管理層發言
Thank you for standing by, and welcome to Zscaler's Third Quarter Fiscal 26 Earnings Conference Call. Currently, all participants are in a listen-only mode. After the speakers' presentation, there will be a question and answer session. To ask a question during the session, you will need to press 1 on your telephone. To remove yourself from the queue, you may press *1 again. I would now like to hand the call over to Kim Watkins, SVP of Investor Relations. Please go ahead.
Good afternoon, and thank you for joining us today. Welcome to Zscaler's Third Quarter Fiscal 26 Earnings Conference Call. On the call with me today are Jay Chaudhry, Chairman and CEO, and Kevin Rubin, CFO. Please note that we posted our earnings release, shareholder letter and a supplemental financial schedule to our investor relations website. Unless otherwise noted, all numbers we talk about today will be on an adjusted non-GAAP basis. You will find a reconciliation of GAAP to the non-GAAP financial measures in our earnings release. Before we get started, I would like to remind you that today's discussion will contain forward-looking statements, including, but not limited to, the company's anticipated future revenue, annual recurring revenue, net new annual recurring revenue, operating margin, gross margin, operating profit, net other income, earnings per share, and free cash flow margin, our customer response to our products, our expectations regarding AI and its impact on our business and customers, and our market share and market opportunity and our objectives and outlook. These statements and other comments are not guarantees of future performance, but rather are subject to risk and uncertainty, some of which are beyond our control. These forward-looking statements apply as of today, and you should not rely on them as representing our views in the future. We undertake no obligation to update these statements after this call. For a more complete discussion of the risks and uncertainties, please see our filings with the SEC as well as in today's earnings release. I also want to inform you that we will be attending the following conferences this quarter: the Baird Global Consumer Technology and Services Conference on June 2, the Bank of America Global Technology Conference on June 3, and the FBN Virtual Technology Conference on June 15. And with that, I will turn the call over to Jay.
Thanks, Kim. And thanks to everyone for joining us today. We delivered strong Q3 results. ARR grew 25%, and non-GAAP operating margin hit an all-time high at 23%. AI is changing the nature of cybersecurity in real time, and Zscaler is the cybersecurity platform for the AI era. This is evident in our results and the reason we are so confident in our long-term potential. We offer the industry's only complete Zero Trust SASE solution, a singular Zero Trust platform across users, across cloud workloads, and across branches. Our architecture is purpose-built to address the limitations of firewall-based SASE solutions and has several key differentiators. First, we hide applications and data behind our Zero Trust Exchange, making them invisible from the Internet and eliminating the attack surface. An attacker cannot breach what it cannot reach. Hence, this architecture provides far superior cyber protection for our customers. Second, we eliminate lateral movement of attackers with our Zero Trust architecture. We only allow authorized users and workloads to access specific applications. This reduces the blast radius of a potential breach, providing better security to our customers. This stands in stark contrast to competitors with firewall-based SASE architecture that connect users to the corporate network. Once a malicious actor gains a foothold on the network, it can roam freely and systematically attempt to compromise critical applications or steal data. This is how most ransomware attacks happen. Finally, scale matters. Our cloud-native Zero Trust Exchange is the largest distributed in-line security platform in the world, spanning across 160 public exchanges and processing more than 500 billion transactions per day. This gives us the best quality and quantity of telemetry data. Simply put, no other cybersecurity vendor has access to datasets with comparable fidelity and breadth. This high-fidelity telemetry fuels our AI security capabilities, continuously improving how we detect, prevent, and stop threats. These differentiators are especially important at a time when organizations are aggressively deploying AI applications and models with growing interest in AI agents at scale. We expect it will not be long before millions of AI agents have access to organizations' mission-critical applications and sensitive data. Today, users are the weakest link in cybersecurity. But soon, AI agents will be the weakest link, because they operate at far greater speed and have far less oversight. Even a single compromised agent can move to data theft in minutes, inflicting catastrophic damage on enterprises. Making it even more challenging, new powerful frontier AI models like Meta's are finding security vulnerabilities in software at machine speed, significantly diminishing the effort, skill, and time needed to breach enterprises. All enterprises already have thousands of known vulnerabilities that they have not been able to patch. Frontier models are multiplying these unremediated vulnerabilities by as much as 10x, and even more powerful models that are currently being developed will undoubtedly make it worse. Enterprises do not have the capacity to patch and update existing vulnerabilities, so backlogs are piling up faster than organizations can address them. To tackle this challenge, the market needs to take a different approach. We provide the two most important defenses against these vulnerabilities: 1) hiding applications from attackers, and 2) eliminating lateral movement at scale. This validates the architecture we pioneered. Zscaler was built for this moment. We started with Zero Trust security for users so users can safely access applications from anywhere. Then we expanded our Exchange to provide Zero Trust security to workloads and connected IoT/OT devices. Now we are expanding our Exchange to secure AI agents. An important element of agentic security is to understand which agents, users, and other identities are communicating with which models, applications, and data sources. On May 21st, we announced our intent to acquire Symmetry Systems, a company that solved this difficult problem. Symmetry provides an access graph that maps how identities, applications, and other data sources connect across the enterprise. We are integrating its access graph technology with our Zero Trust Exchange. We are excited to share more about this at our Zenith Live user conference in Las Vegas next month. We are also partnering with Anthropic on Project Glasswing, and with OpenAI as part of its Daybreak program, formerly known as Trusted Access for Cyber or TAC, which allows us to access frontier models to proactively harden our systems and deliver better security and resilience to our customers. Against this backdrop, investors have asked us where is the ideal place to guard against AI threats? We are in the enviable position of having strong visibility across three critical vantage points for superior security: network, cloud, and endpoint. This is indispensable in enforcing real-time policy decisions. It is a powerful advantage for our customers and an important differentiator for Zscaler. We are enhancing our go-to-market engine across multiple dimensions to help highlight this differentiated approach. For example, we continue to deepen our partnership with global system integrators, or GSIs, who play a meaningful role in expanding the reach of the Zscaler platform. We are seeing strong growth in bookings through our GSI partners. We recently announced the launch of Project AI Guardian, a strategic collaboration with key GSI partners which will help our partners extend the Zero Trust architecture to AI assets including AI agents. GSIs will be able to leverage Zscaler's AI Protect portfolio to build specialized AI discovery and risk mitigation services. We are also continuing to expand our cloud marketplace motion. For fiscal 26 year-to-date, we transacted approximately $900 million in TCV through our cloud marketplaces, which more than doubled year over year. This is becoming a more important route to market as cloud marketplaces simplify procurement, align well with enterprise cloud commitments, and increasingly support larger strategic engagements. These investments are helping expand our reach, and Zscaler's unique architecture for safe adoption of AI is resonating. This is evident in my conversations with customers and partners and why I believe AI is a catalyst for our business. Let me illustrate our progress with a few customer examples. In a seven-figure upsell deal, a Fortune 500 financial technology company chose Zscaler to secure rapid enterprise adoption of AI with our AI Protect solution, which we introduced in January. AI Protect includes AI asset discovery, AI guardrails, and continuous red teaming. Zscaler AI Protect provides this customer a single integrated way to discover and manage all AI assets including shadow AI users, enforce safe access to approved apps, and inspect every prompt and response in real time to stop data leaks and attacks like prompt injection. This customer faced a complex challenge of securing both employee interactions with public AI apps and their own suite of custom-built AI solutions. With our AI red teaming and AI Guard capabilities, the customer moved from a manual reactive effort to an automated proactive approach to harden the growing number of AI applications. For customers building their own AI models and applications, our AI red teaming solution performs continuous security assessment. Our unified user interface and deep integration of multiple products is a key differentiator. Our AI Protect solution is resonating with customers with bookings crossing $100 million over the past 12 months. We are seeing inbound requests from across our customer base, and our pipeline is robust and growing. In another customer example, we closed a seven-figure upsell with a federal agency that previously migrated from a legacy VPN architecture last year to Zscaler's Zero Trust platform. This agency is deploying Zscaler to modernize and unify its data security strategy, gaining broad coverage without the overhead of managing additional endpoint agents or the operational complexity of stitching together various data security products. With this expansion, the customer is now using six of Zscaler's eight data security modules across data classification, email DLP, endpoint DLP, and inline DLP, along with our GenAI Security solution. The expansion underscores our broader momentum in data security, which crossed $500 million ARR, up over 30% year over year. As AI adoption accelerates and sensitive data increasingly resides across multiple locations, customers are reducing cost and complexity by consolidating onto our data security solution. Turning to another customer example, during Q3, we signed the largest branch deal in Zscaler history: an eight-figure upsell with a leading healthcare system to deploy our unified Zero Trust Branch solution across 2,000 sites. Zero Trust Branch disrupts branch firewalls, software-defined wide area networks (SD-WAN), and MPLS networks. With this win, we are displacing both a major firewall incumbent and a legacy VPN incumbent. With Zscaler, the customer is eliminating lateral threat movement in their health clinics at roughly half the cost of its prior legacy solution. We are seeing particular momentum with Zero Trust Branch where ARR has approximately tripled year over year. The next customer I will highlight is a seven-figure new logo win with a leading healthcare technology company for a platform-wide adoption. This deal illustrates why customers choose Zscaler over incumbent firewall vendors: the stickiness of our Zero Trust approach with CIOs and CSOs and our ability to convert a limited initial request into a comprehensive platform win. We received an inbound request for this particular customer after a senior technology leader joined from another customer where he had a great experience deploying Zscaler. He fully understood the difference between Zero Trust SASE and firewall-based SASE. While the initial discussions started around securing users, the company's top priority quickly became securing cloud workloads. The deal quickly grew into a comprehensive platform win including Zero Trust Cloud, Zero Trust Branch, and four data security modules. The last customer win I will highlight is a large automotive manufacturer that adopted our Zero Trust Cloud solution in a seven-figure upsell deal. This is a long-time Zscaler customer whose ARR is up tenfold in the last seven years. This quarter, the customer extended its existing Zscaler Zero Trust SASE footprint by expanding its deployment of Zero Trust Cloud, improving its security posture and securing its massive multi-cloud environment. The customer can now inspect encrypted traffic and enforce granular security policies across hundreds of previously ungoverned cloud workloads. The deal also highlights the benefits of our Zero Trust Cloud solution which was configured in under ten minutes during the customer's proof of concept. Zero Trust Cloud eliminates virtual firewalls in data centers and cloud environments, reducing cost and operational complexity. The strength we are seeing in Zero Trust Cloud and Zero Trust Branch is driving the growth of our Zero Trust Everywhere enterprises that purchase each of our Zero Trust for Users, Zero Trust for Branch, and Zero Trust Cloud. We exited Q3 with more than 700 Zero Trust Everywhere enterprises versus over 550 in Q2. Customers are recognizing that it is no longer enough to just secure their users, and our platform is the industry's only complete Zero Trust SASE solution across users, across cloud workloads, and across branches. In summary, we are confident Zscaler is the cybersecurity platform for the AI era. We expect AI and frontier models to be one of the strongest tailwinds our business has ever seen. Our Zero Trust SASE solution enables us to hide applications and make them invisible to attackers while also eliminating lateral movement. These attributes, along with our scale, are true competitive differentiators for Zscaler. With frontier models uncovering vulnerabilities at unfathomable speeds and AI agents becoming the weakest link in cybersecurity, these differentiators have never been more important than they are today. Our approach is resonating and helping to drive significant wins that demonstrate our ability to attract new customers and further penetrate our installed base of more than 9.4 thousand customers. Among those, we serve just 4.5 thousand enterprises out of a potential 20 thousand enterprises in our primary target market. We are confident that our innovative approach to staying ahead of threat actors will help to drive further share gains. With the significant long-term growth potential, we are well positioned to continue creating significant value for our shareholders. I will hand it over to Kevin to walk through the financials. Thanks, Jay.
We delivered strong Q3 FY26 results, growing revenue 25% while investing with discipline. Year-to-date with 26% revenue growth and a 29% free cash flow margin, we achieved Rule of 55 performance. Our Q3 FY26 net new ARR was $166 million, up 24%, bringing total ARR to $3.5 billion, up 25% year over year. Net new ARR benefited from strength in the public sector vertical, which includes state, local, and federal government and healthcare, including an approximate eight-digit upsell at a federal agency. Net new ARR also benefited from strength of large deals in APJ where the deal value from $1 million-plus deals increased more than 150% year over year. Excluding the contribution from our acquisition of Red Canary, net new ARR was $153 million, up 14% year over year, and total ARR was also up 21%. Red Canary exited Q3 with $127 million of ARR. We have steadily expanded our Zero Trust platform beyond users to protect branches, workloads, AI applications, and now AI agents. We believe AI agents will drive a meaningful increase in machine-to-machine and agent-to-agent interactions over time. In Q3, our non-seat-based metered usage solutions delivered just over 30% of new ACV, and the ARR tied to those offerings grew more than 100% year over year. Revenue of $850 million grew 25% year over year and 4% sequentially, exceeding the high end of our guidance. We closed Q3 with 748 customers generating more than $1 million of ARR and 4 thousand customers exceeding $100 thousand of ARR, growing 18% and 19% year over year, respectively. We also set a record for $1 million-plus New ACV deals for Q3. On a geographic basis, we saw strong growth from the Americas, which accounted for 56% of revenue, up approximately 31% year over year. EMEA accounted for 28% of revenue, up approximately 16%, and APJ for 16% up approximately 23%. Remaining performance obligation, or RPO, of approximately $6.5 billion grew approximately 30%, including approximately 46% classified as current RPO. Our go-to-market strategy is a key growth lever enabling us to deepen customer relationships, accelerate platform adoption, and expand multiyear engagements. Building on Jay's earlier comments on enhancements to our go-to-market engine, we are continuing to strengthen our position as a long-term strategic partner and driving deeper customer adoption over time through our account-centric sales motion. We saw strong momentum this quarter with Z-Flex. Z-Flex gives customers with multiyear commitments the flexibility to activate or swap modules without starting a new procurement cycle, along with premium deployment assistance and support. This program is driving meaningful upsell, shorter sales cycles, and greater forward visibility. In Q3, Z-Flex generated just over $480 million in TCV, up more than 60% quarter over quarter. We have delivered over $1 billion in Z-Flex TCV over the last 12 months in an average four-year term, underscoring customers' long-term commitment to Zscaler. To share a couple customer examples, in a five-year, eight-figure Z-Flex deal, a Fortune 500 finance and insurance customer that spends more than $5 million with us annually increased their ARR by nearly 50%, expanding module adoption across four existing modules and adopting six new modules, including our AI Protect solution. In another example, an existing seven-figure ARR global semiconductor manufacturer customer increased their annual spend with us by 60% in a three-year, eight-figure Z-Flex deal. This customer expanded adoption across six existing modules and adopted six new modules, including our AI Protect and Zero Trust Branch solutions. Turning to operating performance, non-GAAP gross margin was 80.7% compared to 80.3% a year ago. Non-GAAP operating income of $196 million grew $49 million, or 34%, as compared to $147 million last year. Non-GAAP operating margin of 23% increased 140 basis points year over year, demonstrating leverage on sales and marketing. Turning to the balance sheet, we ended the quarter with $3.5 billion in cash, cash equivalents, and short-term investments, and $1.7 billion of debt. In Q3, we generated $198 million in operating cash flow, and CapEx was $42 million or 5% of revenue. This equates to a free cash flow margin of 16% this quarter, down from 18% last year, reflecting the timing of cash collections, and a free cash flow margin of 29% year to date. Looking ahead, I would like to spend a minute and provide an update on increasing memory, storage, and processor prices and availability. As a reminder, we purchase equipment for our data center and Zero Trust Branch appliances. To mitigate costs, we put through a price increase on our branch appliance earlier this calendar year, which we expect to flow through in the next several months. We are also being opportunistic in taking delivery of data center equipment where we can get it to lock in today's prices ahead of potential increases in the future. This is pulling forward some of the investments we expected to make in fiscal 27 into Q4. As a result, we expect higher CapEx in Q4, taking fiscal 26 CapEx to the high single digits as a percentage of revenue, up from our prior expectation of mid single digits. Looking ahead to fiscal 27, based on higher prices we see in the market today, we expect CapEx as a percentage of revenue to increase up to 200 basis points compared to fiscal 26 levels. We will continue to monitor our costs and share regular updates about the impact. Turning to guidance. At the end of the third quarter, two sales leaders departed the company. We already appointed a replacement for one of these leaders and we are in the late stages of hiring a leader for the other role. However, we are taking a prudent approach to our guidance during this transition. Let me provide our outlook for Q4 and full year fiscal 26. As a reminder, these numbers are all on a non-GAAP basis. For the fourth quarter, we expect revenue of $875 million to $878 million, reflecting approximately 22% year over year growth, gross margin of approximately 80%, operating profit of $206 million to $208 million and operating margin of approximately 30% to 31% year over year, net other income of approximately $24.5 million and earnings per share of approximately $1.08 to $1.09 per share, assuming a 21% tax rate and 168 million fully diluted shares. For the full year fiscal 26, we expect ARR of $3.74 billion to $3.75 billion or year over year growth of approximately 24%. This guidance implies net new ARR growth excluding Red Canary of approximately 9.5%. For Red Canary, we expect ARR of $137 million in fiscal 26, up from our prior guidance of $130 million with net new ARR of $10 million in Q4. This includes all the business expected in each period, including fiscal 26 renewals, upsells, and new logos. Revenue of $3.33 billion to $3.34 billion reflecting year over year growth of 24.6% to 24.7%. We expect Red Canary revenue of approximately $137 million in fiscal 26, up from our prior guidance of $125 million. Operating profit of $755 million to $757 million, up approximately 30% year over year, up from our prior guidance of $742 million to $748 million. Earnings per share of $4.10 to $4.11, assuming a 21% tax rate and 168 million fully diluted shares, and free cash flow margin of approximately 22.8% to 23.3%, down from our prior expectations of 26.5% to 27%, reflecting CapEx in the high single digits as a percentage of revenue. Looking to fiscal 27, I would like to provide some early look to better align expectations heading into our second year with ARR as our primary growth metric and following the acquisition of Red Canary. Sitting here today, our view is for total ARR and revenue growth for fiscal 27 of 16% to 17%. Looking ahead, we are excited by the opportunities we see to continue scaling our rapidly expanding AI security portfolio, accelerating Zero Trust Everywhere adoption, and growing our data security revenue. In summary, we are pleased with the results we delivered year to date in fiscal 26. We achieved 25% year over year ARR growth and record operating income. We also saw continued momentum with Z-Flex, and closed a record number of $1 million-plus ARR deals for Q3. The opportunity ahead of us is substantial, and we are confident in our ability to continue driving profitable growth across multiple vectors including product innovation, go-to-market, and customer expansion, and creating value for our shareholders. I want to thank our employees, customers, and partners for their continued support.
分析師問答
With that, you may now open the call for questions. To ask a question during the session, press 1 on your telephone. To remove yourself from the queue, press *1 again. Please limit yourself to one question then return to the queue.
Great. Thank you so much. Lot of strong proof points in these results. Maybe a compound question since you are limiting me to one for both Jay and Kevin. I am just trying to better understand the sales leadership turnover that you highlighted. Jay, if you can comment at all whether these positions, the turnover was voluntary or involuntary, how senior they were, and why this could have an impact when you have such a mature and resilient sales organization. And then maybe for Kevin, on the same topic, is the pipeline there, and you are just assuming a lower close rate, what would your guidance have been if these leaders were still in place? Thanks so much.
Hey Brad. Thank you. So regarding the sales leadership changes, these two leaders were part of our CRO, Mike Rich's team. And it is true that Mike has built a strong bench and a strong sales engine. We just want to improve on it. As these changes are made, it could have impact in the short term, and that is what we are keeping in mind.
Yeah. Thanks, Jay, and thanks, Brad. I do not have much more to offer other than we are taking a prudent approach. We do recognize when leaders of this nature change that it can have some disruptive effects to those organizations. So I am taking a prudent approach to how we think about those changes. Thanks, Brad.
And the only other thing I will add, Brad, is that there will be changes in leadership from time to time. Regarding these two, we have already appointed an internal replacement for one of them, and for the second we are making progress and expect to close that in the near future as well.
That is helpful. Thanks so much for taking the question.
Our next question comes from the line of Saket Kalia of Barclays. Your line is open, Saket.
Okay, great. Hey, guys. Thanks for taking my question here. Kevin, maybe for you, can we just speak to how big—if we exclude that deal, the eight-figure federal deal here in Q3—how do we maybe feel about the underlying flow business? Whether it is new or renewals, again, excluding that large deal which was great to see, I am just curious how you look at the business if we exclude it, if we could size that.
Thanks, Saket. At the highest levels, we delivered a strong quarter and I think we are very pleased with the results of the business. As it relates to the eight-figure upsell that I called out, keep in mind that these contract wins as you see them get reported are TCV, and a large part of that deal was also renewals. So that is already preexisting in ARR as you think about that particular deal you are querying.
And Saket, to add, these are unusually large deals and we point them out. So nothing unusual about this.
Very helpful. Thank you.
Our next question comes from the line of Joshua Tilton of Wolfe Research. Please go ahead, Joshua.
Hey, guys. Thanks for sneaking me in here. Appreciate the early look for the numbers next year. When you look at the growth and kind of what it implies for net new ARR, you guys are kind of calling flat on an organic basis from the guide for this year. Can you kind of help us maybe think about the moving pieces between where that is coming from, whether that is traditional Zscaler business or Red Canary? Or just any color to help us think about the trajectory of organic net new ARR next year in that guide? Thank you very much.
I'll start and Jay can append. First, we have a strong track record of upsells and I expect that to continue into 2027. We shared that we had a net retention of 115% in Q1 and that has been fairly stable over the last several quarters. The area where we have not been performing as well as we'd like is new logo acquisition; it is a large priority for us, but I took a tempered view of new logos going into 2027. Lastly, as we think about Red Canary's contributions, we will be rolling out an integrated SecOps solution that we would expect to be available in 2027. What I do not know is the pace of uptake among existing customers for that. So as a result, for Red Canary we are expecting net new ARR to grow at a slower rate than the overall business in 2027 as you think about modeling. Also keep in mind Red Canary will be included in our results going into next year and will be fully baked into 2027, so we will not be providing separate disclosure of Red Canary in 2027.
If I may add, we already covered that sales leadership turnover is part of our thinking to make sure you understand it may have some impact. But if you look at the overall market opportunity, there is strong demand. Every CIO and CISO I talk to is talking about protecting their environments. While finding new software vulnerabilities and patching is important, customers already have many vulnerabilities. The number one protections they are looking at are hiding their attack surface and implementing Zero Trust access. We fairly uniquely provide those things. So while we were prudent in our forecast, the need for Zscaler today is probably far greater than it has ever been.
Super helpful, guys. Thank you.
Our next question comes from the line of Gregg Moskowitz of Mizuho. Please go ahead, Gregg.
Great. Thank you very much for taking the question. You did very well this quarter in the Americas and APJ, although growth in Europe slowed. What are you guys seeing in Europe? And then just wondering if you had any commentary on the competitive environment both in the Americas and in Europe. Thank you.
If you think about the overall competitive environment, I do not think things are very different in Europe than the rest of the world. You may see from time to time one geography do better in a given quarter and another do better in another quarter. We know some areas of execution we need to improve, we are focused on those, and I am confident we will turn around and make EMEA a higher-growth area.
Okay. Thank you.
Our next question comes from the line of Gabriela Borges of Goldman Sachs. Your line is open, Gabriela.
Hi, good afternoon. Thanks for the question. Kevin, you mentioned something interesting when you were talking about the outlook for next year, which is that new logo growth may be tempered. So either for yourself or for Jay, maybe just give us a sense: when you dig beneath what is going on with the sales relationships and with the customer pipeline, why do you think new logo growth is tempered? Thank you very much.
Thanks, Gabriela. Just to clarify, I was not trying to suggest that new logo growth is necessarily shrinking. What I intended to convey is that my expectations for the early look into next year took a tempered approach to how we thought about the contributions of new logos. New logos are a strategic focus of ours and will continue to be as we go into 2027. I'm providing an early look here far earlier than we would normally do, and so as I looked at what we had in front of us in terms of the different components of the business, that was one area where I thought we can do better.
If I may add, there is a sizable new logo opportunity for us. We have 4.5 thousand enterprise customers with over 2,000 user seats, and that is only a portion of the addressable market. That means a sizable market for us to go after.
Thank you for the color.
Our next question comes from the line of Brian Essex of JPMorgan. Your line is open, Brian.
Jay, if I could maybe ask you to peel back the layers a little bit on the impact of Meta's and OpenAI's models. We are hearing from some channel providers that c-suite executives at enterprises are, to use their words, freaking out over the emergence of these models and the realization of how robust they are. So when you comment about tailwinds in your business from the emergence of foundation models, how do you see that materializing in your pipeline? It sounds like the consultants are very busy right now, but given typical sales cycles and architectural decisions involved with adopting your Zero Trust platform, when might we expect to see impact to pipeline, revenue, billings, and so forth? How is this materializing in your conversations? Thank you.
It is a very important question, Brian. I have never seen so many inbound calls come in so quickly. I received so many calls that I decided to say we will reach out and figure out a programmatic way of engaging with them. We all know customers are very concerned and they are looking for help. Many vendors are taking the approach of helping customers find more vulnerabilities and patch them. While patching is reasonable, we do not think patching alone is sufficient because you will never be done patching. Our recommendations are straightforward: hide your applications and enforce Zero Trust access. Those are fundamental things that need to be done, and that is what we are helping our customers with. We also know this is an area where we need to help customers in a consultative fashion rather than ambulance chasing. We are engaging with them to help them get out of tough situations and keep their boards and CEOs apprised. We are not factoring in any meaningful impact of these new opportunities for Q4, but I do believe we will have impact in fiscal 27. As for specifics: many customers have ZIA broadly deployed for users, but ZPA private access is only for a subset of users. Now they want Zero Trust access for everyone from every location, even from headquarters. So there is increasing interest for ZPA upsell. We have very capable deception technology customers want because they know with all this happening there will be more breaches and they want to catch attackers red-handed using deception and micro-segmentation. That is why I said Zero Trust has never been more important.
Thank you.
Next question comes from the line of Meta Marshall of Morgan Stanley. Please go ahead, Meta.
Great. Thanks. Maybe building on a couple of the questions: as you think about signposts for improvements on the new logo side, will that come from GSI channel outreach, the expansion you are doing, new leadership, flexible pricing? Just trying to get a sense of what you think is most incremental to improve new logos. Thanks.
Meta, thank you. We have pretty specific plans that will be important for fiscal 27. Number one, we have limited coverage in the lower end of the enterprise market, generally between 2,000 to 10,000 users; adding more salespeople in that part of the market where coverage is less is important. Number two, the VAR channel plays an important role in the low end of the market, so we are creating specific programs and incentives for new logo acquisition in that area. Number three, GSIs are natural partners for large enterprises, and we are teaming with them—for example, the AI Guardian program. Number four, we have a program for major accounts where we will focus on getting new logos in addition to working on upsell. We feel good about the opportunities to engage and add incentives to drive more new logo activity.
Thanks. Appreciate it.
Our next question comes from the line of Ittai Kidron of Oppenheimer and Company. Your line is open, Ittai.
Thanks. I appreciate it, guys. Kevin, I just want to make sure I get my bearings right around the ARR commentary. Taking into account your revised guidance for the year and your preliminary view into next year, it looks like Q4 net new ARR is decelerating, and it seems like growth may be returning to mid-single digits next year. So another deceleration. Outside of the sales leadership that you talked about, are there any other elements to take into account here with respect to this? You know, you guys have made a lot of work over the last couple of years turning around the salesforce. I understand when two leaders leave, disruption can happen. I'm just wondering if that is the only element impacting net new ARR here or if there are other things to consider. Thank you.
Thanks for the question. Two factors I mentioned are relevant. One is the departure of two leaders under Mike, which can cause some disruption and we are taking a prudent approach. The other is the pace of uptake with the integrated SecOps products from Red Canary. As we think about how that rolls out and the pace of uptake, I am also taking a prudent approach. As it relates to Q4, the guide implies 9.5% net new ARR growth on an organic basis excluding Red Canary, and keep in perspective that is still an acceleration over last year's performance.
Appreciate it.
Our next question comes from the line of Eric Suppiger of B. Riley Securities. Your line is open.
Yes, thanks for taking the question. On that outlook for fiscal 27, I think you had commented last quarter that the ZIA and ZPA core products were growing in the mid-teens. What growth assumption are you assuming as you look out to 2027 on those core products?
Thanks for the question. It is a bit early and fairly granular. What I can say is we have continued to see consistent performance this year within the ZIA and ZPA product lines, but we did not provide that level of granularity into next year.
If I may add, questions about core products versus non-core products can make them sound like separate buckets, but our customers are asking for Zero Trust Everywhere. We started with Zero Trust for users—ZIA and ZPA—and now they're moving to Zero Trust for cloud workloads, Zero Trust for branches, and Zero Trust for devices. Our focus is to work with customers to do Zero Trust Everywhere, which is a big differentiation and an opportunity to sell larger, more comprehensive deals.
Thank you.
Our next question comes from the line of Adam Borg of Stifel. Please go ahead, Adam.
Awesome. Thanks for taking the question. Maybe just on Symmetry Systems—I'd love to learn more about what that brings to you that you could not do previously around securing AI agents, and given their access graph technology, how are you thinking about movement to identity security more broadly? And maybe a quick follow-up: any color on Symmetry and Square X in terms of contribution to revenue and ARR?
First, Symmetry has built very innovative technology. The problem statement is not basic identity. We believe the identity of agents will largely come from hyperscalers or large software companies that provide platforms to build agents; they are the natural place to build identities. We have always taken the approach of being a Switzerland where we will take identity from different corners. Symmetry pioneered identity mapping to data sources. In a large enterprise, identities—users, workloads, machines—access data sources that may be scattered. Do you know who is accessing what, when, and where? Information sits in many application logs. Symmetry pulls that information together and creates a visual access graph. This was a hard problem solved by a team of experts. Once you understand who talks to whom, this solution can be used to enforce policy on our agentic Exchange that we are building. So it is very complementary and forward-looking technology. This is the kind of work most companies are not thinking about. Zscaler has always taken pride in being innovative and building solutions others have not. Our Zero Trust Exchange is being extended to secure agents, and Symmetry becomes a very useful piece to differentiate our Exchange and provide value for data governance and policy enforcement for our customers.
That is really helpful. And Kevin, any color on Symmetry and Square X contribution to top-line? Thanks again.
Of course. To level set, Symmetry is a technology and talent acquisition. Their ARR is immaterial and in the low single digits. Square X was also incredibly immaterial.
Appreciate the color. Thanks again.
Our next question comes from the line of Fatima Boolani of Citi. Please go ahead, Fatima.
Thank you for taking my question. Kevin, on the commentary with respect to opportunities to step on the gas pedal vis-à-vis new logo acquisition, and in the context of the sales leadership transition, can you give us quantitative color on sales productivity this year and some of your expectations as you think about the complexion of the 16% to 17% growth guide? Specifically, I'd love more quantitative color on sales productivity, sales attrition, and sales hiring that you are thinking about in terms of pipeline build and conversion assumptions. Thank you.
Thanks for the question. For Q3, this was our sixth straight quarter of sales productivity growth, even on the back of some tough comps. We are pleased with the level of productivity and continued improvement we have seen. I would expect going into fiscal 27 that we will continue to drive productivity and add capacity. I caution that it is early to provide a precise quantification of how that rolls into an early look for 2027.
Our next question comes from the line of Gray Powell of BTIG. Please go ahead, Gray.
Great. Thanks for taking the question. Maybe just one on the competitive front: from a technology perspective, how are you staying ahead of firewall vendors who are increasingly trying to upsell Secure Service Edge into your installed base? When you displace legacy vendors, is there a common driver—particular features or the overall platform superiority? Any color would be helpful.
It is pretty simple. If you care about real cyber protection, you need a Zero Trust architecture. Firewalls create a trusted network, and trusted networks enable lateral movement. Our customers understand that. They started with Zero Trust for users and now want Zero Trust for branches where each branch becomes segmented. Firewalls do not prevent lateral movement across the network. They want Zero Trust for devices and workloads as well. Workloads have been traditionally secured by old firewall technology with east-west and north-south rules; we secure them in a Zero Trust fashion. We are on a path to take our customers to Zero Trust Everywhere. That architectural difference—not just feature A or feature B—is our biggest differentiator.
Okay. Thank you very much.
Our next question comes from the line of Andrew DeCasperi of BNP Paribas. Your line is open, Andrew.
Thanks for taking my question. I wanted to ask about the comments on the CapEx guidance. Given you put through a price increase earlier this year and costs have gone even higher, are you considering potentially doing the same around pricing again maybe at the same time next year?
I'll start. We are constantly looking at the balance among pricing, margin, and market dynamics and feel pretty good about where we are. We did push through a price increase earlier this year and have not seen adverse implications. Hardware costs have gone up, and we periodically review pricing where we have an opportunity to increase. I would not commit today that there will be another price change at this time next year; it is something we will evaluate dynamically.
This situation is fairly unique and driven by AI data center demand causing shortages in many parts. As Kevin said, we will look at it from time to time, but this is a special factor everyone is recognizing and adjusting for.
Thank you.
I would now like to turn the conference back to Jay Chaudhry for closing remarks. Sir?
Thank you for joining us for the earnings call. We look forward to seeing you at one of the upcoming investor conferences. Thank you again.
This concludes today's conference call. Thank you for participating. You may now disconnect. Goodbye.