FULLTEXT DEL 2 AV 3

10-K – 2025-08-29 – panw-20250731.htm

Föregående del · Dokumentindex · Nästa del

Furthermore, defects or errors in products or software, or migrations or updates to those products or software, could result in a failure to effectively update end-customers’ hardware and cloud-based products or otherwise cause problems in our customers’ hardware, networks or information technology infrastructure or systems. The data centers, networks, and cloud infrastructure that we use to deliver our products and services may experience technical failures and downtime or may fail to meet the increased requirements of a growing installed end-customer base, any of which could temporarily or permanently expose our end-customers’ networks, leaving their networks unprotected against the latest security threats. Moreover, our products must interoperate with our end-customers’ existing infrastructure, which often have varied specifications, utilize multiple protocol standards, deploy products from multiple vendors, and contain multiple generations of products that have been added over time. As a result, when problems occur in a network, it may be difficult to identify the sources of these problems. Any such technical failure, downtime or failures in general may temporarily or permanently disable our end-customers’ networks, information technology infrastructure or other systems, or expose our end-customers’ networks to attacks from security threats.
The occurrence of any such problem in our products and subscriptions, or migrations or updates to those products or software, whether real or perceived, could result in:
• expenditure of significant financial and product development resources in efforts to analyze, correct, eliminate, or work-around errors or defects or to address and eliminate vulnerabilities;
• loss of existing or potential end-customers or channel partners;
• delayed or lost revenue;
• delay or failure to attain market acceptance;
• an increase in warranty claims compared with our historical experience, or an increased cost of servicing warranty claims, either of which would adversely affect our gross margins; and
• litigation, regulatory inquiries, investigations, or other proceedings, each of which may be costly and harm our reputation.
Further, our products and subscriptions may be misused by end-customers or third parties that obtain access to our products and subscriptions. For example, our products and subscriptions could be used to censor private access to certain information on the Internet. Such use of our products and subscriptions for censorship could result in negative press coverage and negatively affect our reputation.
The limitation of liability provisions in our standard terms and conditions of sale may not fully or effectively protect us from claims as a result of federal, state, or local laws or ordinances, or unfavorable judicial decisions in the United States or other countries. The sale and support of our products and subscriptions also entails the risk of product liability claims. Although we may be indemnified by our third-party manufacturers for product liability claims arising out of manufacturing defects, because we control the design of our products and subscriptions, we may not be indemnified for product liability claims arising out of design defects. While we maintain insurance coverage for certain types of losses, our insurance coverage may not adequately cover any claim asserted against us, if at all. In addition, even claims that ultimately are unsuccessful could result in our expenditure of funds in litigation, divert management’s time and other resources, and harm our reputation.
In addition, our classifications of application type, virus, spyware, vulnerability exploits, data, or URL categories may falsely detect, report, and act on applications, content, or threats that do not actually exist. This risk is heightened by the inclusion of a “heuristics” feature in our products and subscriptions, which attempts to identify applications and other threats not based on any known signatures but based on characteristics or anomalies which indicate that a particular item may be a threat. These false positives may impair the perceived reliability of our products and subscriptions and may therefore adversely impact market acceptance of our products and subscriptions and could result in damage to our reputation, negative publicity, loss of channel partners, end-customers and sales, increased costs to remedy any problem, and costly litigation.
Our ability to sell our products and subscriptions is dependent on the quality of our technical support services and those of our channel partners, and the failure to offer high-quality technical support services could have a material adverse effect on our end-customers’ satisfaction with our products and subscriptions, our sales, and our operating results.
After our products and subscriptions are deployed within our end-customers’ networks, our end-customers depend on our technical support services, as well as the support of our channel partners, to resolve any issues relating to our products. Many larger enterprise, service provider, and government entity end-customers have more complex networks and require higher levels of support than smaller end-customers. If our channel partners do not effectively provide support to the satisfaction of our end-customers, we may be required to provide direct support to such end-customers, which would require us to hire additional personnel and to invest in additional resources. If we are not able to hire such resources fast enough to keep up with unexpected demand, support to our end-customers will be negatively impacted, and our end-customers’ satisfaction with our products and subscriptions will be adversely affected. Additionally, to the extent that we may need to rely on our sales engineers to provide post-sales support while we are ramping up our support resources, our sales productivity will be negatively impacted, which would harm our revenues. Accordingly, our failure, or our channel partners’ failure, to provide and maintain high-quality support services could have a material adverse effect on our business, financial condition, and operating results.
- 25 -

Table of Contents

RISKS RELATED TO INTELLECTUAL PROPERTY AND TECHNOLOGY LICENSING
Claims by others that we infringe their intellectual property rights could harm our business.
Companies in the enterprise security industry own large numbers of patents, copyrights, trademarks, domain names, and trade secrets and frequently enter into litigation based on allegations of infringement, misappropriation, or other violations of intellectual property rights. In addition, non-practicing entities also frequently bring claims of infringement of intellectual property rights. Third parties are asserting, have asserted, and may in the future assert claims of infringement of intellectual property rights against us. For example, on January 31, 2024, in the Centripetal Networks, Inc. lawsuit against us, a jury returned a verdict of non-willful infringement, and, after post-trial motions, a judgment was issued in the lawsuit on October 3, 2024 assessing a lump sum damages amount of $113.6 million, plus statutory interest, which is currently on appeal. Additional examples of patent infringement cases have been disclosed in Note 13. Commitments and Contingencies in Part II, Item 8 of this Annual Report on Form 10-K.
Third parties may also assert such claims against our end-customers or channel partners, whom our standard license and other agreements obligate us to indemnify against claims that our products and subscriptions infringe the intellectual property rights of third parties. In addition, to the extent we hire personnel from competitors, we may be subject to allegations that they have been improperly solicited, that they have divulged proprietary or other confidential information, or that their former employers own their inventions or other work product. Furthermore, we may be unaware of the intellectual property rights of others that may cover some or all of our technology, products, subscriptions, and services. As we expand our footprint, both in our platforms, products, subscriptions, and services and geographically, more overlaps occur and we may face more infringement claims both in the United States and abroad.
While we have been increasing the size of our patent portfolio, our competitors and others may now and in the future have significantly larger and more mature patent portfolios than we have. In addition, litigation has involved and will likely continue to involve patent-holding companies or other adverse patent owners who have no relevant product revenue and against whom our own patents may therefore provide little or no deterrence or protection. In addition, we have not registered our trademarks in all of our geographic markets and failure to secure those registrations could adversely affect our ability to enforce and defend our trademark rights. Any claim of infringement by a third party, even those without merit, could cause us to incur substantial costs defending against the claim, could distract our management from our business, and could require us to cease use of such intellectual property. Furthermore, because of the substantial amount of discovery required in connection with intellectual property litigation, there is a risk that some of our confidential information could be compromised by disclosure during this type of litigation. A successful claimant could secure a judgment, or we may agree to a settlement that prevents us from distributing certain products or performing certain services or that requires us to pay substantial damages, royalties, or other fees. Any of these events could seriously harm our business, financial condition, and operating results.
Our proprietary rights may be difficult to enforce or protect, which could enable others to copy or use aspects of our products or subscriptions without compensating us.
We rely and expect to continue to rely on a combination of confidentiality and license agreements with our employees, consultants, and third parties with whom we have relationships, as well as trademark, copyright, patent, and trade secret protection laws, to protect our proprietary rights. We have filed various applications for certain aspects of our intellectual property. Valid patents may not issue from our pending applications, and the claims eventually allowed on any patents may not be sufficiently broad to comprehensively protect our technology or products and subscriptions. We cannot be certain that we were the first to make the inventions claimed in our pending patent applications or that we were the first to file for patent protection, which could prevent our patent applications from issuing as patents or invalidate our patents following issuance. Additionally, the process of obtaining patent protection is expensive and time-consuming, and we may not be able to prosecute all necessary or desirable patent applications at a reasonable cost or in a timely manner. Any issued patents may be challenged, invalidated or circumvented, and any rights granted under these patents may not actually provide adequate defensive protection or competitive advantages to us. Additional uncertainty may result from changes to patent-related laws and court rulings in the United States and other jurisdictions. As a result, we may not be able to obtain adequate patent protection or effectively enforce any issued patents.
- 26 -

Table of Contents

Despite our efforts to protect our proprietary rights, unauthorized parties may attempt to copy aspects of our products or subscriptions or obtain and use information that we regard as proprietary. We generally enter into confidentiality or license agreements with our employees, consultants, vendors, and end-customers, and generally limit access to and distribution of our proprietary information. However, we cannot be certain that we have entered into such agreements with all parties who may have or have had access to our confidential information or that the agreements we have entered into will not be breached. We cannot guarantee that any of the measures we have taken will prevent misappropriation of our technology. Because we may be an attractive target for computer hackers, we may have a greater risk of unauthorized access to, and misappropriation of, our proprietary information. In addition, the laws of some foreign countries do not protect our proprietary rights to as great an extent as the laws of the United States, and many foreign countries do not enforce these laws as diligently as government agencies and private parties in the United States. From time to time, we may need to take legal action to enforce our patents and other intellectual property rights, to protect our trade secrets, to determine the validity and scope of the proprietary rights of others, or to defend against claims of infringement or invalidity. Such litigation could result in substantial costs and diversion of resources and could negatively affect our business, operating results, and financial condition. Attempts to enforce our rights against third parties could also provoke these third parties to assert their own intellectual property or other rights against us or result in a holding that invalidates or narrows the scope of our rights, in whole or in part. If we are unable to protect our proprietary rights (including aspects of our software and products protected other than by patent rights), we may find ourselves at a competitive disadvantage to others who need not incur the additional expense, time, and effort required to create the innovative products that have enabled us to be successful to date. Any of these events would have a material adverse effect on our business, financial condition, and operating results.
Our use of open source software in our products and subscriptions could negatively affect our ability to sell our products and subscriptions and subject us to possible litigation.
Our products and subscriptions contain software modules licensed to us by third-party authors under “open source” licenses. Some open source licenses contain requirements that we make available applicable source code for modifications or derivative works we create based upon the type of open source software we use. If we combine our proprietary software with, or otherwise distribute or use open source software in a certain manner, we could, under certain open source licenses, be required to release the source code of our proprietary software to the public. This would allow our competitors to create similar products or subscriptions with lower development effort and time and ultimately could result in a loss of product sales for us.
Although we take reasonable steps to monitor our use of open source software to avoid subjecting our products and subscriptions to conditions we do not intend, the terms of many open source licenses have not been interpreted by United States courts, and there is a risk that these licenses could be construed in a way that could impose unanticipated conditions or restrictions on our ability to commercialize our products and subscriptions. From time to time, there have been claims against companies that distribute or use open source software in their products and subscriptions, asserting that open source software infringes the claimants’ intellectual property rights. We could be subject to suits by parties claiming infringement of intellectual property rights in what we believe to be licensed open source software. If we are held to have breached the terms of an open source software license, we could be required to seek licenses from third parties to continue offering our products and subscriptions on terms that are not economically feasible, to reengineer our products and subscriptions, to discontinue the sale of our products and subscriptions if reengineering could not be accomplished on a timely basis, or to make generally available, in source code form, our proprietary code, any of which could adversely affect our business, operating results, and financial condition.
In addition to risks related to license requirements, usage of open source software can lead to greater risks than use of third-party commercial software, as open source licensors generally do not provide warranties or assurance of title or controls on origin of the software. In addition, many of the risks associated with usage of open source software, such as the lack of warranties or assurances of title, cannot be eliminated, and could, if not properly addressed, negatively affect our business. We have established processes to help alleviate these risks, including a review process for screening requests from our development organizations for the use of open source software, but we cannot be sure that our processes for controlling our use of open source software in our products and subscriptions will be effective.
- 27 -

Table of Contents

We license technology from third parties, and our inability to maintain those licenses could harm our business.
We incorporate technology that we license from third parties, including software, into our products and subscriptions. We cannot be certain that our licensors are not infringing the intellectual property rights of third parties or that our licensors have sufficient rights to the licensed intellectual property in all jurisdictions in which we may sell our products and subscriptions. In addition, some licenses may be non-exclusive, and therefore our competitors may have access to the same technology licensed to us. Some of our agreements with our licensors may be terminated for convenience by them. We may also be subject to additional fees or be required to obtain new licenses if any of our licensors allege that we have not properly paid for such licenses or that we have improperly used the technologies under such licenses, and such licenses may not be available on terms acceptable to us or at all. If we are unable to continue to license any of this technology because of intellectual property infringement claims brought by third parties against our licensors or against us, or claims against us by our licensors, or if we are unable to continue our license agreements or enter into new licenses on commercially reasonable terms, our ability to develop and sell products and subscriptions containing such technology would be severely limited and our business could be harmed. Additionally, if we are unable to license necessary technology from third parties, we may be forced to acquire or develop alternative technology, which we may be unable to do in a commercially feasible manner or at all, and we may be required to use alternative technology of lower quality or performance standards. This would limit and delay our ability to offer new or competitive products and subscriptions and increase our costs of production. As a result, our margins, market share, and operating results could be significantly harmed.

RISKS RELATED TO OPERATIONS
Because we depend on manufacturing partners to build and ship our hardware products, we are susceptible to manufacturing and logistics delays and pricing fluctuations that could prevent us from shipping customer orders on time, if at all, or on a cost-effective basis, which may result in the loss of sales and end-customers.
We depend on manufacturing partners, primarily our EMS provider, Flex, to manufacture our hardware product lines. Our substantial reliance on Flex, as well as other manufacturing partners subjects us to potential concentration risks, such as reduced control over the manufacturing process, quality assurance, product costs, product supply, and timing. Our hardware products are manufactured by our manufacturing partners at facilities located primarily in the United States. Some of the components in our products are sourced either through Flex or directly by us from component suppliers outside the United States. The portion of our hardware products that are sourced outside the United States may subject us to geopolitical risks, additional logistical risks, risks associated with international trade agreements, international trade disputes, trade regulations, tariffs, or risks associated with complying with local rules and regulations in foreign countries.
Significant changes to existing international trade agreements, tariffs, or trade regulations could lead to sourcing or logistics disruption resulting from import delays or the imposition of increased tariffs on our sourcing partners. For example, the United States and Chinese governments have each enacted, and discussed additional, import tariffs. Some components that we import for final manufacturing in the United States have been impacted by these tariffs. As a result, our costs have increased and we have raised, and may be required to further raise, prices on our hardware products in response to these and potential new trade regulations.
Our manufacturing partners typically fulfill our supply requirements on the basis of individual purchase orders. We do not have long-term contracts with these manufacturers that guarantee capacity, the continuation of particular pricing terms, or the extension of credit limits. Accordingly, they are not obligated to continue to fulfill our supply requirements and the prices we pay for manufacturing services could be increased on short notice. Our contract with Flex permits them to terminate the agreement for their convenience, subject to prior notice requirements. If we are required to change manufacturing partners, our ability to meet our scheduled product deliveries to our end-customers could be adversely affected, which could cause the loss of sales to existing or potential end-customers, delayed revenue or an increase in our costs which could adversely affect our gross margins. Any production interruptions for any reason, such as a natural disaster, epidemic or pandemic, capacity shortages, or quality problems at one of our manufacturing partners would negatively affect sales of our product lines manufactured by that manufacturing partner and adversely affect our business and operating results.
Managing the supply of our hardware products and product components is complex. Insufficient supply and inventory would result in lost sales opportunities or delayed revenue, while excess inventory would harm our gross margins.
Our manufacturing partners procure components and build our hardware products based on our forecasts, and we generally do not hold inventory for a prolonged period of time. These forecasts are based on historical trends and analysis, adjusted for overall market conditions. In order to reduce manufacturing lead times and plan for adequate component supply, from time to time we may issue forecasts for components and products that are non-cancelable and non-returnable.
- 28 -

Table of Contents

Our inventory management systems and related supply chain visibility tools may be inadequate to enable us to forecast accurately and effectively manage supply of our hardware products and product components. If we ultimately determine that we have excess supply, we may have to reduce our prices and write down inventory, which in turn could result in lower gross margins. If our actual component usage and product demand are lower than the forecast we provide to our manufacturing partners, we accrue for losses on manufacturing commitments in excess of forecasted demand. Alternatively, insufficient supply levels may lead to shortages that result in delayed hardware product revenue or loss of sales opportunities altogether as potential end-customers turn to competitors’ products that are readily available. If we are unable to effectively manage our supply and inventory, our operating results could be adversely affected.
Our hardware products contain key components from limited sources of supply, including outside the United States, and we are susceptible to supply shortages, supply changes, and international regulations, which, in certain cases, have disrupted or delayed our scheduled product deliveries to our end-customers, increased our costs and may result in the loss of sales and end-customers.
Our hardware products rely on key components, including integrated circuit components, which our manufacturing partners purchase on our behalf from a limited number of component suppliers, including sole source providers. The manufacturing operations of some of our component suppliers are geographically concentrated in Asia and elsewhere, which makes our supply chain vulnerable to regional disruptions, such as natural disasters, fire, political instability, civil unrest, power outages, or health risks, and international regulations, such as tariffs, sanctions and import and export controls. In the past, we experienced supply chain disruption and have incurred increased costs resulting from inflationary pressures and changes in U.S. trade policy. We are also monitoring the tensions between China and Taiwan, and between the U.S. and China, which could have an adverse impact on our business or results of operations in future periods.
Further, we do not have volume purchase contracts with any of our component suppliers, and they could cease selling to us at any time. If we are unable to obtain a sufficient quantity of these components in a timely manner for any reason, sales of our hardware products could be delayed or halted, or we could be forced to expedite shipment of such components or our hardware products at dramatically increased costs. Our component suppliers also change their selling prices frequently in response to market trends, including industry-wide increases in demand. Because we do not have, for the most part, volume purchase contracts with our component suppliers, we are susceptible to price fluctuations related to raw materials and components and may not be able to adjust our prices accordingly. Additionally, poor quality in any of the sole-sourced components in our products could result in lost sales or sales opportunities.
If we are unable to obtain a sufficient volume of the necessary components for our hardware products on commercially reasonable terms or the quality of the components do not meet our requirements, we could also be forced to redesign our products and qualify new components from alternate component suppliers. The resulting stoppage or delay in selling our hardware products and the expense of redesigning our hardware products would result in lost sales opportunities and damage to customer relationships, which would adversely affect our business and operating results.
If we are unable to attract, retain, and motivate our key technical, sales, and management personnel, our business could suffer.
Our future success depends, in part, on our ability to continue to attract, retain, and motivate the members of our management team and other key employees. For example, we are substantially dependent on the continued service of our engineering personnel because of the complexity of our offerings. Competition for highly skilled personnel, particularly in engineering, including in the areas of AI and machine learning, is intense, especially in the San Francisco Bay Area, where we have a substantial presence and need for such personnel. In addition, the industry in which we operate generally experiences high employee attrition. Our future performance depends on the continuing services and contributions of our senior management to execute on our business plan and to identify and pursue new opportunities and product innovations. If we are unable to hire, integrate, train, or retain the qualified and highly skilled personnel required to fulfill our current or future needs, our business, financial condition, and operating results could be harmed.
Further, we believe that a critical contributor to our success and our ability to retain highly skilled personnel has been our corporate culture, which we believe fosters innovation, inclusion, teamwork, passion for end-customers, focus on execution, and the facilitation of critical knowledge transfer and knowledge sharing. As we grow and change, we may find it difficult to maintain these important aspects of our corporate culture. While we are taking steps to develop a more inclusive workforce, there is no guarantee that we will be able to do so. Any failure to preserve our culture as we grow could limit our ability to innovate and could negatively affect our ability to retain and recruit personnel, continue to perform at current levels or execute on our business strategy.
- 29 -

Table of Contents

We generate a significant amount of revenue from sales to distributors, resellers, and end-customers outside of the United States, and we are therefore subject to a number of risks associated with international sales and operations.
Our ability to grow our business and our future success will depend to a significant extent on our ability to expand our operations and customer base worldwide. Many of our customers, resellers, partners, suppliers, and manufacturers operate around the world. Operating in a global marketplace, we are subject to risks associated with having an international reach and compliance and regulatory requirements. We may experience difficulties in attracting, managing, and retaining an international staff, and we may not be able to recruit and maintain successful strategic distributor relationships internationally. Business practices in the international markets that we serve may differ from those in the United States and may require us in the future to include terms other than our standard terms related to payment, warranties, or performance obligations in end-customer contracts.
Additionally, our international sales and operations are subject to a number of risks, including the following:
• political, economic, and social uncertainty around the world, health risks such as epidemics and pandemics like COVID-19, macroeconomic challenges, terrorist activities, the Russia-Ukraine war, tensions between China and Taiwan, the hostilities in Israel and the surrounding region, and continued hostilities in the Middle East;
• unexpected changes in, or the application of, foreign and domestic laws and regulations (including intellectual property rights protections), regulatory practices or enforcement policies, trade restrictions, international trade agreements, and foreign legal requirements, including those applicable to the importation, certification, and localization of our products, tariffs, and tax laws and treaties, including regulatory and trade policy changes adopted by the current administration, such as the Sanctions on Russia, or foreign countries in response to regulatory changes adopted by the current administration; and
• non-compliance with U.S. and foreign laws, including antitrust regulations, anti-corruption laws, such as the U.S. Foreign Corrupt Practices Act and the United Kingdom (“U.K.”) Bribery Act, U.S. or foreign sanctions regimes and export or import control laws, and any trade regulations ensuring fair trade practices.
These and other factors could harm our future international revenues and, consequently, materially impact our business, operating results, and financial condition. The expansion of our existing international operations and entry into additional international markets will require significant management attention and financial resources. Our failure to successfully manage our international operations and the associated risks effectively could limit the future growth of our business.
We are exposed to fluctuations in foreign currency exchange rates, which could negatively affect our financial condition and operating results.
Our sales contracts are primarily denominated in U.S. dollars, and therefore, a predominant amount of our revenue is not subject to foreign currency risk. However, in the event of a strengthening of the U.S. dollar against foreign currencies in which we conduct business, the cost of our products to our end-customers outside of the United States would increase, which could adversely affect our financial condition and operating results. In addition, increased international sales in the future, including through our channel partners and other partnerships or as a result of our acquisitions, may result in increased foreign currency denominated sales, increasing our foreign currency risk.
Our operating expenses incurred outside the United States and denominated in foreign currencies are generally increasing and are subject to fluctuations due to changes in foreign currency exchange rates. If we are not able to successfully hedge against the risks associated with foreign currency fluctuations, our financial condition and operating results could be adversely affected. We have entered into forward contracts in an effort to reduce our foreign currency exchange exposure related to our foreign currency denominated revenue and operating expenditures. As of July 31, 2025, the total notional amount of our outstanding foreign currency forward contracts was $1.5 billion. For more information on our hedging transactions, refer to Note 6. Derivative Instruments in Part II, Item 8 of this Annual Report on Form 10-K. The effectiveness of our existing hedging transactions and the availability and effectiveness of any hedging transactions we may decide to enter into in the future may be limited and we may not be able to successfully hedge our exposure, which could adversely affect our financial condition and operating results.
We face risks associated with having operations and employees located in Israel.
We have business operations in Israel and intend to continue growing our presence in Israel, including in connection with our proposed acquisition of CyberArk. Our operations in Israel could be disrupted by political instability, civil unrest, terrorist attacks, acts of violence, acts of war, or other military actions, including the hostilities in Israel and the surrounding region. The future of peace efforts between Israel and its Arab neighbors remains uncertain. The effects of hostilities and violence on the Israeli economy and our operations in Israel are unclear, and we cannot predict the effect on us of further increases in these hostilities or future armed conflict, political instability, or violence in the region. Current or future tensions and conflicts in the Middle East could adversely affect our business, operating results, financial condition, and cash flows.
- 30 -

Table of Contents

In addition, many of our employees in Israel are obligated to perform annual reserve duty in the Israeli military and are subject to being called for active duty under emergency circumstances, which has occurred as a result of hostilities in Israel and the surrounding region. We cannot predict the full impact of these conditions on us in the future, particularly if emergency circumstances or an escalation in the political situation or hostilities occurs. If many of our employees in Israel are called for active duty for a significant period of time, our operations and our business could be disrupted and may not be able to function at full capacity. Any disruption in our operations in Israel could adversely affect our business.
We are subject to international trade regulations and governmental export and import controls that could subject us to liability or impair our ability to compete in international markets.
Because we incorporate encryption technology into our products, certain of our products are subject to U.S. export controls and may be exported outside the United States only with the required export license or through an export license exception. If we were to fail to comply with U.S. export licensing requirements, U.S. customs regulations, U.S. economic sanctions, or other laws or regulations, we could be subject to substantial civil and criminal penalties, including fines, incarceration for responsible employees and managers, and the possible loss of export or import privileges. Obtaining the necessary export license for a particular sale may be time-consuming and may result in the delay or loss of sales opportunities. Furthermore, U.S. export control laws and economic sanctions prohibit the shipment of certain products to U.S. embargoed or sanctioned countries, governments, and persons. Even though we take precautions to ensure that our channel partners comply with all relevant regulations, any failure by our channel partners to comply with such regulations could have negative consequences for us, including reputational harm, government investigations, and penalties.
In addition, various countries regulate the import of certain encryption technology, including through import permit and license requirements, and have enacted laws that could limit our ability to distribute our products or could limit our end-customers’ ability to implement our products in those countries. Changes in our products or changes in export and import regulations may create delays in the introduction of our products into international markets, prevent our end-customers with international operations from deploying our products globally or, in some cases, prevent or delay the export or import of our products to certain countries, governments, or persons altogether. Any change in export or import regulations, economic sanctions, such as the Sanctions on Russia, or related legislation, shift in the enforcement or scope of existing regulations, or change in the countries, governments, persons, or technologies targeted by such regulations could result in decreased use of our products by, or in our decreased ability to export or sell our products to, existing or potential end-customers with international operations. Any decreased use of our products or limitation on our ability to export to or sell our products in international markets would likely adversely affect our business, financial condition, and operating results.
International trade laws and regulations continuously evolve to address technological developments and changes in geopolitical conditions. New regulations or other governmental restrictions that may result from these circumstances could inhibit our ability to transact with foreign suppliers, customers, or other business partners. Monitoring and responding to these developments may require significant resources, and failure to comply with resulting regulations and restrictions may have an adverse impact on our business or results of operation.

RISKS RELATED TO PRIVACY AND DATA PROTECTION
We may incur increased costs to comply with privacy and data protection laws and, if we fail to comply, we could be subject to government enforcement actions, private litigation and adverse publicity.
A wide variety of laws and regulations apply to the collection, use, retention, protection, disclosure, transfer, and other processing of personal data in jurisdictions where we and our customers operate. Compliance with these laws and regulations is difficult and costly. These laws and regulations are also subject to frequent, inconsistent and unexpected changes; new, modified or additional laws or regulations may be adopted; and rulings that invalidate prior laws, regulations, or interpretations of such laws or regulations may be issued. For example, we are subject to the E.U. General Data Protection Regulation (“E.U. GDPR”) and the U.K. General Data Protection Regulation (“U.K. GDPR,” and collectively the “GDPR”), each of which imposes stringent data protection requirements, provide for costly penalties for noncompliance (up to the greater of (a) €20 million under the E.U. GDPR or £17.5 million under the U.K. GDPR, and (b) 4% of annual worldwide turnover), and confer the right upon data subjects and consumer associations to lodge complaints with supervisory authorities, seek judicial remedies, and obtain compensation for damages resulting from violations.
- 31 -

Table of Contents

The GDPR imposes restrictions, among other things, on the transfer of personal data outside of the European Economic Area (“EEA”) (or, in the case of the U.K. GDPR, the U.K.) to non-EEA countries, such as the United States, unless adequate safeguards are implemented or a derogation applies. In practice, we rely on standard contractual clauses approved under the GDPR to carry out such transfers and to receive personal data subject to the GDPR (directly or indirectly) in the United States. In addition, with respect to the personal data that we process on behalf of our customers, we self-certified to the E.U.-U.S. Data Privacy Framework (“E.U.-U.S. DPF”), the UK Extension to the E.U.-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (collectively, the “DPF”), as set forth by the U.S. Department of Commerce, regarding transfers of certain personal data from the E.U., the U.K., and Switzerland to the United States. The DPF has been recognized as adequate under applicable law to allow transfers of personal data from the E.U., U.K., and Switzerland, as the case may be, to companies in the U.S. that have self-certified to the framework. However, the DPF may be subject to legal challenges, which could invalidate its use, disrupt our ability to rely on such data transfer mechanisms, and otherwise cause the legal requirements for such data transfers to be uncertain.
In addition, the U.K. government enacted the U.K. Data (Use and Access) Act 2025 on June 19, 2025, which includes targeted amendments to the U.K.’s data protection regime that cause it to expressly deviate from the GDPR. This development creates new compliance challenges and has created uncertainty with respect to the European Commission’s adequacy determination regarding the U.K.’s data protection regime, which has been extended until December 2025 and must be renewed to permit ongoing relatively unrestricted data flows from the EEA to the UK.
Among other effects of these developments, we may experience additional costs associated with increased compliance burdens, reduced demand for our offerings from current or prospective customers in the EEA, Switzerland, and the U.K. (collectively, “Europe”) to use our products, on account of the risks identified in the Schrems II decision or other developments relating to cross-border data transfers, and we may find it necessary or desirable to make further changes to our processing of personal data of European residents. The regulatory environment applicable to the handling of European residents’ personal data and cross-border data transfers, and our actions taken in response, may cause us to assume additional liabilities or incur additional costs. Moreover, much like with Schrems II, we anticipate future legal challenges to the approved data transfer mechanisms between Europe and the United States, including a challenge to the E.U.-U.S. DPF. Such legal challenges could result in additional legal and regulatory risk, compliance costs, and in our business, operating results, and financial condition being harmed.
We are also subject to the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the “CCPA”). The CCPA requires, among other things, covered businesses to provide enhanced disclosures to California consumers and to afford such consumers certain rights regarding their personal data, including the right to opt out of data sales for targeted advertising, and creates a private right of action to individuals affected by a data breach, if the breach was caused by a lack of reasonable security. The effects of the CCPA have been significant, requiring us to modify our data processing practices and policies and to incur substantial costs and expenses for compliance. Moreover, other U.S. states have enacted laws relating to privacy and security that are potentially relevant to us. These include laws enacted in at least 20 U.S. states, a portion of which are expected to come into effect over the course of our fiscal 2026. The U.S. Department of Justice also has issued rules regarding access to, or transfer of, certain bulk sensitive personal data by countries of concern. Increasingly complex federal or state laws and regulations relating to privacy and security, and interpretations and enforcement of existing laws and regulations relating to these matters, may require us to modify our data practices and policies, incur substantial compliance costs and expenses, and add further complexity to our compliance efforts that could adversely affect our business or increase our potential liability if we fail to comply or are alleged to have done so.
We may also from time to time be subject to obligations relating to personal data by contract, or face assertions that we are subject to self-regulatory obligations or industry standards. Additionally, the Federal Trade Commission and many state attorneys general are more regularly bringing enforcement actions in connection with federal and state consumer protection laws for false or deceptive acts or practices in relation to the online collection, use, dissemination, and security of personal data. Internationally, data localization laws may mandate that personal data collected in a foreign country be processed and stored within that country.
We and our customers may face risk of enforcement actions by regulators or data protection authorities, private litigation and adverse publicity including reputational damage and loss of customer confidence for alleged violations of any of the foregoing obligations. Any such claims could result in substantial costs, ongoing remedial, audit and reporting obligations, and diversion of resources, and distract management and technical personnel. These potential liabilities and enforcement actions could also have an overall negative effect on our business, operating results, and financial condition. The amount and scope of insurance we maintain may not cover all types of claims that may arise.
New legislation affecting the scope of personal data and personal information where we or our customers and partners have operations, especially relating to classification of Internet Protocol (“IP”) addresses, machine identification, AI and machine learning, location data, and other information, may limit or inhibit our ability to operate or expand our business, including limiting strategic partnerships that may involve the sharing or uses of data, and may require significant expenditures and efforts in order to comply. Notably, public perception of potential privacy, data protection, or information security concerns—whether or not valid—may harm our reputation and inhibit adoption of our products and subscriptions by current and future end-customers. Each of these laws and regulations, and any changes to these laws and regulations, or new laws and regulations, could impose significant limitations, or require changes to our business model or practices or growth strategy, which may increase our compliance expenses and make our business more costly or less efficient to conduct.
- 32 -

Table of Contents

Tax, Accounting, Compliance, and Regulatory Risks
We may have exposure to tax liabilities that are greater than anticipated.
Our income tax obligations are based in part on our corporate structure and intercompany arrangements, including the manner in which we develop, value, and use our intellectual property and the valuations of our intercompany transactions. The tax laws applicable to our business, including the laws of the United States and various other jurisdictions, are subject to interpretation and certain jurisdictions may aggressively interpret their laws, regulations, and policies, including in an effort to raise additional tax revenue. The tax authorities of the jurisdictions in which we operate may challenge our methodologies for valuing developed or acquired technology or determining the proper charges for intercompany arrangements, which could increase our worldwide effective tax rate, harm our financial position and operating results, and have a negative effect on our cash flow. Some tax authorities of jurisdictions other than the United States may seek to assert extraterritorial taxing rights on our transactions or operations. It is possible that domestic or international tax authorities may subject us to tax examinations, or audits, and such tax authorities may disagree with certain positions we have taken, and any adverse outcome of such an examination, review or audit could result in additional tax liabilities and penalties and otherwise have a negative effect on our financial position, operating results, and cash flow. Further, the determination of our worldwide provision for income taxes and other tax liabilities requires significant judgment by management, and there are transactions where the ultimate tax determination is uncertain. Although we believe that our estimates are reasonable, the ultimate tax outcome may differ from the amounts recorded on our consolidated financial statements and may materially affect our financial results in the period or periods for which such determination is made.
In addition, our future income tax obligations and effective tax rates could be adversely affected by changes in, or interpretations of, tax laws, regulations, policies, or decisions in the United States or in the other jurisdictions in which we operate including as a result of the U.S. federal tax legislation commonly referred to as the One Big Beautiful Bill Act, which was signed into law on July 4, 2025.
If our estimates or judgments, including those relating to our critical accounting policies, are based on assumptions that change or prove to be incorrect, our operating results differ from our publicly announced guidance or the expectations of securities analysts and investors, resulting in a decline in the market price of our common stock.
The preparation of consolidated financial statements in conformity with U.S. generally accepted accounting principles (“U.S. GAAP”) requires management to make estimates and assumptions that affect the amounts reported on our consolidated financial statements and accompanying notes. We base our estimates on historical experience and on various other assumptions that we believe to be reasonable under the circumstances, the results of which form the basis for making judgments about the carrying amounts of assets, liabilities, equity, revenue, and expenses that are not readily apparent from other sources. For more information relating to critical accounting policies, refer to the section entitled “Critical Accounting Estimates” in “Management’s Discussion and Analysis of Financial Condition and Results of Operations” in Part II, Item 7 of this Annual Report on Form 10-K. In general, if our estimates, judgments or assumptions relating to our critical accounting policies change or if actual circumstances differ from our estimates, judgments or assumptions, our operating results may be adversely affected and could fall below our publicly announced guidance or the expectations of securities analysts and investors, resulting in a decline in the market price of our common stock.
We are obligated to maintain proper and effective internal control over financial reporting. We may not complete our analysis of our internal control over financial reporting in a timely manner, or our internal control may not be determined to be effective, which may adversely affect investor confidence in our company and, as a result, the value of our common stock.
If we are unable to assert that our internal controls are effective, our independent registered public accounting firm may not be able to formally attest to the effectiveness of our internal control over financial reporting. If, in the future, our chief executive officer, chief financial officer, or independent registered public accounting firm determines that our internal control over financial reporting is not effective as defined under Section 404, we could be subject to one or more investigations or enforcement actions by state or federal regulatory agencies, stockholder lawsuits, or other adverse actions requiring us to incur defense costs, pay fines, settlements, or judgments, causing investor perceptions to be adversely affected and potentially resulting in a decline in the market price of our stock.
- 33 -

Table of Contents

Our reputation and/or business could be negatively impacted by corporate responsibility matters and/or our reporting of such matters.
There is an increasing focus from regulators, certain investors, and other stakeholders concerning corporate responsibility matters, both in the United States and internationally. We communicate certain corporate responsibility-related initiatives, goals, and/or commitments regarding sustainability matters, inclusion, responsible sourcing and social investments, and other matters in our annual Corporate Responsibility Report, on our website, in our filings with the SEC, and elsewhere. These initiatives, goals, or commitments could be difficult to achieve and costly to implement. We could fail to achieve, or be perceived to fail to achieve, our corporate responsibility-related initiatives, goals, or commitments. In addition, we could be criticized for the timing, scope or nature of these initiatives, goals, or commitments, or for any revisions to them. To the extent that our required and voluntary disclosures about corporate responsibility matters increase, we could be criticized for the accuracy, adequacy, or completeness of such disclosures. Our actual or perceived failure to achieve our corporate responsibility-related initiatives, goals, or commitments could negatively impact our reputation, result in corporate responsibility-focused investors not purchasing and holding our stock, or otherwise materially harm our business.
In addition, we are or may become subject to various new and proposed sustainability-related laws and regulations, including, for example, the E.U.’s Corporate Sustainability Reporting Directive. Additional regulation may require us to incur significant additional costs associated with increased compliance burdens, including the implementation of additional internal controls processes and procedures, and impose increased oversight obligations on our management and board of directors, as well as require us to retain third-party experts. Noncompliance with applicable regulations or requirements could subject us to investigations, sanctions, enforcement actions, fines or litigation, which could negatively impact our business, operating results or financial condition.
Failure to comply with governmental laws and regulations could harm our business.
Our business is subject to regulation by various federal, state, local, and foreign governmental agencies, including agencies responsible for monitoring and enforcing employment and labor laws, workplace safety, product safety, environmental laws, consumer protection laws, privacy, data security, and data-protection laws, anti-bribery laws (including the U.S. Foreign Corrupt Practices Act and the U.K. Anti-Bribery Act), import/export controls, federal securities laws, and tax laws and regulations. These laws and regulations may also impact our innovation and business drivers in developing new and emerging technologies (e.g., AI and machine learning). In certain jurisdictions, these regulatory requirements may be more stringent than those in the United States. Noncompliance with applicable regulations or requirements could subject us to investigations, sanctions, mandatory product recalls, enforcement actions, disgorgement of profits, fines, damages, civil and criminal penalties, or injunctions. If any governmental sanctions are imposed, or if we do not prevail in any possible civil or criminal litigation resulting from any alleged noncompliance, our business, operating results, and financial condition could be materially adversely affected. In addition, responding to any action will likely result in a significant diversion of management’s attention and resources and an increase in professional fees. Enforcement actions, litigation, and sanctions could harm our business, operating results, and financial condition.
- 34 -

Table of Contents

Risks Related to Our Common Stock
The market price of our common stock historically has been volatile, and the value of an investment in our common stock could decline.
The market price of our common stock has historically been, and is likely to continue to be, volatile and could be subject to wide fluctuations in response to various factors, some of which are beyond our control and unrelated to our business, operating results, or financial condition. These fluctuations could cause a loss of all or part of an investment in our common stock. Factors that could cause fluctuations in the market price of our common stock include, but are not limited to:
• announcements of new products, subscriptions or technologies, commercial relationships, strategic partnerships, acquisitions, or other events by us or our competitors;
• price and volume fluctuations in the overall stock market from time to time;
• news announcements that affect investor perception of our industry, including reports related to the discovery of significant cyberattacks;
• significant volatility in the market price and trading volume of technology companies in general and of companies in our industry;
• fluctuations in the trading volume of our shares or the size of our public float;
• actual or anticipated changes in our operating results or fluctuations in our operating results;
• whether our operating results meet the expectations of securities analysts or investors;
• actual or anticipated changes in the expectations of securities analysts or investors, whether as a result of our forward-looking statements, our failure to meet such expectations or otherwise;
• inaccurate or unfavorable research reports about our business and industry published by securities analysts or reduced coverage of our company by securities analysts;
• litigation involving us, our industry, or both;
• actions instituted by activist shareholders or others;
• regulatory developments in the United States, foreign countries, or both;
• major catastrophic events;
• sales or repurchases of large blocks of our common stock or substantial future sales by our directors, executive officers, employees, and significant stockholders;
• issuances or sales of shares of our common stock, including as part of a capital-raising transaction or as consideration in or in connection with acquisitions;
• issuances or sales of debt or securities convertible into or exchangeable for shares of our common stock, including in connection with acquisitions;
• departures of key personnel; or
• geopolitical or economic uncertainty around the world.
In the past, following periods of volatility in the market price of a company’s securities, securities class action litigation has often been brought against that company. Securities litigation could result in substantial costs, divert our management’s attention and resources from our business, and have a material adverse effect on our business, operating results, and financial condition.
The warrant transactions may affect the value of our common stock.
In June 2020, we issued our 0.375% Convertible Senior Notes due 2025 (the “2025 Notes”), which matured on June 1, 2025. In connection with the sale of our 2025 Notes, we entered into convertible note hedge transactions (the “2025 Note Hedges”) with certain counterparties. In connection with the sale of the 2025 Notes and purchase of the 2025 Note Hedges, we also entered into warrant transactions with the counterparties pursuant to which we sold warrants (the “2025 Warrants”) for the purchase of our common stock. The 2025 Warrants could have a dilutive effect to the extent that the market price per share of our common stock exceeds the applicable strike price of the 2025 Warrants unless, subject to certain conditions, we elect to cash settle such 2025 Warrants.
The applicable counterparties to the 2025 Warrants or their respective affiliates may modify their related hedge positions by entering into or unwinding various derivatives with respect to our common stock and/or purchasing or selling our common stock or other securities of ours in secondary market transactions prior to the expiration of the 2025 Warrants. This activity could cause or prevent an increase or a decrease in the market price of our common stock.
We do not make any representation or prediction as to the direction or magnitude of any potential effect that the transactions described above may have on the price of our common stock. In addition, we do not make any representation that the counterparties or their respective affiliates will engage in these transactions or that these transactions, once commenced, will not be discontinued without notice.
- 35 -

Table of Contents

The issuance of additional stock in connection with financings, acquisitions, investments, our stock incentive plans, exercise of the 2025 Warrants, or otherwise will dilute stock held by all other stockholders.
Our restated certificate of incorporation authorizes us to issue up to 2.0 billion shares of common stock and up to 100.0 million shares of preferred stock with such rights and preferences as may be determined by our board of directors. Subject to compliance with applicable rules and regulations, we may issue shares of common stock or securities convertible into or exchangeable for shares of our common stock from time to time in connection with a financing or other capital raising, acquisition, investment, our stock incentive plans, the settlement of our 2025 Warrants, or otherwise. Any such issuance, including in connection with the proposed CyberArk acquisition, could result in substantial dilution to our existing stockholders and cause the market price of our common stock to decline.
We cannot guarantee that our share repurchase program will be fully consummated or that it will enhance shareholder value, and share repurchases could affect the price of our common stock.
As of July 31, 2025, we had $1.0 billion available under our share repurchase program which will expire on December 31, 2025 and may be suspended or discontinued at any time without prior notice. Although our board of directors has authorized a share repurchase program, we are not obligated to repurchase any specific dollar amount or to acquire any specific number of shares under the program. The share repurchase program could affect the price of our common stock, increase volatility, and diminish our cash reserves. In addition, the program may be suspended or terminated at any time, which may result in a decrease in the price of our common stock.
We do not intend to pay dividends for the foreseeable future.
We have never declared or paid any dividends on our common stock. We intend to retain any earnings to finance the operation and expansion of our business, and we do not anticipate paying any cash dividends in the future. As a result, stockholders may only receive a return on their investments in our common stock if the market price of our common stock increases.
Our charter documents and Delaware law could discourage takeover attempts and lead to management entrenchment, which could also reduce the market price of our common stock.
Provisions in our restated certificate of incorporation and amended and restated bylaws may have the effect of delaying or preventing a change in control of our company or changes in our management. Our amended and restated certificate of incorporation and amended and restated bylaws include provisions that, among other things:
• establish that our board of directors is divided into three classes, Class I, Class II, and Class III, with three-year staggered terms;
• authorize our board of directors to issue shares of preferred stock and to determine the price and other terms of those shares, including preferences and voting rights, without stockholder approval;
• provide our board of directors with the exclusive right to elect a director to fill a vacancy created by the expansion of our board of directors or the resignation, death, or removal of a director;
• prohibit our stockholders from taking action by written consent;
• specify that special meetings of our stockholders may be called only by the chairman of our board of directors, our president, our secretary, or a majority vote of our board of directors;
• require the affirmative vote of holders of at least 66 2/3% of the voting power of all of the then outstanding shares of the voting stock, voting together as a single class, to amend the provisions of our restated certificate of incorporation relating to the issuance of preferred stock and management of our business or our amended and restated bylaws;
• authorize our board of directors to amend our bylaws by majority vote; and
• establish advance notice procedures with which our stockholders must comply to nominate candidates to our board of directors or to propose matters to be acted upon at a stockholders’ meeting.
These provisions may frustrate or prevent any attempts by our stockholders to replace or remove our current management by making it more difficult for our stockholders to replace members of our board of directors, which is responsible for appointing the members of management. In addition, as a Delaware corporation, we are subject to Section 203 of the Delaware General Corporation Law. These provisions may prohibit large stockholders, in particular those owning 15% or more of our outstanding voting stock, from merging or combining with us for a certain period of time. Any of these provisions could, under certain circumstances, depress the market price of our common stock.
- 36 -

Table of Contents

General Risk Factors
Our business is subject to the risks of earthquakes, fire, power outages, floods, health risks, and other catastrophic events, and to interruption by man-made problems, such as terrorism.
Both our corporate headquarters and the location where our products are manufactured are located in the San Francisco Bay Area, a region known for seismic activity. In addition, other natural disasters, such as fire or floods, a significant power outage, telecommunications failure, terrorism, an armed conflict, cyberattacks, epidemics and pandemics such as COVID-19, or other geopolitical unrest could affect our supply chain, manufacturers, logistics providers, channel partners, end-customers, or the economy as a whole, and such disruption could impact our shipments and sales. These risks may be further increased if the disaster recovery plans for us and our suppliers prove to be inadequate. To the extent that any of the above should result in delays or cancellations of customer orders, the loss of customers, or the delay in the manufacture, deployment, or shipment of our products, our business, financial condition, and operating results would be adversely affected.
Our failure to raise additional capital or generate the significant capital necessary to expand our operations and invest in new products and subscriptions could reduce our ability to compete and could harm our business.
We intend to continue to make investments to support our business growth and may require additional funds to respond to business challenges, including the need to develop new features to enhance our portfolio, improve our operating infrastructure, or acquire complementary businesses and technologies. Accordingly, we may need to engage in equity or debt financings to secure additional funds. If we engage in future debt financings, the holders of such additional debt would have priority over the holders of our common stock. Current and future indebtedness may also contain terms that, among other things, restrict our ability to incur additional indebtedness. In addition, we may be required to take other actions that would otherwise be in the interests of the debt holders and would require us to maintain specified liquidity or other ratios, any of which could harm our business, operating results, and financial condition. If we are unable to obtain adequate financing or financing on terms satisfactory to us when we require it, our ability to continue to support our business growth and to respond to business challenges could be significantly impaired, and our business may be adversely affected.

Item 1B. Unresolved Staff Comments
Not applicable.

Item 1C. Cybersecurity
As a global cybersecurity provider, cybersecurity risk management is an integral part of our overall enterprise risk management program. We recognize the critical importance that a strong cybersecurity risk management program plays in maintaining the trust and confidence of our customers, end users, business partners, stockholders and employees. We have established processes and procedures for identifying, evaluating, and responding to risks from cybersecurity threats, including any potential unauthorized access to our information systems that may result in adverse effects on the confidentiality, integrity, or availability of our information systems, data, or information assets.
Cybersecurity Risk Management and Strategy
Our cybersecurity risk management program includes written policies, standards, and procedures for maintaining data privacy, product security and information security to mitigate cybersecurity risks, and to identify, evaluate and respond to cybersecurity threats, vulnerabilities and incidents. Our cybersecurity risk management program and strategy is implemented across several areas, which include, but are not limited to, the following:
• Information Security. We maintain a written information security program, which provides for policies, standards, guidelines, and administrative, technical and physical safeguards that we believe are reasonably designed, in light of the nature, size and complexity of our operations, to protect the resiliency of our operations and the confidentiality, integrity, and availability of our information systems, data, and information assets. The organizational, administrative and technical measures we implement are based on recognized security frameworks established by the National Institute of Standards and Technology, security measures aligned with the ISO/IEC 27000 series of standards, and other generally recognized industry standards. The program is assessed regularly and in light of new and emerging cybersecurity risks.
- 37 -

Table of Contents

• Technical Safeguards and Product Security. We deploy and maintain a variety of technologies to prevent and detect cybersecurity threats across the network, endpoint and cloud. We also apply security-by-design principles in our software development lifecycle, track vulnerabilities of open-source software, and run internal and external network scans at least weekly and after any meaningful change in our network configuration. We conduct regular application security assessments, including our assessments for internet-facing applications that collect, transmit, or display end user data. We also employ tooling in certain areas to help prevent deviations from policy.
• Incident Response and Reporting. We maintain incident response and recovery protocols to enable prompt, effective and orderly identification, evaluation, management, and disposition of actual and potential security threats and incidents, including for purposes of escalation and internal and external-notification steps. We maintain a cross-functional incident response team, including senior representatives from information security, information technology, product, legal, privacy, communications, and finance, that is involved in assessing cybersecurity threats and incidents, assigning severity levels, and evaluating the potential impact, including the potential impact on our business strategy, results of operations and financial condition. This allows for prompt direction of appropriate personnel and resources for incident management and response, and internal notification to appropriate members of management, which may include our chief executive officer, chief product and technology officer, vice president acting as chief information security officer, general counsel, chief financial officer, and/or chief accounting officer, and the security committee of our board of directors (the “Security Committee”). The protocols also establish steps designed to publicly report and/or alert external stakeholders as and when required by applicable law or otherwise determined appropriate.
• Third-Party Risk Management. We maintain a risk-based approach to identifying and overseeing cybersecurity risks presented by certain third parties, including vendors, service providers, suppliers, operations parties, and other external users of our systems, as well as the systems of third parties that could adversely impact our business in the event of a cybersecurity incident affecting those third-party systems. This includes a security process to conduct due diligence prior to engaging contractors and vendors and assess the security capabilities of subcontractors and vendors on a periodic basis.
• Risk and Readiness Assessments. We engage in at least quarterly assessments and testing of the effectiveness of our cybersecurity risk management program and incident response protocols that are designed to identify and evaluate vulnerabilities and weaknesses, address cybersecurity threats and test our readiness to respond to cybersecurity incidents. These efforts include, but are not limited to, threat modeling, vulnerability scans, penetration testing, audits, and tabletop exercises. We regularly engage third parties to perform assessments on our cybersecurity measures, such as audits and independent reviews of our compliance with various security compliance standards, including those established by the American Institute of Certified Public Accountants, operating effectiveness and penetration tests. The results of such assessments are reported to management and we adjust our cybersecurity policies, standards, processes and practices as necessary based on the information provided by these assessments, audits and reviews.
• Awareness and Training. We provide regular training for educating employees about corporate policies and procedures and information security designed to provide our employees with knowledge of best practices and effective tools for safeguarding our data and assets and reducing security risks based on the human threat vector. Our information security compliance training, data protection training, and code of conduct training is mandatory for all employees.
• Governance. As discussed in more detail below under the heading, “Cybersecurity Governance,” our board of directors’ has delegated oversight of enterprise security risk management, including, but not limited to, cybersecurity risk management to the Security Committee. As part of our cybersecurity risk management procedures, senior members of management and the Security Committee are informed regarding security events based on established reporting thresholds, and are provided ongoing updates regarding any such meaningful threat or incident.
We have not identified any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, that have materially impacted or are reasonably likely to materially impact us, including our business strategy, results of operations, or financial condition, to date. However, we face ongoing and increasing cybersecurity risks, including from threat actors that are becoming more sophisticated and effective over time, and we can provide no assurance that there will not be incidents in the future or that past or future threats or incidents will not materially affect us, including our business strategy, results of operations, or financial conditions. For additional information regarding these risks, please refer to Part I, Item 1A, “Risk Factors,” in this Form 10-K, including, but not limited to, the risk factor entitled “ A network or data security incident may allow unauthorized access to our network or data, harm our reputation, create additional liability, and adversely impact our financial results. ”
- 38 -

Table of Contents

Cybersecurity Governance
The Security Committee, which is composed of our independent directors and chaired by our chief product and technology officer, facilitates our board of directors’ responsibility for oversight of security matters, including product security, data security, cybersecurity, security risk management, risk exposure and related controls and enterprise risk management related to these risks. The Security Committee reports regularly to the Board following meetings of the Security Committee with respect to its review and assessment of security matters and other matters that are relevant to the Security Committee’s discharge of its responsibilities. The Security Committee meets quarterly to review with our vice president acting as chief information security officer and other members of management, which may include our chief executive officer, chief product and technology officer, chief financial officer, and general counsel, our cybersecurity programs, cybersecurity risks, mitigation or remediation strategies, and other matters impacting the committee’s responsibilities .
Management is responsible for day-to-day risk management activities, including identifying, assessing and managing our exposure to cybersecurity risks, establishing processes and procedures to ensure that potential cybersecurity risk exposures are monitored, implementing appropriate mitigation or remediation measures as needed, and maintaining cybersecurity risk management programs. Our vice president acting as chief information security officer is responsible for defining, overseeing, managing, implementing, and reviewing compliance with the information security programs described above under the heading “Cybersecurity Risk Management and Strategy. ” This vice president receives regular reports from our information security team and monitors the prevention, detection, and mitigation or remediation of cybersecurity risks. In addition, as described in further detail above under the heading “Cybersecurity Risk Management and Strategy,” a cross functional team is involved in assessing and managing the risks from cybersecurity threats and incidents, and reporting information about risks to the Security Committee.
Our information security team consists of dedicated personnel who are experienced information systems security professionals and information security managers with many years of experience across a variety of technology sub-specialties. In particular, our vice president acting as chief information security officer has extensive experience in the management of cybersecurity risk management programs, having served in various roles in information technology and security for over 25 years. In addition, six of the eleven members of our board of directors have expertise in overseeing cybersecurity and information security management.

Item 2. Properties
Our corporate headquarters is located in Santa Clara, California, where we lease approximately 941,000 square feet of space under three lease agreements that expire in July 2028, with options to extend the lease terms through July 2046. We also lease space for personnel around the world, including Israel and India. In addition, we provide our cloud-based subscription offerings through data centers operated under co-location arrangements in the United States, Europe, and Asia. Refer to Note 12. Leases in Part II, Item 8 of this Annual Report on Form 10-K for more information on our operating leases. Additionally, we own 10.4 acres of land adjacent to our headquarters in Santa Clara, California, which we intend to develop to accommodate future expansion, the speed of which development has been slowed due to the current environment.
We believe that our current facilities are adequate to meet our current needs. We intend to expand our facilities or add new facilities as we add employees and enter new geographic markets, and we believe that suitable additional or alternative space will be available as needed to accommodate ongoing operations and any such growth. However, we expect to incur additional expenses in connection with such new or expanded facilities.

Item 3. Legal Proceedings
The information set forth under the “Litigation” subheading in Note 13. Commitments and Contingencies in Part II, Item 8 of this Annual Report on Form 10-K is incorporated herein by reference.

Item 4. Mine Safety Disclosures
Not applicable.
- 39 -

Table of Contents

Part II

Item 5. Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities
Market Information
Our common stock, $0.0001 par value per share, is traded on the Nasdaq Global Select Market under the symbol “PANW.”
Holders of Record
As of August 18, 2025, there were 565 holders of record of our common stock. Because many of our shares of common stock are held by brokers and other institutions on behalf of stockholders, we are unable to estimate the total number of stockholders represented by these record holders.
Dividend Policy
We have never declared or paid, and do not anticipate declaring or paying in the foreseeable future, any cash dividends on our capital stock. Any future determination as to the declaration and payment of dividends, if any, will be at the discretion of our board of directors, subject to applicable laws, and will depend on then existing conditions, including our financial condition, operating results, contractual restrictions, capital requirements, business prospects, and other factors our board of directors may deem relevant.
Securities Authorized for Issuance under Equity Compensation Plans
See Part III, Item 12 “Security Ownership of Certain Beneficial Owners and Management and Related Stockholder Matters” of this Annual Report on Form 10-K for more information regarding securities authorized for issuance.
Recent Sales of Unregistered Equity Securities
During the three months ended July 31, 2025, holders of the 2025 Notes converted $382.9 million in aggregate principal amount of the 2025 Notes, which we repaid in cash. We also issued 5.6 million shares of our unregistered common stock to the holders of the 2025 Notes for the conversion value in excess of the principal amount. These shares of our common stock were issued in reliance on the exemption from registration provided by Section 3(a)(9) of the Securities Act of 1933, as amended (the “Securities Act”).
Purchases of Equity Securities by the Issuer and Affiliated Purchasers
In February 2019, we announced that our board of directors authorized a $1.0 billion share repurchase program, which is funded from available working capital. We subsequently announced additional increases to this share repurchase program, bringing the total authorization to $4.1 billion, with $1.0 billion remaining as of July 31, 2025. The expiration date of this repurchase authorization was extended to December 31, 2025, and our repurchase program may be suspended or discontinued at any time. Repurchases under our program are to be made at management’s discretion on the open market, through privately negotiated transactions, transactions structured through investment banking institutions, block purchase techniques, 10b5-1 trading plans, or a combination of the foregoing. During the three months ended July 31, 2025, we did not repurchase any shares pursuant to our share repurchase program.
- 40 -

Table of Contents

Stock Price Performance Graph
This performance graph shall not be deemed “filed” for purposes of Section 18 of the Securities Exchange Act of 1934, as amended (the “Exchange Act”), or incorporated by reference into any filing of Palo Alto Networks, Inc. under the Securities Act of 1933, as amended, or the Exchange Act, except as shall be expressly set forth by specific reference in such filing.
This performance graph compares the cumulative total return on our common stock with that of the Nasdaq 100 Index, the Standard & Poor’s 500 Index, and the Standard & Poor’s 500 Information Technology Index for the five years ended July 31, 2025. This performance graph assumes $100 was invested on July 31, 2020, in each of the common stock of Palo Alto Networks, Inc., the Nasdaq 100 Index, the Standard & Poor’s 500 Index, and the Standard & Poor’s 500 Information Technology Index, and assumes the reinvestment of any dividends. The stock price performance on this performance graph is not necessarily indicative of future stock price performance.
Palo Alto Networks, Inc. Comparison of Total Return Performance

Company/Index 7/31/2020 7/31/2021 7/31/2022 7/31/2023 7/31/2024 7/31/2025
Palo Alto Networks, Inc. $ 100.00  $ 155.93  $ 195.02  $ 293.01  $ 380.66  $ 407.00 
Nasdaq 100 Index $ 100.00  $ 138.19  $ 120.50  $ 147.94  $ 183.34  $ 221.52 
S&P 500 Index $ 100.00  $ 136.45  $ 130.11  $ 147.05  $ 179.62  $ 208.95 
S&P 500 Information Technology Index $ 100.00  $ 140.03  $ 132.31  $ 167.84  $ 226.91  $ 280.58 

Item 6. [Reserved]
- 41 -

Table of Contents

Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations
The following discussion and analysis of our financial condition and results of operations should be read in conjunction with our consolidated financial statements and related notes appearing elsewhere in this Annual Report on Form 10-K. The following discussion and analysis contains forward-looking statements based on current expectations and assumptions that are subject to risks and uncertainties, which could cause our actual results to differ materially from those anticipated or implied by any forward-looking statements. Factors that could cause or contribute to such differences include, but are not limited to, those discussed in this Annual Report on Form 10-K, and in particular, the risks discussed under the caption “Risk Factors” in Part I, Item 1A of this report.
Our Management’s Discussion and Analysis of Financial Condition and Results of Operations (“MD&A”) is organized as follows:
• Overview. A discussion of our business and overall analysis of financial and other highlights in order to provide context for the remainder of MD&A.
• Key Financial Metrics. A summary of our U.S. GAAP and non-GAAP key financial metrics, which management monitors to evaluate our performance.
• Results of Operations. A discussion of the nature and trends in our financial results and an analysis of our financial results comparing fiscal 2025 to fiscal 2024. For discussion and analysis related to our financial results comparing fiscal 2024 to 2023, refer to Part II, Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations in our Annual Report on Form 10-K for fiscal 2024, which was filed with the Securities and Exchange Commission on September 6, 2024.
• Liquidity and Capital Resources. An analysis of changes on our balance sheets and cash flows, and a discussion of our financial condition and our ability to meet cash needs.
• Critical Accounting Estimates. A discussion of our accounting policies that require critical estimates, assumptions, and judgments.
• Recent Accounting Pronouncements. A discussion of expected impacts of impending accounting changes on financial information to be reported in the future.

Overview
Our mission is to be the cybersecurity partner of choice for enterprises, organizations, service providers, and government entities to protect our digital way of life. Our cybersecurity platforms and services help secure enterprise users, networks, clouds, and endpoints by delivering comprehensive cybersecurity backed by artificial intelligence (“AI”) and automation. A key element of our strategy is to help our customers simplify their security architectures through consolidating disparate point products. We execute on this strategy by developing our capabilities and packaging our offerings into platforms which are able to cover many of our customers’ needs in the markets in which we operate. Our platformization strategy combines various products and services into a tightly integrated architecture for more secure, faster, and cost-effective outcomes.
Network Security
Our network security platform is designed to deliver complete zero trust solutions to our customers. The platform includes:
• Secure Access Service Edge (“SASE”). Prisma ® Access, when combined with Prisma SD-WAN, provides a comprehensive single-vendor SASE offering that is used to secure remote workforces and cloud-delivered branch offices. Prisma Access Browser further extends SASE security and data protection to the end user device, providing workers with freedom to access business applications securely using our secure browser from any device.
• Next-Generation Firewalls. Our hardware ML-Powered Next-Generation Firewalls (“NGFWs”) secure on-premises environments including campus locations and data centers. Our software NGFWs secure cloud networks.
• Cloud-Delivered Security Services (“CDSS”). Our network security platform integrates a suite of CDSS that complements our SASE and Firewall solutions. These include Advanced Threat Prevention, Advanced WildFire ® , Advanced URL Filtering, Advanced DNS Security, IoT/OT Security, GlobalProtect ® , Prisma Access Agent, Enterprise Data Loss Prevention (“Enterprise DLP”), AI for IT Operations (“AIOps”), Software as a Service (“SaaS”) Security, and AI Access Security. Through these add-on services, our customers are able to secure their content, applications, users, and devices across their entire organization.
• Prisma AIRS. Prisma AIRS is a comprehensive AI security platform that has been designed to protect customers’ entire AI ecosystem by providing AI model scanning, posture management, red teaming, run-time security, and AI agent security.
- 42 -

Table of Contents

• Strata Cloud Manager (“SCM”). SCM, our network security management solution, centrally manages network security across all remote workers, branches, headquarters, campuses, and cloud. SCM leverages AI to simplify and strengthen network security by enabling customers to proactively pinpoint vulnerabilities, gain real-time remediation recommendations, and enhance overall digital experiences, thereby reducing operational burden. This comprehensive solution includes Strata Copilot, which offers a natural language interface for enhanced insights and guided remediation, and integrates Autonomous Digital Experience Monitoring (“ADEM”) to proactively maintain infrastructure health, facilitate AI-driven one-click troubleshooting, and ensure seamless end-user performance across the enterprise.
Security Operations
Our AI-powered Cortex platform transforms end-to-end security operations with unified data, AI, and automation for more secure, faster, and cost effective outcomes. We have consolidated our industry-leading Security Operations and Cloud Security capabilities on a single comprehensive platform to provide centralized visibility, proactive protection, real-time prevention, AI-driven insights, and automated remediation across enterprise and cloud.
• Security Operations. We deliver the next generation of security operations capabilities that unifies standalone Security Information and Event Management (“SIEM”) tools, endpoint security, security automation, cloud detection and response (“CDR”), as well as attack surface management (“ASM”) capabilities on our Cortex ® platform. These include Cortex XSIAM ® , for AI-powered security operations replacing traditional SIEM tools, Cortex XDR ® , for the prevention, detection, and response to complex cybersecurity attacks, Cortex XSOAR ® , for security orchestration, automation, and response (“SOAR”), and Cortex Xpanse ® , for ASM.
• Cloud Security. We deliver comprehensive security across the cloud application development lifecycle through Cortex Cloud, delivered as a scalable SaaS offering. As a comprehensive Cloud Native Application Protection Platform (“CNAPP”) combined with CDR, Cortex Cloud secures multi- and hybrid-cloud environments for applications, data, generative AI (“GenAI”) ecosystem, and the cloud native technology stack across the full development lifecycle, from code to cloud to security operations. As part of the Cortex Cloud platform, customers can expand from Cortex Cloud to our security operations offerings available on a single user experience and unified agent. We also offer our VM-Series and CN-Series virtual firewalls for inline network security on multi- and hybrid-cloud environments.
Threat Intelligence and Advisory Services
• Unit 42 brings together world-renowned expertise across threat research, incident response, and security consulting to deliver intelligence-driven, response-ready outcomes that help customers reduce cyber risk. Our elite consultants serve as trusted advisors to our customers by assessing and testing their security controls against sophisticated threats, transforming their security strategy with a threat-informed approach, and responding to security incidents on behalf of our clients. Additionally, Unit 42 offers managed detection and response (“MDR”) and managed threat hunting services.
For fiscal 2025 and 2024, total revenue was $9.2 billion and $8.0 billion, respectively, representing year-over-year growth of 14.9%. Our growth reflects the increased adoption of our portfolio, which consists of product, subscriptions, and support. We believe our portfolio will enable us to benefit from recurring revenues and new revenues as we continue to grow our end-customer base. As of July 31, 2025, we had end-customers in over 180 countries. Our end-customers represent a broad range of industries, including education, energy, financial services, government entities, healthcare, Internet and media, manufacturing, public sector, and telecommunications, and include almost all of the Fortune 100 companies and a majority of the Global 2000 companies. We maintain a field sales force that works closely with our channel partners in developing sales opportunities. We primarily use a two-tiered, indirect fulfillment model whereby we sell our products, subscriptions, and support to our distributors, which, in turn, sell to our resellers, which then sell to our end-customers.
Our product revenue grew to $1.8 billion or 19.5% of total revenue for fiscal 2025, representing year-over-year growth of 12.4%. Product revenue is derived from sales of hardware products, primarily our ML-Powered Next-Generation Firewall, and software licenses, including SD-WAN, the VM-Series, and Panorama ® . Our ML-Powered Next-Generation Firewall incorporates our PAN-OS operating system, which provides a consistent set of capabilities across our entire network security product line. Our hardware products and software licenses include a broad set of built-in networking and security features and functionalities. Our products are designed for different performance requirements throughout an organization, ranging from our PA-400, which is designed for small organizations and remote or branch offices, to our top-of-the-line PA-7500, which is designed for large-scale data centers and service provider use. The same firewall functionality that is delivered in our hardware products is also available in our VM-Series virtual firewalls, which secure virtualized and cloud-based computing environments, and in our CN-Series container firewalls, which secure container environments and traffic.
- 43 -

Table of Contents

Our subscription and support revenue grew to $7.4 billion or 80.5% of total revenue for fiscal 2025, representing year-over-year growth of 15.5%. Our subscriptions provide our end-customers with near real-time access to the latest intrusion prevention, web security, modern malware prevention, data loss prevention, CASB and AI security capabilities across the network, endpoints, and the cloud. Our subscriptions also include security operations, which enable customers to leverage the AI-powered Cortex platform for advanced capabilities such as security information and event management, next-generation antivirus, endpoint detection and response, extended detection and response, identity threat detection and response, cloud detection and response, SOAR, ASM, and CNAPP for comprehensive cloud security. Additionally, we offer MDR for Cortex subscriptions, powered by Unit 42’s elite expertise. When customers purchase our physical, virtual, or container firewalls, or certain cloud offerings, they typically purchase support in order to receive ongoing security updates, upgrades, bug fixes, and repairs. In addition to the subscriptions purchased with these firewalls, customers may also purchase other subscriptions on a per-user, per-endpoint, or capacity-based basis. We also offer professional services, including incident response, risk management, and digital forensic services.
We continue to invest in innovation as we evolve and further extend the capabilities of our portfolio, as we believe that innovation and timely development of new features and products are essential to meeting the needs of our end-customers and improving our competitive position. During fiscal 2025, we introduced several new offerings, including: Prisma Access Browser, new capabilities in our OT Security solution, Cortex Cloud, Prisma AIRS, and Cortex XSIAM 3.0. Additionally, in August 2024, we completed the acquisition of certain IBM QRadar assets, which we expect will help accelerate the growth of our Cortex business. Additionally, in July 2025, we completed the acquisition of Protect AI, which we expect will enhance the capabilities of our AI security platform. In July 2025, we also entered into a definitive agreement to acquire Software Ltd. (“CyberArk”), an identity security company, which acquisition is expected to close during the second half of our fiscal 2026.
We believe that the growth of our business and our short-term and long-term success are dependent upon many factors, including our ability to extend our technology leadership, grow our base of end-customers, expand deployment of our portfolio and support offerings within existing end-customers, focus on end-customer satisfaction, and address any product vulnerabilities. To manage any future growth effectively, we must continue to improve and expand our information technology and financial infrastructure, our operating and administrative systems and controls, and our ability to manage headcount, capital, and processes in an efficient manner. While these areas present significant opportunities for us, they also pose challenges and risks that we must successfully address in order to sustain the growth of our business and improve our operating results. For additional information regarding the challenges and risks we face, see the “Risk Factors” section in Part I, Item 1A of this Annual Report on Form 10-K.
IMPACT OF MACROECONOMIC DEVELOPMENTS AND OTHER FACTORS ON OUR BUSINESS
Our overall performance depends in part on worldwide economic and geopolitical conditions and their impact on customer behavior. Changes in legislation or regulations and actions by regulators, including changes in enforcement and administration policies, may have an impact on our results of operations and financial condition. Significant changes in U.S. or global trade policy, including further expansion of U.S. export/imports controls and tariffs, as well as retaliatory actions by other countries, may materially and adversely affect our business. Further, economic conditions, including inflation, high interest rates, slow growth, fluctuations in foreign exchange rates, supply chain disruptions, impacts of trade regulations or international trade disputes, and other conditions, may adversely affect our results of operations and financial performance.
The hostilities in Israel and the surrounding region have continued to result in economic and political uncertainty. While we have business operations in Israel, and intend to continue growing our presence in Israel, we currently do not expect significant business disruption. We are actively monitoring, evaluating, and responding to the situation.
We are also monitoring the impact of inflationary pressures and the tensions between China and Taiwan, and between the U.S. and China, which could have an adverse impact on our business or results of operations in future periods.

Key Financial Metrics
We monitor the key financial metrics set forth in the tables below to help us evaluate growth trends, establish budgets, measure the effectiveness of our sales and marketing efforts, and assess operational efficiencies. We discuss revenue, gross margin, and the components of operating income and margin below under “Results of Operations.”

July 31,
2025 2024

(in billions)

Next-Generation Security Annualized Recurring Revenue
$ 5.6  $ 4.2 
Remaining performance obligations
$ 15.8  $ 12.7 

- 44 -

Table of Contents

Year Ended July 31,
2025 2024 2023

(dollars in millions)
Total revenue $ 9,221.5  $ 8,027.5  $ 6,892.7 
Total revenue year-over-year percentage increase 14.9  % 16.5  % 25.3  %
Gross margin 73.4  % 74.3  % 72.3  %
Operating income
$ 1,242.9  $ 683.9  $ 387.3 
Operating margin 13.5  % 8.5  % 5.6  %
Cash flow provided by operating activities $ 3,716.0  $ 3,257.6  $ 2,777.5 
Free cash flow (non-GAAP) $ 3,469.8  $ 3,100.8  $ 2,631.2 

• Next-Generation Security Annualized Recurring Revenue (“NGS ARR”). Our NGS ARR represents the annualized allocated revenue of all active contracts as of the final day of the reporting period related to all product, subscription and support offerings, excluding revenue from hardware products, and legacy attached subscriptions, support offerings and professional services. NGS ARR is an operating metric that we use to assess the strength and trajectory of our business. NGS ARR should be viewed independently of revenue, deferred revenue and remaining performance obligations and does not represent our revenue under U.S. GAAP on an annualized basis, as it is an operating metric that can be impacted by contract start and end dates and renewal rates. NGS ARR is not intended to be a replacement for forecasts of revenue. The scope of products, subscriptions, and support offerings that contribute to NGS ARR will generally increase over time as we introduce or acquire new next-generation products, subscriptions, and support offerings.
• Cash Flow Provided by Operating Activities. We monitor cash flow provided by operating activities as a measure of our overall business performance. Our cash flow provided by operating activities is driven in large part by sales of our products and from up-front payments for subscription and support offerings. Monitoring cash flow provided by operating activities enables us to analyze our financial performance without the non-cash effects of certain items such as share-based compensation costs, depreciation, and amortization, thereby allowing us to better understand and manage the cash needs of our business.
• Free Cash Flow (non-GAAP). We define free cash flow, a non-GAAP financial measure, as cash provided by operating activities less purchases of property, equipment, and other assets. We consider free cash flow to be a profitability and liquidity measure that provides useful information to management and investors about the amount of cash generated by the business after necessary capital expenditures. A limitation of the utility of free cash flow as a measure of our financial performance and liquidity is that it does not represent the total increase or decrease in our cash balance for the period. In addition, it is important to note that other companies, including companies in our industry, may not use free cash flow, may calculate free cash flow in a different manner than we do, or may use other financial measures to evaluate their performance, all of which could reduce the usefulness of free cash flow as a comparative measure. A reconciliation of free cash flow to cash flow provided by operating activities, the most directly comparable financial measure calculated and presented in accordance with U.S. GAAP, is provided below:

Year Ended July 31,
2025 2024 2023

(in millions)
Free cash flow (non-GAAP):
Net cash provided by operating activities $ 3,716.0  $ 3,257.6  $ 2,777.5 
Less: purchases of property, equipment, and other assets 246.2  156.8  146.3 
Free cash flow (non-GAAP) $ 3,469.8  $ 3,100.8  $ 2,631.2 
Net cash used in investing activities $ (2,204.7) $ (1,509.9) $ (2,033.8)
Net cash used in financing activities $ (778.9) $ (1,343.1) $ (1,726.3)

- 45 -

Table of Contents

Results of Operations
The following table summarizes our results of operations for the periods presented and as a percentage of our total revenue for those periods based on our consolidated statements of operations data. The period-to-period comparison of results is not necessarily indicative of results for future periods.

Year Ended July 31,
2025 2024 2023
Amount % of Revenue Amount % of Revenue Amount % of Revenue

(dollars in millions)
Revenue:
Product $ 1,801.9  19.5  % $ 1,603.3  20.0  % $ 1,578.4  22.9  %
Subscription and support 7,419.6  80.5  % 6,424.2  80.0  % 5,314.3  77.1  %
Total revenue 9,221.5  100.0  % 8,027.5  100.0  % 6,892.7  100.0  %
Cost of revenue:
Product 413.2  4.5  % 348.2  4.3  % 418.3  6.1  %
Subscription and support 2,038.4  22.1  % 1,711.0  21.4  % 1,491.4  21.6  %
Total cost of revenue (1)
2,451.6  26.6  % 2,059.2  25.7  % 1,909.7  27.7  %
Total gross profit 6,769.9  73.4  % 5,968.3  74.3  % 4,983.0  72.3  %
Operating expenses:
Research and development 1,984.1  21.5  % 1,809.4  22.5  % 1,604.0  23.3  %
Sales and marketing 3,100.2  33.6  % 2,794.5  34.8  % 2,544.0  36.9  %
General and administrative 442.7  4.8  % 680.5  8.5  % 447.7  6.5  %
Total operating expenses (1)
5,527.0  59.9  % 5,284.4  65.8  % 4,595.7  66.7  %
Operating income
1,242.9  13.5  % 683.9  8.5  % 387.3  5.6  %
Interest expense (3.0) —  % (8.3) (0.1) % (27.2) (0.4) %
Other income, net 355.8  3.8  % 312.7  3.9  % 206.2  3.0  %
Income before income taxes
1,595.7  17.3  % 988.3  12.3  % 566.3  8.2  %
Provision for (benefit from) income taxes
461.8  5.0  % (1,589.3) (19.8) % 126.6  1.8  %
Net income
$ 1,133.9  12.3  % $ 2,577.6  32.1  % $ 439.7  6.4  %

(1) Includes share-based compensation as follows:

Year Ended July 31,
2025 2024 2023

(in millions)
Cost of product revenue $ 5.1  $ 7.3  $ 9.8 
Cost of subscription and support revenue 127.0  121.0  123.4 
Research and development 550.5  525.5  488.4 
Sales and marketing 359.5  300.8  335.3 
General and administrative 258.0  124.1  130.4 
Total share-based compensation $ 1,300.1  $ 1,078.7  $ 1,087.3 

- 46 -

Table of Contents

REVENUE
Our revenue consists of product revenue and subscription and support revenue. Revenue is recognized upon transfer of control of the corresponding promised products and subscriptions and support to our customers in an amount that reflects the consideration we expect to be entitled to in exchange for those products and subscriptions and support. We expect our revenue to vary from quarter to quarter based on seasonal and cyclical factors.
PRODUCT REVENUE
Product revenue is derived from sales of hardware products, primarily our ML-Powered Next-Generation Firewall, and software licenses, including SD-WAN, the VM-Series, and Panorama. Our hardware products and software licenses include a broad set of built-in networking and security features and functionalities. We recognize product revenue at the time of hardware shipment or delivery of software license. As a percentage of product revenue, we expect our revenue from software licenses to vary from quarter to quarter and increase over the long term as we improve features and capabilities of our on-premise software, renew our software license contracts, and expand our installed end-customer base.

Year Ended July 31, Year Ended July 31,
  2025 2024 Change 2024 2023 Change
Amount Amount Amount % Amount Amount Amount %

  (dollars in millions)
Product $ 1,801.9  $ 1,603.3  $ 198.6  12.4  % $ 1,603.3  $ 1,578.4  $ 24.9  1.6  %

Product revenue increased for fiscal 2025 compared to fiscal 2024 driven by an increase in price of, and allocation to, on-premise software licenses due to enhanced features and capabilities beginning in the second quarter of fiscal 2025, and an increased demand for our new generation of hardware products and accessories, partially offset by decreased demand for our prior generation of hardware products.
SUBSCRIPTION AND SUPPORT REVENUE
Subscription and support revenue is derived primarily from sales of our subscription and support offerings. Our subscription and support contracts are typically one to five years. We recognize revenue from subscriptions and support over time as the services are performed. As a percentage of total revenue, we expect our subscription and support revenue to vary from quarter to quarter and increase over the long term as we introduce new subscriptions, renew existing subscription and support contracts, and expand our installed end-customer base.

Year Ended July 31, Year Ended July 31,
  2025 2024 Change 2024 2023 Change
Amount Amount Amount % Amount Amount Amount %

  (dollars in millions)
Subscription $ 4,974.4  $ 4,188.5  $ 785.9  18.8  % $ 4,188.5  $ 3,335.4  $ 853.1  25.6  %
Support 2,445.2  2,235.7  209.5  9.4  % 2,235.7  1,978.9  256.8  13.0  %
Total subscription and support
$ 7,419.6  $ 6,424.2  $ 995.4  15.5  % $ 6,424.2  $ 5,314.3  $ 1,109.9  20.9  %

Subscription and support revenue increased for fiscal 2025 compared to fiscal 2024 due to increased demand for our subscription and support offerings from our end-customers. The mix between subscription revenue and support revenue will fluctuate over time, depending on the introduction of new subscription offerings, renewals of support services, and our ability to increase sales to new and existing end-customers.
- 47 -

Table of Contents

REVENUE BY GEOGRAPHIC THEATER

Year Ended July 31, Year Ended July 31,
  2025 2024 Change 2024 2023 Change
Amount Amount Amount % Amount Amount Amount %

  (dollars in millions)
Americas $ 6,205.1  $ 5,482.9  $ 722.2  13.2  % $ 5,482.9  $ 4,719.9  $ 763.0  16.2  %
Europe, the Middle East, and Africa (“EMEA”) 1,917.4  1,602.0  315.4  19.7  % 1,602.0  1,359.6  242.4  17.8  %
Asia Pacific and Japan (“APAC”) 1,099.0  942.6  156.4  16.6  % 942.6  813.2  129.4  15.9  %
Total revenue $ 9,221.5  $ 8,027.5  $ 1,194.0  14.9  % $ 8,027.5  $ 6,892.7  $ 1,134.8  16.5  %

Revenue from the Americas, EMEA and APAC increased year-over-year for fiscal 2025 as we continued to increase investment in our global sales force in order to support our growth and innovation, with the Americas contributing the highest increase in revenue due to its larger scale.

COST OF REVENUE
Our cost of revenue consists of cost of product revenue and cost of subscription and support revenue.
COST OF PRODUCT REVENUE
Cost of product revenue primarily includes costs paid to our manufacturing partners for procuring components and manufacturing our products. Our cost of product revenue also includes personnel costs, which consist of salaries, benefits, bonuses, share-based compensation, and travel associated with our operations organization, inventory excess and obsolete charges, shipping and tariff costs, amortization of intellectual property licenses, product testing costs, and shared costs. Shared costs consist of certain facilities, depreciation, benefits, recruiting, and information technology costs that we allocate based on headcount. We expect our cost of product revenue to fluctuate with our revenue from hardware products.

  Year Ended July 31, Year Ended July 31,
  2025 2024 Change 2024 2023 Change
Amount Amount Amount % Amount Amount Amount %

  (dollars in millions)
Cost of product revenue $ 413.2  $ 348.2  $ 65.0  18.7  % $ 348.2  $ 418.3  $ (70.1) (16.8) %

Cost of product revenue increased for fiscal 2025 compared to fiscal 2024 primarily due to an increase in inventory excess and obsolete charges and an increased demand for our new generation hardware products and accessories, partially offset by a decreased demand for our prior generation of hardware products.
COST OF SUBSCRIPTION AND SUPPORT REVENUE
Cost of subscription and support revenue includes personnel costs for our global customer support and technical operations organizations, data center and cloud hosting service costs, third-party professional services costs, amortization of acquired intangible assets and capitalized software development costs, customer support and repair costs, and shared costs. We expect our cost of subscription and support revenue to increase as our installed end-customer base grows and adoption of our cloud-based subscription offerings increases.

  Year Ended July 31, Year Ended July 31,
  2025 2024 Change 2024 2023 Change
Amount Amount Amount % Amount Amount Amount %

  (dollars in millions)
Cost of subscription and support revenue $ 2,038.4  $ 1,711.0  $ 327.4  19.1  % $ 1,711.0  $ 1,491.4  $ 219.6  14.7  %

- 48 -

Table of Contents

Cost of subscription and support revenue increased for fiscal 2025 compared to fiscal 2024 primarily due to increased costs to support the growth of our subscription and support offerings. Cloud hosting service costs, which support our cloud-based subscription offerings, increased $189.5 million for fiscal 2025 compared to fiscal 2024. Personnel costs grew $52.9 million for fiscal 2025 compared to fiscal 2024, primarily due to headcount growth. The increase in cost of subscription and support revenue was further driven by increased professional services expense.

GROSS MARGIN
Gross margin has been and will continue to be affected by a variety of factors, including the introduction of new products, manufacturing costs, the average sales price of our products, cloud hosting service costs, personnel costs, the mix of products sold, and the mix of revenue between product and subscription and support offerings. Our higher-end firewall products generally have higher gross margins than our lower-end firewall products within each product series. We expect our gross margins to vary over time depending on the factors described above.

  Year Ended July 31,
  2025 2024 2023
  Amount Gross Margin
Amount Gross Margin
Amount Gross Margin

  (dollars in millions)
Product $ 1,388.7  77.1  % $ 1,255.1  78.3  % $ 1,160.1  73.5  %
Subscription and support 5,381.2  72.5  % 4,713.2  73.4  % 3,822.9  71.9  %
Total gross profit $ 6,769.9  73.4  % $ 5,968.3  74.3  % $ 4,983.0  72.3  %

Product gross margin decreased for fiscal 2025 compared to fiscal 2024 primarily due to unfavorable hardware product mix and an increase in inventory excess and obsolete charges, partially offset by increased software revenue.
Subscription and support gross margin decreased for fiscal 2025 compared to fiscal 2024 primarily due to an increase in costs related to our cloud-based offerings, partially offset by increased leverage of our global customer service organization.

OPERATING EXPENSES
Our operating expenses consist of research and development, sales and marketing, and general and administrative expenses. Personnel costs are the most significant component of operating expenses and consist of salaries, benefits, bonuses, share-based compensation, travel and entertainment, and with regard to sales and marketing expense, sales commissions. Our operating expenses also include shared costs, which consist of certain facilities, depreciation, benefits, recruiting, and information technology costs that we allocate based on headcount to each department. We expect operating expenses generally to increase in absolute dollars and to decrease over the long term as a percentage of revenue as we continue to scale our business. As of July 31, 2025, we expect to recognize approximately $2.2 billion of share-based compensation expense over a weighted-average period of approximately 2.5 years, excluding additional share-based compensation expense related to any future grants of share-based awards. Share-based compensation expense is generally recognized on a straight-line basis over the requisite service periods of the awards.

RESEARCH AND DEVELOPMENT
Research and development expense consists primarily of personnel costs. Research and development expense also includes prototype-related expenses and shared costs. We expect research and development expense to increase in absolute dollars as we continue to invest in our future products and services, although our research and development expense may fluctuate as a percentage of total revenue.

  Year Ended July 31, Year Ended July 31,
  2025 2024 Change 2024 2023 Change
Amount Amount Amount % Amount Amount Amount %

  (dollars in millions)
Research and development $ 1,984.1  $ 1,809.4  $ 174.7  9.7  % $ 1,809.4  $ 1,604.0  $ 205.4  12.8  %

Research and development expense increased for fiscal 2025 compared to fiscal 2024 primarily due to increased personnel costs, which grew $123.4 million for fiscal 2025 compared to fiscal 2024, largely due to headcount growth. The increase in research and development expense was further driven by increased shared costs.
- 49 -

Table of Contents

SALES AND MARKETING
Sales and marketing expense consists primarily of personnel costs, including commission expense. Sales and marketing expense also includes costs for market development programs, promotional and other marketing costs, professional services, and shared costs. We continue to strategically invest in headcount and have grown our sales presence. We expect sales and marketing expense to continue to increase in absolute dollars as we increase the size of our sales and marketing organizations to grow our customer base, increase touch points with end-customers, and expand our global presence, although our sales and marketing expense may fluctuate as a percentage of total revenue.

  Year Ended July 31, Year Ended July 31,
  2025 2024 Change 2024 2023 Change
Amount Amount Amount % Amount Amount Amount %

  (dollars in millions)
Sales and marketing $ 3,100.2  $ 2,794.5  $ 305.7  10.9  % $ 2,794.5  $ 2,544.0  $ 250.5  9.8  %

Sales and marketing expense increased for fiscal 2025 compared to fiscal 2024 primarily due to increased personnel costs, which grew $263.6 million for fiscal 2025 compared to fiscal 2024, largely due to headcount growth.

GENERAL AND ADMINISTRATIVE
General and administrative expense consists primarily of personnel costs and shared costs for our executive, finance, human resources, information technology, and legal organizations, and professional services costs, which consist primarily of legal, auditing, accounting, and other consulting costs. General and administrative expense also includes change in fair value of contingent consideration liability. We expect general and administrative expense to increase in absolute dollars over time as we increase the size of our general and administrative organizations and incur additional costs to support our business growth, although our general and administrative expense may fluctuate as a percentage of total revenue.

  Year Ended July 31, Year Ended July 31,
  2025 2024 Change 2024 2023 Change
Amount Amount Amount % Amount Amount Amount %

  (dollars in millions)
General and administrative $ 442.7  $ 680.5  $ (237.8) (34.9) % $ 680.5  $ 447.7  $ 232.8  52.0  %

General and administrative expenses decreased for fiscal 2025 compared to fiscal 2024 primarily due to litigation-related charges of $204.4 million in fiscal 2024 and a partial release of litigation-related accrual of $38.8 million in fiscal 2025. We also recorded a gain of $135.3 million in fiscal 2025 for the change in fair value of the contingent consideration liability from our acquisition of certain IBM QRadar assets. The decrease in general and administrative expense was partially offset by increased personnel costs, which grew $153.2 million, largely due to increased share-based compensation.

INTEREST EXPENSE
Interest expense primarily consists of interest expense related to our 0.75% Convertible Senior Notes due 2023 (the “2023 Notes”) and our 0.375% Convertible Senior Notes due 2025 (the “2025 Notes,” and together with “2023 Notes,” the “Notes”).

  Year Ended July 31, Year Ended July 31,
  2025 2024 Change 2024 2023 Change
Amount Amount Amount % Amount Amount Amount %

  (dollars in millions)
Interest expense $ 3.0  $ 8.3  $ (5.3) (63.9) % $ 8.3  $ 27.2  $ (18.9) (69.5) %

Interest expense decreased for fiscal 2025 compared to fiscal 2024 primarily due to conversions of the 2025 Notes prior to or upon maturity in June 2025. Refer to Note 11. Debt in Part II, Item 8 of this Annual Report on Form 10-K for more information on the Notes.
- 50 -

Table of Contents

OTHER INCOME, NET
Other income, net includes interest income earned on our cash, cash equivalents, and investments, and gains and losses from foreign currency remeasurement and foreign currency transactions.

  Year Ended July 31, Year Ended July 31,
  2025 2024 Change 2024 2023 Change
Amount Amount Amount % Amount Amount Amount %

  (dollars in millions)
Other income, net $ 355.8  $ 312.7  $ 43.1  13.8  % $ 312.7  $ 206.2  $ 106.5  51.6  %

Other income, net increased for fiscal 2025 compared to fiscal 2024 primarily due to higher interest income as a result of higher average cash, cash equivalents, and investments balance for fiscal 2025 compared to fiscal 2024. The increase was further driven by increased gains from our non-designated derivative instruments and investments, partially offset by increased foreign currency exchange losses for fiscal 2025 compared to fiscal 2024.

PROVISION FOR (BENEFIT FROM) INCOME TAXES
Provision for income taxes consists primarily of U.S. and foreign income taxes. We had a benefit from income taxes during fiscal 2024 primarily due to the release of our valuation allowance on U.S. federal, U.S. states other than California, and U.K. deferred tax assets. We continue to maintain a valuation allowance for California and certain deferred tax assets.

  Year Ended July 31, Year Ended July 31,    
  2025 2024 Change 2024 2023 Change
  Amount Amount Amount % Amount Amount Amount %

  (dollars in millions)
Provision for (benefit from) income taxes
$ 461.8  $ (1,589.3) $ 2,051.1  * $ (1,589.3) $ 126.6  $ (1,715.9) *
Effective tax rate 28.9  % (160.8) % (160.8) % 22.4  %

*    Not meaningful
Our provision for income taxes in fiscal 2025 was $461.8 million, a net change of $2.1 billion compared to a benefit from income taxes of $1.6 billion in fiscal 2024, primarily due to the release of our valuation allowance in fiscal 2024. This is also the primary driver of the change in our effective tax rate for fiscal 2025 compared to fiscal 2024.
During the year ended July 31, 2025, we recorded a deferred tax provision of $218.5 million arising from the remeasurement of our basis differences associated with the U.S. tax effects of foreign deferred tax assets. Our remeasurement is a result of the One Big Beautiful Bill Act ("OBBB") enacted on July 4, 2025 which provides for significant tax law changes and modifications including changes to the U.S. effective tax rates on certain foreign earnings. Refer to Note 16. Income Taxes in Part II, Item 8 of this Annual Report on Form 10-K for more information on OBBB.
- 51 -

Table of Contents

Liquidity and Capital Resources

July 31,
2025 2024

(in millions)
Working capital (deficit) (1)
$ (465.2) $ (833.0)
Cash, cash equivalents, and investments:
Cash and cash equivalents $ 2,268.6  $ 1,535.2 
Investments 6,190.2  5,216.8 
Total cash, cash equivalents, and investments $ 8,458.8  $ 6,752.0 

(1) Current liabilities included net carrying amounts of convertible senior notes of $1.0 billion as of July 31, 2024. Refer to Note 11. Debt in Part II, Item 8 of this Annual Report on Form 10-K for information on the Notes.
As of July 31, 2025, our total cash, cash equivalents, and investments of $8.5 billion were held for general corporate purposes. As of July 31, 2025, we had no unremitted earnings when evaluating our outside basis difference relating to our U.S. investment in foreign subsidiaries. However, there could be local withholding taxes due to various foreign countries if certain lower tier earnings are distributed. Withholding taxes that would be payable upon remittance of these lower tier earnings are not material.

DEBT
In June 2020, we issued the 2025 Notes with an aggregate principal amount of $2.0 billion. The 2025 Notes were converted prior to or settled on the maturity date of June 1, 2025. During fiscal 2025, we repaid in cash $965.6 million in aggregate principal amount of the 2025 Notes and issued 14.0 million shares of common stock to the holders for the conversion value in excess of the principal amount of the 2025 Notes converted, which were fully offset by shares we received from our exercise of the associated note hedges.
In April 2023, we entered into a credit agreement (the “Credit Agreement”) that provides for a $400.0 million unsecured revolving credit facility (the “Credit Facility”), with an option to increase the amount of the Credit Facility by up to an additional $350.0 million, subject to certain conditions. The interest rates and commitment fees are also subject to upward and downward adjustments based on our progress towards the achievement of certain sustainability goals. As of July 31, 2025, there were no amounts outstanding, and we were in compliance with all covenants under the Credit Agreement. Refer to Note 11. Debt in Part II, Item 8 of this Annual Report on Form 10-K for more information on the Credit Agreement.
CAPITAL RETURN
In February 2019, our board of directors authorized a $1.0 billion share repurchase program. Our board of directors subsequently authorized additional increases to this share repurchase program, bringing the total authorization to $4.1 billion. Repurchases will be funded from available working capital and may be made at management’s discretion from time to time. As of July 31, 2025, $1.0 billion remained available for future share repurchases under this repurchase program. The repurchase authorization will expire on December 31, 2025, and may be suspended or discontinued at any time without prior notice. Refer to Note 14. Stockholders’ Equity in Part II, Item 8 of this Annual Report on Form 10-K for more information on this repurchase program.
CONTRACTUAL OBLIGATIONS AND OTHER MATERIAL CASH REQUIREMENTS
We have entered into various non-cancelable operating leases, primarily for our offices and data centers, with lease terms expiring through fiscal 2036. As of July 31, 2025, we have total operating lease obligations of $417.4 million recorded on our consolidated balance sheet.
As of July 31, 2025, our commitments to purchase products, components, cloud hosting and other services totaled $7.1 billion. Refer to Note 13. Commitments and Contingencies in Part II, Item 8 of this Annual Report on Form 10-K for more information on these commitments.
Our acquisition of certain IBM QRadar assets on August 31, 2024 included contingent consideration that requires potential future payments through the fiscal quarter ending October 2028. As of July 31, 2025, we have total contingent consideration obligation of $513.6 million recorded on our consolidated balance sheet. Refer to Note 3. Fair Value Measurements and Note 8. Acquisitions in Part II, Item 8 of this Annual Report on Form 10-K for more information on our contingent consideration obligation.
- 52 -

Table of Contents

On July 30, 2025, we entered into a definitive agreement to acquire CyberArk. The acquisition is expected to close during the second half of our fiscal 2026, subject to the satisfaction of customary closing conditions. Under the terms of the definitive agreement, CyberArk shareholders will receive $45.00 in cash and 2.2005 shares of our common stock for each CyberArk share. This represents an equity value for CyberArk of approximately $25 billion based on the unaffected 10-day average daily volume-weighted average trading prices of our common stock as of July 25, 2025. We expect to fund the cash portion of the consideration with our cash on hand. Refer to Part I, Item 1A “Risk Factors” in this Form 10-K and Note 8. Acquisitions in Part II, Item 8 of this Annual Report on Form 10-K for more information on the acquisition.

CASH FLOWS
The following table summarizes our cash flows for the years ended July 31, 2025, 2024, and 2023:

Year Ended July 31,
2025 2024 2023

(in millions)
Net cash provided by operating activities $ 3,716.0  $ 3,257.6  $ 2,777.5 
Net cash used in investing activities (2,204.7) (1,509.9) (2,033.8)
Net cash used in financing activities (778.9) (1,343.1) (1,726.3)
Net increase (decrease) in cash, cash equivalents, and restricted cash
$ 732.4  $ 404.6  $ (982.6)

Cash from operations could be affected by various risks and uncertainties detailed in Part I, Item 1A “Risk Factors” in this Form 10-K. We believe that our cash flow from operations with existing cash and cash equivalents will be sufficient to meet our anticipated cash needs for at least the next 12 months and thereafter for the foreseeable future. Our future capital requirements will depend on many factors including our growth rate, the timing and extent of spending to support development efforts, the expansion of sales and marketing activities, the introduction of new and enhanced products and subscription and support offerings, the costs to acquire or invest in complementary businesses and technologies, the costs to ensure access to adequate manufacturing capacity, the investments in our infrastructure to support the adoption of our cloud-based subscription offerings, the continuing market acceptance of our products and subscription and support offerings and macroeconomic events. In addition, from time to time, we may incur additional tax liability in connection with certain corporate structuring decisions.
We may also choose to seek additional equity or debt financing. In the event that additional financing is required from outside sources, we may not be able to raise it on terms acceptable to us or at all. If we are unable to raise additional capital when desired, our business, operating results, and financial condition may be adversely affected.
OPERATING ACTIVITIES
Our operating activities have consisted of net income adjusted for certain non-cash items and changes in assets and liabilities. Our largest source of cash provided by our operations is receipts from our customers. Net cash provided by operating activities can be impacted by factors such as timing of payments and collections, vendor payment terms, and timing and amount of tax payments.
Cash provided by operating activities during fiscal 2025 was $3.7 billion, an increase of $458.4 million compared to fiscal 2024. The increase was primarily due to growth of our business as reflected by increases in collections during fiscal 2025, partially offset by higher cash expenditure to support our business growth.
INVESTING ACTIVITIES
Our investing activities have consisted of capital expenditures, net investment purchases, sales, and maturities, and business acquisitions. We expect to continue such activities as our business grows.
Cash used in investing activities during fiscal 2025 was $2.2 billion, an increase of $694.8 million compared to fiscal 2024. The increase was primarily due to an increase in net cash payments for business acquisitions and higher purchases of investments during fiscal 2025.
FINANCING ACTIVITIES
Our financing activities have consisted of repayments of our convertible senior notes, cash used to repurchase shares of our common stock, proceeds from sales of shares through employee equity incentive plans, and payments for tax withholding obligations of certain employees related to the net share settlement of equity awards.
Cash used in financing activities during fiscal 2025 was $778.9 million, a decrease of $564.2 million compared to fiscal 2024. The decrease was primarily due to a decrease in cash used to repurchase our common stock which did not recur during fiscal 2025.
- 53 -

Table of Contents

Critical Accounting Estimates
Our consolidated financial statements have been prepared in accordance with U.S. GAAP. The preparation of these consolidated financial statements requires us to make estimates and assumptions that affect the reported amounts of assets, liabilities, revenue, expenses, and related disclosures. We base our estimates on historical experience and on various other assumptions that we believe are reasonable under the circumstances. We evaluate our estimates and assumptions on an ongoing basis. Actual results could differ materially from those estimates due to risks and uncertainties, including uncertainty in the current economic environment. To the extent that there are material differences between these estimates and our actual results, our future consolidated financial statements will be affected.
We believe that of our significant accounting policies described in Note 1. Description of Business and Summary of Significant Accounting Policies in Part II, Item 8 of this Annual Report on Form 10-K, the critical accounting estimates, assumptions, and judgments that have the most significant impact on our consolidated financial statements are described below.

REVENUE RECOGNITION
The majority of our contracts with our customers include various combinations of our products and subscriptions and support. Our hardware products and software licenses are distinct from our subscriptions and support services as the customer can benefit from the product without these services and such services are separately identifiable within the contract. We account for multiple agreements with a single customer as a single contract if the contractual terms and/or substance of those agreements indicate that they may be so closely related that they are, in effect, parts of a single contract. The amount of consideration we expect to receive in exchange for delivering on the contract is allocated to each performance obligation based on its relative standalone selling price.
When estimating standalone selling price, we first consider the prices charged for a deliverable when sold separately. If the standalone selling price is not observable through past transactions, we estimate it based on our pricing model and our go-to-market strategy, which include factors such as type of sales channel (channel partner or end-customer), the geographies in which our offerings were sold (domestic or international), and offering type (products, subscriptions, or support). As our business offerings evolve over time, we may be required to modify our estimated standalone selling prices, and as a result the timing and classification of our revenue could be affected.

INCOME TAXES
We account for income taxes using the asset and liability method, which requires the recognition of deferred tax assets and liabilities for the expected future tax consequences of events that have been recognized in our consolidated financial statements or tax returns. In addition, deferred tax assets are recorded for all future benefits including, but not limited to, net operating losses, research and development credit carryforwards, and basis differences relating to our global intangible low-taxed income. Valuation allowances are provided when necessary to reduce deferred tax assets to the amount more likely than not to be realized.
Significant judgment is required in determining any valuation allowance recorded against deferred tax assets. In assessing the need for a valuation allowance, we consider all available evidence, including past operating results, estimates of future taxable income, and the feasibility of tax planning strategies. In the event that we change our determination as to the amount of deferred tax assets that can be realized, we will adjust our valuation allowance with a corresponding impact to the provision for income taxes in the period in which such determination is made.
We recognize liabilities for uncertain tax positions based on a two-step process which includes evaluating if a tax position is more likely than not to be sustained on audit and then measuring the tax benefit as the largest amount that is more likely than not to be realized upon ultimate settlement. Assumptions, judgment, and the use of estimates are required in determining if the more-likely-than-not standard has been met and in determining the expected benefit when developing the provision for income taxes. Our evaluations are based upon a number of factors, including changes in facts or circumstances, changes in tax law or guidance, correspondence with tax authorities during the course of audits, and effective settlement of audit issues. Changes in these or other factors could result in material increases or decreases in our provision for (benefit from) income taxes in the period in which we make the change.

LOSS CONTINGENCIES
We are subject to the possibility of various loss contingencies arising in the ordinary course of business. We accrue for loss contingencies when it is probable that an asset has been impaired or a liability has been incurred and the amount of loss can be reasonably estimated. If we determine that a loss is reasonably possible, then we disclose the possible loss or range of the possible loss or state that such an estimate cannot be made. We regularly evaluate current information available to us to determine whether an accrual is required, an accrual should be adjusted, or a range of possible loss should be disclosed.
- 54 -

Table of Contents

From time to time, we are involved in disputes, litigation, and other legal actions. However, there are many uncertainties associated with any litigation, and these actions or other third-party claims against us may cause us to incur substantial settlement charges, which are inherently difficult to estimate and could adversely affect our results of operations. The actual liability in any such matters may be materially different from our estimates, which could result in the need to adjust our liability and record additional expenses. Refer to the “Litigation” subheading in Note 13. Commitments and Contingencies in Part II, Item 8 of this Annual Report on Form 10-K for more information regarding our litigation.

BUSINESS COMBINATIONS
We make significant estimates, assumptions, and judgments when valuing assets acquired and liabilities assumed, especially with respect to purchased intangible assets, in connection with the initial purchase price allocation of an acquired business. Critical estimates in valuing certain purchased intangible assets include, but are not limited to, cash flows that an asset is expected to generate in the future, discount rates, the time and expense that would be necessary to recreate the assets, and the profit margin a market participant would receive on such recreated assets. The amounts and useful lives assigned to identified intangible assets impact the amount and timing of future amortization expense.
One of our business combinations has included post-closing payments contingent upon the occurrence of future events and/or certain conditions being met. Critical estimates used in valuing our contingent consideration obligation include, but are not limited to, estimated future cash payments related to customers entering into qualified new transactions and risk-adjusted discount rates used to present value the expected cash flows. These estimates and assumptions are updated to revalue our contingent consideration liability at the end of each reporting period. Accordingly, subsequent changes in underlying facts and circumstances could result in changes in these estimates and assumptions, which could have a material impact on the estimated future fair values of these obligations.

Recent Accounting Pronouncements
Refer to “Recently Adopted Accounting Pronouncement” and “Recently Issued Accounting Pronouncements” in Note 1. Description of Business and Summary of Significant Accounting Policies in Part II, Item 8 of this Annual Report on Form 10-K for a description of recent accounting pronouncements and our expectation of their impact, if any, on our results of operations and financial condition.
- 55 -

Table of Contents

Item 7A. Quantitative and Qualitative Disclosures About Market Risk
Foreign Currency Exchange Risk
Our sales contracts are primarily denominated in U.S. dollars. A portion of our operating expenditures are denominated in foreign currencies, making them subject to fluctuations in foreign currency exchange rates. Additionally, fluctuations in foreign currency exchange rates may cause us to recognize transaction gains and losses in our statement of operations. Foreign currency remeasurement gains and losses and foreign currency transaction gains and losses have not had a significant impact to our consolidated financial statements.
We enter into foreign currency derivative contracts with maturities of 24 months or less, which we designate as cash flow hedges, to manage the foreign currency exchange risk associated with our revenue and operating expenditures. We also enter into foreign currency derivative contracts that are not designated as hedging instruments to hedge a portion of our outstanding monetary assets and liabilities denominated in foreign currencies. These foreign currency derivative contracts reduce but do not entirely eliminate the effect of foreign exchange rate fluctuations.
A hypothetical 10% change in foreign exchange rates on monetary assets and liabilities would not be material to our financial condition or results of operations after taking into consideration the effect of foreign currency forward contracts in place as of July 31, 2025. The effectiveness of our existing hedging transactions and the availability and effectiveness of any hedging transactions we may decide to enter into in the future may be limited, and we may not be able to successfully hedge our exposure, which could adversely affect our financial condition and results of operations. Refer to Note 6. Derivative Instruments in Part II, Item 8 of this Annual Report on Form 10-K for more information.
As our international operations grow, our risks associated with fluctuations in foreign currency exchange rates will become greater, and we will continue to reassess our approach to managing this risk. In addition, a weakening U.S. dollar can increase the costs of our international expansion and a strengthening U.S. dollar can increase the real cost of our products and services to our end-customers outside of the United States, leading to delays in the purchase of our products and services. For additional information, see the risk factor entitled “We are exposed to fluctuations in foreign currency exchange rates, which could negatively affect our financial condition and operating results.” in Part 1, Item 1A of this Annual Report on Form 10-K.
Interest Rate Risk
The primary objectives of our investment activities are to preserve principal, provide liquidity, and maximize income without significantly increasing risk. Most of the securities we invest in are subject to interest rate risk. To minimize this risk, we maintain a diversified portfolio of cash, cash equivalents, and investments, consisting only of investment-grade securities. To assess the interest rate risk, we performed a sensitivity analysis to determine the impact a change in interest rates would have on the value of the investment portfolio. Based on investment positions as of July 31, 2025, a hypothetical 100 basis point increase in interest rates across all maturities would result in a $132.3 million decline in the fair market value of the portfolio. Such losses would only be realized if we sold the investments prior to maturity. Conversely, a hypothetical 100 basis point decrease in interest rates would lead to a $134.7 million increase in the fair market value of the portfolio.
- 56 -

Table of Contents

Item 8. Financial Statements and Supplementary Data

Index To Consolidated Financial Statements

Page
Reports of Independent Registered Public Accounting Firm (PCAOB ID: 42 )
58

Consolidated Balance Sheets
61

Consolidated Statements of Operations
62

Consolidated Statements of Comprehensive Income
63

Consolidated Statements of Stockholders’ Equity
64

Consolidated Statements of Cash Flows
65

Notes to Consolidated Financial Statements
66

- 57 -

Table of Contents

Report of Independent Registered Public Accounting Firm
To the Stockholders and the Board of Directors of Palo Alto Networks, Inc.
Opinion on the Financial Statements
We have audited the accompanying consolidated balance sheets of Palo Alto Networks, Inc. (the Company) as of July 31, 2025 and 2024, the related consolidated statements of operations, comprehensive income, stockholders’ equity and cash flows for each of the three years in the period ended July 31, 2025, and the related notes (collectively referred to as the “consolidated financial statements”). In our opinion, the consolidated financial statements present fairly, in all material respects, the financial position of the Company at July 31, 2025 and 2024, and the results of its operations and its cash flows for each of the three years in the period ended July 31, 2025, in conformity with U.S. generally accepted accounting principles.
We also have audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the Company’s internal control over financial reporting as of July 31, 2025, based on criteria established in Internal Control—Integrated Framework issued by the Committee of Sponsoring Organizations of the Treadway Commission (2013 framework), and our report dated August 29, 2025 expressed an unqualified opinion thereon.
Basis for Opinion
These financial statements are the responsibility of the Company’s management. Our responsibility is to express an opinion on the Company’s financial statements based on our audits. We are a public accounting firm registered with the PCAOB and are required to be independent with respect to the Company in accordance with the U.S. federal securities laws and the applicable rules and regulations of the Securities and Exchange Commission and the PCAOB.
We conducted our audits in accordance with the standards of the PCAOB. Those standards require that we plan and perform the audit to obtain reasonable assurance about whether the financial statements are free of material misstatement, whether due to error or fraud. Our audits included performing procedures to assess the risks of material misstatement of the financial statements, whether due to error or fraud, and performing procedures that respond to those risks. Such procedures included examining, on a test basis, evidence regarding the amounts and disclosures in the financial statements. Our audits also included evaluating the accounting principles used and significant estimates made by management, as well as evaluating the overall presentation of the financial statements. We believe that our audits provide a reasonable basis for our opinion.
Critical Audit Matter
The critical audit matters communicated below are matters arising from the current period audit of the financial statements that were communicated or required to be communicated to the audit committee and that: (1) relate to accounts or disclosures that are material to the financial statements and (2) involved our especially challenging, subjective or complex judgments. The communication of critical audit matters does not alter in any way our opinion on the consolidated financial statements, taken as a whole, and we are not, by communicating the critical audit matters below, providing separate opinions on the critical audit matters or on the accounts or disclosures to which they relate.
- 58 -

Table of Contents

REVENUE RECOGNITION

Description
of the Matter
As described in Note 1 to the consolidated financial statements, the Company’s contracts with customers sometimes contain multiple performance obligations, which are accounted for separately if they are distinct. In such cases, the transaction price is then allocated to the distinct performance obligations on a relative standalone selling price basis, and revenue is recognized when control of the distinct performance obligation is transferred. For example, product revenue is recognized at the time of hardware shipment or delivery of software license, and subscription and support revenue is recognized over time as the services are performed.
Auditing the Company’s revenue recognition was complex, including the identification and determination of distinct performance obligations and the timing of revenue recognition. For example, there were certain customer arrangements with nonstandard terms and conditions that required judgment to determine the distinct performance obligations and the impact on the timing of revenue recognition.

How We Addressed
the Matter in Our Audit
We obtained an understanding, evaluated the design and tested the operating effectiveness of the Company’s process and controls to identify and determine the distinct performance obligations and the timing of revenue recognition.
To test the identification and determination of the distinct performance obligations and the timing of revenue recognition, our audit procedures included, among others, reading the executed contract and other contractual documents to understand the contract, identifying the performance obligation(s), determining the distinct performance obligations, and evaluating the timing of revenue recognition for a sample of individual sales transactions. We evaluated the accuracy of the Company’s contract summary documentation, specifically related to the identification and determination of distinct performance obligations and the timing of revenue recognition.

VALUATION OF CONTINGENT CONSIDERATION LIABILITY IN CONNECTION WITH THE ACQUISITION OF IBM QRADAR ASSETS

Description
of the Matter
As described in Note 8 to the consolidated financial statements, the Company completed the acquisition of certain IBM QRadar assets on August 31, 2024, for which the purchase consideration included contingent consideration. The Company has determined the fair value of contingent consideration liability to be $513.6 million as of July 31, 2025, using a discounted cash flow valuation technique including an estimate of future cash payments related to customers entering into qualified new transactions with the Company as well as a risk-adjusted discount rate used to present value the expected cash flows.
Auditing the Company’s accounting for contingent consideration liability was complex due to estimation uncertainty in the Company’s determination of the fair value due to the significant assumption about customer transactions that will qualify for cash payments under the arrangement. The significant assumption is forward-looking, dependent upon customer behavior, and could be affected by various factors including future economic and market conditions.

How We Addressed
the Matter in Our Audit
We obtained an understanding, evaluated the design and tested the operating effectiveness of the Company’s process and controls to estimate fair value of the contingent consideration liability. We also tested controls regarding management’s review of assumptions used in the valuation model.
To test the estimated fair value of this contingent consideration liability, our audit procedures included, among others, assessing the valuation methodology with the assistance of a valuation specialist, and testing the significant assumption about customer transactions that will qualify for cash payments under the arrangement and the completeness and accuracy of the underlying data used by the Company. We also performed a sensitivity analysis to evaluate the changes in the fair value of this contingent consideration liability that would result from changes in the significant assumption. We also considered whether the assumption was consistent with evidence obtained in other areas of the audit.

/s/ Ernst & Young LLP
We have served as the Company’s auditor since 2009.
San Mateo, California
August 29, 2025
- 59 -

Table of Contents

Report of Independent Registered Public Accounting Firm
To the Stockholders and the Board of Directors of Palo Alto Networks, Inc.
Opinion on Internal Control Over Financial Reporting
We have audited Palo Alto Networks, Inc.’s internal control over financial reporting as of July 31, 2025, based on criteria established in Internal Control—Integrated Framework issued by the Committee of Sponsoring Organizations of the Treadway Commission (2013 framework) (the COSO criteria). In our opinion, Palo Alto Networks, Inc. (the Company) maintained, in all material respects, effective internal control over financial reporting as of July 31, 2025, based on the COSO criteria.
We also have audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the consolidated balance sheets of the Company as of July 31, 2025 and 2024, the related consolidated statements of operations, comprehensive income, stockholders’ equity and cash flows for each of the three years in the period ended July 31, 2025, and the related notes and our report dated August 29, 2025 expressed an unqualified opinion thereon.
Basis for Opinion
The Company’s management is responsible for maintaining effective internal control over financial reporting and for its assessment of the effectiveness of internal control over financial reporting included in the accompanying Management’s Annual Report on Internal Control over Financial Reporting. Our responsibility is to express an opinion on the Company’s internal control over financial reporting based on our audit. We are a public accounting firm registered with the PCAOB and are required to be independent with respect to the Company in accordance with the U.S. federal securities laws and the applicable rules and regulations of the Securities and Exchange Commission and the PCAOB.
We conducted our audit in accordance with the standards of the PCAOB. Those standards require that we plan and perform the audit to obtain reasonable assurance about whether effective internal control over financial reporting was maintained in all material respects.
Our audit included obtaining an understanding of internal control over financial reporting, assessing the risk that a material weakness exists, testing and evaluating the design and operating effectiveness of internal control based on the assessed risk, and performing such other procedures as we considered necessary in the circumstances. We believe that our audit provides a reasonable basis for our opinion.
Definition and Limitations of Internal Control Over Financial Reporting
A company’s internal control over financial reporting is a process designed to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements for external purposes in accordance with generally accepted accounting principles. A company’s internal control over financial reporting includes those policies and procedures that (1) pertain to the maintenance of records that, in reasonable detail, accurately and fairly reflect the transactions and dispositions of the assets of the company; (2) provide reasonable assurance that transactions are recorded as necessary to permit preparation of financial statements in accordance with generally accepted accounting principles, and that receipts and expenditures of the company are being made only in accordance with authorizations of management and directors of the company; and (3) provide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use, or disposition of the company’s assets that could have a material effect on the financial statements.
Because of its inherent limitations, internal control over financial reporting may not prevent or detect misstatements. Also, projections of any evaluation of effectiveness to future periods are subject to the risk that controls may become inadequate because of changes in conditions, or that the degree of compliance with the policies or procedures may deteriorate.
/s/ Ernst & Young LLP
San Mateo, California
August 29, 2025
- 60 -

Table of Contents

PALO ALTO NETWORKS, INC.

CONSOLIDATED BALANCE SHEETS
(In millions, except per share data)
July 31,
2025 2024
Assets
Current assets:
Cash and cash equivalents $ 2,268.6   $ 1,535.2  
Short-term investments 634.6   1,043.6  
Accounts receivable, net of allowance for credit losses of $ 9.7 and $ 7.5 as of July 31, 2025 and July 31, 2024, respectively
2,965.0   2,618.6  
Short-term financing receivables, net 714.6   725.9  
Short-term deferred contract costs 419.5   369.0  
Prepaid expenses and other current assets 520.5   557.4  
Total current assets 7,522.8   6,849.7  
Property and equipment, net 387.3   361.1  
Operating lease right-of-use assets 347.0   385.9  
Long-term investments 5,555.6   4,173.2  
Long-term financing receivables, net 1,002.3   1,182.1  
Long-term deferred contract costs 585.9   562.0  
Goodwill 4,566.6   3,350.1  
Intangible assets, net 762.7   374.9  
Deferred tax assets
2,424.2   2,399.0  
Other assets 421.8   352.9  
Total assets $ 23,576.2   $ 19,990.9  
Liabilities and stockholders’ equity
Current liabilities:
Accounts payable $ 232.2   $ 116.3  
Accrued compensation 607.6   554.7  
Accrued and other liabilities 846.0   506.7  
Deferred revenue 6,302.2   5,541.1  
Convertible senior notes, net —   963.9  
Total current liabilities 7,988.0   7,682.7  

Long-term deferred revenue 6,449.7   5,939.4  
Deferred tax liabilities
89.1   387.7  
Long-term operating lease liabilities 338.2   380.5  
Other long-term liabilities 886.8   430.9  
Total liabilities 15,751.8   14,821.2  
Commitments and contingencies (Note 13)

Stockholders’ equity:
Preferred stock; $ 0.0001 par value; 100.0 shares authorized; none issued and outstanding as of July 31, 2025 and July 31, 2024
—   —  
Common stock and additional paid-in capital; $ 0.0001 par value; 2,000.0 shares authorized; 667.9 and 650.2 shares issued and outstanding as of July 31, 2025 and July 31, 2024, respectively
5,291.9   3,821.1  
Accumulated other comprehensive income (loss)
48.4   ( 1.6 )
Retained earnings
2,484.1   1,350.2  
Total stockholders’ equity 7,824.4   5,169.7  
Total liabilities and stockholders’ equity $ 23,576.2   $ 19,990.9  

See notes to consolidated financial statements.
- 61 -

Table of Contents

PALO ALTO NETWORKS, INC.

CONSOLIDATED STATEMENTS OF OPERATIONS
(In millions, except per share data)

Year Ended July 31,
2025 2024 2023
Revenue:
Product $ 1,801.9   $ 1,603.3   $ 1,578.4  
Subscription and support 7,419.6   6,424.2   5,314.3  
Total revenue 9,221.5   8,027.5   6,892.7  
Cost of revenue:
Product 413.2   348.2   418.3  
Subscription and support 2,038.4   1,711.0   1,491.4  
Total cost of revenue 2,451.6   2,059.2   1,909.7  
Total gross profit 6,769.9   5,968.3   4,983.0  
Operating expenses:
Research and development 1,984.1   1,809.4   1,604.0  
Sales and marketing 3,100.2   2,794.5   2,544.0  
General and administrative 442.7   680.5   447.7  
Total operating expenses 5,527.0   5,284.4   4,595.7  
Operating income
1,242.9   683.9   387.3  
Interest expense ( 3.0 ) ( 8.3 ) ( 27.2 )
Other income, net 355.8   312.7   206.2  
Income before income taxes
1,595.7   988.3   566.3  
Provision for (benefit from) income taxes
461.8   ( 1,589.3 ) 126.6  
Net income
$ 1,133.9   $ 2,577.6   $ 439.7  
Net income per share, basic
$ 1.71   $ 4.04   $ 0.73  
Net income per share, diluted
$ 1.60   $ 3.64   $ 0.64  
Weighted-average shares used to compute net income per share, basic
662.5   638.5   606.4
Weighted-average shares used to compute net income per share, diluted
709.3   707.9   684.5

See notes to consolidated financial statements.
- 62 -

Table of Contents

PALO ALTO NETWORKS, INC.

CONSOLIDATED STATEMENTS OF COMPREHENSIVE INCOME
(In millions)

Year Ended July 31,
2025 2024 2023
Net income
$ 1,133.9   $ 2,577.6   $ 439.7  
Other comprehensive income, net of tax:

Change in unrealized gains (losses) on investments 18.5   48.2   ( 13.0 )
Cash flow hedges:
Change in unrealized gains (losses) 29.6   ( 18.9 ) ( 0.2 )
Net realized (gains) losses reclassified into earnings 1.9   12.3   25.6  
Net change on cash flow hedges 31.5   ( 6.6 ) 25.4  
Other comprehensive income
50.0   41.6   12.4  
Comprehensive income
$ 1,183.9   $ 2,619.2   $ 452.1  

See notes to consolidated financial statements.
- 63 -

Table of Contents

PALO ALTO NETWORKS, INC.

CONSOLIDATED STATEMENTS OF STOCKHOLDERS’ EQUITY
(In millions)

  Common Stock
and
Additional Paid-In Capital Accumulated Other Comprehensive Income (Loss) Retained Earnings (Accumulated Deficit)
Total Stockholders’ Equity
  Shares Amount
Balance as of July 31, 2022 597.7   $ 1,932.7   $ ( 55.6 ) $ ( 1,667.1 ) $ 210.0  

Net Income
—  —  —  439.7   439.7  
Other comprehensive income
—  —  12.4   —  12.4  
Issuance of common stock in connection with employee equity incentive plans 22.6   259.7   —  —  259.7  
Taxes paid related to net share settlement of equity awards —  ( 20.4 ) —  —  ( 20.4 )
Share-based compensation for equity-based awards —  1,097.0   —  —  1,097.0  
Repurchase and retirement of common stock ( 3.6 ) ( 250.0 ) —  —  ( 250.0 )

Settlement of convertible notes 22.9   —  —  —  — 
Settlement of note hedges
( 22.9 ) —  —  —  — 
Balance as of July 31, 2023 616.7   3,019.0   ( 43.2 ) ( 1,227.4 ) 1,748.4  

Net income
—  —  —  2,577.6   2,577.6  
Other comprehensive income
—  —  41.6   —  41.6  
Issuance of common stock in connection with employee equity incentive plans 19.5   282.7   —  —  282.7  
Taxes paid related to net share settlement of equity awards —  ( 26.6 ) —  —  ( 26.6 )
Share-based compensation for equity-based awards —  1,115.3   —  —  1,115.3  
Repurchase and retirement of common stock ( 4.0 ) ( 566.7 ) —  —  ( 566.7 )

Settlement of convertible notes 14.0   ( 2.6 ) —  —  ( 2.6 )
Settlement of note hedges
( 14.0 ) —  —  —  — 
Settlement of warrants 18.0   —  —  —  — 

Balance as of July 31, 2024 650.2   3,821.1   ( 1.6 ) 1,350.2   5,169.7  

Net income —  —  —  1,133.9   1,133.9  
Other comprehensive income —  —  50.0   —  50.0  
Issuance of common stock in connection with employee equity incentive plans 17.7   369.3   —  —  369.3  
Taxes paid related to net share settlement of equity awards —  ( 183.8 ) —  —  ( 183.8 )
Share-based compensation for equity-based awards —  1,285.3   —  —  1,285.3  

Settlement of convertible notes 14.0   —  —  —  — 
Settlement of note hedges ( 14.0 ) —  —  —  — 

Balance as of July 31, 2025 667.9   $ 5,291.9   $ 48.4   $ 2,484.1   $ 7,824.4  

See notes to consolidated financial statements.
- 64 -

Table of Contents

PALO ALTO NETWORKS, INC.

CONSOLIDATED STATEMENTS OF CASH FLOWS
(In millions)

Year Ended July 31,
2025 2024 2023
Cash flows from operating activities
Net income
$ 1,133.9   $ 2,577.6   $ 439.7  
Adjustments to reconcile net income to net cash provided by operating activities:

Share-based compensation for equity-based awards 1,295.1   1,075.4   1,074.5  
Deferred income taxes ( 349.9 ) ( 2,033.7 ) 12.5  
Depreciation and amortization 343.4   283.3   282.2  

Amortization of deferred contract costs 480.6   446.0   413.4  
Amortization of debt issuance costs
1.1   3.5   6.7  
Change in fair value of contingent consideration liability
( 135.3 ) —   —  
Reduction of operating lease right-of-use assets 65.4   55.3   49.9  
Amortization of investment premiums, net of accretion of purchase discounts ( 41.1 ) ( 60.1 ) ( 52.2 )

Changes in operating assets and liabilities, net of effects of acquisitions:
Accounts receivable, net ( 345.3 ) ( 154.3 ) ( 320.3 )
Financing receivables, net 191.1   ( 865.9 ) ( 738.7 )
Deferred contract costs ( 555.0 ) ( 489.3 ) ( 431.9 )
Prepaid expenses and other assets 88.3   ( 134.1 ) ( 270.6 )
Accounts payable 106.8   ( 15.0 ) 1.0  
Accrued compensation 51.3   3.8   84.4  
Accrued and other liabilities 147.5   384.5   ( 74.8 )
Deferred revenue 1,238.1   2,180.6   2,301.7  
Net cash provided by operating activities 3,716.0   3,257.6   2,777.5  
Cash flows from investing activities
Purchases of investments ( 3,695.9 ) ( 3,551.3 ) ( 5,460.4 )
Proceeds from sales of investments 1,196.9   956.2   965.9  
Proceeds from maturities of investments 1,594.9   1,852.6   2,811.5  
Business acquisitions, net of cash and restricted cash acquired
( 1,054.4 ) ( 610.6 ) ( 204.5 )
Purchases of property, equipment, and other assets ( 246.2 ) ( 156.8 ) ( 146.3 )
Net cash used in investing activities ( 2,204.7 ) ( 1,509.9 ) ( 2,033.8 )
Cash flows from financing activities
Repayments of convertible senior notes ( 965.6 ) ( 1,033.7 ) ( 1,692.0 )

Repurchases of common stock —   ( 566.7 ) ( 272.7 )
Proceeds from sales of shares through employee equity incentive plans 370.5   283.9   258.8  
Payments for taxes related to net share settlement of equity awards ( 183.8 ) ( 26.6 ) ( 20.4 )

Net cash used in financing activities ( 778.9 ) ( 1,343.1 ) ( 1,726.3 )
Net increase (decrease) in cash, cash equivalents, and restricted cash
732.4   404.6   ( 982.6 )
Cash, cash equivalents, and restricted cash—beginning of period 1,546.8   1,142.2   2,124.8  
Cash, cash equivalents, and restricted cash—end of period $ 2,279.2   $ 1,546.8   $ 1,142.2  

Reconciliation of cash, cash equivalents, and restricted cash to the consolidated balance sheets
Cash and cash equivalents $ 2,268.6   $ 1,535.2   $ 1,135.3  
Restricted cash included in prepaid expenses and other current assets 10.6   11.6   6.9  

Total cash, cash equivalents, and restricted cash $ 2,279.2   $ 1,546.8   $ 1,142.2  

Non-cash investing and financing activities
Equity consideration for business acquisitions $ ( 27.1 ) $ ( 27.4 ) $ ( 0.3 )
Contingent consideration for a business acquisition
$ ( 648.9 ) $ —   $ —  

Supplemental disclosures of cash flow information
Cash paid for income taxes $ 505.5   $ 342.3   $ 147.1  
Cash paid for contractual interest $ 1.7   $ 5.6   $ 20.2  

See notes to consolidated financial statements.
- 65 -

Table of Contents

Notes To Consolidated Financial Statements

1. Description of Business and Summary of Significant Accounting Policies
Description of Business
Palo Alto Networks, Inc. (the “Company,” “we,” “us,” or “our”), headquartered in Santa Clara, California, was incorporated in March 2005 under the laws of the State of Delaware and commenced operations in April 2005. Our cybersecurity platforms and services help enterprises, organizations, service providers, and government entities to secure their users, networks, clouds, and endpoints by delivering comprehensive cybersecurity backed by artificial intelligence and automation.
Basis of Presentation
The accompanying consolidated financial statements have been prepared in conformity with U.S. generally accepted accounting principles (“U.S. GAAP”). The consolidated financial statements include all adjustments necessary for a fair presentation of our annual results. All adjustments are of a normal recurring nature.
Principles of Consolidation
The consolidated financial statements include our accounts and our wholly owned subsidiaries. All significant intercompany balances and transactions have been eliminated in consolidation.
Use of Estimates
The preparation of consolidated financial statements in conformity with U.S. GAAP requires management to make estimates and assumptions that affect the amounts reported and disclosed in the consolidated financial statements and the accompanying notes. We evaluate our estimates on an ongoing basis. Management estimates include, but are not limited to, the standalone selling price for our products and services, share-based compensation, fair value of assets acquired and liabilities assumed in business combinations, fair value of our contingent consideration liability, the assessment of recoverability of our intangibles and goodwill, valuation allowance against deferred tax assets, valuation of inventory and manufacturing partner and supplier liabilities, deferred contract costs benefit period, and loss contingencies. We base our estimates on assumptions, both historical and forward looking, that we believe are reasonable. Actual results could differ materially from those estimates due to risks and uncertainties.
Stock Split
On December 12, 2024, we effected a two -for-one stock split of our outstanding shares of common stock through an amendment to our restated certificate of incorporation (“Stock Split”), which also effected a proportionate increase in the number of authorized shares of our common stock from 1.0  billion to 2.0  billion. The par value per share of our common stock remains unchanged at $ 0.0001 per share after the Stock Split. All references made to share or per share amounts related to our common stock have been retroactively adjusted on the accompanying consolidated financial statements and applicable disclosures to reflect the effects of the Stock Split.
Concentrations of Risks
Financial instruments that subject us to concentrations of credit risk consist primarily of cash and cash equivalents, investments, derivative contracts, accounts receivable and financing receivables.
We invest only in high-quality credit instruments and our cash and cash equivalents and available-for-sale investments consist primarily of fixed income securities held at large, diverse financial institutions to reduce the credit risk exposure to any single financial institution. Deposits held with banks may exceed the amount of insurance provided on such deposits.
Our derivative contracts expose us to credit risk to the extent that the counterparties are unable to meet the terms of the arrangement. We mitigate credit risk by transacting with multiple major financial institutions with high credit ratings and also enter into master netting arrangements, which permit net settlement of transactions with the same counterparty. We are not required to pledge, and are not entitled to receive, cash collateral related to these derivative instruments. We do not enter into derivative contracts for trading or speculative purposes.
Our accounts receivable are primarily derived from our distributors in various geographical locations. Our financing receivables are with qualified end-customers and channel partners. We perform ongoing credit evaluations and generally do not require collateral on accounts receivable or financing receivables.
- 66 -

Table of Contents

As of July 31, 2025, three distributors individually represented 10% or more of our gross accounts receivable, and in the aggregate represented 44.8 % of our gross accounts receivable. As of July 31, 2025, no end-customers or channel partners represented 10% or more of our gross financing receivables.
For fiscal 2025, three distributors represented 10% or more of our total revenue, representing 18.8 %, 14.4 %, and 11.0 % respectively. No single end-customer accounted for more than 10% of our total revenue in fiscal 2025, 2024, or 2023.
We rely on an electronics manufacturing services provider (“EMS provider”) to assemble most of our products and sole source component suppliers for certain components.
Comprehensive Income
Comprehensive income is comprised of net income and other comprehensive income. Our other comprehensive income includes unrealized gains and losses on available-for-sale investments and unrealized gains and losses on cash flow hedges, net of tax effects.
Foreign Currency Transactions
The functional currency of our foreign subsidiaries is the U.S. dollar. Monetary assets and liabilities denominated in foreign currencies have been remeasured into U.S. dollars using the exchange rates in effect at the balance sheet dates. Foreign currency remeasurement gains and losses and foreign currency transaction gains and losses are not significant to the consolidated financial statements.
Fair Value
We define fair value as the price that would be received from selling an asset or paid to transfer a liability in an orderly transaction between market participants at the measurement date. When determining the fair value measurements for assets and liabilities which are required to be recorded at fair value, we consider the principal or most advantageous market in which to transact and the market-based risk.
We categorize assets and liabilities recorded or disclosed at fair value on our consolidated balance sheets based upon the level of judgment associated with inputs used to measure their fair value. The categories are as follows:
• Level 1—Inputs are unadjusted quoted prices in active markets for identical assets or liabilities.
• Level 2—Inputs are quoted prices for similar assets and liabilities in active markets or inputs that are observable for the assets or liabilities, either directly or indirectly through market corroboration, for substantially the full term of the financial instruments.
• Level 3—Inputs are unobservable inputs based on our own assumptions used to measure assets and liabilities at fair value. The inputs require significant management judgment or estimation.
Our financial assets and liabilities that are measured at fair value on a recurring basis include marketable securities, derivative financial instruments, and contingent consideration liability. Goodwill, intangible assets, and other long-lived assets are measured at fair value on a nonrecurring basis, only if impairment is indicated. Certain certificates of deposit, time deposits, and overnight sweep accounts recorded in cash and cash equivalents and short-term investments are stated at their carrying amounts, which approximate fair value due to their short maturities. The carrying amounts of accounts receivable, accounts payable, and accrued liabilities approximate fair value due to their short-term nature.
Cash, Cash Equivalents, and Investments
We consider all highly liquid investments with original maturities of three months or less at the date of purchase to be cash equivalents. Investments not considered cash equivalents and with maturities of one year or less from the consolidated balance sheet date are classified as short-term investments. Investments with maturities greater than one year from the consolidated balance sheet date are classified as long-term investments.
We determine the classification of our investments in marketable debt securities at the time of purchase and reevaluate such determination at each balance sheet date. Our marketable debt securities are classified as available-for-sale. Debt securities in an unrealized loss position are written down to its fair value with the corresponding charge recorded in other income, net on our consolidated statements of operations, if it is more likely than not that we will be required to sell the impaired security before recovery of its amortized cost basis, or we have the intention to sell the security. If neither of these conditions are met, we determine whether a credit loss exists by comparing the present value of the expected cash flows of the security with its amortized cost basis. An allowance for credit losses is recorded in other income, net on our consolidated statements of operations for an amount not to exceed the unrealized loss. Unrealized losses that are not credit-related are included in accumulated other comprehensive income (loss) (“AOCI”) in stockholders’ equity.
- 67 -

Table of Contents