No more typing reviews! Try our Samantha, our new voice AI agent.

Cisco Identity Services Engine (ISE) vs Sophos Network Access Control comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Nov 5, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco Identity Services Eng...
Ranking in Network Access Control (NAC)
3rd
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
144
Ranking in other categories
Cisco Security Portfolio (4th)
Sophos Network Access Control
Ranking in Network Access Control (NAC)
7th
Average Rating
8.4
Reviews Sentiment
6.2
Number of Reviews
24
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of June 2026, in the Network Access Control (NAC) category, the mindshare of Cisco Identity Services Engine (ISE) is 18.6%, down from 25.3% compared to the previous year. The mindshare of Sophos Network Access Control is 3.0%, up from 1.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Network Access Control (NAC) Mindshare Distribution
ProductMindshare (%)
Cisco Identity Services Engine (ISE)18.6%
Sophos Network Access Control3.0%
Other78.4%
Network Access Control (NAC)
 

Featured Reviews

NF
Network and Technology Information Manager at Akkodis
Has improved authentication management and simplified visitor network access
The log capacity in Cisco Identity Services Engine (ISE) could be enhanced because today natively on the ISE can only have a look at the logs from the day before. You cannot search into the oldest logs; you have to use another tool for that. This can be blocking if you don't have any log consolidation solution. To do a search for an issue or something that happened two days ago, you cannot search directly in there. The capacity of Cisco Identity Services Engine (ISE) could be enhanced. Something between one week and one month for the log capacity would be nice.
HirenPatel2 - PeerSpot reviewer
Manager at rspl
Have faced delays in support despite strong multi-layer policy configuration
I have observed some disadvantages as we have experienced one particular problem. We were facing an issue of synchronization of the endpoint with our firewall with help on a cloud for heartbeat syncing. However, it was not syncing as per our requirement. The user has to connect our firewall with the help of VPN. We were supposed to assume a solution on a cloud, which has good synchronization on a cloud with Sophos Central. It will sync with our firewall as well with the help of Sophos Central. Endpoint and firewall synchronization is not as smooth as we are expecting from Sophos Network Access Control. We have to connect with VPN. We are expecting that if we have already installed an endpoint on our system and it is connected to the internet, then it must be synchronized on a cloud with Sophos Central. Through Sophos Central, it must connect with our firewall. If the endpoint is configured on Sophos Central and the firewall is also configured in Sophos Central, then there should be no need to connect to VPN.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Cisco ISE (Identity Services Engine) is the best solution for Cisco network customers."
"Typically, the installation is pretty simple."
"ISE helps us protect our industrial control systems and SCADA systems by segmenting them off from the rest of the network, eliminating trust, and making our government and law-enforcement-related audits go a lot faster and a lot smoother than they used to."
"The solution enables us to authenticate with AD."
"The ROI we have seen is because Cisco gives us what they promised us; they deliver, our requirements are being met, and that results in getting value for what we pay."
"Unauthenticated devices are not allowed on our network and that has been an improvement for our company."
"From my assessments so far, however, ISE still wins the show and it's likely that the partner that was doing the deployment originally on behalf of Cisco probably missed out on a number of things."
"It does a good job of establishing trust for each access request, no matter the source, and it's also very effective at helping with the distributed network and at securing access."
"The scalability of the system and the performance of the system and the solution's most valuable features."
"The product has the capabilities to satisfy all kinds of needs that a company may have, and you can find the right solution without spending a lot of money."
"I found all Sophos Network Access Control features valuable, but IP blocking is the most useful."
"The installation is very straightforward."
"There is good documentation that helps to deploy a new wireless access point and a controller in a very easy way."
"The initial setup is very easy."
"The most valuable features of Sophos Network Access Control are the quick response times to threats and reliable security."
"I am very satisfied with this solution overall. All of the features that we use have been working successfully."
 

Cons

"It's expensive to scale Cisco ISE, but our situation is stable so we don't need to scale it for now."
"The Guest Network verification needs to add a QR code option."
"It would be nice if it could be configured easily by default."
"The ISE software needs to be improved so that it is easier to administer."
"The primary issue is the slowness of the application and the web interface. We have multiple admin nodes and app nodes. So when I need to get some information about a particular user, the GUI would take ten to fifteen seconds in loading when we need to know right away."
"It is too complex. It should be easy to use. We are not such a big team. We only have three engineers to work with this, and we don't use all of the functionality of the product. Its range of functionality is too wide for us, and this is the reason why we are thinking of switching to a more simple product. We have shortlisted a Microsoft solution. We have a big footprint for Microsoft products, especially in security. As a global strategy, we try to leverage to the maximum what is possible around Microsoft."
"We are waiting for TACACS integration to completely replace the Cisco ACS line of products."
"A main issue is that the upgrade process, over time, is extraordinarily fragile. Repeatedly, over the past several years, when we've tried to upgrade our Cisco ISE implementation, the upgrade has broken it. Ultimately, we have then had to rebuild it because we need it."
"The solution could increase the integration with other platforms or other systems. This would be very useful."
"Continuous development in specific areas might be required."
"The difficult thing was finding the metrics."
"It would be beneficial to consider some improvements regarding the dashboard."
"Users are not controlled by role-based access; it's basically device-based control. The definition of role-based control is a little vague here because on the cloud level, it regulates access rather than tasks."
"Sophos Network Access Control requires a lot of resources to work, which is an area for improvement. Pricing could also be improved because it's costly."
"One area in which the product could be improved is the user interface. While functional, it can be somewhat cluttered and unintuitive, especially for new users."
"Sometimes we encounter intermediate-level support staff who use trial-and-error approaches, but sometimes we receive support from excellent staff members who resolve issues within seconds."
 

Pricing and Cost Advice

"Standard licensing gives backup access and very few features, and then there's VM licensing - each VM we use needs to be licensed."
"It is fairly expensive and that's part of why we have implemented it in the type of 'hack' that we did, to service multiple clients."
"Cisco is moving towards a subscription service, which would mean additional costs."
"It is not that pricey."
"I think the price is okay."
"We are running Version 2.9 because Version 2.9 of the ISE has a persistent license — it's a one-time payment. The latest version (3.1) is only available if you do a yearly subscription."
"Hardware appliances are expensive...Now moving to DNA-styled licensing, we have subscription-based licensing for everything. I hope it will continue to be fair, but we will have to wait and see."
"There is a license to use this solution and the price is reasonable."
"Sophos Network Access Control is an expensive solution."
"It provides a moderate pricing option for all of its features and benefits."
"Sophos Network Access Control is costly but has a similar price range as CrowdStrike and Check Point. The product can get more market share if Sophos can play around with Sophos Network Access Control pricing and improve it."
"I rate the price of Sophos Network Access Control a five out of ten."
"Sophos Network Access Control is very cheap compared to other solutions like Cisco, Barracuda, and Palo Alto."
"It is quite expensive."
report
Use our free recommendation engine to learn which Network Access Control (NAC) solutions are best for your needs.
900,747 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
10%
Financial Services Firm
10%
Government
7%
Computer Software Company
7%
Construction Company
10%
Manufacturing Company
9%
Healthcare Company
9%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business45
Midsize Enterprise32
Large Enterprise91
By reviewers
Company SizeCount
Small Business16
Midsize Enterprise3
Large Enterprise3
 

Questions from the Community

Which is better - Aruba Clearpass or Cisco ISE?
Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can adapt the policies to VPN access, wired, or wireless access. You can securely ...
What are the main differences between Cisco ISE and Forescout Platform?
OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cannot secure the port if a device does not support 802.1x. Cameras, badge readers, ...
How does Cisco ISE compare with Fortinet FortiNAC?
Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if someone plugs in with a device that is not allowed and will block it. The user exper...
What is your experience regarding pricing and costs for Sophos Network Access Control?
The pricing of Sophos Network Access Control is good, but it is somewhat high.
What needs improvement with Sophos Network Access Control?
In my opinion, one feature that should be added is the ability to trace emails from individuals who change their IP address or send misbehaving emails from alternative networks. If someone sends a ...
What is your primary use case for Sophos Network Access Control?
Sophos Network Access Control serves primary use cases for both networking purposes and security purposes.
 

Also Known As

Cisco ISE
No data available
 

Overview

 

Sample Customers

Aegean Motorway, BC Hydro, Beachbody, Bucks County Intermediate Unit , Cisco IT, Derby City Council, Global Banking Customer, Gobierno de Castilla-La Mancha, Houston Methodist, Linz AG, London Hydro, Ministry of Foreign Affairs, Molina Healthcare, MST Systems, New South Wales Rural Fire Service, Reykjavik University, Wildau University
Rushmoor Borough Council
Find out what your peers are saying about Cisco Identity Services Engine (ISE) vs. Sophos Network Access Control and other solutions. Updated: June 2026.
900,747 professionals have used our research since 2012.