- MANAGEMENT'S DISCUSSION AND ANALYSIS OF FINANCIAL CONDITION AND RESULTS OF OPERATIONS.
Company Overview
VirnetX Holding Corporation ("Company", "we", "us", or "our") is an Internet security software and technology company with patented cybersecurity solutions that are designed to ensure resilient, secure communications across any network or device.
Our flagship platform, VirnetX One™, is built on Zero Trust Network Access (ZTNA) principles and extends our patented Secure Domain Name System (SDNS) technology to establish end-to-end encrypted communications on demand, regardless of user location or endpoint. VirnetX One™ operates as a security-as-a-service platform and may be deployed in cloud, on-premises, or hybrid enterprise environments. The platform is designed to protect applications, services, and infrastructure by providing an additional security layer that integrates with existing systems to reduce exposure to evolving cyber threats affecting data, operating systems, infrastructure components, and gateway security controllers.
VirnetX Matrix™ leverages the VirnetX One™ platform to secure communications using encrypted, identity-based access controls, including in contested or high-risk environments. It is designed to protect internet-enabled enterprise applications, connected devices, and control systems, such as file servers, data backup systems, and VPN or firewall environments. VirnetX Matrix™ is intended to be deployed without requiring material changes to an enterprise's existing infrastructure and provides centralized visibility and policy enforcement to address unauthorized access and evolving attack techniques.
VirnetX War Room™ is also built on the VirnetX One™ platform, provides secure collaboration and visualization capabilities designed to support sensitive, unclassified but secure communications. The platform enables controlled access to virtual meeting environments by validating user and device permissions prior to granting access. VirnetX War Room™ is intended for use cases where confidentiality and access control are critical, including government, law enforcement, legal, financial, and healthcare environments.
Our products, including VirnetX One™, VirnetX Matrix™, and VirnetX War Room™, are designed to support U.S. Department of Defense (DoD), federal government, and commercial customers requiring real-time encrypted communications and network security. Our solutions are designed to be applicable across a range of public and private sector markets, including critical infrastructure, law enforcement, healthcare, financial services, legal services, energy, and related industries. We pursue sales opportunities nationwide and engage with universities and academic institutions to support research collaboration, workforce development, and technology transition initiatives.
VirnetX iSCOUT (IoT System for Connected Object Understanding and Telemetry) leverages a common, secure IoT and data infrastructure to fuse sensor, geospatial, and agency data into a unified operating picture, including in disaster response and smart city environments. It is designed to support mission-specific applications that can be customized for a range of markets, with two initial implementations currently in development: a Humanitarian Assistance Disaster Relief-Emergency Response (HADR-ER) capability that provides federal, state, and local partners with a real-time operating picture for national emergency management, and a smart city solution for international markets, including Japan, tailored to urban resilience, mobility, and critical infrastructure monitoring in dense metropolitan environments. VirnetX iSCOUT is intended to be deployed as a shared, exportable technology stack, with each application configured for its distinct mission, and we may pursue additional customized applications for other markets in the future.
We also support international sales of our commercial products in compliance with applicable U.S. export control laws and regulations, including the International Traffic in Arms Regulations (ITAR) and the Export Administration Regulations (EAR). Our compliance processes are designed to ensure that international transactions adhere to export control requirements while supporting authorized global customers.
Index
Our technology focuses on system design and evaluation to address the continued growth of Internet of Things (IoT) and edge computing environments. We are developing a federated, hybrid mesh network architecture designed with security as a foundational element, extending secure networking capabilities to resource-constrained devices through obfuscated and lightweight security mechanisms designed to protect communications without exposing underlying security processes. These efforts support secure identity, trust enforcement, and encrypted communications for distributed and edge-based systems, aligning our architecture with the industry's shift toward decentralized and resilient network models. This approach incorporates dynamic trust evaluation, autonomous recovery, and distributed decision-making to enhance network resilience and adaptability.
To support system design and evaluation, we employ Model-Based Systems Engineering (MBSE) and agent-based modeling methodologies. These approaches enable simulation and analysis of complex systems, including cyber-physical environments and adaptive networks, and support assessment of system behavior under evolving threat conditions.
Certain of our services are designed to align with the Department of Defense's Digital Engineering Strategy (DE) by supporting cybersecurity integration across system design, command and control, battle management, and sensor orchestration, and by enhancing our MBSE and cyber threat assessment capabilities. Our Dynamic Trust Evaluation (DTE) methods are designed to enforce trust policies throughout system lifecycles, and our cyber threat intelligence and assessment services provide structured analysis of cyber risks and vulnerabilities.
We intend to make available our digital engineering, cyber MBSE, and cyber threat intelligence services to federal, state, and local government agencies, subject to applicable contracting requirements. We hold a Multiple Award Schedule (MAS) and obtained DoD Joint Certification Program (DD Form 2345) certifications for our facilities in Zephyr Cove, Nevada, and Farmington, Utah, which permit access to certain unclassified technical data subject to export controls.
Additionally, we are developing a Center for Advanced Software and Hardware Integration at our Farmington, Utah facility, that incorporates artificial intelligence (AI) and digital twin technologies alongside our Software-Defined Networks (SDN) capabilities. This facility is intended to support development and integration of secure, adaptive software solutions. We have entered into strategic relationships, including an investment in L2 Holdings, LLC (OmniTeq), an AI/Machine Learning (ML) solutions provider, and cooperative agreements, including a Cooperative Research and Development Agreement (CRADA) with the Air Force Research Laboratory, Intelligence Systems Directorate (AFRL/RI). The CRADA focuses on cybersecurity and Zero Trust Network Access (ZTNA)-related technologies, extends through 2030, and supports collaboration in areas relevant to defense and intelligence operations.
In addition to federal, state, and local government agencies and defense customers, we pursue sales opportunities nationwide and engage with universities and academic institutions to support research collaboration, workforce development, and technology transition initiatives. We also support international sales of our commercial products in compliance with applicable U.S. export control laws and regulations, including the International Traffic in Arms Regulations (ITAR) and the Export Administration Regulations (EAR). Our compliance processes are designed to ensure that international transactions adhere to export control requirements while supporting authorized global customers.
Our intellectual property portfolio is a core component of our business. We own U.S. and foreign patents, as well as pending patent applications, that are primarily directed to securing real-time communications over the Internet and related services. These patents underpin our technology and products. Certain portions of this portfolio were acquired by our principal operating subsidiary, VirnetX, Inc., from Leidos, Inc. in 2006.
Our employees include the core development team behind our inventions, technology, and software. Some members of this team have worked together for over twenty years and were on the same team that invented and developed this technology while working at Leidos, Inc. The team has continued its research and development work to refine our unique network security technology and make it more secure and easy to deploy.
Index
Results of Operations
Three and Six Months Ended June 30, 2026
Compared with the Three and Six Months Ended June 30, 2025
(in thousands, except per share amounts)
Revenue
We recognized revenue $48 in the three months and six months ended June 30, 2025 and no revenue during the same periods in 2026.
Research and Development Expenses
Our research and development expenses decreased slightly in 2026 compared to 2025, totaling $1,126 and $1,215 for the three months ended June 30, 2026 and 2025, and totaling $2,288 and $2,474 for the six months ended June 30, 2026 and 2025. The decrease was related to compensation.
Selling, General and Administrative Expenses
Our selling, general and administrative expenses increased $749 and $1,308 in the three and six months ended June 30, 2026 compared to 2025. The variance was primarily related to increases of $388 in legal expenses, $362 in equity compensation, and $395 in travel expense.
Liquidity and Capital Resources
As of June 30, 2026, our cash and cash equivalents totaled approximately $13,090 and our short-term investments totaled approximately $799, compared to cash and cash equivalents of approximately $15,548 and short-term investments of approximately $5,979 at December 31, 2025, respectively. Working capital was $11,847 at June 30, 2026.
Based on the Company's current rate of operating expenditures and without giving effect to any future financing or additional revenue, existing liquid resources are projected to be insufficient to sustain the current level of operations for twelve months from the date of issuance of these financial statements. This condition triggers the going concern disclosure requirements under U.S. GAAP and as required, is described in notes to our condensed consolidated financial statements. Management intends to continue pursuit of cash generation via revenue sources and financing.
On June 2, 2026, the SEC declared our shelf registration statement of Form S-3 effective (File No. 333-295960). The S-3 covers the offer and sale up to $20 million in securities in one or more offerings, in amounts, at prices and on terms determined at the time of the offering.
Income Taxes
Our effective tax rate is 0% for income tax for the three and six months ended June 30, 2026 and 2025, and we expect our effective tax rate for the full year will be 0%. Our effective tax rate is less than the 21% statutory tax rate primarily due to our valuation allowance. Based on the weight of available evidence, including net cumulative losses and expected future losses, we have determined it is more likely than not that our U.S. federal and state deferred tax assets will not be realized and therefore we have provided a full valuation allowance on the U.S. federal and state net deferred tax assets.
Contractual Obligations
We have leases in Nevada, Utah and California, the last of which expires in 2035. See Note 8 - Leases in the accompanying condensed consolidated financial statements for details.
Index
Off-Balance Sheet Arrangements
None.