This conference call transcript was computer generated and almost certianly contains errors. This transcript is provided for information purposes only.EarningsCall, LLC makes no representation about the accuracy of the aforementioned transcript, and you are cautioned not to place undue reliance on the information provided by the transcript.
12/2/2025
Hello, and welcome to CrowdStrike's fiscal third quarter 2026 financial results conference call. At this time, all participants are in a listen-only mode. After the speaker's presentation, we will conduct a question-and-answer session. Please be advised that today's conference is being recorded. I would now like to hand the call over to Andy Nowinski, Vice President of Investor Relations and Strategic Finance. Andy, please go ahead.
Good afternoon, and thank you for your participation today. With me on the call are George Kurtz, Chief Executive Officer and founder of CrowdStrike, and Bert Podbear, Chief Financial Officer. Before we get started, I would like to note that certain statements made during this conference call that are not historical facts, including those regarding our future plans, objectives, growth, including projections, and expected performance, including our outlook for the fourth quarter and fiscal year 2026, and any assumptions for fiscal periods beyond that, are forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995. These forward-looking statements represent our outlook only as of the date of this call. While we believe any forward-looking statements we make are reasonable, actual results could differ materially because the statements are based on current expectations and are subject to risks and uncertainties. We do not undertake and expressly disclaim any obligation to update or alter our forward-looking statements, whether as a result of new information, future events, or otherwise. Further information on these and other factors that could affect the company's financial results is included in the filings we make with the SEC from time to time, including the section titled Risk Factors in the company's quarterly and annual reports. Additionally, unless otherwise stated, excluding revenue, all financial measures disclosed in this call will be non-GAAP. A discussion of why we use non-GAAP financial measures and a reconciliation schedule showing GAAP versus non-GAAP results is currently available in our earnings release, which may be found on our investor relations website at ir.crowdstrike.com or on our Form 8K filed with the SEC today.
With that, I will now turn the call over to George. Thank you, Andy, and a warm welcome to the CrowdStrike team. Andy is no stranger to many on this call, and I'm glad to have him with us to lead investor relations. I'm excited to share CrowdStrike's fantastic Q3. It was a record quarter as the business continued accelerating. On the back of record attendance at Falcon Global and Falcon Europe, the momentum we're seeing with customers, prospects, and partners drives my conviction in our near-term and long-term growth. Last quarter, Q2, we delivered our forecasted reacceleration a quarter early. This quarter, we furthered the trend with relentless execution. Across the entire CrowdStrike team, I'm extremely proud of our Q3, with highlights including, one, record Q3 net new ARR of $265 million, which grew 73% year over year, beating our expectations by more than 10%. Two, ending ARR of $4.92 billion, which accelerated to 23% growth year over year. Three, record Q3 free cash flow of $296 million, or 24% of revenue. Four, all-time record operating income of $265 million, or 21% of revenue. This is the second consecutive quarter of record operating income. Five, broad-based ending ARR acceleration across cloud, next-gen identity, and next-gen SIM collectively, as well as acceleration in our endpoint business. And six, more than $1.35 billion in ending ARR from accounts that have adopted the Falcon Flex subscription model, growing more than 200% year over year. Underpinning these financial highlights is the CISO, CIO, and board feedback I regularly hear. CrowdStrike is mission critical in today's agentic society. No matter how the market swings, geopolitical tensions evolve, or what technologies are in vogue, our digital society mandates cybersecurity as a necessity. And now more than ever, synonymous with that, CrowdStrike is a necessity. Our growth is driven by pervasive, durable, and thematic market forces. Organizations of all sizes are in the midst of AI transformations, investing in the future of workforce productivity in the name of speed, scale, and cost benefits. In the midst of this societal shift, what I've shared over the past few years and quarters is unfolding before our very eyes. One, AI is rapidly expanding the attack surface. Businesses are onboarding a whole new type of workforce today, the agentic workforce. Humans using agents to do more and agents working by themselves, each with access to data, applications, compute, and sometimes even other agents. While the benefits of this newfound workforce are exciting and increasingly vital for market competitiveness, the rapidly expanding risk profile of this realm cannot be ignored. Every single agent expands the attack surface, necessitating protection. CrowdStrike is both the armor and intelligence layer that keeps each agentic identity secure. The intelligence layer. providing visibility and context to organizations from agentic threats and risks. And the armor, protecting agents from attacks, influence, exfiltration, and data manipulation. In addition, CrowdTrack is also present as the foundational protector of the underlying technologies powering the AI revolution, providing security by design for the world's cloud and token factories. Two, The democratization of destruction wasn't just a bold prediction. It's already today's reality. Businesses every day are having jarring, lightbulb moments witnessing AI-powered adversarial tradecraft firsthand. Just a few weeks ago, a major AI company shared that China state-sponsored adversaries were using their LLM to create and operationalize active cyber intrusion agents. This is just one of the many AI-enabled attacks we've seen. The AI cyber battleground is no longer theoretical. It's now real. Now, just as anyone can use AI to vibe code and become a software engineer, anyone can now also vibe hack, becoming a sophisticated adversary with AI. Three, cybersecurity in the agentic era demands a single platform. The criticality in being able to operate with agility, efficacy, and speed to stop breaches is having the data, the controls, and the actions in a single platform, not multiple platforms, because when you have multiple platforms, by definition, you don't have a platform. Tap switching and contact switching cost time. Data stitching doesn't scale. These are the seams and cracks where adversaries thrive. The leaky lifeboat of PowerPoint platforms and point product fragments simply cannot offer the protection, scalability, and cost benefits or the ease of use of a single platform solution. CrowdStrike wins as the market's broadest and only single platform solution. Taking my three points together, one, we've built the right architecture, a single console, single data backend, single sensor, agentic hyperscale platform, that is frictionless and one-of-a-kind in cybersecurity. Two, it's the right time with the rapid growth of AI agents raising the threat risk profile and driving a holistic technology shift. And three, we're in the right position. CrowdStrike's technology, innovation engine, and ecosystem position us as the operating system of cybersecurity for the agentic era. Market demand is high because the need is real. We have the right architecture, we have the right products, and we're in the right market position to continue taking share. Successful AI adoption requires cybersecurity transformation, necessitating a new operating system to create a structure around the next chapter of enterprise security programs. Falcon Next Gen SIM is the foundation of our platform, turning CrowdStrike into our customer's operating system for cybersecurity. Next-Gen SIM has become a scale disruptor in a market that has historically been slow to evolve as customers embrace the speed and efficiency advantages versus legacy competitors. And with the acquisition of Onum, we're making it even easier to build on CrowdStrike with a hyper-scalable telemetry detection pipeline that brings CrowdStrike even closer to all our customers' critical data. Falcon NextGen SIM had a record net new ARR quarter, a clear outcome of the deliberate strategic choices we've made over the past several years. We know that the value of the technology is only as good as the platform on which it's delivered. So we invested heavily in integrating NextGen SIM to create a unified single platform. This isn't just a single console. It's a truly integrated and unified data backend that brings together all of CrowdStrike in one place, delivering not just economies of scale, but far superior outcomes. And with Charlotte as the agentic SOC orchestrator, now FedRAMP high approved, we're delivering the AI SOC of the future today. Furthering our position as the operating system of cybersecurity, we recently announced our expanded partnership with AWS. Through this announcement, all of AWS's millions of customers will have access to Falcon NextGen SIM natively within their AWS security console, enabling them to immediately access, interact with, and analyze AWS telemetry directly in NextGen SIM. Going a step further, we've also enabled federated search so that AWS customers can query their data from a single console. We're incredibly excited about what the future holds and thank AWS for both our amazing partnership and for their validation of Falcon NextGen SIM as the best choice for their customers. A large European bank renewed their more than 500,000 workload EDR deployment, adding NextGen SIM, Onum, and Charlotte in a large eight-figure expansion deal. With our acquisition of Onum, this financial institution was able to eliminate their existing streaming pipeline point product as well as migrate off Splunk. Competing against hyperscalers and firewall vendor SIMs, Falcon NextGen SIM won the hearts and minds of the security and IT team as the easiest solution, fastest to see value, and best agentic stock transformation platform. Our identity business continues to perform exceptionally well. While the demand for our ITDR offering has increased, it's the launch of both our PAM and FalconShield offerings that has our customers increasingly excited. Falcon Shield had a record net new ARR quarter, growing nearly 50% sequentially as market demand for SaaS application security has become a mainstream necessity. Securing SaaS app misuse from human and non-human identities has never been more important or challenging. Nefarious agentic behavior is targeting data-rich SaaS applications that have quickly become a feeding ground for breaches. From on-prem apps to cloud apps, we stop these breaches. A Fortune 500 logistics company used Falcon Shield to uncover exfiltrated CRM data in less than 30 minutes from deployment. resulting in a seven-figure deal. A leading customer experience platform saw a Shield demo and activated the module via Flex within an hour. And lastly, a Global 500 personal care leader conducted a Shield assessment, uncovering 25 unknown shadow instances of their CRM. This customer quickly transacted a seven-figure expansion, bringing their SaaS environment under control. As these examples illustrate, today's elevated third-party SaaS risk environment demands visibility and protection. Falcon Shield delivers near-immediate time to value and is a product that we can land new logo accounts with even without endpoint deployments. Turning to the cloud where we delivered Q3 record net new ARR. While CrouchRite continues to benefit from M&A-related market disruptions, it is our customers' embrace of best-in-class runtime protection that continues to push us forward. As the cloud security market matures, customers are realizing that posture doesn't equate to prevention. Security teams now understand that they need active defense within their cloud environments, and this can only be delivered in runtime. CrowdStrike is the cloud runtime security leader as validated by the most recent Frost and Sullivan CWP report. And with our recent acquisition of Pangea, we're now positioned to protect the entirety of our customers' AI infrastructure. At our recent analyst day at our Falcon conference, we discussed how protecting AI is akin to protecting a building. Security teams don't want a non-integrated, fragmented series of solutions to protect their critical AI infrastructure because they know that this complexity creates gaps that are increasingly exploitable by AI-enabled adversaries. CrowdStrike Falcon Cloud Security offers customers a unified, integrated, end-to-end solution that enables secure adoption of transformative technology without slowing the end user down. A Fortune 500 consumer packaged goods company grew their Falcon deployment with Falcon Cloud Security in a seven-figure expansion deal. This customer took the opportunity to displace Wiz, bringing their cloud security program to Falcon for the benefit of our consolidated CSPM, ASPM, CIEM, and CDR approach. The outcome delivered is single platform management, better visibility, and the ability to stop cloud breaches versus simply alerting on them. This was just one of multiple whiz replacements. In addition, Falcon Cloud Security was selected to protect a leading Neo cloud in an eight-figure transaction. This token factory decided it was time to secure AI from the source so that enterprises of all sizes would trust and build with confidence on them. cybersecurity became a differentiator and business enabler not a cost and finally i wanted to touch on our endpoint business our endpoint business accelerated in the quarter on the heels of ai driven demand in the world of ai so much is being pushed to the edge employees are now deploying new applications such as cloud desktop and chat gpt directly onto their machines driving both rapidly improved productivity and also significant new risks. This is further exacerbated by the rapid adoption of new AI browsers, such as Common and Atlas, which bring new opportunities and concurrently new vulnerabilities and threats. AI adoption is supercharging renewed interest in the endpoint, as the endpoint is the epicenter of human and non-human interaction with AI. In this new agentic world, the endpoint has quickly become the risk point, the productivity point, and the opportunity point. A large government agency took the opportunity to modernize, replacing more than 75,000 endpoints of legacy AV with Falcon, as well as deploying us in their AWS environment for cloud protection in what was a strong federal quarter for CrowdStrike. In addition, EY brought us into a Fortune 500 healthcare account where in just a few months we were able to modernize the endpoint, cloud, and SIM environments, an eight-figure end-to-end Flex expansion deal where we displaced two SIMs, Defender for endpoint, and a point cloud security product. Frequently imitated but never duplicated, Falcon Flex makes it easier than ever for our customers to experience the full power of the Falcon platform without procurement friction. The Flex model cultivates more platform utilization, accelerating module adoption. Falcon Flex is an unlock, not an ELA. Flex customer and the account ARR more than tripled year over year. But what has us even more excited is the momentum we're seeing in Reflex activity. The number of Reflex accounts more than doubled quarter over quarter to more than 200, with 10 customers Reflexing more than 2x their initial Flex subscription. This demonstrates that Flex customers can and do increase their ARR and TCV spend with CrowdStrike, which is contrary to the ELA model, where all the economic value is realized once up front. When we launched Flex, we believed that it would allow customers to more quickly benefit from the full value of our platform, and that's exactly what's happening. As customers and partners alike continue to embrace Flex as the best way to adopt Falcon, we expect it to become our licensing standard. Our community or crowd powers our technology, and that's who we build for. Our ecosystem partners continue leading us to new heights, affirming CrowdStrike's market and category leadership. Our alliance team delivered a record quarter in terms of deal value closed with partners. CrowdStrike's market position comes to light in mission-critical times. F5 asked us to partner with them to further secure their BIG-IP hardware and virtual appliances. We rapidly deployed our sensor on BIG-IP, which they certified, and F5 took the opportunity to purchase Falcon and Overwatch licensing for their install base in a large flex transaction. We are pleased to be taking our industry-leading protection capabilities to new insertion points designed to enhance network perimeter protection. Today, hundreds of F5 customers are now securing their F5 appliances with CrouchRite, many of whom weren't CrouchRite customers prior. Partners take us into new account environments, implementing Falcon as part of their broader agentic enterprise architecture vision. Experiencing the success of next-gen SIM in the market, EY took a bold step to standardize their SIM practice on Falcon in a large seven-figure transaction. EY is migrating accounts for which they own and operate multiple legacy SIM technologies, consolidating on CrowdStrike. Additionally, EY is a leading global partner of ours for next-gen SIM implementations, taking numerous Fortune 500 accounts through the journey from legacy SIM to next-gen SIM migration. Deloitte announced NextGen SIM in their MXDR practice, replacing their legacy SIM provider. And WePro, too, has standardized security delivery and incident response on Falcon. The GSI community is quickly seizing the SIM and SOC transformation opportunity that only our single platform provides. The ecosystem embrace of partner-led services on Falcon is correlated to the opportunity we represent. A recent Canalys report showed that our ecosystem creates up to $7 in services opportunities for every dollar of Falcon product sales, illustrating the large ecosystem opportunity surrounding the Falcon platform. I want to return to yesterday's announcement that we made with AWS. AWS selected Falcon Next Gen SIM as the default SIM for all their customers offered in their Security Hub console. This brings Falcon NextGen SIM with pre-populated AWS data to millions of AWS customers in a product-led growth motion. Our intent is to convert NextGen SIM usage into flex subscriptions as more accounts experience the power, speed, and actionability of their AWS data, CrowdStrike data, and other third-party data in NextGen SIM. Our NextGen SIM helps AWS fill a critical market gap now competing with other hyperscaler SIMs and doing so with Falcon. Our next-gen SIM delivers value for AWS customers, even those who don't yet use Falcon, because we've become a federated, pre-populated, and affordable security data lake for observability, triage, and threat hunting. And Charlotte is there to help operate the whole system on a customer's behalf. In addition, Accenture is our launch partner with AWS, helping AWS customers leave their legacy SIEM for Falcon Next-Gen SIEM on AWS. Our partnership with AWS continues from strength to strength, with CrowdStrike announced as AWS's Global Security Partner of the Year and AWS's Global Marketplace Partner of the Year yesterday at reInvent. We're excited about the opportunity to engage AWS accounts, onboarding them to Falcon, and serving as their operating system for cybersecurity. Lastly, I want to share a noteworthy MSSP partnership, which we've announced today with Kroll, a leading mid-market professional services firm. Kroll's cybersecurity division performs thousands of incident response engagements yearly for mid-market firms around the world, largely from their cyber insurance panel inclusion. Kroll had been using a point product DVR in their incident response and managed detection and response business. Now, Kroll exclusively uses Falcon, and in an almost eight-figure rip-and-replace transaction, Kroll is migrating nearly half a million endpoints to Falcon, which were previously running on a point product SMB EDR, and up-leveling their own MDR service with Falcon Complete for service providers, with our Falcon Complete team becoming the SOC for Kroll. This partnership announcement illustrates the value that only CrowdStrike can deliver. the best technology platform with numerous expansion opportunities to help customers and partners alike consolidate. The services opportunities partners need to see value, whether that be in an incident response, proactive assessments, managed detection response, or SOC transformation, and our skilled and agentic MDR teams to up-level partners so they can focus on selling and client services while we focus on stopping breaches as the world's SOC. We've improved Kroll's technology stack, displaced an inferior point product, improved their margins with Falcon Complete, and they migrated their entire practice to us. This transaction highlights the power of Falcon to be a business creator for our ecosystem. We're not selling products. We're delivering outcomes, introducing the world to a whole new way of performing cybersecurity and risk management. In closing, this was one of our very best quarters in company history, Acceleration is back. We're winning and we're living the company's mission of stopping breaches. AI represents our largest opportunity and demand driver yet. We're using AI to revolutionize cybersecurity. And even larger, we're securing the world's use of AI so businesses of all sizes can adopt more AI faster, securely, and with confidence. The takeaway is this, AI adoption necessitates the right cybersecurity. It necessitates CrowdStrike. Jensen Wong summed up our market position best, saying, quote, I can't imagine a better defender than CrowdStrike, end quote, on the stage at NVIDIA GTC in Washington, D.C. The transformative work we're doing with NVIDIA is representative of how we're securing AI at its very source, all the way down to its human and non-human users and its outcomes. I see this as a generational opportunity for the company. AI is but one of many tailwinds continuing to propel CrowdStrike to new heights. One thing is certain, whenever our customers engage in technology change and transformation, cybersecurity has been a constant necessity, and that constant is CrowdStrike. With that, we have a big Q4 opportunity in front of us, a robust demand environment, and no shortage of breaches to stop. Cybersecurity doesn't slow down for the holidays, and neither do we. Stay safe, happy holidays, and I'll pass the call over to Bert Podbear, CrowdStrike's CFO.
You're reading a preview of the CRWD Q3 2026 earnings call.
Free account.
