← Back to blog

63% of Enterprises Use SD‑WAN: When IT Should Keep MPLS for Voice

October 6, 2026
63% of Enterprises Use SD‑WAN: When IT Should Keep MPLS for Voice

For most cloud-first, multi-site businesses, SD-WAN is the better fit today. MPLS still makes sense for a small set of latency-sensitive, compliance-bound or poorly connected locations, and the practical outcome for many mid-size and larger networks is a hybrid setup that keeps MPLS on a handful of critical links while shifting everything else to SD-WAN.


TL;DR:

  • SD-WAN deployment is faster and more flexible, making it suitable for most branch sites, while MPLS remains essential for latency-sensitive or compliance-heavy locations.
  • MPLS circuits, though reliable with guaranteed SLAs, entail long provisioning times and higher costs that scale with site count and bandwidth.
  • SD-WAN relies on public internet quality and encryption, requiring proper security measures like SASE, and its performance depends on the reliability of the underlying link.
  • Hybrid networks are common, with MPLS kept at critical locations and SD-WAN used elsewhere, supporting gradual migration over several quarters.
  • A redundancy approach combining MPLS and SD-WAN improves disaster recovery, with SD-WAN providing automatic failover across multiple links.

Businessvoip
Get Your Business Phones Working
BusinessVoip.ca designs, programs, cables, and installs supported VoIP phone systems for Ontario businesses and multi-site operations.
Visit BusinessVoip.ca

Table of Contents

What Is MPLS and How Does It Operate?

MPLS, or Multiprotocol Label Switching, routes traffic across a carrier's private backbone using labels instead of full IP lookups at every hop. A carrier assigns a short label to each packet at the network edge, and routers along the path forward traffic based on that label rather than re-examining the destination address each time. The result is a predictable, carrier-managed path between sites, sold with a contractual service level agreement covering latency, jitter and uptime.

That predictability is why MPLS became the default choice for voice and other real-time applications for two decades. A business leasing MPLS circuits gets a private path that does not compete with public internet congestion, so call quality and video performance stay consistent even during busy hours.

The tradeoff shows up in cost and flexibility. MPLS circuits are priced per site and per megabit, provisioning a new circuit often takes weeks to months, and every site added to the network means another carrier order, another installation window and another recurring fee. None of that maps well to cloud and SaaS traffic, which wants to go straight to the internet rather than detour through a data center.

  • MPLS forwards traffic using labels over a carrier-owned backbone, not the public internet.
  • It carries a contractual SLA for latency, jitter and packet loss, which is why real-time voice and video rely on it.
  • New circuits typically take weeks to months to provision, and costs scale with site count and bandwidth.

What Is SD-WAN and How Do Businesses Deploy It?

SD-WAN, or software-defined wide area networking, separates the control plane from the data plane. Instead of routing decisions living in each physical router, a central controller pushes policy to edge appliances or virtual instances at every site, and those devices decide in real time which path (MPLS, broadband, 4G or 5G) best suits each type of traffic. According to Cisco, this architecture lets businesses use active-active multipath routing across commodity internet circuits, something MPLS-only networks cannot do without adding a second parallel network.

The practical benefit is direct internet breakout. A branch office can send Microsoft 365 or Salesforce traffic straight to the nearest cloud point of presence instead of routing it back through a central hub, which cuts latency for everyday SaaS use and reduces the load on expensive MPLS circuits. Centralized orchestration also means a new site can be brought online in days rather than months, since there is no private circuit to provision, only an internet connection and a pre-configured appliance.

The catch is that SD-WAN performance is only as good as the underlay carrying it. Because most SD-WAN deployments ride on public broadband, cable or fiber internet rather than a dedicated circuit, quality depends on local ISP reliability, and businesses need to add encryption and edge security themselves, often through a SASE framework that bundles a next-generation firewall with the SD-WAN fabric.

  • SD-WAN uses a central controller to steer traffic across multiple links based on application needs.
  • Direct internet breakout sends cloud and SaaS traffic straight out, skipping the backhaul that MPLS-only designs require.
  • Underlay quality and integrated security (commonly through SASE) determine whether SD-WAN performs as well as the MPLS circuits it replaces.

How Do MPLS and SD-WAN Compare on Cost, Performance, Security and Management?

The decision usually comes down to five practical dimensions, and the answer differs by site rather than by company as a whole.

On cost, MPLS charges recurring fees per circuit that climb with bandwidth and distance, while SD-WAN licensing runs on top of comparatively cheap broadband or fiber internet. Savings show up fastest at branch sites with modest bandwidth needs and no regulatory requirement for a private circuit. On performance, MPLS's SLA guarantees deterministic latency and jitter, which matters most for voice, video conferencing and real-time trading systems. SD-WAN instead steers traffic adaptively across available paths, which works well for most applications but cannot promise the same worst-case ceiling that a carrier-backed SLA does.

Security differs structurally, not just in degree. Palo Alto Networks notes that MPLS provides privacy through physical and logical isolation rather than encryption, which was fine when traffic stayed inside the private backbone. SD-WAN traffic typically crosses the public internet, so it relies on encrypted tunnels and is commonly paired with a SASE stack that adds a next-generation firewall and firewall-as-a-service at the edge.

Scalability tilts clearly toward SD-WAN. Standing up a new MPLS circuit involves carrier lead times measured in weeks or months, while an SD-WAN site typically goes live in days once an internet connection is in place. Operationally, MPLS management sits mostly with the carrier, while SD-WAN shifts more configuration and monitoring in-house or to a managed provider, which means IT teams need application-aware policy skills they may not have needed before.

According to the 2026 WAN Manager Survey, a majority of enterprises have deployed SD-WAN and direct internet access now connects more than half of sites, while MPLS persists mainly at locations with specific QoS, geographic or compliance requirements. That split mirrors the hybrid pattern most networks land on rather than an all-or-nothing switch.

  • Cost savings from SD-WAN appear fastest at branch sites with modest bandwidth and no compliance requirement for a private circuit.
  • MPLS's SLA guarantees a performance ceiling that matters for voice and real-time trading; SD-WAN's adaptive steering handles most other traffic well.
  • Security on MPLS relies on isolation, while SD-WAN requires encryption and, usually, a SASE layer for equivalent protection.

What Does a Practical Hybrid Migration Look Like?

Few enterprises move everything to SD-WAN in one step. The common pattern keeps a reduced set of MPLS circuits active at headquarters, data centers or sites with strict compliance needs, while every other location runs on SD-WAN over broadband, with MPLS and internet links coexisting on the same edge appliance so traffic can shift between them automatically.

  1. Pilot SD-WAN at five to ten lower-risk branch sites and measure application performance against the old MPLS baseline before touching anything critical, a pattern Network World describes as the standard rollout sequence.
  2. Validate SLAs for voice, video and any latency-sensitive line-of-business application running on the pilot sites.
  3. Expand to additional sites in phases, right-sizing or canceling MPLS circuits that are no longer carrying critical traffic.
  4. Retain MPLS only where geography, regulation or application sensitivity genuinely requires it, often a small fraction of the original footprint.

For a medium-size enterprise with 20 to 50 sites, this phased approach typically plays out over several quarters rather than all at once, giving IT teams time to build underlay redundancy (a second ISP or a 4G/5G failover link) before cutting over voice or other sensitive traffic.

Cost levers during this transition include right-sizing remaining MPLS circuits to the minimum bandwidth actually needed, investing in diverse underlay providers so a single ISP outage does not take down a site, and choosing between a managed SD-WAN service and a do-it-yourself deployment based on in-house networking staff. Regulatory data residency rules, government contracts or sites in regions with thin internet infrastructure are the usual reasons a location keeps MPLS indefinitely rather than migrating.

What Should You Check Before Migrating Your WAN?

A migration project succeeds or fails on preparation, not vendor selection. Before signing anything, gather a real baseline and confirm the underlay can carry voice and video without the private circuit backing it up.

  • Measure current latency, jitter and packet loss on existing links, and map which applications depend on which thresholds.
  • Confirm every candidate site has redundant direct internet access, with symmetric upload and download bandwidth sized for simultaneous voice calls, not just web browsing.
  • Verify 4G or 5G fallback is available where a second wired ISP is not, our internet and phone for business guide covers underlay options in more detail.
  • Confirm SASE readiness, segmentation and encryption requirements are covered before any site breaks out to the internet directly.
  • Nail down monitoring, SLA terms and contract exit conditions in writing before committing to a managed SD-WAN provider.

Pro Tip: Run your baseline measurements during your worst-case traffic hour, not a quiet Tuesday morning, or you will underestimate what the new network needs to handle.

What Voice Quality Checks Matter for SD-WAN or MPLS?

Voice traffic behaves differently from web browsing or file transfer, and it punishes a poorly tuned network immediately rather than slowly. Reserved bandwidth and DSCP 46 marking for RTP voice packets matter on both MPLS and SD-WAN, because without that marking, a large file upload at a branch office can degrade a call in progress.

MPLS has historically made voice QoS simpler because the carrier SLA already guarantees low jitter and loss. Matching that on SD-WAN means configuring application-aware path selection so voice always takes the best available link, reserving bandwidth per site, and testing how the local broadband connection holds up under real contention during peak hours, not just at idle.

G.711 remains the better codec choice when bandwidth allows, since compressed codecs trade call clarity for smaller packets. On constrained links, a compressed codec may be the only realistic option.

  • Mark RTP voice traffic with DSCP 46 so it gets priority treatment ahead of other traffic.
  • Reserve bandwidth per site sized for simultaneous calls, not average usage.
  • Test local broadband contention at peak hours before trusting an SD-WAN link with live voice.

During a network check, our technicians verify site wiring, traffic shaping and QoS policing before any phone goes live, the same checks detailed in our VoIP QoS setup guide.

Pro Tip: If your SD-WAN underlay can't hold a steady 100 ms round trip under load, fix the underlay before blaming the phone system.

What Protocols and Technologies Power MPLS and SD-WAN?

MPLS relies on label distribution protocols, typically LDP or RSVP-TE, to build label-switched paths across a carrier's routers, with each router forwarding based on a short label rather than a full routing table lookup. That label-based forwarding is what lets a carrier guarantee a path and attach an SLA to it, since the route a packet takes is fixed and predictable rather than dynamically chosen hop by hop.

SD-WAN works at a different layer. Edge appliances build encrypted overlay tunnels, commonly using IPsec, across whatever underlying transport exists: broadband, fiber, 4G or MPLS itself. A central controller distributes policy to every appliance, and each device makes real-time path decisions based on measured latency, jitter and loss across the available tunnels, a design Cloudflare's learning resources describe as ISP-agnostic by design. That independence from any single transport type is what lets SD-WAN mix MPLS, internet and cellular links under one policy framework, something MPLS-only architectures were never built to do.

What Goes Wrong When Businesses Adopt SD-WAN or MPLS?

The most common SD-WAN mistake is treating it as a pure cost-cutting swap rather than an architecture change. The WAN Manager Survey warns that enabling direct internet breakout without upgrading branch security leaves a network exposed, since traffic that used to funnel through a central firewall now exits locally at every site. Skipping that step is the single most avoidable failure in SD-WAN rollouts.

A second pitfall is underestimating underlay quality. An SD-WAN deployment inherits the reliability of whatever broadband or fiber connection it rides on, and a site with a single unreliable ISP gains little from sophisticated path steering if there is no second path to steer toward.

MPLS carries its own risks, mainly inflexibility. Locking into long-term circuit contracts before confirming actual bandwidth needs leads to overpaying for capacity that goes unused, and the multi-month provisioning timeline can stall expansion into new locations when the business needs to move faster than a carrier can install a circuit.

What Do Real Deployments Show About These Tradeoffs?

A multi-site retail or office network moving from MPLS-only to SD-WAN typically reports faster cloud application performance once SaaS traffic stops backhauling through a central data center, along with lower monthly connectivity costs at smaller branch locations. Organizations that skip the security upgrade step, however, often find their direct internet breakout sites becoming the weakest point in an otherwise solid network.

On the other side, businesses in regions with limited broadband competition, or those bound by data residency or industry compliance rules, frequently find that keeping MPLS at a handful of sites avoids both a performance gap and a compliance headache that SD-WAN alone cannot solve. Network World's analysis concludes that the two technologies are complementary rather than competing, with the right mix depending on each site's bandwidth needs, application sensitivity and management preference rather than a blanket rule.

How Does WAN Choice Affect Reliability and Disaster Recovery?

Network resilience improves when a site has more than one type of path to fall back on, and this is where SD-WAN has a structural advantage over an MPLS-only design. A site running SD-WAN across two internet providers, or internet plus a 4G or 5G failover link, keeps functioning during a single-provider outage because traffic reroutes automatically.

SD-WAN rerouting traffic across backup paths

An MPLS-only site, by contrast, depends entirely on that one carrier circuit staying up. A hybrid design that pairs an existing MPLS link with an internet-based SD-WAN overlay gets the best of both: the deterministic SLA when the MPLS circuit is healthy, and an automatic internet failover when it is not. For disaster recovery specifically, that redundancy matters more than raw bandwidth, since the goal during an outage is keeping critical voice and application traffic alive on whatever path remains, not maximizing throughput.

Where Are MPLS and SD-WAN Headed Next?

The clearest trend is convergence around SASE, bundling SD-WAN's path steering with cloud-delivered security so branch offices get both performance and protection from a single managed service.

MPLS is not disappearing, but its role is narrowing to the workloads that genuinely need a guaranteed path: certain compliance-bound industries, specific geographies with thin internet infrastructure, and latency-critical applications where an SLA-backed circuit remains worth the premium. Expect managed SD-WAN and SASE offerings, the kind of bundled service that reduces the in-house skill gap smaller IT teams face, to keep gaining ground over do-it-yourself deployments as the technology matures.

Our Take on Where WAN Budgets Should Go

The honest forecast is that full rip-and-replace rarely makes sense. SD-WAN paired with SASE is the clear long-term direction, but the smarter budget move is investing in underlay redundancy and security integration first, then migrating site by site, rather than canceling every MPLS circuit on a fixed date and hoping the internet holds up.

— James

How We Help You Get WAN and Voice Right From Day One

Whatever direction your network takes, voice quality depends on the details: wiring, bandwidth reservation and QoS policing done correctly at every site. We run a network check before anything goes live, confirming the underlay, cabling and traffic shaping can actually support the phone system before we install a single handset.

Businessvoip

  • We design, program and install the full phone system on-site, so every phone works from day one.
  • Our network check verifies QoS policing, wiring and bandwidth before cutover, catching underlay problems early.
  • Pricing is fixed with no annual increases.

If your team is weighing an SD-WAN migration or just wants confidence that your current network can carry voice reliably, book a phone system design review and we will walk through what your sites need before you commit to anything.

FAQ

Is MPLS outdated?

MPLS is not outdated, but its role has narrowed. The 2026 WAN Manager Survey found MPLS remains in place at sites with specific QoS, geographic or compliance needs even as SD-WAN adoption has grown.

Is MPLS a LAN or WAN?

MPLS is a wide area network (WAN) technology, connecting separate sites over a carrier's backbone rather than linking devices within a single building. It is never used to build a local area network inside one office.

Is MPLS still a thing?

Yes, MPLS is still actively deployed, particularly for latency-sensitive applications and locations where a carrier SLA matters more than cost savings. Many enterprises run it alongside SD-WAN in a hybrid model rather than replacing it outright.

Is SD-WAN obsolete?

No, SD-WAN is the dominant growth direction in enterprise networking right now. The WAN Manager Survey reports 63% of enterprises have already deployed it, with direct internet access now connecting 54% of sites.

Sources