EPS · actual vs est
Revenue · actual vs est
Summary
Generated 2026-02-05
Management highlights
- Emphasized agentic AI-driven risk fabric for pre-breach risk management, moving beyond traditional vulnerability detection to operationalizing cyber risk management aligned with risk tolerance.
- Highlighted product innovations: broadened Qualys ETM platform to third-party data, launched orchestration layer, introduced agentic AI risk fabric, agentic AI risk management marketplace, natively integrated Identity Security Posture Management, and confirmed exploits before compromise.
- Shared customer success stories: a Global 50 customer unified security stack with Qualys for mid-6-figure upsell, a global 200 company in Latin America secured 7-figure upsell, and federal business saw mid-6-figure expansion with a government agency.
- Leveraged partner ecosystem with increased partner-led deal registration and mROC partners launching new services.
- Beta tested QFlex to help customers accelerate adoption of Qualys ETM platform.
Segment performance
For the full year, Qualys grew revenues by 10% to $669.1 million. In the fourth quarter, revenues grew 10% to $175.3 million. The channel contributed 51% of total revenues, up from 48% a year ago, with channel partner revenues growing 17% and direct growing 4%. Outside the U.S. saw 15% growth, ahead of domestic growth of 6%. Product mix: Cybersecurity Asset Management combined with ETM made up 10% of total bookings and 13% of new bookings in 2025, up from 8% and 9% respectively; Patch Management made up 8% of total bookings and 16% of new bookings in 2025, up from 7% and 16% respectively; TotalCloud made up 5% of total bookings in 2025, up from 4% a year ago.
Guidance
- Full year 2026 revenue expected to be in the range of $717 million to $725 million, growth rate 7% to 8%. First quarter 2026 revenues expected to be $172.5 million to $174.5 million, growth rate 8% to 9%.
- Full year 2026 EBITDA margin in mid-40s, free cash flow margin in low 40s. Full year EPS expected $7.17 to $7.45. First quarter 2026 EPS expected $1.76 to $1.83.
- Planned capital expenditures in 2026 $8 million to $12 million, first quarter 2026 $1.2 million to $2.6 million.
Risks
- Market changes and competition could impact adoption of new products like ETM. - Uncertainty in the pace of ETM adoption by customers, especially in the early stages of partner and QFlex rollout.
Q&A highlights
Q: Can you talk a little bit more about some of your QFlex offerings and how it potentially helps remove friction and perhaps encourages broader adoption of your platform?
A: The QFlex proposal allows customers at their pace to consolidate capabilities on a single platform with Qualys over time, leveraging different Qualys capabilities throughout the year as threats change, with positive feedback in the beta phase.
Q: Can you maybe help us understand like where the customer is in terms of their AI journey? And also help us understand what that opportunity looks like for Qualys?
A: Customers are leveraging VMDR and cross-selling into ETM with agentic AI capabilities, which help them get outcomes quickly. Agentic AI capabilities are a differentiator for customers to upgrade or cross-sell, and Qualys looks forward to customers bringing more data around their AI solutions into Qualys ETM.
Q: Would just love to hear more about how Agent Val is elevating ETM from an efficacy perspective. And just how Agent Val is reducing total net hours at the customer level and how that's resonating with customers?
A: Agent Val leverages autonomous decision-making to confirm exploitability in the environment, saving IT teams time by not chasing false positives, and allowing for immediate remediation once exploit is confirmed, which is a significant time saving and resonates positively with customers.
Q: I have a couple of questions. I mean I appreciate these are not your estimates, but if I look at 2023 market share data which you gave, at the time you had market -- total market as $64 billion. In the current deck, you are talking about $53 billion market for 2026. My question here is that basically, is the core market shrinking for VM and exposure management?
A: Vulnerability management has evolved, and Qualys is focusing on solutions customers actually want, such as Patch Management, Cybersecurity Asset Management, and ETM with agentic AI, which are areas customers are focusing on, and the company is maximizing share of customer spend in these areas.
Q: Nice color there on why the Armis acquisition by ServiceNow won't be impactful. It sounds like a key portion here is that basically, they're lacking Patch Management. So can you dive a little bit further here and explain why Patch Management has remained such a differentiator for Qualys here?
A: Patch Management is highly integrated with VM, quickly detecting, validating exploitability, and fixing issues within minutes. Qualys agents have deployed 140 million patches in 12 months, and it's a highly integrated solution that customers need to quickly fix vulnerabilities before attackers exploit them, which competitors lack.
Q: Joo Mi, are there any headwinds leading to expectation of no change in NDER in your calendar '26 guidance -- that's embedded in calendar '26 guidance?
A: Our guidance is assuming no material change in net dollar expansion rate, informed by pipeline, existing customers' spending plans, and preliminary discussions, with the base case assuming similar gross dollar retention and upsell expectations.
Q: Keeping a little high level here, Anthropic's new model release today put an emphasis on cybersecurity and specifically, the model's performance for vulnerability discovery and patching. So I was just wondering, if you could talk about what you believe these developments mean for Qualys and maybe the cybersecurity industry more broadly as model providers look to potentially go deeper into cybersecurity?
A: Anthropic's development helps stress the importance of using ETM and Agent Val to quickly validate and fix vulnerabilities in customer environments, as attackers use AI to find issues, and Qualys' platform empowers customers to stay ahead by finding and fixing issues quickly.
Q: Can you help us understand -- I know you kind of touched on this, but can you help us just better understand the strategy you're taking to get customers to adopt not just vulnerability management, but also prioritization and Patch Management. And then I'm wondering, is there a way to think about what percentage of the customer base is just using that basic functionality of vulnerability management?
A: Qualys focuses on providing integrated solutions like Patch Management and Cybersecurity Asset Management to add execution around vulnerabilities, giving customers dollar value-based prioritization and quick remediation. The percentage of customers using basic vulnerability management is not specified, but focus is on moving to more integrated solutions.
Q: How engaged are partners involved in core VM renewals? Or are they -- or a lot of them, the newer partners that you attracted last year, are they more about selling new products?
A: mROC partners are excited about offering higher value services around ROC, leveraging agentic AI capabilities to reduce staff time, with early positive conversations and wins, though it's early days for full traction.
Q: Junaid Siddiqui: Sumedh, you've talked about the Risk Operations Center's focus on proactive risk management versus the SOC's focus on detection after the breach being a major differentiator. Just wanted to ask, are you starting to see budgets flow more towards proactive security versus reactive detection and response?
A: Yes, there is more focus on proactive risk management with customers shifting or asking for budget to move in that direction, as reactive solutions have fatigue and proactive solutions like ROC are seen as more valuable.
Q: Joshua Tilton: Can you guys hear me? Sumedh, I want to follow up on your answer when you were asked about kind of Anthropic blog post today on cybersecurity. And I just -- I want to reask the question, but I want to ask it in a much more simpler way. Is the way to think about it that a lot of the functionality that Anthropic was talking to was more around application security testing. And kind of some of the vulnerability discovery that happens before you would use a traditional VM tool. And again, I just play a security expert on TV. So if I'm thinking about it the wrong way, please let me know. But is that kind of the right way to think about it?
A: Yes, Anthropic's focus is on application security testing and vulnerability discovery before traditional VM tools, while Qualys' focus is on quickly assessing and fixing vulnerabilities in customer environments after discovery.
Key numbers
Reported versus consensus
Earnings calendar feed
| Metric | Reported | Consensus | Delta | Prior year |
|---|---|---|---|---|
| EPS | $1.87 | $1.78 | +5.1% | $1.60 |
| Revenue | $175.3M | $173.2M | +1.2% | $159.2M |
Transcript
February 5, 2026Full transcript unavailable for redistribution
The structured summary above covers the available call sections. Full transcript text is not included on this page.
Continue exploring
Prior quarters
This page presents the stored structured earnings-call summary and deterministic earnings calendar values. How this is generated. For informational purposes only; not investment advice.