Palo Alto Networks (PANW) 10-K risk factor changes: FY2025 vs FY2024
The 2025-07-31 10-K against the 2024-07-31 one, compared heading by heading and sentence by sentence.
Item 1A100 rewritten60 added24 removed502 unchanged
All filing items960 rewritten524 added424 removed2,075 unchanged
Summary
counted, not written
- Item 1A lists 47 risk factor headings: 2 new, 8 reworded and 37 unchanged since FY2024. 2 headings from FY2024 no longer appear.
- Sentence by sentence, 524 added, 424 removed, 960 rewritten and 2,075 unchanged across 19 items that differ.
New Item 1A headings (2)
- We may not complete the acquisition of CyberArk within the timeframe we anticipate or at all, which could negatively impact our future business and financial results.Cybersecurity
- As a result of the CyberArk acquisition, we anticipate that the scope and size of our business will substantially change and result in certain incremental risks, including increased competition.Cybersecurity
Removed Item 1A headings (2)
- We may not have the ability to raise the funds necessary to settle conversions of our Notes, repurchase our Notes upon a fundamental change, or repay our Notes in cash at their maturity, and our future debt may contain limitations on our ability to pay cash upon conversion or repurchase of our Notes.
- We may still incur substantially more debt or take other actions that would diminish our ability to make payments on our Notes when due.
Reworded Item 1A headings (8)
- We [added: have and] may [added: in the future] acquire other
[removed: businesses,][added: businesses (including CyberArk),] which could subject us to adverse claims or liabilities, require significant management attention, disrupt our business, adversely affect our operating results, may not result in the expected benefits of such acquisitions, and may dilute stockholder value. [removed: Because some of the key components in our][added: Our] hardware products[removed: come][added: contain key components] from limited sources of supply, [added: including outside the United States, and] we are susceptible to supply[removed: shortages or][added: shortages,] supply changes, [added: and international regulations,] which, in certain cases, have disrupted or delayed our scheduled product deliveries to our end-customers, increased our costs and may result in the loss of sales and end-customers.- We are subject to [added: international trade regulations and] governmental export and import controls that could subject us to liability or impair our ability to compete in international markets.
- If our estimates or
[removed: judgments][added: judgments, including those] relating to our critical accounting[removed: policies][added: policies,] are based on assumptions that change or prove to be incorrect, our operating results[removed: could fall below][added: differ from] our publicly announced guidance or the expectations of securities analysts and investors, resulting in a decline in the market price of our common stock. - Our reputation and/or business could be negatively impacted by
[removed: ESG][added: corporate responsibility] matters and/or our reporting of such matters. - The
[removed: convertible note hedge and]warrant transactions may affect the value of our common stock. - The issuance of additional stock in connection with financings, acquisitions, investments, our stock incentive plans,
[removed: the conversion of our Notes or]exercise of the[removed: related][added: 2025] Warrants, or otherwise will dilute stock held by all other stockholders. - Our charter documents and Delaware
[removed: law, as well as certain provisions contained in the indentures governing our Notes,][added: law] could discourage takeover attempts and lead to management entrenchment, which could also reduce the market price of our common stock.
A heading is new when no FY2024 heading matches it after ignoring case and punctuation, and reworded when it shares at least 60 percent of its words with one that went away. All current risk factor headings.
Sentences by item
24 items, with every count and a link to each item that changed
Underlined words on a shaded ground are new in FY2025; struck-through words were in FY2024. Sentences that are wholly new or wholly gone are labelled rather than marked.
Item 1A. Risk Factors
100 rewritten, 60 added, 24 removed, 502 unchanged
- We [added: have and] may [added: in the future] acquire other [removed: businesses,] [added: businesses (including CyberArk),] which could subject us to adverse claims or liabilities, require significant management attention, disrupt our business, adversely affect our operating results, may not result in the expected benefits of such acquisitions, and may dilute stockholder value.
- [removed: Because some of the key components in our] [added: Our] hardware products [removed: come] [added: contain key components] from limited sources of supply, [added: including outside the United States, and] we are susceptible to supply [removed: shortages or] [added: shortages,] supply changes, [added: and international regulations,] which, in certain cases, have disrupted or delayed our scheduled product deliveries to our end-customers, increased our costs and may result in the loss of sales and end-customers.
- We are subject to [added: international trade regulations and] governmental export and import controls that could subject us to liability or impair our ability to compete in international markets.
- If our estimates or [removed: judgments] [added: judgments, including those] relating to our critical accounting [removed: policies] [added: policies,] are based on assumptions that change or prove to be incorrect, our operating results [removed: could fall below] [added: differ from] our publicly announced guidance or the expectations of securities analysts and investors, resulting in a decline in the market price of our common stock.
- Our reputation and/or business could be negatively impacted by [removed: ESG] [added: corporate responsibility] matters and/or our reporting of such matters.
- The [removed: convertible note hedge and] warrant transactions may affect the value of our common stock.
- The issuance of additional stock in connection with financings, acquisitions, investments, our stock incentive plans, [removed: the conversion of our Notes or] exercise of the [removed: related] [added: 2025] Warrants, or otherwise will dilute stock held by all other stockholders.
- Our charter documents and Delaware [removed: law, as well as certain provisions contained in the indentures governing our Notes,] [added: law] could discourage takeover attempts and lead to management entrenchment, which could also reduce the market price of our common stock.
The instability in the global credit markets, inflation, changes in public policies such as domestic and international [added: legislation or] regulations, [added: changes in enforcement and administration policies,] taxes, any increases in interest rates, fluctuations in foreign currency exchange rates, or international trade agreements, international trade disputes, [added: trade regulations, tariffs and changes in tariffs,] geopolitical turmoil, and other disruptions to global and regional economies and markets continue to add uncertainty to global economic conditions.
Military actions or armed conflict, including the hostilities in Israel and the surrounding region, [removed: Russia’s invasion of Ukraine] [added: the Russia-Ukraine war] and any related political or economic responses and counter-responses, and uncertainty about, or changes in, government and trade relationships, policies, and treaties could also lead to worsening economic and market conditions and geopolitical environment.
For example, from the end of fiscal [removed: 2023] [added: 2024] to the end of fiscal [removed: 2024,] [added: 2025,] our headcount increased from [removed: 13,948 to] 15,289 [added: to 16,068] employees.
We have experienced revenue growth rates of [removed: 16.5%] [added: 14.9%] and [removed: 25.3%] [added: 16.5%] in fiscal [removed: 2024] [added: 2025] and fiscal [removed: 2023,] [added: 2024,] respectively.
[removed: Our future success depends, in part, on our ability to expand the deployment of our portfolio with existing end-customers, especially large enterprise customers, including through our platformization strategy, and create demand for our new offerings,] The rate at which our end-customers purchase additional products, subscriptions, and support depends on a number of factors, including the perceived need for additional security products, including subscription and support offerings, as well as general economic conditions.
Deployments for large enterprise end-customers are also more complex, require greater product functionality, scalability, and a broader range of services, and are more [removed: time-consuming.][added: time-consuming and resource-consuming.]
We are engaging in costly marketing and sales efforts to accelerate [removed: platformization] [added: our strategies, including platformization,] and attract new customers, which may fail or may not be as successful as intended or at all.
Subscription and support revenue accounts for a significant portion of our revenue, comprising [removed: 80.0%] [added: 80.5%] of total revenue in fiscal [removed: 2024, 77.1%] [added: 2025, 80.0%] of total revenue in fiscal [removed: 2023,] [added: 2024,] and [removed: 75.2%] [added: 77.1%] of total revenue in fiscal [removed: 2022.][added: 2023.]
For fiscal [removed: 2024, four] [added: 2025, three] distributors individually represented 10% or more of our total revenue and in the aggregate represented [removed: 59.0%] [added: 44.2%] of our total revenue.
As of July 31, [removed: 2024, two] [added: 2025, three] distributors individually represented 10% or more of our gross accounts receivable and in the aggregate represented [removed: 31.5%] [added: 44.8%] of our gross accounts receivable.
Government certification [added: or technical] requirements for products and subscriptions like ours may change, thereby restricting our ability to sell into the federal government sector until we have attained the revised [removed: certification.][added: certification or technical requirements.]
If our products and subscriptions are late in achieving or fail to achieve compliance with these certifications and [removed: standards,] [added: standards] or [added: technical requirements, or] our competitors achieve compliance with these certifications and [removed: standards,] [added: standards or technical requirements,] we may be disqualified from selling our products, subscriptions, and support offerings to such governmental entity, or be at a competitive disadvantage, which would harm our business, operating results, and financial condition.
Government [added: entity] demand and payment for our products, subscriptions, and support offerings may be impacted by government shutdowns, [added: changes in governmental administrations,] public sector budgetary cycles, [added: fiscal policies,] contracting [added: policies or] requirements, [removed: and] funding authorizations, [added: and efforts by a government to evaluate and reduce overall government spending and analyze and enhance its operational efficiency,] with funding reductions or delays adversely affecting public sector demand for our products, subscriptions, and support offerings.
Additionally, the U.S. government may require certain of the products that it purchases to be manufactured in the United States [removed: and] [added: or] other relatively high-cost manufacturing locations, and we may not manufacture all products in locations that meet such requirements, affecting our ability to sell these products, subscriptions, and support offerings to the U.S. government.
[removed: Many] [added: Some] of our competitors have [added: or may attain] greater financial, technical, marketing, sales, and other resources, greater name recognition, longer operating histories, and a larger base of customers than we do.
Further, they may have greater resources for research and development of new technologies, the provision of customer support, and the pursuit of [removed: acquisitions.][added: acquisitions or other strategic investments.]
Conditions in our market could change rapidly and significantly as a result of technological advancements, [removed: partnering or] [added: partnering,] acquisitions [added: or strategic investments] by our competitors, or continuing market consolidation.
Our current and potential competitors may also establish cooperative relationships among themselves or with third parties that may further enhance their [removed: resources.][added: resources or product or service offerings.]
We [added: have and] may [added: in the future] acquire other [removed: businesses,] [added: businesses (including CyberArk),] which could subject us to adverse claims or liabilities, require significant management attention, disrupt our business, adversely affect our operating results, may not result in the expected benefits of such acquisitions, and may dilute stockholder value.
Additionally, we may be subject to litigation or other claims in connection with the acquired company, [added: product, or technology,] including claims from terminated employees, customers, former stockholders, or other third parties, which may differ from or be more significant than the risks our business faces.
If we are unsuccessful at integrating past or future [removed: acquisitions] [added: acquisitions, including the pending acquisition of CyberArk,] in a timely manner, or the technologies, products, or operations associated with such acquisitions, into our company, our revenue and operating results could be adversely affected.
We may have difficulty retaining key personnel [added: or customers] of the acquired business.
We may not successfully evaluate or utilize [removed: the] [added: any] acquired technology, products, or personnel, realize anticipated synergies from [removed: the] [added: an] acquisition, or accurately forecast the financial impact of an acquisition transaction and integration of such acquisition, including accounting charges and any potential impairment of goodwill and intangible assets recognized in connection with such acquisitions.
We may have to pay cash, incur debt, or issue equity or equity-linked securities to pay for any future acquisitions, [added: including the pending acquisition of CyberArk,] each of which could adversely affect our financial condition or the market price of our common [removed: stock.][added: stock, and result in dilution to our stockholders.]
Furthermore, the sale [removed: of equity] or issuance of [added: equity or] equity-linked debt to finance any future acquisitions could result in dilution to our stockholders.
These efforts could subject us to regulatory risk, legal liability, including under [removed: new proposed] legislation regulating AI in jurisdictions such as the E.U. and [added: laws and] regulations being considered in other jurisdictions, or brand or reputational harm.
Increasingly, companies are subject to a wide variety of attacks on [removed: their networks on] an ongoing basis.
The [removed: conflict in Ukraine] [added: Russia-Ukraine war] and associated activities in Ukraine and Russia may increase the risk of cyberattacks on various types of infrastructure and operations, and the United States government has warned companies to be prepared for [removed: a significant increase in] [added: additional] Russian cyberattacks in response to the Sanctions on Russia.
Additionally, defects or vulnerabilities may cause our products or subscriptions to become [added: partially or fully unavailable] temporarily [removed: unavailable,] [added: or permanently,] to be vulnerable to security attacks, cause them to fail to help secure networks, or [removed: temporarily] interrupt end-customers’ networking traffic, or the availability of other information technology infrastructure or systems.
For example, in [removed: April] [added: November] 2024, we became aware of [removed: a command injection] [added: an authentication bypass] vulnerability [removed: in] [added: through] the [removed: GlobalProtect feature] [added: management web interface] of certain versions of our PAN-OS software.
To remediate the matter, we published a security advisory to advise customers, provided software updates for affected PAN-OS versions, and [removed: are actively] engaged in customer outreach, support and remediation efforts for potentially impacted customers.
In addition, due to the [removed: Russian invasion of Ukraine,] [added: Russia-Ukraine war,] there could be a significant increase in Russian cyberattacks against our customers, resulting in an increased risk of a security breach of our end-customers’ systems.
- We may not complete the acquisition of CyberArk within the timeframe we anticipate or at all, which could negatively impact our future business and financial results.
- As a result of the CyberArk acquisition, we anticipate that the scope and size of our business will substantially change and result in certain incremental risks, including increased competition.
\- 14 \-
- Our failure to raise additional capital or generate the significant capital necessary to expand our operations and invest in new products and subscriptions could reduce our ability to compete and could harm our business.
Our future success depends, in part, on our ability to expand the deployment of our portfolio with existing end-customers, especially large enterprise customers, including through our platformization strategy, and create demand for our new offerings.
We continue to evaluate such opportunities and expect to continue to make such acquisitions and investments in the future, such as our pending acquisition of CyberArk Software Ltd. (“CyberArk”).
In particular, we believe that there are significant benefits and synergies that may be realized from our proposed acquisition of CyberArk, including through leveraging our and CyberArk’s products, scale, and combined enterprise customer bases.
However, the efforts to realize the anticipated benefits and synergies will be a complex process and may disrupt both our and CyberArk’s existing operations if not implemented in a timely and efficient manner.
The full benefits of the proposed acquisition of CyberArk, including the anticipated sales or growth opportunities, may not be realized as expected or may not be achieved within the anticipated time frame, or at all.
We have recorded, and may in the future record, liability for contingent consideration obligations from acquisitions that are to be settled in cash, the fair value of which is assessed on a quarterly basis.
If changes are made in our assumptions used to determine the liability’s fair value or our assumptions are incorrect, adjustments could be made that may have a material impact, favorable or unfavorable, on our operating results.
We may also be required to make cash payments of contingent consideration in excess of its initial fair value, or in excess of our expectations for a particular period, which could adversely impact cash flows.
We may not complete the acquisition of CyberArk within the timeframe we anticipate or at all, which could negatively impact our future business and financial results.
The completion of the acquisition of CyberArk is subject to a number of conditions, including, among others:
- the effectiveness of a registration statement on Form S-4 to be filed by us registering the shares of our common stock to be issued to CyberArk shareholders as consideration in the acquisition and the absence of any stop order or proceedings seeking a stop order;
- the approval for listing on Nasdaq of our shares of common stock to be issued in connection with the proposed acquisition;
- obtaining the requisite CyberArk shareholder approval in connection with the proposed acquisition;
- the expiration or termination of any waiting period (or extensions thereof) applicable to the acquisition under the Hart-Scott-Rodino Antitrust Improvements Act of 1976, as amended (the “HSR Act”) and the making, approval, expiration, termination or receipt of, as applicable, all applicable filings, registrations, waiting periods (or extensions of waiting periods) and approvals under specified antitrust and foreign investment laws; and
- the absence of governmental restraints or prohibitions preventing the consummation of the proposed acquisition.
No assurance can be given that the required CyberArk shareholder approval and governmental and regulatory consents and approvals will be obtained or that any of the required conditions to closing will be satisfied in a timely manner or at all.
As a result, although it is currently anticipated that we will complete the acquisition of CyberArk during the second half of our fiscal 2026, the possible timing and likelihood of completion are uncertain.
There can be no assurance that the acquisition of CyberArk will be completed in the anticipated timeframe or at all.
Any delay in completing the proposed acquisition could cause the combined company not to realize, or to be delayed in realizing, some or all of the benefits and synergies that we anticipate to achieve if the proposed acquisition were to be successfully completed within its expected time frame.
In addition, the relevant governmental authorities from which approvals under specified antitrust and foreign investment laws must be obtained may impose or seek to impose conditions on the completion of the acquisition or require changes to the terms of the proposed acquisition or agreements to be entered into in connection with the CyberArk acquisition.
Such conditions or changes and the process of obtaining these approvals, could have the effect of delaying or impeding completion of the CyberArk acquisition or imposing additional costs or limitations on us following the acquisition, which may have an adverse effect on our business, results of operations, and financial condition.
The failure or inability to satisfy all of the required conditions could delay the completion of the acquisition for a significant period of time or prevent it from occurring at all.
In addition, under limited circumstances, we or CyberArk may elect to terminate the definitive agreement or we and CyberArk may mutually decide to terminate the definitive agreement, before or after obtaining the requisite CyberArk shareholder approval.
A termination of the definitive agreement could materially and adversely affect our business, results of operations and reputation.
If the acquisition of CyberArk is delayed or not completed, we could be subject to a number of risks that may adversely affect our business, operating results and financial condition, including, among other things:
- we may experience negative reactions from the financial markets, including negative impacts on the market price of our common stock;
- we could incur significant acquisition costs that we would be unable to recoup;
- under specified circumstances in connection with the termination of the definitive agreement, we would be required to pay CyberArk a termination fee of $1.0 billion;
- negative perception from industry contacts, business partners, and other third parties, which could impact our operations or our ability to compete for new business or obtain renewals in the marketplace more broadly; and
- reputational harm, negative publicity, negative reactions from employees, and other negative impacts resulting from delay or failure to complete the acquisition of CyberArk.
As a result of the CyberArk acquisition, we anticipate that the scope and size of our business will substantially change and result in certain incremental risks, including increased competition.
We believe that the CyberArk acquisition will expand the scope and size of our business by adding substantial assets and operations to our existing business.
The anticipated future growth of our business may impose significant added responsibilities on our senior management, and our senior management’s attention may be diverted from the management of our business and its day-to-day operations to the completion and integration of the CyberArk acquisition.
The CyberArk acquisition could also create uncertainty for our and CyberArk’s employees, partners, and customers, particularly during the anticipated post-acquisition integration process, and result in disruption to existing business relationships and the development of new business relationships.
Following completion of the proposed acquisition of CyberArk, our success, including with respect to realizing the anticipated benefits and synergies from the proposed acquisition, will depend, in part, on our ability to manage our expansion, which poses numerous risks and uncertainties, including the need to integrate the operations and business of CyberArk into our existing business in a timely and efficient manner, to combine systems and management controls and to integrate relationships with industry contacts and business partners.
In addition, we will be required to devote significant attention and resources prior to closing to prepare for the post-closing integration and operation of the combined company, and we will be required post-closing to devote significant attention and resources to successfully align our and CyberArk’s business practices and operations.
- We may not have the ability to raise the funds necessary to settle conversions of our Notes, repurchase our Notes upon a fundamental change, or repay our Notes in cash at their maturity, and our future debt may contain limitations on our ability to pay cash upon conversion or repurchase of our Notes.
- We may still incur substantially more debt or take other actions that would diminish our ability to make payments on our Notes when due.
Moreover, additional state privacy laws have been passed and will require potentially substantial efforts to obtain compliance.
These include laws enacted in at least 19 states, and six other states have active privacy bills pending in state legislative processes.
For example, beginning in fiscal 2023, we were required to capitalize and amortize research and development expenses as required by the Tax Cuts and Jobs Act.
As a result of this change and our increased profitability, we have paid significantly more U.S. cash taxes during fiscal 2024 and we expect our cash tax payments to increase in future periods.
We may not have the ability to raise the funds necessary to settle conversions of our Notes, repurchase our Notes upon a fundamental change, or repay our Notes in cash at their maturity, and our future debt may contain limitations on our ability to pay cash upon conversion or repurchase of our Notes.
We will need to make cash payments (a) if holders of our 2025 Notes require us to repurchase all, or a portion of, their 2025 Notes upon the occurrence of a fundamental change (e.g., a change of control of Palo Alto Networks, Inc.) before the maturity date, (b) upon conversion of our 2025 Notes, or (c) to repay our 2025 Notes in cash at their maturity unless earlier converted or repurchased.
Effective August 1, 2024 through October 31, 2024, all of the 2025 Notes are convertible.
If all of the note holders decided to convert their 2025 Notes, we would be obligated to pay the $1.0 billion principal amount of the 2025 Notes in cash.
Under the terms of the 2025 Notes, we also have the option to settle the amount of our conversion obligation in excess of the aggregate principal amount of the 2025 Notes in cash or shares of our common stock.
If our cash provided by operating activities, together with our existing cash, cash equivalents, and investments, and existing sources of financing, are inadequate to satisfy these obligations, we will need to obtain third-party financing, which may not be available to us on commercially reasonable terms or at all, to meet these payment obligations.
In addition, our ability to repurchase or to pay cash upon conversion of our 2025 Notes may be limited by law, regulatory authority, or agreements governing our future indebtedness.
Our failure to repurchase our 2025 Notes at a time when the repurchase is required by the applicable indenture governing such 2025 Notes or to pay cash upon conversion of such 2025 Notes as required by the applicable indenture would constitute a default under the indenture.
A default under the applicable indenture or the fundamental change itself could also lead to a default under agreements governing our future indebtedness.
If the payment of the related indebtedness were to be accelerated after any applicable notice or grace periods, we may not have sufficient funds to repay the indebtedness and repurchase our 2025 Notes or to pay cash upon conversion of our 2025 Notes.
We may still incur substantially more debt or take other actions that would diminish our ability to make payments on our Notes when due.
We and our subsidiaries may incur substantial additional debt in the future, subject to the restrictions contained in our debt instruments, that could have the effect of diminishing our ability to make payments on our 2025 Notes when due.
The 2025 Note Hedges for our 2025 Notes are generally expected to reduce the potential dilution to our common stock upon any conversion of our 2025 Notes.
This activity could also cause or prevent an increase or a decrease in the market price of our common stock or our 2025 Notes, which could affect a note holder’s ability to convert its 2025 Notes and, to the extent the activity occurs during any observation period related to a conversion of our 2025 Notes, it could affect the amount and value of the consideration that the note holder will receive upon conversion of our 2025 Notes.
As of July 31, 2024, we had $500.0 million available under our share repurchase program.
On August 15, 2024, our board of directors authorized a $500.0 million increase to our share repurchase program, bringing the total remaining authorization for future share repurchases to $1.0 billion.
Additionally, certain provisions contained in the indenture governing our 2025 Notes could make it more difficult or more expensive for a third party to acquire us.
The application of Section 203 or certain provisions contained in the indenture governing our 2025 Notes also could have the effect of delaying or preventing a change in control of us.
An excerpt. Shown here: 40 of 100 rewritten, 40 of 60 added and all 24 removed. The counts are complete. For every sentence, read Item 1A. Risk Factors in the FY2025 filing and the FY2024 filing.
Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations
155 rewritten, 82 added, 60 removed, 284 unchanged
- Results of Operations. A discussion of the nature and trends in our financial results and an analysis of our financial results comparing fiscal [removed: 2024] [added: 2025] to fiscal [removed: 2023.][added: 2024.]
For discussion and analysis related to our financial results comparing fiscal [removed: 2023] [added: 2024] to [removed: 2022,] [added: 2023,] refer to Part II, Item 7.
Management’s Discussion and Analysis of Financial Condition and Results of Operations in our Annual Report on Form 10-K for fiscal [removed: 2023,] [added: 2024,] which was filed with the Securities and Exchange Commission on September [removed: 1, 2023.][added: 6, 2024.]
Our cybersecurity platforms and services help secure enterprise users, networks, clouds, and endpoints by delivering comprehensive cybersecurity backed by [removed: AI] [added: artificial intelligence (“AI”)] and automation.
Our platformization strategy combines various products and services into a tightly integrated architecture [removed: and makes security] [added: for more secure,] faster, [removed: less complex,] and [removed: more cost-effective.][added: cost-effective outcomes.]
[removed: Network Security:][added: Network Security]
[removed: -] Our network security [removed: platform,] [added: platform is] designed to deliver complete zero trust solutions to our [removed: customers, includes our hardware and software ML-Powered Next-Generation Firewalls, AI Runtime Security, as well as a cloud-delivered SASE.][added: customers.]
[added: - *Secure Access Service Edge (“SASE”).*] Prisma® Access, [removed: our SSE solution,] when combined with Prisma SD-WAN, provides a comprehensive single-vendor SASE offering that is used to secure remote workforces and [removed: securely enable the] cloud-delivered [removed: branch.][added: branch offices.]
[removed: Our network security platform also includes our cloud-delivered security services, such as] [added: These include] Advanced Threat Prevention, Advanced WildFire®, Advanced URL Filtering, Advanced DNS Security, IoT/OT Security, GlobalProtect®, [added: Prisma Access Agent,] Enterprise [removed: DLP, AIOps, SaaS] [added: Data Loss Prevention (“Enterprise DLP”), AI for IT Operations (“AIOps”), Software as a Service (“SaaS”)] Security, and AI Access Security.
Through these add-on [removed: security] services, our customers are able to secure their content, applications, users, and devices across their entire organization.
- [added: *Cloud Security.*] We deliver [removed: scalable and] comprehensive security across the cloud application development lifecycle through [removed: our Code to CloudTM platform, Prisma Cloud.][added: Cortex Cloud, delivered as a scalable SaaS offering.]
As a comprehensive [removed: CNAPP, Prisma] Cloud [added: Native Application Protection Platform (“CNAPP”) combined with CDR, Cortex Cloud] secures multi- and hybrid-cloud environments for applications, data, [removed: GenAI] [added: generative AI (“GenAI”)] ecosystem, and the [removed: entire] cloud native technology stack across the full development lifecycle, from code to [removed: cloud.][added: cloud to security operations.]
[removed: Security Operations:][added: Security Operations]
- [added: *Security Operations.*] We deliver the next generation of security operations capabilities that [removed: combine security analytics,] [added: unifies standalone Security Information and Event Management (“SIEM”) tools,] endpoint security, [added: security] automation, [added: cloud detection] and [removed: ASM solutions through] [added: response (“CDR”), as well as attack surface management (“ASM”) capabilities on] our [removed: Cortex] [added: Cortex®] platform.
These include Cortex [removed: XSIAM, our AI-driven] [added: XSIAM®, for AI-powered] security operations [removed: platform,] [added: replacing traditional SIEM tools,] Cortex [removed: XDR®] [added: XDR®,] for the prevention, detection, and response to complex cybersecurity attacks, Cortex [removed: XSOAR®] [added: XSOAR®,] for [removed: SOAR,] [added: security orchestration, automation,] and [added: response (“SOAR”), and] Cortex [removed: XpanseTM] [added: Xpanse®,] for ASM.
[removed: Threat] [added: Threat] Intelligence and Advisory [removed: Services (Unit 42):][added: Services]
- Unit 42 brings together world-renowned [added: expertise across] threat [removed: researchers with an elite team of] [added: research,] incident [removed: responders] [added: response,] and security [removed: consultants] [added: consulting] to [removed: create an] [added: deliver] intelligence-driven, response-ready [removed: organization to] [added: outcomes that] help customers [removed: manage] [added: reduce] cyber risk.
Our [added: elite] consultants serve as trusted advisors to our customers by assessing and testing their security controls against [removed: the right] [added: sophisticated] threats, transforming their security strategy with a threat-informed approach, and responding to security incidents on behalf of our clients.
Additionally, Unit 42 offers managed detection and response [added: (“MDR”)] and managed threat hunting services.
For fiscal [removed: 2024] [added: 2025] and [removed: 2023,] [added: 2024,] total revenue was [removed: $8.0] [added: $9.2] billion and [removed: $6.9] [added: $8.0] billion, respectively, representing year-over-year growth of [removed: 16.5%.][added: 14.9%.]
As of July 31, [removed: 2024,] [added: 2025,] we had end-customers in over 180 countries.
Our product revenue grew to [removed: $1.6] [added: $1.8] billion or [removed: 20.0%] [added: 19.5%] of total revenue for fiscal [removed: 2024,] [added: 2025,] representing year-over-year growth of [removed: 1.6%.][added: 12.4%.]
Product revenue is derived from sales of [removed: our appliances,] [added: hardware products,] primarily our ML-Powered Next-Generation [removed: Firewall.][added: Firewall, and software licenses, including SD-WAN, the VM-Series, and Panorama®.]
Our [removed: appliances] [added: hardware products] and software licenses include a broad set of built-in networking and security features and functionalities.
Our products are designed for different performance requirements throughout an organization, ranging from our [removed: PA-410,] [added: PA-400,] which is designed for small organizations and remote or branch offices, to our top-of-the-line PA-7500, which is designed for large-scale data centers and service provider use.
The same firewall functionality that is delivered in our [removed: physical appliances] [added: hardware products] is also available in our VM-Series virtual firewalls, which secure virtualized and cloud-based computing environments, and in our CN-Series container firewalls, which secure container environments and traffic.
Our subscription and support revenue grew to [removed: $6.4] [added: $7.4] billion or [removed: 80.0%] [added: 80.5%] of total revenue for fiscal [removed: 2024,] [added: 2025,] representing year-over-year growth of [removed: 20.9%.][added: 15.5%.]
Our subscriptions provide our end-customers with near real-time access to the latest [removed: antivirus,] intrusion prevention, web [removed: filtering,] [added: security,] modern malware prevention, data loss prevention, CASB and AI security capabilities across the network, endpoints, and the cloud.
When customers purchase our physical, virtual, or container [removed: firewall appliances,] [added: firewalls,] or certain cloud offerings, they typically purchase support in order to receive ongoing security updates, upgrades, bug fixes, and repairs.
In addition to the subscriptions purchased with these [removed: appliances,] [added: firewalls,] customers may also purchase other subscriptions on a per-user, per-endpoint, or capacity-based basis.
[removed: On] [added: Additionally, in] August [removed: 31,] 2024, we completed the acquisition of [removed: IBM’s] [added: certain IBM] QRadar [removed: SaaS assets and] [added: assets, which] we expect [removed: the acquisition] will help accelerate the growth of our Cortex [removed: XSIAM] business.
[removed: Worsening] [added: Further,] economic conditions, including inflation, [removed: higher] [added: high] interest rates, [removed: slower] [added: slow] growth, fluctuations in foreign exchange rates, supply chain disruptions, [added: impacts of trade regulations or international trade disputes,] and other conditions, may adversely affect our results of operations and financial performance.
The hostilities in Israel and the surrounding region have [removed: increased the levels of] [added: continued to result in] economic and political uncertainty.
We are actively monitoring, evaluating, and responding to the [removed: developing] situation.
We discuss revenue, gross margin, and the components of operating income [removed: (loss)] and margin below under “Results of Operations.”
| | | | [added: 2025 | | | | | |] 2024 | | | | | | 2023 | | |
| [removed: Cash,] [added: Total cash,] cash equivalents, and investments | | | $ | [removed: 6,752.0] [added: 8,458.8] | | | | | $ | [removed: 5,437.9] [added: 6,752.0] | |
| | | | [removed: 2024] [added: 2025] | | | | | | [removed: 2023] [added: 2024] | | | | | | [removed: 2022] [added: 2023] | | |
| Total revenue | | | $ | [removed: 8,027.5] [added: 9,221.5] | | | | | $ | [removed: 6,892.7] [added: 8,027.5] | | | | | $ | [removed: 5,501.5] [added: 6,892.7] | |
| Total revenue year-over-year percentage increase | | | [removed: 16.5] [added: 14.9] | | % | | | | [removed: 25.3] [added: 16.5] | | % | | | | [removed: 29.3] [added: 25.3] | | % |
Our mission is to be the cybersecurity partner of choice for enterprises, organizations, service providers, and government entities to protect our digital way of life.
The platform includes:
Prisma Access Browser further extends SASE security and data protection to the end user device, providing workers with freedom to access business applications securely using our secure browser from any device.
- *Next-Generation Firewalls.* Our hardware ML-Powered Next-Generation Firewalls (“NGFWs”) secure on-premises environments including campus locations and data centers.
Our software NGFWs secure cloud networks.
- *Cloud-Delivered Security Services (“CDSS”).* Our network security platform integrates a suite of CDSS that complements our SASE and Firewall solutions.
- *Prisma AIRS.* Prisma AIRS is a comprehensive AI security platform that has been designed to protect customers’ entire AI ecosystem by providing AI model scanning, posture management, red teaming, run-time security, and AI agent security.
\- 42 \-
- *Strata Cloud Manager (“SCM”).* SCM, our network security management solution, centrally manages network security across all remote workers, branches, headquarters, campuses, and cloud.
SCM leverages AI to simplify and strengthen network security by enabling customers to proactively pinpoint vulnerabilities, gain real-time remediation recommendations, and enhance overall digital experiences, thereby reducing operational burden.
This comprehensive solution includes Strata Copilot, which offers a natural language interface for enhanced insights and guided remediation, and integrates Autonomous Digital Experience Monitoring (“ADEM”) to proactively maintain infrastructure health, facilitate AI-driven one-click troubleshooting, and ensure seamless end-user performance across the enterprise.
Our AI-powered Cortex platform transforms end-to-end security operations with unified data, AI, and automation for more secure, faster, and cost effective outcomes.
We have consolidated our industry-leading Security Operations and Cloud Security capabilities on a single comprehensive platform to provide centralized visibility, proactive protection, real-time prevention, AI-driven insights, and automated remediation across enterprise and cloud.
As part of the Cortex Cloud platform, customers can expand from Cortex Cloud to our security operations offerings available on a single user experience and unified agent.
Our subscriptions also include security operations, which enable customers to leverage the AI-powered Cortex platform for advanced capabilities such as security information and event management, next-generation antivirus, endpoint detection and response, extended detection and response, identity threat detection and response, cloud detection and response, SOAR, ASM, and CNAPP for comprehensive cloud security.
Additionally, we offer MDR for Cortex subscriptions, powered by Unit 42’s elite expertise.
During fiscal 2025, we introduced several new offerings, including: Prisma Access Browser, new capabilities in our OT Security solution, Cortex Cloud, Prisma AIRS, and Cortex XSIAM 3.0.
Additionally, in July 2025, we completed the acquisition of Protect AI, which we expect will enhance the capabilities of our AI security platform.
In July 2025, we also entered into a definitive agreement to acquire Software Ltd. (“CyberArk”), an identity security company, which acquisition is expected to close during the second half of our fiscal 2026.
Changes in legislation or regulations and actions by regulators, including changes in enforcement and administration policies, may have an impact on our results of operations and financial condition.
Significant changes in U.S. or global trade policy, including further expansion of U.S. export/imports controls and tariffs, as well as retaliatory actions by other countries, may materially and adversely affect our business.
| | | | 2025 | | | | | | 2024 | | |
| | | | (in billions) | | | | | | | | |
| Next-Generation Security Annualized Recurring Revenue | | | $ | 5.6 | | | | | $ | 4.2 | |
| Remaining performance obligations | | | $ | 15.8 | | | | | $ | 12.7 | |
- Next-Generation Security Annualized Recurring Revenue (“NGS ARR”). Our NGS ARR represents the annualized allocated revenue of all active contracts as of the final day of the reporting period related to all product, subscription and support offerings, excluding revenue from hardware products, and legacy attached subscriptions, support offerings and professional services.
NGS ARR is an operating metric that we use to assess the strength and trajectory of our business.
NGS ARR should be viewed independently of revenue, deferred revenue and remaining performance obligations and does not represent our revenue under U.S. GAAP on an annualized basis, as it is an operating metric that can be impacted by contract start and end dates and renewal rates.
NGS ARR is not intended to be a replacement for forecasts of revenue.
The scope of products, subscriptions, and support offerings that contribute to NGS ARR will generally increase over time as we introduce or acquire new next-generation products, subscriptions, and support offerings.
| Free cash flow (non-GAAP) | | | $ | 3,469.8 | | | | | $ | 3,100.8 | | | | | $ | 2,631.2 | |
Product revenue is derived from sales of hardware products, primarily our ML-Powered Next-Generation Firewall, and software licenses, including SD-WAN, the VM-Series, and Panorama.
Our hardware products and software licenses include a broad set of built-in networking and security features and functionalities.
As a percentage of product revenue, we expect our revenue from software licenses to vary from quarter to quarter and increase over the long term as we improve features and capabilities of our on-premise software, renew our software license contracts, and expand our installed end-customer base.
| | | | 2025 | | | | | | 2024 | | | | | | Change | | | | | | | | | | | | 2024 | | | | | | 2023 | | | | | | Change | | | | | | | | |
| | | | 2025 | | | | | | 2024 | | | | | | Change | | | | | | | | | | | | 2024 | | | | | | 2023 | | | | | | Change | | | | | | | | |
| | | | 2025 | | | | | | 2024 | | | | | | Change | | | | | | | | | | | | 2024 | | | | | | 2023 | | | | | | Change | | | | | | | | |
| | | | 2025 | | | | | | 2024 | | | | | | Change | | | | | | | | | | | | 2024 | | | | | | 2023 | | | | | | Change | | | | | | | | |
The increase in cost of subscription and support revenue was further driven by increased professional services expense.
| | | | 2025 | | | | | | | | | | | | 2024 | | | | | | | | | | | | 2023 | | | | | | | | |
We empower enterprises, organizations, service providers, and government entities to protect themselves against today’s most sophisticated cyber threats.
We focus on delivering value in four sectors of the cybersecurity industry:
Strata Cloud Manager, our network security management solution, can centrally manage our network security platform irrespective of form factor, location, or scale.
Strata Cloud Manager includes the Strata Copilot which provides a natural language interface to simplify and accelerate platform management.
Cloud Security:
These products are delivered as SaaS or software subscriptions.
Product revenue also includes revenue derived from software licenses of Panorama®, SD-WAN, and the VM-Series.
During fiscal 2024, we introduced several new offerings, including: Prisma Cloud Darwin release with newly integrated Code to Cloud intelligence capabilities, PAN-OS 11.2 Quasar, Cortex XSIAM 2.0, new Cortex XSIAM features, Prisma SASE 3.0, and Precision AITM.
Additionally, we acquired productive investments that fit well within our long-term strategy.
For example, in December 2023, we acquired Dig, which we expect will enhance our Prisma Cloud capabilities with a DSPM solution that is intended to provide customers with visibility into, and secure data stored across, their multi-cloud environments; and we acquired Talon, which will support Prisma SASE’s approach to provide secure access to business applications for unmanaged and personal devices with an enterprise browser.
In May 2024, we announced an expanded partnership with International Business Machines Corporation (“IBM”) to deliver AI-powered security outcomes for customers, as part of which we agreed to acquire IBM's QRadar SaaS assets, including QRadar intellectual property rights, customer relationships and customer contracts.
| | | | (in millions) | | | | | | | | |
| Total deferred revenue | | | $ | 11,480.5 | | | | | $ | 9,296.4 | |
| | | | | | | | | | | | | | | | | | |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| | | | Year Ended July 31, | | | | | | | | | | | | | | |
| Billings | | | $ | 10,208.1 | | | | | $ | 9,194.4 | | | | | $ | 7,471.5 | |
| Billings year-over-year percentage increase | | | 11.0 | | % | | | | 23.1 | | % | | | | 37.0 | | % |
- Deferred Revenue. Our deferred revenue primarily consists of amounts that have been invoiced but have not been recognized as revenue as of the period end.
The majority of our deferred revenue balance consists of subscription and support revenue that is recognized ratably over the contractual service period.
We monitor our deferred revenue balance because it represents a significant portion of revenue to be recognized in future periods.
- Billings. We define billings as total revenue plus the change in total deferred revenue, net of acquired deferred revenue, during the period.
We have considered billings to be a key metric used by management to manage our business.
There are inherent limitations in using billings to evaluate our operating results as the variability in payment terms may cause fluctuation in billings.
Beginning in the first fiscal quarter of 2025, billings will no longer be a key financial metric and will no longer be reported.
We calculate billings in the following manner:
| | | | (in millions) | | | | | | | | | | | | | | |
| Billings: | | | | | | | | | | | | | | | | | |
| Add: change in total deferred revenue, net of acquired deferred revenue | | | 2,180.6 | | | | | | 2,301.7 | | | | | | 1,970.0 | | |
Product revenue also includes revenue derived from software licenses of Panorama, SD-WAN, and the VM-Series.
Our three geographic theaters had similar year-over-year revenue growth rates for fiscal 2024, with the Americas contributing the highest increase in revenue due to its larger scale.
Product gross margin increased for fiscal 2024 compared to fiscal 2023 primarily due to increased software revenue and lower costs largely driven by an easing of supply chain challenges.
Subscription and support gross margin increased for fiscal 2024 compared to fiscal 2023 primarily due to our growth in subscription and support revenue, which outpaced the subscription and support costs.
The increase in sales and marketing expense was further driven by increased costs associated with sales and marketing events and go-to-market initiatives.
* Not meaningful
| Total cash, cash equivalents, and investments | | | $ | 6,752.0 | | | | | $ | 5,437.9 | |
Beginning in fiscal 2023, we were required to capitalize and amortize research and development expenses as required by the Tax Cuts and Jobs Act.
As a result of this change and our increased profitability, we have paid significantly more U.S. cash taxes during fiscal 2024 and we expect our cash tax payments to increase in future periods.
The 2025 Notes mature on June 1, 2025; however, under certain circumstances, holders may surrender their 2025 Notes for conversion prior to the maturity date.
Upon conversion of the 2025 Notes, we will pay cash equal to the aggregate principal amount of the 2025 Notes to be converted, and, at our election, we will pay or deliver cash and/or shares of our common stock for the amount of our conversion obligation in excess of the aggregate principal amount of the 2025 Notes being converted.
An excerpt. Shown here: 40 of 155 rewritten, 40 of 82 added and 40 of 60 removed. The counts are complete. For every sentence, read Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations in the FY2025 filing and the FY2024 filing.
Item 7A. Quantitative and Qualitative Disclosures About Market Risk
6 rewritten, 1 added, 5 removed, 17 unchanged
Our sales contracts are [added: primarily] denominated in U.S. dollars.
A portion of our operating expenditures are [removed: incurred outside of the United States and are] denominated in foreign [removed: currencies and are] [added: currencies, making them] subject to fluctuations [removed: due to changes] in foreign currency exchange rates.
We enter into foreign currency derivative contracts with maturities of 24 months or less, which we designate as cash flow hedges, to manage the foreign currency exchange risk associated with our [removed: foreign currency denominated] [added: revenue and] operating expenditures.
A hypothetical 10% change in foreign exchange rates on monetary assets and liabilities would not be material to our financial condition or results of operations after taking into consideration the effect of foreign currency forward contracts in place as of July 31, [removed: 2024.][added: 2025.]
Based on investment positions as of July 31, [removed: 2024,] [added: 2025,] a hypothetical 100 basis point increase in interest rates across all maturities would result in a [removed: $97.8] [added: $132.3] million decline in the fair market value of the portfolio.
Conversely, a hypothetical 100 basis point decrease in interest rates would lead to a [removed: $97.8] [added: $134.7] million increase in the fair market value of the portfolio.
\- 56 \-
In June 2020, we issued $2.0 billion aggregate principal amount of the 2025 Notes.
We carry these instruments at face value less unamortized issuance costs on our consolidated balance sheets.
As these instruments have a fixed annual interest rate, we have no financial and economic exposure associated with changes in interest rates.
However, the fair value of fixed rate debt instruments fluctuates when interest rates change, and additionally, in the case of the 2025 Notes, when the market price of our common stock fluctuates.
\- 57 \-
Item 1. Business
103 rewritten, 98 added, 127 removed, 129 unchanged
Palo Alto Networks, Inc. is a global cybersecurity provider [removed: with a] [added: and our] vision [removed: of] [added: is] a world where each day is safer and more secure than the one before.
Our platformization strategy combines various products and services into a tightly integrated architecture [removed: and makes security] [added: for more secure,] faster, [removed: less complex,] and [removed: more cost-effective.][added: cost-effective outcomes.]
[removed: Network Security:][added: Network Security]
[added: - *Secure Access Service Edge (“SASE”).*] Prisma® Access, [removed: our Security Services Edge (“SSE”) solution,] when combined with Prisma SD-WAN, provides a comprehensive single-vendor SASE offering that is used to secure remote workforces and [removed: securely enable the] cloud-delivered [removed: branch.][added: branch offices.]
[removed: Our network security platform also includes our cloud-delivered security services, such as] [added: These include] Advanced Threat Prevention, Advanced WildFire®, Advanced URL Filtering, Advanced DNS Security, IoT/OT Security, GlobalProtect®, [added: Prisma Access Agent,] Enterprise Data Loss Prevention (“Enterprise DLP”), AI for IT Operations (“AIOps”), [removed: SaaS] [added: Software as a Service (“SaaS”)] Security, and AI Access Security.
Through these add-on [removed: security] services, our customers are able to secure their content, applications, users, and devices across their entire organization.
[removed: Cloud Security:][added: Cloud-Delivered Security Services]
- [added: *Cloud Security.*] We deliver [removed: scalable and] comprehensive security across the cloud application development lifecycle through [removed: our Code to CloudTM platform, Prisma Cloud.][added: Cortex Cloud, delivered as a scalable SaaS offering.]
As a comprehensive Cloud Native Application Protection Platform [removed: (“CNAPP”), Prisma] [added: (“CNAPP”) combined with CDR, Cortex] Cloud secures multi- and hybrid-cloud environments for applications, data, generative AI (“GenAI”) ecosystem, and the [removed: entire] cloud native technology stack across the full development lifecycle, from code to [removed: cloud.][added: cloud to security operations.]
[removed: Security Operations:][added: Security Operations]
- [added: *Security Operations.*] We deliver the next generation of security operations capabilities that [removed: combine security analytics,] [added: unifies standalone Security Information and Event Management (“SIEM”) tools,] endpoint security, [added: security] automation, [added: cloud detection] and [added: response (“CDR”), as well as] attack surface management (“ASM”) [removed: solutions through] [added: capabilities on] our Cortex® platform.
These include Cortex XSIAM®, [removed: our AI-driven] [added: for AI-powered] security operations [removed: platform,] [added: replacing traditional SIEM tools,] Cortex [removed: XDR®] [added: XDR®,] for the prevention, detection, and response to complex cybersecurity attacks, Cortex [removed: XSOAR®] [added: XSOAR®,] for security orchestration, automation, and response (“SOAR”), and Cortex [removed: Xpanse®] [added: Xpanse®,] for ASM.
[removed: Threat] [added: Threat] Intelligence and Advisory [removed: Services (Unit 42):][added: Services]
- [added: Threat Intelligence, Incident Response and Security Consulting.] Unit [removed: 42®] [added: 42] brings together world-renowned threat [removed: researchers with an elite team of] [added: researchers,] incident [removed: responders] [added: responders,] and security consultants to create an intelligence-driven, response-ready organization [removed: to help customers] [added: that is passionate about helping clients proactively] manage cyber risk.
Our [added: elite] consultants serve as trusted advisors to our customers by assessing and testing their security controls against [removed: the right] [added: sophisticated] threats, transforming their security strategy with a threat-informed approach, and responding to security incidents on behalf of our clients.
Additionally, Unit 42 offers managed detection and response [added: (“MDR”)] and managed threat hunting services.
[removed: Hardware] [added: Next-Generation Firewalls. Our hardware] and software [removed: firewalls. Our] ML-Powered Next Generation Firewalls [removed: embed] [added: use AI—including] machine learning [removed: in the core of the firewall] and [removed: employ inline] deep [removed: learning in the cloud, empowering our customers to] [added: learning—to] stop zero-day threats in real time, [removed: see] and [added: detect and] secure [removed: their] [added: the] entire enterprise including Internet of Things [removed: (“IoT”), and reduce errors with automatic policy recommendations.][added: (“IoT”).]
All of our hardware and software firewalls incorporate [removed: our] [added: the] PAN-OS® operating system and [removed: come with] [added: include] the same rich set of features, ensuring consistent operation across our entire product line.
Our [removed: appliances] [added: hardware] and software are designed for different performance requirements throughout an [removed: organization and are classified based on throughput, ranging] [added: organization—with the ability to secure everything] from [removed: our PA-410, which is designed for] small [removed: organizations] [added: businesses] and branch offices, to [removed: our top-of-the-line PA-7500 Series, which is designed for] large-scale data centers and service providers.
We also offer Cloud NGFW, a managed [removed: next-generation firewall (“NGFW”)] [added: NGFW] offering, to secure customers’ applications on Amazon Web Services (“AWS”) and Microsoft Azure (“Azure”).
[added: Panorama.] Panorama is used for centralized policy management, device management, software licensing and updates, centralized logging and reporting, and log storage.
[removed: Many of our existing deployments continue using Panorama as the security management solution, while new] [added: New] deployments benefit from using [removed: Strata Cloud Manager instead] [added: SCM] for managing network security estate—including our Next-Generation Firewalls and SASE—with a cloud-based, unified management interface.
[removed: Cloud-delivered security services:][added: - *Cloud-Delivered Security Services (“CDSS”)*.]
In addition, [removed: it offers] [added: we offer] inline deep learning to deliver real-time detection and prevention of unknown, evasive, and targeted command-and-control (“C2”) communications over HTTP, unknown-TCP, unknown-UDP, and encrypted over SSL.
Advanced Threat Prevention is the [removed: first] [added: industry’s only] offering to protect the enterprise from unknown command and control in [removed: real-time.][added: real-time with the power of Precision AITM.]
[removed: It delivers] [added: We deliver] real-time detection and prevention of unknown, evasive, and targeted web-based threats, such as [removed: phishing, malware, and C2.][added: phishing.]
In addition, [removed: it] [added: the service] includes a cloud-based URL filtering database which consists of millions of URLs across many categories and is designed to analyze web traffic and prevent web-based threats, such as phishing, malware, and C2.
[removed: It] [added: The service] allows our network security platform access to Domain Name System (“DNS”) signatures that are generated using advanced predictive analysis, machine learning, and malicious domain data from a growing threat intelligence sharing community of which we are a [removed: part.][added: part of.]
[removed: It offers] [added: We offer] comprehensive DNS attack coverage and [removed: includes] [added: include] industry-first protections against multiple emerging DNS-based network attacks, including real-time analysis of DNS response to prevent DNS hijacking.
[removed: It] [added: The service] uses machine learning to baseline normal behavior, identify anomalous activity, assess risk, and provide policy [removed: recommendations to allow trusted behavior with a new Device-ID policy construct on our network security platform.][added: recommendations.]
- SaaS Security API. SaaS Security API [removed: (formerly Prisma SaaS)] is a multi-mode, cloud access security broker (“CASB”) that helps govern sanctioned SaaS application usage across all users and helps prevent breaches and non-compliance.
- SaaS Security Inline. SaaS Security Inline adds an inline service to automatically gain visibility and control over thousands of known and [removed: new] [added: newly] sanctioned, unsanctioned and tolerated SaaS applications in use within organizations today.
[removed: It] [added: The service] provides enterprise data protection and compliance across all SaaS applications and prevents cloud threats in real [removed: time with best-in-class security.][added: time.]
[removed: It] [added: The solution] can be combined with SaaS Security API as a complete integrated CASB.
Regardless of the operating [removed: systems,] [added: system,] laptops, tablets, and phones will stay connected to the corporate network when they are on a network of any kind [removed: and,] [added: and] as a result, are protected as if they never left the corporate campus.
- Enterprise DLP. This cloud-delivered security service provides [removed: consistent,] [added: consistent and] reliable protection of sensitive data, such as personally identifiable information and intellectual property, for all traffic types, applications, and users.
Native integration with our products makes [removed: it] [added: the service] simple to deploy, [removed: and] [added: while] advanced machine learning minimizes management complexity.
[added: - AI Access Security.] AI Access Security classifies and prioritizes GenAI applications to assess risk, detect anomalies and visualize insights across multiple GenAI-specific attributes.
[removed: It] [added: The service] prevents sensitive data loss and defends against malicious responses, ensuring safe and effective AI adoption.
[added: - AIOps.] AIOps [removed: redefines network operational experience by empowering] [added: enables] security teams to proactively strengthen security posture and resolve network disruptions.
Our mission is to be the cybersecurity partner of choice for enterprises, organizations, service providers, and government entities to protect our digital way of life.
Our network security platform is designed to deliver complete zero trust solutions to our customers.
The platform includes:
Prisma Access Browser further extends SASE security and data protection to the end user device, providing workers with freedom to access business applications securely using our secure browser from any device.
- *Next-Generation Firewalls*.
Our hardware ML-Powered Next-Generation Firewalls (“NGFWs”) secure on-premises environments including campus locations and data centers.
Our software NGFWs secure cloud networks.
Our network security platform integrates a suite of CDSS that complements our SASE and Firewall solutions.
- *Prisma AIRS.* Prisma AIRS is a comprehensive AI security platform that has been designed to protect customers’ entire AI ecosystem by providing AI model scanning, posture management, red teaming, run-time security, and AI agent security.
SCM, our network security management solution, centrally manages network security across all remote workers, branches, headquarters, campuses, and cloud.
SCM leverages AI to simplify and strengthen network security by enabling customers to proactively pinpoint vulnerabilities, gain real-time remediation recommendations, and enhance overall digital experiences, thereby reducing operational burden.
This comprehensive solution includes Strata Copilot, which offers a natural language interface for enhanced insights and guided remediation, and integrates Autonomous Digital Experience Monitoring (“ADEM”) to proactively maintain infrastructure health, facilitate AI-driven one-click troubleshooting, and ensure seamless end-user performance across the enterprise.
Our AI-powered Cortex platform transforms end-to-end security operations with unified data, AI, and automation for more secure, faster, and cost effective outcomes.
We have consolidated our industry-leading Security Operations and Cloud Security capabilities on a single comprehensive platform to provide centralized visibility, proactive protection, real-time prevention, AI-driven insights, and automated remediation across enterprise and cloud.
As part of the Cortex Cloud platform, customers can expand from Cortex Cloud to our security operations offerings available on a single user experience and unified agent.
Products and Services
NETWORK SECURITY
This includes SD-WAN capabilities to intelligently steer traffic to data centers, branches, and the cloud, natively integrated into our Next-Generation Firewalls.
Enterprise data, applications, users, and devices become integral components of an organization’s security policy.
Our firewalls come in hardware form factors, containerized form factors, called CN-Series, as well as virtual form factors, called VM-Series, available on all major cloud hosting service providers.
Preventions are delivered in seconds to our network security platform.
The solution can be combined with SaaS Security Inline for a complete integrated CASB.
- Prisma Access Agent. Prisma Access Agent provides secure, remote access to corporate resources for employees working from any location or device.
The agent establishes an encrypted tunnel to Prisma Access or our NGFW, ensuring consistent security, data protection, and threat prevention for a distributed workforce accessing any application.
Prisma AIRS. Prisma AIRS is a comprehensive AI security platform engineered to protect customers' entire AI ecosystem across its lifecycle.
It addresses unique AI security challenges such as prompt injection, data poisoning, and sensitive data leakage, by providing deep visibility and control across AI models, data, and applications.
The platform offers AI Model Scanning for vulnerabilities, Posture Management for secure configurations, and AI Red Teaming for proactive testing.
Critically, Runtime Security prevents threats during live AI model execution, while AI Agent Security extends protection to autonomous AI agents.
As an AI-powered, unified cloud management solution, SCM enables organizations to enhance their network security posture and streamline operations.
It utilizes AI to swiftly identify potential vulnerabilities, provide real-time recommendations for remediation, proactively address support needs, and improve overall digital experiences, leading to reduced operational overhead and improved speed, accuracy, and scale of support.
By analyzing telemetry, historical data, and its diverse knowledge base, SCM can instantly answer questions, pinpoint solutions to known problems, and automate data collection to speed up assisted support for new challenges.
Built into this robust solution are Strata Copilot, offering a natural language interface for intuitive insights and guided actions, and ADEM, designed for proactive infrastructure health, simplified troubleshooting, and consistent end-user performance across the network.
Many of our existing deployments continue to use Panorama as the security management solution.
- Cortex Cloud. Available as a stand-alone cloud-based service or an add-on to Cortex XDR or to Cortex XSIAM.
Cortex Cloud, the next generation of Prisma Cloud, merges CNAPP with CDR for real-time cloud security.
The solution allows you to harness the power of AI and automation to prioritize cloud risks with runtime context, enable remediation at scale, and stop attacks as they happen.
As part of the Cortex platform, customers can transform end-to-end security operations, from code to cloud to SOC, by adopting Cortex Cloud together with Cortex XSIAM.
Existing customers can continue leveraging Prisma Cloud as they upgrade to Cortex Cloud for significantly better, faster and more effective multi-cloud protection.
THREAT INTELLIGENCE AND ADVISORY SERVICES
Our research and development efforts are strategically centered on expanding our leadership within the enterprise security industry through AI-powered innovation.
We empower enterprises, organizations, service providers, and government entities to protect themselves against today’s most sophisticated cyber threats.
We focus on delivering value in four sectors of the cybersecurity industry:
- Our network security platform, designed to deliver complete zero trust solutions to our customers, includes our hardware and software ML-Powered Next-Generation Firewalls, AI Runtime Security, as well as a cloud-delivered Secure Access Service Edge (“SASE”).
Strata Cloud Manager, our network security management solution, can centrally manage our network security platform irrespective of form factor, location, or scale.
Strata Cloud Manager includes the Strata Copilot which provides a natural language interface to simplify and accelerate platform management.
These products are delivered as software as a service (“SaaS”) or software subscriptions.
Product, Subscription, and Support
Our customer offerings are available in the form of the product, subscription, and support offerings described below:
PRODUCTS
The content, applications, users, and devices—the elements that run a business—become integral components of an enterprise’s security policy via our Content-ID™, App-ID™, User-ID™, and Device-ID technologies.
In addition to these components, key features include site-to-site virtual private network (“VPN”), remote access Secure Sockets Layer (“SSL”) VPN, and Quality-of-Service.
Our firewalls come in a hardware form factor, a containerized form factor, called CN-Series, as well as a virtual form factor, called VM-Series, that is available for virtualization and cloud environments from companies such as Broadcom Inc., Microsoft Corporation (“Microsoft”), Amazon.com, Inc. (“Amazon”), and Alphabet Inc. (“Alphabet”), and in Kernel-based Virtual Machine /OpenStack environments.
SD-WAN. Our SD-WAN is integrated with PAN-OS so that our end-customers can get the security features of our PAN-OS ML-Powered Next-Generation Firewall together with SD-WAN functionality.
The SD-WAN overlay supports dynamic, intelligent path selection based on the applications, services, and conditions of the links that each application or service is allowed to use, allowing applications to be prioritized based on criteria such as whether the application is mission-critical, latency-sensitive, or meets certain health criteria.
Panorama. Panorama is our centralized security management solution for global control of our network security platform.
Panorama can be deployed as a virtual appliance or a physical appliance.
SUBSCRIPTIONS
We offer a number of subscriptions as part of our network security platform.
Of these subscription offerings, cloud-delivered security services, such as Advanced Threat Prevention, Advanced WildFire, Advanced URL Filtering, Advanced DNS Security, IoT/OT Security, SaaS Security Inline, GlobalProtect, Enterprise DLP, AIOps, and AI Runtime Security are sold as options to our hardware and software firewalls, whereas SaaS Security API, AI Access Security, Prisma Access, Prisma SD-WAN, Strata Cloud Manager, Prisma Cloud, Cortex XSIAM, Cortex XDR, Cortex XSOAR, and Cortex Xpanse are sold on a per-user, per-endpoint, or capacity-based basis—and they can be activated by customers with or without our firewalls.
Our subscription offerings include:
It includes mechanisms—such as protocol decoder-based analysis, protocol anomaly-based protection, stateful pattern matching, statistical anomaly detection, heuristic-based analysis, custom vulnerability and spyware “phone home” signatures, and workflows—to manage popular open-source signature formats to extend our coverage.
In addition, Advanced WildFire defeats highly evasive modern malware at scale with a new infrastructure and patented analysis techniques, including intelligent runtime memory analysis, dependency emulation, malware family fingerprinting, and more.
Once identified, whether in the cloud or inline, preventive measures are automatically generated and delivered in seconds or less to our network security platform.
While many vendors use machine learning to categorize web content or prevent malware downloads, Advanced URL Filtering is the industry’s first inline web protection engine capable of detecting never-before-seen web-based threats and preventing them in real-time.
Unlike other solutions, it does not require endpoint routing configurations to be maintained and therefore cannot be bypassed.
Expanded categorization of DNS traffic and comprehensive analytics allow deep insights into threats, empowering security personnel with the context to optimize their security posture.
Other subscriptions have also been enhanced with IoT context to prevent threats on various devices, including IoT and OT devices.
It delivers complete visibility and granular enforcement across all user, folder, and file activity within sanctioned SaaS applications, and can be combined with SaaS Security Inline for a complete integrated CASB.
The solution is easy to deploy being natively integrated on network security platform, eliminating the architectural complexity of traditional CASB products, while offering low total cost of ownership.
When a remote user logs into the device, GlobalProtect automatically determines the closest gateway available to the roaming device and establishes a secure connection.
GlobalProtect ensures that the same secure application enablement policies that protect users at the corporate site are enforced for all users, independent of their location.
It helps minimize the risk of a data breach both on-premises and in the cloud—such as in Office/Microsoft 365™, Salesforce®, and Box—and assists in meeting stringent data privacy and compliance regulations, including the E.U. General Data Protection Regulation, the California Consumer Privacy Act, the Payment Card Industry Data Security Standard , HIPAA (Health Insurance Portability and Accountability Act) requirements, and others.
- AI Access Security. GenAI applications can inadvertently expose sensitive company data, such as intellectual property, trade secrets, source code, financial records and customer information, leading to significant business and compliance risks.
In addition, public GenAI tools can be exploited to spread malware and compromise cybersecurity defenses.
- AIOps: AIOps is available in both free and licensed premium versions.
With these capabilities, Prisma Access delivers an optimized digital experience and application performance to end users.
AI Runtime Security:
- AI applications and large language model (“LLM”) models challenge traditional security.
Increasingly sophisticated attacks on AI ecosystems require protection from AI applications, models and datasets.
AI Runtime Security continuously monitors AI applications, models and datasets for potential threats and anomalies.
An excerpt. Shown here: 40 of 103 rewritten, 40 of 98 added and 40 of 127 removed. The counts are complete. For every sentence, read Item 1. Business in the FY2025 filing and the FY2024 filing.
Item 3. Legal Proceedings
1 rewritten, 0 added, 0 removed, 1 unchanged
The information set forth under the “Litigation” subheading in Note [removed: 12.][added: 13.]
Cover and table of contents
31 rewritten, 6 added, 2 removed, 92 unchanged
For the fiscal year ended July 31, [removed: 2024][added: 2025]
The aggregate market value of voting stock held by non-affiliates of the registrant was approximately [removed: $108.1] [added: $119.7] billion as of January 31, [removed: 2024,] [added: 2025,] the last business day of the registrant’s most recently completed second fiscal quarter (based on the closing sales price for the common stock on the Nasdaq Global Select Market on such date).
On August [removed: 19, 2024, 325.6] [added: 18, 2025, 668.9] million shares of the registrant’s common stock, $0.0001 par value, were outstanding.
Portions of the information called for by Part III of this Annual Report on Form 10-K is hereby incorporated by reference from the definitive proxy statement for the registrant’s [removed: 2024] [added: 2025] annual meeting of stockholders, which will be filed with the Securities and Exchange Commission not later than 120 days after the registrant’s fiscal year ended July 31, [removed: 2024.][added: 2025.]
| Item 1. | | | [removed: [Business](#id0a9ebb26d9d4578997f123b627a595a_13)] [added: [Business](#i7c6d02d19ae642d183bd6885f5b5223e_13)] | | | [removed: [4](#id0a9ebb26d9d4578997f123b627a595a_13)] [added: [4](#i7c6d02d19ae642d183bd6885f5b5223e_13)] | | |
| Item 1A. | | | [Risk [removed: Factors](#id0a9ebb26d9d4578997f123b627a595a_46)] [added: Factors](#i7c6d02d19ae642d183bd6885f5b5223e_46)] | | | [removed: [15](#id0a9ebb26d9d4578997f123b627a595a_46)] [added: [14](#i7c6d02d19ae642d183bd6885f5b5223e_46)] | | |
| Item 1B. | | | [Unresolved Staff [removed: Comments](#id0a9ebb26d9d4578997f123b627a595a_79)] [added: Comments](#i7c6d02d19ae642d183bd6885f5b5223e_82)] | | | [removed: [36](#id0a9ebb26d9d4578997f123b627a595a_79)] [added: [37](#i7c6d02d19ae642d183bd6885f5b5223e_82)] | | |
| Item 1C. | | | [removed: [Cybersecurity](#id0a9ebb26d9d4578997f123b627a595a_82)] [added: [Cybersecurity](#i7c6d02d19ae642d183bd6885f5b5223e_85)] | | | [removed: [37](#id0a9ebb26d9d4578997f123b627a595a_82)] [added: [37](#i7c6d02d19ae642d183bd6885f5b5223e_85)] | | |
| Item 2. | | | [removed: [Properties](#id0a9ebb26d9d4578997f123b627a595a_85)] [added: [Properties](#i7c6d02d19ae642d183bd6885f5b5223e_88)] | | | [removed: [39](#id0a9ebb26d9d4578997f123b627a595a_85)] [added: [39](#i7c6d02d19ae642d183bd6885f5b5223e_88)] | | |
| Item 3. | | | [Legal [removed: Proceedings](#id0a9ebb26d9d4578997f123b627a595a_88)] [added: Proceedings](#i7c6d02d19ae642d183bd6885f5b5223e_91)] | | | [removed: [39](#id0a9ebb26d9d4578997f123b627a595a_88)] [added: [39](#i7c6d02d19ae642d183bd6885f5b5223e_91)] | | |
| Item 4. | | | [Mine Safety [removed: Disclosures](#id0a9ebb26d9d4578997f123b627a595a_91)] [added: Disclosures](#i7c6d02d19ae642d183bd6885f5b5223e_94)] | | | [removed: [39](#id0a9ebb26d9d4578997f123b627a595a_91)] [added: [39](#i7c6d02d19ae642d183bd6885f5b5223e_94)] | | |
| Item 5. | | | [Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity [removed: Securities](#id0a9ebb26d9d4578997f123b627a595a_97)] [added: Securities](#i7c6d02d19ae642d183bd6885f5b5223e_100)] | | | [removed: [40](#id0a9ebb26d9d4578997f123b627a595a_97)] [added: [40](#i7c6d02d19ae642d183bd6885f5b5223e_100)] | | |
| Item 7. | | | [Management’s Discussion and Analysis of Financial Condition and Results of [removed: Operations](#id0a9ebb26d9d4578997f123b627a595a_106)] [added: Operations](#i7c6d02d19ae642d183bd6885f5b5223e_109)] | | | [removed: [43](#id0a9ebb26d9d4578997f123b627a595a_106)] [added: [42](#i7c6d02d19ae642d183bd6885f5b5223e_109)] | | |
| Item 7A. | | | [Quantitative and Qualitative Disclosures About Market [removed: Risk](#id0a9ebb26d9d4578997f123b627a595a_190)] [added: Risk](#i7c6d02d19ae642d183bd6885f5b5223e_187)] | | | [removed: [57](#id0a9ebb26d9d4578997f123b627a595a_190)] [added: [56](#i7c6d02d19ae642d183bd6885f5b5223e_187)] | | |
| Item 8. | | | [Financial Statements and Supplementary [removed: Data](#id0a9ebb26d9d4578997f123b627a595a_193)] [added: Data](#i7c6d02d19ae642d183bd6885f5b5223e_190)] | | | [removed: [58](#id0a9ebb26d9d4578997f123b627a595a_193)] [added: [57](#i7c6d02d19ae642d183bd6885f5b5223e_190)] | | |
| Item 9. | | | [Changes in and Disagreements with Accountants on Accounting and Financial [removed: Disclosure](#id0a9ebb26d9d4578997f123b627a595a_337)] [added: Disclosure](#i7c6d02d19ae642d183bd6885f5b5223e_322)] | | | [removed: [96](#id0a9ebb26d9d4578997f123b627a595a_337)] [added: [95](#i7c6d02d19ae642d183bd6885f5b5223e_322)] | | |
| Item 9A. | | | [Controls and [removed: Procedures](#id0a9ebb26d9d4578997f123b627a595a_340)] [added: Procedures](#i7c6d02d19ae642d183bd6885f5b5223e_325)] | | | [removed: [96](#id0a9ebb26d9d4578997f123b627a595a_340)] [added: [95](#i7c6d02d19ae642d183bd6885f5b5223e_325)] | | |
| Item 9B. | | | [Other [removed: Information](#id0a9ebb26d9d4578997f123b627a595a_346)] [added: Information](#i7c6d02d19ae642d183bd6885f5b5223e_328)] | | | [removed: [97](#id0a9ebb26d9d4578997f123b627a595a_346)] [added: [96](#i7c6d02d19ae642d183bd6885f5b5223e_328)] | | |
| Item 9C. | | | [Disclosure Regarding Foreign Jurisdictions That Prevent [removed: Inspections](#id0a9ebb26d9d4578997f123b627a595a_349)] [added: Inspections](#i7c6d02d19ae642d183bd6885f5b5223e_331)] | | | [removed: [97](#id0a9ebb26d9d4578997f123b627a595a_349)] [added: [96](#i7c6d02d19ae642d183bd6885f5b5223e_331)] | | |
| Item 10. | | | [Directors, Executive Officers and Corporate [removed: Governance](#id0a9ebb26d9d4578997f123b627a595a_355)] [added: Governance](#i7c6d02d19ae642d183bd6885f5b5223e_337)] | | | [removed: [98](#id0a9ebb26d9d4578997f123b627a595a_355)] [added: [97](#i7c6d02d19ae642d183bd6885f5b5223e_337)] | | |
| Item 11. | | | [Executive [removed: Compensation](#id0a9ebb26d9d4578997f123b627a595a_358)] [added: Compensation](#i7c6d02d19ae642d183bd6885f5b5223e_340)] | | | [removed: [98](#id0a9ebb26d9d4578997f123b627a595a_358)] [added: [97](#i7c6d02d19ae642d183bd6885f5b5223e_340)] | | |
| Item 12. | | | [Security Ownership of Certain Beneficial Owners and Management and Related Stockholder [removed: Matters](#id0a9ebb26d9d4578997f123b627a595a_361)] [added: Matters](#i7c6d02d19ae642d183bd6885f5b5223e_343)] | | | [removed: [98](#id0a9ebb26d9d4578997f123b627a595a_361)] [added: [97](#i7c6d02d19ae642d183bd6885f5b5223e_343)] | | |
| Item 13. | | | [Certain Relationships and Related Transactions, and Director [removed: Independence](#id0a9ebb26d9d4578997f123b627a595a_364)] [added: Independence](#i7c6d02d19ae642d183bd6885f5b5223e_346)] | | | [removed: [98](#id0a9ebb26d9d4578997f123b627a595a_364)] [added: [97](#i7c6d02d19ae642d183bd6885f5b5223e_346)] | | |
| Item 14. | | | [Principal Accountant Fees and [removed: Services](#id0a9ebb26d9d4578997f123b627a595a_367)] [added: Services](#i7c6d02d19ae642d183bd6885f5b5223e_349)] | | | [removed: [98](#id0a9ebb26d9d4578997f123b627a595a_367)] [added: [97](#i7c6d02d19ae642d183bd6885f5b5223e_349)] | | |
| Item 15. | | | [Exhibits and Financial Statement [removed: Schedules](#id0a9ebb26d9d4578997f123b627a595a_373)] [added: Schedules](#i7c6d02d19ae642d183bd6885f5b5223e_355)] | | | [removed: [99](#id0a9ebb26d9d4578997f123b627a595a_373)] [added: [98](#i7c6d02d19ae642d183bd6885f5b5223e_355)] | | |
| Item 16. | | | [Form 10-K [removed: Summary](#id0a9ebb26d9d4578997f123b627a595a_376)] [added: Summary](#i7c6d02d19ae642d183bd6885f5b5223e_358)] | | | [removed: [103](#id0a9ebb26d9d4578997f123b627a595a_376)] [added: [101](#i7c6d02d19ae642d183bd6885f5b5223e_358)] | | |
- expectations regarding annual recurring [removed: revenue] [added: revenue, remaining performance obligations,] and product development strategy;
- statements regarding expected profitability, [added: trends in annual recurring revenue, trends in remaining performance obligations,] our mix of product and subscription and support revenue, cost of revenue, gross margin, cash flows, operating expenses, including future share-based compensation expense, income taxes, investment plans, and liquidity;
- our ability to successfully acquire and integrate companies and assets and [removed: our] expectations and intentions with respect to the [added: assets,] products and technologies that we [removed: acquire] [added: acquire, including with respect to our proposed acquisition of CyberArk Software Ltd.] and [removed: introduce;][added: our expectations regarding the benefits and synergies of the proposed acquisition;]
- the effects of worldwide economic and geopolitical conditions, including but not limited to hostilities in Israel and the surrounding [removed: region,] [added: regions,] inflation, [added: tariff rates,] interest rate levels, [added: public or administration policies, trade regulations, trade policy,] growth rates and other conditions, on our operating and financial results and performance;
These forward-looking statements are [added: based on current expectations and assumptions that are] subject to [removed: a number of risks, uncertainties,] [added: risks] and [removed: assumptions,] [added: uncertainties,] including those described in “Risk Factors” included in Part I, Item 1A and elsewhere in this Annual Report on Form 10-K.
| Item 6. | | | [\[Reserved\]](#i7c6d02d19ae642d183bd6885f5b5223e_106) | | | [41](#i7c6d02d19ae642d183bd6885f5b5223e_106) | | |
| | | | [Signatures](#i7c6d02d19ae642d183bd6885f5b5223e_361) | | | [102](#i7c6d02d19ae642d183bd6885f5b5223e_361) | | |
- expectations relating to our customer financing activities;
- our ability to complete, on a timely basis, or at all, announced transactions, including our proposed acquisition of CyberArk Software Ltd.;
- expectations regarding contingent consideration obligations;
- the manufacture, delivery and cost of certain of our products;
| Item 6. | | | [\[Reserved\]](#id0a9ebb26d9d4578997f123b627a595a_103) | | | [42](#id0a9ebb26d9d4578997f123b627a595a_103) | | |
| | | | [Signatures](#id0a9ebb26d9d4578997f123b627a595a_379) | | | [104](#id0a9ebb26d9d4578997f123b627a595a_379) | | |
Item 1B. Unresolved Staff Comments
0 rewritten, 0 added, 1 removed, 1 unchanged
\- 36 \-
Item 1C. Cybersecurity
7 rewritten, 0 added, 0 removed, 35 unchanged
We maintain a cross-functional incident response team, including senior representatives from information security, information technology, product, legal, privacy, [removed: communications] [added: communications,] and [removed: accounting,] [added: finance,] that is involved in assessing cybersecurity threats and incidents, assigning severity levels, and evaluating the potential impact, including the potential impact on our business strategy, results of operations and financial condition.
This allows for prompt direction of appropriate personnel and resources for incident management and response, and internal notification to appropriate members of management, which may include our chief executive officer, chief product [added: and technology] officer, [added: vice president acting as] chief information security officer, general counsel, chief financial officer, and/or chief accounting officer, and the security committee of our board of directors (the “Security Committee”).
The Security Committee, which is composed of [removed: all of] our independent [removed: directors,] [added: directors and chaired by our chief product and technology officer,] facilitates our board of directors’ responsibility for oversight of security matters, including product security, data security, cybersecurity, security risk management, risk exposure and related controls and enterprise risk management related to these risks.
The Security Committee meets quarterly to review with our [added: vice president acting as] chief information security officer and other members of management, which may include our chief executive officer, chief product [added: and technology] officer, chief financial officer, and general counsel, our cybersecurity programs, cybersecurity risks, mitigation or remediation strategies, and other matters impacting the committee’s responsibilities.
Our [added: vice president acting as] chief information security officer is responsible for defining, overseeing, managing, implementing, and reviewing compliance with the information security programs described above under the heading “Cybersecurity Risk Management and Strategy.” [removed: Our chief information security officer] [added: This vice president] receives regular reports from our information security team and monitors the prevention, detection, and mitigation or remediation of cybersecurity risks.
In particular, our [added: vice president acting as] chief information security officer has extensive experience in the management of cybersecurity risk management programs, having served in various roles in information technology and security for over [removed: 20 years, including having previously served as the chief security officer of two other publicly traded technology companies.][added: 25 years.]
In addition, six of the [removed: ten] [added: eleven] members of our board of directors have expertise in overseeing cybersecurity and information security management.
Item 2. Properties
1 rewritten, 0 added, 0 removed, 8 unchanged
Refer to Note [removed: 11.][added: 12.]
Item 5. Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities
11 rewritten, 4 added, 10 removed, 20 unchanged
Our common stock, $0.0001 par value per share, is traded on the Nasdaq Global Select Market under the symbol “PANW.” [removed: Prior to October 22, 2021, our common stock traded on the New York Stock Exchange under the symbol “PANW.”]
As of August [removed: 19, 2024,] [added: 18, 2025,] there were [removed: 502] [added: 565] holders of record of our common stock.
During the three months ended July 31, [removed: 2024,] [added: 2025,] holders of the 2025 Notes converted [removed: $199.6] [added: $382.9] million in aggregate principal amount of the 2025 Notes, which we repaid in cash.
We also issued [removed: 1.3] [added: 5.6] million shares of our unregistered common stock to the holders of the 2025 Notes for the conversion value in excess of the principal amount.
[removed: In December 2020, August 2021, August 2022, and November 2023, we] [added: We subsequently] announced additional [removed: $700.0 million, $676.1 million, $915.0 million, and $316.7 million] increases to this share repurchase program, [removed: respectively,] bringing the total authorization to [removed: $3.6] [added: $4.1] billion, with [removed: $500.0 million] [added: $1.0 billion] remaining as of July 31, [removed: 2024.][added: 2025.]
The expiration date of this repurchase authorization was extended to December 31, [removed: 2024,] [added: 2025,] and our repurchase program may be suspended or discontinued at any time.
During the three months ended July 31, [removed: 2024,] [added: 2025,] we did not repurchase any shares pursuant to our share repurchase program.
This performance graph compares the cumulative total return on our common stock with that of the Nasdaq 100 Index, the Standard & Poor’s 500 Index, and the Standard & Poor’s 500 Information Technology Index for the five years ended July 31, [removed: 2024.][added: 2025.]
This performance graph assumes $100 was invested on July 31, [removed: 2019,] [added: 2020,] in each of the common stock of Palo Alto Networks, Inc., the Nasdaq 100 Index, the Standard & Poor’s 500 Index, and the Standard & Poor’s 500 Information Technology Index, and assumes the reinvestment of any dividends.
[removed: ][added: ]
| Company/Index | | | | | | [removed: 7/31/2019] [added: 7/31/2020] | | | | | | [removed: 7/31/2020] [added: 7/31/2021] | | | | | | [removed: 7/31/2021] [added: 7/31/2022] | | | | | | [removed: 7/31/2022] [added: 7/31/2023] | | | | | | [removed: 7/31/2023] [added: 7/31/2024] | | | | | | [removed: 7/31/2024] [added: 7/31/2025] | | |
| Palo Alto Networks, Inc. | | | | | | $ | 100.00 | | | | | $ | 155.93 | | | | | $ | 195.02 | | | | | $ | 293.01 | | | | | $ | 380.66 | | | | | $ | 407.00 | |
| Nasdaq 100 Index | | | | | | $ | 100.00 | | | | | $ | 138.19 | | | | | $ | 120.50 | | | | | $ | 147.94 | | | | | $ | 183.34 | | | | | $ | 221.52 | |
| S&P 500 Index | | | | | | $ | 100.00 | | | | | $ | 136.45 | | | | | $ | 130.11 | | | | | $ | 147.05 | | | | | $ | 179.62 | | | | | $ | 208.95 | |
| S&P 500 Information Technology Index | | | | | | $ | 100.00 | | | | | $ | 140.03 | | | | | $ | 132.31 | | | | | $ | 167.84 | | | | | $ | 226.91 | | | | | $ | 280.58 | |
Additionally, during the three months ended July 31, 2024, we issued a total of 12,841 shares of our unregistered common stock in connection with certain of our acquisitions (the “Transactions”).The Transactions did not involve any underwriters, any underwriting discounts or commissions, or any public offering.
The issuances of the securities pursuant to the Transactions were exempt from registration under the Securities Act by virtue of Section 4(a)(2) of the Act and Rule 506 of Regulation D promulgated thereunder.
Between May 1, 2024 and May 31, 2024, June 1, 2024 and June 30, 2024, and July 1, 2024 and July 31, 2024, shares of restricted stock were delivered by certain employees upon vesting of equity awards to satisfy tax withholding requirements.
The average value of shares delivered to satisfy tax withholding requirements during these periods were $308.10 per share, $317.02 per share, and $330.89 per share, respectively.
The number of shares delivered to satisfy tax withholding requirements during these periods was not significant.
\- 41 \-
| Palo Alto Networks, Inc. | | | | | | $ | 100.00 | | | | | $ | 112.97 | | | | | $ | 176.15 | | | | | $ | 220.31 | | | | | $ | 331.01 | | | | | $ | 430.03 | |
| Nasdaq 100 Index | | | | | | $ | 100.00 | | | | | $ | 140.37 | | | | | $ | 193.97 | | | | | $ | 169.14 | | | | | $ | 207.66 | | | | | $ | 257.35 | |
| S&P 500 Index | | | | | | $ | 100.00 | | | | | $ | 111.96 | | | | | $ | 152.76 | | | | | $ | 145.67 | | | | | $ | 164.63 | | | | | $ | 201.10 | |
| S&P 500 Information Technology Index | | | | | | $ | 100.00 | | | | | $ | 138.91 | | | | | $ | 194.51 | | | | | $ | 183.79 | | | | | $ | 233.14 | | | | | $ | 315.19 | |
Item 6. [Reserved]
0 rewritten, 1 added, 1 removed, 0 unchanged
\- 41 \-
\- 42 \-
Item 8. Financial Statements and Supplementary Data
473 rewritten, 245 added, 164 removed, 822 unchanged
| [Reports of Independent Registered Public Accounting [removed: Firm](#id0a9ebb26d9d4578997f123b627a595a_196)] [added: Firm](#i7c6d02d19ae642d183bd6885f5b5223e_193)] (PCAOB ID: 42) | | | [removed: [59](#id0a9ebb26d9d4578997f123b627a595a_196)] [added: [58](#i7c6d02d19ae642d183bd6885f5b5223e_193)] | | |
| [Consolidated Balance [removed: Sheets](#id0a9ebb26d9d4578997f123b627a595a_205)] [added: Sheets](#i7c6d02d19ae642d183bd6885f5b5223e_199)] | | | [removed: [62](#id0a9ebb26d9d4578997f123b627a595a_205)] [added: [61](#i7c6d02d19ae642d183bd6885f5b5223e_199)] | | |
| [Consolidated Statements of [removed: Operations](#id0a9ebb26d9d4578997f123b627a595a_208)] [added: Operations](#i7c6d02d19ae642d183bd6885f5b5223e_202)] | | | [removed: [63](#id0a9ebb26d9d4578997f123b627a595a_208)] [added: [62](#i7c6d02d19ae642d183bd6885f5b5223e_202)] | | |
| [removed: [Consolidated Statements of Comprehensive Income (Loss)](#id0a9ebb26d9d4578997f123b627a595a_211)] [added: CONSOLIDATED STATEMENTS OF COMPREHENSIVE INCOME (In millions)] | | | [removed: [64](#id0a9ebb26d9d4578997f123b627a595a_211)] | | | [added: | | | | | | | | | | | |]
| [Consolidated Statements of Stockholders’ [removed: Equity](#id0a9ebb26d9d4578997f123b627a595a_223)] [added: Equity](#i7c6d02d19ae642d183bd6885f5b5223e_217)] | | | [removed: [65](#id0a9ebb26d9d4578997f123b627a595a_223)] [added: [64](#i7c6d02d19ae642d183bd6885f5b5223e_217)] | | |
| [Consolidated Statements of Cash [removed: Flows](#id0a9ebb26d9d4578997f123b627a595a_226)] [added: Flows](#i7c6d02d19ae642d183bd6885f5b5223e_220)] | | | [removed: [66](#id0a9ebb26d9d4578997f123b627a595a_226)] [added: [65](#i7c6d02d19ae642d183bd6885f5b5223e_220)] | | |
| [Notes to Consolidated Financial [removed: Statements](#id0a9ebb26d9d4578997f123b627a595a_229)] [added: Statements](#i7c6d02d19ae642d183bd6885f5b5223e_223)] | | | [removed: [67](#id0a9ebb26d9d4578997f123b627a595a_229)] [added: [66](#i7c6d02d19ae642d183bd6885f5b5223e_223)] | | |
We have audited the accompanying consolidated balance sheets of Palo Alto Networks, Inc. (the Company) as of July 31, [removed: 2024] [added: 2025] and [removed: 2023,] [added: 2024,] the related consolidated statements of operations, comprehensive [removed: income (loss),] [added: income,] stockholders’ equity and cash flows for each of the three years in the period ended July 31, [removed: 2024,] [added: 2025,] and the related notes (collectively referred to as the “consolidated financial statements”).
In our opinion, the consolidated financial statements present fairly, in all material respects, the financial position of the Company at July 31, [removed: 2024] [added: 2025] and [removed: 2023,] [added: 2024,] and the results of its operations and its cash flows for each of the three years in the period ended July 31, [removed: 2024,] [added: 2025,] in conformity with U.S. generally accepted accounting principles.
We also have audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the Company’s internal control over financial reporting as of July 31, [removed: 2024,] [added: 2025,] based on criteria established in Internal Control—Integrated Framework issued by the Committee of Sponsoring Organizations of the Treadway Commission (2013 framework), and our report dated [removed: September 6, 2024] [added: August 29, 2025] expressed an unqualified opinion thereon.
The critical audit [removed: matter] [added: matters] communicated below [removed: is a matter] [added: are matters] arising from the current period audit of the financial statements that [removed: was] [added: were] communicated or required to be communicated to the audit committee and that: (1) [removed: relates] [added: relate] to accounts or disclosures that are material to the financial statements and (2) involved our especially challenging, [removed: subjective,] [added: subjective] or complex judgments.
The communication of [removed: the] critical audit [removed: matter] [added: matters] does not alter in any way our opinion on the consolidated financial statements, taken as a whole, and we are not, by communicating the critical audit [removed: matter] [added: matters] below, providing [removed: a] separate [removed: opinion] [added: opinions] on the critical audit [removed: matter] [added: matters] or on the accounts or disclosures to which [removed: it relates.][added: they relate.]
| *How We Addressed* *the Matter in Our Audit* | | | We obtained an understanding, evaluated the design and tested the operating effectiveness of the Company’s process and controls to identify and determine the distinct performance obligations and the timing of revenue recognition. To test the identification and determination of the distinct performance obligations and the timing of revenue recognition, our audit procedures included, among others, reading the executed contract and [removed: purchase order] [added: other contractual documents] to understand the contract, identifying the performance obligation(s), determining the distinct performance obligations, and evaluating the timing of revenue recognition for a sample of individual sales transactions. We evaluated the accuracy of the Company’s contract summary documentation, specifically related to the identification and determination of distinct performance obligations and the timing of revenue recognition. | | |
We have audited Palo Alto Networks, Inc.’s internal control over financial reporting as of July 31, [removed: 2024,] [added: 2025,] based on criteria established in Internal Control—Integrated Framework issued by the Committee of Sponsoring Organizations of the Treadway Commission (2013 framework) (the COSO criteria).
In our opinion, Palo Alto Networks, Inc. (the Company) maintained, in all material respects, effective internal control over financial reporting as of July 31, [removed: 2024,] [added: 2025,] based on the COSO criteria.
We also have audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the consolidated balance sheets of the Company as of July 31, [removed: 2024] [added: 2025] and [removed: 2023,] [added: 2024,] the related consolidated statements of operations, comprehensive [removed: income (loss),] [added: income,] stockholders’ equity and cash flows for each of the three years in the period ended July 31, [removed: 2024,] [added: 2025,] and the related notes and our report dated [removed: September 6, 2024] [added: August 29, 2025] expressed an unqualified opinion thereon.
| | | | [added: | | | | | |] 2024 | | | | | | 2023 | | |
| Cash and cash equivalents | | | $ | [added: 2,268.6 | | | | | $ |] 1,535.2 | | | | | $ | 1,135.3 | |
| Short-term investments | | | [removed: 1,043.6] [added: 634.6] | | | | | | [removed: 1,254.7] [added: 1,043.6] | | |
| Accounts receivable, net of allowance for credit losses of [removed: $7.5] [added: $9.7] and [removed: $7.8] [added: $7.5] as of July 31, [removed: 2024] [added: 2025] and July 31, [removed: 2023,] [added: 2024,] respectively | | | [removed: 2,618.6] [added: 2,965.0] | | | | | | [removed: 2,463.2] [added: 2,618.6] | | |
| Short-term financing receivables, net | | | [removed: 725.9] [added: 714.6] | | | | | | [removed: 388.8] [added: 725.9] | | |
| Short-term deferred contract costs | | | [removed: 369.0] [added: 419.5] | | | | | | [removed: 339.2] [added: 369.0] | | |
| Prepaid expenses and other current assets | | | [removed: 557.4] [added: 520.5] | | | | | | [removed: 466.8] [added: 557.4] | | |
| Total current assets | | | [removed: 6,849.7] [added: 7,522.8] | | | | | | [removed: 6,048.0] [added: 6,849.7] | | |
| Property and equipment, net | | | [removed: 361.1] [added: 387.3] | | | | | | [removed: 354.5] [added: 361.1] | | |
| Operating lease right-of-use assets | | | [removed: 385.9] [added: 347.0] | | | | | | [removed: 263.3] [added: 385.9] | | |
| Long-term investments | | | [removed: 4,173.2] [added: 5,555.6] | | | | | | [removed: 3,047.9] [added: 4,173.2] | | |
| Long-term financing receivables, net | | | [removed: 1,182.1] [added: 1,002.3] | | | | | | [removed: 653.3] [added: 1,182.1] | | |
| Long-term deferred contract costs | | | [removed: 562.0] [added: 585.9] | | | | | | [removed: 547.1] [added: 562.0] | | |
| Goodwill | | | [removed: 3,350.1] [added: 4,566.6] | | | | | | [removed: 2,926.8] [added: 3,350.1] | | |
| Intangible assets, net | | | [removed: 374.9] [added: 762.7] | | | | | | [removed: 315.4] [added: 374.9] | | |
| Deferred tax assets | | | [removed: 2,399.0] [added: 2,424.2] | | | | | | [removed: 23.1] [added: 2,399.0] | | |
| Other assets | | | [removed: 352.9] [added: 421.8] | | | | | | [removed: 321.7] [added: 352.9] | | |
| Total assets | | | $ | [removed: 19,990.9] [added: 23,576.2] | | | | | $ | [removed: 14,501.1] [added: 19,990.9] | |
| Accounts payable | | | $ | [removed: 116.3] [added: 232.2] | | | | | $ | [removed: 132.3] [added: 116.3] | |
| Accrued compensation | | | [removed: 554.7] [added: 607.6] | | | | | | [removed: 548.3] [added: 554.7] | | |
| Accrued and other liabilities | | | [removed: 506.7] [added: 846.0] | | | | | | [removed: 390.8] [added: 506.7] | | |
| Deferred revenue | | | [removed: 5,541.1] [added: 6,302.2] | | | | | | [removed: 4,674.6] [added: 5,541.1] | | |
| Convertible senior notes, net | | | [removed: 963.9] [added: —] | | | | | | [removed: 1,991.5] [added: 963.9] | | |
| Total current liabilities | | | [removed: 7,682.7] [added: 7,988.0] | | | | | | [removed: 7,737.5] [added: 7,682.7] | | |
\- 57 \-
VALUATION OF CONTINGENT CONSIDERATION LIABILITY IN CONNECTION WITH THE ACQUISITION OF IBM QRADAR ASSETS
| *Description* *of the Matter* | | | As described in Note 8 to the consolidated financial statements, the Company completed the acquisition of certain IBM QRadar assets on August 31, 2024, for which the purchase consideration included contingent consideration. The Company has determined the fair value of contingent consideration liability to be $513.6 million as of July 31, 2025, using a discounted cash flow valuation technique including an estimate of future cash payments related to customers entering into qualified new transactions with the Company as well as a risk-adjusted discount rate used to present value the expected cash flows. Auditing the Company’s accounting for contingent consideration liability was complex due to estimation uncertainty in the Company’s determination of the fair value due to the significant assumption about customer transactions that will qualify for cash payments under the arrangement. The significant assumption is forward-looking, dependent upon customer behavior, and could be affected by various factors including future economic and market conditions. | | |
| *How We Addressed* *the Matter in Our Audit* | | | We obtained an understanding, evaluated the design and tested the operating effectiveness of the Company’s process and controls to estimate fair value of the contingent consideration liability. We also tested controls regarding management’s review of assumptions used in the valuation model. To test the estimated fair value of this contingent consideration liability, our audit procedures included, among others, assessing the valuation methodology with the assistance of a valuation specialist, and testing the significant assumption about customer transactions that will qualify for cash payments under the arrangement and the completeness and accuracy of the underlying data used by the Company. We also performed a sensitivity analysis to evaluate the changes in the fair value of this contingent consideration liability that would result from changes in the significant assumption. We also considered whether the assumption was consistent with evidence obtained in other areas of the audit. | | |
August 29, 2025
August 29, 2025
| | | | 2025 | | | | | | 2024 | | |
| Net income | | | $ | 1,133.9 | | | | | $ | 2,577.6 | | | | | $ | 439.7 | |
| Net income | | | — | | | | | | — | | | | | | — | | | | | | 1,133.9 | | | | | | 1,133.9 | | |
| Other comprehensive income | | | — | | | | | | — | | | | | | 50.0 | | | | | | — | | | | | | 50.0 | | |
| Settlement of convertible notes | | | 14.0 | | | | | | — | | | | | | — | | | | | | — | | | | | | — | | |
| Settlement of note hedges | | | (14.0) | | | | | | — | | | | | | — | | | | | | — | | | | | | — | | |
| Balance as of July 31, 2025 | | | 667.9 | | | | | | $ | 5,291.9 | | | | | $ | 48.4 | | | | | $ | 2,484.1 | | | | | $ | 7,824.4 | |
| Net income | | | $ | 1,133.9 | | | | | $ | 2,577.6 | | | | | $ | 439.7 | |
| Change in fair value of contingent consideration liability | | | (135.3) | | | | | | — | | | | | | — | | |
| Contingent consideration for a business acquisition | | | $ | (648.9) | | | | | $ | — | | | | | $ | — | |
Stock Split
On December 12, 2024, we effected a two-for-one stock split of our outstanding shares of common stock through an amendment to our restated certificate of incorporation (“Stock Split”), which also effected a proportionate increase in the number of authorized shares of our common stock from 1.0 billion to 2.0 billion.
As part of our financing credit risk management policy, we may sell financing receivables with an internal risk rating of 5 or greater on a non-recourse basis to third-party financial institutions when the outstanding balance of our financing receivables exceeds preestablished thresholds.
We classify the proceeds from these sales as cash flows from operating activities on our consolidated statements of cash flows.
Our sales contracts are primarily denominated in U.S. dollars.
Inventory consists primarily of raw materials and service-related spares, and is stated at the lower of average cost and net realizable value.
Inventory is included in prepaid expenses and other current assets on our consolidated balance sheets.
Inventory that is obsolete or in excess of forecasted demand is written down to its estimated realizable value.
Once inventory has been written down, a new, lower-cost basis for that inventory is established.
We record a liability for manufacturing purchase commitments in excess of our forecasted demand.
We use consistent demand forecasts for our valuation of excess and obsolete inventory and manufacturing partner and supplier liabilities.
Inventory write-downs and excess manufacturing purchase commitment charges are included in cost of product revenue on our consolidated statements of operations.
Contingent consideration obligation incurred in connection with a business combination is recorded at fair value on the acquisition date and remeasured at each subsequent reporting period until the related contingencies have been resolved, with the change in fair value recognized in general and administrative expense on our consolidated statements of operations.
Payments not made soon after the acquisition date to settle a contingent consideration liability are classified as cash flows from financing activities up to the amount of the contingent consideration liability recognized at the acquisition date.
Our convertible senior notes were fully settled upon maturity as of July 31, 2025.
Recently Adopted Accounting Pronouncement
We adopted the standard in our fourth quarter of fiscal 2025.
Segment Information for more details.
*Expense Disaggregation Disclosures*
In November 2024, the FASB issued authoritative guidance that expands annual and interim disclosure of specified information about certain costs and expenses in the notes to financial statements.
The standard is effective for our annual period in fiscal 2028 and interim period in our first quarter of fiscal 2029, and could be applied either prospectively or retrospectively.
*Measurement of Credit Losses for Accounts Receivable and Contract Assets*
In July 2025, the FASB issued authoritative guidance that provides a practical expedient for estimating expected credit losses on accounts receivable and contract assets.
The standard is effective for us in our first quarter of fiscal 2027 and will be applied on a prospective basis.
[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)
September 6, 2024
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| Balance as of July 31, 2021 | | | 291.9 | | | | | | $ | 2,311.2 | | | | | $ | (9.9) | | | | | $ | (1,666.8) | | | | | $ | 634.5 | |
| Cumulative-effect adjustment from adoption of new accounting pronouncement | | | — | | | | | | (581.9) | | | | | | — | | | | | | 266.7 | | | | | | (315.2) | | |
| Net loss | | | — | | | | | | — | | | | | | — | | | | | | (267.0) | | | | | | (267.0) | | |
| Other comprehensive loss | | | — | | | | | | — | | | | | | (45.7) | | | | | | — | | | | | | (45.7) | | |
| Repurchase and retirement of common stock | | | (2.0) | | | | | | (566.7) | | | | | | — | | | | | | — | | | | | | (566.7) | | |
Reclassification
Certain prior period amounts in the consolidated financial statements and accompanying notes have been reclassified to conform to the current period presentation.
Stock Split Effected in the Form of a Stock Dividend (“Stock Split”)
On September 13, 2022, we executed a three-for-one stock split of our common stock, effected in the form of a stock dividend.
Management believes that the financial institutions that hold our investments are financially sound and, accordingly, are subject to minimal credit risk.
We may sell, in certain instances, these financing arrangements on a non-recourse basis to third-party financial institutions.
Acquisition-related in-process research and development represents the fair value of incomplete research and development projects that have not reached technological feasibility as of the date of acquisition.
Initially, these assets are not subject to amortization.
Assets related to projects that have been completed are transferred to developed technology, which are subject to amortization.
Our EMS provider assembles our products using design specifications, quality assurance programs, and standards that we establish, and it procures components and assembles products based on our demand forecasts.
If the actual component usage and product demand are significantly lower than forecast, we record a liability for manufacturing purchase commitments in excess of our forecasted demand, including costs for excess components or for carrying costs incurred by our manufacturing partners and component suppliers.
Through July 31, 2024, we have not accrued any significant costs associated with this exposure.
Prior to August 1, 2021, our convertible senior notes were separated into a liability and an equity component.
The carrying amount of the liability component was calculated by measuring the fair value of a similar liability that did not have an associated convertible feature, using a discounted cash flow model with a risk-adjusted yield.
The carrying amount of the equity component representing the conversion option was determined by deducting the fair value of the liability component from the par value of the notes as a whole.
This difference represented a debt discount that was amortized to interest expense using the effective interest method over the term of the notes.
The equity component was not remeasured as it continued to meet the conditions for equity classification.
Transaction costs related to the issuance of the notes were allocated to the liability and equity components using the same proportions as the proceeds from the notes.
Transaction costs attributable to the equity component were netted with the equity component of the notes in additional paid-in capital.
Upon the notes becoming convertible, the net carrying amount of the liability component was classified as a current liability and a portion of the equity component representing the conversion option was reclassified to temporary equity.
The portion of the equity component classified as temporary equity was measured as the difference between the principal and net carrying amount of the notes, excluding debt issuance costs.
Transaction costs related to the issuance of the notes are netted with the liability and are amortized on a straight-line basis, which approximates the effective interest rate method, to interest expense over the term of the notes.
We adopted the new debt guidance using the modified-retrospective approach.
The adoption of this standard resulted in an increase to convertible senior notes, net of $444.3 million, a decrease to accumulated deficit of $266.7 million, a decrease to additional paid-in capital of $581.9 million, and a decrease to temporary equity of $129.1 million on August 1, 2021.
Product revenue also includes revenue derived from software licenses of Panorama, SD-WAN, and the VM-Series.
Our appliances and software licenses have significant standalone functionalities and capabilities.
We recognize liabilities for uncertain tax positions based on a two-step process.
The first step is to evaluate the tax position for recognition by determining if the weight of available evidence indicates that it is more likely than not that the position will be sustained on audit, including resolution of related appeals or litigation processes, if any.
The standard is effective for our annual periods beginning in fiscal 2025 and interim periods beginning in the first quarter of fiscal 2026, and requires retrospective application for all prior periods presented in the financial statements.
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| | | | July 31, 2023 | | | | | | | | | | | | | | | | | | | | |
| Certificates of deposit | | | $ | 48.1 | | | | | $ | — | | | | | $ | — | | | | | $ | 48.1 | |
An excerpt. Shown here: 40 of 473 rewritten, 40 of 245 added and 40 of 164 removed. The counts are complete. For every sentence, read Item 8. Financial Statements and Supplementary Data in the FY2025 filing and the FY2024 filing.
Item 9A. Controls and Procedures
6 rewritten, 1 added, 2 removed, 6 unchanged
Our management, with the participation of our chief executive officer and chief financial officer, evaluated the effectiveness of our disclosure controls and procedures pursuant to Rule [removed: 13a-15(e)] [added: 13a-15(f)] under the Securities Exchange Act of 1934, as amended (the “Exchange Act”).
Based on our evaluation, our chief executive officer and chief financial officer concluded that, as of July 31, [removed: 2024,] [added: 2025,] our disclosure controls and procedures are designed at a reasonable assurance level and are effective to provide reasonable assurance that information we are required to disclose in reports that we file or submit under the Exchange Act is recorded, processed, summarized, and reported within the time periods specified in Securities and Exchange Commission (“SEC”) rules and forms, and that such information is accumulated and communicated to our management, including our chief executive officer and chief financial officer, as appropriate, to allow timely decisions regarding required disclosure.
Our management assessed the effectiveness of our internal control over financial reporting as of July 31, [removed: 2024,] [added: 2025,] based on the framework set forth by the Committee of Sponsoring Organizations of the Treadway Commission (“COSO”) in Internal Control - Integrated Framework (2013 framework).
Based on that assessment, management concluded that, as of July 31, [removed: 2024,] [added: 2025,] our internal control over financial reporting was effective.
The effectiveness of our internal control over financial reporting as of July 31, [removed: 2024] [added: 2025] has been audited by Ernst & Young LLP, the independent registered public accounting firm that audits our consolidated financial statements, as stated in their report which is included in Part II, Item 8 of this Annual Report on Form 10-K.
There were no changes in our internal control over financial reporting identified in connection with the evaluation required by Rule 13a-15(d) and 15d-15(d) of the Exchange Act that occurred during the [added: fiscal] quarter ended July 31, [removed: 2024] [added: 2025] that have materially affected, or are reasonably likely to materially affect, our internal control over financial reporting.
\- 95 \-
\- 96 \-
[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)
Item 9B. Other Information
1 rewritten, 9 added, 0 removed, 1 unchanged
No [removed: directors] [added: other officers] or [removed: officers,] [added: directors,] as defined in Rule 16a-1(f), adopted, [removed: modified] [added: modified,] and/or terminated a “Rule 10b5-1 trading arrangement” or a “non-Rule 10b5-1 trading arrangement,” as defined in Regulation S-K Item 408, during the fourth quarter of fiscal [removed: 2024.][added: 2025.]
Set forth below is certain information regarding Rule 10b5-1 trading plans adopted or terminated by our directors and officers (as defined in Rule 16a-1(f)) during the fourth quarter of fiscal 2025.
The Rule 10b5-1 trading plans listed below are each intended to satisfy the affirmative defense of Rule 10b5-1(c).
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| Name | | | | | | Title | | | | | | Date Plan Was Adopted | | | | | | Date Plan Was Terminated | | | | | | Original Expiration Date | | | | | | Total Amount of Common Stock to Be Sold Under the Plan | | |
| Nikesh Arora | | | | | | Chief Executive Officer | | | | | | June 24, 2025 | | | | | | Not applicable | | | | | | December 24, 2025 or when all shares have been sold | | | | | | 846,408 | | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
Item 9C. Disclosure Regarding Foreign Jurisdictions That Prevent Inspections
0 rewritten, 1 added, 2 removed, 2 unchanged
\- 96 \-
\- 97 \-
[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)
Item 10. Directors, Executive Officers and Corporate Governance
1 rewritten, 0 added, 0 removed, 0 unchanged
The information required by this item will be contained in our definitive proxy statement to be filed with the SEC in connection with our [removed: 2024] [added: 2025] annual meeting of stockholders (the “Proxy Statement”), which is expected to be filed not later than 120 days after the end of our fiscal year ended July 31, [removed: 2024] [added: 2025] and is incorporated herein by reference.
Item 14. Principal Accountant Fees and Services
0 rewritten, 1 added, 2 removed, 2 unchanged
\- 97 \-
\- 98 \-
[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)
Item 15. Exhibits and Financial Statement Schedules
53 rewritten, 6 added, 17 removed, 108 unchanged
| [removed: [3.1](https://www.sec.gov/Archives/edgar/data/1327567/000119312512415530/d405168dex31.htm)] [added: [3.1](https://www.sec.gov/Archives/edgar/data/1327567/000132756725000027/panwex31restatedcertificat.htm)] | | | | | | Restated Certificate of Incorporation of the [removed: Registrant.] [added: Registrant, as amended.] | | | | | | [removed: 10-K] | | | | | | [removed: 001-35594] | | | | | | [removed: 3.1] | | | | | | [removed: October 4, 2012] | | | | | | | | |
| [removed: [3.2](https://www.sec.gov/Archives/edgar/data/1327567/000119312522157474/d274773dex31.htm)] [added: [3.2](https://www.sec.gov/Archives/edgar/data/1327567/000132756725000024/ex31amendedandrestatedbyla.htm)] | | | | | | Amended and Restated Bylaws of the Registrant. | | | | | | 8-K | | | | | | 001-35594 | | | | | | 3.1 | | | | | | [removed: May 23, 2022] [added: August 18, 2025] | | | | | | | | |
| [removed: [4.3](https://www.sec.gov/Archives/edgar/data/1327567/000132756723000024/panwex43q423.htm)] [added: [4.](https://www.sec.gov/Archives/edgar/data/1327567/000132756725000027/panwex41descriptionofregis.htm)[1](https://www.sec.gov/Archives/edgar/data/1327567/000132756725000027/panwex41descriptionofregis.htm)] | | | | | | Description of Registrant’s Securities. | | | | | | [removed: 10-K] | | | | | | [removed: 001-35594] | | | | | | [removed: 4.3] | | | | | | [removed: September 1, 2023] | | | | | | | | |
| [removed: [10.4](https://www.sec.gov/Archives/edgar/data/1327567/000132756724000029/panwex1042021equityincenti.htm)*] [added: [10.4](https://www.sec.gov/Archives/edgar/data/1327567/000132756725000027/panwex1042021equityincenti.htm)*] | | | | | | 2021 Equity Incentive Plan, as amended and [removed: restated on December 12, 2023.] [added: restated, and related form agreements.] | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| [removed: [10.7](https://www.sec.gov/Archives/edgar/data/1327567/000132756724000029/panwex1072012employeestock.htm)*] [added: [10](https://www.sec.gov/Archives/edgar/data/1327567/000132756725000027/panwex1052012employeestock.htm)[.5](https://www.sec.gov/Archives/edgar/data/1327567/000132756725000027/panwex1052012employeestock.htm)*] | | | | | | 2012 Employee Stock Purchase Plan, as amended and restated, and related form agreements. | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| [removed: [10.8](https://www.sec.gov/Archives/edgar/data/1327567/000119312518303084/d634580dex991.htm)*] [added: [10](https://www.sec.gov/Archives/edgar/data/1327567/000119312518303084/d634580dex991.htm)[.6](https://www.sec.gov/Archives/edgar/data/1327567/000119312518303084/d634580dex991.htm)*] | | | | | | RedLock Inc. 2015 Stock Plan, as amended, and related form agreements under RedLock Inc. 2015 Stock Plan, as amended. | | | | | | S-8 | | | | | | 333-227901 | | | | | | 99.1 | | | | | | October 19, 2018 | | | | | | | | |
| [removed: [10.13](https://www.sec.gov/Archives/edgar/data/1327567/000119312522310112/d424580dex991.htm)*] [added: [10.7](https://www.sec.gov/Archives/edgar/data/1327567/000119312522310112/d424580dex991.htm)*] | | | | | | Cider Security Ltd. 2020 Equity Incentive Plan. | | | | | | S-8 | | | | | | 333-268931 | | | | | | 99.1 | | | | | | December 21, 2022 | | | | | | | | |
| [removed: [10.14](https://www.sec.gov/Archives/edgar/data/1327567/000119312522310112/d424580dex992.htm)*] [added: [10.8](https://www.sec.gov/Archives/edgar/data/1327567/000119312522310112/d424580dex992.htm)*] | | | | | | US Sub-Plan to Cider Security Ltd. 2020 Equity Incentive Plan. | | | | | | S-8 | | | | | | 333-268931 | | | | | | 99.2 | | | | | | December 21, 2022 | | | | | | | | |
| [removed: [10.15](https://www.sec.gov/Archives/edgar/data/1327567/000132756714000043/panwex102q115.htm)*] [added: [10.9](https://www.sec.gov/Archives/edgar/data/1327567/000132756714000043/panwex102q115.htm)*] | | | | | | Employee Incentive Compensation Plan, as amended and restated. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.2 | | | | | | November 25, 2014 | | | | | | | | |
| [removed: [10.16](https://www.sec.gov/Archives/edgar/data/1327567/000132756724000029/panwex1016amendedclawbackp.htm)] [added: [10.10](https://www.sec.gov/Archives/edgar/data/1327567/000132756724000029/panwex1016amendedclawbackp.htm)] | | | | | | Clawback Policy, adopted as of August 29, 2017, amended August 14, 2024. | | | | | | [added: 10-K] | | | | | | [added: 001-35594] | | | | | | [added: 10.16] | | | | | | [added: September 6, 2024] | | | | | | | | |
| [removed: [10.17](https://www.sec.gov/Archives/edgar/data/1327567/000132756722000008/panw-ex104q222.htm)*] [added: [10.11](https://www.sec.gov/Archives/edgar/data/1327567/000132756725000017/panwex101q325.htm)*] | | | | | | Amended and Restated Outside Director Compensation Policy (last amended February [removed: 16, 2022).] [added: 12, 2025).] | | | | | | 10-Q | | | | | | 001-35594 | | | | | | [removed: 10.4] [added: 10.1] | | | | | | [removed: February 23, 2022] [added: May 21, 2025] | | | | | | | | |
| [removed: [10.21](https://www.sec.gov/Archives/edgar/data/1327567/000132756722000016/panw-ex103q322.htm)*] [added: [10.12](https://www.sec.gov/Archives/edgar/data/1327567/000132756722000016/panw-ex103q322.htm)*] | | | | | | Continued Service Policy. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.3 | | | | | | May 20, 2022 | | | | | | | | |
| [removed: [10.22](https://www.sec.gov/Archives/edgar/data/1327567/000132756722000028/panwex1023q422deferredcomp.htm)*] [added: [10.13](https://www.sec.gov/Archives/edgar/data/1327567/000132756722000028/panwex1023q422deferredcomp.htm)*] | | | | | | Palo Alto Networks, Inc. Deferred Compensation Plan effective June 1, [removed: 2022] [added: 2022.] | | | | | | 10-K | | | | | | 001-35594 | | | | | | 10.23 | | | | | | September 6, 2022 | | | | | | | | |
| [removed: [10.24](https://www.sec.gov/Archives/edgar/data/1327567/000132756718000011/ex102offerletternarora.htm)*] [added: [10.15](https://www.sec.gov/Archives/edgar/data/1327567/000132756718000011/ex102offerletternarora.htm)*] | | | | | | Offer Letter between the Registrant and Nikesh Arora, dated May 30, 2018. | | | | | | 8-K | | | | | | 001-35594 | | | | | | 10.2 | | | | | | June 4, 2018 | | | | | | | | |
| [removed: [10.25](https://www.sec.gov/Archives/edgar/data/1327567/000119312521267862/d200133dex101.htm)*] [added: [10.16](https://www.sec.gov/Archives/edgar/data/1327567/000119312521267862/d200133dex101.htm)*] | | | | | | Offer Letter between the Registrant and Josh Paul, dated August 5, 2021. | | | | | | 8-K | | | | | | 001-35594 | | | | | | 10.1 | | | | | | September 8, 2021 | | | | | | | | |
| [removed: [10.26](https://www.sec.gov/Archives/edgar/data/1327567/000132756718000031/panwex104q119.htm)*] [added: [10.17](https://www.sec.gov/Archives/edgar/data/1327567/000132756718000031/panwex104q119.htm)*] | | | | | | Confirmatory Employment Letter with Updated Change in Control Protection between the Registrant and Lee Klarich, dated December 19, 2011. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.4 | | | | | | November 30, 2018 | | | | | | | | |
| [removed: [10.27](https://www.sec.gov/Archives/edgar/data/0001327567/000119312521087516/d160663dex101.htm)*] [added: [10.18](https://www.sec.gov/Archives/edgar/data/0001327567/000119312521087516/d160663dex101.htm)*] | | | | | | Addendum to Employment Offer Letter by and between the Registrant and Dipak Golechha, dated March 17, 2021. | | | | | | 8-K | | | | | | 001-35594 | | | | | | 10.1 | | | | | | March 19, 2021 | | | | | | | | |
| [removed: [10.28](https://www.sec.gov/Archives/edgar/data/1327567/000132756722000016/panw-ex101q322.htm)*] [added: [10.19](https://www.sec.gov/Archives/edgar/data/1327567/000132756722000016/panw-ex101q322.htm)*] | | | | | | Addendum to Employment Offer Letter by and between the Registrant and Dipak Golechha, dated February 18, 2022. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.1 | | | | | | May 20, 2022 | | | | | | | | |
| [removed: [10.29](https://www.sec.gov/Archives/edgar/data/1327567/000119312521244832/d204334dex101.htm)*] [added: [10.20](https://www.sec.gov/Archives/edgar/data/1327567/000119312521244832/d204334dex101.htm)*] | | | | | | Employment Offer Letter by and between the Registrant and William “BJ” Jenkins, dated July 27, 2021. | | | | | | 8-K | | | | | | 001-35594 | | | | | | 10.1 | | | | | | August 12, 2021 | | | | | | | | |
| [removed: [10.30](https://www.sec.gov/Archives/edgar/data/1327567/000132756722000016/panw-ex102q322.htm)*] [added: [10.21](https://www.sec.gov/Archives/edgar/data/1327567/000132756722000016/panw-ex102q322.htm)*] | | | | | | Addendum to Employment Offer Letter between the Registrant and William “BJ” Jenkins, dated February 18, 2022. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.2 | | | | | | May 20, 2022 | | | | | | | | |
| [removed: [10.31](https://www.sec.gov/Archives/edgar/data/1327567/000132756721000029/panwex1027q421directoroffe.htm)*] [added: [10.22](https://www.sec.gov/Archives/edgar/data/1327567/000132756725000017/panwex102q325.htm)*] | | | | | | Form of Offer Letter between the Registrant and its directors. | | | | | | [removed: 10-K] [added: 10-Q] | | | | | | 001-35594 | | | | | | [removed: 10.27] [added: 10.2] | | | | | | [removed: September 3, 2021] [added: May 21, 2025] | | | | | | | | |
| [removed: [10.32](https://www.sec.gov/Archives/edgar/data/1327567/000132756719000016/panwex101q319.htm)] [added: [10.23](https://www.sec.gov/Archives/edgar/data/1327567/000132756719000016/panwex101q319.htm)] | | | | | | Amended and Restated Flextronics Manufacturing Services Agreement, by and between the Registrant and Flextronics Telecom Systems Ltd., dated April 1, 2019. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.1 | | | | | | May 30, 2019 | | | | | | | | |
| [removed: [10.33](https://www.sec.gov/Archives/edgar/data/1327567/000132756721000029/panwex1029q421supplieragre.htm)] [added: [10.24](https://www.sec.gov/Archives/edgar/data/1327567/000132756721000029/panwex1029q421supplieragre.htm)] | | | | | | Vendor Information Security Terms between the Registrant and Flextronics Telecom Systems Ltd., dated July 23, 2021. | | | | | | 10-K | | | | | | 001-35594 | | | | | | 10.29 | | | | | | September 3, 2021 | | | | | | | | |
| [removed: [10.34](https://www.sec.gov/Archives/edgar/data/1327567/000119312520163579/d936599dex102.htm)] [added: [10.](https://www.sec.gov/Archives/edgar/data/1327567/000119312520163579/d936599dex103.htm)[45](https://www.sec.gov/Archives/edgar/data/1327567/000119312520163579/d936599dex103.htm)] | | | | | | Form of [removed: Convertible Note Hedge] [added: Warrant] Confirmation. | | | | | | 8-K | | | | | | 001-35594 | | | | | | [removed: 10.2] [added: 10.3] | | | | | | June 8, 2020 | | | | | | | | |
| [removed: [10.36](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000027/panwex1029q415buildinge.htm)] [added: [10.25](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000027/panwex1029q415buildinge.htm)] | | | | | | Lease between the Registrant and Santa Clara Campus Property Owner I LLC, dated May 28, 2015. | | | | | | 10-K | | | | | | 001-35594 | | | | | | 10.29 | | | | | | September 17, 2015 | | | | | | | | |
| [removed: [10.37](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000027/panwex1030q415buidlingf.htm)] [added: [10.26](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000027/panwex1030q415buidlingf.htm)] | | | | | | Lease between the Registrant and Santa Clara Campus Property Owner I LLC, dated May 28, 2015. | | | | | | 10-K | | | | | | 001-35594 | | | | | | 10.30 | | | | | | September 17, 2015 | | | | | | | | |
| [removed: [10.38](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000027/panwex1031q415buildingb.htm)] [added: [10.27](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000027/panwex1031q415buildingb.htm)] | | | | | | Lease between the Registrant and Santa Clara Campus Property Owner I LLC, dated May 28, 2015. | | | | | | 10-K | | | | | | 001-35594 | | | | | | 10.31 | | | | | | September 17, 2015 | | | | | | | | |
| [removed: [10.39](https://www.sec.gov/Archives/edgar/data/1327567/000119312515347005/d59912dex101.htm)] [added: [10.28](https://www.sec.gov/Archives/edgar/data/1327567/000119312515347005/d59912dex101.htm)] | | | | | | Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated October 7, 2015. | | | | | | 8-K/A | | | | | | 001-35594 | | | | | | 10.1 | | | | | | October 19, 2015 | | | | | | | | |
| [removed: [10.4](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000036/amendmentno1topaloaltonetw.htm)[0](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000036/amendmentno1topaloaltonetw.htm)] [added: [10.29](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000036/amendmentno1topaloaltonetw.htm)] | | | | | | Amendment No. 1 to Lease by and between the Registrant and Santa Clara Phase I Property LLC, dated November 9, 2015. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.2 | | | | | | November 24, 2015 | | | | | | | | |
| [removed: [10.41](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000036/amendmenno1topaloaltonetwo.htm)] [added: [10.30](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000036/amendmenno1topaloaltonetwo.htm)] | | | | | | Amendment No. 1 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated November 9, 2015. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.3 | | | | | | November 24, 2015 | | | | | | | | |
| [removed: [10.42](https://www.sec.gov/Archives/edgar/data/1327567/000132756716000073/panwex101q117_amendmentno1.htm)] [added: [10.31](https://www.sec.gov/Archives/edgar/data/1327567/000132756716000073/panwex101q117_amendmentno1.htm)] | | | | | | Amendment No. 1 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated September 16, 2016. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.1 | | | | | | November 22, 2016 | | | | | | | | |
| [removed: [10.43](https://www.sec.gov/Archives/edgar/data/1327567/000132756716000073/panwex102q117_amendmentno1.htm)] [added: [10.32](https://www.sec.gov/Archives/edgar/data/1327567/000132756716000073/panwex102q117_amendmentno1.htm)] | | | | | | Amendment No. 1 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated September 16, 2016. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.2 | | | | | | November 22, 2016 | | | | | | | | |
| [removed: [10.44](https://www.sec.gov/Archives/edgar/data/1327567/000132756716000073/panwex103q117_amendmentno2.htm)] [added: [10.33](https://www.sec.gov/Archives/edgar/data/1327567/000132756716000073/panwex103q117_amendmentno2.htm)] | | | | | | Amendment No. 2 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated September 16, 2016. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.3 | | | | | | November 22, 2016 | | | | | | | | |
| [removed: [10.45](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000007/panwex101q217_amendmentno2.htm)] [added: [10.34](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000007/panwex101q217_amendmentno2.htm)] | | | | | | Amendment No. 2 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated November 16, 2016. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.1 | | | | | | March 1, 2017 | | | | | | | | |
| [removed: [10.46](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000007/panwex102q217_amendmentno2.htm)] [added: [10.35](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000007/panwex102q217_amendmentno2.htm)] | | | | | | Amendment No. 2 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated November 16, 2016. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.2 | | | | | | March 1, 2017 | | | | | | | | |
| [removed: [10.47](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000007/panwex103q217_amendmentno3.htm)] [added: [10.36](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000007/panwex103q217_amendmentno3.htm)] | | | | | | Amendment No. 3 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated November 16, 2016. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.3 | | | | | | March 1, 2017 | | | | | | | | |
| [removed: [10.48](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000027/panwex1040q417_amendmentno.htm)] [added: [10.37](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000027/panwex1040q417_amendmentno.htm)] | | | | | | Amendment No. 3 to Lease by and between the Registrant and Santa Clara EFH LLC, dated June 22, 2017. | | | | | | 10-K | | | | | | 001-35594 | | | | | | 10.40 | | | | | | September 7, 2017 | | | | | | | | |
| [removed: [10.49](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000027/panwex1041q417_amendmentno.htm)] [added: [10.38](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000027/panwex1041q417_amendmentno.htm)] | | | | | | Amendment No. 3 to Lease by and between the Registrant and Santa Clara G LLC, dated June 22, 2017. | | | | | | 10-K | | | | | | 001-35594 | | | | | | 10.41 | | | | | | September 7, 2017 | | | | | | | | |
| [removed: [10.5](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000027/panwex1042q417_amendmentno.htm)[0](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000027/panwex1042q417_amendmentno.htm)] [added: [10.39](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000027/panwex1042q417_amendmentno.htm)] | | | | | | Amendment No. 4 to Lease by and between the Registrant and Santa Clara EFH LLC, dated June 22, 2017. | | | | | | 10-K | | | | | | 001-35594 | | | | | | 10.42 | | | | | | September 7, 2017 | | | | | | | | |
| [removed: [10.51](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000035/panwex105q118_amendmentno4.htm)] [added: [10.40](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000035/panwex105q118_amendmentno4.htm)] | | | | | | Amendment No. 4 to Lease by and between the Registrant and Santa Clara Phase III EFH LLC, dated September 29, 2017. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.5 | | | | | | November 21, 2017 | | | | | | | | |
| [2.1](https://www.sec.gov/Archives/edgar/data/0001327567/000119312525169870/d804159dex21.htm)* | | | | | | Agreement and Plan of Merger, dated as of July 30, 2025, by and among Palo Alto Networks, Inc., Athens Strategies Ltd. and CyberArk Software Ltd. | | | | | | 8-K | | | | | | 001-35594 | | | | | | 2.1 | | | | | | July 31, 2025 | | | | | | | | |
\- 98 \-
| [10.14](https://www.sec.gov/Archives/edgar/data/1327567/000132756725000027/panwex1014nirzukamendmentl.htm)* | | | | | | Amendment and Restated Employment Letter between Palo Alto Networks, Inc. and Nir Zuk, dated July 7, 2025. | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| [10.44](https://www.sec.gov/Archives/edgar/data/1327567/000132756725000010/panwex103creditagreement-a.htm) | | | | | | Amendment No. 1, dated as of November 22, 2024, to Credit Agreement, dated as of April 13, 2023, among Palo Alto Networks, Inc., the lenders party thereto, and Wells Fargo Bank, National Association, as administrative agent. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.3 | | | | | | February 14, 2025 | | | | | | | | |
* Schedules omitted pursuant to Item 601(b)(2) of Regulation S-K.
The Registrant agrees to furnish supplementally a copy of any omitted schedule to the SEC upon request; provided, however, that the Registrant may request confidential treatment pursuant to Rule 24b-2 of the Securities Exchange Act of 1934, as amended, for any schedules or exhibits so furnished.
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| Exhibit Number | | | | | | Exhibit Description | | | | | | Incorporated by Reference | | | | | | | | | | | | | | | | | | | | | | | | | | |
| Form | | | | | | File No. | | | | | | Exhibit | | | | | | Filing Date | | | | | | | | | | | | | | | | | | | | |
| [4.1](https://www.sec.gov/Archives/edgar/data/0001327567/000119312520163579/d936599dex41.htm) | | | | | | Indenture between the Registrant and U.S. Bank National Association, dated as of June 8, 2020. | | | | | | 8-K | | | | | | 001-35594 | | | | | | 4.1 | | | | | | June 8, 2020 | | | | | | | | |
| [4.2](https://www.sec.gov/Archives/edgar/data/0001327567/000119312520163579/d936599dex41.htm) | | | | | | Form of Global 0.375% Convertible Senior Note due 2025 (included in Exhibit 4.1). | | | | | | 8-K | | | | | | 001-35594 | | | | | | 4.2 | | | | | | June 8, 2020 | | | | | | | | |
| [10.5](https://www.sec.gov/Archives/edgar/data/1327567/000132756724000029/panwex1052021eipoption.htm)* | | | | | | Form of 2021 Equity Incentive Plan Global Stock Option Award Agreement. | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| [10.6](https://www.sec.gov/Archives/edgar/data/1327567/000132756724000029/panwex1062021eiprsu.htm)* | | | | | | Form of 2021 Equity Incentive Plan Global Restricted Stock Unit Award Agreement. | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)
| [10.9](https://www.sec.gov/Archives/edgar/data/1327567/000119312520320091/d23873dex991.htm)* | | | | | | Sinefa Group, Inc. 2020 Stock Plan. | | | | | | S-8 | | | | | | 333-251423 | | | | | | 99.1 | | | | | | December 17, 2020 | | | | | | | | |
| [10.10](https://www.sec.gov/Archives/edgar/data/1327567/000119312520320099/d35944dex991.htm)* | | | | | | Expanse Holding Company, Inc. Amended and Restated 2012 Stock Incentive Plan | | | | | | S-8 | | | | | | 333-251425 | | | | | | 99.1 | | | | | | December 17, 2020 | | | | | | | | |
| [10.11](https://www.sec.gov/Archives/edgar/data/0001327567/000119312521265618/d214080dex991.htm)* | | | | | | Gamma Networks, Inc. 2018 Stock Option and Grant Plan. | | | | | | S-8 | | | | | | 333-259327 | | | | | | 99.1 | | | | | | September 3, 2021 | | | | | | | | |
| [10.12](https://www.sec.gov/Archives/edgar/data/1327567/000119312521074955/d51651dex991.htm)* | | | | | | Bridgecrew, Inc. 2019 Stock Incentive Plan. | | | | | | S-8 | | | | | | 333-254042 | | | | | | 99.1 | | | | | | March 9, 2021 | | | | | | | | |
| [10.23](https://www.sec.gov/Archives/edgar/data/0001327567/000132756720000041/panwex101q121.htm)* | | | | | | Employment Agreement between Palo Alto Networks (Israel Analytics) Ltd. and Nir Zuk, dated August 18, 2020. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.1 | | | | | | November 19, 2020 | | | | | | | | |
| [10.35](https://www.sec.gov/Archives/edgar/data/1327567/000119312520163579/d936599dex103.htm) | | | | | | Form of Warrant Confirmation. | | | | | | 8-K | | | | | | 001-35594 | | | | | | 10.3 | | | | | | June 8, 2020 | | | | | | | | |
\- 101 \-
\- 102 \-
An excerpt. Shown here: 40 of 53 rewritten, all 6 added and all 17 removed. The counts are complete. For every sentence, read Item 15. Exhibits and Financial Statement Schedules in the FY2025 filing and the FY2024 filing.
Item 16. Form 10-K Summary
11 rewritten, 9 added, 7 removed, 38 unchanged
Pursuant to the requirements of Section 13 or 15(d) of the Securities Exchange Act of 1934, the Registrant has duly caused this report to be signed on its behalf by the undersigned, thereunto duly authorized, on [removed: September 6, 2024.][added: August 29, 2025.]
| /s/ NIKESH ARORA | | | | | | Chairman, Chief Executive Officer and Director (Principal Executive Officer) | | | | | | [removed: September 6, 2024] [added: August 29, 2025] | | |
| /s/ DIPAK GOLECHHA | | | | | | Chief Financial Officer (Duly Authorized Officer and Principal Financial Officer) | | | | | | [removed: September 6, 2024] [added: August 29, 2025] | | |
| /s/ JOSH PAUL | | | | | | Chief Accounting Officer (Duly Authorized Officer and Principal Accounting Officer) | | | | | | [removed: September 6, 2024] [added: August 29, 2025] | | |
| /s/ APARNA BAWA | | | | | | Director | | | | | | [removed: September 6, 2024] [added: August 29, 2025] | | |
| /s/ JOHN M. DONOVAN | | | | | | Director | | | | | | [removed: September 6, 2024] [added: August 29, 2025] | | |
| /s/ CARL ESCHENBACH | | | | | | Director | | | | | | [removed: September 6, 2024] [added: August 29, 2025] | | |
| /s/ JAMES J. GOETZ | | | | | | Director | | | | | | [removed: September 6, 2024] [added: August 29, 2025] | | |
| /s/ RT HON SIR JOHN KEY | | | | | | Director | | | | | | [removed: September 6, 2024] [added: August 29, 2025] | | |
| /s/ MARY PAT MCCARTHY | | | | | | Director | | | | | | [removed: September 6, 2024] [added: August 29, 2025] | | |
| /s/ LORRAINE TWOHILL | | | | | | Director | | | | | | [removed: September 6, 2024] [added: August 29, 2025] | | |
\- 101 \-
\- 102 \-
| /s/ LEE KLARICH | | | | | | Chief Product and Technology Officer and Director | | | | | | August 29, 2025 | | |
| Lee Klarich | | | | | | | | | | | | | | |
| /s/ RALPH HAMERS | | | | | | Director | | | | | | August 29, 2025 | | |
| Ralph Hamers | | | | | | | | | | | | | | |
| /s/ HELLE THORNING-SCHMIDT | | | | | | Director | | | | | | August 29, 2025 | | |
| Helle Thorning-Schmidt | | | | | | | | | | | | | | |
| | | | | | | | | | | | | | | |
[Table of](#id0a9ebb26d9d4578997f123b627a595a_7) [Contents](#id0a9ebb26d9d4578997f123b627a595a_7)
\- 104 \-
| /s/ NIR ZUK | | | | | | Chief Technology Officer and Director | | | | | | September 6, 2024 | | |
| Nir Zuk | | | | | | | | | | | | | | |
| /s/ DR. HELENE D. GAYLE | | | | | | Director | | | | | | September 6, 2024 | | |
| Dr. Helene D. Gayle | | | | | | | | | | | | | | |
\- 105 \-