Skip to main content
PROFITVISIONLAB
Equity Deep Research

NET vs ZS Head-to-Head: In the Age of AI Agents, Should You Back the Highway Builder or the Tollbooth Operator?

Cloudflare builds the highway, Zscaler runs the tollbooth. Which side should you back in the age of AI agents? MarketSurge live data, a nine-metric financial head-to-head, five-year scenario valuations, and a dual Four-Layer Defensive Screen evaluation. Both stocks carry an EPS Rating of 98 and an SMR of A — yet their P/S ratios differ by 4x.

NET vs ZS Head-to-Head: In the Age of AI Agents, Should You Back "the Company That Builds the Highway" or "the Company That Runs the Tollbooth"?
Cloudflare (NET)|NYSE|Connectivity Cloud + AI Agent Infrastructure
Zscaler (ZS)|Nasdaq|Zero Trust Security + AI Agent Governance

NET Price $184 (2026/04/14)|52-Week Range $100–$260|Market Cap ~$69B
ZS Price $122 (2026/04/14)|52-Week Range ~$95–$280|Market Cap ~$18B

Written: 2026/04/15|Data as of: NET Q4 FY2025 / ZS Q2 FY2026
ProfitVision LAB Single-Stock Research Series|Shiba the Disciplined

Introduction: One Highway, Two Toll-Collection Logics

Investors in 2026 face a question that looks simple but is actually decisive: as the age of Agentic AI moves into full swing, should you buy "the company that builds the highway," or "the company that sets up the tollbooth on that highway"?

Cloudflare is the highway builder. It has deployed nodes in 330 cities worldwide, giving AI agents somewhere to run, somewhere to compute, and somewhere to store data — what it sells is "the right to use the road." Zscaler is the tollbooth operator on that highway. It lets no traffic pass freely — every car, every passenger, every piece of cargo must be authenticated at its "sky checkpoint" — what it sells is "safe passage."

On the surface, both companies sit in "cloud security" and compete in the SASE (Secure Access Service Edge) race, and their share prices have been highly correlated over the past 12 months. But once you strip away the marketing language and dig into their technical architecture, revenue models, and AI strategy, you find a counterintuitive fact: NET and ZS have completely different DNA — they are betting on two entirely different structural theses for the AI era.

NET's bet is: AI agents need a native runtime environment, and Cloudflare's edge network is that environment.

ZS's bet is: the more numerous and autonomous AI agents become, the more rigid the need for governance and security becomes — and Zscaler is the only platform that can authenticate trillion-scale traffic at millisecond latency.

This report will not tell you "which one to buy" — it will use data and logic to let you arrive at your own answer.

I. The Underlying Logic: Two Companies With Completely Different DNA

1.1 Cloudflare: From CDN to "the Operating System of the Agentic Era"

Cloudflare was founded in 2009, originating from an open-source anti-spam project called "Project Honey Pot." Seventeen years later, CEO Matthew Prince redefined the company's evolutionary arc using an "acts of a play" framework: Act 1 was reverse proxy (WAF, DDoS protection), Act 2 was forward proxy (Zero Trust, SASE), Act 3 was the developer platform (Workers serverless computing), and Act 4 — happening right now — is infrastructure for the agentic internet.

In his opening essay for Agents Week in April 2026, Prince offered a precise analogy: Workers' V8 isolate architecture is like "giving every agent a knife, a stove, and just enough counter space," while a traditional container is like "giving every agent an entire commercial kitchen, even if all it wants to do is make a cup of coffee." That explains why Cloudflare's newly launched Dynamic Workers can spin up in milliseconds, execute AI-generated code, and vanish — 100 times faster than containers, at a fraction of the cost.

Cloudflare positions itself as a "Connectivity Cloud" — a neutral, global network fabric that frees customers from being locked into the closed ecosystems of AWS, Azure, or GCP. Its core architectural advantage is that every server can run every function — from security to AI inference. That lets it deliver sub-100ms latency to 95% of the world's connected population.

1.2 Zscaler: From VPN Replacement to "the Identity-Verification Hub of the AI Era"

Zscaler was founded by Jay Chaudhry in 2007. Chaudhry was born in a village without electricity at the foot of the Himalayas in India, made his way to the US on a scholarship, and had already sold four security companies in succession before founding Zscaler. In 2007 he saw something the industry wouldn't admit: the cloud was moving enterprise applications outside the castle walls. Spending money to reinforce the walls (firewalls, VPNs) amounted to guarding an empty city.

His answer was the "Zero Trust Exchange" — a cloud-based "checkpoint in the sky." All traffic — whether from human users, IoT devices, or now AI agents — must be authenticated before it is allowed to communicate. No trust, only verification.

At the Q2 FY2026 earnings call in February 2026, Chaudhry formally declared Zscaler "the security platform for the AI era" and appointed Dr. Swamy Kocherlakota as Executive Vice President of "Agentic AI Security Engineering" — a role designed specifically around securing AI agents. ZS also became an early partner for Microsoft Entra Agent ID, extending Zero Trust principles to "non-human identities."

DNA Differences at a Glance
DimensionNET (Cloudflare)ZS (Zscaler)
Founded20092007
OriginCDN + DDoS protectionCloud proxy (VPN replacement)
2026 PositioningConnectivity Cloud + AI Agent PlatformZero Trust Exchange + AI Security Platform
Core Selling PointHelps you run fast and cheapKeeps bad actors out, keeps data from leaking
Role in the AI EraThe agent's "runtime environment"The agent's "identity police"
Revenue ModelSubscription + usage-based billing (Workers AI, R2)Pure subscription (multi-year contracts)
CEO StyleMatthew Prince: product-obsessed, developer-community-orientedJay Chaudhry: sales machine, enterprise-relationship-oriented
Network Scale330+ cities, 13,000 interconnects150+ data centers

II. Financial Head-to-Head: Nine Key Metrics

Lay the two companies' latest earnings side by side and the numbers don't lie. Below is a direct comparison as of the most recently completed quarter (NET: Q4 CY2025 / ZS: Q2 FY2026, both through the end of January 2026).

Financial MetricNET (Cloudflare)ZS (Zscaler)Edge
Most Recent Quarterly Revenue $614.5M (+34% YoY) $815.8M (+26% YoY) ZS on size
NET on speed
Full-Year Revenue Guidance FY2026: $2.785–2.795B (+28-29%) FY2026: $3.309–3.322B (+24%) NET on speed
ARR / Subscription Visibility RPO $2.496B (+48% YoY) ARR $3.359B (+25% YoY)
RPO $6.051B (+31% YoY)
ZS on size
NET's RPO accelerating
Non-GAAP Gross Margin 74.9% 80.0% ZS
Non-GAAP Operating Margin 14.6% (Q4) / 14% full-year guidance 22.2% (Q2) ZS
GAAP Operating Profit Loss (-8% of revenue) Loss (SBC ~26.5%) — (both operate at a loss)
Free Cash Flow $99.4M (16% margin) $169.1M (21% margin) ZS
DBNRR / Net Retention Rate 120% (YoY +9pp) Approx. 115-120% (not separately disclosed by the company) NET accelerating
$100K+ Customers 4,298 (+23% YoY) 3,886 (+18% YoY) NET on pace
$1M+ Customers 269 (+55% YoY) 728 (+18% YoY) ZS on size
NET accelerating
Rule of 40 ~48 (34% growth + ~14% margin) ~62 (26% growth + 36% FCF margin, H1) ZS
Cash Position Not separately disclosed (has convertible notes maturing in 2026) $3.513B ZS
📊 Financial Head-to-Head Summary
ZS wins on "money already in hand" — higher gross margin, better operating leverage, a stronger Rule of 62 showing, and a $3.5B cash fortress.
NET wins on "acceleration" — a faster revenue growth rate (34% vs. 26%), DBNRR that has snapped back to 120% (a nine-percentage-point annual jump), a 55% surge in million-dollar customers, and 48% RPO growth — the strongest forward-looking indicator of the two.

In a sentence: ZS is "a better today," NET is "a faster-accelerating tomorrow."

III. The Age of AI Agents: Whose Positioning Is More Irreplaceable?

This is the most important chapter in this report. Agentic AI is not the future — it is already happening. As Anthropic announced Managed Agents in April 2026, OpenAI rolled out an enterprise version of Codex, and Microsoft rolled out its Copilot Agent ecosystem in full, a new question has surfaced: what infrastructure do these autonomously operating AI agents actually need?

3.1 Cloudflare: "I Am the Agent's Home"

Matthew Prince's declaration at Agents Week (April 13, 2026) was blunt: Cloudflare wants to become "the underlying operating system of the agentic internet."

Concretely, Agent Cloud provides an entire value chain from development to deployment:

Dynamic Workers — an ultra-lightweight runtime built on V8 isolates, where AI-generated code spins up, executes, and disappears within milliseconds. 100 times faster than traditional containers, supporting millions of concurrent executions.

Artifacts — a Git-compatible storage primitive designed for the agentic era. It supports the creation of tens of millions of repositories, giving agents a "permanent home" to store code and data.

Sandboxes (GA) — a full, isolated Linux environment where agents can clone repos, install Python packages, and run builds, just like human developers.

Think Framework — a persistent Agents SDK that lets agents support long-running tasks across sessions, rather than only responding to a single prompt.

Unified Model Catalog — after acquiring Replicate, developers can switch between OpenAI GPT-5.4, Anthropic Claude, and open-source models within a single interface by changing just one line of code.

OpenAI's head of Codex product, Rohan Varma, publicly endorsed Cloudflare — and that is no coincidental partnership. When the world's most capable AI lab chooses to run its agents on Cloudflare, it's worth thinking seriously about what that implies.

3.2 Zscaler: "I Decide What Agents Can and Can't Do"

Chaudhry's logic runs in the opposite direction: the more numerous and autonomous agents become, the more they need to be governed. At the Q2 earnings call he said it directly: "Our Zero Trust Exchange architecture is fundamentally different from a firewall — a firewall lets a user or an AI agent roam freely once it's on the network, which dramatically raises the risk of a breach."

ZS's AI security strategy runs along three lines:

AI Protect — real-time monitoring of enterprise AI application traffic, including prompt monitoring, data-loss prevention, and Shadow AI asset inventory. ThreatLabz's 2026 report found that the number of enterprise AI/ML applications surged to over 3,400 within a year, with sensitive data transmission volume up 93%. If you don't know how many people at your company are secretly using ChatGPT, or how much data is flowing to external models, you've already lost.

Agentic AI Security — a governance framework designed specifically for non-human identities. ZS integrates with Microsoft Entra Agent ID, applying Zero Trust verification to every AI agent — as strictly as it does for humans. Kocherlakota's new role leads this product line.

ZDX CoPilot — uses AI agents to automatically diagnose network and application performance problems. Over the past 12 months, ZDX Advanced Plus bookings surpassed $100M, growing over 80%.

The scale at which ZS processes AI traffic is a number that cannot easily be replicated: in all of 2025, it processed nearly one trillion AI transactions. That isn't just data volume — it's a threat-intelligence flywheel. Every intercepted attack, every new infiltration technique, trains ZS's models further, making the next interception more precise.

Core Comparison
What AI Agents NeedWhat NET ProvidesWhat ZS Provides
Runtime EnvironmentDynamic Workers + SandboxesNot provided (not NET's territory)
Model InferenceWorkers AI + Unified Model CatalogNot provided
Persistent StorageArtifacts, R2, Durable ObjectsNot provided
Identity VerificationCloudflare Access + Managed OAuthZero Trust Exchange (trillion-scale)
Traffic MonitoringAI Gateway (rate limiting, fallback)AI Protect + ThreatLabz (trained on one trillion data points)
Data-Loss PreventionBasic DLPEnterprise-grade DLP + Shadow AI inventory
Non-Human Identity GovernanceMCP security (announced at Agents Week)Microsoft Entra Agent ID integration
Compliance and RegulationBasicFull suite of FedRAMP, SOC 2, HIPAA
🎯 Conclusion on AI-Agent Positioning
NET and ZS are not fighting over the same spot — they occupy an upstream-downstream relationship in the AI agent value chain.

NET = "where" agents run (Infrastructure Layer)
ZS = "who" governs agents (Governance Layer)

The most likely enterprise-procurement outcome is: buy both. Deploy agents using Cloudflare's Agent Cloud, and manage their access permissions and data flows using Zscaler's Zero Trust Exchange.

IV. A Deep Cross-Comparison of Moats

A common mistake investors make is treating "moat" as a binary — you either have one or you don't. The genuinely useful analysis is: where is the moat deepest, and where is it most fragile?

4.1 Network Effects and Scale

NET: 330+ cities, 13,000 interconnects, a 4.5-million-developer ecosystem. The free tier is its most powerful acquisition mechanism — the natural upgrade path from free to paid to enterprise lowers customer-acquisition cost. DBNRR has snapped back to 120%, meaning existing customers are ramping spend faster. Million-dollar customers surged 55% for the full year, with 69 net adds — a single-quarter record.

ZS: 150+ data centers, processing more than 500 billion transactions per day, and nearly one trillion AI transactions across all of 2025. More than 45% of the Fortune 500 and roughly 40% of the Global 2000 are customers. 728 million-dollar ARR customers. More than 450 enterprises have gone Zero Trust Everywhere, three quarters ahead of schedule.

Verdict: NET's network is wider (330 vs. 150), ZS's security traffic runs deeper (500 billion transactions per day). The two moats are deep along different dimensions — NET is deep in developer stickiness, ZS is deep in threat-intelligence data volume.

4.2 Switching Costs

NET: Once an enterprise has deployed serverless applications on Workers, stored data in R2, and managed state with Durable Objects, moving away means rewriting the entire backend. As Agent Cloud deepens, switching costs will stack further. But NET's free tier also means the "trial" bar is extremely low — customers find it easy to come in, and, in theory, easy to leave (if they haven't gone deep).

ZS: The Zero Trust Exchange replaces an enterprise's entire network security architecture — VPN, firewall, SWG, all swapped out. Once deployed, ZS becomes the mandatory path for every packet of traffic. Moving away isn't just a technical cost — it's a compliance risk, and you'd have to explain to the CISO and the board why you're tearing down the security architecture and starting over.

Verdict: ZS has the higher switching cost. Replacing security architecture is more painful than migrating a developer platform — it involves compliance, audits, and organizational politics.

4.3 Data Flywheels

NET: observes more than 20% of global internet traffic every day and is one of the largest sources of DDoS attack intelligence. But NET's data flywheel is mainly used for "performance optimization" (routing, caching, latency minimization) — its depth on the security side doesn't match ZS's.

ZS: nearly one trillion AI transactions and 500 billion routine transactions a day, all of it security intelligence. Every interception trains the model further — attacker techniques, targets, timing patterns. This flywheel has been spinning for nearly 20 years, and no new entrant can replicate it.

Verdict: ZS's security-data flywheel is unmatched in depth. NET's traffic-data flywheel is stronger in breadth, but its security-intelligence density doesn't match ZS.

4.4 Brand and Mindshare

NET: mindshare in SASE is around 6.0-6.4%, but its mindshare within the developer community is extremely high. 100% of PeerSpot users say they'd recommend it. NET's brand is extremely strong on perceptions of being "fast, innovative, and developer-friendly."

ZS: SASE mindshare is around 9.1-9.7% — meaningfully higher than NET. In the minds of CISOs and enterprise security decision-makers, ZS is synonymous with Zero Trust. 98% of users say they'd recommend it. A regular in the Leaders quadrant of the Gartner SSE Magic Quadrant.

Verdict: ZS has stronger brand mindshare in enterprise security procurement. NET has a stronger brand among developers and technical decision-makers. Different audiences, different moats.

4.5 Overall Moat Scorecard

Moat DimensionNET RatingZS Rating
Network Scale★★★★★★★★☆☆
Developer Ecosystem★★★★★★☆☆☆☆
Switching Costs★★★☆☆★★★★★
Security Data Flywheel★★★☆☆★★★★★
Brand (Enterprise Security)★★☆☆☆★★★★★
Brand (Developers)★★★★★★★☆☆☆
TAM Expansion Potential★★★★★★★★★☆
OverallDeep moat (wide type)Deep moat (deep type)
NET's moat is like the Amazon River — extremely wide, with countless tributaries (CDN + security + compute + storage + AI inference) — but not every tributary is necessarily the deepest.
ZS's moat is like the Mariana Trench — not nearly as wide (focused solely on security) — but in its core territory, it runs so deep competitors can't see the bottom.

V. Crossfire: Are They Really Fighting Over the Same Market?

5.1 The SASE Overlap: Real, But Overstated

On the surface, NET and ZS have clear product overlap in SASE: Cloudflare One (ZT Access + Gateway + Browser Isolation) goes head-to-head with Zscaler's ZIA + ZPA. In October 2025, Cloudflare even published a 37-feature comparison document claiming it had "surpassed Zscaler" in overall feature completeness within four years.

But the data reveals the truth: Cloudflare's security revenue is about 30-35% of the total (Act 2), while Zscaler's is 100%. NET's SASE business is more of a natural upsell from its CDN customer base rather than a direct raid on ZS's large enterprise accounts. In terms of deep penetration into the Fortune 500, ZS (45%+) far exceeds NET.

Cloudflare's SASE advantage lies in simpler deployment, lower cost, and a unified management console. Zscaler's advantage lies in the depth of its security features, the completeness of its compliance certifications, and its trust foundation with large enterprises. The two attract different buyers — NET attracts "enterprises already using Cloudflare's CDN who add security on top," while ZS attracts "CISOs for whom security is the primary requirement."

5.2 The Real Threat Isn't Each Other

For NET, the biggest threat is the edge services of the hyperscalers — AWS, Azure, GCP (Lambda@Edge, Cloudfront Functions, Azure Edge Zones). If the hyperscalers commit seriously to edge AI inference and cut prices aggressively, NET's differentiation could get squeezed.

For ZS, the biggest threat is Palo Alto Networks' (PANW) "platformization dumping" strategy — giving away SASE tools for free in exchange for customers abandoning other vendors — plus the possibility of CrowdStrike extending into network security.

The competition between NET and ZS looks more like "accidental overlap" than "head-on collision." If you're a CISO, you wouldn't skip buying Zscaler just because Cloudflare has Zero Trust — any more than you'd skip buying Cloudflare because AWS has a WAF.

5.2.1 The Competitive Triangle: NET × ZS × PANW × CRWD

You can't just look at these two companies head-to-head. Bringing Palo Alto Networks (PANW) and CrowdStrike (CRWD) into the picture is necessary to see the full competitive dynamic:

CapabilityNETZSPANWCRWD
Zero Trust / SASE 🟡 Act 2, catching up 🟢 Core business, 20 years deep 🟡 Prisma SASE, firewall pivot 🔴 Not core
Endpoint Security (EDR/XDR) 🔴 Doesn't do this 🔴 Entering via Red Canary 🟡 Cortex XDR 🟢 Falcon platform, #1 in the industry
AI Inference / Edge Computing 🟢 Workers AI + Agent Cloud 🔴 Doesn't do this 🔴 Doesn't do this 🔴 Doesn't do this
AI Agent Security Governance 🟡 MCP security, Managed OAuth 🟢 Entra Agent ID, AI Protect 🟡 Still building out 🟡 Charlotte AI
DDoS / CDN 🟢 One of the largest globally 🔴 Not offered 🔴 Doesn't do this 🔴 Doesn't do this
Developer Platform 🟢 4.5 million developers 🔴 None 🔴 None 🔴 Minimal
Platformization / Bundling 🟡 Natural upsell 🟡 ZFlex flexible plans 🟢 Free SASE for lock-in (platformization dumping) 🟡 Modular expansion
Fortune 500 Penetration 🟡 Moderate 🟢 >45% 🟢 Very high 🟢 Very high

A few key observations:

First, NET has almost no rival in AI inference / edge computing. PANW, CRWD, and ZS none of them touch this space. NET's Agent Cloud is an exclusive position — among security companies, no one else offers a one-stop platform combining "a runtime environment for agents + inference services + storage + security." This is the core logic behind NET's valuation premium.

Second, PANW is ZS's biggest near-term threat. Nikesh Arora's "platformization dumping" — giving away SASE tools for free in exchange for full customer lock-in — is a highly effective sales strategy. Chaudhry has repeatedly emphasized on earnings calls that "we win the vast majority of head-to-head Zero Trust competitions," but PANW's strategy isn't to out-feature ZS — it's to fight a war of attrition on price. ZS's 22% non-GAAP operating margin gives it some room to cut prices, but if PANW's free-tools strategy persists for more than three years, ZS's new-customer acquisition rate could be systematically suppressed.

Third, CRWD is more complementary to ZS than competitive. CrowdStrike does endpoint security (Falcon), ZS does network security (Zero Trust Exchange). Large enterprises typically procure both, forming a dual layer of "endpoint + network" defense. Chaudhry has publicly called CRWD a partner on multiple occasions. But over the long run, if CRWD extends into network security (its Charlotte AI is already moving in that direction), the overlap could grow.

5.2.2 Comparing Management Quality: Prince vs. Chaudhry

Management quality is often the decisive variable in long-term investment returns. Below is a comparison of the two CEOs' track records:

DimensionMatthew Prince (NET)Jay Chaudhry (ZS)
Ownership Stake ~1% (co-founder, but heavily diluted) ~17% (largest single shareholder, very strong skin in the game)
Capital Allocation Conservative — almost no large acquisitions, prefers to build in-house (Replicate is a rare exception) Recently turned aggressive — Red Canary, SPLX, SquareX, totaling $692M
Vision vs. Execution Vision is extremely strong (Act 4's Agent Cloud positioned early), but AI inference revenue is materializing slowly Execution is extremely strong (AI Security ARR hit $400M three quarters ahead of schedule), but the vision is comparatively conservative
Earnings-Call Style Product-oriented, rich in technical detail, occasionally overly optimistic Numbers-oriented, tightly disciplined, carefully worded
Succession Risk Low — Prince is 51, co-founder Michelle Zatlyn is COO, a stable dual-core structure Medium-high — Chaudhry is 72; energetic, but age is an objective fact. No formal succession plan has been announced. CFO Kevin Rubin and the new CTO are potential candidates, but nothing is confirmed.
Crisis Response Excellent — the 2022 decision to cut off Kiwi Farms and similar controversial calls demonstrated decisiveness Excellent — rapidly scaled the sales team when Zero Trust demand exploded during COVID, seizing the window
👤 Management Comparison Summary
Chaudhry's 17% ownership stake is a rare high-water mark among SaaS CEOs market-wide — when the stock fell 38%, several billion dollars of his personal wealth evaporated. That level of aligned interest should reassure investors: he won't do anything that harms shareholders. But succession risk is a "gray rhino" that can't be ignored — a 72-year-old CEO needs a clear succession plan.

Prince's product instincts are one of NET's biggest competitive advantages. From Workers to Agent Cloud, he has kept positioning infrastructure ahead of market demand. But his 1% ownership stake means his interests aren't as tightly aligned as Chaudhry's — not a knock on his diligence, but an objective gap in incentive structure.

5.3 The Lesson From the Mythos Episode: What Did the Panic Actually Reveal?

On March 27, 2026, Anthropic was reported to be testing a frontier model called Claude Mythos, capable of autonomously discovering network vulnerabilities. On the news, security stocks fell an average of 5%. ZS, already down 38%, took a further hit. On April 7, Anthropic officially released Mythos Preview along with the Project Glasswing safety framework, triggering a broader SaaS sell-off.

The market's panic logic was: if an AI model can find vulnerabilities on its own, do you still need Zscaler?

That logic makes a fundamental error — equating "vulnerability discovery" with "security protection." Mythos is an X-ray machine — it can show you what's wrong inside your body. Zscaler is the emergency room — it saves you in real time when you're under attack. A stronger X-ray machine doesn't make the ER redundant — if anything, it means more people learn they need treatment, and demand for the ER only rises.

Broken down by product line:

Impact on ZS: neutral to slightly positive. Mythos finding more vulnerabilities means enterprises become more aware of the scale of their attack surface, accelerating Zero Trust deployment budgets. ZS's AI Protect — Shadow AI inventory, AI asset management, prompt monitoring — is precisely the answer to the risks Mythos exposes. More importantly, ZS's own ThreatLabz 2026 report had already revealed that enterprise AI/ML application count surged to over 3,400 within a year, sensitive data transmission rose 93%, and AI-driven attacks can go from discovery to lateral movement to data exfiltration in as little as 16 minutes. Mythos merely validated, in a more dramatic way, the story ZS was already telling.

Impact on NET: mildly negative, then quickly reversing to positive. NET's share price also got dragged down, but Cloudflare resolved it perfectly at Agents Week on April 13 — announcing Managed OAuth (letting AI agents securely browse internal applications), MCP security governance, Cloudflare Mesh (private network access for agents), and Shadow MCP detection rules. NET's message was clear: agents need tighter security? I'll provide the secure runtime environment for that — that's infrastructure's job.

The most important lesson from the Mythos episode isn't that some company will get wiped out — it's that: the TAM for AI security is being dramatically expanded. As AI models themselves become double-edged swords — both attack tool and defense tool — enterprise security spending can only go up. This is a structural tailwind for both NET and ZS — they simply benefit through different channels.

5.4 Comparing TAM: Whose Ceiling Is Higher?

TAM (Total Addressable Market) is the anchor for growth-stock valuation. The two companies' TAM narratives are entirely different, and understanding the difference is key to understanding the valuation gap.

TAM DimensionNETZS
Company-Cited TAM $181B (2025) → $231B (2028) ~$96B (SSE/SASE + AI Security + Data Security)
TAM Composition CDN + security + compute + storage + AI inference + IoT + 5G SSE/SASE + Zero Trust + AI security + data security
Current Penetration ~$2.17B / $181B = ~1.2% ~$3.36B / $96B = ~3.5%
Upward Revision From the AI Era Very large — Agent Cloud's compute + storage + inference is all incremental Large — non-human identity governance + AI data security is pure incremental

NET's TAM is "wider" — it can point to nearly all of cloud infrastructure spend. But that also means NET must compete against different rivals in every sub-market (Akamai in CDN, ZS in security, AWS Lambda@Edge in compute). A big TAM doesn't mean you can actually capture it.

ZS's TAM is more "focused" — concentrated in the single vertical of security, but going deeper globally than anyone else. Penetration of just 3.5% means it could grow several-fold simply by capturing more of the existing market — before even counting the new market for non-human identity governance that AI agents create. Chaudhry noted on the Q2 earnings call that Zero Trust Everywhere customers have ARR 2-3 times that of average customers — that's "density expansion" within the existing TAM.

5.5 Five-Year Scenario Valuation Model

Laying out all the variables, here's a projection of fair market cap five years out under three scenarios:

NET Five-Year Scenario Valuation (CY2030)
ScenarioFY2030 RevenueAssumptionsP/SImplied Market Capvs. Current
🐻 Bear$5.8BGrowth decelerates to 18% CAGR, AI inference fails to scale, gross margin compressed to 72%10x$58B-16%
📊 Base$7.2B25% CAGR, Agent Cloud contributes 10% of revenue, operating margin 20%+15x$108B+57%
🐂 Bull$9.0BAgent Cloud usage revenue ignites, 30% CAGR, becomes a top-five cloud platform18x$162B+135%
ZS Five-Year Scenario Valuation (FY2031, through 2031/07)
ScenarioFY2031 ARRAssumptionsP/SImplied Market Capvs. Current
🐻 Bear$5.8BOrganic growth falls to 15%, PANW continues taking share, SBC compresses valuation5x$29B+61%
📊 Base$7.5B20% CAGR, AI Security becomes a second engine, turns GAAP-profitable8x$60B+233%
🐂 Bull$9.5BNon-human identity TAM explodes, 25% CAGR, Zero Trust becomes a regulatory standard10x$95B+428%
📈 Key Findings From the Five-Year Return Comparison

ZS's return is higher than NET's under all three scenarios — including the bear case. That's not because ZS's fundamentals are better — it's because its starting valuation is lower. When a Rule-of-62 company is priced at 5.4x P/S, you get a safety net: "even if you're wrong, you won't lose that much." ZS's bear-case return is still +61%, while NET's bear-case return is -16%.

NET's bull-case ceiling is higher ($162B), but it has no safety net — a classic "high return, high risk" growth-stock profile. If Agent Cloud ignites successfully, NET's return could far exceed most tech stocks. But if AI inference revenue is still negligible two years from now, a 25x P/S valuation will get mercilessly compressed by the market.

In a sentence: ZS's risk-adjusted return is meaningfully better than NET's. But NET's absolute upside ceiling is higher — contingent on Agent Cloud delivering.

5.6 Comparing Revenue Quality: Whose Dollars Are "Easier to Earn"?

Earning a dollar isn't the same quality everywhere. Below is a breakdown of revenue quality along four dimensions:

Predictability: ZS's revenue comes almost 100% from multi-year subscription contracts; ARR and RPO offer extremely high visibility (FY2026 ARR guidance of $3.73-3.745B). NET is also predominantly subscription-based, but usage-based models like Workers AI and R2 are growing — this adds growth elasticity but also adds forecasting difficulty.

Gross Margin Structure: ZS's 80% non-GAAP gross margin reflects the economics of pure software — it doesn't need to buy GPUs or build data centers (it rides on public clouds). NET's 74.9% gross margin reflects a "hardware-intensive" business model — servers, GPUs, and interconnect equipment across 330 cities worldwide are all NET's own capital expenditure. As Agent Cloud scales, GPU capex could compress margins further.

Customer Concentration Risk: NET's large customers account for 73% of revenue (Q4 2025), and million-dollar customers surged 55% — good news (enterprises are spending more), but it also means losing a handful of large accounts could have an outsized impact. ZS's customer base is more distributed (3,886 accounts at $100K+, 728 at $1M+); while it likewise leans on large customers proportionally, the absolute count is larger.

Cash Conversion Efficiency: ZS's combined H1 FY2026 Rule of 62 (26% growth + 36% FCF margin) is top-tier across SaaS companies market-wide. NET's FCF margin doubled from 10% in Q4 2024 to 16% in Q4 2025 — a good trend, but the absolute level still trails ZS. NET's capex (13% of revenue) is an ongoing cash drain that ZS barely has to deal with.

VI. Valuation and Risk: Whose Margin of Safety Is Larger?

6.1 Valuation Comparison

Valuation MetricNETZS
Market Cap~$69B~$18B
P/S (MarketSurge)26.17x6.57x
Forward P/E159.31x29.05x
P/E (TTM, N/A x S&P)194x33x
EPS Rating9898
Composite Rating7944
Debt147.8%96.9%
Mutual Fund %57%54%
Short Interest-2.0% (shorts covering)4.6% (short pressure present)
Analyst Consensus Price Target~$232 (22 Buy / 10 Hold / 3 Sell)~$268 (majority Buy)
Implied Upside~26% (from $184)~120% (from $122)
💰 Valuation Conclusion (MarketSurge Live Data)
ZS is unusually cheap — P/S 6.57x, Forward P/E 29.05x — for a company with 69% EPS growth, an EPS Rating of 98, SMR = A, and a Rule of 62. This is deep-panic pricing. The market has priced in the fear that AI will replace security work (the Claude Mythos episode), tariff impacts, and PANW competitive pressure all at once — but the fundamentals (EPS 98, SMR A) simply don't support that conclusion.

NET is expensive enough that it must keep proving itself — P/S 26.17x, Forward P/E 159.31x. But NET's EPS Rating is likewise 98 and SMR is also A, meaning the market is willing to pay a very high premium for its growth trajectory (30% YoY revenue growth). A Composite of 79, far better than ZS's 44, indicates a healthier overall picture.

The most striking comparison: both have an EPS Rating of 98, both have SMR = A, both have Sales Growth of 30% — yet NET's P/S is four times ZS's. That gap doesn't reflect a difference in fundamentals — it reflects a "growth-story valuation premium." The market has paid a massive insurance premium for NET's Agent Cloud narrative, while giving almost no credit at all to ZS's AI Security narrative.

6.2 Risk Matrix

Risk ItemNET Risk LevelZS Risk Level
Valuation Bubble / Multiple Compression🔴 High🟢 Low (already heavily compressed)
Sustained GAAP Losses🟡 Medium🟡 Medium (SBC 26.5%)
Hyperscaler Pushback🟡 Medium🟢 Low
AI Replacing Security FunctionsN/A🟢 Low (logic runs the opposite way)
PANW Platformization Dumping🟢 Low🟡 Medium
AI Inference Revenue Materializing🟡 Medium (still negligible)N/A
Organic Growth Slowdown🟢 Low (accelerating)🟡 Medium (organic ARR +21%)
Acquisition Integration Risk🟢 Low (Replicate is small)🟡 Medium (Red Canary integration underway)
Key-Person Risk🟢 Low (dual-CEO structure)🟡 Medium (Chaudhry is 72)
Gross Margin Pressure🟡 Medium (GPU capex)🟢 Low (stable at 80%)

VII. Dual Evaluation Through the Four-Layer Defensive Screen

Below, we apply ProfitVision LAB's Four-Layer Defensive Screen to evaluate whether either stock is suitable as a Bull Put Spread candidate.

⚡ NET's Four-Layer Defensive Screen (MarketSurge 2026/04/15)
LayerMetricDataResult
1: PositioningA/D RatingD❌ Fails (one-vote veto)
RS Rating68❌ Fails (<80)
3M RS / 6M RS21 / 19⚠️ Extremely weak
U/D Vol Ratio0.97⚠️ Sell pressure still exceeds buy pressure
2: MoatROE-8.16%❌ Below 17% threshold (GAAP loss)
EPS Rating98✅ Top-tier
SMR RatingA✅ Top-tier
Sales Growth Rate30%✅ Strong
3: VolatilityIV RankElevated (post-Mythos + tariffs)✅ Favorable
4: TechnicalsPrice vs. 50MA$184 (50MA estimated ~$200-210)❌ Below 50MA
Composite Rating79⚠️ Middling

🎯 NET Overall Verdict: ⏸️ Watch Actively

A double veto on positioning (A/D = D, RS = 68) — institutions are still net sellers, and relative strength hasn't recovered. But NET's situation is considerably better than ZS's: RS at 68 isn't far from the 80 threshold, EPS Rating 98 and SMR A are both top-tier, and Composite 79 is also close to breakout territory.

Signals to wait for: ① A/D rises back to C+ or better ② RS breaks above 80 ③ share price reclaims the 50MA ④ Q1 FY2026 earnings (5/7) confirm DBNRR holding at 120%+. If at least the first three of these four conditions confirm, a Bull Put Spread can be initiated. NET's positioning metrics are much closer to "clearance" than ZS's — a good quarterly-earnings catalyst may be all it needs.

⚡ ZS's Four-Layer Defensive Screen (MarketSurge 2026/04/15)
LayerMetricDataResult
1: PositioningA/D RatingE❌ Fails (lowest grade)
RS Rating6❌ Fails (near the floor)
3M RS / 6M RS3 / 3❌ Among the weakest in the entire market
U/D Vol Ratio0.70❌ Sell pressure far exceeds buy pressure
2: MoatROE-3.56%❌ Below 17% threshold (GAAP loss)
EPS Rating98✅ Top-tier
EPS Growth Rate69%✅ Clears (far above the 25% threshold)
SMR RatingA✅ Top-tier
Sales Growth Rate30%✅ Strong
3: VolatilityIV RankElevated✅ Favorable (rich premium)
4: TechnicalsPrice vs. 50MAFar below the 50MA❌ Fails
Composite Rating44❌ Very weak

🎯 ZS Overall Verdict: ⏸️ Watch Cautiously (downgraded from Watch Actively)

The latest MarketSurge data is worse than expected: A/D has deteriorated from D+ to E (the lowest grade), RS is only 6 (3M RS = 3), and a U/D Vol Ratio of 0.70 confirms institutions are exiting in size. A Composite Rating of 44 signals across-the-board breakdown.

Yet the fundamental data is extremely contradictory: EPS Rating 98 (top-tier), EPS Growth 69% (far above the threshold), SMR = A (top-tier), Sales Growth 30%, Forward P/E of just 29.05 — this is a growth stock being priced as a "value trap." A P/S of 6.57 on a Rule-of-62 company is panic pricing.

Conclusion: the extreme divergence between fundamentals and positioning is both the most dangerous and the most opportunity-rich combination. Entering while A/D = E means catching a falling knife, but when A/D recovers from E to C, that's often where the next leg starts. Wait strictly for: ① A/D ≥ C ② RS ≥ 50 (first stop the bleeding, don't demand perfection) ③ price reclaims the 50MA. Once triggered, execute a Bull Put Spread with Short Put $100-105, Delta <30, DTE 30-45 days.

VIII. Conclusion: It's Not Either/Or — It's Understanding What You're Buying

By this point, the conclusion writes itself.

If you buy NET, you're buying:

A "toll-road" platform company transitioning from a CDN/security company into the operating-system infrastructure of the AI-agent era. Its revenue acceleration (34% growth, DBNRR 120%, RPO +48%) is one of the strongest forward-looking signals in the entire market. Agent Cloud has just received a public endorsement from OpenAI. TAM is expanding from $181B (2025) to $231B (2028).

But you're also buying one of the highest valuations anywhere in the market — P/S of 25x, P/E of 165x. You're paying "the day-after-tomorrow's price" for "tomorrow's story." AI inference revenue is still negligible right now — the CEO admits it himself. Gross margin is under pressure from GPU capex (down from 77.6% to 74.9%).

Suitable for: investors willing to pay a premium for high-quality growth, with a longer holding horizon, who can stomach a 30-40% drawdown.

If you buy ZS, you're buying:

Security infrastructure that is "essential" to the AI era. The more numerous and autonomous AI agents become, the more rigid ZS's demand becomes — that's logical deduction, not marketing copy. A data flywheel built on one trillion AI transactions, 20 years of accumulated threat intelligence, and Zero Trust penetration above 45% of the Fortune 500 — these are walls built over time.

More importantly, you're buying a stock the market has seriously mispriced. A P/S of 5.4x, Rule of 62, non-GAAP operating margin of 22%, and $3.5B in cash — this doesn't look like the valuation of "a company about to be replaced by AI." It looks like a quality asset being sold off in a panic.

But you're also buying some real risks: organic ARR growth slowing to 21% (excluding Red Canary), PANW's platformization offensive, SBC at 26.5% of revenue, and succession risk with Chaudhry at 72.

Suitable for: disciplined investors who prioritize margin of safety, are willing to wait for technical confirmation, and prefer "value found in panic."

Options Strategy Framework: Discipline Comes Before Conviction

Even the best story requires waiting for the right entry timing. Below is a concrete options framework for each stock:

NET Options Strategy (Pending Confirmation)

NET currently cannot execute a Bull Put Spread, because the Four-Layer Screen has not yet cleared on MarketSurge data. But if the following signals appear after the Q1 FY2026 earnings report on 4/30, deployment can be initiated:

Entry Conditions: A/D ≥ C+, RS ≥ 80, share price holding above the 50MA, DBNRR sustained at 120%+. If all four conditions clear, execute a Bull Put Spread: Delta <30, DTE 30-45 days, Short Put set below the nearest support level (estimated $160-165 zone, to be confirmed against post-earnings technical structure). Risk unit: 5% of account (~$600).

Alternative Strategy: If the share price breaks above $200 after earnings but positioning hasn't fully confirmed, consider a Poor Man's Covered Call (PMCC) — buy a long-dated, deep-in-the-money call (Delta 80+, DTE 180+) and sell a short-dated out-of-the-money call (Delta 30, DTE 30-45) — harvesting the time-value spread to capture IV premium while retaining upside participation.

ZS Options Strategy (Watch Cautiously — downgraded from Watch Actively)

ZS's positioning metrics are worse than previously estimated: A/D has deteriorated to E (the lowest grade), RS is only 6, 3M RS = 3, U/D Vol Ratio 0.70. This isn't a "bottoming soon" signal — it's a "institutions are still systematically selling" signal. But the fundamental metrics (EPS 98, EPS Growth 69%, SMR A, Forward P/E 29) diverge sharply from the positioning data — that kind of divergence usually means either the market is right (there's bad news you don't know about) or the market is wrong (excessive panic).

Trigger Conditions (all must be met before executing):

① A/D Rating recovers to B or above (indicating institutional selling pressure has stopped)
② RS Rating recovers to 70 or above (indicating relative strength has been restored)
③ Share price reclaims the 50MA (technical confirmation of a bottom)
④ IV Rank >30% (ensuring premium is rich enough)

Execution Parameters: Bull Put Spread, Short Put Delta <30, DTE 30-45 days, Short Put strike set in the $100-105 zone (below the long-term support band), risk unit 5% of account (~$600).

Early-Positioning Strategy: if you have strong conviction in ZS's long-term thesis but don't want to wait for positioning confirmation, consider scaling into Cash-Secured Puts — sell puts at a $95-100 strike, DTE 60 days, rolling monthly. If assigned, you build a long-term position at a very low cost basis; if not assigned, you keep harvesting time value. The precondition is that you're genuinely willing to hold ZS at $95-100.

Discipline comes before conviction — even the best story requires waiting for the right entry timing.
The market belongs to whoever survives the longest.

Final Framework

Decision DimensionChoose NETChoose ZS
What do you believe AI agents need?A place to run (Platform)A police force to govern them (Security)
What's your risk appetite?High growth, high volatility, long-term holdValue re-rating, disciplined waiting, margin of safety
What's your valuation tolerance?Willing to pay 26x P/S (betting AI delivers)Looking to catch 6.6x P/S (betting the panic is overdone)
Catalyst timeline?Q1 FY2026 earnings (5/7)A/D recovering from E + Q3 FY2026 earnings (5/28)
Options strategy preference?Watch Actively for Bull Put SpreadWatch Cautiously (wait for A/D ≥ C)

If you must choose only one, ask yourself: what do you think is the actual bottleneck of the AI-agent era?

If you believe the bottleneck is "nowhere to run" — buy NET.

If you believe the bottleneck is "running unsupervised" — buy ZS.

If you believe the bottleneck is "both" — you already know the answer.

📌 Tracking Log
DateEventCallFollow-up Result
2026/04/15Initial publication. NET: Q4 FY2025 data; ZS: Q2 FY2026 data.⏸️ Watch on both

▸ Next update: after NET's Q1 FY2026 earnings (2026/05/07) + ZS's Q3 FY2026 earnings (2026/05/28)
▸ Early-update triggers:
  ① NET or ZS A/D Rating recovers to B or above
  ② A major AI Agent Security acquisition or partnership event
  ③ PANW or CRWD announces a direct competitor to Agent Cloud
  ④ Cloudflare discloses quantifiable Agent Cloud revenue figures
  ⑤ Zscaler announces Chaudhry's succession plan

⚠️ Disclaimer|This article is part of ProfitVision LAB's Head-to-Head Research series #NET-vs-ZS, with data as of 2026/04/15. Content is for educational and research purposes only and does not constitute investment advice. Options trading involves significant risk, and losses may exceed the initial investment. The author does not manage funds on others' behalf and does not provide trade signals through any group or channel, nor guarantee profits. At the time of writing, the author held no position in NET or ZS.
CloudflareNETZscalerZSAI AgentsZero TrustSASEAgent CloudMoatOptionsFour-Layer ScreenHead-to-Head Research

— Shiba the Disciplined · ProfitVision LAB · 2026/04/15