Netskope is the second pure-play vendor of scale in security service edge, and the clearest available test of whether architectural differentiation converts into a durable business when the competitor holding the same ground is four times larger and profitable. It listed on Nasdaq in September 2025 at $19 a share, traded as high as $28, fell to $7.67, and now sits near $14. In the four quarters it has reported as a public company it has exceeded revenue and earnings expectations every time, and the shares fell after three of them.
That disjunction is the subject worth examining. The operating business is growing annual recurring revenue at 27% and improved its non-GAAP operating margin by eleven points in a year. The market has been trading something else entirely: decelerating growth, a cash outflow in the first half of the current year, an unusually large convertible debt load for a recently listed software company, and a share structure in which public shareholders hold roughly 6% of the votes.
The investment case reduces to a single comparison. Netskope holds approximately $899m of annual recurring revenue growing 27%, at a non-GAAP operating margin of minus 9%. Zscaler holds $3.5bn growing 25%, at plus 23%. Netskope trades at roughly 6 times forward revenue against Zscaler near 9. If the margin gap is a matter of timing and scale, the discount is the opportunity. If it is structural, the discount is the correct price.
The franchise
Sanjay Beri founded Netskope in October 2012 after running access and security at Juniper Networks, and the company emerged from stealth a year later selling a cloud access security broker. The founding observation was that employees had begun reaching software-as-a-service applications directly, frequently from unmanaged devices, and that the security industry’s instinct to block this was going to fail. The product had to make the traffic safe rather than prevent it.
The technical problem was one of visibility, and it is worth setting out because it explains the shape of the company today. A firewall inspecting cloud traffic sees an address, a port and at best a server name. It can establish that an employee reached a cloud storage provider. A web gateway sees a URL and a category, and can establish that the request was to cloud storage. Neither can determine which account was used, whether it was the corporate tenant or a personal one, what action was taken, or what data moved. Netskope built an inline proxy that terminated the session, interpreted the application’s own semantics, and made decisions on instance, activity and content. A policy could permit uploads to the corporate tenant of a service, block uploads to a personal tenant of the same service, and inspect the content of both.
That heritage separates Netskope from both groups of competitors. Vendors descended from firewalls, meaning Palo Alto Networks, Fortinet and Cisco, begin from a network flow model and add application and data context above it. Vendors descended from web gateways, principally Zscaler and the former Blue Coat business now inside Broadcom, terminate and inspect traffic but originated in a web problem of URL categorisation and malware rather than a data problem. Netskope started at the application and data layer and acquired its networking capability later, purchasing Infiot in 2022 for software-defined wide area networking. The consequence is visible in the product: data protection and cloud application granularity are native, and the networking is bolted on.
The commercial estate now comprises approximately 4,700 customers, of which 1,686 spend more than $100,000 a year, a cohort that grew 23% and represents around 86% of recurring revenue. Average spend within it exceeds $450,000. More than a third of the Fortune 100 are customers. Module attachment is the clearest evidence the platform argument is working: customers run 4.4 products on average, with 59% on four or more and 29% on six or more, both up materially year on year.
Business model
Revenue is subscription, sold by capacity and module, and the company steers investors to annual recurring revenue rather than billings. That figure reached $899m at the end of July 2026, having grown 34%, 31%, 29% and 27% across the last four reported quarters. The deceleration is orderly rather than alarming, but it is unambiguous and it is the single most important number in the bear case.
Gross margin has improved substantially as the network scales, reaching 77% on a non-GAAP basis, and operating losses have narrowed sharply. Non-GAAP operating margin moved from minus 16% to minus 9% over the year. The gap between GAAP and non-GAAP figures is unusually wide and should be handled with care: the GAAP operating loss for the year to January 2026 was roughly $653m against $256m the year before, almost entirely because listing triggered vesting on restricted stock. That is a one-off accounting event rather than a deterioration in the business, and the GAAP margins from that year are not a run rate.
Cash flow is where the current argument sits. The year to January 2026 produced the company’s first positive free cash flow, at $12.4m. The first half of the current year produced an outflow of $86.9m, against guidance of a small positive margin for the full year. Management attributes this to a deliberate shift of multi-year contracts onto annual billing, which reduces cash collected today in exchange for a cleaner renewal book later, and points to future committed billings growing 78%. The explanation is plausible and the strategy is defensible. It also requires a large second-half reversal to be true, and because Netskope does not disclose calculated billings, there is no published figure against which an outside observer can test it before the results arrive.
The balance sheet holds approximately $1.07bn of cash and securities against $698.1m of convertible notes raised privately in January 2023. Carrying debt of that size is uncommon for a software company this recently public and this far from profitability, and the company’s own risk factors flag servicing it as a specific concern.
The platform: SSE, SASE and NewEdge
Security service edge is the delivery of security controls from the cloud rather than from appliances in a data centre, on the premise that if users and applications have both left the building there is nothing left for a perimeter to defend. It assembles four components: a secure web gateway inspecting internet traffic, a cloud access security broker governing software-as-a-service use, zero trust network access connecting users to individual applications rather than to networks, and data loss prevention operating across all of them. Secure access service edge is the same set combined with the networking functions, principally software-defined wide area networking and firewall as a service, that connect branches and sites.
Netskope sells this as Netskope One, marketed on the claim of one engine, one client, one console and one network. The architectural argument is single-pass inspection: traffic is decrypted and examined once, with every policy applied in the same pass, rather than being chained through separate services each imposing its own latency. Data loss prevention runs from a common classification layer across web, cloud application and private application traffic, which is the direct inheritance of the cloud access security broker origin.
The most genuinely differentiated asset is NewEdge, the private network Netskope built and owns rather than renting from a public cloud. It spans more than 120 data centres across 80 regions with over 11,000 peering adjacencies, including direct peering with the major productivity and application providers, and every location runs the full service stack rather than a subset. Netskope publishes a processing latency commitment below ten milliseconds. Gartner cited network breadth when placing the company furthest on ability to execute in its 2026 evaluation of secure access service edge platforms.
Owning the network is a real advantage and a real cost. It produces control over performance and a defensible claim in evaluations where latency decides the outcome, and it is why gross margin has been able to expand towards 77% as utilisation rises. It also means capital expenditure that a competitor running on rented infrastructure does not carry, and the company does not break out what NewEdge costs. In a business where free cash flow is the contested metric, a differentiator that consumes capital without separate disclosure is a gap worth noting.
The platform’s clearest omission is that Netskope has no endpoint agent in the detection sense and no security information and event management product. It secures the path between the user and the application. It does not observe what happens on the device or correlate alerts across the estate. Against Palo Alto Networks, which can sell secure access service edge alongside endpoint detection, or Microsoft, which sells everything inside one agreement, that is a structural limit on how much of a security budget Netskope can consolidate.
AI security: the CASB problem again
Netskope’s artificial intelligence products are the most credible part of its growth narrative, for a reason that is architectural rather than promotional. Governing employee use of generative AI services is, in structural terms, the same problem the company was founded to solve. An organisation needs to know which AI services its staff are using, whether the account is corporate or personal, what is being sent in a prompt, and whether the response contains anything it should not. That is instance awareness, activity awareness and content classification applied to a new category of application, which is precisely what a cloud access security broker does.
The product set now includes an AI gateway, guardrails applied to prompts and responses, a broker for agentic traffic, and red-teaming tooling, alongside a data security command centre introduced in the most recent quarter. The company reports more than fifty patented machine learning detection techniques and several thousand data classifiers underpinning them.
The claim to treat carefully is monetisation. Netskope does not disclose revenue, recurring revenue or customer counts for its AI products, and management has described traction qualitatively without quantifying it. The architecture is genuinely well suited to the problem and the positioning is not opportunistic, but a reader should distinguish between a credible product thesis and demonstrated revenue, and only the first is currently evidenced.
The listing and what has happened since
Netskope raised approximately $1.04bn in September 2025, selling 54.97m shares at $19 including a fully exercised over-allotment, entirely in primary stock with no selling shareholders. The offering valued the company near $7.3bn, below the $7.5bn it had achieved privately in July 2021, and the shares rose 18% on debut. Prior funding exceeded $1bn across equity rounds led by Sequoia, ICONIQ, Lightspeed and Accel, and the convertible note taken in January 2023.
The subsequent record is the most instructive part of the company’s short public history. The first result in December 2025 beat expectations and the shares fell about 12% on guidance. The full-year result in March 2026 beat again, guided the following year to roughly 23% growth against 32% achieved, and the shares fell around 17%, then fell a further 15% the next day as the lock-up released approximately 390m shares early. The first quarter of the current year, reported in June, beat on revenue and earnings but disclosed a $57.2m free cash flow outflow against a positive figure a year earlier, and the shares fell roughly 20% while ten brokers cut price targets in a single day. The most recent quarter, reported on 2 September 2026, beat again, raised full-year guidance and showed an eleven-point margin improvement, and the shares finally rose, by around 13%.
The pattern is consistent and worth stating plainly: the operating results have been better than expected every quarter, and the share price has responded to guidance, cash flow and share supply instead. A company that beats and falls three times in four is not being disbelieved on its numbers; it is being disbelieved on the trajectory those numbers imply.
The moat
The strongest element is the owned network combined with inline placement. Once an organisation routes its traffic through Netskope, the platform sits at the decision point for every subsequent control, and policies, application definitions, data classifiers, exception handling and compliance rules accumulate inside it. Removing the service is a network and security transformation performed in reverse, not a cancelled subscription. The 114% net revenue retention and rising module attachment both reflect that position.
The second is the data layer itself. Classification quality, the granularity of application instance and activity awareness, and fifteen years of accumulated understanding of how cloud applications actually behave are not quickly replicated by a competitor whose starting point was a firewall rule or a URL category. This is why Netskope tends to be strong in evaluations where data protection is the deciding criterion, and why it claims high win rates against legacy proxy and data protection incumbents once it reaches a proof of concept.
The third is analyst standing, which matters in this market because secure access service edge purchases are large, slow and heavily committee-driven. Netskope has been a Gartner leader in security service edge for five consecutive years and in secure access service edge platforms for three, positioned furthest on execution in the most recent of the latter.
The limits are the mirror image. Netskope has no endpoint and no security operations product, so it cannot bundle back against competitors who can. It sells into two separate budget holders, since networking and security teams frequently procure independently, which lengthens sales cycles for the full platform. It is a quarter of Zscaler’s size, funding research and network capital expenditure from a smaller base while losing money. And a free-standing security vendor without a wider platform is structurally exposed to the consolidation argument that Palo Alto Networks and Microsoft make in every large evaluation.
Competitive landscape
The market is consolidating around a small number of platforms, and the contest is no longer about whether security should be delivered from the cloud. It is about whether a buyer wants the best independent implementation of that idea or an adequate one attached to something already purchased.
| Competitor | Where it is strongest | Netskope advantage | Netskope vulnerability |
|---|---|---|---|
| Zscaler | Scale, profitability, the largest inline traffic base and a mature access franchise | Data-centric heritage, owned full-stack points of presence and faster growth | Four times larger with a 23% operating margin against minus 9%, and a longer public record |
| Palo Alto Networks | Breadth across network, cloud, security operations and identity | Purpose-built cloud architecture rather than a firewall model extended outward | Can bundle endpoint detection with secure access edge; Netskope has nothing to bundle back |
| Microsoft | Identity, endpoint and productivity data inside agreements already signed | Independent enforcement across every cloud and application, not one vendor estate | Adequate controls arriving at near-zero incremental cost inside an existing licence |
| Cloudflare | A global internet-scale network, developer adoption and edge performance | Deeper enterprise data protection and cloud application governance | Can combine connectivity, performance and security on one network at aggressive pricing |
| Cato Networks | Converged networking and security built as one platform from the outset | Stronger data security depth and a longer enterprise track record | Rose sharply in the 2026 evaluations and competes directly for the same converged budget |
| Cisco and Fortinet | Branch networking, appliances, channel reach and installed estates | No hardware legacy to preserve and a simpler direct-to-cloud model | Incumbents can meet hybrid requirements and bundle networking with security cheaply |
Zscaler is the comparison that governs the investment case, and the two are consistently bracketed together as the only pure-play vendors of scale. Netskope was placed furthest on ability to execute in Gartner’s 2026 secure access service edge evaluation, in which Zscaler entered the leaders quadrant; the same report noted Zscaler’s healthier financial position, which is the whole argument in one observation. Netskope grows faster and is architecturally credible. Zscaler earns a 23% operating margin and generates cash every quarter. The market is currently paying about a third less per unit of revenue for the faster grower, which is a rational price for the risk rather than an obvious inefficiency.
Palo Alto Networks and Microsoft are the structural threats rather than the head-to-head ones. Neither has to build a better product; each needs a good enough one attached to a budget the customer has already committed. Netskope’s answer is that data protection at this level of granularity is not a feature that can be adequately bundled, and that argument holds in evaluations where data is the deciding criterion and weakens everywhere else.
One further point of context: Netskope has been the aggressor in patent litigation against Fortinet, having filed for declaratory judgment in 2022 after receiving infringement threats and subsequently filing its own infringement claims. The current status of those actions could not be established from public sources and no damages exposure has been disclosed.
The investment debate
Netskope trades near $14.27, giving a market capitalisation of approximately $5.76bn and, against roughly $1.07bn of liquidity and $698m of convertible debt, an enterprise value near $5.4bn. That is around 6 times guided revenue for the year to January 2027. The shares are 25% below the offer price and 49% below their high, having at one point traded as low as $7.67.
The constructive case is that the operating trajectory and the share price have diverged and one of them is wrong. Recurring revenue is compounding at 27%, faster than Zscaler on a like-for-like quarter and considerably faster on an organic basis. Non-GAAP gross margin has reached 77% and non-GAAP operating margin improved eleven points in a year, which is the pattern of a business approaching profitability rather than one struggling towards it. The large-customer cohort grew 23% and module attachment is rising, so the land-and-expand motion is intact. Gartner leadership is genuine and repeated. The artificial intelligence products address a problem the architecture was already built for. And the valuation carries a substantial discount to the only true comparable.
The bearish case does not dispute those facts; it disputes what they will become. Growth has decelerated from 34% to 27% in four quarters and net revenue retention from 118% to 114%, and neither has stopped. The company burned $86.9m of free cash in the first half against a full-year guide of a small positive margin, which requires a substantial second-half reversal that rests on a billing-model transition management chose to undertake. Because Netskope does not publish calculated billings, that explanation cannot be independently tested until the outcome arrives. Accumulated losses stand at $2.6bn. Roughly 400m shares are outstanding with the lock-up long expired. And the two largest competitors can bundle across categories Netskope does not sell into at all.
Two disclosure gaps deserve particular weight. Netskope disclosed dollar-based gross retention once, at 96% in mid-2025, and has not repeated it. With net retention falling four points, the difference between weakening expansion and rising churn is the most important distinction an investor could draw, and the company has withdrawn the number that would draw it. Second, unlike Zscaler it does not report a cohort of customers above $1m of recurring revenue, which invites the inference that the largest-deal picture is less flattering than the $100,000 cohort it does report. Neither omission is evidence of a problem. Both remove the evidence that would settle one.
Governance is the remaining consideration and it is stark. Netskope has three share classes, with Class B carrying twenty votes per share. Holders of Class B controlled approximately 99.3% of voting power immediately after listing, leaving the public Class A stock, despite being the larger class by share count, with roughly 6% of the votes. Conversions are gradually diluting the control block, but a Class A shareholder should understand that ownership here confers economics and effectively no governance rights.
The sell side has been unusually consistent through the volatility. Ten firms cut price targets on a single day in June without a single downgrade, and targets have been rising again since August. Consensus sits at a buy with an average target near $18, implying roughly 30% upside. Analysts have held their ratings and repriced their expectations four times in eleven months, which is a reasonable description of the stock itself.
What to watch
Free cash flow in the second half is the decisive number. Management has guided to a positive full-year margin after an $86.9m first-half outflow, and the entire billing-transition explanation stands or falls on whether that reversal appears. If it does not, the market will conclude the cash profile is structural rather than transitional, and the multiple will reflect that.
Recurring revenue growth and net retention are the second pair. Growth has stepped down each of the last four quarters and retention has fallen four points. Stabilisation at 27% and 114% would support the argument that this is a maturing business finding its rate. Continued decline would suggest the pure-play position is being squeezed by bundles. Any reinstatement of gross retention disclosure would materially improve the ability to judge which.
On the platform: whether artificial intelligence products are ever quantified in revenue rather than described, whether Netskope acquires or builds into endpoint or security operations to answer the bundling problem, and whether the margin improvement continues at roughly the recent pace towards breakeven, which on current trajectory would arrive during the next financial year.
Finally the comparison itself. Zscaler reports its own full-year results imminently, and the gap between the two on growth, margin and cash generation is the cleanest available measure of whether Netskope is closing on the incumbent or being outrun by it.
Bottom line
Netskope is a technically serious company with a genuine architectural claim, repeated analyst leadership in its category, and a growth rate that exceeds the larger incumbent it is chasing. The cloud access security broker heritage produced a data protection capability competitors built later and less natively, the owned network is a real asset rather than a marketing construct, and the artificial intelligence products extend the founding problem rather than chasing a theme.
What it has not yet demonstrated is that the model produces cash. Every quarter as a public company has beaten expectations and the shares fell after three of them, because the market is not assessing the printed quarter but the distance still to travel: from minus 9% operating margin to positive, from a first-half cash outflow to a full-year inflow, and from a 27% growth rate that has stepped down four quarters running to one that holds.
The discount to Zscaler is roughly a third on revenue, and it is not mispricing so much as a price for that uncertainty. A reader assessing Netskope should treat the second-half cash reversal as the test that matters, hold the withdrawn gross retention disclosure and the absent billings figure firmly in view when weighing management’s explanation of it, and recognise that as a Class A shareholder they would be backing that judgement with no ability to influence it.