SEC EDGAR · 10-K

10-K – 2026-03-05 – crwd-20260131.htm

558009 tecken · 4 HTML-del(ar)

Fulltext som ren TXT · Öppna originalkällan

Automatiskt nyckeltalsindex

Detta är sökträffar och textkontext, inte verifierade eller normaliserade redovisningsvärden.

Omsättning
  • These forward-looking statements include, but are not limited to, statements concerning the following: | • our future financial performance, including our expectations regarding our revenue, cost of revenue, gross profit or gross margin, operating expenses (including changes in sales and marketing, research and development, and general and administrative expenses), and our ability to achieve, and maintain, future profitability; | • market acceptance of our cloud platform;
  • • the expected impacts of the Strategic Plan (as defined below). | These statements are based on our current plans, estimates and projections in light of information currently available to us. These forward-looking statements may be affected by risks, uncertainties and other factors discussed elsewhere in this Annual Report on Form 10-K, including under “Risk Factors.” Furthermore, new risks and uncertainties emerge from time to time, and it is impossible for us to predict all risks and uncertainties or how they may affect us. If any of these risks or uncertain | We intend to announce material information to the public through the CrowdStrike Investor Relations website ir.crowdstrike.com, SEC filings, press releases, public conference calls, and public webcasts. We use these channels, as well as social media and our blog, to communicate with our investors, customers, and the public about our company, our offerings, and other issues. It is possible that the information we post on social media and our blog could be deemed to be material information. As suc
  • Bringing CrowdStrike to the Market | We primarily sell the Falcon platform through our sales and partner teams that leverage our network of channel partners to maximize effectiveness and scale. We have a low friction land-and-expand sales strategy. Key elements of our growth strategy include: | • Growing Our Customer Base by Replacing Legacy and Other Endpoint Security Products. Given the limitations of existing legacy and other endpoint security products, many organizations are replacing their existing legacy and other endpoint security products with our Falcon platform. We will continue to invest in customer acquisition programs, including our channel partnerships and new programs, like our free trial program of Falcon Go that is easily downloaded from our website, the AWS Marketplac
  • • Leveraging Our Falcon Platform to Enter New Markets. Because we leverage a single data model and open cloud architecture, we are uniquely positioned to continue innovating and rapidly deploying new cloud modules on our platform. For example, Falcon Discover includes use cases outside of security, such as application license management, AWS spend analysis, and asset inventory. Because our lightweight sensor collects diverse endpoint data once for repeated use, we can expand our addressable mark | • Broadening Our Reach into New Customer Segments. While we initially targeted large sophisticated enterprises, we have expanded our go-to-market efforts to include customers of all sizes with a dedicated inside sales team focused on smaller organizations. We also released Falcon Complete in 2018, our turnkey solution that combines the most popular cloud modules of our Falcon platform with our remediation and response capabilities, to create a solution for customers with limited or no internal s | 11
  • • Broadening Our Reach into U.S. Public Sector Verticals. We continue to invest heavily in the acquisition of customers in the U.S. federal government as well as the state, local, and higher education verticals. Our platform is authorized by several federal agencies via the Federal Risk and Authorization Management Program (“FedRAMP”). Additionally, Department of Defense organizations can rely upon CrowdStrike’s Impact Level 5 provisional authorization to satisfy their cloud-based security requi | • Expanding Our International Footprint. We are expanding our international operations and intend to invest globally to broaden our international footprint. We grew our international revenue from $1,270.7 million for fiscal 2025 to $1,595.4 million for fiscal 2026, representing an increase of 26%. We intend to grow our international customer base by increasing our investments in our overseas operations, including adding headcount in Europe, the Middle East, Asia-Pacific, including Japan, and exp | • Extending Our Falcon Platform and Ecosystem. We designed our architecture to be open, interoperable, and highly extensible. We launched the CrowdStrike Marketplace, the first open cloud-based application PaaS for cybersecurity, which allows customers to purchase CrowdStrike products and provides an ecosystem of trusted partners and applications for our customers to choose from. We plan to continue investing in the CrowdStrike Store to empower our partners by making it easier to build applicati
  • Some of the world’s largest enterprises, government organizations, and high-profile brands trust us to protect their business. As of January 31, 2026, we are trusted by more than 88,000 organizations, including our end customers and those of our Managed Security Service Providers (“MSSPs”), worldwide. Historically, we and our channel partners have primarily sold to large organizations, but have increasingly focused on selling to small and medium-sized businesses, particularly through our trial-t | Sales and Marketing | Our sales and marketing organizations work together closely to drive market awareness, build a strong sales pipeline and cultivate customer relationships to drive revenue growth.
  • Sales and Marketing | Our sales and marketing organizations work together closely to drive market awareness, build a strong sales pipeline and cultivate customer relationships to drive revenue growth. | Sales
  • Our sales and marketing organizations work together closely to drive market awareness, build a strong sales pipeline and cultivate customer relationships to drive revenue growth. | Sales | We primarily sell subscriptions to our Falcon platform and cloud modules through our world-class, global sales team, which is comprised of field sales and inside sales professionals who are segmented by a customer’s organizational size. Our sales team also leverages a powerful go-to-market sales motion with our vast ecosystem of channel and alliances partners. We also use our sales team to identify current customers who may be interested in free trials of additional cloud modules, which serves a
Återkommande intäkter
  • Seasonality | Given the annual budget approval process of many of our customers, we see seasonal patterns in our business. Net new ARR generation is typically greater in the second half of the year, particularly in the fourth quarter, as compared to the first half of the year. In addition, we also experience seasonality in our operating margin, typically with a lower margin in the first half of our fiscal year due to a step up in costs for payroll taxes and annual sales and marketing events. This also impacts | Human Capital Resources
  • We monitor the following key metrics to help us evaluate our business, identify trends affecting our business, formulate business plans, and make strategic decisions. | Annual Recurring Revenue ( “ ARR ” ) | ARR is calculated as the annualized value of our customer subscription contracts as of the measurement date, assuming any contract that expires during the next 12 months is renewed on its existing terms. To the extent that we are negotiating a renewal with a customer after the expiration of the subscription, we continue to include that revenue in ARR if we are actively in discussion with such organization for a new subscription or renewal, or until such organization notifies us that it is not re
  • Annual Recurring Revenue ( “ ARR ” ) | ARR is calculated as the annualized value of our customer subscription contracts as of the measurement date, assuming any contract that expires during the next 12 months is renewed on its existing terms. To the extent that we are negotiating a renewal with a customer after the expiration of the subscription, we continue to include that revenue in ARR if we are actively in discussion with such organization for a new subscription or renewal, or until such organization notifies us that it is not re | The following table sets forth our ARR as of the dates presented (dollars in thousands):
  • ARR is calculated as the annualized value of our customer subscription contracts as of the measurement date, assuming any contract that expires during the next 12 months is renewed on its existing terms. To the extent that we are negotiating a renewal with a customer after the expiration of the subscription, we continue to include that revenue in ARR if we are actively in discussion with such organization for a new subscription or renewal, or until such organization notifies us that it is not re | The following table sets forth our ARR as of the dates presented (dollars in thousands): | As of January 31,
  • 2026 2025 | Annual recurring revenue $ 5,252,751 $ 4,241,838 | Year-over-year growth 24 % 23 %
  • ARR increased 24% year-over-year and grew to $5.3 billion as of January 31, 2026, of which $1.0 billion was net new ARR added during fiscal 2026. ARR increased 23% year-over-year and grew to $4.2 billion as of January 31, 2025, of which $806.7 million was net new ARR added during fiscal 2025. | Dollar-Based Net Retention Rate
  • Dollar-Based Net Retention Rate | Our dollar-based net retention rate compares our ARR from a set of subscription customers against the same metric for those subscription customers from the prior year. Our dollar-based net retention rate reflects customer renewals, expansion, contraction, and churn, and excludes revenue from our incident response and proactive services. We calculate our dollar-based net retention rate as of period end by starting with the ARR from all subscription customers as of 12 months prior to such period e | Our dollar-based net retention rate can fluctuate from period to period due to large customer contracts in a given period and incentives provided, which may reduce our dollar-based net retention rate in subsequent periods. In addition, if our customers are not able to fully utilize their product subscriptions (including in connection with our flexible subscription offering), we may experience increased contraction as such customers may elect to renew with shorter subscription periods, fewer clou
  • • On October 25, 2024, Delta Airlines, Inc. (“Delta”) filed a complaint against CrowdStrike, Inc. in the Superior Court for Fulton County, Georgia, alleging, among other things, computer trespass, trespass to personalty, breach of contract, intentional misrepresentation/fraud by omission, strict-liability product defect, gross negligence, and deceptive and unfair business practices. Delta is seeking unspecified monetary damages, attorneys’ fees and unspecified punitive damages. The matter has be | The Company has received requests for information from the U.S. Department of Justice and the U.S. Securities and Exchange Commission relating to the Company’s recognition of revenue and reporting of ARR for transactions with certain customers, the July 19 Incident and related matters. The Company is cooperating and providing information in response to these requests. | Additionally, some customers and third parties have asserted claims against the Company. The Company has also received inquiries from other governmental authorities and third parties related to the July 19 Incident. The Company is cooperating and providing information in connection with these inquiries.
Rörelseresultat
  • The preparation of financial statements in conformity with U.S. GAAP requires management to make estimates and assumptions that affect the amounts reported in our consolidated financial statements and accompanying notes. We base our estimates on historical experience and on various other assumptions that we believe to be reasonable under the circumstances, as discussed in the section titled “Management’s Discussion and Analysis of Financial Condition and Results of Operations.” The results of th | Additionally, we regularly monitor our compliance with applicable financial reporting standards and review new pronouncements and drafts thereof that are relevant to us. As a result of new standards, changes to existing standards and changes in their interpretation, we might be required to change our accounting policies, alter our operational policies and implement new or enhance existing systems so that they reflect new or amended financial reporting standards, or we may be required to restate | We are subject to risks associated with our equity investments, including partial or complete loss of invested capital, and significant changes in the fair value of this portfolio could adversely impact our financial results.
Periodens resultat
  • We have a history of losses, and while we have achieved profitability in certain periods, we may not be able to achieve or sustain profitability in the future. | We have incurred net losses each year prior to fiscal 2024, and we may not achieve or maintain profitability in the future. We experienced net losses of $162.5 million and $15.2 million for fiscal 2026 and 2025, respectively, and net income of $72.2 million for fiscal 2024 . As of January 31, 2026, we had an accumulated deficit of $1.3 billion. While we have experienced significant growth in revenue in recent periods, and have achieved profitability during certain periods, including fiscal 2024, | 23
  • Provision for Income Taxes. Provision for income taxes consists of state income taxes in the United States, foreign income taxes, and withholding taxes related to customer payments in certain foreign jurisdictions in which we conduct business. We maintain a full valuation allowance on our U.S. federal and state and certain foreign deferred tax assets, including net operating loss carryforwards and tax credits, which we have determined are not realizable on a more-likely-than-not basis. We regula | Net Income Attributable to Non-controlling Interest . Net income attributable to non-controlling interest consists of the Falcon Funds’ non-controlling interest share of gains and losses and interest income from our strategic investments.
  • Provision for income taxes 34,176 71,130 32,232 | Net income (loss) (161,165) (12,566) 73,439 | Net income attributable to non-controlling interest 1,337 2,675 1,258
  • Net income (loss) (161,165) (12,566) 73,439 | Net income attributable to non-controlling interest 1,337 2,675 1,258 | Net income (loss) attributable to CrowdStrike $ (162,502) $ (15,241) $ 72,181
  • Net income attributable to non-controlling interest 1,337 2,675 1,258 | Net income (loss) attributable to CrowdStrike $ (162,502) $ (15,241) $ 72,181
  • Provision for income taxes 1 % 2 % 1 % | Net income (loss) (3) % — % 2 % | Net income attributable to non-controlling interest — % — % — %
  • Net income (loss) (3) % — % 2 % | Net income attributable to non-controlling interest — % — % — % | Net income (loss) attributable to CrowdStrike (3) % — % 2 %
  • Net income attributable to non-controlling interest — % — % — % | Net income (loss) attributable to CrowdStrike (3) % — % 2 %
Resultat per aktie
  • The Company computes basic and diluted net income (loss) per share attributable to common stockholders using the two-class method required for participating securities. Under the two-class method, basic net income (loss) per share attributable to common stockholders is computed by dividing the net income (loss) attributable to common stockholders by the weighted-average number of shares of common stock outstanding during the period. On December 11, 2024, all of the Company’s outstanding shares o | Diluted earnings per share attributable to common stockholders adjusts basic earnings per share for the potentially dilutive impact of outstanding stock options, RSUs, PSUs, Special PSU Awards, ESPP obligations, and founder holdbacks. The dilutive potential shares are computed using the treasury stock method. The effects of the outstanding stock options, RSUs, PSUs, Special PSU Awards, ESPP obligations, and founders holdbacks are excluded from the computation of the diluted earnings per share in | Revision of Prior Period Financial Statements
Kassaflöde
  • • our ability to successfully expand in our existing markets and into new markets; | • sufficiency of cash and cash equivalents and cash flow from operations to meet cash needs for at least the next 12 months; | • anticipated developments relating to our valuation allowances for our deferred tax assets;
  • Seasonality | Given the annual budget approval process of many of our customers, we see seasonal patterns in our business. Net new ARR generation is typically greater in the second half of the year, particularly in the fourth quarter, as compared to the first half of the year. In addition, we also experience seasonality in our operating margin, typically with a lower margin in the first half of our fiscal year due to a step up in costs for payroll taxes and annual sales and marketing events. This also impacts | Human Capital Resources
  • revenue does not increase. We also have incurred and expect to continue to incur significant additional legal, accounting, and other expenses as a public company. Any failure to increase our revenue as we invest in our business or to manage our costs could prevent us from achieving or maintaining profitability or positive cash flow. | If organizations do not adopt cloud-based SaaS-delivered endpoint security solutions, our ability to grow our business and results of operations may be adversely affected.
  • Total cash, cash equivalents, and restricted cash shown in the consolidated statements of cash flows $ 5,314,617 $ 4,324,666 $ 3,377,597 | Supplemental disclosure of cash flow information: | Interest paid $ 22,500 $ 22,500 $ 22,500
Likvida medel
  • • our ability to successfully expand in our existing markets and into new markets; | • sufficiency of cash and cash equivalents and cash flow from operations to meet cash needs for at least the next 12 months; | • anticipated developments relating to our valuation allowances for our deferred tax assets;
  • We may need to raise additional capital to expand our operations and invest in new solutions, which capital may not be available on terms acceptable to us, or at all, and which could reduce our ability to compete and could harm our business. | We expect that the combination of our existing cash and cash equivalents and cash flows from operations will be sufficient to meet our anticipated cash needs for working capital and capital expenditures for at least the next 12 months. Retaining or expanding our current levels of personnel and product and service offerings may require additional funds to respond to business challenges, including the need to develop new products or services and enhancements to our Falcon platform, improve our ope | If we cannot maintain our company culture as we grow, we could lose the innovation, teamwork, passion, and focus on execution that we believe contribute to our success and our business may be harmed.
  • Interest Expense. Interest expense consists primarily of amortization of debt issuance costs, contractual interest expense for our Senior Notes issued in January 2021, and amortization of debt issuance costs on our revolving facility, which expired in January 2026. | Interest Income. Interest income consists primarily of income earned on our cash and cash equivalents. | Other Income (Expense), Net. Other income (expense), net consists primarily of gains and losses on strategic investments and foreign currency transaction gains and losses.
  • Liquidity and Capital Resources | Our primary sources of liquidity as of January 31, 2026, consisted of: (i) $5.2 billion in cash and cash equivalents, which mainly consists of cash on hand and highly liquid investments in money market funds, U.S. Treasury bills, and time deposits, and (ii) cash we expect to generate from operations. It is not currently possible to reasonably estimate the amount of loss or range of possible loss that might result from adverse judgments, settlements, penalties, or other resolution of proceedings | Our short-term and long-term liquidity requirements primarily arise from: (i) business acquisitions and investments we may make from time to time, (ii) working capital requirements, (iii) interest and principal payments related to our outstanding indebtedness, (iv) research and development and capital expenditure needs, and (v) license and service arrangements integral to our business operations. Our ability to fund these requirements will depend, in part, on our future cash flows, which are det
  • Interest Rate Risk | Our cash and cash equivalents primarily consist of cash on hand and highly liquid investments in money market funds, U.S. Treasury bills, and time deposits. Our investments do not have significant interest rate risk, as the yields on our investments are fixed rates. As of January 31, 2026, we had cash and cash equivalents of $5.2 billion. As of January 31, 2025, we had cash and cash equivalents of $4.3 billion. The primary objectives of our investment activities are the preservation of capital, | Our debt obligations consist of a variety of financial instruments that expose us to interest rate risk, including, but not limited to our Senior Notes. The interest rate on the Senior Notes is fixed.
  • Current assets: | Cash and cash equivalents $ 5,230,125 $ 4,323,295
  • Cash, cash equivalents, and restricted cash at the end of period: | Cash and cash equivalents $ 5,230,125 $ 4,323,295 $ 3,375,069 | Restricted cash included in prepaid expenses and other current assets 523 1,371 2,528
Nettoskuld
  • 2026 2025 2024 | Net cash provided by operating activities $ 1,612,349 $ 1,381,727 $ 1,166,207 | Net cash used in investing activities (764,479) (536,588) (340,650)
  • Net cash provided by operating activities $ 1,612,349 $ 1,381,727 $ 1,166,207 | Net cash used in investing activities (764,479) (536,588) (340,650) | Net cash provided by financing activities 132,452 107,208 93,158
  • Net cash used in investing activities (764,479) (536,588) (340,650) | Net cash provided by financing activities 132,452 107,208 93,158 | Net increase in cash, cash equivalents, and restricted cash 989,951 947,069 920,673
  • Operating Activities | Net cash provided by operating activities during fiscal 2026 was $1.6 billion, which resulted from net loss of $161.2 million, adjusted for non-cash charges of $1.8 billion and net cash outflow of $59.3 million from changes in operating assets and liabilities. Non-cash charges primarily consisted of $1.1 billion in stock-based compensation expense, $449.4 million of amortization of deferred contract acquisition costs, $250.2 million of depreciation and amortization, $31.2 million of amortization | Net cash provided by operating activities during fiscal 2025 was $1.4 billion, which resulted from net loss of $12.6 million, adjusted for non-cash charges of $1.4 billion and net cash outflow of $6.0 million from changes in operating assets and liabilities. Non-cash charges primarily consisted of $861.4 million in stock-based compensation expense, $318.8 million of amortization of deferred contract acquisition costs, $188.0 million of depreciation and amortization, $26.0 million of amortization
  • Net cash provided by operating activities during fiscal 2026 was $1.6 billion, which resulted from net loss of $161.2 million, adjusted for non-cash charges of $1.8 billion and net cash outflow of $59.3 million from changes in operating assets and liabilities. Non-cash charges primarily consisted of $1.1 billion in stock-based compensation expense, $449.4 million of amortization of deferred contract acquisition costs, $250.2 million of depreciation and amortization, $31.2 million of amortization | Net cash provided by operating activities during fiscal 2025 was $1.4 billion, which resulted from net loss of $12.6 million, adjusted for non-cash charges of $1.4 billion and net cash outflow of $6.0 million from changes in operating assets and liabilities. Non-cash charges primarily consisted of $861.4 million in stock-based compensation expense, $318.8 million of amortization of deferred contract acquisition costs, $188.0 million of depreciation and amortization, $26.0 million of amortization | 70
  • Investing Activities | Net cash used in investing activities during fiscal 2026 of $764.5 million was primarily due to business acquisitions, net of cash acquired, of $382.3 million, which was related to the Onum Technology Inc. and Pangea Cyber Corporation acquisitions, purchases of property and equipment of $302.1 million, capitalized internal-use software and website development costs of $68.8 million, purchases of strategic investments of $10.8 million, and purchases of deferred compensation investments of $6.0 mi | Net cash used in investing activities during fiscal 2025 of $536.6 million was primarily due to business acquisitions, net of cash acquired, of $310.3 million, which was related to the Flow Security and Adaptive Shield acquisitions, purchases of property and equipment of $254.9 million, capitalized internal-use software and website development costs of $59.0 million, purchases of strategic investments of $19.7 million, and purchases of deferred compensation investments of $2.7 million, partially
  • Net cash used in investing activities during fiscal 2026 of $764.5 million was primarily due to business acquisitions, net of cash acquired, of $382.3 million, which was related to the Onum Technology Inc. and Pangea Cyber Corporation acquisitions, purchases of property and equipment of $302.1 million, capitalized internal-use software and website development costs of $68.8 million, purchases of strategic investments of $10.8 million, and purchases of deferred compensation investments of $6.0 mi | Net cash used in investing activities during fiscal 2025 of $536.6 million was primarily due to business acquisitions, net of cash acquired, of $310.3 million, which was related to the Flow Security and Adaptive Shield acquisitions, purchases of property and equipment of $254.9 million, capitalized internal-use software and website development costs of $59.0 million, purchases of strategic investments of $19.7 million, and purchases of deferred compensation investments of $2.7 million, partially | Financing Activities
  • Financing Activities | Net cash provided by financing activities of $132.5 million during fiscal 2026 was primarily due to proceeds from our employee stock purchase plan of $125.8 million, capital contributions from non-controlling interests of $6.0 million, and proceeds from the exercise of stock options of $3.2 million, partially offset by distributions to non-controlling interest holders of $2.5 million. | Net cash provided by financing activities of $107.2 million during fiscal 2025 was primarily due to proceeds from our employee stock purchase plan of $99.6 million, capital contributions from non-controlling interest holders of $8.5 million, and proceeds from the exercise of stock options of $4.0 million, partially offset by distributions to non-controlling interest holders of $4.9 million.
Eget kapital
  • There was no impact to the consolidated statements of cash flows from operating activities, investing activities, or financing activities for any period. The impact to the consolidated statements of comprehensive income (loss) is limited to the impact to Net income (loss) as detailed above. The impact to the consolidated statements of stockholders' equity is to Additional paid-in capital and Accumulated deficit for the same amounts as detailed above, with no resulting impact on Total stockholder
  • Consolidated Statements of Stockholders’ Equity for the years ended January 31, 2026, 2025 and 2024 | 85
  • Opinions on the Financial Statements and Internal Control over Financial Reporting | We have audited the accompanying consolidated balance sheets of CrowdStrike Holdings, Inc. and its subsidiaries (the “Company”) as of January 31, 2026 and 2025, and the related consolidated statements of operations, of comprehensive income (loss), of stockholders’ equity and of cash flows for each of the three years in the period ended January 31, 2026, including the related notes (collectively referred to as the “consolidated financial statements”). We also have audited the Company’s internal c | In our opinion, the consolidated financial statements referred to above present fairly, in all material respects, the financial position of the Company as of January 31, 2026 and 2025, and the results of its operations and its cash flows for each of the three years in the period ended January 31, 2026 in conformity with accounting principles generally accepted in the United States of America. Also in our opinion, the Company maintained, in all material respects, effective internal control over f
  • Total assets $ 11,086,684 $ 8,701,578 | Liabilities and Stockholders’ Equity | Current liabilities:
  • Commitments and contingencies (Note 10) | Stockholders’ Equity | Preferred stock, $ 0.0005 par value; 100,000 shares authorized as of January 31, 2026 and January 31, 2025; no shares issued and outstanding as of January 31, 2026 and January 31, 2025.
  • Accumulated other comprehensive income (loss) 16,756 ( 9,593 ) | Total CrowdStrike Holdings, Inc. stockholders’ equity 4,428,390 3,279,494 | Non-controlling interest 44,215 39,423
  • Non-controlling interest 44,215 39,423 | Total stockholders’ equity 4,472,605 3,318,917 | Total liabilities and stockholders’ equity $ 11,086,684 $ 8,701,578
  • Total stockholders’ equity 4,472,605 3,318,917 | Total liabilities and stockholders’ equity $ 11,086,684 $ 8,701,578
Antal aktier
  • The aggregate market value of the common stock held by non-affiliates of the registrant, based on the closing price of a share of the registrant’s common stock on July 31, 2025 (the last business day of the registrant’s most recently completed second fiscal quarter) as reported by the Nasdaq Global Select Market on such date was approximately $ 109.3 billion. | As of February 28, 2026, the number of shares of the registrant’s Class A common stock outstanding was 253,614,090 . | DOCUMENTS INCORPORATED BY REFERENCE
  • Sales of substantial amounts of our common stock in the public markets, or the perception that they might occur, could reduce the price that our common stock might otherwise attain and may dilute your voting power and your ownership interest in us. | Sales of a substantial number of shares of our common stock in the public market, particularly sales by our directors, executive officers and significant stockholders, or the perception that these sales could occur, could adversely affect the market price of our common stock. As of February 28, 2026, we had 253,614,090 shares of Class A common stock outstanding. | We may also issue our shares of common stock or securities convertible into shares of our common stock from time to time in connection with a financing, acquisition, investments or otherwise. Any such issuance could result in substantial dilution to our existing stockholders and cause the market price of our common stock to decline.
  • Market Information for Common Stock | Our Class A common stock has been listed and traded on the Nasdaq Global Select Market under the symbol “CRWD” since June 12, 2019. Prior to that date, there was no public market for our Class A common stock. On December 11, 2024, all of our outstanding shares of Class B common stock automatically converted into an equal number of shares of Class A common stock pursuant to the provisions of the Amended and Restated Certificate of Incorporation. | Holders of Record
  • Net Income (Loss) per Share | The Company computes basic and diluted net income (loss) per share attributable to common stockholders using the two-class method required for participating securities. Under the two-class method, basic net income (loss) per share attributable to common stockholders is computed by dividing the net income (loss) attributable to common stockholders by the weighted-average number of shares of common stock outstanding during the period. On December 11, 2024, all of the Company’s outstanding shares o | Diluted earnings per share attributable to common stockholders adjusts basic earnings per share for the potentially dilutive impact of outstanding stock options, RSUs, PSUs, Special PSU Awards, ESPP obligations, and founder holdbacks. The dilutive potential shares are computed using the treasury stock method. The effects of the outstanding stock options, RSUs, PSUs, Special PSU Awards, ESPP obligations, and founders holdbacks are excluded from the computation of the diluted earnings per share in
  • Stock Incentive Plan | In May 2019, the Company’s board of directors adopted, and the stockholders approved the CrowdStrike Holdings, Inc. 2019 Equity Incentive Plan (the “2019 Plan”) with the purpose of granting stock-based awards to employees, directors, officers, and consultants, including stock options, restricted stock awards, RSUs, PSUs, and Special PSU Awards. A total of 8,750,000 shares of Class A common stock were initially available for issuance under the 2019 Plan. The Company’s compensation committee admin | The 2011 Plan was terminated on June 10, 2019, which was the business day prior to the effectiveness of the Company’s registration statement on Form S-1 used in connection with the Company’s initial public offering (“IPO”), and stock-based awards are no longer granted under the 2011 Plan. Any shares underlying stock options that expire, terminate, or are forfeited or repurchased under the 2011 Plan will be automatically transferred to the 2019 Plan.
  • (1) The performance adjustment represents adjustments in shares outstanding due to the actual achievement of performance-based awards, the achievement of which was based upon pre-defined financial performance targets. | (2) Excludes in progress PSUs and the 2026 Special PSU Award where pre-defined targets have not yet been achieved.
  • Employee Stock Purchase Plan | In May 2019, the board of directors adopted, and the stockholders approved, the CrowdStrike Holdings, Inc. 2019 Employee Stock Purchase Plan (“ESPP”), which became effective on June 10, 2019, which was the business day prior to the effectiveness of the Company’s registration statement on Form S-1 used in connection with the Company’s IPO. A total of 3,500,000 shares of Class A common stock were initially reserved for issuance under the ESPP. The Company’s compensation committee administers the E | The ESPP provides for consecutive offering periods that will typically have a duration of approximately 24 months in length and are comprised of four purchase periods of approximately six months in length. The offering periods are scheduled to start on the first trading day on or after June 11 and December 11 of each year. The first offering period commenced on June 11, 2019 and ended on June 10, 2021.
  • 13. Net Income (Loss) Per Share Attributable to Common Stockholders | Basic and diluted net income (loss) per share attributable to CrowdStrike’s common stockholders is computed in conformity with the two-class method required for participating securities. Basic net income (loss) per share attributable to CrowdStrike common stockholders is computed by dividing the net income (loss) attributable to CrowdStrike by the weighted-average number of shares of common stock outstanding during the period. Diluted net income per share attributable to CrowdStrike common stock | The rights of the holders of Class A and Class B common stock are identical, except with the respect to voting and conversion rights. As such, the undistributed earnings are allocated equally to each share of common stock without class distinction and the resulting basic and diluted net income (loss) per share attributable to CrowdStrike common stockholders are the same for shares of Class A and Class B common stock. On December 11, 2024, all of the Company’s outstanding shares of Class B common
Antal anställda
  • • our ability to successfully close and integrate acquisitions to contribute to our growth objectives; | • the attraction and retention of qualified employees and key personnel; | • the July 19 Incident (as defined below), including potential or anticipated developments, our remediation and other efforts in connection with the incident, the outcome of lawsuits, claims and inquiries related to the incident, our customer commitment packages, and the effect on our customer and partner relationships and our business, results of operations and financial condition; and
  • Generative AI : Innovations like Charlotte AI leverage generative AI and agentic reasoning to automate time-intensive tasks, enabling security analysts to work more efficiently. Charlotte AI transforms hours of routine investigation into minutes, addressing critical skills gaps and enhancing operational efficiency. Powered by the Falcon platform’s unique data advantage, Charlotte continues to evolve, delivering time savings and workflow automation to meet the demands of modern security operation | Securing AI : The Falcon platform provides comprehensive security from emerging threats and new attack surfaces for organizations implementing their own generative AI services and applications. AI Detection and Response (“AIDR”) provides visibility and governance into how employees use AI and how AI agents operate by mapping relationships between users, prompts, models, agents, and Model Context Protocol (“MCP”) servers, and enforcing policy across these relationships. Unstructured data is analy | 10
  • Intellectual Property | We believe that our intellectual property rights are valuable and important to our business. We rely on trademarks, patents, copyrights, trade secrets, license agreements, intellectual property assignment agreements, confidentiality procedures, non-disclosure agreements, and employee non-disclosure and invention assignment agreements to establish and protect our proprietary rights. Though we rely in part upon these legal and contractual protections, we believe that factors such as the skills and | We continue to grow our global portfolio of intellectual property rights in connection with our products, services, research and development, and other activities to protect our proprietary technology relevant to our business. We file patent applications to protect our intellectual property and believe that the duration of our issued patents is sufficient when considering the expected lives of our products. We intend to continue pursuing additional intellectual property protection to the extent
  • Human Capital Resources | As of January 31, 2026, we had 10,698 full-time employees. We also engage temporary employees and consultants as needed to support our operations. None of our employees in the United States are represented by a labor union or subject to a collective bargaining agreement. In certain countries in which we operate, we are subject to local labor law requirements which may automatically make our employees subject to industry-wide collective bargaining agreements. We have not experienced any work stop | Attraction, Retention, and Talent Development
  • Attraction, Retention, and Talent Development | Supporting our people is a foundational value for CrowdStrike. We believe the company’s success depends on our ability to attract, retain and develop employees. The skills, experience and industry knowledge of key employees significantly benefit our customers, operations and our overall company performance. | Our talent sourcing is aligned to our organizational strategy to provide the expertise and skills needed to move our mission forward. We have created a high-performance talent model that pinpoints the top traits and qualities we look for in talent and that may already exist within the organization, then consistently use that model to develop interview questions, screen candidates, and make hiring decisions.
  • • Organizational reputation and culture | We provide robust compensation and benefits programs to help meet the needs of our employees. In addition to base salary, these programs (which vary by country/region) include annual bonuses or commission plans, equity awards, an employee stock purchase plan, a 401(k) plan or pension schemes internationally, healthcare and insurance benefits, health savings and flexible spending accounts, paid time off, family leave, family care resources, flexible work schedules, adoption and infertility assist | 18
  • CrowdStrike has had a distributed workforce since its inception. While working remotely has its advantages, we also believe that building community and engagement happens at a faster pace when people can come together. | Since the beginning, we recognized that creating high-functioning, effective remote and hybrid teams would require careful planning and system design to not only establish the culture but help it grow and evolve organically. We have designed our processes, systems, and teams so that most employees can perform their jobs without needing to be physically present in the same room or even in the same time zone. Part of supporting our remote and hybrid culture also involves actively encouraging perso | Our People and Core Values
  • • We rely on our key technical, sales and management personnel to grow our business, and the loss of one or more key employees could harm our business. | • If we are unable to attract and retain qualified personnel, our business could be harmed.
Bruttomarginal
  • These forward-looking statements include, but are not limited to, statements concerning the following: | • our future financial performance, including our expectations regarding our revenue, cost of revenue, gross profit or gross margin, operating expenses (including changes in sales and marketing, research and development, and general and administrative expenses), and our ability to achieve, and maintain, future profitability; | • market acceptance of our cloud platform;
  • Professional Services Cost of Revenue. Professional services cost of revenue consists primarily of employee-related costs, such as salaries and bonuses, stock-based compensation expense, consulting expense, and an allocated portion of facilities and administrative costs. | Gross Profit and Gross Margin | Gross profit and gross margin have been and will continue to be affected by various factors, including the timing of our acquisition of new subscription customers, renewals from existing subscription customers, sales of additional modules to existing subscription customers, the data center and bandwidth costs associated with operating our cloud platform, the extent to which we expand our customer support and cloud operations organizations, and the extent to which we can increase the efficiency o
  • Gross Profit and Gross Margin | Gross profit and gross margin have been and will continue to be affected by various factors, including the timing of our acquisition of new subscription customers, renewals from existing subscription customers, sales of additional modules to existing subscription customers, the data center and bandwidth costs associated with operating our cloud platform, the extent to which we expand our customer support and cloud operations organizations, and the extent to which we can increase the efficiency o | Operating Expenses
  • Professional services revenue increased by $55.2 million, or 29%, in fiscal 2026 , as compared to fiscal 2025, which was primarily attributable to an increase in the number of professional service hours. | Cost of Revenue, Gross Profit, and Gross Margin | The following shows cost of revenue related to subscriptions and professional services for fiscal 2026, as compared to fiscal 2025 (in thousands, except percentages):
  • Professional services cost of revenue increased by $47.4 million, or 30%, in fiscal 2026 , as compared to fiscal 2025. The increase in professional services cost of revenue was primarily due to an increase in consulting expenses of $18.7 million, an increase in employee-related expenses of $15.5 million driven by a 12% increase in average headcount, an increase in stock-based compensation expense of $5.7 million, charges related to the Strategic Plan of $3.3 million, and an increase in allocated | The following shows gross profit and gross margin for subscriptions and professional services for fiscal 2026, as compared to fiscal 2025 (in thousands, except percentages): | Year Ended January 31, Change
  • 2026 2025 | Subscription gross margin 78 % 78 % — % | Professional services gross margin 18 % 19 % (1) %
  • Subscription gross margin 78 % 78 % — % | Professional services gross margin 18 % 19 % (1) % | Total gross margin 75 % 75 % — %
  • Professional services gross margin 18 % 19 % (1) % | Total gross margin 75 % 75 % — %

Fulltext

Dokumentet är delat för att hålla varje sida lätt att hämta. Del 1 · Del 2 · Del 3 · Del 4

crwd-20260131 0001535527 2026 FY false P4Y P3Y P1Y .25 P1Y http://fasb.org/us-gaap/2025#CostOfGoodsAndServicesSold http://fasb.org/us-gaap/2025#CostOfGoodsAndServicesSold http://fasb.org/us-gaap/2025#SellingAndMarketingExpense http://fasb.org/us-gaap/2025#ResearchAndDevelopmentExpense http://fasb.org/us-gaap/2025#GeneralAndAdministrativeExpense 469 365 165 iso4217:USD xbrli:shares iso4217:USD xbrli:shares crwd:user xbrli:pure crwd:reporting_unit crwd:installment crwd:day crwd:purchase_period crwd:change_in_contribution crwd:lawsuit crwd:position 0001535527 2025-02-01 2026-01-31 0001535527 2025-07-31 0001535527 us-gaap:CommonClassAMember 2026-02-28 0001535527 2026-01-31 0001535527 2025-01-31 0001535527 us-gaap:CommonClassAMember 2026-01-31 0001535527 us-gaap:CommonClassAMember 2025-01-31 0001535527 us-gaap:CommonClassBMember 2026-01-31 0001535527 us-gaap:CommonClassBMember 2025-01-31 0001535527 us-gaap:SubscriptionAndCirculationMember 2025-02-01 2026-01-31 0001535527 us-gaap:SubscriptionAndCirculationMember 2024-02-01 2025-01-31 0001535527 us-gaap:SubscriptionAndCirculationMember 2023-02-01 2024-01-31 0001535527 crwd:ProfessionalServicesMember 2025-02-01 2026-01-31 0001535527 crwd:ProfessionalServicesMember 2024-02-01 2025-01-31 0001535527 crwd:ProfessionalServicesMember 2023-02-01 2024-01-31 0001535527 2024-02-01 2025-01-31 0001535527 2023-02-01 2024-01-31 0001535527 us-gaap:CommonStockMember 2023-01-31 0001535527 us-gaap:AdditionalPaidInCapitalMember 2023-01-31 0001535527 us-gaap:RetainedEarningsMember 2023-01-31 0001535527 us-gaap:AccumulatedOtherComprehensiveIncomeMember 2023-01-31 0001535527 us-gaap:NoncontrollingInterestMember 2023-01-31 0001535527 2023-01-31 0001535527 us-gaap:CommonStockMember 2023-02-01 2024-01-31 0001535527 us-gaap:AdditionalPaidInCapitalMember 2023-02-01 2024-01-31 0001535527 us-gaap:RetainedEarningsMember 2023-02-01 2024-01-31 0001535527 us-gaap:NoncontrollingInterestMember 2023-02-01 2024-01-31 0001535527 us-gaap:AccumulatedOtherComprehensiveIncomeMember 2023-02-01 2024-01-31 0001535527 us-gaap:CommonStockMember 2024-01-31 0001535527 us-gaap:AdditionalPaidInCapitalMember 2024-01-31 0001535527 us-gaap:RetainedEarningsMember 2024-01-31 0001535527 us-gaap:AccumulatedOtherComprehensiveIncomeMember 2024-01-31 0001535527 us-gaap:NoncontrollingInterestMember 2024-01-31 0001535527 2024-01-31 0001535527 us-gaap:CommonStockMember 2024-02-01 2025-01-31 0001535527 us-gaap:AdditionalPaidInCapitalMember 2024-02-01 2025-01-31 0001535527 us-gaap:RetainedEarningsMember 2024-02-01 2025-01-31 0001535527 us-gaap:NoncontrollingInterestMember 2024-02-01 2025-01-31 0001535527 us-gaap:AccumulatedOtherComprehensiveIncomeMember 2024-02-01 2025-01-31 0001535527 us-gaap:CommonStockMember 2025-01-31 0001535527 us-gaap:AdditionalPaidInCapitalMember 2025-01-31 0001535527 us-gaap:RetainedEarningsMember 2025-01-31 0001535527 us-gaap:AccumulatedOtherComprehensiveIncomeMember 2025-01-31 0001535527 us-gaap:NoncontrollingInterestMember 2025-01-31 0001535527 us-gaap:CommonStockMember 2025-02-01 2026-01-31 0001535527 us-gaap:AdditionalPaidInCapitalMember 2025-02-01 2026-01-31 0001535527 us-gaap:RetainedEarningsMember 2025-02-01 2026-01-31 0001535527 us-gaap:NoncontrollingInterestMember 2025-02-01 2026-01-31 0001535527 us-gaap:AccumulatedOtherComprehensiveIncomeMember 2025-02-01 2026-01-31 0001535527 us-gaap:CommonStockMember 2026-01-31 0001535527 us-gaap:AdditionalPaidInCapitalMember 2026-01-31 0001535527 us-gaap:RetainedEarningsMember 2026-01-31 0001535527 us-gaap:AccumulatedOtherComprehensiveIncomeMember 2026-01-31 0001535527 us-gaap:NoncontrollingInterestMember 2026-01-31 0001535527 us-gaap:SubsequentEventMember 2026-02-01 2026-02-28 0001535527 crwd:TwoEndUsersMember us-gaap:CustomerConcentrationRiskMember us-gaap:FinanceReceivablesMember 2026-01-31 0001535527 crwd:TwoEndUsersMember us-gaap:CustomerConcentrationRiskMember us-gaap:FinanceReceivablesMember 2025-02-01 2026-01-31 0001535527 crwd:TwoEndUsersMember us-gaap:CustomerConcentrationRiskMember us-gaap:FinanceReceivablesMember 2025-01-31 0001535527 crwd:TwoEndUsersMember us-gaap:CustomerConcentrationRiskMember us-gaap:FinanceReceivablesMember 2024-02-01 2025-01-31 0001535527 crwd:AccelMember srt:MaximumMember crwd:CrowdstrikeFalconFundLlcMember 2019-07-31 0001535527 crwd:CrowdstrikeFalconFundLlcMember crwd:AccelMember 2019-07-01 2019-07-31 0001535527 crwd:AccelMember srt:MaximumMember crwd:CrowdstrikeFalconFundLlcMember 2021-12-31 0001535527 srt:MinimumMember 2026-01-31 0001535527 srt:MaximumMember 2026-01-31 0001535527 srt:MinimumMember us-gaap:ComputerEquipmentMember 2026-01-31 0001535527 srt:MaximumMember us-gaap:ComputerEquipmentMember 2026-01-31 0001535527 us-gaap:FurnitureAndFixturesMember 2026-01-31 0001535527 srt:MinimumMember crwd:PurchasedSoftwareMember 2026-01-31 0001535527 srt:MaximumMember crwd:PurchasedSoftwareMember 2026-01-31 0001535527 us-gaap:SoftwareDevelopmentMember 2026-01-31 0001535527 srt:MinimumMember 2025-02-01 2026-01-31 0001535527 srt:MaximumMember 2025-02-01 2026-01-31 0001535527 us-gaap:RestrictedStockUnitsRSUMember 2025-02-01 2026-01-31 0001535527 crwd:PerformanceBasedStockUnitsMember 2025-02-01 2026-01-31 0001535527 crwd:EmployeeStockPurchasePlanMember 2025-02-01 2026-01-31 0001535527 us-gaap:ShareBasedCompensationAwardTrancheOneMember 2025-02-01 2026-01-31 0001535527 us-gaap:ShareBasedCompensationAwardTrancheTwoMember 2025-02-01 2026-01-31 0001535527 us-gaap:ShareBasedCompensationAwardTrancheThreeMember 2025-02-01 2026-01-31 0001535527 crwd:ShareBasedPaymentArrangementTrancheFourMember 2025-02-01 2026-01-31 0001535527 2022-12-01 2022-12-31 0001535527 us-gaap:SeniorNotesMember 2026-01-31 0001535527 us-gaap:SeniorNotesMember 2025-01-31 0001535527 us-gaap:MoneyMarketFundsMember us-gaap:FairValueInputsLevel1Member 2026-01-31 0001535527 us-gaap:MoneyMarketFundsMember us-gaap:FairValueInputsLevel2Member 2026-01-31 0001535527 us-gaap:MoneyMarketFundsMember us-gaap:FairValueInputsLevel3Member 2026-01-31 0001535527 us-gaap:MoneyMarketFundsMember 2026-01-31 0001535527 us-gaap:MoneyMarketFundsMember us-gaap:FairValueInputsLevel1Member 2025-01-31 0001535527 us-gaap:MoneyMarketFundsMember us-gaap:FairValueInputsLevel2Member 2025-01-31 0001535527 us-gaap:MoneyMarketFundsMember us-gaap:FairValueInputsLevel3Member 2025-01-31 0001535527 us-gaap:MoneyMarketFundsMember 2025-01-31 0001535527 us-gaap:USTreasurySecuritiesMember us-gaap:FairValueInputsLevel1Member 2026-01-31 0001535527 us-gaap:USTreasurySecuritiesMember us-gaap:FairValueInputsLevel2Member 2026-01-31 0001535527 us-gaap:USTreasurySecuritiesMember us-gaap:FairValueInputsLevel3Member 2026-01-31 0001535527 us-gaap:USTreasurySecuritiesMember 2026-01-31 0001535527 us-gaap:USTreasurySecuritiesMember us-gaap:FairValueInputsLevel1Member 2025-01-31 0001535527 us-gaap:USTreasurySecuritiesMember us-gaap:FairValueInputsLevel2Member 2025-01-31 0001535527 us-gaap:USTreasurySecuritiesMember us-gaap:FairValueInputsLevel3Member 2025-01-31 0001535527 us-gaap:USTreasurySecuritiesMember 2025-01-31 0001535527 crwd:DeferredCompensationInvestmentsMember us-gaap:FairValueInputsLevel1Member 2026-01-31 0001535527 crwd:DeferredCompensationInvestmentsMember us-gaap:FairValueInputsLevel2Member 2026-01-31 0001535527 crwd:DeferredCompensationInvestmentsMember us-gaap:FairValueInputsLevel3Member 2026-01-31 0001535527 crwd:DeferredCompensationInvestmentsMember 2026-01-31 0001535527 crwd:DeferredCompensationInvestmentsMember us-gaap:FairValueInputsLevel1Member 2025-01-31 0001535527 crwd:DeferredCompensationInvestmentsMember us-gaap:FairValueInputsLevel2Member 2025-01-31 0001535527 crwd:DeferredCompensationInvestmentsMember us-gaap:FairValueInputsLevel3Member 2025-01-31 0001535527 crwd:DeferredCompensationInvestmentsMember 2025-01-31 0001535527 us-gaap:FairValueInputsLevel1Member 2026-01-31 0001535527 us-gaap:FairValueInputsLevel2Member 2026-01-31 0001535527 us-gaap:FairValueInputsLevel3Member 2026-01-31 0001535527 us-gaap:FairValueInputsLevel1Member 2025-01-31 0001535527 us-gaap:FairValueInputsLevel2Member 2025-01-31 0001535527 us-gaap:FairValueInputsLevel3Member 2025-01-31 0001535527 crwd:PrivatelyHeldEquitySecuritiesMember 2026-01-31 0001535527 crwd:PrivatelyHeldDebtAndOtherSecuritiesMember 2026-01-31 0001535527 crwd:PrivatelyHeldEquitySecuritiesMember 2025-01-31 0001535527 crwd:PrivatelyHeldDebtAndOtherSecuritiesMember 2025-01-31 0001535527 crwd:PrivatelyHeldEquitySecuritiesMember 2025-02-01 2026-01-31 0001535527 crwd:PrivatelyHeldEquitySecuritiesMember 2024-02-01 2025-01-31 0001535527 crwd:InternalRiskRatingOneToFourMember 2026-01-31 0001535527 crwd:InternalRiskRatingOneToFourMember 2025-01-31 0001535527 crwd:InternalRiskRatingFiveToSixMember 2026-01-31 0001535527 crwd:InternalRiskRatingFiveToSixMember 2025-01-31 0001535527 crwd:InternalRiskRatingSevenToNineMember 2026-01-31 0001535527 crwd:InternalRiskRatingSevenToNineMember 2025-01-31 0001535527 crwd:DataCenterAndOtherComputerEquipmentMember 2026-01-31 0001535527 crwd:DataCenterAndOtherComputerEquipmentMember 2025-01-31 0001535527 us-gaap:SoftwareDevelopmentMember 2025-01-31 0001535527 us-gaap:LeaseholdImprovementsMember 2026-01-31 0001535527 us-gaap:LeaseholdImprovementsMember 2025-01-31 0001535527 crwd:PurchasedSoftwareMember 2026-01-31 0001535527 crwd:PurchasedSoftwareMember 2025-01-31 0001535527 crwd:FurnitureAndEquipmentMember 2026-01-31 0001535527 crwd:FurnitureAndEquipmentMember 2025-01-31 0001535527 us-gaap:ConstructionInProgressMember 2026-01-31 0001535527 us-gaap:ConstructionInProgressMember 2025-01-31 0001535527 crwd:DataCenterAndOtherComputerEquipmentMember 2025-02-01 2026-01-31 0001535527 crwd:DataCenterAndOtherComputerEquipmentMember 2024-02-01 2025-01-31 0001535527 us-gaap:DevelopedTechnologyRightsMember 2026-01-31 0001535527 us-gaap:DevelopedTechnologyRightsMember 2025-02-01 2026-01-31 0001535527 us-gaap:CustomerRelationshipsMember 2026-01-31 0001535527 us-gaap:CustomerRelationshipsMember 2025-02-01 2026-01-31 0001535527 us-gaap:IntellectualPropertyMember 2026-01-31 0001535527 us-gaap:IntellectualPropertyMember 2025-02-01 2026-01-31 0001535527 us-gaap:DevelopedTechnologyRightsMember 2025-01-31 0001535527 us-gaap:DevelopedTechnologyRightsMember 2024-02-01 2025-01-31 0001535527 us-gaap:CustomerRelationshipsMember 2025-01-31 0001535527 us-gaap:CustomerRelationshipsMember 2024-02-01 2025-01-31 0001535527 us-gaap:IntellectualPropertyMember 2025-01-31 0001535527 us-gaap:IntellectualPropertyMember 2024-02-01 2025-01-31 0001535527 us-gaap:RevolvingCreditFacilityMember 2019-04-30 0001535527 us-gaap:LetterOfCreditMember 2019-04-30 0001535527 crwd:SwinglineFacilityMember 2019-04-30 0001535527 us-gaap:RevolvingCreditFacilityMember crwd:ARCreditAgreementMember 2021-01-04 0001535527 us-gaap:LetterOfCreditMember crwd:ARCreditAgreementMember 2021-01-04 0001535527 crwd:SwinglineFacilityMember crwd:ARCreditAgreementMember 2021-01-04 0001535527 crwd:AlternateBaseRateLoansMember us-gaap:FederalFundsEffectiveSwapRateMember crwd:ARCreditAgreementMember 2022-01-06 2022-01-06 0001535527 crwd:AlternateBaseRateLoansMember us-gaap:EurodollarMember crwd:ARCreditAgreementMember 2022-01-06 2022-01-06 0001535527 crwd:AlternateBaseRateLoansMember us-gaap:EurodollarMember crwd:ARCreditAgreementMember srt:MinimumMember 2022-01-06 2022-01-06 0001535527 crwd:AlternateBaseRateLoansMember us-gaap:EurodollarMember crwd:ARCreditAgreementMember srt:MaximumMember 2022-01-06 2022-01-06 0001535527 crwd:ARCreditAgreementMember srt:MinimumMember 2022-01-06 2022-01-06 0001535527 crwd:ARCreditAgreementMember srt:MaximumMember 2022-01-06 2022-01-06 0001535527 crwd:ARCreditAgreementMember 2026-01-31 0001535527 us-gaap:RevolvingCreditFacilityMember 2026-01-31 0001535527 crwd:A300SeniorNotesMember us-gaap:SeniorNotesMember 2021-01-20 0001535527 crwd:PlusMakeWholePremiumMember crwd:A300SeniorNotesMember us-gaap:DebtInstrumentRedemptionPeriodOneMember us-gaap:SeniorNotesMember 2021-01-20 2021-01-20 0001535527 crwd:ProceedsFromEquityOfferingProvidedPrincipalAmountOfRedemptionsDoesNotExceed40Member crwd:A300SeniorNotesMember us-gaap:DebtInstrumentRedemptionPeriodOneMember us-gaap:SeniorNotesMember 2021-01-20 2021-01-20 0001535527 crwd:A300SeniorNotesMember us-gaap:DebtInstrumentRedemptionPeriodTwoMember us-gaap:SeniorNotesMember 2021-01-20 2021-01-20 0001535527 crwd:A300SeniorNotesMember us-gaap:DebtInstrumentRedemptionPeriodThreeMember us-gaap:SeniorNotesMember 2021-01-20 2021-01-20 0001535527 crwd:A300SeniorNotesMember us-gaap:DebtInstrumentRedemptionPeriodFourMember us-gaap:SeniorNotesMember 2021-01-20 2021-01-20 0001535527 crwd:A300SeniorNotesMember us-gaap:SeniorNotesMember 2021-01-20 2021-01-20 0001535527 crwd:A300SeniorNotesMember us-gaap:SeniorNotesMember 2025-02-01 2026-01-31 0001535527 crwd:A300SeniorNotesMember us-gaap:SeniorNotesMember 2024-02-01 2025-01-31 0001535527 crwd:A300SeniorNotesMember us-gaap:DebtInstrumentRedemptionPeriodFiveMember us-gaap:SeniorNotesMember 2021-01-20 2021-01-20 0001535527 crwd:A300SeniorNotesMember us-gaap:SeniorNotesMember 2026-01-31 0001535527 crwd:A300SeniorNotesMember us-gaap:SeniorNotesMember 2025-01-31 0001535527 country:BR 2025-02-01 2026-01-31 0001535527 country:DK 2025-02-01 2026-01-31 0001535527 country:GB 2025-02-01 2026-01-31 0001535527 country:IL 2025-02-01 2026-01-31 0001535527 country:ES 2025-02-01 2026-01-31 0001535527 country:US 2025-02-01 2026-01-31 0001535527 country:AU 2025-02-01 2026-01-31 0001535527 country:IN 2025-02-01 2026-01-31 0001535527 us-gaap:ForeignTaxJurisdictionOtherMember 2025-02-01 2026-01-31 0001535527 country:US 2026-01-31 0001535527 stpr:CA 2026-01-31 0001535527 us-gaap:StateAndLocalJurisdictionMember 2026-01-31 0001535527 country:GB 2026-01-31 0001535527 crwd:EquityIncentivePlan2019Member us-gaap:CommonClassAMember 2019-05-31 0001535527 crwd:EquityIncentivePlan2019Member us-gaap:CommonClassAMember 2019-05-01 2019-05-31 0001535527 us-gaap:EmployeeStockOptionMember 2025-02-01 2026-01-31 0001535527 crwd:ServiceBasedRestrictedStockUnitsMember 2025-02-01 2026-01-31 0001535527 crwd:ServiceBasedRestrictedStockUnitsMember us-gaap:ShareBasedCompensationAwardTrancheOneMember 2025-02-01 2026-01-31 0001535527 crwd:ServiceBasedRestrictedStockUnitsMember us-gaap:ShareBasedCompensationAwardTrancheTwoMember 2025-02-01 2026-01-31 0001535527 crwd:ServiceBasedRestrictedStockUnitsMember us-gaap:ShareBasedCompensationAwardTrancheThreeMember 2025-02-01 2026-01-31 0001535527 crwd:ServiceBasedRestrictedStockUnitsMember crwd:ShareBasedPaymentArrangementTrancheFourMember 2025-02-01 2026-01-31 0001535527 us-gaap:RestrictedStockUnitsRSUMember 2026-01-31 0001535527 crwd:PerformanceBasedStockUnitsMember 2026-01-31 0001535527 crwd:SpecialPerformanceBasedStockUnitsMember us-gaap:SubsequentEventMember 2026-01-01 2026-03-05 0001535527 crwd:SpecialPerformanceBasedStockUnitsMember srt:MinimumMember us-gaap:SubsequentEventMember 2026-01-01 2026-03-05 0001535527 crwd:SpecialPerformanceBasedStockUnitsMember srt:MaximumMember us-gaap:SubsequentEventMember 2026-01-01 2026-03-05 0001535527 crwd:SpecialPerformanceBasedStockUnitsMember 2022-02-01 2023-01-31 0001535527 2022-02-01 2023-01-31 0001535527 crwd:SpecialPerformanceBasedStockUnitsMember us-gaap:ShareBasedCompensationAwardTrancheOneMember 2022-02-01 2023-01-31 0001535527 crwd:SpecialPerformanceBasedStockUnitsMember us-gaap:ShareBasedCompensationAwardTrancheTwoMember 2022-02-01 2023-01-31 0001535527 crwd:SpecialPerformanceBasedStockUnitsMember crwd:ShareBasedPaymentArrangementTrancheFiveMember 2022-02-01 2023-01-31 0001535527 crwd:SpecialPerformanceBasedStockUnitsMember us-gaap:ShareBasedCompensationAwardTrancheThreeMember 2022-02-01 2023-01-31 0001535527 crwd:SpecialPerformanceBasedStockUnitsMember crwd:ShareBasedPaymentArrangementTrancheFourMember 2022-02-01 2023-01-31 0001535527 srt:MinimumMember crwd:SpecialPerformanceBasedStockUnitsMember 2025-02-01 2026-01-31 0001535527 srt:MaximumMember crwd:SpecialPerformanceBasedStockUnitsMember 2025-02-01 2026-01-31 0001535527 crwd:SpecialPerformanceBasedStockUnitsMember 2026-01-31 0001535527 crwd:SpecialPerformanceBasedStockUnitsMember 2025-02-01 2026-01-31 0001535527 crwd:ShareBasedCompensationAwardOtherThanStockOptionsMember 2025-01-31 0001535527 crwd:ShareBasedCompensationAwardOtherThanStockOptionsMember 2025-02-01 2026-01-31 0001535527 crwd:ShareBasedCompensationAwardOtherThanStockOptionsMember 2026-01-31 0001535527 us-gaap:EmployeeStockMember us-gaap:CommonClassAMember 2019-05-31 0001535527 us-gaap:EmployeeStockMember 2019-05-01 2019-05-31 0001535527 us-gaap:EmployeeStockMember 2021-05-31 0001535527 us-gaap:EmployeeStockMember us-gaap:CommonClassAMember 2019-05-01 2019-05-31 0001535527 us-gaap:EmployeeStockMember 2025-02-01 2026-01-31 0001535527 crwd:RolloverFeatureMember us-gaap:EmployeeStockMember 2024-02-01 2025-01-31 0001535527 crwd:RolloverFeatureMember us-gaap:EmployeeStockMember 2025-02-01 2026-01-31 0001535527 crwd:RolloverFeatureMember us-gaap:EmployeeStockMember 2023-02-01 2024-01-31 0001535527 us-gaap:EmployeeStockMember 2026-01-31 0001535527 us-gaap:EmployeeStockMember 2025-01-31 0001535527 srt:MinimumMember us-gaap:EmployeeStockMember 2025-02-01 2026-01-31 0001535527 srt:MaximumMember us-gaap:EmployeeStockMember 2025-02-01 2026-01-31 0001535527 srt:MinimumMember us-gaap:EmployeeStockMember 2024-02-01 2025-01-31 0001535527 srt:MaximumMember us-gaap:EmployeeStockMember 2024-02-01 2025-01-31 0001535527 srt:MinimumMember us-gaap:EmployeeStockMember 2023-02-01 2024-01-31 0001535527 srt:MaximumMember us-gaap:EmployeeStockMember 2023-02-01 2024-01-31 0001535527 us-gaap:EmployeeStockMember 2024-02-01 2025-01-31 0001535527 us-gaap:EmployeeStockMember 2023-02-01 2024-01-31 0001535527 us-gaap:SubscriptionAndCirculationMember us-gaap:CostOfSalesMember 2025-02-01 2026-01-31 0001535527 us-gaap:SubscriptionAndCirculationMember us-gaap:CostOfSalesMember 2024-02-01 2025-01-31 0001535527 us-gaap:SubscriptionAndCirculationMember us-gaap:CostOfSalesMember 2023-02-01 2024-01-31 0001535527 crwd:ProfessionalServicesMember us-gaap:CostOfSalesMember 2025-02-01 2026-01-31 0001535527 crwd:ProfessionalServicesMember us-gaap:CostOfSalesMember 2024-02-01 2025-01-31 0001535527 crwd:ProfessionalServicesMember us-gaap:CostOfSalesMember 2023-02-01 2024-01-31 0001535527 us-gaap:SellingAndMarketingExpenseMember 2025-02-01 2026-01-31 0001535527 us-gaap:SellingAndMarketingExpenseMember 2024-02-01 2025-01-31 0001535527 us-gaap:SellingAndMarketingExpenseMember 2023-02-01 2024-01-31 0001535527 us-gaap:ResearchAndDevelopmentExpenseMember 2025-02-01 2026-01-31 0001535527 us-gaap:ResearchAndDevelopmentExpenseMember 2024-02-01 2025-01-31 0001535527 us-gaap:ResearchAndDevelopmentExpenseMember 2023-02-01 2024-01-31 0001535527 us-gaap:GeneralAndAdministrativeExpenseMember 2025-02-01 2026-01-31 0001535527 us-gaap:GeneralAndAdministrativeExpenseMember 2024-02-01 2025-01-31 0001535527 us-gaap:GeneralAndAdministrativeExpenseMember 2023-02-01 2024-01-31 0001535527 country:US 2025-02-01 2026-01-31 0001535527 country:US 2024-02-01 2025-01-31 0001535527 country:US 2023-02-01 2024-01-31 0001535527 us-gaap:EMEAMember 2025-02-01 2026-01-31 0001535527 us-gaap:EMEAMember 2024-02-01 2025-01-31 0001535527 us-gaap:EMEAMember 2023-02-01 2024-01-31 0001535527 srt:AsiaPacificMember 2025-02-01 2026-01-31 0001535527 srt:AsiaPacificMember 2024-02-01 2025-01-31 0001535527 srt:AsiaPacificMember 2023-02-01 2024-01-31 0001535527 crwd:OtherCountriesMember 2025-02-01 2026-01-31 0001535527 crwd:OtherCountriesMember 2024-02-01 2025-01-31 0001535527 crwd:OtherCountriesMember 2023-02-01 2024-01-31 0001535527 2026-02-01 2026-01-31 0001535527 2027-02-01 2026-01-31 0001535527 srt:MinimumMember 2027-02-01 2026-01-31 0001535527 srt:MaximumMember 2027-02-01 2026-01-31 0001535527 2024-11-06 2024-11-06 0001535527 2024-09-04 2024-09-20 0001535527 2024-11-21 0001535527 2025-04-10 2025-04-10 0001535527 2025-07-03 2025-07-17 0001535527 2025-11-01 2026-01-31 0001535527 us-gaap:UnfundedLoanCommitmentMember 2026-01-31 0001535527 country:US 2026-01-31 0001535527 country:US 2025-01-31 0001535527 country:DE 2026-01-31 0001535527 country:DE 2025-01-31 0001535527 us-gaap:NonUsMember 2026-01-31 0001535527 us-gaap:NonUsMember 2025-01-31 0001535527 crwd:PangeaCyberCorporationMember 2025-09-26 0001535527 crwd:PangeaCyberCorporationMember 2025-09-26 2025-09-26 0001535527 2025-09-26 2025-09-26 0001535527 crwd:PangeaCyberCorporationMember 2025-02-01 2026-01-31 0001535527 crwd:OnumTechnologyInc.Member 2025-09-12 0001535527 crwd:OnumTechnologyInc.Member 2025-09-12 2025-09-12 0001535527 2025-09-12 2025-09-12 0001535527 crwd:OnumTechnologyInc.Member us-gaap:DevelopedTechnologyRightsMember 2025-09-12 0001535527 crwd:OnumTechnologyInc.Member us-gaap:DevelopedTechnologyRightsMember 2025-09-12 2025-09-12 0001535527 crwd:OnumTechnologyInc.Member us-gaap:CustomerRelationshipsMember 2025-09-12 0001535527 crwd:OnumTechnologyInc.Member us-gaap:CustomerRelationshipsMember 2025-09-12 2025-09-12 0001535527 crwd:OnumTechnologyInc.Member 2025-02-01 2026-01-31 0001535527 crwd:A.S.AdaptiveShieldLtd.Member 2024-11-20 0001535527 crwd:A.S.AdaptiveShieldLtd.Member 2024-11-20 2024-11-20 0001535527 crwd:A.S.AdaptiveShieldLtd.Member us-gaap:DevelopedTechnologyRightsMember 2024-11-20 0001535527 crwd:A.S.AdaptiveShieldLtd.Member us-gaap:DevelopedTechnologyRightsMember 2024-11-20 2024-11-20 0001535527 crwd:A.S.AdaptiveShieldLtd.Member us-gaap:CustomerRelationshipsMember 2024-11-20 0001535527 crwd:A.S.AdaptiveShieldLtd.Member us-gaap:CustomerRelationshipsMember 2024-11-20 2024-11-20 0001535527 crwd:FlowSecurityMember 2024-03-26 0001535527 crwd:FlowSecurityMember 2024-03-26 2024-03-26 0001535527 crwd:FlowSecurityMember us-gaap:DevelopedTechnologyRightsMember 2024-03-26 2024-03-26 0001535527 crwd:RSUAndPSUMember 2025-02-01 2026-01-31 0001535527 crwd:RSUAndPSUMember 2024-02-01 2025-01-31 0001535527 crwd:RSUAndPSUMember 2023-02-01 2024-01-31 0001535527 us-gaap:EmployeeStockOptionMember 2025-02-01 2026-01-31 0001535527 us-gaap:EmployeeStockOptionMember 2024-02-01 2025-01-31 0001535527 us-gaap:EmployeeStockOptionMember 2023-02-01 2024-01-31 0001535527 us-gaap:EmployeeStockMember 2025-02-01 2026-01-31 0001535527 us-gaap:EmployeeStockMember 2024-02-01 2025-01-31 0001535527 us-gaap:EmployeeStockMember 2023-02-01 2024-01-31 0001535527 2025-05-06 2025-07-31 0001535527 crwd:SeverancePaymentsAndEmployeeBenefitsMember 2025-02-01 2026-01-31 0001535527 crwd:StockBasedCompensationAwardsMember 2025-02-01 2026-01-31 0001535527 crwd:NonEmployeeCostsMember 2025-02-01 2026-01-31 0001535527 crwd:CostOfRevenueSubscriptionMember 2025-02-01 2026-01-31 0001535527 crwd:CostOfRevenueProfessionalServicesMember 2025-02-01 2026-01-31 0001535527 us-gaap:EmployeeSeveranceMember 2025-01-31 0001535527 crwd:NonEmployeeCostsMember 2025-01-31 0001535527 us-gaap:EmployeeSeveranceMember 2025-02-01 2026-01-31 0001535527 us-gaap:EmployeeSeveranceMember 2026-01-31 0001535527 crwd:NonEmployeeCostsMember 2026-01-31 0001535527 srt:RevisionOfPriorPeriodErrorCorrectionAdjustmentMember 2023-01-31 0001535527 srt:ScenarioPreviouslyReportedMember 2025-01-31 0001535527 srt:RevisionOfPriorPeriodErrorCorrectionAdjustmentMember 2025-01-31 0001535527 us-gaap:SubscriptionAndCirculationMember srt:ScenarioPreviouslyReportedMember 2024-02-01 2025-01-31 0001535527 us-gaap:SubscriptionAndCirculationMember srt:RevisionOfPriorPeriodErrorCorrectionAdjustmentMember 2024-02-01 2025-01-31 0001535527 us-gaap:SubscriptionAndCirculationMember srt:ScenarioPreviouslyReportedMember 2023-02-01 2024-01-31 0001535527 us-gaap:SubscriptionAndCirculationMember srt:RevisionOfPriorPeriodErrorCorrectionAdjustmentMember 2023-02-01 2024-01-31 0001535527 crwd:ProfessionalServicesMember srt:ScenarioPreviouslyReportedMember 2024-02-01 2025-01-31 0001535527 crwd:ProfessionalServicesMember srt:RevisionOfPriorPeriodErrorCorrectionAdjustmentMember 2024-02-01 2025-01-31 0001535527 crwd:ProfessionalServicesMember srt:ScenarioPreviouslyReportedMember 2023-02-01 2024-01-31 0001535527 crwd:ProfessionalServicesMember srt:RevisionOfPriorPeriodErrorCorrectionAdjustmentMember 2023-02-01 2024-01-31 0001535527 srt:ScenarioPreviouslyReportedMember 2024-02-01 2025-01-31 0001535527 srt:RevisionOfPriorPeriodErrorCorrectionAdjustmentMember 2024-02-01 2025-01-31 0001535527 srt:ScenarioPreviouslyReportedMember 2023-02-01 2024-01-31 0001535527 srt:RevisionOfPriorPeriodErrorCorrectionAdjustmentMember 2023-02-01 2024-01-31 0001535527 us-gaap:CommonClassAMember us-gaap:SubsequentEventMember 2026-02-01 2026-03-04 0001535527 us-gaap:SubsequentEventMember 2026-03-04 0001535527 crwd:SGNLMember us-gaap:SubsequentEventMember 2026-02-20 0001535527 crwd:SGNLMember us-gaap:SubsequentEventMember 2026-02-20 2026-02-20 0001535527 crwd:SeraphicMember us-gaap:SubsequentEventMember 2026-02-03 0001535527 crwd:SeraphicMember us-gaap:SubsequentEventMember 2026-02-03 2026-02-03 0001535527 crwd:AnuragSahaMember crwd:AnuragSahaPlanAfterModificationMember 2025-11-01 2026-01-31 0001535527 crwd:MichaelSentonasMember crwd:MichaelSentonasPlanAfterModificationMember 2025-11-01 2026-01-31 0001535527 crwd:AnuragSahaMember crwd:AnuragSahaPlanPriorToModificationMember 2025-11-01 2026-01-31 0001535527 crwd:MichaelSentonasMember crwd:MichaelSentonasPlanPriorToModificationMember 2025-11-01 2026-01-31 0001535527 crwd:GeorgeKurtzMember 2025-11-01 2026-01-31 0001535527 crwd:GeorgeKurtzMember 2026-01-31 0001535527 crwd:MichaelSentonasMember crwd:MichaelSentonasPlanAfterModificationMember 2026-01-31 0001535527 crwd:AnuragSahaMember crwd:AnuragSahaPlanAfterModificationMember 2026-01-31 0001535527 2026-01-31 2025-02-01 2026-01-31

Table of Contents

UNITED STATES
SECURITIES AND EXCHANGE COMMISSION
WASHINGTON, D.C. 20549
___________________________________________________________________________________________________
FORM  10-K
___________________________________________________________________________________________________
(Mark One)
☑
ANNUAL REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934

For the fiscal year ended  January 31 , 2026
OR
☐
TRANSITION REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934

For the transition period from to
Commission File Number:  001-38933
___________________________________________________________________________________________________
CROWDSTRIKE HOLDINGS, INC.
(Exact Name of Registrant as Specified in Its Charter)
___________________________________________________________________________________________________
Delaware 45-3788918
(State or other jurisdiction of
incorporation or organization) (I.R.S. Employer
Identification Number)

206 E. 9th Street , Suite 1400 , Austin , Texas 78701
(Address of principal executive offices)
Registrant’s telephone number, including area code: ( 888 ) 512-8906
Securities registered pursuant to Section 12(b) of the Act:
Title of each class of securities Trading symbol(s) Name of each exchange on which registered
Class A common stock, par value $0.0005 per share CRWD The Nasdaq Stock Market LLC
(Nasdaq Global Select Market)

Securities registered pursuant to Section 12(g) of the Act:
None.
___________________________________________________________________________________________________
Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act of 1933, as amended. Yes ☑  No ☐
Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes ☐ No ☑
Indicate by check mark whether the registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yes ☑  No ☐
Indicate by check mark whether the registrant has submitted electronically every interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit and post such files)  Yes ☑    No ☐
Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See the definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company” and “emerging growth company” in Rule 12b-2 of the Exchange Act.

Large Accelerated Filer ☑ Accelerated Filer ☐

Non-accelerated Filer ☐
Smaller reporting company ☐

Emerging growth company ☐

If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐
Indicate by check mark whether the registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C. 7262(b)) by the registered public accounting firm that prepared or issued its audit report. ☑
If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements of the registrant included in the filing reflect the correction of an error to previously issued financial statements. ☑
Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the registrant’s executive officers during the relevant recovery period pursuant to §240.10D-1(b). ☑
Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Exchange Act). Yes ☐  No  ☑
The aggregate market value of the common stock held by non-affiliates of the registrant, based on the closing price of a share of the registrant’s common stock on July 31, 2025 (the last business day of the registrant’s most recently completed second fiscal quarter) as reported by the Nasdaq Global Select Market on such date was approximately $ 109.3 billion.
As of February 28, 2026, the number of shares of the registrant’s Class A common stock outstanding was  253,614,090 .
DOCUMENTS INCORPORATED BY REFERENCE
Portions of the registrant’s definitive Proxy Statement relating to its 2026 Annual Meeting of Stockholders are incorporated by reference into Part III of this Form 10-K where indicated. Such Proxy Statement will be filed with the United States Securities and Exchange Commission within 120 days after the end of the fiscal year to which this Annual Report on Form 10-K relates.

Table of Contents

CROWDSTRIKE HOLDINGS, INC.
TABLE OF CONTENTS
Page No.
Part I

Item 1.
Business
4

Item 1A.
Risk Factors
21

Item 1B.
Unresolved Staff Comments
56

Item 1C.
Cybersecurity
56

Item 2.
Properties
57

Item 3.
Legal Proceedings
57

Item 4.
Mine Safety Disclosures
57

Part II

Item 5.
Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities
58

Item 6.
[Reserved]
59

Item 7.
Management’s Discussion and Analysis of Financial Condition and Results of Operations
60

Item 7A.
Quantitative and Qualitative Disclosures about Market Risk
78

Item 8.
Financial Statements and Supplementary Data
79

Item 9.
Changes in and Disagreements with Accountants on Accounting and Financial Disclosure
124

Item 9A.
Controls and Procedures
125

Item 9B.
Other Information
125

Item 9C.
Disclosure Regarding Foreign Jurisdictions that Prevent Inspections
126

Part III

Item 10.
Directors, Executive Officers and Corporate Governance
126

Item 11.
Executive Compensation
126

Item 12.
Security Ownership of Certain Beneficial Owners and Management and Related Stockholder Matters
127

Item 13.
Certain Relationships and Related Transactions and Director Independence
127

Item 14.
Principal Accountant Fees and Services
127

Part IV

Item 15.
Exhibits and Financial Statement Schedules
127

Item 16.
Form 10-K Summary
127

Signatures
131

Power of Attorney
132

1

Table of Contents

SPECIAL NOTE REGARDING FORWARD-LOOKING STATEMENTS
This Annual Report on Form 10-K contains forward-looking statements within the meaning of the Securities Act of 1933, as amended (the “Securities Act”), the Securities Exchange Act of 1934, as amended (the “Exchange Act”), and the Private Securities Litigation Reform Act of 1995. All statements contained in this Annual Report on Form 10-K other than statements of historical fact, including statements regarding our future operating results and financial position, our business strategy and plans and our objectives for future operations, are forward-looking statements. The words “believe,” “may,” “will,” “potentially,” “estimate,” “continue,” “anticipate,” “intend,” “could,” “would,” “project,” “plan,” “expect” and similar expressions that convey uncertainty of future events or outcomes are intended to identify forward-looking statements.
These forward-looking statements include, but are not limited to, statements concerning the following:
• our future financial performance, including our expectations regarding our revenue, cost of revenue, gross profit or gross margin, operating expenses (including changes in sales and marketing, research and development, and general and administrative expenses), and our ability to achieve, and maintain, future profitability;
• market acceptance of our cloud platform;
• the effects of increased competition in our markets and our ability to compete effectively;
• our ability to maintain the security and availability of our cloud platform;
• our ability to maintain and expand our customer base, including by attracting new customers;
• our ability to develop new solutions, or enhancements to our existing solutions, and bring them to market in a timely manner;
• anticipated trends, growth rates and challenges in our business and in the markets in which we operate;
• our business plan and our ability to effectively manage our growth and associated investments;
• beliefs and objectives for future operations;
• our relationships with third parties, including channel partners and technology alliance partners;
• our ability to maintain, protect and enhance our intellectual property rights;
• our ability to successfully defend litigation brought against us and respond to government investigations and inquiries;
• our ability to successfully expand in our existing markets and into new markets;
• sufficiency of cash and cash equivalents and cash flow from operations to meet cash needs for at least the next 12 months;
• anticipated developments relating to our valuation allowances for our deferred tax assets;
• our ability to expand internationally;
• our ability to comply with laws and regulations that currently apply or become applicable to our business both in the United States and internationally;
• our ability to develop, maintain, and improve our internal control over financial reporting;
• macroeconomic factors, including inflation and instability in the global credit and financial markets;
2

Table of Contents

• our ability to successfully close and integrate acquisitions to contribute to our growth objectives;
• the attraction and retention of qualified employees and key personnel;
• the July 19 Incident (as defined below), including potential or anticipated developments, our remediation and other efforts in connection with the incident, the outcome of lawsuits, claims and inquiries related to the incident, our customer commitment packages, and the effect on our customer and partner relationships and our business, results of operations and financial condition; and
• the expected impacts of the Strategic Plan (as defined below).
These statements are based on our current plans, estimates and projections in light of information currently available to us. These forward-looking statements may be affected by risks, uncertainties and other factors discussed elsewhere in this Annual Report on Form 10-K, including under “Risk Factors.” Furthermore, new risks and uncertainties emerge from time to time, and it is impossible for us to predict all risks and uncertainties or how they may affect us. If any of these risks or uncertainties materialize, our business, revenue and financial results could be harmed, and the trading price of our Class A common stock could decline. Forward-looking statements made in this Annual Report on Form 10-K speak only as of the date on which such statements are made, and we undertake no obligation to update them in light of new information or future events, except as required by law.
We intend to announce material information to the public through the CrowdStrike Investor Relations website ir.crowdstrike.com, SEC filings, press releases, public conference calls, and public webcasts. We use these channels, as well as social media and our blog, to communicate with our investors, customers, and the public about our company, our offerings, and other issues. It is possible that the information we post on social media and our blog could be deemed to be material information. As such, we encourage investors, the media, and others to follow the channels listed above, including the social media channels listed on our investor relations website, and to review the information disclosed through such channels. Any updates to the list of disclosure channels through which we will announce information will be posted on the investor relations page on our website.

3

Table of Contents

PART I

ITEM 1. BUSINESS
Overview
Founded in 2011, CrowdStrike reinvented cybersecurity for the cloud and artificial intelligence (“AI”) era and transformed the way cybersecurity is delivered and experienced by customers. When we started CrowdStrike, cyberattackers had an asymmetric advantage over legacy cybersecurity products that could not keep pace with rapid changes in adversary tactics, a dynamic that has intensified as adversaries increasingly leverage automation, identity abuse, and AI to operate at machine speed.
We took a fundamentally different approach to solve this problem with the AI-native CrowdStrike Falcon cybersecurity platform, which serves as the operating system for cybersecurity. CrowdStrike built the first, true, cloud-native platform with AI at the core, capable of harnessing vast amounts of security and enterprise data to drive real-time security decisions and response – stopping breaches at scale through a single lightweight sensor.
The CrowdStrike Falcon platform is designed to be the definitive platform for cybersecurity consolidation, purpose-built to stop breaches. The platform’s single, lightweight sensor collects and integrates data from across the enterprise, including endpoints, cloud workloads, identities, and third-party sources. This data is ingested once and reused across multiple security functions, forming the foundation for detection, investigation, and response across the platform. We use this to train our AI to detect and prevent threats and drive workflow automation to give security teams machine speed advantage to stop adversaries. By consolidating and replacing legacy point products and fragmented platforms across key areas of security and IT, the Falcon platform delivers a unified, modern approach that increases capabilities, reduces complexity, and lowers costs – all while stopping breaches.
We believe our approach has defined a new category called the AI Security Cloud, which has the power to transform the cybersecurity industry the same way the cloud has transformed the customer relationship management, human resources, and service management industries. Using cloud-scale AI, our AI Security Cloud enriches and correlates trillions of cybersecurity events per week with indicators of attack, threat intelligence, and enterprise data (including data from across endpoints, workloads, identities, DevOps, IT assets, configurations and AI interactions). This data is continuously curated, labeled, and validated through real-world security operations, including managed detection and response, threat intelligence, and incident response activities, creating high-fidelity intelligence grounded in real adversary behavior and outcomes – cyber Reinforced Learning from Human Feedback (“RLHF”) at scale.
This intelligence is used to train and refine our AI models, enabling the Falcon platform to provide real-time context on adversary behavior, inform security decisions, and automatically prevent threats across our customer base. The more data that is fed into our Falcon platform, the more intelligent the AI Security Cloud becomes, the stronger our ability to anticipate and counter evolving adversary tradecraft, and the more our customers benefit, creating a powerful network effect that increases the overall value we provide.
CrowdStrike: The Architectural Purpose Behind the Platform
Our Falcon platform was purpose-built in the cloud to harness the power of data and AI to deliver the next generation of automated protection and provide threat hunters with the intelligence required to stop sophisticated attacks, including malware-free and fileless attacks. This approach has made CrowdStrike an industry leader in protection across endpoints, cloud workloads, identity data, and AI systems, delivering consistent security execution across hybrid and cloud environments, and allowing us to rapidly extend this best-in-class protection across new and emerging areas of enterprise risk.
Today, we offer 33 cloud modules on our Falcon platform via a SaaS subscription-based model that spans multiple large markets, including corporate endpoint and cloud workload security, managed security services, security and vulnerability management, IT operations management, identity protection, next-generation security information and event management (“SIEM”) and log management, threat intelligence services, data protection, SaaS security posture management, Security Orchestration, Automation and Response (“SOAR”) and AI powered workflow automation, and security for generative AI and AI-driven systems through AI detection and response.
4

Table of Contents

Our Falcon platform is composed of tightly integrated, proprietary technologies that enable us to deliver superior protection and performance, while reducing complexity for our customers. Our Falcon platform consists of our easily deployed, intelligent lightweight sensor, and our Enterprise Graph, which unifies our ground-breaking graph technologies into a single, connected intelligence layer.
Our single, lightweight-sensor approach has changed how organizations experience cybersecurity, delivering protection without impacting the user, resources or productivity. With the lightweight sensor installed on each endpoint and cloud workload, our Falcon platform automates detection and prevention capabilities in real time across our entire global customer base. This also enables our Falcon platform to intelligently ingest data once and stream high fidelity data back into the Security Cloud to be re-used for multiple use cases, continuously improve our Falcon platform’s AI algorithms and make its real-time decision-making faster and smarter to keep customers ahead of changing adversary tactics.
Our Enterprise Graph correlates and contextualizes the vast data of our Security Cloud to transform raw signals into authoritative security context, enabling us to collect data once and reuse it repeatedly to support real-time detection, investigation, and response across the platform. By creating a living, connected model of the enterprise, the Enterprise Graph makes signals immediately actionable by both AI-driven workflows and human analysts. The highly advanced graph technologies underpinning the Falcon platform include:
• Our Threat Graph, which uses a combination of AI and behavioral pattern-matching techniques to correlate and analyze trillions of cybersecurity events, enriched with threat intelligence, and third-party data to identify and link threat activity together to automatically prevent threats in real time across CrowdStrike’s global customer base. This also provides customers with increased visibility of attacks for proactive threat hunting and timely detection and remediation of novel threats.
• Our Intel Graph, which analyzes and correlates data and threat intelligence to visualize the connections between adversaries and attacks to help customers prioritize investigations and gain a deep understanding of the threat landscape. The latest intel on adversaries, tactics, techniques, and procedures is delivered seamlessly within the CrowdStrike Falcon platform and is mapped to the MITRE ATT&CK® framework.
• Our Asset Graph, which dynamically monitors and tracks the complex interactions among assets, providing a single holistic view of the risks those assets pose. Asset Graph provides graph visualizations of the relationships among all assets such as devices, users, accounts, applications, cloud workloads and operations technology, along with the rich context necessary for proper security hygiene and proactive security posture management to reduce risk in their organizations - without impacting IT.
The Falcon platform was purpose-built with the foresight that the future of cybersecurity would need to be cloud-native and AI-driven. While AI is revolutionizing many technology fields, including cybersecurity solutions, to be truly effective, algorithms that enable AI depend on the quality and volume of data that trains them and the selection of the right differentiating features from that data.
This is why we believe our Security Cloud and our cloud-native architecture creates a fundamental differentiator from our competitors. The expansive amount of high fidelity data crowdsourced and captured in our Security Cloud enables the continuous training of our algorithms. We call this cloud-scale AI. Our technology is uniquely effective because we not only have a massive amount of high fidelity data to continuously train our AI models but also because we couple that data with deep human cybersecurity expertise, which supports our industry-leading efficacy and low false positives.
By analyzing and correlating information across our massive, crowdsourced dataset, we are able to deploy our AI algorithms at cloud-scale and build a more intelligent, effective solution to detect threats and stop breaches that on-premise, cloud-hosted and hybrid products cannot match due to the inherent architectural limitations those products have with respect to data storage and analysis. The more data that is fed into our Falcon platform, the more intelligent the Security Cloud becomes, and the more our customers benefit, creating a powerful network effect that increases the overall value we provide.
5

Table of Contents

Industry Background: The Trends Driving a Need for a New Approach to Security
We believe there are a number of important trends that drive the need for a new approach to security. These include:
• The Increasing Speed, Sophistication and Disruption of Cybersecurity Threats : Adversary sophistication continues to increase as militaries and intelligence services of well-funded nation-states, technically advanced criminal organizations and hackers advance their tactics. In addition, the commoditization of technologies like generative AI makes it easier for low-skilled adversaries to move faster and launch more sophisticated attacks. This includes non-malware based attacks like social engineering that exploit user identities and credentials. These attacks are pervasive, targeting a broad range of industries including technology, transportation, healthcare, financial services, governments and political organizations, utility, retail, and public infrastructure. The number and scale of attacks continue to increase. The typical attack cycle starts with attackers attempting to penetrate endpoints to establish a beachhead. Once inside, adversaries steal and exploit legitimate credentials to escalate privileges, move laterally and progress and attack, often downloading malware or ransomware. At this stage in the threat lifecycle, the adversary is able to encrypt, destroy, or silently exfiltrate sensitive data.
• An Expanded Attack Surface Driven By Cloud, AI and Distributed Environments : Organizations everywhere are embracing digital transformation and are becoming more distributed as they adopt the cloud, increase workforce mobility, and grow their number of connected devices. They are adding more workloads to a myriad of different endpoints beyond the traditional cybersecurity perimeter, exposing an increasingly broad attack surface to adversaries. This trend accelerated significantly with the need to support an increasingly remote workforce in 2020 due to the COVID-19 pandemic and we believe this trend continues today.
• A Growing Cyber Skills Gap : Trained cybersecurity professionals are in high demand, and organizations continue to face a dire shortage of talent to fill much needed cybersecurity positions. As a result, existing cybersecurity teams are often overwhelmed by the velocity of cyberattacks and the operational burden created by fragmented tools, siloed data, and high volumes of low-fidelity alerts that require manual investigation and correlation across multiple systems. Adversaries exploit this complexity by accelerating attacks, while AI-enabled techniques compress response windows, increasing the need for automation and AI-driven security execution to keep pace.
• The Need to Reduce Complexity and Simplify Security Operations : Organizations are increasingly looking to reduce the complexity of their security and IT stack. Modern security requires fewer point products, fewer agents and technologies that consume fewer resources. Increasingly, organizations are looking to standardize on trusted platforms that deliver an immediate return on investment and lower total cost of ownership.
Competitive Market: Existing Security Solutions Are Limited and Exacerbate Ongoing Trends :
We believe the aforementioned trends are exacerbated by the architectural limitations of legacy cybersecurity products and fragmented platforms, which are characterized by:
• On-Premise Security and Bolt-On Cloud Products That Lead to Constrained and Impacted Users : On-premise products are siloed, lack integration, and have limited ability to collect, process, and analyze vast amounts of data—attributes that are required to be effective in today’s increasingly dynamic threat landscape. Meanwhile, these solutions often require more sensors on the endpoint as new capabilities are patchworked together, which can have a dramatic negative impact on user performance.
Many on-premise vendors have tried to solve this problem by simply extending on-premise products to the cloud. Since their products were not purpose built to run in the cloud, traditional on-premise issues such as complex deployments, data silos, lack of integrations, limited scalability, and high maintenance costs continue to manifest. We believe that any product that was originally designed for on-premise deployments and migrated to the cloud cannot by definition be a cloud native solution.
Some other vendors attempt to solve this problem by acquiring disparate products and stitching them together into fragmented platforms. This can force customers to focus on implementing integrations, not security outcomes and stopping the breach. The resulting complexity can impede workflows and slow down response time.
6

Table of Contents

• Legacy Signature-Based Products That Are Not Effective Against Unknown Threats : Signature-based products are designed to detect attacks that are already cataloged as previously identified threats. As a result, such products are fundamentally unable to prevent unknown threats resulting from shifts in attacker tradecraft. An attacker may be able to bypass a signature-based defense with just a slight modification to an existing attack. Many significant breaches seen in the last two decades have involved the failure of a legacy signature-based antivirus product to detect a previously unknown or modified version of a previously known attack.
• Malware-Focused Products That Miss Sophisticated Attacks : Traditionally, organizations have focused on protecting their networks and endpoints against malware-based attacks. These attacks involve malware built for the specific purpose of performing malicious activities, stealing data, or destroying systems. Our 2026 Global Threat Report observed that 82% of detections were malware-free. Therefore, a malware-centric defensive approach will leave the organization vulnerable to attacks that do not leverage malware.
• Application Whitelisting Products That Are Ineffective : Application whitelisting products resort to an “always allow” or “always block” policy on an endpoint to allow or prevent processes from executing. Whitelisting relies in part on manually creating and maintaining a complex list of rules, burdening end users and IT organizations. This does not prevent fileless attacks from exploiting legitimate whitelisted applications, compromising the integrity of the whitelisting product.
• The Limitations of Legacy SIEMs : Originally designed years or even decades ago for a vastly different cybersecurity landscape, legacy SIEM solutions struggle to meet the demands of modern security operations. These systems lack the scalability to handle today’s data volumes and adversary speed, while escalating costs make centralized data collection and retention increasingly difficult. Poor scalability contributes to siloed, disjointed SOC architectures, forcing analysts to manually correlate data across multiple consoles, diverting time and resources from threat detection and response. Complex onboarding processes further delay time-to-value, requiring significant effort to integrate new data sources. As a result, legacy SIEMs hinder operational efficiency, limit visibility, and increase the risk of data breaches.
CrowdStrike: Built for This Moment and the Future
We believe that the cloud-native architecture of the Falcon platform and Security Cloud provides a sustainable advantage in addressing the needs of our customers as their businesses and the threat landscape continues to evolve.
We offer our customers compelling business value that includes ease of adoption, rapid time-to-value, superior efficacy rates in detecting threats and preventing breaches, and reduced total cost of ownership by consolidating legacy, siloed, and multi-sensor security products in a single solution. We also allow thinly-stretched security organizations to automate previously manual tasks, freeing them to focus on their most important objectives. With the Falcon platform, organizations can transform how they combat threats, evolving from slow, manual, and reactionary to fast, automated, and predictive, while gaining visibility across the threat lifecycle.
Key benefits of our approach and the CrowdStrike Falcon platform include:
• The Power of the Crowd : Our crowdsourced data enables every customer to benefit from contributing to the Security Cloud. As more high fidelity data is fed into our Security Cloud, our AI models continue to train and improve, increasing the overall efficacy of the Falcon platform. This unique data layer is powered and turned into action by the Enterprise Graph. Enterprise Graph unifies our pioneering graph technologies (including Threat Graph, Intel Graph, and Asset Graph) into a living, connected model of the enterprise. This makes signals instantly actionable by both AI agents and human analysts to put threats, adversaries, and assets into the context needed to make the rapid, informed decisions that stop breaches.
• Driving AI Innovation and Security : We are a pioneer in leveraging AI to transform cybersecurity, combining AI for cybersecurity with cybersecurity for AI. The Falcon platform’s AI-native architecture uses advanced models and the power of the Security Cloud to detect and stop breaches, while innovations like Charlotte AI represent a significant advancement in agentic AI—delivering autonomous security decisions within customer-defined guardrails to triage detections, reduce noise, and accelerate response. Charlotte AI, powered by high-fidelity data and continual training, reduces routine investigation workloads, bridging critical skills gaps for
7

Table of Contents

stretched teams. As AI continues to evolve, CrowdStrike is driving the next generation of AI-powered agentic cybersecurity—enabling AI to act independently while ensuring human oversight and control. Beyond delivering AI-driven protection, we also secure the AI systems organizations depend on, helping customers safeguard generative AI applications and agents, protect sensitive data, and mitigate the risks posed by AI misconfigurations and vulnerabilities. By advancing AI innovation and security, we empower organizations to stay ahead of adversaries, increase operational efficiency, and securely embrace the AI-driven future.
• High Efficacy, Low False Positives : The vast telemetry of the Security Cloud and the best practices employed in continually training our AI models results in exceptionally high efficacy rates and low false positives, delivering proven performance in real-world scenarios.
• Consolidation of Siloed Products : Integrating and maintaining numerous security products creates blind spots that attackers can exploit, increases costs, and negatively impacts both end-user system performance and the experience of the security analyst. Our cloud-native platform gives customers a unified approach to address their most critical areas of risk seamlessly. We empower customers to rapidly deploy and scale industry leading technologies across Endpoint and Workspace Security, Identity Protection, Cloud Security, Next-Gen SIEM and Modern Log Management, Data Protection, Exposure Management, IT Automation, ITSecOps and Risk, Threat Intelligence, and SaaS Security Posture Management from a single platform.
• Reducing Sensor Bloat : Our single intelligent lightweight sensor enables frictionless deployment of our platform at scale, enabling customers to rapidly adopt our technology across any type of workload running on a variety of endpoints. The sensor is non-intrusive to the end user, requires no reboots and continues to protect the endpoint and track activity even when offline. Through our single lightweight sensor approach, customers can adopt multiple platform modules to address their critical areas of risk without burdening the endpoint with multiple sensors. Legacy approaches often require multiple sensors as they layer on new capabilities. This can severely impact user performance and create barriers to security.
• Rapid Time to Value : Our cloud-native platform was built to rapidly scale industry leading protection across the entire enterprise, eliminating lengthy implementation periods and professional services engagements that next-gen and legacy competitors may require. Our single sensor, collect once and re-use many times approach enables us to activate new modules in real time.
• Elite Security Teams as a Force Multiplier : Adversaries are relentlessly innovating new forms of sophisticated attacks, bypassing traditional malware to exploit user credentials and identities. In this evolving landscape, automation and autonomous security are no longer sufficient on their own. Stopping today’s sophisticated attacks requires a combination of powerful automation and elite threat hunting. Falcon Complete provides a comprehensive monitoring, management, response, and remediation solution to our customers and is designed to bring enterprise level security to companies that may lack the resources or expertise to do so on their own.
CrowdStrike Falcon OverWatch, part of CrowdStrike Counter Adversary Operations, combines world-class human intelligence from our elite security experts with the power of the Falcon platform. OverWatch is a force multiplier that extends the capabilities and improves the productivity of our customers’ security teams. Because our world-class team can see attacks across our entire customer base, their expertise is enhanced by their constant visibility into the threat landscape.
Furthermore, these elite security teams (including Falcon Complete, Falcon Overwatch, and our Professional Services teams) are key ingredients into the development of our automation and AI systems. New and increasingly sophisticated models are developed, benchmarked, and validated using data distilled from their operations. As these models gain capabilities and efficacy, our elite teams become more efficient in dealing with existing threats, which in turn allows for more focus on emerging and novel threats, which further enhances their models and automation systems, creating a positive feedback loop and data flywheel for our customers.
8

Table of Contents

• Alleviating the Skills Shortage through Automation : CrowdStrike automates manual tasks to free security teams to focus on their most important job – stopping the breach. Our Falcon Fusion capability automates workflows to reduce the need to switch between different security tools and tasks, while our Falcon Insight XDR and Falcon Next-Gen SIEM modules provide a unified solution that enables security teams to rapidly and efficiently identify, hunt, and eliminate threats across multiple security domains using first and third party datasets.
• Lower Total Cost of Ownership : Our cloud-native platform eliminates our customers’ need for initial or ongoing purchases of hardware and does not require their personnel to configure, implement or integrate disparate point products. Additionally, our comprehensive platform reduces overall personnel costs associated with ongoing maintenance, as well as the need for software patches and upgrades for separate products.
Securing Identities and Data Across the Pillars of Modern Enterprise Security
As modern attacks and adversaries grow more sophisticated, CrowdStrike believes that stopping breaches in the modern era requires security that delivers unified visibility and protection across three critical areas: Endpoint and Cloud workloads, Identity Threat Protection and Data Protection.
According to the CrowdStrike 2026 Global Threat Report, 82% of detections in 2025 were malware-free, reflecting a sustained shift toward hands-on-keyboard operations, abuse of legitimate tools, and credential-driven movement that are difficult to distinguish from normal use behavior. Stopping these advanced attacks requires a holistic approach that delivers true end-to-end protection across workloads, identities, and data. CrowdStrike is able to natively enforce protection at the device layer, the identity layer, and the data layer, extending our bold vision for security by driving modern Defense in Depth to the enterprise.
By delivering these powerful capabilities through a unified platform with a single sensor, CrowdStrike is able to connect the endpoint and workload to user identity, and the data that is being used and accessed. Customers can see the full health and state of endpoints and workloads, in context with the identity that is using and accessing them, aligned with where data is being created, who is using it, where it flows and how it is protected. CrowdStrike delivers this through a unified platform experience. This is how CrowdStrike believes security should and must be delivered today to combat advanced adversaries and stop breaches in the modern era. This means security solutions that are easy to deploy, easy to manage, and highly effective.
The CrowdStrike Falcon Platform: Built to Innovate and Scale
Our platform approach allows us to rapidly innovate, build, and deploy highly integrated modules that address critical customer problems and access additional market opportunities. Our Falcon platform is composed of two tightly integrated proprietary technologies: our lightweight sensor and our Security Cloud. Our cloud-delivered modules integrate seamlessly within the Falcon platform to provide customers with a unified set of cloud-delivered technologies across Endpoint and Workspace Security, Identity Protection, Cloud Security, Next-Gen SIEM and Modern Log Management, Data Protection, Exposure Management, IT Automation, ITSecOps and Risk, Threat Intelligence, and SaaS Security Posture Management.
The Falcon platform also encompasses recently acquired technologies where integration may be ongoing. We can rapidly and cost effectively develop and deliver additional cloud modules on our Falcon platform without the need for additional sensors, and are expanding options for our new customers to test modules on a trial basis as well as offering in-application trials for existing customers. Our expanding set of open APIs and the Foundry app development platform allow customers and partners to build their own capabilities on top of the Falcon platform.
Unifying data from our modules and customers into a single cloud infrastructure gives us significant advantages in developing and delivering innovative AI capabilities to detect and prevent threats, as well as improving user productivity and efficiency through cutting-edge generative AI systems such as our Charlotte AI module.
9

Table of Contents

CrowdStrike Falcon Platform: Unified Security Across Major Categories
Our cloud-native Falcon platform integrates seamlessly with our single lightweight sensor to deliver robust functionality across key areas of cybersecurity and IT operations. The Falcon platform delivered 32 cloud modules as of January 31, 2026 and currently delivers 33 cloud modules, enabling customers to address their most critical areas of risk with speed, confidence, and visibility through one unified platform. Key areas of focus include:
Endpoint Security : The Falcon platform offers next-generation antivirus, endpoint detection and response (“EDR”) and extended detection and response (“XDR”) to defend against malware, fileless attacks, and advanced threats. With cross-domain telemetry and unified incident management, we enable organizations to detect, investigate, and respond to threats across the security stack efficiently and effectively.
Cloud Security : CrowdStrike provides robust cloud security solutions to protect workloads, containers, and applications in real time. Our offerings include runtime protection, cloud security posture management, application security posture management and more to secure multi-cloud environments and enhance the resilience of cloud-native applications. By integrating seamlessly into developer workflows, we empower teams to shift security left and mitigate vulnerabilities before deployment.
Exposure Management : CrowdStrike’s exposure management solutions unify data from multiple sources, including IT hygiene, vulnerability management, and external attack surface management. These capabilities allow organizations to predict attack paths, prioritize remediation efforts, and proactively reduce their risk exposure. Real-time insights and guided actions empower customers to address vulnerabilities before they can be exploited.
Managed Detection and Response (“MDR”) : Falcon Complete Next-Gen MDR delivers a comprehensive managed security service subscription that combines 24/7 expert monitoring, investigation, response, and remediation to stop breaches across the entire attack lifecycle. Delivered by CrowdStrike’s team of security experts and powered by the AI-native Falcon platform, it combines industry-leading endpoint protection and extends managed protection across cloud security, identity protection, asset visibility, and Next-Gen SIEM, with 24/7 managed threat hunting from Falcon Adversary OverWatch for a full-stack MDR service. Falcon Complete Next-Gen MDR is also backed by an underwritten limited warranty policy, underscoring our commitment to breach protection and customer confidence.
Counter Adversary Operations : CrowdStrike’s Counter Adversary Operations include proactive threat hunting and intelligence capabilities. These solutions leverage the insights of elite security experts and the power of Threat Graph to identify and mitigate advanced threats, providing customers with actionable intelligence to strengthen their defenses.
Identity Protection : Identity protection solutions from CrowdStrike safeguard against identity-based attacks with real-time detection, behavioral analytics, and policy enforcement. These capabilities provide visibility into anomalies and lateral movement, enabling organizations to defend their most critical assets.
Next-Generation SIEM and Log Management : CrowdStrike’s Next-Gen SIEM and log management solutions deliver AI-driven detection, advanced data pipelining, centralized case management, investigation, and response capabilities, alongside high-performance log management for any data source. This comprehensive approach enhances security operations and enables organizations to respond to threats with speed and precision.
Generative AI : Innovations like Charlotte AI leverage generative AI and agentic reasoning to automate time-intensive tasks, enabling security analysts to work more efficiently. Charlotte AI transforms hours of routine investigation into minutes, addressing critical skills gaps and enhancing operational efficiency. Powered by the Falcon platform’s unique data advantage, Charlotte continues to evolve, delivering time savings and workflow automation to meet the demands of modern security operations.
Securing AI : The Falcon platform provides comprehensive security from emerging threats and new attack surfaces for organizations implementing their own generative AI services and applications. AI Detection and Response (“AIDR”) provides visibility and governance into how employees use AI and how AI agents operate by mapping relationships between users, prompts, models, agents, and Model Context Protocol (“MCP”) servers, and enforcing policy across these relationships. Unstructured data is analyzed for malicious actions such as prompt injection, and sensitive data can be automatically redacted to keep AI interactions safe and compliant.
10

Table of Contents

IT Automation : Falcon for IT converges security and IT operations, providing visibility into enterprise assets and enabling rapid resolution of issues. With generative AI workflows and automation capabilities, Falcon for IT empowers organizations to streamline IT processes, resolve operational challenges quickly, and maintain a secure and efficient infrastructure.
SaaS Security : Adaptive Shield, a CrowdStrike company, delivers continuous monitoring and proactive risk mitigation for business-critical SaaS applications. With context and visibility, organizations can address risks from users, devices, and non-human identities.
Data Protection : Falcon Data Protection prevents data theft by combining content with context, providing real-time visibility into sensitive data movement across endpoints, web applications, cloud drives, and USB storage devices. This modern approach empowers organizations to secure enterprise data without disrupting productivity, addressing the unique risks of the GenAI era.
Application Development : The Falcon Foundry no-code application development platform allows customers to quickly create their own apps to solve custom security and IT use-cases with full access to CrowdStrike’s data, threat intelligence, automation, and cloud-scale infrastructure.
Bringing CrowdStrike to the Market
We primarily sell the Falcon platform through our sales and partner teams that leverage our network of channel partners to maximize effectiveness and scale. We have a low friction land-and-expand sales strategy. Key elements of our growth strategy include:
• Growing Our Customer Base by Replacing Legacy and Other Endpoint Security Products. Given the limitations of existing legacy and other endpoint security products, many organizations are replacing their existing legacy and other endpoint security products with our Falcon platform. We will continue to invest in customer acquisition programs, including our channel partnerships and new programs, like our free trial program of Falcon Go that is easily downloaded from our website, the AWS Marketplace, the Google Marketplace, and the Microsoft Marketplace. We also increasingly work with Managed Service Providers (“MSPs”), and Managed Security Service Providers (“MSSPs”), who operate the Falcon platform on a customer’s behalf, acting as an outsourced security team to manage risk, products, and outcomes for customers.
• Further Penetrating Existing Customers. Our growth will depend in part on our ability to continue to expand our relationships with our customers by deploying on additional endpoints in their environment and cross-selling more cloud modules. When customers deploy our lightweight sensor, they can easily add additional cloud modules. We also offer in-application trial usage of additional modules to cross-sell to existing customers. While some new customers initially deploy our Falcon platform broadly across the organization, others elect to deploy only in selected business units and later deploy on additional endpoints and subscribe to additional modules. Over time, we seek to deploy our solution enterprise-wide for all customers. The power of our land-and-expand strategy is evidenced by our 115% dollar-based net retention rate as of January 31, 2026.
• Leveraging Our Falcon Platform to Enter New Markets. Because we leverage a single data model and open cloud architecture, we are uniquely positioned to continue innovating and rapidly deploying new cloud modules on our platform. For example, Falcon Discover includes use cases outside of security, such as application license management, AWS spend analysis, and asset inventory. Because our lightweight sensor collects diverse endpoint data once for repeated use, we can expand our addressable market by rapidly adding new cloud modules that leverage this data. We intend to continue to develop new cloud modules for broader endpoint use cases.
• Broadening Our Reach into New Customer Segments. While we initially targeted large sophisticated enterprises, we have expanded our go-to-market efforts to include customers of all sizes with a dedicated inside sales team focused on smaller organizations. We also released Falcon Complete in 2018, our turnkey solution that combines the most popular cloud modules of our Falcon platform with our remediation and response capabilities, to create a solution for customers with limited or no internal security expertise. As a result, we can sell our Falcon platform to the largest enterprises or smallest businesses with any level of security sophistication and budget. We continue to look for new ways to broaden our reach into new customer segments.
11

Table of Contents

• Broadening Our Reach into U.S. Public Sector Verticals. We continue to invest heavily in the acquisition of customers in the U.S. federal government as well as the state, local, and higher education verticals. Our platform is authorized by several federal agencies via the Federal Risk and Authorization Management Program (“FedRAMP”). Additionally, Department of Defense organizations can rely upon CrowdStrike’s Impact Level 5 provisional authorization to satisfy their cloud-based security requirements. To further meet the compliance demands of the government, customers can elect to deploy the Falcon platform in the AWS GovCloud. We have also successfully been embedded into several strategic government-wide cybersecurity programs and contracts, such as the Department of Homeland Security’s Continuous Diagnostics and Mitigation Approved Products List, which serves to provide federal agencies with innovative security tools. As a result, the Cybersecurity and Infrastructure Security Agency has leveraged a significant investment in our platform to support modernization efforts within the Federal Civilian Executive Branch. Further evidence of our progress into these critical markets is demonstrated by virtue of the fact that 25 of the 50 U.S. states have standardized on CrowdStrike’s platform at the enterprise level.
• Expanding Our International Footprint. We are expanding our international operations and intend to invest globally to broaden our international footprint. We grew our international revenue from $1,270.7 million for fiscal 2025 to $1,595.4 million for fiscal 2026, representing an increase of 26%. We intend to grow our international customer base by increasing our investments in our overseas operations, including adding headcount in Europe, the Middle East, Asia-Pacific, including Japan, and expanding data centers overseas.
• Extending Our Falcon Platform and Ecosystem. We designed our architecture to be open, interoperable, and highly extensible. We launched the CrowdStrike Marketplace, the first open cloud-based application PaaS for cybersecurity, which allows customers to purchase CrowdStrike products and provides an ecosystem of trusted partners and applications for our customers to choose from. We plan to continue investing in the CrowdStrike Store to empower our partners by making it easier to build applications and to enable our customers to more easily discover, try, and purchase additional cloud modules from both trusted partners and us. We also endeavor to work with more partners, new partner types, new technology companies, and new service providers to help more customer segments and new customers realize novel outcomes from the Falcon Platform.
Technology
We have designed an innovative architecture from the ground up to overcome the limitations of existing security products and deliver cloud-based solutions. The key design principles of our Falcon platform include:
Cloud Native Architecture. We built the Falcon platform entirely in and for the cloud, enabling collection and analysis of a massive, crowdsourced dataset from all of our customers to stop breaches. Our platform is designed to be redundant, resilient, and high-performing. Delivering security from the cloud enables agility, ease of use, and protection for workloads on a variety of endpoints wherever they are located. As customer adoption grows, the network effect of each additional endpoint added to the Falcon platform will amplify the breadth and depth of our dataset and intelligence.
Falcon Sensor. We designed an intelligent lightweight sensor that is installed on each endpoint or cloud workload. This sensor incorporates identification and prevention of known and unknown malware and fileless attacks using machine learning, AI, exploit blocking, and advanced behavioral techniques, to protect workloads across all endpoints while capturing and recording high fidelity endpoint data. Our sensor is capable of acting autonomously and continues to collect data and protect workloads running on endpoints even when offline. The sensor recommences transmitting data to our Falcon platform when the connection to the cloud has been re-established. Our lightweight sensor is built to support Windows, Mac, and Linux operating systems. The sensor is hardened against attacks and uses a combination of kernel and user-mode modules to collect and transmit high fidelity endpoint events as they take place on a system. It correlates these events using a local situational model on the endpoint, analyzes via agent-based AI models and is capable of taking a variety of preventative and responsive actions on the endpoint, either automatically or via human control. Events are streamed by the sensor to the cloud in real time in order to be further analyzed in the Threat Graph, where additional correlation and AI algorithms can be applied. The sensor is also capable of being remotely reconfigured in real time based on analytics in our cloud platform to collect and analyze different events or take other actions as risk and threat postures change.
12

Table of Contents

Threat Graph. Threat Graph is our proprietary, powerful, scalable, and dynamic graph database. Threat Graph continually looks for malicious activity by combining AI with behavioral pattern-matching techniques to look beyond file features and track the behaviors of every OS process and software program executed on an endpoint in a customer’s network environment. By applying powerful graph analytics and AI algorithms to cybersecurity, we enrich the data collected with our proprietary and third-party threat intelligence, such as adversary capabilities, motivations, attributions, and threat indicators. The graph data model allows our AI algorithms to identify relationships between events that are not directly related but which could indicate an attack that would otherwise remain undetected. We believe that our AI algorithms are advantaged by the rich proprietary dataset that we use to train them. Threat Graph provides customers with complete real time and historical visibility and insight into events occurring on their endpoints for hunting and searching, even if the endpoint is unreachable or no longer exists.
Threat Graph also provides query and hunting capability over the full set of high-fidelity events collected in the graph. This correlated data, natively represented in a graph structure, enables new products and cloud modules to be created rapidly since the platform provides the visibility, collection, correlation, and actions over data as reusable building blocks. This collect-once, use repeatedly approach is the reason why we have been able to deliver new cloud modules covering IT hygiene and vulnerability management quickly and enables us to continue expanding the Falcon platform rapidly in the future.
Intel Graph. Intel Graph analyzes and correlates massive amounts of data on adversaries, their victims and their tools, providing extraordinary insights into shifting adversary tactics and techniques, powering our adversary-focused approach with world-class threat intelligence.
Asset Graph. Asset Graph dynamically monitors and tracks the complex interactions among enterprise entities, providing a single holistic view of the risks those assets pose. Asset Graph provides graph visualizations of the relationships among entities and assets such as devices, users, accounts, cloud workloads, along with the rich context necessary for proper security hygiene and proactive security posture management to reduce risk in their organizations.
High Fidelity Data and Smart Filtering. The presence of a local graph model in our sensor enables it to track the state of the machine in real time, perform rapid machine learning and behavioral analysis, and provide efficient event streaming to the cloud. We call this “smart filtering.” This allows us to keep performance overhead on the endpoint to a minimum, dramatically reduce the bandwidth required for sensor-cloud communication, efficiently process large volumes of data, and separate signals from noise. The Falcon sensor collects and analyzes unfiltered data with local machine learning and behavioral algorithms on the endpoint but only streams high fidelity endpoint events to the cloud to just send what is necessary for detection, prevention and investigation of attacks. This smart filtering architecture allows us to reduce network load for our customers. The Falcon platform collects an array of high fidelity endpoint events, such as code execution, network, file system and user activity. This information can be used for a variety of use cases beyond security, such as IT operations and vulnerability management.
Management Interface. The Falcon platform management interface gives customers an intuitive and informative view of their complete environment, with timely alerts and detailed search capabilities. We provide real-time endpoint and cloud workload visibility to allow customers to review details and respond to threats instantly and effectively, from anywhere, and maintain an index of these events for future use.
APIs and Integrations. Our Falcon platform and architecture is built around a rich set of APIs that efficiently and effectively complement and expand a customer’s existing security infrastructure, such as security information event management, or SIEMs, intrusion prevention systems and intrusion detection systems. The platform includes streaming, query and batch APIs allowing customers and partners to integrate a variety of solutions seamlessly. It also includes rich management and control APIs. The platform allows third parties to develop additional cloud modules and features, furthering the power of the Falcon platform. By connecting existing security systems to the Falcon platform, we allow our customers to further leverage their security investments.
Data Center Operations
We have data center co-location facilities throughout the United States and in Europe, and we also utilize third-party data centers located in the United States and Europe. Our technology infrastructure, combined with select use of third-party resources, provides us with a distributed, resilient and scalable architecture on a global scale.
13

Table of Contents

Professional Services
In addition to our Falcon platform and cloud modules, we also offer incident response, forensic investigatory, and breach recovery services; technical assessment and strategic advisory services; Next-Gen SEIM consulting; platform deployment and operational services; as well as training and certifications to assist organizations that have experienced a breach or who are assessing their security posture and ability to respond to breaches.
• Incident Response, Forensics, and Recovery Services. Our incident response services typically begin by deploying our lightweight sensor to a customer’s endpoints or cloud workloads to provide visibility in order to determine if an attacker is currently in the environment, what assets have been compromised, and how much damage has been done. In addition to enriching the response team’s understanding of the attack, the full suite of Falcon platform’s next-gen prevention capabilities, cloud security, exposure management, and identity protection offerings can also be leveraged to help to slow down and prevent an active attacker from moving at-will throughout a compromised customer’s environment, increasing the risk and potential damage to the customer. We also provide customized surgical recovery services by providing the tools and staffing to eject attackers out of the network, lock down credentials from further use, remediate impacted systems and ensure adversaries stay out. In addition to providing valuable breach remediation to our customers, our incident response services also act as a strong lead generation engine for our Falcon platform, cloud, identity, Next-Gen SIEM, and many other modules. After experiencing the benefits of our platform firsthand, many of our incident response customers become subscription customers.
• Consulting Services. Our proactive consulting security services include technical assessment and strategic advisory services designed to help organizations understand their cyber maturity levels. These services include endpoint, identity, and cloud workload compromise assessments, cybersecurity maturity assessments, security program in-depth assessments, service organization control assessments, IT hygiene assessments, and active directory security assessments. We advise customers on readiness and preparation through the execution of table-top exercises, live fire exercises, red team/blue team assessments, and advanced adversary emulation exercises. We also offer AI red-teaming and other AI security services to help organizations understand where these emerging models introduce cyber risk, where they can be exploited, and where to take corrective security actions. All of these services are designed to evaluate our customers’ security profile so they can identify areas of vulnerability, secure their network, and improve their response if their defenses are breached. Our services also align to executive and board level cybersecurity priorities and are designed to help organizations effectively achieve cybersecurity risk reduction objectives and to maximize investments.
• Platform Professional Services. Our platform deployment and operational services are designed to help customers maximize the value of their investment in the CrowdStrike Falcon platform and transform their Security Operations Centers. These services provide seamless deployment of Falcon modules across endpoint, cloud, identity, Next-Gen SIEM and virtually every other module ensuring rapid time-to-value and alignment to CrowdStrike’s recommended security configurations to prevent breaches. For customers requiring deeper, hands-on expertise, we offer Resident Services with experts embedded directly with customer teams to provide tailored guidance, ongoing optimization, and support for evolving security needs. Our services are designed to accelerate time-to-value, enhance security posture, and ensure the long-term success of SIEM deployments within any organization. Additionally, our operational services provide tailored guidance and best practices to optimize platform performance, streamline workflows, and address specific cybersecurity challenges. The goal of these services are to empower organizations to fully operationalize CrowdStrike’s solutions, enhance security posture, and achieve measurable outcomes in cyber risk reduction with the Falcon platform.
• CrowdStrike University Training and Certification. We offer training and certification services to customers and partners on CrowdStrike technologies and cybersecurity topics to facilitate the adoption of CrowdStrike and to broaden and deepen their skills. CrowdStrike University is an online learning management system that organizes all CrowdStrike e-learning, instructor-led training and certification preparation courses in one place, providing a personalized learning experience for individuals who have an active training subscription. CrowdStrike currently offers proctored exam certifications through industry leading training partner Pearson Vue for our CrowdStrike Certified Falcon Administrator, Falcon Responder, Falcon Hunter, Cloud Specialist, Identity Specialist, and Next-Gen SIEM Engineer programs. Our offerings are designed to accommodate varying levels of proficiency from foundational concepts to advanced skills in threat detection, incident response, cloud security,
14

Table of Contents

intelligence and other proactive security operations aligned to the Falcon platform. Our training offerings provide a structured learning path to accelerate CrowdStrike adoption, drive operational success, and equip professionals with validated expertise in modern cybersecurity practices.
Customers
Some of the world’s largest enterprises, government organizations, and high-profile brands trust us to protect their business. As of January 31, 2026, we are trusted by more than 88,000 organizations, including our end customers and those of our Managed Security Service Providers (“MSSPs”), worldwide. Historically, we and our channel partners have primarily sold to large organizations, but have increasingly focused on selling to small and medium-sized businesses, particularly through our trial-to-pay model. We engage our customers through our global customer and technical advisory boards in which we solicit feedback from our customers on a regular basis allowing us to understand their evolving needs. We have used this feedback to develop new cloud modules, such as Falcon FileVantage, and we intend to continue to develop new cloud modules based on our customer’s feedback. Our business is not dependent on any particular end customer.
Sales and Marketing
Our sales and marketing organizations work together closely to drive market awareness, build a strong sales pipeline and cultivate customer relationships to drive revenue growth.
Sales
We primarily sell subscriptions to our Falcon platform and cloud modules through our world-class, global sales team, which is comprised of field sales and inside sales professionals who are segmented by a customer’s organizational size. Our sales team also leverages a powerful go-to-market sales motion with our vast ecosystem of channel and alliances partners. We also use our sales team to identify current customers who may be interested in free trials of additional cloud modules, which serves as a powerful driver of our land and expand model. By segmenting our sales teams, we can deploy a low-touch sales model that efficiently identifies prospective customers.
Marketing
Our marketing organization is focused on building our brand reputation, increasing the awareness and reputation of our platform, and driving customer demand. As part of these efforts, we deliver targeted content to demonstrate thought leadership in the security industry, including speaking engagements with the security industry’s foremost organizations to provide expert advice, issuing regular reports on the state of the industry, educating the public about cybersecurity threats, and identifying and naming adversary groups. We also engage in paid media, web marketing, industry and trade conferences (including our annual Fal.Con conference), analyst engagements, whitepaper development, demand generation via digital and web, and targeted displacement campaigns. We employ a wide range of digital programs, including search engine marketing, online and social media initiatives, and content syndication to increase traffic to our website and encourage prospective customers to sign up for a free trial of the Falcon platform. Additionally, we engage in joint marketing activities with our channel and technology alliance partners.
Partnership Ecosystem
We operate a partner-first go-to-market strategy to land new logos and expand in existing accounts. We partner with a diverse set of partners. We work with a wide array of go-to-market partners in our technology alliance partners to design go-to-market strategies that combine our platform with products and/or services provided by our technology alliance partners. These partner integrations deliver more secure solutions and an improved end user experience to their customers. Our technology alliance partnerships focus on security analytics, network and infrastructure security, threat platforms and orchestration, and automation. The CrowdStrike Store is an open cloud-based application PaaS for cybersecurity and the industry’s first unified security cloud ecosystem of trusted third-party applications. Falcon for AWS, available in the AWS Marketplace, allows customers to easily purchase and take advantage of the metered billing (pay-as-you-go) pricing option to scale their consumption as their business needs change. In addition to AWS, we bring CrowdStrike to market through Google Marketplace, and starting fiscal year 2027, the Microsoft Marketplace. We work with a vast network of resellers, distributors, MSSPs, MSPs, and global system integrators (“GSIs”) to deliver diverse customer experiences, tailored to the needs of the
15

Table of Contents

customer. Our best-in-class ecosystem helps us source new logos, expand within existing accounts, and maintain high renewal rates because we meet customers where they are and work with those they trust.
Research and Development
Our research and development organizations are responsible for the design, architecture, operation and quality of our cloud native Falcon platform. In addition, the research and development organizations work closely with our customer success teams to promote customer satisfaction.
Our success is a result of our continuous drive for innovation. Our internal team of security experts, researchers, intelligence analysts, and threat hunters continuously analyzes the evolving global threat landscape to develop products that defend against today’s most sophisticated and stealthy attacks and report on emerging security issues. We invest substantial resources in research and development to enhance our Falcon platform, and develop new cloud modules, features and functionality. We believe timely development of new, and enhancement of our existing products, services, and features is essential to maintaining our competitive position. We work closely with our customers and channel partners to gain valuable insight into their security management practices to assist us in designing new cloud modules and features that extend the capability of our platform. Our technical staff monitors and tests our software on a regular basis, and we also make our Falcon platform available for third-party validation. We also maintain a regular release process to update and enhance our existing solutions. In addition, we engage security consulting firms to perform periodic vulnerability analysis of our solutions.
Our research and development leadership team is predominantly located in the United States. We also maintain research and development centers internationally, including in Romania, Israel and India. We employ subject matter experts in a number of jurisdictions around the world. We plan to continue to dedicate significant resources to research and development.
Competition
We primarily compete with established and emerging security product vendors. While the market for traditional endpoint and IT operations solutions has historically been intensely competitive, we believe that the architecture of our cloud-native, single sensor platform fundamentally differentiates us compared to both next-gen and legacy competitors in the security industry. Additionally, as we look to enter into adjacent markets and expand our total addressable market, we may face new competitors. However, we do not believe any of our competitors currently have a true platform offering equivalent to the Falcon platform, which can be leveraged to win in legacy markets and define new categories.
Our competitors currently include the following by general category:
• legacy antivirus product providers who offer a broad range of approaches and solutions including traditional signature-based antivirus protection;
• alternative endpoint security providers who generally offer a mix of on-premises and cloud-hosted products that rely heavily on malware-only or application whitelisting techniques;
• network security vendors who are supplementing their core perimeter-based offerings with endpoint or cloud security solutions;
• cloud security vendors, including those who focus on public cloud infrastructure and services;
• identity security vendors that seek to identify and secure user accounts and related activities;
• professional service providers who offer cybersecurity response services; and
• legacy SIEM vendors who offer a range of log management and security capabilities.
We compete on the basis of a number of factors, including but not limited to our:
• ability to offer a unified and modular platform that enables rapid innovation, scaling, and deployment;
16

Table of Contents

• ability to identify security threats and prevent security breaches;
• ability to integrate with other participants in the security ecosystem;
• time to value, price, and total cost of ownership;
• brand awareness, reputation, and trust in the provider’s services;
• strength of sales, marketing, and channel partner relationships;
• customer support, incident response, and proactive services; and
• ability to rapidly ingest and search both first and third-party data.
Although certain of our competitors enjoy greater resources, recognition, deeper customer relationships, larger existing customer bases, or more mature intellectual property portfolios, we believe that we compete favorably with respect to these factors and that we are well positioned as a leading provider of endpoint and workload security solutions.
Intellectual Property
We believe that our intellectual property rights are valuable and important to our business. We rely on trademarks, patents, copyrights, trade secrets, license agreements, intellectual property assignment agreements, confidentiality procedures, non-disclosure agreements, and employee non-disclosure and invention assignment agreements to establish and protect our proprietary rights. Though we rely in part upon these legal and contractual protections, we believe that factors such as the skills and ingenuity of our employees and the functionality and frequent enhancements to our solutions are larger contributors to our success in the marketplace.
We continue to grow our global portfolio of intellectual property rights in connection with our products, services, research and development, and other activities to protect our proprietary technology relevant to our business. We file patent applications to protect our intellectual property and believe that the duration of our issued patents is sufficient when considering the expected lives of our products. We intend to continue pursuing additional intellectual property protection to the extent we believe it would be beneficial and cost-effective. Despite our efforts to protect our intellectual property rights, they may not be respected in the future, particularly in certain foreign jurisdictions where laws may not protect our proprietary rights as fully as in the United States, or may be invalidated, circumvented, or challenged. Our industry is characterized by the existence of a large number of patents and frequent claims and related litigation based on allegations of patent infringement or other violations of intellectual property rights. We believe that competitors will try to develop products that are similar to ours and that may infringe our intellectual property rights. Our competitors or other third-parties may also claim that our security platform and other solutions infringe their intellectual property rights. In particular, some companies in our industry have extensive patent portfolios. From time to time, third parties have in the past and may in the future assert claims of infringement, misappropriation and other violations of intellectual property rights against us or our customers, with whom our agreements may obligate us to indemnify against these claims. Successful claims of infringement by a third party could prevent us from offering certain products or features, require us to develop alternate, non-infringing technology, which could require significant time and during which we could be unable to continue to offer our affected products or solutions, require us to obtain a license, which may not be available on reasonable terms or at all, or force us to pay substantial damages, royalties, or other fees. For additional information, see the section titled “Risk Factors—Risks Related to Intellectual Property, Legal, and Regulatory Matters—The success of our business depends in part on our ability to protect and enforce our intellectual property rights.”
Backlog
We enter into both single and multi-year subscription contracts for our solutions. We generally invoice our subscription customers at the beginning of the subscription term, or in some instances, such as in multi-year arrangements, in installments. Until we have the contractual right to invoice, these contract amounts are classified as backlog. They are not recorded in deferred revenue or elsewhere in our consolidated financial statements. As of January 31, 2026, we had backlog of approximately $4.2 billion. We expect backlog will change from period to period for several reasons, including the timing and duration of customer agreements, varying billing cycles of subscription agreements, and the timing and duration of customer renewals. Because revenue for any period is a function of revenue recognized from deferred revenue under contracts in
17

Table of Contents

existence at the beginning of the period, as well as contract renewals and new customer contracts during the period, backlog at the beginning of any period is not necessarily indicative of future revenue performance. We do not utilize backlog as a key management metric internally.
Seasonality
Given the annual budget approval process of many of our customers, we see seasonal patterns in our business. Net new ARR generation is typically greater in the second half of the year, particularly in the fourth quarter, as compared to the first half of the year. In addition, we also experience seasonality in our operating margin, typically with a lower margin in the first half of our fiscal year due to a step up in costs for payroll taxes and annual sales and marketing events. This also impacts the timing of operating cash flow.
Human Capital Resources
As of January 31, 2026, we had 10,698 full-time employees. We also engage temporary employees and consultants as needed to support our operations. None of our employees in the United States are represented by a labor union or subject to a collective bargaining agreement. In certain countries in which we operate, we are subject to local labor law requirements which may automatically make our employees subject to industry-wide collective bargaining agreements. We have not experienced any work stoppages, and we consider our relations with our employees to be good.
Attraction, Retention, and Talent Development
Supporting our people is a foundational value for CrowdStrike. We believe the company’s success depends on our ability to attract, retain and develop employees. The skills, experience and industry knowledge of key employees significantly benefit our customers, operations and our overall company performance.
Our talent sourcing is aligned to our organizational strategy to provide the expertise and skills needed to move our mission forward. We have created a high-performance talent model that pinpoints the top traits and qualities we look for in talent and that may already exist within the organization, then consistently use that model to develop interview questions, screen candidates, and make hiring decisions.
CrowdStrike has always been a mission-focused organization. We hire and develop people based on their merits and alignment to our mission of stopping breaches. Our work requires us to consider problems from all angles. We believe that an open, collaborative environment strengthens our ability to build strong teams, serve our customers and drive innovation.
To attract high performers, we have a team dedicated to building and promoting our employer brand focused on creating a strong employer value proposition, which includes:
• Competitive pay and benefits
• Flexible working arrangements
• Roles and tasks designed for growth
• Professional development opportunities
• Organizational reputation and culture
We provide robust compensation and benefits programs to help meet the needs of our employees. In addition to base salary, these programs (which vary by country/region) include annual bonuses or commission plans, equity awards, an employee stock purchase plan, a 401(k) plan or pension schemes internationally, healthcare and insurance benefits, health savings and flexible spending accounts, paid time off, family leave, family care resources, flexible work schedules, adoption and infertility assistance, and employee assistance programs.
18

Table of Contents

We invest resources to develop the talent needed to remain a leader in cybersecurity. We deliver numerous training opportunities, provide rotational assignment opportunities, have expanded our focus on continuous learning and development, and ensure we manage performance, provide feedback, and develop talent.
Distributed Workforce
For CrowdStrike, the ability to work remotely or in a hybrid arrangement is a deliberate strategy that we believe fuels rapid innovation and helps us attract, hire and retain the best and brightest around the world, regardless of their specific location. Our culture is purpose-built around this ability, creating a competitive advantage for both the company and its customers and minimizing disruption from localized issues such as natural disasters, political events, or health emergencies.
CrowdStrike has had a distributed workforce since its inception. While working remotely has its advantages, we also believe that building community and engagement happens at a faster pace when people can come together.
Since the beginning, we recognized that creating high-functioning, effective remote and hybrid teams would require careful planning and system design to not only establish the culture but help it grow and evolve organically. We have designed our processes, systems, and teams so that most employees can perform their jobs without needing to be physically present in the same room or even in the same time zone. Part of supporting our remote and hybrid culture also involves actively encouraging personal well-being through initiatives, including wellness programs, engagement programs (speaker series, employee resource groups, gift exchanges, mentorship opportunities, virtual events, etc.), community outreach activities, recognition programs, and groups to connect people, no matter where they are geographically, with similar interests, life circumstances or backgrounds. We continue to find ways to bring our employees together to build community and camaraderie.
Our People and Core Values
At CrowdStrike, we embrace the mantra of “One Team. One Fight.” Our global team is passionate about working together toward our mission to stop breaches, knowing they will be fully included, supported and valued along the way. We are Fanatical About the Customer, Relentlessly Focused on Innovation and believe that our Limitless Passion drives Unlimited Potential for every CrowdStriker. Our Core Values sum up our culture. We provide the support and resources needed to enable people to do their best work.
Information about our Executive Officers
The following table sets forth certain information with respect to our current executive officers as of March 4, 2026:

Name Age Position
George Kurtz 55 President, Chief Executive Officer and Director

Burt W. Podbere 60 Chief Financial Officer

Michael Sentonas 52 President

There is no family relationship between any of our directors or executive officers and any other director or executive officer.
George Kurtz - President, Chief Executive Officer, and Director
Mr. Kurtz is one of our co-founders and has served as our President, Chief Executive Officer, and a member of our board of directors since November 2011. From October 2004 to October 2011, Mr. Kurtz served in executive roles at McAfee, Inc., a security technology company, including as Executive Vice President and Worldwide Chief Technology Officer from October 2009 to October 2011. In October 1999, Mr. Kurtz founded Foundstone, Inc., a security technology company, where he served as its Chief Executive Officer until it was acquired by McAfee, Inc. in October 2004. Since November 2017, he has also served as Chairman of the Board, and as President for the CrowdStrike Foundation, a nonprofit established to support the next generation of talent and research in cybersecurity and artificial intelligence through scholarships, grants, and other activities. He also served on the board of directors of Hewlett Packard Enterprise, an enterprise information technology company, from June 2019 to April 2023. Mr. Kurtz holds a B.S. in accounting from Seton Hall University. Mr. Kurtz also holds a CPA license from the State of New Jersey with an inactive status.
19

Table of Contents

Burt W. Podbere - Chief Financial Officer
Mr. Podbere has served as our Chief Financial Officer since September 2015. From May 2014 to August 2015, Mr. Podbere served as Chief Financial Officer for OpenDNS, Inc. (acquired by Cisco in 2015), a cloud-delivered network security company, where he oversaw the finance function. From October 2011 to April 2014, he served as Chief Financial Officer for Net Optics, Inc. (acquired by Ixia in 2013), a manufacturer of network monitoring and intelligent access solutions for physical and virtual networks. Since November 2017, he has also served as Treasurer and as a board member for the CrowdStrike Foundation, a nonprofit established to support the next generation of talent and research in cybersecurity and artificial intelligence through scholarships, grants, and other activities. Mr. Podbere is a Chartered Accountant and holds a B.A. from McGill University.
Michael Sentonas - President
Mr. Sentonas has served as our President since March 2023. Prior to being appointed President, Mr. Sentonas served as our Chief Technology Officer since February 2020, and as our Vice President, Technology Strategy from May 2016 to February 2020. Immediately prior to joining us, Mr. Sentonas served at McAfee Corp. from March 2004 to April 2016 in various positions, and finally as Chief Technology Officer – Security Connected from November 2013 to April 2016. Mr. Sentonas is a board member of the CrowdStrike Foundation, a nonprofit established to support the next generation of talent and research in cybersecurity and artificial intelligence through scholarships, grants, and other activities, and a member of the Forbes Technology Counsel, an organization for senior technology executives. He is an active public speaker on security issues and advises government and business communities on global and local cyber security threats. Mr. Sentonas holds a B.S. in computer science from Edith Cowan University, Western Australia.
Corporate Information
Our principal executive offices are located at 206 E. 9th Street, Suite 1400, Austin, Texas 78701 and our telephone number is (888) 512-8906. We are a holding company and all of our business operations are conducted through our subsidiaries, including CrowdStrike, Inc. Our website address is www.crowdstrike.com. Information contained on, or that can be accessed through, our website does not constitute part of this Annual Report on Form 10-K.
Available Information
Our Annual Report on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, and amendments to these reports are filed with the SEC pursuant to Sections 13(a) and 15(d) of the Exchange Act. Such reports and other information filed or furnished by us with the SEC are available free of charge on our website at https://ir.crowdstrike.com/financial-information/sec-filings, as soon as reasonably practicable after we file such material with, or furnish it to, the SEC. The SEC maintains a website that contains the materials we file with or furnish to the SEC at www.sec.gov.
20

Table of Contents

ITEM 1A. RISK FACTORS
A description of the risks and uncertainties associated with our business is set forth below. You should carefully consider the risks and uncertainties described below, as well as the other information in this Annual Report on Form 10-K, including our consolidated financial statements and the related notes and “Management’s Discussion and Analysis of Financial Condition and Results of Operations.” The occurrence of any of the events or developments described below, or of additional risks and uncertainties not presently known to us or that we currently deem immaterial, could materially and adversely affect our business, results of operations, financial condition and growth prospects. In such an event, the market price of our Class A common stock, or “common stock,” could decline, and you could lose all or part of your investment.
Summary of Risk Factors
Our business is subject to numerous risks and uncertainties, any one of which could materially adversely affect our business, results of operations, financial condition, and growth prospects. Below is a summary of some of these risks. This summary is not complete, and should be read together with the entire section titled “Risk Factors” in this Annual Report on Form 10-K, as well as the other information in this Annual Report on Form 10-K and the other filings that we make with the SEC.
• The July 19 Incident has had, and is expected to continue to have, an adverse effect on our business, sales, customer and partner relations, reputation, results of operations and financial condition.
• We have experienced rapid growth in recent periods, and if we do not manage our future growth, our business and results of operations will be adversely affected.
• We have a history of losses, and while we have achieved profitability in certain periods, including fiscal 2024, we may not be able to achieve or sustain profitability in the future.
• If organizations do not adopt cloud-based SaaS-delivered endpoint security solutions, our ability to grow our business and results of operations may be adversely affected.
• If we are unable to successfully enhance our existing products and services and introduce new products and services in response to rapid technological changes and market developments as well as evolving security threats, our competitive position and prospects will be harmed.
• If we are unable to attract new customers, our future results of operations could be harmed.
• If our customers do not renew their subscriptions for our products and add additional cloud modules to their subscriptions, our future results of operations could be harmed.
• Our sales cycles can be long and unpredictable, and our sales efforts require considerable time and expense.
• We face intense competition and could lose market share to our competitors, which could adversely affect our business, financial condition, and results of operations.
• If our solutions fail or are perceived to fail to detect or prevent incidents or have or are perceived to have defects, errors, or vulnerabilities, our brand and reputation would be harmed, which would adversely affect our business and results of operations.
• As a cybersecurity provider, we have been, and expect to continue to be, a target of cyberattacks. If our or our service providers’ internal networks, systems, or data are or are perceived to have been compromised, our reputation may be damaged and our financial results may be negatively affected.
• We rely on third-party data centers, such as Amazon Web Services, and our own colocation data centers to host and operate our Falcon platform, and any disruption of or interference with our use of these facilities may negatively affect our ability to maintain the performance and reliability of our Falcon platform, which could cause our business to suffer.
21

Table of Contents

• We rely on our key technical, sales and management personnel to grow our business, and the loss of one or more key employees could harm our business.
• If we are unable to attract and retain qualified personnel, our business could be harmed.
• Our results of operations may fluctuate significantly, which could make our future results difficult to predict and could cause our results of operations to fall below expectations.
• If we are not able to maintain and enhance our CrowdStrike and Falcon brands and our reputation as a provider of high-efficacy security solutions, our business and results of operations may be adversely affected.
• Claims by others that we infringe their proprietary technology or other intellectual property rights could result in significant costs and substantially harm our business, financial condition, results of operations, and prospects.
• We are required to comply with stringent, complex and evolving laws, rules, regulations and standards in many jurisdictions, as well as contractual obligations, relating to data privacy and security. Any actual or perceived failure to comply with these requirements could have a material adverse effect on our business.
• Failure to comply with laws and regulations applicable to our business could subject us to fines and penalties and could also cause us to lose customers or negatively impact our ability to contract with customers, including those in the public sector.
• We are currently, and may in the future become, involved in litigation that may adversely affect us.
• We have in the past experienced, and may in the future experience, warranty claims, product returns, and claims related to product liability and product defects from real or perceived defects in our solutions or their misuse by our customers or third parties and indemnity provisions in various agreements potentially expose us to substantial liability for intellectual property infringement and other losses.
• Future acquisitions, strategic investments, partnerships, or alliances could be difficult to identify and integrate, divert the attention of key management personnel, disrupt our business, dilute stockholder value and adversely affect our business, financial condition and results of operations.
Risks Related to Our Business and Industry
The July 19 Incident has had, and is expected to continue to have, an adverse effect on our business, sales, customer and partner relations, reputation, results of operations and financial condition.
On July 19, 2024, we released a content configuration update for our Falcon sensor that resulted in system crashes for certain Windows systems (the “July 19 Incident”). We have incurred, and expect to continue to incur, significant costs and expenses related to the incident. The July 19 Incident has harmed, and is expected to continue to harm, our business, sales, customer and partner relations, and our reputation. As a result of the July 19 Incident, certain of our existing or prospective customers have deferred or decided against purchases of our products and services and terminated or chosen not to renew their contracts with us, and others may take similar actions in the future. The July 19 Incident has negatively impacted, and may in the future negatively impact, our existing or prospective partners’ ability or willingness to promote our products or services. Certain of our competitors have aggressively approached our current and prospective customers and partners to attempt to capitalize on the July 19 Incident, and may continue to do so. Furthermore, we have agreed to, and expect to agree to in the future, provide incentives in connection with our commercial arrangements with our customers, including subscription period extensions, discounts or promotional modules. The July 19 Incident has received negative media coverage and harmed our reputation and brand. Additional negative media coverage and publicity, whether directly or indirectly related to the July 19 Incident, may harm our reputation and brand further, exacerbating the effects discussed herein. These factors may result in harm to our business, results of operations and financial condition. While we are investing in enhancements to software resiliency, testing and customer controls following the July 19 Incident, we cannot guarantee that such enhancements will be effective, or that our products do not have or will not have defects, errors, or vulnerabilities.
22

Table of Contents

We are party to a number of legal proceedings relating to the July 19 Incident, such as lawsuits filed by or on behalf of third parties, including securities litigation brought on behalf of certain purchasers of our common stock, derivative litigation asserting claims against certain officers and directors, and putative class actions brought by individual consumers. We have also received inquiries from governmental authorities and other third parties, and governmental authorities may seek to impose undertakings, injunctive relief, consent decrees or other penalties, which could, among other things, materially increase our expenses or otherwise require us to alter how we operate our business. Third parties, including governmental authorities, may take certain actions in response to the July 19 Incident that may negatively impact our business and operations and may result in additional costs and expenses relating to compliance, product development or other matters. Some customers and other third parties claiming to have been impacted by the incident have asserted claims against us or otherwise communicated their intent to seek indemnification or compensation from us. Additional claims may also be asserted by or on behalf of customers, customers’ insurers, partners, stockholders or others seeking monetary damages or other relief. These lawsuits, claims and inquiries are resulting, and are expected to result in the future, in the incurrence of significant costs and expenses, the diversion of management’s attention from the operation of our business and other negative impacts on our business and operations.
While we maintain insurance policies that may cover certain costs, claims and liabilities in connection with the July 19 Incident, we expect that our insurance coverage will not cover all costs, claims and liabilities actually incurred, and we cannot be certain that our insurance will continue to be available to us on commercially reasonable terms, or at all, or that any insurer will not deny coverage as to any future claim. The successful assertion of one or more large claims against us that exceed available insurance coverage, or the occurrence of changes in our insurance policies, including premium increases or the imposition of large deductible or co-insurance requirements, could have a material adverse effect on our business, including our financial condition, results of operations and reputation.
We have experienced rapid growth in recent periods, and if we do not manage our future growth, our business and results of operations will be adversely affected.
We have experienced rapid revenue growth in recent periods and we expect to continue to invest broadly across our organization to support our growth. Although we have experienced rapid growth historically, we may not sustain our current growth rates and our investments to support our growth may not be successful. The growth and expansion of our business will require us to invest significant financial and operational resources and the continuous dedication of our management team. Our future success will depend in part on our ability to manage our growth effectively, which will require us to, among other things:
• effectively attract, integrate, and retain a large number of new employees, particularly members of our sales and marketing and research and development teams;
• further improve our Falcon platform, including our cloud modules, and IT infrastructure, including expanding and optimizing our data centers, to support our business needs;
• enhance our information and communication systems to ensure that our employees and offices around the world are well coordinated and can effectively communicate with each other and our growing base of channel partners and customers; and
• improve our financial, management, and compliance systems and controls.
If we fail to achieve these objectives effectively, our ability to manage our expected growth, ensure uninterrupted operation of our Falcon platform and key business systems, and comply with the rules and regulations applicable to our business could be impaired. Additionally, the quality of our platform and services could suffer and we may not be able to adequately address competitive challenges. Any of the foregoing could adversely affect our business, results of operations, and financial condition.
We have a history of losses, and while we have achieved profitability in certain periods, we may not be able to achieve or sustain profitability in the future.
We have incurred net losses each year prior to fiscal 2024, and we may not achieve or maintain profitability in the future. We experienced net losses of $162.5 million and $15.2 million for fiscal 2026 and 2025, respectively, and net income of $72.2 million for fiscal 2024 . As of January 31, 2026, we had an accumulated deficit of $1.3 billion. While we have experienced significant growth in revenue in recent periods, and have achieved profitability during certain periods, including fiscal 2024, we cannot assure you when or whether we will reach sustained profitability. We also expect our operating expenses to increase in the future as we continue to invest for our future growth, which will negatively affect our results of operations if our total
23

Table of Contents

revenue does not increase. We also have incurred and expect to continue to incur significant additional legal, accounting, and other expenses as a public company. Any failure to increase our revenue as we invest in our business or to manage our costs could prevent us from achieving or maintaining profitability or positive cash flow.
If organizations do not adopt cloud-based SaaS-delivered endpoint security solutions, our ability to grow our business and results of operations may be adversely affected.
We believe our future success will depend in large part on the growth, if any, in the market for cloud-based SaaS-delivered endpoint security solutions. The use of SaaS solutions to manage and automate security and IT operations is at an early stage and rapidly evolving. As such, it is difficult to predict its potential growth, if any, customer adoption and retention rates, customer demand for our solutions, customer consolidation on our platform, or the success of existing competitive products. Any expansion in our market depends on a number of factors, including the cost, performance, and perceived value associated with our solutions and those of our competitors. If our solutions do not achieve widespread adoption or there is a reduction in demand for our solutions due to a lack of customer acceptance, technological challenges, damage to our reputation including as a result of the July 19 Incident, competing products, privacy concerns, decreases in corporate spending, weakening economic conditions or otherwise, it could result in early terminations, reduced customer retention rates, or decreased revenue, any of which would adversely affect our business, results of operations, and financial results. We do not know whether the trend in adoption of cloud-based SaaS-delivered endpoint security solutions we have experienced in the past will continue in the future. Furthermore, to the extent we or other SaaS security providers experience security incidents, loss or disclosure of customer data, disruptions in delivery, or other problems, the market for SaaS solutions as a whole, including our security solutions, could be negatively affected. You should consider our business and prospects in light of the risks and difficulties we encounter in this new and evolving market.
If we are unable to successfully enhance our existing products and services and introduce new products and services in response to rapid technological changes and market developments as well as evolving security threats, our competitive position and prospects will be harmed.
Our ability to increase revenue from existing customers and attract new customers will depend in significant part on our ability to anticipate and respond effectively to rapid technological changes and market developments as well as evolving security threats. The success of our Falcon platform depends on our ability to take such changes into account and invest effectively in our research and development organization to increase the reliability, availability and scalability of our existing solutions and introduce new solutions. If we fail to effectively anticipate, identify or respond to such changes in a timely manner, or at all, our business could be harmed. Even if we adequately fund our research and development efforts there is no guarantee that we will realize a return on such efforts.
Success in delivering enhancements and new solutions depends on several factors, including the timely completion, introduction and market acceptance of the enhancement or new solution, the risk that such enhancement or new solution may have quality or other defects or deficiencies (such as those experienced in connection with the July 19 Incident), especially in the early stages of introduction, as well as our ability to seamlessly integrate all of our product and service offerings and develop adequate sales capabilities in new markets. Failure to effectively deliver, integrate, and manage perceptions with respect to enhancements and new solutions could erode our competitive position, significantly impair our revenue growth, and negatively impact our operating results.
If we are unable to attract new customers, our future results of operations could be harmed.
To expand our customer base, we need to convince potential customers to allocate a portion of their discretionary budgets to purchase our Falcon platform. Our sales efforts often involve educating our prospective customers about the uses and benefits of our Falcon platform. Enterprises and governments that use legacy security products, such as signature-based or malware-based products, firewalls, intrusion prevention systems, and antivirus, for their IT security may be hesitant to purchase our Falcon platform if they believe that these products are more cost effective, provide substantially the same functionality as our Falcon platform or provide a level of IT security that is sufficient to meet their needs. We may have difficulty convincing prospective customers of the value of adopting our solution. Even if we are successful in convincing prospective customers that a cloud native platform like ours is critical to protect against cyberattacks, they may not decide to purchase our Falcon platform for a variety of reasons, some of which are out of our control. For example, any deterioration in general economic conditions, including as a result of the geopolitical environment or changes and uncertainty regarding trade policies or tariffs, the outbreak of diseases or other public health crises, volatility in the banking and financial services sector, or inflation (as well as government policies such as raising interest rates in response to inflation), have in the past and may in the future cause our
24

Table of Contents

current and prospective customers to delay or cut their overall security and IT operations spending, and such delays or cuts may fall disproportionately on cloud-based security solutions like ours. Economic weakness, customer financial difficulties, constrained spending on security and IT operations, and the impact of the July 19 Incident may result in decreased revenue, reduced sales, an increase in multi-phase subscription start dates, shorter terms for customer subscriptions, lengthened sales cycles, increased churn, lower demand for our products, and adversely affect our results of operations and financial conditions. Furthermore, we may need to exercise more flexibility in customer payment terms as customers navigate a more challenging economic environment. Additionally, if the incidence of cyberattacks were to decline, or be perceived to decline, or if organizations adopt endpoints that use operating systems we do not adequately support, our ability to attract new customers and expand sales of our solutions to existing customers could be adversely affected. If organizations do not continue to adopt our Falcon platform, our sales will not grow as quickly as anticipated, or at all, and our business, results of operations, and financial condition would be harmed.
If our customers do not renew their subscriptions for our products and add additional cloud modules to their subscriptions, our future results of operations could be harmed.
In order for us to maintain or improve our results of operations, it is important that our customers renew their subscriptions for our Falcon platform when existing contract terms expire, and that we expand our commercial relationships with our existing customers by selling additional cloud modules and by deploying to more endpoints in their environments. Our customers have no obligation to renew their subscription for our Falcon platform after the expiration of their contractual subscription period, which is generally one to three years, and in the normal course of business, some customers have elected not to renew. In addition, customers that previously signed multi-year subscription contracts may renew for shorter contract subscription lengths, and customers may cease using certain cloud modules altogether. Even if customers choose to renew their subscription of certain cloud modules, they may decline to purchase additional cloud modules or choose not to consolidate onto our Falcon platform. Our customer retention, renewals and expansion may decline or fluctuate as a result of a number of factors, including our customers’ satisfaction with our products and services, our customers’ ability to fully utilize their product subscriptions, our pricing, customer security and networking issues and requirements, our customers’ spending levels, decreases in the number of endpoints to which our customers deploy our solutions, mergers and acquisitions involving our customers, industry developments, competition, the impact of the July 19 Incident, including the impact of our customer commitment packages, and general economic and geopolitical conditions. Any such impacts on customer renewals may result from a variety of different factors, including customers electing to renew with shorter subscription periods, fewer cloud modules, fewer endpoints or smaller contract values. If our efforts to maintain and expand our relationships with our existing customers are not successful, our business, results of operations, and financial condition may materially suffer.
Our sales cycles can be long and unpredictable, and our sales efforts require considerable time and expense.
Our revenue recognition is difficult to predict because of the length and unpredictability of the sales cycle for our Falcon platform. Customers often view the subscription to our Falcon platform as a significant strategic decision and, as a result, frequently require considerable time to evaluate, test and qualify our Falcon platform prior to entering into or expanding a relationship with us. Large enterprises and government entities in particular often undertake a significant evaluation process that further lengthens and adds uncertainty to our sales cycle. In addition, uncertain economic or geopolitical conditions, including in connection with changes in trade policies and tariffs, may lead to additional scrutiny of budgets by current and prospective customers, which has resulted in, for example, longer sales cycles for products and services, and may result in shifting demand for IT products and services, and slower adoption of new technologies. We have also experienced, and may continue to experience, longer sales cycles in connection with the July 19 Incident. We may also experience longer sales cycles as customers seek to consolidate on our Falcon platform and negotiate larger deals, including in connection with our flexible subscription offering.
Our direct sales team develops relationships with our customers, and works with our channel partners on account penetration, account coordination, sales and overall market development. We spend substantial time and resources on our sales efforts without any assurance that our efforts will produce a sale. Security solution purchases are frequently subject to budget constraints, multiple approvals and unanticipated administrative, processing and other delays. As a result, it is difficult to predict whether and when a sale will be completed. The failure of our efforts to secure sales after investing resources in a lengthy sales process could adversely affect our business and results of operations.
25

Table of Contents

We face intense competition and could lose market share to our competitors, which could adversely affect our business, financial condition, and results of operations.
The market for security and IT operations solutions is intensely competitive, fragmented, and characterized by rapid changes in technology, customer requirements, industry standards, increasingly sophisticated attackers, and by frequent introductions of new or improved products or services to combat security threats. We expect to continue to face intense competition from current competitors, as well as from new entrants into the market. If we are unable to anticipate or react to these challenges, our competitive position could weaken, and we could experience a decline in revenue or reduced revenue growth, and loss of market share that would adversely affect our business, financial condition, and results of operations. Our ability to compete effectively depends upon numerous factors, many of which are beyond our control, including, but not limited to:
• product capabilities, including performance and reliability, of our Falcon platform, including our cloud modules, services, and features compared to those of our competitors;
• our ability, and the ability of our competitors, to improve existing products, services, and features, or to develop new ones to address evolving customer needs;
• our ability to attract, retain, and motivate talented employees;
• our ability to establish and maintain relationships with channel partners and direct customers;
• the strength of our sales and marketing efforts;
• the strength of our reputation and brand, including the impact to our reputation and brand as a result of the July 19 Incident; and
• acquisitions or consolidation within our industry, which may result in more formidable competitors.
Our competitors include the following by general category:
• legacy antivirus product providers who offer a broad range of approaches and solutions including traditional signature-based anti-virus protection;
• alternative endpoint security providers who generally offer a mix of on-premise and cloud-hosted products that rely heavily on malware-only or application whitelisting techniques;
• network security vendors who are supplementing their core perimeter-based offerings with endpoint or cloud security solutions;
• cloud security vendors, including those who focus on public cloud infrastructure and services;
• identity security vendors that seek to identify and secure user accounts and related activities;
• professional service providers who offer cybersecurity response services; and
• legacy SIEM vendors who offer a range of log management and security capabilities.
Many of our competitors have greater financial, technical, marketing, sales, and other resources, greater name recognition, longer operating histories, and a larger base of customers than we do. They may be able to devote greater resources to the development, promotion, and sale of services than we can, and they may offer lower pricing than we do. Further, they may have greater resources for research and development of new technologies, the provision of customer support, and the pursuit of acquisitions. Our larger competitors have substantially broader and more diverse product and services offerings as well as routes to market, which allows them to leverage their relationships based on other products or incorporate functionality into existing products to gain business in a manner that discourages users from purchasing our platform, including our cloud modules. Conditions in our market are changing rapidly and significantly as a result of technological advancements, including with respect to AI. Our competitors may more successfully incorporate AI into their products, gain or leverage superior access
26

Table of Contents

to certain AI technologies, and achieve higher market acceptance of their AI solutions. Conditions in our market could also change rapidly and significantly due to partnering or acquisitions by our competitors or continuing market consolidation. Some of our competitors have recently made acquisitions of businesses or have established cooperative relationships that may allow them to offer more directly competitive and comprehensive solutions than were previously offered and adapt more quickly to new technologies and customer needs. These competitive pressures in our market or our failure to compete effectively may result in price reductions, fewer orders, reduced revenue and gross margins, increased net losses and loss of market share. Further, competitors that specialize in providing protection from a single type of security threat may be able to deliver these targeted security products to the market quicker than we can or convince organizations that these limited products meet their needs. Even if there is significant demand for cloud-based security solutions like ours, if our competitors include functionality that is, or is perceived to be, equivalent to or better than ours in legacy products that are already generally accepted as necessary components of an organization’s IT security architecture, we may have difficulty increasing the market penetration of our solutions. Furthermore, even if the functionality offered by other security and IT operations providers is more limited than the functionality of our platform, organizations may elect to accept such limited functionality in lieu of adding products from additional vendors like us. If we are unable to compete successfully, or if competing successfully requires us to take aggressive pricing or other actions, our business, financial condition, and results of operations would be adversely affected.
Competitive pricing pressure may reduce our gross profits and adversely affect our financial results.
If we are unable to maintain our pricing due to competitive pressures or other factors, our margins will be reduced and our gross profits, business, results of operations, and financial condition would be adversely affected. The subscription prices for our Falcon platform, cloud modules, and professional services may decline for a variety of reasons, including competitive pricing pressures, discounts, anticipation of the introduction of new solutions by our competitors, or promotional programs offered by us or our competitors. The cybersecurity market remains very competitive, and competition may further increase in the future. Competitors may reduce the price of products or subscriptions that compete with ours or may bundle them with other products and subscriptions.
If our solutions fail or are perceived to fail to detect or prevent incidents or have or are perceived to have defects, errors, or vulnerabilities, our brand and reputation would be harmed, which would adversely affect our business and results of operations.
Real or perceived defects, errors or vulnerabilities in our Falcon platform and cloud modules, the failure of our platform to detect or prevent incidents, including advanced and newly developed attacks, misconfiguration of our solutions, or the failure of customers to take action on attacks identified by our platform could harm our reputation and adversely affect our business, financial position and results of operations. Because our cloud native security platform is complex, it has contained, and may in the future contain defects, errors or vulnerabilities that are not detected until after deployment. For example, the July 19 Incident harmed our brand and reputation, business and results of operations. In addition, we identified a transport layer security issue that impacted certain Falcon Linux sensors, which led us to release a security fix and publish a security advisory to remediate the matter in February 2025. If we fail to timely detect defects or errors before deployment in the future, our brand and reputation, business and results of operations will suffer further. We cannot assure you that our products will detect all cyberattacks, especially in light of the rapidly changing security threat landscape that our solution seeks to address. Due to a variety of both internal and external factors, including, without limitation, defects or misconfigurations of our or third-party solutions, our solutions could be or become vulnerable to security incidents (both from intentional attacks and accidental causes) that cause them to fail to secure endpoints and detect and block attacks. Furthermore, any defects, errors or vulnerabilities in third-party technology or solutions we rely on could result in disruptions to our operations and adversely impact our business, financial condition and results of operations. In addition, because the techniques used by computer hackers to access or sabotage networks and endpoints change frequently and generally are not recognized until launched against a target, there is a risk that an advanced attack could emerge that our cloud native security platform is unable to detect or prevent until after some of our customers are affected. Additionally, our Falcon platform may falsely indicate a cyberattack or threat that does not actually exist, which may lessen customers’ trust in our solutions.
Moreover, as our cloud native security platform is adopted by an increasing number of enterprises and governments, individuals and organizations behind advanced cyberattacks may intensify their efforts to defeat our security platform. If this happens, our systems and subscription customers could be specifically targeted by attackers and could result in vulnerabilities in our platform or undermine the market acceptance of our Falcon platform and could adversely affect our reputation as a provider of security solutions. Because we host customer data on our cloud platform, which in some cases may contain personally-identifiable information or potentially confidential information, a security compromise, or an accidental or intentional misconfiguration or malfunction of our platform or third-party platforms, could result in personally-identifiable
27

Table of Contents

information and other customer data being accessible such as to attackers or to other customers. Further, if a high profile security breach occurs with respect to another next-generation or cloud-based security system, our customers and potential customers may lose trust in cloud solutions generally, and cloud-based security solutions such as ours in particular.
Organizations are increasingly subject to a wide variety of attacks on their networks, systems, and endpoints. No security solution, including our Falcon platform, can address all possible security threats or block all methods of penetrating a network or otherwise perpetrating a security incident. If any of our customers experiences a successful cyberattack while using our solutions or services, such customer could be disappointed with our Falcon platform, regardless of whether our solutions or services blocked the theft of any of such customer’s data, if the customer failed to protect its own credentials, or if the attack would have otherwise been mitigated or prevented if the customer had fully deployed aspects of our Falcon platform. Similarly, if our solutions detect attacks against a customer but the customer does not address the vulnerability, customers and the public may erroneously believe that our solutions were not effective. Security breaches against customers that use our solutions may result in customers and the public believing that our solutions failed. Our Falcon platform may fail to detect or prevent malware, viruses, worms or similar threats for any number of reasons, including our failure to enhance and expand our Falcon platform to reflect the increasing sophistication of malware, viruses and other threats. Real or perceived security breaches of our customers’ networks could cause disruption or damage to their networks or other negative consequences and could result in negative publicity to us, damage to our reputation, and other customer relations issues, and may adversely affect our revenue and results of operations.
As a cybersecurity provider, we have been, and expect to continue to be, a target of cyberattacks. If our or our service providers’ internal networks, systems, or data are or are perceived to have been compromised, our reputation may be damaged and our financial results may be negatively affected.
As a provider of security solutions, we have in the past been, and may in the future be, specifically targeted by bad actors for attacks intended to circumvent our security capabilities or to exploit our Falcon platform as an entry point into customers’ endpoints, networks, or systems. In particular, because we have been involved in the identification of organized cybercriminals and nation-state actors, we have been the subject of intense efforts by sophisticated cyber adversaries who seek to compromise our systems. Such efforts may also intensify as geopolitical tensions increase. In addition, bad actors have attempted to leverage the July 19 Incident to facilitate malicious activity, including, for example, through sending phishing emails posing as CrowdStrike support. Such activity, whether or not successful, could result in additional harm to our business. We are also susceptible to inadvertent compromises of our systems and data, including those arising from process, coding, or human errors. Moreover, we utilize third-party service providers to, among other things, host, transmit, or otherwise process electronic data in connection with our business activities, including our supply chain, operations, and communications. Our third-party service providers and other vendors have faced and may continue to face cyberattacks, compromises, interruptions in service, or other security incidents from a variety of sources. A successful attack or other incident that results in an interruption of service or that compromises our or our service providers’ internal networks, systems, or data could have a significant negative effect on our operations, reputation, financial resources, and the value of our intellectual property. We cannot assure you that any of our efforts to manage this risk, including adoption of a comprehensive incident response plan and process for detecting, mitigating, and investigating security incidents that we regularly test through table-top exercises, testing of our security protocols through additional techniques, such as penetration testing, debriefing after security incidents, to improve our security and responses, and regular briefing of our directors and officers on our cybersecurity risks, preparedness, and management, will be effective in protecting us from such attacks.
It is virtually impossible for us to entirely eliminate the risk of such attacks, compromises, interruptions in service, or other security incidents affecting our internal systems or data, or that of our third-party service providers and vendors. Organizations are subject to a wide variety of attacks on their supply chain, networks, systems, and endpoints, and techniques used to sabotage or to obtain unauthorized access to networks in which data is stored or through which data is transmitted change frequently. Furthermore, employee error or malicious activity could compromise our systems. As a result, we may be unable to anticipate these techniques or implement adequate measures to prevent an intrusion into our networks, which could result in unauthorized access to customer data, intellectual property including access to our source code, and information about vulnerabilities in our product, which in turn, could reduce the effectiveness of our solutions, or lead to cyberattacks or other intrusions of our customers’ networks, litigation, governmental audits and investigations and significant legal fees, any or all of which could damage our relationships with our existing customers and could have a negative effect on our ability to attract and retain new customers. We have expended, and anticipate continuing to expend, significant resources in an effort to prevent security breaches and other security incidents impacting our systems and data. Since our business is focused on providing reliable security services to our customers, we believe that an actual or perceived security incident affecting our internal systems or data
28

Table of Contents

or data of our customers would be especially detrimental to our reputation, customer confidence in our solution, and our business.
In addition, while we maintain insurance policies that may cover certain liabilities in connection with a cybersecurity incident, we cannot be certain that our insurance coverage will be adequate for liabilities actually incurred, that insurance will continue to be available to us on commercially reasonable terms, or at all, or that any insurer will not deny coverage as to any future claim. The successful assertion of one or more large claims against us that exceed available insurance coverage, or the occurrence of changes in our insurance policies, including premium increases or the imposition of large deductible or co-insurance requirements, could have a material adverse effect on our business, including our financial condition, results of operations and reputation.
We rely on third-party data centers, such as Amazon Web Services, and our own colocation data centers to host and operate our Falcon platform, and any disruption of or interference with our use of these facilities may negatively affect our ability to maintain the performance and reliability of our Falcon platform which could cause our business to suffer.
Our customers depend on the continuous availability of our Falcon platform. We currently host our Falcon platform and serve our customers using a mix of third-party data centers, primarily Amazon Web Services, Inc., or AWS, and our data centers, hosted in colocation facilities. Consequently, we may be subject to service disruptions as well as failures to provide adequate support for reasons that are outside of our direct control. We have experienced, and expect that in the future we may experience interruptions, delays and outages in service and availability from time to time due to a variety of factors, including infrastructure changes, human or software errors, website hosting disruptions and capacity constraints.
The following factors, many of which are beyond our control, can affect the delivery, availability, and the performance of our Falcon platform:
• the development and maintenance of the infrastructure of the internet;
• the performance and availability of third-party providers of cloud infrastructure services, such as AWS, with the necessary speed, data capacity and security for providing reliable internet access and services;
• decisions by the owners and operators of the data centers where our cloud infrastructure is deployed to terminate our contracts, discontinue services to us, shut down operations or facilities, increase prices, change service levels, limit bandwidth, declare bankruptcy or prioritize the traffic of other parties;
• physical or electronic break-ins, acts of war or terrorism, human error or interference (including by disgruntled employees, former employees or contractors) and other catastrophic events;
• cyberattacks, including denial of service attacks, targeted at us, our data centers, or the infrastructure of the internet;
• failure by us to maintain and update our cloud infrastructure to meet our data capacity requirements;
• errors, defects or performance problems in our software, including third-party software incorporated in our software;
• improper deployment or configuration of our solutions;
• the failure of our redundancy systems, in the event of a service disruption at one of our data centers, to provide failover to other data centers in our data center network; and
• the failure of our disaster recovery and business continuity arrangements.
29

Table of Contents

The adverse effects of any service interruptions on our reputation, results of operations, and financial condition may be disproportionately heightened due to the nature of our business and the fact that our customers have a low tolerance for interruptions of any duration. Interruptions or failures in our service delivery could result in a cyberattack or other security threat to us or to one of our customers during such periods of interruption or failure. Additionally, interruptions or failures in our service could cause customers to terminate their subscriptions with us, adversely affect our renewal rates, and harm our ability to attract new customers. Our business would also be harmed if our customers believe that a cloud-based SaaS-delivered endpoint security solution is unreliable. We have experienced, and may in the future experience, service interruptions and other performance problems due to a variety of factors. The occurrence of any of these factors, or if we are unable to rapidly and cost-effectively fix such errors or other problems that may be identified, could damage our reputation, negatively affect our relationship with our customers or otherwise harm our business, results of operations and financial condition.
We rely on our key technical, sales and management personnel to grow our business, and the loss of one or more key employees could harm our business.
Our future success is substantially dependent on our ability to attract, retain, and motivate the members of our management team and other key employees throughout our organization. In particular, we are highly dependent on the services of George Kurtz, our President and Chief Executive Officer, who is critical to our future vision and strategic direction. We rely on our leadership team in the areas of operations, security, research and development, marketing, sales, support and general and administrative functions. Although we have entered into employment agreements with our key personnel, our employees, including our executive officers, work for us on an “at-will” basis, which means they may terminate their employment with us at any time. Leadership transitions can be inherently difficult to manage. In particular, they can cause operational and administrative inefficiencies, and could impact relationships with key customers and vendors. If Mr. Kurtz, or one or more of our key employees, or members of our management team resigns or otherwise ceases to provide us with their service, our business could be harmed.
If we are unable to attract and retain qualified personnel, our business could be harmed.
There is significant competition for personnel with the skills and technical knowledge that we require across our technology, cyber, sales, professional services, and administrative support functions. Competition for these personnel is intense, especially for experienced sales professionals and for engineers experienced in designing and developing cloud applications and security software. We have from time to time experienced, and we expect to continue to experience, difficulty in hiring and retaining employees with appropriate qualifications. For example, in recent years, recruiting, hiring and retaining employees with expertise in the cybersecurity industry has become increasingly difficult as the demand for cybersecurity professionals has increased as a result of the recent cybersecurity attacks on global corporations and governments. Additionally, our incident response and proactive services team is small and comprised of personnel with highly technical skills and experience, who are in high demand, and who would be difficult to replace. More generally, the technology industry is subject to substantial and continuous competition for engineers with high levels of experience in designing, developing and managing software and Internet-related services. Many of the companies with which we compete for experienced personnel have greater resources than we have. Our competitors also may be successful in recruiting and hiring members of our management team or other key employees, and it may be difficult for us to find suitable replacements on a timely basis, on competitive terms, or at all. We have in the past, and may in the future, be subject to allegations that employees we hire have been improperly solicited, or that they have divulged proprietary or other confidential information or that their former employers own such employees’ inventions or other work product, or that they have been hired in violation of non-compete provisions or non-solicitation provisions.
In addition, job candidates and existing employees often consider the value of the equity awards they receive in connection with their employment. Therefore, volatility or lack of performance in our stock price could affect our ability to attract and retain our key employees. Also, many of our employees have become, or will soon become, vested in a substantial amount of equity awards, which may give them a substantial amount of personal wealth. This may make it more difficult for us to retain and motivate these employees, and this wealth could affect their decision about whether or not they continue to work for us. In addition, the Strategic Plan (as defined in the notes to our consolidated financial statements) could negatively affect our ability to recruit and retain skilled personnel . Any failure to successfully attract, integrate or retain qualified personnel to fulfill our current or future needs could adversely affect our business, results of operations and financial condition.
30

Table of Contents

If we do not effectively expand and train our direct sales force, we may be unable to add new customers or increase sales to our existing customers, and our business will be adversely affected.
We depend on our direct sales force to obtain new customers and increase sales with existing customers. Our ability to achieve significant revenue growth will depend, in large part, on our success in recruiting, training and retaining sufficient numbers of sales personnel, particularly in international markets. We have expanded our sales organization significantly in recent periods and expect to continue to add additional sales capabilities in the near term. There is significant competition for sales personnel with the skills and technical knowledge that we require. New hires require significant training and may take significant time before they achieve full productivity, and this delay is accentuated by our long sales cycles. Our recent hires and planned hires may not become productive as quickly as we expect, and we may be unable to hire or retain sufficient numbers of qualified individuals in the markets where we do business or plan to do business. In addition, a large percentage of our sales force is new to our company and selling our solutions, and therefore this team may be less effective than our more seasoned sales personnel. Furthermore, hiring sales personnel in new countries, or expanding our existing presence, requires upfront and ongoing expenditures that we may not recover if the sales personnel fail to achieve full productivity. We cannot predict whether, or to what extent, our sales will increase as we expand our sales force or how long it will take for sales personnel to become productive. If we are unable to hire and train a sufficient number of effective sales personnel, or the sales personnel we hire are not successful in obtaining new customers or increasing sales to our existing customer base, our business and results of operations will be adversely affected.
Because we recognize revenue from subscriptions to our platform over the term of the subscription, downturns or upturns in new business will not be immediately reflected in our results of operations.
We generally recognize revenue from customers ratably over the terms of their subscription, which is generally one to three years. As a result, a substantial portion of the revenue we report in each period is attributable to the recognition of deferred revenue relating to agreements that we entered into during previous periods. Consequently, any increase or decline in new sales or renewals in any one period will not be immediately reflected in our revenue for that period. Any such change, however, would affect our revenue in future periods. In addition, subscription commencement dates may be impacted by a number of factors, some of which we may exercise varying degrees of control over, including terms negotiated with our customers and our internal review, approval and provisioning processes. As a result, the impact of new subscriptions may not be immediately reflected in our results of operations. Moreover, the effect of downturns or upturns in new sales and potential changes in our rate of renewals, including as a result of the July 19 Incident, may not be fully reflected in our results of operations until future periods. In addition, customer commitment packages introduced following the July 19 Incident that extend subscription periods will lengthen the applicable term over which we recognize revenue, which has adversely affected, and is expected to continue to adversely affect, our results. We may also be unable to timely reduce our cost structure in line with a significant deterioration in sales or renewals that would adversely affect our results of operations and financial condition.
Our results of operations may fluctuate significantly, which could make our future results difficult to predict and could cause our results of operations to fall below expectations.
Our results of operations may vary significantly from period to period, which could adversely affect our business, financial condition and results of operations. Our results of operations have varied significantly from period to period, and we expect that our results of operations will continue to vary as a result of a number of factors, many of which are outside of our control and may be difficult to predict, including:
• our ability to attract new and retain existing customers;
• the budgeting cycles, seasonal buying patterns, and purchasing practices of customers;
• economic difficulties confronting our customers, which may impact the number of modules or endpoint deployments they are willing or able to purchase;
• insolvency or credit difficulties confronting our customers, affecting their ability to purchase or pay for our solutions, including in connection with our customer and end-user financing arrangements;
• the timing and length of our sales cycles;
• changes in customer or channel partner requirements or market needs;
31

Table of Contents

• any disruption in our relationship with channel partners;
• changes in the growth rate of the cloud-based SaaS-delivered endpoint security solutions market;
• the timing and success of new product and service introductions by us or our competitors or any other competitive developments, including consolidation among our customers or competitors;
• decisions by organizations to purchase security solutions from larger, more established security vendors or from their primary IT equipment vendors;
• changes in our pricing policies or those of our competitors;
• the level of awareness of cybersecurity threats, particularly advanced cyberattacks, and the market adoption of our Falcon platform;
• significant security breaches of, technical difficulties with or interruptions to, the use of our Falcon platform;
• the impact to our business from the July 19 Incident;
• negative media coverage or publicity;
• our ability to successfully expand our business domestically and internationally;
• the amount and timing of operating costs (including new hires), tightening of labor markets and capital expenditures related to the expansion of our business;
• extraordinary expenses such as litigation, regulatory or other dispute-related settlement payments or outcomes;
• increases or decreases in our expenses caused by fluctuations in foreign currency exchange rates;
• future accounting pronouncements or changes in our accounting policies or practices;
• developments relating to our valuation allowances for our deferred tax assets;
• deteriorating or volatile conditions in the global economy and financial markets, including as a result of weak or negative gross domestic product growth, uncertainty or disruptions in the capital and credit markets, changing interest rates, inflation, tariffs and trade restrictions, bank failures or adverse conditions impacting financial institutions, and supply-chain disruptions; and
• political events, geopolitical unrest or tension, acts of war and terrorism.
In addition, we experience seasonal fluctuations in our financial results as we typically receive a higher percentage of our annual orders from new customers, as well as renewal orders from existing customers, in the second half of the fiscal year as compared to the first half of the year due to the annual budget approval processes of many of our customers. In addition, we also experience seasonality in our operating margin, typically with a lower margin in the first half of our fiscal year. Any of the above factors, individually or in the aggregate, may result in significant fluctuations in our financial and other results of operations from period to period. As a result of this variability, our historical results of operations should not be relied upon as an indication of future performance. Moreover, this variability and unpredictability could result in our failure to meet our operating plan or the expectations of investors or analysts for any period. If we fail to meet such expectations for these or other reasons, our stock price could fall substantially, and we could face costly lawsuits, including securities class action suits. For example, we are currently party to securities litigation brought in connection with the July 19 Incident on behalf of certain purchasers of our common stock.
32

Table of Contents

If we are not able to maintain and enhance our CrowdStrike and Falcon brands and our reputation as a provider of high-efficacy security solutions, our business and results of operations may be adversely affected.
We believe that maintaining and enhancing our CrowdStrike and Falcon brands and our reputation as a provider of high-efficacy security solutions is critical to our relationship with our existing customers, channel partners, and technology alliance partners and our ability to attract new customers and partners. The successful promotion of our CrowdStrike and Falcon brands depends on a number of factors, including our marketing efforts, our ability to continue to develop additional cloud modules and features for our Falcon platform, our ability to successfully differentiate our Falcon platform from competitive cloud-based or legacy security solutions and, ultimately, our ability to detect and stop breaches. Although we believe it is important for our growth, our brand promotion activities may not be successful or yield increased revenue.
In addition, independent industry or financial analysts and research firms often test our solutions and provide reviews of our Falcon platform, as well as the products of our competitors, and perception of our Falcon platform in the marketplace may be significantly influenced by these reviews. If these reviews are negative, or less positive as compared to those of our competitors’ products, our brand may be adversely affected. Our solutions may fail to detect or prevent threats in any particular test for a number of reasons that may or may not be related to the efficacy of our solutions in real world environments. To the extent potential customers, industry analysts or testing firms believe that the occurrence of a failure to detect or prevent any particular threat is a flaw or indicates that our solutions or services do not provide significant value, we may lose customers, and our reputation, financial condition and business would be harmed. Additionally, the performance of our channel partners and technology alliance partners may affect our brand and reputation if customers do not have a positive experience with these partners. In addition, we have in the past worked, and continue to work, with high profile private and public customers as well as assist in analyzing and remediating high profile cyberattacks, which sometimes involve nation-state actors. Our work with such customers has exposed us to publicity and media coverage. Changing political environments in the United States and abroad may amplify the media and political scrutiny we face. Negative publicity about us, including about our management, the efficacy and reliability of our Falcon platform, our products offerings, our professional services, and the customers we work with, even if inaccurate, has in the past adversely affected, and may in the future adversely affect, our reputation and brand. For example, the July 19 Incident, which received significant media attention and negative publicity, harmed our reputation and brand.
If we are unable to maintain successful relationships with our channel partners and technology alliance partners, or if our channel partners or technology alliance partners fail to perform, our ability to market, sell and distribute our Falcon platform will be limited, and our business, financial position and results of operations will be harmed.
In addition to our direct sales force, we rely on our channel partners to sell and support our Falcon platform. The vast majority of sales of our Falcon platform flow through our channel partners, and we expect this to continue for the foreseeable future. Additionally, we have entered, and intend to continue to enter, into technology alliance partnerships with third parties to support our future growth plans. The loss of a substantial number of our channel partners or technology alliance partners, or the failure to recruit additional partners, could adversely affect our results of operations. Our ability to achieve revenue growth in the future will depend in part on our success in maintaining successful relationships with our channel partners and in training our channel partners to independently sell and deploy our Falcon platform. If we fail to effectively manage our existing sales channels, or if our channel partners are unsuccessful in fulfilling the orders for our solutions, or if we are unable to enter into arrangements with, and retain a sufficient number of, high quality channel partners in each of the regions in which we sell solutions and keep them motivated to sell our products, our ability to sell our products and results of operations will be harmed.
Our international operations and plans for future international expansion expose us to significant risks, and failure to manage those risks could adversely impact our business.
We derived approximately 33%, 32%, and 32% of our total revenue from our international customers for fiscal 2026, fiscal 2025, and fiscal 2024, respectively. We are continuing to adapt to and develop strategies to address international markets and our growth strategy includes expansion into target geographies, but there is no guarantee that such efforts will be successful. We expect that our international activities will continue to grow in the future, as we continue to pursue opportunities in international markets. These international operations will require significant management attention and financial resources and are subject to substantial risks, including:
• greater difficulty in negotiating contracts with standard terms, enforcing contracts and managing collections, and longer collection periods;
33