CrowdStrike Holdings, Inc.
CRWDBusiness Summary
CrowdStrike operates in the cybersecurity industry, which it describes as being transformed by the shift to cloud-native, AI-driven security solutions. The company defines a new category called the AI Security Cloud, which it believes has the power to transform the cybersecurity industry the same way the cloud has transformed customer relationship management, human resources, and service management industries. The filing notes that adversary sophistication continues to increase, with militaries and intelligence services of well-funded nation-states, technically advanced criminal organizations, and hackers advancing their tactics, and that the commoditization of technologies like generative AI makes it easier for low-skilled adversaries to move faster and launch more sophisticated attacks.
CrowdStrike positions itself as an industry leader in protection across endpoints, cloud workloads, identity data, and AI systems. The filing names competitors by general category: legacy antivirus product providers, alternative endpoint security providers, network security vendors, cloud security vendors, identity security vendors, professional service providers, and legacy SIEM vendors. The company states that it does not believe any of its competitors currently have a true platform offering equivalent to the Falcon platform. CrowdStrike competes on factors including its ability to offer a unified and modular platform, its ability to identify security threats and prevent security breaches, its ability to integrate with other participants in the security ecosystem, time to value, price, total cost of ownership, brand awareness, reputation, strength of sales and marketing and channel partner relationships, customer support, incident response, and its ability to rapidly ingest and search both first and third-party data.
CrowdStrike generates revenue primarily through a SaaS subscription-based model for its Falcon platform and cloud modules, with additional revenue from professional services. Subscription revenue accounted for 95% of total revenue for each of fiscal 2026 and fiscal 2025. Professional services revenue accounted for 5% of total revenue for each of fiscal 2026 and fiscal 2025. The company's subscriptions are generally priced on a per-endpoint and per-module basis, and a substantial majority of customers purchase subscriptions with a term over one year. The company views its professional services business primarily as an opportunity to cross-sell subscriptions to its Falcon platform and cloud modules.
As of January 31, 2026, CrowdStrike offered 32 cloud modules on its Falcon platform, and currently delivers 33 cloud modules. Key areas of focus include Endpoint Security, Cloud Security, Exposure Management, Managed Detection and Response (MDR), Counter Adversary Operations, Identity Protection, Next-Generation SIEM and Log Management, Generative AI (including Charlotte AI), Securing AI (including AI Detection and Response), IT Automation, SaaS Security (Adaptive Shield), Data Protection, and Application Development (Falcon Foundry). The Falcon platform is composed of tightly integrated proprietary technologies including a lightweight sensor and the Enterprise Graph, which unifies Threat Graph, Intel Graph, and Asset Graph. The company also offers professional services including incident response, forensic investigatory, and breach recovery services; technical assessment and strategic advisory services; Next-Gen SIEM consulting; platform deployment and operational services; and training and certifications.
During fiscal 2026, CrowdStrike completed acquisitions of Onum Technology Inc. and Pangea Cyber Corporation, with net cash used for business acquisitions of $382.3 million 1. The company also entered into definitive agreements to acquire SGNL.AI, Inc. for $627.9 million in cash, net of $9.4 million of cash acquired 2, and Seraphic Algorithms Ltd. for $327.4 million in cash, net of $1.1 million of cash and restricted cash acquired 3, both of which closed after the fiscal year end. In June 2025, the board of directors authorized a share repurchase program of up to $1.0 billion 4 of outstanding common stock. The company also implemented a Strategic Plan during the year, which resulted in charges of $3.4 million 5 in subscription cost of revenue, $3.3 million 6 in professional services cost of revenue, $9.0 million 7 in sales and marketing expenses, $16.6 million 8 in research and development expenses, and $12.5 million 9 in general and administrative expenses.
Total revenue for fiscal 2026 was $4,812,005,000 10, an increase of 22% compared to $3,953,624,000 11 in fiscal 2025. Subscription revenue grew 21% to $4,564,683,000 12 from $3,761,480,000 13, and professional services revenue grew 29% to $247,322,000 14 from $192,144,000 15. The company reported a net loss attributable to CrowdStrike of $162,502,000 16 for fiscal 2026, compared to a net loss of $15,241,000 17 in fiscal 2025. Gross margin was 75% 18 for both fiscal 2026 and fiscal 2025. Cash and cash equivalents were $5,230,125,000 19 as of January 31, 2026, up from $4,323,295,000 20 as of January 31, 2025.
Business Outlook
CrowdStrike's growth strategy includes growing its customer base by replacing legacy and other endpoint security products, further penetrating existing customers through its land-and-expand model, leveraging its Falcon platform to enter new markets, broadening its reach into new customer segments (including small and medium-sized businesses through its trial-to-pay model), broadening its reach into U.S. public sector verticals, and expanding its international footprint. The company grew its international revenue from $1,270.7 million 21 for fiscal 2025 to $1,595.4 million 22 for fiscal 2026, representing an increase of 26% 23. The company intends to grow its international customer base by increasing investments in overseas operations, including adding headcount in Europe, the Middle East, Asia-Pacific, including Japan, and expanding data centers overseas. The company also plans to continue investing in the CrowdStrike Store to empower partners and enable customers to more easily discover, try, and purchase additional cloud modules.
CrowdStrike's growth strategy also includes extending its Falcon platform and ecosystem through the CrowdStrike Marketplace, the first open cloud-based application PaaS for cybersecurity. The company plans to continue investing in the CrowdStrike Store to empower partners by making it easier to build applications and to enable customers to more easily discover, try, and purchase additional cloud modules from both trusted partners and CrowdStrike. The company also endeavors to work with more partners, new partner types, new technology companies, and new service providers to help more customer segments and new customers realize novel outcomes from the Falcon Platform. Additionally, the company is expanding options for new customers to test modules on a trial basis as well as offering in-application trials for existing customers.
The filing states that the company expects its gross profit to increase in dollar amount and its gross margin to increase modestly over the long term as it grows its business, although gross margin could fluctuate from period to period. The company expects sales and marketing expenses to increase in dollar amount as it continues to make significant investments in its sales and marketing organization, but anticipates they will decrease as a percentage of total revenue over time. Research and development expenses are expected to increase in dollar amount as the company continues to increase investments in its technology architecture and software platform, but are anticipated to decrease as a percentage of total revenue over time. General and administrative expenses are expected to increase in dollar amount over time, and the company expects to incur significant legal and professional services and other expenses associated with the July 19 Incident and related matters in future periods.
The company expects to continue to invest broadly across its organization to support growth. The company's research and development organization is responsible for the design, architecture, operation and quality of its cloud native Falcon platform, and the company plans to continue to dedicate significant resources to research and development. The company has data center co-location facilities throughout the United States and in Europe, and also utilizes third-party data centers located in the United States and Europe. The company's technology infrastructure, combined with select use of third-party resources, provides it with a distributed, resilient and scalable architecture on a global scale. As of January 31, 2026, the company had 10,698 24 full-time employees.
The filing does not provide specific R&D spending levels, capital expenditure plans, or share repurchase authorization amounts beyond the $1.0 billion authorization already noted. The company has never declared or paid any cash dividends on its capital stock and currently intends to retain all available funds and any future earnings for use in the operation of its business, not expecting to pay any dividends in the foreseeable future.
The July 19 Incident has had, and is expected to continue to have, an adverse effect on the company's business, sales, customer and partner relations, reputation, results of operations and financial condition. The company has incurred, and expects to continue to incur, significant costs and expenses related to the incident. The company has experienced delays in creating sales opportunities and longer sales cycles, including delays in customer purchasing decisions, and sales cycles may be elongated in future periods. Customer commitment packages introduced following the July 19 Incident have resulted, and are expected to continue to result, in increased contraction due to elongated subscription terms and decreased upsell dollar values. The company is also party to a number of legal proceedings relating to the July 19 Incident, including securities litigation, derivative litigation, and putative class actions, and has received inquiries from governmental authorities.
The company faces risks from macroeconomic factors, including inflation and instability in the global credit and financial markets, which have in the past and may in the future cause current and prospective customers to delay or cut their overall security and IT operations spending. The company also faces risks related to its international operations, including greater difficulty in negotiating contracts, higher costs of doing business internationally, risks associated with trade restrictions and foreign legal requirements, compliance with anti-bribery laws, and the uncertainty of protection for intellectual property rights in some countries. Additionally, the company is subject to stringent, complex and evolving laws, rules, regulations and standards in many jurisdictions relating to data privacy and security, and any actual or perceived failure to comply could have a material adverse effect on its business.
Risk Factors
The July 19 Incident has had, and is expected to continue to have, an adverse effect on the company's business, sales, customer and partner relations, reputation, results of operations and financial condition. The company has incurred significant costs and expenses related to the incident, including $82.4 million 25 in general and administrative expenses associated with the July 19 Incident and related matters during fiscal 2026. The company is party to a number of legal proceedings relating to the incident, including securities litigation, derivative litigation, and putative class actions, and has received inquiries from governmental authorities. The company has a history of losses, with an accumulated deficit of $1.3 billion 26 as of January 31, 2026, and while it achieved profitability in fiscal 2024 with net income of $72.2 million 27, it may not be able to achieve or sustain profitability in the future. The company faces intense competition from legacy antivirus providers, alternative endpoint security providers, network security vendors, cloud security vendors, identity security vendors, professional service providers, and legacy SIEM vendors, many of which have greater financial, technical, marketing, sales, and other resources.
Management Priorities
Management's message emphasizes that CrowdStrike reinvented cybersecurity for the cloud and AI era and transformed the way cybersecurity is delivered and experienced by customers. Key themes include the company's AI-native Falcon platform serving as the operating system for cybersecurity, the power of its Security Cloud and crowdsourced data creating a powerful network effect, and the company's land-and-expand sales strategy evidenced by a 115% 28 dollar-based net retention rate as of January 31, 2026. Management highlights that the company's approach has defined a new category called the AI Security Cloud, which has the power to transform the cybersecurity industry. The filing also discusses the company's strategic priorities including growing its customer base by replacing legacy products, further penetrating existing customers, leveraging the Falcon platform to enter new markets, broadening reach into new customer segments and U.S. public sector verticals, and expanding its international footprint. Management acknowledges the July 19 Incident and states that the company is investing in enhancements to software resiliency, testing and customer controls following the incident.
View Source Annual Report on SEC.gov ↗
References
- [1] Item 7, MD&A — Cash Flows
- [2] Item 7, MD&A — Contractual Obligations and Commitments
- [3] Item 7, MD&A — Contractual Obligations and Commitments
- [4] Item 1A, Risk Factors — Risks Related to Ownership of Our Common Stock
- [5] Item 7, MD&A — Cost of Revenue, Gross Profit, and Gross Margin
- [6] Item 7, MD&A — Cost of Revenue, Gross Profit, and Gross Margin
- [7] Item 7, MD&A — Sales and Marketing
- [8] Item 7, MD&A — Research and Development
- [9] Item 7, MD&A — General and Administrative
- [10] Item 8, Consolidated Statements of Operations
- [11] Item 8, Consolidated Statements of Operations
- [12] Item 8, Consolidated Statements of Operations
- [13] Item 8, Consolidated Statements of Operations
- [14] Item 8, Consolidated Statements of Operations
- [15] Item 8, Consolidated Statements of Operations
- [16] Item 8, Consolidated Statements of Operations
- [17] Item 8, Consolidated Statements of Operations
- [18] Item 7, MD&A — Cost of Revenue, Gross Profit, and Gross Margin
- [19] Item 8, Consolidated Balance Sheets
- [20] Item 8, Consolidated Balance Sheets
- [21] Item 1, Business — Broadening Our International Footprint
- [22] Item 1, Business — Broadening Our International Footprint
- [23] Item 1, Business — Broadening Our International Footprint
- [24] Item 1, Business — Human Capital Resources
- [25] Item 7, MD&A — General and Administrative
- [26] Item 1A, Risk Factors — Risks Related to Our Business and Industry
- [27] Item 1A, Risk Factors — Risks Related to Our Business and Industry
- [28] Item 7, MD&A — Key Metrics
- [29] Item 8, Consolidated Statements of Operations
- [30] Item 8, Consolidated Statements of Operations
- [31] Item 8, Consolidated Statements of Operations
- [32] Item 8, Consolidated Statements of Operations
- [33] Item 8, Consolidated Statements of Operations
- [34] Item 8, Consolidated Statements of Operations
- [35] Item 8, Consolidated Statements of Cash Flows
- [36] Item 8, Consolidated Statements of Cash Flows
- [37] Item 1A, Risk Factors — Risks Related to our Indebtedness
- [38] Item 7, MD&A — Cost of Revenue, Gross Profit, and Gross Margin
- [39] Item 7, MD&A — Cost of Revenue, Gross Profit, and Gross Margin
- [40] Item 7, MD&A — Cost of Revenue, Gross Profit, and Gross Margin
- [41] Item 7, MD&A — Key Metrics
- [42] Item 7, MD&A — Key Metrics
- [43] Item 7, MD&A — Key Metrics
Analysis on 6/8/2026