Netskope (NASDAQ:NTSK) held its second-quarter earnings conference call on Wednesday. Below is the complete transcript from the call.
Benzinga APIs provide real-time access to earnings call transcripts and financial data. Visit https://www.benzinga.com/apis/ to learn more.
Access the full call at https://edge.media-server.com/mmc/p/x6yzcqmo/
Summary
Netskope reported strong Q2 fiscal 2027 results with ARR reaching $899 million, up 27% year-over-year, and revenue growing 29% to $221 million, surpassing guidance.
The company highlighted strategic initiatives around AI security, launching several new products such as the Agentic Broker, AI Guardrails, and AI Gateway, and reported significant customer engagement and pipeline growth.
Future guidance for Q3 fiscal 2027 includes revenue between $227 million to $229 million, with a continued focus on ramping sales reps and capitalizing on AI security opportunities.
Netskope emphasized its competitive advantage through its Netskope One platform and NewEdge private cloud network, positioning itself as a leader in AI security and SASE markets.
Management noted significant progress in strategic partnerships, including collaborations with Nvidia, CrowdStrike, and Amazon, as well as the launch of the Catalyst Managed Service Provider Program.
Full Transcript
OPERATOR
Thank you for standing by and welcome to Netskope's second quarter fiscal 2027 earnings conference call. At this time, all participants are in a listen-only mode. After the speakers' remarks, there will be a question-and-answer session. I would now like to hand the conference over to Michelle Spover, Chief Communications and Investor Relations Officer. Please go ahead.
Michelle Spover, Chief Communications and Investor Relations Officer
Good afternoon and thank you for joining us today. With me on the call are Netskope CEO and Co-Founder Sanjay Beri and CFO Drew Del Matto. The press release announcing our financial results for the second quarter of fiscal 2027 was issued earlier today and is posted to our investor relations at investors.netskope.com along with a supplemental presentation. Before we begin, let me remind everyone that certain statements we make on today's call are forward-looking, including statements related to our guidance for the third quarter and full 2027 fiscal year, market opportunity, growth prospects, sales ramping, competitive position, impact of AI, and demand for AI security. These forward-looking statements are subject to known and unknown risks and uncertainties which could cause actual results to differ materially from those anticipated by these statements. Additionally, these statements apply only as of today and we undertake no obligation to update them in the future. For a detailed description of risks and uncertainties, please refer to our SEC filings as well as our earnings press release.
Finally, unless otherwise noted, all financial metrics we discuss on this call other than revenue will be on an adjusted non-GAAP basis. We have provided reconciliations of these non-GAAP financial measures against the most directly comparable GAAP financial measures in our earnings press release. Now let me turn the call over to Sanjay to discuss our business momentum and highlights from our Q2 financial performance.
Sanjay Beri, Chief Executive Officer & Founder
We had a strong second quarter with our results reflecting durable demand for Netskope's highly differentiated platform. In the age of AI, security and network modernization have become inseparable, and businesses can no longer afford to trade security for performance. As enterprises embrace AI and cloud, they need a modern architecture that understands the context and intent of today's internet, cloud, and AI environments. This architecture must protect massive amounts of transactions and data spanning thousands of cloud and private applications and data stores, billions of websites and other destinations, and a vast set of commercial and open-weight AI apps and models. It must inspect and control traffic in real time at high speed and with data sovereignty. The need for this architecture is becoming even more acute as the volume and velocity of transactions and data, and the number of humans and AI agents originating these transactions and operating on data, grows exponentially. Netskope uniquely delivers this modern, scalable, resilient, and sovereign real-time architecture through the combination of our Netskope One platform and NewEdge private cloud network.
This is why customers are choosing us as the trusted partner to help them say yes to AI. They want to capture the enormous potential of one of the most defining technologies of our lifetime without compromising security, performance, or control. This positions us exceptionally well to address a massive $170 billion greenfield opportunity in AI security within our $336 billion total addressable market. I'll come back to that in a moment. First, a few highlights from the quarter.
We ended Q2 with ARR of $899 million, up 27% year over year, and delivered net new ARR of $54 million. Revenue grew 29% year over year to $221 million, ahead of our guidance, and our net retention rate, or NRR, increased to 114%. Our outperformance flowed through to the bottom line with our operating margin improving 11 percentage points year over year to negative 9%, significantly ahead of our guided range. Demand for our Netskope One platform of 25 security, networking, analytics, and AI products remains strong as enterprises continue to modernize their infrastructure for the AI era.
We were particularly encouraged by the traction from our recently announced AI security suite. While it's still early, we're seeing strong customer engagement and rapid pipeline generation for these products, with some deals closed and many more currently in the proof of concept, or POC, stage. Enterprises globally remain strategically focused on modernizing their security and infrastructure, reducing technology sprawl, protecting sensitive transactions and data, ensuring data sovereignty, and, of course, safely using AI.
A hot topic in my daily dialogues with CXOs is the fact AI creates exponentially more transactions and data and a much more complex attack surface—and how modernization and AI adoption go hand in hand. The Mythos moment this past spring underscored just how quickly the landscape is changing. The pace of innovation across frontier models and increasingly capable open-weight models is accelerating the ability to discover vulnerabilities and strengthen defenses at AI speed.
But that same acceleration works both ways. These models are also lowering the barrier for attackers, compressing the time from discovery to exploitation, and expanding the attack surface not only through human adversaries, but increasingly through autonomous AI agents operating at machine speed. We are already seeing this play out with AI agents escaping isolated environments, exploiting vulnerabilities, escalating privileges, moving laterally, and stealing credentials—even when they were not explicitly instructed to attack.
They were simply asked to complete a cybersecurity benchmark, and when the intended route proved difficult, found another path to the answer. This is perhaps the clearest example yet of cyber risk extending beyond human attackers. Leveraging AI, malicious intent is no longer the security threshold. An agent does not need to be prompted to be a bad actor. Instead, a stated task, enough autonomy, and an environment that can be circumvented can be enough to do damage.
All this reinforces that rogue agent risk is not an isolated incident or a mishap. It is a real and emerging control risk that CISOs face today and considerably broadens the security problem. And this is why AI security is becoming such a critical priority for enterprises. The challenge is no longer simply how to secure AI models or prevent employees from using AI. It's how to give enterprises the visibility, control, protection, and performance they need as AI becomes deeply embedded across their people, applications, data, and increasingly autonomous agents.
I've had more than 100 conversations with customers this quarter, and in almost every one of them a CISO or CIO comes back to the same question: How do we move faster with AI without losing control of IT security? IT and infrastructure leaders don't want to say no to using AI. They want to say yes to it, but do so safely. Let me share a few challenges they're facing and how Netskope is helping solve them. First, let's start with visibility. The majority of customers I talk to about AI security do not know what or how AI models and applications are being used, what corporate data is being fed into them, where agents are in their organization, what they have access to, and what they are doing. Netskope's platform solves this problem by allowing companies to answer the question of "What AI am I using?", including providing full visibility into agentic and MCP traffic via our AgentIQ Broker. It bridges the gap between human or agent and LLM interactions or machine-to-machine workflows. Agentic Broker has been a natural starting point for customers securing AI and a game changer as they tackle unsanctioned and unmonitored AI usage in their organizations.
In addition, our recently released AI Command Center provides customers with a unified, real-time, continuous, and correlated view of where their AI risk is and makes policy and remediation recommendations that help them act on it. The second issue customers are grappling with is how to put the right defense layer around AI to prevent AI-specific threats like prompt injection and jailbreaking, and to ensure models adhere to company policy, preventing misuse or unwanted responses.
Imagine a scenario where an adversary attempts to override system rules through a multi-turn attack in order to exfiltrate data. Our AI Guardrail solution is designed precisely to help customers address this. In addition, our AI Gateway secures API traffic between private applications, autonomous agents, and LLMs, and can be deployed on premises or in the cloud. Third, customers need a highly performant network that can handle the exceptional volume of AI transactions and data and the growing amount of highly interactive, latency-sensitive agentic communications, while ensuring they're adhering to strict regulations, including data sovereignty.
Our NewEdge private cloud spans more than 120 data centers around the globe, and we operate all our products in our unified platform at each location, creating distinct performance and sovereignty advantages. NewEdge also allows customers to define geo-based policies to control exactly where their AI security and networking processing occurs, giving them sovereignty over their transactions and data wherever it lives or flows. Customers are seeing that today's AI environment has become a watershed moment for security.
AI security–related pipeline is growing at a rapid pace, and deals are moving into proof-of-concept phases. In fact, we estimate that approximately a third of our AI security pipeline is already in or entering the important POC phase. In general, enterprises are following their structured budgeting, validation, executive approval, and procurement lifecycle, which typically take 6 to 12 months. Let me share a few early AI security wins closed during the second quarter and the use cases we solve for customers.
First, a global electronics manufacturer in EMEA needed visibility into agentic, or MCP, traffic; a way to understand the associated risk; enable governance; and apply a control point to enforce policy. In Q2 they expanded their existing Netskope deployment with a broad AI security upsell including AI Guardrails, our DLP, AI SecOps Agent, Agentic Broker, and AI Gateway. They're putting the controls in place to safely embrace agentic AI rather than having to slow it down or shut it off.
In another example, a large auto insurer had a mandate from leadership to drive AI adoption company-wide, but they recognized that they couldn't move at that pace without the right security and governance foundation. In Q2 they expanded their Netskope One platform with AI Guardrails, AI Gateway, Agentic Broker with DLP, and Red Teaming, giving them the visibility, controls, and guardrails to move forward with AI confidently. These wins showcase how we are enabling customers to say yes to AI today, letting them safely use, not block, AI and move faster with it—but with the confidence that their transactions and data are protected, their AI usage is governed, and their agents are operating within appropriate boundaries. Netskope delivers that AI runtime security with the guardrails and high-performance network customers need to adopt AI broadly without compromising security or user experience. As security leaders navigate an increasingly complex AI landscape—from open-weight models to closed frontier models, from copilots to autonomous agents, and from traditional AI applications to MCP-based interactions—they need a platform that can see, understand, and govern all of it.
That is what Netskope One was built to do from inception. Our AI-native platform was built to give customers granular visibility and real-time context and control of all their transactions, users, agents, tool calls, data, and more. This includes dynamically and intelligently understanding the nature, intent, and risk of those transactions, combined with a high-performance private cloud network that delivers both security and performance and enables real-time policy and security enforcement.
That foundation is now becoming even more important in the AI era. We're excited to see this important validation of our product–market fit and strategy resonating with our existing customers, as well as a strong AI pipeline of opportunity with new customers. In addition to our early success in AI security, our platform selling motion continues to drive momentum across our SSE and SASE business, with customers increasingly adopting more products across our Netskope One portfolio.
The number of customers spending more than $100,000 in ARR during Q2 grew 23% year over year, and 59% of our customers are now using four or more Netskope One products, up from 51% a year ago. During the second quarter, we had great new logo and expansion wins across geographies and key verticals like financial services, manufacturing, healthcare, telecom, and government. Let me share a few that illustrate the key problems we solve for customers across key use cases.
First, customers continue to select our Netskope One platform to modernize for the cloud and AI. As I mentioned previously, modernization is an important precursor to AI-safe adoption. As such, customers are adopting our SSE and SASE offerings as the infrastructure and foundation to then build on and adopt our AI security offerings. We saw this in a great new logo win with a U.S. financial services company in which cloud modernization and AI enablement are key initiatives driving their future growth and scale.
Our platform differentiation across network and security helped us win a competitive deal in which they purchased eight products across our SASE suite. In addition, they also landed with our AI Guardrails and Agentic Broker AI security products. Similarly, we landed another cloud modernization AI deal with a leading technology company who needed to improve SaaS and cloud visibility and data protection, protect and govern AI usage including shadow AI, and monitor and control MCP traffic.
Again, our single unified platform and highly performant NewEdge network were the differentiating factors against competitors in this deal. We also continue to see customers replace legacy infrastructure with our modern SASE architecture built for scale. For example, a Fortune 500 healthcare provider selected Netskope to modernize security, replace fragmented legacy systems, and consolidate vendor sprawl with a unified platform for a global distributed workforce.
Doing so required protecting highly sensitive IP and other data for regulatory compliance and safely enabling and governing increased GenAI usage. Our highly granular contextual controls, unified data protection, and NewEdge high performance were key drivers in winning the seven-figure multi-product deal from an incumbent competitor. And finally, data sovereignty is increasingly important for customers in highly regulated industries and governments.
For example, we expanded with a European government agency that chose us for our data sovereignty capabilities and bought our Digital Experience Management to pair with our in-country NewEdge network for optimized user experience. Another example is a new win with a financial services company where data sovereignty is key to regulatory compliance. In addition to achieving this with our NewEdge data planes, which run all of our products at the sovereign edge, they also consolidated and modernized their legacy network security tools with Netskope's unified SSE platform.
As these wins demonstrate, customers are gravitating to Netskope to modernize their network, become a core security platform for the cloud and AI era, and eliminate the trade-off between security and network performance. Shifting gears a bit, we've long believed in openness, industry collaboration, and integration across our ecosystem. Earlier this year we joined Anthropic's Project Glasswing and OpenAI's Daybake programs and released integrations with these and other cloud and AI partners.
These partnerships demonstrate the important role Netskope plays within the broader AI and security landscape. In Q2, we continued to expand and deepen these collaborations. In addition to announcing important new partnerships, we were pleased to join Nvidia's Open Secure AI Alliance, a coalition of industry leaders committed to building open frontier AI tools that defenders can inspect, adapt, and trust. The world needs both open and closed frontier models orchestrated proactively and with care across the entire AI ecosystem to truly bring positive, impactful outcomes to the world.
Nvidia has been a terrific partner to build alongside, and this initiative accelerates our commitment to building open AI tools, ensuring our enterprise customers can trust, adapt, and securely deploy advanced AI across their environments. We were also pleased to join CrowdStrike's Project Quiltworks, integrating real-time data from Netskope into Falcon's next-gen SIEM, giving critical insight across users, applications, and data, and helping defenders correlate risk automatically and prioritize action faster.
We also continued to broaden our collaboration with Anthropic, integrating our industry-recognized DLP and threat scanning with Claude Enterprise. In addition, we announced an integration with Amazon Bedrock Agent Core, bringing Netskope AI Guardrails into agentic workflows for AWS customers. This lets organizations move AI agents into production with the confidence that what an AI agent is allowed to do and what it actually does are, in fact, the same thing.
And finally, on the go-to-market partnership front, we launched the Netskope Catalyst Managed Service Provider Program to streamline the delivery of managed services based on Netskope solutions. As we've mentioned in the past, we value our partnerships with MSPs around the globe and view them as an important vehicle and lever for growth within the mid-market. Last quarter I talked about how Netskope is transforming how we operate and how AI is accelerating our product velocity.
In Q2 we kept up our relentless pace of innovation. Let me share some of these innovations. Last month we introduced Netskope One Dataset Command Center, a unified control plane that discovers, understands, and protects sensitive data everywhere it lives—in the cloud, on the network, on premises, on endpoints, in email, and inside AI applications. It goes right at a problem I hear from CISOs everywhere: they still lack a central overview of their sensitive data.
That fragmentation represents a large, underserved market opportunity for a platform that can unify it. Dataset Command Center is built to do that by correlating signals from DLP, DSPM, CASB, SWG, and more, so teams can go from finding a risk to fixing it in a few clicks instead of a multi-day investigation across disconnected tools. Dataset Command Center sits alongside the DLP AI SecOps Agent we introduced in AgentScope last quarter. As customers scale their use of AI, they're increasingly focused on optimizing the cost and performance of each workload.
This is creating a growing need for network optimization purpose-built for AI. In July, we announced the real-world results of our AI Fast Path technology. AI Fast Path optimizes the network path between users, sites, and agents to AI destinations for faster inference results and minimizes time to first token to accelerate agentic AI workflows. In real-world testing on our NewEdge network, AI Fast Path reduced latency by as much as 90%. NewEdge analyzes tens of millions of routes per day, evaluating latency, jitter, and packet loss, amongst other factors, and ultimately makes tens of thousands of route changes to identify the fastest, most reliable path for AI traffic. Beyond AI, we're continuing to innovate across our Netskope One platform, including delivering enhancements to our enterprise browser and Zero Trust access solutions during Q2. And finally, we enhanced our platform to address advances in quantum computing that are shrinking the timeline for Q-Day—when some of the existing cryptography algorithms that are central to secure communications on the internet will be compromised. Sophisticated threat actors are pursuing the harvest-now, decrypt-later technique to store away encrypted packets now to decrypt them later when powerful quantum computers are available.
These trends have resulted in government mandates throughout the world on hard timelines for implementing post-quantum cryptography algorithms. In order to address this, Netskope engineered and natively integrated NIST-approved post-quantum cryptography algorithms in its SASE platform across our more than 120 data centers globally in Q2, bringing quantum-resilient encryption to the globe. This helps our customers transition to a quantum-safe environment and meet regulatory mandates for their sensitive communications to SaaS and AI services worldwide.
We strongly believe that we have, and are continuing to build upon, the right platform for the right moment. In Q2, we are proud to receive important third-party validation of our leadership in key markets. Netskope was again named a Leader in the prestigious Gartner Magic Quadrant for both SSE and SASE for the fifth year and third year in a row, respectively. Correspondingly, in Gartner's companion Critical Capabilities Report for SSE, Netskope ranked amongst the two highest scoring vendors for all four category use cases, including Essential SSE, Advanced SSE, Private Application Access, and Secure SaaS and AI Enablement.
And in the corresponding Critical Capabilities Report for SASE, Netskope was the only vendor ranked as the highest scoring for three key use cases, including Foundational SASE Platform, Zero Trust SASE Platform, and Sovereign SASE. Additionally, in IDC's Worldwide SASE MarketScape report published last month, Netskope was recognized for SASE leadership, pointing to our single policy engine, common data model, and NewEdge's distributed enforcement as significant differentiators.
This also points to something crucial to understand: while AI is dominating the conversation, modern cloud and network security is the foundation for corporate AI adoption that is safe without compromising on performance. In fact, with growing agentic infrastructure, customers are increasingly recognizing that speed is a distinct competitive advantage and that Netskope offers the optimal path for inference. I shared in the past Netskope's AI-native philosophy—not only in how we build our market-leading platform, but how we operate our business.
Today, AI is accelerating how we work across the company, helping us innovate and expand our Netskope One platform faster than ever before while also accelerating sales rep and SE training, streamlining customer support, recruiting and developing talent, and automating other processes. Our teams have leaned into this new era, enabling us to move faster, operate more efficiently, and scale with greater leverage. In closing, Netskope sits at the intersection of cloud, AI, networking, and security, positioning us to address a massive market opportunity that we are still in the early stages of capturing.
We are scaling our go-to-market engine well to capitalize on that opportunity while continuing to innovate rapidly and deepen our strategic position with customers and partners. Our goal is to be the essential adaptive fabric for the modern AI enterprise, and we believe our differentiated architecture, technology, leadership, and growing customer footprint create a durable structural moat that will compound over time. I am pleased with our second quarter outperformance across every key metric and proud of our team of Netskopers for continuously embodying the guts, resolve, integrity, and tenacity that define our culture and what we stand for.
As well, I am grateful to the thousands of customers who trust Netskope to help steer them through two of the greatest technological revolutions in our lifetime—cloud and AI. With that, let me now turn the call over to Drew.
Drew Del Matto, Chief Financial Officer
Thank you, Sanjay. And as you just heard, demand for our business is strong, our platform selling motion continues to gain momentum, and we are innovating rapidly. Before I share more about our Q2 results, let me remind you that all financial comparisons are on both a year-over-year and non-GAAP basis unless stated otherwise. Moving to our Q2 results, ARR grew 27% to $899 million. Net new ARR of $54 million grew 9%. Revenue grew 29% to $220.5 million, ahead of our guided range.
Demand continues to be durable across all of our regions. Revenue in EMEA grew 37%, APJ grew 31%, and the Americas grew 25%. We're also seeing the strength of our results reflected in our customer expansion and retention rates. NRR rose to 114%, and our gross retention rate, or GRR, hit another all-time high, ticking up again in Q2. Remaining performance obligations, or RPO, grew 36% year over year to $1.35 billion. Moving on to our customer metrics, as Sanjay noted, the number of customers generating more than $100,000 in ARR grew 23% year over year in Q2 to 1,686.
These customers compose 87% of our total ARR, and adoption of our Netskope One platform continues to increase. At the end of Q2, 59% of our customers were using four or more products versus 51% a year ago, and 41% were using five or more products, up from 35% a year ago. Our platform expansion continues to gain steam as we add more products to our Netskope One platform of over 25 products. This continuing innovation expands our market opportunity to $336 billion and extends our runway for growth.
Turning to the rest of the income statement, our investments remain disciplined. We are demonstrating the operating leverage that comes from our platform and infrastructure being built to scale. Gross margin was 77%, increasing approximately 2 percentage points year over year. This increase is driven by the scale benefits of our new edge architecture as we continue to progress towards our long-term target of 80% gross margin. Q2 operating margin was negative 9%, an impressive 11 percentage point improvement compared to Q2 of last year and significantly ahead of our guidance.
This improvement was driven by operating leverage across the P&L as revenue grows. The biggest contributor was R&D, which improved approximately 8 points as a percent of revenue compared to last year. Netskope One's common platform architecture delivers the rapid product velocity Sanjay mentioned earlier. While we scale efficiently, our AI investments are accelerating that velocity. Sales and marketing expenses were roughly flat year over year as a percent of revenue as we continue to ramp our existing sales force and invest in quota-carrying sales reps to address the massive market opportunity ahead of us.
G&A expenses also improved approximately 1 point as a percent of revenue compared to Q2 of last year, reflecting leverage across our infrastructure. Net loss per share was $0.03 using 405 million weighted average shares, exceeding our guidance. Fully diluted share count using the treasury stock method was approximately 511 million shares as of July 31, 2026. Negative free cash flow of $29.8 million was slightly ahead of our expectations. This benefit was driven by our outperformance on both the top and bottom line.
Note that contracted future billings grew 75%, reflecting our transition to annual billings. As Sanjay noted, we are already seeing the impressive results that AI is delivering. This transformation includes shifting some of our investments to areas where we see the greatest opportunity and demand. As such, we reallocated spend towards our AI infrastructure and tokens in R&D and G&A. We made the hard decision to reduce around 5% of our workforce as we continue to drive AI nativeness company-wide.
Finally, we maintain a strong balance sheet and ended the second quarter with $1.1 billion in cash, cash equivalents, and marketable securities. Here are a few modeling points and assumptions underlying our Q3 and fiscal year 2027 outlook. First, on ARR, we continue to expect net new ARR to grow year over year in the second half of our fiscal year. This follows our typical second-half quarterly cadence with a seasonally stronger fourth quarter. On billings, a reminder that we are transitioning customers to annual billings, which is proceeding faster than expected.
We expect to be through the transition by the middle of next fiscal year. This shift temporarily defers cash collections but gives us strong forward visibility into cash flows and customer commitments. On cash flow, we expect between $10 and $20 million of free cash flow in Q3. For the full year, we now expect capital expenditures of approximately 4% to 5% of revenue related to the continued infrastructure investments in our new edge network. We've noted these modeling points in the appendix of our investor presentation.
I'll now share our guidance, which reflects the strong underlying demand, early traction with our AI security products, and continued progress in sales reps ramping. As a reminder, these numbers are all non-GAAP unless stated otherwise. For Q3 fiscal 2027, we expect revenue in the range of $227 million to $229 million, representing growth of approximately 24%, operating margin of approximately negative 8%, and net loss per share of $0.03 to $0.04, using approximately 415 million weighted average common shares outstanding.
For the full fiscal year, we are raising our guidance. We now expect revenue in the range of $888 million to 808, $92 million, representing growth of approximately 26%. We are pleased to raise our full-year revenue guidance by more than our Q2 revenue beat. This reflects our momentum and confidence in the durability of demand. Gross margin of approximately 77%, operating margin of approximately negative 9%, net loss per share of $0.15 using approximately 415 million weighted average common shares outstanding, and positive free cash flow margin of approximately.
In summary, demand for Netskope solutions is strong, our platform momentum continues to grow, and our rapid pace of innovation places us center stage for the age of AI. With that, operator, let's open the line for questions.
OPERATOR
Thank you, ladies and gentlemen. To ask a question, please press star 1 1 on your telephone, then wait for your name to be announced. To withdraw your question, please press star 1 1 again. Please stand by while we compile the Q&A roster. Our first question comes from the line of Matt Hedberg with RBC Capital Markets. Your line is open.
Simran, Analyst at RBC Capital Markets (on behalf of Matt Hedberg)
Hey guys, this is Simran on for Matt Hedberg. Thanks for taking my question, and congrats on the quarter. First for me, as we think about ARR and the DSAL from last quarter, could you talk a little bit more about the important building blocks that could point to ARR acceleration from here?
Sanjay Beri, Chief Executive Officer & Founder
Great, thanks for the question. First of all, we're obviously very happy with our Q2 performance and the growth in our pipeline across AI security and beyond. One of the key things for us, as we mentioned, is we see that AI security pipeline, and some of that closed in Q2, but we really see a lot of that in the back half, especially towards Q4, and with our reps ramping. Obviously that's a key for us for growth. 50% roughly of our reps are ramping.
And one of the key areas for us is not only the product innovation, but continuing to grow that rep ramping count. And that'll happen in the back half of the year, first in EMEA and APJ where we really started growing our fully ramped reps first, and then later in North America.
Simran, Analyst at RBC Capital Markets (on behalf of Matt Hedberg)
Great, that's helpful. And then double-clicking on the AI piece. Is there a way to quantify a bit more and help us size this contribution and then just more generally why you were well positioned for the AI era?
Sanjay Beri, Chief Executive Officer & Founder
Yeah, it's a great question. Sure. I can't get in a conversation with our customers or prospects. I was running an AI Fast Lane event. It's events we run across cities across the world. I was in New York, had a large global media CIO on stage with me and beyond. And we're having those events everywhere. And why we're well positioned is really, one, when you look at our platform—and it really is a broad platform—for over a third now, the Fortune 100, we are their inline processing point.
They send their traffic to us. We have a public site, AI-index.netskope.com, where you can actually see what AI traffic is going through enterprises today. We're processing trillions of AI connections. And so why we're in a great footprint is a lot of this traffic we already see. It already goes through New Edge, which is the fastest path for inference for AI transactions. And so now these new products that we released—right, Agentic Broker earlier in the year, Guardrails, our AI Command Center last quarter—they really shine a light on that traffic to say, wait, what is that traffic?
Is it from agents, is it from users, is it prompts, responses, what kind of data? We give them the visibility that they want, with, frankly, not a lot of deployment. It's very easy to get the visibility, and then we allow them to enforce real-time policy. Really for us, it's a combination of the things that we always highlight: the fact that we run one of the world's largest private cloud networks; we've released AI Fast Path; you combine that with our ability to be very granular in understanding the language of the Internet for cloud and AI and our data protection; and you have a perfect, almost traffic point to govern AI. So that's one. The second question related to that, which you asked, was around AI growth pipeline and so on. So we started releasing a lot of our AI security products in Q1. We released some more in Q2, and we actually already announced one related to it, our Dataset Command Center, in Q3 this quarter. And so really for us, those are getting into POC. I think we announced close to one third of them are in proof of concept now.
Enterprises follow their normal cycle—POC; after they POC, they go get budget; then they go through procurement, and so on. And so we really see that normal 6–12 month cycle. And that's why we pointed to really the back half of the year, where we see some of those deals closing, in addition to the ones that will close this quarter. But good question.
Simran, Analyst at RBC Capital Markets (on behalf of Matt Hedberg)
Great. Thanks, guys. Congrats again.
OPERATOR
Thank you. Our next question comes from the line of Jonathan Ho with William Blair. Your line is open.
Jonathan Ho, Analyst at William Blair
Hi, good afternoon.
OPERATOR
Hello. Hello. Looks like Jonathan Ho has disconnected. We'll move on to the next one. Please stand by for our next question. Our next question comes from the line of Brad Zelnick with Deutsche Bank. Your line is open.
Bob, Analyst at Deutsche Bank (on behalf of Brad Zelnick)
Great, thanks for taking my question. This is Bob on for Brad today. Sanjay, I want to stick to the same theme on your AI security suite. It's great to see the strong interest in the product. Can you maybe provide more detail on which products are resonating the best with customers within the suite as they embark on these POCs, and more broadly, are you seeing these new capabilities help you get in front of more prospects that you might have been more difficult to
Sanjay Beri, Chief Executive Officer & Founder
Yeah, it's a good question. So are you the products that are resonating? I come back to always use cases. And if you're a CISO or CIO and you look today, you know that a large portion of your AI usage in your company is business-unit-led or shadow. Ninety percent of AI usage in many companies is of that ilk. And so the first question that you have in your mind is, well, wait a minute, tell me, what am I using? What AI exists in my company? What agents, what rogue agents, what sanctioned agents, what MCP servers?
Give me that visibility and then obviously enforce my policy. And so it's probably not surprising that the things that are resonating are, one, our Agentic Broker. What does that do? It shines a light on what agentic traffic and agents are in your company, tells you what those agents are accessing. Are they going to my corporate Office 365? Are they accessing private data? What are they doing? And so one, Agentic Broker: that is your way to understand agentic use and then enforce policy.
Because we're not a visibility platform, we're a real-time policy enforcement tool and platform as well. The second is Guardrails. Guardrails take a look at every prompt and every response and they say, well, wait, how do I make sure that in addition to what Netskope can give me on a granular context—like tell me that's a corporate version of Claude Code, a personal version—and let me make governance decisions on what type of AI can be used, how do I also, when it's used, make sure that it isn't spewing out data or content that is not part of my acceptable use policy?
I don't want it spewing out weapons content or content that is not applicable to what I want my company to hear. Guardrails is the second piece to that, and those were actually the first two, really, that we started releasing. And then, really, we released last quarter our AI Command Center. That is a central governance point where you can see all agentic use in your company. And so we foresee over time that that will be another big driver for.
UNKNOWN, Analyst
Thank you. I guess just one follow-up for Drew. Just in terms of the net new ARR ticking up sequentially from last quarter, can you maybe talk about the drivers of that uptick and if there's anything that stands out there?
Drew Del Matto, Chief Financial Officer
No, I think just overall strong demand in the business. There were a few, there were some AI deals, but I think overall it was demand in the business. AI funnel remains strong. It's something we expect really, I think, driving over the long term and just strong durability of demand over the longer term.
UNKNOWN, Analyst
Thanks for taking the question.
Drew Del Matto, Chief Financial Officer
You're welcome.
OPERATOR
Thank you.
Sanjay Beri, Chief Executive Officer & Founder
Good question.
OPERATOR
Please stand by for our next question. Our next question comes from the line of Jonathan Ho with William Blair. Your line is open.
Jonathan Ho, Analyst at William Blair
Hi, I'm back. Hopefully I can answer your question this time. I wanted to dig a little bit into your commentary around quantum-proof cryptography. Can you talk a little bit about that capability, and is this opening up either new opportunities for you or increasing your ability to see win rates? I just want to get a little bit more color there.
Sanjay Beri, Chief Executive Officer & Founder
Yeah, great question. So when you think about what we have implemented now across the world, it really allows our customers—so either they're a user, or they're coming from a manufacturing floor, or they're coming from any system—it allows them to talk to Netskope using quantum-resilient encryption. And we're using lattice-based encryption, which is pretty much the standard that NIST recommends. And as a result, that critical part communicating out to the internet, right, is protected.
And so what does that open up for us? Well, really it allows us to be well ahead of the timeline for when it is recommended people implement quantum-resilient encryption. And so for us and our customers that means, well, wait a minute. If I'm a financial services company, healthcare organization, I know that without doing anything—really, like if you are a Netskope customer, you don't actually really have to do anything now to enable quantum-resilient encryption—you have Netskope, you have the platform, and we built that in there for you.
Really it allows us to do that. And then as websites and AI applications adopt more and support quantum, Netskope's ready: when that site supports it, or that app, Netskope is going to be able to communicate with it using quantum-resilient encryption. So it's future-proofing, it's now allowing people to meet their regulatory environments, and it's allowing people to use it now. And so that's really for us a key. We always want to skate to where the puck's going, and that's a good example of that.
And so that'll help us, obviously, in proof of concepts continue our high win rates, which are above 80% when we get to a POC. That's probably a good way to look at it.
Jonathan Ho, Analyst at William Blair
Excellent. And can you give us a little bit of an update in terms of the federal government space and some of the opportunities that you have with either FedRAMP High or some of your sponsoring agencies, as well as some new opportunities that are coming up, especially with zero trust programs with the government side? Thank you.
Sanjay Beri, Chief Executive Officer & Founder
Yeah, great. So we feel we're very well positioned for the federal market. For us, as you know, we became FedRAMP certified—FedRAMP High certified. We started building our federal team. We brought on our federal leader this year in the U.S. federal market. And then we've really just been ramping our sales team and building them. For us, federal is a small piece of our business, but a very important growing one where we have a great platform for it.
We feel really good about that and being able to serve both the commercial and beyond side of the federal for years to come.
OPERATOR
Thank you. Please stand by for our next question. Ladies and gentlemen, we ask that you limit yourself to one question. Our next question comes from the line of Richard Poland with Wells Fargo. Your line is open.
Richard Poland, Analyst at Wells Fargo
Hey guys, thanks for taking the question. Sanjay, I'm just curious—I think the AI commentary in general about how it's progressing was really encouraging. I think you mentioned one-third of the AI security pipeline is already entering kind of the POC phase, and the general sales cycle is six to twelve months. I guess from the POC phase, is there typically, you know, a rough ballpark of how far into the six to twelve months we are, and just kind of any visibility you might have into, you know, what the uplifts have looked like so far for the ones that have closed, or just kind of contextualizing how the monetization side—while probably not too important yet—just any early indications you have on that side? Thanks.
Sanjay Beri, Chief Executive Officer & Founder
Yeah, it's a great question. And we are seeing AI security wins. We talked a little about them in my opening, and so they're across financial services, they're across tech companies and beyond. So we're seeing good traction, people really adopting our AI security. But if you just look back, we really released our AI security products—we started releasing them in Q1 of this year. We released some more in Q2, like AI Command Center, and then we released even a related product, our Dataset Command Center, this quarter, just, you know, three, four weeks ago.
And when you think about a typical cycle for an enterprise, what they do is they evaluate. They look, okay, what's my problem? It's, okay, uncovering AI, understanding it. Let me evaluate something. They go to POC, and then what they do is they, in many cases for AI, they go ask for budget. It could be out of stream where they have a committee meeting every quarter and they ask, okay, I have to go get budget for this—gets approved—and then you move forward.
That's just the normal enterprise sales cycle, and that really falls in that six- to twelve-month sales cycle process. And so for us, we converted and have converted some of our earlier beta customers because they got to look at it earlier, right. But really we see some of that pipeline that has entered POC really in the back part of the year, right? More towards the end of the year where some of that's converting. We expect to convert some of our more beta customers and beyond in Q3.
But we see that pipeline building, we see the POCs building, and then as a result we see the ARR building, and that's how I'd look at it. The last comment I'd make is AI security for us—it's not a product, it is a part of our platform, and it's composed actually of multiple products. And so customers also over time will bite off pieces of it. And so for us, we're really building a big pillar of Netskope where you have many products over time, and as you grow in sophistication of AI security, you'll grow with Netskope.
And our goal is obviously to release that functionality, a new product, well in advance of when you need it. So that's a good way for you to think about it.
OPERATOR
Thank you. Please stand by for our next question. Our next question comes from the line of Meta Marshall with Morgan Stanley. Your line is open.
Ryan, Analyst at Morgan Stanley (on behalf of Meta Marshall)
Yeah. Great. This is Ryan on for Meta, and thanks for taking the question. Any additional details you could provide around the sale of the AI product portfolio and how that's impacting sales cycles? Are you seeing them compress as customers look to evolve their security stack much quicker, or elongate given the potentially more complex cycle? Just any additional details there would be helpful, thank you.
Sanjay Beri, Chief Executive Officer & Founder
Sure. Absolutely. So if you look at AI security for us, there are existing customers and then there's obviously net new, and we go after both. And so if you're an existing customer, to adopt our Guardrails and Agentic Brokers—one of the beauties, we're an organically built platform; we built ground up. We release things when they're truly integrated. We don't just price-list integrate them, we actually integrate them in a common GUI, common policies, one data protection engine, one threat protection engine.
That organic approach of being purely building properly a platform enables customers to adopt these products and implement them from a technical point of view in a very easy way. Like the Agentic Broker and the Guardrails, you can enable that. If you're deployed, for example, with our next-gen SWG product, you just enable it and you can try it out. And so that's the beauty of having it. It's a common GUI and DLP. And so that's one. There's the other set of products like the AI Gateway, where that's meant for east-west coverage of your AI traffic, maybe within your public cloud or your data center.
Obviously you're going to install that, right? And so you're going to deploy it. And so our goal is just make it as easy as possible, make sure we cover north-south, east-west, and all one GUI, common policies. So I think that makes it easier for customers to technically deploy. They still have their sales cycle though, right, outside of that, but our goal is make the POC part as easy as you can.
OPERATOR
Thank you. Our next question comes from Brian Essex with J.P. Morgan. Your line is open.
John, Analyst at J.P. Morgan (on behalf of Brian Essex)
Hi. Thank you for taking my question. This is John on behalf of Brian. I just wanted to touch on the CapEx part. You mentioned the full-year CapEx is now expected to be around 45% of revenue tied to NewEdge. So I'm just curious, is this step-up primarily demand-driven capacity, or is it a prebuild ahead of the anticipated agentic traffic? And just curious, as those traffic grows, should we assume the CapEx to scale with it, or would there be, over time, would architecture absorb the volume at a lower incremental cost?
Drew Del Matto, Chief Financial Officer
Thank you. Great question, John. Look, it's continued infrastructure investment. Again, we see strong demand going forward. We've always kind of said it low single digits. I think we said somewhere between 3% and 5%. We're saying 4%, 5%. Between 4% and 5%. So I think we're pretty consistent with what we've said all along. Quite honestly, we've seen some growth, we're overperforming a little bit and so just maybe it scales up a little bit of that. The ARR comes in before the revenue.
Just think of that in that sense. So I think we're well within the typical expectations we had. The other considerations really aren't a factor as of yet. And you know, we'll obviously update more on that front as we go forward.
OPERATOR
Thank you. Please stand by for our next question. Our next question comes from the line of Srinik Kothari with Baird. Your line is open.
Zach, Analyst at Baird (on behalf of Srinik Kothari)
Hey guys, this is Zach on for Shrenik. Thanks for taking our question. So great to see NRR kick back up to 114% and 59% of customers now using four or more, 29% using six or more products. And so you guys, you know, offer still more than 25 products. So I guess the question is, how should we think about the natural ceiling for NRR, especially as AI security, data security, SD-WAN, other modules mature? And does the breadth of the portfolio create a path back toward sustainably higher expansion, or does the increasing enterprise scale naturally constrain NRR despite stronger dollar expansion?
Sanjay Beri, Chief Executive Officer & Founder
Yeah, I think from an NRR perspective we mentioned before, it can fluctuate quarter by quarter. The range we're kind of in, right, we have 113, 114, 115. That range which we've seen in the past quarters, that's what we've seen historically. And while we don't guide on NRR, I think qualitatively we know that with average customers having four or five products, we have a lot of ability to upsell for many, many, many years. Customers and enterprises, as you know, with a platform like ours, which is quite broad, they often will start with one or two core use cases and then they'll grow the year after and the year after.
And so we feel like what we have built with the platform and the number of products is just a durable, right, platform which will grow with them. And AI security absolutely will be a part of that NRR in different timelines for different customers and verticals. But for us it is a big pillar and we feel really good about our position there, and that will help us drive expansion.
OPERATOR
Thank you. Our next question comes from the line of Aidan Perry with Piper Sandler. Your line is open.
Aidan Alvarabo, Analyst at Piper Sandler (on behalf of Aidan Perry)
Hi, this is Aidan Alvarabo, and thanks for taking my question, really. Things may still be early, but can you talk about how customers are responding to the transaction-based pricing on the new AI products now that deployments are starting to scale? And are usage levels supporting larger commitments than initially expected? Thank you.
Sanjay Beri, Chief Executive Officer & Founder
Yes. So on the transaction-based pricing part, when you think about how we price, like take an example, the agentic broker, an agent, right, it's not a user, and so we try to price in the way that makes sense for what we're actually doing. And so if you think about the agentic broker, it's covering agent transactions. And so we price by transaction. And I think a lot of what we'll see on the internet will be non-human and, as a result, perhaps user pricing, right—even just subjectively—wouldn't make sense.
And so for us I think people get it; they get that transaction-based pricing makes sense. That's how agents think. They are used to, for inference pricing—tokens—transactions are sort of a prompt and a response. And what we have been trying to do is make sure they have visibility into it so they can see how many transactions are happening and, as a result, they have a sense of, okay, what's that going to look like when I buy? So I think the key is with your customers, just make sure that you're transparent, you're giving them a way to see it, then price in what makes sense from a usage perspective.
I think the transaction model has been received well. You've seen some of our other products like AgentScope, which is our AI agents—separate from AI security. We started releasing some of our AI agents like our DLP SecOps agent. That's more outcome-based pricing. It's based on, for example, how many cases across the thousands or millions of DLP incidents do we create and find that needle in the haystack for you, and that's the outcome you want. For us, we're committed to the models of transaction-based and, for AgentScope, outcome-based pricing.
OPERATOR
Thank you. Our next question comes from the line of Ishan Shetty with KeyBanc Capital Markets. Your line is open.
Ishan Shetty, Analyst at KeyBanc Capital Markets (on behalf of Milan)
Hey, this is Ishan on for Milan. Thanks again for taking the question and apologies in advance for the background noise. Sanjay, how do you view the current competitive landscape in SASE today? And particularly, do you think demand right now is healthy enough to support multiple scale vendors over the long term? And then just maybe a quick follow-up to that: in the competitive bake-offs, what are some of the primary reasons customers are choosing Netskope over competitors?
And conversely, where are you seeing competitors win against Netskope? Thanks again for taking the question and congrats on the quarter.
Sanjay Beri, Chief Executive Officer & Founder
Thank you. If you look at SASE, we have 25-plus products. They span everything from how to govern cloud and on-prem databases to cloud firewalls to digital experience management to enterprise browsers. I mean if you think about the word SASE, it keeps expanding. More and more is being put into SASE. In fact, there used to be like 20, 30 of the vendors that you're consolidating now right into SASE. And so really the way I think more about it is one of the biggest markets in security and networking was data and network security.
And you used to buy boxes and appliances and different data protection systems and different VPNs and different edge firewalls, and all that sort of is being converged and consolidated for simplicity, modernized from a security perspective into SASE. Yes, absolutely, SASE is a durable, I think long-term market, supports multiple vendors—given especially what you're doing is you're converging so many things. In addition to that, you look at what we are talking about for some of this call—AI security.
Well, okay, is that really part of just SASE? Is that a totally new market? And we think about it as a pillar, right, that's even outside of SASE. And so for us we know we have a very durable, long, good CAGR market in SASE. We're a leader. You saw that in all the analyst reports. SASE itself keeps growing in terms of what it encompasses. And so you get more and more TAM as SASE naturally subsumes more and more markets. And then we've entered AI security, which is a completely new TAM and a massive TAM.
And then you have AgentScope, which is our AI agent. So look, we don't lack for TAM for a long, long time. And as always, to be blunt, in security and networking, most CIOs you talk to, they don't want one platform for all of security and networking. They don't. They want a few that are open. And that's what we're committed to—being an open platform that converges many different systems but integrates with the others, like your EDR, like CrowdStrike, for example, some new integrations and beyond.
And so we feel really good about that for the future and now.
OPERATOR
Thank you. Our next question comes from the line of Oppenheimer and Company. Your line is open.
Nolan Genevine, Analyst at Oppenheimer (on behalf of Ittai Kidron)
Hi, this is Nolan Genevine on for Ittai Kidron. Thanks for taking my question. I just kind of wanted to double click on some of the commentary around the salesforce ramping. I think you had said earlier that roughly about 50% were ramped at this point and, you know, expecting that to improve through the year. Can you maybe just confirm is that an increase sequentially? When we think about the percentage of ramp reps, any more color there would be great.
Sanjay Beri, Chief Executive Officer & Founder
Thank you. The second half of the year, if you just take us back to last year, towards the end of the year we started investing obviously in new reps and ramping them. We started there in EMEA and APJ and you've seen the growth obviously in those regions, and then later on in NAM because obviously we were getting some of the leadership pieces in NAM for the next level of scale done last year. And that will result in an increased number of fully ramped reps.
That's probably a better way to think about it and, over time, just continue to grow our capacity. Now in addition to that, we also announced, for example on our earnings call just earlier, the Catalyst program for managed services. That's just another sign of, well, we're continuing growing our partnerships as well. Yes, we're growing more feet on the street and more reps and more SEs and we're ramping them. And that capacity is coming live later in the year and next year.
But we're also expanding our partnerships and that's very important to us. The AI partnerships—Anthropic, for example. We talked about the Amazon partnership, we talked about the Nvidia Open Secure AI Alliance. We talked as well about our partnerships with MSPs, SPs, SIs. All of those are also big pieces of our strategy and plan as we ramp and grow our go-to-market team. With such a great win rate, it's natural that we do that.
OPERATOR
Thank you, ladies and gentlemen. No further questions in the queue. I would now like to turn the call back over to Michelle for closing remarks.
Michelle Spover, Chief Communications and Investor Relations Officer
Thank you, and thank you everyone for joining us today. We're pleased with our Q2 results and the momentum we're seeing across the business. We remain focused on helping enterprises with their cloud and AI transformation journeys, driving continued innovation across our robust platform, and executing against a significant opportunity ahead of us. We appreciate your continued support and look forward to speaking with many of you over the coming weeks and months.
With that, we'll close the call. Thanks again.
OPERATOR
That concludes today's conference call. Thank you for your participation. You may now disconnect.
Disclaimer: This transcript is provided for informational purposes only. While we strive for accuracy, there may be errors or omissions in this automated transcription. For official company statements and financial information, please refer to the company's SEC filings and official press releases. Corporate participants' and analysts' statements reflect their views as of the date of this call and are subject to change without notice.
Login to comment