a. Zscaler 101
I will be turning these 101s into an archive category and linking to them starting next earnings season. Thank you to @JBL on Discord for the great recommendation.
Zscaler is a large player in network security. It competes with Palo Alto’s next-gen suite, Cloudflare and many others. Zscaler’s Zero Trust Exchange (ZTE) is its overarching, cloud-native security platform. It blazes a trail between users, apps and devices across eligible networks. Zero Trust is exactly what it sounds like: never trusting anything. The exchange vets and verifies all traffic as it moves within a company’s perimeter. It doesn’t allow bad actors to breach infrastructure weak spots and gain free access to everything else thereafter. That’s called “lateral threat movement.” It never trusts (as the name indicates) and constantly verifies. Zscaler uses risk scores to assess needed levels of security for requests. That makes sure it’s only creating user friction when there’s actual security concern. This Zero Trust approach routinely cuts infrastructure costs for customers by shrinking the attack surface down to grant more granular permission.
ZTE replaces an antiquated firewall and virtual private network (VPN) setup in which fixed rules determine entry into the firewall-protected environment. Once that entry is granted, every device & user within a perimeter gets perpetual and unconditional access. I think it’s clear to see how that could be more problematic than ZTE’s approach.
Product & Growth Pillar #1 – Zero Trust Everywhere
Zero Trust Everywhere (can’t call it ZTE because that’s the name of Zero Trust Exchange) is made up of its core network security products, branch-level security, and Zero Trust Cloud.
Core Network Security Products:
Zscaler Internet Access (ZIA) protects internet connections. It’s the middleman between a user and a network that ensures proper authorization & access.
Zscaler Private Access (ZPA) offers remote access to internal apps. This upgrades VPN utility by “connecting directly to required resources without public exposure,” per Zscaler filings.
Zscaler Digital Experience (ZDX) ensures high quality and always-on performance of cloud apps. It sifts through networks to identify sources holding back productivity to be fixed.
This includes application performance monitoring, some endpoint monitoring tools and more.
Zscaler for Users is the firm’s bundle that combines ZIA, ZPA and ZDX.
Branch-Level Security:
For newer, ZPA-related products, Zero Trust Segmentation localizes and separates networks. Branch security treats every single company location as its own island or network to shrink the attack surface. These “islands” connect to single apps or network subsections only when needed. That’s called micro-segmentation. This lowers the risk of lateral threat movement and is offered through a unified appliance. This means there’s one console for campuses, factories, retail shops etc., thus reducing complexity and friction.
Zero Trust Cloud:
Zero Trust Cloud is Zscaler’s name for cloud app and workload use cases within its core network security products. Zscaler also offers configuration analysis and cloud workload protection products.
Product & Growth Pillar #2 – Data Security Everywhere:
Zscaler Data Fabric is the term it uses for openly integrating with a long list of needed data sources. It handles ingestion, organization, “harmonization” and the unleashing of this lucrative context. Zscaler offers data security across endpoints, email, web, GenAI apps, legacy software etc. If it’s already protecting so much of the world’s network traffic… and if it already leverages all of this data (structured and unstructured) … that gives it a head start on using this insight to offer more products.
Data security posture management (DSPM) granularly tags, organizes and protects cloud-native data.
Data Loss Prevention (DLP) guards clients against data leakage or theft. This works for email, cloud, web, endpoints and more.
Data Fabric for security is how Zscaler collects and combines needed context from 1st-and 3rd-party sources. This improves overarching security visibility to ensure proper hygiene, strong risk management and timely remediation.
Data Security Everywhere is the name of the unified suite.
Product & Growth Pillar #3 – “Agentic Operations:”
This includes security operations (SecOps), IT Operations (ITOps) and all other AI product innovation. ITOps includes products like its AI Copilot for ZDX (GenAI assistant) and ZDX Network Intelligence. This tracks internet service provider (ISP) performance. It readily uses outage data to refine Zscaler’s zero trust exchange efficacy. This helps performance and up-time.
Within SecOps:
Unified Vulnerability Management (UVM). This offers a bird's-eye view to tag, assess and remediate vulnerabilities across all cloud environments and assets. It ranks all issues, prioritizes pressing items and offers the best course of action for remediation.
Risk360 flags vulnerabilities and offers end-to-end risk quantification with intuitive next steps for remediation.
Business Insights: Broad visibility into app usage, costs, needs and engagement. This helps minimize unneeded apps and licenses.
Other AI Product innovation to know:
AI Data Security Classification adds what it calls “human-like intuition” to identifying sensitive data across 200 types of information. This accelerates the process of uncovering “unexpected sensitive data” and vulnerabilities. Rather than static if/then statements across a few categories determining if data posture is healthy, this makes that process far more dense and nuanced, without adding hefty cost of complexity.
b. Key Points
Go-to-market fixes are working.
Forward-looking demand signals are strong.
Product expansion is gaining momentum.
c. Demand
Beat revenue estimates by 1.7% & beat guidance by 1.9%.
Its 25.7% 2-year revenue compounded annual growth rate (CAGR) compares to 27.2% last quarter and 29.3% 2 quarters ago.
Beat billings estimates by 5.3% & beat guidance by 5.3%.
As a reminder, annual recurring revenue (ARR) is a new company disclosure. It’s moving focus away from billings and towards that, which is something I support. Better metric from this type of business. $1M+ ARR customers rose 18% Y/Y.


d. Profits & Margins
SPONSORED
Upgrade below to read the rest of this article (profits, balance sheet, guidance, detailed conference call notes and my take), dozens more reviews from this quarter and consistently thorough news & analysis. There's a reason why several Fortune 500 executives are consistent readers.
Missed 80.2% GPM estimates by 90 basis points (bps; 1 basis point = 0.01%).
Beat EBIT estimates by 3.7% & beat guidance by 3.9%.
OpEx rose by 16% Y/Y.
Beat $0.80 EPS estimates by $0.095 & beat guidance by $0.09.
Beat free cash flow (FCF) estimates by 29%.
Gross margin weakness was driven by a “one-time deployment of a large private cloud in a government contract.” This included some hardware deployments (was required), so it lowered overall GPM. They expect GPM to go right back to 80% next quarter.
For the full year, data center CapEx was about 6% of revenue vs. a little under 7% Y/Y. This was due to investment timing more than anything.


e. Balance Sheet
$3.5B in cash & equivalents.
$1.7B in convertible notes. Newly issued this quarter.
3.3% Y/Y share count dilution.
f. Guidance & Valuation
Annual revenue guidance beat estimates by 2.5%.
Annual EBIT guidance beat estimates by 1.8%.
Annual $3.66 EPS guidance met estimates.
Annual ARR guidance was $3.687B. This includes 7%-9% net new ARR growth for the year excluding Red Canary M&A.
Annual FCF margin guidance of 26.3% missed 27.3% estimates. FCF dollar guidance was roughly in line thanks to the revenue beat.
Q1 guidance was similarly ahead on revenue and EBIT and in line for EPS. And again, it sees GPM moving back to 80% next quarter.
Guidance assumes stable macro and Red Canary contributing $95M to ARR ($90M revenue) next year.
Zscaler loves to offer initial annual guidance that it feels comfortable with easily beating. It loves setting targets that it can subsequently raise throughout the year. When setting the first guide for a year, companies are most vulnerable to disappointing vs. street expectations. It’s when teams love to be conservative (like Zscaler) and when analysts have to look out the furthest when guessing on current year results. Based on this, considering the very first guide is ahead of consensus estimates, this is quite encouraging. I see the 22.5% Y/Y revenue growth guidance ending up closer to 25% Y/Y based on this team’s consistent track record.
ZS trades for 56x forward FCF and 77x forward EPS. FCF is expected to compound at a 26% clip for the next 2 years. EPS is expected to compound at an 18% clip.


g. Call & Release
Growth Vector #1 – Zero Trust Everywhere
When we hear Zero Trust Everywhere, our minds should immediately go to platform-level adoption and protecting every relevant asset-to-asset connection. That’s really what they mean. The company was hoping to get to 390 Zero Trust Everywhere customers 4 quarters from now. They’re already at 350+ and exceeding internal expectations.
Zero Trust for Users (ZIA + ZPA + ZDX) continues to perform well, as even the most mature products within that grouping generate solid growth. And while that’s true, Zscaler expanding to branch-level and cloud connections are the 2 most exciting pieces of this category.
Zero Trust Cloud continues to be popular for retrieval augmented generation (RAG) (letting models and apps tap into more data sources). Zscaler just debuted a new onboarding product that allows customers to deploy this technology in under 10 minutes – with no dedicated virtual machines (VMs). This is called Zero Trust Gateway for Cloud Workloads and is built for AWS clients.
Zero Trust for branches upgrades legacy Software-Defined Wide Area Network (SD-Wan) functionality. As a reminder, SD-Wan is a digital manager of network connectivity. It splits network hardware and software-based control. This cuts costs, streamlines management & augments protection. SD-WAN is great for network optimization and can handle significant traffic routing needs. But? This requires direct appliance installation and does run into security concerns. Why? It's not zero trust. It gives users or agents within a branch access to entire networks and apps within them.
On the other hand, Branch doesn’t require hefty hardware installation. Just a cloud-native branch connector and a virtual machine (VM) to seamlessly turn on. This connector blazes a trail between branch users and specific cloud environment applications or networks. That traffic is vetted and verified on a session-by-session basis with its Zero Trust exchange. That reduces lateral threat movement at the branch level by shrinking permission down to a single workload or app… and requiring incremental permission for anything else.
This setup is driving wonderful demand for this product as an upgrade for SD-WANs, VPNs, firewalls and SWG appliances. This product on its own is displacing several hardware and software-based point solutions. And things are going so well here that Zscaler doesn’t even need to do any outbound demand generation to fill this product’s pipeline. That made my head turn.
There’s a large firewall refresh cycle coming next year, and this product is ideally positioned to greatly disrupt it. That could be why Fortinet had such underwhelming things to say about expectations for their own hardware firewall refresh cycle next year. As an aside, this product was made possible by network segmentation technology purchased in their Airgap M&A. It’s heartening to see them inorganically execute as well as they have.
Zero Trust Everywhere won a 7-figure annual contract and will deliver that customer 60% cost savings.
Zscaler signed its largest-ever branch deal during Q4. This includes 400 locations and 150,000 devices.
Zero Trust Cloud notched a sequential ARR acceleration during the quarter, as demand for its core products builds. This included an up-sell with an existing Fortune 10 healthcare firm (I think UNH).
Customers moving from one product category to Zero Trust Everywhere are generating a 2x-3x ARR uplift.
Growth Vector #2 – Data Security Everywhere:
Data Security is now at $425M in ARR vs. $350M six months ago. That’s an average of $37.5M in net new ARR per quarter. For context, SentinelOne is doing a little over $50M in net new ARR for their entire business. Zscaler is generating the majority of that in one growth area. And there’s plenty of room to run. Just 30% of its customers have 3+ modules (10% have 4+). There’s a lot of cross-selling to do, in addition to more new logo generation. During the quarter, this business secured a Fortune 500 services company in a new 7-figure deal. The customer bought its DLP tool and several other products.
Data Fabric is driving considerable cost savings due to ZS’s architecture not requiring it to store all of these data logs in a massive data lake for customers.
Growth Vector #3 – Agentic Operations:
As a reminder, Agentic Ops includes security operations (SecOps) IT operations (ITOps) and all AI-based innovation. This bucket crossed $400M in ARR and momentum is expected to remain very strong.
Starting with AI-based innovation, ZS is hard at work on security for AI applications. It now has a well-established business in safeguarding client users and assets from public AI apps, and is now gaining considerable momentum with private apps too. A product called AI Guard is used for securing these types of connections. They’ve grown a wonderfully successful business via securing users, workloads, devices and more; moving to inter-agent connection security is a “natural extension” of the platform.
Another agent-to-agent security tool is now testing with a handful of large customers. We'll hear more about that next quarter. They’re also working on use cases that secure model context protocols (MCPs), which connect agents with various data sources and apps. This is highly important for giving enterprises the confidence needed to embrace AI... and doing so with Zscaler at their side. All in all, AI transactions on its cloud rose by 35x Y/Y, and this exponential traffic growth means more demand for ensuring all of these interactions are done securely. Enter Zscaler.
Investors didn’t hear much about the ITOps bucket, but leadership did talk about further lacing AI innovation into ZDX Copilot (part of zero trust everywhere and this product bucket). That drove 58% Y/Y bookings growth. The team sees expansion beyond user performance issues to non-human entities as a key unlock here.
SecOps ARR soared higher by 85% Y/Y, as its Data Fabric product shines in providing scalable, organized, interoperable ingestion of needed data for Zscaler to protect its customers and assets. SecOps is also where its new managed detection and response product (MDR; purchased via Red Canary M&A) works its magic in blending AI-based and expert security analyst protection. MDR greatly lowers the talent barrier for clients to run their own investigations, as ZS now provides the assets needed to do so. This was a key missing piece in ZS’s pursuit of a fully-fledged Security Operations Center (SOC). An SOC is a holistic, end-to-end, single vendor environment where all client security data and work is done. No MDR services meant Zscaler couldn’t claim to have a full SOC. Now it can.
To summarize, ZS offers bottleneck-free usage of 1st-and 3rd-party data. It pairs that with Zero Trust Everywhere + Data Security Everywhere to greatly bolster asset coverage and use cases. It then deepens the product utility and data generation via other SecOps products like Risk360, Unified Vulnerability Management and more. From there, it adds AI-based automation and improvement wherever it can. It uses all of its tools to seamlessly collect more signal and experience, which, in turn, spins a positive flywheel and improves every product in the ecosystem. With Red Canary now purchased, it thinks it will get to a full SOC offering 12-18 months sooner. This is the platform-level vision for the firm.
ZFlex & Go-To-Market:
CrowdStrike has Falcon Flex. SentinelOne has SentinelOne Flex. And Zscaler has ZFlex. All three are updated module selling formats. All three allow customers to more flexibly consume commitments and mix-and-match modules within existing contracts. That is shrinking sales cycles, driving faster product adoption and supporting platform-wide demand. It’s emboldening customers to commit to more usage, knowing they can use what they want… when they want. Importantly, these deals come with preset contract values, so it’s not nearly as vulnerable to consumption-based fluctuations as a firm like MongoDB. While only a few months into this journey, they think this is partially why new business rose from 22% of total to 27% of total during fiscal year 2025. During Q4, this reeled in $100M in contract value and 50% sequential growth. It’s becoming the “preferred motion for strategic multi-year deals," including a 2x ARR up-sell with a large customer.
g. Take
Great quarter. I’m encouraged to see their strong initial annual guide for 2026 and am even more encouraged by the qualitative commentary on platform-wide adoption. It would be easy to poke fun at them by copying CrowdStrike’s go-to-market changes… but why wouldn’t they? This team is anything but dumb, and they can see how well that is working for Falcon Flex (their partner) on the endpoint side. CrowdStrike has shown everyone what works. They’ve shown Zscaler the template. It would make zero sense to do anything but emulate it. And so Zscaler is.
All of these go-to-market fixes are working and are helping drive better cross-selling quarter after quarter. The gross margin miss did bother me a little, but hearing that it was related to a one-off onboarding expense for a large public sector client made that miss entirely fine with me. That's especially true because they guided to a Q1 80% GPM. This company is easily one of the highest-quality network security vendors on the planet. Arguably the highest-quality period. They have a great product suite, a founder-led team and a massive runway. While the multiple is a bit stretched, it deserves to be. This name won’t be traditionally “cheap” for a long time, and I have no interest in trimming at these current levels. Very pleased.
