Unit Economics
The metrics that move a cyber software valuation are a small set of numbers — ARR growth, NRR, Rule of 40, gross retention, CAC payback, magic number, and burn multiple. This section covers what each measures, the 2026 benchmark, how they interact, and how they read in diligence. Valuation multiples (page 12) are an output; these unit economics are the inputs, and the multiple can be derived from them rather than lifted from a comp.
For most of the last decade the operating rule was "growth at all costs": a company growing 40% with a −5% margin out-valued one growing 10% with a +35% margin. In 2026 that shifted. The profitability-weighted reading of Rule of 40 now prevails — "a company scoring 45 with 10% growth and 35% margin is often more attractive than one with 40% growth and 5% margin" (Beancount.io, May 2026). The same dataset shows the elite cohort — high NRR and fast CAC payback — averaging 71% growth and a 47 Rule-of-40 score (Beancount.io). The implication: a cyber asset can no longer be valued on growth rate alone; how efficiently that growth was bought matters, and the efficiency metrics below are where the multiple is set.
The metric hierarchy: one headline number, then the quality stack
Not all metrics are equal. ARR and its growth rate is the headline — it is the first number any buyer asks for, and a $10M-ARR company growing 40% is a fundamentally different asset from one growing 10%, often 3–4× the multiple. But growth alone can mislead: it can be bought (with unsustainable CAC) or rented (with churn underneath expansion). The rest of the stack answers whether the growth is durable and efficient. The metrics fall into two groups — retention (is revenue sticky?) and efficiency (what did the growth cost?).
| Metric | What it measures | 2026 benchmark | Elite | Why it moves the multiple |
|---|---|---|---|---|
| ARR growth % | Pace of recurring-revenue expansion | Varies by scale; 20%+ at >$1B ARR is uncommon | Top names 25%+ at scale | The single biggest multiple driver — but only with the quality stack below |
| Net Revenue Retention (NRR) | Expansion − churn − contraction within the existing base | Median ~101% (compressed) | 111%+; enterprise (>$100K ACV) median 118% | Durability signal under the growth number; >120% is "land-and-expand works" |
| Gross Revenue Retention (GRR) | Retention before expansion (pure stickiness) | ~85–90% SaaS; higher for mission-critical | 90%+ | Strips the flattery out of NRR; the true churn floor |
| Rule of 40 | Growth % + FCF (or EBITDA) margin % | ≥40 is the bar; market now favors the profit-weighted read | Leaders 45–78 | The single best one-number quality screen post-2026 reset |
| CAC payback | Months to recover customer-acquisition cost | Median 15–18 months | <12 months | How efficiently growth is bought; long payback = growth on credit |
| Magic number | New ARR ÷ prior-period S&M spend | ~0.7+ acceptable; >1.0 efficient | >1.0 | Sales-efficiency read; complements CAC payback |
| Burn multiple | Net cash burned ÷ net new ARR | <1.5 good; <1.0 elite | <1.0 | The 2026 capital-efficiency metric — dollars burned per dollar of ARR added |
Benchmarks: NRR median ~101%, top 111%+, enterprise 118% / mid-market 108% / SMB 97% (DigitalApplied, 2026); CAC payback median 15–18 mo, elite <12 (Beancount.io). Security land-and-expand public names routinely report NRR 113–125% (SaaS Capital Efficiency, 2026).
NRR — the defining retention metric, and its limits
Net Revenue Retention is the most important durability number and also the most flattering. It nets three things inside the existing customer base over a year: expansion (upsell, cross-sell, seat growth, consumption) minus churn (logos lost) minus contraction (downgrades). NRR >100% means the existing base grows even with zero new logos — the engine behind every "land-and-expand" cyber story, and why the strongest names compound through a downturn.
But NRR has a structural limitation: it can hide churn behind expansion. A company can post 115% NRR while losing 15% of its logos a year, because a handful of large accounts expanding fast can mask a leaky base. This is why a rigorous read pairs NRR with GRR (gross retention): GRR strips out expansion and shows the underlying stickiness floor. NRR 120% / GRR 90% is a healthy land-and-expand machine; NRR 120% / GRR 75% is a leaky bucket masked by a few large accounts — a very different risk profile in diligence, and the kind of thing a buyer's commercial due diligence (34) is built to surface.
The 2026 position: median NRR has compressed to ~101% from the 110%+ norm of the 2021 cohort, while the elite hold 111%+ and enterprise-grade cyber names (high ACV, mission-critical) still run 118%+ (DigitalApplied). The dispersion is what matters — retention quality, not just growth, now separates the premium names.
Rule of 40 — the one-number quality screen
Rule of 40 holds that a healthy software company's growth rate % + profit margin % should clear 40. Its value is that it forces the growth-vs-profitability trade into a single comparable number: a 60%-growth / −25%-margin hyper-grower (35) and a 15%-growth / 30%-margin compounder (45) are directly rankable. Post-2026-reset, the market reads it profitability-weighted — rewarding the quality of the 40, not just the level. Two cautions: (1) use FCF margin, not adjusted-EBITDA framing, or the score flatters; (2) Rule of 40 is a scale metric — sub-$10M-ARR companies should be growing far faster than 40 alone, so an early-stage target should not be allowed to mask a weak growth rate behind a thin profit. The leaders clear the bar comfortably: Zscaler posted a ~78 Rule-of-40 in a recent quarter — one of a handful of >$3B-ARR names still growing 25%+ (Finro Q2 2026).
Efficiency: CAC payback, magic number, burn multiple — what the growth cost
Growth is only as good as what was paid for it. Three metrics triangulate efficiency:
- CAC payback — months of gross margin to recover the cost of landing a customer. 2026 median 15–18 months; elite <12 (Beancount.io). Long payback isn't fatal for enterprise deals with high NRR (you recover it on expansion), but a long payback with low NRR is growth bought on credit — the worst combination in diligence.
- Magic number — net new ARR ÷ prior-quarter S&M. >1.0 means each sales dollar returns more than a dollar of ARR within a year; ~0.7 is the acceptable floor. It is the go-to-market efficiency read that complements CAC payback.
- Burn multiple — net cash burned ÷ net new ARR. The defining capital-efficiency metric of the post-2021 era: <1.0 is elite (less than a dollar burned per dollar of ARR added), <1.5 acceptable, >2.0 a red flag. It is the single fastest way to see whether a "fast-growing" private cyber company is actually efficient or is simply converting venture dollars into ARR at a loss.
The interaction matters: NRR and CAC payback move together. Companies that combine high NRR with fast payback are the ones averaging 71% growth and 47 Rule-of-40 (Beancount.io) — because high retention means the expensive-to-acquire customer keeps paying and expanding, which shortens effective payback and compounds the LTV. That virtuous loop is what a premium cyber multiple is actually pricing.
From metrics to multiple — how the inputs set the output
| Profile | Reads like | Multiple posture |
|---|---|---|
| Premium platform | 25%+ growth at scale, NRR 118%+, R40 50+, payback <12mo, burn <1.0 | Top of the public ladder — the PANW/CRWD/ZS tier |
| Quality single-platform | 20–35% growth, NRR 110–120%, R40 40+, payback ~12–15mo | Premium-but-dispersed; re-rates on durability |
| Efficient compounder | 10–18% growth, NRR ~105%, R40 45+ on profit, payback <15mo | Re-rated up in 2026 for FCF quality |
| Sugar-high grower | 40%+ growth, NRR <105%, GRR <80%, payback >20mo, burn >2.0 | Discounted — growth without durability or efficiency |
| Leaky bucket | NRR >110% but GRR <80% (whale-dependent) | Diligence discount — expansion masking churn |
The core analytical move is to build the multiple from the metrics rather than quoting a comp and back-fitting the story. Two "endpoint" companies can trade three turns apart purely on growth × retention × efficiency; when a target's metrics do not match its chosen comp, the comp is wrong.
→ Cross-references: Economics, TAM & Market Sizing, Valuation Benchmarks, Public Trading Comps, Commercial Due Diligence, Why Most Acquisitions Fail, Earnings & Cyber Signals.
Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.