Operator
Ladies and gentlemen, thank you for standing by. Welcome to Qualys' second quarter 2026 investor call. At this time, all participants are in a listen-only mode. After the speaker's presentation, there will be a question and answer session. To ask a question during this session, you would need to press star 1-1 on your telephone. You will then hear an automated message advised and your hand is raised. And to withdraw your question, please press star 1-1 again. Please be advised that today's conference is being recorded. I would like now to turn the conference over to Blair King, Investor Relations. Please go ahead.
Thank you, Michelle. Good afternoon and welcome to Qualys' second quarter 2026 earnings call. Joining me today to discuss our results are Sumetha Kaur, our president and CEO, and Jumi Kim, our CFO. Before we get started, I would like to remind you that our remarks today will include forward-looking statements that generally relate to product capabilities, future events, or future financial or operating performance. Actual results may differ materially from these statements. Factors that could cause results to differ materially are set forth in today's press release and our filings with the SEC, including our latest Form 10-Q and 10-K. Any forward-looking statements that we make on this call are based on assumptions as of today, and we undertake no obligation to update these statements as a result of new information or future events. During this call, we will present both GAAP and non-GAAP financial measures. A reconciliation of GAAP to non-GAAP measures is included in today's press release. And as a reminder, the press release, prepared remarks, and investor presentation are all available on the Investor Relations section of our website. With that, I'd like to turn the call over to Samed.
Thank you, Blair, and welcome to our second quarter earnings call. The adversary's playbook has been fundamentally rewritten by AI, collapsing exploit timelines and making one thing undeniably clear. Durable, pre-breach risk management increasingly requires a vendor-neutral, agentic AI fabric that moves beyond theoretical exposure to autonomous quantification of actual exploitable risk and remediation. Demonstrating this conviction, we delivered another quarter of strong revenue growth and profitability. The urgency behind that conviction continues to intensify. Frontier and open-source AI models are capable of discovering and weaponizing vulnerabilities faster than any human team can triage them, compressing exploit timelines to hours, and in some cases, turning disclosure into compromise before a patch even exists. AI is simultaneously becoming the greatest force multiplier and the most formidable challenge cybersecurity has ever faced. Where we part ways with continuous threat exposure management, CTEM solutions is how we respond to it. CTEM solutions today respond by generating more findings, more theoretical risk scores, and more dashboards, and then pass along these findings off to siloed solutions that collect data and do the patching while losing critical time at every handoff. That approach was already failing before AI accelerated the threat landscape, and it is fundamentally inadequate now. We believe that defenders who win in this new era of AI will not be the ones who simply detect more and more vulnerabilities and produce dashboard tourism. They will be the ones who can autonomously detect vulnerabilities at AI speed, validate actual exploitability in production, quantify that risk in dollar terms, remediate it, and then prove the exposure is closed in multi-vendor environments, all before an adversary gets there first. That is the design outcome of the AI-native risk operations rock powered by our enterprise to risk management ETM solution, and it is where nearly every customer conversation we are having is heading. Against this backdrop, I am pleased to announce major new capabilities on the platform we'll showcase at Black Hat later this week, spanning both AI for security and security for AI to address the post-method threat landscape head-on. First, with respect to AI for security, we're pleased to introduce InstaScan, powered by Agent Insta, the newest addition to our agentic AI marketplace and ETM solution for AI speed detection that is continuous, instantaneous, and scanless. Today, when a new vulnerability advisory is released, it takes 24 hours to a week for organizations to detect it through traditional scan cycles, while adversaries weaponize the same vulnerability in minutes. Agent Insta is designed to collapse that timeline by converting the asset inventory software paths and threat intelligence our customers already collect with Qualys sensors into high-confidence exposure findings without a scan. New detections appear within minutes of disclosure, and no rescan required and no agent disruption. The finding is then handed to Agent Val for instant exploit validation, and the risk impact is determined and quantified immediately. While competitors are still processing an advisory, writing signatures, and waiting for a scan to complete, our customers already know whether they are exposed and are taking action before a vendor patch exists. Because the finding flows straight into validation and remediation, detection is not a report. It is the first step of a continuous closed loop. With last quarter's launch of true conformant agent, while safely validating actual exploitability across chain attack paths in live production environments and hyper-prioritizing millions of findings to the fewer than 1% that require immediate action, the bottleneck is now shifting from identifying what to fix to actually fixing it before adversaries can act. This leads me to the next phase of our True Risk Eliminate agenda, autonomous zero-day remediation at scale. Through AI-scored autonomous remediation waves, the AI-native ROC now determines the right action for every asset in multi-vendor environments, deploying a patch, staging a control rolled out where concussion is warranted, or applying a compensatory control where operational risk demands it. Every action is gated by our AI-driven patch reliability score and resiliency snapshots, delivering rollback rates below 1.5%, below half of 1%. The most critical assets remain human-in-the-loop oversight while the platform autonomously remediates the rest. Orchestrating the cycle is Agent Sarah, who prioritizes exploitable risk, quantifies it in dollar terms, sequence continuous waves, and revalidates closure with Agent Val, all without proportional headcount. Furthermore, with the introduction of peer-to-peer patching, we are accelerating the delivery across distributed environments while removing the dependency on centralized infrastructure. Put simply, these newest innovations make autonomous zero-day remediation, wave-driven, vendor-agnostic, safe, and provable. In live benchmarking, this collapsed the window of exposure from 21 days to minutes and auto-patched 60% of the vulnerabilities. This is not incremental. It turns a massive surge in exploitable vulnerability volume from an impossible backlog into a continuously clear queue at the speed of modern attacks. You cannot solve a minutes problem with a month-long solution. And that's the gap the AI Native Rock was designed to solve with Agent Insta, providing AI speed detections, Agent RAL hyper-prioritizing validator exposures, and agents that are performing autonomous remediation in a continuous closed loop. Turning to security for AI, as enterprises raise AI workloads into production, the AI infrastructure they are building is already the next attack surface. With the introduction of local AI 2.0, organizations can now see their full AI estate from workforce to workload and from code to runtime. Through new sensors that see AI activity at both the employee and workload level, security teams can now discover shadow AI activity across the organization, from what employees are doing with AI to which models, endpoints, and services are running in production across hybrid multi-cloud environments. We have also extended our posture management coverage to SaaS platforms, including Anthropic and OpenAI, to help organizations enforce security and compliance policies across the AI platforms their teams are already using. Additionally, they can now identify security gaps in code before deployment, remediate with Dart Rails at runtime, and test model context MCP tool exploits across over 50 adversarial scenarios. And of equal importance, every AI risk across the entire stack from GPU to infrastructure to supply chain to the newest prompt injection attacks is now scored and prioritized through the same true risk engine that powers the risk operation center. For organizations seeking to secure the infrastructure, powering their AI future, these new innovations become an increasingly strong differentiator for Qualys. As ROC adoption accelerates and these capabilities continue to compound, we remain laser focused on driving ETM adoption throughout our VMDR customer base and positioning Qualys for larger upsell opportunities over time. Moving to our business update, with customers spending $500,000 or more with us growing 8% from a year ago to $229,000, let me share a couple of recent wins which illustrate why organizations are turning to Qualys to help unify their security stack and operationalize The first is with an existing global 300 customer managing a complex data-intensive environment spanning on-prem multicloud and rapidly growing LLMs in production. As the volume and velocity of vulnerabilities across the environment accelerated, their teams recognized that prioritization based on theoretical risk scores couldn't deliver the business context needed to act decisively. With fragmented telemetry, disconnected tools, and little automation, their teams were spending more time documenting risk than reducing it, while unpatched assets and shadow IT were silently extending exposure windows by once. As a result, the customer chose Qualys to operationalize their ROC, adopting VMDR, ETM, True Risk Eliminate, and Total AI alongside several other modules in a low seven-figure QFlex annual upsell. By consolidating Qualys and third-party data into a unified risk fabric, this customer has aligned risk reporting to the board's tolerance level, shifted remediation from manual processes to autonomous workflows, and reduced its exposure window from months to hours while flattening the hiring curve and delivering better security outcomes. This is also an outstanding example of how we are leveraging our channel partners to activate the ROC to win new business. The second is with a European healthcare company that has been a small existing scan on behalf of Qualys customer but was relying on a managed service provider to run their broader vulnerability program across more than 140 locations. That model delivered people and process but not autonomy. Scan operations, prioritization, and remediation guidance all flowed through the provider's team on the provider's timeline, leaving the customer dependent on external resources to understand and act on its own risk. As this environment grew more complex and vulnerability volume surge, the limitation of that dependency became unsustainable. Costs for ballooning remediation cycles for the customer had limited visibility into the varied data driving the decisions made on its behalf. This customer chose Qualys, consolidating its stack into the Qualys platform by adopting VMDR, ETM, and True Risk Eliminate in a six-figure QFlex upsell. Rock automation was the entry point and remediation was the immediate proof of value. By unifying detection, prioritization, and autonomous remediation into a single AI-native workflow, this customer has replaced a manual people and process dependency with a platform that delivers significantly lower cost, less complexity, full control, and peace of mind for the CISO. These wins reflect the broader ETM momentum we are starting to see as more and more customers recognize the efficiencies and scale of AI-native ROC automation. Further supporting our growth trajectory, QFlex continues to gain traction as another strategic lever for accelerating ETM adoption. As we heard in the customer wins I described earlier, QFlex played a direct role in enabling significant upsells for Qualys by giving these customers the flexibility to commit broadly across the platform while preserving the ability to shift investments as their needs evolve. This precisely the value proposition of QFlex model was designed to deliver. Building on strong results from our initial rollout, we have now taken QFlex live for enterprise customers, looking to expand with Qualys and believe it can become an increasingly important driver of platform expansion over time. Turning to our executive team, with the recent departure of our CISO and general manager of our ETM business, I want to address how we are positioning for continuity and acceleration. To lead product strategy and our ETM business going forward, I have appointed Shailesh Atle as our chief product solutions officer, a nearly 14-year QALIS veteran who has served as our SVP of products for the last five years. Shailesh has been instrumental in shaping many of the platform innovations we discussed today, and his deep institutional knowledge of our technology, our customers, and our roadmap makes him the natural leader to drive the next phase of ETM adoption and our customer-led growth strategy. Additionally, I am pleased to welcome Nathan Smolenski as our new Chief Information Security Officer. Nathan is a seasoned cybersecurity executive with over 24 years of experience driving security transformations across financial services, insurance, and high-growth CES environments, most recently serving as the global CISO at Syrah. We are excited to have both Shalish and Nathan in these critical roles as we continue to scale our platform and accelerate ROC adoption. In summary, Qualysys continued innovation spanning both AI for security and security for AI, growing AI-native ROC adoption powered by our ETM solution, a growing federal pipeline for new business opportunities, strong partner-led execution, and promising early QFLEX engagement continue to reinforce the demand we're seeing for a unified risk management platform that anonymously moves beyond theoretical exposure to validated, quantified, and remediated risk at the speed of modern attacks in multi-vendor environments. We believe these achievements not only advance our strong competitive differentiation, but also sharpen the market opportunity ahead of us and bolster our confidence in re-accelerating long-term growth in the business. With that, I will turn the call over to Junie to further discuss our second quarter results and outlook for the third quarter and full year 2026.
Thanks, Meg, and good afternoon. Before I start, I'd like to note that except for revenues, all financial figures are non-gaffed and growth rates are based on comparisons to the prior year period, unless stated otherwise. Turning to second quarter results, revenues grew 11 percent to 182.2 million. As a result of a strategic emphasis on leveraging our partner ecosystem to drive growth, the channel has continued to increase its contribution, making up 54% of total revenues compared to 49% a year ago. Revenues from channel partners grew 22%, with revenues from direct remaining largely unchanged from Q2 of last year. IGEO, 15% growth outside the U.S. was ahead of domestic business, which grew 8%. The U.S. and international revenue mix was 55% and 45%, respectively. In Q2, our overall upsell execution improved with our net dollar expansion rate at 105%, up from 104% last quarter. The net dollar expansion rate of customers with prior year purchase of ETM or CSAM subscriptions in Q2 was 107%, consistent to last quarter. Moving on to product mix. Our differentiated new products continue to drive growth. First, ETM CSAM combined made up 12% of total bookings and 14% of new bookings on an LTN basis in Q2, up from last year's 9% and 10% respectively. Next, patch management made up 9% of total bookings and 16% of new bookings on an LTM basis in Q2. This compares to 7% and 16% respectively in Q2 of last year. Lastly, total cloud made up 5% of total LTM bookings in Q2 and changed from a year ago. We believe that these differentiated products combined will increase contribution to bookings in 2026, given our opportunity to increase market share and maximize share wallet. Reflecting our scalable and sustainable business model adjusted EBITDA for the second quarter of 2026 was $83.8 million, representing a 46% margin, compared to 45% last year. Operating expenses in Q2 increased by 8% to $73.2 million, driven by investments in sales and marketing, which grew 14%. With a strong performance, EPS for the second quarter of 2026 was $1.98 per diluted share, and a free cash flow was $55.9 million, representing a 31% margin compared to 20% in the prior year due to fluctuations in working capital. Normalizing for this, first half of the 2026 margin was 42% compared to 43% in the prior In Q2, we continue to invest the cash we generated from operations back into QALYS, including $3.7 million in capital expenditures and $76.8 million to repurchase $797,000 of our outstanding shares. As of the end of the quarter, we had $229.8 million remaining in our share repurchase program. With that, let us turn to guidance, starting with the revenue. For the full year 2026, we now expect revenues to be in the range of $732 to $738 million, which represents a growth rate of 9 to 10 percent. This compares to prior guidance of 721 to 727 million. For the third quarter of 2026, we expect revenues to be in the range of 185.5 to 187.5 million, representing a growth rate of 9 to 10 percent. This guidance assumes their net dollar expansion rate remains at current levels with moderate growth contribution from new business in 2026. Shifting to profitability guidance, for the full year 2026, we expect EBITDA margin to be in the mid-40s, with a low teens increase in operating expenses and free cash flow in the low 40s. We expect full-year EPS to be in the range of 7.74 to 7.88, up from the prior range of 7.44 to 7.65. For the third quarter of 2026, we expect EPS to be in the range of 1.91 to 1.90. Our planned capital expenditures in 2026 are expected to be in the range of $8 to $12 million, and for the third quarter of 2026, in the range of $1 to $2.5 million. With that submitted, I would be happy to answer any other questions.
Operator
Thank you. As a reminder, to ask a question, please press star 11 on your telephone and wait for your name to be announced. To withdraw your question, please press star 1-1 again. The first question comes from Kingsley Crane with Canaccord. Your line is now open.
Great. Thanks for taking the question, and congrats on amazing results. Sumed, look, the volume of AI-generated vulnerabilities, it's a clear reason why customers need InstaScan in the ROC. Can you just double-click again on how this is showing up in pipeline, how this is showing up in urgency, and then if CVE volumes were to double again, how could you capture that in your per asset pricing model?
Yeah, that's a great question. And I think even though the disclosure findings are increasing, I think the organization's ability to remediate is what is currently being looked at, right? And that's really where our focus has been on helping these customers with autonomous remediation, because at a very high level, you cannot go and tell your management as a security leader that you are going to respond to autonomous AI exploits with more manual tools that are emailing each other on what needs to be fixed, et cetera. And so if you look at sort of the risk operation center and what we are focused on is Agent Sera is already helping with the autonomous remediation piece. But to do a great job with that and with high confidence, you need to significantly hyper-prioritize your findings, and that's where Agent Val on the Risk Operations Center platform is helping run actual exploits to reduce the number of findings that need to be auto-remediated that actually matter to the business. And then now our latest announcement yesterday of Agent Insta, which is the ability to scan instantaneously whenever new advisory comes out, now shrinks the timeline from the advisory coming to the timeline when the vulnerabilities even detected in the customer environment. And so with all three of these on the ATM platform, you now actually have a real path to get something that is important and exploitable in your business that are mediated within the first 24 hours with minimal human intervention. And that is the conversation that everybody is having is that they need to go have conversations internally to say how are we going to move towards a roadmap that allows us a feasible autonomous remediation plan and the ETM is enabling that. And so we, of course, have been ahead of this, as you know, for the last few years with creating autonomous simulation capabilities. And so we already had a few customers in the pipeline who were discussing with this, who saw this beforehand. And so the conversation with PostMethos is helping, helped us accelerate a couple of these opportunities. opportunities. However, there's a large number of customers that are very, very curious now about what they can do and what is the art of the possible with this kind of autonomous remediation. And so we're very excited to see that pipeline in terms of the conversations, in terms of POCs is looking good, and we're happy with that. And of course, we have to now move forward, get the POCs done, look at the budget, see when they will close, et cetera. But I would say with all the innovation and the investment that we've made, we're pretty excited to see the current conversations that we're having.
Great. And then just to follow up for either Sumed or Jumi, building off of that, you know, billing through 16%, it was a really sizable raise. On top of a broad base beat, we're now talking about re-accelerating long-term growth. Is it that the conviction in the business hasn't changed and the market has come toward you this quarter? or could you help us understand how much more bullish you are on the business today than you were three months ago?
Look, I think we always sort of were ahead of this with remediation, et cetera, and so the conviction that this is what the market is going to need and the investments that we put in before that has always been there. I think right now with the advent of AI, it's just accelerated what we are sort of seeing was going to happen at some point. And so that's sort of driving – the conversations are driving us to feel like because of the investment we put in the platform, these are solutions that actually can help customers right now in what they are looking for to set up as auto-remediation capabilities for the future. So, I mean, I will say that a lot of that goes to us being able to see where the industry is going to go and putting the investment behind it. and now positive conversations with the customers are kind of helping us get through to ensuring that we can actually work through to see how these opportunities can close. Thanks so much. Congrats.
Operator
Thank you. And our next question is going to come from Jonathan Ho with William Blair. Your line is open.
Hi, good afternoon, and congratulations on the strong quarter. I wanted to understand a little bit better. When you talk to your customers, about sort of their change in, you know, the exposure risk management process, can you maybe help us understand how much of this is that they need to cover more assets, you know, versus the fundamental patch management process changing, you know, versus having, you know, sort of the rock part of this on the managed side? You know, can you just maybe unpack that for us a little bit in terms of what they're buying and also what they intend to buy over time? Thank you.
Great question. I think at the end, what they are focusing on is, can I remediate the thing that actually matters to my environment as fast as possible, right? And that includes all assets in their environment, but that doesn't necessarily mean that they don't have other products that might be helping them get some visibility through acquisitions, this, that. And I think that's where if you look at our strategy around ETM and what we have done with the concept of a ROC is that the ROC is a multi-vendor solution. So it gives us the ability for the customers who are leveraging Qualys to have capabilities like Instascan where we can instantaneously detect things. We could do the same on data collecting from other scan-only products that are just throwing a bunch of CVEs. So we are seeing with ETM that it is allowing us to expand licenses in the early POCs that we have with some of these customers in the early purchases. They are also bringing data on other tools from outside of Qualys into the ETM solution so that they can get a holistic view across multiple tools and then prioritize the ones that really matter, run the exploits, and then get into the remediation piece. So I think it's the focus on adding on the patch management and eliminate capabilities is one aspect. And then with ETM broadening the coverage of how many assets that they should look at to make sure the remediation succeeds is helping us that even if they have some other scan-only CVE detection tool, which is producing a lot of false positives, we can all still bring that license as part of the Qualys ETM solution.
Excellent. And just given the relative proximity of Mythos, when do you think the bulk of the spending will start to materialize? I'm guessing we haven't seen it yet. I just wanted to get your sense for, you know, how you think this is developing with the pipeline.
Yeah, I think, you know, it's the same that we had talked about when Lock4J came out and SolarWinds and stuff. Look, our customers typically tend to be enterprises, organizations that are more thinking of long-term changes in their security programs and less about the knee-jerk reaction of, you know, immediate spending. and that's kind of what we're seeing right now as well. A lot of these conversations are CISOs looking at the ways to use this post-methods threat landscape to make the point to the team's internal stakeholders on long-term sustainable changes that they can make to their security program where it's not that you do this one thing for the one month. For companies to roll out a program that allows them to do autonomous remediation, That's where they need to think through, work with different stakeholders, and then look at the budget. Does it come from an existing solution that they can get rid of? Is it something that they need to add on, et cetera? So I think we are early on. We feel like in these conversations, and we will see as the next few quarters goes to see what meaningful signals come in terms of when these budgets might be leveraged otherwise. But so far right now, it's a lot more of positive conversations and pipeline building. Thank you.
Operator
Thank you. And our next question will come from Patrick Colville with Scotia Bank. Your line is open.
Thank you so much for having me on. I guess let me just ask Sumed a question first, and then, Jimmy, I'd like to ask you one after, if possible. Great to see the guide to med, you know, fiscal year guide being raised from 8% to 10%. And then in your prepared remarks, talking about re-excelerating growth in the long term, I guess, can I ask, one question is like, I think that's new disclosure. I don't think you've said that before. Can you just clarify that that is new? And then what gives you confidence, if it is new, to say that now? Is it stuff you're seeing or just conversations or just kind of help provide some color around that?
Yeah, I wouldn't say it's new, Patrick. I think we always talked about investing and innovating in the platform and our belief that what we're doing and helping with the focus on remediation is something that we've been working on strategically, you know, along with a focus on federal and along with focus on working with our partners to focus on that acceleration of growth in the long term, you know, getting into long-term double-digit growth has been a focus for us. So, I think that is not new, so to say. I would say that given the current conversations that are happening, you know, it just gives us an opportunity again to talk about what we have already built and the innovations that we have already done and see how this maps to the current focus that the market has in terms of, look, at the end of the day, the CISOs need to be able to go tell their board and management somehow that they are going to adopt some form of autonomous remediation. And so they're going to have to figure out how they're going to do that. And if you look in the market, you know, with Qualys having 150 million patches deployed in the last 12 months, 40 million of those already being deployed autonomously, that gives us an interesting conversation point to build confidence for them when they're looking at these things. And so right now, you know, it's the same sort of what we've always talked about and focused on is working towards innovating and investing to create long-term growth and double-digit revenue growth is what we've always been looking at. And so this is just continuing on that momentum.
Okay. Very helpful, Shumet. And Jumi, if I may, the disclosure about new bookings, So 14% of new bookings were from ETM and CSAM, which, if my model's correct, that's the same as last quarter. And then 15% of new bookings from patch in 2Q, again, if my model's correct, that's the same as last quarter. So I guess totally understand all the kind of quality of the commentary around ETM and patch. shouldn't like how come it's not showing up more clearly in that new booking number and should we expect that proportion of new bookings to etm and csam and patch to increase as we look towards kind of 3q and 4q yeah in terms of the percentage contribution to bookings from new customers we do anticipate fluctuations um we're not too surprised whether it goes up or down so if you take a look at the percentage that made up from patch management last quarter was 15, this quarter
is 16. You're right on the ETN side, ETN CSAM, it's 14, the same as last quarter. We're not too surprised by it because it really depends more on the customers who are onboarding at that point in time, what they end up starting off with. So for example, if we have a new prospect that decide to purchase more of that or spend more of that budget on VMDR versus ETM versus cash management, we want to make sure that the customer is set up to succeed and grow with us. And so this percentage, it's a healthy percentage. What it lends itself to for us is it's really a validation that when we land new logos, go after the market, and when we're able to win, it's partly due to the fact that we were able to innovate and lead the market in terms of our continuous enhancement and our product solution set with ATM, CSAM, as well as patch management.
Operator
Thank you. And the next question is going to come from Rudy Kessinger with DA Davidson. Your line's open.
Hey, guys. Thanks for taking my questions and congrats on the showing results here. You know, I guess if I hear what you're saying in that, you know, the myth of stuff is more so still in the pipeline and conversation stages, and that wasn't really the driver of the quarter. It sounds like more so just better ETM execution, but certainly seeing those demand trends, I guess, and your goal is to accelerate growth going forward. I guess, are you guys more willing to maybe, you know, utilize some of that margin and put that to work and maybe take margins down a bit further to help drive that accelerated growth? Or how should we think about the growth profitability tradeoff, you know, into next year?
Look, I think we always look at, we've talked about this, we always look at investing in the innovation, investing in our sales and marketing as we have been doing more recently. and I think we are, you know, we always focus on ROI and we see the opportunity ahead of us and as the opportunity is moved through the pipeline, it is something that we continue to evaluate, but at this point we feel good about kind of the investments that we're making and I think as we see the opportunity, we will continue to evaluate that to make additional investments.
Right, and to double-click on that, part of the reason why we're able to accelerate the top line growth currently without necessarily having to double dip on the investment is the fact that we are a partner first partner-led growth momentum right now with majority of our growth especially when it comes to new local acquisitions we're working very with our partners and we are we believe that we are investing appropriately at the current levels with the sales and marketing expense going up by 17 in q1 and 14 in q2 in the second half we're anticipating further acceleration in the investments into sales and marketing.
Got it. Then for my follow-up, current calculated buildings was really strong in the quarter. Anything to call out there as far as, you know, maybe early renewals or anything like that that drove the better sequential and year-over-year on CCB in Q2? And then for Q3 in the full year, just any directional commentary on CCB growth expectations?
Yeah, Q2, from a current billings perspective, there's always naturally quarterly fluctuations. So I would point to the LTM, which has smoothed out some of the lumpiness in the current billings growth rate, which is still an acceleration. As of last quarter, it was 8.5% on the LTM growth, and then this quarter it's at 10%. We're very pleased with the growth. And because of that, we decided to increase the revenue growth guidance. In terms of the second half current billings growth, we're still anticipating for the baseline 7% to 8%, which implies the full-year current billings growth in line with a revenue growth rate of 9% to 10%.
Super helpful. Thanks, and congrats again on the results.
Operator
Thank you. And the next question is going to come from Junad Siddiqui with Truist. Your line's open.
Thank you for taking my question. So Matt, Truth Confirm appears to be a powerful tool for ETM by helping customers validate which vulnerabilities are actually exploitable in their environment. Is that becoming like the land motion for ETM?
You know in other words once customers see exploit validation reduce thousands of findings to a handful of truly exploitable risks how often does that conversation expand into broader ETM remediation and risk quantification deployments that's a great question I think you know when you look at the entire vulnerability lifecycle to be successful with that you know there's a three bucket side which is detection as fast as possible and that's where our innovation with agent insta which I call I like to call scanless scanning the ability to post the detection in less than one hour make it possible for you to get that visibility of what might be exposed however just based on what is exposed from a vulnerability perspective you know doesn't give you the confidence that this is actually exploitable and not exploiting the environment because you have other tools that you might have put in place and so we definitely see that with true conform it's a differentiator there are a lot of quote-unquote CTIM solutions that are just aggregating findings and giving you a theoretical score but that theoretical score doesn't necessarily tell you whether it is actually going to be exploitable or not so when we are able to tell the customer look at the ETM solution will help you theoretically reduce your findings to the 1% that matter and then additionally you can run these lightweight safe exploits to further reduce the number of findings that actually will work in your environment that becomes a very interesting conversation because why is that interesting because now that you have reduced the number of findings you It makes autonomous remediation, which is the next thing that we are selling to them, really plausible. If you tell somebody that you're going to fix a million vulnerabilities autonomously, that's a very hard conversation. But if you can show to them that highly validated 70 vulnerabilities are the ones that we are going to fix with automation because they are confirmed exploitable and we cannot wait for attackers to exploit them, that conversation becomes a lot better. And so TrueConfirm is definitely a key part of the conversation, especially with our existing VMDR customers who are just getting great scanning. Now the ability to upgrade to ETM and then run the validation, which then encourages them to look for the Eliminate, which is the remediation kind of fits and makes all these pieces work together really well. And so it is an important piece of every conversation we are having with existing customers.
And just as a follow-up, could you just help us understand the behavior of, you know those customers that have not yet adopted etm like those vmdr only customers are you still experiencing a high amount of churn there and is that kind of like still the primary source of any pressure on your overall uh and the dollar attention rate i i think nothing to call out we're pleased with the overall momentum of the business and it's we look at that as a great opportunity for us to talk to our existing vmdr customers because all of them are going to have to answer to their management and board what they are doing to find a way for autonomous remediation. And so the conversation of upgrading to ETM and the conversation of upgrading and adding on Eliminate, we look at that VMDR customer base as a big base that we have where we can actually create growth opportunities because almost everybody is going to need some sort of a prioritization and remediation solution moving forward after the post-methos era. So that's actually a pretty good way for us to look at it. I think less and less customers will, I mean more and more customers I would say would want to look at a solution that's not just scanning but also giving them remediation and that's what we're seeing in the conversations right now. Great, thank you.
Operator
Thank you. And the next question will come from Joseph Gallo with Jeffries. Your line's open.
Hi, this is Grant Darling on for Joe Gallo. but thanks for taking the questions. I wanted to ask first, have you seen anything different competitively post-Methos release? It seems like we're hearing more chatter from a variety of players who are signaling more interest in the space. So your results certainly signal strength, but just curious if you're seeing or expecting any change in competitive dynamics, and also if there's any difference in the frequency of competitive displacements to call out.
Well, I think the problem the customers have is the chatter. There's too many solutions that are just throwing more and more CVEs, CVEs, which is kind of something that they're focusing on, and that creates a lot of chatter and noise for customers that they have to weed through. And so where we are seeing success is not just the traditional, hey, let's find a million CVE findings. Where we are differentiating and why we are seeing that differentiator is things like true conform, right, where we're basically able to not just tell you the CVEs there, but actually I have the ability to find a way to give you confidence in its exploitability by actually exploiting it in some cases, giving you additional information in other cases. Our autonomous remediation, while there's a lot of tools that are throwing out CVEs and tools that are saying that they can find something and then they will email the patching solution what they need to fix, we're actually natively patching that in a matter of hours. And so the interest is more to say, oh, wait, there is a solution that can actually allow me to fix and exploit and expose vulnerability in four hours from the release versus I'm going to have a hodgepodge of these different solutions that is not actually going to work in the environment. And so I think that's really kind of what's driving the conversations right now. And that's what we're excited about.
Got it. And then maybe for my follow up, you know, you've referenced the growing federal pipeline a few times. I guess just any way to quantify the size of that business today and then just any more detail that you could provide regarding your thoughts about that opportunity and maybe your right to win there going forward.
It is right now not a big part of the business, but that is where the opportunity lies right now. I think if you look at the focus of the current administration, if you look at the new SISA board, very interesting that the new SISA board really talks about fast detection, exploit validation, and quick remediation. I've heard this somewhere for the last two years, right? So we focused on building this and being ready for this. And so the federal government is also very, very focused on ensuring that they are seeing outcomes, which are, you know, CISA's new requirement of remediating in 72 hours, okay? How are you going to remediate something if your scan is taking two days? That's where InstaScan is going to help you find the issue in the first 60 minutes, giving you a realistic chance to meet the BARD requirement. And so that is creating very, very positive conversations with the federal customers that we are engaged with. A lot of them have very old school, traditional on-prem solutions for scanning, different solutions for patching. They've been trying to patch those together for a while. And now these Bards and the focus from the administration is giving them an opportunity to look at something that is more modern and something that is really helping them give an outcome that is measurable. And so now with Qualys having a FedRAMP-HIGH platform that actually is the only platform that can do both the detection and the patching as a FedRAMP-HIGH solution and our modern approach with agentic AI capabilities built in with these three different agents or it's just sort of having one generic agent that is just talking in the back end to Anthropic or something like that, it creates a big differentiation in our mind. And I think that gives us the opportunity to go out and the right to have these conversations and work towards winning some of these opportunities that are coming our way. And so for us, given that right now it's not a big material part of the business, is where we see the big opportunity moving forward. and we're excited about the conversations and the investments that we're putting behind that.
Operator
Thank you. And the next question is going to come from Joshua Tilton with Wolf Research. Your line is open.
Hey, guys. Can you hear me? Yes. Awesome. Apologize for the background noise. I am in Vegas for Black Hat. Maybe just two quick clarifications. First one, Jimmy, I think you said you still expect 7% to 8% part of billing through up to the year. um can you help us understand like you know why that stands or is unupdated from i guess what you expected last quarter given the strong building's growth in 2q is it a conservative thing is it a 2q is a blitz type thing um just help us help us understand why that that full year outlook is left uh unchanged maybe i'll just i'll ask my second question now anyway you can help us understand, you know, what net dollar retention rate is baked into the full year guidance, since I think it's the second quarter now that it's kind of picked up for us.
Yeah, to clarify, the current billings guidance for the full year is now in line with a revenue guidance of 9 to 10 percent. So, the 7 to 8 percent is for the second half current billings. So, what we're assuming is for the baseline, the second half current billings will grow by 7% to 8% year-over-year, and that's predicated on no meaningful change to our net dollar expansion rate, which is now at 105% versus 103% that we started off the year at.
To be clear, the current billing is 7% to 8% is for the second half, you're saying?
Okay. Super helpful. Thank you.
Operator
Thank you. And the next question will come from Mike Sickos with Needham. Your line's open.
Hey, thanks for taking the questions here, guys. if i could just pick up on where josh was leaving off there um i think even earlier this year we're talking about a soft guide for that seven to eight percent ccb in calendar 26. just given the year-to-date out performance we've seen why not tweak that ccb even for back half of this year at seven to eight percent why not take that slightly higher again we're coming off this mid-teens result you just posted in q2 it doesn't seem like there was any real fluctuations from early renewals. So can you just help us think about what your assumptions are in deriving that 7-8% in the back half?
Yes. Quarterly current billings, because we don't actively manage to it, it tends to be lumpy. And so if you take a look at it on an LTN basis, that's what we like to point to if you're trying to gauge the business momentum. So on an LTN current billings growth rate, last quarter it was at 8.5%. This quarter it's currently sitting at 10%. And so what we believe right now is, look, it's great that we see the acceleration and the LTM current billings growth rate. And I think that that 10% better reflects the current business momentum today. And as Suna commented on before, we didn't know exactly when the acceleration or heightened kind of pressure from our existing customers who are already pretty far along the discussion of ETM adoption. We're really going to execute on those deals. And Q2 is a reflection of that. If you were to take a look at our customer base and take a look at them and split them into two different camps, there were already a smaller cohort of customers that were pretty far along in the discussion around the ROC adoption, upgrading to ETM, that ended up translating into a better than expected results in Q2. But that said, the second camp of customers that are not as far along in discussion, what we're anticipating right now is we're not seeing any significant increases or acceleration in the sales cycle for the cohort of customers that are up for renewal in the second half. So given that, it's a data point Q2 very strong quarter.
We're not anticipating any meaningful material changes in the deal cycle in second half, and so therefore we decided to keep the baseline at seven to eight percent for the current billing growth for the second half of this year thank you for spelling that out jimmy and maybe another one here just wanted to get a better sense um it was great to see the last 12 months uh net dollar expansion improved by a point again this quarter to 105 uh especially since you have this improvement for total company meanwhile the etm CSAM NDR was unchanged sequentially at 107. Can you, I guess, provide any further granularity, almost like a quarterly snapshot here, as far as what was driving the total company improvement from products or cohort of customers adopting or increasing spend? I'd just love to get a little bit more on that.
Yes. If you take a look at our product mix, that'll help you to kind of come with us in this journey of different product adoptions and as customers come up for renewal where they decide to spend more on. So right now with our ETM and CSAM currently making up 12% of total bookings up from 9% a year ago period, that kind of tells you that that's really helping to drive the bookings growth momentum that we see in the business today. Patch management definitely contributed to that as well currently at eight percent a year ago um it was at 70 and then offsetting that was the vmdr contribution coming down to 49 um down from 54 a year ago excellent thank you so much thank you and the next question will come from brian essex with jp morgan your line's open great good afternoon thank you for taking the question um i guess It's ASF2, I think both for Jumi.
But I guess, Jumi, I'd love to – it's great to see the traction that you've got on the partner side of the business, on the indirect side. But I would love to kind of understand where you're guiding spending, particularly in sales and marketing, but for OPEX overall. I think, you know, last quarter you talked about mid-teams growth. It seems like you're pointed in the same direction, but you've come in well under that for the first half of the year. But I'd love to understand, you know, where are you seeing traction? Where might you regulate greater spend? And, you know, what might, outside of our performance on the top line in the back half of the year, you know, how are you regulating spend on OPEX and sales and marketing relative to that mid-team level when we've come in material below that in the first half? And then I got a follow-up.
Yeah, on the sales and marketing spend, majority of that spend increase is driven by the headcount. So if you take a look at the 17% year-over-year for Q1 and 14% year-over-year for Q2, both quarters, majority of it was basically investing back into our business, expanding our team, making sure that we have the right team members and the GTM team, whether it be sales or marketing or product, all across the board that's really focused on selling our product and better positioning yourself and working very closely with our partners. Now, with that said, we are leveraging AI back into our business as well. And that certainly helped to make sure that we're looking at the operating efficiency, making sure that it's appropriate level of investment that we're spending each quarter. And so with that in mind, we're very pleased with the momentum that we see today. And we do anticipate increasing spend, whether it be number one is always going to be headcount for us right now for 2026.
But there are other certainly investments that we're making which is uh demand making sure that we're we're investing that for this and to generate sufficient pipeline that's quality that we can execute on for the second half of this year okay great that that's helpful and maybe just how how far penetrated are you into your installed base with qflex and how are you regulating the level of availability um that customers might have for qflex are you still measuring it and keeping it kind of like the high-end customers or could we expect maybe a broader rollout as you develop more experience with QFlex across your customer install base?
Yeah, we have rolled out QFlex. It's really more intended for our enterprise customers, and so now it's available, generally available to enterprise customers, and we are having appropriate level of discussions with the set of customers that are up for renewal, as well as new prospects, as we discuss with them what they're looking for, is Q plus something that's going to be advantageous to them. And really, if you think about this product, it's a premium product, right? It helps the customers really adopt a number of our solutions in a seamless way. And so they're more than willing to pay the premium price for this. And the way that we think about it right now is it's going to be right for customers who are willing to grow for existing customers as we look to drive our net dollar expansion rate further up and continue to focus on that metric as customers grow with us, it will be right for our enterprise customers who are looking for a cost-effective way to gain more value while at the same time increasing their spend with QALYS.
Operator
Thank you. And the next question comes from Srinik Kothari with Bayard. Your line is open.
Yeah, thanks for taking my question. Again, congrats on the great quarter. So my big picture, you did underscore that near term, there is a stronger patch management cycle, but you believe there's a broader category reset underway around the control plane for the pre-breach risk management, as you described, exploit validation, risk quantification, and autonomous remediation. Around the AI urgency, I remember last quarter you guys did say since it's broadening the opportunity, customers may extend sales cycles or pause renewals. Can you add any finer point around these broader strategic deal conversion, timing, sales cycles? How long are these evaluations taking? Are you seeing these conversion rates getting faster broadly, just directionally, and then add a quick follow-up?
Yeah, that's a great question. I think as I mentioned earlier too, and when we talk about the ROC, right, the Risk Corporation Center pre-breach risk management is broader than just vulnerability management. Obviously, that is the focus right now. We've talked about the use of misconfigurations as part of these attacks, the use of identities and the recent open air hugging phase was a great example of a vulnerability misconfiguration and identity being used. And so the risk cooperation center has been broadly built around that. I think in terms of the way we are seeing the conversations is not about saying can I just patch for the next one month and I'm done. I think the conversation with customers is really about nobody is saying that they're just going to patch now and then go back to not having a regular patching cycle and autonomous patching in the future. So the broad-based conversation is about how are they moving forward, create a process throughout their organization that is long-lasting where they're able to, any thread that comes out, they're able to actually respond to that thread very quickly. And so we see this more as something that is broadly being talked about and we see the opportunity for that to be something that we can focus on. And so I think right now, like with any corporation, large companies, they want to understand what the big picture roadmap is that they can talk to their management about while focusing on sort of phases that they can deploy. And so the ROC conversation allows us to have a much broader strategic conversation with ETM. And then the vulnerability management, patch management is something more of a, that they're focusing on right now to be able to have that phased approach. So overall, I think our innovation around ROC that we have been focusing on is coming to the help quite a bit for these customers to have broader conversation while the focus right now is changing their patch management processes and programs. So I do think that the opportunity, or rather this is giving us an opportunity to have those broader conversations with the customer. And, you know, as Jumi said, of course there were a small cohort of customers that was already in this process before Mythos came out to adopt patch management. Just a reminder, 150 million patches already applied by Qualys. So some customers have been at the forefront of these. So that helped us sort of say, look, we were right. The customers were like, look, we're already in the process. We were right to focus on patch management. So that helps in the short term. But then there's a long cohort of customers that are having these conversations now and is going to create the opportunity for us to have sustained conversations of additional things in the ROC as we move forward and they get comfortable with auto-patching.
Got it. Very helpful. And Julie, just a follow-up to Mike and Josh's question around the NDR improvement. Very encouraging to see that pick up. The ETM cohort, though, remained at 107, I think they highlighted. Is QFlex going live? And you did highlight it's playing a direct role in several of these large platform expansion, also helping pull forward the commitments, helping bookings more than near-term usage. So is that what is explaining these budgets, shifting towards more newly urgent capabilities reflected in your NDR next 12 months versus something more strategic around ETM, CSAM usage will follow through? Just wanted to understand if QFlex is playing a role there.
Yeah, Q-plus is really meant to accommodate customers who are looking for that flexibility and who are willing to spend more with us. And so we wanted to make the selling motion seamless, easier for them, where it creates a win-win opportunity for both the customers as well as us. And so we're very pleased with us going GA with it broadly. It still applies to a small percentage of customers today who signed up for Q-plus. it's not yet reflected in the numbers but we believe that this will help drive the NDR up for us broadly speaking.
Got it, very helpful, thanks.
Operator
Thank you. This will conclude today's question-and-answer session and also concludes today's conference call. Thank you so very much for participating and you may now disconnect.