Qualys, Inc. (QLYS) Earnings Call Transcript & Summary

August 4, 2026

NASDAQ US Information Technology Software earnings 61 min

Earnings Call Speaker Segments

Operator

operator
#1

Ladies and gentlemen, thank you for standing by. Welcome to Qualys' Second Quarter 2026 Investor Call. [Operator Instructions] Please be advised that today's conference is being recorded. I would like now to turn the conference over to Blair King, Investor Relations. Please go ahead.

Blair King

executive
#2

Thank you, Michelle. Good afternoon, and welcome to Qualys' Second Quarter 2026 Earnings Call. Joining me today to discuss our results are Sumedh Thakar, our President and CEO; and Joo Mi Kim, our CFO. Before we get started, I would like to remind you that our remarks today will include forward-looking statements that generally relate to product capabilities, future events or future financial or operating performance. Actual results may differ materially from these statements. Factors that could cause results to differ materially are set forth in today's press release and our filings with the SEC, including our latest Form 10-Q and 10-K. Any forward-looking statements that we make on this call are based on assumptions as of today, and we undertake no obligation to update these statements as a result of new information or future events. During this call, we will present both GAAP and non-GAAP financial measures. A reconciliation of GAAP to non-GAAP measures is included in today's press release. And as a reminder, the press release, prepared remarks and investor presentation are all available on the Investor Relations section of our website. With that, I'd like to turn the call over to Sumedh.

Sumedh Thakar

executive
#3

Thank you, Blair, and welcome to our second quarter earnings call. The adversary's playbook has been fundamentally rewritten by AI, collapsing exploit time lines and making one thing undeniably clear. Durable pre-breach risk management increasingly requires a vendor-neutral agentic AI fabric that moves beyond theoretical exposure to autonomous quantification of actual exploitable risk and remediation. Demonstrating this conviction, we delivered another quarter of strong revenue growth and profitability. The urgency behind that conviction continues to intensify. Frontier and open source AI models are capable of discovering and weaponizing vulnerabilities faster than any human team can triage them, compressing exploit time lines to hours and in some cases, turning disclosure into compromise before a patch even exists. AI is simultaneously becoming the greatest force multiplier and the most formidable challenge cybersecurity has ever faced. Where we part ways with the continuous threat exposure management, CTEM, solutions, is how we respond to it. CTEM solutions today respond by generating more findings, more theoretical risk scores and more dashboards and then pass along these findings off to siloed solutions that collect data and do the patching while losing critical time at every handoff. That approach was already failing before AI accelerated the threat landscape, and it is fundamentally inadequate now. We believe the defenders who win in this new era of AI will not be the ones who simply detect more and more vulnerabilities and produce dashboard tourism. They will be the ones who can autonomously detect vulnerabilities at AI speed, validate actual exploitability in production, quantify that risk in dollar terms, remediate it and then prove the exposure is closed in multi-vendor environments, all before an adversary gets there first. That is the design outcome of the AI-native risk operations powered by our Enterprise TruRisk Management, ETM, solution, and it is where nearly every customer conversation we are having is heading. Against this backdrop, I'm pleased to announce major new capabilities on the platform we will showcase at Black Hat later this week, spanning both AI for security and security for AI to address the post-Mythos threat landscape head on. First, with respect to AI for security, we're pleased to introduce InstaScan, powered by Agent Insta, the newest addition to our agentic AI marketplace and ETM solution for AI speed detection that is continuous, instantaneous and scanless. Today, when a new vulnerability advisory is released, it takes 24 hours to a week for organizations to detect it through traditional scan cycles, while adversaries weaponize the same vulnerability in minutes. Agent Insta is designed to collapse that time line. By converting the asset inventory, software patch and threat intelligence our customers already collect with Qualys sensors into high confidence exposure findings without a scan, new detections appear within minutes of disclosure and no rescan required and no agent disruption. The finding is then handed to Agent Val for instant exploit validation and the risk impact is determined and quantified immediately. While competitors are still processing an advisory writing signatures and waiting for a scan to complete, our customers already know whether they are exposed and are taking action before a vendor patch exists. Because the finding flows straight into validation and remediation, detection is not a report. It is the first step of a continuous closed loop. With last quarter's launch of TruConfirm and Agent Val safely validating actual exploitability across chained attack paths in live production environments and hyperprioritization using millions of findings to the fewer than 1% that require immediate action, the bottleneck is now shifting from identifying what to fix to actually fixing it before adversaries can act. This leads me to the next phase of our TruRisk Eliminate agenda, autonomous zero-day remediation at scale. Through AI scored autonomous remediation waves, the AI-native ROC now determines the right action for every asset in multi-vendor environment, deploying a patch [indiscernible], staging a control rolled out where caution is warranted or applying a compensatory control where operational risk demands it. Every action is gated by our AI-driven patch reliability score and resiliency snapshots, delivering rollback rates below 1.5%, below half of 1%. The most critical assets remain human-in-the-loop oversight while the platform autonomously remediates the rest. Orchestrating the cycle is Agent Sara, who prioritizes exploitable risk, quantifies it in dollar terms, sequence continuous waves and revalidates closure with Agent Val, all without proportional headcount. Furthermore, with the introduction of peer-to-peer patching, we are accelerating the delivery across distributed environments while removing the dependency on centralized infrastructure. Put simply, these newest innovations make autonomous zero-day remediation wave-driven vendor-agnostic, safe and provable. In live benchmarking, this collapsed the window of exposure from 21 days to minutes and auto patch 60% of the vulnerabilities. This is not incremental. It turns a massive surge in exploitable vulnerability volume from an impossible backlog into a continuously clear queue at the speed of modern attacks. You cannot solve a minutes problem with a month-long solution. And that's the gap the AI-native ROC was designed to solve with Agent Insta, providing AI speed detections, Agent Val hyperprioritizing validated exposures, and Agent Sara performing autonomous remediation in a continuous closed loop. Turning to security for AI. As enterprises raise AI workloads into production, the AI infrastructure they are building is already the next attack surface. With the introduction of TotalAI 2.0, organizations can now see their full AI estate from workforce to workload and from code to run time. Through new sensors that see AI activity at both the employee and workload level, security teams can now discover shadow AI activity across the organization, from what employees are doing with AI to which models, endpoints and services are running in production across hybrid multi-cloud environments. We have also extended our posture management coverage to SaaS platforms, including Anthropic and OpenAI to help organizations enforce security and compliance policies across the AI platforms their teams are already using. Additionally, they can now identify security gaps in code before deployment, remediate with guardrails at run time and test model context MCP tool exploits across over 50 adversarial scenarios. And of equal importance, every AI risk across the entire stack from GPU to infrastructure to supply chain to the newest prompt injection attacks is now scored and prioritized through the same true TruRisk that powers the risk operations center. For organizations seeking to secure the infrastructure, powering their AI future, these new innovations become an increasingly strong differentiator for Qualys. As ROC adoption accelerates and these capabilities continue to compound, we remain laser-focused on driving ETM adoption throughout our VMDR customer base and positioning Qualys for larger upsell opportunities over time. Moving to our business update with customers spending $500,000 or more with us growing 8% from a year ago to 229. Let me share a couple of recent wins, which illustrate why organizations are turning to Qualys to help unify their security stack and operationalize the ROC. The first is with an existing Global 300 customer managing a complex data-intensive environment spanning on-prem, multi-cloud and rapidly growing LLMs in production. As the volume and velocity of vulnerabilities across the environment accelerated, their teams recognized that prioritization based on theoretical risk scores couldn't deliver the business context needed to act decisively. With fragmented telemetry, disconnected tools and little automation, their teams were spending more time documenting risk than reducing it, while unpatched assets and shadow IT were silently extending exposure windows by months. As a result, the customer chose Qualys to operationalize their ROC, adopting VMDR, ETM, TruRisk Eliminate and TotalAI alongside several other modules in a low seven-figure QFlex annual upsell. By consolidating Qualys and third-party data into unified risk fabric, this customer has aligned risk reporting to the Board's tolerance level, shifted remediation from manual processes to autonomous workflows and reduced its exposure window from months to hours while flattening the hiring curve and delivering better security outcomes. This is also an outstanding example of how we are leveraging our channel partners to activate the ROC with new -- to win new business. The second is with a European health care company that has been a small existing scan on behalf of Qualys customer, but was relying on a managed service provider to run the broader vulnerability program across more than 140 locations. That model delivered people and process, but not autonomy. Scan operations prioritization and remediation guidance all flowed through the provider's team on the provider's time line, leaving the customer dependent on external resources to understand and act on its own risk. As this environment grew more complex and vulnerability volume surge, the limitation of that dependency became unsustainable. Costs for ballooning remediation cycles were [indiscernible], the customer had limited visibility into the very data driving the decisions made on its behalf. This customer chose Qualys consolidating its stack into the Qualys platform by adopting VMDR, ETM and TruRisk Eliminate in a six-figure QFlex upsell. ROC automation was the entry point and remediation was the immediate proof of value. By unifying detection prioritization and autonomous remediation into a single AI-native workflow, this customer has replaced a manual people and process dependency with a platform that delivers significantly lower cost, less complexity, full control and peace of mind for the CISO. These wins reflect the broader ETM momentum we are starting to see as more and more customers recognize the efficiencies and scale of AI-native ROC automation. Further supporting our growth trajectory, QFlex continues to gain traction as another strategic lever for accelerating ETM adoption. As we heard in the customer wins I described earlier, QFlex played a direct role in enabling significant upsells for Qualys by giving these customers the flexibility to commit broadly across the platform while preserving the ability to shift investments as their needs evolve. This precisely the value proposition of QFlex model was designed to deliver. Building on strong results from our initial rollout, we have now taken QFlex live for enterprise customers looking to expand with Qualys and believe it can become an increasingly important driver of platform expansion over time. Turning to our executive team. With the recent departure of our CISO and General Manager of our ETM business, I want to address how we are positioning for continuity and acceleration. To lead product strategy and our ETM business going forward, I have appointed Shailesh Athalye as our Chief Product Solutions Officer, a nearly 14-year Qualys veteran who has served as our SVP of Products for the last 5 years. Shailesh has been instrumental in shaping many of the platform innovations we discussed today, and his deep institutional knowledge of our technology, our customers and our road map makes him the natural leader to drive the next phase of ETM adoption and our customer-led growth strategy. Additionally, I'm pleased to welcome Nathan Smolenski as our new Chief Information Security Officer. Nathan is a seasoned cybersecurity executive with over 25 -- 24 years of experience driving security transformations across financial services, insurance and high-power -- high-growth SaaS environments, most recently serving as the global CISO at Cyera. We are excited to have both Shailesh and Nathan in these critical roles as we continue to scale our platform and accelerate ROC adoption. In summary, Qualys' continued innovation spanning both AI for security and security for AI, growing AI-native ROC adoption powered by our ETM solution, a growing federal pipeline for new business opportunities, strong partner-led execution and promising early QFlex engagement continue to reinforce the demand we're seeing for a unified risk management platform that autonomously moves beyond theoretical exposure to validated, quantified and remediated risk at the speed of modern attacks in multi-vendor environments. We believe these achievements not only advance our strong competitive differentiation, but also sharpen the market opportunity ahead of us and bolster our confidence in reaccelerating long-term growth in the business. With that, I will turn the call over to Joo Mi to further discuss our second quarter results and outlook for the third quarter and full year 2026.

Joo Mi Kim

executive
#4

Thanks, Sumedh, and good afternoon. Before I start, I'd like to note that except for revenues, all financial figures are non-GAAP, and growth rates are based on comparisons to the prior year period unless stated otherwise. Turning to second quarter results. Revenues grew 11% to $182.2 million. As a result of a strategic emphasis on leveraging our partner ecosystem to drive growth, the channels continue to increase its contribution, making up 54% of total revenues compared to 49% a year ago. Revenues from channel partners grew 22%, with revenues from direct remaining largely unchanged from Q2 of last year. By geo, 15% growth outside the U.S. was ahead of our domestic business, which grew 8%. U.S. and international revenue mix was 55% and 45%, respectively. In Q2, our overall upsell execution improved, with our net dollar expansion rate at 105%, up from 104% last quarter. The net dollar expansion rate of customers with prior year purchase of ETM or CSAM subscriptions in Q2 was [ 107% ], consistent to last quarter. Moving on to product mix. Our differentiated new products continue to drive growth. First, ETM/CSAM combined made up 12% of total bookings and 14% of new bookings on an LTM basis in Q2, up from last year's 9% and 10%, respectively. Next, patch management made up 9% of total bookings and 16% of new bookings on an LTM basis in Q2. This compares to 7% and 16%, respectively, in Q2 of last year. Lastly, TotalCloud made up 5% of total LTM bookings in Q2, unchanged from a year ago. We believe that these differentiated products combined will increase contribution to bookings in 2026, given our opportunity to increase market share and maximize share of wallet. Reflecting our scalable and sustainable business model, adjusted EBITDA for the second quarter of 2026 was $83.8 million, representing a 46% margin compared to 45% last year. Operating expenses in Q2 increased by 8% to $73.2 million, driven by investments in sales and marketing, which grew 14%. With this strong performance, EPS for the second quarter of 2026 was $1.98 per diluted share and our free cash flow was $55.9 million, representing a 31% margin compared to 20% in the prior year due to fluctuations in working capital. Normalizing for this, first half of 2026 margin was 42% compared to 43% in the prior year. In Q2, we continue to invest the cash we generated from operations back into Qualys, including $3.7 million in capital expenditures and $76.8 million to repurchase 797,000 of our outstanding shares. As of the end of the quarter, we had $229.8 million remaining in our share repurchase program. With that, let us turn to guidance, starting with revenue. For the full year 2026, we now expect revenues to be in the range of $732 million to $738 million, which represents a growth rate of 9% to 10%. This compares to prior guidance of $721 million to $727 million. For the third quarter of 2026, we expect revenues to be in the range of $185.5 million to $187.5 million, representing a growth rate of 9% to 10%. This guidance assumes our net dollar expansion rate remains at current levels with moderate growth contribution from new business in 2026. Shifting to profitability guidance. For the full year 2026, we expect EBITDA margin to be in the mid-40s, with a low teens increase in operating expenses and free cash flow in the low 40s. We expect full year EPS to be in the range of $7.74 to $7.88, up from the prior range of $7.44 to $7.65. For the third quarter of 2026, we expect EPS to be in the range of $1.91 to $1.98. Our planned capital expenditures in 2026 are expected to be in the range of $8 million to $12 million and for the third quarter of 2026 in the range of $1 million to $2.5 million. With that, Sumedh and I would be happy to answer any of the questions.

Operator

operator
#5

[Operator Instructions] The first question comes from Kingsley Crane with Canaccord.

William Kingsley Crane

analyst
#6

Congrats on amazing results. Sumedh, look, the volume of AI-generated vulnerabilities, it's a clear reason why customers need InstaScan and the ROC. Can you just double-click again on how this is showing up in pipeline, how this is showing up in urgency? And then if CVE volumes were to double again, how could that -- how could you capture that in your per asset pricing model?

Sumedh Thakar

executive
#7

That's a great question. And I think even though the disclosure findings are increasing, I think the organization's ability to remediate is what is currently being looked at, right? And that's really where our focus has been on helping these customers with autonomous remediation because at a very high level, you cannot go and tell your management as a security leader that you're going to respond to autonomous AI exploits with more manual tools that are e-mailing each other on what needs to be fixed, et cetera. And so if you look at sort of the risk operations center and what we are focused on is Agent Sara is already helping with the autonomous remediation piece. But to do a great job with that and with high confidence, you need to significantly hyperprioritize your findings, and that's where Agent Val on the risk operations center platform is helping run actual exploits to reduce the number of findings that need to be auto remediated that actually matter to the business. And then now, our latest announcement yesterday of Agent Insta, which is the ability to scan instantaneously whenever new advisory comes out, now shrinks the time line from the advisory coming to the time line when the advisory -- the vulnerability even detected in the customer environment. And so with all three of these on the ETM platform, you now actually have a real path to get something that is important and exploitable in your business remediated within the first 24 hours with minimal human intervention. And that is the conversation that everybody is having, is that they need to go -- have conversations internally to say, how are we going to move towards a road map that allows us a feasible autonomous remediation plan, and the ETM is enabling that. And so we, of course, have been ahead of this, as you know, for the last few years with creating autonomous remediation capabilities. And so we already had a few customers in the pipeline who were discussing with this, who saw this beforehand. And so the conversation with post-Mythos is helping -- helped us accelerate a couple of these opportunities. However, there's a large number of customers that are very, very curious now about what they are -- what they can do and what is the art of the possible with this kind of autonomous remediation. And so we're very excited to see that pipeline in terms of the conversations, in terms of POCs. It's looking good, and we're happy with that. And of course, we have to now move forward, get the POCs done, look at the budget, see when they will close, et cetera. But I would say with all the innovation and the investment that we have made, we're pretty excited to see the current conversations that we are having.

William Kingsley Crane

analyst
#8

Great. And then just a follow-up for either Sumedh or Joo Mi. Building off of that, billings grew 16%. It was a really sizable raise. On top of a broad-based beat, we're now talking about reaccelerating long-term growth. Is it that the conviction in the business hasn't changed and the market has come towards you this quarter? Or just -- can you help us understand just how much more bullish you are in the business today than you were 3 months ago?

Sumedh Thakar

executive
#9

Look, I think we've always sort of -- we're ahead of this, with remediation, et cetera. And so the conviction that this is what the market is going to need and the investments that we put in before that has always been there. I think right now, with the advent of AI, it's just accelerated what we have sort of been seeing was going to happen at some point. And so that's sort of driving -- the conversations are driving us to feel like because of the investment we put in the platform, these are solutions that actually can help customers right now in what they are looking for to set up as auto remediation capabilities for the future. So I mean I will say that a lot of that goes to us being able to see where the industry is going to go and putting the investment behind it and now, positive conversations with the customers are kind of helping us get through to ensuring that we can actually work through to see how these opportunities can close.

Operator

operator
#10

And our next question is going to come from Jonathan Ho with William Blair.

Jonathan Ho

analyst
#11

Congratulations on the strong quarter. I wanted to understand a little bit better. When you talk to your customers about sort of their change in the exposure risk management process, can you maybe help us understand how much of this is that they need to cover more assets versus the fundamental patch management process changing versus having sort of the ROC part of this on the managed side. Can you just maybe unpack that for us a little bit in terms of what they're buying and also what they intend to buy over time?

Sumedh Thakar

executive
#12

Great question. I think at the end, what they are focusing on is can I remediate the thing that actually matters to my environment as fast as possible, right? And that includes all assets in their environment, but that doesn't necessarily mean that they have -- they don't have other products that might be helping them get some visibility through acquisitions with that. And I think that's where if you look at our strategy around ETM and what we have done with the concept of a ROC is that the ROC is a multi-vendor solution. So it gives us the ability for the customers who are leveraging Qualys to have capabilities like InstaScan where we can instantaneously detect things. We could do the same on data collecting from other scan-only products that are just throwing a bunch of CVEs. So we are seeing with ETM that it is allowing us to expand licenses in the early POCs that we have with some of these customers and early purchases. They are also bringing data on other tools from outside of Qualys into the ETM solutions so that they can get a holistic view across multiple tools and then prioritize the ones that really matter, run the exploit and then get into the remediation piece. So I think it's the focus on adding on the patch management eliminate capabilities is one aspect. And then with ETM broadening the coverage of with how many assets that they should look at to make sure the remediation succeeds is helping us that even if they have some other scan-only CVE detection tool, which is producing a lot of false positives, we can all still bring that license as part of the Qualys ETM solution.

Jonathan Ho

analyst
#13

Excellent. And just given the relative proximity of Mythos, when do you think the bulk of the spending will start to materialize? I'm guessing we haven't seen it yet. I just wanted to get your sense for how you think this is developing with the pipeline.

Sumedh Thakar

executive
#14

I think we -- it's the same that we had talked about when Log4j came out and SolarWinds and stuff. Our customers typically tend to be enterprises, organizations that are more thinking of long-term changes in their security programs and less about the knee-jerk reaction of immediate spending, and that's kind of what we're seeing right now as well. A lot of these conversations are CISOs looking at ways to use this post-Mythos threat landscape to make the point to their teams, internal stakeholders on long-term sustainable changes that they can make to their security program, where it's not that you do this one thing for the 1 month. For companies to roll out a program that allows them to do autonomous remediation, that's where they need to think through, work with different stakeholders and then look at the budget. Does it come from an existing solution that they can get rid of? Does it something that they need to add on? Et cetera. So I think we are early on, we feel, like in these conversations. And we will see, as the next few quarters goes, we'll see what meaningful signals come in terms of when these budgets might be leveraged otherwise. But so far, right now, it's a lot more of positive conversations and pipeline building we're doing.

Operator

operator
#15

And our next question will come from Patrick Colville with Scotiabank.

Patrick Edwin Colville

analyst
#16

I guess let me just ask Sumedh a question first and then Joo Mi, I'd like to ask you one after, if possible. Great to see the guide, Sumedh, your fiscal year guide being raised from 8% to 10%. And then in your prepared remarks, talking about reaccelerating growth in the long term. I guess can I ask -- one question is like I think that's a new disclosure. I don't think you said that before. Can you just clarify that, that is new? And then what gives you confidence if it is new to say that now? Is it stuff you're seeing or just conversations or just kind of help provide some color around that?

Sumedh Thakar

executive
#17

I wouldn't say it's new, Patrick. I think we always talked about investing and innovating in the platform, and our belief that what we're doing and helping with the focus on remediation is something that we've been working on strategically, along with a focus on federal and along with focus on working with our partners to focus on that acceleration of growth in the long term. Getting into long-term double-digit growth has been a focus for us. So I think that is not new, so to say. I would say that given the current conversations that are happening, it just gives us an opportunity again to talk about what we have already built and the innovations that we have already done and see how this maps to the current focus that the market has in terms of -- look, at the end of the day, the CISOs need to be able to go tell the Board and management somehow that they are going to adopt some form of autonomous remediation. And so they're going to have to figure out how they're going to do that. And if you look in the market, with Qualys having 150 million patches deployed in the last 12 months, 40 million of those already being deployed autonomously, that gives us an interesting conversation point to build confidence for them when they're looking at these things. And so right now, it's the same sort of what we have always talked about and focused on, is working towards innovating and investing to create long-term growth and double-digit revenue growth is what we've always been looking at. And so this is just continuing on that momentum.

Patrick Edwin Colville

analyst
#18

And Joo Mi, if I may, the disclosure about new bookings, so 14% of new bookings were from ETM and CSAM, which if my model is correct, that's the same as last quarter. And then 15% of new bookings from patch in 2Q. Again, if my model is correct, that's the same as last quarter. So I guess, I totally understand all the kind of qualitative commentary around ETM and patch. Shouldn't -- like how come it's not showing up more clearly in that new booking number? And should we expect that proportion of new bookings to ETM and CSAM and patch to increase as we look towards kind of 3Q and 4Q?

Joo Mi Kim

executive
#19

In terms of the percentage contribution to bookings from new customers, we do anticipate fluctuations. We're not too surprised whether it goes up or down. So if you take a look at the percentage that made up from patch management last quarter was 15%. This quarter, it's 16. You're right, on the ETM side, ETM/CSAM, it's 14%, the same as last quarter. We're not too surprised by it because it really depends more on the customers who are onboarding at that point in time, what they end up starting off with. So for example, if we have a new prospect that decide to purchase more of that or spend more of that budget on VMDR or versus ETM versus patch management, we want to make sure that, that customer is set up to succeed and grow with us. And so this percentage, it's a healthy percentage. What it lends itself to -- for us is it's really a validation that when we land new logos, go after the market and when we're able to win, it's partly due to the fact that we were able to innovate and lead the market in terms of our continuous enhancement and our product solution set with ETM/CSAM as well as patch management.

Operator

operator
#20

And the next question is going to come from Rudy Kessinger with D.A. Davidson.

Rudy Kessinger

analyst
#21

Congrats on the strong results here. I guess if I hear what you're saying, in that the Mythos stuff is more so still in the pipeline and conversation stages, and that wasn't really the driver of the quarter. It sounds like more so just better ETM execution, but certainly seeing those demand trends. I guess -- and your goal is to accelerate growth going forward. I guess, are you guys more willing to maybe utilize some of that margin and put that to work and maybe take margins down a bit further to help drive that accelerated growth? Or how should we think about the growth profitability trade-off into next year?

Sumedh Thakar

executive
#22

Look, I think we always look at -- we've talked about this. We always look at investing in the innovation, investing in our sales and marketing as we have been doing more recently. And I think we are -- we always focus on ROI, and we see the opportunity ahead of us. And as the opportunities move through the pipeline, it is something that we continue to evaluate. But at this point, we feel good about kind of the investments that we're making. And I think as we see the opportunity, we will continue to evaluate that to make additional investments where needed.

Joo Mi Kim

executive
#23

Right. And to double-click on that, part of the reason why we're able to accelerate the top line growth currently without necessarily having to double dip on the investment is the fact that we are a partner-first, partner-led growth momentum right now, with majority of our growth, especially when it comes to new logo acquisitions, we're working very [indiscernible] with our partners. And we believe that we are investing appropriately at the current levels with the sales and marketing expense going up by 17% in Q1 and 14% in Q2. In the second half, we're anticipating further acceleration in the investments into sales and marketing.

Rudy Kessinger

analyst
#24

Got it. And then for my follow-up, current calculated billings was really strong in the quarter. Anything to call out there as far as maybe early renewals or anything like that, that drove the better sequential and year-over-year on CCB in Q2? And then for Q3 and the full year, just any directional commentary on CCB growth expectations?

Joo Mi Kim

executive
#25

Q2, from a current billings perspective, there's always naturally quarterly fluctuations. So I would point to the LTM, which has smooth out some of the lumpiness in the current billings growth rate, which is still an acceleration. As of last quarter, it was 8.5% on the LTM growth. And then this quarter, it's at 10%. We're very pleased with the growth. And because of that, we decided to increase the revenue growth guidance. In terms of the second half current billings growth, we're still anticipating for the baseline 7% to 8%, which implies a full year current billings growth in line with the revenue growth rate of 9% to 10%.

Operator

operator
#26

And the next question is going to come from Junaid Siddiqui with Truist.

Junaid Siddiqui

analyst
#27

Sumedh, TruConfirm appears to be a powerful tool for ETM by helping customers validate which vulnerabilities are actually exploitable in their environment. Is that becoming like the land motion for ETM? In other words, once customers see exploit validation reduced thousands of findings to a handful of truly exploitable risks, how often does that conversation expand into broader ETM remediation and risk quantification deployments?

Sumedh Thakar

executive
#28

That's a great question. I think when you look at the entire vulnerability life cycle to be successful with that, those are three buckets, right, which is detection as fast as possible, and that's where our innovation with Agent Insta, which I call -- I like to call it scanless scanning, the ability to post detection in less than 1 hour, makes it possible for you to get that visibility of what might be exposed. However, just based on what is exposed from a vulnerability perspective, doesn't give you the confidence that this is actually exploitable and not exploitable environment because you have other tools that you might have put in place. And so we definitely see that with TruConfirm, it's a differentiator. There are a lot of "CTEM solutions" that are just aggregating findings and giving you a theoretical score, but that theoretical score doesn't necessarily tell you whether it is actually going to be exploitable or not. So when we are able to tell the customer, look, the ETM solution will help you theoretically reduce your findings to the 1% that matter. And then additionally, you can run these lightweight safe exploits to further reduce the number of findings that actually will work in your environment. That becomes a very interesting conversation because -- why is that interesting? Because now that you have reduced the number of findings, it makes autonomous remediation, which is the next thing that we are selling to them, really plausible. If you tell somebody that you're going to fix 1 million vulnerabilities autonomously, that's a very hard conversation. But if you can show to them that highly validated 70 vulnerabilities are the ones that we are going to fix with automation because they are confirmed exploitable and we cannot wait for attackers to exploit them, that conversation becomes a lot better. And so TruConfirm is definitely a key part of the conversation, especially with our existing VMDR customers who are just getting great scanning. Now the ability to upgrade to ETM and then run the validation, which then encourages them to look for the eliminate, which is the remediation kind of fits and makes all these pieces work together really well. And so it is an important piece of every conversation we are having with existing customers.

Junaid Siddiqui

analyst
#29

Great. And just a follow-up, could you just help us understand the behavior of those customers that have not yet adopted ETM, like those VMDR-only customers? Are you still experiencing a high amount of churn there? And is that kind of like still the primary source of any pressure on your overall net dollar retention rate?

Sumedh Thakar

executive
#30

I think nothing to call out. We are pleased with the overall momentum of the business, and it's -- we look at that as a great opportunity for us to talk to our existing VMDR customers because all of them are going to have to answer to their management and Board what they are doing to find a way for autonomous remediation. And so the conversation of upgrading to ETM and the conversation of upgrading and adding on eliminate, we look at that VMDR customer base as a big base that we have where we can actually create growth opportunities because almost everybody is going to need some sort of a prioritization and remediation solution moving forward after the post-Mythos era. So that's actually a pretty good way for us to look at it, is I think less and less customers -- I mean, more and more customers, I would say, would want to look at a solution that's not just scanning, but also giving them remediation, and that's what we're seeing in the conversations right now.

Operator

operator
#31

And the next question will come from Joseph Gallo with Jefferies.

Grant Darling

analyst
#32

This is Grant Darling on for Joe Gallo. I wanted to ask first, have you seen anything different competitively post-Mythos release? It seems like we're hearing more chatter from a variety of players who are signaling more interest in the space. So your results certainly signal strength, but just curious if you're seeing or expecting any change in competitive dynamics? And also if there's any difference in the frequency of competitive displacements to call out?

Sumedh Thakar

executive
#33

Well, I think the problem the customers have is the chatter, right? There's too many solutions that are just throwing more and more CVEs and which is kind of something that they're focusing on, and that creates a lot of chatter and noise for customers that they have to read through. And so where we are seeing success is not just the traditional, hey, let's find 1 million CVE findings. Where we are differentiating and why we are seeing that differentiator is things like TruConfirm, right, where we're basically able to not just tell you the CVE is there, but actually have the ability to find a way to give you confidence in its exploitability by actually exploiting it in some cases, giving you additional information in other cases. Our autonomous remediation, while there's a lot of tools that are throwing out CVEs and tools that are saying that they can find something and then they will e-mail the patching solution what they need to fix, we're actually natively patching that in a matter of hours. And so the interest is more to say, oh, wait, there is a solution that can actually allow me to fix an exploited exposed vulnerability in 4 hours from the release versus I'm going to have a hotspot of these different solutions that is not actually going to work in the environment. And so I think that's really kind of what's driving the conversations right now, and that's what we're excited about.

Grant Darling

analyst
#34

Got it. And then maybe for my follow-up, you've referenced the growing federal pipeline a few times. I guess just any way to quantify the size of that business today? And then just any more detail that you could provide regarding your thoughts about that opportunity and maybe your right to win there going forward?

Sumedh Thakar

executive
#35

It is right now not a big part of the business, but that is where the opportunity lies right now. I think if you look at the focus of the current administration, if you look at the new CISA BOD, very interesting that the new CISA BOD really talks about fast detection, exploit validation and quick remediation. I've heard this somewhere for the last 2 years, right? So we've focused on building this and being ready for this. And so the federal government is also very, very focused on ensuring that they are seeing outcomes, which are CISA's new requirement of remediating in 72 hours, okay? How are you going to remediate something if your scan is taking 2 days? That's where InstaScan is going to help you find the issue in the first 60 minutes, giving you a realistic chance to meet the board requirement. And so that is creating very, very positive conversations with the federal customers that we are engaged with. A lot of them have very old school traditional on-prem solutions for scanning, different solutions for patching. They've been trying to patch those together for a while. And now, these BODs and the focus from the administration is giving them an opportunity to look at something that is more modern and something that is really helping them give an outcome that is measurable. And so now with Qualys having a FedRAMP high platform that actually is the only platform that can do both the detection and the patching as a FedRAMP high solution and our modern approach with agentic AI capabilities built in with these three different agents versus sort of having one generic agent that is just talking to, in the back end, to Anthropic or something like that, it creates a big differentiation in our mind. And I think that gives us the opportunity to go out and the right to have these conversations and work towards winning some of these opportunities that are coming our way. And so for us, given that right now, it's not a big material part of the business is where we see the big opportunity moving forward. And we're excited about the conversations and the investments that we're putting behind that.

Operator

operator
#36

And the next question is going to come from Joshua Tilton with Wolfe Research.

Joshua Tilton

analyst
#37

I apologize for the background noise. I'm in Vegas for Black Hat. Maybe just two quick clarifications. First one, Joo Mi, I think you said you still expect 7% to 8% product billings growth for the year. Can you help us understand like why that stands or is un-updated from, I guess, what you expected last quarter, given the strong billings growth in 2Q? Is it a conservative thing? Is it a 2Q is a blitz type thing? Just help us understand why that full year outlook is left unchanged. And maybe I'll just -- I'll ask my second question now. Any way you could help us understand what net dollar retention rate is baked into the full year guidance since I think it's the second quarter now that it kind of picks up for us?

Joo Mi Kim

executive
#38

To clarify, the current billings guidance for the full year is now in line with our revenue guidance of 9% to 10%. So the 7% to 8% is for the second half current billings. So what we're assuming is for the baseline, the second half current billings will grow by 7% to 8% year-over-year, and that's predicated on no meaningful change to our net dollar expansion rate, which is now at 105% versus 103% that we started off the year.

Joshua Tilton

analyst
#39

To be clear, the current billings of 7% to 8% is for the second half, you're saying?

Joo Mi Kim

executive
#40

That's right.

Operator

operator
#41

And the next question will come from Mike Cikos with Needham.

Michael Cikos

analyst
#42

If I could just pick up on where Josh was leading off there. I think even earlier this year, we were talking about a soft guide for that 7% to 8% CCB in calendar '26. Just given the year-to-date outperformance we've seen, why not tweak that CCB even for back half of this year at 7% to 8%? Why not take that slightly higher? Again, we're coming off this mid-teens result you just posted in Q2. It doesn't seem like there was any real fluctuations from early renewals. So can you just help us think about what your assumptions are in driving that 7% to 8% in the back half?

Joo Mi Kim

executive
#43

Yes. Quarterly current billings because we don't actively manage to it, it tends to be lumpy. And so if you take a look at it on an LTM basis, that's what we like to point to if you're trying to gauge the business momentum. So on the LTM current billings growth rate, last quarter, it was at 8.5%. This quarter, it's currently sitting at 10%. And so what we believe right now is, it's great that we see that acceleration in the LTM current billings growth rate. And I think that, that 10% better reflects the current business momentum today. And as Sumedh commented on before, we didn't know exactly when the acceleration or heightened kind of pressure from our existing customers who are already pretty far along the discussion of ETM adoption, we're really going to execute on those deals. And Q2 is a reflection of that. If you were to take a look at our customer base and take a look at them and split them into two different camps, there are already a smaller cohort of customers that were pretty far along in the discussion around the ROC adoption upgrading to ETM that ended up translating into a better-than-expected results in Q2. But that said, the second camp of customers that are not as far along in discussion, what we're anticipating right now is we're not seeing any significant increases or acceleration in the sales cycle for the cohort of customers that are up for renewal in the second half. So given that, it's a data point, Q2 very strong quarter. We're not anticipating any meaningful material changes in the deal cycle in second half. And so therefore, we decided to keep the baseline at 7% to 8% for the current billings for the second half of this year.

Michael Cikos

analyst
#44

Understood. And maybe another one here. Just wanted to get a better sense. It was great to see the last 12 months net dollar expansion improved by 1 point again this quarter to 105%, especially since you have this improvement for total company. Meanwhile, the ETM and CSAM NDR was unchanged sequentially at 107%. Can you, I guess, provide any further granularity, almost like a quarterly snapshot here as far as what was driving the total company improvement from products or cohort of customers adopting or increasing spend? I'd just love to get a little bit more on that.

Joo Mi Kim

executive
#45

If you take a look at our product mix, that will help you to kind of come with us in this journey of different product adoptions and as customers come up for renewal, where they decide to spend more on. So right now, with our ETM and CSAM currently making up 12% of total bookings, up from 9% a year ago period, that kind of tells you that, that's really helping to drive the bookings growth momentum that we see in the business today. Patch management definitely contributed to that as well, currently at 8% a year ago, it was at 7%. And then offsetting that was the VMDR contribution coming down to 49%, down from 54% a year ago.

Operator

operator
#46

And the next question will come from Brian Essex with JPMorgan.

Brian Essex

analyst
#47

I guess I have two. I think both for Joo Mi. But I guess, Joo Mi, I'd love to -- it's great to see the traction that you've got on the partner side of the business, on the indirect side. But I would love to kind of understand where you're guiding spending, particularly in sales and marketing, but for OpEx overall. I think last quarter, you talked about mid-teens growth. It seems like you're pointed in the same direction, but you've come in well under that for the first half of the year. I'd love to understand where are you seeing traction? Where might you regulate greater spend? And what might -- outside of outperformance on the top line in the back half of the year, how are you regulating spend on OpEx and sales and marketing relative to that mid-teen level when we've come in materially below that in the first half? And then I've got a follow-up.

Joo Mi Kim

executive
#48

On the sales and marketing spend, majority of that spend increase is driven by the headcount. So if you take a look at the 17% year-over-year for Q1 and 14% year-over-year for Q2, both quarters, majority of it was basically investing back into our business, expanding our team, making sure that we have the right team members and the GTM team, whether it be sales or marketing or product all across the board that's really focused on selling our product and better positioning ourselves and working very closely with our partners. Now with that said, we are leveraging AI back into our business as well, and that certainly helped to make sure that we're looking at the operating efficiency, making sure that it's an appropriate level of investment that we're spending each quarter. And so with that in mind, we're very pleased with the momentum that we see today. And we do anticipate increasing spend, whether it be -- number one is always going to be headcount for us right now for 2026, but there are other certainly investments that we're making, which is demand, making sure that we're investing back in the business to generate sufficient pipeline that's quality that we can execute on for the second half of this year.

Brian Essex

analyst
#49

Okay. Great. That's helpful. And maybe just on how far penetrated are you into your installed base with QFlex? And how are you regulating the level of availability that customers might have for QFlex? Are you still measuring it and keeping it kind of like the high-end customers? Or could we expect maybe a broader roll out as you develop more experience with QFlex across your customer installed base?

Joo Mi Kim

executive
#50

We have rolled out QFlex. It's really more intended for our enterprise customers. And so now it's available -- generally available to enterprise customers, and we are having appropriate level of discussions with the set of customers that are up for renewal as well as new prospects as we discuss with them what they're looking for, is QFlex something that's going to be advantageous to them. And really, if you think about this product, it's a premium product, right? It helps the customers really adopt a number of our solutions in a seamless way. And so they're more than willing to pay the premium price for this. And the way that we think about it right now is it going to be right for customers who are willing to grow [ with us ] and our existing customers as we look to drive our net dollar expansion rate further up and continue to focus on that metric as customers grow with us. It will be right for our enterprise customers who are looking for a cost-effective way to gain more value while at the same time, increasing their spend with Qualys.

Operator

operator
#51

And the next question comes from Shrenik Kothari with Baird.

Shrenik Kothari

analyst
#52

Again, congrats on the great quarter. So big picture, you did underscore that near term, there is a stronger patch management cycle, but you believe there's a broader category reset underway around the control plane for the pre-breach risk management, as you described, exploit validation, risk quantification and autonomous remediation. Around the AI urgency, I remember last quarter, you guys did say since it's broadening the opportunity, customers may extend sales cycles or pause renewals. Just can you add any finer point around these broader strategic deal conversion timing, sales cycles? How long are these evaluations taking? Are you seeing these conversion rates getting faster broadly just directionally? And then I have a quick follow-up.

Sumedh Thakar

executive
#53

It's a great question. I think as I mentioned earlier too, and when we talk about the ROC, right, the risk operations center pre-breach risk management is broader than just vulnerability management. Obviously, that is a focus right now. We've talked about the use of misconfigurations as part of these attacks, the use of identities and the recent OpenAI-Hugging Face is a great example of a vulnerability misconfiguration and identity being used. And so the risk operations center has been broadly built around that. I think in terms of the way we are seeing the conversations, it's not about saying, can I just patch for the next 1 month and I'm done? I think there is a -- the conversation with customers are really about -- nobody is saying that they're just going to patch now and then go back to not having regular patching cycle and autonomous patching in the future. So the broad-based conversation is about how do they moving forward create a process throughout their organization that is long-lasting where they're able to -- any threat that comes up, they're able to actually respond to that threat very quickly. And so we see this more as something that is broadly being talked about, and we see the opportunity for that to be something that we can focus on. And so I think right now, like with any corporation, large companies, they want to understand what the big picture road map is that they can talk to their management about while focusing on sort of phases that they can deploy. And so the ROC conversation allows us to have a much broader strategic conversation with ETM. And then the vulnerability management, patch management is something more of a -- that they're focusing on right now to be able to have that phased approach. So overall, I think our innovation around ROC that we have been focusing on is coming to help quite a bit for these customers to have broader conversation while the focus right now is changing their patch management processes and programs. So I do think that the opportunity -- or rather this is giving us an opportunity to have those broader conversations with the customer. And as Joo Mi said, of course, there were a small cohort of customers that was already in this process before Mythos came out to adopt patch management. Just a reminder, 150 million patches already applied by Qualys. So some customers have been at the forefront of these. So that helped us sort of say, look, we were right. The customers were like, look, we're already in the process. We were right to focus on patch management. So that helps in the short term, but then there's a long cohort of customers that are having these conversations now and is going to create the opportunity for us to have sustained conversations of additional things in the ROC as we move forward and they get comfortable with a patch.

Shrenik Kothari

analyst
#54

Got it. Very helpful. And Joo Mi, just a follow-up to Mike and Josh's question around the NDR improvement, very encouraging to see that pick up. The ETM cohort though remains at 107%, I think they highlighted. Is QFlex going live? and you did highlight it's playing a direct role in several of these large platform expansion and also helping pull forward the commitments, helping bookings more than near-term usage. So is that what is kind of explaining these budgets shifting towards more newly urgent capabilities reflected in your sort of NDR next 12 months versus something more strategic on ETM/CSAM usage will follow through? Like just wanted to understand if QFlex is playing a role there.

Joo Mi Kim

executive
#55

QFlex is really meant to accommodate customers who are looking for that flexibility and who are willing to spend more with us. And so we wanted to make the selling motion seamless, easier for them where it creates a win-win opportunity for both the customers as well as us. And so we're very pleased with us going today with it broadly. It still applies to a small percentage of customers today who signed up for QFlex. It's not yet reflected in the numbers, but we believe that this will help drive the NDR for us broadly speaking.

Operator

operator
#56

This will conclude today's question-and-answer session and also concludes today's conference call. Thank you so very much for participating, and you may now disconnect.

Read the full transcript via the API

You're viewing the first half of this call. Get the complete Qualys, Inc. transcript — plus 251,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.

Get the API View API docs →

This call discussed

For developers and AI pipelines

Programmatic access to Qualys, Inc. earnings transcripts and 251,000+ others is available through the EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments, full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.