Skip to content

Compare moats

Up to three covered companies, band by band. Every call is a curated editorial judgment, never a disclosed figure — and every band carries its cited basis.

comparing Cloudflare×Celestica×NetApp× maximum of 3 — remove one to swap
Cloudflare NET ai moat: latest change 2026-02-26 Celestica CLS ai moat: latest change 2026-02-27 NetApp NTAP ai moat: latest change 2026-06-05
Moat rating wide

The band is earned by a measured share gap on a hard-to-rebuild asset, not asserted. W3Techs' 17 September 2026 survey (w3techs.com/technologies/overview/proxy) puts Cloudflare in front of 25.8% of all websites, an 85.0% share of the reverse-proxy market, against Amazon CloudFront at 5.5%, Fastly at 3.0% and Akamai at 2.1% - roughly fifteen times the nearest rival. The FY2025 10-K filed 2026-02-26 describes what a challenger would have to reproduce to contest that: a network that 'spans more than 330 cities in over 125 countries worldwide and interconnects with over 13,000 networks globally', architected to 'run every service on every server in every city' - capacity and peering accumulated city by city over a decade, not bought in a quarter. The position has been monetised without margin decay: SEC XBRL fundamentals on this site show GAAP gross margin inside a 74.5-78.7% band in every fiscal year from FY2017 to FY2025 while revenue grew from $134.9M to $2,167.9M, and Cloudflare's Q4/FY2025 results release of 2026-02-10 (cloudflare.com/press/press-releases/2026/cloudflare-announces-fourth-quarter-and-fiscal-year-2025-financial-results/) reports remaining performance obligations up 48% and new annual contract value up nearly 50% year over year. What stops this being a certainty rather than a judgement: the dominant share sits in application services, while SASE and developer compute are contested by vendors the 10-K itself concedes hold 'substantially greater financial, technical, and other resources.'

source: sec.gov

narrow

The FY2025 10-K shows a real but bounded edge. On the durable side, Celestica is increasingly engaged as an ODM: its HPS business co-designs (JDM) or fully designs the platforms it builds, it states 'We have hardware and software patents that are integral to our HPS business' and that 'our increased R&D activities have resulted in the growth of our dependence on our patent portfolio', and HPS reached 41% of total revenue in 2025 (from 21% in 2023) at a margin profile the filing says is higher than traditional EMS work. On the limiting side, the same filing concedes 'Some of our competitors have greater scale and provide a broader range of services than we provide', the master supply agreements 'do not typically guarantee a particular level of business or fixed pricing', work is won 'on a program-by-program basis', and the top 10 customers were 79% of 2025 revenue with three customers individually at 32%, 14% and 12%. An advantage that must be re-won each program against greater-scale rivals, for a handful of buyers who can in-source, is narrow rather than wide.

source: sec.gov

narrow

The FY2026 10-K shows a real, durable lock but not an unassailable one. On the durable side: "Our cloud storage services are based on the same ONTAP data management software that underpins our on-premises ONTAP storage infrastructure offerings", and the same filing's income statement shows the company holding a gross margin near 71% across all three reported years - $4,433M on $6,268M in FY2024, $4,613M on $6,572M in FY2025 and $4,899M on $6,925M in FY2026 - while revenue grew from $6,268M to $6,925M and income from operations widened from 19% to 24% of net revenues. Holding that margin through the memory-cost shock the same filing discloses is the commercial evidence the lock is worth something. On the limiting side, the filing says competition "is intense", that in public cloud "customers may choose native cloud services that are consumed as operating expenses", and that "New competitors or alliances among existing competitors could emerge and quickly gain significant market share" - and IDC's 1Q26 external-storage tracker (Blocks & Files, 2026-06-16, cited on the AFF/ASA product row below) ranks NetApp second behind Dell, not first.

source: sec.gov

Moat type cost scale

The FY2025 10-K states the mechanism outright, and it is a unit-cost curve rather than a user-to-user network: 'We have chosen to utilize this idle capacity to create a free tier of service which has generated substantial global scale for us. In turn, this scale makes us attractive partners for Internet Service Providers (ISPs) globally, which reduces our co-location and bandwidth costs. As our network grows, these dynamics become even more powerful.' The same section explains why the curve applies to every line rather than one: the architecture lets Cloudflare 'deploy standard, commodity hardware' and run 'every service on every server in every city', so a new product reaches 330+ cities at near-zero incremental capital. That is what lets the filing claim Workers is offered 'at prices that are highly competitive with public cloud vendors' while FY2025 GAAP gross margin still printed 74.5%. Switching costs (traffic routed through Cloudflare, DNS delegated to it) and threat-intelligence feedback from aggregate traffic sit on top, but the filing-stated primary source is cost falling as the network grows.

source: sec.gov

switching costs

Cost scale is explicitly not the source: the 10-K states competitors have greater scale and a broader service range. What does bind a customer is the design-in. Within HPS, Celestica 'design[s] and manufacture[s] products, either as customized solutions, white box solutions or under Joint Design and Manufacturing (JDM) engagements', holds 'hardware and software patents that are integral to our HPS business', and delivers 'complete platform solutions... integration and orchestration of various technologies into rack-scale designs'. The filing adds that 'a majority of these supply agreements also require the customer to purchase unused inventory that we have purchased to fulfill that customer's forecasted manufacturing demand', a contractual cost of walking away mid-program. Moving a qualified, jointly designed rack-scale platform to another ODM means requalifying a design Celestica partly owns, which is friction the commodity assembly work does not carry.

source: sec.gov

switching costs

The FY2026 10-K makes the source of the advantage explicit and it is the cost of leaving the data-management layer, not a network or a patent estate. The same ONTAP software runs the on-premises arrays and the cloud services ("Our cloud storage services are based on the same ONTAP data management software that underpins our on-premises ONTAP storage infrastructure offerings"), and the AFF family "allows customers to connect to clouds for more data services, data tiering, caching, and disaster recovery". A customer's volume layout, snapshot and replication workflow and operating tools therefore carry from the array into Azure, AWS and Google rather than being abandoned at the cloud boundary — the filing describes NetApp as "the only provider of enterprise-grade storage services natively embedded in the world's largest public cloud providers", so the usual moment of escape is instead the moment the relationship renews.

source: sec.gov

Leadership clear leader

Leadership is measured, not inferred. W3Techs on 2026-09-17 records an 85.0% reverse-proxy market share against 5.5% for Amazon CloudFront and 2.1% for Akamai, and makes Cloudflare the largest authoritative-DNS provider at 18.5% of all websites versus 9.9% for the next-placed GoDaddy Group. The FY2025 10-K reports the enterprise side moving the same way - 4,298 large customers at 2025 year-end against 3,497 a year earlier and 2,756 in 2023 - and the Q4/FY2025 results release (cloudflare.com/press/press-releases/2026/cloudflare-announces-fourth-quarter-and-fiscal-year-2025-financial-results/) cites the largest annual contract value deal in company history at about $42.5M per year. The band is for the application-services core the share data covers; in SASE and in serverless compute Cloudflare is a challenger to larger incumbents, and no independent placement naming Cloudflare in those markets was obtained for this profile.

source: sec.gov

at parity

The 10-K claims no share leadership. It states plainly that 'Some of our competitors have greater scale and provide a broader range of services than we provide', and lists Hon Hai, Flex, Jabil, Sanmina, Benchmark and Plexus in EMS plus Quanta, Wiwynn and Accton in ODM. Its stated competitive advantage is execution quality, not position: 'our track record in advanced manufacturing capabilities, design and engineering, quality, delivery, managing complexity and responsiveness'. It is also winning: CCS revenue grew 42% to $9.19 billion and total revenue reached $12.39 billion in FY2025. Competing on comparable terms with a field it neither leads nor trails is parity.

source: sec.gov

co leader

IDC's 1Q26 external enterprise storage systems tracker, as reported by Blocks & Files on 2026-06-16 (cited in full on the AFF/ASA product row below), ranks NetApp second worldwide behind Dell and ahead of Everpure, Huawei and HPE, attributing the placing to "its growing all-flash business and cloud-integrated data management". Second of five ranked vendors, in a market whose leader is someone else, is a shared front rank rather than an owned one - and the distinct claim NetApp makes in the FY2026 10-K is positional rather than volumetric: being "the only provider of enterprise-grade storage services natively embedded in the world's largest public cloud providers".

source: sec.gov

Pricing power moderate

Evidence cuts both ways, which is why this is not the top band. For it: GAAP gross margin has never left a 74.5-78.7% band across FY2017-FY2025 (SEC XBRL fundamentals on this site) even as revenue compounded 16x, and the Q4/FY2025 results release (cloudflare.com/press/press-releases/2026/cloudflare-announces-fourth-quarter-and-fiscal-year-2025-financial-results/) shows customers committing more rather than less - RPO +48% year over year and new ACV up nearly 50%. Against it: FY2025's 74.5% is the lowest reading in that nine-year series, a large permanent free tier anchors the entry price, the 10-K positions Workers 'at prices that are highly competitive with public cloud vendors', and the competition risk factor warns that larger rivals can 'sell products and services with which we compete at zero or negative margins, offer fee waivers and reductions or other economic and non-economic concessions', with competitive pressure that 'may result in price reductions, fewer subscriptions, reduced revenue and gross margin'.

source: sec.gov

weak

The filing describes price as contested by contract, not set by Celestica: master supply agreements 'do not typically guarantee a particular level of business or fixed pricing', 'Some of these agreements require us to provide specific price reductions to our customers over the term of the contracts', and the Item 1A risk factor 'We operate in an industry comprised of numerous competitors and aggressive pricing dynamics' says competitors may be 'willing to, or able to make sales or provide services at lower margins than we do'. The site's fundamentals show gross margin at 12.06% in FY2025, up from 8.96% in FY2022, 9.47% in FY2023 and 10.72% in FY2024 — improving, but still low double digits, and the filing attributes the higher margin to mix (HPS is 'higher margin profile than our traditional EMS businesses' and went from 21% to 41% of revenue over the same span) rather than to raising prices.

source: sec.gov

moderate

It holds price rather than raising it. On the figures filed with the FY2026 10-K, gross margin was 70.7% of revenue in FY2024 ($4,433M on $6,268M), 70.2% in FY2025 ($4,613M on $6,572M) and 70.7% in FY2026 ($4,899M on $6,925M) - flat across three years in which revenue grew from $6,268M to $6,925M - and it held that level while absorbing a component-cost shock. It is no stronger than that because the filing's own risk factor lists "competitive pricing, customer price sensitivity" and "pricing and discounting pressures" among the drivers of gross margin, and discloses that the company "experienced inflationary pressure and supply chain constraints beginning in the second half of fiscal 2026, resulting in increased costs for memory and other components, which have affected our gross margins" - a cost shock it is absorbing rather than fully passing on.

source: sec.gov

Summary

Cloudflare sells security, performance and connectivity as services delivered from one global anycast network rather than from boxes at a customer's edge. The FY2025 10-K frames the market as a consolidation away from enterprises that 'string together a diverse set of on-premises hardware boxes from different vendors' and away from 'stringing together multiple point-cloud solutions that only address specific network needs', toward one integrated provider it calls the Connectivity Cloud, and places Cloudflare as 'a leader in this Connectivity Cloud category'. The economics are unusual: idle capacity funds a free tier, the free tier buys global traffic scale, that scale makes Cloudflare a peering partner ISPs want, and peering cuts colocation and bandwidth cost - a loop the filing says 'become[s] even more powerful' as the network grows. Independent measurement confirms where that loop has already settled the market: W3Techs on 2026-09-17 shows an 85.0% reverse-proxy share and the largest authoritative-DNS footprint at 18.5% of all websites. Commercially the company ended 2025 with roughly 332,000 paying customers in more than 190 countries and 4,298 large customers, up from 2,756 two years earlier, with no customer above 10% of revenue. The contested half of the story is the growth half: the SASE platform competes with established cloud-security, email-security and SD-WAN vendors, and the developer platform competes for storage and compute against hyperscalers, markets where the 10-K's own risk factors concede rivals have greater name recognition, larger customer bases and 'more mature products and services developed for large customers'. The core is defended; the adjacencies are being fought for, and FY2025 gross margin at a nine-year low of 74.5% is the first visible cost of building GPU capacity for that fight.

Celestica is a contract design and manufacturing company that has been pulled up the value chain by the AI data-center build-out. Its CCS segment, which builds networking switches, optical systems, data center racks, servers and storage for hyperscalers and other cloud and AI service providers, grew 42% to $9.19 billion in 2025, and Communications alone went from 33% of revenue in 2023 to 57% in 2025. The part of that business with a defensible position is HPS, where Celestica is the designer rather than the assembler: HPS revenue rose 81% in 2025 to 41% of the total, carries a higher margin than traditional EMS work, and rests on a patent portfolio the filing calls integral to the business. That design-in position is what separates it from pure build-to-print capacity. What caps the moat is the customer side of the ledger. The 10-K describes an industry where 'aggressive pricing is a common business dynamic', where master supply agreements guarantee neither volume nor price and some of them 'require us to provide specific price reductions to our customers over the term of the contracts', and where the company bids program by program against Hon Hai, Flex, Jabil, Sanmina, Benchmark and Plexus on the EMS side and Quanta, Wiwynn and Accton on the ODM side, plus Arista and Cisco where a customer might buy an off-the-shelf switch instead. Revenue concentration has tightened as the AI mix grew, from 64% of revenue in the top 10 customers in 2023 to 79% in 2025, with a single customer at 32%. The company also notes its HPS offerings can compete with a customer's own hardware, which may 'negatively impact our relationship with, or result in a loss of business from, such customers'. So the profile is a genuine but program-scoped advantage, held by a company whose fortunes turn on a few buyers' capital plans.

NetApp sells storage hardware but the asset is ONTAP, the data-management software that has run its arrays for over three decades and now also runs inside the three largest public clouds as a first-party service. The FY2026 10-K organises the company into two segments, Hybrid Cloud (AFF and ASA all-flash arrays, AFX for AI workloads, FAS hybrid-flash, E/EF-Series, StorageGRID object storage) and Public Cloud (Azure NetApp Files, Amazon FSx for NetApp ONTAP, Google Cloud NetApp Volumes, Cloud Volumes ONTAP), and states that both rest on the same ONTAP software. That is the whole argument: an enterprise that has standardised its snapshots, replication and multiprotocol access on ONTAP carries those habits with it when it moves workloads to a hyperscaler, and NetApp is paid on both sides of the move. The evidence that the lock has commercial value is the margin's steadiness: across the three years the FY2026 10-K reports, gross margin sat at 70.7%, 70.2% and 70.7% of revenue ($4,433M on $6,268M, $4,613M on $6,572M, $4,899M on $6,925M) while revenue grew, and the filing's own percentage-of-revenue table shows no mix shift doing that work - product and services held near 46% and 54% of revenue throughout. The limits are equally in the filing. NetApp is second, not first: IDC's 1Q26 tracker puts it behind Dell in external enterprise storage, and the 10-K's competition section concedes that cloud providers are simultaneously partners and rivals, that consumption models "may reduce overall demand for our traditional on-premises offerings sold through a capital expenditure (capex) model", and that alternative architectures "may reduce or eliminate demand for some of our offerings". Component exposure is real too: the filing discloses "inflationary pressure and supply chain constraints beginning in the second half of fiscal 2026, resulting in increased costs for memory and other components, which have affected our gross margins", and names NAND among the components whose supply can tighten. This is a durable second place built on software stickiness, not a structural monopoly.

Chain position

Cloudflare sits between end users and whatever hosts the application - origin data centre, public cloud or SaaS - so it is a control layer in front of infrastructure rather than infrastructure a workload runs on, which the 10-K argues is the point: customers 'concerned about being locked in to any one public cloud provider' want policy enforced by 'an independent and integrated services provider'. Two AI-era roles follow from that position. As a supplier, the filing describes 'ongoing deployment of graphics processing units (GPUs) across our global network of servers' behind Workers AI, Vectorize and AI Gateway, putting inference next to the user instead of in a region. As a gatekeeper, the application-services suite now exists in part to 'easily identify, block and control access from AI crawlers and AI agents and operators' and underpins announced efforts to let content creators monetise how those crawlers reach their work - which makes Cloudflare a toll point between AI model builders and the open web.

Celestica sits between component suppliers and the hyperscale buyer, and owns the design only in part of that span. It 'procure[s] substantially all of our materials and components on behalf of our customers pursuant to individual purchase orders that are generally short-term in nature', then designs, assembles, integrates at rack scale and tests the switches, optical systems, servers, storage and data-center racks that cloud, AI and enterprise customers deploy. In ATS it is a pure EMS contractor that does 'not generally collaborate with ATS customers on the design of the solutions we manufacture'; in HPS it is the designer of record or a joint designer. The economics follow that split: the segment where it holds design IP is the one with the higher margin profile.

NetApp sits between the memory supply and the enterprise data centre. Upstream, the FY2026 10-K says "Third-party component costs make up a significant portion of our product costs" and singles out NAND as hard to manage "if supplies of certain components, including NAND, become limited relative to demand". Downstream, the hyperscalers are channel, partner and rival at once: the filing states "We both partner with and compete against cloud service providers through our cloud-based software and services offerings", while Azure NetApp Files, Amazon FSx for NetApp ONTAP and Google Cloud NetApp Volumes are delivered as those clouds' own natively embedded services. Distribution is a mix of direct sales and "an ecosystem of partners, including the leading cloud providers".

Products (share / barrier)
Long-horizon vote +0.38 at weight 0.20 · swarm neutral

Editorial prior, not backtested.

see exactly how it voted →

-0.01 at weight 0.20 · swarm neutral

Editorial prior, not backtested.

see exactly how it voted →

+0.13 at weight 0.20 · swarm neutral

Editorial prior, not backtested.

see exactly how it voted →