Palo Alto Networks 10-K 2026-07-31

Filed 2026-09-10. 24 sections, 581K characters. Original on sec.gov · Markdown · JSON

What changed since the 2025-07-31 10-KNew, removed and reworded risk factor headings, then every item sentence by sentence.

Cover and table of contents

UNITED STATES

SECURITIES AND EXCHANGE COMMISSION

Washington, D.C. 20549


FORM 10-K


(Mark One)

☒ ANNUAL REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934

For the fiscal year ended July 31, 2026

or

☐ TRANSITION REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934

For the transition period from to

Commission File Number 001-35594

Palo Alto Networks, Inc.

(Exact name of registrant as specified in its charter)

Delaware20-2530195
(State or other jurisdiction of incorporation or organization)(I.R.S. Employer Identification No.)

3000 Tannery Way

Santa Clara, California 95054

(Address of principal executive offices) (Zip Code)

(408) 753-4000

(Registrant’s telephone number, including area code)

Securities registered pursuant to Section 12(b) of the Act:

Title of each classTrading Symbol(s)Name of each exchange on which registered
Common stock, $0.0001 par value per sharePANWThe Nasdaq Stock Market LLC (Nasdaq Global Select Market)

Securities registered pursuant to Section 12(g) of the Act:

None

Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes ☒ No ☐

Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes ☐ No ☒

Indicate by check mark whether the registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yes ☒ No ☐

Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yes ☒ No ☐

Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See the definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company,” and “emerging growth company” in Rule 12b-2 of the Exchange Act.

Large accelerated filer☒Accelerated filer☐
Non-accelerated filer☐Smaller reporting company☐
Emerging growth company☐

If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐

Indicate by check mark whether the registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C. 7262(b)) by the registered public accounting firm that prepared or issued its audit report. ☒

If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements of the registrant included in the filing reflect the correction of an error to previously issued financial statements. ☐

Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the registrant’s executive officers during the relevant recovery period pursuant to §240.10D-1(b). ☐

Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Act). Yes ☐ No ☒

The aggregate market value of voting stock held by non-affiliates of the registrant was approximately $123.4 billion as of January 31, 2026, the last business day of the registrant’s most recently completed second fiscal quarter (based on the closing sales price for the common stock on the Nasdaq Global Select Market on such date). Shares of common stock held by each executive officer and director have been excluded in that such persons may be deemed to be affiliates. This determination of affiliate status is not necessarily a conclusive determination for other purposes.

On August 31, 2026, 818 million shares of the registrant’s common stock, $0.0001 par value, were outstanding.

DOCUMENTS INCORPORATED BY REFERENCE

Portions of the information called for by Part III of this Annual Report on Form 10-K is hereby incorporated by reference from the definitive proxy statement for the registrant’s 2026 annual meeting of stockholders, which will be filed with the Securities and Exchange Commission not later than 120 days after the registrant’s fiscal year ended July 31, 2026.

Table Of Contents

Page
PART I
Item 1.Business4
Item 1A.Risk Factors17
Item 1B.Unresolved Staff Comments37
Item 1C.Cybersecurity37
Item 2.Properties39
Item 3.Legal Proceedings39
Item 4.Mine Safety Disclosures39
PART II
Item 5.Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities40
Item 6.[Reserved]41
Item 7.Management’s Discussion and Analysis of Financial Condition and Results of Operations42
Item 7A.Quantitative and Qualitative Disclosures About Market Risk57
Item 8.Financial Statements and Supplementary Data58
Item 9.Changes in and Disagreements with Accountants on Accounting and Financial Disclosure104
Item 9A.Controls and Procedures104
Item 9B.Other Information105
Item 9C.Disclosure Regarding Foreign Jurisdictions That Prevent Inspections105
PART III
Item 10.Directors, Executive Officers and Corporate Governance106
Item 11.Executive Compensation106
Item 12.Security Ownership of Certain Beneficial Owners and Management and Related Stockholder Matters106
Item 13.Certain Relationships and Related Transactions, and Director Independence106
Item 14.Principal Accountant Fees and Services106
PART IV
Item 15.Exhibits and Financial Statement Schedules107
Item 16.Form 10-K Summary111
Signatures112

- 2 -

Part I

SPECIAL NOTE REGARDING FORWARD-LOOKING STATEMENTS

This Annual Report on Form 10-K, including, without limitation, the sections entitled “Business,” “Risk Factors,” and “Management’s Discussion and Analysis of Financial Condition and Results of Operations,” contains forward-looking statements within the meaning of Section 27A of the Securities Act of 1933, as amended, and Section 21E of the Securities Exchange Act of 1934, as amended. Forward-looking statements generally can be identified by words such as “anticipate,” “believe,” “continue,” “could,” “estimate,” “expect,” “intend,” “may,” “plan,” “potentially,” “projects,” “will,” “will be,” “will continue,” “will likely result,” “would,” and similar expressions that convey uncertainty of future events or outcomes.

These forward-looking statements include, but are not limited to, statements concerning the following:

  • expectations regarding the cybersecurity landscape and demand;

  • expectations regarding our platformization strategy and related progress and opportunities, our product development strategy, and drivers of and factors affecting growth in our business;

  • expectations regarding annual recurring revenue and remaining performance obligations;

  • expectations regarding artificial intelligence;

  • expectations regarding our strategic partnerships;

  • statements regarding expected profitability, new revenues, trends in annual recurring revenue, trends in remaining performance obligations, our mix of product and subscription and support revenue, cost of revenue, gross margin, cash flows, operating expenses, including future share-based compensation expense, income taxes, investment plans, and liquidity;

  • expected recurring revenues resulting from growth in our end-customers and increased adoption of our products, subscriptions and services;

  • the performance advantages of our products and subscription and support offerings and the potential benefits to our customers;

  • expectations regarding future investments in research and development and product development, customer support, in our employees and in our sales force, including expectations regarding growth in our sales headcount;

  • expectations that we will continue to expand our global presence;

  • expectations regarding our revenues, including the seasonality and cyclicality from quarter to quarter;

  • expectations relating to our customer financing activities;

  • the sufficiency of our cash flow from operations with existing cash, cash equivalents, and investments to meet our cash needs for the foreseeable future;

  • our ability to successfully acquire and integrate companies and assets and expectations and intentions with respect to the assets, products and technologies that we acquire;

  • expectations regarding the benefits and synergies from our acquisition and integration of companies, assets, and technologies, including our acquisition of CyberArk Software Ltd.;

  • expectations regarding contingent consideration obligations;

  • expectations regarding the change in fair value of our convertible senior notes and capped call transactions and its impact on us and our financial results;

  • statements regarding our competition, including the expanded scope of our competitors as a result of entering into new product and service categories;

  • the timing and amount of capital expenditures and share repurchases;

  • the effects of worldwide economic and geopolitical conditions, including, but not limited to, hostilities in Israel and the surrounding regions, inflation, tariff rates, interest rate levels, public or administration policies, trade regulations, trade policy, growth rates and other conditions, on our operating and financial results and performance;

  • expectations regarding the manufacture, delivery and cost of certain of our products;

  • the effects of litigation or regulatory developments involving us or affecting our industry;

  • our debt repayment obligations; and

  • other statements regarding our future operations, financial condition and prospects, and business strategies.

These forward-looking statements are based on current expectations and assumptions that are subject to risks and uncertainties, including those described in “Risk Factors” included in Part I, Item 1A and elsewhere in this Annual Report on Form 10-K. Moreover, we operate in a very competitive and rapidly changing environment, and new risks emerge from time to time. It is not possible for our management to predict all risks, nor can we assess the impact of all factors on our business or the extent to which any factor, or combination of factors, may cause actual results to differ materially from those contained in any forward-looking statements we may make. In light of these risks, uncertainties, and assumptions, the forward-looking events and circumstances discussed in this Annual Report on Form 10-K may not occur, and actual results could differ materially and adversely from those anticipated or implied in the forward-looking statements. We undertake no obligation to revise or publicly release the results of any revision to these forward-looking statements, except as required by law. Given these risks and uncertainties, readers are cautioned not to place undue reliance on such forward-looking statements.

- 3 -

Item 1. Business

General

Palo Alto Networks, Inc. is a global artificial intelligence (“AI”) cybersecurity provider and our vision is a world where each day is safer and more secure than the one before. We were incorporated in 2005 and are headquartered in Santa Clara, California.

Our mission is to be the cybersecurity partner of choice, protecting our digital way of life. Our platforms and services help secure enterprise users, networks, clouds, endpoints, AI apps and agents, and identities by delivering comprehensive cybersecurity backed by AI and automation, and provide real-time visibility and monitoring across cloud infrastructure, applications and AI workloads. A key element of our strategy is to help our customers simplify their security architectures through consolidating disparate point products. We execute on this strategy by developing our capabilities and packaging our offerings into platforms, which are able to cover many of our customers’ needs in the markets in which we operate. Our platformization strategy combines various products and services into a tightly integrated architecture for more secure, faster, and cost-effective outcomes.

Network & AI Security

Our Network & AI Security platform is designed to deliver complete zero trust solutions to our customers. The platform includes:

  • Secure Access Service Edge (“SASE”). Prisma® Access, when combined with Prisma SD-WAN, provides a comprehensive AI-powered SASE solution that secures users, branches, data, AI apps and agents from the most evasive threats in the new AI landscape. Our Prisma Browser™ further extends zero-trust security and data protection to the browser, where the majority of work is done today, providing users with the freedom to work securely using our secure browser from any device.

  • Next-Generation Firewalls. Our ML-Powered Next-Generation Firewalls (“NGFWs”) secure on-premises environments including campus locations and data centers. Our software NGFWs secure virtual and cloud networks.

  • Cloud-Delivered Security Services (“CDSS”). Our network security platform integrates a suite of Precision AI powered security capabilities that complements our SASE and NGFW solutions. These include Advanced Threat Prevention, Advanced WildFire®, Advanced URL Filtering, Advanced DNS Security, Device Security, Quantum Security, Next-Gen Trust Protection (“NGTS”), GlobalProtect®, Prisma Access Agent, Enterprise Data Loss Prevention (“Enterprise DLP”), Software as a Service (“SaaS”) Security, and AI Access Security™. Through these add-on services, our customers are able to secure their content, applications, users, devices, and connection across their entire organization.

  • Prisma AIRS. Prisma AIRS™ is our comprehensive AI security platform designed to help organizations discover, assess, and protect AI agents, applications, models and data across the AI lifecycle. It supports key enterprise use cases, including securing AI-assisted software development, protecting custom AI applications from development through runtime, and governing autonomous AI agents. Prisma AIRS™ brings together AI Gateway, Agent Security, AI Red Teaming, AI Runtime Security™, AI Model Security, and AI Posture Management in a unified platform. These capabilities provide visibility into AI assets and activity, assess risks before deployment, and enforce security controls during live AI interactions and agent actions.

  • Strata Cloud Manager (“SCM”). SCM is our AI-powered unified network security management and operations solution. It enables customers to manage and monitor their NGFW and SASE environments through a single, streamlined interface. SCM helps customers centrally manage configurations and security policies, assess security posture and network health, and streamline troubleshooting and remediation. It includes Strata Copilot, which offers a natural language interface for actionable insights and guided remediation, and integrates Autonomous Digital Experience Monitoring (“ADEM”) to help customers monitor and improve end-user performance across the enterprise.

Cortex

Our AI-powered Cortex® platform transforms end-to-end security operations and observability with unified data, AI, and automation for more secure, faster, and cost effective outcomes.

  • Security Operations. We deliver the next generation of security operations capabilities that unifies standalone Security Information and Event Management (“SIEM”) tools, endpoint security, security automation, cloud detection and response (“CDR”), as well as attack surface management (“ASM”) capabilities on our Cortex platform. These include Cortex XSIAM®, for AI-powered security operations replacing traditional SIEM tools; Cortex XDR®, for the prevention, detection, and response to complex cybersecurity attacks; Cortex XSOAR®, for security orchestration, automation, and response (“SOAR”); Cortex Xpanse®, for ASM; and Koi Agentic Endpoint Security. Additionally, Cortex XSIAM integrates with the Chronosphere Telemetry Pipeline to ingest and optimize massive data volumes, promoting cost-effective scaling of autonomous operations.

- 4 -

  • Cloud Security. We deliver comprehensive security across the cloud application development lifecycle through Cortex Cloud®, delivered as a scalable SaaS offering. As a comprehensive Cloud Native Application Protection Platform (“CNAPP”) combined with CDR, Cortex Cloud secures multi- and hybrid-cloud environments for applications, data, generative AI (“GenAI”) ecosystem, and the cloud native technology stack across the full development lifecycle, from code to cloud to security operations. As part of the Cortex Cloud platform, customers can expand from Cortex Cloud to our security operations offerings available on a single user experience and unified agent. We also offer our VM-Series and CN-Series virtual firewalls for inline network security on multi- and hybrid-cloud environments.

  • Observability. Chronosphere, our next-generation observability platform, delivers real-time visibility and monitoring across cloud-native infrastructure, applications, and AI workloads. Purpose-built to handle the massive data volumes of the AI era, Chronosphere enables organizations to maintain system resilience and uptime with high cost-efficiency and reliability. Our observability platform provides comprehensive visibility into complex digital environments and automated troubleshooting of issues. It allows customers to transition from passive monitoring to proactive management of their entire digital estate. Our telemetry pipeline acts as an intelligent control layer that filters, transforms, and routes data. This helps reduce data volumes, enabling customers to cost-effectively scale their security and observability posture.

Idira

Idira™, our next-generation identity security platform, is designed to secure human, agentic, and machine identities across the enterprise with intelligent privilege controls and continuous threat prevention. By unifying identity access management, privilege access management, and identity governance and administration, organizations can continuously discover and protect against identity risk throughout the end-to-end identity lifecycle. The platform includes:

  • Workforce Identity Security. Our solutions apply identity assurance and modern access controls for the entire workforce, including through adaptive multi-factor authentication (“MFA”), single sign-on (“SSO”), secure browsing, web session protection, workforce password management, and automated identity lifecycle management. Our approach enforces least privilege by elevating access only when required.

  • Information Technology (“IT”) and Developer Identity Security (Modern Privilege Access Management). Our solutions secure high-risk access for IT administrators, third-party vendors, developers, and cloud operations teams across hybrid and multi-cloud environments, delivering just-in-time privileged access, session is

Showing the first 8K of 74K characters. Open the full section

Item 1A. Risk Factors

Our operations and financial results are subject to various risks and uncertainties including those described below. The risks and uncertainties described below are not the only ones we face. Additional risks and uncertainties that we are unaware of, or that we currently believe are not material, also may become important factors that affect us. If any of the following risks or others not specified below materialize, our business, financial condition, and operating results could be materially adversely affected, and the market price of our common stock could decline. In addition, the impacts of any worsening of the economic environment may exacerbate the risks described below, any of which could have a material impact on us.

Risk Factor Summary

Our business is subject to numerous risks and uncertainties. These risks include, but are not limited to, the following:

  • Our operating results may be adversely affected by unfavorable economic and market conditions and the uncertain geopolitical environment.

  • Our business and operations have experienced growth in recent periods, and if we do not effectively manage our future growth or are unable to improve our systems, processes, and controls, our business and operating results could be adversely affected.

  • Our revenue growth rate in recent periods may not be indicative of our future performance, and we may not be able to maintain profitability, which could cause our business, financial condition, and operating results to suffer.

  • Our operating results may vary significantly from period to period, including due to seasonality, which makes our results difficult to predict and could cause our results to fall short of expectations.

  • If we are unable to sell new and additional products, subscriptions, and support offerings to existing end-customers or attract new customers, especially large enterprise customers, our future revenue and operating results will be harmed.

  • We rely on revenue from subscription and support offerings, and because we recognize revenue from subscription and support over the term of the relevant service period, downturns or upturns in sales or renewals of these subscription and support offerings are not immediately reflected in full in our operating results.

  • Our consumption- or usage-based offerings may expose us to customer usage optimization behavior that could create revenue volatility.

  • The sales prices of our products, subscriptions, and support offerings may decrease, which may reduce our revenue and gross profits and adversely impact our financial results.

  • We rely on our channel partners to sell a substantial portion of our products, including subscriptions and support, and if these channel partners fail to perform, our ability to sell and distribute our products and subscriptions will be limited and our operating results will be harmed.

  • We are exposed to the credit and liquidity risk of our customers, and to credit exposure in weakened markets, which could result in material losses.

  • A portion of our revenue is generated by sales to government entities, which are subject to a number of challenges and risks.

  • We face intense competition and we may lack sufficient financial or other resources to maintain or improve our competitive position.

  • The “identity security” market lacks a universally accepted definition, which could lead to mischaracterization of our offerings and adverse evaluations by industry stakeholders.

  • Customer trends toward vendor consolidation in cybersecurity may favor competitors offering broader platforms.

  • Cloud infrastructure providers and advanced AI companies increasingly offer native security and observability capabilities that compete directly with our offerings.

  • We have acquired and may in the future acquire other businesses, which could subject us to adverse claims or liabilities, require significant management attention, disrupt our business, adversely affect our operating results, may not result in the expected benefits of such acquisitions, and may dilute stockholder value.

  • As a result of the CyberArk acquisition, the scope and size of our business have substantially changed, which resulted in certain incremental risks, including increased competition.

  • If we do not accurately predict, prepare for, and respond promptly to rapidly evolving technological and market developments and successfully manage product and subscription introductions and transitions to meet changing end-customer needs in the enterprise security industry, our competitive position and prospects will be harmed.

  • The success of our strategy depends on maintaining a broad ecosystem of integrations with third-party technologies, which requires significant ongoing investment.

- 17 -

  • Issues in the development, deployment, or use of AI may result in reputational harm, legal liability, and could adversely affect our business and operating results.

  • The emergence of AI agents as a new class of identity presents both opportunities and risks that could impact our identity security offerings.

  • A significant network or data security incident may materially impact our reputation, financial condition, and operating results.

  • Defects, errors, or vulnerabilities in our products, subscriptions, or support offerings, the failure of our products or subscriptions to block a virus or prevent a security breach or incident, misuse of our products, or risks of product liability claims could harm our reputation and adversely impact our operating results.

  • Our shared responsibility security model relies on customers to configure and use our products securely, and customer errors could harm our reputation even when we are not at fault.

  • Our ability to sell our products and subscriptions is dependent on the quality of our technical support services and those of our channel partners, and the failure to offer high-quality technical support services could have a material adverse effect on our end-customers’ satisfaction with our products and subscriptions, our sales, and our operating results.

  • Our subscription agreements typically contain service-level commitments, and failure to meet these commitments could reduce our revenue and harm our business.

  • We rely on data center facilities operated by third-party cloud service providers, and any limitations on capacity, or interference with our use could adversely affect our business, financial condition, and results of operations.

  • Claims by others that we infringe their intellectual property rights could harm our business.

  • Our proprietary rights may be difficult to enforce or protect, which could enable others to copy or use aspects of our products or subscriptions without compensating us.

  • Our use of open source software in our products and subscriptions could negatively affect our ability to sell our products and subscriptions and subject us to possible litigation.

  • We license technology from third parties, and our inability to maintain those licenses could harm our business.

  • We depend on manufacturing partners and limited sources of supply for our hardware products, making us susceptible to manufacturing delays, supply shortages, pricing fluctuations, and international trade risks that could prevent timely shipment of customer orders and result in the loss of sales and end-customers.

  • If we are unable to attract, retain, and motivate our key technical, sales, and management personnel, our business could suffer.

  • We generate a significant amount of revenue from sales to distributors, resellers, and end-customers outside of the United States, and we are therefore subject to a number of risks associated with international sales and operations, including export and import controls that could subject us to liability or impair our ability to compete in international markets.

  • Our products and subscriptions are subject to certification, testing, and regulatory approval requireme

Showing the first 8K of 124K characters. Open the full section

Item 1B. Unresolved Staff Comments

Not applicable.

Item 1C. Cybersecurity

As a global cybersecurity provider, cybersecurity risk management is an integral part of our overall enterprise risk management program. We recognize the critical importance that a strong cybersecurity risk management program plays in maintaining the trust and confidence of our customers, end users, business partners, stockholders and employees. We have established processes and procedures for identifying, evaluating, and responding to risks from cybersecurity threats, including any potential unauthorized access to our information systems that may result in adverse effects on the confidentiality, integrity, or availability of our information systems or information.

Cybersecurity Risk Management and Strategy

Our cybersecurity risk management program includes written policies, standards, and procedures for maintaining data privacy, product security and information security to mitigate cybersecurity risks, and to identify, evaluate and respond to cybersecurity threats, vulnerabilities and incidents. Our cybersecurity risk management program and strategy is implemented across several areas, which include, but are not limited to, the following:

  • Information Security. We maintain a written information security program, which provides for policies, standards, guidelines, and administrative, technical and physical safeguards that we believe are reasonably designed, in light of the nature, size and complexity of our operations, to protect the resiliency of our operations and the confidentiality, integrity, and availability of our information systems and information. The organizational, administrative and technical measures we implement are guided by recognized security frameworks established by the National Institute of Standards and Technology, the ISO/IEC 27000 series of standards, and other generally recognized industry standards. The program is assessed regularly and in light of new and emerging cybersecurity risks.

  • Technical Safeguards and Product Security. We deploy and maintain a variety of technologies to detect and manage cybersecurity threats across the network, endpoint and cloud, as well as leverage Unit 42 to assess our internal security posture. We also apply security-by-design principles in our software development lifecycle, track vulnerabilities of open-source software, and run regular internal and external network scans. We conduct regular application security assessments, including our assessments for internet-facing applications that collect, transmit, or display end user data. We also employ tooling in certain areas to help prevent deviations from policy.

- 37 -

  • Incident Response and Reporting. We maintain incident response and recovery protocols to enable prompt, effective and orderly identification, evaluation, management, and disposition of actual and potential security threats and incidents, including for purposes of escalation and internal and external-notification steps. We maintain a cross-functional incident response team, including senior representatives from information security, information technology, product, legal, privacy, communications, and finance, that is involved in assessing cybersecurity threats and incidents, assigning severity levels, and evaluating the potential impact, including the potential impact on our business strategy, results of operations and financial condition. Additionally, we utilize Unit 42 to support our response to threats. This allows for prompt direction of appropriate personnel and resources for incident management and response, and internal notification to appropriate members of management, which may include our chief executive officer, chief product and technology officer, chief information security officer, general counsel, chief financial officer, and/or chief accounting officer, and the security committee of our board of directors (the “Security Committee”).

  • Third-Party Risk Management. We maintain a risk-based approach to identifying and overseeing cybersecurity risks presented by certain third parties, including vendors, service providers, suppliers, operations parties, and other external users of our systems, as well as the systems of third parties that are important to our operations and/or process sensitive information on our behalf. This includes a security process to conduct due diligence prior to engaging contractors and vendors and assess the security capabilities of subcontractors and vendors on a periodic basis based on our assessment of each third party’s operational criticality and risk profile. In addition, we maintain a security program designed to protect the security and integrity of our hardware products and data throughout the product design, development, manufacturing, delivery, and service and repair processes, which includes consideration of applicable supply chain risk management standards.

  • Risk and Readiness Assessments. We engage in at least quarterly assessments and testing of the effectiveness of our cybersecurity risk management program and incident response protocols that are designed to identify and evaluate vulnerabilities and weaknesses, address cybersecurity threats and test our readiness to respond to cybersecurity incidents. These efforts include, but are not limited to, threat modeling, vulnerability scans, penetration testing, audits, and/or tabletop exercises. We regularly engage third parties to perform assessments on our cybersecurity measures, such as audits and independent reviews of our compliance with various security compliance standards, including those established by the American Institute of Certified Public Accountants, operating effectiveness and penetration tests. The results of such assessments are reported to management and we adjust our cybersecurity policies, standards, processes and practices as necessary based on the information provided by these assessments, audits and reviews.

  • Awareness and Training. We provide regular training for educating employees about corporate policies and procedures and information security designed to provide our employees with knowledge of best practices and effective tools for safeguarding our data and assets and reducing security risks based on the human threat vector. Employees are also trained on the responsible use of AI and on the secure use of AI through regular trainings. We also deliver experiential training, including by periodically conducting simulated phishing exercises to test employee awareness and compliance with our security policies.

  • Governance. As discussed in more detail below under the heading, “Cybersecurity Governance,” our board of directors has delegated oversight of enterprise security risk management, including, but not limited to, cybersecurity risk management to the Security Committee. As part of our cybersecurity risk management procedures, senior members of management and the Security Committee are informed regarding security events based on established reporting thresholds, and are provided ongoing updates regarding any such meaningful threat or incident.

As a global cybersecurity provider, we recognize that we may be a particularly attractive target for sophisticated threat actors. We have not identified any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, that have materially impacted or are reasonably likely to materially impact us, including our business strategy, results of operations, or financial condition, to date. However, we face ongoing and increasing cybersecurity risks, including from threat actors that are becoming more sophisticated and effective over time, and we can provide no assurance that there will not be incidents in the future or that past or future threats or incidents will not materially affect us, including our business strategy, results of operations, or financial conditions. Despite our efforts, we cannot eliminate all risks from cybersecurity threats or provide assurances that we have not experienced an undetected cybersecurity incident. For additional information regarding these risks, please refer to Part I, Item 1A, “Risk Factors,” in this Form 10-K, including, but not limited to, the risk factor entitled “A significant network or data security incident may materially impact our reputation, financial condition, and operating results.”

- 38 -

Cybersecurity Governance

The Security Committee, which is composed of our independent directors and chaired by our chief product and technology officer, facilitates our board of directors’ responsibility for oversight of security matters, including product security, data security, cybersecurity, security risk management, risk exposure and related controls and enterprise risk management related to these risks. The Security Committee, including our chief information security officer, reports regularly to the Board following meetings of the Security Committee with respect to its review and assessment of security matters and other matters that are relevant to the Security Committee’s discharge of its responsibilities. The Security Committee meets quarterly to review with our chief information security officer and other members of management, which may include our chief executive officer, chief product and technology officer, chief financial officer, and general counsel, our cybersecurity programs, cybersecurity risks, mitigation or remediation strategies, and other matters impacting the committee’s responsibilities.

Management is responsible for day-to-day risk management activities, with our chief information security officer being primarily responsible for identifying, assessing and managing our exposure to cybersecurity risks, establishing processes and procedures so that potential cybersecurity risk exposures are monitored, implementing appropriate mitigation or remediation measures as needed, and maintaining cybersecurity risk management programs. Our chief information security officer is also responsible for defining, overseeing, managing, implementing, and reviewing compliance with the information security programs described above under the heading “Cybersecurity Risk Management and Strategy.” Our chief information security officer receives regular reports from our information security team and monitors the prevention, detection, and mitigation or remediation of cybersecurity risks, and works closely to keep the management team apprised of key risks, treats, and incidents. In addition, as described in further detail above under the heading “Cybersecurity Risk Management and Strategy,” a cross functional team is involved in assessing and managing the risks from cybersecurity threats and incidents, and reporting information about risks to the Security Committee.

Our information security team consists of dedicated personnel who are experienced information systems security professionals and information security managers with many years of experience across a variety of technology sub-specialties. In particular, our chief information security officer has extensive experience in the management of cybersecurity risk management programs, having served in various roles in information technology and security for over 25 years. In addition, seven of the ten members of our board of directors have expertise in overseeing cybersecurity and information security management.

Item 2. Properties

Our corporate headquarters is located in Santa Clara, California, where we lease approximately 941,000 square feet of space under three lease agreements that expire in July 2040, with options to extend the lease terms through July 2052. We also lease space for personnel around the world, including Israel and India. In addition, we provide our cloud-based subscription offerings through data centers operated under co-location arrangements in the United States, Europe, and Asia. Refer to Note 12. Leases in Part II, Item 8 of this Annual Report on Form 10-K for more information on our operating leases. Additionally, we own 24.9 acres of land adjacent to our headquarters in Santa Clara, California, which we intend to develop to accommodate future expansion.

We believe that our current facilities are adequate to meet our current needs. We intend to expand our facilities or add new facilities as we add employees and enter new geographic markets, and we believe that suitable additional or alternative space will be available as needed to accommodate ongoing operations and any such growth. However, we expect to incur additional expenses in connection with such new or expanded facilities.

Item 3. Legal Proceedings

The information set forth under the “Litigation” subheading in Note 13. Commitments and Contingencies in Part II, Item 8 of this Annual Report on Form 10-K is incorporated herein by reference.

Item 4. Mine Safety Disclosures

Not applicable.

- 39 -

Part II

Item 5. Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities

Market Information

Our common stock, $0.0001 par value per share, is traded on the Nasdaq Global Select Market under the symbol “PANW.”

Holders of Record

As of August 31, 2026, there were 585 holders of record of our common stock. Because many of our shares of common stock are held by brokers and other institutions on behalf of stockholders, we are unable to estimate the total number of stockholders represented by these record holders.

Dividend Policy

We have never declared or paid, and do not anticipate declaring or paying in the foreseeable future, any cash dividends on our capital stock. Any future determination as to the declaration and payment of dividends, if any, will be at the discretion of our board of directors, subject to applicable laws, and will depend on then existing conditions, including our financial condition, operating results, contractual restrictions, capital requirements, business prospects, and other factors our board of directors may deem relevant.

Recent Sales of Unregistered Equity Securities

None.

Purchases of Equity Securities by the Issuer and Affiliated Purchasers

In February 2019, our board of directors authorized a $1.0 billion share repurchase program, which is funded from available working capital. Our board of directors subsequently authorized additional increases to this share repurchase program, bringing the total authorization to $5.1 billion, with $1.0 billion remaining as of July 31, 2026. The expiration date of this repurchase authorization was extended to December 31, 2026, and our repurchase program may be suspended or discontinued at any time. Repurchases under our program are to be made at management’s discretion from time to time on the open market, through privately negotiated transactions, transactions structured through investment banking institutions, block purchase techniques, 10b5-1 trading plans, or a combination of the foregoing. During the three months ended July 31, 2026, we did not repurchase any shares pursuant to our share repurchase program.

- 40 -

Stock Price Performance Graph

This performance graph shall not be deemed “filed” for purposes of Section 18 of the Securities Exchange Act of 1934, as amended (the “Exchange Act”), or incorporated by reference into any filing of Palo Alto Networks, Inc. under the Securities Act of 1933, as amended, or the Exchange Act, except as shall be expressly set forth by specific reference in such filing.

This performance graph compares the cumulative total return on our common stock with that of the Nasdaq 100 Index, the Standard & Poor’s 500 Index (“S&P 500 Index), and the Standard & Poor’s 500 Information Technology Index (“S&P 500 Information Technology Index”) for the five years ended July 31, 2026. This performance graph assumes $100 was invested on July 31, 2021, in each of the common stock of Palo Alto Networks, Inc., the Nasdaq 100 Index, the S&P 500 Index, and the S&P 500 Information Technology Index, and assumes the reinvestment of any dividends. The stock price performance on this performance graph is not necessarily indicative of future stock price performance.

Palo Alto Networks, Inc. Comparison of Total Return Performance

3806

Company/Index7/31/20217/31/20227/31/20237/31/20247/31/20257/31/2026
Palo Alto Networks, Inc.$100.00$125.07$187.92$244.13$261.02$498.93
Nasdaq 100 Index$100.00$87.20$107.06$132.67$160.30$196.50
S&P 500 Index$100.00$95.36$107.77$131.64$153.14$183.10
S&P 500 Information Technology Index$100.00$94.49$119.86$162.04$200.37$252.91

Item 6. [Reserved]

- 41 -

Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations

The following discussion and analysis of our financial condition and results of operations should be read in conjunction with our consolidated financial statements and related notes appearing elsewhere in this Annual Report on Form 10-K. The following discussion and analysis contains forward-looking statements based on current expectations and assumptions that are subject to risks and uncertainties, which could cause our actual results to differ materially from those anticipated or implied by any forward-looking statements. Factors that could cause or contribute to such differences include, but are not limited to, those discussed in this Annual Report on Form 10-K, and in particular, the risks discussed under the caption “Risk Factors” in Part I, Item 1A of this report.

Our Management’s Discussion and Analysis of Financial Condition and Results of Operations (“MD&A”) is organized as follows:

  • Overview. A discussion of our business and overall analysis of financial and other highlights in order to provide context for the remainder of MD&A.

  • Key Financial Metrics. A summary of our U.S. GAAP and non-GAAP key financial metrics, which management monitors to evaluate our performance.

  • Results of Operations. A discussion of the nature and trends in our financial results and an analysis of our financial results comparing fiscal 2026 to fiscal 2025. For discussion and analysis related to our financial results comparing fiscal 2025 to 2024, refer to Part II, Item 7 Management’s Discussion and Analysis of Financial Condition and Results of Operations in our Annual Report on Form 10-K for fiscal 2025, which was filed with the Securities and Exchange Commission on August 29, 2025.

  • Liquidity and Capital Resources. An analysis of changes on our balance sheets and cash flows, and a discussion of our financial condition and our ability to meet cash needs.

  • Critical Accounting Estimates. A discussion of our accounting policies that require critical estimates, assumptions, and judgments.

  • Recent Accounting Pronouncements. A discussion of expected impacts of impending accounting changes on financial information to be reported in the future.

Overview

Our mission is to be the cybersecurity partner of choice, protecting our digital way of life. Our platforms and services help secure enterprise users, networks, clouds, endpoints, AI apps and agents, and identities by delivering comprehensive cybersecurity backed by AI and automation, and provide real-time visibility and monitoring across cloud infrastructure, applications and AI workloads. A key element of our strategy is to help our customers simplify their security architectures through consolidating disparate point products. We execute on this strategy by developing our capabilities and packaging our offerings into platforms, which are able to cover many of our customers’ needs in the markets in which we operate. Our platformization strategy combines various products and services into a tightly integrated architecture for more secure, faster, and cost-effective outcomes.

Network & AI Security

Our Network & AI Security platform is designed to deliver complete zero trust solutions to our customers. The platform includes:

  • Secure Access Service Edge. Prisma® Access, when combined with Prisma SD-WAN, provides a comprehensive AI-powered SASE solution that secures users, branches, data, AI apps and agents from the most evasive threats in the new AI landscape. Our Prisma Browser™ further extends zero-trust security and data protection to the browser, where the majority of work is done today, providing users with the freedom to work securely using our secure browser from any device.

  • Next-Generation Firewalls. Our ML-Powered NGFWs secure on-premises environments including campus locations and data centers. Our software NGFWs secure virtual and cloud networks.

  • Cloud-Delivered Security Services. Our network security platform integrates a suite of Precision AI powered security capabilities that complements our SASE and NGFW solutions. These include Advanced Threat Prevention, Advanced WildFire®, Advanced URL Filtering, Advanced DNS Security, Device Security, Quantum Security, NGTS, GlobalProtect®, Prisma Access Agent, Enterprise DLP, SaaS Security, and AI Access Security™. Through these add-on services, our customers are able to secure their content, applications, users, devices, and connection across their entire organization.

- 42 -

  • Prisma AIRS. Prisma AIRS™ is our comprehensive AI security platform designed to help organizations discover, assess, and protect AI agents, applications, models and data across the AI lifecycle. It supports key enterprise use cases, including securing AI-assisted software development, protecting custom AI applications from development through runtime, and governing autonomous AI agents. Prisma AIRS™ brings together AI Gateway, Agent Security, AI Red Teaming, AI Runtime Security™, AI Model Security, and AI Posture Management in a unified platform. These capabilities provide visibility into AI assets and activity, assess risks before deployment, and enforce security controls during live AI interactions and agent actions.

  • Strata Cloud Manager. SCM, is our AI-powered unified network security management and operations solution. It enables customers to manage and monitor their NGFW and SASE environments through a single, streamlined interface. SCM helps customers centrally manage configurations and security policies, assess security posture and network health, and streamline troubleshooting and remediation. It includes Strata Copilot, which offers a natural language interface for actionable insights and guided remediation, and integrates ADEM to help customers monitor and improve end-user performance across the enterprise.

Cortex

Our AI-powered Cortex® platform transforms end-to-end security operations and observability with unified data, AI, and automation for more secure, faster, and cost effective outcomes.

  • Security Operations. We deliver the next generation of security operations capabilities that unifies standalone SIEM tools, endpoint security, security automation, CDR, as well as ASM capabilities on our Cortex platform. These include Cortex XSIAM®, for AI-powered security operations replacing traditional SIEM tools; Cortex XDR®, for the prevention, detection, and response to complex cybersecurity attacks; Cortex XSOAR®, for SOAR; Cortex Xpanse®, for ASM; and Koi Agentic Endpoint Security. Additionally, Cortex XSIAM integrates with the Chronosphere Telemetry Pipeline to ingest and optimize massive data volumes, promoting cost-effective scaling of autonomous operations.

  • Cloud Security. We deliver comprehensive security across the cloud application development lifecycle through Cortex Cloud®, delivered as a scalable SaaS offering. As a comprehensive CNAPP combined with CDR, Cortex Cloud secures multi- and hybrid-cloud environments for applications, data, GenAI ecosystem, and the cloud native technology stack across the full development lifecycle, from code to cloud to security operations. As part of the Cortex Cloud platform, customers can expand from Cortex Cloud to our security operations offerings available on a single user experience and unified agent. We also offer our VM-Series and CN-Series virtual firewalls for inline network security on multi- and hybrid-cloud environments.

  • Observability. Chronosphere, our next-generation observability platform, delivers real-time visibility and monitoring across cloud-native infrastructure, applications, and AI workloads. Purpose-built to handle the massive data volumes of the AI era, Chronosphere enables organizations to maintain system resilience and uptime with high cost-efficiency and reliability. Our observability platform provides comprehensive visibility into complex digital environments and automated troubleshooting of issues. It allows customers to

Showing the first 8K of 84K characters. Open the full section

Item 7A. Quantitative and Qualitative Disclosures About Market Risk

Foreign Currency Exchange Risk

Our sales contracts are primarily denominated in U.S. dollars. A portion of our operating expenditures are denominated in foreign currencies, making them subject to fluctuations in foreign currency exchange rates. Additionally, fluctuations in foreign currency exchange rates may cause us to recognize transaction gains and losses in our statement of operations. Foreign currency remeasurement gains and losses and foreign currency transaction gains and losses have not had a significant impact to our consolidated financial statements.

We enter into foreign currency derivative contracts with maturities of 24 months or less, which we designate as cash flow hedges, to manage the foreign currency exchange risk associated with our revenue and operating expenditures. We also enter into foreign currency derivative contracts that are not designated as hedging instruments to hedge a portion of our outstanding monetary assets and liabilities denominated in foreign currencies. These foreign currency derivative contracts reduce but do not entirely eliminate the effect of foreign exchange rate fluctuations.

A hypothetical 10% change in foreign exchange rates on monetary assets and liabilities would not be material to our financial condition or results of operations after taking into consideration the effect of foreign currency forward contracts in place as of July 31, 2026. The effectiveness of our existing hedging transactions and the availability and effectiveness of any hedging transactions we may decide to enter into in the future may be limited, and we may not be able to successfully hedge our exposure, which could adversely affect our financial condition and results of operations. Refer to Note 6. Derivative Instruments in Part II, Item 8 of this Annual Report on Form 10-K for more information.

As our international operations grow, our risks associated with fluctuations in foreign currency exchange rates will become greater, and we will continue to reassess our approach to managing this risk. In addition, a weakening U.S. dollar can increase the costs of our international expansion and a strengthening U.S. dollar can increase the real cost of our products and services to our end-customers outside of the United States, leading to delays in the purchase of our products and services. For additional information, see the risk factor entitled “We are exposed to fluctuations in foreign currency exchange rates, which could negatively affect our financial condition and operating results.” in Part I, Item 1A of this Annual Report on Form 10-K.

Interest Rate Risk

The primary objectives of our investment activities are to preserve principal, provide liquidity, and maximize income without significantly increasing risk. Most of the securities we invest in are subject to interest rate risk. To minimize this risk, we maintain a diversified portfolio of cash, cash equivalents, and investments, consisting only of investment-grade securities. To assess the interest rate risk, we performed a sensitivity analysis to determine the impact a change in interest rates would have on the value of the investment portfolio. Based on investment positions as of July 31, 2026, a hypothetical 100 basis point increase in interest rates across all maturities would result in a $128 million decline in the fair market value of the portfolio. Such losses would only be realized if we sold the investments prior to maturity. Conversely, a hypothetical 100 basis point decrease in interest rates would lead to a $131 million increase in the fair market value of the portfolio.

- 57 -

Item 8. Financial Statements and Supplementary Data

Index To Consolidated Financial Statements

Page
Reports of Independent Registered Public Accounting Firm (PCAOB ID: 42)59
Consolidated Balance Sheets62
Consolidated Statements of Operations63
Consolidated Statements of Comprehensive Income64
Consolidated Statements of Stockholders’ Equity65
Consolidated Statements of Cash Flows66
Notes to Consolidated Financial Statements67

- 58 -

Report of Independent Registered Public Accounting Firm

To the Stockholders and the Board of Directors of Palo Alto Networks, Inc.

Opinion on the Financial Statements

We have audited the accompanying consolidated balance sheets of Palo Alto Networks, Inc. (the Company) as of July 31, 2026 and 2025, the related consolidated statements of operations, comprehensive income, stockholders’ equity and cash flows for each of the three years in the period ended July 31, 2026, and the related notes (collectively referred to as the “consolidated financial statements”). In our opinion, the consolidated financial statements present fairly, in all material respects, the financial position of the Company at July 31, 2026 and 2025, and the results of its operations and its cash flows for each of the three years in the period ended July 31, 2026, in conformity with U.S. generally accepted accounting principles.

We also have audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the Company’s internal control over financial reporting as of July 31, 2026, based on criteria established in Internal Control—Integrated Framework issued by the Committee of Sponsoring Organizations of the Treadway Commission (2013 framework), and our report dated September 10, 2026 expressed an unqualified opinion thereon.

Basis for Opinion

These financial statements are the responsibility of the Company’s management. Our responsibility is to express an opinion on the Company’s financial statements based on our audits. We are a public accounting firm registered with the PCAOB and are required to be independent with respect to the Company in accordance with the U.S. federal securities laws and the applicable rules and regulations of the Securities and Exchange Commission and the PCAOB.

We conducted our audits in accordance with the standards of the PCAOB. Those standards require that we plan and perform the audit to obtain reasonable assurance about whether the financial statements are free of material misstatement, whether due to error or fraud. Our audits included performing procedures to assess the risks of material misstatement of the financial statements, whether due to error or fraud, and performing procedures that respond to those risks. Such procedures included examining, on a test basis, evidence regarding the amounts and disclosures in the financial statements. Our audits also included evaluating the accounting principles used and significant estimates made by management, as well as evaluating the overall presentation of the financial statements. We believe that our audits provide a reasonable basis for our opinion.

Critical Audit Matters

The critical audit matters communicated below are matters arising from the current period audit of the financial statements that were communicated or required to be communicated to the audit committee and that: (1) relate to accounts or disclosures that are material to the financial statements and (2) involved our especially challenging, subjective or complex judgments. The communication of critical audit matters does not alter in any way our opinion on the consolidated financial statements, taken as a whole, and we are not, by communicating the critical audit matters below, providing separate opinions on the critical audit matters or on the accounts or disclosures to which they relate.

- 59 -

REVENUE RECOGNITION

Description of the MatterAs described in Note 1 to the consolidated financial statements, the Company’s contracts with customers sometimes contain multiple performance obligations, which are accounted for separately if they are distinct. In such cases, the transaction price is then allocated to the distinct performance obligations on a relative standalone selling price basis, and revenue is recognized when control of the distinct performance obligation is transferred. For example, product revenue is recognized at the time of hardware shipment or delivery of software license, and subscription and support revenue is recognized over time as the services are performed. Auditing the Company’s revenue recognition was complex, including the identification and determination of distinct performance obligations and the timing of revenue recognition. For example, there were certain customer arrangements with nonstandard terms and conditions that required judgment to determine the distinct performance obligations and the impact on the timing of revenue recognition.
How We Addressed the Matter in Our AuditWe obtained an understanding, evaluated the design and tested the operating effectiveness of the Company’s process and controls to identify and determine the distinct performance obligations and the timing of revenue recognition. To test the identification and determination of the distinct performance obligations and the timing of revenue recognition, our audit procedures included, among others, reading the executed contract and other contractual documents to understand the contract, identifying the performance obligation(s), determining the distinct performance obligations, and evaluating the timing of revenue recognition for a sample of individual sales transactions. We evaluated the accuracy of the Company’s contract summary documentation, specifically related to the identification and determination of distinct performance obligations and the timing of revenue recognition.

ACQUISITION OF CYBERARK SOFTWARE LTD. (“CYBERARK”) - VALUATION OF PLATFORM RENEWALS

Description of the MatterAs disclosed in Notes 1 and 8 to the consolidated financial statements, on February 11, 2026, the Company completed the acquisition of CyberArk for total purchase consideration of $21.1 billion. The Company accounted for the acquisition as a business combination. In connection with this acquisition, the Company recognized platform renewals intangible assets of $3.5 billion. Auditing the Company’s valuation of the acquired platform renewals intangible assets was complex due to the significant judgment and estimation in determining the fair value of the platform renewals. Specifically, the fair value estimate for the acquired platform renewals intangible assets is sensitive to changes in the Company’s assumption related to forecasted revenue attributable to platform renewals. This significant assumption is forward-looking and could be affected by future economic and market conditions.
How We Addressed the Matter in Our AuditWe obtained an

Showing the first 8K of 207K characters. Open the full section

Item 9. Changes in and Disagreements with Accountants on Accounting and Financial Disclosure

Not applicable.

Item 9A. Controls and Procedures

Evaluation of Disclosure Controls and Procedures

Our management, with the participation of our chief executive officer and chief financial officer, evaluated the effectiveness of our disclosure controls and procedures pursuant to Rule 13a-15(b) under the Securities Exchange Act of 1934, as amended (the “Exchange Act”). In designing and evaluating the disclosure controls and procedures, management recognizes that any controls and procedures, no matter how well designed and operated, can provide only reasonable assurance of achieving the desired control objectives. In addition, the design of disclosure controls and procedures must reflect the fact that there are resource constraints and that management is required to apply its judgment in evaluating the benefits of possible controls and procedures relative to their costs.

Based on our evaluation, our chief executive officer and chief financial officer concluded that, as of July 31, 2026, our disclosure controls and procedures are designed at a reasonable assurance level and are effective to provide reasonable assurance that information we are required to disclose in reports that we file or submit under the Exchange Act is recorded, processed, summarized, and reported within the time periods specified in Securities and Exchange Commission (“SEC”) rules and forms, and that such information is accumulated and communicated to our management, including our chief executive officer and chief financial officer, as appropriate, to allow timely decisions regarding required disclosure.

Management’s Annual Report on Internal Control over Financial Reporting

Our management is responsible for establishing and maintaining adequate internal control over financial reporting as defined in Rule 13a-15(f) under the Exchange Act. Our management assessed the effectiveness of our internal control over financial reporting as of July 31, 2026, based on the framework set forth by the Committee of Sponsoring Organizations of the Treadway Commission (“COSO”) in Internal Control - Integrated Framework (2013 framework). In accordance with guidance issued by the SEC staff, companies are permitted to exclude acquisitions from their assessment of internal control over financial reporting for the first fiscal year in which the acquisition occurred. Our assessment of the effectiveness of our internal control over financial reporting as of July 31, 2026 excluded CyberArk, which we acquired on February 11, 2026. We have included the financial results of CyberArk in our consolidated financial statements since the date of acquisition, which constituted 2% of total consolidated assets, less than 1% of total consolidated net assets, and 6% of total consolidated revenue as of and for the year ended July 31, 2026. Based on that assessment, management concluded that, as of July 31, 2026, our internal control over financial reporting was effective.

The effectiveness of our internal control over financial reporting as of July 31, 2026 has been audited by Ernst & Young LLP, the independent registered public accounting firm that audits our consolidated financial statements, as stated in their attestation report which is included in Part II, Item 8 of this Annual Report on Form 10-K.

Changes in Internal Control over Financial Reporting

There were no changes in our internal control over financial reporting identified in connection with the evaluation required by Rule 13a-15(d) under the Exchange Act that occurred during the fiscal quarter ended July 31, 2026 that have materially affected, or are reasonably likely to materially affect, our internal control over financial reporting.

- 104 -

Item 9B. Other Information

Trading Plans of Directors and Executive Officers

Set forth below is certain information regarding Rule 10b5-1 trading plans adopted, modified or terminated by our directors and officers (as defined in Rule 16a-1(f)) during the fourth quarter of fiscal 2026. The Rule 10b5-1 trading plans listed below are each intended to satisfy the affirmative defense of Rule 10b5-1(c).

NameTitleActionDate of ActionExpiration DateTotal Amount of Common Stock to Be Sold Under the Plan
Dipak GolechhaChief Financial OfficerModifiedJune 25, 2026September 30, 202750,000 or, if earlier, when all shares have been sold
William D. Jenkins Jr.PresidentAdoptedJune 28, 2026January 31, 2027148,217 or, if earlier, when all shares have been sold

No other officers or directors, as defined in Rule 16a-1(f), adopted, modified, and/or terminated a “Rule 10b5-1 trading arrangement” or a “non-Rule 10b5-1 trading arrangement,” as defined in Regulation S-K Item 408, during the fourth quarter of fiscal 2026.

Item 9C. Disclosure Regarding Foreign Jurisdictions That Prevent Inspections

Not applicable.

- 105 -

Part III

Item 10. Directors, Executive Officers and Corporate Governance

The information required by this item will be contained in our definitive proxy statement to be filed with the SEC in connection with our 2026 annual meeting of stockholders (the “Proxy Statement”), which is expected to be filed not later than 120 days after the end of our fiscal year ended July 31, 2026 and is incorporated herein by reference.

Our Board has adopted a Code of Business Conduct and Ethics that applies to all our employees, officers and directors, including our Chief Executive Officer, Chief Financial Officer, and other executive and senior financial officers. We will post amendments to our Code of Business Conduct and Ethics or waivers of our Code of Business Conduct and Ethics for directors and executive officers on the same website.

Item 11. Executive Compensation

The information required by this item will be set forth in the Proxy Statement and is incorporated herein by reference.

Item 12. Security Ownership of Certain Beneficial Owners and Management and Related Stockholder Matters

The information required by this item will be set forth in the Proxy Statement and is incorporated herein by reference.

Item 13. Certain Relationships and Related Transactions, and Director Independence

The information required by this item will be set forth in the Proxy Statement and is incorporated herein by reference.

Item 14. Principal Accountant Fees and Services

The information required by this item will be set forth in the Proxy Statement and is incorporated herein by reference.

- 106 -

Part IV

Item 15. Exhibits and Financial Statement Schedules

Documents filed as part of this Annual Report on Form 10-K are as follows:

**1.**Consolidated Financial Statements

Our Consolidated Financial Statements are listed in the “Index to Consolidated Financial Statements” under Part II, Item 8 of this Annual Report on Form 10-K.

**2.**Financial Statement Schedules

Financial statement schedules have been omitted because they are not required, not applicable, not present in amounts sufficient to require submission of the schedule, or the required information is shown in the Consolidated Financial Statements or the notes thereto.

**3.**Exhibits

The following documents are incorporated by reference or are filed with this Annual Report on Form 10-K, in each case as indicated therein (numbered in accordance with Item 601 of Regulation S-K).

Exhibit Index

Exhibit NumberExhibit DescriptionIncorporated by Reference
FormFile No.ExhibitFiling Date
2.1^Agreement and Plan of Merger, dated as of July 30, 2025, by and among Palo Alto Networks, Inc., Athens Strategies Ltd. and CyberArk Software Ltd.8-K001-355942.1July 31, 2025
3.1Restated Certificate of Incorporation of the Registrant, as amended.10-K001-355943.1August 29, 2025
3.2Amended and Restated Bylaws of the Registrant.8-K001-355943.1August 21, 2026
3.3Certificate of Change of Location of Registered Agent and/or Registered Office.8-K001-355943.1August 30, 2016
4.1Description of Registrant’s Securities.10-K001-355944.1August 29, 2025
4.2Indenture, dated June 10, 2025, by and between CyberArk Software Ltd. and U.S. Bank Trust Company, National Association.8-K001-355944.1February 11, 2026
4.3First Supplemental Indenture, dated as of February 11, 2026, by and among Palo Alto Networks, Inc., CyberArk Software Ltd. and U.S. Bank Trust Company, National Association.8-K001-355944.2February 11, 2026
4.4Form of Global 0.00% Convertible Senior Note due 2030 (contained in Exhibit 4.2 hereto).8-K001-355944.3February 11, 2026
4.5Form of Amended and Restated Confirmation of Capped Call Transaction.
10.1*Form of Indemnification Agreement between the Registrant and its directors and officers.S-1/A333-18062010.1July 9, 2012
10.2*2012 Equity Incentive Plan and related form agreements.10-Q001-3559410.2November 26, 2019

- 107 -

Exhibit NumberExhibit DescriptionIncorporated by Reference
FormFile No.ExhibitFiling Date
10.3*Form of 2012 Equity Incentive Plan Performance-Based Restricted Stock Unit Award Agreement.10-Q001-3559410.4November 19, 2021
10.4*2021 Equity Incentive Plan, as amended and restated.8-K001-3559410.1December 11, 2025
10.5*^Form Award Agreements under the 2021 Equity Incentive plan, as amended and restated.
10.6*^2012 Employee Stock Purchase Plan, as amended and restated, and related form agreements.
10.7*RedLock Inc. 2015 Stock Plan, as amended, and related form agreements under RedLock Inc. 2015 Stock Plan, as amended.S-8333-22790199.1October 19, 2018
10.8*Cider Security Ltd. 2020 Equity Incentive Plan.S-8333-26893199.1December 21, 2022
10.9*US Sub-Plan to Cider Security Ltd. 2020 Equity Incentive Plan.S-8333-26893199.2December 21, 2022
10.10*CyberArk Software Ltd. 2024 Share Incentive Plan, as amended.S-8 POS333-2902354.4February 11, 2026
10.11*CyberArk Software Ltd. 2014 Share Incentive Plan, as amended.S-8 POS333-2902354.5February 11, 2026
10.12*Employee Incentive Compensation Plan, as amended and restated.10-Q001-3559410.2November 25, 2014
10.13Clawback Policy, adopted as of August 29, 2017, amended August 14, 2024.10-K001-3559410.16September 6, 2024
10.14*Amended and Restated Outside Director Compensation Policy (last amended February 12, 2025).10-Q001-3559410.1May 21, 2025
10.15*Continued Service Policy.10-Q001-3559410.3May 20, 2022
10.16*Palo Alto Networks, Inc. Deferred Compensation Plan effective June 1, 2022.10-K001-3559410.23September 6, 2022
10.17*Amendment and Restated Employment Letter between Palo Alto Networks, Inc. and Nir Zuk, dated July 7, 2025.10-K001-3559410.14August 29, 2025
10.18*Offer Letter between the Registrant and Nikesh Arora, dated May 30, 2018.8-K001-3559410.2June 4, 2018
10.19*Offer Letter between the Registrant and Josh Paul, dated August 5, 2021.8-K001-3559410.1September 8, 2021
10.20*Confirmatory Employment Letter with Updated Change in Control Protection between the Registrant and Lee Klarich, dated December 19, 2011.10-Q001-3559410.4November 30, 2018
10.21*Addendum to Employment Offer Letter by and between the Registrant and Dipak Golechha, dated March 17, 2021.8-K001-3559410.1March 19, 2021
10.22*Addendum to Employment Offer Letter by and between the Registrant and Dipak Golechha, dated February 18, 2022.10-Q001-3559410.1May 20, 2022

- 108 -

Exhibit NumberExhibit DescriptionIncorporated by Reference
FormFile No.ExhibitFiling Date
10.23*Employment Offer Letter by and between the Registrant and William “BJ” Jenkins, dated July 27, 2021.8-K001-3559410.1August 12, 2021
10.24*Addendum to Employment Offer Letter between the Registrant and William “BJ” Jenkins, dated February 18, 2022.10-Q001-3559410.2May 20, 2022
10.25*Form of Offer Letter between the Registrant and its directors.10-Q001-3559410.2May 21, 2025
10.26**Amended and Restated Flextronics Manufacturing Services Agreement, by and between the Registrant and Flextronics Telecom Systems Ltd., dated April 1, 2019.10-Q001-3559410.1May 30, 2019
10.27Vendor Information Security Terms between the Registrant and Flextronics Telecom Systems Ltd., dated July 23, 2021.10-K001-3559410.29September 3, 2021
10.28Lease between the Registrant and Santa Clara Campus Property Owner I LLC, dated May 28, 2015.10-K001-3559410.29September 17, 2015
10.29Lease between the Registrant and Santa Clara Campus Property Owner I LLC, dated May 28, 2015.10-K001-3559410.30September 17, 2015
10.30Lease between the Registrant and Santa Clara Campus Property Owner I LLC, dated May 28, 2015.10-K001-3559410.31September 17, 2015
10.31Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated October 7, 2015.8-K/A001-3559410.1October 19, 2015
10.32Amendment No. 1 to Lease by and between the Registrant and Santa Clara Phase I Property LLC, dated November 9, 2015.10-Q001-3559410.2November 24, 2015
10.33Amendment No. 1 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated November 9, 2015.10-Q001-3559410.3November 24, 2015
10.34Amendment No. 1 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated September 16, 2016.10-Q001-3559410.1November 22, 2016
10.35Amendment No. 1 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated September 16, 2016.10-Q001-3559410.2November 22, 2016
10.36Amendment No. 2 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated September 16, 2016.10-Q001-3559410.3November 22, 2016
10.37Amendment No. 2 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated November 16, 2016.10-Q001-3559410.1March 1, 2017
10.38Amendment No. 2 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated November 16, 2016.10-Q001-3559410.2March 1, 2017
10.39Amendment No. 3 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated November 16, 2016.10-Q001-3559410.3March 1, 2017

- 109 -

Exhibit NumberExhibit DescriptionIncorporated by Reference
FormFile No.ExhibitFiling Date
10.40Amendment No. 3 to Lease by and between the Registrant and Santa Clara EFH LLC, dated June 22, 2017.10-K001-3559410.40September 7, 2017
10.41Amendment No. 3 to Lease by and between the Registrant and Santa Clara G LLC, dated June 22, 2017.10-K001-3559410.41September 7, 2017
10.42Amendment No. 4 to Lease by and between the Registrant and Santa Clara EFH LLC, dated June 22, 2017.10-K001-3559410.42September 7, 2017
10.43Amendment No. 4 to Lease by and between the Registrant and Santa Clara Phase III EFH LLC, dated September 29, 2017.10-Q001-3559410.5November 21, 2017
10.44Amendment No. 4 to Lease by and between the Registrant and Santa Clara Phase III G LLC, dated September 29, 2017.10-Q001-3559410.6November 21, 2017
10.45Amendment No. 5 to Lease by and between the Registrant and Santa Clara Phase III EFH LLC, dated September 29, 2017.10-Q001-3559410.7November 21, 2017
10.46Amendment No. 5 to Lease by and between the Company and Santa Clara Phase III EFH, LLC, dated April 8, 2026.8-K001-3559410.1April 13, 2026
10.47Amendment No. 5 to Lease by and between the Company and Santa Clara Phase III G, LLC, dated April 8, 2026.8-K001-3559410.2April 13, 2026
10.48Amendment No. 6 to Lease by and between the Company and Santa Clara Phase III EFH, LLC, dated April 8, 2026.8-K001-3559410.3April 13, 2026
10.49Credit Agreement, dated as of April 13, 2023 among the Registrant, the lenders party thereto and Wells Fargo, National Association, as administrative agent.8-K001-3559410.1April 19, 2023
10.50Amendment No. 1, dated as of November 22, 2024, to Credit Agreement, dated as of April 13, 2023, among Palo Alto Networks, Inc., the lenders party thereto, and Wells Fargo Bank, National Association, as administrative agent.10-Q001-3559410.3February 14, 2025
10.51*^Executive Change in Control and Severance Policy.8-K001-3559410.1August 21, 2026
19.1^Insider Trading Policy and Requirements for Trading Plans, as amended and restated.10-K001-3559419.1August 29, 2025
21.1List of subsidiaries of the Registrant.
23.1Consent of Independent Registered Public Accounting Firm.
24.1Power of Attorney (contained in the signature page to this Annual Report on Form 10-K).
31.1Certification of the Chief Executive Officer pursuant to Section 302(a) of the Sarbanes-Oxley Act of 2002.
31.2Certification of the Chief Financial Officer pursuant to Section 302(a) of the Sarbanes-Oxley Act of 2002.

- 110 -

Exhibit NumberExhibit DescriptionIncorporated by Reference
FormFile No.ExhibitFiling Date
32.1†Certification of Chief Executive Officer pursuant to 18 U.S.C. Section 1350, as adopted pursuant to Section 906 of the Sarbanes-Oxley Act of 2002.
32.2†Certification of Chief Financial Officer pursuant to 18 U.S.C. Section 1350, as adopted pursuant to Section 906 of the Sarbanes-Oxley Act of 2002.
97.1Compensation Recovery Policy.10-K001-3559497.1September 6, 2024
101.INSXBRL Instance Document.
101.SCHXBRL Taxonomy Schema Linkbase Document.
101.CALXBRL Taxonomy Calculation Linkbase Document.
101.DEFXBRL Taxonomy Definition Linkbase Document.
101.LABXBRL Taxonomy Labels Linkbase Document.
101.PREXBRL Taxonomy Presentation Linkbase Document.
104Cover Page Interactive Data File (formatted as inline XBRL and contained in Exhibit 101).
  • Indicates a management contract or compensatory plan or arrangement.

^ Schedules (or similar schedules) have been omitted pursuant to Item 601(a)(5) of Regulation S-K. The Registrant agrees to furnish supplementally a copy of any omitted schedules (or similar attachments) to the SEC upon request; provided, however, that the Registrant may request confidential treatment pursuant to Rule 24b-2 of the Securities Exchange Act of 1934, as amended, for any schedules (or similar attachments) so furnished.

† The certifications attached as Exhibit 32.1 and Exhibit 32.2 that accompany this Annual Report on Form 10-K, are not deemed filed with the Securities and Exchange Commission and are not to be incorporated by reference into any filing of the Registrant under the Securities Act of 1933, as amended, or the Securities Exchange Act of 1934, as amended, whether made before or after the date of this Annual Report on Form 10-K, irrespective of any general incorporation language contained in such filing.

Item 16. Form 10-K Summary

Not applicable.

- 111 -

Signatures

Pursuant to the requirements of Section 13 or 15(d) of the Securities Exchange Act of 1934, the registrant has duly caused this report to be signed on its behalf by the undersigned, thereunto duly authorized.

PALO ALTO NETWORKS, INC.
By:/s/ NIKESH ARORA
Nikesh Arora
Chairman and Chief Executive Officer
Date:September 10, 2026

- 112 -

Power of Attorney

KNOW ALL PERSONS BY THESE PRESENTS, that each person whose signature appears below constitutes and appoints Nikesh Arora, Dipak Golechha, and Josh Paul, and each of them, as his or her true and lawful attorney-in-fact and agent, with full power of substitution and resubstitution, for him or her and in his or her name, place and stead, in any and all capacities, to sign any and all amendments to this Annual Report on Form 10-K, and to file the same, with all exhibits thereto, and other documents in connection therewith, with the Securities and Exchange Commission, granting unto said attorneys-in-fact and agents, and each of them, full power and authority to do and perform each and every act and thing requisite and necessary to be done in connection therewith, as fully to all intents and purposes as he or she might or could do in person, hereby ratifying and confirming all that said attorneys-in-fact and agents, or any of them, or their, his or her substitutes, may lawfully do or cause to be done by virtue thereof.

Pursuant to the requirements of the Securities Exchange Act of 1934, this report has been signed below by the following persons on behalf of the Registrant and in the capacities and on the dates indicated:

SignatureTitleDate
/s/ NIKESH ARORAChairman, Chief Executive Officer and Director (Principal Executive Officer)September 10, 2026
Nikesh Arora
/s/ DIPAK GOLECHHAChief Financial Officer (Duly Authorized Officer and Principal Financial Officer)September 10, 2026
Dipak Golechha
/s/ JOSH PAULChief Accounting Officer (Duly Authorized Officer and Principal Accounting Officer)September 10, 2026
Josh Paul
/s/ LEE KLARICHChief Product and Technology Officer and DirectorSeptember 10, 2026
Lee Klarich
/s/ APARNA BAWADirectorSeptember 10, 2026
Aparna Bawa
/s/ JOHN M. DONOVANDirectorSeptember 10, 2026
John M. Donovan
/s/ CARL ESCHENBACHDirectorSeptember 10, 2026
Carl Eschenbach
/s/ JAMES J. GOETZDirectorSeptember 10, 2026
James J. Goetz
/s/ MARK GOODBURNDirectorSeptember 10, 2026
Mark Goodburn
/s/ RT HON SIR JOHN KEYDirectorSeptember 10, 2026
Rt Hon Sir John Key
/s/ HELLE THORNING-SCHMIDTDirectorSeptember 10, 2026
Helle Thorning-Schmidt
/s/ LORRAINE TWOHILLDirectorSeptember 10, 2026
Lorraine Twohill

- 113 -