Compare moats
Up to three covered companies, band by band. Every call is a curated editorial judgment, never a disclosed figure — and every band carries its cited basis.
| Nebius Group | Palo Alto Networks | NVIDIA | |
|---|---|---|---|
| Moat rating | narrow The FY2025 20-F positions Nebius as 'one of the few global, at scale, multi-tenant clouds purpose built for AI,' but the same filing names its central dependency plainly: 'We currently rely on Nvidia for the GPU chips we use' — a purpose-built neocloud renting a supply the hyperscalers it competes with also control, which is a real but narrow position. | narrow Real but bounded. The FY2025 10-K's own Competition section calls the enterprise security industry "intensely competitive" and names four categories of rival — platform incumbents (Cisco, Microsoft, Alphabet), independent security vendors (Check Point, Fortinet, CrowdStrike, Zscaler, Wiz), point-product startups, and the public cloud vendors — while conceding that "some of our competitors may have substantially greater financial, technical, and other resources, greater name recognition, larger sales and marketing budgets, broader distribution, more diversified product lines, and larger and more mature intellectual property portfolios." That record supports a defensible position, not an unassailable one: narrow, not wide. | wide Wide: the CUDA software platform and its developer installed base create high switching costs across the AI-training stack, defended by $76.7B cumulative R&D and reinforced by ~71% FY2026 gross margins and Data Center revenue (~90% of total) up 68% YoY — durable, hard-to-replicate advantages per the FY2026 10-K. |
| Moat type | cost scale The moat the filing describes is engineering: designs that 'optimize power and cooling efficiency, lower latency' plus 'a consistent track record of being one of the first-to-deploy the latest generation of NVIDIA GPU chips' — density and time-to-deploy at scale, not a switching lock. | switching costs The 10-K describes an installed estate standardised on one operating system — "All of our hardware and software firewalls incorporate the PAN-OS operating system and include the same rich set of features, ensuring consistent operation across our entire product line" — across hardware, containerised CN-Series and virtual VM-Series form factors, centrally administered through Panorama and Strata Cloud Manager. That estate is monetised as recurring contract: subscription and support was 80.5% of total revenue in fiscal 2025 (80.0% in fiscal 2024, 77.1% in fiscal 2023), on terms "typically one to five years." The company's own risk factors describe the friction from the other side — customers "may face real or perceived switching costs when switching to our solutions from legacy security vendors" and "have often invested substantial personnel and financial resources to design and operate their networks... [and] may prefer to purchase from their existing suppliers rather than add or switch to a new supplier." As the incumbent in most of those estates, that friction now runs in Palo Alto's favour. | intangibles ip The durable edge rests on proprietary IP and software: the full-stack CUDA development platform running on all NVIDIA GPUs plus hundreds of proprietary domain libraries/SDKs/APIs, and $76.7B cumulative R&D yielding "inventions that are essential to modern computing" (NVIDIA invented the GPU in 1999). This is reinforced by developer-ecosystem network effects and CUDA switching costs, per the FY2026 10-K Business section. |
| Leadership | fast follower The 20-F's own claim is 'one of the FEW global, at scale' AI clouds — a differentiated challenger to the hyperscalers it names as the competitive field, not a claimed leader of it; the first-to-deploy record is a follower's speed advantage, not category leadership. | co leader The 10-K claims parity-plus, not primacy: "We believe we generally compete favorably with our competitors on the basis of these factors as a result of the features and performance of our portfolio, the ease of integration of our security solutions with technological infrastructures, and the relatively low total cost of ownership of our products," and reports that its "products and services have been recognized as leading in 25 categories by third-party industry analysts firms." It qualifies that immediately by conceding that some competitors carry greater resources, name recognition and distribution. Independent analyst placements match a co-leader read rather than a sole-leader one — a Leader in the inaugural 2025 Gartner Magic Quadrant for Hybrid Mesh Firewalls, a Leader for the third consecutive time in the 2025 Magic Quadrant for SASE Platforms, and a Leader in the 2026 Magic Quadrant for Endpoint Protection Platforms for the fourth consecutive year — in categories that name other Leaders too. | clear leader FY2026 Data Center revenue was $193.7B (~90% of the $215.9B total), up 68% YoY on the Blackwell ramp, and NVIDIA describes itself as "a data center scale AI infrastructure company reshaping all industries." The 10-K frames named rivals as parties who "provide or intend to provide" GPUs/accelerators — incumbent-leader positioning. |
| Pricing power | weak The filing frames a 'highly competitive' market with 'frequent introduction of new or improved solutions' and a GPU cost base set by a single supplier (NVIDIA) — a renter of compute competing on efficiency has little list-price control. | moderate Moderate, with the evidence pointing both ways in the same filing. Gross margin computed from the three years of income statements inside this FY2025 10-K runs 72.3% (fiscal 2023), 74.3% (fiscal 2024) and 73.4% in fiscal 2025 on revenue of $9.22 billion — against 68.8% in fiscal 2022 as reported in the prior-year 10-K (accession 0001327567-24-000029, filed September 6, 2024). Over the same span subscription and support rose from 77.1% to 80.5% of revenue: a mix shift toward software that has been margin-accretive, not margin-destructive, which is the direct answer to whether platformisation is simply discounting. Against that, the 10-K's risk factors state plainly that sales prices "may decline for a variety of reasons, including competitive pricing pressures, discounts, a change in our mix... or promotional programs," that the company "anticipate[s] that the sales prices and gross profits for our products could decrease over product life cycles," and that it "has also experienced demands for customer financing and deferred payments." Pricing is defended by bundle economics rather than commanded outright. | strong FY2026 gross margin was 71.1% (75.0% in FY2025); per the 10-K MD&A the ~3.9pt decline reflects the Hopper HGX→Blackwell full-system mix shift and a one-time $4.5B H20 excess-inventory/purchase-obligation charge, not competitive price erosion. A low-70s% hardware gross margin evidences strong pricing power. |
| Summary | Nebius sells a 'unified full-stack AI cloud that spans the complete AI journey – from compute capacity to software and services,' with hardware and software built in-house — the neocloud pitch of hyperscaler reliability at purpose-built efficiency, and a first-to-deploy record on new NVIDIA silicon. Two things bound the moat, both from the filing: it 'currently rel[ies] on Nvidia for the GPU chips,' the same constraint every neocloud shares, and it is a Nasdaq 'Controlled Company' whose founding shareholder holds concentrated voting power. The three non-core segments (Toloka, Avride, TripleTen) are separate businesses, not the cloud moat. | A deployed firewall estate is the anchor. Every Palo Alto firewall — appliance, VM-Series, CN-Series, Cloud NGFW — runs the same PAN-OS with the same feature set and is managed from one console, so the security policy, the operator skills and the integration work are all specific to the vendor, and 80.5% of fiscal 2025 revenue is the recurring subscription and support contract sitting on top of it (10-K, Business and Risk Factors). Platformisation is the attempt to convert that anchor into wallet share: the 10-K states the strategy as helping customers "simplify their security architectures through consolidating disparate point products" by packaging offerings "into a tightly integrated architecture," and the acquisitions are consistent with it — IBM's QRadar assets in August 2024 "to help accelerate the growth of our Cortex business," Protect AI in July 2025, and the CyberArk agreement signed in July 2025. The evidence that consolidation is real rather than a discount: remaining performance obligation grew 36% year over year to $18.4 billion against 31% revenue growth in the quarter ended April 30, 2026 (Palo Alto Networks FQ3 2026 results release, June 2, 2026) — contracted future obligation compounding faster than recognised revenue, which is the opposite of what buying revenue with price would produce. The counterweight is disclosed in the same filings: the 10-K warns sales prices "may decline for a variety of reasons, including competitive pricing pressures, discounts," anticipates that "sales prices and gross profits for our products could decrease over product life cycles," and reports "demands for customer financing and deferred payments." Against CrowdStrike in security operations and Zscaler in SASE, Palo Alto is competing across the whole surface rather than defending a monopoly on any one of them — hence a narrow moat, not a wide one. | NVIDIA pairs market-leading accelerated-computing hardware (the Blackwell data-center platform) with a proprietary full-stack software moat — CUDA plus hundreds of domain libraries — funded by $76.7B of cumulative R&D, and its "large and growing number of developers and installed base... strengthens our ecosystem and increases the value of our platform for our customers" (FY2026 10-K). Competition is intensifying from AMD, Intel and Huawei, and from hyperscalers (Alphabet, Amazon, Microsoft) designing internal AI silicon, but rivals must overcome NVIDIA's entrenched CUDA software ecosystem to displace it. |
| Chain position | Layer-8 neocloud — a purpose-built AI compute provider reselling NVIDIA silicon at scale. | A security-software consumer of the AI stack rather than a supplier to it — it buys compute to run Precision AI and now sells protection for the stack itself through Prisma AIRS (AI model scanning, posture management, red teaming, runtime and AI-agent security). Distribution is two-tier and concentrated: 44.2% of fiscal 2025 revenue came through three distributors and more than 8,500 channel partners, while no single end-customer exceeded 10% of revenue in fiscal 2025, 2024 or 2023. | Upstream compute-platform supplier: NVIDIA sells full-stack data-center systems (GPU + Arm CPU + DPU + NVLink/InfiniBand networking + CUDA software) to cloud providers and enterprises, and relies on third-party foundry/assembly-test-packaging partners (e.g., SPIL, Amkor, Wistron, Fabrinet). Per the FY2026 10-K, several of its largest customers (hyperscalers such as Amazon, Alphabet, Microsoft) are simultaneously customers and emerging competitors developing internal accelerated-computing silicon. |
| Products (share / barrier) |
|
|
|
| Long-horizon vote | -0.01 at weight 0.20 · swarm neutral Editorial prior, not backtested. | +0.13 at weight 0.20 · swarm neutral Editorial prior, not backtested. | +0.42 at weight 0.20 · swarm bullish Editorial prior, not backtested. |