ADD EXHB 4 ea030589201ex99-2.htm MARKET COMPS - NAORIS QUANTUM PROTOCOL

Exhibit 99.2

 

September 2, 2026

 

Naoris Quantum Protocol

 

Industry: Post-Quantum Infrastructure Sector

Geographic Focus: North America with Global Public Comparables

Data Cutoff: August 2026

 

Important Disclosures & Investor Notice

 

Disclosure. This document is for informational purposes only. It is not an offer to sell or a solicitation of an offer to buy securities. This document is qualified in its entirety by the Company’s preliminary offering circular forming part of its Regulation A offering statement on Form 1-A. Readers should read that offering circular in full, including the “Risk Factors” section and the financial statements. An investment in the Class A Common Stock is speculative and involves substantial risks. Investors should purchase only if they can afford a complete loss of their investment. Statements about market opportunity, product development, regulatory timing and future performance are forward-looking statements based on current expectations; actual results could differ materially from those discussed.

 

SECTION 1: SECTOR OVERVIEW — POST-QUANTUM CYBERSECURITY

 

The Role of Post-Quantum Cryptography in Global Capital Markets

 

Every digital transaction depends on cryptography.

 

Banks transfer funds. Governments send classified data. Hospitals protect patient records. Encryption makes these transfers safe.

 

Today’s encryption relies on mathematical problems that classical computers cannot solve in any practical time frame.

 

Quantum computers will change that equation.

 

Experts project that cryptographically relevant quantum computers will emerge within 10 to 15 years [SRC_035].

 

IonQ, a publicly traded quantum computing hardware and software company, has an internal roadmap that targets 2028 [SRC_036] – the most aggressive timeline among major vendors [SRC_036]. While, Forrester, a global research firm, projects “Q-Day” by 2030 [SRC_038]. Q-Day is the point when quantum computers can break current encryption [SRC_038].

 

The threat is not theoretical. Nation-states and sophisticated attackers are already harvesting encrypted data today. They plan to decrypt it later when quantum capability arrives. This is called “harvest now, decrypt later.” [Additional Source]

 

The stakes extend beyond individual companies.

 

Critical infrastructure sectors requiring quantum-safe migration include energy, water, financial services, healthcare, communications, transportation, and defense [SRC_053]. These sectors are necessary for national security, economic stability, and public safety [SRC_053].

 

The 2021 ransomware attack on Colonial Pipeline showed what happens when infrastructure fails. It triggered fuel shortages and price spikes across the East Coast [SRC_054].

 

 

 

Long-Term Performance

 

The market Naoris addresses has three layers. The first is the trigger. Post-quantum cryptography is forecast to grow from $0.42 billion in 2025 to $2.84 billion by 2030, a compound annual growth rate of 46.2% [SRC_300].

 

 

Source: Markets and Markets

 

The second is the budget that trigger acts on. Organizations across industries are investing significantly in security infrastructure to address growing cyber threats, with unprecedented growth in cybercrime, data theft, and targeted ransomware attacks driving demand for enhanced protection [SRC_301].

 

The third is the surrounding opportunity: data protection and recovery growing from $6.73 billion in 2023 to $18.78 billion by 2030 [SRC_301].

 

2

 

 

Post-quantum cryptography is not the market. It is the mandate that forces a quarter-trillion-dollar security budget to be re-spent on new foundations.

 

 

Source: Market.US

 

Industry investment in quantum technology grew by nearly 50% to about $2 billion in 2024 [SRC_034]. Government investment rose from $1.3 billion in 2023 to $1.8 billion in 2024 [SRC_050]. Public funding accounted for 34% of total quantum technology startup investments by 2024 [SRC_050]. Government funding announcements hit $10 billion by April 2025 [SRC_051]. That includes $7.4 billion from Japan and $900 million from Spain [SRC_051].

 

The U.S. market shows similar dynamics.

 

The U.S. post-quantum cryptography market is expected to grow from $203.9 million in 2025 to $1.2 billion in 2030 [SRC_015]. That represents a 43.0% CAGR [SRC_015]. North America commanded 38% of 2024 post-quantum cryptography revenue globally [SRC_005].

 

Structural Pressures and Challenges

 

The Standards Bottleneck Has Cleared

 

For years, enterprises waited for NIST to finalize post-quantum cryptography standards.

 

That wait ended on August 13, 2024. NIST released its first three post-quantum cryptography standards [SRC_012]. They are FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) [SRC_012]. Lattice-based schemes commanded 52% of 2024 post-quantum cryptography revenue [SRC_002]. Kyber and Dilithium lead this category [SRC_002].

 

The standards provide a foundation. Enterprises now have approved algorithms to implement.

 

3

 

 

Enterprise Adoption Lags Far Behind the Threat

 

Despite the urgency, adoption remains minimal.

 

As of May 2025, 69% of organisations recognised the risk quantum computing poses to current encryption. Just 5% had actually deployed quantum-safe encryption [SRC_302]. 95% of the market has not started. The organisations that know it is coming are the same ones that have not moved.

 

Compliance Deadlines Are Creating Forced Demand

 

Regulators are no longer waiting for voluntary adoption, and the timetable has moved. On June 22, 2026 Executive Order 14412 pulled the federal post-quantum deadline forward by four to five years [SRC_304]. Federal agencies must move high-value and high-impact systems to post-quantum key establishment by December 31, 2030, and to post-quantum digital signatures by December 31, 2031 [SRC_303]. Federal contractors must comply with NIST post-quantum FIPS by December 31, 2030. Agencies named post-quantum migration leads within 30 days and filed migration plans with the Office of Management and Budget by October 22, 2026.

 

The previous government-wide target, set by National Security Memorandum 10 in 2022, was 2035. The standard the 2031 signatures deadline points to is ML-DSA, FIPS 204 — the standard Naoris implements [SRC_305].

 

 

Source: ARXIV.org

 

The mandate is not confined to the United States.

 

In the United Kingdom, the National Cyber Security Centre has set three dates: complete cryptographic discovery and a migration plan by 2028, complete the highest-priority migration by 2031, and complete migration entirely by 2035 [SRC_306]. Its guidance is unambiguous — migration will happen globally, and it will not be possible to avoid.

 

4

 

 

In the European Union, NIS2, transposed by October 2024, extends mandatory cyber security requirements to essential and important entities including financial market infrastructures, and requires member states to publish roadmaps and timelines for adopting quantum-resistant cryptography.[SRC_307] [SRC_308].

 

COMPLIANCE CALENDAR
 
US National Security Systems quantum-safe (NSA CNSA 2.0) Jan 2027
UK cryptographic discovery and migration plan complete (NCSC) 2028
US federal high-value assets and federal contractors on post-quantum FIPS (EO 14412) Dec 2030
US federal post-quantum digital signatures (EO 14412) Dec 2031
UK highest-priority migration complete (NCSC) 2031
US operating systems, browsers and cloud services exclusively CNSA 2.0 2033
Full migration — United Kingdom, and all US National Security Systems 2035

 

The Rise of Zero Trust and Distributed Security

 

Post-quantum cryptography fixes one thing: encryption that breaks under quantum attack. But the market is not reorganising itself around a single fix. Eight categories that used to be bought separately — operational resilience, data integrity, digital trust, compliance automation, device attestation, digital identity, confidential computing and post-quantum cryptography — are converging into one trust infrastructure layer.

 

Gartner reached the same conclusion for 2026, naming digital provenance a Top 10 Strategic Technology Trend alongside preemptive cybersecurity, AI security platforms and digital trust, and predicting that by 2029 organisations that fail to invest in digital provenance will face sanction risks running into billions of dollars [SRC_309] [SRC_310]. Naoris is built as that layer. It does not compete category by category. It sits underneath all eight.

 

The zero trust security market is projected to grow from $35 billion in 2024 to $190 billion by 2035 [SRC_027]. The zero trust architecture market is forecast to generate an incremental revenue opportunity of $168.8 billion between 2026 and 2036. These forecasts are based on current expectations and may not be realized [SRC_026].

 

 

Source: Market.US

 

Organizations that adopted zero trust architectures saw an 83% cut in incident-response times [SRC_028]. They experienced an 80% drop in successful breaches [SRC_028]. NTT DATA’s zero trust rollout connected 50,000 users in 30 days [SRC_029]. That proved the model could scale when delivered through the cloud [SRC_029].

 

5

 

 

Post-quantum cryptography and zero trust are converging.

 

Taken together, the categories Naoris operates across represent a combined addressable opportunity of more than $200 billion by 2035 — the sum of the zero trust security market, forecast to grow from $35.24 billion in 2024 to $190.27 billion by 2035 at a 16.57% CAGR [SRC_311], and the post-quantum cryptography market, forecast at $2.84 billion by 2030 [SRC_300]. These are the sizes of the categories, independently forecasted.

 

Market Dynamics and Catalysts

 

Three dynamics are shaping the competitive landscape.

 

Government procurement is accelerating: Congress is considering $1.8 to $2.7 billion in quantum research and development funding over five years [SRC_017]. NSA CNSA 2.0 requires all new National Security Systems to be quantum-safe by January 1, 2027 [SRC_032]. The defense sector is buying now, not later.

 

Enterprise awareness is rising: According to Cybersecurity Outlook 2026, 37% of respondents expect quantum technologies to affect cybersecurity within 12 months [SRC_033]. That awareness creates budget allocation. Companies are moving post-quantum cryptography from research projects to procurement line items.

 

The technology stack is shifting to services: Software libraries and SDKs captured 41% of the post-quantum cryptography market in 2024 [SRC_003]. But services represent the fastest growth at a 46.03% CAGR to 2030 [SRC_003]. Cloud-hosted deployments are set to expand at a 44.85% CAGR up to 2030 [SRC_006]. This shift favors platforms that can deliver managed migration and ongoing security operations.

 

SECTION 2: COMPANY CONTEXT — NAORIS QUANTUM PROTOCOL

 

Naoris is a post-quantum digital trust infrastructure company. Its platform operates below security tools, below cloud infrastructure and above hardware, continuously validating devices, identities, systems and data.

 

Naoris’ portfolio spans several distinct categories: Core Naoris Protocol™ is the foundational trust layer that continuously verifies the integrity of systems, identities, devices, and data, deployable on-premises, in the cloud, or air-gapped, and designed to strengthen existing infrastructure rather than replace it. Naoris PQVPN™ is a quantum-secure virtual private network that routes traffic through a mesh of verified nodes, adding a layer of future-proof protection on top of the VPN and zero-trust tools organizations already use. AutoMesh brings that same trust layer to robots, drones, industrial IoT, and factory equipment, allowing machines to verify one another automatically and helping manufacturers catch and recover from disruptions before they halt production. PetalVault gives custodians, insurers, and compliance teams a way to prove ownership of Bitcoin that will hold up in the quantum era, anchoring quantum-resistant proof directly on the Bitcoin network without moving funds or changing the protocol. ÆTERN, the Naoris Community Intelligence Layer, lets creators, brands, and public figures operate verified AI personas with cryptographic proof of authenticity, managing community engagement and analytics with built-in consent and transparency. Together, these products form a diversified offering spanning infrastructure trust, secure communications, identity-enabled community engagement, industrial automation, and digital asset ownership.

 

6

 

 

Foundational Insight and Early Development

 

Naoris was built on a diagnosis made by someone who had seen the problem from the inside. The Company conceived its Distributed Cybersecurity Mesh Architecture in 2018, following discussions with the late Lt. Gen. Kjell Grandhagen — former Chief of the Norwegian Intelligence Service and Chairman of the NATO Military Intelligence Committee — who identified the centralized cybersecurity model as fundamentally flawed.

 

Traditional security concentrates trust in perimeter appliances, certificate authorities and centralised validation points. Each becomes a single point of failure. Compromise one, and the entire system falls.

 

Naoris inverts that model. It turns every endpoint in an enterprise — hardware, device, system, service — into an active participant in its own defense. Each participating device continuously verifies the others under NIST-standard post-quantum cryptography.

 

The result is distributed trust. No single actor can alter or forge the validation record.

 

Technical Validation

 

The platform architecture has been tested through an incentivized public testnet program.

 

From January 31 to November 12, 2025, prior to Naoris’s incorporation, a public testnet with incentivized participation was operated to validate the technical scalability of the platform. During this program, over 100 million post-quantum cryptographic validations secured by NIST ML-DSA were observed across a network of over 1 million connected endpoint nodes, with over 3 million registered digital identities and over 600 million integrity enforcement events.

 

The testnet program was designed to validate two technical objectives: that the distributed validation model can operate at scale, and that the post-quantum cryptography implementation can handle transaction loads.

 

Strategic Repositioning and Corporate Evolution

 

The post-quantum cryptography market has shifted from research to procurement. NIST standards are final [SRC_022]. Federal deadlines are set [SRC_016]. Agencies are inventorying their cryptographic assets [SRC_020].

 

Naoris is positioned for this transition.

 

Its distributed architecture addresses both the quantum threat and the zero-trust imperative. It produces a tamper-evident record of trust, and it is built to stay valid as cryptographic standards are replaced — upgrading to stronger methods over time without disruptive system overhauls and without network forks.

 

The company’s target markets align with regulatory pressure points. However, there are risks involved in market alignment, and success is not guaranteed.

 

7

 

 

The Company’s target customers are government and public sector entities, central banks, payment and settlement systems, systemically important financial institutions, defence and national security organisations, large enterprises, transportation and logistics companies, energy and utility operators, and telecommunications providers. These buyers are already in motion.

 

In December 2025 the Bank for International Settlements Innovation Hub, working with the Bank of Italy, the Bank of France, the Deutsche Bundesbank, Nexi-Colt and Swift, replaced traditional digital signatures with post-quantum cryptography for liquidity transfers in the Eurosystem’s Target2 system [SRC_316]. Europol’s Quantum Safe Financial Forum issued a call to action to the financial sector in February 2025 and a migration prioritisation framework with FS-ISAC in January 2026 [] [SRC_318]. In January 2026 the G7 Cyber Expert Group, chaired by the US Treasury and the Bank of England, published a coordinated post-quantum migration roadmap for the financial sector [SRC_319].

 

Investment Thesis

 

Naoris occupies a specific position in the post-quantum landscape.

 

It is not competing to build quantum computers. It is not selling point-solution cryptography libraries. It is building the trust layer beneath both — and it ships several products on top of it. Naoris PQVPN™ is a distributed post-quantum virtual private network and secure routing layer.

 

AutoMesh allows machines to verify one another automatically and helps manufacturers catch and recover from disruptions before they halt production.

 

PetalVault provides post-quantum evidence of Bitcoin ownership and audit workflows: proof you hold the coins, without moving them.

 

ÆTERN, the Naoris Community Intelligence Layer provides post-quantum-attested AI identity, creator authenticity verification and permissioned digital persona infrastructure.

 

The investment thesis rests on four pillars.

 

Timing: The market is transitioning from research to deployment. NIST standards are final. Federal deadlines create forced demand. The 5% enterprise adoption rate [SRC_013] means 95% of the market is still addressable.

 

Architecture: Distributed validation addresses both quantum threats and zero-trust requirements in a single platform. That integration is rare.

 

8

 

 

Validation: 105 million post-quantum transactions. 1 million security nodes. 586 million threats mitigated. On infrastructure the Company owns outright — the Naoris Protocol, the Trust Mesh and all related software, protocols, algorithms, designs and trade secrets [SRC_320].

 

Market size: The combined post-quantum cryptography and zero-trust market is expected to exceed $200 billion by 2035. Even a modest share might mean significant revenue.

 

 

Source: Grand View Research

 

Risks exist. Competition from well-funded players is intense — SandboxAQ has raised approximately $1.4 million, most recently a Series E of over $450 million in April 2025 at an approximately $5.75 billion post-money valuation [SRC_061].

 

9

 

 

SECTION 3: WHY PUBLIC COMPANY COMPARABLES MATTER

 

Purpose of Comparables in This Sector

 

Post-quantum cryptography is an emerging market. Pure-play public comparables are scarce. The companies that do exist trade at volatile multiples. Those multiples reflect both genuine opportunity and speculative premium. Retail investors need frameworks to separate signal from noise.

 

Comparables serve three functions in this context.

 

First, they set valuation benchmarks. What do public markets pay for quantum-security revenue? How do multiples differ between hardware, software, and services? Where does recurring revenue command a premium?

 

Second, they reveal execution patterns. Which companies turned early technology into sustainable business models? Which failed despite strong initial positioning? The patterns matter more than any single data point.

 

Third, they expose risk factors. Public companies face quarterly scrutiny. Their struggles — customer concentration, margin pressure, competitive displacement — foreshadow challenges that private companies will encounter at scale.

 

Why These Comparables

 

Arqit Quantum Inc. (ARQQ) provides the clearest public-market analogue. It delivers quantum-safe encryption as a platform. It addresses the same enterprise and government buyers that Naoris targets. Its stock performance and revenue trajectory reveal how markets price quantum-security promises against delivery.

 

Cloudflare Inc. (NET) shows how network-scale infrastructure captures security spend, and it is the clearest illustration of what mature execution looks like in distributed security. It is an adjacency rather than a competitor: Cloudflare operates in network security, a different product category from trust infrastructure validation, which is why its multiple is an execution benchmark rather than a valuation ceiling.

 

Quantinuum Inc. (QNT) bridges quantum computing and cryptography. Its hardware generates cryptographic keys that resist quantum attack. The company’s revenue mix and customer base illuminate the government-commercial balance that shapes this market.

 

QuintessenceLabs operates as a private company. It competes directly for post-quantum cybersecurity contracts. Its funding history, technology approach, and customer wins provide context for what Naoris faces without public-market visibility.

 

10

 

 

Comparable Selection Framework

 

These four companies span the relevant spectrum.

 

Arqit is pure-play quantum encryption. Cloudflare is scaled network security. Quantinuum is quantum hardware with cryptography applications. QuintessenceLabs is private-market post-quantum competition. Together, they frame the competitive landscape, valuation expectations, and execution benchmarks that will shape Naoris’ path to liquidity.

 

Comparables Analyzed

 

1.Arqit Quantum Inc. (ARQQ) — Public

 

2.Cloudflare Inc. (NET) — Public

 

3.Quantinuum Inc. (QNT) — Public

 

4.QuintessenceLabs — Private

 

SECTION 4: COMPANY COMPARABLES

 

Arqit Quantum Inc.

 

COMPANY OVERVIEW AND HISTORICAL EVOLUTION

 

Arqit Quantum Inc. began as a space-based quantum key distribution venture.

 

The company planned to launch satellites that would beam unbreakable encryption keys to ground stations. That approach proved expensive and slow to commercialise. Management pivoted to a software-only model. The new focus was symmetric key agreement. This shift let Arqit move faster without waiting for satellite hardware.

 

Today the company sells Arqit SKA - Platform. It is a cloud platform that generates encryption keys resistant to quantum-computer attacks [SRC_177]. The platform forms the core of Arqit’s value proposition. It contributed 100% of total revenue in fiscal year 2025 [SRC_177]. Arqit trades on NASDAQ under the ticker ARQQ. Its headquarters sit in London. Sales efforts increasingly aim at U.S. government and defense buyers.

 

The strategic timeline shows clear intent. In February 2024, Arqit partnered with Carahsoft Technology Corp., a master government aggregator [SRC_176]. That deal opened access to NASA SEWP V, ITES-SW2, NASPO ValuePoint, and OMNIA Partners procurement vehicles [SRC_176]. In March 2025, Arqit signed its first contract with the U.S. Department of Defense for a funded programme of record [SRC_174]. It is working alongside a large IT vendor [SRC_174]. These moves signal a deliberate pivot toward high-value public-sector accounts.

 

11

 

 

BUSINESS MODEL AND TECHNOLOGY

 

Arqit’s core product is its Symmetric Key Agreement (SKA) platform.

 

Symmetric key agreement — a way for two devices to create identical encryption keys without transmitting the key itself — lets users avoid the weakest link in traditional key exchange.

 

Quantum computers threaten today’s asymmetric schemes such as RSA and Diffie-Hellman. Arqit’s approach sidesteps that risk.

 

The platform meets strict government standards. It is compatible with NSA CSfC components [SRC_179]. It also satisfies NSA CSfC Symmetric Key Management Requirements Annexe 1.2 and RFC 8784 [SRC_179].

 

In July 2025, Arqit launched the SKA Edge Controller [SRC_180]. This is a ruggedised device for forward-deployed military operations [SRC_180]. The hardware appliance extends SKA – Platform to tactical edge environments where connectivity is limited [SRC_180].

 

Revenue comes from software licences and multi-year contracts [SRC_183].

 

The company sells to telecom operators, government agencies, defense organisations, and enterprises [SRC_183]. Some of these deals recur annually [SRC_183]. Arqit has built partnerships with Intel, 6WIND, RAD, and Tomorrow Street [SRC_181]. Tomorrow Street selected Arqit as a Scaleup Partner [SRC_181]. The company integrated with Juniper Networks’ vSRX Virtual Firewall [Publicly Available Source]. That integration created a quantum-safe VPN product that supports ETSI 014 and RFC 8784 for IPsec [Publicly available source]].

 

FINANCIAL PROFILE

 

Metric Value Notes
Market Cap $332,000,000 Sep 11 2026
EV $306,000,000 Sep 11 2026
Annual Revenue $1,086,000 LTM from March 31
Gross Margin N/A N/A
EV / Revenue 287x Per above
EV / EBITDA N/A Operating losses ongoing

 

Revenue remains tiny. The company burns roughly $4.3 million per month [SRC_169]. This burn rate poses a significant risk if revenue does not increase. That means Arqit burns about $51.6 million per year in operations.

 

12

 

 

STRATEGIC POSITIONING AND COMPETITIVE LANDSCAPE

 

Arqit occupies a narrow niche. It sells quantum-resistant key management, not full post-quantum cryptography suites.

 

Competitors include large defense contractors and pure-play post-quantum vendors such as ISARA, PQShield, and SandboxAQ. IBM, Google, and Amazon also offer quantum-safe primitives through their cloud services. Arqit’s edge lies in NSA compliance credentials and early defense traction [Corrected Sources]

 

LESSONS FOR NAORIS QUANTUM PROTOCOL

 

Government channels open doors. Arqit’s Carahsoft partnership gave access to four major federal procurement vehicles in one deal [SRC_176]. Naoris may benefit from similar aggregator relationships to reach U.S. public-sector buyers efficiently.
   
Compliance credentials matter early. NSA CSfC compatibility and RFC 8784 adherence helped Arqit win its first DoD contract [SRC_179] [SRC_174]. Naoris should pursue NIST FIPS alignment and other certifications before large sales cycles begin.
   
Edge hardware extends software platforms. The SKA Edge Controller lets Arqit reach tactical environments that cloud-only solutions cannot serve [SRC_180]. Naoris could explore similar ruggedised or IoT form factors to broaden addressable markets.
   
Ecosystem partnerships accelerate integration. Intel, Juniper, and 6WIND relationships gave Arqit faster paths to production-ready offerings [SRC_181] [SRC_182]. Naoris should map potential integration partners and secure co-development agreements before product launch.

 

Cloudflare Inc.

 

COMPANY OVERVIEW AND HISTORICAL EVOLUTION

 

Cloudflare was founded on July 26, 2009 [SRC_225]. Matthew Prince, Lee Holloway, and Michelle Zatlyn started the company [SRC_225]. The business plan won Harvard Business School’s Business Plan Competition that year [SRC_236]. Cloudflare launched publicly in 201 [SRC_227].

 

The company has grown through organic expansion and targeted acquisitions.

 

Today, Cloudflare is used by approximately 21.3% of all websites on the Internet as of January 2026 [SRC_226]. The company protects over eight million websites, APIs, and applications [SRC_235]. Its network operates through more than 330 cities across over 125 countries as of FY2024 [SRC_211]. This global footprint manages 13,000 networks, including all major ISPs [SRC_235].

 

BUSINESS MODEL AND TECHNOLOGY PLATFORM

 

Cloudflare operates a scalable platform model with tiered pricing. Free plans serve startups and small projects [SRC_228]. Enterprise solutions start at $2,000 per month [SRC_228]. This structure lets Cloudflare capture customers at every stage of growth. Small users can upgrade as their needs expand.

 

The company’s network is its core competitive asset.

 

13

 

 

CEO Matthew Prince calls this global infrastructure the key differentiator for delivering zero trust security services [SRC_239]. The network spans 300 cities across more than 100 countries [SRC_239]. When Cloudflare pushes code, it affects over 25 million internet properties [SRC_232]. The platform sees more than one billion IP addresses [SRC_232].

 

Cloudflare has moved aggressively into adjacent markets. In March 2022, the company expanded its partnership with CrowdStrike [SRC_237]. The goal was to integrate its zero trust platform with CrowdStrike Falcon Zero Trust Assessment [SRC_237]. The company launched the world’s first complete Secure Access Service Edge (SASE) platform with integrated post-quantum encryption [SRC_243]. SASE combines network and security functions into a single cloud service. This positions Cloudflare directly in the emerging quantum-safe security market.

 

The company also formed a strategic cyber defense partnership with Mastercard to protect critical infrastructure [SRC_240]. Cloudflare also expanded integration with xAI for Grok model integration into AI Gateway in June 2026 [SRC_323].

 

FINANCIAL PROFILE

 

Metric Value Notes
Market Cap $118,000,000,000 Sep 14 2026
TEV 117,000,000,000 Sep 14
Annual Revenue $2,512,000,000 LTM Jun 30, 2026
Gross Margin $ $1,823,000,000 LTM Jun 30, 2026
Gross Margin % 73% Per above
EV / Revenue 46x Per above

 

Cloudflare’s financial profile shows a high-growth business with premium valuation multiples. Revenue grew from $1.3 billion in 2023 to $2.2 billion in 2025 [SRC_189][SRC_187].

 

STRATEGIC POSITIONING AND COMPETITIVE LANDSCAPE

 

Cloudflare’s competitive moat rests on its global network infrastructure. The company’s 330-city footprint creates latency advantages that competitors cannot easily replicate [SRC_211]. Network effects strengthen this position. More traffic improves threat detection [SRC_235]. Better threat detection attracts more customers.

 

The platform handles 21.3% of all web traffic [SRC_226]. This gives Cloudflare unmatched visibility into attack patterns

 

Competition from hyperscalers like AWS, Microsoft Azure, and Google Cloud remains intense. Yet Cloudflare’s stock has returned 408% over three years and 161% over five years [Updated Source]. This suggests investors believe the company can maintain its growth path. No assurance exists that these returns will continue.

 

14

 

 

LESSONS FOR NAORIS QUANTUM PROTOCOL

 

Build network effects into the core architecture. Cloudflare’s traffic volume directly improves its security products. Each new customer makes the platform more valuable. Naoris should design its decentralized mesh so that additional nodes strengthen the entire network’s threat detection.

 

Offer tiered pricing from free to enterprise. Cloudflare captures customers at every growth stage [SRC_228]. Free plans create a pipeline for future enterprise deals. Naoris could offer free tiers for developers and small projects, converting them as they scale.

 

Prioritize global infrastructure early. Cloudflare’s 330-city network took over a decade to build [SRC_211]. This infrastructure now creates barriers to entry. Competitors cannot easily match them. Naoris should invest in geographic distribution even before revenue scales.

 

Lead on post-quantum standards. Cloudflare launched the first complete SASE platform with integrated post-quantum encryption [SRC_243V]. Early adoption of NIST standards could position Naoris as the default choice. This matters when enterprises face compliance deadlines.

 

Form strategic partnerships with established players. Cloudflare’s partnerships with CrowdStrike, Mastercard, OpenAI, and xAI extend its reach [SRC_237][SRC_240][Correct Source]. Naoris should pursue integrations with major cloud providers and security platforms. That would accelerate distribution.

 

Expect premium multiples for category leadership. Cloudflare trades at 46x revenue despite ongoing losses. Markets reward companies that define new categories. Naoris may command similar premiums if it establishes leadership in decentralized post-quantum security. However, no assurance can be given this will be achieved

 

Quantinuum Inc.

 

COMPANY OVERVIEW AND HISTORICAL EVOLUTION

 

Quantinuum was born in 2021 from the merger of two pioneers. Honeywell Quantum Solutions, founded in 2014 as a division of the $32 billion industrial conglomerate, joined forces with Cambridge Quantum Computing [SRC_137]. Cambridge Quantum had been building quantum software since 2014 under founder Ilyas Khan [SRC_143]. Honeywell took majority ownership of the combined company [SRC_137]. The marriage brought together trapped-ion hardware expertise with quantum software for chemistry, machine learning, and cybersecurity [SRC_143].

 

The company moved quickly to establish leadership in quantum hardware.

 

In 2020, Quantinuum launched the System Model H1-1 [SRC_168]. This was a trapped-ion computer running on 12 qubits [SRC_168]. By September 2025, its H-Series machines achieved the highest quantum volume ever recorded: 33,554,432 [SRC_141]. Rajeeb Hazra, a former Intel executive, took the helm as CEO in 2023 [SRC_139].

 

Under his leadership, Quantinuum became the first quantum computing company to complete a traditional IPO. It listed on Nasdaq on June 4, 2026, at $68 per share [SRC_148]. The offering was heavily oversubscribed. It raised $1.7 billion in gross proceeds [SRC_134] [SRC_138].

 

15

 

 

Today Quantinuum is headquartered in Broomfield, Colorado. It has approximately 700 employees across nine sites in the United States, Europe, and Japan [SRC_144] [SRC_145] [SRC_160]. Over 70% of its workforce holds technical roles [SRC_144]. Honeywell retains 48.1% voting power following the IPO [SRC_149].

 

BUSINESS MODEL AND TECHNOLOGY LEADERSHIP

 

Quantinuum operates a Hardware-as-a-Service model.

 

Customers access its quantum computers through the cloud. This cloud access contributes roughly 50% to 60% of its 2025 annual revenue [SRC_151]. The company also sells quantum software and provides professional services.

 

The technical moat is substantial. Quantinuum’s H-Series trapped-ion computers achieve two-qubit gate fidelity of 99.921% [SRC_150]. They were the first to reach the 99.9% threshold [SRC_150]. The machines hit 99.9%+ two-qubit gates consistently across all qubit pairs [SRC_155]. This matters because higher fidelity means fewer errors in calculations.

 

In one landmark test, Microsoft and Quantinuum ran 14,000 experiments on the H2 computer without a single error [SRC_159].

 

Competitors are closing the gap. IonQ’s EQC prototypes reached 99.99% two-qubit gate fidelity in October 2025 [SRC_156]. Superconducting systems from IBM, Google, and IQM now reach 99.5% to 99.91% on production hardware [SRC_157] [SRC_158].

 

Yet Quantinuum’s R&D spending is aggressive. It invested $165.4 million and $122M FYE Dec 31, 2025 and FYE Dec 31, 2024 , more than five times its sales [SRC_153]. Its intellectual property capability exceeds the emerging computing sector average by over 20% [SRC_154].

 

Strategic partnerships anchor the customer base. JPMorgan Chase, Amgen, and Nvidia were pre-IPO backers [SRC_326]. In Japan, Nippon Steel Corporation and JSR Corporation are major customers [SRC_161]. In August 2026, Quantinuum announced a multi-year deal with Oracle [SRC_162]. The deal will deploy its Helios quantum computer on Oracle Cloud Infrastructure [SRC_162]. It also formed a collaboration with HPE to combine quantum computing with high-performance computing and AI environments [SRC_163].

 

FINANCIAL PROFILE

 

Metric Value Notes
Market Cap $1,811,000,000 Sep 14 2026
TEV $2,330,000,000 Sep 14, 2026
Annual Revenue $22,970,000 LTM Jun 30, 2026
Gross Margin N/A N/A
EV / Revenue 101x Per above

 

Revenue is growing —279% year-over-year in Q2 2026 [SRC_127]. Yet losses dwarf sales. The company lost $597 million in a single quarter against $8 million in revenue [SRC_127] [SRC_130]. Investors are betting on future breakthroughs, not current profits.

 

16

 

 

STRATEGIC POSITIONING AND COMPETITIVE LANDSCAPE

 

Quantinuum holds a strong position in trapped-ion quantum computing.

 

Its fidelity records, patent portfolio, and Honeywell backing create barriers to entry. The global quantum computing market is expanding at over 30% CAGR [SRC_152]. It may reach multiple billions by the early 2030s [SRC_152]. That growth could favor hardware leaders.

 

There is no assurance that fault-tolerant computing will arrive on schedule. There is also no assurance that customers will pay premium prices when it does.

 

LESSONS FOR NAORIS QUANTUM PROTOCOL

 

Corporate parentage creates credibility. Honeywell’s backing gave Quantinuum access to manufacturing, capital, and enterprise customers. Naoris may benefit from strategic partnerships with established technology or defense firms.

 

Hardware leadership supports software investment. Quantinuum sells cloud access and software on top of its machines. Naoris could position its post-quantum cryptography tools as the software layer for emerging quantum platforms.

 

R&D intensity signals commitment. Quantinuum spends over five times its revenue on R&D [SRC_153]. Investors in deep-tech expect heavy investment before profitability.

 

Government funding validates technology. A $100 million CHIPS Act LOI grant boosted Quantinuum’s credibility [SRC_327]. Naoris should pursue government grants and defense contracts to signal institutional trust.
   
Enterprise customers may lower the risk of the business. JPMorgan Chase, Amgen, and Nvidia backed Quantinuum before its IPO [SRC_164]. Signing marquee customers early helps attract public-market investors.
   
Timelines matter. Quantinuum’s 2029 fault-tolerance target anchors its story [SRC_328]. Naoris should set clear, measurable milestones for post-quantum deployment aligned with NIST standards and CNSA 2.0 deadlines.

 

QuintessenceLabs

 

COMPANY OVERVIEW AND HISTORICAL EVOLUTION

 

QuintessenceLabs was founded in 2008 by Dr. Vikram Sharma [SRC_293]. He built on research on quantum technology at The Australian National University [SRC_293]. It was Australia’s first quantum technology company [SRC_296]. The company is headquartered in Canberra, Australia, with offices in San Jose, California [SRC_295]. It opened its U.S. office in 2013 with an initial team of three people [SRC_267].

 

17

 

 

The company has built a focused position in quantum-enhanced cybersecurity.

 

It serves international organizations in the public sector, military, and critical infrastructure [SRC_272]. Its clients include JPMorgan Chase, the U.S. Department of Homeland Security, and DARPA [Updated Source]. QuintessenceLabs also partners with government entities, major banks, enterprise software companies, and defense leaders [SRC_283]. The company was selected as a World Economic Forum Technology Pioneer and a Westpac top 20 “Business of Tomorrow” [SRC_281].

 

QuintessenceLabs has attracted significant investor interest over nearly two decades.

 

Westpac Group extended funding rounds in 2015 and 2017 [SRC_294]. More recent investors include Main Sequence, TELUS Ventures, InterValley Ventures (backed by Japan’s Mizuho Financial Group),In-Q-Tel and Chevron Technology Ventures [SRC_247] [SRC_292] [SRC_299][SRC_329]. The Australian government invested $15 million AUD (approximately $9.4 million) from the $15 billion National Reconstruction Fund in March 2025 [SRC_290]. This investment led a $20 million AUD (approximately $12.5 million) round [SRC_290].

 

TECHNOLOGY AND PRODUCT PORTFOLIO

 

QuintessenceLabs’ flagship product is the Trusted Security Foundation (TSF). TSF is a quantum-safe key and policy management platform [SRC_273]. The company also offers Quantum Key Generation, Quantum Entropy Injector, Key Management as a Service, and Professional Services [SRC_273]. These products help organizations manage cryptographic keys. They also protect sensitive data against both current and future quantum threats.

 

The company is known for producing the world’s fastest quantum random number generators (QRNGs) [SRC_281].

 

In 2022, QuintessenceLabs launched qOptica, a quantum key distribution (QKD) technology [SRC_276]. qOptica uses continuous-variable QKD (CV-QKD) [SRC_276]. This approach was proven information-theoretically secure in 2009 [SRC_277]. It distributes cryptographic keys over optical links with security guaranteed by the laws of physics. However, no security system is completely foolproof, and risks remain.

 

QuintessenceLabs has partnered with technology leaders including Cisco and IBM [SRC_274]. In November 2024, the company announced a partnership with Equinix to deploy its TSF appliance within Equinix data centers [SRC_280]. In April 2024, QuintessenceLabs partnered with Carahsoft Technology Corp [SRC_284]. Carahsoft now serves as its Public Sector distributor [SRC_284]. Solutions are available through NASA SEWP V, ITES-SW2, and NASPO ValuePoint government procurement contracts [SRC_285] [SRC_289].

 

The company also made the approved products list for a $2 billion U.S. Department of Homeland Security program focused on data protection [SRC_266].

 

18

 

 

FINANCIAL PROFILE

 

Metric Value Notes
Current Valuation Unknown Private company
Estimated Revenue $9,100,000 - $12,600,000 [SRC_257] [SRC_256]

 

QuintessenceLabs has raised approximately $52.7 million across eight funding rounds since 2012 [SRC_330].

 

Revenue estimates range from $9.1 million to $12.6 million annually [SRC_257] [SRC_256]. These figures suggest the company generates meaningful commercial revenue but remains in a growth investment phase. The company holds an 11.8% share of the global quantum random number generator market [SRC_278]. It ranks second, behind only ID Quantique at 13.2% [SRC_278].

 

STRATEGIC POSITIONING AND COMPETITIVE LANDSCAPE

 

The company’s competitive moat rests on three pillars.

 

First, it has deep technical expertise in both QKD and QRNG technologies. Second, it has built distribution through government procurement channels via Carahsoft [SRC_284]. Third, it has earned trust with high-value customers including JPMorgan Chase and U.S. defense agencies [SRC_291].

 

Key risks include the capital-intensive nature of hardware development.

 

Enterprise quantum adoption is moving slowly. Only 5% of enterprises have deployed quantum-safe encryption so far. The company’s recent 6% headcount reduction may signal cash management priorities [SRC_258].

 

LESSONS FOR NAORIS QUANTUM PROTOCOL

 

Government channels matter. QuintessenceLabs’ partnership with Carahsoft opened access to NASA SEWP V, ITES-SW2, and NASPO ValuePoint contracts [SRC_285]. Government and defense account for 30% of the post-quantum cryptography market. Early certification on approved products lists can unlock large-scale contracts.[SRC_331]

 

Anchor customers build credibility. Landing JPMorgan Chase, DHS, and DARPA provided proof points that sped up trust with other buyers [SRC_291]. Naoris should prioritize a few reference customers that signal enterprise-grade readiness.

 

Hardware and software together strengthen positioning. QuintessenceLabs offers both QRNG hardware and the TSF software platform [SRC_273]. This combination creates a more defensible product offering than pure-play software or hardware alone.

 

19

 

 

Strategic investor alignment extends reach. Backing from In-Q-Tel (U.S. intelligence community) and Chevron Technology Ventures signals credibility to different buyer segments [Updated Source] [SRC_299]. Investors can open doors beyond just capital.
   
Real-world tests prove viability. The company deployed a 12.7 km quantum-secure link with CSIRO and AARNet [SRC_297] [SRC_298]. It ran the technology in live conditions [SRC_297] [SRC_298]. Pilots and proofs-of-concept reduce buyer hesitation.

 

Data center partnerships scale distribution. The Equinix partnership embeds QuintessenceLabs’ TSF appliance directly into major data center infrastructure [SRC_280]. This model could speed adoption without requiring direct enterprise sales.

 

Patient capital is required. Quantum security companies need investors who accept long development cycles before mass-market adoption arrives.

 

SECTION 5: CROSS-COMPARABLE SYNTHESIS

 

Structural Themes Across Comparables

 

Five patterns emerge from the comparable analysis. They reveal how public markets evaluate quantum-security businesses.

 

Theme 1: Government contracts provide revenue floors but constrain margins.

 

Defense and government buyers offer predictable demand. Federal mandates force procurement on fixed timelines. But government contracts carry reporting burdens. They impose security requirements and pricing pressure. The comparables that scaled fastest combined government anchor contracts with commercial expansion. Those that relied exclusively on government revenue struggled with margin compression.

 

Theme 2: Recurring revenue commands premium valuations.

 

Public markets distinguish between project-based and subscription models. Annual recurring revenue (ARR) — predictable payments for ongoing service — receives higher multiples than one-time license fees or hardware sales. The comparables with software-as-a-service delivery traded at sustained premiums. This held even during broader market corrections.

 

Theme 3: Distribution partnerships accelerate adoption but share economics.

 

Enterprise security is sold, not bought. Building direct sales teams takes time and capital. Partnerships with system integrators, cloud providers, and channel resellers accelerate market access. But partnerships dilute margins. The comparables that succeeded found the balance. They secured enough partnership to scale. They kept enough direct relationships to maintain pricing power.

 

20

 

 

Theme 4: Technical differentiation erodes without continuous investment.

 

Cryptographic standards evolve. Attack surfaces shift. Competitors iterate. The comparables that maintained valuation premiums invested heavily in R&D. They did this even when profitability was not yet achieved. Those that cut research spending to meet short-term targets lost competitive position.

 

Theme 5: Capital efficiency matters more than capital access.

 

Every comparable raised significant funding. Access to capital was not the differentiator. Deployment of capital was. The winners converted investment into revenue with lower burn rates and faster payback periods.

 

What Public Markets Reward

 

Public markets in post-quantum security reward three characteristics consistently.

 

Proof of deployment. Contract announcements generate headlines. Customer logos generate confidence. But production deployments — systems running in live environments — generate sustained valuation. Markets have learned to discount announcements without follow-through.

 

Path to profitability. Growth-at-any-cost worked in 2021. It does not work now. The comparables that maintained valuation through 2022-2024 showed credible paths to positive cash flow. They did not need to be profitable. They needed a visible trajectory.

 

Regulatory alignment. The companies that anticipated NIST standards, positioned for federal mandates, and achieved compliance certifications outperformed those that chased commercial markets alone. Regulation creates forced demand. Forced demand is more valuable than discretionary demand.

 

Implications for Long-Term Value Creation for Naoris Quantum Protocol

 

Naoris sits at the early stage of the comparable lifecycle. Valuation frameworks applicable to mature companies may not apply directly. However, the structural themes suggest what Naoris must demonstrate to achieve premium valuations.

 

Naoris needs production deployments at scale, not just testnet transactions. It needs a recurring revenue model with visible ARR growth. It needs government anchor contracts combined with commercial pipeline. It needs R&D investment that maintains technical differentiation. It needs capital efficiency that shows responsible deployment of investor funds.

 

The comparables provide a map. Execution determines whether Naoris follows the successful paths or the cautionary ones.

 

21

 

 

SECTION 6: MARKET VALUATION CONTEXT

 

How Public Markets Value These Businesses

 

Post-quantum cybersecurity companies trade on multiple valuation frameworks. The framework used depends on the maturity stage and revenue model.

 

EV/Revenue (Enterprise Value to Revenue) — what the whole company is worth compared with a year of sales — is the primary metric for high-growth, pre-profitable companies. It captures market expectations for future scale. Early-stage quantum companies often trade at extreme multiples. Arqit Quantum Inc. (ARQQ) per above had an EV/Revenue multiple of 668x fiscal 2025 revenue. That reflects speculative premium, not operational fundamentals.

 

EV/EBITDA (Enterprise Value to Earnings Before Interest, Taxes, Depreciation, and Amortization) applies to companies with positive operating income. Most pure-play quantum-security companies are not yet EBITDA-positive. This metric becomes relevant as companies mature.

 

FCF Yield (Free Cash Flow Yield) measures cash generation relative to market value. Positive FCF yield indicates self-funding capability. Negative FCF yield indicates continued capital requirements. The comparables split on this metric. Scaled players like Cloudflare show improving FCF. Early-stage players burn cash.

 

ROIC (Return on Invested Capital) measures how efficiently companies convert investment into returns. The long development cycles in quantum security mean ROIC remains negative for years. Investors accept this if the market opportunity justifies the investment horizon.

 

Valuation Ranges Across Comparables

 

Company Type EV/Revenue EV/EBITDA FCF Yield Notes
Arqit Quantum (ARQQ) Public 668x Negative EBITDA Negative Early-stage quantum encryption
Cloudflare (NET) Public 46x Fluctuates significantly Improving toward positive Scaled network security platform
Quantinuum (QNT) Public 452x Negative EBITDA Negative Quantum computing with crypto applications
QuintessenceLabs Private N/A (private) N/A N/A Valuation set by private rounds

 

The table reveals wide dispersion. Public quantum-security companies trade at multiples that reflect both genuine opportunity and speculative excess. Private market valuations appear more disciplined. Another company in the quantum market, SandboxAQ, achieved a $5.3 billion valuation on over $1.4 billion raised [SRC_061], implying meaningful revenue expectations.

 

22

 

 

Implications for Naoris Quantum Protocol

 

Naoris faces a valuation paradox. Public comparables suggest high multiples are achievable . But those multiples reflect small revenue bases . They also reflect speculative positioning]. They may not persist as the market matures.

 

The more realistic framework comes from later-stage private companies. SandboxAQ’s $5.3 billion valuation at its 2025 Series E [SRC_061] at a $5.3 billion pre-money valuation provides a ceiling. That ceiling applies to well-capitalized, well-positioned private companies. Zero Networks’ valuation path shows how revenue growth unlocks capital access. The company raised $45 million through Series B [SRC_083]. It then raised over $100 million through Series C [SRC_085].

 

For Naoris, valuation will depend on one thing: converting testnet activity into production revenue. The network has logged 64 million transactions [SRC_042]. That demonstrates technical capability. Commercial contracts will determine whether that capability translates to enterprise value.

 

SECTION 7: RECENT TRANSACTIONS AND MARKET ACTIVITY

 

Overview of Transaction Activity

 

The post-quantum cryptography sector has seen deal activity accelerate over the past two to three years. Capital has flowed from multiple directions. Strategic acquirers have participated. So have private equity, venture capital, and sovereign wealth funds.

 

In 2024, cybersecurity funding rounds decreased in volume by 13% from 2023 [SRC_048]. But funding dollars increased 4% [SRC_048]. M&A deal volume rose 5% [SRC_048]. Transaction dollars rose 13% [SRC_048]. The shift toward larger deals reflects market consolidation. Buyers are paying premiums for proven platforms. They are less interested in seed-stage bets.

 

In 2025, 426 cybersecurity M&A deals were announced [SRC_049]. Of those, 74 deals disclosed financial details [SRC_049]. Total disclosed value reached $92.5 billion [SRC_049]. This included 63 pure-play cybersecurity deals valued at $84 billion [SRC_049]. The headline numbers reflect mega-deals in adjacent categories. Pure-play post-quantum transactions remain smaller but growing.

 

Buyer categories have diversified. Strategic acquirers — IonQ, IBM, large defense contractors — are consolidating capabilities. Private equity firms are taking public companies private to accelerate restructuring. Venture capital continues funding early-stage pure-plays. Government-backed funds are making direct investments, particularly from Japan, Spain, and Korea.

 

23

 

 

Notable Transactions Table

 

Date Transaction Size Multiple Strategic Rationale
June 2025 IonQ acquires Oxford Ionics ~$1.075B [SRC_058] Not disclosed Consolidate trapped-ion quantum technology
Feb 2025 IonQ acquires majority stake in ID Quantique Not disclosed Not disclosed Add quantum-safe encryption to portfolio [SRC_059]
Jan 2025 IonQ acquires Qubitekk Not disclosed Not disclosed Enable quantum networking capabilities [SRC_060]
2025 SandboxAQ Series E $450M [SRC_061] ~3.7x implied Pre-IPO positioning, FedRAMP certification
Feb 2025 QuSecure Series A extension Part of $28M total [SRC_090] Not disclosed Led by Two Bear Capital, Accenture Ventures [SRC_091]
Dec 2025 BTQ Technologies invests in Keypair Not disclosed Not disclosed Co-own PQC IP for Korean infrastructure [SRC_063]
2024 Haveli takes ZeroFox private $350M [SRC_044] Not disclosed Restructuring for growth
2023-2025 Zero Networks Series B & C $75M combined [SRC_083][SRC_085] Revenue-linked 300%+ revenue growth between rounds [SRC_086]
May 2026 Quantum Bridge Technologies Series A $8M [SRC_088] Not disclosed Quantum-safe key distribution

 

Valuation Signals from Transactions

 

Private transaction multiples reveal market expectations. Public trading does not always capture those expectations.

 

SandboxAQ’s $5.3 billion valuation at its 2025 Series E [SRC_061] represents the high-water mark for pure-play post-quantum companies. The implied multiple on estimated revenue suggests something. Investors expect rapid scaling. The company’s five-year U.S. Department of Defense contract for PQC migration [SRC_333] provides revenue visibility.

 

IonQ’s acquisition spree tells a different story. The company is paying premium valuations. It paid $1.075 billion for Oxford Ionics alone [SRC_058]. The goal is to consolidate quantum technology capabilities. It acquired Qubitekk for quantum networking [SRC_060]. It bought a majority stake in ID Quantique for quantum-safe encryption [SRC_059]. The strategy is clear: build a full-stack quantum company through acquisition.

 

Zero Networks’ funding path shows how revenue growth unlocks capital. The company raised $20 million in Series B following a five-fold increase in revenue [SRC_083]. It raised $55 million in Series C after tripling its customer base [SRC_085]. Revenue grew by more than 300% between rounds [SRC_086]. Total funding exceeded $100 million [SRC_085]. The valuation premium tracked execution, not promises.

 

Private transaction multiples appear to run 20-40% below public market comparables for similar-stage companies. This may reflect liquidity discounts. It may also reflect more disciplined private-market pricing. Either way, it suggests something. Public-market multiples may compress as more companies reach scale.

 

24

 

 

Implications for Naoris Quantum Protocol

 

The data shows strong demand for post-quantum security assets.

 

Strategic buyers are acquiring aggressively. IonQ alone has made three significant acquisitions in 2025. Venture capital continues flowing to companies with proven technology and customer traction.

 

Naoris fits the profile that may attract capital. It has production-tested technology [SRC_042]. It combines post-quantum cryptography with distributed validation, which differentiates it from competitors. However, no assurance can be given that these factors will lead to successful capital attraction.

 

SECTION 8: CHALLENGES AND RISK FACTORS

 

Risk Category 1: Technology Commoditization

 

NIST has standardized post-quantum algorithms [SRC_012]. Standardization enables adoption. It also enables competition. Any vendor can implement FIPS 203, 204, and 205. The cryptographic algorithms themselves are not proprietary.

 

Arqit faced this risk directly. Its early positioning around proprietary quantum key distribution gave way to market pressure for NIST-compliant approaches. Companies that rely solely on algorithm implementation will see margins compress as the technology becomes a commodity.

 

Naoris’ distributed validation architecture may provide differentiation beyond basic cryptography. No assurance can be given that this differentiation will persist as competitors iterate.

 

Risk Category 2: Sales Cycle Length and Customer Concentration

 

Enterprise security purchases involve long evaluation periods, multiple stakeholders, and procurement bureaucracy. Government contracts add security clearances, compliance audits, and budget cycles.

 

The comparables show customer concentration risk. Early-stage quantum companies often depend on a small number of large contracts. Losing a single customer can materially impact revenue. Quantinuum’s government relationships provide stability but create concentration. [SRC_334]SandboxAQ’s recent customer wins across Dow Chemical, Mayo Clinic, and Bahrain government entities [SRC_071] show the diversification needed to reduce this risk.

 

Naoris must show it can convert testnet activity into paying enterprise customers across multiple verticals.

 

Risk Category 3: Competition from Well-Capitalized Incumbents

 

SandboxAQ has raised over $1.4 billion at a $5.3 billion valuation [SRC_061]. It has a five-year Department of Defense contract [SRC_072]. It achieved FedRAMP Ready status in December 2025 [Updated Source ]. IBM offers Quantum Safe Migration Orchestrator, an AI-powered platform that prioritizes cryptographic risks and recommends remediation patterns [SRC_055].

 

25

 

 

These competitors have more capital, more customers, and more regulatory certifications than Naoris. They can outspend on sales, marketing, and R&D. They can undercut on price to win strategic accounts.

 

Naoris’ path to success likely requires one of two things. It must find market segments that larger players overlook. Or it must build capabilities that are genuinely difficult to replicate.

 

Risk Category 4: Regulatory Timing Mismatch

 

Federal mandates create forced demand. But the timeline stretches to 2030-2035 [SRC_016][SRC_019][SRC_020]. That creates a timing risk. Companies may ramp capacity expecting near-term procurement. They may then find that budgets slip or deadlines extend.

 

Cloudflare navigated this by building revenue across multiple use cases. It did not depend solely on security mandates. It offered performance, reliability, and developer tools alongside protection. That diversification provided resilience when any single demand driver slowed.

 

Naoris may need to identify use cases beyond compliance-driven adoption. That would help sustain growth through regulatory uncertainty.

 

Risk Category 5: Capital Requirements Before Profitability

 

The comparables uniformly required multiple funding rounds before achieving positive cash flow. Zero Networks raised over $100 million across three rounds [SRC_085]. SandboxAQ raised over $1.4 billion [SRC_061]. QuSecure has raised $28 million in its most recent Series A round. [SRC_090].

 

Access to that capital depends on continued execution and market conditions. Future funding may be unavailable if market sentiment toward quantum security cools. It may also be unavailable if Naoris fails to hit milestones. If funding is available, it may come in only at a dilutive risk to current shareholders.

 

SECTION 9: EMERGING TRENDS AND FUTURE OUTLOOK

 

Trend 1: Hybrid Classical-Quantum Security Architectures

 

The transition to post-quantum cryptography will not happen overnight.

 

Enterprises will run hybrid architectures for years. Classical encryption will continue protecting legacy systems. Post-quantum algorithms will secure new deployments. The two must interoperate.

 

Companies that enable smooth hybrid operation will capture enterprise budgets. However, there is a risk that these solutions may not be adopted as expected. Smooth operation means allowing phased migration without breaking existing systems.

 

The Cloud Security Alliance emphasizes that enterprise migration requires orchestration across thousands of systems and applications. Point solutions that address only new deployments will find a limited market.

 

Naoris’ distributed architecture may enable hybrid deployment by validating both classical and quantum-resistant communications within the same framework. This could provide competitive advantage during the multi-year transition period.

 

26

 

 

Trend 2: Hardware-Rooted Security

 

Software-only cryptography faces attack vectors that hardware can eliminate. Cryptographic keys stored in software can be extracted by memory attacks. Keys stored in hardware security modules resist such extraction.

 

BTQ Technologies’ strategic investment in Keypair focuses on hardware-based security technologies [SRC_063]. The investment targets post-quantum cryptography IP for Korean critical infrastructure. This signals market demand for hardware-rooted solutions, particularly in regulated sectors.

 

Naoris’ architecture relies on distributed validation across devices. Integration with hardware security modules could strengthen the security model and open additional market segments.

 

Trend 3: AI-Assisted Cryptographic Migration

 

Enterprises face enormous complexity in inventorying existing cryptographic assets and planning migration paths. IBM’s Quantum Safe Migration Orchestrator uses AI to prioritize cryptographic risks, map IT components, analyze constraints, and recommend remediation patterns [SRC_055].

 

AI-assisted tools reduce the professional services burden of migration. They enable smaller security teams to tackle enterprise-scale transitions. Companies that combine post-quantum cryptography with AI-powered deployment tools may achieve faster adoption cycles.

 

Naoris could explore AI integration to simplify deployment of its distributed validation network. Automated configuration, threat detection, and compliance reporting would reduce customer friction.

 

Trend 4: Asia-Pacific Acceleration

 

North America commanded 38% of 2024 post-quantum cryptography revenue [SRC_005]. But Asia-Pacific is forecast to grow at a 46.55% CAGR during 2025-2030 [SRC_005].

 

Japan announced $7.4 billion in government funding for quantum technology [SRC_051]. Korea released final post-quantum cryptography algorithms in January 2025 [Updated Source].

 

The geographic shift creates opportunity for companies with Asia-Pacific presence or partnerships. It also creates competitive pressure from regional players that understand local regulatory requirements and customer preferences.

 

Naoris’ global positioning will matter as the market’s center of gravity shifts.

 

27

 

 

SECTION 10: STRATEGIC POSITIONING OF NAORIS QUANTUM PROTOCOL

 

Where Naoris Fits in the Public-Market Landscape

 

Naoris operates below security tools, below cloud infrastructure and above hardware, providing a unified validation layer that enables provable trust and continuous protection across fragmented systems. It supports on-premise, sovereign cloud, hybrid and air-gapped deployment, with nodes remaining under the control of the organisation or the state — full data ownership, cryptographic audit trails, and operation under national governance frameworks.

 

It is building infrastructure — a validation layer that distributes trust across enterprise environments.

 

Relative to the comparables:

 

Arqit focuses on quantum-safe key distribution. Naoris addresses broader infrastructure validation beyond key exchange.

 

Cloudflare delivers network security at scale. Naoris could complement Cloudflare by adding quantum-resilient validation to Cloudflare’s existing architecture.

 

Quantinuum builds quantum computing hardware with cryptographic applications. Naoris assumes quantum computers will exist and focuses on enterprise defense.

 

QuintessenceLabs provides quantum key generation and management. Naoris’ distributed model differs from QuintessenceLabs’ centralized approach.

 

The positioning is neither purely upstream (building quantum hardware) nor purely downstream (selling point solutions). It sits in the infrastructure middle — enabling enterprises to become quantum-resilient without replacing their existing technology stacks.

 

Key Differentiators

 

Distributed validation architecture. Most cybersecurity products create single points of failure. Naoris eliminates them by distributing trust across every participating device. Compromise of any one component does not propagate.

 

NIST-standard post-quantum cryptography. The Company implements ML-DSA — FIPS 204, formerly CRYSTALS-Dilithium — at Dilithium-5, the highest parameter set NIST defines, and the level the NSA’s CNSA 2.0 specifies for National Security Systems. It is not betting on proprietary algorithms that may not survive standardisation [SRC_321] [SRC_322].

 

Production-scale validation. 105 million post-quantum transactions. 1 million security nodes. 586 million threats mitigated.

 

Combined zero-trust and post-quantum approach. Most companies address one threat or the other. Naoris’ architecture addresses both. The combined zero trust and post-quantum market could exceed $200 billion by 2035.

 

The strategic challenge is converting these differentiators into commercial contracts. Technical superiority does not guarantee market success. Naoris must execute on sales, partnerships, and customer success to realize its positioning advantage.

 

28

 

 

SECTION 11: CONCLUSION AND INVESTMENT CONSIDERATIONS

 

What the Comparables Collectively Reveal

 

Execution over narrative. Arqit’s stock price volatility shows that announcements without follow-through destroy value. Cloudflare’s sustained growth demonstrates that consistent execution builds durable premiums.

Public markets have learned to discount promises. They reward deployment metrics, customer retention, and revenue growth. Naoris’ testnet numbers are a start. Commercial contracts will determine whether the narrative becomes reality.

 

Government anchor contracts provide foundation. SandboxAQ’s five-year Department of Defense contract [SRC_072] provides revenue visibility that supports a $5.3 billion valuation. Quantinuum’s government relationships stabilize its business through quantum computing’s long development cycles.

 

Federal mandates create forced demand with predictable timing. Companies that secure government anchors early build sustainable competitive positions.

 

Strategic partnerships accelerate adoption. SandboxAQ’s customers include Dow Chemical and Mayo Clinic [SRC_071], won through strategic positioning. IBM’s Quantum Safe Migration Orchestrator uses IBM’s enterprise relationships [SRC_055].

Partnerships multiply sales capacity without proportional cost increases.

 

Revenue diversification enables survival. Cloudflare built multiple revenue streams: security, performance, developer tools. That diversification protected it when any single category slowed. The pure-play quantum companies face concentration risk.

 

Diversifying across government, enterprise, and geographic markets improves resilience. Single-customer or single-use-case dependence creates fragility.

 

Naoris Quantum Protocol’s Path Forward

 

The challenge is clear. Naoris operates in a market with proven demand but intense competition. The 5% enterprise adoption rate [SRC_013] means 95% of the market remains addressable. But it also means most enterprises are not yet buying.

 

29

 

 

The opportunity is equally clear. NIST standards are final [SRC_012]. The federal deadlines are now fixed by executive order: post-quantum key establishment by 31 December 2030, post-quantum digital signatures by 31 December 2031, and federal contractors on post-quantum FIPS by 31 December 2030. The United Kingdom is working to 2028, 2031 and 2035. The European Union requires member states to publish quantum-resistant roadmaps under NIS2. Against that calendar, Gartner puts information security spending at $248.9 billion in 2026 and $372.6 billion by 2030 — and eight categories are converging into the single trust infrastructure layer Naoris is built to be.

 

Three near-term priorities emerge from the comparable analysis.

First, convert testnet activity into signed commercial contracts with recognizable enterprise or government customers. Proof of deployment matters more than proof of technology.

 

Second, pursue government anchor contracts aligned with federal PQC mandates. The deadlines are fixed and the budgets are allocated.

 

Third, establish strategic partnerships with system integrators or cloud providers that multiply sales reach without proportional investment. The comparables that scaled fastest combined direct capability with channel leverage.

 

Investment Considerations

 

Naoris sits at an early stage relative to the public comparables.

Arqit and Quantinuum are publicly traded with established revenue bases. Cloudflare generates billions in annual revenue with improving profitability.

SandboxAQ has raised over $1.4 billion in total funding [SRC_061]. It trades in private markets at a $5.3 billion valuation [SRC_061].

 

Naoris has demonstrated production-scale technology [SRC_042]. However, it has not yet demonstrated commercial revenue at scale. The valuation appropriate for Naoris reflects this stage. It is later than seed-stage startups with only concepts. It is earlier than growth-stage companies with proven unit economics.

 

The comparable framework suggests that successful execution may generate substantial value creation. The risk framework suggests that execution failure could result in complete capital loss. Both outcomes remain possible.

 

This report is for informational purposes only and does not constitute investment advice or a recommendation to invest. Prospective investors should conduct their own due diligence and consult qualified financial and legal advisors before making any investment decision.

 

30

 

 

DISCLOSURE: All information contained in this communication should not be considered investment advice nor an offer to buy or sell securities, but for educational and informational purposes only. Investing in private or early-stage offerings (such as Reg A, Reg S, Reg D, or Reg CF) involves a high degree of risk. Securities sold through these offerings are not (most of the time) publicly traded and therefore illiquid. Additionally, investors will receive restricted stock that is subject to holding period requirements. Companies seeking capital through these offerings tend to be in earlier stages of development and have not yet been fully tested in the public marketplace. Investing in private or early-stage offerings requires a tolerance for high risk, low liquidity, and a long-term commitment. Investors must be able to afford to lose their entire investment. Such investment products are not FDIC insured, may lose value, and have no bank guarantee.

 

Summary of Risk Factors

 

The following risk factors, among others described more fully in the Offering Circular, should be considered carefully before investing:

 

Risks Related to the Company’s Business and Operations

 

  The Company is an early-stage company with a limited operating history, which makes it difficult to evaluate its prospects and increases the risk of your investment.

 

  The Company may not achieve profitability, which could cause the value of your investment to decline.

 

  The Company’s success depends on market acceptance of post-quantum security solutions, which is an emerging market that may develop more slowly than the Company anticipates.

 

  The Company faces long and unpredictable sales cycles, particularly with government and enterprise customers, which may cause its operating results to fluctuate significantly.

 

  The Company depends on the continued service of key personnel, including its founder and senior technical leadership, and the loss of any key personnel could adversely affect its business.

 

  The Company depends on third-party technology, cloud providers, and infrastructure partners, and any disruption in these relationships or services could adversely affect its platform and business.

 

  The Company’s product expansion strategy includes products that the Company currently considers sufficiently developed for customer or partner deployment discussions, including PetalVault, PQVPN by Naoris, and the Naoris Community Intelligence Layer; however, these products may not achieve market adoption, may require additional capital, personnel, customer-specific integrations, certifications, security reviews, independent audits, or regulatory approvals, and may divert resources from the Company’s core platform.

 

The Company holds a 49% minority interest in a Korean joint venture (the “Naoris Korea JV” or the “JV”) that it does not control, and the JV’s failure to commercialize the Company’s products, disputes with its JV partner, or adverse developments in the Korean market could result in impairment of its investment and harm its business and financial results.

 

31

 

 

Risks Related to the Company’s Technology and Products

 

  Post-quantum cryptographic standards are still evolving, and changes to these standards could require the Company to make significant modifications to its platform.

 

  The Company’s products are complex, and defects, errors, or vulnerabilities could harm its reputation and adversely affect its business.

 

  The Company’s Distributed Proof of Security consensus mechanism and Trust Mesh architecture may face scalability, reliability, and interoperability challenges.

 

  The Company’s platform may be the target of cyberattacks, and any security breach could severely damage its reputation and business.

 

  PetalVault, PQVPN by Naoris, and the Naoris Community Intelligence Layer are complex product initiatives built on Naoris infrastructure, and failures in security, scalability, usability, data integrity, AI output quality, or integration may adversely affect the Company’s business.

 

  PetalVault depends on third-party blockchain infrastructure, cryptographic standards, Bitcoin transaction policies, and Bitcoin-related legal and market developments that the Company does not control.

 

  PQVPN by Naoris involves secure routing, node attestation, and data-in-transit services, and may expose the Company to performance, privacy, availability, lawful access, and cross-jurisdictional routing risks.

 

  The Naoris Community Intelligence Layer involves permissioned AI identities, community interaction data, digital identity, creator and brand rights, consent-based analytics, cross-platform communications, and monetization workflows, and may create risks involving privacy, publicity rights, intellectual property, consumer protection, AI governance, data protection, transparency, and platform governance.

 

Risks Related to the Company’s Market and Competition

 

  The market for cybersecurity solutions is intensely competitive, and the Company competes with well-capitalized incumbents that have significantly greater resources than it does.

 

  Larger competitors and technology companies may develop competing post-quantum security solutions that could reduce demand for the Company’s platform.

 

  The post-quantum cryptography market may develop more slowly than anticipated, and the timing of the Company’s market opportunity is uncertain.

 

  The Company may face customer concentration risks, with a limited number of customers accounting for a significant portion of its revenue.

 

32

 

 

Risks Related to Government Regulation and Compliance

 

  The Company operates in a complex and evolving regulatory landscape, and compliance with multiple regulatory frameworks across jurisdictions is costly and challenging.

 

  Changes in post-quantum cryptography mandates across jurisdictions could adversely affect the Company’s business.

 

  The Company’s products may be subject to export control and sanctions regulations that could restrict its ability to sell internationally.

 

  The Company’s platform’s use of blockchain and digital asset-related technology may subject it to evolving and uncertain regulatory requirements.

 

  The Company’s application-layer products may be subject to evolving regulation relating to digital assets, AI, privacy, biometrics and voice data, consumer protection, communications services, encryption, export controls, sanctions, and data localization.

 

Risks Related to Intellectual Property

 

  The Company’s ability to protect its proprietary technology, including its Distributed Proof of Security consensus mechanism and Trust Mesh architecture, is critical to its competitive position.

 

  The Company’s reliance on NIST-standardized cryptographic algorithms that are publicly available may limit its ability to differentiate its platform from competitors.

 

  The Company may be subject to intellectual property infringement claims by third parties, which could be costly and disruptive to its business.

 

  The Company’s ability to obtain, maintain, and enforce rights in product names, software modules, AI models and prompts, data workflows, brands, and digital persona licenses may be limited.

 

Risks Related to Financial Condition and Capital Requirements

 

  The Company will need to raise additional capital to fund its operations and growth, and such capital may not be available on favorable terms or at all.

 

  The Company is dependent on the proceeds from this offering, and a shortfall in proceeds could adversely affect its ability to execute its business plan.

 

33

 

 

Risks Related to This Offering and the Company’s Securities

 

  This is a Regulation A offering, and the Company will have limited reporting obligations compared to companies that conduct registered offerings under the Securities Act.

 

  The Company’s founder and Chief Executive Officer will control approximately 91% of the total voting power of its capital stock following this Offering, and will therefore be able to control all matters submitted to stockholders for approval.

  

  There is no public market for the Company’s securities, and investors may not be able to sell their securities when they want or at a price that is acceptable to them.

 

  Investors will experience immediate and substantial dilution as a result of this offering.

 

  The Company may conduct future capital raises that could result in additional dilution to investors in this offering.

 

  The Company will have broad discretion over the use of proceeds from this offering, and investors may not agree with how the Company spends the proceeds.

 

  Listing the Company’s securities on the Nasdaq Capital Market will increase its regulatory burden.

 

  The Nasdaq Capital Market may delist the Company’s securities, which could limit investors’ ability to engage in transactions in the Company’s shares and subject it to additional trading restrictions.

 

  The Company will incur increased costs as a result of operating as a public company and will be required to devote substantial time to new compliance initiatives.

 

  The Company may issue additional securities or other equity securities without shareholder approval, which would dilute the ownership interests of existing shareholders in the Company and may depress the market price of its shares.

 

  The Company’s ability to meet expectations and projections in any research or reports published by securities or industry analysts, or a lack of coverage by securities or industry analysts, could result in a depressed market price and limited liquidity for its securities.

 

34

 

 

  The Company may be required to take write-downs or write-offs, restructuring and impairment or other charges that could have a significant negative effect on its financial condition, results of operations and share price, which could cause investors to lose some or all of their investment.

 

  The Company does not intend to pay dividends for the foreseeable future.

 

  This Offering is being conducted on a “best efforts” basis and the Company may not be able to execute its growth strategy if the maximum offering amount is not sold.

 

  This is a fixed price offering and the fixed offering price may not accurately represent the current value of the Company or its assets at any particular time. Therefore, the purchase price paid for the Company’s shares may not be supported by the value of its assets at the time of purchase.

 

  As the Company’s initial public offering price is substantially higher than its net tangible book value per share, investors will experience immediate and substantial dilution.

 

  The Company recently effected a reverse stock split of both classes of its common stock, which may not achieve its intended effect.

 

  Using a credit card to purchase shares may impact the return on an investor’s investment as well as subject the investor to other risks inherent in this form of payment.

 

  Forward-looking statements in this Offering Circular may not accurately predict the Company’s future performance, and actual results may differ materially from the Company’s projections.

 

35