8/4/2026

speaker
Operator

Ladies and gentlemen, thank you for standing by. Welcome to QALYS' second quarter 2026 investor call. At this time, all participants are in a listen-only mode. After the speaker's presentation, there will be a question and answer session. To ask a question during the session, you would need to press star 11 on your telephone. You will then hear an automated message of ads and your hand is raised. And to withdraw your question, please press star 11 again. Please be advised that today's conference is being recorded. I would like now to turn the conference over to Blair King, Investor Relations. Please go ahead.

speaker
Blair King
Investor Relations

Thank you, Michelle. Good afternoon and welcome to Qualys' second quarter 2026 earnings call. Joining me today to discuss our results are Sumedh Thakar, our President and CEO, and Joo Mi Kim, our CFO. Before we get started, I would like to remind you that our remarks today will include forward-looking statements that generally relate to product capabilities, future events, or future financial or operating performance. Actual results may differ materially from these statements. Factors that could cause results to differ materially are set forth in today's press release and our filings with the SEC. including our latest Form 10-Q and 10-K. Any forward-looking statements that we make on this call are based on assumptions as of today, and we undertake no obligation to update these statements as a result of new information or future events. During this call, we will present both GAAP and non-GAAP financial measures. A reconciliation of GAAP to non-GAAP measures is included in today's press release. And as a reminder, the press release prepared remarks and investor presentation are all available on the investor relations section of our website. With that, I'd like to turn the call over to Sumedh.

speaker
Sumedh Thakar
President and CEO

Thank you, Blair, and welcome to our second quarter earnings call. The adversary's playbook has been fundamentally rewritten by AI, collapsing exploit timelines and making one thing undeniably clear. Durable, pre-breach risk management increasingly requires a vendor-neutral, agentic AI fabric that moves beyond theoretical exposure to autonomous quantification of actual exploitable risk and remediation. Demonstrating this conviction, we delivered another quarter of strong revenue growth and profitability. The urgency behind that conviction continues to intensify. Frontier and open source AI models are capable of discovering and weaponizing vulnerabilities faster than any human team can triage them, compressing exploit timelines to hours, and in some cases, turning disclosure into compromise before a patch even exists. AI is simultaneously becoming the greatest force multiplier and the most formidable challenge cybersecurity has ever Where we part ways with continuous threat exposure management, CTEM solutions is how we respond to it. CTEM solutions today respond by generating more findings, more theoretical risk scores, and more dashboards, and then pass along these findings off to siloed solutions that collect data and do the patching while losing critical time at every handoff. That approach was already failing before AI accelerated the threat landscape, and it is fundamentally inadequate now. We believe the defenders who win in this new era of AI will not be the ones who simply detect more and more vulnerabilities and produce dashboard tourism. They will be the ones who can autonomously detect vulnerabilities at AI speed, validate actual exploitability in production, quantify that risk in dollar terms, remediate it, and then prove the exposure is closed in multi-vendor environments, all before an adversary gets there first. That is the design outcome of the AI native risk operations rock powered by our enterprise to risk management ETM solution. And it is where nearly every customer conversation we are having is heading. Against this backdrop, I'm pleased to announce major new capabilities on the platform we'll showcase at Black Hat later this week, spanning both AI for security and security for AI to address the post-mythos threat landscape head on. First, with respect to AI for security, we're pleased to introduce Instascan, powered by Agent Insta, The newest addition to our agentic AI marketplace and ETM solution for AI speed detection that is continuous, instantaneous, and scanless. Today, when a new vulnerability advisory is released, it takes 24 hours to a week for organizations to detect it through traditional scan cycles while adversaries weaponize the same vulnerability in minutes. Agent Insta is designed to collapse that timeline by converting the asset inventory software paths and Threat Intelligence, our customers already collect with Qualys sensors into high confidence exposure findings without a scan. New detections appear within minutes of disclosure and no rescan required and no agent disruption. The finding is then handed to Agent Val for instant exploit validation and the risk impact is determined and quantified immediately. While competitors are still processing and advisory writing signatures and waiting for a scan to complete, our customers already know whether they are exposed and are taking action before a vendor patch exists. Because the finding flows straight into validation and remediation, detection is not a report. It is the first step of a continuous closed loop. With last quarter's launch of true conformant agent safely validating actual exploitability across chain attack paths in live production environments and hyper-prioritizing millions of findings to the fewer than 1% that require immediate action The bottleneck is now shifting from identifying what to fix to actually fixing it before adversaries can act. This leads me to the next phase of our True Risk Eliminate agenda, autonomous zero-day remediation at scale. Through AI-scored autonomous remediation waves, the AI-native ROC now determines the right action for every asset in multi-vendor environments, deploying a patch staging a control rolled out where concussion is warranted or applying a compensating control where operational risk demands it. Every action is gated by our AI-driven patch reliability score and resiliency snapshots, delivering rollback rates below 1.5%, below half of 1%. The most critical assets remain human in the loop oversight while the platform autonomously remediates the rest. Orchestrating the cycle is Agent Serra, who prioritizes exploitable risk, quantifies it in dollar terms, sequence continuous waves, and revalidates closure with Agent Val, all without proportional headcount. Furthermore, with the introduction of peer-to-peer patching, we are accelerating the delivery across distributed environments while removing the dependency on centralized infrastructure. Put simply, these newest innovations make autonomous zero-day remediation wave-driven vendor agnostic, safe, and provable. In live benchmarking, this collapsed the window of exposure from 21 days to minutes and auto patched 60% of the vulnerabilities. This is not incremental. It turns a massive surge in exploitable vulnerability volume from an impossible backlog into a continuously clear queue at the speed of modern attacks. You cannot solve a minutes problem with a month-long solution. and that's the gap the AI native rock was designed to solve with agent Insta providing AI speed detections, agent RAL hyper-prioritizing validator exposures and agents that are performing autonomous remediation in a continuous closed loop. Turning to security for AI as enterprises raise AI workloads into production, the AI infrastructure they are building is already the next attack surface. With the introduction of Local AI 2.0, Organizations can now see their full AI estate from workforce to workload and from code to runtime. Through new sensors that see AI activity at both the employee and workload level, security teams can now discover shadow AI activity across the organization, from what employees are doing with AI to which models, endpoints, and services are running in production across hybrid multi-cloud environments. We have also extended our portion management coverage to SaaS platforms, including Anthropic and OpenAI, to help organizations enforce security and compliance policies across the AI platforms their teams are already using. Additionally, they can now identify security gaps in code before deployment, remediate without drills at runtime, and test model context MCP tool exploits across over 50 adversarial scenarios. And of equal importance, every AI risk across the entire stack from GPU to infrastructure to supply chain to the newest prompt injection attacks is now scored and prioritized through the same true risk engine that powers the risk operation center. For organizations seeking to secure the infrastructure, powering the AI future, these new innovations become an increasingly strong differentiator for Qualys. As ROC adoption accelerates and these capabilities continue to compound, we remain laser focused on driving ETM adoption throughout our VMDR customer base and positioning Qualys for larger upsell opportunities over time. Moving to our business update with customers spending $500,000 or more with us growing 8% from a year ago to $229, let me share a couple of recent wins which illustrate why organizations are turning to Qualys to help unify their security stack and operationalize the rock. The first is with an existing global 300 customer managing a complex data intensive environment spanning on-prem multicloud and rapidly growing LLMs in production. As the volume and velocity of vulnerabilities across the environment accelerated, their teams recognized that prioritization based on theoretical risk scores couldn't deliver the business context needed to act decisively. With fragmented telemetry, disconnected tools, and little automation, their teams were spending more time documenting risk than reducing it, while unpatched assets and shadow IT were silently extending exposure windows by months. As a result, the customer chose Qualys to operationalize their ROC. adopting VMDR, ETM, True Risk Eliminate, and Total AI alongside several other modules in a low seven-figure QFLIX annual upsell. By consolidating Qualys and third-party data into unified risk fabric, this customer has aligned risk reporting to the board's tolerance level, shifted remediation from manual processes to autonomous workflows, and reduced its exposure window from months to hours while flattening the hiring curve and delivering better security outcomes. This is also an outstanding example of how we are leveraging our channel partners to activate the rock to win new business. The second is with a European healthcare company that has been a small existing scan on behalf of Qualys customer, but was relying on a managed service provider to run the broader vulnerability program across more than 140 locations. That model delivered people and process, but not autonomy. Scan operations, prioritization, and remediation guidance all flowed through the provider's team on the provider's timeline, leaving the customer dependent on external resources to understand and act on its own risk. As this environment grew more complex and vulnerability volume surged, the limitation of that dependency became unsustainable. Costs for ballooning remediation cycles for the customer had limited visibility into the varied data driving the decisions made on its behalf. This customer chose Qualys, consolidating its stack into the Qualys platform by adopting VMDR, ETM, and TrueRisk Eliminate in a six-figure QFlex upsell. Rock automation was the entry point, and remediation was the immediate proof of value. By unifying detection, prioritization, and autonomous remediation into a single AI-native workflow, this customer has replaced a manual people and process dependency with a platform that delivers significantly lower cost A less complexity, full control, and peace of mind for the CISO. These wins reflect the broader ETM momentum we are starting to see as more and more customers recognize the efficiencies and scale of AI native rock automation. Further supporting our growth trajectory, QFlex continues to gain traction as another strategic lever for accelerating ETM adoption. As we heard in the customer wins I described earlier, QFlex played a direct role in enabling significant upsells for QALYS by giving these customers the flexibility to commit broadly across the platform while preserving the ability to shift investments as their needs evolve. This precisely the value proposition of QFlex model was designed to deliver. Building on strong results from our initial rollout, we have now taken QFlex live for enterprise customers looking to expand with Qualys and believe it can become an increasingly important driver of platform expansion over time. Turning to our executive team, with the recent departure of our CISO and general manager of our ETM business, I want to address how we are positioning for continuity and acceleration. To lead product strategy and our ETM business going forward, I have appointed Shailesh Atle as our chief product solutions officer, a nearly 14-year Qualys veteran who has served as our SVP of products for the last five years. Shailesh has been instrumental in shaping many of the platform innovations we discussed today. and his deep institutional knowledge of our technology, our customers and our roadmap makes him the natural leader to drive the next phase of ETM adoption and our customer-led growth strategy. Additionally, I'm pleased to welcome Nathan Smolenski as our new Chief Information Security Officer. Nathan is a seasoned cybersecurity executive with over 24 years of experience driving security transformations across financial services, insurance and high-growth SaaS environments most recently serving as the Global CISO at Ciara. We are excited to have both Shailesh and Nathan in these critical roles as we continue to scale our platform and accelerate rock adoption. In summary, Qualys' continued innovation spanning both AI for security and security for AI, growing AI-native rock adoption powered by our ETM solution, a growing federal pipeline for new business opportunities, strong partner-led execution, and promising early QFlex engagement continue to reinforce the demand we're seeing for a unified risk management platform that autonomously moves beyond theoretical exposure to validated, quantified, and remediated risk at the speed of modern attacks in multi-vendor environments. We believe these achievements not only advance our strong competitive differentiation, but also sharpen the market opportunity ahead of us and bolster our confidence in re-accelerating long-term growth in the business. With that, I will turn the call over to Joo Mi to further discuss our second quarter results and outlook for the third quarter and full year 2026.

speaker
Joo Mi Kim
CFO

Thanks, Meg, and good afternoon. Before I start, I'd like to note that except for revenues, all financial figures are non-GAAP and growth rates are based on comparisons to the prior year period unless stated otherwise. Turning to second quarter results. Revenues grew 11% to $182.2 million. As a result of a strategic emphasis on leveraging our partner ecosystem to drive growth, the channels continued to increase its contribution, making up 54% of total revenues compared to 49% a year ago. Revenues from channel partners grew 22%, with revenues from direct remaining largely unchanged from Q2 of last year. By GEO, 15% growth outside the US was ahead of our domestic business, which grew 8%. The US and international revenue mix was 55% and 45% respectively. In Q2, our overall upsell execution improved with our net dollar expansion rate at 105% up from 104% last quarter. The net dollar expansion rate of customers with prior year purchase of ETM or CSAM subscriptions in Q2 was 107%, consistent to last quarter. Moving on to product mix, Our differentiated new products continue to drive growth. First, ETM CSAM combined made up 12% of total bookings and 14% of new bookings on an LTN basis in Q2, up from last year's 9% and 10% respectively. Next, Patch Management made up 9% of total bookings and 16% of new bookings on an LTN basis in Q2. This compares to 7% and 16% respectively in Q2 of last year. Lastly, Total Cloud made up 5% of total LTN bookings in Q2, unchanged from a year ago. We believe that these differentiated products combined will increase contribution to bookings in 2026, given our opportunity to increase market share and maximize share of wallet. Reflecting our scalable and sustainable business model, adjusted EBITDA for the second quarter of 2026 was $83.8 million, representing a 46% margin compared to 45% last year. Operating expenses in Q2 increased by 8% to $73.2 million, driven by investments in sales and marketing, which grew 14%. With a strong performance, EPS for the second quarter of 2026 with $1.98 per diluted share and a free cash flow of $55.9 million, representing a 31% margin compared to 20% in the prior year due to fluctuations in working capital. Normalizing for this, first half of the 2026 margin was 42% compared to 43% in the prior year. In Q2, we continued to invest the cash we generated from operations back into Qualys, including $3.7 million in capital expenditures and 76.8 million to repurchase 797,000 of our outstanding shares. As of the end of the quarter, we had 229.8 million remaining in our share repurchase program. With that, let us turn to guidance, starting with revenue. For the full year 2026, we now expect revenues to be in the range of 732 to 738 million, which represents a growth rate of 9 to 10%. This compares the prior guidance of $721 to $727 million. The third quarter of 2026, we expect revenues to be in the range of $185.5 to $187.5 million, representing a growth rate of 9% to 10%. This guidance assumes their net dollar expansion rate remains at current levels, with moderate growth contribution from new business in 2026. Shifting to profitability guidance, for the full year 2026, we expect EBITDA margin to be in the mid 40s, with a low team's increase in operating expenses and free cash flow in the low 40s. We expect full year EPS to be in the range of 7.74 to 7.88, up from the prior range of 7.44 to 7.65. For the third quarter of 2026, we expect EPS to be in the range of 1.91 to 1.98. Our planned capital expenditures in 2026 are expected to be in the range of 8 to 12 million, and for the third quarter of 2026, in the range of 1 to 2.5 million. With that submitted, I would be happy to answer any other questions.

speaker
Operator

Thank you. As a reminder, to ask a question, please press star 11 on your telephone and wait for your name to be announced. To withdraw your question, please press star 11 again. The first question comes from Kingsley Crane with Canaccord. Your line is now open.

speaker
Kingsley Crane
Analyst, Canaccord

Great. Thanks for taking the question and congrats on amazing results. Sumedh, look, the volume of AI-generated vulnerabilities, it's a clear reason why customers need InstaScan, and The Rock. Can you just double-click again on how this is showing up in pipeline, how this is showing up in urgency, and then if CVE volumes were to double again, how could you capture that in your pro-asset pricing models?

speaker
Sumedh Thakar
President and CEO

Yeah, that's a great question, and I think even though the disclosure findings are increasing, I think the organization's ability to remediate is a What is currently being looked at, right? And that's really where our focus has been on helping these customers with autonomous remediation, because at a very high level, you cannot go and tell your management as a security leader that you're going to respond to autonomous AI exploits with more manual tools that are emailing each other on what needs to be fixed, etc. And so if you look at sort of the risk operation center and what we are focused on is agent Sera is already helping with the autonomous remediation piece, but to do a great job with that and with high confidence you need to significantly hyper-prioritize your findings and that's where Agent Val on the Risk Operations Center platform is helping run actual exploits to reduce the number of findings that need to be auto-remediated that actually matter to the business and then now our latest announcement yesterday of Agent Insta which is the ability to scan instantaneously whenever new advisory comes out now shrinks the timeline from the advisory coming to the timeline when the advisory at the vulnerabilities even detected in the customer environment. And so with all three of these on the ETM platform, you now actually have a real path to get something that is important and exploitable in your business that are mediated within the first 24 hours with minimal human intervention. And that is the conversation that everybody's having is that they need to go have conversations internally to say how are we going to move towards a roadmap that allows us a feasible autonomous remediation plan, and the ETM is enabling that. And so we, of course, have been ahead of this, as you know, for the last few years with creating autonomous remediation capabilities. And so we already had a few customers in the pipeline who were discussing with this, who saw this beforehand, And so the conversation with PostMethos helped us accelerate a couple of these opportunities. However, there's a large number of customers that are very, very curious now about what they can do and what is the art of the possible with this kind of autonomous remediation. And so we're very excited to see that pipeline in terms of the conversations, in terms of POCs is looking good and we're happy with that. And of course, we have to now move forward, get the POCs done, look at the budget, see when they will close, et cetera. But I would say with all the innovation and the investment that we have made, we're pretty excited to see the current conversations that are happening.

speaker
Kingsley Crane
Analyst, Canaccord

Great. And then just to follow up for either Sumedh or Joo Mi, Building off of that, you know, billings grew 16%. It was a really sizable raise. On top of a broad base beat, we're now talking about re-accelerating long-term growth. Is it that the conviction in the business hasn't changed and the market has come toward you this quarter? Or just can you help us understand, you know, how much more bullish you are on the business today than you were three months ago? Thanks.

speaker
Sumedh Thakar
President and CEO

Look, I think we always sort of went ahead of this with remediation, etc. And so the conviction that this is what the market is going to need and the investments that we put in before that has always been there. I think right now with the advent of AI, it's just accelerated what we are sort of being seen was going to happen at some point. And so that's sort of driving the conversations are driving us to feel like because of the investment we put in the platform, these are solutions that actually can help customers right now in what they are looking for to set up as an auto remediation capabilities for the future. So I mean, I will say that a lot of that goes to us being able to see where the industry is going to go and putting the investment behind it. And now positive conversations with the customers are kind of helping us get through to Thank you so much. Congrats.

speaker
Operator

Thank you. And our next question is going to come from Jonathan Ho with William Blair. Your line is open.

speaker
Jonathan Ho
Analyst, William Blair

Hi. Good afternoon and congratulations on the strong quarter. I wanted to understand a little bit better when you talk to your customers about sort of their change in the exposure risk management process. Can you maybe help us understand how much of this is that they need to cover more assets versus the fundamental patch management process changing versus having sort of the rock part of this on the managed side? Can you just maybe unpack that for us a little bit in terms of what they're buying? and also what they intend to buy over time. Thank you.

speaker
Sumedh Thakar
President and CEO

Great question. I think at the end, what they are focusing on is can I remediate the thing that actually matters to my environment as fast as possible, right? And that includes all assets in their environment, but that doesn't necessarily mean that they don't have other products that might be helping them get some visibility through acquisitions, this, that. and I think that's where if you look at our strategy around ETM and what we have done with the concept of a ROC is that the ROC is a multi-vendor solution. So it gives us the ability for the customers who are leveraging Qualys to have capabilities like Instascan where we can instantaneously detect things. We could do the same on data collecting from other scan only products that are just throwing a bunch of CVEs. So we are seeing with ETM that it is allowing us to expand licenses in the early POCs that we have with some of these customers, early purchases. They are also bringing data on other tools from outside of Qualys into the ETM solutions so that they can get a holistic view across multiple tools and then prioritize the ones that really matter, run the exploits, and then get into the remediation piece. So I think it's the focus on adding on the batch management, eliminate capabilities is one aspect, and then with ETM broadening The coverage of how many assets that they should look at to make sure the remediation succeeds is helping us that even if they have some other scan-only CVE detection tool, which is producing a lot of false positives, we can all still bring that license as part of the Qualys ETM solution.

speaker
Jonathan Ho
Analyst, William Blair

Excellent. And just given the relative proximity of Mythos, when do you think the bulk of the spending will start to materialize? I'm guessing we haven't seen it yet. I just wanted to get your sense for how you think this is developing with the pipeline. Thank you.

speaker
Sumedh Thakar
President and CEO

Yeah, I think it's the same that we had talked about when the log project came out and SolarWinds and stuff. Look, our customers typically tend to be enterprises, organizations that are more thinking of long term changes in their security programs and less about the knee jerk reaction of immediate spending. And that's kind of what we're seeing right now as well. A lot of these conversations are CISOs looking at the ways to use this post-mythos threat landscape to make the point to the team's internal stakeholders on long-term sustainable changes that they can make to their security program, where it's not that you do this one thing for the one month. For companies to roll out a program that allows them to do autonomous remediation, that's where they need to think through, work with different stakeholders, and then look at the budget, does it come from an existing solution that they can get rid of, is it something that they need to add on, et cetera. So I think we are early on, we feel like in these conversations, and we will see as the next few quarter goes to see what meaningful signals come in terms of when these budgets might be leveraged otherwise. But so far right now it's a lot more of positive conversations and pipeline building that we're doing. Thank you.

speaker
Operator

Thank you, and our next question will come from Patrick Colville with Scotiabank. Your line is open.

speaker
Patrick Colville
Analyst, Scotiabank

Thank you so much for having me on. I guess let me just ask Sumedh a question first, and then Joo Mi, I'd like to ask you one after, if possible. Great to see the guide, Sumedh, you know, fiscal year guide being raised from 8% to 10%. And then in your prepared remarks, talking about re-exerting growth in the long term, I guess, can I ask, one question is like, I think that's new disclosure. I don't think you've said that before. Can you just clarify that that is new? And then what gives you confidence, if it is new, to say that now? Is it stuff you're seeing or just conversations or just kind of help provide some color around that?

speaker
Sumedh Thakar
President and CEO

Yeah, I wouldn't say it's new, Patrick. I think we always talked about investing and innovating in the platform and our belief that what we're doing and helping with the focus on remediation is something that we've been working on strategically, along with a focus on federal and along with focus on working with our partners. to focus on that acceleration of growth in the long term. You know, getting into long term double digit growth has been a focus for us. So I think that is not new, so to say. I would say that given the current conversations that are happening, it just gives us an opportunity again to talk about what we've already built and the innovations that we've already done. and see how this maps to the current focus that the market has in terms of, look at the end of the day, the CISOs need to be able to go tell their board and management somehow that they are going to adopt some form of autonomous remediation. And so they're gonna have to figure out how they're gonna do that. look in the market, you know, with Qualys having 150 million patches deployed in the last 12 months, 40 million of those already being deployed autonomously. That gives us an interesting conversation point to build confidence for them when they're looking at these things. And so right now, you know, it's the same sort of what we've always talked about and focused on is working towards innovating and investing to create long-term growth and double-digit revenue growth is what we've always been looking at. And so this is just continuing on that momentum.

speaker
Patrick Colville
Analyst, Scotiabank

Okay. Very helpful, Sumedh. And, Joo Mi, if I may, the disclosure about new bookings, so 14% of new bookings were from ETM and CSAM, which, if my model is correct, that's the same as last quarter. and then 15% of new bookings from Patch in 2Q. Again, if my model is correct, that's the same as last quarter. So I guess I totally understand all the kind of qualitative commentary around ETM and Patch. How come it's not showing up more clearly in that new booking number? And should we expect that proportion of new bookings to ETM and CSAM and Patch to increase as we look towards the kind of 3Q and 4Q.

speaker
Joo Mi Kim
CFO

Yeah, in terms of the percentage contribution to bookings from your customers, we do anticipate fluctuations. We're not too surprised whether it goes up or down. So if you take a look at the percentage that made a from Patch Management last quarter was 15. This quarter is 16. You're right, on the ETN side, ETN CSAM, it's 14, the same as last quarter. We're not too surprised by it because it really depends more on the customer. So we're onboarding at that point in time what they end up starting off with. So for example, if we have a a new prospect that decide to purchase more of that or spend more of that budget on VMDR or versus ETM versus task management. We want to make sure that the customer is set up to succeed and grow with us. And so this percentage, it's a healthy percentage. What it lends itself to for us is it's really a validation that when we land new logos, go after the market, and when we're able to win, It's partly due to the fact that we were able to innovate and lead the market in terms of our continuous enhancement and our product solution set with ATM, CSAM, as well as patch management.

speaker
Patrick Colville
Analyst, Scotiabank

Thank you so much.

speaker
Operator

Thank you. And the next question is going to come from Rudy Kessinger with DA Davidson. Your line's open.

speaker
Rudy Kessinger
Analyst, DA Davidson

Hey, guys. Thanks for taking my questions. Congrats on the strong results here. you know I guess if I hear what you're saying in that you know the mythos stuff is is more so so in the pipeline and conversation stages and and that wasn't really the driver of the quarter it sounds like more so just better ETM execution but certainly seeing those demand trends I guess if your goal is to accelerate growth going forward I guess are you guys more willing to maybe utilize some of that margin and put that to work and maybe take margins down a bit further to help drive that accelerated growth? Or how should we think about the growth profitability trade-off into next year?

speaker
Sumedh Thakar
President and CEO

Look, I think we always look at, we've talked about this, we always look at investing in the innovation, investing in our sales and marketing as we have been doing more recently and I think we are, you know, we always focus on ROI and we see the opportunity ahead of us and as the opportunities move through the pipeline. It is something that we continue to evaluate. But at this point, we feel good about the investments that we're making. And I think as we see the opportunity, we will continue to evaluate that to make additional investments.

speaker
Joo Mi Kim
CFO

Right, and to double-click on that, part of the reason why we're able to accelerate the top-line growth currently without necessarily having to double-dip on the investment is the fact that we are a partner-first, partner-led growth momentum right now with majority of our growth, especially when it comes to new local acquisitions. We're working very closely with our partners, and we believe that we are investing appropriately at the current levels with the sales and marketing expense going up. 17% in Q1 and 14% in Q2. In the second half, we're anticipating further acceleration and the investments into sales and marketing.

speaker
Rudy Kessinger
Analyst, DA Davidson

Got it. Then for my follow-up, current calculated billings is really strong in the quarter. Anything to call out there as far as, you know, maybe early renewals or anything like that that drove the better sequential in year-over-year on CCB in Q2 and then for Q3 in the full year, just any directional commentary on CCB growth expectations?

speaker
Joo Mi Kim
CFO

From a current billings perspective, there's always naturally quarterly fluctuations. So I would point to the LTM, which just smooths out some of the lumpiness in the current billings growth rate, which is still an acceleration. As of last quarter, it was 8.5% under LTM growth. And then this quarter, it's at 10%. We're very pleased with the growth. And because of that, we decided to increase the Revenue Growth Guidance. In terms of the second half current billings growth, we're still anticipating for the baseline 7% to 8%, which implies a full year current billings growth in line with a revenue growth rate of 9% to 10%.

speaker
Rudy Kessinger
Analyst, DA Davidson

Super helpful. Thank you, and congrats again on the results.

speaker
Operator

Thank you. And the next question is going to come from Junaid Siddiqui with Truist. Your line's open.

speaker
Junaid Siddiqui
Analyst, Truist

Great. Thank you for taking my question. So Matt, TrueConfirm appears to be a powerful tool for ETM by helping customers validate which vulnerabilities are actually exploitable in their environment. Is that becoming like the land motion for ETM? You know, in other words, once customers see exploit validation reduce thousands of findings to a handful of truly exploitable risks, how often does that conversation expand into broader ETM remediation and risk quantification deployments?

speaker
Sumedh Thakar
President and CEO

That's a great question. I think, you know, when you look at the entire vulnerability life cycle to be successful with that, you know, there's a three bucket side, which is detection as fast as possible. And that's where our innovation with Agent Insta, which I call, I like to call it scanless scanning. The ability to post the detection in less than one hour makes it possible for you to get that visibility of what might be exposed. However, just based on what is exposed from a vulnerability perspective doesn't give you the confidence that this is actually exploitable and not exploitable in the environment because you have other tools that you might have put in place. And so we definitely see that with TrueConfirm, it's a differentiator. There are a lot of quote unquote CTEM solutions that are just aggregating findings and giving you a theoretical score. but that theoretical score doesn't necessarily tell you whether it is actually going to be exploitable or not. So when we are able to tell the customer, look, the ETM solution will help you theoretically reduce your findings to the 1% that matter and then additionally you can run these lightweight safe exploits to further reduce the number of findings that actually will work in your environment, that becomes a very interesting conversation because, why is that interesting? Because now that you have reduced the number of findings, it makes autonomous remediation, which is the next thing that we are selling to them, really plausible. If you tell somebody that you're gonna fix a million vulnerabilities autonomously, that's a very hard conversation, but if you can show to them that highly validated 70 vulnerabilities are the ones that we are going to fix with automation because they are confirmed exploitable and we cannot wait for attackers to exploit them, that conversation becomes a lot and so TruConform is definitely a key part of the conversation especially with our existing VMDR customers who are just getting great scanning now the ability to upgrade to ETM and then run the validation which then encourages them to look for the eliminate which is the remediation kind of all fits and makes all these pieces work together really well and so it is an important piece of every conversation we are having with existing customers.

speaker
Junaid Siddiqui
Analyst, Truist

Great thank you and just to follow up could you just help us understand the behavior of Those customers that have not yet adopted ETM, like those VMDR-only customers, are you still experiencing a high amount of churn there? And is that still the primary source of any pressure on your overall net dollar retention rate?

speaker
Sumedh Thakar
President and CEO

I think nothing to call out. these with the overall momentum of the business and it's we look at that as a great opportunity for us to talk to our existing VMDR customers because all of them are going to have to answer to their management and board what they are doing to find a way for autonomous remediation and so the conversation of upgrading to ETM and the conversation of upgrading and adding on eliminate We look at that VMDR customer base as, you know, a big base that we have where we can actually create growth opportunities because almost everybody is going to need some sort of a prioritization and remediation solution moving forward after the post-method era. So that's actually a pretty good way for us to look at it as, you know, I think less and less customers will, I mean, more and more customers I would say would want to look at a solution that's not just scanning but also giving them remediation and that's what we're seeing in the conversations right now. Thank you.

speaker
Operator

Thank you. And the next question will come from Joseph Gallo with Jefferies. Your line's open.

speaker
Grant Darling
Analyst, Jefferies

Hi, this is Grant Darling on for Joe Gallo. Thanks for taking the questions. I wanted to ask first, have you seen anything different competitively post-Methos release? It seems like we're hearing More chatter from a variety of players who are signaling more interest in the space. So your results certainly signal strength, but just curious if you're seeing or expecting any change in competitive dynamics, and also if there's any difference in the frequency of competitive displacements to call out.

speaker
Sumedh Thakar
President and CEO

Well, I think the problem the customers have is the chatter, right? There's too many solutions that are just throwing more and more CVEs, which is kind of the something that they're focusing on, and that creates a lot of chatter and noise for customers that they have to read through. And so where we are seeing success is not just the traditional, hey, let's find a million CVE findings. Where we are differentiating and why we are seeing that differentiator is things like TrueConfirm, where we're basically able to not just tell you the CVE is there, but actually have the ability to find a way to give you confidence in its exploitability by actually exploiting it in some cases, giving you additional information in other cases. Our autonomous remediation, while there's a lot of tools that are throwing out CVEs and tools that are saying that they can find something and then they will email the patching solution what they need to fix, we're actually natively patching that in a matter of hours. And so the interest is more to say, oh wait, there is a solution that can actually allow me to fix an exploited, exposed vulnerability in four hours from the release, versus I'm going to have a hodgepodge of these different solutions that is not actually going to work in the environment. And so I think that's really kind of what's driving the conversations right now, and that's what we're excited about.

speaker
Grant Darling
Analyst, Jefferies

Got it. And then maybe for my follow-up, you've referenced the growing federal pipeline a few times. I guess just any way to quantify the size of that business today and then just any more detail that you could provide regarding your thoughts about that opportunity and maybe your right to win there going forward.

speaker
Sumedh Thakar
President and CEO

It is right now not a big part of the business, but that is where the opportunity lies right now. I think if you look at the focus of the current administration, if you look at the new CISA board, very interesting that the new CISA board really talks about fast detection, exploit validation, and quick remediation. I've heard this somewhere for the last two years, right? So we focused on building this and being ready for this. The federal government is also very, very focused on ensuring that they are seeing outcomes, which are CISA's new requirement of remediating in 72 hours. How are you going to remediate something if your scan is taking two days? That's where Instascan is going to help you find the issue in the first 60 minutes, giving you a realistic chance to meet the board requirement. And so that is creating very, very positive conversations with the federal customers that we are engaged with. A lot of them have very old school traditional on-prem solutions for scanning, different solutions for patching. They've been trying to patch those together for a while. And now these boards and the focus from the administration is giving them an opportunity to look at something that is more modern and something that is really helping them give an outcome that is measurable. And so now with Qualys having a FedRAMP high, platform that actually is the only platform that can do both the detection and the patching as a FedRAMP high solution and our modern approach with agentic AI capabilities built in with these three different agents versus sort of having one generic agent that is just talking in the backend to Anthropic or something like that. It creates a big differentiation in our mind and I think that gives us the opportunity to go out and the right to have these conversations and work towards winning some of these opportunities that are coming our way. And so for us, given that right now it's not a big material part of the business, is where we see the big opportunity moving forward. And we're excited about the conversations and the investments that we're putting behind that.

speaker
Grant Darling
Analyst, Jefferies

Understood. Thank you.

speaker
Operator

Thank you. And the next question is going to come from Joshua Tilton with Wolf Research. Your line is open.

speaker
Joshua Tilton
Analyst, Wolf Research

Hey guys, can you hear me? Yes. Awesome. Apologize for the background noise. I am in Vegas for Black Hat. Maybe just two quick clarifications. First one, Joo Mi, I think you said you still expect 7% to 8% part of billing through up to the year. Can you help us understand, like, you know, why that stands or is unupdated from, I guess, what you expected last quarter, given the strong Billings growth in 2Q? Is it a conservative thing? Is it a 2Q is a blitz type thing? Just help us help us understand why that that full year outlook is left unchanged. Maybe I'll just I'll ask my second question now. Anyway, you can help us understand, you know, what what Net dollar retention rate is baked into the full year guidance since I think it's the second quarter now that it's kind of picked up for us. Thanks.

speaker
Joo Mi Kim
CFO

Yeah, to clarify, the current billings guidance for the full year is now in line with a revenue guidance of 9 to 10 percent. So the 7 to 8 percent is for the second half current billings. So what we're assuming is for the baseline, the second half current billings will grow by 7 to 8 percent year over year. and that's predicated on no meaningful change to our net dollar expansion rate, which is now at 105% versus 103 that we started off the year at.

speaker
Joshua Tilton
Analyst, Wolf Research

To be clear, the current billing is seven to eight is for the second half, you're saying?

speaker
Joo Mi Kim
CFO

That's right.

speaker
Joshua Tilton
Analyst, Wolf Research

Okay. Super helpful. Thank you.

speaker
Operator

Thank you. And the next question will come from Mike Sikos with Needham. Your line's open.

speaker
Joshua Tilton
Analyst, Wolf Research

If I could just pick up on where Josh was leaving off there. I think even earlier this year we were talking about a soft guide for that 7-8% CCB in calendar 26. Just given the year-to-date outperformance we've seen, Why not tweak that CCB even for back half of this year at 7% to 8%? Why not take that slightly higher? Again, we're coming off this mid-teens result you just posted in Q2. It doesn't seem like there was any real fluctuations from early renewals. So can you just help us think about what your assumptions are in deriving that 7% to 8% in the back half?

speaker
Joo Mi Kim
CFO

Yes, quarterly current because we don't actively manage to it, it tends to be lumpy. And so if you take a look at on an LTM basis, that's what we like to point to if you're trying to gauge the business momentum. So on an LTM current buildings growth rate last quarter, it was at 8.5%. This quarter, it's currently sitting at 10%. And so what we believe right now is It's great that we see that acceleration and the LTM current billings growth rate, and I think that that 10% better reflects the current business momentum today. And as Sumedh commented on before, we didn't know exactly when the acceleration or heightened kind of pressure from our existing customers, who are already pretty far along the discussion of ETM adoption, were really going to execute on those deals. Q2 is a reflection of that. If you were to take a look at our customer base and take a look at them and split them into two different camps, there are already a smaller cohort of customers that were pretty far along in the discussion around the ROC adoption upgrading to ETM that ended up translating into a better than expected results in Q2. But that said, the second camp of customers that are not as far along in discussion, what we're anticipating right now is we're not seeing any significant increases or acceleration in the sales cycle for the cohort of customers that are up for renewal in the second half. So given that it's a data point Q2 very strong quarter, we're not anticipating any meaningful material changes. in the deal cycle in second half and so therefore we decided to keep the baseline at seven to eight percent for the current billing scores for the second half of this year.

speaker
Joshua Tilton
Analyst, Wolf Research

Thank you for spelling that out to me and maybe another one here just wanted to get a better sense. It was great to see the last 12 months net dollar expansion improved by a point again this quarter to 105 especially since You have this improvement for total company. Meanwhile, the ETM and CSAM NDR was unchanged sequentially at 107. Can you, I guess, provide any further granularity, almost like a quarterly snapshot here, as far as what was driving the total company improvement from products or cohort of customers adopting or increasing spend? I'd just love to get a little bit more on that.

speaker
Joo Mi Kim
CFO

Yes, if you take a look at our product mix, that'll help you to kind of come with us in this journey of different product adoptions and as customers come up for renewal, where they decide to spend more on. So right now with our ETM and CSAM currently making up 12% of total bookings, up from 9% a year ago period. That kind of tells you that that's really helping to drive the bookings growth momentum that we see in the business today. Patch management definitely contributed to that as well, currently at 8% a year ago. It was at 7%. And then offsetting that was the VMDR contribution coming down to 49%, down from 54% a year ago.

speaker
Joshua Tilton
Analyst, Wolf Research

Excellent. Thank you so much.

speaker
Operator

Thank you. And the next question will come from Brian Essex with J.P. Morgan. Your line's open.

speaker
Brian Essex
Analyst, J.P. Morgan

Great. Good afternoon. Thank you for taking the question. I guess I have to. I think both for Jimmy. But I guess, Jimmy, I'd love to. It's great to see the traction that you've got on a partner side of the business on the indirect side. But I would love to kind of understand where you're guiding spending, particularly in sales and marketing, but for OpEx overall. I think, you know, last quarter you talked about mid-teens growth. It seems like you're pointed in the same direction, but you've You've come in well under that for the first half of the year. I'd love to understand, you know, where are you seeing traction? Where might you regulate greater spend? And, you know, what might, outside of outperformance on the top line in the back half of the year, you know, how are you regulating spend on OpEx and sales and marketing relative to that mid-team level when we've come in material below that in the first half? And then I got a follow-up.

speaker
Joo Mi Kim
CFO

Yeah, on the sales and marketing spend, majority of that spend increase is driven by the headcount. So if you take a look at the 17% year over year for Q1 and 14% year over year for Q2, both quarters, majority of it was basically investing back into our business, expanding our team, making sure that we have the right team members. and the GTM team, whether it be sales or marketing or product, all across the board that's really focused on selling our product and better positioning ourselves and working very closely with our partners. Now, with that said, we are leveraging AI back into our business as well, and that certainly helped to make sure that we're looking at the operating efficiency, making sure that it's appropriate level of investment that we're spending each quarter. And so with that in mind, we're very pleased with the momentum that we see Today, and we do anticipate increasing spend, whether it be number one is always going to be headcount for us right now for 2026, but there are other certainly investments that we're making, which is demand, making sure that we're investing that business to generate sufficient pipeline that's quality that we can execute off of the second half of this year.

speaker
Brian Essex
Analyst, J.P. Morgan

Okay, great. That's helpful. And maybe just how far penetrated are you into your installed base with QFlex? and how are you regulating the level of availability that customers might have for QFlex? Are you still measuring it and keeping it kind of like the high-end customers or could we expect maybe a broader rollout as you develop more experience with QFlex across your customer install base?

speaker
Joo Mi Kim
CFO

Yeah, we have rolled out two flights. It's really more intended for our enterprise customers. And so now it's available, generally available to price customers. And we are having and many more. Thank you for joining us. for existing customers. As we look to drive our net dollar expansion rate further up and continue to focus on that metric as customers grow with us, it will be right for our enterprise customers who are looking for a cost-effective way to gain more value while at the same time increasing their spend with quality.

speaker
Brian Essex
Analyst, J.P. Morgan

Okay, that's helpful. Thank you.

speaker
Operator

Thank you. And the next question comes from Srinik Kothari with Bayard. Your line is open.

speaker
Srinik Kothari
Analyst, Bayard

Thanks for taking my question. Again, congrats on the great quarter. Sumedh, big picture, you did underscore that near term there is a stronger patch management cycle, but you believe there's a broader category reset underway around the control plane for The P, Bridge, Risk Management, as you described, Exploited Validation, Risk Quantification, and Autonomous Remediation. Around the AI urgency, I remember last quarter you guys did say since it's broadening the opportunity, customers may extend sales cycles or pause renewals. Can you add any finer points around these broader strategic deals, conversion, timing, sales cycles? How long are these evaluations taking? Are you seeing these conversion rates getting faster broadly, just directionally, and then add a quick follow-up?

speaker
Sumedh Thakar
President and CEO

Yeah, that's a great question. I think, as I mentioned earlier, too, and when we talk about the ROC, the Risk Cooperation Center pre-breach risk management is broader than just vulnerability management. Obviously, that is the focus right now we've talked about. the use of misconfigurations as part of these attacks the use of identities and the recent open air hugging face was a great example of a vulnerability misconfiguration and identity being used and so the risk cooperation center has been broadly built around that I think in terms of the way we are seeing the conversations is not about saying can I just patch for the next one month and I'm done. I think there is a, the conversation with customers are really about nobody is saying that they're just gonna patch now and then go back to not having regular patching cycle and autonomous matching in the future. So the broad-based conversation is about how are they moving forward, create a process throughout their organization that is long-lasting where they're able to, you know, any threat that comes out they're able to actually respond to that threat very quickly and so we see this more as something that is that is broadly being talked about and we see the opportunity for that to be something that we can focus on and so I think right now like with any corporation large companies they want to understand what the big picture roadmap is that they can talk to their management about while focusing on sort of phases that they can deploy and so that rock conversation allows us to have a much broader strategic conversation with ETM. And then the vulnerability management, patch management is something more of a, that they're focusing on right now to be able to have that phased approach. So overall, I think our innovation around rock that we have been focusing on is coming to the help quite a bit for these customers to have broader conversation while the focus right now is changing their patch management processes and programs. So I do think that The opportunity, or rather, this is giving us an opportunity to have those broader conversations with the customer. And as Joo Mi said, of course, there were a small cohort of customers that was already in this process before Mythos came out to adopt patch management. Just a reminder, 150 million patches already applied by Qualys. So some customers have been at the forefront of these. So that helped us sort of say, look, we were right. The customers were like, look, we're already in the process. We were right to focus on patch management. So that helps in the short term, but then there's a long cohort of customers that are having these conversations now and is going to create the opportunity for us to have sustained conversations of additional things in the ROC as we move forward and they get comfortable with auto-patching.

speaker
Srinik Kothari
Analyst, Bayard

Got it. Very helpful. And Joo Mi, just a follow-up to Mike and Josh's question around the NDR improvement. Very encouraging to see that pick up. The ETM cohort, though, remained at 107, I think they highlighted. But is QFlex going live? And you did highlight it's playing a direct role in several of these large platform expansion, also helping pull forward the commitment, helping bookings more than near-term usage. So is that what is explaining these budgets shifting towards more newly urgent capabilities reflected in your So, NDR next 12 months versus something more strategic around ETM, CSAM usage will follow through. Just wanted to understand if QFlex is playing a role there.

speaker
Joo Mi Kim
CFO

Yeah, QFlex is really nuts. to accommodate customers who are looking for that flexibility and who are willing to spend more with us. And so we wanted to make the selling motion seamless, easier for them, where it creates a win-win opportunity for both the customers as well as us. And so we're very pleased with us going GA with it broadly. It still applies to a small percentage of customers today who signed up for QFLI, so it's not yet reflected in the numbers, but we believe that this will help drive the NDR up for us broadly speaking.

speaker
Srinik Kothari
Analyst, Bayard

Got it. Very helpful. Thanks.

speaker
Operator

Thank you. This will conclude today's question and answer session and also concludes today's conference call. Thank you so very much for participating and you may now disconnect.

Disclaimer

This conference call transcript was computer generated and almost certianly contains errors. This transcript is provided for information purposes only.EarningsCall, LLC makes no representation about the accuracy of the aforementioned transcript, and you are cautioned not to place undue reliance on the information provided by the transcript.

-

-