10-K: Qualys Reports Strong 2025 Growth Amid Macro Headwinds
Annual Report
Qualys, Inc. announced a 10% revenue increase to $669.1 million and a 14.1% rise in net income for fiscal year 2025, driven by strong customer demand and strategic investments.
Summary
- Revenues increased by 10% to $669.1 million in 2025, up from $607.6 million in 2024 and $554.5 million in 2023.
- Net income grew to $198.320 million in 2025, a 14.1% increase from $173.680 million in 2024.
- Diluted net income per share was $5.44 in 2025, compared to $4.65 in 2024 and $4.03 in 2023.
- Adjusted EBITDA reached $313.409 million in 2025, maintaining 47% of revenues, up from $282.842 million in 2024.
- Net cash provided by operating activities significantly increased to $309.400 million in 2025, from $244.094 million in 2024.
- The net dollar expansion rate remained strong at 103% for both 2025 and 2024, indicating robust customer retention and growth.
- Approximately 76% of the 2025 revenue increase came from existing customers, with 24% from new customers.
- International customers contributed 63% of the revenue increase in 2025, highlighting global expansion.
- Channel partners generated 49% of total revenues in 2025, an increase from 46% in 2024 and 43% in 2023.
- The company repurchased 1.4 million shares of common stock for $182.9 million in 2025, with $160.5 million remaining under the program as of December 31, 2025.
- An additional $200.0 million was authorized for the share repurchase program on February 5, 2026, increasing the total authorization to $1.6 billion.
Sentiment
Score: 7
Explanation: StockSavvy.ai views this filing positively due to solid revenue and net income growth, strong operating cash flow, and consistent customer expansion, indicating a healthy core business. However, the noted macroeconomic headwinds and intense competitive landscape warrant a balanced perspective.
Positives
- Achieved significant revenue growth of 10% year-over-year, reaching $669.1 million in 2025.
- Reported strong net income growth of 14.1% to $198.320 million in 2025.
- Maintained a healthy Adjusted EBITDA margin of 47% of revenues, with Adjusted EBITDA increasing to $313.409 million.
- Demonstrated robust customer retention and expansion with a consistent net dollar expansion rate of 103%.
- Generated substantial cash flow from operating activities, increasing to $309.400 million in 2025.
- Continued investment in research and development, enhancing the cloud platform and suite of solutions.
- Expanded global reach and customer base, with a majority of Forbes Global 100 companies utilizing Qualys solutions.
- Actively returned capital to shareholders through a significant share repurchase program, with an additional $200 million authorized.
- Maintained effective internal control over financial reporting as of December 31, 2025.
- Strong corporate governance with a dedicated CISO reporting to the CEO and an ISMS aligned to ISO/IEC 27001 standards.
Negatives
- The trading price of common stock declined from $115.06 at December 31, 2024, to $109.05 at December 31, 2025, despite positive financial results.
- Experienced an increase in income tax provision by $12.4 million in 2025, partly due to the One Big Beautiful Bill Act (OBBBA) and decreased tax benefits.
- Noted ongoing macroeconomic uncertainties, including inflationary pressures, high interest rates, and geopolitical conflicts, which could reduce IT security spending.
- The sales cycle for solutions can be long and unpredictable, particularly for large transactions and in the current macroeconomic environment.
- Reliance on 15 shared cloud platforms makes the company vulnerable to service disruptions from natural disasters, cyberattacks, or other events.
- Faces intense competition from both large public companies (e.g., CrowdStrike, Palo Alto Networks) and smaller specialized providers.
- Sales prices are subject to competitive pressures, which may lead to decreases and impact gross profits.
- Risks associated with international operations, including foreign currency fluctuations, political instability, and regulatory changes, could harm business and operating results.
- The use of AI/machine learning technologies in solutions could introduce additional cybersecurity risks or legal liabilities due to evolving regulations.
Risks
- Quarterly and annual operating results may vary, potentially causing the stock price to decline.
- Failure to anticipate market needs or enhance solutions on a timely or cost-effective basis could harm competitiveness.
- Inability to effectively scale and adapt the platform to meet customer performance requirements could harm operating results.
- Failure to renew existing subscriptions, sell additional subscriptions, or attract new customers would harm operating results.
- Research and development efforts may not produce successful products or enhancements that generate significant revenue.
- The platform, products, website, and internal systems are subject to intentional disruption or security incidents, potentially leading to liability and reputational damage.
- Long and unpredictable sales cycles require considerable time and expense, causing revenue fluctuations.
- Adverse economic conditions or reduced IT spending may negatively impact business.
- Disruption of service at the 15 shared cloud platforms could interrupt delivery of solutions and reduce revenues.
- Intense competition in the markets may lead to a lack of sufficient financial or other resources to maintain or improve competitive position.
- Sales prices of solutions are subject to competitive pressures and may decrease, reducing gross profits.
- Solutions failing to detect vulnerabilities or incorrectly detecting them could harm brand and reputation.
- Inability to recruit and retain qualified sales personnel would harm sales and business growth.
- Reliance on third-party channel partners to generate a substantial amount of revenues, with risks if these relationships are not effectively managed.
- Significant international operations expose the company to foreign currency fluctuations, political instability, and regulatory changes.
- Failure to appropriately manage future growth or improve systems and processes could negatively affect operating results.
- Dependence on the continued services and performance of senior management and other key employees.
- Sales to government entities are subject to challenges and risks, including certification requirements like FedRAMP.
- Undetected software errors or flaws in solutions could harm reputation, decrease market acceptance, or result in liability.
- Privacy and data handling concerns (e.g., GDPR, CCPA, NIS2, UK GDPR, EU Data Act) could result in additional cost and liability or inhibit sales.
- Use of AI/machine learning technologies in solutions could result in harm to business and operating results due to technical errors, security risks, or evolving regulations.
- Solutions contain third-party open source software components, and failure to comply with licenses could restrict ability to sell solutions.
- Reliance on third-party software and data that may be difficult to replace or cause errors or failures.
- Failure to protect proprietary technology and intellectual property rights could substantially harm business.
- Assertions by third parties of infringement or other violations of intellectual property rights could result in significant costs.
- Governmental export or import controls could subject the company to liability or limit ability to compete in foreign markets.
- Requirement to collect higher sales and use or other taxes could lead to liability for past sales and decrease future sales.
- Changes in income tax provision or adverse outcomes from examination of income tax returns could adversely affect operating results.
- Market volatility may affect stock price and the value of an investment.
- Actual operating results may differ significantly from guidance.
- Future sales of shares by existing stockholders could cause the stock price to decline.
- The share repurchase program may not be fully consummated or enhance stockholder value, and repurchases could affect the stock price.
- Anti-takeover provisions in charter documents and Delaware law could make an acquisition more difficult.
- Disruptive technologies could gain wide adoption and supplant cloud-based solutions.
- May not maintain profitability in the future.
- Forecasts of market growth may prove to be inaccurate.
- Financial results are based in part on estimates or judgments relating to critical accounting policies, which may prove incorrect.
- Changes in financial accounting standards may cause adverse and unexpected revenue fluctuations.
- Failure to maintain an effective system of internal control over financial reporting could impair ability to produce timely and accurate financial statements.
Future Outlook
The company anticipates continued revenue growth from new and existing customers, driven by strong market position and demand for its solutions. It plans significant investments in research and development to enhance its cloud platform and introduce new solutions. The company will continue to evaluate the impact of macroeconomic factors and monitor the effects of the One Big Beautiful Bill Act (OBBBA) and anticipated guidance from the U.S. Department of the Treasury. Share repurchases are expected to continue in 2026.
Management Comments
- Management will continue to evaluate the nature and extent of the impact of macroeconomic factors on the business, financial position, results of operations, and cash flows.
- Management expects to continue to expand shared cloud platform infrastructures and invest in customer support and operations teams to support growth.
- Management expects to continue to devote resources to research and development to continuously improve existing solutions and develop new ones.
- Management expects to continue to invest in sales and marketing teams and programs to support new solutions on the platform.
Industry Context
StockSavvy.ai notes Qualys operates in a highly competitive and rapidly evolving cybersecurity market, characterized by increasing complexities due to cloud adoption, containers, serverless models, and geographically dispersed IT assets. The company's integrated platform approach aims to counter tool fragmentation, a common industry challenge, by offering a unified view of IT and OT asset inventory, security, and compliance posture. Key competitors include established players like CrowdStrike, Palo Alto Networks, Rapid7, and Tenable Holdings, as well as emerging private firms such as Invicti, Tanium, and Wiz (which has announced a pending acquisition by Google). The market is driven by the continuous threat of cyber-attacks and the evolving landscape of regulatory compliance needs, which Qualys addresses with its comprehensive suite of cloud-based solutions.
Comparison to Industry Standards
- Qualys competes with large public companies such as CrowdStrike, Palo Alto Networks, Rapid7, and Tenable Holdings, which often have greater name recognition, larger sales and marketing budgets, and broader distribution networks.
- The company also competes with privately held security providers including Invicti, Tanium, and Wiz (which has announced a pending acquisition by Google).
- Qualys believes its suite of solutions generally competes favorably with respect to product functionality, breadth of offerings, flexibility of delivery models, ease of deployment and use, total cost of ownership, scalability and performance, customer support, and platform extensibility.
- The company's cloud-based delivery model and integrated platform are positioned against traditional on-premise enterprise software products and disparate point solutions offered by competitors.
Corporate Governance
| Change Type | Description | Effective Date | Impact Assessment |
|---|---|---|---|
| Policy Adoption | The Board of Directors adopted a code of business conduct and ethics applicable to all employees, officers, and directors. | NA | Enhances ethical standards and compliance across the organization, fostering trust among stakeholders. |
| Committee Oversight | The Compensation and Talent Committee oversees compensation policies, plans, and benefits programs, and the overall compensation philosophy. | NA | Ensures competitive and fair compensation practices, crucial for attracting and retaining talent. |
| Risk Oversight | The Board of Directors, with assistance from management, monitors and assesses strategic risk exposure, including cybersecurity risks, through the Audit and Risk Committee. | NA | Provides robust oversight of critical risks, integrating cybersecurity into overall enterprise risk management. |
| Cybersecurity Management Structure | A Chief Information Security Officer (CISO) with over two decades of experience reports to the CEO and provides quarterly briefings to the Audit and Risk Committee on cybersecurity risks and activities. | NA | Establishes clear accountability and expert guidance for managing cybersecurity threats, enhancing the company's security posture. |
| Cybersecurity Framework | An Information Security Management System (ISMS) aligned to ISO/IEC 27001 standards is in place, along with a Computer Security Incident Response Team (CSIRT) and Product Security Incident Response Team (PSIRT). | NA | Ensures a structured and certified approach to identifying, assessing, and responding to cybersecurity threats and vulnerabilities, improving resilience. |
| Executive Compensation Plan | The 2025 Corporate Bonus Plan is effective from January 1, 2025, to December 31, 2025, basing payments on ASV growth, Revenue growth, and Non-GAAP EPS, equally weighted. | January 1, 2025 | Aligns executive incentives with key financial and operational performance metrics, driving company growth and profitability. |
| Executive Severance Policy | An Executive Severance Policy is in place with an initial two-year term, automatically renewing annually unless non-renewed with 60 days' notice. It outlines benefits for qualified terminations, including those in connection with a Change in Control. | October 30, 2025 | Reinforces and encourages continued attention and dedication of key management personnel by providing clarity and protection in the event of involuntary termination, particularly around a Change in Control. |
Legal Proceedings
- As of December 31, 2025, there has not been at least a reasonable possibility that the company has incurred a material loss from any ongoing legal proceedings, individually or taken together.
Stakeholder Impact
- Shareholders: Benefit from revenue and net income growth, increased operating cash flow, and ongoing share repurchase program. Face risks from market volatility, potential stock price decline, and macroeconomic uncertainties.
- Employees: Benefit from competitive compensation, robust benefits, talent development programs, and a healthy work-life balance with a hybrid work schedule. Risks include intense competition for skilled personnel and potential impact of macroeconomic conditions on hiring.
- Customers: Benefit from enhanced cloud-based IT, security, and compliance solutions, real-time visibility, and continuous updates. Face risks from potential solution failures, security incidents, or incorrect implementation.
- Channel Partners: Play a significant role in revenue generation (49% in 2025), indicating strong reliance on these relationships for market reach and sales.
- Regulatory Bodies: The company is subject to various regulations (e.g., SEC, GDPR, CCPA, NIS2, FedRAMP) and actively manages compliance, with potential impacts from changes in laws or enforcement actions.
Next Steps
- Continue to innovate and enhance the cloud platform and suite of solutions through significant R&D investments.
- Expand the use of solutions by the large and diverse customer base, focusing on selling additional solutions and increasing subscriptions.
- Drive new customer growth and broaden global reach by targeting key accounts, offering free services, and enhancing sales and marketing efforts.
- Strengthen relationships with channel partners and explore new partnerships to accelerate adoption and expand market presence.
- Selectively pursue technology acquisitions to bolster capabilities and leadership position, including deep learning AI and machine learning technologies.
- Continue to use cash to repurchase shares under the authorized share repurchase program in 2026.
- Monitor the impact of the One Big Beautiful Bill Act (OBBBA) and anticipated guidance from the U.S. Department of the Treasury on future financial results.
- File the Proxy Statement for the 2026 Annual Meeting of Stockholders within 120 days of December 31, 2025.
Key Dates
| Date | Description |
|---|---|
| December 30, 1999 | Qualys, Inc. incorporated in Delaware. |
| 2000 | Launched first cloud solution, Vulnerability Management (VM). |
| September 26, 2012 | The 2012 Equity Incentive Plan became effective. |
| May 2018 | European Union's General Data Protection Regulation (GDPR) took effect. |
| June 9, 2021 | Company's stockholders approved the 2021 Employee Stock Purchase Plan (ESPP). |
| January 1, 2022 | California Privacy Rights Act (CPRA) obligations began. |
| June 8, 2022 | Company's stockholders approved the Amended and Restated 2012 Equity Incentive Plan. |
| July 1, 2023 | CPRA enforcement authorized. |
| December 2023 | FASB issued ASU 2023-09 Income Taxes (Topic 740): Improvements to Income Tax Disclosures. |
| January 2024 | Many countries enacted legislation to apply the Pillar Two directive for tax years beginning in January 2024. |
| June 12, 2024 | Company's stockholders approved an amendment to the Restated 2012 Plan, increasing shares reserved for issuance by 1,092 thousand. |
| November 2024 | FASB issued ASU 2024-03 Income StatementReporting Comprehensive IncomeExpense Disaggregation Disclosures (Subtopic 220-40): Disaggregation of Income Statement Expenses. |
| July 4, 2025 | The One Big Beautiful Bill Act (OBBBA) was signed into law. |
| June 19, 2025 | UK Data (Use and Access) Bill received Royal Assent. |
| September 12, 2025 | European Union's Data Act (the Data Act) became applicable. |
| July 2025 | FASB issued ASU 2025-05, Financial Instruments-Credit Losses (Topic 326): Measurement of Credit Losses for Accounts Receivable and Contract Assets. |
| September 2025 | FASB issued ASU 2025-06 IntangiblesGoodwill and Other Internal-Use Software (Subtopic 350-40): Targeted Improvements to the Accounting for Internal-Use Software. |
| December 31, 2025 | Fiscal year end for the Annual Report on Form 10-K. |
| February 5, 2026 | Board of directors authorized an additional $200.0 million for the share repurchase program. |
| February 11, 2026 | Number of shares of common stock outstanding was 35,675,926. |
| February 20, 2026 | Date of the Annual Report on Form 10-K. |
Recommendation
buyQualys, Inc. demonstrates strong financial health with a 10% increase in revenue and a 14.1% rise in net income for fiscal year 2025, alongside robust operating cash flow and a consistent 103% net dollar expansion rate. These results indicate effective execution and strong customer loyalty in a critical and growing cybersecurity market. While macroeconomic uncertainties and intense competition are noted risks, the company's continued investment in R&D, global expansion, and active share repurchase program position it well for future growth. The recent decline in stock price, as shown in the performance graph, may present an attractive entry point for long-term investors given the underlying business strength and strategic initiatives.
Keywords
Cybersecurity, Cloud Security, IT Security, Compliance Solutions, Vulnerability Management, Risk Management, SaaS, Enterprise TruRisk Platform, Endpoint Detection and Response, Patch Management, Cloud-Native Application Protection Platform, AI/Machine Learning, Data Privacy, SEC Filing, 10-K
Disclaimer:The information provided here is for general informational purposes only and does not constitute financial advice, recommendation, or endorsement of any kind. It may contain errors or omissions. You should not rely on this information to make financial decisions. Always seek the advice of a qualified financial professional before making any investment or financial decisions. Use of this information is at your own risk.