Palo Alto Networks, Inc. Common Stock 2026 Q4 Earnings Call
Review the key takeaways and the transcript of this earnings call.
- Palo Alto Networks reported record fiscal year 2026 results, exceeding guidance across every financial metric in Q4 with bookings momentum accelerating for the second consecutive quarter.
- Remaining performance highlights include record RPO surpassing $21.2 billion, up 34% year over year, and next generation security ARR reaching $9.1 billion, up 63%.
- The company added nearly $1 billion in net new next generation security ARR in Q4 alone, nearly doubling year over year.
- Revenue by platform showed network and AI security grew 17% to $8.35 billion, Cortex grew 25% to $1.92 billion, and Idera grew 21% to $1.26 billion in fiscal 2026.
- Total company revenue for Q4 was $3.41 billion, up 34%, and $11.5 billion for the full year, up 24%.
- Gross margin was 74.8% in Q4 and 75.8% for the full year, with declines due to mix shift towards SaaS offerings.
- Non-GAAP operating margin was 29.6% in Q4 and 29.2% for the full year, expanding 40 basis points year over year despite acquisitions.
- Adjusted free cash flow was $1.29 billion in Q4, up 35%, and $4.41 billion for the full year, with a margin of 38.4%.
- The company closed two large acquisitions in fiscal 2026: Cyberark (now Idera) and Chronosphere, both exceeding initial expectations and accelerating growth.
- Palo Alto Networks also completed acquisitions of Embrace and Console in Q4, expanding observability and AI-first IT/security operations capabilities.
- Platform adoption grew strongly with approximately 220 net new platforms added in Q4, more than double the volume from two years ago, and net revenue retention exceeded 120% for the platform cohort.
- Notable large Q4 deals included a $126 million agreement with a global telecom leader, a $72 million deal with a premier IT service provider, and a $53 million deal with a global payments platform.
- Management emphasized the transformative impact of AI on cybersecurity, including the rise of autonomous agents, weaponization of AI for vulnerabilities, and the shift from visibility to velocity in defense.
- They highlighted the strategic importance of unified real-time defense platforms to address machine-speed cyber threats and the expanding attack surface from AI deployments.
STOCKNOW INSIGHTS
Continue with outlook and guidance.
Log in to unlock executive comments and Q&A highlights.
Log in for the full summaryStockNow uses AI to translate and summarize earnings calls. Accuracy and completeness are not guaranteed.
Transcript
Preview the first fifteen paragraphs, organized by speaker.
Fiscal fourth quarter results are Nikesh Arora, our Chairman and Chief Executive Officer, and Dipak Golechha, our Chief Financial Officer. You can find the press release and other information to supplement today's discussion on our website at investors.paloaltonetworks.com. While there, please click on the link for quarterly results to find the Q4 2026 supplemental financial information and Q4 2026 earnings presentation. During the course of today's call, we will be making forward-looking statements and projections regarding the company's business operations and financial performance, as well as the company's recent acquisitions. These statements made today are subject to a number of risks and uncertainties that could cause our actual results to differ from these forward-looking statements. Please review our press release and recent SEC filings for a description of these risks and uncertainties. We assume no obligation to update any forward-looking statements made in today's presentation.
This presentation also contains non-GAAP financial measures and key metrics relating to the company's past and expected future performance. Non-GAAP financial measures should not be considered a substitute for financial measures prepared in accordance with GAAP. The most directly comparable GAAP financial metrics and reconciliations are in the press release and the appendix of the investor presentation. Unless specifically noted otherwise, all results and comparisons are on a fiscal year-over-year basis. I will now turn the call over to Nikesh.
Thank you, Hamza. Good day, everyone, and thank you for being with us to discuss our progress. As you can see, our execution fueled a record finish to the fiscal year. We exceeded our guidance across every financial metric in Q4, with bookings momentum accelerating for the second straight quarter. This performance is a direct result of record-breaking platformization adoption and the growing urgency among customers to fortify their defenses as AI fundamentally redefines the security landscape. We achieved record RPO, surpassing the $20 billion threshold for the first time to close the year at $21.2 billion, representing a growth rate of 34%. NGS ARR reached $9.1 billion, up 63%, enabling us to report one of our most substantial Next-Generation Security ARR outperformance to date. Most notably, we added nearly $1 billion in net new NGS ARR this quarter alone.
I remember my first Analyst Day in 2019, shortly after I arrived. We set a high bar to reach $1 billion in Next-Generation Security revenue by fiscal 2022, just as we were initiating our pivot from a single-product firewall vendor at a unified security platform. That transformation journey has reached a pivotal inflection point, and the scale of our current success is a testament to that vision. We delivered broad-based strength across our platforms in Q4. With Network & AI Security, our largest business, reporting exceptional results across SASE, software, and hardware firewalls. XSIAM maintained its strong momentum, while Prisma AIRS achieved a significant milestone, surpassing $100 million in ARR within four quarters of general availability. This represents the fastest-scaling product in the history of Palo Alto Networks. Fiscal 2026 marked a pivotal inflection point in our transformation journey.
We closed the two largest acquisitions in our history with CyberArk and Chronosphere, both of which are exceeding our initial expectation. Both businesses are gaining significant traction within our platformized architecture and are scaling at an accelerated pace compared to their previous standalone performance. These achievements are a testament to the execution and deep collaboration of the thousands of new colleagues who joined us this past year. We look forward to continuing this shared momentum into FY 2027. Q4 was the very first quarter in which we witnessed the profound implications of cyber-capable models. As I have said before, AI is a long-term tailwind for cybersecurity. While these models are becoming increasingly proficient at uncovering vulnerabilities, detection is merely the opening act. Truly validating, interpreting context, and resolving these issues requires broad cybersecurity platforms working alongside frontier AI.
This synergy is essential to stress test environments, manage agentic actions, and trigger machine speed remediation during an active threat. Defending at that speed necessitates a unified data architecture where AI processes every signal, collapsing response times from days to just minutes. Platformization is the only viable strategy for real-time defense, fighting AI with AI, and that philosophy continued to gain significant resonance with our customers in Q4. During the fourth quarter, we achieved approximately 220 net new platformizations, surpassing our prior record and representing more than twice the volume for when we initiated this metric two years ago. The performance validates that our philosophy of real-time defense to unified architecture continues to gain significant resonance. Beyond initial adoption, standardizing on our platform yields superior retention and expansion with NRR, or net revenue retention, exceeding 120% for our platformized cohort in Q4.
As we look forward, we remain on track towards our long-term objective of over 4,000 platformizations by fiscal 2030, which serves as a bedrock for reaching our $20 billion Next-Generation Security ARR target. Our largest Q4 wins show platformization in action. During the fourth quarter, we secured a $126 million agreement with a global telecoms leader. This organization moved to standardize on our network security platforms, bolstering their Next-Generation Firewall footprint while displacing legacy proxy providers with Prisma Access for SASE. We also closed a $72 million transaction with a premier IT service provider. This client has fully embraced platformization across Network & AI Security, Cortex, and Idira, making eight-figure investments in each, serving as a powerful validation of our cross-sell momentum in Q4. A further highlight was a $53 million platformization deal with a leading global payments platform.
Beyond standardizing their network defense on our architecture, they committed high seven figures to Prisma AIRS as they accelerate their enterprise AI initiatives. Fiscal 2026 has emerged as a landmark period in the rapid evolution of AI, marked by three distinct inflections over the last six months. Each of these shifts fundamentally redefines how AI interacts with the enterprise, and by extension, how it impacts the cybersecurity landscape. For us to effectively lead and protect our customers, maintaining our position as the vanguard of these structural changes is paramount. The first inflection was the arrival of OpenClau. Earlier this year, OpenClau served as the catalyst for the transition from standard LLMs to agentic action, fundamentally altering the dynamic between human operators and AI systems. Just a year ago, AI was largely defined by individual human prompting, a synchronous multi-turn dialogue where task was completed with a personal loop.
Virtually overnight, we witnessed the emergence of fully autonomous agents. These are persistent entities that operate for extended durations, executing complex workflows without direct supervision. Where a single employee once managed one task at a time, that same individual can now orchestrate thousands of autonomous agents. The implications for the enterprise are profound. Each of these agents generates continuous traffic, interacting with models, creating internal data, and communicating with other tools and agents around the clock. This creates a massive volume of telemetry that must be observed, while every agent requires its own set of credentials. We are now securing a whole new class of machine identities with autonomous permissions. The surge in traffic, data, and identity complexity represents a significant long-term tailwind across every one of our platforms. The second was the Mythos moment, which proved that deep domain training enables AI to achieve unprecedented proficiency.
In our sector, this has manifested as the weaponization of AI to identify and exploit vulnerabilities at scale. This shift has exposed the deep technical debt within the enterprise, where legacy flaws and persistent misconfigurations that once took months for a human to uncover are now exploited in minutes. In an AI-driven threat environment, there is no longer anywhere to hide. For our customers, the Mythos moment reframed the security challenge from visibility to velocity. Organizations must now identify exposures before they are weaponized and respond at machine speed. This is why real-time defense has shifted from a future roadmap item to a present-day requirement. To address this, we expanded our Frontier AI Critical Defense Program last month, introducing a multi-modal harness that enables enterprises to stress-test their environments. This service leverages the most sophisticated cyber-capable models available, and we are proud to be the first certified commercial partner for Mythos 5.
The third involves an emerging inflection point that we expect will dominate the cybersecurity dialogue in the coming quarters. For the past 90 days, the market has moved beyond a handful of frontier models towards a diversified ecosystem of open-weight and open-source architectures. Enterprises are increasingly prioritizing sovereign control over their AI, leading to the deployment of specialized models deeply integrated with proprietary data. We expect a major acceleration as organizations utilize internal telemetry to fine-tune models for bespoke enterprise use cases. While frontier models will continue to set the high watermark for intelligence, the broader market is heading towards rapid fragmentation and proliferation. Crucially, each new deployment adds more infrastructure to fortify and more sensitive data to protect. The surface area requiring platform as protection is expanding dramatically. Three pivotal moments, each with a unique impact, yet all leading to a single conclusion.
As the relationship between humans and AI evolves and deployments multiply, the necessity for unified real-time defense has never been greater. It is early days, but we are beginning to see the signs of how these trends are impacting our business, starting with our largest business, Network & AI Security. AI represents a significant long-term tailwind that is expanding our total addressable market in network security while reinforcing that platformization is the only viable strategy for the modern enterprise. As the global AI build-out continues, every new data center becomes critical infrastructure that requires robust fortification through hardware and software firewalls, whether delivered natively by cloud providers or by a unified security platform. The ecosystem driving this infrastructure expansion had reached a pivotal inflection point, and now we are seeing a new vanguard of buyers emerge, spanning sovereigns, neo clouds, and frontier labs, all racing to deploy massive computational capacity that must be secured.
We achieved strong early traction with this cohort in FY 2026, including multiple seven-figure bookings in the fourth quarter. In total, our firewall execution drove accelerated bookings for the fiscal year, fueled by robust demand for latest 5th-generation hardware and the continued momentum of our software offerings as customers scale their cloud and AI workloads. As this infrastructure matures and autonomous agents are deployed, we expect a dramatic proliferation of agentic traffic across every network and cloud environment. The impact on our SASE platform is already evident, where agentic traffic has surged 9X over the last nine months. Defending at this scale requires machine speed inspection, a core competence we have refined for two decades, enabling us to block more than 30 billion attacks in a single day. Ultimately, AI is underscoring the urgent need for unified platforms that deliver real-time defense.
In FY 2026, our platform advantage drove exceptional results in our SASE business, where bookings grew 40% with broad strength across access, SD-WAN, and secure browser. We successfully displaced legacy incumbents in nearly 100 accounts, representing over $400 million in total contract value, nearly double the volume of displacement from a year ago. While we have rapidly ascended to the number 2 position in this market, we are playing to win and remain on a clear trajectory to become the SASE leader within the next five to seven years. We are in the early chapters of this shift, where the future necessitates securing both human and machine identities through a unified architecture capable of providing defenses at machine speed. Organizations are transitioning AI initiatives from experimentation to full-scale production, significantly widening the defensive perimeter with each new deployment.
Prisma AIRS has continuously adapted alongside these adoption cycles, evolving to mitigate the unique risk emerging from every phase of the AI journey. While our initial focus addressed the chatbot-centric era of generative AI, our vision has expanded towards providing a comprehensive architecture for agentic security. This unified approach begins with securing machine identities and credentials, incorporates deep observability of agentic footprints, and extends to the endpoint where we analyze behavioral intent. By funneling this traffic through our AI gateway, we ensure that security policies are enforced in real time across every interaction. Prisma AIRS achieved a remarkable milestone in Q4, surpassing $100 million in ARR within just four quarters of general availability, marking the most rapid scale out of any product in our history.
FULL TRANSCRIPT
Continue the full translated transcript in StockNow.
Log in to unlock every statement, the English original, and speaker-by-speaker history.
Log in for the full transcriptCall participants
12 people spoke on this call — only 2 are shown here.
PARTICIPANT LIST
View participant details in StockNow.
Log in to see executives and analysts, their roles, and complete speaking history.
Log in to view all participantsKeep exploring
