole user interface. It's not terribly difficult. The drop-down menus are easy to use. However, when you're looking for some things in the user interface, it takes a minute to find where you were prior."
"Migration could be better. Right now, we back up with the new version, and it requires a lot of licensing and other things. Whenever we choose a product, it's very difficult because we have to meet the requirements of each feature. There is no standard feature, so the best system that we bought may not fit the solution. We have to look at every feature that the customer uses. If you compare it with other products like Aruba, it's not the same. With Cisco, I have to read all about the features on this version and the licensing required for the product. In Aruba, that thing is covered when you get one license because it covers almost everything. It could also be more scalable."
"The solution could offer more useful documentation."
"An area that could be improved is the information about licensing, which is fairly confusing at present."
"The difficult thing was finding the metrics."
"Sophos Network Access Control needs improvement regarding its slow interface, loading time, and reporting."
"In order to provide better management, it would be ideal with they offered better plugins for their firewall."
"I would like more details on the incoming connection, like what is the download speed and how it fluctuates. If Sophos can give that information, it would be really good."
"Sophos Network Access Control requires a lot of resources to work, which is an area for improvement. Pricing could also be improved because it's costly."
"Sophos Network Access Control could be improved by having an ASIC chip similar to FortiNAC, as this would provide better processing for big organizations."
 

Pricing and Cost Advice

"According to my sales and account team, the prices we're getting are pretty good."
"I have complaints. I don't enjoy the licensing model. Once we moved from 2.7 to 3.1, switching from Base, Plus, and Apex to Essential and Advantage in Premier, we went from a perpetual, with our base licenses, to now a subscription-base. So, we will have to renew those licenses every year, and I'm not a fan of that for our base licenses. Apex/Premier, we already expected, which is fine, but for basic connectivity, I am not a fan of that."
"The solution’s pricing is okay."
"The SMARTnet technical support is available at an additional cost."
"The recent changes in the licensing model have caused some issues with the team."
"Its licensing could be improved. It used to be perpetual, but now they are moving away from that."
"ISE has always been expensive compared to other products in terms of what it does on a user level."
"Pricing is not a problem for Cisco because it has a lot of features and not much competition, although it's more expensive than other products. But if I do a cost-benefit analysis, Cisco provides high quality."
"I rate the price of Sophos Network Access Control a five out of ten."
"It is quite expensive."
"Sophos Network Access Control is very cheap compared to other solutions like Cisco, Barracuda, and Palo Alto."
"It provides a moderate pricing option for all of its features and benefits."
"Sophos Network Access Control is costly but has a similar price range as CrowdStrike and Check Point. The product can get more market share if Sophos can play around with Sophos Network Access Control pricing and improve it."
"Sophos Network Access Control is an expensive solution."
report
Use our free recommendation engine to learn which Network Access Control (NAC) solutions are best for your needs.
914,351 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
10%
Financial Services Firm
10%
Outsourcing Company
9%
Comms Service Provider
7%
Outsourcing Company
11%
Construction Company
10%
Healthcare Company
8%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business45
Midsize Enterprise32
Large Enterprise91
By reviewers
Company SizeCount
Small Business16
Midsize Enterprise3
Large Enterprise3
 

Questions from the Community

Which is better - Aruba Clearpass or Cisco ISE?
Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can adapt the policies to VPN access, wired, or wireless access. You can securely ...
What are the main differences between Cisco ISE and Forescout Platform?
OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cannot secure the port if a device does not support 802.1x. Cameras, badge readers, ...
How does Cisco ISE compare with Fortinet FortiNAC?
Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if someone plugs in with a device that is not allowed and will block it. The user exper...
What is your experience regarding pricing and costs for Sophos Network Access Control?
The pricing of Sophos Network Access Control is good, but it is somewhat high.
What needs improvement with Sophos Network Access Control?
In my opinion, one feature that should be added is the ability to trace emails from individuals who change their IP address or send misbehaving emails from alternative networks. If someone sends a ...
What is your primary use case for Sophos Network Access Control?
Sophos Network Access Control serves primary use cases for both networking purposes and security purposes.
 

Also Known As

Cisco ISE
No data available
 

Overview

 

Sample Customers

Aegean Motorway, BC Hydro, Beachbody, Bucks County Intermediate Unit , Cisco IT, Derby City Council, Global Banking Customer, Gobierno de Castilla-La Mancha, Houston Methodist, Linz AG, London Hydro, Ministry of Foreign Affairs, Molina Healthcare, MST Systems, New South Wales Rural Fire Service, Reykjavik University, Wildau University
Rushmoor Borough Council
Find out what your peers are saying about Cisco Identity Services Engine (ISE) vs. Sophos Network Access Control and other solutions. Updated: September 2026.
914,351 professionals have used our research since 2012.