speaker
Operator
Conference Operator

Hello, and welcome to CrowdStrike's fiscal second quarter 2026 financial results conference call. At this time, all participants are in a listen-only mode. After the speaker's presentation, we will conduct a question and answer session. Please be advised that today's conference is being recorded. I would now like to hand the call over to Maria Riley, Vice President of Investor Relations. Maria, please go ahead.

speaker
Maria Riley
Vice President, Investor Relations, CrowdStrike

Good afternoon, and thank you for your participation today. With me on the call are George Kurtz, Chief Executive Officer and Founder of CrowdStrike, and Bert Podbear, Chief Financial Officer. Before we get started, I would like to note that certain statements made during this conference call that are not historical facts, including those regarding our future plans, objectives, growth, including projections, and expected performance, including our outlook for the third quarter and fiscal year 2026, and any assumptions for fiscal periods beyond that are forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995. These forward-looking statements represent our outlook only as of the date of this call. While we believe any forward-looking statements we make are reasonable, actual results could differ materially because the statements are based on current expectations and are subject to risks and uncertainties. We do not undertake and expressly disclaim any obligation to update or alter our forward-looking statements, whether as a result of new information, future events, or otherwise. Further information on these and other factors that could affect the company's financial results is included in the filings we make with the SEC from time to time, including the section titled Risk Factors in the company's quarterly and annual reports. Additionally, unless otherwise stated, excluding revenue, all financial measures disclosed on this call will be non-GAAP. A discussion of why we use non-GAAP financial measures in a reconciliation schedule showing GAAP versus non-GAAP results is currently available in our earnings release, which may be found on our investor relations website at ir.crowdstrike.com or on our form 8K filed with the SEC today. With that, I will now turn the call over to George.

speaker
George Kurtz
Chief Executive Officer and Founder, CrowdStrike

Thank you, Maria, and thank you all for joining our Q2 FY26 earnings call. Reflecting on our second quarter, the key theme was reacceleration. We've talked about reacceleration coming in the back half of this fiscal year. It's here now. I'm proud of CrowdStrike's ability to deliver reacceleration, our return to year-over-year net new ARR growth, a quarter early. Our reacceleration is driven largely by AI necessitated demand for the Falcon platform and stellar execution across the business. Q2 was a robust quarter where we exceeded all guided metrics. Highlights included, one, record Q2 net new ARR of $221 million, double digit millions ahead of our expectations, showcasing accelerating net new ARR. Two, ending ARR of $4.66 billion, growing more than 20% year over year. Three, record Q2 free cash flow of $284 million, or 24% of revenue. Four, record operating income of $255 million, or 22% of revenue. Five, total revenue growth of 21% year-over-year, reaching $1.17 billion and exceeding the high end of our guidance. Six, cloud next-gen identity and next-gen SIM platform solutions are now more than $1.56 billion in ending ARR, growing more than 40% year-over-year. And seven, we surpassed the 1,000 Falcon Flex customer milestone, with the average Flex customer representing more than $1 million of ending ARR. Building on last quarter's Reflex momentum, now more than 100 customers have already Reflexed. We're very pleased with adoption rates, seeing so many customers Reflex validates the Flex model and illustrates customers accelerating consolidation with CrowdStrike. Quarters like this one highlight our momentum and progress on the path to $10 billion in ending ARR. Setting new records, achieving net new ARR reacceleration sooner than anticipated, and rising competitive win rates highlight CrowdStrike leading the way in cybersecurity. Our innovative solutions are winning at scale, like exposure management, which surpassed 300 million in ending ARR and was named a leader in the 2025 IDC worldwide exposure management market scape. CrowdStrike's market leadership was further reflected in Gartner's latest magic quadrant for endpoint protection platforms, where we were placed in the leader box for the sixth consecutive year. Our position was furthest right for completeness of vision and highest for ability to execute out of all vendors for the third year in a row. In cybersecurity, as well as the broader technology market, AI's impact is palpable. As organizations of all sizes embrace AI transformation, I hear several thematic concerns from executives and boards. One, where is shadow AI emerging in my business? Two, how do I control what data enters AI systems? Three, how do I control what AI systems can do in my enterprise? Which ultimately leads to the focal question of four, how do I secure AI agents? AI has made the role of CISOs and COOs more complicated than ever. Answering these four questions is far too difficult, expensive, nuanced, conditional, and incomplete. At the same time, adversaries are now using AI democratizing destruction at mass scale. Our threat intelligence research uncovered Famous Chalima, a North Korean nexus group using Gen AI to infiltrate more than 320 enterprises by automating fabricated resumes and conducting deep fake interviews. The threat is real. CrowdStrike's role in the agentic era is staying ahead of AI-armed threat actors to secure AI at every layer, beginning with the AI model itself, to the workloads and hosts on which they run, to the actual human and agentic identities, to the end-user devices accessing these systems and applications. In this time of societal and technological revolution, we secure where AI happens. Enterprises are quickly realizing AI security is not a network problem. AI doesn't happen in transit. Model creation and AI development happens in the cloud and in the data center. AI adoption happens at the endpoint on the computing device itself. And AI access happens by users with human and increasingly non-human machine identities. CrowdStrike secures each of these attack surfaces. We deliver AI for security, where we revolutionize security operations with our own SOC agent, Charlotte. We also deliver security for AI, helping the world securely adopt the power of agentic outcomes. This combination, grounded in our data foundation, is a competitive moat. You can't just stitch or acquire a unified, AI-native platform. AI security's primary enforcement mechanism is not and will not be the firewall. AI security must be on the devices, workloads, data, and identities anywhere, everywhere, and always on. AI security, and now enterprise security in the agentic era, is fundamentally a data, speed, and enforcement problem, one that CrowdStrike solves today and is uniquely positioned to solve tomorrow. Driving adoption of the Falcon platform as the operating system of cybersecurity is our next-gen SIM. Every day, customers are discovering the power of our native hyperscalable data foundation to solve their most complex security and IT problems. Falcon Next Gen SIM had a stellar Q2 with year-over-year growth of more than 95% and ending ARR of more than $430 million. Next Gen SIM is becoming synonymous with AI SOC transformation, akin to upgrading from a typewriter to a computer, unlocking new capabilities, cost efficiencies, and agentic speed. A leading global 2000 communications platform chose NextGen SIM in a highly competitive 7-figure legacy SIM replacement. Synthesizing EDR and third-party data proved easier, faster, and more effective than going with a network-first SIM product. And we're not stopping. Today, we're incredibly excited to announce our intent to acquire ONIM, a leading data pipeline platform. Built on a proprietary, stateless, in-memory architecture, we believe ONIM is the perfect complement to Next Gen SIM. It offers unparalleled speed, scale, and efficiency in onboarding to Next Gen SIM while giving customers control of their data. ONIM will bring Falcon's AI-powered detections closer to third-party data sources in pipeline, starting analysis before data even enters the Falcon platform. Here's why ONIM stood out to us. One, speed. ONIM delivers five times more events per second than its nearest competitor and processes data in real-time versus legacy batch and store methods. Two, cost. ONIM's smart filtering reduces data storage costs by 50%. Three, superior outcomes. ONIM's real-time pipeline detection starts before data enters the Falcon platform, delivering up to 70% faster incident response with 40% less ingestion overhead. If our next-gen sim is the engine that powers the modern SOC, then data is the fuel that makes the engine run. ONIM is both the pipeline and the filter. Streaming high-quality, filtered fuel quickly into the engine to drive robust, efficient, and superior performance. With ONUM, CrowdStrike will align with each stage of the AI lifecycle, ingestion and detection of data, filtration and optimization of data, as well as actioning and enforcement to produce high-fidelity, autonomous outcomes across security and non-security use cases. Before, migrating data into Next-Gen SIM was a long pole in a displacement tent, often requiring third-party tools. Our acquisition of Onum is a direct response to a growing chorus of frustration with the incomplete data and punitive costs from today's third-party tools. We're forging a new path. ONIM and Next Gen SIM will enable CrowdStrike customers to focus on earlier in pipeline detection, blazing fast data streaming, and high fidelity data filtration, optimizing the agentic Next Gen SIM experience. Most importantly, the acquisition of ONIM will give our customers control of their security, observability, and IT data, uniquely positioning CrowdStrike as our customer's data foundation. With our performant data platform as its foundation, CrowdStrike is rapidly expanding our pace of AI innovation. Charlotte is our agentic SOC analyst, automating actions and now end-to-end autonomous workflows across the SOC. Charlotte had a record quarter growing more than 85% over Q1. We're embedding Charlotte across the entirety of the Falcon platform, empowering customers to achieve their agentic security goals out of the box with immediate ROI. Charlotte is constantly learning and improving as we train it on our market-leading threat intelligence, battleground incident response, and scaled Falcon Complete MDR analyst behavior. As one of cybersecurity's largest MDRs, our Falcon Complete SOC data is akin to the encyclopedia of threat telemetry, resulting in a powerful cybersecurity AI feedback loop. Our unique cyber data advantage coupled with our data science expertise create a reinforcement learning flywheel, continuously adapting and improving autonomous detection and response. The outcome is Charlotte turning our data mode into a fortified and dynamic AI wall. Our customers are facing AI disruption which is driving our next-gen identity business. As agentic identities proliferate, customers require an identity security solution to safely leverage agentic AI, preventing exploitation, misuse, and breaches. We recently announced the launch of Next-Gen Identity Protection, which extends our best-in-class identity protection to non-human identities, or NHI, SaaS applications, and most importantly, AI agents. Including Falcon Shield, our Next-Gen Identity Protection business exceeded $435 million of ending ARR in Q2, growing more than 21% year over year. Based on customer demand and seeing another opportunity to innovate, we launched our own PAM offering in Q1. Elevated uncertainty around the future of legacy PAM tools is driving heightened interest in our next-gen PAM solution. Driven by the excitement for next-gen identity protection and next-gen privilege access, these new solutions significantly expand our identity opportunity. A leading global consulting firm decided to replace their legacy PAM after years of frustration with cost, limited efficacy, and point product woes. Our ability to deliver privileged account password rotation, privileged user identification and risk assessment, privileged escalation detection, user risk profile insights, and flexible MFA controls for different departments help this customer consolidate with confidence. With nothing new to deploy, this customer seamlessly met all device trust, escalating privilege, and cyber insurance requirements. Moving to our cloud business, the rapid adoption of AI has placed a spotlight on the importance of securing cloud infrastructure at runtime. While out-of-band posture tools can lend an overall view of security health, they are incapable of stopping breaches. CrowdStrike is a leader in cloud runtime protection, with the largest and most sophisticated enterprises trusting us to protect their most critical production environments. With the need to secure AI as a backdrop, we delivered impressive net new ARR in cloud this past quarter. Total cloud ending ARR exceeded $700 million, growing more than 35% year over year. A Fortune 500 energy supplier selected Falcon Cloud Security in a seven-figure win. The ease of adoption for our single-platform approach and having ASPM already natively integrated drove this win. Our ASPM reduced months of manual work into minutes. Through this upsell, Falcon Cloud Security consolidated more than 10 point products across CNAP, CSPM, ASPM, CDR, and container security. Contributing to our platform growth is our revolutionary Falcon Flex model, helping customers accelerate and maximize Falcon platform adoption. In Q2, we crossed 1,000 Falcon Flex customers, adding more than 220 new Flex customers. Not only are we and our partners successfully landing new Flex deals, we also continue to see increases in, one, platform adoption. Utilization of Flex contracts is more than 75% across the Flex customer base. Two, reflexes. We more than doubled the number of reflexed accounts to nearly 10% of all Flex customers. In just an average of five months from their initial Flex subscriptions, this cohort of Flex customers found themselves wanting more modules and more consolidation. Reflexes, on average, are yielding a nearly 50% uplift in flex customer ending ARR, illustrating the strength of the Falcon platform and the power of our game-changing licensing model. Reflex activity gives us conviction in our net new ARR acceleration, highlighting the difference between a one-time ELA and the recurring flex model. A lighthouse example of the reflex motion was with a Fortune 500 software firm which completed an 8-figure reflex. 18 months prior to their initial flex subscription expiration, this customer decided to take their next strategic step with CrowdStrike, enabling them to modernize their SOC by replacing a legacy SIM and a hyperscaler SIM. They also adopted Charlotte to agentify threat hunting and SOC operations. What was recently a very successful flex has become an even more impressive reflex. Consolidation isn't just a phenomenon with our customers. We also see it with our ecosystem partners. Diverse partner types are continuing to standardize on Falcon as their cybersecurity platform of choice. Take Red Canary, an MDR focused on the mid-market to small enterprise recently acquired by Zscaler, one of our strategic technology partners. Red Canary decided to consolidate and migrate their legacy point product EDR install base of more than 100,000 endpoints across hundreds of customers onto Falcon. Through a multi-million dollar Q2 transaction, Red Canary is migrating these customers to CrowdStrike, where they will enjoy Red Canary's MDR services delivered on the Falcon platform. Red Canary is just one of the many MSSPs who build their business on CrowdStrike. Further into the SMB market, Amazon Business Prime selected CrowdStrike Falcon Go for millions of businesses around the world. Business Prime members now receive Falcon Go as part of their subscription, opening a significant sub-100 user TAM. This partnership highlights our ability to strategically monetize new markets and migrate underserved segments from legacy ineffective technologies. And lastly, industry stalwarts like NVIDIA continue to choose CrowdStrike as their cybersecurity partner of choice. With our recently announced integration of Falcon Cloud Security with NVIDIA Universal LLM NIM Microservices and NEMO Safety, NVIDIA customers now benefit from full AI lifecycle protection for over 100,000 LLMs through Falcon. Partners sourced over 60% of Q2 new business, highlighting our ecosystem's competitive advantage and leadership across all customer segments. I started my remarks talking about acceleration. AI is accelerating every aspect of our society and revolutionizing the way we work, but it's also accelerating the adversary. I know all too well that there is no peacetime in cybersecurity. The adversary never rests. The world is soon to embark on the largest arms race ever, the arms race over AI superiority. The world's AI infrastructure necessitates protection from development to deployment, from cloud to endpoint, and from human to agent. CrowdStrike isn't just a passenger in this revolution, we're driving it. We're becoming the foundation of our customers' AI future, delivering the security platform that makes AI transformation possible. Looking forward, AI-driven market demand and customer-driven consolidation brought together by our revolutionary Flex licensing model drive my belief in sustained growth. In light of the demand environment and our platform superiority, our guidance now assumes back half net new ARR will grow at least 40% versus last year. With that, I'll turn the call over to Bert Podbear, CrowdStrike CFO.

Disclaimer

This conference call transcript was computer generated and almost certianly contains errors. This transcript is provided for information purposes only.EarningsCall, LLC makes no representation about the accuracy of the aforementioned transcript, and you are cautioned not to place undue reliance on the information provided by the transcript.

-

-

Investor presentation