This conference call transcript was computer generated and almost certianly contains errors. This transcript is provided for information purposes only.EarningsCall, LLC makes no representation about the accuracy of the aforementioned transcript, and you are cautioned not to place undue reliance on the information provided by the transcript.
6/3/2025
Welcome to CrowdStrike's fiscal first quarter 2026 financial results conference call. At this time, all participants are in a listen-only mode. After the speaker's presentation, we will conduct a question and answer session. Please be advised that today's conference is being recorded. I would now like to hand the call over to Maria Riley, Vice President of Investor Relations. Maria, please go ahead.
Good afternoon, and thank you for your participation today. With me on the call are George Kurtz, Chief Executive Officer and Founder of CrowdStrike, and Bert Podbear, Chief Financial Officer. Before we get started, I would like to note that certain statements made during this conference call that are not historical facts including those regarding our future plans, objectives, growth, including projections, and expected performance, including our outlook for the second quarter and fiscal year 2026, and any assumptions for fiscal periods beyond that, are forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995. These forward-looking statements represent our outlook only as of the date of this call. While we believe any forward-looking statements we make are reasonable, actual results could differ materially because the statements are based on current expectations and are subject to risks and uncertainties. We do not undertake and expressly disclaim any obligation to update or alter our forward-looking statements whether as a result of new information, future events, or otherwise. Further information on these and other factors that could affect the company's financial results is included in the filings we make with the SEC from time to time, including the section titled Risk Factors in the company's quarterly and annual reports. Additionally, unless otherwise stated, excluding revenue, all financial measures disclosed on this call will be non-GAAP. A discussion of why we use non-GAAP financial measures and a reconciliation schedule showing GAAP versus non-GAAP results is currently available in our earnings press release, which may be found on our investor relations website at ir.crowdstrike.com or on our form 8K filed with the SEC today. With that, I will now turn the call over to George.
Thank you, Maria, and thank you all for joining our Q1 FY2026 earnings call. Our fiscal year started from a position of strength. While the market navigates evolving condition, CrowdStrike is capitalizing on accelerated demand through continuous innovation, increasing win rates, and platform consolidation at scale. We consolidate point products without compromise, and most importantly, CrowdStrike stops the breach. In Q1, where we met or exceeded our key metrics, highlights include 1. Q1 net new ARR of $194 million, double-digit millions ahead of our expectations. Two, Q1 ending ARR surpassing $4.4 billion, maintaining our leadership as the only pure play cybersecurity software company of this size. Three, subscription gross margin of 80% demonstrating our AI platform efficiency. Four, sustained 97% gross retention as customers remain firmly committed to Falcon. Five, free cash flow of $279 million, or 25% of revenue, demonstrating double-digit quarter-on-quarter growth. And six, added $774 million of total Falcon Flex account value, bringing the total deal value of accounts that have adopted Falcon Flex the $3.2 billion growing 31% sequentially and more than six times year over year. Seeing our customers and ecosystem embrace Falcon Flex at this speed and scale gives me confidence. Confidence in improving sequential net new ARR growth next quarter and accelerating back half net new ARR. Falcon Flex is significantly evolving our go-to-market and customer experience. The subscription model sparks Falcon platform adoption, delivers point product consolidation, and fuels partner success. I'd like to share where we are with Falcon Flex, as well as a thematic customer win showcasing the power of the model. In less than two years since starting Falcon Flex, we've closed more than $3.2 billion of total account deal value across more than 820 accounts that have adopted this subscription model. Here are the trends we're seeing. One, customers spend more. The average Flex customer deal size is greater than $1 million in ending ARR. Two, customers commit to longer durations. The average Flex subscription length is 31 months. And three, Flex customers adopt Falcon faster. More than 75% of Flex contracts are already deployed. The outcome of these points taken together is a phenomenon we're already seeing, reflexes. 39 Flex customers have already deployed their initial contract demand plan and have returned to us for a reflex. These customers' initial Flex contracts were 35 months, nearly three years on average, and within just five months, they came back to CrowdTrack wanting more of the Falcon platform to achieve their cybersecurity consolidation goals. The model we pioneered is a game changer. Flex accelerates what would have taken years of module sales cycles into rapid platform transformations, unlocking adoption and spend while creating even more platform stickiness. Now let's witness Flex in action at a Fortune 100 technology firm. We began our relationship with this account pre-Falcon Flex when they selected CrowdStrike to displace and consolidate a point product EDR and legacy AV. Our initial EDR contract was for $12 million over a three-year term. When we launched Falcon Flex, this customer took the opportunity to accelerate their cybersecurity modernization, executing a five-year, $100 million plus contract. This is the power of Flex. evolving Falcon from what was a singular outcome sale into a multi-dimensional platform experience more than eight times the size of the initial deal. This transformational flex contract was for securing cloud workloads, expanding in other business units, next-gen SIM to replace two legacy SIMs, and broad-based adoption of Falcon Complete to standardize detection and response. Within just nine months of the initial Flex contract, this customer had already utilized 95% of their initial subscription and still had more point products to consolidate and cybersecurity outcomes to deliver. As a result, in Q1, this customer reflexed to realize the following new outcomes. Expansion of Falcon endpoint protection across multiple additional business units, replacing and consolidating cloud protection with Falcon Cloud Security, which has since become the standard across a vast and growing cloud estate. Identity protection became an imperative across sensitive assets, NextGen SIM quickly became the central enterprise data store, replacing multiple legacy SIMs and expanding beyond security use cases into IT. Data protection is replacing legacy DLP from endpoint to cloud. Falcon for IT is replacing a legacy endpoint management tool. And Charlotte AI will deliver agentic analyst capabilities and automation, accelerating security outcomes at scale. This customer more than doubled their initial Flex subscription in their Q1 nine-figure Reflex over an unchanged subscription duration. Through Flex, this customer now spends nearly 20x their initial EDR purchase. replacing more than eight technologies and deploying more than 10 Falcon modules, this customer still has much more to achieve with the Falcon platform across millions of workloads, petabytes of data, and hundreds of thousands of identities. With Flex dramatically accelerating Falcon platform adoption, customers are already seeing our agentic AI transforming their security outcomes. We're on the cusp of the fifth industrial revolution with artificial general intelligence on the horizon. What excites me the most is the necessity agentic AI is creating for CrowdStrike's AI native security, growing our total addressable market each and every day. Here's why and how. In a recent market survey, 96% of respondents plan to expand their use of AI agents in the next 12 months, with two-thirds already building agents and some targeting to reach over 1 billion in-production agents. At their core, every AI agent represents a unique superhuman identity, necessitating visibility, control and protection for every single agent. These autonomous AI agents increasingly have access to multiple internal and external data stores, applications and machines, automating business processes and workflows at scale. Simply put, AI agents dramatically increase the size, severity, and speed of the enterprise attack surface. Size, more agents everywhere. Severity, everything is connected faster than it can be contained. Speed, autonomous agents move at machine speed. This is the new attack surface, and it's an adversary's paradise. Just as enterprises need best-in-class protection for devices, data, workloads, and human identities, every AI agent has the same needs, too. As an AI-first company, CrowdStrike is uniquely positioned to secure the identity, the workload, the infrastructure, the data, and underlying AI models themselves. We have the platform. We have the expertise. We have the track record. CrowdStrike will be the protector of autonomous AI agents. While we see a massive opportunity to protect AI agents, our use of agentic AI is already transforming the SOC. Charlotte AI is our agentic security analyst. completing tasks and making decisions to supercharge human SOC personnel. With the launch of Charlotte AI's expanded detection triage, customers now have access to an agentic SOC analyst delivering autonomous expert level triage, reasoning and response and machine speed, flattening the hiring curve, saving time and delivering even better security outcomes. The power of Charlotte AI came to life in an eight figure Falcon Flex expansion for a global healthcare provider. Charlotte AI was the tip of the spear in this customer's AI native SOC transformation with Next Gen SIM, where we displaced a legacy SIM. Charlotte AI and Next Gen SIM started a new chapter of cybersecurity for this customer. Charlotte AI enables this customer's level one threat analyst team delivering on the promise of agentic security today. We deliver an AI-first, automated approach, eliminating clicks, panes of glass, and manual operations for a predictive, fast, and cost-efficient SOC. Next, I'll share updates on the momentum we're experiencing in our cloud, identity exposure management, and next-gen SIM platform products. First, turning to our cloud business. Cloud had a very strong start to the year with Q1 net new and total ARR growth accelerating year over year over the prior quarter. Our native unified offering combines cloud workload protection, posture management, application security, and SaaS security on a single backend and with both agent and agentless form factors. In Q1, we built on this approach with the launch of cloud data protection, all on our unified sensor, the very same sensor that also delivers our world-class workload protection, which is what the market now wants and needs. Our innovation and commercial success was recognized in the 2025 Frost Radar Cloud and Application Runtime Security Report, where we scored highest out of all vendors on the Innovation Index. Further driving our success is recent M&A in the space, increasing our relevance and competitiveness as a hyperscaler agnostic independent solution. We also announced the general availability of both our AI model scanning and AI security dashboard technologies at RSA. With the rapid growth of AI tools across the enterprise, CrowdStrike is ensuring that enterprises can safely adopt AI while managing potential risks such as model vulnerabilities, data leakage, unsanctioned use, and identity-based privilege. A prime example of a customer adopting Falcon Cloud Security was a seven-figure technology customer doubling their spend with us. This customer had CrowdStrike on the endpoint and was using a competitor's point product CSPM for cloud protection. The incident response call came into CrowdStrike when the competitor's CSPM didn't stop the breach. A rapid platform expansion including Falcon Cloud Security quickly illustrated the difference between just alerting on a breach and actually stopping one. This customer was able to consolidate on Falcon, save money, and most importantly, see the benefits of Falcon Cloud Security's protection. Moving on to our exposure management business, which includes vulnerability management and attack surface management. CrowdStrike is rapidly evolving from an incumbent compliment to a scaled disruptor. Historically, our biggest displacement gap was the lack of network scanning, something near and dearer to me as someone who pioneered the vulnerability management space. With the launch of AI-powered network vulnerability assessment, CrowdStrike now delivers unified exposure management for both managed and unmanaged devices. With this innovation, CrowdStrike customers no longer need to rely on legacy third-party VM point products. Our winning offering in this space is yielding exciting share gains. A large financial services customer purchased Falcon Exposure Management across 120,000 devices through their Flex subscription. Utilizing Charlotte AI and Falcon Exposure Management together allows for AI to finally automate vulnerability detection. Now with network vulnerability scanning, this customer is moving away from their long-standing legacy VM vendor and their existing attack surface management vendor as well. Moving on to our next-gen SIM business, where we're disrupting the proverbial horse and buggy with the combustion engine. Our next-gen SIM delivered triple-digit ending ARR growth while displacing antiquated, expensive, and poor-performing point products. With LockScale as a foundational component of the Falcon platform, we're creating even deeper tie-ins across the rest of the CrowdStrike and third-party ecosystem. This quarter, we announced Falcon Adversary Overwatch for Next-Gen Sim, which brings together our world-class threat hunting and our hyper-performant, cost-efficient data platform. This makes the AI-powered SOC turnkey, hunting across native and third-party data with real-time intelligence and automation to deliver full visibility, high-fidelity alerts, and accelerated response. This is exactly why a leading payments company displaced a legacy SIEM in a large seven-figure win. NextGen SIM was our entry point to the account where they were frustrated with ballooning costs, latency, and complexity. Substantially faster query times, accelerated and customizable dashboarding, and significant cost savings resulted in this new logo win. Within our identity business, we continued rapid expansion in both coverage and functionality. In April, we announced the general availability of Falcon Privileged Access. Before CrowdStrike, identity customers relied on third-party integrations for enforcement. Today, CrowdStrike customers experience just-in-time access and permissions for critical applications and services, all within our single AI-native platform. The need is real. A foreign government expanded their seven-figure existing Falcon platform subscription with identity protection. Gaining insights into stale accounts, exposed credentials, shared passwords, and agent-free unmanageable devices went beyond the incumbent's limited approach. Falcon was the clear winner, providing immediate time to value in securing identities. Our ecosystem partners continue accelerating CrowdStrike's growth with 60% of our Q1 annual deal value sourced by partners. Several highlights include, first, GuidePoint joins our $1 billion partner ranks as our fifth partner to achieve this noteworthy milestone, joining AWS, Optiv, CDW, and SHI, and further cementing CrowdStrike as cybersecurity's benchmark for partner success. Second, our MSSP business continues growing at a rapid pace, now representing more than 15% of our Q1 deal value. We won our largest Latin American deal of all time through our MSSP channel last quarter. And third, NVIDIA's recently announced Enterprise AI Factory, their reference AI architecture, integrates Falcon as the cybersecurity standard for securing NVIDIA's hardware and software. A marquee partnership with Microsoft, which we announced yesterday, highlights our bold ecosystem leadership. Since last summer, we've worked to find common ground where together we can make the world a safer, more resilient place. I was pleased to have Satya join me at Falcon last fall, and yesterday we announced a joint threat actor strategic collaboration where we map each other's adversaries naming conventions. Through this Rosetta Stone collaboration, we unite defenders in knowing the adversary, both in our nomenclature and Microsoft's, so they can better defend. Together, we take the guesswork out of adversary attribution for the benefit of our joint customers and the entire market. In closing, I'm very pleased with where we are and even more excited about where we're going. Q2 will be a quarter of improving sequential net new ARR growth, followed by back half net new ARR acceleration. Here's why. The platform wins. Across 30 Falcon modules, we have the products and innovation engine that stops breaches. In addition, we're seeing momentum build across the entire business. I began today's comments talking about uncertainties facing the world. What's certain is that the world increasingly needs cybersecurity and increasingly needs CrowdStrike. CrowdStrike is best positioned to protect the workloads, identities, data and infrastructure for the AI age and the superhuman AI agents themselves. Our Falcon Flex subscription model is accelerating platform adoption at a faster pace than we've ever seen before. And our execution is delivering speed and efficiency across the business. It's all of these elements together that gives me confidence and excitement in our future. And that's why the company has authorized up to $1 billion in share repurchases. I'm more certain than I have ever been of CrowdStrike's place as the world's leading cybersecurity platform for the AI era, with the unequivocal mission of stopping breaches. Thank you to our team, partners, and customers who tell me that they cannot live without CrowdStrike. And I'll now turn the call over to Bert Podbear, CrowdStrike CFO.
You're reading a preview of the CRWD Q1 2026 earnings call.
Free account.
