CrowdStrike Holdings Inc Stock price
Compare with Peer Group
📊 Peer Group
📈 What is it?
The peer group consists of the companies with the most similar business model. They serve as a benchmark for putting a stock into context.
🧮 How is it selected?
Based on similarity of business model, meaning companies from the same industry with comparable products and a similar customer base. That's the only way to compare apples to apples.
🏛️ Why does it matter?
Whether a stock is cheap or expensive is best judged by comparison. A P/E of 18 or an EV/FCF of 20 can look cheap or expensive depending on the yardstick. The peer group gives you the most accurate one: companies with a similar business model that operate under the same conditions.
🎯 What does it mean for investors?
When a metric sits below the peer average, the stock is valued more cheaply relative to its competitors, and above the average more expensively. A discount to the peer group can be an opportunity, but it can also have a reason (for example lower growth). The comparison is a starting point, not a verdict.
AI Insights on CrowdStrike Holdings Inc
Insights
Invest better with AI
StocksGuide Unlimited – full access to AI analyses
👉 More detailed insights
👉 Exclusive perspectives on opportunities & risks
👉 Clear answers to your questions
Invest better with AI
StocksGuide Unlimited – full access to AI analyses
👉 More detailed insights
👉 Exclusive perspectives on opportunities & risks
👉 Clear answers to your questions
Invest better with AI
StocksGuide Unlimited – full access to AI analyses
👉 More detailed insights
👉 Exclusive perspectives on opportunities & risks
👉 Clear answers to your questions
Invest better with AI
StocksGuide Unlimited – full access to AI analyses
👉 More detailed insights
👉 Exclusive perspectives on opportunities & risks
👉 Clear answers to your questions
Create a Free Account to create an CrowdStrike Holdings Inc alert.
Set up alerts on Stock Price, Dividend Yield, Valuation (e.g. P/E or EV/Sales) or Strategy Scores and sit back and relax.
StocksGuide Free
Key metrics
📘 Market Capitalization
📈 What is it?
Market capitalization shows how much a company is currently worth on the stock market.
🧮 How is it calculated?
🏛️ Why is it important?
It helps classify companies by size (Large, Mid, Small Cap) and indicates their market presence and relative stability.
🧮 Calculation
🎯 What does this mean for investors?
- Large-cap companies tend to be more stable, often pay dividends, but may grow more slowly.
- Smaller firms may offer higher growth potential but come with more volatility.
- Market capitalization is a useful indicator of company size — but not a measure of whether a stock is undervalued or overvalued.
📘 Enterprise Value (EV)
📈 What is it?
Enterprise Value represents the total cost to acquire a company — including its debt and excluding its cash reserves.
🧮 How is it calculated?
(= Market Cap + Net Debt)
🏛️ Why is it important?
EV gives a more complete picture of a company's value than market cap alone and is used in key valuation ratios like EV/FCF or EV/Sales.
🧮 Calculation
🎯 What does this mean for investors?
- Enterprise Value shows the true cost of buying a company, including all financial obligations.
- It is more accurate than just looking at market cap, especially when comparing companies with different levels of debt or cash.
- Professional investors prefer EV-based multiples because they better reflect the company’s full financial footprint.
📘 Net Debt
📈 What is it?
Net Debt shows how much debt remains after subtracting a company’s available cash reserves.
🧮 How is it calculated?
🏛️ Why is it important?
It indicates how dependent a company is on borrowed money and how easily it can service its debt in the short term.
🧮 Calculation
🎯 What does this mean for investors?
- Low or negative net debt signals financial strength and flexibility.
- Companies with strong cash positions are better positioned in crises.
- High net debt increases financial risk — especially in environments with rising interest rates or economic downturns.
📘 Cash
📈 What is it?
Cash represents all liquid assets a company can access immediately — including cash, bank deposits, and short-term investments.
🧮 How is it calculated?
🏛️ Why is it important?
It reflects a company’s financial flexibility and resilience — enabling investments, buybacks, or buffer in downturns.
🧮 Calculation
🎯 What does this mean for investors?
- A strong cash position means greater room for maneuver and crisis resistance.
- Cash-rich companies can invest, pay down debt, or repurchase shares.
- But excess idle cash might indicate a lack of growth opportunities.
📘 Shares Outstanding
📈 What is it?
Shares outstanding represent the total number of a company’s shares currently held by investors — excluding treasury stock.
🧮 How is it calculated?
🏛️ Why is it important?
It’s the basis for key metrics like Earnings Per Share (EPS), Market Capitalization, or the Price/Earnings ratio (P/E).
🧮 Calculation
🎯 What does this mean for investors?
- Fewer shares in circulation typically increase earnings per share — making each share more valuable.
- Share buybacks reduce the number of shares and boost per-share metrics.
- Issuing new shares does the opposite — diluting shareholder value and lowering per-share figures.
📘 Price-to-Earnings Ratio (P/E)
📈 What is it?
The P/E ratio shows how many times a company's earnings per share are reflected in its current share price — in other words, how "expensive" the stock appears relative to its profits.
🧮 How is it calculated?
🏛️ Why is it important?
The P/E ratio is one of the most widely used valuation metrics. It helps investors assess whether a stock appears cheap or expensive compared to its earnings power.
🧮 Calculation
📊 P/E (TTM) = Based on earnings from the last 12 months (Trailing Twelve Months):🎯 What does this mean for investors?
- A low P/E may indicate undervaluation — or signal underlying issues.
- A high P/E may reflect strong growth expectations — or an overvalued stock.
📘 Price-to-Sales Ratio (P/S)
📈 What is it?
The P/S ratio shows how much investors are paying for $1 of the company’s revenue – regardless of profitability.
🧮 How is it calculated?
🏛️ Why is it important?
P/S is especially useful for evaluating growth companies or businesses not yet profitable. It reflects how the market values the company’s sales.
🧮 Calculation
Market Cap = $247.14b | Revenue (TTM) = $5.40b
Market Cap = $247.14b | Estimated Revenue = $6.12b
🎯 What does this mean for investors?
- A low P/S may indicate undervaluation — or low profitability.
- A high P/S can reflect strong growth expectations — or excessive optimism.
- Especially helpful when evaluating companies where profits are low, volatile, or negative.
📘 Enterprise Value to Sales (EV/Sales)
📈 What is it?
EV/Sales shows how much investors are paying for $1 of revenue — considering not just equity, but also debt and cash. It’s the capital structure–adjusted version of the P/S ratio.
🧮 How is it calculated?
🏛️ Why is it important?
It’s ideal for comparing companies with different levels of debt. It reflects a company's true cost relative to its revenue.
🧮 Calculation
Enterprise Value = $243.33b | Revenue (TTM) = $5.40b
Enterprise Value = $243.33b | Forward Revenue = $6.12b
🎯 What does this mean for investors?
- EV/Sales allows for capital structure–neutral company comparisons.
- A lower ratio may indicate undervaluation; a higher one may signal strong growth expectations or overvaluation.
- Especially helpful when evaluating high-growth companies with low or negative earnings.
📘 Enterprise Value to Free Cash Flow (EV/FCF)
📈 What is it?
EV/FCF shows how many years it would take for a company to "pay back" its enterprise value using its free cash flow.
🧮 How is it calculated?
🏛️ Why is it important?
It focuses on real cash generation, ignoring accounting noise — ideal for assessing profitability and value based on liquidity, not earnings.
🧮 Calculation
🎯 What does this mean for investors?
- A low EV/FCF may signal undervaluation and strong cash generation.
- A high EV/FCF might reflect weak recent cash flow or aggressive growth expectations.
- Best suited for stable, mature businesses with predictable free cash flows.
📘 Price-to-Book Ratio (P/B)
📈 What is it?
The P/B ratio compares a company’s market value to its book value — showing how much investors are paying for each dollar of net assets.
🧮 How is it calculated?
🏛️ Why is it important?
P/B is commonly used for asset-heavy industries like banks or industrials. It helps assess whether a stock is trading above or below its net asset value.
🧮 Calculation
🎯 What does this mean for investors?
- A P/B below 1 may signal undervaluation — or weak profitability.
- A P/B above 1 implies the market expects future value creation (e.g., brand, IP, growth).
- Best used for companies with tangible assets and strong balance sheets.
📘 Equity Ratio
📈 What is it?
The equity ratio indicates what portion of a company’s total assets is financed by shareholders’ equity – in other words, how much it relies on its own capital.
🧮 How is it calculated?
🏛️ Why is it important?
A high equity ratio reflects financial strength and stability, especially during downturns. It’s a key indicator of a company’s solvency and long-term risk profile.
🧮 Calculation
🎯 What does this mean for investors?
- Companies with high equity ratios are generally more resilient and less dependent on external debt.
- Low equity ratios can signal higher risk or aggressive financial strategies.
- Important: Always assess the equity ratio in combination with the return on equity (ROE). This shows not just how stable the company is – but also how efficiently it uses shareholder capital.
📘 Return on Equity (ROE)
📈 What is it?
Return on equity (ROE) shows how efficiently a company uses its shareholders’ equity to generate profit. In other words: how much net income is earned per dollar of equity.
🧮 How is it calculated?
🏛️ Why is it important?
ROE is a core profitability metric. It helps investors understand whether a company delivers attractive returns on the capital provided by its shareholders.
🧮 Calculation
🎯 What does this mean for investors?
- A high ROE indicates that the company is using its capital efficiently and profitably.
- It’s especially meaningful for capital-intensive businesses or firms with high equity bases.
- Important: A very high ROE can also result from high debt levels – always interpret it alongside the equity ratio to assess financial health.
📘 Return on Capital Employed (ROCE)
📈 What is it?
ROCE measures how efficiently a company generates profits from its total capital – including both equity and interest-bearing debt.
🧮 How is it calculated?
It evaluates the return on all capital employed, regardless of how it’s financed.
🏛️ Why is it important?
ROCE is ideal for comparing companies with different financing structures. It shows how well management uses capital to create value for both shareholders and creditors.
🧮 Calculation
🎯 What does this mean for investors?
- A high ROCE means the company uses its capital efficiently – regardless of whether it's funded by debt or equity.
- The higher the ROCE compared to peers, the more value the company creates with its invested capital.
- Especially relevant for capital-intensive sectors like industrials, energy, or infrastructure.
📘 Return on Invested Capital (ROIC)
📈 What is it?
ROIC measures how efficiently a company generates returns from the capital invested in its core operations – regardless of whether the capital comes from equity or debt.
🧮 How is it calculated?
- NOPAT = Net Operating Profit After Taxes
- Invested Capital = Operating assets minus non-interest-bearing liabilities
🏛️ Why is it important?
ROIC is one of the most accurate indicators of capital efficiency. Unlike return on equity, it is not distorted by leverage and shows how much value is created for all capital providers.
🧮 Calculation
🎯 What does this mean for investors?
- A high ROIC shows how effectively a company uses the capital that is truly invested in its core operations.
- Unlike ROCE, ROIC focuses only on the capital that is actively used to run the business – and that requires a return (i.e. interest-bearing).
- Especially useful when comparing companies with large amounts of excess cash or non-interest-bearing liabilities – giving a more realistic picture of capital efficiency.
📘 Leverage Ratio (Debt-to-Equity)
📈 What is it?
The leverage ratio indicates how much a company relies on interest-bearing debt (such as loans and bonds) relative to its shareholders’ equity.
🧮 How is it calculated?
🏛️ Why is it important?
This ratio helps assess a company’s financial structure and risk profile. High leverage can enhance returns – but also increases exposure to interest rate changes and financial stress.
🧮 Calculation
🎯 What does this mean for investors?
- A low leverage ratio signals financial strength and independence.
- A higher ratio can improve returns in good times but increases risk during downturns or rising interest rate periods.
- 👉 Always interpret in the context of industry, capital intensity, and interest rate environment.
📘 Revenue
📈 What is it?
Revenue shows how much a company earns in total from selling its products and services – the gross income before any costs are deducted.
🧮 How is it calculated?
🏛️ Why is it important?
Revenue is one of the key figures to assess a company’s size, market position, and growth potential.
🧮 Calculation
🎯 What does this mean for investors?
- Growing revenue indicates rising demand and can be an early signal of future earnings growth.
- Comparing actual and expected revenue reveals trends in the market environment and analyst sentiment.
- Note: Strong revenue alone isn’t enough – margins and profitability matter just as much.
📘 EBITDA
📈 What is it?
EBITDA stands for “Earnings Before Interest, Taxes, Depreciation, and Amortization.” It reflects a company’s operating profit before the effects of financing, taxes, and accounting depreciation.
🧮 How is it calculated?
🏛️ Why is it important?
EBITDA is widely used to evaluate a company’s operating performance – especially across capital-intensive sectors or international comparisons.
🧮 Calculation
🎯 What does this mean for investors?
- A high or growing EBITDA indicates strong operational profitability – independent of taxes, interest, or accounting methods.
- It’s especially useful for comparing companies across sectors or geographies.
- Important: EBITDA is not a net income figure – it excludes key costs like depreciation and interest.
📘 EBIT
📈 What is it?
EBIT stands for “Earnings Before Interest and Taxes.” It reflects a company’s operating profit after depreciation, but before interest and tax expenses.
🧮 How is it calculated?
🏛️ Why is it important?
EBIT is a core profitability metric that shows how well the company performs in its main business operations – independent of capital structure and tax environment.
🧮 Calculation
🎯 What does this mean for investors?
- A high EBIT indicates strong profitability from the company’s core business – before financial and tax effects.
- It allows better comparison between companies with different debt levels or tax structures.
- Compared to EBITDA, EBIT already accounts for depreciation and reflects capital intensity more clearly.
📘 Net Income
📈 What is it?
Net income is the company’s total profit – the amount left after all expenses, taxes, interest, and depreciation have been deducted.
🧮 How is it calculated?
🏛️ Why is it important?
Net income is the most comprehensive measure of a company’s profitability – showing how much actual profit remains after all business and financing costs.
🧮 Calculation
🎯 What does this mean for investors?
- Growing net income indicates that the company is managing all of its costs efficiently.
- It directly influences valuation metrics like P/E ratio and the company’s dividend capacity.
- Over time, net income trends reveal how resilient and profitable the business model really is.
📘 Free Cash Flow (FCF)
📈 What is it?
Free Cash Flow shows how much actual cash remains after a company covers its operating expenses and capital expenditures.
🧮 How is it calculated?
🏛️ Why is it important?
FCF reflects a company’s real financial strength – regardless of accounting profits. It shows how much flexibility a company has for dividends, share buybacks, or debt reduction.
🧮 Calculation
🎯 What does this mean for investors?
- High free cash flow means the company generates real, usable cash – independent of reported net income.
- It’s often the most reliable base for sustainable dividends and buybacks.
- Declining FCF can be an early warning sign – even when profits appear stable.
📘 Revenue Growth
📈 What is it?
Revenue growth shows how much a company’s sales have changed compared to the previous year – both on a trailing basis (TTM) and based on forward projections.
🧮 How is it calculated?
Forward = (Expected revenue ÷ Revenue in prior year − 1) × 100
Forward growth is based on analyst estimates for the current fiscal year.
🏛️ Why is it important?
Rising revenue signals growing demand, business expansion, and market share gains – especially important for growth-oriented companies.
🧮 Calculation
🎯 What does this mean for investors?
- Growth is the engine of long-term value creation – especially in tech and growth sectors.
- What matters is not just current growth, but its sustainability.
- Forward projections reflect whether analysts expect continued momentum – or a slowdown.
📘 EBITDA Growth
📈 What is it?
EBITDA growth shows how much a company’s operating profit (before interest, taxes, depreciation, and amortization) has increased or decreased compared to the previous year.
🧮 How is it calculated?
Forward = (Expected EBITDA ÷ EBITDA from prior year − 1) × 100
The forward estimate is based on analyst projections for the current fiscal year.
🏛️ Why is it important?
Growing EBITDA indicates improving operational profitability – regardless of financing or accounting effects.
🧮 Calculation
🎯 What does this mean for investors?
- Strong EBITDA growth signals operational efficiency and scalability – especially during growth phases.
- EBITDA growth can be an early indicator of margin and earnings expansion – but should be assessed alongside revenue and EBIT.
📘 EBIT Growth
📈 What is it?
EBIT growth shows how much a company’s operating profit (after depreciation, but before interest and taxes) has increased compared to the previous year.
🧮 How is it calculated?
Forward = (Expected EBIT ÷ EBIT from prior year − 1) × 100
The forward estimate is based on analyst projections for the current fiscal year.
🏛️ Why is it important?
EBIT growth is a direct indicator of a company’s business performance – taking into account capital intensity through depreciation.
🧮 Calculation
🎯 What does this mean for investors?
- Rising EBIT signals improving operating profitability – even after accounting for depreciation.
- It’s especially important for evaluating companies with significant capital expenditures.
- Combined with revenue and EBITDA growth, EBIT growth provides a well-rounded view of operational progress.
📘 Net Income Growth
📈 What is it?
Net income growth shows how much a company’s bottom-line profit has increased or decreased compared to the previous year – both on a trailing basis (TTM) and based on analyst projections.
🧮 How is it calculated?
Forward = (Expected net income ÷ Net income from prior year − 1) × 100
The forward estimate reflects analysts’ expectations for the current fiscal year.
🏛️ Why is it important?
Net income is the ultimate measure of profitability. Growing net income signals stronger efficiency, cost control, and sustainable earnings power.
🧮 Calculation
🎯 What does this mean for investors?
- Stronger net income boosts valuation, dividend potential, and investor confidence.
- If profits stall while revenue grows, it may signal margin pressure.
📘 Free Cash Flow Growth
📈 What is it?
Free cash flow (FCF) growth shows how a company’s available cash – after covering operating expenses and capital expenditures – has changed compared to the previous year.
🧮 How is it calculated?
🏛️ Why is it important?
Free cash flow reflects real financial strength. Growing FCF indicates more flexibility for dividends, share buybacks, and reinvestment.
🧮 Calculation
🎯 What does this mean for investors?
- Declining FCF may point to rising investments, increasing costs, or weaker operating performance.
- Especially for dividend investors, FCF growth is critical – since dividends are paid from actual available cash.
- A negative trend isn't always bad, but it deserves closer attention.
📘 Gross Margin
📈 What is it?
Gross margin shows how much of a company’s revenue remains after deducting the direct costs of goods sold (like materials and production). It represents the company’s “raw profit” before fixed costs, taxes, and interest.
🧮 How is it calculated?
Or simply: Gross Margin = Gross Profit ÷ Revenue × 100
🏛️ Why is it important?
Gross margin indicates how efficiently a company can produce or procure what it sells. It is a key measure of product-level profitability and pricing power.
🧮 Calculation
🎯 What does this mean for investors?
- A high gross margin suggests strong pricing power and efficient production.
- Falling margins may signal rising input costs or competitive pressure.
- Compared to peers, gross margin offers insights into the quality of a business model.
📘 EBITDA Margin
📈 What is it?
The EBITDA margin shows how much of a company’s revenue remains as operating profit before interest, taxes, depreciation, and amortization.It reflects operating efficiency without being distorted by financing or accounting factors.
🧮 How is it calculated?
🏛️ Why is it important?
The EBITDA margin reveals how much operating income a company generates per dollar of revenue – independent of capital structure and tax effects.
🧮 Calculation
🎯 What does this mean for investors?
- A high EBITDA margin reflects strong core profitability – before accounting distortions.
- It allows for effective comparisons across companies and sectors.
- A stable or growing margin signals efficient cost control and business scalability.
📘 EBIT Margin
📈 What is it?
The EBIT margin shows what percentage of revenue remains as operating profit after depreciation but before interest and taxes.
🧮 How is it calculated?
🏛️ Why is it important?
The EBIT margin reflects a company’s core profitability while accounting for capital intensity (e.g. machinery, infrastructure). It’s especially useful for comparing businesses with different levels of depreciation.
🧮 Calculation
🎯 What does this mean for investors?
- A high EBIT margin shows that the company remains efficient even after factoring in depreciation.
- It’s especially relevant for capital-intensive industries.
- Stable or rising EBIT margins over time are a strong indicator of pricing power and business quality.
📘 Net margin
📈 What is it?
Net margin shows how much of a company’s revenue remains as bottom-line profit after deducting all costs, interest, taxes, and depreciation.
🧮 How is it calculated?
🏛️ Why is it important?
Net margin reflects a company’s overall efficiency – across operations, financing, and taxation. It shows how much actual profit is generated from each dollar of revenue.
🧮 Calculation
🎯 What does this mean for investors?
- A high net margin means the company is not only strong operationally but also manages financing and taxes efficiently.
- Peer comparisons reveal business quality and competitiveness.
- Declining margins despite revenue growth can be a red flag for rising costs or inefficiencies.
📘 Free cash flow margin
📈 What is it?
The free cash flow (FCF) margin shows how much of a company’s revenue remains as actual free cash after covering all operating expenses and capital expenditures.
🧮 How is it calculated?
🏛️ Why is it important?
This margin reflects the true liquidity generated by the business – independent of accounting rules or depreciation. It’s especially relevant for dividends, buybacks, and reinvestment decisions.
🧮 Calculation
🎯 What does this mean for investors?
- A high FCF margin means a company consistently generates strong cash flow.
- It’s a positive signal for financial stability and shareholder returns.
- The long-term trend is key – a declining margin may indicate rising investments or weakening operating efficiency.
📘 Earnings per share (EPS)
📈 What is it?
Earnings per Share (EPS) shows how much profit is attributable to a single share – and is one of the most important metrics for evaluating a company's performance.
🧮 How is it calculated?
The diluted share count reflects potential new shares that could be issued through options, convertible bonds, or other rights.
🏛️ Why is it important?
EPS is the basis for many key valuation metrics like P/E ratio, PEG ratio, or payout ratio. It enables comparisons of profitability across companies, regardless of their size.
🧮 Calculation
🎯 What does this mean for investors?
- EPS captures per-share profitability and is especially useful for comparisons over time or with analyst estimates.
- Rising EPS may signal consistent growth or share buybacks.
- Important: Always use diluted EPS for more realistic valuations – especially in companies with stock-based compensation.
📘 Free cash flow per share (FCF per share)
📈 What is it?
Free Cash Flow per Share shows how much free cash flow a company generates per outstanding share – after investments, but before dividends or debt repayments.
🧮 How is it calculated?
Free cash flow is calculated as operating cash flow minus capital expenditures (CapEx).
🏛️ Why is it important?
FCF per Share reveals how much real cash is available per share – useful for dividends, buybacks, or reducing debt. Unlike net income, free cash flow is harder to manipulate and often seen as a more reliable metric.
🧮 Calculation
🎯 What does this mean for investors?
- High FCF per share signals strong financial flexibility.
- It shows how much capital the company can effectively reinvest or return to shareholders.
- Particularly relevant for dividend payers and capital-efficient businesses.
📘 Short interest
📈 What is it?
Short interest indicates how many shares of a company are currently sold short – that is, borrowed and sold by investors who expect the price to decline.
🧮 How is it calculated?
It reflects the percentage of a company’s shares that are being shorted relative to the total shares available.
🏛️ Why is it important?
Short interest serves as a sentiment indicator: A high value may signal skepticism or bearish expectations – but also increases the potential for a short squeeze if prices rise unexpectedly.
🧮 Calculation
🎯 What does this mean for investors?
- Low short interest usually indicates market confidence in the company.
- High short interest can be a warning sign – or an opportunity if sentiment shifts.
- Especially relevant in volatile markets or ahead of key earnings releases.
📘 Employees
📈 What is it?
The employee count shows how many people a company employs worldwide – offering insights into its size, structure, and business model.
🧮 How is it calculated?
🏛️ Why is it important?
It helps assess operational scale, labor intensity, and cost structure. Combined with revenue and profit, it enables key metrics like revenue per employee or productivity.
🧮 Calculation
🎯 What does this mean for investors?
- A high headcount can signal operational complexity – but also significant growth capacity.
- Revenue per employee is a key indicator of efficiency.
- Especially useful for comparing tech, industrial, or service-heavy companies.
📘 Turnover per employee
📈 What is it?
Revenue per employee indicates how much revenue a company generates on average per employee – a key measure of efficiency and productivity.
🧮 How is it calculated?
The employee count is typically taken from the most recent annual report.
🏛️ Why is it important?
This metric helps compare business models – especially between labor-intensive and technology-driven companies. A high value suggests automation, operational efficiency, or strong value creation per head.
🧮 Calculation
🎯 What does this mean for investors?
- A high revenue per employee indicates a scalable and margin-strong business model.
- A low figure may reflect labor-intensive operations or lower value-add.
- Especially helpful when comparing tech companies to industrial or service sectors.
CrowdStrike Holdings Inc Stock Analysis
Analyst Opinions
61 Analysts have issued a CrowdStrike Holdings Inc forecast:
Analyst Opinions
61 Analysts have issued a CrowdStrike Holdings Inc forecast:
CrowdStrike Holdings Inc Events
Past Events
|
SEP
10
Goldman Sachs Communacopia + Technology Conference 2026
7 days ago
|
|
SEP
10
Citi’s 2026 Global TMT Conference
7 days ago
|
|
SEP
2
Fal.con
15 days ago
|
|
AUG
26
Q2 2027 Earnings Call
22 days ago
|
|
JUN
3
Q1 2027 Earnings Call
4 months ago
|
|
MAR
5
Morgan Stanley Technology
7 months ago
|
|
MAR
3
Q4 2026 Earnings Call
7 months ago
|
|
DEC
3
UBS Global Technology and AI Conference 2025
10 months ago
|
|
DEC
2
Q3 2026 Earnings Call
10 months ago
|
|
SEP
9
Goldman Sachs Communacopia + Technology Conference 2025
about one year ago
|
|
AUG
27
Q2 2026 Earnings Call
about one year ago
|
StocksGuide Free
CrowdStrike Holdings Inc — Goldman Sachs Communacopia + Technology Conference 2026
1. Question Answer
Good afternoon. For those of us who have been at the conference for the last couple of days, the number of thought leaders in AI on the stage who have talked about cybersecurity, we're pretty much batting 10 out of 10. So really excited to have George Kurtz, CEO and Co-Founder of CrowdStrike, on stage with me. George, thank you for being here.
Great to be here.
George, I want to start off with some of the most exciting announcements at Falcon from last week because as far as industry conferences go, the combination of having Jensen, thought leaders from Anthropic, OpenAI, all of the enterprise customers in one place along with, I think it was 11,000 customers was really a different level of conference than what we've seen before. And I want to start with one very specific announcement that you announced, which was SafeMind. So to bring the audience up to speed, SafeMind is CrowdStrike taking Nemotron and applying it to very specific proprietary CrowdStrike data to create a continuous penetration testing loop. George, maybe I'll turn it over to you. Tell us a little bit about the evolution of this idea and why it's important.
Sure. So it was a fantastic event. We had over 10,000 customers. It became really an industry conference, and we were lucky enough to have Jensen and Lip-Bu Tan and Brockman Air and others. So it was great from that standpoint. I think when you look at SafeMind, it goes well beyond the models, right? We think about it as really an agentic system, which consists of the models and the harness. It's very important to put those together. And if I was to distill it down into 3 areas, you have a red model, which is the offensive model, Red Tempest, and you have a blue model, Blue Solano, which is our defensive model. And then you have a harness that works in combination with that. So I would say, I don't know, maybe 6-plus months ago, I sat down with Jensen and we were talking about security. And really, the conversation was we need to do something to provide defenders with what they were lacking and give them sort of a fighting shot in the agentic world that we live in today.
So they're great partners. And part of what we did was we started the cybersecurity super intelligence lab led by Bartley Richardson, who came from NVIDIA. So that kind of helped. And the whole idea was how do we work in tandem with NVIDIA to leverage the Nemotron models. We use multiple ones, but Nemotron Ultra 3 and basically create something that was bespoke for CrowdStrike and its rich data set and its history of collecting all this data. But the whole idea, just to summarize, and we'll get back to the questions here is with the harness and with the Red and the Blue models, you have this continuous loop where the defense is always learning from the offense. And one of the things and Jensen was insistent on it, which was like we need to have a digital twin because we talked about all of the other areas in technology driving and robotics that have digital twins, so that we can very quickly simulate this environment. So it can run in the digital twin or it can run in the real world.
I want to put 2 potential bottlenecks in front of you on SafeMind adoption going exponential. The first is CISOs are a pretty conservative bunch, and we've been talking about automating the SOC for a really long time, and it's still like pulling teeth. How do you get CISOs comfortable with something as important as pen testing being automated in a continuous loop?
Well, I think it starts with like we already know -- we were on the system. So we already know what the systems are. We already know the identities. We already know the exposures, the pass levels, the vulnerability management aspect of it. And we built an incredible digital twin, sometimes you call it digital cousin and everything is not exact. But basically, it allows us to very quickly simulate what that environment looks like. And I think that's the first part in getting people comfortable with these sort of technologies. Now if you want to leverage this internally or you want to leverage it externally and you want to just consume the models directly, you're going to be able to do that for companies that are part of our QuiltWorks Trusted Access program. But within the technology itself, there'll be some guardrails around it, but the digital twin will serve as a way to really very quickly simulate what could happen. And that's very exciting and important for customers.
The other pushback that we've heard just in the last week or so is, okay, well, if you look at the publicly available Nemotron benchmarks, they're not on the frontier. And so there is a progression that will happen over time here. But why does that not matter for CrowdStrike to have an incredibly performant frontier model solution or a cyber frontier model?
We're not trying to solve the millennial -- like math problems, right? So what we're trying to solve is the hardest security problems and Nemotron is very good for our purposes. And the key, as I mentioned, is the training, the data, but the model -- the harness. So even if you take our harness and you apply it to any of the frontier models, we actually get better results. So when you put those in combination and you actually spend the time to do the training and really adjust it for what we wanted, you get fantastic results for the security use case. And I think you've been a big proponent of these sort of verticalized type models that you've written about in the past. And I think there a lot of opportunity. Open weight, I think, is really part of the future.
Now for customers, they'll have choice. We've got partnerships. I know we'll talk about with Anthropic and OpenAI. That will be available through the platform. You want to use our model is fantastic. But you can consume it through our harness or you can consume it through MCP. But obviously, we've got a monetization strategy around tokens to be able to do that. So if you look at the benchmarks that we put out, we haven't tested against Astra, but we were getting as good or better performance for a much, much lower price. What we talked about was the remediation in a frontier model was about $10 for that remediation activity. And in ours, it was $0.03 with the same results because of the way we've built it and the way we can operate it.
So I do think Open weight will have a massive impact on the entire AI industry. And one of the reasons why we're proponents -- and I know Jensen was up here earlier, but when he came to our conference, he basically said, like we are the poster child for why they built Nemotron and sort of the partnership with NVIDIA to get it to the place. I mean we shortcut it a lot of time because of the relationships and understanding how their models work where we didn't have to figure it all out from scratch. They provided what we needed.
Jensen earlier, he was incredibly bullish on the CrowdStrike opportunity. So one other thing he said that I want to pick your brain on is he talked about the commercial opportunity for frontier labs in security. And I know that, that can be via partnership, as you just alluded to. How do you think about the risk that the frontier model swim lane converges with the security swim lane over the medium term?
Well, there's always going to be a role. And I think you have to look at where these models are really good and where it all kind of interplays with security. So first, when you look at these models, I mean, they've come a long way. They're incredible just from January to where we are today and what they can do. And there will always be a role and success for both frontier and for companies like CrowdStrike. I had dinner with Marco, your CIO at Goldman last night, very, very sharp guy. I think he might have been around on stage, I'm not sure, but incredibly sharp. And we talked about kind of the roles. And being a Formula 1 guy, he sort of said, look, if I need Formula 1 sort of results in the most critical areas of alpha, and I don't care about the money I spend, I'm going to go to the frontier. But his comment was for all the other things, I'm going to leverage these sort of open weight models. And that makes a lot of sense to me.
So when you look at Frontier labs, and again, they're partners of ours. They're very good at obviously finding the sort of -- if they can write code, they can understand vulnerabilities and they can create patches. But -- and they can sift through lots of data, but these things are not in line, and they're not taking action in real time. So while there's a tremendous amount of benefit, there is a massive opportunity for companies like CrowdStrike who have all the data. We're the system of record. We're in line. We're a net data creator, 7 trillion events per day. And all of the models that we train on are our data. There is no Reddit of CrowdStrike security data that somebody can just train on. And I think working together and giving customers choice is a great outcome.
There's one other architectural question that I think is relevant here. So when you and the team founded CrowdStrike 10-plus years ago now. There is an architectural change in endpoint such that the incumbents in endpoint, when they tried to address it, they sort of really struggled. And CrowdStrike was able to out-innovate with next-generation EDR and all of the modules that followed. How do you think about the risk that AI creates an architectural shift such that all of the domain experience of the last 10-plus years is not the same domain experience that can be applied to the next time?
I actually think it becomes even more important because it starts with the data. You don't have AI without the training data like period, right? So if you train it on garbage or your synthetic data is not where it needs to be, you're going to get substandard outcomes. So when we think about these architectural shifts, it actually plays into our hands because we have all this data. And sometimes they're all saying it's better to be lucky than good. We actually had annotated this data for the last 10 years. Like we started doing this before there was Gen AI. And that data is basically in a format for the most part, I mean, there's always curation we have to do, that it was incredible for training. So that creates a moat. This data moat that we have creates a barrier for, I think, others, and it plays into our hands in terms of this inflection point that we see in AI today. And we see the results of it based upon what we've just built. The good news is we are an AI company from the beginning. It started in machine learning. And obviously, now we've got many opportunities in front of us with Agentic AI.
I know it's only been a handful of business days since all of the product releases at Falcon. And the reality is you wouldn't have put these types of products in front of customers if you didn't think they were going to be hugely popular. My question for you is what surprised you in the feedback? And is there anything -- were there us that came down the pipe that made you think, that should really be on the product road map?
Well, we'll take Guardian as an example. This is one that I announced and we shipped that day. And from a Guardian perspective, this is really -- falls under the category of AIDR, AI detection and response. And what that means is we've basically moved from sort of just EDR of protecting a human in a computer or a cloud workload to protecting the agent, everything the agent does, everything the agent touches. And we think it's a bigger opportunity potentially than EDR because on average, at least the math is there'll be 90 AI agents per human. Now obviously, I think it would be unlimited. It doesn't mean why can't you have 1,000 or what have you.
So we actually worked on that. And it's a great story because we had so much feedback from customers in what they wanted. So we bought Pangea which really did prompt inspection. And then we had our customers saying, well, we don't know where all these AI agents are. It's AI agents run amuck. And the CEO on down and the Board is saying, we have to deploy AI agents, but we can't go fast enough because of the security issues. So they told us this. I mean, every customer was saying this. And we had a piece of it. So what we did is we created a Tiger team internally about 6 months ago. And this is a great example of like how you have to operate today. And I said, okay, we're going to put a Tiger team in place, and we're going to start. So I had a kickoff meeting, and it was a smaller group, but then 200 people show up. Everybody wanted to be part of the Tiger team.
And I'm like, this is not a Tiger team. So I disinvited 200 people, and then I reinvited and I handpicked the best all-stars from CrowdStrike. Like it was a privilege to be in this team. Then we ran 3 meetings a week that I was on, 3 status meetings. And to be honest, it was no different than when I started the company. It was like, here's what we want, here's what we're going to build, change that, move that. I don't like the color. I mean it's that level of detail. And it's incredible because -- I mean, the good news is with the platform, 80% of this stuff is built. We don't have to build agents and workflows. I mean, we created a new workflow, but we don't have to build the architecture around it. So with a very short period of time with a small team and leveraging AI, we got an incredible product out. So that when I got on stage, I was able to announce Guardian GA. It went live while I spoke and then our customers were turning it on and using it in their workshops in the afternoon. So that one is super exciting, and I think it's going to be a total home run for us.
And when they turn it on, it consumes flex credits?
Well, it's -- if you license it through Flex, it consumes Flex credits. It really consumes tokens, which, again, are made available through Flex. But part of Flex, as you probably saw in the last quarter, did 935 Flex. We're $2.3 billion worth of total Flex contracts. And we've gone to a Flex first selling motion, which means like if you wanted to sell something that wasn't Flex, you'd have to get it approved up through probably the President -- Head of Sales President of the company. So not to say that some of them don't get through for whatever reason. But at the end of the day, we tripled the amount of Flex deals last quarter than we've done.
There are a lot of technical decisions made early on in CrowdStrike with the lightweight sensor that you have and the Knowledge graph and all that good stuff. Threat, threat graph. My question for you is, if you think about the pace of agentic attack, for lack of a better word. Is there a scalability upgrade that has to happen? And I guess we can take it in 2 ways. One, internally for your own architecture, did you have to upgrade to be able to meet the pace and speed of agentic attacks? And then two, we can talk about customers.
The good news is that we've built the technology and the platform to be scalable. So when we think about these attacks and we think about agentic attacks, there's 2 things that you have to really keep in mind. Number one is things happen faster and more of them happen. This is the simple explanation. The agents haven't figured out some new miraculous way or class of attacks that have never been seen before that we're not covering for, okay? So you have more attacks and they come faster. That's a big piece. And obviously, these agentic attacks are good because they can shrink so many different vulnerabilities together, really esoteric things that a human couldn't keep track of to be able to find an access path in.
We've all heard and read the Hugging Face. Examples, so from that standpoint, we have the technologies, and we've understood what was happening. We talked about this breakout time. It used to be days and hours and minutes. It was 27 minutes last year with 27 seconds we saw in some cases. And part of what I talked about at Falcon is this window has now collapsed to like 0 because of the -- the new Apex predator is the agent state, not the nation state. And now everyone can operate with nation state capability. So we, of course, keep adapting, but the big part is making sure that you've got the right AI internally with the right speed and the platform to keep up with what the adversary is doing.
This leads to the modernization of question. I think about your share in even classic endpoint, for example, let alone your share in next-generation SIEM, which is going to be benchmarking below what endpoint is because it's newer. There is a lot of heavy lifting that customers still have to do from a modernization standpoint. Talk to us about some of those conversations. When enterprises call you in and say, look, we haven't historically been a CrowdStrike customer. How do you walk them through legacy to next gen across the key pillars?
I think we just want to start with, well, what are you trying to solve? And we have a lot of customers that I think we're looking -- sometimes legacy technology is just there's inertia, right? Hey, we'll get around to it whenever we get around to it. Half the market is still legacy. So -- and we're -- we've got massive customers, but half the market is still legacy. So plenty of headroom in front of us. But I think with this Mythos moment, what we're seeing now is customers going, hey, maybe legacy is not good enough. Maybe it's time to make a change. And there's always these technology inflection points that people go, wait a minute, we got to do something different.
And I think AIDR or Guardian as the product will actually spur more activity around what we had is not going to work and how do we modernize this. And some of the companies that we've won and we've got a great amount of net new logos, you would look at those. If you knew the names, you go, I can't believe for 15 years, you've been on legacy technology. But they still are, and we're happy to have them over. But it's taking them on the journey. Let's solve what you have today, maybe you want AIDR, your SIEM is outdated. You're spending too much money. You've got one of every tool and 2 of everything else, like how do we get rid of this stuff? And that's really the conversation, which leads to flex and then also the demand planning that we do year-over-year, which has been great in having customers actually consume more flex sooner.
What about in terms of budget? One of the industry conversations that we've been having is CISOs generally have more of a carte blanche than they did a year ago because enterprises are so determined to make AI a reality. When they get that carte blanche, how do they then map it to specific security products? I guess it depends very much on the problem they're trying to solve. But maybe just give us some high-level commentary on what you're seeing at a budgetary level.
Well, from a budgetary level, it really starts with what problem are they trying to solve. So one of our largest customers, one of the hyperscalers worked with us as a design partner for Guardian. And they came to us and they said, we want these things, great. You'll be a design -- it was unbelievable to have them as a design partner. And I said, okay, well, what does success look like at -- when this thing pops out the other end, what does it look like? And what are you looking for? And it wasn't a feature. It wasn't a technology sort of widget that they wanted as success.
The #1 thing was we want to go faster in AI deployment. The CEO wants us to go faster. And we're actually -- we can't go fast enough. So when you have that level of support at the CEO level down, what we're seeing is that basically, security is hitting the gas pedal for the first time for IT rather than hitting the brake pedal. And this, I think, we talked about this before we got on stage. It's really the first time I've seen hitting the gas pedal in security rather than hitting the brakes. So that gives you additional budget where the CTO -- the CT -- the Chief Data Officer, whatever it might be, saying, we got to go faster, we need security to be part of it.
This is the durability of growth question. Are we hitting the gas pedal for 2 to 4 quarters until we're up to a higher level of security and then we come back down to 40 miles per hour? Or is this the period of time where we're staying at 200 miles per hour and perhaps even going higher?
Well, the world we live in today is if you went on vacation for a week, you're outdated. Like come back and what happened? The world has changed in a week. It is a much different pace. We're -- I always say to my folks, we're looking at a watch, not a calendar, like we got to go. So that's kind of the pace we're in. I actually don't see that changing. And my simple math on this is, do I think there's more AI in a year, 3 years or 5 years? For me, absolutely. Do I think the technology is going to change even faster? Absolutely. Has security paralleled the slope of the technology curve for the last -- how long I've been in it? Yes.
And what we did at Investor Day, you were there, we plotted the adoption of the cloud and you can plot the revenue stream over the last 10 years, and you can kind of see it go like this and security goes along with it. If you just take the main labs and you look at how fast, never been seen before the revenue growth, it goes like this. So I think the inflection point for security is going to be a lot sooner and a lot steeper than what we saw with the cloud, just because of what I said, you can't really roll this stuff out unless you have security. So I think it's going to be durable. I think it's a long tailwind. And honestly, this is -- we're going to look back. I hope to be back in 5 years, every year with you, but 5 years ago, man, that was kind of Micky Mouse with all the stuff that we saw in 2026 compared to what we're going to see. It's just going to change that fast.
Let me ask you about a couple of product cycles. So you already touched on AIDR and the frontier model inflection followed by what is pretty much happening real time in security. How do we think about AIDR in terms of an attach rate or a token allocation? Give us some clues as to how that product cycle market develops over time.
Well, if you look at -- just look at the AI spend, I think today, it's like $2.7 trillion going to almost $6 trillion in 2030. Those are sort of the stats that we gave at our Investor Day. And if you took an attach rate of 1% to 8%, pick whatever math you want, these are massive numbers that are in front of us. And as I said, there's not going to be a company that doesn't have some level of AIDR, just like we would go, that's crazy, you don't have antivirus. That's crazy, you don't have EDR. Well, it wasn't crazy in 2011 when I started the company, nobody even know what this stuff was. So in 2026, you can go to any company. They don't have AIDR, right? And that's the opportunity in front of us.
So the attach rate, the -- I'm a simple math guy, pick whatever percent you want in a massive TAM. You have to buy into the fact that it is going to be needed and it's going to be mandated. And I think given the level of compliance that's out there, 100% is going to be mandated. How can it not in these regulated industries? How can anyone go back to the regulators? Take what you guys do? How can you go back to the regulators? We don't know what our agent did. It did something. That's not going to fly. So having visibility, having full traceability of the life cycle of that agent, tying it together with identity as a control plane is going to be critical. And that's going to be, again, a massive TAM opportunity for us.
Let's go to the identity control plane. So over the last several years, the world has thought about privileged access, identity access, identity governance, and you've had these 3 pillars. What's unique about agentic identity is fundamentally, it's more ephemeral. I think that's probably the best way to describe old versus new. And then we see the types of products that CrowdStrike is releasing, which we can debate whether they're overlay technologies or you can actually do full displacement over time. Talk to us about how the construct of identity is changing and why CrowdStrike addresses that as opposed to the classic pillar guys.
Well, let's take -- I mean it's multiple areas of identity. And one of the first areas that we got into was ITDR identity detection response. And that basically was do you have your directories configured right, can they be abused, things like lateral movement when an adversary gets in. And we got into that in 2020. We saw identity is going to be important stopping breaches. Now where we are today essentially is this model of PAM, privileged account management was really born in the late '90s, early 2000s, where I have all these Windows administrator credentials and I got to put them somewhere. And I want to make sure they're secure. Then cloud came about, and it was like, why have all these cloud accounts, I got to put them somewhere and I got to make sure they're secure. We think that's an outdated model, which is one of the reasons why we acquired Signal AI.
And these -- the founders all came from Google. They built their identity stack for Google Cloud through an acquisition and super smart bunch. But the whole idea is the world needs to move to human and nonhuman, needs to move to zero standing privileges. So essentially, you can think about a hotel. Let me just give you an analogy. Somebody -- you check into this hotel here, you get a card key. You can go wherever you want. You want to go to the gym, you want to go to the rooftop, you just click it, right? Standing -- that's standing privileges. Zero standing privileges, you get access and you only get into the room. And as soon as you get into the room, your access is turned off. Then you move and you want to go to the gym, everything else is turned off and you just go to the gym, but you know you're going to the gym. Then you want to go to the restaurant and you go to the restaurant. But everything else has turned off.
By the way, if you lose the card, nobody has access to anything. That's the simple analogy of 0 standing privileges. And this is what's needed in an agentic world. When the agent runs, you don't want to load the agent up with every entitlement to do whatever it wants because guess what, it figures out a way to do things you don't want. And that's part of the problem. It literally steals tokens and credentials and all kinds of crazy stuff that you've read about. And this is why what we released, we're so excited about because it becomes a control plane in addition to run time, we now have the identity control plane with nonhuman identities and signal.ai, which is now our next-gen identity solution.
Do you need visibility into the network or a network control plane for the platform to be complete?
Well, it's interesting to say that. So one of the things we announced at Falcon is an AI gateway, which coming out in September. And that's for things that we may not run on. But also what's interesting is we actually have a transparent proxy on the agent. So we actually see all the Agentic traffic before it ever hits a gateway as long as you're running our agent. So we'll be able to cover, obviously, our agent plus if you're not running an agent doing something else, we don't -- we're not covered in the whole environment, we'll be able to see that through our gateway or no problem, there's plenty of gateways that are out there. We actually integrate with most of all the big AI gateways, and we actually can implement control points from those gateways as well.
You've alluded a little bit to why agentic security is hard. How did you all solve the problem of visibility given that we hear about things, for example, like agent session management or life cycle agent management where it doesn't have the same parameters that a human would have had or machine identity would have had a year ago. How did you think about addressing that visibility question?
Well, the good news is we've sort of architected for this in the human world, and it applies in the agentic world at super scale. And that is -- and you probably have seen this in your own world, you're using ChatGPT or Claude and you get called to dinner and you come back to your session or you close the computer for the night and you boot it up and you take over from where you left. Well, all of that is -- you have to track the state and you have to understand when it started and what it did. And we've always had that concept of not losing the state in a process or a human world, and we have that in the Agentic world. And that was part of our threat graph and all of the graphs that we've built. And this is why it's so important to be able to understand the context across a long horizon of what someone or something is doing.
So we had that concept. We've actually extended it out for the Agentic world, but it allows us to track these things over long periods of time because you might have a short-running agent or you may have a much longer running agent and you have to put it all together. The other piece of that, which is important is you have to tie together the, say, the prompt layer with the runtime layer because you're going to have a prompt that sort of passes the smell test of I'm going to run this prompt and it looks good. But underneath, if you don't have the technology to understand, a, the identity, but also run time, what it's doing, you're not going to know if the prompt actually did something bad. So we're in a unique position to tie together the prompt itself, the identity and actually what it did, which is very unique in the industry.
Let's talk about SIEM.
Let's talk about it.
There has been what I would call a big gap in intelligence in the industry because customers don't put all their data in the SIEM. And then once it's in the SIM, it's either expensive or they don't have the right security domain experience to know what to do with it. So you get all the stories of the burned out SOC analysts trying to find a needle in a haystack. How is the upgrade cycle in SIEM going? I would have loved to have seen it happen faster and earlier, but the reality is these things take time.
They do take time because they are embedded. You have workflows. There's plenty of SIEMs that have been around and technologies that are decent. But obviously, there's a modernization cycle taking place. And it takes time because a lot of processes are built around these. So how we got in the SIEM business was we had customers saying, your data is incredible, your product is easy to use. Like why can't you just take some third-party data in, and they asked us this year-over-year. And so finally, we said, okay, we're going to do that.
We bought Humio and obviously became next-gen SIEM, log-scale next-gen SIEM. Now what does that actually mean? Well, it means that -- and where this becomes disruptive is that customers are not charged for the first-party data that we generate. So think about what was happening. We were generating 80% of the data that was going into their SIEM and they were being charged by the SIEM vendor. So we said, well, why don't you just keep it in Falcon? We won't charge you to ingest that data. This is a very important point. And every customer actually has access and gets 10 gigs for free. We won't charge you for that. but we will charge you to ingest the third-party data. So when you do the math on this, it's like, well, why would I take all the data out of Falcon, put it somewhere else, be charged the tax to put it somewhere else and have disconnected systems. And this is why it's resonated so well. It's faster, better and better outcomes and then obviously, cheaper to operate better TCO.
CrowdStrike strikes me as a company that has had its foot on the gas from an R&D standpoint from day 1, and I don't think that's ever really changed during the number of years that you've been public. My question for you is, does the efficient frontier of R&D change? Have you noticed anything different in the way that CrowdStrike operates over the last year because of AI productivity, for example? And it sort of creates this expansive idea of all of the places that you could compete over time essentially getting pulled in from a road map standpoint.
Well, if you look at -- what is AI? AI really just bends time. We always talk about this concept of how do you bend time, AI bends time, right? You can do more things faster. Obviously, what does that translate to potentially efficiencies around headcount, spend, those sort of things. And then what we've tried to do is be very diligent and efficient where we apply it, whether it's in legal, do we really -- we want to be more efficient in terms of like getting through all this data and AI is very good at that. We think about development. Of course, there's a crawl walk run because you want to apply AI in the right spots. Where do you want to write code? Where do you want to deploy code? How do you make sure that AI is to a level where it is today? It wasn't a year ago.
Just a year ago, it wasn't as good as it is today. So we've been very diligent on where we apply it and how we apply it. But overall, more and more agentic workflows and processes are taking place internally. And again, we're seeing that in many of the other customers. And really, the problems that we're solving for customers, we have to solve for ourselves, the visibility, the control, the identity, and we're doing that as customer zero. But I couldn't be more excited about just being in technology and security today, because of how fast it's moving and the opportunity that's in front of us. But if you look at every area, not just coding agents, but whether it's legal, whether it's marketing, whether it's HR, all of these processes are going to be reimagined and they're going to need security as part of that modernization.
I'm curious if you're willing to share with us has your day-to-day changed? Or in what way has your day-to-day changed?
Well, I used to ask for a white paper and then 3 months later, I would get one. So now I can write one in an hour and go here it is. I kind of...
What's the last white paper that you wrote in an hour?
I can write -- I mean, I'm like -- I need a white paper. I wrote it and then give it to the marketing people. Like -- so that was -- I do this all the time, like there isn't anything that I haven't really optimized. I mean I write my own programs. I have an Apple developer license. Everything is curated, all my workflows like you spend a lot of time setting this stuff up and getting things running and playing with the models and open source, open weight technology. So you got to be in this stuff and you got to have a passion for it. But my day-to-day piece has changed.
Actually, now all of our -- I don't have to do white papers anymore. Like in the early days, like I don't need to wait, I'll write one. Now the whole company is like, well, how do we do this and do it better using AI technology. And for me, it's changed dramatically just the speed at which I can do things. I think about AI as a little bit of like an Ironman suit. Like if you put it on, you could be super human, but you sort of have to know what you want to get out of it. And I would say I'm pretty darn good at prompting.
I believe it. I'm glad I asked the question. Please join me in thanking George Kurtz for his time.
CrowdStrike Holdings Inc — Goldman Sachs Communacopia + Technology Conference 2026
CrowdStrike positions itself as the security control plane for an agentic AI era, unveiling SafeMind, Guardian AIDR, identity advances and SIEM integration.
📊 Key Message
- Takeaway: CrowdStrike frames itself as the security control plane for an "agentic" AI era, pairing proprietary telemetry with verticalized models and orchestration: SafeMind for continuous pen‑testing, Guardian for AI detection & response, and identity/SIEM work to turn data into automated defense and tokenized revenue.
🎯 Strategic Highlights
- Product: SafeMind pairs offensive (Red Tempest) and defensive (Blue Solano) agent models plus a harness and a digital twin to run continuous penetration tests in simulation or live environments.
- Monetization: Guardian and model services consume tokens available via Flex; CrowdStrike has moved to a Flex‑first selling motion and cites $2.3B of total Flex contracts.
- Moat: Management stresses a decade of annotated security telemetry (they cite trillions of events) as a data moat that improves vertical model training and runtime control.
🔭 New Information
- Announcements: SafeMind unveiled; Guardian declared Generally Available and demoed live; an AI gateway is planned for September; identity control plane expanded (Signal.ai integration) and next‑gen SIEM/log scale positioning reiterated.
- Commercials: Company claims large cost efficiency (example: remediation at ~$0.03 vs ~$10 with a frontier model), emphasizes token metering via Flex, and reports a sharp increase in Flex deals.
❓ Analyst Q&A
- SafeMind adoption: CISOs' conservatism was raised; management points to digital twins, guardrails and the QuiltWorks Trusted Access program to enable staged, audited deployment.
- Model strategy: CrowdStrike uses NVIDIA Nemotron models plus its "harness," arguing vertical training yields better security outcomes and far lower operating cost than generic frontier models, while keeping customer choice for other models.
- Identity & visibility: Management highlighted zero standing privileges for agents, tying prompts to runtime and identity, and SIEM integration (Humio) to avoid duplicate ingestion and reduce TCO.
⚡ Bottom Line
- Implication: The product slate meaningfully expands CrowdStrike's TAM and strengthens its data/identity moat; near‑term revenue impact hinges on token/Flex adoption, but the moves deepen differentiation for AI‑driven security over the medium term.
CrowdStrike Holdings Inc — Citi’s 2026 Global TMT Conference
1. Question Answer
I'll give folks a couple of minutes here to settle in, but good afternoon to everyone joining us here and folks joining and tuning in on the webcast. My name is Fatima Boolani. I jointly head up our software equity research franchise here at Citi. And I am so privileged and delighted to be able to put a capstone on Citi's TMT Conference on day 3 with a keynote session with the CFO of CrowdStrike, Burt Podbere. Thank you so much for being here.
Fatima, always a pleasure. Thanks for having us.
Burt, I want to start our conversation off with a statement. It has never been a more exciting or important or consequential time to be a cybersecurity company. And so with that in mind, to set the tone of our discussion and our dialogue, can you give us a state of the union on the business, on the financials, on the overall strategy and specifically, the key messages that you want to really hammer home post your second fiscal quarter results and on the back of your annual user and partner conference, Fal.Con last week.
Yes. Thanks. Hi, everybody. Great to be here. And I love talking about the Mythos moment, right? So the Mythos moment happened back in April, and there was a lot of activity around that, a lot of kind of things that came out of that. You had good stuff, not such good stuff. But for us, it was a defining moment with respect to, hey, conversations are happening faster than they ever happened before. And then they turned it into ARR for Q2. So Q2 results were sensational, Fatima.
It was our best quarter in company history, whether it was net new ARR, non-GAAP profitability, we had a record Q2 free cash flow quarter. So the numbers backed up the comments that the Mythos moment for us was real, and it was more than just conversations, but it was ARR. Then you kind of went into products. We've had great product growth across the board, Next-Gen SIEM, cloud, Next-Gen Identity. You had AIDR, which was great. You had exposure on and on and on. Flex, which is our go-to-market license, which is the most elegant license, I think not only security, but software has ever seen, did really, really well. It was one of those moments where you're getting data and you're saying, "Wow, this data is super impressive with Flex."
The top 10 deals of the quarter by deal value were all Flex deals, not non-Flex deals. So we're excited about that. And then you mentioned Fal.Con. Fal.Con was us coming out and saying, "Hey, we can be super innovative as well. We don't have to be a start-up." And we came out with some stuff, whether it was SafeMind or Guardian, whatever it was, it was really, really well received. And then, of course, I have to add my two cents, and I pulled in some long-term targets, $10 billion and $20 billion. I pulled those in. So I think all that combined kind of led for a really, really good Fal.Con. So that's kind of the state of the union, and hopefully, that resonates with everybody here.
Burt, Fal.Con was clearly eventful from a product announcement and a financial and target model expectations update. But we'll come back to that because there's a lot of layers of that -- those onions to peel. But Fal.Con last week, record-breaking attendance for you. It is your biggest pipeline generator for the business. But interestingly, this year, the timing of the event clearly transpired and potentially even benefited from this post-Mythos moment and the Hugging Face incidents that we continue to hear about in the headlines in the news.
So I want to ask you, Burt, you see and speak to a lot of customers at these events. What was clear? What was the most distinct thread in your Chief Information Security Officer and buyer conversations this year at Fal.Con versus years prior?
Yes. Well, certainly, it was about protecting the agents, protecting these AI agents. And customers were -- after 3 things really, they said, "Look, with these agents that are coming out, we need visibility. We need control. We need to control what and when these agents go out. We need guardrails around this. We need audit. We got to be auditable. All this stuff that's going out, we need to understand what's going on, what the reporting, we're getting questions from regulators, et cetera, et cetera." And I'll throw in a fourth, cost.
We need to be able to control the cost of this stuff. So those are the 4 things that the folks in security were talking to us about. And by the way, they were talking to us about it before the conference, right? We have off-sites with the management team, about 50 of us go somewhere, and we kind of figured out what we're going to do for the next 10 years. But on this particular offsite, which happened just after Mythos, we had a CIO from a Fortune 50, and they were on a screen like this. There are 50 of us there, like this room here, but it's smaller, 50 of us, and he was on the Zoom, and you saw the panic in his eyes. He's like, my CEO wants AI deployed everywhere. And I'm scared to death that we're going to be putting out these agents, and we're not only going to be opening the back door, we're going to be opening the front door for the adversaries, help us.
And so we went through what I just went through all of you folks in terms of what he was looking for. And then we worked collaboratively with him and his team to put out Guardian, and we couldn't be more pleased. So the CIOs and CISOs, that was the main theme that they were kind of focused on. Help us, which is very different from the past where we're prospecting. We're going out to look for customers. Customers are coming to us. Prospects are coming to us going to go, well, we have a real need, and we think you can help us. So please pick up the phone and let's talk. And we did more of that than almost anything else we've ever done.
Burt, one of the lines of conversations and consistent conversations and debate, frankly, that I've interfaced with investors on is this notion of, well, the environment, the cyberattack landscape has never been more pernicious. It has never been so as demanding. It has never been as sophisticated ever even in prior computing cycles. And so the question and the debate is, well, in the post-Mythos moment in these Hugging Face in the headlines, why aren't we necessarily seeing massive budgetary explosion.
Now certainly, we saw some of the tinges of that in your second fiscal quarter. But how would you allay concerns or sort of emphasize to investors that maybe the Mythos moment isn't a moment, it's actually an era of sustainably and durably capturing more growth in budget. So really, the pain point is why didn't we see a budgetary explosion immediately after these events like we maybe saw in the past?
Yes. It's a great question, Fatima. So first of all, I'm driving to your conference, and I'm listening to the radio, and there's some guy talking about AI doom. And I'm kind of like listening to this going, okay, well, he's not all wrong. But then there are companies like us who can help stop and prevent the doom. And so what does that all mean? You think about the landscape and the threat landscape, look, years ago, the #1 threat actor were these nation-state attacks. They would hire 1,000 people. They put in a bunker. They put them in a bunker 65 feet below the ground, and they come up with all these sophisticated ways to disrupt companies, attack companies, change election, all this kind of stuff.
And today, it's now in somebody's living room, right? These attacks can be generated in somebody's living room with all these agents that are as sophisticated as anybody that we've ever had seen before. And so we're in this really kind of strange period where people are figuring out how to use these things, mostly for good, but some for bad. And for the bad, what's really happened is, number one, it's not just the volume of attacks that have gone through the roof, speed. The speed of these attacks has never been faster. You've seen the sophistication -- it's never been more creative in terms of how to attack somebody and steal their prized possessions.
So you're seeing all that combined and the threat landscape has just exploded in terms of the surface of attack. And you need companies like us to help kind of plug the dam. So fortunately, for us, we feel that sometimes it's better to be lucky than good. We've talked a little bit about that. And what do I mean by that is that AI is consumed at the endpoint. And last I checked, we really know how to run an endpoint business. And so it really came to us. And the great news is we're prepared. We're prepared.
We launched a battle-tested product called Guardian that actually prevents the breach on these agents that people are building faster than you can drink your coffee. It's incredible what we're seeing in this space. Look, I actually think that we are in the greatest transformation of technology the world has ever seen. So I've been in security a long time. I've been in software a long time. I've never seen anything like this. The consumption of AI is through the roof. And we just happen to be in the right position to help secure the AI.
Burt, you alluded to this in talking about some of the highlights from Fal.Con, but some of the things that stood out to us certainly was there was a pretty curated slate of very high-impact SKU expansions and product introductions. So the velocity of the innovation is clear, but specifically with the launch of AI Guardian and SafeMind, those 2 specifically come to mind.
Can you give us and maybe help us with some parameters as to which one of the newest product introductions you expect to have most salient impact on your financial performance and your financial momentum near term? And asking this going back to, hey, the budgetary consciousness has never been on as high alert, right? So where would those killer products be where you're commandeering the budget?
Yes. So obviously, we haven't released SafeMind yet, so it's early days. So nothing really contemplated in the financials for this fiscal year. We contemplated it next year, but it's still early days. We've still to launched it. I think Guardian as part of the AIDR category, I think that's going to have some legs. On that one, I would say the following. I think that AIDR as a category will be bigger than EDR. So let me repeat that. AIDR as a category will be bigger than EDR. That's our view. And that just tells you what's out in front of us.
In terms of near term, I mean, have your pick, you've got Next-Gen SIEM, Next-Gen Identity, you've got cloud, you've got Exposure Management, on and on and on. These products are doing really, really well, right? Last quarter was our best quarter in company history. We did $333 million net new ARR, 51% growth year-over-year. I mean, these are big numbers. And I gave increased guidance when we'll talk about that, I'm sure, all because of the momentum we're seeing. You talked about in your earlier question about why aren't we seeing it -- why are we seeing this uptick from the Mythos moment more than what we're seeing.
And I come back and I go, well, for us, it was pretty good. I'm not so sure others are benefiting the way we are because we're here at the right moment. It goes back to being an endpoint company, right? AI is consumed at the endpoint. You're going to hear a lot of other folks talk about, wow, it's all about workflow or it's all about network or it's all about this that and the other thing. No. So your homework, you're reading, AI is consumed at the endpoint. We see network traffic before it even goes to the network before it's encrypted. So when you think about that, it's hard to refute the comments that I'm making. And for us, we're proving it with the numbers. Words are cheap. Talk is cheap. Show me the scoreboard. And so I -- we did that last quarter for sure and certainly in some of the guidance that I gave.
Burt, just drawing from your past experience in having been a pretty critical vendor in securing prior computing cycles, I think a helpful frame of reference that you've provided is let's think about the monetizable opportunity for you for AI security from the standpoint of, hey, if we're going to be spending $1 trillion of CapEx on -- and generating $3 trillion of demand on all this AI infrastructure. Well, there's going to be some portion of that, that's going to have security wrapped around it, right?
So I think your framing has been for every dollar of AI demand, there's going to be $0.03 to $0.04 maybe of cybersecurity spend. Can you walk us through kind of some of the foundational underpinnings of your thought process there? What sort of led you to this being an appropriate mental model for folks to think about in terms of the incrementality of market opportunity for you?
Yes. Let's start with the budget. Look, if a company is breached, they're going to find the money. Let's start there. So now companies are really getting worried, and boards are getting really worried about their companies in terms of how do we prevent from getting breached. And they're looking and they're coming to us. We're getting calls from folks that you all would know in this room, CEOs of very prominent companies that are calling us directly and saying, "What do we need to be worried about? And how can you help protect us?" This is not the CIO, this is not the CISO. This is the CEO of Fortune 500 companies calling us and asking us for help.
Board members from these companies calling us and saying, "What do we need to be thinking about as Board members. We want to make sure we're doing the diligent thing." So the budgets, they're going to come from net new, but they're also going to be coming from other areas as AI becomes more prolific within organizations and organizations are going to become more efficient and effective of what they do, dollars are going to free up. And we're already seeing it. So we think that we're in a great spot to capture more of those dollars, and become more of a strategic partner for these firms, and they're looking to us for help.
And by the way, we do pick up the phone. We are one of those companies that picks up the phone, answers calls from the management team all the way down as part of our culture, right? When things are good and when things are not so good. We're there, we're there for our customers. We're -- when we say we're customer focused, we are customer focused. Look, we got a CEO. He's across the bridge over there. It comes from Jersey. This guy doesn't stop, right? He's still a founder. So think about that, still a founder. Most of our competitors are not founders, and there is a difference. This guy wrote the most selling cyber book in the world history called Hacking Exposed. This guy built a cybersecurity company for cybersecurity professionals. That's what he did. And because he's a founder, there's no rest for those who kind of work with him day to day.
George doesn't have an off button, I heard.
There's no off button. It's just go. And the great news is he's a really good human being. This guy is -- has a great reputation. He's tough as nails and to work for him is brutal, right? It's kind of like he is on, that means you are on. I'm coming to my 11th year in next week. And I reflect back and I said, man, keeping up with that guy was a real challenge for me in my career, and I've never been happier and never been -- I've never learned more. And I went on stage for our sales kickoff at about, I don't know, 3,000, 4,000 sales folks, and I said 2 things. I said a bunch of stuff, I said 2 things that they needed to remember.
One, don't make deals with customers that are on the side, because we'll find out about it, and you're sacked. There's no room for it. And number two is never bet against George. That's a real bad bet, right? That guy just keeps going, the innovation that you've seen at Fal.Con, the go-to-market engine that he's built, taking out friction through our Flex offering. We'll talk about that, I'm sure. And the way that he kind of gets the most out of his team, right? It's focused. There's never -- I've never met a more purposeful man in my life. And it shows again in the scoreboard, shows in the numbers.
In talking about George, I have to harken back to July 2024. That was a very pivotal moment for you as a company. The business financially and strategically is in a dramatically different place since July 2024 when you did have the outage that was heard around the world and felt around the world.
So Burt, what I want to ask you, between you and George, what have been some of the factors in navigating through this period where you're absolutely now in the free and clear? What has surprised you the most? And how has that experience influenced the way you've managed the business, managed operations and frankly, steward capital?
Yes. I mean that was an event. And look, I never want to go through it again, but there were some silver linings, right? We -- our touch points with customers were through the roof. We talk to almost all our customers. Sometimes there was groups of 1,000, whatever it was. We were on the phone, all of us, we were in a room, I don't know, about for 50 people and on the board, the whiteboard. You would have Burt that took all the companies that thought we were going to go broke. So I had to go through our financials. You had the bigger companies that George took, Mike Sentonas, our President. He took some more of the technical challenges, on and on down the line.
50 of us. And we all had companies that were associated with our name or events that we had to go to. So silver lining there is just more touch points with our customers. The biggest, I guess, surprise was this from that point on until now is the speed of AI adoption. It's incredible. We've never seen anything like this in our lifetimes, and maybe we never will again. And so the speed of AI adoption means security, right? Somebody asked me the other day and said, "Well, who runs sidecar with the AI providers, the frontier models to make sure that it gets out and used accordingly." I said, "Well, you're going to have these folks over here saying they need that and these folks over here saying they need this." At the end of the day, they need security.
Just to my former example with the CIO kind of talking about, hey, I can't deploy without you guys. So with that in mind, it's -- we're partners to all these folks, right? We're enablers for AI adoption. So we used to talk about security following the technology curve. Now we're talking about security following the AI adoption curve, which is much steeper than the technology curve. So it's been really good for us. You saw it in the numbers. You saw it in the guide, and you're seeing it in the business. You're probably hearing it in my voice. I've never been more excited to be kind of -- I've been in the company 11 years in terms of what's in front of us.
Burt, Flex and the Flex motion was given birth, the concept and the procurement vehicle sort of came into being after the event. And so at 40% of -- nearly 40% of the ARR mix today, you're just 2 years in. Can you give us some perspective and shed light on the design and contours of some of these commercial engagements, the adoption and then the economic impact? I know you sort of peppered in some stats earlier. And then ultimately, what have you learned and changed in the Flex process programming in the 2 years since introduction?
Yes. So for those that aren't familiar with Flex, it's the most elegant go-to-market, I think, that's ever been invented. And I wish I could take credit for it. It was the customers coming to us and saying, "Hey, you now have 25 modules. You have 26. How do we get access to all of it?" So we kind of worked through with our customers what would make the most sense for them. And we wanted to make it really easy. I mean, as I said earlier, George is from Jersey. He's just how do we make this so easy for customers to purchase. So we come with this license where basically you negotiate once and then you've got a deal for a period of time. And then you're able to add more, but not renegotiate terms. It's already done.
It's just adding another PO to an existing contract where the blocker is me, the CFO. But if the business unit owner goes to the CFO and says, "Hey, I need more for CrowdStrike, but I'm going to give you back X for something else and the X is going to be more than what we're asking for CrowdStrike." Well, you don't need to be a CFO to do the math to say, "Okay, let's go do that." In the entire life of software and security for sure, no one really was able to kind of grab on to a license where you have 3 winners at the same time. You have the economic buyer, you have the vendor, us and procurement. I've never seen all 3 of those win at the same time.
So the economic buyer wins because they're able to consolidate, get the best outcomes at a cheaper cost. We win because we're locking in our customers for longer, bigger contracts and being bigger supporters and bigger kind of advocates and trusted advisers and procurement wins because they're after the biggest discount. The biggest discounts are our Flex contracts. They get paid based on additional discounts they're able to achieve. And guess what? Flex allows for exactly that. So you have 3 winners. And then you saw some of the stats, like we now have over 2,900 customers on Flex. You mentioned the 40% uplift when we move somebody from a non-Flex to a Flex. That's up from 34% the year before.
You're looking at folks that are able to look at Flex and look at us and become meaningfully involved with us with a Flex contract. And you've seen some of the data with respect to what it looks like in terms of re-Flex. That's when a customer comes back to us after the original contract. So let's say these contracts are, I don't know, pick a term, 5 years, 6 years, 7 years, whatever the number is. And when we originally came out with this thing, Fatima, we said, "Well, maybe we get a re-Flex halfway through the contract," or whatever it was. It's 8 months. People are coming back to us on average, 8 months into the contract, not even a year and adding more. So you've got re-Flex dynamics, which surprised us in a very positive way, meaning that customers are moving to us faster and with more.
As you think about Flex as the de facto, not even dominant, just the de facto sales motion, how long should we expect to get to 100% of the ARR mix being Flex, Part A. Part B is as you cycle through and build more data points around re-Flex behavior, re-re-Flex behavior and then dare, I say, re-re-re-Flex behavior, again...
Multi re-Flex.
We probably need to figure out a better term for that. What should that natural cadence be? Because I think from a financial standpoint, is there a concern or risk that you might be in a period where it could act like an ELA cliff, ELA-style cliff to your numbers, right? If you can help us assuage some of those concerns as you drive more success with these very meaty long-duration Flex deals.
Perfect. So a couple of big picture items on Flex. Number one, it's a commitment model, not a consumption model. That's number one. Number two, it's not an ELA. You're not getting an all-you-can-eat license with us. You have access to everything, but it is not an ELA -- I lived through those. I didn't like those. No.
Not great.
No, not great. It was painful as a CPA. And then when I think about the re-Flex and the multi-re-Flex data, I think one of the strongest pieces of data we have with Flex in general is the multi-re-Flex. So when a customer comes back more than once, it's a 53% uplift from when they first initiated a deal with us, 53%. That's massive. So to me, out of all the Flex stats that we gave out on the earnings call and at Fal.Con, that one stood out to me more than any of the others. And the other ones were really strong.
But that one kind of said to me that, "Hey, look, customers are going more with us. Customers want to kind of put their chips in with us and be our partners." And to me, there was nothing more evident than, again, the scoreboard. Now why does Flex really work for us and maybe not so much for others, right? You've seen probably other Flex type of licenses that other companies have come out with. Some companies, they don't even change the names. They call it Flex.
Imitation is the...
Imitation...
Sincerest form of flattery.
Fair dues. Fair dues. But here's the difference. For Flex to really work, you need multiple products. We got 34 today, and they need to be turned on instantaneously, right? Time to market, instantly. So you need those 2 things. And if you don't have those 2 things, Flex isn't going to be as powerful for you at all. So when we thought about it, we had that in mind. What are the things that are going to make Flex kind of -- what's the moat around Flex? And it's those 2 things.
Now I, as an accountant worked on for you guys and for myself and my own sanity, I wanted to make sure that the revenue recognition was the same as a non-Flex contract, ratable recognition. So we work with the auditors to be able to do that. And today, there's no mixed models for me, like no confusion. It's the same. There's no additional things you need to add to your model or subtract or take out or fix. It's one model before and after Flex. So saves me from doing a lot of conversation around mixed models and saves you in terms of being able to understand our business and make the appropriate investment decisions.
And what's that journey to 100% ARR make?
Oh yes. So sorry about that one. So the journey is...
It was a multi-headed question.
Multi-headed question. Many of your questions are always multi-headed. I have to...
My specialty.
I need my notes to kind of keep up. So right now, we're Flex first. So basically, if you want to have a non-Flex item, you've got to go to our President for an exception. And that's more painful. It's more scrutiny, tell me exactly why the customer doesn't want to have a Flex license. Have you done your job. It's not where you want to do Flex. You get paid more with the Flex license. And so there's all these incentives to make sure that, that happens. And I do -- I actually do see a world where it is -- there is no other license. It's just Flex.
Burt, you said 34 modules under the umbrella today. I know you love all your modules equally. But in the spirit of it being in a fantasy football season, what are the modules in the portfolio that are in their rookie season that you feel very good about? And what are the modules that are your goats, your MVPs that are driving the bus?
Yes. Giants is going to have a good year this year? I think so, right? Maybe.
Feels like a Chiefs Super Bowl year to me, again.
Yes. There's always hope at the beginning of the year with the Giants. So I hope that you guys do well. For us, though, we've got multiple opportunities, right? So clearly, the rookies, you've got Guardian, that's -- as I said, that AIDR category is going to be, I think, bigger than EDR as a category. And then obviously, SafeMind, I mean, that's just -- we're the world's first security frontier model. And so I have high hopes for that one, too. I think it's going to get a lot of usage. I think if there's a -- we're going to have a different monetization go-to-market with respect to pricing on that one. There will be pack of tokens and then off you go with the upsell and additional packs.
And then you got -- the ones that we've disclosed for so many years. And you've got cloud, it's over a $900 million business growing 29% year-over-year. You've got Next-Gen SIEM, just under $700 million, growing 60% year-over-year. You've got Next-Gen Identity, just under $600 million, growing 33% year-over-year. All 3 of those can be IPOs in today's world, which is different than when we went public, which the bar is higher, I think, today to go public than when we went out. But all 3 of those today can be IPOs. You've got Exposure Management, which has grown over the last quarter. Exposure Management is going to be huge. Like you've seen in the news, Anthropic finding all these vulnerabilities, millions and millions of vulnerabilities. There's no chance anybody can patch all those in a reasonable amount of time.
But our Exposure Management, what does it do? It takes all those vulnerabilities and prioritizes them for you. So you know where to focus and can use us to help patch and remediate. And that's a benefit of what we're seeing with some of the great things that are coming out of the Anthropics and OpenAI in the world is they're able to find things out and then we can come in, prioritize them for you and make it real, right? So we're excited about Exposure Management in a big way. Obviously, I think when you look at endpoint and what's been happening there, you've had 4 quarters in a row, we've had acceleration in the endpoint. And that is because, again, go to the scoreboard.
We've done that because that's where AI is consumed, right? Everybody can talk about whatever they want, go to the scoreboard. I used to always get the question about pricing about, okay, God, you're pricing to the bottom. You're pricing security at the bottom. I am like, what? My margins are best in breed. That dog doesn't hunt. So just -- I mean, you guys are all financial experts. You look at the numbers. You look at the numbers first, do that in this case as well. And the narrative should then play into the numbers. And if it doesn't, well, then do you have belief in these other companies or less belief? More belief? Less belief. So that's how I think about it. So products -- I can't -- it's like pick your favorite pet, right? It's like they're all kind of special to me. And I see just dramatic opportunity in front of us.
Burt, with Exposure Management, it seems that, that is really hitting escape velocity just right place, right time. What would behoove you in terms of what parameters? Are you stress testing to be able to give investors some more visibility around that quantitatively? Largely because the word vulnerability at this conference was one of the most oft-cited kind of term at the conference. And so what would compel you to say, "Hey, this gives me confidence to carve this piece of the business out and talk about it in the same breath as your other $1 billion business, almost $1 billion businesses like Crowd, N-G SIEM and Identity"?
Yes. I mean, we're rapidly approaching the same cadence of disclosures for Exposure Management. We gave out some data in the past. We talked about it being a $300 million business a few quarters ago in ending ARR. So it's definitely on that path. I think that it increased quarter-over-quarter in terms of its growth. So I'm excited about Exposure Management. I'm excited about disclosing more data of Exposure Management as I am AI, right? So down the track, I'm excited to be able to give out numbers and disclosures on Guardian, more on -- and maybe as a group, maybe I'll break that one out, but as a group of different products that we have that are AI related, whether it's Charlotte or even breakout, obviously, SafeMind. I mean there's a few products in there that I would kind of categorize.
I'm going through it now in my own head, like what's the -- I want to give you guys as much knowledge as you can to make the most informed decision you can. I've been pretty good about transparency. It's been, I think, one of our hallmarks, right, in terms of giving you guys enough data to make the best decision you can, highest and best use of dollar of your dollars. And so I think I'm going to be giving those out in the not-too-distant future. Bear with me as I go through when I'm going to be disclosing the stuff, but, yes.
No, we appreciate that. So we talked a lot about Flex as a conduit for more wallet share penetration and expansion. I want to talk to you about QuiltWorks as another go-to-market mechanism where you're finding strength in numbers by building very close partnerships with a very diverse constituency, let's say, right? So a same question around go-to-market and your ability to build consensus and a consortium-focused go-to-market. Tell me about -- and tell us about QuiltWorks and how that's distinct from traditional partner go-to-market motions.
Yes. So QuiltWorks, we handpicked a bunch of companies to help us think through and go to market on a variety of things. It could be in terms of looking at your health of your security stack, right? You can use them and us to kind of go in and say, "Hey, guys, you guys are just -- you're way below the bar," right? "And here's how we can help you." So today, we have 25 companies within QuiltWorks. They've generated or helped us generate $400 million in pipeline in TCV. So it's clearly working. And it gets us closer with the ecosystem, right?
We're going to -- we plan to have more in QuiltWorks. We think that it's a real powerful way to go to market. We've got a great go-to-market motion on our partner side. DB, who runs our entire kind of alliances, GSIs, partners, QuiltWorks. You've had the chance to meet him. He's special. Before CrowdStrike, even during CrowdStrike, I always thought that companies kind of failed badly, certainly in security on the partner side and the go-to-market side. This guy transformed it for me, took it to a different level. QuiltWorks is only one piece of it. The hyperscaler marketplaces is another one. Look at all the work we've done with Amazon. We were even with Microsoft...
Your archnemesis, in some ways.
Yes, perfectly. And in fairness with the folks over at Microsoft, we're trying to work together for resiliency together. So we do things in partnership even with Microsoft. Thank God, Satya has about 5 businesses that are bigger than security to think about. But we're -- they're everywhere, right? Their OS is everywhere. So for us, the QuiltWorks piece is just another element of expanding our footprint and our reach, right? We've got great depth and these guys add breadth. QuiltWorks is something that continues to add breadth in terms of our reach, and I think it's brilliant.
I think another one of the models that you helped pioneer was the ability to -- with the benefit of united terms -- united and unified terms and conditions, help customers retire their hyperscaler spend towards CrowdStrike's portfolio of products. And that was one of a more pioneering effort for you. Where are you on that journey with respect to GMV done with AWS, GMV done with Azure and then certainly, we can't leave GCP out of the mix. So...
We have it all with those guys, right? It's a model that works, right? And everybody is making money on it, right? So that's the key is you got to make sure that your partners make money, right? And if the partners are making money with you, they're going to stick with you and they're going to do more with you. So Microsoft is a big company, right? And they -- as I said, they have businesses much larger than security. So there are pieces of the business that makes sense that we work together on, right? No one was more surprised than me 2 years ago when Satya was kind of at our -- on video at our Fal.Con, I mean, we were trying to work together on resiliency.
And today, we're actually doing business with them, even though we're competing. So as the industry kind of collides, you'll probably see more of that, really, I think, in a good way. I think it's a positive thing. Look, we're still competing as hard as we can in the marketplace for customer dollars. There's no doubt. But where we can work together, we will. And a lot of that is because of DB, and the team that DB has assembled. I mean these are top shelf folks changed my whole view on go-to-market on the partnership side. I kind of -- I come from the old school where you take your head of sales who needs to do something else and you put them out there and hope for the best.
This is not who we are. Let's get the best person for the job, whatever it is, wherever they are and make them the leader and fortify them. Don't starve them, fortify them. At first, I'm the first to kind of ask the questions about you need how much to do what? What marketing programs for your partners do you want to do? How much do we want to spend? I'm kind of like T-Rex, right? Like, wait a second. I promised the street that we're not growth at all costs. We're very judicious about how we deploy our capital. But he comes with ROI.
I want to segue into a conversation about competition. As you've gained prominence and yourself grown significantly larger and much bigger, I'd argue your competitive set isn't your normal and usual suspects, right? How do you look at the landscape today? And who do you see as your prime competitors? And let's talk about the frontier labs, right? Can we put some of the fears and concerns to bed around their potential ability to usurp or commoditize any parts of your portfolio and value proposition. So yes, just kind of broad strokes, the competitive landscape and what you are seeing today?
I love that question, right? So who are my competitors? It's Microsoft. Microsoft, it's not even close. Yes, we have a section with Palo Alto and a section with Splunk and what have you. Microsoft is our biggest competitor. Now having said that, the frontier models, I love that question, right? So let's make no mistake about it. The frontier models for us, the frontier labs, these are friends of ours, period. great customers of ours, great partners of ours. We had Ash from Anthropic in the investor session, and he came up on stage and said, "We're using CrowdStrike to secure our business. CrowdStrike is the security operating system of our business." He said it on stage. It's on video. You can go back and listen to it.
The reason is that we're enabling the frontier models. They see us as a catalyst because they want deployment everywhere, but they know that there are CISOs out there and CISOs out there and companies out there that are fearful of these things going rouge, Hugging Face -- whatever pick one, Hugging Face one, whatever it is. They want us to secure it. So they're our biggest proponents. And what gives us confidence that, well, they just can't create a CrowdStrike. So I asked Graham and say again, and he said, "Look, we -- our Claude code and our really smart developers, they can't build a CrowdStrike. You can't reason our way to CrowdStrike.
The other piece of -- the other side of the coin is they don't have data. We're net data creators. These labs need data. They need data with context. We have both of those things, right? So there -- the partnership is really hand in glove. We have all the data. We have the context center of the data. You can use our data to be able to do whatever you need to do to get the highest and best outcomes for your customers, whoever they might be. So we feel that we're in a fantastic position with respect to the frontier labs to be their partners for years to come. And they know it, not only the frontier labs, we have Jensen on stage. And he's talking about how much of a partnership we have with NVIDIA, right? Because they recognize the same thing. They're going to make their chips safe, right? So George and folks like Jensen, they're trying to change the world. And I'm happy to have a front row seat.
Burt, on the theme of competition, I want to expand the definitional scope of it a little bit. About 15% of your business today is services. So professional services in the way -- and by way of incident response, breach assessment, breach remediation. Frankly, that would bring you some pretty unique angles and perspectives from a product development standpoint. So I want to ask you about how does the strategic nature or how does your services -- professional services franchise stand to become more strategic in the era of AI where we're going to see higher volumes and variety and sophistication of breaches, number one.
And number two, where do you sort of draw the lines and rules of engagement with some of your partners who potentially can compete or would theoretically compete with you in that area? How do you grapple those dynamics?
Yes. So on our P&L, we break out our service deployments about 5%, right? So it's not a big piece of our business. Having said that, it's extremely strategic, as you're pointing out, right? Because we'll go in and some of them will be using some shabby technology and get breached and we come in and fix it, right? That's what that business is. But we also do assessments with QuiltWorks, for example, and do some kind of forward-looking things to preventative medicine, if you will, to kind of make sure that the health of these companies is in good shape.
So for me, I think about professional services as the tip of the spear. It's our biggest lead gen. I think it's one of those things that, hey, we're -- I love it. I want them for one thing selfishly, cross-sell my product. Whatever you do, be friends with the customer, be there for them, they talk to the customers a lot, cross-sell the product. We track that, obviously. That's what I care about.
What do those metrics look like on the cross-sell?
We haven't been giving them out, but they're healthy. Maybe that's another one I might give out more of, certainly with QuiltWorks and everything else. But that -- we have given it out in the past. So we have done it and it's pretty robust and exciting for me. And I don't care who uses our services and what they use our services for. And even if you're a competitor in my services business, and we're in a competitive environment and okay, we lose, but they use our tech afterwards, I'm a happy guy. Win-win, right? So look, I want my services business to do well. I want my services business to win. I want my services business to grow. But it's not first of mind. It's the cross-sell. It's all about product.
I want to shift gears into talking and asking you about how CrowdStrike is consuming and running on AI. So the influence of AI and how you've managed the business and manage a disciplined cost structure and envelope. So how are you balancing accelerating AI adoption at CrowdStrike internally, but also driving efficiencies that are visible on the P&L and to investors?
Yes. Let's take a look at the P&L. So we start with sales. So the sales team has AI type of tools that we use to help them with respect to prospecting, finding out what customers are using, how much they're using. So we're using AI for all that information. Go down to gross margin, our DevOps. So we've got very healthy gross margin. We're knocking on the door of my long-term model, which is 20 -- sorry, 30, where are we now? 20. I want to be between I'd love to be 30 -- sorry, gross margin, I'd like to be between 82% and 85% is my model. We're at 81%.
So we're knocking on the door. We use AI in the DevOps area, which is basically our data centers, and we use AI to help find multiple data stores so that we can consolidate those. And then you go down the P&L into our operating model. So you've got R&D. So we have -- we're using AI. Coders are using AI. They're actually -- I think like everybody else, coders or the traditional coders are turning into reviewers and they're turning into folks that can use 10 agents and just review and make sure the code that the agents are spinning out is accurate and correct. So you're becoming really efficient at what you're doing and you're accelerating what you're doing in your business from an R&D perspective.
And even in G&A, think about legal. You have all these companies that are out there doing good work that we can leverage. Legora is one of them that's out there that you can leverage and you can look at a contract and just isolate all the non-unique and unique terms. So we're using it there. I use it in finance for automation. I closed my books, by the way, in a day. So in one day, I can go to you guys. Now the auditors take time to go review everything, but I'm ready to go to you guys to the street in a day. One quarter, it was a day 0, I could go to you guys, right? And that is a lot of automation. There's a lot of AI in there to kind of help me through that. So it's manifesting itself across every line in the P&L in terms of top line, in terms of bottom line, we're trying to be efficient with our use. When I budget -- so I have lines in the budget for every group and I budget a certain amount of AI spend, tokens, right?
So I have amount of tokens that each group can have, and that's what you have. And here's your overall envelope, expense envelope and tokens is part of it. AI is part of it. And we have technology that can monitor usage, meter usage. So if you're over a certain amount, you're cut off and then we investigate why you're burning through tokens faster than you should. And if it's for good stuff, great, you get more. If you're building a game, you're out, right? So we do monitor this stuff. So we're using it prevalently in our work.
Burt, I think it's important spending a little bit more time on the gross margin banding that you shared, right, 82% to 85%. As the business continues to become more data intensive in terms of telemetry generation from agents and a bigger footprint, I mean, what are some of the things that you're doing to be able to maintain such a high watermark of gross margins as you are ingesting even greater torrents and avalanches of data and digital exhaust to be more efficacious for your customers?
Look, this is my favorite topic.
Love gross margins.
Gross margin.
You were at 30% gross margin 12 years ago.
I know. We were talking about that when we were private, and I said, I'm going to turn this company around and I'm going to take it public on gross margin. So we've done a great job, obviously, but we've got more to go. So when we think about who we are today, we've got public cloud, private cloud on the public side, their partners are doing great. We look for less expensive areas by geo. So there could be -- for example, Amazon has West 2 versus West 1, which is a lower cost colo, and we use more of that. We're now pretty big. And so we consume more.
So we leverage the discount capability, so with the public clouds. Private side, we have our own clouds, and we're looking for opportunities through AI, some of it in terms of the multiple data stores, but also migrations. What are the expensive things that we're paying for in the cloud that we could do ourselves. So I feel good about our trajectory to get to the -- even the higher end of the long-term model in gross margin because of those things. And I think it really helps.
Now I'm sure that some of you are thinking, well, for your older -- for your own data centers, isn't the cost of a big iron expensive for you folks? And yes, I talked about it at Fal.Con. It's gone up to 11%, 12% or projecting to go up to 11%, 12%. But I've already baked that into my free cash flow margin for FY '28. I said it's going to be 32.5%. So I've taken up my free cash flow margin, knowing that I'm still going to have some of these expenses that I'm going to have to pay for with respect to more expensive hardware. So I feel pretty good about all of that combined.
This is a great way for me to round trip back to our opening dialogue around your medium-term financial targets, which you did update last week. So whereas we were looking at a $20 billion ARR target in fiscal '36, we're now talking about that within fiscal '35. Whereas we were looking at a $10 billion ARR bogey in fiscal '30, we're looking -- '31, excuse me. We're now looking at it within fiscal '30. What are the 3 most sensitive or influential catalysts that would have those outcomes happen in fiscal '29 and in fiscal '33?
Yes. Look, I mean, Guardian, that could be something that can propel it for sure. You have just the continuation of the big 3 that I like to call them, Next-Gen SIEM, cloud, Next-Gen Identity. Next-Gen Identity -- we'll probably talk about it if we have time. But that's a huge catalyst for us, right? We spent a lot of money. We bought a lot of companies within that category, and it's done extremely well. As I said, that is part and parcel with what we're seeing in this AI revolution. So I think those are some of the things that can continue to help us get to those targets in the first place. And hopefully, if they do really, really well, exceed them.
And remember, when we think about the $20 billion, we gave examples at Fal.Con that we only need to penetrate those TAMs at about 3.5% across the board. 3.5%, we're averaging 4%. And one does well, you're miles faster. So I get really excited about how low the bar is in terms of market penetration to get there on a product basis. So I think that with our go-to-market engine, Flex, all these things combined, I feel really good about those -- bringing in those dates with hitting $10 billion and $20 billion.
Burt, I want to end our conversation asking you about capital allocation, especially around M&A, your size, your scale alongside how rapidly we're watching IT lines blur between one another. How do you think about transformational and larger M&A? You've got the share price currency for it. You've got the market size and dominance and test for it. What is the framework for M&A today? And how has that evolved in the last 2 years?
It's actually stayed pretty constant. We're looking for great tech and great people. It starts there. We're not buying ARR like some of our competitors. We're looking -- look, if we found a much bigger company and it obviously came with ARR, but it had great people, great tech, we're going to do it. The bar for us isn't -- obviously, it's an input is price, but it's the tech. So if a company that we're looking at has an agent and we can't smash that agent into ours, it's an immediate no. If we don't see a path or if the path is going to be too long and we got to rewrite the whole thing, no, we're not buying it. Having said that, if it's -- if we see a path, then that's pass that bar. And for us, it's about the integration, the seamless integration. That's the starting point.
Price, we negotiate and whatever it is, we can -- if it makes sense, we're going to find a way. But it's really about the tech. So for me, I would love to do bigger deals. I'd like to do more deals. I'd like to do bigger deals. I'd like to do it all. But in this case, the CFO is not the gatekeeper. It's the tech people. It has to fit in. When we bought Preempt, which was the base of our security product, we knew that at the time, it was going to be 1 year, 1.5 years to kind of integrate, and we said it's worth it. So we bought it. We waited 1 year, 1.5 years. We integrated it seamlessly, and then we started to sell it, and you see the results today. So today, with AI and everything else, we think that if there's a technology like that today, we'd be able to integrate it a hell of a lot faster, maybe even as quick as half the time.
So these are all good things for us in the end for us to be thinking about M&A. And I think our -- George, our CEO; and our President, Mike Sentonas, they get 10 calls a week. I get calls from the other side on the investment banking side, think about this one, think about that one. And then we have a whole ecosystem of folks that constantly are calling us with respect to the companies that they think could fit well with us. And so we've got a huge and healthy pipeline. We also hired a guy at Okta to run our corp dev, Peter Sizgoric. So he's a machine. He's able to siphon through all these companies and give us the take on them pretty fast, rapidly understanding how they can fit into our company. So we have -- we do have a machine, but we're not out there buying ARR. That's not who we are. Buying great tech, great people, that's never going to change. Big companies could come with ARR and so be it. We'll be prepared for that.
Burt, my last question for you is, what is one consistent palpable, salient investor misunderstanding or misperception that you'd like to wave away?
Yes. So the one thing that I'd love to leave you all with is that the Mythos moment wasn't just the start of something. It's going to be enduring, it's long. And it's not just about Guardian. It's about selling the platform. The conversations that we've seen, the demand that we've seen post the Mythos moment has been incredible. It's in the numbers. It's back to the scoreboard. And so I'd love to leave you all with the notion that the Mythos moment wasn't just about Guardian, it was about folks consolidating with us, highest and best use of their dollars going with us, being a strategic partner with us, being -- growing with us and us being able to enable them to roll out agents, but also protect all their other environments, whether it's cloud, whether it's endpoint, whatever it is.
I think that's the biggest -- it's not a misconception. It's something that maybe the lightbulb doesn't go off for everybody to say it's more than just Guardian what we saw with the Mythos moment. That's the biggie for me. And I think we're at this moment in time where it doesn't come too often. This is a gift. This is a gift to us, and I'll take gifts. But I think it's a big one. I think it's transformative for us as a company. I think it's -- it could be the biggest act in our company history. So hopefully, you get the same feeling in listening to me talk today and your great questions to get that feeling that that's truly how I feel.
Burt, fortune favors the ready. So, we're watching. Thank you so much. This is fantastic. I appreciate it.
Thank you. Great to be here. Thanks, guys.
CrowdStrike Holdings Inc — Citi’s 2026 Global TMT Conference
CFO frames a sustained "Mythos moment": record Q2 ARR and product momentum (Guardian, SafeMind) plus Flex license driving durable growth.
📣 Key Message
- Message: Management says the April "Mythos" incidents accelerated customer demand for AI security; Q2 was the company's best-ever quarter (net new ARR strength and record free cash flow) and CrowdStrike's endpoint‑centric platform positions it to capture durable AI security spend.
🎯 Strategic Highlights
- AI products: Guardian (agent protection) is positioned inside a new AI‑driven detection/remediation category (AIDR); management expects AIDR to be larger than traditional endpoint detection (EDR). SafeMind is a frontier‑model security offering with tokenized pricing planned.
- Flex license: 2,900+ Flex customers, ~40% of ARR, average re‑Flex at ~8 months and multi‑re‑Flex customers show a 53% uplift—Flex is driving faster expansion and longer commitments.
- Platform scale: Several large product lines approaching billion‑dollar scale: cloud (~$900M, +29% YoY), Next‑Gen SIEM (~$700M, +60% YoY), Next‑Gen Identity (~$600M, +33% YoY); Exposure Management is accelerating.
🔭 New Information
- Updates: Management reiterated earlier target timing (moving $10B and $20B ARR targets sooner), confirmed Q2 net new ARR strength ($333M, +51% YoY), said SafeMind revenue not expected this fiscal year while Guardian/AIDR is already in commercialization, and flagged forthcoming disclosure plans for Exposure Management and other AI product metrics.
❓ Analyst Q&A
- Budget timing: Why not an immediate security budget surge? Management: enterprises fear rapid AI deployment but budget cycles and controls delay spend; CrowdStrike benefits because AI is consumed at the endpoint where they have strong footing.
- Flex cliff risk: Is Flex like an ELA cliff? Management: Flex is a commitment model (not all‑you‑can‑eat), revenue recognized ratably, and strong re‑Flex behavior reduces cliff concerns.
- M&A & capital: Acquisition focus is on tech and integration feasibility (agent compatibility); they won't buy ARR for its own sake—price matters but fit and integration speed are decisive.
⚡ Bottom Line
- Conclusion: CrowdStrike presents a constructive growth story: endpoint data advantage, strong product velocity (AI guardrails + platform modules) and a rapidly scaling Flex motion should sustain ARR expansion; key risks are enterprise budget timing, successful product monetization (SafeMind/Guardian), cloud cost trends and execution on disclosure/integration milestones.
CrowdStrike Holdings Inc — Fal.con
1. Management Discussion
Good morning, everybody. It's great to see everybody once again. best to see everybody live and in person, and welcome to what is our biggest Falcon event ever. And we've never been more excited to host you with so many of our customers here, so many of our partners here. Hopefully, you've had a chance to talk to a few of them.
Hopefully, you had a chance to catch some incredible keynotes from George and Mike and others. It's been a fantastic start. We've got a really, really exciting lineup for you today. And I'm going to go over to the quick agenda and hopefully, you're able to leave here with the same feeling that I have when I came here and I'm feeling today about the opportunity in front of us.
So George is going to come up first. He's going to talk about our next chapter securing AI. We're going to then have a customer fireside chat with DB. We'll have a customer and partner filed a fireside chat with DB. Then we're going to have a little break for lunch, a quick break. Maybe about 25 minutes. Then we're going to hear from Mike, the winning platform for the AI era. Then you'll hear from me, I'll come and finish it off. And then we'll have a quick interlude and then we'll go right into Q&A.
So I'm excited for today. I hope you guys get a lot out of today. We've extended the Q&A session well was 1 of the part of the feedback that we got from last year, you guys wanted more time with us. So not only are we going to give you more time for Q&A, but George, Mike and myself are going to stay extra after, so you can have one-on-one conversations with us. All right. So enjoy the day. Let's kick it all off.
Please welcome Chief Executive Officer and Founder of CrowdStrike. George Kurtz.
Well, I can't believe with an event that we've been able to pull off. I think one of the premier security conference is now, and obviously, we get to spend some time with the financial community, and it's important to be able to what we're building, the innovation that we're driving at CrowdStrike and more importantly, how we're solving customer problems.
So with that, I will jump into the presentation. And as Burt said, we're excited for the fact that we've got more time to answer questions, which I know many of you want to get through. So what is the state of AI? Some of this should be self-explanatory, but I at least wanted to go through what we've seen in some of the numbers this McKinsey stat.
If you look at organizations that used at least one AI in at least one business unit, it was 55% 2, probably like a PT and today is 89%. ChatGPT messages are up 8x and reasoning tokens, 320x that's where we are today, right? So we started with chatbots, then we moved to reasoning. Now we move to agents. That is driving, of course, the spend.
And I always talk about following the money. There's always this question, I know in the financial community. Is it a boom? Is it a bubble? What's happening? Is it going to last? Because we've been through fits and starts in AI for a long time. If you remember the cycles of AI and machine learning and those sort of things.
I think where we are, to me, it's very clear that this is a megatrend that we've never seen before, and it's the fastest-growing transformation of spend in the enterprise history. And just look at the stats, $2.67 trillion with a T in 2026, going to $5.95 trillion in 2030. Again, a Gartner stat.
So for me, if we follow the money, it's all going to make sense and what that means in terms of the opportunity from a security perspective. Now we've seen this movie before. And we've seen it with the cloud adoption and the hyperscalers. And what we saw over a period of time is the adoption of hyperscalers.
I remember when I started CrowdStrike, we were a very early customer of AWS I think they had like 5 services at the time, compare that to today. But you can see the slope of the curve over time and the adoption of the cloud. And there was a point -- if you remember in the not so distant past, where you would walk into a financial services company, maybe like yourselves.
And you would say, hey, let's talk about the cloud and they go we're never going to the cloud. That's a risky we're not going to do that. Think about where we are in 2026. So if you fast forward to looking at cloud security, and I say this all the time, security parallels the slope of the curve, the technology curve.
So if we just take cloud as a, again, a tectonic shift in technology, you can see cloud security actually paralleling the slope of that. Now if we plot Frontier labs, it's a much different curve. And it's something that I've never seen before. I don't think any of us in our lifetimes have seen growth as what we're seeing now in the frontier models.
And you can just look at the slope of their revenue and sort of what they put out publicly, if you will, even though many of them are private. But in general, you can see how fast the adoption is and how fast the spend is. Well, certainly, I think the adoption now for security is going to parallel that. And what's important to realize there we go.
What's important to realize is that -- that's okay. Just keep it over there -- is that securities role is different this time in that security is now the accelerator not to break. And in many of the technology shifts, it was like, well, security got to get in the way, and it's going to slow us down. Now you have to have security in order to go fast.
And that's one of the defining changes that I've seen in security and AI. So adoption is a necessity. It's larger net new opportunity and it's immediate and rapid spin. And what I would say specific to this is, again, just sizing the opportunity, if it's 2.6 today, going to 3.6 and you took a simple example, just a simple one.
Now you can put your own filter on this. But if it was 1% of the AI spend going to 8% of the AI spend, it's to $36 billion to $291 billion opportunity for security. Let that sink in. And again, apply whatever filter you want on it, what I can tell you, it's big.
And I'm a simple math guy, and I look at this and I look at AI and my simple math is, do I think there is going to be more AI in a year, in 3 years and 5 years than there is today? And if you can say yes to that, then the natural corollary is then by definition, you're going to have more security for all of that AI that's created.
And where we are today, I was talking to Jensen in the green room we're just talking about the future and where things are going. And what we're seeing today, we're probably going to laugh in 5 years when we come back. We're going to remember these kind of simple concepts and what it was able to do.
And the more complexity that you have, the more security challenges that we're going to have to face. So massive opportunity. It's a sustained opportunity and it's certainly not just kind of a peak of what we're seeing. Now I've said this, you've heard me on the conference calls, we've talked about it on many of the one-on-ones.
I see AI security being bigger than EDR. Obviously, when we started the company, we redefined the market. There wasn't even a term called EDR, but we redefined it and we knew we built a big business and obviously now built a big platform company on EDR and then obviously in additional technologies.
But when we think about the velocity of the initial launch, just to put it in perspective, I'm not going to move around a lot because of my mic here. So I'll just kind of stay here. But if we think about the velocity, when we launched EDR we saw a 10x increase 3 quarters from launch. Now a different time, it was a lot earlier in the life cycle.
But what we've seen with AIDR is a 79X increase in uptake just after 3 months. A massive adoption. Yes, we're a bigger company. It's a different period of time. But I like 79 and I can do math pretty quick. And to me, that is a ski velocity. So what's driving this? Why is it happening? Well, AI has evolved -- if we think about the non-agentic adversary that we've been fighting for many years when I started the company, dwell times, we're in the months. expertise, you need nations that need to have high expertise -- the cost was high.
The success framework was a 1060 in terms of minutes. Now the agentic adversary has really changed everything, talking about seconds minimal expertise cost is negligible and it's in real time, right? The speed of inference, you saw my keynote yesterday. So it just dramatically shifted in a very short period of time.
And this is what customers are facing. From nation state to agent state, I went through the pyramid of pain, as I call it, which is hacktivists at the bottom, e-crime in the middle, nation state at the top, but now it's the agent state.
And that agent state now is powering and enabling everyone to act as if they were a nation state and really flattening this curve of expertise. Whether it's a activist or an e-crime group or an agent, they are all in the same category. They all have the same level of expertise.
So let's talk about Cyber's next frontier. Where is it actually going? For us, we made an announcement yesterday. We talked about the cyber security Super Intelligence Lab. And why did we create this Well, it's important to realize like where the world is. You have Frontier labs, which have done a tremendous job.
We partnered with them. They're changing the world. But again, the success criteria is a little bit different. If you look at what they're focused on building incredible models, selling lots of tokens and solving lots of broad problems, fantastic for society.
Crores Frontier lab is really focused, solely focused on solving today and future cybersecurity problems with Frontier caliber technology from a model and a harness -- and that was part of our Safe Mine announcement, which we're going to get to.
So what's important to realize here is where the technologies evolve what we've done with NVIDIA, what we've been able to reproduce in our labs, and we'll go through some of the stats the capabilities are now being put back in the hands of the defenders, which was, again, a big part of my theme.
The adversaries have frontier caliber, AI, but the defenders didn't. So let's jump into this. a little bit more. So Super Intelligence Lab is totally focused on Frontier AI research, open weight, open source model training. We've been big proponents of these technologies.
And again, open source and open weight are actually 2 different things. If you look at Nemoto from NVIDIA as an example, it's actually open source and Open weight. Some of the other models are simply just open weight. So use a combination of these is fine, but a lot of it comes down to the harness engineering, right?
What Jensen said, the exoskeleton of what makes the model work. And we've seen incredible advances in the harness engineering that we've been able to build in the reinforced learning based upon the massive amount of data that we have, the team, the patents, the partners and then obviously a national security element to this.
So why are we trusted with this data? Why are customers looking at us to solve some of these problems at the scale at model scale? We generate 7 trillion security events per day, which is a massive amount of information. So we are a net creator of security data. And you heard me a couple of quarters ago in the SaaS apocalypse, saying, like if you are a net creator of data, you're going to be very sticky, right?
The data that we have is not available. You can't go to Red it and go find Crown Strikes telemetry and security data. So when we think about the training of these models and the outcomes that customers are looking for, it does start with the data.
Cyber expertise, just to give you a few stats. 270 PHDs, 300 AI researchers and 500 threat researchers, right? And that doesn't count a whole bunch of other areas that we're focused on. And the R&D investment over $1 billion, you see the ecosystem. I'm not going to go through all the names. But we're in the right place with the right people and the right technology at the right time.
All right. So why does cybersecurity need its own model and harness. I think hugging face was a great example of why the defenders were out matched. And when you look at that example and you go through lessons learned, we got lucky that the model and the agents were totally focused on passing the test rather than causing havoc and damage. -- if it was a nascent state, it might have been a different outcome.
But when we look at the frontier models, they're really good at general knowledge, finding all the possibilities, but they can be very expensive. And this very specialized model that we built, we'll go through the red and the blue.
It's cyber specific mastery. This is very important. Our models are not designed to solve the world's complex math problems. They're designed to solve the world's most complex security problems, precise deterministic outcomes, deterministic outcomes.
This is very important. Everyone in this room has used a model somewhere and asked the question 3 times and got 3 different answers. That's not great in security. So you have to have deterministic outcomes and what customers are looking for is cost efficiency and data sovereignty.
Where is the data that customers care about from a security perspective. Last I checked, it's in the Falcon platform. And you know what they don't want to do, they don't necessarily want to ship it out and pay for that; and two, have it in some other place that maybe they're not as comfortable as having it in the Falcon platform.
So these are very important elements of why customers -- they literally moved us after the announcement yesterday on the models and when they can get access to them. So that's why we announced cybersecurity front, first frontier model and harness family combined as an [ Ingenix ] system, which is safe mine.
It's a family of models, open source, open weight, CrowdStrike data and the CrowdStrike harness that, again, we've taken our expertise. We've worked as well with NVIDIA. You heard from Jensen yesterday, on what we've been able to do together. And there's a massive focus from NVIDIA and us to be able to take these models and to be able to create them in a way that they can be very specific and solving security use cases.
And we did a lot of engineering with them. We did a lot of work in the training. We did a lot of post training. We provided feedback in what we want in future models. And I think we're in a great position to continue to deliver an at-scale model with incredible performance and cost characteristics. There's also a routing layer.
I talked yesterday about model choice, right? So when we think about the models, sure, we have models but there are other open source models, fantastic. You have frontier models, right? You heard from OpenAI yesterday. You're going to hear from Anthropic today. At the end of the day, we want to use the best models, the best tools to get the best outcome for customers at the best cost.
So there's a model routing layer. And by the way, this opens up an opportunity for us to be able to provide technologies like Frontier labs to our customers and be able to monetize that through the platform, which is really interesting, right?
Because we become a distribution path for the Frontier labs as well. Trusted partner, trusted data, data sovereignty and again, allowing customers choice to get the best outcome, which is stopping the breach. And providing automation and capabilities that they couldn't get from any human on the planet. So let's talk about the model.
You've got Red Tempest, which is our red model. Of course, this is the model focused on finding vulnerabilities, finding exploits and finding ways to attack. So you need a red model. And part of what I talked about in the keynote was there's been a lot of work around finding vulnerabilities. Hey, I'm going to basically run this model over my source code, I'm going to find a ton of vulnerabilities, I can create some patches, but then what do I do?
So to be fair, the industry has been focused on finding all these vulnerabilities. And if you understand code, great, you can find a lot of vulnerabilities in source code, but then what do you do with all that?
So you have to have a red model that's focused on delivering sort of security offensive capabilities at nation state level. and find ways to attack. But at the same time then, you must have a blue model. And this is the area that I highlighted in the keynote, which was really a missing piece to me.
If you think about all these models, they've been focused on the attack piece, the red piece, not the blue piece. And what we've been able to do is to create a blue model that actually learns from the red model that detects threat stop breaches and user cyber tooling to stop the attacks.
And this is one of the areas, just think about the hugging face incident. And when I told the story -- I mean it's out there, it's their story. I kind of repeated it yesterday, which was -- they didn't know what was going on. They had some signals. They saw all volumes of attack 17,600 attacks that they saw, looked like in nationstate.
They try to piece it all together. They went to the frontier model and it refused. Refusal rates. This is a problem, okay? So when we think about Blue Solano, these are the kind of technologies that organizations need to be able to in real time, provide a view of what's happening, provide defenses.
But more importantly, when you look at putting red and blue together, it's this constant learning loop. This is the unique piece. You're constantly learning from the red team. Now why is this important for us? Well, scale matters in AI. I think we all know that.
Scale matters in AI. If you have a massive amount of data, which we do, and you have a massive amount of telemetry which you're getting every day. And you understand the attacks because you're seeing them. You have threat intelligence. You have an MDR service like Falcon complete. You have this constant loop where you're always learning from the adversary. Those get fed into the model. And then very quickly, we can run attacks either in a real environment or I showed the digital twin, where we can actually simulate an environment so that we can understand what the exploitability is.
This is a very important term that the industry is focused on exploitability because you can't patch everything. We hit the sound Barry on patching. So you need to know where the priority is -- you need to know what controls are in place and what risk is out there if you don't take an action. This very quickly just as one use case.
I mean it's an unlimited number of use cases, models in a harness one use case that our customers went nuts for because the digital twin aspect of recreating the environment. We actually know the environment. We have the agents running.
We have the identities. We have the infrastructure basically math of what's running. We know every system, we know what's on it. right? We know the versions, we know the vulnerabilities. So in our digital twin, we can recreate that very quickly and then begin to create these automated loops of red and blue testing and then go back to our customers and say these are the things that are really important.
Again, I'm giving you one example. It's an unlimited number of examples of what we can do, but this is what we actually wanted to show. So very excited about SafeLine. Now what does it all mean? And these are the benchmark testings that we did. So let me just take you through. We have Frontier Lab 1 and Frontier Lab II and then we have Blue Solano. You can see Blue Solano had detection rates, 37% better detection rates than Frontier Lab 1 and 29% better than Frontier Lab II, okay?
Because it's very specific in our domain, but what was it trained on? It wasn't trained on a bunch of stuff on the Internet. It was actually trained on some of the most valuable security and threat data in the industry, which is what we've accumulated over the last 15 years. So detection rates better.
Number 2 is the cost per task. So what this is saying here is you got Frontier Lab 1 and 2 and that Red Tempest was actually 66% less or 78% less per task. And then when you look on the blue side, it was up to 99% more cost effective. So I'm going to let the numbers sink in because in your travels, I'm sure that you're talking to customers, you hear -- you ask anybody that you bump into, they will say, man, the cost is out of control. I'm trying to use these models and it's like amazingly how amazing how expensive it is.
So what they want is they want the best outcome using the best model with data that is protected in some fashion, sovereign to them or with a trusted partner, and they want the lowest cost. And that's what we're delivering. Better value. Now we look at detection speed.
But last I checked in security speed matters, right? Matters in racing and it matters in security, 2 things that I like. And we are 6x faster with safe mine detection. Now what I want to reinforce here is that, yes, you have better detection rates, better value, faster speed, but it isn't just the models, right? It isn't just a harness.
It's the combination of all these put together in a system, which is constantly learning from a loop and creating this kind of reinforced learning element to it, red and blue and then being able to have the flexibility across the massive data set that we have. This is how you achieve frontier level performance at a fraction of the cost.
So really excited about that. Now I couldn't go through this without -- I'm going to try to get to this to avoid the questions that I'm going to get anyway. So how are you going to price all this? What does it mean?
Now this is very important. So there will be initial token packs. So there will be CrowdStrike tokens. So that means a different way to monetize the platform. I'll say that again. There's now token pricing, which will be a different monetization stream that will be open CrowdStrike.
This is exciting. There will be token expansion packs where you can buy more tokens and it's all supported by Falcon Flex. So I talked about Safe Mine as being the harness for our cyber models, but the commercial harness is Falcon Flex, and they go together hand in glove.
Now when we think about the tokens and working with customers, I can tell you what customers don't like. They don't like variability. They don't like runaway spend. They don't like surprises. Nobody does. And I think they're getting a lot of that with some of the other technologies that are out there.
So what we're doing is really looking across the entire organization, figuring out how many tokens they need as a company. And then we can set bands of token usage and they certainly can burst up from that. But again, we want to put them in a position where they can understand and predict their spend at the lowest cost.
Again, but remember, we started [ QuoteWorks ]. We did a lot of work around AI readiness using our technologies, but it was the setup for the trusted partner and access program that we've created here. So we're going to first work -- if you want to just get access to the models directly and outside of the Falcon platform, you're going to be able to do that, but you need to be part of the Quote Works program.
So this will be in review, and we'll be rolling it out over the back half of the year. So again, you got to make sure that you've got the right partners, you got to put the right controls around it, and we want to get the right feedback.
So we're excited about this, but we want to be very thoughtful about how it gets rolled out and the folks that we're working with. So that's availability and monetization. Okay.
[Presentation]
All right. Well, for me, again, seeing this technology in action, there's a lot more that we haven't exposed. It's been an incredible journey. And again, I think when we look at the next active CrowdStrike, to actually be able to operate a frontier type model specific to cybersecurity and the ability to actually monetize that through token flows is exciting for me.
And again, I think the sky is the future when we think about how many agents are going to be available and how much environment will actually change over time and how important these models will be to our customers. So we'll talk a little bit about securing AI and agents.
As I mentioned in the keynote, AI is the new attack surface. Right? We originally started the company protecting computers and people. Now it's about protecting agents. This is a stat where today, on average, or evolving that they believe there will be 90 agents per person, per employee.
And the reality is that's today or in the near distant future. If we think about agents themselves, it's almost unlimited. It's almost unbounded. Why should you have 90 and not 1,000 or 10,000, right? Who knows what it's going to be? I don't know, but I sure know it's going to be more than 90 and we have the ability then to tap into a TAM that really doesn't have an upper bound.
You're not talking about just cloud workloads. You're not talking about just systems. You're not talking about just employees. You're talking about all the agents that get created from now in perpetuity that we have the ability to actually protect.
So for me, that massively expands our TAM and part of the reason why we pioneered AI DR, right? AI DR AI detection response is a new category, right? The product is Guardian, but the category is AI DR, just like EDR was a category. And AI DR is focused on visibility, discovery, where are all my agents.
One of the biggest challenges that you're going to find when you talk to customers, they don't know where AI is taking place. They don't know where it's actually being consumed. So first, you have to find it, understand what shadow AI is, who's hiding cloud somewhere, who's hiding this? Who's running that? We can do that. Then you have to have AI control and guardrails and then certainly, you have to be able to protect the prompts. Is it a malicious prompt, what is it doing?
What is it sending out? Mike did a great demo this morning on that. So Guardian AI agent security is something that we've worked on. I mean it was around the clock that we worked on this with some of our biggest partners. Right? Some of our design partners.
So we worked -- our biggest design partner on this was Amazon. You heard from CJ this morning if you're in the keynote. So this is something we've been working on at scale to meet the most demanding enterprise. And we launched this during my keynote.
We flipped it live, and it was operational. And the results that we've seen so far are incredible. So let's talk about Guardian and the Agentic security life cycle. So an agent gets created, well, you need to know where it is. It accesses data, and it has permissions, it has an identity, right, and it has permissions and entitlements.
It then assigns tasks it executes. And at some point, it gets decommissioned. It could be a short running agent or it could be a long running agent. But you have to be able to instrument all of this, and Guardian covers every stage of the agent life cycle and provides visibility and traceability on exactly what it's doing.
So think about a financial institution. You can't go back to a regulator and go, well, I don't know what happened, like it was some AI thing. You can't do that, right? You have to be able to know exactly what happened, what it did, what it touched, what identity it was and have full traceability -- so obviously important from a security perspective, but it's going to be mandated from a compliance perspective.
There's no way -- it is not going to be something that every company that is regulated, public company in a certain industry is not going to have. It will be a must-have technology. Number two, what does it actually do? It discovers the agent, it controls and observes the agent run time, run time.
This is something you've heard for us, what, 15 years, the agents run and they're commanded by a prompt. And then it detects and stops threats. So one of the cool things that we've done is we've now combined the prompt layer into the run time layer. And Mike's demo this morning talked about putting a prompt in that would have just gotten through sort of anything because it looked like a benign prompt.
But unless you're actually looking at the run time and understanding what's happening, you're going to miss it. So we've taken our historical heritage and expertise over 15 years, and we've combined that with prompt visibility. And essentially, our agent, sometimes down to the chip layer, I talked about Intel, but our agent being able to have full visibility into the operating system, the prompt the application may be a browser.
Maybe it's a electron app, which is how AI agents -- sorry, how AI applications are consumed by cloud or chat PT all the way out using identity to where that agent is actually talking to. So what does the future look like? The future of endpoint, and I say endpoint, and I'll say workloads here is cloud and endpoint.
And I've talked a lot about endpoint. But the reality is we have a lot of customers actually running this in their cloud workloads. So I don't want you to miss this point. It covers endpoints. You're on your cloud, you're on your codecs covers you, no problem on all the other applications.
But you do have customers that are now running these agents in cloud containers, a femoral containers, where we actually instrument those too. So we work in both environments. And oh, by the way, there's a third one called SaaS agents. We instrument those 2. So you have 3 areas, my focus has been on endpoint just to kind of make the point, but we're covering all 3 of those areas.
That's a very important piece that I want to make sure that you don't miss. We can protect these agents wherever they run. Endpoint cloud or SaaS environment. So you combine that with identity, next-gen identity, which is our nonhuman identity for agents, 0 standing privileges only getting the entitlements you need at the time of execution and then they're gone.
This is critically important and creates a control plane from an identity perspective. And then obviously, Guardian wraps this together with visibility protection control. And this is really the future of what endpoints and cloud workload protection looks like.
All right. Falcon Flex, we're going to go through these obviously, accelerating our adoption almost $2.3 billion in Flex -- total Flex value, 101% growth. Last quarter, 935 new Flex opportunities added you can see the growth there. It's been something that quite -- it's been remarkable, the success we've had with it.
And again, I call this the commercial harness. So much so that everyone in the industry is coping flex, they don't even bother to change the name of it. But each Flex is not created equal, and I think we've done a good job of leveraging this with our customers.
The other thing that I'll mention, too, is just by having something you call Flex doesn't mean it's operationalized. We invented it, and we've been at it the longest. What that means is we know how to sell it internally. We've enabled our partners.
We've enabled the third-party ecosystem like the marketplace is to be able to deal with this and you have to have the systems that actually work. So there is a barrier to entry because you have to make all that work before you can just say you have Flex. And this is why we've driven the friction out of this model.
So what's our next chapter? Well, I think we're in an incredible time period in technology. I mean I couldn't be more excited about just the technology changes that are coming. And we've got the right technology at the right time. Right?
Cyber is at the top of the list of everything that we're doing in terms of AI, and you're not going to be able to accelerate the adoption of AI without cybersecurity when Jensen and I had our first call on building out the models probably 6 months ago, he said, George, this is the most important thing I'm working on with you.
We've got to solve security because he knows if we don't solve security, it's just going to hold back AI adoption. So this is very important. So right technology, right time and the right execution. We've got an ecosystem look, I'm blown away when I come to this conference.
This is now an industry conference. Look at all the partners that are here. You will talk to them. They will tell you, this is the most valuable conference they come to. Just from a customer perspective. And by the way, we've opened it up, we have competitors here.
It's been an open conference. It's been incredible, but you have to have the right ecosystem, and you have to be around long enough to realize how important the ecosystem is. If you just -- [indiscernible] lately, you may not know how important an ecosystem is, and we've cultivated that over the last 15 years.
Right go-to-market with Falcon Flex and as I said, at the right time. Security is how AI scales. And this is one of the reasons why we've been able to leverage the right technology with the right commercial harness to solve problems and have them been solved in the past.
So for me, I really think it's an inflection point for CrowdStrike. You can see the momentum, which we demonstrated last quarter, you can see the demand environment is not a spike it's sustained. And I think that's important because spikes is buying more of something.
Sustained is solving a different problem, solving a different problem. And the problem is AI security, and that's a long tail problem there's going to be plenty of opportunity to solve. So with that, I want to thank everybody here.
Obviously, we're going to be up for questions. And I look forward to chatting with you soon. Thanks so much.
Please welcome Chief Business Officer at CrowdStrike, Daniel Bernard. And enterprise go-to-market cybersecurity at Anthropic, Ash Alhashim.
Good afternoon, everyone, both in the room and those watching. Wow, what a great conference and how cool is it to hear what we just heard from George and to have the leading frontier lab and Anthropic here on stage with us here at this conference. Everybody sit back and get ready for some interesting, good conversation.
I think the feedback is consistent that everybody enjoys these sessions. So we're going to make this interactive. And it's an honor to have Ash, who leads the cybersecurity go-to-market anatropic with me up here today. Ash, I want to start our discussion.
First, focused on Anthropic as a CrowdStrike customer. Congratulations. You guys won a big award today. But talk a little bit about that journey from when we started working with a company, nobody had ever heard before. playing around with AI a number of years ago.
Yes. First of all, thank you for having me. It's a pleasure to be here. I joined the therapy a little less than 3 years ago. And back then, we've been working with CrowdStrike as long as I can remember, it was a very different kind of company.
It was an AI research lab, very focused on safety. We didn't have the household name that we do today. And a big part of when you think about our mission and you think about what we're trying to do and what's at stake, we want to usher in transformative AI in a way that benefits humanity in the way that is safe and helps the world. In order to do that, you got to go fast.
You have to have smart people, you have to have a lot of things, but you also got to just move incredibly fast. And one of the kind of principles, I think that guides a lot of our decision-making is like building with the best building blocks. So reinventing the wheel in an area like security that goes so deep and just doesn't make sense, partnering with the best partners does make sense.
I mean you guys are essentially the operating system for how we run our how we secure our company. And without -- what I can say is like we use Falcon across the business. I mean, indeed, the benefits of like the in security, all the threat intelligence and telemetry that comes off of that just makes us -- allows us to be able to scale really, really effectively while remaining incredibly secure.
Cloud next-gen, you guys really -- you really use the full stack I think one of the questions that I heard a lot earlier in the year and maybe one of the questions that's on everybody's minds here is like, why didn't you guys just Cloud code your way to CrowdStrike. That was when Frontier labs really came out and came out with some really cool harnesses and I think the technology really evolved. That was sort of one of the questions of the day. And so what better way to answer that question than actually ask the source.
Well, I mean, first of all, I'm like legally obligated to say clock code is amazing and very or everything. But at the end of the day, I mean, in all seriousness, it's -- this is a very effective development productivity tool.
You can build really, really cool things and 1 shows some real apps with cloud security. But again, going back to -- we use CrowdStrike ourselves to secure our business. This isn't something that a [ cladcode ] or even a team of very talented engineers working company like Anthropic can just build overnight.
This takes time, skill, distribution network effects, a level of determinism that comes with experience. I mean these are hard fought things that you've learned over decades effectively. And you can't build a product like this. A lot of this is just inherent to like the time it takes.
So when we think about what CrowdStrike is for us, it's like it's the operating system for security and cloud code, again, while useful in building some things, it's just not -- it's not going to -- we're not there.
And the data is also something that I think we talk about too, maybe your perspectives on what we do over there.
Absolutely. Yes. Again, going off like the telemetry and the -- that you all have the data that you've gotten. I mean, this is proprietary data. This is -- George was talking about how these models are trained. Obviously, there's a lot of inputs that go into these things. But a lot of it is public knowledge and working on helping these models get better at reasoning over time.
You can't reason your way to building something like a crowd strike. This is something that, again, takes a lot of like industry skill expertise and the proprietary data that just can't be amassed in other ways.
Perfect. Well, I think that's really a clear way to capture the question, the creative question of, can you cloud code your way to CrowdStrike and you heard the answer right there from Anthropic themselves. So maybe moving along a little bit into some of the last 12 or so months, and really, it started a lot earlier than that.
Anthropic and CrowdStrike working together as a partner. Let's maybe go there next. And we'll come to meet those, but like a lot of the things actually predate dose. So why did Anthropic start working with CrowdStrike? Where did that journey start from your perspective?
Yes. I mean around the beginning of last year, our Frontier Red team and our post-trading team started to realize these models were getting more and more capable or technical tasks, coding was like the first breakout use case that we had late 2024.
And over time, in early 2025, we started to realize these models are starting to get be I don't know if I would use this term capable, but knowledgeable, Sentient and aware of how these things work. And we just -- you could see where the curve was going.
These models were eventually going to get to a moment where they could become very, very effective and highly capable and dangerous, they're dual use, right? There's offensive capabilities as well as defensive capabilities. So in the wrong hands, these models could do a lot of damage.
In the right hands, we can really protect and secure the world in a way and at a scale that we've never been able to before. That's where you all came in. I mean, you were one of tiny handful of companies where we had amazing researchers, industry expertise.
And we needed to work with you because, again, going back to our mission, we want to make sure AI is safe and beneficial for humanity. We don't get there by going and try to do all this ourselves. We also don't have the expertise that you all have in security.
So we work with you very closely to help us train these models, tune these models to be even more effective at certain cybersecurity tasks with an eye in mind of like making sure that these -- we tip the scales as much as we can in favor of defensive use.
And also to learn how to make these models generally more safe, like to build better safeguards for responsible deployment. When it comes to the other part of like the ushering in transformative AI in a way it's beneficial to humanity, we need to -- we knew we would need to lean on the distribution and the reputation and the brand and the trust that CrowdStrike has in the market.
As a company, we talk about this a lot. We see ourselves as an intelligence hyperscaler. Just the same way 10 or so years ago, companies started moving everything to the cloud for compute, we think of ourselves as providing that same kind of layer of intelligence that other organizations can build on. That's our heritage.
We work with -- we build for builders. So working with CrowdStrike to build -- help you all build solutions that are powered by AI, which is where we are best in class and marry that with what you're best in class at is just the right way to get broad distribution in ways that benefit ourselves and our partners as well as the world a lot.
Perfect. Let's go back to April of this year where we all encountered the Methos moment, as we call it here, inaugural founding members of Project Glasswing from the start, working very closely with our friends at Anthropic. What did that really change in your perspective and the team's perspective on cyber? And how did it also evolve your business?
Yes. I mean the methos moment was kind of like an inflection point where all of the sudden again, we knew the moment was coming. It was just a matter of how big it would be and when it would come as the outstanding question. And when we're close to finishing training meet those, we realized wholly held. This is here.
So there were a few things that we wanted to make sure we got right with launching ethos. Number one, again, like our safeguards needed work. We needed time to catch up and these models were generally made safe.
And we needed to get the word out to the world, and we also needed to work with our closest defensive partners to help you all hard indoor systems and prepare your customers so it was very fun to work with you all in those early days.
I mean one of the reasons I think we also partnered with you was not just like the business benefits and the distribution but also just the quality of your engineering teams, the product team researchers. This is not an industry that's known for moving slowly, right?
So we can't afford to partner with companies that just can't keep up, and you guys have been tremendous at the pace that you've been able to offer.
And you guys have also been super helpful and Quit works our program over there, where our -- some of our trusted partners that are part of that program, use our technology and your technology to really deliver Frontier AI readiness at a new scale. So that's been a great collaboration, and we appreciate that.
Moving along, we talked about this past year I want to now hit the partnership work we're doing and things we're doing in the market. Specifically, at the platform level, the vision here is to enable different module experiences within CrowdStrike to be powered by different Anthropic models when a customer wants that to happen. Can you talk about that strategy on your side? And what does it mean from a token flow perspective?
Yes. I mean I think we just announced the marketplace work we're doing together. So now a big part of how we think about working with our partners. Like CrowdStrike is we want to, again, expand our reach, lean on the strength of our partners, the network effects, the reputation of the trust. But we also want to make it good for our customers -- or for the end of mutual customers.
Removing friction, aligning commercial and operational incentives. So these things all matter a ton. And what having CrowdStrike products available in the marketplace allows for on the entropic marketplace allows for is a couple of things.
Number one, no longer are our mutual buyers kind of doing the fight of like, is this an AI line item or a security line item. Now these things are kind of merged in source Exactly. You can -- if you have a commit with Anthropic and you have a commit with CrowdStrike, you can use a CrowdStrike product on the therapic marketplace and burn down our simultaneously.
So hugely beneficial to our customers and really unlocks a lot of speed. It also -- I mean both of us are thinking about net new logo growth. And in particular, now we have the benefit like reaching into your distribution network and you have the benefit of reaching into ours. Companies that have come to lean on us for that premier like frontier model intelligence and lean on you for their security needs. They get it all in one place.
Yes. Today, we actually announced that today the marketplace go live, which opens -- I mean, Anthropic has done a fantastic job building the premier Frontier lab business in the last couple of years.
It opens all the investments that companies have made in anthropic to utilize that investment on CrowdStrike purchases. So we're really excited about that. And I think you guys are very forward leaning in how you're engaging with the ecosystem, engaging with us.
And then even at a product level, the build-out that's going to -- that were going on together in terms of powering certain modules to be Anthropic-powered modules. It all comes back to what George was talking about customer choice.
And getting to the point that a customer can bring a token, their AP IT and actually use their anthropic spend again to activate different experiences within the CrowdStrike platform. with us being involved in the token flow. I don't know if there's anything else you want I think that's sort of like the big journey absolutely do well. That's exactly right.
Perfect. Great. Lots of opportunity there. And again, ASH was here. We started our week with our Partner Summit. Partner Summit now has over 2,500 folks there. It's the folks who are on the floor or the folks who bring us to market every day, the folks who implement our technology -- and I think it was very powerful for them to hear from you as well there on how you want to work with the ecosystem. Maybe some thoughts there on how you want to work with the ecosystem.
Yes. I mean it's -- again, we talked about like the commercial benefits of working with the ecosystem. I mean it's a good business for us. It's a good business for you. As far as Beyond that though, I mean, I think technically and operationally -- again, like I said this, I think the other day, which is like if you want to go far, you don't go it alone, right?
You need to partner with companies that you trust to have shared admissions and rent kind of strengths that help you with your thing. So building an ecosystem is a huge part of how we go to market, and it's going to become an increasingly important part. I mean the Anthropic marketplace itself is very young. You're one of our. .
It might be the first security partner.
The first security partners in there. So very happy to have you there because it's going to become such an important part of how we go to.
And I think underneath this the collaboration, and you were saying a bunch of nice things about the folks at CrowdStrike, and I would echo it right back to you. We've been on these paths before and we listen to each other. And so what we've learned in succeeding with many other hyperscaler marketplaces, we're happy to share that intelligence with you so that it's very successful over here. And it's good. That's all goodness and opens a lot of doors for you and opens certainly a lot of doors for us.
So to kind of round out our chat today, what gets you the most excited about working with CrowdStrike? There's a lot of names. There's a lot of folks. There's a lot of places. There's a lot of choices. We have a very special relationship. And what is it about that, that kind of you want to share with this audience that makes CrowdStrike unique and special?
Yes. I mean these are strange times, right? Like the early Anthropic, we used to say things will never be killed again. It's definitely proven out to be true. And in moments like this, where it's like uncharted territory, we're all figuring it out together. You really just -- you have no chance of winning if you're not doing it with folks you enjoy working with who are like-minded, who can operate at the same speed.
So I would break it down in like the business parts and the engineering or technical parts, the engineering, like the savvy and the speed and the scale that you all can operate at gives us a lot of wind at our sails.
And then on the business side, again, it's like the fun, the network, the relationships. I mean, I'm a salesperson by training. So it's my favorite thing of the world to come to things like this and hang out with folks like you and George and team and meet customers and alike. So yes, hugely -- a huge fan of being able to do this together.
Well, thanks. And I think we certainly find ourselves in a lot of the same hallways in accounts. And it's good for us to be able to help your customers optimize and use their Anthropic spend and unlock more value. And certainly, it's something that we hear a lot from customers, answering the question that George really talked about earlier, how do we secure agents.
So together, I think we really fulfill that vision, that mission. We had a great chat today about your thoughts on both CrowdStrike as a customer and what you hear from the team over there on how we partner together at a technology level, on a go-to-market level and ultimately, how you can't cloud code your way CrowdStrike. And with that, thank you, Ash, for the time. Thank you so much.
Appreciate it.
Please welcome Vice President Enterprise AI of NVIDIA [indiscernible]; Vice President Business Development of [indiscernible]; and Chief AI and [indiscernible] Officer of CrowdStrike [ Barley Richardson ].
Okay. We've got a good exciting panel here. bringing another aspect of diving head first into AI to the forefront, a great crew. And we're going to talk a lot about Safe Mind here next. And this is really the crew behind from an ecosystem perspective behind the announcement of Safe Mind yesterday. Barley, I'm going to start with you. So we have fantastic collaboration with these partners who are also customers and friends. I want to start the discussion today talking about the problem that we set out to solve, the problem when you came here and the opportunity, what was the thought process and the genesis really of Safe Mind?
Yes. It's -- and we kind of took a very straightforward path, like the premise and the setup is fairly simple, right? I think we all heard from George last year talk about cybersecurity, AI and cybersecurity super intelligence. And so we start from that premise, right? And I think we've seen a lot in the news we've seen about models, agents, harnesses, all the tech we can talk about being used for all these offensive capabilities, right, like able to evade, able to attack.
And so when we set out to think about Safe Mind and what we wanted to add to the conversation was, well, how do we take best-in-class AI? How do we take best-in-class models? How do we take best-in-class harnesses and engineering and really advantage, and I would say disproportionately the Defender, right, like versus the attacker. So Safe Mind is about harnessing all this power and everything that you -- that we hear about, which is valid and these models have real capabilities, right, like to find vulnerabilities and exploit. But it's taking that and harnessing it and turning it back towards the advantage of that Defender.
Justin, I'm going to come to you next. NVIDIA is a key part of how we were able to productize and deliver Safe Mind, specifically with Nemotron. So maybe walk us from the audience perspective back a little bit, like talk to us a little bit about why NVIDIA made Nemotron, what is Nemotron? Feel free to introduce it to the audience. And then we'll come back to open source a little bit later, but take it away on Nemotron.
Yes. So our view as AI has advanced is there's a lot of great advancements happening at the frontier. But if you can build open models that are near frontier, you can unlock many new use cases across industries. And so the goal of Nemotron is to build an open foundation that every company can domain adapt into these new domains and unlock new business.
I think if you look at the open source software industry, it powers 80% of the digital economy today. In the long run, I think open models will power 80% of the intelligence out there in the world. And it gives really a cost-advantaged way to run AI in these specialty use cases like cybersecurity. And our approach is put the data out there, put the techniques out there openly, put the weights out there and then work with experts in industry like CrowdStrike to do that domain adaptation so you can have always-on lowest cost defensive AI to help defenders.
And certainly, open source is something that's near and dear to our hearts as well. You guys are active in that active. I think there was a letter back in the summer, maybe a little summary on there. We were proud to be, I think, the first cyber phone call on that one.
Yes. Well, this all starts, it's funny with the models. And I think the conversation stops there too soon. The harness is really where the frontier is happening right now. And we also, I think, created this program together, we call it the Open Secure AI Alliance. And that was really to teach the industry when we're talking about auto run on these models to do autonomous long-running work, there's a model and there's a harness.
And -- and so there's a safety question that the industry has that if an agent that has the wrong understanding of its goal, decides to break out of an environment, like where does that probabilistic system meet deterministic controls. And the only way that the industry can understand where these agents are going is if we all share traces from these agents. And if there's a lab leak, you'd want to look at the trace because then you can know exactly the attack path and what can be exploited. That allows us to, I think, build the mitigating controls into the right security layers within an organization. And so I think that openness and transparency across organizations is going to allow us to build the best defense and the best deterministic controls for these future Frontier AI Systems.
And that's certainly the journey that we went on and the value that we see in Nemotron. Now all this needed a home. And Sean, I'm coming to you next. We needed a performant AI Neo cloud with the right GPU stack with the right inference speed. Can you talk about the rise of CoreWave, what you guys are up to and a deep partnership that you have with NVIDIA as well that really brought us together?
Yes. So CoreWeave is a purpose-built AI cloud. So we have more than 50 data centers and growing. We offer the latest and greatest NVIDIA hardware. We're predominantly 100% NVIDIA. And then we build a very thoughtful software stack on top of that to offer an AI cloud to our customers. We've actually been a long-time partner of CrowdStrike, where CrowdStrike, I would say, is our #1 security partner. We work very closely with them to secure our infrastructure for our customers.
And about a year ago, I think after a meeting with NVIDIA and CrowdStrike, NVIDIA said, "Hey, you should talk to CoreWeave as you start to build these Agentic systems and offer them to customers." And I remember very late on Halloween because I skipped taking my kids out working with CoreWeave to get this done. And it's -- sorry, working with CrowdStrike to get this done. And they've moved incredibly fast. And it's amazing to see. We work with a lot of SaaS and security companies. And just general sort of software companies.
And I would say that CrowdStrike really looks more like an AI company to work with the speed they operate at and just sort of you can see with Safe Mind and what's been produced and released over the past year is really incredible. So for us, we have the training and inference infrastructure. We've partnered with the team. We're looking forward to now going and seeing how this scales to all of our customers.
Fantastic. So the building blocks, the ingredients, Nemotron, need the home, CoreWeave as the Cloud, partly right back over to you. Let's talk about the performance and what we've already seen so far with the design partners and in the lab on what Safe Mind is capable of.
Yes. It's really encouraging. And like you said, there's a lot of moving pieces and there's a lot of blocks and a lot of components that go into this. Certainly, it needs a home, certainly it needs models, it needs harnesses. SafeMind is actually comprised of 2 different classes of models. We call them Red Tempest and Blue Solano. And the core premise there is that the best defense that you can make must -- it must be informed by the best and the most and many permutations of offense that you have.
That's driven and accelerated by also CrowdStrike's wealth of data in all of these areas, right? Like we have over a decade of experience in both red teaming and offensive capabilities on counter adversary side. But we also, on the Defender side, we have an equal or even greater amount of data that we see when our Overwatch teams or our SOC teams are actually going in and providing the remediation -- so we not only see the outcome, we see the whole path that they took, the reasoning path that they took. So that allows us to post train and train these Red Tempest and Blue Solano models that are highly performant.
And Dan, to your question, what we see is, one, it has to be that first, you must be accurate, right? Like so if you're going in and you're using a model like Blue Solano to automate your defense and remediation, it has to be accurate. It has to do what you wanted to do. And we see comparatively with just if you were to go to the AI shop and pull a model off the shelf and pull a harness off the shelf compared to that, we see a 70% increase in accuracy versus that, right? Like -- and that's due to all the fine-tuning that we were able to do, like Justin was saying, we're able to take a model near or at Frontier capability, use the data from CrowdStrike and blow a path right like this. So a 70% increase.
So at first, it must be accurate, right? Like it must do what you want it to do. And then second, you really quickly realize, well, it must be cost effective, right? Like if it's accurate, you also must be able to run it at scale, at speed because these defense and remediations, you're not doing it once, you're not doing it twice. This is continuous. We're in the world of continuous defense, continuous remediation. And on that front, again, versus you go out and go to the leading frontier -- go to the leading frontier capable model in the leading harness, we are 99% cost reduction from that.
So to give you an example of that in dollars per remediation, right, per detection that we go and remediate, that's $10 before, and that's down to $0.03 now.
Fantastic results, and so much of it became possible through the deep collaboration over the past year with NVIDIA. That collaboration really started years ago working with NVIDIA, but the last year has really been an accelerant in terms of the technical collaboration, the amount of time and the folks and people that have been invested on it. Justin, I want to ask you, having been involved with us at a very deep level, can you talk about what this partnership means to NVIDIA and how you guys work with CrowdStrike?
Well, I'll just say it's a pleasure to work with you guys. You guys are so fun to work with because you move fast. I think George and Jensen, you could see the kind of the relationship they've built sitting down with each other, talking about where the industry is going and talking about how we make the world a safer place.
And it takes both of us. We are really just an accelerated computing company. We like to make algorithms run faster and more efficiently. Jensen will talk about the 5 layer cake. That's really because power is the limiter. And then you want to make sure that you can generate tokens at the lowest performance per watt. And if we can do that, and we can work with you guys on cybersecurity, we can make these AI models run faster and more efficiently on partners like Core Weave -- we can do it at scale, it can run anywhere, any cloud, any data center, any infrastructure to deliver like the lowest latency results.
And I think the shared mission across the teams is we want to put the defenders at a differential advantage. And so kind of with that is the North Star, you guys have the data. You guys have the perception of every enterprise system and customer all the attack insights of what's going on, both with human attackers and now agentic attackers. And so we working together, I think, can build the best, most cost-effective, most widely available system. Totally agree.
And it's really not like a, oh, here's our drop, -- good luck, guys. Feel free, Barley to jump in and even Sean, because you guys work so closely with NVIDIA as well. when you're at this level, it's not like, hey, we're going to meet next Tuesday or we'll see in November. It's a full contact sport.
I mean that's how Jensen is. So it's a full contact sport, maybe some insights on that collaboration. It's a mosh pit in all the great ways, right? Like we have all of the experts, I sold that from Justin, right? Like I told that comment from Justin. But it really is that. Like that's the speed you need to move at, right?
Like that's the speed we must move at. It's to Dan's point, it's not like, yes, it's got on a call on Tuesday, and we'll work through these types of things. And then it's not like, oh, let's get on a call and then we'll have our engineers on this call, and then we'll have our product people on this particular call.
No, we all get together all working the problem like in real time, right, like in solving it in real -- there's been many days where I've been on the phone with Justin or I've been on the phone with or we or like our engineers have been talking in real time and we'll go to headquarters. And I think that's the key. One is like having all the people there, like in the right place to do it, and that can virtually in the right room, white boarding.
But it's not a, we do this at this cadence. This is the job, right? Like this is the job, and we're doing the job all the time in this very highly collaborated all the best ways of mash pit full team sport. Sean, let's cover our partnership together.
What we're doing together I think we pioneered a very new exciting type of partnership in the neo cloud space. I don't think it had ever been done a security company in a neocloud. Why don't you fill everybody in on what we're doing together, both within Core weave and then in the market.
Yes. So we've grown extremely fast. I actually came through an acquisition of a company called [ Waybiases ] to CoreWeave. And it was incredible to see at the pace that we're adding infrastructure and that we're also adding customers and then also just the general demand.
One thing the team at CoreWeave saw super early is that security is very important to our customers, very important to us, and we've made a huge investment there. And deploying CrowdStrike across our estate was sort of the first step. And I think as we see some of the newer solutions that CrowdStrike is offering from the Pangea acquisition, we did a very nice integration with the Pangea acquisition and some of our software tooling to help customers secure generative AI.
And then beyond that, now with Safe Minds, we really see that as an opportunity to go together both to the AI natives, but also the enterprise and bring joint solutions to them. And so we're extremely excited to see this, one, out in the open; and two, how do our sales teams and our go-to-market teams talk to our customers and solve real problems for them.
Yes. I think of CoreWeave, I think it's an important point to make here as really a net new greenfield attack surface. I mean a couple of years ago, there weren't -- nobody had ever heard of a Neo cloud. There was no such thing. And it's this whole new world that's emerged. And it's a whole new set of workloads that didn't exist before either that runs on the Neo cloud.
So it's really important. I mean, none of it would be possible if it wasn't for the foundational layer that NVIDIA has brought to the world, but the attack surface has just expanded so much. We have a huge opportunity together to go secure all the great work that your customers do. Of course, it's an honor to secure you and we love your cloud, but there's a sizable opportunity in the market that we're after together.
Yes. This is all net new as well, right? Like all of our customers use hyperscalers. This is just an expansion of the market. And so we really see a huge opportunity.
So Justin, maybe rounding it out a little bit here. Why do you guys work with CrowdStrike? Jensen had a lot to say on stage, but I'd love to get your thoughts on why we're on this mission together, why our companies work together. There's I don't know, 3,000-plus security companies in the world. There's a lot of great ones downstairs. Everyone should go check them out. But we put a lot of effort, focus, attention in a concerted manner on you. You guys certainly do the same for us. Why?
I smile [indiscernible], because I can get a hold of you. Anytime I to. you guys move fast. I think you guys have deep expertise in cybersecurity. We're a big customer of CrowdStrike. I think Jensen said it on stage, you're his #1 cybersecurity partner because you guys have this vision for how to secure the world's infrastructure. And we don't want to be a cybersecurity company. It's very clear. We know what we do. We can accelerate algorithms. We can make LLMs run fast. We can create a foundational digital intelligence for the world. But you guys have the domain expertise. You guys can really take it into every global enterprise in every country to secure the digital infrastructure that's critical to our economy.
Well, I think what our panel today really represents is in essence, the power of the crowd. And I mean that because there's a whole new world as AI came and collided with security over the last couple of years, there's a whole new world that we've embraced a whole -- a lot of great people and a lot of opportunity.
And certainly, we haven't sat on the sidelines investing heavily in these partnerships, utilizing the tech working very closely with the people to innovate and co-innovate and create new solutions for customers. And I think SafeMind is a great example of that. It's the next chapter for CrowdStrike.
The fact that now we're a frontier lab, cybers first frontier lab, and the honor of building with and on NVIDIA and having the home for that be Core weave and then the fantastic results that we're delivering in the market. This is the full circle right here, and we wanted to take some moments to share it all with you. So thank you to our panelists, and I believe next up is lunch.
[Break]
Welcome President of CrowdStrike. Michael Sentonas.
Good afternoon. Great to see everybody in person. We always do this every quarter over Zoom. It is much better, I have to say, doing it in person and getting an opportunity to see everybody and to connect. As you heard from Bert at the start, we'll make sure that we have a lot of time for Q&A and get an opportunity to see everybody afterwards.
So I hope everybody got to see the keynotes over the last couple of days, I've spoken to a few of you. So I know some of you have, which is absolutely fantastic. What Falcon for those of you -- and I know some of you are here for the very early days back in San Diego.
Great to see how this -- how big this has become in such a huge community event. And it gives us a great opportunity to connect with you all, which is absolutely fantastic. Let me go back to last week, we shared a lot of numbers with you all. Fantastic results, talking about how we achieved $5.8 billion in ending ARR, which represents a 23% CAGR over the 2-year period.
This is incredible, and I just wanted to sort of unpack a little bit of this as we go through the numbers. It's about 30% of our weight to our $20 billion ARR target we provided last year at the Investor so I'm going to unpack some of this and dive into a little bit of this and talk a little bit about how we're going to get there and just give you a view of walk to how we get to that $20 billion products, the investments where we think we have an unfair opportunity, and I want to step you through that, which I think is going to be a lot of fun to go through.
Now those of you that were here last year, you probably remember this slide, it was in the deck that we shared with everybody. We talked about our rapidly emerging businesses. We talked about identity, next-gen team cloud. Key drivers of our $10 billion to $20 billion ARR targets, which have performed incredibly well.
I'm really proud of the way that the team has performed and we shared numbers across those areas last week. Just to kind of take a little bit of a step forward as we talk about this path to $20 billion. Let's just start off with the key information straight up.
Today, I'm excited to show you that we believe we can reach the $10 billion ARR target within FY '30. Similarly, we believe we can reach the $20 billion target within FY '35 and I'm going to talk you through the path to get there. So this is an important one.
And I think if we look at the path to $20 billion from a market share perspective and what we have to do, the target addressable market, which go through with you every year continues to get bigger. It is a staggering $565 billion market by calendar year 34.
When you look at all of the pieces that go into the portfolio that we have, this is not all security. All security is obviously big. And these are the areas that we play in and technology that we believe we have a right to win in, and I'm going to talk through.
Let me break this down a little bit for you because when we think about that path to 20, how do we get there? We talk about market share in core endpoint. If we look at how we're performing there, we talk about around modern endpoint, we have around 20% of the market. Close to 50% is still using a lot of the legacy.
But then if you start to look at and you build that out and I will go through a little bit of the product areas and you start to think about the market share that we have and how we get to that $20 billion start to unpack a little bit of this.
From a market share perspective, if I take a step back, on average, we've covered -- we've captured roughly 4% share of the security market that we address for the last 6 years, start to play some of that math forward on that path to $20 billion. What do we need to capture in calendar year 34 on that path to $20 billion.
So if you start to think about that math, we have to -- we only have to capture 3.5% of the market in calendar year 34 to hit our $20 billion ARR target despite the fact that we've averaged over 4% market share every year over the course of the last 6 years.
We obviously strive for a lot more. But I'm just talking you through an illustrative path to that calendar year 34 time frame. Let me jump into the product and let me unpack some of the opportunity by product. So jumping into this. Let's start with the genetic security. We're going to start there today. We estimate this market will reach $115 billion in calendar year 34.
This is where we look at technology like Safemind and Falcon Guardian, which we announced yesterday, Charlotte, AI Gateway, new announcement that I made this morning. If we capture 3.5% of that market, we can add $4 billion in ARR. And as you heard from George, we launched a new AI model called models and harnesses called Safemind incredibly excited about this when you think about the applications and the problems that we can solve.
This is very, very significant. We announced Guardian this week. Today, I announced the AI Gateway and additional innovations that we're working on. Hopefully, you saw some of the demos where Guardian is working with other products, you're going to get the opportunity to build on the platform and see how all of the components can come together.
So let me jump into Guardian and unpack a little bit of this. Hopefully, again, everyone saw the demo. This is incredible innovation that we built in-house. We took the Pangea acquisition. We took some of the capabilities that Pangea brings, but we also took the sensor and the platform, which is the incredible point to sort of touch on for a little bit. We give customers the ability now to see what agents are doing.
We give customers the ability to control those agents. We start to have the ability to understand what you're doing in cloud in codecs have a look at [ Kyro ] to have a look at the open weight models and start to make sure that anything that's going on inside the organization that's happening at machine speed, Guardian has the ability to either give you visibility to give you some control, but importantly, to stop attacks.
I talked about supply chain and the threats of supply chain and agents having the ability to pull down packages and compromise an organization at a speed that we've never seen before. all part of the same capabilities with Guardian.
So that visibility across the entire estate. This is one of the biggest things that CISOs are asking us for, CIOs are asking us for tell us what's in our network, tell us who's using it, tell us what they're doing with it, tell us what tokens their spending and help us get control. And we've answered that question, which is absolutely phenomenal.
The architecture that I stepped through as well today, and I'm just going to touch on this a little bit here to make sure that everyone caught that or if people weren't in the session is really important because we think about AIDR as a category when we've been talking about AIDR, we think about the data, the identity, the applications, the infrastructure, the models, all of this has to be protected.
This is what you need to protect yourself in an AI world today. It requires a comprehensive solution. It requires a platform you're not going to stitch this together with 10 different products. It's going to be very hard to be able to do that.
That's why we've been making sure that we bring Guardian together with a sensor, with the platform and then it becomes an off-ramp to all of the other products across the CrowdStrike platform. That's really, really important.
So adding capabilities around discovery posture hooks into identity, data protection will have a reconnaissance as a technology category because wait until you see an agent that starts to [ exfiltrate ] data and every organization on the platform on the planet, I should say, if I can speak English this afternoon.
We'll start to want to bring in data protection solutions into their organizations. Run time guardrails, response, SaaS, endpoint cloud, everything needs to be part of the capability here that we talk about. So this is important for me because when we think about the journey that CrowdStrike has been on, EDR defined how we secure the endpoint.
AI DR will define how we secure the estate. And Guardian is how we deliver it. Hopefully, that's super clear. I want to roll the demo again because this is a pretty cool demo and I'm super proud of this one. So roll the demo.
[Presentation]
Now a lot in that demo. And the coolest thing for me, when George announced Guardian, yesterday on stage, the product became generally available for every one of our customers, literally in the 30 seconds, the first 30 seconds of that announcement, which is fantastic. We've got a flood of customers last night saying, how do we get it?
Falcon Flex, call your count rep asked for the module to be flexed in and you're using Guardian. It is a license entitlement. The sensor was updated some weeks ago for all of our customers. So today, we have customers that are running Falcon Guardian. So incredibly proud of that project.
Let's talk a little bit about how we win in this market, which I think is very clear to everybody. AI has to be secured at run time. We already have the sensor on the endpoint where agents run where the models and applications run.
Even if you're using frontier AI in the cloud, you are connecting from the user, from the endpoint, you're leveraging identity, you're connecting to those models. We give visibility and control into that whole thing. We have the data in the context that no other vendor has because of that visibility.
And finally, you need to have protection across the entire Agentic attack surface. That includes as I've said, models, identities, applications, infrastructure, all of it, the Falcon platform covers all of it, which is incredibly powerful. Now another topic. We've been talking about this for the last couple of years. Let's talk about the Agentic SOC market and opportunity.
We estimate this will be a $52 billion market opportunity by calendar year '34 I'd like to unpack a little bit of this. Again, let's use that same math. If we capture 3.5% of this market, of course, we want to do more, that would equate to $1.8 billion in ARR.
So let me get that clicking. Now here's a different perspective, a different way to look at this. Unlike Falcon Guardian, which is a new product, a new category. We're not starting at 0 in this market, we have nearly $700 million in ARR from our Next Gen C business. So to capture 1.8 of that ARR in calendar year 34, we only have to grow our annual recurring revenue at a 13% CAGR, which is very achievable, I would argue.
So as you can see from this slide, we're currently growing that we're currently growing our ARR by 60%. So again, just playing that out, so you can see an illustrative example up through the calendar year 34. So I talked a lot about this morning. Even with an army of agents, even with a lot of solutions, defenders still have one problem, and that is time.
I believe, and George talked about it in his keynote, the concept of breakout time that you've heard from us for so long now is probably disappearing because things are happening so fast that you need to operate at machine speed.
So we talk about agents and adversaries more importantly, having the ability to reason to adapt to act at machine speed that breakout time as a concept is basically at 0 today. So the reason why we talk about this is attacks that way for humans, which means the solutions that we knew that we use, that organizations use to protect themselves need to discover this decide and move in real-time speeds.
And if the breakout time does get to 0, if it's happening that quickly, the time to investigate will also go to 0. That's why the old stock model is broken, and we need to think a little bit differently, attacks that move at that real-time speed need solutions that can bridge that gap.
So why don't I show you another demo and jump into the AgenticSOX solution built on next-gen same. Roll the demo.
[Presentation]
We're faster. We're natively available to all of our customers, and it has a massive disruptive price structure. Faster in terms of the way that the technology is architecture, which is critical to winning in this space available to all of our customers.
We did the work several years ago. Every one of our customers is next-gens enabled. License entitlement to turn it on if they want to use that. And importantly, we do not charge them for the data that's already native to CrowdStrike.
We also given capabilities like federated search leave data where it lies and give them the ability to search across data source. So architecturally better, smarter, faster and a much more disruptive price opportunity. So let me sort of touch on the identity market.
We estimate this will be a $48 billion market in calendar year 4. Again, playing out of the math. If we capture 3.5% of this market, this will equate to about $1.7 billion in ARR across an entity, privileged access management and so on. And as I said with NextGen [indiscernible] this is not a market that we're starting at 0.
With nearly $585 million in ARR from our next-gen identity solutions. And today, we launched Agentic identity provider, which means we're well positioned to grow our ARR at a 14% CAGR to reach $1.7 billion in calendar year '34. As you can see by the chart here, we're actually growing at 33%.
So you can do the math across this. So I want to walk through a little bit about how the solution works, how it's a little bit different. And then you can see how the solution is going to win in the marketplace. And the reason why this is so critically important today with identity, people get trusted when they log in, they get trusted when they authenticate access that they keep and is persistent in their session.
That's the wrong way of looking at identity. We need to flip the model, remove standing privilege and give access only when needed, give access that's tightly scoped to the task, give tightly scoped access that is short-lived, which reduces risk. And then when the task and the work is completed, access is gone.
It's a different way of thinking. When agents hand off between each other. You have the ability, again, to give agent to an access to remove it as the hand-off complaints and make sure that you remove all the risk inside the organization.
That's why today, we announced CrowdStrike Agentic identity provider solution, which extends continuous identity discovery enrichment and z-standing access to all agents. I hope the demo works this time. Roll the demo.
[Presentation]
So this is how you solve identity problems today. Solutions for both humans and agents, which you saw continuous access, which you saw the addition of single AI acquisition that we made at the start of the year gives us incredible power and opportunity to make sure that we enforce 0 standing a privilege. This is mandatory to solve identity problems today.
So let's wrap this up and look at everything that we've talked about. We know that adversaries are going to use autonomous systems to find weaknesses to adapt to attack our defenders are going to need the same solutions to be able to respond.
They are going to need to use AI to defend against AI. We have the single AI native platform that can do that for our customers with simple deployment with the one agent, one sensor solution. So just jumping through this a little bit. When you start to sum up the total AI security opportunity in front of us, we estimate that, that will be $215 billion by calendar '34.
If you recall from George's presentation, we tied AI security spending to the overall AI spend, he showed a slide range of 1% of the spend at the low end and 8% at the high end, which equated to a range of $36 million to $291 billion.
So this market estimate sits towards the high end of that range. If we can capture 3.5% of that market, that would equate to $7.5 billion of ARR in calendar '34. That $7.5 billion is roughly 38% on of the $20 billion target that we are chasing. So we're incredibly excited about the AI opportunity that's in front of us. That $7.5 billion that we can potentially add to our in calendar 34 is incredibly exciting for us, which is why we are so focused on this as we start to build out our platforms and work with the team.
So we announced an incredible amount of innovations this week. We've still got to go platform enhancements new features, new releases. And I can't say this enough, I'm so proud of what the engineering team has done, the speed that they're working out to get customers the right solutions that they need to protect themselves -- this is the summary. We'll make sure that you all have the slide. I'll be back for Q&A. Thank you.
I heard a lot of things today. I heard one of the front tier mall guys say reasoning can't build another CrowdStrike. They don't have the data. They don't have the context of the data, and they don't have the expertise. I heard that over and over. I mean, that was pretty cool. .
I mean I knew that, but something else when somebody else frontier guy says that. We heard from our core -- we friends and NVIDIA friends, and you combine that with what George had talked about with Jensen yesterday, it all is packaging up for us to be in this unique opportunity in its time in this world where something has come to us, and we were ready for it.
And that's the important thing to take away. CrowdStrike is ready for what's coming, right? All these amazing innovation that we're seeing in the world today needs to be secured, right? CIOs are panicking because -- their CEO is saying, we're AI, 89% of companies that George talked about are touching AI, right? They need to be protected. And guess what?
We have Guardian. All right. Let's do a quick recap of what was talked about today. There's a lot of opportunities that we talked about AI adoption is storing. We talked about the stat. You guys see it. We see it every day. We see it every day in the news. The tier, it's now it's happening at AI speed -- it's just incredible what we're seeing with respect to AI and adoption of AI.
George talked about building cybersecurities. First, model, purpose built for defenders. I mean he was on stage with Jensen and the 2 of them were going back and forth about what this could mean. I mean Jensen's excited about it, let alone George. I think everybody in that audience who was there was kind of going, wow, that is something unique.
That is actually kind of the DNA of CrowdStrike. Being such a ahead of the curve type of company, innovative, thoughtful knowing where the puck is going, if you're a hockey fan, I mean that was incredible what I saw, right? Securing agents, George and Mike to talk about securing agents.
We talked about -- George talked about, hey, for every person there's potentially 90 agents. Then George talked about, well, could be more. could be 1,000, 10,000, whatever number is. And I agree. I spoke to one investor after our Q2 earnings call, and we went through that and we said, hey, 1 human to 90 agents. And there was a pause. I as a very big investor. There was a pause. And he goes, "Can't be 1,000 or more?" And we're like, yes, potentially could. So his mind was thinking kind of like what your mind is thinking right now. This is a massive opportunity for us.
Today, we now have 34 modules. We have a Cyber Frontier model. We have the technology that's required in today's world. And we're showcasing it here at Falcon in front of 10,000 of our partners and customers. And if you were in that auditorium when we were going through all this stuff, you saw the energy, you saw the excitement. What I saw, I saw people going on their phones and texting their folks, we need this, we need this, we need this. That's what I saw. And we talked about the endpoint is the control plane. Look, AI is consumed at the endpoint. We've shown you over the past several quarters that our endpoint business is growing, accelerating Why? Because of what I just said, AI is consumed at the endpoint right? So there's no way in the world today who does [indiscernible] better than us. And now again, something has come to us that requires the end point to be able to digest all this activity that's taking place in this new AI world.
And then Mike just walked us through this incredible TAM, right? You walked us through on a market -- by product, how we think about getting to the numbers that we talked about, the $20 billion and the market in front of us, the [ $563 billion ]. That's a big number, right? And we have the tools, we have the technology, we have the people, we have the AI to get there. The time expansion is going to come from inorganic and of course, organic as well. So we have both of those avenues go after that big TAM. And I think we're in the pull George likes racing in we all like racing in CrowdStrike, full position. We're in a full position to go get that TAM. Sorry, guys.
So when you put this all together, all the things that I just talked about gives me conviction in our ability to scale this company to new heights. I mean each one of those things to me, screens this conviction towards our goals. And I'll share some more of those goals with you a little later.
All right. Probably worth a minute just to take a look at the Q2 highlights. It's the $333 million in net new ARR, 51% year-over-year, an all-time record for us. Non-GAAP operating income of $372 million, an all-time record for us. So you've got top line growth and all time record. You've got profitability at an all-time record. For me, this was the greatest quarter in CrowdStrike's history. And for me to see it all come together was just super exciting. And we paused when we read all of your notes. You wrote brief thoughtful notes about the quarter and not just about the quarter but the outlook so I read them all. We all read them all. And we want to just thank you guys for hitting on point because you did capture that. And that was, I think, well received by all your readers.
Let's talk a little bit about Fal.Con Flex. I said it at zillion times, but it's worth repeating. It's a commitment model, not a consumption model. George talked a little bit about it. We worked diligently with our auditors and everybody else and how we're -- and obviously, our customers to be able to get what they wanted, right? I'd love to be able to take credit for Flex, but it's the customers. The customers deserve the credit. Those are the folks that told us what they wanted. They wanted to digest all of the things that we had, make it simple for us, make it easy for us. And then we put our thinking caps on George [indiscernible], that we got to make this thing friction-free. We got to make sure that this thing can be super well absorbed super fast and super simple to be able to get through the end of the contract. And you've heard many times about why it's successful -- you've heard many times about you can track once and then it's another PO just on the reflexes.
And I've talked to each of you after our earnings call, talk about the fact that, hey, look, if this is being consumed faster and you've seen the data then how fast it's being reflexed all you need to do with the reflex is get to the CFO and say, "Hey, I just need a little more for CrowdStrike." And by the way, I'm going to give back a bunch of though that I'm spending on somebody else. So any CFO [indiscernible] their waiting gold is going to take that deal every single day, right.
The other thing I'd like to talk about is that Flex has the same -- as the same kind of retention that non-flex does. So ARR and revenue are recognized ratably -- there's no change. There's no mixed models. There's no confusion over how we're doing this thing. It's very simple. There's no change, right? And that's part of the beauty of the elegance of this model. It does a lot of other really good things for us. It allows us to contract faster. They can get a bigger -- we get bigger deals, we get longer deals, able to kind of reflect really quickly because they've taken the friction out of the sales process. So there's a lot of goodness in Flex.
And as George has talked about many times, it's not just here's the license and everybody can use it. They're stealing the name, but you actually need to have the right -- you have to have the right technology. You have to have the best technology out there. You have to have many modules where you can reflex to. You also need to be able to click on those modules straight away. You need all those things to be able to have proper Flex and see the results that we're putting up on the board.
George has shown you these numbers just before you've seen them all, but I'd like to go to the one all the way on the right, the average ending ARR uplift from a non-flex deal to a flex deal. We talked about the 40% but last year to 34%. That's a big jump, 34% to 40%. And so when we go to the sales team, you have folks that they're kind of like they like the old ways or they're used to selling new ways. Would you put that stat in front of them they go, yes, yes, I'm going to get them on Flex. Hey, these folks are quite operated, right? So it works really well for the customer. It really works well for us. It works well for our sales team. It all kind of comes together.
Let's talk a little bit about what we're seeing with the power of Flex first go-to-market. You can see here the Flex logos as of 2Q '26. We had 61% enterprise and 39% nonenterprise. Now it's 50-50 so why is that happening, right? So Flex First. Our sales team is going out there and selling Flex First because they know that if they go to a non-Flex deal, they got to get Mike to go approve it. And that's additional friction from a sales perspective the sales rep doesn't want to go to Mike for an exception, right? So we are really leaning forward on Flex First. There's friction if you don't go there. And we've already seen all the benefits why you need to go there. So I envision a period of time at some point in the future where there is no such thing as a non-Flex deal for CrowdStrike.
George covered the tectonic shifts, what we're seeing in cybersecurity in the world, right? I've talked to -- I think it was Michael, we were talking about the fact that this is a generational shift that we're seeing in technology. You can call whatever you want, generational, there's an inflection point, for me, it's transformational, right? What we're seeing in the world today. And Mike talked about our path to $20 billion in ARR from a market share perspective. I'm going to now talk about the $20 billion from a customer and geographic perspective. And for me, I like looking at things on there are different planes, right? You can do market share. I like customers, I like geos. I want to see how -- I want to see it all. And that's how we build our internal models.
Mike talked about the 3.5%. You saw all the numbers, you can all do the math. Given the track record that we've had of capturing roughly 4% over the last 6 years of market share, we feel that we can we can be able to reach the 3.5% and then some. You go to execute, you got to do all those things, but it's there for us for the taking. [ 30% ] isn't a huge, huge number against the 565, 3.5%, 565 for me, I think we can achieve that. We just got to execute. We got to do all the things we've been doing in the past to be able to get there, but really achievable from -- as I think it from a TAM perspective.
Look, if you want to look at our customers and you look at new logos, today, we've talked about the fact that we've got 100,000 organizations as of Q1. And that includes SMB, it includes MSSP, it includes everything. And then you look at these numbers. And if you start from the group that has a small global [indiscernible] of 13,000 plus in that category, all the way up to $50 million in the SMB space, 100,000 organizations is a drop in the ocean in terms of logo runway to get to our TAM. And I've talked to all of you over the years about how we have so much headroom in both new logos and our base, and I'll talk about our base in a minute. But you can see the stats here. We have just begun really. We went public in 2019, it's only sorry, 2026, right? We're in the early innings of our journey in terms of going after customers. So we feel we have a tremendous amount of headroom to go with respect to going after new logo.
The geographic opportunity. Look where we were in FY '22. 72% in the U.S. and the rest of the world was 28%. 5 years later, 65% in the U.S. and 35% rest of world. I'm excited about our international opportunity. You can see CY '34 international market community of $244 billion. It's great. I have a goal in my mind. I think I've talked about it with all of you in the past, I'd like to be 50-50. It's hard to get to 50-50 when the U.S. is doing so well. But the international has done well, too. We're spending more money in S&M in the international markets. We're spending money on sovereign cloud to go after the international markets. Again, I think we're in the pole position to capture a whole bunch of that $244 billion by CY 34.
The expansion opportunity. So as I talked about we have a lot of headroom in new logos, tons ahead. We also have a tremendous opportunity in the -- with our current base. We were at $5.8 billion in 2Q of '27 ending ARR. This is existing modules within the existing customer base in terms of the white space. We showed you the white space opportunity 2Q '26 of $21 billion. We're going to add another $8 billion based on our customer base today. Total white space opportunity for 2Q '27 $29 billion. That's pretty good. So I have this tremendous opportunity in headroom in new logos. I have this tremendous opportunity to sell more to my existing customers who love us already. We want to do more with us, who want to swap out other technologies. They want to have the best outcomes and we help them lower their TCO. This is why we've been winning.
I love this slide. So my good friend, DB came to the company 4 years ago, and I'll be honest with you, transformed our whole partner kind of go-to market, right? We kind of look like everybody else before it was there. We weren't investing in it enough. And DB came along and really transformed for what I saw the partner community, all of our partners, whether it's GSIs, whether it's the partners we had on stage, you can see the numbers. We had 8 partners, each with a lifetime TCV of $1 billion. That's impressive. 19 each with lifetime TCV at $500 million and 65 each with lifetime TCV of $100 million. 65 each with a lifetime TCV value of $100 million.
I remember, George, when we hit $100 million TCV as a company. And here, I've got 65 partners each with $100 million plus, incredible. 890 of our partners doubled their business with CrowdStrike year-over-year, 890. So part of our success is nourishing and growing with our partner community. And what I've seen in the last 4 years has shown me that if you can do it right, you can hit the numbers that we've been hitting. As you saw, we -- earlier for Mike, we pulled in some of the dates, some were hitting the $10 billion and the $20 billion. For the $10 billion, we said we were going to do it at the end of FY '31. Now we're doing it within FY '30, similar theme for $20 billion. We said we were going to be able to hit that by the end of FY '36. Now we're going to do it within FY '35. And why are we saying that -- we're seeing significant momentum in the business.
The business is firing and there's a huge opportunity. We've got both of those dynamics happening. And for us, when you see that momentum, I can tell you right now that my friend, George he's not laying that momentum slide away. Put on the accelerator, right, George?
Okay. Let's talk about the target model. So here's a summary of the target model in full year FY '29. So the ones in green, S&M, R&D G&A, we're already in the band. Subscription gross margin, 81% to our target model of 82%, that's 85%. So we're right on the cusp. Operating margin, we've seen incredible increases in that. We're now at 24%. This is all of 1/2 of '27 to our target model of [ 20% ] to 32%. And I've talked about free cash flow for the first half. And we talked about ending the year at 30% plus to our target model of 34% to 38%. I think we're in year sort of all these things. I feel that this is the same 3 years ago when we said it, same now, not changing it. I'm not extending it out, keeping it as it is. And there's still room for efficiencies across a lot of this stuff, right? AI is helping me with that.
So for me, you got a lot of things that are making this model work from all of the products that Mike has talked about, to Flex that we've come into the partnerships. I feel really good about this model. I'll go into a little more detail, especially about gross margin expansion. So many of you have met me for the first time back in 2015 when I started. And when I started, gross margin was in the 30s. And I looked at George and I said we got to do some different things to be able to go public and he goes, "Yes, I know, let's figure it out." So we did. We figured out what we need to do -- what we needed to do with respect to increasing our product portfolio, moving to our own private cloud, all those things needed to come together in a way that we're going to increase our gross margin and still be able to get the liver the products that are best in breed and then a platform that's best-in-class in the world. And we did.
And we went from the 30s [indiscernible]. This is a story that is most near and dear to my heart, right? George and Mike have their products, they love all that stuff. I love gross margin. I worked hard with the teams on gross margin. We figured out ways to be able to deliver the best-in-class products to the world and still be able to deliver a great gross margin, which then I take and reinvest into our business. Last year, we put $1 billion in R&D, $1 billion. So gross margin expansion matters. So how are we doing it? So we've got our public cloud partners and customers and we did a couple of things with them. One is we looked at where it was more economical to put the compute and the storage. For example, Amazon, we went more to the West 2, there's West 1. We also have scale. So we're able to have volume discounts with our public cloud providers. So that's going to help us more in the future as well. As we get bigger and everyone else, we're able to enjoy better discounts.
On the private side, we're able to look and say, "Hey, look, where are the more expensive areas that we can bring into our private cloud and let's do some more migrations." So we continue to look for areas to continue to migrate for those more expensive areas. We also are using AI to find multiple data stores and reduce that, reduce our costs. So I feel really good about where we're going with gross margin.
Obviously, a point at 81% going from 81% to 82% is a lot harder than going from [ 30, 31 ]. But I feel really good about it. And for over 10 years that I've been at the company, we've never taken our eye off of gross margin, ever.
All right. Let's talk a little bit about free cash flow margin expansion and some CapEx. So as you all know, we talked about FY '27 having a 30%-plus free cash margin. So now I'm talking about FY '28. And I'm looking at a 32.5% plus free cash flow margin. I feel really good about that. I also look at my CapEx. So we have a slight increase in CapEx going to 11% to 12% next year. And even with that, I still feel really good about the free cash flow margin. So they go hand and hand, you got to talk about both right? And obviously, the prices have storage and everything else have gone up. We're aware of it. We've done a great job in terms of procuring and great job with our vendors and our strategic vendors to lock in certain pricing. So I feel really good about at the end of the day, the 32.5% plus free cash flow margin.
Look, we got a lot of growth opportunities. Mike touched on them earlier, George touched them on earlier. I believe these -- capturing a percentage of the TAM that I talked about is very achievable. It's a large, it's an expanding TAM. Large and expanding. Those are really good words. And I think we're right in the epicenter being able to get it done.
Conviction in FY '27 net new ARR acceleration. Let me walk you through kind of some of the history. When I was here last year at this time, I said that for this year, we're going to do 20% in terms of growth on net new ARR. I think you were all here for that. Then at the 3Q '26 earnings call, I said I'm going to do 20% but on a bigger number. You all remember that. Then after 4Q, I said I'm going to take that 20% then raised it to 22.5%. I felt pretty good about that. And then we had a big jump in 1Q, right? 520 basis points. I was really happy about that. And I said I thought it was a prudent guide when I did it. We're looking at all the factors. It's not to execute incident, but we did. And then, of course, last quarter, 34%.
Overall, total raise to date, $220 million FY '27. I'm really proud of that. And a lot of things needed to happen for that to work. And now as I think about the future and all the things we talked about here today here's what we think about, I think about this. I think about 20% plus year-over-year net new ARR growth for next year. That's what I think about. We told you that at the midpoint, we're going to be at [ 1.355 ] in -- at the end of this year and the next year, [ $1626 million ] [indiscernible] great at that.
So that I think that summarizes our conviction in where we think this business could go. Pretty exciting times for us and I'm willing to go out again at Falcon, which is well before end of Q4 to talk about next year. So with that, I hope that this has been enlightening for everybody. I hope that it's been transparent with everybody. I hope that it's been consistent with what you've seen in the past. So with that, we're just going to get ready for setup for Q&A. So stay tuned. You can take a bio-break or whatever and come back in about 5 minutes and then we start Q&A. Does that make sense? Work for everybody. Awesome. Thanks, everybody. Thanks for your time.
[Break]
Please welcome Vice President, Investor Relations and Strategic Finance; Andy Nowinski. Joined by Chief Executive Officer and Founder; George Kurtz; President, Michael Sentonas; Financial Officer, Burt Podbere; and Chief Business Officer; Daniel Bernard of CrowdStrike.
All right. Thanks, everyone. This is my favorite part of the day. So we have 45 minutes for the Q&A. If you could please raise your hand, I'll get you in and then wait for the microphone because we have a lot of viewers on the webcast that also want to hear your question. And then if you could please state your name and your firm for the webcast viewers. That also be helpful. So why don't we get started? Let's go first here with Brian.
2. Question Answer
Good afternoon. Brian Essex from JPMorgan. Thanks for doing this again this year. I'll say you have to be here to appreciate the scale. I don't think I have to sit in the top tier of arena to watch a keynote before for a security software company. That's pretty impressive.
But George, I'd love to -- the question on why Anthropic Cloud why you can't cloud code, you waited CrowdStrike strike. I think it was great to hear Anthropic so operationally, I think we've all been reiterating why you can't do that. But I would love to from a technical perspective, if you could just put a bow on that, and describe for maybe generalists that are listening, if you take a model and add a harness to get an agent, how you're engineering of your own proprietary agent protects your IP, your data, your processes, your context from access by some of the foundation models and limits their ability to maybe to distill what you're doing on your platform?
Well, a lot of it starts again with the data itself, but the data is really captured because of the architecture. I mean if you think about the scale that we operate in, we have a single agent that operates in multiple operating systems, if you will. Then you have to collect this data in mass, which is really hard to do in a performant way. Then you have to have a cloud at scale that understands how to process all this, then you have to make sense with all the algorithms and then you have to have deep security domain knowledge to be able to understand what's good, what's bad and you have to be in line. This is really important. There's no LLM that's in line, didn't stop anything. Will give you a text explanation of something. It doesn't stop anything. And in security, you have to be right the first time, first and final as we talk about when you make a conviction on something.
So it's a much different model, if you will, I mean, operating model than just say, I have an LLM and a harness, right? That's not going to do it. Now we talked about how to leverage models, which we're building. We talked about the frontier models, which we're partnering with. Again, it's about customer choice, but as a net data creator, the 7 trillion events, this is what our system was trained on. There is no edit for what we actually created you're starting to see the Frontier labs, they're buying old books so they can scan all the out of print books because they need more data. The fact that we create data, have it and we have an architectural system gives us a unique advantage. Two is we're totally focused on security. This is a big deal. We have a company and a sales team and a customer success team that's focused on making sure that companies don't get breached. That's our mission. We're not doing other things. This focus is very important.
And then when you put it all together, we have distribution. Like I think sometimes people forget in 2026, what it means to have distribution. I think all of a sudden, now you whip out Claude and you're going to dominate the world. Like, yes, it's technology, but all the fundamental things that we all learn in business school you still actually need. So that's the reason why we're partnering with Anthropic with OpenAI and obvious you've seen the ecosystem because customers want a trusted security partner. They want their data to remain with the trusted security partner, but they still want to have access to all these different models, ours and others in a way that gives them sovereignty and the results at the right cost.
Thanks for the question, Brian. Please be patient. We have plenty of time. We've got 40 minutes here. So next question we'll take from Saket.
Saket Kalia at Barclays. Thanks for a great couple of days here. I want to -- George, I want to ask a little bit of a product of so many great announcements. The one that I thought was super interesting was Guardian, right? And that too would ever watch. as I compare to cloud security, it felt like cloud security in the past, lagged cloud spending, right, more than we expected. That market also had some big players, right, like Wizz, for example, and so maybe the question is because you had a great comparison, right, of hyperscalers to kind of the frontier models. Maybe the question is, do you think Agentic security will lag as much as cloud security did? And is there another Wizz out there in this space that's on your radar?
Well, I think if you go back to the graph that I created, which basically had sort of the cloud adoption and the security adoption, right? I mean it was a longer time horizon. I think right now, as I said, you can't roll out AI without security. And when every customer is literally begging you for a product like Guardian, I don't think that's going to take long. So it's just a different point in time. It's a different type of technology.
And what you have to realize is from a cloud perspective, when cloud first came out, we were 1 of the early adopters, if you remember when I started the company, not everyone needed cloud. You could wait a few years. Like if you go to the Board and you say, hey, we're going to wait the next 3 or 4 years until technology shifts a little bit more and we kind of get around to it to implement AI, you're not going to be in the seat long, right? It's not going to happen. So the fact that it's a mandate, the fact that the benefits are incredible from a cost perspective, it isn't like companies are going to wait to migrate to AI. They're there. They have to be there. So that's number one. That's going to force it.
And I think when you look at where we are today and sort of other companies, I think we're in pole position, like we already have the agent. We delivered prompt visibility, what we're able to build and the unique capabilities to fuse prompt visibility with sort of the run time heritage that we have is incredible. I mean I got off the keynote and was like when can we get this thing. Even though I said it was available, like where, when. I got to have it, my phone blew up, your phone blew up. So I haven't been really involved in something like that. Really, since when I -- when we first launched EDR, like when people saw EDR, they're like, okay, nobody has that. We want that. And it's the same thing now.
So I think we're in a great position to be the dominant player in that space because the flywheel that we've built, the heritage around endpoint. And again, I want to be clear, I mean, we've been talking sort of end point, we have many, many customers with work workload, and this works in a workload. So if you're running Claude in a workload or open a codex in a workload in a container, we run there and do the same thing. It's very important.
Thanks, Saket. We're going to take a few from this side of the room now. Let's go to Gabriela.
Gabriela Borges from Goldman Sachs. My favorite product announcement was actually a safe mind. So maybe for George and Mike, talk a little bit about how customers have been saying for years, the odds are against us as defenders. What do you think the paradigm shift is going to look like to go from all of the vulnerability management issues, the pen testing, the patching -- the patching Tuesdays becoming continuous versus just adopting something like Safe Mind and Burt for you, like how do you model something like because there are all of these pieces between front-end model distribution and token consumption and there seems to be a lot of moving pieces to it. So I would love your thoughts collectively.
Well, when you look at [ Safe Mind ], what we've found from customers is they want something that allows them to operate at the same frontier caliber. And they want specific to security use cases, right? We're not solving the world's problems. We're solving the world securities problem. That's a big difference. So we have the data. We've got the technology. I mean you saw Barley, he came from NVIDIA, and this is what he was doing there. So we are in a unique position, again, to build not only a lab for security, but to actually deliver on these frontier caliber models. And tomorrow, you'll even hear more stats on what we were able to do. So we're excited about that piece.
I think data sovereignty, what I mean by that is not just by geography, the fact that the data is being kept within CrowdStrike is a huge opportunity for our customers because they can use our models or they can use a frontier model, they can use all of it. It doesn't matter, we can do the model routing, right? So that is a massive opportunity. But I think maybe to sort of the heart of your point around vulnerabilities and exposures and things of that nature, in a post ethos world, it's all about exploitability. And there isn't enough time to get the patches out. There just isn't. You think about your organizations.
If you're a cloud organization and you want to like put something out in a template grade, but not everybody operates that way. So we have to be able to -- like in this first incarnation, this is one example is not -- I mean the thing is unlimited to what it can do but customers love the fact that we can create a digital twin of their environment and then very rapidly understand where those exposures are and then rapidly allow the system to create the mitigations. And that's going to drive a lot of adoption can't do that on their own, and it's sometimes too risky to try to figure it all out. So it's a great first use case. I don't know anything else you want to add to that?
Just that it's an iterative cycle that you can run every day, all day. every weekend, every night, I just keep getting better as you go.
The bad guys are getting better, right, with reinforced and learning. So we might as well do this. So this is one of the most exciting projects I've been involved in. I can tell you, I had standing calls 3 times a week at 9:00. I was in there in the UI, change this, do that. Here's what we're building. I mean this was like we really galvanized the whole company, would you say around this. And we handticked the best engineers in a relatively small team to be able to put this together and deliver something that I think is just going to be extraordinary.
Yes. On the modeling, it's no different than anything else that we do with new products, right? So I look to George and Mike and all the customers that they talk to get the inputs, get kind of a flow about what we can do. And then really baking on assumptions on the top line to figure out where it could go. And then you bake in some of the assumptions on the cost side, right? Similar to the 40-page deck I did the gross margin when we took it from [ 30 to 80 ] so it's no different. There's no change in terms of the methodology.
I will say when we think about costs, just kind of jog my mind, if you remember the demo that Mike did, we actually include the ability to understand the token usage and provide visibility to cost. This is huge. There isn't an IT organization that is asking for this. They have no idea what's going on. In fact, we had one customer that basically came back and said, by EA, was spending $10,000 a month on tokens. And he's like, "I don't like how did that happen?"
So I'll tell you the story. She was very diligent and she was taking all these e-mails and she was putting them all together and what's going to happen for the week, putting it into Claude, but Claude didn't really understand how to read the EML format. So it built a parser every time she put a new e-mail in. It literally built a parter. So all these new e-mails get dumped in and the token usage goes nuts. So not only do we have the ability to actually provide protection, but we're selling now into the financial -- I mean, the IT world that is concerned about costs, right? The CFO isn't necessarily our customer. But when you think about cost and AI, it's going to be a huge benefit to be able to provide that visibility to the entire organization. I mean you want this.
100%, right? Okay.
All right. Thanks, Gabriela. Great question. Next one, let's go to [indiscernible].
Maybe just a question on -- you noted greater efficacy than the frontier models that you guys have from the Red Tempest and [ Blue Solano ] and the lower cost. And so A couple of questions there. Just one, what were instances where they did find vulnerabilities that maybe your models didn't find originally? Then second, just where do you envision -- I understand that customers want choice, but where do you envision that they will use choice kind of in open mind?
Yes. I mean you have to look at like it depends on the model, depends on the scenario. And at any point, [indiscernible] could be better. I mean, obviously, these evolve new models are coming out, right? But I think when you look at how the models work, you have to include the harness as a needed element, right? And I do think this gets overlooked. So you can have a couple of models, and they can be good, but when you actually apply the harness to it, they get really good and you get to reduce the false positive. So to be fair, as we went through this, and we've trained our system, it kept getting better and better and better until we got to a point of better performance in the areas that we were focused on, which are generally what people care about.
The other thing to realize, too, when you think about cost, this concept of a turn in a model. So if it took you 20 turns in a model versus 16 in our model, just as an example, might take less. If it took 16 in the frontier model, it's so cheap to the extra 4 turns, and it doesn't matter in terms of cost. If it took you 4 extra times, you get there.
So from that standpoint, you can get essentially the same or better results at a cheaper cost. And it's just kind of the engineering that goes into it, but a lot of it comes down to the training and the harness and then obviously, the post training around how you keep getting better and better, which is going to give you the great results. We only have one thing to focus on is security, right? So we're not worried about all the other things in the model, and that's really what allowed us to get these sort of results.
Look, it's going to go up and down over time. New models are going to come out. And I think maybe the last part of your question is we can provide the routing so the customer can pick what do they want to use a frontier model, great like they want ours, they want the best answer. They want a composite view like use all of it, right? But the whole idea is that we want to get paid through the whole token flow process.
Okay. Thanks for the question. Let's keep going down the line here. John?
John DiFucci from Guggenheim Securities. Listen, there's a lot here, and I appreciate it because it was almost like -- I don't know, it was like an AI 101 or actually AI 401. But what you're doing looks really different from what we're seeing from a lot of others. And I'm not quite sure because admittedly, the others are really vague, which makes me think don't have much or they're just further behind probably. And -- but we can think about and you showed those graphs up there about the potential for growth. And you gave some numbers, but the potential looks pretty impressive. But one of the things I was thinking about when you were up there and I guess this question is for Burt.
I know you gave the cost per task, which is a lot lower than the LLMs but we don't even know what the profit is on the LLMs because they're private companies. I mean, maybe some people in this room do, but I don't. How should we think about margins? Like if this really takes off, and I know you gave some [ $28 ] of free cash flow, that's great. But how should we be thinking about that? Is this going to weigh a little bit on margins. You've done a great job. You did I remember talking to you guys when you were private when it was 30%. I said don't tell anybody that until you get it above 60. But how should we think about that right now? Or -- because it seems like they could weigh on margins a little bit this business?
Yes. So it comes down to what George talked about, tokens, right? At the end of the day, we're going to price tokens appropriately to be able to have the cost bake into those tokens so that can make sense for everybody, right? So it goes back to the regional theme about margin. We talked about it on stage and I talked about it with Gabriela's question. There's going to be no change in how we think about putting that model together. But it's going to come through with tokens.
Yes. And what I would say is, again, as you build these because they're so specific to security, there's less things that we need to do in all the other areas, right? When you're a frontier model, I mean you got to account for anything that they could possibly do. So our scope is more focused on security, which again, if you're just in that area and you're training in that area and you're doing alignment in that area, yes, it takes money but it's focused in area.
And again, I think the great thing that we talked about was partnering with NVIDIA to be able to leverage some of their technologies to do that. So I think we put together a very cost-effective way, which gives us frontier caliber capabilities. with unique data sets and partners that are helping us and working with us to get the best performance at the lowest cost.
Thanks, John. Start over on the side to Fatima.
Fatima Boolani from Citi. George, I wanted to ask you a question with respect to a slide that you shared. It was a triangle slide with cloud and endpoint AIDR, the network. My question for you is how much of the traditional conventional alphabet soup that is cybersecurity for the average buyer? How much of that is an opportunity for you? And how much of that is a limitation or a challenge to you in articulating your vision? And what I'm getting at is eventually does the distinction even matter because your core principles are grounded in the one sensor approach? I mean, how is that resonating? And is that something that buyers are saying that I'm ready to just sensorize everything to help solve for these multitudinous use cases in cyber. So just kind of your thoughts on these fault dichotomies and alphabet soup and if that's a hindrance?
Well, there's an alphabet soup obviously in the market. And you heard me say this probably in the past, I've never seen a PowerPoint that was wrong, right? It all looks good, right? It all has great -- same message, different colors, but the proof is in the pudding. I mean when you come to an event like this in a stadium that you've never seen before with so many customers, right, with pinners that you've never seen, Jensen shows up to, you know you've got something special. And I think what customers have recognized is that the point -- I mean, you have the AI creation, we're going to build models and those sort of things got it, right? That happens in the data center. We're working with all of those partners.
But for the companies that are actually consuming AI, it's what you're doing right now because probably each one of you have some level of AI on your desktop. If not there's long running agents in the cloud. That's where it's going or it's a SaaS agent from any other the platform players, right? But if you take 2 of the 3 of them, we're world-class experts in that. We have more agents deployed than any private security -- not private, any stand-alone security company. So that really is a unique benefit and that sort of flywheel, the crowd and the CrowdStrike and the platform piece that we've been talking about. No one wants yet another agent. No one yet wants like all these other vendors, right?
And when customers stop their buying and they basically say, what is CrowdStrike doing? Are you solving this problem? Because if you're solving this problem, we're going to buy it from you using Falcon Flex and using the single agent. And that's a huge differentiation between us and just about all the other companies that are out there.
Thanks, Fatima. Let's go next to Gregg.
Gregg Moskowitz from Mizuho. I also have a question on Safe Mind and just have to say running countless iterations of Red Tempest and [ Blue Solano ] in a closed loop. It just really shows incredible ingenuity. But as it relates to the token aspect of the equation, naturally Safe mind is going to be part of Flex. But do customers need to procure initial token packs? Or will they be included with Guardian or some other module to whet their appetite.
And secondly, how are you guys planning to approach pricing of Guardian because to my mind, the functionality is surely even more powerful than your AIDR module. And as we've seen demand for AIDR out of the gate has been pretty remarkable.
Yes. So I'll try to make sure I cover a few of those. I'll let Mike jump in, if I forgot anything. So pricing, pricing will go up on Guardian. I mean the capability is unbelievable. So compared to what we would call AIDR, right, that's going to be retired the category, the AIDR and the product will be Guardian and price goes up.
From a token perspective, companies. Well, I'll start with you really won't be able to consume you -- from a Safe Mind perspective, you won't be able to consume Safe Mind unless you're a Falcon Flex customer. Let me just say that piece. So put that aside. But for the purposes of what we're talking about here, you can buy the tokens and we'll look at the estate that you have. And then generally, what we try to do and this work out well with customers is we'll basically come up with a number of tokens for your entire estate. And then if Burt doesn't use a lot, but I use a lot, it sort of all equals out, but we give some level of visibility to customers. So it isn't sort of up and down. And Burt didn't use any. I crushed it. I've got to pay more money. We basically look at the pool of tokens.
And then if they exceed that pool for that month, then they can certainly buy more from the Falcon Flex packs. So that's -- customers really like that. So it's predictable, but there is obviously a step function if they're using more.
And we want customers to be able to have access to Red Tempest. We want customers to have access to Blue Solano, the harness all 3. Think of all the areas where we can use this in the platform, having Safe Mind working together with Guardian. Think of the power of Safe Mind with exposure management. Think of Safe Mind working with next-gen C. So there's going to be many different ways that people can access the technology. Some will include with token, some of you buy outright. As George said, Falcon Flex is the easiest way to get this. Something that I said earlier, we got you. Everyone that was war texting us, flex it in, go for it, you're done. So that needs to be easy as well, which I think is important. We want predictability. Finance teams want predictability when they think about the usage of that.
Thanks, Gregg. Let's go to the next question over here. Let's go to Patrick.
Patrick Colville from Scotiabank. I'm actually going to stick to Safe Mind. I think one of the reasons why is we've just seen the power of proprietary harnesses. I mean, tonight, snowflake just printed this most extraordinary result. And part of the reason is because they have a proprietary harness. And here today, I'm like this is potentially to be explosive for CrowdStrike, this is really exciting. When I speak to CISOs, some are already using these models in cybersec and what they've been telling me is that it's really expensive in terms of the commits the OpenAI Anthropic demanding. And I can see how this will be really compelling to kind of lower that cost.
But my question is, is this is like what proprietary it's cross-track adding. You touched on this in your presentation, George. But is it the to Intel? Is it the kind of red teaming for years? Like what value add are you guys providing to make that harness so robust? And then but just to be clear, Safe Mine is included in the gross margin, free cash flow margin and ARR guide you put out today?
So if you think about it's a system, right, you've got the harness in the models. And I think you really bring up an important point because the models are going to get to a point where there's just diminishing returns as they keep getting better and better, right? They'll keep getting better and better for sure. But when you think about what makes the difference, a lot of it is going to be this exoskeletal in the harness. And there is a lot of know-how that goes into our software as an example, right, that people haven't replicated and there's a lot of know-how that actually goes into something like the harness, which essentially is software.
So we've taken all years of experience and seeing [indiscernible], understand how they work, understand how to protect against those. And then we've built a harness to be able to get the best outcome with the lowest false positives. And there's also a level of cost engineering that goes into it. Like you can do a lot of dumb things and potentially get the right answer, but it might be really expensive. And it's just like cloud, like when you think about how we've optimized our cloud to get 81% gross margin. Like you can't just go, I have a cloud and I have an agent and have at it. Things have to be optimized.
So those become barriers to entry, right? The 15 years of that we've used to train the models. The experience that we have in Falcon Complete, in our services team, we understand how these attacks work. We understand how to recover from them. and it's all that intellectual property that goes into building proprietary software, AKA, a harness, so different than the software that we built for the last 15 years.
And I think you will see that across different industries. You pointed to one here in your example, where the harness is going to make the difference because the models are all -- like they're all going to be really close. If you look at the open weight models now, they are very close to the frontier models. Close enough to get good results, right? So the software layer that goes on top of it, I think, is really going to be the X factor that gets you the best results for the lowest cost and that harness engineering is important. We saw this early on, like we couldn't have delivered a harness now like we didn't start it yesterday. We started a long ago because we saw what was happening in preparation for this point in time.
So we've seen examples where you can grab a model and a harness and get 80% false positives. So if you're doing red teaming and you're looking for issues inside your environment, you got 80% false positive, you're burning tokens and you're getting nothing. And then you have to keep tuning and tuning and tuning and you're burning takes the whole time. By the time you get to a point where you're getting an effective outcome, you've got no money left.
So to your question about what's different about us, we provide the models we provide the harness, we provide the training, we provide the threat intelligence. The goal is that the customer uses it, and they get the result when they first run. And that's hugely different.
One thing to add to Mike's comment, I think there's a long history of security buyers and security practitioners wanting security products. And I think this speaks to that very trend. You guys have tracked us for a long time. A lot of generic technology companies have played in cyber. There's a reason that there's a crowd strike.
Yes. So to answer your second part of the question, so it hasn't been released yet, right? So I haven't baked it in this year. It's contemplated for next year. But just remember, it's early days with this thing.
Thanks for the question, Patrick. Ittai?
Ittai Kidron from Oppenheimer. Thanks for the day, super informative and Burt great guiding [ 28th ] net new ARR for 34% another 34% year-over-year growth. I appreciate that.
You said that. I didn't say it.
George, I want to go back to your early presentation, you made the comparison of the cloud adoption and AI adoption. But one comment that you said immediately following that well that you don't expect a spike in security spend as it relates to this. You expected -- I think it was a consistently strong growth, maybe I'm paraphrising there, but you certainly try to remove the possibility of the spike. And my question is why? If AI spend is growing vertically up and enterprises need to operationalize it here and now and they can do it without security, why shouldn't the growth of your business not decelerate into fiscal '35 target, but rather accelerate, not for quarter 2, but accelerate for 2, 3, 4 years, heading into this, especially given what we're seeing from the frontier models.
Well, I want to be specific, what I said, which was a spike is just buying more of the same, right? Sustained momentum and tailwinds are buying something different to solve a different problem, right? So when you look at the growth, I mean the growth would be explosive for sure. Well, what I was saying is the methos moment isn't like a 1-quarter trend, right, to be very specific to answer your question.
And when you see the curve and sort of how that curve going up, these are sustained tailwinds because you're not just buying more of the same, you're buying something to solve a different problem. The problem that we see today and the problem in the future. And that is a massive opportunity, right? And that's what I was really saying. It isn't a 1 corner phenomenon of like, hey, you've seen a spike because methos moment. this is going to be a long-term trend. Getting back to my point, if you think there's going to be more AI in a year, 3 years or 5 years from now, security is going to parallel the slope of that curve, for sure.
Thanks, Ittai. Let's take our next question. We're on this side. Let's go to Michael.
It's Michael Turrin with Wells Fargo Securities. Appreciate all the content over the past couple of days. And I just wanted to spend some time getting your perspective on the tone of customer conversations you're having at the event. I'm sure you've been busy. Curious specifically on the sense of urgency around AI this year versus last year. And we're talking about some of the same things, but you didn't have the fully featured product vision behind it. We didn't have to methos moment in some of the things that are out there today. So curious to pick your brain on that.
And then George, with enterprise AI spend, you mentioned it's net new, are you finding that true for cybersecurity currently? Or if not, where does that come from?
I'll let you take the first part.
Yes. Look, I think as George said, we got hammered with questions as soon as George presented. It was Safe Mind. It was Guardian. Obviously, today, people are asking about our identity provider because they're trying to wrap their head around like this is going to solve the problem in security that we've had for a long time. Last night I was walking back to my home and I walk pass the lobby of the hotel, and there was a group of customers and they called me over. And they were just saying you guys are operating at a different level, like we're just not hearing this from other people. And it was when can we get it? Is it part of Flex, where does it go in the products, what comes next. And ultimately, everybody said, we have comfort. We came here worried about what we're doing with the AI because we have to go back to our business and tell them how we're securing it. You've given us the answer.
And I've run into the sales reps and people are like, can you come and see this customer, can you come to that event I've had about 12 EBC requests in the last 6 hours. Everyone's had the same sort of thing. So it's definitely hitting the challenges that people are having and we're giving them the answer I think is critically important. I think George said it well, we've got to stay a full of people and that live stream went to an incredible amount of people around the world. So it's like coming in from everywhere. It's not just the people at the event.
I think when you look at the -- I mean reframe the question, when you look at the budget, where is AI budget security budget coming from? It's coming from all over. You could have a CTO basically saying, "Hey, we're rolling out AI, AI agents in this part of the business and we can't roll it out unless we have the security piece, right." Boom. The budget is now -- you were getting security budget from a larger budget of spend. So that happens.
You have budget coming from, hey, we're going to get rid of a few products, and we're going to take that, and we're going to burn down more Flex and here you go, right? We have it there. And then you sort of have budget that there's always corporate money somewhere. And I always use the example. If a customer has a breach are they not going to find money to go remediate it? Like, yes, of course, they are, right? So there's always a sort of money that's hanging out there where if somebody has to do something very quickly and its CEO money and CFO money somewhere where they go, hey, we got to get this done because we're holding back the adoption.
When we met with one of our big design partners, huge. I said, what's the #1 success criteria. And it wasn't like this feature, that feature. The #1 success criteria was we need to roll out AI faster from the CEO down. And if that's the mandate, this isn't the security CISO. This is the CEO go and roll it out next week, you're going to find money for it. So that's what we've seen.
Thanks, Michael. Let's take our next question over here from Brad.
Brad Zelnick with Deutsche Bank. Thanks so much for having us. I think what my friend, John DiFucci was trying to say is that this has actually been a master class this week. I think of all the vendors in luminaries that we listen to, this is the strongest, clearest vision for the future of where AI and cyber are going. So my hats off to you.
A lot of questions to ask. I want to touch on next-gen identity which is a cornerstone of that pyramid that you showed us really important. And how differentiated the approach is that you're taking. There's a well-established TAM market that's been around for years that others are saying is the answer you after a couple of very key acquisitions are now just getting up and running at something that is potentially seems very different, very disruptive. If you can just explain to us the why and why it's the right solution would be great.
And then from Burt, if you can maybe even frame it for us in the context as we saw like AIDR, how quickly it's ramped in a matter of months. What the milestones are for this next-gen identity solution that you're thinking about ahead?
Yes. So look, as you know, we've been talking about identity threat detection bonds for years now through the preempt acquisition. We're very unique in the way that we approach that. But we've not stopped there. For us, we were thinking about time access. We're thinking about PAM use case. There's not a customer that I've spoken to that said to me, "I love my PAM" They kind of feel it's a bit bloated. It's a bit archaic but they use what they have, they're sweating their assets, but they're asking us for a much more efficient way to do just-in-time access.
There's some session recording and some bolting things that people ask about, but we added the just-in-time access piece. The biggest thing that we've thought about is how do you solve the problem for identity tomorrow. And sovereign identity is solving it for the human, it's solving it for the nonhuman, it's solving it for the agent. This concept of giving somebody trust once so that they can carry out their activity, making somebody an administrator you forget they're an admin, you don't take it away, they get breached. There's a huge drama that happens with it. That model is fundamentally broken.
Without sort of going sort of too deep in the topic, it's the same thing with things like session cookies. Somebody gets a session cookie, they can do things because they got privilege. Even if employee leaves, getting that cookie back is really hard, that's why adversaries go for it. There has to be a better way. And that's why we bought Signal AI. Signal has thought about that problem and built a very elegant way to give access when you need it, access on demand based on business logic based on taking in identity information. So you give somebody access to do the task that they need and then you take it as soon as -- take it away as soon as they finish. This is the dream of security professionals.
We've talked about this at our [ Dentivers ] last quarter, several organizations stood on stage and said, "Hey, this is how identity needs to work today. And there one company that can do it is CrowdStrike" That wasn't a CrowdStrike event. It wasn't a security event. It was an identity event that has all the identity players. So we're really excited about that. The identity provider release includes that capability. And we're going to just keep adding our releases.
So we're going to be talking about identity provider at Falcon Europe. We're going to save something for the next event. And we're going to keep building on the way that, that works. But you saw all the pieces on the screen. You can use it for authentication, you've got the Falcon Identity manager that you can use there. You saw -- you bring in vaulting, you do the agents, do the humans, it's all included.
So just to follow on that, I just want to make an example, like if we think about Next-Gen Identity versus the older technology, a PAM technology, right? As Mike said, we're solving for the problems of the future, which is I should be able to give you my user name and my password and have nothing bad happen. Because ultimately, you have my using a password, but you're not entitled to do anything. You don't meet any of the criteria to do what I want to do. So you have a user name and password nothing happens. If you think about all these attacks that you read about, it's mostly a user and a password at an MFA that's compromised. And then all of a sudden, everything falls apart because of those entitlements that are attached but you know why? Because they pulled it out of some Vault that had standing privileges. That's the difference.
When you pull it out of the -- you're protecting the credential, which has all the entitlements attached to it and you pull it out of a Vault and it works everywhere. And our model is I'll just give you the user name of credential, but it doesn't have any of the entitlements, it doesn't matter, right? So you don't get entitled until you actually -- the system understands what you want to do. And then you only get those entitlements for that micro slice in time. It's a much different model, and it's much more conducive to what the identic world needs. And this is why, again, we got ahead of the curve in buying something like signal. And now you can see the fruits of what it's going to bear.
I think the ramp is going to be just as fast as securing agents. I mean I think people are going to realize really fast. I need both.
We spend a lot of time on the integration, like the big thing acquiring it was making sure that it's part of the Identity suite, making sure that in the back end, it's all integrated. Same thing that we're doing with [ Surafic ]. Obviously, the customer did last night where a customer was talking about signal technology that's in this release. Obviously, they didn't use the name because we hadn't -- they didn't know the new name last night but they're talking about [ Surafic ] and the 2. And they basically said, "Hey, we're turning off [indiscernible] products. There was a whole conversation like you guys have really done it." And we're using Signal, we're using [ Surafic ] it then became a conversation, well, what can we do in the Identity space. It was just fascinating to see people are saying, "Hey, this just does it a much more elegant way and actually solve the problem for tomorrow."
Thanks, Brad. Let's go to our next question here. Let's take one from Matt.
Thanks, guys, for doing this. This is great. George and Mike, I know you've talked about this before and Burt, you mentioned it today. You guys fundamentally believe that the endpoint is the key control plane for the AI era. And it's clear in your numbers, Burt, you always say the scorecard is the financials and the results and the guidance certainly illustrate that's the case. I still get the question from investors like, why not a network vendor, why not a SaaS vendor. Like why -- so I guess we get your perspective. But I guess I'm curious like -- why is that such an important place versus a network, a SaaS-based vendor?
I'm going to say it in a different way because you said endpoint, which is true, we talked about endpoint, but let me say it in a different way, and I think it will make sense. Run time is the control point. you never get to generate any network traffic until you actually run it and execute it. The agent has to be spawned. It has to have an identity and then it has to do something and then it has to reach across the network, right? So you're never going to have any network traffic unless you run something. And this is why when we think about run time as being one of the most critical control points along with Identity, right, because you got to run it and has to -- you have to have the right Identity. We're actually seeing this. We actually have a transparent proxy.
By the way, all the network traffic we see because we have a transparent proxy built into it. So whatever -- we see it before it hits the network. So we're actually in front of the network seeing it. And then by the way, if there is some AI that's taking place that doesn't have our agent on it, Mike talked about the gateway. We're actually launching a gateway. So -- and by the way, if you're not using our gateway, fine, there's a whole bunch of other gateways. We integrate AIDR into all the other gateways to give visibility and enforcement. But it starts on time. You'll never have network traffic unless you actually execute something, and by the way, the network traffic goes through our proxy. So we actually see it before it hits the gateway. Pre-encryption.
Thanks, Matt. We'll take our last question here from Joe.
And that's both endpoint and cloud workload, just to be clear.
Yes. Joe Gallo, Jefferies. Thanks for the question, and thanks for all this. George, you laid out the AI security TAM as a percentage of AI spend. you're not sure if it's 1%, you're not sure it's 8%. You answered Michael's earlier question just like, hey, budgets are fluid. People just need security. So as you're thinking through your pricing, like how are you approaching that? Because like on one hand, you want to make sure you set the appropriate price and drive long-term value. On the other hand, you want to drive adoption. So like how do you even approach that with this never-ending stream of new products. Like if people don't really know if I'm allocating 1% or 8%, like what are customers thinking about and what are you guys thinking about as you set prices?
Well, look, I wish I had a crystal ball on pricing. I mean, if you figure it out, let me know. I'm just trying to give you one representative example of what's happened in security in terms of percentages. And you can take 1%, you could take 8%, you could take somewhere in between but I know it's going to be meaningful. And I think it's going to be different in each customer. If you're in an environment that's highly regulated and you're driving AI adoption that's coming down from the CEO and they're trying to keep headcount down there's going to be a lot more AI security, right, that might have a higher budget, I think financial services.
If you're in other areas, maybe it's a little bit less. But I think on average, I believe it's actually going to be a greater spend than what we saw in cloud security. So if you use that as a benchmark, I think it's going to be a greater spend there. It will evolve over time. But at the end of the day, what's different in this cycle is when the cloud came out, not everyone needed the cloud, you operate in your data center, you're like, "Oh, if I get to the cloud or get to the cloud."
In today's environment, everyone needs AI, which means that security for the first time is the gas pedal, not the brake pedal. And that, I think, gives us opportunity to take more of that budget. And given the fact that we are a platform, we can come in and we can consolidate. And by the way, we can come in and be aggressive in some of the newer products, just to get the adoption then you turn it on with Flex. It's a single agent. It's there. It's an entitlement. Like the ability to actually scale this quickly is there. It's there in the commercial harness and it's there in the technology platform piece.
All right. Thanks, everyone. All right, are we wrapped up?
Well, yes. So final -- so thanks for that. I guess my final thoughts are, we know that you can be in a lot of different places and to come out to spend a little bit of time in Vegas with us to hear what we have to say, but probably more importantly here, what our customers and partners have to say means a lot. That's the best use cases that we have. They're walking around with our technology in hand. So we appreciate it. We'll be around. We can take some more questions and do our little fireside chats over there. And I hope you guys enjoyed the conference, and we'll see you soon.
Thanks, everybody.
CrowdStrike Holdings Inc — Fal.con
CrowdStrike Holdings Inc — Fal.con
CrowdStrike used its Falcon conference to launch SafeMind frontier security models, Guardian for AI-agent runtime protection, and token-based monetization via Falcon Flex.
🎯 Key Message
- Core: SafeMind is a CrowdStrike-built family of cybersecurity-first frontier models and harnesses (Red Tempest for offensive simulation; Blue Solano for defensive detection/remediation) trained on CrowdStrike telemetry to deliver deterministic security outcomes.
- Positioning: Guardian is a runtime agent control product (endpoint, cloud, SaaS) that adds prompt visibility and enforcement; token pricing and Falcon Flex are the commercial levers.
🔍 Strategic Highlights
- Models & Data: CrowdStrike emphasizes proprietary scale — ~7 trillion security events/day, 270 PhDs/300 AI researchers — to fine‑tune open‑weight models for security tasks rather than general LLM use.
- Run‑time Control: Guardian discovers agents, enforces guardrails, logs traceability and integrates with identity to remove standing privileges and stop agentic attacks in real time.
- Partnerships: Technical stack built with NVIDIA (Nemotron), CoreWeave (AI cloud) and Anthropic (marketplace/token flow) for model hosting, performance and distribution.
🆕 New Information
- Product Launches: SafeMind (Red Tempest/Blue Solano), Falcon Guardian GA, AI Gateway and Agentic identity provider are now public; SafeMind delivers benchmark claims (≈37% better detection, up to 99% lower cost per task, 6x faster detection vs generic frontier models).
- Monetization: Token packs and expansion packs will be sold, routed via Falcon Flex (commitment model) to give customers predictable spend; SafeMind access initially tied to trusted programs and Flex rollouts.
❓ Analyst Q&A
- Tokens & Pricing: Management stressed predictability (token pools, bands, burst capacity) and said token sales are a new monetization stream; exact pricing and margin impact will evolve but tokens aim to bake model costs into predictable contracts.
- Availability & GTM: Guardian is generally available and sold through Falcon Flex; SafeMind will roll out with design partners and a phased commercial program in H2.
- Differentiation: Analysts pressed on harness vs model differentiation; management highlighted proprietary telemetry, harness engineering and continuous red/blue learning loops as barriers to replication.
⚡ Bottom Line
- Investor view: CrowdStrike is pivoting from endpoint leader to a platform monetizing AI‑security: product demos, partner infrastructure and a tokenized commercial model create meaningful upside to ARR and TAM capture, but watch execution on token pricing, cost per task and competitive responses.
CrowdStrike Holdings Inc — Q2 2027 Earnings Call
1. Management Discussion
Hello, and welcome to CrowdStrike's Fiscal Second Quarter 2027 Financial Results Conference Call. [Operator Instructions] Please be advised that today's conference is being recorded. I would now like to hand the call over to Andy Nowinski, Vice President of Investor Relations and Strategic Finance. Andy, please go ahead.
Good afternoon, and thank you for your participation today. With me on the call are George Kurtz, Chief Executive Officer and Founder of CrowdStrike; and Burt Podbere, Chief Financial Officer. Before we get started, I would like to note that certain statements made during this conference call that are not historical facts, including those regarding our future plans, objectives, growth, including projections, and expected performance, including our outlook for the third quarter and fiscal year 2027, and any assumptions for fiscal periods beyond that are forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995. .
These forward-looking statements represent our outlook only as of the date of this call. While we believe any forward-looking statements we make are reasonable, actual results could differ materially because the statements are based on current expectations and are subject to risks and uncertainties. We do not undertake and expressly disclaim any obligation to update or alter our forward-looking statements, whether as a result of new information, future events or otherwise. Further information on these and other factors that could affect the company's financial results is included in the filings we make with the SEC from time to time, including the section titled Risk Factors in the company's annual and quarterly reports.
Additionally, unless otherwise stated, excluding revenue, all financial measures disclosed on this call will be non-GAAP. A discussion of why we use non-GAAP financial measures and a reconciliation schedule showing GAAP versus non-GAAP results is currently available in our earnings release, which may be found on our Investor Relations website at ir.crowdstrike.com or on our Form 8-K filed with the SEC today. With that, I will now turn the call over to George.
Thank you, Andy, and thank you for joining CrowdStrike's Q2 FY '27 earnings call. When we last spoke, we were just weeks after what we called the Mythos moment, an inflection point in cybersecurity. The world came to understand that cybersecurity is a necessity for AI adoption. New models created a new risk environment with no turning back. Recently, this realization became even clearer with the market's newest adversary AI agents themselves. We told you this was the future, and this future is now a reality.
Our previous guidance foreshadowed this conviction and CrowdStrike's Q2 was our very best quarter in company history. Inflection has become acceleration. Our Q2 results set a new bar. Here's what we delivered. One, all-time record net new ARR of $333 million, accelerating to 51% year-over-year growth and beating the high end of our guidance by more than $45 million. Two, ending ARR growth accelerated for the fourth consecutive quarter, reaching $5.84 billion, up more than 25% year-over-year; three, total revenue growth accelerated for the fifth consecutive quarter, reaching $1.47 billion, up 26% year-over-year.
Four, Q2 record free cash flow of $377 million or 26% of revenue, growing 33% year-over-year. Five, all-time record operating income of $372 million or 25% of revenue, growing 46% year-over-year. Six, all-time record net new ARR from new logos, while both net and gross dollar-based retention improved over the prior quarter. Seven, all-time record Falcon Flex quarter with ending ARR from accounts that have adopted the Falcon Flex subscription model surpassing $2.29 billion, accelerating to 101% year-over-year growth. And eight, FY '27, net new ARR guidance increase of 630 basis points. We now expect year-over-year growth of 34% at the midpoint, a 1,150 basis point increase from our initial outlook.
The quarter was a sea change for CrowdStrike, and I see these dynamics continuing. We're in an arms race. AI is driving more cyber attacks. AI is driving more cyber spending, AI is driving a clear divide between the cybersecurity companies that solve problems and knows that compound problems. CrowdStrike's quarter demonstrates the market trusting us more than ever to secure their adoption of AI with cybersecurity's single platform of choice. The world's adoption of AI is rapidly expanding the attack surface, more models, more agents more agentic applications, more data and with that more identities, more permissions, more policies, more cyber attacks and more risk.
Agent proliferation is becoming mainstream to augment work and personal life. Agents are powerful forces for productivity and good. Agents are also human and machine risk multipliers with access to data, continuous operational capability and limited judgment. We're seeing agents go rogue swarming to attack and moving beyond their guardrails to autonomously harm. Agents are proving capable of data theft, permission alteration and full on command and control at scale, leading to organizational compromise. The agent of today is both a friend and foe. The currency of protection is increasingly presence and speed.
Do you have the right technology deployed that can see, prevent and stop agentic attacks? Do you have the right technology that can outpace an entirely new real-time adversary? The AI threat environment is shining a clear light on which products work and which don't. We see failing products as open doors for agentic adversaries. At CrowdStrike, we don't just stop these breaches we and our partners help the world recover from them. In this threat landscape, CrowdStrike stands out. Our market-leading cybersecurity services are in high demand, the flywheel we've created of best-in-class incident response services, allotted by law firms and insurance brokers translates into best-in-class product outcomes for new customers.
Ever since Mythos, we've seen growth in our business, not measured by meetings or calls, but measured by ARR. And we don't see the threat landscape subsiding. Far from it. Demand for AI grows our TAM driving the need for CrowdStrike. The AI transformation doesn't just necessitate a technological lift and shift, it's necessitating a fundamentally new go-to-market motion, one based on maximizing time to value, ecosystem impact and ROI. The Falcon platform removes friction from cybersecurity and the go-to-market motion we created with Falcon Flex does the same.
Flex is the commercial harness to enable customer success in the agentic era. This quarter, we kicked Falcon Flex activity into high gear with our Flex first go-to-market strategy. Our top 10 deals by deal value were each flexes and the results speak for themselves. This quarter, we delivered record Flex steel volume, adding more than 935 Flex accounts. That's more than 10 flexes every day of the quarter and more flexes than the last 3 quarters combined. When Falcon customers convert from standard subscriptions to Flex, we see a greater than 40% average ending ARR uplift. We're not just focused on converting existing customers to Flex, we use Flex from the start with new logo customers.
Flex new logo ARR contributed 34% of Q2 net new ARR, a record. We also saw a record reflex activity for existing Flex customers with more than 630 accounts having reflexed at least once up 6x year-over-year. On average, a customer's first reflex happens in 8 months from their initial Flex. Lastly, we saw record repeat reflex customers with average ending ARR uplift of 53% from their initial Flex subscription. Falcon Flex wins include a frontier lab that significantly grew with CrowdStrike in an 8-figure ARR deal using Flex to maintain cost visibility while significantly growing Falcon Cloud security across its rapidly expanding data center infrastructure.
A European automotive manufacturer called upon CrowdStrike to replace a next-gen EDR, a legacy SIEM and a legacy vulnerability management product, landing with an 8-figure net new Falcon Flex CrowdStrike delivered superior outcomes and immediate platform consolidation. Our Falcon Flex go-to-market motion unlocks the complete aperture of the Falcon platform. When looking at our Q2 performance, I'm pleased to see strength across so many different product areas. Increasingly, the epicenter of agentic work securing the endpoint is now a top spend priority. CrowdStrike is the leader in endpoint. We're now capitalizing on our ubiquitous endpoint presence to deliver the future of AI security.
In Q2, our endpoint business accelerated for the fourth consecutive quarter as customers look to secure their growing AI attack surface. We're seeing dramatic expansion in agentic work on the endpoint, both through fast-growing tools such as Codex and Claude as well as custom agentic applications. In sampling our customer base, we've seen more than 400% growth in Claude usage and more than 100% growth in custom agent usage on endpoints in recent months. As enterprises look to deploy these new technologies, they're also seeking ways to contain the new risk created ranging from code exploitation to data leakage to identity compromise. Instead of turning to science projects or point products, the market is trusting CrowdStrike as critical infrastructure to both enable and safeguard their AI future.
A large financial services firm work with 2 of our GSI partners to replace a next-gen EDR in an 8-figure Flex win across more than 100 entities and hundreds of thousands of endpoints, CrowdStrike was selected for the best detection coverage, deployment ease and the lightest impact. Our endpoint success fuels the adoption of AIDR, a product surging past our expectations. AIDR ending ARR nearly tripled versus Q1 as customers embrace our frictionless approach to AI visibility and security. One of the world's largest banks adopted AIDR in an 8-figure Flex win. Immediate AI deployments necessitated security, visibility and control. We were selected for AI usage visibility and data exfiltration prevention.
Demand adoption and growth like this is rarely seen. I can't wait to unveil our newest AI security innovations at next week's Fal.Con conference. Moving to our cloud identity and next-gen SIEM businesses. The market is rapidly embracing these products to protect fast expanding attack services. We delivered record Q2 net new ARR from the combination of these businesses. Unpacking these results, our next-gen SIEM business delivered another banner quarter driven by record Q2 net new ARR. NextGen SIEM ending ARR surpassed $695 million this quarter as both new and existing customers are standardizing on Falcon as the operating system of the SOC. Our native first-party data advantage, coupled with the speed and efficiency of our platform continue to set us apart.
Features like Agent works enable security teams to build, deploy and manage custom AI security agents, setting the foundation for the AI SoC. In an 8-figure Falcon Flex win, a major American power provider replaced a legacy acquired SIEM, selecting next-gen SIEM over a firewall first product for technical, speed and economic superiority. Turning to our Identity business. Ending ARR grew 34% year-over-year to more than $585 million driven by strength across our identity product portfolio. Specifically, Falcon Shield had another strong quarter as enterprises look to secure their third-party agentic applications. Shield ending ARR grew more than 185% year-over-year in Q2.
In addition, our privileged account security offering saw a stellar adoption with ending ARR growing more than 35x year-over-year. Rounding out our identity portfolio, we're seeing early success with signal. Large enterprises are rethinking decades of legacy access controls, no longer effective for the agentic era. Instead, they're embracing Signals real-time granular access model for both humans and nonhuman alike. In 1 customer alone, Signal brokered more than 30 million unique access decisions without friction.
A major global financial firm added next-gen identity to their Falcon deployment following a Board-mandated AI security audit. Hand-in-hand with next-gen identity was an immediate deployment of ADR and where identity protection enabled AI adoption. Moving on to cloud, where ending ARR exceeded $905 million, growing more than 29% year-over-year. CrowdStrike is the leader in cloud runtime security, which has become an imperative in protecting modern AI workloads. Our customers tell us that point in time, posture scans are no longer enough to protect against fast-moving threats that now proliferate in seconds. A mega technology conglomerate opted to use Falcon Cloud Security for our runtime superiority in an 8-figure ARR win. CrowdStrike now secures this organization's AI cloud and labs because of our build pipeline integration and compatibility with internal tools resonating with their DevOps teams.
Finally, we're seeing the Mythos moment transform the market's need for exposure management, pressuring antiquated vulnerability management products built for a bygone era. The agentic adversary has broken the exploit sound barrier, and you simply cannot patch vulnerabilities fast enough. As the patch window collapsed, our exposure management business accelerated sequentially in Q2. Falcon Exposure Management offers real-time detection and continuous prioritization to successfully contain a new speed and scale of vulnerability risk. Our representative exposure management when included a global religious organization that replaced a legacy vulnerability management product as part of their AI transformation initiatives.
In this 7-figure flex, the account also immediately deployed AIDR to bring visibility and control to its AI usage, showcasing CrowdStrike's position to protect against AI threats and govern AI adoption. Our partner ecosystem is mobilized around Falcon and its role in securing AI. Project QuoteWerks, has united more than 25 of our partners from GSIs to hyperscalers, resellers to ISVs and even distributors and MSPs. To date, our QuoteWerks partners are collaborating with us on nearly $400 million of total contract value pipeline.
We've seen exceptional engagement from GSI partners, resulting in our GSI business growing nearly 50% year-over-year, largely focused on next-gen SIEM transformations and vulnerability management needs. Across our MSSP business, we're seeing significant traction in the SMB space with key partners such as Kroll. Three quarters ago, Kroll took a strategic step to migrate all of its customers off a competing next-gen endpoint technology. A majority of customers already successfully migrated to Falcon across 450,000 endpoints, tracking ahead of plan, Kroll took a major next step with a multiyear Flex subscription growing their spend with CrowdStrike by more than 3x.
This Flex addresses platform consolidation and SIEM transformation across Kroll's existing Falcon installed base and incoming new customers. and another Q2 when Accenture standardized on CrowdStrike for its new SMB-focused Accenture Edge business launched in June. Lastly, Q2 showcased the power of our one-of-a-kind cloud marketplace go-to-market motion across AWS, Google and Microsoft. Each of our hyperscaler marketplace partners we saw a record Q2 as customers use their hyperscaler of choice for security investments. In Q2 alone, we transacted more than $600 million in deal value through cloud marketplaces representing more than 30% year-over-year growth. We quickly saw traction with our Microsoft marketplace presence, opening a new addressable market. Immediate Microsoft marketplace wins included a new logo Australian health care provider started using CrowdStrike for SOC transformation in a 7-figure flex. An American manufacturing firm previously used our services and has now expanded to the Falcon platform through a 7-figure flex on Microsoft Marketplace.
In closing, Q2 was an incredible quarter where the Mythos moment turned into acceleration. Acceleration in net new ARR, acceleration in ending ARR, acceleration in Falcon Flex, acceleration in our ecosystem, acceleration in innovation, we're seeing endpoint as the epicenter for AI adoption. We're seeing AI DR define a new cybersecurity category. We're seeing next-gen SIEM as the operating system of cybersecurity. Falcon Identity becoming the security front door for human and nonhuman users and exposure management as mission-critical for prioritizing AI risk.
Taken together, the Falcon platform is cybersecurity's infrastructure layer for AI adoption. AI adoption is accelerating from Frontier labs and open weight models alike, and we're still in the early innings of the AI revolution. When I look at our business, here's what this acceleration means. Last quarter, we raised our forward net new ARR growth guidance by 520 basis points and this quarter, we're raising our FY '27 year-over-year net new ARR growth outlook by an additional 630 basis points, even more than last quarter. That's a raise to our net new ARR guidance of more than $100 million since the start of the year. Delivery of a quarter like this and this outlook is fueled by the demand environment and our technology team, ecosystem and customers.
The innovation engine is an overdrive. As I shared last quarter, Dr. Bartley Richardson previously at NVIDIA has joined us as our Chief AI Autonomous Systems Officer as part of our long planned and mutually agreed upon CTO leadership transition. I can't wait to share the vision and innovation that we are bringing to the world's adoption of AI Falcon in Las Vegas next week. The conference sold out in early August, and it's our largest pipeline generation event of the year. We'll have record customer and partner attendance. I also encourage everyone to tune into our investor briefing on Wednesday, September 2. Our role in securing enterprises, governments and economies is vital to AI adoption and mission-critical in an AI-first world. I'll now turn the call over to Burt Podbere, CrowdStrike's CFO.
Thank you, George, and good afternoon, everyone. As a quick reminder, unless otherwise noted, all numbers except revenue mentioned during my remarks today are non-GAAP. Additionally, all earnings per share and share amounts presented today and in our accompanying investor materials, have been adjusted to reflect our recent 4-for-1 stock split for all periods presented. We delivered a record second quarter, exceeding expectations across all guided metrics. We achieved an all-time record $333 million of net new ARR well ahead of our guidance and accelerating to 51% growth year-over-year. .
Ending ARR reached $5.84 billion, up more than 25% over the prior year as growth accelerated for the fourth consecutive quarter. As George discussed, the post-Mythos demand environment continued to strengthen in Q2. The customer urgency we began to see in Q1 translated into increased cybersecurity investment, accelerated modernization and stronger demand for the Falcon platform. Our acceptable Q2 performance was broad-based across customer sizes and geographies. Net new ARR contribution from new logos was an all-time record. And both our dollar-based net and gross retention rates improved sequentially. Platform adoption also continued to deepen with 51%, 35% and 26% of subscription customers adopting 6, 7 and 8 or more modules, respectively.
Falcon Flex continues to be a key driver of our platform consolidation with this quarter showcasing the power of our Flex First strategy. In Q2, customers converting from standard subscriptions to Flex delivered an average ending ARR uplift of more than 40%. From that new baseline, customers completing their first reflex this quarter generated an additional average ending ARR expansion of 25%. Looking at the cumulative uplift of customers who have reflexed at least twice, in Q2, these customers had average ending ARR 53% higher than their initial flex starting point, increasing for the second consecutive quarter. Taken together, these results underscore exceptional execution and the power of our platform strategy with AI-driven demand, accelerating platform consolidation and helping deliver the strongest quarter in CrowdStrike's history.
We also exited the quarter with a record Q3 pipeline further reinforcing our confidence in the demand environment ahead. Moving to the P&L. Total revenue exceeded our guidance range and grew 26% over Q2 of last year to reach $1.47 billion, with year-over-year growth accelerating sequentially for the fifth consecutive quarter. Subscription revenue grew 27% over Q2 of last year to reach $1.40 billion and professional services revenue was an all-time record $71 million as AI creates incremental demand for our AI readiness and incident response services, further increasing software cross-sell opportunities. The geographic mix of second quarter revenue consisted of approximately 65% from the U.S. and 35% from international geographies. Broad-based strength across our major regions drove international year-over-year revenue growth acceleration for the fifth consecutive quarter.
Total Q2 non-GAAP gross margin was 79%, up approximately 110 basis points over the prior year. Non-GAAP subscription gross margin was 81%, up approximately 90 basis points over the prior year, driven by continued cloud optimization efforts as we remain focused on achieving our FY '29 target model of 82% to 85% non-GAAP subscription gross margin. Second quarter non-GAAP operating income was a record $372 million, exceeding our guidance and non-GAAP operating margin was 25%, up 350 basis points over the prior year. The outperformance was driven by strong top line execution, continued gross margin expansion and increased operating efficiency. Our internal investments in automation and AI continue to yield greater operational efficiencies and productivity gains across our business.
The combination of accelerating revenue growth and substantial year-over-year operating margin expansion demonstrates our strong operating leverage as we invest in the significant opportunities ahead positioning us to deliver durable, profitable growth. In Q2, we delivered $5 million of GAAP net income attributable to CrowdStrike, marking the third consecutive quarter of positive GAAP earnings. Non-GAAP net income attributable to CrowdStrike was a record $323 million or $0.31 per diluted share, exceeding our guidance and up 34% compared to the prior year on a split-adjusted basis.
Moving to cash. Our cash and cash equivalents grew to $5.01 billion. We generated Q2 record cash flow from operations of $530 million and Q2 record free cash flow of $377 million or 26% of revenue, exceeding our free cash flow margin expectation of 24.5%. Moving to our outlook and modeling notes. Consistent with our guidance philosophy, our outlook reflects the strength we see in the business while maintaining a prudent approach. Our record second quarter performance, record Q3 pipeline and broad-based demand across customer segments and the Falcon platform give us increased confidence in the strength of the demand environment and our long-term growth opportunity. As a result, we are once again raising our fiscal 2027 net new ARR outlook. At the midpoint, we now expect $1.355 billion of net new ARR for the full year, an increase of approximately $116 million from our initial FY '27 outlook.
This equates to expected year-over-year net new ARR growth of approximately 34% compared to 22.5% in our initial FY '27 outlook representing an increase of 1,150 basis points. The magnitude of this increase reflects more than our Q2 outperformance. As AI expands the attack surface and increases the urgency around cybersecurity, we believe it is driving a broader security modernization cycle that creates durable demand across the Falcon platform. Combined with continued platform consolidation and strong Falcon Flex momentum, these demand signals reinforce our confidence in the full year opportunity ahead. Before I walk through our detailed guidance, let me highlight 2 additional items to keep in mind.
First, the acquisition of XM Cyber's technology assets is expected to close in the second half of FY '27 and will not bring any ARR or revenue to CrowdStrike nor are we including any ARR or revenue from this transaction into the FY '27 guidance. And second, at the midpoint of our guidance, we expect free cash flow margin of 27.5% in Q3 and continue to expect at least 30% for the full fiscal year on our increased revenue guidance. With that, for the third quarter of FY '27, we expect annual recurring revenue to be in the range of $6.184 billion to $6.188 billion, up 26% year-over-year. This translates to net new ARR of $343 million to $347 million, up 29% to 31% year-over-year. Total revenue to be in the range of $1.523 billion to $1.529 billion, up 23% to 24% year-over-year.
Non-GAAP income from operations to be in the range of $373 million to $376 million and non-GAAP net income attributable to CrowdStrike to be in the range of $325 million to $328 million. Diluted non-GAAP net income per share attributable to CrowdStrike to be approximately $0.31, assuming a 21% tax rate and approximately 1.048 billion weighted average diluted shares. For the full fiscal year 2027, we expect annual recurring revenue to be in the range of $6.603 billion to $6.612 billion, up 26% year-over-year. This translates to net new ARR of $1.350 billion to $1.359 billion, up 34% year-over-year. Total revenue to be in the range of $5.991 billion to $6.011 billion, up 25% over the prior fiscal year. Non-GAAP income from operations is expected to be between $1.497 billion and $1.508 billion, and non-GAAP net income attributable to CrowdStrike to be between $1.303 billion and $1.312 billion, assuming a 21% tax rate and approximately 1.044 billion weighted average diluted shares, we expect non-GAAP net income per share attributable to CrowdStrike to be in the range of $1.25 to $1.26.
George and I will now take your questions.
[Operator Instructions] Our first question comes from Saket Kalia with Barclays.
2. Question Answer
Okay. Excellent. Well, great to see the acceleration continue. George, maybe for you, the Mythos moment happened in the spring. And now we've gotten a few months of activity behind us. Could you maybe talk about what transpired after that? And as you look back, what were some of the key drivers of this upside here in Q2?
Thanks, Sak. So as we mentioned in the spring, the Mythos moment was building. And as we told you it was going to be a growth driver and a tailwind for us, and you saw that show up in our results. When we think about AI agents going rogue when you think about the need for protecting AI and understanding where shadow AI is, it all points to the technologies that we're building and delivering here like AIDR, which was just had a phenomenal quarter, no surprise.
Obviously, cloud identity next-gen SIEM, endpoint was accelerating and exposure management. which is a big element now given the fact that companies can't keep up with the patching. So when you put all of that together, it comes to what we said the Mythos moment was a point of acceleration, and we see those tailwinds continuing.
Operator, next question, please.
Your next question will come from Brian Essex with JPMorgan.
Great to see the nice magnitude of net new ARR upside this quarter. Maybe, George, for you, just to piggyback on Saket's question there. I would love to get your view on the durability of strength that you're seeing on the back of the Mythos moment, so to speak. I mean how much of the momentum goes beyond next quarter, perhaps beyond the end of the year. And given what you have in your pipeline, how much visibility do you have into the strength, maybe just into next year and beyond?
Sure. I think when you look at the durability, it's -- in my opinion, it is absolutely there. It's one of the reasons why we raised FY '27 outlook again. And what we're hearing from customers is they want to deploy more AI, but to be held back because of security compliance, privacy data protection type issues. So every customer that we talk to is concerned about the agentic threats. We've seen agents go wild. We've seen them break out of the Frontier labs. And this is a sustainable tailwind. If we believe that AI is in its early days and it's only going to get better and more powerful, combined with the autonomous nature of these attacks, it's absolutely something that every company is going to need.
And as I said in the prior earnings call, I think the AIDR business can be bigger than the EDR business, just given the pure number of agents, which each person will have, which is estimated to be about 90. So for me, it's a sustained tailwinds, and I think we're only going to see more stories around agents gone wild and we're going to be there to protect our customers.
Yes. I think, Brian, the numbers back it up. Look, you start with the record Q3 pipeline. So that prompted us to raise our full year guidance by an additional [ 630 ] based. That means we moved our FY '27 near growth rate from 27.7% at the end of last quarter to 34% this quarter. When compared to our initial guide for the year, we raised the growth rate 1,150 basis points or $116 million in just 2 quarters. That talks to the durability of the things that towards.
Your next question will come from Gabriela Borges with Goldman Sachs.
George and Burt, I wanted to ask you a little bit of product question. You gave a little bit of -- you gave the case studies earlier on customer journeys and some of the flagship wins in the quarter. What I want to better understand is if you have a customer, let's say it's a large financial organization. And they go from having agents being sandboxed and isolated regardless of how effective those sand boxes can be to actually wanting the agents to have rural customer data, real enterprise data. Walk us through the before and after, how do you advise those clients on what products they need to buy from a CrowdStrike clearly Identity as a part of it to be able to say, agents isolated to agents in production.
Sure. Well, I think to make the agents productive, they're going to have to have access to data. And again, when you look at what we're delivering for customers, it's looking across the entire spectrum of threats, right? You have to have an identity control plane, which we have for nonhuman identities. You have to have data protection, which we have. You have to understand at front time what the agents are actually doing, whether that's in a sandbox or if those agents are running essentially on your computer, your laptop, you have to understand the exposures that you have, you have to be able to keep track of where those agents are calling out to.
We can do all of that. So if it's in a sandbox, we can run in a sandbox. If it's out of a sandbox, which many of our customers are just kind of consuming AI on their desktops using the various Frontier lab partners and the like. and we cover all of those, including if you're creating agents in a cloud environment. So from my perspective, the agents -- first of all, you need to know where AI is being created. You need to know where it's being consumed, and you have to put the right guardrails around identity, data, execution and network connectivity, and we're delivering that for our customers.
Thanks, Gabriela. Operator, next.
Your next question will come from Matt Hedberg with RBC.
I'll offer my congrats as well. I wanted to piggyback sort of on this train of thought. And George, you talked about it in your prepared remarks, but I just -- I think we're all sitting back there and we're seeing these agents going rogue. And just how quickly this landscape is changing. So I guess from your perspective, I just wanted to kind of get a double click on like how do you see the threat landscape today. And when we think about how quickly this is changing, the relationship with the Frontier labs is obviously great. But talk to us about why you're uniquely positioned even if these Frontier labs start to release some of their own security solutions in the future.
Sure. Well, I think it's important that when you look at AI and to make AI protection more effective, you have to have very deep data expertise. And this has been something that's been basically built in the platform from day 1. Over the last 15 years, we have some of the richest threat data -- richest attack data, richest data around actually how to mitigate the threats in the industry. So when you look at the models that we've built, we've trained on those specifically and that gives us a unique perspective. Customers, of course, want choice. They want to work with frontier models. They want to work with our technology and our platform, fantastic. But having the right data, having it trained in a specific fashion and labeled appropriately, I think, is unique.
And we have data that just isn't available outside of the CrowdStrike walls. That's very important. The other piece is, and I mentioned this some time ago, we are net data creators. We're constantly creating new data that's coming out of our endpoints. We're constantly using that data update our algorithms as the threat environment changes. And again, I think this is very important to our customers. They want security companies, they can trust. They want data sovereignty from a technology perspective, and they want to get actual results based upon the information in their own environment, and we're delivering that today.
Your next question will come from Fatima Boolani with Citi.
I wanted to double back on some of the earlier questions around portfolio pervasiveness so specifically just around the acceleration that you continue to see in Falcon Flex, both from a standard conversion and Reflex. George, I was hoping if you could help us maybe parse out more granularly where you are seeing the most incremental or outsized traction on a SKU or disciplinary basis as organizations move to production-grade AI adoption. And I guess in other words, sort of what parts of the portfolio have proven to be most potent in giving organizations the assurances and confidence they need that they are in a secure situation with their AI adoption.
Sure. I'll take that, Fatima. So first, let's just talk about Flex. So Flex, it was an all-time record flex quarter with year-over-year growth accelerating to 101% and year-over-year, surpassing $2.29 billion. And a lot of that is coming from some of the different technologies that we've been talking about quarter after quarter. When you think about cloud, next-gen SIEM, next-gen identity, ending ARR was $2.1 billion, up 39% year-over-year. And if you go down the list of how we've done in each one of those particular elements, they're all really impressed right? You think about cloud over $905 million and ending ARR up 29%. You've got next-gen identity, which is a big piece of the AI story. That's up 33% year-over-year.
And then you've got, obviously, Nextgen SIEM, just a home run for us. That's coming up on almost $700 million, and that's up 60% year-over-year. So all 3 of those can be an IPO by itself. So you're seeing kind of adoption through our Flex licensing really showcased itself in those 3 products. And then George mentioned a whole bunch of other ones. We talked about exposure management having a great quarter. We talked about AIDR having a fantastic quarter. So I think the point is that Flex is letting itself to be able to buy multiple of our products at the same time. And that's what's leading to bigger, longer deals for us. And it's better for the customer. At the end of the day, it's the platform sale. That's what matters. Customers are looking to consolidate on. They want more -- better outcomes at a cheaper cost.
Thanks, Fatima. Operator, next question.
Next question will come from Meta Marshall with Morgan Stanley.
Great. I wanted to maybe follow up on some of that next-gen SIEM strength. If we're having this conversation a year ago, there was a lot of -- they can start with -- our customers can start moving their AIDR data over and then kind of gradually over time, expand those implementations. I just wanted to get a sense, as you guys are seeing continued really strong growth, is that kind of land happening differently? Like are people taking more of a chance upfront and moving more to you guys initially? And then just are we seeing kind of more data or logs being put into the SIM to give better signals as they try to kind of detect more advanced attacks.
Yes. Well, when you look at next-gen SIEM, the great news is it's every customer's next-gen SIEM enabled. Like the data is just in the platform. So it's just a matter of signing up and paying for the license entitlement and you're up and running with the court, what we call first-party data, the data that we actually generate. So that has made it incredibly easy and friction-free for many customers. They routinely say it's the easiest SIEM to get up and running. It's the quickest return in terms of time to value of what they're putting in and the results are getting out. And then it's very easy to connect to other data sources.
We've seen the other data sources rapidly expand. If we think about AI, AI agents, SaaS and SaaS cloud agents, if you will. These are all an identity. These are all areas that customers have to instrument because we see these cross-domain attacks that go from internal systems to the cloud or cloud to internal systems and everything in between. So we've seen just tremendous results there. It's a fantastic product. and it's very disruptive from a price point because of how we charge for the first-party data that we create. So it is a story of better, faster and more value for the money. And you can see the results they speak for themselves.
Thanks, Meta. Operator, next question.
Our next question will come from Adam Tindle with Raymond James.
Congrats on a great quarter. George, I wanted to ask on AIDR versus the core EDR platform kind of a 2-parter. I ask because investors are struggling with the definition and a view that there might be more gray area between AIDR and your core platform. So I guess the first part of the question would be, is there kind of a simple way to think about AIDR, where is this incremental where customers are buying this in addition to EDR? Or is this being used more as a substitute for EDR or any other products. And the second part would be, you've kind of alluded to some metrics around this that have been helpful. But I wonder if you might just take a second to put in context the ramp of AIDR versus other products at the stage as we try to think about the potential ultimate size of that platform.
Yes. So on the first point, it is separate and incremental. It's another module and it's priced separately, which is, again, where we're seeing a lot of the growth. So that is certainly a good fact to make sure that we clear up if there was any confusion about it. When we think about the beauty of the architecture and the platform, it's still using the same agent. And if you want to enable AIDR, again, that's a license entitlements part of our friction-free deployment. Again, why is Falcon Flex so successful? Why have we been successful in media time to value, and you don't have to roll out yet another agent. So that's very important. And when we talk about sort of like the ramp of this, it's been incredible over the last couple of quarters.
And we've seen almost the results sort of parallel some of the Frontier labs growth as they continue to add more agents and capabilities, you have customers that are deploying more AI, they actually want to deploy AI faster and they need to scale incredibly fast. So when you combine what we're building with -- again, it's on the same platform, that's the beauty, but we're able to monetize it separately we think that's a home run. And we're showing the value to customers and they're willing to pay for it because it's very unique in the environment and they don't want to deploy yet another agent, right? They're getting it all with CrowdStrike, and that's what they're looking for.
All right. Thanks, Adam. Operator, next question.
Our next question will come from Roger Boyd with UBS.
For George or maybe for Burt, given the traction you're seeing around AI security and you noted the acceleration in overall AI usage across your installed base inflecting. Look, I appreciate your updated views on how you're evolving the pricing model. And namely, are customers asking for token-based pricing in cybersecurity. And if so, how is that incorporated in the Feds contracts?
Yes. So we actually have token-based pricing as part of AIDR. So we already have that today. And what's important from a customer perspective is they do want some certainty on what they're paying. So we provide a certain number of tokens across an environment, and we -- obviously, we scale out to how big the customer is, and then if they exceed that token usage, they can buy extra token packs. And again, the beauty is it's all consumable via the Falcon Flex licensing. So it's a model, I think that served us well, where it's not runaway cost for customers. They can define it, they can budget for it. But certainly, as they scale up their AI if they exceed their budget allowance, they certainly can up-level the tokens, and it's friction-free to do that with Falcon Flex.
Okay. Thanks for the question. Operator, next question, please.
Our next question comes from Rob Owens with Piper Sandler.
Great. Thank you and good afternoon. George, I guess back to the start in thinking about your history with Foundstone a little bit. And twice on this call, you did mention exposure management. So love to understand the evolution of that market where you're seeing displacement? Because I think you mentioned a large-scale transaction there. And effectively, what the older solutions aren't providing at this point. I know that you guys adopted a network scanning capability a year ago. But with AI, I'd assume it's well beyond that at this point. So just would love for you to drill down on that opportunity in why CrowdStrike is winning.
Sure. So when we think about where we are with exposure management, I think it's a rebirth and certainly, we're in full position in that area. So what I mean by that is given the fact that there's an exponential increase in vulnerabilities that are found Frontier AI and patches that can be created via Frontier AI, that's great. The problem is you've hit the sound barrier of actually rolling out a patch. And what that means is that companies are looking for their ability to prioritize where these exposures are because they're not going to be able to fix everything all at once within the window of what autonomous agents can actually exploit.
So that's really the driver in an area where customers are looking at and saying, "Hey, I've got to think about this differently." I can't be doing the same old things that we've been doing. I can't keep using the same old legacy exposure management or vulnerability management technology. So they want a view of their assets. They want a view of where their protection is Falcon. They want to view what's exposed, right, what patches need to be applied but haven't and they want to understand the attack paths. And we are delivering that in an autonomous fashion within the Falcon platform. And that's a big reason why we're displacing a lot of legacy vendors in the market today.
Thanks Rob. Operator, next question.
Our next question comes from Mike Cikos with Needham.
And congratulations on another significant lift tier to the net new ARR guide following the strong 2Q execution. George, maybe for you, we've been doing a significant amount of work with CISOs. And the common refrain we're hearing comes back to AI governance, both in terms of security as well as the pull-through on the economic need to control these AI costs -- my question really ties to, can you just put a finer point on discussing how customers are turning to crowd in terms of serving as that strategic partner for implementing and enforcing AI governance guardrails. I think that would be super helpful.
Sure. Well, on the product today, we have the ability to set policy and enforce those guardrails, which is incredibly useful, needed and incredibly difficult. As you might imagine, in some organizations that are dealing with -- they make chemicals as an example. Well, that may be something that is not an approved sort of topic, if you will, in other companies. But in some companies, that's what they make, right? So you have to be able to have the right models to understand what's happening in the environment. You have to be able to set the policies in a way that actually work and minimize false positives.
And then you have to give these customers very good results very quickly. so they can roll this thing out without a lot of friction. And we're doing that today. The other piece that you touched on, which is very important, is we actually have the ability to count tokens and track cost. And this is very important as you expand outside of the boundaries of just pure security. When we think about IT infrastructure, and we think about the CIO, having the ability to help them manage cost is a big part of our selling point as well. So you get the guardrails that you're looking for, get the protection you need and also you have visibility into where your AI agents are and what people are actually spending on these results.
And it's incredible. I mean we've heard EA spending $10,000 just on tokens because of the way they were using the models. And dramatically, once you understand and have visibility around that, you can dramatically cut those costs down. So it's really a one-two punch of protection and cost management.
Thanks, Mike. Operator, next question.
Our next question comes from Patrick Colville with Scotiabank.
I guess this one for both George and Burt, please. I mean you talked about the Frontier lab, 8-figure deal with this customer protecting their rapidly expanding data center infrastructure. I mean any more questions -- any more details you can share on this specific 8-figure deal. And then to zoom out the aperture a little bit, could you just talk to this emerging customer category of helping to protect the Frontier labs?
Sure. I think you've got the digital natives that are out there, AI native companies. You've got the fronter labs, as you might imagine, all of the companies that are involved in creating need to protect AI. And they're turning to CrowdStrike because we've got the right technologies across the entire stack. And again, like if you look at what we've done with NVIDIA and how we have integrated into their platforms. It's a complete ecosystem from the chips all the way up to the applications and AI inference. So we think we're in a great position to be able to help these rapidly growing and expanding companies because they're going to need visibility.
They're going to need protection. They're going to need control. They're going to need compliance as they continue to scale. And we think the sky is the limit with the Frontier model creators and anyone involved in the AI ecosystem and we're there for them. And we think we have a very unique and differentiated technology in those areas.
Thanks Patrick. Operator, next question.
Our next question comes from Joseph Gallo with Jefferies.
There's a lot of excitement and big numbers with the emerging products in the call, but I just wanted to focus on endpoint, which accelerated for the fourth tray quarter. Can you just unpack that a little bit more? Is that new logos? Is that selling more managed services and premium SKUs. And just how much runway is left there, just given it's perceived as a more mature market.
Sure. Well, I think when you look at companies desire to protect again, a lot of the AI is being consumed on the end point. right? It might be created in the cloud, but it's being consumed on the endpoint. You can think about your own organizations and perhaps how you even use AI. So that has driven the need for companies like CrowdStrike to be able to actually protect those instances. .
If we think about the market, about half the market is still using legacy AV, right? So legacy AV and legacy providers are not really going to have the capabilities to identify role AI agents, shadow AI and be able to protect against its very unique and differentiated, but it fits within the platform that we built from the beginning. So that's one area where, again, if you want to protect these endpoints, you're going to have to have something like CrowdStrike, and that includes net new wins from a lot of the legacy providers that are out there, certainly in addition to cross-selling into our customer base.
Our next question comes from Todd Weller with Stephens.
Congrats, George, a question on QuoteWerks. Can you talk about how impactful it was in the quarter? And then trying to better understand the monetization angles there. Should we initially think about that as like a partner-led motion where they're leveraging your platform and Frontier AI model capabilities to do assessments and then that drives kind of follow-on platform pull-through?
Yes, that's exactly right. When we think about the Mythos moment. There's many of our partners. And again, we're a very partner-first organization that want to be able to service their customers. They've got great relationships, but we need to be able to arm them with Frontier caliber capabilities to be able to understand where these vulnerabilities are, what threats are out there and what they can do. So essentially, they're leveraging our platform and a partner-led motion and finding vulnerabilities, understanding exposure and then obviously working on remediation with some of the largest enterprises in the world.
And of course, that leads to platform pull-through. So I think from our perspective, it's been a home run in QuoteWerks. We have many companies that want to still yet get into it. We're working through all of those, and we'll continue to expand the partners as well as its capabilities within the platform for them to leverage.
Thank you. This concludes today's question-and-answer session. I would now like to turn the call back over to George Kurtz for closing remarks.
Thank you for your time today. We appreciate your continued support and look forward to seeing you at Fal.Con 2026 and other upcoming events. Thank you.
CrowdStrike Holdings Inc — Q2 2027 Earnings Call
CrowdStrike Holdings Inc — Q2 2027 Earnings Call
Record Q2: accelerating ARR growth, strong margins and a raised FY‑27 net‑new ARR guide driven by AI security demand.
📊 Quarter at a Glance
- Net new ARR: $333M (+51% YoY); beat high end of guidance by >$45M (ARR = Annual Recurring Revenue).
- Ending ARR: $5.84B (+25% YoY), growth accelerated for 4th consecutive quarter.
- Revenue: $1.47B (+26% YoY), fifth consecutive quarter of sequential acceleration; subscription revenue $1.40B.
- Profit & Cash: Non‑GAAP operating income $372M (25% margin); free cash flow $377M (26% of revenue); cash balance $5.01B.
- Product traction: Falcon Flex ARR >$2.29B (101% YoY); AIDR, next‑gen SIEM and identity showed strong net new ARR gains.
🎯 What Management Says
- AI as tailwind: Management views AI agent threats as a durable, company‑wide demand driver accelerating security modernization and platform consolidation.
- Flex go‑to‑market: Falcon Flex (consumption/pricing model) is central to winning large deals and increasing per‑account ARR via initial Flex sales and repeat "reflex" expansions.
- Platform strategy: Emphasis on endpoint + AIDR, next‑gen SIEM, identity and exposure management as integrated controls for agentic AI risk.
🔭 Outlook & Guidance
- FY '27 net new ARR: Midpoint now $1.355B (≈34% YoY growth), an increase of ~$116M vs. initial guide; raised twice this year.
- Q3 / FY revenue: Q3 revenue guide $1.523–1.529B; full‑year revenue $5.991–6.011B (+25% YoY).
- Cash & margins: Expect Q3 free cash flow margin ~27.5% and ≥30% for full year; non‑GAAP EPS ~$1.25–1.26 for FY.
- Model note: XM Cyber asset acquisition won’t contribute ARR/revenue to FY '27 guidance.
❓ Analyst Q&A
- Durability: Management repeatedly argued the AI/security tailwind is sustainable, citing pipeline strength and elevated customer urgency; they pointed to record Q3 pipeline as validation.
- AIDR vs EDR: AIDR is incremental (separate licensed module) not a substitute; it uses the same agent which eases deployment and supports token‑based consumption models.
- Pricing & tokens: Token pricing exists for AIDR; CrowdStrike says customers get budget certainty via token packs and Flex handles scaling, not a runaway cost model.
⚡ Bottom Line
- Investor take: Strong execution: record net new ARR, margin expansion and raised guidance signal durable demand tied to AI security needs and effective platform monetization via Flex; key watch items are continued execution on large deal conversions, token consumption economics and competitive responses as the market evolves.
CrowdStrike Holdings Inc — Q1 2027 Earnings Call
1. Management Discussion
Hello, and welcome to CrowdStrike's Fiscal First Quarter 2027 Financial Results Conference Call. [Operator Instructions] Please be advised that today's conference is being recorded.
I would now like to hand the call over to Andy Nowinski, Vice President of Investor Relations and Strategic Finance. Andy, please go ahead.
Good afternoon, and thank you for your participation today. With me on the call are George Kurtz, Chief Executive Officer and Founder of CrowdStrike; and Burt Podbere, Chief Financial Officer.
Before we get started, I would like to note that certain statements made during this conference call that are not historical facts, including those regarding our future plans, objectives growth, including projections and expected performance, including our outlook for the second quarter and fiscal year 2027 and any assumptions for fiscal periods beyond that are forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995. These forward-looking statements represent our outlook only as of the date of this call. While we believe any forward-looking statements we make are reasonable, actual results could differ materially because the statements are based on current expectations and are subject to risks and uncertainties. We do not undertake and expressly disclaim any obligation to update or alter our forward-looking statements, whether as a result of new information, future events or otherwise.
Further information on these and other factors that could affect the company's financial results is included in the filings we make with the SEC from time to time, including the section titled Risk Factors in the company's annual and quarterly reports.
Additionally, unless otherwise stated, excluding revenue, all financial measures disclosed on this call will be non-GAAP. A discussion of why we use non-GAAP financial measures and a reconciliation schedule showing GAAP versus non-GAAP results is currently available in our earnings release, which may be found on our Investor Relations website at ir.crowdstrike.com or on our Form 8-K filed with the SEC today.
With that, I will now turn the call over to George.
Thank you, Andy, and thank you for joining CrowdStrike's Q1 FY '27 Earnings Call. We started our fiscal year in an environment where cybersecurity has dramatically risen in organizational visibility and funding priority. CrowdStrike is now being understood as critical AI infrastructure. Frontier AI Lab started a new chapter in the AI revolution. New model releases starting in April, connected AI innovation with cybersecurity necessity. CrowdStrike was the only cybersecurity company selected by both Anthropic and OpenAI from the very start to secure these new models, their adoption and the new risk they create.
Today, AI adoption is not a nice to have, it's an existential imperative across every geography and vertical. The more AI an organization adopts the more cybersecurity it requires. In this new agentic era, we're now guiding net new ARR acceleration for the full year. Q1 highlights included: one, record Q1 net new ARR of $256 million up 32% year-over-year and exceeding the high end of our guidance; two, ending ARR of $5.51 billion, accelerating over our record Q4 and more than 24% growth; three, total revenue of $1.39 billion, up 26% year-over-year, beating guidance and accelerating for the fourth consecutive quarter; four, all-time record free cash flow of $468 million or 34% of revenue, exceeding our expectations, our free cash flow Rule of 40 was 59 increasing for the fourth consecutive quarter.
Five, record Q1 operating income of $326 million or 24% of revenue, up 62% year-over-year, exceeding guidance; and six, we added over 300 Falcon Flex accounts in the quarter with accounts that have adopted this subscription model reaching more than $1.9 billion in ending ARR growing 99% year-over-year. These data points illustrate momentum, traction and achievement. It's on the backs of our strong Q1 results and the unprecedented market dynamics I see that we are raising our growth expectations for the full year net new ARR by more than 500 basis points.
For the full year, we now expect net new ARR growth to accelerate over FY '26. What I see is AI driving structural demand for cybersecurity that compounds not decelerate. The AI enterprise unfolding in real time and CrowdStrike is a necessity to secure it. AI's technology progression has unfolded in waves. Wave 1 of AI adoption was about making information rapidly accessible and foreshadowing the power of reasoning using existing data points to connect new dots. Wave 2 of AI adoption started with the agent, transforming what was once a basic web experience into a rich connected and human-like digital worker. Agents became a major unlock moment for the enterprise, opening the door to productivity gains and augmentation of human workers. The concept of the Agentic workforce was born and for the first time, enterprises could start pointing to economic value creation and newfound outputs from the AI revolution.
This brings us to Q1 right in the middle of Wave 2, the wave of agent creation. In April of Q1, more happened in a matter of weeks in cybersecurity than in the whole year prior, the Mythos inflection moment. In collaboration with Anthropic from the start, we saw a new model emerge that had relevance for the cybersecurity market, relevance for defenders in identifying vulnerabilities much faster than before, including the chaining of multiple vulnerabilities to create lethal cyber attacks. Project Glasswing brought together CrowdStrike and a focused group of consequential companies to ensure market readiness for Anthropics new model.
Shortly thereafter, OpenAI announced GPT 5.5 cyber later known as Daybreak, where we were selected as a founding member of their trusted access for cyber program. CrowdStrike is the only cybersecurity company to secure both Anthoropic and OpenAI's introduction programs from the very start. What the Mythos moment proved is that the world, starting from the Frontier AI labs themselves realize that AI needs a cybersecurity ecosystem. This was a Mythos inflection point. The discussion evolved from is AI going to disrupt cybersecurity to organizations and even the Frontier AI labs relying on Falcon as their AI-powered Defender for the post Mythos era. Even more consequential is how adversaries can use these new and future models to democratize destruction.
Now any human or agent can be a [indiscernible] or worse wage serious cyberattacks that threatened enterprise survival, nation-state continuity and critical infrastructure operations. AI has now directly entered the world of cybersecurity across 2 dimensions. One, you need cybersecurity to secure AI itself, deploying AI across the enterprise is simply too risky without cybersecurity from the start. Cybersecurity is now foundational AI infrastructure; and two, an explosion in greenfield attack surfaces each of which needs cybersecurity. The AI revolution has led to a boom in one, hardware, GPUs, MPUs, GPUs and training chips; two, data centers and hyperscalers, training and housing AI models; three, neo-cloud, a whole new class of cloud focusing on inference; four, token factories, we're seeing unprecedented eye-watering demand for Anthropic and OpenAI; and five, agentic applications a whole new class of identic tools such as Cursor, Sierra, [ 11 Labs, Exa, Lagora ] and more.
The inflection point is that every player in this value chain is experiencing hypergrowth in every one of these technologies need cybersecurity. The Mythos moment crystallize the reality for the market and for the first time in my career, the market's view of cybersecurities role has shifted from being viewed primarily through the lens of risk management, compliance and protection to being recognized as a strategic accelerator and a critical enabler of AI adoption.
Here's how we're seeing this shift manifest across our ecosystem, customers and business. As soon as Project Glasswing and Mythos were announced, a deluge of customer prospect and partner inquiries followed. Post Mythos threat landscape readiness reached a fever pitch with the primary question being, is my organization protected. The immediate focus turned to uncovering and remediating vulnerability susceptible to being weaponized by new models. Answering this question across tens of thousands of organizations created an opportunity to showcase the power of our platform and ecosystem. Within days of Anthropic's Project Glasswing and open AI [ TAC ], we announced Project [ Quito ] to unite and mobilize the industry around Mythos readiness. Footworks is a phased process of vulnerability discovery, prioritization, remediation and then executive communication, [indiscernible] protected conversations at executive and Board levels quickly became opportunities to leapfrog legacy point-in-time vulnerability discovery. The answer became real-time, continuous discovery and remediation.
This conversation plays right into the strength of Falcon's continuous exposure management solution and Falcon for IT, both of which saw adoption nearly double year-over-year in the quarter. We saw immediate interest from our ecosystem to join our coalition. After the announcement of Project [ Quite Works ] Accenture, EY, IBM, Kroll and OpenAI joined us to use the latest OpenAI and Anthropic models for [ Quote Works ] engagements. And a few weeks later, we expanded the coalition to include [ Armin, Cognizant , HCL check ], Infosys, KPMG, NTT Data, Tata Consultancy Services and WiPro and more recently, insurers such as Coalition, Liberty Mutual Insurance, [ Lockton Resilience ] and [ Marsh ] joined the coalition to start underwriting Frontier AI model risk to the enterprises they serve.
[ Quote Works ] engagements include EY engaged with a Fortune 100 account and uncovered more than 45 million vulnerabilities, leveraging Falcon Exposure Management and Frontier models, and the engagement is also accelerating Next-Gen SIEM adoption within this account. Kroll, who recently replaced their incumbent next-gen endpoint vendor with CrowdStrike brought us into a clothing manufacturer, which is becoming a new logo account on the back of a [ Quote Works ] assessment. [ QuoteWorks ] is how we're preparing the market for cybersecurity's Y2K moment with CrowdStrike as the key security control for AI deployment. Footworks and the AI accelerated demand environment are delivering growth across the business.
In Q1, we delivered innovation and saw a pronounced demand across the following platform modules. First, endpoint, our endpoint business again accelerated for the third consecutive quarter, the endpoint has become the epicenter of where AI happens and our best-in-class efficacy sets us apart. The rapid adoption of AI tools like [ Quad Cowork ] and codecs have dramatically expanded the endpoint attack surface. Our endpoint leadership continues to widen with Gartner naming as a leader for the seventh consecutive year and storing us the very highest both axis of the Magic Quadrant, ahead of all other participants for the fourth year in a row.
Today, we're seeing 2 new phenomena on the endpoint. First, AI's rapid evolution has created renewed enterprise focus on endpoint security investment. Second, nonhuman identities and agents require their own underlying host, creating greenfield demand for sensors, we're already seeing companies deploying agentic workloads inside virtual machines, each requiring its own sensor. Illustrating this was an 8-figure new logo land in a major U.S. government agency. We replaced a legacy AV and operating system EDR and a legacy vulnerability management point product across more than 200,000 hosts, and that unlocks what's next.
We pioneered EDR. We have the endpoint real estate, and that gives us the structural advantage to own what we're bringing to the market, AIDR, AI detection and response. AIDR is quickly becoming a new growth pillar in our business with ending ARR growing more than 250% sequentially and Q2 pipeline already exceeding $50 million. We went from 0 to this in under 2 quarters. In my career, I've never seen adoption happen this fast. As I look forward, I see AIDR as a larger opportunity than EDR. Here's why.
First, our structural advantage. We built EDR because the endpoint is where attacks execute, and you need a sensor there to see them. The same is true for AI. Agents run on the end point. They make tool calls, access files in both APIs and move data at the process level to detect and respond to AI threats in real time, you need a runtime sensor where AI executes. That's Falcon. While competitors may provide AI visibility, only CrowdStrike can detect, block and respond where AI actually runs, the pattern that made EDRs repeats.
Second, the AIDR market opportunity is structurally larger. EDR secured one attack surface, the host. AIDR secures 7 data, models, prompts, agents, identities, infrastructure and the interaction layer where they converge. Worldwide spending on AI is forecasted to total over $2.5 trillion and only a low single-digit percent of organizations have an advanced AI security strategy. The gap between AI adoption and AI protection is the widest asymmetry in security since the cloud transition, and it's moving faster. We're already converting the demand and automotive financial services leader added AIDR to more than 30,000 hosts for shadow AI visibility and protection in a 7-figure win, greenfield opportunity, seamless upsell, same sensor.
Moving to Next-Gen SIEM, Cloud and Identity. We saw a record Q1 net new ARR from the combination of these businesses. Combined, these businesses have now exceeded $2 billion in ending ARR. Our Next-Gen SIEM business exceeded $600 million in ending ARR and has transformed CrowdStrike into the operating system of the AI SOC. Charlotte AI, where ending ARR accelerated sequentially over Q4 is now the reasoning engine across Falcon. Triaging alerts, correlating cross-domain telemetry and automating investigation at machine speed. This quarter, we expanded that vision with [indiscernible] Works, our ecosystem of purpose-built AI agents built on the Falcon platform. Partners, including Accenture, AWS, Anthropic, Deloitte, NVIDIA, OpenAI and Salesforce are building specialized security agents that operate natively on Falcon data. The result of security operations center that runs at AI speed, orchestrated by Charlotte extended by the ecosystem and grounded in the richest telemetry in the industry.
A key Next-Gen SIEM win was an 8-figure new logo land in a major fuel retailer. CrowdStrike was selected to replace a legacy SIM, a next-gen EDR and stitch together software from a network security hardware vendor. The performance and price superiority of Next-Gen SIEM, combined with Charlotte AI's autonomous triage eliminates swivel chair alert management successfully starting this customer's AI SOC journey. Cloud had another strong quarter as enterprises continue securing their AI infrastructure. concern around elevated risk from new frontier models has pushed customers to harden their cloud environment. An 8-figure win in a high-performance AI chip company allowed this customer to secure the rapidly expanding Kubernetes managed data center and cloud environments in the wake of the AI boom.
Next-Gen Identity net new ARR growth accelerated versus Q4. In the AI era, every agent needs an identity, every identity needs governance and every enterprise is realizing they can't tell a human from machine in their environment. Falcon Shield had another stellar quarter with ending ARR growing nearly 4x year-over-year as organizations secure their SaaS agentic attack surface. Our recently acquired Signal Solution and our fast-growing privileged access offering are boasting strong early demand as enterprises lock down what agents can do and access. A major American health care company selected Falcon Next-Gen Identity and Signal in a 7-figure expansion to solve a problem that simply didn't exist 2 years ago, governing what AI agents can and cannot do across the enterprise.
Signal delivers granular, policy-based authorization over agentic workloads in real time. This is the identity opportunity in the AI era. Falcon Flex is how we go to market. with accounts that have adopted the subscription model rapidly approaching $2 billion in ending ARR. The most exciting part is the re-flex dynamic customers renewing and expanding their investment beyond their first Flex contract with highlights including the number of re-Flex customers reached 480, representing nearly 25% of all Flex customers. The average re-Flex uplift was 26% with the average re-Flex happening in 7 months, well ahead of their subscription renewal date and the most compelling over 130 customers have re-Flex multiple times with the average ARR uplift over their original Flex coming in at 51%.
Customers are coming back multiple times and they're continuously spending more, consolidating on CrowdStrike. This is the power of the platform in action. To secure AI organizations need the Falcon platform to deliver the platform you need the right go-to-market model. Flex is the commercial harness to drive secure AI adoption.
In closing, I'm proud of the start of our year. Q1 was another beat and as the quarter progressed, we saw the Mythos inflection point. The world of cybersecurity and Frontier AI collided. The result is that Frontier AI needs the very best defender and that's CrowdStrike. The inflection is now the need for cybersecurity to defend AI is nonnegotiable. CrowdStrike is not only in the right place at the right time, we're the right technology to stop the breach. Think of CrowdStrike as the picks and shovels for the world's largest technology gold rush of all time.
CrowdStrike is in the prime position to be the world's AI security layer with nearly 100,000 businesses, including hundreds of the Fortune 500 already trusting us to secure their organizations. Our ecosystem of thousands of partners are looking to us the answers on how to secure AI at global scale. This is even bigger than customers and partners. The market's very best AI talent seeks out CrowdStrike to join our mission. I'm excited to announce [ Dr. Bartley Richardson ] joins my leadership team as Chief AI and Autonomous System Officer. He joins CrowdStrike from a long-time strategic partner, NVIDIA, where he led agentic AI and cybersecurity AI. [ Bartley ] deepens our NVIDIA collaboration and furthers our verticalization of AI into cybersecurity. The best AI talent in the world is choosing to build at CrowdStrike.
In this inflection moment, I see CrowdStrike's opportunity larger than ever before. The technology is here, the talent is here and the market opportunity is here. We're raising our full year net new ARR guidance by more than $50 million. We now expect full year net new ARR growth to accelerate over last year. At $5.5 billion in ending ARR, we are accelerating. We see this as the AI tailwind in action.
Given the strength of this quarter and our confidence in what's ahead, I'm announcing CrowdStrike's first dock split as a public company. We'll be doing a 4-for-1 stock split making CrowdStrike more accessible for investors to join our mission. Cybersecurity isn't a nice to have in the world of AI. It's a need to have. And CrowdStrike is the innovator of choice, the partner of choice and the protector of choice for this new accelerated AI world. Thank you for your trust.
I'll now turn the call over to Burt Podbere, our CFO.
Thank you, George, and good afternoon, everyone. As a quick reminder, unless otherwise noted, all numbers except revenue mentioned during my remarks today are non-GAAP.
We delivered strong first quarter results to begin the new fiscal year, exceeding expectations across all guided metrics. We achieved record Q1 net new ARR of $255.8 million, up 32% year-over-year driving ending ARR to $5.51 billion, accelerating growth to more than 24% year-over-year. As George outlined, the Mythos moment marked an inflection point for the industry, confirming that cybersecurity is not just foundational to AI adoption, it is critical AI infrastructure.
Our Q1 results and FY '27 outlook reflect the very beginnings of this technology wave with broad-based momentum fueled by customers consolidating their security needs, lowering their total cost of ownership and accelerating AI adoption with CrowdStrike as their security foundation. This strength is reflected in our continued strong retention rates, increased module adoption, third consecutive quarter of ending ARR growth acceleration for the endpoint business and Q2 record pipeline. Additionally, we closed the acquisitions of Signal and [ Surafic ] in the first quarter, contributing a combined $7.8 million of acquired net new ARR, which was within our stated expectations of $5 million to $8 million.
Moving to the P&L. Total revenue exceeded our guidance range and grew 26% over Q1 of last year to reach $1.39 billion, with year-over-year growth accelerating sequentially for the fourth consecutive quarter. Subscription revenue grew 26% over Q1 of last year to reach $1.32 billion, and professional services revenue remained strong at $64.8 million up 23% year-over-year, driven by the elevated threat environment. The geographic mix of first quarter revenue consisted of approximately 66% from the U.S. and 34% from international geographies with EMEA and overall international year-over-year revenue growth accelerating compared to Q4.
Total non-GAAP gross margin was our Q1 record 79% and non-GAAP subscription gross margin was a Q1 record 81% of revenue, up 90 basis points over the prior year driven by continued cloud optimization. First quarter non-GAAP operating income was a Q1 record $325.7 million, and non-GAAP operating margin was 24% up 530 basis points over the prior year and exceeding our guidance. The outperformance was driven by our strong top line performance gross margin improvement and increased operating efficiency, underscoring our commitment to durable profitable growth.
In Q1, we once again delivered positive GAAP net income attributable to CrowdStrike of $27.8 million. Non-GAAP net income attributable to CrowdStrike was a Q1 record $283.4 million or $1.10 on a diluted per share basis, exceeding our guidance.
Moving to cash. Our cash and cash equivalents were $4.55 billion. We generated record cash flow from operations of $590.9 million and record free cash flow of $468.5 million or 34% of revenue. In Q1, we repurchased $176 million of shares outstanding at an average price of $365.63. We now have approximately $1.3 billion remaining under our share repurchase authorization. We will remain opportunistic in returning capital to shareholders as we remain focused on capturing the significant growth opportunities ahead of us.
Finally, as George mentioned, we are announcing a [ 4:1 ] forward stock split to make ownership of CrowdStrike stock more accessible to investors. Stockholders of record after the close of market on June 25, 2026 we'll receive an additional 3 shares of common stock for every 1 share held after the close of market on July 1, 2026, with trading on a split-adjusted basis expected to commence at market open on July 2, 2026.
Moving to our outlook and modeling notes. Our record Q2 pipeline and strong momentum across competitive displacements Falcon Flex adoption and platform consolidation give us conviction in the durability of CrowdStrike's growth trajectory, profitability expansion and cash flow generation. As George outlined, AI adoption has become an existential imperative, and it requires cybersecurity. CrowdStrike provides critical infrastructure that enterprises need to adopt AI safely and at scale. Our broad business momentum and the accelerating AI tailwind we see are reflected in our raised FY '27 outlook.
We now expect FY '27 net new ARR growth to accelerate over FY '26 with year-over-year growth of 27.7% at the midpoint, a 520 basis point increase in year-over-year growth from our prior guidance translating to an increase of $52 million to $1.291 billion of net new ARR. Given our Q1 net new ARR outperformance and increased outlook for the full fiscal year, we now expect FY '27 net new ARR seasonality to be approximately 42% in the first half and 58% in the second half.
Moving to cash. At the midpoint of our guidance, we expect free cash flow margin of 24.5% in Q2, our seasonally lowest free cash flow quarter and continue to expect at least 30% for the full fiscal year on our increased revenue guidance. As a result of our outperformance in Q1, we now expect the seasonal mix of free cash flow dollars between the first and second half to be 46% in the first half and 54% in the second half.
For the second quarter of FY '27, we expect annual recurring revenue to be in the range of $5.793 billion to $5.795 billion, reflecting a year-over-year growth rate of 24% translating to net new ARR of $284 million to $286 million, reflecting a year-over-year growth rate of 28% to 29%. We expect total revenue to be in the range of $1.436 billion to $1.442 billion, reflecting a year-over-year growth rate of 23%. We expect non-GAAP income from operations to be in the range of $346 million to $349 million and non-GAAP net income attributable to CrowdStrike to be in the range of $301 million to $303 million. We expect diluted non-GAAP net income per share attributable to CrowdStrike to be approximately $1.16 to $1.17 utilizing a 21% tax rate and weighted average share count of approximately 258 million shares on a diluted basis.
Adjusted for the stock split, we expect diluted non-GAAP net income per share attributable to CrowdStrike to be approximately $0.29, utilizing a weighted average share count of approximately 1.034 billion shares on a diluted basis.
For the full fiscal year 2027, we expect annual recurring revenue to be in the range of $6.532 billion to $6.556 billion, reflecting a year-over-year growth rate of 24% to 25% and translating to net new ARR of $1.279 billion to $1.303 billion reflecting a year-over-year growth rate of 27% to 29%. We expect total revenue to be in the range of $5.915 billion to $5.959 billion reflecting growth rate of 23% to 24% over the prior fiscal year. Non-GAAP income from operations is expected to be between $1.452 billion and $1.480 billion. We expect non-GAAP net income attributable to CrowdStrike to be between $1.263 billion and $1.285 billion. Utilizing a 21% tax rate and approximately 259 million weighted average shares on a diluted basis we expect non-GAAP net income per share attributable to CrowdStrike to be in the range of $4.88 to $4.96. Adjusted for the stock split, we expect diluted non-GAAP net income per share attributable to CrowdStrike to be approximately $1.22 to $1.24 utilizing a weighted average share count of approximately 1.036 billion shares on a diluted basis.
George and I will now take your questions.
[Operator Instructions] Our first question comes from Meta Marshall with Morgan Stanley.
2. Question Answer
Great. George and Burt, you noted a lot of tailwinds for the business as customers invest in AI. Can you just unpack which of those are the biggest near-term drivers that prompted you to meaningfully raise the net new ARR guidance for both Q2 and the full fiscal year?
Sure. Thanks, Meta. The first we drive demand for us in terms of the tailwinds of the AI tailwinds that George talked about in his prepared remarks. But then you look into other things that really give us confidence in terms of raising the guide. One is basically the strong module adoption rates that we have, the strong gross and net retention rates that we have. And of course, our strong Q2 record Q2 pipeline. And then you can throw in the Mythos moment, which created an inflection point around ARR for our business. So you combine all those things that gave us confidence for both the Q2 guide as well as the full year guide.
Our next question will come from Saket Kalia with Barclays.
Okay. Great. Great to see the raised net new ARR for the year. George, maybe for you related to that point, can you just give us a little bit of color on when you started to see that inflection in demand related to what I think we called the ethos moment. I'm curious how it's sort of unfolded here from a timing perspective?
Yes. Thanks, Saket. It actually started RSA just at the end of March, which is slightly before Mythos. And every meeting that we had with customers was all about protecting AI and providing visibility into things like shadow AI. We talked about the inflection point in endpoint and the acceleration. And obviously, there's a lot of customers that want to deploy more but they're actually being held back because they don't have the right visibility, security controls around everything from identity to data protection to MCP type services. So every meeting was literally the same meeting all over on help us protect these AI workloads that are running on the endpoints. And all the developers are running it, marketing is running it, accounting is running it. We heard just crazy stories about AI run amok.
And the biggest thing for me when I ask what outcome the customer is looking for. It wasn't a technology outcome per se, it was we need to solve the security issue because we want to deploy AI faster. We want to go faster in our business, and our CEO is demanding the adoption of AI. We can't do it securely. So that was a kind of a lifeful moment, obviously, or an inflection point in RSA. And then you combine that with Mythos in April. And I mean the -- literally, the thousands of interactions that we've had with customers on Mythos and briefings and our project [ Footworks ] has been incredible. So you kind of put all that together, and you've got a real inflection point in the market.
Your next question will come from Brian Essex with JPMorgan.
Thanks, everyone. Likewise, great to see the pretty impressive net new ARR increase in recent guide. George, would love to pick your brain a little bit. We've been hearing that security has been gaining budgets outside of traditional IT and security budgets, maybe around RSA. And then after Mythos release, was released. It seems as though we have a bit of panic spending, which we're seeing a lot in the consulting industry, and it sounds like everyone is seeing it in their pipeline.
But would love your sense of where the money is -- where do you think the money is coming from? How much of the current AI tailwind might be incremental security spend? And how much is maybe a reallocation of existing budgets towards vendors perceived as more AI native and where is the money coming from within, what I would imagine are relatively set budgets for the year?
Yes. I think you have to look at just a crazy inflection point in the adoption of frontier type models, right? And we've all seen the revenue curves with the big players that are out there. So we're tending to follow the slope of that adoption curve. And the token spend has been just jaw dropping. And when you have that level of adoption, you're going to have incremental funding around security. I think if we look at this realistically 2 years ago, there wasn't these big token budgets, right? All of a sudden there is and people are finding money and it's incremental, and they need to adopt more of it. We have plenty of companies that are tracking token usage not only from the spend standpoint of what are they spending, but they want to know who's spending it, are they spending it enough? Are they going fast enough.
So we've seen it being incremental. And at the end of the day, getting back to something I've said time and time again. If you want to create AI, you need GPUs, if you want to use AI, you need security, and that's what we're finding.
Your next question will come from Gabriela Borges with Goldman Sachs.
George and Burt, I want to ask you a little bit about the modules in your business where you price based on consumption. I think there might be a little bit of that in your Next-Gen SIEM business maybe in the cloud business as well. What I want to ask you is, are you seeing a change in or a step function change in the amount of ingestion, data injection, cloud workloads, that sort of dynamic either because of agentic activity or because perhaps the amount of agentic threats that customers have to deal with has gone up in the SOC. And I'm wondering because of the structural advantages you have on the cost and performance side in Next-Gen SIEM, can that now create an additional motion for you to have success in the Next-Gen SIEM product.
Well, when we think about the agentic world, it's all about data, and that's been a foundational element of CrowdStrike since my starting of the company. If you have the right amount of data, you can sell most security use cases. And in today's world, it's all about creating data, using that data for training, instrumenting the agentic SOC. And that's why we've seen incredible adoption in our Next-Gen SIEM. We've seen workloads increase in the cloud. We've seen companies where in the past, they may not have put as much data into their SIEM just because of a legacy provider and sort of the cost model.
And given the disruptive nature of our SIM pricing, it's all part of our platform, and we're really charging for third-party ingest, it's been a real win for customers. So we're seeing more and more adoption broader and we're able to cover use cases that weren't covered in the past just given sort of the economics of how we go market with it. So I think there'll be more tailwinds. And again, there are a lot of customers now that are using that data with our own AI agents that we provide on the platform, and they're getting incredible outcomes. So the data gravity and the data moat that we talk about is obviously here. It's been here, and it's only getting bigger given the nature of AI.
Your next question will come from Matthew Hedberg with RBC.
George, you mentioned your Script Cloud Security had another strong quarter. I guess I'm curious with the rise in AI demand, how is cloud security impacted by AI? And what are you seeing in terms of either competitive displacements or win rates in the segment?
Well, yes, it's a good question. And when you think about cloud security for a long time, it was about posture management. In the AI world, it's really about runtime protection and control because you're seeing out these AI workloads being hosted in the cloud, right? And these containers that have agents that are long-running agents, right? And they're being spun up with a certain level of control, and they need the run time enforcement that we bring to it, which is a real strategic advantage for us. So that has certainly played into our favor.
And then you combine that with the ability to understand sort of SaaS posture for cloud providers and some of the attack vectors around those SaaS providers. It's been just a very I would say, a bright spot for us given the full nature of the cloud stack that we've been building over many years.
Your next question comes from Rob Owens with Piper Sandler.
Great. Andy, thanks for the question, George and Burt. George, another seminal cyber event here in our careers, but definitely probably lending to a greater step function than we've seen historically in terms of the opportunity. And so given the events of the last couple of months, how are you thinking about your business in general and where you might lean in to take advantage of it? Obviously, you've been building out the product set. But given the greater sense of urgency? Are there things you're contemplating from packaging, pricing, further M&A to really go after this opportunity is seemingly is exploding from a demand perspective.
Well, I guess, I mean, I'll start with the Flex model itself, and it's something that we put in for a few years now, and we're all seeing the benefits of the Flex model in terms of taking advantage of helping customers in these Mythos moments. There are many technologies that are rapidly evolving in an enterprise, and they all need protection. A lot of them obviously is sent around AI.
I think we've done a good job from an acquisition perspective. I think we've been very strategic in getting companies that fit within our portfolio. Again, we spent a lot of time on the integration, which is something customers recognize and reward us for and will continue to be acquisitive. We're always looking at companies. Again, we tend to buy tech and great teams and spend a lot of time on the integration. But I think there's just a lot of areas in AI that are rapidly emerging and we continue to monitor that market, and we'll continue to build it organically as we have.
And inorganically as we round out the entire portfolio, specifically in that area. You've got data protection. We continue to invest in those areas. You've got Falcon for IT. We've seen just incredible progress in replacing some of the larger incumbents in that market. So where we need to, we'll augment that with acquisitions, and we continue to be a company that drives innovation organically as well.
Your next question will come from Josh Tilton with Wolfe.
George, maybe for you, I thought it was very interesting in the prepared remarks. You mentioned how things were just moving so fast in the month of April. I'm just trying to understand, was there any delayed spending or decision-making that maybe changed the net new ARR seasonality relative to what you guys were initially thinking 90 days ago. And I'm just asking because I'm trying to reconcile the incredibly impressive raise and understandably so kind of to the beat that you saw in the quarter.
Well, I'll start and I'll turn it over to Burt. But as I mentioned earlier, you kind of look at March and RSA is a real inflection point. And you have to look at sort of the adoption of things like [ quad co ] just exploded. I mean I think everyone knows the numbers there, right? So seeing this massive adoption very quickly of AI agents, and that really kind of took place, I think, in earnest towards the end of March. And then the Mythos moment was in April and then obviously, just incredible demand from that standpoint that we saw. And obviously, you're seeing it in the forward guidance and the rate.
So Burt, do you want to add to that?
Yes. So for sure, I mean, all the things that George said, it all came down to just our record Q2 pipeline. That gave us the confidence as we looked out into the full year. It gave us confidence in terms of how we saw the business, the momentum in the business. And as I look at Q1, and I remark on Q1, I look at the 32% year-over-year growth rate for net new ARR. That's an impressive number.
Then you go to the cash, our record cash -- free cash flow and you look at our rule of 59, which is impressive at our scale. So you look at all those things combined, and that gives me confidence in terms of the raise that we looked at for the year.
Your next question will come from Joe Gallo with Jefferies.
I've got a 2 part on agentic identity. This is clearly a huge need that all CSOs know they have. But at the same time, companies aren't really deploying security there. What is causing that? And what's the catalyst that can revert that? And then just two, can you talk a little bit more about your product positioning in identity outside of ITDR, especially now with Signal in the fold and just the right to win that agentic identity market.
Yes. I mean we've been in the identity market in some segments since 2020. And we've built a great business there, one of the largest pure-play security identity businesses around. And what are we seeing? Well, obviously, with what we've built, the organic evolution of the products and now combined with Signal we've got an incredible opportunity in front of us. Just Signal alone, we've got customers who are using it for nonhuman identities and they're getting incredible results. And I met with a customer at RSA, became a 2-time customer. This particular gentleman left one company that was a Signal customer. And the first thing he did was to get Signal as next company, which we called out in the prepared remarks.
And I asked him, I said, "What do you like? What works? Why you hear so quickly for your second time around?" He said, "It would take him 2 weeks to get an identity up and running and now it takes them like 2 minutes." And the amount of just efficiencies that he was able to provide is incredible. And what we're seeing right now, and we're working with customers right now on this is using a Signal as the identity control plane combined with our AIDR. So we see a fantastic opportunity. And remember, we're not saddled with legacy technology and sort of patchwork of things that we have to deal with, with respect to sort of vaulting, right? Customers want a new, they want a fresh approach of 0 standing privileges and we have it, and it works in the agentic world. So we feel really good about this acquisition and our Identity business.
Your next question will come from Roger Boyd with UBS.
Great [indiscernible] for the question. George, I wanted to come back to AI detection response and a pretty impressive pipeline and color you provided on that product. From a higher perspective, relative to that $2.5 trillion forecast AI market, how are you thinking about the TAM for AIDR? And then a few months ago, it felt like this is a pretty early market. I guess can you talk about with these early deals what you're seeing from a competitive perspective? What's giving you the right to win here?
Yes. So Roger, I think when you look at this market now and the TAM, I think, is going to be very large. I called out in my prepared remarks, I think it's going to be larger than EDR. And the reason why I think that is from an EDR perspective, we're protecting machines and workloads and such. In the agentic world, on average, and this an industry stat, there will be 90 agents per employee. So when you look at all of those agents that need protection, this is what gives me confidence that it is going to be a bigger market than EDR. And why do we have a right to win? Well, we've pretty much created the EDR category. We're the #1 pure-play player in that category. And customers already have what they need. They already have the agent. They already have visibility into what's happening. And we've created some incredible advancements that gives like unparalleled visibility to what's happening at the agentic layer. And we're working with some of the biggest companies on the planet now.
In preview mode on some of this technology in addition to what we already have in the market. So as a leader in EDR, it is a natural evolution where customers have said, we need this to protect our agents, and we are there to meet them in the market. So for me, it's one of the most exciting times since when I started the company because it really is just an incredible moment to be in security. And given all of the fast-moving tailwinds of AI, I think we're perfectly positioned.
Your next question will come from Eric Heath with KeyBanc.
Can you hear me okay?
Yes.
George, as the security industry starts to embrace and leverage these frontier models to deliver products and services as you've done, do the pricing models need to move to more of a token-based pricing model? Just how do you see this evolving?
Well, it is an evolving market. And the great news is that Falcon Flex license already contemplates that. Remember, Flex is a commitment model, but it has the ability to use tokens, use credits, things of that nature. So I think we're in a great spot because we've done the hard work of getting these Falcon Flex licenses in place. We've got customers who already committed massive dollars to it.
And then as it evolves, we can easily add token consumption into the model. And that's certainly something that we may do in the future. But obviously, it's moving pretty quick and we want to make sure that we get it right. We want to make sure we meet customers where they want to be met where they've got a level of flexibility but also a level of certainty around the spend. And I think as a company, we've done a good job to help provide that to our customers, which is why you've seen the adoption around Flex.
Our next question will come from Fatima Boolani with Citi. Well, we'll go to our next caller, and we can check back in with Fatima. So our next question will come from John DiFucci with Guggenheim Securities.
Thank you. George, a question for you. You said the gap between AI adoption and AI protection is the widest asymmetry in security since the cloud transition. You also talked about an inflection in the market, which implies some incremental business, and that's your results look good, and that's reflected. But it seems like that's more about interest and intent and it sounds like we're still really early in this journey for enterprises.
So my question is, like, where are we in the actual adoption of AI in the enterprise. Our enterprise is still trying to figure out how to harness its power and stepping in lightly or are they actually really starting to deploy it broadly. And I guess, more importantly, as it pertains to CrowdStrike because I don't think they are necessarily going to be aligned where are enterprises in their journey of adoption of security for AI?
Well, yes, John, let's start from the top. It's still the early innings, as you might imagine, in AI adoption, but you have to look across an enterprise where they've gone deep very quickly, obviously, around developers first, and then they're moving into other areas. So depending on the industry, depending on the company. But certainly, in the developer world, just since January and the evolution of some of the models and the harnesses that they've created to actually get worked on, you've just seen incredible adoption very quickly. And that, like many other technology sort of inflection points, the adoption front runs the security piece of it. And that's why so many CSOs and CIOs CEOs are calling us saying, we need something to keep up with the adoption of security. We wanted of AI. We want to go faster, and we need something like CrowdStrike and AIDR. So we're still in the early innings.
The other thing I will point out, even when you look at our pipelines and the things that Burt talked about is the AI adoption isn't all enterprise-wide yet. And it's almost like the early days of EDR, where someone would adopt it in a division or geography or something. We're still in those early innings, and we're seeing incredible pipeline. So once it goes really mainstream and entire companies adopted across all of their employees and workloads, again, I think you're going to see just another incremental increase in opportunities there.
Your next question comes from Gregg Moskowitz with Mizuho.
George, as you know, the U.S. government just announced an executive order to upgrade systems for advanced AI, can you talk about the role that you expect CrowdStrike to play here? And then maybe for Burt, how, if at all, is this being reflected in your guidance?
Yes. So I mean, first, let me commend the administration for calling out the need for AI security. And I think the White House struck an appropriate balance here. And we're certainly excited and we'll continue to engage. We've been very active in D.C. We work very closely with various groups, administration, et cetera. And I think this is a good thing.
When you look at AI and how important it is for the future of the federal business and the security of the country, is something that you really have to get right. And I think the executive order will create a tailwind ultimately for businesses like CrowdStrike because these federal governments are going to need to expedite prioritize cyber defenses in a more modern way. And you have to keep in mind that when we think about this, cybersecurity is national security. And it's incredibly important, we're at the epicenter there, we will continue to engage, and we're happy to be part of those efforts as they unfold.
Your next question comes from [ Michael Turrin ] with Wells Fargo Securities.
I appreciate you taking the question. I want to go back to just the shape of what you're seeing and how it shows up in the model. The 1Q ARR was strong, but a bit closer to the guide, especially relative to how the full year numbers went up. So I know, George, you've mentioned the post Mythos moment multiple times. Maybe speak to the sequence of what you're expecting for rest of the year in terms of pipeline progression and Burt, maybe you can just also touch on how we should think about the visibility you have into the ARR guide for the rest of the year versus what would drive further upside?
Yes. So I'll start and turn it over to Burt. But when you look at AIDR, I mean, it's 250% quarter-over-quarter up with a $50 million-plus pipeline and that's only growing by the day. I mean the EB -- our executive briefing centers are full with companies that want to be talking about Mythos, how to protect AI. Every conversation, every rep, every -- you name it. And we've done a tremendous amount of executive and Board briefings because Mythos this is from the back room to the boardroom. I can tell you, CEO after CEO, who called their CISOs on the weekend saying, is this thing really a problem? What does it mean for us? How do we protect theirselves? What does it mean going forward? And it really is a Y2K moment for security. So that's -- we look at the upcoming year in the guidance and it reflects that sort of momentum that we've seen in the pipeline.
Yes, I think that's exactly right. So for us, again, we're getting that confidence from all the fundamentals in the business. We're getting the confidence from all the conversations we're having with our customers, what George talked about with the Mythos moment and there's not a conversation that isn't happening from our largest customers down to our smaller customers about how are we going to protect our AI.
Look, I think the world is looking to us to be an accelerant for AI deployment because CISOs all over the world are the ones that have to kind of be the roadblock in terms of deploying all of the AI, but they can't do it unless they know that they are the proper guardrails in place, and that's where they look to CrowdStrike. So based on all of that, I got confidence in the full year guide as well as the Q2 guide.
Thank you. This concludes today's question-and-answer session. I would now like to turn the call back over to George Kurtz for closing remarks.
I want to thank everyone for their time today. We certainly appreciate your continued support and look forward to seeing you at our upcoming events. Thanks so much and see you soon.
CrowdStrike Holdings Inc — Q1 2027 Earnings Call
CrowdStrike Holdings Inc — Q1 2027 Earnings Call
CrowdStrike reported a strong Q1 beat, raised full-year net new ARR guidance, flagged AI-driven demand acceleration and announced a 4‑for‑1 stock split.
📊 Quarter at a Glance
- Net new ARR: $255.8M (+32% YoY) — record Q1, exceeded high end of guide.
- Ending ARR: $5.51B (+24% YoY) — ARR acceleration vs prior quarter.
- Revenue: $1.39B (+26% YoY) — fourth consecutive quarter of acceleration.
- Profitability: Non‑GAAP operating income $325.7M (24% margin), non‑GAAP EPS $1.10; GAAP net income $27.8M.
- Cash flow: Free cash flow $468.5M (34% of revenue); $590.9M cash from ops; $4.55B cash balance.
🎯 What Management Says
- AI as tailwind: Management calls AI adoption an existential accelerator for cybersecurity, citing recent "Mythos" events and partnership access with Anthropic and OpenAI as demand catalysts.
- Product focus: Rapid push on AI Detection & Response (AIDR) and Next‑Gen SIEM, with AIDR ending ARR up >250% sequentially and a >$50M Q2 pipeline; endpoint sensors remain strategic advantage.
- Go‑to‑market: Falcon Flex subscription model driving upsell/renewals and partner coalition (consulting firms, insurers) to deploy continuous exposure management.
🔭 Outlook & Guidance
- Raised guide: FY‑27 net new ARR increased by ~$52M; FY net new ARR growth now expected to accelerate over FY‑26 (midpoint ~27.7%, a ~520bps raise).
- Q2 guide: Ending ARR $5.793–5.795B; net new ARR $284–286M; revenue $1.436–1.442B; non‑GAAP operating income $346–349M; non‑GAAP EPS $1.16–1.17 ($0.29 post 4‑for‑1 split).
- Full year: ARR $6.532–6.556B (24–25% growth); net new ARR $1.279–1.303B; revenue $5.915–5.959B; non‑GAAP EPS $4.88–4.96 ($1.22–1.24 post‑split). Free cash flow targeted ≥30% for FY; Q2 seasonal low ~24.5%.
❓ Analyst Q&A
- Drivers of the raise: Management pointed to Mythos/Project Glasswing momentum, record Q2 pipeline, strong module adoption and retention as rationale.
- AIDR TAM & competition: Mgmt views AIDR (AI Detection and Response) as potentially larger than EDR because of many nonhuman agents per user; advantage is existing endpoint sensor and telemetry.
- Pricing & SIEM: Falcon Flex can accommodate token/consumption models; Next‑Gen SIEM ingestion economics and lower cost model seen as a competitive win amid rising agentic telemetry.
⚡ Bottom Line
- Summary: CrowdStrike beat Q1, raised FY ARR expectations, is generating strong cash and margins, and is positioning itself as a core AI‑security vendor; near‑term upside depends on conversion of elevated pipeline into multi‑module deployments while execution and integration of acquisitions remain key.
CrowdStrike Holdings Inc — Morgan Stanley Technology
1. Question Answer
All right. Welcome, everybody. We're going to have a great act to follow here with CrowdStrike, but I'll read the disclosures first. If any research disclosures that you're interested in, please see morganstanley.com/researchclosures, or reach out to your sales representative. Delighted to have CrowdStrike here, Burt Podbere, CFO.
Maybe to kick off. We just had Sam on stage. How do you think about everything that Sam said, and how it relates to kind of all the security we're going to need to protect against that?
Meta, you said it right, they're going to need security. And we're here to help. Look, we have a partnership with OpenAI and others. And we're really excited about what we can do together. And we don't comment on who our customers are. But certainly, we have a lot of interactions with Sam and the team. So we're excited to see what the future holds.
All right. Perfect. All right. We're going to put on as good of a show. All right.
I'm here to help.
Exactly. So you reported very strong fiscal Q4 earnings on Tuesday this week. There were a lot of highlights. We saw EDR reaccelerate, continued strong growth across multiple growth pillars, strong traction with Flex. What were some of the most encouraging signs for you versus kind of expectations you had coming into the quarter?
Yes. So first, let me start off by saying that last year was one of the greatest years in our company history. Super proud of the team, super proud of being part of that team and really proud to have the customers that we have to make us who we are. And then if you dig down a little deeper, it really all starts with net new ARR. In Q4, $330.7 million, that's our biggest net new ARR number in company history. And for those who aren't familiar exactly with what net new ARR means for us, it's the one metric that's forward-looking that we give out. And it really talks to the health of the business. That's our metric. That's what we focus on. That's what the company rallies around. But there are other things that are important, too. And we had a couple of other records that standout for me and for many, non-GAAP operating income or our profitability. That was a record, right? So we did $326 million. Again, we're known for a company that does not grow at all costs, we grow profitably. And then our free cash flow. As a CFO, that's a number that I look at all the time. So for a record $376 million of free cash flow, really proud of the team, really proud of how we all rallied together and everybody in the management team is focused on those 3 metrics for sure.
Got it. I mean you were confident enough to raise your fiscal '27 ARR guidance from the 20% set at the Analyst Day. What were some of the drivers there? And a question we've gotten from investors is just, would you have raised it without some of the acquisitions?
Yes. So it would have been the same without those acquisitions. It would have been the same number. We disclosed what the acquired ARR was, and it was very small, $5 million to $8 million. And so -- for SGNL and Seraphic. And so we were really confident in being able to give out that guide for net new ARR for fiscal '27. I think it goes to, and it speaks to the momentum of the business. It starts there, right, with the records across the board from all different sizes of companies. We have broad-based demand. So it started there and then you saw that I talked about Q1 pipeline. So we had a record Q1 pipeline, 49% year-over-year. So those are 2 things that give us confidence as we look into the future, but it goes beyond that.
Look at the numbers that we provided with respect to our emerging products, Next-Gen SIEM, Next-Gen identity, cloud, over $1.9 billion, growing at 45%. I mean, those are some of the signs to me that says, "Hey, our customers are really, really looking at things other than what we were known for, the Next-Gen AV." So it says that, "hey, we're going beyond what we've -- and doing well on products that were essentially the older products that we had brought out." So that gives me a lot of confidence in terms of being able to put out a guide like that. And some of you may not realize, but that's the first time we've ever guided a specific guidance to net new ARR. And I think that goes and talks to the fact that we really are trying to be more transparent with our results and how we think about the business.
So between the momentum in the business, the product performance and also our Flex, right? Flex licensing, if you think about it, it's not a new product. It's not a new TAM. But you know what, it really matters, right? To be able to offer a customer with the ability to acquire our technology easily, seamlessly, flexibly, that really matters. It takes out the friction in the sales process, which is huge. And when we came up with the Flex licensing, the success is also driven -- you can see with everybody else, you are coming with -- all these other companies coming up with their versions of Flex because it's working. So really proud to see all those numbers. And then you look at within Flex, and you see we have a person or a company who will engage with us and they'll do a first Flex license. And what we've been tracking is, well, how long will it take before a customer comes back to the [ well ] and say, "Hey, we want to re-Flex." And we've given some data on that, and the data is strong, right? And I think we gave out a stat -- now that I think, we give out a stat on companies that are re-Flexing multiple times, almost 100 customers have re-Flexed multiple times within that same original contract period.
And so all those signs gives me a lot of confidence to be able to give a guide the way I did.
Okay. Perfect. We'll dive more into Flex in a second. But maybe to just kind of talk about some of the bigger thematics that have been going on within cyber right now, you and George addressed this on the earnings call, but just can you talk about how you have seen this AI disruption of cyber kind of come through discussions, and how you guys think about where that misjudges kind of the market?
Yes, it's a great question. And for us, when we think about it, there are really 2 different types of companies. One type of company would be the ones that have an exponential vulnerability to AI, and the other one is companies that are going to thrive. And those are the companies that have data moats. Those are the companies that can use AI to accelerate. We've been thriving with AI. You saw our results for last quarter. You don't have to go further than that. But why? Well, we're a net data creator. We create data.
So we collect data. We curate data. We're the folks that use that data as a backbone of our business, and certainly, we can use AI to accelerate what we do. When you think about AI, AI is created with GPUs. CrowdStrike secures that AI. And the big picture for us is that, "Hey, AI is great for a lot of things." You heard Sam up here. There's a lot of things that AI can do. Their AI is really good for reasoning, right? You can do incredible reports really quickly, gathering all this information, and it's fantastic for that. But when you're thinking about cyber, you need to be completely accurate and you need speed. And if you don't have both, you don't get a second chance, right?
And so, for us, it's more than just the technology. It's the support systems, it's the testing, it's the trust, right? You've got to trust your cyber professionals. And for us, we've been in the business a long time, we've been able to curate an incredible team to be able to work with our customers, build that trust. Tough to build trust with AI when sometimes you're -- you get a lot of -- in security, for security purposes when you're thinking about false positives. False positives, the name that you're probably all familiar with is hallucinations. You can't ask AI to -- something and you get 3 different answers, right? It's just -- that's not what it was built for, right?
So we have been able to benefit from other changes in the environment, like the hyperscalers. Remember when they all came out and they were talking about security within the hyperscalers. Well, look at our cloud business, right? It actually was a huge opportunity for us. Our cloud business, $800 million, growing 35%. Those are fantastic numbers. And it was generated from something that was going to change the world, and it has. And at first, we're running against the same things that we're seeing with AI, right? AI is going to dismantle a lot of SaaS companies. They said that with the hyperscalers. And it was an accelerant for our business. So we draw the parallels between the 2 so we give people an understanding of how we think about it.
Got it. Just the other question that we've been getting is just the, well, when does it become material that we can see it? I know you guys had a number of strong stats within the quarter in terms of what you were seeing as far as AI security. But when do you guys think about it being a material catalyst for the business?
Yes. Today, it is from the standpoint of the following. So number one, we use AI and agentic AI even in our product set today. So for example, we've -- in our exposure management. So if you are running Windows, pick one, 10, and you want to know if that version has the latest patch, you can use Charlotte, which is one of our AI tools, it's an orchestrator, to identify how many of the machines have the latest patch and it'll tell you. And then if you want to go beyond and say, "Hey, Charlotte, can you patch this?" So Charlotte, along with some of our other technologies, for example, Falcon for IT and others, can patch it for you. So you can see that it's already built into the product set.
And then you have specific things that we look at in terms of how is the adoption going for some of our AI tools? Charlotte, so last quarter, we gave out the fact that Charlotte has 6x the utilization year-over-year. It's also 3x the ARR year-over-year. So we're seeing signs that -- even on specific products that things are moving in the right direction as well as AI VR, which is our AI detection and response product. We just had it in the market for just a few weeks, and we saw a 5x quarter-over-quarter growth rate.
So we're already seeing the momentum ourselves with our AI tools. And I think a lot of people don't even -- don't realize that CrowdStrike was built on AI. In my day, it was called machine learning, right? And then we were doing agentic AI years ago. So we were on the front edge of doing all this work with AI, and it's really helped our business.
Got it. Okay. I want to go back to just another tailwind for the industry, which is just kind of this platformization versus best-of-breed. Just how do you think that, that -- like if you think about companies consolidating down to a right number of vendors, how do you -- how is that discussion going on with customers in terms of what you can bring to them in that conversation?
Yes, I love this question, right? So since the dawn of time, what do customers want? They want the best outcome at the cheapest price. That hasn't changed. And so what our platform has been able to enable is just that, right? So we feel we're the only pure-play cybersecurity company with the singular platform, right? We have 1 sensor, we have 1 console, and we have 1 platform, right? We don't have any integration tools. We do it all for you, and that's our customer promise. So we would go to our customers and say, "Hey, look, we have this opportunity to not only give you the best outcomes, but help you consolidate on us for a variety of things." And that matters, right?
So if you have disparate different technologies and they all have to work together, guess where the adversaries go, right there. They're going to look for those weak links. They're going to look for those stitching that you're putting together. They're going to go right to that stitching and go attack. But if there is no stitching, my arm is attached to my body, there's nowhere to attack, right? So we feel that that's the right approach. And clearly, it's been successful. So the consolidation tailwinds for us, I think, are going to continue for quite some time. And I think they're going to win. I mean, if you've got a crystal ball, maybe I think there's going to be maybe 3 or 4 full security platforms that exist, of which endpoint would be the center.
So that's how I think about it. And customers seem to be gravitating to it. And then you throw on the ability to purchase our technology easily with the Flex. And it's just -- it goes hand in glove. And so we're getting the -- we're seeing the momentum when we talk about our platform being the platform of choice. It's because of all these things that I've just described that make it work.
So you mentioned Flex being a reason why you have kind of more confidence in the business. It grew ARR 120% year-over-year. Can you just talk about like when customers are coming back to re-Flex? Just what is it -- where is it that they just start experimenting with more products? Is it that they're getting tons of usage? Just what is kind of bringing them back? And then how do you think about the -- why not just kind of convert everybody to a Flex model?
Yes. Great stuff. So a big accelerant to the re-Flexing is Next-Gen SIEM, right? They've used it. They want more of it. It's the backbone for companies in terms of their data. And we're -- we brought something to the market, which has just been so well accepted, so well received because it works, it's fast, it's less expensive than some of our competitors. All those things matter. So that's a big part of it. And then it's about how we flight our products. We have 33 different products that somebody could buy. And so basically, what Flex is able to do is it's like, "Hey, look, you have the whole book ready for you. You just pull it down, however you want, when you want." And so when you've got -- it's like anything else, when you bought a suite of things. It doesn't have to be technology, you bought a suite of different things, and you paid for it. You want to make sure you're getting the maximum value out of what you paid for. So you're going to try this and you're going to try that and you are like, that really helps, and that really helps. And then you get the viral effect of 3 things being able to do the work of 5.
And so for us, we've made it -- we flighted it in such a way that it allows customers to, in the apps, try other things. So why are we seeing such great results from our re-Flexes is because they are doing that, exactly that. They're trying different things, they're recognizing that, "Oh, I didn't realize you had that." This is today one of the biggest fights I have -- it's not fights, one of the things. I'm on a crusade with all our customers to educate all of our customers about some of the things that we have. So we have 33 different modules. So granted, that's a lot of modules. And oftentimes, when I'm meeting with customers, I get the look, "Oh, you actually have that?" And I'm like, yes, we've had it for 2 years, right? Because they were only focused over here.
And so what I try to do and what the sales team is trying to do is to educate our customers with respect to all the different features and functionality that we have. And that's also aided in the ability to see the re-Flexing.
In terms of Flex and where it's going, look, we've told the Street, we've told our own sales team that Flex is the future. So starting this fiscal year, fiscal '27, if it's not a Flex deal, you need to actually get an exception from management. There has to be a specific reason why you don't have a Flex deal. And so we're building that into -- we built it into our processes so that it's got to be something like myself or George or our President, Mike Sentonas, that's going to have to give authorizations, or a few others that have to give authorizations.
And so if you're a sales rep, you're going to go, okay, I don't want to go through that, right? That's not something I want to do. So I'm going to go after Flex. Oh, and by the way, my colleagues are making a bunch of dough, right, I am selling Flex, and by the way, my customers love it. So it's a win-win-win. And that is a recipe that's really hard to create.
Yes. Okay. Perfect. I mean maybe just going to the core for a second -- or not the core, but just the center of endpoint. You've talked about endpoint security as seeing reacceleration in past couple of quarters driven by AI demand. Can you just talk about kind of some of the underlying trends, and where you're kind of seeing this reacceleration take place?
AI is a big fundamental shift, right? And it's using AI at the edge. One of the things that I've seen in this year is we've had customers that are still -- big customers that are still on legacy AV. I'm out of my mind, right? You're a Global 2000 whatever, and you're using that? Are you kidding me, right? And so it's just a matter of time this time bomb is going to go off, you're going to get hit. And so the amazing stat is that from monitoring the endpoint, there's still 50% out there that's with legacy AV. And we're scratching our heads going, how could that be, on the one hand, on the other hand, let's attack. Okay, we're going to go after those, and we've been super successful with that. And now with AI, the -- obviously, the attack surface has completely changed, right? There are so many new attack surface areas using AI to be able to attack that the old legacy technologies just can't keep up, right? The speed of which attacks are coming in is in multiples from what it was because of AI.
So you got to think about the adversaries. They're going to leverage every single piece of technology to be better, stronger, faster than any company can prevent. So you need to stay ahead of that. So if you're on a legacy technology, it's only a matter of time before you're going to get hit for sure. And so that's why we've invested so heavily in AI. And that's why our product set is laced with AI everywhere. And for us, we see that as a future and not an accelerant.
Got it. I mean, just how have you seen competitive dynamics shift over the last year? Competitors are not standing still. Everybody has a platform. Everybody has a Flex now. Just what is -- how is that changing the competitive landscape?
Yes. We announced this partnership with Microsoft, right, to be on the Microsoft Marketplace. And this is amazing to me. Being at the company now in my 11th year, I never thought I'd see the day when Sachin will be up and talking to my sales team, right, about how to use the marketplace. So today, we have zero going through Microsoft. We have 1.5 billion going through AWS, right? Now we've done a lot of work with AWS to flight it, to make sure it's used appropriately. And with Microsoft, they have this Microsoft Azure Consumption Commitment, right, that you can use for CrowdStrike. I never really thought I'd see the day that, that would happen. But here we are. So it's better together and ultimately, who wins? The customer, right?
So between Sachin and George, they've been able to work through the competitive aspect of it in certain areas to carve out what's best for the customer.
How do you think that, that Microsoft relationship kind of ramps?
Yes. I mean we got 1.5 billion going through AWS. So I think the Microsoft folks who are running the Microsoft Marketplace, they're going to want to see that as well. But not only Microsoft, like you think about all these GSIs, right? They're looking at that number and going, "Wait, we have an opportunity to go do something like that?" So anyway, it's a lot of tailwinds with respect to the partnerships. So I talked about Sam, who was up here earlier and others. And we feel that, that dynamic is really changing the competitive landscape about who's going with who, who's associating with who. And they're just becoming -- for us, they're becoming less and less competitors that we're seeing, right? So now, obviously we talked about Microsoft. By far, they're our biggest competitor, right, if not close. But then you have others who are kind of in our space. You have Palo doing some things and some others, but that's pretty much it. There's not much else out there.
Okay. Perfect. I mean, Next-Gen SIEM has been a home run for you guys. It grew 75% year-over-year, over $500 million in ARR scale. Just how are you seeing being able to improve that product, being able to differentiate that product and kind of give this kind of SecOp solution that customers looking for?
Yes, it's been a home run, and I was involved in the transaction way back when, when we bought this company, Humio, and saw the potential that rested in that. And we built our Next-Gen SIEM based on that technology. And I think when you look at the technology and you're scouring the world, we got great folks who understand technology. We saw something a little different there. We saw a company that can really do what it does at scale. The speed was incredibly fast, and just the way it was designed, the architecture was very different than anything that was in the market. And we said, okay, well, if we can get to a faster response for asking queries, and if we can do it at a cheaper level, this is a home run for our customers. And we were able to do that.
And a big piece of the architecture is that it was index free, right? So the timing was incredibly fast versus some of the legacy SIEM vendors. And so for us, we've been able to showcase why it's faster, cheaper and you can log everything. Like if you're using one of the legacy technologies, it's expensive to log everything, really expensive. So customers were not. And so there were a whole bunch of logs falling on the floor. And so at first, when we were out there going to go, okay, well, the 20% that's falling on the floor, we'll take that, we'll log it for you, and it worked.
And then it's like, okay, well, we're doing the 20%, let's go for the rest. And when you think about SIEM, and you think about where the data and security data comes from, 80% of our SIEM, the security comes from us, comes from Falcon, and then first party. And then you've got 20% from a third party. So we've made it really attractive on pricing for the first party, like sometimes it's free. And then you pay for third party. And so that competitive advantage has really helped in terms of the cost structure.
Got it. I mean you had the Onum acquisition, just how do you see this kind of conversions of SIEM, observability, security analytics? We've seen Palo do acquisitions as well that kind of around this convergence.
It's really funny. Their acquisition of Chronosphere, the Humio technology that I talked about, that was the backbone for Chronosphere back then, right? So we have what it takes to do a lot more in observability because of the technology we have. And we're just being really thoughtful about how and when and all that kind of stuff that we -- before we bring it to market. And it's also going to stand up to the customer promise, which is we're only ever going to have 1 sensor, right? And so that all takes work to flight it and make it enterprise grade. And so for us, we have that ability to do it. And so we're excited about what we can do in that
space.
And for us, I think the Onum acquisition was really, really significant in that, if you're not familiar with what Onum is, it's basically a highway, and it delivers data from Depot A to Depot B. And for us, we saw a technology that not only did that, but also did a detection on route. So by the time it got to the SIEM, you'd have already filtered out so much data and understanding to make your SIEM, again, more cost-effective. So Onum is an accelerant to our Next-Gen SIEM. And that's why we went after it. And now not only do we have the data, but now we control the routes of where the data is going. So it's been a really, really powerful combination, adding Onum to our Next-Gen SIEM, and you're seeing the results.
Right. I mean cloud security, another strong area for you guys, $800 million ARR in the last quarter, growing 35% year-over-year. I think you mentioned that earlier. Just we've had the acquisition of Wiz by Google, or pending acquisition. Just how do we see kind of opportunities for competitive displacements in the market?
Yes. So when you think of cloud security, I'll break it down in the simplistic form. One is, you've got run time, which is Crowd Workload Protection, which we have. You need a sensor for that. And then you have cloud, then you have a nonagent, right, where you can do things like reporting, compliance. This is where companies like Wiz and others have kind of made their forte. Our belief and our strategy is you need both. You need the run time and you need the compliance side, and we have both, and we're investing in both. And over the years, we've invested in ASPM and DSPM, and we've got a lot of technology around cloud. That's why you're seeing the $800 million. It's because we have all these different cloud technologies that work as one.
Again, it's our brand promise, right? And customers are getting a tremendous amount of value from what we're able to provide from visibility in the cloud, to detection in the cloud, response in the cloud, run time, real-time, these things actually matter. In security, nanoseconds matter. And if you're not built for it, you're not going to stop it. So we feel pretty good about our strategy. We feel pretty good about how we're able to do work with both the sensor and the nonsensor, and we're going to continue to invest in that area.
Got it. Just rounding out all the different categories you guys have. On the identity side, again, over $500 million of ARR, growing 30% plus year-over-year. Just where does that fit in? We're going to have other identity people up here later on in the day, just how are you thinking about building out that kind of fuller identity platform? And does it expand beyond identity to kind of a more fulsome platform?
Yes. I love what we've done with identity. I was there when we purchased our first identity product, Preempt. And that was a home run for us, not only from the technology, but from the people. We still have the founders in our company all these years later. That was the foundation, right? And then we said, hey, there are 3 parts to identity. There's the identity creation, that's Microsoft. We're not going to do that. Then you have the identity brokering, right? That's the Oktas and Pings and that's not in our focus area. And then you have security in the identity. That's us. So Preempt was our first. And then we started adding other different pieces. We've got a PAM offering, just in time credentialing, right, which is the modern PAM. We're not -- we didn't build this thing on vaulting, which is actually fairly easy to do. So -- but you can see where we're going with that.
We also acquired Falcon Shield. We call it Shield now. And that's identity for the applications, the machines and the non-machines. So what we've done with our identity protection is enterprise grade and a big piece of our technology. And when you think about it, right? When you think about our earlier discussion on AI and where AI is going, when Anthropic announced their AI tool, it was talking about vulnerabilities. And even if you took out all the vulnerabilities in the world, took them all out, and it wasn't an issue, companies are still going to get breached. There are many, many other ways that adversaries are going to get in. Identity is another one, right?
So if you have a strong identity platform, you've now taken off another, or reduced the risk in another area of attack. And so you need identity in security, you absolutely do. It's a fundamental pillar. And we're going to continue to invest in our identity products to make sure that we're on the front lines of this thing, right? And for us, obviously, there's the vulnerability, sure, but that's a small piece of what you have to protect to stop a breach.
I mean maybe a question on the AI security portfolio that kind of wraps into you guys wanted to have this 1 platform, no stitches as you were kind of describing earlier. That's led to a lot of kind of smaller acquisitions. Just how do you see kind of the AI security piece of the portfolio growing? And just how do you see kind of the acquisition strategy of CrowdStrike evolving?
Yes. Number one, I think you're all seeing that the velocity of our acquisitions has increased, and I love that. I think that we've got a war chest of cash, and I think the highest and best use of that cash isn't sitting in the bank getting whatever 3%, 4%, it's definitely applying it to investment in R&D and certainly on inorganic activity. We've been really successful in buying great tech and great people, right? And then putting our distribution on top of that and you see the inflection. We've been really, really successful at that. So to deviate from that would take something exceptional, right? And we're doing so well, why would we go and buy something that's completely transformational when we're already transforming everything in what we're doing. So it would have to be kind of like I look at it as a deal of the century. But I rely on our CEO, George Kurtz; and our President, Mike Sentonas, to kind of bring thoughtful enhancements to our platform.
So I have the money for it, and I can go raise a bunch even through your bank to help me do whatever we need to do. But right now, I love our success in buying great tech and great people.
And then maybe just -- we've mentioned a whole suite of products, you have Flex. Just how -- any -- you've made some investments kind of in channel to kind of better sell all of these products. Just how are you finding the most effective way to sell these products through the channel or just channel optimization that you made it to do?
Yes. We've got a great leader in our channel, our Chief Business Officer, Daniel Bernard. And he's just transformed how we think about the channel. We're a channel-first company, so part of it is incenting the channel in the right way. We had a CCP program in place, and the CCP program was basically incentives for our customers, and it really, really worked. But we did it for partners, too. And we saw the success. And so we're going to continue with that -- with some of those programs and making sure that the channel, when they're seeing a customer, the first product out of their bag is CrowdStrike. That's our mission, right? Unless they're exclusive, and there is no other cyber product, which we always want. But for those that are some of the larger ones that are not exclusive, it's about how do we make sure that CrowdStrike is the first out of the bag.
Right. Okay. So we spent 95% of our time talking about kind of ways to enhance the top line. Just -- we'll end with the CFO question of just what does this all mean to the bottom line?
Yes. So we've got that long-term target that we -- out there, and it's my kind of North Star. So what are we doing to make sure that we are able to hit those targets? Well, we are well on our way. It starts with gross margin, right? So we had a record gross margin quarter in Q4, 81% on subscription non-GAAP, and that's hard. Moving the needle on gross margin is really hard. What have been able to do? We've been able to optimize some of the public clouds that we leverage as well as our own, right? We've migrated certain things over that made sense. And then our scale. When you're able to consume as much as we do, you're going to get a better deal when you're talking to some of the hyperscalers. You're going to get a better deal.
We look at ways within some of the hyperscalers, what's the most economical way to do it? For example, in Amazon, they have something called West 1 and West 2. West 2 is in different geo, a little less expensive. So okay, let's put more of our customers over to West. So it's little things like that, that add up. Look, I'm looking for 0.1% at a time, 0.2%, 0.3% would be fantastic in a quarter. That's where I'm going. But if I continue to do that, I'm going to get to where I need to be. I'm not far from my long-term model, by the way. So I only need a few of those to get me there.
Okay. All right. Perfect. Well, Burt, congratulations on a fantastic quarter and a fantastic story.
Thank you so much, Meta. Thanks, everyone.
CrowdStrike Holdings Inc — Morgan Stanley Technology
📊 Quarter at a Glance
- Net new ARR: $330.7M (record)
- Free cash flow: $376M (record)
- Next-Gen SIEM ARR: >$500M, +75% YoY
- Cloud security ARR: $800M, +35% YoY
- Identity ARR: >$500M, +30% YoY
🎯 What Management Says
- Guidance momentum: Raised fiscal 2027 net new ARR guidance; record Q1 pipeline up 49% YoY.
- Flex & platform: Flex licensing drives adoption; re-Flexing momentum with large customer engagement.
- AI strategy: AI embedded across products (e.g., Charlotte); strong demand for AI-enabled security and platform consolidation.
🔭 Outlook & Guidance
- Outlook: Net new ARR guidance raised for fiscal 2027; Q1 pipeline +49% YoY; margin and mix benefits guided by ongoing product momentum.
❓ Analyst Q&A
- AI materiality: AI-driven security momentum is already visible; management cites product usage and ARR growth as proof.
- Platform vs. best-of-breed: Emphasis on a single-sensor, single-console platform to reduce stitching risk and drive consolidation.
- Channel & partnerships: Microsoft Marketplace and cloud partners expanding go-to-market; channel-first strategy supported by Flex.
⚡ Bottom Line
CrowdStrike reinforces durable, multi-pillar growth: record net new ARR, strong cash generation, and AI-powered product momentum. A platform-centric, Flex-driven model supports repeated expansions across SIEM, cloud, and identity. While near-term AI-driven competitive dynamics pose risks, the company shows clear, executable paths to higher ARR and margin progression for shareholders.
CrowdStrike Holdings Inc — Q4 2026 Earnings Call
1. Management Discussion
Hello, and welcome to CrowdStrike's Fiscal Fourth Quarter 2026 Financial Results Conference Call. [Operator Instructions] Please be advised that today's conference is being recorded. I would now like to hand the call over to Andy Nowinski, Vice President of Investor Relations and Strategic Finance. Andy, please go ahead. Thank you.
Good afternoon, and thank you for your participation today. With me on the call are George Kurtz, Chief Executive Officer and Founder of CrowdStrike; and Burt Podbere, Chief Financial Officer. Before we get started, I would like to note that certain statements made during this conference call that are not historical facts, including those regarding our future plans, objectives, growth, including projections and expected performance, including our outlook for the first quarter and fiscal year 2027, and any assumptions for fiscal periods beyond that are forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995.
These forward-looking statements represent our outlook only as of the date of this call. While we believe any forward-looking statements we make are reasonable, actual results could differ materially because the statements are based on current expectations and are subject to risks and uncertainties. We do not undertake and expressly disclaim any obligation to update or alter our forward-looking statements, whether as a result of new information, future events or otherwise. Further information on these and other factors that could affect the company's financial results is included in the filings we make with the SEC from time to time, including the section titled Risk Factors in the company's annual and quarterly reports.
Additionally, unless otherwise stated, excluding revenue, all financial measures disclosed on this call will be non-GAAP. A discussion of why we use non-GAAP financial measures and a reconciliation schedule showing GAAP versus non-GAAP results is currently available in our earnings release, which may be found on our Investor Relations website at ir.crowdstrike.com or on our Form 8-K filed with the SEC today.
With that, I will now turn the call over to George.
Thank you, Andy, and thank you all for joining CrowdStrike's Q4 FY '26 Earnings Call. I couldn't be more pleased with our results. AI is driving elevated demand for the Falcon platform and is a key accelerant for our business. At the same time, AI is weaponizing adversaries to attack with increased speed, sophistication and precision.
We're seeing this play out in real time in the Middle East as emboldened adversaries fuel nation state activity. FY '26 was CrowdStrike's best year yet capped by a blockbuster Q4 where we set new records across the business. Summarizing our results. One, all-time record net new ARR of $331 million for the quarter, which grew 47% year-over-year, coming in well ahead of our expectations.
For the year, we delivered $1.01 billion in net new ARR, up 25% year-over-year, our first year delivering over $1 billion of net new ARR. Two, ending ARR of $5.25 billion, crossing the $5 billion milestone, which accelerated to 24% growth year-over-year. CrowdStrike is the fastest and only pure-play cybersecurity software company to achieve this milestone. Three, record free cash flow of $376 million for the quarter or 29% of revenue. And for the year, we delivered record free cash flow of $1.24 billion or 26% of revenue. Four, all-time record operating income of $326 million for the quarter or 25% of revenue. This is the third consecutive quarter of record operating income.
For the year, we delivered $1.05 billion of operating income, exceeding the $1 billion operating income milestone for the first time. Five, record net new ARR from cloud, next-gen identity and next-gen SIEM collectively, ending ARR for these solutions collectively grew more than 45% year-over-year. Amidst today's AI backdrop, our endpoint business accelerated for the second consecutive quarter. Six, dollar-based net retention of 115% and gross retention of 97% showcasing best-in-class durability and stickiness, which leads to my final point. Seven, we delivered $1.69 billion in ending ARR from accounts that have adopted the Falcon Flex subscription model, growing more than 120% year-over-year, turbocharging our land and expand motion.
Our Q4 and FY 2026 execution showcases CrowdStrike's leadership in every theater, every segment and every route to market. In our third consecutive quarter of net new ARR acceleration, the voice of the market is clear. CrowdStrike is durable, mission-critical infrastructure for both securing AI and accelerating global AI adoption. We find ourselves in one of the most defining times in the history of modern technology. AI has gone from DreamWorks to reality, now increasingly in production across the enterprise.
From CrowdStrike's founding, we've been building AI innovation for cybersecurity, yet the pace of AI innovation is broadly misunderstood. Novel discoveries are often interpreted as the [indiscernible] of existing categories. The market is questioning enterprise software's role in an agentic world. It's in moments like these where opportunity is created. In the same way that we anticipated the cloud revolution, we pioneered and built for the agentic revolution.
Here's what I see unfolding in the market. We see the AI revolution creating 2 disparate groups of software companies. Group 1, those who are now existentially vulnerable. These are historically nice to have technologies that are productivity features and point products geared to legacy pricing models. Group 2, those who will thrive. These are mission-critical trusted infrastructure technologies necessary for global continuity with deep IP.
These technologies are net data creators producing novel, fresh and proprietary data that doesn't exist elsewhere. -- data that is fuel for the agentic business outcomes. In these companies, proprietary data is just one part of the advantage. The other is trusted enterprise architectural superiority, which drives stickiness, adoption and scale. Here's why CrowdStrike is winning and how AI is driving even more competitive success for us. One, our competitive moat is becoming an opportunity ocean.
Falcon is a vertically integrated net data creator and third-party data aggregator. We generate real-time data that no one else has from customer environments and our world-class threat intelligence. What Frontier AI labs cannot do, we've been doing for over a decade. Cyber reinforced learning from human feedback or RLHF at scale. Our MDR analyst, threat hunters and incident responders produce expert label data as a byproduct of operations. These labels don't come from Internet text. They come from stopping real breaches in real time.
Threat Graph correlates more than 1 trillion security events per day across approximately 2 trillion vertices, analyzing 15-plus petabytes of data, structured, queriable, security signals at scale no one can replicate. Frontier models can augment security, summarize alerts, draft queries, speed up triage. That's extremely valuable, but stopping breaches require sensors, real-time telemetry, continuous expert validation and enforcement, a closed-loop system, not a text model.
As our technology evolves, our data improves, as our data improves, our platform evolves. As our experts validate outcomes, our AI agents get better. This is a flywheel and network effect that no one else has in cybersecurity at our size and scale, and it's how we stand behind our brand promise of stopping breaches. This dynamic is not cyclical, it is structural. Two, we win because Falcon is purpose-built for securing AI at every layer.
The layers of the new AI stack are the attack surface of the future and Falcon can secure all of them. AI must be secured at every level, including: one, GPU foundation, partnering with NVIDIA, AMD, Intel and others to secure AI at the source; two, hardware and infrastructure OEMs, securing AI factories such as Dell, HPE and Super Micro; and novel AI operating systems such as vast data; three, Neo clouds and hyperscalers, securing where AI happens in the cloud across AWS, OCI, GCP, Azure and inference disruptors such as CoreWeave, Nebius and Crusoe. Four, token factories, securing the use of frontier model creators like anthropic, OpenAI and Google Gemini; and 5 AI applications in agents securing AI native software and the agentic workforce.
Not only do we secure the use of each of these companies' products, but we also secure nearly all of the companies themselves. We secure the world's AI future by securing the world's AI leaders. And three, we win because efficacy and precision matter more than ever. In cybersecurity, you simply cannot have a hallucination. You can't prompt twice. It's first time final. It's the difference between thwarting an adversary or experiencing a breach. Cybersecurity is a unique paradigm. Success for us and our customer is, did we stop a breach? We win because cybersecurity needs to be faster and more deterministic than ever before, and we uniquely deliver superior outcomes.
Our agentic SOC and AI technologies are transforming security. CrowdStrike's AI innovation is setting new adoption standards on the journey to delivering security AGI. Charlotte is our flagship agent, and now we have 10 other agents representing specific security skills and roles within security teams. Between Charlotte and our other agents we can already see the mobilization of securities agenetic workforce working hand-in-hand with human security professionals.
Coming back to Charlotte, our agentic [indiscernible] built from multiple models allowing us to optimize from the latest and greatest LLMs. We couple industry innovation with our own AI expertise, training and models from security's richest data source, Falcon adversary threat and security analyst training data. We saw Charlotte usage soar more than 6x year-over-year as ARR more than tripled. A thematic win was in a leading cloud software provider in an 8-figure re-Flex transaction. The re-Flex expanded the adoption of next-gen SIEM and Charlotte. Their 30-day use of Charlotte tells a compelling story, achieving a 3x faster mean time to respond, using the power of our domain-specific AI, Charlotte accelerates streamlines and democratizes security outcomes. Technology innovation is just one part of our success.
Our results are also driven by our go-to-market innovation, creating the revolutionary Falcon Flex subscription model, which we now see mimic across cybersecurity. The model transformed our discussions with customers to demand planning based on risk, data, attack surface and overall platform capabilities. Let me share our Q4 Falcon Flex performance within the now $1.69 billion ending ARR cohort of Flex account value, growing greater than 120% year-over-year.
We now have more than 1,600 customers who have adopted Falcon Flex and added more than 350 Flex customers in Q4. That amounts to nearly 4 new Falcon Flex customers each day of the quarter. The average Flex customers ending ARR is greater than $1 million. The proof of Falcon adoption success is in the re-Flex. Customers are using what they buy and expanding their Flex commitments. More than 380 Flex accounts have already re-Flexed representing more than 23% of the Flex customer base, up from 5% in Q1. The average ARR lift after a re-Flex is 26%, happening on average within 7 months.
And the platform adoption grows even further from there. We're now tracking the number of customers who are repeat re-Flexers. Nearly 100 customers have re-Flex multiple times. The multiple time re-Flex cohort now represents approximately 6% of of total Flex customers and over 1/4 of all re-Flex customers. Our multiple time re-Flexers on average, have an ARR lift of an additional 48% from their initial Flex subscription.
In summary, Falcon Flex unlocks never seen before adoption for customers. Flex is now how we go to market. A key win includes a major enterprise software player that started with using one module, threat intelligence and spending low 6 figures. Through Falcon Flex, this customer is now using 25 modules and spending $86 million in total Flex contract value with us.
Flex is creating its own flywheel. Demand drives use, use drives more demand. Flex is the stage on which our platform solutions shine. Collectively, our next-gen identity, cloud and next-gen SIEM businesses grew more than 45% year-over-year reaching more than $1.9 billion in ending ARR. Our NextGen Identity business ended FY '26 with more than $520 million of ending ARR growing more than 34% year-on-year, a double-digit acceleration versus 2 quarters ago.
Key drivers include our privileged account security solution which grew more than 170% sequentially. Falcon Shield and the ARR grew more than 300% year-over-year, more than 5x since our acquisition of Adaptive Shield as customers protect the rapidly growing agentic SaaS attack surface. Our ability to secure both human and agentic identities wherever they exist is rapidly turning CrowdStrike into our customers' identity secure control plane, a key identity win, an iconic department store selecting CrowdStrike over an SMB point product in a 7-figure deal driven by the ease of use of our IT DR and PAM solutions in a Flex consolidation.
While our next-gen Identity business had an excellent quarter, we're most excited for what's ahead. We recently closed the acquisition of SGNL AI. This is SGNL, bringing the power of zero standing privilege for all identities to the Falcon platform. With SGNL AI, CrowdStrike is delivering high fidelity, content-driven, real-time authorization to the market, enabling our customers to rapidly reduce their identity attack surface even as they rapidly expand the number of identities within their organization.
We're moving access from static point in time to real time and redefining Zero Trust. Access should be always on granular and dynamic. But we're not shopping there. Our recent acquisition of Seraphic turns any browser into a secure enterprise browser without impacting user behavior. The browser has become the front door for AI applications and Seraphic meets human and nonhuman users where they are and where they're going, agentic browsers for real-time visibility and protection.
Turning to our cloud business, where net new ARR growth accelerated for the second consecutive quarter and ending ARR grew more than 35% year-over-year. For the first time, our cloud business exceeded $800 million in ending ARR as our customers look to us to secure the infrastructure powering their AI future. Our unique ability to operate in run time at scale continues to set us apart from the rest of the market. A key win in our cloud business was with a major enterprise data platform company who deployed Falcon Cloud Security in an 8-figure total deal value Flex.
After extensive testing, this account ripped out their existing provider for our runtime protection first approach, realizing the integrated benefits of CSPM, CIEM, CDR, and Overwatch threat hunting, which resulted in a 90% reduction in mean time to detect and respond for their cloud environment.
Turning to our next-gen SIEM business, where we delivered a record quarter. Our Next-Gen SIEM business grew over 75% year-over-year, delivering ending ARR of more than $585 million. Next-Gen SIEM has proven itself a scaled market disruptor where our performance and cost advantages set us apart from legacy competitors. At the same time, our launch of agentic security workflows is powering the cybersecurity operating system of the future.
With Falcon Onum, we're enabling our customers to connect data sources quickly and efficiently, resonating with both security and IT teams. A key win in the quarter was with a Fortune 500 retailer highlighting our strength and momentum in the next-gen SIEM space. In the 7-figure deal, we replaced a legacy SIEM and its attached point product data pipeline. Falcon's fully native data pipeline and an expected 80% faster query performance was a game changer in helping this customer build out their agentic SoC.
Rounding out our product portfolio, I want to touch on our endpoint and other AI-specific businesses. Amidst the backdrop of accelerating AI proliferation, our endpoint business accelerated for the second consecutive quarter. The endpoint is rapidly becoming the epicenter of AI usage driven by the growth of technologies ranging from MCP servers to [ coding ] tools to localized LLMs. AI is the fastest-growing attack surface on the endpoint. As of Q4, our sensors detected more than 1,800 distinct AI applications running on enterprise devices, representing nearly 160 million unique application instances across our customer base.
And with the acquisition of Seraphic, we now give our customers even more control over their knowledge workers usage of AI tools. Lastly, I want to touch on our recently launched AIDR offering. In just a short time, AIDR has become 1 of our most in-demand products, growing more than 5x versus last quarter despite having only been available for a few weeks. AI adoption is moving faster than can be controlled and our AIDR offering gives customers immediate visibility into their employees' usage of AI tools, including the specific models being used as well as detections into potentially malicious or noncompliant usage, bringing model scanning, visibility, guardrails and detections to AI usage positions CrowdStrike as a catalyst for enterprise AI adoption.
Concluding the discussion on our platform solutions. Seeing is believing. Please reference our investor deck, which now includes a link to product demo videos, showcasing AI innovation across the Falcon platform. Our partner go-to-market delivered beyond expectations this past year. We saw growing practices across EY, Accenture, Deloitte, HCL, Wipro, KPMG and Infosys taking shape focused on next-gen SIEM migrations.
Our MSSP business also continues to grow at a rapid pace. In just over 3 years, we've gone from a sub-$100 million MSSP business to more than $1.3 billion spanning market-leading partners like Kroll, Pax8, and NInjaOne. Finally, our hyperscaler leadership continues to differentiate Crowdstrike from every other cybersecurity player. This past year alone, we did nearly $1.5 billion of total contract value on the AWS marketplace, growing nearly 50% year-over-year.
Then a few weeks ago, Satya Nadella and I spoke to CrowdStrike's go-to-market team together. We are now open for business on the Microsoft marketplace and customers can use their Microsoft Azure consumption commitment dollars on Falcon. This is a watershed moment reflecting a clear evolution of how our companies see each other and how Microsoft and CrowdStrike are working together to make the world a safer place.
In summary, we didn't just have a great partner year, we built an ecosystem to win the next decade. Closing my remarks today, I'm proud of the team and our partners for executing a terrific FY '26. Here are my key takeaways as I look at the business today and into the future. First, CrowdStrike is an AI adoption accelerator. Our customers are safely and securely using more than 1,800 distinct AI applications on their endpoints, which would not be possible without CrowdStrike.
Second, AI necessitates AI security. Every enterprise deploying AI needs an independent protection layer for visibility, compliance and enforcement. As AI adoption grows, CrowdStrike becomes even more of a necessity to these organizations. And third, our data moat creates a structural advantage delivering cybersecurity at scale requires more than a prompt. It requires expert label telemetry from our global sensors, MDR analysts and elite incident responders. It is a structural advantage no LLM provider can replicate. In addition. Agentic cybersecurity requires in-line prevention as well as real-time remediation.
Since the founding of CrowdStrike, we created an AI-native platform. Enterprises have trusted us to help them safely navigate market transitions like digital transformation and cloud migration. The AI revolution is now upon us, and just like prior market transitions, adoption of AI will be secured by CrowdStrike. Thank you for your trust.
I'll now turn the call over to Burt Podbere, CrowdStrike CFO.
Thank you, George, and good afternoon, everyone. As a quick reminder, unless otherwise noted, all numbers, except revenue mentioned during my remarks today are non-GAAP. We delivered exceptional fourth quarter results and a record finish to the year, exceeding expectations across all guided metrics driven by continued Flex and re-Flex momentum and strong organic growth across the platform.
FY '26 was a milestone year for CrowdStrike. For the full fiscal year, ending ARR growth accelerated to 24% and net new ARR accelerated to 25% year-over-year. We delivered this record top line performance while exceeding our profitability and free cash flow targets. Operating income reached a record $1.05 billion or 22% of revenue, and we delivered record free cash flow of $1.24 billion or 26% of revenue. The combination of growth, scale, profitability and cash flow put CrowdStrike in rare air.
The strength of our platform and the significant market opportunity ahead further reinforce our conviction in the path to achieving our future growth milestones of $10 billion and $20 billion of ending ARR as well as our target profitability model. Our full year momentum was punctuated by an exceptional fourth quarter. We achieved record net new ARR of $330.7 million, up 47% year-over-year and well ahead of our stated expectations driving ending ARR to $5.25 billion.
Our fourth quarter results showcased the success of our Flex led go-to-market strategy. Momentum was broad-based across customers of all sizes from enterprise to downmarket and MSSPs, achieving another record quarter in our corporate business. Customers continue to leverage Falcon to consolidate their security needs and lower their total cost of ownership resulting in higher retention rates over the prior quarter and strong module adoption rates.
As of Q4, 50% of subscription customers are now using 6-or-more modules. 34% are using 7 or more and 24% are using 8-or-more modules. Our gross retention rate remained high at 97%, and our dollar-based net retention rate increased to 115% in the quarter. At our more than $5 billion ending ARR scale, these retention rates highlight the durability of our customer relationships and our ability to both retain and expand our customer base.
Our strong business momentum and Q1 record pipeline entering FY '27, which grew 49% year-over-year, gives us conviction in our ability to deliver profitable growth throughout FY '27 and beyond. As we lapse the 1-year mark from the end of our highly successful CCP program, we have seen that accounts that took CCP deals have gross and net retention rates higher than the company average, have shown a strong trend of early renewal and have already expanded more than twice the total $80 million of ARR value we provided.
Moving to the P&L. Total revenue exceeded our guidance range and grew 23% over Q4 of last year to reach $1.31 billion. Subscription revenue grew 23% over Q4 of last year to reach $1.24 billion, and professional services revenue remained strong at $63.1 million, up 26% year-over-year, driven by the elevated threat environment. The geographic mix of fourth quarter revenue consisted of approximately 66% from the U.S. and 34% from international geographies with both EMEA and APAC year-over-year revenue growth accelerating compared to Q3.
We saw broad strength across all our major geographic markets with the U.S., Japan, Europe, the Middle East and Africa, all exceeding expectations. Total Q4 non-GAAP gross margin was a record 79% and Q4 non-GAAP subscription gross margin was a record 81% of revenue, primarily as a result of continued cloud optimization. Fourth quarter non-GAAP operating income was a record $325.8 million, and non-GAAP operating margin was 25%, exceeding our guidance.
The outperformance was driven by our strong top line performance, gross margin improvement and sales execution, underscoring our commitment to durable profitable growth as we continue to balance strong net new ARR growth and operational excellence. In Q4, we delivered positive GAAP net income attributable to CrowdStrike of $38.7 million. Non-GAAP net income attributable to CrowdStrike was a record $289.1 million or $1.12 on a diluted per share basis, exceeding our guidance.
Moving to cash. Our cash and cash equivalents increased to $5.23 billion. We generated record cash flow from operations of $497.9 million and record free cash flow of $376.4 million or 29% of revenue. Our FY '27 outlook reflects our confidence in the durability of CrowdStrike's growth trajectory, profitability expansion and cash flow generation. The fundamental tailwinds, platform consolidation, AI proliferation and Flex adoption are continuing to gain momentum.
As George mentioned earlier, we see the AI revolution creating 2 disparate groups of software companies, one, those who are now extensionally vulnerable and two, those who will thrive. CrowdStrike is thriving amid the AI revolution as we not only leverage AI within our entire platform, but our platform helps organizations adopt AI safely and securely.
The AI revolution represents a new and generational growth opportunity for CrowdStrike as accelerating AI adoption necessities security built for this next era of technology. As AI adoption accelerates, combined with our record Q1 pipeline and continued platform consolidation momentum, we have strong conviction to once again raise our FY '27 ARR outlook. The outlook we are providing today includes the acquisitions of SGNL and Seraphic, both of which closed in February and are expected to contribute a combined $5 million to $8 million of acquired net new ARR in Q1.
We are assuming minimal organic contribution from these acquisitions in the remaining quarters of FY '27 as we remain committed to natively integrating their capabilities into the Falcon platform before fully scaling go-to-market, consistent with our proven M&A strategy and brand promise. We expect FY '27 net new ARR seasonality to remain unchanged relative to FY '26 with approximately 41% in the first half and 59% in the second half.
Beginning in Q1, we are changing the sales commission amortization expense period from 4 to 5 years to reflect our longer customer relationship periods. We expect this change to benefit non-GAAP operating income by $85 million to $95 million in FY '27, partially offset by additional operating expenses resulting from the integration of our recent acquisition of SGNL, Seraphic, Onum and Pangea of $74 million to $80 million.
For a detailed breakout of the acquisition impacts to our guidance, please refer to the guidance slides of our Q4 FY '26 earnings presentation available at ir.crowdstrike.com following our prepared remarks today. Additionally, we remain confident in our previously provided assumptions for FY '27 partner rebates to represent approximately 0.8% of total revenue.
Moving to interest income. Based on expected market rates and cash outlay from our recent acquisitions, we are assuming interest income of $160 million to $170 million for FY '27.
Moving to cash. At the midpoint of our guidance, we expect free cash flow margin to be approximately 33% in Q1 and at least 30% for the full fiscal year. In FY '27, we expect the seasonal mix of free cash flow dollars between the first and second half of the fiscal year to be 43% in the first half and 57% in the second half, with Q2 remaining our seasonally lowest quarter.
We anticipate capital expenditures as a percentage of revenue to be 7% to 8% in FY '27 with these investments more weighted to the first half of the year. Finally, as of March 2, we repurchased approximately 144,000 shares following our fiscal year-end and had approximately $950 million remaining under our current share repurchase authorization. We will remain opportunistic in returning capital to shareholders as we remain focused on capturing the significant growth opportunities ahead of us.
For the first quarter of FY '27, we expect annual recurring revenue to be in the range of $5.502 billion to $5.504 billion, inclusive of the estimated acquired ARR and reflecting a year-over-year growth rate of 24%, translating to net new ARR of $249 million to $251 million, reflecting a year-over-year growth rate of 29% to 30%. We expect total revenue to be in the range of $1.360 billion to $1.364 billion, reflecting a year-over-year growth rate of 23% to 24%. We expect non-GAAP income from operations to be in the range of $308 million to $310 million, and non-GAAP net income attributable to CrowdStrike to be in the range of $275 million to $277 million.
We expect diluted non-GAAP net income per share attributable to CrowdStrike to be approximately $1.06 to $1.07, utilizing a 21.0% tax rate and weighted average share count of approximately 259 million shares on a diluted basis. For the full fiscal year 2027, we expect annual recurring revenue to be in the range of $6.466 billion to $6.516 billion, reflecting a year-over-year growth rate of 23% to 24% and and translating to net new ARR of $1.213 billion to $1.264 billion, reflecting a year-over-year growth rate of 20% to 25%.
We expect total revenue to be in the range of $5.868 billion to $5.928 billion, reflecting a growth rate of 22% to 23% over the prior fiscal year. Non-GAAP income from operations is expected to be between 1.422 billion and $1.462 billion. We expect fiscal 2027 non-GAAP net income attributable to CrowdStrike to be between $1.241 billion and $1.271 billion, utilizing a 21.0% tax rate and approximately 260 million weighted average shares on a diluted basis. We expect non-GAAP net income per share attributable to CrowdStrike to be in the range of $4.78 to $4.90. George and I will now take your questions.
[Operator Instructions] Our first question comes from Joe Gallo at Jefferies.
2. Question Answer
Really nice results and guide. George, securing AI is a huge market opportunity. Would love your thoughts on, one, when securing AI materializes to ARR meaningfully for you? Is that a fiscal '27 story? And then two, how much of the new market opportunity goes to pure-play cyber vendors. In cloud, people certainly use the hyperscalers for some of their security needs. So just curious how much of that new AI market goes to pure-play cyber vendors like yourselves?
Yes. Thanks, Joe. Obviously, we're still in the early innings, but we continue to ramp in protecting AI and it's happening today in terms of ARR growth. And we're obviously blown away of what we've seen with Pangea and AIDR. It was up 5x quarter over quarter from when we acquired the company. So we're really excited about that.
The other piece to keep in mind is that not only is it going to drive AIDR growth, but we're going to see growth in protecting attack services like cloud. We're going to see growth in next-gen SIEM. We're going to see growth in other areas that all touch AI. So from that standpoint, I said early innings, but lots of opportunity for us. And I think with regards to hyperscalers, I'm glad you asked the question because when I started the company in 2011, we pioneered, Bob delivered security.
And over the years, as cloud was maturing, I heard a lot about the hyperscalers actually providing all the security services. Well, that didn't happen. In fact, as you've seen with our results and our partnership with AWS, as an example, we transact billions through these platforms, and they're a great partner, and there's a lot more exposure in the cloud. So we see the same thing happening what I call AI hyperscalers, being able to actually partner with these hyperscalers leveraging AI and their LLMs and also being able to leverage the technology to provide better outcomes within the platform of record for our customers, which [indiscernible]. .
Our next question comes from Rob Owens at Piper Sandler.
George, you talked about the 10 other agents that you guys have besides Charlotte and some of the traction that's Crowdstrike seeing with security agents. But can you provide color on some of the recent acquisitions. When we look at agentic security more broadly, where are customers in their journey? And do you see identity as maybe one of the main hurdles for them getting agenetic deployments at scale.
Yes, Rob, identity is one of the biggest threat vectors right now that we see, in fact, one of our latest threat reports, 80% of the breaches are non-malware base, right? So a lot of it is around identity. And between the identity stack that we've built over the years, again, we got into identity in 2020. We've built that out. It's a big business. And now really with the addition of SGNL AI. This is, in my mind, game-changing technology to have 0 standing privileges to be able to protect nonhuman identities and human identities in a much more modern stack than anything else that's out there in the market.
It's a perfect fit to CrowdStrike in our platform. You combine that then with something like Seraphic in browser security. So now you're able to protect the front door of really where these attacks happen, plus where AI takes place and you add the identity layer to that. And again, we're providing something that we think is going to be very unique in the industry. And of course, Pangea, which is our AIDR product, when you look at EDR, in today's market, EDR is a must, its compliance mandate, and we believe that EDR will be a similar opportunity --, AIDR will be a similar opportunity to EDR in the coming years, driven by compliance and the need to accelerate protecting AI.
Our next question comes from Fatima Boolani at Citi.
George, I wanted to direct this to you, I had a question about the next-generation SIEM opportunity. There are very much percolating fears that the open-ended stock modernization share capture opportunity that had thus far been pretty open ended has -- is perceived to maybe be at more risk from what the Frontier Labs may or may not be pursuing.
So maybe in the context of the opportunity ocean commentary in your prepared remarks. Can you help us with a deeper explanation and understanding of what your current nature of relationship, partnership and integration is with the Frontier Labs and the frontier Models? And how should we very critically think about the durability of your moat from any potential commoditization from an architectural or technical or frankly, any other relevant contextual standpoint?
Yes, Great question. So when you look at what we've built, and I talked about this in the prepared remarks, we're a net data creator, right? We have telemetry that we create from our agents and from other parts of our platform that is unique. We put it into various data stores, including next-gen SIEM and our Threat Graph. And we're able to understand the threats in real time with real-time prevention. That's vastly different than what the LLM providers in Frontier models do. .
Now certainly, we leverage the Frontier models. We have our own small language models. We have our own curated data. So I think we get the best of both worlds, but we're doing this in a platform that is driving consolidation that we've got millions and millions of workflows on already and becomes very, very sticky. So from the standpoint of our next-gen SIEM, you've got to look at the next-gen SOC opportunity and what we're doing with Charlotte and the agents that we've created where we're driving meaningful change in the soc or overall driving down costs and getting better outcomes, and we're doing it in a compliant way.
To be a security vendor, you have to have trust, customers are driven by compliance, and we are the epicenter of creating this data. So what we also are open to is having an open model. We have customers that create their own agents that leverage our technologies that leverage our MCP services. And this is part of having an open platform, which is why our customers loved [indiscernible]
Our next question comes from Saket Kalia at Barclays.
Great finish to the year. George, maybe for you. The cloud security business, I think, is the biggest piece of kind of that 3 platform product group, if you will. And it's continued to add a consistent amount of net new ARR dollars over the last few years, which has been great to see. Maybe the question is how do you see the competitive environment in cloud security right now? And how do you think about the longevity of the growth in that market as you look out into the future?
Well, when we look at the cloud market, I couldn't be prouder of our execution and the products that we brought to market. One of the areas that we focused on, as you know, for a long time, is run time protection, and that's the technology that really is focused on stopping breaches. And I think customers have realized just by having the ability to understand sort of exposures doesn't mean you're going to stop the breach.
So with our CSPM technology with -- a lot of the other technologies that we have acquired like Falcon Shield, it has become an extremely potent offering for our customers. And again, why is it resonating? One, the technology works. Two, it all works together, and we're able to drive down cost, complexity and get a better outcome, which is stopping the breach. It's not just about reporting on some exposures. It's about understanding the overall control plane in the cloud and being able to protect it and we're giving the customers what they want, and that's the right outcome at a much lower cost than the competitors that are out there. So I think that's why in a nutshell you're seeing the results in our cloud business.
Our next question comes from Brian Essex at JPMorgan.
Congrats on some nice results. And Burt, congrats on the return to GAAP profitability. Really good to see. Maybe a quick question for you, George, on identity. Great to see the acceleration there. Could you unpack that business a little bit and help us understand, I mean, obviously, identity was 1 of the segments that was part of the CCP incentive plans that you guys were pursuing. How much of the resurgence in growth there on the identity side is I guess, renewal of CCP or Flex deals versus net new kind of emerging identity product. It would be great to get a feel underneath the covers there.
Well, it's one of the modules everyone wanted. And certainly, it was a fan favorite in days of CCP. So we're seeing success from that. And as I've mentioned many times, once a customer engages with the module is an extremely high percentage that they're going to continue to renew that.
So we continue to see that. But I think overall, you have to look at the threat landscape and the fact that identity is really one of -- the compromised identity, it's really one of the #1 drivers of breaches and customers are being are focused on being able to protect those identities, both in the cloud and on-premise, if you will, and there's a massive compliance need for something like. So we're getting the benefit from the platform consolidation piece, and we're also getting the benefit from having a very mature stack now.
Not only can we prevent these sort of reaches what ITD are, but you include now Falcon Shield protecting SaaS identities. -- and then you kind of look at what we've done with our PAM offering, it's been very, very well received by our customers. So I think that's why you're seeing our opportunity to continue to grow there. And as I said earlier, we couldn't be more excited about the SGNL AI acquisition that we just completed. .
Our next question comes from Brad Zelnick at Deutsche Bank.
Congrats on a really strong finish to the year, an impressive ARR guidance out of the gate for next year, implying 22.5% net new growth, which is above your prior commentary and now off of even a higher base. After such a strong fiscal '26, this obviously stands out in a very good way. Can you talk about the building block to get you there? And especially how to think about the renewal opportunity that you have visibility to and the expansion opportunity given just how much you can address today versus when many of those customers might have last transacted?
Brad, thanks for your comments, and I'll give you an insight into how we thought about the guide. I mean first and foremost, it starts with the strong momentum that we're seeing in -- we saw in Q4 a broad-based demand from all sizes of businesses from all business sizes, whether it's enterprise all the way down to MSPs.
And then that rolled over into Q1 when we talked about the record Q1 pipeline, which grew 49% year-over-year. Then as George mentioned, CrowdStrike is thriving in this AI revolution. We are not only leveraging AI within the entire platform, but our platform also helps organizations use AI security, and that's the key.
And then one think we're still benefiting from the consolidation tailwinds. Customers continue to seek the best outcomes at the lower TCO, which we're helped to provide. And the consolidation really comes from the strength of our platform. you look at cloud, NextGen identity and next-gen SIEM collectively, we posted our record net new ARR, resulting in $1.9 billion in ending IRR, up 45% year-over-year.
Looking Endpoint that accelerated for the second straight quarter on the heels of AI-driven demand. The menu peg onto that the success that we saw in Flex. We added over 350 Flex customers in Q4. The average Flex customer ending ARR that was over $1 million, those guys have adopted nearly 10 modules well over our company average and then re-Flex. We have greater than 380 re-Flex customers. The average time for our re-Flex is 7 months, 100 customers re-Flex multiple times with the average ARR lift post reflex for this cohort was 48%. These are really, really great numbers for us. And so you combine all those things and other things gave us the confidence to be able to come out with the guide that we came out with for that new ARR for next year. . .
Our next question comes from Matt Hedberg at RBC.
Congrats from me as well. George, I wanted to ask about pricing. Obviously, Flex and Re-Flex is doing extremely well, but there's obviously a lot of concerns that I think we're all seeing out there about potentially fewer knowledge workers sees in the future. due to AI. The flip side to that is way more Asian. So I guess a 2-part question. First, how do you think about agent pricing? And second, how well does Flex position customers for this potential mix shift in could consumption become a bigger element to the growth algorithm?
Well, when we look at the overall threat landscape and how we go to market, obviously, we protect endpoints and cloud workloads. You have to look at those in totality, but now we have the opportunity to protect AI agents and industry stats is that each knowledge worker will have 90 AI agents. So even if the mix moves around, we have a massive opportunity to protect AI agents.
We have a massive opportunity to protect all of these AI cloud workloads. And from what I've seen in different technology shifts, we tend to create more opportunity as technology advances, not less opportunity. So that's the way we would view that piece of it.
In terms of Flex, look, it's been a smashing success there's a reason why some so many other companies sort of copied or model we try to copy it. Customers like it. You can see the success in the numbers. And it just makes it so much easier to help customers very quickly. You look at the acquisition we did -- they were available immediately to customers as soon as the deal closed and/or we went to a GA, but we didn't have to go through another procurement cycle. So -- that's really the model that we're leading with going to market this year, and we couldn't be more excited about it, and I think the Flex results speak for themselves.
Our next question comes from Roger Boyd at UBS.
Okay. Great. George, I want to go back to your comments on why you're best positioned to benefit from AI SoC. And I appreciate your comments around your approach of tech plus human expertise and the [ flywheel ] that creates giving you an advantage in terms of operationalizing this technology. I think it's also made the lowest friction way for some enterprises to benefit from some of this emerging tech. .
And I guess with that in mind, what sort of growth are you seeing with some of the managed service offerings like completing Overwatch relative to the acceleration you're seeing in the overall endpoint business right now?
Yes. Those businesses continue to grow extremely well. And when you look at why it's because we're getting the right outcome that customers need. One of the things that we track is mean time to detection, meantime to remediation. We are absolutely best-in-class for customers.
It's very difficult for them to replicate what we do. Why? Because it's a network effect, right? It's the full view that we see in over 176 countries where we actually have our software operating.. So When you're at the tip of the spear in seeing the activity through our technology, the tip of the spear and responding to some of the biggest breaches in the world combined with our threat intelligence, you've got the right understanding and the right DNA to create the right technology and outcome for customers.
So that's what we continue to see. Obviously, they're leveraging our technology and we're providing the automation, but there are many, many customers who don't have the skills or expertise to get the outcomes that we provide, which is stopping the breach, identifying these sort of threats, remediating much faster than they ever could and ultimately giving them the best outcome for a cost that it's very hard to replicate. And that's why it's been a fantastic success for us.
Our next question comes from Gabriela Borges at Goldman Sachs.
George, I really appreciated your description on what LLMs are not not and as a [indiscernible] to the RHLF commentary. I want to ask you the opposite question. What do you think the role is of Anthropic in cybersecurity use cases, whether it's on the [ cutting ] side or the pen testing side or even the data allocation side, what role do you think they should have?
I mean I guess I'll talk just in general terms for LLM providers. And there's certainly a lot of things you can help sort through lots of data very quickly. And it's something that the security industry and most secure players are leveraging. In our particular case, we certainly leverage technology like that, but we've built our own bespoke models depending on the module and trained in a certain way, with the vertical expertise to get the right outcome.
Here's what you have to remember is that what customers want is real-time prevention, you have to be in line, you have to be able to get the data in milliseconds and you have to make a decision. That's not the case within LLM. There's many ratings it can do, and it's certainly a fantastic technology, but it's not stopping any breaches in real time.
And that's one of the areas, I think, again, where we shine. So from my perspective, we continue to work with them. We continue to partner with them and amazing technologies. And I think it really is going to be the better together approach as the industry goes forward. Customers want to leverage their own models. We leverage [ neumotron ] with NVIDIA. It's an unbelievable time to be in tech and you're going to have agents talk to agents and our agents talking to customer agents that are inside their network. But at the end of the day, as the platform system of record for security, this is where you want to be. It is a very sticky place. We create the data, we curate the data. And again, we want to be open and work with any of the models that are out there. and we want to meet our customers where they have AI and leverage their technologies as well as ours. .
Our next question comes from Todd Weller at Stephens..
Yes. Appreciate the question. George, this is the second quarter of endpoint acceleration. Can you talk about what's driving that, how you think about the durability of the growth acceleration? And then related to this, there's been a lot of action in the market recently around browser security. Do you see that as a new category or as an extension of endpoint?
Well, when you think about endpoint acceleration, it's a simple answer, AI. We've talked about it, and we're showing it in the results. And I mean one of the biggest things you look at, [indiscernible] comes out, our customers immediately are looking at all of our technologies to be able to identify it, put controls around it and make sure that they can leverage these technologies in an efficient and compliant way.
So that's where AI meets the -- rubber meets the road is at the endpoint, and that's how people consume it. So that's where we're seeing it. And then you combine that with browser security. That's really the front door now for how people are interacting with AI models and LLMs and the various technologies that are out there as well as how threats get into the environment.
So you combine that with our agent and the ability to have protection across any browser, not just as an organization to switch their browser. We can protect any browser that's out there. We tie it into our identity stack. And I can tell you the feedback from our customers as soon as we made the announcement, they were looking at how fast can we get this technology because they know on our platform, it's going to be additive for them. and we're excited about the category and the great company, Seraphic that we acquired.
Our next question comes from Dan Ives at Wedbush.
Yes. It's a great, great quarter, as always. I -- George, I was going to say what -- when it comes to Anthropic and Claude and obviously all the worries out there and you hear in the Q&A. To some extent, can't this also be a huge benefit to you as it just further spreads the word and customers realize essentially what they don't have and you do have, especially with the Microsoft partnership at the same time?
Yes, as I said in my prepared remarks, AI is a tailwind for us. And I mean I take a simple approach is will we have more AI in the next year or 2 or 5 years? And for me, the answer is absolutely yes. And if that AI is being deployed with AI agents, you're going to need protection, you're going to need something like AIDR. You're going to need identity security. You're going to need browser security. You're going to need compliance around this. And that's the way we look at it.
And again, we leverage the technologies that are out there. Why wouldn't we? And we have our own unique IP and our own model. So we get the best of both worlds. And there's many things that customers are looking for in these workflows and sort of data curation and knowledge in the security industry that you can't just get from a general LLM model. So I've talked about this before, and it's a great opportunity to work together, and that's really what we're focused on.
This concludes today's question-and-answer session.
All right. So thanks, everyone, for their time today. We appreciate your continued support and look forward to seeing you at our upcoming events. Thanks so much.
CrowdStrike Holdings Inc — Q4 2026 Earnings Call
CrowdStrike Holdings Inc — UBS Global Technology and AI Conference 2025
1. Question Answer
All right. We will get things going here. Thank you all for being here on day 3 of the UBS Tech and AI Conference. I have the pleasure of starting the day off with George Kurtz, Co-Founder and CEO of CrowdStrike.
George, fresh off earnings. Appreciate you being here on short notice. But yes, thanks for being here.
Great to be here.
Yes. Cool. I think I want to talk a lot about the high-level strategy here. But given we're just off earnings last night and before we get into the bigger picture, maybe just review some of the highlights from last night.
I felt like a very strong quarter on all regards. But in your words, what's about?
Well, I think if you look at the quarter, it was broad based performance. Obviously, our ARR stands out year-over-year, 7% growth. We had a lower comp, of course. But when you look across our product lines, including next-gen SIM, including cloud, including identity, these all accelerated.
So if you look at that, you look at our free cash flow, it was a record. You look at our gross margin for subscription 81%. We're getting big deals done Falcon Flex. We've doubled the reflexes. When you put it all together, what I would say is we delivered an incredible quarter, broad-based success across all the product lines and geographies. And I think it really shows the power of the single platform that we've built and the fact that companies are embracing what we're doing, particularly technologies like next-gen SIM and I'm sure we'll talk more about that.
Awesome. Maybe 2 quick questions in the quarter. This is, I think, the best quarter of net new ARR since, I think, calendar 4Q '23 I know you got this question last night -- or I know I got this question, I'm sure you did too. You acquired 2 companies in the quarter.
Can you talk a little bit about the contribution there? I think there was maybe some misinterpretation.
There was a lot of misinterpretation. We said de minimis, but de minimis means de minimis. It means $2.8 million of contribution. And there's some crazy numbers being thrown out there. So just to be crystal clear, was $2.8 million of net new contribution.
Yes. Very clear.
For the acquisitions, right.
And then the other question I got was just around the bottom line operating margin, EBIT. In many regards, this is a record quarter for non-GAAP operating income, EPS despite the fact that you closed 2 acquisitions, you had a record Falcon conference in September. Can you just talk about the operational execution? I know Burt is here somewhere. I'm sure we're pretty pleased with the quarter as well.
Yes, we are very pleased with the quarter. And I think when you look at sort of bottom line, what do you have in the quarter, where you have Falcon, which is our biggest selling event in the entire year, which drives the record pipeline, which we called out. And we did 2 acquisitions with de minimis revenue, right?
So we still have to absorb all the expenses of the folks that we brought over. And we still had a fantastic bottom line results. So I know when we look at this and we look at overall the performance, obviously, things that Burt and I focus on ARR, we focus on cash, free cash flow. And these are the things that help drive the business, and these were records for us.
Yes. Cool. Maybe zooming out, I want to talk about platforms. And last night, you talked about CrowdStrike as the operating system for security operating system for the stock. I think that idea demands a true single platform. So I'd love to get kind of your expanded thoughts on why that's so important, especially as we enter an AI attack landscape.
Yes. It's again, what's the ethos of cross right? It is the single agent single platform, and it's how I built the company. And I've learned from what not to do. I was at a prior company before, we did 21 acquisitions and it all looks good on the PowerPoint, but we can never get them integrated.
So you have to look at those lessons learned in the past and go, okay, I'm not going to repeat that. I see it being repeated in other parts of our industry, but we're not going to repeat that. That's why we've been so thoughtful about M&A.
And I know that's another topic we'll cover. But in a single platform, it really focuses on the data and the data architecture. And for me, data, in my opinion, can solve most security challenges that are out there. And I think most people would believe that data can solve that, whether that is a endpoint use case, whether that's a risk use case, whether that's an identity use case. If you have the data, you can not only identify things, but you can also prevent these breaches.
And it really does then set up all of the AI training that allows the operating system to work at scale. You mentioned that yourself. The SoC is transforming. It isn't just kind of alert and triage and alert in triage. It needs to have much more autonomy built into the stock.
And one of the things that I talked about at Falcon is CrowdStrike really being the first 2 security AGI. We've got a lot of efforts internally working on this. Now the industry has to get to AGI. But along with that, our goal is to map out and bring the industry to a level 5 autonomy. And if we think about the simple analogy of autonomous driving, you have an autonomous safer well, you have an autonomous SOC agent, right?
You have a Level 5 model in cars. And we mapped out a Level 5 model in security. So when you have that level of autonomous interactions, a, you've got to get it right; and b, it's just a different way to instrument and operate the stock, and we're really pioneering that.
Yes. Cool. I wanted to talk about Falcon Flex that you mentioned. And I think, in my view, it highlights what customers think of your platform. I talk to some of those customers who appreciate the flexibility it gives them to try out new solutions while still making a broader commitment to CrowdStrike. I think you now have $135 billion of ARR going through Flex contracts, growing very rapidly. What's going right there and where can that go from here?
Flex is something that we put together in combination with our customers. And it was really a demand from our customers saying, look, we want to do more with CrowdStrike. You've got -- I mean, I started with 1 module. We went public with 10. We've got 30-plus modules today and growing. And customers basically want the ability to leverage the entire platform.
So they came to us and said, how can you make it easier? How can you maybe take a page out of the hyperscale or playbook and give us a commitment model? It's not a consumption model, it's a commitment model. So customers commit, the more they commit, the better the dealers, they get a rate card for it. And then the entire product platform is opened up to them and friction-free procurement, right, you just have to go through it once. They can add a new product, and then it basically just burns down their commitment.
This has been, as I said on the call, often imitated, never duplicated. Ours, I think, is still differentiated from the others that are out there. that couldn't even kind of renamed their flex model. They just gave it something flex, which is, I guess, invitations the sincere for flattery. But in any case, it works, customers like it. And the key is they're consuming more of it faster than sort of the contract term, right? So if you had a 3-year contract term and you can -- as an example, consume it in 18 months, you're up for a reflex or even sooner.
So these are the dynamics that we're working with. And each customer is going to be a little bit different. But from a selling motion, it moves from, hey, here's another module. Here's another module to let us look at the outcome that you want. Let us look at how you want to consolidate and get rid of these 5 other products that don't work well and are costly and then move it all into Flex. And that's why we keep getting bigger and bigger Flex deals, yes.
I think it's really interesting, and that reflex activity remains super strong. You have 200 reflex customers that have shown up. And I know people have kind of equated this to an ELA. Like that doesn't sound like ELA buying motion...
It's not an ELA. The term ELA is banned from our company. This is not an ELA. It is a commitment model, again, very similar to what you would see in a hyperscaler. And we kind of view ourselves as a hyperscaler of security, having the model, having the platform, you have to have both together.
You asked me about the platform earlier. A big piece of having the platform is actually having the model, the licensing model that can help customers consolidate and be part of the platform journey. And you have to have both pieces. And we put both together and really, we're hitting on all cylinders with both areas.
Yes. Okay. I want to talk a bit about next-gen SIM, which continues to grow, I think, pretty close to 100%. It's almost $0.5 billion in scale. You called out a couple of key wins on the call last night. It feels like the legacy replacement cycle there is maybe accelerating a little bit? Is that a fair thing to say?
It does. It feels a lot like the legacy replacement of AV. So when I came out with next-gen AV. We were, again, semantic [ Mcfe ] all the big guys and nobody thought we had a chance. And we've seen how all that played out. It feels a lot like that in that customers are frustrated.
They're certainly frustrated with the cost. They're frustrated with the performance they're frustrated with the complexity. And they're looking for a new model this sort of alert and this triage is just getting old. There's too much data. It's happening too quick and humans just can't keep up with it.
So when you look at our next-gen SIM, the beauty of it, is -- and before we even got into the business, our customers were saying, like we're taking all of your EDR data, and we're putting it and paying to put it in another SIM and it's costing us a lot of money. Like 80-plus percent of the data that was going into a SIM was from CrowdStrike. So they said, why don't you just take the 20% that you don't actually create and take it into your platform? And that's what we've been able to do.
So what is maybe underappreciated is they don't have to pay for the 80% they generate. There's a retention fee and those sort of things, but the transfer they don't have to pay for. So this is a huge cost savings to them. This is why we can be very disruptive in the pricing because we already have the data. So it makes it a lot easier when you go do a rip and replace.
The one I talked about was a large bank in Europe. Not only did we replace their SIM, but we also added on them to it. And this pipelining technology is very exciting. So I think the combination of what we built having it integrated and EDR data is really the highest resolution data that's out there, combined with things like Charlotte AI, making a winning combination.
Beyond that brownfield replacement cycle, there's also a greenfield opportunity to sell in the customers who maybe never bought a formal SIM before. And I think that you're kind of reinventing that coming from a very strong EDR standpoint. How do you think about that opportunity, both directly and indirectly working with some of your managed security service provider partners?
Well, certainly, the big folks out there, big companies have SIMs. And I think what we've been able to do, and we've shown this over time as we've been able to take something that's very complex.
And we've been able to take that model and bring it down all the way to the SMB. So we did that with endpoint, [ NextAV ], those sort of things. So we have the ability to do that with SIM. When you think about the companies, and there's so many smaller companies that are out there, it could be million dollar company, it could be even a billion dollar company.
There's still a lot of risk that they have and having visibility into their security posture is important and even combining that with the managed service provider motion. So we think we can tap into the SIM market at a lower stratification than it's done before because for the most part, if you were setting up an enterprise SIM, it's a ton of complexity, you need lots of people.
And because of the way that the product works in the platform, it's very easy, it's natively built in. This is the other piece. Every customer we have has next-gen SIM. Now what do I mean by that? I want to be very specific. They have access to next-gen SIM, and we give them 10 gigabytes of next-gen SIM for free, okay? So then it's on us to be able to upsell them. So even the smaller customers, we have plenty of small customers that are using the 10 gigabytes, and we have the ability to grow that.
Very cool. Last question on SIM. Earlier this week at Reinvent, AWS announced that Falcon [ Flex ] SIM is going to be the default in for their customers and security hub. Can you talk about how important that is? And when you look at competition in the end market, some of the other hyperscalers are in some ways, your competition. I know has been a big partner for you. But what does this mean this next step?
Well, we're really excited about this announcement came at Reinvent. And if you look at 2 of the I guess 4 hyperscalers now sort of have their own, right? And this is a great, great addition to AWS so their customers can actually consume AWS data into a SIM that is now part of their stack. So you can go into your console, you can assume data flow it in and then pay as you go. And that is going to dramatically open up new customers for us.
It is pay as you go, so part of our selling motion will be to move them over to [ Apu ] subscription. And it's a win for AWS because it gives them native capability within the platform, which they didn't necessarily have before. So obviously, we just got going on it. We just announced it at Reinvent, which was this weakest obviously, a big runway ahead of us. But in terms of the opportunity, we're already hearing from people who are using it and liking the technology.
The other piece that I want to mention is what we did with F5. It's a very similar motion. So F5 worked with us, they said, hey, we want to put CrowdStrike on our F5 appliances, which one, if you look at the appliance landscape, these are one of the most attacked sort of surfaces, but nobody runs anything on them. So working in collaboration with F5, we were able to certify our sensor to run an F5, which was a great collaboration.
And now we have new customers coming to us saying, hey, we weren't a crowds customer. We use your technology with F5. It's way better than anything we have. We had no idea, and we want to get to an EBC, and we're doing that already, and we just announced it a couple of weeks ago. So if you look at what we did with and then you kind of look at AWS, we're going to hit a whole bunch of customers that we've never hit before in a whole bunch of different regions where we want to continue to build out our momentum.
Cool. I want to talk a little bit about the Onum acquisition. You talked about it being a game changer for the next-gen SIM product, and I think broadly your exposure to the observability market. Can you -- what does that do for you in terms of emerging trends in that space around federated distributed data structures? And what led you to the one acquisition in the first place.
Well, interesting, the Onum acquisition, I was talking to a customer and I was traveling and they said, hey, you got to meet this company. It's really cool. And I knew a little bit about them, and I was in town and basically set up a meeting 1 hour, met some folks and I'm like, okay, this really is good stuff. And if you look at the background of the founders, again, we buy teams in tech, right? You have to have the right team, you have to have the right cultural fit. They came out of [ ivo ].
So they knew they knew the whole SIM space. And they knew some of the problems associated with moving data, getting it in and duplicate data and costs and those sort of things. So they really built a next-gen pipeline and technology that can -- it's much more efficient in how it operates. It's not just designed to sort of reduce data and save cost. Yes, it can do that. But there's so much logic that's built into the pipeline. Now what that means is that as data is created and sense of were, they can actually apply logic to it in the pipeline.
So it has to move from point A to point B. And that logic can be security logic, so you can do detection in the pipeline even before it hits our SIM makes it really efficient or it can be IT sort of logic, like where you're looking for performance? Are you looking for sort of anomalies in sort of IT infrastructure data, if you will.
So that's why, to your point, of observability, we do have capabilities within Onum and then you combine that with LogScale, which, by the way, LogScale started at [ Jumia ], which is what we bought, 50% of the customers were observability customers. So we actually have the tech for observability, and we have more and more customers using it with their own sort of custom workflows.
It's more work we need to do around the workflows and some of the data that we take in, but it's all doable. So from that standpoint, if you only control the data fabric, I think it's a huge competitive advantage versus some of the other competitors that are out there, yes.
I wanted to go high level here and talk about AI in a few different ways. But maybe to start, last month, we saw state actors leverage an LLM to help propagate a tax on I think, 30 different enterprises. And I think we've always been talking about as an industry like this potential risk. But now that we're seeing it, like what is that doing to your customer conversations? Like are you hearing more concern? Is that elevating budgets what's the general level of panic over what we saw with them?
There's a lot of concern about it. And I sort of try to distill problems into time and money. I mean that's just make it easy. And there is a time element to this AI attack vector. And there's also a money element that it's much cheaper for adversaries to do it. But what it has done is it has massively compressed the window that a defender has to be able to protect themselves.
It used to be months and it was weeks, days, hours now and sometimes seconds. We've actually -- and we called this out 1 of our threat reports seen an attack or pivot from 1 system to another in 51 seconds, right? So incredibly quick. So AI is driving a lot of the tooling around this. And in this particular case, they were using a public model, and they were basically just driving new attacks and creating sort of what I'll call AI-type malware, that isn't really malware. It's more prompts, right?
So it can hit a system, and then it can basically say, what system on my hand, Well, what's interesting, what files are here, look at the files. Like there's no malware. It's just prompting and then it's creating scripts that will actually do that for the adversary on their behalf. So it's unique every time it hits a new system, it's unique, which again becomes a problem in the world, and that's why you need AI to fight AI.
Makes sense. The second AI theme question is how enterprises are thinking about securing AI, whether it's in first-party applications or API calls or through SaaS. And I've heard a lot of customers of your site interest in Falcon Shield, you talked about, I think, 50% sequential growth last night. You acquired Pangea to add functionality there. How are you helping customers grapple with challenges around securing applications?
Yes. So there's -- let me step back a little bit and when we talk about the AI applications, there's the AI creation, and we help secure that and then there's the applications, the use of AI, AI agents, et cetera. And I think where we see a huge opportunity, and I'll get to the -- some of the acquisitions is in the ability to secure these AI agents.
I talked about this in September at our event. There's a stat on average a enterprise sort of person will control about 90 different agents in the future. So all those agents are going to need to be protected. Very similar to the way we protect endpoints, right? They have access to data. they have access to compute. They have access to other agents. They have access to workflow.
So if you think about our opportunity, that we have in front of us. Everybody has a laptop or a device here, like we've built a huge business in protecting these technologies, cloud, et cetera. But we have a massive opportunity to protect all these AI agents. And now they're going to be at a different price point. If you have 90 of them, you're one person, it's going to be at a different price point, but it opens up a much broader opportunity for us.
So when you look at what we did with Pangea, Pangea not only provides technology around sort of prompt injection, guard railing, identity, those sort of things. But it actually has a whole building block layer. So if you're building AI applications, you can actually use the Pangea building blocks. And it's not something because we really are releasing it in Q4 because we're integrating it. We haven't talked a lot about it, but it's really exciting, so it could be part of the whole sort of building of AI applications where you can build the security into it. That's why we're excited about that acquisition.
And then Shield is amazing because you have a lot of SaaS applications with identity, certainly a lot of them driven by AI, shadow AI and Falcon Shield is immediate time to value. It's one of those technologies that when you run it, there's always a hot moment, and it's a very quick sales cycle. And we're getting a lot of net new business where customers just try it out, and they're like, wow, okay, once they're in the platform, then we have the ability to cross-sell them.
And the last point on AI is the use of AI to improve security operations and the idea of the genic so where we're headed. I've been pretty encouraged by some of the feedback I've heard about Charlotte.
I think -- the one example that stands out is a customer told me that they're regular seeing 3-hour investigations being done in a minute, and that trust level is increasing. At some point, like this is going to become a bigger deal. Do you feel like we're getting there is 2026, the year where we're going to see more adoption of some of the agenetic AI technology in the stock?
I think so. There's a cycle of AI adoption. I think everyone here would probably remember their first ChatGPT sort of [ mom and said ], wow, okay, that's really interesting, right? Then you started to use it and then there was people bringing the first power users we're bringing it into the enterprise.
And then the enterprise security folks and IT folks like, wait a minute, we got to control this thing, right, and then they kind of went through their motions and -- now we're in the deployment of AI agent. So we're in the early phase.
So as more and more organizations get comfortable with AI, they're going to drive more AI across their entire architecture, including security. There isn't too many companies that go into it that tell me, hey, I've got unlimited budget and unlimited people. Conversely, it's like, hey, budgets are tight and people are tight. We don't want to add more people. So how do we leverage AI? So Charlotte is a perfect force multiplier.
And the beauty of Charlotte is that we've taken a lot of what we do as 1 of the largest MDR providers, and we've built that into Charlotte. So think about the training data. We've got over 10 years of MDR data that we've annotated. And sometimes it's better to be lucky than good. You didn't know like Jenny was coming 10 years ago. But the training data was laid out in the way that made it really easy for us to do that. So that creates a moat in what I call the [ Reddit ] of security data, where we have all that, we're able to train Charlotte. So Charlotte has now become really a workflow orchestration layer.
And it's gone well beyond our competitors sort of chat bots, and that's why you're seeing customers go, wow, okay, this is really evolving. And like every week or 2, there's new capabilities, and it gets better and better and better. And again, we're driving towards that autonomous SOC. That is our vision. That's down the road, but you're going to see more and more adoption, obviously, of Charlotte, we get more training. And then people get more comfortable with allowing it to do more things autonomously.
So I would say a year ago, this felt like an AI agent for the SOC felt like a road map item that everybody had to have. It seems to me like it's showing up more in wins. You continue to highlight Charlotte and Flex deals. How do you think about like driving adoption there versus like customers coming in to try and pull it and try to monetize it. And is it conceivable at some point that like cloud security and same identity, we could potentially have a Charlotte segment disclosure?
Yes, that's a Burt question, but it's possible. on the disclosure side. When we think about the adoption of it, though, and what we're seeing is customers, they want something more than a chatbot. And I think to your point, 1 of your earlier questions, we've been able to build it within the platform. Like we just didn't slap together a chatbot and go here it is.
So we wired it into each of the modules, and we actually built our own smaller LOMs, if small ends. And basically, because it's built into the platform, it allows us to actually do work on behalf of the customer in our workflow. And that's vastly different than others, but the platform really sets up Charlotte and again, gets back to how things are built. Not all things are built equally. And it will continue to grow and at some point, maybe there will be disclosure around that. So we'll take that up with Burt.
8 Very good. Maybe 2 last questions or 3. Just on the M&A strategy and coming maybe full circle on the idea of a platform. You've always had a very disciplined approach to M&A. At Falcon, you did note that you're not ruling out larger scale acquisitions. Can you just talk about kind of the framework and the high bar you set for whenever you're looking at going external for R&D?
Sure. When we think about M&A and what we've done, and I think what we've been incredibly successful with is tech and teams, right? And I always say teams first really because if you don't have the right team, tech doesn't matter.
So techies matter. And we started there, and I think we have a great track record of these acquisitions. If you go down the list from Preempt to Humio, I mean these are all stars for us, Falcon Shield, et cetera. So that has worked well.
We're not ruling out doing something big, but it has to have a high bar. And my general philosophy, on an M&A deal is I say no to everything until I run out of nose. And then when I run out of those, it's a default, yes, that's how we get a deal done. That's how all of our deals got done.
So is there a larger acquisition that could potentially hit the yes, for sure. But again, we're not chasing ARR. If it comes with it, great. We want the best tech and the best team for the best outcome of our customers, and we don't want to dilute the value of the platform of what we built.
And we're going to see many others out there struggle we're trying to put piece parts together. And that's -- again, I got a lot of scars on my back from prior companies. I don't want to be in that situation. So I won't rule it out, but it's going to have to have a high bar.
At Falcon, you laid out a target for fiscal '27 for 20% net new AR growth. And last night, you reiterated that on a higher fiscal '26 base. Could you just parse out your confidence in that number and maybe more of a Burt question, but I'm for sure the answer is everything we've talked about thus far. But -- what's your confidence in that? I know you talked about record pipeline in 4Q, but...
Yes. Well, I think it does start with a record pipeline. You have to have some visibility looking out, right? You have to -- you look at where we are today, the acquisitions, what we've done, the integrations we've done, Falcon coming out of it, Falcon Europe as well. and customers just coming around. There's a lot of customers -- new customers that are coming that might have been with another vendor through a life cycle.
They might have had a 3- or 5-year deal that are now coming up, going, okay, like they're dissolution, the dissolution with the outcome and the cost. And they're talking to their peers, and we're solving really hard problems. And if you talk to them, and I encourage you, and I know you do, but if you talk to most customers, we're the #1 security control they have.
Number one, right? And what do they do? They talk to their friends in the industry and go, what are you doing different? Like CrowdStrike. So that continues to build. And I think when you look at our road map, you look at the pipeline, you look at the market opportunity, particularly with AI in the areas that we're leading in that gives us confidence. And at our scale, there's not many 20% growers. I mean we're in rare, right?
So from my perspective, I think it's all coming together and you've got this tectonic shift in technology with AI that's going to help really drive that into the future years, awesome.
I think that's a great place to end things. But this has been a great conversation. George, thank you for being here. And thank you all for listening in.
Fantastic. Thank you so much.
CrowdStrike Holdings Inc — Q3 2026 Earnings Call
1. Management Discussion
Hello, and welcome to CrowdStrike's Fiscal Third Quarter 2026 Financial Results Conference Call. [Operator Instructions] Please be advised that today's conference is being recorded.
I would now like to hand the call over to Andy Nowinski, Vice President of Investor Relations and Strategic Finance. Andy, please go ahead.
Good afternoon, and thank you for your participation today. With me on the call are George Kurtz, Chief Executive Officer and Founder of CrowdStrike; and Burt Podbere, Chief Financial Officer.
Before we get started, I would like to note that certain statements made during this conference call that are not historical facts, including those regarding our future plans, objectives, growth, including projections and expected performance, including our outlook for the fourth quarter and fiscal year 2026 and any assumptions for fiscal periods beyond that are forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995.
These forward-looking statements represent our outlook only as of the date of this call. While we believe any forward-looking statements we make are reasonable, actual results could differ materially because the statements are based on current expectations and are subject to risks and uncertainties. We do not undertake and expressly disclaim any obligation to update or alter our forward-looking statements, whether as a result of new information, future events or otherwise. Further information on these and other factors that could affect the company's financial results is included in the filings we make with the SEC from time to time, including the section titled Risk Factors in the company's quarterly and annual reports.
Additionally, unless otherwise stated, excluding revenue, all financial measures disclosed on this call will be non-GAAP. A discussion of why we use non-GAAP financial measures and a reconciliation schedule showing GAAP versus non-GAAP results is currently available in our earnings release, which may be found on our Investor Relations website at ir.crowdstrike.com or on our Form 8-K filed with the SEC today.
With that, I will now turn the call over to George.
Thank you, Andy, and a warm welcome to the CrowdStrike team. Andy is no stranger to many on this call, and I'm glad to have him with us to lead Investor Relations.
I'm excited to share CrowdStrike's fantastic Q3. It was a record quarter as the business continued accelerating. On the back of record attendance at Falcon Global and Falcon Europe, the momentum we're seeing with customers, prospects and partners drives my conviction in our near-term and long-term growth.
Last quarter, Q2, we delivered our forecasted reacceleration a quarter early. This quarter, we furthered the trend with relentless execution. Across the entire CrowdStrike team, I'm extremely proud of our Q3 with highlights including: one, record Q3 net new ARR of $265 million, which grew 73% year-over-year, beating our expectations by more than 10%; two, ending ARR of $4.92 billion, which accelerated to 23% growth year-over-year; three, record Q3 free cash flow of $296 million or 24% of revenue; four, all-time record operating income of $265 million or 21% of revenue, this is the second consecutive quarter of record operating income; five, broad-based ending ARR acceleration across cloud, Next-Gen Identity and Next-Gen SIEM collectively as well as acceleration in our endpoint business; and six, more than $1.35 billion in ending ARR from accounts that have adopted the Falcon Flex subscription model, growing more than 200% year-over-year.
Underpinning these financial highlights is the CISO, CIO and Board feedback I regularly hear. CrowdStrike is mission-critical in today's agentic society. No matter how the market swings, geopolitical tensions evolve or what technologies are in vogue, our digital society mandates cybersecurity as a necessity. And now more than ever, synonymous with that, CrowdStrike is a necessity.
Our growth is driven by pervasive, durable and thematic market forces. Organizations of all sizes are in the midst of AI transformations, investing in the future of workforce productivity in the name of speed, scale and cost benefits. In the midst of this societal shift, what I've shared over the past few years and quarters is unfolding before our very eyes.
One, AI is rapidly expanding the attack surface. Businesses are onboarding a whole new type of workforce today, the agentic workforce, humans using agents to do more and agents working by themselves, each with access to data, applications, compute and sometimes even other agents.
While the benefits of this newfound workforce are exciting and increasingly vital for market competitiveness, the rapidly expanding risk profile of this realm cannot be ignored. Every single agent expands the attack surface, necessitating protection. CrowdStrike is both the armor and intelligence layer that keeps each agentic identity secure. The intelligence layer, providing visibility and context to organizations from agentic threats and risks, and the armor protecting agents from attacks, influence, exfiltration and data manipulation.
In addition, CrowdStrike is also present as the foundational protector of the underlying technologies powering the AI revolution, providing security by design for the world's cloud and token factories.
Two, the democratization of destruction wasn't just a bold prediction, it's already today's reality. Businesses every day are having jarring, lightbulb moments witnessing AI-powered adversarial trade craft firsthand. Just a few weeks ago, a major AI company shared that China state-sponsored adversaries were using their LLM to create and operationalized active cyber intrusion agents. This is just one of the many AI-enabled attacks we've seen. The AI cyber battleground is no longer theoretical, it's now real. Now just as anyone can use AI to vibe code and become a software engineer, anyone can now also vibe hack, becoming a sophisticated adversary with AI.
Three, cybersecurity in the agentic era demands a single platform. The criticality in being able to operate with agility, efficacy and speed to stop breaches is having the data, the controls and the actions in a single platform, not multiple platforms because when you have multiple platforms, by definition, you don't have a platform. Tab switching and contact switching cost time, data stitching doesn't scale. These are the seams and cracks where adversaries thrive.
The leaky lifeboat of PowerPoint platforms and point product fragments simply cannot offer the protection, scalability and cost benefits or the ease of use of a single platform solution. CrowdStrike wins as the market's broadest and only single platform solution.
Taking my 3 points together: One, we've built the right architecture, a single console, single data backend, single sensor, agentic hyperscale platform that is frictionless and one of a kind in cybersecurity; two, it's the right time with the rapid growth of AI agents raising the threat risk profile and driving a holistic technology shift; and three, we're in the right position. CrowdStrike's technology, innovation engine and ecosystem position us as the operating system of cybersecurity for the agentic era.
Market demand is high because the need is real. We have the right architecture, we have the right products and we're in the right market position to continue taking share. Successful AI adoption requires cybersecurity transformation, necessitating a new operating system to create a structure around the next chapter of enterprise security programs.
Falcon Next-Gen SIEM is the foundation of our platform, turning CrowdStrike into our customers' operating system for cybersecurity. Next-Gen SIEM has become a scale disruptor in a market that has historically been slow to evolve as customers embrace the speed and efficiency advantages versus legacy competitors. And with the acquisition of Onum, we're making it even easier to build on CrowdStrike with a hyper scalable telemetry detection pipeline that brings CrowdStrike even closer to all our customers' critical data.
Falcon Next-Gen SIEM had a record net new ARR quarter, a clear outcome of the deliberate strategic choices we've made over the past several years. We know that the value of the technology is only as good as the platform on which it's delivered. So we invested heavily in integrating Next-Gen SIEM to create a unified single platform.
This isn't just a single console. It's a truly integrated and unified data backend that brings together all of CrowdStrike in one place, delivering not just economies of scale, but far superior outcomes. And with Charlotte as the agentic SOC orchestrator, now FedRAMP High approved, we're delivering the AI SOC of the future today.
Furthering our position as the operating system of cybersecurity, we recently announced our expanded partnership with AWS. Through this announcement, all of AWS's millions of customers will have access to Falcon Next-Gen SIEM natively within their AWS security console, enabling them to immediately access, interact with and analyze AWS telemetry directly in Next-Gen SIEM. Going a step further, we've also enabled federated search so that AWS customers can query their data from a single console.
We're incredibly excited about what the future holds and thank AWS for both our amazing partnership and for their validation of Falcon Next-Gen SIEM as the best choice for their customers. A large European bank renewed their more than 500,000 workload EDR deployment, adding Next-Gen SIEM, Onum and Charlotte in a large 8-figure expansion deal. With our acquisition of Onum, this financial institution was able to eliminate their existing streaming pipeline point product as well as migrate off Splunk.
Competing against hyperscalers and firewall vendor SIEMs, Falcon Next-Gen SIEM won the hearts and minds of the security and IT team as the easiest solution, fastest to see value and best agentic SOC transformation platform.
Our identity business continues to perform exceptionally well. While the demand for our ITDR offering has increased, it's the launch of both our PAM and Falcon Shield offerings that has our customers increasingly excited. Falcon Shield had a record net new ARR quarter, growing nearly 50% sequentially as market demand for SaaS application security has become a mainstream necessity, securing SaaS app misuse from human and nonhuman identities has never been more important or challenging.
Nefarious agentic behavior is targeting data-rich SaaS applications that have quickly become a feeding ground for breaches. From on-prem apps to cloud apps, we stopped these breaches. A Fortune 500 logistics company used Falcon Shield to uncover exfiltrated CRM data in less than 30 minutes from deployment, resulting in a 7-figure deal. A leading customer experience platform saw a Shield demo and activated the module via Flex within an hour.
And lastly, a Global 500 personal care leader conducted a Shield assessment uncovering 25 unknown shadow instances of their CRM. This customer quickly transacted a 7-figure expansion, bringing their SaaS environment under control. As these examples illustrate, today's elevated third-party SaaS risk environment demands visibility and protection. Falcon Shield delivers near immediate time to value and is a product that we can land new logo accounts with even without endpoint deployments.
Turning to the cloud, where we delivered Q3 record net new ARR. While CrowdStrike continues to benefit from M&A-related market disruptions, it is our customers embrace of best-in-class runtime protection that continues to push us forward. As the cloud security market matures, customers are realizing that posture doesn't equate to prevention. Security teams now understand that they need active defense within their cloud environments, and this can only be delivered in runtime. CrowdStrike is the cloud runtime security leader as validated by the most recent Frost & Sullivan CWP report.
And with our recent acquisition of Pangea, we're now positioned to protect the entirety of our customers' AI infrastructure. At our recent Analyst Day at our Falcon conference, we discussed how protecting AI is akin to protecting a building. Security teams don't want a nonintegrated, fragmented series of solutions to protect their critical AI infrastructure because they know that this complexity creates gaps that are increasingly exploitable by AI-enabled adversaries.
CrowdStrike Falcon Cloud Security offers customers a unified, integrated end-to-end solution that enables secure adoption of transformative technology without slowing the end user down. A Fortune 500 consumer packaged goods company grew their Falcon deployment with Falcon Cloud Security in a 7-figure expansion deal. This customer took the opportunity to displace Wiz, bringing their cloud security program to Falcon for the benefit of our consolidated CSPM, ASPM, CIEM and CDR approach. The outcome delivered is single platform management, better visibility and the ability to stop cloud breaches versus simply alerting on them. This was just one of multiple Wiz replacements.
In addition, Falcon Cloud Security was selected to protect a leading neo cloud in an 8-figure transaction. This token factory decided it was time to secure AI from the source so that enterprises of all sizes would trust and build with confidence on them. Cybersecurity became a differentiator and business enabler, not a cost.
And finally, I wanted to touch on our endpoint business. Our endpoint business accelerated in the quarter on the heels of AI-driven demand. In the world of AI, so much is being pushed to the edge. Employees are now deploying new applications such as cloud desktop and ChatGPT directly onto their machines, driving both rapidly improved productivity and also significant new risks. This is further exacerbated by the rapid adoption of new AI browsers such as Comet and Atlas, which bring new opportunities and concurrently new vulnerabilities and threats.
AI adoption is supercharging renewed interest in the endpoint as the endpoint is the epicenter of human and nonhuman interaction with AI. In this new agentic world, the endpoint has quickly become the risk point, the productivity point and the opportunity point.
A large government agency took the opportunity to modernize, replacing more than 75,000 endpoints of legacy AV with Falcon as well as deploying us in their AWS environment for cloud protection in what was a strong federal quarter for CrowdStrike.
In addition, EY brought us into a Fortune 500 health care account, where in just a few months, we were able to modernize the endpoint, cloud and SIEM environments, an 8-figure end-to-end Flex expansion deal where we displaced 2 SIEMs, Defender for endpoint and a point cloud security product.
Frequently imitated but never duplicated, Falcon Flex makes it easier than ever for our customers to experience the full power of the Falcon platform without procurement friction. The Flex model cultivates more platform utilization, accelerating module adoption. Falcon Flex is an unlock, not an ELA.
Flex customer ending account ARR more than tripled year-over-year. But what has us even more excited is the momentum we're seeing in reflex activity. The number of reflex accounts more than doubled quarter-over-quarter to more than 200 with 10 customers reflexing more than 2x their initial Flex subscription. This demonstrates that Flex customers can and do increase their ARR and TCV spend with CrowdStrike, which is contrary to the ELA model, where all the economic value is realized once upfront.
When we launched Flex, we believe that it would allow customers to more quickly benefit from the full value of our platform, and that's exactly what's happening. As customers and partners alike continue to embrace Flex as the best way to adopt Falcon, we expect it to become our licensing standard.
Our community or crowd powers our technology, and that's who we build for. Our ecosystem partners continue leading us to new heights, affirming CrowdStrike's market and category leadership.
Our Alliance team delivered a record quarter in terms of deal value closed with partners. CrowdStrike's market position comes to light in mission-critical times. F5 asked us to partner with them to further secure their BIG-IP hardware and virtual appliances. We rapidly deployed our sensor on BIG-IP, which they certified and F5 took the opportunity to purchase Falcon and OverWatch licensing for their installed base in a large Flex transaction.
We are pleased to be taking our industry-leading protection capabilities to new insertion points, designed to enhance network perimeter protection. Today, hundreds of F5 customers are now securing their F5 appliances with CrowdStrike, many of whom weren't CrowdStrike customers prior.
Partners take us into new account environments, implementing Falcon as part of their broader agentic enterprise architecture vision. Experiencing the success of Next-Gen SIEM in the market, EY took a bold step to standardize their SIEM practice on Falcon in a large 7-figure transaction. EY is migrating accounts for which they own and operate multiple legacy SIEM technologies, consolidating on CrowdStrike.
Additionally, EY is a leading global partner of ours for Next-Gen SIEM implementations, taking numerous Fortune 500 accounts through the journey from legacy SIEM to Next-Gen SIEM migration. Deloitte announced Next-Gen SIEM in their MXDR practice, replacing their legacy SIEM provider. And Wipro, too, has standardized security delivery and incident response on Falcon.
The GSI community is quickly seizing the SIEM and SOC transformation opportunity that only our single platform provides. The ecosystem embrace of partner-led services on Falcon is correlated to the opportunity we represent. A recent Canalys report showed that our ecosystem creates up to $7 in services opportunities for every dollar of Falcon product sales, illustrating the large ecosystem opportunity surrounding the Falcon platform.
I want to return to yesterday's announcement that we made with AWS. AWS selected Falcon Next-Gen SIEM as the default SIEM for all their customers offered in their Security Hub console. This brings Falcon Next-Gen SIEM with prepopulated AWS data to millions of AWS customers in a product-led growth motion. Our intent is to convert Next-Gen SIEM usage into Flex subscriptions as more accounts experience the power, speed and actionability of their AWS data, CrowdStrike data and other third-party data in Next-Gen SIEM.
Our Next-Gen SIEM helps AWS fill a critical market gap, now competing with other hyperscaler SIEMs and doing so with Falcon. Our Next-Gen SIEM delivers value for AWS customers, even those who don't yet use Falcon because we've become a federated prepopulated and affordable security data lake for observability, triage and threat hunting. And Charlotte is there to help operate the whole system on a customer's behalf.
In addition, Accenture is our launch partner with AWS, helping AWS customers leave their legacy SIEM for Falcon Next-Gen SIEM on AWS. Our partnership with AWS continues from strength to strength with CrowdStrike announced as AWS's Global Security Partner of the Year and AWS's Global Marketplace Partner of the Year yesterday at re:Invent. We're excited about the opportunity to engage AWS accounts, onboarding them to Falcon and serving as their operating system for cybersecurity.
Lastly, I want to share a noteworthy MSSP partnership, which we've announced today with Kroll, a leading mid-market professional services firm. Kroll's cybersecurity division performs thousands of incident response engagements yearly for mid-market firms around the world, largely from their cyber insurance panel inclusion. Kroll had been using a point product EDR in their incident response and managed detection and response business.
Now Kroll exclusively uses Falcon. And in an almost 8-figure rip and replace transaction, Kroll is migrating nearly 0.5 million endpoints to Falcon, which were previously running on a point product SMB EDR and up-leveling their own MDR service with Falcon Complete for service providers with our Falcon Complete team becoming the SOC for Kroll.
This partnership announcement illustrates the value that only CrowdStrike can deliver, the best technology platform with numerous expansion opportunities to help customers and partners alike consolidate, the services opportunities partners need to see value, whether that be an incident response, proactive assessments, managed detection and response or SOC transformation and our scaled and agentic MDR teams to up-level partners so they can focus on selling and client services while we focus on stopping breaches as the world SOC.
We've improved Kroll's technology stack, displaced an inferior point product, improved their margins with Falcon Complete and they migrated their entire practice to us. This transaction highlights the power of Falcon to be a business creator for our ecosystem. We're not selling products. We're delivering outcomes, introducing the world to a whole new way of performing cybersecurity and risk management.
In closing, this was one of our very best quarters in company history. Acceleration is back. We're winning and we're living the company's mission of stopping breaches. AI represents our largest opportunity and demand driver yet. We're using AI to revolutionize cybersecurity. And even larger, we're securing the world's use of AI, so businesses of all sizes can adopt more AI faster, securely and with confidence.
The takeaway is this, AI adoption necessitates the right cybersecurity. It necessitates CrowdStrike. Jensen Huang summed up our market position best saying, "I can't imagine a better defender than CrowdStrike," on the stage at NVIDIA GTC in Washington, D.C. The transformative work we're doing with NVIDIA is representative of how we're securing AI at its very source, all the way down to its human and nonhuman users and its outcomes. I see this as a generational opportunity for the company.
AI is but one of many tailwinds continuing to propel CrowdStrike to new heights. One thing is certain, whenever our customers engage in technology change and transformation, cybersecurity has been a constant necessity, and that constant is CrowdStrike.
With that, we have a big Q4 opportunity in front of us, a robust demand environment and no shortage of breaches to stop. Cybersecurity doesn't slow down for the holidays and neither do we. Stay safe, happy holidays, and I'll pass the call over to Burt Podbere, CrowdStrike's CFO.
Thank you, George, and good afternoon, everyone. As a quick reminder, unless otherwise noted, all numbers, except revenue mentioned during my remarks today are non-GAAP. Additionally, the results we are reporting today include the acquisitions of Onum and Pangea, which closed during the quarter and were de minimis to revenue and ARR.
We delivered an exceptional third quarter driven by organic growth, exceeding expectations across all guided metrics. We achieved record Q3 net new ARR of $265 million, exceeding our expectations by double-digit millions and more than 10 percentage points.
Net new ARR growth accelerated to 73% year-over-year and ending ARR reached $4.92 billion, accelerating to 23% growth over last year.
As George highlighted, our performance reflects the success of our single platform strategy as organizations prioritize cybersecurity in the agentic era and customers consolidate on Falcon as the operating system of the SOC.
We delivered acceleration across the platform with cloud, Next-Gen SIEM and Next-Gen Identity, all delivering strong results. Momentum was broad-based across customers of all sizes from enterprise to down market and MSSPs, achieving record results in our corporate business and strong performance in the public sector, particularly in U.S. federal and higher education.
Falcon Flex continues to be a powerful driver of platform consolidation with over $1.35 billion in ending ARR from accounts that have adopted the Flex subscription model. Falcon Flex is quickly becoming the standard licensing model as it makes it easier for customers to adopt more of the Falcon platform faster.
Customers continue to leverage Falcon to consolidate their security needs and lower their total cost of ownership, resulting in higher retention rates over the prior quarter and increased module adoption rates.
As of Q3, 49% of subscription customers are now using 6-or-more modules, 34% are using 7-or-more and 24% are using 8-or-more modules. With our business momentum increasing and our all-time record high pipeline entering Q4, we have strong conviction in our ability to deliver profitable growth as we finish FY '26 and look into FY '27 and beyond.
Moving to the P&L. Total revenue exceeded our guidance range and grew 22% over Q3 of last year to reach $1.23 billion. Subscription revenue grew 21% over Q3 of last year to reach $1.17 billion and professional services revenue was $65.5 million.
The geographic mix of third quarter revenue consisted of approximately 67% from the U.S. and 33% from international geographies with both U.S. and APAC year-over-year revenue growth accelerating compared to Q2.
Total non-GAAP gross margin was 78% and non-GAAP subscription gross margin increased to 81% of revenue. Total non-GAAP operating expenses in the third quarter were $703.2 million or 57% of revenue.
In Q3, we saw a typical step-up in sales and marketing expenses from our annual Falcon conference we hosted in September, which was our biggest selling event of the year and set multiple records with over 8,000 attendees joining us.
Non-GAAP operating income was a record $264.6 million, and operating margin was 21%, exceeding our guidance. The outperformance was driven by our strong top line performance, gross margin improvement and sales execution, underscoring our commitment to profitable growth as we balance accelerating net new ARR growth with operational excellence.
GAAP net loss attributable to CrowdStrike was $34.0 million, which included $26.2 million of costs associated with the July 19 incident and related matters and $5.6 million of acquisition-related expenses. Non-GAAP net income attributable to CrowdStrike was a record $245.4 million or $0.96 on a diluted per share basis, exceeding our guidance.
Moving to cash. Our cash and cash equivalents were $4.80 billion. We generated record cash flow from operations of $397.5 million and record Q3 free cash flow of $295.9 million or 24% of revenue. Payments for incident-related and strategic plan costs impacted Q3 free cash flow by approximately $53 million.
Moving to our outlook and modeling notes. The AI-driven demand environment, combined with our record pipeline and the continued momentum in customer platform consolidation on Falcon gives us strong conviction as we finish Q4 and look toward FY '27.
While we do not guide to ending ARR or net new ARR, our revenue guidance includes the following assumptions: Low to mid-teens sequential net new ARR growth Q3 to Q4, bringing ending ARR growth for FY '26 to 23% year-over-year. At the midpoint of our net new ARR assumptions, we expect second half net new ARR growth of at least 50% year-over-year, well above our previously provided assumptions of at least 40% year-over-year, driven by our strong Q3 outperformance and record pipeline. Additionally, we continue to expect FY '27 year-over-year net new ARR growth of at least 20% from our now increased FY '26 net new ARR assumptions.
As we discussed during our September investor briefing, as a result of our successful CCP and related partner programs, our ARR to subscription revenue assumptions include a separation of $13 million to $15 million in Q4. Consistent with what we noted at Falcon, this gets you to the midpoint of our FY '26 revenue guidance, which we have raised by $24.1 million at the midpoint to reflect our strong Q3 outperformance and a record pipeline. We ask that you please be mindful of these dynamics when updating your models.
Moving to cash. We expect Q4 free cash flow margin to be 27% and include cash payments of approximately $33 million in connection with incident-related costs. This brings our full year FY '26 free cash flow margin expectation to 25%.
Finally, we remain confident in our previously provided assumptions for FY '27 partner rebates, non-GAAP operating margin and free cash flow margin, which are detailed in the modeling assumption slide of our Q3 FY '26 earnings presentation available at ir.crowdstrike.com following our prepared remarks today.
Moving to our outlook. For the fourth quarter of FY '26, we expect total revenue to be in the range of $1.290 billion to $1.300 billion, reflecting a year-over-year growth rate of 22% to 23%. We expect non-GAAP income from operations to be in the range of $315 million to $319 million and non-GAAP net income attributable to CrowdStrike to be in the range of $282 million to $287 million.
We expect diluted non-GAAP net income per share attributable to CrowdStrike to be approximately $1.09 to $1.11, utilizing a 21% tax rate and weighted average share count of approximately 258 million shares on a diluted basis.
For the full fiscal year of 2026, we currently expect total revenue to be in the range of $4.797 billion to $4.807 billion, reflecting a growth rate of 21% to 22% over the prior fiscal year. Non-GAAP income from operations is expected to be between $1.036 billion and $1.040 billion. We expect fiscal 2026 non-GAAP net income attributable to CrowdStrike to be between $950 million and $954 million. Utilizing a 21% tax rate and approximately 256 million weighted average shares on a diluted basis, we expect non-GAAP net income per share attributable to CrowdStrike to be in the range of $3.70 to $3.72.
George and I will now take your questions.
[Operator Instructions] Our first question will come from Brian Essex with JPMorgan.
2. Question Answer
Nice results. And Andy, congratulations on the new role. Maybe for George, great to hear the acceleration in the endpoint segment of the business. And I know you guys aren't giving any update until year-end on the emerging segments of the business. But could you offer a little bit of color of how those segments are behaving as you kind of lap the initial CCP initiatives of last year?
And then maybe for George -- I mean, maybe for Burt, I know you're not offering any kind of impact from Pangea and Onum on ARR, but any sense of the seasonality, organic seasonality for net new ARR?
Yes. Brian, thanks. Yes, when we look at, obviously, the emerging products, which was the heart of your question, they performed fantastic. If you look at Next-Gen SIEM, it's been an all-star standout for us. We've seen just incredible results from a customer perspective and what they're able to do and driving down the cost and get better outcomes.
Identity as well, that's key to the -- securing AI in an enterprise. And then obviously, cloud, we talked about some of the big wins throughout the quarter. So when we look at those segments, and as you mentioned, we'll be reporting out on those next quarter, we're very, very pleased on the results and customers are embracing the technology and the consolidation the single platform delivers. So from that standpoint, I think we're very happy.
And then as we lap the CCP, CCP was designed to do exactly what we delivered, right? We helped customers through a situation. And also, we provided a way to accelerate Flex adoption, and we've seen that with our Flex license adoption throughout the quarter, which we called out. And then obviously, we had a fantastic endpoint quarter, which continues to help drive all the other modules. So overall, I couldn't be happier with the quarter that we just put up.
Yes. And on your question with respect to Pangea, I think that I called out that we have got a de minimis impact from both a revenue standpoint and net new ARR. And we're excited that those are going to roll into the platform in Q4. So that's how we think about it.
Your next question will come from Saket Kalia with Barclays.
Great quarter, and congrats, Andy. George, maybe for you. I just want to pick up on your comment earlier on SIEM. It feels like the SIEM market is starting to see more velocity of displacements. Can you just maybe talk about what sort of value you're able to capture in those opportunities compared to what customers were maybe spending before? And then maybe relatedly, how do you kind of think about the timetable for legacy SIEM renewals in the coming quarters, years, which, of course, I imagine you'd be targeting?
Yes. So I'll try to wrap this up into one answer here. But Saket, let me just kind of lay this out, if you look at the journey that we've been on and how we've been able to replace legacy AV, it feels a lot like that market in the early days when we think about replacing legacy SIEM, customers are looking for better outcomes. They're looking for faster results, and they're looking for lower cost. And because we already have the EDR data in the platform, we can offer disruptive pricing versus our competitors. The most -- the stickiest data that's out there is the EDR data, we already have it.
And really, what it becomes is a journey to activate Next-Gen SIEM for our customers. So when we think about the opportunity to work with customers and how we get in and the opportunity going forward, keep in mind, all of our customers are Next-Gen SIM enabled, all of our customers are Next-Gen SIM enabled. It's a huge difference between us and everyone else in the marketplace. And all we need to do is go through the licensing exercise, and Flex is helping to accelerate that. So we can offer competitive disruptive pricing and then overall grow our total wallet share with the customer over time. So it's a multiyear long-tail journey that feels very similar to the displacement of legacy AV.
Your next question will come from Matt Hedberg with RBC.
Congrats from me as well on the quarter and Andy to you as well. George, building on your Next-Gen SIEM success and Onum and a little bit related to Saket's question, do you see a further push into observability? Obviously, there's been some movement with some of your cyber competitors to go deeper into observability. Just curious on kind of how you view that market? And is that a consolidation opportunity for you as well?
Well, we do view it as a consolidation opportunity. And I'll remind everyone on the call that when we acquired Humio, which became LogScale, 50% of their business was actually in observability. So we have all of the technology. And in fact, because the platform is collecting so much data and so much telemetry, we have customers today that are using it for observability use cases. You combine that with our agent technology, which does deep inspection within its platform. And we have data that goes well beyond security data that is already being consumed by customers.
And then you combine that with Onum pipelining technology, the data fabric, which again has the ability to take IT data. And we have a fantastic opportunity in front of us to consolidate in those areas, which, again, this is nothing new to us, we've actually been doing this. And this has been part of our selling motion as well as what customers are embracing. So it's already there, and there's certainly more that we can do and certainly more we will do.
Your next question will come from Gabriela Borges with Goldman Sachs.
Question for Burt. So CrowdStrike has years and years of data on customer cohorts and how your customer cohorts typically expand with you over time. You've now got several quarters of data on Flex and how the Flex customers expand with you over time. There's a piece of this which is structural, which is you're making it easier for customers to consolidate with you. But I'm wondering if there's also a dynamic where you see an elevated tailwind to NRR for a period of time because of Flex and Flex starting with your best and most excited customers and then perhaps normalizes lower. So my question for you is how do you think about that dynamic? How do you think about the tailwind that Flex is driving in the model and how sustainable that is?
Thanks, Gabriela. So the way I think about this is our Flex licensing, it's continuous. Net ARR will be continuous throughout time. And the beauty of this whole program is that it's designed for customers to easily buy more. So over time, we're excited about the opportunity as we bring more products to market and offer more availability to our customers easily. And I think that's the biggest piece that everybody on the call should just remember is that, that's exactly what Flex was designed to do, make it easier for customers to buy, make it very easier for us to be able to deploy and be able to give value and lower TCO. That's how we think about it.
And the benefit is that we're seeing bigger deals and longer deals. And that's all good for us, and it's great for the customers. And I think the most important thing is and not get lost in things I've just said is consolidation. We started this company talking about consolidation, the ability for customers to do more with us, spend more with us and lower their total TCO but spending more with us. So I think that's the biggest point that I want to drive home.
Your next question will come from Dan Ives with Wedbush.
And also congrats on the Mercedes deal, George. Can you just talk about AI? Like as you're starting to see more and more deployments, talk about how that's changing the conversations with customers, even over the last 3, 6, 9 months relative to where CrowdStrike sits. Can you maybe just give some insight into how those have changed from your perspective?
Yes. Great. Thanks, Dan. Thanks, as always. Yes, when we think about the conversation of AI, what customers have realized is that CrowdStrike is probably the only company in security that's moved beyond chatbots. And what I mean by that is Charlotte AI and its related agents are deeply embedded into the platform. At our last Falcon in Europe, we talked about 11 AI agents and AgentWorks, which allows our customers to actually create their own security agents, which we think is going to be a massive opportunity for us.
So it's moved from chatbots to actual doing work, and this is something that we continually hear differentiates us from our competitors. Our competitors are still stuck on chatbots where we've done the orchestration within the platform. We've created models around each of our modules, and we're delivering results. Things that would take 4 days of work, we're delivering in minutes for customers.
And at the various events that I was at both in Las Vegas for Falcon and in Europe for our Falcon in Europe, our customers talk about just the evolution of Charlotte, the maturation of it and how it's become a key part of their success in their SOC. And it gets back to what I said earlier, CrowdStrike has become the operating system for the SOC and Charlotte is a big piece of it.
Your next question will come from Joseph Gallo with Jefferies.
Congrats, Andy, on the new role. It was awesome to see you guys maintain the fiscal '27 net new ARR growth of 20% on higher numbers. You mentioned several key components of the business accelerated in 3Q. Is there 1 or 2 products that you think have an outsized growth impact for upside next year?
And then as a part of that, security for AI feels necessary but very early. Is that accounted for in your preliminary fiscal '27 guidance? Or is that more longer term?
Yes, sure. So I think when we look at next year, again, seeing the momentum that we talked about with Next-Gen SIEM, again, it's an all-star product. It delivers a lot of value, which is key in this market when you're talking about consolidation. And it's enabling customers to do things that they haven't been able to do.
And I think one of the areas that maybe is really not appreciated is that many organizations of all sizes are making a decision in the past to not collect certain data because of the cost. With CrowdStrike, we can actually open the aperture, and we can provide value to collect all that data. So in general, we're expanding the wallet share, but we're giving them more value because we're collecting data they've never seen, and we're giving them outcomes that weren't available to them previously.
So I would look at that as an all-star. I would look at cloud. We look at the displacements that we talked about in the call. We looked about -- we talked about the runtime protection, which is key. Customers want that protection. And then we look at Falcon Shield, which is, again, cloud and identity, but it is a key technology to help protect the SaaS applications. So these are all fantastic opportunities for us in the coming year, and we'll continue to double down on them.
Your next question will come from Fatima Boolani with Citi.
Here I go. George, I wanted to direct this to you. You gave us a lot of information about your strengthening partnership with AWS. And your proximity to AWS for customer and a very, very strategic partner has only cemented further. So I wanted to ask you a very high-level strategic question. This proximity that preclude you or influence you or potentially maybe even complicate your relationship with other hyperscalers and your customers who would typically presumably have multi-cloud infrastructure footprints. I would love for you to sort of dive into some of those dynamics a little bit, again, just by virtue of the strengthening partnership with AWS and the availability of the full Falcon suite in a very deep integrated way inside AWS.
Yes. So first, we couldn't be more excited about this partnership. And really, I mean, I think this is something that's going to be incredible for AWS customers as well as customers at CrowdStrike and the fact that now natively, you can actually flow data from AWS into Next-Gen SIEM. It's right in your console, and it's going to be a tremendous enabler for new customer acquisition. And it's a needed technology for AWS customers. So overall, a fantastic relationship, and we're excited to be deeply integrated.
And when we think about the current environment, as you know, there's always an area to cooperate with many different companies that are out there. Just look at the AI space and how many people work with different companies that are out there. I think if you look at that and you apply it to security, of course, we're going to work with other players that are out there. They're going to leverage the best technology in the market, which is CrowdStrike. And we're there to support all of our customers and potential partners. So it doesn't preclude us from doing that. But again, I think this reinforces what a great relationship we have with AWS, how we've been able to partner with them, not only in the technology side, but also in the marketplace. And you've seen the evidence of that by the awards that I called out. So overall, extremely excited about what the future brings.
Your next question will come from Meta Marshall with Morgan Stanley.
Great. You noted core EDR acceleration in the quarter and you kind of noted AI as a catalyst for that. But just is that kind of more endpoints getting protected or as they become more intelligent or just existing customers looking to modernize as part of general AI adoption?
Sure. When you think about endpoints and the adoption of AI, a lot of it takes place at the endpoint. Think about all of the various technologies that are out there where people are running these as a user on their endpoints. And we've seen some big announcements from consulting firms and others that are leveraging AI in their business because they have to and they have to drive efficiencies.
So what that means is that, that creates opportunities and exposure for companies. So they're going to need to monitor what sort of queries go in. They're going to need to monitor what data comes out. They're going to need to monitor what other services are connected into those AI desktop technologies, and that becomes another threat vector. So this becomes a catalyst. Again, I think this is underappreciated as a new risk vector that we hadn't had over the last number of years. Now with the adoption of this, this isn't AI creation, it's AI adoption. And that, I believe, is going to be a massive market opportunity for us. So that's where we see that. And overall, as I always say, 50% of the market is still legacy AV, and there's still a long runway in the endpoint business to be able to take that legacy market share.
Your next question will come from Patrick Colville with Scotiabank.
All right. I guess this one is for George. I want to ask about discounting levels because if I think about this time last year, we had the CCP program, but we also had CrowdStrike very correctly being aggressive to cement and extend its position through discounting. That was the right strategy, and these results prove that. But as I think about the quarter we've just had, fiscal 3Q and as we look towards fiscal '27, I guess, can you just talk about how you're thinking about just discounting and normal course of business discounting? Are those levels going to diminish over time as we have the Falcon outage further and further in the rearview mirror and your position is looking very strong?
Sure. Well, I think when you look at this market and you look at, say, enterprise sales, I mean, there's always some level of discounting. That's not unique to us. It's not unique to security, and it's not unique to software companies. It just happens as a normal course of business. And I think we've been very prudent in how we operate in those areas. And we've tried to focus on things like CCP, which again, allow customers to take new technologies in, but protect the price point and allow us to basically capture them in a flex opportunity.
So we're going to use the tools available to us to be competitive. We continue to take share. We continue to drive new customer business. And we don't see anything out of normal course of business, but we've got various tools in our toolbox, and we tend to use those judiciously and again, where it makes sense for us and for the customer, and that just drives the growth that you've seen. And I'll also point out the 81% gross margin, like you have to look at the margin as well. And we've been able to be successful, and we've been able to protect the margin.
Your next question will come from Eric Heath with KeyBanc.
Nice set of results. George, I wanted to ask about the partnership with F5. I thought that was pretty interesting. But correct me if I'm wrong, but I believe this part of the infrastructure stack historically was never able to support endpoint agents before. So does this expand the endpoint TAM? How meaningful can this be? And are there other areas of the infrastructure stack you think this is applicable to?
Yes. This is a great and insightful question. I'm really glad that you asked it because it does. And what we've seen over the years is that customers have been asking for a long time to protect these appliances. And in many cases, the appliances has not been available to us, the underlying operating system, if you will, to be able to protect, but there's been a huge demand there.
So we worked with F5 in great partnership and very quickly to be able to certify our agent to run on their platform. And we do think that this will create a model, working model that will open it up to other appliance vendors to be able to have it protected. And I can tell you just some anecdotal stories. There was a story just last week of a noncustomer never used CrowdStrike, had the opportunity to actually use our technology because of F5 and was blown away. And within a week, we had them in an EBC, and now we're getting into a proof of value.
So this play works, and we're going to expand our market and be very forward leaning in being able to protect other appliances that are out there, which you probably have seen are the tip of the spear for many of these nation state breaches.
Your next question will come from Roger Boyd with UBS.
Well, congrats, Andy, on the new role. I wanted to double-click on the Kroll partnership. I know MSP has been a growing part of the channel for CrowdStrike for the past couple of quarters. Can you walk us through that longer-term opportunity as you expand with Kroll and other -- beyond kind of the initial endpoint landing spot?
Sure. Yes. We are excited about this opportunity. We took out another EDR vendor that was in there. We're providing a much better solution for them and their customers. And they're in a segment that allows us to bring our technology to. There's a lot of incident response engagements they're doing. They're part of the insurance panels. And it opens up a market opportunity with one customer and just accelerates our ability to penetrate that.
So these are the type of models that we like to create. We've been very successful in the MSSP market. This is just another proof point of us working with customers like Kroll and the reach that they have and the trust that they have. So the idea is to create more Kroll opportunities and certainly grow the opportunity that we have with Kroll, which I feel very confident we will.
Your next question will come from Tal Liani with BofA.
I'm trying -- you're a $5 billion revenue company and you only provide one number, revenue or ARR. There's no breakdown. So I'm trying to understand a little bit of the kind of any segmentation of your revenues. And the question I have is, can you discuss verticals like contribution of SMB and trends in SMB, kind of new market opportunities that were not in your core before and how you're addressing them? And also new customers versus upsell to existing customers. Are you disclosing NRR and GRR? I know you stopped doing it a few quarters ago.
Actually, let me take the last part of your question first. So basically, we are going to be giving out dollar-based net retention and gross retention rates at the end of the year. So that's what we've talked about, and we will do that, Tal at the end of Q4. So -- and we do it every Q4. So I think you'll be -- you'll get that information.
Now with respect to breaking out how we think about our business, whether it's enterprise or SMB or MSSP, the great news about our business is that we sell all of it. We're successful with all of it. We're successful with small deals. We're successful with large enterprise deals. And for us, we have that great technology that it's the same. It's the same technology for if you're a 5-person shop or you're the largest company in the world. And the beauty of how we're able to deliver our technology is that it's up and running in seconds.
So when you think about segmentation, you think about who we sell to, it really is everybody. Our ability and our success is agnostic. We are really driving new wins and displacing competitors on a daily basis, right? And for us, to continue to invest in the business and for us to be able to continue to make sure that we're able to deliver in a very timely manner, these are the successful things that we look at to be able to sell to all of our customers, whether big or small. So we're excited about that. And we're also rare in the entire security community to be able to do that successfully.
Your next question will come from Mike Cikos with Needham.
This is Jeff Hopson on for Mike. With the increased amount of M&A activity in security we've seen this year, including CrowdStrike recently, how are you guys approaching the buy versus build when it comes to a technology like AI that's developing pretty quickly?
Well, when we look at the market, certainly, there's a lot of activity out there, and it probably isn't a week that goes by that we don't talk to some bankers that are talking about other companies. The great news is we've got a tremendous balance sheet. We're in a fantastic position to be able to build or buy or partner. And I think we've been very thoughtful about our acquisitions. And a big part of our strategy has been the integration.
When you look at Pangea, we're really starting to sell that in Q4 because we wanted to take the time and effort to integrate it. It's not just kind of stitch together. The single platform, which I talked about, is very important to our customers. So we're going to continue to be thoughtful. We're going to continue to buy what we perceive as best-of-breed in the market, not legacy technologies. We're going to integrate them, which is part of our customer brand promise. And we're going to continue to grow them within our sales motion and the channel that we built. So we'll be opportunistic, but we'll also be very strategic in what we buy.
Your last question will come from Adam Borg with Stifel.
Awesome. And Andy, congrats on the role. Maybe just on the identity business. It's great to hear stronger quarter there qualitatively. I know we've talked in the past about PAM being almost like a 1.0 product. Love to hear more about how you're thinking about that product, in particular, and the maturity in coming quarters.
Yes. So identity, as we mentioned, super important in an AI era, something that we got into many years ago, and we continue to evolve that. And we've seen some really nice wins specific to our PAM technology. We have to look at what customers are telling us and basically skate to the puck of where they're going, which is they're looking for more modern identity solutions. They're looking for solutions that can do just in time and some of the kind of legacy vaulting they'd like to move away from. So those are areas of focus for us.
We'll continue to build out our identity stack. It's been very successful for us. But certainly, there's more to do. There's more to build out and there's more opportunity in front of us. The good news is there's demand from customers, as you've seen lots of market movement. And as customers think about what they're going to do next, they want to make sure they set themselves up for really in the next era of agentic identity, and CrowdStrike will be there for them.
This concludes today's question-and-answer session. I would now like to turn the call back to George Kurtz for closing remarks.
Thanks, everyone, today for your time. We appreciate your continued support. We'll actually be presenting at the UBS conference tomorrow and a live webcast and replay of the presentation will be available on our IR website, and we look forward to seeing many of you at the conference. So thanks so much. Stay safe, and we'll talk soon.
CrowdStrike Holdings Inc — Q3 2026 Earnings Call
CrowdStrike Holdings Inc — Goldman Sachs Communacopia + Technology Conference 2025
1. Question Answer
All right. Fantastic. We will go ahead and kick it off day 2 of the Goldman Sachs Communacopia + Technology Conference. Thanks so much, everyone, for joining us at the CrowdStrike session. Delighted to welcome George Kurtz back on stage with me, Founder and CEO of CrowdStrike. Thank you for joining us.
Great to be here.
So George, I know how much you pride yourself on being more than just a vendor to your customers. What I mean by that is we spend a lot of time having more strategic conversations about where security strategy is going. So maybe to start, share with us some of those conversations on AI strategy in particular. With your largest, your most technology sophisticated enterprise customers, how are they working with you and how are they thinking about what their security strategy looks like in an age of AI adoption?
Yes. I think when you look at customers and larger enterprise, everyone is in their early days of their journey of AI. And it started in 2022 with, hey, this ChatGPT thing is pretty cool. It can give us some really cool results until you get something wrong and you have to correct it and it's like, "Oh, yes, you were right. Yes, I'm sorry about that, I was wrong." And as you get through that journey, then it's like, okay, well, where can we operationalize AI and what does it mean for a business?
And I think keeping my CEO hat on, it's really about can it make you money or save you money and people are in that journey. And where can they use it, what areas, do they start in legal, do they start in sales, do they look in -- they're in financial services and sort of trading and those sort of things? And how do you do that in a secure way? And it started from -- we've got everybody using ChatGPT and it's totally uncontrolled, and data is going everywhere to we're going to shut it all down and then we're going to open things back up. We have to put guardrails around it. We have to manage the data. We have to manage the identity.
So that's been a couple of year journey, and we've been helping them with providing the guardrails, understanding the models, protecting the intellectual property, but you really have to enable AI to allow people to get all the benefits from it. And we're such in the early innings. That's what we're seeing right now. And I don't think there's a company that I've talked to where I talk to the people in the business and they go, "We want to use more AI, but we can't." And it's like, "Well, why can't you? Well, corporate doesn't let us." So great opportunity for us.
And to what extent is this building on the existing security foundational elements that already exist versus maybe catalyzing an incremental step function in modernization or next-generation product and architecture?
Well, I think if you look at most companies, I don't know how many companies in here think like their data is really good. I haven't found one. If you think like your data is really good, show hands, it's probably be like 0. Because everyone is like, oh, we have this data, it's in Salesforce, it's kind of a mess. And does that sound familiar?
Absolutely.
Right? And so I think there is this process now of like, okay, well, we've got to get our data architecture in line, we've got to make sure that we can put it in a Snowflake or Databricks or what have you, and we've got to train it and those sort of things. And it's just kind of a force function into like let's start cleansing the data, let's start labeling the data, and how do we move data around the organization and begin to provide some level of governance around it, which some have. But that needs to be in place so that you can actually get the training done on these models and then implement it in a secure fashion. And then it ties into identity, which I know we're going to talk more about.
But it all starts to come together, and it's like just the next industrial revolution that we're going to see around AI and all of the things that you're going to need to actually get the full benefit of it. They're all going to need security, all of it. And if you believe in AI and you believe there's going to be more AI in 5 years than there is today, then you're going to believe in the security story that security has to be part of AI in order to enable it.
Yes. And it's interesting because not all pieces of the security budget are created equal. What I mean by that is an analyst will break down, okay, here's network endpoint identity SIEM. The question for you is, how do you think about where in the stack the value is going to accrue? And you made a really interesting comment on the earnings report saying that AI is not a network problem. So maybe elaborate on that a little bit and how you think about the framework for what's defensible versus what's less important.
I think you have to look at where AI originates from and how people use it. So certainly, the data is a big piece of it. I talked about what CrowdStrike does in terms of like our training for some of our AI models, like we've become the Reddit of AI security data because we have all these annotated security events over the last 10 years. And you have to look at in each company, where the data is coming from, how it's labeled, how you have this kind of human feedback loop that you're still going to need. And then you have to look at who's using it.
Like at the end of the day, you have some autonomous actions that take place, but it's for the benefit of humans. And humans are going to be guiding all these AI agents, right? So that's why when I talked about it on the earnings call, it was like you got to -- it's at the endpoint, it's at the workload, it's at the data level. It isn't like some network device that's magically going to make AI secure. Like you have to look at how people use it and where it originates from and a lot of it starts around data and humans.
Yes. And let's stay here with data. We hear this argument that, well, the offense has the data, too. Meaning you've got defenders using AI in the security architectures, you've also got the bad guys using AI to attack. And my question for you is, can it actually be inverted this time around where the defenders can use AI to apply it to the data such that the defenses get stronger at a faster pace than the attackers who is trying to hold in it. I'm curious how you think about that.
Well, the way we look at it at the highest level is you have AI for security, which is the way we started CrowdStrike and was machine learning at the time, but it was using that to secure systems. And then you have securing AI to two different things. So when we think about the ability to actually secure companies, it really comes down to a time element, like the window of exposure and how fast things can be exploited have moved from weeks to days to now minutes and sometimes seconds. On one of our threat reports, we talked about exploitation of 52 seconds. So you're going to need AI to be part of that solution.
But I just kind of give you an idea of the threat landscape, maybe tell you one story. It was a week or 2 ago, our researchers found some malware. And it was really interesting because what it did is it would drop on a system and then it would gather a bit of information of what that system was. And then it would go out to a GPT and it would start querying it for like, hey, write a script that allows me to get all the data off the system or write a script that allows me to move from one place to another or it went through a whole bunch of recursive sort of questions into a public GPT.
So think about each time it dropped on a system, it gave a unique response back to what was on that system. So it actually learned what the function of the system was. Was it a database? Was it an e-mail server? Was it a desktop? And then based upon learning that, it would actually provide different actions for how it was going to exploit it and what data it was going to harvest from it. That's kind of what we're dealing with, right? And the speed of that's happening -- at which that's happening is like unparalleled.
Yes, absolutely. Well, the threat intelligence part of your business leads really nicely into discussion around security operations center. Your AI SIEM business was up more than 95% in 2Q, ARR north of $430 million. And one of my favorite phrases that you used, it's like upgrading from a typewriter to a computer with moving from legacy solutions to fast solutions. So what do you see as the biggest impediment today in your customer base from getting people to make that upgrade cycle from typewriter to computer?
Well, there's always a level of inertia in what people are familiar with. And when you've got newer technologies, you have to really focus on what the outcome is. And sometimes you may talk to a customer like, well, we do it this way, and it's like, okay, but what is your outcome? You don't really need to do those five steps when we can just go right to the step that you want and the outcome that you desire. And that's really what we focus on.
But I don't know, I'm a simple guy, I like to just break it down into better, faster, cheaper. Like we can offer a solution that gives you better outcomes faster and we can reduce your cost. I mean we're taking costs from some of the big legacy SIEM vendors, and we're cutting it to 1/3 on what people were paying. So there's a reason why people are moving to CrowdStrike. And what's important to keep in mind, too, is every Falcon platform customer has Next-Gen SIEM built in. It's in the platform. The only thing we need to do is license it, and we actually give them 10 gigabytes free so anybody can use it.
The second critical piece, which sometimes I think it's often overlooked is we actually don't charge for first-party data, okay? What that means is first-party data is CrowdStrike data, the data that we generate from our agents that people were taking from their legacy SIEM and paying to move it -- sorry, taking from us and paying to move it into a legacy SIEM, you don't have to do that anymore. You actually don't pay for that. So that's vastly different than their old models and very disruptive. So where we charge them is for ingest on the data that we don't have.
Now when you combine that with Onum, that's the acquisition we did last week or a last week or 2 ago, that's like the railroads, right? We control the pipeline of where data originates and where it's going to go. And we can do in pipeline detection with AI at the source of the data and the events where it originates. And again, this is for third-party data. So it's very disruptive on the speed and the cost. So we can go into a customer and basically say we can dramatically reduce your cost and give you a much better outcome.
And maybe to crystallize this point on Onum and the data pipeline piece of this. When you approach customers in the pipeline today or when your sales team does and they say to you, well, we get this on 2/3, but this is not a priority for us. It's going to take us X number of months to migrate. What is X in the number of months and what is it post Onum?
Well, it depends on each customer. And let me just tell you through the sales cycle, typically how it occurs, which is we're at the point now of customers going, okay, we know your stuff works, we know it works at scale, you have plenty of reference customers, we tried it, we like it. So we want to move from our legacy SIEM to you, which means we're not going to renew something. So we got to move it all over to you. And typically, the way that would work is you would run two systems in parallel, and then you would cut over.
So what Onum allows us to do is not only can it do in-pipeline detection and really cool kind of features, but you can fork the data. So literally, you can have one event and send it to multiple places, it doesn't matter. So you can keep your legacy SIEM running and then deprecate that over time. And then by the time the renewal comes up, you're up and running on CrowdStrike. And by the way, Charlotte can help actually even in the migration process. That is going to dramatically accelerate the adoption of Next-Gen SIEM. That's one.
And two, and we just sort of talked about the security use cases when we announced it. But guess what, it's an IT product. So any data in your environment in IT can be consumed by Onum. And that then moves -- continues to move us into different buying centers, into the DevOps buying center, into the IT buying center, right? You become much more strategic when you're consolidating all these costs. So it is a very strategic acquisition that we did. I think a year or 2 when we're back here, we're talking about, you can be like that was a really good acquisition because it goes well beyond security into IT.
Yes. And I'm curious because the problems in the SOC have been compounding for 10-plus years now. Do you think there is an incremental stress function happening because of AI such that the scalability of log ingestion is increasingly at a breaking point because the complexity of being able to do AI logs is changing? A couple of different concepts in there. So maybe correct my technical knowledge.
Yes. I think people, just in general, are overwhelmed with the amount of data they have and sort of the noise that they have to deal with. One of the things that we developed is something called Signal, which is to separate the signal from the noise because you have so much data, and that's kind of an AI element that gets rid of all the noise. But in general, SOCs are overwhelmed. They're using legacy technologies. They're using legacy workflows like SOAR, I think, is going to be dead, right? And we can talk about sort of agentic SOAR and what that looks like. But these are all transforming the SOC.
We work with lots of companies, lots of the companies in the room here, banks, et cetera. And it's not like you guys are piling on the headcount. I'm sure the conversation is how do you do more with less, right? That's everywhere, not just in IT. So when we think about the SOC, it has to transform and it has to become agentic. You've got to use AI for what it's really good at. It can deal with lots of data very quickly. It can understand patterns very quickly, and it can take actions even if it's a guided action, which is going to dramatically reduce the cycle time to getting things done and separate the noise from the signal.
Yes, absolutely. So it leads nicely into a question around agentic in the SOC. And we know that security people are some of the most risk-averse people in the IT organization. And yet you're seeing a success with Charlotte. And one of the comments you made to me a couple of weeks ago was you've actually put enough guardrails on Charlotte to make it act deterministically with a set of framework. Tell us a little more about that. How do you put the right guardrails on the agents to get to a place of productivity?
Yes, that's a good question. So when we built Charlotte, it was built as an agentic technology from day 1, actually before people were calling these things Agentic AI agents. And the whole idea was we wanted to go beyond just kind of a chatbot, right? So you can think about Charlotte as an orchestration layer with multiple models underneath it. And we had to provide to your question, guardrails, we had to build all this. So that when you ask Charlotte a question, I'm sure when you use ChatGPT or Claude or what have you, you ask a question three times, you get three different answers. And you're like, well, I just ask the question, why can't I get the same answer? And in security, it's not a great thing if you got like three different answers to one security question. So we actually had to build the guardrails around that to give a deterministic outcome.
And those are the kind of things that are maturing in -- think technologies beyond Charlotte, where when you implement AI, you want to make sure you get the right answer one time. But we've built all of that in and then we built all the workflows in. So again, Charlotte has become more of an orchestrator of agentic workflows, which is really where we're seeing a lot of activity. And we've got over 30 million different unique workflows that customers are using per week across the platform, which is saving a lot of time and effort. But you couldn't get the right results. And to your point around security, like people don't want to take action if you're getting like random results. So we had to do a lot of work around that.
Well, maybe let me ask you the flip side of that question, which is if you think about copilots versus truly autonomous agents, Copilots tend to be more deterministic. So with the guardrails, what levels show it up from being more than just a copilot?
I'm going to save that for Falcon because I'm going to talk about that. So it is a good question. But I think if you look at where a lot of the industry is at, they're in the -- I still have to keep my hand on the steering wheel, right? And you want to get to a point where the car can drive itself. And in any big organization, again, you're going to have like a lot of resistance from a risk perspective where you don't want these random -- these agents doing random things. And that's why having the right data to train it on, getting the right outcomes, having the guardrails and then it's going to be an evolution over time where you're going to have that sort of autonomous piece.
Yes. And the amazing thing about some of these concepts that you're talking about, whether it's in the SOC or in the CrowdStrike stack more broadly, is some of the connectivity you have with the agent into observability. And when we discussed in the past, I think you framed it as, look, there are five categories of observability. We can do two of those five categories. So maybe bring us up to speed, how are you thinking about your technical road map in observability? And where do you see CrowdStrike's right to compete?
Yes. We keep getting asked more and more for different data elements. Like if you look at Falcon for IT, which has allowed us to cross over into the IT world of gathering information. So you have this sort of digital employee experience and these sort of things, like we can gather a lot of that information. And these are big categories that are out there that go beyond security. And why do we have a right to win there? Well, we have -- I'd like to say we're in the real estate business, right? We have beachfront real estate, which is our agents, whether they're running on a laptop or whether they're running in a cloud, whether it's an ephemeral workload. And they can pull telemetry beyond just security. What's the health of the system? What is it doing? What's the user doing, all the identity data associated with it.
So these become very interesting to companies. And we have something -- it doesn't get a lot of airplay and it should, but it's called Falcon Foundry, which is the ability to actually create your own module on our platform. And I think that's really the hallmark of a true platform is you can create your own stuff on it. So you can actually combine and mix and match IT and security data in your own application and you can solve unique challenges.
So we have customers doing this and solving things like we didn't even think about. And that's part of the ability to go out beyond just security. So our ability to go into IT, we're already there in certain aspects, but I think there's a huge runway ahead of us into solving more problems beyond just security. But within our own lane, you don't want to go too far afield, but there are a lot of things that we can do that tie in nicely that expand our TAM.
Yes. Just from a lane concept, so clearly, there are industry leaders in IT asset management, observability, et cetera. So do you envision a world where 5 years from now or 10 years from now, how do you think about where CrowdStrike fits relative to those incumbents?
Well, I think there's a huge market and lots of bleed over and observability wants to go on security, security wants to go on observability, those sort of things. I think at the end of the day, it's going to be a lot around the workflow and how do you get the data. And then how do you operationalize that and how does that impact sort of TCO and price.
And a lot of times, if you can supply 80% of what somebody wants at a very good price point, they're like, hey, that does what I need. Like that's good enough, and that does what I want in some of these other maybe ancillary areas, right? And then if you're really specialized and you have companies that have spent a decade doing it, that might be their niche. But it doesn't mean that it sort of limits your opportunity because I think having the real estate as a strategic beachhead allows you to do many things, and there's still a lot of TAM that you can capture.
What are some of the most interesting or maybe one or two most interesting examples of what customers are building on Foundry? And to what extent does that shape your own product road map?
Yes. I mean we have customers that are building applications like, again, you can pull data in from anywhere and build it into the workflow. So they're looking at specific identity use cases and then they're tying into things like Workday, what's the employee doing? Are they on a tip into badge readers? Well, did somebody badge in? Are they really the employee, they want to get to this piece? So they're pulling from lots of different systems to solve sort of an identity use case. Is it really you? Compliance. They're pulling data from a lot of different areas, and then they're building compliance workflows around specific compliance needs that they have for their own industry, and they can load all that up in there.
They're looking at using Foundry for a digital employee experience. So is your computer slow? Why is it slow? Is it about to fail? Is the hard drive? Like all these things that cost a lot of money, they're actually using CrowdStrike to solve that. We didn't really plan on it. We just have all this data and then they solve different use cases, and we're like, that's a pretty good idea.
Yes, really cool. Okay. Let's talk a little bit about the identity use case in particular. So you've been investing in identity since 2020. How do you think about where it makes sense for CrowdStrike to compete across the identity SIEM lanes? And where do you sort of draw the line between being able to invest in specific identity solutions?
Well, we've been in identity since 2020. We saw it as a major threat vector and things that were really causing companies to be breached. So first thing that we did is we got into ITDR. We helped really pioneer a lot of that. So identity threat detection and response. We've got a tremendous amount of telemetry out of those systems. And the key thing here is we already run on the high ground, which is domain controllers, right? This is the most sacred of systems in an environment is to run on a domain controller. So we had customers over the years say, okay, you give us all this rich telemetry. You're already running on our domain controllers. We're using legacy like PAM technologies. So why don't you come out with something that can help us and again, save time, money and move to more modern architecture?
So with our PAM module, it's more conditional access and just-in-time access than kind of just credential vaulting. And we think that's a more modern way to deal with identity. Now you have governance. I mean, there's a lot of pieces to identity. We do a few of them. More we're adding, more we're coming out with, et cetera. But it's a big market. And again, the good news is we were there very early and we identified it. ITDR, I don't know, we're probably the biggest player in that whole market. And then we keep adding like the PAM module, we just launched a quarter ago. Why? Because customers said, we want it. We launched it, and we already have customers on it moving from legacy technology. So I think we have more than our fair share of opportunity to win in that market. And it's a huge pool of dollars and a great growth opportunity for us.
And just to be clear here, you mentioned you don't have a vaulting product today. Do you envision a scenario where customers can use you as their PAM solution without needing a "legacy PAM" solution as well? Or is it more complicated?
Well, I think customers want more just in time. I mean the vaulting is -- I mean, it's a glorified password manager. Most of that was created in 1999 to store Windows credentials. What people want is real-time access, conditional access. And not to say you don't need to store like certain passwords, but that will become more commoditized.
Yes. It's interesting because we've talked about so many different adjacencies that sit around in the CrowdStrike platform. It leads me to a question on R&D and how you think about prioritizing R&D. Scale is important in security. You have competitors that will say, "Hey, we're out investing you 2:1 or 4:1." But we also know that not all R&D dollars are created equal. So how do you think about incrementally investing R&D? And how do you counter those claims on competitors saying, will we invest more?
I mean they can say whatever they want. A lot of this is where do you actually allocate in some accounting allocation like your R&D. So I think the proof is in the pudding of like what do customers say, where is the innovation, how fast you are innovating? Are you one platform? Are you three or four platforms? I mean this is -- the proof is in the cake that you're baking, right? It's not in saying that you spend a lot on the ingredients. I mean there's a lot of ingredients that people spend money on and the product is c***.
So for me, that's what it's all about. It's about driving innovation, and it's about the fact that we have a brand promise of the single-agent architecture with one platform. Last I check customers want one. You look at ServiceNow, one. You look at some of these Workday, one. One in CrowdStrike. And that costs actually a lot of money to do and to do it right. So that's the way I would look at it. And I don't get hung up. We spend a lot of money on R&D. We drive a lot of innovation there. Innovation is our lifeblood, and we're focused on solving the customer problems. And it's very complicated and it's a very convoluted process that we have to go through, not really. We just listen to the customer, we build what they want.
Yes. Well said. Let me ask you about Falcon Flex because by all the metrics that you've disclosed, it's been a home run in making it easier for customers to buy across the platform. Talk to us a little bit about how durable the momentum you're seeing with Falcon Flex. I'm sure we'll get more updates of Falcon. But to the extent you're willing to give us a little color now, how do we think about the durability of growth driven by Falcon and some of the ARR uplift that you're seeing?
On falcon Flex?
Falcon Flex, yes.
Well, I think Falcon Flex, we pioneered this licensing model. As you've seen everyone now has a Core Flex model, one that we've got the idea from, again, driving innovation not only in the technology, but in the licensing world. And we listen to customers. They basically said, we want to buy more from CrowdStrike, make it easy. You got 30 modules. Like you guys can't keep track of them. We can't keep track of them. So make them all available to us, make it easy for us to buy. The only people that like going through procurement are the procurement people. So let's go through it one time, we get a rate card and we want to add more, we do that. And it's been a total home run.
Out of the 1,000-plus Flex customers that we talked about, we got 10% of them reflexing. And of sort of that pool, we've seen 75% utilization of the Flex license. So we're seeing customers actually use more of their Flex sooner than they anticipated and we anticipated. And someone might come back and say, "Well, geez, is that a problem? Are they going to get a big bill? No. Because what we're doing is we're working with them on the demand plan to actually remove and consolidate the other products they have, so they can buy more of CrowdStrike.
The 75% utilization, maybe just benchmark that for us. How do you contextualize that?
Well, if there's a pool of dollars, they've used 75% of it faster than sort of you would on a monthly basis. If it's -- they're using more of it faster.
Yes. I got you. Okay. And then talk to us a little bit about what the reflex in the renewals motion is going to look like over the next 12 months. You have an elevated amount of Flex deals because of the customer commitment program in the last 12 months. So what should we be looking for in the renewal cycle? Do you think you'll see similar uplift? You've already talked about customers tracking ahead of their demand plans. Maybe just paint a picture of...
So just to reinforce, the Flex is the licensing model, right? It's a commitment, not a consumption. You commit, it's not a consumption. So it's very easy to track. It doesn't have variability to revenue and those sort of things. The CCP was just a way that we were able to work with customers and give them a pool of dollars that they can spend. But the byproduct of that sort of benefit of that is we had to move everybody to Flex. So if you want a CCP, it was a customer commitment package you had to have Flex. So we vastly accelerated the move to Flex rather than just waiting for the natural renewal cycle.
So we have a lot of customers that are just on Flex and consuming it. And then CCP is the customer packages that burn off Q3, Q4. Some of it runs multiyear type of thing, but you're going to see those kind of run out. And then obviously, the whole idea is 95% of the time, someone is going to renew that module if they got something for free.
Yes, absolutely. So I know Burt and the team have spent time dissecting the delta between ARR and subscription revenue. Maybe I'll ask you a higher-level question. When do you think that begins to normalize? And how does that shape the way you're thinking about the 2027 growth algorithm, understanding that it's too early for us?
Yes. I mean the key metric for us is ARR. So if you look at the $221 million that we delivered last quarter, it was a record for us, reacceleration. Burt talked about the 40% reacceleration in the back half of the year, right, 40% growth in ARR. That's the key metric. There's a bit of a divergence now because we really have an accounting artifact between revenue and ARR, and that is the partner rebates. So the reality is when we gave away some free products, we had to pay the partners on stuff that was free. That is actually a contra item. You would think it's a sales expense, it's not. It means you have revenue minus the contract gives you new revenue -- it gives you your net revenue. That's where you see the divergence. So when the partner rebates are -- when they're abated over Q3 and Q4, then ARR and revenue converge back together.
So it's interesting because you've seen so much success on the back of some of the "free programs" in terms of adoption. How do you think about does it make sense for that to perpetuate for longer? Or have you all as a management team drawn a line in the sand and said, look, this is the period of time in which we're running this particular program?
Well, that was for a specific incident we had to deal with. That's in the rearview mirror. But we have the ability with Falcon Flex to be able to be very creative and work deals. Hey, you have a legacy technology that you want to run out, we can be creative and put money in a pool. Like if you want to move from your old SIEM to our SIEM, we can help you with that. So there's a lot of levers that we can pull and we do. And this is a normal part of running a software and technology business. This is what happens, like you figure out where you are, what deal you're trying to get through and who you want to replace and you just kind of creatively come up with like how do you make it a win for the customer and how do you make it a win for them. And with Flex, you only pay for what you use when you use it. And it makes it really easy to ramp out of an old technology and ramp into ours without a whole bunch of extra cost. So those are the levers that we pull, and that's software 101.
Yes, absolutely. So I wanted to ask a question about unit economics because CrowdStrike has had consistently benchmarked best of class relative to security relative to all software. I'm curious when you look internally throughout your operating structure, are there particular levers that you're excited to pull because of AI applications internally? Maybe there's a little bit of discussion here as well on you're touching so many different points within the IT stack now that the CAC actually goes down relative to addressing some of these new categories. So maybe just holistically, how do you think about the durability of where your margins can go?
Well, we look at AI everywhere internally. Maybe just in general, like where can we be more efficient, things like legal, things like sales, marketing, et cetera, those are kind of ones you would expect, and we've gotten tremendous efficiencies out of it. But one of the big areas that we're investing in, which actually drives Charlotte to be even better and better is our Falcon Complete MDR service, right, our managed detection response. We have one of the largest MDR businesses in the world. And by the way, we have to drive automation in it, right?
And I think there's -- sometimes there's confusion of like, well, you have an analyst, how many customers can they handle? There isn't this weird like -- or I would say, legacy mindset of like you have one customer to -- seven customers to one analyst. We don't even think about it that way. The platform does the work, it drives the automation. So we continue to get more and more leverage in that business. And the output in terms of the technology we built actually goes into Charlotte. So what we use internally then gets commercialized and goes into Charlotte, and that becomes the basis for solving customer problems.
Yes. And maybe just on this point with the customer exposure that you have as well. What I mean by that is earlier in the conversation, you touched on having more personas using CrowdStrike in DevOps, in IT observability, Falcon IT, et cetera. So how do you think about the way your breadth is expanding with end customers? And does it actually end up changing your LTV to CAC because the incremental cost of those personas coming on to the platform is actually quite low?
I think it can. I think it can change the CAC over time. You just have to keep in mind that there are some specialized centers, right? If you're selling the DevOps, the same person who's selling traditional sort of endpoint protection and related technologies may not be the same person that can talk cloud and DevOps and those sort of things. So there's still a little incremental spend as you specialize. But I think overall, we've been very efficient in our CAC. We've got in-app trials. We've got the ability to turn things on very quickly and license them and make it friction-free. So all that accrues value to us and our shareholders. And then as we bring on these new technologies and we have new buying centers, we have the ability, again, to go out and be very efficient from a CAC perspective. Just keep in mind, though, there's some specialization that's needed in those areas.
Yes. All right, fair. Maybe we can leave the audience with a tease for Falcon. What are the milestones that people should be watching for next week?
Well, it's going to be, obviously, as you might expect, a big talk around AI, some of the things that we've already developed, what we're doing in those areas, and I think how we're really disrupting the industry. And I think one of the things that I would leave you with is, if you think about what we did in the sort of take cloud and Next-Gen SIEM and all those things out of the equation. If you think about what we did when we started the company is we had agents that ran on a computer that protected users with an identity and their data and where they went.
And if you think about the explosion of AI agents, you may have a 10,000-person company that has 1 million AI agents. They're all going to need security. They all have identities. They all have access to data. They all have access to workflows. And by the way, you're going to have to do introspection of what they did because you're going to need it from a compliance standpoint. There's no way Goldman Sachs is going to release a whole bunch of AI agents without security and without compliance, and that goes for every other company out here. So that's the big opportunity, and you'll hear more about that at Falcon.
Fantastic. Well, George, thank you. Please join me in thanking George Kurtz for the time.
All right. Thank you.
CrowdStrike Holdings Inc — Q2 2026 Earnings Call
1. Management Discussion
Hello, and welcome to CrowdStrike's Fiscal Second Quarter 2026 Financial Results Conference Call. [Operator Instructions] Please be advised that today's conference is being recorded. I would now like to hand the call over to Maria Riley, Vice President of Investor Relations. Maria, please go ahead.
Good afternoon, and thank you for your participation today. With me on the call are George Kurtz, Chief Executive Officer and Founder of CrowdStrike; and Burt Podbere, Chief Financial Officer.
Before we get started, I would like to note that certain statements made during this conference call that are not historical facts, including those regarding our future plans, objectives, growth, including projections and expected performance, including our outlook for the third quarter and fiscal year 2026 and any assumptions for fiscal periods beyond that are forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995.
These forward-looking statements represent our outlook only as of the date of this call. While we believe any forward-looking statements we make are reasonable, actual results could differ materially because the statements are based on current expectations and are subject to risks and uncertainties. We do not undertake and expressly disclaim any obligation to update or alter our forward-looking statements, whether as a result of new information, future events or otherwise.
Further information on these and other factors that could affect the company's financial results is included in the filings we make with the SEC from time to time, including the section titled Risk Factors in the company's quarterly and annual reports.
Additionally, unless otherwise stated, excluding revenue, all financial measures disclosed on this call will be non-GAAP. A discussion of why we use non-GAAP financial measures and a reconciliation schedule showing GAAP versus non-GAAP results is currently available in our earnings release, which may be found on our Investor Relations website at ir.crowdstrike.com or on our Form 8-K filed with the SEC today. With that, I will now turn the call over to George.
Thank you, Maria, and thank you, all, for joining our Q2 FY '26 earnings call. Reflecting on our second quarter, the key theme was reacceleration. We've talked about reacceleration coming in the back half of this fiscal year. It's here now. I'm proud of CrowdStrike's ability to deliver reacceleration, our return to year-over-year net new ARR growth a quarter early. Our reacceleration is driven largely by AI-necessitated demand for the Falcon platform and stellar execution across the business.
Q2 was a robust quarter where we exceeded all guided metrics. Highlights included: one, record Q2 net new ARR of $221 million, double-digit millions ahead of our expectations, showcasing accelerating net new ARR; two, ending ARR of $4.66 billion, growing more than 20% year-over-year; three, record Q2 free cash flow of $284 million or 24% of revenue; four, record operating income of $255 million or 22% of revenue; five, total revenue growth of 21% year-over-year, reaching $1.17 billion and exceeding the high end of our guidance; six, cloud, Next-Gen Identity, and Next-Gen SIEM platform solutions are now more than $1.56 billion in ending ARR, growing more than 40% year-over-year; and seven, we surpassed the 1,000 Falcon Flex customer milestone with the average Flex customer representing more than $1 million of ending ARR.
Building on last quarter's re-Flex momentum, now more than 100 customers have already re-Flexed. We're very pleased with adoption rates. Seeing so many customers re-Flex validates the Flex model and illustrates customers' accelerating consolidation with CrowdStrike. Quarters like this one highlight our momentum and progress on the path to $10 billion in ending ARR. Setting new records, achieving net new ARR reacceleration sooner than anticipated and rising competitive win rates highlight CrowdStrike leading the way in cybersecurity.
Our innovative solutions are winning at scale like Exposure Management, which surpassed $300 million in ending ARR and was named a leader in the 2025 IDC Worldwide Exposure Management Marketscape. CrowdStrike's market leadership was further reflected in Gartner's latest Magic Quadrant for Endpoint Protection Platforms where we were placed in the Leaderbox for the sixth consecutive year. Our position was furthest right for completeness of vision and highest for ability to execute out of all vendors for the third year in a row.
In cybersecurity as well as the broader technology market, AI's impact is palpable. As organizations of all sizes embrace AI transformation, I hear several thematic concerns from executives and Boards. One, where is shadow AI emerging in my business? Two, how do I control what data enters AI systems? Three, how do I control what AI systems can do in my enterprise? Which ultimately leads to the focal question of four, how do I secure AI agents? AI has made the role of CISOs and COOs more complicated than ever.
Answering these 4 questions is far too difficult, expensive, nuanced, conditional and incomplete. At the same time, adversaries are now using AI, democratizing destruction at mass scale. Our threat intelligence research uncovered Famous Chollima, a North Korean nexus group, using GenAI to infiltrate more than 320 enterprises by automating fabricated resumes and conducting deepfake interviews. The threat is real.
CrowdStrike's role in the agentic era is staying ahead of AI-armed threat actors to secure AI at every layer. Beginning with the AI model itself to the workloads and hosts on which they run to the actual human and agentic identities, to the end-user devices accessing these systems and applications. In this time of societal and technological revolution, we secure where AI happens. Enterprises are quickly realizing AI security is not a network problem. AI doesn't happen in transit. Model creation and AI development happens in the cloud and in the data center.
AI adoption happens at the endpoint on the computing device itself. And AI access happens by users with human and increasingly, nonhuman machine identities. CrowdStrike secures each of these attack surfaces. We deliver AI for security, where we revolutionize security operations with our own SOC agent, Charlotte. We also deliver security for AI helping the world securely adopt the power of agentic outcomes. This combination, grounded in our data foundation, is a competitive moat. You can't just stitch or acquire a unified AI native platform.
AI security's primary enforcement mechanism is not and will not be the firewall. AI security must be on the devices, workloads, data and identities anywhere, everywhere and always on. AI security and now enterprise security in the agentic era is fundamentally a data, speed and enforcement problem, one that CrowdStrike solves today and is uniquely positioned to solve tomorrow.
Driving adoption of the Falcon platform as the operating system of cybersecurity is our Next-Gen SIEM. Every day, customers are discovering the power of our native hyperscalable data foundation to solve their most complex security and IT problems. Falcon Next-Gen SIEM had a stellar Q2 with year-over-year growth of more than 95% and ending ARR of more than $430 million. Next-GEN SIEM is becoming synonymous with AI SOC transformation, akin to upgrading from a typewriter to a computer, unlocking new capabilities, cost efficiencies and agentic speed.
A leading Global 2000 communications platform chose Next-Gen SIEM in a highly competitive 7-figure legacy SIEM replacement. Synthesizing EDR and third-party data proved easier, faster and more effective than going with a network-first SIEM product. And we're not stopping. Today, we're incredibly excited to announce our intent to acquire Onum, a leading data pipeline platform. Built on a proprietary stateless in-memory architecture, we believe Onum is the perfect complement to Next-Gen SIEM. It offers unparalleled speed, scale and efficiency in onboarding to Next-Gen SIEM while giving customers control of their data.
Onum will bring Falcon's AI-powered detections closer to third-party data sources in pipeline, starting analysis before data even enters the Falcon platform. Here's why Onum stood out to us. One, speed. Onum delivers 5x more events per second than its nearest competitor and processes data in real-time versus legacy batch and store methods. Two cost. Onum's smart filtering reduces data storage costs by 50%. Three, superior outcomes. Onum's real-time pipeline detection starts before data enters the Falcon platform, delivering up to 70% faster incident response with 40% less ingestion overhead. If our Next-Gen SIEM is the engine that powers the modern SOC, then data is the fuel that makes the engine run. Onum is both the pipeline and the filter, streaming high-quality filter fuel quickly into the engine to drive robust, efficient and superior performance.
With Onum, CrowdStrike will align with each stage of the AI life cycle, ingestion and detection of data, filtration and optimization of data as well as actioning and enforcement to produce high-fidelity autonomous outcomes across security and nonsecurity use cases. Before, migrating data into Next-Gen SIEM was a long pole in a displacement tent, often requiring third-party tools. Our acquisition of Onum is a direct response to a growing course of frustration with the incomplete data and punitive costs from today's third-party tools.
We're forging a new path. Onum and Next-Gen SIEM will enable CrowdStrike customers to focus on earlier in pipeline detection, blazing fast data streaming and high-fidelity data filtration, optimizing the agentic Next-Gen SIEM experience. Most importantly, the acquisition of Onum will give our customers control of their security, observability and IT data, uniquely positioning CrowdStrike as our customers' data foundation.
With our performant data platform as its foundation, CrowdStrike is rapidly expanding our pace of AI innovation. Charlotte is our agentic SOC analyst, automating actions and now end-to-end autonomous workflows across the SOC. Charlotte had a record quarter, growing more than 85% over Q1. We're embedding Charlotte across the entirety of the Falcon platform, empowering customers to achieve their agentic security goals out of the box with immediate ROI.
Charlotte is constantly learning and improving as we train it on our market-leading threat intelligence, battleground incident response and scaled Falcon Complete MDR analyst behavior. As one of cybersecurity's largest MDRs, our Falcon Complete SOC data is akin to the encyclopedia threat telemetry, resulting in a powerful cybersecurity AI feedback loop. Our unique cyber data advantage, coupled with our data science expertise, create a reinforcement learning flywheel, continuously adapting and improving autonomous detection and response.
The outcome is Charlotte turning our data moat into a fortified and dynamic AI wall. Our customers are facing AI disruption, which is driving our Next-Gen Identity business. As agentic identities proliferate, customers require an identity security solution to safely leverage agentic AI, preventing exploitation, misuse and breaches. We recently announced the launch of Next-Gen Identity Protection, which extends our best-in-class identity protection to nonhuman identities or NHI, SaaS applications and most importantly, AI agents. Including Falcon Shield, our Next-Gen Identity Protection business exceeded $435 million of ending ARR in Q2, growing more than 21% year-over-year.
Based on customer demand and seeing another opportunity to innovate, we launched our own PAM offering in Q1. Elevated uncertainty around the future of legacy PAM tools is driving heightened interest in our Next-Gen PAM solution. Driven by the excitement for Next-Gen Identity Protection and Next-Gen Privilege Access, these new solutions significantly expand our identity opportunity.
A leading global consulting firm decided to replace their legacy PAM after years of frustration with cost, limited efficacy and point product woes. Our ability to deliver privileged account password rotation, privileged user identification and risk assessment, privileged escalation detection, user risk profile insights and flexible MFA controls for different departments helped this customer consolidate with confidence. With nothing new to deploy, this customer seamlessly met all device trust, escalating privilege and cyber insurance requirements.
Moving to our Cloud business, the rapid adoption of AI has placed a spotlight on the importance of securing cloud infrastructure at run time. While out-of-band posture tools can lend an overall view of security health, they are incapable of stopping breaches. CrowdStrike is a leader in cloud runtime protection with the largest and most sophisticated enterprises trusting us to protect their most critical production environments.
With the need to secure AI as a backdrop, we delivered impressive net new ARR in Cloud this past quarter. Total Cloud ending ARR exceeded $700 million, growing more than 35% year-over-year. A Fortune 500 energy supplier selected Falcon Cloud Security in a 7-figure win. The ease of adoption for our single-platform approach and having ASPM already natively integrated drove this win. Our ASPM reduced months of manual work into minutes. Through this upsell, Falcon Cloud Security consolidated more than 10-point products across CNAP, CSPM, ASPM, CDR and container security.
Contributing to our platform growth is our revolutionary Falcon Flex model, helping customers accelerate and maximize Falcon platform adoption. In Q2, we crossed 1,000 Falcon Flex customers, adding more than 220 new Flex customers. Not only are we and our partners successfully landing new Flex deals, we also continue to see increases in: one, platform adoption. Utilization of Flex contracts is more than 75% across the Flex customer base; two, re-Flexes. We more than doubled the number of re-Flexed accounts to nearly 10% of all Flex customers. In just an average of 5 months from their initial Flex subscriptions, this cohort of Flex customers found themselves wanting more modules and more consolidation.
Re-Flexes on average are yielding a nearly 50% uplift in Flex customer ending ARR, illustrating the strength of the Falcon platform and the power of our game-changing licensing model. Re-Flex activity gives us conviction in our net new ARR acceleration, highlighting the difference between a onetime ELA and the recurring Flex model.
A lighthouse example of the re-Flex motion was with a Fortune 500 software firm which completed an 8-figure re-Flex. 18 months prior to their initial Flex subscription expiration, this customer decided to take their next strategic step with CrowdStrike, enabling them to modernize their SOC by replacing a legacy SIEM and a hyperscaler SIEM. They also adopted Charlotte to identify threat hunting and SOC operations. What was recently a very successful Flex has become an even more impressive re-Flex.
Consolidation isn't just a phenomenon with our customers. We also see it with our ecosystem partners. Diverse partner types are continuing to standardize on Falcon as their cybersecurity platform of choice. Take Red Canary, an MDR focused on the mid-market to small enterprise recently acquired by Zscaler, one of our strategic technology partners. Red Canary decided to consolidate and migrate their legacy point product EDR installed base of more than 100,000 endpoints across hundreds of customers onto Falcon.
Through a multimillion-dollar Q2 transaction, Red Canary is migrating these customers to CrowdStrike, where they will enjoy Red Canary's MDR services delivered on the Falcon platform. Red Canary is just one of the many MSSPs who build their business on CrowdStrike. Further into the SMB market, Amazon Business Prime selected CrowdStrike Falcon Go for millions of businesses around the world. Business Prime members now receive Falcon Go as part of their subscription, opening a significant sub-100 user TAM. This partnership highlights our ability to strategically monetize new markets and migrate underserved segments from legacy ineffective technologies.
And lastly, industry stalwarts like NVIDIA continue to choose CrowdStrike as their cybersecurity partner of choice. With our recently announced integration of Falcon Cloud Security, with NVIDIA universal LLM NIM microservices and NeMo Safety, NVIDIA customers now benefit from full AI life cycle protection for over 100,000 LLMs through Falcon. Partners sourced over 60% of Q2 new business, highlighting our ecosystem's competitive advantage and leadership across all customer segments.
I started my remarks talking about acceleration. AI is accelerating every aspect of our society and revolutionizing the way we work, but it's also accelerating the adversary. I know all too well that there is no peace time in cybersecurity. The adversary never rests. The world is soon to embark on the largest arms race ever, the arms race over AI superiority. The world's AI infrastructure necessitates protection from development to deployment, from cloud to endpoint, and from human to agent.
CrowdStrike isn't just a passenger in this revolution, we're driving it. We're becoming the foundation of our customers' AI future, delivering the security platform that makes AI transformation possible. Looking forward, AI-driven market demand and customer-driven consolidation, brought together by our revolutionary Flex licensing model, drive my belief in sustained growth. In light of the demand environment and our platform superiority, our guidance now assumes back half net new ARR will grow at least 40% versus last year. With that, I'll turn the call over to Burt Podbere, CrowdStrike's CFO.
Thank you, George, and good afternoon, everyone. We delivered a strong second quarter, exceeding expectations across all guided metrics. We achieved record Q2 net new ARR of $221 million and net new ARR reacceleration a quarter ahead of our expectations, growing ending ARR to $4.66 billion, up 20% over last year. Market demand for our AI native Falcon platform and Falcon Flex subscription model drove strength across the business. The number of deals with total deal value over $10 million doubled year-over-year, and we reached a new milestone of 800 customers with ending ARR exceeding $1 million.
As George highlighted, customers are increasingly consolidating their security operations onto the Falcon platform as they modernize their security stack for the AI era. This momentum is reflected in our module adoption metrics with 48%, 33% and 23% of subscription customers adopting 6, 7, and 8 or more modules, respectively. Most notably, among our customers with over $100,000 in ending ARR, we reached a new milestone with 60% adopting 8 or more modules, demonstrating the power of our platform consolidation strategy.
Looking into the back half of the year, the combination of strong Falcon Flex momentum, record Q3 pipeline and increasing demand for our AI-powered innovations reinforces our conviction in driving year-over-year growth acceleration in both net new ARR and ending ARR. Moreover, we have a clear line of sight to well exceed the $5 billion ending ARR milestone by fiscal year-end, achieving the ambitious goal we set in 2022 as we execute on our path to $10 billion in ending ARR by FY '31.
Moving to the P&L. Total revenue exceeded our guidance range and grew 21% over Q2 of last year to reach $1.17 billion. Subscription revenue grew 20% over Q2 of last year to reach $1.10 billion, and professional services revenue was a record $66.0 million. The geographic mix of second quarter revenue consisted of approximately 67% from the U.S. and 33% from international geographies, with both U.S. and EMEA year-over-year growth accelerating compared to Q1.
Total non-GAAP gross margin was 78% and non-GAAP subscription gross margin remained best-in-class at 80% of revenue. Total non-GAAP operating expenses in the second quarter were $652.5 million or 56% of revenue. In the second quarter, non-GAAP operating income was a record $255.0 million and operating margin was 22%, exceeding our guidance. Strong top line performance and efficiency gains from our strategic plan drove the outperformance in profitability, highlighting our commitment to profitable growth as we accelerate net new ARR growth and execute on the path to achieving our target operating model.
GAAP net loss attributable to CrowdStrike was $77.7 million and included $35.7 million of expenses for outage and related matters and $38.4 million of strategic plan-related charges. Non-GAAP net income attributable to CrowdStrike was a record $237.4 million or $0.93 on a diluted per share basis, exceeding our guidance. In Q2, our long-term projected non-GAAP tax rate decreased to 21% from 22.5%, reflecting recent changes in tax legislation and resulting in a $0.03 benefit on a diluted per share basis.
Moving to cash. Our cash and cash equivalents grew to a record $4.97 billion. We generated record Q2 cash flow from operations of $332.8 million and record Q2 free cash flow of $283.6 million or 24% of revenue. Expenses for outage-related and strategic plan costs impacted Q2 free cash flow by approximately $29 million.
Moving to our outlook and modeling notes. Our leadership is showcased by our record Q2 performance, strong Falcon Flex adoption and expansion, continued strong retention rates and broad success across our AI-powered Falcon platform. This momentum further bolsters our conviction in continued net new ARR acceleration for the back half of FY '26.
While we do not guide to ending ARR or net new ARR, our revenue guidance includes the following assumptions: high single-digit sequential net new ARR growth Q2 to Q3 and at least 40% year-over-year net new ARR growth for the back half of the fiscal year, bringing ending ARR growth for FY '26 to more than 22%. Our revenue guidance also assumes a wider-than-typical range for professional services, given the strong Q2 performance. Additionally, as we discussed last quarter, as a result of our successful CCP and related partner programs, our ARR to subscription revenue assumptions includes a separation of $10 million to $15 million per quarter through Q4. When this impact begins to subside, we ask that you please reflect this when updating your models.
Moving to cash. Payments related to strategic plan costs are expected to be de minimis in Q3, and we expect to make Q3 cash payments of approximately $51 million in connection with outage-related costs. As previously discussed, we expect to exit this fiscal year with a free cash flow margin of 27% in Q4, expanding to more than 30% for the full year FY '27.
Moving to our outlook. For the third quarter of FY '26, we expect total revenue to be in the range of $1,208.0 million to $1,218.0 million, reflecting a year-over-year growth rate of 20% to 21%. We expect non-GAAP income from operations to be in the range of $256.0 million to $262.0 million and non-GAAP net income attributable to CrowdStrike to be in the range of $238.1 million to $242.8 million. We expect diluted non-GAAP net income per share attributable to CrowdStrike to be approximately $0.93 to $0.95, utilizing a 21% tax rate and weighted average share count of approximately 257 million shares on a diluted basis.
For the full fiscal year 2026, we currently expect total revenue to be in the range of $4,749.5 million to $4,805.5 million, reflecting a growth rate of 20% to 22% over the prior fiscal year. Non-GAAP income from operations is expected to be between $1,000.1 million and $1,040.1 million. We expect fiscal 2026 non-GAAP net income attributable to CrowdStrike to be between $922.4 million and $954.0 million. Utilizing a 21% tax rate and approximately 256 million weighted average shares on a diluted basis, we expect non-GAAP net income per share attributable to CrowdStrike to be in the range of $3.60 to $3.72.
Finally, Fal.Con 2025 begins on Monday, September 15. With over 100 sponsors and over 8,000 attendees, Fal.Con is going to be our largest customer event yet. We will hold an investor briefing during the conference on Wednesday, September 17. The briefing will be webcast live on our Investor Relations website, and we look forward to seeing many of you there. George and I will now take your questions.
[Operator Instructions] Our first question comes from Andy Nowinski with Wells Fargo.
2. Question Answer
I'm really impressed with the many new products you launched this quarter, particularly on the identity side. But I do have a question around the revenue guidance that you gave for both Q3 and the full year. I'm wondering if the partner rebate program you talked about last quarter remains in effect for the remainder of the year or if it goes beyond that. And if so, is that $10 million to $15 million per quarter that you just mentioned, I mean, is that -- I guess, is that factored in into your revenue guidance? Or is there more to it than just the partner rebate program?
Thanks, Andy. It's Burt. Hey, first, let me start off by saying that ARR is the best leading indicator of our business. We've used it since we went public. George and I talk about it all the time. First and foremost, we're very pleased with net new ARR performance in the quarter as well as our record Q3 pipeline.
Second, our guidance now assumes back half net new ARR will grow at least 40% versus last year with high single-digit sequential net new ARR growth in Q2 to Q3 and ending ARR growth for FY '26 to be more than 22%. Finally, we did give a wider range than typical for pro services and for partner rebates. Last year after the outage, we made an investment in our partners through these programs. And that has paid off and has helped us sustain our high retention rates and accelerating the new ARR. As previously stated, we expect the impact of CCP and special partner programs to subside starting in Q4 of FY '26. We would do this all again, Andy, 100% of the time. Making those investments really paid off for us.
Your next question will come from Matt Hedberg with RBC.
George, it was really interesting to hear you talk about identity. It seems like you're having a lot of success there with Shield and even some legacy displacement as well as your PAM acquisition now. Given the announced Palo Alto-CyberArk deal, can you talk a little bit more holistically about how you're thinking about targeting the identity market versus some of the pure plays and just kind of how you see this market evolving over time?
Well, yes, thanks for that. When you look at identity, this is something that we were well ahead of the curve in identifying in 2020, which is why we did the Preempt acquisition. We took the time. We've integrated it. It's a key part of our platform and our fabric today. Our customers love it. And they want more. They've been asking us for years to come out with a PAM solution, which we did in Q1. They're looking for alternatives, and they're looking for a next-gen technology that isn't just legacy stitched together.
So from the standpoint of identity, we've identified it very early as a key element to solving the security breach problems that are out there. With the announcement we made this quarter in terms of our Next-Gen Identity, which includes Shield, the uptake has been fantastic. We look at the breaches that are happening today. A huge part of that is in the enterprise SaaS market, right? And our product, Shield, combined with our other identity solutions, are key in helping prevent these.
So I think we're in a perfect spot and we're in a position where customers are demanding alternatives to legacy solutions. And we're going to continue to evolve. But the good news is we've been in the market since 2020. We've recognized identity is critical very early on.
Your next question will come from Saket Kalia with Barclays.
Nice quarter.
Thank you.
George, maybe for you. Thanks a lot for that comment on just the second half net new ARR growth of 40%. That's great to hear and I think very useful. Maybe the question is, what are you seeing from the customers who bought those customer care packages? That, of course, offered those customers great value in the wake of the outage. How do you maybe think about that net retention in the second half? And just as importantly, how helpful can Falcon Flex be in that process? Does that make sense?
Yes, it's a great question. And I have to go to the historical numbers on our renewal rates for modules. So 95-plus percent of the time, a customer will renew a module once they adopt it. So I got to start with that. Obviously, CCP was a new element for us, right? But when you look at the value that we provide in these modules and once customers see it, integrated into the platform and into their workflows, 95%-plus they're going to renew it. So we feel confident that we'll see these CCP packages roll into renewals.
And we've spent the last number of months working with customers and making sure that we've got the right level of success there. So I feel good about that. And obviously, that will take place in Q3 and Q4. And overall, when you've got the right platform solving real problems that are out there, that's a good thing for us and it's a good thing for customers. Flex, of course, is a big part of that. Remember, our CCP program, a lot of it was delivered through Flex. So we were able to seed the market much more rapidly in the Flex licensing mechanism than we would have. So we leveraged the CCP program to actually seed Flex and now we have the ability to re-Flex them on those CCP packages as they burn off.
Your next question will come from Brian Essex with JPMorgan.
George, I had a question for you on Onum. It looks like this is pushing in the direction of real-time analysis on streaming data. And I'd love to get your sense of how this -- how you envision this competing against legacy solutions, and also how you think it will either complement or potentially cannibalize what you're seeing on LogScale. I know from a practical standpoint, how do customer -- how do you anticipate customers utilizing this platform relative to what they're already using on a Next-Gen SIEM basis?
Well, first, let me say how excited I am about this acquisition. This is something, I think, really going to supercharge our Next-Gen SIEM business, which includes LogScale and something customers have been asking for. They're looking for a modern pipeline technology that will be able to get data, whether it's security data or IT data from 1 place to another. But the amazing thing about the technology is the in-pipeline detection. So we can begin doing detections at the point really of forwarding for third-party data, which is critical and it gives us tremendous flexibility.
And it's a great value prop for customers, right? Less data to move around and quick results, if you will. I think what's important, and I want to reiterate is our pricing in Next-Gen SIEM is very disruptive. Why is that? Well, we actually don't charge customers for data that CrowdStrike generates. This is why we're seeing so many displacements. If you think about legacy SIEMs, people have to take data out of our platform and put it somewhere else and pay for it. They actually don't have to do that with CrowdStrike. They only pay for the ingest of the third-party data.
Now we have other ways to monetize retention and those sort of things. But between Onum and between the way we actually price and the way we can run it because the technology is very scalable, we again think this is a tremendous value for customers and will be disruptive to the market.
Your next question will come from Gabriela Borges with Goldman Sachs.
George, I actually wanted to revisit some of the dynamics of competition on EDR in particular. One of the things we see in technology is invariably, CrowdStrike has been really good at innovating with some of the leading-edge modules that you've introduced over the years. Maybe just remind us, how do you feel about EDR? Are you seeing within the Flex contracts equal interest in EDR? Or are customers maybe -- is it all else equal with modules between EDR and the U.S. stuff? And to what extent are you still landing customers in EDR?
Well, I mean, 2 things are important. One is to realize that the modern SOC is built on EDR and it's built on SIEM, and in our case, Next-Gen SIEM. So without that EDR data, it becomes very difficult to manage and execute on Next-Gen SIEM and all the AI elements on top of it. We're the leader, as many third-party organizations have pointed to, in that space. We've pioneered it. And we continue to innovate, which is really important.
And the thing to remember is when you look at EDR, it's a way to get telemetry into the platform. But then you have all of the other AI elements across the platform. It also then allows the collect once, reuse many philosophy that we have so we can light up all the other modules. And I think a key element is, and customers are seeing this, there is a huge difference in the service layer that we put on top of EDR, things like Overwatch or Complete. Competitor's not even close in this area.
So what we're focused on is stopping the breach, and it's a combination of our technology and the service overlay, which is highly automated. But between those, people are really seeing the distinction. And then when you wrap it with Next-Gen SIEM and Charlotte AI on top of it, it's really a winning combination. So we're the leader in it. We continue to invest and we continue to innovate, and that's a core part of our DNA.
Your next question will come from Joe Gallo with Jefferies.
It was awesome to see the $700 million in Cloud ARR growing 35%. Can you just talk through an update on that competitive environment? Has that stabilized? And where are customers in the journey to vendor consolidation for cloud security?
Sure. It's still in the early days. When you look at Cloud Security, it really 2 paths to go down, right? CSPM, which is really more of a kind of a vulnerability exposure policy, doesn't really do any enforcement. And that was an easy button for a lot of customers. And certainly, vendors had success in that area. I think what people have realized as the market matures a bit is you really need cloud workload protection, which is something that CrowdStrike helped to pioneer and we have leading technology in that area.
So when you combine that with ASPM, right, or DSPM or SaaS security posture management and all of the other technologies, we have a very fulsome offering underpinned by cloud workload protection. So given the disruption in the market, we've seen tremendous interest and conversions with customers. So still very early innings but we are very excited about being one of the largest cloud security providers in the market by revenue. And we continue to invest and innovate there. And I think it's a perfect time, given the market dynamics, to take advantage of it.
Your next question will come from Mike Cikos with Needham.
Leila, maybe we can go to the next question and come back to Mike.
Sure. We'll go to Tal Liani with Bank of America.
Yes. Can you hear me?
Yes. Hi, Tal.
So if you wouldn't tell me that ARR is going to grow 40% a year -- 40% year-over-year in the second half, I would have told you that growth is clearly decelerating because your growing -- ARR is growing on a constant basis, 5%, around 5% a quarter on a sequential basis. And that translates into deceleration on a year-over-year basis. You started with about 32% last year, and every quarter, it slows down to about [ 20.5% ]. But now you're giving this guidance of 40% growth in the second half. And the question is, what drives it and how sustainable is it? So when you think kind of beyond just the year-over-year impact of the CCP and what happened last year, how sustainable is this acceleration of growth?
Yes, I'll start, and then George could kick in. So there are a lot of factors that give us confidence in the back half. We talk about how we're a consolidator, that continues. AI, that's a big piece of who we are. And I think that when you combine those 2 with the strength of the platform, these are the things that give customers confidence in going with us.
Certainly, as we've moved through our journey, the biggest piece that I see out there for us in terms of how we're going to continue to reaccelerate growth is this opportunity for customers to lean in more with us with Flex. Flex has been extremely well received. Customers are able to easily implement it. It's very easy in terms of to procure. And at the end of the day, it allows customers to be able to use Flex as they need it. And we've already given out a lot of stats with respect to how fast they're burning through their Flex licenses, which has been fantastic for them and fantastic for us. With that, I'll turn it over to George.
Yes. I think Burt covered sort of the financial mechanics around that. I guess what I would comment on is what I hear in the field. I spend day and night with customers, and it's all about how we're solving problems that can't be solved by other companies, how we are the #1 security product for stopping breaches in some of the largest enterprises around the world, and how customers want to go in more with us and consolidate around CrowdStrike.
So I kind of look at the feedback that I get and I look at the threat environment. We have one of the largest incident response practices in the world. And we're in helping noncustomers cleanup breaches from other technologies that they thought they were getting a good deal on. As I've said in the past, a good deal on a leaky lifeboat isn't really a good deal. So when you look at the end goal of saving time, money, and consolidation with the right outcome of stopping breaches, that's what our customers are buying and that's what I'm hearing. So that's why I get confident in the back half.
Our next question, we'll return to Mike Cikos with Needham.
This is Jeff Hopson on for Mike. Can you guys hear me okay?
Yes.
Perfect. Congrats on the impressive Charlotte AI growth. I'm just looking for any insights to specific features that may have pushed customers to adopt. Or I guess on the flip side, any hurdles that are keeping some organizations on the sidelines as some are still hesitant to adopt AI overall?
Well, if you look at Charlotte and its maturation, as with many technologies, these technologies mature very quickly. We've invested a lot into Charlotte. And the fact is we spent a lot of time early on, on the architecture so it's not a chatbot, right? It is something as an orchestration layer that is wired into all of our modules. It's wired into our workflows, and it was really designed for agentic security and security use cases. So customers are solving problems.
What do I mean by that? Tasks that would take 4 days to actually investigate and understand and kind of piece things together now taking an hour. The ability to have Charlotte, right, reports automatically for you. The ability for Charlotte to triage and act autonomously as a Tier 1 analyst, this is what gets customers excited and this is really what's powering the next-gen SOC. So customers are seeing every release more and more features and more and more capabilities. And just like any GenAI product keeps getting more mature and better and better.
Your next question will come from Jonathan Ruykhaver with Cantor Fitzgerald.
So my question is, when I look at the cloud-native attack surface, to me, it seems like it starts in code with misconfigurations. You have open-source vulnerabilities, insecure secrets. All those issues originate in the development stage. And we've seen move less. They capture issues, obviously in run time but it's often too late. So let me hear your strategy, George, or your view on where move to when you look at [indiscernible] Will we see further move beyond just container, et cetera?
Like anything else in security, if you could move left and capture these issues before they're put in production, it's going to be a good thing. We spent time in that area and have technologies. Our ASPM technology covers a lot of that. Our container scanning to understand vulnerabilities and open source before things are published, understanding what golden images are and providing some guardrails around that. So we've invested in those areas. We continue to invest in those areas.
I think a big part of it is going to be the AI story of understanding how all these interdependencies work in the build environments, in code and obviously, in sort of these interactions with MCP-type services. So this is something that we continue to invest in this area. And I think the AI elements we've already built are going to be extremely helpful to solve these challenges in the future.
Your next question will come from Shaul Eyal with TD Cowen.
George or Burt, a question which is not being asked frequently on your conference calls in recent quarters. $5 billion on your balance sheet. You guys focus predominantly on those tuck-in acquisitions. We just heard another 1 announced this evening. Those have been expanding the platform really nicely. Indeed, we see the great results of those historical investments. It would appear as if nothing transformational is on the horizon, and indeed, there's no need for that right now. What's the current thinking of that utilization? Pretty much steady as she goes, more tuck-ins? How are you guys thinking about it for the second half and obviously for calendar '26 and beyond?
Well, as you pointed out, we have an incredible balance sheet. Myself and Mike Sentonas and the team has spent a lot of time looking at the market, looking at the different segments that are out there and really thinking about strategically where we need to go. We certainly have a history of buying acquisitions and taking the time to integrate them. I mean, this is a hallmark of what we do and a proven track record of not just stitching things together.
So we're very thoughtful about these acquisitions. We have a certain sweet spot, which you've seen. Doesn't mean that we can't go outside of that. But we've got to find the right team, the right technology, the right company that makes sense for CrowdStrike. So our #1 goal is to be thoughtful, make sure that it's a fantastic user experience for our customer. And we're not just trying to buy ARR for the sake of ARR. It's got to make sense and it's got to be something that we can execute on and feel really good about.
Our next question will come from Ittai Kidron with Oppenheimer.
Congrats again on a good quarter. I wanted to go back to Gabriela's question on your core EDR business. If you take a look at your ARR and you exclude your [ Fab 3 ], your SIEM, Identity and Cloud Security and you look at the ARR growth of your core business, it seems like it significantly decelerated. It was growing 18%-plus a year ago. It's growing 11% now. How should we think about your core business growth going forward? Do you expect stability there? Are there any potential accelerators in that business? Or just given the size, we should expect that business to continue to decelerate going forward?
Yes. I don't look at it as core, I look at it as a platform. And the platform piece actually sets up all the other modules. So when you look at the 3 that you just articulated, whether it's Identity, Cloud, Next-Gen SIEM, it's all predicated on getting the telemetry into the cloud, which starts with EDR. So we feel really good about that. And I think when you look across the entire platform, you need to look at it as a platform, not separate kind of things out.
But from my perspective, we continue to innovate there and we continue to win. We continue to drive new business and I think people, again, looking for the best technologies with the right outcome, stopping the breach, choose CrowdStrike. And that's what we've seen time and time again.
Your next question will come from Roger Boyd with UBS.
Can you hear me okay?
Yes.
George, I wonder if you could compare and contrast your businesses in SIEM and Identity. Both are roughly similar scale but the growth rates are pretty different. How much of that difference would you attribute to the M&A disruption you've seen in the SIEM market? And given what's happening in the identity market as well as your expanded portfolio there, what's the level of conviction in reaccelerating that identity business from here?
Sure. Well, identity is a key area for us as I talked about. Obviously, we've got the Next-Gen offering that we announced. And I guess the positive news is that Identity was a very popular choice for CCP packages, so you'll see a little bit of impact from that. So I think when you look at identity, it is something that is going to be -- continue to be adopted by customers. There's still a lot of white space out there.
And I think when you look at the SIEM market itself, we're in the perfect spot. Customers are coming to us. They've come to us for years saying, we want something different. We were locked into a vendor. We're being charged too much. Give us something that's better, faster, cheaper that's integrated into your platform. And as I mentioned earlier, it's pretty disruptive. Customers are not paying to take data out of our platform and putting it somewhere else. They actually get it and they're only paying for data they put in.
So I feel really good about both of those businesses. And again, when you put them together and you look at how we're solving problems, Identity, Next-Gen SIEM, Cloud, I mean, these are all critical elements to the future of the company. And I think we've got really good performance around it.
Your next question will come from Jonathan Ho with William Blair.
Let me congratulate you on a strong quarter as well. When we look at cybersecurity to protect agentic AI, you have many of the pieces to help customers solve the AI challenge, yet spending in AI remains fairly fragmented. What are customers buying today? And specific to agentic AI, what categories are you most excited about right now?
Well, certainly, customers are in the early journey of how they leverage AI. And it's moving from, hey, this is really a cool technology to how do we implement it and implement it securely and do it in a way that actually accrues value back to the business. If we believe in AI, and we think there's going to be more AI in the future, in the next year, 3 or 5 years, then security is a necessity. You're not going to have more AI without security.
And what that looks like is everything from helping organizations create secure models to deploying those models, to creating guardrails, to creating visibility into these AI agents and protecting them. If you look at what CrowdStrike does, we're the leader in agent security and protecting computers and workloads, right, which is essentially protecting users, identities, data, workflows. An AI agent is just a superhuman. So we're in the perfect situation to be able to capture protecting all of these super AI agents in the future, and that's a big part of our strategy. So we're working on what's here today and we're also working on the future of protecting these agents.
Your next question will come from Adam Borg with Stifel.
Maybe just on Exposure Management, it was great to hear crossing the $300 million threshold. Love to hear the traction you're seeing. And is this really living alongside what you'll call the traditional VMware exposure vendors or is this displacing them? Any thoughts here would be really helpful.
Yes. It's an exciting business for me. I mean, it's one, in a prior life, I started a company called Foundstone in vulnerability management space. So to see where it's evolved and now into exposure management is exciting. We've got so many assets in terms of agent vulnerability management. And one of the things that may have passed some by is that we, a few quarters ago, added network vulnerability management and we can do that right from our agents across the network. So that's been very well received.
And we've got attack surface management and a host of sort of risk management technologies bundled in there. So I think we're really hitting the sweet spot in the market. And again, it goes to customers want to consolidate. And we've got some great big wins out of it. So -- and I guess the final piece is it's been recognized as a leader in the inaugural IDC Marketscape. So all good things and certainly a needed technology, it may sometimes feel a little sleepy but it's a really rapidly growing business for CrowdStrike.
Your last question will come from Adam Tindle with Raymond James.
Save the best for last. I wanted to continue on the acceleration theme. The net new ARR guidance implies another record of net new ARR for Q3. So I guess the first one for Burt. If you could just talk around assumptions for public sector, given that's Fed fiscal year-end. And then separately, you previously talked about net new ARR accelerating again in fiscal '27. I wonder if that still holds.
For George, real quick since I'm last here. Bigger picture, if I look at your back half guide for net new ARR, you're going to be run rating over $1 billion on that metric. It's a huge milestone, and I just wonder how you're thinking bigger picture about structural changes or things that you need to do to manage an organization of that size.
It's Burt. I'll take the first part. As we stated many times, fed today is not a big piece of our business. But there's a great opportunity for us. The Fed has come out and said they want to run like in the private sector. They want to consolidate, they want to reduce cost. They want to become more efficient. That plays right into our sweet spot. So we feel that there's a Fed opportunity out there for us. But those deals, they take time and we're patient and we want to land the right deals at the right time, but we're excited about that opportunity.
For us, at the end of the day, we've got great certifications with the federal government and we'll take advantage of it. In terms of FY '27, we'll give more comments about FY '27 at the end of our Q4. But we're excited about just the 40% acceleration in net new ARR in the back half. That, to us, should signal to you that we have a lot of confidence in the business, and we've got a lot of things that I talked about earlier that give us that confidence in the business. George, if you have anything else?
Yes. I guess I would add that there's always ways to optimize. I think when you look at go-to-market and you look at how we've evolved from selling modules into selling Flex and platform and activation, we've got to organize for success to make sure that we continue to work with our customers around this consolidation journey and activating more Flex. And I think we've done a good job of that.
But there's different ways to help optimize that. And then we have to take those learnings and apply it to our partner and channel communities. So we're always looking at, again, how do we optimize and how do you take the platform vision that we have and the execution that we see in the field from a selling perspective and make it as impactful as we can. So I think that will be something we continue to look at.
And that concludes the question-and-answer session for today. I'll hand it back to George for closing remarks.
All right. Thanks, Maria. So thank you all for joining us today. We look forward to seeing you soon at Fal.Con 2025. Thank you.
CrowdStrike Holdings Inc — Q2 2026 Earnings Call
Financial data from CrowdStrike Holdings Inc
Revenue
Revenue is the sum of all sales generated by a company, e.g. for its products or services.
Revenue (TTM) metric explainedDirect Costs
Direct costs are the costs incurred directly in connection with the manufacture of the product or service.
Gross Profit
Gross Profit indicates how much of the revenue remains in the company after deducting direct production costs. If the percentage share of sales is calculated, this is referred to as the gross margin.
Gross Profit metric explainedSelling and Administrative Expenses
Selling, general and administrative expenses (SG&A) include all expenses for marketing and sales as well as the general administration of the company.
Research and Development Expense
Research and development costs (R&D) provide information on how much the company invests in the research and development of its products. The costs are particularly interesting as a percentage of revenue and in comparison to direct competitors.
EBITDA
EBITDA (Earnings Before Interest, Taxes, Depreciation and Amortization) is the company's earnings before interest, taxes, depreciation and amortization. The EBITDA margin is calculated as a percentage of sales.
Depreciation and Amortization
Depreciation represents reductions in the value of the company's assets (e.g. due to wear and tear on machinery).
EBIT (Operating Income)
EBIT (Earnings Before Interest and Taxes) is the company's profit before interest and taxes, also known as the operating income. The EBIT Margin is calculated as a percentage of sales at
.
Net Profit
Net Profit represents the profit or loss after deduction of all costs.
Net Profit metric explainedStocksGuide Free
| Jul '26 |
+/-
%
|
||
| Revenue | 5,396 5,396 |
24%
24%
100%
|
|
| - Direct Costs | 1,336 1,336 |
20%
20%
25%
|
|
| Gross Profit | 4,060 4,060 |
26%
26%
75%
|
|
| - Selling and Administrative Expenses | 2,631 2,631 |
16%
16%
49%
|
|
| - Research and Development Expense | 1,556 1,556 |
25%
25%
29%
|
|
| EBITDA | -126 -126 |
56%
56%
-2%
|
|
| - Depreciation and Amortization | 1.25 1.25 |
1%
1%
0%
|
|
| EBIT (Operating Income) EBIT | -128 -128 |
55%
55%
-2%
|
|
| Net Profit | 58 58 |
121%
121%
1%
|
|
In millions USD.
Don't miss a Thing! We will send you all news about CrowdStrike Holdings Inc directly to your mailbox free of charge.
If you wish, we will send you an e-mail every morning with news on stocks of your portfolios.
CrowdStrike Holdings Inc Stock News
Company Profile
CrowdStrike Holdings, Inc. is a holding company, which engages in the provision of cloud-delivered solution for next-generation endpoint protection that offers cloud modules on its Falcon platform through SaaS subscription-based model. It operates through Domestic and International geographical segments. The firm's services include incident response services; proactive services, tabletop exercises, adversary emulation, clod security assessment, and blue team exercises. The company was founded by George P. Kurtz, Marston Gregg, and Dmitri Alperovitch on November 7, 2011 and is headquartered in Sunnyvale, CA.
StocksGuide Free
| Head office | United States |
| CEO | Mr. Kurtz |
| Employees | 10,698 |
| Founded | 2011 |
| Website | ir.crowdstrike.com |


