管理層發言
Good day, everyone, and welcome to Palo Alto Networks' Fiscal Third Quarter 2026 Earnings Call. I am Hamza Fodderwala, Senior Vice President of Investor Relations and Strategic Finance. Please note that this call is being recorded today, Tuesday, June 2, 2026 at 1:30 p.m. Pacific Time. With me on today's call to discuss our fiscal third quarter results are Nikesh Arora, our Chairman and Chief Executive Officer; and Dipak Golechha, our Chief Financial Officer. Following our prepared remarks, Lee Klarich, our Chief Product and Technology Officer and Board member, will join us for the question-and-answer portion. You can find the press release and other information to supplement today's discussion on our website at investors.paloaltonetworks.com. While there, please click on the link for quarterly results to find the Q3 '26 supplemental financial information and Q3 '26 earnings presentation.
During the course of today's call, we will be making forward-looking statements and projections regarding the company's business operations and financial performance as well as the company's recent acquisitions. These statements made today are subject to a number of risks and uncertainties that could cause our actual results to differ from these forward-looking statements. Please review our press release and recent SEC filings for a description of these risks and uncertainties. We assume no obligation to update any forward-looking statements made in today's presentation. Our presentation also contains non-GAAP financial measures and key metrics relating to the company's past and expected future performance. Non-GAAP financial measures should not be considered a substitute for financial measures made in accordance with GAAP. The most directly comparable GAAP financial metrics and reconciliations are in the press release and the appendix of the investor presentation. Unless otherwise noted, all results and comparisons are on a fiscal year-over-year basis. I will now turn the call over to Nikesh.
Thank you, Hamza. Good afternoon, and thank you, everyone, for joining us today for our earnings call. As you can see, our Q3 performance was exceptional, as we delivered a record quarter. Our results surpassed every guided metric, fueled by an acceleration in organic bookings momentum, the sustained tailwinds from our platformization strategy and surging cybersecurity needs as AI transitions from experimental stages to enterprise-wide production. Within our core portfolio, we achieved significant traction in network security and XSIAM, while Prisma AIRS continues to establish itself as the fastest-scaling product in our history. Altogether, we delivered $8.13 billion in NGS ARR during the third quarter, representing 60% year-over-year growth. This is our most significant quarterly outperformance to date and surpassed our guidance. Our RPO reached $18.4 billion, up 36% compared to last year when adjusting for recent CyberArk and Chronosphere acquisitions, both of which are exceeding expectations in the first quarter post close.
Our organic NGS ARR and RPO rose 28% and 22%, respectively. These results are materializing as AI fundamentally redefines the enterprise tech stack, elevating cybersecurity to a mission-critical priority for every organization. Much has been said about Mythos over the last many months. Over the past quarter, frontier AI development reached a critical inflection point. We have entered the era of truly cyber-capable systems where models like Mythos possess the autonomous capability to execute comprehensive attack campaigns from start to finish. This represents a fundamental paradigm shift for the cybersecurity industry. The most critical factor in this transition is speed. When weaponized by adversaries, these frontier models can identify and weaponize vulnerabilities in mere minutes, a process that previously required months of manual effort. Earlier this year, our Unit 42 research demonstrated the acceleration by simulating a comprehensive attack campaign from initial entry to data exfiltration in just 25 minutes.
In contrast, the typical enterprise still requires days to identify a breach. These existing latency gaps are already a concern, but the emergence of these latest models makes them completely unsustainable. We believe this is merely the opening act. As frontier AI development continues to accelerate, we anticipate a 3- to 6-month window before these systems evolve into more sophisticated hacking entities globally. Within a few years, we expect Agentic AI to reach a level of autonomous execution that is truly unprecedented, scanning environments, generating bespoke exploits and orchestrating intrusion campaigns at machine speed without human intervention. That is a trajectory of the modern threat landscape. However, the same technological leap provides a powerful defensive advantage. We evaluated this potential during the quarter, leveraging our strategic partnerships with leading frontier labs.
We utilized early access to their most advanced models to complete the equivalent of years' worth of penetration testing in less than three weeks. This unique vantage point allowed us to introduce Unit 42 frontier AI defense, enabling our customers to fortify their environments against AI-driven attacks. Market reception has been exceptional. With north of 1,200 customers asking to meet us, we have already completed 800 meetings in the last six weeks to help our customers think through their cybersecurity future. These meetings are driving conversations across the platform. In fact, we're already seeing strong interest in our Agentic endpoint security offering since the acquisition of Koi and have already generated interest for over 150 customers. This is critical for securing rising AI coding tools and agents as they proliferate across our endpoints. While identifying vulnerability is a critical first step, true mission-critical production is achieved at run time.
Real-time, in-line defense is the only way to shield even unpatched infrastructure as an attack sequence unfolds. This is where the cybersecurity battle will be won or lost. Countering the next generation of adversaries requires a comprehensive architectural vision that goes far beyond simple large language models. While the capabilities of these frontier systems are impressive, they are not a silver bullet for cybersecurity. We currently see two major structural challenges: First, the prevalence of false positives, with error rates often reaching 25%, forcing manual intervention that destroys the speed advantage of automation. Second, these models always fail at the last mile of complexity, leaving critical gaps in remediation and vulnerability management. In today's threat landscape, the most subtle 1% of novel attack techniques are what lead to the most devastating breaches. For every enterprise, the defensive bar must be perfect, while an attacker only needs to succeed once.
The probabilistic nature of even the most advanced systems leads to inaccuracies. And in a mission-critical environment, the cost of a false positive is simply too high. One wrong enforcement decision can take down a global production network. Just as autonomous vehicles require constant real-time validation, an automated defense must be built on high-fidelity telemetry and battle-tested against every edge case to be mission-ready. An AI model is only as effective as the data it can see. As frontier models become available to everyone, the real competitive advantage shifts from one model to the data fuel. That is why having sensors that sit in line with live traffic is so vital. They provide the telemetry and context needed to outmaneuver bad actors while serving as a critical enforcement point. The logic is simple. The more you integrate, the more you see, the more data you unify. The better the AI performs, the more you inspect your run time, the faster you can stop an attack.
Our global footprint now exceeds 125 million sensors across network, endpoint and cloud, ingesting over 17 petabytes of daily telemetry. This scale creates a powerful flywheel. Every new sensor makes our entire platform more intelligent, which leads to more deployments, more data and even stronger real-time protection. This reality is why platformization is the only sustainable answer. The legacy approach of query-based tools that wait for human reaction cannot keep up with machine-speed threats. We are transforming the industry by consolidating data onto a single platform, reducing breach response times from days to minutes through AI-driven pre-analysis. Point products that silo data and increase latency are becoming obsolete. As the battle moves to fighting AI with AI, we believe Palo Alto Networks is in pole position, and our Q3 results prove that momentum. As AI compresses attack timelines, only a platform that gets smarter with scale can respond fast enough.
During the third quarter, we secured 110 net new platformizations, a figure that includes 20 from our CyberArk and Chronosphere integrations. These strategic additions expand our reach into large addressable markets within identity and observability. Given the fragmented nature of these sectors, they are perfectly aligned with our overarching platformization vision. We concluded Q3 with roughly 2,280 total platformized customers, bolstered by the inclusion of our latest acquisitions. These engagements represent deep architectural commitments rather than simple transactions. When organizations reach this integration milestone, they standardize their infrastructure on our platform, yielding superior long-term retention and expansion. This is reflected in our 120% net retention and single-digit churn rates amongst this cohort. Moving forward, we remain confident in surpassing 4,000 platformizations by fiscal 2030, providing the primary momentum towards our $20 billion target for NGS ARR.
The scale and quality of our customer business this quarter reflect how strategic these platform commitments have become and how customers are increasingly bringing us in to secure their production AI deployments to scale. Let me share a few examples. In Q3, we surpassed $200 million in ARR with a leading frontier AI lab that relies on us for observability across its most demanding training and inference clusters. We expect that to continue to grow next quarter as they complete their migration to Chronosphere. One of our largest Q3 deals was an $80 million transaction with the leading power producer in the United States, an organization in the center of the AI infrastructure expansion. They selected our next-generation firewalls and also adopted SASE to secure a distributed workforce of over 25,000 employees. A global consulting leader signed a deal for over $20 million, selecting Prisma AIRS, our AI security platform, to secure its rapidly growing fleet of AI apps and agents, now running more than 2 trillion tokens per month on our platform.
This was an existing platformized customer who spent several months working closely with us to secure this entirely new frontier. It is also a record Prisma AIRS win and speaks to why our customers partner with us for the AI transformation journey. As AI raises the stakes, these deals further validate our position as a cybersecurity partner of choice. That is particularly notable in our network security business, where we had our strongest Q3 in several years. Our largest business unit, network security, delivered its most robust third quarter performance in years. This momentum underscores the mission-critical role of real-time network traffic inspection as enterprise-wide AI initiatives continue to transition to production. We saw strong growth in hardware, SASE and software firewalls during the period. However, in the early innings, we anticipate that AI will serve as a structural catalyst for deeper traffic inspection requirements.
The initial pace of AI adoption was primarily conversational, but the shift towards Agentic AI represents a fundamental change. Unlike simple chatbots, autonomous agents trigger a massive volume of secondary machine-to-machine interactions, consistently accessing tools and data to complete complex workflows. This creates a surge in nonstop high-volume traffic that must be secured at run time. This evolution directly translates into heightened demand for high-throughput hardware, expanded cloud-based software capacity and the necessity for unified policy enforcement across the entire platform. Our Q3 results featured the strongest hardware performance in a decade, with next-generation firewall booking rising nearly 40% year-over-year. This was supported by our latest Gen 5 appliances and early access in AI data center build-outs. We're seeing early adoption from a new class of buyers, including sovereign infrastructure providers and AI labs, representing a significant new market as deployments move beyond traditional hyperscalers.
A key differentiator for our hardware portfolio remains the strength of our subscription attach, illustrating how customers are standardizing the security stack on our platform. Within our installed base, we currently average more than four subscriptions per device. Our innovation engine continues to expand this opportunity. We now provide 11 advanced subscriptions, including our next-generation trust security, which utilizes CyberArk's certificate management to address emerging compliance standards for shorter certificate lifespans. Palo Alto Networks remains the fastest-growing provider in the SASE market. In Q3, SASE ARR reached $1.6 billion, growing 40% year-over-year as customers prioritize unified protection across hybrid workforces and AI applications. Competitive momentum remains high, with nearly 50 displacement wins totaling $200 million in contract value year-to-date. Secure browser also achieved a major milestone, scaling to 11 million licenses, a fourfold increase that cements its status as a critical control point for the AI enterprise.
Furthermore, software firewalls remain a high-growth pillar of our strategy. ARR rose 25% in Q3, accelerating as organizations expanded their capacity to inspect growing traffic between cloud and AI workloads. As these environments scale, the requirements for high-fidelity telemetry only increase. The carbon architecture approach is driving increased customer growth in Prisma AIRS, which continues to be the fastest-growing product in our history. Organizations are aggressively moving beyond the experimental phase, deploying AI agents and applications to production. This transition creates entirely new mission-critical security demands. We believe we are the first in the industry to embrace AI security platformization — AI security platformization capable of securing and monitoring AI end-to-end. We have effectively doubled our capabilities in this space in just over nine months. Our journey began with securing models and runtime defense.
We then integrated identity security to govern agent access and observability to create agent behavior across complex infrastructure. Most recently, we expanded to Agentic endpoint security as AI tools proliferate across the edge. Our recent acquisition of Portkey marks yet another strategic milestone. As a leading AI gateway processing trillions of tokens monthly, Portkey provides a critical enforcement point to monitor every request to apply real-time policy to agent-to-agent interactions at scale. This relentless innovation has established Prisma AIRS as our fastest-growing product ever, reaching over 300 customers in Q3, tripling our Q2 count, and we have clear visibility towards $100 million in ARR within the next couple of quarters for a product that was not in the market one year ago. Ultimately, securing the AI enterprise generates a massive volume of run-time telemetry. The data is only actionable if processed at machine speed, which is a core mission of our Cortex platform.
XSIAM remains our primary response to the emerging frontier model threat. As attack cycles compress to machine speed, organizations can no longer rely on legacy cloud-based architectures or manual dashboards. Effectively countering AI necessitates a defensive strategy powered by AI. Upon the introduction of XSIAM 42 months ago, we entered the sector as a disruptive innovator, engineering our platforms from the ground up to redefine security operations centers. Today, our platform processes more than 17 petabytes of daily telemetry, a volume unmatched by any other pure-play security vendor. We ended the third quarter with more than $600 million in ARR, representing 100% year-over-year increase across a growing base of 740 customers. The most significant metric, however, is the outcome. The majority of our customers are now responding to threats in under 10 minutes. This is a dramatic reduction from the days or weeks previously required and serves as a blueprint for the modern SOC.
In observability, our Q3 performance was well above our initial expectations. As AI initiatives generate a surge in telemetry, Chronosphere is a purpose-built capability to scale alongside these workloads. Our observability ARR surpassed $300 million this quarter, nearly doubling since our acquisition announcement last autumn. Furthermore, 80% of our net new customer acquisition this year adopted multiple products, reinforcing our platformization momentum. The world's leading AI natives, including two of the top five frontier labs, have adopted Chronosphere, validating our ability to provide observability at AI scale. Beyond our early investments in markets where AI would drive a positive inflection, we also recognized early where AI would overhaul existing security categories. Consider posture management: traditional periodic scanning is insufficient when attack timelines are measured in minutes.
As a result, we proactively transitioned our cloud portfolio from static posture scanning to real-time detection with Cortex Cloud. We're making steady progress and anticipate most Prisma customers will be migrated to Cortex Cloud by the end of the fiscal year. Now as these agents proliferate, every autonomous entity represents a new identity that must be managed, which leads directly to our progress with CyberArk. In our inaugural quarter post close, CyberArk has surpassed our internal benchmarks as we move to execute our unified vision for identity security. Last month, we launched Idira, our next-generation identity platform for the AI-driven enterprise. For years, the industry operated under the Identity Management Fallacy, the belief that you only needed to secure a handful of privileged administrators. In the era of Agentic AI, that distinction has vanished. Every identity, whether human, machine or software agent, now possesses the potential to access sensitive systems at machine speed.
Idira addresses this shift by democratizing modern PAM controls across all users and extending protection to Agentic entities, which represent the primary attack vector of the future. Our execution in Q3 was strong. Joint go-to-market efforts have already initiated approximately 1,000 cross-organization engagements. We have sustained CyberArk's growth trajectory while improving its profitability profile through our integration initiatives. Given our rapid progress, we are now three to six months ahead of our original timeline for converging CyberArk profitability with our own, a milestone we expect to reach within the next 12 to 18 months. This acceleration reinforces our path towards a 40% free cash flow margin in fiscal 2028, which Dipak will talk about more. The events of the third quarter represent a watershed moment for cybersecurity and have elevated our category even higher on the CIO priority list.
Mark my words, Mythos has increased the terminal value of the entire cybersecurity industry. We are identifying several structural catalysts from the AI cycle driving growth across our platform. First, AI creates a massive surge in traffic and connection points requiring real-time inspection. As agents trigger hundreds of secondary actions, network security becomes an indispensable foundation for safe AI adoption. Second, countering machine adversaries requires real-time automated defense. This is a core mission of XSIAM consolidating data onto a single platform, so AI can respond to threats in minutes rather than days. And third, in an environment populated by both humans and agents, identity serves as a primary defensive layer. Because autonomous entities can execute actions independently, securing access via Idira becomes mission-critical. The conversion of these trends validates our platformization strategy.
Managing fragmented data and siloed point products is no longer viable in an AI-driven landscape. A unified platform that gains intelligence with scale is the only path forward. While we're still in the early stages of the shift, we remain committed to innovating ahead of the threat landscape and earning our customers' trust every day. I will now turn the call over to Dipak to discuss our financial results in greater detail.
Thank you, Nikesh, and good afternoon, everyone. We delivered a record Q3 with broad-based demand across our platforms and geographies. We exceeded our guidance ranges across the board, driven by an acceleration in organic bookings growth and outperformance from our recent acquisitions as we made early progress on our integration efforts. Please note that during my remarks, I will discuss results with and without the impact of Chronosphere and CyberArk. The financial impact of our acquisition of Koi, which closed later in the quarter, was immaterial to our Q3 results. Starting with next-generation security ARR. We delivered 60% year-over-year growth in Q3, reaching $8.13 billion. This included $1.63 billion from CyberArk and Chronosphere. We surpassed $300 million in ARR for Chronosphere, our next-generation observability platform. That was an over 50% increase from Q2 and far exceeded our expectations, driven by an existing LLM customer increasing consumption as they continue to migrate from the incumbent vendor.
Excluding the impact of CyberArk and Chronosphere, NGS ARR was $6.5 billion, up 28% year-over-year, and net new NGS ARR was $370 million, up 18% year-over-year. Please note that this excludes ARR attached to our hardware backlog that also reached record levels for a Q3 quarter. We saw notable strength in network security, which is our largest segment and accounts for approximately 70% of our total revenue. All net set factors delivered sustained or accelerating growth in Q3. In SASE, ARR reached $1.6 billion, up 40% year-over-year, more than 2x the overall market growth rate. We have seen a nearly 50% increase in SASE net new NGS ARR over the trailing 12 months, driven by continued scale, strong performance in net new logos and displacement wins. Software firewall showed strength once again this quarter, with ARR up 25% year-over-year, driven in part by the increase in Prisma AIRS and firewall Flex deals.
As Nikesh highlighted, Prisma AIRS continues to be our fastest-growing product ever. We have over 300 Prisma AIRS customers as of Q3, up from just 100 at the end of Q2. As AI adoption grows in the enterprise, we believe AIRS is becoming a foundational infrastructure for secure AI deployment. Turning to remaining performance obligation or RPO. We ended the quarter at $18.4 billion, growing 36% year-over-year. Excluding $1.8 billion from CyberArk and Chronosphere, RPO grew 22% year-over-year, which we believe is a direct result of our platformization strategy, driving deeper customer commitments across our platforms. Current RPO was $8.3 billion, up 34% year-over-year. Excluding the impact from CyberArk and Chronosphere, current RPO was $7.2 billion and grew 17% year-over-year, an acceleration versus 15% in Q2. Total revenue for the quarter was $3 billion, growing 31% year-over-year. Product revenue was $594 million, and total services revenue was $2.4 billion, both growing 31% year-over-year.
As I've highlighted in previous quarters, software and recurring revenue now represents a large and growing portion of this line item. Today, product revenue includes major growth drivers, including software firewalls and Prisma AIRS, SD-WAN and self-hosted identity security subscriptions. As a result, 46% of our trailing 12-month product revenue in Q3 included recurring software revenue, a significant increase from just 22% three years ago. Hardware, which is approximately 10% of our total revenue, delivered its best quarter in a decade, fueled by strong demand for our next-generation firewalls. And we saw early AI data center wins, contributing to record Q3 backlog. Our next-generation firewall bookings grew nearly 40% year-over-year in Q3 as we continue to gain share. AI data centers and AI-driven enterprise networking needs are driving a new market opportunity for us, which could potentially be additive to our long-term growth for firewall appliances.
From a geographic perspective, we saw broad growth across all of our major theaters, with the Americas growing 32% year-over-year, EMEA up 32% year-over-year and JPAC growing 26% year-over-year. Moving down the P&L. Our Q3 strength was not confined simply to our top line metrics as we continue to drive profitable growth across the P&L and executed against our M&A integration strategy. Total gross margin for the quarter was 75.8%. This included services gross margin of 75.1%. We continue to balance services gross margins by driving efficiencies in cloud hosting, whilst the mix shift of our high-growth SaaS offerings increases. Within this, product gross margin was at 78.8%, which was a 40 basis point improvement year-over-year. Turning to the supply chain. We are closely monitoring rising component costs, particularly in memory and storage. Please note that we have approximately 1 million firewalls in the field, and our acquired component volumes are not as significant to some of our peers.
Furthermore, we remain well positioned to navigate these dynamics for the following reasons. First, our higher recurring revenue mix acts as a natural hedge. Hardware today accounts for approximately 10% of our total revenue compared to 20% in fiscal year '21. Second, our vendors view us as a critical infrastructure provider, and we have a track record of leveraging our prior supply chain experience and expertise to mitigate these impacts. This includes evaluating alternative sources of supply and extending purchase commitments with our suppliers. Third, we continue to evaluate further pricing actions. As a reminder, we implemented a 10% price increase on hardware in early April. The impact of pricing and rising component costs are reflected in our Q4 and fiscal 2026 outlook. These dynamics, paired with continued operating efficiency, resulted in non-GAAP operating margin of 21.3% in Q3, flat versus Q3 of '25.
Looking forward, we expect to drive operating leverage as we scale and continue to make progress against our M&A integration plans. In Q3, we made a lot of progress on our integration plans. This was driven by strong execution and collaboration by our teams across every function, including our new colleagues from our recent acquisitions, who have truly risen to the occasion. This is already driving tangible results. Our integration philosophy starts with product and our relentless focus on driving innovation. Just months after closing the CyberArk transaction, we introduced Idira, our next-generation identity security platform. This includes the key innovations Nikesh highlighted, including modern PAM and Agentic identity security integrated with Prisma AIRS as well as deeper integration of identity signals with our core network security and Cortex platforms. Early go-to-market collaboration has also been encouraging, with more than 1,000 cross-organization engagements initiated between the core and identity sales organizations to date.
On the expense side, we're leveraging our combined scale to drive improved cloud hosting economics for the acquired CyberArk business. Post close, we're optimizing our organizations to deliver a unified one-team culture that is future-ready. We are carefully reviewing every single line item across each of our financial statements to drive operating leverage across vendors and functions. This includes streamlining our combined real estate footprint, which includes over 40 new facilities from our acquisitions, to enhancing and fostering collaboration post close. Additionally, we're optimizing our marketing and our IT vendor footprint. To date, we have identified more than 300 IT vendors to streamline and have already dispositioned approximately 20%. All of these factors combined will enable us to hit our CyberArk synergy targets about three to six months earlier than we initially anticipated.
This visibility, paired with our continued operating leverage across the overall company, reinforces our confidence in reaching 40% free cash flow margin in fiscal '28. In Q3, we generated adjusted free cash flow of $910 million, a 57% increase year-over-year. On a trailing 12-month basis, we generated $4.08 billion in adjusted non-GAAP free cash flow. This represents a margin of 38.5%, a 430 basis point improvement year-over-year, even with the inclusion of CyberArk and Chronosphere. We will, of course, have a full year of CyberArk and Chronosphere expenses next year, but these results solidify our continued ability to deliver best-in-class free cash flow margin and enabled us to raise our fiscal '26 guidance. The strong cash flow generation supports our opportunistic share repurchase program. During Q3, we utilized $1 billion to buy back 6.8 million shares at an average cost of $147.69.
We currently maintain $1 billion of remaining capacity under our existing repurchase authorization. Moving to the non-GAAP items. Stock-based compensation increased sequentially to 17% of revenue in Q3, primarily driven by SBC related to our recent acquisitions. While M&A-related SBC will continue to be amortized in future quarters, we expect stock-based compensation as a percentage of revenue to return to pre-acquisition levels on a run-rate basis in approximately 12 to 18 months. Beyond stock-based compensation, our GAAP results also reflect transaction and integration costs from these acquisitions, further detailed in our SFI. These nonrecurring charges resulted in a GAAP net loss per share of $0.22 for the quarter. Our diluted non-GAAP EPS, which adjusts for SBC and one-time items, reached $0.85, which came in $0.05 above the high end of our Q3 guidance. Reflecting on my five years in the seat, I've always maintained that our business model scales well across every line item of our P&L. This financial framework is precisely what allows us to execute our broader corporate strategy from a position of strength.
When you look at our M&A trajectory, we initially proved this execution capability by integrating over 20 tuck-in acquisitions to build out our platforms. Today, we are successfully integrating larger, highly strategic acquisitions, all while driving durable growth and balancing against our profitability commitments. Now turning to guidance. Given the acceleration in our Q3 organic bookings growth, our early progress on M&A integration and the strong Q4 pipeline, we are raising our full year fiscal 2026 guidance across all metrics for both our core and acquired businesses. This quarter and last, we provided a breakout of performance for both our core business and our recent acquisitions. Our intention was always to make this a one-time in nature and move our disclosures closer in line to how we run the business. Therefore, we'll be moving to total company guidance moving forward. Beginning in fiscal 2027, we intend to provide segment-level revenue disclosures across network security, Cortex and identity.
This will align our reporting with how we run the business and our platform strategy post integration. Now let me take you through guidance in detail. For the fourth quarter 2026, we expect NGS ARR of $8.9 billion to $8.95 billion or 59% to 60% growth. We expect RPO of $20.9 billion to $21 billion or 32% to 33% growth, and we expect revenue of $3.345 billion to $3.355 billion or 32% growth. Fully diluted share count of 830 million to 840 million shares, diluted non-GAAP EPS to be in the range of $0.96 to $0.98. For the fiscal year 2026, we expect NGS ARR of $8.9 billion to $8.95 billion or 59% to 60% growth. We expect RPO of $20.9 billion to $21 billion or 32% to 33% growth. We expect revenue of $11.415 billion to $11.425 billion or 24% growth, operating margins to be in the range of 28.9% to 29.2%, diluted non-GAAP EPS to be in the range of $3.77 to $3.79, fully diluted share count of 763 million to 766 million shares and adjusted free cash flow margin of 37.5%. We've included our typical modeling points in the presentation for your review. And with that, I will turn it back over to Hamza for Q&A.
Okay. Thank you, Dipak. Operator instructions. First question goes to Saket Kalia from Barclays, followed by Brian Essex from JPMorgan.
分析師問答
Okay. Excellent. I have a little trouble with video, but I'll ask the question. And congrats to the team on the results and the guide. Nikesh, maybe for you, there's tons to talk about, but I'd love to dig into your network security business just a little bit more since you mentioned a potential multiyear tailwind there. Maybe the question is: can you talk about how much AI data center demand is contributing to that? And outside of AI data center builds, how are your other customers thinking about their network security needs as AI traffic grows?
Thanks, Saket. I thought you were going to ask me about the 40% free cash flow question you mentioned on CNBC. But anyway, we'll save that one. Look, you saw across the board we've always maintained that as more traffic traverses networks, more inspection is needed. When more inspection is needed, hardware is the cheapest and fastest throughput mechanism to inspect the data. I think the multiyear tailwind will come from the fact that more and more data needs to be stored and used for training these frontier labs. You can see the explosion of data centers being built, whether by hyperscalers, frontier labs or neoclouds. You're seeing that demand fall through to some of the hardware vendors in the space. Couple that with scarcity and component pricing; you've seen some price increases, and we've seen some of that mixture of price uplift as well as demand uplift. But I think maybe the number has gone from 5% to 8% to 10% to 12%. So that's a 50% increase in demand for the industry, I think. I expect that this trend should continue for the next few quarters, if not a few years. Lee thinks I gave a good answer.
All right. Thank you, Saket. Next, we'll go to Brian Essex from JPMorgan, followed by Matthew Hedberg from RBC.
Yes. Nikesh, I'd love to ask you about Prisma AIRS. Great to see the traction there, and would love to understand from a customer perspective. One of the things I thought was very important that you mentioned was the ability for a platform to have more effective speed or mean time to detection and response. How are your customers evaluating that as they look at the elevated threat environment they have following the emergence of Mythos and other frontier models?
So let's do a double deep on this. I'm going to start off and then I'll have Lee talk about some of the capabilities that were needed in the AI future. One of the things which we have done, as many of you know, over the last many years, is we built native VM capability in many hyperscalers. Now you're seeing that is where a lot of the models are being hosted. A lot of the AI artifacts sit in the cloud because AI is not typically an on-prem event. It's typically in the cloud, in hyperscalers. I'll have Lee talk about all the capabilities we've built in the last 12 months which have allowed us to provide the security capabilities that AI needs.
So there's, like every cybersecurity space, an end-to-end component. There's a 'shift left,' which is even before you deploy AI: what you do in terms of model scanning and AI red teaming and validating the application itself and the AI usage, all the way through to the runtime components, which are very focused on real-time threats, how to detect and prevent them. And then all of that also becomes a feed into the SOC, and the SOC has to be able to ingest data from all of these different sensors, analyze in real time, use AI and then apply automation in order to achieve the mean time remediation that Nikesh was talking about earlier in the prepared remarks, where we can't be operating in a legacy model that measures mean time to detection in days when attackers, particularly with these new models, are able to carry out attacks start to finish in tens of minutes. The data that feeds into XSIAM, the amount of data that XSIAM can ingest, speed of processing, AI, automation and response — that ability to prove to customers that we can achieve MTTR in minutes is a very powerful proof point that they can achieve the same outcomes as well.
Thank you, Brian. Next, we'll go to Matt Hedberg from RBC, followed by Meta Marshall from Morgan Stanley.
Great, guys. Very impressive results, to say the least. Within your observability platform, the $200 million AI frontier lab customer and $100 million of net new ARR this quarter is super impressive. Can you talk about how observability in security is converging and how that positions you to take share versus competitors that primarily start with an observability-first solution?
Yes. Matt, I think first of all it's important to note that these are each specialized environments. You have to be really, really good at observability regardless of any potential integration with security, and the same is true with security. If you look at previous attempts to try to expand from one to the other, what you saw was perhaps a strength in one area, but then trying to apply the same logic to the other often fell short. You can't take an observability platform, add a little bit and suddenly claim it is a strong security platform, and vice versa. XSIAM is best-in-class in what it does, and we've proven that. Chronosphere from an observability perspective is best-in-class, and we've proven that. In both cases, we have strong road maps of capabilities that we'll continue to add. What you'll see over time is data collected for the observability use case will be valuable as a sensor to the security use case, meaning XSIAM will start to leverage that data to expand what it can analyze for security purposes.
Vice versa, data collected for security will provide broader context for observability. The first part is data cross-pollination. The second part is related to AgentiX. What you're seeing across these spaces is a need for AI-driven automated response, and AgentiX, we believe, is that foundation that will be leveraged across all of our platforms, starting with Cortex and expanding to Chronosphere. AgentiX becomes the other key point where you'll start to see increased integration across observability and security from us. But again, this is starting from positions of independent strength, and the cross-pollination adds to those capabilities.
Thank you, Matt. Next, we'll go to Meta Marshall from Morgan Stanley, followed by Shaul Eyal from Cowen.
Great. Maybe the question for me is just filling in on the $200 million opportunity that you guys have with the frontier lab. How does that change how you're thinking about the opportunity with the AI native? And can you give a sense of the breadth of the platform that they were buying within that deal?
Well, each of the models has a different approach in terms of how they do observability. Some DIY, some use third-party vendors like us. Chronosphere is particularly good at AI-native platforms, whether frontier AI labs or modern SaaS companies. The observability market is maturing: companies are beginning to realize that as volume scales, it's not okay to DIY. Historically, cost has been a barrier. Even at Palo Alto, when we evaluated third-party vendors, costs could be prohibitive. Chronosphere has been able to deliver similar capability at approximately half the cost of what the industry charges, so it starts to meet the number at which you're better off not building your own or relying purely on open source. It's early days. As Lee said, we have a roadmap that requires us to bolster a few more capabilities on the platform to ensure competitiveness. Advanced practitioners already see the capability and are happy to use it. We continue to make progress on the roadmap to make sure Chronosphere becomes a comprehensive platform and a mainstay for us in the future.
Thank you, Meta. Next, we'll go to Shaul Eyal from Cowen, followed by Fatima Boolani from Citi.
Congrats on results and guidance. Nikesh, I know most are focused on the ongoing progress of CyberArk and Chronosphere, great results on that front. I actually want to ask a double-click on Koi and the Agentic endpoint progress and interest that you guys are seeing. There's definitely some sort of renaissance taking place in endpoint. Can you tell us what's driving that?
Sure. The endpoint hasn't changed dramatically for a while in terms of basic attack patterns, but in the last 12 months we've seen a rapid shift: much of the activity on endpoints is becoming Agentic. Think about AI coding tools and agents; they don't just bring a single application — they bring an entire ecosystem of skills, hooks, scripts and orchestration components. It's effectively a whole new endpoint ecosystem layered on top of the existing one, and that requires specialized functionality. You can't secure this new Agentic endpoint with just a couple of added features. We observed this starting last fall and identified that Koi was unique in their ability to provide the necessary security capability. That is what got us excited and led to the acquisition. With the advent of frontier models, interest has increased because it's clear that AI development and Agentic endpoints are critical to success and must be secured.
Thank you, Shaul. Next, we have Fatima Boolani from Citi, followed by Michael Turrin from Wells Fargo.
Nikesh, this one is for you. There is a voracious appetite for any large company that basically had the rug pulled under them as it relates to the risk of novel AI attacks. In the context of Unit 42, I wanted to get a sense: how much incremental investment do you expect to put behind that franchise? How capacity constrained are you? And maybe to take it up another level, this whole notion of the Agentic SOC and Agentic remediation — how much of that are you dog-fooding inside Unit 42, whereby you can drive both scale and efficiency and a strong product feedback loop into the portfolio?
Fatima, thank you for the question. We have repurposed our Unit 42 team to focus primarily on frontier AI defense. As I mentioned, we've had north of 1,200 outreaches from customers, both where we reached out to them and where they reached out to us. Both Lee and I and many people on my team have personally done many meetings: I've done close to 100, Lee has done close to 100. We're doing these meetings to help customers strategize, not just react to models like Mythos because we believe it's real, but also prepare for how infrastructure needs to change six to 12 months from now. We firmly believe customers will have to deploy newer endpoint capability like Koi, adopt Prisma Access or secure browsers, implement virtual patching capability in firewalls and fundamentally reimagine their SOC using XSIAM. Short term, Unit 42 is focused on testing code, ensuring robustness, testing configurations and helping with some form of managed patching for their environments because many patches will be required.
Long term, they're focused on transforming architectures and delivering those capabilities. As it relates to dog-fooding Agentic capabilities, we designed XSIAM with pre-analysis in mind. XSIAM has been a great tool in reducing median time to detect for our customers and has automation and agents running to reduce SOC analyst tasks. Over time, customers may trust those agents to act independently, but for now customers want to observe and approve. Right now, customers are in Phase 0; the common recommendation is: collect all your data because without full data you don't have full context and you can't effectively react to an AI-driven attack.
Next question is Michael Turrin from Wells Fargo, followed by Adam Borg from Stifel.
Great. Congrats on the strong results here. Nikesh, you had some useful details throughout the prepared remarks, but hoping you could expand on some of what you're seeing in terms of AI-driven demand — specifically how some of the larger customer conversations you've had have evolved since Mythos and if there's a greater sense of urgency heading into fiscal Q4? And in terms of metrics, is it RPO, platform wins, or what are the key metrics you'd point us to to help gauge progress as you continue to work towards those opportunities?
Michael, six months ago some thought AI would replace cybersecurity and reduce demand. The opposite has happened: CIO priority has risen and companies are investing more. One important point is the 25% false positive rate — an AI model may identify a vulnerability that is not real, and taking automated remediation steps can cause harm. So while demand is strong and persistent, adoption cycles and deployments still take time. If I had one takeaway for investors, it is that the terminal value of cybersecurity remains intact and has increased with AI. We see robust demand that will continue for longer, but it's not an instantaneous windfall next quarter; deployments and execution still take time. So expect sustained, durable growth rather than a one-quarter spike.
Next, we'll go to Adam Borg from Stifel, and we'll end with John DiFucci from Guggenheim.
Awesome. Thanks so much for taking the question. Great to see the continued traction. Nikesh, maybe go deeper into SASE? These results have been great, outpacing the market. Talk more about the traction you're seeing overall and help us rank order that traction across SASE elements like SSE, SD-WAN, Prisma Browser, et cetera. Any more color would be really helpful.
Adam, I think we're in what I call the second wave of SASE. The first wave was largely Internet access and VPN replacement. Now customers want a comprehensive network stack integrated with security. They want consistent policies across multiple network capabilities and dynamic routing combined with security. We bought SD-WAN years ago and sell it as part of SASE because we believe in a platform approach. Customers are doing network architecture projects and realizing they can duplicate security policies across their network stack rather than learning a new stack. We're seeing stronger willingness among customers to consolidate onto a trusted platform for hardware, software and SASE. That consolidation is driving our SASE traction. In terms of rank order, the overall SASE demand is driven by unified protection (SSE), SD-WAN as part of network modernization, and secure browser adoption. Each contributes differently by customer, but the theme is consolidation and unified policy enforcement across hardware and software. We're taking share from some SASE-only vendors, and hardware remains very relevant, so the combined offering is resonating.
Thank you, Adam. And our last question will go to John DiFucci from Guggenheim.
Thanks, Hamza. Nikesh, everything looked pretty good this quarter. One area I wanted to ask about that wasn't covered: CyberArk. We all modeled CyberArk into our models assuming certain dynamics. It looked like CyberArk outperformed expectations in this first quarter post close. Is that just initial go-to-market momentum or have you actually started joint go-to-market activity? Are you seeing machine identity taking hold yet, or was this primarily core PAM? Can you talk about why CyberArk was so strong this quarter?
John, many things are going well. Most importantly, we have not broken CyberArk. The biggest fear with a large acquisition is breaking the product and the business, and we made sure that didn't happen. The CyberArk product team is working closely with Palo Alto people; the entire CyberArk product team has been in our offices and we're spending significant time together. We are modernizing and innovating the product and demonstrating the roadmap to customers. There are Palo Alto customers asking to meet CyberArk and CyberArk customers asking to meet Palo Alto. We have initiated roughly 1,000 joint meetings and go-to-market engagements where Palo Alto and CyberArk teams engage the customer together. That is already creating momentum. Our integration focus is: don't hurt the top line, improve profitability and remove friction. We are consolidating back-end systems — I received an email this morning that we've migrated one critical system to a common platform and have four more major systems to migrate in the next four months; we expect to complete before the end of the calendar year.
By integrating systems and streamlining operations, and with AI-enabled work to accelerate go-to-market and product development, we expect to reach our synergy and profitability targets sooner; we've said three to six months ahead of plan. CyberArk is an opportunity for Palo Alto to prove we can successfully execute a large, strategic acquisition, integrate teams and accelerate product innovation without breaking the business. It's existential for us, and we're committed to making it succeed.
Thank you, John. This concludes the Q&A portion of the call. I'll pass it back to Nikesh for any closing remarks.
So I just want to say thank you. We officially declare complacency for cybersecurity dead. I want to thank our partners, employees and all of you for supporting us. See you next quarter.