Compare
MPLS, MPLS over collection, SD-WAN, sdMPLS®: the comparison
Thirteen criteria, four columns, one consistent colour code. Then the objections we hear, and our answers.
Operator MPLS, SD-WAN and sdMPLS do not sit at the same level: the first is the operator's private network, the second a software layer on top of your links, the third your own core network, virtualised at the operator. Between the first two sits a fourth, very common offer: MPLS over collection, an operator's private network built on standard fibre accesses, cheaper than legacy MPLS but with a core that stays closed. The table below compares what each one actually delivers.
Operator MPLSMPLS over collectionSD-WANsdMPLS
| Criterion | Operator MPLS | MPLS over collection | SD-WAN | sdMPLS |
|---|---|---|---|---|
| What it is | The incumbent operator's private network, on its dedicated links | An operator's private network, built on standard fibre accesses that it collects | A software layer on top of your Internet links | Your own core network, virtualised at the operator |
| Who controls the core network | The operator alone | The operator alone: every change goes through a ticket | The customer controls its site equipment and policies; the operator's core stays out of reach | The customer, through its VRB, alone or with its partner; instant changes, no ticket |
| Where the network intelligence lives | In the operator's core and routers | In the operator's core | In the appliance at each site | In your VRB, in the core network |
| Access links | Specific, expensive MPLS links | Standard fibre accesses (FTTH, FTTE), collected into the operator's core | Standard Internet links | Standard access links (FTTH, FTTO, xDSL, 4G/5G), collected directly into the core from eleven infrastructure networks |
| Inter-site traffic | The operator's private network | Private network, off the Internet | Public Internet, encrypted | Private network, off the Internet, direct collection into the core |
| Internet exit and access to cloud applications | Centralised exit, usually through head office | Centralised exit through head office or the operator's data centre | Local breakout at each site, to be secured site by site | Single exit at the core, straight onto Flex.eu's transit, behind a firewall, with no detour through head office |
| On-site equipment | Router imposed by the operator | The operator's router | SD-WAN appliance to deploy, secure and maintain at every site | Light termination equipment, chosen by your partner: the intelligence is in the VRB |
| Cost | Premium of about 2.9× vs business Internet | Price of standard accesses + operator service | Licences + appliances + links, 20 to 30% savings through optimisation | Price of standard links + VRB |
| Bringing a site into service | 60 to 120 days | Days to weeks (existing link); every change goes back through the operator | Days to weeks | Days (existing link); instant changes |
| Performance | Guaranteed (SLA) | That of the operator's core, as per contract | Best effort over the Internet | Backbone performance, 3M+ pps per VM (public benchmark in preparation) |
| WAN + voice + cloud | Three separate infrastructures | Usually separate infrastructures | Optimises the WAN; voice and cloud stay on separate infrastructures | One single infrastructure |
| Vendor dependency | Strong (hardware, long contracts) | Strong (the operator's closed core) | Medium (vendor control plane) | Low: standard protocols (VXLAN, EVPN, BGP), exportable configuration |
| Scalability | Limited by the operator | Limited by the operator | Central orchestrator, 1,000 to 2,000 sites max | Spine-leaf architecture, no central bottleneck |
Modern SD-WANs can segment, encrypt, route dynamically and prioritise flows over a site's links. This comparison is not about those edge functions, but about what happens between the sites: who controls the core, and where the traffic goes.
MPLS over collection deserves a word: it is often what an alternative operator or an integrator sells under the name “MPLS”. It starts from the same standard fibre accesses as sdMPLS and, like it, provides a private network off the Internet. The difference lies in the core: fixed and administered by the operator alone in one case, dedicated to your company and controlled from your VRB in the other. It is the first question to ask: what can I change myself, without a ticket?
Market figures (×2.9 premium, 60 to 120 days, 20 to 30%, 1,000 to 2,000 sites): Flex.eu synthesis of public market data (analysts, operators), SDO study, March 2026. VRB performance: 3M+ pps per VM, public benchmark in preparation; no quantified comparison with other routers is published before the benchmark. The MPLS column refers to a contractual guarantee (SLA); sdMPLS speaks of control of the core and backbone performance, and the service commitments are those of the contract.
On mobile, the table scrolls horizontally; the criteria column stays visible.
Objections
The objections we hear, and our answers
Nine questions asked by CIOs, telecom consultancies and incumbent operators. Click to expand.
“It's just another SD-WAN.”
No: an SD-WAN is an overlay sitting on top of a network it does not control. sdMPLS virtualises the core network itself and hands you its control. The difference shows as soon as you talk about end-to-end QoS, from each site's access all the way to the core and the Internet exit, segmentation or traffic engineering.
“Without MPLS, there is no performance guarantee.”
The MPLS guarantee comes from control of the core, not from the protocol. sdMPLS keeps a private, controlled core; it is the access links that become standard.
Concretely, the SDO core is deployed as a geo-cluster, on two separate data centres in the Paris region with two core networks each, with 99.95% availability and a 4-hour guaranteed time to repair (GTR), 24/7, included. These commitments cover the core network; at the access, the type of link chosen site by site (dedicated fibre with guaranteed bandwidth or shared fibre) sets the level of commitment. Since the path is controlled from the access to the core and the Internet exit, QoS applies end to end.
“Running a backbone is too complex for my team.”
The VRB exposes what a network team already knows how to do (routing, QoS, VLANs/segments). What the customer controls is its policy; running the core remains the operator's job. And the distributor can operate the VRB on the customer's behalf.
“You are a small player, that's risky.”
sdMPLS is built on standard protocols (VXLAN, EVPN, BGP) and on a routing system that network teams already know; the VRB configuration exports as plain text: the customer is not locked in. The operator Flex.eu already runs a network of more than 135 distributors, with voice and cloud services in production.
The SDO core has been in production since 2019, after more than five years of research and development. More than 10,000 FTTH, FTTE and FTTO links are connected to it today, on four core networks spread over two separate data centres in the Paris region, so as to remain available whatever the failure.
“We already have an SD-WAN, why change?”
The SD-WAN stays; it only selects a path. sdMPLS replaces what sits underneath. And it removes the second infrastructure (cloud, voice) that SD-WAN does not handle.
“The term sdMPLS is misleading, it isn't MPLS.”
Correct, and deliberate: sdMPLS delivers the capabilities that businesses were looking for in MPLS (a private, controlled core), in a software-defined way. Just as SD-WAN is not a WAN but a software way of doing WAN.
“My operator already offers me a cheaper MPLS, on standard fibre.”
That is probably MPLS over collection: FTTH or FTTE accesses injected into the operator's private core. The network is indeed off the Internet and cheaper than legacy MPLS, but the core stays closed: every route, every class of service, every new flow goes through a ticket. sdMPLS starts from the same accesses and the same direct collection, and adds what is missing: a VRB dedicated to your company, which your team or your partner controls in real time.
“A consumer 4G backup is enough for our small sites.”
Not in a network that is off the Internet. A consumer SIM exits onto the public Internet and therefore cannot join your private network without a tunnel and an appliance to secure at the site. sdMPLS delivers mobile differently: 4G/5G SIMs on a private APN, collected directly into the core, with the same security policy and the same QoS as fixed links. It is a point to check in any tender: does the mobile backup stay inside the private network?
“We would depend on a single operator for collection and core.”
Yes, as with any MPLS: that is what an operated private network is. What matters is how robust that operator is, and how free you are to leave. The SDO core runs four core networks in a geo-cluster across two separate data centres, collects accesses from eleven infrastructure networks, and your configuration exports as plain text over standard protocols. A 4G/5G backup on a private APN complements each site's fixed link.
Going further
Understanding sdMPLS
The full explanation in ten sections, with the diagrams.
Read →The technology
SDO, VXLAN/EVPN core, VRB, software stack, performance, access links, hosting.
Technical details →Writing an invitation to tender
The neutral functional definition and the criteria grid to open your tender to the third way.
Consultants' area →Planned for V2: filters by criterion and PDF export of the comparison.