- 2 -
Part I
- 3 -
Item 1. Business
General
Palo Alto Networks, Inc. is a global artificial intelligence (“AI”) cybersecurity provider and our vision is a world where each day is safer and more secure than the one before. We were incorporated in 2005 and are headquartered in Santa Clara, California.
Our mission is to be the cybersecurity partner of choice, protecting our digital way of life. Our platforms and services help secure enterprise users, networks, clouds, endpoints, AI apps and agents, and identities by delivering comprehensive cybersecurity backed by AI and automation, and provide real-time visibility and monitoring across cloud infrastructure, applications and AI workloads. A key element of our strategy is to help our customers simplify their security architectures through consolidating disparate point products. We execute on this strategy by developing our capabilities and packaging our offerings into platforms, which are able to cover many of our customers’ needs in the markets in which we operate. Our platformization strategy combines various products and services into a tightly integrated architecture for more secure, faster, and cost-effective outcomes.
Network & AI Security
Our Network & AI Security platform is designed to deliver complete zero trust solutions to our customers. The platform includes:
- Secure Access Service Edge (“SASE”). Prisma® Access, when combined with Prisma SD-WAN, provides a comprehensive AI-powered SASE solution that secures users, branches, data, AI apps and agents from the most evasive threats in the new AI landscape. Our Prisma Browser™ further extends zero-trust security and data protection to the browser, where the majority of work is done today, providing users with the freedom to work securely using our secure browser from any device.
- Next-Generation Firewalls. Our ML-Powered Next-Generation Firewalls (“NGFWs”) secure on-premises environments including campus locations and data centers. Our software NGFWs secure virtual and cloud networks.
- Cloud-Delivered Security Services (“CDSS”). Our network security platform integrates a suite of Precision AI powered security capabilities that complements our SASE and NGFW solutions. These include Advanced Threat Prevention, Advanced WildFire®, Advanced URL Filtering, Advanced DNS Security, Device Security, Quantum Security, Next-Gen Trust Protection (“NGTS”), GlobalProtect®, Prisma Access Agent, Enterprise Data Loss Prevention (“Enterprise DLP”), Software as a Service (“SaaS”) Security, and AI Access Security™. Through these add-on services, our customers are able to secure their content, applications, users, devices, and connection across their entire organization.
- Prisma AIRS. Prisma AIRS™ is our comprehensive AI security platform designed to help organizations discover, assess, and protect AI agents, applications, models and data across the AI lifecycle. It supports key enterprise use cases, including securing AI-assisted software development, protecting custom AI applications from development through runtime, and governing autonomous AI agents. Prisma AIRS™ brings together AI Gateway, Agent Security, AI Red Teaming, AI Runtime Security™, AI Model Security, and AI Posture Management in a unified platform. These capabilities provide visibility into AI assets and activity, assess risks before deployment, and enforce security controls during live AI interactions and agent actions.
- Strata Cloud Manager (“SCM”). SCM is our AI-powered unified network security management and operations solution. It enables customers to manage and monitor their NGFW and SASE environments through a single, streamlined interface. SCM helps customers centrally manage configurations and security policies, assess security posture and network health, and streamline troubleshooting and remediation. It includes Strata Copilot, which offers a natural language interface for actionable insights and guided remediation, and integrates Autonomous Digital Experience Monitoring (“ADEM”) to help customers monitor and improve end-user performance across the enterprise.
Cortex
Our AI-powered Cortex® platform transforms end-to-end security operations and observability with unified data, AI, and automation for more secure, faster, and cost effective outcomes.
- Security Operations. We deliver the next generation of security operations capabilities that unifies standalone Security Information and Event Management (“SIEM”) tools, endpoint security, security automation, cloud detection and response (“CDR”), as well as attack surface management (“ASM”) capabilities on our Cortex platform. These include Cortex XSIAM®, for AI-powered security operations replacing traditional SIEM tools; Cortex XDR®, for the prevention, detection, and response to complex cybersecurity attacks; Cortex XSOAR®, for security orchestration, automation, and response (“SOAR”); Cortex Xpanse®, for ASM; and Koi Agentic Endpoint Security. Additionally, Cortex XSIAM integrates with the Chronosphere Telemetry Pipeline to ingest and optimize massive data volumes, promoting cost-effective scaling of autonomous operations.
- 4 -
- Cloud Security. We deliver comprehensive security across the cloud application development lifecycle through Cortex Cloud®, delivered as a scalable SaaS offering. As a comprehensive Cloud Native Application Protection Platform (“CNAPP”) combined with CDR, Cortex Cloud secures multi- and hybrid-cloud environments for applications, data, generative AI (“GenAI”) ecosystem, and the cloud native technology stack across the full development lifecycle, from code to cloud to security operations. As part of the Cortex Cloud platform, customers can expand from Cortex Cloud to our security operations offerings available on a single user experience and unified agent. We also offer our VM-Series and CN-Series virtual firewalls for inline network security on multi- and hybrid-cloud environments.
- Observability. Chronosphere, our next-generation observability platform, delivers real-time visibility and monitoring across cloud-native infrastructure, applications, and AI workloads. Purpose-built to handle the massive data volumes of the AI era, Chronosphere enables organizations to maintain system resilience and uptime with high cost-efficiency and reliability. Our observability platform provides comprehensive visibility into complex digital environments and automated troubleshooting of issues. It allows customers to transition from passive monitoring to proactive management of their entire digital estate. Our telemetry pipeline acts as an intelligent control layer that filters, transforms, and routes data. This helps reduce data volumes, enabling customers to cost-effectively scale their security and observability posture.
Idira
Idira™, our next-generation identity security platform, is designed to secure human, agentic, and machine identities across the enterprise with intelligent privilege controls and continuous threat prevention. By unifying identity access management, privilege access management, and identity governance and administration, organizations can continuously discover and protect against identity risk throughout the end-to-end identity lifecycle. The platform includes:
- Workforce Identity Security. Our solutions apply identity assurance and modern access controls for the entire workforce, including through adaptive multi-factor authentication (“MFA”), single sign-on (“SSO”), secure browsing, web session protection, workforce password management, and automated identity lifecycle management. Our approach enforces least privilege by elevating access only when required.
- Information Technology (“IT”) and Developer Identity Security (Modern Privilege Access Management). Our solutions secure high-risk access for IT administrators, third-party vendors, developers, and cloud operations teams across hybrid and multi-cloud environments, delivering just-in-time privileged access, session isolation, credential protection, and zero standing privileges, while providing native, secure access to cloud services, workloads, and development and operations pipelines. Organizations can eliminate excessive permissions, automate access to dynamic cloud resources, and maintain developer velocity while strengthening identity controls across infrastructure and application environments.
- Machine Identity Security. Our solutions secure the growing volume of non-human identities—such as workloads, applications, containers, service accounts, certificates, and keys, including through centralized discovery and management of secrets, certificate lifecycle automation, workload identity issuance, public key infrastructure-as-a-service, Kubernetes certificate management, and secure code signing.
- Identity Governance and Administration (“IGA”). IGA enables visibility into entitlements, automated joiner–mover–leaver processes, access certification, and ongoing identity compliance. AI-supported policy automation helps organizations govern access at scale and enforce a zero-trust model across all identities.
- AI Agents Security. Our solution discovers AI agents, assigns identity attributes, and restricts their access to task-specific resources. It helps monitor and record agent activity for audit purposes, allows organizations to suspend or revoke access if behavior deviates from expected norms, and governs the lifecycle of the agent and the actions taken to support compliance.
Threat Intelligence and Advisory Services
- Unit 42® brings together world-renowned expertise across threat research, incident response, and security consulting to deliver intelligence-driven, response-ready outcomes that help customers reduce cyber risk. Our elite consultants serve as trusted advisors to our customers by assessing and testing their security controls against sophisticated threats, including Frontier AI, transforming their security strategy with a threat-informed approach, and responding to security incidents on behalf of our clients. Additionally, Unit 42 offers managed detection and response (“MDR”) and managed threat hunting services. In April 2026, we launched a new suite of Unit 42 Frontier AI Defense services to help customers proactively discover and neutralize threats introduced by next-generation AI models.
- 5 -
Products and Services
NETWORK & AI SECURITY
Secure Access Service Edge
- Prisma Access. Prisma Access is a cloud-delivered security offering that helps organizations deliver consistent AI-driven security to remote networks and mobile users. With more than 100 locations around the world, Prisma Access offers global coverage, consistently inspecting all traffic across all ports and providing bidirectional networking to enable branch-to-branch and branch-to-headquarter traffic. Prisma Access consolidates point products into a single cloud-delivered solution, transforming network security and allowing organizations to enable secure hybrid work. Prisma Access protects all application traffic with complete, best-in-class security while also delivering a seamless user experience with industry-leading service-level agreements (“SLAs”). With native SASE integration, our Prisma Access Browser extends zero-trust security to any device—managed or unmanaged—in minutes. Prisma Access delivers seamless user experience with a combination of application acceleration—up to 5x faster than direct-to-internet—and Autonomous Digital Experience Management.
- Prisma SD-WAN. Our Prisma SD-WAN solution is a next-generation SD-WAN solution that makes the secure cloud-delivered branch possible. Prisma SD-WAN enables organizations to replace traditional wide area network (“WAN”) architectures with affordable broadband and internet transport types that promote improved bandwidth availability, redundancy, and performance. Prisma SD-WAN leverages real-time application performance SLAs and visibility to control and intelligently steer application traffic to deliver a powerful user experience. Prisma SD-WAN also provides the flexibility of deploying with an on-premises controller to help businesses meet their industry-specific security compliance requirements and manage deployments with application-defined policies. Our Prisma SD-WAN simplifies network and security operations using AI and automation.
Next-Generation Firewalls. Our hardware and software ML-Powered NGFWs use AI—including machine learning and deep learning—to stop zero-day threats in real time, and detect and secure the entire enterprise including Internet of Things (“IoT”). All of our hardware and software firewalls incorporate the PAN-OS® operating system and include the same rich set of features, ensuring consistent operation across our entire product line. This includes SD-WAN capabilities to intelligently steer traffic to data centers, branches, and the cloud, natively integrated into our NGFWs. Enterprise data, applications, users, and devices become integral components of an organization’s security policy. Our hardware and software are designed for different performance requirements throughout an organization—with the ability to secure everything from small businesses and branch offices, to large-scale data centers and service providers. Our firewalls come in hardware form factors, containerized form factors, called CN-Series, as well as virtual form factors, called VM-Series, available on all major cloud hosting service providers. We also offer Cloud NGFW, a managed NGFW offering, to secure customers’ applications on Amazon Web Services (“AWS”) and Microsoft Azure (“Azure”).
Cloud-Delivered Security Services
- Advanced Threat Prevention. This cloud-delivered security service provides intrusion detection and prevention capabilities and blocks vulnerability exploits, viruses, spyware, buffer overflows, denial-of-service attacks, and port scans from compromising and damaging enterprise information resources. In addition, we offer inline deep learning to deliver real-time detection and prevention of unknown, evasive, and targeted command-and-control (“C2”) communications over HTTP, unknown-TCP, unknown-UDP, and encrypted over SSL. Advanced Threat Prevention is the industry’s only offering to protect the enterprise from unknown command and control in real-time with the power of Precision AITM.
- Advanced WildFire. This cloud-delivered security service provides protection against targeted malware and advanced persistent threats and provides a near real-time analysis engine for detecting previously unseen malware while resisting attacker evasion techniques. Advanced WildFire combines dynamic and static analysis, recursive analysis, and a custom-built analysis environment with network traffic profiling and fileless attack detection to discover even the most sophisticated and evasive threats. Preventions are delivered in seconds to our network security platform.
- Advanced URL Filtering. This cloud-delivered security service offers the industry’s first Inline Deep Learning powered web protection engine. We deliver real-time detection and prevention of unknown, evasive, and targeted web-based threats, such as phishing. In addition, the service includes a cloud-based URL filtering database which consists of millions of URLs across many categories and is designed to analyze web traffic and prevent web-based threats, such as phishing, malware, and C2.
- Advanced DNS Security. This cloud-delivered security service uses machine learning to proactively block malicious domains and stop attacks in progress. The service allows our network security platform access to Domain Name System (“DNS”) signatures that are generated using advanced predictive analysis, machine learning, and malicious domain data from a growing threat intelligence sharing community of which we are a part. We offer comprehensive DNS attack coverage and include industry-first protections against multiple emerging DNS-based network attacks, including real-time analysis of DNS response to prevent DNS hijacking.
- 6 -
- Device Security. This cloud-delivered security service uses machine learning to accurately identify and classify various IoT, connected medical, operational technology (“OT”), and unmanaged IT devices, including never-been-seen-before devices, critical devices, and unmanaged legacy systems. The service uses machine learning to baseline normal behavior, identify anomalous activity, assess and prioritize risk, provide virtual patching, and provide policy and remediation recommendations.
- SaaS Security API. SaaS Security API is a multi-mode, cloud access security broker (“CASB”) that helps govern sanctioned SaaS application usage across all users and helps prevent breaches and non-compliance. Specifically, the service enables the discovery and classification of data stored in supported SaaS applications, protects sensitive data from accidental exposure, identifies and protects against known and unknown malware, and performs user activity monitoring to identify potential misuse or data exfiltration. The solution can be combined with SaaS Security Inline for a complete integrated CASB.
- SaaS Security Inline. SaaS Security Inline adds an inline service to automatically gain visibility and control over thousands of known and newly sanctioned, unsanctioned and tolerated SaaS applications in use within organizations today. The service provides enterprise data protection and compliance across all SaaS applications and prevents cloud threats in real time. The solution can be combined with SaaS Security API as a complete integrated CASB.
- GlobalProtect. GlobalProtect provides protection for users of both traditional laptop and mobile devices. It expands the boundaries of the end-users’ physical network, effectively establishing a logical perimeter that encompasses remote laptop and mobile device users irrespective of their location. Regardless of the operating system, laptops, tablets, and phones will stay connected to the corporate network when they are on a network of any kind and as a result, are protected as if they never left the corporate campus.
- Prisma Access Agent. Prisma Access Agent provides secure, remote access to corporate resources for employees working from any location or device. The agent establishes an encrypted tunnel to Prisma Access or our NGFW, ensuring consistent security, data protection, and threat prevention for a distributed workforce accessing any application.
- Enterprise DLP. This cloud-delivered security service provides consistent and reliable protection of sensitive data, such as personally identifiable information and intellectual property, for all traffic types, applications, and users. Native integration with our products makes the service simple to deploy, while advanced machine learning minimizes management complexity. Enterprise DLP allows organizations to consistently discover, classify, monitor, and protect sensitive data, wherever it may reside.
- AI Access Security. AI Access Security classifies and prioritizes GenAI applications to assess risk, detect anomalies, and visualize insights across multiple GenAI-specific attributes. The service prevents sensitive data loss and defends against malicious responses, ensuring safe and effective AI adoption.
AI Security: Prisma AIRS. Prisma AIRS™ is our comprehensive AI security platform designed to help organizations discover, assess, and protect AI agents, applications, models, and data across the AI lifecycle. It supports key enterprise use cases, including securing AI-assisted software development, protecting custom AI applications from development through runtime, and governing autonomous AI agents as they access enterprise data, tools, and systems. Prisma AIRS brings together AI Gateway, Agent Security, AI Red Teaming, AI Runtime Security, AI Model Security, and AI Posture Management in a unified platform. Together, these capabilities provide visibility into AI assets and activity, identify risks before deployment, and apply security controls to live AI interactions and agent actions.
- AI Gateway. Serves as the centralized AI security control plane through which all enterprise AI traffic flows—including LLM calls, tool invocations, agent interactions, and prompt data. AI Gateway enables organizations to govern AI agents, secure AI coding tools, and safely enable enterprise AI apps from a single control plane. The gateway provides real-time visibility into usage, tracks token consumption and cost, and inspects every interaction to prevent data leakage, prompt injection, and unsafe outputs. Before agents or coding tools access enterprise data or systems, the gateway enforces identity-aware controls and authorizes actions against defined permissions.
- Agent Security. Provides lifecycle security and governance for enterprise AI agents, from development through production. It establishes a central registry to inventory and verify every agent across endpoints, browsers, SaaS tools, and internal systems, mapping autonomous actions directly to human sponsors, specific agents, and business tasks. By assessing operational risk based on permissions, connected data, and integrated tools, Agent Security enforces identity-aware authorization and task-specific boundaries. These capabilities help organizations reduce shadow agent blind spots, protect sensitive data, prevent tool misuse and unauthorized actions, and maintain audit trails as agents automate business processes.
- AI Red Teaming. Continuously validates the security of custom autonomous agents, applications, and models through automated adversarial testing at enterprise scale. By profiling each deployment’s unique business context, workflows, and connected tools, AI Red Teaming autonomously executes over 50 advanced attack techniques—including jailbreaks, prompt injections, and goal manipulation—to test against the intended behavior of AI apps and agents. Enriched by threat intelligence from Unit 42 and the huntr research community, it delivers actionable remediation mapped to industry frameworks (OWASP, NIST, MITRE ATLAS) so teams can secure enterprise AI apps and deploy autonomous systems with confidence.
- AI Runtime Security. Provides continuous, real-time protection for live AI autonomous agents, applications and models operating in production. It actively intercepts mid-conversation threats, such as prompt injections, indirect
- 7 -
injections, malicious URLs, retrieval manipulation, and tool abuse while enforcing enterprise-grade Data Loss Prevention (“DLP”) across prompts and outputs. By stopping exploits as they unfold and preventing unauthorized data exfiltration, AI Runtime Security ensures business continuity, protects high-value enterprise data, and keeps operational agents acting safely within policy boundaries to secure enterprise AI apps and AI-assisted coding.
- AI Model Security. Protects the foundation of the AI ecosystem by extending continuous scanning to underlying model architectures, weights, operators, agent artifacts, code dependencies, and skills. AI Model Security inspects components in-place to identify hidden malware, poisoned assets, unsafe permissions, and indirect injection paths before they reach production. It ensures engineering teams can adopt AI coding safely, prevent secret leakage, and build trusted software without introducing supply chain risk.
- AI Posture Management. Provides continuous, real-time risk assessment across cloud, SaaS, and endpoint environments to help eliminate "Shadow AI" blind spots. It discovers deployed chatbots and agents, maps data flows, and enforces policy rules aligned with frameworks like the E.U. AI Act and OWASP Top 10 for LLMs. By surfacing misconfigurations and untracked AI usage across the enterprise, AISPM enables security teams to manage risk exposure, uphold corporate governance, and use GenAI safely.
Strata Cloud Manager (“SCM”). SCM enables our customers to easily manage their Palo Alto Networks’ Network Security infrastructure—including NGFWs and SASE deployments—from the cloud, via one unified management interface. As an AI-powered, unified cloud management solution, SCM enables organizations to enhance their network security posture and streamline operations. It utilizes AI to swiftly identify potential vulnerabilities, provide real-time recommendations for remediation, proactively address support needs, and improve overall digital experiences, leading to reduced operational overhead and improved speed, accuracy, and scale of support. By analyzing telemetry, historical data, and its diverse knowledge base, SCM can instantly answer questions, pinpoint solutions to known problems, and automate data collection to speed up assisted support for new challenges. Built into this robust solution are Strata Copilot™, offering a natural language interface for intuitive insights and guided actions, and ADEM, designed for proactive infrastructure health, simplified troubleshooting, and consistent end-user performance across the network.
Panorama. Panorama® is used for centralized policy management, device management, software licensing and updates, centralized logging and reporting, and log storage. Many of our existing deployments continue to use Panorama as the security management solution. New deployments benefit from using SCM for managing network security estate—including our NGFWs and SASE—with a cloud-based, unified management interface.
CORTEX
- Cortex XSIAM. Our cloud-based AI-powered security operations platform harnesses the power of AI to significantly improve security outcomes and transform security operations. Cortex XSIAM customers are able to consolidate multiple products into a single unified platform that delivers security information and event management, extended detection and response (“XDR”), SOAR, network traffic analysis, ASM, threat intelligence management (“TIM”), identity threat detection and response, and CDR. Cortex XSIAM integrates these capabilities into a single platform built for security operations, enabling organizations to simplify operations, stop threats at scale, and accelerate incident remediation. Cortex XSIAM automates data integration, analysis, and triage to respond to most alerts, enabling analysts to focus on only the incidents that require human intervention.
- Cortex XDR. This cloud-based service enables organizations to collect telemetry from endpoint, network, identity, and cloud data sources and apply advanced analytics and machine learning to quickly find and stop targeted attacks, insider abuse, and compromised endpoints. Cortex XDR has two product tiers: XDR Prevent and XDR Pro. XDR Prevent delivers enterprise-class endpoint security focused on preventing attacks. XDR Pro extends endpoint detection and response (“EDR”) to include cross-data analytics for network, cloud, and identity data. Going beyond EDR, Cortex XDR detects the most complex threats using analytics across key data sources and reveals the root cause, which can significantly reduce investigation time as compared to siloed tools and manual processes. Additionally, the recent acquisition of Koi Security Ltd. (“Koi”) introduces Agentic Endpoint Security capabilities to protect vibe coding agents and autonomous endpoint tools.
- Cortex XSOAR. Available as a stand-alone, cloud-based service, an on-premises virtual appliance, or delivered natively through Cortex XSIAM, Cortex XSOAR is a comprehensive SOAR offering that unifies playbook automation, case management, real-time collaboration, and threat intelligence management to serve security teams across the incident lifecycle. With Cortex XSOAR, security teams can standardize processes, automate repeatable tasks, and manage incidents across their security product stack to improve response time and analyst productivity. Cortex XSOAR learns from the real-life analyst interactions and past investigations to help SOC teams with analyst assignment suggestions, playbook enhancements, and best next steps for investigations. Many of our customers see significantly faster SOC response times and a significant reduction in the number of SOC alerts which require human intervention.
- 8 -
- Cortex Xpanse. Available as a stand-alone, cloud-based service and a cloud-based subscription module within Cortex XSIAM, Cortex Xpanse provides ASM, which is the ability for an organization to identify what an attacker would see among all of its sanctioned and unsanctioned Internet-facing assets. In addition, Cortex Xpanse detects risky or out-of-policy communications between Internet-connected assets that can be exploited for data breaches or ransomware attacks. Cortex Xpanse continuously identifies Internet assets, risky services, or misconfigurations in third parties to help secure a supply chain or identify risks for mergers and acquisitions due diligence. Finally, compliance teams use Cortex Xpanse to improve their audit processes and stay in compliance by assessing their access controls against regulatory frameworks.
- Cortex Cloud. Available as a stand-alone, cloud-based service or an add-on to Cortex XDR or to Cortex XSIAM. Cortex Cloud, the next generation of Prisma Cloud, merges CNAPP with CDR for real-time cloud security. The solution allows you to harness the power of AI and automation to prioritize cloud risks with runtime context, enable remediation at scale, and stop attacks as they happen. Cortex Cloud consolidates multiple code and cloud security technologies, such as Cloud Detection and Response, Software Composition Analysis, Infrastructure as Code security, CI/CD security, secrets scanning, Cloud Security Posture Management, Cloud Identity and Entitlements Management, API security, Vulnerability Management, Cloud Workload Protection, Web Application and API Security, Cloud Network Security, and Cloud Attack Surface Management into a single unified offering. As part of the Cortex platform, customers can transform end-to-end security operations, from code to cloud to SOC, by adopting Cortex Cloud together with Cortex XSIAM. Existing customers can continue leveraging Prisma Cloud as they upgrade to Cortex Cloud for significantly better, faster, and more effective multi-cloud protection.
- Chronosphere Platform. Our observability platform enables Site Reliability Engineering (“SRE”) teams to efficiently identify and resolve customer-facing issues faster, while managing cloud-native complexity. It provides control over observability costs and access to a purpose-built, highly scalable observability SaaS platform for cloud-native environments. By reducing data volumes, the platform is designed to optimize costs and accelerate troubleshooting. Additionally, the platform supports all telemetry types, including metrics, events, logs, and traces from various delivering application performance monitoring (“APM”) capabilities integrated with open-source telemetry.
- Chronosphere Telemetry Pipeline. Designed to address growing log data volumes, the pipeline allows observability and security teams to collect data from a wide range of sources; transform, enrich, and reduce logs in transit; and route data to any destinations. Our telemetry pipeline is built on open standards and is engineered to operate efficiently and require fewer infrastructure resources than other leading pipelines.
IDIRA
- Privileged Access Management (“PAM”). Available as a core cloud-native platform module or software, Idira PAM establishes a modern framework for securing high-risk administrative access across multi-cloud, on-premises, and hybrid infrastructures. The solution enforces a strict Zero Standing Privilege (“ZSP”) model by utilizing Just-in-Time (“JIT”) dynamic privilege elevation, ensuring that administrative pathways exist exclusively for the duration of an authorized task and are terminated immediately upon completion. The system automates credential rotation, securely manages SSH keys, and delivers real-time session isolation and live monitoring alongside comprehensive forensic recordings to detect and respond to lateral or vertical threat movement. By continually discovering hidden access paths and unmanaged accounts, Idira PAM helps customers reduce the privilege gaps associated with administrative environments.
- Identity and Access Management (“IAM”). Our cloud-based service enables organizations to deliver secure application and infrastructure connectivity for a decentralized workforce. Idira IAM unifies core identity services—including SSO, phishing-resistant MFA, and automated lifecycle management—into a single high-availability identity hub. The platform features an extensive integration catalog with thousands of pre-configured application connections utilizing industry-standard protocols, such as SAML, OpenID Connect, and SCIM. Operating at scale, it enforces policy-driven contextual authentication parameters based on device posture, network environment, and real-time threat intelligence, which are engineered to help organizations mitigate credential-based attacks and unauthorized access.
- Endpoint Privilege Manager. This cloud-based endpoint protection module secures enterprise laptops, workstations, and servers by enforcing strict least-privilege policies directly at the operating system layer. Idira Endpoint Privilege Manager minimizes the local attack surface by stripping standard corporate users of excessive local administrative credentials, which serve as a primary vector for credential harvesting and local exploit execution. In addition to dynamic privilege management, the solution delivers robust application control capabilities, allowing security teams to define execution rules that stop untrusted, malicious, or unapproved software from running on critical endpoints. By connecting local enforcement metrics with central identity governance workflows, it ensures continuous compliance and real-time security posture enforcement across distributed infrastructure.
- 9 -
- Identity Governance. Designed to automate and streamline compliance auditing across the enterprise identity landscape, this cloud-based solution unifies visibility and lifecycle tracking for human and machine accounts. Idira Identity Governance simplifies IGA by replacing fragmented, manual certification workflows with AI-driven continuous visibility and automated access evaluations. The platform aggregates user access rights, role definitions, and historical entitlements to proactively flag policy deviations, toxic access combinations, and orphaned accounts. By automating entitlement reviews, lifecycle onboarding, and offboarding flows, the solution is designed to help organizations reduce operational overhead while supporting ongoing audit readiness across complex multi-cloud and hybrid environments.
- Workforce Password Management. This cloud-delivered solution extends security capabilities to corporate applications, SaaS tools, and web portals that lack native support for federated SSO protocols. Idira Workforce Password Management allows security teams to bring unmanaged password-based applications under centralized administrative oversight. The solution enforces enterprise password policies, automates complex credential generation and rotation, and securely stores data within encrypted enterprise vaults. By integrating directly into the user’s browser workflow, it enables frictionless passwordless entry experiences for the workforce while providing IT leadership with complete visibility into application usage, credential strength, and shared account vulnerabilities.
- Vendor Privileged Access. Designed to mitigate third-party supply chain liabilities, this solution secures and governs remote access for external contractors, supply partners, and service vendors without requiring corporate agents or complex virtual private network (“VPN”) infrastructure. Idira Vendor Privileged Access establishes an isolated, browser-based secure gateway that authenticates external contributors using strict multi-factor checks and contextual policies. Once inside, vendors are restricted to specific authorized applications or servers through precise JIT entitlements, rather than being granted broad network-level visibility. Security operations teams can actively monitor, shadow, and automatically terminate active third-party sessions in real time, capturing full session playbacks in order to achieve accountability and regulatory compliance.
- Secrets Management. This machine identity solution delivers simplified, high-performance protection of non-human credentials across modern application architectures, container environments, and DevOps pipelines. Idira Secrets Management prevents data breaches by systematically removing hard-coded, static passwords, API keys, and configuration tokens from software repositories, source code, and developer environments. It centralizes machine authentication paths under a unified control plane, utilizing programmatic application programming interfaces (“APIs”) and native cloud plug-ins to manage and distribute credentials securely. By consolidating secrets management across complex hybrid structures, it helps security organizations eliminate vault sprawl and establish an optimized, secure non-human security architecture.
- Secrets Hub. Available as a policy-driven orchestration tier, this solution extends enterprise-grade oversight across native cloud secrets stores, including AWS, Azure, Google Cloud, and HashiCorp Vault architectures. Idira Secrets Hub allows security teams to define and enforce uniform credential rotation, expiration, and access policies from a single control plane without forcing developer teams to abandon their preferred cloud-native storage environments. By consolidating disparate, siloed vaults under a singular oversight layer, the platform effectively mitigates "vault sprawl" across complex multi-cloud environments. The solution continually tracks credential lifecycles, automatically flagging policy deviations, overly permissive configurations, and unmanaged shadow vaults to streamline corporate compliance.
- Credential Providers. Engineered to address the operational and security demands of distributed software deployment, this solution eliminates embedded credentials by providing automated, dynamic secret provisioning. Idira Application Credentials Delivery provides secure, JIT secret retrieval for applications residing in traditional data centers, public clouds, and Kubernetes container platforms. Instead of relying on static keys embedded within software configurations, authorized application components pull short-lived authentication materials dynamically at the moment of execution. This continuous injection model significantly reduces the risk of credential scraping or exposure during code breaches, enabling high-velocity software engineering pipelines to scale securely without manual credential upkeep.
- Secure AI Agents. Designed for AI workloads and agents, this solution delivers an identity-first approach to securing the agentic workforce. Idira Secure AI Agents continuously scans SaaS, cloud, and developer environments to discover active "shadow" AI agents and automatically onboards them into a centralized agent registry. The solution routes all interactions through a gateway that applies precise guardrails, granting short-lived permissions exclusively for the duration of a specific task and automatically revoking access the moment a job is completed. If an agent suffers a prompt injection attack or exhibits anomalous behavior, the broker can deny access in real time, while maintaining a clear audit trail.
- 10 -
THREAT INTELLIGENCE AND ADVISORY SERVICES
- Customer Support. Global customer support helps our customers achieve their security outcomes with services and support capabilities covering the customer's entire journey with Palo Alto Networks. This post-sales, global organization advances our customers’ security maturity, supporting them when, where, and how they need it. We offer Standard Support, Premium Support, and Platinum Support to our end-customers and channel partners. Our channel partners that operate a Palo Alto Networks Authorized Support Center typically deliver level-one and level-two support. We provide level-three support 24 hours a day, seven days a week through regional support centers that are located worldwide. We also offer a service offering called Focused Services that includes Customer Success Managers to provide support for end-customers with unique or complex support requirements. We offer our end-customers ongoing support for hardware, software, and cloud offerings. Support for cloud offerings includes a standard level of support with the applicable subscription, with optional premium support offerings available for customers requiring enhanced service levels including ongoing security updates, PAN-OS upgrades, bug fixes, and repairs. End-customers typically purchase these services for a one-year or longer term at the time of the initial product sale and typically renew for successive one-year or longer periods. Additionally, we provide expedited replacement for any defective hardware. We use a third-party logistics provider to manage our worldwide deployment of service-related spares.
- Threat Intelligence, Incident Response and Security Consulting. Unit 42 brings together world-renowned threat researchers, incident responders, and security consultants to create an intelligence-driven, response-ready organization that is passionate about helping clients proactively manage cyber risk. We help security leaders assess and test their security controls, transform their security strategy with a threat-informed approach, and respond to incidents rapidly. The Unit 42 Threat Intelligence team provides threat research that enables security teams to understand adversary intent and attribution, while enhancing protections offered by our products and services to stop advanced attacks. Our security consultants serve as trusted partners with state-of-the-art cyber risk expertise and incident response capabilities, helping customers build effective security programs, uncover critical exposures to prevent incidents, and, should incidents occur, respond to them with speed and confidence. Additionally, Unit 42 experts help customers proactively discover and neutralize threats introduced by next-generation AI models with the Frontier AI Defense service.
- Professional Services. Professional services are primarily delivered directly by Palo Alto Networks and through a global network of authorized channel partners to our end-customers and include on-location and remote, hands-on experts who plan, design, and deploy effective security solutions tailored to our end-customers’ specific requirements. These services include architecture design and planning, implementation, configuration, and firewall migrations for all our products, including Prisma and Cortex deployments. Customers can also purchase on-going technical experts to be part of customer’s security teams to aid in the implementation and operation of their Palo Alto Networks capabilities. Our education services include certifications, as well as free online technical courses and in-classroom training, which are primarily delivered through our authorized training partners.
RESEARCH AND DEVELOPMENT
Our research and development efforts are strategically centered on expanding our leadership within the enterprise security industry through AI-powered innovation. We focus on enhancing our integrated platforms and developing new software and hardware capabilities. Our engineering teams apply deep expertise in AI and machine learning across networking security, cloud security, endpoint security, security operations, and identity security to address the rapidly evolving threat landscape. This approach enables us to leverage core competencies across hardware and software for agile responsiveness and to ensure interoperability with third-party technologies. We supplement our own research with technologies and products licensed from third parties.
We believe that innovation and timely development of new features and products is essential to meeting the needs of our end-customers and improving our competitive position. During fiscal 2026, we introduced several upgrades and new offerings, including: PAN-OS 12.1 Orion, Prisma AIRS 2.0, NGTS, and Prisma AIRS 3.0.
We plan to continue to significantly invest in our research and development efforts as we evolve and extend the capabilities of our portfolio.
- 11 -
ACQUISITIONS
We believe that the industry in which we operate necessitates a variety of technologies, products, capabilities, and features. We evaluate opportunities to acquire complementary businesses, technologies, services, and intellectual property to complement our organic innovation and research and development efforts, advance the development of our platforms, and enable further investment in our key priority areas. Our evaluation of acquisition opportunities seeks to confirm that any potential transaction would accelerate our strategy, represent an attractive customer opportunity, address a customer need, align with our customer base and go-to-market strategy, and present a clear timeline and path for value accretion. Our acquisitions enable us to gain access to talent, technology, products, and features, and can range in size and complexity, from those that enhance or complement existing products and accelerate development of features to those that result in new offerings.
For example, in January 2026, we completed the acquisition of Chronosphere, Inc. (“Chronosphere”), a privately-held observability technology company, forming our next-generation observability platform; in February 2026, we completed the acquisition of CyberArk Software Ltd. (“CyberArk”), an identity security company, forming our next-generation identity security platform; in April 2026, we completed the acquisition of Koi, a privately-held endpoint posture management company, which adds agentic endpoint security capabilities to our security operations platform and enhances Prisma® AIRS™; in May 2026, we completed the acquisition of Portkey, Inc. (“Portkey”), a privately-held AI Gateway company, which enhances the capabilities of Prisma AIRS; in July 2026, we entered into a definitive agreement to acquire Embrace Mobile, Inc. (“Embrace”), a privately-held Real User Monitoring (“RUM”) company that we expect will add RUM capabilities to our observability platform; and in July 2026, we entered into a definitive agreement to acquire Console Systems, Inc. (“Console”), a privately-held company providing an AI-native platform that enables agentic workflows across enterprise operations, which we expect to deepen our agentic capabilities in Cortex.
For additional information related to the impact of acquisitions to our business, see Part I, Item 1A “Risk Factors” and Note 8. Acquisitions and Note 20. Subsequent Events in Part II, Item 8 of this Annual Report on Form 10-K.
INTELLECTUAL PROPERTY
We believe that our intellectual property rights are valuable and important to our business, and that our success depends, in part, on our ability to protect and use our core technology and intellectual property rights. We rely on a combination of trademarks, patents, copyrights, trade secrets, license agreements, intellectual property assignment agreements, confidentiality procedures, non-disclosure agreements, and employee non-disclosure and invention assignment agreements to establish, protect, and control the use of our proprietary technology and intellectual property rights. We continue to grow our global portfolio of intellectual property rights in connection with our products, services, research, and development. We file patent applications to protect our intellectual property and believe that the duration of our issued patents is sufficient when considering the expected lives of our products. We have registered various trademarks for our company and our products in the United States (“U.S.”) and other jurisdictions internationally. We intend to continue pursuing additional protections for our proprietary technology and intellectual property to the extent we believe it would be beneficial and cost-effective.
Despite our efforts to protect our proprietary technology and intellectual property rights, our rights may not be respected in the future or may be invalidated, circumvented, or challenged. Our industry is characterized by the existence of a large number of patents, copyrights, trademarks, domain names, and trade secrets, and frequent claims and related litigation based on allegations of patent infringement, misappropriation, or other violations of intellectual property rights. We believe that competitors will try to develop products that are similar to ours and that may infringe our intellectual property rights. Our competitors, third-parties, and non-practicing entities may also claim that our cybersecurity platforms and services infringe their intellectual property rights. Third parties have in the past and may in the future assert claims of infringement, misappropriation, and other violations of intellectual property rights against us or our customers, with whom our license or other agreements may obligate us to indemnify against these claims. Successful claims of infringement by a third party could affect our ability to offer, or prevent us from offering, certain products and subscriptions. This could result in time during which we may be unable to continue to offer our affected products and subscriptions because of a potential need for us to develop alternate, non-infringing technology, which could require significant time and resources, or require us to obtain a license, which may not be available on reasonable terms or at all, or could require us to pay substantial damages, royalties, or other fees. For additional information, see the section titled “Risks Related to Intellectual Property and Technology Licensing” in Part I, Item 1A “Risk Factors” in this Form 10-K.
GOVERNMENT REGULATION
We are subject to numerous U.S. federal, state, and foreign laws and regulations covering a wide variety of subject matters. Like other companies in the technology industry, we face scrutiny from both U.S. and foreign governments with respect to our compliance with laws and regulations. Our compliance with these laws and regulations may be onerous and could, individually or in the aggregate, increase our cost of doing business, impact our competitive position relative to our peers, and/or otherwise have an adverse impact on our business, reputation, financial condition, and operating results. For additional information about government regulation applicable to our business, see Part I, Item 1A “Risk Factors” in this Form 10-K.
- 12 -
COMPETITION
We operate in the intensely competitive enterprise security industry that is characterized by constant change and innovation. Changes in the application, threat, and technology landscape result in evolving customer requirements for the protection from threats and the safe enablement of applications. Our main competitors fall into four categories:
- large companies that incorporate security or observability features in their products, such as Alphabet Inc., Cisco Systems, Inc., and Microsoft Corporation, or those that have acquired, or may acquire, security vendors and have the technical and financial resources to bring competitive solutions to the market;
- independent vendors that offer a mix of security products, such as Check Point Software Technologies Ltd., CrowdStrike Holdings, Inc., Delinea Inc., Fortinet, Inc., Okta, Inc., SailPoint Technologies, Inc., and Zscaler, Inc., vendors that offer a mix of observability products, such as DataDog, Inc., Dynatrace, Inc., and Elasticsearch B.V., or vendors that may offer a mix of security and observability products;
- startups and point-product vendors that offer independent or emerging solutions across various areas of security; and
- public cloud vendors and startups that offer solutions for cloud security (private, public, and hybrid cloud).
As our market grows, it will attract more highly specialized vendors, as well as larger vendors that may continue to acquire or bundle their products more effectively.
The principal competitive factors in our market include:
- product features, reliability, performance, and effectiveness;
- product line breadth, diversity, and applicability;
- product extensibility and ability to integrate with other technology infrastructures;
- price and total cost of ownership;
- adherence to industry standards and certifications;
- strength of sales and marketing efforts; and
- brand awareness and reputation.
We believe we generally compete favorably with our competitors on the basis of these factors as a result of the features and performance of our portfolio, the ease of integration of our security solutions with technological infrastructures, and the relatively low total cost of ownership of our products. However, some of our competitors may have substantially greater financial, technical, and other resources, greater name recognition, larger sales and marketing budgets, broader distribution, more diversified product lines, and larger and more mature intellectual property portfolios.
SALES, MARKETING, SERVICES, AND SUPPORT
Customers. Our end-customers consist of enterprises, service providers, and government entities. Our end-customers operate in a variety of industries, including education, energy, financial services, government entities, healthcare, Internet and media, manufacturing, public sector, and telecommunications. Our end-customers deploy our portfolio of solutions for a variety of security use cases across several settings. Typical deployment settings include the enterprise network, the enterprise data center, cloud locations, branch or remote locations, and on-device agents. No single end-customer accounted for more than 10% of our total revenue in fiscal 2026, 2025, or 2024.
Distribution. A substantial portion of our sales to end-customers are through our channel partners utilizing a two-tier, indirect fulfillment model whereby we sell to our distributors, which, in turn, sell to our resellers, which then sell to our end-customers. Sales are generally subject to our standard, non-exclusive distributor agreement, which provides for an initial term of one year, one-year renewal terms, termination by us with 30 to 90 days written notice prior to the renewal date, and payment to us from the channel partner within 30 to 75 days calendar days of the date we issue an invoice for such sales. For fiscal 2026, 30% of our total revenue was derived from sales to two distributors.
We also sell our VM-Series virtual firewalls and Cloud NGFW via various cloud marketplaces. For example, our VM-Series virtual firewalls are sold on Amazon’s AWS Marketplace, Microsoft’s Azure Marketplace, Alphabet’s Google Cloud Marketplace, and Oracle Corporation’s Oracle Cloud Marketplace either directly to end-customers or as part of the respective cloud hosting service provider’s offerings under a usage-based licensing model.
Sales. Our sales organization is responsible for large-account acquisition and overall market development, which includes the management of the relationships with our channel partners, working with our channel partners in winning and supporting end-customers through a direct-touch approach, and acting as the liaison between our end-customers and our marketing and product development organizations. We pursue sales opportunities both through our direct sales force and as assisted by our channel partners, which include resellers, global and regional systems integrators, service providers, managed security service providers, and cloud hosting service providers. We expect to continue to grow our sales headcount to expand our reach in all key growth sectors.
- 13 -
Our sales organization is supported by sales engineers with responsibility for pre-sales technical support, solutions engineering for our end-customers, and technical training for our channel partners.
Channel Program. Our NextWave Channel Partner program is focused on building in-depth relationships with solutions-oriented distributors, resellers, managed security service providers, and authorized delivery and services partners that have strong security expertise. The program rewards these partners based on a number of attainment goals, as well as provides them access to marketing resources, Partner Development Funds, technical and sales training, and support. To promote optimal productivity, we operate a formal accreditation program for our channel partners’ sales and technical professionals, including those authorized to provide customer support or implementation services. As of July 31, 2026, we had more than 8,700 channel partners.
Global Customer Success. Our Global Customer Success organization delivers professional, educational, and support services to customers and partners worldwide. We extend the reach and consistency of these services through a global network of certified partners. These offerings help customers successfully deploy, adopt, operate, and realize value from our products throughout their lifecycle. We invest in technical talent with deep domain expertise, AI-enabled capabilities, and automation to enhance delivery, scale, and consistency of our customer success services.
Marketing. Our marketing is focused on building our brand reputation and the market awareness of our portfolio and driving pipeline and end-customer demand. Our marketing team consists primarily of product marketing, brand, demand generation, field marketing, digital marketing, communications, analyst relations, and marketing analytics functions. Marketing activities include pipeline development through demand generation, social media and advertising programs, managing the corporate website and partner portal, trade shows and conferences, analyst relationships, customer advocacy, and customer awareness. Every year we organize multiple signature events, such as our end-customer conference “Ignite” and focused conferences such as “Cortex Symphony” and “SASE Converge.” We also publish threat intelligence research, such as the Unit 42 Global Incident Response and State of Cloud Security Report, which are based on insights from our global threat intelligence team, Unit 42. These activities and tools benefit both our direct and indirect channels and are available at no cost to our channel partners.
Backlog. Contract amounts that are not recorded in deferred revenue or revenue are considered backlog. Orders billed prior to revenue recognition are included in deferred revenue. We expect backlog will change from period to period for various reasons, including the timing of billing and fulfillment, such as inventory shortages. As such, we do not believe that backlog at any particular time is necessarily indicative of our future operating results.
Seasonality. Our business is affected by seasonal fluctuations in customer spending patterns. We have seen seasonal patterns in our business, which we expect to become more pronounced as we continue to grow, with our strongest sequential revenue growth generally occurring in our fiscal second and fourth quarters.
MANUFACTURING
We outsource the manufacturing of our products to various manufacturing partners, which include our electronics manufacturing services provider (“EMS provider”) and original design manufacturers. This approach allows us to reduce our costs as it reduces our manufacturing overhead and inventory and also allows us to adjust more quickly to changing end-customer demand. Our EMS provider is Flextronics International, Ltd. (“Flex”), who assembles our products using design specifications, quality assurance programs, and standards that we establish, and procures components and assembles our products based on our demand forecasts. These forecasts are based upon historical trends and analysis, adjusted for overall market conditions. All of our hardware products are assembled in the U.S.
The component parts within our products are either sourced by our manufacturing partners or by us from various component suppliers. Our manufacturing and supply contracts, generally, do not guarantee a certain level of supply or fixed pricing, which increases our exposure to supply shortages or price increases.
HUMAN CAPITAL
We believe our ongoing success depends on our employees. As AI transforms the cybersecurity landscape, we continue to invest in our workforce to build AI fluency that enables our employees to innovate, adapt, and meet evolving customer needs while delivering on our mission of protecting our digital way of life.
With a global workforce of 21,921 as of July 31, 2026, our People Strategy is a critical element of our overall company strategy and is overseen by our Chief People Officer who regularly updates our board of directors and the board’s Compensation and People Committee on human capital matters.
Our People Strategy is designed to enable a workforce that is nimble, high-performing, and innovative. We take a comprehensive approach to attracting, enabling, and engaging world-class talent and fostering a culture where every employee can thrive. Our approach includes respecting each employee as a unique individual, demonstrating fairness in all we do, and advancing a culture where employees are inspired to do the most impactful work of their careers.
We also focus on building AI fluency across the organization by tailoring AI learning opportunities to specific roles and functions. For example, we offer department based hands-on training and peer-to-peer use case sharing, as well as a range of self-paced learning processes.
- 14 -
Our values of disruption, execution, collaboration, inclusion, and integrity were co-created with employees and serve as the foundation of our culture. These values are embedded in our talent acquisition, learning and enablement, engagement and performance elevation, rewards, and recognition programs.
Attract and Hire. We continue to evolve our talent strategy to meet the rapidly changing technology landscape. Recognizing the pace of innovation in an AI-driven world, our recruitment strategy prioritizes durable, "AI-readiness" capabilities, such as critical thinking, adaptability, and a capacity for continuous learning.
Our global recruiting programs focus on attracting highly skilled talent across technical and business functions who contribute to our culture, mission and continued innovation.
In fiscal 2026, we continued to strengthen our hiring operations by further embedding AI across the talent acquisition lifecycle. We deployed intelligent tools to enhance core processes, such as sourcing and structured interview tools. Each step is optimized for speed, consistency, and bias mitigation, and we maintain human oversight of hiring decisions.
Our Global Hiring Committee continues to play a key role in maintaining objectivity and our hiring standards. This group of cross-functional senior leaders reviews finalist candidates’ information with a focus on experience and capability. To build robust talent pipelines, we partner with academic institutions and other organizations to support new careers in cybersecurity, promote open roles, proactively reach out to candidates across multiple hiring channels, and source candidates with a range of experiences. We also encourage employee referrals and internal mobility.
Onboard and Enable. Each member of our workforce has a unique career journey and individual needs, interests, and goals. To that end, we strive to create an environment where everyone feels valued, respected, and supported to solve the world’s toughest cybersecurity challenges.
Our learning and development programs help employees build critical capabilities in cybersecurity and AI, while strengthening human-centric skills, such as problem solving, resilience, and adaptability. Learning is integrated into employees’ daily work through a blend of in-person experiences and personalized digital resources, including AI-curated onboarding roadmaps and mentor networks. We provide adaptive learning tracks for employees at every stage of their careers, including specialized paths for early-career talent and employees joining through acquisitions. To further build responsible AI fluency across the organization, we introduced ongoing campaigns, the first of which showcased practical AI use cases, and continue to leverage AI-enabled simulations to help managers strengthen coaching and leadership skills.
Listen and Engage. We aim to foster engagement and help employees feel connected to our mission and values. We use in-person and virtual channels to provide a regular flow of information to and between employees and leadership. These channels include company meetings, digital displays across our sites, our intranet, regular email communications, an active Slack platform, pulse surveys, a peer-to-peer recognition platform, and regular two-way dialogue—such as small, in-person listening sessions hosted by our chief executive officer.
Employee sentiment is also collected and measured from external sources, such as Glassdoor and Comparably. In addition, based on employee participation in an anonymous survey, the Best Practice Institute has certified Palo Alto Networks as one of the “America’s Top 100 Most Loved Workplaces” in 2025. Palo Alto Networks has been recognized by Glassdoor as one of the “Best Places to Work” and the “Best Companies in Tech & AI” in 2026 and by Comparably for “Best Company Culture” in 2025, as well as other employer of choice awards.
In addition to our formal, company-wide, semiannual performance review process, which helps employees set learning and development plans, we believe in always-on performance feedback. Further providing engagement are 12 Employee Network Groups, open to all employees, that leverage different perspectives to build, understand, and support our mission.
Compensation and Benefits. We offer employees competitive compensation and our flexible benefits plans include a variety of health, time off, wellness, and voluntary benefits. Our pay strategy, which includes base salary, cash bonus programs, and equity awards, focuses on compensation based on individual performance. Palo Alto Networks is a fair pay company and we conduct an annual assessment of our pay practices. Through our flexible benefits programs, employees are able to request reimbursement for a range of lifestyle items including fitness, caregiving, and education. Additionally, through our Giving+ program, employees can request monetary matching of their charitable donations and volunteer time.
Health, Safety and Wellbeing. Our commitment to the health, safety and wellbeing of our employees includes providing tools, resources, and benefits focused on physical, mental, and emotional wellbeing. This includes courses designed to equip employees with the knowledge to work safely, and mental health-focused resources on our employee intranet.
- 15 -
CORPORATE RESPONSIBILITY
Corporate Responsibility (“CR”) is integrated into our business strategy and supports our mission of protecting our digital way of life. Our CR approach is informed through many inputs, including our business objectives, ongoing stakeholder engagement, investor and customer interests, benchmarking of industry best practices, regulatory developments, and more. We execute meaningful CR initiatives that include advancing environmental sustainability, investing in people, and operating with integrity. Palo Alto Networks has been recognized by multiple organizations for our corporate responsibility practices, including being ranked third overall on Newsweek's list of “America's Most Responsible Companies 2026” and inclusion on TIME’s “World's Most Sustainable Companies of 2026” list.
Advance Environmental Sustainability. Palo Alto Networks remains committed to reducing the adverse environmental impacts of our operations and value chain and supporting customers' sustainability objectives. Our decarbonization pathway includes implementing operational efficiencies, procuring renewable electricity to run our managed sites, targeting greenhouse gas emissions reductions across our value chain, and making progress on our science-based targets. In fiscal 2026, we continued to strengthen the data, systems, and processes that support our environmental strategy, including expanding carbon emissions lifecycle assessments of select firewall products to better understand product-related emissions. We also enhanced our renewable electricity strategy by procuring high-quality Energy Attribute Certificates in key operating regions, where available and feasible. We report progress towards our goals in our annual Corporate Responsibility Report.
Invest in People. As a company built on trust, continuing to be a leader in responsible business practices and social impact supports our corporate strategy. In addition to our People Strategy described in the section titled “Human Capital” above, we continue to communicate our expectations regarding labor standards, business practices, and workplace health and safety conditions to our supply chain through our Global Supplier Code of Conduct. During fiscal 2026, we maintained our affiliate membership in the Responsible Business Alliance. As cyber threats become increasingly sophisticated and AI-driven, we share threat intelligence and research that helps organizations and communities better understand emerging risks, collaborate with industry partners to advance cybersecurity innovation and resilience, and invest in and support initiatives and nonprofit organizations that expand access to cybersecurity education and help develop the next generation of cybersecurity professionals. We also provide opportunities for employees to support causes they care about through volunteering and community engagement initiatives.
Operate with Integrity. We maintain enterprise-wide ethics, compliance, information security, and data privacy programs designed to promote responsible business practices throughout our operations and value chain. Integrity is one of our core values. Employees, contractors and suppliers are informed about our ethics, labor, and governance expectations, including through our Codes of Conduct, compliance training programs and ongoing communications. The Governance and Sustainability Committee of the board of directors provides primary oversight of corporate responsibility and the board of directors and applicable committees receive regular updates on corporate responsibility topics. In fiscal 2026, we achieved certification under the Global Cross-Border Privacy Rules and Privacy Recognition for Processors systems, demonstrating our commitment to internationally recognized, independently assessed privacy standards governing the responsible handling and cross-border transfer of personal data. We also further strengthened our enterprise-wide AI governance program that supports compliance, privacy, and security across both our internal operations and products.
AVAILABLE INFORMATION
Our website is located at www.paloaltonetworks.com, and our investor relations website is located at investors.paloaltonetworks.com. Our Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, and amendments to reports filed or furnished pursuant to Sections 13(a) and 15(d) of the Securities Exchange Act of 1934, as amended (the “Exchange Act”), are available free of charge on the Investors portion of our website as soon as reasonably practicable after we electronically file such material with, or furnish it to, the Securities and Exchange Commission (“SEC”). We also provide a link to the section of the SEC’s website at www.sec.gov that has all of our public filings, including Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, all amendments to those reports, our Proxy Statements, and other ownership-related filings.
We also use our investor relations website as a channel of distribution for important company information. For example, webcasts of our earnings calls and certain events we participate in or host with members of the investment community are on our investor relations website. Additionally, we announce investor information, including news and commentary about our business and financial performance, SEC filings, notices of investor events, and our press and earnings releases, on our investor relations website. Investors and others can receive notifications of new information posted on our investor relations website in real time by signing up for email alerts and RSS feeds.
Further corporate governance information, including our corporate governance guidelines, board committee charters, and code of conduct, is also available on our investor relations website under the heading “Governance.” The contents of our websites are not incorporated by reference into this Annual Report on Form 10-K or in any other report or document we file with the SEC, and any references to our websites are intended to be inactive textual references only. All trademarks, trade names, or service marks used or mentioned herein belong to their respective owners.
- 16 -
Item 1A. Risk Factors
Our operations and financial results are subject to various risks and uncertainties including those described below. The risks and uncertainties described below are not the only ones we face. Additional risks and uncertainties that we are unaware of, or that we currently believe are not material, also may become important factors that affect us. If any of the following risks or others not specified below materialize, our business, financial condition, and operating results could be materially adversely affected, and the market price of our common stock could decline. In addition, the impacts of any worsening of the economic environment may exacerbate the risks described below, any of which could have a material impact on us.
Risk Factor Summary
Our business is subject to numerous risks and uncertainties. These risks include, but are not limited to, the following:
- Our operating results may be adversely affected by unfavorable economic and market conditions and the uncertain geopolitical environment.
- Our business and operations have experienced growth in recent periods, and if we do not effectively manage our future growth or are unable to improve our systems, processes, and controls, our business and operating results could be adversely affected.
- Our revenue growth rate in recent periods may not be indicative of our future performance, and we may not be able to maintain profitability, which could cause our business, financial condition, and operating results to suffer.
- Our operating results may vary significantly from period to period, including due to seasonality, which makes our results difficult to predict and could cause our results to fall short of expectations.
- If we are unable to sell new and additional products, subscriptions, and support offerings to existing end-customers or attract new customers, especially large enterprise customers, our future revenue and operating results will be harmed.
- We rely on revenue from subscription and support offerings, and because we recognize revenue from subscription and support over the term of the relevant service period, downturns or upturns in sales or renewals of these subscription and support offerings are not immediately reflected in full in our operating results.
- Our consumption- or usage-based offerings may expose us to customer usage optimization behavior that could create revenue volatility.
- The sales prices of our products, subscriptions, and support offerings may decrease, which may reduce our revenue and gross profits and adversely impact our financial results.
- We rely on our channel partners to sell a substantial portion of our products, including subscriptions and support, and if these channel partners fail to perform, our ability to sell and distribute our products and subscriptions will be limited and our operating results will be harmed.
- We are exposed to the credit and liquidity risk of our customers, and to credit exposure in weakened markets, which could result in material losses.
- A portion of our revenue is generated by sales to government entities, which are subject to a number of challenges and risks.
- We face intense competition and we may lack sufficient financial or other resources to maintain or improve our competitive position.
- The “identity security” market lacks a universally accepted definition, which could lead to mischaracterization of our offerings and adverse evaluations by industry stakeholders.
- Customer trends toward vendor consolidation in cybersecurity may favor competitors offering broader platforms.
- Cloud infrastructure providers and advanced AI companies increasingly offer native security and observability capabilities that compete directly with our offerings.
- We have acquired and may in the future acquire other businesses, which could subject us to adverse claims or liabilities, require significant management attention, disrupt our business, adversely affect our operating results, may not result in the expected benefits of such acquisitions, and may dilute stockholder value.
- As a result of the CyberArk acquisition, the scope and size of our business have substantially changed, which resulted in certain incremental risks, including increased competition.
- If we do not accurately predict, prepare for, and respond promptly to rapidly evolving technological and market developments and successfully manage product and subscription introductions and transitions to meet changing end-customer needs in the enterprise security industry, our competitive position and prospects will be harmed.
- The success of our strategy depends on maintaining a broad ecosystem of integrations with third-party technologies, which requires significant ongoing investment.
- 17 -
- Issues in the development, deployment, or use of AI may result in reputational harm, legal liability, and could adversely affect our business and operating results.
- The emergence of AI agents as a new class of identity presents both opportunities and risks that could impact our identity security offerings.
- A significant network or data security incident may materially impact our reputation, financial condition, and operating results.
- Defects, errors, or vulnerabilities in our products, subscriptions, or support offerings, the failure of our products or subscriptions to block a virus or prevent a security breach or incident, misuse of our products, or risks of product liability claims could harm our reputation and adversely impact our operating results.
- Our shared responsibility security model relies on customers to configure and use our products securely, and customer errors could harm our reputation even when we are not at fault.
- Our ability to sell our products and subscriptions is dependent on the quality of our technical support services and those of our channel partners, and the failure to offer high-quality technical support services could have a material adverse effect on our end-customers’ satisfaction with our products and subscriptions, our sales, and our operating results.
- Our subscription agreements typically contain service-level commitments, and failure to meet these commitments could reduce our revenue and harm our business.
- We rely on data center facilities operated by third-party cloud service providers, and any limitations on capacity, or interference with our use could adversely affect our business, financial condition, and results of operations.
- Claims by others that we infringe their intellectual property rights could harm our business.
- Our proprietary rights may be difficult to enforce or protect, which could enable others to copy or use aspects of our products or subscriptions without compensating us.
- Our use of open source software in our products and subscriptions could negatively affect our ability to sell our products and subscriptions and subject us to possible litigation.
- We license technology from third parties, and our inability to maintain those licenses could harm our business.
- We depend on manufacturing partners and limited sources of supply for our hardware products, making us susceptible to manufacturing delays, supply shortages, pricing fluctuations, and international trade risks that could prevent timely shipment of customer orders and result in the loss of sales and end-customers.
- If we are unable to attract, retain, and motivate our key technical, sales, and management personnel, our business could suffer.
- We generate a significant amount of revenue from sales to distributors, resellers, and end-customers outside of the United States, and we are therefore subject to a number of risks associated with international sales and operations, including export and import controls that could subject us to liability or impair our ability to compete in international markets.
- Our products and subscriptions are subject to certification, testing, and regulatory approval requirements in foreign jurisdictions, and our failure to obtain or maintain such approvals could limit our ability to sell in those markets.
- We are exposed to fluctuations in foreign currency exchange rates, which could negatively affect our financial condition and operating results.
- We face risks associated with having operations and employees located in Israel.
- We may incur significant costs to comply with privacy and data protection laws and other requirements, and, if we fail to comply, we could be subject to government enforcement actions, private litigation, and adverse publicity, which could materially adversely affect our business, financial condition, and operating results.
- We may have exposure to tax liabilities that are greater than anticipated.
- Our estimates or judgments, including those relating to our critical accounting policies, are based on assumptions that may change or prove to be incorrect and, as a result, our operating results may differ from our publicly announced guidance or the expectations of securities analysts and investors, which may result in a decline in the market price of our common stock.
- We are obligated to maintain proper and effective internal control over financial reporting. We may not complete our analysis of our internal control over financial reporting in a timely manner, or our internal control may not be determined to be effective, which may adversely affect investor confidence in our company and, as a result, the value of our common stock.
- The issuance of additional common stock in connection with financings, acquisitions, investments, our stock incentive plans, convertible notes, or otherwise will dilute the stock held by all other stockholders.
- We may not have the ability to raise the funds necessary to settle conversions of the 2030 Notes, repurchase the 2030 Notes upon a fundamental change, or repay the 2030 Notes in cash at their maturity, and our other debt may contain limitations on our ability to pay cash upon conversion or repurchase of the 2030 Notes.
- The Capped Calls may affect the value of the 2030 Notes and our common stock.
- 18 -
Risks Related to Global Economic and Geopolitical Conditions
Our operating results may be adversely affected by unfavorable economic and market conditions and the uncertain geopolitical environment.
We operate globally, and our business and revenues are impacted by global economic and geopolitical conditions. Instability in global credit markets, inflation, changes in public policies, changes in domestic and international regulations, changes in interest rates, foreign currency exchange rate fluctuations, trade regulations and tariffs, international trade disputes and agreements, changes in tax laws, geopolitical turmoil, and other disruptions to global and regional economies and markets continue to add uncertainty to global economic conditions. Military actions or armed conflict, including the hostilities in Israel and the surrounding region, the Russia-Ukraine war and related political or economic responses, and uncertainty about, or changes in, government and trade relationships could further worsen economic and market conditions and the geopolitical environment. For example, in response to Russia’s invasion of Ukraine, the United States, along with the European Union (the “E.U.”), has imposed restrictive sanctions on Russia, Russian entities, and Russian citizens. We are subject to these governmental sanctions and export controls, which may subject us to liability if we are not in full compliance with applicable laws. In addition, government-mandated restrictions on technology access, including export controls, import restrictions, or requirements that certain technologies not be made available in particular countries or regions, could limit our ability to sell or support our products and subscriptions in affected markets, require us to modify or discontinue certain products or features, or require us to exit certain markets. Any continued or further uncertainty or deterioration in economic and market conditions or the geopolitical environment, or any expansion or imposition of government-mandated technology restrictions, could have a material and adverse impact on our business, financial condition, and operating results, including reductions in sales, longer sales cycles, reductions in subscription or contract duration and value, slower adoption of new technologies, changes in spending patterns or priorities of current and prospective customers, increased component, memory or compute costs, and increased price competition.
Risks Related to Our Business
RISKS RELATED TO OUR GROWTH
Our business and operations have experienced growth in recent periods, and if we do not effectively manage our future growth or are unable to improve our systems, processes, and controls, our business and operating results could be adversely affected.
We have experienced growth and increased demand for our products and subscriptions over recent years. As a result, our employee headcount has increased, and we expect it to continue to grow over the next year. For example, from the end of fiscal 2025 to the end of fiscal 2026, our headcount increased from 16,068 to 21,921 employees, including approximately 4,223 additional headcount as a result of the CyberArk acquisition. In addition, as we have grown, the number of end-customers has also increased, and we have managed more complex deployments of our products and subscriptions with larger end-customers. The growth and expansion of our business and products, subscriptions, and support offerings places a significant strain on our management, operational, and financial resources. To manage any future growth effectively, we must continue to improve and expand our information technology and financial infrastructure, our operating and administrative systems and controls, and our ability to manage headcount, capital, and processes in an efficient manner.
We may not be able to successfully implement, scale, or manage improvements to our systems, processes, and controls in an efficient or timely manner, and our existing systems, processes, and controls may not prevent or detect all errors, omissions, or fraud. Any future growth would add complexity to our organization and require effective coordination. Failure to manage any future growth effectively could result in increased costs, disruption to end-customer relationships, reduced demand for our products, or material harm to our business and operating results.
Our revenue growth rate in recent periods may not be indicative of our future performance, and we may not be able to maintain profitability, which could cause our business, financial condition, and operating results to suffer.
We have experienced revenue growth rates of 24% and 15% in fiscal 2026 and fiscal 2025, respectively. Our revenue for any quarterly or annual period should not be relied upon as an indication of our future revenue or revenue growth for any future period. If we are unable to maintain consistent or increasing revenue or revenue growth, the market price of our common stock could be volatile, and it may be difficult for us to maintain profitability or maintain or increase cash flow on a consistent basis.
In addition, we anticipate that our operating expenses will continue to increase as our business grows. Our growth efforts may prove more expensive than we currently anticipate, and we may not succeed in increasing our revenues sufficiently to offset increasing expenses. Revenue growth may slow or decline, including due to slowing or declining demand, increasing competition, market shifts, or a failure to capitalize on growth opportunities. We have also entered into substantial capital commitments for operating lease obligations and other purchase commitments. If we are unable to increase our revenue sufficiently to offset these costs and commitments, our profitability, cash flow, financial condition, and operating results may suffer.
- 19 -
Our operating results may vary significantly from period to period, including due to seasonality, which makes our results difficult to predict and could cause our results to fall short of expectations.
Our operating results have fluctuated in the past, and will likely continue to fluctuate in the future, as a result of a number of factors, many of which are outside of our control, including those described in this Risk Factors section. For example, we have historically received a substantial portion of sales orders and generated a substantial portion of revenue during the last few weeks of each fiscal quarter. If expected revenue at the end of any fiscal quarter is delayed for any reason, including failed purchase orders, logistics delays, inventory management issues, trade compliance requirements (and changes to such requirements), or failure of systems related to order review and processing, our revenue could fall below our expectations and the estimates of analysts for that quarter. In addition, seasonal factors may cause our second and fourth fiscal quarters to record greater revenue sequentially than our first and third fiscal quarters, driven primarily by end-customer budget cycles, our annual sales compensation structure, and the timing of calendar-year budget planning. As we grow, these seasonal and cyclical variations may become more pronounced. Due to these fluctuations, comparing our results on a period-to-period basis may not be meaningful, and our past results should not be relied on as an indication of our future performance.
This variability and unpredictability could also result in our failure to meet our revenue, margin, or other operating result expectations contained in any forward-looking statements (including financial or business expectations we have provided) or those of securities analysts or investors for a particular period. If we fail to meet or exceed such expectations for these, or any other, reasons, the market price of our common stock could fall substantially, and we could face costly lawsuits, including securities class action suits.
RISKS RELATED TO OUR PRODUCTS AND TECHNOLOGY
If we are unable to sell new and additional products, subscriptions, and support offerings to existing end-customers or attract new customers, especially large enterprise customers, our future revenue and operating results will be harmed.
Our future success depends, in part, on our ability to expand the deployment of our portfolio and new offerings with existing end-customers, especially large enterprise customers, including through our platformization and go-to-market strategies, and to attract new customers. The rate at which existing end-customers purchase additional products, subscriptions, and support offerings, and our ability to win new customers, depend on a number of factors, including the perceived need for security products, including related subscription and support offerings, general economic conditions, switching costs from incumbent vendors, and the time and resources required to deploy our solutions. We are engaging in costly marketing and sales efforts to accelerate our strategies, including platformization, which may not be as successful as intended. Any deterioration in general economic conditions, including as a result of the geopolitical or economic environment, may cause current and prospective customers to delay or cut their overall security and IT spending. If our efforts to sell additional products and subscriptions to existing end-customers or attract new customers are not successful, our revenues may grow more slowly than expected or decline.
Sales to large enterprise end-customers involve risks not typically present with smaller entities, including longer sales cycles, the risk that substantial resources may be spent on a potential end-customer that does not ultimately purchase our products, subscriptions, and support offerings, and increased purchasing power and leverage held by large end-customers in negotiating contractual arrangements. Deployments for large enterprise end-customers are also more complex, require greater product functionality and scalability, and are resource-intensive. Failure to realize sales from large enterprise end-customers could materially and adversely affect our business, financial condition, and operating results.
We rely on revenue from subscription and support offerings, and because we recognize revenue from subscription and support over the term of the relevant service period, downturns or upturns in sales or renewals of these subscription and support offerings are not immediately reflected in full in our operating results.
Subscription and support revenue accounts for a significant portion of our revenue, comprising 80% of total revenue in fiscal 2026, 81% in fiscal 2025, and 80% in fiscal 2024. Sales and renewals of subscription and support contracts may decline and fluctuate as a result of a number of factors, including end-customer satisfaction levels with our products and subscriptions, subscription outages, product uptime or latency, pricing, and reductions in our end-customers’ spending levels. Existing end-customers have no contractual obligation to renew their subscription and support contracts after their initial contract period and may renew for shorter contract terms or terms that are less economically beneficial to us, or not at all. If our sales of new or renewal subscription and support contracts decline, our total revenue and revenue growth rate may decline. Because we recognize subscription and support revenue over the term of the service period typically one to five years, a decline in subscription or support contracts in any one fiscal quarter will not be fully or immediately reflected in that quarter’s revenue but will negatively affect future fiscal quarters.
Our consumption- or usage-based offerings may expose us to customer usage optimization behavior that could create revenue volatility.
A growing portion of our revenue is generated from offerings priced on a consumption or usage basis, including certain of our observability and AI-related offerings. Pricing on this basis may result in significant near-term revenue growth as customers scale their usage but also creates exposure to customer optimization behavior, where customers who have rapidly increased usage subsequently seek to reduce, optimize, or reconfigure their consumption or usage to lower costs. This dynamic has been observed in the industry with cloud-native customers and, more recently, with AI-native
- 20 -
customers, whose data volumes and usage patterns can fluctuate significantly. Certain customer cohorts, including large enterprises and AI-native customers, may represent a meaningful portion of our consumption- or usage-based revenue growth, and any material optimization or reduction in usage by these cohorts, or their failure to renew subscriptions on comparable terms, could result in revenue volatility. If we are unable to accurately forecast or manage consumption or usage dynamics, our business, financial condition, and operating results may be adversely affected.
The sales prices of our products, subscriptions, and support offerings may decrease, which may reduce our revenue and gross profits and adversely impact our financial results.
The sales prices for our products, subscriptions, and support offerings may decline for a variety of reasons, including competitive pricing pressures, discounts, changes in our product mix, anticipation of new offerings, or promotional programs. We also anticipate that sales prices and gross profits for our products, subscriptions, and support offerings could decrease over product life cycles. Declining sales prices could reduce our revenue, gross profits, and profitability and adversely impact our financial and operational results.
We rely on our channel partners to sell a substantial portion of our products, including subscriptions and support, and if these channel partners fail to perform, our ability to sell and distribute our products and subscriptions will be limited and our operating results will be harmed.
A substantial portion of our revenue is generated by sales through our channel partners, including distributors and resellers. For fiscal 2026, two distributors individually represented 10% or more of our total revenue and in the aggregate represented 30% of our total revenue. As of July 31, 2026, one distributor individually represented 19% of our gross accounts receivable.
Training and programs provided to our channel partners to assist them in selling our products, subscriptions, and support offerings may not be effective or utilized. Our channel partners may be unsuccessful in marketing, selling, and supporting our products and subscriptions, and we may not be able to incentivize our channel partners to sell our products and subscriptions, or our channel partners may have incentives to promote our competitors' products and subscriptions. Our agreements with channel partners may generally be terminated for any reason by either party with advance notice prior to each annual renewal date, and we cannot be certain that we will retain them or secure additional or replacement channel partners. Any new channel partner requires extensive training and may take months to achieve productivity. Our channel partner structure could also subject us to lawsuits, liability, and reputational harm if, for example, channel partners misrepresent the functionality of our products or subscriptions or violate laws or our policies. If we fail to effectively manage our channel partners, our ability to sell our products and subscriptions and our operating results will be harmed.
We are exposed to the credit and liquidity risk of our customers, and to credit exposure in weakened markets, which could result in material losses.
Most of our sales are made on an open credit basis, and we have also experienced demands for customer financing and deferred payments due to, among other things, macro-economic conditions. Increases in deferred payments negatively impact our short-term cash flows and subject us to risk of non-payment, including as a result of insolvency. Our efforts to monitor customer payment capability and maintain reserves adequate to cover exposure for doubtful accounts may not be effective. Our exposure to these credit risks may increase if our customers are adversely affected by an economic downturn. In the past, we have experienced non-material losses due to customer bankruptcies or insolvency. If credit market turmoil makes it more difficult for customers to obtain financing or affects their ability to pay, or if these losses increase, our business, financial condition, and operating results could be materially adversely affected.
A portion of our revenue is generated by sales to government entities, which are subject to a number of challenges and risks.
Sales to government entities are subject to a number of risks. Selling to government entities can be highly competitive, expensive, and time-consuming, often requiring significant upfront investment of resources without any assurance of generating a sale and involving longer sales cycles. The substantial majority of our government sales to date have been made indirectly through our channel partners. Government certification and technical requirements may change, and if our products and subscriptions fail to achieve or are late in achieving compliance with these certifications and standards or technical requirements, we may be disqualified or restricted from selling to such entities or be at a competitive disadvantage. Government demand and payment for our products, subscriptions, and support offerings may be impacted by government shutdowns, changes in administrations, budgetary cycles, contracting policies, fiscal policies, and funding authorizations, with funding reductions or delays adversely affecting public sector demand for our products, subscriptions, and support offerings. Government entities may also have rights to terminate contracts for convenience or due to a default, and government audits of their contractors, suppliers, or vendors could result in the government refusing to continue purchasing our products, subscriptions, and support offerings, revenue reductions, or fines and civil or criminal liability, all of which may adversely impact our operating results. Additionally, the U.S. government may require certain products to be manufactured domestically or in other relatively high-cost manufacturing locations, and we may not manufacture all products in locations that meet such requirements, affecting our ability to sell our offerings to the U.S. government.
- 21 -
We face intense competition and we may lack sufficient financial or other resources to maintain or improve our competitive position.
The industry for enterprise security products and the other spaces in which we have offerings is intensely competitive, and we expect competition to increase in the future from established competitors and new market entrants. Our main competitors fall into four categories:
- large companies that incorporate security or observability features in their products, such as Alphabet Inc., Cisco Systems, Inc., and Microsoft Corporation, or those that have acquired, or may acquire, security vendors and have the technical and financial resources to bring competitive solutions to the market;
- independent vendors that may offer a mix of security products, such as Check Point Software Technologies Ltd., CrowdStrike Holdings, Inc., Delinea, Inc., Fortinet, Inc., Okta, Inc., SailPoint Technologies, Inc., and Zscaler, Inc., vendors that may offer a mix of observability products, such as DataDog, Inc., Dynatrace, Inc., and elasticsearch B.V., or vendors that may offer a mix of security and observability products;
- startups and point-product vendors that offer independent or emerging solutions across various areas of security; and
- public cloud vendors and startups that offer solutions for cloud security (private, public, and hybrid cloud).
Some of our competitors have or may attain greater financial, technical, marketing, sales, and other resources, greater name recognition, longer operating histories, and a larger base of customers than we do. Our competitors may devote greater resources to the research and development, promotion and sale of products and services, offer lower pricing, and have broader product and service offerings and more mature intellectual property portfolios to gain business in a manner that discourages users from purchasing our products and subscriptions, including incorporating cybersecurity features into their existing products or services, product bundling, selling at zero or negative margins, and offering concessions. We also face competition from companies with entrenched legacy offerings. End-user customers who have invested substantial resources in their existing infrastructure may prefer to continue purchasing from their existing suppliers rather than switch to our products and subscriptions. As our customers refresh security products, achieve efficiencies, or face budget constraints or economic downturns, they may seek to consolidate vendors or add solutions to their existing infrastructure rather than replacing it with our products and subscriptions.
The maturity and expansion of the enterprise cybersecurity space may attract new players, including cloud hyperscalers, advance AI companies and enterprise software companies in adjacent industries, which may meaningfully enter or further expand into additional cybersecurity categories, including the identity security category. Conditions in our market could change rapidly as a result of technological advancements, including with respect to artificial intelligence ("AI"), acquisitions or strategic investments by our competitors, or continuing market consolidation. Our competitors may develop new or disruptive technologies, products, or services that are equal or superior to ours, more successfully incorporate AI into their products and achieve higher market acceptance of their AI solutions, or deliver products to market more quickly than we can. To compete successfully, we must accurately anticipate technology developments and deliver innovative, relevant, and useful products and technologies in a timely manner. Our current and potential competitors may also establish cooperative relationships among themselves or with third parties that may further enhance their resources or offerings.
These competitive pressures in our market or our failure to compete effectively may result in price reductions, fewer orders, reduced revenue and gross margins, and loss of market share. If we are unable to compete successfully, or if competing successfully requires us to take aggressive pricing or other actions, our business, financial condition, and operating results would be adversely affected.
The “identity security” market lacks a universally accepted definition, which could lead to mischaracterization of our offerings and adverse evaluations by industry stakeholders.
We have significantly expanded our participation in what is commonly referred to as the “identity security” market. However, this market lacks a standardized definition and is subject to varying interpretations by industry analysts, customers, and competitors. This ambiguity could lead to mischaracterization of our identity security products or market positioning by industry stakeholders, resulting in unfavorable evaluations, reviews, or accreditations. Industry analyst reports and rankings can materially influence customer purchasing decisions in the security industry, and unfavorable reviews, downgrades in accreditation, or evolving definitions of the identity security category could negatively affect our reputation, competitive standing, and ability to attract and retain customers.
Customer trends toward vendor consolidation in cybersecurity may favor competitors offering broader platforms.
Enterprise cybersecurity buyers are increasingly seeking to consolidate their vendors to reduce costs, complexity, and integration challenges. While our platformization strategy is designed to benefit from this trend, consolidation may also create opportunities for competitors, including large cybersecurity platform vendors, cloud hyperscalers, and enterprise software companies, to offer broader bundled solutions that include capabilities in categories where we compete, such as identity security and observability. If customers choose to consolidate with vendors offering more comprehensive suites, or if competitors more successfully utilize acquisitions or partnerships to combine capabilities, we may be at a competitive disadvantage. Furthermore, organizations continuously evaluate their information security priorities and may allocate budgets to solutions offered by our competitors, or may not adopt or expand the use of our solutions, which could adversely affect our business, financial condition, and operating results.
- 22 -
Cloud infrastructure providers and advanced AI companies increasingly offer native security and observability capabilities that compete directly with our offerings.
The major public cloud infrastructure providers increasingly offer native security, identity, and observability capabilities that compete with our products and subscriptions. These providers have significant resources and may bundle native capabilities with their cloud infrastructure services at low or no incremental cost to customers, may leverage privileged access to their platforms and telemetry, and may design their native offerings to integrate more seamlessly with their infrastructure than third-party solutions can. As customers increasingly deploy workloads across multiple cloud environments, or as cloud providers expand the scope and depth of their native security and observability capabilities, demand for our offerings could be adversely affected. We may also face pricing pressure as competitors utilize cloud provider economics or offer bundled solutions at reduced total cost of ownership.
In addition, frontier or foundational AI model providers, or similar companies with advanced large language model capabilities, have entered or may enter the cybersecurity and observability markets, whether directly, through partnerships, or by enabling third parties to build competing security applications on top of their models. These companies possess substantial capital, technical talent, and have developed, or proprietary access to, foundational or frontier AI models. Their ability to rapidly iterate on model capabilities, attract AI research talent, and leverage significant compute infrastructure may allow them to introduce competing security capabilities more quickly or at lower cost than we can. If these or other AI companies develop and commercialize security products or embed security functionality into their broader AI platforms, customers may choose to consolidate their security spend with such providers rather than purchase our solutions, which could adversely affect our revenue, market share, and competitive position.
We have acquired and may in the future acquire other businesses, which could subject us to adverse claims or liabilities, require significant management attention, disrupt our business, adversely affect our operating results, may not result in the expected benefits of such acquisitions, and may dilute stockholder value.
As part of our business strategy, we acquire and make investments in complementary companies, products, or technologies. We continue to evaluate such opportunities and expect to continue to make such acquisitions and investments in the future. The identification of suitable acquisition candidates is difficult, and we may not be able to complete such acquisitions on favorable terms, if at all. In addition, we may be subject to claims or liabilities assumed from an acquired company, product, or technology; acquisitions we complete could be viewed negatively by our end-customers, investors, and securities analysts; and we may incur costs and expenses necessary to address an acquired company’s failure to comply with laws and governmental rules and regulations. Additionally, we may be subject to litigation or other claims in connection with the acquired company, product, or technology, including claims from terminated employees, customers, former stockholders, or other third parties, which may differ from or be more significant than the risks our business faces.
If we are unsuccessful at integrating past or future acquisitions in a timely manner or at all, our revenue and operating results could be adversely affected. Any integration process may require significant time and resources, which may disrupt our ongoing business and divert management’s attention. We may have difficulty retaining key personnel or customers of the acquired business, or may not successfully evaluate or utilize acquired technology, products, or personnel, realize anticipated synergies, or accurately forecast the financial impact of an acquisition or its integration, including accounting charges and any potential impairment of goodwill and intangible assets. In particular, we believe there are significant benefits and synergies that may be realized from our recent acquisitions of CyberArk and Chronosphere, including through leveraging our combined products, scale, and enterprise customer bases. However, integrating these businesses is a complex process that may disrupt our existing operations if not implemented efficiently. The full benefits of these acquisitions, including the anticipated sales or growth opportunities, may not be realized as expected or within the anticipated time frame, or at all.
We have recorded, and may in the future record, liability for contingent consideration obligations from acquisitions that are to be settled in cash, the fair value of which is assessed on a quarterly basis. If changes are made in our assumptions used to determine the liability’s fair value or our assumptions are incorrect, adjustments could be made that may have a material impact, favorable or unfavorable, on our operating results. We may also be required to make cash payments of contingent consideration in excess of its initial fair value, or in excess of our expectations for a particular period, which could adversely impact cash flows.
We may have to pay cash, incur debt, or issue equity or equity-linked securities to pay for any future acquisitions, each of which could adversely affect our financial condition or the market price of our common stock and result in dilution to our stockholders.
In addition, any acquisitions may be viewed negatively by our customers, financial markets, or investors and may not ultimately strengthen our competitive position or achieve our goals and business strategy. The occurrence of any of these risks could harm our business, financial condition, and operating results.
As a result of the CyberArk acquisition, the scope and size of our business have substantially changed, which resulted in certain incremental risks, including increased competition.
Our recent CyberArk acquisition has expanded the scope and size of our business by adding substantial assets and operations to our existing business. The integration process for CyberArk could create uncertainty for our and CyberArk’s employees, partners, and customers, divert senior management’s attention, and result in disruption to existing business relationships and the development of new business relationships.
- 23 -
Our success, including with respect to realizing the anticipated benefits and synergies from the CyberArk acquisition, will depend, in part, on our ability to manage our expansion, which poses numerous risks and uncertainties, including the need to integrate the operations and business of CyberArk into our existing business in a timely and efficient manner, to combine systems and management controls, and to integrate relationships with industry contacts and business partners. In addition, we will be required to devote significant attention and resources to successfully align our and CyberArk’s business practices and operations. This process may disrupt our business and, if ineffective, would limit the anticipated benefits and synergies of the acquisition.
In addition, we expect that the CyberArk acquisition will result in increased competition, including as a result of our entry into a new product category. The identity security industry is characterized by constant innovation, evolving customer requirements, and rapid adoption of different technologies and services. These added competitive pressures could result in decreased sales, price reductions, increased operating costs, and lower revenues, margins, and net income for the combined company. These impacts could also result in a delay in realizing, or our failure to realize, expected synergies or cost savings from the CyberArk acquisition.
The occurrence of any of these risks could harm our business, financial condition, and operating results.
If we do not accurately predict, prepare for, and respond promptly to rapidly evolving technological and market developments and successfully manage product and subscription introductions and transitions to meet changing end-customer needs in the enterprise security industry, our competitive position and prospects will be harmed.
The enterprise security industry has grown quickly and continues to evolve rapidly. Moreover, many of our end-customers operate in markets characterized by rapidly changing technologies and business plans, which require them to add numerous network access points and adapt increasingly complex enterprise networks, incorporating a variety of hardware, software applications, operating systems, and networking protocols. If we fail to effectively anticipate, identify, and respond to rapidly evolving technological and market developments in a timely manner, our business will be harmed.
In order to anticipate and respond effectively to rapid technological changes and market developments, as well as evolving security threats, we must invest effectively in research and development to increase the reliability, availability, and scalability of our existing products and subscriptions and introduce new products and subscriptions. Our investments in research and development, including investments in AI, may not result in design or performance improvements, marketable products, subscriptions, or features, or may not achieve the cost savings or additional revenue that we expect. In addition, new and evolving products and services, including those that use AI, require significant investment and raise ethical, technological, legal, regulatory, and other challenges, which may negatively affect our brands and demand for our products and services. Because all of these investment areas are inherently risky, no assurance can be given that such strategies and offerings will be successful or will not harm our reputation, financial condition, and operating results.
We must also continually adapt our products and strategy in response to changes in network infrastructure requirements, including the expanding use of cloud computing and third-party service providers. While we have historically been successful in developing or acquiring and marketing new products and product enhancements that respond to technological and industry changes, we cannot assure that our new or future offerings will achieve widespread market acceptance or be successful. If we fail to accurately predict and address end-customers’ changing needs and emerging technological trends, including in the areas of AI, mobility, virtualization, cloud computing, and software-defined networks, our business could be harmed. The technology in our portfolio is especially complex because it needs to effectively identify and respond to new and increasingly sophisticated methods of attack while minimizing the impact on network performance. Some of our new features and enhancements may require us to develop new hardware architectures involving complex, expensive, and time-consuming research and development processes, and the timetable for commercial availability is uncertain. The success of new products depends on several factors, including appropriate product definition, differentiation from competitors, market acceptance, management of production ramp-up issues, availability of application software, effective management of purchase commitments and inventory, and the risk that new products may have quality defects in the early stages of introduction. If we fail to identify opportunities for new products and subscriptions, experience unanticipated delays in the availability of new products and subscriptions, or fail to meet customer expectations, our competitive position and business prospects will be harmed.
Furthermore, we may require additional funds to respond to business challenges, including the need to develop new features to enhance our portfolio, improve our operating infrastructure, or acquire complementary businesses and technologies. Accordingly, we may need to engage in equity or debt financings to secure additional funds, which may contain terms that, among other things, restrict our ability to incur additional indebtedness. In addition, we may be required to take other actions that would otherwise be in the interests of the debt holders and would require us to maintain specified liquidity or other ratios, any of which could harm our business, financial condition, and operating results. If we are unable to obtain adequate financing or financing on terms satisfactory to us when we require it, our ability to continue to support our business growth and to respond to business challenges could be significantly impaired, and our business may be adversely affected.
The success of our strategy depends on maintaining a broad ecosystem of integrations with third-party technologies, which requires significant ongoing investment.
- 24 -
The success of our strategy depends in part on the breadth and depth of our integrations with third-party technologies, including cloud infrastructure providers, identity providers, security tools, and business applications. Maintaining and expanding these integrations requires continuous engineering, sales, and marketing investment, and we may not always be able to develop, maintain, or update integrations as quickly as customers or channel partners expect. Third-party technology vendors may modify their APIs, deprecate integrations, or introduce competing capabilities that reduce the need for our platform integrations. If we are unable to maintain a broad and current integration ecosystem, or if certain third-party vendors limit or terminate their integrations with our platform, the utility of our offerings could be reduced, adversely affecting our business, financial condition, and operating results.
Issues in the development, deployment, or use of AI may result in reputational harm, legal liability, and could adversely affect our business and operating results.
We have incorporated, and are continuing to develop and deploy, AI into many of our products, solutions, and business operations. AI presents challenges, risks, and potentially unintended consequences. For example, AI algorithms may have flaws, and training datasets may be insufficient or contain biased information. The AI incorporated into our products and operations may not be successful or beneficial, and instead may cause technical, legal, or ethical problems or result in increased costs. Our investments in AI ultimately may not be commercially viable or result in an adequate return of capital, and this could depress the market price of our stock or lead to us incurring unanticipated liabilities.
Vulnerabilities within our AI systems may be identified by researchers or malicious actors before we detect or remediate them, which could result in security incidents, data privacy issues, reputational damage, or loss of customer confidence. Advances in AI have also increased the speed, scale, and sophistication of cybersecurity threat activity, including reducing the time between vulnerability discovery and exploitation. To the extent customers, investors, or other market participants perceive that AI can automate or commoditize aspects of cybersecurity functions, the perceived value of certain cybersecurity solutions could diminish, and customer buying patterns, competitive dynamics, and demand for our products, subscriptions, and support offerings could be adversely affected. Investor and market perceptions regarding AI-related disruption to the cybersecurity industry could adversely affect our business and operating results, or the trading price of our common stock, even if these perceptions do not reflect actual changes in our business, customer demand, competitive positions, or financial performance.
The rapid evolution of AI, including current and future government regulation of AI, requires us to invest significant resources to develop, test, and maintain AI in our products and services in a manner that meets evolving requirements and expectations. The laws, rules, and regulations that have and continue to be adopted by policymakers, and the manner in which such requirements are interpreted or enforced, may require us to incur additional costs to comply with such requirements or make changes to our business practices, including our products and services that incorporate AI. Our efforts and investments regarding AI, and our failure or perceived failure to comply with applicable legal requirements, could damage our customer relationships, cause brand or reputational harm, or subject us to regulatory risk and legal liability, including under laws, rules, and regulations in jurisdictions such as the E.U. and U.S. and laws and regulations in other jurisdictions in which we and our customers operate. Developing, testing, and deploying AI systems may also increase the cost profile of our offerings due to the nature of the computing costs involved in such systems.
The intellectual property ownership and license rights surrounding AI technologies, as well as data protection laws related to the use and development of AI, are currently not fully addressed by courts or regulators. The use or adoption of AI technologies in our products may result in exposure to claims by third parties, including alleging copyright infringement or other intellectual property misappropriation, which may require us to pay compensation or license fees to third parties, as well as regulatory action and enforcement. The evolving legal, regulatory, and compliance framework for AI technologies may also impact our ability to protect our own data and intellectual property against infringement.
The cybersecurity industry is undergoing a transformation as customers increasingly expect AI-native solutions that are designed from the ground up to leverage AI capabilities. If we fail to anticipate, invest in, or execute on the transition to AI-native platforms, or if our competitors develop AI-native offerings that achieve greater market acceptance, we may miss critical opportunities for growth and market leadership, and our business, including our gross margin, and competitive position could be materially harmed.
The emergence of AI agents as a new class of identity presents both opportunities and risks that could impact our identity security offerings.
The rapid deployment of generative AI systems and AI agents is creating a new class of identity that requires authenticated, secure access to sensitive resources at a scale and speed exceeding traditional identity models designed for human users. As AI agents gain capabilities and access within organizations, managing their identities and permissions is emerging as a significant operational and security challenge. The ability of our identity security solutions to evolve to effectively secure this new identity class will depend on continued investment in research and development, the availability of appropriate AI technologies, and market acceptance of our approach and products. If we fail to adequately address the security requirements associated with AI agents, or if our competitors more effectively secure AI identities, demand for our offerings could decline. Additionally, evolving standards, customer expectations, or regulatory requirements could require us to make significant changes to our offerings.
- 25 -
A significant network or data security incident may materially impact our reputation, financial condition, and operating results.
Like all companies, our systems, data, and products are subject to an increasingly wide variety of attacks on an ongoing basis from a variety of sources, including from traditional hackers, malicious code, phishing and ransomware attacks, employee theft or misuse, and sophisticated nation-state actors engaging in intrusions and attacks, including advanced persistent threat intrusions and supply chain attacks. Despite our efforts to prevent breaches, our data, products, corporate systems, and security measures, as well as those of our third-party service providers, remain vulnerable. Malicious actors are using AI to develop advanced cyberattacks and to exploit system vulnerabilities that are not known or remediated. We cannot guarantee that our security measures will provide adequate protection. As a well-known provider of security solutions, we and others in our industry are attractive targets for cyberattacks. The geopolitical environment, including the Russia-Ukraine war and other global events as described in "Risks Related to Global Economic and Geopolitical Conditions" above, increase the risk of cyberattacks on our infrastructure and operations. Because certain third-party service providers are critical to our business, such as cloud services that support various customer-facing operations, cyberattacks that compromise third-party systems could materially impact us.
A significant security breach or incident suffered by us or our third-party service providers could materially impact the confidentiality, integrity, or availability of our networks and products, or networks secured by our products and subscriptions, creating system disruptions and compromise of information. Information stored or otherwise processed on our networks or those of our third-party service providers has previously been, and could in the future be, accessed, disclosed, altered, lost, or stolen, or otherwise used or processed without authorization. Any actual or perceived vulnerability, breach, or data security incident we or our third-party service providers suffer could result in significant reputational damage, loss of channel partners and end-customers, regulatory investigations or enforcement actions, costly litigation, and other liability. We may also incur significant costs and expend significant resources to investigate, remediate, and prevent future incidents, as well as costs to comply with notification obligations resulting from any security incidents. Any of these outcomes could adversely impact the market perception of our products and subscriptions and end-customer and investor confidence in our company, and could materially harm our business, financial condition, and operating results. We cannot guarantee that costs and liabilities incurred in relation to a breach or other incident will be covered by existing insurance policies or that applicable cybersecurity insurance will be available to us in the future on economically reasonable terms or at all.
Defects, errors, or vulnerabilities in our products, subscriptions, or support offerings, the failure of our products or subscriptions to block a virus or prevent a security breach or incident, misuse of our products, or risks of product liability claims could harm our reputation and adversely impact our operating results.
Because our products and subscriptions are complex, they have contained and may contain design or manufacturing defects, vulnerabilities, or errors that are not detected until after deployment. For example, end-customers have reported defects in our products related to performance, scalability, and compatibility. Defects or vulnerabilities may cause our products or subscriptions to become unavailable, to be vulnerable to security attacks, fail to secure networks, or interrupt end-customers’ networking traffic. For example, in May 2026, we became aware of an authentication bypass vulnerability in certain versions of our PAN-OS software and published a security advisory, provided software updates, and engaged in customer outreach, support, and remediation efforts. Because attack techniques change frequently and are generally not recognized until launched, we are unable to comprehensively anticipate, detect, or provide responsive solutions or remediation in all instances. As described in "Risks Related to Global Economic and Geopolitical Conditions" above, the geopolitical environment increases the risk of cyberattacks against us and our customers.
Defects or errors in our products or software, or migrations or updates, could result in a failure to effectively update end-customers’ hardware, software, and products or otherwise cause problems in our customers’ hardware, networks, software, or IT infrastructure. Defects, errors, or a technical failure of our products may temporarily or permanently disable our end-customers’ networks, IT infrastructure, or other systems. Our products must interoperate with end-customers’ existing infrastructure, which often has varied specifications, multiple protocol standards, and products from multiple vendors. When problems occur, it may be difficult to identify the source. The data centers, networks, and cloud infrastructure we use to deliver our products, subscriptions, and support offerings may experience technical failures or downtime that could expose end-customers’ networks to security threats or attacks.
The occurrence of any such problem in our products and subscriptions, or migrations or updates to those products or software, whether real or perceived, could result in:
- expenditure of significant financial and product development resources in efforts to analyze, correct, eliminate, or work-around errors or defects or to address and eliminate vulnerabilities;
- loss of existing or potential end-customers or channel partners;
- delayed or lost revenue;
- delay or failure to attain market acceptance;
- an increase in warranty claims compared with our historical experience, or an increased cost of servicing warranty claims, either of which would adversely affect our gross margins; and
- 26 -
- litigation, regulatory inquiries, investigations, or other proceedings, each of which may be costly and harm our reputation.
Our products and subscriptions may be misused by end-customers or third parties. For example, our products and subscriptions could be used to censor private access to information on the Internet. Such misuse could result in negative press coverage and harm our reputation.
The limitation of liability provisions in our standard terms and conditions may not fully or effectively protect us from claims as a result of applicable laws or unfavorable judicial decisions. The sale and support of our products and subscriptions also entails the risk of product liability claims. Indemnification by third-party manufacturers may not cover claims arising from design or manufacturing defects. Additionally, our insurance coverage may not adequately cover claims asserted against us, and even unsuccessful claims could result in litigation expenses, diversion of management's attention, and reputational harm.
In addition, our classifications of application type, virus, spyware, vulnerability exploits, data, or URL categories may falsely detect and act on threats that do not actually exist. This risk is heightened by the inclusion of heuristics features in our products and subscriptions that identify threats based on characteristics or anomalies rather than known signatures. These false positives may impair the perceived reliability of our products and adversely impact market acceptance of our products and subscriptions, our reputation, and our sales, and result in loss of channel partners or end-customers.
Our shared responsibility security model relies on customers to configure and use our products securely, and customer errors could harm our reputation even when we are not at fault.
We deliver certain of our products under a model in which we are responsible for the security of the underlying platform and infrastructure and our customers are responsible for configuring, deploying, patching, and using our products and configuring and implementing the security controls and posture within their environments. Customers may fail to implement, or may misconfigure, security features made available in our products and subscriptions, or may fail to follow best practices, resulting in security incidents affecting their environments or data. Even if we are not the cause of a customer security incident, our reputation, brand, and customer relationships may nonetheless be adversely impacted. Enterprise customers, regulators, and the market generally may not consistently distinguish between security incidents caused by our products and those caused by a customer failing to implement or misconfiguring security features of our products, and we may face claims, negative publicity, or regulatory scrutiny in either case. Any such incidents could adversely affect market perception of our offerings and, correspondingly, our business, financial condition, and operating results.
Our ability to sell our products and subscriptions is dependent on the quality of our technical support services and those of our channel partners, and the failure to offer high-quality technical support services could have a material adverse effect on our end-customers’ satisfaction with our products and subscriptions, our sales, and our operating results.
After our products and subscriptions are deployed, our end-customers depend on our technical support services and those of our channel partners. Larger enterprise, service provider, and government entity end-customers have more complex networks and require higher levels of support. If our channel partners do not effectively provide support, we may need to provide direct support, requiring additional personnel and resources. If we cannot hire and deploy resources fast enough to meet demand, end-customer satisfaction will be adversely affected, and reliance on sales engineers for post-sales support would negatively impact our sales productivity. Failure by our company and our channel partners to provide high-quality support services could have a material adverse effect on our business, financial condition, and operating results.
Our subscription agreements typically contain service-level commitments, and failure to meet these commitments could reduce our revenue and harm our business.
Our subscription agreements for certain of our product offerings typically contain service-level commitments, including uptime and response time requirements. If we are unable to meet these commitments, we may be contractually obligated to provide service credits, refunds, or, in certain cases, permit customers to terminate their subscriptions. Any such credits or refunds could significantly affect our revenue in the periods in which they are applied. Service-level failures could also damage our reputation, reduce renewals, and expose us to litigation. As our SaaS-based revenues grow and our offerings expand to serve more mission-critical use cases, our exposure to service-level commitment obligations will continue to increase. Any material failure to meet these commitments could adversely affect our business, financial condition, and operating results.
We rely on data center facilities operated by third-party cloud service providers, and any limitations on capacity, or interference with our use could adversely affect our business, financial condition, and results of operations.
We rely on data center facilities operated by third-party cloud service providers to host and operate our cloud-based products and services. Any limitation on the capacity of these third-party providers, or tightening availability of cloud computing resources and machine compute capacity due to increased demand from other customers, supply chain constraints, or allocation decisions by providers, could impede our ability to onboard new customers, expand usage by existing customers, or deliver our products and services with the performance and reliability our customers expect. Demand for cloud computing infrastructure and specialized computing resources, including for AI and machine
- 27 -
learning workloads, has increased significantly across industries, and our third-party providers may prioritize other customers or uses, limit our access to capacity, or be unable to meet our requirements. In addition, decisions by the owners and operators of these data center facilities to terminate our contracts, discontinue services, shut down operations, increase prices, change service levels, limit bandwidth, or prioritize the traffic of other parties could have a material adverse effect on our operations.
RISKS RELATED TO INTELLECTUAL PROPERTY AND TECHNOLOGY LICENSING
Claims by others that we infringe their intellectual property rights could harm our business.
Companies in the enterprise security industry own large numbers of patents, copyrights, trademarks, domain names, and trade secrets and frequently enter into litigation based on allegations of infringement, misappropriation, or other violations of intellectual property rights. Non-practicing entities also frequently bring such claims against companies in the enterprise security industry. Third parties have asserted, and may in the future assert, claims of infringement against us. For example, on January 31, 2024, in the Centripetal Networks, Inc. lawsuit against us, the jury returned a verdict of non-willful infringement, and a judgment was issued on October 3, 2024 assessing damages of $114 million, plus statutory interest, which is currently on appeal. Additional patent infringement cases are disclosed in Note 13. Commitments and Contingencies in Part II, Item 8 of this Annual Report on Form 10-K.
Third parties may also assert such claims against our end-customers or channel partners, whom our standard license and other agreements obligate us to indemnify against claims that our products and subscriptions infringe the intellectual property rights of third parties. In addition, to the extent we hire personnel from competitors, we may be subject to allegations that they have been improperly solicited, that they have divulged proprietary or other confidential information, or that their former employers own their inventions or other work product. Furthermore, we may be unaware of the intellectual property rights of others that may cover some or all of our technology, products, subscriptions, and services. As we expand our footprint, both in our platforms, products, subscriptions, and services and geographically, more overlaps occur and we may face more infringement claims both in the United States and abroad.
Our competitors and others may have significantly larger and more mature patent portfolios than we have, and litigation has involved and will likely continue to involve patent-holding companies or owners who have no relevant product revenue and against whom our own patents provide little or no deterrence. We have not registered our trademarks in all geographic markets, which could adversely affect our ability to enforce and defend our trademark rights. Any infringement claim, even without merit, could cause us to incur substantial defense costs, distract management, and could require us to cease use of such intellectual property. Furthermore, because of the substantial discovery required in IP litigation, there is a risk that our confidential information could be compromised. A successful claimant could secure a judgment or settlement that prevents us from distributing certain products, performing certain services, or that requires us to pay substantial damages, royalties, or other fees. Any of these events could seriously harm our business, financial condition, and operating results.
Our proprietary rights may be difficult to enforce or protect, which could enable others to copy or use aspects of our products or subscriptions without compensating us.
We rely and expect to continue to rely on a combination of confidentiality and license agreements with our employees, consultants, and third parties with whom we have relationships, as well as trademark, copyright, patent, and trade secret protection laws, to protect our proprietary rights. We have filed various applications for certain aspects of our intellectual property. Valid patents may not issue from our pending applications, and the claims eventually allowed on any patents may not be sufficiently broad to comprehensively protect our technology or products and subscriptions. We cannot be certain that we were the first to make the inventions claimed in our pending patent applications or that we were the first to file for patent protection, which could prevent our patent applications from issuing as patents or invalidate our patents following issuance. Additionally, the process of obtaining patent protection is expensive and time-consuming, and we may not be able to prosecute all necessary or desirable patent applications at a reasonable cost or in a timely manner. Any issued patents may be challenged, invalidated or circumvented, and any rights granted under these patents may not actually provide adequate defensive protection or competitive advantages to us. Additional uncertainty may result from changes to patent-related laws and court rulings in the United States and other jurisdictions. As a result, we may not be able to obtain adequate patent protection or effectively enforce any issued patents.
Unauthorized parties may attempt to copy aspects of our products or subscriptions or obtain and use information that we regard as proprietary. We enter into confidentiality or license agreements with employees, consultants, vendors, and end-customers and limit access to our proprietary information; however, these agreements may not be honored or our measures may not prevent misappropriation. As a well-known security provider, we may face a greater risk of unauthorized access to our proprietary information. In addition, the laws of some foreign countries do not protect proprietary rights to the same extent as U.S. laws. We may need to take legal action to enforce our intellectual property rights, which could result in substantial costs and diversion of resources, and could provoke counterclaims. If we are unable to protect our proprietary rights, we may find ourselves at a competitive disadvantage, which would have a material adverse effect on our business, financial condition, and operating results.
- 28 -
Our use of open source software in our products and subscriptions could negatively affect our ability to sell our products and subscriptions and subject us to possible litigation.
Our products and subscriptions contain software modules licensed to us by third-party authors under “open source” licenses. Some open source licenses contain requirements that we make available applicable source code for modifications or derivative works we create based upon the type of open source software we use. If we combine our proprietary software with, or otherwise distribute or use open source software in a certain manner, we could, under certain open source licenses, be required to release the source code of our proprietary software to the public. This would allow our competitors to create similar products or subscriptions with lower development effort and time and ultimately could result in a loss of product sales for us.
The terms of many open source licenses have not been interpreted by United States courts, and these licenses could be construed in a way that imposes unanticipated conditions or restrictions on our ability to commercialize our products and subscriptions. From time to time, there have been claims against companies that distribute or use open source software in their products and subscriptions, asserting that open source software infringes the claimants’ intellectual property rights. We could be subject to suits by parties claiming infringement of intellectual property rights in what we believe to be licensed open source software. If we are held to have breached the terms of an open source software license, we could be required to seek licenses from third parties to continue offering our products and subscriptions on terms that are not economically feasible, to reengineer our products and subscriptions, to discontinue the sale of our products and subscriptions if reengineering could not be accomplished on a timely basis, or to make generally available, in source code form, our proprietary code, any of which could adversely affect our business, financial condition, and operating results.
In addition, usage of open source software can lead to greater risks than use of third-party commercial software, as open source licensors generally do not provide warranties or assurance of title. Our processes to help alleviate these risks, including a review process for screening open source usage requests, may not be effective.
We license technology from third parties, and our inability to maintain those licenses could harm our business.
We incorporate technology that we license from third parties, including software, into our products and subscriptions. We cannot be certain that our licensors are not infringing the intellectual property rights of third parties or that our licensors have sufficient rights to the licensed intellectual property in all jurisdictions in which we may sell our products and subscriptions. In addition, some licenses may be non-exclusive, and therefore our competitors may have access to the same technology licensed to us. Some of our agreements with our licensors may be terminated for convenience by them. We may also be subject to additional fees or be required to obtain new licenses if any of our licensors allege that we have not properly paid for such licenses or that we have improperly used the technologies under such licenses, and such licenses may not be available on terms acceptable to us or at all. If we are unable to continue to license any of this technology because of intellectual property infringement claims brought by third parties against our licensors or against us, or claims against us by our licensors, or if we are unable to continue our license agreements or enter into new licenses on commercially reasonable terms, our ability to develop and sell products and subscriptions containing such technology would be severely limited and our business could be harmed. Additionally, if we are unable to license necessary technology from third parties, we may be forced to acquire or develop alternative technology, which we may be unable to do in a commercially feasible manner or at all, and we may be required to use alternative technology of lower quality or performance standards. This would limit and delay our ability to offer new or competitive products and subscriptions and increase our costs of production. As a result, our margins, market share, and operating results could be significantly harmed.
RISKS RELATED TO OPERATIONS
We depend on manufacturing partners and limited sources of supply for our hardware products, making us susceptible to manufacturing delays, supply shortages, pricing fluctuations, and international trade risks that could prevent timely shipment of customer orders and result in the loss of sales and end-customers.
We depend on manufacturing partners, primarily our EMS provider, Flex, to manufacture our hardware product lines. Our substantial reliance on Flex or other manufacturing partners subjects us to concentration risks, such as reduced control over the manufacturing process, quality assurance, product costs and supply, and timing. Our hardware products are manufactured primarily in the United States, but some components are sourced outside the United States, subjecting us to geopolitical risks, trade regulations, tariffs, logistical risks, and foreign compliance requirements.
Changes to international trade agreements, tariffs, or trade regulations could lead to sourcing or logistics disruptions and increased costs. For example, U.S. and Chinese import tariffs have impacted some of our components, increasing our costs and potentially requiring us to further raise prices on our hardware products.
In the past, we experienced supply chain disruption and have incurred increased costs resulting from inflationary pressures and changes in U.S. trade policy. For example, we experienced supply chain disruption and inflationary pressures during our fourth quarter of fiscal 2026, resulting in increased costs for memory and other components, which have negatively affected our gross margin and could continue to affect our gross margin. Our manufacturing partners typically fulfill supply requirements on individual purchase orders without long-term capacity or pricing guarantees. Our contract with Flex permits termination for convenience, subject to prior notice requirements. Our manufacturing partners procure components and build products based on our forecasts, and from time to time, we
- 29 -
issue non-cancelable, non-returnable forecasts. If we are required to change manufacturing partners, or if our forecasting and inventory management systems prove inadequate, our ability to meet scheduled deliveries could be adversely affected. If our forecasts overestimate demand, we may be obligated to purchase excess inventory that we cannot sell, resulting in write-downs, increased carrying costs, and lower gross margins. Conversely, if our forecasts underestimate demand, we may experience insufficient supply, leading to product shortages, delayed deliveries, lost sales opportunities, and potential damage to customer relationships. Any production interruptions, whether from natural disasters, epidemics or pandemics, capacity shortages, or quality problems, would negatively affect sales and our business and operating results.
Our hardware products rely on key components, including integrated circuit components, purchased from a limited number of suppliers, including sole source providers. The manufacturing operations of some suppliers are geographically concentrated in Asia, making our supply chain vulnerable to regional disruptions and international regulations, including tariffs, sanctions, and export controls. We are also monitoring the tensions between China and Taiwan, and between the U.S. and China, which have increased our costs and could have an adverse impact on our business or results of operations in future periods. We do not have volume purchase contracts with our component suppliers, and they could cease selling to us or change prices at any time. For example, there is currently a global shortage of memory-related components, and certain of our hardware appliances require higher memory content, which has led to and may continue to lead to increased production costs. If we are unable to obtain sufficient components on commercially reasonable terms, we could be forced to redesign our products and qualify new suppliers, resulting in lost sales opportunities and damage to customer relationships.
If we are unable to attract, retain, and motivate our key technical, sales, and management personnel, our business could suffer.
Our future success depends, in part, on our ability to continue to attract, retain, and motivate the members of our management team and other key employees. For example, we are substantially dependent on the continued service of our engineering personnel because of the complexity of our offerings. Competition for highly skilled personnel, particularly in engineering, including in the areas of AI and machine learning, is intense, especially in the San Francisco Bay Area, where we have a substantial presence and need for such personnel. In addition, the industry in which we operate generally experiences high employee attrition. Our future performance depends on the continuing services and contributions of our senior management to execute on our business plan and to identify and pursue new opportunities and product innovations. If we are unable to hire, integrate, train, or retain the qualified and highly skilled personnel required to fulfill our current or future needs, our business, financial condition, and operating results could be harmed. Moreover, our hybrid work environment may also create operational, security, and workplace culture challenges that could hinder execution of our business objectives and our ability to attract and retain qualified and highly skilled personnel.
Further, we believe that a critical contributor to our success and our ability to retain highly skilled personnel has been our corporate culture, which we believe fosters innovation, inclusion, teamwork, passion for end-customers, focus on execution, and the facilitation of critical knowledge transfer and knowledge sharing. As we grow and change, and as we acquire and integrate other businesses, we may find it difficult to maintain these important aspects of our corporate culture. While we are taking steps to develop a more inclusive workforce, there is no guarantee that we will be able to do so. Any failure to preserve our culture as we grow could limit our ability to innovate and could negatively affect our ability to retain and recruit personnel, continue to perform at current levels, or execute on our business strategy.
We generate a significant amount of revenue from sales to distributors, resellers, and end-customers outside of the United States, and we are therefore subject to a number of risks associated with international sales and operations, including export and import controls that could subject us to liability or impair our ability to compete in international markets.
Our ability to successfully grow our business will depend to a significant extent on our ability to expand our operations and customer base worldwide. Operating in a global marketplace, we are subject to risks associated with international reach, compliance, and regulatory requirements. We may experience difficulties in attracting and retaining international personnel or strategic distributor relationships, and business practices in international markets may require non-standard end-customer contract terms related to payment, warranties, or performance obligations.
Additionally, our international sales and operations are subject to a number of risks, including the following:
- political, economic, and social uncertainty around the world, health risks such as epidemics and pandemics, macroeconomic challenges, terrorist activities, the Russia-Ukraine war, tensions between China and Taiwan, the hostilities in Israel and the surrounding region, and continued hostilities in the Middle East;
- unexpected changes in, or the application of, foreign and domestic laws and regulations (including intellectual property rights protections), regulatory practices or enforcement policies, trade restrictions, international trade agreements, and foreign legal requirements, including those applicable to the importation, certification, localization and regulatory approval of our products, tariffs, and tax laws and treaties, including regulatory and trade policy changes adopted by the current administration, such as sanctions, or foreign countries’ response to regulatory changes adopted by the current administration; and
- 30 -
- non-compliance with U.S. and foreign laws, including antitrust regulations, anti-corruption laws, such as the U.S. Foreign Corrupt Practices Act and the United Kingdom (“U.K.”) Bribery Act, U.S. or foreign sanctions regimes and export or import control laws, and any trade regulations ensuring fair trade practices.
These and other factors could harm our future international revenues and, consequently, materially impact our business, financial condition, and operating results. In addition, because we incorporate encryption technology into our products, certain of our products are subject to U.S. export controls and may be exported outside the United States only with the required export license or license exception. U.S. export control laws and economic sanctions prohibit shipment of certain products to embargoed or sanctioned countries, governments, and persons. Various countries also regulate the import of encryption technology. Changes in export or import regulations, economic sanctions, or the countries and technologies targeted by such regulations could decrease use of our products internationally. Any failure by us or our channel partners to comply with trade regulations could subject us to substantial civil and criminal penalties. International trade laws continuously evolve, and monitoring and responding to these developments may require significant resources. Our failure to successfully manage our international operations and the associated risks could limit the future growth of our business.
Our products and subscriptions are subject to certification, testing, and regulatory approval requirements in foreign jurisdictions, and our failure to obtain or maintain such approvals could limit our ability to sell in those markets.
Our products and subscriptions are subject to regulatory requirements in a number of foreign jurisdictions, and the scope and complexity of these requirements continue to expand. For example, in China, our products may be required to comply with cybersecurity and data security laws, including the Cybersecurity Law, the Data Security Law, and related regulations, and may be subject to network security review, critical information infrastructure protection requirements, and mandatory product certifications. Other jurisdictions impose similar requirements, including local testing and certification requirements, in-country data storage or processing mandates, source code review or escrow obligations, and restrictions on the use of foreign-developed encryption or security technologies. Compliance with these requirements is costly and time-consuming, and the regulatory landscape in many jurisdictions is evolving and subject to change with limited or no notice. If we are unable to obtain or maintain required certifications, approvals, or authorizations in a timely manner, or if new or revised requirements render our products or subscriptions non-compliant, we may be unable to sell, deploy, or support our products in affected markets, which could result in lost revenue opportunities, reputational harm, and a material adverse effect on our business, financial condition, and operating results.
We are exposed to fluctuations in foreign currency exchange rates, which could negatively affect our financial condition and operating results.
Our sales contracts are primarily denominated in U.S. dollars, and therefore, a predominant amount of our revenue is not subject to foreign currency risk. However, a strengthening of the U.S. dollar could increase the cost of our products to end-customers outside the United States. Increased international sales in the future may result in greater foreign currency denominated sales, increasing our foreign currency risk.
Our operating expenses incurred outside the United States and denominated in foreign currencies are generally increasing and are subject to fluctuations due to changes in exchange rates. We have entered into forward contracts to reduce our foreign currency exchange exposure. As of July 31, 2026, the total notional amount of our outstanding foreign currency forward contracts was $2.2 billion. For more information, refer to Note 6. Derivative Instruments in Part II, Item 8 of this Annual Report on Form 10-K. The effectiveness of our hedging transactions may be limited, and we may not be able to successfully hedge our exposure, which could adversely affect our financial condition and operating results.
We face risks associated with having operations and employees located in Israel.
We have business operations in Israel, which meaningfully expanded as a result of the acquisition of CyberArk, and we intend to continue growing our presence in Israel. Our operations in Israel could be disrupted by political instability, civil unrest, terrorist attacks, acts of violence or war, or other military actions, including ongoing hostilities in the region. The effects of such hostilities on the Israeli economy and our operations in Israel are unclear, and current or future tensions and conflicts in the Middle East, including any escalation involving Iran, could adversely affect our business, financial condition, operating results, and cash flows.
Many of our employees in Israel are obligated to perform annual reserve duty in the Israeli military and are subject to being called for active duty under emergency circumstances, which has occurred as a result of regional hostilities. If many of our employees in Israel are called for active duty for a significant period of time, our operations could be disrupted and may not function at full capacity, which could adversely affect our business.
- 31 -
RISKS RELATED TO PRIVACY AND DATA PROTECTION
We may incur significant costs to comply with privacy and data protection laws and other requirements, and, if we fail to comply, we could be subject to government enforcement actions, private litigation, and adverse publicity, which could materially adversely affect our business, financial condition, and operating results.
A wide variety of laws, regulations, industry standards, contractual requirements, and other obligations apply to the collection, use, retention, protection, disclosure, transfer, and other processing of personal data in jurisdictions where we and our customers operate. Compliance with these laws and other obligations is difficult and costly, and they are subject to frequent and unexpected changes. For example, we are subject to the E.U. General Data Protection Regulation (“E.U. GDPR”) and the U.K. General Data Protection Regulation (“U.K. GDPR,” and collectively the “GDPR”), each of which imposes stringent data protection requirements and provides for costly penalties for noncompliance (up to the greater of (a) €20 million under the E.U. GDPR or £17.5 million under the U.K. GDPR, and (b) 4% of annual worldwide turnover), and confers the right upon data subjects and consumer associations to lodge complaints with supervisory authorities, seek judicial remedies, and obtain compensation for damages resulting from violations.
The GDPR restricts transfers of personal data outside of the European Economic Area (“EEA”) (or, in the case of the U.K. GDPR, the U.K.) to non-EEA countries, such as the United States, unless adequate safeguards are implemented or a derogation applies. We rely on standard contractual clauses approved under the GDPR to carry out such transfers and to receive personal data subject to the GDPR (directly or indirectly) in the United States. In addition, with respect to the personal data that we process on behalf of our customers, we self-certified to the E.U.-U.S. Data Privacy Framework (“E.U.-U.S. DPF”), the UK Extension to the E.U.-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (collectively, the "DPF") as set forth by the U.S. Department of Commerce for such transfers. However, the DPF may be subject to legal challenges that could invalidate its use. In addition, the U.K. Data (Use and Access) Act 2025 includes changes to the U.K.'s data protection regime that deviate from the GDPR, creating new compliance challenges. We anticipate future legal challenges and developments to approved data transfer mechanisms, including to the E.U.-U.S. DPF, which could result in additional compliance costs and harm our business. Among other effects of these developments, we may also experience reduced demand for our products and subscriptions from current or prospective customers in the EEA, Switzerland, and the U.K. (collectively, “Europe”) on account of the risks identified in the Schrems II decision or other developments relating to cross-border data transfers, and we may find it necessary or desirable to make further changes to our processing of personal data of European residents. The regulatory environment applicable to the handling of European residents’ personal data and cross-border data transfers, and our actions taken in response, may cause us to assume additional liabilities or incur additional costs.
We are also subject to U.S. privacy and data protection laws, including the California Consumer Privacy Act (the "CCPA"), which, among other requirements, requires enhanced disclosures, affords California residents with certain rights regarding their personal data, and creates a private right of action for data breaches caused by a lack of reasonable security. Over twenty other U.S. states have enacted similar privacy laws. Additionally, the U.S. Department of Justice has issued rules regarding access to or transfer of certain bulk sensitive personal data by countries of concern or covered persons, and we are subject to the Health Insurance Portability and Accountability Act ("HIPAA"), both of which carry significant enforcement penalties for non-compliance. These and other increasingly complex federal and state privacy laws and their enforcement may also require us to modify our data practices and incur additional substantial compliance costs.
We are also subject to obligations relating to personal data and data protection by contract and self-regulatory and industry standards. Additionally, the Federal Trade Commission and state attorneys general are more regularly bringing enforcement actions for deceptive practices related to the collection and security of personal data.
We and our customers could face risk of regulatory investigations, enforcement actions, private litigation (including class action litigation), and adverse publicity, including reputational damage and loss of customer confidence, for actual or perceived violations of any of the foregoing data protection obligations. Any such claims could result in substantial costs, remedial and reporting obligations, distraction of management, and diversion of resources. Our insurance may not cover all types of claims that may arise, and we cannot guarantee that applicable insurance will be available to us in the future on economically reasonable terms or at all. If any of the foregoing were to occur, our business, results of operations, and financial condition could be materially adversely affected.
Moreover, new legislation affecting the scope of personal data and information, especially relating to IP addresses, machine identification, AI and machine learning, location data, health information, and other information, may limit or inhibit our ability to operate or expand our business and may require significant additional expenditures to comply. Data localization laws may mandate that personal data collected in a foreign country be processed and stored within that country, potentially requiring costly restructuring of our cloud infrastructure. Public perception of privacy or information security concerns, whether or not valid, may harm our reputation and inhibit adoption of our products and subscriptions. Additionally, existing laws and regulations, and any changes to them, or new laws and regulations, could impose significant limitations or require changes to our business model, which may increase our compliance costs.
We are also subject to federal, state, provincial, and foreign laws regarding cybersecurity and the protection of our systems and confidential information. Many jurisdictions have enacted laws, such as the GDPR and the E.U. Network and Information Systems Directive II, requiring companies to adopt cybersecurity risk management measures and notify regulators (and individuals) of data breaches or cybersecurity incidents. If our data security measures fail to adequately protect our systems or confidential information, we could be liable to both our customers and their users for
- 32 -
any related losses. Additionally, we could face regulatory action or face litigation, and our customers could terminate or materially change their relationships with us, any of which could harm our business, financial condition, or operating results.
Tax, Accounting, Compliance, and Regulatory Risks
We may have exposure to tax liabilities that are greater than anticipated.
Our income tax obligations are based in part on our corporate structure and intercompany arrangements, including the manner in which we develop, value, and use our intellectual property and the valuations of our intercompany transactions. The tax laws applicable to our business, including the laws of the United States and various other jurisdictions, are subject to interpretation and certain jurisdictions may aggressively interpret their laws, regulations, and policies, including in an effort to raise additional tax revenue. The tax authorities of the jurisdictions in which we operate may challenge our methodologies for valuing developed or acquired technology or determining the proper charges for intercompany arrangements, which could increase our worldwide effective tax rate, harm our financial position and operating results, and have a negative effect on our cash flow. Some tax authorities of jurisdictions other than the United States may seek to assert extraterritorial taxing rights on our transactions or operations. It is possible that domestic or international tax authorities may subject us to tax examinations or audits, and such tax authorities may disagree with certain positions we have taken, and any adverse outcome of such an examination, review, or audit could result in additional tax liabilities and penalties and otherwise have a negative effect on our financial condition, operating results, and cash flow. Further, the determination of our worldwide provision for income taxes and other tax liabilities requires significant judgment by management, and there are transactions where the ultimate tax determination is uncertain. Although we believe that our estimates are reasonable, the ultimate tax outcome may differ from the amounts recorded on our consolidated financial statements and may materially affect our financial results in the period or periods for which such determination is made.
In addition, our future income tax obligations and effective tax rates could be adversely affected by changes in, or interpretations of, tax laws, regulations, policies, or decisions in the United States or in the other jurisdictions in which we operate including as a result of the U.S. federal tax legislation commonly referred to as the One Big Beautiful Bill Act, which was signed into law on July 4, 2025. In addition, our effective tax rates could be affected by fluctuations in the market price of our common stock and changes in the fair value of CyberArk’s $1.25 billion aggregate principal amount of 0.00% Convertible Senior Notes due 2030 (the “2030 Notes”) and the fair value of the capped call transactions (the “Capped Calls”) we acquired in connection with the CyberArk acquisition. If our future tax obligations or effective tax rates increase as a result of these or other factors, it could have an adverse effect on our financial condition and operating results.
Moreover, in October 2021, the Organization for Economic Co-operation and Development (“OECD”) issued model rules for a new global minimum tax framework, commonly referred to as “Pillar Two,” which included the introduction of a 15% global minimum tax effective beginning January 1, 2024. To date, approximately 140 countries have tentatively signed a framework agreeing in principle to this initiative. A number of countries in which we do business have implemented or may implement Pillar Two proposals into local tax legislation. On January 5, 2026, the OECD released a “side-by-side” package (the “SbS Package”) that generally establishes an exemption for U.S. multinationals from the 15% global minimum tax. However, the implementation of the SbS Package depends on domestic legislation and regulation in OECD member countries and is subject to subsequent review. Details around the proposals are still uncertain as the OECD and local jurisdictions continue to issue the technical guidance. Our effective tax rate and cash tax payments could increase in future years as a result of these changes.
Our estimates or judgments, including those relating to our critical accounting policies, are based on assumptions that may change or prove to be incorrect and, as a result, our operating results may differ from our publicly announced guidance or the expectations of securities analysts and investors, which may result in a decline in the market price of our common stock.
The preparation of consolidated financial statements in conformity with U.S. generally accepted accounting principles (“U.S. GAAP”) requires management to make estimates and assumptions that affect the amounts reported on our consolidated financial statements and accompanying notes. We base our estimates on historical experience and on various other assumptions that we believe to be reasonable under the circumstances, the results of which form the basis for making judgments about the carrying amounts of assets, liabilities, equity, revenue, and expenses that are not readily apparent from other sources. For more information relating to critical accounting policies, refer to the section entitled “Critical Accounting Estimates” in “Management’s Discussion and Analysis of Financial Condition and Results of Operations” in Part II, Item 7 of this Annual Report on Form 10-K. In general, if our estimates, judgments, or assumptions relating to our critical accounting policies change or if actual circumstances differ from our estimates, judgments, or assumptions, our operating results may be adversely affected and could fall below our publicly announced guidance or the expectations of securities analysts and investors, which may result in a decline in the market price of our common stock.
- 33 -
We are obligated to maintain proper and effective internal control over financial reporting. We may not complete our analysis of our internal control over financial reporting in a timely manner, or our internal control may not be determined to be effective, which may adversely affect investor confidence in our company and, as a result, the value of our common stock.
If we are unable to assert that our internal controls are effective, our independent registered public accounting firm may not be able to formally attest to the effectiveness of our internal control over financial reporting. If, in the future, our chief executive officer, chief financial officer, or independent registered public accounting firm determines that our internal control over financial reporting is not effective as defined under Section 404, we could be subject to one or more investigations or enforcement actions by state or federal regulatory agencies, stockholder lawsuits, or other adverse actions requiring us to incur defense costs and pay fines, settlements, or judgments, causing investor perceptions to be adversely affected and potentially resulting in a decline in the market price of our common stock.
Our reputation and business could be negatively impacted by corporate responsibility matters, including our reporting of such matters.
Governmental authorities, certain investors, and other stakeholders continue to focus on, set and revise, expectations relating to corporate responsibility matters, both in the United States and internationally. Such expectations are evolving and may be contradictory. We communicate corporate responsibility initiatives, goals, and commitments regarding sustainability, inclusion, responsible sourcing, and community impact in our annual Corporate Responsibility Report, on our website, in our SEC filings, and elsewhere. These initiatives may be difficult to achieve and costly to implement. We could be criticized for their scope, nature, timing, or any revisions to them, and for the accuracy or completeness of our disclosures. Our actual or perceived failure to undertake these initiatives and achieve these goals, or the fact that we are undertaking these initiatives, could negatively impact our reputation or otherwise materially harm our business.
In addition, we are or may become subject to various new, proposed, and evolving sustainability-related laws and regulations, including, for example, the E.U.’s Corporate Sustainability Reporting Directive. Additional regulation may require us to incur significant costs associated with increased compliance burdens, including the implementation of additional internal controls processes and procedures, and impose increased oversight obligations on our management and board of directors, as well as require us to retain third-party experts. Noncompliance with applicable regulations or requirements could subject us to investigations, sanctions, enforcement actions, fines, or litigation, which could negatively impact our business, financial condition, and operating results.
Failure to comply with governmental laws and regulations could harm our business.
Our business is subject to regulation by various federal, state, local, and foreign governmental agencies, including agencies responsible for employment and labor laws, workplace safety, product safety, environmental laws, consumer protection laws, privacy, data security, and data protection laws, anti-bribery laws (including the U.S. Foreign Corrupt Practices Act and the U.K. Anti-Bribery Act), import/export controls, securities laws, and tax laws and regulations. These laws and regulations may also impact our ability to develop new technologies, including emerging technologies such as AI. In certain jurisdictions, regulatory requirements may be more stringent than in the United States. Noncompliance could subject us to investigations, sanctions, mandatory product recalls, enforcement actions, disgorgement of profits, fines, damages, civil and criminal penalties, litigation, or injunctions. Responding to any action will likely result in significant diversion of management’s attention and resources. If any governmental sanctions are imposed, our business, financial condition, and operating results could be materially adversely affected.
Risks Related to Our Common Stock and Convertible Notes
The market price of our common stock historically has been volatile, and the value of an investment in our common stock could decline.
The market price of our common stock has historically been, and is likely to continue to be, volatile and could be subject to wide fluctuations in response to various factors, some of which are beyond our control and unrelated to our business, financial condition, or operating results. These fluctuations could cause a loss of all or part of an investment in our common stock. Factors that could cause fluctuations in the market price of our common stock include, but are not limited to:
- announcements by us or our competitors of new products, subscriptions, technologies, commercial relationships, strategic partnerships, acquisitions, or similar events;
- broader price and volume fluctuations in the stock market, and in particular the trading prices and volumes of technology companies and companies in our industry;
- fluctuations in the trading volume of our shares or the size of our public float, including sales or repurchases of large blocks of our common stock and future sales by our directors, executive officers, employees, or significant stockholders;
- issuances or sales of our common stock, or of debt or securities convertible into or exchangeable for our common stock, including in capital-raising transactions or as consideration in connection with acquisitions;
- 34 -
- actual or anticipated changes or fluctuations in our operating results, and whether our operating and/or financial results meet the expectations of securities analysts or investors;
- actual or anticipated changes in analyst or investor expectations, including as a result of our forward-looking statements or our failure to meet such expectations;
- inaccurate or unfavorable research reports about our business and industry, or reduced analyst coverage of our company;
- news or events affecting investor perception of our industry, including reports of significant cyberattacks;
- litigation involving us or our industry, and actions instituted by activist shareholders or others;
- regulatory developments in the United States or other jurisdictions;
- major catastrophic events and geopolitical or economic uncertainty around the world; or
- departures of key personnel.
Securities class action litigation has often been brought against companies that experience periods of volatility in the market price of such company’s securities. Securities litigation could result in substantial costs, divert our management’s attention and resources from our business, and have a material adverse effect on our business, financial condition, and operating results. Our insurance may not cover all types of claims that may arise, and we cannot guarantee that applicable insurance will be available to us in the future on economically reasonable terms or at all.
The issuance of additional common stock in connection with financings, acquisitions, investments, our stock incentive plans, convertible notes, or otherwise will dilute the stock held by all other stockholders.
Our restated certificate of incorporation authorizes us to issue up to 2.0 billion shares of common stock and up to 100 million shares of preferred stock with such rights and preferences as may be determined by our board of directors. Subject to compliance with applicable rules and regulations, we may issue shares of common stock or securities convertible into or exchangeable for shares of our common stock from time to time in connection with a financing or other capital raising transaction, acquisitions, investments, our stock incentive plans, the settlement of our 2030 Notes, or otherwise. Any such issuance could result in substantial dilution to our existing stockholders and cause the market price of our common stock to decline.
We cannot guarantee that our share repurchase program will be fully consummated or that it will enhance shareholder value, and share repurchases could affect the price of our common stock.
As of July 31, 2026, we had $1.0 billion available under our share repurchase program which will expire on December 31, 2026 and may be suspended or discontinued at any time without prior notice. Although our board of directors authorized the program, we are not obligated to repurchase any specific dollar amount or number of shares under the program. The share repurchase program could affect the price of our common stock, increase volatility, and diminish our cash reserves.
We do not intend to pay dividends for the foreseeable future.
We have never declared or paid any dividends on our common stock. We intend to retain any earnings to finance the operation and expansion of our business, and we do not anticipate paying any cash dividends in the future. As a result, stockholders may only receive a return on their investments in our common stock if the market price of our common stock increases.
Our charter documents and Delaware law could discourage takeover attempts and lead to management entrenchment, which could also reduce the market price of our common stock.
Provisions in our restated certificate of incorporation and amended and restated bylaws may have the effect of delaying or preventing a change in control of our company or changes in our management. Our restated certificate of incorporation and amended and restated bylaws include provisions that, among other things:
- establish that our board of directors is divided into three classes, Class I, Class II, and Class III, with three-year staggered terms;
- authorize our board of directors to issue shares of preferred stock and to determine the price and other terms of those shares, including preferences and voting rights, without stockholder approval;
- provide our board of directors with the exclusive right to elect a director to fill a vacancy created by the expansion of our board of directors or the resignation, death, or removal of a director;
- prohibit our stockholders from taking action by written consent;
- specify that special meetings of our stockholders may be called only by the chairman of our board of directors, our president, our secretary, or a majority vote of our board of directors;
- require the affirmative vote of holders of at least 66 2/3% of the voting power of all of the then outstanding shares of the voting stock, voting together as a single class, to amend the provisions of our restated certificate of incorporation relating to the issuance of preferred stock and management of our business or our amended and restated bylaws;
- 35 -
- authorize our board of directors to amend our bylaws by majority vote; and
- establish advance notice procedures with which our stockholders must comply to nominate candidates to our board of directors or to propose matters to be acted upon at a stockholders’ meeting.
These provisions may frustrate or prevent any attempts by our stockholders to replace or remove our current management by making it more difficult for our stockholders to replace members of our board of directors, which is responsible for appointing the members of management. In addition, as a Delaware corporation, we are subject to Section 203 of the Delaware General Corporation Law. These provisions may prohibit large stockholders, in particular those owning 15% or more of our outstanding voting stock, from merging or combining with us for a certain period of time. Any of these provisions could, under certain circumstances, depress the market price of our common stock.
We may not have the ability to raise the funds necessary to settle conversions of the 2030 Notes, repurchase the 2030 Notes upon a fundamental change, or repay the 2030 Notes in cash at their maturity, and our other debt may contain limitations on our ability to pay cash upon conversion or repurchase of the 2030 Notes.
In connection with the consummation of the CyberArk acquisition, we entered into a supplemental indenture (the “Supplemental Indenture”) to the Indenture, dated as of June 10, 2025 (as supplemented by the Supplemental Indenture, the “Indenture”), governing the 2030 Notes, and in the Supplemental Indenture we agreed to guarantee the 2030 Notes.
Accordingly, we will need to make cash payments (a) if holders of the 2030 Notes require us to repurchase all, or a portion of, the 2030 Notes upon the occurrence of a fundamental change before the maturity date, (b) upon conversion of the 2030 Notes, or (c) to repay the 2030 Notes in cash at their maturity, unless earlier converted or repurchased.
If our cash provided by operating activities, together with our existing cash, cash equivalents, and investments, and existing sources of financing, are inadequate to satisfy these obligations, we will need to obtain third-party financing, which may not be available to us on commercially reasonable terms or at all, to meet these payment obligations.
In addition, our ability to repurchase or to pay cash upon conversion of the 2030 Notes may be limited by law, regulatory authority, or agreements governing our other indebtedness. Our failure to repurchase the 2030 Notes at a time when the repurchase is required by the Indenture, or to pay any cash amount due upon their maturity or conversion when required by the Indenture would constitute a default under the Indenture. A default under the Indenture could also lead to a default under agreements governing our other indebtedness. If the payment of the related indebtedness were to be accelerated after any applicable notice or grace periods, we may not have sufficient funds to satisfy all amounts due under our other indebtedness and the 2030 Notes.
The Capped Calls may affect the value of the 2030 Notes and our common stock.
In connection with the issuance of the 2030 Notes, CyberArk had previously entered into the Capped Calls, each with a financial institution (each, together with its affiliates, a “Dealer”). In connection with the CyberArk acquisition, we entered into substantially identical amended and restated letter agreements with respect to the Capped Calls, under which the Capped Calls were assigned to us and now reference our common stock. The Capped Calls are generally expected to reduce the potential dilution to our common stock upon conversion of the 2030 Notes and/or offset any potential cash payments we are required to make in excess of the principal amount of converted 2030 Notes, with such reduction and/or offset subject to a cap.
Any Dealer may modify or unwind its hedge positions by entering into or unwinding various derivatives with respect to our common stock and/or purchasing or selling our common stock or other securities of ours in secondary market transactions prior to the maturity of the 2030 Notes (and is likely to do so following any conversion of the 2030 Notes, any repurchase of the 2030 Notes by us on any fundamental change repurchase date, any redemption date, or any other date on which the 2030 Notes are retired by us, in each case, if we exercise the relevant election under the Capped Calls and in connection with any negotiated unwind or modification of the Capped Calls). This activity could cause or prevent an increase or a decrease in the market price of our common stock or the 2030 Notes, which could affect a note holder’s ability to convert its 2030 Notes and, to the extent the activity occurs during any observation period related to a conversion of the 2030 Notes, it could affect the amount and value of the consideration that the note holder would receive upon conversion of the 2030 Notes.
We do not make any representation or prediction as to the direction or magnitude of any potential effect that the transactions described above may have on the price of the 2030 Notes or our common stock. In addition, we do not make any representation that any Dealer has engaged with or will engage in these transactions or that these transactions, if commenced, have not been or will not be discontinued without notice.
- 36 -
General Risk Factors
Our business is subject to the risks of earthquakes, fire, power outages, floods, health risks, climate change, and other catastrophic events, and to interruption by man-made problems, such as terrorism.
Our corporate headquarters are located in the San Francisco Bay Area, a region known for seismic activity. In addition, climate-related events, including drought, flooding, heat waves, wildfires, increased storm severity, and sea level rise, may increase in frequency and intensity and could disrupt our business operations and damage our facilities. In addition, the data centers and cloud infrastructure we and our third-party providers use to deliver our products, subscriptions, and support offerings are subject to risks from extreme weather events and power disruptions associated with climate change. Other natural disasters, a significant power outage, telecommunications failure, terrorism, an armed conflict, cyberattacks, epidemics and pandemics, or other geopolitical unrest could affect our supply chain, manufacturers, logistics providers, channel partners, end-customers, or the economy as a whole, and such disruption could impact our shipments and sales. We may be subject to increased regulations, reporting requirements, standards, or stakeholder expectations regarding climate change that may impact our business, increase compliance costs, and require additional investment in our operations and disclosures. These risks may be further increased if the disaster recovery plans for us and our suppliers prove to be inadequate. To the extent that any of the above should result in delays or cancellations of customer orders, the loss of customers, or the delay in the manufacture, deployment, or shipment of our products, our business, financial condition, and operating results would be adversely affected.
Item 1B. Unresolved Staff Comments
Not applicable.
Item 1C. Cybersecurity
As a global cybersecurity provider, cybersecurity risk management is an integral part of our overall enterprise risk management program. We recognize the critical importance that a strong cybersecurity risk management program plays in maintaining the trust and confidence of our customers, end users, business partners, stockholders and employees. We have established processes and procedures for identifying, evaluating, and responding to risks from cybersecurity threats, including any potential unauthorized access to our information systems that may result in adverse effects on the confidentiality, integrity, or availability of our information systems or information.
Cybersecurity Risk Management and Strategy
Our cybersecurity risk management program includes written policies, standards, and procedures for maintaining data privacy, product security and information security to mitigate cybersecurity risks, and to identify, evaluate and respond to cybersecurity threats, vulnerabilities and incidents. Our cybersecurity risk management program and strategy is implemented across several areas, which include, but are not limited to, the following:
- Information Security. We maintain a written information security program, which provides for policies, standards, guidelines, and administrative, technical and physical safeguards that we believe are reasonably designed, in light of the nature, size and complexity of our operations, to protect the resiliency of our operations and the confidentiality, integrity, and availability of our information systems and information. The organizational, administrative and technical measures we implement are guided by recognized security frameworks established by the National Institute of Standards and Technology, the ISO/IEC 27000 series of standards, and other generally recognized industry standards. The program is assessed regularly and in light of new and emerging cybersecurity risks.
- Technical Safeguards and Product Security. We deploy and maintain a variety of technologies to detect and manage cybersecurity threats across the network, endpoint and cloud, as well as leverage Unit 42 to assess our internal security posture. We also apply security-by-design principles in our software development lifecycle, track vulnerabilities of open-source software, and run regular internal and external network scans. We conduct regular application security assessments, including our assessments for internet-facing applications that collect, transmit, or display end user data. We also employ tooling in certain areas to help prevent deviations from policy.
- 37 -
- Incident Response and Reporting. We maintain incident response and recovery protocols to enable prompt, effective and orderly identification, evaluation, management, and disposition of actual and potential security threats and incidents, including for purposes of escalation and internal and external-notification steps. We maintain a cross-functional incident response team, including senior representatives from information security, information technology, product, legal, privacy, communications, and finance, that is involved in assessing cybersecurity threats and incidents, assigning severity levels, and evaluating the potential impact, including the potential impact on our business strategy, results of operations and financial condition. Additionally, we utilize Unit 42 to support our response to threats. This allows for prompt direction of appropriate personnel and resources for incident management and response, and internal notification to appropriate members of management, which may include our chief executive officer, chief product and technology officer, chief information security officer, general counsel, chief financial officer, and/or chief accounting officer, and the security committee of our board of directors (the “Security Committee”).
- Third-Party Risk Management. We maintain a risk-based approach to identifying and overseeing cybersecurity risks presented by certain third parties, including vendors, service providers, suppliers, operations parties, and other external users of our systems, as well as the systems of third parties that are important to our operations and/or process sensitive information on our behalf. This includes a security process to conduct due diligence prior to engaging contractors and vendors and assess the security capabilities of subcontractors and vendors on a periodic basis based on our assessment of each third party’s operational criticality and risk profile. In addition, we maintain a security program designed to protect the security and integrity of our hardware products and data throughout the product design, development, manufacturing, delivery, and service and repair processes, which includes consideration of applicable supply chain risk management standards.
- Risk and Readiness Assessments. We engage in at least quarterly assessments and testing of the effectiveness of our cybersecurity risk management program and incident response protocols that are designed to identify and evaluate vulnerabilities and weaknesses, address cybersecurity threats and test our readiness to respond to cybersecurity incidents. These efforts include, but are not limited to, threat modeling, vulnerability scans, penetration testing, audits, and/or tabletop exercises. We regularly engage third parties to perform assessments on our cybersecurity measures, such as audits and independent reviews of our compliance with various security compliance standards, including those established by the American Institute of Certified Public Accountants, operating effectiveness and penetration tests. The results of such assessments are reported to management and we adjust our cybersecurity policies, standards, processes and practices as necessary based on the information provided by these assessments, audits and reviews.
- Awareness and Training. We provide regular training for educating employees about corporate policies and procedures and information security designed to provide our employees with knowledge of best practices and effective tools for safeguarding our data and assets and reducing security risks based on the human threat vector. Employees are also trained on the responsible use of AI and on the secure use of AI through regular trainings. We also deliver experiential training, including by periodically conducting simulated phishing exercises to test employee awareness and compliance with our security policies.
- Governance. As discussed in more detail below under the heading, “Cybersecurity Governance,” our board of directors has delegated oversight of enterprise security risk management, including, but not limited to, cybersecurity risk management to the Security Committee. As part of our cybersecurity risk management procedures, senior members of management and the Security Committee are informed regarding security events based on established reporting thresholds, and are provided ongoing updates regarding any such meaningful threat or incident.
As a global cybersecurity provider, we recognize that we may be a particularly attractive target for sophisticated threat actors. We have not identified any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, that have materially impacted or are reasonably likely to materially impact us, including our business strategy, results of operations, or financial condition, to date. However, we face ongoing and increasing cybersecurity risks, including from threat actors that are becoming more sophisticated and effective over time, and we can provide no assurance that there will not be incidents in the future or that past or future threats or incidents will not materially affect us, including our business strategy, results of operations, or financial conditions. Despite our efforts, we cannot eliminate all risks from cybersecurity threats or provide assurances that we have not experienced an undetected cybersecurity incident. For additional information regarding these risks, please refer to Part I, Item 1A, “Risk Factors,” in this Form 10-K, including, but not limited to, the risk factor entitled “A significant network or data security incident may materially impact our reputation, financial condition, and operating results.”
- 38 -
Cybersecurity Governance
The Security Committee, which is composed of our independent directors and chaired by our chief product and technology officer, facilitates our board of directors’ responsibility for oversight of security matters, including product security, data security, cybersecurity, security risk management, risk exposure and related controls and enterprise risk management related to these risks. The Security Committee, including our chief information security officer, reports regularly to the Board following meetings of the Security Committee with respect to its review and assessment of security matters and other matters that are relevant to the Security Committee’s discharge of its responsibilities. The Security Committee meets quarterly to review with our chief information security officer and other members of management, which may include our chief executive officer, chief product and technology officer, chief financial officer, and general counsel, our cybersecurity programs, cybersecurity risks, mitigation or remediation strategies, and other matters impacting the committee’s responsibilities.
Management is responsible for day-to-day risk management activities, with our chief information security officer being primarily responsible for identifying, assessing and managing our exposure to cybersecurity risks, establishing processes and procedures so that potential cybersecurity risk exposures are monitored, implementing appropriate mitigation or remediation measures as needed, and maintaining cybersecurity risk management programs. Our chief information security officer is also responsible for defining, overseeing, managing, implementing, and reviewing compliance with the information security programs described above under the heading “Cybersecurity Risk Management and Strategy.” Our chief information security officer receives regular reports from our information security team and monitors the prevention, detection, and mitigation or remediation of cybersecurity risks, and works closely to keep the management team apprised of key risks, treats, and incidents. In addition, as described in further detail above under the heading “Cybersecurity Risk Management and Strategy,” a cross functional team is involved in assessing and managing the risks from cybersecurity threats and incidents, and reporting information about risks to the Security Committee.
Our information security team consists of dedicated personnel who are experienced information systems security professionals and information security managers with many years of experience across a variety of technology sub-specialties. In particular, our chief information security officer has extensive experience in the management of cybersecurity risk management programs, having served in various roles in information technology and security for over 25 years. In addition, seven of the ten members of our board of directors have expertise in overseeing cybersecurity and information security management.
Item 2. Properties
Our corporate headquarters is located in Santa Clara, California, where we lease approximately 941,000 square feet of space under three lease agreements that expire in July 2040, with options to extend the lease terms through July 2052. We also lease space for personnel around the world, including Israel and India. In addition, we provide our cloud-based subscription offerings through data centers operated under co-location arrangements in the United States, Europe, and Asia. Refer to Note 12. Leases in Part II, Item 8 of this Annual Report on Form 10-K for more information on our operating leases. Additionally, we own 24.9 acres of land adjacent to our headquarters in Santa Clara, California, which we intend to develop to accommodate future expansion.
We believe that our current facilities are adequate to meet our current needs. We intend to expand our facilities or add new facilities as we add employees and enter new geographic markets, and we believe that suitable additional or alternative space will be available as needed to accommodate ongoing operations and any such growth. However, we expect to incur additional expenses in connection with such new or expanded facilities.
Item 3. Legal Proceedings
The information set forth under the “Litigation” subheading in Note 13. Commitments and Contingencies in Part II, Item 8 of this Annual Report on Form 10-K is incorporated herein by reference.
Item 4. Mine Safety Disclosures
Not applicable.
- 39 -
Part II
Item 5. Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities
Market Information
Our common stock, $0.0001 par value per share, is traded on the Nasdaq Global Select Market under the symbol “PANW.”
Holders of Record
As of August 31, 2026, there were 585 holders of record of our common stock. Because many of our shares of common stock are held by brokers and other institutions on behalf of stockholders, we are unable to estimate the total number of stockholders represented by these record holders.
Dividend Policy
We have never declared or paid, and do not anticipate declaring or paying in the foreseeable future, any cash dividends on our capital stock. Any future determination as to the declaration and payment of dividends, if any, will be at the discretion of our board of directors, subject to applicable laws, and will depend on then existing conditions, including our financial condition, operating results, contractual restrictions, capital requirements, business prospects, and other factors our board of directors may deem relevant.
Recent Sales of Unregistered Equity Securities
None.
Purchases of Equity Securities by the Issuer and Affiliated Purchasers
In February 2019, our board of directors authorized a $1.0 billion share repurchase program, which is funded from available working capital. Our board of directors subsequently authorized additional increases to this share repurchase program, bringing the total authorization to $5.1 billion, with $1.0 billion remaining as of July 31, 2026. The expiration date of this repurchase authorization was extended to December 31, 2026, and our repurchase program may be suspended or discontinued at any time. Repurchases under our program are to be made at management’s discretion from time to time on the open market, through privately negotiated transactions, transactions structured through investment banking institutions, block purchase techniques, 10b5-1 trading plans, or a combination of the foregoing. During the three months ended July 31, 2026, we did not repurchase any shares pursuant to our share repurchase program.
- 40 -
Stock Price Performance Graph
This performance graph shall not be deemed “filed” for purposes of Section 18 of the Securities Exchange Act of 1934, as amended (the “Exchange Act”), or incorporated by reference into any filing of Palo Alto Networks, Inc. under the Securities Act of 1933, as amended, or the Exchange Act, except as shall be expressly set forth by specific reference in such filing.
This performance graph compares the cumulative total return on our common stock with that of the Nasdaq 100 Index, the Standard & Poor’s 500 Index (“S&P 500 Index), and the Standard & Poor’s 500 Information Technology Index (“S&P 500 Information Technology Index”) for the five years ended July 31, 2026. This performance graph assumes $100 was invested on July 31, 2021, in each of the common stock of Palo Alto Networks, Inc., the Nasdaq 100 Index, the S&P 500 Index, and the S&P 500 Information Technology Index, and assumes the reinvestment of any dividends. The stock price performance on this performance graph is not necessarily indicative of future stock price performance.
Palo Alto Networks, Inc. Comparison of Total Return Performance
| Company/Index | 7/31/2021 | 7/31/2022 | 7/31/2023 | 7/31/2024 | 7/31/2025 | 7/31/2026 |
| Palo Alto Networks, Inc. | $100.00 | $125.07 | $187.92 | $244.13 | $261.02 | 498.93 |
| Nasdaq 100 Index | $100.00 | $87.20 | $107.06 | $132.67 | $160.30 | 196.50 |
| S&P 500 Index | $100.00 | $95.36 | $107.77 | $131.64 | $153.14 | 183.10 |
| S&P 500 Information Technology Index | $100.00 | $94.49 | $119.86 | $162.04 | $200.37 | 252.91 |
Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations
The following discussion and analysis of our financial condition and results of operations should be read in conjunction with our consolidated financial statements and related notes appearing elsewhere in this Annual Report on Form 10-K. The following discussion and analysis contains forward-looking statements based on current expectations and assumptions that are subject to risks and uncertainties, which could cause our actual results to differ materially from those anticipated or implied by any forward-looking statements. Factors that could cause or contribute to such differences include, but are not limited to, those discussed in this Annual Report on Form 10-K, and in particular, the risks discussed under the caption “Risk Factors” in Part I, Item 1A of this report.
Our Management’s Discussion and Analysis of Financial Condition and Results of Operations (“MD&A”) is organized as follows:
- Overview. A discussion of our business and overall analysis of financial and other highlights in order to provide context for the remainder of MD&A.
- Key Financial Metrics. A summary of our U.S. GAAP and non-GAAP key financial metrics, which management monitors to evaluate our performance.
- Results of Operations. A discussion of the nature and trends in our financial results and an analysis of our financial results comparing fiscal 2026 to fiscal 2025. For discussion and analysis related to our financial results comparing fiscal 2025 to 2024, refer to Part II, Item 7 Management’s Discussion and Analysis of Financial Condition and Results of Operations in our Annual Report on Form 10-K for fiscal 2025, which was filed with the Securities and Exchange Commission on August 29, 2025.
- Liquidity and Capital Resources. An analysis of changes on our balance sheets and cash flows, and a discussion of our financial condition and our ability to meet cash needs.
- Critical Accounting Estimates. A discussion of our accounting policies that require critical estimates, assumptions, and judgments.
- Recent Accounting Pronouncements. A discussion of expected impacts of impending accounting changes on financial information to be reported in the future.
Overview
Our mission is to be the cybersecurity partner of choice, protecting our digital way of life. Our platforms and services help secure enterprise users, networks, clouds, endpoints, AI apps and agents, and identities by delivering comprehensive cybersecurity backed by AI and automation, and provide real-time visibility and monitoring across cloud infrastructure, applications and AI workloads. A key element of our strategy is to help our customers simplify their security architectures through consolidating disparate point products. We execute on this strategy by developing our capabilities and packaging our offerings into platforms, which are able to cover many of our customers’ needs in the markets in which we operate. Our platformization strategy combines various products and services into a tightly integrated architecture for more secure, faster, and cost-effective outcomes.
Network & AI Security
Our Network & AI Security platform is designed to deliver complete zero trust solutions to our customers. The platform includes:
- Secure Access Service Edge. Prisma® Access, when combined with Prisma SD-WAN, provides a comprehensive AI-powered SASE solution that secures users, branches, data, AI apps and agents from the most evasive threats in the new AI landscape. Our Prisma Browser™ further extends zero-trust security and data protection to the browser, where the majority of work is done today, providing users with the freedom to work securely using our secure browser from any device.
- Next-Generation Firewalls. Our ML-Powered NGFWs secure on-premises environments including campus locations and data centers. Our software NGFWs secure virtual and cloud networks.
- Cloud-Delivered Security Services. Our network security platform integrates a suite of Precision AI powered security capabilities that complements our SASE and NGFW solutions. These include Advanced Threat Prevention, Advanced WildFire®, Advanced URL Filtering, Advanced DNS Security, Device Security, Quantum Security, NGTS, GlobalProtect®, Prisma Access Agent, Enterprise DLP, SaaS Security, and AI Access Security™. Through these add-on services, our customers are able to secure their content, applications, users, devices, and connection across their entire organization.
- 42 -
- Prisma AIRS. Prisma AIRS™ is our comprehensive AI security platform designed to help organizations discover, assess, and protect AI agents, applications, models and data across the AI lifecycle. It supports key enterprise use cases, including securing AI-assisted software development, protecting custom AI applications from development through runtime, and governing autonomous AI agents. Prisma AIRS™ brings together AI Gateway, Agent Security, AI Red Teaming, AI Runtime Security™, AI Model Security, and AI Posture Management in a unified platform. These capabilities provide visibility into AI assets and activity, assess risks before deployment, and enforce security controls during live AI interactions and agent actions.
- Strata Cloud Manager. SCM, is our AI-powered unified network security management and operations solution. It enables customers to manage and monitor their NGFW and SASE environments through a single, streamlined interface. SCM helps customers centrally manage configurations and security policies, assess security posture and network health, and streamline troubleshooting and remediation. It includes Strata Copilot, which offers a natural language interface for actionable insights and guided remediation, and integrates ADEM to help customers monitor and improve end-user performance across the enterprise.
Cortex
Our AI-powered Cortex® platform transforms end-to-end security operations and observability with unified data, AI, and automation for more secure, faster, and cost effective outcomes.
- Security Operations. We deliver the next generation of security operations capabilities that unifies standalone SIEM tools, endpoint security, security automation, CDR, as well as ASM capabilities on our Cortex platform. These include Cortex XSIAM®, for AI-powered security operations replacing traditional SIEM tools; Cortex XDR®, for the prevention, detection, and response to complex cybersecurity attacks; Cortex XSOAR®, for SOAR; Cortex Xpanse®, for ASM; and Koi Agentic Endpoint Security. Additionally, Cortex XSIAM integrates with the Chronosphere Telemetry Pipeline to ingest and optimize massive data volumes, promoting cost-effective scaling of autonomous operations.
- Cloud Security. We deliver comprehensive security across the cloud application development lifecycle through Cortex Cloud®, delivered as a scalable SaaS offering. As a comprehensive CNAPP combined with CDR, Cortex Cloud secures multi- and hybrid-cloud environments for applications, data, GenAI ecosystem, and the cloud native technology stack across the full development lifecycle, from code to cloud to security operations. As part of the Cortex Cloud platform, customers can expand from Cortex Cloud to our security operations offerings available on a single user experience and unified agent. We also offer our VM-Series and CN-Series virtual firewalls for inline network security on multi- and hybrid-cloud environments.
- Observability. Chronosphere, our next-generation observability platform, delivers real-time visibility and monitoring across cloud-native infrastructure, applications, and AI workloads. Purpose-built to handle the massive data volumes of the AI era, Chronosphere enables organizations to maintain system resilience and uptime with high cost-efficiency and reliability. Our observability platform provides comprehensive visibility into complex digital environments and automated troubleshooting of issues. It allows customers to transition from passive monitoring to proactive management of their entire digital estate. Our telemetry pipeline acts as an intelligent control layer that filters, transforms, and routes data. This helps reduce data volumes, enabling customers to cost-effectively scale their security and observability posture.
Idira
Idira™, our next-generation identity security platform, is designed to secure human, agentic, and machine identities across the enterprise with intelligent privilege controls and continuous threat prevention. By unifying identity access management, privilege access management, and identity governance and administration, organizations can continuously discover and protect against identity risk throughout the end-to-end identity lifecycle. The platform includes:
- Workforce Identity Security. Our solutions apply identity assurance and modern access controls for the entire workforce, including through adaptive MFA, SSO, secure browsing, web session protection, workforce password management, and automated identity lifecycle management. Our approach enforces least privilege by elevating access only when required.
- IT and Developer Identity Security (Modern Privilege Access Management). Our solutions secure high-risk access for IT administrators, third-party vendors, developers, and cloud operations teams across hybrid and multi-cloud environments, delivering just-in-time privileged access, session isolation, credential protection, and zero standing privileges, while providing native, secure access to cloud services, workloads, and development and operations pipelines. Organizations can eliminate excessive permissions, automate access to dynamic cloud resources, and maintain developer velocity while strengthening identity controls across infrastructure and application environments.
- Machine Identity Security. Our solutions secure the growing volume of non-human identities—such as workloads, applications, containers, service accounts, certificates, and keys, including through centralized discovery and management of secrets, certificate lifecycle automation, workload identity issuance, public key infrastructure-as-a-service, Kubernetes certificate management, and secure code signing.
- 43 -
- Identity Governance and Administration. IGA enables visibility into entitlements, automated joiner–mover–leaver processes, access certification, and ongoing identity compliance. AI-supported policy automation helps organizations govern access at scale and enforce a zero-trust model across all identities.
- AI Agents Security. Our solution discovers AI agents, assigns identity attributes, and restricts their access to task-specific resources. It helps monitor and record agent activity for audit purposes, allows organizations to suspend or revoke access if behavior deviates from expected norms, and governs the lifecycle of the agent and the actions taken to support compliance.
Threat Intelligence and Advisory Services
- Unit 42® brings together world-renowned expertise across threat research, incident response, and security consulting to deliver intelligence-driven, response-ready outcomes that help customers reduce cyber risk. Our elite consultants serve as trusted advisors to our customers by assessing and testing their security controls against sophisticated threats, including Frontier AI, transforming their security strategy with a threat-informed approach, and responding to security incidents on behalf of our clients. Additionally, Unit 42 offers MDR and managed threat hunting services. In April 2026, we launched a new suite of Unit 42 Frontier AI Defense services to help customers proactively discover and neutralize threats introduced by next-generation AI models.
For fiscal 2026 and 2025, total revenue was $11.5 billion and $9.2 billion, respectively, representing year-over-year growth of 24%. Our growth reflects the increased adoption of our portfolio, which consists of product, subscriptions, and support, and the contributions from our acquisitions in our current fiscal year. We believe our portfolio will enable us to benefit from recurring revenues and new revenues as we continue to grow our end-customer base. As of July 31, 2026, we had end-customers in over 180 countries. Our end-customers represent a broad range of industries, including education, energy, financial services, government entities, healthcare, Internet and media, manufacturing, public sector, and telecommunications, and include almost all of the Fortune 100 companies and a majority of the Global 2000 companies. We maintain a field sales force that works closely with our channel partners in developing sales opportunities. We primarily use a two-tiered, indirect fulfillment model whereby we sell our products, subscriptions, and support to our distributors, which, in turn, sell to our resellers, which then sell to our end-customers.
Our product revenue grew to $2.3 billion, or 19.9% of total revenue for fiscal 2026, representing year-over-year growth of 27%. Product revenue is derived from sales of hardware products, primarily our ML-Powered NGFW, and software licenses, including SD-WAN, VM-Series, and Panorama®. In connection with the acquisition of CyberArk in February 2026, our product revenue also includes on-premise software licenses of certain identity security offerings. Our ML-Powered NGFW incorporates our PAN-OS® operating system, which provides a consistent set of capabilities across our entire network security product line. Our hardware products and software licenses include a broad set of built-in networking and security features and functionalities. Our products are designed for different performance requirements throughout an organization, ranging from our PA-400, which is designed for small organizations and remote or branch offices, to our top-of-the-line PA-7500, which is designed for large-scale data centers and service provider use. The same firewall functionality that is delivered in our hardware products is also available in our VM-Series virtual firewalls, which secure virtualized and cloud-based computing environments, and in our CN-Series container firewalls, which secure container environments and traffic.
Our subscription and support revenue grew to $9.2 billion, or 80.1% of total revenue for fiscal 2026, representing year-over-year growth of 24%. Our subscriptions provide our end-customers with near real-time access to the latest intrusion prevention, web security, modern malware prevention, data loss prevention, cloud security access broker, and AI security capabilities across the network, endpoints, and the cloud. Our subscriptions also include security operations, which enable customers to leverage the AI-powered Cortex platform for advanced capabilities such as security information and event management, next-generation antivirus, endpoint detection and response, extended detection and response, identity threat detection and response, cloud detection and response, SOAR, ASM, and CNAPP for comprehensive cloud security. In connection with our acquisition of Chronosphere in January 2026, our subscriptions also include a next-generation observability platform for cloud-native infrastructure and applications as well as telemetry pipeline management that is designed to handle vast cloud data volumes with cost-efficiency and reliability. With the acquisition of CyberArk, our subscriptions include a next-generation identity security platform designed to secure human, AI, and machine identity across the enterprise with intelligent privilege controls and continuous threat prevention. Additionally, we offer MDR for Cortex subscriptions, powered by Unit 42’s elite expertise. When customers purchase our physical, virtual, or container firewalls, or certain cloud offerings, they typically purchase support in order to receive ongoing security updates, upgrades, bug fixes, and repairs. In addition to the subscriptions purchased with these firewalls, customers may also purchase other subscriptions on a per-user, per-endpoint, or capacity-based basis. We also offer professional services, including incident response, risk management, digital forensic services, and technical account management.
- 44 -
We continue to invest in innovation as we evolve and further extend the capabilities of our portfolio, as we believe that innovation and timely development of, and investment in, new features and products are essential to meeting the needs of our end-customers and improving our competitive position. During fiscal 2026, we introduced several upgrades and new offerings, including: PAN-OS 12.1 Orion, Prisma AIRS 2.0, NGTS, and Prisma AIRS 3.0. Additionally, we evaluate opportunities to acquire complementary businesses, technologies, services, and intellectual property to complement our organic innovation and research and development efforts, advance the development of our platforms, and enable further investment in our key priority areas. For example, on January 29, 2026, we completed the acquisition of Chronosphere, forming our observability platform; on February 11, 2026, we completed the acquisition of CyberArk, forming our next-generation identity security platform; on April 14, 2026, we completed the acquisition of Koi, adding agentic endpoint security capabilities to our security operations platform and enhancing Prisma AIRS; on May 29, 2026, we completed the acquisition of Portkey, enhancing our Prisma AIRS capabilities; on August 27, 2026, we completed the acquisition of Embrace, which we expect will add RUM capabilities to our observability platform; and on September 1, 2026, we completed the acquisition of Console, which we expect will deepen our agentic capabilities in Cortex. On July 16, 2026, we announced the general availability of Prisma AIRS Gateway, which incorporates AI gateway capabilities acquired through Portkey into Prisma AIRS.
We believe that the growth of our business and our short-term and long-term success are dependent upon many factors, including our ability to extend our technology leadership, grow our base of end-customers, expand deployment of our portfolio and support offerings within existing end-customers, focus on end-customer satisfaction, and address any product vulnerabilities. To manage any future growth effectively, we must continue to improve and expand our information technology and financial infrastructure, our operating and administrative systems and controls, and our ability to manage headcount, capital, and processes in an efficient manner. While these areas present significant opportunities for us, they also pose challenges and risks that we must successfully address in order to sustain the growth of our business and improve our operating results. For additional information regarding the challenges and risks we face, see the “Risk Factors” section in Part I, Item 1A of this Annual Report on Form 10-K.
IMPACT OF MACROECONOMIC DEVELOPMENTS AND OTHER FACTORS ON OUR BUSINESS
Our overall performance depends in part on worldwide economic and geopolitical conditions and their impact on customer behavior. Changes in legislation or regulations and actions by regulators, including changes in enforcement and administration policies, may have an impact on our financial condition and operating results. Significant changes in U.S. or global trade policy, including further expansion of U.S. export/imports controls and tariffs, as well as retaliatory actions by other countries, may materially and adversely affect our business. Further, economic conditions, including inflation, high interest rates, slow growth, fluctuations in foreign exchange rates, supply chain disruptions, including increased memory, storage, or other component shortages and costs, impacts of trade regulations or international trade disputes, and other conditions, may materially and adversely affect our financial condition and operating results.
The hostilities in Israel, Iran, and the surrounding region have continued to result in economic and political uncertainty. While we have business operations in Israel, and intend to continue growing our presence in Israel, we currently do not expect significant business disruption. We are actively monitoring, evaluating, and responding to the situation.
We are also monitoring the impact of inflationary pressures and the tensions between China and Taiwan, and between the U.S. and China, which have increased our costs and could have an adverse impact on our business or results of operations in future periods.
Key Financial Metrics
We monitor the key financial metrics set forth in the tables below to help us evaluate growth trends, establish budgets, measure the effectiveness of our sales and marketing efforts, and assess operational efficiencies. We discuss revenue, gross margin, and the components of operating income and margin below under “Results of Operations.”
in billions
| Line item | July 31, 2026 | July 31, 2025 |
|---|---|---|
| Next-Generation Security Annualized Recurring Revenue | $9.1 | $5.6 |
| Remaining performance obligations | $21.2 | $15.8 |
- 45 -
dollars in millions
| Line item | Year Ended July 31, 2026 | Year Ended July 31, 2025 | Year Ended July 31, 2024 |
|---|---|---|---|
| Total revenue | $11,480 | $9,221 | $8,027 |
| Total revenue year-over-year percentage increase | 24% | 15% | 16% |
| Gross margin | 70.4% | 73.4% | 74.3% |
| Operating income | $695 | $1,243 | $684 |
| Operating margin | 6.1% | 13.5% | 8.5% |
| Net cash provided by operating activities | $4,553 | $3,716 | $3,258 |
| Free cash flow (non-GAAP) | $4,113 | $3,469 | $3,101 |
- Next-Generation Security Annualized Recurring Revenue (“NGS ARR”). Our NGS ARR represents the annualized allocated revenue of all active contracts as of the final day of the reporting period related to all product, subscription, and support offerings, excluding revenue from hardware products, and legacy attached subscriptions, support offerings, and professional services. NGS ARR is an operating metric that we use to assess the strength and trajectory of our business. NGS ARR should be viewed independently of revenue, deferred revenue, and remaining performance obligations and does not represent our revenue under U.S. GAAP on an annualized basis, as it is an operating metric that can be impacted by contract start and end dates and renewal rates. NGS ARR is not intended to be a replacement for forecasts of revenue. The scope of products, subscriptions, and support offerings that contribute to NGS ARR will generally increase over time as we introduce or acquire new next-generation products, subscriptions, and support offerings.
- Net Cash Provided by Operating Activities. We monitor net cash provided by operating activities as a measure of our overall business performance. Our net cash provided by operating activities is driven in large part by sales of our products and from up-front payments for subscription and support offerings. Monitoring net cash provided by operating activities enables us to analyze our financial performance without the non-cash effects of certain items such as share-based compensation costs, depreciation, and amortization, thereby allowing us to better understand and manage the cash needs of our business.
- Free Cash Flow (non-GAAP). We define free cash flow, a non-GAAP financial measure, as net cash provided by operating activities less purchases of property, equipment, and other assets. We consider free cash flow to be an operating metric as well as a liquidity measure that provides useful information to management and investors about the amount of cash generated by the business after necessary capital expenditures. A limitation of the utility of free cash flow as a measure of our liquidity is that it does not represent the total increase or decrease in our cash balance for the period. In addition, it is important to note that other companies, including companies in our industry, may not use free cash flow, may calculate free cash flow in a different manner than we do, or may use other financial measures to evaluate their liquidity, all of which could reduce the usefulness of free cash flow as a comparative measure. A reconciliation of free cash flow to net cash provided by operating activities, the most directly comparable financial measure calculated and presented in accordance with U.S. GAAP, is provided below:
in millions
| Line item | Year Ended July 31, 2026 | Year Ended July 31, 2025 | Year Ended July 31, 2024 |
|---|---|---|---|
| Free cash flow (non-GAAP): | |||
| Net cash provided by operating activities | $4,553 | $3,716 | $3,258 |
| Less: purchases of property, equipment, and other assets | 440 | 247 | 157 |
| Free cash flow (non-GAAP) | $4,113 | $3,469 | $3,101 |
| Net cash used in investing activities | $(3,104) | $(2,205) | $(1,510) |
| Net cash used in financing activities | $(1,202) | $(779) | $(1,343) |
- 46 -
Results of Operations
The following table summarizes our results of operations for the periods presented and as a percentage of our total revenue for those periods based on our consolidated statements of operations data. The period-to-period comparison of results is not necessarily indicative of results for future periods.
dollars in millions
| Line item | Year Ended July 31, 2026Amount | Year Ended July 31, 2026% of Revenue | Year Ended July 31, 2025Amount | Year Ended July 31, 2025% of Revenue | Year Ended July 31, 2024Amount | Year Ended July 31, 2024% of Revenue |
|---|---|---|---|---|---|---|
| Revenue: | ||||||
| Product | $2,280 | 19.9% | $1,802 | 19.5% | $1,603 | 20.0% |
| Subscription and support | 9,200 | 80.1% | 7,419 | 80.5% | 6,424 | 80.0% |
| Total revenue | 11,480 | 100.0% | 9,221 | 100.0% | 8,027 | 100.0% |
| Cost of revenue: | ||||||
| Product | 568 | 4.9% | 413 | 4.5% | 348 | 4.3% |
| Subscription and support | 2,835 | 24.7% | 2,038 | 22.1% | 1,711 | 21.4% |
| Total cost of revenue(1) | 3,403 | 29.6% | 2,451 | 26.6% | 2,059 | 25.7% |
| Total gross profit | 8,077 | 70.4% | 6,770 | 73.4% | 5,968 | 74.3% |
| Operating expenses: | ||||||
| Research and development | 2,552 | 22.2% | 1,984 | 21.5% | 1,810 | 22.5% |
| Sales and marketing | 3,931 | 34.3% | 3,100 | 33.6% | 2,794 | 34.8% |
| General and administrative | 899 | 7.8% | 443 | 4.8% | 680 | 8.5% |
| Total operating expenses(1) | 7,382 | 64.3% | 5,527 | 59.9% | 5,284 | 65.8% |
| Operating income | 695 | 6.1% | 1,243 | 13.5% | 684 | 8.5% |
| Other income (expense), net | (159) | (1.4)% | 353 | 3.8% | 304 | 3.8% |
| Income before income taxes | 536 | 4.7% | 1,596 | 17.3% | 988 | 12.3% |
| Provision for (benefit from) income taxes | 229 | 2.0% | 462 | 5.0% | (1,590) | (19.8)% |
| Net income | $307 | 2.7% | $1,134 | 12.3% | $2,578 | 32.1% |
(1) Includes share-based compensation as follows:
in millions
| Line item | Year Ended July 31, 2026 | Year Ended July 31, 2025 | Year Ended July 31, 2024 |
|---|---|---|---|
| Cost of product revenue | $5 | $5 | $7 |
| Cost of subscription and support revenue | 161 | 127 | 121 |
| Research and development | 688 | 551 | 526 |
| Sales and marketing | 513 | 359 | 301 |
| General and administrative | 448 | 258 | 124 |
| Total share-based compensation | $1,815 | $1,300 | $1,079 |
- 47 -
IMPACT OF ACQUISITIONS
Our operating results were impacted by our acquisitions. In discussions of our results of operations, we may qualitatively or quantitatively disclose the impact of our acquisitions on revenue, costs, and expenses for the one year period subsequent to the acquisition date where such discussions would be meaningful.
REVENUE
Our revenue consists of product revenue and subscription and support revenue. Revenue is recognized upon transfer of control of the corresponding promised products and subscriptions and support to our customers in an amount that reflects the consideration we expect to be entitled to in exchange for those products and subscriptions and support. We expect our revenue to vary from quarter to quarter based on seasonal and cyclical factors and business acquisitions.
PRODUCT REVENUE
Product revenue is derived from sales of hardware products, primarily our ML-Powered NGFW, software licenses, including SD-WAN, VM-Series, Panorama, and certain identity security offerings. Our hardware products and software licenses include a broad set of built-in networking and security features and functionalities. We recognize product revenue at the time of hardware shipment or delivery of software license. As a percentage of product revenue, we expect our revenue from software licenses to vary from quarter to quarter and increase over the long term as we improve features and capabilities of our on-premise software, renew our software license contracts, and expand our installed end-customer base.
dollars in millions
| Line item | Year Ended July 31, 2026Amount | Year Ended July 31, 2025Amount | ChangeAmount | Change% | Year Ended July 31, 2025Amount | Year Ended July 31, 2024Amount | ChangeAmount | Change% |
|---|---|---|---|---|---|---|---|---|
| Product | $2,280 | $1,802 | $478 | 27% | $1,802 | $1,603 | $199 | 12% |
Product revenue increased for fiscal 2026 compared to fiscal 2025 driven by increased revenue from software licenses, including from our CyberArk acquisition, and increased demand for our new generation of hardware products.
SUBSCRIPTION AND SUPPORT REVENUE
Subscription and support revenue is derived primarily from sales of our subscription and support offerings. Our subscription and support contracts are typically one to five years. We recognize revenue from subscriptions and support over time as the services are performed. As a percentage of total revenue, we expect our subscription and support revenue to vary from quarter to quarter and increase over the long term as we introduce new subscriptions, renew existing subscription and support contracts, and expand our installed end-customer base.
dollars in millions
| Line item | Year Ended July 31, 2026Amount | Year Ended July 31, 2025Amount | ChangeAmount | Change% | Year Ended July 31, 2025Amount | Year Ended July 31, 2024Amount | ChangeAmount | Change% |
|---|---|---|---|---|---|---|---|---|
| Subscription | $6,239 | $4,974 | $1,265 | 25% | $4,974 | $4,188 | $786 | 19% |
| Support | 2,961 | 2,445 | 516 | 21% | 2,445 | 2,236 | 209 | 9% |
| Total subscription and support | $9,200 | $7,419 | $1,781 | 24% | $7,419 | $6,424 | $995 | 16% |
Subscription and support revenue increased for fiscal 2026 compared to fiscal 2025 due to increased demand for our subscription and support offerings from our end-customers, including from our CyberArk and Chronosphere acquisitions. The mix between subscription revenue and support revenue will fluctuate over time, depending on the introduction of new subscription offerings, renewals of support services, and our ability to increase sales to new and existing end-customers.
- 48 -
REVENUE BY GEOGRAPHIC THEATER
dollars in millions
| Line item | Year Ended July 31, 2026Amount | Year Ended July 31, 2025Amount | ChangeAmount | Change% | Year Ended July 31, 2025Amount | Year Ended July 31, 2024Amount | ChangeAmount | Change% |
|---|---|---|---|---|---|---|---|---|
| Americas | $7,679 | $6,205 | $1,474 | 24% | $6,205 | $5,483 | $722 | 13% |
| Europe, the Middle East, and Africa (“EMEA”) | 2,428 | 1,917 | 511 | 27% | 1,917 | 1,602 | 315 | 20% |
| Asia Pacific and Japan (“APAC”) | 1,373 | 1,099 | 274 | 25% | 1,099 | 942 | 157 | 17% |
| Total revenue | $11,480 | $9,221 | $2,259 | 25% | $9,221 | $8,027 | $1,194 | 15% |
Revenue from the Americas, EMEA and APAC increased year-over-year for fiscal 2026 as we continued to increase investment in our global sales force in order to support our growth and innovation, with the Americas contributing the highest increase in revenue due to its larger scale.
COST OF REVENUE
Our cost of revenue consists of cost of product revenue and cost of subscription and support revenue.
COST OF PRODUCT REVENUE
Cost of product revenue primarily includes costs paid to our manufacturing partners for procuring components and manufacturing our products. Our cost of product revenue also includes personnel costs, which consist of salaries, benefits, bonuses, share-based compensation, and travel associated with our operations organization, inventory excess and obsolete charges, shipping and tariff costs, amortization of intangible assets, product testing costs, and shared costs. Shared costs consist of certain facilities, depreciation, benefits, recruiting, and information technology costs that we allocate based on headcount. We expect our cost of product revenue to fluctuate with our revenue from hardware products.
dollars in millions
| Line item | Year Ended July 31, 2026Amount | Year Ended July 31, 2025Amount | ChangeAmount | Change% | Year Ended July 31, 2025Amount | Year Ended July 31, 2024Amount | ChangeAmount | Change% |
|---|---|---|---|---|---|---|---|---|
| Cost of product revenue | $568 | $413 | $155 | 38% | $413 | $348 | $65 | 19% |
Cost of product revenue increased for fiscal 2026 compared to fiscal 2025 primarily due to increased demand for our hardware products, higher amortization of intangible assets as a result of our CyberArk acquisition, and higher costs primarily driven by supply chain challenges, partially offset by a decrease in inventory excess and obsolete charges.
COST OF SUBSCRIPTION AND SUPPORT REVENUE
Cost of subscription and support revenue includes personnel costs for our global customer support and technical operations organizations, data center and cloud hosting costs, third-party professional services costs, amortization of acquired intangible assets and capitalized software development costs, customer support and repair costs, and shared costs. We expect our cost of subscription and support revenue to increase as our installed end-customer base grows and adoption of our cloud-based subscription offerings increases.
dollars in millions
| Line item | Year Ended July 31, 2026Amount | Year Ended July 31, 2025Amount | ChangeAmount | Change% | Year Ended July 31, 2025Amount | Year Ended July 31, 2024Amount | ChangeAmount | Change% |
|---|---|---|---|---|---|---|---|---|
| Cost of subscription and support revenue | $2,835 | $2,038 | $797 | 39% | $2,038 | $1,711 | $327 | 19% |
Cost of subscription and support revenue increased for fiscal 2026 compared to fiscal 2025, primarily due to higher cloud hosting costs to support the growth of our cloud-based offerings, amortization of intangible assets from acquisitions in fiscal 2026, and personnel costs driven by headcount growth, including from our acquisitions.
- 49 -
GROSS MARGIN
Gross margin has been and will continue to be affected by a variety of factors, including the introduction of new products, manufacturing costs, the average sales price of our products, cloud hosting costs, personnel costs, the mix of products sold, and the mix of revenue between product and subscription and support offerings. Our higher-end firewall products generally have higher gross margins than our lower-end firewall products within each product series. We expect our gross margins to vary over time depending on the factors described above.
dollars in millions
| Line item | Year Ended July 31, 2026Amount | Year Ended July 31, 2026Gross Margin | Year Ended July 31, 2025Amount | Year Ended July 31, 2025Gross Margin | Year Ended July 31, 2024Amount | Year Ended July 31, 2024Gross Margin |
|---|---|---|---|---|---|---|
| Product | $1,712 | 75.1% | $1,389 | 77.1% | $1,255 | 78.3% |
| Subscription and support | 6,365 | 69.2% | 5,381 | 72.5% | 4,713 | 73.4% |
| Total gross profit | $8,077 | 70.4% | $6,770 | 73.4% | $5,968 | 74.3% |
Product gross margin decreased for fiscal 2026 compared to fiscal 2025 primarily due to a decrease in gross margin on our hardware products, including the impact from supply chain challenges, and higher amortization of intangible assets, partially offset by an increase in software license revenue from our CyberArk acquisition and decrease in inventory excess and obsolete charges.
Subscription and support gross margin decreased for fiscal 2026 compared to fiscal 2025 primarily due to higher amortization of intangible assets as a result of our acquisitions in our current fiscal year and an increase in costs related to our cloud-based offerings.
OPERATING EXPENSES
Our operating expenses consist of research and development, sales and marketing, and general and administrative expenses. Personnel costs are the most significant component of operating expenses and consist of salaries, benefits, bonuses, share-based compensation, travel and entertainment, and with regard to sales and marketing expense, sales commissions. Our operating expenses also include shared costs, which consist of certain facilities, depreciation, benefits, recruiting, and information technology costs that we allocate based on headcount to each department. We expect operating expenses generally to increase in absolute dollars and to decrease over the long term as a percentage of revenue as we continue to scale our business. As of July 31, 2026, we expect to recognize approximately $3.3 billion of share-based compensation expense over a weighted-average period of approximately 2.5 years, excluding additional share-based compensation expense related to any future grants of share-based awards. Share-based compensation expense is generally recognized on a straight-line basis over the requisite service periods of the awards.
In March 2026, the Knesset Finance Committee approved the Law for the Encouragement and Incentivization of Research and Development (the “R&D Law”), which provides incentives for qualifying research and development expenditures incurred on or after January 1, 2026. The R&D Law introduces a qualified refundable tax credit, at varying rates based on specified thresholds, for qualifying research and development expenditures incurred in Israel, subject to meeting defined eligibility criteria. The R&D Law further provides that all or a portion of any unutilized tax credit will be refunded in cash upon the lapse of a period stipulated by the R&D Law. The amount of credit ultimately realized, if any, may differ from our current estimates due to, among other things, changes in the interpretive guidance, eligibility determination, or additional regulations that the Israeli government has indicated it intends to issue regarding the implementation of the R&D Law. For the year ended July 31, 2026, the impact of the R&D Law was not material to our consolidated financial statements. The benefit associated with the R&D Law may vary in future periods depending on the level and nature of qualifying expenditures, the evolving regulatory framework, and other factors.
- 50 -
RESEARCH AND DEVELOPMENT
Research and development expense consists primarily of personnel costs. Research and development expense also includes cloud hosting and shared costs. We expect research and development expense to increase in absolute dollars as we continue to invest in our future products and services, although our research and development expense may fluctuate as a percentage of total revenue.
dollars in millions
| Line item | Year Ended July 31, 2026Amount | Year Ended July 31, 2025Amount | ChangeAmount | Change% | Year Ended July 31, 2025Amount | Year Ended July 31, 2024Amount | ChangeAmount | Change% |
|---|---|---|---|---|---|---|---|---|
| Research and development | $2,552 | $1,984 | $568 | 29% | $1,984 | $1,810 | $174 | 10% |
Research and development expense increased for fiscal 2026 compared to fiscal 2025 primarily due to increased personnel costs, which increased by $429 million for fiscal 2026 compared to fiscal 2025, largely due to headcount growth, including from our acquisitions.
SALES AND MARKETING
Sales and marketing expense consists primarily of personnel costs, including commission expense. Sales and marketing expense also includes costs for market development programs, promotional and other marketing costs, professional services, amortization of intangible assets, and shared costs. We continue to strategically invest in headcount and have grown our sales presence. We expect sales and marketing expense to continue to increase in absolute dollars as we increase the size of our sales and marketing organizations to grow our customer base, increase touch points with end-customers, and expand our global presence, although our sales and marketing expense may fluctuate as a percentage of total revenue.
dollars in millions
| Line item | Year Ended July 31, 2026Amount | Year Ended July 31, 2025Amount | ChangeAmount | Change% | Year Ended July 31, 2025Amount | Year Ended July 31, 2024Amount | ChangeAmount | Change% |
|---|---|---|---|---|---|---|---|---|
| Sales and marketing | $3,931 | $3,100 | $831 | 27% | $3,100 | $2,794 | $306 | 11% |
Sales and marketing expense increased for fiscal 2026 compared to fiscal 2025 primarily due to increased personnel costs, which increased by $584 million for fiscal 2026 compared to fiscal 2025, largely due to headcount growth, including from our acquisitions. The increase was further driven by higher amortization of purchased intangible assets as a result of our acquisitions in fiscal 2026.
GENERAL AND ADMINISTRATIVE
General and administrative expense consists primarily of personnel costs and shared costs for our executive, finance, human resources, information technology, and legal organizations, and professional services costs, which consist primarily of legal, auditing, accounting, and other consulting costs. General and administrative expense also includes change in fair value of contingent consideration liability. Excluding the near-term impact of our acquisitions in our current fiscal year, we expect general and administrative expense to increase in absolute dollars over time as we increase the size of our general and administrative organizations and incur additional costs to support our business growth, although our general and administrative expense may fluctuate as a percentage of total revenue.
dollars in millions
| Line item | Year Ended July 31, 2026Amount | Year Ended July 31, 2025Amount | ChangeAmount | Change% | Year Ended July 31, 2025Amount | Year Ended July 31, 2024Amount | ChangeAmount | Change% |
|---|---|---|---|---|---|---|---|---|
| General and administrative | $899 | $443 | $456 | 103% | $443 | $680 | $(237) | (35)% |
General and administrative expense increased for fiscal 2026 compared to fiscal 2025 primarily due to increased personnel costs, which grew $253 million for fiscal 2026 compared to fiscal 2025, primarily due to accelerated vesting of certain equity awards in connection with our acquisitions in fiscal year 2026, employee severance charges in connection with our CyberArk acquisition, and headcount growth, including from our acquisitions. The increase in general and administrative expense was further driven by an increase in acquisition-related costs.
- 51 -
OTHER INCOME (EXPENSE), NET
Other income (expense), net includes interest income earned on our cash, cash equivalents, and investments, interest expense related to our 0.375% Convertible Senior Notes due 2025 (the “2025 Notes”), gains and losses from foreign currency remeasurement and foreign currency transactions, and changes in fair value of our 0.0% Convertible Senior Notes due 2030 (the “2030 Notes”) and capped call transactions we assumed in connection with our acquisition of CyberArk (“Capped Calls”).
dollars in millions
| Line item | Year Ended July 31, 2026Amount | Year Ended July 31, 2025Amount | ChangeAmount | Change% | Year Ended July 31, 2025Amount | Year Ended July 31, 2024Amount | ChangeAmount | Change% |
|---|---|---|---|---|---|---|---|---|
| Other income (expense), net | $(159) | $353 | $(512) | (145)% | $353 | $304 | $49 | 16% |
Other income (expense), net decreased for fiscal 2026 compared to fiscal 2025 primarily due to a loss from the change in fair value of our 2030 Notes, partially offset by gains from the change in fair value of our Capped Calls and gains on sales of our investments to fund acquisitions.
PROVISION FOR (BENEFIT FROM) INCOME TAXES
Provision for income taxes consists primarily of U.S. and foreign income taxes. We had a benefit from income taxes during fiscal 2024 primarily due to the release of our valuation allowance on U.S. federal, U.S. states other than California, and U.K. deferred tax assets.
dollars in millions
| Line item | Year Ended July 31, 2026Amount | Year Ended July 31, 2025Amount | ChangeAmount | Change% | Year Ended July 31, 2025Amount | Year Ended July 31, 2024Amount | ChangeAmount | Change% |
|---|---|---|---|---|---|---|---|---|
| Provision for (benefit from) income taxes | $229 | $462 | $(233) | (50)% | $462 | $(1,590) | $2,052 | (129)% |
| Effective tax rate | 42.7% | 28.9% | 28.9% | (160.8)% |
Our effective tax rate increased for fiscal 2026 compared to fiscal 2025 primarily due to non-deductible changes in fair value of our 2030 Notes and Capped Calls and share based compensation, partially offset by intercompany legal entity restructuring in fiscal 2026 and the impact of adoption of One Big Beautiful Bill Act in fiscal 2025.
- 52 -
Liquidity and Capital Resources
in millions
| Line item | July 31, 2026 | July 31, 2025 |
|---|---|---|
| Working capital (deficit) | $(1,280) | $(465) |
| Cash, cash equivalents, and investments: | ||
| Cash and cash equivalents | $2,514 | $2,269 |
| Investments | 5,392 | 6,190 |
| Total cash, cash equivalents, and investments | $7,906 | $8,459 |
As of July 31, 2026, our total cash, cash equivalents, and investments of $7.9 billion were held for general corporate purposes. As part of the acquisition of CyberArk, we executed an intercompany transaction to repatriate $3.5 billion of foreign earnings, resulting in immaterial income tax expense related to state and other taxes. Our remaining unremitted earnings are indefinitely reinvested.
DEBT
In February 2026 in connection with the acquisition of CyberArk, we entered into a supplemental indenture (the “Supplemental Indenture”) to the Indenture, dated as of June 10, 2025 (together with the Supplemental Indenture, the “Indenture”), between CyberArk, as issuer, and U.S. Bank Trust Company, National Association, as trustee, governing CyberArk’s $1.25 billion aggregate principal amount of the 2030 Notes. As a result of our acquisition of CyberArk and pursuant to the Supplemental Indenture, the 2030 Notes are now exchangeable into shares of our common stock and cash. The 2030 Notes mature on June 15, 2030; however, under certain circumstances, holders may surrender their 2030 Notes for conversion prior to the maturity date. Upon conversion of the 2030 Notes, we will pay cash equal to the aggregate principal amount of the 2030 Notes to be converted, and, at our election, we will pay or deliver cash or a combination of cash and shares of our common stock for the amount of our conversion obligation in excess of the aggregate principal amount of the 2030 Notes converted. During the year ended July 31, 2026, holders surrendered $153 million in aggregate principal amount of the 2030 Notes for conversion, which were settled for $160 million in cash. After giving effect to these conversions, the remaining outstanding principal balance of the 2030 Notes was $1.1 billion.
The sale price condition for the 2030 Notes was not met during the calendar quarter ended June 30, 2026, and as a result, our 2030 Notes are not convertible pursuant to that condition during the calendar quarter ending September 30, 2026. If the sale price condition for the 2030 Notes is met during the calendar quarter ending September 30, 2026 and all of the holders elect to convert their 2030 Notes during the calendar quarter ending December 31, 2026, we would be obligated to settle the $1.1 billion principal amount of the 2030 Notes and a portion of our conversion obligation in excess of the aggregate principal amount of the 2030 Notes, if any, in cash. We believe that our net cash provided by operating activities, our existing cash, cash equivalents, and investments, and existing sources of and access to financing, including any proceeds that may be received from the settlement or termination of the outstanding Capped Calls, will be sufficient to meet our anticipated cash needs should the holders choose to convert their 2030 Notes during the fiscal quarter ending October 31, 2026 or hold the 2030 Notes until maturity on June 15, 2030. Refer to Note 11. Debt in Part II, Item 8 of this Annual Report on Form 10-K for more information on the 2030 Notes.
In April 2023, we entered into a credit agreement (the “Credit Agreement”) that provides for a $400 million unsecured revolving credit facility (the “Credit Facility”), with an option to increase the amount of the Credit Facility by up to an additional $350 million, subject to certain conditions. The interest rates and commitment fees are also subject to upward and downward adjustments based on our progress towards the achievement of certain sustainability goals. As of July 31, 2026, there were no amounts outstanding, and no default or event of default has occurred under the Credit Agreement. Refer to Note 11 Debt in Part II, Item 8 of this Annual Report on Form 10-K for more information on the Credit Agreement.
CAPITAL RETURN
In February 2019, our board of directors authorized a $1.0 billion share repurchase program. Our board of directors subsequently authorized additional increases to this share repurchase program, bringing the total authorization to $5.1 billion. Repurchases will be funded from available working capital and may be made at management’s discretion from time to time. As of July 31, 2026, $1.0 billion remained available for future share repurchases under this repurchase program. The repurchase authorization will expire on December 31, 2026 and may be suspended or discontinued at any time without prior notice. Refer to Note 14. Stockholders’ Equity in Part II, Item 8 of this Annual Report on Form 10-K for more information on this repurchase program.
- 53 -
CONTRACTUAL OBLIGATIONS AND OTHER MATERIAL CASH REQUIREMENTS
We have entered into various non-cancelable operating leases, primarily for our offices, with lease terms expiring through fiscal 2040, with the most significant leases relating to our corporate headquarters in Santa Clara, California. As of July 31, 2026, we have total operating lease obligations of $793 million recorded on our consolidated balance sheet.
As of July 31, 2026, our commitments to purchase products, components, cloud hosting, and other services totaled $8.3 billion. Refer to Note 13. Commitments and Contingencies in Part II, Item 8 of this Annual Report on Form 10-K for more information on these commitments.
Our acquisition of certain QRadar assets from International Business Machines Corporation (“IBM”) on August 31, 2024 included contingent consideration that requires potential future payments through the fiscal quarter ending October 31, 2028. As of July 31, 2026, we have a contingent consideration obligation of $206 million recorded on our consolidated balance sheet. Refer to Note 3. Fair Value Measurements and Note 8. Acquisitions in Part II, Item 8 of this Annual Report on Form 10-K for more information on our contingent consideration obligation.
CASH FLOWS
The following table summarizes our cash flows for the years ended July 31, 2026, 2025, and 2024:
in millions
| Line item | Year Ended July 31, 2026 | Year Ended July 31, 2025 | Year Ended July 31, 2024 |
|---|---|---|---|
| Net cash provided by operating activities | $4,553 | $3,716 | $3,258 |
| Net cash used in investing activities | (3,104) | (2,205) | (1,510) |
| Net cash used in financing activities | (1,202) | (779) | (1,343) |
| Effect of exchange rate changes on cash, cash equivalents, and restricted cash | (3) | — | — |
| Net increase in cash, cash equivalents, and restricted cash | $244 | $732 | $405 |
Cash flows from operations could be affected by various risks and uncertainties detailed in Part I, Item 1A “Risk Factors” in this Annual Report on Form 10-K. We believe that our cash flow from operations with existing cash and cash equivalents will be sufficient to meet our anticipated cash needs for at least the next 12 months and thereafter for the foreseeable future. Our future capital requirements will depend on many factors including our growth rate, the timing and extent of spending to support development efforts, the expansion of sales and marketing activities, the introduction of new and enhanced products and subscription and support offerings, the costs to acquire or invest in complementary businesses and technologies, the costs to ensure access to adequate manufacturing capacity, the investments in our infrastructure to support the adoption of our cloud-based subscription offerings, the continuing market acceptance of our products and subscription and support offerings, and macroeconomic events. In addition, from time to time, we may incur additional tax liability in connection with certain corporate structuring decisions.
We may also choose to seek additional equity or debt financing. In the event that additional financing is required from outside sources, we may not be able to raise it on terms acceptable to us or at all. If we are unable to raise additional capital when desired, our business, financial condition, and operating results may be adversely affected.
OPERATING ACTIVITIES
Our operating activities have consisted of net income adjusted for certain non-cash items and changes in assets and liabilities. Our largest source of cash provided by our operations is receipts from our customers. Net cash provided by operating activities can be impacted by factors such as timing of payments and collections, vendor payment terms, and timing and amount of tax payments.
Net cash provided by operating activities during fiscal 2026 was $4.6 billion, an increase of $837 million compared to fiscal 2025. The increase was primarily due to growth of our business as reflected by increases in collections during fiscal 2026, partially offset by higher cash expenditure to support our business growth.
INVESTING ACTIVITIES
Our investing activities have consisted of capital expenditures, net investment purchases, sales, and maturities, and business acquisitions. We expect to continue such activities as our business grows.
- 54 -
Net cash used in investing activities during fiscal 2026 was $3.1 billion, an increase of $899 million compared to fiscal 2025. The increase was primarily due to an increase in net cash payments for business acquisitions during fiscal 2026, partially offset by higher proceeds from sales and maturities of investments.
FINANCING ACTIVITIES
Our financing activities have consisted of repayments and settlement of conversions of our convertible senior notes, proceeds from Capped Calls, cash used to repurchase shares of our common stock, proceeds from sales of shares through employee equity incentive plans, payments for tax withholding obligations of certain employees related to the net share settlement of equity awards, and payments of contingent consideration.
Net cash used in financing activities during fiscal 2026 was $1.2 billion, an increase of $423 million compared to fiscal 2025. The increase was primarily due to repurchases of our common stock and payments of our contingent consideration during fiscal 2026, partially offset by a decrease in cash used for repayments and settlement of conversions of our convertible notes.
Critical Accounting Estimates
Our consolidated financial statements have been prepared in accordance with U.S. GAAP. The preparation of these consolidated financial statements requires us to make estimates and assumptions that affect the reported amounts of assets, liabilities, revenue, expenses, and related disclosures. We base our estimates on historical experience and on various other assumptions that we believe are reasonable under the circumstances. We evaluate our estimates and assumptions on an ongoing basis. Actual results could differ materially from those estimates due to risks and uncertainties, including uncertainty in the current economic environment. To the extent that there are material differences between these estimates and our actual results, our future consolidated financial statements will be affected.
We believe that of our significant accounting policies described in Note 1. Description of Business and Summary of Significant Accounting Policies in Part II, Item 8 of this Annual Report on Form 10-K, the critical accounting estimates, assumptions, and judgments that have the most significant impact on our consolidated financial statements are described below.
REVENUE RECOGNITION
The majority of our contracts with our customers include various combinations of our products and subscriptions and support. Our hardware products and software licenses are distinct from our subscriptions and support services as the customer can benefit from the product without these services and such services are separately identifiable within the contract. We account for multiple agreements with a single customer as a single contract if the contractual terms and/or substance of those agreements indicate that they may be so closely related that they are, in effect, parts of a single contract. The amount of consideration we expect to receive in exchange for delivering on the contract is allocated to each performance obligation based on its relative standalone selling price.
When estimating standalone selling price, we first consider the prices charged for a deliverable when sold separately. If the standalone selling price is not observable through past transactions, we estimate it based on our pricing model and our go-to-market strategy, which include factors such as type of sales channel (channel partner or end-customer), the geographies in which our offerings were sold (domestic or international), and offering type (products, subscriptions, or support). As our business offerings evolve over time, we may be required to modify our estimated standalone selling prices, and as a result the timing and classification of our revenue could be affected.
INCOME TAXES
We account for income taxes using the asset and liability method, which requires the recognition of deferred tax assets and liabilities for the expected future tax consequences of events that have been recognized in our consolidated financial statements or tax returns. In addition, deferred tax assets are recorded for all future benefits including, but not limited to, net operating losses, research and development credit carryforwards, and basis differences relating to our global intangible low-taxed income. Valuation allowances are provided when necessary to reduce deferred tax assets to the amount more likely than not to be realized.
Significant judgment is required in determining any valuation allowance recorded against deferred tax assets. In assessing the need for a valuation allowance, we consider all available evidence, including past operating results, estimates of future taxable income, and the feasibility of tax planning strategies. In the event that we change our determination as to the amount of deferred tax assets that can be realized, we will adjust our valuation allowance with a corresponding impact to the provision for income taxes in the period in which such determination is made.
- 55 -
We recognize liabilities for uncertain tax positions based on a two-step process which includes evaluating if a tax position is more likely than not to be sustained on audit and then measuring the tax benefit as the largest amount that is more likely than not to be realized upon ultimate settlement. Assumptions, judgment, and the use of estimates are required in determining if the more-likely-than-not standard has been met and in determining the expected benefit when developing the provision for income taxes. Our evaluations are based upon a number of factors, including changes in facts or circumstances, changes in tax law or guidance, correspondence with tax authorities during the course of audits, and effective settlement of audit issues. Changes in these or other factors could result in material increases or decreases in our provision for (benefit from) income taxes in the period in which we make the change.
LOSS CONTINGENCIES
We are subject to the possibility of various loss contingencies arising in the ordinary course of business. We accrue for loss contingencies when it is probable that an asset has been impaired or a liability has been incurred and the amount of loss can be reasonably estimated. If we determine that a loss is reasonably possible, then we disclose the possible loss or range of the possible loss or state that such an estimate cannot be made. We regularly evaluate current information available to us to determine whether an accrual is required, an accrual should be adjusted, or a range of possible loss should be disclosed.
From time to time, we are involved in disputes, litigation, and other legal actions. However, there are many uncertainties associated with any litigation, and these actions or other third-party claims against us may cause us to incur substantial settlement charges, which are inherently difficult to estimate and could adversely affect our results of operations. The actual liability in any such matters may be materially different from our estimates, which could result in the need to adjust our liability and record additional expenses. Refer to the “Litigation” subheading in Note 13. Commitments and Contingencies in Part II, Item 8 of this Annual Report on Form 10-K for more information regarding our litigation.
BUSINESS COMBINATIONS
We make significant estimates, assumptions, and judgments when valuing assets acquired and liabilities assumed, especially with respect to purchased intangible assets, in connection with the initial purchase price allocation of an acquired business. Critical estimates in valuing certain purchased intangible assets include, but are not limited to, cash flows that an asset is expected to generate in the future, discount rates, the time and expense that would be necessary to recreate the assets, and the profit margin a market participant would receive on such recreated assets. The amounts and useful lives assigned to identified intangible assets impact the amount and timing of future amortization expense.
One of our business combinations has included post-closing payments contingent upon the occurrence of future events and/or certain conditions being met. Critical estimates used in valuing our contingent consideration obligation include, but are not limited to, estimated future cash payments related to customers entering into qualified new transactions and risk-adjusted discount rates used to present value the expected cash flows. These estimates and assumptions are updated to revalue our contingent consideration liability at the end of each reporting period. Accordingly, subsequent changes in underlying facts and circumstances could result in changes in these estimates and assumptions, which could have a material impact on the estimated future fair values of these obligations.
Recent Accounting Pronouncements
Refer to “Recently Adopted Accounting Pronouncements” and “Recently Issued Accounting Pronouncements” in Note 1. Description of Business and Summary of Significant Accounting Policies in Part II, Item 8 of this Annual Report on Form 10-K for a description of recent accounting pronouncements and our expectation of their impact, if any, on our results of operations and financial condition.
- 56 -
Item 7A. Quantitative and Qualitative Disclosures About Market Risk
Foreign Currency Exchange Risk
Our sales contracts are primarily denominated in U.S. dollars. A portion of our operating expenditures are denominated in foreign currencies, making them subject to fluctuations in foreign currency exchange rates. Additionally, fluctuations in foreign currency exchange rates may cause us to recognize transaction gains and losses in our statement of operations. Foreign currency remeasurement gains and losses and foreign currency transaction gains and losses have not had a significant impact to our consolidated financial statements.
We enter into foreign currency derivative contracts with maturities of 24 months or less, which we designate as cash flow hedges, to manage the foreign currency exchange risk associated with our revenue and operating expenditures. We also enter into foreign currency derivative contracts that are not designated as hedging instruments to hedge a portion of our outstanding monetary assets and liabilities denominated in foreign currencies. These foreign currency derivative contracts reduce but do not entirely eliminate the effect of foreign exchange rate fluctuations.
A hypothetical 10% change in foreign exchange rates on monetary assets and liabilities would not be material to our financial condition or results of operations after taking into consideration the effect of foreign currency forward contracts in place as of July 31, 2026. The effectiveness of our existing hedging transactions and the availability and effectiveness of any hedging transactions we may decide to enter into in the future may be limited, and we may not be able to successfully hedge our exposure, which could adversely affect our financial condition and results of operations. Refer to Note 6. Derivative Instruments in Part II, Item 8 of this Annual Report on Form 10-K for more information.
As our international operations grow, our risks associated with fluctuations in foreign currency exchange rates will become greater, and we will continue to reassess our approach to managing this risk. In addition, a weakening U.S. dollar can increase the costs of our international expansion and a strengthening U.S. dollar can increase the real cost of our products and services to our end-customers outside of the United States, leading to delays in the purchase of our products and services. For additional information, see the risk factor entitled “We are exposed to fluctuations in foreign currency exchange rates, which could negatively affect our financial condition and operating results.” in Part I, Item 1A of this Annual Report on Form 10-K.
Interest Rate Risk
The primary objectives of our investment activities are to preserve principal, provide liquidity, and maximize income without significantly increasing risk. Most of the securities we invest in are subject to interest rate risk. To minimize this risk, we maintain a diversified portfolio of cash, cash equivalents, and investments, consisting only of investment-grade securities. To assess the interest rate risk, we performed a sensitivity analysis to determine the impact a change in interest rates would have on the value of the investment portfolio. Based on investment positions as of July 31, 2026, a hypothetical 100 basis point increase in interest rates across all maturities would result in a $128 million decline in the fair market value of the portfolio. Such losses would only be realized if we sold the investments prior to maturity. Conversely, a hypothetical 100 basis point decrease in interest rates would lead to a $131 million increase in the fair market value of the portfolio.
- 57 -
Item 8. Financial Statements and Supplementary Data
| Line item | Page |
|---|---|
| Reports of Independent Registered Public Accounting Firm (PCAOB ID: 42) | 59 |
| Consolidated Balance Sheets | 62 |
| Consolidated Statements of Operations | 63 |
| Consolidated Statements of Comprehensive Income | 64 |
| Consolidated Statements of Stockholders’ Equity | 65 |
| Consolidated Statements of Cash Flows | 66 |
| Notes to Consolidated Financial Statements | 67 |
- 58 -
Report of Independent Registered Public Accounting Firm
To the Stockholders and the Board of Directors of Palo Alto Networks, Inc.
Opinion on the Financial Statements
We have audited the accompanying consolidated balance sheets of Palo Alto Networks, Inc. (the Company) as of July 31, 2026 and 2025, the related consolidated statements of operations, comprehensive income, stockholders’ equity and cash flows for each of the three years in the period ended July 31, 2026, and the related notes (collectively referred to as the “consolidated financial statements”). In our opinion, the consolidated financial statements present fairly, in all material respects, the financial position of the Company at July 31, 2026 and 2025, and the results of its operations and its cash flows for each of the three years in the period ended July 31, 2026, in conformity with U.S. generally accepted accounting principles.
We also have audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the Company’s internal control over financial reporting as of July 31, 2026, based on criteria established in Internal Control—Integrated Framework issued by the Committee of Sponsoring Organizations of the Treadway Commission (2013 framework), and our report dated September 10, 2026 expressed an unqualified opinion thereon.
Basis for Opinion
These financial statements are the responsibility of the Company’s management. Our responsibility is to express an opinion on the Company’s financial statements based on our audits. We are a public accounting firm registered with the PCAOB and are required to be independent with respect to the Company in accordance with the U.S. federal securities laws and the applicable rules and regulations of the Securities and Exchange Commission and the PCAOB.
We conducted our audits in accordance with the standards of the PCAOB. Those standards require that we plan and perform the audit to obtain reasonable assurance about whether the financial statements are free of material misstatement, whether due to error or fraud. Our audits included performing procedures to assess the risks of material misstatement of the financial statements, whether due to error or fraud, and performing procedures that respond to those risks. Such procedures included examining, on a test basis, evidence regarding the amounts and disclosures in the financial statements. Our audits also included evaluating the accounting principles used and significant estimates made by management, as well as evaluating the overall presentation of the financial statements. We believe that our audits provide a reasonable basis for our opinion.
Critical Audit Matters
The critical audit matters communicated below are matters arising from the current period audit of the financial statements that were communicated or required to be communicated to the audit committee and that: (1) relate to accounts or disclosures that are material to the financial statements and (2) involved our especially challenging, subjective or complex judgments. The communication of critical audit matters does not alter in any way our opinion on the consolidated financial statements, taken as a whole, and we are not, by communicating the critical audit matters below, providing separate opinions on the critical audit matters or on the accounts or disclosures to which they relate.
- 59 -
REVENUE RECOGNITION
Description of the Matter As described in Note 1 to the consolidated financial statements, the Company’s contracts with customers sometimes contain multiple performance obligations, which are accounted for separately if they are distinct. In such cases, the transaction price is then allocated to the distinct performance obligations on a relative standalone selling price basis, and revenue is recognized when control of the distinct performance obligation is transferred. For example, product revenue is recognized at the time of hardware shipment or delivery of software license, and subscription and support revenue is recognized over time as the services are performed. Auditing the Company’s revenue recognition was complex, including the identification and determination of distinct performance obligations and the timing of revenue recognition. For example, there were certain customer arrangements with nonstandard terms and conditions that required judgment to determine the distinct performance obligations and the impact on the timing of revenue recognition.
How We Addressed the Matter in Our Audit We obtained an understanding, evaluated the design and tested the operating effectiveness of the Company’s process and controls to identify and determine the distinct performance obligations and the timing of revenue recognition. To test the identification and determination of the distinct performance obligations and the timing of revenue recognition, our audit procedures included, among others, reading the executed contract and other contractual documents to understand the contract, identifying the performance obligation(s), determining the distinct performance obligations, and evaluating the timing of revenue recognition for a sample of individual sales transactions. We evaluated the accuracy of the Company’s contract summary documentation, specifically related to the identification and determination of distinct performance obligations and the timing of revenue recognition.
ACQUISITION OF CYBERARK SOFTWARE LTD. (“CYBERARK”) - VALUATION OF PLATFORM RENEWALS
Description of the Matter As disclosed in Notes 1 and 8 to the consolidated financial statements, on February 11, 2026, the Company completed the acquisition of CyberArk for total purchase consideration of $21.1 billion. The Company accounted for the acquisition as a business combination. In connection with this acquisition, the Company recognized platform renewals intangible assets of $3.5 billion. Auditing the Company’s valuation of the acquired platform renewals intangible assets was complex due to the significant judgment and estimation in determining the fair value of the platform renewals. Specifically, the fair value estimate for the acquired platform renewals intangible assets is sensitive to changes in the Company’s assumption related to forecasted revenue attributable to platform renewals. This significant assumption is forward-looking and could be affected by future economic and market conditions.
How We Addressed the Matter in Our Audit We obtained an understanding, evaluated the design, and tested the operating effectiveness of the Company’s process and controls for the valuation of acquired intangible assets, including controls over the significant assumption described above. To test the estimated fair value of the platform renewals intangible assets, we performed audit procedures that included, among others, assessing the valuation methodology, and testing the significant assumption discussed above and the completeness and accuracy of the underlying data used by the Company. We compared the significant assumption used by the Company to current and historical industry, market and economic information and trends where relevant. We assessed sensitivity analyses of the significant assumption to evaluate the changes in the fair value of the platform renewals intangible assets resulting from changes in the assumption. We involved our valuation professionals to assist in evaluating the valuation methodology used in the determination of the fair value estimate.
/s/ Ernst & Young LLP
We have served as the Company’s auditor since 2009.
San Mateo, California
September 10, 2026
- 60 -
Report of Independent Registered Public Accounting Firm
To the Stockholders and the Board of Directors of Palo Alto Networks, Inc.
Opinion on Internal Control Over Financial Reporting
We have audited Palo Alto Networks, Inc.’s internal control over financial reporting as of July 31, 2026, based on criteria established in Internal Control—Integrated Framework issued by the Committee of Sponsoring Organizations of the Treadway Commission (2013 framework) (the COSO criteria). In our opinion, Palo Alto Networks, Inc. (the Company) maintained, in all material respects, effective internal control over financial reporting as of July 31, 2026, based on the COSO criteria.
As indicated in the accompanying Management's Annual Report on Internal Control over Financial Reporting, management’s assessment of and conclusion on the effectiveness of internal control over financial reporting did not include the internal controls of CyberArk, which is included in the 2026 consolidated financial statements of the Company and constituted 2% and less than 1% of total consolidated assets and total consolidated net assets, respectively, as of July 31, 2026 and 6% of total consolidated revenue, for the year then ended. Our audit of internal control over financial reporting of the Company also did not include an evaluation of the internal control over financial reporting of CyberArk.
We also have audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the consolidated balance sheets of the Company as of July 31, 2026 and 2025, the related consolidated statements of operations, comprehensive income, stockholders’ equity and cash flows for each of the three years in the period ended July 31, 2026, and the related notes and our report dated September 10, 2026 expressed an unqualified opinion thereon.
Basis for Opinion
The Company’s management is responsible for maintaining effective internal control over financial reporting and for its assessment of the effectiveness of internal control over financial reporting included in the accompanying Management’s Annual Report on Internal Control over Financial Reporting. Our responsibility is to express an opinion on the Company’s internal control over financial reporting based on our audit. We are a public accounting firm registered with the PCAOB and are required to be independent with respect to the Company in accordance with the U.S. federal securities laws and the applicable rules and regulations of the Securities and Exchange Commission and the PCAOB.
We conducted our audit in accordance with the standards of the PCAOB. Those standards require that we plan and perform the audit to obtain reasonable assurance about whether effective internal control over financial reporting was maintained in all material respects.
Our audit included obtaining an understanding of internal control over financial reporting, assessing the risk that a material weakness exists, testing and evaluating the design and operating effectiveness of internal control based on the assessed risk, and performing such other procedures as we considered necessary in the circumstances. We believe that our audit provides a reasonable basis for our opinion.
Definition and Limitations of Internal Control Over Financial Reporting
A company’s internal control over financial reporting is a process designed to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements for external purposes in accordance with generally accepted accounting principles. A company’s internal control over financial reporting includes those policies and procedures that (1) pertain to the maintenance of records that, in reasonable detail, accurately and fairly reflect the transactions and dispositions of the assets of the company; (2) provide reasonable assurance that transactions are recorded as necessary to permit preparation of financial statements in accordance with generally accepted accounting principles, and that receipts and expenditures of the company are being made only in accordance with authorizations of management and directors of the company; and (3) provide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use, or disposition of the company’s assets that could have a material effect on the financial statements.
Because of its inherent limitations, internal control over financial reporting may not prevent or detect misstatements. Also, projections of any evaluation of effectiveness to future periods are subject to the risk that controls may become inadequate because of changes in conditions, or that the degree of compliance with the policies or procedures may deteriorate.
/s/ Ernst & Young LLP
San Mateo, California
September 10, 2026
- 61 -
PALO ALTO NETWORKS, INC.
CONSOLIDATED BALANCE SHEETS(In millions, except per share data)
| Line item | July 31, 2026 | July 31, 2025 |
|---|---|---|
| Assets | ||
| Current assets: | ||
| Cash and cash equivalents | $2,514 | $2,269 |
| Short-term investments | ||
| Accounts receivable, net of allowance for credit losses of and as of July 31, 2026 and July 31, 2025, respectively | 3,629 | 2,965 |
| Short-term financing receivables, net | ||
| Short-term deferred contract costs | ||
| Prepaid expenses and other current assets | 807 | 520 |
| Total current assets | ||
| Property and equipment, net | ||
| Operating lease right-of-use assets | ||
| Long-term investments | ||
| Long-term financing receivables, net | ||
| Long-term deferred contract costs | ||
| Goodwill | ||
| Intangible assets, net | ||
| Deferred tax assets | ||
| Other assets | ||
| Total assets | $48,460 | $23,576 |
| Liabilities and stockholders’ equity | ||
| Current liabilities: | ||
| Accounts payable | $290 | $232 |
| Accrued compensation | ||
| Accrued and other liabilities | ||
| Deferred revenue | 7,747 | 6,302 |
| Total current liabilities | ||
| Long-term convertible senior notes | ||
| Long-term deferred revenue | ||
| Deferred tax liabilities | ||
| Long-term operating lease liabilities | ||
| Other long-term liabilities | 1,285 | 887 |
| Total liabilities | 20,968 | 15,752 |
| Commitments and contingencies (Note 13) | ||
| Stockholders’ equity: | ||
| Preferred stock; par value; shares authorized; issued and outstanding as of July 31, 2026 and July 31, 2025 | ||
| Common stock and additional paid-in capital; par value; shares authorized; and shares issued and outstanding as of July 31, 2026 and July 31, 2025, respectively | ||
| Accumulated other comprehensive income (loss) | (71) | 48 |
| Retained earnings | 2,791 | 2,484 |
| Total stockholders’ equity | 27,492 | 7,824 |
| Total liabilities and stockholders’ equity |
See notes to consolidated financial statements.
- 62 -
PALO ALTO NETWORKS, INC.
CONSOLIDATED STATEMENTS OF OPERATIONS(In millions, except per share data)
| Line item | Year Ended July 31, 2026 | Year Ended July 31, 2025 | Year Ended July 31, 2024 |
|---|---|---|---|
| Revenue: | |||
| Product | $2,280 | $1,802 | $1,603 |
| Subscription and support | 9,200 | 7,419 | 6,424 |
| Total revenue | |||
| Cost of revenue: | |||
| Product | 568 | 413 | 348 |
| Subscription and support | 2,835 | 2,038 | 1,711 |
| Total cost of revenue | |||
| Total gross profit | |||
| Operating expenses: | |||
| Research and development | |||
| Sales and marketing | 3,931 | 3,100 | 2,794 |
| General and administrative | |||
| Total operating expenses | |||
| Operating income | |||
| Other income (expense), net | () | ||
| Income before income taxes | |||
| Provision for (benefit from) income taxes | () | ||
| Net income | $307 | $1,134 | $2,578 |
| Net income per share, basic | |||
| Net income per share, diluted | |||
| Weighted-average shares used to compute net income per share, basic | |||
| Weighted-average shares used to compute net income per share, diluted |
See notes to consolidated financial statements.
- 63 -
PALO ALTO NETWORKS, INC.
CONSOLIDATED STATEMENTS OF COMPREHENSIVE INCOME(In millions)
| Line item | Year Ended July 31, 2026 | Year Ended July 31, 2025 | Year Ended July 31, 2024 |
|---|---|---|---|
| Net income | $307 | $1,134 | $2,578 |
| Other comprehensive income (loss), net of tax: | |||
| Change in unrealized gains (losses) on investments | () | ||
| Cash flow hedges: | |||
| Change in unrealized gains (losses) | () | ||
| Net realized (gains) losses reclassified into earnings | (55) | 1 | 12 |
| Net change on cash flow hedges | (46) | 31 | (7) |
| Change in fair value of convertible senior notes attributable to instrument-specific credit risk | (11) | — | — |
| Other comprehensive income (loss) | () | ||
| Comprehensive income |
See notes to consolidated financial statements.
- 64 -
PALO ALTO NETWORKS, INC.
CONSOLIDATED STATEMENTS OF STOCKHOLDERS’ EQUITY(In millions)
| Line item | Common Stock and Additional Paid-In CapitalShares | Common Stock and Additional Paid-In CapitalAmount | Accumulated Other Comprehensive Income (Loss) | Retained Earnings (Accumulated Deficit) | Total Stockholders’ Equity |
|---|---|---|---|---|---|
| Balance as of July 31, 2023 | 617 | $3,019 | $(43) | $(1,228) | $1,748 |
| Net Income | — | — | — | 2,578 | 2,578 |
| Other comprehensive income | — | — | 41 | — | |
| Issuance of common stock in connection with employee equity incentive plans | 18 | 297 | — | — | |
| Taxes paid related to net share settlement of equity awards | — | (26) | — | — | () |
| Share-based compensation for equity-based awards | — | 1,079 | — | — | |
| Reclassification of deferred compensation liability to (from) equity | — | (5) | — | — | (5) |
| Repurchase and retirement of common stock | (4) | (567) | — | — | () |
| Replacement awards related to business acquisitions | 1 | 27 | — | — | 27 |
| Settlement of convertible notes | 14 | (3) | — | — | () |
| Settlement of note hedges | (14) | — | — | — | — |
| Settlement of warrants | 18 | — | — | — | — |
| Balance as of July 31, 2024 | 650 | 3,821 | (2) | 1,350 | 5,169 |
| Net income | — | — | — | 1,134 | 1,134 |
| Other comprehensive income | — | — | 50 | — | |
| Issuance of common stock in connection with employee equity incentive plans | 18 | 370 | — | — | |
| Taxes paid related to net share settlement of equity awards | — | (184) | — | — | () |
| Share-based compensation for equity-based awards | — | 1,314 | — | — | |
| Reclassification of deferred compensation liability to (from) equity | — | (32) | — | — | (32) |
| Repurchase and retirement of common stock | — | — | — | — | |
| Replacement awards related to business acquisitions | — | 3 | — | — | 3 |
| Settlement of convertible notes | 14 | — | — | — | — |
| Settlement of note hedges | (14) | — | — | — | — |
| Balance as of July 31, 2025 | 668 | 5,292 | 48 | 2,484 | 7,824 |
| Net income | — | — | — | 307 | 307 |
| Other comprehensive loss | — | — | (119) | — | () |
| Issuance of common stock in connection with employee equity incentive plans | 13 | 292 | — | — | |
| Taxes paid related to net share settlement of equity awards | — | (126) | — | — | () |
| Share-based compensation for equity-based awards | — | 1,787 | — | — | |
| Reclassification of deferred compensation liability to (from) equity | — | (335) | — | — | (335) |
| Repurchase and retirement of common stock | (7) | (1,000) | — | — | () |
| Issuance of common stock in connection with business acquisition | 112 | 18,488 | — | — | 18,488 |
| Replacement awards related to business acquisitions | 2 | 374 | — | — | 374 |
| Settlement of warrants | 27 | — | — | — | — |
| Balance as of July 31, 2026 | 815 | $24,772 | $(71) | $2,791 | $27,492 |
See notes to consolidated financial statements.
- 65 -
PALO ALTO NETWORKS, INC.
CONSOLIDATED STATEMENTS OF CASH FLOWS(In millions)
| Line item | Year Ended July 31, 2026 | Year Ended July 31, 2025 | Year Ended July 31, 2024 |
|---|---|---|---|
| Cash flows from operating activities | |||
| Net income | $307 | $1,134 | $2,578 |
| Adjustments to reconcile net income to net cash provided by operating activities: | |||
| Share-based compensation for equity-based awards | |||
| Deferred income taxes | () | () | () |
| Depreciation and amortization | 855 | 343 | 284 |
| Amortization of deferred contract costs | |||
| Amortization of debt issuance costs | |||
| Change in fair value of convertible senior notes and capped calls | 562 | — | — |
| Change in fair value of contingent consideration liability | () | () | |
| Reduction of operating lease right-of-use assets | |||
| Amortization of investment premiums, net of accretion of purchase discounts | () | () | () |
| Unrealized foreign currency exchange (gains) losses, net | 1 | — | — |
| Changes in operating assets and liabilities, net of effects of acquisitions: | |||
| Accounts receivable, net | () | () | () |
| Financing receivables, net | () | ||
| Deferred contract costs | () | () | () |
| Prepaid expenses and other assets | () | () | |
| Accounts payable | () | ||
| Accrued compensation | |||
| Accrued and other liabilities | |||
| Deferred revenue | |||
| Net cash provided by operating activities | |||
| Cash flows from investing activities | |||
| Purchases of investments | () | () | () |
| Proceeds from sales of investments | |||
| Proceeds from maturities of investments | |||
| Business acquisitions, net of cash and restricted cash acquired | () | () | () |
| Purchases of property, equipment, and other assets | () | () | () |
| Net cash used in investing activities | () | () | () |
| Cash flows from financing activities | |||
| Repayments and settlement of conversions of convertible senior notes | () | () | () |
| Proceeds from capped calls related to convertible senior notes | 10 | — | — |
| Repurchases of common stock | () | () | |
| Proceeds from sales of shares through employee equity incentive plans | |||
| Payments for taxes related to net share settlement of equity awards | () | () | () |
| Payments of contingent consideration liability | () | ||
| Net cash used in financing activities | () | () | () |
| Effect of exchange rate changes on cash, cash equivalents, and restricted cash | (3) | — | — |
| Net increase in cash, cash equivalents, and restricted cash | |||
| Cash, cash equivalents, and restricted cash—beginning of period | 2,279 | 1,547 | 1,142 |
| Cash, cash equivalents, and restricted cash—end of period | $2,523 | $2,279 | $1,547 |
| Reconciliation of cash, cash equivalents, and restricted cash to the consolidated balance sheets | |||
| Cash and cash equivalents | $2,514 | $2,269 | $1,535 |
| Restricted cash included in prepaid expenses and other current assets | 5 | 10 | 12 |
| Restricted cash included in other assets | 4 | — | — |
| Total cash, cash equivalents, and restricted cash | $2,523 | $2,279 | $1,547 |
| Non-cash investing and financing activities | |||
| Equity consideration for business acquisitions | $(18,862) | $(27) | $(27) |
| Contingent consideration for a business acquisition | $() | ||
| Supplemental disclosures of cash flow information | |||
| Cash paid for income taxes | |||
| Cash paid for contractual interest |
See notes to consolidated financial statements.
- 66 -
Notes to Consolidated Financial Statements
1. Description of Business and Summary of Significant Accounting Policies
Description of Business
Palo Alto Networks, Inc. (the “Company,” “we,” “us,” or “our”), headquartered in Santa Clara, California, was incorporated in March 2005 under the laws of the State of Delaware and commenced operations in April 2005. Our cybersecurity platforms and services help secure enterprise users, networks, clouds, endpoints, artificial intelligence (“AI”) apps and agents, and identities by delivering comprehensive cybersecurity backed by AI and automation.
On January 29, 2026, we acquired Chronosphere, Inc. (“Chronosphere”), a privately-held observability technology company, forming our next-generation observability platform. On February 11, 2026, we acquired CyberArk Software Ltd. (“CyberArk”), an identity security company, forming our next-generation identity security platform. The consolidated financial statements include the financial results of Chronosphere and CyberArk prospectively from the respective dates of acquisitions. Refer to Note 8. Acquisitions for more information regarding our acquisitions of Chronosphere and CyberArk.
Basis of Presentation
The accompanying consolidated financial statements have been prepared in conformity with U.S. generally accepted accounting principles (“U.S. GAAP”). The consolidated financial statements include all adjustments necessary for a fair presentation of our annual results. All adjustments are of a normal recurring nature.
Principles of Consolidation
The consolidated financial statements include our accounts and our wholly owned subsidiaries. All significant intercompany balances and transactions have been eliminated in consolidation.
Reclassification
Certain prior period amounts in the consolidated financial statements and accompanying notes have been reclassified to conform to the current presentation.
Use of Estimates
The preparation of consolidated financial statements in conformity with U.S. GAAP requires management to make estimates and assumptions that affect the amounts reported and disclosed in the consolidated financial statements and the accompanying notes. We evaluate our estimates on an ongoing basis. Management estimates include, but are not limited to, the standalone selling price for our products and services, share-based compensation, fair value of assets acquired and liabilities assumed in business combinations, fair value of our contingent consideration liability, fair value of our capped call transactions (“Capped Calls”), the assessment of recoverability of our intangibles and goodwill, valuation allowance against deferred tax assets, and loss contingencies. We base our estimates on assumptions, both historical and forward looking, that we believe are reasonable. Actual results could differ materially from those estimates due to risks and uncertainties.
Stock Split
On December 12, 2024, we effected a two-for-one stock split of our outstanding shares of common stock through an amendment to our restated certificate of incorporation (“Stock Split”), which also effected a proportionate increase in the number of authorized shares of our common stock from 1.0 billion to 2.0 billion. The par value per share of our common stock remains unchanged at per share after the Stock Split. All references made to share or per share amounts related to our common stock have been retroactively adjusted on the accompanying consolidated financial statements and applicable disclosures to reflect the effects of the Stock Split.
Concentrations of Risks
Financial instruments that subject us to concentrations of credit risk consist primarily of cash and cash equivalents, investments, derivative contracts, accounts receivable, and financing receivables.
We invest only in high-quality credit instruments and our cash and cash equivalents and available-for-sale investments consist primarily of fixed income securities held at large, diverse financial institutions to reduce the credit risk exposure to any single financial institution. Deposits held with banks may exceed the amount of insurance provided on such deposits.
- 67 -
Our derivative contracts expose us to credit risk to the extent that the counterparties are unable to meet the terms of the arrangement. We mitigate credit risk by transacting with multiple major financial institutions with high credit ratings and also enter into master netting arrangements, which permit net settlement of transactions with the same counterparty. We are not required to pledge, and are not entitled to receive, cash collateral related to these derivative instruments. We do not enter into derivative contracts for trading or speculative purposes.
Our accounts receivable are primarily derived from our distributors in various geographical locations. Our financing receivables are with qualified end-customers and channel partners. We perform ongoing credit evaluations and generally do not require collateral on accounts receivable or financing receivables.
As of July 31, 2026, one distributor individually represented 19% of our gross accounts receivable. As of July 31, 2026, no end-customers or channel partners represented 10% or more of our gross financing receivables.
For fiscal 2026, two distributors represented 10% or more of our total revenue, representing 15% and 15%, respectively. No single end-customer accounted for more than 10% of our total revenue in fiscal 2026, 2025, or 2024.
We rely on an electronics manufacturing services provider (“EMS provider”) to assemble most of our products and sole source component suppliers for certain components.
Comprehensive Income
Comprehensive income is comprised of net income and other comprehensive income. Our other comprehensive income includes unrealized gains and losses on available-for-sale investments, unrealized gains and losses on cash flow hedges, and change in fair value of convertible senior notes attributable to instrument-specific credit risk, net of tax effects.
Foreign Currency Transactions
The functional currency of our foreign subsidiaries is the U.S. dollar. Monetary assets and liabilities denominated in foreign currencies have been remeasured into U.S. dollars using the exchange rates in effect at the balance sheet dates. Foreign currency remeasurement gains and losses and foreign currency transaction gains and losses are not significant to the consolidated financial statements.
Fair Value
We define fair value as the price that would be received from selling an asset or paid to transfer a liability in an orderly transaction between market participants at the measurement date. When determining the fair value measurements for assets and liabilities which are required to be recorded at fair value, we consider the principal or most advantageous market in which to transact and the market-based risk.
We categorize assets and liabilities recorded or disclosed at fair value on our consolidated balance sheets based upon the level of judgment associated with inputs used to measure their fair value. The categories are as follows:
- Level 1—Inputs are unadjusted quoted prices in active markets for identical assets or liabilities.
- Level 2—Inputs are quoted prices for similar assets and liabilities in active markets or inputs that are observable for the assets or liabilities, either directly or indirectly through market corroboration, for substantially the full term of the financial instruments.
- Level 3—Inputs are unobservable inputs based on our own assumptions used to measure assets and liabilities at fair value. The inputs require significant management judgment or estimation.
Our financial assets and liabilities that are measured at fair value on a recurring basis include marketable securities, derivative financial instruments, Capped Calls related to convertible senior notes, deferred compensation liability, contingent consideration liability, and convertible senior notes. Goodwill, intangible assets, and other long-lived assets are measured at fair value on a nonrecurring basis, only if impairment is indicated. Certain certificates of deposit, time deposits, and overnight sweep accounts recorded in cash and cash equivalents and short-term investments are stated at their carrying amounts, which approximate fair value due to their short maturities. The carrying amounts of accounts receivable, accounts payable, and accrued liabilities approximate fair value due to their short-term nature.
Cash, Cash Equivalents, and Investments
We consider all highly liquid investments with original maturities of three months or less at the date of purchase to be cash equivalents. Investments not considered cash equivalents and with maturities of one year or less from the consolidated balance sheet date are classified as short-term investments. Investments with maturities greater than one year from the consolidated balance sheet date are classified as long-term investments.
- 68 -
We determine the classification of our investments in marketable debt securities at the time of purchase and reevaluate such determination at each balance sheet date. Our marketable debt securities are classified as available-for-sale. Debt securities in an unrealized loss position are written down to its fair value with the corresponding charge recorded in other income (expense), net on our consolidated statements of operations, if it is more likely than not that we will be required to sell the impaired security before recovery of its amortized cost basis, or we have the intention to sell the security. If neither of these conditions are met, we determine whether a credit loss exists by comparing the present value of the expected cash flows of the security with its amortized cost basis. An allowance for credit losses is recorded in other income (expense), net on our consolidated statements of operations for an amount not to exceed the unrealized loss. Unrealized losses that are not credit-related are included in AOCI in stockholders’ equity.
Accounts Receivable
Trade accounts receivable are recorded at the invoiced amount, net of allowances for credit losses. The allowance for credit losses is based on our assessment of collectability. Management regularly reviews the adequacy of the allowance for credit losses on a collective basis by considering the age of each outstanding invoice, each customer’s expected ability to pay and collection history, current market conditions, and, where appropriate, reasonable and supportable forecasts of future economic conditions. Accounts receivable deemed uncollectible are charged against the allowance for credit losses. For the years ended July 31, 2026, 2025 and 2024, the allowance for credit losses activity was not significant.
Financing Receivables
We provide financing arrangements for certain qualified end-customers and channel partners to purchase our products and services. Payment terms on these financing arrangements are generally two to five years. Financing receivables are recorded at amortized cost, which approximates fair value. As part of our financing credit risk management policy, we may sell financing receivables with an internal risk rating of 5 or greater on a non-recourse basis to third-party financial institutions when the outstanding balance of our financing receivables exceeds pre-established thresholds. The financing receivables are derecognized upon sale as these transactions qualify as true sales. We classify the proceeds from these sales as cash flows from operating activities on our consolidated statements of cash flows.
We evaluate the allowance for credit losses by assessing the risks and losses inherent in our financing receivables on either an individual or a collective basis. Our assessment considers various factors, including lifetime expected losses determined using customer risk profile, current economic conditions that may affect a customer’s ability to pay, and forward-looking economic considerations. Financing receivables deemed uncollectible are charged against the allowance for credit losses.
Derivatives
We are exposed to foreign currency exchange risk, which we manage through the use of derivative financial instruments. Our derivative financial instruments are recorded at fair value, on a gross basis, as either assets or liabilities on our consolidated balance sheets.
Our sales contracts are primarily denominated in U.S. dollars. A portion of our operating expenditures are denominated in foreign currencies, making them subject to fluctuations in foreign currency exchange rates. We enter into foreign currency derivative contracts with maturities of 24 months or less, which we designate as cash flow hedges, to manage the foreign currency exchange risk associated with our revenue and operating expenditures. Gains and losses related to the effective portion of our cash flow hedges are recorded as a component of AOCI on our consolidated balance sheets and are reclassified into the financial statement line item associated with the underlying hedged transaction on our consolidated statements of operations when the underlying hedged transaction is recognized in earnings. In the event the underlying hedged transaction does not occur, or it becomes probable that it will not occur within the defined hedge period, the gains or losses on the related cash flow hedges are recognized in other income (expense), net on our consolidated statements of operations. Cash flows from foreign currency derivative contracts designated as cash flow hedges are classified on our consolidated statements of cash flows in the same manner as the underlying hedged transaction, primarily within cash flows from operating activities.
We also enter into foreign currency derivative contracts to hedge a portion of our outstanding monetary assets and liabilities denominated in foreign currencies. These derivatives are not designated as hedging instruments for accounting purposes, and the related gains and losses are recorded in other income (expense), net on our consolidated statements of operations.
Inventory and Manufacturing Partner and Supplier Liabilities
Inventory consists primarily of raw materials and service-related spares, and is stated at the lower of average cost and net realizable value. Inventory is included in prepaid expenses and other current assets on our consolidated balance sheets. Inventory that is obsolete or in excess of forecasted demand is written down to its estimated realizable value. Once inventory has been written down, a new, lower-cost basis for that inventory is established.
- 69 -
We outsource most of our manufacturing, repair, and supply chain management operations to our EMS provider and payments to it are a significant portion of our cost of product revenue. Although we are contractually obligated to purchase manufactured products and components, we generally do not own the components and manufactured products. Product title transfers from our EMS provider to us and immediately to our customers upon shipment. We record a liability for manufacturing purchase commitments in excess of our forecasted demand.
We use consistent demand forecasts for our valuation of excess and obsolete inventory and manufacturing partner and supplier liabilities. These forecasts are based upon historical trends and analysis, adjusted for overall market conditions. Inventory write-downs and excess manufacturing purchase commitment charges are included in cost of product revenue on our consolidated statements of operations.
Property and Equipment
Property and equipment are stated at cost, less accumulated depreciation. Depreciation is computed using the straight-line method over the estimated useful lives of the assets. Land is not depreciated. The estimated useful lives of our depreciable assets are as follows:
| Asset category | Useful life |
|---|---|
| Computers, equipment, and software | 3 years - 5 years |
| Demonstration units | 4 years |
| Furniture and fixtures | 5 years |
| Leasehold improvements | Lesser of 10 years or remaining lease term |
Business Combinations
We include the results of operations of the businesses that we acquire as of the respective dates of acquisition. We allocate the fair value of the purchase price of our acquisitions to the assets acquired and liabilities assumed, including contingent consideration, generally based on their estimated fair values. The excess of the purchase price over the fair values of these identifiable assets and liabilities is recorded as goodwill. Additional information existing as of the acquisition date but unknown to us may become known during the remainder of the measurement period, not to exceed 12 months from the acquisition date, which may result in changes to the amounts and allocations recorded.
A contingent consideration obligation incurred in connection with a business combination is recorded at fair value on the acquisition date and remeasured at each subsequent reporting period until the related contingencies have been resolved, with the change in fair value recognized in general and administrative expense on our consolidated statements of operations. Payments not made soon after the acquisition date to settle a contingent consideration liability are classified as cash flows from financing activities up to the amount of the contingent consideration liability recognized at the acquisition date.
Intangible Assets
Purchased intangible assets with finite lives are carried at cost, less accumulated amortization. Amortization is computed using the straight-line method over the estimated useful lives of the assets.
Impairment of Goodwill, Intangible Assets, and Other Long-Lived Assets
Goodwill is evaluated for impairment on an annual basis in the fourth quarter of our fiscal year, and whenever events or changes in circumstances indicate the carrying amount of goodwill may not be recoverable. We have elected to first assess qualitative factors to determine whether it is more likely than not that the fair value of our single reporting unit is less than its carrying amount, including goodwill. If we determine that it is more likely than not that the fair value is less than its carrying amount, then the quantitative impairment test will be performed. Under the quantitative impairment test, if the carrying amount exceeds its fair value, we will recognize an impairment loss in an amount equal to that excess but limited to the total amount of goodwill.
We evaluate events and changes in circumstances that could indicate carrying amounts of purchased intangible assets and other long-lived assets may not be recoverable. When such events or changes in circumstances occur, we assess the recoverability of an asset or asset group by determining whether or not the carrying amount will be recovered through undiscounted expected future cash flows. If the total of the future undiscounted cash flows is less than the carrying amount of an asset or asset group, we record an impairment loss for the amount by which the carrying amount exceeds the fair value of the asset or asset group.
We did recognize any impairment losses on our goodwill, intangible assets, or other long-lived assets during the years ended July 31, 2026, 2025, and 2024.
Convertible Senior Notes and Capped Calls
Our convertible senior notes issued in June 2020 were fully settled upon maturity as of July 31, 2025. Prior to settlement, these convertible senior notes were accounted for as a liability and measured at their amortized cost. Transaction costs related to the issuance of the notes were netted with the liability and were amortized on a straight-line basis, which approximates the effective interest rate method, to other income (expense), net over the term of the notes.
- 70 -
In connection with the CyberArk acquisition, we acquired CyberArk’s convertible senior notes and assumed certain Capped Calls that CyberArk had previously entered into relating to the issuance of these convertible senior notes. The Capped Calls are expected to reduce the potential dilution to our common stock upon conversion of the convertible senior notes and/or offset our cash payments in excess of the principal amount of converted notes, as the case may be, with such reduction and/or offset subject to a cap.
For the convertible senior notes acquired from CyberArk, we have elected the fair value option to simplify the accounting for embedded features that would otherwise require bifurcation from the debt-host and recognition as a separate derivative liability. These convertible senior notes are measured at fair value on a recurring basis through maturity or settlement. Changes in fair value included in earnings are recorded in other income (expense), net on our consolidated statements of operations, and changes in fair value attributable to instrument-specific credit risk are included in AOCI in our consolidated statements of stockholders’ equity.
We account for Capped Calls as derivative assets, measured at fair value on a recurring basis through maturity or settlement. Capped Calls are recorded in other assets on our consolidated balance sheets. Changes in fair value are recorded in other income (expense), net on our consolidated statements of operations.
Revenue Recognition
Our revenue consists of product revenue and subscription and support revenue. Revenue is recognized when control of promised products, subscriptions and support services are transferred to customers, in an amount that reflects the expected consideration in exchange for those products and services.
We determine revenue recognition through the following steps:
- Identification of the contract, or contracts, with a customer.
- Identification of the performance obligations in the contract.
- Determination of the transaction price.
- Allocation of the transaction price to the performance obligations in the contract.
- Recognition of revenue when, or as, we satisfy a performance obligation.
Revenues are reported net of sales taxes. Shipping charges billed to our customers are included in revenue and related costs are included in cost of revenue.
Product Revenue
Product revenue is derived from sales of our hardware products and software licenses. Our hardware products and software licenses include a broad set of built-in networking and security features and functionalities. We recognize product revenue at the time of hardware shipment or delivery of software license.
Subscription and Support Revenue
Subscription and support revenue is derived primarily from sales of our subscription and support offerings. We recognize subscription and support revenue over time as the services are performed. Our contractual subscription and support contracts are typically one to five years.
Contracts with Multiple Performance Obligations
The majority of our contracts with our customers include various combinations of our products and subscriptions and support. Our hardware products and software licenses are distinct from our subscriptions and support services as the customer can benefit from the product without these services and such services are separately identifiable within the contract. We account for multiple agreements with a single customer as a single contract if the contractual terms and/or substance of those agreements indicate that they may be so closely related that they are, in effect, parts of a single contract. The amount of consideration we expect to receive in exchange for delivering on the contract is allocated to each performance obligation based on its relative standalone selling price.
When estimating standalone selling price, we first consider the prices charged for a deliverable when sold separately. If the standalone selling price is not observable through past transactions, we estimate it based on our pricing model and our go-to-market strategy, which include factors such as type of sales channel (channel partner or end-customer), the geographies in which our offerings were sold (domestic or international), and offering type (products, subscriptions, or support).
Deferred Revenue
We record deferred revenue when customers are invoiced or cash payments are received in advance of our performance. Our payment terms typically require payment within 30 to 75 days of the date we issue an invoice. The current portion of deferred revenue represents the amounts that are expected to be recognized as revenue within one year of the consolidated balance sheet date.
- 71 -
Deferred Contract Costs
We defer contract costs that are recoverable and incremental to obtaining customer sales contracts. Contract costs, which primarily consist of sales commissions, are amortized on a systematic basis that is consistent with the transfer to the customer of the goods or services to which the asset relates. We determine whether sales commissions for initial contracts are commensurate with the commissions for renewal contracts based on whether there is a substantive difference in commission rates in proportion to their respective contract values. Sales commissions for initial contracts that are commensurate and sales commissions for renewal contracts are amortized over the related contractual period. Sales commissions for initial contracts that are not commensurate are amortized over a benefit period of five years. The benefit period is determined by taking into consideration contract length, expected renewals, technology life, and other quantitative and qualitative factors.
We classify deferred contract costs as short-term or long-term based on when we expect to recognize the expense. The amortization of deferred contract costs is included in sales and marketing expense on our consolidated statements of operations. Deferred contract costs are periodically reviewed for impairment. We did not recognize any impairment losses on our deferred contract costs during the years ended July 31, 2026, 2025, or 2024.
Software Development Costs
Internally developed software includes security software developed to deliver our cloud-based subscription offerings to our end-customers. We capitalize internal compensation-related costs and external direct costs incurred during the application development stage and amortize these costs over a useful life of three years. As of July 31, 2026 and 2025, we capitalized as other assets on our consolidated balance sheets $266 million and $167 million in costs, respectively, net of accumulated amortization, for security software developed to deliver our cloud-based subscription offerings. We recognized amortization expense of $104 million, $83 million, and $78 million related to these capitalized costs as cost of subscription and support revenue on our consolidated statements of operations during the years ended July 31, 2026, 2025, and 2024, respectively.
The costs to develop software that is marketed externally have not been capitalized as we believe our current software development process is essentially completed concurrent with the establishment of technological feasibility. As such, all related software development costs are expensed as incurred and included in research and development expense on our consolidated statements of operations.
Share-Based Compensation
Compensation expense related to share-based transactions is measured at fair value on the grant date. We recognize share-based compensation expense for awards with only service conditions on a straight-line basis over the requisite service period. We recognize share-based compensation expense for awards with market conditions and awards with performance conditions on a straight-line basis over the requisite service period for each separately vesting tranche of the award. We recognize share-based compensation expense for awards with performance conditions when it is probable that the performance condition will be achieved. We account for forfeitures of all share-based payment awards when they occur.
Deferred Compensation Plan
We maintain an unfunded nonqualified deferred compensation plan that allows eligible employees to defer a portion of their base salary, bonus, commissions, and vested equity awards which are settled in shares of our common stock. Participants may elect to diversify a portion of their deferred compensation into certain investment funds. Amounts diversified are accounted for as liability-classified awards and are recorded in accrued compensation and other long-term liabilities on our consolidated balance sheets based on the timing of expected distributions. Liability-classified awards are measured at fair value on a recurring basis through distribution with changes in fair value recorded as share-based compensation.
Leases
We determine if an arrangement is a lease at inception. We evaluate the classification of leases at commencement and, as necessary, at modification. Operating lease related balances are included in operating lease right-of-use assets, accrued and other liabilities, and long-term operating lease liabilities on our consolidated balance sheets. We did not have any material finance leases in any of the periods presented.
Operating lease right-of-use assets represent our right to use an underlying asset for the lease term. Operating lease liabilities represent our obligation to make payments arising from the lease. Operating lease right-of-use assets and liabilities are recognized at the present value of the future lease payments at the lease commencement date. The interest rate used to determine the present value of the future lease payments is our incremental borrowing rate, because the interest rates implicit in our leases are not readily determinable. Our incremental borrowing rate is estimated to approximate the interest rate on a collateralized basis with similar terms and payments, and in similar economic environments. Operating lease right-of-use assets also include adjustments related to lease incentives, prepaid or accrued rent and initial direct lease costs. Operating lease right-of-use assets are subject to evaluation for impairment or disposal on a basis consistent with other long-lived assets.
- 72 -
Our lease terms may include periods under options to extend or terminate the lease when it is reasonably certain that we will exercise that option. We generally use the base, non-cancelable lease term when determining our operating lease right-of-use assets and lease liabilities. Operating lease costs are recognized on a straight-line basis over the lease term.
We account for lease and non-lease components as a single lease component and do not recognize right-of-use assets and lease liabilities for leases with a term of 12 months or less. Payments under our lease arrangements are primarily fixed, however, certain lease agreements contain variable payments, which are expensed as incurred and not included in operating lease right-of-use assets and liabilities. Our variable lease payments primarily consist of real estate taxes, common area maintenance charges, and insurance costs.
Income Taxes
We account for income taxes using the asset and liability method, which requires the recognition of deferred tax assets and liabilities for the expected future tax consequences of events that have been recognized in our consolidated financial statements or tax returns. In addition, deferred tax assets are recorded for all future benefits including, but not limited to, net operating losses, research and development credit carryforwards, and basis differences relating to our global intangible low-taxed income. Valuation allowances are provided when necessary to reduce deferred tax assets to the amount more likely than not to be realized.
Significant judgment is required in determining any valuation allowance recorded against deferred tax assets. In assessing the need for a valuation allowance, we consider all available evidence, including past operating results, estimates of future taxable income, and the feasibility of tax planning strategies. In the event that we change our determination as to the amount of deferred tax assets that can be realized, we will adjust our valuation allowance with a corresponding impact to the provision for income taxes in the period in which such determination is made.
We recognize liabilities for uncertain tax positions based on a two-step process which includes evaluating if a tax position is more likely than not to be sustained on audit and then measuring the tax benefit as the largest amount that is more likely than not to be realized upon ultimate settlement.
Loss Contingencies
We are subject to the possibility of various loss contingencies arising in the ordinary course of business. In determining loss contingencies, we consider the likelihood of loss or impairment of an asset, or the incurrence of a liability, as well as our ability to reasonably estimate the amount of loss. An estimated loss contingency is accrued when it is probable that an asset has been impaired or a liability has been incurred and the amount of loss can be reasonably estimated. If we determine that a loss is reasonably possible, then we disclose the possible loss or range of the possible loss or state that such an estimate cannot be made. We regularly evaluate current information available to us to determine whether an accrual is required, an accrual should be adjusted, or a range of possible loss should be disclosed.
Recently Adopted Accounting Pronouncements
Income Tax Disclosures
In December 2023, the Financial Accounting Standards Board (“FASB”) issued authoritative guidance that requires consistent categories and greater disaggregation of information in the effective tax rate reconciliation and additional disclosures of income taxes paid by jurisdiction. We adopted this standard for the year ended July 31, 2026 on a prospective basis. The adoption of this standard results in disclosure of additional jurisdictional level tax information in our consolidated financial statements. Refer to Note 16. Income Taxes for more details.
Government Grants Received by Business Entities
In December 2025, the FASB issued authoritative guidance that establishes the accounting for government grants received by business entities. We early adopted this standard in our fiscal 2026 on a modified prospective basis. The adoption of this standard did not have a material impact on our consolidated financial statements for the year ended July 31, 2026.
Recently Issued Accounting Pronouncements
Expense Disaggregation Disclosures
In November 2024, the FASB issued authoritative guidance that expands annual and interim disclosure of specified information about certain costs and expenses in the notes to financial statements. The standard is effective for our annual periods beginning in fiscal 2028 and interim periods beginning in our first quarter of fiscal 2029, and can be applied either prospectively or retrospectively. Early adoption is permitted. We are currently evaluating the impact of this standard on our disclosures in the consolidated financial statements.
Measurement of Credit Losses for Accounts Receivable and Contract Assets
In July 2025, the FASB issued authoritative guidance that provides a practical expedient for estimating expected credit losses on accounts receivable and contract assets. We plan to adopt this standard beginning in our first quarter of fiscal 2027 and do not expect the adoption of this standard to have a material impact on our consolidated financial statements.
- 73 -
Accounting for Internal-Use Software
In September 2025, the FASB issued authoritative guidance that modernizes the accounting for internal-use software by eliminating project stage-based capitalization and clarifying the requirements, including probable-to-complete threshold, to commence the capitalization of software development costs. The standard is effective for our annual and interim periods beginning in the first quarter of fiscal 2029 and can be applied either prospectively or retrospectively. Early adoption is permitted. We are currently evaluating the impact of this standard on our consolidated financial statements.
Hedge Accounting Improvements
In November 2025, the FASB issued authoritative guidance that clarifies and improves the existing hedge accounting guidance to better reflect the economics of an entity’s risk management activities. The standard is effective for our annual and interim periods beginning in the first quarter of fiscal 2028 and will be applied on a prospective basis. Early adoption is permitted. We are currently evaluating the impact of this standard on our consolidated financial statements.
2. Revenue
Disaggregation of Revenue
The following table presents revenue by geographic theater (in millions):
| Line item | Year Ended July 31, 2026 | Year Ended July 31, 2025 | Year Ended July 31, 2024 |
|---|---|---|---|
| Revenue: | |||
| Americas | |||
| United States | $7,108 | $5,786 | $5,134 |
| Other Americas | 571 | 419 | 349 |
| Total Americas | 7,679 | 6,205 | 5,483 |
| Europe, the Middle East, and Africa (“EMEA”) | 2,428 | 1,917 | 1,602 |
| Asia Pacific and Japan (“APAC”) | 1,373 | 1,099 | 942 |
| Total revenue |
The following table presents revenue for groups of similar products and services (in millions):
| Line item | Year Ended July 31, 2026 | Year Ended July 31, 2025 | Year Ended July 31, 2024 |
|---|---|---|---|
| Revenue: | |||
| Product | $2,280 | $1,802 | $1,603 |
| Subscription and support | |||
| Subscription | 6,239 | 4,974 | 4,188 |
| Support | 2,961 | 2,445 | 2,236 |
| Total subscription and support | 9,200 | 7,419 | 6,424 |
| Total revenue |
Deferred Revenue
During the years ended July 31, 2026 and 2025, we recognized approximately $6.2 billion and $5.5 billion of revenue pertaining to amounts that were deferred as of July 31, 2025 and 2024, respectively.
Remaining Performance Obligations
Remaining performance obligations were billion as of July 31, 2026, of which we expect to recognize as revenue approximately $9.3 billion over the next 12 months and the remainder thereafter.
- 74 -
3. Fair Value Measurements
The following table presents our financial assets and liabilities measured at fair value on a recurring basis as of July 31, 2026 and 2025 (in millions):
| Line item | July 31, 2026Level 1 | July 31, 2026Level 2 | July 31, 2026Level 3 | July 31, 2026Total | July 31, 2025Level 1 | July 31, 2025Level 2 | July 31, 2025Level 3 | July 31, 2025Total |
|---|---|---|---|---|---|---|---|---|
| Cash equivalents: | ||||||||
| Money market funds | $1,514 | — | — | $1,514 | $1,206 | — | — | $1,206 |
| Commercial paper | — | 123 | — | 123 | — | 169 | — | 169 |
| Total cash equivalents | 1,514 | 123 | — | 1,637 | 1,206 | 169 | — | 1,375 |
| Short-term investments: | ||||||||
| Commercial paper | — | 10 | — | 10 | — | 15 | — | 15 |
| Corporate debt securities | — | 374 | — | 374 | — | 584 | — | 584 |
| U.S. government and agency securities | — | 2 | — | 2 | — | 6 | — | 6 |
| Non-U.S. government and agency securities | — | — | — | — | — | 3 | — | 3 |
| Asset-backed securities | — | 6 | — | 6 | — | 22 | — | 22 |
| Total short-term investments | — | 392 | — | 392 | — | 630 | — | 630 |
| Long-term investments: | ||||||||
| Corporate debt securities | — | 3,843 | — | 3,843 | — | 4,050 | — | 4,050 |
| U.S. government and agency securities | — | 68 | — | 68 | — | 164 | — | 164 |
| Non-U.S. government and agency securities | — | 21 | — | 21 | — | 26 | — | 26 |
| Asset-backed securities | — | 903 | — | 903 | — | 1,315 | — | 1,315 |
| Total long-term investments | — | 4,835 | — | 4,835 | — | 5,555 | — | 5,555 |
| Prepaid expenses and other current assets: | ||||||||
| Foreign currency forward contracts | — | 18 | — | 18 | — | 58 | — | 58 |
| Total prepaid expenses and other current assets | — | 18 | — | — | 58 | — | ||
| Other assets: | ||||||||
| Foreign currency forward contracts | — | — | — | — | — | 3 | — | 3 |
| Capped calls related to convertible senior notes | — | 153 | — | — | — | — | ||
| Total other assets | — | 153 | — | — | 3 | — | ||
| Total assets measured at fair value | $1,514 | $5,521 | — | $7,035 | $1,206 | $6,415 | — | $7,621 |
- 75 -
| Line item | July 31, 2026Level 1 | July 31, 2026Level 2 | July 31, 2026Level 3 | July 31, 2026Total | July 31, 2025Level 1 | July 31, 2025Level 2 | July 31, 2025Level 3 | July 31, 2025Total |
|---|---|---|---|---|---|---|---|---|
| Accrued and other liabilities: | ||||||||
| Foreign currency forward contracts | — | $24 | — | $24 | — | $4 | — | $4 |
| Deferred compensation liability | 5 | — | — | 5 | 2 | — | — | 2 |
| Contingent consideration | — | — | 116 | 116 | — | — | 276 | 276 |
| Total accrued and other liabilities | 5 | 24 | 116 | 2 | 4 | 276 | ||
| Long-term convertible senior notes | — | 1,774 | — | — | — | — | ||
| Other long-term liabilities: | ||||||||
| Deferred compensation liability | 400 | — | — | 400 | 57 | — | — | 57 |
| Contingent consideration | — | — | 90 | 90 | — | — | 238 | 238 |
| Total other long-term liabilities | 400 | — | 90 | 57 | — | 238 | ||
| Total liabilities measured at fair value | $405 | $1,798 | $206 | $2,409 | $59 | $4 | $514 | $577 |
The fair value of our contingent consideration liability is estimated using a discounted cash flow valuation technique. We consider the fair value of our contingent consideration liability to be a Level 3 measurement as we use unobservable inputs in determining discounted cash flows to estimate the fair value. The significant unobservable inputs include an estimate of future cash payments related to customers entering into qualified new transactions as well as a risk-adjusted discount rate used to present value the expected cash flows. A significant change in any of these assumptions could have a material impact to the fair value of our contingent consideration liability.
In June 2025, we amended the terms of our contingent consideration arrangement with International Business Machines Corporation (“IBM”). During the three months ended July 31, 2025, we reduced our estimate of future cash payments based on the amended terms and our quarterly assessment of assumptions. During the year ended July 31, 2026, we reduced our estimate of future cash payments based on our quarterly assessment of assumptions. Assumptions considered during our quarterly assessment include the magnitude and likelihood of customers entering into qualified new transactions, the competitive industry environment, and current market conditions.
The following table presents a reconciliation of our contingent consideration liability (in millions):
| Line item | Year Ended July 31, 2026 | Year Ended July 31, 2025 |
|---|---|---|
| Contingent consideration liability at the beginning of the period | $514 | — |
| Initial valuation on the acquisition date | — | 649 |
| Change in fair value | () | () |
| Payments | (191) | — |
| Contingent consideration liability at the end of the period | $206 | $514 |
The total estimated fair value of our financing receivables approximates their carrying amounts as of July 31, 2026 and 2025. We consider the fair value of our financing receivables to be a Level 3 measurement as we use unobservable inputs in determining discounted cash flows to estimate the fair value.
- 76 -
4. Cash Equivalents and Investments
Available-for-sale Debt Securities
The following tables summarize the amortized cost, unrealized gains and losses, and fair value of our available-for-sale debt securities (in millions):
July 31, 2026
| Line item | Amortized Cost | Unrealized Gains | Unrealized Losses | Fair Value |
|---|---|---|---|---|
| Cash equivalents: | ||||
| Commercial paper | $123 | — | — | $123 |
| Total available-for-sale cash equivalents | $123 | — | — | $123 |
| Investments: | ||||
| Commercial paper | $10 | — | — | $10 |
| Corporate debt securities | 4,241 | 8 | (32) | 4,217 |
| U.S. government and agency securities | 70 | — | — | 70 |
| Non-U.S. government and agency securities | 21 | — | — | 21 |
| Asset-backed securities | 910 | 2 | (3) | 909 |
| Total available-for-sale investments | $5,252 | $10 | $(35) | $5,227 |
July 31, 2025
| Line item | Amortized Cost | Unrealized Gains | Unrealized Losses | Fair Value |
|---|---|---|---|---|
| Cash equivalents: | ||||
| Commercial paper | $169 | — | — | $169 |
| Total available-for-sale cash equivalents | $169 | — | — | $169 |
| Investments: | ||||
| Commercial paper | $15 | — | — | $15 |
| Corporate debt securities | 4,588 | 47 | (1) | 4,634 |
| U.S. government and agency securities | 170 | — | — | 170 |
| Non-U.S. government and agency securities | 29 | — | — | 29 |
| Asset-backed securities | 1,328 | 9 | — | 1,337 |
| Total available-for-sale investments | $6,130 | $56 | $(1) | $6,185 |
Unrealized losses related to our available-for-sale debt securities are primarily due to interest rate fluctuations as opposed to credit quality. We do not intend to sell any of the securities in an unrealized loss position and it is not likely that we would be required to sell these securities before recovery of their amortized cost basis, which may be at maturity. We did not recognize any credit losses related to our available-for-sale debt securities during the years ended July 31, 2026 and 2025.
The following table summarizes the amortized cost and fair value of our available-for-sale debt securities as of July 31, 2026, by contractual years-to-maturity (in millions):
| Line item | Amortized Cost | Fair Value |
|---|---|---|
| Due within one year | $514 | |
| Due between one and three years | ||
| Due between three and five years | ||
| Due between five and ten years | 143 | |
| Due after ten years | 159 | |
| Total |
- 77 -
Marketable Equity Securities
Marketable equity securities consist of money market funds and are included in cash and cash equivalents on our consolidated balance sheets. As of July 31, 2026 and 2025, the carrying values of our marketable equity securities were $1.5 billion and $1.2 billion, respectively. There were no unrealized gains or losses recognized for these securities during the years ended July 31, 2026, 2025, and 2024.
5. Financing Receivables
The following table summarizes our short-term and long-term financing receivables (in millions):
| Line item | July 31, 2026 | July 31, 2025 |
|---|---|---|
| Short-term financing receivables, gross | ||
| Unearned income | () | () |
| Allowance for credit losses | () | () |
| Short-term financing receivables, net | ||
| Long-term financing receivables, gross | $1,013 | $1,079 |
| Unearned income | () | () |
| Allowance for credit losses | () | () |
| Long-term financing receivables, net |
The following table presents amortized cost basis of our financing receivables categorized by internal risk rating and year of origination (in millions):
| Internal Risk Rating(1) | July 31, 2026Fiscal Years Ended July 31, 2026 | July 31, 2026Fiscal Years Ended July 31, 2025 | July 31, 2026Fiscal Years Ended July 31, 2024 | July 31, 2026Fiscal Years Ended July 31, 2023 | July 31, 2026Fiscal Years Ended July 31, 2022 | July 31, 2026Total | July 31, 2025Fiscal Years Ended July 31, 2025 | July 31, 2025Fiscal Years Ended July 31, 2024 | July 31, 2025Fiscal Years Ended July 31, 2023 | July 31, 2025Fiscal Years Ended July 31, 2022 | July 31, 2025Fiscal Years Ended July 31, 2021 | July 31, 2025Total |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1 to 4 | $411 | $208 | $438 | $102 | $5 | $1,164 | $261 | $732 | $242 | $9 | $18 | $1,262 |
| 5 to 6 | 156 | 92 | 85 | 9 | — | 342 | 174 | 226 | 50 | — | — | 450 |
| 7 to 10 | — | 32 | 10 | 1 | — | 43 | — | 4 | 14 | — | — | 18 |
| Amortized cost basis of financing receivables |
(1) Internal risk ratings are categorized as 1 through 10, with the lowest rating representing the highest quality.
During the years ended July 31, 2026 and 2025, we sold $54 million and $38 million, respectively, of our financing receivables. The associated gains and losses were not material.
There was no significant activity in allowance for credit losses during the years ended July 31, 2026 and 2025. Past due amounts on financing receivables were not material as of July 31, 2026 and 2025.
6. Derivative Instruments
As of July 31, 2026 and 2025, the notional amount of our outstanding foreign currency forward contracts designated as cash flow hedges was $1.7 billion and $964 million, respectively. Refer to Note 3. Fair Value Measurements for the fair value of our derivative instruments as reported on our consolidated balance sheets as of July 31, 2026 and 2025.
As of July 31, 2026, unrealized gains and losses in AOCI related to our cash flow hedges were a net loss of million, substantially all of which is expected to be recognized into earnings within the next 12 months. As of July 31, 2025, unrealized gains and losses in AOCI related to our cash flow hedges were a net gain of million.
As of July 31, 2026 and 2025, the notional amount of our outstanding foreign currency forward contracts not designated as hedging instruments was $522 million and $504 million, respectively.
7. Inventory
As of July 31, 2026 and 2025, our inventory balance was $117 million and $113 million, respectively.
For the years ended July 31, 2026, 2025, and 2024, inventory write-downs and excess manufacturing purchase commitment charges were million, million, and million, respectively.
- 78 -
8. Acquisitions
Fiscal 2026
Chronosphere, Inc.
On January 29, 2026, we completed our acquisition of Chronosphere, a privately-held observability technology company. The acquisition resulted in forming our next-generation observability platform. The total purchase consideration for the acquisition of Chronosphere was $3.0 billion, which consisted of the following (in millions):
| Line item | Amount | Amount |
|---|---|---|
| Cash | $2,842 | |
| Fair value of replacement awards | 109 | |
| Total | $2,951 |
As part of the acquisition, we issued $525 million of replacement equity awards, of which the portion attributable to services performed prior to the acquisition date was allocated to purchase consideration. The remaining fair value was allocated to future services and will be expensed over the remaining service periods as share-based compensation. The replacement equity awards included 2 million shares of our restricted common stock. These shares of restricted common stock vest over a period of two to three years from the date of issuance.
We have accounted for this transaction as a business combination and allocated the purchase consideration to assets acquired and liabilities assumed based on preliminary estimated fair values, as presented in the following table (in millions):
| Line item | Amount | Amount |
|---|---|---|
| Goodwill | $2,364 | |
| Identified intangible assets | 565 | |
| Cash | 57 | |
| Net liabilities assumed | (35) | |
| Total | $2,951 |
Goodwill generated from this business combination is primarily attributable to the assembled workforce and expected post-acquisition synergies from integrating the Chronosphere observability platform into our business. The goodwill is not deductible for U.S. income tax purposes.
The following table presents details of the identified intangible assets acquired (in millions, except years):
| Line item | Fair Value | Estimated Useful Life |
|---|---|---|
| Developed technology | $300 | 5 years |
| Customer relationships | 255 | 6 years - 10 years |
| Trade name and trademarks | 10 | 1 year |
| Total | $565 |
CyberArk Software Ltd.
On February 11, 2026, we completed our acquisition of CyberArk, an identity security company, forming our next-generation identity security platform. CyberArk shareholders received $45.00 in cash and 2.2005 shares of our common stock for each CyberArk share. The total purchase consideration for the acquisition of CyberArk was $21.1 billion, which consisted of the following (in millions):
| Line item | Amount | Amount |
|---|---|---|
| Cash | $2,308 | |
| Common stock (112 million shares) | 18,488 | |
| Fair value of replacement awards | 265 | |
| Total | $21,061 |
- 79 -
As part of the acquisition, we issued $945 million of replacement equity awards, of which the portion attributable to services performed prior to the acquisition date was allocated to purchase consideration. The remaining fair value was allocated to future services and will be expensed over the remaining service periods as share-based compensation.
We have accounted for this transaction as a business combination and allocated the purchase consideration to assets acquired and liabilities assumed based on preliminary estimated fair values, as presented in the following table (in millions):
| Line item | Amount | Amount |
|---|---|---|
| Goodwill | $14,800 | |
| Identified intangible assets | 6,279 | |
| Cash and cash equivalents | 743 | |
| Accounts receivable, net of allowance for credit losses | 312 | |
| Short-term and long-term investments | 1,217 | |
| Net assets acquired | 60 | |
| Convertible senior notes | (1,303) | |
| Deferred revenue | (776) | |
| Deferred tax liabilities | (271) | |
| Total | $21,061 |
Goodwill generated from this business combination is primarily attributable to the assembled workforce and expected post-acquisition synergies from incorporating the CyberArk next-generation identity security platform into our business. Substantially all of the goodwill is deductible for U.S. income tax purposes.
The following table presents details of the identified intangible assets acquired (in millions, except years):
| Line item | Fair Value | Estimated Useful Life |
|---|---|---|
| Developed technology | $2,537 | 5 years - 7 years |
| Platform renewals | 3,500 | 12 years - 14 years |
| Customer contracts | 219 | 2 years |
| Trade name | 23 | 1 year |
| Total | $6,279 |
For the year ended July 31, 2026, transaction costs related to CyberArk acquisition were $56 million, which were primarily included in general and administrative expense on our consolidated statements of operations.
In connection with our acquisition integration strategy, we initiated a plan to optimize the combined entity’s workforce for a total estimated cost of $60 million. The activities associated with this plan are expected to be substantially completed by the end of fiscal 2027. Employee severance costs are recognized upon notification. If service is required beyond the minimum retention period, expense is recognized ratably over the future service period. During the year ended July 31, 2026, we made cash payments of $18 million under the plan. As of July 31, 2026, a liability of $14 million related to employee severance was included in accrued compensation on our consolidated balance sheets.
The following table summarizes employee severance charges related to the CyberArk acquisition (in millions):
Year Ended July 31, 2026
| Line item | Cash Compensation | Share-based Compensation | Total |
|---|---|---|---|
| Cost of subscription and support revenue | $2 | — | $2 |
| Research and development | 1 | — | 1 |
| Sales and marketing | 16 | 16 | 32 |
| General and administrative | 13 | 1 | 14 |
| Total | $32 | $17 | $49 |
- 80 -
Koi Security Ltd.
On April 14, 2026, we completed our acquisition of Koi Security Ltd. (“Koi”), a privately-held endpoint posture management company. The acquisition adds agentic endpoint security capabilities to our security operations platform and enhances Prisma AIRS™. The total purchase consideration for the acquisition of Koi was $231 million, substantially all of which is comprised of cash.
As part of the acquisition, we issued $61 million of replacement equity awards, which were allocated to future services and will be expensed over the remaining service periods as share-based compensation. The replacement equity awards included 0.3 million shares of our restricted common stock. These shares of restricted common stock vest over a period of three years from the date of issuance.
We have accounted for this transaction as a business combination and allocated the purchase consideration to assets acquired and liabilities assumed based on preliminary estimated fair values, as presented in the following table (in millions):
| Line item | Amount | Amount |
|---|---|---|
| Goodwill | $169 | |
| Identified intangible asset | 35 | |
| Cash and restricted cash | 20 | |
| Net assets acquired | 7 | |
| Total | $231 |
Goodwill generated from this business combination is primarily attributable to the assembled workforce and expected post-acquisition synergies from integrating Koi’s technology into our platforms. The goodwill is deductible for U.S. income tax purposes.
The following table presents details of the identified intangible asset acquired (in millions, except years):
| Line item | Fair Value | Estimated Useful Life |
|---|---|---|
| Developed technology | $35 | 5 years |
Portkey, Inc.
On May 29, 2026, we completed our acquisition of Portkey, Inc. (“Portkey”), a privately-held AI Gateway company. The acquisition enhances the capabilities of Prisma AIRS™. The total purchase consideration for the acquisition of Portkey was $117 million, substantially all of which is comprised of cash.
As part of the acquisition, we issued $2 million of replacement equity awards, which were allocated to future services and will be expensed over the remaining service periods as share-based compensation.
We have accounted for this transaction as a business combination and allocated the purchase consideration to assets acquired and liabilities assumed based on preliminary estimated fair values, as presented in the following table (in millions):
| Line item | Amount | Amount |
|---|---|---|
| Goodwill | $110 | |
| Identified intangible assets | 15 | |
| Cash and cash equivalents | 17 | |
| Net liabilities assumed | (25) | |
| Total | $117 |
Goodwill generated from this business combination is primarily attributable to the assembled workforce and expected post-acquisition synergies from integrating Portkey ’s technology into our platforms. The goodwill is not deductible for U.S. income tax purposes.
The following table presents details of the identified intangible asset acquired (in millions, except years):
| Line item | Fair Value | Estimated Useful Life |
|---|---|---|
| Developed technology | $15 | 5 years |
- 81 -
Embrace Mobile, Inc.
On July 20, 2026, we entered into a definitive agreement to acquire Embrace Mobile, Inc. (“Embrace”), a privately-held user-focused observability company, in exchange for total consideration of $325 million in cash, subject to adjustments. We expect the acquisition to add high-fidelity Real User Monitoring (“RUM”) capabilities to our next-generation observability platform. Refer to Note 20. Subsequent Events for additional information.
Console Systems, Inc.
On July 29, 2026, we entered into a definitive agreement to acquire Console Systems, Inc. (“Console”), a privately-held company providing an AI-native platform that enables agentic workflows across enterprise operations, in exchange for total consideration of $500 million in cash, subject to adjustments. We expect the acquisition to deepen our agentic capabilities in Cortex. Refer to Note 20. Subsequent Events for additional information.
Additional Acquisition-Related Information
Since the date of acquisitions, the combined net impact of the Chronosphere and CyberArk acquisitions on our consolidated statements of operations was revenue of $930 million and operating loss of $797 million for the year ended July 31, 2026.
The following unaudited pro forma financial information summarizes the combined results of operations for Palo Alto Networks, Chronosphere, and CyberArk, as though the companies were combined as of the beginning of our fiscal 2025 (in millions):
| Line item | Year Ended July 31, 2026 | 2025 |
|---|---|---|
| Total revenue | $12,312 | $10,486 |
| Net loss | $(114) | $(37) |
The unaudited pro forma financial information for the years ended July 31, 2026 and 2025 combines the historical results of Palo Alto Networks and Chronosphere for these periods with the historical results of CyberArk for the years ended June 30, 2026 and 2025, respectively. The unaudited pro forma financial information include adjustments attributable to our acquisition of Chronosphere and CyberArk, including amortization of acquired intangible assets, share-based compensation expense from assumed replacement equity awards, acquisition-related transaction costs, employee severance costs under the workforce optimization plan, and income tax impact. We elected the fair value option to account for the convertible senior notes acquired from CyberArk. During the post-acquisition period presented, we recognized approximately $562 million of net losses related to changes in fair value of the convertible senior notes and Capped Calls. Such amounts are reflected in our historical post-acquisition results but are not included as adjustments to the historical periods presented in the unaudited pro forma financial information. The unaudited pro forma financial information is for informational purposes only and is not necessarily indicative of the results of operations that would have been achieved if the acquisitions had taken place at the beginning of our fiscal 2025 or of the results of our future operations of the combined business.
Additional information related to our fiscal 2026 acquisitions, such as that related to income tax and other contingencies existing as of the acquisition date, may become known during the remainder of the measurement period, not to exceed 12 months from the acquisition date, which may result in changes to the amounts and allocations recorded.
Fiscal 2025
IBM QRadar Assets
On August 31, 2024, we completed the acquisition of certain IBM QRadar assets, including certain intellectual property rights, customer relationships, and software as a service customer contracts. The total purchase consideration for the acquisition was $1.1 billion, which consisted of the following (in millions):
| Line item | Amount | Amount |
|---|---|---|
| Cash | $500 | |
| Fair value of contingent consideration liability on the acquisition date | 649 | |
| Return of purchase consideration | (6) | |
| Total | $1,143 |
- 82 -
As part of the acquisition, we agreed to make post-closing payments to IBM contingent upon customers entering into qualified new transactions through June 30, 2028. We also expect to receive a return of purchase consideration of $6 million due to timing of transition of certain underlying customer contracts, of which $2 million and $3 million were received during the years ended July 31, 2026 and 2025, respectively. In addition, we have entered into a transition services arrangement with IBM, under which IBM will perform certain services supporting the acquired assets and customers for a period of time that ends in the fiscal quarter ending October 31, 2026.
Payments related to the contingent consideration liability commenced in the fiscal quarter ended October 31, 2025 and are expected to continue through the fiscal quarter ending October 31, 2028. The estimated range of undiscounted contingent consideration is between $0.3 billion and $0.5 billion. Refer to Note 3. Fair Value Measurements, for more information on the fair value of our contingent consideration liability.
We have accounted for this transaction as a business combination and allocated the purchase consideration to assets acquired and liabilities assumed based on estimated fair values, as presented in the following table (in millions):
| Line item | Amount | Amount |
|---|---|---|
| Goodwill | $701 | |
| Identified intangible assets | 476 | |
| Net liabilities assumed | $(34) | |
| Total | $1,143 |
Goodwill generated from this business combination is primarily attributable to the expected post-acquisition synergies from increased market penetration to support the growth of our Cortex Security Operations business. The goodwill is deductible for U.S. income tax purposes.
The following table presents details of the identified intangible assets acquired (in millions, except years):
| Line item | Fair Value | Estimated Useful Life |
|---|---|---|
| Customer relationships | $464 | 12 years |
| Developed technology | 12 | 2 years |
| Total | $476 |
Protect AI, Inc.
On July 22, 2025, we completed our acquisition of Protect AI, Inc. (“Protect AI”), a privately-held cyber security company focused on AI security. The total purchase consideration for the acquisition of Protect AI was $635 million, which consisted of the following (in millions):
| Line item | Amount | Amount |
|---|---|---|
| Cash | $608 | |
| Fair value of replacement awards | 27 | |
| Total | $635 |
As part of the acquisition, we issued $107 million of replacement equity awards, of which the portion attributable to services performed prior to the acquisition date was allocated to purchase consideration. The remaining fair value was allocated to future services and will be expensed over the remaining service periods as share-based compensation.
We have accounted for this transaction as a business combination and allocated the purchase consideration to assets acquired and liabilities assumed based on estimated fair values, as presented in the following table (in millions):
| Line item | Amount | Amount |
|---|---|---|
| Goodwill | $516 | |
| Identified intangible assets | 70 | |
| Cash | 51 | |
| Net liabilities assumed | (2) | |
| Total | $635 |
- 83 -
Goodwill generated from this business combination is primarily attributable to the assembled workforce and expected post-acquisition synergies from integrating Protect AI technology into our platforms. The goodwill is not deductible for U.S. income tax purposes.
The following table presents details of the identified intangible asset acquired (in millions, except years):
| Line item | Fair Value | Estimated Useful Life |
|---|---|---|
| Developed technology | $70 | 5 years |
Fiscal 2024
Dig Security Solutions Ltd.
On December 5, 2023, we completed our acquisition of Dig Security Solutions Ltd. (“Dig”), a privately-held cyber security company providing a data security posture management solution for multi-cloud environments. The total purchase consideration for the acquisition of Dig was $255 million, which consisted of the following (in millions):
| Line item | Amount | Amount |
|---|---|---|
| Cash | $248 | |
| Fair value of replacement awards | 7 | |
| Total | $255 |
As part of the acquisition, we issued replacement equity awards, which included 0.4 million shares of our restricted common stock. The total fair value of the replacement equity awards was $72 million, of which the portion attributable to services performed prior to the acquisition date was allocated to purchase consideration. The remaining fair value was allocated to future services and will be expensed over the remaining service periods as share-based compensation.
We have accounted for this transaction as a business combination and allocated the purchase consideration to assets acquired and liabilities assumed based on estimated fair values, as presented in the following table (in millions):
| Line item | Amount | Amount |
|---|---|---|
| Goodwill | $186 | |
| Identified intangible assets | 45 | |
| Cash and restricted cash | 22 | |
| Net assets acquired | 2 | |
| Total | $255 |
Goodwill generated from this business combination is primarily attributable to the assembled workforce and expected post-acquisition synergies from integrating Dig technology into our platforms. The goodwill is deductible for U.S. income tax purposes.
The following table presents details of the identified intangible asset acquired (in millions, except years):
| Line item | Fair Value | Estimated Useful Life |
|---|---|---|
| Developed technology | $45 | 5 years |
- 84 -
Talon Cyber Security Ltd.
On December 28, 2023, we completed our acquisition of Talon Cyber Security Ltd. (“Talon”), a privately-held cyber security company providing a secure enterprise browser solution. The total purchase consideration for the acquisition of Talon was $459 million, which consisted of the following (in millions):
| Line item | Amount | Amount |
|---|---|---|
| Cash | $439 | |
| Fair value of replacement awards | 20 | |
| Total | $459 |
As part of the acquisition, we issued replacement equity awards, which included 0.6 million shares of our restricted common stock. The total fair value of the replacement equity awards was $110 million, of which the portion attributable to services performed prior to the acquisition date was allocated to purchase consideration. The remaining fair value was allocated to future services and will be expensed over the remaining service periods as share-based compensation.
We have accounted for this transaction as a business combination and allocated the purchase consideration to assets acquired and liabilities assumed based on estimated fair values, as presented in the following table (in millions):
| Line item | Amount | Amount |
|---|---|---|
| Goodwill | $237 | |
| Identified intangible assets | 132 | |
| Cash and restricted cash | 54 | |
| Net assets acquired | 36 | |
| Total | $459 |
Goodwill generated from this business combination is primarily attributable to the assembled workforce and expected post-acquisition synergies from integrating Talon technology into our platforms. The goodwill is deductible for U.S. income tax purposes.
The following table presents details of the identified intangible asset acquired (in millions, except years):
| Line item | Fair Value | Estimated Useful Life |
|---|---|---|
| Developed technology | $132 | 5 years |
9. Goodwill and Intangible Assets
Goodwill
The following table presents details of our goodwill during the year ended July 31, 2026 (in millions):
| Line item | Amount | Amount |
|---|---|---|
| Balance as of July 31, 2025 | ||
| Goodwill acquired | ||
| Balance as of July 31, 2026 |
- 85 -
Purchased Intangible Assets
The following table presents details of our purchased intangible assets (in millions):
| Line item | July 31, 2026Gross Carrying Amount | July 31, 2026Accumulated Amortization | July 31, 2026Net Carrying Amount | July 31, 2025Gross Carrying Amount | July 31, 2025Accumulated Amortization | July 31, 2025Net Carrying Amount |
|---|---|---|---|---|---|---|
| Intangible assets subject to amortization: | ||||||
| Developed technology | $3,402 | $(614) | $2,788 | $536 | $(274) | $262 |
| Customer relationships and platform renewals | 4,356 | (320) | 4,036 | 609 | (123) | 486 |
| Customer contracts | 219 | (55) | 164 | — | — | — |
| Acquired intellectual property | 24 | (12) | 12 | 24 | (9) | 15 |
| Trade name and trademarks | 33 | (16) | 17 | — | — | — |
| Other | — | — | — | 1 | (1) | — |
| Total purchased intangible assets | $() | $() |
The following table summarizes amortization expense of our intangible assets (in millions):
| Line item | Year Ended July 31, 2026 | Year Ended July 31, 2025 | 2024 |
|---|---|---|---|
| Cost of product revenue | $75 | — | — |
| Cost of subscription and support revenue | 343 | 111 | 98 |
| Sales and marketing | 222 | 55 | 22 |
| General and administrative | — | — | 1 |
| Total intangible assets amortization |
The following table summarizes estimated future amortization expense of our intangible assets subject to amortization as of July 31, 2026 (in millions):
| Line item | Fiscal years ending July 31, |
|---|---|
| Total | 2032 and Thereafter |
- 86 -
10. Property and Equipment
The following table presents details of our property and equipment, net (in millions):
| Line item | July 31, 2026 | July 31, 2025 |
|---|---|---|
| Computers, equipment, and software | $612 | $513 |
| Leasehold improvements | 366 | 325 |
| Land | 178 | 87 |
| Demonstration units | 49 | 47 |
| Furniture and fixtures | 65 | 54 |
| Total property and equipment, gross | ||
| Less: accumulated depreciation | (747) | (639) |
| Total property and equipment, net |
We recognized depreciation expense of million, million, and million related to property and equipment during the years ended July 31, 2026, 2025, and 2024, respectively.
During the year ended July 31, 2026, we purchased 14.5 acres of land adjacent to our headquarters in Santa Clara, California for $91 million to accommodate future expansion of our headquarters.
11. Debt
Convertible Senior Notes, Note Hedges, and Warrants
2025 Convertible Senior Notes
In June 2020, we issued $2.0 billion aggregate principal amount of 0.375% Convertible Senior Notes due 2025 (the “2025 Notes”). The 2025 Notes bear interest at a fixed rate of 0.375% per year, payable semi-annually in arrears on June 1 and December 1 of each year, beginning on December 1, 2020. The 2025 Notes were converted prior to or settled on the maturity date of June 1, 2025 in accordance with their terms.
The following table presents details of our 2025 Notes (number of shares in millions):
| Conversion Rate per $1,000 Principal | Initial Conversion Price | Convertible Date | Initial Number of Shares | |
|---|---|---|---|---|
| 2025 Notes | 20.1612 | $49.60 | March 1, 2025 | 40 |
Holders of the 2025 Notes were able to early convert their 2025 Notes in fiscal 2024 and fiscal 2025 up to March 1, 2025, and conversion requests received on or after March 1, 2025 were settled upon maturity of the 2025 Notes. During the years ended July 31, 2025 and 2024, we repaid in cash $966 million and $1.0 billion, respectively, in aggregate principal amount of the 2025 Notes. We also issued 14 million shares of our common stock to the holders of the 2025 Notes during each of the years ended July 31, 2025 and 2024, for the conversion value in excess of the principal amount. These shares were fully offset by shares we received from the corresponding exercise of the associated note hedges.
The following table sets forth interest expense recognized related to our 2025 Notes (dollars in millions):
| Line item | Year Ended July 31, 2025 | 2024 |
|---|---|---|
| Contractual interest expense | $2 | $5 |
| Amortization of debt issuance costs | 1 | 3 |
| Total interest expense recognized | $3 | $8 |
| Effective interest rate of the liability component | 0.6% | 0.6% |
2025 Note Hedges
To minimize the impact of potential economic dilution upon conversion of our 2025 Notes, we entered into separate convertible note hedge transactions (the “2025 Note Hedges”) with respect to our common stock concurrent with the issuance of the 2025 Notes.
- 87 -
The following table presents details of our Note Hedges (in millions):
| Initial Number of Shares | Aggregate Purchase | |
|---|---|---|
| 2025 Note Hedges | 40 | $371 |
The 2025 Note Hedges covered shares of our common stock at a strike price per share that corresponded to the initial conversion price of the 2025 Notes and were exercisable upon conversion of the 2025 Notes. The 2025 Note Hedges expired upon maturity of the 2025 Notes. The 2025 Note Hedges were separate transactions and were not part of the terms of the 2025 Notes. Holders of the 2025 Notes did not have any rights with respect to the 2025 Note Hedges. Any shares of our common stock that were receivable by us under the 2025 Note Hedges were excluded from the calculation of diluted earnings per share as they were antidilutive.
As a result of the conversions of the 2025 Notes during the years ended July 31, 2025 and 2024, we exercised the corresponding portion of our 2025 Note Hedges and received 14 million shares of our common stock during each of the respective periods.
2025 Warrants
Separately, but concurrently with the issuance of our 2025 Notes, we entered into transactions whereby we sold warrants (the “2025 Warrants”) to acquire shares of our common stock, subject to anti-dilution adjustments. The 2025 Warrants were exercisable over 60 scheduled trading days beginning September 2025.
The following table presents details of our 2025 Warrants (in millions, except per share data):
| Initial Number of Shares | Strike Price per Share | Aggregate Proceeds | |
|---|---|---|---|
| 2025 Warrants | 40 | $68.08 | $203 |
The shares that were issuable under the 2025 Warrants were included in the calculation of diluted earnings per share when the average market value per share of our common stock for the reporting period exceeded the strike price of the 2025 Warrants.
During the year ended July 31, 2026, we net settled all of the 2025 Warrants with the issuance of 27 million shares of our common stock with a fair value of $5.6 billion. The number of net shares issued was determined based on the number of 2025 Warrants exercised multiplied by the difference between the strike price of the 2025 Warrants and their daily volume-weighted-average stock price.
2030 Convertible Senior Notes and Capped Calls
2030 Convertible Senior Notes
In February 2026, in connection with the acquisition of CyberArk, we entered into a supplemental indenture (the “Supplemental Indenture”) to the Indenture, dated as of June 10, 2025 (together with the Supplemental Indenture, the “Indenture”), between CyberArk, as issuer, and U.S. Bank Trust Company, National Association, as trustee, governing CyberArk’s $1.25 billion aggregate principal amount of 0.0% Convertible Senior Notes due 2030 (the “2030 Notes”). As a result of our acquisition of CyberArk and pursuant to the Supplemental Indenture, the 2030 Notes are no longer convertible into ordinary shares of CyberArk. The conversion feature has been modified such that each $1,000 principal amount of the 2030 Notes are exchangeable for a combination of (i) approximately 4.3161 shares of our common stock, which is the effective initial conversion rate, and (ii) cash of $88.2630, subject to adjustment under the Indenture. These modifications result in the 2030 Notes being exchangeable initially for 5.4 million shares of our common stock with an effective initial conversion price of approximately $211.24 per share of common stock, subject to adjustments, and an initial cash amount of $110 million. The 2030 Notes are unsecured, unsubordinated obligations, and the Indenture does not contain any financial covenants or restrictions on the payments of dividends, the incurrence of indebtedness, or the issuance or repurchase of securities by us or any of our subsidiaries. The 2030 Notes mature on June 15, 2030.
We may redeem for cash all or, subject to certain limitations, any portion of the 2030 Notes, at our option, on or after June 20, 2028 and on or prior to the 31st scheduled trading day immediately preceding the maturity date if the last reported sale price of our common stock has been at least $280.75 per share for at least 20 trading days (whether or not consecutive) during any 30 consecutive trading day period ending on and including the trading day preceding the date on which we provide notice of redemption. Any redemption of the 2030 Notes will be at a price equal to 100% of the principal amount of the 2030 Notes, plus accrued and unpaid special interest, if any, up to, but excluding, the redemption date. If we call any or all of the 2030 Notes for redemption, holders may convert such 2030 Notes called for redemption at an increased conversion rate at any time prior to the close of business on the second scheduled trading day immediately preceding the redemption date.
- 88 -
Holders of the 2030 Notes may surrender their 2030 Notes for conversion at their option at any time prior to the close of business on the business day immediately preceding February 15, 2030 under the following circumstances:
- during any calendar quarter commencing after the calendar quarter ended on September 30, 2025 (and only during such calendar quarter), if the last reported sale price of our common stock is greater than or equal to $280.75 per share of our common stock on each applicable trading day for at least 20 trading days (whether or not consecutive) during the period of 30 consecutive trading days ending on the last trading day of the immediately preceding calendar quarter (the “sale price condition”);
- during the five business day period immediately after any ten consecutive trading day period (the “measurement period”) in which the trading price per $1,000 principal amount of the 2030 Notes for each trading day of the measurement period was less than 98% of the aggregate of (i) the product of the last reported sale price of our common stock on each such trading day and the conversion rate for the 2030 Notes on each such trading day and (ii) $88.2630; or
- upon the occurrence of specified corporate events as described in the Indenture.
On or after February 15, 2030, holders may surrender all or, subject to certain limitations, any portion of their 2030 Notes for conversion at any time prior to the close of business on the second scheduled trading day immediately preceding the maturity date, and such conversions will be settled upon the maturity date.
Upon any conversion of the 2030 Notes, holders of the 2030 Notes will receive cash equal to the aggregate principal amount of the 2030 Notes to be converted, and, at our election, cash or a combination of cash and shares of our common stock for any amounts in excess of the aggregate principal amount of the 2030 Notes converted. The conversion rate will be subject to adjustment in connection with certain events. Holders of the 2030 Notes who convert their 2030 Notes in connection with certain corporate events that constitute a “make-whole fundamental change” under the Indenture are, under certain circumstances, entitled to an increase in the conversion rate for a certain period of time. Additionally, following the occurrence of a corporate event that constitutes a “fundamental change” under the Indenture, holders of the 2030 Notes may require us to repurchase for cash all or a portion of the 2030 Notes at a repurchase price equal to 100% of the principal amount of the 2030 Notes plus accrued and unpaid special interest, if any, up to, but excluding, the fundamental change repurchase date.
Our acquisition of CyberArk constituted both a “make-whole fundamental change” and a “fundamental change” under the Indenture. In connection with the make-whole fundamental change, holders had the option to convert all or a portion of their 2030 Notes at an increased conversion rate equal to a combination of approximately 5.5690 shares of our common stock and $113.8860 in cash per $1,000 principal amount (the “make-whole conversion right”). We elected cash settlement as the settlement method for any 2030 Notes surrendered during the make-whole fundamental change period. Certain holders of the 2030 Notes surrendered $153 million in aggregate principal amount of the 2030 Notes during the make-whole fundamental change period for conversion, which were settled for $160 million in cash on May 7, 2026. In connection with the fundamental change, holders had the right to tender all or a portion of their 2030 Notes for cash (the “repurchase right”) pursuant to our offer to purchase in accordance with the obligations under the 2030 Notes. No holders exercised the repurchase right to tender their 2030 Notes. The make-whole conversion right and repurchase right resulting from our acquisition of CyberArk expired on March 20, 2026.
As of July 31, 2026, after giving effect to the 2030 Notes surrendered for conversion during the make-whole conversion period, the remaining outstanding principal balance of the 2030 Notes was $1.1 billion. As of July 31, 2026, the 2030 Notes were classified as a long-term liability on our consolidated balance sheets since the sale price condition was not met during the calendar quarter ended June 30, 2026. The related fair value of $1.8 billion was determined based on the closing trading price per $100 of the 2030 Notes as of the last day of trading for the period. The fair value of the 2030 Notes is primarily affected by the trading price of our common stock and market interest rates.
For the year ended July 31, 2026, changes in fair value of 2030 Notes included in earnings were a loss of $620 million, and changes in fair value attributable to instrument-specific credit risk included in AOCI were a loss of $11 million.
Capped Calls
In connection with our acquisition of CyberArk, on February 11, 2026, we entered into amendments to the Capped Calls that CyberArk purchased from certain financial institutions in connection with the issuance of the 2030 Notes. Under the amendments, we assumed the rights and obligations of CyberArk with respect to the Capped Calls and modified the Capped Calls to require the delivery of shares of our common stock in lieu of ordinary shares of CyberArk. The Capped Calls have a strike price of approximately $211.24 per share, subject to certain adjustments, which corresponds to the effective initial conversion price of our 2030 Notes. The Capped Calls have cap prices ranging from approximately $287.21 to $291.44 per share, subject to certain adjustments. In connection with exercising the Capped Calls, we may elect that the Capped Calls be settled either entirely in cash or a combination of our common stock and cash. The Capped Calls are separate transactions from the 2030 Notes, and holders of the 2030 Notes do not have any rights with respect to the Capped Calls.
The Capped Calls cover shares of our common stock underlying the 2030 Notes, subject to anti-dilution adjustments substantially similar to those applicable to the 2030 Notes. In April 2026, we elected to terminate portions of the Capped Calls in exchange for $10 million in cash in connection with the $153 million in aggregate principal amount of the 2030 Notes surrendered by certain holders during the make-whole conversion period.
- 89 -
As of July 31, 2026, the fair value of the outstanding Capped Calls was $153 million, determined using the Black-Scholes option pricing model and observable inputs, including the price of our common stock, volatility, remaining contractual term, and risk-free interest rate. For the year ended July 31, 2026, the change in fair value of Capped Calls was a gain of $58 million.
Revolving Credit Facility
On April 13, 2023, we entered into a credit agreement (the “Credit Agreement”) with certain institutional lenders that provides for a $400 million unsecured revolving credit facility (the “Credit Facility”), with an option to increase the amount of the Credit Facility by up to an additional $350 million, subject to certain conditions. The Credit Facility matures on April 13, 2028.
The borrowings under the Credit Facility bear interest, at our option, at a base rate plus a spread of 0.000% to 0.375%, or an adjusted term Secured Overnight Financing Rate plus a spread of 1.000% to 1.375%, in each case with such spread being determined based on our leverage ratio. We are obligated to pay an ongoing commitment fee on undrawn amounts at a rate of 0.090% to 0.150%, depending on our leverage ratio. The interest rates and commitment fees are also subject to upward and downward adjustments based on our progress towards the achievement of certain sustainability goals.
As of July 31, 2026, there were no amounts outstanding and no default or event of default has occurred under the Credit Agreement.
12. Leases
We have entered into various non-cancelable operating leases, primarily for our offices, with lease terms expiring through the year ending July 31, 2040. The most significant leases relate to our corporate headquarters in Santa Clara.
In April 2026, we entered into three lease amendments to extend the lease terms of our current corporate headquarters in Santa Clara, California for a period of twelve years through July 2040. The leases contain rent holiday periods, scheduled rent increases, lease incentives, and renewal options which allow the lease terms to be extended through July 2052. Lease payments under the three lease amendments, net of lease incentives such as rent holidays and tenant improvement allowances, are approximately $469 million over the extended lease term through July 2040.
During the years ended July 31, 2026, 2025, and 2024, our net cost for operating leases was million, million, and million, respectively, primarily consisting of operating lease costs of $104 million, $88 million, and $76 million, respectively. Our net cost for operating leases also included variable lease costs, short-term lease costs, and sublease income in the periods presented.
The following tables present additional information for our operating leases (in millions, except for years and percentages):
| Line item | Year Ended July 31, 2026 | Year Ended July 31, 2025 | Year Ended July 31, 2024 |
|---|---|---|---|
| Operating cash flows used in payments of operating lease liabilities | |||
| Right-of-use assets obtained in exchange for new operating lease liabilities(1) |
(1) Includes $262 million in fiscal 2026 relating to the lease amendments of our corporate headquarters in Santa Clara.
| Line item | July 31, 2026 | July 31, 2025 |
|---|---|---|
| Weighted-average remaining lease term | 10 years | 6 years |
| Weighted-average discount rate | % | % |
- 90 -
The following table presents maturities of operating lease liabilities as of July 31, 2026 (in millions):
| Fiscal years ending July 31: | Amount | Amount |
|---|---|---|
| 2027 | $105 | |
| 2028 | 85 | |
| 2029 | 84 | |
| 2030 | 121 | |
| 2031 | ||
| 2032 and thereafter | ||
| Total operating lease payments | ||
| Less: imputed interest | () | |
| Present value of operating lease liabilities | ||
| Current portion of operating lease liabilities(1) | $67 | |
| Long-term operating lease liabilities |
(1) Current portion of operating lease liabilities is included in accrued and other liabilities on our consolidated balance sheet.
As of July 31, 2026, we had additional non-cancelable operating leases for office space that had been signed but had not yet commenced with total future minimum lease payments of $15 million. These leases are expected to commence in or after fiscal 2028, with lease terms ranging from four to five years.
13. Commitments and Contingencies
Purchase Commitments
We have entered into various non-cancelable agreements with cloud hosting service providers, under which we are committed to minimum or fixed purchases of certain cloud hosting services. In addition, in order to reduce manufacturing lead times and plan for adequate supply, we have entered into agreements with manufacturing partners and component suppliers to procure inventory based on our demand forecasts. Other purchase obligations include non-cancellable subscription agreements and other commitments in the normal course of business. The following table presents details of the aggregate future non-cancelable purchase commitments under these agreements as of July 31, 2026 (in millions):
| Line item | Fiscal years ending July 31, | Fiscal years ending July 31, | Fiscal years ending July 31, | Fiscal years ending July 31, | Fiscal years ending July 31, | Fiscal years ending July 31, | Fiscal years ending July 31, | Fiscal years ending July 31, | Fiscal years ending July 31, | Fiscal years ending July 31, | Fiscal years ending July 31, | Fiscal years ending July 31, | ||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Total | 2027 | 2028 | 2029 | 2030 | 2031 | 2032 and Thereafter | ||||||||
| Cloud | $7,686 | $143 | $1,218 | $1,329 | $1,398 | $1,725 | $1,873 | |||||||
| Manufacturing | 370 | 370 | — | — | — | — | — | |||||||
| Other | 186 | 129 | 34 | 13 | 10 | — | — | |||||||
| Total | $1,342 | $1,408 | $1,725 | $1,873 |
Additionally, we have a $81 million minimum purchase commitment with a cloud hosting service provider through September 2027 with no specified annual commitments.
Mutual Covenant Not to Sue and Release Agreement
In January 2020, we executed a Mutual Covenant Not to Sue and Release Agreement for $50 million to extend an existing covenant not to sue for seven years. As the primary benefit of the arrangement was attributable to future use, the amount was recorded in other assets on our consolidated balance sheets and is amortized to cost of product revenue on our consolidated statements of operations over the estimated period of benefit of seven years.
Guarantee
As of July 31, 2026, we have multi-currency notional cash pool for a certain number of our entities with third-party banks. As part of the notional cash pool agreement, the bank extends overdraft credit to our participating entities as needed, provided that the overall notionally pooled balance of all accounts in the pool at the end of each day is positive. In the unlikely event of a default, any overdraft balances incurred would be guaranteed by our collective entities participating in the pool.
- 91 -
Litigation
We are subject to legal proceedings, claims, tax matters, and litigation arising in the ordinary course of business, including, for instance, intellectual property and patent litigation. We accrue for contingencies when we believe that a loss is probable and that we can reasonably estimate the amount of any such loss.
Legal matters could include speculative, substantial, or indeterminate monetary amounts. Significant judgment is required to determine both the likelihood of there being a loss and the estimated amount of a loss related to such matters, and we may be unable to estimate the reasonably possible loss or range of loss. The outcomes of outstanding legal matters are inherently unpredictable, and could, either individually or in aggregate, have a material adverse effect on us and our results of operations. To the extent there is a reasonable possibility that a loss exceeding any amounts already recognized may be incurred, we will either disclose the estimated additional loss or state that such an estimate cannot be made.
The following matters arose in the ordinary course of business.
Centripetal Networks, Inc. v. Palo Alto Networks
On March 12, 2021, Centripetal Networks, Inc. (“Centripetal”) filed a lawsuit against us in the United States District Court for the Eastern District of Virginia. The lawsuit alleges that our products infringe multiple Centripetal patents. We successfully challenged certain of these patents, which were found unpatentable by the U.S. Patent and Trademark Office (“PTO”). The case went to jury trial on January 22, 2024, on patents. On January 31, 2024, the jury returned a verdict of non-willful infringement with a lump sum amount of million, plus statutory interest. After post-trial motions, a judgment was issued on October 3, 2024 affirming infringement on patents, reversing infringement on the fourth patent, and subsequently, reducing the damages amount to million. We posted a surety bond that was agreed upon by the parties and approved by the court. This bond prevents execution of the judgment while appeals are pending. In addition, Centripetal filed infringement contentions on certain of their patents in the European Patent Office and Unified Patent Court in Germany, to which we filed appropriate legal challenges. Those matters are still pending.
As of July 31, 2026 and 2025, we accrued million and million, respectively, based on the judgment and estimated interest, which is recorded in other long-term liabilities on our consolidated balance sheets. The corresponding amount was a charge of million for the year ended July 31, 2026 and a release of million for the year ended July 31, 2025, which is included in general and administrative expense on our consolidated statements of operations.
Finjan, Inc. v. Palo Alto Networks
On November 4, 2014, Finjan, Inc. (“Finjan”) filed a lawsuit against us in the United States District Court for the Northern District of California. The lawsuit alleges that our products infringe multiple Finjan patents. The complaint requests injunctive relief, monetary damages, and attorneys’ fees. On March 21, 2025, the judge issued an order granting summary judgment of non-infringement on all remaining patents at issue. The matter is currently pending appeal. We are unable, at this time, to reasonably estimate a possible loss or potential range of loss, if any.
Eire OG Innovations. v. Palo Alto Networks
On April 3, 2024, Eire OG Innovations filed a lawsuit against us in the United States District Court for the Eastern District of Texas asserting infringement of multiple patents, certain of which were subsequently dismissed. The parties have resolved all pending matters between them as of December 2025. The amount paid by us to resolve these matters was not material.
Indemnification
Under the indemnification provisions of our standard sales related contracts, we agree to defend our end-customers against third-party claims asserting infringement of certain intellectual property rights, which may include patents, copyrights, trademarks, or trade secrets, and to pay judgments or approved settlements attributable to such claims. Our exposure under these indemnification provisions is generally limited to payments made to us for the alleged infringing products over the preceding twelve months under the agreement. However, certain agreements include indemnification provisions that could potentially expose us to losses in excess of these payments. In addition, we indemnify our officers, directors, and certain key employees while they are serving in good faith in their company capacities. To date, we have not recorded any accruals for loss contingencies associated with indemnification claims or determined that an unfavorable outcome is probable or reasonably possible.
- 92 -
14. Stockholders’ Equity
Share Repurchase Program
In February 2019, our board of directors authorized a billion share repurchase program, which is funded from available working capital. Our board of directors subsequently authorized additional increases to this share repurchase program, bringing the total authorization under this share repurchase program to billion (our “current authorization”). The expiration date of our current authorization was extended to December 31, 2026, and our repurchase program may be suspended or discontinued at any time. Repurchases are to be made at management’s discretion from time to time on the open market, through privately negotiated transactions, transactions structured through investment banking institutions, block purchase techniques, 10b5-1 trading plans, or a combination of the foregoing.
The following table summarizes the share repurchase activity under our share repurchase program (in millions, except per share amounts):
| Line item | Year Ended July 31, 2026 | Year Ended July 31, 2025 | Year Ended July 31, 2024 |
|---|---|---|---|
| Number of shares repurchased | |||
| Weighted-average price per share (1) | $147.70 | — | $142.00 |
| Aggregate purchase price (1) |
(1) Includes transaction costs
As of July 31, 2026, billion remained available for future share repurchases under our current repurchase authorization. The total price of the shares repurchased and related transaction costs are reflected as a reduction to common stock and additional paid-in capital on our consolidated balance sheets.
15. Equity Award Plans
Share-Based Compensation Plans
Equity Incentive Plans
Our 2021 Equity Incentive Plan (our “2021 Plan”) became effective in December 2021 and replaced our 2012 Equity Incentive Plan (our “2012 Plan”). Our 2021 Plan provides for the granting of stock options, stock appreciation rights, restricted stock awards (“RSAs”), restricted stock units (“RSUs”), performance shares (“PSAs”), performance-based stock units (“PSUs”) and performance stock options (“PSOs”) to our employees, directors, and consultants. Upon effectiveness of the 2021 Plan, the 2012 Plan was terminated and no further awards will be granted under the 2012 Plan. Awards that were outstanding upon such termination remained outstanding pursuant to their original terms, and any subsequent expiration, cancellation, or forfeiture of awards under our 2012 Plan are returned to our 2021 Plan.
The majority of our equity awards are RSUs, which generally vest over a period of four years from the date of grant. Until vested, RSUs do not have the voting and dividend participation rights of common stock and the shares underlying the awards are not considered issued and outstanding.
Our PSUs generally vest over a period of one to four years from the date of grant. The number of PSUs eligible to vest is determined based on the level of achievement against certain performance conditions, market conditions, and a combination thereof.
During the year ended July 31, 2023, we granted million shares of PSUs with both service and market conditions. The market conditions are satisfied when the price of our common stock is equal to or exceeds stock price targets of $116.67, $133.34, $150.00, and $166.67 based on the average closing price for 30 consecutive trading days during the three- or four-year period following the date of grant. Once a market condition is met, its corresponding one-fourth of the awards vest on each anniversary date of the grant date, subject to continued service. As of July 31, 2026, all stock price targets for these PSU awards have been met, and the related shares will vest when the underlying service conditions are satisfied.
During the year ended July 31, 2023, we granted 2 million shares of PSUs, which contain service and market conditions. The service conditions are satisfied after a period of five years. The market condition is measured based on our total shareholder return (“TSR”) relative to the TSR of the companies listed in the Standard & Poor’s 500 index.
During the years ended July 31, 2026, 2025, and 2024, we granted 3 million, 3 million, and 4 million shares of PSUs, respectively, which contain service, performance and market conditions. The service conditions are satisfied over a period of one to three years. For PSUs granted during the years ended July 31, 2026 and 2025, the performance conditions are based on an average of next-generation security annualized recurring revenue and non-GAAP net income per diluted share. For PSUs granted during the year ended July 31, 2024, the performance conditions are based on revenue growth or billing growth. The market condition is measured based on our TSR relative to the TSR of the companies listed in the Standard & Poor’s 500 index. As of July 31, 2026, we have approved an additional 3 million shares of PSUs, which will be granted upon the performance condition being established during the next two years.
- 93 -
We have also granted PSOs with both service and market conditions. The market condition for PSOs granted in fiscal 2018 and 2019 requires the price of our common stock to equal or exceed $49.63, $66.17, $82.71, and $99.25 based on the average closing price for 30 consecutive trading days during the four-, five-, six-, and seven-and-a-half-year periods following the date of grant in fiscal 2018 and 2019, respectively. Once a market condition is met, its corresponding one-fourth of the PSOs vest on each anniversary date of the grant date, subject to continued service. The maximum contractual term of our outstanding PSOs is seven and a half years from the date of grant, depending on vesting period. As of July 31, 2026, all of our outstanding PSOs have been fully vested.
We net-share settle equity awards held by certain employees by withholding shares upon vesting to satisfy tax withholding obligations. Effective August 14, 2025, our 2021 Plan was amended to provide that the shares withheld by us to satisfy employee tax withholding obligations are retired and are not returned to our 2021 Plan. Prior to the amendment, the shares withheld by us to satisfy employee tax withholding obligations were returned to the 2021 Plan and were available for future issuance. Payments for employees’ tax obligations to the tax authorities are recognized as a reduction to additional paid-in capital and reflected as financing activities on our consolidated statements of cash flows.
A total of 59 million shares of our common stock are reserved for issuance pursuant to our equity incentive plans as of July 31, 2026.
2012 Employee Stock Purchase Plan
Our 2012 Employee Stock Purchase Plan was adopted by our board of directors and approved by the stockholders on June 5, 2012, and was effective upon completion of our initial public offering. On August 29, 2017, we amended and restated our 2012 Employee Stock Purchase Plan (our “2012 ESPP”) to extend the length of our offering periods from 6 to 24 months.
Our 2012 ESPP permits eligible employees to acquire shares of our common stock at 85% of the lower of the fair market value of our common stock on the first trading day of each offering period or on the purchase date. If the fair market value of our common stock on the purchase date is lower than the first trading day of the offering period, the current offering period will be cancelled after purchase and a new 24-month offering period will begin. Under our 2012 ESPP, each 24-month offering period consists of four consecutive 6-month purchase periods, with purchase dates on the first trading day on or after February 28 and August 31 of each year. Participants may purchase shares of common stock through payroll deductions of up to 15% of their eligible compensation, subject to purchase limits of 3,750 shares per six-month purchase period and $25,000 worth of stock for each calendar year. Shares purchased under our 2012 ESPP during the fiscal years ended July 31, 2026, 2025 and 2024 were 2 million, 2 million and 2 million, at an average exercise price of $133.39 per share, $106.99 per share, and $80.32 per share, respectively.
A total of 47 million shares of our common stock are available for sale under our 2012 ESPP as of July 31, 2026. On the first day of each fiscal year, the number of shares in the reserve may be increased by the lesser of (i) 12 million shares, (ii) 1% of the outstanding shares of our common stock on the first day of the fiscal year, or (iii) such other amount as determined by our board of directors.
Assumed Share-Based Compensation Plans
In connection with our acquisitions, we have assumed equity incentive plans of certain acquired companies (collectively “the Assumed Plans”). The equity awards assumed in connection with each acquisition were granted from their respective assumed plans. The assumed equity awards will be settled in shares of our common stock and will retain the terms and conditions under which they were originally granted. No additional equity awards will be granted under and forfeited awards will not be returned to the Assumed Plans. Refer to Note 8. Acquisitions for more information on our acquisitions and the related equity awards assumed.
- 94 -
PSO Activities
The following table summarizes the PSO activity under our stock plans during the years ended July 31, 2026, 2025, and 2024 (in millions, except per share amounts):
| Line item | PSOs OutstandingNumber of Shares | Weighted-Average Exercise Price Per Share | Weighted-Average Remaining Contractual Term(Years) | Aggregate Intrinsic Value |
|---|---|---|---|---|
| Balance—July 31, 2023 | 13 | $32.60 | 2.2 | $1,185 |
| Exercised | (3) | 32.42 | ||
| Balance—July 31, 2024 | 10 | $32.66 | 1.2 | $1,245 |
| Exercised(1) | (9) | 32.65 | ||
| Balance—July 31, 2025 | 1 | $32.76 | 0.5 | $197 |
| Exercised | (1) | 32.76 | ||
| Balance—July 31, 2026 | — | — | 0.0 | — |
| Exercisable—July 31, 2026 | — | — | 0.0 | — |
(1) Includes 1 million shares withheld by us to satisfy exercise price and tax withholding requirements.
The intrinsic value of options exercised during the years ended July 31, 2026, 2025, and 2024 was $235 million, $1.2 billion, and $359 million, respectively.
RSU and PSU Activities
The following table summarizes the RSU and PSU activity under our stock plans during the years ended July 31, 2026, 2025, and 2024 (in millions, except per share amounts):
| Line item | Unvested RSUsNumber of Shares | Unvested RSUsWeighted-Average Grant-Date Fair Value Per Share | Unvested PSUsAggregate Intrinsic Value | Unvested PSUsNumber of Shares | Unvested PSUsWeighted-Average Grant-Date Fair Value Per Share | Aggregate Intrinsic Value |
|---|---|---|---|---|---|---|
| Balance—July 31, 2023 | 24 | $71.30 | $3,013 | 10 | $64.32 | $1,242 |
| Granted(1) | 9 | 137.76 | 4 | 91.39 | ||
| Vested(2) | (12) | 68.63 | (3) | 57.28 | ||
| Forfeited | (3) | 84.12 | (1) | 68.54 | ||
| Balance—July 31, 2024 | 18 | $102.59 | $2,924 | 10 | $77.95 | $1,624 |
| Granted(1) | 6 | 189.45 | 4 | 201.59 | ||
| Vested(2) | (9) | 97.00 | (1) | 64.65 | ||
| Forfeited | (2) | 115.94 | (4) | 92.11 | ||
| Balance—July 31, 2025 | 13 | $143.33 | $2,285 | 9 | $140.92 | $1,635 |
| Granted(1)(3) | 15 | 184.48 | 4 | 186.49 | ||
| Vested(2) | (9) | 144.94 | (3) | 150.68 | ||
| Forfeited | (2) | 158.84 | (2) | 146.42 | ||
| Balance—July 31, 2026 | 17 | $177.41 | $5,594 | 8 | $155.85 | $2,643 |
(1) For PSUs, shares granted represent the aggregate maximum number of shares that may be earned and issued with respect to these awards over their full terms.
(2) Includes time-based vesting for PSUs.
(3) Includes 7 million RSUs assumed in connection with the acquisitions of Chronosphere, CyberArk, Koi, and Portkey with weighted-average grant-date fair value of $176.20, $165.30, $161.59, and $281.69 per share, respectively, for the year ended July 31, 2026.
- 95 -
The aggregate fair value, as of the respective vesting dates, of RSUs vested during the years ended July 31, 2026, 2025, and 2024 was $1.8 billion, $1.6 billion, and $1.6 billion, respectively. The aggregate fair value, as of the respective vesting dates, of PSUs vested during the years ended July 31, 2026, 2025, and 2024 was $663 million, $221 million, and $378 million, respectively.
Shares Available for Grant
The following table presents the stock activity and the total number of shares available for grant under our equity incentive plans as of July 31, 2026 (in millions):
| Line item | Number of shares |
|---|---|
| Balance—July 31, 2025 | |
| Authorized | |
| RSUs and PSUs granted | (13) |
| RSUs and PSUs forfeited | 4 |
| Shares withheld for taxes | |
| Balance—July 31, 2026 |
Share-Based Compensation
We record share-based compensation awards based on estimated fair value as of the grant date. The fair value of RSUs and PSUs not subject to market conditions is based on the closing market price of our common stock on the date of grant.
The fair value of the PSUs subject to market conditions is estimated on the grant date using a Monte Carlo simulation model. The following table summarizes the assumptions used and the resulting grant-date fair value of our PSUs subject to market conditions granted during the years ended July 31, 2026, 2025, and 2024:
| Line item | Year Ended July 31, 2026 | Year Ended July 31, 2025 | Year Ended July 31, 2024 |
|---|---|---|---|
| Volatility | 36.6% - 42.6% | 43.5% - 47.6% | 40.8% - 43.4% |
| Expected term (in years) | 1.0 - 3.0 | 1.0 - 2.9 | 0.9 - 2.9 |
| Dividend yield | — | — | — |
| Risk-free interest rate | 3.6% - 3.9% | 3.7% - 4.5% | 4.4% - 5.3% |
| Grant-date fair value per share | $226.06 - $261.62 | $264.51 - $305.83 | $173.46 - $310.61 |
The expected volatility is based on the historical volatility of our common stock. The expected term is based on the length of each tranche’s performance period from the grant date. The dividend yield assumption is based on our current expectations about our anticipated dividend policy. The risk-free interest rate is based on the implied yield available on U.S. Treasury zero-coupon issues with maturities that approximate the expected term.
The fair value of PSOs was estimated on the grant date using a Monte Carlo simulation model, which predicts settlement of the PSOs midway between the vesting term and the contractual term. No PSOs were granted during the years ended July 31, 2026, 2025, and 2024.
The fair value of shares issued under our 2012 ESPP are estimated on the grant date using the Black-Scholes option pricing model. The following table summarizes the assumptions used and the resulting grant-date fair values of our ESPP:
| Line item | Year Ended July 31, 2026 | Year Ended July 31, 2025 | Year Ended July 31, 2024 |
|---|---|---|---|
| Volatility | 35.6% - 39.2% | 34.3% - 43.3% | 39.6% - 50.0% |
| Expected term (in years) | 0.5 - 2.0 | 0.5 - 2.0 | 0.5 - 2.0 |
| Dividend yield | — | — | — |
| Risk-free interest rate | 3.5% - 4.0% | 3.9% - 4.8% | 4.6% - 5.5% |
| Grant-date fair value per share | $32.77 - $73.67 | $45.43 - $74.81 | $32.81 - $66.66 |
- 96 -
The expected volatility is based on a combination of implied volatility from traded options on our common stock and the historical volatility of our common stock. The expected term represents the term from the first day of the offering period to the purchase dates within each offering period. The dividend yield assumption is based on our current expectations about our anticipated dividend policy. The risk-free interest rate is based on the implied yield available on U.S. Treasury zero-coupon issues with maturities that approximate the expected term.
The following table summarizes share-based compensation by award types (in millions):
| Line item | Year Ended July 31, 2026 | Year Ended July 31, 2025 | Year Ended July 31, 2024 |
|---|---|---|---|
| RSU and RSA | $1,319 | $878 | $866 |
| PSU | 344 | 331 | 124 |
| Others | 152 | 91 | 89 |
| Total share-based compensation |
The following table summarizes share-based compensation included in costs and expenses (in millions):
| Line item | Year Ended July 31, 2026 | Year Ended July 31, 2025 | Year Ended July 31, 2024 |
|---|---|---|---|
| Cost of product revenue | $5 | $5 | $7 |
| Cost of subscription and support revenue | 161 | 127 | 121 |
| Research and development | 688 | 551 | 526 |
| Sales and marketing | 513 | 359 | 301 |
| General and administrative | 448 | 258 | 124 |
| Total share-based compensation |
During the year ended July 31, 2026, the vesting of certain equity awards was accelerated in connection with our acquisitions of CyberArk and Koi; as a result, we recorded share-based compensation of $177 million, including $1 million in cost of subscription and support revenue, $36 million in sales and marketing expense, and $140 million in general and administrative expense on our consolidated statements of operations.
As of July 31, 2026, total compensation cost related to unvested share-based awards not yet recognized was billion. This cost is expected to be amortized over a weighted-average period of approximately 2.5 years. Future grants will increase the amount of compensation expense to be recorded in these periods.
- 97 -
16. Income Taxes
The following table presents the components of income before income taxes (in millions):
| Line item | Year Ended July 31, 2026 | Year Ended July 31, 2025 | Year Ended July 31, 2024 |
|---|---|---|---|
| United States | $466 | $1,125 | $669 |
| Foreign | 70 | 471 | 319 |
| Total |
The following table summarizes our provision for (benefit from) income taxes (in millions):
| Line item | Year Ended July 31, 2026 | Year Ended July 31, 2025 | Year Ended July 31, 2024 |
|---|---|---|---|
| Federal: | |||
| Current | |||
| Deferred | () | () | |
| State: | |||
| Current | |||
| Deferred | () | () | () |
| Foreign: | |||
| Current | |||
| Deferred | 120 | (5) | (2,173) |
| Total | $() |
For the year ended July 31, 2026, our provision for income taxes was million, which represented a $233 million decrease from prior year, primarily due to a one-time deferred tax provision of million recorded during during the year ended July 31, 2025 arising from the remeasurement of our basis difference associated with the U.S. tax effects of foreign deferred tax assets.
- 98 -
We adopted the new income tax disclosures guidance effective in our year ended July 31, 2026 on a prospective basis. The following table presents a reconciliation from the federal statutory tax amount and rate to our provision for incomes taxes and effective tax rate under the requirements of the newly adopted income tax disclosures guidance (dollars in millions):
Year Ended July 31, 2026
| Line item | Amount | Rate |
|---|---|---|
| Federal statutory tax | % | |
| State taxes(1)(2) | ||
| Foreign tax effects: | ||
| Israel: | ||
| Statutory rate differential | (10) | (1.9) |
| Reduced statutory rate on qualifying income | 93 | 17.3 |
| Nondeductible expenses | 22 | 4.1 |
| Intercompany legal entity restructuring(2) | 48 | 9.0 |
| United Kingdom: | ||
| Statutory rate differential | 20 | 3.7 |
| Other jurisdictions | 54 | 10.2 |
| Effect of cross-border tax laws: | ||
| Global intangible low-taxed income(2) | () | () |
| Subpart F income | 22 | 4.1 |
| U.S. branch income (loss)(2) | (117) | (21.9) |
| Other | () | () |
| Tax credits: | ||
| Research and development tax credits | (58) | (10.8) |
| Changes in valuation allowance | (2) | (0.4) |
| Nontaxable or nondeductible items: | ||
| Shared-based compensation | 49 | 9.1 |
| Change in fair value of convertible senior notes and Capped Calls | 118 | 22.0 |
| Other | 7 | 1.3 |
| Changes in unrecognized tax benefits | ||
| Other: | ||
| Intercompany legal entity restructuring(2) | (39) | (7.3) |
| Total | % |
(1) The state and local jurisdictions that contribute to the majority of the tax effect in this category include California, District of Columbia, Maryland, the state and city of New York, and Pennsylvania.
(2) These categories include impacts of an intercompany legal entity restructuring completed Q4 fiscal 2026 with a total impact of $45 million income tax benefit.
- 99 -
Prior to the adoption of the new income tax disclosure guidance, the following table presents a reconciliation from the federal statutory income tax rate to our effective tax rate:
| Line item | Year Ended July 31, 2025 | Year Ended July 31, 2024 |
|---|---|---|
| Federal statutory rate | % | % |
| Effect of: | ||
| State taxes, net of federal tax benefit | ||
| Non-U.S. operations | ||
| Change in valuation allowance | () | |
| U.S. effect of foreign deferred tax assets | ||
| Share-based compensation | () | () |
| Tax credits | (6.2) | (13.4) |
| Non-deductible expenses | ||
| Other, net | ||
| Total | % | ()% |
The following table presents the components of our deferred tax assets and liabilities as of July 31, 2026 and 2025 (in millions):
| Line item | July 31, 2026 | July 31, 2025 |
|---|---|---|
| Deferred tax assets: | ||
| Accruals and reserves | ||
| Operating lease liabilities | 233 | 127 |
| Deferred revenue | 1,385 | 1,266 |
| Net operating loss carryforwards | ||
| Tax credits | 286 | 222 |
| Capitalized research expenditures | ||
| Share-based compensation | ||
| Fixed assets and intangible assets | 921 | 1,561 |
| Gross deferred tax assets | ||
| Valuation allowance | () | () |
| Total deferred tax assets | ||
| Deferred tax liabilities: | ||
| U.S. effect of foreign deferred tax assets | (1,789) | (1,922) |
| Operating lease right-of-use assets | (208) | (108) |
| Deferred contract costs | () | () |
| Other deferred tax liabilities | () | () |
| Total deferred tax liabilities | () | () |
| Net deferred tax assets |
We regularly assess the need for a valuation allowance on our deferred tax assets. In making this assessment, we consider both positive and negative evidence related to the likelihood of realization of the deferred tax assets to determine, based on the weight of available evidence, whether it is more likely than not that some or all the deferred tax assets will not be realized. The assessment requires significant judgment and is performed for each of the applicable jurisdictions. Due to a law change during the year ended July 31, 2026, we released a portion of the valuation allowance for our California deferred tax assets due to these assets becoming “more likely than not” to be realized in the future; however, we still expect future research and development tax credit generation in California to exceed our ability to use the existing tax credits.
- 100 -
As of July 31, 2026, we had federal, state, and foreign net operating loss carryforwards of approximately $474 million, $746 million, and $3.0 billion, respectively, as reported on our tax returns, available to reduce future taxable income, if any. If not utilized, our federal and state net operating loss carryforwards will expire in various amounts at various dates beginning in the years ending July 31, 2034 and July 31, 2030, respectively. Our foreign net operating loss will carry forward indefinitely.
As of July 31, 2026, we had federal and state research and development tax credit carryforwards of approximately $7 million and $382 million, respectively, as reported on our tax returns. If not utilized, the federal credit carryforwards will expire in various amounts at various dates beginning in the year ending July 31, 2040. The state credit carryforwards have no expiration.
As of July 31, 2026, we had foreign tax credit carryforwards of $46 million as reported on our tax returns. If not utilized, the foreign tax credit carryforwards will expire in various amounts at various dates beginning in the year ending July 31, 2029.
As of July 31, 2026, we had million of unrecognized tax benefits, million of which would affect income tax expense if recognized. As of July 31, 2025, we had million of unrecognized tax benefits, million of which would affect income tax expense if recognized.
We file federal, state, and foreign income tax returns in jurisdictions with varying statutes of limitations. Generally, all years remain subject to adjustment due to our net operating loss and credit carryforwards. We currently have ongoing tax audits in various jurisdictions and at various times. The primary focus of these audits is, generally, profit allocation. The ultimate amount and timing of any future settlements cannot be predicted with reasonable certainty.
We recognize both interest and penalties associated with uncertain tax positions as a component of income tax expense. During the years ended July 31, 2026, 2025, and 2024, we recognized income tax expense of million, million, and million related to interest and penalties, respectively. We had accrued interest and penalties on our consolidated balance sheets related to unrecognized tax benefits of million and million as of July 31, 2026 and 2025, respectively.
The following table presents a reconciliation of the beginning and ending amount of our gross unrecognized tax benefits (in millions):
| Line item | Year Ended July 31, 2026 | Year Ended July 31, 2025 | Year Ended July 31, 2024 |
|---|---|---|---|
| Unrecognized tax benefits at the beginning of the period | |||
| Additions for tax positions taken in prior years | |||
| Reductions for tax positions taken in prior years | () | () | () |
| Additions for tax positions taken in the current year | |||
| Reduction relating to audit settlement | (5) | — | — |
| Unrecognized tax benefits at the end of the period |
As part of the acquisition of CyberArk, we executed an intercompany transaction to repatriate $3.5 billion of foreign earnings, resulting in immaterial income tax expense related to state and other taxes. Our remaining unremitted earnings are indefinitely reinvested.
Pursuant to adoption of the new income tax disclosures guidance, the following table presents the income taxes paid, net of refunds (in millions):
Year Ended July 31, 2026
| Federal | |
| State | |
| California | 18 |
| All Others | 51 |
| Foreign | |
| Israel | 24 |
| Netherlands | 13 |
| India | 16 |
| All Others | 37 |
| Total |
- 101 -
17. Net Income Per Share
Basic net income per share is computed by dividing net income by basic weighted-average shares outstanding during the period. Diluted net income per share is computed by dividing net income by diluted weighted-average shares outstanding during the period giving effect to all potentially dilutive securities to the extent they are dilutive. We compute the dilutive effect of shares issuable upon conversion of our convertible senior notes using the if-converted method, and the dilutive effect of warrants related to the issuance of convertible senior notes and equity awards under our employee equity incentive plans using the treasury stock method.
The following table presents the computation of basic and diluted net income per share of common stock (in millions, except per share data):
| Line item | Year Ended July 31, 2026 | Year Ended July 31, 2025 | Year Ended July 31, 2024 |
|---|---|---|---|
| Net income | $307 | $1,134 | $2,578 |
| Weighted-average shares used to compute net income per share, basic | |||
| Weighted-average effect of potentially dilutive securities: | |||
| Convertible senior notes | |||
| Warrants related to the issuance of convertible senior notes | 5 | 25 | 26 |
| Employee equity incentive plans | |||
| Weighted-average shares used to compute net income per share, diluted | |||
| Net income per share, basic | |||
| Net income per share, diluted |
The following securities were excluded from the computation of diluted net income per share of common stock as their effect would have been antidilutive or issuance of such shares is contingent upon the satisfaction of certain conditions which were not satisfied by the end of the applicable period (in millions):
| Line item | Year Ended July 31, 2026 | Year Ended July 31, 2025 | Year Ended July 31, 2024 |
|---|---|---|---|
| Employee equity incentive plans | 5 | 3 | 5 |
18. Other Income (Expense), Net
The following table sets forth the components of other income (expense), net (in millions):
| Line item | Year Ended July 31, 2026 | Year Ended July 31, 2025 | Year Ended July 31, 2024 |
|---|---|---|---|
| Interest income | |||
| Interest expense | — | (3) | (8) |
| Foreign currency exchange gains (losses), net | () | () | |
| Change in fair value of convertible senior notes | (620) | — | — |
| Change in fair value of Capped Calls | |||
| Other, net | () | ||
| Total other income (expense), net | $() |
19. Segment Information
We have operating and reportable segment. We conduct business globally and sales are primarily managed on a geographic theater basis. Our chief operating decision maker (“CODM”) is our Chairman and Chief Executive Officer who reviewed financial information presented on a consolidated basis accompanied by revenue information for purposes of allocating resources and evaluating financial performance. Our CODM used consolidated net income as our measure of segment profit or loss. The consolidated financial information by function as reflected on our consolidated statements of operations was used in our annual budget and forecasting process to establish goals and monitor budget versus actual results. The measure of segment assets is reported on the consolidated balance sheets as total consolidated assets.
- 102 -
The following table presents our long-lived assets, which consist of property and equipment, net and operating lease right-of-use assets, by geographic area (in millions):
| Line item | Year Ended July 31, 2026 | Year Ended July 31, 2025 |
|---|---|---|
| Long-lived assets: | ||
| United States | $759 | $418 |
| Israel | 222 | 162 |
| Other countries | 242 | 154 |
| Total long-lived assets |
Refer to Note 2. Revenue for revenue by geographic theater and revenue for groups of similar products and services for the years ended July 31, 2026, 2025, and 2024.
20. Subsequent Events
Embrace Mobile, Inc.
On August 27, 2026, we completed the acquisition of Embrace. This acquisition will be accounted for as a business combination in the first quarter of fiscal 2027.
Console Systems, Inc.
On September 1, 2026, we completed the acquisition of Console. This acquisition will be accounted for as a business combination in the first quarter of fiscal 2027.
- 103 -
Item 9. Changes in and Disagreements with Accountants on Accounting and Financial Disclosure
Not applicable.
Item 9A. Controls and Procedures
Evaluation of Disclosure Controls and Procedures
Our management, with the participation of our chief executive officer and chief financial officer, evaluated the effectiveness of our disclosure controls and procedures pursuant to Rule 13a-15(b) under the Securities Exchange Act of 1934, as amended (the “Exchange Act”). In designing and evaluating the disclosure controls and procedures, management recognizes that any controls and procedures, no matter how well designed and operated, can provide only reasonable assurance of achieving the desired control objectives. In addition, the design of disclosure controls and procedures must reflect the fact that there are resource constraints and that management is required to apply its judgment in evaluating the benefits of possible controls and procedures relative to their costs.
Based on our evaluation, our chief executive officer and chief financial officer concluded that, as of July 31, 2026, our disclosure controls and procedures are designed at a reasonable assurance level and are effective to provide reasonable assurance that information we are required to disclose in reports that we file or submit under the Exchange Act is recorded, processed, summarized, and reported within the time periods specified in Securities and Exchange Commission (“SEC”) rules and forms, and that such information is accumulated and communicated to our management, including our chief executive officer and chief financial officer, as appropriate, to allow timely decisions regarding required disclosure.
Management’s Annual Report on Internal Control over Financial Reporting
Our management is responsible for establishing and maintaining adequate internal control over financial reporting as defined in Rule 13a-15(f) under the Exchange Act. Our management assessed the effectiveness of our internal control over financial reporting as of July 31, 2026, based on the framework set forth by the Committee of Sponsoring Organizations of the Treadway Commission (“COSO”) in Internal Control - Integrated Framework (2013 framework). In accordance with guidance issued by the SEC staff, companies are permitted to exclude acquisitions from their assessment of internal control over financial reporting for the first fiscal year in which the acquisition occurred. Our assessment of the effectiveness of our internal control over financial reporting as of July 31, 2026 excluded CyberArk, which we acquired on February 11, 2026. We have included the financial results of CyberArk in our consolidated financial statements since the date of acquisition, which constituted 2% of total consolidated assets, less than 1% of total consolidated net assets, and 6% of total consolidated revenue as of and for the year ended July 31, 2026. Based on that assessment, management concluded that, as of July 31, 2026, our internal control over financial reporting was effective.
The effectiveness of our internal control over financial reporting as of July 31, 2026 has been audited by Ernst & Young LLP, the independent registered public accounting firm that audits our consolidated financial statements, as stated in their attestation report which is included in Part II, Item 8 of this Annual Report on Form 10-K.
Changes in Internal Control over Financial Reporting
There were no changes in our internal control over financial reporting identified in connection with the evaluation required by Rule 13a-15(d) under the Exchange Act that occurred during the fiscal quarter ended July 31, 2026 that have materially affected, or are reasonably likely to materially affect, our internal control over financial reporting.
- 104 -
Item 9B. Other Information
Trading Plans of Directors and Executive Officers
Set forth below is certain information regarding Rule 10b5-1 trading plans adopted, modified or terminated by our directors and officers (as defined in Rule 16a-1(f)) during the fourth quarter of fiscal 2026. The Rule 10b5-1 trading plans listed below are each intended to satisfy the affirmative defense of Rule 10b5-1(c).
Name Title Action Date of Action Expiration Date Total Amount of Common Stock to Be Sold Under the Plan
Dipak Golechha Chief Financial Officer Modified June 25, 2026 September 30, 2027 50,000 or, if earlier, when all shares have been sold
William D. Jenkins Jr. President Adopted June 28, 2026 January 31, 2027 148,217 or, if earlier, when all shares have been sold
No other officers or directors, as defined in Rule 16a-1(f), adopted, modified, and/or terminated a “Rule 10b5-1 trading arrangement” or a “non-Rule 10b5-1 trading arrangement,” as defined in Regulation S-K Item 408, during the fourth quarter of fiscal 2026.
Item 9C. Disclosure Regarding Foreign Jurisdictions That Prevent Inspections
Not applicable.
- 105 -
Part III
Item 10. Directors, Executive Officers and Corporate Governance
The information required by this item will be contained in our definitive proxy statement to be filed with the SEC in connection with our 2026 annual meeting of stockholders (the “Proxy Statement”), which is expected to be filed not later than 120 days after the end of our fiscal year ended July 31, 2026 and is incorporated herein by reference.
Our Board has adopted a Code of Business Conduct and Ethics that applies to all our employees, officers and directors, including our Chief Executive Officer, Chief Financial Officer, and other executive and senior financial officers. We will post amendments to our Code of Business Conduct and Ethics or waivers of our Code of Business Conduct and Ethics for directors and executive officers on the same website.
Item 11. Executive Compensation
The information required by this item will be set forth in the Proxy Statement and is incorporated herein by reference.
Item 12. Security Ownership of Certain Beneficial Owners and Management and Related Stockholder Matters
The information required by this item will be set forth in the Proxy Statement and is incorporated herein by reference.
Item 13. Certain Relationships and Related Transactions, and Director Independence
The information required by this item will be set forth in the Proxy Statement and is incorporated herein by reference.
Item 14. Principal Accountant Fees and Services
The information required by this item will be set forth in the Proxy Statement and is incorporated herein by reference.
- 106 -
Part IV
Item 15. Exhibits and Financial Statement Schedules
Documents filed as part of this Annual Report on Form 10-K are as follows:
1.Consolidated Financial Statements
Our Consolidated Financial Statements are listed in the “Index to Consolidated Financial Statements” under Part II, Item 8 of this Annual Report on Form 10-K.
2.Financial Statement Schedules
Financial statement schedules have been omitted because they are not required, not applicable, not present in amounts sufficient to require submission of the schedule, or the required information is shown in the Consolidated Financial Statements or the notes thereto.
3.Exhibits
The following documents are incorporated by reference or are filed with this Annual Report on Form 10-K, in each case as indicated therein (numbered in accordance with Item 601 of Regulation S-K).
Exhibit Index
| Exhibit Number | Exhibit Description | Incorporated by ReferenceForm | Incorporated by ReferenceFile No. | Incorporated by ReferenceExhibit | Incorporated by ReferenceFiling Date |
|---|---|---|---|---|---|
| 2.1^ | Agreement and Plan of Merger, dated as of July 30, 2025, by and among Palo Alto Networks, Inc., Athens Strategies Ltd. and CyberArk Software Ltd. | 8-K | 001-35594 | 2.1 | July 31, 2025 |
| 3.1 | Restated Certificate of Incorporation of the Registrant, as amended. | 10-K | 001-35594 | 3.1 | August 29, 2025 |
| 3.2 | Amended and Restated Bylaws of the Registrant. | 8-K | 001-35594 | 3.1 | August 21, 2026 |
| 3.3 | Certificate of Change of Location of Registered Agent and/or Registered Office. | 8-K | 001-35594 | 3.1 | August 30, 2016 |
| 4.1 | Description of Registrant’s Securities. | 10-K | 001-35594 | 4.1 | August 29, 2025 |
| 4.2 | Indenture, dated June 10, 2025, by and between CyberArk Software Ltd. and U.S. Bank Trust Company, National Association. | 8-K | 001-35594 | 4.1 | February 11, 2026 |
| 4.3 | First Supplemental Indenture, dated as of February 11, 2026, by and among Palo Alto Networks, Inc., CyberArk Software Ltd. and U.S. Bank Trust Company, National Association. | 8-K | 001-35594 | 4.2 | February 11, 2026 |
| 4.4 | Form of Global 0.00% Convertible Senior Note due 2030 (contained in Exhibit 4.2 hereto). | 8-K | 001-35594 | 4.3 | February 11, 2026 |
| 4.5 | Form of Amended and Restated Confirmation of Capped Call Transaction. | ||||
| 10.1* | Form of Indemnification Agreement between the Registrant and its directors and officers. | S-1/A | 333-180620 | 10.1 | July 9, 2012 |
| 10.2* | 2012 Equity Incentive Plan and related form agreements. | 10-Q | 001-35594 | 10.2 | November 26, 2019 |
- 107 -
| Exhibit Number | Exhibit Description | Incorporated by ReferenceForm | Incorporated by ReferenceFile No. | Incorporated by ReferenceExhibit | Incorporated by ReferenceFiling Date |
|---|---|---|---|---|---|
| 10.3* | Form of 2012 Equity Incentive Plan Performance-Based Restricted Stock Unit Award Agreement. | 10-Q | 001-35594 | 10.4 | November 19, 2021 |
| 10.4* | 2021 Equity Incentive Plan, as amended and restated. | 8-K | 001-35594 | 10.1 | December 11, 2025 |
| 10.5*^ | Form Award Agreements under the 2021 Equity Incentive plan, as amended and restated. | ||||
| 10.6*^ | 2012 Employee Stock Purchase Plan, as amended and restated, and related form agreements. | ||||
| 10.7* | RedLock Inc. 2015 Stock Plan, as amended, and related form agreements under RedLock Inc. 2015 Stock Plan, as amended. | S-8 | 333-227901 | 99.1 | October 19, 2018 |
| 10.8* | Cider Security Ltd. 2020 Equity Incentive Plan. | S-8 | 333-268931 | 99.1 | December 21, 2022 |
| 10.9* | US Sub-Plan to Cider Security Ltd. 2020 Equity Incentive Plan. | S-8 | 333-268931 | 99.2 | December 21, 2022 |
| 10.10* | CyberArk Software Ltd. 2024 Share Incentive Plan, as amended. | S-8 POS | 333-290235 | 4.4 | February 11, 2026 |
| 10.11* | CyberArk Software Ltd. 2014 Share Incentive Plan, as amended. | S-8 POS | 333-290235 | 4.5 | February 11, 2026 |
| 10.12* | Employee Incentive Compensation Plan, as amended and restated. | 10-Q | 001-35594 | 10.2 | November 25, 2014 |
| 10.13 | Clawback Policy, adopted as of August 29, 2017, amended August 14, 2024. | 10-K | 001-35594 | 10.16 | September 6, 2024 |
| 10.14* | Amended and Restated Outside Director Compensation Policy (last amended February 12, 2025). | 10-Q | 001-35594 | 10.1 | May 21, 2025 |
| 10.15* | Continued Service Policy. | 10-Q | 001-35594 | 10.3 | May 20, 2022 |
| 10.16* | Palo Alto Networks, Inc. Deferred Compensation Plan effective June 1, 2022. | 10-K | 001-35594 | 10.23 | September 6, 2022 |
| 10.17* | Amendment and Restated Employment Letter between Palo Alto Networks, Inc. and Nir Zuk, dated July 7, 2025. | 10-K | 001-35594 | 10.14 | August 29, 2025 |
| 10.18* | Offer Letter between the Registrant and Nikesh Arora, dated May 30, 2018. | 8-K | 001-35594 | 10.2 | June 4, 2018 |
| 10.19* | Offer Letter between the Registrant and Josh Paul, dated August 5, 2021. | 8-K | 001-35594 | 10.1 | September 8, 2021 |
| 10.20* | Confirmatory Employment Letter with Updated Change in Control Protection between the Registrant and Lee Klarich, dated December 19, 2011. | 10-Q | 001-35594 | 10.4 | November 30, 2018 |
| 10.21* | Addendum to Employment Offer Letter by and between the Registrant and Dipak Golechha, dated March 17, 2021. | 8-K | 001-35594 | 10.1 | March 19, 2021 |
| 10.22* | Addendum to Employment Offer Letter by and between the Registrant and Dipak Golechha, dated February 18, 2022. | 10-Q | 001-35594 | 10.1 | May 20, 2022 |
- 108 -
| Exhibit Number | Exhibit Description | Incorporated by ReferenceForm | Incorporated by ReferenceFile No. | Incorporated by ReferenceExhibit | Incorporated by ReferenceFiling Date |
|---|---|---|---|---|---|
| 10.23* | Employment Offer Letter by and between the Registrant and William “BJ” Jenkins, dated July 27, 2021. | 8-K | 001-35594 | 10.1 | August 12, 2021 |
| 10.24* | Addendum to Employment Offer Letter between the Registrant and William “BJ” Jenkins, dated February 18, 2022. | 10-Q | 001-35594 | 10.2 | May 20, 2022 |
| 10.25* | Form of Offer Letter between the Registrant and its directors. | 10-Q | 001-35594 | 10.2 | May 21, 2025 |
| 10.26** | Amended and Restated Flextronics Manufacturing Services Agreement, by and between the Registrant and Flextronics Telecom Systems Ltd., dated April 1, 2019. | 10-Q | 001-35594 | 10.1 | May 30, 2019 |
| 10.27 | Vendor Information Security Terms between the Registrant and Flextronics Telecom Systems Ltd., dated July 23, 2021. | 10-K | 001-35594 | 10.29 | September 3, 2021 |
| 10.28 | Lease between the Registrant and Santa Clara Campus Property Owner I LLC, dated May 28, 2015. | 10-K | 001-35594 | 10.29 | September 17, 2015 |
| 10.29 | Lease between the Registrant and Santa Clara Campus Property Owner I LLC, dated May 28, 2015. | 10-K | 001-35594 | 10.30 | September 17, 2015 |
| 10.30 | Lease between the Registrant and Santa Clara Campus Property Owner I LLC, dated May 28, 2015. | 10-K | 001-35594 | 10.31 | September 17, 2015 |
| 10.31 | Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated October 7, 2015. | 8-K/A | 001-35594 | 10.1 | October 19, 2015 |
| 10.32 | Amendment No. 1 to Lease by and between the Registrant and Santa Clara Phase I Property LLC, dated November 9, 2015. | 10-Q | 001-35594 | 10.2 | November 24, 2015 |
| 10.33 | Amendment No. 1 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated November 9, 2015. | 10-Q | 001-35594 | 10.3 | November 24, 2015 |
| 10.34 | Amendment No. 1 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated September 16, 2016. | 10-Q | 001-35594 | 10.1 | November 22, 2016 |
| 10.35 | Amendment No. 1 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated September 16, 2016. | 10-Q | 001-35594 | 10.2 | November 22, 2016 |
| 10.36 | Amendment No. 2 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated September 16, 2016. | 10-Q | 001-35594 | 10.3 | November 22, 2016 |
| 10.37 | Amendment No. 2 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated November 16, 2016. | 10-Q | 001-35594 | 10.1 | March 1, 2017 |
| 10.38 | Amendment No. 2 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated November 16, 2016. | 10-Q | 001-35594 | 10.2 | March 1, 2017 |
| 10.39 | Amendment No. 3 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated November 16, 2016. | 10-Q | 001-35594 | 10.3 | March 1, 2017 |
- 109 -
| Exhibit Number | Exhibit Description | Incorporated by ReferenceForm | Incorporated by ReferenceFile No. | Incorporated by ReferenceExhibit | Incorporated by ReferenceFiling Date |
|---|---|---|---|---|---|
| 10.40 | Amendment No. 3 to Lease by and between the Registrant and Santa Clara EFH LLC, dated June 22, 2017. | 10-K | 001-35594 | 10.40 | September 7, 2017 |
| 10.41 | Amendment No. 3 to Lease by and between the Registrant and Santa Clara G LLC, dated June 22, 2017. | 10-K | 001-35594 | 10.41 | September 7, 2017 |
| 10.42 | Amendment No. 4 to Lease by and between the Registrant and Santa Clara EFH LLC, dated June 22, 2017. | 10-K | 001-35594 | 10.42 | September 7, 2017 |
| 10.43 | Amendment No. 4 to Lease by and between the Registrant and Santa Clara Phase III EFH LLC, dated September 29, 2017. | 10-Q | 001-35594 | 10.5 | November 21, 2017 |
| 10.44 | Amendment No. 4 to Lease by and between the Registrant and Santa Clara Phase III G LLC, dated September 29, 2017. | 10-Q | 001-35594 | 10.6 | November 21, 2017 |
| 10.45 | Amendment No. 5 to Lease by and between the Registrant and Santa Clara Phase III EFH LLC, dated September 29, 2017. | 10-Q | 001-35594 | 10.7 | November 21, 2017 |
| 10.46 | Amendment No. 5 to Lease by and between the Company and Santa Clara Phase III EFH, LLC, dated April 8, 2026. | 8-K | 001-35594 | 10.1 | April 13, 2026 |
| 10.47 | Amendment No. 5 to Lease by and between the Company and Santa Clara Phase III G, LLC, dated April 8, 2026. | 8-K | 001-35594 | 10.2 | April 13, 2026 |
| 10.48 | Amendment No. 6 to Lease by and between the Company and Santa Clara Phase III EFH, LLC, dated April 8, 2026. | 8-K | 001-35594 | 10.3 | April 13, 2026 |
| 10.49 | Credit Agreement, dated as of April 13, 2023 among the Registrant, the lenders party thereto and Wells Fargo, National Association, as administrative agent. | 8-K | 001-35594 | 10.1 | April 19, 2023 |
| 10.50 | Amendment No. 1, dated as of November 22, 2024, to Credit Agreement, dated as of April 13, 2023, among Palo Alto Networks, Inc., the lenders party thereto, and Wells Fargo Bank, National Association, as administrative agent. | 10-Q | 001-35594 | 10.3 | February 14, 2025 |
| 10.51*^ | Executive Change in Control and Severance Policy. | 8-K | 001-35594 | 10.1 | August 21, 2026 |
| 19.1^ | Insider Trading Policy and Requirements for Trading Plans, as amended and restated. | 10-K | 001-35594 | 19.1 | August 29, 2025 |
| 21.1 | List of subsidiaries of the Registrant. | ||||
| 23.1 | Consent of Independent Registered Public Accounting Firm. | ||||
| 24.1 | Power of Attorney (contained in the signature page to this Annual Report on Form 10-K). | ||||
| 31.1 | Certification of the Chief Executive Officer pursuant to Section 302(a) of the Sarbanes-Oxley Act of 2002. | ||||
| 31.2 | Certification of the Chief Financial Officer pursuant to Section 302(a) of the Sarbanes-Oxley Act of 2002. |
- 110 -
| Exhibit Number | Exhibit Description | Incorporated by ReferenceForm | Incorporated by ReferenceFile No. | Incorporated by ReferenceExhibit | Incorporated by ReferenceFiling Date |
|---|---|---|---|---|---|
| 32.1† | Certification of Chief Executive Officer pursuant to 18 U.S.C. Section 1350, as adopted pursuant to Section 906 of the Sarbanes-Oxley Act of 2002. | ||||
| 32.2† | Certification of Chief Financial Officer pursuant to 18 U.S.C. Section 1350, as adopted pursuant to Section 906 of the Sarbanes-Oxley Act of 2002. | ||||
| 97.1 | Compensation Recovery Policy. | 10-K | 001-35594 | 97.1 | September 6, 2024 |
| 101.INS | XBRL Instance Document. | ||||
| 101.SCH | XBRL Taxonomy Schema Linkbase Document. | ||||
| 101.CAL | XBRL Taxonomy Calculation Linkbase Document. | ||||
| 101.DEF | XBRL Taxonomy Definition Linkbase Document. | ||||
| 101.LAB | XBRL Taxonomy Labels Linkbase Document. | ||||
| 101.PRE | XBRL Taxonomy Presentation Linkbase Document. | ||||
| 104 | Cover Page Interactive Data File (formatted as inline XBRL and contained in Exhibit 101). |
- Indicates a management contract or compensatory plan or arrangement.
^ Schedules (or similar schedules) have been omitted pursuant to Item 601(a)(5) of Regulation S-K. The Registrant agrees to furnish supplementally a copy of any omitted schedules (or similar attachments) to the SEC upon request; provided, however, that the Registrant may request confidential treatment pursuant to Rule 24b-2 of the Securities Exchange Act of 1934, as amended, for any schedules (or similar attachments) so furnished.
† The certifications attached as Exhibit 32.1 and Exhibit 32.2 that accompany this Annual Report on Form 10-K, are not deemed filed with the Securities and Exchange Commission and are not to be incorporated by reference into any filing of the Registrant under the Securities Act of 1933, as amended, or the Securities Exchange Act of 1934, as amended, whether made before or after the date of this Annual Report on Form 10-K, irrespective of any general incorporation language contained in such filing.
Item 16. Form 10-K Summary
Not applicable.