Phase Space AI

Financial Model Notes

Palo Alto Networks [PANW]

Palo Alto Networks, Inc. [PANW] — Financial Model Notes

As of 2026-07-29. Provenance, construction, adjustments, and the weaknesses in my own numbers. Reproduction scripts are committed under work/.


1. Data provenance

Item Source Retrieval
Prices, split detection Alpaca v2/stocks/bars (raw and split-adjusted) work/fetch_prices.py, work/gap_check.py
Fundamentals SEC XBRL companyfacts CIK 0001327567 work/edgar_pull.py, work/extract.py
Balance sheet, income statement 10-Q Q3 FY26 panw-20260430.htm, read directly work/fetch_docs.py, work/q.py
Acquisition contribution, ARR, RPO, guidance 8-K Ex-99.1 ex991q326earningsrelease.htm, ex991q226earningsrelease.htm work/fetch_pr.py
Disclosure language FY23, FY24 10-Ks + Q2, Q3 FY26 10-Qs work/fetch_hist.py, work/censor.py, work/mentions.py
Multiple history own P/S with explicit split factors work/multiple_hist3.py
Implied path assets/reverse_dcf.py work/run_paths.py, work/run_exit.py, work/tm_sens.py
Peer anchor XBRL + balance sheets, 11 comparators work/anchor.py
Option chain Alpaca options contracts + snapshots work/liquidity.py

Recency asserted. Period 2026-04-30, filed 2026-06-03 — 56 days old. Not stale. Note the contrast with the screen, which used a margin_period of 2025-07-31 — 272 days old.


2. The organic-growth decomposition — the single most important calculation

This is not my estimate. It is the company's own disclosure, and it is quoted verbatim so it can be checked.

From the Q3 FY26 release: "Total revenue for the fiscal third quarter 2026 grew 31% year over year to $3.0 billion. This includes $388 million from CyberArk and Chronosphere.**"

Step Value
Q3 FY26 total revenue $3,002m
Less disclosed acquisition contribution ($388m)
Organic Q3 FY26 revenue $2,614m
Q3 FY25 revenue (all organic) $2,289m
Organic growth +14.2%
Reported growth +31.1%
Acquisition contribution 16.9pp

The same decomposition, all from the company's own disclosures in the same release:

Metric Reported Disclosed acquisition portion Organic
NGS ARR $8.1bn, +60% $1.6bn +28.4%
RPO $18.4bn, +36% $1.8bn +22.6%

Corroborating balance-sheet evidence that the acquisitions are the story, in case the release were ambiguous: goodwill +$17,335m, intangibles +$6,520m, paid-in capital +$19,316m, convertible notes assumed $1,352m, shares issued and outstanding 668m → 813m. None of that is compatible with 31% organic growth.

Why this matters beyond PANW: the screen had every input needed to compute this — the disclosure is in the press release it would have had to read to obtain the ARR figures — and it produced growth_trend: ACCELERATING. The generalisable rule: reported growth must be decomposed for any acquisition whose contribution the company discloses, before the trend label is assigned. A 16.9pp error flipped the sign of the trend.


3. Quarterly series construction

PANW's fiscal Q4 (ending 31 July) is not separately tagged in XBRL; only the full year is. Q4 is derived as the annual value less the three filed quarters, with contiguity enforced before any TTM is summed.

Quarter ended Revenue ($m) Derivation
2025-04-30 2,289 filed 10-Q
2025-07-31 2,536.5 derived: FY25 9,221.5 − (2,139 + 2,257 + 2,289)
2025-10-31 2,474 filed 10-Q
2026-01-31 2,594 filed 10-Q
2026-04-30 3,002 filed 10-Q

TTM revenue = 2,536.5 + 2,474 + 2,594 + 3,002 = $10,606.5m. Matches the screen exactly.

A caveat I raise against my own primary figure. TTM contains only one quarter of CyberArk and Chronosphere, so it understates the current revenue base and therefore overstates the growth the price requires. I run the implied path on both TTM and on the Q3 run-rate annualised ($12,008m), and report both (Valuation §3). The run-rate case moves the margin from −46.2pp to −43.1pp. It does not change the conclusion, but presenting only the harsher figure would have been unfair to the name.


4. Share count

Basis Count Use
Shares issued and outstanding, balance sheet 813m 2026-04-30
dei cover page, 2026-05-26 815m market cap — what the screen used, and correct
Diluted weighted average, Q3 FY26 801m EPS cross-check
Company-guided Q4 FY26 diluted 830–840m forward work: ~835m
12 months forward (my estimate) ~845m ~835m + ~1% SBC issuance, zero buyback

Cross-checks passed: net loss ÷ diluted = −177 ÷ 801 = −$0.221 vs filed −$0.22 ✓; Q2 FY26 432 ÷ 711 = $0.607 vs filed $0.61 ✓.

Split verification. PANW split 3-for-1 on 2022-09-14 and 2-for-1 on 2024-12-16. Both were confirmed independently in the raw, unadjusted Alpaca price series — the 2024 split appears as a −48.5% single-session move ($393.12 → $202.50). The 815m count is post-both-splits and consistent with the price. This check was run because it is exactly the check that CRWD failed in this same cluster (a 4-for-1 split on 2026-07-02 that the screen did not apply, producing a 4.0x market-cap error).

PANW is the only name of the five where the forward share count is HIGHER than today's, because buybacks are zero and SBC issuance continues. Any model that holds 815m flat overstates forward per-share values by ~3.7%.


5. Net cash — two omissions in opposite directions

Component 2026-04-30 ($m) Screen Mine
Cash and cash equivalents 2,364
Short-term investments 747
Long-term investments 3,881 OMITTED
Short-term convertible senior notes (160) OMITTED
Long-term convertible senior notes (1,192) OMITTED
Operating lease liabilities, noncurrent (719) counted as debt disclosed, excluded
Net cash ex-lease +5,640 +2,392 HEADLINE
Net cash incl. noncurrent lease +4,921 Alternative
Financing receivables, ST + LT 591 + 779 excluded excluded — credit exposure, not cash

The screen made two independent errors that partially offset, leaving net cash understated by $3,248m: 1. It omitted $3,881m of long-term investments. PANW holds a large non-current investment portfolio; a pipeline keyed on ShortTermInvestments alone misses it. 2. It omitted $1,352m of convertible notes — the ConvertibleDebtNoncurrent tag the brief explicitly instructed me to check. PANW's value there was $0 as recently as 2025-07-31 and appeared only when CyberArk's notes were assumed, so a pipeline that cached the tag or tested only for prior existence would miss it.

Two omissions cancelling toward a plausible number is worse than one obvious error, because nothing in the output signals a problem. The screen's net_cash_complete: true flag was set.

Stale-tag note, same disease as ADBE: OperatingLeaseLiabilityCurrent for PANW was last filed 2025-07-31. Using it as current would be the ADBE error repeated.


6. Adjustments applied, with reasons

# Adjustment Effect Why
1 Strip the disclosed $388m acquisition contribution from growth 31.1% → 14.2% §2. Company-disclosed. This is the adjustment the whole memo turns on.
2 Same for NGS ARR and RPO +60% → +28.4%; +36% → +22.6% Company-disclosed.
3 Use the current TTM margin, not the screen's 2025-07-31 figure 13.5% → 9.6% The screen's period predates both acquisitions by ~6 months.
4 Add $3,881m of long-term investments and $1,352m of converts to net cash +$3,248m §5.
5 Use ~835m diluted (company-guided) for forward work −2.4% to forward per-share values The company's own Q4 guide; buybacks are zero.
6 Run the implied path on both TTM and run-rate revenue margin −46.2pp and −43.1pp §3. Fairness to the name.
7 Exclude the 2021-10 and 2022-01 P/S observations (34.7x, 34.2x) from the percentile clean-window percentile 100th Artifacts of a pre-3:1-split as-reported share count meeting an adjusted price. Excluding them makes the current percentile look WORSE, not better — they would otherwise sit above today's 24.15x. Disclosed for that reason.
8 Exclude financing receivables ($1,370m) from net cash EV +$1,370m vs including them Customer credit exposure, not cash. Disclosed.

No SBC adjustment. SBC is 14.0% of revenue and 104% of GAAP operating income. The GAAP margin carries it. The guided 28.9–29.2% non-GAAP operating margin is reported for reference and is run only as a sensitivity — and even at a 35% terminal margin, above the non-GAAP figure, the name fails by 29.2pp. The non-GAAP exclusion list is the longest in the cluster and bridges a −6.1% GAAP quarter to +27.1% non-GAAP, a 33.2pp gap.


7. What the model deliberately does not contain


8. Known weaknesses in my own numbers

Stated so a reviewer can attack them.

  1. The 20% terminal margin is arbitrary, and for once that does not matter. The full range 9.6%–35% is run and every value fails by 29.2pp to 71.6pp. This is the one name in the cluster where the terminal margin is not the load-bearing input. It is stated as a weakness anyway, because on CRM and WDAY the same parameter decides everything and a reader should know the same latitude was available here.
  2. TTM revenue understates the base. Addressed by running the run-rate case (§3), which moves the margin 3.1pp. Acknowledged rather than buried.
  3. Organic NGS ARR of +28.4% is a genuinely strong number that my headline treatment underweights. PANW's organic bookings franchise is growing roughly twice as fast as its organic revenue, and if that converts, the revenue line accelerates. It would need to accelerate to ~43–60% and sustain it for five years to justify the price, which is why it does not change the verdict — but a reader who sees only "14.2% organic, decelerating" is getting an incomplete picture and I would rather say so.
  4. Adjusted FCF margin of 38.5% (up 430bp) and the FY28 40% target are the strongest facts in PANW's favour, and the reverse DCF is run on EBIT, not FCF. On a cash basis PANW looks materially better than on a GAAP-EBIT basis. I have not run an FCF-based implied path. At a 40% FCF margin on year-5 revenue of $20.6bn and a 25x FCF exit, the implied equity value is roughly $246/share — still well below spot, so the conclusion survives; but this is an estimate I have not put through the same instrument and I flag it as such.
  5. The clean-window P/S percentile uses n=15 observations (2022-10 onward). Fifteen is thin. The full-history figure (93rd) and the five-year figure (90th) are reported alongside so the reader can see the conclusion does not depend on the window choice.
  6. The 45% probability on the downside case is a judgement, not a computed figure. It is set high because the scenario has a date (the Q3 FY27 anniversary) and requires no operational deterioration. It will be Brier-scored by ledger_scorer.py like any other, and it should be.
  7. I have not verified the exact closing dates of CyberArk and Chronosphere. I infer ~February 2026 from the share count stepping 697m → 816m between the 2025-11-11 and 2026-02-11 cover dates, the goodwill step appearing at 2026-04-30, and the convertible notes appearing in the same period. The inference is well-corroborated but it is an inference, and the anniversary date in the Catalyst Calendar depends on it.