Quick Summary
Covering the latest research from top Wall Street investment banks

Post-quantum migration will extend the firewall upgrade cycle, with PANW offering the clearest platform and monetization path

Institution
Morgan Stanley
Date
2026-08-17
Authors
Ryan Lountzis, Meta A Marshall, Lucas Cerisola
Company
-
Ticker
-
Industry
Cybersecurity and Network Equipment
Rating
Industry View: Attractive
BullishMedium confidenceThe “harvest now, decrypt later” risk and long migration cycles are driving enterprises to invest early; cybersecurity vendors sit at key control points for encryption, traffic inspection, and policy enforcement, while older firewalls may require replacement due to insufficient performance.
AuthorsRyan Lountzis, Meta A Marshall, Lucas Cerisola
CoverageUnited States
Business segmentsFirewalls and Cybersecurity、Identity Security、Cryptographic Asset Discovery and Certificate Management
Research firm divisions/subsidiariesMorgan Stanley(Other)

AI summary card

Post-quantum migration will extend the firewall upgrade cycle, with PANW offering the clearest platform and monetization path

Morgan Stanley believes that although post-quantum cryptographic migration will be a multi-year process, the urgency of the risk and equipment performance requirements will drive upgrades in cybersecurity, identity governance, and certificate management, with PANW holding the most direct monetization advantage.

Industry view is Attractive; PANW is the preferred beneficiary, while CSCO leads the next-best tier; benefits for FTNT, ZS, and CHKP are more oriented toward renewals, upselling, and equipment refreshes.
Post-Quantum CryptographyQuantum SecurityFirewall UpgradesCybersecurityIdentity SecurityCertificate Management
  • Widely used public-key cryptosystems such as RSA and elliptic-curve cryptography face future quantum-computing risk, requiring enterprises to inventory and replace vulnerable encryption in advance.
  • Not every deployment requires firewall replacement, but legacy equipment may be unable to support post-quantum cryptography through software upgrades or meet traffic-inspection performance requirements.
  • AI-driven network-traffic growth combined with post-quantum migration could extend strong firewall hardware demand in 2026 into 2027.
  • PANW already offers paid Quantum-Safe Security and has capabilities in traffic inspection, cryptographic translation, certificate automation, and machine identity.
  • CSCO can monetize through Cisco IQ assessments, professional services, and hardware upgrades, with additional product capabilities expected to launch from late 2026 through 2027.

Report interpretation

Overview

The report discusses the impact of cryptographic migration in a post-quantum world on the cybersecurity industry. Quantum computers have not yet reached the capability to break mainstream cryptography, but attackers can collect encrypted data with long-term sensitivity now and decrypt it once future capabilities emerge; because cryptographic migration across networks, applications, endpoints, and identity systems takes years, customers are investing early.

Core views

Firewalls and cybersecurity platforms sit at execution, inspection, and policy-control points for encrypted connections, positioning them to benefit first from demand for cryptographic asset discovery, quantum-safe connections, and encrypted traffic inspection. PANW has the broadest capability coverage and an existing directly monetized product; CSCO has opportunities in assessment and hardware-refresh revenue, with a relatively comprehensive follow-on product roadmap. For other vendors, near-term value is primarily reflected in retention, platform upselling, compliance competitiveness, and equipment refreshes rather than separately disclosed quantum-security revenue.

Analysis framework

The report compares vendors across capabilities including cryptographic asset inventory, quantum-safe connections, post-quantum traffic inspection, crypto-agility and legacy-system bridging, machine identity, and certificate lifecycle management, while assessing current product maturity, timing of monetization, and follow-on validation indicators.

Methodology notes

  • Competitive Positioning ComparisonPost-Quantum Migration Capability Matrix

    Compares vendors' publicly disclosed coverage of key migration capabilities.

    Uses cryptographic asset inventory, quantum-safe connections, traffic inspection, legacy-system compatibility, and machine identity/certificate management as dimensions to identify the relative leadership of PANW and CSCO.

  • Commercialization AssessmentProduct Maturity and Monetization Path

    Distinguishes among existing paid products, embedded capabilities, roadmap capabilities, and capabilities in testing.

    Focuses on whether revenue comes directly from licenses, assessments, and services, or is primarily reflected indirectly through renewals, upselling, and hardware refreshes.

Asset mapping & comparison

Structured mapping from thesis to named assets (strengths, weaknesses, peers, risks).

  • Palo Alto Networks (PANW)
    Preferred Beneficiary
    Strengths
    Broadest capability coverage; existing paid Quantum-Safe Security; PAN-OS 12.1 supports post-quantum traffic inspection and cryptographic translation, and extends into certificates and machine identity through CyberArk and Venafi.
    Weaknesses
    Has not disclosed the number of paying customers, scanned assets, renewal rates, or quantum-related revenue.
    Comparison
    Has the most complete publicly disclosed set of migration capabilities and the clearest direct monetization path relative to peers.
    Risks
    Customer demand, inspection performance, the scale of hardware upgrades, and conversion to platform-based procurement may fall short of expectations.
  • Cisco (CSCO)
    Leading Second-Tier Player
    Strengths
    Cisco IQ can assess quantum-vulnerable cryptography and make upgrade recommendations; the company can monetize through assessments, professional services, and modern hardware, with a broad product-expansion roadmap.
    Weaknesses
    Some key functions are still expected to become generally available only from late 2026 through 2027.
    Comparison
    Its roadmap breadth is second only to PANW, but its current direct product coverage and clarity of immediate monetization are lower.
    Risks
    Roadmap delays, a low replacement rate for the installed base, and limited software and services upselling.
  • Fortinet (FTNT)
    Indirect Beneficiary
    Strengths
    FortiOS supports hybrid post-quantum key exchange, quantum-safe private network connections, and encrypted traffic inspection; ASICs may benefit performance-sensitive customers.
    Weaknesses
    Management has stated that related capabilities are embedded in FortiOS and carry no additional charge.
    Comparison
    Technology deployment is relatively mature, but direct quantum-security revenue potential is weaker than that of PANW and CSCO.
    Risks
    Uncertainty around actual throughput performance, supported FortiGate generations, and quantum-driven refresh demand.
  • Zscaler (ZS)
    Cloud Inspection Control-Point Beneficiary
    Strengths
    Can decrypt, inspect, and re-encrypt traffic using hybrid post-quantum encryption, while supporting protection for certain private network tunnels.
    Weaknesses
    Capabilities are currently embedded in Zscaler Internet Access, with no separate pricing or disclosed adoption.
    Comparison
    Competitive in cloud traffic inspection, but has more limited cryptographic asset inventory and direct monetization capabilities than PANW.
    Risks
    Latency, computing costs, protocol coverage, and private-application support may constrain large-scale deployment.
  • Check Point (CHKP)
    Limited Beneficiary
    Strengths
    R82 supports quantum-safe site-to-site VPN key exchange, while R82.10 adds inspection for certain post-quantum TLS sessions.
    Weaknesses
    Its migration role is narrow, with no disclosed incremental pricing, customer adoption, or performance data.
    Comparison
    Has VPN and inspection capabilities, but overall coverage is lower than PANW, CSCO, FTNT, and ZS.
    Risks
    Commercial opportunity may be constrained if it does not expand into cryptographic discovery, migration reporting, and certificate management.
  • Netskope (NTSK)
    Early Potential Beneficiary
    Strengths
    Is advancing platform updates around ML-KEM 768, which could support retention, data-security cross-selling, and demand from regulated industries.
    Weaknesses
    The platform remains under development, with customer sandbox testing planned and no broad production availability yet.
    Comparison
    Has architectural relevance, but product maturity and certainty of direct monetization are lower than for deployed peers.
    Risks
    General-availability timing, performance, packaging, and customer demand remain unclear.
  • Okta (OKTA)
    Indirect Identity-Security Beneficiary
    Strengths
    Its existing platform can govern non-human identities; it plans to introduce post-quantum capabilities in two phases across the edge, federation layer, and management tools.
    Weaknesses
    Current revenue opportunities still primarily come from existing identity products, while direct post-quantum products await roadmap delivery.
    Comparison
    Has strong relevance at the identity layer, but less direct exposure to certificate and cryptographic migration than PANW's CyberArk and Venafi.
    Risks
    Uncertainty around delivery timing, authentication-protocol support, tenant migration controls, and product packaging.
  • SailPoint (SAIL)
    Indirect Governance-Layer Beneficiary
    Strengths
    Machine identity and agent identity security products can discover non-human identities, assign ownership, and manage access lifecycles.
    Weaknesses
    Does not directly implement post-quantum cryptography and has not announced a dedicated roadmap.
    Comparison
    Is more focused on identity discovery and governance before migration than on direct cryptographic technology replacement.
    Risks
    Insufficient customer add-on purchases and insufficient integration depth with certificate, PKI, and cryptographic-discovery vendors.
  • CrowdStrike (CRWD)
    Partner-Driven Potential Beneficiary
    Strengths
    Can distribute Keyfactor AgileSec through the Falcon ecosystem for discovery of algorithms, certificates, keys, and machine identities.
    Weaknesses
    Dedicated cryptographic asset inventory and post-quantum readiness capabilities are led by Keyfactor, while CrowdStrike's economic benefit has not been disclosed.
    Comparison
    Currently appears more like a channel and platform-stickiness beneficiary than a migration leader.
    Risks
    Direct monetization potential is limited if findings from the partnership cannot flow into native paid Falcon remediation or risk-exposure workflows.

Key data

  • Maximum TLS Certificate Validity PeriodReduced to 47 days in March 2029The CA/Browser Forum approved a phased reduction, reinforcing demand for automation of certificate issuance, renewal, and replacement.
  • Potential Hardware Refresh Window2026 to 2027The report believes that older firewalls, especially those in use for more than five years, may lack the performance required to support post-quantum cryptography and full traffic inspection.
  • Cisco Product RoadmapLate 2026 to 2027Broader capabilities are planned to cover routing, switching, firewalls, identity, observability, and collaboration products.
  • PANW Direct Monetization MethodQuantum-Safe Security licenses and Secure-Flex creditsBilling capability is linked to the number of cryptographic assets already scanned.

Impact & implications

Post-quantum migration will expand cybersecurity procurement from point encryption upgrades to cryptographic asset discovery, encrypted traffic visibility, certificate lifecycle management, machine identity governance, and equipment performance refreshes. In the near term, cybersecurity vendors are most likely to benefit through installed-base customer renewals, platform upselling, and hardware refreshes; platforms able to integrate network control points with identity and certificate management are more likely to capture direct and visible commercialization opportunities.

Risks

  • Cryptographically relevant quantum computers have not yet emerged, and the pace of customer investment may be slower than expected.
  • Most vendors have not disclosed standalone quantum-security revenue, pricing, adoption rates, or renewal data, limiting visibility into commercial impact.
  • Many capabilities remain at the roadmap, testing, or limited-support stage, and product delivery and performance may fall short of expectations.
  • Post-quantum capabilities may be provided as free or embedded features of existing platforms, making it difficult to generate standalone revenue.
  • The report covers multiple companies with disclosed investment-banking, service, or ownership relationships with Morgan Stanley, requiring attention to conflict-of-interest disclosures.

What to watch

  • PANW's paying customers, Secure-Flex usage, cryptographic asset scan volume, renewal rates, and firewall upgrade demand.
  • CSCO's product roadmap delivery from late 2026 through 2027, Cisco IQ adoption, and hardware replacement rate.
  • Full-inspection performance, customer enablement rates, supported device ranges, and quantum-driven refreshes at FTNT, ZS, and CHKP.
  • The timing and commercialization plan for NTSK's transition from sandbox testing to general availability.
  • Whether OKTA, SAIL, and CRWD can translate identity governance, certificate management, or partner capabilities into measurable upselling.
  • Whether government and highly regulated industries become the first large-scale purchasers for post-quantum migration.
Zhejiang ICP No. 2022035445-5
Disclaimer: Market data, charts, indicators, research views, and other information provided on this website are intended solely for information display, research communication, and educational reference. They should not be regarded as personalized investment advice, securities recommendations, trading instructions, solicitations, or guarantees of return. While we strive to improve the reliability of our data and content, such information may still be subject to delays, errors, incompleteness, or untimely updates due to source differences, methodological limitations, system processing, or market volatility. Users should exercise independent judgment based on their own circumstances and bear all risks and responsibilities arising from the use of this website.

Settings

Sign in to view recent logins