Cover and table of contents
180K characters. Original on sec.gov · Markdown
Cover and table of contents
UNITED STATES SECURITIES AND EXCHANGE COMMISSION
Washington, D.C. 20549
FORM 10-K
| ☒ | Annual Report pursuant to Section 13 or 15(d) of the Securities Exchange Act of 1934 |
For the fiscal year ended December 31, 2025
OR
| ☐ | Transition report pursuant to Section 13 or 15(d) of the Securities Exchange Act of 1934 |
Commission File Number: 001-35580

SERVICEN****OW, I****NC.
(Exact name of registrant as specified in its charter)
| Delaware | 20-2056195 | |||||||
| (State or other jurisdiction of incorporation or organization) | (I.R.S. Employer Identification Number) |
ServiceNow, Inc.
2225 Lawson Lane
Santa Clara, California 95054
(408) 501-8550
(Address, including zip code, and telephone number, including area code, of registrant’s principal executive offices)
Securities registered pursuant to Section 12(b) of the Act:
| Title of each class | Trading Symbol | Name of each exchange on which registered | ||||||||||||
| Common stock, par value $0.001 per share | NOW | The New York Stock Exchange |
Securities registered pursuant to Section 12(g) of the Act:
Not applicable
Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes ☒ No ☐
Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of Act. Yes ☐ No ☒
Indicate by check mark whether the registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days: Yes ☒ No ☐
Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yes ☒ No ☐
Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company or an emerging growth company. See the definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company” and “emerging growth company” in Rule 12b-2 of the Exchange Act.
| Large Accelerated Filer | ☒ | Accelerated Filer | ☐ | ||||||||
| Non-Accelerated Filer | ☐ | Smaller Reporting Company | ☐ | ||||||||
| Emerging Growth Company | ☐ |
If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐
Indicate by check mark whether the registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C. 7262(b)) by the registered public accounting firm that prepared or issued its audit report. ☒
If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements of the registrant included in the filing reflect the correction of an error to previously issued financial statements. ☐
Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the registrant’s executive officers during the relevant recovery period pursuant to §240.10D-1(b). ☐
Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Act). Yes ☐ No ☒
Based on the closing price of the registrant’s Common Stock on the New York Stock Exchange on the last business day of the registrant’s most recently completed second fiscal quarter, June 30, 2025, the aggregate market value of its shares held by non-affiliates was approximately $175.7 billion.
As of January 23, 2026, there were approximately 1,046 million shares of the registrant’s Common Stock outstanding.
DOCUMENTS INCORPORATED BY REFERENCE
Portions of the registrant’s definitive proxy statement for its 2026 Annual Meeting of Stockholders (Proxy Statement) to be filed within 120 days of the registrant’s fiscal year ended December 31, 2025, are incorporated by reference in Part III of this Report on Form 10-K. Except with respect to information specifically incorporated by reference in this Form 10-K, the Proxy Statement is not deemed to be filed as part of this Form 10-K.
Table of Contents
Part I
Forward-Looking Statements
This Annual Report on Form 10-K contains forward-looking statements regarding future events and our future results that are based on our current expectations, estimates, forecasts and projections about our business, our results of operations, the industry in which we operate and the beliefs and assumptions of our management. Words such as “believe,” “may,” “will,” “estimate,” “continue,” “anticipate,” “would,” “could,” “should,” “intend” and “expect,” as well as variations of these words and similar expressions, are intended to identify those forward-looking statements. Forward-looking statements are only predictions and are subject to risks, uncertainties, assumptions and other factors that are difficult to predict. Therefore, actual results may differ materially and adversely from those expressed in any forward-looking statements. Factors that might cause or contribute to such differences include, but are not limited to, those discussed in this Annual Report under “Risk Factors” in Item 1A of Part I and elsewhere herein and in other reports we file with the Securities and Exchange Commission (“SEC”). While forward-looking statements are based on our management’s reasonable expectations at the time that they are made, you should not rely on those statements. We undertake no obligation to revise or update publicly any forward-looking statements for any reason, whether as a result of new information, future events or otherwise, except as may be required by law.
| Item 1. Business | ||
Overview
ServiceNow delivers solutions that help public and private organizations govern, secure and manage artificial intelligence and digitalize and streamline workflows to drive collaboration, productivity and better experiences across the enterprise. We offer an innovative suite of products, including AI-powered applications, and services designed to automate workflows, integrate systems and empower employees, regardless of existing systems, cloud environments or collaboration tools. At the core of these solutions is the ServiceNow AI Platform, a robust, cloud-based platform that facilitates comprehensive delivery of seamless workflows and drives digital transformation across all departments and personas within an organization.
With the emergence of artificial intelligence, organizations are under pressure from their stakeholders to accelerate growth and achieve unprecedented productivity improvements. To meet these demands, they are prioritizing the digitalization and modernization of their workflows through AI-powered automation. At the same time, they are seeking secure and reliable tools to manage the heightened risks associated with AI innovation and ensure measurable returns on investment. ServiceNow addresses these evolving organizational needs by providing solutions that help organizations govern, secure, and manage artificial intelligence, while optimizing their workflows.
We operate in a dynamic and rapidly evolving technology landscape characterized by the accelerating adoption of artificial intelligence and machine learning capabilities across enterprise software. While this period of technological transformation presents both opportunities and uncertainties reminiscent of prior inflection points—such as the shift from on-premises to cloud computing in the early 2010s and the advent of mobile computing before that—we believe our established market position, deep customer relationships, and platform capabilities position us favorably to capitalize on these emerging needs. We have invested in understanding evolving customer requirements through ongoing dialogue with our customer base, which spans diverse industries and use cases, and we have developed our platform to address the practical challenges enterprises encounter when
| 2025 Annual Report | 1 |
Part I
implementing AI-enabled automation within mission-critical business processes while maintaining security, governance and operational continuity.
A critical insight emerging from this technological shift is that AI excels at analyzing data and generating information, but transforming that information into business outcomes requires infrastructure that can orchestrate action across systems, enforce governance policies, and manage complex workflows. AI models can identify patterns, make recommendations, and surface insights, but they cannot independently execute transactions, route approvals, update systems of record, or support compliance with business rules and regulatory requirements. Our platform addresses this fundamental gap by providing the underlying infrastructure that connects AI-generated insights to the operational systems and processes where work actually gets done. This capability—to direct, control, and manage what happens after information is generated—represents a substantial portion of the value enterprises seek when adopting AI technologies.
Several factors contribute to our competitive positioning in this environment. Our two decades partnering with enterprise customers provide us with a deep understanding of how work actually flows across organizations—across departments, systems and organizational silos. We have developed expertise in the operational processes specific to different industries, functional areas and user roles, knowledge that cannot be readily replicated and that proves essential when designing solutions that must integrate with existing workflows rather than replace them. This institutional knowledge enables us to build cross-functional workflows that reflect the practical realities of how enterprises operate, rather than idealized process models. Building on this foundation, our platform’s architecture, developed over years of iteration with customer feedback, allows organizations to deploy AI-enhanced workflows without replacing their existing technology infrastructure or disrupting established processes. We bridge the gap between AI's analytical capabilities and the execution layer where business processes operate, providing the connective tissue that turns insights into outcomes. Equally important, our experience operating a software-as-a-service platform at scale gives us operational expertise in maintaining reliability, security, and performance standards that enterprise customers require, particularly as they entrust increasingly critical functions to AI-enabled systems.
While competitors are actively developing AI capabilities and several entrants have emerged with point solutions focused on data analysis and information generation, we believe many face challenges in delivering the comprehensive integration, workflow orchestration, governance frameworks, and enterprise-grade reliability that our customers require to operationalize AI insights. The AI era has not eliminated—and has arguably intensified—the fundamental need for platforms that can unify disparate systems, maintain data integrity, ensure regulatory compliance, enforce business logic, and provide consistent execution across complex organizational processes.
We recognize that technological transitions create both opportunity and risk. Competitive dynamics may shift as new approaches emerge and customer preferences evolve. However, we believe our established customer relationships, platform investments, and operational experience in workflow orchestration and systems integration provide meaningful advantages as enterprises navigate this transformation. Our strategy focuses on continuing to understand and meet customer needs as they adopt AI technologies, applying our ability to deliver integrated solutions that address the practical complexities of converting AI-generated insights into controlled, governed business outcomes.
| 2 | ![]() |
Part I
Our Platform
The ServiceNow AI Platform (our “Platform”) connects people, processes and data to break down silos and simplify complex business processes, increasing flexibility, scalability and extensibility. Our one platform architecture provides the foundation for organizations to seamlessly integrate AI, data, and workflows and create intelligent processes across their enterprise.
AI. Our Platform’s integrated AI offering, Now Assist, empowers organizations to boost productivity by providing a range of AI tools. These tools operate autonomously with human oversight and adhere to predefined guardrails. Organizations can select the tools that best align with their unique AI transformation needs. To illustrate, organizations can choose to leverage ServiceNow’s language models or integrate third-party or proprietary models. Depending on the selected model, they can process different types of data, such as text, images, audio and video. They can also trust that the selected models are tested to confirm they will perform as intended on our Platform, as all integrated models are regularly evaluated on Platform-representative data. Additionally, organizations can choose to rapidly deploy thousands of out-of-the-box ServiceNow AI agents, integrate AI agents built into third-party applications, or create custom AI agents on our Platform using natural language. These options allow for flexible AI agent workflow orchestration in a wide range of use cases, making AI agents accessible to users with varying technical expertise. AI agents developed using our solutions follow a human-in-the-loop governance model. This allows developers to retain control of application changes while benefiting from AI assistance. We also offer governance tools designed to help manage these AI agents and other AI-powered products. Our AI governance tools include integrated monitoring and guardrails, as well as dataset creation management, benchmarking and performance analytics capabilities. They offer organizations greater visibility into their AI adoption, usage and performance. These tools provide organizations confidence that they are building, testing and deploying AI use cases and applications responsibly as they operationalize their AI strategy.
Data. Our Platform’s single data fabric and integrated data layer, enabled by our Workflow Data Fabric and RaptorDB products, supports organizations’ operationalization of their AI strategy with speed, scale and security. Our data fabric’s architecture also provides our Platform flexibility to create intuitive, efficient and seamless workflows aligned with business needs. For example, our Platform’s data fabric can connect to external data sources in real-time without moving or copying data from its source and map those connections to its single data model, which creates a seamless user experience. AI-enabled tools for the data layer can also help deliver precise, context-aware insights by linking people, processes and systems. By connecting a wide variety of data and systems, our Platform enables a single process flow across people and functions. These capabilities allow the front, middle and back offices to coordinate and address end user requests quickly and effectively.
Workflows. Through its orchestration capabilities, our Platform manages complex, cross-functional workflows end-to-end. For example, an organization’s entire employee onboarding workflow, which spans across both internal and external functions, can be managed by our Platform. AI agents can autonomously trigger information technology (“IT”) provisioning, payroll setup, compliance checks and facilities access – coordinating tasks, monitoring progress and resolving exceptions without human intervention, if desired. Because our AI agents can access required information and understand the context of requests in a single environment, employees can complete their onboarding without contacting multiple departments. Additionally, with our acquisition of Moveworks, Inc. we have strengthened our enterprise workflow automation on our Platform by integrating advanced enterprise search and front-end virtual agent technology. The advanced machine learning, conversational interface, natural language comprehension and broad integration capabilities of this technology help organizations and their employees handle service requests automatically, retrieve information quickly using AI, and complete tasks across diverse business applications, enhancing overall workflow experience.
Together, these AI, data and workflow capabilities support our broad portfolio of products on our Platform.
| 2025 Annual Report | 3 |
Part I
Our Products
Our products are grouped into four areas: Technology, Customer Relationship Management (“CRM”) and Industry, Core Business, and Creator and Other. We release two major Platform upgrades each year, adding new products and functionality that simplify work and enhance productivity.
| Technology | Core Business | ||||||||||||||||
| Our Technology products help companies unite technology, risk management and security operations on a single platform to deliver modern and resilient digital services aligned to an organization’s priorities. | Our Core Business products support processes across HR, legal, finance, supply chain and facilities, helping organizations improve productivity, increase employee satisfaction and fuel business growth. | ||||||||||||||||
![]() | |||||||||||||||||
| CRM and Industry | Creator and Other | ||||||||||||||||
| Our CRM and Industry products help organizations integrate front-end customer service functions with operations, field service resources, sales processes and order management, and provide workflows tailored for specific industries. | Our Creator and Other products help organizations rapidly develop and manage cross-enterprise workflows using AI-powered, low-code development tools, as well as manage data privacy and security. |
| 4 | ![]() |
Part I

Our Technology products help IT departments serve customers, manage IT infrastructure, identify and remediate security vulnerabilities and threats, increase visibility across IT resources and asset lifecycles, optimize IT costs and reduce time spent on administrative tasks. These products also drive enterprise-wide outcomes, as well as support our CRM and Industry and Core Business products. For example, a global energy company implemented a suite of our Technology products, including IT Operations Management (“ITOM”), IT Service Management (“ITSM”), and Risk Management (“RM”), along with Now Assist, to consolidate multiple employee portals into a single AI-powered portal serving over 50,000 employees in more than 10 languages. The solution saved the customer thousands of working hours, resulting in a substantial and immediate reduction in service desk requests.
Asset Management
Asset Management products include IT Asset Management and Enterprise Asset Management. IT Asset Management helps manage the lifecycle of software, hardware and cloud-based IT assets. It is commonly used for software audits, cloud financial operations and hardware inventory processes. Similarly, Enterprise Asset Management helps manage the lifecycle of physical business assets. It helps organizations manage asset planning, deployment, maintenance and retirement. Both products offer comprehensive analytics regarding the financial, contractual and inventory aspects of an organization’s assets.
Now Assist and AI agents for Asset Management help summarize software compliance requirements and recommend actions to avoid potential costs based on software utilization information. For physical business assets, these tools can identify and locate items to fulfill requests, automate approval decisions where desired and execute asset transfers or orders.
| 2025 Annual Report | 5 |
Part I
IT Operations Management
IT Operations Management, or ITOM, identifies, monitors and manages a customer’s physical and cloud-based IT infrastructure. It can simultaneously identify issues from a customer’s IT infrastructure (e.g., physical servers) and digital components (e.g., email), which helps organizations better manage potential disruptions to business services. ITOM also maintains a single record of all IT configurable items, providing organizations better control over on-premises or cloud-based infrastructures while orchestrating key processes and tasks.
Now Assist and AI agents for ITOM simplify complex technical language into easy-to-understand descriptions and provide quick resolution recommendations to IT operations issues. When integrated with our other products such as IT Service Management, ITOM AI agents can help support an organization’s goals to achieve autonomous IT management to help reduce the risk of outages, improve productivity and enhance service reliability.
IT Service Management
IT Service Management, or ITSM, provides predictive intelligence, incident management and response, routine task and request automation, performance analytics and process optimization. ITSM’s real-time tracking and validation enable quick, controlled IT service deployment for change management, development and operations, which helps organizations manage their IT risk and regulatory requirements. ITSM also includes integrated knowledge management and collaboration tools to streamline issue resolution. By adopting ITSM, organizations can optimize their IT operations, reduce downtime, mitigate risks and drive down costs, with an aim to improve employee and customer experiences.
Now Assist and AI agents for ITSM can help automate incident triage, generate summaries and provide intelligent resolution recommendations. These tools reduce routine work for IT staff, allowing them to focus on higher-value activities.
Operational Technology Management
Operational Technology (“OT”) Management products provide visibility and context into technology assets used for operational purposes and devices connected to those assets. They help organizations with OT vulnerability management, issue resolution and lifecycle management. For example, when an OT issue is identified, it provides operators with the business context to assess its criticality and then triggers incident management, so the appropriate team can resolve it at the right time.
Now Assist for OT Management can summarize incident history to support faster resolution. After incident closure, these tools can also generate solution notes or knowledge-based articles to help reduce administrative work and capture resolution steps for future use.
Risk Management
Risk Management, or RM, products, formerly known as Integrated Risk Management, provide capabilities to manage enterprise-wide risks, including those related to compliance, operational resilience, cyber, technology, business continuity, corporate sustainability, privacy and reliance on third parties. RM products also include the AI Control Tower, a dashboard designed to offer organizations a comprehensive view of their AI governance status. This tool delivers insight into an organization’s compliance metrics, risk scores, and performance data, enabling effective monitoring and optimization of AI workflows. These solutions integrate risk management and compliance into daily operations, helping provide real-time visibility, quick issue resolution and resilient risk administration.
| 6 | ![]() |
Part I
Now Assist and AI agents for RM can be configured by a customer to summarize issue and risk assessments, rationalize control objectives, identify control gaps and map regulations to an organization’s controls. These tools can also analyze historical data to identify similar issues, recommend actions and assign owners. They help improve an organization’s ability to respond and address potential threats before they escalate, making risk and compliance operations more efficient and effective.
Security Operations
Security Operations products help organizations address security incidents and vulnerabilities. By identifying and prioritizing threats based on their potential impact and integrating both internal and third-party security and vulnerability data, these products can provide an organization’s security function greater visibility and control of potential threats. These capabilities help simplify and automate threat and vulnerability management, making responses more efficient and helping organizations reduce risks.
Now Assist and AI agents for Security Operations allows security analysts to use natural language to interact with AI agents. These tools provide context-aware insights and targeted recommendations to support security incident resolution, vulnerability assessments, and security operations metric analysis. They help improve productivity, accelerate issue resolution and offer security leaders enhanced visibility into their organization’s security posture and performance.
Strategic Portfolio Management
Strategic Portfolio Management (“SPM”) helps organizations plan, visualize and track value realization across their portfolio of projects, initiatives and digital assets. It helps organizations align their strategy with their investments and operations to drive desired outcomes.
Now Assist and AI agents for SPM help replace cumbersome intake forms with a conversational interface that intelligently summarizes business demands, documents and feedback from stakeholders and turn them into actionable insights. These tools allow organizations to uncover and prioritize tasks that can accelerate strategy and realization of value on their investments.
| 2025 Annual Report | 7 |
Part I

Our CRM and Industry products go beyond traditional CRM by orchestrating end-to-end workflows across front, middle and back-office functions. These products help manage customer interactions from initial quote to deal closure, while also supporting order fulfillment, case management and resolution. Customer representatives and technicians can resolve issues efficiently, while sales teams can manage quoting and deal closure on the same platform. By removing barriers between teams and supporting end-to-end customer service workflows, ServiceNow’s CRM and Industry products help organizations improve customer retention, strengthen loyalty, shorten sales cycles and reduce service delivery costs. These products help organizations provide service through multiple customer channels, deliver proactive support and streamline sales and service processes. As an example, a major digital sports entertainment platform implemented Customer Service Management (“CSM”) with Now Assist to efficiently manage large volumes of customer requests and tailor experiences for customers by categorizing and routing requests based on customer-specific factors. Streamlining these processes reduced response and resolution times, saving their employees tens of thousands of hours annually.
Customer Service Management
Customer Service Management, or CSM, provides customer self-service support across channels, centralizes customer interactions, and directs requests to the appropriate customer representative, all within a unified workspace. It automates complex processes across functions to improve resolution times. CSM enhances customer experience with automated routing, tailored self-service options, and by equipping customer representatives relevant information to resolve issues effectively. It also helps identify and address bottlenecks that may delay service. These capabilities enable organizations to reduce resolution times, increase customer satisfaction and lower operating costs.
Now Assist and AI agents for CSM provide additional efficiency by summarizing cases, chats and calls, suggesting resolution steps, drafting customer communications and generating case closure notes. These tools help shorten time to resolution, reduce case and call volumes and personalize service delivery.
| 8 | ![]() |
Part I
Field Service Management
Field Service Management (“FSM”) manages planning, scheduling and execution of field service work, allowing technicians to be dispatched through the same platform that manages customer cases. It provides automated workflows to help optimize resource allocation, increase technician productivity and improve first-time resolution rates. It also provides data-driven insights to help organizations monitor field operations, identify service bottlenecks and improve efficiency of field operations.
Now Assist and AI agents for FSM supports intuitive mobile workflows, automated note generation, multilingual knowledge creation and intelligent task generation, extending FSM capabilities. These tools help field teams complete jobs more efficiently, document work more accurately and improve overall service delivery.
Sales and Order Management
Sales and Order Management ("SOM") products help organizations manage sales leads and opportunities, configure quotes for complex deals and automate order delivery and fulfillment on our single, unified platform. SOM products include a configure, price, quote solution that supports complex product offerings, enabling sales teams to estimate deal sizes and quickly generate quotes. Once deals close, SOM captures order details from multiple channels, manages fulfillment across systems and provides tools to help assess the risk of order delays and incomplete order fulfillment. Purchased products and services are visible on each customer's account record, allowing sales and service teams to coordinate customer support, identify additional sales opportunities and support customer retention.
Now Assist and AI agents for SOM help automate lead qualification, provide guidance on complex quote configuration and support issue diagnosis and resolution. These tools streamline routine tasks, increase sales and order fulfillment productivity and reduce time required to complete sales processes.
| 2025 Annual Report | 9 |
Part I
Industry
We provide solutions designed to address the requirements of specific industries, including financial services, healthcare and life sciences, manufacturing, public sector, retail, technology and telecommunications. These solutions can be enhanced by Now Assist and AI agents. We expect the number of industry-specific offerings to continue to expand to accommodate our customers’ needs.
Financial Services | Financial Services Operations helps banks and insurance institutions orchestrate work across departments, systems and third parties. These capabilities help reduce contact center volumes, accelerate employee productivity, support personalized service and manage regulatory compliance. | |||||||
Healthcare and Life Sciences | Healthcare and Life Sciences Service Management enables pharmaceutical companies, healthcare providers, and health plan payers. These capabilities help streamline operations, reduce inefficiencies, manage costs and support patient care while maintaining regulatory compliance. | |||||||
Manufacturing | Manufacturing Commercial Operations helps manufacturers automate sales, support and service processes, integrate order to cash and service operations. These capabilities improve issue resolution, claims processing and revenue generation workstreams. | |||||||
Public Sector | Public Sector Digital Services provides government organizations with tools to deliver services at scale. These tools help organizations improve employee productivity and support timely and consistent issue resolutions. | |||||||
Retail | Retail Service Management automates workflows to support retail customer care while Retail Operations simplifies store operations and provides headquarters visibility into store performance. Together, these solutions help improve operational efficiency and reduce costs. | |||||||
Technology | Technology Provider Service Management, combined with Sales and Order Management, helps technology providers manage sales, delivery, support and customer success across the customer lifecycle, from quote to deal closure. By automating workflows and connecting functions, these solutions help reduce costs and improve service delivery. | |||||||
Telecom | Telecom Service Management, Network Inventory Management and Telecom Service Operations Management, combined with Sales and Order Management, enables telecom service providers to manage customer service and infrastructure operations across front, middle and back-office functions. These tools help organizations accelerate revenue, reduce costs and improve service efficiency. | |||||||
| 10 | ![]() |
Part I

Our Core Business products support processes across human resources (“HR”), legal, finance, facilities, among others, connecting each of these functions with a single suite of products. These products help support employees to quickly access information they need to complete their tasks, provide business experts the relevant information and background they need to take action, and allow team leads to track performance and make process improvements. These products help improve efficiency and user experience by automating repetitive processes and providing transparency across functions. For example, a tax compliance software provider deployed a suite of Core Business products, which included HR Service Delivery (“HRSD”) and Workplace Service Delivery (“WSD”), together with Now Assist, to establish an integrated HR portal and automate routine HR requests. The solution significantly reduced the customer’s total HR case volume and helped resolve over half of their new HR cases within the same day, each day.
HR Service Delivery
HR Service Delivery, or HRSD, products help provide employees and HR teams with quick answers, targeted guidance and streamlined actions on our unified Platform, which also integrates seamlessly with other enterprise systems. HRSD automates routine HR tasks and supports processes such as onboarding, leave management, transfers, offboarding, service requests and career development. These capabilities allow employees to access information efficiently and help enable HR teams to shift focus from administrative tasks to strategic priorities. HRSD is designed to help provide clear guidance for employees and automate HR-related services, reducing costs for organizations.
Now Assist and AI agents for HRSD provide HR service representatives AI-generated case summaries and virtual agent support to resolve issues more efficiently. These tools provide employees conversational AI interactions online or over the phone, personalized answers to questions, and proactive reminders or prompts that help employees complete HR tasks.
| 2025 Annual Report | 11 |
Part I
Legal and Contract Operations
Legal and Contract Operations (“LCO”) products include Contract Management Pro and Legal Service Delivery, which supports contract management and legal request handling, respectively. Contract Management Pro is designed to work across contract types and departments, integrating with other ServiceNow products to connect legal, procurement, sales and related functions. These integrations help standardize processes, enhance visibility, improve collaboration and reduce contract review time. Legal Service Delivery is designed to centralize intake and tracking of legal matters through automated workflows, replacing fragmented email-based processes. LCO products can also automate responses to frequently asked questions and provide dashboards and reporting to help anticipate demand and allocate resources.
Now Assist and AI agents for LCO can detect non-standard contract language, recommend pre-approved clauses from a library of acceptable terms, glean contract termination and renewal data to support timely management of contract deadlines, and generate summaries of requests and matters. These tools are intended to improve accuracy, reduce risk and simplify tracking of legal work.
Source-to-Pay Operations
Source-to-Pay Operations (“SPO”) connects organizations’ existing enterprise resource planning and procurement systems to support purchasing, supplier management, performance monitoring and accounts payable processes. These capabilities allow organizations to manage costs, negotiate terms, and onboard suppliers quickly.
Now Assist and AI agents for SPO allow employees to initiate sourcing and procurement requests through conversational AI interactions, and AI agents can pre-fill request details and confirm whether requests comply with organizational spending policies and other protocols.
Workplace Service Delivery
Workplace Service Delivery, or WSD, provides tools for managing workplace services, facilities and real estate. WSD supports functions such as space planning and maintenance, visitor management and wayfinding. Integration with intelligent building systems enables improved space utilization and cost efficiency while maintaining safe and accessible work environments.
Now Assist and AI agents for WSD provides employees with a conversational AI interface to help them handle everyday tasks such as booking reservations, requesting workplace services or managing guest access, without having to navigate multiple systems.
| 12 | ![]() |
Part I

Our Creator products allow organizations to build and customize workflows at scale. These products provide developers with pre-built templates, low-code resources and modular components that support adaptation to changing processes and business models. Other products, such as Workflow Data Fabric, include capabilities for integrating internal and external data in a single, governed model with metadata management, data cataloging and contextual insights to support AI agents, automation and data-driven decision-making.
App Engine
App Engine enables organizations to create enterprise-class workflows using low-code and no-code development tools, supported by AI. App Engine does not require formal coding experience and is designed for scale, security and rapid deployment. Applications developed using App Engine include those that help:
-
streamline product development, including milestone tracking and real-time customer feedback collection;
-
automate loyalty programs, personalized marketing campaigns, and customer feedback collection, tailored to the retailer's brand and customer base;
-
manage supply chain logistics operations, including inventory control and logistics coordination tailored to supply chain networks; and
-
automate licensing, contracting and compliance examinations and financial reviews to reduce process times.
App Engine can also be used with Now Assist and AI agents for Creator to quickly create and scale apps on our Platform. Now Assist for Creator includes various natural language AI capabilities, including text-to-code, text-to-flow, text-to-service catalog and text-to-app. Organizations can select among LLMs to train these tools and align with their requirements, with models vetted for reliability and performance.
| 2025 Annual Report | 13 |
Part I
Platform Privacy and Security
Platform Privacy and Security products provide security, privacy and encryption controls to support protection of sensitive data in the cloud and compliance with applicable regulations. These products enable enforcement of data protection policies and rapid incident response.
Now Assist and AI agents for Platform Privacy and Security enhance these capabilities by auto-classifying data, providing real-time insights into user activity and risk and recommending or initiating protective actions through automated workflows.
RaptorDB
RaptorDB is our high-performance database built to manage workloads at scale. RaptorDB processes high volumes of workflow transactions with low latency and consistent throughput, reducing the need for separate data infrastructure supporting more efficient and scalable workflows. Together with Workflow Data Fabric, these products enable AI-ready data at scale, contextual intelligence and scalable automation across the enterprise.
Workflow Data Fabric
Workflow Data Fabric (“WDF”) provides organizations the ability to use and access a variety of data types—structured or unstructured, streaming or static—both within and outside our Platform. Built on the foundation laid by our legacy Automation Engine product, WDF supports data integrations with a large network of certified partners and a broad set of data integration capabilities, including connecting to real-time external data without copying or moving the data from its source. Additionally, WDF provides users of our Platform with an interface, known as a semantic layer, that helps users interpret and use data to complete tasks without requiring technical knowledge of underlying database structures. With these capabilities, WDF enables organizations to connect, understand and act on any data source, establishing a unified data foundation that supports AI agents, automation and analytics, all of which enhance workflow performance.
| 14 | ![]() |
Part I

We provide expertise to help organizations achieve operational and strategic objectives. Our customer success offerings support customers throughout their lifecycle, from initial adoption through long-term use of our Platform. These offerings include Customer Support, Professional Services and ServiceNow Impact. Together, they are intended to help customers improve efficiency, increase adoption and derive value from their investment in our Platform.
Customer Support
We provide customers with standard and enhanced support through subscription-based services delivered by technical resources located worldwide. Customers also have access to self-service resources through our support portal, which includes documentation, knowledge-based articles, online training, support forums and case creation tools.
Professional Services
Our professional services delivered directly and through our partners, include design, implementation, architecture and optimization services. These services are intended to help our customers implement and configure our products effectively and maximize the value from their use.
ServiceNow Impact
ServiceNow Impact is offered on a subscription basis and provides customers with software tools, guided plans, and AI-driven recommendations to support adoption of our products. The offering includes monitoring of Platform health, reporting on Platform metrics and access to designated experts and technical support.
| 2025 Annual Report | 15 |
Part I
Customers
We primarily sell our services to enterprise customers and support enterprise-wide deployments. As of December 31, 2025, we had approximately 8,700 customers across a wide variety of industries. A growing portion of our revenue is generated from sales to government customers. For additional information, see “Risk Factors—Doing business with the public sector and heavily-regulated entities subjects us to risks related to government procurement processes, regulations and contracting requirements.”
Sales and Marketing
We sell our products and services to enterprises across a wide variety of industries through subscription agreements facilitated by our global direct sales organization. In addition to subscription offerings, certain AI and data solutions include a consumption-based pricing component that governs when customer usage exceeds the fixed number of service credits available under the customer’s subscription agreement. We also sell through managed service providers and resale partners.
Our marketing activities consist primarily of customer referrals, digital advertising (including via our website), trade shows, industry events, brand campaigns and press releases. We also host our annual Knowledge user conference, webinars and other user forums, including regional forums, which we call World Forums, where customers and partners participate in sessions on product usage and industry practices.
We continue to invest in sales and marketing to increase market penetration and expand into new geographies. These efforts include growth in both direct and indirect sales channels, investments in professional services and customer support, and development of strategic partnerships.
Partner Ecosystem
We maintain a global network of partners that provide implementation services, industry expertise and complementary technology offerings. Our partner ecosystem includes organizations in our partner program, public cloud service providers, and strategic alliances, among others. Partners help us extend market reach, drive co-innovation, accelerate adoption of our solutions and support solutions tailored to specific industries and customer needs.
We have expanded relationships with technology providers to strengthen our AI capabilities and improve cloud interoperability, including relationships with AWS, Google, Microsoft, and NVIDIA, among others. Additionally, our relationships with global system integrators such as Accenture, Cognizant, Deloitte, EY, Infosys and KPMG, among others, continue to help us expand our business by offering ServiceNow solutions to their customers.
| 16 | ![]() |
Part I
Our Technology and Operations
We operate a multi-instance architecture that provides each customer with a dedicated application layer and database. This architecture is designed to support availability, scalability, performance, security and customer control. Our cloud infrastructure consists primarily of industry-standard servers, networks and storage components. We deliver our software-as-a-service offering through our own private cloud as well as public cloud service providers, who provide infrastructure-as-a-service, including servers, storage, databases and networking.
Our data centers, along with our environments hosted by public cloud service providers, have been configured in pairs to provide replication, redundancy and high availability. We currently operate data centers in North America, South America, Europe, Asia and Australia, and we regularly evaluate our data center operations and capacity needs in existing and new geographies. We also offer customers the option to deploy our services on dedicated hardware within our data centers.
In addition, our architecture supports deployment in customer-managed data centers or third-party data centers, which may be required to meet certain regulatory or security requirements. While these alternatives may have some limitations relative to our managed cloud and public cloud offerings, a minority of customers use them. We provide standard and enhanced support for these deployments consistent with the support provided to customers using our managed data centers.
Intellectual Property
We rely on a combination of U.S. and international copyright, trade secret, patent and trademark laws, as well as contractual agreements, confidentiality protections and internal procedures, to protect and expand our intellectual property (“IP”) rights. We enter into confidentiality and proprietary rights agreements with employees, partners, vendors, consultants and other third parties, and we limit access to our IP and other proprietary information. We also purchase or license IP and technology for incorporation into our products or services.
We continue to expand our global patent portfolio and other IP rights relevant to our business. Our ability to protect our core technology and IP is an important factor to our success. As of December 31, 2025, we had over 2,000 issued U.S. and foreign patents, including patents acquired from third parties, and had over 580 pending patent applications. We do not consider our business to be materially dependent on any single patent or group of related patents. For additional information, see “Risk Factors—We may not be able to protect or enforce our IP rights.”
Research and Development
Our research and development organization is responsible for the design, development, testing and validation of our solutions. We focus on creating new services and core technologies and enhancing the functionality, reliability and performance of existing solutions.
We also use our own products to collect real-time feedback on new and existing features – as part of what we call our “Now on Now” program – which informs product refinement and helps improve the customer experience. By incorporating insights from the Now on Now program and evaluating emerging technologies, we aim to anticipate customer needs and introduce new solutions-oriented features and services to the market quickly.
Additionally, we deploy our engineers to work directly with strategic customers through our Now Next AI program, where we co-build agentic AI solutions to solve their critical challenges, while simultaneously expanding our AI product capabilities and use cases.
We have made, and expect to continue to make, significant investments in research and development to expand our Platform capabilities, strengthen existing applications, increase the number of applications on our platform, and advance mobile, automation, AI and machine intelligence technologies.
| 2025 Annual Report | 17 |
Part I
Acquisitions and Investments
We have acquired and invested in companies and technologies as part of our business strategy and expect to continue to evaluate and enter into potential strategic transactions. These may include acquisitions of, or investments in, businesses, technologies, services, products and other assets. These transactions are intended to expand or improve our service offerings, enhance go-to-market and sales efforts, strengthen operations, increase access to expertise and support delivery of products and services to international markets.
Competition
We operate in a highly competitive and rapidly evolving market characterized by fragmentation, low barriers to entry, shifting customer needs and frequent introductions of new products and services. As our business expands and the industries in which we operate continue to evolve, we compete with a broad range of solutions and alternative approaches, including:
-
enterprise application software vendors, both cloud-based and on-premises, such as Microsoft, Oracle, SAP, Salesforce and Workday;
-
new technologies and entrants, including point-solutions and platform solutions, particularly those related to AI;
-
custom-developed and in-house solutions;
-
technology consulting firms;
-
systems integrators; and
-
software resellers.
For additional information about competition, see “Risk Factors—A failure to innovate and adapt how we offer our products in response to rapidly evolving technological changes and in the midst of an intensely competitive market may harm our competitive position and business prospects.”
Regulations
We conduct business globally and are subject to a wide range of U.S. federal, state and foreign laws and regulations across a variety of subject matters. The Risk Factors section of this Annual Report on Form 10-K includes additional information regarding government regulations relevant to our business.
| 18 | ![]() |
Part I
Our Ambition, Values and Corporate Purpose
Our ambition to become the defining AI enterprise software company of the 21st century is the driving force behind our overall business strategy and is guided by our values:
![]() | ||||||||||||||||||||||||||||||||||||||
![]() | ![]() | ![]() | ![]() | |||||||||||||||||||||||||||||||||||
| Customers are the center of our world. We strive to deliver the best customer experiences and innovations. | We share the same goals and have clear roles in achieving them. We deliver results as a team and enjoy the journey. | We do not take success for granted. We are always ready to learn and evolve. We grow together, bringing fresh ideas and new perspectives. | We lead with empathy, which means listening and making everyone feel they belong with ServiceNow. | |||||||||||||||||||||||||||||||||||
Our values have remained consistent as our business and workforce have expanded. By prioritizing these values, we seek to build trust with employees and customers and align with our corporate purpose to “make the world work better for everyone.”
| 2025 Annual Report | 19 |
Part I
Human Capital Management
Our People Pact
Our People Pact is central to our ability to fulfill our corporate purpose and reflects our commitment to supporting one another in doing our best work and achieving our shared objectives. To deliver on this commitment, we follow a global people strategy that serves as the foundation for how we plan and deliver on employee programming and experiences, built on three principles:
| People Led | Data Driven | AI Powered | ||||||||||||||||||||||||||||||
![]() | ![]() | ![]() | ||||||||||||||||||||||||||||||
| We apply a product mindset that puts the user at the center of program, process and service design. | We use data to promote accountability, tell meaningful talent stories and support evidence-based decision-making. | We use AI in talent management to enhance efficiency, while supporting, not replacing, human contributions. | ||||||||||||||||||||||||||||||
Our culture is grounded in our values. We gather feedback regularly and use this input to shape programs and address workforce needs globally. Our Employee Voice Survey (“EVS”) measures engagement across areas including belonging, learning and development, recognition, compensation and wellbeing. Insights from our EVS are used to create action plans throughout the organization and to assess the alignment of our human capital management practices with our purpose and business strategy.
Learning and Development
In 2025, we launched ServiceNow University, our AI-powered learning hub that provides professional development tools and resources to strengthen learners’ technical AI skills, industry knowledge and leadership capabilities, among others. It is free and available to organizations and individuals throughout the entire ServiceNow ecosystem—employees, customers and partners. ServiceNow University also supports our upskilling initiative, RiseUp with ServiceNow, which provides training and opportunities for individuals without traditional technology backgrounds to pursue technology careers and helps address talent needs across our ecosystem.
Total Rewards
We provide a total rewards program intended to attract, retain and motivate employees. All our employees are eligible to participate in our annual cash bonus plan or, for those in quota-carrying roles, our sales commission plan, in addition to base salary. We also have a broad-based discretionary equity incentive program and an employee stock purchase plan, which enable employees to share in our success.
Our benefits and wellbeing programs address physical, emotional, social and financial wellbeing. We also provide additional time away through “Wellbeing Days” to support employee health and wellbeing.
| 20 | ![]() |
Part I
Workforce Metrics
As of December 31, 2025, we employed:
![]() | ![]() | ![]() | ||||||||||||||||||||||||||||||
| 29,187 EMPLOYEES on a full-time basis | 14,601 of whom are in the United States | 14,586 of whom are international | ||||||||||||||||||||||||||||||
None of our U.S. employees are represented by a labor union. In certain countries, employees are represented by workers’ councils or employee representatives or have the benefits of collective bargaining arrangements at the national and/or sector level. We have not experienced interruptions of operations or work stoppages due to labor disagreements.
Available Information
You can obtain copies of our Annual Report on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, and other filings with the SEC, and all amendments to these filings, free of charge through our website at www.servicenow.com/company/investor-relations/sec-filings.html as soon as reasonably practicable after we file or furnish them with the SEC. The SEC maintains a website at www.sec.gov that contains reports, proxy and information statements and other information regarding issuers that file electronically with the SEC. The contents of, or information accessible through, these websites are not incorporated into this filing. Our references to the URLs for these websites are intended to be inactive textual references only.
Investors and others should note that we announce material financial information through our investor relations website (https://www.servicenow.com/company/investor-relations.html), SEC filings, press releases, public conference calls, webcasts and social media. We use these channels, including our website and social media, to communicate with our investors and the public about our company, our products and solutions and other issues. It is possible that the information we post on social media could be deemed to be material information. Therefore, we encourage investors, the media and others interested in our company to review the information we make available on our website and the social media channels listed there.
| 2025 Annual Report | 21 |
Part I
| Item 1A. Risk Factors | ||
Investing in our securities involves risks. You should carefully consider the risks and uncertainties described below, together with the other information in this Annual Report on Form 10-K, before making an investment decision. The occurrence of any of the following risks, or additional risks and uncertainties not presently known to us or that we currently believe to be immaterial, could materially and adversely affect our business, financial condition, results of operations, stock price or reputation. The following risks have been grouped by categories and are not in order of significance or probability of occurrence.
Risk Factors Summary
This summary provides an overview of the risks we face and should not be considered a substitute for the more fulsome risk factors discussed immediately following this summary.
Risks Related to Our Ability to Grow Our Business
-
Laws, regulations and customer expectations regarding the use, storage and movement of data may restrict our ability to continue to optimize our platform.
-
A failure to innovate and adapt how we offer our products in response to rapidly evolving technological changes and in the midst of an intensely competitive market may harm our competitive position and business prospects.
-
We may not successfully increase our penetration of international markets or manage risks associated with foreign markets.
-
Incorporating AI technology into our offerings may result in operational, legal, regulatory, ethical and other challenges.
-
We rely on our network of partners for an increasing portion of our revenues, and if these partners fail to perform, our business may be harmed.
-
Doing business with the public sector and heavily-regulated entities subjects us to risks related to government procurement processes, regulations and contracting requirements.
-
If we fail to comply with applicable anti-corruption and anti-bribery laws, export control laws, economic and trade sanctions laws, or other global trade laws, we could be subject to penalties and civil and/or criminal sanctions and our business could be materially adversely affected.
-
Our customer deals are becoming more complex, which tend to involve longer, more expensive sales cycles, increased pricing pressure, and implementation and configuration challenges.
-
As we acquire or invest in companies and technologies, we may not realize the expected business or financial benefits and the acquisitions and investments may divert our management’s attention and result in additional shareholder dilution or costs.
Risks Related to the Operation of Our Business
-
Actual or perceived cybersecurity events experienced by us or our third-party service providers may create the perception that our platform is not secure, and we may lose customers or incur significant liabilities.
-
We may lose key members of our management team or qualified employees or may not be able to attract and retain employees we need.
| 22 | ![]() |
Part I
-
Delays in the release of, or actual or perceived defects in, our products may slow the adoption of our latest technologies, reduce our ability to efficiently provide services, decrease customer satisfaction and adversely impact future product sales.
-
Disruptions or defects in our services could damage our customers’ businesses, subject us to substantial liability and harm our business.
-
Delays in improving our information systems and processes could interfere with our ability to support our existing and growing base of customers and employees as we scale.
-
We may not be able to protect or enforce our IP rights.
-
Our use of open-source software could harm our ability to sell our products and services and subject us to possible litigation.
-
Various factors, including our customers’ business, integration, migration, compliance and security requirements or errors by us, our partners or our customers, may cause implementations of our products to be delayed, inefficient or otherwise unsuccessful.
-
Our failure or perceived failure to achieve our corporate sustainability goals or maintain corporate sustainability practices that meet evolving stakeholder expectations could adversely affect us.
-
We may face natural disasters, including climate change, and other events beyond our control.
Risks Related to the Financial Performance or Financial Position of Our Business
-
Because we generally recognize revenues from our subscription services over the subscription term, a decrease in new subscriptions or renewals may not be immediately reflected in our operating results.
-
As our business grows, we expect our revenue growth rate to decline over the long term.
-
Changes in our effective tax rate or disallowance of our tax positions may adversely affect our business.
-
We may be adversely affected by our debt service obligations.
Risks Related to General Economic Conditions
-
Our industry and business may be harmed by global economic conditions.
-
We may be harmed by foreign currency exchange rate fluctuations.
Risks Related to Ownership of Our Common Stock
-
Our stock price is likely to continue to be volatile.
-
Provisions in our governing documents or Delaware law might discourage, delay or prevent a change of control or changes in our management and, therefore, depress our stock price.
Risks Related to Our Ability to Grow Our Business
Laws, regulations and customer expectations regarding the use, storage and movement of data may restrict our ability to continue to optimize our platform.
Governments have adopted, and likely will continue to adopt, laws and regulations affecting the use, storage and movement of data, including laws related to data privacy and security, the use of machine learning and AI, and data sovereignty or residency requirements. Changing laws, regulations and standards applying to the collection, storage, use, sharing, portability, transfer or other control or processing of data, including personal data, could affect our ability to efficiently and cost-effectively offer our services and to develop our products and services for maximum utility, as well as our customers’ ability to use data or share data. Such changes may restrict our ability
| 2025 Annual Report | 23 |
Part I
to use, store or otherwise process customer data in connection with providing services and could alter or increase our compliance requirements. In some cases, this could impact our ability to offer our services in certain locations or our customers’ ability to deploy our services globally. For example, the EU Data Act has data portability, interoperability and accessibility requirements, as well as unclear data transfer restrictions that could impact our operations. In addition, the Trans-Atlantic Data Privacy Framework, which facilitates the transfer of data between the United States (“U.S.”) and European Union (“EU”), may be subject to legal challenges and regulatory interpretations that could create uncertainties and impact our operations and compliance obligations.
We offer some region-specific services where customer data is hosted locally and customers may elect to receive support from locally-based ServiceNow teams. Setting up and maintaining these region-specific services require significant investment, including to comply with applicable laws and regulations. Actual or perceived non-compliance with those laws, regulations, or the terms of our region-specific service offerings may result in investigations or proceedings against us by regulatory authorities or others, significant fines or damages, orders, litigation, reputational harm and other adverse impacts on our business.
We will also need to continually adapt to customer privacy and security requirements as they change over time. For example, as customers increasingly adopt a hybrid (on-premises and off-premises/hyperscale cloud) approach for their IT workloads, our cloud services may fail to address evolving customer requirements, including data localization. Further, due to heightened concerns relating to privacy and security regulatory matters, our customers from time to time request certain certifications, and a failure to obtain or consistently maintain those certifications may adversely impact our reputation and business.
A failure to innovate and adapt how we offer our products in response to rapidly evolving technological changes and in the midst of an intensely competitive market may harm our competitive position and business prospects.
We compete in markets that evolve rapidly. The pace of innovation will continue to accelerate as customers recognize the advantages of acquiring leading digital technologies and adopting AI native solutions and modern cloud-based infrastructure. Cutting-edge capabilities such as AI, machine learning, hyper automation, low-code/no-code application development, system observability and predictive insights become increasingly relevant to the customer’s evolving needs. With this rapid evolution, we are increasingly competing with alternative solutions and approaches to solve customer needs, and we expect additional competition as we shift our products and services to compete with providers in new and adjacent markets.
Competitors, regardless of their size, may be able to respond more quickly and effectively to new or changing opportunities, technologies, standards, customer requirements and buying practices. They may introduce new technology, solve similar problems in different ways or more effectively utilize existing technology that reduces demand for our services. They may utilize acquisitions, integrations or consolidations to offer integrated or bundled products, enhanced functionality or other advantages. Some of our existing competitors and potential competitors are larger and have greater name recognition, the ability to more efficiently scale their business, more established operations and customer relationships and greater financial and technical resources than we do. “Systems of record” operators may attempt to create technology solutions or other mechanisms that would prevent our systems from integrating with theirs. They may create pricing pressures by reducing the price of competing products, services or subscriptions or bundling their offerings, causing our offerings to appear relatively more expensive. Companies whose products are integrated with our Platform could also seek to compete with us by blocking, limiting or imposing fees on particular integrations or data access. Cloud-based and AI native vendors may build more business applications or AI powered automation solutions that compete with our products and services. We may also encounter customer reluctance or unwillingness to migrate away from their current solutions.
| 24 | ![]() |
Part I
If we are not able to compete successfully, we could experience reduced sales and margins, losses or failure of our products to achieve or maintain market acceptance. Accordingly, to compete effectively, we must:
-
identify and innovate in the right technologies;
-
keep pace with rapidly changing technological developments, such as AI, which may disrupt resource and talent needs and the enterprise software marketplace;
-
accurately predict and meet our customers’ changing digital transformation needs, priorities and adoption practices, including their technology infrastructures and buying and budgetary practices;
-
invest in and continually optimize our own technology platform so that we continue to meet the high-performance expectations of our customers;
-
successfully deliver and promote new, scalable technologies and products, such as AI, to meet customer needs and priorities;
-
efficiently integrate with technologies within our customers’ digital environments;
-
expand our offerings into new and adjacent industries and comply with regulations in such industries;
-
successfully sell to buyers who are not familiar with our offerings;
-
profitably and efficiently market and sell our new and existing products;
-
effectively scale our business processes and operations as we grow;
-
successfully adapt new pricing models;
-
promote ongoing customer relationships and customer value realization;
-
effectively secure our platform, data and customers’ data; and
-
effectively deliver, directly or through our partner ecosystem, the digital transformation process planning, IT systems architecture planning, and product implementation services that our customers require to be successful.
Further, to remain competitive, we may make significant investments in changing how we offer our products or services. These changes could include, among others, bundling certain products and services, modifying service delivery methods, or altering pricing models, such as incorporating more consumption-based pricing components into our offerings. However, customers may not be satisfied with these changes, and, as a result, we may not recover the cost or realize the anticipated benefits of our investments. With respect to service delivery methods, we entered into agreements with public cloud service providers to achieve greater operational and financial efficiencies. Our strategy of migrating an increasing portion of Company hosted instances to these providers depends on our ability to adequately prepare our operations to facilitate the migration, our customers’ willingness to use public cloud services to host their instances, and customer demand not materially falling short of our commitments with the public cloud service providers.
We may not successfully increase our penetration of international markets or manage risks associated with foreign markets.
Sales outside of North America represented 37% of our total revenues for each of the years ended December 31, 2025 and 2024. The growth of our business depends on our ability to increase our sales outside of the U.S. as a percentage of our total revenues. Additionally, operating in international markets requires significant investment and management attention and subjects us to varying regulatory, political and economic risks. We have made, and will continue to make, substantial investments in data centers, geographic-specific service delivery models, advisory councils, cloud computing infrastructure, sales, marketing, partnership arrangements, personnel and facilities in new geographic markets. When we make these investments, it is typically unclear when we will see a return on our investment, and we may significantly underestimate the level of investment and time required to be successful. Our rate of acquisition of new large enterprise customers, a factor affecting our growth, has been generally lower in territories where we are less established and where there may be heightened or evolving regulations and operational and IP risks. We have experienced and may continue to experience difficulties in new geographic markets, including hiring qualified sales management personnel, penetrating the target market and
| 2025 Annual Report | 25 |
Part I
managing local operations. Risks associated with making our products and services available in international markets include, for example:
-
compliance with multiple, conflicting and changing governmental laws and regulations, including antitrust and competition regulations;
-
requirements to have local partner(s), local entity ownership limitations or technology transfer or sharing requirements, or to comply with data residency and transfer laws and regulations, privacy and data protection laws and regulations, which may increase operational costs and restrictions;
-
the possibility that illegal or unethical activities of our local employees or business partners will be attributed to us or cause us harm;
-
longer and potentially more complex sales and payment receipt cycles and other collection difficulties;
-
different pricing and distribution environments;
-
potential changes in international trade policies, tariffs, agreements and practices, including the adoption and expansion of formal or informal trade restrictions or regulatory frameworks that may favor local companies;
-
governmental direction, business practices and/or cultural norms that may favor local companies;
-
more prevalent cybersecurity, IP and AI risks; and
-
localization of our services, including translation into foreign languages and associated expenses.
If we are unable to manage these risks, our business will be adversely affected.
Incorporating AI technology into our offerings may result in operational, legal, regulatory, ethical and other challenges.
We are increasingly innovating and expanding offerings on our platform by integrating AI technology into our customer-facing products and internal operations. We consider AI to be an important driver of future growth, although, like many innovations, it presents risks and uncertainties that may impact our ability to realize its desired or anticipated benefits for our business.
AI technology is evolving quickly. To remain competitive, we must make significant investments to continue to successfully develop and incorporate this technology into our products. Our ability to incorporate AI technology into our products depends on the availability, performance and pricing of third-party hardware and software equipment and technical infrastructure. Our competitors or other third parties may develop or incorporate AI into their products more quickly or successfully than us. They may also have or in the future obtain IP rights that would prevent, limit or interfere with our ability to make, use or sell our AI products. For these reasons, among others, we may not be able to compete effectively in the evolving AI market.
Our business model may be affected by global trends and laws that govern the use of AI. For example, the EU AI Act places new requirements on providers of AI technologies that will need to be addressed in alignment with various deadlines. These and other laws or regulations or enforcement practices may cause us to modify our data handling and compliance practices, which could be costly or disruptive to our operations, and may also impact our ability to use certain data to support our products or our product development efforts or hinder our customers’ ability to adopt or continue to use our products.
We may face new or heightened legal, ethical and other challenges arising out of the perceived or actual impact of AI on human rights, IP, privacy, security, employment and the environment, among other areas. For example, our use of AI, both internally and in our customer-facing products, could lead to copyright infringement claims or other IP claims, potentially requiring us to pay compensation or licensing fees to third parties. Additionally, social and ethical concerns surrounding the use of AI in our offerings could harm our brand and may cause us to incur additional costs. AI systems may not perform as intended or may produce outcomes, such as unreliable or biased results, that could negatively affect customer trust, result in limited adoption of our AI enabled products, expose us to reputational harm or create potential liability. Failure by us or others in our industry to adequately address these concerns could erode public confidence in AI and slow adoption of AI in our products.
| 26 | ![]() |
Part I
We rely on our network of partners for an increasing portion of our revenues, and if these partners fail to perform, our business may be harmed.
An increasing portion of our revenues is generated by sales through our network of partners, including resellers, distributors and managed service providers. Increasingly, we and our customers rely on our partners to provide professional services, including custom implementations, and there may be insufficient qualified implementation partners available to meet customer demand. While we provide our partners with training and programs, including accreditations and certifications, these programs may not be effective or utilized consistently by partners. New partners may also require extensive training and/or significant time and resources to become productive. Separately, our relationships with partners may require us, along with our partners, to comply with complex regulations, contractual requirements and government procurement rules. Failure to adhere to these requirements could result in the loss of business opportunities, potential liabilities or penalties. For example, our partners could misrepresent to our customers the functionality of our platform or products, fail to perform services that meet our customers’ expectations, or violate laws or our corporate policies. Further, changes to our direct go-to-market models may cause friction with our partners. Our partners may also use our platform to develop products and services that compete with our products and services, which could raise IP ownership concerns and strain these partnerships. If we fail to effectively manage and grow our network of partners, our ability to sell our products and efficiently provide our services may be impacted and our business may be harmed.
Doing business with the public sector and heavily-regulated entities subjects us to risks related to government procurement processes, regulations and contracting requirements.
We provide products and services to governmental and heavily-regulated entities directly and through our partners. We have made and may continue to make significant investments to support our efforts to sell to those entities. Processes to obtain authorizations and certifications required for us to provide our products and services to those entities often are lengthy and encounter delays, and we may not be able to satisfy, or maintain compliance with, the associated requirements.
A substantial majority of our sales to government entities in the U.S. have been made indirectly through our distributors, resellers or service provider partners. Doing business with government entities presents a variety of risks. The procurement process for governments and their agencies is highly competitive and time-consuming, may be subject to political influence and may involve different rules and conditions on the offering or pricing of products and services. We incur significant up-front time and expense without any assurance that we (or a third-party distributor, reseller or service provider) will win a contract. Beyond this, demand for our products and services may be adversely impacted by public sector budgetary cycles and funding availability that in any given fiscal cycle may be reduced or delayed, including in connection with an extended federal government shutdown, partisan gridlock or changes to government policy. Further, if we or our partners are successful in receiving a contract award, that award could be challenged during a bid protest process. Bid protests may result in an increase in expenses related to obtaining contract awards or an unfavorable modification or loss of an award. Even if a bid protest were unsuccessful, the delay in the startup and funding of the work under these contracts may cause our actual results to differ materially and adversely from those anticipated.
Our customers also include non-U.S. governments, to which government procurement risks similar to those present in U.S. government contracting and regulatory compliance also apply, particularly in certain emerging markets where our customer base is less established. Across the globe, we have seen political volatility increase, with rapid changes in governments and increased partisanship affecting many aspects of government, including the ability to approve budgets and make commitments. This can significantly delay or impair a government’s ability to contract for software and services such as ours. We have also seen challenges to successful awards through bid protest procedures in jurisdictions outside the U.S. As our non-U.S. government business grows, we may see an increase in bid protests as part of the standard government procurement legal procedures that exist in many jurisdictions. In addition, compliance with complex regulations and contracting provisions in a variety of jurisdictions can be expensive and consume significant management resources. In certain jurisdictions, our ability to win business may be constrained by political and other factors unrelated to our market offerings.
Our public sector customers may have contractual, statutory or regulatory rights to terminate current contracts with us or our third-party distributors or resellers for convenience or due to a default, though such risk may be
| 2025 Annual Report | 27 |
Part I
assumed by such third-party distributor or reseller. If a contract is terminated for convenience, we may only be able to collect fees for products or services delivered prior to termination and settlement expenses. If a contract is terminated due to a default, we may be liable for excess costs incurred by the customer for procuring alternative products or services. In addition, we could be precluded from doing further business with governmental entities. Further, we are required to comply with a variety of complex laws, regulations and contractual provisions relating to the formation, administration or performance of government contracts that give public sector customers substantial rights and remedies, many of which are not typically found in commercial contracts. These laws, regulations and contractual provisions may encompass rights with respect to price protection, refund and setoff, the provision of services in languages other than English, the accuracy of information provided to the government, contractor compliance with supplier diversity policies, constraints on certain business and sales practices, and other obligations that are particular to government contracts. These obligations may apply to us and/or our third-party resellers or distributors whose practices we may not control. Such parties’ non-compliance could create legal, contractual and customer satisfaction issues.
We and governments routinely investigate and audit compliance with contractual and regulatory requirements. For example, as disclosed in Note 18 “Commitments and Contingencies” in the notes to our consolidated financial statements, the Company informed certain U.S. government agencies of an internal investigation and preliminary findings and is cooperating with, among others, the Department of Justice, which commenced its own investigation into the matters. If it is determined that we or our third-party distributors, resellers or service providers have failed to comply with applicable contractual or regulatory requirements, we may be subject to civil and criminal penalties and administrative sanctions, including termination of contracts, forfeiture of profits, cost associated with the triggering of price reduction clauses, fines and suspensions or debarment from future government business, among others, all of which may adversely affect our business. In the United States, our federal business has been concentrated with a small number of third-party distributors, resellers or service providers. If one of those third parties is limited in its ability to do business with the government due to a regulatory or legal issue arising from their own conduct and we are not able to move our business to another third party, our business could be negatively impacted.
Further, we are increasingly doing business in heavily regulated industries, such as financial services, telecommunication, media and television and health care. Current and prospective customers in those industries may be required to comply with more stringent regulations to subscribe to and/or implement our services. In addition, regulatory agencies may impose requirements on third-party vendors that we may not meet. Customers in these heavily-regulated industries often have a right to conduct audits of our systems, products and practices and in some cases the regulators of customers in heavily-regulated industries may directly examine vendors that provide outsourced services to such customers. If one or more customers and/or regulators determine that some aspect of our business does not meet regulatory requirements, our ability to continue or expand our business with those customers may be restricted.
If we fail to comply with applicable anti-corruption and anti-bribery laws, export control laws, economic and trade sanctions laws, or other global trade laws, we could be subject to penalties and civil and/or criminal sanctions and our business could be materially adversely affected**.**
As we continue to expand our business internationally, we will inevitably do more business with large private enterprises and the public sector in countries outside of the U.S. Increased business in countries with heightened trade controls and levels of corruption subjects us and our officers and directors to increased scrutiny and potential liability. We have an established compliance program, but there is a risk that our employees, partners, vendors, customers and agents, as well as those companies to which we outsource certain of our business operations, could violate our policies and applicable law, exposing us to additional scrutiny and potential liability. We have experienced this in the past and may experience it again in the future. In addition, we are subject to customs laws that may impose tariffs on us, either directly or indirectly. This includes tariffs imposed by the U.S. government and other countries on imports, which we are responsible to pay in certain circumstances. Higher tariffs on imports related to our operations could increase our operating costs. We are also subject to global trade laws that apply to our worldwide operations, including prohibitions or restrictions on conducting business in certain geographies or involving certain counterparties, end-users or end-use cases. As a result of the Russia-Ukraine conflict, for example, the U.S. and other jurisdictions have imposed economic and trade sanctions and export control restrictions against Russia and Belarus, as well as certain persons, assets and interests associated with
| 28 | ![]() |
Part I
those countries. For so long as this conflict continues or if serious conflict arises elsewhere, the U.S. and other jurisdictions could impose wider economic and trade sanctions as well as export restrictions, which could impact our business opportunities and operations. Any violation of the U.S. Foreign Corrupt Practices Act of 1977, as amended, the UK Bribery Act, other applicable anti-corruption and anti-bribery laws, or applicable export control or economic and trade sanctions laws by our employees or third-party intermediaries could subject us to significant risks such as adverse media coverage and/or severe criminal or civil sanctions, which could materially adversely affect our reputation and business.
Our customer deals are becoming more complex, which tend to involve longer, more expensive sales cycles, increased pricing pressure, and implementation and configuration challenges.
The customer deals we pursue are becoming more complex as we engage with increasingly larger enterprise customers with multiple workflow products that span the enterprise. These deals can lead to increased costs, longer sales cycles, greater competition and less predictability in our ability to close sales. These customers tend to require considerable time evaluating our portfolio of products and testing our platform prior to making a purchasing decision, require multiple levels of review and approval from a broader set of buyers and stakeholders, and demand more configuration, integration services and features, particularly when switching from legacy on-premises solutions. As a result, these sales opportunities may require us to devote significant sales support and professional services to a smaller number of transactions, diverting those resources from other sales opportunities. If we fail to effectively manage these risks, our business may be negatively affected.
As we acquire or invest in companies and technologies, we may not realize the expected business or financial benefits and the acquisitions and investments may divert our management’s attention and result in additional shareholder dilution or costs.
We have acquired and invested in companies and technologies as part of our business strategy and will continue to evaluate and enter into potential strategic transactions, including, among other things, acquisitions of or investments in businesses, technologies, services, products and other assets. These transactions are intended to, among other things, expand or improve our service offerings and functionality, go-to-market and sales efforts, our operations or our ability to source necessary expertise and provide services in international locations. Although we conduct due diligence regarding these businesses and assets, our efforts may not reveal every material issue. Strategic transactions involve numerous risks, including:
-
difficulties assimilating or integrating the businesses, technologies, products, personnel or operations of the acquired companies;
-
failing to achieve the expected benefits of the acquisition or investment;
-
potential loss of employees of the acquired company;
-
inability to maintain relationships with customers, suppliers and partners of the acquired business;
-
introducing vulnerabilities or threats by integrating acquired technologies or businesses;
-
introducing increased complexity and burden to maintain the technology platform;
-
potential adverse tax consequences;
-
disruption to our business and diversion of management attention and other resources;
-
potential financial, credit or regulatory risks associated with acquiring a business or a part thereof, including risks of delayed, conditioned or denied regulatory clearances and risks relating to customers, suppliers and partners of the acquired business;
-
dependence on acquired technologies or licenses for which alternatives may not be available to us or which may involve significant cost or complexity;
-
in the case of foreign acquisitions, the challenges associated with integrating operations across different cultures, languages, legal regimes and any currency, tax and regulatory risks associated with specific countries;
-
data security or privacy risks, compliance requirements or integration costs from the acquired technology or company;
| 2025 Annual Report | 29 |
Part I
-
impairment of our investments or the possibility our investees will be unable to obtain future funding on favorable terms or at all; and
-
potential unknown liabilities or disputes associated with the acquired businesses.
In addition, the amount or form of consideration we pay for acquisitions could adversely affect our financial condition or stock price. For example, if we finance an acquisition by issuing equity or convertible debt securities or loans, our existing shareholders may be diluted or we could face constraints related to the terms of those securities or indebtedness.
Risks Related to the Operation of Our Business
Actual or perceived cybersecurity events experienced by us or our third-party service providers may create the perception that our platform is not secure, and we may lose customers or incur significant liabilities.
In the ordinary course of our business, we store, transmit, generate, and process our and our customers’ confidential, proprietary and sensitive data. As our business expands across the globe, the number of employees, contractors, vendors and other third parties remotely accessing our systems continues to grow. Our growing business operations increase our exposure to cyberattacks by a range of actors, who have used and will continue to use assorted tactics, techniques, and procedures, including malicious code, ransomware, social engineering, business email compromises, supply chain attacks, denial of service attacks and similar internet-enabled, fraudulent activity, and the frequency of those attacks have become more common. Additionally, as AI technologies continue to advance, threat actors can leverage these technologies to develop more sophisticated attack methods that are increasingly automated, targeted, coordinated and more difficult to defend against. The proliferation of these technologies could enable less skilled threat actors to initiate attacks and increase the frequency, scale and impact of security incidents. Further, during times of war and other major conflicts, we and our third-party providers may be vulnerable to a heightened risk of geopolitically motivated attacks, including cyberattacks, that could materially disrupt our systems and operations, supply chain and ability to provide our services.
Cybersecurity threats are not limited to actors operating in the systems we control directly. Our increasing reliance on third-party providers and public cloud infrastructure introduces new cybersecurity risks to our business operations. Third-party security incidents have occurred in the past and are likely to continue, as we rely on third-party service providers and technologies to operate business systems in a variety of contexts. Supply chain attacks have also increased in frequency and severity. We cannot guarantee that our third-party service providers or our supply chain infrastructure have not been compromised or that they do not contain exploitable defects or bugs that could result in a breach of or disruption to our platform, systems and network or the systems and networks of third parties that support us and our business. Our ability to monitor the data security measures of our third-party providers is limited, and we necessarily depend in part on our providers to have in place and maintain adequate security measures to protect against unauthorized access, cyberattacks and the mishandling of data. Further, employee error or malfeasance in configuring, maintaining and using these services could impact our ability to monitor and secure them effectively.
We have identified vulnerabilities in our products and services in the past and expect to continue to do so in the future. Consistent with our vulnerability management program, we prioritize security risks and consider their severity and potential impact in determining whether and when to remediate or mitigate them. In addition, we cannot be certain that we will be able to prevent, detect or remediate all vulnerabilities, and there have been delays and may continue to be delays in developing patches that can be effectively deployed to address vulnerabilities. Further, security researchers and other entities and individuals have actively searched for, published and/or exploited actual and potential vulnerabilities in our products or services and will likely continue to do so in the future. Also, certain persons, including researchers, have in the past not abided by, and may in the future not abide by, our responsible disclosure program, which has resulted in, and could in the future result in the compromise of our systems or our or our customers’ data. Moreover, the incorporation of third-party, AI-generated or open-source software code into our or our customers’ systems increases the risk of exploitation of
| 30 | ![]() |
Part I
vulnerabilities. We also have inherited and may in the future inherit additional security risks from acquiring or partnering with other companies.
In most instances, our customers are responsible for configuring and determining access levels to the data held in their particular instance for their employees and service providers. While our software is delivered with certain preset configurations, we understand that our customers require flexibility to configure the ServiceNow AI Platform to their specific business needs. We work closely with our customers to help them evaluate their security configurations, including providing guidance to align configuration settings with their business needs. Yet, in configuring our platform, both our employees and customers have made errors in the past and may do so again in the future. We are aware that, on occasion, both our customers and ServiceNow have configured certain settings on our platform, or retained preset configurations, in ways that may not align with preferred or recommended security levels, which can result in, and has resulted in, information being made more widely accessible than intended. Such misconfigurations can be, and have been, identified publicly, increasing the risk of data being exposed unintentionally. In certain cases, customers may misconfigure their systems and claim that they were not properly informed of the risks to their configuration.
Our data security system and data governance framework, designed to protect our and our customers’ information and prevent data loss, may not be effective at preventing, detecting, responding to or remediating material breaches caused by intentional or unintentional actions or inactions by employees, contractors or third parties. Techniques used to sabotage or to obtain unauthorized access to systems are constantly evolving and may go undetected until we become aware of a successful attack. Moreover, we have experienced security incidents, which may reoccur in the future, that resulted in unauthorized access to, loss or inadvertent disclosure of confidential, proprietary and sensitive information. We have observed attempts by third parties to induce or deceive our employees, contractors or users to fraudulently obtain access to our or our customers’ data or assets. In addition, our employees have fallen victim to phishing attacks in the past and are likely to again in the future. Further, despite our security measures, employees, contractors and other individuals (some of whom are supported by nation states) have gained, and in the future may gain, access to our systems to search for and exploit actual or potential vulnerabilities in our products or services or inflict other harms, such as deploying malware or stealing data.
An actual or perceived security breach or compromise can have a material effect on ServiceNow’s operations, finances and reputation. The adverse consequences can include accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to data; disruptions to our services; diversion of funds; litigation; indemnification and other contractual obligations; regulatory investigations; government fines and penalties; reputational damage; negative publicity; business and operational interruptions; loss of sales, customers and partners; mitigation and remediation expenses; and other material costs and liabilities. In addition, the assessment and response to security incidents, as well as implementation of appropriate safeguards to protect against future incidents, can lead to material economic and operational consequences. These consequences can result regardless of whether the incident is suffered by us, affects our third-party service providers or stems from customers’ action or inaction. Moreover, even if a breach is unrelated to our security programs or practices, it could still cause us reputational harm and require us to undertake significant efforts to assess and respond to the breach, including further protecting our customers from their own security risks. There can be no assurance that any limitations of liability provisions in our subscription agreements, terms of use or other agreements would be enforceable or adequate or would otherwise protect us from any such liabilities or damages with respect to any particular claim. In addition, while we maintain insurance coverage to cover potential financial losses, we cannot be certain that such coverage will continue to be available on acceptable terms or in sufficient amounts to cover potential financial losses from a security incident or that an insurer will not deny coverage as to any future claim.
We may lose key members of our management team or qualified employees or may not be able to attract and retain the employees we need.
There is increasingly intense competition for talent in the technology industry. Our success depends substantially upon the continued services of our management team, particularly our chief executive officer and the other members of our executive staff. From time to time in the ordinary course of business, there have been and may
| 2025 Annual Report | 31 |
Part I
continue to be changes in our management team. While we seek to manage these transitions carefully, such changes may result in a loss of institutional knowledge and negatively affect our business.
In the highly competitive technology industry, we face ongoing challenges in attracting and retaining top talent across various roles, such as product development and engineering (particularly with AI and machine learning backgrounds), sales, operations and cybersecurity. These key individual contributors are critical to our success, can command very significant compensation in the market and are actively recruited by our key competitors. Our ability to achieve significant revenue growth may depend on our success in recruiting, training and retaining sufficient qualified personnel to support our growth. We have faced and may continue to face difficulties attracting, hiring and retaining highly-skilled, qualified personnel and may not be able to fill positions in desired geographic areas or at all. Further, as we continue to grow and expand our workforce globally, we may face operational and workplace culture challenges that could negatively impact our ability to maintain the effectiveness of our business execution and the beneficial aspects of our corporate culture. While our work model, where a substantial portion of our employees work partially or fully remote, increased our access to talent, we may not be able to take advantage of a broader talent pool if our competitors offer the same work model or if we continue to rely on our primary operating locations for talent. We are continually evaluating and, as appropriate, enhancing the attractiveness of our compensation packages and benefit programs. As a result, we have experienced and may continue to experience increased costs that may not be offset by either improved productivity or higher sales, potentially resulting in a reduction in our profitability. In addition, we grant equity awards to our employees and sustained declines in our stock price or lower stock price performance relative to our competitors reduces the retention value of such awards, which can impact the attractiveness of our compensation. Many of our employees, including all of our executive officers, are employed “at-will” and may terminate their employment with us at any time. If we fail to attract qualified, new personnel or fail to retain and motivate our current personnel, our business and future growth prospects could be adversely affected.
Delays in the release of, or actual or perceived defects in, our products may slow the adoption of our latest technologies, reduce our ability to efficiently provide services, decrease customer satisfaction and adversely impact future product sales.
We must successfully continue to release new products and updates and features to existing products. The success of any release depends on a number of factors, including our ability to manage the risks associated with actual or perceived quality or other defects or deficiencies, delays in the timing of releases or the adoption of releases by customers, and other complications that may arise during the early stages of introducing our products. If releases are delayed or if customers perceive that our releases contain bugs or other defects or are difficult to implement, customer adoption of our new products or updates may be adversely impacted, customer satisfaction may decrease, our ability to efficiently provide our services may be reduced, and our growth prospects may be harmed.
Disruptions or defects in our services could damage our customers’ businesses, subject us to substantial liability and harm our business.
Our business depends on our platform to be available without disruption. From time to time, we have experienced and expect to continue to experience defects, disruptions, data loss, outages and other performance and quality problems with our platform. New defects may be detected in the future and may arise from our increasing use of public cloud service providers. For example, we provide regular updates to our services, which can contain undetected defects. Defects may also be introduced by our use of third-party software, including open-source software. Disruptions, data loss and service degradation may result from errors we make in developing, delivering, configuring or hosting our services, or designing, installing, expanding or maintaining our cloud infrastructure. They may also arise from incidents outside of our control, including third-party incidents, denial of service or ransomware attacks, as well as from our efforts to address vulnerabilities and security incidents. Although we currently serve our customers primarily using equipment managed by us and co-located in third-party data centers operated by several different providers worldwide, we expect to increasingly serve our customers using data center facilities operated by public cloud service providers. As our reliance on public cloud service providers increases, we face heightened risks of outages or performance degradation beyond our direct control. Similarly, supply chain issues or other incidents involving critical service providers could disrupt our operations or
| 32 | ![]() |
Part I
reduce our productivity. These data centers, whether managed by us or third parties, are vulnerable to damage or interruption from earthquakes, hurricanes, floods, fires, power failures and similar events. They may also be subject to break-ins, sabotage, intentional acts of vandalism and similar misconduct, equipment failure and adverse events caused by operator error or negligence. In addition, an increased use of public cloud service providers increases our vulnerability to cyberattacks. Despite precautions taken at these centers, problems at these centers have occurred, resulting in interruptions in our services. Such problems could occur again and result in similar or lengthier service interruptions and the loss of customer data. Furthermore, our customers may use our services in ways that cause disruptions in service for other customers.
We also have a large ecosystem of vendors and service providers that we use for our products, and a data compromise, supply chain issue or other incident involving a critical service provider could impact our ability to provide our services and reduce our productivity. Our customers use our services to manage important aspects of their businesses, and our reputation and business will be adversely affected if our customers and potential customers believe our services are unreliable. Disruptions or defects in our services may reduce our revenues, cause us to issue credits or pay penalties, subject us to claims and litigation, cause our customers to delay payment or terminate or decline to renew their subscriptions, and adversely affect our ability to attract new customers. Similarly, customers may have unique requirements for system resiliency and performance depending on their business models and customers in highly regulated markets may have more demanding requirements that we may not be able to, or may not choose to, meet. The occurrence of payment delays, service credit, warranty or termination for material breach or other claims against us could result in an increase in our bad debt expense, longer aggregate collection cycles, service level credit accruals and other expenses and a heightened risk of litigation. We may not have insurance sufficient to compensate us for potentially significant losses that may result from claims arising from disruptions to our services.
Delays in improving our information systems and processes could interfere with our ability to support our existing and growing base of customers and employees as we scale.
We rely on our information systems and those of third parties to operate and scale our business. As the information we rely on for our business evolves, including as a result of implementing AI technologies, our information systems, including their infrastructure needs, network capacity and computing power, may need to expand. We have made and continue to make investments to improve our information systems to support the needs of our growing base of customers and employees, increase productivity, develop and enhance our services, expand into new geographic areas, and scale with our overall growth. Such improvements are often complex, costly, time consuming, and may lead to impairments or write downs of existing technologies and other assets. If implementation of these improvements is delayed, or if we encounter unforeseen problems when migrating away from our existing systems and processes, our operations and our ability to manage our business could be negatively impacted. This might lead to disruptions to our operations, loss of customers, loss of revenue, or damage to our reputation, all of which could harm our business plan to successfully scale our operations and enhance productivity.
We may not be able to protect or enforce our IP rights.
Our success depends significantly on our ability to protect our proprietary technology and our brand under patent, copyright, trademark, trade secret and other IP protections in the U.S. and other jurisdictions. The IP protection we have for our technology may be insufficient, and any IP acquired in the future may not provide competitive advantages or other value. In addition, our IP may be contested, circumvented, found unenforceable or invalidated, and we may not be able to prevent third parties from infringing upon them. Further, legal standards relating to the validity, enforceability and scope of protection of IP rights vary.
Despite our efforts to protect our proprietary rights, policing unauthorized use of our IP and technology is difficult, and we may be required to spend significant resources to monitor and protect our IP rights. Unauthorized parties may attempt to copy or obtain and use, or may have copied or obtained and used, our technology to develop products and services that provide features and functionality similar to ours. Our competitors could also independently develop services equivalent to ours, and our IP rights may not be broad enough for us to prevent them from utilizing their developments to compete with us. Reverse engineering, unauthorized copying or other misappropriation of our proprietary technology could enable third parties to benefit from our technology without paying us for it. We may initiate claims or litigation against third parties for infringement or misappropriation of our
| 2025 Annual Report | 33 |
Part I
proprietary rights or to establish the validity of our proprietary rights. However, we may be adversely affected if we are unable to prevent third parties from infringing upon or misappropriating our IP rights or are required to incur substantial costs defending our IP rights.
Third parties may challenge or invalidate our IP rights through administrative proceedings, litigation or allowing contractual rights to expire. There is considerable patent and other IP development activity and claims and related litigation regarding patent and IP rights in our industry. Our competitors, other third parties, including practicing entities and non-practicing entities, own large numbers of patents, copyrights, trademarks and trade secrets, which they may use and have used to assert claims of infringement, misappropriation or other violations of IP rights against us. Moreover, the patent portfolios of many of our competitors and other third parties may be larger than ours. This disparity may increase the risk that our competitors or other third parties may sue us for patent infringement and may limit our ability to counterclaim for patent infringement or settle through patent cross-licenses. We have recorded material charges for legal settlements of such claims in the past. Further, upon expiration of any agreements that allow us to use third-party IP, we may be unable to renew such agreements on favorable terms, if at all, in which case we may face IP litigation or may need to cease offering or to modify our products and services to remove such components. In addition, our subscription agreements generally require us to defend our customers against claims that our technology infringes the IP rights of third parties.
Any claim or litigation, whether or not resolved in our favor, could result in significant expense to us, divert the efforts of our personnel and may result in counterclaims against us. If claims are successfully asserted against us and we are found to be infringing upon, misappropriating or otherwise violating the IP rights of others, we could be required to pay substantial damages and/or make substantial ongoing royalty payments; comply with an injunction and cease offering or modify our products and services; comply with other unfavorable terms, including settlement terms; and indemnify our customers and business partners, obtain costly licenses on their behalf and/or refund fees or other payments previously paid to us. Further, the mere existence of any lawsuit, or any interim or final outcomes, and the public statements related to it (or absence of such statements) by the press, analysts and litigants could be unsettling to our customers and prospective customers. This could adversely impact our customer satisfaction and related renewal rates, cause us to lose potential sales, and could also be unsettling to investors or prospective investors and cause a substantial decline in our stock price.
Effective patent, trademark, copyright and trade secret protection may not be available in every country in which we offer services. The laws of some foreign countries may not offer effective protection for, or be as protective of, IP rights as those in the U.S., and mechanisms for enforcement of IP rights or available remedies may be inadequate, ineffective or scarce. Additionally, the IP ownership and license rights of new technologies and the use of outputs therefrom, such as AI, which we are increasingly building into our product offerings, have not been fully addressed by U.S. and foreign courts interpreting current and new laws or regulations, and the use or adoption of such technologies in our products and services may expose us to potential IP claims; breach of a data license, software license, or website terms of service allegations; claimed violations of privacy rights; and other tort claims. If such laws or regulations require increased transparency, it may impair protection of our trade secrets or other IP.
| 34 | ![]() |
Part I
Our use of open-source software could harm our ability to sell our products and services and subject us to possible litigation.
Our products incorporate software licensed to us by third-party authors under open-source licenses, and we expect to continue to incorporate open-source software into our products and services in the future. Additionally, certain of our products may use or be developed with data sets subject to open-source licenses, which may contain restrictions on data set use. We monitor our use of open-source software and data sets to avoid subjecting our products and services to adverse licensing conditions. However, there can be no assurance that our efforts have been or will be successful. There is little or no legal precedent governing the interpretation of the terms of open-source licenses, and therefore the potential impact of these terms on our business is uncertain and enforcement of these terms may result in unanticipated obligations regarding our products and services. For example, depending on which open-source license governs certain open-source software included within our products and services, we may be subjected to conditions requiring us to offer our products and services to users at no cost; make available the source code for modifications and derivative works based upon, incorporating or using such open-source software; and license such modifications or derivative works under the terms of the particular open-source license. Moreover, if an author or other third party that distributes such open-source software were to allege that we had not complied with the conditions of one or more of these licenses, we could be required to incur significant legal costs defending ourselves against such allegations, be subject to significant damages or be enjoined from distributing our products and services.
Various factors, including our customers’ business, integration, migration, compliance and security requirements or errors by us, our partners or our customers, may cause implementations of our products to be delayed, inefficient or otherwise unsuccessful.
Our business depends upon the successful implementation of our products by our customers either through us or our partners. Further, our customers’ business, integration, migration, compliance and security requirements, or errors by us, our partners or our customers or other factors may cause implementations to be delayed, inefficient or otherwise unsuccessful. As a result of these and other risks, we or our customers may incur significant implementation costs in connection with the purchase, implementation and enablement of our products. Some customer implementations may take longer than planned, delay our ability to sell additional products or fail to meet our customers’ expectations, resulting in customers canceling or failing to renew their subscriptions before our products have been fully implemented. Some customers may lack the resources to effectively manage a digital transformation using our products and, as a consequence, may be unable to see the benefits of our products. Unsuccessful, lengthy or costly implementations and integrations could result in claims from customers, reputational harm and opportunities for other market participants to displace our products.
Our failure or perceived failure to achieve our corporate sustainability goals or maintain corporate sustainability practices that meet evolving stakeholder expectations could adversely affect us.
Our ability to achieve published corporate sustainability goals and commitments is subject to numerous factors both within and outside of our control. Our failure or perceived failure to achieve our corporate sustainability goals or maintain corporate sustainability practices that meet stakeholder expectations or regulatory requirements could harm our reputation, adversely impact our ability to attract and retain employees or customers and expose us to increased scrutiny from the investment community, regulatory authorities and others or subject us to liability. Our reputation also may be harmed by the perceptions that our customers, employees and other stakeholders have about our action or inaction on corporate sustainability issues. In addition, the increasing prevalence of corporate sustainability laws and regulations across the jurisdictions in which we operate may increase compliance risks and costs and, together with differing views on the appropriate role of sustainability practices and disclosures, may subject us to greater stakeholder scrutiny. Any potential damage to our reputation or loss of brand equity may reduce demand for our products and services.
We may face natural disasters, including climate change, and other events beyond our control.
Natural disasters or other catastrophic events may damage or disrupt our operations, international commerce and the global economy, and thus could have a negative effect on our business. Our business operations are subject to interruption by natural disasters, flooding, fire, extreme heat, power shortages, pandemics, terrorism, political
| 2025 Annual Report | 35 |
Part I
unrest, telecommunications failure, vandalism, cyberattacks, geopolitical instability, war, the effects of climate change and other events beyond our control. While we maintain crisis management, business continuity and disaster response plans, such planning may not account for all possible events and the occurrence of such events could make it difficult or impossible for us to deliver our services to our customers, could decrease demand for our services, and could cause us to incur substantial expense. Our insurance may not be sufficient to cover losses or additional expenses we may sustain. In the event of major natural disasters or catastrophic events, our backup systems could fail, critical teams could be impacted, customer data could be lost and resumption of operations could require significant time.
We may be subject to increased costs, regulations, reporting requirements, standards or expectations regarding climate-related impacts on our business. While we seek to mitigate our business risks associated with climate-related risks by establishing environmental sustainability and enterprise risk programs, certain of those risks are inherent wherever business is conducted. Any of our primary locations may be vulnerable to the adverse effects of climate-related risks. For example, our California headquarters have experienced and may continue to experience climate-related events at an increasing frequency and severity, including drought, water scarcity, heat waves, wildfires and air quality impacts and power shutoffs associated with wildfires. Changing market dynamics, global policy developments and increasing frequency and impact of extreme weather events on critical infrastructure in the U.S. and elsewhere have the potential to disrupt our business, the business of our customers and third-party suppliers and may cause us to experience higher attrition, losses and additional costs to maintain or resume operations.
Risks Related to the Financial Performance or Financial Position of Our Business
Because we generally recognize revenues from our subscription services over the subscription term, a decrease in new subscriptions or renewals may not be immediately reflected in our operating results.
We generally recognize revenues from customers ratably over the terms of their subscriptions. Net new annual contract value from new subscriptions and expansion contracts entered into during a period can generally be expected to generate revenues for the duration of the subscription term. As a result, a significant portion of the revenues we report in each period are derived from the recognition of deferred revenues relating to subscriptions entered into during previous periods. Consequently, a decrease in new or renewed subscriptions, expansion contracts in any single reporting period will have a limited impact on our revenues for that period, but they will negatively affect our operating results in future periods. Our subscription model also makes it difficult for us to rapidly increase our revenues through additional sales in any period, as revenues from new customers are generally recognized over the applicable subscription term. Also, our ability to adjust our cost structure in the event of a decrease in new or renewed subscriptions may be limited.
As our business grows, we expect our revenue growth rate to decline over the long term.
You should not rely on our prior revenue growth rate as an indication of our future revenue growth rate. While we have experienced significant revenue growth in prior periods, we expect the growth rate to decline over the long term due to increasing competition, a decrease in the growth rate of our overall market or other reasons. We also expect our costs to increase in future periods as we continue to invest in our strategic priorities, which may not result in a corresponding increase in revenues or growth in our business.
Changes in our effective tax rate or disallowance of our tax positions may adversely affect our business.
We are subject to income taxes in the U.S. and various foreign jurisdictions. We believe that our provision for income taxes is reasonable, but the ultimate tax outcome may differ from the amounts recorded in our consolidated financial statements and may materially affect our financial results in the period or periods in which such outcome is determined. Our effective tax rate could be adversely affected by changes in statutory tax rates, changes in the mix of earnings and losses in countries with differing statutory tax rates, certain non-deductible expenses, the valuation of deferred tax assets and liabilities and the effects of acquisitions. Increases in our effective tax rate would reduce our profitability or in some cases increase our losses.
| 36 | ![]() |
Part I
Additionally, our future effective tax rate could be impacted by changes in accounting principles or changes in federal, state or international tax laws or tax rulings and these changes may have a retroactive effect. For example, the One Big Beautiful Bill Act (“OBBBA”) was enacted on July 4, 2025, introducing a broad range of tax reform provisions that will affect our financial results. The U.S. Department of Treasury has broad authority to issue regulations and interpretative guidance that may significantly impact how we will comply with the law, which could affect our results of operations in the period issued. During 2025, multiple jurisdictions where the Company operates enacted legislation to implement the Organisation for Economic Co-operation and Development (“OECD”) Pillar 2 global minimum tax rules (generally imposing a 15% minimum effective tax rate on relevant groups). In January 2026, the OECD issued additional guidance, including a safe harbor framework for certain U.S.-parented groups such as ours. Even with this safe harbor, we could still be subject to local minimum tax regimes in countries that have adopted these rules. Based on legislation enacted to date and currently available guidance, we have not recorded a material tax liability related to Pillar 2. However, these global minimum tax rules are new and technically complex, and governments continue to issue updates on how they should be interpreted and applied. Differences in how jurisdictions implement the rules, as well as future guidance from the OECD or taxing authorities, could change our tax obligations in future periods. These developments, along with changes in U.S. or foreign tax laws or the interaction of Pillar 2 with other tax regimes, may increase our effective tax rate and could have a material impact on our financial results.
In addition, we are subject to ongoing tax audits globally. Many jurisdictions have not established clear guidance on the tax treatment of cloud computing and digital services. Although we believe our income tax liabilities are reasonably estimated and accounted for in accordance with applicable laws and principles, an adverse resolution of one or more uncertain tax positions in any period could have a material impact on our results of operations for that period. Further, many of our most important intangible assets are held outside the U.S. and are subject to inter-company agreements regarding the development and distribution of those assets to other jurisdictions with potential challenge under permanent establishment or transfer pricing principles. While we believe that our position is appropriate and well founded, if our position were successfully challenged by taxing authorities in other jurisdictions, we may become subject to significant tax liabilities.
We may be adversely affected by our debt service obligations.
Our ability to make payments on, repay or refinance the 2030 Notes in the future will depend on our future performance which is subject to a variety of risks and uncertainties, many of which are beyond our control. If we decide to refinance the 2030 Notes, we may be required to do so on different or less favorable terms or we may be unable to refinance the 2030 Notes at all, both of which may adversely affect our financial condition. Maintenance of our indebtedness, contractual restrictions and additional issuances of indebtedness could:
-
cause us to dedicate a substantial portion of our cash flows towards debt service obligations and principal repayments;
-
increase our vulnerability to adverse changes in general economic, industry and competitive conditions;
-
limit our flexibility in planning for, or reacting to, changes in our business and our industry;
-
impair our ability to obtain future financing for working capital, capital expenditures, acquisitions, general corporate or other purposes; and
-
due to limitations within the debt instruments, restrict our ability to grant liens on property, enter into certain mergers, dispose of all or substantially all of our or our subsidiaries’ assets, taken as a whole, materially change our business or incur subsidiary indebtedness, subject to customary exceptions.
We are required to comply with the covenants set forth in the indentures governing the 2030 Notes. Our ability to comply with these covenants may be affected by events beyond our control. If we breach any of the covenants and do not obtain a waiver from the note holders or lenders, then, subject to applicable cure periods, any outstanding indebtedness may be declared immediately due and payable. In addition, a rating agency’s change to our credit rating may negatively impact the value and liquidity of our securities. Downgrades in our credit ratings could restrict our ability to obtain additional financing in the future and could affect the terms of any such financing.
| 2025 Annual Report | 37 |
Part I
Risks Related to General Economic and Political Conditions
Our industry and business may be harmed by global economic and political conditions.
We operate globally and as a result, our business, revenues and profitability are impacted by global macroeconomic and political conditions. The success of our activities is affected by general economic and market conditions, including, among others, inflation, interest rates, tax rates, foreign exchange rates, economic downturns, recession, economic uncertainty, political instability, warfare, changes in laws, trade barriers, supply chain disruptions and economic and trade sanctions. The U.S. capital markets experienced and continue to experience extreme volatility and disruption. Such volatility could adversely affect our business, financial condition, results of operations and cash flows and future market disruptions could negatively impact us. These unfavorable economic conditions could increase our operating costs and, because our typical contracts with customers lock in our price for a few years, our profitability could be negatively affected. Geopolitical destabilization and warfare have impacted and may continue to impact global currency exchange rates, commodity prices, energy markets, trade and movement of resources, which may adversely affect the buying power of our customers and our access to and cost of resources from our suppliers and ability to operate or grow our business. In addition, from time to time, the U.S. and other key international economies have been impacted and may continue to be impacted by geopolitical and economic instability. These conditions include, among others, high levels of credit defaults, international trade disputes, changes in demand for various goods and services, high levels of persistent unemployment, wage and income stagnation, restricted credit, poor liquidity, reduced corporate profitability, volatility in credit, equity and foreign exchange markets, inflation, bankruptcies, tariffs, international trade agreements, export controls, economic and trade sanctions, health crises and overall economic uncertainty. These conditions can arise suddenly and affect the rate of digital transformation spending and could adversely affect our customers’ or prospective customers’ ability or willingness to purchase our services, delay purchasing decisions, reduce the value or duration of their subscriptions, or affect renewal rates.
We may be harmed by foreign currency exchange rate fluctuations.
We conduct significant transactions, including revenue transactions and intercompany transactions, in currencies other than the U.S. Dollar or the functional operating currency of the transactional entities. In addition, our international subsidiaries maintain significant net assets that are denominated in the functional operating currencies of these entities. Accordingly, changes in the value of currencies relative to the U.S. Dollar have impacted and may continue to impact our consolidated revenues and operating results due to transactional and translational remeasurement that is reflected in our earnings. It is particularly difficult to forecast any impact from exchange rate movements. Unanticipated currency fluctuations have adversely affected and could continue to adversely affect our financial results or cause our results to differ from investor expectations or our own guidance in any future periods. Volatility in foreign currency exchange rates and global financial markets is expected to continue due to global political and economic uncertainty.
We use derivative instruments, such as foreign currency forward contracts, to hedge certain balance sheet and income statement exposures to foreign currency exchange rates. These hedging contracts have reduced and may continue to reduce, but they have not and cannot entirely eliminate, the impact of adverse foreign currency exchange rate movements. To the extent that the counterparties of our hedging contracts fail to perform or fulfill their obligations, we may not receive the anticipated benefit of those arrangements. Further, unanticipated changes in foreign currency exchange rates may result in poorer overall financial performance than if we had not engaged in any hedging transactions, as the hedging instrument we use may not be aligned with the exposures being hedged.
| 38 | ![]() |
Part I
Risks Related to Ownership of Our Common Stock
Our stock price is likely to continue to be volatile.
Our stock price is likely to continue to be volatile and subject to wide fluctuations. In addition, technology companies in general have highly volatile stock prices, and the volatility in stock price and trading volume of securities is often unrelated or disproportionate to the financial performance of the companies issuing the securities. Factors affecting our stock price, some of which are beyond our control, include, among others:
-
changes in the estimates of our operating results, revenue growth or changes in recommendations by securities analysts;
-
changes in the average contract term of our customer agreements, timing of renewals and renewal rates;
-
our ability to meet our financial guidance or financial performance expectations of the securities analysts or investors;
-
announcements of new products, services or technologies, new applications or enhancements to services, strategic alliances, acquisitions or other significant events by us or by our competitors;
-
fluctuations in company valuations, such as high-growth or cloud companies, perceived to be comparable to us;
-
changes to our management team;
-
trading activity by directors, executive officers and significant shareholders or the market’s perception that large shareholders intend to sell their shares;
-
the inclusion, exclusion or removal of our stock from any major trading indices;
-
the size of our market float;
-
the trading volume of our common stock, including sales following the exercise of outstanding options or vesting of equity awards;
-
our issuance or repurchase of shares of our common stock;
-
changes in laws or regulations impacting the delivery of our services;
-
significant litigation or regulatory actions;
-
the amount and timing of customer payments, payment defaults, operating costs and capital expenditures;
-
the amount and timing of equity awards and the related financial statement expenses;
-
the impact of new accounting pronouncements;
-
the inability to conclude that our internal controls over financial reporting are effective;
-
our ability to accurately estimate the total addressable market for our products and services; and
-
overall performance of the equity markets.
Following periods of volatility in the market price of a company’s securities, securities class action litigation has often been brought against that company. Securities litigation could result in substantial costs and divert management’s attention and resources from our business.
| 2025 Annual Report | 39 |
Part I
Provisions in our governing documents or Delaware law might discourage, delay or prevent a change of control or changes in our management and, therefore, depress our stock price.
Our certificate of incorporation and bylaws contain provisions that could depress our stock price by discouraging, delaying or preventing a change in control or changes in our management that our shareholders may deem advantageous. These provisions, among other things:
-
permit our board to establish the number of directors;
-
authorize issuance of “blank check” preferred stock that our board could use to implement a shareholder rights plan;
-
prohibit shareholder action by written consent, which requires all shareholder actions to be taken at a meeting;
-
permit our board to make, alter or repeal our bylaws; and
-
require advance notice for shareholders to submit director nominations or other business at annual shareholders meetings (although our bylaws permit shareholders proxy access).
Further, Section 203 of the Delaware General Corporation Law may discourage, delay or prevent a change in control of our Company. Section 203 imposes certain restrictions on merger, business combinations and other transactions between us and certain shareholders.
| Item 1B. Unresolved Staff Comments | ||
None.
| 40 | ![]() |
Part I
| Item 1C. Cybersecurity | ||
We take a comprehensive approach to cybersecurity risk management. While securing the data customers and other stakeholders entrust to us is a top priority, we, like all companies, are subject to threats of breaches of our cybersecurity programs. Our board of directors (the “Board”) and our management are actively involved in the oversight of our risk management program, of which cybersecurity represents an important component. As described in more detail below, we have established policies, standards, processes and practices for assessing, identifying, and managing material risks from cybersecurity threats. We have devoted significant financial and personnel resources to implement and maintain security measures to meet regulatory requirements and customer expectations as detailed in our Risk Factors, and we intend to continue to make significant investments in our data and cybersecurity infrastructure. There can be no guarantee that our policies and procedures will be properly followed in every instance or that those policies and procedures will be effective as cyber criminals are becoming more sophisticated and effective every day and increasingly targeting enterprise software companies. Although our Risk Factors include further detail about the material cybersecurity risks we face, we believe that risks from prior cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected our business to date. We can provide no assurance that there will not be incidents in the future or that they will not materially affect us, including our business strategy, results of operations, or financial condition.
Risk Management and Strategy
Our policies, standards, processes and practices for assessing, identifying, and managing material risks from cybersecurity threats are integrated into our overall risk management program and are based on frameworks established by the National Institute of Standards and Technology (“NIST”), the International Organization for Standardization and other applicable industry standards. Our cybersecurity program in particular focuses on the following key areas:
Collaboration
Our cybersecurity risks are identified and addressed through a comprehensive, cross-functional approach. Key security, risk, and compliance stakeholders meet regularly to develop strategies for preserving the confidentiality, integrity and availability of Company and customer information, identifying, preventing and mitigating cybersecurity threats, and effectively responding to cybersecurity incidents. We maintain controls and procedures that are designed to ensure prompt escalation of certain cybersecurity incidents so that decisions regarding public disclosure and reporting of such incidents can be made by management and the Board in a timely manner.
Risk Assessment
At least annually, we conduct a cybersecurity risk assessment that takes into account information from internal stakeholders, known information security vulnerabilities, and information from external sources (e.g., reported security incidents that have impacted other companies, industry trends, and evaluations by third parties and consultants). The results of the assessment are used to drive alignment on, and prioritization of, initiatives to enhance our security controls, make recommendations to improve processes, and inform a broader enterprise-level risk assessment that is presented to our Board, Audit Committee and members of management.
Technical Safeguards
| 2025 Annual Report | 41 |
Part I
We regularly assess and deploy technical safeguards designed to protect our information systems from cybersecurity threats. Such safeguards are regularly evaluated and improved based on vulnerability assessments, cybersecurity threat intelligence and incident response experience.
Incident Response and Recovery Planning
We have established comprehensive incident response and recovery plans and continue to regularly test and evaluate the effectiveness of those plans. Our incident response and recovery plans address — and guide our employees, management and the Board on — our response to a cybersecurity incident.
Third-Party Risk Management
We have implemented controls designed to identify and mitigate cybersecurity threats associated with our use of third-party service providers. Such providers are subject to security risk assessments at the time of onboarding, contract renewal, and upon detection of an increase in risk profile. We use a variety of inputs in such risk assessments, including information supplied by providers and third parties. These inputs may include, as appropriate, our review of third-party audit reports, ongoing monitoring activities and validation of relevant security certifications. In addition, we require our providers to meet appropriate security requirements, controls and responsibilities and investigate security incidents that have impacted our third-party providers, as appropriate.
Education and Awareness
Our policies require each of our employees to contribute to our data security efforts. We regularly remind employees of the importance of handling and protecting customer and employee data, including through annual privacy and security training, to enhance employee awareness of how to detect and respond to cybersecurity threats. The training we offer to employees covers critical cybersecurity topics such as phishing, insider threats and the secure use of company systems.
External Assessments
Our cybersecurity policies, standards, processes and practices are regularly assessed by consultants and external auditors. These assessments include a variety of activities including information security maturity assessments, audits and independent reviews of our information security control environment and operating effectiveness. For example, in 2023, 2024 and 2025 we conducted independent cyber maturity assessments to review our controls against the NIST Cybersecurity Framework. The results of significant assessments are reported to management, the Board and Audit Committee. Cybersecurity processes are adjusted, as appropriate, based on the information provided from these assessments. We have also obtained industry certifications and attestations that demonstrate our dedication to protecting the data our customers entrust to us.
| 42 | ![]() |
Part I
Governance
Board Oversight
Our Board, in coordination with the Audit Committee, oversees our management of cybersecurity risk. They receive regular reports from management about the prevention, detection, mitigation, and remediation of material information security risks, including cybersecurity incidents and vulnerabilities. Our Audit Committee is responsible for overseeing our cybersecurity program. The Audit Committee receives regular updates from management on cybersecurity risk resulting from risk assessments, progress of risk reduction initiatives, third-party compliance certifications, control maturity assessments, and relevant ServiceNow, customer and industry cybersecurity incidents.
Management’s Role
The following individuals have primary responsibility for assessing and managing cybersecurity risks:
-
Chief product officer (“CPO”) and chief operating officer (“COO”), who oversees the digital transformation, digital technology and security functions
-
Chief digital information officer (“CDIO”), who oversees enterprise-wide digital technology
-
Chief information security officer (“CISO”), who oversees the security function and reports to the COO
-
Chief technology officer (“CTO”), who oversees product engineering and advanced technologies
-
Chief legal officer (“CLO”), who oversees the legal and compliance functions
These individuals, among others, also serve as members of management’s Security Steering Committee (the “Security Committee”), which is a governing body that drives alignment on security decisions across the Company. The Security Committee meets periodically to review security performance metrics, identify security risks, and assess the status of approved security enhancements. The Security Committee also considers and makes recommendations on security policies and procedures, security service requirements, and risk mitigation strategies.
Our CPO and COO has served in various roles in information technology and information security for over 25 years, including serving as the Head of Platform and in other senior leadership roles at two other large public companies overseeing areas such as cloud infrastructure, platform security and enterprise product development. He holds an undergraduate degree in electrical and computer engineering and a master’s degree in information networking. Our CDIO has served in various roles in information technology for over 20 years, including serving as our Senior Vice President of Digital Technology Experience and in similar senior roles at two other public companies. Our CISO has served in various roles in information technology and information security for almost 20 years, including serving as the Chief Information Security Officer or Chief Security Officer at three other large public companies. He holds undergraduate and master’s degrees in computer science. Our CTO has served in various roles in information technology for over 25 years and has been with us since 2011. Our CLO has over 25 years of experience managing risks, including risks arising from cybersecurity threats, at large public technology companies.
| 2025 Annual Report | 43 |
Part I
| Item 2. Properties | ||
Our principal office is located in Santa Clara, California, where we lease approximately 973,000 square feet of space under lease agreements for our business operations and product development. We also maintain offices globally. All of our properties are currently leased. We believe our existing facilities are adequate to meet our current requirements. Refer to Note 18 “Commitments and Contingencies” in the notes to our consolidated financial statements included elsewhere in this Annual Report on Form 10-K for more information about our lease commitments.
| Item 3. Legal Proceedings | ||
We are party to certain litigation and other legal proceedings. While legal proceedings are inherently unpredictable and subject to uncertainties, we do not believe that the ultimate resolution of any such proceedings, whether taken individually or in the aggregate, is likely to have a material adverse effect on our business, financial position, results of operations or cash flows.
For additional information regarding legal proceedings, refer to Note 18 “Commitments and Contingencies” in the notes to our consolidated financial statements in this Annual Report on Form 10-K.
| Item 4. Mine Safety Disclosures | ||
Not applicable.
| 44 | ![]() |
Part II
| Item 5. Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities | ||
Market Information for Common Stock
Our common stock is listed on the New York Stock Exchange under the symbol “NOW.”
On December 5, 2025, our board of directors approved and declared a 5-for-1 split of our common stock (“Stock Split”), with a proportionate increase in the number of shares of authorized common stock. The Stock Split had a record date of December 16, 2025 and an effective date of December 17, 2025. The par value per share of our common stock remains unchanged at $0.001 per share after the Stock Split. Accordingly, an amount equal to the par value of the additional issued shares resulting from the Stock Split was reclassified from additional paid-in capital to common stock. All references made to common share, equity award and per share amounts throughout this Annual Report on Form 10-K have been retroactively adjusted to reflect the effects of the Stock Split.
Dividends
Our board of directors currently intends to retain any future earnings to support operations and to finance the growth and development of our business, and therefore does not intend to pay cash dividends on our common stock for the foreseeable future.
Stockholders
As of December 31, 2025, there were 783 registered stockholders of record (not including an indeterminate number of beneficial holders of stock held in street name through brokers and other intermediaries) of our common stock.
Securities Authorized for Issuance under Equity Compensation Plans
The information required by this item will be incorporated by reference from our definitive proxy statement to be filed with the SEC pursuant to Regulation 14A.
Stock Performance Graph
This performance graph shall not be deemed “soliciting material” or to be “filed” with the SEC, for purposes of Section 18 of the Securities Exchange Act of 1934, as amended (the “Exchange Act”), or otherwise subject to the liabilities under that section, and shall not be deemed incorporated by reference into any of our other filings under the Securities Act of 1933, (the “Securities Act”) or the Exchange Act except to the extent we specifically incorporate it by reference into such filing.
| 2025 Annual Report | 45 |
Part II
The graph below compares the cumulative total stockholder return on our common stock with the cumulative total return on the S&P 500 Index, NYSE Composite Index and the Standard & Poor Systems Software Index for each of the last five fiscal years ended December 31, 2021 through December 31, 2025, assuming an initial investment of $100. Data for the S&P 500 Index, NYSE Composite Index and the Standard & Poor Systems Software Index assume reinvestment of dividends.
The comparisons in the graph below are based upon historical data and are not indicative of, nor intended to forecast, future performance of our common stock.
Comparison of 5 Year Cumulative Total Return*
Among ServiceNow, Inc., the NYSE Composite index, the S&P 500 Index and the S&P 500 Systems Software Index

![]() | ServiceNow, Inc. | ![]() | NYSE Composite | ![]() | S&P 500 | ![]() | S&P 500 Systems Software |
*$100 invested on 12/31/20 in stock or index, including reinvestment of dividends. Fiscal year ending December 31.
| Base Period | ||||||||||||||||||||
| Dec 31, 2020 | Dec 31, 2021 | Dec 31, 2022 | Dec 31, 2023 | Dec 31, 2024 | Dec 31, 2025 | |||||||||||||||
| ServiceNow, Inc. | 100.00 | 117.93 | 70.54 | 128.35 | 192.60 | 139.15 | ||||||||||||||
| NYSE Composite | 100.00 | 120.68 | 109.39 | 124.46 | 144.12 | 169.62 | ||||||||||||||
| S&P 500 | 100.00 | 128.71 | 105.40 | 133.10 | 166.40 | 196.16 | ||||||||||||||
| S&P Systems Software | 100.00 | 150.49 | 109.14 | 171.24 | 201.53 | 227.15 |
Unregistered Sales of Equity Securities
In connection with the acquisition of Moveworks consummated on December 15, 2025, we issued 7,805,995 shares of our common stock on such date to certain stockholders of Moveworks who had voted in favor of and adopted and approved the acquisition by written consent, dated as of March 9, 2025. The shares of our common stock were issued in reliance on the exemption from registration pursuant to Section 4(a)(2) of the Securities Act, as a transaction by an issuer not involving a public offering, and were in addition to shares of our common stock issued pursuant to an effective Form S-4 registration statement to certain other stockholders of Moveworks.
| 46 | ![]() |
Part II
Issuer Purchases of Equity Securities
Share repurchases of our common stock for the three months ended December 31, 2025 were as follows:
Issuer Purchases of Equity Securities
| Period | Total Number of Shares Purchased (in thousands)****(1) | Average Price Paid Per Share**(1)** | Total Number of Shares Purchased as Part of Publicly Announced Program (in thousands)****(1) | Approximate Dollar Value of Shares that May Yet Be Purchased Under the Program**(2)** (in millions) | ||||||||||||||||||||||||||||
| October 1 - 31 | 786 | $ | 183.10 | 786 | $ | 1.88 | ||||||||||||||||||||||||||
| November 1 - 30 | 1,170 | 167.25 | 1,170 | 1.68 | ||||||||||||||||||||||||||||
| December 1 - 31 | 1,611 | 160.01 | 1,611 | 1.43 | ||||||||||||||||||||||||||||
| Fourth Quarter 2025 | 3,567 | $ | 167.47 | 3,567 | $ | 1.43 |
(1)Share and per share information in this table has been adjusted to reflect the 5-for-1 common stock split effected on December 17, 2025. Refer to Note 2 “Summary of Significant Accounting Policies” in the notes to the consolidated financial statements included in Part II, Item 8 of this Annual Report on Form 10-K for additional information.
(2)On May 16, 2023, our board of directors authorized a program to repurchase up to $1.5 billion of our common stock. In January 2025, our board of directors authorized an additional $3.0 billion in repurchases under the share repurchase program, and in January 2026, our board of directors authorized an additional $5.0 billion in repurchases under the Share Repurchase Program. Refer to Note 14 “Stockholders' Equity” in the notes to the consolidated financial statements included in Part II, Item 8 of this Annual Report on Form 10-K for additional information.
| Item 6. Selected Consolidated Financial Data | ||


Financial Services
Healthcare and Life Sciences
Manufacturing
Public Sector
Retail
Technology
Telecom













