Skip to main content
PANW $397.31 +2.29%
PANW logo
PANW · Palo Alto Networks Inc
Track PANW — free
$397.31 +8.90 (+2.29%) At close · Sep 30
Market Cap
$306.54B
Shares
818.00M
Volume · Sep 30 6.09M Avg daily vol (3M) 6.42M
All earnings calls

Earnings call · FY2021 Q3

Palo Alto Networks Inc (PANW) Q3 2021 Earnings Call Transcript

Concluded May 20, 2021
May 20, 2021 62 turns
Period
FY2021 Q3
Runtime
—
Sources
3 artifacts

Read the call

Transcript

Read the speaker-labelled prepared remarks and analyst questions.

Operator

Good afternoon and thank you for joining us for today’s conference call to discuss Palo Alto Networks' Fiscal Third Quarter 2021 Financial Results. I am Walter Pritchard, Senior Vice President of Investor Relations and Corporate Development. This call is being broadcast live over the web and can be accessed on the Investors section of our website at investors.paloaltonetworks.com. With me on today’s call are Nikesh Arora, our Chairman and Chief Executive Officer; Dipak Golechha, our Chief Financial Officer; and Lee Klarich, our Chief Product Officer. This afternoon, we issued a press release announcing our results for the fiscal third quarter ended April 30, 2021. If you would like a copy of the release, you can access it online on our website. We would like to remind you that during the course of this conference call, management will make forward-looking statements, including statements regarding the impact of COVID-19 and the SolarWinds attack on our business, our customers, the enterprise and cybersecurity industry, and global economic conditions; our belief that cyber-attacks will continue to escalate, our expectations regarding the single equity structure, our expectations related to financial guidance, operating metrics, and modeling points for the fiscal fourth quarter and fiscal year 2021; our expectations regarding our business strategy, our competitive position and the demand and market opportunity for our products and subscriptions, benefits and timing of new products, features, subscription offerings, as well as other financial and operating trends. These forward-looking statements involve a number of risks and uncertainties, some of which are beyond our control, which could cause actual results to differ materially from those anticipated by these statements. These forward-looking statements apply as of today. You should not rely on them as representing our views in the future, and we undertake no obligation to update these statements after this call. For a more detailed description of these factors that could cause actual results to differ, please refer to our quarterly report on Form 10-Q filed with the SEC on February 23, 2021, and our earnings release posted a few minutes ago on our website and filed with the SEC on Form 8-K. Also please note that certain financial measures we use on this call are expressed on a non-GAAP basis and have been adjusted to exclude certain charges. For historical periods, we have provided reconciliations of these non-GAAP financial measures to our GAAP financial measures in the supplemental financial information that can be found in the Investors section of our website located at investors.paloaltonetworks.com. And finally, once we have completed our formal remarks, we will be posting them to our Investor Relations website under the Quarterly Results section. We’d also like to inform you that we’ll be virtually participating in the JPMorgan 49th Annual Global Technology, Media and Telecommunications Conference on May 24 and the BofA Securities 2021 Global Technology Conference at June 8. Please also see the Investors section of our website for additional information about conferences that we may be participating in. And with that, I’d like to turn the call over to Nikesh.

Thank you, Walter. Good afternoon and thank you for joining us today for our earnings call. Let me begin with the current cybersecurity landscape. After the December SolarStorm attack, we saw an acceleration in attacks throughout our third quarter and after the quarter closed. These range from software supply chain attacks like SolarWinds and Codecov to ransomware attacks like Colonial Pipeline. Ransomware especially has been in the spotlight recently and data from our own Unit 42 shows that the average ransom paid in 2020 tripled from 2019 and in 2021 it's more than doubled again. The highest demand we’ve seen is $50 million, up from $30 million in 2020, with organized groups with near nation-state discipline perpetrating coordinated attacks. The targets are not only corporations where healthcare and pharma is a focus with the pandemic, but also government organizations and shared infrastructure. The reason for this vulnerability is deep-seated. Organizations run their operations on technology that is decades old, sometimes predating the internet. They continually bolt on new technologies to automate facilities, and make them compatible with the modern internet, but those platforms are inherently insecure. At the same time, cyber defenses are fragmented, making it very challenging to block sophisticated attacks and lengthening meantime to discovery and repair. Lastly, more and more businesses and consumers are coming online without a baseline of productive protection. In such a scenario, it is imperative that customers focus on securing their most critical assets, while also focusing on reducing the fragmentation and leveraging new technologies like artificial intelligence, machine learning, and using those approaches. With that backdrop, let's focus on our results. Overall, we saw continued strong demand environment and our own continued execution drove Q3 billings revenue and EPS side of guidance. We saw billings growth accelerated 27% in Q3 ahead of our 24% revenue growth forecast with growing ratable revenue contribution. I want to highlight one dynamic regarding our billings to help you better understand the drivers. During COVID, some customers were asking for annual billing plans to meet their needs. We noted to you that we saw success with larger, more strategic transactions in Q3. Along with these deals, we saw an uptick in annual billings plans. Normalizing for this, our billings would have grown greater than 28%, nearly two points higher than we reported, which is the highest billing growth we have seen in the third quarter since Q3 of fiscal year 2018. Last year, we saw billings plan have an approximate one-point impact along with billings. We also saw 38% growth in our remaining performance obligations. This metric is growing faster than both revenue and deferred revenue, and will be a source of consistent revenue growth in the future. Within the strong performance, we also saw 71% growth in ARR or annualized recurring revenue from our next-generation security offerings, where we finished our third quarter at $970 million, up from $840 million in Q2. These ARR, billing, and RPO trends drove 24% year-over-year growth in our reported revenue. It's worth noting, given your attention to NGS ARR, that in the very first week, in the first day of Q4, we transacted one of our largest next-generation security deals in the history of Palo Alto Networks, with a Fortune 30 manufacturer, which brought in $7 million in NGS ARR. So we're already at $980 million on the first day of this quarter. With the acceleration and incremental NGS ARR in Q3 and trends we see in the business, we continue to have confidence in our Q4 targets of $1.15 billion in NGS ARR. As part of the strong Q3 performance, we saw notable momentum in large transactions with 901 customers having spent $1 million with Palo Alto Networks in the last four quarters. This cohort of customers was up 29% year-over-year growing ahead of our overall revenue and billings growth. This growth in active customers has accelerated in recent quarters. As part of this large deal performance, our business is benefiting from growing adoption of multiple Palo Alto Network security platforms across the install base. In Q3, 70% of our Global 2000 customers have purchased products from more than one of these platforms and 41% have purchased all three platforms. This is up from 58% and 25% two years ago. Turning to our product areas, earlier this year we started the dialogue around network security and cloud and AI and shared additional financial metrics to give you more transparency. Having these two product areas under the common umbrella of our world-class R&D and go-to-market organization is key to our strategy, being the largest cybersecurity company in the world. Starting with the network security side of our business, we are the leader in this business. Our strategy of selling customers leading firewall platform delivered to hardware, software, or as a service form factor underpins our success in this market. This has resulted in the business that is 28% larger than our next peer on a revenue basis in Q3. Also, if we look at leading indicators that include deferred revenue and RPO, our scale comes through even further, we are 40% to 50% larger. On these leading balance sheet metrics, we’re growing faster than our next peer. Three years ago, when I joined Palo Alto Networks, we were hardware-based Firewall Company. We had a vision of a hybrid world where the enterprise and data centers would remain predominantly hardware-oriented, growing adoption of software form factors like our VM series firewalls. Meanwhile, the remote access and remote office work, this opportunity has been transformed by cloud adoption and work-from-home trends to secure access service edge or SASE adoption. The reception to our strategy of delivering a firewall and multiple form factors has enabled the accelerating Firewall as a Platform growth rates we just showed you. Within our Firewall as Platform billings, we’re seeing a distinct mix shift towards software. The software mix, which includes our VMs and SASE business, now makes up 40% of Firewall as a Platform, up 21 percentage points from a year ago. We saw seven-figure transactions for our software firewall capability, including VM and CN-Series with a U.S. government agency, a Fortune 30 manufacturer, and a diversified financial services company. While we have seen the significant transition in form factors, one driver of growth in value in our business, our attach subscription support have grown at a steady rate over the last several quarters on a revenue basis. We expect the software mix to continue to increase in the medium term, although along with this, we expect to continue to see attach subscription as a key growth driver. We’re showing you for the first time here, the NetSec annualized recurring revenue, which was $2.66 billion at the end of Q3 and grew 25%. As a reminder, this does not include our hardware business, which continues to be significant. This recurring revenue business is a key driver for strong cash generation, which we have guided to 42% for NetSec in FY 2021. We believe this high degree of recurring revenue and strong cash flow generated by NetSec is something that should be more clear now, given this incremental disclosure over the last two quarters. Now, turning to innovation and focusing first on Prisma SaaS, back at the beginning of the pandemic, we saw customers look to significantly expand remote access capability, while not compromising security or user experience. We’ve met that demand with free remote access trials and broad proof-of-concepts, enabling customers to see that value in Prisma Access, as well as supporting the network transformation as they move to the cloud. We’re seeing these efforts as well as momentum generated for the 2.0 launch, driving strong initial purchases and substantial expansions. This quarter, we saw a number of large Prisma Access transactions including a global technology company, a large manufacturer, and a Fortune 10 healthcare company, all eight figures or greater. Additionally, over 25% of our Prisma Access new customers in Q3 were new to Palo Alto Networks. Lastly, we're seeing early traction in our service provider partners for Prisma Access, including Comcast, Verizon, and Orange Business Services. These relationships are part of broader initiatives to serve providers that we see as a significant growth opportunity. Just yesterday, we announced a significant release in network security focused around a comprehensive approach to Zero Trust. This is timed well and follows last week's executive order out of the White House that defines Zero Trust in a way that is very consistent with the Palo Alto Networks strategy. There has been a lot of noise in the industry around Zero Trust Network Access, a solution continues to be fragmented around either remote users, access control, or enterprise apps. Our approach covers all users and devices, all locations, all apps and the Internet applying consistent access control and security. Our new PAN-OS 10.1 release brings cloud-based identity controls, integrated CASB and enhancements to our URL and DNS Security Services. Palo Alto Networks position across appliance, software and SASE is unique, and these new innovations are applicable to all our customers across all form factors. This is one of the most significant innovation releases for our next core, next-generation firewall franchise, and gives us confidence in continued NetSec growth as we look forward. Now, moving on to cloud and AI, on the Prisma Cloud front, we continue to build on our early leadership position in Cloud Security Posture Management, Cloud Workload Protection capability, and marketplace delivered virtual firewalls, where we are the largest player across this opportunity set. Our strategy is to stay ahead of customer demand as they adopt cloud-native security services across hyperscalars. We believe we've staked out a leadership position in cloud-native security in this business. We've achieved over $250 million in ARR across Prisma Cloud in our marketplace VM-Series. Fueling this growth is 39% growth in total customers and 38% growth in Global 2000 customers across Prisma Cloud. Our unique consumption model in Prisma Cloud based on credits, enables customers to use any of our modules across the cloud deployed workloads, including using multiple capabilities for workloads. We're seeing strong growth in credit consumption, with over 100% growth year-over-year in Q3. Despite our strong position with Prisma Cloud, targeting early opportunities, we see the next big challenge in security at the developer level, or shift-left security. We recently addressed this with our acquisition of Bridgecrew completed in Q3. Traditionally, security issues in code pose a challenge for the CI/CD (Continuous Integration/Continuous Deployment) organization. We’re seeing leading companies drive a collaborative approach between the CI/CD organizations to address this. Shift left integrates security into the DevOps process to catch these issues upfront, where they are easy and quick to fix. It's a win for developers and a win for security. Bridgecrew has an open-source product; Checkov, which delivers significant value to developers as a free download. Post the acquisition close on the release of 2.0 of Checkov, we are seeing strong momentum and customer acceleration with an impressive traction in some parts of the market, including a six-figure customer in Q3. We're only in the very early stages of cross-selling between Bridgecrew software and Prisma Cloud in our Cortex product area. We continue to focus on delivering significant volumes of innovation to XDR and our recently acquired Expanse product. In Q3, we delivered a new release of XDR, expanding endpoint query capability and improving visibility into network activity. With Expanse, we significantly expanded market-based partner integrations to increase security automation and the number of playbooks that customers can deploy. We are seeing steady Cortex customer additions to XDR, which now has 2,400 customers, starting from essentially scratch two years ago. Focus on innovation has been validated by the market as well. We were particularly proud of this validation, with Cortex XDR in Q3 being regarded as the best overall results in round three testing provider. Also in the recently released Forrester Wave, we were identified as a leader in endpoint security software as a service market, across partner contributed content packs, which now exceeds 650 in the marketplace. Our Expanse offering was featured in Tim Jr.'s keynote this week at RSA, where research uncovered that one-third of leading organizations' attack surfaces are susceptible to exposure and are the main avenues for ransomware. No other leading security company has the degree of visibility to identify and prevent today's most pernicious attack vectors. Within Cortex, we are starting to see an uptick in large customer signings, such as a seven-figure transaction with a financial services firm, which included XDR Pro and Expanse. Last during Q3, we formed the new unit 42 under the leadership of Wendy Whitmore, who comes to Palo Alto Networks after building successful security services businesses. Our new team is a combination of two of the most capable teams in cybersecurity. The Unit 42 team is laser-focused on the mission of conducting world-class data breach investigations. The previous Unit 42 team focused on rapidly building threat intelligence and Developer Network products. This new Unit 42 has completed over 1300 engagements in calendar 2020, bringing to bear the power of 140 consultants and responding to SolarWinds, ransomware, Microsoft data breaches and other attack mitigations. We look forward to using our services to become even more of a strategic partner to our customers. As I've reviewed with you here and should be evident in our results, we're seeing broad strength across our business geographies and product areas. We see strength in our pipeline, and continued demand tailwinds remain strong, leading us to raise our FY 2021 guidance. I also want to update you on our plans discussed in Q2 around exploring an equity structure for ClaiSec. We continue to focus on providing transparency for each part of our business. You'll notice the error for NetSec we've highlighted this quarter; we believe this has helped investors gain better insight into our overall financial profile, and especially understanding both sides of the business with different growth and free cash flow characteristics. We have finished all the work required to file any form of equity on ClaiSec. However, given the state of the market and offering extensive conditional shareholders, we have decided at this point it is best to continue with a single equity structure and an integrated P&L, postponing a decision to list ClaiSec equity. Lastly, we're excited to welcome Aparna Bawa, Chief Operating Officer at Zoom to Palo Alto Networks Board of Directors. She brings deep operational, financial, and legal expertise, having served in diverse roles in rapidly growing tech companies such as Zoom, Magento, and Nimble. Her addition follows the February appointment of Dr. Helene Gayle to our Board. We continue to have a strong commitment to diversity at Palo Alto Networks, including at the most senior levels of governance in our company. With that, I'll turn the call over to Dipak Golechha, our CFO. We're excited to have Dipak step into the CFO role, enabling a smooth transition within our organization. He brings world-class experience, and we're already seeing him bring that experience to bear in driving improvements. Over to you, Dipak.

Thanks, Nikesh. I'm excited and humbled to be part of this world-class leadership team. I look forward to driving total shareholder return. As Nikesh indicated, we had a strong third quarter as we continue to deliver winning innovation, while simultaneously adding new customers at pace. The strength gives us confidence to raise guidance for the year. We delivered billings of $1.3 billion, up 27% year-over-year, with strong growth across the Board, ahead of our guidance of 20% to 22% growth. We’ve continued to see some customers ask for billing plans, many involving larger transactions as we become a more strategic partner to our customers. We’ve also utilized our Palo Alto Networks financial services financing capability here. The dollar-weighted contract duration for new subscriptions and support billings in the quarter were consistent year-over-year and remained at approximately three years. We added approximately 2,400 new customers in the quarter. Total deferred revenue at the end of Q3 was $4.4 billion, an increase of 30% year-over-year. Remaining performance obligations or RPO was $4.9 billion, an increase of 38% year-over-year. We continue to see these metrics becoming more meaningful, as we drive growth from our ratable business. Our revenue of $1.07 billion grew 24% year-over-year ahead of our guidance of 21% to 22% growth driven by billings and broad business strengths amidst an increase in our audible subscription revenue. We remain focused on driving this high-quality revenue, with all new product offerings being pure or substantially all subscription in nature. Looking at growth by geography, the Americas grew 24%, EMEA grew 23%, and APAC grew 25%, showing broad executional excellence across the world. Q3 product revenue of $289 million increased 3% compared to the prior year. Q3 subscription revenue of $474 million increased 34%. Support revenue of $311 million increased 33%. In total, subscription and support revenue of $785 million increased 33% and accounted for 73% of total revenue. Our Q3 non-GAAP gross margin was 74.6%, which is down 60 basis points compared to last year, driven by product mix, which are less mature. Q3 non-GAAP operating margin was 17%, an increase of 60 basis points year-over-year. There are several factors driving our operating margins. We have revenue upside, lower travel and event expenses due to COVID, and some shift in spending out of Q3. At the same time, we continue to aggressively invest in growth, largely in the areas of sales capacity and R&D investments. With health conditions improving and geographies of many of our facilities, including our Santa Clara headquarters, we're seeing more employees look to return to the office. We expect this trend will continue to gain steam in Q4, reversing some of the savings we've seen in the last few quarters in our OpEx. Non-GAAP net income for the third quarter increased 22% to $140 million, or $1.38 per diluted share. Our non-GAAP effective tax rate for Q3 was 22%, the EPS expansion was driven by revenue growth and operating expense leverage with an undertone of strong investments for growth. On a GAAP basis for this quarter, net loss increased to $140 million, or $1.50 per basic and diluted share. We ended the third quarter with 9,715 employees, including 39 from the Bridgecrew acquisition close. Turning to the balance sheet and cash flow statement, we finished April with cash, cash equivalents, and investments of $3.8 billion. Q3 cash flow from operations was $278 million, an increase of 64% year-over-year. Free cash flow was $251 million, up to 100% at a margin of 23.4%. Our DSO was 60 days, a decrease of three days from the prior year period and flat from the second quarter. Our Firewall as a Platform, or FWaaP, had another strong quarter, as we continue to grow faster than the market. FWaaP billings grew 26% in Q3, and we continue our transition from hardware and software to SaaS form factors as Nikesh highlighted. Our next-generation security or NGS continues to expand and now represents 27% of our total billings of $346 million, growing at 70% year-over-year. In the third quarter, we added $133 million in new NGS ARR, reaching $973 million. The acquisition of Bridgecrew added an immaterial amount to this number, and we remain confident in our plan to achieve $1.15 billion in NGS ARR by the end of fiscal year 2021. Turning now to guidance and modeling points. For the fourth quarter of 2021, we expect billings to be in the range of $1.695 billion to $1.715 billion, an increase of 22% to 23% year-over-year. We expect revenues to be in the range of $1.165 billion to $1.175 billion, an increase of 23% to 24% year-over-year. We expect non-GAAP EPS to be in the range of $142 to $144, using 101 to 103 million shares. Additionally, I'd like to provide some modeling points. We expect our Q4 non-GAAP effective tax rate to remain at 22% and our CapEx in Q4 to be approximately $30 million to $35 million. As Nikesh indicated, we're seeing broad drivers across our business in Q3, driven by the foundation of innovation and strong sales execution along with trends we see in our pipeline and the long tail demand tailwinds that remain strong, and we're raising our fiscal year 2021 guidance. We expect billings to be in the range of $5.28 billion to $5.3 billion, an increase of 23% year-over-year. We continue to expect next-generation security, ARR, to be approximately $1.15 billion, an increase of 77% year-over-year. We expect revenue to be in the range of $4.2 billion to $4.21 billion, an increase of 23% to 24% year-over-year. We expect product revenue growth of 1% to 2% year-over-year. We expect operating margins to improve by 50 basis points year-over-year. We expect non-GAAP EPS to be in the range of $597 to $599, using 99 to 101 million shares. Regarding free cash flow for the full year, we expect an adjusted free cash flow margin of approximately 30%. Now let's review our fiscal year projections for NetSec and ClaiSec. Overall, we are confirming our ClaiSec projections, while raising NetSec billings by 300 basis points and revenue by 100 basis points, given the strong performance of SASE, VM-Series and subscription business overall within that NetSec. Moving on to adjusted free cash flow, we expect Network Security to deliver a free cash flow margin of 42% in fiscal year ’21, up from 38% in fiscal year ’20. We continue to expect Cloud and AI free cash flow margin of minus 43% in fiscal year ’21, an improvement from negative 59% in fiscal year 20. While we are focused on growth investments in Cloud and AI, over time we expect Cloud and AI to achieve growth operating and free capital margins in line with industry benchmarks as we gain scale, our customer base matures and we become more efficient. In Q3 we repurchased $350 million in our own stock at an average price of $322. As of April 30, 2021, we have $652 million remaining available for repurchases. This is part of a broader capital allocation strategy focused on balancing priorities and maximizing total shareholder return. We start with fueling organic investments and managing priorities across innovation and go-to-market to set the foundation for sustainable growth at Palo Alto Networks. Second, we deploy capital for targeted acquisitions which accelerate this growth opportunity. We rigorously evaluate targets, focusing on acquiring leading technology, retaining key members of the team and following through with integrating these acquisitions into our businesses. Finally, we work to optimize our capital structure using the options available to us in this dynamic market, including deploying debt, using stock for M&A consideration and also buying back our own stock when we see it representing good value. With that, let's move on to the Q&A portion of the call. Walter over to you.

Operator

Thanks. Our first question comes from Brian Essex from Goldman Sachs, with Fatima Boolani from UBS next in line.

Speaker 3

Hey. Hi, thank you. Good afternoon and thank you for taking the question. Maybe for unit cash, we've seen a lot of solid outperformance relative expectations on a network security side. And nice performance this quarter with respect to Cloud and AI ARR growth. Wanted to get a better understanding, given that the outperformance has been on the network security side, how confident are you in your ability to hit that $1.150 billion guide for the full year? How do we think about, you know, how that business has performed relative to your expectations so far this year?

Brian, remember, two or three years ago when we set out targets for next-generation security business, we didn't have the muscle to pivot Palo Alto Networks to figure out how we can move out of the firewall business and have that sales force go out and actually sell Cloud and AI. The good news is over the last two and a half years, we've been building that muscle and learning how the market operates. It's interesting that every one of these markets operates slightly differently. If you look at NGS, it's a combination of SASE, Prisma Cloud, and Cortex. Now SASE's characteristics include a lot of the free trials we gave a few quarters ago, and this push to work from home is forcing customers to rethink their security stack. It’s no longer just about accessing half the apps, half the time; you need full access from wherever you are. So, what we are seeing is network transformations which are driving the success of SASE and some major wins we had with Prisma access. As I mentioned, one of the deals we closed earlier this month is our largest SASE deal ever, which gave us $7 million of NGS ARR. This gives you an idea of the scale of that deal. So we are seeing a lot of traction in the access front and the SASE front, which is promising. Cortex is an interesting space because we compete with players like CrowdStrike and SentinelOne among others. We have a great product, as evidenced by the Forrester Wave and the MITRE results. We are working on creating more muscle around closing those deals. Typically, those deals range from $1 million to $5 million, plus higher end ones and smaller below that. We don’t get lumpy deals there; we need to do more deals. On the cloud front, we have 2,250 customers, and the deals tend to be sizable but come with high variability in duration and consumption. Some deals have shifted in the cloud, where customers are evaluating how many credits they will need over a three-year period, for instance. Others are existing customers that are increasing their consumption due to moving their workloads to the cloud. So all three elements have distinct characteristics. That’s why we see this as a portfolio situation. You saw this quarter we added about $133 million in net new NGS ARR, and I want to reassure you that we are confident about reaching that $1.150 billion target.

Speaker 3

Thank you for the insights. I have a follow-up for Dipak regarding the potential improvements in operating efficiency for cloud and AI. Investors seem to grapple with understanding this business when we evaluate it on a component basis. Given the current high cash burn rate of cloud AI, what is your perspective on the timeline for achieving better profitability and cash flow from that segment? This could influence investors to reassess the business on its own merit and potentially value it more favorably.

Yeah. So, maybe if I answered in two different ways. I mean, we look at what other companies have done as they've scaled over time. And we often benchmark ourselves against where they were at that time, and whether there are things we can do to reach that point. But at the same time, we're not shy about making the right investments if we see opportunities. So that's why I don't want to box ourselves into a timeframe. It really is a question of what opportunities are present at the time. So we have a baseline plan that's constantly improving, but we’re also reflecting on the fact that this is a dynamic market, and sometimes you need to lean in if it makes sense for the long term.

Yeah. If I can add to that.

Speaker 3

Great. Thanks. Oh, go ahead.

There are two parts, one, as Dipak highlighted. We continue to work hard towards achieving gross margin efficiency on those products because product development is in our control. Lee, who’s sitting to my right, and his team work diligently to optimize gross margins. The reality is also how much do we want to invest in sales capacity to drive those results? In each of those areas, we're dealing with highly competitive situations. For instance, in XDR, we compete with dedicated salespeople from CrowdStrike, who outnumber us significantly. So we have to evaluate how much investment we want to make on the sales side. We do get leverage with our Palo Alto sales team, but it's a more hands-on approach. In the Prisma Cloud side, we’re doing well; however, recent equity market conditions have introduced more competition, putting pressure on recruiting qualified cloud security salespeople as startups raise large funds. Therefore, as we move forward, we aim to watch the market carefully. Nonetheless, we just revealed another statistic: $250 million in ARR from cloud security, VMs, and public cloud security. That’s a figure that puts us 25 times ahead of our next competitor.

Speaker 3

Super helpful color. Thank you.

Operator

Great, Thanks. So just a reminder, let's limit to one question. So next up is Fatima Boolani and on deck is Keith Weiss from Morgan Stanley.

Speaker 4

Thanks, Walter. Nikesh, maybe I'll start with you very quickly. You talked through a lot of the areas of strength from a product pillar perspective. But in terms of just zooming back, can you stock rank for us what specific product areas in the NGS portfolio really were the drivers of billings acceleration in the quarter? And then I have a quick follow-up for Dipak, please.

Yeah. As I highlighted, SASE is strong. Dipak highlighted the subscriptions are strong. We're pleased with the way Cortex is evolving, while cloud ends up being lumpy. So, some quarters we’ll get some very large deals, while in others they may be delayed. But across the board, the portfolio is performing in line with our expectations or slightly ahead, as we said, we hit 973 or 980, depending on how you count it.

Nice to meet you.

Operator

Well, we're going to take one question before moving on to Keith Weiss with Sterling Auty from JPMorgan.

Speaker 5

Excellent, thank you guys; Very nice quarter and thanks for taking the question. I think you guys are doing a very good job of illustrating that there's a difference between firewall appliances and more generally firewalling capabilities. And you're seeing that firewall as a platform growth, sustained really well, actually accelerating in recent quarters. I think that's probably one of the key areas that investors are most cautious on, is the durability of growth and firewalling. Can you talk to us a little bit about where you're seeing that strength from? Do you believe it to be durable over the next couple of years, and is there anything that we should be watching out for in terms of tough compares or any one-time items from a year ago period that might upset that growth trend that you've been seeing in firewall as a platform?

Well, I’ll make two points, Keith. One is, customers are looking for firewalling capability, and we can offer that solution either through software or with a deployment of hardware which is more costly, harder to maintain, and harder to upgrade over time. So take a large retailer, for example, deploying 1,200 firewalls in each store; they can choose to go hardware, which is costly and difficult, or opt for Prisma SASE, which is a software-centric solution with a lower total cost of ownership. As a result, we're creating a greater level of substitution in our customer base. Comparatively, we can grow ARPU at 38%. This indicates future revenue potential on the FWaaP front, something that will be harder for hardware-dependent businesses to achieve on a quarterly basis. Therefore, I believe there's more resilience in our network security approach than most hardware-dependent businesses. The second point is that customers are shifting from proxy-based architectures to a full firewall in the cloud. They are realizing they can improve their secure access capabilities with Prisma SASE and making that transition. We're very encouraged by the significant strides made on SASE from where we started 2.5 years ago. At that time, we had a product named GPCS and now we handle six substantial deals per quarter with many more queued up for the future. SASE is strong, which should assure us of continued strength. I think network transformation is in the very early stages; as customers witness the effectiveness of AWS, GCP, and Azure devoting $40 to $50 billion into quarters, they'll realize that relying on MPLS-based architectures to return to data centers doesn't make sense anymore; they require adopting SASE. We believe we have the best SASE solution in the market and feel we are positioned well because we hold more deployed customers at scale.

Operator

Great, Thanks. Next question from Sterling Auty and Saket Kalia from Barclays on deck.

Speaker 6

Hi. Thanks. It's fun to see Walter on the other side trying to keep us to one question after all these years. I want to follow up on Keith’s question as well on FWaaP. Help us understand what are the metrics that we should look at in terms of and you gave a little bit of this last quarter, but when look at your install base of the on-premise appliances, as some of that starts to transition to FWaaP, is that happening? And if it does, how is the dollar-for-dollar comparison? In other words, do your customers still end up spending more with FWaaP versus their traditional clients? Is it smaller or the same?

I'm going to bring in my colleague Lee Klarich, who spends a lot of his time ensuring these transitions work and we see those transitions happen, Lee.

Lee Klarich Board Member

Yes. Thank you, Nikesh. Good question, and actually last quarter we provided some insight into this, if you remember. There are effectively two transitions we see play out. One transition concerns the movement of applications from data centers to the cloud, where the form factor often changes from a hardware form factor to software form factors, VM series, etc. The other transition is based on how employees and users are moving increasingly off the network and soon adapting to a more hybrid state. In that case, they often shift from hardware to hardware plus cloud-delivered SASE architectures. Looking at these transitions, the net effect is generally positive for us in terms of overall spend from customers. There are some trade-offs; hardware migrating to VM-Series or cloud is relatively similar, while hardware through SASE usually results in an uptick in overall spend. This is because SASE includes a broader range of services that integrate networking components and global reach, thus increasing the overall spending envelope as more capabilities are incorporated into the services we provide to customers. So across the board, the trend appears favorable, and we've been tracking this for a few years to gauge performance.

Speaker 6

Great, thank you.

Operator

Great, thanks. Next question from Saket Kalia from Barclays, and then Matt Hedberg from RBC next.

Speaker 8

Okay, great. Thanks for taking my question here. Nikesh, maybe for you. Can you hear me okay, Walter?

Operator

Yeah.

Speaker 8

Okay, cool. Nikesh, that was helpful commentary on the equity structure around ClaiSec. I guess the question is what were some of the things that went into your decision to explore that last quarter, and then maybe reconsider it this quarter, and is it a matter of timing given the volatility in the market or would you say that the probability of exploring that down the road is still relatively low?

I think Saket as we went through the mechanics of creating all the paperwork required to file this. The debate began to happen with some of our shareholders, as they look at the true value creation, and whether they can take this and separate it. Mixing all this together creates issues since 70% of our customers are leveraging multiple platforms. Forty percent of our customers are incorporating all three platforms, which enhances our position with CIOs. When they experience a breach or ransomware, they seek a robust, unified solution from a single partner. Creating an artificial separation would undermine that value for us. This definitely played into the decision. I believe we still have to establish ClaiSec as a profitable, self-sufficient business to achieve a suitable scale in the future. It's too soon to separate them into distinct businesses as we are benefiting from firewall sales relationships, built over more than a decade, for better customer engagement.

Speaker 8

Very helpful. Thanks.

Operator

Great, thanks. Next question from Matt Hedberg from RBC, and then we've got Tal Liani from BofA next.

Speaker 9

Thanks, Walter. Hey, Nikesh, I wanted to talk about, all these recent breaches you alluded to President Biden, talking about the importance of Zero Trust. I guess, how do you think about that impacting your federal business later this year? And then also, as these breaches continue to accelerate in a post-COVID world, do you think you're going to be in a better position to consolidate security spending? There's always that debate on best of breed versus consolidation. Is this just going to accelerate your demand environment even more so?

Matt, what's interesting is, let's start with the second part first. Clearly, whatever approach was used to buy security hasn't worked. We have been historically in a best-of-breed approach. Companies end up with 35, 25, or even 40 vendors to stitch together a solution while that falls on them. Coupled with the two biggest technological transitions in computing history— the shift to the public cloud and network automation led by the cloud—CIOs are needing to reassess security holistically. I don't believe in many security companies capable of delivering best-of-breed solutions across multiple functions effectively; our firewalls rank among the top tier in their categories and we're the only native cloud security company to own a top-tier cloud security product. We can deliver great capabilities across five leadership points. We're providing the best of breed and stitched product arguments successfully. This makes us resonate greatly with customers during these trying times as they seek a reliable partner who can take accountability for security across their entire footprint.

Operator

Great. Thanks, Matt. Next up is Tal Liani with Keith Bachman from BMO on deck.

Speaker 10

Hey, I have an accounting question. Great results; ARR was better than expected, and some people were concerned about potential issues. However, I noticed that you changed the definition of ARR slightly this quarter in your filing. When I compare the language from this quarter to last quarter, it seems you included certain cloud-delivered security services in ARR. Could you quantify this addition? Was it significant to the numbers this quarter? Thanks.

I'll take that question. It's really not material to the overall; we added a couple of cloud-delivered technology solutions like IoT as one example, but when you add them all together, they remain relatively insignificant.

The early launches of our products were meant to ensure they fit in the right bucket. We can sell IoT against Cortex, and they reside in both our firewall business and our cloud AI business.

Speaker 10

Great. Thank you.

Operator

Next up is Keith Bachman, and then Gray Powell from BTIG.

Speaker 11

All right, thank you very much. Nikesh, I want to ask you to flesh out Cortex a bit more in terms of run rate and expectations. Feedback we've been getting from the channels is that Cortex is certainly doing better, and I was wondering if you could talk about win rates, where you're winning. Can you provide any insights on growth associated with the Cortex brand, whether it’s revenues or billings?

I can't give you a metric that we haven't disclosed, but I can tell you that Cortex comprises three products: one is XDR, which competes with players like CrowdStrike and SentinelOne. I think the challenge we have is that our product has been technically ranked better than CrowdStrike and on par with SentinelOne and others. The challenge is that we don’t cover as many deals as CrowdStrike does because they have eight times our dedicated sales force for the XDR category, so we strategically need to focus on where to invest. The good news is, where we compete, we typically don't lose. It does become a price point consideration and we don't concede easily on pricing. For XSOAR, it used to be Phantom; we’re experiencing minimal competition in that category. Customers that recognize they have this need will usually select XSOAR without competitive issues; it tends to be moderate-sized deals, though not as large as cloud deals which can reach eight figures. And within the Expanse access management realm, we are getting clients realizing the importance of a comprehensive picture of their exposure to vulnerability, especially after a breach or ransomware event. We’re seeing stronger customer engagements each time we respond to incidents. The establishment of Unit 42 has been beneficial; we are getting involved in more incidents, which leads to demand for XDR and Expanse services. Overall, we are starting to see more traction with Cortex, as evidenced by the growth of our customer base to 2,400. The primary opportunity for us is in growing our visibility in the market to close more deals.

Speaker 11

Right. Okay. Terrific. Thank you.

Operator

Thanks, Keith. Next up is Gray Powell from BTIG. And on deck is Adam Tindle from Raymond James.

Speaker 12

Hey, great. Can you hear me okay? All right. Thanks for taking the question. So yeah, maybe back on Prisma Access, what's been the reception with Prisma Access 2.0 so far? And do you see that product update with proxy capabilities getting Palo Alto into more traditional secure web gateway replacement deals or potentially improving the pace of new logo ads on the product set?

Yes. Look, we're really excited about the 2.0 launch a few months ago. We're getting great reception from customers for everything included in the launch. Remember, this is where we introduced cloud management, creating a cloud-native experience with easy onboarding and activation. This also introduced our first-ever Autonomous Digital Experience Management add-on module, which allows customers to monitor their end-user experience with applications they access proactively alongside our added proxy capabilities. The upgrade process has been smooth, and nearly all Prisma Access customers have transitioned to version 2.0. Close to 100 customers have adopted the cloud management solution within just a couple of months. The feedback on Autonomous DEM from early adopters has been fantastic and we are growing that pipeline consistently. The proxy capabilities were necessary for alleviating any objections, enabling those customers that require it to transition to Prisma Access comfortably. Overall, we are seeing strong customer engagement and satisfaction and are excited about the future growth of this offering.

Speaker 12

Okay. Great. Thank you very much.

Operator

Thanks, Gray. Next up is Adam Tindle from Raymond James and then Michael Turits from KeyBanc.

Speaker 13

Okay. Thanks. Good afternoon. Congrats on the results. I wanted to ask on profitability, whether it's Nikesh or Dipak wants to weigh in. You’re seeing deal sizes increase. You’re seeing cross-platform adoption, and those were helpful metrics for us. We typically associate those with very healthy contribution margins. You did talk about 50 basis points of operating margin expansion this year, but I wanted to ask beyond this. Do you think that this is something where you can build on and establish sustained margin expansion from here? You’ve referred to a 150 basis points annual expansion a couple of years ago at an analyst day; wondering about the challenges to get back to that level of margin expansion? Thanks.

I think the honest answer is it's pretty situational. Every customer deal is different and we are going to lean in if we need to maximize opportunity; however, I hope that as our portfolio expands and the complexity of the attack surface increases, the leverage will shift into our favor over time, aiding in margin expansion. In general, I’d reaffirm that it's always a focus area for us, and we believe that with scale, margin expansion will be attainable, but we do not want to close the door on growth potential. When I joined Palo Alto, growth was in the low 20s; we’re now at nearly 28. We believe we will see continued growth ahead, supporting considerations for reinvestment while we seek that leverage.

Just adding to that, Adam. I read your note and thank you for your recognition and upgrade. I noticed that you mentioned operating margin leverage and many have highlighted the two businesses. The Network Security is where you see leverage. We’ve strong free cash flow margins growing in Network Security, while NGS is also showing strong performance. The historical context of building a $735 million ARR business in just 2.5 years is noteworthy. This has been achieved with a considerable focus on go-to-market capabilities. If you benchmark against players like CrowdStrike, Okta, or Zscaler, you will note the inherent evolution which doesn’t materialize in two years. Do we believe leveraged growth is achievable in future years? Yes. It hinges significantly on whether we want to invest our sales force comprehensively to capture more deals or maintain a lower growth rate. Palo Alto Networks has never been in a position like we are now with product capability and market awareness. Our offerings resonate with customers, and health crises have increased demand for strong security solutions, encouraging customers to accept higher price points. Therefore, overall, I emphasize we remain focused on growth while also ensuring we don’t overlook margin improvement opportunities.

Operator

Thanks. Next question is from Michael Turits at KeyBanc and after that Patrick Colville at Deutsche Bank.

Speaker 14

Yes, thanks. Nikesh, I think one of the you know investment features here has been that you're the company most likely to balance, consolidate security, but to make that transition to software and to the cloud, and you're proving that out. But that said, you've also done a great job this year on the product/appliance side, up to 3% year-to-date versus what you got to do flat. So I’m just trying to get a sense for the dynamics of that in the next three calendar quarters. Do you think we could get a boost from refresh of what wasn't done last year and is there any constraint to that, if it's going to happen from supply chain components?

That’s a great question, Michael. The situation with supply chains is changing weekly. You can see variations play out regularly in the market. Like other players in the market, we have some inventory capability in place against anticipated demand, both in the short and long term. Ultimately, the market dynamics depend on meeting production needs and managing the ongoing demand. The bright side for us is that we've already transitioned around 40% of our firewall business from hardware to software, so if we encounter supply constraints, we may resolve customer needs by providing software solutions. We also have sufficient baseline availability of hardware units for the recent announcements for hardware launches. Overall, our strategy continues to trend towards software solutions while maintaining production for hardware customers.

Lee Klarich Board Member

While we're transitioning the business, there's still a robust market for hardware. The two new models launched recently scale up to 150 gig throughput with all security features enabled, 75 gig with full SSL decryption—making it an exceptional offering for large campus data center environments. Additionally, our four new appliances in the 400 series improve performance tenfold compared to earlier platforms we had. We consistently deliver leading security capabilities at price points that are competitive even against lower-cost vendors, which changes the dynamic in the hardware space.

I can’t get Lee to elaborate; he keeps indicating our leading competitors. I’ll reiterate that the value we provide in security is competitive.

Speaker 14

Okay, fine.

Operator

Last question here from Patrick Colville with Deutsche Bank.

Speaker 15

Thank you for squeezing me in. I was actually going to ask about new appliances because I think that's super interesting, but Lee covered it pretty comprehensively there. The questions we’ve been getting from investors over the last hour has been about the definition of changes to ARR. Do you mind just quantifying what the certain cloud-delivered security services, how much is that in Q3 versus Q2?

Let me get that cracking. When I said that it was de minimus. It's less than $5 million. So just as an overview to kind of assess the overall impact.

Speaker 15

Great. Very clear. Thank you so much.

Operator

Great, and that concludes the Q&A portion of the call. Thank you all for joining and asking your questions. We're now going to turn it back over to Nikesh for closing remarks.

Hey. I just want to take the opportunity to thank you all for joining our call. I also want to take the opportunity to thank the employees at Palo Alto Networks for all their hard work and dedication to allow us to produce these results. We are here because of what they do. So once again, thank you everyone. I look forward to seeing you in our individual follow-up calls.

Full-screen source Call document