FULLTEXT DEL 1 AV 3
10-K – 2025-08-29 – panw-20250731.htm
panw-20250731 0001327567 false 2025 FY P2Y P1Y http://fasb.org/us-gaap/2025#OtherAssetsNoncurrent http://fasb.org/us-gaap/2025#OtherAssetsNoncurrent http://fasb.org/us-gaap/2025#AccruedLiabilitiesCurrent http://fasb.org/us-gaap/2025#AccruedLiabilitiesCurrent http://fasb.org/us-gaap/2025#OtherLiabilitiesNoncurrent http://fasb.org/us-gaap/2025#OtherLiabilitiesNoncurrent http://fasb.org/us-gaap/2025#AccruedLiabilitiesCurrent P4Y P1Y P3Y P4Y P1Y P4Y P5Y P6Y 25 25 25 25 7.5 25 25 25 25 25 25 25 25 7.5 183 iso4217:USD xbrli:shares iso4217:USD xbrli:shares xbrli:pure panw:instrument panw:day panw:patent panw:offeringPeriod panw:segment 0001327567 2024-08-01 2025-07-31 0001327567 2025-01-31 0001327567 2025-08-18 0001327567 2025-07-31 0001327567 2024-07-31 0001327567 us-gaap:ProductMember 2024-08-01 2025-07-31 0001327567 us-gaap:ProductMember 2023-08-01 2024-07-31 0001327567 us-gaap:ProductMember 2022-08-01 2023-07-31 0001327567 us-gaap:ServiceMember 2024-08-01 2025-07-31 0001327567 us-gaap:ServiceMember 2023-08-01 2024-07-31 0001327567 us-gaap:ServiceMember 2022-08-01 2023-07-31 0001327567 2023-08-01 2024-07-31 0001327567 2022-08-01 2023-07-31 0001327567 us-gaap:CommonStockMember 2022-07-31 0001327567 us-gaap:CommonStockIncludingAdditionalPaidInCapitalMember 2022-07-31 0001327567 us-gaap:AccumulatedOtherComprehensiveIncomeMember 2022-07-31 0001327567 us-gaap:RetainedEarningsMember 2022-07-31 0001327567 2022-07-31 0001327567 us-gaap:RetainedEarningsMember 2022-08-01 2023-07-31 0001327567 us-gaap:AccumulatedOtherComprehensiveIncomeMember 2022-08-01 2023-07-31 0001327567 us-gaap:CommonStockMember 2022-08-01 2023-07-31 0001327567 us-gaap:CommonStockIncludingAdditionalPaidInCapitalMember 2022-08-01 2023-07-31 0001327567 us-gaap:CommonStockMember 2023-07-31 0001327567 us-gaap:CommonStockIncludingAdditionalPaidInCapitalMember 2023-07-31 0001327567 us-gaap:AccumulatedOtherComprehensiveIncomeMember 2023-07-31 0001327567 us-gaap:RetainedEarningsMember 2023-07-31 0001327567 2023-07-31 0001327567 us-gaap:RetainedEarningsMember 2023-08-01 2024-07-31 0001327567 us-gaap:AccumulatedOtherComprehensiveIncomeMember 2023-08-01 2024-07-31 0001327567 us-gaap:CommonStockMember 2023-08-01 2024-07-31 0001327567 us-gaap:CommonStockIncludingAdditionalPaidInCapitalMember 2023-08-01 2024-07-31 0001327567 us-gaap:WarrantMember us-gaap:CommonStockMember 2023-08-01 2024-07-31 0001327567 us-gaap:CommonStockMember 2024-07-31 0001327567 us-gaap:CommonStockIncludingAdditionalPaidInCapitalMember 2024-07-31 0001327567 us-gaap:AccumulatedOtherComprehensiveIncomeMember 2024-07-31 0001327567 us-gaap:RetainedEarningsMember 2024-07-31 0001327567 us-gaap:RetainedEarningsMember 2024-08-01 2025-07-31 0001327567 us-gaap:AccumulatedOtherComprehensiveIncomeMember 2024-08-01 2025-07-31 0001327567 us-gaap:CommonStockMember 2024-08-01 2025-07-31 0001327567 us-gaap:CommonStockIncludingAdditionalPaidInCapitalMember 2024-08-01 2025-07-31 0001327567 us-gaap:CommonStockMember 2025-07-31 0001327567 us-gaap:CommonStockIncludingAdditionalPaidInCapitalMember 2025-07-31 0001327567 us-gaap:AccumulatedOtherComprehensiveIncomeMember 2025-07-31 0001327567 us-gaap:RetainedEarningsMember 2025-07-31 0001327567 2024-12-12 2024-12-12 0001327567 srt:MinimumMember 2024-12-12 0001327567 srt:MaximumMember 2024-12-12 0001327567 2024-12-12 0001327567 panw:FourDistributorsMember us-gaap:CustomerConcentrationRiskMember us-gaap:AccountsReceivableMember 2024-08-01 2025-07-31 0001327567 panw:CustomerAMember us-gaap:CustomerConcentrationRiskMember us-gaap:SalesRevenueNetMember 2024-08-01 2025-07-31 0001327567 panw:CustomerBMember us-gaap:CustomerConcentrationRiskMember us-gaap:SalesRevenueNetMember 2024-08-01 2025-07-31 0001327567 panw:CustomerCMember us-gaap:CustomerConcentrationRiskMember us-gaap:SalesRevenueNetMember 2024-08-01 2025-07-31 0001327567 srt:MinimumMember 2024-08-01 2025-07-31 0001327567 srt:MaximumMember 2024-08-01 2025-07-31 0001327567 srt:MinimumMember panw:ComputerEquipmentEquipmentandSoftwareandSoftwareDevelopmentCostsMember 2025-07-31 0001327567 srt:MaximumMember panw:ComputerEquipmentEquipmentandSoftwareandSoftwareDevelopmentCostsMember 2025-07-31 0001327567 srt:MaximumMember panw:DemonstrationunitsMember 2025-07-31 0001327567 us-gaap:FurnitureAndFixturesMember 2025-07-31 0001327567 us-gaap:LeaseholdImprovementsMember 2025-07-31 0001327567 us-gaap:SoftwareDevelopmentMember 2025-07-31 0001327567 us-gaap:SoftwareDevelopmentMember 2024-08-01 2025-07-31 0001327567 us-gaap:SoftwareDevelopmentMember 2023-08-01 2024-07-31 0001327567 us-gaap:SoftwareDevelopmentMember 2022-08-01 2023-07-31 0001327567 country:US 2024-08-01 2025-07-31 0001327567 country:US 2023-08-01 2024-07-31 0001327567 country:US 2022-08-01 2023-07-31 0001327567 panw:OtherAmericasMember 2024-08-01 2025-07-31 0001327567 panw:OtherAmericasMember 2023-08-01 2024-07-31 0001327567 panw:OtherAmericasMember 2022-08-01 2023-07-31 0001327567 srt:AmericasMember 2024-08-01 2025-07-31 0001327567 srt:AmericasMember 2023-08-01 2024-07-31 0001327567 srt:AmericasMember 2022-08-01 2023-07-31 0001327567 us-gaap:EMEAMember 2024-08-01 2025-07-31 0001327567 us-gaap:EMEAMember 2023-08-01 2024-07-31 0001327567 us-gaap:EMEAMember 2022-08-01 2023-07-31 0001327567 srt:AsiaPacificMember 2024-08-01 2025-07-31 0001327567 srt:AsiaPacificMember 2023-08-01 2024-07-31 0001327567 srt:AsiaPacificMember 2022-08-01 2023-07-31 0001327567 panw:SubscriptionMember 2024-08-01 2025-07-31 0001327567 panw:SubscriptionMember 2023-08-01 2024-07-31 0001327567 panw:SubscriptionMember 2022-08-01 2023-07-31 0001327567 panw:SupportMember 2024-08-01 2025-07-31 0001327567 panw:SupportMember 2023-08-01 2024-07-31 0001327567 panw:SupportMember 2022-08-01 2023-07-31 0001327567 2025-08-01 2025-07-31 0001327567 us-gaap:MoneyMarketFundsMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member 2025-07-31 0001327567 us-gaap:MoneyMarketFundsMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member 2025-07-31 0001327567 us-gaap:MoneyMarketFundsMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member 2025-07-31 0001327567 us-gaap:MoneyMarketFundsMember us-gaap:FairValueMeasurementsRecurringMember 2025-07-31 0001327567 us-gaap:MoneyMarketFundsMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member 2024-07-31 0001327567 us-gaap:MoneyMarketFundsMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member 2024-07-31 0001327567 us-gaap:MoneyMarketFundsMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member 2024-07-31 0001327567 us-gaap:MoneyMarketFundsMember us-gaap:FairValueMeasurementsRecurringMember 2024-07-31 0001327567 us-gaap:CommercialPaperMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member 2025-07-31 0001327567 us-gaap:CommercialPaperMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member 2025-07-31 0001327567 us-gaap:CommercialPaperMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member 2025-07-31 0001327567 us-gaap:CommercialPaperMember us-gaap:FairValueMeasurementsRecurringMember 2025-07-31 0001327567 us-gaap:CommercialPaperMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member 2024-07-31 0001327567 us-gaap:CommercialPaperMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member 2024-07-31 0001327567 us-gaap:CommercialPaperMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member 2024-07-31 0001327567 us-gaap:CommercialPaperMember us-gaap:FairValueMeasurementsRecurringMember 2024-07-31 0001327567 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member 2025-07-31 0001327567 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member 2025-07-31 0001327567 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member 2025-07-31 0001327567 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember 2025-07-31 0001327567 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member 2024-07-31 0001327567 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member 2024-07-31 0001327567 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member 2024-07-31 0001327567 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember 2024-07-31 0001327567 us-gaap:USTreasuryAndGovernmentMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member 2025-07-31 0001327567 us-gaap:USTreasuryAndGovernmentMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member 2025-07-31 0001327567 us-gaap:USTreasuryAndGovernmentMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member 2025-07-31 0001327567 us-gaap:USTreasuryAndGovernmentMember us-gaap:FairValueMeasurementsRecurringMember 2025-07-31 0001327567 us-gaap:USTreasuryAndGovernmentMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member 2024-07-31 0001327567 us-gaap:USTreasuryAndGovernmentMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member 2024-07-31 0001327567 us-gaap:USTreasuryAndGovernmentMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member 2024-07-31 0001327567 us-gaap:USTreasuryAndGovernmentMember us-gaap:FairValueMeasurementsRecurringMember 2024-07-31 0001327567 us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member 2025-07-31 0001327567 us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member 2025-07-31 0001327567 us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member 2025-07-31 0001327567 us-gaap:FairValueMeasurementsRecurringMember 2025-07-31 0001327567 us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member 2024-07-31 0001327567 us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member 2024-07-31 0001327567 us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member 2024-07-31 0001327567 us-gaap:FairValueMeasurementsRecurringMember 2024-07-31 0001327567 us-gaap:CertificatesOfDepositMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel1Member 2025-07-31 0001327567 us-gaap:CertificatesOfDepositMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel2Member 2025-07-31 0001327567 us-gaap:CertificatesOfDepositMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel3Member 2025-07-31 0001327567 us-gaap:CertificatesOfDepositMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember 2025-07-31 0001327567 us-gaap:CertificatesOfDepositMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel1Member 2024-07-31 0001327567 us-gaap:CertificatesOfDepositMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel2Member 2024-07-31 0001327567 us-gaap:CertificatesOfDepositMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel3Member 2024-07-31 0001327567 us-gaap:CertificatesOfDepositMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember 2024-07-31 0001327567 us-gaap:CommercialPaperNotIncludedWithCashAndCashEquivalentsMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel1Member 2025-07-31 0001327567 us-gaap:CommercialPaperNotIncludedWithCashAndCashEquivalentsMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel2Member 2025-07-31 0001327567 us-gaap:CommercialPaperNotIncludedWithCashAndCashEquivalentsMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel3Member 2025-07-31 0001327567 us-gaap:CommercialPaperNotIncludedWithCashAndCashEquivalentsMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember 2025-07-31 0001327567 us-gaap:CommercialPaperNotIncludedWithCashAndCashEquivalentsMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel1Member 2024-07-31 0001327567 us-gaap:CommercialPaperNotIncludedWithCashAndCashEquivalentsMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel2Member 2024-07-31 0001327567 us-gaap:CommercialPaperNotIncludedWithCashAndCashEquivalentsMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel3Member 2024-07-31 0001327567 us-gaap:CommercialPaperNotIncludedWithCashAndCashEquivalentsMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember 2024-07-31 0001327567 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel1Member 2025-07-31 0001327567 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel2Member 2025-07-31 0001327567 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel3Member 2025-07-31 0001327567 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember 2025-07-31 0001327567 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel1Member 2024-07-31 0001327567 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel2Member 2024-07-31 0001327567 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel3Member 2024-07-31 0001327567 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember 2024-07-31 0001327567 us-gaap:USTreasuryAndGovernmentMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel1Member 2025-07-31 0001327567 us-gaap:USTreasuryAndGovernmentMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel2Member 2025-07-31 0001327567 us-gaap:USTreasuryAndGovernmentMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel3Member 2025-07-31 0001327567 us-gaap:USTreasuryAndGovernmentMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember 2025-07-31 0001327567 us-gaap:USTreasuryAndGovernmentMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel1Member 2024-07-31 0001327567 us-gaap:USTreasuryAndGovernmentMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel2Member 2024-07-31 0001327567 us-gaap:USTreasuryAndGovernmentMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel3Member 2024-07-31 0001327567 us-gaap:USTreasuryAndGovernmentMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember 2024-07-31 0001327567 us-gaap:ForeignGovernmentDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel1Member 2025-07-31 0001327567 us-gaap:ForeignGovernmentDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel2Member 2025-07-31 0001327567 us-gaap:ForeignGovernmentDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel3Member 2025-07-31 0001327567 us-gaap:ForeignGovernmentDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember 2025-07-31 0001327567 us-gaap:ForeignGovernmentDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel1Member 2024-07-31 0001327567 us-gaap:ForeignGovernmentDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel2Member 2024-07-31 0001327567 us-gaap:ForeignGovernmentDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel3Member 2024-07-31 0001327567 us-gaap:ForeignGovernmentDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember 2024-07-31 0001327567 us-gaap:AssetBackedSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel1Member 2025-07-31 0001327567 us-gaap:AssetBackedSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel2Member 2025-07-31 0001327567 us-gaap:AssetBackedSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel3Member 2025-07-31 0001327567 us-gaap:AssetBackedSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember 2025-07-31 0001327567 us-gaap:AssetBackedSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel1Member 2024-07-31 0001327567 us-gaap:AssetBackedSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel2Member 2024-07-31 0001327567 us-gaap:AssetBackedSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel3Member 2024-07-31 0001327567 us-gaap:AssetBackedSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember 2024-07-31 0001327567 us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel1Member 2025-07-31 0001327567 us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel2Member 2025-07-31 0001327567 us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel3Member 2025-07-31 0001327567 us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember 2025-07-31 0001327567 us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel1Member 2024-07-31 0001327567 us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel2Member 2024-07-31 0001327567 us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember us-gaap:FairValueInputsLevel3Member 2024-07-31 0001327567 us-gaap:FairValueMeasurementsRecurringMember us-gaap:ShortTermInvestmentsMember 2024-07-31 0001327567 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel1Member 2025-07-31 0001327567 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel2Member 2025-07-31 0001327567 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel3Member 2025-07-31 0001327567 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember 2025-07-31 0001327567 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel1Member 2024-07-31 0001327567 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel2Member 2024-07-31 0001327567 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel3Member 2024-07-31 0001327567 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember 2024-07-31 0001327567 us-gaap:USTreasuryAndGovernmentMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel1Member 2025-07-31 0001327567 us-gaap:USTreasuryAndGovernmentMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel2Member 2025-07-31 0001327567 us-gaap:USTreasuryAndGovernmentMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel3Member 2025-07-31 0001327567 us-gaap:USTreasuryAndGovernmentMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember 2025-07-31 0001327567 us-gaap:USTreasuryAndGovernmentMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel1Member 2024-07-31 0001327567 us-gaap:USTreasuryAndGovernmentMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel2Member 2024-07-31 0001327567 us-gaap:USTreasuryAndGovernmentMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel3Member 2024-07-31 0001327567 us-gaap:USTreasuryAndGovernmentMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember 2024-07-31 0001327567 us-gaap:ForeignGovernmentDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel1Member 2025-07-31 0001327567 us-gaap:ForeignGovernmentDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel2Member 2025-07-31 0001327567 us-gaap:ForeignGovernmentDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel3Member 2025-07-31 0001327567 us-gaap:ForeignGovernmentDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember 2025-07-31 0001327567 us-gaap:ForeignGovernmentDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel1Member 2024-07-31 0001327567 us-gaap:ForeignGovernmentDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel2Member 2024-07-31 0001327567 us-gaap:ForeignGovernmentDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel3Member 2024-07-31 0001327567 us-gaap:ForeignGovernmentDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember 2024-07-31 0001327567 us-gaap:AssetBackedSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel1Member 2025-07-31 0001327567 us-gaap:AssetBackedSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel2Member 2025-07-31 0001327567 us-gaap:AssetBackedSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel3Member 2025-07-31 0001327567 us-gaap:AssetBackedSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember 2025-07-31 0001327567 us-gaap:AssetBackedSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel1Member 2024-07-31 0001327567 us-gaap:AssetBackedSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel2Member 2024-07-31 0001327567 us-gaap:AssetBackedSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel3Member 2024-07-31 0001327567 us-gaap:AssetBackedSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember 2024-07-31 0001327567 us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel1Member 2025-07-31 0001327567 us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel2Member 2025-07-31 0001327567 us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel3Member 2025-07-31 0001327567 us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember 2025-07-31 0001327567 us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel1Member 2024-07-31 0001327567 us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel2Member 2024-07-31 0001327567 us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember us-gaap:FairValueInputsLevel3Member 2024-07-31 0001327567 us-gaap:FairValueMeasurementsRecurringMember us-gaap:OtherLongTermInvestmentsMember 2024-07-31 0001327567 us-gaap:ForeignExchangeForwardMember us-gaap:FairValueMeasurementsRecurringMember 2025-07-31 0001327567 us-gaap:ForeignExchangeForwardMember us-gaap:FairValueMeasurementsRecurringMember 2024-07-31 0001327567 us-gaap:ForeignExchangeForwardMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member 2025-07-31 0001327567 us-gaap:ForeignExchangeForwardMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member 2025-07-31 0001327567 us-gaap:ForeignExchangeForwardMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member 2025-07-31 0001327567 us-gaap:ForeignExchangeForwardMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member 2024-07-31 0001327567 us-gaap:ForeignExchangeForwardMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member 2024-07-31 0001327567 us-gaap:ForeignExchangeForwardMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member 2024-07-31 0001327567 us-gaap:CommercialPaperMember us-gaap:CashEquivalentsMember 2025-07-31 0001327567 us-gaap:CashEquivalentsMember 2025-07-31 0001327567 us-gaap:CommercialPaperNotIncludedWithCashAndCashEquivalentsMember us-gaap:InvestmentsMember 2025-07-31 0001327567 us-gaap:CorporateDebtSecuritiesMember us-gaap:InvestmentsMember 2025-07-31 0001327567 us-gaap:USTreasuryAndGovernmentMember us-gaap:InvestmentsMember 2025-07-31 0001327567 us-gaap:ForeignGovernmentDebtSecuritiesMember us-gaap:InvestmentsMember 2025-07-31 0001327567 us-gaap:AssetBackedSecuritiesMember us-gaap:InvestmentsMember 2025-07-31 0001327567 us-gaap:InvestmentsMember 2025-07-31 0001327567 us-gaap:CommercialPaperMember us-gaap:CashEquivalentsMember 2024-07-31 0001327567 us-gaap:CorporateDebtSecuritiesMember us-gaap:CashEquivalentsMember 2024-07-31 0001327567 us-gaap:USTreasuryAndGovernmentMember us-gaap:CashEquivalentsMember 2024-07-31 0001327567 us-gaap:CashEquivalentsMember 2024-07-31 0001327567 us-gaap:CertificatesOfDepositMember us-gaap:InvestmentsMember 2024-07-31 0001327567 us-gaap:CommercialPaperNotIncludedWithCashAndCashEquivalentsMember us-gaap:InvestmentsMember 2024-07-31 0001327567 us-gaap:CorporateDebtSecuritiesMember us-gaap:InvestmentsMember 2024-07-31 0001327567 us-gaap:USTreasuryAndGovernmentMember us-gaap:InvestmentsMember 2024-07-31 0001327567 us-gaap:ForeignGovernmentDebtSecuritiesMember us-gaap:InvestmentsMember 2024-07-31 0001327567 us-gaap:AssetBackedSecuritiesMember us-gaap:InvestmentsMember 2024-07-31 0001327567 us-gaap:InvestmentsMember 2024-07-31 0001327567 us-gaap:MoneyMarketFundsMember 2025-07-31 0001327567 us-gaap:MoneyMarketFundsMember 2024-07-31 0001327567 panw:InternalCreditRiskRating1To4Member 2025-07-31 0001327567 panw:InternalCreditRiskRating1To4Member 2024-07-31 0001327567 panw:InternalCreditRiskRating5To6Member 2025-07-31 0001327567 panw:InternalCreditRiskRating5To6Member 2024-07-31 0001327567 panw:InternalCreditRiskRating7To10Member 2025-07-31 0001327567 panw:InternalCreditRiskRating7To10Member 2024-07-31 0001327567 us-gaap:CashFlowHedgingMember 2025-07-31 0001327567 us-gaap:CashFlowHedgingMember 2024-07-31 0001327567 us-gaap:NondesignatedMember 2025-07-31 0001327567 us-gaap:NondesignatedMember 2024-07-31 0001327567 panw:IBMsQRadarAssetsMember 2024-08-31 2024-08-31 0001327567 panw:IBMsQRadarAssetsMember 2024-08-31 0001327567 panw:IBMsQRadarAssetsMember us-gaap:CustomerRelationshipsMember 2024-08-31 2024-08-31 0001327567 panw:IBMsQRadarAssetsMember us-gaap:DevelopedTechnologyRightsMember 2024-08-31 2024-08-31 0001327567 2024-08-31 2024-08-31 0001327567 panw:ProtectAIMember 2025-07-22 2025-07-22 0001327567 panw:ProtectAIMember 2025-07-22 0001327567 panw:ProtectAIMember us-gaap:DevelopedTechnologyRightsMember 2025-07-22 2025-07-22 0001327567 panw:CyberArkSoftwareLtd.Member 2025-07-30 0001327567 panw:CyberArkSoftwareLtd.Member 2025-07-30 2025-07-30 0001327567 panw:CyberArkSoftwareLtd.Member panw:PaloAltoNetworksMember 2025-07-30 0001327567 panw:CyberArkSoftwareLtd.Member panw:CyberArkSoftwareLtd.Member 2025-07-30 0001327567 panw:DigSecuritySolutionsLtdMember 2023-12-05 2023-12-05 0001327567 panw:DigSecuritySolutionsLtdMember panw:ReplacementEquityAwardsMember 2023-12-05 2023-12-05 0001327567 panw:DigSecuritySolutionsLtdMember us-gaap:RestrictedStockMember 2023-12-05 2023-12-05 0001327567 panw:DigSecuritySolutionsLtdMember 2023-12-05 0001327567 panw:DigSecuritySolutionsLtdMember us-gaap:DevelopedTechnologyRightsMember 2023-12-05 2023-12-05 0001327567 panw:TalonCyberSecurityLtdMember 2023-12-28 2023-12-28 0001327567 panw:TalonCyberSecurityLtdMember panw:ReplacementEquityAwardsMember 2023-12-28 2023-12-28 0001327567 panw:TalonCyberSecurityLtdMember us-gaap:RestrictedStockMember 2023-12-28 2023-12-28 0001327567 panw:TalonCyberSecurityLtdMember 2023-12-28 0001327567 panw:TalonCyberSecurityLtdMember us-gaap:DevelopedTechnologyRightsMember 2023-12-28 2023-12-28 0001327567 panw:CiderSecurityLtdMember 2022-12-20 2022-12-20 0001327567 panw:CiderSecurityLtdMember panw:ReplacementEquityAwardsMember 2022-12-20 2022-12-20 0001327567 panw:CiderSecurityLtdMember us-gaap:RestrictedStockMember 2022-12-20 2022-12-20 0001327567 panw:CiderSecurityLtdMember 2022-12-20 0001327567 panw:CiderSecurityLtdMember us-gaap:DevelopedTechnologyRightsMember 2022-12-20 2022-12-20 0001327567 panw:UndisclosedAcquireeMember 2023-04-01 2023-04-30 0001327567 us-gaap:DevelopedTechnologyRightsMember 2025-07-31 0001327567 us-gaap:DevelopedTechnologyRightsMember 2024-07-31 0001327567 us-gaap:CustomerRelationshipsMember 2025-07-31 0001327567 us-gaap:CustomerRelationshipsMember 2024-07-31 0001327567 us-gaap:PatentsMember 2025-07-31 0001327567 us-gaap:PatentsMember 2024-07-31 0001327567 us-gaap:TrademarksAndTradeNamesMember 2025-07-31 0001327567 us-gaap:TrademarksAndTradeNamesMember 2024-07-31 0001327567 us-gaap:OtherIntangibleAssetsMember 2025-07-31 0001327567 us-gaap:OtherIntangibleAssetsMember 2024-07-31 0001327567 panw:ComputerEquipmentEquipmentandSoftwareandSoftwareDevelopmentCostsMember 2025-07-31 0001327567 panw:ComputerEquipmentEquipmentandSoftwareandSoftwareDevelopmentCostsMember 2024-07-31 0001327567 us-gaap:LeaseholdImprovementsMember 2024-07-31 0001327567 us-gaap:LandMember 2025-07-31 0001327567 us-gaap:LandMember 2024-07-31 0001327567 panw:DemonstrationunitsMember 2025-07-31 0001327567 panw:DemonstrationunitsMember 2024-07-31 0001327567 us-gaap:FurnitureAndFixturesMember 2024-07-31 0001327567 panw:A2023NotesMember 2018-07-31 0001327567 panw:A2025NotesMember 2020-06-30 0001327567 panw:A2023NotesMember 2018-07-01 2018-07-31 0001327567 panw:A2025NotesMember 2020-06-01 2020-06-30 0001327567 panw:A2025NotesMember 2024-08-01 2025-07-31 0001327567 panw:A2025NotesMember 2023-08-01 2024-07-31 0001327567 panw:A2025NotesMember 2022-08-01 2023-07-31 0001327567 panw:A2025NotesMember 2025-07-31 0001327567 panw:A2025NotesMember 2024-07-31 0001327567 panw:A2025NotesMember us-gaap:FairValueInputsLevel2Member 2024-07-31 0001327567 panw:A2023NotesMember 2024-08-01 2025-07-31 0001327567 panw:A2023NotesMember 2023-08-01 2024-07-31 0001327567 panw:A2023NotesMember 2022-08-01 2023-07-31 0001327567 panw:A2023NotesMember 2025-07-31 0001327567 panw:A2023NotesMember 2024-07-31 0001327567 panw:A2023NotesMember 2023-07-31 0001327567 panw:A2025NotesMember 2023-07-31 0001327567 panw:A2023NoteHedgesMember 2018-07-01 2018-07-31 0001327567 panw:A2025NoteHedgesMember 2020-06-01 2020-06-30 0001327567 panw:A2023NoteHedgesMember us-gaap:CommonStockMember 2024-08-01 2025-07-31 0001327567 panw:A2023NoteHedgesMember us-gaap:CommonStockMember 2023-08-01 2024-07-31 0001327567 panw:A2023NoteHedgesMember us-gaap:CommonStockMember 2022-08-01 2023-07-31 0001327567 panw:A2023WarrantsMember 2018-07-31 0001327567 panw:A2023WarrantsMember 2018-07-01 2018-07-31 0001327567 panw:A2025WarrantsMember 2020-06-30 0001327567 panw:A2025WarrantsMember 2020-06-01 2020-06-30 0001327567 panw:A2023WarrantsMember 2023-08-01 2024-07-31 0001327567 us-gaap:RevolvingCreditFacilityMember 2023-04-13 0001327567 us-gaap:RevolvingCreditFacilityMember us-gaap:BaseRateMember srt:MinimumMember 2023-04-13 2023-04-13 0001327567 us-gaap:RevolvingCreditFacilityMember us-gaap:BaseRateMember srt:MaximumMember 2023-04-13 2023-04-13 0001327567 us-gaap:RevolvingCreditFacilityMember us-gaap:SecuredOvernightFinancingRateSofrMember srt:MinimumMember 2023-04-13 2023-04-13 0001327567 us-gaap:RevolvingCreditFacilityMember us-gaap:SecuredOvernightFinancingRateSofrMember srt:MaximumMember 2023-04-13 2023-04-13 0001327567 us-gaap:RevolvingCreditFacilityMember srt:MinimumMember 2023-04-13 2023-04-13 0001327567 us-gaap:RevolvingCreditFacilityMember srt:MaximumMember 2023-04-13 2023-04-13 0001327567 us-gaap:RevolvingCreditFacilityMember 2025-07-31 0001327567 us-gaap:OperatingLeaseLeaseNotYetCommencedMember 2025-07-31 0001327567 srt:MinimumMember 2025-07-31 0001327567 srt:MaximumMember 2025-07-31 0001327567 panw:CloudMember 2025-07-31 0001327567 us-gaap:InventoriesMember 2025-07-31 0001327567 panw:OtherPurchaseObligationMember 2025-07-31 0001327567 panw:ServiceProviderPurchaseCommitmentMember 2024-08-01 2025-07-31 0001327567 2020-01-31 0001327567 2020-01-01 2020-01-31 0001327567 2024-01-22 2024-01-22 0001327567 2024-01-31 0001327567 2024-10-03 2024-10-03 0001327567 2024-10-03 0001327567 2019-02-28 0001327567 2022-08-30 0001327567 2023-11-30 0001327567 2024-08-31 0001327567 us-gaap:RestrictedStockUnitsRSUMember srt:MaximumMember panw:A2021EquityIncentivePlanMember 2024-08-01 2025-07-31 0001327567 panw:PerformanceStockUnitsPSUsMember srt:MinimumMember panw:A2021EquityIncentivePlanMember 2024-08-01 2025-07-31 0001327567 panw:PerformanceStockUnitsPSUsMember srt:MaximumMember panw:A2021EquityIncentivePlanMember 2024-08-01 2025-07-31 0001327567 panw:MarketConditionStockPriceTargetsMember panw:PerformanceStockUnitsPSUsSubjectToServiceAndMarketConditionsMember us-gaap:ShareBasedCompensationAwardTrancheOneMember panw:A2021EquityIncentivePlanMember 2022-08-01 2023-07-31 0001327567 panw:MarketConditionStockPriceTargetsMember panw:PerformanceStockUnitsPSUsSubjectToServiceAndMarketConditionsMember us-gaap:ShareBasedCompensationAwardTrancheTwoMember panw:A2021EquityIncentivePlanMember 2022-08-01 2023-07-31 0001327567 panw:MarketConditionStockPriceTargetsMember panw:PerformanceStockUnitsPSUsSubjectToServiceAndMarketConditionsMember us-gaap:ShareBasedCompensationAwardTrancheThreeMember panw:A2021EquityIncentivePlanMember 2022-08-01 2023-07-31 0001327567 panw:MarketConditionStockPriceTargetsMember panw:PerformanceStockUnitsPSUsSubjectToServiceAndMarketConditionsMember panw:ShareBasedPaymentArrangementTrancheFourMember panw:A2021EquityIncentivePlanMember 2022-08-01 2023-07-31 0001327567 panw:MarketConditionStockPriceTargetsMember panw:PerformanceStockUnitsPSUsSubjectToServiceAndMarketConditionsMember panw:A2021EquityIncentivePlanMember 2022-08-01 2023-07-31 0001327567 panw:MarketConditionStockPriceTargetsMember panw:PerformanceStockUnitsPSUsSubjectToServiceAndMarketConditionsMember srt:MinimumMember panw:A2021EquityIncentivePlanMember 2022-08-01 2023-07-31 0001327567 panw:MarketConditionStockPriceTargetsMember panw:PerformanceStockUnitsPSUsSubjectToServiceAndMarketConditionsMember srt:MaximumMember panw:A2021EquityIncentivePlanMember 2022-08-01 2023-07-31 0001327567 panw:MarketConditionTotalShareholderReturnVsStandardPoors500IndexMember panw:PerformanceStockUnitsPSUsSubjectToServiceAndMarketConditionsMember panw:A2021EquityIncentivePlanMember 2022-08-01 2023-07-31 0001327567 panw:A2021EquityIncentivePlanMember panw:PerformanceStockUnitsPSUsSubjectToServicePerformanceAndMarketConditionsMember 2024-08-01 2025-07-31 0001327567 panw:A2021EquityIncentivePlanMember panw:PerformanceStockUnitsPSUsSubjectToServicePerformanceAndMarketConditionsMember 2023-08-01 2024-07-31 0001327567 panw:A2021EquityIncentivePlanMember panw:PerformanceStockUnitsPSUsSubjectToServicePerformanceAndMarketConditionsMember 2022-08-01 2023-07-31 0001327567 panw:PerformanceStockUnitsPSUsSubjectToServicePerformanceAndMarketConditionsMember srt:MinimumMember panw:A2021EquityIncentivePlanMember 2024-08-01 2025-07-31 0001327567 panw:PerformanceStockUnitsPSUsSubjectToServicePerformanceAndMarketConditionsMember srt:MaximumMember panw:A2021EquityIncentivePlanMember 2024-08-01 2025-07-31 0001327567 panw:A2021EquityIncentivePlanMember panw:PerformanceStockUnitsPSUsSubjectToServicePerformanceAndMarketConditionsMember 2025-07-31 0001327567 panw:PerformanceStockOptionsMember us-gaap:ShareBasedCompensationAwardTrancheOneMember panw:A2021EquityIncentivePlanMember 2017-08-01 2019-07-31 0001327567 panw:PerformanceStockOptionsMember us-gaap:ShareBasedCompensationAwardTrancheTwoMember panw:A2021EquityIncentivePlanMember 2017-08-01 2019-07-31 0001327567 panw:PerformanceStockOptionsMember us-gaap:ShareBasedCompensationAwardTrancheThreeMember panw:A2021EquityIncentivePlanMember 2017-08-01 2019-07-31 0001327567 panw:PerformanceStockOptionsMember panw:ShareBasedPaymentArrangementTrancheFourMember panw:A2021EquityIncentivePlanMember 2017-08-01 2019-07-31 0001327567 panw:A2021EquityIncentivePlanMember panw:PerformanceStockOptionsMember 2017-08-01 2019-07-31 0001327567 panw:A2021EquityIncentivePlanMember 2025-07-31 0001327567 panw:A2012EmployeeStockPurchasePlanMember us-gaap:EmployeeStockMember 2017-08-28 2017-08-28 0001327567 panw:A2012EmployeeStockPurchasePlanMember us-gaap:EmployeeStockMember 2017-08-29 2017-08-29 0001327567 panw:A2012EmployeeStockPurchasePlanMember us-gaap:EmployeeStockMember 2024-08-01 2025-07-31 0001327567 panw:A2012EmployeeStockPurchasePlanMember us-gaap:EmployeeStockMember 2025-07-31 0001327567 panw:A2012EmployeeStockPurchasePlanMember us-gaap:EmployeeStockMember 2023-08-01 2024-07-31 0001327567 panw:A2012EmployeeStockPurchasePlanMember us-gaap:EmployeeStockMember 2022-08-01 2023-07-31 0001327567 panw:A2012EmployeeStockPurchasePlanMember us-gaap:EmployeeStockMember 2024-07-31 0001327567 panw:A2012EmployeeStockPurchasePlanMember us-gaap:EmployeeStockMember 2023-07-31 0001327567 us-gaap:EmployeeStockMember srt:MaximumMember panw:A2012EmployeeStockPurchasePlanMember 2025-07-31 0001327567 us-gaap:EmployeeStockOptionMember 2022-07-31 0001327567 us-gaap:EmployeeStockOptionMember 2021-08-01 2022-07-31 0001327567 panw:PerformanceStockOptionsMember 2022-07-31 0001327567 panw:PerformanceStockOptionsMember 2021-08-01 2022-07-31 0001327567 us-gaap:EmployeeStockOptionMember 2022-08-01 2023-07-31 0001327567 panw:PerformanceStockOptionsMember 2022-08-01 2023-07-31 0001327567 us-gaap:EmployeeStockOptionMember 2023-07-31 0001327567 panw:PerformanceStockOptionsMember 2023-07-31 0001327567 us-gaap:EmployeeStockOptionMember 2023-08-01 2024-07-31 0001327567 panw:PerformanceStockOptionsMember 2023-08-01 2024-07-31 0001327567 us-gaap:EmployeeStockOptionMember 2024-07-31 0001327567 panw:PerformanceStockOptionsMember 2024-07-31 0001327567 us-gaap:EmployeeStockOptionMember 2024-08-01 2025-07-31 0001327567 panw:PerformanceStockOptionsMember 2024-08-01 2025-07-31 0001327567 us-gaap:EmployeeStockOptionMember 2025-07-31 0001327567 panw:PerformanceStockOptionsMember 2025-07-31 0001327567 us-gaap:RestrictedStockUnitsRSUMember 2022-07-31 0001327567 panw:PerformanceStockUnitsPSUsMember 2022-07-31 0001327567 us-gaap:RestrictedStockUnitsRSUMember 2022-08-01 2023-07-31 0001327567 panw:PerformanceStockUnitsPSUsMember 2022-08-01 2023-07-31 0001327567 us-gaap:RestrictedStockUnitsRSUMember 2023-07-31 0001327567 panw:PerformanceStockUnitsPSUsMember 2023-07-31 0001327567 us-gaap:RestrictedStockUnitsRSUMember 2023-08-01 2024-07-31 0001327567 panw:PerformanceStockUnitsPSUsMember 2023-08-01 2024-07-31 0001327567 us-gaap:RestrictedStockUnitsRSUMember 2024-07-31 0001327567 panw:PerformanceStockUnitsPSUsMember 2024-07-31 0001327567 us-gaap:RestrictedStockUnitsRSUMember 2024-08-01 2025-07-31 0001327567 panw:PerformanceStockUnitsPSUsMember 2024-08-01 2025-07-31 0001327567 us-gaap:RestrictedStockUnitsRSUMember 2025-07-31 0001327567 panw:PerformanceStockUnitsPSUsMember 2025-07-31 0001327567 srt:MinimumMember panw:PerformanceStockUnitsPSUsSubjectToServicePerformanceAndMarketConditionsMember 2024-08-01 2025-07-31 0001327567 srt:MaximumMember panw:PerformanceStockUnitsPSUsSubjectToServicePerformanceAndMarketConditionsMember 2024-08-01 2025-07-31 0001327567 srt:MinimumMember panw:PerformanceStockUnitsPSUsSubjectToServicePerformanceAndMarketConditionsMember 2023-08-01 2024-07-31 0001327567 srt:MaximumMember panw:PerformanceStockUnitsPSUsSubjectToServicePerformanceAndMarketConditionsMember 2023-08-01 2024-07-31 0001327567 srt:MinimumMember panw:PerformanceStockUnitsPSUsSubjectToServicePerformanceAndMarketConditionsMember 2022-08-01 2023-07-31 0001327567 srt:MaximumMember panw:PerformanceStockUnitsPSUsSubjectToServicePerformanceAndMarketConditionsMember 2022-08-01 2023-07-31 0001327567 panw:PerformanceStockUnitsPSUsSubjectToServicePerformanceAndMarketConditionsMember 2024-08-01 2025-07-31 0001327567 panw:PerformanceStockUnitsPSUsSubjectToServicePerformanceAndMarketConditionsMember 2023-08-01 2024-07-31 0001327567 panw:PerformanceStockUnitsPSUsSubjectToServicePerformanceAndMarketConditionsMember 2022-08-01 2023-07-31 0001327567 us-gaap:EmployeeStockMember 2024-08-01 2025-07-31 0001327567 us-gaap:EmployeeStockMember 2023-08-01 2024-07-31 0001327567 us-gaap:EmployeeStockMember 2022-08-01 2023-07-31 0001327567 srt:MinimumMember us-gaap:EmployeeStockMember 2024-08-01 2025-07-31 0001327567 srt:MaximumMember us-gaap:EmployeeStockMember 2024-08-01 2025-07-31 0001327567 srt:MinimumMember us-gaap:EmployeeStockMember 2023-08-01 2024-07-31 0001327567 srt:MaximumMember us-gaap:EmployeeStockMember 2023-08-01 2024-07-31 0001327567 srt:MinimumMember us-gaap:EmployeeStockMember 2022-08-01 2023-07-31 0001327567 srt:MaximumMember us-gaap:EmployeeStockMember 2022-08-01 2023-07-31 0001327567 us-gaap:ProductMember us-gaap:CostOfSalesMember 2024-08-01 2025-07-31 0001327567 us-gaap:ProductMember us-gaap:CostOfSalesMember 2023-08-01 2024-07-31 0001327567 us-gaap:ProductMember us-gaap:CostOfSalesMember 2022-08-01 2023-07-31 0001327567 us-gaap:ServiceMember us-gaap:CostOfSalesMember 2024-08-01 2025-07-31 0001327567 us-gaap:ServiceMember us-gaap:CostOfSalesMember 2023-08-01 2024-07-31 0001327567 us-gaap:ServiceMember us-gaap:CostOfSalesMember 2022-08-01 2023-07-31 0001327567 us-gaap:ResearchAndDevelopmentExpenseMember 2024-08-01 2025-07-31 0001327567 us-gaap:ResearchAndDevelopmentExpenseMember 2023-08-01 2024-07-31 0001327567 us-gaap:ResearchAndDevelopmentExpenseMember 2022-08-01 2023-07-31 0001327567 us-gaap:SellingAndMarketingExpenseMember 2024-08-01 2025-07-31 0001327567 us-gaap:SellingAndMarketingExpenseMember 2023-08-01 2024-07-31 0001327567 us-gaap:SellingAndMarketingExpenseMember 2022-08-01 2023-07-31 0001327567 us-gaap:GeneralAndAdministrativeExpenseMember 2024-08-01 2025-07-31 0001327567 us-gaap:GeneralAndAdministrativeExpenseMember 2023-08-01 2024-07-31 0001327567 us-gaap:GeneralAndAdministrativeExpenseMember 2022-08-01 2023-07-31 0001327567 panw:PerformanceStockOptionsMember us-gaap:ShareBasedCompensationAwardTrancheTwoMember panw:A2021EquityIncentivePlanMember 2019-08-01 2020-07-31 0001327567 panw:PerformanceStockOptionsMember panw:ShareBasedPaymentArrangementTrancheFourMember panw:A2021EquityIncentivePlanMember 2019-08-01 2020-07-31 0001327567 panw:PerformanceStockOptionsMember us-gaap:ShareBasedCompensationAwardTrancheOneMember panw:A2021EquityIncentivePlanMember 2019-08-01 2020-07-31 0001327567 panw:PerformanceStockOptionsMember us-gaap:ShareBasedCompensationAwardTrancheThreeMember panw:A2021EquityIncentivePlanMember 2019-08-01 2020-07-31 0001327567 panw:A2021EquityIncentivePlanMember panw:PerformanceStockOptionsMember 2018-08-01 2019-07-31 0001327567 us-gaap:InternalRevenueServiceIRSMember 2025-07-31 0001327567 us-gaap:StateAndLocalJurisdictionMember 2025-07-31 0001327567 us-gaap:ForeignCountryMember 2025-07-31 0001327567 us-gaap:InternalRevenueServiceIRSMember us-gaap:ResearchMember 2025-07-31 0001327567 us-gaap:StateAndLocalJurisdictionMember us-gaap:ResearchMember 2025-07-31 0001327567 panw:RestrictedStockUnitsRSUsandPerformanceStockUnitsPSUsMember 2024-08-01 2025-07-31 0001327567 panw:RestrictedStockUnitsRSUsandPerformanceStockUnitsPSUsMember 2023-08-01 2024-07-31 0001327567 panw:RestrictedStockUnitsRSUsandPerformanceStockUnitsPSUsMember 2022-08-01 2023-07-31 0001327567 country:US 2025-07-31 0001327567 country:US 2024-07-31 0001327567 country:IL 2025-07-31 0001327567 country:IL 2024-07-31 0001327567 panw:CountriesExcludingUnitedStatesAndIsraelMember 2025-07-31 0001327567 panw:CountriesExcludingUnitedStatesAndIsraelMember 2024-07-31 0001327567 panw:NikeshAroraMember 2025-05-01 2025-07-31 0001327567 panw:NikeshAroraMember 2025-07-31 0001327567 2025-05-01 2025-07-31 Table of Contents UNITED STATES SECURITIES AND EXCHANGE COMMISSION Washington, D.C. 20549 _____________________ FORM 10-K _____________________ (Mark One) ☒ ANNUAL REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934 For the fiscal year ended July 31 , 2025 or ☐ TRANSITION REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934 For the transition period from to Commission File Number 001-35594 Palo Alto Networks, Inc . (Exact name of registrant as specified in its charter) Delaware 20-2530195 (State or other jurisdiction of incorporation or organization) (I.R.S. Employer Identification No.) 3000 Tannery Way Santa Clara , California 95054 (Address of principal executive offices, including zip code) ( 408 ) 753-4000 (Registrant’s telephone number, including area code) Securities registered pursuant to Section 12(b) of the Act: Title of each class Trading Symbol(s) Name of each exchange on which registered Common stock, $0.0001 par value per share PANW The Nasdaq Stock Market LLC (Nasdaq Global Select Market) Securities registered pursuant to Section 12(g) of the Act: None Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes ☒ No ☐ Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes ☐ No ☒ Indicate by check mark whether the registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yes ☒ No ☐ Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yes ☒ No ☐ Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See the definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company,” and “emerging growth company” in Rule 12b-2 of the Exchange Act. Large accelerated filer ☒ Accelerated filer ☐ Non-accelerated filer ☐ Smaller reporting company ☐ Emerging growth company ☐ If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐ Indicate by check mark whether the registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C. 7262(b)) by the registered public accounting firm that prepared or issued its audit report. ☒ If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements of the registrant included in the filing reflect the correction of an error to previously issued financial statements. ☐ Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the registrant’s executive officers during the relevant recovery period pursuant to §240.10D-1(b). ☐ Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Act). Yes ☐ No ☒ The aggregate market value of voting stock held by non-affiliates of the registrant was approximately $ 119.7 billion as of January 31, 2025, the last business day of the registrant’s most recently completed second fiscal quarter (based on the closing sales price for the common stock on the Nasdaq Global Select Market on such date). Shares of common stock held by each executive officer and director have been excluded in that such persons may be deemed to be affiliates. This determination of affiliate status is not necessarily a conclusive determination for other purposes. On August 18, 2025, 668.9 million shares of the registrant’s common stock, $0.0001 par value, were outstanding. DOCUMENTS INCORPORATED BY REFERENCE Portions of the information called for by Part III of this Annual Report on Form 10-K is hereby incorporated by reference from the definitive proxy statement for the registrant’s 2025 annual meeting of stockholders, which will be filed with the Securities and Exchange Commission not later than 120 days after the registrant’s fiscal year ended July 31, 2025. Table of Contents Table Of Contents Page PART I Item 1. Business 4 Item 1A. Risk Factors 14 Item 1B. Unresolved Staff Comments 37 Item 1C. Cybersecurity 37 Item 2. Properties 39 Item 3. Legal Proceedings 39 Item 4. Mine Safety Disclosures 39 PART II Item 5. Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities 40 Item 6. [Reserved] 41 Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations 42 Item 7A. Quantitative and Qualitative Disclosures About Market Risk 56 Item 8. Financial Statements and Supplementary Data 57 Item 9. Changes in and Disagreements with Accountants on Accounting and Financial Disclosure 95 Item 9A. Controls and Procedures 95 Item 9B. Other Information 96 Item 9C. Disclosure Regarding Foreign Jurisdictions That Prevent Inspections 96 PART III Item 10. Directors, Executive Officers and Corporate Governance 97 Item 11. Executive Compensation 97 Item 12. Security Ownership of Certain Beneficial Owners and Management and Related Stockholder Matters 97 Item 13. Certain Relationships and Related Transactions, and Director Independence 97 Item 14. Principal Accountant Fees and Services 97 PART IV Item 15. Exhibits and Financial Statement Schedules 98 Item 16. Form 10-K Summary 101 Signatures 102 - 2 - Table of Contents Part I SPECIAL NOTE REGARDING FORWARD-LOOKING STATEMENTS This Annual Report on Form 10-K, including, without limitation, the sections entitled “Business,” “Risk Factors,” and “Management’s Discussion and Analysis of Financial Condition and Results of Operations,” contains forward-looking statements within the meaning of Section 27A of the Securities Act of 1933 and Section 21E of the Securities Exchange Act of 1934. Forward-looking statements generally can be identified by words such as “anticipate,” “believe,” “continue,” “could,” “estimate,” “expect,” “intend,” “may,” “plan,” “potentially,” “projects,” “will,” “will be,” “will continue,” “will likely result,” “would,” and similar expressions that convey uncertainty of future events or outcomes. These forward-looking statements include, but are not limited to, statements concerning the following: • expectations regarding the cybersecurity landscape; • expectations regarding our platformization strategy and related progress and opportunities; • expectations regarding annual recurring revenue, remaining performance obligations, and product development strategy; • expectations regarding artificial intelligence; • expectations regarding our strategic partnerships; • expectations regarding drivers of and factors affecting growth in our business; • statements regarding expected profitability, trends in annual recurring revenue, trends in remaining performance obligations, our mix of product and subscription and support revenue, cost of revenue, gross margin, cash flows, operating expenses, including future share-based compensation expense, income taxes, investment plans, and liquidity; • expected recurring revenues resulting from growth in our end-customers and increased adoption of our products and cloud-delivered security solutions; • the performance advantages of our products and subscription and support offerings and the potential benefits to our customers; • expectations regarding future investments in research and development and product development, customer support, in our employees and in our sales force, including expectations regarding growth in our sales headcount; • expectations that we will continue to expand our global presence; • expectations regarding our revenues, including the seasonality and cyclicality from quarter to quarter; • expectations relating to our customer financing activities; • the sufficiency of our cash flow from operations with existing cash, cash equivalents, and investments to meet our cash needs for the foreseeable future; • our ability to successfully acquire and integrate companies and assets and expectations and intentions with respect to the assets, products and technologies that we acquire, including with respect to our proposed acquisition of CyberArk Software Ltd. and our expectations regarding the benefits and synergies of the proposed acquisition; • our ability to complete, on a timely basis, or at all, announced transactions, including our proposed acquisition of CyberArk Software Ltd.; • expectations regarding contingent consideration obligations; • the timing and amount of capital expenditures and share repurchases; • the effects of worldwide economic and geopolitical conditions, including but not limited to hostilities in Israel and the surrounding regions, inflation, tariff rates, interest rate levels, public or administration policies, trade regulations, trade policy, growth rates and other conditions, on our operating and financial results and performance; • the manufacture, delivery and cost of certain of our products; • the effects of litigation or regulatory developments involving us or affecting our industry; and • other statements regarding our future operations, financial condition and prospects, and business strategies. These forward-looking statements are based on current expectations and assumptions that are subject to risks and uncertainties, including those described in “Risk Factors” included in Part I, Item 1A and elsewhere in this Annual Report on Form 10-K. Moreover, we operate in a very competitive and rapidly changing environment, and new risks emerge from time to time. It is not possible for our management to predict all risks, nor can we assess the impact of all factors on our business or the extent to which any factor, or combination of factors, may cause actual results to differ materially from those contained in any forward-looking statements we may make. In light of these risks, uncertainties, and assumptions, the forward-looking events and circumstances discussed in this Annual Report on Form 10-K may not occur, and actual results could differ materially and adversely from those anticipated or implied in the forward-looking statements. We undertake no obligation to revise or publicly release the results of any revision to these forward-looking statements, except as required by law. Given these risks and uncertainties, readers are cautioned not to place undue reliance on such forward-looking statements. - 3 - Table of Contents Item 1. Business General Palo Alto Networks, Inc. is a global cybersecurity provider and our vision is a world where each day is safer and more secure than the one before. We were incorporated in 2005 and are headquartered in Santa Clara, California. Our mission is to be the cybersecurity partner of choice for enterprises, organizations, service providers, and government entities to protect our digital way of life. Our cybersecurity platforms and services help secure enterprise users, networks, clouds, and endpoints by delivering comprehensive cybersecurity backed by artificial intelligence (“AI”) and automation. A key element of our strategy is to help our customers simplify their security architectures through consolidating disparate point products. We execute on this strategy by developing our capabilities and packaging our offerings into platforms which are able to cover many of our customers’ needs in the markets in which we operate. Our platformization strategy combines various products and services into a tightly integrated architecture for more secure, faster, and cost-effective outcomes. Network Security Our network security platform is designed to deliver complete zero trust solutions to our customers. The platform includes: • Secure Access Service Edge (“SASE”). Prisma ® Access, when combined with Prisma SD-WAN, provides a comprehensive single-vendor SASE offering that is used to secure remote workforces and cloud-delivered branch offices. Prisma Access Browser further extends SASE security and data protection to the end user device, providing workers with freedom to access business applications securely using our secure browser from any device. • Next-Generation Firewalls . Our hardware ML-Powered Next-Generation Firewalls (“NGFWs”) secure on-premises environments including campus locations and data centers. Our software NGFWs secure cloud networks. • Cloud-Delivered Security Services (“CDSS”) . Our network security platform integrates a suite of CDSS that complements our SASE and Firewall solutions. These include Advanced Threat Prevention, Advanced WildFire ® , Advanced URL Filtering, Advanced DNS Security, IoT/OT Security, GlobalProtect ® , Prisma Access Agent, Enterprise Data Loss Prevention (“Enterprise DLP”), AI for IT Operations (“AIOps”), Software as a Service (“SaaS”) Security, and AI Access Security. Through these add-on services, our customers are able to secure their content, applications, users, and devices across their entire organization. • Prisma AIRS. Prisma AIRS is a comprehensive AI security platform that has been designed to protect customers’ entire AI ecosystem by providing AI model scanning, posture management, red teaming, run-time security, and AI agent security. • Strata Cloud Manager (“SCM”) . SCM, our network security management solution, centrally manages network security across all remote workers, branches, headquarters, campuses, and cloud. SCM leverages AI to simplify and strengthen network security by enabling customers to proactively pinpoint vulnerabilities, gain real-time remediation recommendations, and enhance overall digital experiences, thereby reducing operational burden. This comprehensive solution includes Strata Copilot, which offers a natural language interface for enhanced insights and guided remediation, and integrates Autonomous Digital Experience Monitoring (“ADEM”) to proactively maintain infrastructure health, facilitate AI-driven one-click troubleshooting, and ensure seamless end-user performance across the enterprise. Security Operations Our AI-powered Cortex platform transforms end-to-end security operations with unified data, AI, and automation for more secure, faster, and cost effective outcomes. We have consolidated our industry-leading Security Operations and Cloud Security capabilities on a single comprehensive platform to provide centralized visibility, proactive protection, real-time prevention, AI-driven insights, and automated remediation across enterprise and cloud. • Security Operations. We deliver the next generation of security operations capabilities that unifies standalone Security Information and Event Management (“SIEM”) tools, endpoint security, security automation, cloud detection and response (“CDR”), as well as attack surface management (“ASM”) capabilities on our Cortex ® platform. These include Cortex XSIAM ® , for AI-powered security operations replacing traditional SIEM tools, Cortex XDR ® , for the prevention, detection, and response to complex cybersecurity attacks, Cortex XSOAR ® , for security orchestration, automation, and response (“SOAR”), and Cortex Xpanse ® , for ASM. • Cloud Security. We deliver comprehensive security across the cloud application development lifecycle through Cortex Cloud, delivered as a scalable SaaS offering. As a comprehensive Cloud Native Application Protection Platform (“CNAPP”) combined with CDR, Cortex Cloud secures multi- and hybrid-cloud environments for applications, data, generative AI (“GenAI”) ecosystem, and the cloud native technology stack across the full development lifecycle, from code to cloud to security operations. As part of the Cortex Cloud platform, customers can expand from Cortex Cloud to our security operations offerings available on a single user experience and unified agent. We also offer our VM-Series and CN-Series virtual firewalls for inline network security on multi- and hybrid-cloud environments. - 4 - Table of Contents Threat Intelligence and Advisory Services • Unit 42 ® brings together world-renowned expertise across threat research, incident response, and security consulting to deliver intelligence-driven, response-ready outcomes that help customers reduce cyber risk. Our elite consultants serve as trusted advisors to our customers by assessing and testing their security controls against sophisticated threats, transforming their security strategy with a threat-informed approach, and responding to security incidents on behalf of our clients. Additionally, Unit 42 offers managed detection and response (“MDR”) and managed threat hunting services. Products and Services NETWORK SECURITY Secure Access Service Edge • Prisma Access. Prisma Access is a cloud-delivered security offering that helps organizations deliver consistent AI-driven security to remote networks and mobile users. With more than 100 locations around the world, Prisma Access offers global coverage, consistently inspecting all traffic across all ports and providing bidirectional networking to enable branch-to-branch and branch-to-headquarter traffic. Prisma Access consolidates point products into a single cloud-delivered solution, transforming network security and allowing organizations to enable secure hybrid work. Prisma Access protects all application traffic with complete, best-in-class security while also delivering a seamless user experience with industry-leading service-level agreements (“SLA”s). With native SASE integration, Prisma Access Browser extends Zero Trust to any device—managed or unmanaged—in minutes. Prisma Access delivers seamless user experience with a combination of application acceleration—up to 5x faster than direct-to-internet—and Autonomous Digital Experience Management. • Prisma SD-WAN. Our Prisma SD-WAN solution is a next-generation SD-WAN solution that makes the secure cloud-delivered branch possible. Prisma SD-WAN enables organizations to replace traditional wide area network (“WAN”) architectures with affordable broadband and internet transport types that promote improved bandwidth availability, redundancy and performance at a reduced cost. Prisma SD-WAN leverages real-time application performance SLAs and visibility to control and intelligently steer application traffic to deliver a powerful user experience. Prisma SD-WAN also provides the flexibility of deploying with an on-premises controller to help businesses meet their industry-specific security compliance requirements and manage deployments with application-defined policies. Our Prisma SD-WAN simplifies network and security operations using AI and automation. Next-Generation Firewalls. Our hardware and software ML-Powered Next Generation Firewalls use AI—including machine learning and deep learning—to stop zero-day threats in real time, and detect and secure the entire enterprise including Internet of Things (“IoT”). All of our hardware and software firewalls incorporate the PAN-OS ® operating system and include the same rich set of features, ensuring consistent operation across our entire product line. This includes SD-WAN capabilities to intelligently steer traffic to data centers, branches, and the cloud, natively integrated into our Next-Generation Firewalls. Enterprise data, applications, users, and devices become integral components of an organization’s security policy. Our hardware and software are designed for different performance requirements throughout an organization—with the ability to secure everything from small businesses and branch offices, to large-scale data centers and service providers. Our firewalls come in hardware form factors, containerized form factors, called CN-Series, as well as virtual form factors, called VM-Series, available on all major cloud hosting service providers. We also offer Cloud NGFW, a managed NGFW offering, to secure customers’ applications on Amazon Web Services (“AWS”) and Microsoft Azure (“Azure”). Cloud-Delivered Security Services • Advanced Threat Prevention. This cloud-delivered security service provides intrusion detection and prevention capabilities and blocks vulnerability exploits, viruses, spyware, buffer overflows, denial-of-service attacks, and port scans from compromising and damaging enterprise information resources. In addition, we offer inline deep learning to deliver real-time detection and prevention of unknown, evasive, and targeted command-and-control (“C2”) communications over HTTP, unknown-TCP, unknown-UDP, and encrypted over SSL. Advanced Threat Prevention is the industry’s only offering to protect the enterprise from unknown command and control in real-time with the power of Precision AI TM . • Advanced WildFire. This cloud-delivered security service provides protection against targeted malware and advanced persistent threats and provides a near real-time analysis engine for detecting previously unseen malware while resisting attacker evasion techniques. Advanced WildFire combines dynamic and static analysis, recursive analysis, and a custom-built analysis environment with network traffic profiling and fileless attack detection to discover even the most sophisticated and evasive threats. Preventions are delivered in seconds to our network security platform. - 5 - Table of Contents • Advanced URL Filtering. This cloud-delivered security service offers the industry’s first Inline Deep Learning powered web protection engine. We deliver real-time detection and prevention of unknown, evasive, and targeted web-based threats, such as phishing. In addition, the service includes a cloud-based URL filtering database which consists of millions of URLs across many categories and is designed to analyze web traffic and prevent web-based threats, such as phishing, malware, and C2. • Advanced DNS Security. This cloud-delivered security service uses machine learning to proactively block malicious domains and stop attacks in progress. The service allows our network security platform access to Domain Name System (“DNS”) signatures that are generated using advanced predictive analysis, machine learning, and malicious domain data from a growing threat intelligence sharing community of which we are a part of. We offer comprehensive DNS attack coverage and include industry-first protections against multiple emerging DNS-based network attacks, including real-time analysis of DNS response to prevent DNS hijacking. • IoT/OT Security. This cloud-delivered security service uses machine learning to accurately identify and classify various IoT and operational technology (“OT”) devices, including never-been-seen-before devices, mission-critical OT devices, and unmanaged legacy systems. The service uses machine learning to baseline normal behavior, identify anomalous activity, assess risk, and provide policy recommendations. • SaaS Security API. SaaS Security API is a multi-mode, cloud access security broker (“CASB”) that helps govern sanctioned SaaS application usage across all users and helps prevent breaches and non-compliance. Specifically, the service enables the discovery and classification of data stored in supported SaaS applications, protects sensitive data from accidental exposure, identifies and protects against known and unknown malware, and performs user activity monitoring to identify potential misuse or data exfiltration. The solution can be combined with SaaS Security Inline for a complete integrated CASB. • SaaS Security Inline. SaaS Security Inline adds an inline service to automatically gain visibility and control over thousands of known and newly sanctioned, unsanctioned and tolerated SaaS applications in use within organizations today. The service provides enterprise data protection and compliance across all SaaS applications and prevents cloud threats in real time. The solution can be combined with SaaS Security API as a complete integrated CASB. • GlobalProtect. This subscription provides protection for users of both traditional laptop and mobile devices. It expands the boundaries of the end-users’ physical network, effectively establishing a logical perimeter that encompasses remote laptop and mobile device users irrespective of their location. Regardless of the operating system, laptops, tablets, and phones will stay connected to the corporate network when they are on a network of any kind and as a result, are protected as if they never left the corporate campus. • Prisma Access Agent. Prisma Access Agent provides secure, remote access to corporate resources for employees working from any location or device. The agent establishes an encrypted tunnel to Prisma Access or our NGFW, ensuring consistent security, data protection, and threat prevention for a distributed workforce accessing any application. • Enterprise DLP. This cloud-delivered security service provides consistent and reliable protection of sensitive data, such as personally identifiable information and intellectual property, for all traffic types, applications, and users. Native integration with our products makes the service simple to deploy, while advanced machine learning minimizes management complexity. Enterprise DLP allows organizations to consistently discover, classify, monitor, and protect sensitive data, wherever it may reside. • AI Access Security. AI Access Security classifies and prioritizes GenAI applications to assess risk, detect anomalies and visualize insights across multiple GenAI-specific attributes. The service prevents sensitive data loss and defends against malicious responses, ensuring safe and effective AI adoption. • AIOps. AIOps enables security teams to proactively strengthen security posture and resolve network disruptions. AIOps provides continuous best practice recommendations powered by machine learning based on industry standards, security policy context, and advanced telemetry data collected from our network security customers to improve security posture. The service also intelligently predicts health, performance, and capacity problems up to seven days in advance and provides actionable insights to resolve the predicted disruptions. Prisma AIRS. Prisma AIRS is a comprehensive AI security platform engineered to protect customers' entire AI ecosystem across its lifecycle. It addresses unique AI security challenges such as prompt injection, data poisoning, and sensitive data leakage, by providing deep visibility and control across AI models, data, and applications. The platform offers AI Model Scanning for vulnerabilities, Posture Management for secure configurations, and AI Red Teaming for proactive testing. Critically, Runtime Security prevents threats during live AI model execution, while AI Agent Security extends protection to autonomous AI agents. - 6 - Table of Contents Strata Cloud Manager. SCM enables our customers to easily manage their Palo Alto Networks’ Network Security infrastructure—including NGFWs and SASE deployments—from the cloud, via one unified management interface. As an AI-powered, unified cloud management solution, SCM enables organizations to enhance their network security posture and streamline operations. It utilizes AI to swiftly identify potential vulnerabilities, provide real-time recommendations for remediation, proactively address support needs, and improve overall digital experiences, leading to reduced operational overhead and improved speed, accuracy, and scale of support. By analyzing telemetry, historical data, and its diverse knowledge base, SCM can instantly answer questions, pinpoint solutions to known problems, and automate data collection to speed up assisted support for new challenges. Built into this robust solution are Strata Copilot, offering a natural language interface for intuitive insights and guided actions, and ADEM, designed for proactive infrastructure health, simplified troubleshooting, and consistent end-user performance across the network. Panorama. Panorama is used for centralized policy management, device management, software licensing and updates, centralized logging and reporting, and log storage. Many of our existing deployments continue to use Panorama as the security management solution. New deployments benefit from using SCM for managing network security estate—including our Next-Generation Firewalls and SASE—with a cloud-based, unified management interface. SECURITY OPERATIONS • Cortex XSIAM. Our cloud-based AI-powered security operations platform harnesses the power of AI to significantly improve security outcomes and transform security operations. Cortex XSIAM customers are able to consolidate multiple products into a single unified platform that delivers security information and event management, extended detection and response (“XDR”), SOAR, network traffic analysis, ASM, threat intelligence management (“TIM”), identity threat detection and response, and CDR. CDR is the latest addition to Cortex XSIAM and XDR that addresses the growing need for security teams to respond to cloud threats with purpose-built SOC tools that seamlessly integrate with their security programs. Cortex XSIAM integrates these capabilities into a single platform built for security operations, enabling organizations to simplify operations, stop threats at scale, and accelerate incident remediation. Cortex XSIAM automates data integration, analysis, and triage to respond to most alerts, enabling analysts to focus on only the incidents that require human intervention. • Cortex XDR. This cloud-based service enables organizations to collect telemetry from endpoint, network, identity and cloud data sources and apply advanced analytics and machine learning, to quickly find and stop targeted attacks, insider abuse, and compromised endpoints. Cortex XDR has two product tiers: XDR Prevent and XDR Pro. XDR Prevent delivers enterprise-class endpoint security focused on preventing attacks. XDR Pro extends endpoint detection and response (“EDR”) to include cross-data analytics for network, cloud, and identity data. Going beyond EDR, Cortex XDR detects the most complex threats using analytics across key data sources and reveals the root cause, which can significantly reduce investigation time as compared to siloed tools and manual processes. • Cortex XSOAR. Available as a stand-alone cloud-based service, an on-premises virtual appliance, or delivered natively through Cortex XSIAM, Cortex XSOAR is a comprehensive SOAR offering that unifies playbook automation, case management, real-time collaboration, and threat intelligence management to serve security teams across the incident lifecycle. With Cortex XSOAR, security teams can standardize processes, automate repeatable tasks, and manage incidents across their security product stack to improve response time and analyst productivity. Cortex XSOAR learns from the real-life analyst interactions and past investigations to help SOC teams with analyst assignment suggestions, playbook enhancements, and best next steps for investigations. Many of our customers see significantly faster SOC response times and a significant reduction in the number of SOC alerts which require human intervention. • Cortex Xpanse. Available as a stand-alone cloud-based service and a cloud-based subscription module within Cortex XSIAM, Cortex Xpanse provides ASM, which is the ability for an organization to identify what an attacker would see among all of its sanctioned and unsanctioned Internet-facing assets. In addition, Cortex Xpanse detects risky or out-of-policy communications between Internet-connected assets that can be exploited for data breaches or ransomware attacks. Cortex Xpanse continuously identifies Internet assets, risky services, or misconfigurations in third parties to help secure a supply chain or identify risks for mergers and acquisitions due diligence. Finally, compliance teams use Cortex Xpanse to improve their audit processes and stay in compliance by assessing their access controls against regulatory frameworks. • Cortex Cloud. Available as a stand-alone cloud-based service or an add-on to Cortex XDR or to Cortex XSIAM. Cortex Cloud, the next generation of Prisma Cloud, merges CNAPP with CDR for real-time cloud security. The solution allows you to harness the power of AI and automation to prioritize cloud risks with runtime context, enable remediation at scale, and stop attacks as they happen. Cortex Cloud consolidates multiple code and cloud security technologies such as Cloud Detection and Response, Software Composition Analysis, Infrastructure as Code security, CI/CD security, secrets scanning, Cloud Security Posture Management, Cloud Identity and Entitlements Management, API security, Vulnerability Management, Cloud Workload Protection, Web Application and API Security, Cloud Network Security, and Cloud Attack Surface Management into a single unified offering. As part of the Cortex platform, customers can transform end-to-end security operations, from code to cloud to SOC, by adopting Cortex Cloud together with Cortex XSIAM. Existing customers can continue leveraging Prisma Cloud as they upgrade to Cortex Cloud for significantly better, faster and more effective multi-cloud protection. - 7 - Table of Contents THREAT INTELLIGENCE AND ADVISORY SERVICES • Customer Support. Global customer support helps our customers achieve their security outcomes with services and support capabilities covering the customer's entire journey with Palo Alto Networks. This post-sales, global organization advances our customers’ security maturity, supporting them when, where, and how they need it. We offer Standard Support, Premium Support, and Platinum Support to our end-customers and channel partners. Our channel partners that operate a Palo Alto Networks Authorized Support Center typically deliver level-one and level-two support. We provide level-three support 24 hours a day, seven days a week through regional support centers that are located worldwide. We also offer a service offering called Focused Services that includes Customer Success Managers to provide support for end-customers with unique or complex support requirements. We offer our end-customers ongoing support for hardware, software, and certain cloud offerings, which includes ongoing security updates, PAN-OS upgrades, bug fixes, and repairs. End-customers typically purchase these services for a one-year or longer term at the time of the initial product sale and typically renew for successive one-year or longer periods. Additionally, we provide expedited replacement for any defective hardware. We use a third-party logistics provider to manage our worldwide deployment of service-related spares. • Threat Intelligence, Incident Response and Security Consulting. Unit 42 brings together world-renowned threat researchers, incident responders, and security consultants to create an intelligence-driven, response-ready organization that is passionate about helping clients proactively manage cyber risk. We help security leaders assess and test their security controls, transform their security strategy with a threat-informed approach, and respond to incidents rapidly. The Unit 42 Threat Intelligence team provides threat research that enables security teams to understand adversary intent and attribution, while enhancing protections offered by our products and services to stop advanced attacks. Our security consultants serve as trusted partners with state-of-the-art cyber risk expertise and incident response capabilities, helping customers build effective security programs, uncover critical exposures to prevent incidents, and, should incidents occur, respond to them with speed and confidence. • Professional Services. Professional services are primarily delivered directly by Palo Alto Networks and through a global network of authorized channel partners to our end-customers and include on-location and remote, hands-on experts who plan, design, and deploy effective security solutions tailored to our end-customers’ specific requirements. These services include architecture design and planning, implementation, configuration, and firewall migrations for all our products, including Prisma and Cortex deployments. Customers can also purchase on-going technical experts to be part of customer’s security teams to aid in the implementation and operation of their Palo Alto Networks capabilities. Our education services include certifications, as well as free online technical courses and in-classroom training, which are primarily delivered through our authorized training partners. RESEARCH AND DEVELOPMENT Our research and development efforts are strategically centered on expanding our leadership within the enterprise security industry through AI-powered innovation. We focus on enhancing our integrated platforms and developing new software and hardware capabilities. Our engineering teams apply deep expertise in AI and machine learning across networking security, cloud security, endpoint security, and security operations to address the rapidly evolving threat landscape. This approach enables us to leverage core competencies across hardware and software for agile responsiveness and to ensure interoperability with third-party technologies. We supplement our own research with technologies and products licensed from third parties. We believe that innovation and timely development of new features and products is essential to meeting the needs of our end-customers and improving our competitive position. During fiscal 2025, we introduced several new offerings, including: Prisma Access Browser, new capabilities in our OT Security solution, Cortex Cloud, Prisma AIRS, and Cortex XSIAM 3.0. We plan to continue to significantly invest in our research and development efforts as we evolve and extend the capabilities of our portfolio. ACQUISITIONS We believe that the enterprise security industry in which we operate necessitates a variety of technologies, products, capabilities, and features. We evaluate opportunities to acquire complementary businesses, technologies, services, and intellectual property to complement our organic innovation and research and development efforts, advance the development of our platforms, and enable further investment in our key priority areas. Our evaluation of acquisition opportunities seeks to confirm that any potential transaction would accelerate our strategy, represent an attractive customer opportunity, address a customer need, align with our customer base and go-to-market strategy, and present a clear timeline and path for value accretion. Our acquisitions enable us to gain access to talent, technology, products and features, and can range in size and complexity, from those that enhance or complement existing products and accelerate development of features to those that result in new offerings. - 8 - Table of Contents For example, in August 2024, we completed the acquisition of certain QRadar assets from International Business Machines Corporation (“IBM”), which we expect will help accelerate the growth of our Cortex business. Additionally, in July 2025, we completed the acquisition of Protect AI, Inc., a privately-held cyber security company (“Protect AI”), which we expect will enhance the capabilities of our AI security platform. In July 2025, we also entered into a definitive agreement to acquire CyberArk Software Ltd. (“CyberArk”), an identity security company, which acquisition is expected to close during the second half of our fiscal 2026. For additional information related to the impact of acquisitions to our business, see Part I, Item 1A “Risk Factors” in this Form 10-K. INTELLECTUAL PROPERTY We believe that our intellectual property rights are valuable and important to our business, and that our success depends, in part, on our ability to protect and use our core technology and intellectual property rights. We rely on a combination of trademarks, patents, copyrights, trade secrets, license agreements, intellectual property assignment agreements, confidentiality procedures, non-disclosure agreements, and employee non-disclosure and invention assignment agreements to establish, protect and control the use of our proprietary technology and intellectual property rights. We continue to grow our global portfolio of intellectual property rights in connection with our products, services, research and development. We file patent applications to protect our intellectual property and believe that the duration of our issued patents is sufficient when considering the expected lives of our products. We have registered various trademarks for our company and our products in the United States (“U.S.”) and other jurisdictions internationally. We intend to continue pursuing additional protections for our proprietary technology and intellectual property to the extent we believe it would be beneficial and cost-effective. Despite our efforts to protect our proprietary technology and intellectual property rights, our rights may not be respected in the future or may be invalidated, circumvented, or challenged. Our industry is characterized by the existence of a large number of patents and frequent claims and related litigation based on allegations of patent infringement or other violations of intellectual property rights. We believe that competitors will try to develop products that are similar to ours and that may infringe our intellectual property rights. Our competitors, third-parties and non-practicing entities, may also claim that our cybersecurity platforms and services infringe their intellectual property rights. From time to time, third parties have in the past and may in the future assert claims of infringement, misappropriation and other violations of intellectual property rights against us or our customers, with whom our license or other agreements may obligate us to indemnify against these claims. Successful claims of infringement by a third party could affect our ability to offer, or prevent us from offering, certain products or features. This could result in time during which we may be unable to continue to offer our affected products or solutions because of a potential need for us to develop alternate, non-infringing technology, which could require significant time and resources, or require us to obtain a license, which may not be available on reasonable terms or at all, or could require us to pay substantial damages, royalties, or other fees. For additional information, see the section titled “Risks Related to Intellectual Property and Technology Licensing” in Part I, Item 1A “Risk Factors” in this Form 10-K. GOVERNMENT REGULATION We are subject to numerous U.S. federal, state, and foreign laws and regulations covering a wide variety of subject matters. Like other companies in the technology industry, we face scrutiny from both U.S. and foreign governments with respect to our compliance with laws and regulations. Our compliance with these laws and regulations may be onerous and could, individually or in the aggregate, increase our cost of doing business, impact our competitive position relative to our peers, and/or otherwise have an adverse impact on our business, reputation, financial condition, and operating results. For additional information about government regulation applicable to our business, see Part I, Item 1A “Risk Factors” in this Form 10-K. COMPETITION We operate in the intensely competitive enterprise security industry that is characterized by constant change and innovation. Changes in the application, threat, and technology landscape result in evolving customer requirements for the protection from threats and the safe enablement of applications. Our main competitors fall into four categories: • large companies that incorporate security features in their products, such as Cisco Systems, Inc. (“Cisco”), Microsoft, Alphabet, or those that have acquired, or may acquire, security vendors and have the technical and financial resources to bring competitive solutions to the market; • independent security vendors, such as Check Point Software Technologies Ltd. (“Check Point”), Fortinet, Inc. (“Fortinet”), CrowdStrike Holdings, Inc. (“CrowdStrike”), Zscaler, Inc. (“Zscaler”), and Wiz, Inc. (“Wiz”), that offer a mix of security products; • startups and point-product vendors that offer independent or emerging solutions across various areas of security; and • public cloud vendors and startups that offer solutions for cloud security (private, public, and hybrid cloud). - 9 - Table of Contents As our market grows, it will attract more highly specialized vendors, as well as larger vendors that may continue to acquire or bundle their products more effectively. The principal competitive factors in our market include: • product features, reliability, performance, and effectiveness; • product line breadth, diversity, and applicability; • product extensibility and ability to integrate with other technology infrastructures; • price and total cost of ownership; • adherence to industry standards and certifications; • strength of sales and marketing efforts; and • brand awareness and reputation. We believe we generally compete favorably with our competitors on the basis of these factors as a result of the features and performance of our portfolio , the ease of integration of our security solutions with technological infrastructures, and the relatively low total cost of ownership of our products. However, some of our competitors may have substantially greater financial, technical, and other resources, greater name recognition, larger sales and marketing budgets, broader distribution, more diversified product lines, and larger and more mature intellectual property portfolios. SALES, MARKETING, SERVICES, AND SUPPORT Customers. Our end-customers consist of enterprises, service providers, and government entities. Our end-customers operate in a variety of industries, including education, energy, financial services, government entities, healthcare, Internet and media, manufacturing, public sector, and telecommunications. Our end-customers deploy our portfolio of solutions for a variety of security use cases across several settings. Typical deployment settings include the enterprise network, the enterprise data center, cloud locations, branch or remote locations, and on-device agents. No single end-customer accounted for more than 10% of our total revenue in fiscal 2025, 2024, or 2023. Distribution. We primarily sell our products and subscription and support offerings to end-customers through our channel partners utilizing a two-tier, indirect fulfillment model whereby we sell our products and subscription and support offerings to our distributors, which, in turn, sell to our resellers, which then sell to our end-customers. Sales are generally subject to our standard, non-exclusive distributor agreement, which provides for an initial term of one year, one-year renewal terms, termination by us with 30 to 90 days written notice prior to the renewal date, and payment to us from the channel partner within 30 to 45 calendar days of the date we issue an invoice for such sales. For fiscal 2025, 44.2% of our total revenue was derived from sales to three distributors. We also sell our VM-Series virtual firewalls and Cloud NGFW via various cloud marketplaces. For example, our VM-Series virtual firewalls are sold on Amazon’s AWS Marketplace, Microsoft’s Azure Marketplace, Alphabet’s Google Cloud Marketplace, and Oracle Corporation’s Oracle Cloud Marketplace either directly to end customers or as part of the respective cloud hosting service provider’s offerings under a usage-based licensing model. Sales. Our sales organization is responsible for large-account acquisition and overall market development, which includes the management of the relationships with our channel partners, working with our channel partners in winning and supporting end-customers through a direct-touch approach, and acting as the liaison between our end-customers and our marketing and product development organizations. We pursue sales opportunities both through our direct sales force and as assisted by our channel partners, which include resellers, global and regional systems integrators, service providers, managed security service providers, and cloud hosting service providers. We expect to continue to grow our sales headcount to expand our reach in all key growth sectors. Our sales organization is supported by sales engineers with responsibility for pre-sales technical support, solutions engineering for our end-customers, and technical training for our channel partners. Channel Program. Our NextWave Channel Partner program is focused on building in-depth relationships with solutions-oriented distributors, channel, delivery and services partners that have strong security expertise. The program rewards these partners based on a number of attainment goals, as well as provides them access to marketing resources, technical and sales training, and support. To promote optimal productivity, we operate a formal accreditation program for our channel partners’ sales and technical professionals. As of July 31, 2025, we had more than 8,500 channel partners. Global Customer Success. Our Global Customer Success organization is responsible for delivering professional, educational, and support services directly to our end-customers and partners. We leverage a global network of certified partners to extend the reach and consistency of these services. We believe that a comprehensive suite of customer success offerings is critical to the successful deployment, adoption, and ongoing use of our products. To support this, we have invested in hiring and developing technical experts with deep domain knowledge and proven experience across our portfolio. - 10 - Table of Contents Marketing. Our marketing is focused on building our brand reputation and the market awareness of our portfolio and driving pipeline and end-customer demand. Our marketing team consists primarily of product marketing, brand, demand generation, field marketing, digital marketing, communications, analyst relations, and marketing analytics functions. Marketing activities include pipeline development through demand generation, social media and advertising programs, managing the corporate website and partner portal, trade shows and conferences, analyst relationships, customer advocacy, and customer awareness. Every year we organize multiple signature events, such as our end-customer conference “Ignite” and focused conferences such as “Cortex Symphony” and “SASE Converge.” We also publish threat intelligence research, such as the Unit 42 Cloud Threat Report and the Unit 42 Network Threat Trends Research Report, which are based on data from our global threat intelligence team, Unit 42. These activities and tools benefit both our direct and indirect channels and are available at no cost to our channel partners. Our products and services have been recognized as leading in 25 categories by third-party industry analysts firms that perform independent assessments of these categories. This recognition by third parties is an important measure of validation for our customers. Backlog. Contract amounts that are not recorded in deferred revenue or revenue are considered backlog. Orders billed prior to revenue recognition are included in deferred revenue. We expect backlog will change from period to period for various reasons, including the timing of billing and fulfillment, such as inventory shortages. As such, we do not believe that backlog at any particular time is necessarily indicative of our future operating results. Seasonality. Our business is affected by seasonal fluctuations in customer spending patterns. We have begun to see seasonal patterns in our business, which we expect to become more pronounced as we continue to grow, with our strongest sequential revenue growth generally occurring in our fiscal second and fourth quarters. MANUFACTURING We outsource the manufacturing of our products to various manufacturing partners, which include our electronics manufacturing services provider (“EMS provider”) and original design manufacturers. This approach allows us to reduce our costs as it reduces our manufacturing overhead and inventory and also allows us to adjust more quickly to changing end-customer demand. Our EMS provider is Flextronics International, Ltd. (“Flex”), who assembles our products using design specifications, quality assurance programs, and standards that we establish, and procures components and assembles our products based on our demand forecasts. These forecasts are based upon historical trends and analysis, adjusted for overall market conditions. All of our hardware products are assembled in the U.S. The component parts within our products are either sourced by our manufacturing partners or by us from various component suppliers. Our manufacturing and supply contracts, generally, do not guarantee a certain level of supply or fixed pricing, which increases our exposure to supply shortages or price increases. HUMAN CAPITAL We believe our ongoing success depends on our employees. With a global workforce of 16,068 as of July 31, 2025, our People Strategy is a critical element of our overall company strategy and is overseen by our Chief People Officer who regularly updates our board of directors and the board’s Compensation and People Committee on human capital matters. Our People Strategy is designed to enable a workforce that is nimble, high-performing and innovative. We take a comprehensive approach to attracting, enabling and engaging world-class talent and fostering a culture where every employee can thrive. Our approach includes respecting each employee as a unique individual, demonstrating fairness in all we do and advancing a culture where employees are inspired to do the best work of their careers. We also focus on integrating AI into people programs and processes to build a more agile, skilled and forward-thinking workforce prepared for the future of cybersecurity. Our values of disruption, execution, collaboration, inclusion and integrity were co-created with employees and serve as the foundation of our culture. These values are embedded in our talent acquisition, learning and enablement, engagement and performance elevation, rewards and recognition programs. Attract & Hire. At Palo Alto Networks, we source talent with the necessary skills and capabilities to contribute to our culture and mission. We utilize structured interviewing practices, thorough job analyses and success profiles to identify high-quality candidates and staff critical roles. In fiscal 2025, we began to transform our hiring operations by strategically embedding AI across the talent acquisition lifecycle to sharpen our competitive edge for talent. We are deploying intelligent tools to automate and enhance core processes, including AI-generated job descriptions, structured interview guides and preparation materials; intelligent interview scheduling; launching an automated talent sourcing and screening pilot; and using AI to augment feedback summaries. Each step is optimized for speed, consistency and bias mitigation. Recognizing that technical skills evolve rapidly in an AI-driven world, our recruitment strategy prioritizes durable, "AI-readiness" capabilities. We assess candidates for core competencies such as critical thinking, adaptability and a capacity for continuous learning to help ensure every hire can not only excel today but also innovate and lead in the future. - 11 - Table of Contents Our Global Hiring Committee continues to play a key role in maintaining our hiring standards, which help drive objectivity. This group of cross-functional senior leaders reviews finalist candidates’ information with a focus on experience and capability. To build robust talent pipelines, we partner with academic institutions and other organizations to support new careers in cybersecurity, promote open roles, proactively reach out to candidates across multiple hiring channels and source candidates with a range of experiences. We also encourage employee referrals. Onboard & Enable. Each member of our workforce has a unique career journey and individual needs, interests and goals. To that end, we strive to create an environment where everyone feels valued, respected and supported to solve the world’s toughest cybersecurity challenges. In fiscal 2025, we started to evolve from a traditional training program to a system of AI-powered talent enablement, where we integrate learning and growth throughout the flow of an employee’s daily work. From day 1, new hires embark on a journey that blends in-person connection with personalized digital guidance, including generative AI onboarding roadmaps and AI-curated mentor networks. For ongoing growth, through The Learning Center, our intelligent learning platform, we deliver adaptive learning tracks for employees, including specialized paths for interns, new graduates and individuals joining through acquisitions. We also piloted real-time AI-enabled feedback simulations to coach and equip managers with the skills to guide their teams more effectively. Development information about core business elements, required company-wide compliance training and information about activities on topics ranging from well-being to collaboration are also offered. To further support our employees to advance up the AI adoption curve, we have offered self-paced online certifications, live training and an experimentation challenge that encouraged peer-driven use cases and employees voting to select the finalists. We will continue our enablement journey, using employee questions and feedback to offer both practical and role-specific use cases to help increase productivity and new skill acquisition. On average, employees completed 36 hours of development during fiscal 2025. Listen & Engage. We aim to foster engagement and help employees feel connected to our mission and values. Through our comprehensive approach, we use in-person and virtual channels to provide a regular flow of information to and between employees and leadership. These channels include company meetings, digital displays across our sites, our intranet, regular email communications, an active Slack platform, pulse surveys, a peer-to-peer recognition platform and regular two-way dialogue—such as small, in-person listening sessions hosted by our chief executive officer. Employee sentiment is also collected and measured from external sources, such as Glassdoor and Comparably. In addition, based on employee participation in an anonymous survey, the Best Practice Institute has certified Palo Alto Networks as one of the “Top 100 Global Most Loved Workplaces” since 2021. Palo Alto Networks has been recognized by Comparably for “Best Leadership Teams” and “Best Company Outlook”, in addition to other employer of choice awards. Our chief executive officer has also earned a 91% employee approval rating on Glassdoor, a top percentile score. In addition to our formal, company-wide, semiannual performance review process, which helps employees set learning and development plans, we believe in always-on performance feedback. Further providing engagement are eleven Employee Network Groups, open to all employees, that leverage different perspectives to build, understand and support our culture. Compensation & Benefits. We offer employees competitive compensation and our flexible benefits plans include a variety of health, time off, wellness and voluntary benefits. Our pay strategy, which includes base salary, cash bonus programs, and equity awards, focuses on compensation based on individual performance. Palo Alto Networks is a fair pay company and we annually engage a third-party consultancy to analyze our pay practices. Through our flexible benefits programs, employees are able to request reimbursement for a range of lifestyle items including fitness, caregiving and education. Additionally, through our Giving+ program, employees can request monetary matching of their charitable donations and volunteer time. Health, Safety & Wellbeing. Our commitment to the health, safety and wellbeing of our employees includes providing tools, resources and benefits focused on physical, mental and emotional wellbeing. This includes courses designed to equip employees with the knowledge to work safely, safety awareness campaigns and a mental health hub on our employee intranet. CORPORATE RESPONSIBILITY Our Corporate Responsibility (CR) strategy supports our company's purpose of a safe and secure world, and is informed through many inputs, including our business strategy and objectives, ongoing stakeholder engagement, investor and customer interests, benchmarking of industry best practices, regulatory developments and more. We execute meaningful CR initiatives that include advancing environmental sustainability, investing in people and operating with integrity. Advance Environmental Sustainability. Palo Alto Networks is doing our part to limit global warming to less than 1.5°C. Our decarbonization pathway includes implementing operational efficiencies, procuring 100% renewable electricity, targeting greenhouse gas emissions reductions across our value chain and making progress on our science-based targets. We continue to be recognized by CDP (formerly Carbon Disclosure Project) as a “Supplier Engagement Assessment A-list.” We report progress towards our goals in our annual Corporate Responsibility report. - 12 - Table of Contents Invest in People. In addition to our People Strategy described in the section titled “Human Capital” above, we continue to communicate our expectations regarding labor standards, business practices and workplace health and safety conditions to our supply chain through our Global Supplier Code of Conduct. During fiscal 2025, we maintained our affiliate membership in the Responsible Business Alliance. As a company built on trust, continuing to be a leader in responsible business practices and social impact supports our corporate strategy. We made charitable grants through our donor-advised fund to support nonprofit organizations providing services in areas such as cybersecurity education and expanding pathways to cyber careers. We maintained our work to provide cybersecurity curriculum to schools, universities and nonprofit organizations to help prepare people for careers in cybersecurity. Operate with Integrity. Integrity is one of our core values. Employees, contractors and suppliers are informed about our governance expectations, including through our Codes of Conduct, compliance training programs and ongoing communications. The Governance and Sustainability Committee of the board of directors provides primary oversight of corporate responsibility and the board of directors and applicable committees receive regular updates on corporate responsibility topics. AVAILABLE INFORMATION Our website is located at www.paloaltonetworks.com, and our investor relations website is located at investors.paloaltonetworks.com. Our Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, and amendments to reports filed or furnished pursuant to Sections 13(a) and 15(d) of the Securities Exchange Act of 1934, as amended (the “Exchange Act”), are available free of charge on the Investors portion of our website as soon as reasonably practicable after we electronically file such material with, or furnish it to, the Securities and Exchange Commission (“SEC”). We also provide a link to the section of the SEC’s website at www.sec.gov that has all of our public filings, including Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, all amendments to those reports, our Proxy Statements, and other ownership-related filings. We also use our investor relations website as a channel of distribution for important company information. For example, webcasts of our earnings calls and certain events we participate in or host with members of the investment community are on our investor relations website. Additionally, we announce investor information, including news and commentary about our business and financial performance, SEC filings, notices of investor events, and our press and earnings releases, on our investor relations website. Investors and others can receive notifications of new information posted on our investor relations website in real time by signing up for email alerts and RSS feeds. Further corporate governance information, including our corporate governance guidelines, board committee charters, and code of conduct, is also available on our investor relations website under the heading “Governance.” The contents of our websites are not incorporated by reference into this Annual Report on Form 10-K or in any other report or document we file with the SEC, and any references to our websites are intended to be inactive textual references only. All trademarks, trade names, or service marks used or mentioned herein belong to their respective owners. - 13 - Table of Contents Item 1A. Risk Factors Our operations and financial results are subject to various risks and uncertainties including those described below. The risks and uncertainties described below are not the only ones we face. Additional risks and uncertainties that we are unaware of, or that we currently believe are not material, also may become important factors that affect us. If any of the following risks or others not specified below materialize, our business, financial condition, and operating results could be materially adversely affected, and the market price of our common stock could decline. In addition, the impacts of any worsening of the economic environment may exacerbate the risks described below, any of which could have a material impact on us. Risk Factor Summary Our business is subject to numerous risks and uncertainties. These risks include, but are not limited to, the following: • Our operating results may be adversely affected by unfavorable economic and market conditions and the uncertain geopolitical environment. • Our business and operations have experienced growth in recent periods, and if we do not effectively manage any future growth or are unable to improve our systems, processes, and controls, our operating results could be adversely affected. • Our revenue growth rate in recent periods may not be indicative of our future performance, and we may not be able to maintain profitability, which could cause our business, financial condition, and operating results to suffer. • Our operating results may vary significantly from period to period, which makes our results difficult to predict and could cause our results to fall short of expectations, and such results may not be indicative of future performance. • Seasonality may cause fluctuations in our revenue. • If we are unable to sell new and additional product, subscription, and support offerings to our end-customers, especially to large enterprise customers, our future revenue and operating results will be harmed. • If we are unable to attract new customers, our future results of operations could be harmed. • We rely on revenue from subscription and support offerings, and because we recognize revenue from subscription and support over the term of the relevant service period, downturns or upturns in sales or renewals of these subscription and support offerings are not immediately reflected in full in our operating results. • The sales prices of our products, subscriptions, and support offerings may decrease, which may reduce our revenue and gross profits and adversely impact our financial results. • We rely on our channel partners to sell substantially all of our products, including subscriptions and support, and if these channel partners fail to perform, our ability to sell and distribute our products and subscriptions will be limited and our operating results will be harmed. • We are exposed to the credit and liquidity risk of our customers, and to credit exposure in weakened markets, which could result in material losses. • A portion of our revenue is generated by sales to government entities, which are subject to a number of challenges and risks. • We face intense competition in our market and we may lack sufficient financial or other resources to maintain or improve our competitive position. • We have and may in the future acquire other businesses (including CyberArk), which could subject us to adverse claims or liabilities, require significant management attention, disrupt our business, adversely affect our operating results, may not result in the expected benefits of such acquisitions, and may dilute stockholder value. • We may not complete the acquisition of CyberArk within the timeframe we anticipate or at all, which could negatively impact our future business and financial results. • As a result of the CyberArk acquisition, we anticipate that the scope and size of our business will substantially change and result in certain incremental risks, including increased competition. • If we do not accurately predict, prepare for, and respond promptly to rapidly evolving technological and market developments and successfully manage product and subscription introductions and transitions to meet changing end-customer needs in the enterprise security industry, our competitive position and prospects will be harmed. • Issues in the development and deployment of AI may result in reputational harm and legal liability and could adversely affect our results of operations. • A network or data security incident may allow unauthorized access to our network or data, harm our reputation, create additional liability, and adversely impact our financial results. • Defects, errors, or vulnerabilities in our products, subscriptions, or support offerings, the failure of our products or subscriptions to block a virus or prevent a security breach or incident, misuse of our products, or risks of product liability claims could harm our reputation and adversely impact our operating results. - 14 - Table of Contents • Our ability to sell our products and subscriptions is dependent on the quality of our technical support services and those of our channel partners, and the failure to offer high-quality technical support services could have a material adverse effect on our end-customers’ satisfaction with our products and subscriptions, our sales, and our operating results. • Claims by others that we infringe their intellectual property rights could harm our business. • Our proprietary rights may be difficult to enforce or protect, which could enable others to copy or use aspects of our products or subscriptions without compensating us. • Our use of open source software in our products and subscriptions could negatively affect our ability to sell our products and subscriptions and subject us to possible litigation. • We license technology from third parties, and our inability to maintain those licenses could harm our business. • Because we depend on manufacturing partners to build and ship our hardware products, we are susceptible to manufacturing and logistics delays and pricing fluctuations that could prevent us from shipping customer orders on time, if at all, or on a cost-effective basis, which may result in the loss of sales and end-customers. • Managing the supply of our hardware products and product components is complex. Insufficient supply and inventory would result in lost sales opportunities or delayed revenue, while excess inventory would harm our gross margins. • Our hardware products contain key components from limited sources of supply, including outside the United States, and we are susceptible to supply shortages, supply changes, and international regulations, which, in certain cases, have disrupted or delayed our scheduled product deliveries to our end-customers, increased our costs and may result in the loss of sales and end-customers. • If we are unable to attract, retain, and motivate our key technical, sales, and management personnel, our business could suffer. • We generate a significant amount of revenue from sales to distributors, resellers, and end-customers outside of the United States, and we are therefore subject to a number of risks associated with international sales and operations. • We are exposed to fluctuations in foreign currency exchange rates, which could negatively affect our financial condition and operating results. • We face risks associated with having operations and employees located in Israel. • We are subject to international trade regulations and governmental export and import controls that could subject us to liability or impair our ability to compete in international markets. • We may incur increased costs to comply with privacy and data protection laws and, if we fail to comply, we could be subject to government enforcement actions, private litigation and adverse publicity. • We may have exposure to tax liabilities that are greater than anticipated. • If our estimates or judgments, including those relating to our critical accounting policies, are based on assumptions that change or prove to be incorrect, our operating results differ from our publicly announced guidance or the expectations of securities analysts and investors, resulting in a decline in the market price of our common stock. • We are obligated to maintain proper and effective internal control over financial reporting. We may not complete our analysis of our internal control over financial reporting in a timely manner, or our internal control may not be determined to be effective, which may adversely affect investor confidence in our company and, as a result, the value of our common stock. • Our reputation and/or business could be negatively impacted by corporate responsibility matters and/or our reporting of such matters. • Failure to comply with governmental laws and regulations could harm our business. • The market price of our common stock historically has been volatile, and the value of an investment in our common stock could decline. • The warrant transactions may affect the value of our common stock. • The issuance of additional stock in connection with financings, acquisitions, investments, our stock incentive plans, exercise of the 2025 Warrants, or otherwise will dilute stock held by all other stockholders. • We cannot guarantee that our share repurchase program will be fully consummated or that it will enhance shareholder value, and share repurchases could affect the price of our common stock. • We do not intend to pay dividends for the foreseeable future. • Our charter documents and Delaware law could discourage takeover attempts and lead to management entrenchment, which could also reduce the market price of our common stock. • Our business is subject to the risks of earthquakes, fire, power outages, floods, health risks, and other catastrophic events, and to interruption by man-made problems, such as terrorism. • Our failure to raise additional capital or generate the significant capital necessary to expand our operations and invest in new products and subscriptions could reduce our ability to compete and could harm our business. - 15 - Table of Contents Risks Related to Global Economic and Geopolitical Conditions Our operating results may be adversely affected by unfavorable economic and market conditions and the uncertain geopolitical environment. We operate globally, and as a result, our business and revenues are impacted by global economic and geopolitical conditions. The instability in the global credit markets, inflation, changes in public policies such as domestic and international legislation or regulations, changes in enforcement and administration policies, taxes, any increases in interest rates, fluctuations in foreign currency exchange rates, or international trade agreements, international trade disputes, trade regulations, tariffs and changes in tariffs, geopolitical turmoil, and other disruptions to global and regional economies and markets continue to add uncertainty to global economic conditions. Military actions or armed conflict, including the hostilities in Israel and the surrounding region, the Russia-Ukraine war and any related political or economic responses and counter-responses, and uncertainty about, or changes in, government and trade relationships, policies, and treaties could also lead to worsening economic and market conditions and geopolitical environment. In response to Russia’s invasion of Ukraine, the United States, along with the European Union (the “E.U.”) has imposed restrictive sanctions on Russia, Russian entities, and Russian citizens (“Sanctions on Russia”). We are subject to these governmental sanctions and export controls, which may subject us to liability if we are not in full compliance with applicable laws. Any continued or further uncertainty, weakness or deterioration in economic and market conditions or the geopolitical environment could have a material and adverse impact on our business, financial condition, and results of operations, including reductions in sales of our products and subscriptions, longer sales cycles, reductions in subscription or contract duration and value, slower adoption of new technologies, alterations in the spending patterns or priorities of current and prospective customers (including delaying purchasing decisions), increased costs for the chips and components to manufacture our products, and increased price competition. Risks Related to Our Business RISKS RELATED TO OUR GROWTH Our business and operations have experienced growth in recent periods, and if we do not effectively manage any future growth or are unable to improve our systems, processes, and controls, our operating results could be adversely affected. We have experienced growth and increased demand for our products and subscriptions over the last few years. As a result, our employee headcount has increased, and we expect it to continue to grow over the next year. For example, from the end of fiscal 2024 to the end of fiscal 2025, our headcount increased from 15,289 to 16,068 employees. In addition, as we have grown, the number of end-customers has also increased, and we have managed more complex deployments of our products and subscriptions with larger end-customers. The growth and expansion of our business and product, subscription, and support offerings places a significant strain on our management, operational, and financial resources. To manage any future growth effectively, we must continue to improve and expand our information technology and financial infrastructure, our operating and administrative systems and controls, and our ability to manage headcount, capital, and processes in an efficient manner. We may not be able to successfully implement, scale, or manage improvements to our systems, processes, and controls in an efficient or timely manner, which could result in material disruptions of our operations and business. In addition, our existing systems, processes, and controls may not prevent or detect all errors, omissions, or fraud. We may also experience difficulties in managing improvements to our systems, processes, and controls, or in connection with third-party software licensed to help us with such improvements. Any future growth would add complexity to our organization and require effective coordination throughout our organization. Failure to manage any future growth effectively could result in increased costs, disrupt our existing end-customer relationships, reduce demand for or limit us to smaller deployments of our products, or materially harm our business performance and operating results. Our revenue growth rate in recent periods may not be indicative of our future performance, and we may not be able to maintain profitability, which could cause our business, financial condition, and operating results to suffer. We have experienced revenue growth rates of 14.9% and 16.5% in fiscal 2025 and fiscal 2024, respectively. Our revenue for any quarterly or annual period should not be relied upon as an indication of our future revenue or revenue growth for any future period. If we are unable to maintain consistent or increasing revenue or revenue growth, the market price of our common stock could be volatile, and it may be difficult for us to maintain profitability or maintain or increase cash flow on a consistent basis. - 16 - Table of Contents In addition, we have incurred losses in fiscal years prior to fiscal 2023. We anticipate that our operating expenses will continue to increase in the foreseeable future as we continue to grow our business. Our growth efforts may prove more expensive than we currently anticipate, and we may not succeed in increasing our revenues sufficiently, or at all, to offset increasing expenses. Revenue growth may slow or revenue may decline for a number of possible reasons, including slowing demand for our products or subscriptions, increasing competition, a decrease in the growth of, or a demand shift in, our overall market, or a failure to capitalize on growth opportunities. We have also entered into a substantial amount of capital commitments for operating lease obligations and other purchase commitments. Any failure to increase our revenue as we grow our business could prevent us from maintaining profitability or maintaining or increasing cash flow on a consistent basis, or satisfying our capital commitments. If we are unable to navigate these challenges as we encounter them, our business, financial condition, and operating results may suffer. Our operating results may vary significantly from period to period, which makes our results difficult to predict and could cause our results to fall short of expectations, and such results may not be indicative of future performance. Our operating results have fluctuated in the past, and will likely continue to fluctuate in the future, as a result of a number of factors, many of which are outside of our control and may be difficult to predict, including those factors described in this Risk Factor section. For example, we have historically received a substantial portion of sales orders and generated a substantial portion of revenue during the last few weeks of each fiscal quarter. If expected revenue at the end of any fiscal quarter is delayed for any reason, including the failure of anticipated purchase orders to materialize (particularly for large enterprise end-customers with lengthy sales cycles), our logistics partners’ inability to ship products prior to fiscal quarter-end to fulfill purchase orders received near the end of a fiscal quarter, our failure to manage inventory to meet demand, any failure of our systems related to order review and processing, or any delays in shipments based on trade compliance requirements (including new compliance requirements imposed by new or renegotiated trade agreements), our revenue could fall below our expectations and the estimates of analysts for that quarter. Due to these fluctuations, comparing our revenue, margins, or other operating results on a period-to-period basis may not be meaningful, and our past results should not be relied on as an indication of our future performance. This variability and unpredictability could also result in our failure to meet our revenue, margin, or other operating result expectations contained in any forward-looking statements (including financial or business expectations we have provided) or those of securities analysts or investors for a particular period. If we fail to meet or exceed such expectations for these, or any other, reasons, the market price of our common stock could fall substantially, and we could face costly lawsuits, including securities class action suits. Seasonality may cause fluctuations in our revenue. We believe there are significant seasonal factors that may cause our second and fourth fiscal quarters to record greater revenue sequentially than our first and third fiscal quarters. We believe that this seasonality results from a number of factors, including: • end-customers with a December 31 fiscal year-end choosing to spend remaining unused portions of their discretionary budgets before their fiscal year-end, which potentially results in a positive impact on our revenue in our second fiscal quarter; • our sales compensation plans, which are typically structured around annual quotas and commission rate accelerators, which potentially results in a positive impact on our revenue in our fourth fiscal quarter; and • the timing of end-customer budget planning at the beginning of the calendar year, which can result in a delay in spending at the beginning of the calendar year, potentially resulting in a negative impact on our revenue in our third fiscal quarter. As we continue to grow, seasonal or cyclical variations in our operations may become more pronounced, and our business, operating results, and financial position may be adversely affected. RISKS RELATED TO OUR PRODUCTS AND TECHNOLOGY If we are unable to sell new and additional product, subscription, and support offerings to our end-customers, especially to large enterprise customers, our future revenue and operating results will be harmed. Our future success depends, in part, on our ability to expand the deployment of our portfolio with existing end-customers, especially large enterprise customers, including through our platformization strategy, and create demand for our new offerings. The rate at which our end-customers purchase additional products, subscriptions, and support depends on a number of factors, including the perceived need for additional security products, including subscription and support offerings, as well as general economic conditions. If our efforts to sell additional products and subscriptions to our end-customers are not successful, our revenues may grow more slowly than expected or decline. - 17 - Table of Contents Sales to large enterprise end-customers, which is part of our growth strategy, involve risks that may not be present, or that are present to a lesser extent, with sales to smaller entities, such as (a) longer sales cycles and the associated risk that substantial time and resources may be spent on a potential end-customer that elects not to purchase our products, subscriptions, and support, and (b) increased purchasing power and leverage held by large end-customers in negotiating contractual arrangements. Deployments for large enterprise end-customers are also more complex, require greater product functionality, scalability, and a broader range of services, and are more time-consuming and resource-consuming. All of these factors add further risk to business conducted with these end-customers. Failure to realize sales from large enterprise end-customers could materially and adversely affect our business, operating results, and financial condition. If we are unable to attract new customers, our future results of operations could be harmed. To increase our revenue and maintain profitability, we must add new customers. To do so, we must successfully convince prospective customers of the value of adopting our solutions. We are engaging in costly marketing and sales efforts to accelerate our strategies, including platformization, and attract new customers, which may fail or may not be as successful as intended or at all. Additionally, prospective customers’ decisions to purchase our solutions depend on a variety of factors, many of which are out of our control. These factors significantly impact our ability to add new customers and increase the time, resources and sophistication required to do so. For example, prospective customers may face real or perceived switching costs when switching to our solutions from legacy security vendors and products. Deployment of our solutions may require a significant commitment of resources from our customers. Any deterioration in general economic conditions, including as a result of the geopolitical environment or inflation (as well as government policies such as raising interest rates in response to inflation), have in the past caused, and may in the future cause, our current and prospective customers to delay or cut their overall security and IT operations spending. If our efforts to attract new customers are not successful, our sales may not grow as quickly as anticipated, or at all, and our business, operating results, and financial condition will be harmed. We rely on revenue from subscription and support offerings, and because we recognize revenue from subscription and support over the term of the relevant service period, downturns or upturns in sales or renewals of these subscription and support offerings are not immediately reflected in full in our operating results. Subscription and support revenue accounts for a significant portion of our revenue, comprising 80.5% of total revenue in fiscal 2025, 80.0% of total revenue in fiscal 2024, and 77.1% of total revenue in fiscal 2023. Sales and renewals of subscription and support contracts may decline and fluctuate as a result of a number of factors, including end-customers’ level of satisfaction with our products and subscriptions, the frequency and severity of subscription outages, our product uptime or latency, the prices of our products and subscriptions, and reductions in our end-customers’ spending levels. Existing end-customers have no contractual obligation to, and may not, renew their subscription and support contracts after the completion of their initial contract period. Additionally, our end-customers may renew their subscription and support agreements for shorter contract lengths or on other terms that are less economically beneficial to us. If our sales of new or renewal subscription and support contracts decline, our total revenue and revenue growth rate may decline, and our business will suffer. In addition, because we recognize subscription and support revenue over the term of the relevant service period, which is typically one to five years, a decline in subscription or support contracts in any one fiscal quarter will not be fully or immediately reflected in revenue in that fiscal quarter but will negatively affect our revenue in future fiscal quarters. The sales prices of our products, subscriptions, and support offerings may decrease, which may reduce our revenue and gross profits and adversely impact our financial results. The sales prices for our products, subscriptions, and support offerings may decline for a variety of reasons, including competitive pricing pressures, discounts, a change in our mix of products, subscriptions, and support offerings, anticipation of the introduction of new products, subscriptions, or support offerings, or promotional programs or pricing pressures. Furthermore, we anticipate that the sales prices and gross profits for our products could decrease over product life cycles. Declining sales prices could adversely affect our revenue, gross profits, and profitability. We rely on our channel partners to sell substantially all of our products, including subscriptions and support, and if these channel partners fail to perform, our ability to sell and distribute our products and subscriptions will be limited and our operating results will be harmed. Substantially all of our revenue is generated by sales through our channel partners, including distributors and resellers. For fiscal 2025, three distributors individually represented 10% or more of our total revenue and in the aggregate represented 44.2% of our total revenue. As of July 31, 2025, three distributors individually represented 10% or more of our gross accounts receivable and in the aggregate represented 44.8% of our gross accounts receivable. - 18 - Table of Contents We provide our channel partners with specific training and programs to assist them in selling our products, including subscriptions and support offerings, but there can be no assurance that these steps will be utilized or effective. In addition, our channel partners may be unsuccessful in marketing, selling, and supporting our products and subscriptions. We may not be able to incentivize these channel partners to sell our products and subscriptions to end-customers and, in particular, to large enterprises. These channel partners may also have incentives to promote our competitors’ products and may devote more resources to the marketing, sales, and support of competitive products. Our agreements with our channel partners may generally be terminated for any reason by either party with advance notice prior to each annual renewal date. We cannot be certain that we will retain these channel partners or that we will be able to secure additional or replacement channel partners. In addition, any new channel partner requires extensive training and may take several months or more to achieve productivity. Our channel partner sales structure could subject us to lawsuits, potential liability, and reputational harm if, for example, any of our channel partners misrepresent the functionality of our products or subscriptions to end-customers or violate laws or our corporate policies. If we fail to effectively manage our sales channels or channel partners, our ability to sell our products and subscriptions and operating results will be harmed. We are exposed to the credit and liquidity risk of our customers, and to credit exposure in weakened markets, which could result in material losses. Most of our sales are made on an open credit basis. Beyond our open credit arrangements, we have also experienced demands for customer financing and deferred payments due to, among other things, macro-economic conditions. Increases in deferred payments result in payments being made over time, negatively impacting our short-term cash flows, and subject us to risk of non-payment by our customers, including as a result of insolvency. We monitor customer payment capability in granting such financing arrangements, seek to limit the amounts to what we believe customers can pay and maintain reserves we believe are adequate to cover exposure for doubtful accounts to mitigate credit risks of these customers. However, there can be no assurance that these programs will be effective in reducing our credit risks. To the degree that turmoil in the credit markets makes it more difficult for some customers to obtain financing, those customers’ ability to pay could be adversely impacted, which in turn could have a material adverse impact on our business, operating results, and financial condition. Our exposure to the credit risks relating to the financing activities described above may increase if our customers are adversely affected by a global economic downturn or periods of economic uncertainty. If we are unable to adequately control these risks, our business, operating results, and financial condition could be harmed. In addition, in the past, we have experienced non-material losses due to bankruptcies among customers. If these losses increase due to global economic conditions, they could harm our business and financial condition. A portion of our revenue is generated by sales to government entities, which are subject to a number of challenges and risks. Sales to government entities are subject to a number of risks. Selling to government entities can be highly competitive, expensive, and time-consuming, often requiring significant upfront time and expense without any assurance that these efforts will generate a sale. The substantial majority of our sales to date to government entities have been made indirectly through our channel partners. Government certification or technical requirements for products and subscriptions like ours may change, thereby restricting our ability to sell into the federal government sector until we have attained the revised certification or technical requirements. If our products and subscriptions are late in achieving or fail to achieve compliance with these certifications and standards or technical requirements, or our competitors achieve compliance with these certifications and standards or technical requirements, we may be disqualified from selling our products, subscriptions, and support offerings to such governmental entity, or be at a competitive disadvantage, which would harm our business, operating results, and financial condition. Government entity demand and payment for our products, subscriptions, and support offerings may be impacted by government shutdowns, changes in governmental administrations, public sector budgetary cycles, fiscal policies, contracting policies or requirements, funding authorizations, and efforts by a government to evaluate and reduce overall government spending and analyze and enhance its operational efficiency, with funding reductions or delays adversely affecting public sector demand for our products, subscriptions, and support offerings. Government entities may have statutory, contractual, or other legal rights to terminate contracts with our distributors and resellers for convenience or due to a default, and any such termination may adversely impact our future operating results. Governments routinely investigate and audit government contractors’ administrative processes, and any unfavorable audit could result in the government refusing to continue buying our products, subscriptions, and support offerings, a reduction of revenue, or fines or civil or criminal liability if the audit uncovers improper or illegal activities, which could adversely impact our operating results in a material way. Additionally, the U.S. government may require certain of the products that it purchases to be manufactured in the United States or other relatively high-cost manufacturing locations, and we may not manufacture all products in locations that meet such requirements, affecting our ability to sell these products, subscriptions, and support offerings to the U.S. government. - 19 - Table of Contents We face intense competition in our market and we may lack sufficient financial or other resources to maintain or improve our competitive position. The industry for enterprise security products is intensely competitive, and we expect competition to increase in the future from established competitors and new market entrants. Our main competitors fall into four categories: • large companies that incorporate security features in their products, such as Cisco, Microsoft, Alphabet or those that have acquired, or may acquire, security vendors and have the technical and financial resources to bring competitive solutions to the market; • independent security vendors, such as Check Point, Fortinet, CrowdStrike, Zscaler, and Wiz, that offer a mix of security products; • startups and point-product vendors that offer independent or emerging solutions across various areas of security; and • public cloud vendors and startups that offer solutions for cloud security (private, public, and hybrid cloud). Some of our competitors have or may attain greater financial, technical, marketing, sales, and other resources, greater name recognition, longer operating histories, and a larger base of customers than we do. They may be able to devote greater resources to the promotion and sale of products and services than we can, and they may offer lower pricing than we do. Further, they may have greater resources for research and development of new technologies, the provision of customer support, and the pursuit of acquisitions or other strategic investments. They may also have larger and more mature intellectual property portfolios, and broader and more diverse product and service offerings, which allow them to leverage their relationships based on other products or incorporate functionality into existing products to gain business in a manner that discourages users from purchasing our products and subscriptions, including incorporating cybersecurity features into their existing products or services and product bundling, selling at zero or negative margins, and offering concessions or a closed technology offering. Some competitors may have broader distribution and established relationships with distribution partners and end-customers. Other competitors specialize in providing protection from a single type of security threat, which may allow them to deliver these specialized security products to the market more quickly than we can. We also face competition from companies that have entrenched legacy offerings at end-user customers. End-user customers have also often invested substantial personnel and financial resources to design and operate their networks and have established deep relationships with other providers of networking and security products. As a result, these organizations may prefer to purchase from their existing suppliers rather than add or switch to a new supplier such as us. In addition, as our customers refresh the security products bought in prior years, they may seek to consolidate vendors, which may result in current customers choosing to purchase products from our competitors. Due to budget constraints or economic downturns, organizations may add solutions to their existing network security infrastructure rather than replacing it with our products and subscriptions. Conditions in our market could change rapidly and significantly as a result of technological advancements, partnering, acquisitions or strategic investments by our competitors, or continuing market consolidation. Our competitors and potential competitors may be able to develop new or disruptive technologies, products, or services, and leverage new business models that are equal or superior to ours, achieve greater market acceptance of their products and services, disrupt our markets, and increase sales by utilizing different distribution channels than we do. In addition, new and enhanced technologies, including AI and machine learning, continue to increase our competition. To compete successfully, we must accurately anticipate technology developments and deliver innovative, relevant, and useful products, services, and technologies in a timely manner. Some of our competitors have made or could make acquisitions of businesses that may allow them to offer more directly competitive and comprehensive solutions than they had previously offered and adapt more quickly to new technologies and end-customer needs. Our current and potential competitors may also establish cooperative relationships among themselves or with third parties that may further enhance their resources or product or service offerings. These competitive pressures in our market or our failure to compete effectively may result in price reductions, fewer orders, reduced revenue and gross margins, and loss of market share. If we are unable to compete successfully, or if competing successfully requires us to take aggressive pricing or other actions, our business, financial condition, and results of operations would be adversely affected. - 20 - Table of Contents We have and may in the future acquire other businesses (including CyberArk), which could subject us to adverse claims or liabilities, require significant management attention, disrupt our business, adversely affect our operating results, may not result in the expected benefits of such acquisitions, and may dilute stockholder value. As part of our business strategy, we acquire and make investments in complementary companies, products, or technologies. We continue to evaluate such opportunities and expect to continue to make such acquisitions and investments in the future, such as our pending acquisition of CyberArk Software Ltd. (“CyberArk”). The identification of suitable acquisition candidates is difficult, and we may not be able to complete such acquisitions on favorable terms, if at all. In addition, we may be subject to claims or liabilities assumed from an acquired company, product, or technology; acquisitions we complete could be viewed negatively by our end-customers, investors, and securities analysts; and we may incur costs and expenses necessary to address an acquired company’s failure to comply with laws and governmental rules and regulations. Additionally, we may be subject to litigation or other claims in connection with the acquired company, product, or technology, including claims from terminated employees, customers, former stockholders, or other third parties, which may differ from or be more significant than the risks our business faces. If we are unsuccessful at integrating past or future acquisitions, including the pending acquisition of CyberArk, in a timely manner, or the technologies, products, or operations associated with such acquisitions, into our company, our revenue and operating results could be adversely affected. Any integration process may require significant time and resources, which may disrupt our ongoing business and divert management’s attention, and we may not be able to manage the integration process successfully or in a timely manner. We may have difficulty retaining key personnel or customers of the acquired business. We may not successfully evaluate or utilize any acquired technology, products, or personnel, realize anticipated synergies from an acquisition, or accurately forecast the financial impact of an acquisition transaction and integration of such acquisition, including accounting charges and any potential impairment of goodwill and intangible assets recognized in connection with such acquisitions. In particular, we believe that there are significant benefits and synergies that may be realized from our proposed acquisition of CyberArk, including through leveraging our and CyberArk’s products, scale, and combined enterprise customer bases. However, the efforts to realize the anticipated benefits and synergies will be a complex process and may disrupt both our and CyberArk’s existing operations if not implemented in a timely and efficient manner. The full benefits of the proposed acquisition of CyberArk, including the anticipated sales or growth opportunities, may not be realized as expected or may not be achieved within the anticipated time frame, or at all. We have recorded, and may in the future record, liability for contingent consideration obligations from acquisitions that are to be settled in cash, the fair value of which is assessed on a quarterly basis. If changes are made in our assumptions used to determine the liability’s fair value or our assumptions are incorrect, adjustments could be made that may have a material impact, favorable or unfavorable, on our operating results. We may also be required to make cash payments of contingent consideration in excess of its initial fair value, or in excess of our expectations for a particular period, which could adversely impact cash flows. We may have to pay cash, incur debt, or issue equity or equity-linked securities to pay for any future acquisitions, including the pending acquisition of CyberArk, each of which could adversely affect our financial condition or the market price of our common stock, and result in dilution to our stockholders. Furthermore, the sale or issuance of equity or equity-linked debt to finance any future acquisitions could result in dilution to our stockholders. In addition, any acquisitions may be viewed negatively by our customers, financial markets, or investors and may not ultimately strengthen our competitive position or achieve our goals and business strategy. The occurrence of any of these risks could harm our business, operating results, and financial condition. We may not complete the acquisition of CyberArk within the timeframe we anticipate or at all, which could negatively impact our future business and financial results . The completion of the acquisition of CyberArk is subject to a number of conditions, including, among others: • the effectiveness of a registration statement on Form S-4 to be filed by us registering the shares of our common stock to be issued to CyberArk shareholders as consideration in the acquisition and the absence of any stop order or proceedings seeking a stop order; • the approval for listing on Nasdaq of our shares of common stock to be issued in connection with the proposed acquisition; • obtaining the requisite CyberArk shareholder approval in connection with the proposed acquisition; • the expiration or termination of any waiting period (or extensions thereof) applicable to the acquisition under the Hart-Scott-Rodino Antitrust Improvements Act of 1976, as amended (the “HSR Act”) and the making, approval, expiration, termination or receipt of, as applicable, all applicable filings, registrations, waiting periods (or extensions of waiting periods) and approvals under specified antitrust and foreign investment laws; and • the absence of governmental restraints or prohibitions preventing the consummation of the proposed acquisition. - 21 - Table of Contents No assurance can be given that the required CyberArk shareholder approval and governmental and regulatory consents and approvals will be obtained or that any of the required conditions to closing will be satisfied in a timely manner or at all. As a result, although it is currently anticipated that we will complete the acquisition of CyberArk during the second half of our fiscal 2026, the possible timing and likelihood of completion are uncertain. There can be no assurance that the acquisition of CyberArk will be completed in the anticipated timeframe or at all. Any delay in completing the proposed acquisition could cause the combined company not to realize, or to be delayed in realizing, some or all of the benefits and synergies that we anticipate to achieve if the proposed acquisition were to be successfully completed within its expected time frame. In addition, the relevant governmental authorities from which approvals under specified antitrust and foreign investment laws must be obtained may impose or seek to impose conditions on the completion of the acquisition or require changes to the terms of the proposed acquisition or agreements to be entered into in connection with the CyberArk acquisition. Such conditions or changes and the process of obtaining these approvals, could have the effect of delaying or impeding completion of the CyberArk acquisition or imposing additional costs or limitations on us following the acquisition, which may have an adverse effect on our business, results of operations, and financial condition. The failure or inability to satisfy all of the required conditions could delay the completion of the acquisition for a significant period of time or prevent it from occurring at all. In addition, under limited circumstances, we or CyberArk may elect to terminate the definitive agreement or we and CyberArk may mutually decide to terminate the definitive agreement, before or after obtaining the requisite CyberArk shareholder approval. A termination of the definitive agreement could materially and adversely affect our business, results of operations and reputation. If the acquisition of CyberArk is delayed or not completed, we could be subject to a number of risks that may adversely affect our business, operating results and financial condition, including, among other things: • we may experience negative reactions from the financial markets, including negative impacts on the market price of our common stock; • we could incur significant acquisition costs that we would be unable to recoup; • under specified circumstances in connection with the termination of the definitive agreement, we would be required to pay CyberArk a termination fee of $1.0 billion; • negative perception from industry contacts, business partners, and other third parties, which could impact our operations or our ability to compete for new business or obtain renewals in the marketplace more broadly; and • reputational harm, negative publicity, negative reactions from employees, and other negative impacts resulting from delay or failure to complete the acquisition of CyberArk. As a result of the CyberArk acquisition, we anticipate that the scope and size of our business will substantially change and result in certain incremental risks, including increased competition . We believe that the CyberArk acquisition will expand the scope and size of our business by adding substantial assets and operations to our existing business. The anticipated future growth of our business may impose significant added responsibilities on our senior management, and our senior management’s attention may be diverted from the management of our business and its day-to-day operations to the completion and integration of the CyberArk acquisition. The CyberArk acquisition could also create uncertainty for our and CyberArk’s employees, partners, and customers, particularly during the anticipated post-acquisition integration process, and result in disruption to existing business relationships and the development of new business relationships. Following completion of the proposed acquisition of CyberArk, our success, including with respect to realizing the anticipated benefits and synergies from the proposed acquisition, will depend, in part, on our ability to manage our expansion, which poses numerous risks and uncertainties, including the need to integrate the operations and business of CyberArk into our existing business in a timely and efficient manner, to combine systems and management controls and to integrate relationships with industry contacts and business partners. In addition, we will be required to devote significant attention and resources prior to closing to prepare for the post-closing integration and operation of the combined company, and we will be required post-closing to devote significant attention and resources to successfully align our and CyberArk’s business practices and operations. This process may disrupt our business and, if ineffective, would limit the anticipated benefits and synergies of the acquisition. In addition, we expect that the completion of the CyberArk acquisition will result in increased competition, including, as a result of our entry into a new product category. CyberArk faces intense competition in the information security and identity security industry in which it operates, characterized by constant innovation, evolving customer requirements, and rapid adoption of different technologies and services. These added competitive pressures could result in decreased sales, price reductions, increased operating costs, and lower revenues, margins and net income for the combined company. These impacts could also result in a delay in realizing, or our failure to realize, expected synergies or cost savings from the CyberArk acquisition. The occurrence of any of these risks could harm our business, operating results, and financial condition. - 22 - Table of Contents If we do not accurately predict, prepare for, and respond promptly to rapidly evolving technological and market developments and successfully manage product and subscription introductions and transitions to meet changing end-customer needs in the enterprise security industry, our competitive position and prospects will be harmed. The enterprise security industry has grown quickly and continues to evolve rapidly. Moreover, many of our end-customers operate in markets characterized by rapidly changing technologies and business plans, which require them to add numerous network access points and adapt increasingly complex enterprise networks, incorporating a variety of hardware, software applications, operating systems, and networking protocols. If we fail to effectively anticipate, identify, and respond to rapidly evolving technological and market developments in a timely manner, our business will be harmed. In order to anticipate and respond effectively to rapid technological changes and market developments, as well as evolving security threats, we must invest effectively in research and development to increase the reliability, availability, and scalability of our existing products and subscriptions and introduce new products and subscriptions. Our investments in research and development, including investments in AI, may not result in design or performance improvements, marketable products, subscriptions, or features, or may not achieve the cost savings or additional revenue that we expect. In addition, new and evolving products and services, including those that use AI, require significant investment and raise ethical, technological, legal, regulatory, and other challenges, which may negatively affect our brands and demand for our products and services. Because all of these investment areas are inherently risky, no assurance can be given that such strategies and offerings will be successful or will not harm our reputation, financial condition, and operating results. In addition, we must continually change our products and expand our business strategy in response to changes in network infrastructure requirements, including the expanding use of cloud computing. For example, organizations are moving portions of their data to be managed by third parties, primarily infrastructure, platform, and application service providers, and may rely on such providers’ internal security measures. While we have historically been successful in developing, acquiring, and marketing new products and product enhancements that respond to technological change and evolving industry standards, we may not be able to continue to do so, and there can be no assurance that our new or future offerings will be successful or will achieve widespread market acceptance. If we fail to accurately predict and address end-customers’ changing needs and emerging technological trends in the enterprise security industry, including in the areas of AI, mobility, virtualization, cloud computing, and software-defined networks, our business could be harmed. The technology in our portfolio is especially complex because it needs to effectively identify and respond to new and increasingly sophisticated methods of attack, while minimizing the impact on network performance. Additionally, some of our new features and related enhancements may require us to develop new hardware architectures that involve complex, expensive, and time-consuming research and development processes. The development of our portfolio is difficult and the timetable for commercial release and availability is uncertain as there can be long time periods between releases and availability of new features. If we experience unanticipated delays in the availability of new products, features, and subscriptions, and fail to meet customer expectations for such availability, our competitive position and business prospects will be harmed. The success of new features depends on several factors, including appropriate new product definition, differentiation of new products, subscriptions, and features from those of our competitors, and market acceptance of these products, services, and features. Moreover, successful new product introduction and transition depends on a number of factors, including our ability to manage the risks associated with new product production ramp-up issues, the availability of application software for new products, the effective management of purchase commitments and inventory, the availability of products in appropriate quantities and costs to meet anticipated demand, and the risk that new products may have quality or other defects or deficiencies, especially in the early stages of introduction. There can be no assurance that we will successfully identify opportunities for new products and subscriptions, develop and bring new products and subscriptions to market in a timely manner, achieve market acceptance of our products and subscriptions, or that products, subscriptions, and technologies developed by others will not render our products, subscriptions, and technologies obsolete or noncompetitive. Issues in the development and deployment of AI may result in reputational harm and legal liability and could adversely affect our results of operations. We have incorporated, and are continuing to develop and deploy, AI into many of our products and solutions, including services that support our products and solutions. We are also incorporating AI into the operations of our business. AI presents challenges and risks that could affect our products and solutions, and the operations of our business. For example, AI algorithms may have flaws, and datasets used to train models may be insufficient or contain biased information. The AI that is being incorporated into our products, solutions, and business operation tools may not be successful or beneficial, and instead may cause technical, legal or ethical problems or result in increased costs. The investments that we are making across our business in AI reflect our ongoing efforts to innovate and provide products and services that are useful to our customers, as well as provide efficiencies in our business. Such investments ultimately may not be commercially viable or may not result in an adequate return of capital and we may incur unanticipated liabilities. These efforts could subject us to regulatory risk, legal liability, including under legislation regulating AI in jurisdictions such as the E.U. and laws and regulations being considered in other jurisdictions, or brand or reputational harm. - 23 - Table of Contents The rapid evolution of AI, including potential government regulation of AI, requires us to invest significant resources to develop, test, and maintain AI in our products and services in a manner that meets evolving requirements and expectations. The rules and regulations adopted by policymakers over time may require us to make changes to our business practices. Developing, testing, and deploying AI systems may also increase the cost profile of our offerings due to the nature of the computing costs involved in such systems. The intellectual property ownership and license rights surrounding AI technologies, as well as data protection laws related to the use and development of AI, are currently not fully addressed by courts or regulators. The use or adoption of AI technologies in our products may result in exposure to claims by third parties of copyright infringement or other intellectual property misappropriation, which may require us to pay compensation or license fees to third parties. The evolving legal, regulatory, and compliance framework for AI technologies may also impact our ability to protect our own data and intellectual property against infringing use. A network or data security incident may allow unauthorized access to our network or data, harm our reputation, create additional liability, and adversely impact our financial results. Increasingly, companies are subject to a wide variety of attacks on an ongoing basis. In addition to traditional computer “hackers,” malicious code (such as viruses and worms), phishing attempts, employee theft or misuse, and denial of service attacks, sophisticated nation-state and nation-state supported actors engage in intrusions and attacks (including advanced persistent threat intrusions and supply chain attacks), and add to the risks to our internal networks, cloud-deployed enterprise and customer-facing environments and the information they store and process. Incidences of cyberattacks and other cybersecurity breaches and incidents have increased and are likely to continue to increase. We and our third-party service providers face security threats and attacks from a variety of sources. Despite our efforts and processes to prevent breaches of our internal networks, systems, and websites, our data, corporate systems, and security measures, as well as those of our third-party service providers, are still vulnerable to computer viruses, break-ins, phishing attacks, ransomware attacks, or other types of attacks from outside parties, or breaches due to employee error, malfeasance, or some combination of these. We cannot guarantee that the measures we have taken to protect our networks, systems, and websites will provide adequate security. Furthermore, as a well-known provider of security solutions, we may be a more attractive target for such attacks. The Russia-Ukraine war and associated activities in Ukraine and Russia may increase the risk of cyberattacks on various types of infrastructure and operations, and the United States government has warned companies to be prepared for additional Russian cyberattacks in response to the Sanctions on Russia. A security breach or incident, or an attack against our service availability suffered by us, or our third-party service providers, could impact our networks or networks secured by our products and subscriptions, creating system disruptions or slowdowns and exploiting security vulnerabilities of our products. In addition, the information stored or otherwise processed on our networks, or those of our third-party service providers, could be accessed, publicly disclosed, altered, lost, stolen, rendered unavailable, or otherwise used or processed without authorization, which could subject us to liability and cause us financial harm. Any actual or perceived breach of security in our systems or networks, or any other actual or perceived data security incident we or our third-party service providers suffer, could result in significant damage to our reputation, negative publicity, loss of channel partners, end-customers, and sales, loss of competitive advantages over our competitors, increased costs to remedy any problems and otherwise respond to any incident, regulatory investigations and enforcement actions, demands, costly litigation, and other liability. In addition, we may incur significant costs and operational consequences of investigating, remediating, eliminating, and putting in place additional tools, devices, and other measures designed to prevent actual or perceived security breaches and other security incidents, as well as the costs to comply with any notification obligations resulting from any security incidents. Any of these negative outcomes could adversely impact the market perception of our products and subscriptions and end-customer and investor confidence in our company and could seriously harm our business or operating results. Defects, errors, or vulnerabilities in our products, subscriptions, or support offerings, the failure of our products or subscriptions to block a virus or prevent a security breach or incident, misuse of our products, or risks of product liability claims could harm our reputation and adversely impact our operating results. Because our products and subscriptions are complex, they have contained and may contain design or manufacturing defects or errors that are not detected until after their commercial release and deployment by our end-customers. For example, from time to time, certain of our end-customers have reported defects in our products related to performance, scalability, and compatibility. Additionally, defects or vulnerabilities may cause our products or subscriptions to become partially or fully unavailable temporarily or permanently, to be vulnerable to security attacks, cause them to fail to help secure networks, or interrupt end-customers’ networking traffic, or the availability of other information technology infrastructure or systems. For example, in November 2024, we became aware of an authentication bypass vulnerability through the management web interface of certain versions of our PAN-OS software. To remediate the matter, we published a security advisory to advise customers, provided software updates for affected PAN-OS versions, and engaged in customer outreach, support and remediation efforts for potentially impacted customers. Because the techniques used by computer hackers to access or sabotage networks change frequently and generally are not recognized until launched against a target, we may be unable to anticipate these techniques and provide a solution in time to protect our end-customers’ networks. In addition, due to the Russia-Ukraine war, there could be a significant increase in Russian cyberattacks against our customers, resulting in an increased risk of a security breach of our end-customers’ systems. - 24 - Table of Contents