Blog

Patent Litigation Tactics for Cybersecurity Companies: Challenging Patents at the Patent Office

Fish & Richardson

Authors

This article expands on “Tactic No. 5: Launch a counter strike at the patent office” from our previously published article “Five Tactics for Cybersecurity Companies to Defeat Patent Infringement Claims.” It is the final installment in the series.

For more than a decade, inter partes review (IPR) under the America Invents Act (AIA) has been the defining tool for challenging patent validity at the U.S. Patent and Trademark Office (USPTO), and it was the focus of Tactic No. 5 in our original article. But the landscape has shifted dramatically. A wave of changes to how the USPTO exercises its discretion to institute IPRs, culminating in the “settled expectations” doctrine and the centralization of institution decisions in the Director, has reduced IPR institution rates. As a result, challengers have increasingly turned to two alternatives: post-grant review (PGR) and ex parte reexamination (EPRx).

Here, we recap the mechanics of IPR, explain the recent changes reshaping IPR practice, and outline how a cybersecurity company weighing a validity challenge at the USPTO should now consider IPR, PGR, and EPRx side by side.

Key points

  • IPR remains a powerful mechanism for challenging patent validity on novelty and obviousness grounds, but institution has become less reliable due to an increased application of USPTO Director discretion to deny petitions for IPR.
  • With IPR institution harder to obtain, EPRx filings have surged and now make up the majority of post-grant validity challenges.
  • PGR remains a potent option for challenging recently issued patents, including on grounds unavailable in IPR.

IPR in brief

IPR is conducted before the Patent Trial and Appeal Board (PTAB). An IPR petitioner (in many cases the defendant in a district court patent infringement action) may challenge one or more claims of an issued patent only on novelty (35 U.S.C. § 102) and obviousness (§ 103) grounds, and only on the basis of prior-art patents and printed publications. A petitioner served with an infringement complaint in district court must file its petition for IPR within one year of service of the complaint. The PTAB institutes review only if a petition shows a “reasonable likelihood” that the petitioner will prevail on at least one challenged claim, and it has a mandate to issue a final written decision within one year of institution.

As our original article explained, IPR offers several tangible advantages over district court litigation: It is generally faster and less expensive, it is governed by the lower “preponderance of the evidence” burden rather than the “clear and convincing evidence” standard, and it is decided by technically trained administrative patent judges. An IPR that is instituted and results in a final written decision also carries estoppel, meaning that the petitioner cannot later raise in district court or any other forum any ground it “raised or reasonably could have raised” in the IPR. Those features still hold. What has changed is the threshold question of whether the USPTO will agree to institute the review.

The shifting discretionary denial landscape

The most consequential recent development in IPR is not a change in the law but to how the USPTO decides whether to institute IPR in the first place. The Director has advanced broad, largely unreviewable discretion to deny institution, and the Office now exercises that discretion increasingly often. As such, many petitions are being denied on discretionary grounds without an evaluation or consideration of the merits.

Two features of the current regime have had a significant impact:

  • Institution is a centralized, Director-level decision. The Director personally decides whether to institute IPR, frequently through notice-based decisions. A petitioner should not necessarily expect a merits-focused panel to reach its arguments; the discretionary decision comes first and can end the matter.
  • A broad list of discretionary factors applies. In deciding whether to deny institution, at least the following factors are weighed by the Director:
    • Whether a parallel district court or International Trade Commission proceeding is likely to resolve the same validity issues first
    • Whether another forum has already adjudicated validity
    • Whether the petitioner has filed serial or multiple petitions against the same patent
    • Whether the petitioner has taken inconsistent claim-construction positions across forums
    • How heavily the petition relies on expert testimony
    • The parties’ U.S. manufacturing activity
    • The “settled expectations of the parties, such as the length of time the claims have been in force.”

The “settled expectations” factor

The final factor – settled expectations – implicates the age of a patent subject to challenge. Conceptually, once a patent has been in force for some number of years, the patent owner and the public are said by the Director to develop reliance interests that a later validity challenge would upset.

The factor was first applied in June 2025 decisions and its scope was quickly extended. Early decisions denied institution for patents in force roughly eight years (in at least one case regardless of whether the petitioner knew of the patent during that period), and a later decision reached a patent only about three years old. While there is no bright-line rule on when expectations become “settled,” recent decisions indicate that roughly six years is sufficient.

Why this matters for cybersecurity companies

Cybersecurity companies are frequently sued by non-practicing entities (NPEs) asserting older software patents, so the settled expectations factor might frustrate attempts by Cybersecurity companies to leverage the PTAB. A patent that would historically have been a strong candidate for IPR review on the merits may now draw a discretionary denial because it has been in force for several years. That reality is a primary reason to evaluate the alternatives below.

Why consider EPRx?

EPRx is the most widely available of the three tools. Any person may ask the USPTO’s Central Reexamination Unit to reexamine an issued patent at any time during its enforceability based on prior-art patents and printed publications that raise a “substantial new question of patentability.”

A cybersecurity defendant might choose it for several reasons:

  • Lower discretionary denial risk. EPRx generally is not subject to the IPR discretionary denial framework. However, EPRx requests are vulnerable to discretionary denial under 35 U.S.C. § 325(d) if they present the same or substantially the same prior art or arguments previously presented to the USPTO, including in a discretionarily denied IPR petition.
  • It creates no petitioner estoppel. EPRx does not trigger the statutory estoppel that attaches to IPR. As such, EPRx may enable probing a patent’s weaknesses while preserving certain invalidity defenses for litigation.
  • It is lower in cost and complexity. There is no adversarial discovery, no depositions, and no oral hearing between the parties.
  • It has no page or word limit. Unlike an IPR petition, which is capped by a strict word count, a reexamination request has no length limit, so a requester can advance multiple prior-art grounds and mount a more robust challenge.
  • Anonymity is available. A party may request reexamination through a registered practitioner and remain anonymous for the duration of the proceeding.

The trade-offs are significant. After filing, the requester has essentially no ongoing role absent exceptional circumstances (the proceeding is between the patent owner and the examiner), so the challenger cannot rebut the patent owner’s arguments as the reexamination unfolds.

Why consider PGR?

PGR is the broadest of the three tools but it is time-limited. A petitioner may challenge a patent within nine months of its issuance, but only for patents subject to the AIA (generally, those with an effective filing date on or after March 16, 2013). Unlike IPR and EPRx, PGR is not confined to novelty and obviousness based on patents and printed publications. It allows challenges on essentially any ground of invalidity, including patent eligibility under § 101 and written description and enablement under § 112. While this breadth enables challenges on a wider range of issues, it likewise expands the scope of estoppel applicable to petitioners that receive unfavorable final written decisions on the merits.

A cybersecurity company might consider PGR for a few reasons:

  • It reaches broader grounds, including § 101. Because many cybersecurity patents are vulnerable to eligibility challenges (the subject of the prior article in this series), PGR can combine a § 101 attack with prior-art grounds in a single proceeding.
  • It allows early resolution. For a competitor’s recently issued patent, PGR allows a challenge before the patent has been asserted and before it has aged into settled expectations territory.

There are trade-offs, however. The nine-month window may close before a company knows it has a problem; as noted, PGR carries the broadest estoppel of the three proceedings; and it runs through some of the same discretionary denial factors as IPR, although settled expectations arguments do not apply for recently issued patents.

Choosing among IPR, EPRx, and PGR

No single tool is right for every case. The choice turns on timing, the grounds available, the tolerance for estoppel, and, increasingly, exposure to discretionary denial.

  • Timing. PGR is available only in the first nine months after issuance of the patent; IPR opens after that window and must be filed within one year of being served with an infringement complaint; EPRx is available at essentially any time during enforceability.
  • Grounds. IPR and EPRx are limited to §§ 102 and 103 based on patents and printed publications; PGR reaches any ground, including §§ 101 and 112.
  • Estoppel and participation. IPR and PGR are adversarial proceedings that create estoppel but allow the challenger to participate fully; EPRx creates no requester estoppel but gives the requester no role after filing.
  • Discretionary denial exposure. IPR and PGR institution now runs through the Director’s discretionary framework, including settled expectations; EPRx is not subject to that framework but remains subject to § 325(d) discretion.

For a cybersecurity company facing an older, litigation-worn patent, EPRx may now be the most reliable route to review, even though it offers the least control. For a recently issued patent, PGR’s breadth (especially the ability to raise § 101) can be decisive. And where a patent is neither brand new nor especially old and the prior art is strong, IPR remains a formidable option, provided the petitioner is prepared to address the discretionary denial factors head-on.

Timing and procedural considerations

  • Mind the deadlines. The one-year IPR bar (running from service of an infringement complaint) and the nine-month PGR window (running from issuance of the patent) are strict. EPRx has no comparable deadline but, like IPR and PGR, is most useful when filed early enough to support a motion to stay a district court case.
  • Brief discretion affirmatively. Because the discretionary decisions in IPR and PGR come first, a petitioner should assume the patent owner will seek discretionary denial and should address the discretionary factors, including settled expectations, directly in or alongside the petition rather than waiting to respond.
  • Coordinate with the litigation. A post-grant validity challenge can support a motion to stay a district court case, but the strength of that argument depends on timing and the type of proceeding chosen.

Example

Consider a cybersecurity company sued in district court by an NPE asserting a software patent for detecting network intrusions. The company locates strong prior-art publications predating the patent.

  • If the patent issued within the last nine months, the company can consider PGR, allowing it to combine those prior-art grounds with a § 101 eligibility challenge in a single proceeding.
  • If the patent is a few years old, the company may file an IPR within one year of being served with the complaint, but should expect the patent owner to argue settled expectations and should brief that issue up front, marshaling facts showing the challenge is timely and that no factors justify denial.
  • If the patent has been in force for many years, an IPR may face a substantial risk of discretionary denial on settled expectations grounds. EPRx, which does not run through that framework and creates no estoppel, may offer a more dependable path to having the prior art considered at the cost of the company’s ability to participate once the proceeding is underway.

Strategic considerations for cybersecurity companies

Proactive steps before litigation:

  • Monitor competitor and NPE patents early while PGR’s nine-month window is still open and before settled expectations arguments have a chance to harden.
  • Maintain a prior-art library. The technical literature, open-source projects, and prior products that populate the cybersecurity field are fertile sources of §§ 102 and 103 art.
  • Track the age and enforcement history of patents of concern, because a patent’s time in force now bears directly on whether IPR is a realistic option or whether EPRx is the better vehicle.

Defensive steps once a case is filed:

  • Evaluate all three tools together at the outset rather than defaulting to IPR.
  • Address discretionary denial, especially settled expectations, as a first-order issue in any IPR petition.
  • Consider EPRx where the patent’s age makes IPR institution unlikely, or where preserving litigation defenses by avoiding estoppel is a priority.
  • Coordinate the chosen proceeding with a potential motion to stay and with the company’s positions in any Rule 12(b) motions to maintain consistency across forums.

Takeaways

A counter strike at the patent office remains one of the most valuable tools in a cybersecurity defendant’s arsenal, but it is no longer synonymous with IPR. The rise of expanded discretionary denials and the settled expectations doctrine have made IPR institution less certain, particularly for the older software patents that NPEs often assert against cybersecurity companies. In response, the center of gravity has shifted toward EPRx, while PGR retains a valuable, albeit narrow, role for recently issued patents and for eligibility-based challenges. The best strategy today is to evaluate IPR, EPRx, and PGR together, matching the tool to the patent’s age, the grounds available, and the company’s tolerance for estoppel and discretionary denial risk.

This concludes our series on patent litigation tactics for cybersecurity companies. For the overview that began it, see “Five Tactics for Cybersecurity Companies to Defeat Patent Infringement Claims.”


Special thanks to Principals Karl RennerUsman Khan, and Kristi Sawert for their contributions to this article.