Palo Alto Networks (PANW) 10-K risk factor changes: FY2026 vs FY2025
The 2026-07-31 10-K against the 2025-07-31 one, compared heading by heading and sentence by sentence.
Item 1A269 rewritten155 added192 removed200 unchanged
All filing items1,099 rewritten965 added542 removed1,861 unchanged
Summary
counted, not written
- Item 1A lists 51 risk factor headings: 15 new, 13 reworded and 23 unchanged since FY2025. 11 headings from FY2025 no longer appear.
- Sentence by sentence, 965 added, 542 removed, 1,099 rewritten and 1,861 unchanged across 16 items that differ.
New Item 1A headings (15)
- Our consumption- or usage-based offerings may expose us to customer usage optimization behavior that could create revenue volatility.
- The “identity security” market lacks a universally accepted definition, which could lead to mischaracterization of our offerings and adverse evaluations by industry stakeholders.
- Customer trends toward vendor consolidation in cybersecurity may favor competitors offering broader platforms.Cybersecurity
- Cloud infrastructure providers and advanced AI companies increasingly offer native security and observability capabilities that compete directly with our offerings.AI
- The success of our strategy depends on maintaining a broad ecosystem of integrations with third-party technologies, which requires significant ongoing investment.
- The emergence of AI agents as a new class of identity presents both opportunities and risks that could impact our identity security offerings.AI
- A significant network or data security incident may materially impact our reputation, financial condition, and operating results.
- Our shared responsibility security model relies on customers to configure and use our products securely, and customer errors could harm our reputation even when we are not at fault.
- Our subscription agreements typically contain service-level commitments, and failure to meet these commitments could reduce our revenue and harm our business.
- We rely on data center facilities operated by third-party cloud service providers, and any limitations on capacity, or interference with our use could adversely affect our business, financial condition, and results of operations.
- We depend on manufacturing partners and limited sources of supply for our hardware products, making us susceptible to manufacturing delays, supply shortages, pricing fluctuations, and international trade risks that could prevent timely shipment of customer orders and result in the loss of sales and end-customers.
- Our products and subscriptions are subject to certification, testing, and regulatory approval requirements in foreign jurisdictions, and our failure to obtain or maintain such approvals could limit our ability to sell in those markets.
- We may incur significant costs to comply with privacy and data protection laws and other requirements, and, if we fail to comply, we could be subject to government enforcement actions, private litigation, and adverse publicity, which could materially adversely affect our business, financial condition, and operating results.
- We may not have the ability to raise the funds necessary to settle conversions of the 2030 Notes, repurchase the 2030 Notes upon a fundamental change, or repay the 2030 Notes in cash at their maturity, and our other debt may contain limitations on our ability to pay cash upon conversion or repurchase of the 2030 Notes.
- The Capped Calls may affect the value of the 2030 Notes and our common stock.
Removed Item 1A headings (11)
- Seasonality may cause fluctuations in our revenue.
- If we are unable to attract new customers, our future results of operations could be harmed.
- We may not complete the acquisition of CyberArk within the timeframe we anticipate or at all, which could negatively impact our future business and financial results.
- A network or data security incident may allow unauthorized access to our network or data, harm our reputation, create additional liability, and adversely impact our financial results.
- Because we depend on manufacturing partners to build and ship our hardware products, we are susceptible to manufacturing and logistics delays and pricing fluctuations that could prevent us from shipping customer orders on time, if at all, or on a cost-effective basis, which may result in the loss of sales and end-customers.
- Managing the supply of our hardware products and product components is complex. Insufficient supply and inventory would result in lost sales opportunities or delayed revenue, while excess inventory would harm our gross margins.
- Our hardware products contain key components from limited sources of supply, including outside the United States, and we are susceptible to supply shortages, supply changes, and international regulations, which, in certain cases, have disrupted or delayed our scheduled product deliveries to our end-customers, increased our costs and may result in the loss of sales and end-customers.
- We are subject to international trade regulations and governmental export and import controls that could subject us to liability or impair our ability to compete in international markets.
- We may incur increased costs to comply with privacy and data protection laws and, if we fail to comply, we could be subject to government enforcement actions, private litigation and adverse publicity.
- The warrant transactions may affect the value of our common stock.
- Our failure to raise additional capital or generate the significant capital necessary to expand our operations and invest in new products and subscriptions could reduce our ability to compete and could harm our business.
Reworded Item 1A headings (13)
- Our business and operations have experienced growth in recent periods, and if we do not effectively manage
[removed: any][added: our] future growth or are unable to improve our systems, processes, and controls, our [added: business and] operating results could be adversely affected. - Our operating results may vary significantly from period to period, [added: including due to seasonality,] which makes our results difficult to predict and could cause our results to fall short of
[removed: expectations, and such results may not be indicative of future performance.][added: expectations.] - If we are unable to sell new and additional
[removed: product, subscription,][added: products, subscriptions,] and support offerings to[removed: our end-customers,][added: existing end-customers or attract new customers,] especially[removed: to]large enterprise customers, our future revenue and operating results will be harmed. - We rely on our channel partners to sell
[removed: substantially all][added: a substantial portion] of our products, including subscriptions and support, and if these channel partners fail to perform, our ability to sell and distribute our products and subscriptions will be limited and our operating results will be harmed. - We face intense competition
[removed: in our market]and we may lack sufficient financial or other resources to maintain or improve our competitive position. - We have [added: acquired] and may in the future acquire other
[removed: businesses (including CyberArk),][added: businesses,] which could subject us to adverse claims or liabilities, require significant management attention, disrupt our business, adversely affect our operating results, may not result in the expected benefits of such acquisitions, and may dilute stockholder value. - As a result of the CyberArk acquisition,
[removed: we anticipate that]the scope and size of our business[removed: will][added: have] substantially[removed: change and result][added: changed, which resulted] in certain incremental risks, including increased competition. - Issues in the
[removed: development and deployment][added: development, deployment, or use] of AI may result in reputational[removed: harm and][added: harm,] legal[removed: liability][added: liability,] and could adversely affect our[removed: results of operations.][added: business and operating results.] - We generate a significant amount of revenue from sales to distributors, resellers, and end-customers outside of the United States, and we are therefore subject to a number of risks associated with international sales and
[removed: operations.][added: operations, including export and import controls that could subject us to liability or impair our ability to compete in international markets.] [removed: If our][added: Our] estimates or judgments, including those relating to our critical accounting policies, are based on assumptions that [added: may] change or prove to be[removed: incorrect,][added: incorrect and, as a result,] our operating results [added: may] differ from our publicly announced guidance or the expectations of securities analysts and investors,[removed: resulting][added: which may result] in a decline in the market price of our common stock.- Our reputation
[removed: and/or][added: and] business could be negatively impacted by corporate responsibility[removed: matters and/or][added: matters, including] our reporting of such matters. - The issuance of additional [added: common] stock in connection with financings, acquisitions, investments, our stock incentive plans,
[removed: exercise of the 2025 Warrants,][added: convertible notes,] or otherwise will dilute [added: the] stock held by all other stockholders. - Our business is subject to the risks of earthquakes, fire, power outages, floods, health risks, [added: climate change,] and other catastrophic events, and to interruption by man-made problems, such as terrorism.
A heading is new when no FY2025 heading matches it after ignoring case and punctuation, and reworded when it shares at least 60 percent of its words with one that went away. All current risk factor headings.
Sentences by item
24 items, with every count and a link to each item that changed
Underlined words on a shaded ground are new in FY2026; struck-through words were in FY2025. Sentences that are wholly new or wholly gone are labelled rather than marked.
Item 1A. Risk Factors
269 rewritten, 155 added, 192 removed, 200 unchanged
- Our business and operations have experienced growth in recent periods, and if we do not effectively manage [removed: any] [added: our] future growth or are unable to improve our systems, processes, and controls, our [added: business and] operating results could be adversely affected.
- Our operating results may vary significantly from period to period, [added: including due to seasonality,] which makes our results difficult to predict and could cause our results to fall short of [removed: expectations, and such results may not be indicative of future performance.][added: expectations.]
- If we are unable to sell new and additional [removed: product, subscription,] [added: products, subscriptions,] and support offerings to [removed: our end-customers,] [added: existing end-customers or attract new customers,] especially [removed: to] large enterprise customers, our future revenue and operating results will be harmed.
- We rely on our channel partners to sell [removed: substantially all] [added: a substantial portion] of our products, including subscriptions and support, and if these channel partners fail to perform, our ability to sell and distribute our products and subscriptions will be limited and our operating results will be harmed.
- We face intense competition [removed: in our market] and we may lack sufficient financial or other resources to maintain or improve our competitive position.
- We have [added: acquired] and may in the future acquire other [removed: businesses (including CyberArk),] [added: businesses,] which could subject us to adverse claims or liabilities, require significant management attention, disrupt our business, adversely affect our operating results, may not result in the expected benefits of such acquisitions, and may dilute stockholder value.
- As a result of the CyberArk acquisition, [removed: we anticipate that] the scope and size of our business [removed: will] [added: have] substantially [removed: change and result] [added: changed, which resulted] in certain incremental risks, including increased competition.
- Issues in the [removed: development and deployment] [added: development, deployment, or use] of AI may result in reputational [removed: harm and] [added: harm,] legal [removed: liability] [added: liability,] and could adversely affect our [removed: results of operations.][added: business and operating results.]
- A [added: significant] network or data security incident may [removed: allow unauthorized access to our network or data, harm our reputation, create additional liability, and adversely] [added: materially] impact our [added: reputation,] financial [added: condition, and operating] results.
- [removed: Because we] [added: We] depend on manufacturing partners [removed: to build] and [removed: ship] [added: limited sources of supply for] our hardware products, [removed: we are] [added: making us] susceptible to manufacturing [removed: and logistics delays and] [added: delays, supply shortages,] pricing [removed: fluctuations] [added: fluctuations, and international trade risks] that could prevent [removed: us from shipping] [added: timely shipment of] customer orders [removed: on time, if at all, or on a cost-effective basis, which may] [added: and] result in the loss of sales and end-customers.
- We generate a significant amount of revenue from sales to distributors, resellers, and end-customers outside of the United States, and we are therefore subject to a number of risks associated with international sales and [removed: operations.][added: operations, including export and import controls that could subject us to liability or impair our ability to compete in international markets.]
- We may incur [removed: increased] [added: significant] costs to comply with privacy and data protection laws [added: and other requirements,] and, if we fail to comply, we could be subject to government enforcement actions, private [removed: litigation] [added: litigation,] and adverse [removed: publicity.][added: publicity, which could materially adversely affect our business, financial condition, and operating results.]
- [removed: If our] [added: Our] estimates or judgments, including those relating to our critical accounting policies, are based on assumptions that [added: may] change or prove to be [removed: incorrect,] [added: incorrect and, as a result,] our operating results [added: may] differ from our publicly announced guidance or the expectations of securities analysts and investors, [removed: resulting] [added: which may result] in a decline in the market price of our common stock.
[removed: - Our] [added: Our] reputation [removed: and/or] [added: and] business could be negatively impacted by corporate responsibility [removed: matters and/or] [added: matters, including] our reporting of such [removed: matters.][added: matters.]
- The [removed: warrant transactions] [added: Capped Calls] may affect the value of [added: the 2030 Notes and] our common stock.
- The issuance of additional [added: common] stock in connection with financings, acquisitions, investments, our stock incentive plans, [removed: exercise of the 2025 Warrants,] [added: convertible notes,] or otherwise will dilute [added: the] stock held by all other stockholders.
[removed: - Our] [added: Our] business is subject to the risks of earthquakes, fire, power outages, floods, health risks, [added: climate change,] and other catastrophic events, and to interruption by man-made problems, such as [removed: terrorism.][added: terrorism.]
We operate globally, and [removed: as a result,] our business and revenues are impacted by global economic and geopolitical conditions.
[removed: The instability] [added: Instability] in [removed: the] global credit markets, inflation, changes in public [removed: policies such as] [added: policies, changes in] domestic and international [removed: legislation or] regulations, changes in [removed: enforcement and administration policies, taxes, any increases in] interest rates, [removed: fluctuations in] foreign currency exchange [removed: rates, or international] [added: rate fluctuations,] trade [removed: agreements,] [added: regulations and tariffs,] international trade [removed: disputes, trade regulations, tariffs] [added: disputes] and [added: agreements,] changes in [removed: tariffs,] [added: tax laws,] geopolitical turmoil, and other disruptions to global and regional economies and markets continue to add uncertainty to global economic conditions.
Military actions or armed conflict, including the hostilities in Israel and the surrounding region, the Russia-Ukraine war and [removed: any] related political or economic [removed: responses and counter-responses,] [added: responses,] and uncertainty about, or changes in, government and trade [removed: relationships, policies, and treaties] [added: relationships] could [removed: also lead to worsening] [added: further worsen] economic and market conditions and [added: the] geopolitical environment.
[removed: In] [added: For example, in] response to Russia’s invasion of Ukraine, the United States, along with the European Union (the [removed: “E.U.”)] [added: “E.U.”),] has imposed restrictive sanctions on Russia, Russian entities, and Russian [removed: citizens (“Sanctions on Russia”).][added: citizens.]
Any continued or further [removed: uncertainty, weakness] [added: uncertainty] or deterioration in economic and market conditions or the geopolitical [removed: environment] [added: environment, or any expansion or imposition of government-mandated technology restrictions,] could have a material and adverse impact on our business, financial condition, and [removed: results of operations,] [added: operating results,] including reductions in [removed: sales of our products and subscriptions,] [added: sales,] longer sales cycles, reductions in subscription or contract duration and value, slower adoption of new technologies, [removed: alterations] [added: changes] in [removed: the] spending patterns or priorities of current and prospective [removed: customers (including delaying purchasing decisions),] [added: customers,] increased [removed: costs for the chips and components to manufacture our products,] [added: component, memory or compute costs,] and increased price competition.
Our business and operations have experienced growth in recent periods, and if we do not effectively manage [removed: any] [added: our] future growth or are unable to improve our systems, processes, and controls, our [added: business and] operating results could be adversely affected.
We have experienced growth and increased demand for our products and subscriptions over [removed: the last few] [added: recent] years.
For example, from the end of fiscal [removed: 2024] [added: 2025] to the end of fiscal [removed: 2025,] [added: 2026,] our headcount increased from [removed: 15,289 to] 16,068 [removed: employees.][added: to 21,921 employees, including approximately 4,223 additional headcount as a result of the CyberArk acquisition.]
The growth and expansion of our business and [removed: product, subscription,] [added: products, subscriptions,] and support offerings places a significant strain on our management, operational, and financial resources.
We may not be able to successfully implement, scale, or manage improvements to our systems, processes, and controls in an efficient or timely manner, [removed: which could result in material disruptions of] [added: and] our [removed: operations] [added: existing systems, processes,] and [removed: business.][added: controls may not prevent or detect all errors, omissions, or fraud.]
Any future growth would add complexity to our organization and require effective [removed: coordination throughout our organization.][added: coordination.]
Failure to manage any future growth effectively could result in increased costs, [removed: disrupt our existing] [added: disruption to] end-customer relationships, [removed: reduce] [added: reduced] demand for [removed: or limit us to smaller deployments of] our products, or [removed: materially] [added: material] harm [added: to] our business [removed: performance] and operating results.
We have experienced revenue growth rates of [removed: 14.9%] [added: 24%] and [removed: 16.5%] [added: 15%] in fiscal [removed: 2025] [added: 2026] and fiscal [removed: 2024,] [added: 2025,] respectively.
[removed: We] [added: In addition, we] anticipate that our operating expenses will continue to increase [removed: in the foreseeable future] as [removed: we continue to grow] our [removed: business.][added: business grows.]
Our growth efforts may prove more expensive than we currently anticipate, and we may not succeed in increasing our revenues [removed: sufficiently, or at all,] [added: sufficiently] to offset increasing expenses.
Revenue growth may slow or [removed: revenue may decline for a number of possible reasons,] [added: decline,] including [added: due to] slowing [removed: demand for our products] or [removed: subscriptions,] [added: declining demand,] increasing competition, [removed: a decrease in the growth of, or a demand shift in, our overall market,] [added: market shifts,] or a failure to capitalize on growth opportunities.
We have also entered into [removed: a] substantial [removed: amount of] capital commitments for operating lease obligations and other purchase commitments.
If we are unable to [removed: navigate] [added: increase our revenue sufficiently to offset] these [removed: challenges as we encounter them,] [added: costs and commitments,] our [removed: business,] [added: profitability, cash flow,] financial condition, and operating results may suffer.
Our operating results may vary significantly from period to period, [added: including due to seasonality,] which makes our results difficult to predict and could cause our results to fall short of [removed: expectations, and such results may not be indicative of future performance.][added: expectations.]
Our operating results have fluctuated in the past, and will likely continue to fluctuate in the future, as a result of a number of factors, many of which are outside of our [removed: control and may be difficult to predict,] [added: control,] including those [removed: factors] described in this Risk [removed: Factor] [added: Factors] section.
If expected revenue at the end of any fiscal quarter is delayed for any reason, including [removed: the failure of anticipated] [added: failed] purchase [removed: orders to materialize (particularly for large enterprise end-customers with lengthy sales cycles), our] [added: orders,] logistics [removed: partners’ inability to ship products prior to fiscal quarter-end to fulfill purchase orders received near the end of a fiscal quarter, our failure to manage] [added: delays,] inventory [added: management issues, trade compliance requirements (and changes] to [removed: meet demand, any] [added: such requirements), or] failure of [removed: our] systems related to order review and processing, [removed: or any delays in shipments based on trade compliance requirements (including new compliance requirements imposed by new or renegotiated trade agreements),] our revenue could fall below our expectations and the estimates of analysts for that quarter.
Due to these fluctuations, comparing our [removed: revenue, margins, or other operating] results on a period-to-period basis may not be meaningful, and our past results should not be relied on as an indication of our future performance.
[removed: We believe there are significant] [added: In addition,] seasonal factors [removed: that] may cause our second and fourth fiscal quarters to record greater revenue sequentially than our first and third fiscal [removed: quarters.][added: quarters, driven primarily by end-customer budget cycles, our annual sales compensation structure, and the timing of calendar-year budget planning.]
- Our consumption- or usage-based offerings may expose us to customer usage optimization behavior that could create revenue volatility.
- The “identity security” market lacks a universally accepted definition, which could lead to mischaracterization of our offerings and adverse evaluations by industry stakeholders.
- Customer trends toward vendor consolidation in cybersecurity may favor competitors offering broader platforms.
- Cloud infrastructure providers and advanced AI companies increasingly offer native security and observability capabilities that compete directly with our offerings.
- The success of our strategy depends on maintaining a broad ecosystem of integrations with third-party technologies, which requires significant ongoing investment.
- The emergence of AI agents as a new class of identity presents both opportunities and risks that could impact our identity security offerings.
- Our shared responsibility security model relies on customers to configure and use our products securely, and customer errors could harm our reputation even when we are not at fault.
- Our subscription agreements typically contain service-level commitments, and failure to meet these commitments could reduce our revenue and harm our business.
- We rely on data center facilities operated by third-party cloud service providers, and any limitations on capacity, or interference with our use could adversely affect our business, financial condition, and results of operations.
- Our products and subscriptions are subject to certification, testing, and regulatory approval requirements in foreign jurisdictions, and our failure to obtain or maintain such approvals could limit our ability to sell in those markets.
- We may not have the ability to raise the funds necessary to settle conversions of the 2030 Notes, repurchase the 2030 Notes upon a fundamental change, or repay the 2030 Notes in cash at their maturity, and our other debt may contain limitations on our ability to pay cash upon conversion or repurchase of the 2030 Notes.
In addition, government-mandated restrictions on technology access, including export controls, import restrictions, or requirements that certain technologies not be made available in particular countries or regions, could limit our ability to sell or support our products and subscriptions in affected markets, require us to modify or discontinue certain products or features, or require us to exit certain markets.
As we grow, these seasonal and cyclical variations may become more pronounced.
Our consumption- or usage-based offerings may expose us to customer usage optimization behavior that could create revenue volatility.
A growing portion of our revenue is generated from offerings priced on a consumption or usage basis, including certain of our observability and AI-related offerings.
Pricing on this basis may result in significant near-term revenue growth as customers scale their usage but also creates exposure to customer optimization behavior, where customers who have rapidly increased usage subsequently seek to reduce, optimize, or reconfigure their consumption or usage to lower costs.
This dynamic has been observed in the industry with cloud-native customers and, more recently, with AI-native
customers, whose data volumes and usage patterns can fluctuate significantly.
Certain customer cohorts, including large enterprises and AI-native customers, may represent a meaningful portion of our consumption- or usage-based revenue growth, and any material optimization or reduction in usage by these cohorts, or their failure to renew subscriptions on comparable terms, could result in revenue volatility.
As of July 31, 2026, one distributor individually represented 19% of our gross accounts receivable.
Our efforts to monitor customer payment capability and maintain reserves adequate to cover exposure for doubtful accounts may not be effective.
Government entities may also have rights to terminate contracts for convenience or due to a default, and government audits of their contractors, suppliers, or vendors could result in the government refusing to continue purchasing our products, subscriptions, and support offerings, revenue reductions, or fines and civil or criminal liability, all of which may adversely impact our operating results.
End-user customers who have invested substantial resources in their existing infrastructure may prefer to continue purchasing from their existing suppliers rather than switch to our products and subscriptions.
The maturity and expansion of the enterprise cybersecurity space may attract new players, including cloud hyperscalers, advance AI companies and enterprise software companies in adjacent industries, which may meaningfully enter or further expand into additional cybersecurity categories, including the identity security category.
The “identity security” market lacks a universally accepted definition, which could lead to mischaracterization of our offerings and adverse evaluations by industry stakeholders.
We have significantly expanded our participation in what is commonly referred to as the “identity security” market.
However, this market lacks a standardized definition and is subject to varying interpretations by industry analysts, customers, and competitors.
This ambiguity could lead to mischaracterization of our identity security products or market positioning by industry stakeholders, resulting in unfavorable evaluations, reviews, or accreditations.
Industry analyst reports and rankings can materially influence customer purchasing decisions in the security industry, and unfavorable reviews, downgrades in accreditation, or evolving definitions of the identity security category could negatively affect our reputation, competitive standing, and ability to attract and retain customers.
Customer trends toward vendor consolidation in cybersecurity may favor competitors offering broader platforms.
Enterprise cybersecurity buyers are increasingly seeking to consolidate their vendors to reduce costs, complexity, and integration challenges.
While our platformization strategy is designed to benefit from this trend, consolidation may also create opportunities for competitors, including large cybersecurity platform vendors, cloud hyperscalers, and enterprise software companies, to offer broader bundled solutions that include capabilities in categories where we compete, such as identity security and observability.
If customers choose to consolidate with vendors offering more comprehensive suites, or if competitors more successfully utilize acquisitions or partnerships to combine capabilities, we may be at a competitive disadvantage.
Furthermore, organizations continuously evaluate their information security priorities and may allocate budgets to solutions offered by our competitors, or may not adopt or expand the use of our solutions, which could adversely affect our business, financial condition, and operating results.
Cloud infrastructure providers and advanced AI companies increasingly offer native security and observability capabilities that compete directly with our offerings.
The major public cloud infrastructure providers increasingly offer native security, identity, and observability capabilities that compete with our products and subscriptions.
These providers have significant resources and may bundle native capabilities with their cloud infrastructure services at low or no incremental cost to customers, may leverage privileged access to their platforms and telemetry, and may design their native offerings to integrate more seamlessly with their infrastructure than third-party solutions can.
As customers increasingly deploy workloads across multiple cloud environments, or as cloud providers expand the scope and depth of their native security and observability capabilities, demand for our offerings could be adversely affected.
We may also face pricing pressure as competitors utilize cloud provider economics or offer bundled solutions at reduced total cost of ownership.
In addition, frontier or foundational AI model providers, or similar companies with advanced large language model capabilities, have entered or may enter the cybersecurity and observability markets, whether directly, through partnerships, or by enabling third parties to build competing security applications on top of their models.
- Seasonality may cause fluctuations in our revenue.
- If we are unable to attract new customers, our future results of operations could be harmed.
- We may not complete the acquisition of CyberArk within the timeframe we anticipate or at all, which could negatively impact our future business and financial results.
\- 14 \-
- Managing the supply of our hardware products and product components is complex.
Insufficient supply and inventory would result in lost sales opportunities or delayed revenue, while excess inventory would harm our gross margins.
- Our hardware products contain key components from limited sources of supply, including outside the United States, and we are susceptible to supply shortages, supply changes, and international regulations, which, in certain cases, have disrupted or delayed our scheduled product deliveries to our end-customers, increased our costs and may result in the loss of sales and end-customers.
- We are subject to international trade regulations and governmental export and import controls that could subject us to liability or impair our ability to compete in international markets.
- Failure to comply with governmental laws and regulations could harm our business.
- The market price of our common stock historically has been volatile, and the value of an investment in our common stock could decline.
- We cannot guarantee that our share repurchase program will be fully consummated or that it will enhance shareholder value, and share repurchases could affect the price of our common stock.
- We do not intend to pay dividends for the foreseeable future.
- Our charter documents and Delaware law could discourage takeover attempts and lead to management entrenchment, which could also reduce the market price of our common stock.
- Our failure to raise additional capital or generate the significant capital necessary to expand our operations and invest in new products and subscriptions could reduce our ability to compete and could harm our business.
\- 15 \-
In addition, our existing systems, processes, and controls may not prevent or detect all errors, omissions, or fraud.
We may also experience difficulties in managing improvements to our systems, processes, and controls, or in connection with third-party software licensed to help us with such improvements.
\- 16 \-
In addition, we have incurred losses in fiscal years prior to fiscal 2023.
Any failure to increase our revenue as we grow our business could prevent us from maintaining profitability or maintaining or increasing cash flow on a consistent basis, or satisfying our capital commitments.
Seasonality may cause fluctuations in our revenue.
We believe that this seasonality results from a number of factors, including:
- end-customers with a December 31 fiscal year-end choosing to spend remaining unused portions of their discretionary budgets before their fiscal year-end, which potentially results in a positive impact on our revenue in our second fiscal quarter;
- our sales compensation plans, which are typically structured around annual quotas and commission rate accelerators, which potentially results in a positive impact on our revenue in our fourth fiscal quarter; and
- the timing of end-customer budget planning at the beginning of the calendar year, which can result in a delay in spending at the beginning of the calendar year, potentially resulting in a negative impact on our revenue in our third fiscal quarter.
As we continue to grow, seasonal or cyclical variations in our operations may become more pronounced, and our business, operating results, and financial position may be adversely affected.
All of these factors add further risk to business conducted with these end-customers.
If we are unable to attract new customers, our future results of operations could be harmed.
To increase our revenue and maintain profitability, we must add new customers.
To do so, we must successfully convince prospective customers of the value of adopting our solutions.
Additionally, prospective customers’ decisions to purchase our solutions depend on a variety of factors, many of which are out of our control.
These factors significantly impact our ability to add new customers and increase the time, resources and sophistication required to do so.
For example, prospective customers may face real or perceived switching costs when switching to our solutions from legacy security vendors and products.
Deployment of our solutions may require a significant commitment of resources from our customers.
If our efforts to attract new customers are not successful, our sales may not grow as quickly as anticipated, or at all, and our business, operating results, and financial condition will be harmed.
Additionally, our end-customers may renew their subscription and support agreements for shorter contract lengths or on other terms that are less economically beneficial to us.
As of July 31, 2025, three distributors individually represented 10% or more of our gross accounts receivable and in the aggregate represented 44.8% of our gross accounts receivable.
We may not be able to incentivize these channel partners to sell our products and subscriptions to end-customers and, in particular, to large enterprises.
These channel partners may also have incentives to promote our competitors’ products and may devote more resources to the marketing, sales, and support of competitive products.
We cannot be certain that we will retain these channel partners or that we will be able to secure additional or replacement channel partners.
An excerpt. Shown here: 40 of 269 rewritten, 40 of 155 added and 40 of 192 removed. The counts are complete. For every sentence, read Item 1A. Risk Factors in the FY2026 filing and the FY2025 filing.
Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations
117 rewritten, 119 added, 94 removed, 292 unchanged
- Results of Operations. A discussion of the nature and trends in our financial results and an analysis of our financial results comparing fiscal [removed: 2025] [added: 2026] to fiscal [removed: 2024.][added: 2025.]
For discussion and analysis related to our financial results comparing fiscal [removed: 2024] [added: 2025] to [removed: 2023,] [added: 2024,] refer to Part II, Item [removed: 7.][added: 7 Management’s Discussion and Analysis of Financial Condition and Results of Operations in our Annual Report on Form 10-K for fiscal 2025, which was filed with the Securities and Exchange Commission on August 29, 2025.]
Our mission is to be the cybersecurity partner of [removed: choice for enterprises, organizations, service providers, and government entities to protect] [added: choice, protecting] our digital way of life.
Our [removed: cybersecurity] platforms and services help secure enterprise users, networks, clouds, [added: endpoints, AI apps] and [removed: endpoints] [added: agents, and identities] by delivering comprehensive cybersecurity backed by [removed: artificial intelligence (“AI”)] [added: AI] and [removed: automation.][added: automation, and provide real-time visibility and monitoring across cloud infrastructure, applications and AI workloads.]
We execute on this strategy by developing our capabilities and packaging our offerings into [removed: platforms] [added: platforms,] which are able to cover many of our customers’ needs in the markets in which we operate.
Network [added: & AI] Security
Our [removed: network security] [added: Network & AI Security] platform is designed to deliver complete zero trust solutions to our customers.
[added: Our] Prisma [removed: Access Browser] [added: Browser™] further extends [removed: SASE] [added: zero-trust] security and data protection to the [removed: end user device,] [added: browser, where the majority of work is done today,] providing [removed: workers] [added: users] with [added: the] freedom to [removed: access business applications] [added: work] securely using our secure browser from any device.
- *Next-Generation Firewalls.* Our [removed: hardware] ML-Powered [removed: Next-Generation Firewalls (“NGFWs”)] [added: NGFWs] secure on-premises environments including campus locations and data centers.
Our software NGFWs secure [added: virtual and] cloud networks.
- *Cloud-Delivered Security [removed: Services (“CDSS”).*] [added: Services.*] Our network security platform integrates a suite of [removed: CDSS] [added: Precision AI powered security capabilities] that complements our SASE and [removed: Firewall] [added: NGFW] solutions.
These include Advanced Threat Prevention, Advanced WildFire®, Advanced URL Filtering, Advanced DNS Security, [removed: IoT/OT] [added: Device] Security, [added: Quantum Security, NGTS,] GlobalProtect®, Prisma Access Agent, Enterprise [removed: Data Loss Prevention (“Enterprise DLP”), AI for IT Operations (“AIOps”), Software as a Service (“SaaS”)] [added: DLP, SaaS] Security, and AI Access [removed: Security.][added: Security™.]
Through these add-on services, our customers are able to secure their content, applications, users, [added: devices,] and [removed: devices] [added: connection] across their entire organization.
[removed: This comprehensive solution] [added: It] includes Strata Copilot, which offers a natural language interface for [removed: enhanced] [added: actionable] insights and guided remediation, and integrates [removed: Autonomous Digital Experience Monitoring (“ADEM”)] [added: ADEM] to [removed: proactively maintain infrastructure health, facilitate AI-driven one-click troubleshooting,] [added: help customers monitor] and [removed: ensure seamless] [added: improve] end-user performance across the enterprise.
Our AI-powered [removed: Cortex] [added: Cortex®] platform transforms end-to-end security operations [added: and observability] with unified data, AI, and automation for more secure, faster, and cost effective outcomes.
- *Security Operations.* We deliver the next generation of security operations capabilities that unifies standalone [removed: Security Information and Event Management (“SIEM”)] [added: SIEM] tools, endpoint security, security automation, [removed: cloud detection and response (“CDR”),] [added: CDR,] as well as [removed: attack surface management (“ASM”)] [added: ASM] capabilities on our [removed: Cortex®] [added: Cortex] platform.
These include Cortex XSIAM®, for AI-powered security operations replacing traditional SIEM [removed: tools,] [added: tools;] Cortex XDR®, for the prevention, detection, and response to complex cybersecurity [removed: attacks,] [added: attacks;] Cortex XSOAR®, for [removed: security orchestration, automation, and response (“SOAR”), and] [added: SOAR;] Cortex Xpanse®, for [removed: ASM.][added: ASM; and Koi Agentic Endpoint Security.]
- *Cloud Security.* We deliver comprehensive security across the cloud application development lifecycle through Cortex [removed: Cloud,] [added: Cloud®,] delivered as a scalable SaaS offering.
As a comprehensive [removed: Cloud Native Application Protection Platform (“CNAPP”)] [added: CNAPP] combined with CDR, Cortex Cloud secures multi- and hybrid-cloud environments for applications, data, [removed: generative AI (“GenAI”)] [added: GenAI] ecosystem, and the cloud native technology stack across the full development lifecycle, from code to cloud to security operations.
- Unit [removed: 42] [added: 42®] brings together world-renowned expertise across threat research, incident response, and security consulting to deliver intelligence-driven, response-ready outcomes that help customers reduce cyber risk.
Our elite consultants serve as trusted advisors to our customers by assessing and testing their security controls against sophisticated threats, [added: including Frontier AI,] transforming their security strategy with a threat-informed approach, and responding to security incidents on behalf of our clients.
Additionally, Unit 42 offers [removed: managed detection and response (“MDR”)] [added: MDR] and managed threat hunting services.
For fiscal [removed: 2025] [added: 2026] and [removed: 2024,] [added: 2025,] total revenue was [removed: $9.2] [added: $11.5] billion and [removed: $8.0] [added: $9.2] billion, respectively, representing year-over-year growth of [removed: 14.9%.][added: 24%.]
Our growth reflects the increased adoption of our portfolio, which consists of product, subscriptions, and [removed: support.][added: support, and the contributions from our acquisitions in our current fiscal year.]
As of July 31, [removed: 2025,] [added: 2026,] we had end-customers in over 180 countries.
Our product revenue grew to [removed: $1.8 billion] [added: $2.3 billion,] or [removed: 19.5%] [added: 19.9%] of total revenue for fiscal [removed: 2025,] [added: 2026,] representing year-over-year growth of [removed: 12.4%.][added: 27%.]
Product revenue is derived from sales of hardware products, primarily our ML-Powered [removed: Next-Generation Firewall,] [added: NGFW,] and software licenses, including SD-WAN, [removed: the] VM-Series, and Panorama®.
Our ML-Powered [removed: Next-Generation Firewall] [added: NGFW] incorporates our [removed: PAN-OS] [added: PAN-OS®] operating system, which provides a consistent set of capabilities across our entire network security product line.
Our subscription and support revenue grew to [removed: $7.4 billion] [added: $9.2 billion,] or [removed: 80.5%] [added: 80.1%] of total revenue for fiscal [removed: 2025,] [added: 2026,] representing year-over-year growth of [removed: 15.5%.][added: 24%.]
Our subscriptions provide our end-customers with near real-time access to the latest intrusion prevention, web security, modern malware prevention, data loss prevention, [removed: CASB] [added: cloud security access broker,] and AI security capabilities across the network, endpoints, and the cloud.
We also offer professional services, including incident response, risk management, [removed: and] digital forensic [removed: services.][added: services, and technical account management.]
We continue to invest in innovation as we evolve and further extend the capabilities of our portfolio, as we believe that innovation and timely development [removed: of] [added: of, and investment in,] new features and products are essential to meeting the needs of our end-customers and improving our competitive position.
Changes in legislation or regulations and actions by regulators, including changes in enforcement and administration policies, may have an impact on our [removed: results of operations and] financial [removed: condition.][added: condition and operating results.]
Further, economic conditions, including inflation, high interest rates, slow growth, fluctuations in foreign exchange rates, supply chain disruptions, [added: including increased memory, storage, or other component shortages and costs,] impacts of trade regulations or international trade disputes, and other conditions, may [added: materially and] adversely affect our [removed: results of operations and] financial [removed: performance.][added: condition and operating results.]
The hostilities in [removed: Israel] [added: Israel, Iran,] and the surrounding region have continued to result in economic and political uncertainty.
We are also monitoring the impact of inflationary pressures and the tensions between China and Taiwan, and between the U.S. and China, which [added: have increased our costs and] could have an adverse impact on our business or results of operations in future periods.
| | | | [added: 2026 | | | | | |] 2025 | | | | | | 2024 | | |
| Next-Generation Security Annualized Recurring Revenue | | | $ | [removed: 5.6] [added: 9.1] | | | | | $ | [removed: 4.2] [added: 5.6] | |
| Remaining performance obligations | | | $ | [removed: 15.8] [added: 21.2] | | | | | $ | [removed: 12.7] [added: 15.8] | |
| | | | [removed: 2025] [added: 2026] | | | | | | [removed: 2024] [added: 2025] | | | | | | [removed: 2023] [added: 2024] | | |
- *Secure Access Service Edge.* Prisma® Access, when combined with Prisma SD-WAN, provides a comprehensive AI-powered SASE solution that secures users, branches, data, AI apps and agents from the most evasive threats in the new AI landscape.
- *Prisma AIRS.* Prisma AIRS™ is our comprehensive AI security platform designed to help organizations discover, assess, and protect AI agents, applications, models and data across the AI lifecycle.
It supports key enterprise use cases, including securing AI-assisted software development, protecting custom AI applications from development through runtime, and governing autonomous AI agents.
Prisma AIRS™ brings together AI Gateway, Agent Security, AI Red Teaming, AI Runtime Security™, AI Model Security, and AI Posture Management in a unified platform.
These capabilities provide visibility into AI assets and activity, assess risks before deployment, and enforce security controls during live AI interactions and agent actions.
- *Strata Cloud Manager.* SCM, is our AI-powered unified network security management and operations solution.
It enables customers to manage and monitor their NGFW and SASE environments through a single, streamlined interface.
SCM helps customers centrally manage configurations and security policies, assess security posture and network health, and streamline troubleshooting and remediation.
Cortex
Additionally, Cortex XSIAM integrates with the Chronosphere Telemetry Pipeline to ingest and optimize massive data volumes, promoting cost-effective scaling of autonomous operations.
- *Observability.* Chronosphere, our next-generation observability platform, delivers real-time visibility and monitoring across cloud-native infrastructure, applications, and AI workloads.
Purpose-built to handle the massive data volumes of the AI era, Chronosphere enables organizations to maintain system resilience and uptime with high cost-efficiency and reliability.
Our observability platform provides comprehensive visibility into complex digital environments and automated troubleshooting of issues.
It allows customers to transition from passive monitoring to proactive management of their entire digital estate.
Our telemetry pipeline acts as an intelligent control layer that filters, transforms, and routes data.
This helps reduce data volumes, enabling customers to cost-effectively scale their security and observability posture.
Idira
Idira™, our next-generation identity security platform, is designed to secure human, agentic, and machine identities across the enterprise with intelligent privilege controls and continuous threat prevention.
By unifying identity access management, privilege access management, and identity governance and administration, organizations can continuously discover and protect against identity risk throughout the end-to-end identity lifecycle.
The platform includes:
- *Workforce Identity Security.* Our solutions apply identity assurance and modern access controls for the entire workforce, including through adaptive MFA, SSO, secure browsing, web session protection, workforce password management, and automated identity lifecycle management.
Our approach enforces least privilege by elevating access only when required.
- *IT and Developer Identity Security (Modern Privilege Access Management).* Our solutions secure high-risk access for IT administrators, third-party vendors, developers, and cloud operations teams across hybrid and multi-cloud environments, delivering just-in-time privileged access, session isolation, credential protection, and zero standing privileges, while providing native, secure access to cloud services, workloads, and development and operations pipelines.
Organizations can eliminate excessive permissions, automate access to dynamic cloud resources, and maintain developer velocity while strengthening identity controls across infrastructure and application environments.
- *Machine Identity Security.* Our solutions secure the growing volume of non-human identities—such as workloads, applications, containers, service accounts, certificates, and keys, including through centralized discovery and management of secrets, certificate lifecycle automation, workload identity issuance, public key infrastructure-as-a-service, Kubernetes certificate management, and secure code signing.
- *Identity Governance and Administration.* IGA enables visibility into entitlements, automated joiner–mover–leaver processes, access certification, and ongoing identity compliance.
AI-supported policy automation helps organizations govern access at scale and enforce a zero-trust model across all identities.
- *AI Agents Security.* Our solution discovers AI agents, assigns identity attributes, and restricts their access to task-specific resources.
It helps monitor and record agent activity for audit purposes, allows organizations to suspend or revoke access if behavior deviates from expected norms, and governs the lifecycle of the agent and the actions taken to support compliance.
In April 2026, we launched a new suite of Unit 42 Frontier AI Defense services to help customers proactively discover and neutralize threats introduced by next-generation AI models.
In connection with the acquisition of CyberArk in February 2026, our product revenue also includes on-premise software licenses of certain identity security offerings.
In connection with our acquisition of Chronosphere in January 2026, our subscriptions also include a next-generation observability platform for cloud-native infrastructure and applications as well as telemetry pipeline management that is designed to handle vast cloud data volumes with cost-efficiency and reliability.
With the acquisition of CyberArk, our subscriptions include a next-generation identity security platform designed to secure human, AI, and machine identity across the enterprise with intelligent privilege controls and continuous threat prevention.
During fiscal 2026, we introduced several upgrades and new offerings, including: PAN-OS 12.1 Orion, Prisma AIRS 2.0, NGTS, and Prisma AIRS 3.0.
Additionally, we evaluate opportunities to acquire complementary businesses, technologies, services, and intellectual property to complement our organic innovation and research and development efforts, advance the development of our platforms, and enable further investment in our key priority areas.
For example, on January 29, 2026, we completed the acquisition of Chronosphere, forming our observability platform; on February 11, 2026, we completed the acquisition of CyberArk, forming our next-generation identity security platform; on April 14, 2026, we completed the acquisition of Koi, adding agentic endpoint security capabilities to our security operations platform and enhancing Prisma AIRS; on May 29, 2026, we completed the acquisition of Portkey, enhancing our Prisma AIRS capabilities; on August 27, 2026, we completed the acquisition of Embrace, which we expect will add RUM capabilities to our observability platform; and on September 1, 2026, we completed the acquisition of Console, which we expect will deepen our agentic capabilities in Cortex.
On July 16, 2026, we announced the general availability of Prisma AIRS Gateway, which incorporates AI gateway capabilities acquired through Portkey into Prisma AIRS.
| | | | 2026 | | | | | | 2025 | | |
| Total revenue | | | $ | 11,480 | | | | | $ | 9,221 | | | | | $ | 8,027 | |
| Operating income | | | $ | 695 | | | | | $ | 1,243 | | | | | $ | 684 | |
Management’s Discussion and Analysis of Financial Condition and Results of Operations in our Annual Report on Form 10-K for fiscal 2024, which was filed with the Securities and Exchange Commission on September 6, 2024.
- *Secure Access Service Edge (“SASE”).* Prisma® Access, when combined with Prisma SD-WAN, provides a comprehensive single-vendor SASE offering that is used to secure remote workforces and cloud-delivered branch offices.
- *Prisma AIRS.* Prisma AIRS is a comprehensive AI security platform that has been designed to protect customers’ entire AI ecosystem by providing AI model scanning, posture management, red teaming, run-time security, and AI agent security.
- *Strata Cloud Manager (“SCM”).* SCM, our network security management solution, centrally manages network security across all remote workers, branches, headquarters, campuses, and cloud.
SCM leverages AI to simplify and strengthen network security by enabling customers to proactively pinpoint vulnerabilities, gain real-time remediation recommendations, and enhance overall digital experiences, thereby reducing operational burden.
Security Operations
We have consolidated our industry-leading Security Operations and Cloud Security capabilities on a single comprehensive platform to provide centralized visibility, proactive protection, real-time prevention, AI-driven insights, and automated remediation across enterprise and cloud.
During fiscal 2025, we introduced several new offerings, including: Prisma Access Browser, new capabilities in our OT Security solution, Cortex Cloud, Prisma AIRS, and Cortex XSIAM 3.0.
Additionally, in August 2024, we completed the acquisition of certain IBM QRadar assets, which we expect will help accelerate the growth of our Cortex business.
Additionally, in July 2025, we completed the acquisition of Protect AI, which we expect will enhance the capabilities of our AI security platform.
In July 2025, we also entered into a definitive agreement to acquire Software Ltd. (“CyberArk”), an identity security company, which acquisition is expected to close during the second half of our fiscal 2026.
| Total revenue | | | $ | 9,221.5 | | | | | $ | 8,027.5 | | | | | $ | 6,892.7 | |
| Operating income | | | $ | 1,242.9 | | | | | $ | 683.9 | | | | | $ | 387.3 | |
| Cash flow provided by operating activities | | | $ | 3,716.0 | | | | | $ | 3,257.6 | | | | | $ | 2,777.5 | |
| Product | | | $ | 1,801.9 | | | | | 19.5 | | % | | | | $ | 1,603.3 | | | | | 20.0 | | % | | | | $ | 1,578.4 | | | | | 22.9 | | % |
| Subscription and support | | | 7,419.6 | | | | | | 80.5 | | % | | | | 6,424.2 | | | | | | 80.0 | | % | | | | 5,314.3 | | | | | | 77.1 | | % |
| Total revenue | | | 9,221.5 | | | | | | 100.0 | | % | | | | 8,027.5 | | | | | | 100.0 | | % | | | | 6,892.7 | | | | | | 100.0 | | % |
| Product | | | 413.2 | | | | | | 4.5 | | % | | | | 348.2 | | | | | | 4.3 | | % | | | | 418.3 | | | | | | 6.1 | | % |
| Subscription and support | | | 2,038.4 | | | | | | 22.1 | | % | | | | 1,711.0 | | | | | | 21.4 | | % | | | | 1,491.4 | | | | | | 21.6 | | % |
| Total cost of revenue(1) | | | 2,451.6 | | | | | | 26.6 | | % | | | | 2,059.2 | | | | | | 25.7 | | % | | | | 1,909.7 | | | | | | 27.7 | | % |
| Total gross profit | | | 6,769.9 | | | | | | 73.4 | | % | | | | 5,968.3 | | | | | | 74.3 | | % | | | | 4,983.0 | | | | | | 72.3 | | % |
| Research and development | | | 1,984.1 | | | | | | 21.5 | | % | | | | 1,809.4 | | | | | | 22.5 | | % | | | | 1,604.0 | | | | | | 23.3 | | % |
| Sales and marketing | | | 3,100.2 | | | | | | 33.6 | | % | | | | 2,794.5 | | | | | | 34.8 | | % | | | | 2,544.0 | | | | | | 36.9 | | % |
| General and administrative | | | 442.7 | | | | | | 4.8 | | % | | | | 680.5 | | | | | | 8.5 | | % | | | | 447.7 | | | | | | 6.5 | | % |
| Total operating expenses(1) | | | 5,527.0 | | | | | | 59.9 | | % | | | | 5,284.4 | | | | | | 65.8 | | % | | | | 4,595.7 | | | | | | 66.7 | | % |
| Operating income | | | 1,242.9 | | | | | | 13.5 | | % | | | | 683.9 | | | | | | 8.5 | | % | | | | 387.3 | | | | | | 5.6 | | % |
| Interest expense | | | (3.0) | | | | | | — | | % | | | | (8.3) | | | | | | (0.1) | | % | | | | (27.2) | | | | | | (0.4) | | % |
| Other income, net | | | 355.8 | | | | | | 3.8 | | % | | | | 312.7 | | | | | | 3.9 | | % | | | | 206.2 | | | | | | 3.0 | | % |
| Income before income taxes | | | 1,595.7 | | | | | | 17.3 | | % | | | | 988.3 | | | | | | 12.3 | | % | | | | 566.3 | | | | | | 8.2 | | % |
| Net income | | | $ | 1,133.9 | | | | | 12.3 | | % | | | | $ | 2,577.6 | | | | | 32.1 | | % | | | | $ | 439.7 | | | | | 6.4 | | % |
| Research and development | | | 550.5 | | | | | | 525.5 | | | | | | 488.4 | | |
| Sales and marketing | | | 359.5 | | | | | | 300.8 | | | | | | 335.3 | | |
| General and administrative | | | 258.0 | | | | | | 124.1 | | | | | | 130.4 | | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| | | | Year Ended July 31, | | | | | | | | | | | | | | | | | | | | | | | | Year Ended July 31, | | | | | | | | | | | | | | | | | | | | |
| | | | Amount | | | | | | Amount | | | | | | Amount | | | | | | % | | | | | | Amount | | | | | | Amount | | | | | | Amount | | | | | | % | | |
| | | | (dollars in millions) | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| Product | | | $ | 1,801.9 | | | | | $ | 1,603.3 | | | | | $ | 198.6 | | | | | 12.4 | | % | | | | $ | 1,603.3 | | | | | $ | 1,578.4 | | | | | $ | 24.9 | | | | | 1.6 | | % |
| Subscription | | | $ | 4,974.4 | | | | | $ | 4,188.5 | | | | | $ | 785.9 | | | | | 18.8 | | % | | | | $ | 4,188.5 | | | | | $ | 3,335.4 | | | | | $ | 853.1 | | | | | 25.6 | | % |
An excerpt. Shown here: 40 of 117 rewritten, 40 of 119 added and 40 of 94 removed. The counts are complete. For every sentence, read Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations in the FY2026 filing and the FY2025 filing.
Item 7A. Quantitative and Qualitative Disclosures About Market Risk
4 rewritten, 1 added, 1 removed, 19 unchanged
A hypothetical 10% change in foreign exchange rates on monetary assets and liabilities would not be material to our financial condition or results of operations after taking into consideration the effect of foreign currency forward contracts in place as of July 31, [removed: 2025.][added: 2026.]
For additional information, see the risk factor entitled *“We are exposed to fluctuations in foreign currency exchange rates, which could negatively affect our financial condition and operating results.”* in Part [removed: 1,] [added: I,] Item 1A of this Annual Report on Form 10-K.
Based on investment positions as of July 31, [removed: 2025,] [added: 2026,] a hypothetical 100 basis point increase in interest rates across all maturities would result in a [removed: $132.3] [added: $128] million decline in the fair market value of the portfolio.
Conversely, a hypothetical 100 basis point decrease in interest rates would lead to a [removed: $134.7] [added: $131] million increase in the fair market value of the portfolio.
\- 57 \-
\- 56 \-
Item 1. Business
96 rewritten, 139 added, 42 removed, 190 unchanged
Palo Alto Networks, Inc. is a global [added: artificial intelligence (“AI”)] cybersecurity provider and our vision is a world where each day is safer and more secure than the one before.
Our mission is to be the cybersecurity partner of [removed: choice for enterprises, organizations, service providers, and government entities to protect] [added: choice, protecting] our digital way of life.
Our [removed: cybersecurity] platforms and services help secure enterprise users, networks, clouds, [added: endpoints, AI apps] and [removed: endpoints] [added: agents, and identities] by delivering comprehensive cybersecurity backed by [removed: artificial intelligence (“AI”)] [added: AI] and [removed: automation.][added: automation, and provide real-time visibility and monitoring across cloud infrastructure, applications and AI workloads.]
We execute on this strategy by developing our capabilities and packaging our offerings into [removed: platforms] [added: platforms,] which are able to cover many of our customers’ needs in the markets in which we operate.
Network [added: & AI] Security
Our [removed: network security] [added: Network & AI Security] platform is designed to deliver complete zero trust solutions to our customers.
[added: Our] Prisma [removed: Access Browser] [added: Browser™] further extends [removed: SASE] [added: zero-trust] security and data protection to the [removed: end user device,] [added: browser, where the majority of work is done today,] providing [removed: workers] [added: users] with [added: the] freedom to [removed: access business applications] [added: work] securely using our secure browser from any device.
Our [removed: hardware] ML-Powered Next-Generation Firewalls (“NGFWs”) secure on-premises environments including campus locations and data centers.
Our software NGFWs secure [added: virtual and] cloud networks.
Our network security platform integrates a suite of [removed: CDSS] [added: Precision AI powered security capabilities] that complements our SASE and [removed: Firewall] [added: NGFW] solutions.
These include Advanced Threat Prevention, Advanced WildFire®, Advanced URL Filtering, Advanced DNS Security, [removed: IoT/OT] [added: Device] Security, [added: Quantum Security, Next-Gen Trust Protection (“NGTS”),] GlobalProtect®, Prisma Access Agent, Enterprise Data Loss Prevention (“Enterprise DLP”), [removed: AI for IT Operations (“AIOps”),] Software as a Service (“SaaS”) Security, and AI Access [removed: Security.][added: Security™.]
Through these add-on services, our customers are able to secure their content, applications, users, [added: devices,] and [removed: devices] [added: connection] across their entire organization.
[removed: This comprehensive solution] [added: It] includes Strata Copilot, which offers a natural language interface for [removed: enhanced] [added: actionable] insights and guided remediation, and integrates Autonomous Digital Experience Monitoring (“ADEM”) to [removed: proactively maintain infrastructure health, facilitate AI-driven one-click troubleshooting,] [added: help customers monitor] and [removed: ensure seamless] [added: improve] end-user performance across the enterprise.
Our AI-powered [removed: Cortex] [added: Cortex®] platform transforms end-to-end security operations [added: and observability] with unified data, AI, and automation for more secure, faster, and cost effective outcomes.
- *Security Operations.* We deliver the next generation of security operations capabilities that unifies standalone Security Information and Event Management (“SIEM”) tools, endpoint security, security automation, cloud detection and response (“CDR”), as well as attack surface management (“ASM”) capabilities on our [removed: Cortex®] [added: Cortex] platform.
These include Cortex XSIAM®, for AI-powered security operations replacing traditional SIEM [removed: tools,] [added: tools;] Cortex XDR®, for the prevention, detection, and response to complex cybersecurity [removed: attacks,] [added: attacks;] Cortex XSOAR®, for security orchestration, automation, and response [removed: (“SOAR”), and] [added: (“SOAR”);] Cortex Xpanse®, for [removed: ASM.][added: ASM; and Koi Agentic Endpoint Security.]
- *Cloud Security.* We deliver comprehensive security across the cloud application development lifecycle through Cortex [removed: Cloud,] [added: Cloud®,] delivered as a scalable SaaS offering.
Our elite consultants serve as trusted advisors to our customers by assessing and testing their security controls against sophisticated threats, [added: including Frontier AI,] transforming their security strategy with a threat-informed approach, and responding to security incidents on behalf of our clients.
Prisma Access protects all application traffic with complete, best-in-class security while also delivering a seamless user experience with industry-leading service-level agreements [removed: (“SLA”s).][added: (“SLAs”).]
With native SASE integration, [added: our] Prisma Access Browser extends [removed: Zero Trust] [added: zero-trust security] to any device—managed or unmanaged—in minutes.
Prisma SD-WAN enables organizations to replace traditional wide area network (“WAN”) architectures with affordable broadband and internet transport types that promote improved bandwidth availability, [removed: redundancy] [added: redundancy,] and [removed: performance at a reduced cost.][added: performance.]
Next-Generation Firewalls. Our hardware and software ML-Powered [removed: Next Generation Firewalls] [added: NGFWs] use AI—including machine learning and deep learning—to stop zero-day threats in real time, and detect and secure the entire enterprise including Internet of Things (“IoT”).
This includes SD-WAN capabilities to intelligently steer traffic to data centers, branches, and the cloud, natively integrated into our [removed: Next-Generation Firewalls.][added: NGFWs.]
The service allows our network security platform access to Domain Name System (“DNS”) signatures that are generated using advanced predictive analysis, machine learning, and malicious domain data from a growing threat intelligence sharing community of which we are a [removed: part of.][added: part.]
- [removed: IoT/OT] [added: Device] Security. This cloud-delivered security service uses machine learning to accurately identify and classify various [removed: IoT and] [added: IoT, connected medical,] operational technology [removed: (“OT”)] [added: (“OT”), and unmanaged IT] devices, including never-been-seen-before devices, [removed: mission-critical OT] [added: critical] devices, and unmanaged legacy systems.
The service uses machine learning to baseline normal behavior, identify anomalous activity, assess [added: and prioritize] risk, [added: provide virtual patching,] and provide policy [added: and remediation] recommendations.
- GlobalProtect. [removed: This subscription] [added: GlobalProtect] provides protection for users of both traditional laptop and mobile devices.
- AI Access Security. AI Access Security classifies and prioritizes GenAI applications to assess risk, detect [removed: anomalies] [added: anomalies,] and visualize insights across multiple GenAI-specific attributes.
Strata Cloud [removed: Manager.] [added: Manager (“SCM”).] SCM enables our customers to easily manage their Palo Alto Networks’ Network Security infrastructure—including NGFWs and SASE deployments—from the cloud, via one unified management interface.
Built into this robust solution are Strata [removed: Copilot,] [added: Copilot™,] offering a natural language interface for intuitive insights and guided actions, and ADEM, designed for proactive infrastructure health, simplified troubleshooting, and consistent end-user performance across the network.
Panorama. [removed: Panorama] [added: Panorama®] is used for centralized policy management, device management, software licensing and updates, centralized logging and reporting, and log storage.
New deployments benefit from using SCM for managing network security estate—including our [removed: Next-Generation Firewalls] [added: NGFWs] and SASE—with a cloud-based, unified management interface.
- Cortex XDR. This cloud-based service enables organizations to collect telemetry from endpoint, network, [removed: identity] [added: identity,] and cloud data sources and apply advanced analytics and machine [removed: learning,] [added: learning] to quickly find and stop targeted attacks, insider abuse, and compromised endpoints.
- Cortex XSOAR. Available as a [removed: stand-alone] [added: stand-alone,] cloud-based service, an on-premises virtual appliance, or delivered natively through Cortex XSIAM, Cortex XSOAR is a comprehensive SOAR offering that unifies playbook automation, case management, real-time collaboration, and threat intelligence management to serve security teams across the incident lifecycle.
- Cortex Xpanse. Available as a [removed: stand-alone] [added: stand-alone,] cloud-based service and a cloud-based subscription module within Cortex XSIAM, Cortex Xpanse provides ASM, which is the ability for an organization to identify what an attacker would see among all of its sanctioned and unsanctioned Internet-facing assets.
- Cortex Cloud. Available as a [removed: stand-alone] [added: stand-alone,] cloud-based service or an add-on to Cortex XDR or to Cortex XSIAM.
Cortex Cloud consolidates multiple code and cloud security [removed: technologies] [added: technologies,] such as Cloud Detection and Response, Software Composition Analysis, Infrastructure as Code security, CI/CD security, secrets scanning, Cloud Security Posture Management, Cloud Identity and Entitlements Management, API security, Vulnerability Management, Cloud Workload Protection, Web Application and API Security, Cloud Network Security, and Cloud Attack Surface Management into a single unified offering.
Existing customers can continue leveraging Prisma Cloud as they upgrade to Cortex Cloud for significantly better, [removed: faster] [added: faster,] and more effective multi-cloud protection.
We offer our end-customers ongoing support for hardware, software, and [removed: certain] cloud [removed: offerings, which includes ongoing security updates, PAN-OS upgrades, bug fixes, and repairs.][added: offerings.]
Our engineering teams apply deep expertise in AI and machine learning across networking security, cloud security, endpoint security, [added: security operations,] and [added: identity] security [removed: operations] to address the rapidly evolving threat landscape.
- *Secure Access Service Edge (“SASE”).* Prisma® Access, when combined with Prisma SD-WAN, provides a comprehensive AI-powered SASE solution that secures users, branches, data, AI apps and agents from the most evasive threats in the new AI landscape.
- *Prisma AIRS.* Prisma AIRS™ is our comprehensive AI security platform designed to help organizations discover, assess, and protect AI agents, applications, models and data across the AI lifecycle.
It supports key enterprise use cases, including securing AI-assisted software development, protecting custom AI applications from development through runtime, and governing autonomous AI agents.
Prisma AIRS™ brings together AI Gateway, Agent Security, AI Red Teaming, AI Runtime Security™, AI Model Security, and AI Posture Management in a unified platform.
These capabilities provide visibility into AI assets and activity, assess risks before deployment, and enforce security controls during live AI interactions and agent actions.
SCM is our AI-powered unified network security management and operations solution.
It enables customers to manage and monitor their NGFW and SASE environments through a single, streamlined interface.
SCM helps customers centrally manage configurations and security policies, assess security posture and network health, and streamline troubleshooting and remediation.
Cortex
Additionally, Cortex XSIAM integrates with the Chronosphere Telemetry Pipeline to ingest and optimize massive data volumes, promoting cost-effective scaling of autonomous operations.
- *Observability.* Chronosphere, our next-generation observability platform, delivers real-time visibility and monitoring across cloud-native infrastructure, applications, and AI workloads.
Purpose-built to handle the massive data volumes of the AI era, Chronosphere enables organizations to maintain system resilience and uptime with high cost-efficiency and reliability.
Our observability platform provides comprehensive visibility into complex digital environments and automated troubleshooting of issues.
It allows customers to transition from passive monitoring to proactive management of their entire digital estate.
Our telemetry pipeline acts as an intelligent control layer that filters, transforms, and routes data.
This helps reduce data volumes, enabling customers to cost-effectively scale their security and observability posture.
Idira
Idira™, our next-generation identity security platform, is designed to secure human, agentic, and machine identities across the enterprise with intelligent privilege controls and continuous threat prevention.
By unifying identity access management, privilege access management, and identity governance and administration, organizations can continuously discover and protect against identity risk throughout the end-to-end identity lifecycle.
The platform includes:
- *Workforce Identity Security.* Our solutions apply identity assurance and modern access controls for the entire workforce, including through adaptive multi-factor authentication (“MFA”), single sign-on (“SSO”), secure browsing, web session protection, workforce password management, and automated identity lifecycle management.
Our approach enforces least privilege by elevating access only when required.
- *Information Technology (“IT”) and Developer Identity Security (Modern Privilege Access Management).* Our solutions secure high-risk access for IT administrators, third-party vendors, developers, and cloud operations teams across hybrid and multi-cloud environments, delivering just-in-time privileged access, session isolation, credential protection, and zero standing privileges, while providing native, secure access to cloud services, workloads, and development and operations pipelines.
Organizations can eliminate excessive permissions, automate access to dynamic cloud resources, and maintain developer velocity while strengthening identity controls across infrastructure and application environments.
- *Machine Identity Security.* Our solutions secure the growing volume of non-human identities—such as workloads, applications, containers, service accounts, certificates, and keys, including through centralized discovery and management of secrets, certificate lifecycle automation, workload identity issuance, public key infrastructure-as-a-service, Kubernetes certificate management, and secure code signing.
- *Identity Governance and Administration (“IGA”).* IGA enables visibility into entitlements, automated joiner–mover–leaver processes, access certification, and ongoing identity compliance.
AI-supported policy automation helps organizations govern access at scale and enforce a zero-trust model across all identities.
- *AI Agents Security.* Our solution discovers AI agents, assigns identity attributes, and restricts their access to task-specific resources.
It helps monitor and record agent activity for audit purposes, allows organizations to suspend or revoke access if behavior deviates from expected norms, and governs the lifecycle of the agent and the actions taken to support compliance.
In April 2026, we launched a new suite of Unit 42 Frontier AI Defense services to help customers proactively discover and neutralize threats introduced by next-generation AI models.
NETWORK & AI SECURITY
AI Security: Prisma AIRS. Prisma AIRS™ is our comprehensive AI security platform designed to help organizations discover, assess, and protect AI agents, applications, models, and data across the AI lifecycle.
It supports key enterprise use cases, including securing AI-assisted software development, protecting custom AI applications from development through runtime, and governing autonomous AI agents as they access enterprise data, tools, and systems.
Prisma AIRS brings together AI Gateway, Agent Security, AI Red Teaming, AI Runtime Security, AI Model Security, and AI Posture Management in a unified platform.
Together, these capabilities provide visibility into AI assets and activity, identify risks before deployment, and apply security controls to live AI interactions and agent actions.
- AI Gateway. Serves as the centralized AI security control plane through which all enterprise AI traffic flows—including LLM calls, tool invocations, agent interactions, and prompt data.
AI Gateway enables organizations to govern AI agents, secure AI coding tools, and safely enable enterprise AI apps from a single control plane.
The gateway provides real-time visibility into usage, tracks token consumption and cost, and inspects every interaction to prevent data leakage, prompt injection, and unsafe outputs.
Before agents or coding tools access enterprise data or systems, the gateway enforces identity-aware controls and authorizes actions against defined permissions.
- Agent Security. Provides lifecycle security and governance for enterprise AI agents, from development through production.
- *Secure Access Service Edge (“SASE”).* Prisma® Access, when combined with Prisma SD-WAN, provides a comprehensive single-vendor SASE offering that is used to secure remote workforces and cloud-delivered branch offices.
- *Prisma AIRS.* Prisma AIRS is a comprehensive AI security platform that has been designed to protect customers’ entire AI ecosystem by providing AI model scanning, posture management, red teaming, run-time security, and AI agent security.
SCM, our network security management solution, centrally manages network security across all remote workers, branches, headquarters, campuses, and cloud.
SCM leverages AI to simplify and strengthen network security by enabling customers to proactively pinpoint vulnerabilities, gain real-time remediation recommendations, and enhance overall digital experiences, thereby reducing operational burden.
Security Operations
We have consolidated our industry-leading Security Operations and Cloud Security capabilities on a single comprehensive platform to provide centralized visibility, proactive protection, real-time prevention, AI-driven insights, and automated remediation across enterprise and cloud.
- AIOps. AIOps enables security teams to proactively strengthen security posture and resolve network disruptions.
AIOps provides continuous best practice recommendations powered by machine learning based on industry standards, security policy context, and advanced telemetry data collected from our network security customers to improve security posture.
The service also intelligently predicts health, performance, and capacity problems up to seven days in advance and provides actionable insights to resolve the predicted disruptions.
Prisma AIRS. Prisma AIRS is a comprehensive AI security platform engineered to protect customers' entire AI ecosystem across its lifecycle.
It addresses unique AI security challenges such as prompt injection, data poisoning, and sensitive data leakage, by providing deep visibility and control across AI models, data, and applications.
The platform offers AI Model Scanning for vulnerabilities, Posture Management for secure configurations, and AI Red Teaming for proactive testing.
Critically, Runtime Security prevents threats during live AI model execution, while AI Agent Security extends protection to autonomous AI agents.
CDR is the latest addition to Cortex XSIAM and XDR that addresses the growing need for security teams to respond to cloud threats with purpose-built SOC tools that seamlessly integrate with their security programs.
During fiscal 2025, we introduced several new offerings, including: Prisma Access Browser, new capabilities in our OT Security solution, Cortex Cloud, Prisma AIRS, and Cortex XSIAM 3.0.
For example, in August 2024, we completed the acquisition of certain QRadar assets from International Business Machines Corporation (“IBM”), which we expect will help accelerate the growth of our Cortex business.
Additionally, in July 2025, we completed the acquisition of Protect AI, Inc., a privately-held cyber security company (“Protect AI”), which we expect will enhance the capabilities of our AI security platform.
In July 2025, we also entered into a definitive agreement to acquire CyberArk Software Ltd. (“CyberArk”), an identity security company, which acquisition is expected to close during the second half of our fiscal 2026.
We believe that a comprehensive suite of customer success offerings is critical to the successful deployment, adoption, and ongoing use of our products.
To support this, we have invested in hiring and developing technical experts with deep domain knowledge and proven experience across our portfolio.
Our products and services have been recognized as leading in 25 categories by third-party industry analysts firms that perform independent assessments of these categories.
This recognition by third parties is an important measure of validation for our customers.
We also focus on integrating AI into people programs and processes to build a more agile, skilled and forward-thinking workforce prepared for the future of cybersecurity.
Attract & Hire. At Palo Alto Networks, we source talent with the necessary skills and capabilities to contribute to our culture and mission.
We utilize structured interviewing practices, thorough job analyses and success profiles to identify high-quality candidates and staff critical roles.
In fiscal 2025, we began to transform our hiring operations by strategically embedding AI across the talent acquisition lifecycle to sharpen our competitive edge for talent.
We are deploying intelligent tools to automate and enhance core processes, including AI-generated job descriptions, structured interview guides and preparation materials; intelligent interview scheduling; launching an automated talent sourcing and screening pilot; and using AI to augment feedback summaries.
Recognizing that technical skills evolve rapidly in an AI-driven world, our recruitment strategy prioritizes durable, "AI-readiness" capabilities.
We assess candidates for core competencies such as critical thinking, adaptability and a capacity for continuous learning to help ensure every hire can not only excel today but also innovate and lead in the future.
We also encourage employee referrals.
In fiscal 2025, we started to evolve from a traditional training program to a system of AI-powered talent enablement, where we integrate learning and growth throughout the flow of an employee’s daily work.
From day 1, new hires embark on a journey that blends in-person connection with personalized digital guidance, including generative AI onboarding roadmaps and AI-curated mentor networks.
For ongoing growth, through The Learning Center, our intelligent learning platform, we deliver adaptive learning tracks for employees, including specialized paths for interns, new graduates and individuals joining through acquisitions.
We also piloted real-time AI-enabled feedback simulations to coach and equip managers with the skills to guide their teams more effectively.
Development information about core business elements, required company-wide compliance training and information about activities on topics ranging from well-being to collaboration are also offered.
To further support our employees to advance up the AI adoption curve, we have offered self-paced online certifications, live training and an experimentation challenge that encouraged peer-driven use cases and employees voting to select the finalists.
We will continue our enablement journey, using employee questions and feedback to offer both practical and role-specific use cases to help increase productivity and new skill acquisition.
On average, employees completed 36 hours of development during fiscal 2025.
Our chief executive officer has also earned a 91% employee approval rating on Glassdoor, a top percentile score.
Advance Environmental Sustainability. Palo Alto Networks is doing our part to limit global warming to less than 1.5°C.
An excerpt. Shown here: 40 of 96 rewritten, 40 of 139 added and 40 of 42 removed. The counts are complete. For every sentence, read Item 1. Business in the FY2026 filing and the FY2025 filing.
Cover and table of contents
37 rewritten, 6 added, 4 removed, 88 unchanged
For the fiscal year ended July 31, [removed: 2025][added: 2026]
(Address of principal executive [removed: offices, including zip code)][added: offices) (Zip Code)]
The aggregate market value of voting stock held by non-affiliates of the registrant was approximately [removed: $119.7] [added: $123.4] billion as of January 31, [removed: 2025,] [added: 2026,] the last business day of the registrant’s most recently completed second fiscal quarter (based on the closing sales price for the common stock on the Nasdaq Global Select Market on such date).
On August [removed: 18, 2025, 668.9] [added: 31, 2026, 818] million shares of the registrant’s common stock, $0.0001 par value, were outstanding.
Portions of the information called for by Part III of this Annual Report on Form 10-K is hereby incorporated by reference from the definitive proxy statement for the registrant’s [removed: 2025] [added: 2026] annual meeting of stockholders, which will be filed with the Securities and Exchange Commission not later than 120 days after the registrant’s fiscal year ended July 31, [removed: 2025.][added: 2026.]
| Item 1. | | | [removed: [Business](#i7c6d02d19ae642d183bd6885f5b5223e_13)] [added: [Business](#i9de53d23105c4f5abc3ad801ca7a41c7_13)] | | | [removed: [4](#i7c6d02d19ae642d183bd6885f5b5223e_13)] [added: [4](#i9de53d23105c4f5abc3ad801ca7a41c7_13)] | | |
| Item 1A. | | | [Risk [removed: Factors](#i7c6d02d19ae642d183bd6885f5b5223e_46)] [added: Factors](#i9de53d23105c4f5abc3ad801ca7a41c7_49)] | | | [removed: [14](#i7c6d02d19ae642d183bd6885f5b5223e_46)] [added: [17](#i9de53d23105c4f5abc3ad801ca7a41c7_49)] | | |
| Item 1B. | | | [Unresolved Staff [removed: Comments](#i7c6d02d19ae642d183bd6885f5b5223e_82)] [added: Comments](#i9de53d23105c4f5abc3ad801ca7a41c7_82)] | | | [removed: [37](#i7c6d02d19ae642d183bd6885f5b5223e_82)] [added: [37](#i9de53d23105c4f5abc3ad801ca7a41c7_82)] | | |
| Item 1C. | | | [removed: [Cybersecurity](#i7c6d02d19ae642d183bd6885f5b5223e_85)] [added: [Cybersecurity](#i9de53d23105c4f5abc3ad801ca7a41c7_85)] | | | [removed: [37](#i7c6d02d19ae642d183bd6885f5b5223e_85)] [added: [37](#i9de53d23105c4f5abc3ad801ca7a41c7_85)] | | |
| Item 2. | | | [removed: [Properties](#i7c6d02d19ae642d183bd6885f5b5223e_88)] [added: [Properties](#i9de53d23105c4f5abc3ad801ca7a41c7_88)] | | | [removed: [39](#i7c6d02d19ae642d183bd6885f5b5223e_88)] [added: [39](#i9de53d23105c4f5abc3ad801ca7a41c7_88)] | | |
| Item 3. | | | [Legal [removed: Proceedings](#i7c6d02d19ae642d183bd6885f5b5223e_91)] [added: Proceedings](#i9de53d23105c4f5abc3ad801ca7a41c7_91)] | | | [removed: [39](#i7c6d02d19ae642d183bd6885f5b5223e_91)] [added: [39](#i9de53d23105c4f5abc3ad801ca7a41c7_91)] | | |
| Item 4. | | | [Mine Safety [removed: Disclosures](#i7c6d02d19ae642d183bd6885f5b5223e_94)] [added: Disclosures](#i9de53d23105c4f5abc3ad801ca7a41c7_94)] | | | [removed: [39](#i7c6d02d19ae642d183bd6885f5b5223e_94)] [added: [39](#i9de53d23105c4f5abc3ad801ca7a41c7_94)] | | |
| Item 5. | | | [Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity [removed: Securities](#i7c6d02d19ae642d183bd6885f5b5223e_100)] [added: Securities](#i9de53d23105c4f5abc3ad801ca7a41c7_100)] | | | [removed: [40](#i7c6d02d19ae642d183bd6885f5b5223e_100)] [added: [40](#i9de53d23105c4f5abc3ad801ca7a41c7_100)] | | |
| Item 7. | | | [Management’s Discussion and Analysis of Financial Condition and Results of [removed: Operations](#i7c6d02d19ae642d183bd6885f5b5223e_109)] [added: Operations](#i9de53d23105c4f5abc3ad801ca7a41c7_106)] | | | [removed: [42](#i7c6d02d19ae642d183bd6885f5b5223e_109)] [added: [42](#i9de53d23105c4f5abc3ad801ca7a41c7_106)] | | |
| Item 7A. | | | [Quantitative and Qualitative Disclosures About Market [removed: Risk](#i7c6d02d19ae642d183bd6885f5b5223e_187)] [added: Risk](#i9de53d23105c4f5abc3ad801ca7a41c7_187)] | | | [removed: [56](#i7c6d02d19ae642d183bd6885f5b5223e_187)] [added: [57](#i9de53d23105c4f5abc3ad801ca7a41c7_187)] | | |
| Item 8. | | | [Financial Statements and Supplementary [removed: Data](#i7c6d02d19ae642d183bd6885f5b5223e_190)] [added: Data](#i9de53d23105c4f5abc3ad801ca7a41c7_190)] | | | [removed: [57](#i7c6d02d19ae642d183bd6885f5b5223e_190)] [added: [58](#i9de53d23105c4f5abc3ad801ca7a41c7_190)] | | |
| Item 9. | | | [Changes in and Disagreements with Accountants on Accounting and Financial [removed: Disclosure](#i7c6d02d19ae642d183bd6885f5b5223e_322)] [added: Disclosure](#i9de53d23105c4f5abc3ad801ca7a41c7_310)] | | | [removed: [95](#i7c6d02d19ae642d183bd6885f5b5223e_322)] [added: [104](#i9de53d23105c4f5abc3ad801ca7a41c7_310)] | | |
| Item 9A. | | | [Controls and [removed: Procedures](#i7c6d02d19ae642d183bd6885f5b5223e_325)] [added: Procedures](#i9de53d23105c4f5abc3ad801ca7a41c7_313)] | | | [removed: [95](#i7c6d02d19ae642d183bd6885f5b5223e_325)] [added: [104](#i9de53d23105c4f5abc3ad801ca7a41c7_313)] | | |
| Item 9B. | | | [Other [removed: Information](#i7c6d02d19ae642d183bd6885f5b5223e_328)] [added: Information](#i9de53d23105c4f5abc3ad801ca7a41c7_316)] | | | [removed: [96](#i7c6d02d19ae642d183bd6885f5b5223e_328)] [added: [105](#i9de53d23105c4f5abc3ad801ca7a41c7_316)] | | |
| Item 9C. | | | [Disclosure Regarding Foreign Jurisdictions That Prevent [removed: Inspections](#i7c6d02d19ae642d183bd6885f5b5223e_331)] [added: Inspections](#i9de53d23105c4f5abc3ad801ca7a41c7_322)] | | | [removed: [96](#i7c6d02d19ae642d183bd6885f5b5223e_331)] [added: [105](#i9de53d23105c4f5abc3ad801ca7a41c7_322)] | | |
| Item 10. | | | [Directors, Executive Officers and Corporate [removed: Governance](#i7c6d02d19ae642d183bd6885f5b5223e_337)] [added: Governance](#i9de53d23105c4f5abc3ad801ca7a41c7_328)] | | | [removed: [97](#i7c6d02d19ae642d183bd6885f5b5223e_337)] [added: [106](#i9de53d23105c4f5abc3ad801ca7a41c7_328)] | | |
| Item 11. | | | [Executive [removed: Compensation](#i7c6d02d19ae642d183bd6885f5b5223e_340)] [added: Compensation](#i9de53d23105c4f5abc3ad801ca7a41c7_331)] | | | [removed: [97](#i7c6d02d19ae642d183bd6885f5b5223e_340)] [added: [106](#i9de53d23105c4f5abc3ad801ca7a41c7_331)] | | |
| Item 12. | | | [Security Ownership of Certain Beneficial Owners and Management and Related Stockholder [removed: Matters](#i7c6d02d19ae642d183bd6885f5b5223e_343)] [added: Matters](#i9de53d23105c4f5abc3ad801ca7a41c7_334)] | | | [removed: [97](#i7c6d02d19ae642d183bd6885f5b5223e_343)] [added: [106](#i9de53d23105c4f5abc3ad801ca7a41c7_334)] | | |
| Item 13. | | | [Certain Relationships and Related Transactions, and Director [removed: Independence](#i7c6d02d19ae642d183bd6885f5b5223e_346)] [added: Independence](#i9de53d23105c4f5abc3ad801ca7a41c7_337)] | | | [removed: [97](#i7c6d02d19ae642d183bd6885f5b5223e_346)] [added: [106](#i9de53d23105c4f5abc3ad801ca7a41c7_337)] | | |
| Item 14. | | | [Principal Accountant Fees and [removed: Services](#i7c6d02d19ae642d183bd6885f5b5223e_349)] [added: Services](#i9de53d23105c4f5abc3ad801ca7a41c7_340)] | | | [removed: [97](#i7c6d02d19ae642d183bd6885f5b5223e_349)] [added: [106](#i9de53d23105c4f5abc3ad801ca7a41c7_340)] | | |
| Item 15. | | | [Exhibits and Financial Statement [removed: Schedules](#i7c6d02d19ae642d183bd6885f5b5223e_355)] [added: Schedules](#i9de53d23105c4f5abc3ad801ca7a41c7_346)] | | | [removed: [98](#i7c6d02d19ae642d183bd6885f5b5223e_355)] [added: [107](#i9de53d23105c4f5abc3ad801ca7a41c7_346)] | | |
| Item 16. | | | [Form 10-K [removed: Summary](#i7c6d02d19ae642d183bd6885f5b5223e_358)] [added: Summary](#i9de53d23105c4f5abc3ad801ca7a41c7_349)] | | | [removed: [101](#i7c6d02d19ae642d183bd6885f5b5223e_358)] [added: [111](#i9de53d23105c4f5abc3ad801ca7a41c7_349)] | | |
This Annual Report on Form 10-K, including, without limitation, the sections entitled “Business,” “Risk Factors,” and “Management’s Discussion and Analysis of Financial Condition and Results of Operations,” contains forward-looking statements within the meaning of Section 27A of the Securities Act of [removed: 1933] [added: 1933, as amended,] and Section 21E of the Securities Exchange Act of [removed: 1934.][added: 1934, as amended.]
- expectations regarding the cybersecurity [removed: landscape;][added: landscape and demand;]
- expectations regarding our platformization strategy and related progress and [removed: opportunities;][added: opportunities, our product development strategy, and drivers of and factors affecting growth in our business;]
- expectations regarding annual recurring [removed: revenue,] [added: revenue and] remaining performance [removed: obligations, and product development strategy;][added: obligations;]
- statements regarding expected profitability, [added: new revenues,] trends in annual recurring revenue, trends in remaining performance obligations, our mix of product and subscription and support revenue, cost of revenue, gross margin, cash flows, operating expenses, including future share-based compensation expense, income taxes, investment plans, and liquidity;
- expected recurring revenues resulting from growth in our end-customers and increased adoption of our [removed: products] [added: products, subscriptions] and [removed: cloud-delivered security solutions;][added: services;]
- our ability to successfully acquire and integrate companies and assets and expectations and intentions with respect to the assets, products and technologies that we [removed: acquire, including with respect to our proposed acquisition of CyberArk Software Ltd. and our expectations regarding the benefits and synergies of the proposed acquisition;][added: acquire;]
- the effects of worldwide economic and geopolitical conditions, [removed: including] [added: including,] but not limited [removed: to] [added: to,] hostilities in Israel and the surrounding regions, inflation, tariff rates, interest rate levels, public or administration policies, trade regulations, trade policy, growth rates and other conditions, on our operating and financial results and performance;
- [added: expectations regarding] the manufacture, delivery and cost of certain of our products;
- the effects of litigation or regulatory developments involving us or affecting our industry; [removed: and]
| Item 6. | | | [\[Reserved\]](#i9de53d23105c4f5abc3ad801ca7a41c7_103) | | | [41](#i9de53d23105c4f5abc3ad801ca7a41c7_103) | | |
| | | | [Signatures](#i9de53d23105c4f5abc3ad801ca7a41c7_352) | | | [112](#i9de53d23105c4f5abc3ad801ca7a41c7_352) | | |
- expectations regarding the benefits and synergies from our acquisition and integration of companies, assets, and technologies, including our acquisition of CyberArk Software Ltd.;
- expectations regarding the change in fair value of our convertible senior notes and capped call transactions and its impact on us and our financial results;
- statements regarding our competition, including the expanded scope of our competitors as a result of entering into new product and service categories;
- our debt repayment obligations; and
| Item 6. | | | [\[Reserved\]](#i7c6d02d19ae642d183bd6885f5b5223e_106) | | | [41](#i7c6d02d19ae642d183bd6885f5b5223e_106) | | |
| | | | [Signatures](#i7c6d02d19ae642d183bd6885f5b5223e_361) | | | [102](#i7c6d02d19ae642d183bd6885f5b5223e_361) | | |
- expectations regarding drivers of and factors affecting growth in our business;
- our ability to complete, on a timely basis, or at all, announced transactions, including our proposed acquisition of CyberArk Software Ltd.;
Item 1C. Cybersecurity
17 rewritten, 6 added, 2 removed, 23 unchanged
We have established processes and procedures for identifying, evaluating, and responding to risks from cybersecurity threats, including any potential unauthorized access to our information systems that may result in adverse effects on the confidentiality, integrity, or availability of our information [removed: systems, data,] [added: systems] or [removed: information assets.][added: information.]
- Information Security. We maintain a written information security program, which provides for policies, standards, guidelines, and administrative, technical and physical safeguards that we believe are reasonably designed, in light of the nature, size and complexity of our operations, to protect the resiliency of our operations and the confidentiality, integrity, and availability of our information [removed: systems, data,] [added: systems] and [removed: information assets.][added: information.]
The organizational, administrative and technical measures we implement are [removed: based on] [added: guided by] recognized security frameworks established by the National Institute of Standards and Technology, [removed: security measures aligned with] the ISO/IEC 27000 series of standards, and other generally recognized industry standards.
- Technical Safeguards and Product Security. We deploy and maintain a variety of technologies to [removed: prevent and] detect [added: and manage] cybersecurity threats across the network, endpoint and [removed: cloud.][added: cloud, as well as leverage Unit 42 to assess our internal security posture.]
We also apply security-by-design principles in our software development lifecycle, track vulnerabilities of open-source software, and run [added: regular] internal and external network [removed: scans at least weekly and after any meaningful change in our network configuration.][added: scans.]
This allows for prompt direction of appropriate personnel and resources for incident management and response, and internal notification to appropriate members of management, which may include our chief executive officer, chief product and technology officer, [removed: vice president acting as] chief information security officer, general counsel, chief financial officer, and/or chief accounting officer, and the security committee of our board of directors (the “Security Committee”).
- Third-Party Risk Management. We maintain a risk-based approach to identifying and overseeing cybersecurity risks presented by certain third parties, including vendors, service providers, suppliers, operations parties, and other external users of our systems, as well as the systems of third parties that [removed: could adversely impact] [added: are important to] our [removed: business in the event of a cybersecurity incident affecting those third-party systems.][added: operations and/or process sensitive information on our behalf.]
This includes a security process to conduct due diligence prior to engaging contractors and vendors and assess the security capabilities of subcontractors and vendors on a periodic [removed: basis.][added: basis based on our assessment of each third party’s operational criticality and risk profile.]
These efforts include, but are not limited to, threat modeling, vulnerability scans, penetration testing, audits, [removed: and] [added: and/or] tabletop exercises.
- Governance. As discussed in more detail below under the heading, “Cybersecurity Governance,” our board of [removed: directors’] [added: directors] has delegated oversight of enterprise security risk management, including, but not limited to, cybersecurity risk management to the Security Committee.
For additional information regarding these risks, please refer to Part I, Item 1A, “Risk Factors,” in this Form 10-K, including, but not limited to, the risk factor entitled “*A [added: significant] network or data security incident may [removed: allow unauthorized access to our network or data, harm our reputation, create additional liability, and adversely] [added: materially] impact our [added: reputation,] financial [added: condition, and operating] results.*”
The Security [removed: Committee] [added: Committee, including our chief information security officer,] reports regularly to the Board following meetings of the Security Committee with respect to its review and assessment of security matters and other matters that are relevant to the Security Committee’s discharge of its responsibilities.
The Security Committee meets quarterly to review with our [removed: vice president acting as] chief information security officer and other members of management, which may include our chief executive officer, chief product and technology officer, chief financial officer, and general counsel, our cybersecurity programs, cybersecurity risks, mitigation or remediation strategies, and other matters impacting the committee’s responsibilities.
Management is responsible for day-to-day risk management activities, [removed: including] [added: with our chief information security officer being primarily responsible for] identifying, assessing and managing our exposure to cybersecurity risks, establishing processes and procedures [removed: to ensure] [added: so] that potential cybersecurity risk exposures are monitored, implementing appropriate mitigation or remediation measures as needed, and maintaining cybersecurity risk management programs.
Our [removed: vice president acting as] chief information security officer is [added: also] responsible for defining, overseeing, managing, implementing, and reviewing compliance with the information security programs described above under the heading “Cybersecurity Risk Management and Strategy.” [removed: This vice president] [added: Our chief information security officer] receives regular reports from our information security team and monitors the prevention, detection, and mitigation or remediation of cybersecurity [removed: risks.][added: risks, and works closely to keep the management team apprised of key risks, treats, and incidents.]
In particular, our [removed: vice president acting as] chief information security officer has extensive experience in the management of cybersecurity risk management programs, having served in various roles in information technology and security for over 25 years.
In addition, [removed: six] [added: seven] of the [removed: eleven] [added: ten] members of our board of directors have expertise in overseeing cybersecurity and information security management.
Additionally, we utilize Unit 42 to support our response to threats.
In addition, we maintain a security program designed to protect the security and integrity of our hardware products and data throughout the product design, development, manufacturing, delivery, and service and repair processes, which includes consideration of applicable supply chain risk management standards.
Employees are also trained on the responsible use of AI and on the secure use of AI through regular trainings.
We also deliver experiential training, including by periodically conducting simulated phishing exercises to test employee awareness and compliance with our security policies.
As a global cybersecurity provider, we recognize that we may be a particularly attractive target for sophisticated threat actors.
Despite our efforts, we cannot eliminate all risks from cybersecurity threats or provide assurances that we have not experienced an undetected cybersecurity incident.
The protocols also establish steps designed to publicly report and/or alert external stakeholders as and when required by applicable law or otherwise determined appropriate.
Our information security compliance training, data protection training, and code of conduct training is mandatory for all employees.
Item 2. Properties
2 rewritten, 0 added, 0 removed, 7 unchanged
Our corporate headquarters is located in Santa Clara, California, where we lease approximately 941,000 square feet of space under three lease agreements that expire in July [removed: 2028,] [added: 2040,] with options to extend the lease terms through July [removed: 2046.][added: 2052.]
Additionally, we own [removed: 10.4] [added: 24.9] acres of land adjacent to our headquarters in Santa Clara, California, which we intend to develop to accommodate future [removed: expansion, the speed of which development has been slowed due to the current environment.][added: expansion.]
Item 5. Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities
10 rewritten, 5 added, 9 removed, 16 unchanged
As of August [removed: 18, 2025,] [added: 31, 2026,] there were [removed: 565] [added: 585] holders of record of our common stock.
In February 2019, [removed: we announced that] our board of directors authorized a $1.0 billion share repurchase program, which is funded from available working capital.
[removed: We] [added: Our board of directors] subsequently [removed: announced] [added: authorized] additional increases to this share repurchase program, bringing the total authorization to [removed: $4.1] [added: $5.1] billion, with $1.0 billion remaining as of July 31, [removed: 2025.][added: 2026.]
The expiration date of this repurchase authorization was extended to December 31, [removed: 2025,] [added: 2026,] and our repurchase program may be suspended or discontinued at any time.
Repurchases under our program are to be made at management’s discretion [added: from time to time] on the open market, through privately negotiated transactions, transactions structured through investment banking institutions, block purchase techniques, 10b5-1 trading plans, or a combination of the foregoing.
During the three months ended July 31, [removed: 2025,] [added: 2026,] we did not repurchase any shares pursuant to our share repurchase program.
This performance graph compares the cumulative total return on our common stock with that of the Nasdaq 100 Index, the Standard & Poor’s 500 [removed: Index,] [added: Index (“S&P 500 Index),] and the Standard & Poor’s 500 Information Technology Index [added: (“S&P 500 Information Technology Index”)] for the five years ended July 31, [removed: 2025.][added: 2026.]
This performance graph assumes $100 was invested on July 31, [removed: 2020,] [added: 2021,] in each of the common stock of Palo Alto Networks, Inc., the Nasdaq 100 Index, the [removed: Standard & Poor’s] [added: S&P] 500 Index, and the [removed: Standard & Poor’s] [added: S&P] 500 Information Technology Index, and assumes the reinvestment of any dividends.
[removed: ][added: ]
| Company/Index | | | | | | [removed: 7/31/2020] [added: 7/31/2021] | | | | | | [removed: 7/31/2021] [added: 7/31/2022] | | | | | | [removed: 7/31/2022] [added: 7/31/2023] | | | | | | [removed: 7/31/2023] [added: 7/31/2024] | | | | | | [removed: 7/31/2024] [added: 7/31/2025] | | | | | | [removed: 7/31/2025] [added: 7/31/2026] | | |
None.
| Palo Alto Networks, Inc. | | | | | | $ | 100.00 | | | | | $ | 125.07 | | | | | $ | 187.92 | | | | | $ | 244.13 | | | | | $ | 261.02 | | | | | $ | 498.93 | |
| Nasdaq 100 Index | | | | | | $ | 100.00 | | | | | $ | 87.20 | | | | | $ | 107.06 | | | | | $ | 132.67 | | | | | $ | 160.30 | | | | | $ | 196.50 | |
| S&P 500 Index | | | | | | $ | 100.00 | | | | | $ | 95.36 | | | | | $ | 107.77 | | | | | $ | 131.64 | | | | | $ | 153.14 | | | | | $ | 183.10 | |
| S&P 500 Information Technology Index | | | | | | $ | 100.00 | | | | | $ | 94.49 | | | | | $ | 119.86 | | | | | $ | 162.04 | | | | | $ | 200.37 | | | | | $ | 252.91 | |
Securities Authorized for Issuance under Equity Compensation Plans
See Part III, Item 12 “Security Ownership of Certain Beneficial Owners and Management and Related Stockholder Matters” of this Annual Report on Form 10-K for more information regarding securities authorized for issuance.
During the three months ended July 31, 2025, holders of the 2025 Notes converted $382.9 million in aggregate principal amount of the 2025 Notes, which we repaid in cash.
We also issued 5.6 million shares of our unregistered common stock to the holders of the 2025 Notes for the conversion value in excess of the principal amount.
These shares of our common stock were issued in reliance on the exemption from registration provided by Section 3(a)(9) of the Securities Act of 1933, as amended (the “Securities Act”).
| Palo Alto Networks, Inc. | | | | | | $ | 100.00 | | | | | $ | 155.93 | | | | | $ | 195.02 | | | | | $ | 293.01 | | | | | $ | 380.66 | | | | | $ | 407.00 | |
| Nasdaq 100 Index | | | | | | $ | 100.00 | | | | | $ | 138.19 | | | | | $ | 120.50 | | | | | $ | 147.94 | | | | | $ | 183.34 | | | | | $ | 221.52 | |
| S&P 500 Index | | | | | | $ | 100.00 | | | | | $ | 136.45 | | | | | $ | 130.11 | | | | | $ | 147.05 | | | | | $ | 179.62 | | | | | $ | 208.95 | |
| S&P 500 Information Technology Index | | | | | | $ | 100.00 | | | | | $ | 140.03 | | | | | $ | 132.31 | | | | | $ | 167.84 | | | | | $ | 226.91 | | | | | $ | 280.58 | |
Item 8. Financial Statements and Supplementary Data
468 rewritten, 487 added, 181 removed, 855 unchanged
| [Reports of Independent Registered Public Accounting [removed: Firm](#i7c6d02d19ae642d183bd6885f5b5223e_193)] [added: Firm](#i9de53d23105c4f5abc3ad801ca7a41c7_193)] (PCAOB ID: 42) | | | [removed: [58](#i7c6d02d19ae642d183bd6885f5b5223e_193)] [added: [59](#i9de53d23105c4f5abc3ad801ca7a41c7_193)] | | |
| [Consolidated Balance [removed: Sheets](#i7c6d02d19ae642d183bd6885f5b5223e_199)] [added: Sheets](#i9de53d23105c4f5abc3ad801ca7a41c7_199)] | | | [removed: [61](#i7c6d02d19ae642d183bd6885f5b5223e_199)] [added: [62](#i9de53d23105c4f5abc3ad801ca7a41c7_199)] | | |
| [Consolidated Statements of [removed: Operations](#i7c6d02d19ae642d183bd6885f5b5223e_202)] [added: Operations](#i9de53d23105c4f5abc3ad801ca7a41c7_202)] | | | [removed: [62](#i7c6d02d19ae642d183bd6885f5b5223e_202)] [added: [63](#i9de53d23105c4f5abc3ad801ca7a41c7_202)] | | |
| [Consolidated Statements of Comprehensive [removed: Income](#i7c6d02d19ae642d183bd6885f5b5223e_205)] [added: Income](#i9de53d23105c4f5abc3ad801ca7a41c7_205)] | | | [removed: [63](#i7c6d02d19ae642d183bd6885f5b5223e_205)] [added: [64](#i9de53d23105c4f5abc3ad801ca7a41c7_205)] | | |
| [Consolidated Statements of Stockholders’ [removed: Equity](#i7c6d02d19ae642d183bd6885f5b5223e_217)] [added: Equity](#i9de53d23105c4f5abc3ad801ca7a41c7_214)] | | | [removed: [64](#i7c6d02d19ae642d183bd6885f5b5223e_217)] [added: [65](#i9de53d23105c4f5abc3ad801ca7a41c7_214)] | | |
| [Consolidated Statements of Cash [removed: Flows](#i7c6d02d19ae642d183bd6885f5b5223e_220)] [added: Flows](#i9de53d23105c4f5abc3ad801ca7a41c7_217)] | | | [removed: [65](#i7c6d02d19ae642d183bd6885f5b5223e_220)] [added: [66](#i9de53d23105c4f5abc3ad801ca7a41c7_217)] | | |
| [Notes to Consolidated Financial [removed: Statements](#i7c6d02d19ae642d183bd6885f5b5223e_223)] [added: Statements](#i9de53d23105c4f5abc3ad801ca7a41c7_220)] | | | [removed: [66](#i7c6d02d19ae642d183bd6885f5b5223e_223)] [added: [67](#i9de53d23105c4f5abc3ad801ca7a41c7_220)] | | |
We have audited the accompanying consolidated balance sheets of Palo Alto Networks, Inc. (the Company) as of July 31, [removed: 2025] [added: 2026] and [removed: 2024,] [added: 2025,] the related consolidated statements of operations, comprehensive income, stockholders’ equity and cash flows for each of the three years in the period ended July 31, [removed: 2025,] [added: 2026,] and the related notes (collectively referred to as the “consolidated financial statements”).
In our opinion, the consolidated financial statements present fairly, in all material respects, the financial position of the Company at July 31, [removed: 2025] [added: 2026] and [removed: 2024,] [added: 2025,] and the results of its operations and its cash flows for each of the three years in the period ended July 31, [removed: 2025,] [added: 2026,] in conformity with U.S. generally accepted accounting principles.
We also have audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the Company’s internal control over financial reporting as of July 31, [removed: 2025,] [added: 2026,] based on criteria established in Internal Control—Integrated Framework issued by the Committee of Sponsoring Organizations of the Treadway Commission (2013 framework), and our report dated [removed: August 29, 2025] [added: September 10, 2026] expressed an unqualified opinion thereon.
Critical Audit [removed: Matter][added: Matters]
| *How We Addressed* *the Matter in Our Audit* | | | We obtained an understanding, evaluated the [removed: design] [added: design,] and tested the operating effectiveness of the Company’s process and controls [removed: to estimate fair value of] [added: for] the [removed: contingent consideration liability. We also tested controls regarding management’s review] [added: valuation] of [removed: assumptions used in] [added: acquired intangible assets, including controls over] the [removed: valuation model.] [added: significant assumption described above.] To test the estimated fair value of [removed: this contingent consideration liability, our] [added: the platform renewals intangible assets, we performed] audit procedures [added: that] included, among others, assessing the valuation [removed: methodology with the assistance of a valuation specialist,] [added: methodology,] and testing the significant assumption [removed: about customer transactions that will qualify for cash payments under the arrangement] [added: discussed above] and the completeness and accuracy of the underlying data used by the Company. We [removed: also performed a] [added: compared the significant assumption used by the Company to current and historical industry, market and economic information and trends where relevant. We assessed] sensitivity [removed: analysis] [added: analyses of the significant assumption] to evaluate the changes in the fair value of [removed: this contingent consideration liability that would result] [added: the platform renewals intangible assets resulting] from changes in the [removed: significant] assumption. We [removed: also considered whether] [added: involved our valuation professionals to assist in evaluating] the [removed: assumption was consistent with evidence obtained] [added: valuation methodology used] in [removed: other areas] [added: the determination] of the [removed: audit.] [added: fair value estimate.] | | |
We have audited Palo Alto Networks, Inc.’s internal control over financial reporting as of July 31, [removed: 2025,] [added: 2026,] based on criteria established in Internal Control—Integrated Framework issued by the Committee of Sponsoring Organizations of the Treadway Commission (2013 framework) (the COSO criteria).
In our opinion, Palo Alto Networks, Inc. (the Company) maintained, in all material respects, effective internal control over financial reporting as of July 31, [removed: 2025,] [added: 2026,] based on the COSO criteria.
We also have audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the consolidated balance sheets of the Company as of July 31, [removed: 2025] [added: 2026] and [removed: 2024,] [added: 2025,] the related consolidated statements of operations, comprehensive income, stockholders’ equity and cash flows for each of the three years in the period ended July 31, [removed: 2025,] [added: 2026,] and the related notes and our report dated [removed: August 29, 2025] [added: September 10, 2026] expressed an unqualified opinion thereon.
| | | | [added: | | | | | | | | | | | | | | | | | | | | | | | |] 2025 | | | | | | [added: | | | | | | | | | | | |] 2024 | | | [added: | | | | | |]
| Cash and cash equivalents | | | [removed: $ | 2,268.6 | | | | | $] [added: 17] | [removed: 1,535.2] | |
| Short-term investments | | | [removed: 634.6] [added: 557] | | | | | | [removed: 1,043.6] [added: 635] | | |
| Accounts receivable, net of allowance for credit losses of [removed: $9.7] [added: $4] and [removed: $7.5] [added: $10] as of July 31, [removed: 2025] [added: 2026] and July 31, [removed: 2024,] [added: 2025,] respectively | | | [removed: 2,965.0] [added: 3,629] | | | | | | [removed: 2,618.6] [added: 2,965] | | |
| Short-term financing receivables, net | | | [removed: 714.6] [added: 592] | | | | | | [removed: 725.9] [added: 715] | | |
| Short-term deferred contract costs | | | [removed: 419.5] [added: 544] | | | | | | [removed: 369.0] [added: 419] | | |
| [removed: Prepaid] [added: Total prepaid] expenses and other current assets | | | [removed: 520.5] | | | [added: —] | | | [removed: 557.4] | | | [added: 18 | | | | | | — | | | | | | 18 | | | | | | — | | | | | | 58 | | | | | | — | | | | | | 58 | | |]
| Total current assets | | | [removed: 7,522.8] [added: 8,643] | | | | | | [removed: 6,849.7] [added: 7,523] | | |
| Property and equipment, net | | | [removed: 387.3] [added: 523] | | | | | | [removed: 361.1] [added: 387] | | |
| [removed: Operating] [added: Reduction of operating] lease right-of-use assets | | | [removed: 347.0] [added: 75] | | | | | | [removed: 385.9] [added: 65] | | | [added: | | | 56 | | |]
| Long-term investments | | | [removed: 5,555.6] [added: 4,835] | | | | | | [removed: 4,173.2] [added: 5,555] | | |
| Long-term financing receivables, net | | | [removed: 1,002.3] [added: 944] | | | | | | [removed: 1,182.1] [added: 1,002] | | |
| Long-term deferred contract costs | | | [removed: 585.9] [added: 667] | | | | | | [removed: 562.0] [added: 586] | | |
| Intangible assets, net | | | [removed: 762.7] [added: 7,017] | | | | | | [removed: 374.9] [added: 763] | | |
| Deferred tax assets | | | [removed: 2,424.2] [added: 2,443] | | | | | | [removed: 2,399.0] [added: 2,424] | | |
| Accounts payable | | | [removed: $] [added: 43] | [removed: 232.2] | | | | | [removed: $] [added: 107] | [removed: 116.3] | | [added: | | | (15) | | |]
| Accrued compensation | | | [removed: 607.6] [added: 327] | | | | | | [removed: 554.7] [added: 51] | | | [added: | | | 4 | | |]
| Accrued and other liabilities | | | [removed: 846.0] [added: 838] | | | | | | [removed: 506.7] [added: 846] | | |
| Deferred revenue | | | [removed: 6,302.2 | | | | | | 5,541.1] [added: (776)] | | |
| Convertible senior [removed: notes, net] [added: notes] | | | — | | | | | | [removed: 963.9] [added: 7] | | | [added: | | | 21 | | |]
| Total current liabilities | | | [removed: 7,988.0] [added: 9,923] | | | | | | [removed: 7,682.7] [added: 7,988] | | |
| Long-term deferred revenue | | | [removed: 6,449.7] [added: 7,009] | | | | | | [removed: 5,939.4] [added: 6,450] | | |
| Deferred tax liabilities | | | [removed: 89.1] [added: 251] | | | | | | [removed: 387.7] [added: 89] | | |
| Long-term operating lease liabilities | | | [removed: 338.2 | | | | | | 380.5] [added: $] | [added: 726] | |
| Other long-term liabilities | | | [removed: 886.8] [added: 1,285] | | | | | | [removed: 430.9] [added: 887] | | |
ACQUISITION OF CYBERARK SOFTWARE LTD. (“CYBERARK”) - VALUATION OF PLATFORM RENEWALS
| *Description* *of the Matter* | | | As disclosed in Notes 1 and 8 to the consolidated financial statements, on February 11, 2026, the Company completed the acquisition of CyberArk for total purchase consideration of $21.1 billion. The Company accounted for the acquisition as a business combination. In connection with this acquisition, the Company recognized platform renewals intangible assets of $3.5 billion. Auditing the Company’s valuation of the acquired platform renewals intangible assets was complex due to the significant judgment and estimation in determining the fair value of the platform renewals. Specifically, the fair value estimate for the acquired platform renewals intangible assets is sensitive to changes in the Company’s assumption related to forecasted revenue attributable to platform renewals. This significant assumption is forward-looking and could be affected by future economic and market conditions. | | |
September 10, 2026
As indicated in the accompanying Management's Annual Report on Internal Control over Financial Reporting, management’s assessment of and conclusion on the effectiveness of internal control over financial reporting did not include the internal controls of CyberArk, which is included in the 2026 consolidated financial statements of the Company and constituted 2% and less than 1% of total consolidated assets and total consolidated net assets, respectively, as of July 31, 2026 and 6% of total consolidated revenue, for the year then ended.
Our audit of internal control over financial reporting of the Company also did not include an evaluation of the internal control over financial reporting of CyberArk.
September 10, 2026
| | | | 2026 | | | | | | 2025 | | |
| Cash and cash equivalents | | | $ | 2,514 | | | | | $ | 2,269 | |
| Goodwill | | | 22,010 | | | | | | 4,567 | | |
| Other assets | | | 678 | | | | | | 422 | | |
| Total assets | | | $ | 48,460 | | | | | $ | 23,576 | |
| Accounts payable | | | $ | 290 | | | | | $ | 232 | |
| Accrued compensation | | | 1,048 | | | | | | 608 | | |
| Deferred revenue | | | 7,747 | | | | | | 6,302 | | |
| Long-term convertible senior notes | | | 1,774 | | | | | | — | | |
| Total liabilities | | | 20,968 | | | | | | 15,752 | | |
| Retained earnings | | | 2,791 | | | | | | 2,484 | | |
| Product | | | $ | 2,280 | | | | | $ | 1,802 | | | | | $ | 1,603 | |
| Subscription and support | | | 9,200 | | | | | | 7,419 | | | | | | 6,424 | | |
| Total revenue | | | 11,480 | | | | | | 9,221 | | | | | | 8,027 | | |
| Product | | | 568 | | | | | | 413 | | | | | | 348 | | |
| Subscription and support | | | 2,835 | | | | | | 2,038 | | | | | | 1,711 | | |
| Total cost of revenue | | | 3,403 | | | | | | 2,451 | | | | | | 2,059 | | |
| Total gross profit | | | 8,077 | | | | | | 6,770 | | | | | | 5,968 | | |
| Research and development | | | 2,552 | | | | | | 1,984 | | | | | | 1,810 | | |
| Sales and marketing | | | 3,931 | | | | | | 3,100 | | | | | | 2,794 | | |
| General and administrative | | | 899 | | | | | | 443 | | | | | | 680 | | |
| Total operating expenses | | | 7,382 | | | | | | 5,527 | | | | | | 5,284 | | |
| Operating income | | | 695 | | | | | | 1,243 | | | | | | 684 | | |
| Other income (expense), net | | | (159) | | | | | | 353 | | | | | | 304 | | |
| Income before income taxes | | | 536 | | | | | | 1,596 | | | | | | 988 | | |
| Net income | | | $ | 307 | | | | | $ | 1,134 | | | | | $ | 2,578 | |
| Net income | | | $ | 307 | | | | | $ | 1,134 | | | | | $ | 2,578 | |
| Change in fair value of convertible senior notes attributable to instrument-specific credit risk | | | (11) | | | | | | — | | | | | | — | | |
| Comprehensive income | | | $ | 188 | | | | | $ | 1,184 | | | | | $ | 2,619 | |
| Balance as of July 31, 2023 | | | 617 | | | | | | $ | 3,019 | | | | | $ | (43) | | | | | $ | (1,228) | | | | | $ | 1,748 | |
| Reclassification of deferred compensation liability to (from) equity | | | — | | | | | | (5) | | | | | | — | | | | | | — | | | | | | (5) | | |
| Replacement awards related to business acquisitions | | | 1 | | | | | | 27 | | | | | | — | | | | | | — | | | | | | 27 | | |
| Balance as of July 31, 2024 | | | 650 | | | | | | 3,821 | | | | | | (2) | | | | | | 1,350 | | | | | | 5,169 | | |
| Reclassification of deferred compensation liability to (from) equity | | | — | | | | | | (32) | | | | | | — | | | | | | — | | | | | | (32) | | |
\- 57 \-
VALUATION OF CONTINGENT CONSIDERATION LIABILITY IN CONNECTION WITH THE ACQUISITION OF IBM QRADAR ASSETS
| *Description* *of the Matter* | | | As described in Note 8 to the consolidated financial statements, the Company completed the acquisition of certain IBM QRadar assets on August 31, 2024, for which the purchase consideration included contingent consideration. The Company has determined the fair value of contingent consideration liability to be $513.6 million as of July 31, 2025, using a discounted cash flow valuation technique including an estimate of future cash payments related to customers entering into qualified new transactions with the Company as well as a risk-adjusted discount rate used to present value the expected cash flows. Auditing the Company’s accounting for contingent consideration liability was complex due to estimation uncertainty in the Company’s determination of the fair value due to the significant assumption about customer transactions that will qualify for cash payments under the arrangement. The significant assumption is forward-looking, dependent upon customer behavior, and could be affected by various factors including future economic and market conditions. | | |
August 29, 2025
| Goodwill | | | 4,566.6 | | | | | | 3,350.1 | | |
| Other assets | | | 421.8 | | | | | | 352.9 | | |
| Total assets | | | $ | 23,576.2 | | | | | $ | 19,990.9 | |
| Total liabilities | | | 15,751.8 | | | | | | 14,821.2 | | |
| Retained earnings | | | 2,484.1 | | | | | | 1,350.2 | | |
| Product | | | $ | 1,801.9 | | | | | $ | 1,603.3 | | | | | $ | 1,578.4 | |
| Subscription and support | | | 7,419.6 | | | | | | 6,424.2 | | | | | | 5,314.3 | | |
| Total revenue | | | 9,221.5 | | | | | | 8,027.5 | | | | | | 6,892.7 | | |
| Product | | | 413.2 | | | | | | 348.2 | | | | | | 418.3 | | |
| Subscription and support | | | 2,038.4 | | | | | | 1,711.0 | | | | | | 1,491.4 | | |
| Total cost of revenue | | | 2,451.6 | | | | | | 2,059.2 | | | | | | 1,909.7 | | |
| Total gross profit | | | 6,769.9 | | | | | | 5,968.3 | | | | | | 4,983.0 | | |
| Total operating expenses | | | 5,527.0 | | | | | | 5,284.4 | | | | | | 4,595.7 | | |
| Operating income | | | 1,242.9 | | | | | | 683.9 | | | | | | 387.3 | | |
| Income before income taxes | | | 1,595.7 | | | | | | 988.3 | | | | | | 566.3 | | |
| Net income | | | $ | 1,133.9 | | | | | $ | 2,577.6 | | | | | $ | 439.7 | |
| Comprehensive income | | | $ | 1,183.9 | | | | | $ | 2,619.2 | | | | | $ | 452.1 | |
| Balance as of July 31, 2022 | | | 597.7 | | | | | | $ | 1,932.7 | | | | | $ | (55.6) | | | | | $ | (1,667.1) | | | | | $ | 210.0 | |
| Balance as of July 31, 2023 | | | 616.7 | | | | | | 3,019.0 | | | | | | (43.2) | | | | | | (1,227.4) | | | | | | 1,748.4 | | |
| Balance as of July 31, 2024 | | | 650.2 | | | | | | 3,821.1 | | | | | | (1.6) | | | | | | 1,350.2 | | | | | | 5,169.7 | | |
| Other comprehensive income | | | — | | | | | | — | | | | | | 50.0 | | | | | | — | | | | | | 50.0 | | |
| Settlement of convertible notes | | | 14.0 | | | | | | — | | | | | | — | | | | | | — | | | | | | — | | |
| Balance as of July 31, 2025 | | | 667.9 | | | | | | $ | 5,291.9 | | | | | $ | 48.4 | | | | | $ | 2,484.1 | | | | | $ | 7,824.4 | |
| Deferred income taxes | | | (349.9) | | | | | | (2,033.7) | | | | | | 12.5 | | |
| Depreciation and amortization | | | 343.4 | | | | | | 283.3 | | | | | | 282.2 | | |
| Accounts receivable, net | | | (345.3) | | | | | | (154.3) | | | | | | (320.3) | | |
| Financing receivables, net | | | 191.1 | | | | | | (865.9) | | | | | | (738.7) | | |
| Deferred contract costs | | | (555.0) | | | | | | (489.3) | | | | | | (431.9) | | |
| Accounts payable | | | 106.8 | | | | | | (15.0) | | | | | | 1.0 | | |
| Accrued compensation | | | 51.3 | | | | | | 3.8 | | | | | | 84.4 | | |
| Deferred revenue | | | 1,238.1 | | | | | | 2,180.6 | | | | | | 2,301.7 | | |
| Purchases of investments | | | (3,695.9) | | | | | | (3,551.3) | | | | | | (5,460.4) | | |
| Repayments of convertible senior notes | | | (965.6) | | | | | | (1,033.7) | | | | | | (1,692.0) | | |
As of July 31, 2025, three distributors individually represented 10% or more of our gross accounts receivable, and in the aggregate represented 44.8% of our gross accounts receivable.
*Segment Reporting*
In November 2023, the Financial Accounting Standards Board (“FASB”) issued authoritative guidance that expands annual and interim disclosure requirements for reportable segments, primarily through enhanced disclosures about significant segment expenses.
An excerpt. Shown here: 40 of 468 rewritten, 40 of 487 added and 40 of 181 removed. The counts are complete. For every sentence, read Item 8. Financial Statements and Supplementary Data in the FY2026 filing and the FY2025 filing.
Item 9A. Controls and Procedures
7 rewritten, 4 added, 1 removed, 5 unchanged
Our management, with the participation of our chief executive officer and chief financial officer, evaluated the effectiveness of our disclosure controls and procedures pursuant to Rule [removed: 13a-15(f)] [added: 13a-15(b)] under the Securities Exchange Act of 1934, as amended (the “Exchange Act”).
Based on our evaluation, our chief executive officer and chief financial officer concluded that, as of July 31, [removed: 2025,] [added: 2026,] our disclosure controls and procedures are designed at a reasonable assurance level and are effective to provide reasonable assurance that information we are required to disclose in reports that we file or submit under the Exchange Act is recorded, processed, summarized, and reported within the time periods specified in Securities and Exchange Commission (“SEC”) rules and forms, and that such information is accumulated and communicated to our management, including our chief executive officer and chief financial officer, as appropriate, to allow timely decisions regarding required disclosure.
Our management is responsible for establishing and maintaining adequate internal control over financial reporting as defined in [removed: Rules] [added: Rule] 13a-15(f) under the Exchange Act.
Our management assessed the effectiveness of our internal control over financial reporting as of July 31, [removed: 2025,] [added: 2026,] based on the framework set forth by the Committee of Sponsoring Organizations of the Treadway Commission (“COSO”) in Internal Control - Integrated Framework (2013 framework).
Based on that assessment, management concluded that, as of July 31, [removed: 2025,] [added: 2026,] our internal control over financial reporting was effective.
The effectiveness of our internal control over financial reporting as of July 31, [removed: 2025] [added: 2026] has been audited by Ernst & Young LLP, the independent registered public accounting firm that audits our consolidated financial statements, as stated in their [added: attestation] report which is included in Part II, Item 8 of this Annual Report on Form 10-K.
There were no changes in our internal control over financial reporting identified in connection with the evaluation required by Rule 13a-15(d) [removed: and 15d-15(d) of] [added: under] the Exchange Act that occurred during the fiscal quarter ended July 31, [removed: 2025] [added: 2026] that have materially affected, or are reasonably likely to materially affect, our internal control over financial reporting.
In accordance with guidance issued by the SEC staff, companies are permitted to exclude acquisitions from their assessment of internal control over financial reporting for the first fiscal year in which the acquisition occurred.
Our assessment of the effectiveness of our internal control over financial reporting as of July 31, 2026 excluded CyberArk, which we acquired on February 11, 2026.
We have included the financial results of CyberArk in our consolidated financial statements since the date of acquisition, which constituted 2% of total consolidated assets, less than 1% of total consolidated net assets, and 6% of total consolidated revenue as of and for the year ended July 31, 2026.
\- 104 \-
\- 95 \-
Item 9B. Other Information
3 rewritten, 2 added, 1 removed, 7 unchanged
Set forth below is certain information regarding Rule 10b5-1 trading plans [removed: adopted] [added: adopted, modified] or terminated by our directors and officers (as defined in Rule 16a-1(f)) during the fourth quarter of fiscal [removed: 2025.][added: 2026.]
| Name | | | | | | Title | | | | | | [removed: Date Plan Was Adopted] [added: Action] | | | | | | Date [removed: Plan Was Terminated] [added: of Action] | | | | | | [removed: Original Expiration] [added: Expiration] Date | | | | | | Total Amount of Common Stock to Be Sold Under the Plan | | |
No other officers or directors, as defined in Rule 16a-1(f), adopted, modified, and/or terminated a “Rule 10b5-1 trading arrangement” or a “non-Rule 10b5-1 trading arrangement,” as defined in Regulation S-K Item 408, during the fourth quarter of fiscal [removed: 2025.][added: 2026.]
| Dipak Golechha | | | | | | Chief Financial Officer | | | | | | Modified | | | | | | June 25, 2026 | | | | | | September 30, 2027 | | | | | | 50,000 or, if earlier, when all shares have been sold | | |
| William D. Jenkins Jr. | | | | | | President | | | | | | Adopted | | | | | | June 28, 2026 | | | | | | January 31, 2027 | | | | | | 148,217 or, if earlier, when all shares have been sold | | |
| Nikesh Arora | | | | | | Chief Executive Officer | | | | | | June 24, 2025 | | | | | | Not applicable | | | | | | December 24, 2025 or when all shares have been sold | | | | | | 846,408 | | |
Item 9C. Disclosure Regarding Foreign Jurisdictions That Prevent Inspections
0 rewritten, 1 added, 1 removed, 2 unchanged
\- 105 \-
\- 96 \-
Item 10. Directors, Executive Officers and Corporate Governance
1 rewritten, 2 added, 0 removed, 0 unchanged
The information required by this item will be contained in our definitive proxy statement to be filed with the SEC in connection with our [removed: 2025] [added: 2026] annual meeting of stockholders (the “Proxy Statement”), which is expected to be filed not later than 120 days after the end of our fiscal year ended July 31, [removed: 2025] [added: 2026] and is incorporated herein by reference.
Our Board has adopted a Code of Business Conduct and Ethics that applies to all our employees, officers and directors, including our Chief Executive Officer, Chief Financial Officer, and other executive and senior financial officers.
We will post amendments to our Code of Business Conduct and Ethics or waivers of our Code of Business Conduct and Ethics for directors and executive officers on the same website.
Item 14. Principal Accountant Fees and Services
0 rewritten, 1 added, 1 removed, 2 unchanged
\- 106 \-
\- 97 \-
Item 15. Exhibits and Financial Statement Schedules
55 rewritten, 30 added, 5 removed, 107 unchanged
| [removed: [2.1](https://www.sec.gov/Archives/edgar/data/0001327567/000119312525169870/d804159dex21.htm)*] [added: [2.1](https://www.sec.gov/Archives/edgar/data/0001327567/000119312525169870/d804159dex21.htm)^] | | | | | | Agreement and Plan of Merger, dated as of July 30, 2025, by and among Palo Alto Networks, Inc., Athens Strategies Ltd. and CyberArk Software Ltd. | | | | | | 8-K | | | | | | 001-35594 | | | | | | 2.1 | | | | | | July 31, 2025 | | | | | | | | |
| [3.1](https://www.sec.gov/Archives/edgar/data/1327567/000132756725000027/panwex31restatedcertificat.htm) | | | | | | Restated Certificate of Incorporation of the Registrant, as amended. | | | | | | [added: 10-K] | | | | | | [added: 001-35594] | | | | | | [added: 3.1] | | | | | | [added: August 29, 2025] | | | | | | | | |
| [removed: [3.2](https://www.sec.gov/Archives/edgar/data/1327567/000132756725000024/ex31amendedandrestatedbyla.htm)] [added: [3.2](https://www.sec.gov/Archives/edgar/data/0001327567/000119312526361122/d180372dex31.htm)] | | | | | | Amended and Restated Bylaws of the Registrant. | | | | | | 8-K | | | | | | 001-35594 | | | | | | 3.1 | | | | | | August [removed: 18, 2025] [added: 21, 2026] | | | | | | | | |
| [removed: [4.](https://www.sec.gov/Archives/edgar/data/1327567/000132756725000027/panwex41descriptionofregis.htm)[1](https://www.sec.gov/Archives/edgar/data/1327567/000132756725000027/panwex41descriptionofregis.htm)] [added: [4.1](https://www.sec.gov/Archives/edgar/data/1327567/000132756725000027/panwex41descriptionofregis.htm)] | | | | | | Description of Registrant’s Securities. | | | | | | [added: 10-K] | | | | | | [added: 001-35594] | | | | | | [added: 4.1] | | | | | | [added: August 29, 2025] | | | | | | | | |
| [removed: [10.4](https://www.sec.gov/Archives/edgar/data/1327567/000132756725000027/panwex1042021equityincenti.htm)*] [added: [10.4](https://www.sec.gov/Archives/edgar/data/1327567/000119312525315915/d15273dex101.htm)*] | | | | | | 2021 Equity Incentive Plan, as amended and [removed: restated, and related form agreements.] [added: restated.] | | | | | | [added: 8-K] | | | | | | [added: 001-35594] | | | | | | [added: 10.1] | | | | | | [added: December 11, 2025] | | | | | | | | |
| [removed: [10](https://www.sec.gov/Archives/edgar/data/1327567/000132756725000027/panwex1052012employeestock.htm)[.5](https://www.sec.gov/Archives/edgar/data/1327567/000132756725000027/panwex1052012employeestock.htm)*] [added: [10.](https://www.sec.gov/Archives/edgar/data/1327567/000132756726000023/panwex106-2012espp.htm)[6](https://www.sec.gov/Archives/edgar/data/1327567/000132756726000023/panwex106-2012espp.htm)*^] | | | | | | 2012 Employee Stock Purchase Plan, as amended and restated, and related form agreements. | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| [removed: [10](https://www.sec.gov/Archives/edgar/data/1327567/000119312518303084/d634580dex991.htm)[.6](https://www.sec.gov/Archives/edgar/data/1327567/000119312518303084/d634580dex991.htm)*] [added: [10.](https://www.sec.gov/Archives/edgar/data/1327567/000119312518303084/d634580dex991.htm)[7](https://www.sec.gov/Archives/edgar/data/1327567/000119312518303084/d634580dex991.htm)*] | | | | | | RedLock Inc. 2015 Stock Plan, as amended, and related form agreements under RedLock Inc. 2015 Stock Plan, as amended. | | | | | | S-8 | | | | | | 333-227901 | | | | | | 99.1 | | | | | | October 19, 2018 | | | | | | | | |
| [removed: [10.7](https://www.sec.gov/Archives/edgar/data/1327567/000119312522310112/d424580dex991.htm)*] [added: [10.](https://www.sec.gov/Archives/edgar/data/1327567/000119312522310112/d424580dex991.htm)[8](https://www.sec.gov/Archives/edgar/data/1327567/000119312522310112/d424580dex991.htm)*] | | | | | | Cider Security Ltd. 2020 Equity Incentive Plan. | | | | | | S-8 | | | | | | 333-268931 | | | | | | 99.1 | | | | | | December 21, 2022 | | | | | | | | |
| [removed: [10.8](https://www.sec.gov/Archives/edgar/data/1327567/000119312522310112/d424580dex992.htm)*] [added: [10.9](https://www.sec.gov/Archives/edgar/data/1327567/000119312522310112/d424580dex992.htm)*] | | | | | | US Sub-Plan to Cider Security Ltd. 2020 Equity Incentive Plan. | | | | | | S-8 | | | | | | 333-268931 | | | | | | 99.2 | | | | | | December 21, 2022 | | | | | | | | |
| [removed: [10.9](https://www.sec.gov/Archives/edgar/data/1327567/000132756714000043/panwex102q115.htm)*] [added: [10.1](https://www.sec.gov/Archives/edgar/data/1327567/000132756714000043/panwex102q115.htm)[2](https://www.sec.gov/Archives/edgar/data/1327567/000132756714000043/panwex102q115.htm)*] | | | | | | Employee Incentive Compensation Plan, as amended and restated. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.2 | | | | | | November 25, 2014 | | | | | | | | |
| [removed: [10.10](https://www.sec.gov/Archives/edgar/data/1327567/000132756724000029/panwex1016amendedclawbackp.htm)] [added: [10.1](https://www.sec.gov/Archives/edgar/data/1327567/000132756724000029/panwex1016amendedclawbackp.htm)[3](https://www.sec.gov/Archives/edgar/data/1327567/000132756724000029/panwex1016amendedclawbackp.htm)] | | | | | | Clawback Policy, adopted as of August 29, 2017, amended August 14, 2024. | | | | | | 10-K | | | | | | 001-35594 | | | | | | 10.16 | | | | | | September 6, 2024 | | | | | | | | |
| [removed: [10.11](https://www.sec.gov/Archives/edgar/data/1327567/000132756725000017/panwex101q325.htm)*] [added: [10.1](https://www.sec.gov/Archives/edgar/data/1327567/000132756725000017/panwex101q325.htm)[4](https://www.sec.gov/Archives/edgar/data/1327567/000132756725000017/panwex101q325.htm)*] | | | | | | Amended and Restated Outside Director Compensation Policy (last amended February 12, 2025). | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.1 | | | | | | May 21, 2025 | | | | | | | | |
| [removed: [10.12](https://www.sec.gov/Archives/edgar/data/1327567/000132756722000016/panw-ex103q322.htm)*] [added: [10.1](https://www.sec.gov/Archives/edgar/data/1327567/000132756722000016/panw-ex103q322.htm)[5](https://www.sec.gov/Archives/edgar/data/1327567/000132756722000016/panw-ex103q322.htm)*] | | | | | | Continued Service Policy. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.3 | | | | | | May 20, 2022 | | | | | | | | |
| [removed: [10.13](https://www.sec.gov/Archives/edgar/data/1327567/000132756722000028/panwex1023q422deferredcomp.htm)*] [added: [10.1](https://www.sec.gov/Archives/edgar/data/1327567/000132756722000028/panwex1023q422deferredcomp.htm)[6](https://www.sec.gov/Archives/edgar/data/1327567/000132756722000028/panwex1023q422deferredcomp.htm)*] | | | | | | Palo Alto Networks, Inc. Deferred Compensation Plan effective June 1, 2022. | | | | | | 10-K | | | | | | 001-35594 | | | | | | 10.23 | | | | | | September 6, 2022 | | | | | | | | |
| [removed: [10.14](https://www.sec.gov/Archives/edgar/data/1327567/000132756725000027/panwex1014nirzukamendmentl.htm)*] [added: [10.1](https://www.sec.gov/Archives/edgar/data/1327567/000132756725000027/panwex1014nirzukamendmentl.htm)[7](https://www.sec.gov/Archives/edgar/data/1327567/000132756725000027/panwex1014nirzukamendmentl.htm)*] | | | | | | Amendment and Restated Employment Letter between Palo Alto Networks, Inc. and Nir Zuk, dated July 7, 2025. | | | | | | [added: 10-K] | | | | | | [added: 001-35594] | | | | | | [added: 10.14] | | | | | | [added: August 29, 2025] | | | | | | | | |
| [removed: [10.15](https://www.sec.gov/Archives/edgar/data/1327567/000132756718000011/ex102offerletternarora.htm)*] [added: [10.1](https://www.sec.gov/Archives/edgar/data/1327567/000132756718000011/ex102offerletternarora.htm)[8](https://www.sec.gov/Archives/edgar/data/1327567/000132756718000011/ex102offerletternarora.htm)*] | | | | | | Offer Letter between the Registrant and Nikesh Arora, dated May 30, 2018. | | | | | | 8-K | | | | | | 001-35594 | | | | | | 10.2 | | | | | | June 4, 2018 | | | | | | | | |
| [removed: [10.16](https://www.sec.gov/Archives/edgar/data/1327567/000119312521267862/d200133dex101.htm)*] [added: [10.1](https://www.sec.gov/Archives/edgar/data/1327567/000119312521267862/d200133dex101.htm)[9](https://www.sec.gov/Archives/edgar/data/1327567/000119312521267862/d200133dex101.htm)*] | | | | | | Offer Letter between the Registrant and Josh Paul, dated August 5, 2021. | | | | | | 8-K | | | | | | 001-35594 | | | | | | 10.1 | | | | | | September 8, 2021 | | | | | | | | |
| [removed: [10.17](https://www.sec.gov/Archives/edgar/data/1327567/000132756718000031/panwex104q119.htm)*] [added: [10.20](https://www.sec.gov/Archives/edgar/data/1327567/000132756718000031/panwex104q119.htm)*] | | | | | | Confirmatory Employment Letter with Updated Change in Control Protection between the Registrant and Lee Klarich, dated December 19, 2011. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.4 | | | | | | November 30, 2018 | | | | | | | | |
| [removed: [10.18](https://www.sec.gov/Archives/edgar/data/0001327567/000119312521087516/d160663dex101.htm)*] [added: [10.2](https://www.sec.gov/Archives/edgar/data/0001327567/000119312521087516/d160663dex101.htm)[1](https://www.sec.gov/Archives/edgar/data/0001327567/000119312521087516/d160663dex101.htm)*] | | | | | | Addendum to Employment Offer Letter by and between the Registrant and Dipak Golechha, dated March 17, 2021. | | | | | | 8-K | | | | | | 001-35594 | | | | | | 10.1 | | | | | | March 19, 2021 | | | | | | | | |
| [removed: [10.19](https://www.sec.gov/Archives/edgar/data/1327567/000132756722000016/panw-ex101q322.htm)*] [added: [10.22](https://www.sec.gov/Archives/edgar/data/1327567/000132756722000016/panw-ex101q322.htm)*] | | | | | | Addendum to Employment Offer Letter by and between the Registrant and Dipak Golechha, dated February 18, 2022. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.1 | | | | | | May 20, 2022 | | | | | | | | |
| [removed: [10.20](https://www.sec.gov/Archives/edgar/data/1327567/000119312521244832/d204334dex101.htm)*] [added: [10.2](https://www.sec.gov/Archives/edgar/data/1327567/000119312521244832/d204334dex101.htm)[3](https://www.sec.gov/Archives/edgar/data/1327567/000119312521244832/d204334dex101.htm)*] | | | | | | Employment Offer Letter by and between the Registrant and William “BJ” Jenkins, dated July 27, 2021. | | | | | | 8-K | | | | | | 001-35594 | | | | | | 10.1 | | | | | | August 12, 2021 | | | | | | | | |
| [removed: [10.21](https://www.sec.gov/Archives/edgar/data/1327567/000132756722000016/panw-ex102q322.htm)*] [added: [10.2](https://www.sec.gov/Archives/edgar/data/1327567/000132756722000016/panw-ex102q322.htm)[4](https://www.sec.gov/Archives/edgar/data/1327567/000132756722000016/panw-ex102q322.htm)*] | | | | | | Addendum to Employment Offer Letter between the Registrant and William “BJ” Jenkins, dated February 18, 2022. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.2 | | | | | | May 20, 2022 | | | | | | | | |
| [removed: [10.22](https://www.sec.gov/Archives/edgar/data/1327567/000132756725000017/panwex102q325.htm)*] [added: [10.25](https://www.sec.gov/Archives/edgar/data/1327567/000132756725000017/panwex102q325.htm)*] | | | | | | Form of Offer Letter between the Registrant and its directors. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.2 | | | | | | May 21, 2025 | | | | | | | | |
| [removed: [10.23](https://www.sec.gov/Archives/edgar/data/1327567/000132756719000016/panwex101q319.htm)] [added: [10.2](https://www.sec.gov/Archives/edgar/data/1327567/000132756719000016/panwex101q319.htm)[6](https://www.sec.gov/Archives/edgar/data/1327567/000132756719000016/panwex101q319.htm)] | | | | | | Amended and Restated Flextronics Manufacturing Services Agreement, by and between the Registrant and Flextronics Telecom Systems Ltd., dated April 1, 2019. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.1 | | | | | | May 30, 2019 | | | | | | | | |
| [removed: [10.24](https://www.sec.gov/Archives/edgar/data/1327567/000132756721000029/panwex1029q421supplieragre.htm)] [added: [10.2](https://www.sec.gov/Archives/edgar/data/1327567/000132756721000029/panwex1029q421supplieragre.htm)[7](https://www.sec.gov/Archives/edgar/data/1327567/000132756721000029/panwex1029q421supplieragre.htm)] | | | | | | Vendor Information Security Terms between the Registrant and Flextronics Telecom Systems Ltd., dated July 23, 2021. | | | | | | 10-K | | | | | | 001-35594 | | | | | | 10.29 | | | | | | September 3, 2021 | | | | | | | | |
| [removed: [10.25](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000027/panwex1029q415buildinge.htm)] [added: [10.28](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000027/panwex1029q415buildinge.htm)] | | | | | | Lease between the Registrant and Santa Clara Campus Property Owner I LLC, dated May 28, 2015. | | | | | | 10-K | | | | | | 001-35594 | | | | | | 10.29 | | | | | | September 17, 2015 | | | | | | | | |
| [removed: [10.26](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000027/panwex1030q415buidlingf.htm)] [added: [10.29](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000027/panwex1030q415buidlingf.htm)] | | | | | | Lease between the Registrant and Santa Clara Campus Property Owner I LLC, dated May 28, 2015. | | | | | | 10-K | | | | | | 001-35594 | | | | | | 10.30 | | | | | | September 17, 2015 | | | | | | | | |
| [removed: [10.27](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000027/panwex1031q415buildingb.htm)] [added: [10.](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000027/panwex1031q415buildingb.htm)[30](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000027/panwex1031q415buildingb.htm)] | | | | | | Lease between the Registrant and Santa Clara Campus Property Owner I LLC, dated May 28, 2015. | | | | | | 10-K | | | | | | 001-35594 | | | | | | 10.31 | | | | | | September 17, 2015 | | | | | | | | |
| [removed: [10.28](https://www.sec.gov/Archives/edgar/data/1327567/000119312515347005/d59912dex101.htm)] [added: [10.3](https://www.sec.gov/Archives/edgar/data/1327567/000119312515347005/d59912dex101.htm)[1](https://www.sec.gov/Archives/edgar/data/1327567/000119312515347005/d59912dex101.htm)] | | | | | | Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated October 7, 2015. | | | | | | 8-K/A | | | | | | 001-35594 | | | | | | 10.1 | | | | | | October 19, 2015 | | | | | | | | |
| [removed: [10.29](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000036/amendmentno1topaloaltonetw.htm)] [added: [10.3](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000036/amendmentno1topaloaltonetw.htm)[2](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000036/amendmentno1topaloaltonetw.htm)] | | | | | | Amendment No. 1 to Lease by and between the Registrant and Santa Clara Phase I Property LLC, dated November 9, 2015. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.2 | | | | | | November 24, 2015 | | | | | | | | |
| [removed: [10.30](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000036/amendmenno1topaloaltonetwo.htm)] [added: [10.3](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000036/amendmenno1topaloaltonetwo.htm)[3](https://www.sec.gov/Archives/edgar/data/1327567/000132756715000036/amendmenno1topaloaltonetwo.htm)] | | | | | | Amendment No. 1 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated November 9, 2015. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.3 | | | | | | November 24, 2015 | | | | | | | | |
| [removed: [10.31](https://www.sec.gov/Archives/edgar/data/1327567/000132756716000073/panwex101q117_amendmentno1.htm)] [added: [10.3](https://www.sec.gov/Archives/edgar/data/1327567/000132756716000073/panwex101q117_amendmentno1.htm)[4](https://www.sec.gov/Archives/edgar/data/1327567/000132756716000073/panwex101q117_amendmentno1.htm)] | | | | | | Amendment No. 1 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated September 16, 2016. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.1 | | | | | | November 22, 2016 | | | | | | | | |
| [removed: [10.32](https://www.sec.gov/Archives/edgar/data/1327567/000132756716000073/panwex102q117_amendmentno1.htm)] [added: [10.3](https://www.sec.gov/Archives/edgar/data/1327567/000132756716000073/panwex102q117_amendmentno1.htm)[5](https://www.sec.gov/Archives/edgar/data/1327567/000132756716000073/panwex102q117_amendmentno1.htm)] | | | | | | Amendment No. 1 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated September 16, 2016. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.2 | | | | | | November 22, 2016 | | | | | | | | |
| [removed: [10.33](https://www.sec.gov/Archives/edgar/data/1327567/000132756716000073/panwex103q117_amendmentno2.htm)] [added: [10.3](https://www.sec.gov/Archives/edgar/data/1327567/000132756716000073/panwex103q117_amendmentno2.htm)[6](https://www.sec.gov/Archives/edgar/data/1327567/000132756716000073/panwex103q117_amendmentno2.htm)] | | | | | | Amendment No. 2 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated September 16, 2016. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.3 | | | | | | November 22, 2016 | | | | | | | | |
| [removed: [10.34](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000007/panwex101q217_amendmentno2.htm)] [added: [10.3](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000007/panwex101q217_amendmentno2.htm)[7](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000007/panwex101q217_amendmentno2.htm)] | | | | | | Amendment No. 2 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated November 16, 2016. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.1 | | | | | | March 1, 2017 | | | | | | | | |
| [removed: [10.35](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000007/panwex102q217_amendmentno2.htm)] [added: [10.38](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000007/panwex102q217_amendmentno2.htm)] | | | | | | Amendment No. 2 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated November 16, 2016. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.2 | | | | | | March 1, 2017 | | | | | | | | |
| [removed: [10.36](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000007/panwex103q217_amendmentno3.htm)] [added: [10.3](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000007/panwex103q217_amendmentno3.htm)[9](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000007/panwex103q217_amendmentno3.htm)] | | | | | | Amendment No. 3 to Lease by and between the Registrant and Santa Clara Campus Property Owner I LLC, dated November 16, 2016. | | | | | | 10-Q | | | | | | 001-35594 | | | | | | 10.3 | | | | | | March 1, 2017 | | | | | | | | |
| [removed: [10.37](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000027/panwex1040q417_amendmentno.htm)] [added: [10.](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000027/panwex1040q417_amendmentno.htm)[40](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000027/panwex1040q417_amendmentno.htm)] | | | | | | Amendment No. 3 to Lease by and between the Registrant and Santa Clara EFH LLC, dated June 22, 2017. | | | | | | 10-K | | | | | | 001-35594 | | | | | | 10.40 | | | | | | September 7, 2017 | | | | | | | | |
| [removed: [10.38](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000027/panwex1041q417_amendmentno.htm)] [added: [10.41](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000027/panwex1041q417_amendmentno.htm)] | | | | | | Amendment No. 3 to Lease by and between the Registrant and Santa Clara G LLC, dated June 22, 2017. | | | | | | 10-K | | | | | | 001-35594 | | | | | | 10.41 | | | | | | September 7, 2017 | | | | | | | | |
| [removed: [10.39](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000027/panwex1042q417_amendmentno.htm)] [added: [10.4](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000027/panwex1042q417_amendmentno.htm)[2](https://www.sec.gov/Archives/edgar/data/1327567/000132756717000027/panwex1042q417_amendmentno.htm)] | | | | | | Amendment No. 4 to Lease by and between the Registrant and Santa Clara EFH LLC, dated June 22, 2017. | | | | | | 10-K | | | | | | 001-35594 | | | | | | 10.42 | | | | | | September 7, 2017 | | | | | | | | |
| [4.2](https://www.sec.gov/Archives/edgar/data/1327567/000119312526045600/d40626dex41.htm) | | | | | | Indenture, dated June 10, 2025, by and between CyberArk Software Ltd. and U.S. Bank Trust Company, National Association. | | | | | | 8-K | | | | | | 001-35594 | | | | | | 4.1 | | | | | | February 11, 2026 | | | | | | | | |
| [4.3](https://www.sec.gov/Archives/edgar/data/1327567/000119312526045600/d40626dex42.htm) | | | | | | First Supplemental Indenture, dated as of February 11, 2026, by and among Palo Alto Networks, Inc., CyberArk Software Ltd. and U.S. Bank Trust Company, National Association. | | | | | | 8-K | | | | | | 001-35594 | | | | | | 4.2 | | | | | | February 11, 2026 | | | | | | | | |
| [4.4](https://www.sec.gov/Archives/edgar/data/1327567/000119312526045600/d40626dex41.htm) | | | | | | Form of Global 0.00% Convertible Senior Note due 2030 (contained in Exhibit 4.2 hereto). | | | | | | 8-K | | | | | | 001-35594 | | | | | | 4.3 | | | | | | February 11, 2026 | | | | | | | | |
| [4.5](https://www.sec.gov/Archives/edgar/data/1327567/000132756726000023/panwex45formofamendedandre.htm) | | | | | | Form of Amended and Restated Confirmation of Capped Call Transaction. | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
\- 107 \-
| [10.5](https://www.sec.gov/Archives/edgar/data/1327567/000132756726000023/panwex105-formoptionandrsu.htm)*^ | | | | | | Form Award Agreements under the 2021 Equity Incentive plan, as amended and restated. | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| [1](https://www.sec.gov/Archives/edgar/data/1327567/000119312526045627/d19556dex44.htm)[0.](https://www.sec.gov/Archives/edgar/data/1327567/000119312526045627/d19556dex44.htm)[10](https://www.sec.gov/Archives/edgar/data/1327567/000119312526045627/d19556dex44.htm)* | | | | | | CyberArk Software Ltd. 2024 Share Incentive Plan, as amended. | | | | | | S-8 POS | | | | | | 333-290235 | | | | | | 4.4 | | | | | | February 11, 2026 | | | | | | | | |
| [1](https://www.sec.gov/Archives/edgar/data/1327567/000119312526045627/d19556dex45.htm)[0.1](https://www.sec.gov/Archives/edgar/data/1327567/000119312526045627/d19556dex45.htm)[1](https://www.sec.gov/Archives/edgar/data/1327567/000119312526045627/d19556dex45.htm)* | | | | | | CyberArk Software Ltd. 2014 Share Incentive Plan, as amended. | | | | | | S-8 POS | | | | | | 333-290235 | | | | | | 4.5 | | | | | | February 11, 2026 | | | | | | | | |
\- 108 \-
\- 109 \-
| [10.4](https://www.sec.gov/Archives/edgar/data/1327567/000119312526151637/d49517dex101.htm)[6](https://www.sec.gov/Archives/edgar/data/1327567/000119312526151637/d49517dex101.htm) | | | | | | Amendment No. 5 to Lease by and between the Company and Santa Clara Phase III EFH, LLC, dated April 8, 2026. | | | | | | 8-K | | | | | | 001-35594 | | | | | | 10.1 | | | | | | April 13, 2026 | | | | | | | | |
| [10.47](https://www.sec.gov/Archives/edgar/data/1327567/000119312526151637/d49517dex102.htm) | | | | | | Amendment No. 5 to Lease by and between the Company and Santa Clara Phase III G, LLC, dated April 8, 2026. | | | | | | 8-K | | | | | | 001-35594 | | | | | | 10.2 | | | | | | April 13, 2026 | | | | | | | | |
| [10.48](https://www.sec.gov/Archives/edgar/data/1327567/000119312526151637/d49517dex103.htm) | | | | | | Amendment No. 6 to Lease by and between the Company and Santa Clara Phase III EFH, LLC, dated April 8, 2026. | | | | | | 8-K | | | | | | 001-35594 | | | | | | 10.3 | | | | | | April 13, 2026 | | | | | | | | |
| [10.51](https://www.sec.gov/Archives/edgar/data/1327567/000119312526361122/d180372dex101.htm)*^ | | | | | | Executive Change in Control and Severance Policy. | | | | | | 8-K | | | | | | 001-35594 | | | | | | 10.1 | | | | | | August 21, 2026 | | | | | | | | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
\- 110 \-
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| Exhibit Number | | | | | | Exhibit Description | | | | | | Incorporated by Reference | | | | | | | | | | | | | | | | | | | | | | | | | | |
| Form | | | | | | File No. | | | | | | Exhibit | | | | | | Filing Date | | | | | | | | | | | | | | | | | | | | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
\- 98 \-
\- 99 \-
\- 100 \-
| [10.](https://www.sec.gov/Archives/edgar/data/1327567/000119312520163579/d936599dex103.htm)[45](https://www.sec.gov/Archives/edgar/data/1327567/000119312520163579/d936599dex103.htm) | | | | | | Form of Warrant Confirmation. | | | | | | 8-K | | | | | | 001-35594 | | | | | | 10.3 | | | | | | June 8, 2020 | | | | | | | | |
Certain portions of this exhibit have been omitted as the Registrant has determined (i) the omitted information is not material and (ii) the omitted information would likely cause harm to the Registrant if publicly disclosed.
An excerpt. Shown here: 40 of 55 rewritten, all 30 added and all 5 removed. The counts are complete. For every sentence, read Item 15. Exhibits and Financial Statement Schedules in the FY2026 filing and the FY2025 filing.
Item 16. Form 10-K Summary
13 rewritten, 7 added, 8 removed, 37 unchanged
Pursuant to the requirements of Section 13 or 15(d) of the Securities Exchange Act of 1934, the [removed: Registrant] [added: registrant] has duly caused this report to be signed on its behalf by the undersigned, thereunto duly [removed: authorized, on August 29, 2025.][added: authorized.]
KNOW ALL [removed: THESE] PERSONS BY THESE PRESENTS, that each person whose signature appears below constitutes and appoints Nikesh Arora, Dipak Golechha, and Josh Paul, and each of them, as his or her true and lawful attorney-in-fact and agent, with full power of substitution and resubstitution, for him or her and in his or her name, place and stead, in any and all capacities, to sign any and all amendments to this Annual Report on Form 10-K, and to file the same, with all exhibits thereto, and other documents in connection therewith, with the Securities and Exchange Commission, granting unto said attorneys-in-fact and agents, and each of them, full power and authority to do and perform each and every act and thing requisite and necessary to be done in connection therewith, as fully to all intents and purposes as he or she might or could do in person, hereby ratifying and confirming all that said attorneys-in-fact and agents, or any of them, or their, his or her substitutes, may lawfully do or cause to be done by virtue thereof.
| /s/ NIKESH ARORA | | | | | | Chairman, Chief Executive Officer and Director (Principal Executive Officer) | | | | | | [removed: August 29, 2025] [added: September 10, 2026] | | |
| /s/ DIPAK GOLECHHA | | | | | | Chief Financial Officer (Duly Authorized Officer and Principal Financial Officer) | | | | | | [removed: August 29, 2025] [added: September 10, 2026] | | |
| /s/ JOSH PAUL | | | | | | Chief Accounting Officer (Duly Authorized Officer and Principal Accounting Officer) | | | | | | [removed: August 29, 2025] [added: September 10, 2026] | | |
| /s/ LEE KLARICH | | | | | | Chief Product and Technology Officer and Director | | | | | | [removed: August 29, 2025] [added: September 10, 2026] | | |
| /s/ APARNA BAWA | | | | | | Director | | | | | | [removed: August 29, 2025] [added: September 10, 2026] | | |
| /s/ JOHN M. DONOVAN | | | | | | Director | | | | | | [removed: August 29, 2025] [added: September 10, 2026] | | |
| /s/ CARL ESCHENBACH | | | | | | Director | | | | | | [removed: August 29, 2025] [added: September 10, 2026] | | |
| /s/ JAMES J. GOETZ | | | | | | Director | | | | | | [removed: August 29, 2025] [added: September 10, 2026] | | |
| /s/ RT HON SIR JOHN KEY | | | | | | Director | | | | | | [removed: August 29, 2025] [added: September 10, 2026] | | |
| /s/ HELLE THORNING-SCHMIDT | | | | | | Director | | | | | | [removed: August 29, 2025] [added: September 10, 2026] | | |
| /s/ LORRAINE TWOHILL | | | | | | Director | | | | | | [removed: August 29, 2025] [added: September 10, 2026] | | |
\- 111 \-
| | | | | | |
| Date: | | | September 10, 2026 | | |
\- 112 \-
| /s/ MARK GOODBURN | | | | | | Director | | | | | | September 10, 2026 | | |
| Mark Goodburn | | | | | | | | | | | | | | |
\- 113 \-
\- 101 \-
\- 102 \-
| | | | | | | | | | | | | | | |
| /s/ RALPH HAMERS | | | | | | Director | | | | | | August 29, 2025 | | |
| Ralph Hamers | | | | | | | | | | | | | | |
| /s/ MARY PAT MCCARTHY | | | | | | Director | | | | | | August 29, 2025 | | |
| Mary Pat McCarthy | | | | | | | | | | | | | | |
\- 103 \-