Fortinet (FTNT) 10-K risk factor changes: FY2025 vs FY2024
The 2025-12-31 10-K against the 2024-12-31 one, compared heading by heading and sentence by sentence.
Item 1A125 rewritten57 added40 removed802 unchanged
All filing items988 rewritten460 added372 removed2,333 unchanged
Summary
counted, not written
- Item 1A lists 59 risk factor headings: 3 new, 5 reworded and 51 unchanged since FY2024. 1 heading from FY2024 no longer appears.
- Sentence by sentence, 460 added, 372 removed, 988 rewritten and 2,333 unchanged across 20 items that differ.
New Item 1A headings (3)
- Our billings, revenue and free cash flow growth, including our product and service billings and revenue, may slow, and our operating margins may decline, particularly if our billings and revenue do not improve or grow as anticipated, or if customer demand, renewal rates, pricing, competitive dynamics, implementation timing, cost structure, or macroeconomic conditions adversely affect our business, which could negatively impact our financial condition and results of operations.
- Actual, possible or perceived defects, errors or vulnerabilities, including critical vulnerabilities, in our products or services, the failure of our products or services to detect or prevent a security incident or the misuse of our products could harm our and our customers’ operational results and reputation.
- We are currently, and may in the future become, involved in litigation that may adversely affect us.
Removed Item 1A headings (1)
- Our billings, revenue and free cash flow growth may slow or may not continue, and our operating margins may decline.
Reworded Item 1A headings (5)
- Our real estate investments, including construction,
[removed: acquisition][added: acquisition, development] or leasing of new data centers, data center expansions or office buildings, could involve significant risks to our business. - We rely on third-party channel partners for substantially all of our revenue. If our partners fail to perform, our ability to sell our products and services will be limited, and if we fail to optimize our channel partner model going forward, our operating results may be harmed. Additionally, a small number of distributors represents a large percentage of our revenue and accounts receivable, and one distributor accounted for
[removed: 31%][added: 32%] of our total net accounts receivable as of December 31,[removed: 2024.][added: 2025.] - Because we depend on several third-party manufacturers to build our products, we are susceptible to manufacturing delays that could prevent us from shipping customer orders on time, if at all, and may result in the loss of sales and
[removed: customers, additional][added: customers; additionally] third-party manufacturing cost increases and changes in the geopolitical environment could result in lower gross margins and free cash flow. - Investors’ expectations of our performance relating to
[removed: environmental, social][added: corporate responsibility] and[removed: governance][added: sustainability] factors may impose additional costs and expose us to new risks. - Political instability, changes in trade [added: policies and] agreements and conflicts
[removed: such as the war in Ukraine]could adversely affect our business and financial performance.
A heading is new when no FY2024 heading matches it after ignoring case and punctuation, and reworded when it shares at least 60 percent of its words with one that went away. All current risk factor headings.
Sentences by item
24 items, with every count and a link to each item that changed
Underlined words on a shaded ground are new in FY2025; struck-through words were in FY2024. Sentences that are wholly new or wholly gone are labelled rather than marked.
Item 1A. Risk Factors
125 rewritten, 57 added, 40 removed, 802 unchanged
- [added: adverse] economic conditions, including macroeconomic and regional economic challenges resulting, for example, from a recession, [removed: tariffs] [added: tariffs, disruptions of global supply chains] or other economic downturn, increased inflation or possible stagflation in certain geographies, changing interest rates, the war in Ukraine, tensions between China and Taiwan, [added: conflicts in the Middle East] or other factors;
- sales strategy, productivity, [removed: retention] [added: hiring] and [added: retention, and] execution, and our ability to attract and retain new end-customers or sell additional products and services to our existing end-customers, including customer demand for platform solutions like ours versus point solutions;
- component shortages, including chips and other components, and product inventory shortages, including those caused by factors outside of our control, such as [removed: epidemics and pandemics,] [added: international trade disputes or tariffs, labor or] supply chain disruptions, inflation and other cost increases, international [removed: trade disputes or tariffs, natural disasters, health emergencies, power outages, civil unrest, labor disruption, international] conflicts, terrorism, wars, such as the war in [removed: Ukraine] [added: Ukraine, tensions between China] and [added: Taiwan, conflicts in the Middle East,] critical infrastructure [removed: attacks;][added: attacks, natural disasters, health emergencies, epidemics and pandemics, power outages and civil unrest;]
[removed: A] [added: Generally, a] reduction to backlog increases our aggregate billings and revenue during the quarter when delivered;
- supplier [added: or regulatory] cost increases and any lack of market acceptance of our price increases designed to help offset any supplier [added: or regulatory] cost increases;
- the impact to our business, the global economy, disruption of global supply chains and creation of significant volatility and disruption of the financial markets due to factors such as [added: tariffs and policy disputes,] increased inflation or possible stagflation in certain geographies, changing interest rates, the war in [removed: Ukraine] [added: Ukraine, tensions between China] and [added: Taiwan, conflicts in the Middle East and] other factors;
[removed: - defects or vulnerabilities, including critical vulnerabilities, in our products or services, as well as reputational harm from the failure or misuse of our products or services, and any actual or perceived defects or vulnerabilities, including critical vulnerabilities, in our products or services, failure of our products or services] to detect or prevent a security incident or to cause a disruption to operations, failure of our customers to implement preventative actions such as updates to one of our deployed solutions or failure to help secure our customers;
- increased expenses, unforeseen liabilities or write-downs and any negative impact on results of operations from any acquisition or equity investment, as well as [removed: accounting risks,] integration risks related to product plans and products and risks of negative impact by such acquisitions and equity investments on our financial results;
- any decreases in demand by channel partners or end-customers, including any such decreases caused by factors outside of our control such as [removed: natural disasters and health emergencies, including earthquakes, droughts, fires, power outages, typhoons, floods, pandemics or epidemics and manmade events such as civil unrest, labor disruption,] international trade [removed: disputes,] [added: disputes or tariffs, labor or supply chain disruptions, inflation and other cost increases,] international conflicts, terrorism, wars, such as the war in [removed: Ukraine] [added: Ukraine, tensions between China] and [added: Taiwan, conflicts in the Middle East,] critical infrastructure [removed: attacks;][added: attacks, natural disasters, health emergencies, epidemics and pandemics, power outages and civil unrest;]
- execution risk associated with our efforts to capture the opportunities related to our identified growth drivers, such as risk associated with our ability to capitalize on the convergence of networking and security, vendor consolidation of various cyber security solutions, SD-WAN, infrastructure security, security operations, [added: SASE and other cloud security solutions, endpoint protection, IoT and OT security opportunities and product refresh cycles;]
- the deferral of orders from distributors, resellers or end-customers in anticipation of new products or product enhancements announced by us or our competitors, price decreases or changes in our registration policies, or the acceleration of orders in response to our announced or expected price list [removed: increases;][added: increases, including those related to tariffs;]
- increases [removed: or decreases] in our [removed: billings, revenue and] expenses caused by fluctuations in foreign currency exchange rates or a [removed: strengthening] [added: weakening] of the U.S. dollar, as a significant portion of our expenses [removed: is] [added: are] incurred and paid in currencies other than the U.S. dollar, and [removed: the impact] such fluctuations may [removed: have on the actual prices that our partners and customers are willing to pay for] [added: negatively affect] our [removed: products] [added: financial condition] and [removed: services;][added: results of operations;]
- the impact of cloud-based and hosted security [removed: solutions] [added: solutions, including increased demand for such services and uncertainty associated with transition to providing such services,] on our billings, revenue, operating margins and free cash flow;
- political, economic and social instability, including geo-political instability and uncertainty, such as that caused by the war in Ukraine, tensions between China and Taiwan, [added: conflicts in the Middle East,] and any disruption or negative impact on our ability to sell to, ship product to and support customers in certain regions based on trade restrictions, embargoes and export control law restrictions;
- legislative or regulatory changes, such as with respect to privacy, information and cybersecurity, exports, the environment, regional component bans, and requirements for local [removed: manufacture.][added: manufacturing.]
Weak global and regional economic conditions and spending environments, based on a downturn in the economy, a possible recession and the effects of ongoing or increased inflation or possible stagflation in certain geographies, tariffs or other trade disruptions, changing interest rates, geopolitical instability and uncertainty, a reduction in information technology spending regardless of macroeconomic conditions, the effects of epidemics and pandemics and the impact of the war in [removed: Ukraine] [added: Ukraine, tensions between China and Taiwan or conflicts in the Middle East] could have a material adverse impacts on our financial condition and results of operations and our business, including resulting in longer sales cycles, lower prices for our products and services, increased component costs, higher default rates among our channel partners, reduced [removed: unit sales, lower prices and slower or declining growth.]
These can negatively impact our business by putting downward pressure on growth if we are unable to achieve the increases in [added: product prices necessary to appropriately offset the additional costs in a manner sufficient to maintain margins.]
[removed: Efforts] [added: Given the international nature of our operations, efforts] to withdraw from or materially modify international trade agreements, or to change corporate tax policy related to international commerce, could adversely affect our financial condition and results of operations as could the continuing uncertainty regarding whether such actions will be taken.
Moreover, efforts to implement changes related to export or import regulations (including the imposition of new [added: or increases in] border taxes or [added: tariff rates, changes in customs or] tariffs [added: classifications or modifications to tariff exemptions] on foreign imports), trade barriers, economic sanctions and other related policies could harm our results of operations.
While we do not currently expect [removed: these] tariffs to have a significant effect on our raw material and product import costs, if the United States expands increased tariffs, [added: changes in customs] or [added: tariffs classifications or modifications to tariff exemptions or if] retaliatory trade measures are taken by other countries in response to the [added: U.S.] tariffs, the cost of our products could increase, our operations could be disrupted or we could be required to raise our prices, which may result in the loss of customers and harm to our reputation and operating performance.
Any modification in these areas, any shift in the enforcement or scope of existing regulations or any change in the countries, [removed: governments,] [added: administrations,] persons or technologies targeted by such regulations, could result in decreased use of our products by, or in our decreased ability to export or sell our products to, existing or potential end-customers with international operations and could result in increased costs.
We may experience slowing growth or a decrease in billings, revenue, operating margin and free cash flow for a number of reasons, including a slowdown in pipeline growth or for demand for our products or services generally, a shift in demand from products to services, decrease in services revenue growth, increased competition, execution challenges including sales execution challenges and lack of optimal sales productivity, worldwide or regional economic challenges based on inflation or possible stagflation, a regional recession or a recession in the global economy, changing interest rates, [removed: the war in Ukraine,] [added: as] a [added: result of regional conflicts, a] decrease in the growth of our overall market or softness in demand in certain geographies or industry verticals, such as the service provider industry, changes in our strategic opportunities, execution risks, lower sales productivity and our failure for any reason to continue to capitalize on sales and growth opportunities due to other risks identified in the risk factors described in this periodic report.
Our real estate investments, including construction, [removed: acquisition] [added: acquisition, development] or leasing of new data centers, data center expansions or office buildings, could involve significant risks to our business.
[added: The] current global supply chain and inflation issues have exacerbated many of these construction risks and created additional risks for our business.
- unexpected lack of power access or unexpected increases in power [removed: needs;][added: needs or connectivity;]
[added: The loss of the services or the] distraction of our senior management for any reason could adversely affect our business, financial condition and results of operations.
Additionally, a small number of distributors represents a large percentage of our revenue and accounts receivable, and one distributor accounted for [removed: 31%] [added: 32%] of our total net accounts receivable as of December 31, [removed: 2024.][added: 2025.]
A significant portion of our sales [removed: is] [added: are] generated through a limited number of distributors, and substantially all of our revenue is from sales by our channel partners, including distributors and resellers.
Six distributor customers who purchase directly from us accounted for [removed: 69%] [added: 67%] and [removed: 70%] [added: 69%] of our total net accounts receivable in the aggregate as of December 31, [removed: 2024] [added: 2025] and [removed: 2023,] [added: 2024,] respectively.
See Note [removed: 16.][added: 15.]
Our channel partners may also market, sell and support products and services that are competitive with ours, and may devote more resources to the marketing, sales and support of such products, or may decide to cease selling our products and services [removed: altogether in favor of a competitor’s products and services.]
Our channel partner sales structure could subject us to lawsuits, potential liability and reputational harm if, for [added: example, any of our channel partners misrepresent the functionality of our products or services to end-customers, our service provider customers suffer a cyber event impacting end-users, or our channel partners violate laws or our corporate policies.]
[added: In addition, in the event significant customers require payment terms for] FortiGuard and other security subscriptions and FortiCare technical support services in arrears or for shorter periods of time than annually, such as monthly or quarterly, this may negatively impact our billings and revenue.
Our competitors include companies such as Check Point, Cisco, CrowdStrike, F5 Networks, HPE, Huawei, [removed: Juniper,] Microsoft, Netskope, Palo Alto Networks, SonicWALL, Sophos, and Zscaler.
Some of our existing and potential [removed: competitors enjoy] [added: competitors’] competitive advantages [removed: such as:][added: include:]
In addition, certain of our larger competitors [added: may] have broader product offerings, and leverage their relationships based on other products or incorporate functionality into existing products in a manner that discourages customers from purchasing our products.
[removed: Also, many of our smaller competitors that specialize] in providing protection from a single type of security threat are often able to deliver these specialized security products to the market more quickly than we can.
[added: Customers may accept these bundled] products and services rather than separately purchasing our products and services.
For example, in [removed: February] [added: May] 2025, our [added: former] Chief Financial Officer, Keith Jensen, [removed: announced his upcoming retirement] [added: retired] after 11 years at Fortinet.
None of our key employees [removed: has] [added: have] an employment agreement for a specific term, and any of our employees may terminate their employment at any time.
- defects or vulnerabilities, including critical vulnerabilities, in our products or services, as well as reputational harm from the failure or misuse of our products or services, and any actual or perceived defects or vulnerabilities, including critical vulnerabilities, in our products or services, failure of our products or services
- investors’ expectations of our operational performance relating to our sustainability commitments;
unit sales, lower prices and slower or declining growth.
U.S. tariffs, and any new or additional retaliatory tariffs that may be imposed by foreign countries, may also adversely affect our customers and, consequently, demand for our products.
We are monitoring this evolving situation and there can be no assurance that we will be able to mitigate the impacts of any trade measures on our business, which could adversely impact our business, operating results, financial condition, and our stock price.
Our billings, revenue and free cash flow growth, including our product and service billings and revenue, may slow, and our operating margins may decline, particularly if our billings and revenue do not improve or grow as anticipated, or if customer demand, renewal rates, pricing, competitive dynamics, implementation timing, cost structure, or macroeconomic conditions adversely affect our business, which could negatively impact our financial condition and results of operations.
altogether in favor of a competitor’s products and services.
Additionally, if our channel partners experience issues such as cyberattacks or other operational disruptions, it could negatively impact our ability to receive orders from them and, among other things, may adversely affect our billings and revenue.
Also, many of our smaller competitors that specialize
indebtedness, sell selected assets or reduce or delay planned capital, operating or investment expenditures.
Sales to these
such as managing and growing the channel business for sales to small businesses and more actively selling to the end-customer for sales to larger organizations.
Our business operations, contract awards, and revenue streams are subject to governmental actions, which may introduce risks to our financial performance and strategic growth.
In addition, these actions could eliminate or reduce the operations of an agency that we work with, terminate employees with whom we have business relations with or cancel or modify a contract with us.
Any failure to comply with these actions, shifts in federal procurement strategies, or budgetary reductions imposed by the agency could adversely impact our financial results, competitive positioning, and overall business operations; and
practice.
disclose information in order to gain access to our networks and confidential information.
potential increased costs for shipping and products, and potential delays and interruptions in the supply chain.
For example, as a result of the rapid global build-out of AI infrastructure, there is currently a global shortage of memory chips, which are a component in certain of our products.
As a result, we are currently experiencing, and may continue to experience, constraints on the availability of memory chips.
If we are unable to obtain sufficient quantities of memory chips on commercially reasonable terms, we have experienced, and may continue to experience, delays in the production and delivery of our products and increased costs to source available memory chips, any of which could harm our business, financial condition and results of operations.
To mitigate increased hardware costs resulting from these shortages, we are implementing price increases, which may negatively impact demand for our products and may not be sufficient or timely to offset rising input costs, potentially resulting in margin compression and adversely affecting our business, financial condition and results of operations.
During prior periods of supply chain disruption, including during the COVID-19 pandemic we increased our purchase order commitments.
allow users to choose “best-of-breed” defenses from among the wide range of dedicated security applications available.
Any new restrictions that negatively impact our ability to receive supply of hardware components from Taiwan would negatively impact our business and financial results.
If we are required to change third-party manufacturers, our ability to meet our scheduled product deliveries to our customers would be adversely affected, which could
Additionally, if actual demand does not directly match with
deployments and more demanding environments and business models.
Changes to our warranty reserve estimates could materially impact our gross margins and operating results.
Increased competition from other companies implementing AI more effectively or rapidly could impact customer preferences and reduce demand for our products or services.
In addition, vulnerabilities within our AI systems or solutions may be identified by competitors, researchers, or malicious actors before we detect or remediate them, which could result in security incidents, reputational damage, or loss of customer confidence.
Our AI-related initiatives may result in new or enhanced governmental or regulatory
The cost to
In addition to the GDPR, the EU has also enacted legislation that would regulate non-personal data and establish new cybersecurity standards, and other countries, including the U.K., may similarly do so in the future.
In particular, the EU Data Act went into effect in 2024 and imposes certain data and cloud service interoperability and switching obligations to enable users to switch between cloud service providers (as well as certain requirements concerning cross-border international transfers of non-personal data outside the EEA).
Additionally, the EU’s Network and Information Security Directive II, adopted in 2023, regulates resilience and incident response capabilities of entities operating in a number of sectors, including the digital infrastructure sector and provides for EU member states to have issued implementing legislation by October 2024.
Further, DORA became effective in January 2025 and imposes certain requirements on entities in the financial sector and their third-party cloud service providers related to managing and mitigating information and communication technology risk.
If we are unable to transfer data, including personal data, between and among countries and regions in which we operate, or are otherwise required to modify our practices, including our data privacy and security controls and procedures, it could affect the manner in which we provide our services, the geographical location or segregation of our relevant systems and operations, and could adversely affect our financial results.
other risks.
We are currently, and may in the future become, involved in litigation that may adversely affect us.
- as the supply chain challenges normalize, our product revenue growth rate may be lower versus prior quarters where delivery from backlog contributed more to billings.
For fiscal year 2024, the comparably lower backlog contribution to billings resulted in decreased year-over-year quarterly growth rates;
- investors’ expectations of our performance relating to environmental, social and governance (“ESG”) and commitment to carbon neutrality;
SASE and other cloud security solutions, endpoint protection, IoT and OT security opportunities and product refresh cycles;
- increased demand for cloud-based and hosted services and the uncertainty associated with transitioning to providing such services;
product prices necessary to appropriately offset the additional costs in a manner sufficient to maintain margins.
Our business benefits directly and indirectly from free trade agreements, and we also rely on various corporate tax provisions related to international commerce, as we develop, market and sell our products and services globally.
For example, in recent years, the United States has imposed additional import tariffs on certain goods from different countries.
As a result, other countries imposed retaliatory tariffs on goods exported from the United States and both the United States and foreign countries have threatened to alter or leave current trade agreements.
Our billings, revenue and free cash flow growth may slow or may not continue, and our operating margins may decline.
The
The loss of the services or the
example, any of our channel partners misrepresent the functionality of our products or services to end-customers, our service provider customers suffer a cyber event impacting end-users, or our channel partners violate laws or our corporate policies.
In addition, in the event significant customers require payment terms for
Customers may accept these bundled
We may not manufacture all
prospects not to buy from us and, in some instances, subject us to potential liability that is not contractually limited.
For example, recently, an individual gained unauthorized access to a limited number of files stored on our instance of a third-party cloud-based shared file drive, which included limited data related to a small percentage of our customers.
We do not currently believe that this incident was material as a result of our assessment of various factors, including, but not limited to, because (i) our operations, products, and services have not been impacted, and (ii) we have identified no evidence of additional access to any other of our resources.
As a result, we have not experienced, and do not currently believe that the incident is reasonably likely to have a material impact to our financial condition, operating results or business.
However, we remain subject to various
risks due to the incident and its impact, including reputational harm, adverse impacts to customer relationships, potential litigation, and additional regulatory scrutiny.
In response to component shortages in previous periods, we increased our purchase order commitments.
available.
sophisticated techniques to gain access to and attack systems and networks.
Many organizations have invested substantial personnel and financial resources to design and operate their networks and have
Under these rules, we are required to obtain sourcing data
We
defensive protection or competitive advantages to us.
product lines, integrating reporting systems and procedures, and maintaining uniform standards, controls, development practices, procedures and policies.
new operational requirements for companies and became effective on January 1, 2020.
Any change in export or import regulations, economic sanctions or related legislation, shift
For example, under the EU’s Corporate Sustainability Reporting Directive, we will be required to make certain disclosures in 2026 relating to our ESG impacts, risks, and opportunities for 2025.
In addition, the SEC adopted a rule that requires climate disclosures in periodic and other filings with the SEC covering fiscal years beginning in 2025, which rule has been stayed pending the completion of a judicial review.
To comply with this SEC rule, if such rule goes into effect in its current form, we will be required to establish additional internal controls, engage additional consultants and incur additional costs related to evaluating, managing and reporting on our environmental impact and climate-related risks and opportunities.
If we fail to implement sufficient oversight or accurately capture and disclose on environmental matters, our reputation, business, operating results and financial condition may be materially adversely affected.
jurisdiction.
Any person or entity
Inflation rates in the United States significantly increased in 2022 resulting in federal action to increase interest rates, adversely affecting capital markets activity.
such as FortiCare support and FortiGuard subscription services and could otherwise materially negatively impact our business.
An excerpt. Shown here: 40 of 125 rewritten, 40 of 57 added and all 40 removed. The counts are complete. For every sentence, read Item 1A. Risk Factors in the FY2025 filing and the FY2024 filing.
Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations
227 rewritten, 95 added, 77 removed, 305 unchanged
*•macroeconomic, geopolitical factors and other disruption on our manufacturing or sales, including [removed: the transition in administrations,] tariffs or other trade disruptions, public health issues, wars, natural disasters and economic growth;*
- *government [removed: regulation, tariffs] [added: regulation] and other policies;*
- *drivers of long-term growth and operating leverage, such as pricing of our products and services, sales productivity, pipeline and capacity, functionality, value and technology improvements in our [added: product and] service offerings;*
*•our ability to successfully anticipate market changes, including those related to cloud-based [added: and AI] solutions and to sell, support and meet service level agreements related to cloud-based solutions;*
- *trends in revenue, cost of revenue and gross margin, including [removed: expectations regarding] product revenue, service revenue and inventory related charges;*
- *trends in our operating [removed: expense,] [added: expenses,] including sales and marketing [removed: expense,] [added: expenses,] research and development [removed: expense,] [added: expenses,] general and administrative [removed: expense, and expectations regarding these] expenses;*
*•expected impact of plans and strategy for the acceleration of our data center footprint and our [removed: points of presence] [added: PoP] deployment;*
[removed: *•expectations regarding spending] [added: *•spending] related to real estate assets, acquisitions and development, including data centers and points of presence, office building and warehouse investments, as well as other capital expenditures and to the impact on free cash flow and expenses;*
- *estimates of a range of [removed: 2025] [added: 2026] spending on capital expenditures;*
[removed: *•expansions] [added: *•expansions, development, improvements, operating, subleasing] and other [removed: changes to our] real property holdings [removed: and development;*][added: activities;*]
As of December 31, [removed: 2024,] [added: 2025,] our end-customers were located in over 100 countries and included enterprises across a wide variety of market verticals, including financial services, retail, healthcare and operational technology market verticals, communication and security service providers, and government organizations.
[removed: As of December 31, 2024, we held 1,034 U.S. patents and 1,378 global patents and we] [added: We] have been recognized in over 140 enterprise analyst reports demonstrating both our vision and execution across security and networking products.
- [removed: FortiOS—FortiOS] [added: FortiOS—Our unified operating system] enables the convergence of [removed: security and] networking [added: and AI-powered security] to enforce consistent [removed: security] policies across [added: all] form factors and edges.
As the [removed: foundation] [added: foundational engine] of the Fortinet Security Fabric, FortiOS empowers organizations to unify management and [removed: analytics for comprehensive] [added: analytics, providing] network visibility and control at scale.
- FortiASIC—Our ASIC-based SPUs increase the speed, scale, efficiency and value of our solutions while [removed: improving user experience,] reducing footprint and power requirements.
[removed: - FortiCloud—Our organically built global] [added: FortiCloud is our private] cloud [removed: infrastructure,] [added: SaaS platform,] powered by FortiStack, which is our [added: secure] SaaS platform operating as a private cloud service provider and leveraging software and hardware to optimize and secure all [removed: layers, provides customers with global reach, flexible connectivity, and cost savings.][added: layers.]
- FortiEndpoint—FortiEndpoint converges secure connectivity, endpoint protection and advanced capabilities like endpoint detection and response and [removed: XDR,] [added: ZTNA,] into a single agent.
This minimizes the need for manual intervention and provides faster remediation of threats across [removed: all] environments.
- OT Security—The Fortinet Security Fabric enables security for [added: OT systems and CPS, including] converged IT/OT [removed: ecosystems.][added: architectures.]
These competitive differentiators [removed: allow us to] provide [removed: CIOs, CISOs, CTOs,] [added: networking] and [removed: their organizations] [added: security professionals] with [removed: an integrated AI-driven cybersecurity] [added: a cyber security] platform [removed: with] [added: comprised of] over 50 products across three solution [removed: pillars.][added: pillars:]
- Secure Networking—Our Secure Networking solutions focus on the convergence of networking and security via FortiOS, our networking and security operating system that is the foundation of our Fortinet Security Fabric platform and supports [removed: over 30] [added: a broad range of] functions that can be delivered via a physical, virtual, cloud or SaaS [removed: solution.][added: solutions.]
Our network firewall offerings consist of a [removed: FortiGate] [added: FortiGate, which can be deployed at branch, campus,] data center, [removed: hyperscale] [added: internal segmentation, private] and [removed: distributed firewalls,] [added: public cloud to enable hybrid mesh firewall solutions,] as well as encrypted applications (SSL inspection, virtual private network and IPsec connectivity).
Our Secure Connectivity solution includes FortiSwitch secure ethernet switches, FortiAP wireless local area network access points and FortiExtender 5G connectivity [removed: gateways.][added: gateways and NAC for securing IoT devices.]
The Fortinet Unified SASE solution includes a single-vendor SASE solution that includes firewall, SD-WAN, secure web gateway, cloud access services broker, [removed: DLP] [added: DLP, DEM, RBI] and [removed: zero trust network access] [added: ZTNA] to deliver flexible secure access for all users.
Our global and scalable cloud network includes [removed: 150+ points of presence] [added: over 190 PoPs] to deliver [removed: the] [added: a] seamless secure access experience.
[removed: Given this,] [added: Leveraging this global infrastructure,] we [added: believe we] are well positioned to support customers expanding from SD-WAN to a single-vendor SASE platform.
Additionally, we offer a full suite of [removed: comprehensive,] integrated cloud security solutions that enable customers to secure their applications from code to cloud.
Our solutions include application security that includes [removed: our] web application firewalls, cloud network security with virtualized firewalls and cloud-native firewalls, cloud-native application [removed: protection and code security.]
We deliver a holistic approach to cloud security, offering a single unified [removed: platform for cloud security and secure CI/CD application development needs,] [added: platform,] consolidating protection across multiple disparate tools, including coding, deploying, and running applications across hybrid and [removed: multi-clouds, and delivering AI-driven security across integrated solutions][added: multi-clouds.]
- AI-Driven Security Operations (SecOps)—Our AI-Driven SecOps portfolio provides a [removed: comprehensive] suite of cybersecurity solutions that identify, protect, detect, respond and recover from threats, all integrated within the Fortinet Security Fabric.
At the core is FortiAnalyzer, which serves as the central SOC platform with its unified data lake that [removed: provides] [added: provides:] built-in SIEM, SOAR, XDR and threat intelligence, enabling centralized visibility, analytics and automation with complete control.
FortiSIEM delivers [removed: robust] security information and event management for more advanced SOC requirements, while FortiSOAR enables automated orchestration and playbook-driven response.
This solution set also includes [removed: FortiEDR, FortiXDR,] [added: FortiEndpoint,] FortiNDR, FortiSandbox, FortiDeceptor, FortiDLP and FortiRecon, helping organizations achieve defense in depth, ensuring attackers face multiple layers of detection and mitigation across endpoints, networks, and applications.
FortiGuard Labs is our cybersecurity threat intelligence and research organization comprised of experienced threat hunters, researchers, analysts, engineers and data scientists who develop and utilize [removed: machine learning] [added: ML] and AI technologies to provide timely protection updates and actionable threat intelligence for the benefit of our customers.
FortiCare Technical Support Service is a [removed: per-device] technical support service, which provides customers access to experts to ensure efficient and effective operations and maintenance of their Fortinet [removed: capabilities.][added: solution.]
Organizations have the flexibility to procure different levels of service for different [removed: devices] [added: solutions] based on their availability needs.
We offer three [removed: per-device] support options tailored to the needs of our enterprise customers: FortiCare Elite, FortiCare Premium and FortiCare Essential.
In addition to FortiCare [removed: device level] [added: solution based] services, Advanced Support service options are available per account.
These services are available for regional account support in three options: Core, Pro and Pro Plus, and can be [removed: globalized] [added: available or provided on a global basis] at the Pro and Pro Plus levels.
The Fortinet Training Institute has issued [removed: over one] [added: approximately two] million certifications to date.
*•our gross margins and operating expenses for 2026;*
As of December 31, 2025, we held 1,064 U.S. patents and a total of 1,405 global patents, including 321 AI-related patents.
FortiOS includes advanced encryption and other security technologies designed to address evolving cybersecurity threats, including emerging quantum-resistant cryptographic capabilities.
- FortiCloud—Our organically built global cloud infrastructure provides customers with global reach, flexible connectivity and cost savings.
- FortiAI—FortiAI provides a dual-layered defense across the Fortinet Security Fabric through the AI for Security and Security for AI framework.
Within AI for Security, FortiAI-Assist uses generative and agentic AI to support NOC and SOC teams in monitoring, analysis and response activities across enterprise environments.
Security for AI comprises of FortiAI-Protect and FortiAI-SecureAI.
FortiAI-Protect utilizes AI/ML to address AI-driven threats and zero-day attacks, and support governance over GenAI applications, FortiAI-SecureAI focus on protecting an organization’s AI infrastructure, including LLMs and APIs, and preventing data leakage into and out of LLMs.
FortiAI protects the AI ecosystem, infrastructure, models, workloads, data and supply chains, while leveraging unified AI intelligence across the Fortinet Security Fabric to defend against threats.
Our OT Security Platform is purpose-built to protect the engineered systems that underpin critical infrastructure and supply chains around the world.
This includes securing energy and utilities systems, manufacturing environments, and transportation, utilizing FortiGuard OT Security Services.
These offerings include security capabilities for CPS assets and tools that support centralized NOC and SOC functions.
We also allow our customers to deploy our FortiSASE as Sovereign SASE, which provides control over the technology elements needed for a SASE solution.
FortiSASE Sovereign delivers full SASE capabilities within infrastructure environments that organizations control, including on-premises, in private data centers or trusted colocation environments.
protection and code security.
We continue to develop all the core SASE capabilities in a single operating system, FortiOS, including Next-Gen Firewall, SD-WAN, ZTNA, secure web gateway, cloud access security broker and DLP.
This native integration of our Next-Gen Firewall, SD-WAN and SASE has become the New-Generation SASE Firewall.
- Total gross margin was 80.5% in 2025, remaining comparatively flat compared to 80.6% in 2024.
Product revenue grew 16% in 2025 compared to 2024.
We experienced product revenue growth across our hardware products and software licensing, which mainly benefited from growth in secure networking hardware products and term licenses.
We expect our product revenue to continue to grow in 2026.
We expect our service revenue to continue to grow in 2026.
Total gross margin remained comparatively flat in 2025 compared to 2024.
While we are implementing price increases to mitigate higher hardware component costs, the impact on our margins will depend on the timing and market acceptance of these adjustments.
Our product gross margin may decline if these pricing actions do not fully offset rising input costs.
We currently do not expect the U.S. tariffs to have a meaningful impact on our gross margin.
However, changes in trade policy, including increases in tariff rates, changes in customs or tariffs classifications, or modifications to tariff exemptions, could adversely affect our gross margin in the future, and we expect any resulting impact would primarily relate to our hardware sales to the U.S. customers.
Operating margin increased 0.4 percentage points in 2025, driven by revenue growth exceeding expense growth, resulting in improved operating leverage.
For the full year 2026, we expect our operating margin to decrease compared to 2025 as we continue to make strategic investments.
Total revenue is expected to increase in 2026 compared to the prior year; however, our expenses are expected to outpace revenue growth, primarily reflecting investments in sales and marketing headcount, product development and the continued capital expenditures in data centers and real estate.
While these strategic investments are intended to drive long-term revenue growth and market expansion, we anticipate they may result in near-term compression of our operating margins.
In addition, we may experience higher operating expenses driven in part by the weakening of the U.S. dollar relative to foreign currencies, as a portion of our expenses are incurred and paid in currencies other than the U.S. dollar.
Tariffs imposed by the United States, as well as any new or additional retaliatory tariffs that could be imposed by other countries in response, could have a material adverse impact on global trade, supply chains and other worldwide economic and geopolitical conditions, which could increase our product costs and also affect customer sentiment in deciding whether to purchase our products.
We continue to monitor the impact of tariffs on our business.
In addition, as a result of the rapid global build-out of AI infrastructure, there is currently a global shortage of memory chips, which are a component in certain of our products.
As a result, we are currently experiencing, and may continue to experience, constraints on the availability of memory chips, which may lead to delays in the production and delivery of our products and increased costs to source available memory chips, any of which could harm our business, financial condition and results of operations.
To mitigate increased hardware costs resulting from these shortages, we are implementing price increases, which may negatively impact demand for our products and may not be sufficient or timely to offset rising input costs, potentially resulting in margin compression and adversely affecting our business, financial condition and results of operations.
Depending on the solution, these may be sold in a bundle or standalone as part of a solution sale.
| Revenue | | | $ | 6,799.6 | | | | | $ | 5,955.8 | | | | | $ | 5,304.8 | |
performance, all of which could reduce the usefulness of free cash flow as a comparative measure.
*•expectations that our operating expense will increase year over year in absolute dollars during 2025;*
As of December 31, 2024, our customers included approximately 80% of the Fortune 100 companies and approximately 72% of the Global 2000 companies.
We were also ranked #7 in the Forbes Most Trusted Companies list in 2024.
To further validate our strategy,
FortiOS has been recognized across five Gartner Magic Quadrants, including Firewall, SD-WAN, SSE, SASE Platforms and Wired and Wireless LAN.
- FortiAI—Our AI innovations encompass generative AI, big data AI for threat intelligence to process and analyze trillions of events using AI/ML, network operations AI for self-healing networks and automated network orchestration, automation and response, and AI for LLM leakage to protection against data leakage into LLMs.
Our GenAI assists security teams to make better decisions, rapidly respond to threats and save time on even the most complex tasks.
FortiAI is seamlessly integrated into the user experience of several of our products, including FortiAnalyzer, FortiSIEM and FortiSOAR, to help optimize threat investigation and response, SIEM queries, SOAR playbook creation, among other functions.
It also provides an OT Security Platform with features and products to extend Security Fabric capabilities to OT networks in factories, plants, remote locations and ships.
To help alleviate security risks across the organization, we have continued to enhance our OT Security Platform offerings.
These innovations range from edge products to NOC and SOC tools and services to provide effective and efficient networking and cybersecurity performance and operation.
Our wireless LAN solution leverages secure networking to provide secure wireless access for the enterprise LAN edge.
with visibility and context across hybrid and multi-cloud.
- Total gross margin was 80.6% in 2024, an increase of 3.9 percentage points compared to 76.7% in 2023.
- On August 1, 2024, we closed our acquisition of Lacework, a privately held data-driven cloud security company.
On August 5, 2024, we completed the acquisition of Next DLP, a privately held insider risk and DLP company.
From August 2024 to December 2024, revenue from these two acquired companies was $33.5 million, or 0.6% of total revenue in 2024.
Product revenue remained comparatively flat in 2024 compared to 2023.
We expect product revenue growth rates to be higher in 2025 compared to 2024 which had a challenging comparison to a 2023 year benefiting from the greater backlog contribution to billings.
We expect our service revenue to continue to grow in 2025, with growth opportunities that include unified SASE and SecOps offerings as well as the year over year increase in current deferred revenue.
While service revenue is expected to grow in 2025, we anticipate that the growth rates will continue to slow down in 2025 due to slowing short term deferred revenue growth over the past several quarters.
Total gross margin increased 3.9 percentage points in 2024 compared to 2023, primarily driven by increased product and service gross margin and a shift in the revenue mix to higher margin service revenue.
We expect our operating expenses as a percentage of revenue to increase for full year 2025 compared to full year 2024 as we expand our workforce organically and through acquisitions.
Operating margin increased 6.9 percentage points in 2024 as a result of improvement in gross margin and decrease in operating expenses as a percentage of revenue.
We expect our operating margin to decrease for full year 2025 compared to full year 2024 as we grow our sales and marketing, and research and development workforce organically and through acquisitions, increase our product development investments, and expand our data center footprint and our colocation and cloud hosting capacity to support business growth.
growth and adversely affect our results of operations and financial performance.
Our backlog may fluctuate over quarters.
A reduction to backlog increases our aggregate billings and revenue during the quarter when delivered.
If we experience supply chain shortages and cannot fulfill orders or if customers cancel or delay delivery of orders, our backlog may be affected, which will negatively impact our aggregate backlog to billings conversion and revenue in such quarter, and as the supply chain challenges normalized, our product revenue growth rate may be lower versus prior quarters where delivery from backlog contributed more to billings.
expenses.
We often continue to gather additional information throughout the measurement period, and if we make changes to the amounts recorded, such changes are recorded in the period in which they are identified.
In general, deferred tax assets
| Gain on bargain purchase | | | 106.3 | | | | | | — | | | | | | — | | |
| Less: net loss attributable to non-controlling interests, net of tax | | | — | | | | | | — | | | | | | (0.7) | | |
| Net income attributable to Fortinet, Inc. | | | $ | 1,745.2 | | | | | $ | 1,147.8 | | | | | $ | 857.3 | |
| Gain on bargain purchase | | | 2 | | | | | | — | | | | | | — | | |
| Net income including non-controlling interests | | | 29 | | | | | | 22 | | | | | | 19 | | |
| Less: net loss attributable to non-controlling interests, net of tax | | | — | | | | | | — | | | | | | — | | |
| Product | | | $ | 1,908.7 | | | | | 32 | | % | | | | $ | 1,927.3 | | | | | 36 | | % | | | | $ | (18.6) | | | | | (1) | | % |
| Service | | | 4,047.1 | | | | | | 68 | | | | | | 3,377.5 | | | | | | 64 | | | | | | 669.6 | | | | | | 20 | | |
An excerpt. Shown here: 40 of 227 rewritten, 40 of 95 added and 40 of 77 removed. The counts are complete. For every sentence, read Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations in the FY2025 filing and the FY2024 filing.
Item 7A. Quantitative and Qualitative Disclosures about Market Risk
6 rewritten, 0 added, 0 removed, 20 unchanged
We are exposed to interest rate risks [added: primarily] related to our investment portfolio and [added: the] outstanding [removed: debt.][added: debt, as changes in prevailing interest rates may affect the fair value of investments and the cost of future financing activities.]
To minimize this risk, we maintain our portfolio of cash, cash equivalents, investments and marketable equity securities in a variety of securities, including commercial paper, corporate debt securities, U.S. government and agency securities, certificates of deposit and term deposits, money market [removed: funds, municipal bonds] [added: funds] and marketable equity securities.
A 10% decrease in interest rates would have resulted in a decrease of [added: $16.2 million,] $15.5 million [removed: in our interest income in 2024,] and [removed: would have resulted in an insignificant decrease] [added: $12.0 million] in our interest income [removed: in 2023] [added: for 2025, 2024,] and [removed: 2022.][added: 2023, respectively.]
We recognized an expense of [removed: $16.9] [added: $4.9] million in [removed: 2024] [added: 2025] due to foreign currency transaction losses.
Long-term material changes in the value of the U.S. dollar against other foreign currencies, such as the EUR, GBP and [removed: JPY] [added: JPY,] could adversely impact our operating expenses in the future.
For foreign currency exchange rate risk, a 10% increase or decrease of foreign currency exchange rates against the U.S. dollar with all other variables held constant would have resulted in a [removed: $14.2] [added: $17.2] million change in the value of our foreign currency cash balances as of December 31, [removed: 2024.][added: 2025.]
Item 1. Business
56 rewritten, 24 added, 14 removed, 164 unchanged
As of December 31, [removed: 2024,] [added: 2025,] our end-customers were located in over 100 countries and included enterprises across a wide variety of market verticals, including financial services, retail, healthcare and operational technology (“OT”) market verticals, communication and security service providers, and government organizations.
[removed: As of December 31, 2024, we held 1,034 U.S. patents and 1,378 global patents and we] [added: We] have been recognized in over 140 enterprise analyst reports demonstrating both our vision and execution across security and networking products.
- [removed: FortiOS—FortiOS] [added: FortiOS—Our unified operating system] enables the convergence of [removed: security and] networking [added: and AI-powered security] to enforce consistent [removed: security] policies across [added: all] form factors and edges.
As the [removed: foundation] [added: foundational engine] of the Fortinet Security Fabric, FortiOS empowers organizations to unify management and [removed: analytics for comprehensive] [added: analytics, providing] network visibility and control at scale.
- FortiASIC—Our Application-Specific Integrated Circuit (“ASIC”)-based security processing units (“SPUs”) increase the speed, scale, efficiency and value of our solutions while [removed: improving user experience,] reducing footprint and power requirements.
[removed: - FortiCloud—Our organically built global cloud infrastructure, powered by FortiStack which] [added: FortiCloud] is our [removed: secure] [added: private cloud] software as a service (“SaaS”) [added: platform, powered by FortiStack, which is our secure SaaS] platform operating as a private cloud service provider and leveraging software and hardware to optimize and secure all [removed: layers, provides customers with global reach, flexible connectivity, and cost savings.][added: layers.]
- FortiEndpoint—FortiEndpoint converges secure connectivity, endpoint protection and advanced capabilities like endpoint detection and response and [removed: extended detection and response (“XDR”),] [added: Universal Zero Trust Network Access (“ZTNA”),] into a single agent.
This minimizes the need for manual intervention and provides faster remediation of threats across [removed: all] environments.
- OT Security—The Fortinet Security Fabric enables security for [added: OT systems and Cyber-Physical Systems (“CPS”), including] converged IT/OT [removed: ecosystems.][added: architectures.]
These competitive differentiators [removed: allow us to] provide [removed: Chief Information Officer (“CIO”)s, Chief Information Security Officer (“CISO”)s, Chief Technology Officer (“CTO”)s,] [added: networking] and [removed: their organizations] [added: security professionals] with [removed: an integrated AI-driven cybersecurity] [added: a cyber security] platform [removed: with] [added: comprised of] over 50 products across three solution [removed: pillars.][added: pillars:]
- Secure Networking—Our Secure Networking solutions focus on the convergence of networking and security via FortiOS, our networking and security operating system that is the foundation of our Fortinet Security Fabric platform and supports [removed: over 30] [added: a broad range of] functions that can be delivered via a physical, virtual, cloud or [removed: software as a] SaaS [removed: solution.][added: solutions.]
Our network firewall offerings consist of a [removed: FortiGate] [added: FortiGate, which can be deployed at branch, campus,] data center, [removed: hyperscale] [added: internal segmentation, private] and [removed: distributed firewalls,] [added: public cloud to enable hybrid mesh firewall solutions,] as well as encrypted applications (secure sockets layer (“SSL”) inspection, virtual private network and Internet Protocol Security [removed: (“IPsec”)] connectivity).
Our Secure Connectivity solution includes FortiSwitch secure ethernet switches, FortiAP wireless local area network access points and FortiExtender 5G connectivity [removed: gateways.][added: gateways and Network Access Control (“NAC”) for securing Internet of Things (“IoT”) devices.]
The Fortinet Unified SASE solution includes a single-vendor SASE solution that includes firewall, SD-WAN, secure web gateway, cloud access services broker, Data Loss Prevention [removed: (“DLP”)] [added: (“DLP”), Digital Experience Monitoring (“DEM”), Remote Browser Isolation (“RBI”)] and [removed: zero trust network access] [added: ZTNA] to deliver flexible secure access for all users.
Our global and scalable cloud network includes [removed: 150+ points of presence] [added: over 190 PoPs] to deliver [removed: the] [added: a] seamless secure access experience.
[removed: Given this,] [added: Leveraging this global infrastructure,] we [added: believe we] are well positioned to support customers expanding from SD-WAN to a single-vendor SASE platform.
Additionally, we offer a full suite of [removed: comprehensive,] integrated cloud security solutions that enable customers to secure their applications from code to cloud.
Our solutions include application security that includes [removed: our] web application firewalls, cloud network security with virtualized firewalls and cloud-native firewalls, cloud-native application protection and code security.
We deliver a holistic approach to cloud security, offering a single unified [removed: platform for cloud security and secure Continuous Integration/Continuous Delivery (“CI/CD”) application development needs,] [added: platform,] consolidating protection across multiple disparate tools, including coding, deploying, and running applications across hybrid and [removed: multi-clouds, and delivering AI-driven security across integrated solutions with visibility and context across hybrid and multi-cloud.][added: multi-clouds.]
- AI-Driven Security Operations (SecOps)—Our AI-Driven SecOps portfolio provides a [removed: comprehensive] suite of cybersecurity solutions that identify, protect, detect, respond and recover from threats, all integrated within the Fortinet Security Fabric.
At the core is FortiAnalyzer, which serves as the central SOC platform with its unified data lake that [removed: provides] [added: provides:] built-in [removed: SIEM, SOAR,] [added: security information and event management (“SIEM”); security, orchestration, automation, and response (“SOAR”);] XDR and threat intelligence, enabling centralized visibility, analytics and automation with complete control.
FortiSIEM delivers [removed: robust] security information and event management for more advanced SOC requirements, while FortiSOAR enables automated orchestration and playbook-driven response.
This solution set also includes [removed: FortiEDR, FortiXDR,] [added: FortiEndpoint,] FortiNDR, FortiSandbox, FortiDeceptor, FortiDLP and FortiRecon, helping organizations achieve defense in depth, ensuring attackers face multiple layers of detection and mitigation across endpoints, networks, and applications.
FortiGuard Labs is our cybersecurity threat intelligence and research organization comprised of experienced threat hunters, researchers, analysts, engineers and data scientists who develop and utilize [removed: machine learning] [added: ML] and AI technologies to provide timely protection updates and actionable threat intelligence for the benefit of our customers.
[removed: The] portfolio consists of FortiGuard application security services, content security services, device security services, NOC/SOC security services and web security services.
FortiCare Technical Support Service is a [removed: per-device] technical support service, which provides customers access to experts to ensure efficient and effective operations and maintenance of their Fortinet [removed: capabilities.][added: solution.]
Organizations have the flexibility to procure different levels of service for different [removed: devices] [added: solutions] based on their availability needs.
We offer three [removed: per-device] support options tailored to the needs of our enterprise customers: FortiCare Elite, FortiCare Premium and FortiCare Essential.
In addition to FortiCare [removed: device level] [added: solution based] services, Advanced Support service options are available per account.
These services are available for regional account support in three options: Core, Pro and Pro Plus, and can be [removed: globalized] [added: available or provided on a global basis] at the Pro and Pro Plus levels.
The Fortinet Training Institute has issued [removed: over one] [added: approximately two] million certifications to date.
During the year ended December 31, [removed: 2024,] [added: 2025,] we generated total revenue of [removed: $5.96] [added: $6.80] billion and net income of [removed: $1.75] [added: $1.85] billion.
See Part II, Item 8 of this Annual Report on Form 10-K for more information on our consolidated balance sheets as of December 31, [removed: 2024] [added: 2025] and [removed: 2023] [added: 2024] and our consolidated statements of income, comprehensive income, [added: stockholders’] equity (deficit), and cash flows for each of the three years ended December 31, [removed: 2024, 2023] [added: 2025, 2024] and [removed: 2022.][added: 2023.]
Our principal executive office is located at 909 Kifer Road, Sunnyvale, California [removed: 94086] [added: 94086,] and our telephone number at that location is (408) 235-7700.
Depending on the solution or form factor purchased, customers may also access our products via the cloud through our data centers and PoPs, third-party colocations and cloud providers such as Amazon Web Services, [removed: Microsoft Azure and Google Cloud.]
[removed: Refer to Note 16] Segment Information in Part II, Item 8 of this Annual Report on Form 10-K for distributor customers accounted for 10% or more of our revenue or net accounts receivable.
Approximately [removed: 88%] [added: 87%] of our hardware is manufactured in Taiwan.
Once our products are manufactured, they are sent to either our warehouse in [removed: California] [added: California, our warehouse in the Netherlands] or to our logistics partner in Taoyuan City, Taiwan, where accessory packaging and quality-control testing are performed.
Supply chain security management begins with [removed: the] establishing control of a qualified supplier base, which provides qualified and trusted components for use in design, development, manufacturing and post-sale product support.
Our Trusted Supplier Program (“TSP”) was developed in accordance with the requirements defined in National Institute of Standards and Technology Special Publications (“NIST SP”) 800-161 Supply Chain Risk Management Practices for Federal Information Systems and Organizations and other directives as periodically established by the U.S. government for [added: securing the Information and Communication Technology Services supply chain, in response to increasing customer demand for transparency in the security of the hardware, firmware and software that is included in our products and to comply with U.S. government directives.]
As of December 31, 2025, we held 1,064 U.S. patents and a total of 1,405 global patents, including 321 AI-related patents.
FortiOS includes advanced encryption and other security technologies designed to address evolving cybersecurity threats, including emerging quantum-resistant cryptographic capabilities.
- FortiCloud—Our organically built global cloud infrastructure provides customers with global reach, flexible connectivity and cost savings.
- FortiAI—FortiAI provides a dual-layered defense across the Fortinet Security Fabric through the AI for Security and Security for AI framework.
Within AI for Security, FortiAI-Assist uses generative and agentic AI to support Network Operations Center (“NOC”) and Security Operations Center (“SOC”) teams in monitoring, analysis and response activities across enterprise environments.
Security for AI comprises of FortiAI-Protect and FortiAI-SecureAI.
FortiAI-Protect utilizes AI/Machine Learnings (“ML”) to address AI-driven threats and zero-day attacks, and support governance over generative AI (“GenAI”) applications, FortiAI-SecureAI focus on protecting an organization’s AI infrastructure, including large language models (“LLMs”) and Application Programming Interface (“APIs”), and preventing data leakage into and out of LLMs.
FortiAI protects the AI ecosystem, infrastructure, models, workloads, data and supply chains, while leveraging unified AI intelligence across the Fortinet Security Fabric to defend against threats.
Our OT Security Platform is purpose-built to protect the engineered systems that underpin critical infrastructure and supply chains around the world.
This includes securing energy and utilities systems, manufacturing environments, and transportation, utilizing FortiGuard OT Security Services.
These offerings include security capabilities for CPS assets and tools that support centralized NOC and SOC functions.
We also allow our customers to deploy our FortiSASE as Sovereign SASE, which provides control over the technology elements needed for a SASE solution.
FortiSASE Sovereign delivers full SASE capabilities within infrastructure environments that organizations control, including on-premises, in private data centers or trusted colocation environments.
We continue to develop all the core SASE capabilities in a single operating system, FortiOS, including Next-Gen Firewall, SD-WAN, ZTNA, secure web gateway, cloud access security broker and DLP.
This native integration of our Next-Gen Firewall, SD-WAN and SASE has become the New-Generation SASE Firewall.
The
Microsoft Azure and Google Cloud.
Refer to Note 15.
Additionally, we manage global memory component supply through diversified sourcing arrangements, strategic inventory planning and coordination with key supply chain partners.
Memory components are obtained from multiple suppliers, and we continuously monitor availability, lead times and logistics conditions to support manufacturing continuity and delivery schedules.
These actions are intended to mitigate supply volatility and maintain operational flexibility.
We have been certified to Environmental Product Declarations for our FortiGate 50G family.
We continue to focus on skilling, upskilling and reskilling individuals.
material with, or furnish it to, the Securities and Exchange Commission (the “SEC”).
As of December 31, 2024, our customers included approximately 80% of the Fortune 100 companies and approximately 72% of the Global 2000 companies.
We were also ranked #7 in the Forbes Most Trusted Companies list in 2024.
To further validate our strategy, FortiOS has been recognized across five Gartner Magic Quadrants, including Firewall, Software-Defined Wide-Area Network (“SD-WAN”), Security Service Edge (“SSE”), SASE Platforms and Wired and Wireless Local Area Network (“LAN”).
- FortiAI—Our AI innovations encompass generative AI (“GenAI”), big data AI for threat intelligence to process and analyze trillions of events using AI/Machine Learning (“ML”), network operations AI for self-healing networks and automated network orchestration, automation and response, and AI for Large Language Model (“LLM”) leakage to protection against data leakage into LLMs.
Our GenAI assists security teams to make better decisions, rapidly respond to threats and save time on even the most complex tasks.
FortiAI is seamlessly integrated into the user experience of several of our products, including FortiAnalyzer, FortiSIEM and FortiSOAR, to help optimize threat investigation and response, Security information and event management (“SIEM”) queries, Security, orchestration, automation, and response (“SOAR”) playbook creation, among other functions.
It also provides an OT Security Platform with features and products to extend Security Fabric capabilities to OT networks in factories, plants, remote locations and ships.
To help alleviate security risks across the organization, we have continued to enhance our OT Security Platform offerings.
These innovations range from edge products to Network Operations Center (“NOC”) and Security Operations Center (“SOC”) tools and services to provide effective and efficient networking and cybersecurity performance and operation.
Our wireless LAN solution leverages secure networking to provide secure wireless access for the enterprise LAN edge.
securing the Information and Communication Technology Services supply chain, in response to increasing customer demand for transparency in the security of the hardware, firmware and software that is included in our products and to comply with U.S. government directives.
We generally enter into confidentiality
We submitted our survey on environment to CDP, which is a not-for-profit charity organization that runs the global disclosure system for companies to manage their environmental impacts.
We continue to focus on skilling, upskilling and reskilling individuals and are on track to reach our goal of training one million people in cybersecurity by 2026 with over 630,000 individuals trained as of the end of 2024.
An excerpt. Shown here: 40 of 56 rewritten, all 24 added and all 14 removed. The counts are complete. For every sentence, read Item 1. Business in the FY2025 filing and the FY2024 filing.
Item 3. Legal Proceedings
1 rewritten, 0 added, 0 removed, 4 unchanged
Refer to Note [removed: 12.][added: 11.]
Cover and table of contents
42 rewritten, 5 added, 6 removed, 101 unchanged
For the year ended December 31, [removed: 2024][added: 2025]
The aggregate market value of voting stock held by non-affiliates of the registrant, as of June 30, [removed: 2024,] [added: 2025,] the last business day of the registrant’s most recently completed second quarter, was [removed: $31,496,083,015] [added: $56,846,175,983] (based on the closing price for shares of the registrant’s common stock as reported by The Nasdaq Global Select Market on that date).
As of February [removed: 18, 2025,] [added: 20, 2026,] there were [removed: 768,974,062] [added: 739,923,583] shares of the registrant’s common stock outstanding.
Portions of the registrant’s definitive Proxy Statement relating to its [removed: 2025] [added: 2026] Annual Meeting of Stockholders (“Proxy Statement”) are incorporated by reference into Part III of this Annual Report on Form 10-K where indicated.
| | | | [Risk Factor [removed: Summary](#i534f17d0e8de499a94e79a163c06da17_10)] [added: Summary](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_10)] | | | [removed: [1](#i534f17d0e8de499a94e79a163c06da17_10)] [added: [1](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_10)] | | |
| Item 1. | | | [removed: [Business](#i534f17d0e8de499a94e79a163c06da17_16)] [added: [Business](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_16)] | | | [removed: [3](#i534f17d0e8de499a94e79a163c06da17_16)] [added: [3](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_16)] | | |
| Item 1A. | | | [Risk [removed: Factors](#i534f17d0e8de499a94e79a163c06da17_19)] [added: Factors](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_19)] | | | [removed: [11](#i534f17d0e8de499a94e79a163c06da17_19)] [added: [12](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_19)] | | |
| Item 1B. | | | [Unresolved Staff [removed: Comments](#i534f17d0e8de499a94e79a163c06da17_22)] [added: Comments](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_22)] | | | [removed: [46](#i534f17d0e8de499a94e79a163c06da17_22)] [added: [48](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_22)] | | |
| Item 1C. | | | [removed: [Cybersecurity](#i534f17d0e8de499a94e79a163c06da17_25)] [added: [Cybersecurity](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_25)] | | | [removed: [46](#i534f17d0e8de499a94e79a163c06da17_25)] [added: [49](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_25)] | | |
| Item 2. | | | [removed: [Properties](#i534f17d0e8de499a94e79a163c06da17_28)] [added: [Properties](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_28)] | | | [removed: [49](#i534f17d0e8de499a94e79a163c06da17_28)] [added: [51](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_28)] | | |
| Item 3. | | | [Legal [removed: Proceedings](#i534f17d0e8de499a94e79a163c06da17_31)] [added: Proceedings](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_31)] | | | [removed: [49](#i534f17d0e8de499a94e79a163c06da17_31)] [added: [51](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_31)] | | |
| Item 4. | | | [Mine Safety [removed: Disclosures](#i534f17d0e8de499a94e79a163c06da17_34)] [added: Disclosures](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_34)] | | | [removed: [49](#i534f17d0e8de499a94e79a163c06da17_34)] [added: [51](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_34)] | | |
| Item 5. | | | [Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity [removed: Securities](#i534f17d0e8de499a94e79a163c06da17_40)] [added: Securities](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_40)] | | | [removed: [50](#i534f17d0e8de499a94e79a163c06da17_40)] [added: [52](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_40)] | | |
| Item 6. | | | [removed: [\[Reserved\]](#i534f17d0e8de499a94e79a163c06da17_46)] [added: [\[Reserved\]](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_46)] | | | [removed: [52](#i534f17d0e8de499a94e79a163c06da17_46)] [added: [54](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_46)] | | |
| Item 7. | | | [Management’s Discussion and Analysis of Financial Condition and Results of [removed: Operations](#i534f17d0e8de499a94e79a163c06da17_49)] [added: Operations](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_49)] | | | [removed: [53](#i534f17d0e8de499a94e79a163c06da17_49)] [added: [55](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_49)] | | |
| Item 7A. | | | [Quantitative and Qualitative Disclosures about Market [removed: Risk](#i534f17d0e8de499a94e79a163c06da17_61)] [added: Risk](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_58)] | | | [removed: [72](#i534f17d0e8de499a94e79a163c06da17_61)] [added: [74](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_58)] | | |
| Item 8. | | | [Financial Statements and Supplementary [removed: Data](#i534f17d0e8de499a94e79a163c06da17_64)] [added: Data](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_61)] | | | [removed: [73](#i534f17d0e8de499a94e79a163c06da17_64)] [added: [75](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_61)] | | |
| Item 9. | | | [Changes in and Disagreements with Accountants on Accounting and Financial [removed: Disclosure](#i534f17d0e8de499a94e79a163c06da17_163)] [added: Disclosure](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_172)] | | | [removed: [113](#i534f17d0e8de499a94e79a163c06da17_163)] [added: [116](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_172)] | | |
| Item 9A. | | | [Controls and [removed: Procedures](#i534f17d0e8de499a94e79a163c06da17_166)] [added: Procedures](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_175)] | | | [removed: [113](#i534f17d0e8de499a94e79a163c06da17_166)] [added: [116](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_175)] | | |
| Item 9B. | | | [Other [removed: Information](#i534f17d0e8de499a94e79a163c06da17_169)] [added: Information](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_178)] | | | [removed: [115](#i534f17d0e8de499a94e79a163c06da17_169)] [added: [118](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_178)] | | |
| Item 9C. | | | [Disclosure Regarding Foreign Jurisdictions that Prevents [removed: Inspections](#i534f17d0e8de499a94e79a163c06da17_175)] [added: Inspections](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_184)] | | | [removed: [115](#i534f17d0e8de499a94e79a163c06da17_175)] [added: [118](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_184)] | | |
| Item 10. | | | [Directors, Executive Officers and Corporate [removed: Governance](#i534f17d0e8de499a94e79a163c06da17_181)] [added: Governance](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_190)] | | | [removed: [116](#i534f17d0e8de499a94e79a163c06da17_181)] [added: [119](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_190)] | | |
| Item 11. | | | [Executive [removed: Compensation](#i534f17d0e8de499a94e79a163c06da17_184)] [added: Compensation](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_193)] | | | [removed: [116](#i534f17d0e8de499a94e79a163c06da17_184)] [added: [119](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_193)] | | |
| Item 12. | | | [Security Ownership of Certain Beneficial Owners and Management and Related Stockholder [removed: Matters](#i534f17d0e8de499a94e79a163c06da17_187)] [added: Matters](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_196)] | | | [removed: [116](#i534f17d0e8de499a94e79a163c06da17_187)] [added: [119](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_196)] | | |
| Item 13. | | | [Certain Relationships and Related Transactions, and Director [removed: Independence](#i534f17d0e8de499a94e79a163c06da17_190)] [added: Independence](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_199)] | | | [removed: [116](#i534f17d0e8de499a94e79a163c06da17_190)] [added: [119](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_199)] | | |
| Item 14. | | | [Principal Accounting Fees and [removed: Services](#i534f17d0e8de499a94e79a163c06da17_193)] [added: Services](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_202)] | | | [removed: [116](#i534f17d0e8de499a94e79a163c06da17_193)] [added: [119](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_202)] | | |
| Item 15. | | | [Exhibits and Financial Statement [removed: Schedules](#i534f17d0e8de499a94e79a163c06da17_199)] [added: Schedules](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_208)] | | | [removed: [117](#i534f17d0e8de499a94e79a163c06da17_199)] [added: [120](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_208)] | | |
| Item 16. | | | [Form 10-K [removed: Summary](#i534f17d0e8de499a94e79a163c06da17_214)] [added: Summary](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_223)] | | | [removed: [120](#i534f17d0e8de499a94e79a163c06da17_214)] [added: [123](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_223)] | | |
- Adverse economic conditions, such as a possible economic downturn or recession, and possible impacts of inflation or stagflation, [removed: tariffs] [added: tariffs, trade policies] or other trade disruptions, changing interest rates, changes in government spending or regulation or reduced information technology (“IT”) spending, including firewall spending, may adversely impact our business.
- We have been, [added: are currently] and may in the future [removed: be,] [added: be] susceptible to supply chain constraints, supply shortages and disruptions, long or less predictable lead times for components and finished goods and supply changes because some of the key components in our products come from limited sources of supply.
[removed: - As a result of supply chain disruptions in previous periods, we increased our purchase order commitments in previous periods and, were in some instances required to and may] [added: Similar conditions could arise] in the [removed: future be required] [added: future, which may require us] to accept or pay for components and finished goods regardless of our level of sales in a particular period, which may negatively or unpredictably impact our operating results and financial condition.
- Our real estate assets, including construction, acquisitions, [added: improvements,] leasing activity, and ongoing maintenance and management of office buildings, warehouses, data centers and points of presence (“PoPs”), as well as data center [added: operations,] expansions or enhancements, could involve significant risks to our business.
[removed: A] [added: Generally, a] reduction to backlog increases our aggregate billings and revenue during the quarter when delivered.
- Any weakness in sales strategy, productivity, [removed: personnel] [added: personnel, hiring] and [added: retention, and] execution could negatively impact our results of operations.
- We rely significantly on revenue from FortiGuard and other security subscriptions and FortiCare technical support services, and revenue from these services may decline or [removed: fluctuate.][added: fluctuate in manners that could adversely impact our results of operations.]
[added: Our Product Security Incident Response] Team publicly posts on our FortiGuard Labs website known product vulnerabilities, including critical vulnerabilities, and methods for customers to mitigate the risk of vulnerabilities.
- If our internal enterprise IT networks, our operational networks, our research and development [removed: (“R&D”)] networks, our back-end labs and cloud stacks hosted in our data centers or PoPs, colocation vendors or public cloud providers are compromised, public perception of our products and services may be harmed, our customers may be breached and harmed, we may become subject to liability, and our business, operating results and stock price may be adversely impacted.
- We generate a majority of billings, revenue and cash flow from sales outside of the United [removed: States.][added: States, which may expose us to risks associated with international operations and may adversely affect our business, financial condition and results of operations.]
- A portion of our revenue is generated by sales to government organizations and other [added: adjacent] customers, which are subject to a number of regulatory requirements, their own supply chain constraints and contractual requirements, challenges and [removed: risks.][added: risks, including impacts from geopolitical dynamics.]
- We order components [added: and finished goods] from third-party manufacturers based on our forecasts of future demand and targeted inventory levels, which exposes us to the risk of product shortages, [added: tariffs,] may result in lost sales, higher expenses and inventory excesses which may lead to inventory charges and costs related to future purchase commitments, possibly requiring us to sell our products at discounts or offer various other incentives.
For the Year Ended December 31, 2025
| | | | [Exhibit Index](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_220) | | | [121](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_220) | | |
| | | | [Signatures](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_226) | | | [124](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_226) | | |
- During prior periods of supply chain disruption, including during the COVID-19 pandemic, we increased our purchase order commitments.
- Our billings, revenue and free cash flow growth, including our product and service billings and revenue, may slow, and our operating margins may decline, particularly if our billings and revenue do not improve or grow as anticipated, or if customer demand, renewal rates, pricing, competitive dynamics, implementation timing, cost structure, or macroeconomic conditions adversely affect our business, which could negatively impact our financial condition and results of operations.
| | | | [Exhibit Index](#i534f17d0e8de499a94e79a163c06da17_211) | | | [118](#i534f17d0e8de499a94e79a163c06da17_211) | | |
| | | | [Signatures](#i534f17d0e8de499a94e79a163c06da17_217) | | | [121](#i534f17d0e8de499a94e79a163c06da17_217) | | |
- Our billings, revenue, and free cash flow growth may slow or may not continue to grow, and our operating margins may decline.
- As the supply chain challenges normalize, our product revenue growth rate may be lower versus prior quarters where delivery from backlog contributed more to billings.
For the fiscal year 2024, the comparably lower backlog contribution to billings resulted in decreased year-over-year quarterly growth rates.
Our Product Security Incident Response
An excerpt. Shown here: 40 of 42 rewritten, all 5 added and all 6 removed. The counts are complete. For every sentence, read Cover and table of contents in the FY2025 filing and the FY2024 filing.
Item 1C. Cybersecurity
3 rewritten, 1 added, 1 removed, 42 unchanged
However, due to the importance of cybersecurity to our company, in July 2024, our board of directors formed Cybersecurity Committee of our board of directors (the “Cybersecurity [added: Committee”), which is solely dedicated to cybersecurity risk management.]
Our CISO, Dr. Carl Windsor, has over [removed: 25] [added: 26] years of experience in various technology and cybersecurity leadership positions, including over [removed: 18] [added: 19] years at our company driving product security and strategy and reports to the board Cybersecurity Committee.
[removed: Our CISO] monitors, and participates in, our various cybersecurity policies and procedures, and our cybersecurity team regularly updates our CISO on the current status.
Our CISO
Committee”), which is solely dedicated to cybersecurity risk management.
Item 2. Properties
5 rewritten, 6 added, 14 removed, 5 unchanged
Our corporate headquarters is located in Sunnyvale, California, and comprises approximately 395,000 square feet of building space on 21 acres of [removed: land and includes space for future development of PoPs.][added: land.]
| Location | | | | | | [removed: Owned] [added: Approximate Owned] Square Footage | | | | | | Description of Use | | |
| [removed: Burnaby, Calgary and Ottawa,] Canada | | | | | | [removed: 680,000] [added: 1,000] | | | | | | Data [removed: center, PoP, support functions] [added: center] and [added: office space, sales and support,] research and development [added: functions, and PoP] | | |
We maintain additional leased offices throughout the world, predominantly used as sales and support offices and [removed: PoPs,] [added: PoP,] and leased data center spaces throughout the world operated under colocation arrangements.
For information regarding the geographical location of our property and equipment, refer to Note [removed: 16 of our consolidated financial statements in Part II, Item 8 of this Annual Report on Form 10-K.][added: 15.]
As of December 31, 2025, we operated the facilities in the following geographies (square feet in thousands):
| United States | | | | | | 2,400 | | | | | | Corporate headquarters, data centers, research and development, warehousing and operations, sales and support functions, and PoP | | |
| EMEA | | | | | | 910 | | | | | | Data center and office space, warehousing and operations, sales and support functions, and PoP | | |
| Asia Pacific (“APAC”) | | | | | | 40 | | | | | | Office space and PoP | | |
| Total | | | | | | 4,350 | | | | | | | | |
of our consolidated financial statements in Part II, Item 8 of this Annual Report on Form 10-K.
In January 2024, we purchased an additional 480,000 square feet of building space in Santa Clara, California, which is located in close proximity to our corporate headquarters and includes space for future development of a data center.
Refer to Note 17.
Subsequent Events, in Part II, Item 8 of this Annual Report on Form-10K for the February 2025 signing of a definitive agreement subject to regulatory approval for an additional 540,000 square feet of building space in Frankfurt, Germany.
Along with our corporate headquarters, as of December 31, 2024, we operated the following facilities:
| Union City, California | | | | | | 770,000 | | | | | | Warehousing, operations, and PoP | | |
| Atlanta, Georgia | | | | | | 226,000 | | | | | | Sales and support functions and PoP | | |
| Plano & Frisco, Texas | | | | | | 130,000 | | | | | | Office space and data center | | |
| Torija, Spain | | | | | | 120,000 | | | | | | Data center | | |
| Chicago, Illinois | | | | | | 114,000 | | | | | | Office space and PoP | | |
| Sunrise, Florida | | | | | | 100,000 | | | | | | Office space | | |
| Sunnyvale, California | | | | | | 97,000 | | | | | | Development | | |
| Valbonne, France | | | | | | 70,000 | | | | | | Sales and support functions and PoP | | |
| McMahons Point, Australia | | | | | | 40,000 | | | | | | Office space and PoP | | |
| New York, New York | | | | | | 40,000 | | | | | | Sales and support functions and PoP | | |
Item 4. Mine Safety Disclosure
0 rewritten, 0 added, 1 removed, 2 unchanged
*All share and per share amounts presented in this Part II have been retroactively adjusted to reflect the five-for-one forward stock split of our common stock effective June 22, 2022.*
Item 5. Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities
12 rewritten, 11 added, 6 removed, 24 unchanged
As of February [removed: 18, 2025,] [added: 20, 2026,] there were [removed: 50] [added: 51] holders of record of our common stock.
Information responsive to this item is incorporated herein by reference to our definitive proxy statement with respect to our [removed: 2024] [added: 2025] Annual Meeting of Stockholders to be filed with the Securities and Exchange Commission (the “SEC”) within 120 days after the end of the fiscal year covered by this Annual Report on Form 10-K.
[removed: ][added: ]
| | | | | | | December [removed: 2019] [added: 2020] * | | | | | | December [removed: 2020] [added: 2021] | | | | | | December [removed: 2021] [added: 2022] | | | | | | December [removed: 2022] [added: 2023] | | | | | | December [removed: 2023] [added: 2024] | | | | | | December [removed: 2024] [added: 2025] | | |
| S&P 500 Index | | | | | | $ | 100 | | | | | $ | [removed: 116] [added: 127] | | | | | $ | [removed: 148] [added: 102] | | | | | $ | [removed: 119] [added: 127] | | | | | $ | [removed: 148] [added: 157] | | | | | $ | 182 | |
| * Assumes that $100 was invested on December 31, [removed: 2019] [added: 2020] in stock or index, including reinvestment of dividends. Stockholder returns over the indicated period should not be considered indicative of future stockholder returns. | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
From 2016 through [removed: 2023,] [added: 2024,] our board of directors approved increases to our Repurchase Program by various amounts and extended the term to February [removed: 29, 2024.][added: 28, 2026.]
In January [removed: 2024,] [added: 2026,] our board of directors approved a [removed: $500.0 million] [added: $1.0 billion] increase in the authorized stock repurchase amount under the Repurchase Program, bringing the aggregate amount authorized to be repurchased to [removed: $7.25] [added: $10.25] billion of our outstanding common [removed: stock.][added: stock through February 28, 2027.]
In [removed: October 2024,] [added: August 2025,] our board of directors approved a $1.0 billion increase in the authorized stock repurchase amount under the Repurchase Program and extended the term of the Repurchase Program to February 28, [removed: 2026,] [added: 2027,] bringing the aggregate amount authorized [removed: to be repurchased] [added: for repurchases] to [removed: $8.25] [added: $9.25] billion of our outstanding common stock through February 28, [removed: 2026.][added: 2027.]
Under the Repurchase Program, [removed: share repurchases] [added: we] may [removed: be made by us] [added: repurchase common stock] from time to time in privately negotiated transactions or in open market transactions.
The Repurchase Program does not require us to purchase a minimum number of shares, and may be [added: suspended, modified or discontinued at any time without prior notice.]
Since its [removed: inception,] [added: inception through December 31, 2025,] we have repurchased [removed: 238.6] [added: 267.3] million shares of our common stock under the Repurchase Program for an aggregate purchase price of [removed: $6.22] [added: $8.51] billion.
| Fortinet, Inc. | | | | | | $ | 100 | | | | | $ | 242 | | | | | $ | 165 | | | | | $ | 197 | | | | | $ | 318 | | | | | $ | 267 | |
| NASDAQ Computer | | | | | | $ | 100 | | | | | $ | 138 | | | | | $ | 89 | | | | | $ | 147 | | | | | $ | 201 | | | | | $ | 258 | |
The following table provides information with respect to the shares of common stock we repurchased under the Repurchase Program during the three months ended December 31, 2025 (in millions, except average price paid per share amounts):
| | | | | | | | | | | | | | | | | | | | | | | | | | | |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| Period | | | | | | Total Number of Shares Purchased | | | | | | Average Price Paid per Share | | | | | | Total Number of Shares Purchased as Part of Publicly Announced Plan or Program | | | | | | Approximate Dollar Value of Shares that May Yet Be Purchased Under the Plans or Programs | | |
| October 1 - October 31, 2025 | | | | | | — | | | | | | $ | — | | | | | — | | | | | | $ | 795.9 | |
| November 1 - November 30, 2025 | | | | | | 0.7 | | | | | | $ | 78.46 | | | | | 0.7 | | | | | | $ | 738.6 | |
| December 1 - December 31, 2025 | | | | | | — | | | | | | $ | — | | | | | — | | | | | | $ | 738.6 | |
| Total | | | | | | 0.7 | | | | | | $ | — | | | | | 0.7 | | | | | | | | |
As of February 24, 2026, approximately $1.27 billion remained available for future share repurchases.
| Fortinet, Inc. | | | | | | $ | 100 | | | | | $ | 139 | | | | | $ | 337 | | | | | $ | 229 | | | | | $ | 274 | | | | | $ | 442 | |
| NASDAQ Computer | | | | | | $ | 100 | | | | | $ | 150 | | | | | $ | 207 | | | | | $ | 133 | | | | | $ | 221 | | | | | $ | 301 | |
In February 2024, our board of directors approved an extension of the Repurchase Program to February 28, 2025.
suspended, modified or discontinued at any time without prior notice.
There were no repurchases of common stock during the three months ended December 31, 2024.
As of December 31, 2024, approximately $2.03 billion remained available for future share repurchases under the Repurchase Program.
Item 8. Financial Statements and Supplementary Data
473 rewritten, 258 added, 173 removed, 705 unchanged
| [Report of Independent Registered Public Accounting [removed: Firm](#i534f17d0e8de499a94e79a163c06da17_67)] [added: Firm](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_64)] (PCAOB ID No.34) | | | [removed: [74](#i534f17d0e8de499a94e79a163c06da17_67)] [added: [76](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_64)] | | |
| [Notes to Consolidated Financial [removed: Statements](#i534f17d0e8de499a94e79a163c06da17_85)] [added: Statements](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_82)] | | | [removed: [81](#i534f17d0e8de499a94e79a163c06da17_85)] [added: [83](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_82)] | | |
We have audited the accompanying consolidated balance sheets of Fortinet, Inc. and subsidiaries (the “Company”) as of December 31, [removed: 2024] [added: 2025] and [removed: 2023,] [added: 2024,] the related consolidated statements of income, comprehensive income, [added: stockholders’] equity (deficit), and cash flows, for each of the three years in the period ended December 31, [removed: 2024,] [added: 2025,] and the related notes (collectively referred to as the “financial statements”).
In our opinion, the financial statements present fairly, in all material respects, the financial position of the Company as of December 31, [removed: 2024] [added: 2025] and [removed: 2023,] [added: 2024,] and the results of its operations and its cash flows for each of the three years in the period ended December 31, [removed: 2024,] [added: 2025,] in conformity with accounting principles generally accepted in the United States of America.
We have also audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the Company’s internal control over financial reporting as of December 31, [removed: 2024,] [added: 2025,] based on criteria established in *Internal Control – Integrated Framework (2013)* issued by the Committee of Sponsoring Organizations of the Treadway Commission and our report dated February [removed: 21, 2025,] [added: 24, 2026,] expressed an unqualified opinion on the Company’s internal control over financial reporting.
We are a public accounting firm registered with the PCAOB and are required to be independent with respect to the Company in accordance with the [removed: US] [added: U.S.] federal securities laws and the applicable rules and regulations of the Securities and Exchange Commission and the PCAOB.
The critical audit [removed: matter] [added: matters] communicated below [removed: is a matter] [added: are matters] arising from the current-period audit of the financial statements that [removed: was] [added: were] communicated or required to be communicated to the audit committee and that (1) [removed: relates] [added: relate] to accounts or disclosures that are material to the financial statements and (2) involved our especially challenging, subjective, or complex judgments.
The communication of critical audit matters does not alter in any way our opinion on the financial statements, taken as a whole, and we are not, by communicating the critical audit [removed: matter] [added: matters] below, providing [removed: a] separate [removed: opinion] [added: opinions] on the critical audit [removed: matter] [added: matters] or on the accounts or disclosures to which [removed: it relates.][added: they relate.]
- Obtained and read the related contract documents and evaluated whether management had properly identified the [removed: contract terms and conditions.][added: performance obligations.]
| | | | [removed: December 31, 2024] | | | | | | [removed: December 31, 2023] [added: 2024] | | | [added: | | | 2023 | | |]
| Cash and cash equivalents | | | $ | [removed: 2,875.9] [added: 2,495.3] | | | | | $ | [removed: 1,397.9] [added: 2,875.9] | |
| Short-term [removed: investments] [added: investments:] | | | [removed: 1,126.4] | | | | | | [removed: 1,021.5] | | | [added: | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |]
| Marketable equity securities | | | [removed: 64.2] | | | | | | [removed: 21.0] | | | [added: | | | | | | | | | 64.2 | | |]
| Accounts receivable—Net of allowance for credit losses of [removed: $5.9] [added: $7.4] million and [removed: $8.2] [added: $5.9] million at December 31, [removed: 2024] [added: 2025] and [removed: 2023,] [added: 2024,] respectively | | | [removed: 1,463.4] [added: 1,691.2] | | | | | | [removed: 1,402.0] [added: 1,463.4] | | |
| Inventory | | | [removed: 315.5] [added: 399.5] | | | | | | [removed: 484.8] [added: 315.5] | | |
| Prepaid expenses and other current assets | | | [removed: 126.1] [added: 227.0] | | | | | | [removed: 101.1] [added: 126.1] | | |
| Total current assets | | | [removed: 5,971.5] [added: 5,900.2] | | | | | | [removed: 4,428.3] [added: 5,971.5] | | |
| PROPERTY AND EQUIPMENT—NET | | | [removed: 1,349.5] [added: 1,619.0] | | | | | | [removed: 1,044.4] [added: 1,349.5] | | |
| DEFERRED CONTRACT COSTS | | | [removed: 622.9] [added: 735.5] | | | | | | [removed: 605.6] [added: 622.9] | | |
| DEFERRED TAX ASSETS | | | [removed: 1,335.6] [added: 1,314.9] | | | | | | [removed: 868.8] [added: 1,335.6] | | |
| GOODWILL | | | [removed: 235.4] [added: 257.4] | | | | | | [removed: 126.5] [added: 235.4] | | |
| OTHER INTANGIBLE ASSETS—NET | | | [removed: 115.0] [added: 97.3] | | | | | | [removed: 35.3] [added: 115.0] | | |
| OTHER ASSETS | | | [removed: 133.2] [added: 125.2] | | | | | | [removed: 150.0] [added: 133.2] | | |
| [removed: TOTAL ASSETS] [added: Total assets] | | | $ | [added: 10,389.2 | | | | | $ |] 9,763.1 | | | | | $ | 7,258.9 | |
| LIABILITIES AND STOCKHOLDERS’ [removed: EQUITY (DEFICIT)] [added: EQUITY] | | | | | | | | | | | |
| Accounts payable | | | $ | [removed: 190.9] [added: 230.8] | | | | | $ | [removed: 204.3] [added: 190.9] | |
| Accrued liabilities | | | [removed: 337.9] [added: 354.6] | | | | | | [removed: 423.7] [added: 337.9] | | |
| Accrued payroll and compensation | | | [removed: 255.7] [added: 312.9] | | | | | | [removed: 242.3] [added: 255.7] | | |
| Deferred revenue | | | [removed: 3,276.2] [added: 3,636.0] | | | | | | [removed: 2,848.7] [added: 3,276.2] | | |
| Total current liabilities | | | [removed: 4,060.7] [added: 5,034.0] | | | | | | [removed: 3,719.0] [added: 4,060.7] | | |
| DEFERRED REVENUE | | | [removed: 3,084.7] [added: 3,479.8] | | | | | | [removed: 2,886.3] [added: 3,084.7] | | |
| LONG-TERM DEBT | | | [removed: 994.3] [added: 496.6] | | | | | | [removed: 992.3] [added: 994.3] | | |
| OTHER LIABILITIES | | | [removed: 129.6] [added: 141.3] | | | | | | [removed: 124.7] [added: 129.6] | | |
| Total liabilities | | | [removed: 8,269.3] [added: 9,151.7] | | | | | | [removed: 7,722.3] [added: 8,269.3] | | |
| COMMITMENTS AND CONTINGENCIES (Note [removed: 12)] [added: 11)] | | | | | | | | | | | |
| STOCKHOLDERS’ [removed: EQUITY (DEFICIT):] [added: EQUITY:] | | | | | | | | | | | |
| Common stock, $0.001 par value—1,500.0 shares authorized; [removed: 767.0] [added: 743.0] shares and [removed: 761.0] [added: 767.0] shares issued and outstanding at December 31, [removed: 2024] [added: 2025] and [removed: 2023,] [added: 2024,] respectively | | | [removed: 0.8] [added: 0.7] | | | | | | 0.8 | | |
| Additional paid-in capital | | | [removed: 1,636.2] [added: 1,770.1] | | | | | | [removed: 1,416.4] [added: 1,636.2] | | |
| Accumulated other comprehensive loss | | | [removed: (26.1)] [added: (25.4)] | | | | | | [removed: (18.9)] [added: (26.1)] | | |
| Accumulated deficit | | | [removed: (117.1)] [added: (507.9)] | | | | | | [removed: (1,861.7)] [added: (117.1)] | | |
| [Consolidated Balance Sheets](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_67) | | | [78](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_67) | | |
| [Consolidated Statements of Income](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_70) | | | [79](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_70) | | |
| [Consolidated Statements of Comprehensive Income](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_73) | | | [80](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_73) | | |
| [Consolidated Statements of](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_76) [](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_76)[Stockholders’](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_76) [](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_76)[Equity (Deficit)](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_76) | | | [81](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_76) | | |
| [Consolidated Statements of Cash Flows](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_79) | | | [82](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_79) | | |
February 24, 2026
| LONG-TERM INVESTMENTS | | | 339.7 | | | | | | — | | |
| Current portion of long-term debt | | | 499.7 | | | | | | — | | |
| Repurchase and retirement of common stock | | | (28.7) | | | | | | (0.1) | | | | | | (45.5) | | | | | | — | | | | | | (2,244.2) | | | | | | (2,289.8) | | |
| Excise tax on net stock repurchases | | | — | | | | | | — | | | | | | (18.3) | | | | | | — | | | | | | — | | | | | | (18.3) | | |
| Stock-based compensation expense | | | — | | | | | | — | | | | | | 279.5 | | | | | | — | | | | | | — | | | | | | 279.5 | | |
| Net income | | | — | | | | | | — | | | | | | — | | | | | | — | | | | | | 1,853.4 | | | | | | 1,853.4 | | |
| BALANCE—December 31, 2025 | | | 743.0 | | | | | | $ | 0.7 | | | | | $ | 1,770.1 | | | | | $ | (25.4) | | | | | $ | (507.9) | | | | | $ | 1,237.5 | |
| Other | | | (52.7) | | | | | | (92.1) | | | | | | 60.6 | | |
Amounts previously reported as marketable equity securities are included in short-term investments in prior periods to conform with current period presentation in our consolidated balance sheets.
Amounts previously reported as gain on bargain purchase are included in other income (expense)—net in prior periods to conform with current period presentation in our consolidated statements of income.
Amounts previously reported as loss from equity method investments and gain on bargain purchase are included in other in prior periods to conform with current period presentation in section of net cash provided by operating activities in our consolidated statements of cash flows.
The reclassification had no impact on our previously reported total assets, net income or cash flows from operating or investing activities and did not result in a restatement of prior period consolidated financial statements.
financial statements on a recurring basis.
We consider relevant quantitative and qualitative information, including general market conditions and the duration of the unrealized loss, in assessing whether a decline in fair value below amortized cost is attributable to credit related factors and whether we intend to sell, or will be required to sell, the security before recovery of its amortized cost basis.
We often continue to gather additional information throughout the measurement period, not to exceed one year from the acquisition date.
Measurement period adjustments that relate to facts and circumstances that existed as of the acquisition date are generally recorded with a corresponding adjustment to goodwill, as if the accounting had been completed at the acquisition date.
Adjustments identified after the measurement period are recognized in the consolidated statements of income in the period identified.
On July 4, 2025, H.R. 1, an Act to Provide for Reconciliation Pursuant to Title II of House Concurrent Resolution 14 (the “Act”) commonly referred to as the One Big Beautiful Bill Act, was enacted.
The Act makes permanent certain elements of the Tax Cuts and Jobs Act, including immediate expensing of U.S. research and development expenditures, immediate expensing of certain eligible assets, and various modifications to the international tax framework.
As a result of the Act, our income tax liability in 2025 decreased by $120.0 million and our GAAP effective tax rate for 2025 increased by one percentage point.
Research and development costs also include ASIC and system prototype and certification-related expenses, depreciation of property and equipment and facility-related expenses.
The majority of our research and development is focused on software and hardware development.
Security subscription include SaaS which is either hosted by us or provided through cloud providers.
Income Taxes.
*Expense Disaggregation Disclosures*
*Credit Losses*
In July 2025, the FASB issued ASU 2025-05—Financial Instruments—Credit Losses (Topic 326): Measurement of Credit Losses for Accounts Receivable and Contract Assets (“ASU 2025-05”), which provides a practical expedient for estimating expected credit losses for current accounts receivable and current contract assets that arise from transactions accounted for under Revenue from Contracts with Customers (Topic 606).
*Internal-Use Software*
In September 2025, the FASB issued ASU 2025-06, Intangibles—Goodwill and Other—Internal-Use Software (Subtopic 350-40): Targeted Improvements to the Accounting for Internal-Use Software (“ASU 2025-06”), which amends the cost capitalization criteria for internal-use software development costs by removing all references to prescriptive and sequential software project development stages and providing new guidance on how to evaluate whether the probable-to-complete recognition threshold has been met.
The amendments are effective for our annual period beginning fiscal year 2028 and interim reporting periods within those annual reporting periods and can be applied prospectively, retrospectively, or via a modified prospective transition method, with early adoption permitted.
We are currently assessing adoption timing and the method of adoption.
| | | | 2025 | | | | | | 2024 | | | | | | 2023 | | |
| Product | | | $ | 2,218.4 | | | | | $ | 1,908.7 | | | | | $ | 1,927.3 | |
Short-Term and Long-Term Investments
| | | | | | |
| --- | --- | --- | --- | --- | --- |
| [Consolidated Balance Sheets as of December 31, 202](#i534f17d0e8de499a94e79a163c06da17_70)[4](#i534f17d0e8de499a94e79a163c06da17_70) [and 202](#i534f17d0e8de499a94e79a163c06da17_70)[3](#i534f17d0e8de499a94e79a163c06da17_70) | | | [76](#i534f17d0e8de499a94e79a163c06da17_70) | | |
| [Consolidated Statements of Income for the years ended December 31, 202](#i534f17d0e8de499a94e79a163c06da17_73)[4](#i534f17d0e8de499a94e79a163c06da17_73)[, 202](#i534f17d0e8de499a94e79a163c06da17_73)[3](#i534f17d0e8de499a94e79a163c06da17_73) [and 202](#i534f17d0e8de499a94e79a163c06da17_73)[2](#i534f17d0e8de499a94e79a163c06da17_73) | | | [77](#i534f17d0e8de499a94e79a163c06da17_73) | | |
| [Consolidated Statements of Comprehensive Income for the years ended December 31, 202](#i534f17d0e8de499a94e79a163c06da17_76)[4](#i534f17d0e8de499a94e79a163c06da17_76)[, 202](#i534f17d0e8de499a94e79a163c06da17_76)[3](#i534f17d0e8de499a94e79a163c06da17_76) [and 202](#i534f17d0e8de499a94e79a163c06da17_76)[2](#i534f17d0e8de499a94e79a163c06da17_76) | | | [78](#i534f17d0e8de499a94e79a163c06da17_76) | | |
| [Consolidated Statements of Equity (Deficit) for the years ended December 31, 202](#i534f17d0e8de499a94e79a163c06da17_79)[4](#i534f17d0e8de499a94e79a163c06da17_79)[, 202](#i534f17d0e8de499a94e79a163c06da17_79)[3](#i534f17d0e8de499a94e79a163c06da17_79) [and 202](#i534f17d0e8de499a94e79a163c06da17_79)[2](#i534f17d0e8de499a94e79a163c06da17_79) | | | [79](#i534f17d0e8de499a94e79a163c06da17_79) | | |
| [Consolidated Statements of Cash Flows for the years ended December 31, 202](#i534f17d0e8de499a94e79a163c06da17_82)[4](#i534f17d0e8de499a94e79a163c06da17_82)[, 202](#i534f17d0e8de499a94e79a163c06da17_82)[3](#i534f17d0e8de499a94e79a163c06da17_82) [and 202](#i534f17d0e8de499a94e79a163c06da17_82)[2](#i534f17d0e8de499a94e79a163c06da17_82) | | | [80](#i534f17d0e8de499a94e79a163c06da17_82) | | |
February 21, 2025
| | | | | | | | | | | | |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| GAIN ON BARGAIN PURCHASE | | | 106.3 | | | | | | — | | | | | | — | | |
| LESS: NET LOSS ATTRIBUTABLE TO NON-CONTROLLING INTERESTS, NET OF TAX | | | — | | | | | | — | | | | | | (0.7) | | |
| Less: comprehensive income attributable to non-controlling interests | | | — | | | | | | — | | | | | | 0.2 | | |
| Comprehensive income attributable to Fortinet, Inc. | | | $ | 1,738.0 | | | | | $ | 1,149.1 | | | | | $ | 841.9 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| BALANCE—December 31, 2021 | | | 810.0 | | | | | | $ | 0.8 | | | | | $ | 1,253.6 | | | | | $ | (4.8) | | | | | $ | (467.9) | | | | | $ | 16.7 | | | | | $ | 798.4 | |
| Acquisition of the non-controlling interests | | | — | | | | | | — | | | | | | 3.4 | | | | | | — | | | | | | — | | | | | | (16.9) | | | | | | (13.5) | | |
| Net income | | | — | | | | | | — | | | | | | — | | | | | | — | | | | | | 857.3 | | | | | | (0.7) | | | | | | 856.6 | | |
| Gain on bargain purchase | | | (106.3) | | | | | | — | | | | | | — | | |
| Other | | | (15.2) | | | | | | 18.5 | | | | | | 23.6 | | |
| Repurchase and retirement of common stock | | | (0.6) | | | | | | (1,500.5) | | | | | | (1,991.2) | | |
We consult with our investment managers and consider available quantitative and qualitative evidence in evaluating, among other factors, general market conditions, the duration and extent to which the fair value is less than cost, and our ability to hold the investment.
Subsequently, we recognize our proportionate share of the
values of these identifiable assets and liabilities is recorded as goodwill.
Our estimates and assumptions are subject to change based on information existing at acquisition date but unknown to us, which may become known during the remainder of the measurement period, not to exceed 12 months from the acquisition date, and if we make changes to the amounts recorded, such amounts are recorded in the period in which they are identified.
The tax benefits recognized
To date, SaaS revenue has not represented a significant percentage of our total revenue.
of products, gross margin objectives, pricing practices, geographies and the term of a service contract.
In the event we change our warranty reserve estimates, the resulting charge against future cost of revenue or reversal of previously recorded charges may materially affect our gross margins and operating results.
*Segment Reporting*
In November 2023, the Financial Accounting Standards Board (the “FASB”) issued Accounting Standards Update (“ASU”) 2023-07, Segment Reporting (Topic 280): Improvements to Reportable Segment Disclosures, which is intended to improve reportable segment disclosure requirements, primarily through enhanced disclosures about significant expenses.
Segment Information.
disaggregation of rate reconciliation categories and income taxes paid by jurisdiction.
*Income Statement*
| | | | | | | | | | | | | | | | | | | | | | | | |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| Commercial paper | | | 401.7 | | | | | | 0.2 | | | | | | (0.1) | | | | | | 401.8 | | |
| Total available-for-sale investments | | | $ | 1,021.4 | | | | | $ | 0.6 | | | | | $ | (0.5) | | | | | $ | 1,021.5 | |
| | | | December 31, 2023 | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
An excerpt. Shown here: 40 of 473 rewritten, 40 of 258 added and 40 of 173 removed. The counts are complete. For every sentence, read Item 8. Financial Statements and Supplementary Data in the FY2025 filing and the FY2024 filing.
Item 9A. Controls and Procedures
7 rewritten, 1 added, 5 removed, 27 unchanged
Based on that evaluation, our chief executive officer and chief financial officer concluded that our disclosure controls and procedures were effective as of December 31, [removed: 2024] [added: 2025] to provide reasonable assurance that information we are required to disclose in reports that we file or submit under the Exchange Act is recorded, processed, summarized and reported within the time periods specified in SEC rules and forms, and that such information is accumulated and communicated to our management, including our Chief Executive Officer and Chief Financial Officer, as appropriate, to allow timely decisions regarding required disclosure.
Based on this evaluation, management concluded that our internal control over financial reporting was effective as of December 31, [removed: 2024.][added: 2025.]
The effectiveness of our internal control over financial reporting as of December 31, [removed: 2024] [added: 2025] has been audited by Deloitte & Touche LLP, an independent registered public accounting firm, as stated in its report, which appears in this Item under the heading “Report of Independent Registered Public Accounting Firm.”
There were no [removed: other] changes in our internal controls over financial reporting (as defined in Rules 13a-15(f) or 15d-15(f) under the Exchange Act) during [removed: 2024] [added: 2025] that have materially affected, or are reasonably likely to materially affect, our internal controls over financial reporting.
We have audited the internal control over financial reporting of Fortinet, Inc. and subsidiaries (the “Company”) as of December 31, [removed: 2024,] [added: 2025,] based on criteria established in *Internal Control – Integrated Framework (2013)* issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO).
In our opinion, the Company maintained, in all material respects, effective internal control over financial reporting as of December 31, [removed: 2024,] [added: 2025,] based on criteria established in *Internal Control – Integrated Framework (2013)* issued by COSO.
We have also audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the consolidated financial statements as of and for the year ended December 31, [removed: 2024,] [added: 2025,] of the Company and our report dated February [removed: 21, 2025,] [added: 24, 2026,] expressed an unqualified opinion on those financial statements.
February 24, 2026
As permitted by applicable SEC guidance, management has excluded Lacework, a privately held data-driven cloud security company, Next DLP, a privately held data security company, and Perception Point, a privately held advanced collaboration and email security company from its assessment of internal control over financial reporting as of December 31, 2024, because Lacework, Next DLP and Perception Point were acquired by us in business combinations during the fiscal year ended December 31, 2024.
Lacework, Next DLP and Perception Point revenues represented approximately 0.5%, less than 0.1% and less than 0.1% of our consolidated total revenue, respectively, for the year ended December 31, 2024.
As described in “Management’s Report on Internal Control over Financial Reporting”, management excluded from its assessment the internal control over financial reporting at Lacework, Inc. (“Lacework”), a privately held data-driven cloud security company, Next DLP Holdings Limited (“Next DLP”), a privately held data security company, and Perception Point, Ltd. (“Perception Point”), a privately held advanced collaboration and email security company from its assessment of internal control over financial reporting as of December 31, 2024.
Lacework, Next DLP, and Perception Point revenues represented approximately 0.5%, less than 0.1%, and less than 0.1%, respectively, of the Company’s consolidated total revenue for the year ended December 31, 2024.
February 21, 2025
Item 9B. Other Information
0 rewritten, 1 added, 20 removed, 1 unchanged
No director or Section 16 officer of the Company adopted or terminated a “Rule 10b5-1 trading arrangement” or “non-Rule 10b5-1 trading arrangement,” as each term is defined in Item 408(a) of Regulation S-K, during the three months ended December 31, 2025.
On December 9, 2024, William H.
Neukom, one of our directors, entered into a pre-arranged written stock sale plan in accordance with Rule 10b5-1 under the Exchange Act for the purchase of shares of our common stock (the “Neukom Plan”) during an open trading window in accordance with our insider trading policy.
The Neukom Plan is intended to satisfy the affirmative defense of Rule 10b5-1(c) under the Exchange Act.
The Neukom Plan provides for the potential purchase by Mr. Neukom of up to $35,000 worth of shares of our common stock per at the market price, on five dates between March 6, 2025 and March 6, 2026, as specified in the Neukom Plan.
On December 9, 2024, Kenneth A.
Goldman, one of our directors, entered into a pre-arranged written stock sale plan in accordance with Rule 10b5-1 under the Exchange Act for the sale of shares of our common stock (the “Goldman Plan”) during an open trading window in accordance with our insider trading policy.
The Goldman Plan is intended to satisfy the affirmative defense of Rule 10b5-1(c) under the Exchange Act.
The Goldman Plan provides for the potential sale by Mr. Goldman of up to 3,000 shares of our common stock, issued upon the exercise of vested options to purchase shares of our common stock, at the market price, so long as the market price is equal to or greater than $95.00 per share, between March 10, 2025 and March 10, 2026.
On December 9, 2024, Ken Xie, our Chief Executive Officer and one of our directors, entered into a pre-arranged written stock sale plan in accordance with Rule 10b5-1 under the Exchange Act for the sale of shares of our common stock (the “Ken Xie Plan”) during an open trading window in accordance with our insider trading policy.
The Ken Xie Plan is intended to satisfy the affirmative defense of Rule 10b5-1(c) under the Exchange Act.
The Ken Xie Plan provides for the potential sale by Mr. Xie of up to (a) 734,880 shares of our common stock, issued upon the vesting and settlement of RSUs and PSUs for shares of our common stock and the exercise of vested options to purchase shares of our common stock and (b) the net shares (which are not yet determinable) after shares are withheld to satisfy tax obligations upon such vesting and settlement of RSUs and PSUs, in each case, at the market price, all between March 10, 2025 and May 6, 2026.
On December 10, 2024, Michael Xie, our Chief Technology Officer and one of our directors, entered into a pre-arranged written stock sale plan in accordance with Rule 10b5-1 under the Exchange Act for the sale of shares of our common stock (the “Michael Xie Plan”) during an open trading window in accordance with our insider trading policy.
The Michael Xie Plan is intended to satisfy the affirmative defense of Rule 10b5-1(c) under the Exchange Act.
The Michael Xie Plan provides for the potential sale by Mr. Xie of up to (a) 624,285 shares of our common stock, issued upon the vesting and settlement of RSUs for shares of our common stock and the exercise of vested options to purchase shares of our common stock and (b) the net shares (which are not yet determinable) after shares are withheld to satisfy tax obligations upon such vesting and settlement of RSUs and PSUs, in each case, at the market price, all between March 11, 2025 and May 6, 2026.
Each of the Neukom Plan, Goldman Plan, Ken Xie Plan and Michael Xie Plan (each, a “10b5-1 Plan,” and together, the “10b5-1 Plans”) includes a representation from each of Mr. Neukom, Mr. Goldman, Mr. Ken Xie and Mr. Michael Xie, respectively, to the broker administering the plan that they were not in possession of any material nonpublic information regarding us or the securities subject to the respective 10b5-1 Plan at the time the respective 10b5-1 Plan were entered into.
A similar representation was made to us in connection with the adoption of each 10b5-1 Plan under our insider trading policy.
Those representations for each 10b5-1 Plan were made as of the respective date of adoption of the applicable 10b5-1 Plan, and speak only as of that date.
In making those representations, there is no assurance with respect to any material nonpublic information of which Mr. Neukom, Mr. Goldman, Mr. Ken Xie and Mr. Michael Xie, as applicable, were unaware, or with respect to any material nonpublic information acquired by Mr. Neukom, Mr. Goldman, Mr. Ken Xie and Mr. Michael Xie or us, as applicable, after the date of each such representation.
Once executed, transactions under the 10b5-1 Plans will be disclosed publicly through Form 4 and/or Form 144 filings with the SEC in accordance with applicable securities laws, rules and regulations.
Except as may be required by law, we do not undertake any obligation to update or report any modification, termination, or other activity under current or future Rule 10b5-1 plans that may be adopted by Mr. Neukom, Mr. Goldman, Mr. Ken Xie or Mr. Michael Xie or our other officers or directors, or their affiliated entities.
Item 10. Directors, Executive Officers and Corporate Governance
1 rewritten, 0 added, 0 removed, 8 unchanged
Information responsive to this item is incorporated herein by reference to our definitive proxy statement with respect to our [removed: 2025] [added: 2026] Annual Meeting of Stockholders to be filed with the SEC within 120 days after the end of the fiscal year covered by this Annual Report on Form 10-K.
Item 11. Executive Compensation
1 rewritten, 0 added, 0 removed, 0 unchanged
Information responsive to this item is incorporated herein by reference to our definitive proxy statement with respect to our [removed: 2025] [added: 2026] Annual Meeting of Stockholders to be filed with the SEC within 120 days after the end of the fiscal year covered by this Annual Report on Form 10-K.
Item 12. Security Ownership of Certain Beneficial Owners and Management and Related Stockholder Matters
1 rewritten, 0 added, 0 removed, 0 unchanged
Information responsive to this item is incorporated herein by reference to our definitive proxy statement with respect to our [removed: 2025] [added: 2026] Annual Meeting of Stockholders to be filed with the SEC within 120 days after the end of the fiscal year covered by this Annual Report on Form 10-K.
Item 13. Certain Relationships and Related Transactions, and Director Independence
1 rewritten, 0 added, 0 removed, 0 unchanged
Information responsive to this item is incorporated herein by reference to our definitive proxy statement with respect to our [removed: 2025] [added: 2026] Annual Meeting of Stockholders to be filed with the SEC within 120 days after the end of the fiscal year covered by this Annual Report on Form 10-K.
Item 14. Principal Accounting Fees and Services
1 rewritten, 0 added, 0 removed, 1 unchanged
Information responsive to this item is incorporated herein by reference to our definitive proxy statement with respect to our [removed: 2025] [added: 2026] Annual Meeting of Stockholders to be filed with the SEC within 120 days after the end of the fiscal year covered by this Annual Report on Form 10-K.
Item 15. Exhibits and Financial Statement Schedules
12 rewritten, 0 added, 2 removed, 80 unchanged
| [removed: [4.2](https://www.sec.gov/Archives/edgar/data/1262039/000126203925000011/ftnt-ex42_20241231xk.htm)*] [added: [4.2](https://www.sec.gov/Archives/edgar/data/1262039/000126203926000007/ftnt-ex42_20251231xk.htm)*] | | | | | | Description of Securities Registered Pursuant to Section 12 of the Exchange Act | | | | | | | | | | | | | | | | | | | | |
| [removed: [10.16](https://www.sec.gov/Archives/edgar/data/1262039/000126203924000037/ftnt-ex104amendedandrestat.htm)†] [added: [10.1](https://www.sec.gov/Archives/edgar/data/1262039/000126203925000028/ftnt-ex101_changeofctrlsev.htm)[5](https://www.sec.gov/Archives/edgar/data/1262039/000126203925000028/ftnt-ex101_changeofctrlsev.htm)†] | | | | | | [removed: Amended and Restated] Change of Control Severance Agreement, effective as of [removed: August 7, 2024,] [added: May 15, 2025,] between the Company and [removed: Keith Jensen] [added: Christian Ohlgart] | | | | | | Quarterly Report on Form 10-Q (File No. 001-34511) | | | | | | August 8, [removed: 2024] [added: 2025] | | | | | | [removed: 10.4] [added: 10.1] | | |
| [removed: [10.1](https://www.sec.gov/Archives/edgar/data/1262039/000126203923000021/exhibit101-formofpsuawarda.htm)[7](https://www.sec.gov/Archives/edgar/data/1262039/000126203923000021/exhibit101-formofpsuawarda.htm)†] [added: [10.1](https://www.sec.gov/Archives/edgar/data/1262039/000126203923000021/exhibit101-formofpsuawarda.htm)[6](https://www.sec.gov/Archives/edgar/data/1262039/000126203923000021/exhibit101-formofpsuawarda.htm)†] | | | | | | Form of performance stock unit award agreement under Amended and Restated 2009 Equity Incentive Plan | | | | | | Quarterly Report on Form 10-Q (File No. 001-34511) | | | | | | May 8, 2023 | | | | | | 10.1 | | |
| [removed: [10.](https://www.sec.gov/Archives/edgar/data/1262039/000126203923000021/exhibit102-globalrsuagreem.htm)[18](https://www.sec.gov/Archives/edgar/data/1262039/000126203923000021/exhibit102-globalrsuagreem.htm)†] [added: [10.1](https://www.sec.gov/Archives/edgar/data/1262039/000126203923000021/exhibit102-globalrsuagreem.htm)[7](https://www.sec.gov/Archives/edgar/data/1262039/000126203923000021/exhibit102-globalrsuagreem.htm)†] | | | | | | Form of restricted stock unit award agreement under Amended and Restated 2009 Equity Incentive Plan (Additional Form) | | | | | | Quarterly Report on Form 10-Q (File No. 001-34511) | | | | | | May 8, 2023 | | | | | | 10.2 | | |
| [removed: [1](https://www.sec.gov/Archives/edgar/data/1262039/000126203925000011/ftnt-ex191insidertradingpo.htm)[9.1](https://www.sec.gov/Archives/edgar/data/1262039/000126203925000011/ftnt-ex191insidertradingpo.htm)*] [added: [19.1](https://www.sec.gov/Archives/edgar/data/1262039/000126203925000011/ftnt-ex191insidertradingpo.htm)] | | | | | | Insider Trading Policy | | | | | | [added: Annual Report on Form 10-K (File No. 001-34511)] | | | | | | [added: February 21, 2025] | | | | | | [added: 19.1] | | |
| [removed: [21.1](https://www.sec.gov/Archives/edgar/data/1262039/000126203925000011/ftnt-ex211_20241231xk.htm)*] [added: [21.1](https://www.sec.gov/Archives/edgar/data/1262039/000126203926000007/ftnt-ex211_20251231xk.htm)*] | | | | | | List of subsidiaries | | | | | | | | | | | | | | | | | | | | |
| [removed: [23.1](https://www.sec.gov/Archives/edgar/data/1262039/000126203925000011/ftnt-ex231_20241231xk.htm)*] [added: [23.1](https://www.sec.gov/Archives/edgar/data/1262039/000126203926000007/ftnt-ex231_20251231xk.htm)*] | | | | | | Consent of Independent Registered Public Accounting Firm | | | | | | | | | | | | | | | | | | | | |
| [removed: [24.1](#i534f17d0e8de499a94e79a163c06da17_217)*] [added: [24.1](#i71fcb98cc5f34eafa1d5d1bdeaf1bef2_226)*] | | | | | | Power of Attorney (incorporated by reference to the signature page of this Annual Report on Form 10-K) | | | | | | | | | | | | | | | | | | | | |
| [removed: [31.1](https://www.sec.gov/Archives/edgar/data/1262039/000126203925000011/ftnt-ex311_20241231xk.htm)*] [added: [31.1](https://www.sec.gov/Archives/edgar/data/1262039/000126203926000007/ftnt-ex311_20251231xk.htm)*] | | | | | | Certification of Chief Executive Officer pursuant to Exchange Act Rules 13a-14(a) and 15d-14(a), as adopted pursuant to Section 302 of the Sarbanes-Oxley Act of 2002 | | | | | | | | | | | | | | | | | | | | |
| [removed: [31.2](https://www.sec.gov/Archives/edgar/data/1262039/000126203925000011/ftnt-ex312_20241231xk.htm)] [added: [31.2](https://www.sec.gov/Archives/edgar/data/1262039/000126203926000007/ftnt-ex312_20251231xk.htm)] | | | | | | Certification of Chief Financial Officer pursuant to Exchange Act Rules 13a-14(a) and 15d-14(a), as adopted pursuant to Section 302 of the Sarbanes-Oxley Act of 2002 | | | | | | | | | | | | | | | | | | | | |
| [removed: [32.1](https://www.sec.gov/Archives/edgar/data/1262039/000126203925000011/ftnt-ex321_20241231xk.htm)] [added: [32.1](https://www.sec.gov/Archives/edgar/data/1262039/000126203926000007/ftnt-ex321_20251231xk.htm)] | | | | | | Certifications of Chief Executive Officer and Chief Financial Officer pursuant to 18 U.S.C. Section 1350, as adopted pursuant to Section 906 of the Sarbanes-Oxley Act of 2002 | | | | | | | | | | | | | | | | | | | | |
| 104* | | | | | | Cover Page Interactive Data File - the cover page from the Company’s Annual Report on Form 10-K for the year ended December 31, [removed: 2024] [added: 2025] is formatted in inline XBRL. | | | | | | | | | | | | | | | | | | | | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | |
| [10.15](https://www.sec.gov/Archives/edgar/data/1262039/000126203918000009/ftnt-ex1022_20171231xk.htm)† | | | | | | Offer Letter, dated as of April 3, 2014, by and between the Company and Keith Jensen | | | | | | Annual Report on Form 10-K (File No. 001-34511) | | | | | | February 26, 2018 | | | | | | 10.22 | | |
Item 16. Form 10-K summary
14 rewritten, 1 added, 13 removed, 38 unchanged
| Date: February [removed: 21, 2025] [added: 24, 2026] | | | | | | | | |
| | | | | | | [removed: Keith Jensen,] [added: Christiane Ohlgart,] Chief Financial Officer | | |
| | | | | | | (Duly Authorized Officer and Principal Financial [added: Officer and Principal Accounting] Officer) | | |
| [added: /s/ Christiane Ohlgart] | | | | | | [removed: Christiane Ohlgart,] Chief [removed: Accounting Officer] [added: Financial Officer] | | | [added: | | | February 24, 2026 | | |]
| [added: Christiane Ohlgart] | | | | | | [removed: (Duly Authorized] [added: (Principal Financial] Officer and Principal Accounting [removed: Officer)] [added: Officer)] | | | [added: | | | | | |]
KNOW ALL PERSONS BY THESE PRESENTS, that each person whose signature appears below constitutes and appoints Ken Xie and [removed: Keith Jensen,] [added: Christiane Ohlgart,] jointly and severally, his or her attorney-in-fact, with the power of substitution, for him or her in any and all capacities, to sign any amendments to this Annual Report on Form 10-K and to file the same, with exhibits thereto and other documents in connection therewith, with the Securities and Exchange Commission, hereby ratifying and confirming all that each of said attorneys-in-fact, or his substitute or substitutes, may do or cause to be done by virtue hereof.
| /s/ Ken Xie | | | | | | Chief Executive Officer and Chairman | | | | | | February [removed: 21, 2025] [added: 24, 2026] | | |
| /s/ Michael Xie | | | | | | President, Chief Technology Officer and Director | | | | | | February [removed: 21, 2025] [added: 24, 2026] | | |
| /s/ Kenneth A. Goldman | | | | | | Director | | | | | | February [removed: 21, 2025] [added: 24, 2026] | | |
| /s/ Ming Hsieh | | | | | | Director | | | | | | February [removed: 21, 2025] [added: 24, 2026] | | |
| /s/ Jean Hu | | | | | | Director | | | | | | February [removed: 21, 2025] [added: 24, 2026] | | |
| /s/ Janet Napolitano | | | | | | Director | | | | | | February [removed: 21, 2025] [added: 24, 2026] | | |
| /s/ Judith Sim | | | | | | Director | | | | | | February [removed: 21, 2025] [added: 24, 2026] | | |
| /s/ Admiral James Stavridis | | | | | | Director | | | | | | February [removed: 21, 2025] [added: 24, 2026] | | |
| Date: February 24, 2026 | | | | | | | | |
| | | | | | | | | |
| --- | --- | --- | --- | --- | --- | --- | --- | --- |
| FORTINET, INC. | | | | | | | | |
| | | | By: | | | /s/ Keith Jensen | | |
| | | | | | | | | | | | | | | |
| /s/ Keith Jensen | | | | | | Chief Financial Officer | | | | | | February 21, 2025 | | |
| Keith Jensen | | | | | | (Principal Financial Officer) | | | | | | | | |
| /s/ Christiane Ohlgart | | | | | | Principal Accounting Officer | | | | | | February 21, 2025 | | |
| Christiane Ohlgart | | | | | | | | | | | | | | |
| /s/ William H. Neukom | | | | | | Director | | | | | | February 21, 2025 | | |
| William H. Neukom | | | | | | | | | | | | | | |
| /s/ Maggie Wilderotter | | | | | | Director | | | | | | February 21, 2025 | | |
| Maggie Wilderotter | | | | | | | | | | | | | | |