MAAT INDEX

CLAIM #68039 · Zscaler Inc (ZS) · 2025Q3 earnings call · Sep 2, 2025 · due Aug 31, 2025

We expect to close this transaction in August 2025.

Remo Canessa · CFO

PENDING
graded after results covering Aug 31, 2025 are reported

In context

Jay Chaudhry (Chairman and CEO): Thank you, Ashwin. Our strong Q3 results demonstrate growing demand for our platform and continued improvement in our sales productivity. More customers are adopting Zscaler's comprehensive solutions with platform-wide deals for our zero trust security. Driven by the strong demand, we achieved two significant milestones. First, we achieved our best Q3 with TCV bookings of over $1 billion. And second, our remaining performance obligations, or RPO, are now nearly $5 billion. New logo ACV had strong growth of over 40% year over year. Total new ACV was up double digits year over year once again in the quarter. Our annual recurring revenue, or ARR, was approximately $2.9 billion, representing the third straight quarter of 23% year-over-year growth. We remain on track to reach $3 billion or more in ARR by the end of this quarter. We are proud of achieving these strong top-line results at scale while delivering strong profitability. Our year-to-date fiscal 2025 revenue growth of 24% combined with our free cash flow margin of 28% resulting in rule of 52 performance. While many SaaS companies struggle to achieve rule of 40 performance, we have exceeded this industry benchmark for each of the last 21 quarters. Moving on to discussion of our platform, I am very pleased to share that our platform now secures over 50 million users, another significant milestone. This milestone gives us several competitive advantages. First, more users deliver a powerful network effect and strengthen our market. Zscaler's Zero Trust Exchange platform sits in line for enterprise communications. Every time we secure a user from a new attack, we apply that protection for all users of our platform, creating a flywheel for improving security. The magnitude of this effect is staggering. Last year alone, our exchange processed over 100 trillion transactions, blocked over 60 billion threats, and enforced over 5 trillion policies. This unique network effect differentiates Zscaler from other vendors trying to pursue this market segment and delivers unparalleled cybersecurity to our customers. Hence, more and more enterprises are selecting Zscaler as the partner of choice. Second, more users mean more high-quality data for our AI solutions. The millions of users, workloads, IoT OT devices on our platform result in over 500 billion transactions, generating over 20 petabytes of high-fidelity data per day. As you know, AI is only as good as the data that powers it, and I believe we have the best data. There are two unique aspects to our proprietary data: one, its vast quantity, and two, its high fidelity, both of which we utilize to train our models and deliver highly effective AI solutions. Third, the large volume of proprietary data I just talked about empowers us to deliver cutting-edge solutions for security operations. By leveraging our data fabric technology and correlating our logs with third-party data, we have introduced exposure management and threat management solutions, which deliver a new level of actionable insights for our customers' security operations. Leveraging our scale, we're building new security operational solutions, copilots, and agentic AI solutions that will be showcased at our upcoming Zenith Live conferences. With our Zero Trust Exchange platform, we fundamentally transform cybersecurity from a firewall-based model to zero trust architecture. Firewall-based security creates trusted and untrusted networks. Once a user or a threat actor gets on the trusted network, they are then blindly trusted and can move unchecked across the enterprise network. That is what makes ransomware and other cyber attacks so dangerous. With Zscaler's zero trust architecture, there's no concept of trusted networks. Every user, every workload, every IoT OT device, and every AI model is untrusted. With zero trust, we connect only the authorized party to the authorized application. While legacy vendors are attempting to cobble together disjointed point products and calling it a platform, we are constantly expanding our core Zero Trust Exchange by integrating new functionality to solve more and more of our customers' security concerns. Our industry-leading capabilities are recognized by our customers, partners, and leading third-party analyst firms. Of note, I am thrilled to share that Gartner once again recognized Zscaler as a leader in their Magic Quadrant, extending our status as a leader in the MQ for user security for over a decade. Moving on to the macro environment, customers remain cautious about their IT spending due to ongoing economic uncertainty. While customers are still prioritizing cyber and data protection, return on investment and the value delivered remain important to customers. A couple of quarters ago, we launched our cost-taker program to help customers identify and eliminate legacy security and networking products such as firewalls, VPNs, VDIs, and more. We are seeing great success with our program as more and more customers are embracing it to reduce cost and complexity while improving security. Additionally, to help our customers unlock more cost savings, we launched a new purchasing program in Q3 called Z Flex. Z Flex allows customers to flexibly scale their adoption of our platform to meet the constantly evolving organizational demands for cyber and data protection. Customers can seamlessly adopt, scale, and change modules based on agreed pricing, which simplifies the procurement process. Since its recent launch, Z Flex commitments contributed over $65 million in TCV bookings. To give you an example, an existing Fortune 500 technology customer made a multiyear commitment under the Z Flex program, increasing their ARR by over 40% to approximately $19 million. As part of the flex commitment, the customer added managed threat hunting, micro-segmentation, identity threat detection, GNI protection, and several data security modules. This win also demonstrates our growing capabilities in the SOC and Zero Trust cloud. I expect the contribution from Z Flex to grow meaningfully in the next fiscal year. Moving to products, we are seeing significant growth drivers in three categories: Zero Trust Everywhere, Data Security Everywhere, and Agentic Operations. Each of these categories is growing significantly faster than our overall ARR, and their combined ARR is approaching $1 billion. Let me cover each of these categories in more detail. On our last earnings call, we introduced Zero Trust Everywhere, which highlights our unique ability to take Zero Trust security beyond users, Zero Trust for cloud workloads, and Zero Trust for branches. In Q3, 59% of customers who bought Zero Trust branch were new logo customers. Many of these new logo customers are starting their branch journey by securing a small number of branches, which creates significant upsell opportunities for us. We are enhancing our Zero Trust branch functionality with several new offerings. For example, in Q3, we launched our new unified appliance for branch that brings together zero trust branch connectivity and zero trust device segmentation into a single plug-and-play appliance. This solution dramatically simplifies branch infrastructure, eliminating the need for SD WAN, firewall, NAC, and legacy segmentation. I expect zero trust branch to be a significant growth contributor in fiscal 2026. Another key pillar of our Zero Trust Everywhere strategy is zero trust cloud, which enables secure communication from workload to workload and from workload to the Internet. Initially, our customers leverage Zero Trust cloud to secure a small number of workloads to get comfortable with this innovative approach that requires no East-West firewalls, no North-South firewalls, no virtual private networks, no extra routes, and no direct connects. Now we are seeing larger deals for Zero Trust Cloud to secure a larger number of workloads, resulting in acceleration of Zero Trust cloud ARR. To share an example, an existing financial services customer made their initial purchase of cloud workload protection to secure all their internal workload traffic. This is an impressive 7-figure ACV land deal for workload protection. We are seeing tremendous success as more customers are becoming Zero Trust Everywhere enterprises by embracing zero trust for users, branches, and cloud. Last quarter, we shared our goal to triple the number of Zero Trust Everywhere customers from over 130 to over 390 by the end of fiscal 2026. I'm pleased to share that we ended Q3 with over 210 Zero Trust Everywhere enterprises, which is over 60% quarter-over-quarter growth. With this strong momentum, we remain on track to achieve our target. The second category driving our growth is data security everywhere. We have the most comprehensive data security capabilities to secure all types of data, whether structured or unstructured, data in motion or data at rest, and data across all channels, including Gen AI apps, web, email, endpoint, SaaS, DSPM, and more. Our comprehensive data security capabilities are resonating with customers and helping us win large deals. To give you an example, in a 7-figure ACV deal, an existing Fortune 50 automotive customer added an endpoint DLP module and privileged mode access or PRA while expanding Zero Trust users with more ZPA seats. This customer now has six of our eight data security modules, including inline DLP, SaaS security, cyber isolation, data isolation, classification and encryption, and endpoint DLP. With this deal, the customer's annual spend with us increased by over 50% to well over $10 million. Historically, data security was an important consideration for data-heavy regulated industries such as finance and healthcare. With the increasing adoption of GenAI and SaaS applications, data security is now becoming important to all industries. To give you an example, in a 7-figure ACV deal, a new logo, Fortune 100 food and beverage company, adopted Zero Trusted users and multiple data security modules. Moving to agentic operations, our third category of growth. Our agentic operations are expanding rapidly in two areas: IT ops and SecOps. For IT ops, we delivered ZDX Copilot last year as an embedded feature in our ZDX Advanced Plus package. Since the launch of ZDX Copilot a year ago, bookings for ZDX Advanced Plus grew over 70% year over year to nearly $75 million. ZDX CoPilot helps lower the mean time to resolution of service tickets, and its capabilities are becoming a key differentiator for us. To give you an example, an existing US-based large healthcare customer purchased ZDX Advanced Plus for 140,000 users in a 7-figure ACV deal. ZDX Copilot was an important consideration for this win. Moving on to the second area of agentic operations, SecOps, where we have several modules including Risk 360, Business Insights, Unified Vulnerability Management, Identity Threat Detection, and Cyber Asset Attack Surface Management, or Chasm. Our SecOps solution built on the data fabric technology we acquired last year is gaining traction and it drove over 120% year-over-year growth in SecOps ACV. To share a customer example, an existing US-based healthcare customer purchased Unified Vulnerability Management for 400,000 assets in a 7-figure ACV deal. The customer told me that UBM gave them an accurate asset inventory within two hours, which is a dramatic reduction from the six months it would have taken them otherwise. We will continue to expand our SecOps solution. The acquisition of Red Canary will allow us to expand into soft categories of managed detection and response, or MDR, and threat intel. We expect to close this transaction in August 2025. In addition to developing AI-powered solutions, we are enabling customers to safely adopt AI. Our GenAI data security module is enabling enterprises to securely use public Gen AI apps such as Microsoft 365 Copilot, Deepsea, ChatGPT, and more. In Q3, many customers, including an existing global 2,000 tech company, a leading fleet management company, and a large federal customer, and more purchased our GenAI data security module. In addition to securing public AI apps, we are introducing solutions to secure customers' private AI apps such as AI models and inference engines. We are expanding the functionality of our Zero Trust Exchange with an LLM proxy to analyze prompt queries to detect and prevent prompt injections and other malicious activities and analyze responses to prevent data leakage and enforce the right access. I believe these cutting-edge innovations will position Zscaler to be a market leader in the AI security space. Our customer obsession, employee dedication to our mission, and our customers' trust in our platform are driving us to deliver innovations that solve our customers' most critical security challenges. With a strong go-to-market machine and strong momentum in Zero Trust Everywhere and AI security, I am more excited than ever about our continued growth to $5 billion or more in ARR. Now I'd like to turn over the call to Remo for our financial results.

Verify independently

SEC filings for ZS · Claim quote is verbatim from the 2025Q3 earnings call.