Last month a sharp young engineer on my team asked, with the particular confidence of someone who's read a lot of vendor blogs, whether there was any point studying for CCNP. "Networking is just SASE in the cloud now," he said. "Nobody's subnetting by hand anymore." It's a fair question, and I've heard versions of it for years — the same question was asked about routing when switching arrived, about switching when virtualisation arrived, about everything on-prem when the cloud arrived. So I gave him the honest, longer answer, and it's worth writing down.

I ran real networks before the cloud swallowed them. I supported a mobile operator's 2G cell-expansion, ran a network-inventory audit on another carrier's equipment, built out Cisco switching and IP telephony for a holding company and its subsidiaries. That grounding didn't become worthless when SASE arrived. It became the thing that lets me actually understand what SASE is doing — and, more usefully, what it's doing wrong at 3am when the vendor dashboard says everything's green and users say nothing works.

1. The question every young engineer asks

The instinct behind "is CCNP still worth it?" isn't stupid. It's true that fewer people configure a router by hand than did a decade ago, and it's true that the market is moving decisively — standalone SD-WAN deployments are in decline, roughly two-thirds of enterprises are folding them into SASE, and the whole secure-access market is growing fast. If your mental model of networking is "type commands into a Cisco box," that model is genuinely shrinking.

But that was never what the fundamentals were. Subnetting, routing, how a packet actually finds its way, why latency happens, what a retransmission storm looks like — those aren't Cisco trivia. They're the physics of how information moves, and SASE runs on exactly the same physics. Abstraction doesn't repeal the fundamentals; it just hides them until something breaks and you need to see through the abstraction to fix it.

2. What SASE actually is, minus the marketing

Cut through the acronym soup and SASE is a straightforward idea: take the networking (SD-WAN, routing) and the security (secure web gateway, zero-trust access, firewalling) that used to be separate boxes in separate teams, and deliver them as one cloud-based service applied at the edge, close to the user, wherever the user is. The driver is that the old model — backhaul everything to a corporate data centre to inspect it — stopped making sense once the applications moved to the cloud and the users moved to their kitchen tables.

It's a genuinely good idea, and it's winning for good reasons. But notice what it is underneath: it's routing and security policy, converged and moved to the cloud. Someone still has to understand the routing and the security policy. The convergence changed where the work happens and who does it; it didn't abolish the work or the understanding it requires.

SASE doesn't mean nobody needs to understand networking. It means the people who understand networking now also need to understand identity and security policy — which is a bigger job, not a smaller one.

3. The fundamentals didn't die; they moved up the stack

When I debug a SASE or cloud-networking problem today, I'm using exactly the mental models CCNP drilled into me — just applied to virtual constructs instead of physical ones. A cloud VNet peering issue is a routing problem. A ZTNA policy that's silently dropping traffic is an access-control-list problem wearing a nicer interface. A "the app is slow from the branch" ticket is the same latency-and-path analysis I did on physical circuits, now across a provider's backbone I can't see directly. The person who understands why gets to the answer. The person who only knows which buttons to click files a support ticket and waits.

This is the part the "certs are dead" crowd misses. Automation and cloud didn't remove the need to understand systems; they raised the stakes on it, because now one misunderstanding scales instantly across the whole estate instead of being contained to one device you can walk over and unplug.

4. Even Cisco pivoted — read the curriculum

Here's the tell that settles the argument for me. Look at what happened to the CCNP curriculum itself. It didn't stand still defending the old world; it absorbed the new one. The current professional-level security material now covers zero-trust architecture, secure service edge and SD-WAN, cloud security frameworks, MFA and endpoint posture, the MITRE ATT&CK model, AI-driven defence. Zero trust, SSE and SASE are explicitly replacing the traditional VPN in the syllabus.

In other words, the certification my young colleague dismissed as legacy is teaching precisely the SASE-era skills he thought made it obsolete. The vendor whose boxes are supposedly disappearing rewrote its whole professional track around securing a cloud-first, perimeter-less network. When the incumbent reinvents its own flagship credential that thoroughly, "the fundamentals are dead" is not the lesson. "The fundamentals moved, keep up" is.

5. Where deep networking still plainly wins

Beyond the debugging, there are whole domains where deep networking isn't optional and never became so. Anything with hard latency or reliability requirements — trading, industrial control, real-time voice and video, the telecom world I came from — still lives and dies on people who understand the network at a level no dashboard abstracts away. Regulated environments with strict data-residency rules need someone who genuinely understands traffic paths, which is exactly why "sovereign SASE" has become a thing. And every SASE deployment I've seen go badly went badly because someone treated it as a magic appliance instead of a network they still had to design.

The cloud abstracts the routine and commoditises the simple. It does not abstract the hard cases, and the hard cases are where careers are made. The engineer who can operate comfortably at the abstract layer and drop down to first principles when the abstraction leaks is worth several who can only do one.

6. What I'd actually tell him to learn now

So here's the advice I gave, and I stand by it. Yes, learn the fundamentals — do the CCNP-level work, because the mental models are permanent even as the products churn. But don't stop there, and don't learn them the way I did, as pure on-prem networking. Learn them alongside the new shape of the job: identity and zero-trust access, because the perimeter is now a person, not a place; cloud networking constructs, because that's where the packets actually go now; and enough security to speak the language, because networking and security stopped being separate disciplines the moment SASE fused them.

The honest summary is that networking didn't shrink — it merged with security and moved to the cloud, which made the fundamentals more valuable, not less, and the job bigger, not smaller. CCNP isn't a relic. It's the ground floor of a building that got taller. Study the fundamentals, then keep climbing. If you're weighing which networking or security path to invest in next, ask me — I've watched a lot of these bets pay off and a few not.