CrowdStrike Holdings (NASDAQ:CRWD) held its second-quarter earnings conference call on Wednesday. Below is the complete transcript from the call.
This transcript is brought to you by Benzinga APIs. For real-time access to our entire catalog, please visit https://www.benzinga.com/apis/ for a consultation.
Access the full call at https://crowdstrike-fiscal-second-quarter-2027-results-conference-call.open-exchange.net/registration
Summary
CrowdStrike Holdings, Inc. reported a record Q2 with net new ARR of $333 million, up 51% year-over-year, and total revenue of $1.47 billion, marking a 26% increase year-over-year.
The company raised its FY27 net new ARR growth guidance to 34% at the midpoint, reflecting strong demand for its Falcon platform driven by AI adoption.
Record Falcon Flex performance with ARR surpassing $2.29 billion, growing 101% year-over-year, indicates strong customer adoption of flexible subscription models.
CrowdStrike's next-gen SIEM, identity, and cloud businesses all showed robust growth, contributing significantly to the company's performance.
Management highlighted the increasing importance of AI security, noting strong customer demand for AIDR and the necessity of protecting AI-based assets.
The company's gross margin increased to 79%, with a notable rise in non-GAAP operating income to $372 million, demonstrating strong operational efficiency.
CrowdStrike's partner ecosystem, including the QuiltWorks initiative, showed significant traction, contributing to pipeline growth and customer acquisition.
The company emphasized its strategic positioning as a leader in cybersecurity for AI environments, with a focus on expanding its product offerings and customer base.
Full Transcript
OPERATOR
Hello and welcome to CrowdStrike's fiscal second quarter 2027 financial results conference call. At this time, all participants are in a listen-only mode. After the speaker's presentation, we will conduct a question-and-answer session. Please be advised that today's conference is being recorded. I would now like to hand the call over to Andy Nowinski, Vice President of Investor Relations and Strategic Finance. Andy, please go ahead.
Andy Nowinski, Vice President of Investor Relations and Strategic Finance
Good afternoon and thank you for your participation today. With me on the call are George Kurtz, Chief Executive Officer and founder of CrowdStrike, and Burt Podbere, Chief Financial Officer. Before we get started, I would like to note that certain statements made during this conference call that are not historical facts, including those regarding our future plans, objectives, growth, including projections and expected performance, including our outlook for the third quarter and fiscal year 2027 and any assumptions for fiscal periods beyond that, are forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995. These forward-looking statements represent our outlook only as of the date of this call. While we believe any forward-looking statements we make are reasonable, actual results could differ materially because the statements are based on current expectations and are subject to risks and uncertainties. We do not undertake and expressly disclaim any obligation to update or alter our forward-looking statements, whether as a result of new information, future events, or otherwise.
Further information on these and other factors that could affect the company's financial results is included in the filings we make with the SEC from time to time, including the section titled Risk Factors in the company's annual and quarterly reports. Additionally, unless otherwise stated, excluding revenue, all financial measures disclosed on this call will be non-GAAP. A discussion of why we use non-GAAP financial measures and a reconciliation schedule showing GAAP vs. non-GAAP results is currently available in our earnings release, which may be found on our investor relations website at ir.crowdstrike.com or on our Form 8-K filed with the SEC today. With that, I will now turn the call over to George.
George Kurtz, President and CEO
Thank you, Andy, and thank you for joining CrowdStrike's Q2 FY27 earnings call. When we last spoke, we were just weeks after what we called the Mythos moment, an inflection point in cybersecurity. The world came to understand that cybersecurity is a necessity for AI adoption. New models created a new risk environment with no turning back. Recently, this realization became even clearer with the market's newest adversary, AI agents themselves. We told you this was the future, and this future is now a reality.
Our previous guidance foreshadowed this conviction, and CrowdStrike's Q2 was our very best quarter in company history. Inflection has become acceleration. Our Q2 results set a new bar. Here's what we delivered. 1. All-time record net new ARR of $333 million, accelerating to 51% year-over-year growth and beating the high end of our guidance by more than $45 million. 2. Ending ARR growth accelerated for the fourth consecutive quarter, reaching $5.84 billion, up more than 25% year over year. 3. Total revenue growth accelerated for the fifth consecutive quarter, reaching $1.47 billion, up 26% year over year. 4. Q2 record free cash flow of $377 million, or 26% of revenue, growing 33% year over year. 5. All-time record operating income of $372 million, or 25% of revenue, growing 46% year over year. 6. All-time record net new ARR from new logos, while both net and gross dollar-based retention improved over the prior quarter. 7. All-time record Falcon Flex quarter with ending ARR from accounts that have adopted the Falcon Flex subscription model surpassing $2.29 billion, accelerating to 101% year-over-year growth, and 8.
FY27 net new ARR guidance increase of 630 basis points. We now expect year-over-year growth of 34% at the midpoint, an 1150 basis point increase from our initial outlook. The quarter was a sea change for CrowdStrike, and I see these dynamics continuing. We're in an arms race. AI is driving more cyberattacks. AI is driving more cyber spending. AI is driving a clear divide between the cybersecurity companies that solve problems and those that compound problems.
CrowdStrike's quarter demonstrates the market trusting us more than ever to secure their adoption of AI. With cybersecurity's single platform of choice, the world's adoption of AI is rapidly expanding the attack surface. More models, more agents, more agentic applications, more data—and with that, more identities, more permissions, more policies, more cyberattacks, and more risk. Agent proliferation is becoming mainstream to augment work and personal life.
Agents are powerful forces for productivity, and good agents are also human and machine risk multipliers with access to data, continuous operational capability, and limited judgment. We're seeing agents go rogue, swarming to attack and moving beyond their guardrails to autonomously harm. Agents are proven capable of data theft, permission alteration, and full-on command and control at scale, leading to organizational compromise. The agent of today is both a friend and foe.
The currency of protection is increasingly presence and speed. Do you have the right technology deployed that can see, prevent, and stop agentic attacks? Do you have the right technology that can outpace an entirely new, real-time adversary? The AI threat environment is shining a clear light on which products work and which don't. We see failing products as open doors for agentic adversaries. At CrowdStrike, we don't just stop these breaches; we and our partners help the world recover from them.
In this threat landscape, CrowdStrike stands out. Our market-leading cybersecurity services are in high demand. The flywheel we've created of best-in-class incident response services—lauded by law firms and insurance brokers—translates into best-in-class product outcomes for new customers. Ever since Mythos, we've seen growth in our business not measured by meetings or calls, but measured by ARR. And we don't see the threat landscape subsiding. Far from it. Demand for AI grows, driving the need for CrowdStrike. The AI transformation doesn't just necessitate a technological lift and shift, it's necessitating a fundamentally new go-to-market motion, one based on maximizing time to value, ecosystem impact, and ROI. The Falcon platform removes friction from cybersecurity, and the go-to-market motion we created with Falcon Flex does the same. Flex is the commercial harness to enable customer success in the agentic era.
This quarter, we kicked Falcon Flex activity into high gear with our Flex-first go-to-market strategy. Our top 10 deals by deal value were each Flexes, and the results speak for themselves. This quarter, we delivered record Flex deal volume, adding more than 935 Flex accounts. That's more than 10 Flexes every day of the quarter and more Flexes than the last three quarters combined. When Falcon customers convert from standard subscriptions to Flex, we see a greater than 40% average ending ARR uplift.
We're not just focused on converting existing customers to Flex; we use Flex from the start. With new-logo customers, Flex new-logo ARR contributed 34% of Q2 net new ARR, a record. We also saw record Reflex activity for existing Flex customers, with more than 630 accounts having reflexed at least once, up 6x year over year. On average, a customer's first Reflex happens in eight months from their initial Flex. Lastly, we saw record repeat Reflex customers, with average ending ARR uplift of 53% from their initial Flex subscription.
Falcon Flex wins include a frontier lab that significantly grew with CrowdStrike in an eight-figure ARR deal, using Flex to maintain cost visibility while significantly growing Falcon Cloud Security across its rapidly expanding data center infrastructure. A European automotive manufacturer called upon CrowdStrike to replace a next-gen EDR, a legacy SIEM, and a legacy vulnerability management product. Landing with an eight-figure net new Falcon Flex, CrowdStrike delivered superior outcomes and immediate platform consolidation.
Our Falcon Flex go-to-market motion unlocks the complete aperture of the Falcon platform. When looking at our Q2 performance, I'm pleased to see strength across so many different product areas. Increasingly the epicenter of agentic work, securing the endpoint is now a top spend priority. CrowdStrike is the leader in endpoint. We're now capitalizing on our ubiquitous endpoint presence to deliver the future of AI security. In Q2, our endpoint business accelerated for the fourth consecutive quarter as customers look to secure their growing AI attack surface.
We're seeing dramatic expansion in agentic work on the endpoint, both through fast-growing tools such as Codex and Claude, as well as custom agentic applications. In sampling our customer base, we've seen more than 400% growth in Claude usage and more than 100% growth in custom agent usage on endpoints in recent months. As enterprises look to deploy these new technologies, they're also seeking ways to contain the new risk created, ranging from code exploitation to data leakage to identity compromise.
Instead of turning to science projects or point products, the market is trusting CrowdStrike as critical infrastructure to both enable and safeguard their AI future. A large financial services firm worked with two of our GSI partners to replace a next-gen EDR in an eight-figure Flex win across more than 100 entities and hundreds of thousands of endpoints. CrowdStrike was selected for the best detection, coverage, deployment ease, and the lightest impact.
Our endpoint success fuels the adoption of AIDR, a product surging past our expectations. AIDR ending ARR nearly tripled versus Q1 as customers embrace our frictionless approach to AI visibility and security. One of the world's largest banks adopted AIDR in an eight-figure Flex win. Immediate AI deployments necessitated security, visibility, and control. We were selected for AI usage visibility and data exfiltration prevention. Demand, adoption, and growth like this is rarely seen.
I can't wait to unveil our newest AI security innovations at next week's Falcon conference. Moving to our Cloud, Identity, and next-gen SIEM businesses, the market is rapidly embracing these products to protect fast-expanding attack surfaces. We delivered record Q2 net new ARR from the combination of these businesses. Unpacking these results, our next-gen SIEM business delivered another banner quarter driven by record Q2 net new ARR. Next-gen SIEM ending ARR surpassed $695 million this quarter as both new and existing customers are standardizing on Falcon as the operating system of the SOC.
Our native first-party data advantage, coupled with the speed and efficiency of our platform, continues to set us apart. Features like AgentWorks enable security teams to build, deploy, and manage custom AI security agents, setting the foundation for the AI SOC. In an eight-figure Falcon Flex win, a major American power provider replaced a legacy acquired SIEM, selecting next-gen SIEM over a firewall-first product for technical speed and economic superiority.
Turning to our Identity business, ending ARR grew 34% year over year to more than $585 million, driven by strength across our Identity product portfolio. Specifically, Falcon Shield had another strong quarter as enterprises looked to secure their third-party agentic applications. Shield ending ARR grew more than 185% year over year in Q2. In addition, our privileged account security offering saw stellar adoption, with ending ARR growing more than 35x year over year.
Rounding out our Identity portfolio, we're seeing early success with Signal. Large enterprises are rethinking decades of legacy access controls no longer effective for the agentic era. Instead, they're embracing Signal's real-time, granular access model for both humans and non-human alike. In one customer alone, Signal brokered more than 30 million unique access decisions without friction. A major global financial firm added next-gen Identity to their Falcon deployment following a board-mandated AI security audit.
Hand in hand with next-gen Identity was an immediate deployment of AIDR, where identity protection enabled AI adoption. Moving on to Cloud, where ending ARR exceeded $905 million, growing more than 29% year over year, CrowdStrike is the leader in cloud runtime security, which has become an imperative in protecting modern AI workloads. Our customers tell us that point-in-time posture scans are no longer enough to protect against fast-moving threats that now proliferate in seconds.
A mega technology conglomerate opted to use Falcon Cloud Security for our runtime superiority in an eight-figure ARR win. CrowdStrike now secures this organization's AI cloud and labs because of our build pipeline integration and compatibility with internal tools resonating with their DevOps teams. Finally, we're seeing the Mythos moment transform the market's need for exposure management, pressuring antiquated vulnerability management products built for a bygone era.
The agentic adversary has broken the exploit sound barrier, and you simply cannot patch vulnerabilities fast enough. As the patch window collapsed, our exposure management business accelerated sequentially in Q2. Falcon Exposure Management offers real-time detection and continuous prioritization to successfully contain a new speed and scale of vulnerability risk. A representative exposure management win included a global religious organization that replaced a legacy vulnerability management product as part of their AI transformation initiatives.
In this seven-figure Flex, the account also immediately deployed AIDR to bring visibility and control to its AI usage, showcasing CrowdStrike's position to protect against AI threats and govern AI adoption. Our partner ecosystem is mobilized around Falcon and its role in securing AI. Project Quiltworks has united more than 25 of our partners—from GSIs to hyperscalers, resellers to ISVs, and even distributors and MSPs. To date, our Quiltworks partners are collaborating with us on nearly $400 million of total contract value pipeline.
We've seen exceptional engagement from GSI partners, resulting in our GSI business growing nearly 50% year over year, largely focused on next-gen SIEM transformations and vulnerability management needs. Across our MSSP business, we're seeing significant traction in the SMB space with key partners such as Kroll. Three quarters ago, Kroll took a strategic step to migrate all of its customers off a competing next-gen endpoint technology. A majority of customers already successfully migrated to Falcon across 450,000 endpoints.
Tracking ahead of plan, Kroll took a major next step with a multi-year Flex subscription, growing their spend with CrowdStrike by more than three times. This Flex addresses platform consolidation and SIEM transformation across Kroll's existing Falcon install base and incoming new customers. In another Q2 win, Accenture standardized on CrowdStrike for its new SMB-focused Accenture Edge business launched in June. Lastly, Q2 showcased the power of our one-of-a-kind cloud marketplace go-to-market motion.
Across AWS, Google, and Microsoft—each of our hyperscaler marketplace partners—we saw a record Q2 as customers use their hyperscaler of choice for security investments. In Q2 alone, we transacted more than $600 million in deal value through cloud marketplaces, representing more than 30% year-over-year growth. We quickly saw traction with our Microsoft Marketplace presence, opening a new addressable market. Immediate Microsoft Marketplace wins included a new-logo Australian healthcare provider starting to use CrowdStrike for SOC transformation in a seven-figure Flex.
An American manufacturing firm previously used our services and has now expanded to the Falcon platform through a seven-figure Flex on Microsoft Marketplace. In closing, Q2 was an incredible quarter where the Mythos moment turned into acceleration—acceleration in net new ARR, acceleration in ending ARR, acceleration in Falcon Flex, acceleration in our ecosystem, acceleration in innovation. We're seeing endpoint as the epicenter for AI adoption. We're seeing AIDR define a new cybersecurity category. We're seeing next-gen SIEM as the operating system of cybersecurity, Falcon Identity becoming the security front door for human and non-human users, and exposure management as mission critical for prioritizing AI risk. Taken together, the Falcon platform is cybersecurity's infrastructure layer for AI adoption. AI adoption is accelerating from frontier labs and open-weight models alike, and we're still in the early innings of the AI revolution.
When I look at our business, here's what this acceleration means: last quarter we raised our forward net new ARR growth guidance by 520 basis points, and this quarter we're raising our FY27 year-over-year net new ARR growth outlook by an additional 630 basis points, even more than last quarter. That's a raise to our net new ARR guidance of more than $100 million since the start of the year. Delivery of a quarter like this and this outlook is fueled by the demand environment and our technology team, ecosystem, and customers.
The innovation engine is in overdrive. As I shared last quarter, Dr. Bartley Richardson, previously at NVIDIA, has joined us as our Chief AI Autonomous System Officer as part of our long-planned and mutually agreed upon CTO leadership transition. I can't wait to share the vision and innovation that we are bringing to the world's adoption of AI at Falcon in Las Vegas next week. The conference sold out in early August, and it's our largest pipeline generation event of the year.
We'll have record customer and partner attendance. I also encourage everyone to tune into our investor briefing on Wednesday, September 2nd. Our role in securing enterprises, governments, and economies is vital to AI adoption and mission critical in an AI-first world. I'll now turn the call over to Burt Podbere, CrowdStrike's CFO.
Burt Podbere, Chief Financial Officer
Thank you, George, and good afternoon, everyone. As a quick reminder, unless otherwise noted, all numbers except revenue mentioned during my remarks today are non-GAAP. Additionally, all earnings per share and share amounts presented today and in our accompanying investor materials have been adjusted to reflect our recent 4-for-1 stock split for all periods presented. We delivered a record second quarter, exceeding expectations across all guided metrics.
We achieved an all-time record $333 million of net new ARR, well ahead of our guidance and accelerating to 51% growth year over year. ARR reached $5.84 billion, up more than 25% over the prior year as growth accelerated for the fourth consecutive quarter. As George discussed, the post-Mythos demand environment continued to strengthen in Q2. The customer urgency we began to see in Q1 translated into increased cybersecurity investment, accelerated modernization, and stronger demand for the Falcon platform.
Our exceptional Q2 performance was broad-based across customer sizes and geographies. Net new ARR contribution from new logos was an all-time record, and both our dollar-based net and gross retention rates improved sequentially. Platform adoption also continued to deepen with 51%, 35%, and 26% of subscription customers adopting six, seven, and eight or more modules, respectively. Falcon Flex continues to be a key driver of our platform consolidation, with this quarter showcasing the power of our Flex-first strategy.
In Q2, customers converting from standard subscriptions to Flex delivered an average ending ARR uplift of more than 40% from that new baseline. Customers completing their first reflex this quarter generated an additional average ending ARR expansion of 25%. Looking at the cumulative uplift of customers who have reflexed at least twice in Q2, these customers had average ending ARR 53% higher than their initial Flex starting point, increasing for the second consecutive quarter.
Taken together, these results underscore exceptional execution and the power of our platform strategy, with AI-driven demand accelerating platform consolidation and helping deliver the strongest quarter in CrowdStrike's history. We also exited the quarter with a record Q3 pipeline, further reinforcing our confidence in the demand environment ahead. Moving to the P&L, total revenue exceeded our guidance range and grew 26% over Q2 of last year to reach $1.47 billion, with year-over-year growth accelerating sequentially for the fifth consecutive quarter.
Subscription revenue grew 27% over Q2 of last year to reach $1.40 billion, and professional services revenue was an all-time record $71 million as AI creates incremental demand for our AI readiness and incident response services, further increasing software cross-sell opportunities. The geographic mix of second-quarter revenue consisted of approximately 65% from the U.S. and 35% from international geographies. Broad-based strength across our major regions drove international year-over-year revenue growth acceleration for the fifth consecutive quarter.
Total Q2 non-GAAP gross margin was 79%, up approximately 110 basis points over the prior year. Non-GAAP subscription gross margin was 81%, up approximately 90 basis points over the prior year, driven by continued cloud optimization efforts. As we remain focused on achieving our FY29 target model of 82% to 85% non-GAAP subscription gross margin, second-quarter non-GAAP operating income was a record $372 million, exceeding our guidance, and non-GAAP operating margin was 25%, up 350 basis points over the prior year.
The outperformance was driven by strong top-line execution, continued gross margin expansion, and increased operating efficiency. Our internal investments in automation and AI continue to yield greater operational efficiencies and productivity gains across our business. The combination of accelerating revenue growth and substantial year-over-year operating margin expansion demonstrates our strong operating leverage as we invest in the significant opportunities ahead, positioning us to deliver durable profitable growth.
In Q2 we delivered $5 million of GAAP net income attributable to CrowdStrike, marking the third consecutive quarter of positive GAAP earnings. Non-GAAP net income attributable to CrowdStrike was a record $323 million, or $0.31 per diluted share, exceeding our guidance and up 34% compared to the prior year on a split-adjusted basis. Moving to cash, our cash and cash equivalents grew to $5.01 billion. We generated Q2 record cash flow from operations of $530 million and Q2 record free cash flow of $377 million, or 26% of revenue, exceeding our free cash flow margin expectation of 24.5%.
Moving to our outlook and modeling notes, consistent with our guidance philosophy, our outlook reflects the strength we see in the business while maintaining a prudent approach. Our record second-quarter performance, record Q3 pipeline, and broad-based demand across customer segments and the Falcon platform give us increased confidence in the strength of the demand environment and our long-term growth opportunity. As a result, we are once again raising our fiscal 2027 net new ARR outlook.
At the midpoint, we now expect $1.355 billion of net new ARR for the full year, an increase of approximately $116 million from our initial FY27 outlook. This equates to expected year-over-year net new ARR growth of approximately 34% compared to 22.5% in our initial FY27 outlook, representing an increase of 1,150 basis points. The magnitude of this increase reflects more than our Q2 outperformance. As AI expands the attack surface and increases the urgency around cybersecurity, we believe it is driving a broader security modernization cycle that creates durable demand across the Falcon platform.
Combined with continued platform consolidation and strong Falcon Flex momentum, these demand signals reinforce our confidence in the full-year opportunity ahead. Before I walk through our detailed guidance, let me highlight two additional items to keep in mind. First, the acquisition of XM Cyber's technology assets is expected to close in the second half of FY27 and will not bring any ARR or revenue to CrowdStrike, nor are we including any ARR or revenue from this transaction into the FY27 guidance.
And second, at the midpoint of our guidance, we expect free cash flow margin of 27.5% in Q3 and continue to expect at least 30% for the full fiscal year on our increased revenue guidance. With that, for the third quarter of FY27, we expect annual recurring revenue to be in the range of $6.184 to $6.188 billion, up 26% year over year. This translates to net new ARR of $343 to $347 million, up 29% to 31% year over year; total revenue to be in the range of $1.5 to $1.529 billion, up 23% to 24% year over year; non-GAAP income from operations to be in the range of $373 to $376 million; and non-GAAP net income attributable to CrowdStrike to be in the range of $325 to $328 million. Diluted non-GAAP net income per share attributable to CrowdStrike to be approximately $0.31, assuming a 21% tax rate and approximately 1.048 billion weighted average diluted shares. For the full fiscal year 2027, we expect annual recurring revenue to be in the range of $6.603 to $6.612 billion, up 26% year over year.
This translates to net new ARR of $1.350 to $1.359 billion, up 34% year over year. Total revenue to be in the range of $5.991 to $6.011 billion, up 25% over the prior fiscal year. Non-GAAP income from operations is expected to be between $1.497 and $1.508 billion, and non-GAAP net income attributable to CrowdStrike to be between $1.303 and $1.312 billion. Assuming a 21% tax rate and approximately 1.044 billion weighted average diluted shares, we expect non-GAAP net income per share attributable to CrowdStrike to be in the range of $1.25 to $1.26.
George and I will now take your questions.
OPERATOR
Thank you. If you would like to ask a question, please click on the raise hand button, which can be found on the bar at the bottom of the Zoom window. You may remove yourself from the queue at any time by lowering your hand. When it is your turn, you will hear your name called and receive a message on your screen notifying you that you may unmute yourself. In the interest of time, participants will be limited to one question. Our first question comes from Sakit Kalia with Barclays.
Please unmute your audio and ask your question.
Sakit Kalia, Analyst at Barclays
Can you hear me okay?
OPERATOR
Yes, go ahead.
Sakit Kalia, Analyst at Barclays
Okay, excellent. Well, hey, guys, thanks for taking my question here and great to see the acceleration continue. George, maybe for you, the Mythos moment happened in the spring, and now we've gotten a few months of activity behind us. Could you maybe talk about what transpired after that? And as you look back, what were some of the key drivers of this upside here in Q2?
George Kurtz, President and CEO
Thanks, Zach. So, as we mentioned in the spring, the Mythos moment was building, and as we told you, it was going to be a growth driver and a tailwind for us. And you saw that show up in our results. When we think about AI agents going rogue, when you think about the need for protecting AI and understanding where shadow AI is, it all points to the technologies that we're building and delivering here. Like AIDR, which just had a phenomenal quarter.
No surprise. Obviously, cloud, identity, next-gen SIEM, endpoint was accelerating, and exposure management, which is a big element now given the fact that companies can't keep up with the patching. So when you put all of that together, it comes to what we said. The Mythos moment was a point of acceleration. And we see those tailwinds continuing.
Andy Nowinski, Vice President of Investor Relations and Strategic Finance
Thanks, Saket. Operator.
OPERATOR
Next question, please. Your next question will come from Brian Essex with JP Morgan. Please unmute your audio and ask your question.
Brian Essex, Analyst at J.P. Morgan
Hi, good afternoon. Thanks for taking the question. And great to see the nice magnitude of net new ARR upside this quarter. Maybe, George, for you just to piggyback on Sakic's question there, would love to get your view on the durability of strength that you're seeing on the back of the Mythos moment, so to speak. I mean, how much of the momentum goes beyond next quarter, perhaps beyond the end of the year? And given what you have in your pipeline, how much visibility do you have into the strength?
Maybe just into next year and beyond. Thank you.
George Kurtz, President and CEO
Sure. I think when you look at the durability, it's, in my opinion, it is absolutely there. It's one of the reasons why we raised FY27 outlook again. And what we're hearing from customers is they want to deploy more AI, but they're being held back because of security, compliance, privacy, data protection type issues. So every customer that we talk to is concerned about the agentic threats. We've seen agents go wild, we've seen them break out of the Frontier labs, and this is a sustainable tailwind.
If we believe that AI is in its early days and is only going to get better and more powerful, combined with the autonomous nature of these attacks, it's absolutely something that every company is going to need. And as I said in a prior earnings call, I think the AIDR business can be bigger than the EDR business just given the pure number of agents which each person will have, which is estimated to be about 90. So for me it's sustained tailwinds and I think we're only going to see more stories around agents gone wild and we're going to be there to protect our customers.
Burt Podbere, Chief Financial Officer
Yeah, I think, Brian, the numbers back it up. Look, you start with the record Q3 pipeline. So that prompted us to raise our full year guidance by an additional 630 basis points. That means we moved our FY27 NR growth rate from 27.7 at the end of last quarter to 34% this quarter. When compared to our initial guide for the year, we raised the growth rate 1,150 basis points or $116 million in just two quarters. That talks to the durability of the things that George talked about.
Andy Nowinski, Vice President of Investor Relations and Strategic Finance
Thanks, Brian. Operator, next question please.
OPERATOR
Your next question will come from Gabriela Borges with Goldman Sachs. Please unmute your audio and ask your question.
Gabriela Borges, Analyst at Goldman Sachs
Hey, good afternoon. Thank you, George and Bert. I wanted to ask you a little bit of a product question. You gave a little bit of... you gave the case studies earlier on customer journeys and some of the flagship wins in the quarter. What I want to better understand is if you have a customer, let's say it's a large financial organization and they go from having agents being sandboxed and isolated, regardless of how effective those sandboxes can be, to actually wanting the agents to have real customer data, real enterprise data.
Walk us through the before and after. How do you advise those clients on what products they need to buy from CrowdStrike? Clearly, identity is a part of it. To be able to say agents isolated to agents in production. Thank you.
George Kurtz, President and CEO
Sure. Well, I think to make the agents productive, they're going to have to have access to data. And again, when you look at what we're delivering for customers, it's looking across the entire spectrum of threats. You have to have an identity control plane, which we have for non-human identities. You have to have data protection, which we have. You have to understand at runtime what the agents are actually doing. Whether that's in a sandbox, or if those agents are running essentially on your computer or your laptop, you have to understand the exposures that you have.
You have to be able to keep track of where those agents are calling out to. We can do all of that. So if it's in a sandbox, we can run in a sandbox. If it's out of a sandbox, which many of our customers are just kind of consuming AI on their desktops using the various frontier lab harnesses and the like. And we cover all of those, including if you're creating agents in a cloud environment. So from my perspective, first of all, you need to know where AI is being created, you need to know where it's being consumed, and you have to put the right guardrails around identity, data, execution, and network connectivity.
And we're delivering that for our customers. Thanks, Gabriela. Operator, next.
OPERATOR
Your next question will come from Matt Hedberg with RBC. Please unmute your audio and ask your question.
Matt Hedberg, Analyst at RBC Capital Markets
Hey guys, thanks for taking my questions. I'll offer my congrats as well. I wanted to piggyback on this train of thought, and George, you talked about it in your prepared remarks, but I think we’re all sitting back here and we're seeing these agents going rogue and just how quickly this landscape is changing. So from your perspective, I just wanted to double click on how you see the threat landscape today. And when we think about how quickly this is changing, the relationship with the frontier labs is obviously great.
But talk to us about why you're uniquely positioned even if these frontier labs start to release some of their own security solutions in the future.
George Kurtz, President and CEO
Sure. Well, I think it's important that when you look at AI, and to make AI protection more effective, you have to have very deep data expertise. And this has been something that's been basically built in the platform from day one. Over the last 15 years, we have some of the richest threat data, richest attack data, richest data around actually how to mitigate these threats in the industry. So when you look at the models that we've built, we've trained on those specifically, and that gives us a unique perspective.
Customers, of course, want choice. They want to work with frontier models, they want to work with our technology and our platform. Fantastic. But having the right data, having it trained in a specific fashion and labeled appropriately, I think is unique. And we have data that just isn't available outside of the CrowdStrike walls. That's very important. The other piece is, and I mentioned this some time ago, we are net data creators. We're constantly creating new data that's coming out of our endpoints.
We're constantly using that data to update our algorithms as the threat environment changes. And again, I think this is very important to our customers. They want security companies they can trust, they want data sovereignty from a technology perspective, and they want to get actual results based upon the information in their own environment. And we're delivering that today. Thanks, Matt.
OPERATOR
Next question. Your next question will come from Fatima Bulani with Citi. Please unmute your audio and ask your question.
Fatima Bulani, Analyst at Citi
Good afternoon. Thank you so much for taking my question. I wanted to double back on some of the earlier questions around portfolio pervasiveness, specifically just around the acceleration that you continue to see in Falcon Flex, both from a standard conversion and in Flex. George, I was hoping if you could help us maybe parse out more granularly where you are seeing the most incremental or outsized traction on a SKU or disciplinary basis as organizations move to production-grade AI adoption.
In other words, what parts of the portfolio have proven to be most potent in giving organizations the assurances and confidence they need that they are in a secure situation with their AI adoption?
Burt Podbere, Chief Financial Officer
Sure, I'll take that, Fatima. So first, let's just talk about Flex. It was an all-time record Flex quarter with year-over-year growth accelerating to 101% year over year, surpassing 2.29 billion. And a lot of that is coming from some of the different technologies that we've been talking about quarter after quarter. When you think about cloud, Next Gen SIEM, Next Gen Identity, ending ARR was 2.1 billion, up 39% year over year. And if you go down the list of how we've done in each one of those particular elements, they're all really impressive, right?
You think about cloud, over $905 million in ending ARR, up 29%. You've got Next Gen Identity, which is a big piece of the AI story, that's up 33% year over year. And then you've got obviously Next Gen SIEM, just a home run for us. That's coming up on almost $700 million and that's up 60% year over year. So all three of those can be an IPO by themselves. So you're seeing adoption through our Flex licensing really showcase itself in those three products.
And then George mentioned a whole bunch of other ones. We talked about exposure management having a great quarter. You talk about IDR having a fantastic quarter. So I think the point is that Flex is lending itself to be able to buy multiple of our products at the same time. And that's what's leading to bigger, longer deals for us, and it's better for the customer. At the end of the day, it's the platform sale, that's what matters. Customers are looking to consolidate.
They want more, better outcomes at a cheaper cost.
George Kurtz, President and CEO
Thanks, Fatima. Operator. Next question.
OPERATOR
Our next question will come from Meta Marshall with Morgan Stanley. Please unmute your audio and ask your question.
Meta Marshall, Analyst at Morgan Stanley
Great, thanks. I wanted to maybe follow up on some of that Next Gen SIEM strength. If we were having this conversation a year ago, there was a lot of "they can start with their customers can start moving their EDR data over and then kind of gradually over time expand those implementations." I just wanted to get a sense, as you guys are seeing continued really strong growth, is that kind of land happening differently? Are people taking more of a chance up front and moving more to you guys initially?
And then are we seeing more data or logs being put into the SIEM to get better signals as they try to detect more advanced attacks? Thanks.
George Kurtz, President and CEO
Yeah, well, when you look at Next Gen SIEM, the great news is every customer is Next Gen SIEM-enabled. The data is just in the platform, so it's just a matter of signing up and paying for the license entitlement and you're up and running with the CrowdStrike first-party data — the data that we actually generate. So that has made it incredibly easy and friction-free for many customers. They routinely say it's the easiest SIEM to get up and running.
It's the quickest return in terms of time to value of what they're putting in and the results they're getting out. And then it's very easy to connect other data sources. We've seen the other data sources rapidly expand. If we think about AI, AI agents, SaaS, cloud agents if you will, and identity — these are all areas that customers have to instrument because we see these cross-domain attacks that go from internal systems to the cloud, or cloud to internal systems and everything in between.
So we've seen just tremendous results there. It's a fantastic product and it's very disruptive from a price point because of how we charge for the first-party data that we create. So it is a story of better, faster, and more value for the money. And you can see the results — they speak for themselves. Thanks, Mia.
OPERATOR
Next question, please. Our next question will come from Adam Tindall with Raymond James. Please unmute your audio and ask your question.
Adam Tindall, Analyst at Raymond James
Okay, thanks. Good afternoon and congrats on a great quarter. George, I wanted to ask on AIDR versus the core EDR platform — kind of a two-parter. I ask because investors are struggling with the definition and a view that there might be more gray area between AIDR and your core platform. So the first part of the question would be, is there a simple way to think about AIDR? Where is this incremental, where customers are buying this in addition to EDR, or is this being used more as a substitute for EDR or any other products?
And the second part would be, you've alluded to some metrics around this that have been helpful, but I wonder if you might just take a second to put in context the ramp of AIDR versus other products at this stage as we try to think about the potential ultimate size of that platform. Thank you.
George Kurtz, President and CEO
Yeah, so on the first point, it is separate and incremental. It's another module and it's priced separately, which is again where we're seeing a lot of the growth. So that is certainly a good fact to make sure that we clear up if there was any confusion about it. When we think about the beauty of the architecture and the platform, it's still using the same agent. And if you want to enable AIDR, again, that's a license entitlement. It's part of our friction-free deployment.
Again, why is Falcon Flex so successful? Why have we been successful? Media time to value. You don't have to roll out yet another agent. So that's very important. And when we talk about the ramp of this, it's been incredible over the last couple of quarters, and we've seen the results sort of parallel some of the frontier labs' growth as they continue to add more agents and capabilities. You have customers that are deploying more AI. They actually want to deploy AI faster and they need to scale incredibly fast.
So when you combine what we're building with — again, it's on the same platform, that's the beauty — but we're able to monetize it separately. We think that's a home run and we're showing the value to customers, and they're willing to pay for it because it's very unique in the environment and they don't want to deploy yet another agent. They're getting it all with CrowdStrike, and that's what they're looking for. All right, thanks, Adam. Operator, next question.
OPERATOR
Our next question will come from Roger Boyd with UBS. Please unmute your audio and ask your question.
Roger Boyd, Analyst at UBS
Thanks for the question for George or maybe for Bert, given the traction you're seeing around AI security and you noted the acceleration in AIDR overall AI usage across your install base and inflecting. I appreciate your updated views on how you're evolving the pricing model and namely are customers asking for token-based pricing in cybersecurity and if so, how is that being incorporated into Flex contracts? Thanks.
George Kurtz, President and CEO
Yeah, so we actually have token-based pricing as part of AIDR. So we already have that today. And what's important from a customer perspective is they do want some certainty on what they're paying. So we provide a certain number of tokens across an environment and obviously we scale that to how big the customer is and then if they exceed that token usage, they can buy extra token packs. And again, the beauty is it's all consumable via the Falcon Flex licensing.
So it's a model I think has served us well where it's not runaway cost for customers. They can define it, they can budget for it, but certainly as they scale up their AI, if they exceed their budget allowance, they certainly can up-level the tokens and it's friction free to do that with Falcon Flex. Okay, thanks for the question. Operator, next question please.
OPERATOR
Our next question comes from Rob Owens with Piper Sandler. Please unmute your audio and ask your question.
Rob Owens, Analyst at Piper Sandler
Great, thank you and good afternoon. George, I guess back to the start and thinking about your history with Foundstone a little bit and twice on this call you did mention exposure management. So love to understand the evolution of that market, where you're seeing displacement because I think you mentioned a large-scale transaction there and effectively what the older solutions aren't providing at this point. I know that you guys adopted a network scanning capability a year ago, but with AI I'd assume it's well beyond that at this point.
So just would love for you to drill down on that opportunity and why CrowdStrike is winning. Thanks.
George Kurtz, President and CEO
Sure. So when we think about where we are with exposure management, I think it's a rebirth and certainly we're in pole position in that area. So what I mean by that is given the fact that there's an exponential increase in vulnerabilities that are found via frontier AI and patches that can be created via frontier AI, that's great. The problem is you've hit the sound barrier of actually rolling out a patch. And what that means is that companies are looking for their ability to prioritize where these exposures are because they're not going to be able to fix everything all at once within the window of what autonomous agents can actually exploit.
So that's really the driver in an area where customers are looking at and saying, hey, I've got to think about this differently. I can't be doing the same old things that we've been doing. I can't keep using the same old legacy exposure management or vulnerability management technology. So they want a view of their assets, they want a view of where their protection is—Falcon. They want a view of what's exposed—what patches need to be applied but haven't. And they want to understand the attack paths. And we are delivering that in an autonomous fashion within the Falcon platform. And that's a big reason why we're displacing a lot of legacy vendors in the market today. Okay, thanks, Rob. Operator, next question.
OPERATOR
Our next question comes from Mike Cikos with Needham. Please unmute your audio and ask your question.
Mike Cikos, Analyst at Needham
Thank you for taking the questions and congratulations on another significant lift here to the net new ARR guide following the strong 2Q execution. George, maybe for you. We've been doing a significant amount of work with CISOs and the common refrain we're hearing comes back to AI governance both in terms of security as well as the pull-through on the economic need to control these AI costs. My question really ties to: Can you just put a finer point on discussing how customers are turning to CrowdStrike in terms of serving as that strategic partner for implementing and enforcing AI governance guardrails?
I think that'd be super helpful. Thank you.
George Kurtz, President and CEO
Sure. Well, in the product today, we have the ability to set policy and enforce those guardrails, which is incredibly useful, needed and incredibly difficult as you might imagine in some organizations that are dealing with, you know, they make chemicals as an example. Well, that may be something that is not an approved sort of topic, if you will, in other companies. But in some companies that's what they make, right. So you have to be able to have the right models to understand what's happening in the environment, you have to be able to set the policies in a way that actually work and minimize false positives.
And then you have to give these customers very good results very quickly so they can roll this thing out without a lot of friction. And we're doing that today. The other piece, and you touched on it, which is very important, is we actually have the ability to count tokens and track cost. And this is very important as you expand outside of the boundaries of just pure security. When we think about IT infrastructure and we think about the CIO, having the ability to help them manage cost is a big part of our selling point as well.
So you get the guardrails that you're looking for, get the protection you need, and also you have visibility into where your AI agents are and what people are actually spending on these results. And it's incredible. I mean, we've heard, you know, EA spending $10,000 just on tokens because of the way they were using the models. And once you have visibility around that you can dramatically cut those costs down. So it's really a one-two punch of protection and cost management.
Thanks, Mike. Operator, next question.
OPERATOR
Our next question comes from Patrick Colville with Scotiabank. Please unmute your audio and ask your question.
Patrick Colville, Analyst at Scotiabank
Thank you for having me on. I guess this one for both George and Bert, please. You talked about the frontier lab eight-figure deal with this customer protecting their rapidly expanding data center infrastructure. I mean, any more details you can share on this specific eight-figure deal? And then to zoom out the aperture a little bit, could you just talk to this emerging customer category of helping to protect the frontier labs. Thank you.
George Kurtz, President and CEO
Sure. I think you've got the digital natives that are out there, AI-native companies, you've got the frontier labs. As you might imagine, all the companies that are involved in creating AI need to protect AI and they're turning to CrowdStrike because we've got the right technologies across the entire stack. And again, if you look at what we've done with NVIDIA and how we have integrated into their platforms, it's a complete ecosystem from the chips all the way up to the applications and AI inference.
So we think we're in a great position to be able to help these rapidly growing and expanding companies because they're going to need visibility, they're going to need protection, they're going to need control, they're going to need compliance as they continue to scale. And we think the sky's the limit with the frontier model creators and anyone involved in the AI ecosystem. And we're there for them and we think we have a very unique and differentiated technology in those areas.
All right, thanks, Patrick. Operator, next question.
OPERATOR
Our next question comes from Joseph Gallo with Jefferies. Please unmute your audio and ask your question.
Joseph Gallo, Analyst at Jefferies
Hey guys, thanks for the question. There's a lot of excitement and big numbers with the emerging products on the call, but I just wanted to focus on endpoint, which accelerated for the fourth straight quarter. Can you just unpack that a little bit more? Is that new logos, is that selling more managed services and premium SKUs, and just how much runway is left there just given it's perceived as a more mature market?
George Kurtz, President and CEO
Sure. Well, I think when you look at companies' desire to protect AI, again, a lot of the AI is being consumed on the endpoint, right. It might be created in the cloud, but it's being consumed on the endpoint. You can think about your own organizations and perhaps how you even use AI. So that has driven the need for companies like CrowdStrike to be able to actually protect those instances. If we think about the market, about half the market is still using legacy AV, right.
So legacy AV and legacy providers are not really going to have the capabilities to identify rogue AI agents, shadow AI and be able to protect against it. It's very unique and differentiated, but it fits within the platform that we built from the beginning. So that's one area where, again, if you want to protect these endpoints, you're going to have to have something like CrowdStrike, and that includes net new wins from a lot of the legacy providers that are out there, certainly in addition to cross-selling into our customer base.
Thanks, Joe. Operator, next question please.
OPERATOR
Our next question comes from Todd Weller with Stephens. Please unmute your audio and ask your question.
Todd Weller, Analyst at Stephens
Yeah, good afternoon. Congrats and thanks for taking the question. George, question on QuiltWorks. Can you talk about how impactful it was in the quarter and then trying to better understand the monetization angles there? Should we initially think about that as like a partner-led motion where they're leveraging your platform and frontier AI model capabilities to do assessments and then that drives kind of follow-on platform pull-through.
George Kurtz, President and CEO
Thank you. Yeah, that's exactly right. When we think about the Mythos moment, there's many of our partners, and again we're a very partner-first organization, that want to be able to service their customers. They've got great relationships, but we need to be able to arm them with frontier-caliber capabilities to be able to understand where these vulnerabilities are, what threats are out there and what they can do. So essentially they're leveraging our platform in a partner-led motion and finding these vulnerabilities, understanding exposure and then obviously working on remediation with some of the largest enterprises in the world.
And of course, that leads to platform pull-through. So I think from our perspective, it's been a home run in QuiltWorks. We have many companies that want to still yet get into it. We're working through all of those and we'll continue to expand the partners as well as its capabilities within the platform for them to leverage.
OPERATOR
Thank you. This concludes today's question and answer session. I would now like to turn the call back over to George Kurtz for closing remarks.
George Kurtz, President and CEO
Thank you for your time today. We appreciate your continued support and look forward to seeing you at Fal.Con 2026 and other upcoming events. Thank you.
Disclaimer: This transcript is provided for informational purposes only. While we strive for accuracy, there may be errors or omissions in this automated transcription. For official company statements and financial information, please refer to the company's SEC filings and official press releases. Corporate participants' and analysts' statements reflect their views as of the date of this call and are subject to change without notice.
Login to comment