North American cybersecurity and networking vendors in the post-quantum encryption migration Report Interpretation
Morgan Stanley sees Harvest-Now-Decrypt-Later risk and lengthy migration work bringing post-quantum security investment forward. Palo Alto Networks has the broadest disclosed capabilities and clearest direct monetization path, while Cisco forms the next tier and many peers benefit chiefly through retention, attach and refresh activity.
Summary
Morgan Stanley sees Harvest-Now-Decrypt-Later risk and lengthy migration work bringing post-quantum security investment forward. Palo Alto Networks has the broadest disclosed capabilities and clearest direct monetization path, while Cisco forms the next tier and many peers benefit chiefly through retention, attach and refresh activity.
- A sufficiently capable quantum computer could break widely used RSA and elliptic-curve public-key cryptography, while migration across networks, applications, devices and identities will take years.
- Older firewalls may lack the performance for post-quantum cryptography, potentially extending strong 2026 firewall hardware demand into 2027.
- PANW offers a paid Quantum-Safe Security application and broad coverage across inventory, connectivity, inspection, crypto-agility and machine identity.
- Cisco can monetize assessments and selected hardware today, with broader capabilities scheduled through late 2026 and 2027.
- For most vendors, early economics are expected to be retention, platform attach and upgrade activity rather than a separately disclosed quantum-security revenue stream.
Report Interpretation
Overview
This Morgan Stanley update assesses how the transition to post-quantum encryption could affect North American cybersecurity and networking vendors. It identifies network-security control points as early beneficiaries, ranks Palo Alto Networks as the best positioned, and expects most near-term commercial benefits outside PANW to be indirect.
Core views
The report frames post-quantum security as a multi-year migration rather than an immediate replacement cycle. Modern cryptography uses symmetric encryption to protect data and asymmetric, public-key cryptography for authentication, key exchange and digital signatures. A sufficiently powerful quantum computer could break widely used RSA and elliptic-curve cryptography, although no cryptographically relevant quantum computer exists today. Morgan Stanley argues that the clock has nevertheless started because adversaries can collect long-lived encrypted data now for later decryption, while replacing vulnerable cryptography across networks, applications, devices and identities will take years. Network-security vendors are positioned at enforcement and inspection points where customers must upgrade encrypted connections while retaining visibility and policy controls. Post-quantum protection does not always require a new firewall, but legacy equipment may not support the software upgrade or have sufficient performance for new encryption technologies. Combined with AI-driven growth in network traffic, this could create a larger refresh cycle, particularly for installed equipment more than five years old. The report therefore thinks stronger firewall hardware results in 2026 could extend into 2027, with early spending concentrated at network-security and key-encryption control points. Morgan Stanley's disclosed-capability comparison places Palo Alto Networks first: it is the only vendor screened as having direct exposure across cryptographic inventory and readiness, quantum-safe connectivity, post-quantum traffic inspection, crypto-agility/legacy bridging, and machine identity/certificate lifecycle management. PANW already sells Quantum-Safe Security, a paid application that inventories algorithms, keys and certificates and recommends remediation; PAN-OS 12.1 adds post-quantum traffic inspection and cipher translation for legacy applications. CyberArk and Venafi expand its reach into certificate automation and machine identity. The report sees direct monetization today through licenses and Secure-Flex credits, while noting that disclosed customer numbers, scanned assets, renewals and quantum-related revenue are absent. Cisco is viewed as the broadest next-tier vendor. Cisco IQ can assess routing, switching, data-center and firewall environments for quantum-vulnerable encryption and recommend software upgrades, feature activation or hardware replacement. Selected quantum-safe transport and hardware-trust capabilities are available, with wider support across routing, switching, firewalls, identity, observability and collaboration targeted through December 2026 and June 2027. Morgan Stanley expects current monetization from assessments, professional services and selected modern hardware, with the broader software, support and infrastructure-refresh opportunity dependent on roadmap delivery and customer adoption during late 2026 and 2027. Fortinet, Zscaler and Check Point have meaningful but narrower shipping capabilities. Fortinet supports hybrid classical/post-quantum encryption, private-network connections and encrypted-traffic inspection through FortiOS; because these capabilities are included without added cost, the expected benefit is retention, FortiGuard and Security Fabric attach, regulated-industry positioning and possible appliance refresh. Zscaler can inspect traffic using hybrid post-quantum encryption through Zscaler Internet Access and protect selected private-network tunnels, but the capability is included in the existing product; the expected near-term effects are retention, differentiation in large enterprise deals and wider Zero Trust Exchange adoption. Check Point supports quantum-safe site-to-site VPN key exchange and selected post-quantum web-session inspection; potential economics are adoption of R82/R82.10, support, subscriptions and refresh, with a larger opportunity requiring broader migration functionality. Identity security is another important migration layer. The CA/Browser Forum's phased reduction of maximum publicly trusted TLS certificate validity from 398 days to 47 days by March 2029 reinforces the need to automate certificate issuance, renewal and replacement. PANW's CyberArk and Venafi assets provide the most direct exposure to certificate and post-quantum migration. Okta's current identity platform governs non-human identities, while its two-phase plan starts with hybrid key exchange at the edge and federation layer before expanding to the Okta Integration Network and administrative tools; direct revenue depends on those capabilities reaching general availability. SailPoint's machine- and agent-identity products can support discovery, ownership and access reviews ahead of credential replacement, but its benefit is indirect because it does not itself implement post-quantum cryptography. Netskope's architecture is relevant but remains in development: it has identified five post-quantum update areas in Netskope One and is building around ML-KEM 768, with customer sandbox testing planned instead of broad production availability. Its opportunity is therefore contingent on general availability, performance, packaging and demand. CrowdStrike's role is partner-led: Keyfactor AgileSec is available through its Marketplace and can use the Falcon footprint for cryptographic discovery, but Keyfactor owns the specialized readiness product. Morgan Stanley expects near-term value chiefly through Falcon platform stickiness unless CrowdStrike develops native discovery or integrates partner findings into paid remediation or Flex workflows. Across the group, Morgan Stanley emphasizes that its capability labels measure publicly disclosed thematic product exposure as of August 2026, not customer adoption, revenue contribution, stock ratings or overall investment attractiveness. The common commercial test is whether quantum-readiness tools drive measurable adoption, attach, refresh and eventually standalone revenue rather than remaining an embedded feature.
Analysis framework
Morgan Stanley begins with the cryptographic vulnerability and migration timeline, then identifies the network and identity control points where the transition requires discovery, inspection, connectivity, certificate management and governance. It compares vendors' publicly disclosed capabilities across five migration functions and assesses each company's current product role, likely monetization timing and the operational milestones that would validate commercial uptake.
Methodology notes
Assessment of cybersecurity vendors at network-enforcement, traffic-inspection and identity-governance control points.
The report maps where encryption migration work occurs and evaluates which vendors control the relevant parts of the security stack, helping distinguish direct product exposure from indirect platform benefits.
Post-quantum migration demand transmission from cryptographic vulnerability to discovery, software upgrades, hardware refresh, identity management and vendor monetization.
The report links a long migration process and performance constraints in legacy infrastructure to potential retention, attach, services and equipment-refresh effects across cybersecurity vendors.
Asset mapping & comparison
Structured mapping from thesis to named assets (strengths, weaknesses, peers, risks).
- Palo Alto Networks (PANW)Best-positioned vendor with direct monetization available today across network and identity migration functions.
- Strengths
- Broadest disclosed platform; paid Quantum-Safe Security; post-quantum inspection, cipher translation, certificate automation and machine-identity capabilities.
- Weaknesses
- Customer count, assets scanned, renewal rates and quantum revenue have not been disclosed.
- Comparison
- The report screens PANW as direct across all five assessed migration capabilities, ahead of Cisco and other peers.
- Risks
- Commercial uptake and firewall upgrade requirements remain to be demonstrated.
- Cisco (CSCO)Broadest next-tier post-quantum platform and potential infrastructure-refresh beneficiary.
- Strengths
- Cisco IQ assessments, selected current capabilities, and a broad roadmap across networking and security products.
- Weaknesses
- The larger opportunity depends on future roadmap features reaching general availability.
- Comparison
- Second to PANW in the report's capability assessment.
- Risks
- Execution timing, installed-base replacement needs and measurable software/services attach.
- Fortinet (FTNT)Shipping network capabilities primarily support retention, attach and appliance refresh.
- Strengths
- Hybrid encryption, encrypted-traffic inspection and custom-chip performance advantages.
- Weaknesses
- Capabilities are included in FortiOS without additional cost rather than sold as a standalone product.
- Comparison
- Narrower than PANW and Cisco in the disclosed-capability comparison.
- Risks
- Customer enablement, compatible FortiGate generations and inspection throughput.
- Zscaler (ZS)Cloud inspection control point with indirect near-term monetization.
- Strengths
- Hybrid post-quantum traffic inspection, tunnel protection and existing policy enforcement.
- Weaknesses
- Post-quantum inspection is included in Zscaler Internet Access; adoption, pricing and compute costs are undisclosed.
- Comparison
- More direct inspection exposure than identity-centric vendors but narrower overall scope than PANW.
- Risks
- Protocol breadth, private-application support, latency and expansion beyond session visibility.
- Netskope (NTSK)Relevant architecture, but commercial benefit depends on moving from development to general availability.
- Strengths
- Netskope One is being updated around ML-KEM 768 and may support data-security cross-sell.
- Weaknesses
- Platform remains in development with planned sandbox testing rather than broad production availability.
- Comparison
- Partial or limited across the assessed migration categories.
- Risks
- General-availability timing, performance, packaging, supported traffic paths and demand.
- Okta (OKTA)Identity-governance participant whose direct post-quantum opportunity depends on roadmap execution.
- Strengths
- Existing governance of non-human identities and a planned two-phase migration roadmap.
- Weaknesses
- Current opportunity is in existing identity products rather than a dedicated post-quantum offering.
- Comparison
- More identity-focused and less direct in traffic inspection than network-security vendors.
- Risks
- Delivery timing, protocol support, tenant migration controls, customer pilots and packaging.
- SailPoint (SAIL)Indirect beneficiary through machine-identity discovery and governance during migration.
- Strengths
- Machine and agent identity discovery, ownership and lifecycle controls.
- Weaknesses
- Does not implement post-quantum cryptography directly and has not announced a direct roadmap.
- Comparison
- Governance-focused rather than a direct cryptographic migration platform.
- Risks
- Product attach, customer adoption and integrations with certificate and cryptographic-discovery vendors.
- CrowdStrike (CRWD)Partner-led discovery exposure through the Keyfactor AgileSec Marketplace integration.
- Strengths
- Falcon footprint can distribute cryptographic discovery through Keyfactor AgileSec.
- Weaknesses
- Keyfactor owns the specialized inventory and readiness product; CrowdStrike economics are undisclosed.
- Comparison
- Less direct ownership of the migration than PANW, Cisco or vendors with native network capabilities.
- Risks
- Marketplace deployment and economics, customer demand, and whether findings become native paid Falcon workflows.
Key data
- TLS certificate validity398 days to 47 days by March 2029CA/Browser Forum's phased reduction in maximum publicly trusted certificate validity.
- Cisco broader roadmap timingDecember 2026 and June 2027Target dates for wider support across networking, firewall, identity, observability and collaboration.
- Potential affected firewall installed baseMore than 5 years oldMorgan Stanley says older equipment may lack performance to optimize for post-quantum cryptography.
- PANW capability coverageDirect across five assessed migration capabilitiesCryptographic inventory/readiness, quantum-safe connectivity, post-quantum inspection, crypto-agility/legacy bridge, and machine identity/certificate lifecycle.
Impact & implications
The report argues that post-quantum migration can broaden cybersecurity upgrade activity, initially benefiting vendors that control encrypted traffic and identity workflows. PANW has the clearest current paid offering; Cisco has a substantial roadmap-led opportunity; and other vendors' near-term gains are more likely to show up in retention, platform attach, services and refresh activity than in standalone quantum-security revenue.
Risks
- Legacy firewalls may not require replacement if software upgrades and performance are sufficient, limiting the refresh opportunity.
- Most vendors have not disclosed customer adoption, pricing, revenue contribution or performance data for post-quantum capabilities.
- Cisco's larger opportunity depends on timely roadmap execution through late 2026 and 2027.
- Netskope's opportunity depends on moving from sandbox testing to a broadly available production product.
What to watch
- PANW customer counts, Secure-Flex consumption, inventory assets scanned, renewal rates and evidence of integrated platform purchases.
- Cisco feature releases, Cisco IQ uptake, installed-base hardware replacement needs and software/services attach.
- Evidence of quantum-driven appliance refreshes and full-inspection performance for Fortinet and Check Point.
- Zscaler protocol coverage, latency, private-application support and expansion toward enterprise encryption inventory.
- Netskope general-availability timing, sandbox adoption, performance, packaging and customer demand.
- Okta roadmap delivery, protocol support, tenant migration controls and customer pilots.
- Whether CrowdStrike develops native cryptographic inventory capabilities or paid remediation integration.