Post-quantum migration will extend the firewall upgrade cycle, with PANW offering the clearest platform and monetization path
AI summary card
Post-quantum migration will extend the firewall upgrade cycle, with PANW offering the clearest platform and monetization path
Morgan Stanley believes that although post-quantum cryptographic migration will be a multi-year process, the urgency of the risk and equipment performance requirements will drive upgrades in cybersecurity, identity governance, and certificate management, with PANW holding the most direct monetization advantage.
- Widely used public-key cryptosystems such as RSA and elliptic-curve cryptography face future quantum-computing risk, requiring enterprises to inventory and replace vulnerable encryption in advance.
- Not every deployment requires firewall replacement, but legacy equipment may be unable to support post-quantum cryptography through software upgrades or meet traffic-inspection performance requirements.
- AI-driven network-traffic growth combined with post-quantum migration could extend strong firewall hardware demand in 2026 into 2027.
- PANW already offers paid Quantum-Safe Security and has capabilities in traffic inspection, cryptographic translation, certificate automation, and machine identity.
- CSCO can monetize through Cisco IQ assessments, professional services, and hardware upgrades, with additional product capabilities expected to launch from late 2026 through 2027.
Report interpretation
Overview
The report discusses the impact of cryptographic migration in a post-quantum world on the cybersecurity industry. Quantum computers have not yet reached the capability to break mainstream cryptography, but attackers can collect encrypted data with long-term sensitivity now and decrypt it once future capabilities emerge; because cryptographic migration across networks, applications, endpoints, and identity systems takes years, customers are investing early.
Core views
Firewalls and cybersecurity platforms sit at execution, inspection, and policy-control points for encrypted connections, positioning them to benefit first from demand for cryptographic asset discovery, quantum-safe connections, and encrypted traffic inspection. PANW has the broadest capability coverage and an existing directly monetized product; CSCO has opportunities in assessment and hardware-refresh revenue, with a relatively comprehensive follow-on product roadmap. For other vendors, near-term value is primarily reflected in retention, platform upselling, compliance competitiveness, and equipment refreshes rather than separately disclosed quantum-security revenue.
Analysis framework
The report compares vendors across capabilities including cryptographic asset inventory, quantum-safe connections, post-quantum traffic inspection, crypto-agility and legacy-system bridging, machine identity, and certificate lifecycle management, while assessing current product maturity, timing of monetization, and follow-on validation indicators.
Methodology notes
Compares vendors' publicly disclosed coverage of key migration capabilities.
Uses cryptographic asset inventory, quantum-safe connections, traffic inspection, legacy-system compatibility, and machine identity/certificate management as dimensions to identify the relative leadership of PANW and CSCO.
Distinguishes among existing paid products, embedded capabilities, roadmap capabilities, and capabilities in testing.
Focuses on whether revenue comes directly from licenses, assessments, and services, or is primarily reflected indirectly through renewals, upselling, and hardware refreshes.
Asset mapping & comparison
Structured mapping from thesis to named assets (strengths, weaknesses, peers, risks).
- Palo Alto Networks (PANW)Preferred Beneficiary
- Strengths
- Broadest capability coverage; existing paid Quantum-Safe Security; PAN-OS 12.1 supports post-quantum traffic inspection and cryptographic translation, and extends into certificates and machine identity through CyberArk and Venafi.
- Weaknesses
- Has not disclosed the number of paying customers, scanned assets, renewal rates, or quantum-related revenue.
- Comparison
- Has the most complete publicly disclosed set of migration capabilities and the clearest direct monetization path relative to peers.
- Risks
- Customer demand, inspection performance, the scale of hardware upgrades, and conversion to platform-based procurement may fall short of expectations.
- Cisco (CSCO)Leading Second-Tier Player
- Strengths
- Cisco IQ can assess quantum-vulnerable cryptography and make upgrade recommendations; the company can monetize through assessments, professional services, and modern hardware, with a broad product-expansion roadmap.
- Weaknesses
- Some key functions are still expected to become generally available only from late 2026 through 2027.
- Comparison
- Its roadmap breadth is second only to PANW, but its current direct product coverage and clarity of immediate monetization are lower.
- Risks
- Roadmap delays, a low replacement rate for the installed base, and limited software and services upselling.
- Fortinet (FTNT)Indirect Beneficiary
- Strengths
- FortiOS supports hybrid post-quantum key exchange, quantum-safe private network connections, and encrypted traffic inspection; ASICs may benefit performance-sensitive customers.
- Weaknesses
- Management has stated that related capabilities are embedded in FortiOS and carry no additional charge.
- Comparison
- Technology deployment is relatively mature, but direct quantum-security revenue potential is weaker than that of PANW and CSCO.
- Risks
- Uncertainty around actual throughput performance, supported FortiGate generations, and quantum-driven refresh demand.
- Zscaler (ZS)Cloud Inspection Control-Point Beneficiary
- Strengths
- Can decrypt, inspect, and re-encrypt traffic using hybrid post-quantum encryption, while supporting protection for certain private network tunnels.
- Weaknesses
- Capabilities are currently embedded in Zscaler Internet Access, with no separate pricing or disclosed adoption.
- Comparison
- Competitive in cloud traffic inspection, but has more limited cryptographic asset inventory and direct monetization capabilities than PANW.
- Risks
- Latency, computing costs, protocol coverage, and private-application support may constrain large-scale deployment.
- Check Point (CHKP)Limited Beneficiary
- Strengths
- R82 supports quantum-safe site-to-site VPN key exchange, while R82.10 adds inspection for certain post-quantum TLS sessions.
- Weaknesses
- Its migration role is narrow, with no disclosed incremental pricing, customer adoption, or performance data.
- Comparison
- Has VPN and inspection capabilities, but overall coverage is lower than PANW, CSCO, FTNT, and ZS.
- Risks
- Commercial opportunity may be constrained if it does not expand into cryptographic discovery, migration reporting, and certificate management.
- Netskope (NTSK)Early Potential Beneficiary
- Strengths
- Is advancing platform updates around ML-KEM 768, which could support retention, data-security cross-selling, and demand from regulated industries.
- Weaknesses
- The platform remains under development, with customer sandbox testing planned and no broad production availability yet.
- Comparison
- Has architectural relevance, but product maturity and certainty of direct monetization are lower than for deployed peers.
- Risks
- General-availability timing, performance, packaging, and customer demand remain unclear.
- Okta (OKTA)Indirect Identity-Security Beneficiary
- Strengths
- Its existing platform can govern non-human identities; it plans to introduce post-quantum capabilities in two phases across the edge, federation layer, and management tools.
- Weaknesses
- Current revenue opportunities still primarily come from existing identity products, while direct post-quantum products await roadmap delivery.
- Comparison
- Has strong relevance at the identity layer, but less direct exposure to certificate and cryptographic migration than PANW's CyberArk and Venafi.
- Risks
- Uncertainty around delivery timing, authentication-protocol support, tenant migration controls, and product packaging.
- SailPoint (SAIL)Indirect Governance-Layer Beneficiary
- Strengths
- Machine identity and agent identity security products can discover non-human identities, assign ownership, and manage access lifecycles.
- Weaknesses
- Does not directly implement post-quantum cryptography and has not announced a dedicated roadmap.
- Comparison
- Is more focused on identity discovery and governance before migration than on direct cryptographic technology replacement.
- Risks
- Insufficient customer add-on purchases and insufficient integration depth with certificate, PKI, and cryptographic-discovery vendors.
- CrowdStrike (CRWD)Partner-Driven Potential Beneficiary
- Strengths
- Can distribute Keyfactor AgileSec through the Falcon ecosystem for discovery of algorithms, certificates, keys, and machine identities.
- Weaknesses
- Dedicated cryptographic asset inventory and post-quantum readiness capabilities are led by Keyfactor, while CrowdStrike's economic benefit has not been disclosed.
- Comparison
- Currently appears more like a channel and platform-stickiness beneficiary than a migration leader.
- Risks
- Direct monetization potential is limited if findings from the partnership cannot flow into native paid Falcon remediation or risk-exposure workflows.
Key data
- Maximum TLS Certificate Validity PeriodReduced to 47 days in March 2029The CA/Browser Forum approved a phased reduction, reinforcing demand for automation of certificate issuance, renewal, and replacement.
- Potential Hardware Refresh Window2026 to 2027The report believes that older firewalls, especially those in use for more than five years, may lack the performance required to support post-quantum cryptography and full traffic inspection.
- Cisco Product RoadmapLate 2026 to 2027Broader capabilities are planned to cover routing, switching, firewalls, identity, observability, and collaboration products.
- PANW Direct Monetization MethodQuantum-Safe Security licenses and Secure-Flex creditsBilling capability is linked to the number of cryptographic assets already scanned.
Impact & implications
Post-quantum migration will expand cybersecurity procurement from point encryption upgrades to cryptographic asset discovery, encrypted traffic visibility, certificate lifecycle management, machine identity governance, and equipment performance refreshes. In the near term, cybersecurity vendors are most likely to benefit through installed-base customer renewals, platform upselling, and hardware refreshes; platforms able to integrate network control points with identity and certificate management are more likely to capture direct and visible commercialization opportunities.
Risks
- Cryptographically relevant quantum computers have not yet emerged, and the pace of customer investment may be slower than expected.
- Most vendors have not disclosed standalone quantum-security revenue, pricing, adoption rates, or renewal data, limiting visibility into commercial impact.
- Many capabilities remain at the roadmap, testing, or limited-support stage, and product delivery and performance may fall short of expectations.
- Post-quantum capabilities may be provided as free or embedded features of existing platforms, making it difficult to generate standalone revenue.
- The report covers multiple companies with disclosed investment-banking, service, or ownership relationships with Morgan Stanley, requiring attention to conflict-of-interest disclosures.
What to watch
- PANW's paying customers, Secure-Flex usage, cryptographic asset scan volume, renewal rates, and firewall upgrade demand.
- CSCO's product roadmap delivery from late 2026 through 2027, Cisco IQ adoption, and hardware replacement rate.
- Full-inspection performance, customer enablement rates, supported device ranges, and quantum-driven refreshes at FTNT, ZS, and CHKP.
- The timing and commercialization plan for NTSK's transition from sandbox testing to general availability.
- Whether OKTA, SAIL, and CRWD can translate identity governance, certificate management, or partner capabilities into measurable upselling.
- Whether government and highly regulated industries become the first large-scale purchasers for post-quantum migration.