Depending on the offering, it can include site connectivity, virtual networks, cloud interconnection, software-defined wide area networking (SD-WAN), remote access, performance controls, or security functions, ordered through a contract, portal, or application programming interface (API).
There is no industry-wide NaaS feature set. Some services primarily lease managed connectivity; others expose on-demand configuration, consumption billing, lifecycle automation, and service-level objectives across providers or clouds. Buyers should examine the service boundary, control model, data handling, interoperability, and responsibilities rather than infer them from the label.
Key points
Service boundaryIdentify which physical infrastructure, virtual functions, orchestration, monitoring, and support the provider operates.
Customer dutiesThe customer still governs users, applications, data, requested policy, and controls that remain on its side of the demarcation.
AssuranceContracts should define service levels, security evidence, change control, incident coordination, data location, portability, and termination arrangements.
Important limitationOutsourcing operation does not outsource accountability. Provider outages, lock-in, opaque routing, jurisdiction, telemetry gaps, API security, and unclear incident duties can introduce risk, while advertised elasticity or automation may apply only to a subset of the service.