Search Company
Review management commentary and the analyst Q&A from PANW's Q4 2026 earnings call. Use the transcript to track changes in demand, guidance, operating priorities, and the KPIs behind the company's reported results.
Hamza Fodderwala: Good day, everyone, and welcome to Palo Alto Networks fiscal fourth quarter 26 earnings conference call. I am Hamza Fodderwala, senior vice president of investor relations and strategic finance. Please note that this call is being recorded today Tuesday, 09/01/2026 at 01:30PM Pacific time. With me on today's call to discuss our fiscal fourth quarter results are Nikesh Arora, our chairman and chief executive officer and Dipak Golechha, our chief financial officer. You can find the press release and other to supplement today's discussion on our website at investors.paloaltonetworks.com. While there, please click on the link for quarterly results to find the Q4 26 supplemental financial information and Q4 26 earnings presentation. During the course of today's call, we will be making forward-looking statements and projections regarding the company's business operations, and financial performance as well as the company's recent acquisitions. These statements made today are subject to a number of risks and uncertainties that could cause our actual results to differ from these forward looking statements Please review our press release and recent SEC filings for a description of these risks and uncertainties. We assume no obligation to update any forward looking statements made in today's presentation. This presentation also contains non GAAP financial measures and key metrics relating to the company's past and expected future performance, non GAAP financial measures should not be considered a substitute for financial measures prepared in accordance with GAAP. The most directly comparable GAAP financial metrics and reconciliations are in the press release and the appendix of the investor presentation. Unless specifically noted otherwise, all results and comparisons are on a fiscal year over year basis. I will now turn the call over to Nikesh.
Nikesh Arora: Thank you, Hamza. Good day, everyone, and thank you for being with us to discuss our progress. As you can see, our execution fueled record finish to the fiscal year. We exceeded our guidance across every financial metric in Q4, with bookings momentum accelerating for the second straight quarter. This performance is a direct result of record breaking platformization adoption the growing urgency among customers to fortify their defenses, as AI fundamentally redefines the security landscape. We achieved record RPO, surpassing the $20 billion threshold for the first time, to close the year at $21.2 billion representing a growth rate of 34%. And GSARR reached $9.1 billion, up 63% enabling us to report 1 of our most substantial next generation security ARR performances to date. Most notably, we added nearly $1 billion in net new NGS ARR this quarter alone. I remember my first analyst day in 2019, shortly after I arrived, we set a high bar to reach $1 billion in next generation security revenue by fiscal 22. Just as we were initiating our pivot from a single product firewall vendor at a unified security platform. That transformation journey has reached a pivotal inflection point and the scale of our current success is a testament to that vision. We delivered broad based strength across our platforms in Q4. With network security, our largest business reporting exceptional results across SASE, software, and hardware firewalls. XSIAM, maintained its strong momentum while Prisma AIRS achieved a significant milestone surpassing $100 million in ARR within 4 quarters of general availability. This represents the fastest scaling product in the history of Palo Alto Networks. Fiscal 26, marked a pivotal inflection point in our transformation journey. We closed the 2 largest acquisitions in our history, with CyberArk and Chronosphere. Both of which are exceeding our initial expectation. Both businesses are gaining significant traction within our platformized architecture and are scaling at an accelerated pace compared to their previous standalone performance. These achievements are a testament to the execution and deep collaboration of the thousands of new colleagues who joined us this past year. We look forward to continuing this shared momentum into FY 27. Q4 was the very first quarter in which we witnessed the profound implications of cyber capable models. As I have said before, AI is a long term tailwind for cybersecurity. While these models are becoming increasingly proficient at uncovering vulnerabilities, detection is merely the opening act. Truly validating interpreting context, and resolving these issues requires broad cybersecurity platforms working alongside Frontier AI. This synergy is essential for stress test environments manage agentic actions, and trigger machine speed remediation during an active threat. Defending at that speed necessitates a unified data architecture where AI processes every signal collapsing response times from days to just minutes. Platformization is the only viable strategy for real time defense. Fighting AI with AI. And that philosophy continued to get significant resonance with our customers in Q4. During the fourth quarter, we achieved approximately 22 net new platformizations, surpassing our prior record representing more than twice the volume from when we initiated this metric 2 years ago. The performance validates that our philosophy of real time defense through a unified architecture continues to gain significant resonance. Beyond initial adoption, standardizing our platform yields superior retention and expansion, with NRR, or net revenue retention, exceeding 120% for our platformized cohort in Q4. As we look forward, we remain on track towards our long term objective of over 4 thousand platformizations by fiscal 2030, which serves as a bedrock for reaching our $20 billion next generation security ARR target. Our largest Q4 wins show a platformization in action, During the fourth quarter, we secured a $126 million agreement with the global telecoms leader This organization moved to standardize on our network security platforms, bolstering their next generation firewall footprint while displacing legacy proxy providers with Prisma Access for SASE. We also closed a $72 million transaction with a premier IT service provider This client has fully embraced platformization across network security, Cortex, and Idira, making 8 figure investments in each serving as a powerful validation of our cross sell momentum in Q4. A further highlight, a $53 million platformization deal with the leading global payments platform. Beyond standardizing their network defense and architecture, they committed high 7 figures to Prisma AIRS as they accelerate their enterprise AI initiatives. Fiscal 26 has emerged as a landmark period in the rapid evolution of AI. Marked by 3 distinct inflections over the last 6 months. Each of these shifts fundamentally redefines how AI interacts with the enterprise, and by extension, how it impacts the cybersecurity landscape. For us to effectively lead and protect our customers, maintaining our position as a vanguard of these structural changes is paramount. The first inspection was the arrival of OpenClaw. Earlier this year, OpenClaw served as the catalyst for the transition from standard LLMs to agentic action. Fundamentally altering the dynamic between human operators and AI systems. Just a year ago, AI was largely defined by individual human prompting, a synchronous, multi-turn dialogue where a task was completed with a person in the loop. Virtually overnight, we witnessed the emergence of fully autonomous agents, These are persistent entities that operate for extended durations executing complex workflows without direct supervision. For a single employee once managed 1 task at a time, that same individual can now orchestrate thousands of autonomous agents. The implications for the enterprise are profound. Each of these agents generates continuous traffic, interacting with models, creating internal data, and communicating with other tools and agents around the clock. This creates a massive volume of telemetry that must be observed while every agent requires its own set of credentials. We are now securing a whole new castle of machine identities with autonomous permissions. This surge in traffic data, and identity complexity represents a significant long term tailwind across every 1 of our platforms. The second was a Mythos moment. Which proved that deep domain training enables AI to achieve unprecedented proficiency. In our sector, this is manifested as the weaponization of AI to identify and exploit vulnerabilities at scale. This shift has exposed the deep technical debt within the enterprise, where legacy flaws and persistent misconfigurations that once took months for a human to uncover, are now exploited in minutes. In an AI-driven threat environment, there is no longer anywhere to hide. For our customers, the mid sized moment reframed the security challenge from visibility to velocity. Organizations must now identify exposures before they are weaponized and respond at machine speed. This is why real time defense has shifted from a future roadmap item to a present day requirement. To address this, we expanded our Frontier AI Defense Service last month, introducing a multimodal harness that enables enterprises to stress test their environments. This service leverages the most sophisticated cyber capable models available, and we are proud to be the first certified commercial partner for Mythos 5. The third, involves an emerging inflection point that we expect will dominate the cybersecurity dialogue in the coming quarters. For the past 90 days, the market has moved beyond a handful of frontier models towards a diversified ecosystem of open weight, and open source architectures. Enterprises are increasingly prioritizing sovereign control over their AI. Leading to the deployment of specialized models deeply integrated with proprietary data. We expect a major acceleration as organizations utilize internal telemetry to fine tune models for bespoke enterprise use cases. While frontier models will continue to set the high watermark for intelligence, the broader market is heading towards rapid fragmentation and proliferation. Crucially, each new deployment adds more infrastructure to fortify and more sensitive data to protect. The surface area requiring platforms protection is expanding dramatically. 3 pivotal moments each with a unique impact, yet all leading to a single conclusion. As the relationship between humans and AI evolves, and deployments multiply, the necessity for unified real time defence has never been greater. It is early days, but we are beginning to see the signs of how these trends are impacting our business. Starting with our largest business, network security. AI represents a significant long term tailwind that is expanding our total addressable market in network security while reinforcing that platformization is the only viable strategy for the modern enterprise. As the global AI build out continues, every new data center becomes critical infrastructure. That requires robust fortification through hardware and software firewalls. Whether delivered natively by cloud providers, or via unified security platform. The ecosystem driving this infrastructure expansion has reached a pivotal inflection point And now we are seeing a new vanguard of buyers emerge, spanning sovereigns, neo clouds, and Frontier Labs. All racing to deploy massive computational capacity that must be secured. We achieved strong early traction with this cohort in FY 26, including multiple 7-figure bookings in the fourth quarter. In total, our firewall execution drove accelerated bookings for the fiscal year fueled by robust demand for latest Gen 5 hardware and the continued momentum of our software offerings as customers scale their cloud and AI workloads. As this infrastructure matures, and autonomous agents are deployed, we expect a dramatic proliferation of agentic traffic across every network and cloud environment. The impact on our SASE platform is already evident. Where agentic traffic has surged 9x over the last 9 months. Defending at the scale requires machine speed inspection. A competence, a core competence we have refined for 2 decades. Enabling us to block more than 30 billion attacks in a single day. Ultimately, AI is underscoring the urgent need for unified platforms that deliver real time defense. In FY 2026, our platform advantage drove exceptional results in our SASE business, where bookings grew 40%, with broad strength across access, SD WAN, and secure browser. We successfully displaced legacy incumbents in nearly 100 accounts representing over $400 million in total contract value, nearly double the volume of displacement from a year ago. Now we have rapidly ascended to the number 2 position in the market. We are playing to win, and remain on a clear trajectory to become the SASE leader in the next 5 to 7 years. 1 of the early chapters of this shift for the future will necessitate securing both human and machine identities through a unified architecture capable of providing defenses at machine speed. Organizations are transitioning AI initiatives from experimentation to full scale production, significantly widening the defensive perimeter with each new deployment. Prisma AIRS, has continuously adapted alongside these adoption cycles evolving to mitigate the unique risk emerging from every phase of the AI journey. While our initial focus addressed the chat box centric era of generative AI, our vision has expanded towards providing a comprehensive architecture for agentic security. This unified approach begins with securing machine identities and credentials incorporates deep observability of agentic footprints extends to the endpoint where we analyze behavioral intent. By funneling this traffic through our AI gateway, ensure that security policies are enforced in real time across every interaction. Prisma AIRS achieved a remarkable milestone in Q4, surpassing $100 million in ARR, within just 4 quarters of general availability. Marking the most rapid scale out of any product in our history. Our momentum is reflected in a growing base of over 800 customers for this product, with the majority of our largest transactions now featuring multi module adoption in Q4. We are also seeing significant early validation of our agentic endpoint strategy following the Koi acquisition. We believe the endpoint is reaching a critical inflection point as AI driven development tools migrate to the desktop environment. This shift creates an expanded surface area where agents autonomously manage files and access sensitive credentials. Legacy security tools often remain blind to the underlying intent and reasoning behind these machine speed actions. In this landscape, visibility without action is insufficient, Our platform wise approach delivers end to end transparency, from the initial prompt to the final execution, enabling in line prevention and machine speed. This capability is becoming a fundamental requirement for the enterprise, They have already secured over 100 logos representing a 2.5x increase since finalizing the Koi integration earlier this year. Ultimately, the synergy of detection and prevention is most effective when unified as a single platform with XSIAM serving as a central nervous system for this critical telemetry. Earlier this year, our Unit 42 researchers demonstrated the staggering speed of modern threats by simulating a comprehensive AI driven attack in under 30 minutes. Contrast that with the industry standard defense report response of 4 days, and it is clear that legacy approaches are no longer sustainable. Customers standardizing on XSIAM are transforming their operation, reducing their mean time to respond to less than 10 minutes. Massively from the days or weeks acquired previously. As we continue our relentless push towards true real time defense. In the fourth quarter, XSIAM maintained its exceptional momentum, concluding the year with over $700 million in ARR, up 70% while surpassing the thousandth customer milestone in the platform. The power of our architecture lies in the fact that live telemetry is already resonant with an XSIAM, allowing us to seamlessly unlock new value through our unified data lake. Expanding a deployment does not require the friction of new product integration, it simply involves querying existing data in new ways. As of Q4, the majority of customers have embraced this platform advantage utilizing multiple modules, including exposure management, and cloud security. Turning to observability, we continue to see the world's premier AI native and cloud first organizations standard on our technology. The entire entities pioneering the AI frontier generate telemetry to scale that traditional tools cannot withstand. Chronosphere has engineered specifically for these massive data volumes capturing every training run-in agent loop. This quarter, we signed a $20 million deal with a hyper growth AI inference provider that processes tens of trillions of tokens a day. This is no longer there is no stronger validation of our platform than when the architects of the AI ecosystem trusts us to monitor their own infrastructure. Since finalizing the Chronosphere acquisition in Q2, our observable ARR has more than doubled eclipsing the $500 million mark. This performance has significantly outperformed our initial targets, and represents the most rapid post acquisition scaling in our history. Our cross sell strategy is delivering tangible results. With XSIAM contributing to 50% of net new cross fit logos this quarter, through multiple 7-figure agreements. We are further enriching the stack with the acquisition of Embrace, integrating real user monitoring to complement our core metrics logs, traces. This expansion enables us to provide a comprehensive end to end observability platform that spans from the core infrastructure to the final user experience. Collectively, XSIAM and observability now represent over $1 billion in ARR. A remarkable achievement for data intensive platforms that were not part of our portfolio, just a few years ago. The cornerstone of our success throughout my tenure at Palo Alto Networks has been our ability to identify premier technology and world class talent, and seamlessly integrate them into our culture. While the complexity of our integration effort naturally increased scale of this year's acquisitions, result has been extraordinary. In Q4, the success was most evident in our performance with CyberArk, or now called Idea. Just 2 quarters after finalizing our largest acquisition date, we are accelerating growth while capturing synergies ahead of schedule. A rare feat that demonstrates the power of our integration engine. These results are a testament to the deep collaboration with our new colleagues from a go to market perspective our joint efforts yielded over 400 shared leads, driving more than 200 net new logos for our installed base. We are also seeing a significant move towards larger commitments with $5 million-plus TCV deals up 50% year over in the fourth quarter. Yet, the most significant challenge and opportunity remains the rise of Agentech AI. By definition, an agent possesses agency. Necessitating and dictating a machine identity with the precise context and permissions required to execute its workflow. As enterprises deploy thousands of these autonomous entities, many remain outside of formal governance, often lacking properly scoped permissions. This summer served as a wake up call as rogue agents compromised environments at several frontier AI labs. In 1 notable instance, an agent escaped its sandbox and exploited system vulnerabilities because its access had never been properly restricted. At its core, this represents a fundamental identity crisis for the enterprise. This is the strategic imperative behind our Idira platform. Idea extends sophisticated identity security privileged controls to AI agents, ensuring every machine action is authorized, scoped, and fully auditable. As we integrate these agentic controls, our AI gateway into Prisma AIRS, we are empowering organizations to enforce security policies and maintain defense in real time. Fiscal 26, was a transformative year for Palo Alto Networks and broader industry, We remain convinced that the AI tailwinds catalyzing cybersecurity demand will only intensify as we look towards the future. First, the global AI infrastructure build out is drawing trillions in investment. We anticipate more capital expenditure in the next 5 years, than the preceding 2 decades. This massive expansion is fueled by demand that continues to outstrip supply. For AI, to deliver on this promise, both traffic and data volume must scale. And has to do every bit requires inspection, and every byte requires observability. This search critical infrastructure is a permanent tailwind for cybersecurity, a trend already manifesting in the accelerated momentum of our network security and observability businesses this year. Second, is the strategic imperative transition towards real time defense. With cyber attacks now operating machine speed, fragmented legacy tools are no longer viable. There is approximately $1 trillion of global cybersecurity debt that must be modernized to defend against automated threats. Because AI operates instantaneously. This modernization must occur on unified platforms. Platformization is the only solution for real time defense, ensuring the telemetry and policy are harmonized across every control point. We are still in the early chapters of the structural change. Third, AI has inaugurated a fundamentally new market for cybersecurity. The rise of autonomous agents will dramatically expand network surface area that requires fortification. Robust governance and security guardrails for AI have shifted from optional features to essential enterprise requirements. While this market is evolving rapidly, we believe the future belongs to architectures providing end to end controls. A vision we are delivering through Prisma AIRS. Lastly, I do wanna mention in breaking news, we closed our acquisition of console today. Console brings an AI first approach to product development in the IT and security operations space. Andre and his team are going to work as part of our Cortex effort to identify our capabilities and drive us faster into the AI era. I want to welcome both the Embrace and console teams acquisitions as we close this quarter to Palo Alto Networks. As we move into fiscal 27, significant momentum we understand that our continued leadership must be earned through disciplined execution every quarter. I want to express my gratitude to our employees, for their performance during this milestone year, to our customers for their enduring partnership. With that, let me hand it over to Dipak.
Dipak Golechha: Thank you, Nikesh, and good afternoon, everyone. We delivered a strong close to a record year. Driven by the broad based strength across our platforms and the early results of our integration efforts. Our teams executed with discipline, and we exceeded guidance across every metric. Before walking through the details, please note that I will be speaking to our results both on a reported and a pro forma basis to provide a normalized growth comparison where applicable. All growth percentages will be on a year over year basis unless stated otherwise. Starting with the top line, Q4 RPO exceeded $20 billion for the first time. Ending the year at $21.2 billion, up 34%. Our bookings growth accelerated for the second consecutive quarter on a pro forma basis. Driven by the success of our platformization strategy. Current RPO reached $9.3 billion also up 34% as contract durations remained steady year over year. We also delivered a record result in NGS ARR, which reached $9.1 billion in Q4 up 63%. As Nikesh highlighted, most notable was the nearly $1 billion of net new NGS ARR in Q4 which almost doubled year on year, and is a milestone that only a select category of technology companies have ever achieved. I still recall my first quarter as CFO in Q3 of fiscal 21, when we surpassed $970 million in total NGS ARR. We have now added approximately that amount in a single quarter. that is a testament to the multiple growth drivers in our business. 5 years ago, SASE was still in its infancy, and XSIAM had not yet launched. Today, those have either surpassed or are approaching $1 billion ARR businesses. To provide more visibility into our growth drivers, we are introducing new revenue disclosure by platform. As I previewed last quarter. Those 3 platforms are network and AI security, Cortex, and Idera. We have provided historical periods as well as product composition for these platforms in the appendix of our earnings presentation published on our website. Before diving into our revenue by platform, please note that network and AI security includes the certificate lifecycle management business we acquired with CyberArk. Which has since been rebranded to Next Generation Trust Security or NGTS. NGTS contributed approximately $85 million to network and AI security revenue in fiscal year 26. Additionally, the revenue by platform I will discuss excludes certain items like professional services which are reported in the category titled Other as shown in the earnings presentation, appendix. Lee's start with network and AI security. Our revenue here grew 17% for the full fiscal 26, reaching $8.35 billion in revenue. We continue to deliver above market and double digit growth in network security, which speaks to our strong competitive position and the large market opportunity still ahead of us in our largest platform. As an example, we continue to gain share in SASE, with bookings in ARR growing well ahead of the overall market. Our software firewall business accelerated once again, reaching 29% ARR growth in Q4, and Prisma AIRS surpassed $100 million in ARR within its first year of general availability. Finally, we had another strong quarter in our hardware firewall business, driven by the adoption of our latest Gen 5 appliances. Turning to Cortex, which includes our security operations and observability platform, revenue grew 25% in fiscal year 26, to $1.92 billion in revenue. As noted earlier, XSIAM continues to be a key driver of Cortex, with ARR growing 70% in Q4. On the observability side, our ARR surpassed $500 million and more than doubled since we closed the acquisition of Cronosphere, In Q2. Keep in mind and as we noted last quarter, our Q4 net new ARR includes a 9 figure benefit from a large LLM customer migrating to Chronosphere from an incumbent vendor. Lastly, we have Idea, which consists of our identity security platform from the CyberArk acquisition, closed in early fiscal Q3. As noted earlier, Idira excludes revenue from the certificate lifecycle management acquired from. On a pro forma basis, Idira revenue reached $1.26 billion in fiscal year 2026, and grew 21%. Our bookings grew faster than revenue in Q4, which is a testament to our early integration success. And go to market collaboration. In total, our revenue grew 34% to $3.41 billion in the fourth quarter, and for the full fiscal year revenue reached $11.5 billion up 24% year over year. From a geographic perspective, we delivered robust growth across all of our regions. The Americas was up 33% year over year, EMEA was up 39% year over year, and JPAC was up 34% year over year. Moving down the P and L, total gross margin in Q4 was 74.8%, down 100 basis points year over year. For the full fiscal year, gross margin was 75.8%, down 60 basis points year over year. This decline reflects a mix shift towards our faster growing SaaS offerings, which continue to scale with our platforms and have yet to reach their gross margin maturity. Looking ahead, the growing majority of revenue is cloud and SaaS, and we anticipate that mix shift will drive our cloud hosting costs faster than total revenue. In fiscal year 27. Turning to the supply chain, We expect rising commodity costs to persist in our hardware business particularly as it relates to memory and storage. As a reminder, while we are pleased with the strength that we are seeing in our hardware demand, revenue from hardware represents approximately 10% of the total company. We continue to manage our component cost exposure through our strategic supplier relationships, and selective pricing actions across our portfolio of hardware products. Ultimately, our primary focus remains on optimizing the business total operating income, and margin, and this focus was reflected in our Q4 results and our full year results. Q4 non GAAP operating margin came in at 29.6%, and for the full fiscal year, we achieved operating margin of 29.2%, an increase of 40 basis points year over year. This annual expansion is particularly notable as it includes a partial year of our largest acquisitions. Which operated at much lower operating margins at standalone entities. We are making excellent progress on this front, regarding CyberArk synergies, our integration synergy targets remain 3 to 6 months ahead of plan. Looking ahead to fiscal year 2027, we anticipate higher cost of goods sold will be more than offset by continued operating leverage as we scale efficiently and deliver on M&A synergies. Our focus on operating leverage drove Q4 non GAAP EPS of $1.02 exceeding the high end of our guided range by $0.04. Adjusted free cash flow for the fourth quarter reached $1.29 billion growing 35% year over year. For the full fiscal year 2026, adjusted free cash flow was $4.41 billion, delivering a margin of 38.4%, an increase of 40 basis points year over year. As a result of our strong free cash flow generation, we ended fiscal 26 with a robust balance sheet including $7.9 billion in cash, cash equivalents and short term investments. Stepping back, over the past 3 years, we have proven our ability to deliver durable and profitable growth. Our execution has driven over 500 basis points of operating margin expansion, We have achieved this while capturing market share across new categories, driven by our industry leading R&D investment. Our operating leverage has also translated directly to cash flow, Adjusted free cash flow margin has been 38% or better in each of the last 4 years. And we sustain the strong cash flow generation even while absorbing the impacts of large M&A, and as our customers moved increasingly from multiyear to annual billing. This track record of scaling profitably is the bedrock of financial model. It provides us with the ability to neutralize potential cost headwinds, while simultaneously fueling our innovation engine. Our ultimate competitive advantage. And the catalyst for our customers' platformization journeys. Looking ahead, we continue to have increasing visibility into our free cash flow. This is being driven by a combination of steady operating margin expansion as well as a smooth transition to deferred or annual billing in our core business. To provide some context, annual billings increased significantly from 6% of bookings in fiscal 2020 to 27% in fiscal 2025. Now we are seeing a steady rise in the percentage of annual billings having increased by low single digits year over year in fiscal 2026, to about 30% of total bookings. With this structural transition now largely stabilized, we have highly predictable, compounding cash engine. Going forward. This cash flow visibility paired with our continued focus on margin expansion, and durable double digit bookings growth, reinforces our confidence in achieving our 40% free cash flow margin target in fiscal 2028. Before we turn to guidance, I also want to step back and frame the growth opportunity ahead. As I mentioned earlier, our industry leading R&D investment over the years has fueled our innovation engine, and expanded our market opportunity into new categories. That ongoing commitment has earned us leadership recognition in nearly every major category that we operate in. What began predominantly as a standalone firewall business is now a platform with multiple billion dollar ARR businesses. And several more approaching that milestone. We continue to remain underpenetrated against our total addressable market, of $340 billion by 2030. We believe that AI will only expand our opportunity while reinforcing the need for platformization and real time cyber defense. This puts us on track to achieve our target of $20 billion in NGS ARR by fiscal year 2030. With that long term framework in mind, let's turn to our Q1 and our fiscal year 2027 guidance. Note that our recently closed acquisitions of Console and Embrace are immaterial to our fiscal year 2027. Guidance. For the fiscal first quarter 27, we expect for Q1, we expect NGS ARR of $9.54 billion to $9.56 billion or 63% growth We expect RPO of $20.8 billion to $20.9 billion or 34% to 35% growth, and we expect revenue of $3.3 billion to $3.31 billion or 33% to 34% growth. Fully diluted share count of 37 to 44 million shares and diluted non GAAP EPS to be in the range of $0.96 to $0.98 per share. For fiscal year 2027, we expect NGS ARR of $11.075 billion to $11.175 billion or 22% to 23% growth We expect RPO of $25.2 billion to $25.4 billion or 19% to 20% growth, and we expect revenue of $14.1 billion to $14.2 billion or 23% to 24% growth. We are guiding operating margin of 29.5%, and diluted non GAAP EPS to be in the range of $4.16 to $4.19 per Fully diluted share count of 844 to 847 million shares and adjusted free cash flow margin of 38%. We have included our typical modeling points in the appendix of our presentation for your review, but I would like to point out a few things. First, as previously mentioned, our fiscal year 2026 net new NGS ARR included a 9 figure benefit from a large LLM, customer migrating to Cronosphere, from an incumbent provider. Our outlook assumes the tail end of this migration will last through Q1 of fiscal 27, and that the net new ARR contribution from this migration will be less than what was added in Q4. This will impact the seasonality of the net new NGS ARR in fiscal 2027 making Q1 larger than normal. We expect 60% to 61% of the net new NGS ARR to fall in the second half of FY 27. Second, while we do not intend to give revenue guidance by platform, we are providing initial modeling points to help you establish the revenue growth trajectory for each of the platforms within the context of our total company guidance. For fiscal year, 2027, we expect network and AI security revenue growth of low double digits year over year. We expect Cortex revenue up approximately 30% year over year, and we expect IDERA revenue of approximately $1.5 billion, representing pro form a growth of high teens to 20%. Year over year. With that, I will turn it back to Hamza for Q&A.
Hamza Fodderwala: Okay. Thank you, Deepak. Please ensure that only 1 question is asked by each analyst. First question will be Robbie Owens, from Piper Sandler followed by Brian Essex from JPMorgan.
Robbie Owens: Gregg. Thank you, Hamza, and thank you guys for taking my question. Question. Nikesh, your prepared remarks spoke to a lot of the tailwinds that you guys are seeing across cyber right now, and I think that was evidence in your booking strength, and you mentioned the second straight quarter of acceleration. But this has been uneven throughout the environment. And, obviously, scaled players and players with breadth of coverage has really mattered here. So to that end, as you look at the new fiscal year, how are you thinking about M&A? How are you thinking about something else that could be transformational to Palo Alto, just given that the market is shifting so quickly? While you have had an ability to take advantage of it, given what you have done in the past, what are you contemplating moving forward? Thanks.
Operator: Robbie, thank you for your question.
Nikesh Arora: I will just send you the names of the company so it makes it easier. I do not have to answer them and stuff. You would appreciate that, right? I would appreciate that. As I always maintain that you know, M and A is not a strategy. M&A is a consequence of stuff that we do from a product development perspective. To give you a sense, if you know, I talked about the 3 major pivots we have seen in AI already in the last 7 months. We have seen people go from LLMs to agents to now open weight models. And every 1 of these technological shifts on the customer side obviously requires a slightly different security architecture. How do you protect these agents? How do you ensure that open rate models are protected, agents do not go rogue? And obviously we have a point of view internally and we are building towards that from a product development perspective. But sometimes, you can get caught flat footed because you are going down 1 path, and suddenly the market shifts elsewhere. This is where I--you know, we have the privilege of looking at the entire cybersecurity landscape and seeing 40 or 50 companies that have been funded in this category, and then you suddenly realize that some other company had the strategy right, and that is when you step in and make an acquisition. So the acquisition happens because you know, they have got a technology trend right and we would rather embrace it quickly and get on that so our customers can have that capability much faster Because honestly, as you can see, after Mythos, what has happened is customers are willing to experiment with a lot of AI implementations, but before they deploy, they want to ensure a robust security harness around it. The most common questions we get are, you know, what do I do about the vulnerabilities that Mythos is going to find in my environment? How do I solve it today and how do I fall out of the long term? Or what happens if we deploy agents and our agents go rogue? How do we make sure our agent does not go running to hugging face?
Robbie Owens: Excellent. Thank you.
Nikesh Arora: Alright. Thank you, Robbie. I will keep your request. I will send you the company's name. As soon as I buy it. I appreciate that.
Robbie Owens: Alright.
Hamza Fodderwala: Thanks for the question, Robbie. Next, we have, Brian Essex from JPMorgan. Followed by Saket Kalia from Barclays.
Brian Essex: Hey. Gregg. Thanks for taking the question. Nikesh, look. it is great to see the acceleration in CyberArk performance. You know, in a only, you know, 200 net new logos from the Palo Alto install base. Would love to get a sense of, you know, what those conversations are like. How big are those deals relative to the rest of the CyberArk platform, and you still have a amount of your installed base. I think a lot of people, you know, focus on cost synergies. They forget about the revenue synergies. You know, how much penetration do you think you can get into your installed base with the CyberArk platform? Thank you.
Nikesh Arora: Look. I am really excited about CyberArk. I think if you look at both ends and you rightfully articulate we have been able to really hit the ground running on the cost synergy side. You have seen there our margin is reverting back to what our stand alone margin was in just about 2 quarters. And, you know, we think we will be at a stable point coming into the next quarter. So to be able to transform a large company like CyberArk in 9 months, and get their margins up by 1 thousand basis points or more, is already good work on the cost side. But like you said, we did not buy it for cost synergies. We bought it because we felt there is a need in the market for identity security, and this was an inflection point. I think the phase 1 from our perspective was do not break it, accelerate their momentum. And you have seen we have begun we have been able to do that. We used to hire a new leader. Last quarter, Sunny Singh, he is right now in our sales conference in Asia. Rallying the troops and CyberArk. The team has taken really well to joining Palo Alto. there is been phenomenal collaboration between the 2 teams. I am excited. We just launched a new product called Modern PAM. So CyberArk was in traditional PAM. Modern PAM is a expansion category for PAM. Something they had not spent a lot of time on before. The product team at CyberArk has been, or idea and I should say, has been amazing at being able to embrace it, That product is generally available now. We expect to try and upgrade all of the existing traditional WAM customers to that. there is a lot of activities we have going on in both on the up sell and expansion side as well as the net new sales side. So as long as we can run at a faster growth rate than 1.1 thousand basis points. I think that is a phenomenal acquisition for us. Not to mention that they have a pole position in being able to help with nonhuman identities and agents going forward because that is a whole new field where there is no established leader.
Brian Essex: Got it. Very helpful. Thank you.
Hamza Fodderwala: Alright. Thank you, Brian. Next, we have Saket Kalia from Barclays followed by Fatima Boolani from Citi.
Saket Kalia: Okay, Gregg. Hey, guys. Thanks for taking my questions. Great finish to the year. Nikesh, maybe for you. You know, you said that Mythos is not a moment. But it is rather the beginning. And so maybe the question here is, how are you seeing buying behavior change as the AI threat becomes the new normal? And what I mean by that is do you see more of a willingness to platformize? Do you see more pipeline growth than you would expect? Do you see more appreciation for value, less sensitivity in pricing? I guess I am just curious if you can translate this new beginning to some of the deal dynamics that you saw in the quarter. Or the last couple of quarters.
Nikesh Arora: Please make sure the suites show up at Hamza's house. The week before. Otherwise, you will not get your first spot to ask questions in the future. So in terms of the momentum, look, I did say, Mitra, since the beginning because what is happening is I have been I have strived for 8 years to go and get CEO's interest in cybersecurity. I could not. But Dario did a phenomenal job by having Mythos because every CEO now wants to talk about what does this mean to us, how do we get access to it, how do we test ourselves, from a vulnerability perspective? But, you know, they are wise. They sit down and say, listen, I get it. That this is the new normal. People will be able to find vulnerabilities much faster. How do I solve this problem in the long term? that is really where the conversation starts about the only way to solve this problem in the long term is if something escapes past your perimeter, you have got to find it quickly and shut it down. That talks about modernizing their cyber estate. That talks about platformization. That talks about having an AI driven SOC. So that is why we are been able to have so many conversations around the modernization of infrastructure. And every conversation is not about fragmenting their estate and buying yet more smaller vendors. it is more about finding a consolidated way of sort of standardizing our platform evaluating a platform. I think this is a big tailwind for the larger players in the in the sector. I do not think this is a moment where you know, you will see, obviously, startups with some unique products, Nish, products which they are able to bring to market faster, which customers will use in the interim. But I think this is definitely a long term, I would say, duration changing trajectory change to our growth rate. Because you think about it, you know, open source models are now already able to compete with the capabilities of Mythos, and this thing is going to get better not worse. If that happens and this capability becomes commonplace, we have a short window to get all the cybersecurity technical debt, which has not been paid over many years, back to up to the mark. And I suspect there will be some major breaches over the coming years because customers have not been able to get their transformation act in place, and that is generally going to be a tailwind for all of us in this space.
Saket Kalia: Very helpful. Thank you.
Hamza Fodderwala: Thank you, Saket. Next, we have Fatima Boolani from Citi followed by Matthew Hedberg from RBC.
Fatima Boolani: Thank you for taking my question. Nikesh, you brought up this concept of technical debt. So I wanted to zoom out and ask you a question in the context of something you announced earlier. This week or a couple of weeks ago, Frontier AI Critical Defense. So 1 thing we have not necessarily heard you talk about is this notion of operational technology, and the use case here. Potentially gaining critical mass and especially in the context of your own platformization strategy. So now that we know what the models are capable of in terms of insane vulnerability chaining against a part of your technical environment that has historically been underinvested in, again, with a lot of technical debt. What are some of the gating factors here still for you to be able to accelerate wallet capture? And then relatedly, how does that cooperation versus competition continuum with some of the frontier lab partners that you have? Get expressed in this market opportunity with OT that seems like it would be ripe for more capture.
Nikesh Arora: Fatima, a lot of questions in there. Look, first and foremost, I think 9 months ago, we were all guilty and convicted of near death. Cybersecurity and software because at Frontier I was going to eat all of our lunch and breakfast and dinner. Clearly, the last 6 to 9 months, it is become apparent that not happening. We are all going to be enjoying this feast together. And we have seen both OpenAI and Anthropic and even Google come to the table in terms of partnerships, We have early access to these models. We are able to test them. We are able to test their cybersecurity capabilities. As I said in my prepared remarks, we were the first or are the first commercial partner allowed to use Mythos as part of our testing harness. We already use OpenAI 5.0 as part of our testing harness. Are able to bring multiple models to customers. Because, you know, the customers are quickly disenchanted from this notion of finding more vulnerabilities. They wanna know what do I do about them. The last thing they want is more security problems. They have enough already. So the conversation is quickly shifting from what do I do about this And in that conversation is where the need for platforms, as I was mentioning earlier, comes up. In terms of OT specifically, I think the challenge even more pronounced because OT is hard to patch. Even if you found a vulnerability in an OT, instance or deployment, you know, imagine patching an oil rig out in the ocean, or imagine patching a bunch of technology which does not have remote cannot be remotely patched. You would have to go there and fix it. The good news is Lee is not here this week, so I am gonna do Lee right now. So we have actually built a capability where we could build signatures for OT vulnerabilities and open source vulnerabilities and deploy them in under 4 hours. So we can find an open source vulnerability, an OT vulnerability, deploy the fix in 4 hours, and propagate that to our software and hardware firewalls, so that it will stop the bad actors in their tracks. Which is a far cry from the current standard of 55 days Saket, 55 days to patch open source vulnerabilities, or OT vulnerabilities. In the wild. This will allow our customers to have the ability to block the bad actors for any network related OT or open source vulnerability in under 4 hours. So it is a good thing you asked me what the gating factor was. The gating factor is really the customers taking the time to understand what major changes do they need to make, you know, doing POCs, assessing what the environment looks like, thinking about who they want to deploy, then eventually getting down deployment. This is not something customers are they take their time to go do the deployment. that is why I think it is a long term tailwind, and you will start seeing that in constant overperformance in the industry on a quarterly basis, but it is not going to be, you know, coding agent style ARRs that we are seeing in the AI space. Which I am envious of.
Video: But yeah. Good Lee answer, but not good sideburns. Lee's sideburns. Well, you know, that is easy to fix.
Hamza Fodderwala: Okay. Thank you, Fatima, for the questions. Next, we have Matthew Hedberg from RBC. Followed by Michael Turrin from Wells Fargo.
Matthew Hedberg: Thanks, Hamza. Nikesh, you guys have a long standing vision of being the number 1 vendor in a category I mean, you do not enter a market unless you think you could be the share leader. And so I guess putting Lee's hat on again, you have had a lot of success obviously in observability with stand Chronosphere. You added Embrace, synthetics or you developed synthetics. You know, where are you from a functionality perspective now versus some of the historic market leaders there? And how much of this is share shift versus just, like, this market's just getting bigger with AI, and we think we can take a lion's share of it.
Nikesh Arora: Well, look. The premise of Chronosphere has been that it was designed for the AI era. It is a net new technology. The premise of Chronosphere is that because of the large volumes of data that are being sort of you know, spit out in the observability space. It is designed as a architecture that allowed you to have a lower total cost of ownership. So Chronosphere is on average 30% or 40% cheaper than any of the leading incumbent observability solutions out there. From a parity of capability perspective, you know, we started off being very good from an AI native perspective from traces, logs, and metrics. So a majority of Chronosphere's customers are AI native customers, including a very large frontier AI lab. With the absorption of Embrace and the development of synthetics, that will put us at par with some of the leading players on a cross sort of capability perspective, which allows us to go after the enterprise space. So that will allow all the Palo Alto sellers to start selling for now we are restricting Conosphere just to AI native sales because it is where it is more suited. But I expect the next 6 months, we will get to a point where Chronosphere will be a competitive product in its category vis a vis other enterprise players And then we have both an AI first capability as well as cost So that should allow us over time, as the space normalizes, to have a multibillion dollar ARR business. Very excited. it is, you know, it is we bought it when it is $85 million ARR. it is already crossed $500 million ARR. Know, we can clearly see line of sight for that to keep getting bigger. Over the next few quarters. And then hopefully, address the enterprise market with it as well. Because remember, for us to reach our aspirations of a bigger business, we need to have multiple multibillion dollar ARR businesses. Observability is such a TAM. SIM is such a TAM. And obviously, a network security business and identity business are similar TAMs.
Hamza Fodderwala: Thank you. Thank you, Matthew. Next, we have Michael Turrin from Wells Fargo followed by Gray Powell from BTIG.
Michael Turrin: Thanks very much for taking the question. Great close to the year. Maybe just on the initial fiscal 27 guide, I am curious how you approach that exercise given the inflection points taking shape across cyber. You mentioned 3 major AI inflections you have seen formed, and we are so early in the overall 2027 cybersecurity budget discussion. So maybe just walk us through what you are assuming as a baseline and any key drivers of up you see on the horizon we should focus on as well? Thank you.
Nikesh Arora: Michael, we take the guidance very thoughtfully. And we look at where you are from a consensus perspective. We make sure we look at the underlying business plans of our businesses. Evaluate if we are able going to be able to meet beat, or exceed your consensus, We are delighted to see that we expect with our execution and the tailwinds, we are going to be able to exceed your consensus. And that is how we guide.
Dipak Golechha: it is very clear. We look forward to that. Go ahead, Dipak. Yeah. No. I think, Michael, look, we do look at a lot of different inputs If I just look at a number of the different trends, we will look at what is happening to pipeline, Are we seeing traction? Do we see a trend? Terms of what is going on with some of the new areas that we have We take all of that, ingest it all, look at the resource requirement, required territory planning, etcetera, etcetera. And that is effectively how we do it. it is a pretty well established well-honed process. I would not say much has changed, from a process point of view. In the in the last 5, 6 years that I have been here as the as the CFO and I think we have been pretty you know, pretty transparent and there have been a number of inflection points that we have been able to kind of capture within our forecast. Criteria.
Michael Turrin: Thank you.
Hamza Fodderwala: Alright. Thank you, Michael. Next, we have Gray Powell from BTIG followed by Meta Marshall from Morgan Stanley.
Gregg Moskowitz: Great. Thanks for taking the questions, and congratulations on the really strong results. So I just want to make sure that I was looking at it correctly. I think last quarter you called out $200 million in competitive SASE displacements for the last 9 months. This quarter that number jumped to $450 million So I just want to make sure that those are comparable with statistics because if so, you had a really big Q4. Either way, what is either way, the numbers are impressive. what is driving the improved pace of displacements and just overall strength in SASE relative to peers?
Nikesh Arora: Well, I think the number is 400. I remember correctly. 54? Okay. it is 54. Good. Well, clearly, we had a good Q4. that is evident in our numbers. So, yes, we did have a good Q4. Look. The displacement is a consequence of 2 events. 1, when SASE as a category came about early, it was a very Internet driven phenomenon. It was Internet access driven, But COVID changed all of that. When we hit the COVID mark, people wanted sort of access consistently both to the private access as well as Internet access, which is where we come from. We come from a private access space. And obviously, our product on the Internet access space is now at par or far exceeds the competitive landscape we have in front of us, is really the sort of integration of SASE with SD WAN, which we were early in. We were the first player to go acquire CloudGenix, integrated that into a SASE fabric. Having our SASE fabric be consistent with our hardware and software firewall fabric, allows our customers who use Palo Alto firewalls to actually gravitate towards our SASE solution as opposed to elsewhere. And not just that, it also makes it an easier choice if they are looking to consolidate and have 1 platform, because they already are using our consoles, our Stata Cloud Manager, our services, for the hardware and software firewall use case, then it does not feel like a big sort of change or to go adopt us on the SASE front as well. Because they already also have our agents in many cases, which do the VPN product, is now a consistent agent with SASE. So we have surrounded the SASE sort of incumbents with effectively a complete platform where the choice of the standardization or platformization is a simpler choice for them if they choose to just replace the SASE piece because they already have the other elements from us. So sometimes it is that. Sometimes it is just you know, perhaps customers want to modernize their SASE infrastructure.
Gregg Moskowitz: And just to clarify, it is Like, it was 200 year-to-date at Q3, and it is $4.50 for the full year.
Nikesh Arora: Alright. So it is a pretty big number for Q4. Thank you.
Gregg Moskowitz: That all makes a lot of sense.
Hamza Fodderwala: Okay. Next, we have, Meta Marshall from Morgan Stanley. And our last question will be Brad Zelnick. From Deutsche Bank.
Meta Marshall: Great. Thanks. Nikesh, you were mentioning this addressing of the $1 trillion of technical debt. You know, platforms can help enterprises pay for that in some ways. But just how do you think either about ways that you can help them in terms of professional services, investment, or other things that can help from just speeding up the amount of technical debt they can address in a compressed period of time. Thanks.
Nikesh Arora: So as you know, Meta, a few years ago when we launched the platformization strategy, we have had very clear models in the market where we are willing to take staggered payment or align their contracts or deploy before their existing vendor has to be replaced to drive faster platformization. So we make all that available. Honestly, the constraint that you always run into it, the customers always have a full deck. They are already working on a series of things that they would like to get done in their enterprise. And today, with AI, there is a very large contingent of AI transformation that is out there People want to transform customer support. They want to go do coding. on an aggressive basis, they want to deploy LLM. So this is yet another priority that must be managed in the context of that overall priority. So it is just a balance that customers strike. that is why they do not go whole hog and say, let's go replace everything tomorrow. They do sit down and say, let's have a more cohesive and intelligent transformation plan. As a transformation plan, it is going to take 5 years, it is too long. You gotta get it done sooner. So typically end up in the 1, 2, 3 range, but it is not something that gets done in 1 quarter. And they wanna sort of crawl, walk around. They wanna get some stuff done as other vendors sort of fall off their sort of end-of-life periods or their contracts are up for renewal. So all I can say is the desire to standardize or platformize on larger vendors where products are at par or better than the state of the art of the market is becoming more and more of a trend, and that is generally in our favor.
Meta Marshall: Great. Thanks.
Hamza Fodderwala: Thank you, Fatima. And last but certainly not least, we have Brad Zelnick from Deutsche Bank.
Brad Zelnick: Wonderful. Thanks very much, Hamza. Nice to see everybody. Nikesh, you have strong credibility doing M&A at this point, and today's console acquisition seems directionally consistent. With moving closer to autonomous security operations. And I could ask the simple 'why console, but if you fast forward 5 years and Palo Alto has succeeded beyond your wildest expectations, what is the most valuable activity that customers have completely stopped doing themselves because Palo Alto Networks is doing it for them.
Nikesh Arora: it is a great question, Brad. I think that is why I know why Hamza saves you for last. So if you believe that we are going to spend $5 trillion of CapEx in the next 5 years building data centers and AI capability, I have to believe AI is going to be adding tremendous value to our lives in the enterprise space. Otherwise, it makes no sense to deploy $5 trillion in the ground. So I am an optimist and believe that we will be using a lot of AI to do a lot of agentic tasks. And if that is true, cybersecurity has to become less manual and more agentic and more done by us than the customers themselves. Because the bad actors will be using AI from their angle. Which means we have to make sure our customers are as agentified or AI fied as the bad actors are. Now that is not possible as you are discovering in every industry category You cannot deploy AI effectively until you have the right data in place. The right training data, the right data, have to break the silos and have things talk to each other. Now that leads itself towards a cohesive unified data lake of some sorts, whether it is an enterprise IT data lake, observability data lake, a security data lake. If you see strategically where we have been pivoting the business over the last 2 or 3 years, is we are a very data first company. Now we ingest a lot of data on XDR. We ingest 19 petabytes a day. In the SIM product already, and we have just barely north of 1 thousand customers. We have observability data, which is now the data of an entire Frontier LLM. That is being ingested to provide them observability. So we are becoming a data oriented AI first cybersecurity company. Our aspiration is to reduce the amount of human intervention in the act of detection, prevention, and remediation in the cyberspace. So if you would ask me what is that north star, that is our north star. Question is how do we get there? And that is where the whole company is focused in trying to get there. So 5 years from now, if we were far exceeding our expectations of ourselves, I would be able to walk in to a company and say, you wanna replace x? Guess what, I have agents that can understand your deployment. My agents will replace that product, and I can do that in under a week. And when I deploy my product, you are gonna need a lot less people and our products will actually just look for validation from you and get the task done without having you to get into the nitty-gritty of how to configure things, what policies to write. Because we have seen that across thousands of instances, and we can bring that intellectual knowledge to bear. Today, if you look at enterprise products, every enterprise product starts dumb for the next customer. Despite being deployed for 100 thousand customers. I think AI gives us the opportunity of learning from the multiple deployments we do the multiple customers we have, and show up more intelligent for the next customer every time. that is the aspiration we have.
Brad Zelnick: Makes sense. Thank you.
Hamza Fodderwala: Thanks, Brad. Alright. That concludes the Q&A portion of the call. I will hand it back to Nikesh for any closing remarks.
Nikesh Arora: Just want to take the opportunity to once again thank all of you guys for being here. Thank our customers, our shareholders, and all of our employees for what was a spectacular FY 26 for Palo Alto Networks.