−Removed: ITEM 2 — MANAGEMENT’S DISCUSSION AND ANALYSIS OF FINANCIAL CONDITION AND RESULTS OF
+Added: ITEM 2 — MANAGEMENT’S DISCUSSION AND ANALYSIS OF FINANCIAL CONDITION AND RESULTS OF OPERATIONS.
Company Overview
−Removed: We develop patented cybersecurity solutions that ensure resilient, secure communications across any network or device.
−Removed: Built on Zero Trust Network Access (ZTNA) principles, our flagship platform,
−Removed: VirnetX One™, virtualizes on-demand private networks using patented Secure Domain Names and automatically establishes secure links regardless of location or endpoint.
−Removed: Our products, including War Room™ and VirnetX Matrix™, are designed to support the U.S.
−Removed: Department of War (DoW) with real-time, encrypted collaboration.
−Removed: War Room TM offers advanced
−Removed: visualization for situational awareness, while VirnetX Matrix TM secures communications through robust encryption, even in contested environments.
−Removed: Our War Room™ software product provides safe and secure video conferencing meeting environment where sensitive communications and data is invisible to those not authorized to view it.
−Removed: validates permissions of all the users, and devices requesting access to any secure meeting room prior to granting access.
−Removed: We believe our War Room™ will be an attractive solution for government and law enforcement agencies as well as all
−Removed: professional sectors such as legal, financial, and medical where limiting access to confidential data is a critical requirement.
−Removed: Our VirnetX Matrix™ product provides superior security for internet-enabled enterprise applications and their connected devices, and for control systems currently deployed by those enterprises
−Removed: (e.g., file servers, data back-up systems, VPN/firewalls).
−Removed: VirnetX Matrix™ provides a true “zero-trust” access protection, “single-click” ease of use, and is a highly effective added layer of protection that is deployed simply, without the need for
−Removed: changes to an enterprise’s existing, in-place infrastructure.
−Removed: We believe VirnetX Matrix™ is an attractive solution for all businesses, cloud and on-premise application service providers, and original equipment manufacturers (OEMs), looking to
−Removed: improve visibility and management of their networks to mitigate morphing attacks on their networks and for real time access and control of their users.
−Removed: Our Digital Engineering (DE) services are designed to strengthen our current and evolving Model-Based Systems Engineering (MBSE) processes while also providing comprehensive Cyber Threat Assessment
−Removed: services seamlessly integrating into the DoW Digital Engineering strategy.
−Removed: Additionally, our DE professional services include integration of our subject matter expertise in kinetic and non-kinetic secure, automated, command and control, battle
−Removed: management, and all-domain collection sensor orchestration.
−Removed: With embedded secure communication from R&D to operational deployment, our Dynamic Trust Evaluation (DTE) methods continuously enforce real-time trust policies, ensuring resilient and
−Removed: adaptive network security.
−Removed: Our Cyber Threat Intelligence (CTI) and assessment services deliver context-aware insights, empowering defense leaders to anticipate and mitigate emerging cyber threats.
−Removed: We have undertaken activities to align our products and services with DoW’s Digital Engineering Strategy, and as such, plan to make available the following services to Federal, state, and local
−Removed: government agencies.
−Removed: DE services for embedding cybersecurity in system design, command and control processes, battle management, and all-domain sensor orchestration and lifecycle management to enhance system resilience by identifying
−Removed: vulnerabilities early via threat modeling and design.
−Removed: Advanced hybrid Cyber MBSE services for building artificial intelligence and machine learning (AI/ML) hybrid models to represent communication flows and threat boundaries using specialized VirnetX engineering to
−Removed: customize architectures in multi domain digital engineering projects.
−Removed: Cyber Threat Assessment services for providing systematic evaluation of cyber risks, vulnerabilities, and potential impacts on critical systems with threat modeling, risk prioritization, and AI/ML based defensive
−Removed: and offensive threat mitigation strategies.
−Removed: We are building our Center for Advanced Software/Hardware Integration, at our Farmington, Utah office, utilizing AI/ML and digital twin technology integrated with VirnetX’s SDNS technology.
−Removed: to further augment our product strategy to provide secure, dynamic cyber-driven, AI to the marketplace.
−Removed: In addition to our investments with L2 Holdings, LLC (OmniTeq), AI/ML solutions provider and OP Media, Inc, a dynamic software platform
−Removed: provider, we participated in a Cooperative Research and Development Agreement (CRADA) with the Air Force (AF) Research Laboratory Intelligence Systems Directorate (AFRL/RI) to facilitate collaboration on cybersecurity and Zero Trust technologies to
−Removed: support integrated surveillance and reconnaissance operations as well as AF and joint targeting processes.
−Removed: This CRADA continues through 2030 and allows us to apply for security clearances for our employees.
−Removed: We are also beginning to integrate AI/ML
−Removed: capabilities into VirnetX Matrix™ to enhance its zero-trust security, threat detection, and network resilience by enabling autonomous threat response, adaptive access control, and self-healing network architectures.
−Removed: We intend to sell directly to U.S.
−Removed: defense, intelligence and government agencies.
−Removed: We obtained a Multiple Award Schedule (MAS) contract, so we can sell our products, services, and solutions at
−Removed: pre-negotiated prices to Federal, state, and local government buyers.
−Removed: To strengthen our ability to support these markets, we have obtained DD Form 2345 certifications for our facilities in Zephyr Cove, Nevada, and Farmington, Utah.
−Removed: certification, formally known as the Militarily Critical Technical Data Agreement and administered by the DoW’s Joint Certification Program, enables us to access and share unclassified technical data with military or space applications subject to
−Removed: export controls under the Export Administration Regulations or the International Traffic in Arms Regulations.
−Removed: This certification is an essential step in ensuring that we can securely handle sensitive technical information while advancing
−Removed: opportunities with U.S.
−Removed: defense and government agencies.
−Removed: We intend to continue our activities to commercialize our products, services and intellectual property in and outside the United States including VirnetX One™, War Room™, VirnetX Matrix™ and our
−Removed: Secured Domain Name Registry and Technology.
−Removed: We believe our product portfolio to secure devices and systems are suitable in areas such as national defense, local, state, Federal and foreign governments, critical infrastructure, law enforcement,
−Removed: healthcare, finance, legal, oil and gas, medical, and related support industries.
−Removed: We continue to actively pursue new sales opportunities in and outside of the United States.
+Added: VirnetX Holding Corporation (“Company”, “we”, “us”, or “our”) is an Internet security software and technology company with patented cybersecurity solutions that are designed to ensure resilient,
+Added: secure communications across any network or device.
+Added: Our flagship platform, VirnetX One™, is built on Zero Trust Network Access (ZTNA) principles and extends our patented Secure Domain Name System (SDNS) technology to establish end-to-end encrypted
+Added: communications on demand, regardless of user location or endpoint.
+Added: VirnetX One™ operates as a security-as-a-service platform and may be deployed in cloud, on-premises, or hybrid enterprise environments.
+Added: The platform is designed to protect
+Added: applications, services, and infrastructure by providing an additional security layer that integrates with existing systems to reduce exposure to evolving cyber threats affecting data, operating systems, infrastructure components, and gateway
+Added: security controllers.
+Added: VirnetX Matrix™ leverages the VirnetX One™ platform to secure communications using encrypted, identity-based access controls, including in contested or high-risk environments.
+Added: It is designed to
+Added: protect internet-enabled enterprise applications, connected devices, and control systems, such as file servers, data backup systems, and VPN or firewall environments.
+Added: VirnetX Matrix™ is intended to be deployed without requiring material changes to
+Added: an enterprise’s existing infrastructure and provides centralized visibility and policy enforcement to address unauthorized access and evolving attack techniques.
+Added: VirnetX War Room™ also built on the VirnetX One™ platform, provides secure collaboration and visualization capabilities designed to support sensitive, unclassified but secure communications.
+Added: platform enables controlled access to virtual meeting environments by validating user and device permissions prior to granting access.
+Added: VirnetX War Room™ is intended for use cases where confidentiality and access control are critical, including
+Added: government, law enforcement, legal, financial, and healthcare environments.
+Added: Our products, including VirnetX One™, VirnetX Matrix™, and VirnetX War Room™, are designed to support U.S.
+Added: Department of Defense (DoD), federal government, and commercial customers requiring real-time
+Added: encrypted communications and network security.
+Added: Our solutions are designed to be applicable across a range of public and private sector markets, including critical infrastructure, law enforcement, healthcare, financial services, legal services,
+Added: energy, and related industries.
+Added: We pursue sales opportunities nationwide and engage with universities and academic institutions to support research collaboration, workforce development, and technology transition initiatives.
+Added: We also support international sales of our commercial products in compliance with applicable U.S.
+Added: export control laws and regulations, including the International Traffic in Arms Regulations (ITAR)
+Added: and the Export Administration Regulations (EAR).
+Added: Our compliance processes are designed to ensure that international transactions adhere to export control requirements while supporting authorized global customers.
+Added: Our technology focuses on system design and evaluation to address the continued growth of Internet of Things (IoT) and edge computing environments.
+Added: We are developing a federated, hybrid mesh network
+Added: architecture designed with security as a foundational element, extending secure networking capabilities to resource-constrained devices through obfuscated and lightweight security mechanisms designed to protect communications without exposing
+Added: underlying security processes.
+Added: These efforts support secure identity, trust enforcement, and encrypted communications for distributed and edge-based systems, aligning our architecture with the industry’s shift toward decentralized and resilient
+Added: network models.
+Added: This approach incorporates dynamic trust evaluation, autonomous recovery, and distributed decision-making to enhance network resilience and adaptability.
+Added: To support system design and evaluation, we employ Model-Based Systems Engineering (MBSE) and agent-based modeling methodologies.
+Added: These approaches enable simulation and analysis of complex systems,
+Added: including cyber-physical environments and adaptive networks, and support assessment of system behavior under evolving threat conditions.
+Added: Certain of our services are designed to align with the Department of Defense’s Digital Engineering Strategy (DE) by supporting cybersecurity integration across system design, command and control,
+Added: battle management, and sensor orchestration, and by enhancing our MBSE and cyber threat assessment capabilities.
+Added: Our Dynamic Trust Evaluation (DTE) methods are designed to enforce trust policies throughout system lifecycles, and our cyber threat
+Added: intelligence and assessment services provide structured analysis of cyber risks and vulnerabilities.
+Added: We intend to make available our digital engineering, cyber MBSE, and cyber threat intelligence services to federal, state, and local government agencies, subject to applicable contracting
+Added: requirements.
+Added: We hold a Multiple Award Schedule (MAS) and obtained DoD Joint Certification Program (DD Form 2345) certifications for our facilities in Zephyr Cove, Nevada, and Farmington, Utah, which permit access to certain unclassified technical
+Added: data subject to export controls.
+Added: These certifications streamline procurement of our products and services by federal, state, and local government agencies and support our ability to engage with government and defense customers while maintaining
+Added: compliance with applicable handling and security requirements.
+Added: Additionally, we are developing a Center for Advanced Software and Hardware Integration at our Farmington, Utah facility, that incorporates artificial intelligence (AI) and digital twin technologies
+Added: alongside our Software-Defined Networks (SDN) capabilities.
+Added: This facility is intended to support development and integration of secure, adaptive software solutions.
+Added: We have entered into strategic relationships, including an investment in L2
+Added: Holdings, LLC (OmniTeq), an AI/Machine Learning (ML) solutions provider, and cooperative agreements, including a Cooperative Research and Development Agreement (CRADA) with the Air Force Research Laboratory, Intelligence Systems Directorate
+Added: The CRADA focuses on cybersecurity and Zero Trust Network Access (ZTNA)-related technologies, extends through 2030, and supports collaboration in areas relevant to defense and intelligence operations.
+Added: In addition to federal, state, and local government agencies and defense customers, we pursue sales opportunities nationwide and engage with universities and academic institutions to support research
+Added: collaboration, workforce development, and technology transition initiatives.
+Added: We also support international sales of our commercial products in compliance with applicable U.S.
+Added: export control laws and regulations, including the International Traffic
+Added: in Arms Regulations (ITAR) and the Export Administration Regulations (EAR).
+Added: Our compliance processes are designed to ensure that international transactions adhere to export control requirements while supporting authorized global customers.
+Added: Our intellectual property portfolio is a core component of our business.
+Added: and foreign patents, as well as pending patent applications, that are primarily directed to securing real-time
+Added: communications over the Internet and related services.
+Added: These patents underpin our technology and products.
+Added: Certain portions of this portfolio were acquired by our principal operating subsidiary, VirnetX, Inc., from Leidos, Inc.
Our employees include the core development team behind our inventions, technology, and software.
Some members of this team have worked together for over twenty years and were on the same team that
−Removed: invented and developed this technology while working at Leidos, Inc., or Leidos.
+Added: invented and developed this technology while working at Leidos, Inc.
The team has continued its research and development work to refine our unique network security technology and make it more secure and easy to deploy.
−Removed: Our portfolio of intellectual property is the foundation of our business model.
−Removed: We currently own U.S.
−Removed: and foreign patents and pending applications.
−Removed: portfolio is primarily focused on securing real-time communications over the Internet, and related services, and is used in all our technology and products, some of which were acquired by our principal operating subsidiary, VirnetX, Inc., from
−Removed: Leidos in 2006.
−Removed: Results of Operation
−Removed: Three and Nine Months Ended September 30, 2025
−Removed: Compared with the Three and nine Months Ended September 30, 2024
+Added: Results of Operation s
+Added: Three Months Ended March 31, 2026
+Added: Compared with the Three Months Ended March 31, 2025
(in thousands, except per share amounts)
−Removed: We recognized revenue of $106 and $5 in the nine months ended September 30, 2025 and 2024.
+Added: We recognized no revenue in the three months ended March 31, 2026 and 2025.
Research and Development Expenses
−Removed: Our research and development expenses remained steady between 2025 and 2024 totaling $1,143 and $3,617 for the three and nine months ended September 30, 2025 compared to $1,176 and $3,667 for the
−Removed: three and nine months ended September 30, 2024.
+Added: Our research and development expenses remained steady between 2026 and 2025 totaling $1,162 and $1,259 for the three months ended March 31, 2026 and 2025, respectively.
Selling, General and Administrative Expenses
−Removed: Our selling, general and administrative expenses decreased from $3,213 in 2024 to $3,059 for the three months ended September 30, 2025, and decreased from $10,066 in 2024 to $8,624 for the nine months
−Removed: ended September 30, 2025.
−Removed: The decrease was related to legal fees incurred in 2024 to protect our patents;
−Removed: no similar costs were incurred in 2025.
−Removed: Loss on impairment of investment
−Removed: Effective September 30, 2025, we identified an impairment in our investment in OP Media Inc., and a result, we recognized an impairment loss
−Removed: totaling $500.
+Added: Our selling, general and administrative expenses increased from $2,788 to $3,346 for the three months ended March 31, 2026, primarily related to compensation expense and corporate travel.
Liquidity and Capital Resources
−Removed: As of September 30, 2025, our cash and cash equivalents totaled $17,129 and our short-term investments totaled $11,064, compared to cash and cash equivalents of $23,296 and short-term investments of
−Removed: $14,786 at December 31, 2024, respectively.
−Removed: Working capital was $26,363 at September 30, 2025, and $31,009 at December 31, 2024.
−Removed: We expect that our cash and cash equivalents and short-term investments as of September 30, 2025, will be sufficient to fund our current level of operating expenses and provide related working capital
−Removed: for the foreseeable future.
−Removed: Over the longer term, we expect to derive our future revenue from collaborating with others to integrate our family of cybersecurity products and services into their solutions and to resell them to their current and
−Removed: future customers as well as from license fees and royalties associated with our patent portfolio, technology, software and secure domain name registry.
−Removed: Our effective tax rate is 0% for income tax for the three and nine months ended September 30, 2025, and 2024, and we expect our effective tax rate for the full year will be 0%.
−Removed: Our effective tax rate
−Removed: is less than the 21% statutory tax rate primarily due to our valuation allowance.
+Added: As of March 31, 2026, the Company held approximately $17.2 million in cash, cash equivalents and short-term investments.
+Added: Based on the Company’s current rate of operating expenditures and without giving effect to any future financing or additional revenue, existing liquid resources are projected to be insufficient to sustain the current
+Added: level of operations through May 2027, a period of less than twelve months from the date of issuance of these financial statements.
+Added: This condition triggers the going concern disclosure requirements under U.S.
+Added: GAAP and as required, is described in
+Added: notes to our condensed consolidated financial statements.
+Added: Management intends to continue pursuit of cash generation via revenue sources and financing.
+Added: Our effective tax rate is 0% for income tax for the three months ended March 31, 2026 and 2025, and we expect our effective tax rate for the full year will be 0%.
+Added: Our effective tax rate is less than the 21% statutory
+Added: tax rate primarily due to our valuation allowance.
Based on the weight of available evidence, including net cumulative losses and expected future losses, we have determined it is more likely than not that our U.S.
−Removed: federal and state deferred tax assets will not be realized and therefore we have provided a full valuation allowance on the U.S.
+Added: federal and state deferred tax
+Added: assets will not be realized and therefore we have provided a full valuation allowance on the U.S.
federal and state net deferred tax assets.
1 unchanged sentence
We have leases in Nevada, Utah and California, the last of which expires in 2035.
−Removed: See Note 8 – Leases in the accompanying consolidated financial statements for details.
+Added: See Note 8 – Leases in the accompanying condensed consolidated financial statements for details.
Off-Balance Sheet Arrangements
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.