Palo Alto Networks 10-K 2025-07-31
Filed 2025-08-29. 24 sections, 527K characters. Original on sec.gov · Markdown · JSON
Cover and table of contents
UNITED STATES
SECURITIES AND EXCHANGE COMMISSION
Washington, D.C. 20549
FORM 10-K
(Mark One)
☒ ANNUAL REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934
For the fiscal year ended July 31, 2025
or
☐ TRANSITION REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934
For the transition period from to
Commission File Number 001-35594
Palo Alto Networks, Inc.
(Exact name of registrant as specified in its charter)
| Delaware | 20-2530195 | ||||
| (State or other jurisdiction of incorporation or organization) | (I.R.S. Employer Identification No.) | ||||
3000 Tannery Way
Santa Clara, California 95054
(Address of principal executive offices, including zip code)
(408) 753-4000
(Registrant’s telephone number, including area code)
Securities registered pursuant to Section 12(b) of the Act:
| Title of each class | Trading Symbol(s) | Name of each exchange on which registered | ||||||||||||
| Common stock, $0.0001 par value per share | PANW | The Nasdaq Stock Market LLC (Nasdaq Global Select Market) |
Securities registered pursuant to Section 12(g) of the Act:
None
Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes ☒ No ☐
Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes ☐ No ☒
Indicate by check mark whether the registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yes ☒ No ☐
Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yes ☒ No ☐
Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See the definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company,” and “emerging growth company” in Rule 12b-2 of the Exchange Act.
| Large accelerated filer | ☒ | Accelerated filer | ☐ | ||||||||
| Non-accelerated filer | ☐ | Smaller reporting company | ☐ | ||||||||
| Emerging growth company | ☐ |
If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐
Indicate by check mark whether the registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C. 7262(b)) by the registered public accounting firm that prepared or issued its audit report. ☒
If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements of the registrant included in the filing reflect the correction of an error to previously issued financial statements. ☐
Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the registrant’s executive officers during the relevant recovery period pursuant to §240.10D-1(b). ☐
Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Act). Yes ☐ No ☒
The aggregate market value of voting stock held by non-affiliates of the registrant was approximately $119.7 billion as of January 31, 2025, the last business day of the registrant’s most recently completed second fiscal quarter (based on the closing sales price for the common stock on the Nasdaq Global Select Market on such date). Shares of common stock held by each executive officer and director have been excluded in that such persons may be deemed to be affiliates. This determination of affiliate status is not necessarily a conclusive determination for other purposes.
On August 18, 2025, 668.9 million shares of the registrant’s common stock, $0.0001 par value, were outstanding.
DOCUMENTS INCORPORATED BY REFERENCE
Portions of the information called for by Part III of this Annual Report on Form 10-K is hereby incorporated by reference from the definitive proxy statement for the registrant’s 2025 annual meeting of stockholders, which will be filed with the Securities and Exchange Commission not later than 120 days after the registrant’s fiscal year ended July 31, 2025.
Table Of Contents
- 2 -
Part I
SPECIAL NOTE REGARDING FORWARD-LOOKING STATEMENTS
This Annual Report on Form 10-K, including, without limitation, the sections entitled “Business,” “Risk Factors,” and “Management’s Discussion and Analysis of Financial Condition and Results of Operations,” contains forward-looking statements within the meaning of Section 27A of the Securities Act of 1933 and Section 21E of the Securities Exchange Act of 1934. Forward-looking statements generally can be identified by words such as “anticipate,” “believe,” “continue,” “could,” “estimate,” “expect,” “intend,” “may,” “plan,” “potentially,” “projects,” “will,” “will be,” “will continue,” “will likely result,” “would,” and similar expressions that convey uncertainty of future events or outcomes.
These forward-looking statements include, but are not limited to, statements concerning the following:
-
expectations regarding the cybersecurity landscape;
-
expectations regarding our platformization strategy and related progress and opportunities;
-
expectations regarding annual recurring revenue, remaining performance obligations, and product development strategy;
-
expectations regarding artificial intelligence;
-
expectations regarding our strategic partnerships;
-
expectations regarding drivers of and factors affecting growth in our business;
-
statements regarding expected profitability, trends in annual recurring revenue, trends in remaining performance obligations, our mix of product and subscription and support revenue, cost of revenue, gross margin, cash flows, operating expenses, including future share-based compensation expense, income taxes, investment plans, and liquidity;
-
expected recurring revenues resulting from growth in our end-customers and increased adoption of our products and cloud-delivered security solutions;
-
the performance advantages of our products and subscription and support offerings and the potential benefits to our customers;
-
expectations regarding future investments in research and development and product development, customer support, in our employees and in our sales force, including expectations regarding growth in our sales headcount;
-
expectations that we will continue to expand our global presence;
-
expectations regarding our revenues, including the seasonality and cyclicality from quarter to quarter;
-
expectations relating to our customer financing activities;
-
the sufficiency of our cash flow from operations with existing cash, cash equivalents, and investments to meet our cash needs for the foreseeable future;
-
our ability to successfully acquire and integrate companies and assets and expectations and intentions with respect to the assets, products and technologies that we acquire, including with respect to our proposed acquisition of CyberArk Software Ltd. and our expectations regarding the benefits and synergies of the proposed acquisition;
-
our ability to complete, on a timely basis, or at all, announced transactions, including our proposed acquisition of CyberArk Software Ltd.;
-
expectations regarding contingent consideration obligations;
-
the timing and amount of capital expenditures and share repurchases;
-
the effects of worldwide economic and geopolitical conditions, including but not limited to hostilities in Israel and the surrounding regions, inflation, tariff rates, interest rate levels, public or administration policies, trade regulations, trade policy, growth rates and other conditions, on our operating and financial results and performance;
-
the manufacture, delivery and cost of certain of our products;
-
the effects of litigation or regulatory developments involving us or affecting our industry; and
-
other statements regarding our future operations, financial condition and prospects, and business strategies.
These forward-looking statements are based on current expectations and assumptions that are subject to risks and uncertainties, including those described in “Risk Factors” included in Part I, Item 1A and elsewhere in this Annual Report on Form 10-K. Moreover, we operate in a very competitive and rapidly changing environment, and new risks emerge from time to time. It is not possible for our management to predict all risks, nor can we assess the impact of all factors on our business or the extent to which any factor, or combination of factors, may cause actual results to differ materially from those contained in any forward-looking statements we may make. In light of these risks, uncertainties, and assumptions, the forward-looking events and circumstances discussed in this Annual Report on Form 10-K may not occur, and actual results could differ materially and adversely from those anticipated or implied in the forward-looking statements. We undertake no obligation to revise or publicly release the results of any revision to these forward-looking statements, except as required by law. Given these risks and uncertainties, readers are cautioned not to place undue reliance on such forward-looking statements.
- 3 -
Item 1. Business
General
Palo Alto Networks, Inc. is a global cybersecurity provider and our vision is a world where each day is safer and more secure than the one before. We were incorporated in 2005 and are headquartered in Santa Clara, California.
Our mission is to be the cybersecurity partner of choice for enterprises, organizations, service providers, and government entities to protect our digital way of life. Our cybersecurity platforms and services help secure enterprise users, networks, clouds, and endpoints by delivering comprehensive cybersecurity backed by artificial intelligence (“AI”) and automation. A key element of our strategy is to help our customers simplify their security architectures through consolidating disparate point products. We execute on this strategy by developing our capabilities and packaging our offerings into platforms which are able to cover many of our customers’ needs in the markets in which we operate. Our platformization strategy combines various products and services into a tightly integrated architecture for more secure, faster, and cost-effective outcomes.
Network Security
Our network security platform is designed to deliver complete zero trust solutions to our customers. The platform includes:
-
Secure Access Service Edge (“SASE”). Prisma® Access, when combined with Prisma SD-WAN, provides a comprehensive single-vendor SASE offering that is used to secure remote workforces and cloud-delivered branch offices. Prisma Access Browser further extends SASE security and data protection to the end user device, providing workers with freedom to access business applications securely using our secure browser from any device.
-
Next-Generation Firewalls. Our hardware ML-Powered Next-Generation Firewalls (“NGFWs”) secure on-premises environments including campus locations and data centers. Our software NGFWs secure cloud networks.
-
Cloud-Delivered Security Services (“CDSS”). Our network security platform integrates a suite of CDSS that complements our SASE and Firewall solutions. These include Advanced Threat Prevention, Advanced WildFire®, Advanced URL Filtering, Advanced DNS Security, IoT/OT Security, GlobalProtect®, Prisma Access Agent, Enterprise Data Loss Prevention (“Enterprise DLP”), AI for IT Operations (“AIOps”), Software as a Service (“SaaS”) Security, and AI Access Security. Through these add-on services, our customers are able to secure their content, applications, users, and devices across their entire organization.
-
Prisma AIRS. Prisma AIRS is a comprehensive AI security platform that has been designed to protect customers’ entire AI ecosystem by providing AI model scanning, posture management, red teaming, run-time security, and AI agent security.
-
Strata Cloud Manager (“SCM”). SCM, our network security management solution, centrally manages network security across all remote workers, branches, headquarters, campuses, and cloud. SCM leverages AI to simplify and strengthen network security by enabling customers to proactively pinpoint vulnerabilities, gain real-time remediation recommendations, and enhance overall digital experiences, thereby reducing operational burden. This comprehensive solution includes Strata Copilot, which offers a natural language interface for enhanced insights and guided remediation, and integrates Autonomous Digital Experience Monitoring (“ADEM”) to proactively maintain infrastructure health, facilitate AI-driven one-click troubleshooting, and ensure seamless end-user performance across the enterprise.
Security Operations
Our AI-powered Cortex platform transforms end-to-end security operations with unified data, AI, and automation for more secure, faster, and cost effective outcomes. We have consolidated our industry-leading Security Operations and Cloud Security capabilities on a single comprehensive platform to provide centralized visibility, proactive protection, real-time prevention, AI-driven insights, and automated remediation across enterprise and cloud.
-
Security Operations. We deliver the next generation of security operations capabilities that unifies standalone Security Information and Event Management (“SIEM”) tools, endpoint security, security automation, cloud detection and response (“CDR”), as well as attack surface management (“ASM”) capabilities on our Cortex® platform. These include Cortex XSIAM®, for AI-powered security operations replacing traditional SIEM tools, Cortex XDR®, for the prevention, detection, and response to complex cybersecurity attacks, Cortex XSOAR®, for security orchestration, automation, and response (“SOAR”), and Cortex Xpanse®, for ASM.
-
Cloud Security. We deliver comprehensive security across the cloud application development lifecycle through Cortex Cloud, delivered as a scalable SaaS offering. As a comprehensive Cloud Native Application Protection Platform (“CNAPP”) combined with CDR, Cortex Cloud secures multi- and hybrid-cloud environments for applications, data, generative AI (“GenAI”) ecosystem, and the cloud native technology stack across the full development lifecycle, from code to cloud to security operations. As part of the Cortex Cloud platform, customers can expand from Cortex Cloud to our security operations offerings available on a single user experience and unified agent. We also offer our VM-Series and CN-Series virtual firewalls for inline network security on multi- and hybrid-cloud environments.
- 4 -
Threat Intelligence and Advisory Services
- Unit 42® brings together world-renowned expertise across threat research, incident response, and security consulting to deliver intelligence-driven, response-ready outcomes that help customers reduce cyber risk. Our elite consultants serve as trusted advisors to our customers by assessing and testing their security controls against sophisticated threats, transforming their security strategy with a threat-informed approach, and responding to security incidents on behalf of our clients. Additionally, Unit 42 offers managed detection and response (“MDR”) and managed threat hunting services.
Products and Services
NETWORK SECURITY
Secure Access Service Edge
-
Prisma Access. Prisma Access is a cloud-delivered security offering that helps organizations deliver consistent AI-driven security to remote networks and mobile users. With more than 100 locations around the world, Prisma Access offers global coverage, consistently inspecting all traffic across all ports and providing bidirectional networking to enable branch-to-branch and branch-to-headquarter traffic. Prisma Access consolidates point products into a single cloud-delivered solution, transforming network security and allowing organizations to enable secure hybrid work. Prisma Access protects all application traffic with complete, best-in-class security while also delivering a seamless user experience with industry-leading service-level agreements (“SLA”s). With native SASE integration, Prisma Access Browser extends Zero Trust to any device—managed or unmanaged—in minutes. Prisma Access delivers seamless user experience with a combination of application acceleration—up to 5x faster than direct-to-internet—and Autonomous Digital Experience Management.
-
Prisma SD-WAN. Our Prisma SD-WAN solution is a next-generation SD-WAN solution that makes the secure cloud-delivered branch possible. Prisma SD-WAN enables organizations to replace traditional wide area network (“WAN”) architectures with affordable broadband and internet transport types that promote improved bandwidth availability, redundancy and performance at a reduced cost. Prisma SD-WAN leverages real-time application performance SLAs and visibility to control and intelligently steer application traffic to deliver a powerful user experience. Prisma SD-WAN also provides the flexibility of deploying with an on-premises controller to help businesses meet their industry-specific security compliance requirements and manage deployments with application-defined policies. Our Prisma SD-WAN simplifies network and security operations using AI and automation.
Next-Generation Firewalls. Our hardware and software ML-Powered Next Generation Firewalls use AI—including machine learning and deep learning—to stop zero-day threats in real time, and detect and secure the entire enterprise including Internet of Things (“IoT”). All of our hardware and software firewalls incorporate the PAN-OS® operating system and include the same rich set of features, ensuring consistent operation across our entire product line. This includes SD-WAN capabilities to intelligently steer traffic to data centers, branches, and the cloud, natively integrated into our Next-Generation Firewalls. Enterprise data, applications, users, and devices become integral components of an organization’s security policy. Our hardware and software are designed for different performance requirements throughout an organization—with the ability to secure everything from small businesses and branch offices, to large-scale data centers and service providers. Our firewalls come in hardware form factors, containerized form factors, called CN-Series, as well as virtual form factors, called VM-Series, available on all major cloud hosting service providers. We also offer Cloud NGFW, a managed NGFW offering, to secure customers’ applications on Amazon Web Services (“AWS”) and Microsoft Azure (“Azure”).
Cloud-Delivered Security Services
-
Advanced Threat Prevention. This cloud-delivered security service provides intrusion detection and prevention capabilities and blocks vulnerability exploits, viruses, spyware, buffer overflows, denial-of-service attacks, and port scans from compromising and damaging enterprise information resources. In addition, we offer inline deep learning to deliver real-time detection and prevention of unknown, evasive, and targeted command-and-control (“C2”) communications over HTTP, unknown-TCP, unknown-UDP, and encrypted over SSL. Advanced Threat Prevention is the industry’s only offering to protect the enterprise from unknown command and control in real-time with the power of Precision AITM.
-
Advanced WildFire. This cloud-delivered security service provides protection against targeted malware and advanced persistent threats and provides a near real-time analysis engine for detecting previously unseen malware while resisting attacker evasion techniques. Advanced WildFire combines dynamic and static analysis, recursive analysis, and a custom-built analysis environment with network traffic profiling and fileless attack detection to discover even the most sophisticated and evasive threats. Preventions are delivered in seconds to our network security platform.
- 5 -
-
Advanced URL Filtering. This cloud-delivered security service offers the industry’s first Inline Deep Learning powered web protection engine. We deliver real-time detection and prevention of unknown, evasive, and targeted web-based threats, such as phishing. In addition, the service includes a cloud-based URL filtering database which consists of millions of URLs across many categories and is designed to analyze web traffic and prevent web-based threats, such as phishing, malware, and C2.
-
Advanced DNS Security. This cloud-delivered security service uses machine learning to proactively block malicious domains and stop attacks in progress. The service allows our network security platform access to Domain Name System (“DNS”) signatures that are generated using advanced predictive analysis, machine learning, and malicious domain data from a growing threat intelligence sharing community of which we are a part of. We offer comprehensive DNS attack coverage and include industry-first protections against multiple emerging DNS-based network attacks, including real-time analysis of DNS response to prevent DNS hijacking.
-
IoT/OT Security. This cloud-delivered security service uses machine learning to accurately identify and classify various IoT and operational technology (“OT”) devices, including never-been-seen-before devices, mission-critical OT devices, and unmanaged legacy systems. The service uses machine learning to baseline normal behavior, identify anomalous activity, assess risk, and provide policy recommendations.
-
SaaS Security API. SaaS Security API is a multi-mode, cloud access security broker (“CASB”) that helps govern sanctioned SaaS application usage across all users and helps prevent breaches and non-compliance. Specifically, the service enables the discovery and classification of data stored in supported SaaS applications, protects sensitive data from accidental exposure, identifies and protects against known and unknown malware, and performs user activity monitoring to identify potential misuse or data exfiltration. The solution can be combined with SaaS Security Inline for a complete integrated CASB.
-
SaaS Security Inline. SaaS Security Inline adds an inline service to automatically gain visibility and control over thousands of known and newly sanctioned, unsanctioned and tolerated SaaS applications in use within organizations today. The service provides enterprise data protection and compliance across all SaaS applications and prevents cloud threats in real time. The solution can be combined with SaaS Security API as a complete integrated CASB.
-
GlobalProtect. This subscription provides protection for users of both traditional laptop and mobile devices. It expands the boundaries of the end-users’ physical network, effectively establishing a logical perimeter that encompasses remote laptop and mobile device users irrespective of their location. Regardless of the operating system, laptops, tablets, and phones will stay connected to the corporate network when they are on a network of any kind and as a result, are protected as if they never left the corporate campus.
-
Prisma Access Agent. Prisma Access Agent provides secure, remote access to corporate resources for employees working from any location or device. The agent establishes an encrypted tunnel to Prisma Access or our NGFW, ensuring consistent security, data protection, and threat prevention for a distributed workforce accessing any application.
-
Enterprise DLP. This cloud-delivered security service provides consistent and reliable protection of sensitive data, such as personally identifiable information and intellectual property, for all traffic types, applications, and users. Native integration with our products makes the service simple to deploy, while advanced machine learning minimizes management complexity. Enterprise DLP allows organizations to consistently discover, classify, monitor, and protect sensitive data, wherever it may reside.
-
AI Access Security. AI Access Security classifies and prioritizes GenAI applications to assess risk, detect anomalies and visualize insights across multiple GenAI-specific attributes. The service prevents sensitive data loss and defends against malicious responses, ensuring safe and effective AI adoption.
-
AIOps. AIOps enables security teams to proactively strengthen security posture and resolve network disruptions. AIOps provides continuous best practice recommendations powered by machine learning based on industry standards, security policy context, and advanced telemetry data collected from our network security customers to improve security posture. The service also intelligently predicts health, performance, and capacity problems up to seven days in advance and provides actionable insights to resolve the predicted disruptions.
Prisma AIRS. Prisma AIRS is a comprehensive AI security platform engineered to protect customers' entire AI ecosystem across its lifecycle. It addresses unique AI security challenges such as prompt injection, data poisoning, and sensitive data leakage, by providing deep visibility and control across AI models, data, and applications. The platform offers AI Model Scanning for vulnerabilities, Posture Management for secure configurations, and AI Red Teaming for proactive testing. Critically, Runtime Security prevents threats during live AI model execution, while AI Agent Security extends protection to autonomous AI agents.
- 6 -
Strata Cloud Manager. SCM enables our customers to easily manage their Palo Alto Networks’ Network Security infrastructure—including NGFWs and SASE deployments—from the cloud, via one unified management interface. As an AI-powered, unified cloud management solution, SCM enables organizations to enhance their network security posture and streamline operations. It utilizes AI to swiftly identify potential vulnerabilities, provide real-time recommendations for remediation, proactively address support needs, and improve overall digital experiences, leading to reduced operational overhead and improved speed, accuracy, and scale of support. By analyzing telemetry, historical data, and its diverse knowledge base, SCM can instantly answer questions, pinpoint solutions to known problems, and automate data collection to speed up assisted support for new challenges. Built into this robust solution are Strata Copilot, offering a natural language interface for intuitive insights and guided actions, and ADEM, designed for proactive infrastructure health, simplified troubleshooting, and consistent end-user performance across the network.
Panorama. Panorama is used for centralized policy management, device management, software licensing and updates, centralized logging and reporting, and log storage. Many of our existing deployments continue to use Panorama as the security management solution. New deployments benefit from using SCM for managing network security estate—including our Next-Generation Firewalls and SASE—with a cloud-based, unified management interface.
SECURITY OPERATIONS
-
Cortex XSIAM. Our cloud-based AI-powered security operations platform harnesses the power of AI to significantly improve security outcomes and transform security operations. Cortex XSIAM customers are able to consolidate multiple products into a single unified platform that delivers security information and event management, extended detection and response (“XDR”), SOAR, network traffic analysis, ASM, threat intelligence management (“TIM”), identity threat detection and response, and CDR. CDR is the latest addition to Cortex XSIAM and XDR that addresses the growing need for security teams to respond to cloud threats with purpose-built SOC tools that seamlessly integrate with their security programs. Cortex XSIAM integrates these capabilities into a single platform built for security operations, enabling organizations to simplify operations, stop threats at scale, and accelerate incident remediation. Cortex XSIAM automates data integration, analysis, and triage to respond to most alerts, enabling analysts to focus on only the incidents that require human intervention.
-
Cortex XDR. This cloud-based service enables organizations to collect telemetry from endpoint, network, identity and cloud data sources and apply advanced analytics and machine learning, to quickly find and stop targeted attacks, insider abuse, and compromised endpoints. Cortex XDR has two product tiers: XDR Prevent and XDR Pro. XDR Prevent delivers enterprise-class endpoint security focused on preventing attacks. XDR Pro extends endpoint detection and response (“EDR”) to include cross-data analytics for network, cloud, and identity data. Going beyond EDR, Cortex XDR detects the most complex threats using analytics across key data sources and reveals the root cause, which can significantly reduce investigation time as compared to siloed tools and manual processes.
-
Cortex XSOAR. Available as a stand-alone cloud-based service, an on-premises virtual appliance, or delivered natively through Cortex XSIAM, Cortex XSOAR is a comprehensive SOAR offering that unifies playbook automation, case management, real-time collaboration, and threat intelligence management to serve security teams across the incident lifecycle. With Cortex XSOAR, security teams can standardize processes, automate repeatable tasks, and manage incidents across their security product stack to improve response time and analyst productivity. Cortex XSOAR learns from the real-life analyst interactions and past investigations to help SOC teams with analyst assignment suggestions, playbook enhancements, and best next steps for investigations. Many of our customers see significantly faster SOC response times and a significant reduction in the number of SOC alerts which require human intervention.
-
Cortex Xpanse. Available as a stand-alone cloud-based service and a cloud-based subscription module within Cortex XSIAM, Cortex Xpanse provides ASM, which is the ability for an organization to identify what an attacker would see among all of its sanctioned and unsanctioned Internet-facing assets. In addition, Cortex Xpanse detects risky or out-of-policy communications between Internet-connected assets that can be exploited for data breaches or ransomware attacks. Cortex Xpanse continuously identifies Internet assets, risky services, or misconfigurations in third parties to help secure a supply chain or identify risks for mergers and acquisitions due diligence. Finally, compliance teams use Cortex Xpanse to improve their audit processes and stay in compliance by assessing their access controls against regulatory frameworks.
-
Cortex Cloud. Available as a stand-alone cloud-based service or an add-on to Cortex XDR or to Cortex XSIAM. Cortex Cloud, the next generation of Prisma Cloud, merges CNAPP with CDR for real-time cloud security. The solution allows you to harness the power of AI and automation to prioritize cloud risks with runtime context, enable remediation at scale, and stop attacks as they happen. Cortex Cloud consolidates multiple code and cloud security technologies such as Cloud Detection and Response, Software Composition Analysis, Infrastructure as Code security, CI/CD security, secrets scanning, Cloud Security Posture Management, Cloud Identity and Entitlements Management, API security, Vulnerability Management, Cloud Workload Protection, Web Application and API Security, Cloud Network Security, and Cloud Attack Surface Management into a single unified offering. As part of the Cortex platform, customers can transform end-to-end security operations, from code to cloud to SOC, by adopting Cortex Cloud together with Cortex XSIAM. Existing customers can continue leveraging Prisma Cloud as they upgrade to Cortex Cloud for significantly better, faster and more effective multi-cloud protection.
- 7 -
THREAT INTELLIGENCE AND ADVISORY SERVICES
-
Customer Support. Global customer support helps our customers achieve their security outcomes with services and support capabilities covering the customer's entire journey with Palo Alto Networks. This post-sales, global organization advances our customers’ security maturity, supporting them when, where, and how they need it. We offer Standard Support, Premium Support, and Platinum Support to our end-customers and channel partners. Our channel partners that operate a Palo Alto Networks Authorized Support Center typically deliver level-one and level-two support. We provide level-three support 24 hours a day, seven days a week through regional support centers that are located worldwide. We also offer a service offering called Focused Services that includes Customer Success Managers to provide support for end-customers with unique or complex support requirements. We offer our end-customers ongoing support for hardware, software, and certain cloud offerings, which includes ongoing security updates, PAN-OS upgrades, bug fixes, and repairs. End-customers typically purchase these services for a one-year or longer term at the time of the initial product sale and typically renew for successive one-year or longer periods. Additionally, we provide expedited replacement for any defective hardware. We use a third-party logistics provider to manage our worldwide deployment of service-related spares.
-
Threat Intelligence, Incident Response and Security Consulting. Unit 42 brings together world-renowned threat researchers, incident responders, and security consultants to create an intelligence-driven, response-ready organization that is passionate about helping clients proactively manage cyber risk. We help security leaders assess and test their security controls, transform their security strategy with a threat-informed approach, and respond to incidents rapidly. The Unit 42 Threat Intelligence team provides threat research that enables security teams to understand adversary intent and attribution, while enhancing protections offered by our products and services to stop advanced attacks. Our security consultants serve as trusted partners with state-of-the-art cyber risk expertise and incident response capabilities, helping customers build effective security programs, uncover critical exposures to prevent incidents, and, should incidents occur, respond to them with speed and confidence.
-
Professional Services. Professional services are primarily delivered directly by Palo Alto Networks and through a global network of authorized channel partners to our end-customers and include on-location and remote, hands-on experts who plan, design, and deploy effective security solutions tailored to our end-customers’ specific requirements. These services include architecture design and planning, implementation, configuration, and firewall migrations for all our products, including Prisma and Cortex deployments. Customers can also purchase on-going technical experts to be part of customer’s security teams to aid in the implementation and operation of their Palo Alto Networks capabilities. Our education services include certifications, as well as free online technical courses and in-classroom training, which are primarily delivered through our authorized training partners.
RESEARCH AND DEVELOPMENT
Our research and development efforts are strategically centered on expanding our leadership within the enterprise security industry through AI-powered innovation. We focus on enhancing our integrated platforms and developing new software and hardware capabilities. Our engineering teams apply deep expertise in AI and machine learning across networking security, cloud security, endpoint security, and security operations to address the rapidly evolving threat landscape. This approach enables us to leverage core competencies across hardware and software for agile responsiveness and to ensure interoperability with third-party technologies. We supplement our own research with technologies and products licensed from third parties.
We believe that innovation and timely development of new features and products is essential to meeting the needs of our end-customers and improving our competitive position. During fiscal 2025, we introduced several new offerings, including: Prisma Access Browser, new capabilities in our OT Security solution, Cortex Cloud, Prisma AIRS, and Cortex XSIAM 3.0.
We plan to continue to significantly invest in our research and development efforts as we evolve and extend the capabilities of our portfolio.
ACQUISITIONS
We believe that the enterprise security industry in which we operate necessitates a variety of technologies, products, capabilities, and features. We evaluate opportunities to acquire complementary businesses, technologies, services, and intellectual property to complement our organic innovation and research and development efforts, advance the development of our platforms, and enable further investment in our key priority areas. Our evaluation of acquisition opportunities seeks to confirm that any potential transaction would accelerate our strategy, represent an attractive customer opportunity, address a customer need, align with our customer base and go-to-market strategy, and present a clear timeline and path for value accretion. Our acquisitions enable us to gain access to talent, technology, products and features, and can range in size and complexity, from those that enhance or complement existing products and accelerate development of features to those that result in new offerings.
- 8 -
For example, in August 2024, we completed the acquisition of certain QRadar assets from International Business Machines Corporation (“IBM”), which we expect will help accelerate the growth of our Cortex business. Additionally, in July 2025, we completed the acquisition of Protect AI, Inc., a privately-held cyber security company (“Protect AI”), which we expect will enhance the capabilities of our AI security platform. In July 2025, we also entered into a definitive agreement to acquire CyberArk Software Ltd. (“CyberArk”), an identity security company, which acquisition is expected to close during the second half of our fiscal 2026.
For additional information related to the impact of acquisitions to our business, see Part I, Item 1A “Risk Factors” in this Form 10-K.
INTELLECTUAL PROPERTY
We believe that our intellectual property rights are valuable and important to our business, and that our success depends, in part, on our ability to protect and use our core technology and intellectual property rights. We rely on a combination of trademarks, patents, copyrights, trade secrets, license agreements, intellectual property assignment agreements, confidentiality procedures, non-disclosure agreements, and employee non-disclosure and invention assignment agreements to establish, protect and control the use of our proprietary technology and intellectual property rights. We continue to grow our global portfolio of intellectual property rights in connection with our products, services, research and development. We file patent applications to protect our intellectual property and believe that the duration of our issued patents is sufficient when considering the expected lives of our products. We have registered various trademarks for our company and our products in the United States (“U.S.”) and other jurisdictions internationally. We intend to continue pursuing additional protections for our proprietary technology and intellectual property to the extent we believe it would be beneficial and cost-effective.
Despite our efforts to protect our proprietary technology and intellectual property rights, our rights may not be respected in the future or may be invalidated, circumvented, or challenged. Our industry is characterized by the existence of a large number of patents and frequent claims and related litigation based on allegations of patent infringement or other violations of intellectual property rights. We believe that competitors will try to develop products that are similar to ours and that may infringe our intellectual property rights. Our competitors, third-parties and non-practicing entities, may also claim that our cybersecurity platforms and services infringe their intellectual property rights. From time to time, third parties have in the past and may in the future assert claims of infringement, misappropriation and other violations of intellectual property rights against us or our customers, with whom our license or other agreements may obligate us to indemnify against these claims. Successful claims of infringement by a third party could affect our ability to offer, or prevent us from offering, certain products or features. This could result in time during which we may be unable to continue to offer our affected products or solutions because of a potential need for us to develop alternate, non-infringing technology, which could require significant time and resources, or require us to obtain a license, which may not be available on reasonable terms or at all, or could require us to pay substantial damages, royalties, or other fees. For additional information, see the section titled “Risks Related to Intellectual Property and Technology Licensing” in Part I, Item 1A “Risk Factors” in this Form 10-K.
GOVERNMENT REGULATION
We are subject to numerous U.S. federal, state, and foreign laws and regulations covering a wide variety of subject matters. Like other companies in the technology industry, we face scrutiny from both U.S. and foreign governments with respect to our compliance with laws and regulations. Our compliance with these laws and regulations may be onerous and could, individually or in the aggregate, increase our cost of doing business, impact our competitive position relative to our peers, and/or otherwise have an adverse impact on our business, reputation, financial condition, and operating results. For additional information about government regulation applicable to our business, see Part I, Item 1A “Risk Factors” in this Form 10-K.
COMPETITION
We operate in the intensely competitive enterprise security industry that is characterized by constant change and innovation. Changes in the application, threat, and technology landscape result in evolving customer requirements for the protection from threats and the safe enablement of applications. Our main competitors fall into four categories:
-
large companies that incorporate security features in their products, such as Cisco Systems, Inc. (“Cisco”), Microsoft, Alphabet, or those that have acquired, or may acquire, security vendors and have the technical and financial resources to bring competitive solutions to the market;
-
independent security vendors, such as Check Point Software Technologies Ltd. (“Check Point”), Fortinet, Inc. (“Fortinet”), CrowdStrike Holdings, Inc. (“CrowdStrike”), Zscaler, Inc. (“Zscaler”), and Wiz, Inc. (“Wiz”), that offer a mix of security products;
-
startups and point-product vendors that offer independent or emerging solutions across various areas of security; and
-
public cloud vendors and startups that offer solutions for cloud security (private, public, and hybrid cloud).
- 9 -
As our market grows, it will attract more highly specialized vendors, as well as larger vendors that may continue to acquire or bundle their products more effectively.
The principal competitive factors in our market include:
-
product features, reliability, performance, and effectiveness;
-
product line breadth, diversity, and applicability;
-
product extensibility and ability to integrate with other technology infrastructures;
-
price and total cost of ownership;
-
adherence to industry standards and certifications;
-
strength of sales and marketing efforts; and
-
brand awareness and reputation.
We believe we generally compete favorably with our competitors on the basis of these factors as a result of the features and performance of our portfolio, the ease of integration of our security solutions with technological infrastructures, and the relatively low total cost of ownership of our products. However, some of our competitors may have substantially greater financial, technical, and other resources, greater name recognition, larger sales and marketing budgets, broader distribution, more diversified product lines, and larger and more mature intellectual property portfolios.
SALES, MARKETING, SERVICES, AND SUPPORT
Customers. Our end-customers consist of enterprises, service providers, and government entities. Our end-customers operate in a variety of industries, including education, energy, financial services, government entities, healthcare, Internet and media, manufacturing, public sector, and telecommunications. Our end-customers deploy our portfolio of solutions for a variety of security use cases across several settings. Typical deployment settings include the enterprise network, the enterprise data center, cloud locations, branch or remote locations, and on-device agents. No single end-customer accounted for more than 10% of our total revenue in fiscal 2025, 2024, or 2023.
Distribution. We primarily sell our products and subscription and support offerings to end-customers through our channel partners utilizing a two-tier, indirect fulfillment model whereby we sell our products and subscription and support offerings to our distributors, which, in turn, sell to our resellers, which then sell to our end-customers. Sales are generally subject to our standard, non-exclusive distributor agreement, which provides for an initial term of one year, one-year renewal terms, termination by us with 30 to 90 days written notice prior to the renewal date, and payment to us from the channel partner within 30 to 45 calendar days of the date we issue an invoice for such sales. For fiscal 2025, 44.2% of our total revenue was derived from sales to three distributors.
We also sell our VM-Series virtual firewalls and Cloud NGFW via various cloud marketplaces. For example, our VM-Series virtual firewalls are sold on Amazon’s AWS Marketplace, Microsoft’s Azure Marketplace, Alphabet’s Google Cloud Marketplace, and Oracle Corporation’s Oracle Cloud Marketplace either directly to end customers or as part of the respective cloud hosting service provider’s offerings under a usage-based licensing model.
Sales. Our sales organization is responsible for large-account acquisition and overall market development, which includes the management of the relationships with our channel partners, working with our channel partners in winning and supporting end-customers through a direct-touch approach, and acting as the liaison between our end-customers and our marketing and product development organizations. We pursue sales opportunities both through our direct sales force and as assisted by our channel partners, which include resellers, global and regional systems integrators, service providers, managed security service providers, and cloud hosting service providers. We expect to continue to grow our sales headcount to expand our reach in all key growth sectors.
Our sales organization is supported by sales engineers with responsibility for pre-sales technical support, solutions engineering for our end-customers, and technical training for our channel partners.
Channel Program. Our NextWave Channel Partner program is focused on building in-depth relationships with solutions-oriented distributors, channel, delivery and services partners that have strong security expertise. The program rewards these partners based on a number of attainment goals, as well as provides them access to marketing resources, technical and sales training, and support. To promote optimal productivity, we operate a formal accreditation program for our channel partners’ sales and technical professionals. As of July 31, 2025, we had more than 8,500 channel partners.
Global Customer Success. Our Global Customer Success organization is responsible for delivering professional, educational, and support services directly to our end-customers and partners. We leverage a global network of certified partners to extend the reach and consistency of these services. We believe that a comprehensive suite of customer success offerings is critical to the successful deployment, adoption, and ongoing use of our products. To support this, we have invested in hiring and developing technical experts with deep domain knowledge and proven experience across our portfolio.
- 10 -
Marketing. Our marketing is focused on building our brand reputation and the market awareness of our portfolio and driving pipeline and end-customer demand. Our marketing team consists primarily of product marketing, brand, demand generation, field marketing, digital marketing, communications, analyst relations, and marketing analytics functions. Marketing activities include pipeline development through demand generation, social media and advertising programs, managing the corporate website and partner portal, trade shows and conferences, analyst relationships, customer advocacy, and customer awareness. Every year we organize multiple signature events, such as our end-customer conference “Ignite” and focused conferences such as “Cortex Symphony” and “SASE Converge.” We also publish threat intelligence research, such as the Unit 42 Cloud Threat Report and the Unit 42 Network Threat Trends Research Report, which are based on data from our global threat intelligence team, Unit 42. These activities and tools benefit both our direct and indirect channels and are available at no cost to our channel partners.
Our products and services have been recognized as leading in 25 categories by third-party industry analysts firms that perform independent assessments of these categories. This recognition by third parties is an important measure of validation for our customers.
Backlog. Contract amounts that are not recorded in deferred revenue or revenue are considered backlog. Orders billed prior to revenue recognition are included in deferred revenue. We expect backlog will change from period to period for various reasons, including the timing of billing and fulfillment, such as inventory shortages. As such, we do not believe that backlog at any particular time is necessarily indicative of our future operating results.
Seasonality. Our business is affected by seasonal fluctuations in customer spending patterns. We have begun to see seasonal patterns in our business, which we expect to become more pronounced as we continue to grow, with our strongest sequential revenue growth generally occurring in our fiscal second and fourth quarters.
MANUFACTURING
We outsource the manufacturing of our products to various manufacturing partners, which include our electronics manufacturing services provider (“EMS provider”) and original design manufacturers. This approach allows us to reduce our costs as it reduces our manufacturing overhead and inventory and also allows us to adjust more quickly to changing end-customer demand. Our EMS provider is Flextronics International, Ltd. (“Flex”), who assembles our products using design specifications, quality assurance programs, and standards that we establish, and procures components and assembles our products based on our demand forecasts. These forecasts are based upon historical trends and analysis, adjusted for overall market conditions. All of our hardware products are assembled in the U.S.
The component parts within our products are either sourced by our manufacturing partners or by us from various component suppliers. Our manufacturing and supply contracts, generally, do not guarantee a certain level of supply or fixed pricing, which increases our exposure to supply shortages or price increases.
HUMAN CAPITAL
We believe our ongoing success depends on our employees. With a global workforce of 16,068 as of July 31, 2025, our People Strategy is a critical element of our overall company strategy and is overseen by our Chief People Officer who regularly updates our board of directors and the board’s Compensation and People Committee on human capital matters. Our People Strategy is designed to enable a workforce that is nimble, high-performing and innovative. We take a comprehensive approach to attracting, enabling and engaging world-class talent and fostering a culture where every employee can thrive. Our approach includes respecting each employee as a unique individual, demonstrating fairness in all we do and advancing a culture where employees are inspired to do the best work of their careers. We also focus on integrating AI into people programs and processes to build a more agile, skilled and forward-thinking workforce prepared for the future of cybersecurity. Our values of disruption, execution, collaboration, inclusion and integrity were co-created with employees and serve as the foundation of our culture. These values are embedded in our talent acquisition, learning and enablement, engagement and performance elevation, rewards and recognition programs.
Attract & Hire. At Palo Alto Networks, we source talent with the necessary skills and capabilities to contribute to our culture and mission. We utilize structured interviewing practices, thorough job analyses and success profiles to identify high-quality candidates and staff critical roles. In fiscal 2025, we began to transform our hiring operations by strategically embedding AI across the talent acquisition lifecycle to sharpen our competitive edge for talent. We are deploying intelligent tools to automate and enhance core processes, including AI-generated job descriptions, structured interview guides and preparation materials; intelligent interview scheduling; launching an automated talent sourcing and screening pilot; and using AI to augment feedback summaries. Each step is optimized for speed, consistency and bias mitigation. Recognizing that technical skills evolve rapidly in an AI-driven world, our recruitment strategy prioritizes durable, "AI-readiness" capabilities. We assess candidates for core competencies such as critical thinking, adaptability and a capacity for continuous learning to help ensure every hire can not only excel today but also innovate and lead in the future.
- 11 -
Our Global Hiring Committee continues to play a key role in maintaining our hiring standards, which help drive objectivity. This group of cross-functional senior leaders reviews finalist candidates’ information with a focus on experience and capability. To build robust talent pipelines, we partner with academic institutions and other organizations to support new careers in cybersecurity, promote open roles, proactively reach out to candidates across multiple hiring channels and source candidates with a range of experiences. We also encourage employee referrals.
Onboard & Enable. Each member of our workforce has a unique career journey and individual needs, interests and goals. To that end, we strive to create an environment where everyone feels valued, respected and supported to solve the world’s toughest cybersecurity challenges.
In fiscal 2025, we started to evolve from a traditional training program to a system of AI-powered talent enablement, where we integrate learning and growth throughout the flow of an employee’s daily work. From day 1, new hires embark on a journey that blends in-person connection with personalized digital guidance, including generative AI onboarding roadmaps and AI-curated mentor networks. For ongoing growth, through The Learning Center, our intelligent learning platform, we deliver adaptive learning tracks for employees, including specialized paths for interns, new graduates and individuals joining through acquisitions. We also piloted real-time AI-enabled feedback simulations to coach and equip managers with the skills to guide their teams more effectively.
Development information about core business elements, required company-wide compliance training and information about activities on topics ranging from well-being to collaboration are also offered. To further support our employees to advance up the AI adoption curve, we have offered self-paced online certifications, live training and an experimentation challenge that encouraged peer-driven use cases and employees voting to select the finalists. We will continue our enablement journey, using employee questions and feedback to offer both practical and role-specific use cases to help increase productivity and new skill acquisition. On average, employees completed 36 hours of development during fiscal 2025.
Listen & Engage. We aim to foster engagement and help employees feel connected to our mission and values. Through our comprehensive approach, we use in-person and virtual channels to provide a regular flow of information to and between employees and leadership. These channels include company meetings, digital displays across our sites, our intranet, regular email communications, an active Slack platform, pulse surveys, a peer-to-peer recognition platform and regular two-way dialogue—such as small, in-person listening sessions hosted by our chief executive officer.
Employee sentiment is also collected and measured from external sources, such as Glassdoor and Comparably. In addition, based on employee participation in an anonymous survey, the Best Practice Institute has certified Palo Alto Networks as one of the “Top 100 Global Most Loved Workplaces” since 2021. Palo Alto Networks has been recognized by Comparably for “Best Leadership Teams” and “Best Company Outlook”, in addition to other employer of choice awards. Our chief executive officer has also earned a 91% employee approval rating on Glassdoor, a top percentile score.
In addition to our formal, company-wide, semiannual performance review process, which helps employees set learning and development plans, we believe in always-on performance feedback. Further providing engagement are eleven Employee Network Groups, open to all employees, that leverage different perspectives to build, understand and support our culture.
Compensation & Benefits. We offer employees competitive compensation and our flexible benefits plans include a variety of health, time off, wellness and voluntary benefits. Our pay strategy, which includes base salary, cash bonus programs, and equity awards, focuses on compensation based on individual performance. Palo Alto Networks is a fair pay company and we annually engage a third-party consultancy to analyze our pay practices. Through our flexible benefits programs, employees are able to request reimbursement for a range of lifestyle items including fitness, caregiving and education. Additionally, through our Giving+ program, employees can request monetary matching of their charitable donations and volunteer time.
Health, Safety & Wellbeing. Our commitment to the health, safety and wellbeing of our employees includes providing tools, resources and benefits focused on physical, mental and emotional wellbeing. This includes courses designed to equip employees with the knowledge to work safely, safety awareness campaigns and a mental health hub on our employee intranet.
CORPORATE RESPONSIBILITY
Our Corporate Responsibility (CR) strategy supports our company's purpose of a safe and secure world, and is informed through many inputs, including our business strategy and objectives, ongoing stakeholder engagement, investor and customer interests, benchmarking of industry best practices, regulatory developments and more. We execute meaningful CR initiatives that include advancing environmental sustainability, investing in people and operating with integrity.
Advance Environmental Sustainability. Palo Alto Networks is doing our part to limit global warming to less than 1.5°C. Our decarbonization pathway includes implementing operational efficiencies, procuring 100% renewable electricity, targeting greenhouse gas emissions reductions across our value chain and making progress on our science-based targets. We continue to be recognized by CDP (formerly Carbon Disclosure Project) as a “Supplier Engagement Assessment A-list.” We report progress towards our goals in our annual Corporate Responsibility report.
- 12 -
Invest in People. In addition to our People Strategy described in the section titled “Human Capital” above, we continue to communicate our expectations regarding labor standards, business practices and workplace health and safety conditions to our supply chain through our Global Supplier Code of Conduct. During fiscal 2025, we maintained our affiliate membership in the Responsible Business Alliance. As a company built on trust, continuing to be a leader in responsible business practices and social impact supports our corporate strategy. We made charitable grants through our donor-advised fund to support nonprofit organizations providing services in areas such as cybersecurity education and expanding pathways to cyber careers. We maintained our work to provide cybersecurity curriculum to schools, universities and nonprofit organizations to help prepare people for careers in cybersecurity.
Operate with Integrity. Integrity is one of our core values. Employees, contractors and suppliers are informed about our governance expectations, including through our Codes of Conduct, compliance training programs and ongoing communications. The Governance and Sustainability Committee of the board of directors provides primary oversight of corporate responsibility and the board of directors and applicable committees receive regular updates on corporate responsibility topics.
AVAILABLE INFORMATION
Our website is located at www.paloaltonetworks.com, and our investor relations website is located at investors.paloaltonetworks.com. Our Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, and amendments to reports filed or furnished pursuant to Sections 13(a) and 15(d) of the Securities Exchange Act of 1934, as amended (the “Exchange Act”), are available free of charge on the Investors portion of our website as soon as reasonably practicable after we electronically file such material with, or furnish it to, the Securities and Exchange Commission (“SEC”). We also provide a link to the section of the SEC’s website at www.sec.gov that has all of our public filings, including Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, all amendments to those reports, our Proxy Statements, and other ownership-related filings.
We also use our investor relations website as a channel of distribution for important company information. For example, webcasts of our earnings calls and certain events we participate in or host with members of the investment community are on our investor relations website. Additionally, we announce investor information, including news and commentary about our business and financial performance, SEC filings, notices of investor events, and our press and earnings releases, on our investor relations website. Investors and others can receive notifications of new information posted on our investor relations website in real time by signing up for email alerts and RSS feeds. Further corporate governance information, including our corporate governance guidelines, board committee charters, and code of conduct, is also available on our investor relations website under the heading “Governance.” The contents of our websites are not incorporated by reference into this Annual Report on Form 10-K or in any other report or document we file with the SEC, and any references to our websites are intended to be inactive textual references only. All trademarks, trade names, or service marks used or mentioned herein belong to their respective owners.
- 13 -
Item 1A. Risk Factors
Our operations and financial results are subject to various risks and uncertainties including those described below. The risks and uncertainties described below are not the only ones we face. Additional risks and uncertainties that we are unaware of, or that we currently believe are not material, also may become important factors that affect us. If any of the following risks or others not specified below materialize, our business, financial condition, and operating results could be materially adversely affected, and the market price of our common stock could decline. In addition, the impacts of any worsening of the economic environment may exacerbate the risks described below, any of which could have a material impact on us.
Risk Factor Summary
Our business is subject to numerous risks and uncertainties. These risks include, but are not limited to, the following:
-
Our operating results may be adversely affected by unfavorable economic and market conditions and the uncertain geopolitical environment.
-
Our business and operations have experienced growth in recent periods, and if we do not effectively manage any future growth or are unable to improve our systems, processes, and controls, our operating results could be adversely affected.
-
Our revenue growth rate in recent periods may not be indicative of our future performance, and we may not be able to maintain profitability, which could cause our business, financial condition, and operating results to suffer.
-
Our operating results may vary significantly from period to period, which makes our results difficult to predict and could cause our results to fall short of expectations, and such results may not be indicative of future performance.
-
Seasonality may cause fluctuations in our revenue.
-
If we are unable to sell new and additional product, subscription, and support offerings to our end-customers, especially to large enterprise customers, our future revenue and operating results will be harmed.
-
If we are unable to attract new customers, our future results of operations could be harmed.
-
We rely on revenue from subscription and support offerings, and because we recognize revenue from subscription and support over the term of the relevant service period, downturns or upturns in sales or renewals of these subscription and support offerings are not immediately reflected in full in our operating results.
-
The sales prices of our products, subscriptions, and support offerings may decrease, which may reduce our revenue and gross profits and adversely impact our financial results.
-
We rely on our channel partners to sell substantially all of our products, including subscriptions and support, and if these channel partners fail to perform, our ability to sell and distribute our products and subscriptions will be limited and our operating results will be harmed.
-
We are exposed to the credit and liquidity risk of our customers, and to credit exposure in weakened markets, which could result in material losses.
-
A portion of our revenue is generated by sales to government entities, which are subject to a number of challenges and risks.
-
We face intense competition in our market and we may lack sufficient financial or other resources to maintain or improve our competitive position.
-
We have and may in the future acquire other businesses (including CyberArk), which could subject us to adverse claims or liabilities, require significant management attention, disrupt our business, adversely affect our operating results, may not result in the expected benefits of such acquisitions, and may dilute stockholder value.
-
We may not complete the acquisition of CyberArk within the timeframe we anticipate or at all, which could negatively impact our future business and financial results.
-
As a result of the CyberArk acquisition, we anticipate that the scope and size of our business will substantially change and result in certain incremental risks, including increased competition.
-
If we do not accurately predict, prepare for, and respond promptly to rapidly evolving technological and market developments and successfully manage product and subscription introductions and transitions to meet changing end-customer needs in the enterprise security industry, our competitive position and prospects will be harmed.
-
Issues in the development and deployment of AI may result in reputational harm and legal liability and could adversely affect our results of operations.
-
A network or data security incident may allow unauthorized access to our network or data, harm our reputation, create additional liability, and adversely impact our financial results.
-
Defects, errors, or vulnerabilities in our products, subscriptions, or support offerings, the failure of our products or subscriptions to block a virus or prevent a security breach or incident, misuse of our products, or risks of product liability claims could harm our reputation and adversely impact our operating results.
- 14 -
-
Our ability to sell our products and subscriptions is dependent on the quality of our technical support services and those of our channel partners, and the failure to offer high-quality technical support services could have a material adverse effect on our end-customers’ satisfaction with our products and subscriptions, our sales, and our operating results.
-
Claims by others that we infringe their intellectual property rights could harm our business.
-
Our proprietary rights may be difficult to enforce or protect, which could enable others to copy or use aspects of our products or subscriptions without compensating us.
-
Our use of open source software in our products and subscriptions could negatively affect our ability to sell our products and subscriptions and subject us to possible litigation.
-
We license technology from third parties, and our inability to maintain those licenses could harm our business.
-
Because we depend on manufacturing partners to build and ship our hardware products, we are susceptible to manufacturing and logistics delays and pricing fluctuations that could prevent us from shipping customer orders on time, if at all, or on a cost-effective basis, which may result in the loss of sales and end-customers.
-
Managing the supply of our hardware products and product components is complex. Insufficient supply and inventory would result in lost sales opportunities or delayed revenue, while excess inventory would harm our gross margins.
-
Our hardware products contain key components from limited sources of supply, including outside the United States, and we are susceptible to supply shortages, supply changes, and international regulations, which, in certain cases, have disrupted or delayed our scheduled product deliveries to our end-customers, increased our costs and may result in the loss of sales and end-customers.
-
If we are unable to attract, retain, and motivate our key technical, sales, and management personnel, our business could suffer.
-
We generate a significant amount of revenue from sales to distributors, resellers, and end-customers outside of the United States, and we are therefore subject to a number of risks associated with international sales and operations.
-
We are exposed to fluctuations in foreign currency exchange rates, which could negatively affect our financial condition and operating results.
-
We face risks associated with having operations and employees located in Israel.
-
We are subject to international trade regulations and governmental export and import controls that could subject us to liability or impair our ability to compete in international markets.
-
We may incur increased costs to comply with privacy and data protection laws and, if we fail to comply, we could be subject to government enforcement actions, private litigation and adverse publicity.
-
We may have exposure to tax liabilities that are greater than anticipated.
-
If ou
Showing the first 8K of 133K characters. Open the full section
Item 1B. Unresolved Staff Comments
Not applicable.
Item 1C. Cybersecurity
As a global cybersecurity provider, cybersecurity risk management is an integral part of our overall enterprise risk management program. We recognize the critical importance that a strong cybersecurity risk management program plays in maintaining the trust and confidence of our customers, end users, business partners, stockholders and employees. We have established processes and procedures for identifying, evaluating, and responding to risks from cybersecurity threats, including any potential unauthorized access to our information systems that may result in adverse effects on the confidentiality, integrity, or availability of our information systems, data, or information assets.
Cybersecurity Risk Management and Strategy
Our cybersecurity risk management program includes written policies, standards, and procedures for maintaining data privacy, product security and information security to mitigate cybersecurity risks, and to identify, evaluate and respond to cybersecurity threats, vulnerabilities and incidents. Our cybersecurity risk management program and strategy is implemented across several areas, which include, but are not limited to, the following:
- Information Security. We maintain a written information security program, which provides for policies, standards, guidelines, and administrative, technical and physical safeguards that we believe are reasonably designed, in light of the nature, size and complexity of our operations, to protect the resiliency of our operations and the confidentiality, integrity, and availability of our information systems, data, and information assets. The organizational, administrative and technical measures we implement are based on recognized security frameworks established by the National Institute of Standards and Technology, security measures aligned with the ISO/IEC 27000 series of standards, and other generally recognized industry standards. The program is assessed regularly and in light of new and emerging cybersecurity risks.
- 37 -
-
Technical Safeguards and Product Security. We deploy and maintain a variety of technologies to prevent and detect cybersecurity threats across the network, endpoint and cloud. We also apply security-by-design principles in our software development lifecycle, track vulnerabilities of open-source software, and run internal and external network scans at least weekly and after any meaningful change in our network configuration. We conduct regular application security assessments, including our assessments for internet-facing applications that collect, transmit, or display end user data. We also employ tooling in certain areas to help prevent deviations from policy.
-
Incident Response and Reporting. We maintain incident response and recovery protocols to enable prompt, effective and orderly identification, evaluation, management, and disposition of actual and potential security threats and incidents, including for purposes of escalation and internal and external-notification steps. We maintain a cross-functional incident response team, including senior representatives from information security, information technology, product, legal, privacy, communications, and finance, that is involved in assessing cybersecurity threats and incidents, assigning severity levels, and evaluating the potential impact, including the potential impact on our business strategy, results of operations and financial condition. This allows for prompt direction of appropriate personnel and resources for incident management and response, and internal notification to appropriate members of management, which may include our chief executive officer, chief product and technology officer, vice president acting as chief information security officer, general counsel, chief financial officer, and/or chief accounting officer, and the security committee of our board of directors (the “Security Committee”). The protocols also establish steps designed to publicly report and/or alert external stakeholders as and when required by applicable law or otherwise determined appropriate.
-
Third-Party Risk Management. We maintain a risk-based approach to identifying and overseeing cybersecurity risks presented by certain third parties, including vendors, service providers, suppliers, operations parties, and other external users of our systems, as well as the systems of third parties that could adversely impact our business in the event of a cybersecurity incident affecting those third-party systems. This includes a security process to conduct due diligence prior to engaging contractors and vendors and assess the security capabilities of subcontractors and vendors on a periodic basis.
-
Risk and Readiness Assessments. We engage in at least quarterly assessments and testing of the effectiveness of our cybersecurity risk management program and incident response protocols that are designed to identify and evaluate vulnerabilities and weaknesses, address cybersecurity threats and test our readiness to respond to cybersecurity incidents. These efforts include, but are not limited to, threat modeling, vulnerability scans, penetration testing, audits, and tabletop exercises. We regularly engage third parties to perform assessments on our cybersecurity measures, such as audits and independent reviews of our compliance with various security compliance standards, including those established by the American Institute of Certified Public Accountants, operating effectiveness and penetration tests. The results of such assessments are reported to management and we adjust our cybersecurity policies, standards, processes and practices as necessary based on the information provided by these assessments, audits and reviews.
-
Awareness and Training. We provide regular training for educating employees about corporate policies and procedures and information security designed to provide our employees with knowledge of best practices and effective tools for safeguarding our data and assets and reducing security risks based on the human threat vector. Our information security compliance training, data protection training, and code of conduct training is mandatory for all employees.
-
Governance. As discussed in more detail below under the heading, “Cybersecurity Governance,” our board of directors’ has delegated oversight of enterprise security risk management, including, but not limited to, cybersecurity risk management to the Security Committee. As part of our cybersecurity risk management procedures, senior members of management and the Security Committee are informed regarding security events based on established reporting thresholds, and are provided ongoing updates regarding any such meaningful threat or incident.
We have not identified any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, that have materially impacted or are reasonably likely to materially impact us, including our business strategy, results of operations, or financial condition, to date. However, we face ongoing and increasing cybersecurity risks, including from threat actors that are becoming more sophisticated and effective over time, and we can provide no assurance that there will not be incidents in the future or that past or future threats or incidents will not materially affect us, including our business strategy, results of operations, or financial conditions. For additional information regarding these risks, please refer to Part I, Item 1A, “Risk Factors,” in this Form 10-K, including, but not limited to, the risk factor entitled “A network or data security incident may allow unauthorized access to our network or data, harm our reputation, create additional liability, and adversely impact our financial results.”
- 38 -
Cybersecurity Governance
The Security Committee, which is composed of our independent directors and chaired by our chief product and technology officer, facilitates our board of directors’ responsibility for oversight of security matters, including product security, data security, cybersecurity, security risk management, risk exposure and related controls and enterprise risk management related to these risks. The Security Committee reports regularly to the Board following meetings of the Security Committee with respect to its review and assessment of security matters and other matters that are relevant to the Security Committee’s discharge of its responsibilities. The Security Committee meets quarterly to review with our vice president acting as chief information security officer and other members of management, which may include our chief executive officer, chief product and technology officer, chief financial officer, and general counsel, our cybersecurity programs, cybersecurity risks, mitigation or remediation strategies, and other matters impacting the committee’s responsibilities.
Management is responsible for day-to-day risk management activities, including identifying, assessing and managing our exposure to cybersecurity risks, establishing processes and procedures to ensure that potential cybersecurity risk exposures are monitored, implementing appropriate mitigation or remediation measures as needed, and maintaining cybersecurity risk management programs. Our vice president acting as chief information security officer is responsible for defining, overseeing, managing, implementing, and reviewing compliance with the information security programs described above under the heading “Cybersecurity Risk Management and Strategy.” This vice president receives regular reports from our information security team and monitors the prevention, detection, and mitigation or remediation of cybersecurity risks. In addition, as described in further detail above under the heading “Cybersecurity Risk Management and Strategy,” a cross functional team is involved in assessing and managing the risks from cybersecurity threats and incidents, and reporting information about risks to the Security Committee.
Our information security team consists of dedicated personnel who are experienced information systems security professionals and information security managers with many years of experience across a variety of technology sub-specialties. In particular, our vice president acting as chief information security officer has extensive experience in the management of cybersecurity risk management programs, having served in various roles in information technology and security for over 25 years. In addition, six of the eleven members of our board of directors have expertise in overseeing cybersecurity and information security management.
Item 2. Properties
Our corporate headquarters is located in Santa Clara, California, where we lease approximately 941,000 square feet of space under three lease agreements that expire in July 2028, with options to extend the lease terms through July 2046. We also lease space for personnel around the world, including Israel and India. In addition, we provide our cloud-based subscription offerings through data centers operated under co-location arrangements in the United States, Europe, and Asia. Refer to Note 12. Leases in Part II, Item 8 of this Annual Report on Form 10-K for more information on our operating leases. Additionally, we own 10.4 acres of land adjacent to our headquarters in Santa Clara, California, which we intend to develop to accommodate future expansion, the speed of which development has been slowed due to the current environment.
We believe that our current facilities are adequate to meet our current needs. We intend to expand our facilities or add new facilities as we add employees and enter new geographic markets, and we believe that suitable additional or alternative space will be available as needed to accommodate ongoing operations and any such growth. However, we expect to incur additional expenses in connection with such new or expanded facilities.
Item 3. Legal Proceedings
The information set forth under the “Litigation” subheading in Note 13. Commitments and Contingencies in Part II, Item 8 of this Annual Report on Form 10-K is incorporated herein by reference.
Item 4. Mine Safety Disclosures
Not applicable.
- 39 -
Part II
Item 5. Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities
Market Information
Our common stock, $0.0001 par value per share, is traded on the Nasdaq Global Select Market under the symbol “PANW.”
Holders of Record
As of August 18, 2025, there were 565 holders of record of our common stock. Because many of our shares of common stock are held by brokers and other institutions on behalf of stockholders, we are unable to estimate the total number of stockholders represented by these record holders.
Dividend Policy
We have never declared or paid, and do not anticipate declaring or paying in the foreseeable future, any cash dividends on our capital stock. Any future determination as to the declaration and payment of dividends, if any, will be at the discretion of our board of directors, subject to applicable laws, and will depend on then existing conditions, including our financial condition, operating results, contractual restrictions, capital requirements, business prospects, and other factors our board of directors may deem relevant.
Securities Authorized for Issuance under Equity Compensation Plans
See Part III, Item 12 “Security Ownership of Certain Beneficial Owners and Management and Related Stockholder Matters” of this Annual Report on Form 10-K for more information regarding securities authorized for issuance.
Recent Sales of Unregistered Equity Securities
During the three months ended July 31, 2025, holders of the 2025 Notes converted $382.9 million in aggregate principal amount of the 2025 Notes, which we repaid in cash. We also issued 5.6 million shares of our unregistered common stock to the holders of the 2025 Notes for the conversion value in excess of the principal amount. These shares of our common stock were issued in reliance on the exemption from registration provided by Section 3(a)(9) of the Securities Act of 1933, as amended (the “Securities Act”).
Purchases of Equity Securities by the Issuer and Affiliated Purchasers
In February 2019, we announced that our board of directors authorized a $1.0 billion share repurchase program, which is funded from available working capital. We subsequently announced additional increases to this share repurchase program, bringing the total authorization to $4.1 billion, with $1.0 billion remaining as of July 31, 2025. The expiration date of this repurchase authorization was extended to December 31, 2025, and our repurchase program may be suspended or discontinued at any time. Repurchases under our program are to be made at management’s discretion on the open market, through privately negotiated transactions, transactions structured through investment banking institutions, block purchase techniques, 10b5-1 trading plans, or a combination of the foregoing. During the three months ended July 31, 2025, we did not repurchase any shares pursuant to our share repurchase program.
- 40 -
Stock Price Performance Graph
This performance graph shall not be deemed “filed” for purposes of Section 18 of the Securities Exchange Act of 1934, as amended (the “Exchange Act”), or incorporated by reference into any filing of Palo Alto Networks, Inc. under the Securities Act of 1933, as amended, or the Exchange Act, except as shall be expressly set forth by specific reference in such filing.
This performance graph compares the cumulative total return on our common stock with that of the Nasdaq 100 Index, the Standard & Poor’s 500 Index, and the Standard & Poor’s 500 Information Technology Index for the five years ended July 31, 2025. This performance graph assumes $100 was invested on July 31, 2020, in each of the common stock of Palo Alto Networks, Inc., the Nasdaq 100 Index, the Standard & Poor’s 500 Index, and the Standard & Poor’s 500 Information Technology Index, and assumes the reinvestment of any dividends. The stock price performance on this performance graph is not necessarily indicative of future stock price performance.
Palo Alto Networks, Inc. Comparison of Total Return Performance

| Company/Index | 7/31/2020 | 7/31/2021 | 7/31/2022 | 7/31/2023 | 7/31/2024 | 7/31/2025 | ||||||||||||||||||||||||||||||||
| Palo Alto Networks, Inc. | $ | 100.00 | $ | 155.93 | $ | 195.02 | $ | 293.01 | $ | 380.66 | $ | 407.00 | ||||||||||||||||||||||||||
| Nasdaq 100 Index | $ | 100.00 | $ | 138.19 | $ | 120.50 | $ | 147.94 | $ | 183.34 | $ | 221.52 | ||||||||||||||||||||||||||
| S&P 500 Index | $ | 100.00 | $ | 136.45 | $ | 130.11 | $ | 147.05 | $ | 179.62 | $ | 208.95 | ||||||||||||||||||||||||||
| S&P 500 Information Technology Index | $ | 100.00 | $ | 140.03 | $ | 132.31 | $ | 167.84 | $ | 226.91 | $ | 280.58 |
Item 6. [Reserved]
- 41 -
Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations
The following discussion and analysis of our financial condition and results of operations should be read in conjunction with our consolidated financial statements and related notes appearing elsewhere in this Annual Report on Form 10-K. The following discussion and analysis contains forward-looking statements based on current expectations and assumptions that are subject to risks and uncertainties, which could cause our actual results to differ materially from those anticipated or implied by any forward-looking statements. Factors that could cause or contribute to such differences include, but are not limited to, those discussed in this Annual Report on Form 10-K, and in particular, the risks discussed under the caption “Risk Factors” in Part I, Item 1A of this report.
Our Management’s Discussion and Analysis of Financial Condition and Results of Operations (“MD&A”) is organized as follows:
-
Overview. A discussion of our business and overall analysis of financial and other highlights in order to provide context for the remainder of MD&A.
-
Key Financial Metrics. A summary of our U.S. GAAP and non-GAAP key financial metrics, which management monitors to evaluate our performance.
-
Results of Operations. A discussion of the nature and trends in our financial results and an analysis of our financial results comparing fiscal 2025 to fiscal 2024. For discussion and analysis related to our financial results comparing fiscal 2024 to 2023, refer to Part II, Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations in our Annual Report on Form 10-K for fiscal 2024, which was filed with the Securities and Exchange Commission on September 6, 2024.
-
Liquidity and Capital Resources. An analysis of changes on our balance sheets and cash flows, and a discussion of our financial condition and our ability to meet cash needs.
-
Critical Accounting Estimates. A discussion of our accounting policies that require critical estimates, assumptions, and judgments.
-
Recent Accounting Pronouncements. A discussion of expected impacts of impending accounting changes on financial information to be reported in the future.
Overview
Our mission is to be the cybersecurity partner of choice for enterprises, organizations, service providers, and government entities to protect our digital way of life. Our cybersecurity platforms and services help secure enterprise users, networks, clouds, and endpoints by delivering comprehensive cybersecurity backed by artificial intelligence (“AI”) and automation. A key element of our strategy is to help our customers simplify their security architectures through consolidating disparate point products. We execute on this strategy by developing our capabilities and packaging our offerings into platforms which are able to cover many of our customers’ needs in the markets in which we operate. Our platformization strategy combines various products and services into a tightly integrated architecture for more secure, faster, and cost-effective outcomes.
Network Security
Our network security platform is designed to deliver complete zero trust solutions to our customers. The platform includes:
-
Secure Access Service Edge (“SASE”). Prisma® Access, when combined with Prisma SD-WAN, provides a comprehensive single-vendor SASE offering that is used to secure remote workforces and cloud-delivered branch offices. Prisma Access Browser further extends SASE security and data protection to the end user device, providing workers with freedom to access business applications securely using our secure browser from any device.
-
Next-Generation Firewalls. Our hardware ML-Powered Next-Generation Firewalls (“NGFWs”) secure on-premises environments including campus locations and data centers. Our software NGFWs secure cloud networks.
-
Cloud-Delivered Security Services (“CDSS”). Our network security platform integrates a suite of CDSS that complements our SASE and Firewall solutions. These include Advanced Threat Prevention, Advanced WildFire®, Advanced URL Filtering, Advanced DNS Security, IoT/OT Security, GlobalProtect®, Prisma Access Agent, Enterprise Data Loss Prevention (“Enterprise DLP”), AI for IT Operations (“AIOps”), Software as a Service (“SaaS”) Security, and AI Access Security. Through these add-on services, our customers are able to secure their content, applications, users, and devices across their entire organization.
-
Prisma AIRS. Prisma AIRS is a comprehensive AI security platform that has been designed to protect customers’ entire AI ecosystem by providing AI model scanning, posture management, red teaming, run-time security, and AI agent security.
- 42 -
- Strata Cloud Manager (“SCM”). SCM, our network security management solution, centrally manages network security across all remote workers, branches, headquarters, campuses, and cloud. SCM leverages AI to simplify and strengthen network security by enabling customers to proactively pinpoint vulnerabilities, gain real-time remediation recommendations, and enhance overall digital experiences, thereby reducing operational burden. This comprehensive solution includes Strata Copilot, which offers a natural language interface for enhanced insights and guided remediation, and integrates Autonomous Digital Experience Monitoring (“ADEM”) to proactively maintain infrastructure health, facilitate AI-driven one-click troubleshooting, and ensure seamless end-user performance across the enterprise.
Security Operations
Our AI-powered Cortex platform transforms end-to-end security operations with unified data, AI, and automation for more secure, faster, and cost effective outcomes. We have consolidated our industry-leading Security Operations and Cloud Security capabilities on a single comprehensive platform to provide centralized visibility, proactive protection, real-time prevention, AI-driven insights, and automated remediation across enterprise and cloud.
-
Security Operations. We deliver the next generation of security operations capabilities that unifies standalone Security Information and Event Management (“SIEM”) tools, endpoint security, security automation, cloud detection and response (“CDR”), as well as attack surface management (“ASM”) capabilities on our Cortex® platform. These include Cortex XSIAM®, for AI-powered security operations replacing traditional SIEM tools, Cortex XDR®, for the prevention, detection, and response to complex cybersecurity attacks, Cortex XSOAR®, for security orchestration, automation, and response (“SOAR”), and Cortex Xpanse®, for ASM.
-
Cloud Security. We deliver comprehensive security across the cloud application development lifecycle through Cortex Cloud, delivered as a scalable SaaS offering. As a comprehensive Cloud Native Application Protection Platform (“CNAPP”) combined with CDR, Cortex Cloud secures multi- and hybrid-cloud environments for applications, data, generative AI (“GenAI”) ecosystem, and the cloud native technology stack across the full development lifecycle, from code to cloud to security operations. As part of the Cortex Cloud platform, customers can expand from Cortex Cloud to our security operations offerings available on a single user experience and unified agent. We also offer our VM-Series and CN-Series virtual firewalls for inline network security on multi- and hybrid-cloud environments.
Threat Intelligence and Advisory Services
- Unit 42 brings together world-renowned expertise across threat research, incident response, and security consulting to deliver intelligence-driven, response-ready outcomes that help customers reduce cyber risk. Our elite consultants serve as trusted advisors to our customers by assessing and testing their security controls against sophisticated threats, transforming their security strategy with a threat-informed approach, and responding to security incidents on behalf of our clients. Additionally, Unit
Showing the first 8K of 79K characters. Open the full section
Item 7A. Quantitative and Qualitative Disclosures About Market Risk
Foreign Currency Exchange Risk
Our sales contracts are primarily denominated in U.S. dollars. A portion of our operating expenditures are denominated in foreign currencies, making them subject to fluctuations in foreign currency exchange rates. Additionally, fluctuations in foreign currency exchange rates may cause us to recognize transaction gains and losses in our statement of operations. Foreign currency remeasurement gains and losses and foreign currency transaction gains and losses have not had a significant impact to our consolidated financial statements.
We enter into foreign currency derivative contracts with maturities of 24 months or less, which we designate as cash flow hedges, to manage the foreign currency exchange risk associated with our revenue and operating expenditures. We also enter into foreign currency derivative contracts that are not designated as hedging instruments to hedge a portion of our outstanding monetary assets and liabilities denominated in foreign currencies. These foreign currency derivative contracts reduce but do not entirely eliminate the effect of foreign exchange rate fluctuations.
A hypothetical 10% change in foreign exchange rates on monetary assets and liabilities would not be material to our financial condition or results of operations after taking into consideration the effect of foreign currency forward contracts in place as of July 31, 2025. The effectiveness of our existing hedging transactions and the availability and effectiveness of any hedging transactions we may decide to enter into in the future may be limited, and we may not be able to successfully hedge our exposure, which could adversely affect our financial condition and results of operations. Refer to Note 6. Derivative Instruments in Part II, Item 8 of this Annual Report on Form 10-K for more information.
As our international operations grow, our risks associated with fluctuations in foreign currency exchange rates will become greater, and we will continue to reassess our approach to managing this risk. In addition, a weakening U.S. dollar can increase the costs of our international expansion and a strengthening U.S. dollar can increase the real cost of our products and services to our end-customers outside of the United States, leading to delays in the purchase of our products and services. For additional information, see the risk factor entitled “We are exposed to fluctuations in foreign currency exchange rates, which could negatively affect our financial condition and operating results.” in Part 1, Item 1A of this Annual Report on Form 10-K.
Interest Rate Risk
The primary objectives of our investment activities are to preserve principal, provide liquidity, and maximize income without significantly increasing risk. Most of the securities we invest in are subject to interest rate risk. To minimize this risk, we maintain a diversified portfolio of cash, cash equivalents, and investments, consisting only of investment-grade securities. To assess the interest rate risk, we performed a sensitivity analysis to determine the impact a change in interest rates would have on the value of the investment portfolio. Based on investment positions as of July 31, 2025, a hypothetical 100 basis point increase in interest rates across all maturities would result in a $132.3 million decline in the fair market value of the portfolio. Such losses would only be realized if we sold the investments prior to maturity. Conversely, a hypothetical 100 basis point decrease in interest rates would lead to a $134.7 million increase in the fair market value of the portfolio.
- 56 -
Item 8. Financial Statements and Supplementary Data
Index To Consolidated Financial Statements
- 57 -
Report of Independent Registered Public Accounting Firm
To the Stockholders and the Board of Directors of Palo Alto Networks, Inc.
Opinion on the Financial Statements
We have audited the accompanying consolidated balance sheets of Palo Alto Networks, Inc. (the Company) as of July 31, 2025 and 2024, the related consolidated statements of operations, comprehensive income, stockholders’ equity and cash flows for each of the three years in the period ended July 31, 2025, and the related notes (collectively referred to as the “consolidated financial statements”). In our opinion, the consolidated financial statements present fairly, in all material respects, the financial position of the Company at July 31, 2025 and 2024, and the results of its operations and its cash flows for each of the three years in the period ended July 31, 2025, in conformity with U.S. generally accepted accounting principles.
We also have audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the Company’s internal control over financial reporting as of July 31, 2025, based on criteria established in Internal Control—Integrated Framework issued by the Committee of Sponsoring Organizations of the Treadway Commission (2013 framework), and our report dated August 29, 2025 expressed an unqualified opinion thereon.
Basis for Opinion
These financial statements are the responsibility of the Company’s management. Our responsibility is to express an opinion on the Company’s financial statements based on our audits. We are a public accounting firm registered with the PCAOB and are required to be independent with respect to the Company in accordance with the U.S. federal securities laws and the applicable rules and regulations of the Securities and Exchange Commission and the PCAOB.
We conducted our audits in accordance with the standards of the PCAOB. Those standards require that we plan and perform the audit to obtain reasonable assurance about whether the financial statements are free of material misstatement, whether due to error or fraud. Our audits included performing procedures to assess the risks of material misstatement of the financial statements, whether due to error or fraud, and performing procedures that respond to those risks. Such procedures included examining, on a test basis, evidence regarding the amounts and disclosures in the financial statements. Our audits also included evaluating the accounting principles used and significant estimates made by management, as well as evaluating the overall presentation of the financial statements. We believe that our audits provide a reasonable basis for our opinion.
Critical Audit Matter
The critical audit matters communicated below are matters arising from the current period audit of the financial statements that were communicated or required to be communicated to the audit committee and that: (1) relate to accounts or disclosures that are material to the financial statements and (2) involved our especially challenging, subjective or complex judgments. The communication of critical audit matters does not alter in any way our opinion on the consolidated financial statements, taken as a whole, and we are not, by communicating the critical audit matters below, providing separate opinions on the critical audit matters or on the accounts or disclosures to which they relate.
- 58 -
REVENUE RECOGNITION
| Description of the Matter | As described in Note 1 to the consolidated financial statements, the Company’s contracts with customers sometimes contain multiple performance obligations, which are accounted for separately if they are distinct. In such cases, the transaction price is then allocated to the distinct performance obligations on a relative standalone selling price basis, and revenue is recognized when control of the distinct performance obligation is transferred. For example, product revenue is recognized at the time of hardware shipment or delivery of software license, and subscription and support revenue is recognized over time as the services are performed. Auditing the Company’s revenue recognition was complex, including the identification and determination of distinct performance obligations and the timing of revenue recognition. For example, there were certain customer arrangements with nonstandard terms and conditions that required judgment to determine the distinct performance obligations and the impact on the timing of revenue recognition. | ||||
| How We Addressed the Matter in Our Audit | We obtained an understanding, evaluated the design and tested the operating effectiveness of the Company’s process and controls to identify and determine the distinct performance obligations and the timing of revenue recognition. To test the identification and determination of the distinct performance obligations and the timing of revenue recognition, our audit procedures included, among others, reading the executed contract and other contractual documents to understand the contract, identifying the performance obligation(s), determining the distinct performance obligations, and evaluating the timing of revenue recognition for a sample of individual sales transactions. We evaluated the accuracy of the Company’s contract summary documentation, specifically related to the identification and determination of distinct performance obligations and the timing of revenue recognition. | ||||
VALUATION OF CONTINGENT CONSIDERATION LIABILITY IN CONNECTION WITH THE ACQUISITION OF IBM QRADAR ASSETS
| Description of the Matter | As described in Note 8 to the consolidated financial statements, the Company completed the acquisition of certain IBM QRadar assets on August 31, 2024, for which the purchase consideration included contingent consideration. The Company has determined the fair value of contingent consideration liability to be $513.6 million as of July 31, 2025, using a discounted cash flow valuation technique including an estimate of future cash payments related to customers entering into qualified new transactions with the Company as well as a risk-adjusted discount rate used to present value the expected cash flows. Auditing the Company’s accounting for contingent consideration liability was complex due to estimation uncertainty in the Company’s determination of the fair value due to the significant assumption about customer transactions that will qualify for cash payments under the arrangement. The significant assumption is forward-looking, dependent upon cus |
Showing the first 8K of 179K characters. Open the full section
Item 9. Changes in and Disagreements with Accountants on Accounting and Financial Disclosure
Not applicable.
Item 9A. Controls and Procedures
Evaluation of Disclosure Controls and Procedures
Our management, with the participation of our chief executive officer and chief financial officer, evaluated the effectiveness of our disclosure controls and procedures pursuant to Rule 13a-15(f) under the Securities Exchange Act of 1934, as amended (the “Exchange Act”). In designing and evaluating the disclosure controls and procedures, management recognizes that any controls and procedures, no matter how well designed and operated, can provide only reasonable assurance of achieving the desired control objectives. In addition, the design of disclosure controls and procedures must reflect the fact that there are resource constraints and that management is required to apply its judgment in evaluating the benefits of possible controls and procedures relative to their costs.
Based on our evaluation, our chief executive officer and chief financial officer concluded that, as of July 31, 2025, our disclosure controls and procedures are designed at a reasonable assurance level and are effective to provide reasonable assurance that information we are required to disclose in reports that we file or submit under the Exchange Act is recorded, processed, summarized, and reported within the time periods specified in Securities and Exchange Commission (“SEC”) rules and forms, and that such information is accumulated and communicated to our management, including our chief executive officer and chief financial officer, as appropriate, to allow timely decisions regarding required disclosure.
Management’s Annual Report on Internal Control over Financial Reporting
Our management is responsible for establishing and maintaining adequate internal control over financial reporting as defined in Rules 13a-15(f) under the Exchange Act. Our management assessed the effectiveness of our internal control over financial reporting as of July 31, 2025, based on the framework set forth by the Committee of Sponsoring Organizations of the Treadway Commission (“COSO”) in Internal Control - Integrated Framework (2013 framework). Based on that assessment, management concluded that, as of July 31, 2025, our internal control over financial reporting was effective.
The effectiveness of our internal control over financial reporting as of July 31, 2025 has been audited by Ernst & Young LLP, the independent registered public accounting firm that audits our consolidated financial statements, as stated in their report which is included in Part II, Item 8 of this Annual Report on Form 10-K.
Changes in Internal Control over Financial Reporting
There were no changes in our internal control over financial reporting identified in connection with the evaluation required by Rule 13a-15(d) and 15d-15(d) of the Exchange Act that occurred during the fiscal quarter ended July 31, 2025 that have materially affected, or are reasonably likely to materially affect, our internal control over financial reporting.
- 95 -
Item 9B. Other Information
Trading Plans of Directors and Executive Officers
Set forth below is certain information regarding Rule 10b5-1 trading plans adopted or terminated by our directors and officers (as defined in Rule 16a-1(f)) during the fourth quarter of fiscal 2025. The Rule 10b5-1 trading plans listed below are each intended to satisfy the affirmative defense of Rule 10b5-1(c).
| Name | Title | Date Plan Was Adopted | Date Plan Was Terminated | Original Expiration Date | Total Amount of Common Stock to Be Sold Under the Plan | |||||||||||||||||||||||||||
| Nikesh Arora | Chief Executive Officer | June 24, 2025 | Not applicable | December 24, 2025 or when all shares have been sold | 846,408 | |||||||||||||||||||||||||||
No other officers or directors, as defined in Rule 16a-1(f), adopted, modified, and/or terminated a “Rule 10b5-1 trading arrangement” or a “non-Rule 10b5-1 trading arrangement,” as defined in Regulation S-K Item 408, during the fourth quarter of fiscal 2025.
Item 9C. Disclosure Regarding Foreign Jurisdictions That Prevent Inspections
Not applicable.
- 96 -
Part III
Item 10. Directors, Executive Officers and Corporate Governance
The information required by this item will be contained in our definitive proxy statement to be filed with the SEC in connection with our 2025 annual meeting of stockholders (the “Proxy Statement”), which is expected to be filed not later than 120 days after the end of our fiscal year ended July 31, 2025 and is incorporated herein by reference.
Item 11. Executive Compensation
The information required by this item will be set forth in the Proxy Statement and is incorporated herein by reference.
Item 12. Security Ownership of Certain Beneficial Owners and Management and Related Stockholder Matters
The information required by this item will be set forth in the Proxy Statement and is incorporated herein by reference.
Item 13. Certain Relationships and Related Transactions, and Director Independence
The information required by this item will be set forth in the Proxy Statement and is incorporated herein by reference.
Item 14. Principal Accountant Fees and Services
The information required by this item will be set forth in the Proxy Statement and is incorporated herein by reference.
- 97 -
Part IV
Item 15. Exhibits and Financial Statement Schedules
Documents filed as part of this Annual Report on Form 10-K are as follows:
**1.**Consolidated Financial Statements
Our Consolidated Financial Statements are listed in the “Index to Consolidated Financial Statements” under Part II, Item 8 of this Annual Report on Form 10-K.
**2.**Financial Statement Schedules
Financial statement schedules have been omitted because they are not required, not applicable, not present in amounts sufficient to require submission of the schedule, or the required information is shown in the Consolidated Financial Statements or the notes thereto.
**3.**Exhibits
The following documents are incorporated by reference or are filed with this Annual Report on Form 10-K, in each case as indicated therein (numbered in accordance with Item 601 of Regulation S-K).
Exhibit Index
| Exhibit Number | Exhibit Description | Incorporated by Reference | ||||||||||||||||||||||||||||||||||||
| Form | File No. | Exhibit | Filing Date | |||||||||||||||||||||||||||||||||||
| 2.1*** | Agreement and Plan of Merger, dated as of July 30, 2025, by and among Palo Alto Networks, Inc., Athens Strategies Ltd. and CyberArk Software Ltd. | 8-K | 001-35594 | 2.1 | July 31, 2025 | |||||||||||||||||||||||||||||||||
| 3.1 | Restated Certificate of Incorporation of the Registrant, as amended. | |||||||||||||||||||||||||||||||||||||
| 3.2 | Amended and Restated Bylaws of the Registrant. | 8-K | 001-35594 | 3.1 | August 18, 2025 | |||||||||||||||||||||||||||||||||
| 3.3 | Certificate of Change of Location of Registered Agent and/or Registered Office. | 8-K | 001-35594 | 3.1 | August 30, 2016 | |||||||||||||||||||||||||||||||||
| 4.1 | Description of Registrant’s Securities. | |||||||||||||||||||||||||||||||||||||
| 10.1* | Form of Indemnification Agreement between the Registrant and its directors and officers. | S-1/A | 333-180620 | 10.1 | July 9, 2012 | |||||||||||||||||||||||||||||||||
| 10.2* | 2012 Equity Incentive Plan and related form agreements. | 10-Q | 001-35594 | 10.2 | November 26, 2019 | |||||||||||||||||||||||||||||||||
| 10.3* | Form of 2012 Equity Incentive Plan Performance-Based Restricted Stock Unit Award Agreement. | 10-Q | 001-35594 | 10.4 | November 19, 2021 | |||||||||||||||||||||||||||||||||
| 10.4* | 2021 Equity Incentive Plan, as amended and restated, and related form agreements. | |||||||||||||||||||||||||||||||||||||
| 10.5* | 2012 Employee Stock Purchase Plan, as amended and restated, and related form agreements. | |||||||||||||||||||||||||||||||||||||
| 10.6* | RedLock Inc. 2015 Stock Plan, as amended, and related form agreements under RedLock Inc. 2015 Stock Plan, as amended. | S-8 | 333-227901 | 99.1 | October 19, 2018 | |||||||||||||||||||||||||||||||||
| 10.7* | Cider Security Ltd. 2020 Equity Incentive Plan. | S-8 | 333-268931 | 99.1 | December 21, 2022 | |||||||||||||||||||||||||||||||||
- 98 -
| Exhibit Number | Exhibit Description | Incorporated by Reference | ||||||||||||||||||||||||||||||||||||
| Form | File No. | Exhibit | Filing Date | |||||||||||||||||||||||||||||||||||
| 10.8* | US Sub-Plan to Cider Security Ltd. 2020 Equity Incentive Plan. | S-8 | 333-268931 | 99.2 | December 21, 2022 | |||||||||||||||||||||||||||||||||
| 10.9* | Employee Incentive Compensation Plan, as amended and restated. | 10-Q | 001-35594 | 10.2 | November 25, 2014 | |||||||||||||||||||||||||||||||||
| 10.10 | Clawback Policy, adopted as of August 29, 2017, amended August 14, 2024. | 10-K | 001-35594 | 10.16 | September 6, 2024 | |||||||||||||||||||||||||||||||||
| 10.11* | Amended and Restated Outside Director Compensation Policy (last amended February 12, 2025). | 10-Q | 001-35594 | 10.1 | May 21, 2025 | |||||||||||||||||||||||||||||||||
| 10.12* | Continued Service Policy. | 10-Q | 001-35594 | 10.3 | May 20, 2022 | |||||||||||||||||||||||||||||||||
| 10.13* | Palo Alto Networks, Inc. Deferred Compensation Plan effective June 1, 2022. | 10-K | 001-35594 | 10.23 | September 6, 2022 | |||||||||||||||||||||||||||||||||
| 10.14* | Amendment and Restated Employment Letter between Palo Alto Networks, Inc. and Nir Zuk, dated July 7, 2025. | |||||||||||||||||||||||||||||||||||||
| 10.15* | Offer Letter between the Registrant and Nikesh Arora, dated May 30, 2018. | 8-K | 001-35594 | 10.2 | June 4, 2018 | |||||||||||||||||||||||||||||||||
| 10.16* | Offer Letter between the Registrant and Josh Paul, dated August 5, 2021. | 8-K | 001-35594 | 10.1 | September 8, 2021 | |||||||||||||||||||||||||||||||||
| 10.17* | Confirmatory Employment Letter with Updated Change in Control Protection between the Registrant and Lee Klarich, dated December 19, 2011. | 10-Q | 001-35594 | 10.4 | November 30, 2018 | |||||||||||||||||||||||||||||||||
| 10.18* | Addendum to Employment Offer Letter by and between the Registrant and Dipak Golechha, dated March 17, 2021. | 8-K | 001-35594 | 10.1 | March 19, 2021 | |||||||||||||||||||||||||||||||||
| 10.19* | Addendum to Employment Offer Letter by and between the Registrant and Dipak Golechha, dated February 18, 2022. | 10-Q | 001-35594 | 10.1 | May 20, 2022 | |||||||||||||||||||||||||||||||||
| 10.20* | Employment Offer Letter by and between the Registrant and William “BJ” Jenkins, dated July 27, 2021. | 8-K | 001-35594 | 10.1 | August 12, 2021 | |||||||||||||||||||||||||||||||||
| 10.21* | Addendum to Employment Offer Letter between the Registrant and William “BJ” Jenkins, dated February 18, 2022. | 10-Q | 001-35594 | 10.2 | May 20, 2022 | |||||||||||||||||||||||||||||||||
| 10.22* | Form of Offer Letter between the Registrant and its directors. | 10-Q | 001-35594 | 10.2 | May 21, 2025 | |||||||||||||||||||||||||||||||||
| 10.23** | Amended and Restated Flextronics Manufacturing Services Agreement, by and between the Registrant and Flextronics Telecom Systems Ltd., dated April 1, 2019. | 10-Q | 001-35594 | 10.1 | May 30, 2019 | |||||||||||||||||||||||||||||||||
| 10.24 | Vendor Information Security Terms between the Registrant and Flextronics Telecom Systems Ltd., dated July 23, 2021. | 10-K | 001-35594 | 10.29 | September 3, 2021 | |||||||||||||||||||||||||||||||||
| 10.25 | Lease between the Registrant and Santa Clara Campus Property Owner I LLC, dated May 28, 2015. | 10-K | 001-35594 | 10.29 | September 17, 2015 | |||||||||||||||||||||||||||||||||
| 10.26 | Lease between the Registrant and Santa Clara Campus Property Owner I LLC, dated May 28, 2015. | 10-K | 001-35594 | 10.30 | September 17, 2015 | |||||||||||||||||||||||||||||||||
- 99 -
| Exhibit Number | Exhibit Description | Incorporated by Reference | ||||||||||||||||||||||||||||||||||||
| Form | File No. | Exhibit | Filing Date | |||||||||||||||||||||||||||||||||||
| 10.27 | Lease between the Registrant and Santa Clara Campus Property Owner I LLC, dated May 28, 2015. | 10-K | 001-35594 | 10.31 | September 17, 2015 | |||||||||||||||||||||||||||||||||
| 10.28 | Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated October 7, 2015. | 8-K/A | 001-35594 | 10.1 | October 19, 2015 | |||||||||||||||||||||||||||||||||
| 10.29 | Amendment No. 1 to Lease by and between the Registrant and Santa Clara Phase I Property LLC, dated November 9, 2015. | 10-Q | 001-35594 | 10.2 | November 24, 2015 | |||||||||||||||||||||||||||||||||
| 10.30 | Amendment No. 1 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated November 9, 2015. | 10-Q | 001-35594 | 10.3 | November 24, 2015 | |||||||||||||||||||||||||||||||||
| 10.31 | Amendment No. 1 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated September 16, 2016. | 10-Q | 001-35594 | 10.1 | November 22, 2016 | |||||||||||||||||||||||||||||||||
| 10.32 | Amendment No. 1 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated September 16, 2016. | 10-Q | 001-35594 | 10.2 | November 22, 2016 | |||||||||||||||||||||||||||||||||
| 10.33 | Amendment No. 2 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated September 16, 2016. | 10-Q | 001-35594 | 10.3 | November 22, 2016 | |||||||||||||||||||||||||||||||||
| 10.34 | Amendment No. 2 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated November 16, 2016. | 10-Q | 001-35594 | 10.1 | March 1, 2017 | |||||||||||||||||||||||||||||||||
| 10.35 | Amendment No. 2 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated November 16, 2016. | 10-Q | 001-35594 | 10.2 | March 1, 2017 | |||||||||||||||||||||||||||||||||
| 10.36 | Amendment No. 3 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated November 16, 2016. | 10-Q | 001-35594 | 10.3 | March 1, 2017 | |||||||||||||||||||||||||||||||||
| 10.37 | Amendment No. 3 to Lease by and between the Registrant and Santa Clara EFH LLC, dated June 22, 2017. | 10-K | 001-35594 | 10.40 | September 7, 2017 | |||||||||||||||||||||||||||||||||
| 10.38 | Amendment No. 3 to Lease by and between the Registrant and Santa Clara G LLC, dated June 22, 2017. | 10-K | 001-35594 | 10.41 | September 7, 2017 | |||||||||||||||||||||||||||||||||
| 10.39 | Amendment No. 4 to Lease by and between the Registrant and Santa Clara EFH LLC, dated June 22, 2017. | 10-K | 001-35594 | 10.42 | September 7, 2017 | |||||||||||||||||||||||||||||||||
| 10.40 | Amendment No. 4 to Lease by and between the Registrant and Santa Clara Phase III EFH LLC, dated September 29, 2017. | 10-Q | 001-35594 | 10.5 | November 21, 2017 | |||||||||||||||||||||||||||||||||
| 10.41 | Amendment No. 4 to Lease by and between the Registrant and Santa Clara Phase III G LLC, dated September 29, 2017. | 10-Q | 001-35594 | 10.6 | November 21, 2017 | |||||||||||||||||||||||||||||||||
| 10.42 | Amendment No. 5 to Lease by and between the Registrant and Santa Clara Phase III EFH LLC, dated September 29, 2017. | 10-Q | 001-35594 | 10.7 | November 21, 2017 | |||||||||||||||||||||||||||||||||
| 10.43 | Credit Agreement, dated as of April 13, 2023 among the Registrant, the lenders party thereto and Wells Fargo, National Association, as administrative agent. | 8-K | 001-35594 | 10.1 | April 19, 2023 | |||||||||||||||||||||||||||||||||
- 100 -
| Exhibit Number | Exhibit Description | Incorporated by Reference | ||||||||||||||||||||||||||||||||||||
| Form | File No. | Exhibit | Filing Date | |||||||||||||||||||||||||||||||||||
| 10.44 | Amendment No. 1, dated as of November 22, 2024, to Credit Agreement, dated as of April 13, 2023, among Palo Alto Networks, Inc., the lenders party thereto, and Wells Fargo Bank, National Association, as administrative agent. | 10-Q | 001-35594 | 10.3 | February 14, 2025 | |||||||||||||||||||||||||||||||||
| 10.45 | Form of Warrant Confirmation. | 8-K | 001-35594 | 10.3 | June 8, 2020 | |||||||||||||||||||||||||||||||||
| 19.1** | Insider Trading Policy and Requirements for Trading Plans, as amended and restated. | |||||||||||||||||||||||||||||||||||||
| 21.1 | List of subsidiaries of the Registrant. | |||||||||||||||||||||||||||||||||||||
| 23.1 | Consent of Independent Registered Public Accounting Firm. | |||||||||||||||||||||||||||||||||||||
| 24.1 | Power of Attorney (contained in the signature page to this Annual Report on Form 10-K). | |||||||||||||||||||||||||||||||||||||
| 31.1 | Certification of the Chief Executive Officer pursuant to Section 302(a) of the Sarbanes-Oxley Act of 2002. | |||||||||||||||||||||||||||||||||||||
| 31.2 | Certification of the Chief Financial Officer pursuant to Section 302(a) of the Sarbanes-Oxley Act of 2002. | |||||||||||||||||||||||||||||||||||||
| 32.1† | Certification of Chief Executive Officer pursuant to 18 U.S.C. Section 1350, as adopted pursuant to Section 906 of the Sarbanes-Oxley Act of 2002. | |||||||||||||||||||||||||||||||||||||
| 32.2† | Certification of Chief Financial Officer pursuant to 18 U.S.C. Section 1350, as adopted pursuant to Section 906 of the Sarbanes-Oxley Act of 2002. | |||||||||||||||||||||||||||||||||||||
| 97.1 | Compensation Recovery Policy. | 10-K | 001-35594 | 97.1 | September 6, 2024 | |||||||||||||||||||||||||||||||||
| 101.INS | XBRL Instance Document. | |||||||||||||||||||||||||||||||||||||
| 101.SCH | XBRL Taxonomy Schema Linkbase Document. | |||||||||||||||||||||||||||||||||||||
| 101.CAL | XBRL Taxonomy Calculation Linkbase Document. | |||||||||||||||||||||||||||||||||||||
| 101.DEF | XBRL Taxonomy Definition Linkbase Document. | |||||||||||||||||||||||||||||||||||||
| 101.LAB | XBRL Taxonomy Labels Linkbase Document. | |||||||||||||||||||||||||||||||||||||
| 101.PRE | XBRL Taxonomy Presentation Linkbase Document. | |||||||||||||||||||||||||||||||||||||
| 104 | Cover Page Interactive Data File (formatted as inline XBRL and contained in Exhibit 101). |
- Indicates a management contract or compensatory plan or arrangement.
** Certain portions of this exhibit have been omitted as the Registrant has determined (i) the omitted information is not material and (ii) the omitted information would likely cause harm to the Registrant if publicly disclosed.
*** Schedules omitted pursuant to Item 601(b)(2) of Regulation S-K. The Registrant agrees to furnish supplementally a copy of any omitted schedule to the SEC upon request; provided, however, that the Registrant may request confidential treatment pursuant to Rule 24b-2 of the Securities Exchange Act of 1934, as amended, for any schedules or exhibits so furnished.
† The certifications attached as Exhibit 32.1 and Exhibit 32.2 that accompany this Annual Report on Form 10-K, are not deemed filed with the Securities and Exchange Commission and are not to be incorporated by reference into any filing of the Registrant under the Securities Act of 1933, as amended, or the Securities Exchange Act of 1934, as amended, whether made before or after the date of this Annual Report on Form 10-K, irrespective of any general incorporation language contained in such filing.
Item 16. Form 10-K Summary
Not applicable.
- 101 -
Signatures
Pursuant to the requirements of Section 13 or 15(d) of the Securities Exchange Act of 1934, the Registrant has duly caused this report to be signed on its behalf by the undersigned, thereunto duly authorized, on August 29, 2025.
| PALO ALTO NETWORKS, INC. | |||||
| By: | /s/ NIKESH ARORA | ||||
| Nikesh Arora | |||||
| Chairman and Chief Executive Officer |
- 102 -
Power of Attorney
KNOW ALL THESE PERSONS BY THESE PRESENTS, that each person whose signature appears below constitutes and appoints Nikesh Arora, Dipak Golechha, and Josh Paul, and each of them, as his or her true and lawful attorney-in-fact and agent, with full power of substitution and resubstitution, for him or her and in his or her name, place and stead, in any and all capacities, to sign any and all amendments to this Annual Report on Form 10-K, and to file the same, with all exhibits thereto, and other documents in connection therewith, with the Securities and Exchange Commission, granting unto said attorneys-in-fact and agents, and each of them, full power and authority to do and perform each and every act and thing requisite and necessary to be done in connection therewith, as fully to all intents and purposes as he or she might or could do in person, hereby ratifying and confirming all that said attorneys-in-fact and agents, or any of them, or their, his or her substitutes, may lawfully do or cause to be done by virtue thereof.
Pursuant to the requirements of the Securities Exchange Act of 1934, this report has been signed below by the following persons on behalf of the Registrant and in the capacities and on the dates indicated:
| Signature | Title | Date | ||||||||||||
| /s/ NIKESH ARORA | Chairman, Chief Executive Officer and Director (Principal Executive Officer) | August 29, 2025 | ||||||||||||
| Nikesh Arora | ||||||||||||||
| /s/ DIPAK GOLECHHA | Chief Financial Officer (Duly Authorized Officer and Principal Financial Officer) | August 29, 2025 | ||||||||||||
| Dipak Golechha | ||||||||||||||
| /s/ JOSH PAUL | Chief Accounting Officer (Duly Authorized Officer and Principal Accounting Officer) | August 29, 2025 | ||||||||||||
| Josh Paul | ||||||||||||||
| /s/ LEE KLARICH | Chief Product and Technology Officer and Director | August 29, 2025 | ||||||||||||
| Lee Klarich | ||||||||||||||
| /s/ APARNA BAWA | Director | August 29, 2025 | ||||||||||||
| Aparna Bawa | ||||||||||||||
| /s/ JOHN M. DONOVAN | Director | August 29, 2025 | ||||||||||||
| John M. Donovan | ||||||||||||||
| /s/ CARL ESCHENBACH | Director | August 29, 2025 | ||||||||||||
| Carl Eschenbach | ||||||||||||||
| /s/ JAMES J. GOETZ | Director | August 29, 2025 | ||||||||||||
| James J. Goetz | ||||||||||||||
| /s/ RALPH HAMERS | Director | August 29, 2025 | ||||||||||||
| Ralph Hamers | ||||||||||||||
| /s/ RT HON SIR JOHN KEY | Director | August 29, 2025 | ||||||||||||
| Rt Hon Sir John Key | ||||||||||||||
| /s/ MARY PAT MCCARTHY | Director | August 29, 2025 | ||||||||||||
| Mary Pat McCarthy | ||||||||||||||
| /s/ HELLE THORNING-SCHMIDT | Director | August 29, 2025 | ||||||||||||
| Helle Thorning-Schmidt | ||||||||||||||
| /s/ LORRAINE TWOHILL | Director | August 29, 2025 | ||||||||||||
| Lorraine Twohill | ||||||||||||||
- 103 -