管理層發言
Ladies and gentlemen, thank you for standing by. Welcome to Qualys' Second Quarter 2026 Investor Call. Operator Instructions: Please be advised that today's conference is being recorded. I would like now to turn the conference over to Blair King, Investor Relations. Please go ahead.
Thank you, Michelle. Good afternoon, and welcome to Qualys' Second Quarter 2026 Earnings Call. Joining me today to discuss our results are Sumedh Thakar, our President and CEO; and Joo Mi Kim, our CFO. Before we get started, I would like to remind you that our remarks today will include forward-looking statements that generally relate to product capabilities, future events or future financial or operating performance. Actual results may differ materially from these statements. Factors that could cause results to differ materially are set forth in today's press release and our filings with the SEC, including our latest Form 10-Q and 10-K. Any forward-looking statements that we make on this call are based on assumptions as of today, and we undertake no obligation to update these statements as a result of new information or future events. During this call, we will present both GAAP and non-GAAP financial measures. A reconciliation of GAAP to non-GAAP measures is included in today's press release. And as a reminder, the press release, prepared remarks and investor presentation are all available on the Investor Relations section of our website. With that, I'd like to turn the call over to Sumedh.
Thank you, Blair, and welcome to our second quarter earnings call. The adversary's playbook has been fundamentally rewritten by AI, collapsing exploit timelines and making one thing undeniably clear. Durable pre-breach risk management increasingly requires a vendor-neutral agentic AI fabric that moves beyond theoretical exposure to autonomous quantification of actual exploitable risk and remediation. Demonstrating this conviction, we delivered another quarter of strong revenue growth and profitability. The urgency behind that conviction continues to intensify. Frontier and open source AI models are capable of discovering and weaponizing vulnerabilities faster than any human team can triage them, compressing exploit timelines to hours and in some cases, turning disclosure into compromise before a patch even exists. AI is simultaneously becoming the greatest force multiplier and the most formidable challenge cybersecurity has ever faced. Where we part ways with the continuous threat exposure management, CTEM, solutions is how we respond to it. CTEM solutions today respond by generating more findings, more theoretical risk scores and more dashboards and then pass those findings along to siloed solutions that collect data and do the patching while losing critical time at every handoff. That approach was already failing before AI accelerated the threat landscape, and it is fundamentally inadequate now. We believe the defenders who win in this new era of AI will not be the ones who simply detect more and more vulnerabilities and produce dashboard tourism. They will be the ones who can autonomously detect vulnerabilities at AI speed, validate actual exploitability in production, quantify that risk in dollar terms, remediate it and then prove the exposure is closed in multi-vendor environments, all before an adversary gets there first. That is the design outcome of the AI-native risk operations powered by our Enterprise TruRisk Management, ETM, solution, and it is where nearly every customer conversation we are having is heading. Against this backdrop, I'm pleased to announce major new capabilities on the platform we will showcase at Black Hat later this week, spanning both AI for security and security for AI to address the post-Mythos threat landscape head on. First, with respect to AI for security, we're pleased to introduce InstaScan, powered by Agent Insta, the newest addition to our agentic AI marketplace and ETM solution for AI-speed detection that is continuous, instantaneous and scanless. Today, when a new vulnerability advisory is released, it takes 24 hours to a week for organizations to detect it through traditional scan cycles, while adversaries weaponize the same vulnerability in minutes. Agent Insta is designed to collapse that timeline. By converting the asset inventory, software patch and threat intelligence our customers already collect with Qualys sensors into high-confidence exposure findings without a scan, new detections appear within minutes of disclosure with no rescan required and no agent disruption. The finding is then handed to Agent Val for instant exploit validation and the risk impact is determined and quantified immediately. While competitors are still processing an advisory, writing signatures and waiting for a scan to complete, our customers already know whether they are exposed and are taking action before a vendor patch exists. Because the finding flows straight into validation and remediation, detection is not a report. It is the first step of a continuous closed loop. With last quarter's launch of TruConfirm and Agent Val safely validating actual exploitability across chained attack paths in live production environments and hyper-prioritization using millions of findings to the fewer than 1% that require immediate action, the bottleneck is now shifting from identifying what to fix to actually fixing it before adversaries can act. This leads me to the next phase of our TruRisk Eliminate agenda, autonomous zero-day remediation at scale. Through AI-scored autonomous remediation waves, the AI-native ROC now determines the right action for every asset in a multi-vendor environment, deploying a patch where appropriate, staging a control rollout where caution is warranted or applying a compensatory control where operational risk demands it. Every action is gated by our AI-driven patch reliability score and resiliency snapshots, delivering rollback rates below 1.5%, below half of 1%. The most critical assets remain human-in-the-loop oversight while the platform autonomously remediates the rest. Orchestrating the cycle is Agent Sara, who prioritizes exploitable risk, quantifies it in dollar terms, sequences continuous waves and revalidates closure with Agent Val, all without proportional headcount. Furthermore, with the introduction of peer-to-peer patching, we are accelerating the delivery across distributed environments while removing the dependency on centralized infrastructure. Put simply, these newest innovations make autonomous zero-day remediation wave-driven, vendor-agnostic, safe and provable. In live benchmarking, this collapsed the window of exposure from 21 days to minutes and auto-patched 60% of the vulnerabilities. This is not incremental. It turns a massive surge in exploitable vulnerability volume from an impossible backlog into a continuously clear queue at the speed of modern attacks. You cannot solve a minutes problem with a month-long solution. And that's the gap the AI-native ROC was designed to solve with Agent Insta, providing AI-speed detections, Agent Val hyper-prioritizing validated exposures, and Agent Sara performing autonomous remediation in a continuous closed loop. Turning to security for AI. As enterprises raise AI workloads into production, the AI infrastructure they are building is already the next attack surface. With the introduction of TotalAI 2.0, organizations can now see their full AI estate from workforce to workload and from code to runtime. Through new sensors that see AI activity at both the employee and workload level, security teams can now discover shadow AI activity across the organization, from what employees are doing with AI to which models, endpoints and services are running in production across hybrid multi-cloud environments. We have also extended our posture management coverage to SaaS platforms, including Anthropic and OpenAI, to help organizations enforce security and compliance policies across the AI platforms their teams are already using. Additionally, they can now identify security gaps in code before deployment, remediate with guardrails at runtime and test model-context and model-control-plane exploits across over 50 adversarial scenarios. And of equal importance, every AI risk across the entire stack from GPU to infrastructure to supply chain to the newest prompt injection attacks is now scored and prioritized through the same TruRisk that powers the risk operations center. For organizations seeking to secure the infrastructure powering their AI future, these new innovations become an increasingly strong differentiator for Qualys. As ROC adoption accelerates and these capabilities continue to compound, we remain laser-focused on driving ETM adoption throughout our VMDR customer base and positioning Qualys for larger upsell opportunities over time. Moving to our business update with customers spending $500,000 or more with us, that cohort grew 8% from a year ago to 229. Let me share a couple of recent wins, which illustrate why organizations are turning to Qualys to help unify their security stack and operationalize the ROC. The first is with an existing Global 300 customer managing a complex data-intensive environment spanning on-prem, multi-cloud and rapidly growing LLMs in production. As the volume and velocity of vulnerabilities across the environment accelerated, their teams recognized that prioritization based on theoretical risk scores couldn't deliver the business context needed to act decisively. With fragmented telemetry, disconnected tools and little automation, their teams were spending more time documenting risk than reducing it, while unpatched assets and shadow IT were silently extending exposure windows by months. As a result, the customer chose Qualys to operationalize their ROC, adopting VMDR, ETM, TruRisk Eliminate and TotalAI alongside several other modules in a low seven-figure QFlex annual upsell. By consolidating Qualys and third-party data into a unified risk fabric, this customer has aligned risk reporting to the Board's tolerance level, shifted remediation from manual processes to autonomous workflows and reduced its exposure window from months to hours while flattening the hiring curve and delivering better security outcomes. This is also an outstanding example of how we are leveraging our channel partners to activate the ROC to win new business. The second is with a European health care company that had been a small VMDR customer relying on a managed service provider to run the broader vulnerability program across more than 140 locations. That model delivered people and process, but not autonomy. Scan operations prioritization and remediation guidance all flowed through the provider's team on the provider's timeline, leaving the customer dependent on external resources to understand and act on its own risk. As this environment grew more complex and vulnerability volume surged, the limitation of that dependency became unsustainable. Costs for ballooning remediation cycles were mounting, and the customer had limited visibility into the very data driving the decisions made on its behalf. This customer chose Qualys, consolidating its stack into the Qualys platform by adopting VMDR, ETM and TruRisk Eliminate in a six-figure QFlex upsell. ROC automation was the entry point and remediation was the immediate proof of value. By unifying detection, prioritization and autonomous remediation into a single AI-native workflow, this customer has replaced a manual people-and-process dependency with a platform that delivers significantly lower cost, less complexity, full control and peace of mind for the CISO. These wins reflect the broader ETM momentum we are starting to see as more and more customers recognize the efficiencies and scale of AI-native ROC automation. Further supporting our growth trajectory, QFlex continues to gain traction as another strategic lever for accelerating ETM adoption. As we heard in the customer wins I described earlier, QFlex played a direct role in enabling significant upsells for Qualys by giving these customers the flexibility to commit broadly across the platform while preserving the ability to shift investments as their needs evolve. This precisely the value proposition QFlex was designed to deliver. Building on strong results from our initial rollout, we have now taken QFlex live for enterprise customers looking to expand with Qualys and believe it can become an increasingly important driver of platform expansion over time. Turning to our executive team. With the recent departure of our CISO and General Manager of our ETM business, I want to address how we are positioning for continuity and acceleration. To lead product strategy and our ETM business going forward, I have appointed Shailesh Athalye as our Chief Product Solutions Officer, a nearly 14-year Qualys veteran who has served as our SVP of Products for the last five years. Shailesh has been instrumental in shaping many of the platform innovations we discussed today, and his deep institutional knowledge of our technology, our customers and our road map makes him the natural leader to drive the next phase of ETM adoption and our customer-led growth strategy. Additionally, I'm pleased to welcome Nathan Smolenski as our new Chief Information Security Officer. Nathan is a seasoned cybersecurity executive with 24 years of experience driving security transformations across financial services, insurance and high-growth SaaS environments, most recently serving as the global CISO at Cyera. We are excited to have both Shailesh and Nathan in these critical roles as we continue to scale our platform and accelerate ROC adoption. In summary, Qualys' continued innovation spanning both AI for security and security for AI, growing AI-native ROC adoption powered by our ETM solution, a growing federal pipeline for new business opportunities, strong partner-led execution and promising early QFlex engagement continue to reinforce the demand we're seeing for a unified risk management platform that autonomously moves beyond theoretical exposure to validated, quantified and remediated risk at the speed of modern attacks in multi-vendor environments. We believe these achievements not only advance our strong competitive differentiation, but also sharpen the market opportunity ahead of us and bolster our confidence in reaccelerating long-term growth in the business. With that, I will turn the call over to Joo Mi to further discuss our second quarter results and outlook for the third quarter and full year 2026.
Thanks, Sumedh, and good afternoon. Before I start, I'd like to note that except for revenues, all financial figures are non-GAAP, and growth rates are based on comparisons to the prior year period unless stated otherwise. Turning to second quarter results. Revenues grew 11% to $182.2 million. As a result of a strategic emphasis on leveraging our partner ecosystem to drive growth, the channels continue to increase their contribution, making up 54% of total revenues compared to 49% a year ago. Revenues from channel partners grew 22%, with revenues from direct remaining largely unchanged from Q2 of last year. By geography, 15% growth outside the U.S. was ahead of our domestic business, which grew 8%. U.S. and international revenue mix was 55% and 45%, respectively. In Q2, our overall upsell execution improved, with our net dollar expansion rate at 105%, up from 104% last quarter. The net dollar expansion rate of customers with a prior year purchase of ETM or CSAM subscriptions in Q2 was 107%, consistent with last quarter. Moving on to product mix. Our differentiated new products continue to drive growth. First, ETM/CSAM combined made up 12% of total bookings and 14% of new bookings on an LTM basis in Q2, up from last year's 9% and 10%, respectively. Next, patch management made up 9% of total bookings and 16% of new bookings on an LTM basis in Q2. This compares to 7% and 16%, respectively, in Q2 of last year. Lastly, TotalCloud made up 5% of total LTM bookings in Q2, unchanged from a year ago. We believe that these differentiated products combined will increase contribution to bookings in 2026, given our opportunity to increase market share and maximize share of wallet. Reflecting our scalable and sustainable business model, adjusted EBITDA for the second quarter of 2026 was $83.8 million, representing a 46% margin compared to 45% last year. Operating expenses in Q2 increased by 8% to $73.2 million, driven by investments in sales and marketing, which grew 14%. With this strong performance, EPS for the second quarter of 2026 was $1.98 per diluted share and our free cash flow was $55.9 million, representing a 31% margin compared to 20% in the prior year due to fluctuations in working capital. Normalizing for this, first half of 2026 margin was 42% compared to 43% in the prior year. In Q2, we continue to invest the cash we generated from operations back into Qualys, including $3.7 million in capital expenditures and $76.8 million to repurchase 797,000 of our outstanding shares. As of the end of the quarter, we had $229.8 million remaining in our share repurchase program. With that, let us turn to guidance, starting with revenue. For the full year 2026, we now expect revenues to be in the range of $732 million to $738 million, which represents a growth rate of 9% to 10%. This compares to prior guidance of $721 million to $727 million. For the third quarter of 2026, we expect revenues to be in the range of $185.5 million to $187.5 million, representing a growth rate of 9% to 10%. This guidance assumes our net dollar expansion rate remains at current levels with moderate growth contribution from new business in 2026. Shifting to profitability guidance. For the full year 2026, we expect EBITDA margin to be in the mid-40s, with a low-teens increase in operating expenses and free cash flow in the low 40s. We expect full year EPS to be in the range of $7.74 to $7.88, up from the prior range of $7.44 to $7.65. For the third quarter of 2026, we expect EPS to be in the range of $1.91 to $1.98. Our planned capital expenditures in 2026 are expected to be in the range of $8 million to $12 million and for the third quarter of 2026 in the range of $1 million to $2.5 million. With that, Sumedh and I would be happy to answer any of the questions.
分析師問答
Operator Instructions: The first question comes from Kingsley Crane with Canaccord.
Congrats on amazing results. Sumedh, the volume of AI-generated vulnerabilities is a clear reason why customers need InstaScan and the ROC. Can you just double-click again on how this is showing up in pipeline, how this is showing up in urgency? And then if CVE volumes were to double again, how could you capture that in your per-asset pricing model?
That's a great question. Even though disclosure findings are increasing, an organization's ability to remediate is what's currently being tested. That's where our focus has been — helping customers with autonomous remediation. At a high level, you can't tell your management as a security leader that you're going to respond to autonomous AI exploits with more manual tools that involve emailing each other on what needs to be fixed. Our approach focuses on the risk operations center. Agent Sara is already helping with autonomous remediation, but to do this well and with high confidence, you need to significantly hyper-prioritize your findings. That's where Agent Val on the ROC platform helps by running actual exploit validation to reduce the number of findings that need to be auto-remediated to those that actually matter to the business. Our latest announcement of Agent Insta, which can scan instantaneously whenever a new advisory comes out, now shrinks the timeline from advisory release to detection in the customer environment. With all three of these on the ETM platform, you now have a real path to get something that is important and exploitable in your business remediated within the first 24 hours with minimal human intervention. That is the conversation that everybody is having: how they will move toward a roadmap that allows feasible autonomous remediation, and ETM is enabling that. We've been ahead of this for the last few years with autonomous remediation capabilities, so we already had a few customers in the pipeline who were discussing this beforehand, and post-Mythos has helped accelerate a couple of these opportunities. There's a large number of customers now very curious about what's possible, so the pipeline in terms of conversations and POCs is looking good. We now need to move forward with POCs, look at budgets and closing timing, but given our innovation and investment, we're excited about the current conversations.
Great. And then just a follow-up for either Sumedh or Joo Mi. Building off of that, billings grew 16% — it was a sizable raise. On top of a broad-based beat, we're now talking about reaccelerating long-term growth. Is it that the conviction in the business hasn't changed and the market has come towards you this quarter? Or can you help us understand how much more bullish you are in the business today than you were three months ago?
We've always believed that remediation and autonomous remediation would be key market needs and invested accordingly. The conviction hasn't changed; AI has accelerated the timing of what we expected to happen. Because of the investments we've put into the platform, these solutions can help customers now with the autonomous remediation capabilities they are asking for. Positive conversations with customers are helping us see how opportunities can close, but we still need to execute POCs and work through budgets and timing. So while the market dynamic has accelerated, our strategy and conviction remain consistent with prior quarters, and we're optimistic given the current pipeline.
The next question is from Jonathan Ho with William Blair.
Congratulations on the strong quarter. I wanted to understand a little better. When you talk to your customers about their change in the exposure risk management process, can you help us understand how much of this is that they need to cover more assets versus the fundamental patch management process changing versus having the ROC part of this on the managed side? Can you unpack what they're buying and what they intend to buy over time?
Great question. Ultimately, customers want to remediate what actually matters to their environment as quickly as possible. That includes all assets, but they may already have other tools providing some visibility. Our ETM strategy and the ROC is designed as a multi-vendor solution, so it can ingest telemetry from Qualys sensors and other scan-only products. ETM allows us to expand licenses in early POCs because customers bring in data from other tools into ETM to get a holistic view across multiple tools, prioritize what matters, run exploit validation and then execute remediation. So adding patch management and ETM broadens coverage and makes remediation more successful. Even if customers have scan-only tools producing many false positives, they can bring that data into ETM and benefit from our validation and remediation workflow.
Excellent. And just given the relative proximity of Mythos, when do you think the bulk of the spending will start to materialize? I'm guessing we haven't seen it yet. I wanted to get your sense for how this is developing in the pipeline.
It's similar to responses we've seen with big incidents like Log4j or SolarWinds. Our enterprise customers tend to plan longer-term changes to their security programs rather than immediate knee-jerk spending. CISOs are using the post-Mythos threat landscape to justify long-term, sustainable changes like autonomous remediation, and those decisions require stakeholder alignment and budget planning. We're early in many of these conversations; we'll continue to build pipeline and wait to see when budgets are allocated. For now, it's primarily positive conversations and pipeline development.
The next question is from Patrick Colville with Scotiabank.
Let me ask Sumedh first and then Joo Mi. Great to see the guide raise from 8% to 10% for the fiscal year and the comment about reaccelerating growth long term. Can you clarify if that reacceleration commentary is new? And what gives you confidence to say that now? Is it things you're seeing or just conversations?
I wouldn't call it new. We've always focused on investing and innovating in the platform with a view to long-term growth, including remediation capabilities, federal focus and partner execution. The advent of AI has accelerated the path we saw coming, and given our investments and existing traction — for example, 150 million patches deployed in the last 12 months with 40 million deployed autonomously — we have data points that help customers gain confidence. So it's continuation of a long-term strategy and seeing stronger tailwinds now.
Joo Mi, on the disclosure about new bookings: ETM/CSAM were 14% of new bookings and patch was 16% of new bookings on an LTM basis, roughly the same as last quarter. Why isn't that showing up more clearly given the qualitative commentary? Should we expect those proportions to increase in 3Q and 4Q?
We expect fluctuations in the percentage contribution to bookings from quarter to quarter because it depends on which customers are onboarding and what they purchase at that time. For example, a new prospect might allocate more budget to VMDR or ETM or patch management depending on their needs. The current percentages are healthy and validate that when we land logos, we often do so due to our continuous product enhancements like ETM/CSAM and patch management. Over time, we expect these differentiated products to increase their contribution to bookings as customers expand.
The next question is from Rudy Kessinger with D.A. Davidson.
Congrats on the strong results. If the Mythos-related demand is still largely in pipeline and conversation stages and wasn't the primary driver of the quarter, and you're aiming to accelerate growth, are you more willing to use margin to invest in growth next year? How should we think about the growth-profitability trade-off into next year?
We continuously evaluate investments in innovation and sales and marketing and focus on ROI. We're already investing and will continue to evaluate additional investments as opportunities move through the pipeline. At this point, we feel good about our current investments and will adjust as we see opportunities that justify additional spend.
Part of why we're able to accelerate top-line growth without significantly increasing investments is our partner-first, partner-led growth model. The majority of our growth in new logos is driven through partners. We're investing appropriately now — sales and marketing expense up 17% in Q1 and 14% in Q2 — and we anticipate further acceleration of investments in the second half.
Understood. And then for my follow-up, current calculated billings was really strong in the quarter. Anything to call out that drove the better sequential and year-over-year on CCB in Q2, like early renewals? And any directional commentary on CCB growth expectations for Q3 and the full year?
Quarterly current billings do have natural lumpiness. We prefer to point to LTM current billings to smooth that. LTM current billings growth was 8.5% last quarter and is 10% this quarter, reflecting acceleration. Because of that, we increased revenue guidance. For the second half, we still expect baseline current billings growth of 7% to 8%, which implies full year current billings growth in line with our revenue guidance of 9% to 10%.
The next question is from Junaid Siddiqui with Truist.
Sumedh, TruConfirm appears to be a powerful tool for ETM by helping customers validate which vulnerabilities are actually exploitable in their environment. Is that becoming the land motion for ETM? Once customers see exploit validation reduce thousands of findings to a handful, how often does that expand into broader ETM remediation and risk quantification deployments?
Great question. The vulnerability lifecycle to be successful requires three buckets: detection as fast as possible, validation of exploitability, and remediation. Agent Insta provides fast detection, but detection alone doesn't confirm exploitability. TruConfirm and Agent Val are differentiators because they allow customers to reduce theoretical findings to the 1% that matter and run lightweight, safe exploit validations to further reduce the number of findings that will actually work in their environment. That makes autonomous remediation much more plausible. Telling someone you'll fix a million vulnerabilities autonomously is unrealistic, but showing that you will autonomously fix a much smaller, highly validated set of vulnerabilities — the ones confirmed exploitable — is a much more compelling conversation. TruConfirm is a key part of the upgrade discussion for our existing VMDR customers and often leads to ETM and elimination conversations.
Great. Just a follow-up: for VMDR-only customers, are you seeing high churn? Is that the main source of pressure on your overall net dollar retention rate?
Nothing material to call out. We view our VMDR customer base as a large opportunity to upgrade to ETM because most customers will need prioritization and remediation solutions post-Mythos. We see this as a growth opportunity to engage existing customers who will want more than scanning, not as a churn-driven pressure point.
The next question is from Joseph Gallo with Jefferies (note: Grant Darling on for Joe Gallo).
Have you seen anything different competitively post-Mythos? There's more chatter from various players signaling interest in the space. Are you seeing or expecting any change in competitive dynamics or differences in the frequency of competitive displacements?
Customers are seeing a lot of chatter and noise from solutions that produce more and more CVEs. The problem is the chatter. We're differentiating by not just aggregating CVEs but by providing exploit validation like TruConfirm and native autonomous remediation that actually fixes vulnerabilities in hours rather than just emailing patch instructions to other teams. Customers appreciate a solution that can remediate an exposed vulnerability within a few hours rather than leaving them with disparate point solutions. That's driving the interest we're seeing.
Got it. And for my follow-up, can you quantify the federal business size today and give more detail on the opportunity and your right to win there?
It's not a big part of the business today, but it's a growing opportunity. The current administration and CISA's new directives emphasize fast detection, exploit validation and quick remediation. CISA's requirements for rapid remediation create demand for solutions that can detect quickly and remediate in measurable time frames. Qualys has a FedRAMP High platform capable of FedRAMP High detection and patching, and our agentic AI capabilities are differentiated in our view. That combination gives us a strong right to win as federal customers modernize to meet these requirements, and we're actively engaging in those opportunities.
The next question is from Joshua Tilton with Wolfe Research.
Quick clarifications. Joo Mi, you said you still expect 7% to 8% product billings growth for the year. Can you help us understand why that remains unchanged given the strong billings growth in Q2? Is it a conservative view or is Q2 a blitz? Also, what net dollar retention rate is baked into the full year guidance?
To clarify, the 7% to 8% current billings guidance is for the second half baseline. The full year current billings guidance is now in line with our revenue guidance of 9% to 10%. For the baseline, the second half current billings growth assumption of 7% to 8% is predicated on no meaningful change to our net dollar expansion rate, which is currently at 105% versus 103% at the start of the year.
To be clear, the 7% to 8% current billings is for the second half, correct?
That's correct.
The next question is from Mike Cikos with Needham.
Even earlier this year you discussed a baseline guide for 7% to 8% CCB for 2026. Given the year-to-date outperformance, why not raise that CCB for the back half? Q2 was mid-teens; why not take the back half higher?
Quarterly current billings are lumpy, and we don't actively manage to a quarterly metric. LTM current billings smooth out lumpiness and showed acceleration — 8.5% last quarter and 10% this quarter. Q2 benefited from a smaller cohort of customers who were far along in ETM discussions and translated into better-than-expected results. For the larger cohort not as far along, we don't see meaningful acceleration in their sales cycles yet. Given that mix and the natural lumpiness, we maintained the second half baseline at 7% to 8% for current billings.
Understood. One more: net dollar expansion improved to 105% and ETM/CSAM cohort remains at 107%. Can you provide granularity on what's driving total company improvement — product mix, cohorts adopting, or other factors?
Product mix helps explain the NDR and bookings trends. ETM/CSAM now makes up 12% of total bookings, up from 9% a year ago, which helps drive bookings momentum. Patch management also contributed, moving from 7% to 8% of bookings year over year. VMDR's contribution has come down to 49% from 54% a year ago. These shifts in mix and the expansion of differentiated products are contributing to the improvement in NDR and bookings momentum.
The next question is from Brian Essex with JPMorgan.
Joo Mi, great to see partner traction on the indirect side. I'd like to understand where you're guiding spending, particularly sales and marketing and OpEx overall. Last quarter you talked about mid-teens growth in S&M; it seems you're in similar direction but came in below that in the first half. Where are you seeing traction, where would you increase spend, and how will you regulate OpEx relative to that mid-teen level?
Most of the sales and marketing spend increase is driven by headcount. The year-over-year increases — 17% in Q1 and 14% in Q2 — are investments in expanding our GTM team across sales, marketing and product to work closely with partners and drive execution. We're also leveraging AI internally to improve operating efficiency. We anticipate continuing to invest, with headcount being the primary driver of additional spend for 2026, alongside demand generation investments to produce quality pipeline for the second half.
Okay, and how far penetrated are you in your installed base with QFlex? Are you limiting availability to high-end enterprise customers or rolling it out broader as you gain experience?
QFlex is generally available and primarily intended for enterprise customers. It's designed for customers who want flexibility and are willing to commit more broadly across the platform. It tends to be a premium offering and is right for enterprise customers who want to grow with us in a cost-effective way. Today it applies to a smaller percentage of customers, but we believe it will help drive net dollar expansion as more enterprise customers adopt it.
The next question is from Shrenik Kothari with Baird.
Congrats on a great quarter. You underscored that near term there's a stronger patch management cycle, but you believe there's a broader category reset around the control plane for pre-breach risk management, exploit validation, risk quantification and autonomous remediation. Last quarter you said customers may extend sales cycles or pause renewals as they reassess. Can you add finer points on strategic deal conversion timing and sales cycles? How long are evaluations taking and are conversions getting faster?
The ROC is broader than vulnerability management and includes misconfigurations and identity vectors. Customers aren't looking for a one-month patching exercise; they want long-term processes to respond quickly to threats. We see ROC as enabling broader strategic conversations where customers can adopt phased approaches: start with detection and patch management, then expand into validation and autonomous remediation. Some customers were already ahead and helped drive short-term patch cycles, but a larger cohort is now engaging in longer-term conversations about ROC and ETM adoption. That gives us an opportunity for sustained strategic deals rather than just short-term fixes.
Quick follow-up on NDR and QFlex. ETM cohort remains at 107% NDR. Is QFlex helping pull forward commitments and bookings ahead of near-term usage and thereby affecting the total company NDR versus ETM cohort? Is QFlex playing a role in shifting budgets toward urgent capabilities?
QFlex is intended for customers who want flexibility and who are willing to spend more with us. It's currently adopted by a small percentage of customers and isn't yet reflected materially in our numbers, but we expect it will help drive NDR over time by enabling customers to commit broadly and expand usage as they grow with Qualys.
This concludes the question-and-answer session.